Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
CSRF Vulnerability

Hello, welcome to my new article, this article will talk about how I found CSRF on the login page. First, let me introduce myself, my name…Continue reading on Medium »
Read more...
Recox v2.0 -classifying vulnerabilities in web applications

The script’s goal is to aid in the classification of vulnerabilities in web applications. RecoX, the emerging methodology, can detect…Continue reading on Medium »
Read more...
hacking: security in practice
What non-fiction books would a typical black hat hacker read ?

I wanna know what all non fiction or to some extent fiction books would a black hat hacker read. I know for sure that Cryptonomicon would be there in the list. what else ?

submitted by /u/dassicity
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Hackers Say They Can Unlock and Start Honda Cars Remotely

Hackers Say They Can Unlock and Start Honda Cars RemotelyPost Views: 11
Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
Kevin2600, a security researcher, published a technical report and videos on a vulnerability that he claims allows anyone armed with a simple hardware device to steal the code to unlock Honda vehicles.
Hackers could unlock and remotely start virtually all models of Honda cars, according to security researchers. Kevin2600, who works for cybersecurity firm Star-V Lab, dubbed the attack RollingPWN.

“This weakness allows anyone to permanently open the car door or even start the car engine from a long distance,” Kevin2600 wrote in his report. “The Rolling-PWN bug is a serious vulnerability. We found it in a vulnerable version of the rolling codes mechanism, which is implemented in huge amounts of Honda vehicles.”

In a phone call, Kevin2600 explained that the attack relies on a weakness that allows someone using a software defined radio—such as HackRF—to capture the code that the car owner uses to open the car, and then replay it so that the hacker can open the car as well. In some cases, he said, the attack can be performed from 30 meters (approximately 98 feet) away.

In the videos, Kevin2600 and his colleagues show how the attack works by unlocking different models of Honda cars with a device connected to a laptop.

The Honda models that Kevin2600 and his colleagues tested the attack on use a so-called rolling code mechanism, which means that—in theory—every time the car owner uses the keyfob, it sends a different code to open it. This should make it impossible to capture the code and use it again. But the researchers found that there is a flaw that allows them to roll back the codes and reuse old codes to open the car, Kevin2600 said.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png pic.twitter.com/9hziAqMCC2

— Kevin2600 (@Kevin2600) July 7, 2022
The researcher told Motherboard that he and his colleagues went to a Honda dealership to test the attack on different models, and found that 10 of them are vulnerable, which makes them think all Honda models from 2012 to 2022 are vulnerable to this attack.

A Honda spokesperson told Motherboard that the vulnerability found by Kevin2600 is “old news.”

“Thus, I’d hope that you would treat it as such and move on to something current rather than creating a new round of people thinking that this is a ‘new’ thing,” the spokesperson wrote in an email.

The spokesperson was referring to research from earlier this year, which focused on fixed codes, and not rolling codes.

“We’ve looked into past similar allegations and found them to lack substance. While we don’t yet have enough information to determine if this report is credible, the key fobs in the referenced vehicles are equipped with rolling code technology that would not allow the vulnerability as represented in the report. In addition, the videos offered as evidence of the absence of rolling code do not include sufficient evidence to support the claims,” the spokesperson wrote.
Trending: How do QR Codes work and how criminal hackers use them to generate phishing attacks – Demo Trending: OSINT Tool: Pagodo These kinds of attacks to unlock cars and other targets are relatively common. Earlier this year, other security researchers found a similar issue with other Honda cars, although in that case the problem was with fixed codes, as opposed to rolling codes. Then in June, researchers demons[...]

___________________________
@hacking_Attack
@Hacking_Video