Никак всё люди не отстанут от зарядных станций для электричек. То кабель отрежут, то устроят глубокий личный досмотр через тот же кабель. А тут ребятки доковырялись до Qualcomm HomePlug GreenPHY модемов, которые стоят почти в каждой зараядке и через которые станцию можно окирпичить.
https://www.youtube.com/watch?v=XZAeKbhGSa4
P.S. Вообще, то, как организовано взаимодействие зарядки и машины, вызывает неподдельный интерес. И езернета туда напихали, и каких-то беспроводных сложностей, и аутентификация есть, и билинг за деньгами следит. Прям технолоджия какая-то.
YouTube
PIBuster Exploiting a Common Misconfiguration in CCS EV Chargers
This paper presents PIBuster, a new attack vector against the EV charging infrastructure. The attack targets the Qualcomm HomePlug GreenPHY modems used inside CCS chargers and vehicles, and is enabled by a common misconfiguration in their Parameter Information Block (PIB). The vulnerability allows an attacker to overwrite the PIB of modems, which contains many critical fields. We create a safe laboratory testbed for evaluating PIB security, use it to pinpoint the necessary conditions for the attack, and determine that a single configuration byte is responsible. We collect a large dataset of PIBs from real-world EV chargers, and evaluate them using our test bed, determining that 41 out of 69 charging stations exhibit the vulnerable configuration. Finally, we identify a specific high-impact attack that results in a persistent denial of service, and that can only be resolved by replacing hardware.
About the Speaker:
Marcell Szak?ly is a DPhil student in the Systems Security Lab at the University of Oxford. He studies the security of the EV charging infrastructure, and supervises master's students on related topics. His research has revealed potential security issues in the CCS charging process, and his measurement study showed that many currently deployed chargers use outdated (and less secure) version of the protocol.
Marcell began pursuing cybersecurity research after earning a Master of Physics from Oxford. His work still incorporates many physical aspects, with a strong focus on electronics and RF hardware. He is primarily interested in finding and understanding potential attacks, caused in part by physical design flaws.
Обсуждение 1
Обсуждение не доступно в веб-версии. Чтобы написать комментарий, перейдите в приложение Telegram.
Обсудить в Telegram