Yikes and double Yikes - Haxtors take control of Jeep
- FlyingPenguin
- Flightless Bird
- Posts: 33161
- Joined: Wed Nov 22, 2000 11:13 am
- Location: Central Florida
- Contact:
FYI: Sprint blocked the port that this hack uses, so while you should install the update, the attack vector has been blocked. The hacker who revealed this exploit says that the blocked port has closed the exploit access vector.
---
“The Government of Spain will not applaud those who set the world on fire just because they show up with a bucket.” - Prime Minister of Spain, Pedro Sánchez

“The Government of Spain will not applaud those who set the world on fire just because they show up with a bucket.” - Prime Minister of Spain, Pedro Sánchez

From Chrysler's site. You enter your VIN, which determines the version you get.FlyingPenguin wrote:Hey Los, did you download that update from a secure website. I heard they weren't using SSL?
Hopefully the car at least checks the update to make sure it's signed with Chrysler's public key. However knowing these guys, the car will probably take any file.
I've updated several times over the last 2 years for new features and improvements. I only get them from Chrysler.
Yeah, I wouldn't doubt that it will take any file. That's why I grab it from Chrysler.
------------------------------------------

