Calling all Security Minded Geeks ?

DevSecOps

Well-Known Member
First Name
Todd
Joined
Sep 22, 2021
Threads
69
Messages
4,741
Reaction score
11,508
Location
Sacramento, CA
Vehicles
'21 Audi SQ5 / '23 Rivian R1T / '23 M3P
Occupation
CISO
Country flag
QNX isn't my thing, and I don't know if it's anyone's here. But lately I've been noticing DNS buffer overflow attempts that have been blocked by Cisco AMP, from IP's in PA to the MME. Blackberry admitted to a BadAlloc bug affecting 175 million vehicles and medical equipment ( CVE-2021-22156 ) just a few months ago after dragging their feet for quite some time on it. Wondering if anyone else has seen attempts to probe at the MME Sync system?

Also kinda curious if the MME initiates a VPN to Ford for OTA's - if anyone knows.
Sponsored

 

sockmeister

Well-Known Member
Joined
Sep 24, 2020
Threads
6
Messages
1,882
Reaction score
2,996
Location
Pennsylvania
Vehicles
2021 Mustang Mach-E4x
Occupation
SW Engineer
Country flag
QNX isn't my thing, and I don't know if it's anyone's here. But lately I've been noticing DNS buffer overflow attempts that have been blocked by Cisco AMP, from IP's in PA to the MME. Blackberry admitted to a BadAlloc bug affecting 175 million vehicles and medical equipment ( CVE-2021-22156 ) just a few months ago after dragging their feet for quite some time on it. Wondering if anyone else has seen attempts to probe at the MME Sync system?

Also kinda curious if the MME initiates a VPN to Ford for OTA's - if anyone knows.
IPs in PA, you say!? I promise, it wasn't me... ?
 

sockmeister

Well-Known Member
Joined
Sep 24, 2020
Threads
6
Messages
1,882
Reaction score
2,996
Location
Pennsylvania
Vehicles
2021 Mustang Mach-E4x
Occupation
SW Engineer
Country flag
@CHeil402 Has seen some of the Mach-E's update attempts through his router's logs. Maybe there's some more information about what exactly it connected to?

I doubt it opens a VPN, but I'm sure it's end-to-end encrypted at least, in this day and age...
 
OP
OP
DevSecOps

DevSecOps

Well-Known Member
First Name
Todd
Joined
Sep 22, 2021
Threads
69
Messages
4,741
Reaction score
11,508
Location
Sacramento, CA
Vehicles
'21 Audi SQ5 / '23 Rivian R1T / '23 M3P
Occupation
CISO
Country flag

CHeil402

Well-Known Member
First Name
Chris
Joined
Sep 21, 2020
Threads
8
Messages
723
Reaction score
1,316
Location
King of Prussia, PA
Vehicles
2017 Audi A4, 2021 MME
Occupation
Electrical Engineer
Country flag
@CHeil402 Has seen some of the Mach-E's update attempts through his router's logs. Maybe there's some more information about what exactly it connected to?

I doubt it opens a VPN, but I'm sure it's end-to-end encrypted at least, in this day and age...
My car hasn't done anything "interesting" recently but the car's TCU talks to TomTom and Ford's server's over https. Doesn't look like a VPN, but that shouldn't be needed anyway.

Ford Mustang Mach-E Calling all Security Minded Geeks ? Screenshot_20220103-204923_Firewalla


Ford Mustang Mach-E Calling all Security Minded Geeks ? Screenshot_20220103-205018_Firewalla
 


OP
OP
DevSecOps

DevSecOps

Well-Known Member
First Name
Todd
Joined
Sep 22, 2021
Threads
69
Messages
4,741
Reaction score
11,508
Location
Sacramento, CA
Vehicles
'21 Audi SQ5 / '23 Rivian R1T / '23 M3P
Occupation
CISO
Country flag
Doesn't look like a VPN, but that shouldn't be needed anyway.
Most critical infrastructure will use a VPN (not the ones for consumers) but direct to the MFG so to prevent MIM or DNS Spoofing attempts. Tesla is a good example of a auto MFG that uses a VPN to push vehicle updates.

The day to day traffic for the car I have looked at many times over, but I have never received an OTA, hence my curiosity.
 

benk016

Well-Known Member
First Name
Ben
Joined
Nov 12, 2020
Threads
37
Messages
3,019
Reaction score
4,683
Location
Tulsa, Oklahoma
Vehicles
2021 Mustang Mach-E GT
Country flag
I've always suspected that Ford only uses cellular for sending any communication to the car such as lock/unlock. Wifi maybe would send some telemetry data and give it an alternative download route for update files. But for the actual communication with the car, I suspect is through a private network on cellular.

As far as downloads, it's probably just downloading it from azure storage like all their files are.
 

sockmeister

Well-Known Member
Joined
Sep 24, 2020
Threads
6
Messages
1,882
Reaction score
2,996
Location
Pennsylvania
Vehicles
2021 Mustang Mach-E4x
Occupation
SW Engineer
Country flag
My car hasn't done anything "interesting" recently but the car's TCU talks to TomTom and Ford's server's over https. Doesn't look like a VPN, but that shouldn't be needed anyway.

Ford Mustang Mach-E Calling all Security Minded Geeks ? Screenshot_20220103-205018_Firewalla


Ford Mustang Mach-E Calling all Security Minded Geeks ? Screenshot_20220103-205018_Firewalla
So the Sync Maps are made by Garmin, but it's also using TomTom for something? That's interesting.
 

Av8tor

Well-Known Member
First Name
Kevin
Joined
Aug 6, 2021
Threads
30
Messages
708
Reaction score
919
Location
Richmond, VA
Vehicles
Fusion Hybrid, MME GTPE
Occupation
Systems Engineer IOT
Country flag
So the Sync Maps are made by Garmin, but it's also using TomTom for something? That's interesting.
I think TomTom is a traffic feed, Apple Maps uses it too. Not 100% positive, but that's what I'm thinking.
 

sockmeister

Well-Known Member
Joined
Sep 24, 2020
Threads
6
Messages
1,882
Reaction score
2,996
Location
Pennsylvania
Vehicles
2021 Mustang Mach-E4x
Occupation
SW Engineer
Country flag
I think TomTom is a traffic feed, Apple Maps uses it too. Not 100% positive, but that's what I'm thinking.
That makes sense! I wondered where that came from.
Supposedly in '23 they'll be shifting to a partnership with Google. I wonder if this means Android Automotive OS on the touchscreens, and native google maps.
Sponsored

 
 




Top