White hat security researchers Charlie Miller and Chris Valasek have once again hacked a 2014 Jeep Cherokee, this time plugging a laptop directly into the vehicle’s CAN network via a port under the dashboard.
“Instead of merely compromising one of the so-called electronic control units or ECUs on a target car’s CAN network and using it to spoof messages to the car’s steering or brakes, they also attacked the ECU that sends legitimate commands to those components, which would otherwise contradict their malicious commands and prevent their attack,” explained Wired’s Whitney Curtis. “By putting that second ECU into ‘bootrom’ mode—the first step in updating the ECU’s firmware that a mechanic might use to fix a bug—they were able to paralyze that innocent ECU and send malicious commands to the target component without interference.”