Web Hack List

Collected research

Hacking Kia: Remotely Controlling Cars With Just a License Plate

Kia's owner site and dealer portal front the same backend API gateway through a header-driven proxy servlet. This case study shows the dealer portal accepted accounts created through the consumer registration endpoint, so a self-issued session token reached dealer-only functions: resolving a licence plate to a VIN, disclosing the owner's name, phone and email, and adding the attacker as an unseen second user able to send remote lock, start and locate commands.

Record

Researcher
Sam Curry and @samwcyo
Published by
samcurry.net
Date
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Sam Curry and @samwcyo, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .