Collected research
Hacking Kia: Remotely Controlling Cars With Just a License Plate
Kia's owner site and dealer portal front the same backend API gateway through a header-driven proxy servlet. This case study shows the dealer portal accepted accounts created through the consumer registration endpoint, so a self-issued session token reached dealer-only functions: resolving a licence plate to a VIN, disclosing the owner's name, phone and email, and adding the attacker as an unseen second user able to send remote lock, start and locate commands.
Record
- Researcher
- Sam Curry and @samwcyo
- Published by
- samcurry.net
- Date
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Sam Curry and @samwcyo, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .