DEF CON Forum Site Header Art

Announcement

Collapse
No announcement yet.

Tractor Hacking - Future Reverse Engineering Work JTAG attack on the ECU

Collapse
X
Collapse
  •  

  • Tractor Hacking - Future Reverse Engineering Work JTAG attack on the ECU


    Future Reverse Engineering Work

    JTAG attack on the ECU

    Upon investigation of the ECU board it was noted that there may be JTAG or similar debug pins exposed that have been previously accessed, likely during the remanufacturing process. These are pictured below:
    Click image for larger version

Name:	ECU-Brain-JTAG-Highlight.jpg
Views:	16615
Size:	2.44 MB
ID:	236233



    Injecting debug commands into the CAN network

    The J1939 spec specifies a number of debugging commands that can be injected into the CAN network to receive back certain information. It is likely that this is possible using no more specialized equipment than our SparkFun RedBoard and CAN-BUS shield. However this avenue has not yet been investigated.
    Intercepting and filtering CAN packets

    If it is determined that certain packets are being used to filter system messages the lack of integrity checks or encryption (similar to unencrypted UDP) on the CAN network would allow a physical device to be placed in between a control unit, like the ECU and the rest of the network to intercept and filter packets that cause the vendor lockdown.


      Posting comments is disabled.

    Article Tags

    Collapse

    Latest Articles

    Collapse

    Working...
    X