{"id":3526,"date":"2015-08-10T18:42:58","date_gmt":"2015-08-10T11:42:58","guid":{"rendered":"http:\/\/ttud.com.vn\/?p=3526"},"modified":"2017-09-27T18:45:30","modified_gmt":"2017-09-27T11:45:30","slug":"rolljam-bo-kit-30-hack-duoc-khoa-cua-bang-remote-cua-hang-trieu-xe-hoi-va-cua-gara","status":"publish","type":"post","link":"https:\/\/casta.ttud.com.vn\/index.php\/rolljam-bo-kit-30-hack-duoc-khoa-cua-bang-remote-cua-hang-trieu-xe-hoi-va-cua-gara\/","title":{"rendered":"Rolljam: B\u1ed9 kit 30$ hack \u0111\u01b0\u1ee3c kh\u00f3a c\u1eeda b\u1eb1ng remote c\u1ee7a h\u00e0ng tri\u1ec7u xe h\u01a1i v\u00e0 c\u1eeda gara"},"content":{"rendered":"<p><strong>T\u1ea1i DefCon 2015 \u0111ang di\u1ec5n ra t\u1eeb ng\u00e0y 6 &#8211; 9\/8 \u1edf Las Vegas (m\u1ed9t trong nh\u1eefng h\u1ed9i ngh\u1ecb hacker l\u1edbn nh\u1ea5t th\u1ebf gi\u1edbi t\u1ed5 ch\u1ee9c h\u00e0ng n\u0103m), chuy\u00ean gia b\u1ea3o m\u1eadt Samy Kamkar \u0111\u00e3 gi\u1edbi thi\u1ec7u b\u1ed9 c\u00f4ng c\u1ee5 c\u00f3 gi\u00e1 32$ d\u00f9ng \u0111\u1ec3 hack c\u00e1ch m\u1edf kh\u00f3a c\u1eeda c\u00e1c lo\u1ea1i xe h\u01a1i kh\u00f4ng c\u1ea7n ch\u00eca kh\u00f3a (keyless &#8211; d\u00f9ng remote \u0111\u1ec3 m\u1edf c\u1eeda xe) c\u0169ng nh\u01b0 remote c\u1eeda gara \u0111\u1ec3 xe. Thi\u1ebft b\u1ecb t\u00ean l\u00e0 Rolljam, nh\u00ecn b\u1ec1 ngo\u00e0i th\u00ec th\u1ea5y gi\u00f4ng gi\u1ed1ng m\u1ed9t c\u00e1i Raspberry Pi nh\u01b0ng s\u1ee9c m\u1ea1nh c\u1ee7a n\u00f3 th\u1eadt l\u00e0 gh\u00ea g\u1edbm.<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-3527\" src=\"http:\/\/ttud.com.vn\/wp-content\/uploads\/2017\/09\/10082015231611-duytranrolljam.jpg\" alt=\"\" width=\"500\" height=\"333\" srcset=\"https:\/\/casta.ttud.com.vn\/wp-content\/uploads\/2017\/09\/10082015231611-duytranrolljam.jpg 500w, https:\/\/casta.ttud.com.vn\/wp-content\/uploads\/2017\/09\/10082015231611-duytranrolljam-300x200.jpg 300w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/p>\n<p>Samy Kamkar m\u00f4 t\u1ea3 ho\u1ea1t \u0111\u1ed9ng c\u1ee7a Rolljam nh\u01b0 sau: B\u1ed9 rolljam s\u1ebd \u0111\u01b0\u1ee3c \u0111\u1eb7t \u1ea9n gi\u1ea5u trong ph\u1ea1m vi \u0111\u00e2u \u0111\u00f3 g\u1ea7n chi\u1ebfc xe, khi ch\u1ee7 xe s\u1eed d\u1ee5ng remote b\u1ea5m m\u1edf kh\u00f3a xe, rolljam s\u1ebd ph\u00e1t ra m\u1ed9t s\u00f3ng radio ph\u00e1 t\u00e1c d\u1ee5ng c\u1ee7a remote xe, \u0111\u1ed3ng th\u1eddi &#8220;copy&#8221; l\u1ea1i to\u00e0n b\u1ed9 m\u00e3 l\u1ec7nh m\u00e0 remote truy\u1ec1n t\u1edbi xe \u0111\u1ec3 m\u1edf kh\u00f3a. Ch\u1ee7 xe s\u1ebd th\u1ea5y l\u00e0 l\u1ea7n nh\u1ea5n n\u00fat \u0111\u1ea7u ti\u00ean kh\u00f4ng c\u00f3 t\u00e1c d\u1ee5ng (c\u1eeda xe kh\u00f4ng \u0111\u01b0\u1ee3c m\u1edf), h\u1ecd ph\u1ea3i b\u1ea5m remote l\u1ea7n 2 \u0111\u1ec3 m\u1edf kh\u00f3a xe. L\u00fac n\u00e0y th\u00ec m\u00e3 kh\u00f3a c\u1ee7a remote \u0111\u00e3 \u0111\u01b0\u1ee3c rolljam sao ch\u00e9p l\u1ea1i v\u00f4 b\u1ed9 nh\u1edb c\u1ee7a n\u00f3. M\u1ed9t th\u1eddi gian sau, c\u00f3 th\u1ec3 l\u00e0 v\u00e0i gi\u1edd, v\u00e0i ng\u00e0y, v\u00e0i tu\u1ea7n, khi ch\u1ee7 xe kh\u00f4ng \u0111\u1ec3 \u00fd, hacker s\u1ebd s\u1eed d\u1ee5ng rolljam \u0111\u1ec3 m\u1edf kh\u00f3a c\u1eeda chi\u1ebfc xe, c\u00f3 th\u1ec3 l\u1ea5y tr\u1ed9m chi\u1ebfc xe \u0111i m\u1ea5t. C\u00e1ch l\u00e0m t\u01b0\u01a1ng t\u1ef1 c\u00f3 th\u1ec3 s\u1eed d\u1ee5ng \u0111\u1ec3 tr\u1ed9m m\u00e3 m\u1edf kh\u00f3a c\u1eeda gara nh\u00e0 \u0111\u1ec3 xe c\u1ee7a n\u1ea1n nh\u00e2n.<\/p>\n<p>Vi\u1ec7c hack kh\u00f3a c\u1eeda xe b\u1eb1ng c\u00e1ch sao ch\u00e9p m\u00e3 remote \u0111\u00e3 \u0111\u01b0\u1ee3c c\u00e1c hacker khai th\u00e1c t\u1eeb nhi\u1ec1u n\u0103m nay. Do \u0111\u00f3 c\u00e1c h\u00e3ng xe h\u01a1i \u0111\u00e3 s\u1eeda l\u1ed7 h\u1ed5ng b\u1ea3o m\u1eadt n\u00e0y b\u1eb1ng c\u00e1ch, m\u1ed7i l\u1ea7n khi ch\u1ee7 xe b\u1ea5m remote m\u1edf kh\u00f3a c\u1eeda th\u00ec m\u00e3 \u0111\u1ed3ng b\u1ed9 gi\u1eefa remote v\u00e0 xe \u0111\u01b0\u1ee3c \u0111\u1ed5i kh\u00e1c, tr\u00e1nh vi\u1ec7c 1 m\u00e3 \u0111\u01b0\u1ee3c s\u1eed d\u1ee5ng 2 l\u1ea7n. H\u1ec7 th\u1ed1ng rolljam c\u1ee7a Samy Kamkar ti\u1ebfn b\u1ed9 h\u01a1n \u1edf ch\u1ed7 n\u00f3 ph\u00e1 s\u00f3ng \u0111\u1ed3ng b\u1ed9 c\u1ee7a remote v\u00e0 xe trong l\u1ea7n \u0111\u1ea7u ti\u00ean 2 b\u00ean mu\u1ed1n ti\u1ebfp c\u1eadn nhau (l\u1ea7n \u0111\u1ea7u ti\u00ean ch\u1ee7 xe b\u1ea5m m\u1edf c\u1eeda nh\u01b0ng kh\u00f4ng c\u00f3 t\u00e1c d\u1ee5ng). Trong l\u1ea7n 2 ch\u1ee7 xe b\u1ea5m remote, rolljam s\u1ebd ch\u1eb7n v\u00e0 sao ch\u00e9p l\u1ea1i \u0111o\u1ea1n m\u00e3 &#8220;s\u1ed1 2&#8221; n\u00e0y \u0111\u1ed3ng th\u1eddi ph\u00e1t l\u1ea1i \u0111o\u1ea1n m\u00e3 &#8220;s\u1ed1 1&#8221; \u0111\u1ec3 m\u1edf xe. Ch\u1ee7 xe c\u1ee9 t\u01b0\u1edfng l\u00e0 l\u00fac \u0111\u1ea7u h\u1ecd b\u1ea5m n\u00fat kh\u00f4ng \u0103n, nh\u01b0ng th\u1ef1c ra l\u00e0 thao t\u00e1c m\u1edf c\u1eeda xe \u0111\u00e3 b\u1ecb hacker thu th\u1eadp l\u1ea1i. \u0110o\u1ea1n m\u00e3 &#8220;s\u1ed1 2&#8221; m\u00e0 rolljam sao ch\u00e9p ch\u01b0a \u0111\u01b0\u1ee3c s\u1eed d\u1ee5ng n\u00ean hi\u1ec3n nhi\u00ean sau n\u00e0y s\u1ebd d\u00f9ng \u0111\u1ec3 m\u1edf c\u1eeda xe \u0111\u01b0\u1ee3c.<\/p>\n<p>Tr\u01b0\u1edbc \u0111\u00f3, h\u1ed3i cu\u1ed1i th\u00e1ng 7 v\u1eeba r\u1ed3i Samy c\u00f3 tr\u00ecnh di\u1ec5n m\u1ed9t thi\u1ebft b\u1ecb kh\u00e1c t\u00ean l\u00e0 OwnStar, n\u00f3 hack \u0111\u01b0\u1ee3c h\u1ec7 th\u1ed1ng \u0111i\u1ec1u khi\u1ec3n OnStar RemoteLink tr\u00ean xe GM \u0111\u1ec3 m\u1edf kh\u00f3a c\u1eeda xe v\u00e0 \u0111\u1ec1 m\u00e1y xe.<\/p>\n<p><iframe loading=\"lazy\" title=\"OwnStar - hacking cars with OnStar to locate, unlock and remote start vehicles\" width=\"625\" height=\"352\" src=\"https:\/\/www.youtube.com\/embed\/3olXUbS-prU?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe><\/p>\n<p style=\"text-align: center;\">Samy tr\u00ecnh di\u1ec5n hack xe b\u1eb1ng OwnStar\u200b<\/p>\n<p>Samy Kamkar cho bi\u1ebft anh \u0111\u00e3 th\u1eed nghi\u1ec7m v\u00e0 th\u1ea5y rolljam th\u00e0nh c\u00f4ng v\u1edbi xe c\u1ee7a ch\u00ednh m\u00ecnh c\u0169ng nh\u01b0 c\u1ee7a c\u00e1c h\u00e3ng Nissan, Cadillac, Ford, Toyota, Lotus, VW, Chrysler v.v&#8230; c\u0169ng nh\u01b0 m\u1ed9t s\u1ed1 th\u01b0\u01a1ng hi\u1ec7u remote c\u1eeda gara \u0111\u1ec3 xe l\u00e0 Viper, Genie, Liftmaster. Samy n\u00f3i r\u1eb1ng c\u00e1ch n\u00e0y c\u00f3 th\u1ec3 m\u1edf c\u1eeda \u0111\u01b0\u1ee3c h\u00e0ng tri\u1ec7u xe h\u01a1i kh\u00e1c nhau v\u00e0 l\u1ed7 h\u1ed5ng b\u1ea3o m\u1eadt n\u00e0y n\u1eb1m \u1edf chip \u0111i\u1ec1u khi\u1ec3n remote c\u1ee7a xe cung c\u1ea5p b\u1edfi c\u00e1c h\u00e3ng Microchip (chip t\u00ean Keeloq), Texas Instruments (chip Hisec)&#8230;<\/p>\n<p>Trang Wired \u0111\u00e3 li\u00ean h\u1ec7 v\u1edbi c\u00e1c h\u00e3ng xe h\u01a1i, h\u00e3ng kh\u00f3a c\u1eeda gara \u0111\u1ec3 th\u00f4ng b\u00e1o v\u1ec1 t\u00ecnh tr\u1ea1ng n\u00e0y nh\u01b0ng ch\u01b0a nhi\u1ec1u n\u01a1i ph\u1ea3n h\u1ed3i l\u1ea1i. Liftmaster hay VW t\u1eeb ch\u1ed1i b\u00ecnh lu\u1eadn. Trong khi \u0111\u00f3 ph\u00e1t ng\u00f4n vi\u00ean c\u1ee7a Cadillac l\u00e0 \u00f4ng David Caldwell th\u00ec n\u00f3i r\u1eb1ng &#8220;Ch\u00fang t\u00f4i bi\u1ebft c\u00e1ch hack n\u00e0y&#8221;, nh\u01b0ng \u00f4ng cho r\u1eb1ng ch\u1ec9 c\u00f3 xe Cadillac nh\u1eefng \u0111\u1eddi tr\u01b0\u1edbc m\u1edbi b\u1ecb \u1ea3nh h\u01b0\u1edfng, c\u00f2n t\u1eeb \u0111\u1eddi 2015 tr\u1edf \u0111i \u0111\u00e3 s\u1eed d\u1ee5ng h\u1ec7 th\u1ed1ng kh\u00f3a c\u1eeda ki\u1ec3u m\u1edbi, kh\u00f4ng b\u1ecb hack theo ki\u1ec3u n\u00e0y \u0111\u01b0\u1ee3c n\u1eefa. \u0110\u00e1p l\u1ea1i, Samy Kamkar c\u0169ng cho r\u1eb1ng Cadillac n\u00f3i \u0111\u00fang, h\u1ec7 th\u1ed1ng kh\u00f3a ki\u1ec3u m\u1edbi c\u1ee7a h\u00e3ng xe h\u01a1i s\u1eed d\u1ee5ng th\u1ebf h\u1ec7 chip Dual Keeloq, c\u00f3 &#8220;\u0111o\u1ea1n m\u00e3&#8221; t\u1ef1 \u0111\u1ed9ng b\u1ecb h\u1ebft h\u1ea1n sau m\u1ed9t kho\u1ea3ng th\u1eddi gian nh\u1ea5t \u0111\u1ecbnh, v\u00ec v\u1eady d\u00f9 rolljam c\u00f3 ch\u00e9p l\u1ea1i th\u00ec c\u0169ng kh\u00f4ng x\u00e0i \u0111\u01b0\u1ee3c.<\/p>\n<p>Nh\u01b0 \u0111\u00e3 n\u00f3i, ph\u01b0\u01a1ng ph\u00e1p t\u01b0\u01a1ng t\u1ef1 c\u1ee7a Samy Kamkar t\u1eebng \u0111\u01b0\u1ee3c s\u1eed d\u1ee5ng nhi\u1ec1u, nh\u01b0ng c\u00e1ch c\u1ee7a Samy ti\u00ean ti\u1ebfn h\u01a1n \u1edf ch\u1ed7 b\u1ed9 rolljam kh\u00f4ng c\u1ea7n ph\u1ea3i n\u1ed1i v\u1edbi m\u00e1y t\u00ednh, sau khi \u0111\u00e1nh c\u1eafp \u0111o\u1ea1n m\u00e3, n\u00f3 s\u1eed d\u1ee5ng nh\u01b0 m\u1ed9t c\u00e1i remote m\u1edf c\u1eeda \u0111\u1ed9c l\u1eadp lu\u00f4n. Samy cho bi\u1ebft anh s\u1ebd tr\u00ecnh di\u1ec5n v\u00e0 c\u00f3 th\u1ec3 s\u1ebd c\u00f4ng b\u1ed1 r\u1ed9ng r\u00e3i rolljam tr\u00ean k\u00eanh GitHub v\u00e0o th\u1ee9 S\u00e1u 14\/8 sau khi k\u1ebft th\u00fac DefCon. Samy Kamkar n\u00f3i l\u00e0 v\u1edbi t\u01b0 c\u00e1ch m\u1ed9t chuy\u00ean gia b\u1ea3o m\u1eadt, rolljam c\u1ee7a anh mu\u1ed1n c\u1ea3nh b\u00e1o c\u00e1c h\u00e3ng xe h\u01a1i c\u0169ng nh\u01b0 h\u00e3ng kh\u00f3a c\u1eeda h\u00e3ng n\u00e2ng c\u1ea5p h\u1ec7 th\u1ed1ng b\u1ea3o m\u1eadt c\u1ee7a m\u00ecnh \u0111i, c\u00f3 nh\u1eefng ph\u01b0\u01a1ng ph\u00e1p b\u1ea3o m\u1eadt m\u00e0 m\u00e3 m\u1edf kh\u00f3a s\u1ebd t\u1ef1 \u0111\u1ed9ng h\u1ebft h\u1ea1n n\u1ebfu kh\u00f4ng x\u00e0i ch\u1ec9 trong v\u00f2ng v\u00e0i gi\u00e2y, \u0111i\u1ec3n h\u00ecnh l\u00e0 b\u1ea3o m\u1eadt 2 l\u1edbp c\u1ee7a Google ho\u1eb7c SecurID.<\/p>\n<p style=\"text-align: right;\">Theo Wired\u200b<\/p>\n<p style=\"text-align: right;\">Ngu\u1ed3n tinhte.vn<\/p>\n","protected":false},"excerpt":{"rendered":"<p>T\u1ea1i DefCon 2015 \u0111ang di\u1ec5n ra t\u1eeb ng\u00e0y 6 &#8211; 9\/8 \u1edf Las Vegas (m\u1ed9t trong nh\u1eefng h\u1ed9i ngh\u1ecb hacker l\u1edbn nh\u1ea5t th\u1ebf gi\u1edbi t\u1ed5 ch\u1ee9c h\u00e0ng n\u0103m), chuy\u00ean gia b\u1ea3o m\u1eadt Samy Kamkar \u0111\u00e3 gi\u1edbi thi\u1ec7u b\u1ed9 c\u00f4ng c\u1ee5 c\u00f3 gi\u00e1 32$ d\u00f9ng \u0111\u1ec3 hack c\u00e1ch m\u1edf kh\u00f3a c\u1eeda c\u00e1c lo\u1ea1i xe h\u01a1i kh\u00f4ng [&hellip;]<\/p>\n","protected":false},"author":17,"featured_media":3527,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[47],"tags":[],"class_list":["post-3526","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tin-tuc"],"_links":{"self":[{"href":"https:\/\/casta.ttud.com.vn\/index.php\/wp-json\/wp\/v2\/posts\/3526","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/casta.ttud.com.vn\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/casta.ttud.com.vn\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/casta.ttud.com.vn\/index.php\/wp-json\/wp\/v2\/users\/17"}],"replies":[{"embeddable":true,"href":"https:\/\/casta.ttud.com.vn\/index.php\/wp-json\/wp\/v2\/comments?post=3526"}],"version-history":[{"count":1,"href":"https:\/\/casta.ttud.com.vn\/index.php\/wp-json\/wp\/v2\/posts\/3526\/revisions"}],"predecessor-version":[{"id":3528,"href":"https:\/\/casta.ttud.com.vn\/index.php\/wp-json\/wp\/v2\/posts\/3526\/revisions\/3528"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/casta.ttud.com.vn\/index.php\/wp-json\/wp\/v2\/media\/3527"}],"wp:attachment":[{"href":"https:\/\/casta.ttud.com.vn\/index.php\/wp-json\/wp\/v2\/media?parent=3526"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/casta.ttud.com.vn\/index.php\/wp-json\/wp\/v2\/categories?post=3526"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/casta.ttud.com.vn\/index.php\/wp-json\/wp\/v2\/tags?post=3526"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}