Smart Tractor Retrofit Systems: Architecture and Attack Surface

▶ Watch (02:40)

The FGD Dynamics retrofit kit costs $5,000-$10,000 and turns any tractor into an automated machine. A tablet, a motorized steering wheel, and a GPS antenna are all it takes. The system communicates GPS position and control commands via HTTPS and MQTT to a cloud broker hosted in China. A Bluetooth remote adds another wireless surface.

FGD and FAMO look like competing brands. They are the same hardware. That single fact meant every vulnerability Felix and Bernhard found applied across two of the most widely sold automation systems in central Europe.

Breaking MQTT Authentication: From One Device to 40,000

▶ Watch (06:36)

The device encrypted MQTT traffic with TLS but validated none of the server certificates. Redirecting to a netcat socket dumped credentials in plaintext. All devices shared the same username and a two-character password: “2020.”

“Well turns out two characters did the trick.” — Bernhard

An MQTT multi-level wildcard (#) subscribed to every topic at once. The traffic volume crashed their machine, so they built TTOR to handle 100k messages per second. In the lock command broadcast demo (15:40), one broker message locks every connected tractor and only the vendor can restore it.

Mass GPS Surveillance: Field Patterns, Farmers’ Lives, and a War Zone

▶ Watch (12:34)

Over several months of passive broker access, they tracked roughly 40,000 systems. Most operate in Asia, with around 50,000 in the European Union and 300 in the United States. The data includes GPS traces of every field operation, home locations, IP addresses, and sometimes email addresses shared when farmers collaborate on a field.

One device was active 20 kilometers from the front line in Ukraine at 3 a.m. Tractors near the North Korean border appeared as well. GPS anomalies close to Ukraine showed devices scattered wildly, consistent with active jamming.

Remote Root via Unsigned OTA Update

▶ Watch (19:23)

The HMI tablet is a locked-down Android device, but bypassing the lockdown required one key press and a USB-C cable. The vendor’s own code needed root access, shipped the su binary pre-installed, and left the device rooted.

“And in this case they just use MD5.” — Bernhard

The OTA update mechanism had no transport encryption and no asymmetric signature, just an MD5 checksum. A man-in-the-middle swaps the update URL for any binary and recalculates the hash. The Meterpreter root shell via spoofed OTA (21:46) shows the full chain: intercept, serve a malicious APK, receive a root shell.

Steering Hijack, Lawnmower Camera Feeds, and Elevator Robots

▶ Watch (25:04)

The ECU is a 200-kilobyte ARM binary with no symbols. Bernhard found the packet handler by looking for dense conditionals and magic bytes, reversed the protocol, and confirmed that steering requires a heartbeat, a waypoint, and an execute packet in sequence. The steering wheel hijack demo (25:50) shows the motor overpowering the driver’s hands.

The same broken broker also served lawnmowers with cameras and indoor robots that open doors and call elevators.

“Well, talk about scope grip.” — Felix Eberstaller

The lawnmower camera feed access demo (27:47) pulled live video from unsigned cloud buckets across multiple continents.

Q&A

Is the vendor here today? Felix said he did not think so, then clarified that the vendor had said in May that everything was fixed but had not actually resolved the security issues, and the CEO only learned of the vulnerabilities two weeks before Black Hat due to internal miscommunication. ▶ 31:25

Can you refine steering wheel control beyond a point-to-point waypoint? In theory yes, but for the demo they only implemented waypoint-to-waypoint and said full continuous steering control was close but never completed. ▶ 32:59

What does the MQTT broker provide, and can the system run without it? The broker supports fleet management and field-operation tracking; tractors can run offline if maps are pre-loaded, but most farmers stay connected for the data features. ▶ 33:27

Notable Quotes

Well turns out two characters did the trick. Bernhard · ▶ 11:07

And in this case they just use MD5. Bernhard · ▶ 20:01

Well, talk about scope grip. Felix Eberstaller · ▶ 27:43

Key Takeaways

  • A shared two-character password and an MQTT wildcard exposed 40,000 farming automation devices to any attacker with the client certificate.
  • The HMI tablet ships pre-rooted and accepts OTA updates verified only by MD5, enabling remote root via a man-in-the-middle attack.
  • The same broker controls lawnmowers with open camera feeds and indoor robots that operate elevators and doors, extending the blast radius far beyond agriculture.