Hardware Reverse and Firmware Extraction

▶ Watch (3:22)

Erazo began by disassembling the Kia Gen5WB head unit (FCC ID: not given). The board uses an unknown system-on-chip (TMM 92000), a CAN microcontroller, EEPROM, and two SPI flash chips. One 2 MB chip holds the factory reset binary. The second flash contains the full firmware. Erazo dumped both chips and discovered UART access on the back of the board. He soldered headers and began reversing the boot process. Binwalk returned false positives, so he did manual extraction using PNG and JPEG magic bytes. The firmware revealed 110 real‑time operating system tasks.

Vulnerability: 882 PNG Files Without Integrity Checks

▶ Watch (14:41)

The boot chain has secure boot for the first‑stage ROM loader and cryptographic integrity checks for the second‑stage bootloader and the main RTOS binary. But Erazo found that after the RTOS loads the 882 PNG files from flash into RAM, it runs no hash or signature verification on those images. The libpng library only validates CRC and chunk headers. He patched a single PNG in the firmware, replaced it with a “HACK” image, and the head unit booted and displayed the altered graphic. The same size requirement applies: the replacement must match the original pixel dimensions and file‑offset alignment.

QR Phishing Attack and Android Malware Demo

▶ Watch (18:52)

Erazo targeted the in‑car QR code that displays the Kia user manual. He crafted a replacement QR image that points to a phishing domain (revisit.com) instead of the official Kia site. The phishing page mimics Kia’s interface and offers a “Kia official app” download. That APK contains a backdoor with command‑and‑control access. In the live demo, a phone scanned the malicious QR, downloaded the APK, and installed it. Erazo then showed a remote shell dumping SMS, location, and contacts from the Android 14 phone. The attack vectors are USB (via a drive‑by download) or physical firmware flashing.

Key Takeaways

  • The Kia Gen5WB head unit lacks integrity checks on its 882 embedded PNG images.
  • Replacing any image is possible if it matches the original size and offset.
  • The QR phishing chain used a modified QR to install a backdoored Android APK.
  • Erazo will release his PNG manipulation tool after DEF CON.

Notable Quotes

we have here the most elaborated QR fishing in the automative war Danilo Erazo · ▶ 17:43

I have access to the cell phone to you know h location contacts and cm is um recording the microphone this is very danger Danilo Erazo · ▶ 23:03