How Invite-Only Registration Falls to Client-Side Patches

▶ Watch (5:04)

The dealer software required an invite token for registration. Eaton revealed the hidden registration form using Chrome DevTools. The server accepted blank invite tokens, creating accounts without verification. A secondary step needed dealer admin approval. Checking a profile update checkbox during login established a valid session. That session loaded admin JavaScript files previously unobtainable, including user creation scripts. The site took a minute to load because of hundreds of scripts.

National Admin Access via Missing Server-Side Checks

▶ Watch (8:38)

Eaton used Chrome local overrides to patch two client-side checks. He commented out a popup requiring a valid dealer code. He modified the redirect function to return an empty string instead of blocking navigation. The admin user creation page loaded and showed a create button with a national access option. The server verified the invite token but never checked if the caller had admin privileges. The new national admin account granted root access to all 1,700 dealerships.

Car Takeover Through Dealer Enrollment Abuse

▶ Watch (13:23)

The enrollment system pairs owners to their cars for mobile app control. Eaton created a consumer account, then used the dealer enrollment tool to transfer a friend’s car by entering the VIN. The system assumed dealers had verified identity and ownership. The friend confirmed Eaton could start the engine, unlock doors, and honk the horn through the manufacturer’s app. Cars never linked to a mobile account were vulnerable to silent takeover with no notification sent.

Lateral Movement Across Brands and Third-Party Systems

▶ Watch (18:57)

The luxury sub-brand used the same dealer software on a different domain. The invite exploit worked, but national admin creation failed with an obscure error. Eaton found a user impersonation tool that let corporate users log in as any dealer employee, bypassing two-factor authentication without notification. By impersonating a high-privilege employee who worked for both brands, he used SSO system IDs to pivot into the luxury sub-brand’s dealer network.

Blast Radius: PII, Telematics, and Financial Data

▶ Watch (22:45)

The national admin account provided SSO access to third-party systems. The TSD rental platform exposed driver’s license numbers, insurance policies, and addresses for all customers. A telematics dashboard showed real-time car locations. The freight tracking system monitored 400,000 in-transit cars and offered cancel or reroute options. Finance contracts, employee Social Security numbers, and customer leads from a million surveys were all accessible.

Notable Quotes

unlocking your car was really just the tip of the iceberg as to what I could do Eaton Zveare · ▶ 0:43

the server doesn’t check it. It could be blank. Eaton Zveare · ▶ 5:40

I could do this for any car I found in the wild, not just my friends. Eaton Zveare · ▶ 15:38

I consider it a Christmas gift Eaton Zveare · ▶ 2:43

Key Takeaways

  • Two server-side vulnerabilities exposed 1,700+ dealerships to full compromise.
  • Any 2012+ model car from this manufacturer could be remotely taken over.
  • Dealers store extensive PII including SSNs, licenses, and financial contracts.

About the Speaker(s)

Eaton Zveare is a senior security research engineer at Traceable by Harness. As a member of the ASPEN Labs team, he has contributed to the security of some of the world’s largest organizations by finding and responsibly disclosing many critical vulnerabilities. He is best known for his high-profile security disclosures in the automotive space.

Roshan Piyush leads Security Research at Traceable by Harness, where he also oversees Aspen Labs. With over a decade of experience in cybersecurity and a recent focus on API security, Roshan researches detection and prevention techniques across CI/CD pipelines, software supply chains, runtime environments, and cloud-native architectures. He has been involved with projects like OWASP crAPI and Coraza WAF.