Tuesday, November 19, 2024
HomeHacksGPS Tracking Apps Flaw Let Hackers Remotely Hijack the Car & Kill...

GPS Tracking Apps Flaw Let Hackers Remotely Hijack the Car & Kill Engines to Create a Traffic Jam

Published on

A critical security flaw in GPS Tracking Apps that allows remote hackers to hijack the car and kill the engine while the car moving on the road.

A Hacker who reportedly shared details with Motherboard that he broke into thousands of accounts belonging to users of two GPS tracker apps
 iTrack and ProTrack.

He compromised more than 7,000 iTrack accounts and more than 20,000 ProTrack accounts that managed by the respective car owners to
use to monitor and manage fleets of their vehicles through GPS tracking devices.

- Advertisement - SIEM as a Service

Protrack is a professional Web-based GPS tracking software. A lot of customers from all over the world are using this software to provide live tracking service to the car owners.

iTrack is another app that provides GPS Tracking Security Systems, GPS Security System India, vehicle tracking system, vehicle protection, fleet management system.

Due to the critical security bug in both GPS tracking apps, he brute-forced “millions of usernames” via the apps’ API. Then, he said he wrote a script to attempt to login using those usernames and the default password.

This Flaw let the hacker to automatically break into thousands of accounts who all are using the default password.

Also, the hacker claims that he can track vehicles in some many countries around the world, including South Africa, Morocco, India, and the Philippines.

The hacker shared the alot more information to Motherboard including, name and model of the GPS tracking devices they use, the devices’ unique ID numbers (technically known as an IMEI number); usernames, real names, phone numbers, email addresses, and physical addresses. (According to L&M, he was not able to get all of this information for all users; for some users he was only able to get some of the above information.)

This data breach legitimacy was checked by the motherboard with some of the users and confirmed that the data provided by the hackers was completely original.

Hacker was never tried to kill any cars engine and he didn’t provide any evidence that he can do that. but one of the hardware GPS maker said “customers can turn off the engines remotely if the vehicles are going under 20 kilometers per hour”

GPS Tracking Apps


“My target was the company, not the customers. Customers are at risk because of the company,” L&M told Motherboard in an online chat. “They need to make money, and don’t want to secure their customers.” Hacker said.

ProTrack denied the data breach via email, but confirmed that its prompting users to change passwords.

“Our system is working very well and change password is normal way for account security like other systems, a company representative said.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Also Read:

PASTA – A New Car Hacking Tool Developed by Toyota to Test The Security Vulnerabilities

Modern Cars are Vulnerable to Hacking and Malware Attack

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Phobos Ransomware Admin as Part of International Hacking Operation

The U.S. Department of Justice unsealed criminal charges today against Evgenii Ptitsyn, a 42-year-old Russian...

Maxar Space Data Leak, Threat Actors Gain Unauthorized Access to the System

Maxar Space Systems, a leader in space technology and Earth intelligence solutions, has recently...

Apache Kafka Vulnerability Let Attackers Escalate Privileges

A newly identified vulnerability tracked as CVE-2024-31141, has been discovered in Apache Kafka Clients that could allow...

Zohocorp ManageEngine ADAudit Plus SQL Injection Vulnerability

Zohocorp, the company behind ManageEngine, has released a security update addressing a critical SQL...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Crypto Network Security: Essential Tips To Protect Your Digital Assets In 2023 

Exploring the world of cryptocurrencies has been a thrilling journey for me. The allure...

New RansomHub Attack Killing Kaspersky’s TDSSKiller To Disable EDR

RansomHub has recently employed a novel attack method utilizing TDSSKiller and LaZagne, where TDSSKiller,...

Chinese Hackers Using Open Source Tools To Launch Cyber Attacks

Three Chinese state-backed threat groups, APT10, GALLIUM, and Stately Taurus, have repeatedly employed a...