Millions of KIA vehicles could be hacked & tracked due to website bug

Was this actually exploited, or just a possibility stemming from a vulnerability or misconfiguration?
The group who alerted KIA to it didn't indicate whether it was being exploited in the wild or not, but it wasn't a complex exploit either. KIA hasn't commented and refused to respond to wired, so it appears to be unknown as to that status.
 
Sheer guess once you are in with any credentials you can call their API with a key built out of license plate and state and retrieve data. It might not be completely obvious however they figured out the pattern which must be simple.

It requires you know what you doing/reading not like you are using site as the owner of car….

Reminds me of that first version of knock off twitter called TruthSocial. Once in you could get any data you pleased.
 
  • Haha
Reactions: D60
Back
Top Bottom