• Log In
  • Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • HomePage
  • Instructor
  • Syllabus
  • Schedule
    • First Half of the Semester
      • Week 1: Course Introduction
      • Week 2: Meterpreter, Avoiding Detection, Client Side Attacks, and Auxiliary Modules
      • Week 3: Social Engineering Toolkit, SQL Injection, Karmetasploit, Building Modules in Metasploit, and Creating Exploits
      • Week 4: Porting Exploits, Scripting, and Simulating Penetration Testing
      • Week 5: Independent Study – Perform Metasploit Attack and Create Presentation
      • Week 6: Ettercap
      • Week 7: Introduction to OWASP’s WebGoat application
    • Second Half of the Semester
      • Week 8: Independent Study
      • Week 9: Introduction to Wireless Security
      • Week 10: Wireless Recon, WEP, and WPA2
      • Week 11: WPA2 Enterprise, Wireless beyond WiFi
      • Week 12: Jack the Ripper, Cain and Able, Delivery of Sample Operating Systems
      • Week 13: Independent Study – Analyze provided Operating System Samples and Create Assessment Report
      • Week 14: Deliver Assessment to Operating System Class either in person or via teleconferenc
  • Assignments
    • Analysis Reports
    • Group Project Report and Presentation
  • Webex
  • Harvard Coursepack
  • Gradebook

MIS 5212-Advanced Penetration Testing

MIS 5212 - Section 001 - Wade Mackey

Fox School of Business

Insecure Android apps put connected cars at risk

February 19, 2017 by Ahmed A. Alkaysi 1 Comment

In this article, it is discussed how many of the Android apps that are used to locate and unlock their vehicles are missing many security features. Some of these features include: obfuscation, which is used to make it harder for hackers to reverse engineer the code, code integrity checks, encryption of credentials, and a check to see if the phone is running rooted. Another security flaw is a lack of check to see if there is an overlay on top of the app that displays a fake login, used to expose the login credentials.

The article states that while these types of apps might not enable theft, it could make the job easier. Some of the apps have the ability to unlock the car and disable the alarms. Also, per Kaspersky, “Accessing the car and deliberate tampering with its elements may lead to road accidents, injuries, or death.” As cars become more connected and transitioning to be an IoT, security will become paramount.

http://www.csoonline.com/article/3171671/security/insecure-android-apps-put-connected-cars-at-risk.html

Filed Under: Week 05 Tagged With:

Reader Interactions

Comments

  1. Mauchel Barthelemy says

    February 26, 2017 at 8:17 am

    I’m not sure if this is either more of a Google’s Android issue or a developer one. Regardless what is, all parties involved should play their part to resolve this issue. Like I always say, the key here will be to work together. Together is stronger, and in turn stronger is better against hacking. The Android team will need to reinforce the process of approving Apps. Force developers to follow proper security procedures to protect users. Developers can play their part by not only following strong security protocols, but also focus on adopting a security mindset when coding. Users can contribute to this by disciplined themselves to report anything suspicious.

    Log in to Reply

Leave a Reply Cancel reply

You must be logged in to post a comment.

Primary Sidebar

Weekly Discussions

  • Uncategorized (35)
  • Week 01 (2)
  • Week 02 (14)
  • Week 03 (13)
  • Week 04 (10)
  • Week 05 (7)
  • Week 06 (29)
  • Week 07 (8)
  • Week 08 (1)
  • Week 09 (6)
  • Week 10 (12)
  • Week 11 (7)
  • Week 12 (4)
  • Week 13 (6)
  • Week 14 (18)

Copyright © 2025 · Magazine Pro Theme on Genesis Framework · WordPress · Log in