Heavy Trucking Telematics Control Module
Challenge
Quickly evaluate a third-party telematics control module for compliance with the customer's security specifications ahead of deployment.
Approach
Applied a five-stage threat modeling methodology (reconnaissance, scanning, gaining access, maintaining access, and covering tracks), using custom attack scripts to exploit poorly implemented encryption in the module's communications.
Outcome
Identified five critical vulnerabilities across network and physical attack vectors, fully compromising the integrity and confidentiality of the system.