Well, this is neat: Malware activity from Autel scantool

OVERKILL

$100 Site Donor 2021
Joined
Apr 28, 2008
Messages
58,096
Location
Ontario, Canada


The pics he posted, calling home to China:

1710693877171.jpg

1710693886524.jpg


The tool:
1710693917141.jpg


And his statement:
I don’t buy the clone stuff. This wasn’t cheap and from a reputable supplier

As I've been saying recently, it's only going to get worse as cyberthreats get more complex and "smart devices", as well as connected electronics, often coming from China, become more prolific.
 
Well known that a lot of CCP IC's have this functionality built in to them. Completely possible that Autel has nothing to do with it. However anyone that uses a CCP chip knows this. This is why they continue to put varios sanctions on CCP chip manufacture in the name of homeland security. It is in fact a threat.
 
Well known that a lot of CCP IC's have this functionality built in to them. Completely possible that Autel has nothing to do with it. However anyone that uses a CCP chip knows this. This is why they continue to put varios sanctions on CCP chip manufacture in the name of homeland security. It is in fact a threat.
Yup, exactly.

Also, for those who might be wary of the source, Daniel Cuthbert is:
Blackhat/Brucon Review Board & UK Government Cyber Security Advisory Board
This isn't some nobody posting nonsense on twitter for the lul's, he's an SME.

Slight tangent, but the device he's using for his home firewall is "Firewalla", who sell complete solutions at pretty reasonable prices:
Firewalla Products | Firewalla

Pretty comparable price-wise to Ubiquiti.
 
Slight tangent, but the device he's using for his home firewall is "Firewalla", who sell complete solutions at pretty reasonable prices:
Firewalla Products | Firewalla

I considered purchasing a Firewalla before I built my OPNsense box. I decided on the DIY route because it was less expensive and my primary reason at the time was to learn about firewalls and networking.
I think I came in under $150 by purchasing a used computer from Goodwill and a Ruckus access point and network card from Ebay.
 
I had a Chinese robot vacuum. It stayed in constant communication with mainland China according to the DNS logs on my firewall.
 
Kinda on/off topic but @OVERKILL or anyone else, do you all know of any open source or even maybe subscription service products that you could spin up on a VM and watch/filter traffic in and out of your network? Beyond an adblocker like Pihole.

Is Alienvault still relevant?
 
Kinda on/off topic but @OVERKILL or anyone else, do you all know of any open source or even maybe subscription service products that you could spin up on a VM and watch/filter traffic in and out of your network? Beyond an adblocker like Pihole.

Is Alienvault still relevant?
Sounds like you want a transparent firewall?

Not going transparent, you can achieve that on the perimeter with PFsense/OPNsense and ntopng, unless you are looking for even more detailed information than it provides?

 
Kinda on/off topic but @OVERKILL or anyone else, do you all know of any open source or even maybe subscription service products that you could spin up on a VM and watch/filter traffic in and out of your network? Beyond an adblocker like Pihole.

Is Alienvault still relevant?
Should also add, this is the detail my UDM SE provides (beyond my PiHole):
Screen Shot 2024-03-17 at 3.12.58 PM.jpg

Screen Shot 2024-03-17 at 3.13.34 PM.jpg
 
Back
Top