{"id":62137,"date":"2022-03-30T11:04:40","date_gmt":"2022-03-30T13:04:40","guid":{"rendered":"https:\/\/teknomers.com\/fr\/le-bogue-dacces-sans-cle-de-honda-pourrait-permettre-aux-voleurs-de-deverrouiller-et-de-demarrer-les-vehicules-a-distance\/"},"modified":"2022-03-30T11:04:45","modified_gmt":"2022-03-30T13:04:45","slug":"le-bogue-dacces-sans-cle-de-honda-pourrait-permettre-aux-voleurs-de-deverrouiller-et-de-demarrer-les-vehicules-a-distance","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/le-bogue-dacces-sans-cle-de-honda-pourrait-permettre-aux-voleurs-de-deverrouiller-et-de-demarrer-les-vehicules-a-distance\/","title":{"rendered":"Le bogue d&#8217;acc\u00e8s sans cl\u00e9 de Honda pourrait permettre aux voleurs de d\u00e9verrouiller et de d\u00e9marrer les v\u00e9hicules \u00e0 distance"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both\"><\/div>\n<p>Un duo de chercheurs a publi\u00e9 une preuve de concept (PoC) d\u00e9montrant la capacit\u00e9 d&#8217;un acteur malveillant \u00e0 verrouiller, d\u00e9verrouiller et m\u00eame d\u00e9marrer \u00e0 distance des v\u00e9hicules Honda et Acura au moyen de ce qu&#8217;on appelle une attaque par relecture.<\/p>\n<p>L&#8217;attaque est rendue possible, gr\u00e2ce \u00e0 une vuln\u00e9rabilit\u00e9 dans son syst\u00e8me sans cl\u00e9 \u00e0 distance (<a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-27254\" target=\"_blank\">CVE-2022-27254<\/a>) qui affecte les mod\u00e8les Honda Civic LX, EX, EX-L, Touring, Si et Type R fabriqu\u00e9s entre 2016 et 2020. Ayyappan Rajesh, \u00e9tudiant \u00e0 UMass Dartmouth, et Blake Berry (HackingIntoYourHeart) sont cr\u00e9dit\u00e9s d&#8217;avoir d\u00e9couvert le probl\u00e8me.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/mset2\" target=\"_blank\" title=\"Automatic GitHub Backups\"><img loading=\"lazy\" decoding=\"async\" alt=\"Sauvegardes GitHub automatiques\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/02\/Le-celebre-gang-de-logiciels-malveillants-TrickBot-ferme-son-infrastructure.png\" width=\"300\" height=\"250\" \/><\/a><\/div>\n<p>&#8220;Un pirate informatique peut obtenir un acc\u00e8s complet et illimit\u00e9 au verrouillage, au d\u00e9verrouillage, au contr\u00f4le des fen\u00eatres, \u00e0 l&#8217;ouverture du coffre et au d\u00e9marrage du moteur du v\u00e9hicule cible o\u00f9 le seul moyen d&#8217;emp\u00eacher l&#8217;attaque est de ne jamais utiliser votre t\u00e9l\u00e9commande ou, apr\u00e8s avoir \u00e9t\u00e9 compromis (ce qui serait difficile \u00e0 r\u00e9aliser), en r\u00e9initialisant votre t\u00e9l\u00e9commande chez un concessionnaire&#8221;, Berry <a rel=\"nofollow noopener\" href=\"https:\/\/github.com\/HackingIntoYourHeart\/Unoriginal-Rice-Patty\" target=\"_blank\">expliqu\u00e9<\/a> dans un article GitHub.<\/p>\n<p>Le probl\u00e8me sous-jacent est que le porte-cl\u00e9s \u00e0 distance des v\u00e9hicules Honda concern\u00e9s transmet le m\u00eame signal de radiofr\u00e9quence non crypt\u00e9 (433,215 MHz) \u00e0 la voiture, permettant ainsi \u00e0 un adversaire d&#8217;intercepter et de rejouer la demande ult\u00e9rieurement pour d\u00e9marrer le moteur sans fil comme ainsi que verrouiller et d\u00e9verrouiller les portes.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/cs-feb-header\" target=\"_blank\" title=\"Prevent Data Breaches\"><img loading=\"lazy\" decoding=\"async\" alt=\"Emp\u00eacher les violations de donn\u00e9es\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/03\/1647417170_810_Facebook-frappe-dune-amende-de-186-millions-de-dollars-GDPR.jpeg\" width=\"728\" height=\"90\" \/><\/a><\/div>\n<p>Ce n&#8217;est pas la premi\u00e8re fois qu&#8217;un d\u00e9faut de ce genre est d\u00e9couvert sur des v\u00e9hicules Honda.  Un probl\u00e8me connexe d\u00e9couvert dans les mod\u00e8les Honda HR-V 2017 (<a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2019-20626\" target=\"_blank\">CVE-2019-20626<\/a>score CVSS : 6,5) aurait \u00e9t\u00e9 \u00ab apparemment ignor\u00e9 \u00bb par la soci\u00e9t\u00e9 japonaise, a all\u00e9gu\u00e9 Berry.<\/p>\n<p>&#8220;Les fabricants doivent mettre en place <a rel=\"nofollow noopener\" href=\"https:\/\/en.wikipedia.org\/wiki\/Rolling_code\" target=\"_blank\">Codes roulants<\/a>autrement connu sous le nom de code de saut,&#8221; Rajesh <a rel=\"nofollow noopener\" href=\"https:\/\/github.com\/nonamecoder\/CVE-2022-27254\" target=\"_blank\">mentionn\u00e9<\/a>.  &#8220;Il s&#8217;agit d&#8217;une technologie de s\u00e9curit\u00e9 couramment utilis\u00e9e pour fournir un nouveau code pour chaque authentification d&#8217;un syst\u00e8me d&#8217;entr\u00e9e sans cl\u00e9 \u00e0 distance (RKE) ou d&#8217;entr\u00e9e sans cl\u00e9 passive (PKE).&#8221;<\/p>\n<p>Nous avons demand\u00e9 \u00e0 Honda un commentaire, et nous mettrons \u00e0 jour l&#8217;histoire une fois que nous aurons entendu.<\/p>\n<p><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2022\/03\/hondas-keyless-access-bug-could-let.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Un duo de chercheurs a publi\u00e9 une preuve de concept (PoC) d\u00e9montrant la capacit\u00e9 d&#8217;un acteur malveillant \u00e0 verrouiller, d\u00e9verrouiller et m\u00eame d\u00e9marrer \u00e0 distance des v\u00e9hicules Honda et Acura au moyen de ce qu&#8217;on appelle une attaque par relecture. L&#8217;attaque est rendue possible, gr\u00e2ce \u00e0 une vuln\u00e9rabilit\u00e9 dans son syst\u00e8me sans cl\u00e9 \u00e0 distance [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":62138,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[507,6813,9044,4168,4158,4165,4161,7192,2360,39473,2526,16835,4157,4159,4171,4170,65,4167,4160,4163,4162,5848,2102,1181,4172,4169,351,4166,11956,4164],"class_list":["post-62137","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-aux","tag-bogue","tag-cle","tag-comment-pirater","tag-cyber-actualites","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-dacces","tag-demarrer","tag-deverrouiller","tag-distance","tag-honda","tag-lactualite-de-la-cybersecurite","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-la-securite-des-informations","tag-les","tag-logiciel-malveillant-de-ransomware","tag-mises-a-jour-de-la-cybersecurite","tag-nouvelles-de-piratage","tag-nouvelles-de-pirates","tag-permettre","tag-pourrait","tag-sans","tag-securite-informatique","tag-securite-internet","tag-vehicules","tag-violation-de-donnees","tag-voleurs","tag-vulnerabilite-logicielle"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/62137","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=62137"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/62137\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/62138"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=62137"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=62137"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=62137"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}