{"id":14492,"date":"2020-05-20T07:08:22","date_gmt":"2020-05-20T05:08:22","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=14492"},"modified":"2021-10-12T12:25:00","modified_gmt":"2021-10-12T10:25:00","slug":"security-incident-source-code-for-mercedes-olu-leaked","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2020\/05\/20\/security-incident-source-code-for-mercedes-olu-leaked\/","title":{"rendered":"Security incident: Source Code for Mercedes OLU leaked"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2015\/01\/Schutz.jpg\" width=\"40\" align=\"left\" height=\"47\">[<a href=\"https:\/\/www.borncity.com\/blog\/2020\/05\/20\/sicherheitsvorfall-mercedes-olu-software-abgreifbar\/\" target=\"_blank\" rel=\"noopener noreferrer\">German<\/a>]There has been a security incident at Mercedes Benz. A Swiss engineer found a GitLab server where he could create an account and then access the source code of onboard logic units (OLUs). These OLUs are built into the new 'Smart Car' models of the Mercedes-Benz VANs (Vito, eVito) and allow the use of Daimler digital services. <\/p>\n<p><!--more--><\/p>\n<h2>Mercedes-Benz: Digitalization in transport sector<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" src=\"https:\/\/vg04.met.vgwort.de\/na\/781c931c2a1d40b19398ed3fe103aba3\" width=\"1\" height=\"1\">First a few words about OLUs. Onboard Logic Units (OLUs) are electronic control units that are also used in Mercedes-Benz vehicles (Smart Car). Mercedes Benz VANS describes their purpose in the project 'Digitalization in the transport sector' in <a href=\"https:\/\/web.archive.org\/web\/20201127143525\/https:\/\/blog.mercedes-benz-passion.com\/2019\/10\/mercedes-benz-vans-treibt-digitalisierung-im-transportsektor-voran\/\" target=\"_blank\" rel=\"noopener noreferrer\">this German blog post<\/a>. There they wrote:<\/p>\n<blockquote>\n<p>The current generation of the Sprinter (VANs) came onto the market as a fully networked vehicle just over a year ago. With it &#8211; and now also with the Vito and eVito models &#8211; the Mercedes PRO connect services can be used. <\/p>\n<\/blockquote>\n<p>The networking solution from Mercedes-Benz enables customers to control orders online and to request vehicle information such as location, tank level or maintenance intervals in almost real time. Among other things, transport companies can reduce downtimes through forward-looking maintenance and repair management. At the same time, Mercedes-Benz also enables a business management analysis of the fleet. According to the blog post, fleet operators from small businesses to major customers use the services of Mercedes PRO. In July 2019 almost every second new Sprinter customer had activated one or more services.<\/p>\n<h2>Access to the source code<\/h2>\n<p>Daimler has stored the source code of&nbsp; the software for this onboard logic units on a GitLab server so that developers can access it. <\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">A Swiss software engineer found the server using Google dorks and then registered an account &#8212; because Daimler didn't limit the registration process to Daimler corporate emails.<\/p>\n<p>He then downloaded 580 of Daimler's OLU repos. <a href=\"https:\/\/t.co\/9oxbqS3PqT\">pic.twitter.com\/9oxbqS3PqT<\/a><\/p>\n<p>\u2014 Catalin Cimpanu (@campuscodi) <a href=\"https:\/\/twitter.com\/campuscodi\/status\/1262392263596007426?ref_src=twsrc%5Etfw\">May 18, 2020<\/a><\/p><\/blockquote>\n<p><span id=\"preserveb3e9cf5e302b496ea4a3bceabb79ba45\" class=\"wlWriterPreserve\"><SCRIPT charset=\"utf-8\" src=\"https:\/\/platform.twitter.com\/widgets.js\" async><\/SCRIPT><\/span> <\/p>\n<p>Apparently, the Daimler people made a mistake in securing the GitLab server. <a href=\"https:\/\/www.zdnet.de\/88379887\/mercedes-benz-verliert-quellcode-von-smart-car-komponenten\/\" target=\"_blank\" rel=\"noopener noreferrer\">Till Kottmann<\/a> is a software developer from Switzerland. He came across the Daimler GitLab server via 'Google Dorks' and discovered that the administrators had not limited the registration of new accounts to e-mail addresses of Daimler employees.&nbsp; <\/p>\n<p>According to him, this enabled him to create his own account at the Git-Web portal of the Mercedes-Benz parent company Daimler. He could then access the source code repository. There he found the source code of more than 580 Git repositories, which he downloaded. <\/p>\n<p>Among them was the source code of the Onboard Logic Units (OLUs) that are installed in Daimler vehicles. The OLUs are supposed to connect the vehicles 'with the cloud'. Among other things, this involves tracking vehicles, or deactivating a stolen vehicle. An article from ZDNet with more details can be found <a href=\"https:\/\/www.zdnet.com\/article\/mercedes-benz-onboard-logic-unit-olu-source-code-leaks-online\/\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]There has been a security incident at Mercedes Benz. A Swiss engineer found a GitLab server where he could create an account and then access the source code of onboard logic units (OLUs). These OLUs are built into the new &hellip; <a href=\"https:\/\/borncity.com\/win\/2020\/05\/20\/security-incident-source-code-for-mercedes-olu-leaked\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580],"tags":[69],"class_list":["post-14492","post","type-post","status-publish","format-standard","hentry","category-security","tag-security"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/14492","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=14492"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/14492\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=14492"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=14492"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=14492"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}