Well that's not good.....Infotainment System Hacks on CX-5 2017

:
2017 Mazda CX-5 GT
So I decided to hack my 2017 CX-5 GT this afternoon. I just want to disable the touch screen locking, and replace the background image.

I used the same setup as with my 2016 Mazda3.

I have a backup home router just in case my main ever goes bad. Hooked up my SurfacePro4 and the CX-5 to it.

Connection1.PNG



Connection Looks Good. 192.168.1.2 is the Mazda

Connection3.PNG


Well crap.

I did a port scan just to see if mazda left any other port open.

Connection2.PNG



I also tried rebooting everything and tried connecting as soon as the car was turned on thinking that maybe they disable it after 30 seconds or something. No joy. I'm willing to admit there is a possibility its something I'm doing on my end, but I don't think so.

I'm suspecting that Mazda has made some changes to the system.
 
Why are you trying it that way? Did you try the AIO method of loading from a Memory Stick?

Sent from my XT1585 using Tapatalk
 
Why are you trying it that way? Did you try the AIO method of loading from a Memory Stick?

Sent from my XT1585 using Tapatalk

Because I'm not using any automated scripts that may or may not work on this system. I know linux and would rather edit the 2 files and use WinSCP to replace the screen.
 
It works pretty well. It checks your system and if it's not a version known to work it lets you abort.

Sent from my XT1585 using Tapatalk
 
I'd probably do a full range port scan just to make sure they didn't put SSH on some high non-standard port. Not likely but I'd check anyway.
 
I didn't think the new car was supported for the tweaks.
Mazda have clamped down now on any diy software downloads for the MZD, so the latest versions are not available on the "tweak" sites.

I haven't got a clue what you chaps are showing above with the ports etc, you are very clever, I grew up with a ZX spectrum and a slide rule!
 
While the tweaking implications aren't good (for now, anyway), it's probably a good thing for security. I'm not familiar with the old 'hack' process, but the ability to easily connect wirelessly and 'hack' the system couldn't have been good for security.
 
How secure does a headunit need to be?

Sent from my XT1585 using Tapatalk
 
How secure does a headunit need to be?

Sent from my XT1585 using Tapatalk

Considering there's often minimal security in and between systems within cars... I'd prefer a very secure headunit. Theoretically the entertainment system can't talk to the safety systems, but in reality the line is probably more blurred than we'd like to believe across all manufacturers.
 
and i'd like to believe anyone wanting to hack a HU would probably try to attack a brand that has more then 3% market share. :) lol
 
Considering there's often minimal security in and between systems within cars... I'd prefer a very secure headunit. Theoretically the entertainment system can't talk to the safety systems, but in reality the line is probably more blurred than we'd like to believe across all manufacturers.

and i'd like to believe anyone wanting to hack a HU would probably try to attack a brand that has more then 3% market share. :) lol

Agreed Joe.

And yeah, you have a point 7. People liked to pretend Mac was impervious to viruses, when the reality is that Windows just happens to still be 90% of the market share and Mac is less than 10%. If that was the opposite, you'd better believe Mac would have just as many.
 
Huh. I'm surprised there's a wireless connection for the HU. Why? Would this be the latent "real time traffic" that 7 mentioned looked was lurking (and eating up people's cellphone data plan)? I can't imagine they'd want ports open for traffic. Also there are plenty of ports beyond 1021.
 
What is the version number of the software? Is it different then the last 59 that just came out?

Sent from my XT1585 using Tapatalk
 
Huh. I'm surprised there's a wireless connection for the HU. Why? Would this be the latent "real time traffic" that 7 mentioned looked was lurking (and eating up people's cellphone data plan)? I can't imagine they'd want ports open for traffic. Also there are plenty of ports beyond 1021.

I think you can rest easy. If and when the U.S. gets Live Traffic, the data used is not very much. I use my CX5 for 20 days out of every month and the most I have seen it use is 50MB maximum total in a month. My SIM Free phone plan is only 250MB. (I know, I know... It IS cheap):eek:

Just for comparison, I presume the Stitcher and Aha MZD Apps would use more data?

Jonno21
 
Back