Zero Days: Electric Motorcycles are a Security Nightmare · PersephoneKarnstein.github.io
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
A detailed security research writeup exposing critical vulnerabilities in Zero Motorcycles electric bikes. Researchers reverse-engineered the Android app using JADX and Frida, extracted hardcoded credentials from the app's BuildConfig, downloaded firmware from the OTA server using a fake VIN, and discovered the firmware uses
Table of contents
Depotting AttemptsAndroid AppFirmwareAttacksFridaCAN BusMalicious FirmwareWorst Case ScenariosA C2 for your MotorcycleStuxnet for your MotorcycleDisclosure Attempts and the LawDisclosure AttemptsDisclosure Success!LegalSort: