|
|
Message-ID: <CAOJKFBBgP_ixci3K0=EdoXXk91=sLD-K5KYNDmYVVnKhYWeeRA@mail.gmail.com>
Date: Mon, 7 Jul 2025 12:38:50 -0500
From: Brandon Perry <bperry.volatile@...il.com>
To: oss-security@...ts.openwall.com
Subject: Electric Charger Research
Attached is a write-up of some research I've been doing since November last
year. The research covers the digital protocols used from an electric
vehicle -> charger (ISO-15118) and the protocols used to manage the charger
from a central management system (OCPP). I also cover some of the equipment
I've used to do the research.
tl;dr - Your vehicle charger port or EVSE charger cable is functionally a
network interface utilizing powerline communication over the control pilot
pin. Using a development kit for electric vehicle and charger research, I
showed how SSH can be configured to listen on the charger cable
accidentally, allowing a vehicle to initiate the network and authenticate
to the SSH server over the charger cable.
I also demonstrate two separate issues affecting open source CSMS
implementations, one a full denial of service, the other partial DoS.
You can also find this HTML file here: https://ocpp.us/howto.html
I hope this helps others. Thanks.
Content of type "text/html" skipped
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.