Modern Odometer Manipulation - collin & oblivion

Colin

DEF CON 33 · Day 1 · Main Stage

Overview

In this insightful DEF CON talk, Colin delves into the surprisingly straightforward world of modern odometer manipulation. Challenging the common assumption that digital odometers are tamper-proof, he reveals how readily available devices can prevent mileage from accumulating, effectively devaluing used cars and defrauding warranty and lease providers. The presentation meticulously details the reverse engineering of one such device, exposing its core functionality: a simple modification of a single byte within a specific CAN bus message.

Watch on YouTube

Visual summary for Modern Odometer Manipulation - collin & oblivion by Colin
Visual summary for Modern Odometer Manipulation - collin & oblivion by Colin

Key moments

  1. 0:00 Introduction and talk agenda
  2. 2:00 Odometer importance and modern manipulation method
  3. 2:20 Discovery of the widespread odometer manipulation device
  4. 4:10 Device's man-in-the-middle installation and setup
  5. 4:40 Key components: STM32 microcontroller and CAN transceivers
  6. 5:10 Goal: obtain firmware, starting with SWD debug access
  7. 6:00 Useful tip: powering automotive components with USB-C PD

Modern Odometer Manipulation

Speakers: Colin

Conference: DEF CON

YouTube: https://www.youtube.com/watch?v=FYHvL8V_m-Q

Overview

In this insightful DEF CON talk, Colin delves into the surprisingly straightforward world of modern odometer manipulation. Challenging the common assumption that digital odometers are tamper-proof, he reveals how readily available devices can prevent mileage from accumulating, effectively devaluing used cars and defrauding warranty and lease providers. The presentation meticulously details the reverse engineering of one such device, exposing its core functionality: a simple modification of a single byte within a specific CAN bus message.

Colin's journey, spurred by an automotive forum discussion, highlights a critical vulnerability in vehicle systems that prioritize functionality over robust security for essential metrics. By demonstrating the relative ease with which these devices operate and how their firmware can be extracted even from protected microcontrollers, the talk underscores the urgent need for enhanced defensive measures. It serves as a stark warning to consumers, manufacturers, and regulatory bodies about the widespread potential for odometer fraud in the digital age.

The significance of this research extends beyond individual car sales, impacting the entire automotive ecosystem. Accurate odometer readings are fundamental to vehicle valuation, insurance premiums, warranty claims, and lease agreements. The proliferation of such manipulation devices, openly advertised and sold internationally, poses a substantial threat to consumer trust and financial integrity within the automotive industry, necessitating a re-evaluation of current security paradigms.

Background

▶ Watch: Introduction and talk agenda (0:00)

The odometer is a fundamental component of any vehicle, serving as a primary indicator of its wear and tear. It quantifies the distance a car has traveled, directly influencing its resale value, warranty eligibility, and lease return conditions. Historically, mechanical odometers could be physically "rolled back," a practice largely mitigated by the introduction of digital odometers in modern vehicles. The prevailing belief was that these digital systems were inherently more secure, making manipulation difficult, if not impossible.

However, Colin's research was sparked by an online automotive forum discussion that hinted at a new form of odometer manipulation – not rolling back an existing value, but preventing new mileage from registering in the first place. This concept intrigued him and led to the discovery of an active online web store, primarily based in Europe, openly advertising and selling devices for this exact purpose. These devices claimed compatibility with 53 different vehicle makes and numerous models, indicating a sophisticated and widespread operation.

The advertised features were particularly concerning: configurable modes allowed users to prevent all miles from being recorded, display all miles, or even register only a fractional amount of miles driven. The latter feature was highlighted as particularly insidious, as it could bypass routine checks like those performed during oil changes or by services like Carfax. The devices, priced between €300 and €600, also offered Bluetooth app control, suggesting a professional and user-friendly interface for illicit activity. While the European site was transparent about the device's function, a "shadow sister site" used identical infrastructure and imagery but fabricated descriptions to sell the devices in the US, presumably to circumvent stricter anti-fraud laws. This sophisticated distribution network underscored the scale and profitability of the odometer manipulation market.

Key Findings

▶ Watch: Discovery of the widespread odometer manipulation device (2:20)

The primary finding of Colin's research is the surprising simplicity and effectiveness of modern odometer manipulation devices. Despite the perceived security of digital odometers, the device he reverse-engineered achieves its fraudulent goal by merely intercepting and modifying a single byte within a specific CAN bus message. This byte, identified as odo_count in the Comma AI Open DBC project, directly controls the odometer's incrementation. The device's various modes—zeroing out the byte, or dividing its value by a configurable divisor—demonstrate a direct and unsophisticated approach to falsifying mileage.

A significant secondary finding involved the successful extraction of firmware from the device's STM32F1 microcontroller, despite its enabled flash read protection. This was accomplished through a sophisticated shellcode execution via glitch and flash patch block attack. This process not only revealed the device's operational logic but also highlighted a vulnerability in certain microcontroller protection mechanisms that can be bypassed with precise hardware manipulation and timing. The successful firmware extraction allowed for a complete understanding of the device's functionality, confirming its man-in-the-middle design and its targeted, byte-level manipulation of CAN messages. This revelation challenges the assumption that modern vehicle systems are inherently secure against such fundamental data tampering.

Technical Deep Dive

▶ Watch: Device's man-in-the-middle installation and setup (4:10)

The core of the odometer manipulation device is a compact PCB featuring an STM32 microcontroller, power regulation circuitry (stepping 15V down to 5V, then 3.3V), and two CAN transceivers. Its design is explicitly man-in-the-middle, intended to be wired into the back of the vehicle's instrument panel cluster. This position grants the device full control over CAN messages flowing between the instrument panel and the rest of the vehicle's ECUs.

To understand the device's logic, Colin aimed to extract its firmware. The STM32F1 microcontroller initially presented a challenge due to flash read protection being enabled. This protection prevents direct reads from flash memory, returning zeros instead. The protection is active under three conditions: when a debugger is connected, or when booting to the bootloader or SRAM. The latter two can be cleared by a simple reset, but the debugger lock requires a full power cycle.

Colin employed an advanced attack detailed in the paper "One Exploit to Rule Them All," specifically the "shellcode execution via glitch and flash patch block" method. This multi-stage exploit works as follows:

  1. SRAM Payload Preparation: A two-stage payload is loaded into SRAM. At this point, the debugger is connected, so flash is protected.
  2. Rapid Power Cycle & SRAM Retention: A critical step involves a very quick power cycle. This is achieved by tightly controlling the VCC pin and quickly reacting to changes in the NRESET line. By removing capacitors that resist voltage changes on these lines and resistors on the BOOT0 and BOOT1 pins, a Raspberry Pi Pico can precisely control the power and boot mode. The Pico momentarily drops VCC for approximately 2 microseconds, just enough time for NRESET to register a full power cycle, clearing the debugger's flash protection lock, but short enough for SRAM data retention to preserve the loaded payloads at room temperature.
  3. Boot to SRAM: After the power glitch, the device is booted to SRAM, which now has a new lock due to the SRAM boot mode.
  4. Flash Patch Block (FPB) Setup: The first stage of the SRAM payload executes. It configures the Flash Patch Block (FPB), a debugging feature on STM32s. The FPB allows an attacker to specify a flash address (comparator) and an override value. When the microcontroller attempts to read from the comparator address, it returns the override value instead. Crucially, FPB settings persist across resets. Here, the FPB is configured to redirect the flash entry point to the second stage of the payload in SRAM.
  5. Reboot to Flash & Execution Redirection: The device is then rebooted to flash. This clears the SRAM boot lock. Due to the active FPB, when the microcontroller attempts to execute the legitimate flash entry point, execution is redirected to the second stage of the payload in SRAM. This payload then transmits the full flash contents back to the Pico via UART.

With the firmware successfully extracted, Colin used Ghidra for reverse engineering. He configured Ghidra with the correct memory regions (RAM, flash mirrored at address zero) and selected Cortex little-endian. A crucial step was using the SVD loader Ghidra script by Level Down Security. This script leverages ARM-provided SVD files to automatically label memory regions and peripheral registers (timers, watchdogs, CAN controllers), significantly accelerating the analysis process.

Starting from the well-defined ARM entry point (stack pointer at address zero, reset interrupt pointer at address four), Colin followed the last calls of functions until reaching the main application loop. The core functionality was found within two hooks that intercept CAN messages. Leveraging Comma AI's Open DBC project on GitHub for message definitions, he identified that the device specifically targets a message with a particular arbitration ID and DLC (Data Length Code).

The manipulation itself is remarkably simple: the device modifies the sixth byte of this specific CAN message. This byte, labeled odo_count in Open DBC, is directly responsible for odometer incrementation. Depending on the configured mode, the device either zeros out this byte (preventing any mileage accumulation) or divides its value by a configurable divisor (for fractional mileage accumulation) before forwarding the message to the instrument panel cluster.

Beyond the core manipulation, the firmware revealed additional features. For devices without the Bluetooth adapter, users could change modes by holding down the up or down buttons on the steering wheel. Mode changes were confirmed by the device sending a hard-coded message to the instrument panel cluster, causing it to blink on and off as feedback. No other complex odometer-related logic was found, reinforcing the conclusion that the entire manipulation hinges on this single-byte modification.

Demo / Proof of Concept

▶ Watch: Goal: obtain firmware, starting with SWD debug access (5:10)

While the talk did not feature a live demonstration of odometer manipulation on a vehicle (due to the federal illegality of such actions), Colin provided detailed evidence of the firmware extraction and analysis process. He showed a screenshot of the precise power glitch waveform, illustrating the VCC drop and NRESET behavior crucial for the SRAM data retention attack. This visual evidence confirmed the successful implementation of the hardware-level exploit used to bypass the STM32F1's flash read protection.

The subsequent reverse engineering of the extracted firmware served as the definitive proof of concept for how the device operates. By detailing the specific CAN message ID, the targeted byte (the sixth byte, identified as odo_count), and the simple logic applied to it (zeroing or fractional division), Colin demonstrated precisely how the odometer value is manipulated. This static analysis of the device's internal code provided irrefutable evidence of its fraudulent capabilities and mechanisms, effectively acting as a "virtual" proof of concept for the underlying attack.

Defensive Implications

▶ Watch: Useful tip: powering automotive components with USB-C PD (6:00)

The findings presented by Colin have significant defensive implications for various stakeholders in the automotive industry. The primary victims of odometer manipulation are used car buyers, who unknowingly purchase vehicles with inaccurate mileage, leading to inflated prices and unexpected wear. Beyond consumers, warranty providers and lease providers (including OEMs) are directly impacted. Warranties are often tied to mileage limits, and residual values for leased vehicles are calculated based on expected odometer readings. Fraudulent manipulation directly undermines these agreements, leading to financial losses.

The fact that the device merely prevents mileage from incrementing, rather than rolling back an existing value, suggests that the current threat model for odometers might be incomplete. Manufacturers may have focused on preventing direct rewriting of the odometer value, overlooking the simpler, man-in-the-middle approach to prevent accumulation.

For Consumers (Buyers):

  • Pre-purchase Inspection (PPI): Always get a comprehensive PPI from a trusted, independent mechanic. Service technicians are often adept at spotting inconsistencies.
  • Wear of Consumables: Examine the wear on high-touch interior components (steering wheel, pedals, driver's seat) and common wear items (tires, brakes). Excessive wear inconsistent with the displayed mileage is a red flag.
  • Diagnostic Reporting: This is a crucial area for detection.
  • Cross-ECU Comparison: Many modern cars track odometer values on multiple ECUs (e.g., gateway, transmission, engine control unit). A full diagnostic report should reveal these values, which should be very similar. Significant discrepancies (e.g., a 2018 Jeep Grand Cherokee showing 19,000 miles on the dash but over 30,000 miles on the secure gateway) are strong indicators of manipulation.
  • Engine Hours: Compare engine hours to the displayed mileage. A low mileage reading paired with high engine hours could indicate extensive idling or manipulation.
  • Oil Life Indicator Resets: Track the number of times the oil life indicator has been reset. If a car has very low mileage but an unusually high number of oil changes/resets, it could be suspicious, especially as oil changes are often mileage-based.

For OEMs and Manufacturers:

  • Secure Onboard Communication (SecOC): The simplicity of the attack, targeting an unprotected CAN message, highlights the urgent need for SecOC. Authenticating and encrypting critical CAN messages, especially those related to essential vehicle data like mileage, would prevent unauthorized modification by man-in-the-middle devices.
  • Redundant Odometer Storage and Cross-Verification: While some vehicles store odometer data in multiple ECUs, the comparison process needs to be more robust. ECUs should periodically cross-verify their stored odometer values and flag discrepancies. If a man-in-the-middle device attempts to lie about the mileage to a querying ECU, the discrepancy should still be detectable by other modules communicating securely.
  • Firmware Updates: While not commonly done for CAN specifications, manufacturers could potentially release software updates that alter the arbitration ID or byte location of the odometer message, or introduce new integrity checks. However, this is a complex undertaking given the number of ECUs that rely on stable CAN protocols.
  • Microcontroller Security: For future designs, manufacturers should ensure that microcontrollers used in critical systems have robust flash protection mechanisms that are resistant to power glitching or other physical attacks. Newer STM32s, for instance, are reported to patch the specific exploit used by zeroing RAM on boot, preventing payload persistence.
  • Enhanced Anomaly Detection: Implement more sophisticated anomaly detection within ECUs, looking for patterns like an odometer that never increments, or discrepancies between mileage and other operational metrics (e.g., fuel consumption, engine load).

Key Takeaways

  • Digital Odometer Fraud is Widespread and Simple: Modern digital odometers are not inherently tamper-proof. Devices are readily available online that prevent mileage accumulation by modifying a single byte in a specific CAN message.
  • Man-in-the-Middle is Key: These devices operate by sitting between the instrument cluster and the rest of the vehicle's ECUs, gaining full control over critical messages.
  • Firmware Protection Can Be Bypassed: Even microcontrollers with flash read protection (like the STM32F1) can have their firmware extracted using advanced techniques like the "shellcode execution via glitch and flash patch block" attack, involving precise power cycling and hardware modifications.
  • Reliance on Unsecured CAN Messages: The core vulnerability lies in the lack of security for critical data transmitted over the CAN bus, allowing a simple modification of the odo_count byte to falsify mileage.
  • Defenders Need Multi-Layered Strategies: Detecting manipulation requires more than just looking at the dashboard. Consumers should get PPIs and check diagnostic reports for inconsistencies across multiple ECUs, engine hours, and oil life indicator resets.
  • Manufacturers Must Adopt SecOC: To truly secure vehicle data, OEMs must implement Secure Onboard Communication (SecOC) for critical CAN messages to prevent unauthorized modifications and ensure data integrity.

About the Speaker(s)

Colin is a security researcher with a passion for understanding and manipulating technology. His journey began with iOS jailbreaking, seeking to customize and "cheat" in games, which cultivated an early interest in making things work beyond their intended design. This led him to hacking AAA video games and reverse engineering anti-cheat mechanisms. His love for reverse engineering and exploitation eventually propelled him into the field of cybersecurity. In his professional career, Colin has specialized in areas such as voltage fault injection for extracting firmware from flash-protected chips and MCU emulation to analyze and exploit extracted firmware. His diverse background in hardware and software exploitation uniquely positioned him to tackle the challenge of modern odometer manipulation.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Solid DEF CON-caliber research that takes a real-world fraud problem and works it all the way down to firmware extraction via power glitching a protected STM32F1. The CAN bus finding itself is almost embarrassingly simple — one byte, no auth — but the hardware attack chain to get there is the actual contribution, and it's legitimate.

Heather Calloway (CISO) — WEAK

Technically competent work exposing a real consumer fraud vector, but the talk stays in the hardware exploit lane and never makes the institutional leap. The governance exposure here — OEM liability, regulatory obligation, insurance fraud at scale — is substantial and goes almost entirely unaddressed.

→ Top-rated talks at DEF CON 33

All talks from DEF CON 33