CarHackerKit is designed for authorized security research and educational purposes only.
- Obtain Written Authorization - Always get explicit permission from the vehicle owner before testing
- Use Isolated Test Benches - Never test on vehicles that may be driven
- Avoid Safety-Critical Systems - Never inject messages affecting brakes, steering, or throttle
- Follow Local Laws - Ensure compliance with computer fraud and vehicle tampering laws
If you discover a security vulnerability in CarHackerKit itself:
- Do NOT open a public issue
- Email security concerns to the maintainer
- Include detailed steps to reproduce
- Allow 90 days for a fix before public disclosure
If you discover vulnerabilities in vehicle systems using this tool:
- Follow responsible disclosure - Contact the manufacturer first
- Use coordinated disclosure - Work with CERT/CC or Auto-ISAC
- Do not publish exploits for safety-critical systems without coordination
- Consider public safety - Some issues may warrant longer embargo periods
| Version | Supported |
|---|---|
| 1.x.x | ✅ |
This tool includes safety measures:
- Rate limiting on OBD-II queries to prevent ECU flooding
- Warnings before potentially dangerous operations
- Logging of all diagnostic commands
- Simulation mode for testing without hardware
The authors of CarHackerKit are not responsible for:
- Damage to vehicles or property
- Injury resulting from misuse
- Legal consequences of unauthorized testing
- Warranty voiding on tested vehicles
Use this tool responsibly and ethically.