Reverse engineering an ancient wireless security keypad using RTL-SDR
1–10 of 23 posts
Re: Reverse engineering an ancient wireless security keypad using RTL-SDR
#2Re: Reverse engineering an ancient wireless security keypad using RTL-SDR
#3Re: Reverse engineering an ancient wireless security keypad using RTL-SDR
#4Re: Reverse engineering an ancient wireless security keypad using RTL-SDR
#5Re: Reverse engineering an ancient wireless security keypad using RTL-SDR
#6Broadcasting FM is as simple as loading a Raspberry Pi up with PiFM[0]. Or, if you don't have the original remote (but are a bit more technical), you can just brute force the combination; most remotes only use a 12-bit DIP switch (4096 combinations)[1].
[0] https://github.com/CodyJHeiser/PiStation [1] http://samy.pl/opensesame/
Re: Reverse engineering an ancient wireless security keypad using RTL-SDR
#7i hope the author is not going to use this panel as-is because it send everything in clear. i would keep the front panel but retrofit a microcontroller in there to encrypt keypresses before it is sent.
The vast majority of garage door openers out there use unencoded RF tech, and it's very seldom a problem. And the other side: there was a recent string of thefts of BMW and VW cars in my area. Reason? They had an inside man at the main office who slipped them copies of the remotes.
The tech is very, very rarely the weak link.
Re: Reverse engineering an ancient wireless security keypad using RTL-SDR
#8Awesome article! I just got an SDR and now I'm hunting for old RF things to interrogate - thanks for the ideas!
Re: Reverse engineering an ancient wireless security keypad using RTL-SDR
#9Because he had guns? Do all your opinions come from Reddit? I have a Master's in engineering and my teeth are very straight. I own a gun.
Re: Reverse engineering an ancient wireless security keypad using RTL-SDR
#10i hope the author is not going to use this panel as-is because it send everything in clear. i would keep the front panel but retrofit a microcontroller in there to encrypt keypresses before it is sent.
Technically you're right, but this is a problem that comes up a lot in wireless home automation. Thing is, what is the attack vector you want to protect against? How many burglars are going to be sitting outside your house (I'm imagining: in a black van with 'Bob's plumbing' written on the outside) analyzing RF patterns when someone comes in, reverse engineer it, then burglarize you home? My estimate is 0, even when…