On Monday the 28th of September 2015 a rather rare event occurred. At around 4
a.m. the moon changed its colour into a dim of red, luckily the sky was clear
enough to see something.
If you missed that event your next chance will be in about 15 years or so.
The reason for being awake this early wasn’t the moon in the first place but
what followed afterwards – my trip to the
hardwear.io Security Conference in The Hague.
During my stay in The Hague I needed to print something, so I asked for a Copy
shop and this is where they sent me:
Against the common rule to just talk about the personal favorites, I will cover
all talks in one, two or more sentences (arbitrarily decided while
writing). This also gives you a broader picture of the conference.
Jumping right in with the keynote of Day 1 by Jon Callas and my favorite quote
“Make your devices fixable”. Enough said.
Unlike the German Oktoberfest in Munich which already started in September, the
Oktoberfest in The Hague started on 2nd October.
In spite of this competing event the decision going to the last day of the
hardwear.io Conference definitely paid off.
Day 2 started with the Keynote from Harald Welte (the father of Osmocom) and his
view about Telecom Security for the last few years. His observation is that
nothing has changed so far – we still suffer from a lack of tools and
monoculture throughout the industry.
On October 1st and 2nd Flo and I were presenting at
hardwear.io in The Hague, NL. My topic was
“Living in a fool’s wireless-secured paradise”
and Flo was presenting his current research
on medical device security. It was the first talk at an international
security conference for me and I am still quite excited!
I was speaking about the (in)security of wireless consumer alarm
systems, which you can buy just in every consumer electronics store
around the corner for about $10 – $250. I analyzed the systems on
different levels, e.g. looking at UART and JTAG and the wireless domain
with Software Defined Radio (SDR). I gave an overview of my current
research and the tools I usually use for hardware hacking, especially my
favorite thing to play with: SDR.
As TROOPERS15 has come to an end, I’ve finally got the time and energy to give
you a deeper insight into the TR15 badge. As most of you have probably heard
during the conference, this year’s badge was based on the
OpenPCD2. The
OpenPCD 2 is a 13.56MHz NFC Reader, Writer and Emulator under the GNU GPL v2. As
NFC is, yet again, on an uprise, a badge with NFC simply gives you the chance to
fiddle around and hack stacks of stuff in the real world. Adding some TROOPERS
spirit and a few little secrets we hope we’ve designed a pretty nice badge!
Simple everyday work dialog:
“The heater in the basement is still missing a proper thermostat, the ‘binary
solution’ isn’t that effective”
– “Buy one…”
– “Ok”
– “Get one you can break…”
– “Ok, but then I’d like a few tools, too”
– “Go for it.”
(That’s the way work should be!)
Result of the dialog: a
Danfoss Living Connect Z ( 014G0013 )
and a
TI CC1100 Wireless Mini Dev Kit plus
a copy of Z-Force to start with. Goal: Talk to the thermostat!
TROOPERS14 has come to an end, and it’s finally time to let you have a go at the
Badge’s source code. As promised, it was slightly modified and extended, to show
you the full potential of your new gadget. I’ve added some nice payloads from
Nikhil Mittal and a few own ones. Above that, for those who took their parts for
soldering home, I’ve also added a few quick instructions on how to do the
soldering.
Greetings from the Print Media Academy in Heidelberg. Just in time for
TROOPERS14, I’ve got the great honor to present this years badge!
Being a TROOPER is tough: You need to know loads of information, learn even more
and be able to work fast.
This year we decided to increase your efficiency and speed when collecting data
from computer systems and, let’s say, hacking them! Your newest gadget is based
on a plain
Arduino Leonardo,
modded with one of our famous shields. After adding a few LEDs and buttons, it
will power up to full functionality.
I recently got in contact with
Intel AMT
for the first time. Surely I had heard about it, knew it was “dangerous”, it was
kind of exploitable and had to be deactivated. But I hadn’t actually seen it
myself. Well, now I have, and I simply love it and you will probably, too (and
don’t forget: love and hate are very very close to each other 😉 )
The following blogpost will be a set of features and instructions on how to own
a device with an unconfigured copy of Intel AMT without using any complicated
hacks or the famous magic!