The training
Software-Defined Radio applied to security assessments
was held by Sébastien Dudek at Troopers21 and was remotely organized – like most
other events – due to Covid-19. Once we were all caffeinated, we had an exciting
journey through basically all things radio.
We started with the technical and physical basics in radio technology, such as
various sorts of antennas, analog to digital coding (and backward), encoding
schemes, and general risks and possible vulnerabilities of using radio devices.
Commonly found vulnerabilities include the following:
Last Friday I gave a talk at the ITSeCX in St.
Pölten, Austria. The conference, hosted by the local University of Applied
Sciences, has already taken place ten times. I don’t know how many people
attended this time, 2014 there were about 600;
I read somewhere on the net.
There were four tracks and some workshops from 4pm to the conference’s end at
midnight. I enjoyed the community-feeling there very much, even though I arrived
late. The only talks I saw, were Adrian Dabrowski speaking about the DARPA Cyber
Grand Challenge, the finals took part in Las Vegas this August, and the very
entertaining end-of-year review from two UAS guys.
The moment, when your team leader asks you to cheat at Pokémon GO…everyone knows
it, right? No? Well, I do 😉
GPS Spoofing Setup
As I’m not a gamer, the technical part was of much more interest – that’s the
real gaming for me.
So, challenge accepted!
In the past I was often fiddling around with SDR (Software Defined Radio),
started with DVB-T sticks some years ago. When I came to ERNW in 2014 I got in
touch with
Michael Ossman’s great HackRF One for
the first time, and subsequently my thesis was based on SDR.
Hey there!
The God of frequencies Michael Ossmann visited us again this year at the
TROOPERS16 and showed us how to break
another device using a specific setup.
Last time he introduced the HackRF One to us (Read
here:https://www.insinuator.net/2014/08/hackrf-one-the-story-continues/), but
this post is a short summary of his talk about “Rapid Radio Reversing”, he is a
wireless security researcher, who makes hardware for hackers. Best known for the
HackRF, Ubertooth, and Daisho projects, he founded Great Scott Gadgets in an
effort to put exciting, new tools into the hands of innovative people.
On October 1st and 2nd Flo and I were presenting at
hardwear.io in The Hague, NL. My topic was
“Living in a fool’s wireless-secured paradise”
and Flo was presenting his current research
on medical device security. It was the first talk at an international
security conference for me and I am still quite excited!
I was speaking about the (in)security of wireless consumer alarm
systems, which you can buy just in every consumer electronics store
around the corner for about $10 – $250. I analyzed the systems on
different levels, e.g. looking at UART and JTAG and the wireless domain
with Software Defined Radio (SDR). I gave an overview of my current
research and the tools I usually use for hardware hacking, especially my
favorite thing to play with: SDR.
Today we received a few
ShareBrained Technology – PortaPack H1
to use with our HackRFs. Having done a first few minutes of scanning, I just
wanted to give you a quick overview of its features and potential…
After having had
Michael Ossmann in
for a few workshops with his
Jawbreaker and
HackRF One
we have used the HackRF on multiple occasions. No matter if
research projects
or actual customer projects, the HackRF has always been of great help. As we
mainly use it on laptops, we’ve got certain constraints concerning its
portability when wanting to do some quick mobile scanning. Although there are a
few solutions for tablets and smartphones, they haven’t been quite able to
convince all of us. So a while back we decided to keep an eye on the
PortaPack and
have been since been waiting for its release.
A few days later than planned (sorry about that), but here we go with part 2
(Part1) and
the demodulation/analysis part.
Initial Analysis
To analyse a captured signal, the tool baudline seems to be the best way at the
moment. So we open it with the following options and have a closer look
(ContextMenu->Input->Open file):
After using the open button, you should be able to see something similar to
this:
Introduction
This and the following two posts should serve as a step-by-step guide through
the whole process of analyzing a radio frequency black box, demodulate and
understand the data transfered and finally modulate our own data in order to
e.g. perform a brute force attacks.
The information provided and the results are immensely inspired by Michael
Ossmann and the workshops he has given at our location. Visit him and his great
tool HackRF at https://greatscottgadgets.com/hackrf/ !
once again, we welcomed Michael Ossmann at the ERNW headquarters for fun with
SDR. This time with Mike´s advanced SDR workshop. And to be up front about it…it
was plain awesome. For everybody who is not familiar with Software Defined Radio
(SDR): Let’s regard it as the ultimate tool when working with radio signals.
Take a look a
this to learn
more.
Mike showed us the new revision of his HackRF One and explained us some more
advanced techniques when it comes to Radio Frequnecies hacking. Compared to last
time, the workshop focused on reversing signals and how to synthesize them. So
this time we were crafting RF packets ourselves instead of just replaying a
capture. This introduces different attack types which can be carried out over
the air for example bruteforcing or fuzzing of radio devices.
today we welcomed Michael Ossmann at the
ERNW headquarter for an exclusive workshop on his
HackRF
gadget. Everybody was quite excited to get hands-on with this shiny piece of
hardware, which is currently
crowd-funded on Kickstarter.
For everybody who’s not familiar
with Software Defined Radio (SDR):
Let’s regard it as the ultimate tool when working with radio signals.
Michael Ossmann in the house.
Let’s quote Michael’s campaign website:
Transmit or receive any radio signal from 30 MHz to 6000 MHz on USB power
with HackRF. HackRF is an open source hardware project to build a Software
Defined Radio (SDR) peripheral.