Car Hacking: With or Without a Flipper Zero
Key Takeaways
The video demonstrates car hacking techniques using a Flipper Zero and alternative methods, including building a replay attack device with a Raspberry Pi and SDR, and explores the potential of replay attacks on keyless entry systems.
Full Transcript
this device was almost illegal where I live recently the government of Canada proposed Banning flipper zeros in an attempt to curb car hacking thieves this got me wondering can you even hack into a car with a flipper zero and if you could would Banning them make any difference in this video I'll demonstrate the basic replay attack that flipper zeros can pull off to unlock some cars I'll also show you how you can build out your own test Target at home using an aftermarket keyless entry system and how you don't actually need a flipper zero to perform this attack and can instead build your own replay device using a Raspberry Pi and software defined radio let's get started by learning how these replay attacks actually work most keyless entry systems communicate over radio frequency or RF when you push a button on the key fob it sends a broadcast out over a specified frequency that the car is tuned to listen in on if the car is within range it will receive the message if you actually demodulate and decode this broadcast you would see that it's just a string of ones and zeros or binary inside of this message includes the command being sent to the car such as to unlock or lock of course this broadcast is sent out into the air so anyone or anything within range could also listen to it and potentially record it in older cars and the cheaper aftermarket keyless entry system will be demo later in this lesson a unique identifier is hardcoded into the key fob that is also paired with the receiver in the car when the key fob sends out a message to a vehicle it includes its unique identifier inside of it and the vehicle then checks this message to make sure it matches its own before performing any commands or actions such as unlocking a vehicle this is what prevents other key fobs from not opening up cars that they shouldn't since this identifier is hardcoded this means that a message for something like and unlock does not differ over time or between key presses this makes a system vulnerable to a replay attack an attacker with a listening device could listen in for the unlock message being sent and record this broadcast to be replayed at a later time they could then return and replay this message over the air to unlock the vehicle this is the replay attack we'll be demoing in this video let's take a look at how I set up the keyless entry system to practice on I picked up this aftermarket keyless entry system on on Amazon and it's actually very straightforward to wire this up outside of a car on a test bench so we have something to demo or practice the replay attack like a lot of components inside of a modern car it runs off of 12 volts so I also picked up this 12vt power supply here it's this one right here and one of the reasons I selected this one is it does have an adapter on it with a terminal breakout so that it's easier to wire up without needing to splice or solder the power supply wiring I also o have these two terminals here one for 12 volts and one for ground and this is just to make the wiring easier and so I don't have to do any soldering so these keyless entry systems are fairly straightforward they come with the receiver module a wiring harness and then of course the key fob for doing the Locking and unlocking inside of the receiver module there's two relays one for the lock and unlock and when we push the lock or unlock button then it fires those relays you can hear them closing so what I've done is I've just wired this up actually as it would be in most cars I've put 12 volts to the input of those relays that's these yellow wires here and then the white wires are the output of those relays and I've actually instead of wiring them up to what would be the motors for locking and unlocking I've just put them into this breadboard and then wired them to two LEDs so we can see when they turn on and off if you're looking to wire this up yourself you don't necessarily actually need to use the LEDs because you will get a fairly audible click from the relays so you can actually tell uh when it's actually receiving the message and if your replay attack was successful just by listening for that click so what I'll do is I'll throw up a wiring uh diagram and table on the screen right now here if you want to pause it and you could use this to wire it up if you wanted to purchase these and wire it up yourself I'll also throw some links down to each of these products in Amazon below and also a more detailed blog that goes through how you can wire this up should you want to do it yourself before we continue with the video a very important announcement the Black Friday discounts at TCM are live now from today until December 2nd you can get 20% off all certification vouchers and 50% off your first payment to the academy in addition we have some special never seen before bundles on sale and discounts for our two upcoming live trainings the popular attacking and defending active directory and our brand new sock level one live seats to these trainings fill up quickly so if you're interested rested make sure to act fast if you've been thinking of taking a TCM certification like the PNP or upping your skills with the hundreds of hours of courses on the academy you won't want to miss out on the sale now that we haven't understanding how this system works let's take a look at how we can do this replay attack with a flipper zero it's actually very straightforward so I just have the standard firmware here and we'll go into sub gigahertz because that's the frequency actually that the key fob broadcasts at so we'll go sub gahz and then we're just going to go read here and then I'll I'll hit the unlock here and you can see that it automatically actually picks picks that up here and we can just hit the uh go back to the config here and then we can go send and what I'll do is I'll bring it down here so we can see and we'll do a send here and you can see that immediately actually does the unlock because it's replaying uh that same unlock message that we just copied however you definitely do not need a flipper zero for uh this attack so what I'm going to do now is I'll set this to the side and then let's take a look at the parts we'll need to actually just do this with a Raspberry Pi zero and an SDR to build your own sub gigahertz replay device we will need a few items so the first one is a Raspberry Pi and I'm going to be using a Raspberry Pi 02 W in this lesson just cuz it's the cheapest one however you can use any device from 2B up so if you have a 2B a three or a four you can also use that I've also got an SD card with the Raspberry Pi OS rber by operating system loaded on it I won't be going over how to do that in this video cuz it's very straightforward and there's a lot of good guides on the internet i' suggest the getting started guide by Raspberry Pi the next item we've got here is the SDR so that stands for software def find radio and I'm using the RTL SDR I'll put a link for this down below and then I've got an antenna here to attach to it just to make the range extend a bit uh if you don't have an antenna then you can actually still get away without one but you'll need to hold the key SW very close to it so just keep that in mind because the raspberry pi0 just has a micro USB adapter into it I'm going to need this adapter to break out to regular USB so that's what I'm using this for to plug the SDR in and then I've just got a power cable to power it so then finally optionally we're going to be broadcasting off of the GPO pin on the Raspberry Pi and if you do want to extend the range for that you can just use a wire and plug it in so the gpio pin that it actually is going to transmit off of is gpo4 which is the fourth one down from the left if you're looking at it from the top that's where the SD card is so you can attach a wire here and this will extend its range however just so you're not causing interference I would suggest actually just running it without one if you're going to be doing it locally uh you still should be able to get about 5T of range without that so what I'll do is I'll just quickly put this all together here and then we can hop over and SSH into it now that that I'm sshed into the Raspberry Pi we'll need to install some tools and drivers we'll start with the ones for the RTL SDR and I'm going to follow the instructions in their quick start guide so to do that we'll just copy and paste these commands from the getting started on Linux section all the way down to here and then we just need to reboot our device to save you from watching me copy and paste these commands I'll just run through them now and I'll see you when they're done I'm finished with the installation steps and just did a quick reboot of the raspe pot the last thing I'd suggest is just to run a quick test to make sure that the Raspberry Pi is able to communicate properly with the SDR to do that there's actually a test utility that's included with the RTL software and we can run that by RTL test and you should see that it finds one device and if you're using the same one as me it should be this RTL SDR blog and then you'll notice down here it is reading the samples in async mode if it's working properly you should just see nothing here so what we can do is hit contrl C to quit it after we let it run for a couple seconds and we should see that it has zero samples per million loss so mine's working properly the last step we'll need to do now to set up our device is actually to install the software that's going to allow our Raspberry Pi to transmit a radio frequency or a broadcast a message so the reason we need to do this is because these less expensive sdrs like the one we are using are actually only able to receive they aren't able to transmit so what we're going to be using is we will use the SDR for the first half half of the replay attack where we're going to save the broadcaster message from the key fob and then after we save it we'll then need to play it back or transmit it and to do that we're going to be making use of some software that can be installed on the Raspberry Pi to allow it to transmit over its GPI opens so that software is available on GitHub and I'll link this down below so what we'll do is we'll just run through the installation steps here so I'll just copy them over and paste them in here and we'll just run through these I'll see you over when mine's done cloning perfect mine's done cloning so I'll just run the installation script here my installation's completed so we can just run a quick reboot now and we'll be ready to run through this replay attack I've got my Hardware all set up and we're now ready to perform the replay attack if you're following along with the commands at home just make sure to take note that I'm running them all from the rpy TX directory so the first step we'll need to do is to record a capture of the key fob sending an unlock transmission or command to do that we'll use the SDR and the rtor SDR tool that we just installed so the command for that is RTL SDR and we'll need to pass in a few parameters so the first one is the sample rate and I found a sample rate of 250,000 works very well for this SDR and then we'll also need to pass in the gain with dasg and I found a gain of 35 works well as well the last parameter we'll need to pass in is the frequency that we want to take a recording at and this is actually the frequency of whatever device we're trying to capture so for us for this key fob it's 433.92 megahertz so to do megahertz we'll go E6 and if you're not sure what the frequency is of the device that you're trying to capture one easy way is to consult the manual of it so in the manual of this key fob it has it listed out alternatively if you do some Googling and are able to find the FCC ID of the device you can usually find the frequency that way as well for most key fobs they are going to be at or right around the 43.92 mahz frequency so that's what we'll tune to here the very last parameter that we need to pass in is just the name of the file that we want to save this capture to so for me I'm going to call it key fob cap and the file type is IQ so we'll hit enter here to start recording and once we see that it's reading samples then we'll just need to press the unlock on the key file a couple of times here so I'll do mine twice just for good measure and then we can hit contrl C to just cancel or stop this so now what we can do is we'll just use the rpy TX tools to replay this transmission back so the command for that is going to be pseudo and it's do slash there is a send IQ commands and we'll need to pass in the same parameters that we did when we we're recording this we'll need to tell the sample rate so that's 250,000 and then we'll also need to specify the frequency so again that's 433.92 mahz we will specify in the type as u8 and then we'll need to pass in the file name- I and we called it key fob undor capture and then we can hit enter and then this will transmit out that capture and replay it and then when it replays we see it unlocking twice so that's how we can perform this replay attack using the raspberry pi and SDR at this point you may be thinking this is too easy and there's no way this would work on a real car and you'd be mostly correct modern cars and we're talking within the last 20 plus years have additional Security on their keyless entry system to prevent things like the basic replay attack we just demonstrated one common method is the use of rolling codes instead of using a single hardcoded identifier that the key fob transmits for the car to verify an algorithm and Seed value are used to generate what are called rolling codes when a button on the key fob is pressed it generates the current rolling code and this is transmitted to the car the car is paired with a matching algorithm and Seed value so it can generate the current rolling code and verify this against the one that the key fob sent if they match it performs the action that was requested such as unlocking the next time a button is pressed on the key fob and a message is sent it generates the next rolling code which the car will also use this prevents replay attacks because as long as the car receives the message from the key fob it will increment to the next rolling code invalidating the previous one which could be replayed in addition most modern cars use encryption on their keyless entry system to prevent things like reverse engineering or brute forcing the rolling code algorithm there are still some more complex attacks that can Target rolling code systems when common one involves jamming the signal near the car to prevent it from receiving the message from the key fob and incrementing its rolling code this is a more complex attack and requires additional Hardware other than just one SDR r or a flipper zero nowadays most car hacking thieves are actually exploiting vulnerabilities in proximity keyless entry systems with something called a relay attack this is also a much more complex attack that requires multiple pieces of Hardware to pull off if you're interested in learning about these more complex attacks or other car hacking attacks such as targeting the physical components of a car make sure to drop a like or leave a comment so I know to make more videos on this subject that wraps up this video thanks for watching
Original Description
https://www.tcm.rocks/pipa-y - The Practical IoT Pentest Associate (PIPA) is the hardware hacking cert Andrew Bellini created! Like hardware and IoT hacking? This is for you!
Check out Andrew Bellini's car hacking guide to get info on supplies, equipment, and more: https://www.tcm.rocks/car-hacking-blog
Can you really hack a car with a Flipper Zero? 🔓 Join Andrew Bellini (DigitalAndrew) in this intro to car hacking as he explores the potential of replay attacks. In this video, you'll learn how to build an affordable test target, discover which targets are susceptible to Flipper Zero attacks, and get step-by-step guidance on building a replay attack device from scratch-no Flipper needed! 🚗💥
If you're interested in IoT hacking and more hands-on tutorials, be sure to subscribe to our channel to catch the latest content!
#carhacking #iotsecurity #flipperzerohacking #flipperzero #hacking
Sponsor a Video: https://www.tcm.rocks/Sponsors
Pentests & Security Consulting: https://tcm-sec.com
Get Trained: https://academy.tcm-sec.com
Get Certified: https://certifications.tcm-sec.com
Merch: https://merch.tcm-sec.com
📱Social Media📱
___________________________________________
X: https://x.com/TCMSecurity
Twitch: https://www.twitch.tv/thecybermentor
Instagram: https://www.instagram.com/tcmsecurity/
LinkedIn: https://www.linkedin.com/company/tcm-security-inc/
TikTok: https://www.tiktok.com/@tcmsecurity
Discord: https://discord.gg/tcm
Facebook: https://www.facebook.com/tcmsecure
Timestamps:
0:00 Intro
0:47 How replay attacks on keyless entry systems work
2:27 Building a practice target keyless entry system
4:26 Black Friday Announcement
5:15 Replay attack with Flipper Zero
6:06 Building a replay attack device with SDR and Raspberry Pi
8:03 Installing drivers and rpitx
10:14 Replay attack with Raspberry Pi and SDR
13:12 How rolling codes work and prevent replay attacks
15:00 Outro
💸Donate💸
___________________________________________
Like the channel? Please consider supp
Watch on YouTube ↗
(saves to browser)
Sign in to unlock AI tutor explanation · ⚡30
Playlist
Uploads from The Cyber Mentor · The Cyber Mentor · 0 of 60
← Previous
Next →
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
Buffer Overflows Made Easy - Part 1: Introduction
The Cyber Mentor
Buffer Overflows Made Easy - Part 2: Spiking
The Cyber Mentor
Buffer Overflows Made Easy - Part 3: Fuzzing
The Cyber Mentor
Buffer Overflows Made Easy - Part 4: Finding the Offset
The Cyber Mentor
Buffer Overflows Made Easy - Part 5: Overwriting the EIP
The Cyber Mentor
Buffer Overflows Made Easy - Part 6: Finding Bad Characters
The Cyber Mentor
Buffer Overflows Made Easy - Part 7: Finding the Right Module
The Cyber Mentor
Buffer Overflows Made Easy - Part 8: Generating Shellcode and Gaining Shells
The Cyber Mentor
HackTheBox - Sunday Walkthrough (Re-Up)
The Cyber Mentor
Networking for Ethical Hackers - TCP, UDP, and the Three-Way Handshake (Re-Up)
The Cyber Mentor
Networking for Ethical Hackers - Network Subnetting (Re-Up)
The Cyber Mentor
Networking for Ethical Hackers - Network Subnetting Part 2: The Challenge (Re-Up)
The Cyber Mentor
Networking for Ethical Hackers - Building A Basic Network with Cisco Packet Tracer (Re-Up)
The Cyber Mentor
HackTheBox - Fighter Walkthrough (Re-Up)
The Cyber Mentor
Beginner Linux for Ethical Hackers - Navigating the File System
The Cyber Mentor
Beginner Linux for Ethical Hackers - Users and Privileges
The Cyber Mentor
Beginner Linux for Ethical Hackers - Common Network Commands
The Cyber Mentor
Beginner Linux for Ethical Hackers - Viewing, Creating, and Editing Files
The Cyber Mentor
Beginner Linux for Ethical Hackers - Controlling Kali Services
The Cyber Mentor
Beginner Linux for Ethical Hackers - Scripting with Bash
The Cyber Mentor
Beginner Linux for Ethical Hackers - Installing and Updating Tools
The Cyber Mentor
Cracking Linux Password Hashes with Hashcat
The Cyber Mentor
Reminder: Twitch Hacking Live Stream Tonight! 2/26/19 at 8PM EST
The Cyber Mentor
Hacking Live Stream: Episode 1 - Kioptrix Level 1, HackTheBox Jerry, and Career Q&A / AMA
The Cyber Mentor
Hacking Live Stream: Episode 2 - HackTheBox Active, Vulnserver Buffer Overflow, and Career Q&A / AMA
The Cyber Mentor
Hacking Live Stream: Episode 3 - Hack The Box Blue, Devel, and Career Q&A / AMA
The Cyber Mentor
New Zero to Hero Pentest Course, New Website, and 2K Subs?!
The Cyber Mentor
Zero to Hero Pentesting: Episode 1 - Course Introduction, Notekeeping, Introductory Linux, and AMA
The Cyber Mentor
Zero to Hero Pentesting: Episode 2 - Python 101
The Cyber Mentor
Zero to Hero Pentesting: Episode 3 - Python 102, Building a Terrible Port Scanner, and a Giveaway
The Cyber Mentor
Zero to Hero Pentesting: Episode 4 - Five Phases of Hacking + Passive OSINT
The Cyber Mentor
Zero to Hero Pentesting: Episode 5 - Scanning Tools (Nmap, Nessus, BurpSuite, etc.) & Tactics
The Cyber Mentor
Zero to Hero Pentesting: Episode 6 - Enumeration (Kioptrix & Hack The Box)
The Cyber Mentor
Zero to Hero Pentesting: Episode 7 - Exploitation, Shells, and Some Credential Stuffing
The Cyber Mentor
Installing Windows Server 2016 on VMWare in 5 Minutes
The Cyber Mentor
Zero to Hero: Week 8 - Building an AD Lab, LLMNR Poisoning, and NTLMv2 Cracking with Hashcat
The Cyber Mentor
A Day in the Life of an Ethical Hacker / Penetration Tester
The Cyber Mentor
Active Directory Exploitation - LLMNR/NBT-NS Poisoning
The Cyber Mentor
Zero to Hero: Week 9 - NTLM Relay, Token Impersonation, Pass the Hash, PsExec, and more
The Cyber Mentor
Zero to Hero: Episode 10 - MS17-010/EternalBlue, GPP/cPasswords, and Kerberoasting
The Cyber Mentor
Writing a Pentest Report
The Cyber Mentor
Zero to Hero: Week 11 - File Transfers, Pivoting, and Reporting Writing
The Cyber Mentor
The Complete Linux for Ethical Hackers Course for 2019
The Cyber Mentor
Full Ethical Hacking Course - Beginner Network Penetration Testing (2019)
The Cyber Mentor
Popping a Shell with SMB Relay and Empire
The Cyber Mentor
Pentesting for n00bs: Episode 1 - Legacy (hackthebox)
The Cyber Mentor
Pentesting for n00bs: Episode 2 - Lame
The Cyber Mentor
Pentesting for n00bs: Episode 3 - Blue
The Cyber Mentor
Web App Testing: Episode 1 - Enumeration
The Cyber Mentor
Pentesting for n00bs: Episode 4 - Devel
The Cyber Mentor
Pentesting for n00bs: Episode 5 - Jerry
The Cyber Mentor
Web App Testing: Episode 2 - Enumeration, XSS, and UI Bypassing
The Cyber Mentor
Pentesting for n00bs: Episode 6 - Nibbles
The Cyber Mentor
Web App Testing: Episode 3 - XSS, SQL Injection, and Broken Access Control
The Cyber Mentor
How NOT to Approach a Cybersecurity Mentor
The Cyber Mentor
Web App Testing: Episode 4 - XXE, Input Validation, Broken Access Control, and More XSS
The Cyber Mentor
Pentesting for n00bs: Episode 7 - Optimum (hackthebox)
The Cyber Mentor
Pentesting for n00bs: Episode 8 - Bashed (hackthebox)
The Cyber Mentor
Pentesting for n00bs: Episode 9 - Grandpa
The Cyber Mentor
Top 5 Internal Pentesting Methods
The Cyber Mentor
More on: Security Basics
View skill →Related Reads
📰
📰
📰
📰
Web3 Navigates Market Dip with Robust Developer Activity Amidst Escalating Cyber Risks
Dev.to AI
A Production Security Checklist
Dev.to · Aman Kumar Singh
Your MCP credential is not revoked when the dashboard says disabled
Dev.to · Mads Hansen
5 SOC Interview Questions That Eliminated Me — And How I Fixed My Answers
Medium · Cybersecurity
Chapters (10)
Intro
0:47
How replay attacks on keyless entry systems work
2:27
Building a practice target keyless entry system
4:26
Black Friday Announcement
5:15
Replay attack with Flipper Zero
6:06
Building a replay attack device with SDR and Raspberry Pi
8:03
Installing drivers and rpitx
10:14
Replay attack with Raspberry Pi and SDR
13:12
How rolling codes work and prevent replay attacks
15:00
Outro
🎓
Tutor Explanation
DeepCamp AI