Radio Hacking: Cars, Hardware, and more! – Samy Kamkar – AppSec California 2016

Radio Hacking: Cars, Hardware, and more! – Samy Kamkar – AppSec California 2016

Watch Samy most recent talk on Browser Manipulation https://www.youtube.com/watch?v=K1T_miPTvPA

In this talk I’ll introduce radio hacking, and take it a few levels into hacking real world devices like wirelessly controlled gates, garages, and cars. Many vehicles are now controlled from mobile devices over GSM and the web, while even more can be unlocked and ignitions started from wireless keyfobs over RF. All of these are subject to attack with low-cost tools (such as RTL-SDR, GNU Radio, HackRF, Arduino, and even a Mattel toy).

We’ll investigate how these features work, and of course, how they can be exploited. I’ll be going from start to finish on new tools and vulnerabilities in this area, such as key-space reduction attacks on fixed-codes, advanced “code grabbers” using RF attacks on encrypted and rolling codes, exploiting mobile devices and poor SSL implementations, and how to protect yourself against such issues.

By the end of this talk you’ll understand not only how vehicles and the wirelessly-controlled physical access protecting them can be exploited and secured, but also learn about various tools for hardware, car and RF research, as well as how to use and build your own inexpensive devices for such investigation!

Samy Kamkar
Samy Kamkar is an independent security researcher, best known for creating The MySpace worm, one of the fastest spreading viruses of all time. His open source software and research highlights the insecurities and privacy implications in every day technologies, from the Evercookie which produces virtually immutable respawning cookies, SkyJack, the drone that wirelessly hijacks other drones, and KeySweeper, a wireless keyboard sniffer camouflaged as a USB wall charger. He continues to release new tools and hardware, for examples most recently the ProxyGambit, OpenSesame and ComboBreaker tools.

Managed by the official OWASP Media Project https://www.owasp.org/index.php/OWASP_Media_Project

50 Comments

  1. joan Jett on October 28, 2021 at 4:12 am

    I definitely need to hear about this bc it’s been a problem with this in my on life … thank you so much for this

  2. hzubovi1 on October 28, 2021 at 4:13 am

    Gone in 8 seconds

  3. K. M. Rayhan on October 28, 2021 at 4:14 am

    it was a nice presentation. I am little curious about the questions end of the presentation. bt thanks for the knowledge .

  4. Kristle on October 28, 2021 at 4:14 am

    Now this is some useful information

  5. I RECOMMEND 99TECHZ ON IG on October 28, 2021 at 4:17 am

    ⬆️⬆️⬆️⬆️⬆️⬆️⬆️
    For a legitimate experience💯

  6. 💯GURUCRACKERS ON INSTA on October 28, 2021 at 4:17 am

    *THANK* *YOU* *SO* *MUCH* *D* *U* *D* *E* 👆🏼 *FOR* *GIVING* *ACCESS* *ME* *INTO* *MY* *MAN’S* *PHONE* ..

  7. MeMnOn1000bc ShEpHeRdKiNgS on October 28, 2021 at 4:18 am

    Funny little joke at 19:20

  8. A Wolff on October 28, 2021 at 4:19 am

    in the old days my dad had a garage door opener that had a roller switch where you could just stand in front of whatever door hold down the button then roll the switch back and forth till it opened it took seconds

  9. Shelia Shuck on October 28, 2021 at 4:20 am

    I will never rely on gps again. Holy.

  10. Floyd French on October 28, 2021 at 4:21 am

    This will sure help the bad guys. They must love you 👎

  11. Mowie Wowie on October 28, 2021 at 4:21 am

    im glad your on our side

  12. Naresh Kaampaati on October 28, 2021 at 4:23 am

    Sir how my thinking hacking by radio frequency, becoze when ever iam thinking inside me my formor church pepole (hackers) sending same recomondations in youtube,in 2016 i sleep in church premisis i experience some eloctric shock in my right side belli area,then iam manuepulated by them i canot live myself no privasi to i feel so bad plz replyto my comment.

  13. EldrichtPalmer on October 28, 2021 at 4:26 am

    hazadhackha_ is that guy, how he gave me an original certificate even with my lapses in school is beyond me, but I have a solid job with that certificate, safe to say it worked, I shouldn’t have said that, oops but I’m Anonnymous who would know? Hahaha .

  14. Mowie Wowie on October 28, 2021 at 4:27 am

    im glad your on our side

  15. Big Guy on October 28, 2021 at 4:29 am

    some one just hacked my key fob yesterday and remote started my vehicle. 2 hours later they also unlocked the doors while i was inside a restaurant. How do I protect against this?

  16. skippy didgeridroo on October 28, 2021 at 4:30 am

    he should of called the method "jam roll"

  17. Barbie Platt on October 28, 2021 at 4:33 am

    What if someone sent a random video to my phone. And when that video was finished it was gone. With no trace. It looked like a YouTube video but didn’t show up in history. How do I find out who sent it?

  18. GURUCRACKERS ON INSTAGRAM 🥰 on October 28, 2021 at 4:33 am

    They did my own perfectly within some minutes he’s just so good in this.

  19. Killer Curl on October 28, 2021 at 4:34 am

    whoa dude do you see that door behind him marked pirate, you think a pirate live in there???????????

  20. nico Blay on October 28, 2021 at 4:35 am

    Fbi planes have now pivoted to drones and there’s prob 60 drones from the once 2 planes. I can see the hertz from these drones via naked eye

  21. ra on October 28, 2021 at 4:35 am

    Can track and trace my stolen phone?

  22. GURUCRACKERS ON INSTAGRAM 🥰 on October 28, 2021 at 4:38 am

    They did my own perfectly within some minutes he’s just so good in this.

  23. Thomas on October 28, 2021 at 4:38 am

    Fascinating. Great job on the presentation. Ten stars

  24. TxExMxiii on October 28, 2021 at 4:39 am

    Locking scooters is what makes dangerous interference to then throw u off . Had fun for while but sinister as fuk

  25. Marie Burton on October 28, 2021 at 4:41 am

    Code monkey shout out!! Cool

  26. GURUCRACKERS ON INSTAGRAM 🥰 on October 28, 2021 at 4:45 am

    They did my own perfectly within some minutes he’s just so good in this

  27. TungstenCarbideProjectile on October 28, 2021 at 4:46 am

    Boring and does not hold attention, annoying voice and i wanted to get into the topic and the info but this presentation is just boring useless garbage… 20$ something device… gone in 60 seconds bla blah blah like what are you trying to talk about here… get your shit together guy…

  28. edmunek on October 28, 2021 at 4:48 am

    if your friend would read the manual of his car he would find the information as well. without even knowing what FCC ID stands for…. 😕

  29. Steve Ballard on October 28, 2021 at 4:48 am

    Check out AM frequencies 666 upwards ….you can hear these demonic creatures through the white noise

  30. Nitin Maurya on October 28, 2021 at 4:48 am

    After 9 years of my graduation, I came to know why this subject was in Computer Science and Engineering in India.

  31. GURUCRACKERS ON INSTAGRAM 🥰 on October 28, 2021 at 4:51 am

    They did my own perfectly within some minutes he’s just so good in this.

  32. Jeff Garcia on October 28, 2021 at 4:53 am

    Can u hire my chain saw, go ruuuwwwtttt

  33. Tim Thomas on October 28, 2021 at 4:55 am

    I wish that you repeated the questions. So I could understand what you were responding to.

  34. 💯GURUCRACKERS ON INSTA on October 28, 2021 at 4:55 am

    *THANK* *YOU* *SO* *MUCH* *D* *U* *D* *E* 👆🏼 *FOR* *GIVING* *ACCESS* *ME* *INTO* *MY* *MAN’S* *PHONE* ..

  35. Adam Lopez on October 28, 2021 at 4:56 am

    Samy is gonna wreck the car

  36. deep purple on October 28, 2021 at 4:56 am

    Revert back to key only. Could cc TV recordings be compromise by external player’s . What’s safe !

  37. GURUCRACKERS ON INSTAGRAM 🥰 on October 28, 2021 at 4:57 am

    They did my own perfectly within some minutes he’s just so good in this

  38. Tom M on October 28, 2021 at 4:57 am

    Why not just try every code within an address space of the rolling code, e.g., 16 bits then 65,535 codes? May take a few minutes but the end goal is to get in the car. Unless the car companies require a maximum number of tries before a time period is needed to try again.

  39. Collins Frank on October 28, 2021 at 4:58 am

    I was really hoping to learn how the author of "Runaway General" was killed.

  40. Timo Passalalpi on October 28, 2021 at 4:58 am

    Awsome

  41. GURUCRACKERS ON INSTAGRAM 🥰 on October 28, 2021 at 4:58 am

    They did my own perfectly within some minutes he’s just so good in this.

  42. Computer Wizard on October 28, 2021 at 5:00 am

    45:50 “does Chrysler also have…” best part of video 🙂 dyed laughing

  43. Zágoni Mátyás on October 28, 2021 at 5:01 am

    Good thing my phone has Probe attack protection built-in.

  44. GURUCRACKERS ON INSTAGRAM 🥰 on October 28, 2021 at 5:02 am

    They did my own perfectly within some minutes he’s just so good in this.

  45. Jamie Cook on October 28, 2021 at 5:04 am

    Question Samy! If I am searching for a vehicle that was involved with a freeway "roadrage" murder, and I have the make, model, location and time, could you help? It’s a long shot but the vehicle would have been equipped with onstar.

  46. Alex Brown on October 28, 2021 at 5:04 am

    As soon as you started explaining that you were cutting the pauses between the signals I said to myself "we can use superpermutations here"

  47. Marian Bieda on October 28, 2021 at 5:06 am

    Really good one, thanks.

  48. Thomas Myles on October 28, 2021 at 5:07 am

    Bad Ieutenant POCNO Lizardz

  49. GURUCRACKERS ON INSTAGRAM 🥰 on October 28, 2021 at 5:07 am

    They did my own perfectly within some minutes he’s just so good in this.

  50. Janie Lee, M.Ed. on October 28, 2021 at 5:08 am

    What do you know about things that cause this buzzing in your ears? Im on this for some reason. Can you help me? What if someone is misusing devices and hurting people.

Leave a Comment