DEF CON Forum Site Header Art

Announcement

Collapse
No announcement yet.

DEFCON 27 Badge "No RF signature" SDR replay attack

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • DEFCON 27 Badge "No RF signature" SDR replay attack

    Here's a quick write-up of our efforts to communicate with the badge using a HackRF One and magnetic loop antenna (RFEAN25).

    Rename GRC_and_PY_files.7z.pdf to GRC_and_PY_files.7z and extract using 7zip for GRC files.

    We also have a 966MB of capture files (all badge types) looking for hosting.

    Other useful information:
    https://www.futureelectronics.com/re...etic-induction
    Attached Files

  • #2
    Do you have that picture of the home brew antenna you showed me vs. what a real probe looks like?
    PGP key: dtangent@defcon.org valid 2020 Jan 15, to 2024 Jan 01 Fingerprint: BC5B CD9A C609 1B6B CD81 9636 D7C6 E96C FE66 156A

    Comment


    • skintigh
      skintigh commented
      Editing a comment
      I made a very effective one wrapping magnet wire around the tip needle-nosed pliers.

  • #3
    Would it be possible to drop the files into a google drive account? I'm interested in doing some analysis on that data you have. I also have some python code to generate messages (based on the original badge source code) and will be adding the modulation / demodulation scheme to your code that I'd like to test. I'm using a HackRF One and either the same sensor you used (RFEAN25), a whip antenna (not sure the model) or will make one to get better sensitivity in the right frequency range. The fact that the other group was able to get a good signal with a spool of what appears to be 30 AWG is pretty darn cool. The one you guys were using seems to suffer a bit in sensitivity at the lower frequency ranges (< 100 MHz) and I'm curious about what kind of distance I can get with the badge.

    P.S. - I'm that lady from Texas, super cool to see the work posted here. Hope your arm is getting better.

    Comment


    • skintigh
      skintigh commented
      Editing a comment
      I just ordered a cheap SDR to do exactly this. Have you had any good results?
Working...
X