Flipper Zero vs Ford F150 (Key Fob Playback Attack)

preview_player
Показать описание
Rolling code protection makes key fob playback attacks difficult but not impossible.

Can it be done? Yes, but its not a practical attack vector because you need physical access to the key fobs already.

Most vehicles now have more sophisticated security than this.

I'm use to working with RF with spectrographic analyzers. When I was using this I misunderstood that the graph display in the SubGhz record function is in the time domain, not the frequency domain.
Рекомендации по теме
Комментарии
Автор

So those days are in the past unless you’re a 2018 Honda civic with that really bad CVE. I so appreciate your demonstration man! Super cool to see a DOS. Honestly I like the use case at the end about locking your buddy out after he’s been drinking. Honestly not a bad idea!

Deven
Автор

I love how you are the only person I've seen that will tell others it will block your key out from working if it's used it before. I did this and now my key won't work

sr-xveu
Автор

came for the flipper stayed for the tool

jakes
Автор

So Basically save a code that was played before then lock them out there Car making the fob undetectable then play the Replay of the one earlier

timteddy
Автор

You can use this to block someone from entering their Ford, or wait for them to get frustrated, go inside and get the other remote and then copy that as well and wait again a few days to come back do the denial and then play back the previous code from the other remote.

MICHIGANLIFEWITHDOGS
Автор

The digital little lights the ones that you keep poking on to he's going to put the same amount of pressure on your eyeball with or without the eyelid

tanielleoconnor
Автор

I came for the Flipper Zero, I stayed because of Tool in the background.

samaeltartaro
Автор

Well explained! I kept being distracted by the awesome Tool song though 😂

Fleamang
Автор

Interesting, I was thinking of buying one to play around. One question, if you cause DoS when someone park the car but did not pressed the key fob yet, the “victim” will not be able to lock the car right?

caueb
Автор

If you bring your car for servicing. They can copy a few signal away from the car and use it at a later date since they know where you live now

TheFlatEarthChannelcom
Автор

Thanks this is useful information explained clearly.

olliehayman
Автор

Now if you could only add the F0 as a new keyfob to the system.

tonysolar
Автор

Putting the key in the ignition and staring the vehicle seems to reset the fob

DKsupreme
Автор

What happens to the key that’s on lockdown?

ppdripz
Автор

Thanks for interesting video.
How much is average or maximum recieving distance from keyfob to hackrf in Urban conditions?
You also press long the button. In real life, the owner of the car just clicks one time and that's all.
Does this sdr simply send the same code that recieved or can also modify it?
For instance if sdr accepted signal "lock", can it send signal "unlock" ?
How to deal with that

dimitridimitri
Автор

Damn. I have two of these. I'd like to get mine working for my ford as a backup but I only have the one fob lol

khayrobs
Автор

so what ur saying is, if u can get a fob far enough away from the car, read& record the unlock. u could then us that unlock providing u use it before the keyfob u recorded from

Dnephilly
Автор

So you copy lock and unlock from both remotes. Won't you DOS both of them? I have a vehicle with two remotes and i'd like to copy signals from both, but I'm scared to DOS them both. I'm a bit confused!

Chupabrah
Автор

Ive heard lots of people are getting locked out of their own car while tinkering with a flipper, its a good learning lesson, you shouldn't be trying to use the same methods of pentesting on everything you can get your hands on. It helps to do some research first, so you at least have an understanding of what you are doing or what might happen. Doing that would have prevented your vehicle getting locked out, or worse consequences if you are messing with another persons property. You can go around pressing buttons using the flipper with malicious intent on others if you like, but you take full responsibility, not the ones who wrote the code or the ones on youtube videos explaining how to do it.

cdrealist
Автор

How did you get a Flipper in the US? They don’t ship to the US as far as I’ve checked the last few months

gothops