Unlock Cars with a Raspberry Pi And SDR - Replay attack

Поделиться
HTML-код
  • Опубликовано: 27 окт 2024
  • НаукаНаука

Комментарии • 161

  • @faithinverity8523
    @faithinverity8523 Год назад +16

    As an over-65 electronics nerd it warms my heart to watch a young person use TERMUX to ssh to an RPi and run a PWM signal out to a make-shift antenna on GPIO4. So marvelously geeky. Thanks and God bless.

  • @g0fvt
    @g0fvt 5 лет назад +43

    Fascinating, I have all the bits to try this... except our cars having rolling code

    • @M4CHINE69
      @M4CHINE69 4 года назад +6

      Is it where the code changes everytime so no one can record the old data then replay it

    • @g0fvt
      @g0fvt 4 года назад +1

      @@M4CHINE69 in a word yes

    • @anthonyc3915
      @anthonyc3915 4 года назад +13

      Ok so I believe in your case with a rolling code you want to use a jammer in conjunction with your sniff and repeat. I believe by jamming the key fobs rf from making it to the vehicle and you simultaneously grabbing the code .. That code you just snatched is still good for a use. I'm an idiot though some 1 please correct me if im wrong.

    • @g0fvt
      @g0fvt 4 года назад +3

      @@anthonyc3915 that would seem a logical approach and in principle should work

    • @rajairfan7679
      @rajairfan7679 4 года назад

      @@anthonyc3915 Hy i need your help give your number plz

  • @china_white_
    @china_white_ Год назад

    I love your video !! U did such a great step by step instructions unlike everybody else tryna explain making this device

  • @HiPh0Plover1
    @HiPh0Plover1 5 лет назад +15

    you didnt think it was useful to do the vid during the day light

  • @maxwellcrafter
    @maxwellcrafter 3 года назад +1

    Neat, I'll have to try this out when I get the chance

  • @jayweezy3264
    @jayweezy3264 4 года назад +7

    so does this basically preform the same thing as a hackrf would withkey fobs?

  • @hahayoucaughtme824
    @hahayoucaughtme824 4 года назад +5

    I just bought all of the pieces can't wait to try it out!

    • @robintewolde1992
      @robintewolde1992 4 года назад +3

      Did it work?

    • @trillboijose
      @trillboijose 4 года назад +2

      Update?

    • @hahayoucaughtme824
      @hahayoucaughtme824 4 года назад +6

      I’m getting an error code... I can capture the signal but can’t replay. From what I have heard this is a problem with the latest release of the program.

    • @robintewolde1992
      @robintewolde1992 4 года назад +1

      @@hahayoucaughtme824 alright. That is bad. Are they gonna fix it ? Or is there a work around ?

  • @udaysharan8977
    @udaysharan8977 4 года назад +1

    Awesome Video thanks for sharing this video

  • @dandwrasan2342
    @dandwrasan2342 5 лет назад +1

    What a fantastic vid and so well put together 👍🏻😊 I have a plutosdr can I do your experiment with it ?

  • @eniggma9353
    @eniggma9353 6 месяцев назад

    very interesting presentation.

  • @hackwithtech5323
    @hackwithtech5323 5 лет назад +3

    In my case it show invalid samplerate warning failed to set center frequency and then started capturing please help

  • @hackwithtech5323
    @hackwithtech5323 5 лет назад +2

    Just subsribed thanks for this i have been searching for this from very long time. but can you please tell me what is the samplerate you use after you get error plz tell me ?

  • @e1Pr0f3ss0r
    @e1Pr0f3ss0r 5 лет назад

    I have watched this video very awesome...
    There is no alternate video on RUclips on this topic...
    Thank you very much

  • @dienadel30
    @dienadel30 5 лет назад +3

    All I saw was a light. On a SEN DIQ command hehe.. My name is Klaus !

  • @hustlersinnovation2085
    @hustlersinnovation2085 2 года назад

    Very educational

  • @siddharth4662
    @siddharth4662 5 лет назад +5

    i doubt if it will work with the Roll keys FOB

  • @9b_vajra4
    @9b_vajra4 4 года назад +1

    why when i enter the cmake comand, it shows
    bash: cmake: command not found

  • @nicolasperezmolina491
    @nicolasperezmolina491 4 года назад +1

    How can i connect my pi through SSH? and do you use a band pass filter?

  • @Яська_Гаспадар_з-пад_Вільні

    Great! What's your car model?

  • @Robert08010
    @Robert08010 Год назад

    Is the "e6" like scientific notation for the fact that the freq was in mHz instead of Hz?

  • @boiclyde
    @boiclyde 5 лет назад +3

    Do you think a Zero would have the power for this?

  • @themonkeyminds7252
    @themonkeyminds7252 5 лет назад

    Very nice sir ...keppe it up ...peace:)

  • @nilsonvidenoff7811
    @nilsonvidenoff7811 5 лет назад +1

    hi moderham could you explain or desglozar the numbers 25000 the g35
    and the e6 in "rtl_sdr -s 25000 -g 35 -f 315.0125e6 filename.iq"

  • @jimmygerilius8494
    @jimmygerilius8494 5 лет назад +4

    I thought the RTL-SDR was only a receiver. How did you transmit on 315/433 MHz ?

    • @ModernHam
      @ModernHam  5 лет назад +6

      The wire attached to the raspberry pi makes it an fm transmitter...

    • @ModernHam
      @ModernHam  5 лет назад +4

      Not the RTL SDR but the pi itself.

    • @arvindsamy49
      @arvindsamy49 5 лет назад +3

      @@ModernHam Hello. How is it possible ? Raspberry has a 433Mhz integrated tramitter ?

  • @NicksStuff
    @NicksStuff 5 лет назад

    I would have bet that such a modern (2006) car had a rolling code!

  • @elvedinbegovic1717
    @elvedinbegovic1717 5 лет назад +1

    Does it work on rolling code (if the car is keyless) if you replay the signals when you are near the car. Can you pull the door handle so the car unlocks?

    • @maikel5642
      @maikel5642 5 лет назад +7

      i don't think so but if you record the keyfob while not in the car's range it should work

  • @gerritsmit346
    @gerritsmit346 2 года назад

    Will this work with other PI models?

  • @williamsonrobert6354
    @williamsonrobert6354 4 года назад

    Isnt there any way to automatically detect The Magic number???

  • @tissentissen7245
    @tissentissen7245 5 лет назад

    Nice video. Does it unlock rolling codes too?

    • @Savage.735
      @Savage.735 5 лет назад +1

      You will will be amazed want it can do with a little help but not on RUclips laws i have a lot to share win the time is right

    • @tissentissen7245
      @tissentissen7245 5 лет назад

      @@Savage.735 You want to share somethig? May be we talk via email?

    • @excitedbox5705
      @excitedbox5705 5 лет назад +5

      @@tissentissen7245 all you do is jam the signal to the car while recording (point a second antenna at the car transmitting white noise with more power than the key does). then when the person hits the button a second time thinking the car didn't catch it, you resend the first code so the person sees the car blink and lock, and keep the second code for once they walk away. Nothing fancy to it like that kid wants to pretend. It works because you will have 2 valid codes that the car never received. Then when you send the first one, the second becomes the active code. On newer cars there may be some more processing to do because the car sends the fob a code back that is used to generate the next code.

    • @tissentissen7245
      @tissentissen7245 5 лет назад

      @@excitedbox5705 hank you for contacting me. Is it possible to use jammer and sdr or one full duplex device for this purpose? - unlocking/replay rolling code of car
      can we contact via email? Your time will be highly appreciated. thanks,

    • @mwlulud2995
      @mwlulud2995 2 года назад

      @@excitedbox5705 yes but how can your jam the signal and at the same time capture it on the raspberry in addition to that the car uses AM signals and sends on two frequencies at the same time... A tutorial from you would be nice!

  • @e1Pr0f3ss0r
    @e1Pr0f3ss0r 5 лет назад +3

    How can i contact u for asking some Questions and taking guidelines...

    • @e1Pr0f3ss0r
      @e1Pr0f3ss0r 5 лет назад +3

      Plz reply just don't like my comments

  • @hackwithtech5323
    @hackwithtech5323 5 лет назад +3

    Help when i transmit it shows caught transmitting 1c and after that nothing happens please help

    • @robintewolde1992
      @robintewolde1992 5 лет назад

      Did u get it to work? i still have a issue with transmitting.

  • @aidangray9082
    @aidangray9082 3 года назад

    Will the raspberry pi zero w work for this?

  • @jbzhitz
    @jbzhitz 3 года назад

    No we shouldn’t already know what programs to use or how if we’re trying to learn how to read radio frequencies and how to setup this device. If we did then why would we need ur video? Thx for teaching this to people that already understand it.

    • @ModernHam
      @ModernHam  3 года назад +4

      What I didn't explain is the most basic concepts of how to operate a raspberry pi. You can find that in 1000 tutorials around the internet. This is RF hacking, not "how to use linux for dummies" . If you don't know how to install an operating system, you need to start there. I'm not here to hold your hand plugging in a power adapter and formatting an SD card

  • @johnygreen2123
    @johnygreen2123 3 года назад

    Can we do this job with just a laptop with kali linux and SDR? do we need to have Raspberry Pi ?

  • @gvnt7004
    @gvnt7004 3 месяца назад

    please make an updated version 2024

  • @mandc20022
    @mandc20022 4 года назад

    Can I use a laptop hooked to a rtlsdr

  • @DDBAA24
    @DDBAA24 5 месяцев назад

    should be on the back of all key fobs, if not check the fcc database 👍

  • @jimikailby7902
    @jimikailby7902 5 лет назад +1

    nice

  • @dandwrasan2342
    @dandwrasan2342 5 лет назад

    Can I do this with a Arduino instead of the pi using 433mhz transmitters

    • @ModernHam
      @ModernHam  5 лет назад

      I think this would be possible. But you would need different software obviously for your transmitter.

  • @mrluis2328
    @mrluis2328 3 года назад

    ./sendiq command not found

  • @dandwrasan2342
    @dandwrasan2342 5 лет назад

    Can I do this with a Arduino instead of the pi

  • @e1Pr0f3ss0r
    @e1Pr0f3ss0r 5 лет назад +1

    Can i use this "Leoie USB2.0 FM DAB DVB-T RTL2832U R820T2 RTL-SDR SDR Dongle Stick"?

  • @user-ze4ub6ci2c
    @user-ze4ub6ci2c 5 лет назад +1

    Great idea but it's more simple with HackRF One

    • @ModernHam
      @ModernHam  5 лет назад +2

      Some want simple, but this is intended for those who want to actually learn how it's done. After all, the "simple" way wouldn't need a video demonstration. This shows more of what happens behind the scenes when you run those scripts made for you on the hackrf

    • @user-ze4ub6ci2c
      @user-ze4ub6ci2c 5 лет назад

      @@ModernHam Thanks ;)

    • @dandwrasan2342
      @dandwrasan2342 5 лет назад +1

      Baki Hanma hi I have some some questions about hackrf and replay attack

    • @user-ze4ub6ci2c
      @user-ze4ub6ci2c 5 лет назад

      @@dandwrasan2342? 😇

    • @e1Pr0f3ss0r
      @e1Pr0f3ss0r 5 лет назад

      Buying Hackrf one is not so simple as u thinking...
      this method is very much easier and comfortable for an common user...

  • @Cristasphoto
    @Cristasphoto 3 года назад

    The FBI liked this video lol I kid I kid.

  • @ericweiss7473
    @ericweiss7473 4 года назад +1

    This doesnt work bro, you dont even have a band pass filter. It just creates noise. thats probably why its shot in the dark so no one can see you unlocking it with the key fob. Id like to see the fft of the replay and maybe the demoded wave form in audacity or something

    • @ModernHam
      @ModernHam  4 года назад +3

      Yeah you're right, I made a thirty minute video to fake unlocking a car for youtube for no reason using an actual method. All the people saying it worked are all just bots I had comment here.

    • @bugzbunny3223
      @bugzbunny3223 4 года назад

      Lol ppl are funny

  • @katana-rl7gb
    @katana-rl7gb 5 лет назад

    Does this work well with Pi 0 w?????

    • @GamingKing545
      @GamingKing545 4 года назад

      probably just use the same connections

  • @hackwithtech5323
    @hackwithtech5323 5 лет назад

    Can we use arduino uno instead of rasberry pi?

    • @ModernHam
      @ModernHam  5 лет назад +1

      giving it the ability to transmit is a little harder. There's a tutorial here : www.instructables.com/id/RF-315433-MHz-Transmitter-receiver-Module-and-Ardu/

    • @hackwithtech5323
      @hackwithtech5323 5 лет назад

      ModernHam thanks brother keep making videos we love your videos

  • @zamsheikh3418
    @zamsheikh3418 5 лет назад +1

    pi@raspberrypi:~/rtl-sdr/build $ cmake ../ -DINSTALL_UDEV_RULES=ON
    -bash: cmake: command not found

  • @Un_Pour_Tous
    @Un_Pour_Tous 5 лет назад

    Can one use a audio amp to extend signal TX on rpitx? I notice it uses that PWM.

  • @atmel9077
    @atmel9077 5 лет назад

    There already are publications about the vulnerabilities of car keyless entry, but those rather showed the weaknesses of their proprietary undocumented "cryptography". But here this is much worse!!! There is NO rolling code AT ALL!!!

    • @ModernHam
      @ModernHam  5 лет назад

      Whats worse is the "cryptography" used is basically the same as generating a hash and matching it against the cars to see if it "belongs".
      This still leaves the possibility of recording dynamic keys, and jamming the frequency in such a way they they never make it to the car, leaving that key open to use at any time in the future.

    • @atmel9077
      @atmel9077 5 лет назад

      @@ModernHam This attack is called "RollJam" and was invented by Samy Kamkar, but, before knowing about this I imagined that I coule record 2 signals while jamming some of the last bits (let's say 4) so I now have two valid rolling codes with the last 4 bits missing. I then transmit my first code with the 16 different combinations, one of which is valid and will lock the car. and the owner will think that the car is successfully locked after the 2nd press. But now I have another valid code with 4 missing bits and I can time again try all 16 combinations and unlock the car.
      *This only works if the lock/unlock button is the same. On many cars it's not however many garage door openers use the same button.

  • @rawexploiterp6951
    @rawexploiterp6951 Год назад

    when was r-pi was 30 bucks...

  • @GamingKing545
    @GamingKing545 4 года назад

    instead of ssh just use a screen thats what i use

  • @e1Pr0f3ss0r
    @e1Pr0f3ss0r 4 года назад

    I am getting error with " sudo ./sendiq commant not found" what should i have to do?

  • @hackwithtech5323
    @hackwithtech5323 5 лет назад

    Bro i am not able to buy raspberry pi 3 can i use raspberry pi zero with wifi ?

    • @ModernHam
      @ModernHam  5 лет назад

      According to github.com/F5OEO/rpitx the PiZero is compatible.

    • @hackwithtech5323
      @hackwithtech5323 5 лет назад

      Thank you for info keep making videos

  • @whereveryouare6334
    @whereveryouare6334 5 лет назад

    raspberry pi zero can ?

    • @mihirkatoch1110
      @mihirkatoch1110 5 лет назад +1

      If you are able to connect rtl sdr with it.

  • @clashofracks6143
    @clashofracks6143 5 лет назад

    Did they update rpitx or something. Everything worked fine but sendiq.sh isn’t in it. So I can’t send the iq file to my car. Did I do something wrong or did they take it out.

    • @ModernHam
      @ModernHam  5 лет назад

      Not that I know of. Are you sure you issued the command within the rpitx folder? I haven't updated mine.

    • @clashofracks6143
      @clashofracks6143 5 лет назад

      Yeah look at their github page. sendiq.sh isn’t there

    • @clashofracks6143
      @clashofracks6143 5 лет назад

      @ModernHam is it possible you copy the code from sendiq.sh and paste it in the comments so I can use it.

    • @chriskaprys
      @chriskaprys 5 лет назад +1

      i set this up today, with v2 of rpitx. sendiq is there, it's just not called sendiq.sh ... it's simply sendiq, without the .sh suffix.

    • @clashofracks6143
      @clashofracks6143 5 лет назад

      I didn’t I must’ve missed a step or something. A day after I set it up(without sendiq) my raspberry pi wouldn’t boot correctly. Did you have this problem

  • @marn200
    @marn200 4 года назад

    $ make
    make: *** No targets were specified and no makefile found. Stop.
    Now, I dit=d see a Makefile.am but that did nothing

  • @cynicaltonez
    @cynicaltonez 4 года назад

    Can u put more then one fob in and can u do it faster 😂

  • @afktree8961
    @afktree8961 2 года назад

    Loud ass intro 🤦🏿‍♂️

  • @Savage.735
    @Savage.735 5 лет назад

    amazing i done it before but another way love to see more maybe we can bring things to light for people that don't believe in real life hacks that R so easy to pull off really cheap and it is not a reality it is happening every day as long as you have a little brain lots of my friends say i be doing to much but win show them day like you need to be working for a security company or something i also have a book coming out this summer i will get back at you on it this summer nice

    • @ModernHam
      @ModernHam  5 лет назад

      Cool stuff! Do Let me know!

    • @clashofracks6143
      @clashofracks6143 5 лет назад

      Your grammar is horrible.

    • @9999-h5p
      @9999-h5p 5 лет назад

      @@ModernHam hello, can you help me in finishing such project? Can we talk via email?

  • @ajzalnoorudheen3366
    @ajzalnoorudheen3366 3 года назад

    Fake

  • @teufeltuna1956
    @teufeltuna1956 2 года назад

    Or, or, just get a Flipper Zero...

  • @ahr0cdovlzk3my1lahqtbmftdw7
    @ahr0cdovlzk3my1lahqtbmftdw7 5 лет назад

    scriptkiddy

  • @stacyhoff9287
    @stacyhoff9287 5 лет назад +1

    Im reporting you

    • @0MVR_0
      @0MVR_0 4 года назад +8

      For unlocking your own car.

  • @MR_RANDOM_PROJECTS
    @MR_RANDOM_PROJECTS Год назад

    Can some one please help me I can’t get pasted cmake ../ -DINSTALL

  • @e1Pr0f3ss0r
    @e1Pr0f3ss0r 5 лет назад

    I have watched this video very awesome...
    There is no alternate video on RUclips on this topic...
    Thank you very much