There is Always One More Bug - or More: Revisiting a Wireless Alarm System

No ratings

Presented at Hacktivity2020 2020 by

Developers of IT systems have known for a long time that there is still one more bug to be found – or at least this is often humorously attributed to various IT products, no matter whether they are soft-, firm-, or hardware.In this talk, SySS IT security expert Matthias Deeg shows that this assumption is sometimes very true, using the example of a wireless alarm system and its accessories, in which yet another security vulnerability could been found over the past few years – more than once.Based on various concrete vulnerabilities of different types, practical experience gained in penetration tests as well as research projects at SySS regarding the security analysis of radio-based systems will be presented, and the following three descriptive attacks will be demonstrated on a revisited wireless alarm system:1) Rolling code attack2) Proximity key cloning attack3) Reactive jamming attack4) Sniffing attack5) Spoofing attack