Black Hat 2007 Other Wireless

posted Aug 2nd 2007 1:07pm by Eliot Phillips
filed under: cons, peripherals hacks


Luis Miras presented “Other Wireless: New ways of being Pwned”. Instead of common con topics like Bluetooth or WiFi, this dealt with the cheap radios used in wireless keyboards, mice, and things like the wireless remote pictured above. These RX/TX pairs are found in 27MHz, 900MHz, and 2.4GHz versions. The devices all use the same main components: a microcontroller, an EEPROM for storing the serial number, and the transmitter. The dongle is nearly the same only with a receiver.

Luis began reversing a Kensington Wireless Presenter by first visiting the FCC website. All radio devices have to be evaluated by them. Just type in the FCC number on the bottom of the device and in some cases you might even get a full schematic. He could then grab datasheets for the radios. By adding your own microcontroller you can send arbitrary key presses to the dongle or you could tap the RX side and easily create a sniffer. To reverse the protocol though you’ll need an oscilloscope or even better a logic analyzer.

He demoed a replay attack: sending the page up command repeatedly. Unfortunately the hacked wireless presenter doesn’t have a full keycode space so you can’t send it arbitrary keystrokes. Luis still needs to break the wireless keyboard encryption scheme in order to create a useful key sniffer though.

Recent Posts

hack a day serves up a fresh hack each day, every day from around the web and a special how-to hack each week.

send us your hacks

have a hack you'd like to see here? tell us about it



hacks

  • aibo hacks (1)
  • cellphones hacks (82)
  • cons (78)
  • contests (30)
  • daily (122)
  • digital audio hacks (19)
  • digital cameras hacks (72)
  • downloads hacks (16)
  • gameboy hacks (35)
  • google hacks (6)
  • gps hacks (37)
  • HackIt (20)
  • handhelds hacks (62)
  • home entertainment hacks (145)
  • home hacks (21)
  • how-to (16)
  • ipod hacks (75)
  • laptops hacks (53)
  • laser hacks (32)
  • macs hacks (40)
  • misc hacks (831)
  • news (204)
  • pcs hacks (147)
  • peripherals hacks (187)
  • playstation hacks (52)
  • podcasts (8)
  • portable audio hacks (43)
  • portable video hacks (27)
  • robots hacks (107)
  • roundup (3)
  • security hacks (56)
  • solar hacks (2)
  • tablet pcs hacks (6)
  • tivo hacks (6)
  • tool-hacks (10)
  • transportation hacks (91)
  • Uncategorized (320)
  • wii hacks (18)
  • wireless hacks (84)
  • xbox hacks (51)
  • resources

    rss newsfeeds

    powered by wordpress