hacking & clonning my garage key with URH ( Universal radio Hacker ) and ARDUINO DIGISPARK + FS1000A

  Рет қаралды 26,851

justanengineer

justanengineer

Күн бұрын

Пікірлер
@jjancar7729
@jjancar7729 Жыл бұрын
Thank you very much friend for the explanation, making the Arduino program available, very grateful. I tell you, you can measure the pause directly in the schedule by zooming in (to obtain more precision) and marking the interval to be measured with the mouse, this way we do without the calculator. Greetings
@justanengineer5599
@justanengineer5599 Жыл бұрын
thanks !
@krautkopp
@krautkopp Жыл бұрын
Thank you so much for this video! I tried before to built an opener for two door garage in the house that I live in but miserably failed. But with your video and code I finally could built something that actually works. The main problem was to decode the very vintage SKX1MD transmitter with URH. If someone else is struggling with those very vintage but in older houses still common transmitters, just let me know 🙂 My working prototype is based on an Arduino Uno R3, which works great. I now will build a smaller version using an Arduino nano and attach it to the USB port of my Vespa Primavera - no more fiddling with keys and searching for remotes which don't work with gloves anyway. Try that with a Flopper-Zero 😄 I really gave up on this until I found your youtube channel. Thank you!
@justanengineer5599
@justanengineer5599 Жыл бұрын
check my newest project here kzbin.info/www/bejne/o5XOdn6VrNKKgKM and here kzbin.info/www/bejne/n4G5lJ6hic-mmpI you will have the Master Key !
@yankovalsky7696
@yankovalsky7696 Ай бұрын
Dzięki za film. Zrobiłem coś podobnego w formie pilota kopiującego (esp32, rxb6, syn115, oled + przyciski). Na razie testuję i poprawiam. Heterodyna potrzebuje chwili na dostrojenie zanim zacznie odbierać poprawnie sygnał, więc przydałby się sdr, żeby odbierać pełny przebieg, łącznie z początkiem transmisji. Czy miałeś może do czynienia z nowszą wersją odbiornika rtl-sdr, tj. v3 lub v4?
@justanengineer5599
@justanengineer5599 Ай бұрын
nie, jeszcze ne bawiłem się V3 i V4 ale chyba zainwestuję w to parę złotych
@yankovalsky7696
@yankovalsky7696 Ай бұрын
@@justanengineer5599, czaję. Spotkałem się z informacją, że v4 jest "głucha" powyżej 100 MHz w porównaniu do v3 i tak wiesz, dopytuję tu i tam, ludzi, którzy mogą mieć o tym pojęcie, hehe. Zaglądam co tam tworzysz, nie tak dawno jutub objawił mi ten kanał. Pozdro.
@masterkush9829
@masterkush9829 10 ай бұрын
i have a question, but the MX-5V reciver can recive key fob signal?
@justanengineer5599
@justanengineer5599 10 ай бұрын
yes MX-RM-5V is a receiver compatible with FS1000A. It can receive keyfob signal but you need the program to record it. Unfortunatelly you cannot use Universal Radio Hacker
@xprisyt2702
@xprisyt2702 Жыл бұрын
Hi, your work is very nice, I have been following you for a long time. With Arduino and 433mhz receiver, I copied the fix code and opened my door immediately. But is it possible to make a project that can flow rolling/hopping codes and write to the LCD screen with Arduino and cc1101 or other RF modules? I can do this as a project for my son at university. I want to have it done.sadece garage door or barrier ..not for car key.At least I have a rolling code, which RF module can I use to read the code of the remote control? Without using sdr/rtl. Thanks.
@justanengineer5599
@justanengineer5599 Жыл бұрын
try to build my latest cc1101-tool. it can record few keypresses of original key. I do not plan to add lcd sceeen because a smartphone can be used to store sequences in some notepad
@forxan
@forxan 2 жыл бұрын
Hi everyone, I would like to be able to receive the signal from a controller with an HCS301 (MICROCHIP KeeLoq) in the transmitter and with a PICxxx or an ATMELxxx in the receiver. There is a library for ARDUINO about receiving
@bennguyen1313
@bennguyen1313 2 жыл бұрын
Wow, very nice! This seems more automated than doing the decoding visually, using inspectrum etc. What kind of signals (frequencies?) don't work with URH, and must be done some other way? For example, if the car uses rolling keys, that means you would have to generate a unique key every time, or could you just toggle thru a set of valid keys? Any plans to use an SDR for the transmission part? I've seen some low(ish) cost SDRs.. for example, the $70 Caribou (a hat for the RPi), or the LimeSDR.
@justanengineer5599
@justanengineer5599 2 жыл бұрын
The limitation ( if any ) comes from RTL-SDR dongle used especially in terms of frequency range that can be monitored / decoded. The URH software actually supports most of modulation types like FSK, AAK/OOK, GMSK and most SDR devices... You may also want to go through the manual github.com/jopohl/urh/releases/download/v2.0.0/userguide.pdf Most of cars are using not only rolling code but pseudorandom seed for code generation en.wikipedia.org/wiki/Remote_keyless_system - that's why replay attack is not working for them, only rolljam attack. I do not have SDR for the transmission part. But If you are considering transmitting spoofed radio data I would suggest to use combination of two boards CC1101 + Arduino Pro Micro (3.3V / 8 MHz version ) as I am doing in my 10$ CC1101 jammer here in my video kzbin.info/www/bejne/rIvGeINjhJd6rLM You do not need specialized devices like Evilcrow RF or Yardstick One or Hack RF for transmission actually... If you look into my Arduino sketch here : raw.githubusercontent.com/mcore1976/cc1101-jammer/main/arduino-pro-micro-cc1101-jammer-v2.ino you will see that you can do all of it in very easy way with any type of required modulation , frequency , preamble, encoding etc... by setting those values with few commands on the beginning of the code and putting your sequence to be send in the command : // send these data to radio over CC1101 ELECHOUSE_cc1101.SendData("my decoded key values!!!"); Good Luck!
@wakis4179
@wakis4179 3 жыл бұрын
Hello very good video however I did not understand how you activate the remote control I see that the remote control is connected with a power bank for the power supply but did you configure a push button on the arduino to launch the code or the simple fact plugging in the arduino starts the code?
@justanengineer5599
@justanengineer5599 3 жыл бұрын
Hi. For simplicity there was no push button. It activates when connected to 5V usb powerbank. Arduino bootloader starts the code and sends radio signal immediately.
@BrianHall
@BrianHall 3 жыл бұрын
I thought garage door openers rotated their codes each time you press the button. Your opener seems to use a static code each time. Is that common?
@justanengineer5599
@justanengineer5599 3 жыл бұрын
There are different models of garage openers. Yes, the one I have uses static code. However this method of hacking can be used also for rolling codes. You would need to record more sequences to discover the algorythm of code generation. The URH tool is helping with reverse engineering of the coding
@saundergroundmb9007
@saundergroundmb9007 3 жыл бұрын
Hey can have your email adem thnks
@matchke7054
@matchke7054 3 жыл бұрын
@@justanengineer5599 is this some of the Aluprof remotes?
@costarica4502
@costarica4502 3 жыл бұрын
@@justanengineer5599 Very Nice job, may be another tutorial with rolling code ? ; )
@tobiasxy1230
@tobiasxy1230 3 жыл бұрын
@@justanengineer5599 Wow... Can you show it in a video, how to reverse rolling code with the URH? It would be exciting... 😉 Please.
@MJ-pp3rs
@MJ-pp3rs 2 жыл бұрын
In my case, the way works but one-time, because I have rolling keys. Now I have recorded several sequences. Where can I find information on how to analyze the algorithm in URH?
@justanengineer5599
@justanengineer5599 2 жыл бұрын
I would suggest to look into this document here github.com/jopohl/urh/releases/download/v2.0.0/userguide.pdf
@tobiasxy1230
@tobiasxy1230 3 жыл бұрын
Hello. This is a perfect video thanks. It helps me... But I have a problem with showing the sample rate... It shows only Pause: the time in ms. How can I change this for showing samples?
@tobiasxy1230
@tobiasxy1230 3 жыл бұрын
Sorry... I have the solution. The samples are the summary of each Bit in the row per sequence... It doesn't show me automatically, I have to mark all the bits and then I see the summary.
@purple_bey
@purple_bey 3 жыл бұрын
thanks
@zoboloff
@zoboloff 2 жыл бұрын
Hi Adam, Thanks for you tuto. I've a 867 MHz key that I would like to clone for educational purpose. What would be the associated module as you are using 1 x FS1000A module for 433 MHz freq ? I have already save the *.wav with my remote impulses ...
@justanengineer5599
@justanengineer5599 2 жыл бұрын
Hi. I can not find FS1000A supporting 868/867 MHz , there are only CC1101 based modules supporting it You need to look for something that supports OOK / ASK modulation with single DATA INPUT pin without SPI bus. Alternatively you may use CC1101 based module and the library from Litle s@tan for CC1101 (the one I am using to build the jamer)
@worldmusic8941
@worldmusic8941 Жыл бұрын
​@@justanengineer5599 can i run the code with arduino leonardo? Second question? void setup() { } void loop() { tone(8, 15000); // generate square wave } Does it work too? For me no
@philippe930
@philippe930 3 жыл бұрын
merci Adam. est-ce qu'il existe des fs1000a en 868Mhz. Tuto très intéressant continue
@justanengineer5599
@justanengineer5599 3 жыл бұрын
Le module 433,92 MHz FS1000A fonctionne très bien à sa deuxième fréquence harmonique 868 MHz
@boofboikarti3235
@boofboikarti3235 3 жыл бұрын
What if we record multiple times , can u show how to analyze multiple attemps(key fob presses) or is it the same process!?!?
@justanengineer5599
@justanengineer5599 3 жыл бұрын
Yes it is the same process. Multiple recordings are actually needed if you have rolling code in the keys
@황휘동-o8t
@황휘동-o8t 2 жыл бұрын
hi You can see that it works with the RF transimitter 315Mhz-green. I have a question here. I wonder if this project is possible with the NRF24L01 module I have. I am trying to upload a program to Arduino by sniffing the automatic door.
@justanengineer5599
@justanengineer5599 2 жыл бұрын
this code will not work with NRF24L01 however I am thinking how to adopt this design to work with this module and jam the drones and other devices operating on wifi frequency
@GunsandGuitars69
@GunsandGuitars69 2 жыл бұрын
@@justanengineer5599 could just do that with Aircrack. Does this program work with the HackRF One?
@akinci8892
@akinci8892 7 ай бұрын
​@@justanengineer5599Hey can we use NRF24L01 with esp32 instead of Arduino?
@lelumpolelum3085
@lelumpolelum3085 2 жыл бұрын
How did you manage to setup the exact required frequency during the transmission?
@justanengineer5599
@justanengineer5599 2 жыл бұрын
the FS1000A always sends on the same frequency as builtin SAW generator module (433.92 in my case). For wireless keys same set of band is used in many countries - either 433.92 or 315MHz see here en.m.wikipedia.org/wiki/Remote_keyless_system . Anyway if you wish to tune to different frequency and have more flexibility you would have to use CC1101 instead like I am showing in my recent video for the jammers. On my github you may find CC1101 projects using SmartRC library which you can easily adopt in order to clone any type of wireless key Please watch this video : kzbin.info/www/bejne/rIvGeINjhJd6rLM and see this Arduino script : github.com/mcore1976/cc1101-jammer/blob/main/arduino-pro-MINI-cc1101-jammer-v2.ino You may set any modulation frequency encoding and payload there according to what you decoded with Universal Radio Hacker tool. Good Luck !
@lelumpolelum3085
@lelumpolelum3085 2 жыл бұрын
@@justanengineer5599 Thanks and I have a bonus question. Whenever I try to find the pulse length on my signal it is different for 0 and 1. 0 has a pulse length between 343 and 350 us and 1, between 400 and 420. It also varies slightly when I analyse the preamble and the payload. Is that a significant difference or should I just stick to one pulse length for all my calculations?
@justanengineer5599
@justanengineer5599 2 жыл бұрын
basically symbol lengths should be constant for ASK/OOK modulation. It is possible that additional Manchester encoding is in use that causes some distraction in URH decoder. Try to decode the signal by selecting different type of modulation
@lelumpolelum3085
@lelumpolelum3085 2 жыл бұрын
@@justanengineer5599 You know, honestly I think it's just some type of protocol of rolling code. I will try to find mine and will get back to you if I succeed. Thanks for the replies.
@aruzat
@aruzat 2 жыл бұрын
Hi man, if i using a CC1101 to copy and replay the signal. It's posible? thnks!
@justanengineer5599
@justanengineer5599 2 жыл бұрын
it is possible. I will be doing such video
@aruzat
@aruzat 2 жыл бұрын
@@justanengineer5599 Oh brother, thank you very much!! your channel is incredible, congratulations :)
@forxan
@forxan 2 жыл бұрын
Hola a tod@s, Me gustaría poder recibir la señal de un mando con un HCS301 (KeeLoq de MICROCHIP) en el emisor y con un PICxxx o un ATMELxxx en el receptor. Hay una librería para ARDUINO sobre recibir la señal de un HCS301 y otra para emitir la señal de un HCS301, pero no lo encuentro... sigo a la búsqueda. Un saludo a todos
@xckiikc
@xckiikc 2 жыл бұрын
How do you get the "pulse" value?
@justanengineer5599
@justanengineer5599 2 жыл бұрын
well you need to count as I am doing it in my video
@The_Auther
@The_Auther 3 жыл бұрын
what device is this to activate the digispark...
@justanengineer5599
@justanengineer5599 3 жыл бұрын
Normal PC (with Linux Mint in my case, but it can be also Windows PC) is used to program the Digispark unit. Digispark has connected the FS1000A module as 433MHz ASK transmitter. The URH is using the RTLSDR USB dongle to capture and decode wireless keyfob, then I am able to re-write the code for Arduino / Digispark to send appropriate radio sequence to open garage doors.
@The_Auther
@The_Auther 3 жыл бұрын
@@justanengineer5599 I ask at the end of the video to activate the digispark, it's a normal charger...
@justanengineer5599
@justanengineer5599 3 жыл бұрын
Yes, it is a normal 5Volts usb powerbank/charger with ON/OFF switch and LED indicator
@user-gj6dw3ot1u
@user-gj6dw3ot1u 2 жыл бұрын
Does this method work with car keys?
@justanengineer5599
@justanengineer5599 2 жыл бұрын
yes but for old cars, only for wireless keys that Do Not have rollover code
@DudeINeedWater
@DudeINeedWater Жыл бұрын
jak skopiować klucze do Flippera Zero
@justanengineer5599
@justanengineer5599 Жыл бұрын
Nie mam tego narzędzia, kosztuje az 2 tysie. Ale z tego co widzę w środku ma chip cc1101 albo ekwiwalent więc pewnie ma tryb nagrywania komunikacji jednak musisz za pomocą Universal Radio Hacker dowiedziec sie co to za czestotliwosc modulacja itd
@For_the-love_of_physics
@For_the-love_of_physics 3 жыл бұрын
Can we make this with Arduino.
@For_the-love_of_physics
@For_the-love_of_physics 3 жыл бұрын
kzbin.info/www/bejne/Y4mVhGqvpr-hmLs .....
@justanengineer5599
@justanengineer5599 3 жыл бұрын
It is made with arduino digispark. You can make it with any arduino.
@For_the-love_of_physics
@For_the-love_of_physics 3 жыл бұрын
@@justanengineer5599 I don't know the code
@justanengineer5599
@justanengineer5599 3 жыл бұрын
The code is available on github. Have you checked the description of the video? The link is there : Link to my example sketch : github.com/mcore1976/urh-arduino-cloning-keys Link to the tool : github.com/jopohl/urh
@For_the-love_of_physics
@For_the-love_of_physics 3 жыл бұрын
@@justanengineer5599 kzbin.info/www/bejne/hmObf5aGq66Kns0 Do you know to make this
@imadeddine3844
@imadeddine3844 2 жыл бұрын
Can you steal the car key sign??
@justanengineer5599
@justanengineer5599 2 жыл бұрын
with URH yes you can record it. But remember that car keys are using rolling codes
@imadeddine3844
@imadeddine3844 2 жыл бұрын
@@justanengineer5599 So how is the solution?
@justanengineer5599
@justanengineer5599 2 жыл бұрын
yardstick one
@DudeINeedWater
@DudeINeedWater Жыл бұрын
how about flipper zero
@justanengineer5599
@justanengineer5599 Жыл бұрын
if you have 500 usd go ahead. this clonnig costs 5 usd
@DudeINeedWater
@DudeINeedWater Жыл бұрын
@@justanengineer5599 ziom kupiłem na joomie za 900 zł, Polacy sprzedają dwa razy drożej
@Falin1989
@Falin1989 Жыл бұрын
for the same price? i'm in!
I Hacked Into My Own Car
20:29
Steve Mould
Рет қаралды 2,8 МЛН
Hacking My Ceiling Fan Radio Signal With a $15 USB TV Tuner (RTL2832U)
7:20
River's Educational Channel
Рет қаралды 17 М.
黑天使只对C罗有感觉#short #angel #clown
00:39
Super Beauty team
Рет қаралды 36 МЛН
1% vs 100% #beatbox #tiktok
01:10
BeatboxJCOP
Рет қаралды 66 МЛН
It’s all not real
00:15
V.A. show / Магика
Рет қаралды 20 МЛН
Universal Radio Hacker - Replay Attack With HackRF
9:30
Tech Minds
Рет қаралды 123 М.
Universal Radio Hacker SDR Tutorial on 433 MHz radio plugs
12:05
#44 Hacking and Cloning a Garage Door Opener using SDR Radio
11:39
Andreas Spiess
Рет қаралды 151 М.
3 Levels of WiFi Hacking
22:12
NetworkChuck
Рет қаралды 2,3 МЛН
黑天使只对C罗有感觉#short #angel #clown
00:39
Super Beauty team
Рет қаралды 36 МЛН