HackRF ONE PortaPack H2+ Car Key Signal - Unlock Car Key FOB

  Рет қаралды 42,385

TAKEAPART

TAKEAPART

Күн бұрын

Пікірлер: 104
@takeapart
@takeapart Жыл бұрын
MUST SEE! check out www.youtube.com/@takeapart/videos
@rogersmith4926
@rogersmith4926 5 күн бұрын
What would you recommend, Flipper zero or Mayhem?
@takeapart
@takeapart 5 күн бұрын
flipper is way more versatile!
@MrCtfx
@MrCtfx Жыл бұрын
But with the rolling code can you open or close it only once?
@takeapart
@takeapart Жыл бұрын
yes… but you can record multiple codes
@MrCtfx
@MrCtfx Жыл бұрын
@@takeapart and here I don't understand: suppose I save a dozen codes after 6 the opening signal with the original remote control is sent to the control unit, will the other 6 signals still be valid?
@takeapart
@takeapart Жыл бұрын
that’s depends on manufacturer…. but mostly rest of the 6 captures won’t work.
@MrCtfx
@MrCtfx Жыл бұрын
@@takeapartI don't quite understand this attack: hack rf will jam by blocking the original remote control, the Flipper Zero will record the codes. The problem is if the owner were to open the car he can always do it manually with the lock and then he will leave: For closing the Flipper will be able to record the codes but if it is only a closing signal how will I open the car?
@JReinhoud
@JReinhoud 2 ай бұрын
​​@@MrCtfxthat is why the rolling keys are basically pretty save and car manufacturers haven't responded (yet). But in theory you could hide close to a car with rolling keys and if a person did want to open his car with his keyfob and you saved and also blocked the rf signal to make it to the car and somehow the owner forgot he wanted to open the car, you could come back later to open the car and rip something out of it. Or if you have access to a keyfab for a limited time you could record it, and possible dont even have to jam because they keyfob is probably out of range, you could access the car (if the owner hadn't already) and rip something out of it. But if you already had access to the keyfob and want to rip something it would probably make more sense to just rip the keyfob also which will probably help you more cause you now are sure you can enter the vehicle unless he is sure it is stolen en puts his car in a more protected environment for instance his garage. So that leaves only the first example somewhat plausible but not likely. And with that example it is more likely that someone places a device near a place the car will often or very likely park and you record long enough till the keyfob was triggered accidentely. But by viewing only rf you will never know it was by accident so you also need a camera or some other way you would know that to make use of that. If you would be sure the incoming key was blocked and no other keys are tried to open or close the car you could maybe make an educated guess that the keyfob was triggered by accident or the owner changed his mind about entering the car and did think he/she was out of range. I also dont know if a closing key will render a good (and unused) recorded opening key useless. Because that will probably happen when the owner changed his mind and will probably press the closing knob till he sees the lights or hears the locking sound. So in the end it will be more likely someone breaks into your car without keys, or steals your keyfab or bruteforces enough keys to enter your vehicle. I dont know if that last part is even a possibility with the rolling keys technique, because it probably resets itself whenever bad keys are received but I think it is possible because a keyfob is also (or can be) out of sync when a key is already used, but I have read story's that users got them working again when pressing enough times again on the keyfob
@anthonyrickardii6198
@anthonyrickardii6198 Ай бұрын
Awesome example and amazing device. Question! Dumb questions too. When you turn it on and want to play a prank on my brother how can I tell what frequency it’s on in order to make it work? Does automatically does it for you ?
@Runner-t3b
@Runner-t3b Ай бұрын
hello how can we create an attack relay without having to press the key? could you tell me what material to buy? thanks
@DryUrEyesMate
@DryUrEyesMate 2 күн бұрын
How an i use this to stop or jam the key signal to stop car theft
@takeapart
@takeapart 2 күн бұрын
unfortunately you can not
@technologyreviews3620
@technologyreviews3620 14 күн бұрын
But can you write the files to a new remote so you can give the owner of the car a spare key?
@takeapart
@takeapart 13 күн бұрын
NO
@EWASTEANDGOLD
@EWASTEANDGOLD 3 ай бұрын
I’m having problems getting it replay captures but no idea why do u need specific aerial or setting
@takeapart
@takeapart 3 ай бұрын
for cleaner RX TX
@Adam-qd8jh
@Adam-qd8jh 2 ай бұрын
You will need to cut and trim your antenna for the best SWR “standing wave ratio”. If you transmit with an antenna with a high impedance “resistance to RF” all of that power will radiate back into your transmitter blowing the amplifier and damaging your radio. That’s why it’s best to have an antenna cut to the right frequency. And also if you just want to play around without worrying I would get a 50 ohm dummy load or make your own with resistors. But you will not got any range with a dummy load just up close but lastly,Just make sure the dummy load you buy is rated for the right amount of power.
@matijabensa
@matijabensa 5 ай бұрын
Nice try but this will work only if you capture the key that wasn't used before, that's why you had to move outside the range.
@takeapart
@takeapart 5 ай бұрын
correct ✅
@Karpakurva
@Karpakurva 5 ай бұрын
what means 'wasn't use'? A key thet was never connected to the car? Before the first use?
@haizaki5012
@haizaki5012 4 ай бұрын
@@Karpakurvathe signal sent was 0005, the car didn’t received it ever, so the first time it received it was from the device, thats what i understood but not sure
@eljam8138
@eljam8138 Жыл бұрын
Nice content ! just started playing around ! when capturing it didnt save anything. wonder why
@takeapart
@takeapart Жыл бұрын
hi, maybe wrong SD card … try different types
@zipit-media
@zipit-media Жыл бұрын
2014 Kia Optima EX, 2010 Lexus 250h... Rolling codes, So I said in the car while It started and grab captures for opening. No luck! Got a suggestion?
@takeapart
@takeapart Жыл бұрын
you have to be far away from car….(capturing key signal) make sure to be outside of the range so the car won’t receive the key signal… only you will capture it. Then you can replay it and it should work.
@zipit-media
@zipit-media Жыл бұрын
Unfortunately it's not working, away from the car 35M outside... Then I get to the car nothing. Does it matter what the antenna is? @@takeapart
@takeapart
@takeapart Жыл бұрын
@zipit-media 35m is still not far enough…. standard range is about 200m ! (in clear line of sight)
@zipit-media
@zipit-media Жыл бұрын
@@takeapart I did 300m, nothing. So you need to see the car 200m?
@heikosoeder
@heikosoeder Жыл бұрын
Jamm the signal with the hackrf and record with flipper or jamm wirt a quansheng.
@billyjoe3309
@billyjoe3309 4 ай бұрын
Can you do replay attacks on 2.4ghz band as well?
@takeapart
@takeapart 4 ай бұрын
sure can , but what use ?
@billyjoe3309
@billyjoe3309 4 ай бұрын
@@takeapart What's the use of doing replay on car keys? Many things run on 2.4Ghz. So the HackRF Repaly you do in the video, can go up to the 2.4Ghz band as well, not just the 433 you played with? :)
@dripstein6130
@dripstein6130 10 ай бұрын
is there a possible way to do brute force with unlocking a car? or is it only possible with capture
@takeapart
@takeapart 10 ай бұрын
maybe for very old aftermarket car alarm systems …..
@honestlocksmith5428
@honestlocksmith5428 8 ай бұрын
Absolutely!
@ahmaddanish2307
@ahmaddanish2307 5 ай бұрын
So the first thing to is search the frequency and capture that ? Sorry i still newbie
@takeapart
@takeapart 5 ай бұрын
yes, but capture it far away from the car
@Karpakurva
@Karpakurva 5 ай бұрын
@@takeapart why near car does'nt help?
@FYP420
@FYP420 Жыл бұрын
How does this work for my keyless entery audi ?
@takeapart
@takeapart Жыл бұрын
hi, it should as hack rf is working from like 1MHz
@omegadroidzero
@omegadroidzero Жыл бұрын
You are going to brick your key FOB. Audi has rolling codes.
@NicolasAlvesDias
@NicolasAlvesDias 6 ай бұрын
but how hack rf one produced rolling code ? as it expires after 1 use by key ? idk if im wrong please correct me
@takeapart
@takeapart 6 ай бұрын
hack rf doesn’t produce rolling codes… please rewatch the video
@jamesbarratt593
@jamesbarratt593 12 күн бұрын
So you sneak out the bush and open the car. Only you ain't got the transponder to start the car so you get arrested in the car.
@takeapart
@takeapart 12 күн бұрын
nobody is talking about stealing someone’s car … video is about opening the car
@tiltedchris847
@tiltedchris847 Жыл бұрын
Hi One question maybe you can help me. I have a portapack h3 and tried to jam the key fob signal. I'm running the correct frequency (imo, analyzed it with the flipper zero) but if I press unlock on the key the car still opens. So there is no signal jamming
@AndresDeMoya
@AndresDeMoya Жыл бұрын
Hi, new to the HackRF scene, but from what I've been reading, the HackRF doesn't have a lot of amplification power, so maybe that's what it's going on, the key is overpowering the HackRF's signal. I've just started messing with it, but I had a similar issue.
@pinklensfb
@pinklensfb 9 ай бұрын
you need a rf amplifier
@ogodogo7319
@ogodogo7319 5 ай бұрын
Hi Bro i have problem whene I go to (replay/open playlist/captures ) i don t find nothing you can help me please i have hacker rf
@takeapart
@takeapart 5 ай бұрын
I think in some fw version there is different folder where hackrf saves captured files. check other folders
@EvgeniX.
@EvgeniX. Жыл бұрын
but can it do a RollJam?
@takeapart
@takeapart Жыл бұрын
absolutely! check out my other video!
@honestlocksmith5428
@honestlocksmith5428 8 ай бұрын
Roll jams are unnecessary.
@EvgeniX.
@EvgeniX. 8 ай бұрын
@@honestlocksmith5428 really?! Did you just invented a new wonderful technique of dealing with rolling codes, that makes the good old roll jam unnecessary? If so, share your finding with the audience here, i bet everyone will be glad to hear 🧐
@bushmaster101
@bushmaster101 Жыл бұрын
Dont you need to install a costom firmware?
@takeapart
@takeapart Жыл бұрын
this os called Mayhem
@qallafabdullah
@qallafabdullah Жыл бұрын
Anyone had the issue where after doing this. The car key fob won’t lock/unlock the car? Cuz thats what I’m dealing with rn I have an old volvo
@takeapart
@takeapart Жыл бұрын
you have to gooogle how to relearn key fob on …. some cars does that (not just cars… garage remotes and others )
@JReinhoud
@JReinhoud Жыл бұрын
thats because the unlock 'code' will change on both the car and normally the FOB. But because you used the portapack to unlock, the car is ahead in the codes. Maybe it will never catch up by its own cause it needs part of the code to keep it in line with each other, but that is just a guess. I had the same problem and after unlocking with the key the manual way (turning the door lock) and also power on the dashboard with my key, the FOB worked again. Or it was the many times I tried unlocking and locking the car with the FOB that eventually resetted it, or brought it back in line again. It is one or the other, maybe both. For reference, it was a VW Caddy 2005 model I tested.
@omegadroidzero
@omegadroidzero Жыл бұрын
You bricked it because of rolling code security.
@grzesiektabul
@grzesiektabul 9 ай бұрын
something doesn't feel right here... the turn signals don't flash when opening...
@takeapart
@takeapart 9 ай бұрын
yes they do flash
@BrainstechKnowlogy
@BrainstechKnowlogy Жыл бұрын
Cool!
@takeapart
@takeapart Жыл бұрын
thanks buddy
@takeapart
@takeapart Жыл бұрын
have you seen other videos? I have seen quite a lot of viral vids there ….
@HEX1337x
@HEX1337x 8 ай бұрын
It is also possible to turn on the car?
@takeapart
@takeapart 8 ай бұрын
@HEX1337x probably, but only aftermarket remote start systems….
@HEX1337x
@HEX1337x 8 ай бұрын
@@takeapart what you mean as aftermarket?
@UfukKay
@UfukKay Жыл бұрын
If I will prank my friends, how can I capture without to get the key ?
@takeapart
@takeapart Жыл бұрын
hhh not possible… unless you spy on your friends and wait until they press keyfob button
@johnsandlin09
@johnsandlin09 3 ай бұрын
How do you make one
@takeapart
@takeapart 3 ай бұрын
make what?
@juddcarey
@juddcarey Жыл бұрын
How do you find out original frequency of key fob?
@takeapart
@takeapart Жыл бұрын
with frequency analyzer…
@bnk28zfp
@bnk28zfp Жыл бұрын
so you trew up key close to car😮 i wannna know how car talk to key))) but thank you!!!!! 😮
@takeapart
@takeapart Жыл бұрын
Im not 100% sure what you mean … but thanks for watching
@bnk28zfp
@bnk28zfp Жыл бұрын
@@takeapart i need to know what kind hadrware can emulate the key near car!!!!!
@takeapart
@takeapart Жыл бұрын
I have bunch of videos on this topic… check them out.
@bnk28zfp
@bnk28zfp Жыл бұрын
because my honda if i have key in my poket i can open door ill unlock by it self !!!!
@takeapart
@takeapart Жыл бұрын
it depends… some cars using different communications for this. but most combination or just subGhz standard fob buttons
@JokerInstalls
@JokerInstalls 9 ай бұрын
Why did the lights flash with the Flipper but not the HackRF?
@takeapart
@takeapart 9 ай бұрын
Hi, I think back door wasn’t properly closed…
@teodorpocs
@teodorpocs 10 ай бұрын
How did you got the right frequency?
@takeapart
@takeapart 10 ай бұрын
easy … EU - 433.92
@teodorpocs
@teodorpocs 10 ай бұрын
@@takeapart Thank you! For an unknown device that the frequency is not public information for?
@takeapart
@takeapart 10 ай бұрын
@teodorpocs use frequency analyzer
@Arekadiusz
@Arekadiusz 7 ай бұрын
It's a completly nosense, one-time use only.
@takeapart
@takeapart 7 ай бұрын
AKA rolling codes
@Arekadiusz
@Arekadiusz 7 ай бұрын
@@takeapart So 99% of nowadays RF devices. So it's more for "test" purposes than actual "offensive" ones.
@Потомпоидумаю
@Потомпоидумаю 9 ай бұрын
Двери открой у машины
@takeapart
@takeapart 9 ай бұрын
stay tuned for that
@jeffreybrunken556
@jeffreybrunken556 Жыл бұрын
👍🏻
@takeapart
@takeapart Жыл бұрын
thanks
@ГарикФарфоров
@ГарикФарфоров Жыл бұрын
My HackRF ONE PortaPack H2 after turning off erases all recordings (Capture) and after the next turn on, only play beep and carrier frequency. Interesting, should it be? How do I save my capture recordings?
@Dread_Pirate_Homesteader
@Dread_Pirate_Homesteader 9 ай бұрын
SD CARD
@Saphira_Paix
@Saphira_Paix Жыл бұрын
yeah with the own keys like ownhotel rooms - pointless. make it at a stranger
I Hacked Into My Own Car
20:29
Steve Mould
Рет қаралды 2,8 МЛН
Rolljam Attack Flipper Zero & HackRF Car Unlock
4:25
TAKEAPART
Рет қаралды 30 М.
She made herself an ear of corn from his marmalade candies🌽🌽🌽
00:38
Valja & Maxim Family
Рет қаралды 18 МЛН
Tuna 🍣 ​⁠@patrickzeinali ​⁠@ChefRush
00:48
albert_cancook
Рет қаралды 148 МЛН
Cat mode and a glass of water #family #humor #fun
00:22
Kotiki_Z
Рет қаралды 42 МЛН
Cheerleader Transformation That Left Everyone Speechless! #shorts
00:27
Fabiosa Best Lifehacks
Рет қаралды 16 МЛН
The new HackRF Portapack H4M
10:10
sn0ren
Рет қаралды 77 М.
CANBUS APP USING OBDII FUNCTIONALITIES
4:54
Electronic Cats
Рет қаралды 2 М.
✅ HackRF Portapack H2: Looking Glass Beginner Guide (See All The Things)
24:17
🥷 RTP Tech Tips 📡
Рет қаралды 47 М.
GPS Spoofing With The HackRF On Windows
8:49
Tech Minds
Рет қаралды 109 М.
Mayhem 2.1.0 for Portapack H4M or H2
13:25
Jeremiah of All Trades
Рет қаралды 9 М.
I Broke My HackRF Portapack! Here's How Not to
8:11
sn0ren
Рет қаралды 40 М.
HackRF One H4M Creating a Remote
10:24
PenTest
Рет қаралды 4,1 М.
This Flipper Zero GPIO Board Does EVERYTHING!!!
20:17
Talking Sasquach
Рет қаралды 64 М.
She made herself an ear of corn from his marmalade candies🌽🌽🌽
00:38
Valja & Maxim Family
Рет қаралды 18 МЛН