{"guid":"1a9291bf-dab5-4824-8b20-ecb393c677a8","title":"Unlocked: PICing a wireless door access system","subtitle":null,"slug":"37c3-12265-unlocked_picing_a_wireless_door_access_system","link":"https://events.ccc.de/congress/2023/hub/event/unlocked_picing_a_wireless_door_access_system/","description":"Mainframe, Oldenburg's Hackerspace, needed a wireless door lock solution. We do not trust vendors advertising promises about the device security and had a closer look.\n\nAttend this talk for a presentation about an unusual variant of lock picking, which does not involve any wrenches, hooks or half-diamond picks. Instead the used tools are a software defined radio, PIC programmer and some self-developed software to gain access without using the original key remote control.\n\nIf you had fun watching the [Hörmann BiSecur talk at 34C3](https://media.ccc.de/v/34c3-9029-uncovering_vulnerabilities_in_hoermann_bisecur), this talk is for you! If you haven't watched it, it is highly recommended to catch up on it before attending this talk. While it is about a different product from a different vendor, there are many parallels and it can be seen as a sequel talk.\n\nThe plan for this talk is to first have a look at the radio signals from the door lock using a SDR. After making sense of the used message protocol, the hardware is analyzed to understand how it works and how to get access to the used micro-controllers (PIC18LF45K80 \u0026 PIC16LF1829). In the next step, the firmware from the read-protected PIC microcontroller is extracted by extending the existing PIC attacks. Last but not least the results will be demonstrated.","original_language":"eng","persons":["sre"],"tags":["37c3","12265","2023","Security",""],"view_count":2801,"promoted":false,"date":"2023-12-29T21:45:00.000+01:00","release_date":"2023-12-30T00:00:00.000+01:00","updated_at":"2026-04-01T15:00:11.107+02:00","length":2327,"duration":2327,"thumb_url":"https://static.media.ccc.de/media/congress/2023/12265-1a9291bf-dab5-4824-8b20-ecb393c677a8.jpg","poster_url":"https://static.media.ccc.de/media/congress/2023/12265-1a9291bf-dab5-4824-8b20-ecb393c677a8_preview.jpg","timeline_url":"https://static.media.ccc.de/media/congress/2023/12265-1a9291bf-dab5-4824-8b20-ecb393c677a8.timeline.jpg","thumbnails_url":"https://static.media.ccc.de/media/congress/2023/12265-1a9291bf-dab5-4824-8b20-ecb393c677a8.thumbnails.vtt","frontend_link":"https://media.ccc.de/v/37c3-12265-unlocked_picing_a_wireless_door_access_system","url":"https://api.media.ccc.de/public/events/1a9291bf-dab5-4824-8b20-ecb393c677a8","conference_title":"37C3: Unlocked","conference_url":"https://api.media.ccc.de/public/conferences/37c3","related":[],"recordings":[{"size":23,"length":2327,"mime_type":"audio/opus","language":"deu","filename":"37c3-12265-deu-Unlocked_PICing_a_wireless_door_access_system_opus-2.opus","state":"new","folder":"opus-translation","high_quality":false,"width":0,"height":0,"updated_at":"2023-12-30T17:15:18.852+01:00","recording_url":"https://cdn.media.ccc.de/congress/2023/opus-translation/37c3-12265-deu-Unlocked_PICing_a_wireless_door_access_system_opus-2.opus","url":"https://api.media.ccc.de/public/recordings/73283","event_url":"https://api.media.ccc.de/public/events/1a9291bf-dab5-4824-8b20-ecb393c677a8","conference_url":"https://api.media.ccc.de/public/conferences/37c3"},{"size":35,"length":2327,"mime_type":"audio/mpeg","language":"deu","filename":"37c3-12265-deu-Unlocked_PICing_a_wireless_door_access_system_mp3-2.mp3","state":"new","folder":"mp3-translated","high_quality":false,"width":0,"height":0,"updated_at":"2023-12-30T17:15:04.193+01:00","recording_url":"https://cdn.media.ccc.de/congress/2023/mp3-translated/37c3-12265-deu-Unlocked_PICing_a_wireless_door_access_system_mp3-2.mp3","url":"https://api.media.ccc.de/public/recordings/73282","event_url":"https://api.media.ccc.de/public/events/1a9291bf-dab5-4824-8b20-ecb393c677a8","conference_url":"https://api.media.ccc.de/public/conferences/37c3"},{"size":null,"length":null,"mime_type":"application/x-subrip","language":"eng","filename":"DRAFT_37c3-12265-eng-deu-Unlocked_PICing_a_wireless_door_access_system.en_DRAFT.srt","state":"todo","folder":"","high_quality":true,"width":null,"height":null,"updated_at":"2024-02-04T13:01:35.066+01:00","recording_url":"https://cdn.media.ccc.de/congress/2023/DRAFT_37c3-12265-eng-deu-Unlocked_PICing_a_wireless_door_access_system.en_DRAFT.srt","url":"https://api.media.ccc.de/public/recordings/74865","event_url":"https://api.media.ccc.de/public/events/1a9291bf-dab5-4824-8b20-ecb393c677a8","conference_url":"https://api.media.ccc.de/public/conferences/37c3"},{"size":234,"length":2327,"mime_type":"video/webm","language":"eng-deu","filename":"37c3-12265-eng-deu-Unlocked_PICing_a_wireless_door_access_system_webm-hd.webm","state":"new","folder":"webm-hd","high_quality":true,"width":1920,"height":1080,"updated_at":"2024-01-01T11:53:24.274+01:00","recording_url":"https://cdn.media.ccc.de/congress/2023/webm-hd/37c3-12265-eng-deu-Unlocked_PICing_a_wireless_door_access_system_webm-hd.webm","url":"https://api.media.ccc.de/public/recordings/73614","event_url":"https://api.media.ccc.de/public/events/1a9291bf-dab5-4824-8b20-ecb393c677a8","conference_url":"https://api.media.ccc.de/public/conferences/37c3"},{"size":122,"length":2327,"mime_type":"video/webm","language":"eng-deu","filename":"37c3-12265-eng-deu-Unlocked_PICing_a_wireless_door_access_system_webm-sd.webm","state":"new","folder":"webm-sd","high_quality":false,"width":720,"height":576,"updated_at":"2024-01-01T11:40:55.303+01:00","recording_url":"https://cdn.media.ccc.de/congress/2023/webm-sd/37c3-12265-eng-deu-Unlocked_PICing_a_wireless_door_access_system_webm-sd.webm","url":"https://api.media.ccc.de/public/recordings/73577","event_url":"https://api.media.ccc.de/public/events/1a9291bf-dab5-4824-8b20-ecb393c677a8","conference_url":"https://api.media.ccc.de/public/conferences/37c3"},{"size":118,"length":2327,"mime_type":"video/mp4","language":"eng-deu","filename":"37c3-12265-eng-deu-Unlocked_PICing_a_wireless_door_access_system_sd.mp4","state":"new","folder":"h264-sd","high_quality":false,"width":720,"height":576,"updated_at":"2023-12-30T17:15:57.442+01:00","recording_url":"https://cdn.media.ccc.de/congress/2023/h264-sd/37c3-12265-eng-deu-Unlocked_PICing_a_wireless_door_access_system_sd.mp4","url":"https://api.media.ccc.de/public/recordings/73285","event_url":"https://api.media.ccc.de/public/events/1a9291bf-dab5-4824-8b20-ecb393c677a8","conference_url":"https://api.media.ccc.de/public/conferences/37c3"},{"size":22,"length":2327,"mime_type":"audio/opus","language":"eng","filename":"37c3-12265-eng-Unlocked_PICing_a_wireless_door_access_system_opus.opus","state":"new","folder":"opus","high_quality":false,"width":0,"height":0,"updated_at":"2023-12-30T15:42:27.313+01:00","recording_url":"https://cdn.media.ccc.de/congress/2023/opus/37c3-12265-eng-Unlocked_PICing_a_wireless_door_access_system_opus.opus","url":"https://api.media.ccc.de/public/recordings/73179","event_url":"https://api.media.ccc.de/public/events/1a9291bf-dab5-4824-8b20-ecb393c677a8","conference_url":"https://api.media.ccc.de/public/conferences/37c3"},{"size":35,"length":2327,"mime_type":"audio/mpeg","language":"eng","filename":"37c3-12265-eng-Unlocked_PICing_a_wireless_door_access_system_mp3.mp3","state":"new","folder":"mp3","high_quality":false,"width":0,"height":0,"updated_at":"2023-12-30T15:40:52.565+01:00","recording_url":"https://cdn.media.ccc.de/congress/2023/mp3/37c3-12265-eng-Unlocked_PICing_a_wireless_door_access_system_mp3.mp3","url":"https://api.media.ccc.de/public/recordings/73178","event_url":"https://api.media.ccc.de/public/events/1a9291bf-dab5-4824-8b20-ecb393c677a8","conference_url":"https://api.media.ccc.de/public/conferences/37c3"},{"size":281,"length":2327,"mime_type":"video/mp4","language":"eng-deu","filename":"37c3-12265-eng-deu-Unlocked_PICing_a_wireless_door_access_system_hd.mp4","state":"new","folder":"h264-hd","high_quality":true,"width":1920,"height":1080,"updated_at":"2023-12-30T14:56:25.926+01:00","recording_url":"https://cdn.media.ccc.de/congress/2023/h264-hd/37c3-12265-eng-deu-Unlocked_PICing_a_wireless_door_access_system_hd.mp4","url":"https://api.media.ccc.de/public/recordings/73139","event_url":"https://api.media.ccc.de/public/events/1a9291bf-dab5-4824-8b20-ecb393c677a8","conference_url":"https://api.media.ccc.de/public/conferences/37c3"},{"size":244,"length":2327,"mime_type":"video/mp4","language":"deu","filename":"37c3-12265-deu-Unlocked_PICing_a_wireless_door_access_system.mp4","state":"new","folder":"h264-hd","high_quality":true,"width":1920,"height":1080,"updated_at":"2023-12-30T14:56:19.190+01:00","recording_url":"https://cdn.media.ccc.de/congress/2023/h264-hd/37c3-12265-deu-Unlocked_PICing_a_wireless_door_access_system.mp4","url":"https://api.media.ccc.de/public/recordings/73138","event_url":"https://api.media.ccc.de/public/events/1a9291bf-dab5-4824-8b20-ecb393c677a8","conference_url":"https://api.media.ccc.de/public/conferences/37c3"},{"size":244,"length":2327,"mime_type":"video/mp4","language":"eng","filename":"37c3-12265-eng-Unlocked_PICing_a_wireless_door_access_system.mp4","state":"new","folder":"h264-hd","high_quality":true,"width":1920,"height":1080,"updated_at":"2023-12-30T14:56:11.798+01:00","recording_url":"https://cdn.media.ccc.de/congress/2023/h264-hd/37c3-12265-eng-Unlocked_PICing_a_wireless_door_access_system.mp4","url":"https://api.media.ccc.de/public/recordings/73137","event_url":"https://api.media.ccc.de/public/events/1a9291bf-dab5-4824-8b20-ecb393c677a8","conference_url":"https://api.media.ccc.de/public/conferences/37c3"}]}