DEF CON 26 IoT VILLAGE - David Tomaschik - Im the One Who Doesnt Knock Unlocking Doors from Network
4,164 views · Published 21 November 2018 · 38:12 · Indexed 1 October 2026
Channel: DEFCONConference · 2018 · Science & Technology
In 2017, I discovered that a popular IP-based door access control system (badge reader and door lock controller) used poorly-implemented cryptography. Through binary analysis and live testing against a functional device, I was able to construct an exploit that would unlock the door without talking to the central authority database or logging the door open event. I'll walk the audience through the steps that made me realize there was a problem, through the binary analysis, and then finally into building a working exploit.
More from this channel
-
7:53
DEF CON 20 Documentary Bonus Clips - CDC muxed
-
47:43
DEF CON 20 - Raphael Mudge - Cortana: Rise of the Automated Red Team
-
43:15
DEF CON 20 - Peter Hannay - Exchanging Demands
-
25:01
DEF CON 20 - Ryan Holeman - Passive Bluetooth Monitoring in Scapy
-
48:14
DEF CON 20 - Xeno Kovah and Corey Kallenberg - No More Hooks
-
51:04
DEF CON 20 - Panel - The Making of DEF CON 20
-
50:01
DEF CON 20 - Josh "m0nk" Thomas and Jeff "stoker" Robble - Off-Grid Communications with Android
-
48:06
DEF CON 20 - Mark Weatherford - The Christopher Columbus Rule and DHS