Latest Samy Kamkar hack unlocks cost cars and many garage door openers

Kedis82ZE8

'15 CX-5 AWD GT w/Tech Pkg
Contributor
Latest Samy Kamkar hack unlocks most cars and many garage door openers

https://threatpost.com/gone-in-less-than-a-second/114154

LAS VEGASDo not let Samy Kamkar near your car.

Kamkar has built a new device that is about the size of a wallet and can intercept the codes used to unlock most cars and many garage doors. The device can be hidden underneath a vehicle and when the owner approaches and hits the unlock button on her key or remote, the device grabs the unique code sent by the remote and stores it for later use.

Known as Rolljam, the device takes advantage of an issue with the way that vehicles that use rolling codes for unlocking produce and receive those codes. Kamkar said that the device works on most vehicles and garage doors that use rolling, rather than fixed, codes. Under normal circumstances, when a driver hits the unlock button her remote, it sends a rolling code to the vehicle. The car recognizes the code and unlocks. These codes are one-time-use only, and a vehicle wont accept a code that its seen before in order to prevent a thief from intercepting the signal and replaying it later. Vehicles that use rolling codes also will invalidate all previous codes when they receive a new code.

Kamkars Rolljam device gets around these defenses by jamming the signal from the remote so the vehicle never hears it.

So when you are walking towards your car, you hit the unlock button because its jammed, the car cant hear it, however my device is also listening so my device hears your signal (and removes the jamming signal because it knows what to remove). Now I have a rolling code that your car has not yet heard, Kamkar said via email.

Then you press unlock again because it didnt work the first time, and I jam again, and listen, and now have two codes. However, at this point I replay the FIRST code I listened to from your key and your car successfully unlocks. To the user/owner, it appears the 2nd time pressing it worked because it happens so quickly (less than a second to jam/sniff+replay). However, I now have the NEXT rolling code in the sequence that hasnt been used yet. I can come back later and conveniently unlock your car. Because I leave the device under your car, it always has the latest code.

The Rolljam device is small now, but Kamkar said he plans to tweak it even further and will get it down to the size of a typical car remote. The device is built from about $30 in hardware, Kamkar said, and he plans to reveal more details about it at DEF CON here Friday. The attack he developed also works on garage door openers that use rolling codes.

This is the second time in the last few months that Kamkar has taken aim at the codes on garage doors. In June he released research that showed he could open any garage door that uses a fixed code in less than 10 seconds. That OpenSesame attack used a toy communicator to send signals to the garage door opener.

And just last week Kamkar released a device called OwnStar that enables him to intercept the traffic from a phone running the OnStar RemoteLink mobile app and locate, unlock, and remotely start a vehicle with OnStar.
 
Last edited:
Garage doors opener

We mostly prefer to fix garage doors and garage doors openers to provide safety and security to our cars and vehicles.But there can be many hackers and hacking systems are available which may unlock our well protected garage doors that can harm our property.But this device may be useful for other purposes also and that's why it has been made.
 
Would it be true that this would not be an issue if one had keyless entry (or whatever it's called with the button on the door handle) and didn't use the remote to unlock the doors?
 
Doesn't matter what you have or drive, if it's locked it can be opened.
 
Meanwhile, thieves continue to have luck with their sophisticated "screwdriver to the window frame" technique...
 
Back