Comment on Flipper Zero 'DarkWeb' Firmware Bypasses Rolling Code Security on Major Vehicle Brands
ArcaneSlime@lemmy.dbzer0.com 2 days agoI do it, my old ass car doesn’t use rolling codes so I use it to keep my car running but locked while I run into the gas station real fast for snacks on break during the winter. Yes this means I’m vulnerable to other people with flippers, but they’d still have to know and sniff my fob’s signal which is easier said than done, and as long as it’s not accessed when I leave it running all they can steal is my jumper cables since I don’t leave anything in the car (theives can also just break the damn window, or use the wedge, inflatable bag, hanger method, they sell the kits at Autozone lol.)
I can also control some Touchtunes jukeboxes in my area, and any TV I come across; doctors office TV has Fox running? Oh look at that now we’re watching Forensic Files, odd. Some drunk moron played the Kid Rock version of Sweet Home Alabama? Oh no it got skipped! How happen?! Also a wealth of other IR or Sub-GHz signals provided by the IRDB (for IR) and elsewhere on github (for SubGHz), fans, AC, even vibrators, you name it.
Also it has a wealth of RFID fobs stored, I have access to some gyms and pools that I otherwise shouldn’t, and a rewritable RFID fob on my keys so I don’t have to show the flipper at the door I can just write it to the fob before I exit my car and look like I have an approved fob. Same with NFC.
Some other cool random things too, ROT13 and Caesar cipher decoders, a key copier, BadUSB, I have a GPIO attachment that lets me trade any pokemon to myself to my GBC, and of course the wifi board loaded with mayhem and evil portal (haven’t played around with flipperHTTP yet, nor the social media app, among others, that use it), it can break into some keypad sentry safes using just the flipper and two wires, lots of stuff! Don’t use much of that very often but I have before and will again.
mmmac@lemmy.zip 2 days ago
Alright I’m sold. $200 seems pretty steep though
ArcaneSlime@lemmy.dbzer0.com 2 days ago
Yeah that’s true, I’ve heard there may be an updated version coming out eventually, maybe then it’ll drop a little. It’s definitely not for everyone, but if you think you’ll use it a lot it can be worth it.
Also if you do get one I recommend installing the Momentum firmware, which isn’t this “darkweb” firmware and can’t do the attack in the article. This firmware is sold (iirc on telegram) and serial locked, an unlocked version is out there, but not where we can get it, maybe it’ll leak one day. I’d eat my farts before I paid for it, Momentum is free.