Power Hack Can Force Home, Office Blackouts

  /     /     /  
Publicated : 22/11/2024   Category : security


Power Hack Can Force Home, Office Blackouts


New free tools can be used to remotely force open doors, unlock windows, trigger alarms -- and turn out the lights



DEFCON 19 -- Las Vegas -- A pair of researchers here today unleashed free handmade tools that spy on and disable home-automation and business systems connected via broadband power lines.
Aside from providing broadband for home-automation systems, the so-called X10 and ZWave broadband-over-power technology is also used in businesses and process-control environments, exposing all communications over those protocols, says David Kennedy, who developed the open-source Social-Engineer Toolkit. They are being widely used in businesses and a lot in access-control systems, he says. We need to bring more exposure to this attack vector.
The tools -- which are now part of the Social-Engineer Toolkit Version 2.0 -- include the X10 Sniffer and X10 Blackout devices. The X10 Sniffer detects which devices are on the broadband power network, and can even track the movement of people in the house or office. The devices plug into a nearby outlet, such as a neighbors home or an outside outlet on the building.
Kennedy and Simon also are putting the final touches on a single X10 hacking tool that both sniffs and disables lights or other devices via cell phone. The tool would allow an attacker to send a text message ordering a light to be turned on or off, or to jam or disable all systems running on the home-automation system.
You could plug it into the next-door neighbors outlet or at the [target] house, and it has sniffing and jamming capabilities, Kennedy says. It sends you a text message saying these are all of the devices, and then you can send the device a text message with a kill command.
The tool, which will be released within the next couple of weeks, also provides information on which device is turned on, or whether a window sensor is tripped, for instance, Simon says.
All we have to do is walk up to the house, plug the device in, and it turns the lights out, none of the sensors work, and we walk out, Kennedy says.
The power-over-broadband hacking tools contain the so-called Teensie microcontroller device, programmed to emulate a keyboard, and an SD card soldered onto the Teensie.
The underlying problem is that X10 technology, which is also used for HVAC systems, motion sensors, electronic door locks, and cameras, has no encryption, so data is sent in the clear.
Kennedy says Zwave power-over-broadband technology supports AES encryption, but he and Simon have yet to find any devices that actually implement it. Its possible to sniff those encryption keys when initializing the devices and inject packets, he says.
Have a comment on this story? Please click Add Your Comment below. If youd like to contact
Dark Readings
editors directly,
send us a message
.

Last News

▸ China facing challenges in dealing with hackers. ◂
Discovered: 05/01/2025
Category: security

▸ UK study shows rapid increase in IT security salaries. ◂
Discovered: 05/01/2025
Category: security

▸ Pioneer introduces 128GB Blu-ray Drive ◂
Discovered: 05/01/2025
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Power Hack Can Force Home, Office Blackouts