Kirils & friends got so excited about the FERMAX intercom system, that they nerd-sniped Iceman to join in on the hunt for MIFARE Desfire cards.
This is a journey into research on a shoe string and our realizations under the way. Detours, Dead Ends and Scope Creep are real.
When reverse engineering the proprietary DUOX PLUS intercom system dubbed the ‘most secure in world’ by FERMAX, previously Kirils & friends focused on its digital 2-wire signalling and employed such tools like oscilloscopes, logic analyzers and breadboards.
While these attacks are important as they shine light on the internal workings on the system, their application in the field is limited as one would need to acquire access to the 2-wire bus, which is only possible from the inside of the building.
Then we noticed something that was right in front of our eyes, Access control panels! These things are out there just on the perimeter. And, when installed on multi-tenant buildings, they have RFID reader modules installed. FERMAX offers modules doing EM4100, MIFARE Classic, and MIFARE Desfire. Even more they offer standalone Bluetooth modules too!
In this talk we give an overview of previous research and expand on it by exploring the possibilities of entering the perimeter by attacking the bluetooth and RFID dimension of these systems, and exploring card cloning, implanting, and cryptographic attacks together with Iceman. In our research we extracted firmware and analyzed two different mobile applications to control the system, TUYA and NearKey.
Attendees will gain insight into decoding and interacting with closed digital protocols, exposing vulnerabilities in real-world access control systems. They also get practically applying RFID attacks to real world systems in use right now.