SDR and Radio
A Software Defined Radio (SDR) is a radio receiver (and sometimes transmitter) whose processing is done in software, letting you tune and analyze almost any frequency with a single cheap device. For a hacker, an SDR opens a huge universe: remote controls, wireless sensors, garage/car remotes, pagers, aircraft ADS-B, GPS, and proprietary IoT protocols. It’s the gateway to radio hacking beyond WiFi/BT.
Hardware
Section titled “Hardware”RTL-SDR ~$25, receive only, up to ~1.7 GHz -> ideal to start (listen)HackRF One TX+RX, 1 MHz - 6 GHz -> transmit (replay), half-duplexLimeSDR / USRP more capable (full-duplex, better range) -> professionalFlipper Zero integrated sub-GHz for common remotes (433/315 MHz)Software
Section titled “Software”GQRX / SDR# visual receiver: see the spectrum and listen/demodulateGNU Radio block framework to process signals (advanced analysis)Universal Radio Hacker (URH) capture, analyze, decode, and REPLAY signals (key)rtl_433 decodes hundreds of ISM sensors/devices (433/868/915 MHz)inspectrum analyze captures visuallyURH is the star tool for pentesting: capture a signal, analyze it (modulation, encoding), extract the message, and resend it.
Typical workflow
Section titled “Typical workflow”1. Find the device's frequency (manual, FCC ID, spectrum scan in GQRX)2. Capture the signal when activating it (e.g. press the remote)3. Analyze: modulation (ASK/OOK, FSK), encoding, packet structure (URH/inspectrum)4. Decode the message5. Resend (replay) with HackRF/Flipper -> if it works, the device is vulnerableCommon attacks
Section titled “Common attacks”# replay attack (the simplest and most frequent)# capture a remote's "open" signal and resend it -> opens the door/garage# works if there's NO rolling code (fixed code)# rolling code: many remotes change the code each time -> simple replay fails# -> attacks like RollJam (jam + capture) on weak implementations# sensor analysis (rtl_433): temperature, doorbells, weather stations, alarms# sensor spoofing/jamming (inject false readings)# passive reception: ADS-B (aircraft), AIS (ships), pagers (POCSAG), etc.The classic case: a garage remote with a fixed code → you capture and resend = access. With a well-done rolling code, simple replay doesn’t work.
Legal considerations
Section titled “Legal considerations”Transmitting on regulated frequencies can be illegal without a license, and there are prohibited bands. Reception is usually legal; transmission (replay/jamming) requires extreme care and authorization. Practice in controlled environments and within the law.
For the defense
Section titled “For the defense”- Well-implemented rolling codes / challenge-response in remotes and key fobs (not fixed codes).
- Encryption and authentication in wireless IoT protocols; anti-replay (counters, nonces).
- Don’t rely on protocol obscurity: proprietary protocols are analyzed with SDR.
- Validate the integrity/origin of sensor data (don’t trust unauthenticated readings).
- Jamming/interference detection where critical (alarms, access).
Testing checklist
Section titled “Testing checklist”- SDR hardware (RTL-SDR for RX, HackRF/Flipper for TX)
- Find the target’s frequency (GQRX/FCC ID)
- Capture the device’s signal (URH)
- Analyze modulation/encoding/structure
- Replay the signal (fixed or rolling code?)
- Decode sensors with rtl_433
- Assess rolling code / anti-replay
- Respect legality (regulated TX)