Skip to content

SDR and Radio

A Software Defined Radio (SDR) is a radio receiver (and sometimes transmitter) whose processing is done in software, letting you tune and analyze almost any frequency with a single cheap device. For a hacker, an SDR opens a huge universe: remote controls, wireless sensors, garage/car remotes, pagers, aircraft ADS-B, GPS, and proprietary IoT protocols. It’s the gateway to radio hacking beyond WiFi/BT.

RTL-SDR ~$25, receive only, up to ~1.7 GHz -> ideal to start (listen)
HackRF One TX+RX, 1 MHz - 6 GHz -> transmit (replay), half-duplex
LimeSDR / USRP more capable (full-duplex, better range) -> professional
Flipper Zero integrated sub-GHz for common remotes (433/315 MHz)
GQRX / SDR# visual receiver: see the spectrum and listen/demodulate
GNU Radio block framework to process signals (advanced analysis)
Universal Radio Hacker (URH) capture, analyze, decode, and REPLAY signals (key)
rtl_433 decodes hundreds of ISM sensors/devices (433/868/915 MHz)
inspectrum analyze captures visually

URH is the star tool for pentesting: capture a signal, analyze it (modulation, encoding), extract the message, and resend it.

1. Find the device's frequency (manual, FCC ID, spectrum scan in GQRX)
2. Capture the signal when activating it (e.g. press the remote)
3. Analyze: modulation (ASK/OOK, FSK), encoding, packet structure (URH/inspectrum)
4. Decode the message
5. Resend (replay) with HackRF/Flipper -> if it works, the device is vulnerable
# replay attack (the simplest and most frequent)
# capture a remote's "open" signal and resend it -> opens the door/garage
# works if there's NO rolling code (fixed code)
# rolling code: many remotes change the code each time -> simple replay fails
# -> attacks like RollJam (jam + capture) on weak implementations
# sensor analysis (rtl_433): temperature, doorbells, weather stations, alarms
# sensor spoofing/jamming (inject false readings)
# passive reception: ADS-B (aircraft), AIS (ships), pagers (POCSAG), etc.

The classic case: a garage remote with a fixed code → you capture and resend = access. With a well-done rolling code, simple replay doesn’t work.

Transmitting on regulated frequencies can be illegal without a license, and there are prohibited bands. Reception is usually legal; transmission (replay/jamming) requires extreme care and authorization. Practice in controlled environments and within the law.

  • Well-implemented rolling codes / challenge-response in remotes and key fobs (not fixed codes).
  • Encryption and authentication in wireless IoT protocols; anti-replay (counters, nonces).
  • Don’t rely on protocol obscurity: proprietary protocols are analyzed with SDR.
  • Validate the integrity/origin of sensor data (don’t trust unauthenticated readings).
  • Jamming/interference detection where critical (alarms, access).
  • SDR hardware (RTL-SDR for RX, HackRF/Flipper for TX)
  • Find the target’s frequency (GQRX/FCC ID)
  • Capture the device’s signal (URH)
  • Analyze modulation/encoding/structure
  • Replay the signal (fixed or rolling code?)
  • Decode sensors with rtl_433
  • Assess rolling code / anti-replay
  • Respect legality (regulated TX)