Slawomir Jasek Profile
Slawomir Jasek

@slawekja

Followers
2K
Following
585
Statuses
662

Training, research, consultations on BLE, NFC/RFID, smart locks and other devices' security https://t.co/S8nCvMyR4S https://t.co/JhcX3YhDJE

Joined April 2015
Don't wanna be here? Send us removal request.
@slawekja
Slawomir Jasek
4 years
Introducing new, free #Bluetooth Low Energy hardware-less HackMe - your go to for mastering #BLE #security #hacking basics hands-on with just a standard Win10 laptop and Android phone. Info: MS store: source:
Tweet media one
Tweet media two
Tweet media three
4
54
180
@slawekja
Slawomir Jasek
3 months
@CayreRomain @ghidraninja Yes, it was nice work, the eLink has interesting vulnerabilities. It was later also presented by @cyberMilosz If you still need more samples I have dozens of vulneraBLE smart locks: auth based on MAC, static hardcoded pass, plain text, '001122..' AES,...
1
0
6
@slawekja
Slawomir Jasek
9 months
@CayreRomain @0K_ultra I like for example Nuki - for the open specification of all their communication protocols No need for reversing to check the security, and there are several open source integrations.
2
0
1
@slawekja
Slawomir Jasek
10 months
@a66ot @herrmann1001 (browsing Kickstarter history...) Yep, of course I backed it up. But usually others beat me at the job - before I even unpack...
0
0
2
@slawekja
Slawomir Jasek
1 year
RT @marcnewlin: I decided to release the PoC scripts ahead of my ShmooCon talk. Happy Hacking :)
0
69
0
@slawekja
Slawomir Jasek
1 year
@jilles_com @OoijenBas @doegox Sure I'm staying for the conference, also love your CTFs by the way!
0
0
1
@slawekja
Slawomir Jasek
1 year
@jilles_com @OoijenBas Thanks Jilles, hope to meet you in Hague again!
1
0
0
@slawekja
Slawomir Jasek
1 year
@marunmagesh Thanks Arun!
0
0
1
@slawekja
Slawomir Jasek
1 year
🛡️ Join my 🚀 action packed hands-on @hardwear_io #Bluetooth #BLE #security assessment #training to master #IoT devices #pentesting! 📦 Included 📱 phone 🍓 raspberry pi 🕵️ sniffers 🔓 smart locks zero days 💣👾 ⏰Seats are filling fast, enroll ASAP!
Tweet media one
0
13
41
@slawekja
Slawomir Jasek
1 year
RT @hardwear_io: 📟Get familiar on how BLE works in practice by controlling your dedicated training device! 💡Slawomir @slawekja is here to…
0
4
0
@slawekja
Slawomir Jasek
2 years
RT @hitbsectrain: Explore BLE advertisements, connections, sniffing, and remote relay attacks with @slawekja at #HITB2023HKT! Join us to en…
0
6
0
@slawekja
Slawomir Jasek
2 years
RT @hardwear_io: New Training alert! 🧬Fingerprinting, sniffing, MITM, etc., the possible attacks you will find out in the Bluetooth Low ene…
0
3
0
@slawekja
Slawomir Jasek
2 years
@mherfurt @pascal_gujer @smartlockpick Yes that was also my first guess when I saw this. I don't think the owner left a phone as article mentions he sent a message to the "thief". But maybe he just left the keyfob inside?
0
0
2
@slawekja
Slawomir Jasek
2 years
RT @Kevin2600: I just wrote an article regarding to BLE relay attack on smart cars. Not much of new stuff, but tested on multiple cars, and…
0
69
0
@slawekja
Slawomir Jasek
2 years
@mame82 @mherfurt Hi Marcus, thanks! Sorry for delay, I've been offline. Yes, I'm aware of @mherfurt work, I was able to remotely relay Tesla as well. Yes, relay requires 2 devices, but BLExy could be used for other Martin's attacks against Tesla (counter confusion, auth extract/replay...)
0
0
4
@slawekja
Slawomir Jasek
2 years
@Kevin2600 @mherfurt It took me a few tries before I figured how to trigger the proximity auto unlock (without owner's app interaction). Looks like the car has several antennas measuring the RSSI from which side you approach.
1
0
4
@slawekja
Slawomir Jasek
2 years
@KimZetter @Tesla @Kevin2600 @CarHackVillage No worries, no pressure at all, it's not urgent :)
0
0
0
@slawekja
Slawomir Jasek
2 years
@KimZetter @Tesla @Kevin2600 @CarHackVillage Main diff of the dumps at first look is that pm3 sniffs the whole ISO14443 (current research dump) and phone (NFCGate, 2020 dump) just ISO7816 - a few bytes shorter on "head"/"tail". But AID, APDUs (at least start) look the same. A few more links in CVE
1
0
0
@slawekja
Slawomir Jasek
2 years
RT @zh4ck: Only at a hacker conference like @HITBSecConf where @sergeybelove scans an NFC Mifare business card from @slawekja via a Flipper…
0
5
0