KeyWe makiyi akangwara haana kuchengetedzwa kubva pakubata kiyi

Vatsvakurudzi vekuchengetedza kubva kuF-Secure analysed smart door kiyi KeyWe Smart Lock uye yakaratidza yakakomba vulnerability, iyo inobvumira kushandisa nRF mufeki yeBluetooth Yakaderera Energy uye Wireshark kubata kudzora traffic uye kubvisa mairi kiyi yakavanzika inoshandiswa kuvhura kukiya kubva kune smartphone.

Dambudziko rinowedzerwa nenyaya yekuti makiyi haatsigire firmware zvigadziriso uye kusagadzikana kunongogadziriswa mubatch nyowani yemidziyo. Vashandisi varipo vanogona chete kubvisa dambudziko nekutsiva kukiya kana kumira kushandisa yavo smartphone kuvhura musuwo. KeyWe inokiya zvitoro zvemadhora zana nemakumi mashanu uye inowanzo shandiswa pamasuo ekugara uye ekutengesa. Pamusoro pekiyi yenguva dzose, kukiya kunogona zvakare kuvhurwa nekiyi yemagetsi kuburikidza nenharembozha pa smartphone kana kushandisa bracelet ine NFC tag.

Kuchengetedza nzira yekutaurirana iyo mirairo inofambiswa kubva kune nharembozha, iyo AES-128-ECB algorithm inoshandiswa, asi kiyi yekuvharira inogadzirwa zvichibva pamakiyi maviri anofungidzira - kiyi yakajairwa uye imwe yekuwedzera yakaverengerwa kiyi, inogona kuve nyore. kutsunga. Kiyi yekutanga inogadzirwa yakavakirwa paBluetooth yekubatanidza paramita seMAC kero, zita remudziyo uye hunhu hwechishandiso.

Iyo algorithm yekuverenga kiyi yechipiri inogona kutsanangurwa kuburikidza nekuongororwa kweiyo mobile application. Sezvo ruzivo rwekugadzira makiyi ruchizivikanwa pakutanga, encryption inongova yepamutemo uye kupaza kiyi inokwana kuona maparamendi ekiyi, tora chikamu chekuvhura gonhi uye kubvisa kodhi yekupinda kubva mairi. Toolkit yekuongorora nzira yekutaurirana nekiyi uye kuona makiyi ekupinda yakabudiswa paGitHub.

Source: opennet.ru

Voeg