April 30, 201313 yr comment_317516 the interesting claim- send an alarm for all systems at the ARC w/o revealing an IP(I assume range of accounts on mass or randoms a/c) just need to know the receivers IP & ports no.s if the protocol is weakness it won't just be the one manufacturer? Edited April 30, 201313 yr by MrHappy Mr Veritas God Link to comment https://www.thesecurityinstaller.co.uk/community/topic/34454-vulnerabilities-in-ip-alarm-signalling-protocols/page/4/#findComment-317516 Share on other sites Share on LinkedIn Share on X Share on Facebook {lang="reddit_text" Share via email Share on Pinterest More sharing options... Share this post
April 30, 201313 yr Author comment_317520 As far as I know, the protocol is mainly used by Alphatronics gear, ENAI make receivers that support the protocol. It doesn't look like the receiver cares about the source IP - only what is in the packet at a higher level. I have a blog, some of which is about alarm security and reverse engineering:http://cybergibbons.com/ Link to comment https://www.thesecurityinstaller.co.uk/community/topic/34454-vulnerabilities-in-ip-alarm-signalling-protocols/page/4/#findComment-317520 Share on other sites Share on LinkedIn Share on X Share on Facebook {lang="reddit_text" Share via email Share on Pinterest More sharing options... Share this post
April 30, 201313 yr comment_317521 Well - part of the problem is that those that rely on IP signalling don't seem to want to say what they use. Some deny using it, others won't comment. As MrHappy has shown, Alphatronics own systems use it. ENAI who are also big in NL make receivers for this protocol. I think it's the best kept secret which 2 IP signalling platforms we use. www.securitywarehouse.co.uk/catalog/ Link to comment https://www.thesecurityinstaller.co.uk/community/topic/34454-vulnerabilities-in-ip-alarm-signalling-protocols/page/4/#findComment-317521 Share on other sites Share on LinkedIn Share on X Share on Facebook {lang="reddit_text" Share via email Share on Pinterest More sharing options... Share this post
May 1, 201313 yr Author comment_317536 I guess the thing is, how would anyone know if the protocol the use is actually secure or not? If they weren't, could they be updated? Matt, I know at least one of the people you use takes security very seriously. Would still be interesting to have a go at their signalling though! I have a blog, some of which is about alarm security and reverse engineering:http://cybergibbons.com/ Link to comment https://www.thesecurityinstaller.co.uk/community/topic/34454-vulnerabilities-in-ip-alarm-signalling-protocols/page/4/#findComment-317536 Share on other sites Share on LinkedIn Share on X Share on Facebook {lang="reddit_text" Share via email Share on Pinterest More sharing options... Share this post
May 1, 201313 yr comment_317538 I have no security concerns at all our preferred signalling is webwayone securitywarehouse Security Supplies from Security Warehouse Trade Members please contact us for your TSI vetted trade discount. Link to comment https://www.thesecurityinstaller.co.uk/community/topic/34454-vulnerabilities-in-ip-alarm-signalling-protocols/page/4/#findComment-317538 Share on other sites Share on LinkedIn Share on X Share on Facebook {lang="reddit_text" Share via email Share on Pinterest More sharing options... Share this post
May 1, 201313 yr Author comment_317540 Yes, they are who I think are taking it seriously. I have a blog, some of which is about alarm security and reverse engineering:http://cybergibbons.com/ Link to comment https://www.thesecurityinstaller.co.uk/community/topic/34454-vulnerabilities-in-ip-alarm-signalling-protocols/page/4/#findComment-317540 Share on other sites Share on LinkedIn Share on X Share on Facebook {lang="reddit_text" Share via email Share on Pinterest More sharing options... Share this post
May 1, 201313 yr comment_317542 I guess the thing is, how would anyone know if the protocol the use is actually secure or not? If they weren't, could they be updated? Matt, I know at least one of the people you use takes security very seriously. Would still be interesting to have a go at their signalling though! If you want to try a stress test I'd be more than happy to provide you with a unit into our receivers. www.securitywarehouse.co.uk/catalog/ Link to comment https://www.thesecurityinstaller.co.uk/community/topic/34454-vulnerabilities-in-ip-alarm-signalling-protocols/page/4/#findComment-317542 Share on other sites Share on LinkedIn Share on X Share on Facebook {lang="reddit_text" Share via email Share on Pinterest More sharing options... Share this post
May 1, 201313 yr comment_317543 I have no security concerns at all our preferred signalling is webwayone The nerd in the video was asking for kit to play with, you sending him some new toys ? Mr Veritas God Link to comment https://www.thesecurityinstaller.co.uk/community/topic/34454-vulnerabilities-in-ip-alarm-signalling-protocols/page/4/#findComment-317543 Share on other sites Share on LinkedIn Share on X Share on Facebook {lang="reddit_text" Share via email Share on Pinterest More sharing options... Share this post
May 1, 201313 yr comment_317547 Ill send stuff to test yes securitywarehouse Security Supplies from Security Warehouse Trade Members please contact us for your TSI vetted trade discount. Link to comment https://www.thesecurityinstaller.co.uk/community/topic/34454-vulnerabilities-in-ip-alarm-signalling-protocols/page/4/#findComment-317547 Share on other sites Share on LinkedIn Share on X Share on Facebook {lang="reddit_text" Share via email Share on Pinterest More sharing options... Share this post
May 1, 201313 yr comment_317548 Even the top end TCD's can be compromised. Many are Linux based and once root is gained and init reset watchdogs bypassed, then a whole host of information is available to a would be attacker. Nothing is 100% secure. Link to comment https://www.thesecurityinstaller.co.uk/community/topic/34454-vulnerabilities-in-ip-alarm-signalling-protocols/page/4/#findComment-317548 Share on other sites Share on LinkedIn Share on X Share on Facebook {lang="reddit_text" Share via email Share on Pinterest More sharing options... Share this post
Archived
This topic is now archived and is closed to further replies.