Skip to content
View in the app

A better way to browse. Learn more.

Security Installer Community

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Csl Dualcom Cs2300-R Vulnerabilities

Featured Replies

  • Author

Agreed

 

Stayed away from what technology?

 

Problem is, neither CSL or Intertek are going to openly say "The CSL CS2300 board testing to EN50136 had some parts self declared, including the encryption and substitution protection".

 

Testing the boards to the depth I tested them would cost between £10k and £20k. That's about one third of the cost of testing again. If you wanted the problems fixed, and needed in-depth advice, add another £5k at least.

 

I don't know if WebWayOne want to pass comment on the self declared aspects of standards testing?

 

Interestingly, since the research went live, two separate people have contacted me to talk about integrating the CSL protocol into panels. They were both shocked at how basic the protocol was, and how bad the documentation was.

I'm still finding it odd how little has been said by CSL. The post has far exceeded the traffic generated by Heatmiser vulnerabilities.

I have a blog, some of which is about alarm security and reverse engineering:
http://cybergibbons.com/

 

 

 

  • Replies 144
  • Views 26.5k
  • Created
  • Last Reply

I would hope it was viewed more than a heating controller. Its a bit more serious. I suppose at some point it will be taken up by mainstream media?

securitywarehouse Security Supplies from Security Warehouse

Trade Members please contact us for your TSI vetted trade discount.

  • Author

The Guardian were going to run it, but then CSL claimed it was only 600 units. Not big enough.

I have a blog, some of which is about alarm security and reverse engineering:
http://cybergibbons.com/

 

 

 

CG how old was the unit you tested, CSL upgraded lots of ours earlier this year

Any comments / opinions posted are my opinion only and do not represent those of my employer or Company

The Guardian were going to run it, but then CSL claimed it was only 600 units. Not big enough.

How would one verify that?

securitywarehouse Security Supplies from Security Warehouse

Trade Members please contact us for your TSI vetted trade discount.

are there any dates on the versions you have or a list of firmware release dates?

securitywarehouse Security Supplies from Security Warehouse

Trade Members please contact us for your TSI vetted trade discount.

  • Author

CG how old was the unit you tested, CSL upgraded lots of ours earlier this year

 

Earliest 2009, latest 2013.

What did they upgrade them to?

I have a blog, some of which is about alarm security and reverse engineering:
http://cybergibbons.com/

 

 

 

  • Author

How would one verify that?

 

Almost impossible as a third party. As of April 2015, the latest firmware they had available for download suffered from these issues. They don't provide any release notes or changelog, so really hard to tell.

I have a blog, some of which is about alarm security and reverse engineering:
http://cybergibbons.com/

 

 

 

So as of April 2015 your findings are valid?

securitywarehouse Security Supplies from Security Warehouse

Trade Members please contact us for your TSI vetted trade discount.

Archived

This topic is now archived and is closed to further replies.

Recently Browsing 0

  • No registered users viewing this page.

Important Information

By using this site, you agree to our Terms of Use.

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.