Hacking COMBUS in a Paradox security system
While working on a project to reverse engineer some of the internal communication protocols used in a Canadian-made Paradox security alarm system, author discovered a shocking secret on the COMBUS – the common bus connecting the control panel with keypads and other peripherals. Turns out that COMBUS isn’t protected neither electrically, nor logically, thus rendering the security system effectively broken.
This talks takes us through the discovery process, allowing to replicate research results, the findings and some theoretical attacks that are possible as a result.
As part of responsible disclosure process the author has notified Paradox, the Canadian company that offers physical security devices, most notably – home/office security alarms, about the discovered vulnerability. The company responded that the information brought forward by the author “has been dealt with”. Author sincerely hopes that means “fixed”.
Biography
Mg. sc. comp. Kirils Solovjovs is Lead Researcher at Possible Security and the most visible white-hat hacker in Latvia having discovered and responsibly disclosed or reported multiple security vulnerabilities in information systems of both national and international significance. Kirils is one of the authors of the jailbreak tool for Mikrotik RouterOS. He has extensive experience in network flow analysis, reverse engineering, social engineering and penetration testing.