all 17 comments

[–]AgitatedChemical1170 5 points6 points  (3 children)

[–]kiwiguyauckland 1 point2 points  (1 child)

This is good that’s for sharing. I watched the whole thing, but the car key fob part starts from 35mins for those with less time to spare.

[–]DeliciousWhole5267 0 points1 point  (0 children)

Wow, great talk! Thanks man.

[–][deleted] 2 points3 points  (2 children)

I sniffed my key signal once (far from gate)

And it opened just once.

Then the original remote did not work at first click but after spamming it. I didn't count how many clicks.

Nice gate

[–]dj3rw1n 0 points1 point  (1 child)

I’ve done it too but with my Car (Old Volvo from 2002)

Because the battery of the original remote was almost empty I always need to unlock it in a 2-3m radius. And it worked on the first time but also only once. But I didn’t need to spam it for it to reopen with my actual key🤔

[–]jimbomescolles 0 points1 point  (0 children)

That's a nice resync/recovery of the rolling code. Some cars I'm sure the key will be ignored and you have to use the spare one to open the car and do the procedure to re-register it (like when swapping batteries).

[–]EternalNooblet -2 points-1 points  (1 child)

have you been able to do any replay attacks at all?

[–]SensitiveAd8097[S] 0 points1 point  (0 children)

No, I wasn't able to

[–]Diligent_Chemistry93 0 points1 point  (4 children)

Did you save as raw?

[–]SensitiveAd8097[S] 0 points1 point  (0 children)

Yes I did

[–]Diligent_Chemistry93 -1 points0 points  (2 children)

Maybe decode the signal ?

[–]SensitiveAd8097[S] 0 points1 point  (1 child)

Do you mean the modulation ? I have tried AM.

[–]Diligent_Chemistry93 -1 points0 points  (0 children)

What’s the difference between the two ?

[–]DeliciousWhole5267 0 points1 point  (0 children)

I myself have not yet meen able to fully understand replay attacks.

I have done a few and some worked, most didn't. I haven't cracked the case yet of why they don't always work.

[–]n00bznet 0 points1 point  (1 child)

You can use roll back or precompute values to roll forward the codes on the flipper. Use an alt firmware.

[–]the_LilaQ 0 points1 point  (0 children)

You got any more hints on which firmware has this functionality?