Hi All,
I've started this NEW thread to continue discussing the possible methods of recovering/testing theory verses a method and vulnerability for recovering lost keys.
Users can choose to upgrade to higher levels of privacy modes such as Advanced or AES which are chargeable. We are just talking about Basic in this thread.
---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
I had misread that Hytera BP was capable of being received on a Motorola set so long as it was set to Enhanced Privacy but that's not possible so thanks to 'Forts' pointing that out.
Hytera says that Basic Privacy solution offers provides key option between 1-255 using 10, 32 or 64 characters to the transmission and receiver frequency, each of which must match up. The keys are not customized, so if a hacker was so minded they need only scan all 255 keys to potentially hit on the one you are using.
You have 1-30 Key IDs to set (as a maximum) and a Key Value.
So, if I have a radio set to set with 'Key ID 1' and '10-Characters' I only need to find the Key value field.
I'm guessing its not as straightforward as trying 1-255 under the Key Value with FFFFFFF for the rest given that the value can be 0-F.
So, what options are available to find/read/sniff/decode it? Method, Tools etc can I use with the RCDB file.
----------------------------------------------------------------------------------------------------------------------------------------------------------
I have reloaded a RCDB extraction of a codeplug into a Hex editor and I think I can see where it should show the value. Its believe given the firmware version (A7.06.01.006) it cant be read in the clear anymore.
@ 0xFF1E071F "Reveal already written basic enc keys from a Hytera Radio?" Yes, as it's not possible to copy to a Moto set, so recovering the original is now the aim.
Regards
Mike
I've started this NEW thread to continue discussing the possible methods of recovering/testing theory verses a method and vulnerability for recovering lost keys.
Users can choose to upgrade to higher levels of privacy modes such as Advanced or AES which are chargeable. We are just talking about Basic in this thread.
---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
I had misread that Hytera BP was capable of being received on a Motorola set so long as it was set to Enhanced Privacy but that's not possible so thanks to 'Forts' pointing that out.
Hytera says that Basic Privacy solution offers provides key option between 1-255 using 10, 32 or 64 characters to the transmission and receiver frequency, each of which must match up. The keys are not customized, so if a hacker was so minded they need only scan all 255 keys to potentially hit on the one you are using.
You have 1-30 Key IDs to set (as a maximum) and a Key Value.
So, if I have a radio set to set with 'Key ID 1' and '10-Characters' I only need to find the Key value field.
I'm guessing its not as straightforward as trying 1-255 under the Key Value with FFFFFFF for the rest given that the value can be 0-F.
So, what options are available to find/read/sniff/decode it? Method, Tools etc can I use with the RCDB file.
----------------------------------------------------------------------------------------------------------------------------------------------------------
I have reloaded a RCDB extraction of a codeplug into a Hex editor and I think I can see where it should show the value. Its believe given the firmware version (A7.06.01.006) it cant be read in the clear anymore.
@ 0xFF1E071F "Reveal already written basic enc keys from a Hytera Radio?" Yes, as it's not possible to copy to a Moto set, so recovering the original is now the aim.
Regards
Mike