"I'm in" - remote exploitation of electronic access control systems
2024-09-26 , Bradman Theatrette

Every cool hackers movie has it, that one scene where they go "I'm In" and bam, they hacked the gibson, maybe they trigger a fire alarm system, or open a door. We know that in reality, most people don't get to do that, but what if we could? This is a rhetorical question, I got to, and in this talk, we'll discuss how you can too, looking into a set of real vulnerabilities for CVE-2024-29838-> CVE-2024-29845 on a electronic access control system, and maybe even a "I'm In" moment

evildaemond is a person who works in security, with focuses in hardware, web pentesting and physsec, and regularly teaches lockpicking and physsec at conferences across Australia. They've released projects like the physsec-methodlogy, enjoys bug bounty and vulnerability disclosure, and has spent more money on stickers than some companies.