Black Hat USA 2018 - SirenJack Cracking a Secure Emergency Warning Siren System @HackersOnBoard
Black Hat USA 2018 - SirenJack Cracking a Secure Emergency Warning Siren System  @HackersOnBoard
Uploaded October 2019 | Updated September 2026, 2 days ago
SirenJack is a vulnerability that was found to affect radio-controlled emergency warning siren systems from ATI Systems. It allows a bad actor, with a $30 handheld radio and a laptop, to set off all sirens in a deployment. Hackers can trigger false alarms at will because the custom digital radio protocol does not implement encryption in vulnerable deployments.

Emergency warning siren systems are public safety tools used to alert the population of incidents, such as weather and man-made threats. They are widely deployed in cities, industrial sites, military installations, and educational institutions across the US and abroad.

Sirens are often activated via a radio frequency (RF) communications system to provide coverage over a large area. Does the security of these RF-based systems match their status as critical infrastructure? The 2017 Dallas siren hack showed that many older siren systems are susceptible to replay attacks, but what about more modern ones?

I studied San Francisco's Outdoor Public Warning System, an ATI deployment, for two years to learn how it was controlled. After piecing together clues on siren poles, and searching the entire radio spectrum for one unknown signal, I found the system's frequency and began passive analysis of the protocol. Monitoring the weekly siren tests, I made sense of patterns in the raw binary data and found the system was insecure and vulnerable to attack.

This presentation will take you on the journey of the research, and detail the tools and techniques used, including leveraging Software Defined Radio and open source software to collect and analyse massive sets of RF data, and analyse a custom digital protocol. It will also cover the Responsible Disclosure process with the vendor, their response, and subsequent change to the protocol. A proof-of-concept will be shown for good measure.
Black Hat USA 2018 - SirenJack Cracking a Secure Emergency Warning Siren SystemDEF CON 27 - Alon Weinberg - Please Inject Me a x64 Code InjectionBlack Hat USA 2018 - I, for One, Welcome Our New Power Analysis OverlordsBlack Hat USA 2018 - Last Call for SATCOM SecurityBlack Hat USA 2018 - Understanding and Exploiting Implanted Medical DevicesDEF CON 27 - Panel - Hacking Congress The Enemy Of My Enemy Is My FriendDEF CON 27 - Ali Islam - Weaponizing Hypervisors to Fight and Beat Car and Medical Devices AttacksAttacks on the Curl-P Hash Function Leading to Signature Forgeries in the IOTA Signature SchemeDEF CON 27 - Elie Bursztein - How Deep Learning Is Revolutionizing Side-Channel CryptanalysisBlack Hat USA 2018 - Breaking the IIoT Hacking industrial Control GatewaysDEF CON 27 - Contests and Events - Contests Awards CeremonyDEF CON 27 - Ariel Herbert-Voss - Dont Red-Team AI Like a Chump
HackersOnBoard |

Black Hat USA 2018 - SirenJack Cracking a Secure Emergency Warning Siren System

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER