SlideShare a Scribd company logo
1 of 32
Explorer’s Guide to Shooting
Satellite Transponders
~ Jay Turla
#! /usr/bin/whoami
• Application Security Engineer at Bugcrowd Inc.
• One of the goons of ROOTCON – the premiere hacking conference in
the Philippines
• Former Senior Security Consultant at Hewlett-Packard Enterprise
(Fortify on Demand)
• Acknowledged and rewarded by Facebook, Adobe, Yahoo,
Microsoft, Mozilla, etc. for his responsible disclosures
• Contributed auxiliary and exploit modules to the Metasploit
Framework e.g. Zemra, w3tw0rk, Phoenix Exploit Kit exploits
• nullcon virgin :)
#! disclaimer
• Some memes and images may have explicit meaning in them but
hope you don’t get angry with me ;)
• Topic is limited to shooting TV sat transponders + the hardware risks
• The views and opinions expressed are not from my employers
#! credits
• Inspired by Adam Laurie’s talk entitled “Satellite Hacking for Fun and
Profit” at Black Hat DC 2009
• Inspired by “Hacking a Bird in the Sky: The Revenge of Angry Birds”
by Jim Geovedi, Raditya Iryandi, and Raoul Chiesa
• My father for the equipments and hardware
• lyngsat.com - a good resource for beaming all those transponders
• Filsat and PhilDISH - satellite association groups / forums in the
Philippines
#! how to shoot the sat transponders?
#! why do we shoot?
• Free Radio and TV
• It’s a geek thing
• It’s a hobby
• for fun and profit
• Card Sharing (illegal stuff)
• You can watch free Pr0n
• …wait I didn’t add that one ^
#! you can watch free……
• Reference: http://rintosingkep.blogspot.com/2013/04/zamjari-tv-channel-khusus-dewasa-di.html
#! previous slide explanation
• Just a fact that such thing exists and just for educational purposes
(some are FTA, some have keys)
• Not to promote p0rnography (seriously) - don’t ask me how
#! satellite hobbyist starter pack
#! satellite hobbyist hardcore pack
• Satellite receiver
• C (4 - 8 GHz)/ Ku (12 - 18 GHz) Band satellite dish
• Ant Cables / TV Cables
• Monitor / TV
• Smart Cards
• Internet connection
• Routers
• Satellite Finder (Digital / Analog)
• Umbrella (it’s freakin hot setting up the dish)
• LNB (Ku / C band)
• PCI DVB-S2 Digital Satellite Tuner Card for PC
#! PCI DVB-S2 Digital Satellite Tuner Card
for PC (Sample)
#! sat frequencies and bands
• reference:
http://www.inetdaemon.com/tutorials/satellite/communications/frequency-bands/
#! sat frequencies and bands
• reference:
http://www.esa.int/spaceinimages/Images/2013/11/Satellite_frequency_bands
#! now choose your satellite
#! now choose your satellite
#! now choose your satellite
#! start the scan
#! choose the scanning method
#! scanning
#! introducing the risks and simple hacks of
the hobbyists for the hardware
#! echo “Hello World”
#! if there is a shell or web interface, there
is a way
#! access me
• Dreambox -> root : dreambox
• Some Linux-based satellite receivers have telnet access (try
bruteforcing root : root)
• Most Linux-based satellite receivers which have Enigma2 firmware
have FTP
• Try the Web UI
• Most don’t have HTTPS :)
• Card sharing credentials / info are stored in plaintext
• dvbsnoop - DVB / MPEG stream analyzer program
(http://dvbsnoop.sourceforge.net/ or opkg update && opkg install
dvbsnoop)
#! vulnerabilities
#! getting the CCcam information of a box
• https://github.com/shipcod3/cccam-info
#! How do I crack a pay-per-view
• How Do I Crack Satellite and Cable Pay TV -
https://www.youtube.com/watch?v=lhbSD1Jba0Q
• Search for Alternative Channels from other Satellite TV’s that are
free (satellite feed hunting)
• Card Sharing (Illegal)
• Watch Streaming videos (yeah but we wan’t a better one right)
• and ……
#! Manny Pacquiao Pay-Per-View for free
last year
• CAID: 2600
Palapa D (113.0°E)
Channel: TVONE
3786 H 5632 (MPEG2/$)
SID: 0001
Provid: null
Even CW: 00 22 66 88 33 55 77 FF
ODD CW: 00 22 66 88 33 55 77 FF
#! Manny Pacquiao Pay-Per-View for free
last year
#! Manny Pacquiao Pay-Per-View for free
last year
#! wait how?
• all you need is searching! Biss, Viaccess, Nagra keys etc.
Questions?
• ???
References
• lyngsat.com
• http://www.inetdaemon.com/tutorials/satellite/communications/fr
equency-bands/
• http://www.esa.int/spaceinimages/Images/2013/11/Satellite_frequ
ency_bands
• http://rintosingkep.blogspot.com/2013/04/zamjari-tv-channel-
khusus-dewasa-di.html

More Related Content

Similar to Explorer's Guide to Shooting Satellite Transponders

Dmk blackops2006 ccc
Dmk blackops2006 cccDmk blackops2006 ccc
Dmk blackops2006 ccc
Dan Kaminsky
 

Similar to Explorer's Guide to Shooting Satellite Transponders (20)

Making and breaking security in embedded devices
Making and breaking security in embedded devicesMaking and breaking security in embedded devices
Making and breaking security in embedded devices
 
Steelcon 2015 - 0wning the internet of trash
Steelcon 2015 - 0wning the internet of trashSteelcon 2015 - 0wning the internet of trash
Steelcon 2015 - 0wning the internet of trash
 
Hardware Reverse Engineering: From Boot to Root
Hardware Reverse Engineering: From Boot to RootHardware Reverse Engineering: From Boot to Root
Hardware Reverse Engineering: From Boot to Root
 
Hackware 1.1
Hackware 1.1Hackware 1.1
Hackware 1.1
 
Hacker Halted 2018: From CTF to CVE – How Application of Concepts and Persist...
Hacker Halted 2018: From CTF to CVE – How Application of Concepts and Persist...Hacker Halted 2018: From CTF to CVE – How Application of Concepts and Persist...
Hacker Halted 2018: From CTF to CVE – How Application of Concepts and Persist...
 
Reverse engineering
Reverse engineeringReverse engineering
Reverse engineering
 
Tracking the International Space Station with Commodore Computers
Tracking the International Space Station with Commodore ComputersTracking the International Space Station with Commodore Computers
Tracking the International Space Station with Commodore Computers
 
Defcon 22-metacortex-grifter-darkside-of-the-internet
Defcon 22-metacortex-grifter-darkside-of-the-internetDefcon 22-metacortex-grifter-darkside-of-the-internet
Defcon 22-metacortex-grifter-darkside-of-the-internet
 
Travelling to the far side of Andromeda
Travelling to the far side of AndromedaTravelling to the far side of Andromeda
Travelling to the far side of Andromeda
 
Dmk blackops2006
Dmk blackops2006Dmk blackops2006
Dmk blackops2006
 
Acpe 2014 Internet Anonymity Using Tor
Acpe 2014  Internet Anonymity Using TorAcpe 2014  Internet Anonymity Using Tor
Acpe 2014 Internet Anonymity Using Tor
 
Dmk blackops2006 ccc
Dmk blackops2006 cccDmk blackops2006 ccc
Dmk blackops2006 ccc
 
BSides Hannover 2015 - Shell on Wheels
BSides Hannover 2015 - Shell on WheelsBSides Hannover 2015 - Shell on Wheels
BSides Hannover 2015 - Shell on Wheels
 
D1 t1 t. yunusov k. nesterov - bootkit via sms
D1 t1   t. yunusov k. nesterov - bootkit via smsD1 t1   t. yunusov k. nesterov - bootkit via sms
D1 t1 t. yunusov k. nesterov - bootkit via sms
 
IoT security is a nightmare. But what is the real risk?
IoT security is a nightmare. But what is the real risk?IoT security is a nightmare. But what is the real risk?
IoT security is a nightmare. But what is the real risk?
 
Digital technology merit badge
Digital technology merit badgeDigital technology merit badge
Digital technology merit badge
 
Skyfall technologies
Skyfall technologiesSkyfall technologies
Skyfall technologies
 
Security Onion
Security OnionSecurity Onion
Security Onion
 
Wi-Fi Hotspot Attacks
Wi-Fi Hotspot AttacksWi-Fi Hotspot Attacks
Wi-Fi Hotspot Attacks
 
44CON 2014 - I Hunt TR-069 Admins: Pwning ISPs Like a Boss, Shahar Tal
44CON 2014 - I Hunt TR-069 Admins: Pwning ISPs Like a Boss, Shahar Tal44CON 2014 - I Hunt TR-069 Admins: Pwning ISPs Like a Boss, Shahar Tal
44CON 2014 - I Hunt TR-069 Admins: Pwning ISPs Like a Boss, Shahar Tal
 

Recently uploaded

+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Victor Rentea
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 

Recently uploaded (20)

Spring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUKSpring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUK
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
 
Ransomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdfRansomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdf
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 

Explorer's Guide to Shooting Satellite Transponders

  • 1. Explorer’s Guide to Shooting Satellite Transponders ~ Jay Turla
  • 2. #! /usr/bin/whoami • Application Security Engineer at Bugcrowd Inc. • One of the goons of ROOTCON – the premiere hacking conference in the Philippines • Former Senior Security Consultant at Hewlett-Packard Enterprise (Fortify on Demand) • Acknowledged and rewarded by Facebook, Adobe, Yahoo, Microsoft, Mozilla, etc. for his responsible disclosures • Contributed auxiliary and exploit modules to the Metasploit Framework e.g. Zemra, w3tw0rk, Phoenix Exploit Kit exploits • nullcon virgin :)
  • 3. #! disclaimer • Some memes and images may have explicit meaning in them but hope you don’t get angry with me ;) • Topic is limited to shooting TV sat transponders + the hardware risks • The views and opinions expressed are not from my employers
  • 4. #! credits • Inspired by Adam Laurie’s talk entitled “Satellite Hacking for Fun and Profit” at Black Hat DC 2009 • Inspired by “Hacking a Bird in the Sky: The Revenge of Angry Birds” by Jim Geovedi, Raditya Iryandi, and Raoul Chiesa • My father for the equipments and hardware • lyngsat.com - a good resource for beaming all those transponders • Filsat and PhilDISH - satellite association groups / forums in the Philippines
  • 5. #! how to shoot the sat transponders?
  • 6. #! why do we shoot? • Free Radio and TV • It’s a geek thing • It’s a hobby • for fun and profit • Card Sharing (illegal stuff) • You can watch free Pr0n • …wait I didn’t add that one ^
  • 7. #! you can watch free…… • Reference: http://rintosingkep.blogspot.com/2013/04/zamjari-tv-channel-khusus-dewasa-di.html
  • 8. #! previous slide explanation • Just a fact that such thing exists and just for educational purposes (some are FTA, some have keys) • Not to promote p0rnography (seriously) - don’t ask me how
  • 9. #! satellite hobbyist starter pack
  • 10. #! satellite hobbyist hardcore pack • Satellite receiver • C (4 - 8 GHz)/ Ku (12 - 18 GHz) Band satellite dish • Ant Cables / TV Cables • Monitor / TV • Smart Cards • Internet connection • Routers • Satellite Finder (Digital / Analog) • Umbrella (it’s freakin hot setting up the dish) • LNB (Ku / C band) • PCI DVB-S2 Digital Satellite Tuner Card for PC
  • 11. #! PCI DVB-S2 Digital Satellite Tuner Card for PC (Sample)
  • 12. #! sat frequencies and bands • reference: http://www.inetdaemon.com/tutorials/satellite/communications/frequency-bands/
  • 13. #! sat frequencies and bands • reference: http://www.esa.int/spaceinimages/Images/2013/11/Satellite_frequency_bands
  • 14. #! now choose your satellite
  • 15. #! now choose your satellite
  • 16. #! now choose your satellite
  • 17. #! start the scan
  • 18. #! choose the scanning method
  • 20. #! introducing the risks and simple hacks of the hobbyists for the hardware
  • 21. #! echo “Hello World”
  • 22. #! if there is a shell or web interface, there is a way
  • 23. #! access me • Dreambox -> root : dreambox • Some Linux-based satellite receivers have telnet access (try bruteforcing root : root) • Most Linux-based satellite receivers which have Enigma2 firmware have FTP • Try the Web UI • Most don’t have HTTPS :) • Card sharing credentials / info are stored in plaintext • dvbsnoop - DVB / MPEG stream analyzer program (http://dvbsnoop.sourceforge.net/ or opkg update && opkg install dvbsnoop)
  • 25. #! getting the CCcam information of a box • https://github.com/shipcod3/cccam-info
  • 26. #! How do I crack a pay-per-view • How Do I Crack Satellite and Cable Pay TV - https://www.youtube.com/watch?v=lhbSD1Jba0Q • Search for Alternative Channels from other Satellite TV’s that are free (satellite feed hunting) • Card Sharing (Illegal) • Watch Streaming videos (yeah but we wan’t a better one right) • and ……
  • 27. #! Manny Pacquiao Pay-Per-View for free last year • CAID: 2600 Palapa D (113.0°E) Channel: TVONE 3786 H 5632 (MPEG2/$) SID: 0001 Provid: null Even CW: 00 22 66 88 33 55 77 FF ODD CW: 00 22 66 88 33 55 77 FF
  • 28. #! Manny Pacquiao Pay-Per-View for free last year
  • 29. #! Manny Pacquiao Pay-Per-View for free last year
  • 30. #! wait how? • all you need is searching! Biss, Viaccess, Nagra keys etc.
  • 32. References • lyngsat.com • http://www.inetdaemon.com/tutorials/satellite/communications/fr equency-bands/ • http://www.esa.int/spaceinimages/Images/2013/11/Satellite_frequ ency_bands • http://rintosingkep.blogspot.com/2013/04/zamjari-tv-channel- khusus-dewasa-di.html