How to hack ESP8266 Lights

Поділитися
Вставка
  • Опубліковано 4 чер 2019
  • A smart home can't be bad, can it?
    Videos:
    - Smart Home - Smart Hack (DE): • 35C3 - Smart Home - S...
    - Smart Home - Smart Hack (EN): • 35C3 - Smart Home - S...
    - Smart Home - Smart Hack (EN,DE,ES): media.ccc.de/v/35c3-9723-smar...
    - (R)evolution of IoT botnets: • LinuxDays 2018 - (R)ev...
    - My personal smart home nightmare: • WOW! The Best SMART HO...
    - Linus reviewing internet of shit: • Philips Hue is a RIPOFF
    Open Source Firmware:
    - ESPurna: github.com/xoseperez/espurna/
    - Sonoff-Tasmota: github.com/arendst/Sonoff-Tas...
    Tutorials:
    - Dumping the firmware: github.com/xoseperez/espurna/...
    - Flashing: github.com/xoseperez/espurna/...
    - Flashing remotly: github.com/ct-Open-Source/tuy...
    Projects:
    - Deauther: github.com/spacehuhn/esp8266_d...
    - Deauth Detector: github.com/spacehuhn/DeauthDe...
    My 4 Lamps (amazon links are affiliates):
    - LYASI E27 9W: amzn.to/2KshhAE
    MY9291 Data = GPIO 4
    MY9291 Clock = GPIO 5
    Pinout: drive.google.com/file/d/0B0OE...
    - [My recommendation] Bawoo E27 7W: amzn.to/2EUjyRH
    Uses PWM to controll the LEDs
    RED = GPIO 14
    GREEN = GPIO 12
    BLUE = GPIO 13
    WHITE = GPIO 14
    - Avatar E14 5W: amzn.to/2KpSai4
    MY9291 Data = GPIO 13
    MY9291 Clock = GPIO 15
    - Hama GU10 4.5W: amzn.to/2KwP9N7
    RED = GPIO 4
    GREEN = GPIO 12
    BLUE = GPIO 14
    WHITE = GPIO 5
    Other mentioned resources (amazon links are affiliates):
    - MY9291 Arduino library: github.com/xoseperez/my92xx
    - USB Serial Adapter (US): amzn.to/2MswDYE
    - USB Serial Adapter (DE): amzn.to/2ETUwCh
    - Cable Hooks (US): amzn.to/2WO0gaM
    - Cable Hooks (DE): amzn.to/2WNZxX6
    - FrogBoard for programming: www.tindie.com/products/fred_...
    - Boards by Travis Lin: www.tindie.com/stores/lspoplove/
    - Seytonic: / @seytonic
    - Kody from Null Byte: / @nullbytewht
    - EverythingApplePro: / everythingapplepro
    Website: spacehuhn.com
    Github: github.com/spacehuhn
    Twitter: / spacehuhn
    Patreon: / spacehuhn
    Discord: / discord
    InsecureSpace Podcast: insecurespace.com/
  • Наука та технологія

КОМЕНТАРІ • 107

  • @spacehuhn
    @spacehuhn  5 років тому +45

    💡Do you want to see preflashed smart light bulbs and if yes, with what firmware?

    • @Luca-gb1og
      @Luca-gb1og 5 років тому +1

      Ich habe das in einem separaten Kommentar geschrieben. Habe dein Kommentar erst später gesehen

    • @gimenesrafael
      @gimenesrafael 4 роки тому +1

      Maybe an open source to do in the most safe way possible even if limited. Sorry by my english.

    • @gimenesrafael
      @gimenesrafael 4 роки тому +1

      What do you think about the Mozilla Iot Gateway ?

    • @NightShadow4467
      @NightShadow4467 4 роки тому +2

      Give us options. Let us pick and choose between deauther, deauther detection, and just normal open source light.

    • @JWSmythe
      @JWSmythe 4 роки тому +2

      I'd like to see them with a USB port, so I can just plug it into a PC, so it would be quickly and easily modified. Just like any Arduino or ESP developer board. If I had 50 lights, it'd be easier to do that, than to solder pins on and then flash.
      If it's easy to do, like this, the firmware is irrelevant. For me, ESPHome with a fallback standalone adjuster, would work well.

  • @SoCalRhetor
    @SoCalRhetor 2 роки тому +4

    This was really well done. I'm a layperson and I found it both informative and engaging. Well designed and executed --writing, narration and illustrations kept me focused for the entire clip. I look forward to watching more of your videos.

    • @spacehuhn
      @spacehuhn  2 роки тому

      Thank you that means a lot ❤️

  • @unclerico4644
    @unclerico4644 3 роки тому +1

    Your projects are so cool!

  • @jolansergerie-jeannotte11
    @jolansergerie-jeannotte11 5 років тому +9

    I will totally look into the hack to flash the firmware through the automated update. Avoid opening the thing

  • @dapeco
    @dapeco 3 роки тому +1

    Well done. Very informative. Did you do this from a script? You are very clear and organized in your thinking and presentation. I will watch this and take notes. I feel like I just had a short course in ethical hacking.

  • @mikeburgess5218
    @mikeburgess5218 5 років тому +6

    I'm really enjoying your video's, i'm a newbie into electronics and coding, but already bought and used the oled deauther (Maltronics), and now learning with a rasperry pi 3b+. Please keep the videos coming i'm learning a lot from you and assoc. :)

  • @BugZapper666
    @BugZapper666 4 роки тому

    Have you managed to flash the bulb at 6:33? I have a similar bulb but the board (I believe esp8285) doesn't have labelled pins and I can't find a datasheet anywhere!

  • @pyguy9915
    @pyguy9915 4 роки тому +3

    Great video, deserves more views : )

  • @jon_raymond
    @jon_raymond 5 років тому +22

    This was a solid and very informative video! Very well done.

  • @NiLuBu
    @NiLuBu 3 роки тому

    Is it possible to use one of the lamps with WLED? I want to use it with Hyperion. :D

  • @BabyDeer_Red4
    @BabyDeer_Red4 2 роки тому +1

    How do you determine the pins if they aren't labeled?

  • @BachtiarDwi
    @BachtiarDwi 3 роки тому

    is there any non hackable/flashable light bulb out there? that could probably not using esp8266 but other thing? i'm afraid i would get something like that

  • @Trekeyus
    @Trekeyus 3 роки тому +1

    Would be awesome to have a pre flashed bulb with the deauth detector

  • @johnjschultz5414
    @johnjschultz5414 3 роки тому +2

    You have a great sense of humor.

  •  4 роки тому

    Great video, thanks for sharing!

  • @upsidedown5564
    @upsidedown5564 5 років тому +2

    Very nice good editing and nice Tutorial

  • @mjyanimations1062
    @mjyanimations1062 3 роки тому +3

    i want to break into a smart light storage warehouse and sneakily flash every light bulb with deauther firmware

  • @shamkarthiks9351
    @shamkarthiks9351 5 років тому

    Can you help me to compile ino files in Android for esp8266 if there is a way?

  • @JasonSmith-xo7lq
    @JasonSmith-xo7lq 4 роки тому +2

    Thank you for all your hard work on bringing awareness of wireless/network security to the public. I have been a Network Engineer for over 25 years, going all the way back to the days of FidoNet (if you know what that is), and really enjoy following your work. Hats off to you sir.

  • @adamp185
    @adamp185 2 роки тому +1

    Great vid! No bull**ting, just good info! Thank you!

  • @boprosplumbing
    @boprosplumbing 3 роки тому +3

    nice video, covered exactly what i was hoping to find information on, perfectly. All the questions i had in my head when i showed up are answered and i got more useful information than i was expecting, Thanks a lot!

  • @nenioc187
    @nenioc187 4 роки тому +2

    Always make my own IoT devices. So thanks for the insight view of those light bulbs! Nice video!

  • @PhattyMo
    @PhattyMo 5 років тому +5

    I was thinking it might be interesting to add an SD card to one of these,to use as a file dump. Sort of an anonymous file sharing server. Something like Sparkfuns "Rogue Router". Typically an SD card would also use pins 12,13,14 though. I'm not sure if the SD card would be happy with having/sharing PWM all over it's data lines. Perhaps if there's a version using the ESP32,that also has some extra GPIO available to connect an SD card to. Or,perhaps you could replace the Flash chip with something larger,to have space for storing files.

  • @rijve11
    @rijve11 5 років тому

    Awesome video bro, your very intelligent 👍

  • @bjornlienemann8836
    @bjornlienemann8836 2 роки тому +1

    Very well informative and all . You must be German . Here in USA many take short cuts and leave a lot out . As I always seen and learned from my relatives in Germany are much more organized and explain in detail. Since I was 1st generation here in USA. I hate the bad habits I have picked up here and wish I had more knowledge from my relatives in Germany . Good job and I will be watching more of your videos and try and learn from you .

  • @to9836
    @to9836 4 роки тому

    Лучшее что я видел) У канала большой потенциал

  • @H3wastooshort
    @H3wastooshort 5 років тому +2

    Maybe sall a LigtBUlb that makes an AP and has som OTA Stuff on it so u can Programm it urself!

  • @vgamesx1
    @vgamesx1 5 років тому +3

    Thanks for the video, I didn't know about espurna and while I don't have any lights to hack, I did pick up a couple of super cheap LINGAN / TONBUX smart outlets and noticed they were obviously using an unbranded esp8266 inside and thought about hacking them, so I'll almost certainly do it sometime later.

  • @Blubb5000
    @Blubb5000 3 роки тому +1

    7:48 OMG! This is the worst stock photo I've probably ever seen. LOL!

  • @roboto_
    @roboto_ 3 роки тому +1

    to anyone looking to do this using tuya convert in 2020, tuya has started shipping with updated firmware that breaks tuya-convert. it's being worked on, if you want to help out check out the issue on github github.com/ct-Open-Source/tuya-convert/issues/483 or even better the wiki page github.com/ct-Open-Source/tuya-convert/wiki/Collaboration-document-for-PSK-Identity-02
    great video btw lol

  • @CyborgElf
    @CyborgElf 5 років тому +3

    Very cool. (That everything apple pro video made me cringe also)

  • @levo5552
    @levo5552 5 років тому +5

    You couldn’t have uploaded this 2 days ago. I just ordered one of these

  • @maantjemol
    @maantjemol 5 років тому +8

    This guy is here hacking a fucking lamp, this is amazing

  • @jyotishmanbharali3757
    @jyotishmanbharali3757 5 років тому +3

    i desperately wait for your videos.

  • @fiiremonky
    @fiiremonky 4 роки тому

    Really appreciate this video. Today I started digging on a ESP8266 device that came with an app called "Magic Home" and tried to see how to hack it. Found out about security issues when I sniffed with wireshark.
    This is a good alternative on how to solve any security concern.

  • @theilluminatimember8896
    @theilluminatimember8896 3 роки тому +3

    I am definitely interested in open source smart home accessories!

  • @hareinjayasekara8740
    @hareinjayasekara8740 3 роки тому +1

    Really nice content

  • @__-yb2hq
    @__-yb2hq 3 роки тому +2

    Very cool vid.

  • @DayanandhanSubramani
    @DayanandhanSubramani Рік тому +1

    time to rip off that wipro rgb smart bulb 😂😂😂😂😂😂😂😂😂😂😂

  • @VincentFischer
    @VincentFischer Рік тому +1

    2020-2021 was a great time. My dollar store "action" had 3euro esp8266 bulbs with 806lm and warm/cold white light dimmable from "LSC" that could run tasmota. Now they silently switched to some obscure chinese chip that probably a cent cheaper >:(

    • @spacehuhn
      @spacehuhn  Рік тому +1

      Yeah noticed the same. Looks like they prefer other chips now that are not as fun to hack.

    • @VincentFischer
      @VincentFischer Рік тому

      @@spacehuhn Small correction in my case they switched to Beken chips which I found out later also have a tasmota like open source firmware (OpenBeken)

  • @ArztvomDienst
    @ArztvomDienst 3 роки тому +4

    During a stay in a rehabilitation clinic I found out they use 802.11 meshed fire alarms... makes me shake my head.

  • @Pia-hx8rz
    @Pia-hx8rz 5 років тому +1

    Thanks; Danke :)

  • @-indeed8285
    @-indeed8285 4 роки тому +1

    Thanks

  • @vinodhgd
    @vinodhgd 3 роки тому +1

    I like connect smart lights in wifi network without internet. Please advice

  • @DDBAA24
    @DDBAA24 2 роки тому +1

    My favorite part was when it ended. Gotta have a powerful ending.

    • @DDBAA24
      @DDBAA24 2 роки тому

      Your so right, they never go deep into the tech. It bothers me. Even 2 years later that's why I thought I should say the problem was never addressed. Never will be.

  • @burnzy3210
    @burnzy3210 5 років тому +2

    *laughs in philips hue*

  • @stanj7223
    @stanj7223 4 роки тому +1

    Vielen Dank! I just started playing with ESP8266, and luckily don't have any smart devices calling home to China on a regular basis... ;-) Yeah, that stuff will get hacked before it goes into service. (Laughs: 'Military-grade encryption' must be the Newfoundland army version)

  • @simplyshorts748
    @simplyshorts748 2 роки тому +1

    So what's your alternative? I love light and without wireless connection I can't change the settings of each lamp. Should I buy bulbs with buttons or should I just foregoe colored and dimmable lights?
    I see your point, but you can't say those lights are useless. If it wasn't for LED lights I would not work with electronics in my free time.
    Enough of the grumble:
    This is a very nice video. Actually I was looking for a video on how to hack remote controlled bulbs, but I stayed here :)

    • @spacehuhn
      @spacehuhn  2 роки тому

      You can use them with open source firmware or hack something together yourself, that’s great about them. For everyone else, I’d look at lights that are controlled through Bluetooth, ZigBee, or similar from a reputable brand. Not that they’re perfect, but still a lot safer compared to these trash noname Wi-Fi lamps.

  • @brianp.s329
    @brianp.s329 2 роки тому +1

    15:39 lol it's funny.

  • @me0wsky
    @me0wsky 3 роки тому +3

    This is interesting, but the funny thing is I've ordered some cheap wifi lightbulbs to actually improve my security. The idea is that while I am away from home for a couple of days or more, I can turn on the lights in the evening to simulate activity and scare off burglars because, in my opinion, they are a far larger threat to my security than some chinese data-mining operation. Also reflashing with open-source software seems like a good idea, I might try that.

    • @SoCalRhetor
      @SoCalRhetor 2 роки тому

      Not really a funny thing considering he anticipated this point, noting that for him, the cost outweighs any benefit that might come from this (trivial, might I add) proposition.

  • @naveenkumar-nn7iv
    @naveenkumar-nn7iv 5 років тому

    Dude u r awsmm....

  • @saurabhgoel6725
    @saurabhgoel6725 5 років тому +2

    Amazing video with meaningful content. Good work.

  • @j.kakaofanatiker
    @j.kakaofanatiker 4 роки тому +1

    0:40 Ok. I will throw my Hue bridge and ligtbulbs and a beta product that works with them out of my window...

  • @bruceadonnelly69
    @bruceadonnelly69 3 роки тому

    Bought led dimmable bulbs... can you explain about these please. I thought dimmable meant just can be dimmed from light switch.

  • @luiscohnen2009
    @luiscohnen2009 3 роки тому

    I am searching for a light bulb with esp8266 inside. Can you name a specific one? I already ordered some but did not find the right one yet.

  • @nightviper7354
    @nightviper7354 4 роки тому

    what can you do with a light bulb you managed to hack?
    turn off the lights? oh no what a nightmare

    • @Trekeyus
      @Trekeyus 3 роки тому

      Turn it into a wifi deauther

  • @lav830
    @lav830 5 років тому +2

    cool video

  • @SlitheringDemon
    @SlitheringDemon 5 років тому +1

    Yeeeeet

  • @FriendlyWire
    @FriendlyWire 5 років тому +1

    Yikes. Thanks for making this video!

  • @muzanunciacion
    @muzanunciacion 3 роки тому

    I bought a ir remote rgbw bulb.. i want to open all the lights in one.. can you please help me.. i just want to open all the lights steady..

  • @alexka2
    @alexka2 3 роки тому

    Hi! Can anyone please help me to figure out the pins of the new Shelly Bulb? OTA went to fail, so I’d go with Tasmota, but cannot find any info about its pins.

  • @uainfo8606
    @uainfo8606 2 роки тому +1

    Tyyy

  • @Luca-gb1og
    @Luca-gb1og 5 років тому +1

    Pls sell a lamp with the deauth detector software! Because the deauther software isn’t very useful in a lamp you have to power with a huge cable. Oder verändere die deauth detector software so, dass man die Lampe normal benutzen kann ( Farbe wechseln und so) und das erkennungs feature ein Zusatz ist. Am besten kann man noch die Farbe des deauth erkunngs Alarm ändern oder dass es pulsiert.

  • @mrcarrino
    @mrcarrino 4 роки тому

    I agree, there are a lot of well-done videos but the depth doesn’t go past what a slightly aggressive DIYer would do. They are good to get you started but there’s a certain point where you have to fend for yourself.

  • @istvanilosvai2962
    @istvanilosvai2962 3 роки тому

    Imagine a lightbulb looking to your hated neighbour

  • @jamcdonald120
    @jamcdonald120 3 роки тому

    shouldnt step 6 be step 1?

  • @boira817
    @boira817 2 роки тому

    hi sorry to bother ! most lightbulbs that sell in my country say ¨Wifi+Bluetooth¨ , does that mean that they dont have an ESP8266 and have some sort of ESP32 ? It does say that it uses the SMART LIFE app
    love your content btw , salutations from argentina

    • @spacehuhn
      @spacehuhn  2 роки тому +1

      Sounds like ESP32 to me

  • @NADA-id2wb
    @NADA-id2wb 5 років тому +1

    We need update for web interface of deauther firmware.. thank u

  • @Coderion
    @Coderion 3 роки тому +1

    Be careful when buying Smart Life Wifi Switches - they use a Realtek Chip instead of an ESP which is incompatible

  • @ElectricalSwift
    @ElectricalSwift 3 роки тому

    Im just looking to hook my light up to my pc for immersive lighting and dont want to waste hundreds for phillips hue.

  • @sgt.mikebaran7105
    @sgt.mikebaran7105 3 роки тому +2

    Motels Are Full Of These Things...Thats Why Hackers Go To Them

  • @piotrszulc9053
    @piotrszulc9053 3 роки тому +1

    I'm rather cs savvy (maybe never messed with flashing stuff but played around with arduino and working as programmer). I'm interested in buying these cheap rgb wifi lights to test if this is something I want and maybe then later move on to much pricier philips hue or something like that.
    I don't want to control this outside my home. I presume that blacklisting access to internet on my router would do the trick so that I don't end up with botnets on my network. Also it would be rather easy to analyze requests that these mobile apps for controlling lightbulbs sends. If something would seem fishy I'd consider going open source and flashing firmware or setting up separate network w/o access to internet.
    If someone breaks into my home and is able to access lightbulbs and flash them then I'd probably worry much more about everything else in my home than lightbulbs.
    If someone is able to spoof my internet well think about it. It's game over. I'd probably worry about my banking credentials rather than lightbulb.
    Metadata? Well I've Facebook app on my Google phone... Nevertheless analyzing requests and disabling accesss to internet should do the trick am I right? If somethings fishy then turning to open source is solution.
    Well I'm more paranoid that these light bulbs might be ticking bombs that would go off when I'm not present at home. Don't know but something like circuit shorting on purpose -> increase of temperature -> fire. I'd assume that when light connector is in off state then it shouldn't be possible. And when going away on holidays probably take them out.
    So I'm planning to give it a go, yolo. Probably everyone has mic and wifi spoofer in their electric kettles mass produced in china, sike :o

  • @mnageh-bo1mm
    @mnageh-bo1mm 5 років тому

    Hi dude all your videos are great but we need a fluxion esp

  • @disfeed
    @disfeed 5 років тому

    100th like!

  • @TravikSkoot
    @TravikSkoot 5 років тому

    Hier sind ja kaum Deutsche xD

  • @Bigdsavage45
    @Bigdsavage45 5 років тому

    Mach mal deutsche Videos was dieses Probe Attacks nutzt und so

  • @pierrotkwezituka3150
    @pierrotkwezituka3150 3 роки тому

    ugh whatever he is just trying to impress people