← All projects
RF SecuritySub-GHz · RF Forensics
433 MHz Doorbell RF Replay
Intercepted and replayed sub-GHz doorbell transmissions programmatically.
01 · The problem
Fixed-code RF transmitters can be trivially replayed — demonstrated on a doorbell.
02 · Approach
- 1
Scanned 433.91 MHz with RTL-SDR / Airspy and Gqrx.
- 2
Saved raw IQ data of the transmission.
- 3
Replayed via a Raspberry Pi transmitter (rpitx / sendiq).
03 · Outcome
Triggered the doorbell on demand, illustrating the security flaws of fixed-code RF.
Next projectCar Keyless Entry Replay (Raspberry Pi)→
