HomeSecurityHackers can unlock hotel doors through Unsaflok vulnerabilities

Hackers can unlock hotel doors through Unsaflok vulnerabilities

Researchers have uncovered vulnerabilities (Unsaflok) affecting 3 million Saflok RFID electronic locks in 13,000 hotels and homes around the world. The researchers were able to easily unlock any door in a hotelby forging a pair of key cards.

Unsaflok vulnerabilities

The vulnerabilities were collectively named “Unsaflok” and were discovered by researchers Lennert Wouters, Ian Carroll, rqu, BusesCanFly, Sam Curry, shell, and Will Caruana in September 2022.

The researchers were at a private hacking in Las Vegas, where they competed with other teams to find vulnerabilities in a hotel room and all of the devices in the room.

The researchers focused on the Saflok electronic lock and discovered vulnerabilities that could open any door within the hotel.

The vulnerabilities were reported to the manufacturer Dormakaba in November 2022, who had time to work to fix the issues and inform all hotels of the risk, without making the issue public.

See also: Atlassian fixes critical vulnerability in Bamboo Data Center

However, according to the researchers, these vulnerabilities have existed for more than 36 years, although there have been no confirmed cases of exploitation.

Now, researchers have publicly disclosed the Unsaflok vulnerabilities, warning that they affect nearly 3 million doors that use Saflok electronic locks.

Unsaflok Vulnerabilities

When the vulnerabilities are linked together, they allow an attacker to unlock any room door in a property using a pair of fake key cards.

The exploitation begins with the attacker reading a keycard, which could be the keycard from their own room.

The researchers reverse-engineered Dormakaba's front desk software and a lock programming device to see how they could forge a master key that could open any room in the property. To clone the key cards, they had to break Dormakaba's key derivation function.

Counterfeit key cards can be created using any MIFARE Classic card and any commercially available tool capable of writing data to these cards (e.g. Poxmark3, Flipper Zero and an NFC-enabled Android smartphone).

As the researchers explained, the equipment used to create the two cards in the attackcosts less than a few hundred dollars.

See also: Ivanti patches a critical Standalone Sentry vulnerability

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Saflok electronic locks hotels

When exploiting vulnerabilities in the Saflok electronic lock, the first card rewrites the lock's data and the second card opens the lock. There is a video showing the process.

The researchers have not provided further technical details at this time, in order to allow time for hotels and homes to upgrade systems .

Unfortunately, the Unsaflok vulnerabilities affect many Saflok models, including the Saflok MT, Quantum series, RT series, Saffire series, and Confidant series (System 6000 or Ambiance software).

As we mentioned earlier, vulnerable locks were found on three million doors in 13,000 properties in 131 countries.

Researchers say that Dormakaba has been replacing/upgrading locks since November 2023, which also requires reissuing all cards and upgrading their encoders. So far, 64% of the locks remain vulnerable.

“It will take a long time for most hotels to be upgraded.”.

See also: GitHub Code Scanning Autofix: New AI tool fixes code vulnerabilities

Hotel staff may be able to detect instances of active exploitation by reviewing the logs lock's entry/exit. However, this data may still be insufficient to accurately identify unauthorized access.

Guests can determine if their room locks are vulnerable to the Unsaflok bugs by using the NFC Taginfo app (Android, iOS) to check their key card type from phone . MIFARE Classic cards indicate a potential vulnerability.

These vulnerabilities affect the security of hotels and homes by allowing malicious users to compromise the Saflok electronic lock. This means that attackers can gain access to hotel rooms or homes without having to have the original key.

This can trust customer in hotels and home rental companies. If customers don’t feel safe, they may decide not to stay in a hotel or rent a home that uses these locks.

As a result, Unsaflok vulnerabilities can lead to significant financial losses for hotels. This can happen either due to loss of customer trust, or due to the need to upgrade or replace locks.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS