Former Fujitsu Laboratories security researcher Jesus Molina participated in this year's Black Hat in Las Vegas, describing to his audience how he managed to gain control of 200 rooms of a luxury hotel in China.
During his stay at the St. Regis Hotel in Shenzhen, the now independent researcher analyzed the remote control system provided to customers to control the various functions of the room: to adjust the lighting, temperature, music, operate the television, and even the windows.
The remote control was an iPad2, so after analysis, Molina found that the entire system was based on the KNX/IP home automation protocol, which contained significant vulnerabilities.
The researcher identified and exploited these specific vulnerabilities, managing to gain control of the televisions and the rest of the rooms, as well as all functions that were set via the remote control.
The researcher said an attacker could create a trojan to control guest room systems remotely, without having to be in the hotel — they could even be in another country, Molina noted.
“The criticality of these types of security gaps should not be underestimated – think for example of creating a chaotic atmosphere by increasing the temperature of rooms at night, with fatal consequences. Hoteliers should understand the risks and liabilities they are exposed to through faulty security systems,” the researcher pointed out.

