██████╗ ██╗ ██╗███╗ ███╗███████╗ ██████╗ ██╗ ██╗███████╗██████╗
██╔════╝ ██║ ██║████╗ ████║██╔════╝██╔═══██╗██║ ██║██╔════╝██╔══██╗
██║ ███╗███████║██╔████╔██║█████╗ ██║ ██║██║ ██║█████╗ ██████╔╝
██║ ██║╚════██║██║╚██╔╝██║██╔══╝ ██║ ██║╚██╗ ██╔╝██╔══╝ ██╔══██╗
╚██████╔╝ ██║██║ ╚═╝ ██║███████╗╚██████╔╝ ╚████╔╝ ███████╗██║ ██║
╚═════╝ ╚═╝╚═╝ ╚═╝╚══════╝ ╚═════╝ ╚═══╝ ╚══════╝╚═╝ ╚═╝
Rolling Code Jam + Capture + Replay PoC for Flipper Zero.
The RollJam attack (Samy Kamkar, DEF CON 23) exploits rolling-code systems by:
- Jamming the target frequency so the car never receives the keyfob's code
- Capturing the code the keyfob transmitted (despite jamming)
- Replaying the captured code later to unlock the car
Phase 1 — Jam + RX (180ms jam / 80ms RX cycles):
Keyfob sends Code A → Car jammed, ignores it → Flipper captures Code A
Phase 2 — Same cycle:
Keyfob sends Code B → Car jammed, ignores it → Flipper captures Code B
Phase 3 — Replay:
Flipper transmits Code A → Car opens ✓
Code B stays valid → attacker's spare key
- Interlaced jam+RX timing: 180ms OOK noise burst → 80ms RX window → repeat
- Signal capture: interrupt-driven, packed LevelDuration (bit31=level, bits0-30=duration µs)
- Signal replay: async TX directly from capture buffer
- Frequency: 433.92 MHz · Modulation: AM650 (OOK) · Internal CC1101 only
Copy rolljam_research.fap to /apps/Sub-GHz/ on your Flipper Zero SD card.
Requires: Flipper Zero with G4MEOVER-FW or Momentum firmware, internal CC1101.
ufbt # in the rolljam/ directory| Repo | Description |
|---|---|
| RollLab | Rollback / sync-window / signal analysis tool |
| ProtoPirate | 27+ protocol decoder/encoder for Car Keyfobs |
| G4MEOVER-FW | Custom Flipper Zero firmware (Momentum fork) |
For authorized security testing, CTF competitions, and educational research only.
Use only on hardware you own or have explicit written permission to test.
- Bitcoin:
39vZWmnUwDReQ15BwqQXzyqVQ6U8LardEf
Kontakt: g4me.over.18@gmail.com
- PayPal: paypal.me/Freakbank1
G4MEOVER18 · GitHub