ecrawford-0 / Capstone

3 stars 0 forks source link

Threat Actor Scenario Prep - MITM attack with Flipper Zero and apple pay #56

Closed ecrawford-0 closed 1 year ago

ecrawford-0 commented 1 year ago

This possible task might be a reach considering it appears that apple pay secure from preliminary research, but we would like to test if its possible to intercept an tap to pay between our two devices with the flipper zero.

ecrawford-0 commented 1 year ago

I found out that when sending money to each other its through sms not nfc. The only way to test this is if we had some kind of legitimate pos terminal, we could try intercept the radio frequencies, but we don't have that

ecrawford-0 commented 1 year ago

I tried to see what happened if I tried reading a NFC card with the flipper between that and the NFC card reader, but it didn't really work. It appears the flippers nfc reading range is shorter than the card reader so unless the flipper zero is attached to the card, the card reader would read it before the flipper did.