Breaking into a house using a Power Bank!

Or… how insecure is the two wire video doorbell implementation from Avidsen.

About a month ago I bought the Avidsen Visiophone YLVA 2+ and the reason why I chose to buy a wired video doorbell over a wireless one, was due to security concerns. Lucky me… I found that with the current device it takes almost the same time for someone with a Quick Charge enabled Power Bank to enter my house as with someone with the door’s key!

Immediately after unboxing the doorbell and removing the single screw from the doorbell for an initial inspection I noticed that both Entry Gate’s and Door’s control electrical contacts where located at the doorbell site. Wait… it couldn’t be, I may be wrong… let’s read the manual.

Page 27 of the PDF (Page 7 of the English Version manual):
No! Bad luck! Exactly what I thought!
Avidsen videophone
Page 29 of the PDF:
The doorbell, with all the controls, is secured in place with a single Philips screw without any form of tamper protection!
Doorphone installation

Page 32 of the PDF:
How to control a 12V electric strike plate for the door and the Gateway entry control:
Door and Gate control

How to get 12V from a QC Power Bank

Power Bank’s rated as QuickCharge 3 (QC3) and later, can output 12V by using Sam Mallicoat’s reply from hackaday:

It’s easy to set a QC3 supply to 12V with just two resistors and a toggle or push button switch. Here’s how: Take a 10K Ohm and a 2.2K Ohm and solder in series across the Vbus (red) to ground(black wire). The tap between the two resistors will measure about a Volt. Solder D+ (green to this tap. Then wire the D- (white) through a N.O. switch to the same tap.
Apply adapter or power pack supply and wait 1.5 seconds to push the button. Presto, 12V @1.5! No need to hold the button, the supply stays at 12.

Schematic [Updated: 03/07/2020]

Get 12V from Quickharge
The output when using a Blitzwolf BW-P6, 10000 mAH with Quick charge 3.0

Breaking into the house

So the procedure is as follows:
1st Step: Unscrew the single Philips Screw.
2nd Step: Apply 12 volts to LK+ and LK- contacts.
3rd Step: Get into the house! (Optional, screw the doorbell back to leave no traces)

This is a serious security issue and every owner should be aware of.

I tried to contact Avidsen from their site’s Contact Form and using two emails from their contact page without any luck. I hope that this post will reach owners out there to avoid any bad situations.

Furthermore, my doorbell is not the only model. There are many more :

Even some of their 4 wire Video doorbells have the same vulnerability:

The same problem seems to exist on their wireless model also:

Be careful… this is not the only company with this vulnerability

After my findings with the current device, I found out that there are many companies out there using two wire implementations for doorbells leaving entrance control exposed. Pay special attention if you plan to buy or already using a wired doorbell for the way the entrance control works. Most of the times the manuals are online, so you can avoid situations like this one.

0 0 votes
Article Rating
Subscribe
Notify of
guest
55 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
Max

The schematic for getting 12V out of a Powerbank seems to contain an error.
Your ouput-terminals (or what I assume represents the output based on the +/- labels) are shorted together and connected to D+. I assume you meant to take the power from vbus and gnd, but maybe you should update your schematic.

Roamin

I don’t think the picture with the silicone gun is to protect someone from opening the box, but rather so that water doesn’t infiltrate between the wall and the back on the doorbell. The text only says to wire 2 or 4 wires depending on the system , and then to test the video call.

CityZen

I think the caulking is just shown for weatherproofing the wiring, or for making a neater installed appearance, but not for security (since they show the caulk bead going between the panel back and the mounting surface instead of between the front and back panels).

Volker

Your schema is off and won’t provide ANY voltage to the outputs because there is a short circuit between the two output poles..
The output probably is between VBUS and GND (“before” the resistors, not after), i.e. directly attached to the powerbank?

trackback

1terrifying

trackback

1plurality

trackback
trackback

writing a doctoral dissertation https://professionaldissertationwriting.com/

trackback

writing your dissertation in https://helpwithdissertationwritinglondon.com/

trackback

help dissertation dissertation help https://dissertationhelpexpert.com/

doctoral dissertation defense https://accountingdissertationhelp.com/

dissertation cover page https://examplesofdissertation.com/

dissertation literature review help https://writing-a-dissertation.net/

writing a literature review for a dissertation https://bestdissertationwritingservice.net/

dissertation writing help https://businessdissertationhelp.com/

dissertation statistics help https://customdissertationwritinghelp.com/

trackback

research writing services https://dissertationhelpspecialist.com/

writing your dissertation proposal https://dissertationhelperhub.com/

trackback

format for writing dissertation proposals https://customthesiswritingservices.com/

hotspot shield free vpn https://freevpnconnection.com/

trackback
trackback

zenmate free vpn https://freehostingvpn.com/

trackback

use vpn to buy crypto https://ippowervpn.net/

trackback

avast vpn buy https://imfreevpn.net/

trackback

buy vpn account https://superfreevpn.net/

vpn free download for pc https://free-vpn-proxy.com/

gay dating in louisiana https://gay-singles-dating.com/

gay piss play dating https://gayedating.com/

trackback

frer gay male dating app https://datinggayservices.com/

trackback

local-singles club https://freephotodating.com/

trackback

best free online dating https://onlinedatingbabes.com/

trackback
trackback
trackback

meet european singles in usa https://speedatingwebsites.com/

trackback

dating gmail germany https://datingpersonalsonline.com/

trackback
trackback
trackback

which is best online dating site https://zonlinedating.com/

tinder dating site pictures women https://onlinedatingservicesecrets.com/

trackback

online casino with free signup bonus real money usa https://onlinecasinos4me.com/

trackback

gay and bi chat and hookup https://newgaychat.com/

gay masturbation live chat https://gaychatcams.net/

naked gay chat rooms https://gaychatspots.com/

trackback

arab friends gay webcam chat https://gay-live-chat.net/

gay geek chat https://chatcongays.com/

gay chat and hookup https://gaychatnorules.com/