Enabling the hidden Wi-Fi radio on the Philips Hue Bridge 2.0: Adventures with 802.11n, ZigBee 802.15.4 and OpenWrt

Wiring up the serial port

Fault injection to boot loader

Root password

Remote shell via SSH

Exploring the hardware & software

Chips

Block diagram of the QCA4531 (from linuxgizmos)

ZigBee Channels

  • channel 0 = 868.3 MHz
  • channel 1–10 = 902–928 MHz (2 MHz)
  • channel 11–26 = 2.4–2.835 GHz (5 MHz apart, 2 MHz bandwidth)
  • channel 11 = 2405 MHz
  • channel 15 = 2425 MHz
  • channel 20 = 2450 MHz
  • channel 25 = 2475 MHz

SDR?

Firmware

Enabling the Wi-Fi interface

Configuring WPA2

DHCP configuration

Moving services to Wi-Fi

Opening up the firewall

dropbear

hk_mdns, hk_hap

Unplugging the Ethernet

Conclusions

--

--

Love podcasts or audiobooks? Learn on the go with our new app.

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store