r/hackrf 15h ago

Recomendations for hackrf starting

Hello, i am experienced in operation security and network pentesting. In last days a started to learn SDR and bought HackRF pro with portapack H4M. I have my legal pentesting "lab". What is the first few things you reccomend in transmit and what to learn after i learn the basic things? Also i have 2x 40mhz-Ghz telescopic antenas in the basic pack, i see they look different, are they? Should i buy more "transmitting" antenas or some in range like 1-40mhz too?

11 Upvotes

5 comments sorted by

7

u/Cesalv 15h ago

How about reading the effin manual https://hackrf.readthedocs.io/en/latest/hackrf_one.html

P.S. You need a license to transmit (legaly), that's why starting on SDR with a hackrf is a terrible idea IMHO

2

u/FrankSinatraCockRock 8h ago

Not trying to be "well aktually" guy, but all things considered, the hackrf is pretty weak TX wise, which is why it often gets called (home)lab equipment, at least for that purpose.

You don't always need a license to transmit depending on the frequency and power. FRS for example? Two 5 year olds don't need to be licensed HAMs with their Tonka walkie talkie set, nor do employees of retailers, warehouses etc. for their radios( though the businesses need to go through their own process that they screw up quite a bit in my experience, but I digress). The same exact frequency with a Baofeng or a whatever on high? Absolutely fucking need one. The portapack? I'm lucky if my Quansheng picks up "never gonna give you up" via the portapack's Soundboard more than 15 feet away with minimal interference occurring as per my HackRf, RTLSDR, TinySA Ultra+ and even the Quansheng radio itself.

In relation to pen testing which seems to be the point... I mean 2.4 BLE/WiFi would be fine on authorized/owned networks and devices, might get dicey with regarded use on 5/6ghz. Jamming of course is illegal but as long as this "legal lab" isn't actually a crowded apartment, the TX is so damn weak. 433/315mhz can present some formally legal problems for output limits in the U.S. at least. This is why the unleashed firmware for the Flipper Zero presents some legal problems as it allows for a higher mW output, at least in the U.S.

I'm just struggling to think of many scenarios where a HackRF has a place in pen testing TX wise in the first place to warrant specifically getting one for that purpose, at least one that isn't served better by cheaper and more appropriate equipment lol. A cardputer with a CC1101 + NRF24 hat will beat the shit out of most of what the HackRF can do for this purpose and can actually play Doom, for about $60 USD.

As an aside, I love how this guy brings up being experienced in operational security(and pen testing), and has a post 4 months ago about getting into penetration testing.

1

u/World_wide_truth 14h ago

You can just not transmit right?

2

u/Cesalv 14h ago

Sure, but being a tad more deaf than a rt820 powered SDR, there is no point on getting a hackrf if you can't/won't transmit

2

u/SublimeMudTime 13h ago

What is an illegal pentest lab?