Hacking My Landlord's Boiler: A Replay Attack Story
2025-04-22

Frustrated with his apartment's inefficient and uneven heating system, the author devised a clever solution using a replay attack. Leveraging inexpensive SDRs (an RTL-SDR and a HackRF clone), he intercepted and replicated the 868MHz radio signals between the existing thermostat and boiler. This allowed him to remotely control the boiler's on/off state. Despite significant challenges, he successfully integrated this into Home Assistant, creating custom automations and using sensors to achieve comfortable temperature control.
Read more
Hardware