About Us
Products
The Alarms
Contact Us
Forum

The Alarms Theft Methods

THEFT METHODS AND PROTECTION AGAINS THEM

These methods are several:

ATTAC WITH ROUGH MEASURES
In this case the thieves stake on the combination of speed, rough measures and enough learning in electrical installation of the car. They break the car and the alarm system arms inevitably. After that they open the engine hood. There are several ways to stop the siren sound. If the siren is non-autonomous, i.e. without built in supply, the cables disconnecting will automatically cause the stopping. If the siren is autonomous the cables disconnecting will not help and in this way the thieves resort to breaking with hummer. After the siren has stopped the thieves look for the relay locking the engine. If the system is from this type where the alarm is with normal opened contacts of the locking relay and it is built in the alarm there is only one way to disarm the interlock namely to find the alarm /that is why the installation is so important/ after that to follow the wires on which system elements correspondent to can determine the couple of cables which has to be …… to start up the engine. In this type of alarm systems the ignition is very hard.

Rough Measures

If the alarm has an interlock type – normal closed contacts and the relay is external it is no needed to resort to the methods mentioned above because all you need to do is to find the alarm and to pull out the alarm's couplings.

There is and another method for disarming the interlock – to have a knowledge of the ignition system of the concrete car to can bypass the interlock with feeding +12V ground signal or other signal according to the supposed interlock.

The Lesi 2000 systems use only built in relays for locking the engine with normal opened contacts.

 

 

ATTAC FOR VALUABLES
In this case the purpose is to dismantle some of the glasses without jerky hits which can arm the shock sensor. After that thrust thief's hand in the car and get valuables. In this case is good to install a volumetric sensor.
The Lesi 2000 systems have inlet for dual-zone volumetric sensor which is completely programmable in contrast to other rival alarms and gives opportunity to choose a different security mode in which to combine the shock and volumetric sensor work as well as to turn them off or on independently each other.

 

CODE ATTACK
The most vulnerable place to attack the alarm system is its code which is emitted at each button pressing. The mass wide-spread security systems are with so called “fixed code” to can support a low price.
Code AttackIn practice this means: Each time you use the remote control it emits a digital code on exact frequency /300-480 MHz/ and the alarm indicates which button is pressed at the moment and what command has to be realized. In the alarm with fixed code the base of the emitted code is the same each time you press a button. Only the first two bits show which button is pressed. You can catch record and use this code by a device costs only 40-50 levs and which device can be made by thousands of engineers in Bulgaria . In practice big part of unprofessional car thieves own this kind of device. With its help the car can be opened, robbed and locked again! The price of such alarm systems is maximum 90-100 levs but the fact that they realize no security makes them very expensive devices. The myth for the alarms with fixed but double code /i.e. to disarm the system you have to press button 1 first and then in 5 seconds to press button 2/ is a fraud because in the code analyst automatically is recorded the number of the pressed button. It is all the same child can read and write and do not know that in the alphabetic B is after A.
Because of the requirements of Instruction 104 our firm does not produce alarm systems with fixed code.
The only alarm systems which deserve their price are these with random or dynamic code – each time you use the distance control it changes the emitted code. In the alarms with fixed code the maximum number of code combinations is 16 millions and only one of them is used. The sense of the number of combinations is your neighbor does not have an alarm system with distance control as yours. The number of combinations is without sense when the code is recorded over the ether. In the alarm systems with random code the number of combinations is 1.8 x 10/19 or 18000000000000000000 /18 trillions/ and each time you press a button the code is different. I.e. in the alarm systems with random code it is senseless to record the code because in practice it will not be used again. If we have to imagine that it is the same as if we have a strong iron door and in the firs case /fixed code/ it is locked by bolt and in the second case /random code/ it is locked by lock with quadrilateral fastening and each time you cross the door the cartridge with key changes!

The standard random code has its own weakly side for attacks – the algorithm used for changing the code. This changing is not random and it is dependent of a mathematical formula. At all kind of systems /without Valcor/ this algorithm is recorded in an external for the processor chip which makes its drawing out possible and then easy making of code analisator for random code systems. Each time pressing a button from the remote control with random code it emits a code consisted from two parts – fixed – unique for each remote control which doesn't change and changeable – calculated on the basis of the fixed part and the mathematical algorithm for code generating recorded in the remote control. This algorithm is known to the alarm too and it is the same for all remote controls. Receiving a signal from the remote control this signal is ………….. to can the alarm understand which button is pressed. If this algorithm is known to the thieves the disarming of the system is no problem. Because of this the Valcor security systems use new generation random code with increased security which is expresses by a pseudo-accidental order of codes and each remote control uses different unique algorithm based on 6 64-bits matrixes combined by the help of algorithms Lesi /” 1” – till 2000 year; “ 2” – till 2003 year or “ 3” – after 2004 year/ which provide high security level and reliability. All of these measures and algorithms which the alarm system uses stultify the usage of devices like code recorders, grabbers, scanners and computers from highest generation for disarming the alarm. Once used code can be repeated in 20 years at the earliest if you press a button over 80 times per day every day!

Here you can see schemes for:

Generation and saving of unique ….. key for each transmitter;
Basic operations in generating and emitting the random code;
Operations at changing and decoding of the random code.

Although the breaking of the Lesi algorithms is practical impossible because of the huge data massive which you have to have /millions of recorded codes from different Valcor remote controls/ to can study the mathematical logic on bases of the codes changing our firm politics is to change these algorithms completely in a certain period of time. In this way it is senseless to try to make or produce a code analysator for Valcor alarm systems. From 2004 year the new generation algorithms are Lesi 3. In practice there is only one way to control a Valcor alarm system by the remote control:

This method is so called “block the radio air”.
If the thieves follow a marked car they can prevent the owner to arm the system by emitting a large transmitter which “block the radio air” of the remote control. In this way they prevent the alarm to accept a code arming the system.
In this case if the alarm works correctly when you leave the car and when you came back it doesn't work the probability the alarm system is broken is little and probably there is a block of the radio air. It is recommended to move your car even you are not sure that the attack is against you.
The another way for using the “block the radio air” method is when the alarm system is already armed and in this case you take part in this action actively. It uses a special feature of a random code principal of work namely after the alarm system accepted the last signal it recalculates an awaiting code emitted from the remote control.
If the remote control emits a signal which is not accepted by the alarm it stays in the alarm memory as an active and true code. In case this code is recorded it lets the thieves to execute a command to the alarm system! As many codes are emitted and not accepted as many times you can arm and disarm the alarm system. But it is impossible to follow you all day with recorder and to expect when you will press a remote control button outside the alarm scope. But to provoke you to do that they do the following:
They switch on a powerful transmitter on the alarm frequency. In this way they prevent the opportunity the system can accept a code and to recalculate the next. After that they hit the car to arm the shock sensor, the siren starts and they wait for the owner to come and start pressing buttons from the remote control to stop the siren.
In the near there is a receiver tuned on the remote control frequency which “listen” and record each code emitted by the owner. As many times you use the remote control as many true codes are emitted /but the maximum number is 16/. The radio-air attack continues till the owner leaves angry that the alarm system is broken and can not be disarmed /the alarm system stops alone after 20 seconds/.
This is because of the principle of work of the random code – if you have emitted for example 10 valid codes and the alarm did not accept them, but the 11 th code is accepted the other 10 loose validity. In this way if the thieves can compel the car owner to leave without emitting a code accepted from the alarm the thieves will dispose with number of valid codes!
If you have in practice this situation or you have suspicion for that open the car, shorten the emergency outlet or disarm the alarm system with the service mode /if your model supports this mode and if it is programmed for this/ and immediately move the car! If you succeed to emit a code which the alarm accepted and do not press buttons again in fact you will delete the codes recorded by the thieves.
There is and another method for disarming Valcor but it has almost zero possibility for success and you rely on only the luck /the chance for success is billion times less than the chance to win from the tote/. The arming code is recorded. As you know it can not be used again but the fixed part of the recorded code will take part in the next code expected from the remote control. The algorithm in the alarm random code has a special protection for mistakes and with its help when the system recalculates the next expected code it doesn't recalculate one concrete code and a massif of codes /16/.
If you emit some of them the alarm system will submit to it immediately. If you emit a code out of these 16 but probable for using in the future the alarm will accept it but will not submit to it because will expect emitting a concrete code which is right behind the emitted already true code as a value but not expected in this moment code.
This is so called defense against loss of synchronization between the alarm and the remote control in case it be pressed over 16 times outside the alarm scope. By emitting two serial true codes the remote control authorizes in the alarm memory and it recalculate a new massif of codes 16 of which are true and the alarm system submits to them.
At the time of chaotically emission of codes from the thieves code analizator on the basis of the before recorded fixed part the possibility to hit one of the these true 16 codes is 1,8 x 10 on 19 degree divided by 16 which is in practice = 0!!! It is probably to hit a true code for accepting in the future. But in practice it is impossible the thieves to have such a big luck that the next code is this that the alarm expects to synchronize.

In this case the attack with guessing the codes can continue thousands years without luck.
If during the attack a true code but out of these 16 is hit the original remote control loses synchronization with the alarm. In this situation when the car owner comes back and press the remote control button once the alarm will not submit.
To restore the synchronization you have to press a button twice after that the alarm will recalculate the new massif of 16 codes and the remote control will work correctly. In this case after the alarm is disarmed it will report for try for attack and the alarm event is from type “loss of synchronization”.
If the attack continues for a long time and there are several true codes hit but out of these 16 on which the alarm submits to immediately, it is possible to lose synchronization even with twice pressing a remote control. In this case the original remote control has to be recorded in the alarm memory again. The recording in fact transfers certain unique mathematical algorithms for each remote control on the basis of the alarm calculates the probable true codes!
Everything said above means that Valcor security systems can not be disarmed by a remote control. The main reason for this is the extremely complicated way for calculating codes and the hardware decision where the random code algorithms are not in an external chip and they are part of the alarm software and placed in the processor and their extraction is impossible.

 

ATTACK WITH STUN GUN
The most of the security systems at the Bulgarian market can be disarmed for only several seconds with stun gun.
The electrical stick is device for self-protection which generates for a short period of time. Because of the low price and hardware specifications the alarms burn out immediately when apply this voltage on the electric circuit connected to the alarm.
Stan Gun AttackSuch circuits are car blinkers, the front hood button, and the LED indicator on the car panel is the surest way to burn out the electric circuit. The siren stops to hoot and the engine can be switched on because at these alarm systems the engine interlock is done with normal closed contacts.
All security systems which our firm produces can not be disarmed with electrical shock stick and this is proven with many tests over some elements and conditions which are inaccessible to the thieves. The whole hardware architecture is well up in the condition the electronics to stand a high voltage. Even that the engine interlock is made by a relay with normal opened contacts – in contrast with mass wide-spread security systems. This means even the alarm electronics burns out the engine can not be run because the car works normal only when the alarm system is in perfect condition.

 

CAR ROBBERY
One of the most dangerous methods for car theft is robbery during driving the car because in this way the driver is under menace too. Here the subjective factor is most important as well as the keeping yourself enough cool to can control the hi-jack system which most of the alarms have. The main principle of work of this system is pressing of some buttons combination from the remote control which will cause turning off the car from 20 to 50 seconds. Of course this is possible when the remote control is separate from the car keys /which is not likely/ or if the reserve remote control is with you. The subjective factor is very important in this moment because of that if you are afraid of robbery it is nice to bring the reserve remote control with you. But at the usual alarm systems even you turn off the engine by the second remote control the thieves can turn it on again by the first remote control which is in them with the car keys.
Only in the Lesi alarm systems the models which have such a hi-jack system independently which remote control you use to turn off the engine it is the only one which can turn it on again. This is possible because the system remembers the remote control code which is armed the hi-jack system and no other remote control can disarm it. At some alarm systems from higher class /Valcor VR 72, 74/ the hi-jack system can be armed even the thieves forced you to give them the keys. After you turn on the engine if you do not press a hidden button in several seconds after 40 seconds the engine will turn off.

 

ALARM UNINSTALLATION
This is a theft method which is extremely uncomfortable for using if the alarm is installed professionally. To find and disarmed such system you need long time and serious learning in cars and alarms and it is too much for most of them.
From all said above the conclusion is that with Valcor security system and professional installation the range of people who can really disarm the system vastly reduce and the chance to prevent the theft increases! You have not to belittle the subjective factor in the security namely parking at lively places, possibility to keep a watch on the car if a long stay is needed and so on. There is and another important aspect in the professional security but people make light of it and it is installation of immobilizer. The immobilizer is a device whose only purpose is to lock the engine al least on three places. Its big advantage to the alarm systems is the coupling missing and party-coloured wires which orientate the thief which are the wires locking the engine. At the immobilizers in the beginning of the installation each wire is black and marked with code. During the installation the marking code is removed and the wire is connected to the respective place. After the installation even the fitter can not say which cable for what is. The disarming of such a device is an extremely hard. For this purpose you have to find and dismantle its plate and to follow which paths to which black wire do to can recover the original scheme. Another big advantage especially of the contact less immobilizers, where the code feeds by a magnetic way, is that no traces of such installed device are to be seen. In this case the surprise for thief will be a very big and therefore the chance to refuse him of further action is so big too.

Bulgarian version44444 English version
© 2005, Lesi-2000 Co., Ltd.