2026-06-04 –, Track 1
Bluetooth Low Energy is absolutely everywhere - in billions of smart devices around us. Most tools to audit it require a laptop, a bunch of dongles, and a pile of scripts often difficult to set up and troubleshoot. But the devices you're testing are mobile. They're in elevators, hospital wards, factory floors, and hotel rooms. Your tool should be too.
BLESPlo.it is built on a simple idea: mobile technology deserves a mobile security tool - one that works for everyone, not just in the lab, but in the field.
At its core, BLESPlo.it is a mobile app - run it standalone and you already have a capable BLE scanner, fingerprinter, and a remote control for the wireless world around you, right in your pocket. Pair it with a small ESP32 companion device (yes, it works with OrangeCon badge!) and enjoy new options impossible with just the phone: low level scanning, cloning/simulating any BLE device with just a few taps, probing pairing modes, and more! You can finally try those latest attacks you heard about but never had the possibility to setup. Now you can simulate any target in seconds and focus on the juicy details instead of fighting your toolchain. And thanks to the dynamic scripting engine you can easily write a custom attack logic on the fly. Share your scripts, device profiles, fingerprint patterns and protocol implementations, let everyone learn from it and secure their devices.
Still not convinced? Come see AI-boosted reversing shenanigans and live stunt hacking of dildos, shooting robots and even a Ferrari car!
Seasoned trainer, speaker and IT security consultant with over two decades of expertise.
Currently focuses on security research of new technologies (especially Bluetooth Low Energy and NFC/RFID) and delivering trainings on these topics.
Loves sharing his knowledge via trainings, workshops, talks and open source hackme's (https://www.smartlockpicking.com/) – at OrangeCon, BlackHat, HackInTheBox, Hardwear.io, HackInParis, Deepsec, Appsec EU, BruCon, Confidence, and many others, including private on-demand sessions.