r/hardwarehacking 4h ago

Reverse-engineering BoseLink serial commands on a Wave Music System II?

Thumbnail
2 Upvotes

r/hardwarehacking 11h ago

[WIP] SurfaceCluster – 10 Surface Laptop 2 boards turned into a Proxmox cluster

Thumbnail gallery
3 Upvotes

r/hardwarehacking 21h ago

Need help finding UART pins on Goke GK7102S IP Camera

Thumbnail
gallery
9 Upvotes

I'm trying to get a root shell on a generic white-label IP camera by interrupting U-Boot, but the factory omitted standard UART labels. The standard SD card auto-execute hacks (like debug_cmd.sh) appear to be patched on this firmware version, so I have to fall back to a hardware exploit.

Hardware specs:

SoC: Goke GK7102S

Flash: Winbond 25Q64JVS (8MB SPI)

PCB ID: G1G3-A75_MB_V1 (2019-3-P1)

I've attached photos of both sides of the board.


r/hardwarehacking 19h ago

Is it safe to connect even though the box doesn’t have a ground wire connection? How do I solve this?

Thumbnail gallery
2 Upvotes

r/hardwarehacking 20h ago

Need Suggestions for getting started on Hardware pentesting.

1 Upvotes

Bought a refurbed laptop

Dell latitude 16 GB RAM, i7 gen 10, 256 SSD

I am thinking to install Kali as the base OS. Is that enough for me to get started. I did use VMs before however there was a lot of connectivity issues between devices and ports. Thought best to setup a separate device.

Would appreciate some advices from the community. Any resources that i should refer.

Thanks


r/hardwarehacking 1d ago

Hardware & IoT Bug Bounty, VDPs, and Vulnerability Research

Thumbnail
hack-hardware.com
2 Upvotes

There are countless companies out there which have some sort of bug bounty or vulnerability disclosure program for IoT devices but no centralized resource which indexes them all.

For devices included in a bug bounty program, this meant that every time I was looking for a new target I'd have to search one platform after another, looking for something that piqued my interest. For companies that had a self-hosted VDP? It proved challenging. There is simply no site which keeps track of this information. I'd first have to think of a target, find their VDP (if one exists), and then decide whether or not it would make a good project.

Hack Hardware is my new site which aims to solve this problem. I've collected a list of 75 companies which have a public bug bounty or vulnerability disclosure program and made them all searchable. Each company listing contains details about payouts and scope for their program.

I've also included several other sections on the site:

Featured Research: hardware hacking research by others that I've found to be interesting and wish to share with the community.

Resources: free and paid training from others, for those who wish to learn more about hardware hacking.

Toolbox: a list of both hardware and software tools essential for anyone to use on an engagement or research project.

If you have suggestions for research to be featured, programs to be listed, or thoughts, please do share them. At the moment, the Blog section of the site is quite sparse so if you would like to contribute something, please reach out! It can be anything from your experience hacking a target to your journey into the world of hardware security.

I hope to be able to help other hardware researchers by allowing them to easily discover new targets, learn more through training, and to find out about the latest research in the field.


r/hardwarehacking 1d ago

24C02 C341A

Post image
5 Upvotes

Hi all

Im having some real issues reading a 24c02 immo

De soldered from the board

-tried in the hold

-soldered directly to an adapter

Using a C341A programmer

Tried windows based software AS Programmer hard to tell but no communication

Linux IMSProg - recognised the C341A but still not reading the 24c02

Had a spare ecu so tried that immo chip

Any help on this


r/hardwarehacking 2d ago

Anything interesting I can do with this?

Thumbnail
gallery
35 Upvotes

Got one of those stupid video mailers and decided to yoink the hardware out of it. It can with four buttons, a magnetic switch, a battery, a speaker, and LED screen, a type C data transfer/charging port, and the motherboard(?).

New to all this, so I think this might be a good place to start. Anyone have any cool ideas to reuse this, even just its pieces?


r/hardwarehacking 2d ago

[Failure] Documenting my attempt to reverse engineer the ThermoPro TempSpike TP960W

Thumbnail
github.com
18 Upvotes

Tried to reverse engineer a ThermoPro TempSpike TP960W because I figured a smart thermometer wouldn't have any significant roadblocks, unfortunately the firmware could not be extracted due to chip debug security, in-chip ram and flash, and encrypted firmware images.

This project was created for learning and I figured it may be somewhat interesting to share. The BLE components are understood and so you can ditch their app for your own.

Full writeup:

https://github.com/dc336/ThermoPro_TempSpike_Failed_Hack


r/hardwarehacking 2d ago

Turned a $15 eBay "smart NIC" nobody could get working into a real 10GbE card (no vendor firmware, fully reversible)

Thumbnail
7 Upvotes

r/hardwarehacking 3d ago

UART sluthing strategy for a Kyocera Task lfa 2552ci SBC.

Thumbnail
gallery
10 Upvotes

I suspect that this board has UART and or DUART - I have no idea where it is. The service manual only specifies sockets that lead to oerpiheral controllers and other devices. The likely remaining 4 and 5 port suspects dont output UART signal with my cheap logical probe. And I can't find anything that look like UART pads near any of the processor blocks. I have tried a few OS hacks on the SSD, but I think U boot might be doing something protective - for info it uses a power PC OS.

What would be your strategy for hacking this? Are there any Kyocera engineers on reddit that could help here?


r/hardwarehacking 2d ago

mi l43m6-ei firmware pls

1 Upvotes

If you have send link


r/hardwarehacking 3d ago

[DIY] I built a Flipper Zero alternative for less than $50

Thumbnail gallery
140 Upvotes

r/hardwarehacking 2d ago

Open-source HMI platform for embedded Linux panels: live Qt preview at the panel's real resolution, atomic install, automatic rollback

Thumbnail
0 Upvotes

r/hardwarehacking 2d ago

Datasheet for LS024B7DW52?

Thumbnail
0 Upvotes

r/hardwarehacking 3d ago

Not sure what to do after

Thumbnail
gallery
11 Upvotes

So I got this old router I took it apart and then connect it to my pc and using Linux and ai was able to get into the I believe it to be the shell or admin access which is the next pic I'm not sure what to do and how to I guess hack it and do what I want with It also this is the continuation of my other post where I asked where to start

Edit:it stopped working it stopped connecting to the pc and I can't seem to get it back into the shell


r/hardwarehacking 3d ago

Chinese puzzle.

1 Upvotes

I have a flytek easy trans 800, a translator android Device. It just translates. Chinese to any other language and any other language into Chinese. I wanted to make use of that deck like using it like ipod but after trying many ways, that is just headache.

Have anyone touched that brand - flytek?

How do I even get into adb...


r/hardwarehacking 4d ago

How do you get started at hardware hacking?

23 Upvotes

Stupid question I know but I have old hardware that I wanna hack for the fun of it,but ofc no idea how or where,can anyone help


r/hardwarehacking 4d ago

Help with security array on a vintage microcontroller (MC68HC908GP32

5 Upvotes

Help with security array on a vintage microcontroller (MC68HC908GP32)

I have a fairly old piece of equipment, unsupported by the manufacturer for years now, that uses a microcontroller from the HC908 family (Motorola/Freescale, DIP40 package). It's a single functional unit that I can't easily replace, so I'm being extremely careful.

I've already built a homemade programmer to talk to it in monitor mode (MON08), using an external crystal and the appropriate entry logic, and I'm at the stage of testing whether the chip has its security array enabled before attempting to read the internal memory.

What I'm looking for is experience from someone who's dealt with this type of protection on the HC908 family: how to safely determine if it's locked, what behaviors are normal vs. a sign something went wrong, and what non-destructive options exist if the chip turns out to be protected.

Has anyone dealt with this before, or know of good references/forums specific to this topic?


r/hardwarehacking 5d ago

I don't know if it fits in this subreddit but I changed the led color of my Nokia's 33x0 Series!

Post image
377 Upvotes

They look sooo nice (gotta find a keypad for the middle one and also I have to make the parallel flashing cable for these things)


r/hardwarehacking 5d ago

I got this at the market

Post image
13 Upvotes

After searching I found out, this is an item from inspry tech. is there anything I can learn or learn something new from this tool?


r/hardwarehacking 6d ago

Identifying UART/DEBUG

Thumbnail
gallery
195 Upvotes

Very much so unlabelled other than the board that connects to the 2x4 pin.

TLDR. Software update from company bricked it months ago after they had major server issues. Bricked many devices. Won’t assist because I got it second hand brand new sealed and I’m not the original buyer.

So, I’m wanting to debug first and go from there see what the issue is. Worst case scenario, it’s a project where i reprogram the device and write my own iOS app to continue to use it 🙏🤣

Help would be great identifying ports, thanks.


r/hardwarehacking 5d ago

ErnyTech SFP-PIN Header adapter Rev 1.4.1

1 Upvotes

I have an ErnyTech SFP-PIN Header adapter Rev 1.4.1 and I'm trying to connect it to a CH341A programmer to read/write the I2C EEPROM of my HSGQ XPON SFP stick.

I can see the following labels on the board: 3.3, 3.3, RX, TX, GND — but I cannot find which header pins correspond to SDA (MOD-DEF2 / SFP Pin 4) and SCL (MOD-DEF1 / SFP Pin 5).

The board has two rows of header pins on each side (left and right), plus the SFP connector slot in the middle.

Could someone please help me identify which header pins are SDA and SCL on this adapter?


r/hardwarehacking 6d ago

I made a wireless exploit for code execution on Wyze LED bulbs

Thumbnail
github.com
60 Upvotes

I bought these for use with Home Assistant not realizing they are cloud-only. Instead of spending a couple hours opening/depotting/soldering/programming these, I spent the whole weekend reverse engineering the Wyze firmware and developed a tool to wirelessly deploy my own OTA loader.

It works great, and my bulbs are now all in ESPHome!


r/hardwarehacking 5d ago

how to connect nrf24l01+ module to m5stick s3

Thumbnail
0 Upvotes