ATC1441

@atc1441.bsky.social

Hack the planet! my biggest passion is to run a custom firmware on as many devices as possible

Fun fact, a web upload trigger gives you root read access on the Tolino Vision Color, but im not even sure if they are in general just more open for tinkering. 7" Full Color Linux eink reader for 200€ is anyway more on the expensive side

BildBildBild

Finally there is DOOM on a Cooking Pot... Nice hacking challenge of a way over-engineered "Smart-device"! Inside we can find 4 SoC's from 4 companies: Heat control via STM32F031 Input button via PIC18F8.. Wifi via ESP32 Main FW Renesas 400Mhz ARM A9 Full video on YouTube: youtu.be/V5Jtc7wTbQ8

Crazy that the Smart BLE Ring with a Matrix Display is real🤪 But something is strange this claimed unknown PAR2860 SoC(If that is really inside the ring) looks very much like the firmware of the 7 Segment Ring (DA14585 SoC) but is still different. maybe a cloned DA14585?

BildBildBild

Just finished Hacking the Pill Camera that you'd swallow for an easy endoscopy Ti CC1310 SoC Glitched and Dumped which allowed to Reverse Engineer its firmware and RF Protocol up to full Image receiving🥳 No security included but short range. 📽️🎬 here: youtu.be/qEIW5gOLzIs

BildBild

Lets take a look inside one of those Aliexpress "Smart" Car Keyfobs which you can retrofit your "Lame" Car Key with 😅 TLDR: It does not run Doom 😞 The internal RTL8762TD Hast sadly "only" 192KB of RAM Find the Teardown video here: youtu.be/oAmtu87EdYo

Bild

Finally there is code execution on this Shi**y Realtek RTL8752H and RTL8762ESL ARM SoC🥳 Full custom firmware goes Brrrrr These chinese vendors like Realtek Bluetrum and Jieli only care about copy protection and cribble down a perfectly fine ARM Core with their tooling🙄

Thats Code execution on the infamous AB5682B BLE SoC used in the cheap headsets and other BLE hardware🥳 This Bluetrum Chip series is ugly 😅 Debug via 1 Wire UART and a somewhat secured proto This code now runs from RAM since we next need a loader to dump an write to Flash