New toy,
Pudu Food delivery Robot.
Doom runs fine on its internal Android RK3399 NanoPC-T4
Basically an over engineered Hoverboard with two RealSense D435 3D Cameras and Lidar
Longer video on YouTube:
youtu.be/cBzTto2OIDQ
New toy,
Pudu Food delivery Robot.
Doom runs fine on its internal Android RK3399 NanoPC-T4
Basically an over engineered Hoverboard with two RealSense D435 3D Cameras and Lidar
Longer video on YouTube:
youtu.be/cBzTto2OIDQ
Finally there is DOOM on a Cooking Pot...
Nice hacking challenge of a way over-engineered "Smart-device"!
Inside we can find 4 SoC's from 4 companies:
Heat control via STM32F031
Input button via PIC18F8..
Wifi via ESP32
Main FW Renesas 400Mhz ARM A9
Full video on YouTube: youtu.be/V5Jtc7wTbQ8
Aha! Mystery solved, the mentioned chip is actually the Display driver
The main SoC is the one next
The DA14535 with a 24 Pin case
renesas.com/en/products/...
This explains why the firmware is so similar to the DA14585^^ Not a clone
This opens up everything for a custom firmware
Ever seen this 32 Pin SoC ? Looks like a tree logo
and 257STWC0A e3
Crazy that the Smart BLE Ring with a Matrix Display is realπ€ͺ
But something is strange this claimed unknown PAR2860 SoC(If that is really inside the ring) looks very much like the firmware of the 7 Segment Ring (DA14585 SoC) but is still different.
maybe a cloned DA14585?
7 Segment Display Smart ring Hacking video:
youtu.be/xOw-6uMfOjc
Smart ring without display hack video:
youtu.be/w90RVspTkt8
What's better then a Smart Ring with 7 Seg Display?
A Smart Ring with matrix Display!
20β¬ version on Aliexpress(Affilia) s.click.aliexpress.com/e/_c4aEitU1
Main BLE SoC PXI PAR2860 with 512KB Flash and 32KB RAM
Still on order but excited to Hack it next!
Previous Hacks in next comment
Maybe this one?
youtu.be/MpSVU3t1J38
It got harder to get this exact SoC inside. There are by now 3 known different SoC with the same outer case/look
The Simple nRF52832 Spectrum Analyzer is now working on the Allmiibo LCD and OLED Variantπ₯³
Fully OTA Updateable from pixljs and back
Find the Source Code of the pixlAnalyzer now here:
github.com/atc1441/pixl...
And a YouTube Explanation Video here:
youtu.be/kgrsfGIeL9w
Just finished Hacking the Pill Camera that you'd swallow for an easy endoscopy
Ti CC1310 SoC Glitched and Dumped which allowed to Reverse Engineer its firmware and RF Protocol up to full Image receivingπ₯³
No security included but short range.
π½οΈπ¬ here: youtu.be/qEIW5gOLzIs
New idea - use the #Raspberrypi to directly drive parallel Eink displays. Pictured - Kindle 6" 1024x758 34pin panel driven by a RPIZ2W and (one of a kind) custom PCB.
youtube.com/shorts/LwGyG...
Benefits - the RPI (or any Linux SBC) can create/push the pixels faster than any ESP32. low cost SBC.
Lets take a look inside one of those Aliexpress "Smart" Car Keyfobs which you can retrofit your "Lame" Car Key with π
TLDR: It does not run Doom π
The internal RTL8762TD Hast sadly "only" 192KB of RAM
Find the Teardown video here:
youtu.be/oAmtu87EdYo
Lets take a look inside one of those tiny Pill Cameras that you swallow to check your innardsπ³
Video on YouTube:
youtu.be/pf_eOLRd6B4
Finally there is code execution on this Shi**y Realtek RTL8752H and RTL8762ESL ARM SoCπ₯³
Full custom firmware goes Brrrrr
These chinese vendors like Realtek Bluetrum and Jieli only care about copy protection and cribble down a perfectly fine ARM Core with their toolingπ
Teardown of the Tuya KWS-303WF Wifi Power Meter including cut-off Relay
Inside we can find:
- Tuya CBU Modul with Beken BK7231N ARM SoC 2MB Flash 256KB RAM
- Relay claimed 63A
- Power Meter
- LCD 60x160 Pixel
- External NTC Temp Sensor
aliexpress.com/item/1005008...
Teardown of an OBD Find My Adapter from Aliexpress
aliexpress.com/item/1005007...
As expected as simple as it could get,
3.3V Voltage Regulator with an currently unknown BLE SoC ESM412 2449XFD
No connection to CAN and OBD just for power
DOOM on a Vape via ScreenSharing and custom Firmware π
Source code on Github here:
github.com/atc1441/Vape...
And find a full video on Youtube with more details:
youtu.be/rVsvtEj9iqE
Teardown of the 2" LCD Screen Mirror device
~20β¬ From Aliexpress
s.click.aliexpress.com/e/_oCyfENx
Surprisingly packed
- Unknown DH390D HT2522A SoC likely HiChip HC15xx 4MB SPI Flash
- Battery Powered
- Speaker
- Realtek WiFi Chip
- Jieli BLE SoC
Similar to youtu.be/pFBn6lMJ7q8
Fun fact this 3β¬ USB-C to Headphone converter has more Flash and RAM then the first moon landing.
de.aliexpress.com/item/1005009...
The internal RISCV Bluetrum SoC AB136D got:
128 KB Flash
60 KB RAM
Perfect USB Rubber Ducky, easy to reflash without opening via the USB DP Pinπ€ͺ
Also got the OLED Amiibo Emulatorπ
Sometimes for < 8β¬ in the combo offers!
aliexpress.com/item/1005008...
They are just too cute and a nice Hackable gadget with everything included in a small case.
nRF52832 SoC
SPI Flash
LCD/OLED
NFC
Battery
Arduino able
x.com/atc1441/stat...
Teardown massacre of random 2β¬ Aliexpress Airpod clones π
80% Bluetrum (AB) and 20% Jieli
Feels like there is some security issue in the connection between the Case and Headphones.
The Phone is connected to the Headsets which again are connected to the Charging case and will forward Playing songs contacts etc. as well as allows to call and change songs.
Nice target
While not a full custom firmware you can find the current Bluetrum AB5682 SoC Hacking results here
github.com/atc1441/Blue...
This SoC Is used in the A9 Pro Airpod Clones and many more cheap BLE Gadgets.
Quite Beefy for its price:
RISCV
2MB Flash
162KB RAM
98KB ROM
Thats Code execution on the infamous
AB5682B BLE SoC used in the cheap headsets and other BLE hardwareπ₯³
This Bluetrum Chip series is ugly π
Debug via 1 Wire UART and a somewhat secured proto
This code now runs from RAM since we next need a loader to dump an write to Flash
Why does this aspire PIXO Vape got a hidden BLE Chip inside? π€
Internals:
Puya PY32F403 ARM SoC 256kb flash 64kb RAM
16MB External flash
LCD with Full touch
Unmentioned WS8000 BLE Module
Full hackability with an USB Flash drive update not including any CRC or sign checkingπ
One more Doom port^^
This time on an Epaper Translatorπ₯³
Running an XR872at SoC and an 296x152 BW E-Paper display with around 400ms of refresh time
Find a teardown done some time ago here:
x.com/atc1441/stat...
Full Youtube video here:
youtu.be/PvTJpbVPxUo
Lets take a closer look inside an 20β¬ Aliexpress Alarmo clone "Smart AI Kids clock" based on the XR872ats SoC
And of course port Doom to itπ
Full Teardown Youtube video:
youtu.be/QutpZBTJRDY
Github repo with full source code:
github.com/atc1441/XR87...
It had to be done π
DOOM on the Xiaomi Mi Band 8 Fitnessband
Running super smooth on the Amoled Display and the custom firmware with toom on just 2MB of Flash
Full video on Youtube:
youtu.be/iqyR_LNp9vc
DOOM on the ANKER Prime Charging stationπ
The internal SWM34S MCU is just way too nice!
8MB RAM + 16MB Flash directly mapped to memory goes brrrr
Video on Youtube: youtu.be/MdOU8SqCqeY
Quick teardown video of an Battery powered 4" LCD Screen Mirror device around 25β¬ from Aliexpress
TLDR: Main SoC is an HCSEMI C3100 which is very similar to the one used in the 20β¬ Handheld Console SF2000
Video Here:
youtu.be/pFBn6lMJ7q8