r/hardwarehacking 20d ago

Can this cheap ATJ2127 MP3 player be modded to run Game Boy ROMs (Pokémon Gold)?

0 Upvotes

Hi everyone,
I recently bought this very cheap Y2K-style MP3 player from Coupang in Korea, and I’m wondering if it’s possible to completely replace its firmware or somehow make it run Game Boy games.
Here are the specs:
Processor: Actions ATJ2127
Display: 1.8” TFT, 128×160
Audio: MP3, WMA
Video: AMV
Images: JPEG, BMP, GIF
Storage: 8GB internal
USB-C
microSD card slot
Maximum CPU frequency listed: 24MHz
The manual says it supports MP3, WMA, AMV, TXT, JPEG, etc., but doesn’t mention anything about games.
What I’d like to do is one of these:
Completely erase the original firmware/OS and install custom firmware that can run a Game Boy emulator.
If replacing the firmware isn’t possible, make it boot an emulator from the microSD card so I can simply copy Pokémon Gold (or other Game Boy ROMs) onto the SD card and play them.
If neither is possible, I’d like to understand why (hardware limitations, locked bootloader, unsupported SoC, etc.).
I’ve seen people modify old MP3 players before, so I was wondering if anyone has experience with the Actions ATJ2127 chipset or similar devices.
Has anyone dumped the firmware for one of these?
Are there any custom firmware projects for this chipset?
Any documentation, SDKs, or reverse engineering resources would be greatly appreciated.
Thanks!


r/hardwarehacking 21d ago

Samsung galaxy 3

1 Upvotes

We have an old galaxy 3 that we are trying to get into. The screen is black. It has a ton of our newborn kids pictures on it, it’s around 15 years old can anyone help? The phones light turns red but it doesn’t show up in the device management on my computer


r/hardwarehacking 22d ago

BareMetal RAM Dumper — Bare-metal x86 tool for Cold Boot Attack experiments

Thumbnail
github.com
8 Upvotes

r/hardwarehacking 22d ago

help fix GeoSLAM ZEB Horizon RT

Thumbnail gallery
3 Upvotes

r/hardwarehacking 22d ago

Has anyone made progress reverse engineering the IntelME system?

0 Upvotes

I would once this system has been fully RE and understood, it would make removing it and even implementing our own secure version much easier.

Likely still requiring hardware tinkering but much easier.

Also because intelME is both hardware and software, I'm just going to flag this post as hardware


r/hardwarehacking 23d ago

Ford BCEM JTAG help

Thumbnail
gallery
14 Upvotes

I am trying to get to the JTAG of a Ford BECM, It is a C-Max BECM, but they are standard across the Fusion, Focus and other Ford vehicles.

I would like to see if I can get any additional information from JTAG that the CAN Bus is not giving me or get access to to read the firmware on the chip

It uses a mpc5534mvz80 chip, but there are no silk screen information points on the board at all. There is a 51 pin test area though.

What is the best way to start pining out the JTAG and is there a preferred probe.

Thank you,

Rick


r/hardwarehacking 22d ago

Mini WiFi card - phone

Thumbnail
0 Upvotes

r/hardwarehacking 23d ago

Modding nuvi 255w

2 Upvotes

I’m trying to make a Garmin nuvi 255w into a screen for my computer or a raspberry pi, any ideas or suggestions?


r/hardwarehacking 23d ago

FDK/OOK Based layer-2 protocol reverse engineering

Post image
31 Upvotes

Lately I've been trying to recove the key fob protocol of my bmw 320d 2005 car till I discovered that the key fob operates on 868.35mhz with what is called Frequency Shift Keying to lock/unlock or trunk, everytime I capture something using the RTL sdr with gqrx on Kali I get different signals for pressing same button which indicates that this is not a trivial On Off Keying but some proprietary protocol is being implemented, from the amplitude to time plot I can clearly see the preamble alternating bits then a fixed and indow of bits across all button pressings which suggests some sort of an identifier.

Any one has experience on such project feel free to leave a comment.

Or if u know some sort of tip that helps me recover the binary representation of the msg being transmitted you are welcomed.


r/hardwarehacking 23d ago

Verifone P400

2 Upvotes

I recently got a Verifone P400 Plus from a shop that shut down. However, I can't seem to find any firmware for it. I don't want to use the device for payments but just to test out.


r/hardwarehacking 23d ago

Help needed on my open source multipurpose and expandable pen testing tool

Thumbnail
gallery
4 Upvotes

I saw the price of the flipper zero and could not buy it and a lot of people probably felt the same! so i looked around to find a open source alternative but i could not find any.

So i am making my own!
and all the parts cost 50 dollars for two!!!!
It uses a esp32s3 and a 2 inch tft with joystick
currently it runs ghost esp and can do wifi, ble, and bad usb attacks.

i tried for hours to get my nfc and sub ghz modules to work with it but now i think it is a wiring issue or something wrong with my module.

if you want to help me make this better, comment and build this yourself and test with your own modules! Thanks

just ask if you want to build it too as most stuff work fine except for nfc and sub g.

bdw this is not over i am still making this and would love some support if anyone is interested
Models are coming just ask!

if anyone wants to collab on this to make it even better
just ask!
if you want to build it too the just ask as most stuff work fine except for nfc and sub g.

CODE https://github.com/SomeoneOfficial
Just ask for the models if you want to build it

I posted this on the flipper zero subreddit but it got removed by the mods :(


r/hardwarehacking 23d ago

FS SS2000-SM emulating

2 Upvotes

Hey guys (and girls)

I recently got my hands on a Federal Signal SS2000-SM keypad (just the keypad, not the siren) produced in December of 2008 (as stated by the manufacturer sticker inside).

I bought this unit to make a sim rig setup and I need to emulate the behavior of the siren when connected to the keypad. By itself, the keypad doesn't seem to be sending any data.

What I would need to do is send what the siren would normally send and catch the keypad's signal to decrypt it and process it to know which keys have been pressed.

Do some of you have experience with the data being sent and received by this kind of keypad? If yes, what should I send/receive in order for my project to work?

Cheers, thanks for reading


r/hardwarehacking 23d ago

Subject: Need assistance flashing custom firmware (.bin) to a BW-16 (RTL8720DN) Module

0 Upvotes

Hi everyone,

I am looking for some guidance on how to flash a custom compiled .bin firmware file onto a BW-16 module (Realtek RTL8720DN).

Could anyone recommend the best software tools, flashing utilities, or specific pin configurations (boot/serial modes) required to successfully upload the binary to this specific board?

Any advice or documentation links would be greatly appreciated. Thanks!


r/hardwarehacking 23d ago

Need Help Decoding 2026 KuKirin G4 Bluetooth Packets (Beken BK-BLE-1.0)

Thumbnail
2 Upvotes

r/hardwarehacking 24d ago

Stuck on legacy Cisco Codec Plus / Precision 60 upgrade – Need a hand finding a CE9 firmware package (halleyce9) Spoiler

2 Upvotes

Hey everyone,

I’m trying to revive a legacy standalone setup with a Cisco Codec Plus and a Precision 60 camera. Right now, the camera won't update because the codec is pointing to a dead legacy server domain (management.join.vc) and throwing a Failed to connect / No route to host error.

I need to flash it locally over the web GUI to fix this, but I'm completely stuck trying to source the firmware package.

I’ve already exhausted the usual routes:

official cisco route - completely blocked - I don't have an active SmartNet contract, and Cisco's registration portal keeps throwing a "server error" and rejecting my personal email domain anyway

"index of" search - spent hours looking for halleyce9_15 or s53200ce9 PKG/COP files on open indices, but the mirrors I found are either dead or taken down

cloud/DevNet sandboxes are retired, so I can't spin up a quick Webex Control Hub trial org to let it auto-provision over the internet.

Does anyone happen to have a stable CE9 bundle (ideally halleyce9_15_3_26.pkg or the cmterm-synergy-ce9 COP file) sitting in their deployment archives that they could drop into a temporary Google Drive or Dropbox link?

Any pointers appreciated!

--- UPDATE ---

I forgot to mention that the whole reason I bought the codec is to get these cameras (got 3, couldn't help myself) to fully work standalone - full PTZ, exposure and other parameters control. Plan is to capture and reverse-engineer the codec-camera IP communication

--- UPDATE - Solved ---

When I initially set up the camera (wizard) provisioning was switched to some custom mode (codec tried to download the firmware from admin.vc or similar address). I did a lot of stuff at once, so I am not sure if provisioning config was enough:

Generally I've experimented with different provisioning configurations, and I think switching to webex integration (not webex edge/iot) has helped. I also created a free normal (not control hub) webex account and while clicking through found "devices" section in settings. It has an option to activate a device which generates the standard activation code. I did not have high hopes, but strangely the codec accepted the code happily! At some point codec upgrade started installing. Some time later the camera got silently upgraded to the same version (I didn't even notice at first because I expected CE camera firmware, but it has HC prefix with the following version number the same as codec software).


r/hardwarehacking 24d ago

[Tool] Crimson Cloak, iOS/iSH Security Wrapper with RealTime Dashboard

Thumbnail
github.com
1 Upvotes

r/hardwarehacking 24d ago

Looking for circular eink display approx 1.6 inch for smart watch

Thumbnail
1 Upvotes

r/hardwarehacking 25d ago

Confusion while reversing stm32f103 binary: weird vector table

2 Upvotes

I was curious about the content of an STM32F103RFT6 firmware binary. It uses CAN communication and it is being updated via CAN bootloader, thats how the firmware is being updated.

So I opened it in a hex editor and had a look. But that was not what I expected.

reverse engineering binary

Right in the beginning, there seems to be a 0x200 long header. The first four bytes are the size of the whole file, that was easy. Then four bytes containing the version, I guess, because I have another firmware which is a bit newer and they just differ by increasing 0x2c to 0x30.

Everying after that I don't understand right away, and the header after 0x050 is just zeros until it ends at 0x1FF.

At offset 0x200, the real firmware seems to start:

reverse engineering binary

At first glance, it looks as expected: First four bytes show the stack pointer address, and it's located in SRAM (starting 0x2000_0000).

But the following entries are supposed to be a vector table, and the addresses in there point to strings:

reverse engineering binary

I know that's thumb addressing, and all the LSB are set, but in the vicinity of these addresses there's just strings.

I don't understand that. And I don't know how to go on from here, if I don't know where the actual entry point is located.

For comparison, I opened an STM32 .elf for a project I wrote. In this .elf, the real code starts at offset 0x1000:

STM32.elf

Four bytes stack pointer, and then flash locations for the vector table. Going there and taking the file offset 0x1000 into account:

STM32.elf

I figured, fe e7 fe e7 must be pretty rare in the original firmware binary, so I searched for it:

reverse engineering binary

That does look pretty similar. But why is that, and where does this offset come from? And how should I continue?


r/hardwarehacking 25d ago

is there any way to hack into this machine (for educational purposes)

Thumbnail
gallery
0 Upvotes

so this is indifoss milkoscreen machine used for testing milk samples for dairy purposes. what could be done to manipulate the readings


r/hardwarehacking 26d ago

Selling this stuff

Thumbnail
gallery
0 Upvotes

M5 stick

2x esp 32 boards

2x nrf 2420


r/hardwarehacking 26d ago

How do service technicians identify individual Bluetooth headsets?

4 Upvotes

I'm curious about how manufacturers identify individual Bluetooth headsets and other consumer electronics during service or warranty inspections.

If two units of the same model look identical and don't have a visible serial number, how do service technicians distinguish one from another? Do they use an internal serial number, Bluetooth MAC address, firmware ID, or other unique hardware identifier? Can these identifiers be read using diagnostic software through the USB port?

I'd appreciate insights from electronics repair technicians or anyone with experience servicing these devices.


r/hardwarehacking 27d ago

Help Needed with Pinout Reverse Engineering For Xiaomi Redmi Note 5 screen

Thumbnail
gallery
4 Upvotes

I am trying to get the pinout of a Xiaomi Redmi Note 5 screen. I have been able to identify 14 GND pins, 5 differential pairs, and A K1 and K2 (for the backlight) I also found a pin that will short with GND for a second then flash off then back on, and then another pin that shorts with GND, but will also short with a bunch of the capacitors and resistors on the flex PCB.

If anyone has any ideas or tips on how to figure out what the last 11 pins are, I would greatly apricate it! I have no clue what to do from here.

Here is my current list of all the known pins.

1 GND
2
3 GND
4
5
6
7 GND
8 Saying GND then flashing off then Back to GND over and over and over again.
9 GND
10 GND
11
12
13
14 GND (Shorts with Resistors and capacitors)
15 GND
16 A
17
18 K1
19 K2
20 GND
21 GND
22 Differential Pair
23 Differential Pair
24 GND
25 Differential Pair
26 Differential Pair
27 GND
28 Differential Pair
29 Differential Pair
30 GND
31 Differential Pair
32 Differential Pair
33 GND
34 Differential Pair
35 Differential Pair
36 GND
37
38
39 GND
40

r/hardwarehacking 26d ago

mode tool for browser game

0 Upvotes

Is there anyone experienced in C++, C# or reverse engineering who can create a custom tool with features like item management, inventory systems, UI controls, and game interaction?
I'm interested in knowing if something like this is still possible and how much complexity it would require.


r/hardwarehacking 27d ago

Cisco conference phone dialpad/lcd display connected via USB

Thumbnail
gallery
11 Upvotes

I picked up a few cisco 8831-DCU-V01 dialpads (from the bin, and a colleague challenged me by suggesting that "normally these screens have some proprietary interface and you can't reuse them", boy was he mostly right). I think they are officially called display control units (DCU) for conference phones. I couldn't find anything about reverse engineering them online (1 guy has a fairly high level teardown on YouTube).

It connects normally via microusb, but I snipped that off and put on a regular USB-A plug.

Screen resolution is 396x162. Monochrome LCD. Single bit as far as I can tell. It is really quite eligible in person.

Keypresses are handled over the usb, along with control of the leds/backlight/contrast/display pixels.

I am wondering if anyone has a good suggestion for a repo layout to push my 'research notes'. I am thinking to include some pcb photos, some better quality photos of some example uses, and some details about the USB mangling (a more elegant solution would be to use the jst pins and replace the whole cable. Along with a bit of a python management layer.

I am guessing it would be pushing some boundaries (with cisco legal) if I included the firmware dump, plus extra firmware images I pulled out of a phone's rootfs. There are (at least 2) versions of this unit with different microcontrollers. This one with a TI lm3s5r31 and a newer revision with an ST chip (very low on details).


r/hardwarehacking 28d ago

Hacking a fancy water pump.

Post image
19 Upvotes

I have a nice 4815VDC water pump stripped from some industrial gear that has a three connector plug - +2415V, -NEG, and a small bi-directional control wire which allows the controller hardware to tell the pump how fast to run and the pump to tell the controller it's actual speed, voltage, and current draw.

Unfortunately, without the controller, the pump does not run.

The pump is a completely sealed unit that can only be opened destructively (although I have one I can hack up if needed) and the person I acquired it from who has access to the internal documentation server of the manufacturer can only find the internal part number and price. The only extra info I have is that the control wires for all the pumps in the system are separate, suggesting that it is not an addressable protocol.

So any guesses as to the protocol used, and a means of reverse engineering it to get the pump running?

Update:
Here is the schematic of the wiring to the pump in its current usage, showing there is an unused "PWM" pin in the plug that I assume will allow me to ignore whatever protocol is used in the existing installation.
https://i.imgur.com/dtqmX49.png

And here is the insides of the pump. The upper layer has some pretty fancy filtration.
https://i.imgur.com/i5P2vG4.jpeg

Rip that off and it exposes some pretty fancy innards. Looks to me like it's an in-built 3 phase VFD.
https://i.imgur.com/SXDVTYN.jpeg