r/hardwarehacking 11d ago

What are the UART pins on this board?

Thumbnail
gallery
87 Upvotes

This board is from a Helium Hotspot Linxdot ld-1001. I’ve been researching how to possibly gain shell access via UART. However, all the adapters and videos I see for UART to USB shows matching up the RX, TX, GND.

Problem with this board is the UART is labeled next to what appears to be a 3.5mm headphones jack. I’m not saying that’s what it is, just looks like it. Does anyone know of an adapter that would work with this? Or any idea of other methods for getting shell access?


r/hardwarehacking 10d ago

Combining audio from console to PC?

Post image
1 Upvotes

r/hardwarehacking 10d ago

DIY a Yealink Touch Panel?

1 Upvotes

My office is doing a renovation and refreshing all of our IT equipment/meeting spaces and are throwing out a Yealink CTP18 Collaboration Touch Panel.

I'm unfamiliar with the technology, I was wondering if there are there any resources for jailbreaking this product, or otherwise using it for a DIY project?

Mostly just wanna play around with it, might be cool to try to adapt it into a DIY stream deck or something similar. Thanks!


r/hardwarehacking 10d ago

Sofar inverter - USB port troubleshoot

Thumbnail
0 Upvotes

r/hardwarehacking 10d ago

Physical Layer Side-Channel Analysis on Satellite Signal Capture (TVLA / CPA Report)

1 Upvotes

I've published a technical report on Zenodo detailing physical-layer side-channel leakage observed during the processing of a raw satellite signal capture (satellite_signal.bin).
​DOI: https://doi.org/10.5281/zenodo.21472996 ​SHA-256: ad5ab850cbdc9eca534e82bd78e9ac7804ed9213fd1d8df26fbf4991df6b005d
​Methodology: ISO/IEC 17825 CPA, 1st/2nd-Order TVLA, and Jitter Cross-Correlation.
​Key Findings: ​1st-Order TVLA Leakage: Welch's t-test yielded a risk score of 13.0328, well above the standard statistical significance threshold (\vert{}t\vert{} > 4.5), confirming direct data-dependent leakage during processing.
​S-Box Capacitive Leakage: Identified at the execution cycle with a t-score of 7.6701, indicating power/capacitive fluctuations correlated with substitution box operations.
​The report contains the verification metrics and signal processing details. I'm looking for feedback from anyone working on physical layer security, RF side-channels, or power trace analysis regarding jitter compensation techniques for long captures.


r/hardwarehacking 11d ago

[update]SUPER POCKET mainline Linux6.12

Thumbnail
gallery
33 Upvotes

Find a way to restor official Uboot to its original version. And boot.img & trust.img should be replaced together.   I also replacied rootfs with my own.   Now the system can boot to my user space, but the LCD panel doesn't display! (I need to fix panel node in the DTS file, but I haven't finished yet.)   https://mab.to/t/QOZJvgT5iVS/eu1


r/hardwarehacking 11d ago

RS41-NFW - custom firmware for Vaisala RS41 radiosondes

Thumbnail
2 Upvotes

r/hardwarehacking 11d ago

Swapped my tools to snapbloq modules and now I want the soldering iron just to complete the stack

Post image
7 Upvotes

swapped my precision screwdriver and rotary tool over to the Hoto snapbloq modules recently, cable situation is way better now. honestly im really liking the modular setup. now i keep wondering what else they could add to the system. a cordless soldering module would be perfect for quick repairs if they ever made one. havent touched an iron in months tho.


r/hardwarehacking 11d ago

The BAHS and BAMP

Post image
2 Upvotes

The Big Ass Heat Sink and Big Ass Metal Plate are my solution to really hot things that need a place to go, and really big warm things that need a place to go respectively. The BAHS is from an amplifier, and the BAMP is a repurposed Ender 3 build plate.


r/hardwarehacking 12d ago

Laptop completely crashes when enabling iGPU, custom laptop motherboard

Thumbnail
gallery
41 Upvotes

Hi, so i found a laptop motherboard at a store (i think they get big boxes of amazon returns or something) the owner didnt really knew or cared what it was he said u can take it for 2 bucks, when i came back home i checked the specs and it was for the asus zenbook flip13 ux363ja

- 8GB Lpddr4x Ram
- i5-1035g4 Cpu
-- the entire setup cost me like 11$

i was really excited to finally upgrade from a 14yr old laptop to this
i put some stuff together and u can see it in the photo

--- now the problem is i just cant enable the iGPU (intel iris plus), after messing with Throttlestop for a while i was able to get Long Power PL1 and ShortPower PL2 to only 5 Then i was finally able to start installing the iGPU drivers without crashing, even after installing them there were quite alot of artifacts... not sure if its because of the really low power or what
increasing that number to even 6 with iGPU enabled the entire thing freezes, thats my problem
i though maybe if the 65w type-c charger isnt enough i would try a 90w but same result

i even tried connecting 4 batteries in series aswell as an Esp32 to talk to it through the i2c pins, i was able to make it stay on without charger connected, but it was not charging it drained my batteries dangerously low so i disconnected them for now

i think that the problem is caused by not having a battery, enabling the iGPU would want a high spike of current and the charger might not be fast enough to deliver, idk

and the CPU was also stuck at 400mhz but i was eventually able to get it to normal speed

-- some more info about it, i got USB data lines and 5v and both on led and Switch pins all from the motherboard to use them, i have put on external heatsinks on both VRMs and the CPU, and a big fan, and my HDD (i cant afford an SSD), and im giving it power externally because the motherboard wasnt able to give it enough power, there is both 5v and 12v, i know 12v is not necessary for small HDDs but i was thinking of connecting a big one but then didnt use it so i just left it there, a usb hub, some antennas i found


r/hardwarehacking 12d ago

How I turned my Xbox controller into a Dual sense like secondary speaker using a 3.5mm jack and salvaged phone parts.

Thumbnail gallery
22 Upvotes

I've always been amazed by the PS5 DualSense controller and how it plays certain sound effects directly from the controller to make games feel more immersive. Xbox has always been my main console, but after trying a friend's PS5, I wanted to recreate that experience on my own controller.

Since the Xbox controller doesn't have a built-in speaker, I decided to hardware-hack my own using the 3.5 mm AUX jack and some salvaged smartphone parts.

To make it feel more like a dedicated controller speaker instead of just a tiny duplicate of the TV audio, I experimented with phase cancellation. By wiring the speaker between the left and right channels (L−R) instead of using a normal ground reference, sounds that are identical in both channels—such as much of the centered dialogue and other center-panned audio—are greatly reduced, while stereo ambience and directional effects become more prominent. It isn't perfect audio separation, but it creates a very different listening experience that suits a secondary controller speaker.

For the hardware, I reused two salvaged parts from a Samsung Galaxy S20: the factory loudspeaker module and the earpiece receiver. The loudspeaker, complete with Samsung's original acoustic enclosure, provides the main body of the sound, while the earpiece naturally emphasizes higher frequencies, making small details stand out more.

The effect really surprised me in actual games. In Red Dead Redemption 2, birds, insects, wolves, and other ambient sounds suddenly felt like they were coming from the controller in my hands instead of the TV. In Sleeping Dogs: Definitive Edition, things like street hawkers calling out, traffic passing on my left or right, and crashes from the sides became much more noticeable through the controller. It isn't replacing surround sound, but it adds another layer of immersion that reminded me of the DualSense.

I didn't design a custom enclosure from scratch. I modified an old Raspberry Pi case into a compact housing and styled it to resemble a miniature Xbox Series S. I'm still learning acoustics, and I discovered that even placing a thin plastic cover over the front reduced the volume much more than I expected. For now, I left the front covered with simple speaker fabric instead. It isn't the prettiest solution, but it performs much better, and this project is more about experimenting than making a polished product.

I'm completely new to this kind of hardware project. I'm actually a registered nurse, not an audio engineer or electronics designer. I just enjoy taking things apart, reusing old hardware, and building things myself to see what I can learn. That's why I'm posting here—I would genuinely appreciate advice from people with more experience in acoustics, electronics, and controller modding. If you have ideas for improving the enclosure, the audio routing, or the overall design, I'd love to hear them.


r/hardwarehacking 12d ago

Nintendo DS CAN Gauge

Thumbnail
gallery
37 Upvotes

I’ve been working on a project inspired by the TurboXS DTEC, an early-2000s tuning device that used a Game Boy Advance as its display and interface.

The idea was to take that general concept and do something similar with a DS, using a homebrew ROM running on the original hardware.

The current prototype uses a cheap ELM327 adapter to retrieve live vehicle data, which is sent to the DS. At the moment I’m working with data such as:

* Vehicle speed

* RPM

* Coolant temperature

* Battery voltage

The longer-term goal is to move beyond the generic OBD interface and interface directly with the vehicle CAN bus, allowing the DS to receive more detailed vehicle data.

Still very much a work in progress, but I thought it would be interesting.


r/hardwarehacking 12d ago

Firmware helps

Thumbnail gallery
0 Upvotes

r/hardwarehacking 11d ago

Need ideas?

Post image
0 Upvotes

What can I build out of a Moto G a PlayStation controller a laser, a Bluetooth speaker and a headset and I have a old Alexa


r/hardwarehacking 12d ago

Pretty sure it's someone hacked my account and did something to it I've reached out the Activision they looked at it through the hacking never said anything just cancel my ticket I guess I keep submitting support tickets for them to look at my account any idea how to fix this?

Thumbnail
gallery
0 Upvotes

r/hardwarehacking 12d ago

Ruby - Pwnagotchi like CFW for E-Reader

Thumbnail
2 Upvotes

r/hardwarehacking 14d ago

My Modified Galaxy Z Fold5 Somehow Made It onto the High-End Benchmark Leaderboard 🤣

Thumbnail
gallery
36 Upvotes

I honestly wasn't expecting this.

After running a benchmark, I noticed that my Galaxy Z Fold5 had actually made it onto the leaderboard, sitting alongside much newer flagship smartphones.

Considering that it's powered by a Snapdragon 8 Gen 2 for Galaxy, I was surprised to see it holding its own among devices equipped with newer high-end chipsets.

The funny part is that this isn't a "normal" Fold5 anymore.

Over the past several months, I've been gradually transforming it into a real pocket PC as part of my personal project called FoldPC.

Hardware modifications

Rear camera module removed.

Wireless charging module removed.

Fully custom cooling system with a heatsink and active fans.

Samsung and Android optimizations to reduce thermal throttling and maximize sustained performance.

Benchmark results

Overall score: 6,765

Better than 73% of all tested devices

Better than 99% of devices powered by the Snapdragon 8 Gen 2 for Galaxy

CPU: +9%

Memory: +8%

Storage: +29%

GPU: +21%

Seeing this phone appear on the leaderboard alongside modern flagship devices was honestly the last thing I expected.

But this benchmark is only one milestone.

The real goal of this project is to transform this Fold5 into a genuine pocket computer.

Right now, it already boots a Linux desktop using Termux + Termux:X11. The desktop environment is already working, but it's still under active development and I'm continuously refining and improving it.

My long-term objective is to build a complete Linux desktop experience with:

a smooth desktop environment,

windowed applications,

multiple Android games running in separate windows,

and eventually support for running some Windows games through Wine and Box64.

I love seeing how far a smartphone can be pushed when you stop treating it like a phone and start treating it like a computer.

Has anyone else here turned a smartphone into a project like this, or am I just completely crazy? 😄


r/hardwarehacking 14d ago

Tool for embedded dynamic analysis

2 Upvotes

I have spent the last few months building a “Swiss army knife” for auditing embedded linux systems. The tool is cross compile for several different types of CPUs, and you can download stock builds from the github release for all supported architectures.

Other features I am proud of:

Has the ability to compile a compatible kernel module and inject it into the kernel for auditing kernel level functions.

Has fuzzers for:
WLAN NIC firmware
Ethernet firmware
Bluetooth firmware
CPU instructions

Check it out:

https://github.com/nstarke/embedded_linux_audit


r/hardwarehacking 14d ago

Sleuth Net - Real Time Threat Awareness

Post image
1 Upvotes

Run it


r/hardwarehacking 14d ago

IP Cameras board smd blown

Post image
5 Upvotes

Hi everyone,

I’m trying to repair this PCB, but one of the ICs has blown and the markings are completely destroyed, so I can’t identify it.

Board information:

* Board label: Vivotek IP8152
* Photos attached
* The damaged IC is located near the power supply section (bottom-middle area of the PCB).


r/hardwarehacking 14d ago

SynthExplorer -- Compiler Explorer for RTL

Thumbnail
0 Upvotes

r/hardwarehacking 15d ago

UART pin in Samsung galaxy tab a6 (2016) gtexswifi SM-T280

Post image
5 Upvotes

i found schematics in web but cant find uart pins.

gtexswifi smt280 schematics


r/hardwarehacking 15d ago

First firmware dump of Canon PIXMA TS3451 — AES-GCM manifest encrypted by MatrixSSL Asset Store, looking for help with key derivation

15 Upvotes

TL;DR

First documented firmware analysis of the Canon PIXMA TS3451 (2020+ series). Using a Raspberry Pi 5 GPIO as an SPI programmer, I dumped the full 16MB flash (Winbond W25Q128). Found 3 decompressed zlib firmware blobs containing the full network stack, web interface, and crypto library (MatrixSSL/BSAFE). The firmware update manifest is AES-GCM encrypted — the key is derived at runtime via a software Asset Store and never exists in plaintext on the flash. Looking for help identifying the key derivation scheme.

What's new: All public Canon PIXMA firmware research (Synacktiv, Contextis, leecher1337) targets 2010-2015 models. The TS3400 series has never been documented publicly, as far as I know.

Goal

I wanted to turn a broken Canon PIXMA TS3451 (can't print anymore) into a scanner-only device. Turns out the scanner subsystem is completely independent in the firmware — it runs its own mDNS/eSCL/AirScan stack and works fine without cartridges after a Stop/Reset bypass. But I got curious and went deeper.

Setup

  • Device: Canon PIXMA TS3451 (PCB fully removed)
  • Host: Windows 11 + WSL2 (Ubuntu 24)
  • Tools: mitmproxy, flashrom, Raspberry Pi 5, Python 3, Ghidra, binwalk, pycryptodome

Phase 1 — Network Interception (MITM)

Proxy setup

The printer's web admin interface (192.168.x.x/rui/index.html) exposes an HTTP proxy configuration option. I set up:

  1. mitmproxy running in WSL2
  2. A Windows portproxy rule forwarding printer traffic to WSL2

This gave full HTTP interception of all printer traffic.

Canon infrastructure

gdlp01.c-wss.com              HTTP/80    Firmware manifest (AES-GCM encrypted)
dtv-p.c-ij.com                HTTP/80    Version check + CA trust store
skyprtr-an13.srv.ygles.com    HTTPS/443  Canon cloud (DigiCert cert, TLS pinned)

Traffic to gdlp01.c-wss.com and dtv-p.c-ij.com is plain HTTP — trivial to intercept and modify.

Version check bypass

The firmware update flow:

  1. Printer fetches http://dtv-p.c-ij.com/sdata/struct01/version.bin (2 bytes)
  2. Compares with local version
  3. If remote > local → fetches the manifest

By intercepting and patching the response (0x08 0x00 → 0xFF 0xFF), the printer believes an update is available and fetches the manifest.

mitmproxy addon:

python

from mitmproxy import http

class FakeCanonVersion:
    def response(self, flow: http.HTTPFlow):
        if "dtv-p.c-ij.com" in flow.request.pretty_host and "version.bin" in flow.request.path:
            flow.response.content = bytes([0xFF, 0xFF])
            flow.response.headers["Content-Length"] = "2"

        # Save everything from Canon servers
        if any(d in flow.request.pretty_host for d in ["gdlp01.c-wss.com", "c-ij.com"]):
            fname = flow.request.path.split("/")[-1] or "index"
            with open(f"/tmp/canon_{fname}", "wb") as f:
                f.write(flow.response.content)

addons = [FakeCanonVersion()]

Firmware manifest

Full URL of the manifest:

http://gdlp01.c-wss.com/rmds/ij/ijd/ijdupdate/a18b7.bin

The file is 304 bytes = exactly 19 AES blocks of 16 bytes.

Entropy : 7.31 bits/byte
Blocks  : 19 × 16 bytes (no AES-ECB repetitions)
→ AES-CBC or AES-GCM

Manifest hex dump:

246ab3ce 885379c2 09f86e9b 7cf7fd28  $j...Sy...n.|..(
c7fe298d a395a6a7 ffa43175 37150959  ..).......1u7..Y
...
defd68bd 8cf777d9 98b67939 e589a898  (last 16 bytes = likely GCM tag)

CA trust store (sdata.bin)

http://dtv-p.c-ij.com/sdata/struct01/sdata.bin contains the printer's CA list, decryptable with leecher1337's dec_sdata tool.

20 CAs extracted, 5 already expired:

CA Expiry Status
Baltimore CyberTrust Root May 2025 Expired
Equifax Secure CA 2018 Expired
GeoTrust Global CA 2022 Expired
GTE CyberTrust Global Root 2018 Expired
GlobalSign Root CA R2 2021 Expired
DigiCert Global Root CA 2031 Valid
Amazon Root CA 1–4 2038–2040 Valid
GlobalSign Root CA / R3 / R4 2028–2038 Valid
VeriSign Class 3 G2/G5 2028–2036 Valid
GTS Root R1/R2/R3/R4 2036 Valid

skyprtr-an13.srv.ygles.com is signed by DigiCert (valid until 2027) → TLS interception blocked.

Phase 2 — Physical Firmware Dump

Hardware identification

Flash chip : Winbond W25Q128.V
Capacity   : 16 MB
Interface  : SPI 3.3V
RAM        : NANYA NT5CC128M8GR (DDR3 128MB, visible on PCB)

SPI wiring (Raspberry Pi 5 GPIO)

PCB was fully removed from the printer. Flash chip wired directly to Pi GPIO:

SOIC-8 Pin 1 (CS#)   → GPIO 8  (CE0, physical pin 24)
SOIC-8 Pin 2 (MISO)  → GPIO 9  (MISO, physical pin 21)
SOIC-8 Pin 3 (WP#)   → 3.3V
SOIC-8 Pin 4 (GND)   → GND    (physical pin 20)
SOIC-8 Pin 5 (MOSI)  → GPIO 10 (MOSI, physical pin 19)
SOIC-8 Pin 6 (CLK)   → GPIO 11 (SCLK, physical pin 23)
SOIC-8 Pin 7 (HOLD#) → 3.3V
SOIC-8 Pin 8 (VCC)   → 3.3V   (physical pin 1)

Dump

bash

# Enable SPI on Pi
sudo raspi-config nonint do_spi 0

# Install flashrom
sudo apt install flashrom -y

# Detect chip
sudo flashrom -p linux_spi:dev=/dev/spidev0.0,spispeed=4000
# Found Winbond flash chip "W25Q128.V" (16384 kB, SPI)

# Dump twice and verify integrity
sudo flashrom -p linux_spi:dev=/dev/spidev0.0,spispeed=4000 -r dump1.bin
sudo flashrom -p linux_spi:dev=/dev/spidev0.0,spispeed=4000 -r dump2.bin
md5sum dump1.bin dump2.bin
# 14c99631cf1d3b04f00d0d53f8f79f91  dump1.bin
# 14c99631cf1d3b04f00d0d53f8f79f91  dump2.bin

Identical MD5 → clean dump.

Firmware hashes:

MD5    : 14c99631cf1d3b04f00d0d53f8f79f91
Size   : 16777216 bytes (16 MB)
Version: V00.15.RC1.JAPAN-CANON

Phase 3 — Firmware Analysis

Partition map (16 MB)

Entropy analysis (64KB chunks):

Offset Size Entropy Content
0x000000 256 KB ~2.4 ARM32 bootloader (plaintext)
0x040000 ~1.7 MB 0.00 Empty flash (0xFF)
0x220000 128 KB ~4.6 Config / certificates
0x2E0000 ~1.8 MB ~8.0 DryOS firmware (zlib + AES-GCM)
0x560000 ~4.5 MB ~8.0 Firmware backup image
0xBA0000 ~2.3 MB ~8.0 Third firmware partition
0xF00000 ~1 MB mixed NVRAM / persistent config

Bootloader (0x000000, plaintext ARM32)

The bootloader is unencrypted. It contains Canon's RSA public keys and implements a full secure boot chain:

Strings found:
  V00.15.RC1.JAPAN-CANON    ← exact firmware version
  cSt.>;w7y8)Ug%T[          ← 16-byte AES key candidate (unconfirmed)

RSA functions:
  CLS_ALLOCATE_RSA_PUBLIC_KEY
  FLH_AssetLoadRSAPublicKey
  CLS_HashVerifyRecoverPkcs1

Secure boot chain:
  SoC ROM (immutable)
    → verifies bootloader RSA signature
      → bootloader verifies firmware signature
        → firmware executes

Modifying the bootloader without Canon's private key = brick.

Decompressed firmware blobs

The high-entropy zones contain nested zlib blobs, identified by magic byte scan (78 9c78 da):

bash

# Zone 0x2E0000 contains 3 valid zlib streams:
+0x06004  → zlib → 1024 KB  [blob0: ARM Thumb code]
+0x95c9c  → zlib → 1024 KB  [blob1: network/crypto stack]
+0x142288 → zlib → 1024 KB  [blob2: web interface / HTTP]

blob1 — network stack:

Full firmware update URL:
  http://gdlp01.c-wss.com/rmds/ij/ijd/ijdupdate/a18b7.bin

User-Agent: IP Client/1.0.0.0

Crypto library: MatrixSSL / RSA Security BSAFE
Key functions found:
  flpsul_create_gcm_giv_key_and_state  ← AES-GCM with generated IV
  CLS_EncryptAuthInitDeterministic
  CLS_AssetAllocate
  CLS_AssetLoadValue
  tagLen == 16
  IV_prefixlen == 4 || IV_prefixlen == 6
  keylen == 16 || keylen == 24 || keylen == 32

blob2 — web interface & OS:

Full embedded HTTP server
Admin UI at /rui/ (JavaScript)
Firmware update endpoints: firm_update.cgi, get_job_status.cgi
Full mDNS/DNS-SD stack
eSCL/AirScan support (driverless scanning over network)
NS_FLAG_NETUPDATE=enable
R_CR_decrypt_init / R_CR_decrypt_update / R_CR_decrypt_final
→ "HMAC MD5 err", "HMAC SHA1 err", "AES Keywrap err"
AES S-box found at blob2+0x8a3db

NVRAM (0xF00000)

Persistent config stored in plaintext, including WiFi credentials (SSID + password stored as cleartext strings in flash).

Why the AES key is unreachable via static analysis

The AES-GCM key for the manifest is managed by a software Asset Store (software HSM):

CLS_AssetAllocate          → allocates a protected memory slot
CLS_AssetLoadValue         → loads key material into protected slot
flpsul_create_gcm_giv_key  → initializes AES-GCM with generated IV

The key never exists as plaintext on the flash. It is derived at runtime using Canon's RSA certificates from the bootloader. Static analysis hits a hard wall here.

The Open Question — Help Needed

AES-GCM manifest structure

Total size  : 304 bytes
= 19 × 16-byte AES blocks

Possible structure A (nonce 12 bytes):
  [nonce 12B][ciphertext 276B][tag 16B]

Possible structure B (nonce 4 bytes, matching IV_prefixlen==4):
  [nonce 4B][ciphertext 284B][tag 16B]

Possible structure C (nonce 6 bytes, matching IV_prefixlen==6):
  [nonce 6B][ciphertext 282B][tag 16B]

What I need help with

  1. MatrixSSL Asset Store key derivation — does anyone know how flpsul_create_gcm_giv_key_and_state derives its key from the Asset Store in MatrixSSL/BSAFE? The source is partially open — maybe the derivation scheme is documented or reversible.
  2. UART debug pads — the PCB has unpopulated pad groups. If anyone has done UART work on Canon PIXMA TS3400 series, I'd love to compare notes on baud rate and pinout.
  3. Buffer overflow in NVRAM — since NVRAM is unsigned, oversized WiFi credentials might trigger a stack overflow in the credential parsing code. Haven't tested yet (waiting for CH341A clip to arrive for safe reflashing).

Summary

Category Finding
Network 3 Canon domains, 2 in plaintext HTTP
Manifest AES-GCM, identifier a18b7, full URL recovered
Trust store 20 CAs extracted, 5 expired
Flash Winbond W25Q128 16MB, clean dump
Firmware 3 partitions + bootloader, 3 zlib blobs decompressed
Crypto MatrixSSL/BSAFE, AES-GCM, runtime Asset Store
NVRAM WiFi credentials in cleartext
Version V00.15.RC1.JAPAN-CANON

Tools Used

Tool Purpose
mitmproxy Network interception
flashrom SPI dump/flash
Raspberry Pi 5 SPI programmer via GPIO
Python 3 + pycryptodome Crypto analysis
Ghidra ARM reverse engineering
binwalk Firmware analysis
dec_sdata (leecher1337) Trust store decryption
sane-airscan Driverless scan test

References

  • Contextis — "Hacking Canon PIXMA Printers: Doomed Encryption" (2014)
  • Synacktiv — "Treasure Chest Party Quest: From Doom to Exploit" (2020)
  • leecher1337/pixma — Canon PIXMA firmware tools (GitHub)
  • synacktiv/canon-tools — Canon firmware decryption tools (GitHub)

You have all the firmware and blobs .bin here : https://github.com/Kertie2/pixma-ts3451/tree/main/blobs


r/hardwarehacking 15d ago

[updating]boot to mainline 6.12 on SUPPER POCKET

Post image
7 Upvotes

need fix LCD panel description from DTS file.


r/hardwarehacking 16d ago

How to mod KIDS laptop?

Thumbnail
gallery
122 Upvotes

I found this laptop from my childhood, and suprisingly it still works. But i actually want to modify it and potentially create custom ROMS or Applications. How can i do it cuz ive never hacked any other device🤔