Anyone here familiar with reverse engineering communication protocols between ICs? This specific one is based on SPI. The observations deducted from logic analyzer traces do match firmware binary reverse engineering observations. But from here on, it gets tedious. This is probably a skill issue. Disassembly and decompilation done my Ghidra. Also kind of looking for legal advice before I publish details. I am located in Germany.
Remote
4 Followers
3 Following
9 Posts
Joined June 14, 2026
Open post
Replying to
interestingly, there are "cheap" alternatives: https://electroniccats.com/store/faulty-cat/ — the Faulty Cat V2.2 at 120 USD.
0
8
1
0
Open post
Replying to
Oh, wow. The ChipSHOUTER Kit sells at 4605 USD. 🤯 So EMFI seems like the most expensive approach... at least when compared to the ChipWhisperer boards.
0
9
1
0
Open post
Replying to
Ah.. and it seems to be derived from the low-cost ChipSHOUTER-PicoEMP Kit
(100 USD, DIY). https://www.newae.com/product-page/chipshouter-picoemp-kit
0
1
1
0
Open post
"1 Button Press Can Hack Millions of Cars —
With the press of a button, millions of cars can be hacked. Professor Aaron Schulman and team discovered a universal vulnerability installed in more than 2,000,000 cars across the US. @WIRED@flipboard.com technology journalist Andy Greenberg exposes the novel hacking technique—including just how easy it is to steal a car—and explains what you need to do to patch a hidden device you may not even know is in your vehicle." /
"A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now — Dealerships installed alarms in millions of vehicles—and left them in even if the buyer didn’t want them. Now researchers warn they can be hacked to unlock, track, and disable cars."
TL;DR: ~2 million vehicles across the US affected, independent of car manufacturers, it's bad, needs manual patching via Bluetooth
YouTube video: https://youtu.be/FwA3CuJxbk4
WIRED article: https://www.wired.com/story/a-device-hidden-in-cars-across-the-us-leaves-them-vulnerable-to-hacking-and-paralysis-patch-it-now/ (https://archive.is/EvBjc)
#itSecurity #carHacking #hacking #karr
0
0
0
0
Open post
Replying to
@diffusedtactics@infosec.exchange @0x00string@infosec.exchange interesting indeed. Do you have an affordable XYZ stage in mind? I don't own 3D printer spare parts anymore.
0
3
0
0
Open post
Replying to
@diffusedtactics@infosec.exchange @0x00string@infosec.exchange sure, that was understood. I was actually looking for specific product recommendations. However, in the meantime I did some research and ordered the cheapest CNC platform I could find. So you have any recommendations (blog articles, videos, ...) for getting started with glitching? Have a nice weekend!
0
1
0
0
Open post
Replying to
@troed@swecyb.com Thanks for your answer. The main problem is probably that there's no public documentation as it's proprietary. So it's a big guessing game. No debug strings in the firmware so I had started to drive everything bottom up, starting from SPI peripheral accesses of the MCU (which does have some SDK source code but again no public datasheet). I'd like to find how the peripheral on the other side works. Presumably, it's quite complex. Looks like it has some 16 bit registers that can be read and written, triggering some action. I guess that static analysis needs to be combined with dynamic analysis (logic analyzer tracing), trying to build up context/ a model.
0
0
0
0
