Jump to content
View in the app

A better way to browse. Learn more.

Tuts 4 You

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Hardware Reverse Engineering

Reverse engineering of circuitry hardware and firmware...

  1. Teddy Rogers

    Ted.

    • 0 replies
    • 9.6k views
    Teddy Rogers
  2. mrexodia
    Started by mrexodia,

    Hey guys, After a long time I started writing on my blog again. https://mrexodia.github.io/reversing/2019/09/28/Analyzing-keyboard-firmware-part-1 Best regards

      • Like
    • 2 replies
    • 8.7k views
  3. 7ingsong
    Started by 7ingsong,

    Hi All, Somebody know how activate HSM module in DEVKIT-MPC5748G board? Thank you

    • 0 replies
    • 8.7k views
  4. Downloading...
    Started by Downloading...,

    Hey guys, I started my journey some time ago here: https://forum.tuts4you.com/topic/39557-getting-docsis-cable-modem-firmware/ My ultimate goal would be to find a remote code execution on the system. The reason you may ask, is twofold: 1. Learning 2. Being able to access the router without opening it up would be nice. But now I am much further in trying to understanding my cable modem / router but I still have so many questions unanswered... What I managed to find so far: *The router has 2 main microcontrollers (one Puma 5 chip and one Realtek chip), what I suppose is that the Puma 5 chip deals with the Modem part and the Realtek chip with th…

      • Thanks
    • 1 reply
    • 26.1k views
  5. Teddy Rogers
    Started by Teddy Rogers,

    GrayKey iPhone unlocker poses serious security concerns https://blog.malwarebytes.com/security-world/2018/03/graykey-iphone-unlocker-poses-serious-security-concerns/ Ted.

      • Like
      • Haha
    • 1 reply
    • 10.2k views
  6. abbas
    Started by abbas,

    hi all anyone know about current high-end memories(HDD/SSD/RAM)? how they are designed, how they work and materials used to enhance speed or denseness or resistance. it does not have to be on market. prototypes and even hypotheses can help.

      • Like
    • 4 replies
    • 13k views
  7. Vivi
    Started by Vivi,

    Anyone have idea how to start reversing COF file i think it was made by MPLab ide (dont know exact controller familly)

    • 0 replies
    • 9k views
  8. secursig
    Started by secursig,

    Anyone got any experience working with the CPU32 or CPU32+ architecture? I'm working on a target that runs its code out of flash and swaps some data in and out of SRAM, but usually not executable code...so I have no breakpoint abilities. I'm having to reflash the target ( lengthy process ) each time I want to try a change from static analysis and it's really frustrating only being able to single step the CPU and not have it stop anywhere. I'd kill for just a single breakpoint at this point. I tried hardcoding in some stops (bgnd opcode) just as a compiler would to force the CPU into background mode to break, but the changes of the executable code are causing checksum…

    • 0 replies
    • 13.6k views
  9. Teddy Rogers
    Started by Teddy Rogers,

    Dumping the Sega Dreamcast VMU ROM (20 Years Later) http://dmitry.gr/index.php?r=05.Projects&proj=25. VMU Hacking Ted.

    • 2 replies
    • 10.9k views
  10. secursig
    Started by secursig,

    As ARM these days is becoming ever so popular on embedded devices..static analysis always doesn't get it done. Here's a couple of useful tools to allow you to run some code in an IDA database if you want to emulate simple subroutines as if you were debugging them with a JTAG...without any debugging hardware. https://github.com/cseagle/sk3wldbg support: x86 x86-64 ARM ARM64 MIPS MIPS64 SPARC SPARC64 M68K This one allows you to bind python style variables to the arm assembly and run it https://github.com/36hours/idaemu Example1 This is easy function for add. .text:000000000040052D public myadd .text:000000000040052D myadd …

    • 0 replies
    • 8.4k views
  11. Frostbane
    Started by Frostbane,

    Found a nice site, good read for electronics enthusiasts and rc engs as well.. do check it out ☆~(ゝ。∂) http://www.devttys0.com/blog/

    • 8 replies
    • 15.1k views
  12. david.lynch
    Started by david.lynch,

    I'm not sure if it is right to ask it here, if not please delete and forgive me. I would like to know the password for telnet access of an IP camera that we own. Firmware image is uImage_userland. Any information would be greatly appreciated!

      • Like
    • 6 replies
    • 12.1k views
  13. secursig
    Started by secursig,

    thought I would post this since it's extremely useful for working on some embedded targets. the basic principle is you use a cheap logic analyzer to intercept read requests to the chip ( usually from the microprocessor of your target ) since some designs they store special information in small chips on PCB, like serial number, password, settings, etc. after the CPU reads all the addresses its interested in over the SPI or I2C bus your logic analyzer sees the waveforms and captures the data. then this utility will convert the logic analyzer file to a binary dump of the chip by reconstructing the flash memory contents so you can see what's inside and load into IDA. very use…

    • 0 replies
    • 8k views
  14. secursig
    Started by secursig,

    Anyone have any experience working with ABATRON BDI2000 or BDI3000 on 683XX based architecture targets? These are the ones that use the CPU32 instruction set. I also have other JTAG pods that support CPU32, but the support for it is kind of dead these days since over thing has gone the way of ARM. The ABATRON I could never do much with except use the single hardware breakpoint, dump registers and memory. Still pretty useful, but it sucks having to clear the breakpoint and re-add it every time you want to step over any call in code. Soft breakpoints are not an option usually because the target devices usually boot from a rom or bootloader in flash which of course is not di…

    • 0 replies
    • 7.4k views
  15. whoknows
    Started by whoknows,

    https://github.com/travisgoodspeed/md380tools/wiki/IDAPro

    • 1 reply
    • 15.6k views
  16. whoknows
    Started by whoknows,

    https://www.tacnetsol.com/blogs/news/6-websites-with-downloadable-firmware-images

  17. khonel
    Started by khonel,

    helo all... im have some problem for calculation / logarithm key on NFC card, im have 3 type NFC card, Apathon, EDA and YGS. im try to find calculation key (i think like making keygen) connection between Key A, key B and UID i'm trying to unlock using MFOC and MFCUK and got conclusions, UID calculation with Key A = Key B but im can't find logarithm for get Value Key B (value UID constan). i hope im get answer, clue or reference about my problem... thanks hardware = Proxmark, acr122u, PN532, arduino uno software = Parrot OS, proxmarx tool, MFOC and MFCUK

    • 1 reply
    • 12.8k views
  18. kb432
    Started by kb432,

    #1 Is it possible to Extract Hardware firmware Remotely Via Software ? #2 How to extract hardware framework from a device such router and so on. Thanks

    • 2 replies
    • 8.9k views
  19. Techlord
    Started by Techlord,

    Read the FULL ARTICLE HERE . Full SOURCES and set of tools can be DOWNLOADED FROM HERE . A PDF created from the website article is attached for the convenience of the readers. PRACTICAL uses : The principles discussed can be used for reversing the firmware of Routers, Dongles etc etc. Please note that while the author has focussed on firmware which is Open Source, the same principles can also be used for Closed-Source Firmware. Firmware Hooking - Using Capstone and Keystone.pdf

    • 0 replies
    • 7.1k views
  20. Teddy Rogers
    Started by Teddy Rogers,

    Ted.

    • 4 replies
    • 13k views
  21. Teddy Rogers
    Started by Teddy Rogers,

    Makes for a bit of an interesting read... http://cturt.github.io/ps4.html Ted.

    • 17 replies
    • 14.2k views
  22. Loizos
    Started by Loizos,

    I did a lot of research , found some useful information before creating this thread, but I am wondering if someone more experienced can provide me with further information on hardware reverse engineering and where to begin.Please keep in mind that I have no experience on hw reversing whatsoever. Best regards, Loizos

      • Like
    • 3 replies
    • 9.1k views
  23. Teddy Rogers
    Started by Teddy Rogers,

    Ken Sherriff has done a couple of charger teardowns, this one is just as interesting. He explains why you should be careful when purchasing cheap counterfeit chargers, it could save your life... http://www.righto.com/2016/03/counterfeit-macbook-charger-teardown.html Ted.

    • 0 replies
    • 8.7k views
  24. Teddy Rogers
    Started by Teddy Rogers,

    TMX 1795: the first, forgotten microprocessor http://www.righto.com/2015/05/the-texas-instruments-tmx-1795-first.html Ted.

    • 4 replies
    • 9.2k views
  25. Zed
    Started by Zed,

    Hello all good friends of this great community need help on how to make copy of my dongle if anyone can help me I would appreciate very much my program is called RODSTAR already and registration but not what else to do ... RODSTAR.txt

    • 2 replies
    • 9.1k views

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.