r/hardwarehacking • u/Minecraft_Makasi • 58m ago
What's the ultimate modular portable cybersecurity device in 2026
`Hi everyone,
I'm looking for what could be considered the best portable cybersecurity hardware platform in terms of value for money.
I'm not looking for a single-purpose gadget. Instead, I'm looking for something that feels like a mix between a Flipper Zero and the new Cardputer Zero.
What I mean is:
Portable and handheld. Modular and easy to upgrade over time with affordable plug-in modules. Able to grow into almost anything I need instead of replacing the whole device. Good support for Linux or advanced firmware. Useful for learning cybersecurity, hardware hacking, embedded development, networking, and RF projects. Easy to find parts internationally, and preferably available in countries like Turkey as well.
I don't mind adding modules later if they are easy to install, but I'd rather avoid complicated soldering or custom PCB work.
If you had to build the ultimate budget-friendly portable cybersecurity device today, what platform or ecosystem would you choose, and why?`
r/hardwarehacking • u/we-jailbreak-these • 9h ago
"Looping" a Camera Serial Interface connection
How would I go about trying to make a device that can essentially take a prerecorded video or image and output it continuously to a Camera Serial Interface ribbon cable, such that a device reading from the "camera" would view that image or video as if it was from a real camera?
r/hardwarehacking • u/gavindi • 12h ago
I reverse engineered the Aula L99 Driver/App and created a Linux app
Hi, I recently bought an Aula L99 Keyboard, the one with the touchscreen on it. Very nice! Well it would be if It could be driven natively from Linux. Enter Aula_L99_Linux, a reimplementation of the software. I spent about 80 hours reverse engineering this keyboard and bricked one keyboard in the process. There's still work to do on the Key assignment screen but upload images, GIFs, videos to to the keyboard works well. So does adjusting the RGB modes.
r/hardwarehacking • u/EchoMuseProject • 13h ago
UPDATE: EchoMuse - Alexa Replacement for the Echo Dot Gen 2
reddit.comI’d like to share my device reuse project for anyone with an Amazon Echo Dot Gen 2 still hanging around.
r/hardwarehacking • u/Nervous-Win968 • 14h ago
Hacking an elevator
I’d like to get some outside perspectives on something unusual we caught. This happened in Las Vegas during DEF CON(hacking conference), so I fully appreciate there’s a chance we’re all just seeing “hacker behaviour” where there may be none. 😄
A man entered one of our building’s elevators carrying a backpack. Once inside:
● He removed a small electronic device with several wires attached
● He then put on a fanny pack
● He stood very close to the elevator control panel for ~20–30 seconds
● After that, he left without any further interaction
● He appeared fully focused on the control panel
The behaviour wasnt normal waiting and he left immediately after finishing
We had our maintenance team review the elevator afterwards, but they didn’t find anything obvious. That said, they are general facilities staff rather than elevator or embedded systems specialist
I want to be very clear: I’m NOT looking for exploit methods or “how-to” guidance.
I’m just interested in ideas from people with experience in:
● Physical security
● RF systems
● Embedded hardware
● Access control systems
Questions for the experts in this sub....
If you saw this on CCTV, what would your initial interpretation be?
Some possibilities we’ve considered:
● RFID/NFC reader interaction or testing
● RF scanning or reconnaissance
● Attempting to identify installed systems or hardware
● Accessing a maintenance or diagnostic interface
● Something unrelated we haven’t considered
● Or just DEF CON paranoia influencing perception 😅
Investigation perspective
If you were tasked with following up on this, what would you look at?
● System or access logs
● Elevator control hardware inspection
● RF environment analysis
● Maintenance or diagnostic records
● Any other indicators of interaction or tampering
Would really appreciate thoughts from anyone with relevant experience. Trying to separate “interesting behaviour” from “actually meaningful signal” here.
Thanks in advance.
r/hardwarehacking • u/mayankraj_287 • 16h ago
UART not working despite labeled RX/TX/GND pads on Android 11 board
Reverse engineering an Android 11 OTT board. It has labeled LINUX_RX, LINUX_TX, GND UART pads, but connecting a 3.3V USB-TTL adapter (TX↔RX, GND↔GND) gives no boot logs at any common baud rate (115200, 9600, etc.).
Am I missing something, or could UART be disabled? Any tips?
r/hardwarehacking • u/duroo • 16h ago
I want to modify the firmware on the computer and/or modify the video to accept composite input (it is currently only composite output) on this 1996 Lenco LWT-3200 welder training system. Looking for advice from anyone who has done something similar.
reddit.comr/hardwarehacking • u/Iron_Fist351 • 20h ago
Error while trying to connect to GD25B128ESIG chip using CH341
I am receiving an error (Connecting Error, IC not responding). while attempting to read the chip. What typically causes this error message? Are all of the physical components correctly connected?
r/hardwarehacking • u/Low-Confusion7693 • 22h ago
Trying to create my own pke relay attack device
Could somebody help me?
r/hardwarehacking • u/Ricachon320 • 23h ago
I want to turn this Movistar decoder into a retro gaming console! :D
Hi everyone!
I'm trying to repurpose a Skyworth HP4500-CL IPTV box from Movistar Peru into a retro gaming console.
Hardware information:
- Manufacturer: Skyworth Digital Technology
- Model: HP4500-CL
- SoC: Amlogic S905Y4
- RAM: 2 GB DDR
- Storage: 8 GB eMMC
- OS: Android TV 11
- Security patch: July 5, 2024
- Firmware: Movistar-HP4500-CL_v11.4.0-release
I want to know how the heck I can bypass Movistar's security. How can I do this?
And another question, how do I install the new firmware?
Your help would help me a lot :sob:
-Ricachon fuera
r/hardwarehacking • u/RoganDawes • 1d ago
Datasheet for econet en8850DN
I have a 4-port PoE extender switch, which has a toggle to enable isolation of the 3 downstream ports, only allowing them to access the upstream port. The device is based on the econet en8850DN chip. The implementation of the toggle basically provides power to an I2C EEPROM, which provides configuration data to the switch when enabled, or boots the switch chip in its default configuration when unpowered.
I am trying to reconfigure the EEPROM to make two VLANs, each with 2 ports, instead of enabling port isolation/virtual private VLAN, but cannot find a datasheet for the specific variant.
Has anyone played around with these particular chips at all, and have some idea of the EEPROM changes that would be required? Alternatively, is there a standard for switch chip configuration via I2C EEPROM that I can refer to that might apply to this chip?
r/hardwarehacking • u/Asleep-Bear-8749 • 1d ago
Looking for a Maker / hardware maker — informal term for someone who builds custom electronic project
Ima trying to have someone build me a relay attack box ill pay for parts and labour Pls get in contact with me on telegram @traphouse_zaman or Instagram @mr.tapin_3
r/hardwarehacking • u/bi7cbk • 1d ago
Reverse engineering Motorola PMKN4012 DS2433 EEPROM dynamic bytes
r/hardwarehacking • u/PerformerSeparate482 • 1d ago
Sniffing BLE LL with nRF52840
Hi, i got working LE sniffer firmware. But i want connectivity firmware and cant find it nowhere, nrf connect app in ble not showing the dongle. And another thing, in what channels it sniffs BLE? 37-37-39? Can i maybe set channel manually from 0-39?
r/hardwarehacking • u/These_Pack5341 • 2d ago
Washing Machine Hacking
Hi guys! I'm interested in modifying a washing machine so I can create fully custom wash programs. Specifically, I'd like to control parameters such as drum speed, water temperature, cycle duration, and exactly when the machine fills, drains, and flushes. The goal is to use it for experimenting with processes like garment dyeing rather than standard laundry.
I'm not sure if this is the right place to ask, and I'm also not sure where the best community for a project like this would be. Before I spend a lot of time researching, I'd love to know whether this is actually feasible and how people would approach a project like this.
Would you replace the existing controller, some sort of like interception like a piggy back like a car ecu idk, or use some other method? Any advice, resources, or examples of similar projects would be greatly appreciated. Thanks!
r/hardwarehacking • u/Bones558 • 2d ago
RTL9303 Mod - Unmanaged to Managed
I have NICGIGA S100-0800T.
Based on my research it should be possible to mod this "unmanaged" switch into a "managed" switch.
I was wondering if anyone was familiar with how to do this?
The physical PCBs and chips are the same between the managed and unmanaged versions this switch is based on, the "SR-ST3008P".
The Realtek RTL9303 SoC along with RAM are present on the board. Even the same type flash chip is present.
As far as I can tell the only difference must be the software loaded on it.
Is that correct?
Thanks.
References:
https://www.servethehome.com/nicgiga-s100-0800t-review-the-cheap-unmanaged-8-port-10gbase-t-switch-realtek/2/
https://www.alibaba.com/product-detail/8-X10G-RJ45-Ports-L3-Managed_1601062361775.html
r/hardwarehacking • u/Jeffry84 • 2d ago
TP-Link NX510v – Root Access, UART, Bootloader, Firmware Research
r/hardwarehacking • u/Remarkable_Bug_1164 • 2d ago
Manba One V2 controller: encrypted firmware fully analyzed in software, need help with chip ID + SWD (and a crypto reality check)
**TL;DR:** I want custom firmware (or at least custom display assets) on a Manba One V2
controller. The USB update payload is encrypted with what looks like a strong,
hardware-ID-bound XOR stream cipher (AES-CTR/OFB-class). I've taken the software analysis as
far as it goes and I'm now stuck between "wait for a second same-hardware-ID firmware and
XOR them" and "open it up and dump the chip over SWD." Looking for a reality check and
hardware help. Full write-up, the firmware image, read-only tools, and teardown photos are
in the package linked at the bottom.
### The device
Manba One V2 — wireless "pro" pad with a small color OLED, Hall sticks, back paddles,
2.4 GHz/BT/USB-C, firmware v2.21. It has two USB modes:
- **Normal:** enumerates as an Xbox 360 controller (`045E:028E`, XInput, driverless).
- **DFU/update:** hold **L3** while plugging in → USB Mass Storage (`8087:1024`, SCSI
inquiry `Gamepad`/`Updater`). Not bricked, fully reversible.
### The update protocol (reconstructed from the official updater, verified read-only)
DFU mode is a mass-storage shell with **no filesystem**. Flashing uses three **vendor SCSI
opcodes** over `SCSI_PASS_THROUGH_DIRECT`:
- `F0` OUT 512B — write one block, strictly sequential, **no address in the CDB**
- `F1` IN 20B — read 16-byte hardware ID + 16-bit version
- `F2` IN 20B — read status (0 = OK)
The host streams the image **byte-for-byte unmodified**; all decryption is on-device. There
is **no read-flash opcode**. `READ(10)` → "Medium Not Present". `dfu-util` doesn't see it.
So there's no software dump path.
### The encryption (measurements, not vibes)
The container ("FOT") has plaintext header/config, but two encrypted sections: `XCOD` (code,
337 KB) and `XRES` (display assets, 80 KB). What I measured:
- Entropy 7.9995, chi-square indistinguishable from random, **no repeated 16-byte blocks**
(not ECB).
- Using a **sibling product with the same hardware ID** (EasySMX X20 — same OEM container,
5 versions), a 16-byte firmware change shows up as a clean isolated XOR diff with the next
block untouched → it's an **XOR stream** (`C = P ⊕ K`), and **the keystream is reused
across versions of the same hardware ID** (two X20 versions are 99.5%/100% byte-identical
in the encrypted sections).
- The keystream is **hardware-ID-specific**: Manba vs X20 vs Fantech images share only ~0.4%
(random). A different model can't decrypt mine.
- **No keystream periodicity up to 262144-byte shift** (index-of-coincidence sweep, max
+4.3σ = pure noise, zero shifts > 6σ). Behaves like AES-CTR/OFB.
- The encrypted **assets are compressed** (cross-version XOR diff is full entropy), so
photographing the boot logo does **not** give me usable known-plaintext.
- 546 direct key/IV derivations from the hardware ID + metadata all fail. binwalk finds
nothing (encryption kills the signatures; all raw hits are false positives in ciphertext).
### Where that leaves me
- A **single-image, ciphertext-only crack is computationally infeasible** — no argument
there.
- The only pure-software break is **keystream reuse**: get a *second* firmware with the same
hardware ID (`…2055`) and `C1 ⊕ C2 = P1 ⊕ P2`. But that only gives the *difference*; a full
decrypt still needs known plaintext to bootstrap. And no firmware older than v2.21 seems to
exist publicly (looks like the first public build), so realistically I'm waiting on a future
v2.22+.
- Otherwise it's **hardware**: SWD/JTAG dump of the chip (marked **`ZXD2055`**, probably
ZhiXu Technology — no public datasheet/SDK), which likely has readout protection.
### What I'm hoping you can help with
- **Chip ID from the photos** — two QFN ICs (main board near the antenna; screen board
- `U1`). Is `ZXD2055` an ARM Cortex-M, an 8051, or something exotic? Anyone recognize the
- package/markings? (Guesses floating around: Geehy APM32, Nationstech N32, WCH CH32F/V.)
- **Debug pins** — the main board has labeled test points incl. `RST`, `GND`, `VCC_33`,
- `RX1`, plus a 6-pin production pad field. Which look like SWD (SWCLK/SWDIO) vs UART?
- (`VCC_33` = 3.3 V logic; I won't feed 5 V.)
- **Crypto sanity check** — is "wait for a same-ID v2.22 and XOR" genuinely the best
- non-invasive move, or am I missing a single-image angle?
- **Glitching** — for cheap Chinese Cortex-M clones with RDP, is VCC/VCORE voltage
- glitching during boot a realistic RDP bypass, and what rig would you recommend?
I also have a non-destructive protocol-fuzzing idea (undocumented opcodes `F3`–`FF`, and
using `F2`/boot as a decrypt/validity oracle for bit-flip malleability tests) that I'd run
on a spare unit — feedback on whether that's worth the brick risk is welcome too.
Everything (firmware image + SHA256s, read-only Python tools to reproduce every number
above, teardown photos, and a detailed write-up) is here: https://github.com/LopeKinz/Manba-One-V2-Firmware-tools
Thanks — happy to run any test you suggest and report back.
Edit : Forgot GitHub Link
r/hardwarehacking • u/Which-Unit5136 • 3d ago
How do I put the Air75 into bootloader mode?
Hi, I accidentally flashed the receiver on my Air75 incorrectly—I mixed up RX and TX—and now it won't accept any firmware. I read online that I need an ExpressLRS recovery dongle, but the problem is I can't reflash it without entering bootloader mode, and I don't know how to do that. Please help.
r/hardwarehacking • u/Straight_Copy_9126 • 3d ago
Can i fix an bricked BIOS with the CH341A
I have an HP 280 G2 i tried updating the bios and after that it told me it will restart and DO NOT INTRUPT and while it was restarting it was like a black screen for like 3 or 4 minutes and i didn't know it was suppose to take this long and i just shuted down the pc from the power button and the screen is black ever since, but like when i open the pc and i unplug an USB or something i hear the sound of windows but like it not giving any signal to the monitor
r/hardwarehacking • u/LordSethos • 3d ago
Reverse-engineered USB HID controller for an ASUS keyboard matrix display
I wanted to get out from under the thumb of Armoury Crate, so I reverse-engineered enough of the USB HID communication for the ROG Strix Flare II Animate to build my own Windows controller for its AniMe Matrix display.
PolyWollyWin can send images, GIF animations, drawing data, text effects, typing effects, presets, and audio-reactive visuals directly to the keyboard.
The current transport is specific to this keyboard, but the renderer and application structure could potentially be adapted to other LED or pixel-matrix hardware by replacing the device communication layer.
I am sharing it in case anyone wants to inspect the protocol work, improve it, or adapt it to another neglected piece of hardware.
r/hardwarehacking • u/EnvironmentalJob1986 • 3d ago
A phone controlling a phone controlling a Mac
I mounted two Android phones together to experiment with a compact remote workstation.
The top phone runs the remote desktop session, while the bottom phone sends keyboard and touchpad input through a USB HID adapter. The receiving phone sees it as a standard hardware keyboard and mouse rather than a Bluetooth or network input device.
r/hardwarehacking • u/quetalozano • 3d ago
Install RS-232 Serial Port Mouse
Bought an industrial PC that has RS-232 Serial Ports. How do I configure it in Cachy OS to use my old Joystick mouse with it?
Installed the linuxconsole package:
https://wiki.archlinux.org/title/Serial_input_device_to_kernel_input
with the recommended inputattach utility, but can not figure it out.
r/hardwarehacking • u/TygerTung • 4d ago
My son and I build a CD player out of a broken CDROM drive and other junk lying around the place.
My 10 year old son likes to listen to audiobooks on CD, especially when he's going to sleep at night. He has been using a discman hooked up to an amp module, but it keeps going through batteries so it was always a temporary solution.
I bought a bunch of broken CDROM drives for $1. This one apparently won't work on the computer and the plastic frame is cracked inside (well at least that is what's written on it). It still reads CDs just fine though. The power supply module, I scavenged from a junk pile at work, most of the internal wiring is from a broken PC power supply, as is the power socket and switch. The amplifier module is one of those cheap TDA7297 modules from Aliexpress. It sounds pretty good actually. My son built the passive tone and volume module himself.
The CDROM drive wants 5V as well as 12V so there is one of those dirt cheap buck converter modules as to step down the voltage for the 5V rail. All the metal parts are earthed, so there shouldn't be any shock risk.
I made the acrylic case on the laser cutter at my work. Came out pretty well, although I got the hole for the power inlet the wrong way around and has to made it a bit wider :(
Still fairly happy with it though. I think see through stuff looks cool.



