Card-Crack: Cardputer ESP32-S3 home-lab recon toolkit

Manual-trigger firmware toolkit for pentesting owned devices:
- Pin Scan: UART/JTAG/SWD detection (baud est + IDCODE reads)
- V-Sense: target voltage probe w/ logic-family guess
- UART Sniff: passive capture + manual-only frame replay
- USB Enum: ESP32-S3 host, read-only descriptor fingerprinting
- DefCred: single-host factory-default login check, rate-limited

Modular shell (core/ + modules/), PlatformIO build, hardware/safety docs.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AAhMHMRAQLQ9hSbBECKNfn
This commit is contained in:
Indiana Holmes
2026-09-10 18:12:42 +00:00
commit 79612197a1
16 changed files with 967 additions and 0 deletions

50
README.md Normal file
View File

@@ -0,0 +1,50 @@
# Card-Crack
A manual-trigger hardware/network **recon toolkit** for the
[M5Stack Cardputer](https://docs.m5stack.com/en/core/Cardputer) (ESP32-S3),
built for **home-lab pentesting of devices you own** — your router, a car's
OBD/USB port, a PC, smart appliances.
> ⚠️ **Authorized use only.** Every tool here is scoped for your own bench:
> single targets you enter by hand, curated default-credential lists (not
> brute-force), rate-limited network checks, and read-only descriptor/ID
> reads. Nothing scans, transmits, or replays on its own — you press the
> action key. Don't point it at anything you don't own or run.
## Modules
| Module | What it does |
|-------------|---------------------------------------------------------------------|
| **Pin Scan**| JTAGulator-style detection of **UART / JTAG / SWD** pins on the probe header. UART baud estimation; JTAG & SWD IDCODE reads. |
| **V-Sense** | Live target-voltage probe through a divider; guesses the logic family so you know what you're touching before driving a pin. |
| **UART Sniff** | Passive UART capture (hex+ascii, selectable baud); freeze a frame and **replay it on a keypress** (manual TX only). |
| **USB Enum**| ESP32-S3 as USB host — reads **descriptors** (VID/PID, class, strings, config) to fingerprint an unknown device. Read-only. |
| **DefCred** | Checks a single host (default: gateway) against a short list of **factory-default logins** over HTTP Basic Auth. Stops on first hit. |
## Build & flash
Requires [PlatformIO](https://platformio.org/).
```bash
# set your lab Wi-Fi for the DefCred module (or edit defcred.cpp)
pio run -e cardputer \
-a "--build-property build.flags=-DCC_WIFI_SSID='\"MyAP\"' -DCC_WIFI_PASS='\"secret\"'"
pio run -e cardputer -t upload
pio device monitor
```
## Controls
- Menu: `;` up · `.` down · `Enter` open
- In a module: <code>`</code> (backtick) back · per-module hints on the bottom bar
## Layout
```
src/core/ shell, module interface, UI helpers, pin map
src/modules/ one file per recon tool
docs/ HARDWARE.md wiring + safety
```
See **[docs/HARDWARE.md](docs/HARDWARE.md)** before wiring — the S3 is a 3V3
part and 5V on a bare GPIO will destroy it.