Card-Crack: Cardputer ESP32-S3 home-lab recon toolkit
Manual-trigger firmware toolkit for pentesting owned devices: - Pin Scan: UART/JTAG/SWD detection (baud est + IDCODE reads) - V-Sense: target voltage probe w/ logic-family guess - UART Sniff: passive capture + manual-only frame replay - USB Enum: ESP32-S3 host, read-only descriptor fingerprinting - DefCred: single-host factory-default login check, rate-limited Modular shell (core/ + modules/), PlatformIO build, hardware/safety docs. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AAhMHMRAQLQ9hSbBECKNfn
This commit is contained in:
41
docs/HARDWARE.md
Normal file
41
docs/HARDWARE.md
Normal file
@@ -0,0 +1,41 @@
|
||||
# Hardware & wiring — read before probing
|
||||
|
||||
The Cardputer's ESP32-S3 is a **3.3 V** part. Several targets you'll poke are
|
||||
not:
|
||||
|
||||
- Car OBD/USB, PC USB: **5 V** VBUS.
|
||||
- Some debug headers idle at 1.8 V.
|
||||
|
||||
**Always** go through protection. Never land a probe on a live target until
|
||||
V-Sense has told you the voltage.
|
||||
|
||||
## Probe header
|
||||
|
||||
`src/core/pins.h` defines `pins::PROBE[]`. By default:
|
||||
|
||||
- `G1`, `G2` — the side Grove connector (safe, use these first).
|
||||
- `G8..G13` — StampS3 pads via a breakout ribbon (optional).
|
||||
|
||||
## Minimum protection rig
|
||||
|
||||
| Signal | Between probe and target |
|
||||
|---------------|-------------------------------------------------------|
|
||||
| Any GPIO in | 1 kΩ series + 3.3 V clamp (BAT54S to 3V3/GND) |
|
||||
| V-Sense (G10) | resistor divider R1:R2 = 2:1 → 0–9.9 V range (ratio 3)|
|
||||
| Level shift | bidirectional shifter (e.g. TXS0108) for 5 V buses |
|
||||
|
||||
Adjust `pins::VSENSE_RATIO` if you change the divider.
|
||||
|
||||
## USB host
|
||||
|
||||
To use **USB Enum** the S3 must supply VBUS to the target as a host. Use an
|
||||
OTG adapter on the S3 USB port, keep the CDC console on the built-in USB, and
|
||||
never hot-plug a 5 V target onto a GPIO — it goes on the USB D+/D-/VBUS lines
|
||||
only.
|
||||
|
||||
## Safety checklist
|
||||
|
||||
1. Target powered from its **own** supply, common ground with the Cardputer.
|
||||
2. V-Sense the line first. If it reads ≥ 5 V, shift or stop.
|
||||
3. Start passive (Pin Scan / UART Sniff). Only replay/TX when you mean to.
|
||||
4. It's your device. Keep it that way.
|
||||
Reference in New Issue
Block a user