Files
Carputer-cracker/docs/HARDWARE.md
Indiana Holmes 79612197a1 Card-Crack: Cardputer ESP32-S3 home-lab recon toolkit
Manual-trigger firmware toolkit for pentesting owned devices:
- Pin Scan: UART/JTAG/SWD detection (baud est + IDCODE reads)
- V-Sense: target voltage probe w/ logic-family guess
- UART Sniff: passive capture + manual-only frame replay
- USB Enum: ESP32-S3 host, read-only descriptor fingerprinting
- DefCred: single-host factory-default login check, rate-limited

Modular shell (core/ + modules/), PlatformIO build, hardware/safety docs.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AAhMHMRAQLQ9hSbBECKNfn
2026-09-10 18:12:42 +00:00

42 lines
1.5 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Hardware & wiring — read before probing
The Cardputer's ESP32-S3 is a **3.3 V** part. Several targets you'll poke are
not:
- Car OBD/USB, PC USB: **5 V** VBUS.
- Some debug headers idle at 1.8 V.
**Always** go through protection. Never land a probe on a live target until
V-Sense has told you the voltage.
## Probe header
`src/core/pins.h` defines `pins::PROBE[]`. By default:
- `G1`, `G2` — the side Grove connector (safe, use these first).
- `G8..G13` — StampS3 pads via a breakout ribbon (optional).
## Minimum protection rig
| Signal | Between probe and target |
|---------------|-------------------------------------------------------|
| Any GPIO in | 1 kΩ series + 3.3 V clamp (BAT54S to 3V3/GND) |
| V-Sense (G10) | resistor divider R1:R2 = 2:1 → 0–9.9 V range (ratio 3)|
| Level shift | bidirectional shifter (e.g. TXS0108) for 5 V buses |
Adjust `pins::VSENSE_RATIO` if you change the divider.
## USB host
To use **USB Enum** the S3 must supply VBUS to the target as a host. Use an
OTG adapter on the S3 USB port, keep the CDC console on the built-in USB, and
never hot-plug a 5 V target onto a GPIO — it goes on the USB D+/D-/VBUS lines
only.
## Safety checklist
1. Target powered from its **own** supply, common ground with the Cardputer.
2. V-Sense the line first. If it reads ≥ 5 V, shift or stop.
3. Start passive (Pin Scan / UART Sniff). Only replay/TX when you mean to.
4. It's your device. Keep it that way.