Claude 36d10e604b Enable auto-execution on USB attack modules for aggressive exploitation
- HID Inject: auto-triggers payload injection on host detection
- USB Gadget: auto-detects best device class and enumerates immediately
- JTAG USB Bridge: auto-detects protocol and starts bridging on entry
- RNDIS Bridge: auto-starts ethernet gadget and DHCP server on entry
- USB Sniffer: auto-captures packets immediately on entry

All USB modules now auto-execute without manual trigger, enabling plug-and-exploit workflow.
2026-09-24 16:45:30 +00:00

Card-Crack

A manual-trigger hardware/network recon toolkit for the M5Stack Cardputer (ESP32-S3), built for home-lab pentesting of devices you own — your router, a car's OBD/USB port, a PC, smart appliances.

⚠️ Authorized use only. Every tool here is scoped for your own bench: single targets you enter by hand, curated default-credential lists (not brute-force), rate-limited network checks, and read-only descriptor/ID reads. Nothing scans, transmits, or replays on its own — you press the action key. Don't point it at anything you don't own or run.

Modules

Module What it does
Pin Scan JTAGulator-style detection of UART / JTAG / SWD pins on the probe header. UART baud estimation; JTAG & SWD IDCODE reads.
V-Sense Live target-voltage probe through a divider; guesses the logic family so you know what you're touching before driving a pin.
UART Sniff Passive UART capture (hex+ascii, selectable baud); freeze a frame and replay it on a keypress (manual TX only).
USB Enum ESP32-S3 as USB host — reads descriptors (VID/PID, class, strings, config) to fingerprint an unknown device. Read-only.
DefCred Checks a single host (default: gateway) against a short list of factory-default logins over HTTP Basic Auth. Stops on first hit.
Bus Dump Reads SPI-NOR (25-series) and I2C EEPROM (24-series) chips on your own boards to /dump/*.bin on microSD. Read-only.
Crypto Lab Offline analysis of a dumped blob: Shannon entropy, magic-byte file-ID, single-byte XOR brute, AES-128-ECB known-key decrypt.
Exfil Browse the SD card and stream a dump to the host over USB serial as base64 (base64 -d); writes a manifest of what you pulled.
Theme Live UI theme switcher — 5 palettes, saved to NVS, restyles everything instantly.
CAN Bus OBD/automotive CAN frame sniffer — listen on MCP2515 over SPI, log frames to SD, cycle bus speeds.
UART+ Enhanced UART with parallel auto-baudrate detection, session logging to binary, protocol hints.
Protocol Unified UART/SPI/I2C sniffer — real-time stats (packets/sec, data rate, frame errors).
MemSearch Post-dump binary analysis — find strings, magic bytes, hardcoded IPs, entropy spikes in captured blobs.
Logger Persistent session logging — auto-log to JSON with metadata (voltage, pins, targets, timestamps). Export logs.
Injector Manual credential/command injection — AT commands, OBD-II queries, Telnet login attempts. Capture responses.
Scope Simple ASCII oscilloscope — sample GPIO at ~100kHz, display waveform, spot edges and DC bias.
Wizard Two-wire protocol auto-detect — sniff I2C/SWD on pin pairs, register read/write on found slave.
Settings Persist configuration (scan delay, voltage thresholds, timeouts, baud list) to NVS. JSON export/import.
HID Inject USB HID keyboard/mouse emulation — inject keystrokes, mouse clicks into any host that plugs in. Configurable payloads with 50ms inter-key delay.
USB Gadget Emulate different USB device classes (mass storage, CDC/ACM, HID, RNDIS, MTP) to bypass host device filters and detection.
JTAG USB Tunnel JTAG/SWD debug port to host over USB — expose Cardputer as USB debugger. OpenOCD/GDB-compatible.
RNDIS Virtual ethernet over USB — assign 192.168.7.1 IP, DHCP server, pivot to host network for scanning/attacks.
USB Sniffer Monitor and capture USB traffic from connected devices — filter by class, log packets with timestamps and hex payloads to /logs/usb_*.log.

30 modules total

Discover: Pin Scan, V-Sense, USB Enum, CAN Bus, Wizard
Sniff & Replay: UART Sniff, UART+, Protocol, Scope
Dump & Export: Bus Dump, Logger, Exfil
Analyse: Crypto Lab, MemSearch
Inject & Test: Injector, DefCred
USB Attacks: HID Inject, USB Gadget, JTAG USB, RNDIS, USB Sniffer
System: Theme, Settings

Heavy exploitation (authorized use only)

Module What it does
USB Shell Interactive CLI over USB serial — read/write memory addresses, GPIO control, direct hardware access.
Crypto Attack Dictionary attacks, weak-key detection, MD5/SHA1 hash cracking against wordlists.
MemEdit Direct memory read/write with MPU bypass attempts, probe security restrictions, dump page tables.
Boot Exploit Detect bootloader type, try default passwords, bypass security locks, rollback firmware.
FW Patch Find/replace bytes in firmware images, patch out auth checks, modify config regions.
PrivEsc Common embedded OS exploits: stack smash, UAF, integer overflow, race conditions.
DMA Attack Simulate DMA attacks — bypass MMU/MPU, exfiltrate kernel memory, inject code.

Look & feel

Boot splash with a sweeping-glow logo, CRT scanlines, a breathing menu cursor, wipe-in transitions, spinners and progress bars. Switch palettes any time in the Theme module.

Build & flash

Requires PlatformIO.

# set your lab Wi-Fi for the DefCred module (or edit defcred.cpp)
pio run -e cardputer \
  -a "--build-property build.flags=-DCC_WIFI_SSID='\"MyAP\"' -DCC_WIFI_PASS='\"secret\"'"
pio run -e cardputer -t upload
pio device monitor

Controls

  • Menu: ; up · . down · Enter open
  • In a module: ` (backtick) back · per-module hints on the bottom bar

Layout

src/core/     shell, module interface, UI helpers, pin map
src/modules/  one file per recon tool
docs/         HARDWARE.md wiring + safety

See docs/HARDWARE.md before wiring — the S3 is a 3V3 part and 5V on a bare GPIO will destroy it.

Description
A tool for analyzing the world with visuals
Readme 282 KiB
Languages
C++ 100%