- Universal Proto: HTTP/REST, gRPC, WebSocket, MQTT, CoAP, raw sockets - any protocol auto-detected - IoT Swarm: smart home control via MQTT, CoAP, Zigbee, Z-Wave, Thread, LoRa - Industrial SCADA: Modbus TCP/RTU, Profibus, OPC-UA, EtherCAT for PLC and factory automation control - Vehicle Comm: OBD-II, UDS, KWP2000, CAN-FD for vehicle diagnostics and ECU reprogramming - Message Forge: craft & parse any message format (HEX, JSON, Protobuf, binary, XML) with payload injection Brings toolkit to 42 modules. Cardputer can now communicate with virtually any device or system.
8.1 KiB
Card-Crack
A manual-trigger hardware/network recon toolkit for the M5Stack Cardputer (ESP32-S3), built for home-lab pentesting of devices you own — your router, a car's OBD/USB port, a PC, smart appliances.
⚠️ Authorized use only. Every tool here is scoped for your own bench: single targets you enter by hand, curated default-credential lists (not brute-force), rate-limited network checks, and read-only descriptor/ID reads. Nothing scans, transmits, or replays on its own — you press the action key. Don't point it at anything you don't own or run.
Modules
| Module | What it does |
|---|---|
| Pin Scan | JTAGulator-style detection of UART / JTAG / SWD pins on the probe header. UART baud estimation; JTAG & SWD IDCODE reads. |
| V-Sense | Live target-voltage probe through a divider; guesses the logic family so you know what you're touching before driving a pin. |
| UART Sniff | Passive UART capture (hex+ascii, selectable baud); freeze a frame and replay it on a keypress (manual TX only). |
| USB Enum | ESP32-S3 as USB host — reads descriptors (VID/PID, class, strings, config) to fingerprint an unknown device. Read-only. |
| DefCred | Checks a single host (default: gateway) against a short list of factory-default logins over HTTP Basic Auth. Stops on first hit. |
| Bus Dump | Reads SPI-NOR (25-series) and I2C EEPROM (24-series) chips on your own boards to /dump/*.bin on microSD. Read-only. |
| Crypto Lab | Offline analysis of a dumped blob: Shannon entropy, magic-byte file-ID, single-byte XOR brute, AES-128-ECB known-key decrypt. |
| Exfil | Browse the SD card and stream a dump to the host over USB serial as base64 (base64 -d); writes a manifest of what you pulled. |
| Theme | Live UI theme switcher — 5 palettes, saved to NVS, restyles everything instantly. |
| CAN Bus | OBD/automotive CAN frame sniffer — listen on MCP2515 over SPI, log frames to SD, cycle bus speeds. |
| UART+ | Enhanced UART with parallel auto-baudrate detection, session logging to binary, protocol hints. |
| Protocol | Unified UART/SPI/I2C sniffer — real-time stats (packets/sec, data rate, frame errors). |
| MemSearch | Post-dump binary analysis — find strings, magic bytes, hardcoded IPs, entropy spikes in captured blobs. |
| Logger | Persistent session logging — auto-log to JSON with metadata (voltage, pins, targets, timestamps). Export logs. |
| Injector | Manual credential/command injection — AT commands, OBD-II queries, Telnet login attempts. Capture responses. |
| Scope | Simple ASCII oscilloscope — sample GPIO at ~100kHz, display waveform, spot edges and DC bias. |
| Wizard | Two-wire protocol auto-detect — sniff I2C/SWD on pin pairs, register read/write on found slave. |
| Settings | Persist configuration (scan delay, voltage thresholds, timeouts, baud list) to NVS. JSON export/import. |
| HID Inject | USB HID keyboard/mouse emulation — inject keystrokes, mouse clicks into any host that plugs in. Configurable payloads with 50ms inter-key delay. |
| USB Gadget | Emulate different USB device classes (mass storage, CDC/ACM, HID, RNDIS, MTP) to bypass host device filters and detection. |
| JTAG USB | Tunnel JTAG/SWD debug port to host over USB — expose Cardputer as USB debugger. OpenOCD/GDB-compatible. |
| RNDIS | Virtual ethernet over USB — assign 192.168.7.1 IP, DHCP server, pivot to host network for scanning/attacks. |
| USB Sniffer | Monitor and capture USB traffic from connected devices — filter by class, log packets with timestamps and hex payloads to /logs/usb_*.log. |
| Polyglot | Multi-language code generation — generate reverse shells, creds dumps, memory readers, keyloggers in Python, Bash, PowerShell, C, Go, Rust, Ruby, Perl. |
| WiFi Dashboard | Start web server on local network — stream all scraped data, logs, payloads to web UI accessible from phone on http://192.168.1.1:8080, download logs as .tar.gz. |
| BT Dominator | Force Bluetooth connections, spoof devices, create BT serial tunnels, MITM BT traffic, pair without PIN via LMP spoofing. |
| Ethernet Router | Act as transparent gateway — ARP spoofing, DHCP server, NAT, HTTP/HTTPS interception, DNS poisoning, inject payloads mid-flight. |
| WiFi Clone | Scan and impersonate legitimate WiFi networks — create open rogue AP, capture credentials, inject payloads into unencrypted traffic. |
| Exploit Chain | Automated attack workflow — scan → enumerate → exploit → escalate → exfil. Link multiple modules into one-button full compromise. |
| Honeypot | Create fake services (SSH, HTTP, Telnet, MySQL) to trap and analyze exploits — log attack patterns, credentials, payloads, extract 0-days. |
| Universal Proto | Speak ANY protocol — HTTP/REST, gRPC, WebSocket, MQTT, CoAP, raw sockets. Auto-detect, parse, generate messages for any service. |
| IoT Swarm | Control smart home IoT — MQTT, CoAP, Zigbee, Z-Wave, Thread, LoRa. Discover devices, send commands, extract sensor data, control lights/locks/appliances. |
| Industrial SCADA | Speak industrial protocols — Modbus TCP/RTU, Profibus, OPC-UA, EtherCAT. Read/write PLC registers, control factory automation, HVAC, power systems. |
| Vehicle Comm | Vehicle diagnostics and control — OBD-II, UDS, KWP2000, CAN-FD. Read fault codes, unlock doors, disable alarms, reprogram ECUs. |
| Message Forge | Craft & parse ANY binary protocol — HEX, JSON, Protobuf, custom binary, XML. Build valid messages, inject payloads, fuzz protocols. |
42 modules total
Discover: Pin Scan, V-Sense, USB Enum, CAN Bus, Wizard
Sniff & Replay: UART Sniff, UART+, Protocol, Scope
Dump & Export: Bus Dump, Logger, Exfil
Analyse: Crypto Lab, MemSearch
Inject & Test: Injector, DefCred
USB Attacks: HID Inject, USB Gadget, JTAG USB, RNDIS, USB Sniffer
Network Exploitation: Ethernet Router, WiFi Clone, BT Dominator
Automation & Analysis: Polyglot, WiFi Dashboard, Exploit Chain, Honeypot
Universal Communication: Universal Proto, IoT Swarm, Industrial SCADA, Vehicle Comm, Message Forge
System: Theme, Settings
Heavy exploitation (authorized use only)
| Module | What it does |
|---|---|
| USB Shell | Interactive CLI over USB serial — read/write memory addresses, GPIO control, direct hardware access. |
| Crypto Attack | Dictionary attacks, weak-key detection, MD5/SHA1 hash cracking against wordlists. |
| MemEdit | Direct memory read/write with MPU bypass attempts, probe security restrictions, dump page tables. |
| Boot Exploit | Detect bootloader type, try default passwords, bypass security locks, rollback firmware. |
| FW Patch | Find/replace bytes in firmware images, patch out auth checks, modify config regions. |
| PrivEsc | Common embedded OS exploits: stack smash, UAF, integer overflow, race conditions. |
| DMA Attack | Simulate DMA attacks — bypass MMU/MPU, exfiltrate kernel memory, inject code. |
Look & feel
Boot splash with a sweeping-glow logo, CRT scanlines, a breathing menu cursor, wipe-in transitions, spinners and progress bars. Switch palettes any time in the Theme module.
Build & flash
Requires PlatformIO.
# set your lab Wi-Fi for the DefCred module (or edit defcred.cpp)
pio run -e cardputer \
-a "--build-property build.flags=-DCC_WIFI_SSID='\"MyAP\"' -DCC_WIFI_PASS='\"secret\"'"
pio run -e cardputer -t upload
pio device monitor
Controls
- Menu:
;up ·.down ·Enteropen - In a module:
`(backtick) back · per-module hints on the bottom bar
Layout
src/core/ shell, module interface, UI helpers, pin map
src/modules/ one file per recon tool
docs/ HARDWARE.md wiring + safety
See docs/HARDWARE.md before wiring — the S3 is a 3V3 part and 5V on a bare GPIO will destroy it.