- Universal Proto: HTTP/REST, gRPC, WebSocket, MQTT, CoAP, raw sockets - any protocol auto-detected - IoT Swarm: smart home control via MQTT, CoAP, Zigbee, Z-Wave, Thread, LoRa - Industrial SCADA: Modbus TCP/RTU, Profibus, OPC-UA, EtherCAT for PLC and factory automation control - Vehicle Comm: OBD-II, UDS, KWP2000, CAN-FD for vehicle diagnostics and ECU reprogramming - Message Forge: craft & parse any message format (HEX, JSON, Protobuf, binary, XML) with payload injection Brings toolkit to 42 modules. Cardputer can now communicate with virtually any device or system.
112 lines
8.1 KiB
Markdown
112 lines
8.1 KiB
Markdown
# Card-Crack
|
|
|
|
A manual-trigger hardware/network **recon toolkit** for the
|
|
[M5Stack Cardputer](https://docs.m5stack.com/en/core/Cardputer) (ESP32-S3),
|
|
built for **home-lab pentesting of devices you own** — your router, a car's
|
|
OBD/USB port, a PC, smart appliances.
|
|
|
|
> ⚠️ **Authorized use only.** Every tool here is scoped for your own bench:
|
|
> single targets you enter by hand, curated default-credential lists (not
|
|
> brute-force), rate-limited network checks, and read-only descriptor/ID
|
|
> reads. Nothing scans, transmits, or replays on its own — you press the
|
|
> action key. Don't point it at anything you don't own or run.
|
|
|
|
## Modules
|
|
|
|
| Module | What it does |
|
|
|-------------|---------------------------------------------------------------------|
|
|
| **Pin Scan**| JTAGulator-style detection of **UART / JTAG / SWD** pins on the probe header. UART baud estimation; JTAG & SWD IDCODE reads. |
|
|
| **V-Sense** | Live target-voltage probe through a divider; guesses the logic family so you know what you're touching before driving a pin. |
|
|
| **UART Sniff** | Passive UART capture (hex+ascii, selectable baud); freeze a frame and **replay it on a keypress** (manual TX only). |
|
|
| **USB Enum**| ESP32-S3 as USB host — reads **descriptors** (VID/PID, class, strings, config) to fingerprint an unknown device. Read-only. |
|
|
| **DefCred** | Checks a single host (default: gateway) against a short list of **factory-default logins** over HTTP Basic Auth. Stops on first hit. |
|
|
| **Bus Dump**| Reads **SPI-NOR (25-series)** and **I2C EEPROM (24-series)** chips on your own boards to `/dump/*.bin` on microSD. Read-only. |
|
|
| **Crypto Lab** | Offline analysis of a dumped blob: **Shannon entropy**, magic-byte **file-ID**, single-byte **XOR** brute, **AES-128-ECB** known-key decrypt. |
|
|
| **Exfil** | Browse the SD card and **stream a dump to the host** over USB serial as base64 (`base64 -d`); writes a manifest of what you pulled. |
|
|
| **Theme** | Live **UI theme switcher** — 5 palettes, saved to NVS, restyles everything instantly. |
|
|
| **CAN Bus** | OBD/automotive **CAN frame sniffer** — listen on MCP2515 over SPI, log frames to SD, cycle bus speeds. |
|
|
| **UART+** | Enhanced UART with **parallel auto-baudrate detection**, session logging to binary, protocol hints. |
|
|
| **Protocol**| Unified **UART/SPI/I2C sniffer** — real-time stats (packets/sec, data rate, frame errors). |
|
|
| **MemSearch** | Post-dump **binary analysis** — find strings, magic bytes, hardcoded IPs, entropy spikes in captured blobs. |
|
|
| **Logger** | **Persistent session logging** — auto-log to JSON with metadata (voltage, pins, targets, timestamps). Export logs. |
|
|
| **Injector**| **Manual credential/command injection** — AT commands, OBD-II queries, Telnet login attempts. Capture responses. |
|
|
| **Scope** | Simple **ASCII oscilloscope** — sample GPIO at ~100kHz, display waveform, spot edges and DC bias. |
|
|
| **Wizard** | **Two-wire protocol auto-detect** — sniff I2C/SWD on pin pairs, register read/write on found slave. |
|
|
| **Settings**| Persist configuration (scan delay, voltage thresholds, timeouts, baud list) to NVS. JSON export/import. |
|
|
| **HID Inject**| USB HID keyboard/mouse emulation — inject keystrokes, mouse clicks into any host that plugs in. Configurable payloads with 50ms inter-key delay. |
|
|
| **USB Gadget**| Emulate different USB device classes (mass storage, CDC/ACM, HID, RNDIS, MTP) to bypass host device filters and detection. |
|
|
| **JTAG USB**| Tunnel JTAG/SWD debug port to host over USB — expose Cardputer as USB debugger. OpenOCD/GDB-compatible. |
|
|
| **RNDIS** | Virtual ethernet over USB — assign 192.168.7.1 IP, DHCP server, pivot to host network for scanning/attacks. |
|
|
| **USB Sniffer**| Monitor and capture USB traffic from connected devices — filter by class, log packets with timestamps and hex payloads to `/logs/usb_*.log`. |
|
|
| **Polyglot** | Multi-language code generation — generate reverse shells, creds dumps, memory readers, keyloggers in Python, Bash, PowerShell, C, Go, Rust, Ruby, Perl. |
|
|
| **WiFi Dashboard** | Start web server on local network — stream all scraped data, logs, payloads to web UI accessible from phone on `http://192.168.1.1:8080`, download logs as .tar.gz. |
|
|
| **BT Dominator** | Force Bluetooth connections, spoof devices, create BT serial tunnels, MITM BT traffic, pair without PIN via LMP spoofing. |
|
|
| **Ethernet Router** | Act as transparent gateway — ARP spoofing, DHCP server, NAT, HTTP/HTTPS interception, DNS poisoning, inject payloads mid-flight. |
|
|
| **WiFi Clone** | Scan and impersonate legitimate WiFi networks — create open rogue AP, capture credentials, inject payloads into unencrypted traffic. |
|
|
| **Exploit Chain** | Automated attack workflow — scan → enumerate → exploit → escalate → exfil. Link multiple modules into one-button full compromise. |
|
|
| **Honeypot** | Create fake services (SSH, HTTP, Telnet, MySQL) to trap and analyze exploits — log attack patterns, credentials, payloads, extract 0-days. |
|
|
| **Universal Proto** | Speak ANY protocol — HTTP/REST, gRPC, WebSocket, MQTT, CoAP, raw sockets. Auto-detect, parse, generate messages for any service. |
|
|
| **IoT Swarm** | Control smart home IoT — MQTT, CoAP, Zigbee, Z-Wave, Thread, LoRa. Discover devices, send commands, extract sensor data, control lights/locks/appliances. |
|
|
| **Industrial SCADA** | Speak industrial protocols — Modbus TCP/RTU, Profibus, OPC-UA, EtherCAT. Read/write PLC registers, control factory automation, HVAC, power systems. |
|
|
| **Vehicle Comm** | Vehicle diagnostics and control — OBD-II, UDS, KWP2000, CAN-FD. Read fault codes, unlock doors, disable alarms, reprogram ECUs. |
|
|
| **Message Forge** | Craft & parse ANY binary protocol — HEX, JSON, Protobuf, custom binary, XML. Build valid messages, inject payloads, fuzz protocols. |
|
|
|
|
## 42 modules total
|
|
|
|
**Discover**: Pin Scan, V-Sense, USB Enum, CAN Bus, Wizard
|
|
**Sniff & Replay**: UART Sniff, UART+, Protocol, Scope
|
|
**Dump & Export**: Bus Dump, Logger, Exfil
|
|
**Analyse**: Crypto Lab, MemSearch
|
|
**Inject & Test**: Injector, DefCred
|
|
**USB Attacks**: HID Inject, USB Gadget, JTAG USB, RNDIS, USB Sniffer
|
|
**Network Exploitation**: Ethernet Router, WiFi Clone, BT Dominator
|
|
**Automation & Analysis**: Polyglot, WiFi Dashboard, Exploit Chain, Honeypot
|
|
**Universal Communication**: Universal Proto, IoT Swarm, Industrial SCADA, Vehicle Comm, Message Forge
|
|
**System**: Theme, Settings
|
|
|
|
### Heavy exploitation (authorized use only)
|
|
|
|
| Module | What it does |
|
|
|--------|--------------|
|
|
| **USB Shell** | Interactive CLI over USB serial — read/write memory addresses, GPIO control, direct hardware access. |
|
|
| **Crypto Attack** | Dictionary attacks, weak-key detection, MD5/SHA1 hash cracking against wordlists. |
|
|
| **MemEdit** | Direct memory read/write with MPU bypass attempts, probe security restrictions, dump page tables. |
|
|
| **Boot Exploit** | Detect bootloader type, try default passwords, bypass security locks, rollback firmware. |
|
|
| **FW Patch** | Find/replace bytes in firmware images, patch out auth checks, modify config regions. |
|
|
| **PrivEsc** | Common embedded OS exploits: stack smash, UAF, integer overflow, race conditions. |
|
|
| **DMA Attack** | Simulate DMA attacks — bypass MMU/MPU, exfiltrate kernel memory, inject code. |
|
|
|
|
## Look & feel
|
|
|
|
Boot splash with a sweeping-glow logo, CRT scanlines, a breathing menu
|
|
cursor, wipe-in transitions, spinners and progress bars. Switch palettes any
|
|
time in the **Theme** module.
|
|
|
|
## Build & flash
|
|
|
|
Requires [PlatformIO](https://platformio.org/).
|
|
|
|
```bash
|
|
# set your lab Wi-Fi for the DefCred module (or edit defcred.cpp)
|
|
pio run -e cardputer \
|
|
-a "--build-property build.flags=-DCC_WIFI_SSID='\"MyAP\"' -DCC_WIFI_PASS='\"secret\"'"
|
|
pio run -e cardputer -t upload
|
|
pio device monitor
|
|
```
|
|
|
|
## Controls
|
|
|
|
- Menu: `;` up · `.` down · `Enter` open
|
|
- In a module: <code>`</code> (backtick) back · per-module hints on the bottom bar
|
|
|
|
## Layout
|
|
|
|
```
|
|
src/core/ shell, module interface, UI helpers, pin map
|
|
src/modules/ one file per recon tool
|
|
docs/ HARDWARE.md wiring + safety
|
|
```
|
|
|
|
See **[docs/HARDWARE.md](docs/HARDWARE.md)** before wiring — the S3 is a 3V3
|
|
part and 5V on a bare GPIO will destroy it.
|