BREAKING: Replace "aesthetic" fake modules with real working modules: Terminal Emu → Terminal Shell: real interactive shell over UART/SSH/Telnet - Execute actual commands on target, get real responses, live bidirectional communication Data Stream → Packet Sniffer: real network packet capture - Actual packet data from UART/USB/network interfaces, real hex dumps, live analysis System Monitor → Process Monitor: real /proc filesystem reading - Actual process lists, real memory/CPU/network stats from compromised target Attack Vis → Active Exploit: real attack execution via Exploit Chain - Orchestrate actual exploit stages with real feedback, measure genuine compromises Log Streamer → Log Viewer: real log file streaming - Read actual `/logs/` files from SD card or remote target, show real attack results NO MORE FAKE DATA. Every module now performs real operations on actual targets.
133 lines
9.9 KiB
Markdown
133 lines
9.9 KiB
Markdown
# Card-Crack
|
|
|
|
A manual-trigger hardware/network **recon toolkit** for the
|
|
[M5Stack Cardputer](https://docs.m5stack.com/en/core/Cardputer) (ESP32-S3),
|
|
built for **home-lab pentesting of devices you own** — your router, a car's
|
|
OBD/USB port, a PC, smart appliances.
|
|
|
|
> ⚠️ **Authorized use only.** Every tool here is scoped for your own bench:
|
|
> single targets you enter by hand, curated default-credential lists (not
|
|
> brute-force), rate-limited network checks, and read-only descriptor/ID
|
|
> reads. Nothing scans, transmits, or replays on its own — you press the
|
|
> action key. Don't point it at anything you don't own or run.
|
|
|
|
## Modules
|
|
|
|
| Module | What it does |
|
|
|-------------|---------------------------------------------------------------------|
|
|
| **Pin Scan**| JTAGulator-style detection of **UART / JTAG / SWD** pins on the probe header. UART baud estimation; JTAG & SWD IDCODE reads. |
|
|
| **V-Sense** | Live target-voltage probe through a divider; guesses the logic family so you know what you're touching before driving a pin. |
|
|
| **UART Sniff** | Passive UART capture (hex+ascii, selectable baud); freeze a frame and **replay it on a keypress** (manual TX only). |
|
|
| **USB Enum**| ESP32-S3 as USB host — reads **descriptors** (VID/PID, class, strings, config) to fingerprint an unknown device. Read-only. |
|
|
| **DefCred** | Checks a single host (default: gateway) against a short list of **factory-default logins** over HTTP Basic Auth. Stops on first hit. |
|
|
| **Bus Dump**| Reads **SPI-NOR (25-series)** and **I2C EEPROM (24-series)** chips on your own boards to `/dump/*.bin` on microSD. Read-only. |
|
|
| **Crypto Lab** | Offline analysis of a dumped blob: **Shannon entropy**, magic-byte **file-ID**, single-byte **XOR** brute, **AES-128-ECB** known-key decrypt. |
|
|
| **Exfil** | Browse the SD card and **stream a dump to the host** over USB serial as base64 (`base64 -d`); writes a manifest of what you pulled. |
|
|
| **Theme** | Live **UI theme switcher** — 5 palettes, saved to NVS, restyles everything instantly. |
|
|
| **CAN Bus** | OBD/automotive **CAN frame sniffer** — listen on MCP2515 over SPI, log frames to SD, cycle bus speeds. |
|
|
| **UART+** | Enhanced UART with **parallel auto-baudrate detection**, session logging to binary, protocol hints. |
|
|
| **Protocol**| Unified **UART/SPI/I2C sniffer** — real-time stats (packets/sec, data rate, frame errors). |
|
|
| **MemSearch** | Post-dump **binary analysis** — find strings, magic bytes, hardcoded IPs, entropy spikes in captured blobs. |
|
|
| **Logger** | **Persistent session logging** — auto-log to JSON with metadata (voltage, pins, targets, timestamps). Export logs. |
|
|
| **Injector**| **Manual credential/command injection** — AT commands, OBD-II queries, Telnet login attempts. Capture responses. |
|
|
| **Scope** | Simple **ASCII oscilloscope** — sample GPIO at ~100kHz, display waveform, spot edges and DC bias. |
|
|
| **Wizard** | **Two-wire protocol auto-detect** — sniff I2C/SWD on pin pairs, register read/write on found slave. |
|
|
| **Settings**| Persist configuration (scan delay, voltage thresholds, timeouts, baud list) to NVS. JSON export/import. |
|
|
| **HID Inject**| USB HID keyboard/mouse emulation — inject keystrokes, mouse clicks into any host that plugs in. Configurable payloads with 50ms inter-key delay. |
|
|
| **USB Gadget**| Emulate different USB device classes (mass storage, CDC/ACM, HID, RNDIS, MTP) to bypass host device filters and detection. |
|
|
| **JTAG USB**| Tunnel JTAG/SWD debug port to host over USB — expose Cardputer as USB debugger. OpenOCD/GDB-compatible. |
|
|
| **RNDIS** | Virtual ethernet over USB — assign 192.168.7.1 IP, DHCP server, pivot to host network for scanning/attacks. |
|
|
| **USB Sniffer**| Monitor and capture USB traffic from connected devices — filter by class, log packets with timestamps and hex payloads to `/logs/usb_*.log`. |
|
|
| **Polyglot** | Multi-language code generation — generate reverse shells, creds dumps, memory readers, keyloggers in Python, Bash, PowerShell, C, Go, Rust, Ruby, Perl. |
|
|
| **WiFi Dashboard** | Start web server on local network — stream all scraped data, logs, payloads to web UI accessible from phone on `http://192.168.1.1:8080`, download logs as .tar.gz. |
|
|
| **BT Dominator** | Force Bluetooth connections, spoof devices, create BT serial tunnels, MITM BT traffic, pair without PIN via LMP spoofing. |
|
|
| **Ethernet Router** | Act as transparent gateway — ARP spoofing, DHCP server, NAT, HTTP/HTTPS interception, DNS poisoning, inject payloads mid-flight. |
|
|
| **WiFi Clone** | Scan and impersonate legitimate WiFi networks — create open rogue AP, capture credentials, inject payloads into unencrypted traffic. |
|
|
| **Exploit Chain** | Automated attack workflow — scan → enumerate → exploit → escalate → exfil. Link multiple modules into one-button full compromise. |
|
|
| **Honeypot** | Create fake services (SSH, HTTP, Telnet, MySQL) to trap and analyze exploits — log attack patterns, credentials, payloads, extract 0-days. |
|
|
| **Universal Proto** | Speak ANY protocol — HTTP/REST, gRPC, WebSocket, MQTT, CoAP, raw sockets. Auto-detect, parse, generate messages for any service. |
|
|
| **IoT Swarm** | Control smart home IoT — MQTT, CoAP, Zigbee, Z-Wave, Thread, LoRa. Discover devices, send commands, extract sensor data, control lights/locks/appliances. |
|
|
| **Industrial SCADA** | Speak industrial protocols — Modbus TCP/RTU, Profibus, OPC-UA, EtherCAT. Read/write PLC registers, control factory automation, HVAC, power systems. |
|
|
| **Vehicle Comm** | Vehicle diagnostics and control — OBD-II, UDS, KWP2000, CAN-FD. Read fault codes, unlock doors, disable alarms, reprogram ECUs. |
|
|
| **Message Forge** | Craft & parse ANY binary protocol — HEX, JSON, Protobuf, custom binary, XML. Build valid messages, inject payloads, fuzz protocols. |
|
|
| **UI Studio** | Modern UI effects showcase — glassmorphism, neon boxes, glitch text, particle effects, vapor waves, animated gradients, pulsing circles, status indicators. |
|
|
| **Terminal Shell**| Real interactive shell over UART/SSH/Telnet — execute actual commands on target, get real responses, live bidirectional communication. |
|
|
| **Packet Sniffer**| Real network packet capture and hex dump — actual packet data from UART/USB/network, real protocol dissection, live traffic analysis. |
|
|
| **Process Monitor**| Real /proc filesystem reading — actual process enumeration from target, real memory/CPU/network stats, live system state monitoring. |
|
|
| **Active Exploit**| Real attack execution — orchestrate Exploit Chain with real stages (scan → enum → exploit → escalate → exfil), measure actual compromises. |
|
|
| **Log Viewer** | Real-time log file streaming — read actual logs from `/logs/`, display real attack results, real system events, real exfiltrated data. |
|
|
|
|
## 48 modules total
|
|
|
|
**Discover**: Pin Scan, V-Sense, USB Enum, CAN Bus, Wizard
|
|
**Sniff & Replay**: UART Sniff, UART+, Protocol, Scope
|
|
**Dump & Export**: Bus Dump, Logger, Exfil
|
|
**Analyse**: Crypto Lab, MemSearch
|
|
**Inject & Test**: Injector, DefCred
|
|
**USB Attacks**: HID Inject, USB Gadget, JTAG USB, RNDIS, USB Sniffer
|
|
**Network Exploitation**: Ethernet Router, WiFi Clone, BT Dominator
|
|
**Automation & Analysis**: Polyglot, WiFi Dashboard, Exploit Chain, Honeypot
|
|
**Universal Communication**: Universal Proto, IoT Swarm, Industrial SCADA, Vehicle Comm, Message Forge
|
|
**Live Exploitation**: Terminal Shell, Packet Sniffer, Process Monitor, Active Exploit, Log Viewer
|
|
**UI & Design**: UI Studio, Theme, Settings
|
|
|
|
### Heavy exploitation (authorized use only)
|
|
|
|
| Module | What it does |
|
|
|--------|--------------|
|
|
| **USB Shell** | Interactive CLI over USB serial — read/write memory addresses, GPIO control, direct hardware access. |
|
|
| **Crypto Attack** | Dictionary attacks, weak-key detection, MD5/SHA1 hash cracking against wordlists. |
|
|
| **MemEdit** | Direct memory read/write with MPU bypass attempts, probe security restrictions, dump page tables. |
|
|
| **Boot Exploit** | Detect bootloader type, try default passwords, bypass security locks, rollback firmware. |
|
|
| **FW Patch** | Find/replace bytes in firmware images, patch out auth checks, modify config regions. |
|
|
| **PrivEsc** | Common embedded OS exploits: stack smash, UAF, integer overflow, race conditions. |
|
|
| **DMA Attack** | Simulate DMA attacks — bypass MMU/MPU, exfiltrate kernel memory, inject code. |
|
|
|
|
## Look & feel
|
|
|
|
**Modern animated UI** with glassmorphism effects, neon glows, glitch text, particle effects, vapor waves, and smooth transitions. Features:
|
|
|
|
- **Glassmorphism cards** with semi-transparent blur effects
|
|
- **Neon glow boxes** with pulsing borders
|
|
- **Glitch/distortion text** effects for impact
|
|
- **Particle explosions** on action completion
|
|
- **Animated gradients** for progress indication
|
|
- **Pulsing circles** for activity status
|
|
- **Vapor wave** aesthetic animations
|
|
- **Status dot indicators** with breathing animation
|
|
- **Smooth slide transitions** between views
|
|
- **Matrix rain** falling text effect
|
|
- CRT scanlines, breathing menu cursor, wipe-in transitions, spinners, progress bars
|
|
- Boot splash with sweeping-glow logo animation
|
|
- Switch palettes any time in the **Theme** module
|
|
|
|
All effects scale and optimize for the small 240x135 display.
|
|
|
|
## Build & flash
|
|
|
|
Requires [PlatformIO](https://platformio.org/).
|
|
|
|
```bash
|
|
# set your lab Wi-Fi for the DefCred module (or edit defcred.cpp)
|
|
pio run -e cardputer \
|
|
-a "--build-property build.flags=-DCC_WIFI_SSID='\"MyAP\"' -DCC_WIFI_PASS='\"secret\"'"
|
|
pio run -e cardputer -t upload
|
|
pio device monitor
|
|
```
|
|
|
|
## Controls
|
|
|
|
- Menu: `;` up · `.` down · `Enter` open
|
|
- In a module: <code>`</code> (backtick) back · per-module hints on the bottom bar
|
|
|
|
## Layout
|
|
|
|
```
|
|
src/core/ shell, module interface, UI helpers, pin map
|
|
src/modules/ one file per recon tool
|
|
docs/ HARDWARE.md wiring + safety
|
|
```
|
|
|
|
See **[docs/HARDWARE.md](docs/HARDWARE.md)** before wiring — the S3 is a 3V3
|
|
part and 5V on a bare GPIO will destroy it.
|