Manual-trigger firmware toolkit for pentesting owned devices: - Pin Scan: UART/JTAG/SWD detection (baud est + IDCODE reads) - V-Sense: target voltage probe w/ logic-family guess - UART Sniff: passive capture + manual-only frame replay - USB Enum: ESP32-S3 host, read-only descriptor fingerprinting - DefCred: single-host factory-default login check, rate-limited Modular shell (core/ + modules/), PlatformIO build, hardware/safety docs. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AAhMHMRAQLQ9hSbBECKNfn
1.5 KiB
1.5 KiB
Hardware & wiring — read before probing
The Cardputer's ESP32-S3 is a 3.3 V part. Several targets you'll poke are not:
- Car OBD/USB, PC USB: 5 V VBUS.
- Some debug headers idle at 1.8 V.
Always go through protection. Never land a probe on a live target until V-Sense has told you the voltage.
Probe header
src/core/pins.h defines pins::PROBE[]. By default:
G1,G2— the side Grove connector (safe, use these first).G8..G13— StampS3 pads via a breakout ribbon (optional).
Minimum protection rig
| Signal | Between probe and target |
|---|---|
| Any GPIO in | 1 kΩ series + 3.3 V clamp (BAT54S to 3V3/GND) |
| V-Sense (G10) | resistor divider R1:R2 = 2:1 → 0–9.9 V range (ratio 3) |
| Level shift | bidirectional shifter (e.g. TXS0108) for 5 V buses |
Adjust pins::VSENSE_RATIO if you change the divider.
USB host
To use USB Enum the S3 must supply VBUS to the target as a host. Use an OTG adapter on the S3 USB port, keep the CDC console on the built-in USB, and never hot-plug a 5 V target onto a GPIO — it goes on the USB D+/D-/VBUS lines only.
Safety checklist
- Target powered from its own supply, common ground with the Cardputer.
- V-Sense the line first. If it reads ≥ 5 V, shift or stop.
- Start passive (Pin Scan / UART Sniff). Only replay/TX when you mean to.
- It's your device. Keep it that way.