UI: - Theme engine (5 palettes) persisted to NVS; live Theme switcher module - Animated shell: boot splash, CRT scanlines, breathing menu cursor, wipe-in transitions, spinners, progress bars New recon modules: - Bus Dump: SPI-NOR + I2C EEPROM readout to microSD (read-only) - Crypto Lab: entropy, magic-byte file-ID, XOR brute, AES-128 known-key - Exfil: SD browser + base64 dump export over USB serial, manifest writer README updated with the new module table and look-and-feel notes. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AAhMHMRAQLQ9hSbBECKNfn
Card-Crack
A manual-trigger hardware/network recon toolkit for the M5Stack Cardputer (ESP32-S3), built for home-lab pentesting of devices you own — your router, a car's OBD/USB port, a PC, smart appliances.
⚠️ Authorized use only. Every tool here is scoped for your own bench: single targets you enter by hand, curated default-credential lists (not brute-force), rate-limited network checks, and read-only descriptor/ID reads. Nothing scans, transmits, or replays on its own — you press the action key. Don't point it at anything you don't own or run.
Modules
| Module | What it does |
|---|---|
| Pin Scan | JTAGulator-style detection of UART / JTAG / SWD pins on the probe header. UART baud estimation; JTAG & SWD IDCODE reads. |
| V-Sense | Live target-voltage probe through a divider; guesses the logic family so you know what you're touching before driving a pin. |
| UART Sniff | Passive UART capture (hex+ascii, selectable baud); freeze a frame and replay it on a keypress (manual TX only). |
| USB Enum | ESP32-S3 as USB host — reads descriptors (VID/PID, class, strings, config) to fingerprint an unknown device. Read-only. |
| DefCred | Checks a single host (default: gateway) against a short list of factory-default logins over HTTP Basic Auth. Stops on first hit. |
| Bus Dump | Reads SPI-NOR (25-series) and I2C EEPROM (24-series) chips on your own boards to /dump/*.bin on microSD. Read-only. |
| Crypto Lab | Offline analysis of a dumped blob: Shannon entropy, magic-byte file-ID, single-byte XOR brute, AES-128-ECB known-key decrypt. |
| Exfil | Browse the SD card and stream a dump to the host over USB serial as base64 (base64 -d); writes a manifest of what you pulled. |
| Theme | Live UI theme switcher — 5 palettes, saved to NVS, restyles everything instantly. |
Look & feel
Boot splash with a sweeping-glow logo, CRT scanlines, a breathing menu cursor, wipe-in transitions, spinners and progress bars. Switch palettes any time in the Theme module.
Build & flash
Requires PlatformIO.
# set your lab Wi-Fi for the DefCred module (or edit defcred.cpp)
pio run -e cardputer \
-a "--build-property build.flags=-DCC_WIFI_SSID='\"MyAP\"' -DCC_WIFI_PASS='\"secret\"'"
pio run -e cardputer -t upload
pio device monitor
Controls
- Menu:
;up ·.down ·Enteropen - In a module:
`(backtick) back · per-module hints on the bottom bar
Layout
src/core/ shell, module interface, UI helpers, pin map
src/modules/ one file per recon tool
docs/ HARDWARE.md wiring + safety
See docs/HARDWARE.md before wiring — the S3 is a 3V3 part and 5V on a bare GPIO will destroy it.