atc1441 Profile Banner
atc1441 Profile
atc1441

@atc1441

Followers
13K
Following
5K
Media
1K
Statuses
4K

Hack the planet! my biggest passion is to run a custom firmware on as many devices as possible

Hamburg, Deutschland
Joined May 2019
Don't wanna be here? Send us removal request.
@atc1441
atc1441
3 days
DOOM on the ANKER Prime Charging station😅. This internal SWM34S MCU is just way too nice!.8MB RAM + 16MB Flash directly mapped to memory allow goes brrrr. Also on Youtube:
24
335
2K
@grok
Grok
1 day
Join millions who have switched to Grok.
21
21
170
@atc1441
atc1441
4 days
Dump successful 🥳
Tweet media one
2
3
46
@atc1441
atc1441
4 days
Debugger aquired, custom firmware runs🙌.Time to dump the firmware out of the 2€ Hörmann Remote clones SoC
@atc1441
atc1441
23 days
Aha! So something along the lines of CA51F55_FM on the SoC of the Hörmann remote Fob Clone. Checking out google with this information again turns up the wanted result 🥳 and even the strange pinout fits. Its an CACHIP CA51F551M2 8051 8KB Flash 768 Byte RAM SoC. Nice journey
Tweet media one
Tweet media two
Tweet media three
3
15
264
@atc1441
atc1441
5 days
That thing does not offer a simple teardown 🤣.At least everything still working and all flashes dumped!
Tweet media one
Tweet media two
0
0
13
@atc1441
atc1441
5 days
Quick teardown video of an Battery powered 4" LCD Screen Mirror device around 25€ from Aliexpress. TLDR: Main SoC is an HCSEMI C3100 which is very similar to the one used in the 20€ Handheld Console SF2000. Video Here:.
Tweet media one
Tweet media two
2
7
148
@atc1441
atc1441
7 days
Sooo Anker also has this stationary "Anker Prime A2345" Charger, it includes BLE as well, and FCC Shows it consists an ESP32-C3 as well as an Synwit SWM34S so technically that could finally run DOOM(Just low FPS)😅.
Tweet media one
Tweet media two
Tweet media three
@atc1441
atc1441
10 days
Fun fact 50% of the (Latest)Firmware in the.BLE Enabled Power Bank Anker Prime 27650mAh.is just to for OTA checking and encryption. Fw version prior to 1.6.2 do not verify OTA at all so better update😅. Did take a look inside and reverse engineered it.
Tweet media one
Tweet media two
Tweet media three
8
17
191
@atc1441
atc1441
7 days
Here is the "More".
@atc1441
atc1441
7 days
That's a success 🥳. Glitched and fully Dumped MSP430F417 in a non destructive way. Doing a Read data CMD and glitching the check if the password was entered we can dump 240bytes at once. By dumping the pass(vctr) area we can read the full flash after one glitch.@travisgoodspeed
Tweet media one
Tweet media two
Tweet media three
0
0
19
@atc1441
atc1441
7 days
@travisgoodspeed Some info's. It was important to separate DVcc and AVcc as much as possible to prevent resets and glitch on DVcc. All expect the last byte of the read CMD was send and the glitch timed to the last byte to prevent any big jitter. After position was found a glitch takes ~1minute.
0
1
7
@atc1441
atc1441
7 days
That's a success 🥳. Glitched and fully Dumped MSP430F417 in a non destructive way. Doing a Read data CMD and glitching the check if the password was entered we can dump 240bytes at once. By dumping the pass(vctr) area we can read the full flash after one glitch.@travisgoodspeed
Tweet media one
Tweet media two
Tweet media three
@atc1441
atc1441
27 days
Custom firmware on an Heat cost Allocator. No use but funny to look into it and its WMBUS RF Packets. Next step is to dump the stock firmware via the ages old Timing attack from @travisgoodspeed (MSP430F417)
Tweet media one
Tweet media two
3
17
192
@atc1441
atc1441
7 days
Nice 🥳.More on that later
Tweet media one
2
0
47
@atc1441
atc1441
9 days
More details now also in this Youtube video about the Anker Prime Power Bank Hacking:.
0
2
35
@atc1441
atc1441
10 days
In the latest Firmware 1.6.2 you have to press the button on the Power Bank to Add it to the Anker App which is good. Only that this is not enforced on the Power Bank and by using a custom tool you can bypass this completely and overtake any Anker Prime 27650mAh Power Bank.
Tweet media one
1
1
54
@atc1441
atc1441
10 days
Be careful out there😅.
Tweet media one
Tweet media two
@atc1441
atc1441
10 days
Fun fact 50% of the (Latest)Firmware in the.BLE Enabled Power Bank Anker Prime 27650mAh.is just to for OTA checking and encryption. Fw version prior to 1.6.2 do not verify OTA at all so better update😅. Did take a look inside and reverse engineered it.
Tweet media one
Tweet media two
Tweet media three
2
6
66
@atc1441
atc1441
10 days
No OTA signature bypass found so far 🥲 .But did create an WebBluetooth tool which allows you to connect to your Power bank and reads basic info's via the encrypted protocol. There is a potential bug which lets you set the OTA Size to uint32, read more about it in the GitHub Repo
Tweet media one
Tweet media two
Tweet media three
1
4
85
@atc1441
atc1441
10 days
Fun fact 50% of the (Latest)Firmware in the.BLE Enabled Power Bank Anker Prime 27650mAh.is just to for OTA checking and encryption. Fw version prior to 1.6.2 do not verify OTA at all so better update😅. Did take a look inside and reverse engineered it.
Tweet media one
Tweet media two
Tweet media three
20
124
1K
@atc1441
atc1441
10 days
Teardown of the nearly "All in One" Zigbee Sensor from Aliexpress:.Contains:.- Telink TLSR Zigbee/BLE SoC 512KB/64KB.- PHO XBR818 I2C 10G Move Sensor.- WHT20 I2C Humidity Temp Sensor.- Light Sensor.- Led.- Button. Just missing a Door sensor to be perfect^^
Tweet media one
Tweet media two
Tweet media three
Tweet media four
8
19
301
@atc1441
atc1441
13 days
0
9
0
@atc1441
atc1441
16 days
Digged into the Gantner ECO NFC Lock. The unlocked STM32L151 did give the Firmware and their Android MoLa App is nice to Reverse engineer still no Luck finding any holes😅. Learned a lot about NFC! The App will emulate an NFC Tag to configure incl. a both way Unique key Handshake
Tweet media one
Tweet media two
Tweet media three
Tweet media four
1
9
112