Tag
The author details how they decrypted Flume water monitor MQTT traffic by extracting a static 32-byte key from flash and using libhydrogen secretbox parameters, revealing that no session keys are involved despite noise key exchange code in firmware.
A detailed walkthrough of rooting a TP-Link TL-841N router via UART, dumping firmware through two methods, and uncovering hardcoded credentials that persist even after a factory reset, highlighting common IoT security weaknesses.
The user used Codex to analyze the official firmware of a portable player, found it is an embedded Linux based on MIPS architecture, and discovered through decompilation that an HTTP service might have a vulnerability.
A detailed account of the first complete reverse engineering, documentation, and emulation of Fisher-Price Pixter devices and their games, covering hardware analysis, ROM dumping, and software emulation.
This blog post is the first part of a series on rooting an Arlo VMC2040 security camera, covering hardware examination, UART discovery, and initial bootloader analysis.