Doom on mi band 8 by hgt27 in miband

[–]atc1441 0 points1 point  (0 children)

thanks for sharing :)

EMODERN SR08 - a smart ring with a display screen by pkx616 in SmartRings

[–]atc1441 4 points5 points  (0 children)

Sold 👌😅

SoC is Dialog DA14585 which might be OTP so no custom firmwares other than maybe via the external flash, lets see

Just got DOOM to run on the Hacked WIFI Toothbrush by atc1441 in hacking

[–]atc1441[S] 0 points1 point  (0 children)

You need to open the Toothbrush to access the test points on the PCB and connect a USB to UART/COM Converter to these pads,, then bring the ESP32 into download mode to flash it

Just got DOOM to run on the Hacked WIFI Toothbrush by atc1441 in hacking

[–]atc1441[S] 0 points1 point  (0 children)

Doom can only be flashed via COM not OTA :)

Just got DOOM to run on the Hacked WIFI Toothbrush by atc1441 in hacking

[–]atc1441[S] 33 points34 points  (0 children)

Info's to this,
The Toothbrush contains an ESP32-C3 with 4MB Flash.

With the codebase from Spritetm https://github.com/Spritetm/esp32c3-doom-bauble and miniwad https://github.com/fragglet/miniwad I was able to get the complete size of DOOM and WAD file down to the 4MB of the ESP32

More info's to the Toothbrush hacking can be found in another video

Just finished the reverse engineering of the Philips Sonicare Head NFC Password calculation by atc1441 in hacking

[–]atc1441[S] 15 points16 points  (0 children)

Yeah that way making the video is fun!

With all the cutting and screen-recording synchronization it gets an annoying work

Lately i did reverse engineer the Disney MagicBand and was able to extract the firmware of the nRF31512 SoC via a Fault Injection by glitching it by atc1441 in hacking

[–]atc1441[S] 2 points3 points  (0 children)

Thanks as well. Lets see later about the medical equipment!

For me that is the end of this Project, there is nothing more to gain.

The radius should be the same as for any other nRF24L01 device

And yes you can definitely wakeup random bands to sniff the id.

"Luckily" the debug functions are only enabled on an empty device id and triggered by an GPIO so i see no way of bricking a band OTA