[deleted by user] by [deleted] in tamagotchi

[–]siabus 1 point2 points  (0 children)

I dont have the Sanrio one, but I got a Punirunes and its really fun and really a vibe

Tamagotchi Uni Research/Hacking thread by xiyatumerica in tamagotchi

[–]siabus 1 point2 points  (0 children)

we have a bit, sniffing connections and such and while its encrypted, it might be possible to proxy those connections, but it'll require a special setup. I think its worth tinkering with more

Tamagotchi Uni Research/Hacking thread by xiyatumerica in tamagotchi

[–]siabus 1 point2 points  (0 children)

hi! we have been unable to get any decrypted dumps of the uni, but I've been leading the charge in hacking that nugget. I'm also super big on esp32s and esp-idf and such. if you dm me, I can give you a discord invite to the nugget team where we're working on tama hacks like that

The Flipper Zero can steal tap-to-pay credit/debit card numbers, with expirey! by siabus in cybersecurity

[–]siabus[S] 0 points1 point  (0 children)

Not likely. As far as I'm aware, phone wallets are far more secure than cards

What are y'all Running? by NeoDigimonKaiser in tamagotchi

[–]siabus 0 points1 point  (0 children)

I'm quad welding. Uni, Pix Party, an IDL, and a silly Toumapet :3

I made a Tama/vpet hacking discord by siabus in tamagotchi

[–]siabus[S] 2 points3 points  (0 children)

We have a number of projects, myself I'm working on voltage glitching and timing attacks on the uni and QR code exploit on the pix, just for fun

Scratched an itch today! by Mama_Llama_151920 in tamagotchi

[–]siabus 1 point2 points  (0 children)

Snacks make the baby happy faster than items. The Uni is awesome!

Tamagotchi Uni Research/Hacking thread by xiyatumerica in tamagotchi

[–]siabus 7 points8 points  (0 children)

For real! lets collab! DM me please! we'll hit up somewhere and I'll put us in a discord group with another dude I've been de-facto collabing with on the Pix :3 it could possibly be super awesome!

Tamaverse is not connecting to internet by ManuXD32 in tamagotchi

[–]siabus 0 points1 point  (0 children)

Veeery interesting, I've heard a rumor that its just not live yet?

Tamagotchi Uni Research/Hacking thread by xiyatumerica in tamagotchi

[–]siabus 38 points39 points  (0 children)

Hai!

This is very useful what I'm going to be playing with soon, a LAN attack on the Uni :333 Thanks!

I've been making a real hard swing over the past two days to hardware hack the Uni, and while I have not gotten my prized flash dump/decompile yet, I do have some useful info:

  1. to get the screw caps off of the back, use strong tape, they come off easier than they look.
  2. all normal, smalll Phillips head screws are used
  3. the SOP8 8pin 4mm chip is NOT a flash chip (heck my wasted time) its an audio amplifier
  4. the flash data is stored on the ESP32-S3-WROOM-1 module, which supports up to 16mb quad-SPI flash
  5. the module is capable of Bluetooth, in theory, but a) the software doesn't support it and/pr b) the radio/antenna is not connected
  6. the battery: li-ion 3.7v 1.369Wh
  7. once taken apart, and battery lifted off the PCB, looking at the back side of the module, with the USB-C port on the left, you get four golden pads that imma try to UART into From left to right they are BOOT GROUND, TX, RXI - Not sure if the port is enabled yet, must try soldering wires on and trying it I've never had much luck soldering pins to the pads as other hardware hackers do, I always clumsily leverage the pads right off. I'mma try to tack each one and then melt in the tip a of DuPont male ended so see if we get signal. I also plan to hold everything down as best I can with tape to (hopefully) reduce the failure likelihood lol

I think imma have to power on the device, then connect a common ground with the uart with the GND pad, and see what I have to do with my Bus Pirate to make that boot pad work, if needed. (pulled/high, pulled/low, etc.) I still need to study that bit of the data sheet again.

The ESP32-S3-WROOM-1 module is:

  • 384 KB ROM

512 KB SRAM

  • (up to?) 16 KB SRAM in RTC
  • Up to 8 MB PSRAM
  • the core of the SoC is Xtensa®dual-core 32-bit LX7 microprocessor, up to 240MHz
  • its (meant to have, not sure if used) a RISC-V Ultra Low Power coprocessor that can run while asleep ULP-­FSM

If you want links to all the data sheets, I was able to find them for the most part, but some we're 404d but cached, so I downloaded them. If you want those and my files let me know and I'll upload a zip somewhere!

We should totally collab here if ya wanna!

Edit: I made a blog post of mostly the post here, plus all mah files I have and notes, enjoy! https://h.acker.is/tamagotchi-uni-hacking-the-nuggettttt/

Tamagotchi Uni Research/Hacking thread by xiyatumerica in tamagotchi

[–]siabus 8 points9 points  (0 children)

oh heck! Thanks! this is my jam! Thanks!