serma-safety-security / hardsploit-gui-ruby

HARDSPLOIT GUI : The essential security auditing tool for Internet of Things devices you'll need in your toolbox
https://hardsploit.io
GNU General Public License v3.0
39 stars 8 forks source link

hardsploit-pen: a piece of hardware to make it even more easy #1

Open davidmann4 opened 8 years ago

davidmann4 commented 8 years ago

Hey I saw your CCC talk few days ago and just had an idea which I would like to share with you guys:

If you would make a pen which has all connections and maybe adjustable size (or adapters) your whole system could work solderless. Would even allow kids to use your tools :)

hk-esc-flashing-tool

maybe the pen has a button and when you click it it "sucks chip souls"

let me know what you think about this idea - I really liked your talk!

cheers,

David

julienmoinard commented 8 years ago

Hi David, First, thank you for your support and your advices.

"If you would make a pen which has all connections and maybe adjustable size (or adapters) your whole system could work solderless."

We have already a similar idea by using POGO pins like in your ESC programming picture (without plastic but rather by drilling a custom PCB). I use them (POGO pins) for Hardsploit testing purpose (after soldering process) or when I need to create a custom reader for SOIC memories or custom headers. But you can use for the moment for soic a probe like : cezdw or another offline reader (custom pcb board, or ZIF reader). But for TQFP it is not easy I have some mechanical troubles to put 64 pins in restrictive area with a good accuracy.

We work to propose soon I hope a reliable probe for the moment it is not perfect and it is not on an industrial process to provide a probe with each Hardsploit. For the moment it is complicated but the CEO (Yann Allain) says to me all the days :

When can I use Hardsploit with 1 button on the GUI and without soldering.

Trust me when a CEO want something he gets it !

Would even allow kids to use your tools :)"

It is the goal. We have another idea like OCR to avoid to enter the name on GUI :smile:

To be honest with you I had not thought to use a button on the probe and I think your have a very good idea in case you need dump lot of devices or you want to use all buses automatically :+1: Maybe we can use different binary code to detect the probe plug in on Hardsploit and with your button idea and OCR recognition system.

After some little change on FPGA, it is possible to trigger pushing button and read a binary hardcoded ( inside probe) identification probe code to know which protocol Hardsploit must use.

New procedure inspired by yours :

A kid or my CEO (:sunglasses:) can use Hardsploit to dump any devices supported by Hardsploit with 1 button on the probe it is better than our first idea thank you so much.
davidmann4 commented 8 years ago

pogo pins + drilling a custom PCB is genius - make sure to post an image when you have something ready.

julienmoinard commented 8 years ago

Sure