Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Hardware Hacking Cheatsheet — Hardware Hacking Cheatsheet | Kitploit
Tools/GitLabGitLab/myasnik/hardware-hacking-cheatsheet
Embedded Systems SecurityIoT SecurityHardware SecurityLearning & EducationCurated ResourcesFirmware Analysis
GitLabmyasnik/hardware-hacking-cheatsheet

Hardware Hacking Cheatsheet

Hardware Hacking Cheatsheet

View Repository
2215 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Hardware Hacking Cheatsheet

[[TOC]]

Disclaimer

  • I'm a noob who's trying to learn this type of things so maybe something could be not 100% correct
  • Sorry for bad english

Notes

  • Follow the easyest path first methodology
  • Sometimes you will need to solder stuff; here a quick and simple how to
    • You could have to solder wires directly on PCB vias (video)
      1. Scratch the surface of the PCB using a cutter until you can see the sparkling under the solder mask
      2. Scratch another time the surface using fiberglass pencil
      3. Clean the surface with some IPA and a cotton swab
      4. Apply a little bit of flux
      5. Tin the wire and solder
    • Notes
      • Always tin your soldering iron tip
      • Temperature: 250-350 C
      • Don't touch PCB with hands

Information gathering and first interaction

  1. Look at the label on the back of the device and find
    • Model name
    • Serial number
    • The society who branded the device (may not be the one who build it)
  2. Search on the internet using the information just gathered
    • Best websites containing information
      • TechInfoDepot
      • OpenWRT
    • Search for ..., this usually leads to a lot of information
      • FCC ID (reference website)
      • SOC name
      • Flash chip name and amount
      • RAM chip name and amount
      • Other possible information sources
  3. Open the device
    • Search for tutorials on how to open the device
    • Some devices could be glued to prevent opening, be gentle
    • Sometimes we have heatsinks that cover some part of the circuit, if possible remove it
  4. Identify components
    • To make circuit names more readable
      • Use cotton + alcohol, when alcohol is dried cover the circuit in chalk, then clean it; now circuit name should be readable
      • Use a magnifying glass
    • Search for information and datasheets on the internet about these components; if nothing is found try on chinese search engines
      • Baidu
      • Sogou
      • Haosou
    • IMPORTANT: finding a component that has VCC and GND well exposed is very useful
  5. Locate UART interface: more or less a TTY
    • Search on internet
    • Search on the PCB for GND, IN or RX, OUT or TX and VCC
    • Search for 3/4 pins on the PCB
      1. Find a reference to GND
        • Using previously found components
        • Usually metal plates are at GND
      2. Find a reference to VCC
        • Using previously found components
        • Search for capacitors, they usually have a point at VCC
      3. Test UART candidate pins filling the table below (bullet points are respectively each column of the table)
        1. Test UART pins resistance against GND (multimeter to resistance measurement, usually 200k)
        2. Test UART pins resistance against VCC (multimeter to resistance measurement, usually 200kOhm)
        3. Power up the device and test UART pins voltage against GND (multimeter to voltage measurement, usually 20V)
        4. Power up the device and DURING BOOT test suspected TX UART pin voltage against GND (multimeter to voltage measurement, usually 20V); if the voltage is oscillating then this pin is probably TX (because it's sending data)
        5. Power up the device and DURING BOOT test suspected RX UART pin voltage against GND (multimeter to voltage measurement, usually 20V); if the voltage is stuck at 0 then this pin is probably RX (because it's waiting to receive data)
        • Table

          PINGND resistanceVCC resistanceVNotes
          1
          2
          3
          4
          • Example

            PINGND resistanceVCC resistanceVNotes
            130kOhm0Ohm3.3VVCC
            24.7kOhm34kOhm3.3V1.6-3.3V on boot - TX
            3INFOhm (multimeter 1)INFOhm (multimeter 1)3.3V0V on boot - RX
            40Ohm30kOhm0VGND
    • Use Jtagulator
      1. Connect it to the computer (baud rate: 115200)
      2. IMPORTANT: H is the print help function, use it everywhere
      3. Connect board GND to Jtagulator GND, board pins 1,2,3 to Jtagulator channels 1,2,3
      4. V: set working voltage
      5. U: enter UART identification menu
      6. U: start identification
      7. Text string to output: default
      8. Starting channel: channel where we put the pin 1 of the board
      9. Ending channel: channel where we put the pin 3 of the board
      10. Ignore non-printable characters: Yes
      11. Done!
    • TODO: - Use BurtleinaBoard + Busside
  6. Connect through UART: use a serial adapter (UART -> USB) to connect to the board through a computer
    • Chosen serial adapter: FT232H + Focaccia Board
    1. Choose the appropriate voltage (3.3V or 5V), else the board or the serial adapter will be damaged
    2. Connect board RX to adapter TX and board TX with adapter RX
      • NOTE: usually connecting VCC pin is not needed
    3. Connect adapter to computer
      1. sudo lsusb to locate the adapter
      2. ls -lart /dev to locate all device files; our should be one of the last, usually ttyUSB0
      3. To access this device we must part of the dialout group (or be root), to check our groups groups $USER
      4. screen /dev/ttyUSB0 $BAUDRATE to attach to the TTY
        • $BAUDRATE can be one of the ones found here
        • Most common $BAUDRATE
          • 115200
          • 9600
          • 57600
          • 38400
          • 19200
        • IMPORTANT: if we fuck up $BAUDRATE we could see gibberish or also NOTHING
        • ctrl + a -> k -> y: close screen
    • If the RX pin seems not to work (you type and press return but noting happens) it could be that the "return" value is wrong: \r\n or \n?
      • To solve this use pyserial, python's library for serial communication, example:
        #!/usr/bin/env python3
        
        import serial
        
Download Tool