
moria
IoT firmware identification and extraction

IoT firmware identification and extraction

From UART to Root: Breaking Into the Xiaomi C200 via U-Boot

The C-based Firmware Patching Framework for Broadcom/Cypress WiFi Chips that enables Monitor Mode, Frame Injection and much more

Analysis and cleanup guide for BadBox malware on Allwinner H713 Android projectors: ADB access, infection proof, firmware backup, dropper removal,…

Research tools for MouseJack vulnerabilities in nRF24L01 wireless devices, including device discovery, packet sniffing, network mapping, and firmware…

Talk to your Intel Management Engine directly — zero-dependency Python tool. Finds memory leaks, partition manifest, live MKHI probing. First public…

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

Tenda Technology Co., Ltd NVR_4H: CH3 v2.1.V27.5.58.6 was discovered to contain a hardcoded cryptographic key.

This is a suite of tools/PoCs/exploits for cameras using the iCSee application. And yes - it can run NES games!

CVE-2025-50777: Root Access and Plaintext Credential Exposure in AZIOT Smart CCTV

Research on CVE-2025-3052, an Insyde firmware vulnerability that exposes an arbitrary write primitive capable of modifying security-critical pointers.

Quarkslab conference talks

Presented at Recon Montreal 2018

Tools for reverse engineering and interacting with the PowerG radio protocol

TROMMEL: Sift Through Embedded Device Files to Identify Potential Vulnerable Indicators

CVE-2024-46383

Live, system-wide USB transfer sniffer in eBPF — decodes USB traffic inline (control SETUP, SCSI, HID) from two universal URB hooks. No usbmon, no…

Extracts hardware random keys from NEC Aterm router firmware images and QR codes to generate valid passwords for gaining shell access.