
lg-webos-kexec
Boots a custom Linux kernel on rooted LG webOS TVs via kexec, with reverse-engineered SoC watchdog support, framebuffer payloads, and an initramfs…

Boots a custom Linux kernel on rooted LG webOS TVs via kexec, with reverse-engineered SoC watchdog support, framebuffer payloads, and an initramfs…

UNISOC BootROM/FDL flasher for macOS: patched spd_dump with CVE-2022-38694 exec_addr2, protocol reference, partition rules, backup verification…

Exploit kit for Exynos 9830 bootROM that delivers signed-boot bypass, custom key injection, and memory-dump payloads for Samsung SM-G985F devices.

From a bare PCB to root: hardware-hacking a ZyXEL P-870HN (BCM6368) over UART — CVE-2025-0890 + CVE-2024-40891, on my own hardware.

Latency x-ray for undocumented hardware

The open-source wireless research platform for ESP32.

A very very very very very very very long interrupt

The C-based Firmware Patching Framework for Broadcom/Cypress WiFi Chips that enables Monitor Mode, Frame Injection and much more

SPI flash read MitM attack PoC

Bootloader exploit for Google Nest Hub (2nd Gen) (elaine)

Exploit writeups I've authored


Intel Management Engine JTAG Proof of Concept - 2022 Instructions

Firmware for a portable hardware hacking device with RFID/NFC, sub-GHz, infrared, and BLE support for wireless security testing and signal emulation.

Long Range Pager Systems pagers and coasters URH and YS1 (yardstick one / cc11xx) information and brute force tool

Active Bluetooth BR/EDR Sniffer/Injector as cheap as any ESP32 board can get. Works with Scapy ;-)

Curated hub of payloads, dumps, and guides for hardware hacking, RFID/NFC, sub-GHz, and wireless security experimentation.