
chipicopwn
Bootloader exploit for Google Nest Hub (2nd Gen) (elaine)

Bootloader exploit for Google Nest Hub (2nd Gen) (elaine)

The IoT Security Testing Guide (ISTG) provides a comprehensive methodology for penetration tests in the IoT field, offering flexibility to adapt…

Keystroke injection vulnerabilities in wireless presentation clickers

A yet non-offical neighbor for the GreatFet One targeting the 433/868/915MHz bands

Independent IoT security research, vulnerability disclosures, and PoCs focusing on firmware analysis, hardware interfaces, and cryptographic flaws.

A coordinated disclosure and security advisory on Fermax Intercom DTML Injection vulneraiblity. Special thanks to Fermax International for prompt…

From UART to Root: Breaking Into the Xiaomi C200 via U-Boot

BLE-based tool that automatically discovers and exploits Shining LED Masks by uploading a custom image without user interaction, proving security…

Firmware for getting a power trace of the behavior of the bluetooth module on the ESP32 when the ESP32 is sent the undocumented hci bluetooth…

A tool for performing MouseJack keystrokes injection attack.

Make the miko robot a free one

A repository that contains all the working PoC I have crafted for known CVEs, and details on any ongoing research I am currently doing (mostly Iot…

Reverse Engineering of the Shining App Mask

Command injection exploit for TP-Link Tapo C200 camera (CVE-2021-4045) providing root shell access via UART and reverse-engineered uhttpd binary…



对NETIS WF2409E路由器进行的一次完整硬件安全分析研究。通过对设备进行拆解分析、调试接口识别、固件提取等工作,记录了硬件分析的全过程、漏洞细节以及相应的安全建议,希望能帮助提高物联网设备的安全性。