#04 - How To Get The Firmware - Hardware Hacking Tutorial

  Рет қаралды 165,264

Make Me Hack

Make Me Hack

Күн бұрын

If you are struggling to get the firmware out of your device, this is the video for you!
In this video I will explain the possible ways we can use to to get the firmware of our IoT device.
I will do a practical example, of one of these possible ways. I will connect the PC to the UART of our sample device, I will analyze the boot log, I will access the command line interface of the boot loader, and I will dump the firmware, exploiting the dump command available in the boot loader. I will use a couple of scripts, do dump the entire EEPROM in an hexadecimal ASCII text file, and, then, to convert back this file in binary form to get the exact image of the EEPROM.
********* Links with additional Information
Channel's Author: www.makemehack...
Channel's Web Site: www.makemehack...
The sample router (Gemtek WVRTM-127ACN) on techinfodepot: en.techinfodepo...
The sample router (Gemtek WVRTM-127ACN) reverse engineered on GitHub, includes scripts to dump the EEPROM to a text file and to convert it back to binary file: github.com/dig...
TTL Serial Adapter (affiliate link): amzn.to/2vvzCYB
PuTTY, the terminal emulator: www.putty.org/
Wireshark, Ethernet analyzer: www.wireshark....
Curl, command line tool for transferring data with URLs: curl.haxx.se/
Wget, retrieving files with URLs: www.gnu.org/so...
Mitmproxy, a free and open source interactive HTTPS proxy: mitmproxy.org/
Bus Pirate: dangerousprotot...
OpenOcd, On Chip Debugger: openocd.org/
U-Boot, The Universal Boot Loader: www.denx.de/wi...
Buildroot, a simple, efficient and easy-to-use tool to generate embedded Linux systems through cross-compilation: buildroot.org/
Binwalk, a fast, easy to use tool for analyzing, reverse engineering, and extracting firmware images: github.com/ReF...
SOIC8 SOP8 Flash Chip IC Test Clips Socket Adpter BIOS/24/25/93/95 Programmer (affiliate link): amzn.to/39A9JFd

Пікірлер: 218
@mihaifelseghi
@mihaifelseghi 4 жыл бұрын
You sir are a human university, the best tutorials ever made, the most comprehensive and clear, keep up the good work, I am waiting for the next video in the series.
@MakeMeHack
@MakeMeHack 4 жыл бұрын
Hello Mihai Felseghi, thank you very much for your appreciation and support.
@Ravecat27
@Ravecat27 3 жыл бұрын
@@MakeMeHack Thank you for your Video, I need help! :( I think all my Devices have a malicous code, Smart TV, Monitor, Smartphone, Computer, Tablet, Xbox one, PS4...... They are all like radio controlled, they will be very fast hot, the sound will be quieter and quieter and the picture quality is worse, dark picture, even die Mini DAB Radio in the Kitchen have this malicous code, do you know about this malicous code?
@oscareriksson9414
@oscareriksson9414 5 ай бұрын
I am a programmer at a finance company, but was always interested in hardware, mostly from a software perspective. I started looking at this series about a year ago and it kick-started a burning interest in electronics and hardware hacking in general. Now my desk is overcrowded with bread boards, several chips and boards like raspberry pies, several arduinos of different types, standalone mc chips, avr and arm cortex and have started soldering stuff together with sensors etc etc. The wires are every where. Even spreding out to the living room! Now I have started looking into openocd and things to get to the bottom of the hardware communication things, saw this video series again and this time I understand wth you are explaining (in terms of technology) which makes me appreciate the video series even more. Grazie mille!
@shoaibraza1900
@shoaibraza1900 2 ай бұрын
How are you now?
@MattSimmonsSysAdmin
@MattSimmonsSysAdmin 4 жыл бұрын
I am totally loving this channel. Thank you for spending the time and effort sharing your knowledge. I have so many of your videos to watch!
@taterfpv
@taterfpv 2 жыл бұрын
This showed up in my feed today. I have no need to do any of this but I watched the entire video. You explain everything so well I just kept watching. Good job man.
@bysectrademark6729
@bysectrademark6729 2 жыл бұрын
This is perfect channel for all beginers in reverse firmware education and understanding what firmware works...Great job! Maybe in future we can send you some firmwares and you can make video from firmware analys this firmware.
@louieearle
@louieearle Жыл бұрын
This was a fantastic video - you have clear depth of knowledge, and you present better than almost every other hardware reversing video. I particularly like the context you give. So often presenters just show a wall of cryptic commands and output. You do a fantastic job in explaining.
@garypaulson5202
@garypaulson5202 2 жыл бұрын
Am really enjoying this video series, thank you! I also am an old man who learned Perl :)
@celebris3
@celebris3 3 жыл бұрын
Valerio, I really like the way you explain - detailed, clear and comprehensive, no shortcuts, no hiding details. Thank you for sharing your experience to us. I just discovered your channel, already subscribed and can't wait to watch from the beginning. Keep up the good work, I am sure this channel will grow up quick. (Y)
@GastoNet
@GastoNet 3 жыл бұрын
Ciao Valerio! You have the most instresting channel I've subscribed in my whole life! Keep the good work and stay safe.
@murrij
@murrij 4 жыл бұрын
like i said in my tweet earlier today, this whole series is awesome. you fill in the blanks on a lot of information that is all over on KZbin but not i none place. thank you.
@MakeMeHack
@MakeMeHack 4 жыл бұрын
Hi murrij, thank you very much for your continued appreciation and support.
@BobanZikic
@BobanZikic Ай бұрын
This is the best explained how to i have ever seen. Must go back to begging and to watch everything...
@WereCatf
@WereCatf 2 жыл бұрын
Just in case someone stumbles upon here: uboot often has the commands to dump the contents of any connected SPI NOR or NAND flash disabled. Also, e.g. Xiaomi likes to disable UART-input entirely for uboot and the installed OS, so none of this will work in that case and you will need to either access the flash directly, use JTAG or find a vulnerability for the installed OS that lets you get root access that way.
@ronwellman
@ronwellman 4 жыл бұрын
I was all smiles during this entire video. Your expertise shows through and this was the exact content I was looking for. I am excited to learn more. Thank you!
@baghdadiabdellatif1581
@baghdadiabdellatif1581 9 ай бұрын
😂 me too. God bless him
@TheMadMagician87
@TheMadMagician87 4 жыл бұрын
Fantastic video's, the density of information is incredible to me! Absolutely loving this series, and particularly this video so far, there are so many things I always wondered about in boot logs that you have addressed, it's inspiring me to learn more about all the other bits in there as well!
@markp5726
@markp5726 Жыл бұрын
Re: TSOP (at 7:31) - there are clips for chips like this available. They can be found by searching for something like "nand tsop clip" or "360 clip". Security researchers use them to find TOCTOU (etc) firmware security flaws.
@M.E63
@M.E63 Жыл бұрын
You can get tsop 48 clips, people used them before for Xbox 360 and ps3 etc but it’s not hard to remove one to read it and solder it back on the board
@EvilSapphireR
@EvilSapphireR 10 ай бұрын
​@@M.E63can you please provide any tutorial/video showing how it is done?
@M.E63
@M.E63 10 ай бұрын
@@EvilSapphireR I’ll try to do that
@EvilSapphireR
@EvilSapphireR 10 ай бұрын
@@M.E63 thanks man!
@papamidnightfpv
@papamidnightfpv 4 жыл бұрын
I have always wanted to get into hardware hacking. This video is great I hope you keep them coming.
@MakeMeHack
@MakeMeHack 4 жыл бұрын
Hello Isaiah Newman, thank you for your appreciation and support. I plan to continue with this series and with this channel. My original ambition was to release a video each week, but in reality, I need more time, so, on average I will release a new video every 10/14 days.
@HiHi-le3ev
@HiHi-le3ev 4 ай бұрын
Плохо что я раньше не нашел вашь Ютуб канал . Мала кто расказывает и показывает так подробно как вы . Хорошего развития канала .
@edgeeffect
@edgeeffect 4 жыл бұрын
I am also an old man.... I haven't seen Expect or TCL for many years.... Expect was ("was", no..... "IS") wonderful for this sort of thing. In the past I ran "end of day" on our mainframe using something very much like expect and my manager thought it was "black magic". I want to go back and look at my old TCL scripts now.
@lindsay5985
@lindsay5985 2 жыл бұрын
Valerio, a genuinely informative video, packed with useful, advanced information that will inspire and spark the interest of tinkerers, young and old, everywhere. We all thank you for sharing so generously. For the feedback you asked for, I would encourage more use of text to display names and acronyms, because you naturally have an endearing strong accent and this could improve the clarity for a wider audience. I will definitely be learning from more of your videos. Subscribed.
@markusschnepf
@markusschnepf 2 жыл бұрын
Right after Super Mario, this is gonna be my 2nd favourite Italian
@gtpsic
@gtpsic 2 жыл бұрын
Fantastic video production. So fascinating. You did a great job. This was easy to follow and packed with so much info. Just fascinating
@anuradhapriyankara5226
@anuradhapriyankara5226 3 жыл бұрын
I have watched most of your videos and what can I say is your videos are fantastic and very informative. I am too an electronic engineer and I'm trying to reverse engineer a set top box these days. Your tutorials were very much helpful for me. I'm currently trying to extract the firmware using JTAG since I have successfully identified JTAG port using your tutorial. Keep up the good work! P.s- you have a nice accent too ;-) I like it
@baghdadiabdellatif1581
@baghdadiabdellatif1581 9 ай бұрын
Good for you, i am too electronic engineer What JTAG did you use?
@bosr
@bosr Жыл бұрын
I agree with the comments here. Thank you so much for sharing such amount of knowledge, in such a structured and brilliant way. We are lucky to have you. Gracie mille, from France.
@daanklem264
@daanklem264 Жыл бұрын
I teach this content and really appreciate your detail and precision! Pure gold!
@ThatNiceDutchGuy
@ThatNiceDutchGuy 2 жыл бұрын
Grazie mille per aver menzionato Expect! Era esattamente la lingua di cui avevo bisogno. Ti auguro il meglio!
@longtran12345678
@longtran12345678 6 ай бұрын
your video is gold, it slowly teaches me so many valuable knowledge, thank you so much. I feel luck to see your video even for the first time.
@callelewander6789
@callelewander6789 2 жыл бұрын
Mr. Giampietro, thank you for sharing your knowledge! You have some serious skills! I will share your material with my colleagues!
@mrsaizo0000
@mrsaizo0000 2 жыл бұрын
Subscribed, things like this is not only good to know, but can help you "modify" certain hardware..
@micmacha
@micmacha Жыл бұрын
I already loved binwalk, and I had no idea it could tell you about the entropy too!
@arkinzoodsma1510
@arkinzoodsma1510 Жыл бұрын
Hello sir I would really want to thank you for your awesome content! It's a real wealth of high quality hands on information coming from experience which you dont see often. Most of the time people make 1 short tutorial and thats itl. Also your english is very understandable and I would dare to say that its easier to follow than some native speakers. You really make an effort to speak clearly and it helps! Have you maybe thought about doing a patreon or something like that? I really hope that you will contineau producing videos!
@BreakinUpBuds
@BreakinUpBuds 3 жыл бұрын
Man I wish you were still making videos you are awesome thanks for what you did make.
@qbitsday3438
@qbitsday3438 Жыл бұрын
Sono indiano e adoro il tuo tutorial.Grazie mille!Mi iscrivo immediatamente! google helped me!
@baghdadiabdellatif1581
@baghdadiabdellatif1581 9 ай бұрын
this is the exact content I was looking for. Thank you. God bless you
@adriancoanda9227
@adriancoanda9227 Жыл бұрын
The dump is easy to reverse engineering intro would be awesome 👌
@GerardFuguet
@GerardFuguet 4 жыл бұрын
You are simply awesome, I hadn’t any idea how to do this and luckily I found you (seems most OpenWRT based routers uses same bootloader structure), I’m very happy to see how you manage your videos/explanations, it denotes you have passion for you work. This is great sir! :) Hope you are safe under these rare days, take care good man!
@MakeMeHack
@MakeMeHack 4 жыл бұрын
Hello Gerard Fuguet, thank you for your appreciation and support. And yes I and my family are safe, at home 🙂
@torftee2235
@torftee2235 4 жыл бұрын
This is just GREAT stuff, Valerio! Grazie mille from Germany!
@M.E63
@M.E63 Жыл бұрын
I understand lots of people can’t solder a TSOP 48 but it’s not near impossible like you say, I’ve done lots of them for tv boards
@stephanonyambo66
@stephanonyambo66 Жыл бұрын
IM IN LOVE WITH HARDARE ENGENEETIND AND REVERSE MODIFICATION with hacking enterferance
@biganguria
@biganguria Жыл бұрын
zio fai prima a parlare in italiano che capisco meglio hahah sei il migliore grazie per sti video
@ramazanciftci1770
@ramazanciftci1770 Жыл бұрын
Maestro mille grazie di Germania por cet seria di video informativo. It was very nice to see in practice things having thought about theoretically. As a thanks I will subscribe your channel for the first time after watching non stop 15 years KZbin videos.
@krzsn5382
@krzsn5382 Жыл бұрын
Great job, you're the best explain this topics... thanks for sharing your knowledge...
@cralx2k
@cralx2k 3 жыл бұрын
These series are gold... AMAZING
@jacobwalters9660
@jacobwalters9660 4 жыл бұрын
Great video. I am inspired to try and dump the firmware of my electric skateboard
@MakeMeHack
@MakeMeHack 4 жыл бұрын
Hello Jacob, thank you for your appreciation!
@murrij
@murrij 4 жыл бұрын
dude that would be cool.
@mostafaarabi4793
@mostafaarabi4793 3 жыл бұрын
You are a young excellent man.thanks.
@thealex7671
@thealex7671 10 ай бұрын
Amazing! You are genius, my friend, i'm gonna watch every your video! ❤❤❤
@marialetiziadigiampietro8423
@marialetiziadigiampietro8423 4 жыл бұрын
Very professional and inspiring video! Can't wait to see the next episode
@MakeMeHack
@MakeMeHack 4 жыл бұрын
Hello Maria Letizia, thank you for your appreciation and support. Next episode should arrive next week!
@stevecross9159
@stevecross9159 3 жыл бұрын
Valerio From the UK great teaching thank you.
@tamilelectronicsforbeggine1229
@tamilelectronicsforbeggine1229 Жыл бұрын
thank you very much for your detailed video script series sir. very useful and im grateful to you
@StefanSonesson
@StefanSonesson Жыл бұрын
Mille grazie! (did I get that right?) fantastic information that got me grabbing cables and stuff. Now for the rest of your videos 😎🙏
@0xssff
@0xssff Ай бұрын
dude youre the best teacher ever
@serggorod1423
@serggorod1423 2 жыл бұрын
Отличный ролик! Время обновить инструменты!
@darkstareng
@darkstareng 2 жыл бұрын
Holio molio this is such an amazing guide. Leave it to a real engineer to know exactly what they're doing!
@jordan2869
@jordan2869 3 ай бұрын
I have a hisense 50U6HF tv (Amazon version) I have soldered RX,TX, GND to debug area and get output in serial console but when i try to interrupt boot to get to uboot it says lockdown mode? I get a shell with no ability to input any commands. How to bypass this?
@pablolopezcorona
@pablolopezcorona Жыл бұрын
Muy interesante la forma de codificar la informacion el los ruters desde el firware.
@mohelm97
@mohelm97 3 жыл бұрын
Thanks a lot, this is pure gold
@googlefuuplayad9055
@googlefuuplayad9055 2 жыл бұрын
20:41 😅😊😁👍👍 27:17 😊😁 31:50 wow. Thanks Thx 4 the vid
@BristlyBright
@BristlyBright 2 жыл бұрын
Thank you for this great video series! I really appreciate the knowledge you are sharing with others. Grazie mille!
@MiguelGuatemala
@MiguelGuatemala Жыл бұрын
Excelentemente EXPLICADO,!! gracias
@annag5458
@annag5458 3 жыл бұрын
Fabulous video on first principles
@TheRealKitWalker
@TheRealKitWalker 3 жыл бұрын
So very very useful. Thanks for sharing 👏👏👍👍✌️✌️
@matheuso86
@matheuso86 2 жыл бұрын
Sir, please, continue this awesome work!!
@johnSmith-mo5ne
@johnSmith-mo5ne 7 ай бұрын
A lot of thank for this useful guide. You are great!
@BehzadmozaffariTazehkand
@BehzadmozaffariTazehkand 3 ай бұрын
the best discusion that have ever seen
@wawandharmawan2441
@wawandharmawan2441 14 күн бұрын
Interesting video. Thanks for your explanation. Can you make Raspberry Pi Pico board as a tool to read/write firmware of CSR-BC417 Chip which is in cheap bluetooth module HC-05? I tried it but failed, and I don't know why.
@meowme7644
@meowme7644 3 жыл бұрын
impressive! instantly subbed 😉 very nice thank you👍👍 have a nice Domenica
@xEnergyShootx
@xEnergyShootx 2 жыл бұрын
questo video è un tesoro, complimenti
@TheRazgr1z1
@TheRazgr1z1 2 жыл бұрын
10/10 please dont stop CIAO !!!!
@Xindak
@Xindak Жыл бұрын
How to get firmware if i have only JTAG interface on board? On board i have small ic eeprom - this is all firmware of this board or in processor is another soft? I was looking channel like this about 1 year, i hope you turn back to making video!
@saurabhambulkar1
@saurabhambulkar1 3 жыл бұрын
Great ,information in the video....keep it up make those wonderful videos..
@ashfaquekhan7282
@ashfaquekhan7282 Жыл бұрын
"Great Teacher Valerio"
@BlensonPaul
@BlensonPaul 7 ай бұрын
great explanation, love you man. .
@MarcioSantosMarcio-D-Santos
@MarcioSantosMarcio-D-Santos Жыл бұрын
Thank you and you gained another subscriber, I would like to change the firmware of an Epson printer, but I don't know if it's possible, just looking to find out
@GianlucaRoccaGian
@GianlucaRoccaGian 3 жыл бұрын
Grandeee esattamente cosa voglio imparare ❤️❤️
@elcondor7627
@elcondor7627 Жыл бұрын
This is just hacking ASMR :)
@oscardowning9507
@oscardowning9507 Жыл бұрын
This man is a true legend
@rhodyrhckthaladro7840
@rhodyrhckthaladro7840 2 жыл бұрын
A very helpful video...
@rupioe582
@rupioe582 2 жыл бұрын
Very nice video you might have started a passion for hardware hacking ❤
@cybergen2K
@cybergen2K 4 жыл бұрын
Definitely deserves more subs! Grazi!
@vieiracastro82
@vieiracastro82 3 жыл бұрын
Thank you for share the World so much knowledge, is impressive you domain, congratulations!!!
@martinneff1681
@martinneff1681 4 жыл бұрын
Great Tutorial, pls keep it up. Your are a very good tutor.
@indian3197
@indian3197 Жыл бұрын
Hello Sir. I got a cable modem device. It has a black cable where one end of it is connected to the motherboard and the other end of the cable has an audio jack connector facing outside. Do you know which type of cable should I use to connect to this audio jack and my laptop?.
@030H
@030H 2 жыл бұрын
This is amazing. Thank you so much, I'm subscribing to your channel 👍
@Kingsize001100
@Kingsize001100 3 жыл бұрын
You are a genius. Keep making videos!
@bajwakamran5791
@bajwakamran5791 2 жыл бұрын
Very interesting and detailed information
@wilwad
@wilwad Жыл бұрын
You sir know what you are talking about thus I have subscribed
@emmyweed5827
@emmyweed5827 Жыл бұрын
A true artist
@MedicalStudentChannel
@MedicalStudentChannel 2 жыл бұрын
You are a perfect teacher !!!!!!!!!!!!!!!!!
@foxitize
@foxitize Жыл бұрын
In what cases can the firmware be dumped only by opening the chip and visually reading the rom under a microscope?
@Diablo-RED
@Diablo-RED Жыл бұрын
Salve è complimenti per il video su Github, ho letto la tua guida per sostituire il Firmware con uno Open Source ad un wvrtm-127acn ho un wvrtm-130acn volevo sapere sè la procedura è la stessa!? è sé il Dump dell Firmware è indispensabile ó si può saltare in quanto richiede circa 11 ore per il dump!? Grazie!
@Nick_Wine
@Nick_Wine Жыл бұрын
Sei un grande.
@drigogt
@drigogt 4 жыл бұрын
May I ask you a question: where is stored the UUID in a board? In the EEPROM? Is this usually a hash?
@ombudsman3821
@ombudsman3821 Жыл бұрын
Bravo. Molto interessante
@IdoSamuelson
@IdoSamuelson 2 жыл бұрын
Thank you. What are the options when there is not much data in uart boot beside "ERROR" , will appriciate help
@McKaktus259
@McKaktus259 3 жыл бұрын
Thanks for the video. I am currently trying to gain access to a system through UART. However, when I connect my UART-USB bridge, I can only see the output of the device (so baud rate seems to be correct) but cannot send any commands. I have checked the wiring and settings. Both TX and RX are connected to the MCU (I checked the traces). Do you have any idea other idea?
@bosr
@bosr Жыл бұрын
Thanks!
@testinasdlkfj
@testinasdlkfj 2 жыл бұрын
You can't sniff the router's WAN interface? What about creating a subnet using the target router connecting it's WAN interface to any LAN port on the primary router.
@riskydissonance
@riskydissonance 2 жыл бұрын
Loving the content, thank you!!!
@brontobytesdm9003
@brontobytesdm9003 2 жыл бұрын
I am thinking that when you speak in such a rhythm as Italian that it makes your brain sync and work better. So I am wanting to at least teach my person to be in a rhythm - well as I have been dancing a lot and have body rhythm.
@arthurbrazzle6854
@arthurbrazzle6854 3 жыл бұрын
I had to pause and make this comment @27:13....."1 byte = 3 chars (2 hex digits + space)" -> um no :P But everything else is impressive :)
@90daner
@90daner Жыл бұрын
bellissimo video mister!
#05 - How To Get The Root File System - Hardware Hacking Tutorial
33:20
#01 - Identifying Components - Hardware Hacking Tutorial
16:53
Make Me Hack
Рет қаралды 66 М.
How Strong is Tin Foil? 💪
00:26
Preston
Рет қаралды 98 МЛН
А ВЫ ЛЮБИТЕ ШКОЛУ?? #shorts
00:20
Паша Осадчий
Рет қаралды 8 МЛН
小丑妹妹插队被妈妈教训!#小丑#路飞#家庭#搞笑
00:12
家庭搞笑日记
Рет қаралды 36 МЛН
WORLD BEST MAGIC SECRETS
00:50
MasomkaMagic
Рет қаралды 50 МЛН
Extracting Firmware from Embedded Devices (SPI NOR Flash) ⚡
18:41
Flashback Team
Рет қаралды 575 М.
[016] IT9919 Hacking - part 1 - Reading firmware with flashrom
32:55
Hardware Hacking - UART Shell with FlipperZero & Buspirate !
23:08
AlrikRr - Ethical Hacking
Рет қаралды 534
DEF CON 24 - Hardware Hacking Village - Matt DuHarte - Basic Firmware Extraction
45:50
DEF CON Hardware Hacking Village
Рет қаралды 99 М.
#03 - How To Find The JTAG Interface - Hardware Hacking Tutorial
27:52
IoT Hacking - Polycom Conference Phone - Firmware Extraction
33:53
#02 - How To Find The UART Interface - Hardware Hacking Tutorial
23:47
How Strong is Tin Foil? 💪
00:26
Preston
Рет қаралды 98 МЛН