Low-cost attacks on STM8 readout protection

published on
As part of my HC-12 hacking project I needed to acquire the firmware of an STM8 microcontroller that had readout protection enabled. I was long-time intrigued by fault-injection attacks, most recently triggered by this 35C3 Talk on PS2 Vita Hacking which used voltage glitching to overcome protection measures. From the STM8 reference manual: 4.5.1: Readout protection Readout protection is selected by programming the ROP option byte to 0xAA. When readout protection is enabled, reading or modifying the Flash program memory and DATA area [using the SWIM debug interface] is forbidden. Read More...

Viomi Firmware Update Analysis

published on
After rooting the Viomi V2, the question arises whether it’s safe to perform a firmware update. So we look at the filesystem diff and some of the binaries. New in 3.5.3_0045 Looking at the diff comparing 0045 with the 0044 firmware, we see some minor changes to the base system. Looking at the changes in RobotApp we can infer changed features: new properties around lifetime of filter, brush or mop multimap management clean preferences management probably some improvements in area cleaning / navigation probably some work on dynamic obstacle detection (like doors) So performing the update to 0045 should be safe and preserve your root access. Read More...

Rooting the Xiaomi STYJ02YM (viomi-v7) Vacuum Robot

published on
microUSB port Opening the battery case My motivation to get root access is to have a talking and blinking robot that can move through my flat and is independent of any cloud. Whatever your reasons, so far it’s not supported by dustcloud, although I already added support to python-miio which allows to remote control most functionality through a python cli. Luckily, it turns out not to be too hard to get root access (all this is with the 3. Read More...

Programming the EPM240 devboard on Linux

published on
The supposedly simple task of programming a simple Altera CPLD took me a few days to resolve. Here’s what I learned. There’s no Open Source toolchain for Altera. So you must download the multi-GB Quartus Lite software. After installation, I followed the My First FPGA tutorial which mostly worked ok (apart from the ‘Megawizard Plug-in Manager’ thing). Pin mappings are of course different, but I found the schematic for the EPM240 minimal development board. Read More...

Verkehrsprojekt Deutsche Einheit Nr. 8: So ändern sich die Reisezeiten

published on
Reisezeitänderungen von München Dass die Verbindung München-Berlin schneller wird, haben alle mitbekommen, aber was heißt das für den Rest? Der Vergleich der alten mit den neuen Reisezeiten von München aus, macht einem sofort klar, dass das Verkehrsprojekt Deutsche Einheit seinem Namen alle Ehre macht. Praktisch jede Reise die in den neuen Bundesländern beginnt oder endet profitiert von schnelleren Verbindungen. Im folgenden eine interaktive Karte. Im Menü lässt sich einer von 8 Startbahnhöfen auswählen. Read More...


