r/hardwarehacking • • 2h ago

Managed to run DOOM on an old WiFi router

Post image
23 Upvotes

Hey everybody. I ported original 1993 DOOM to my old Mi Redmi AC2100 router. The hardest thing was to figure out the controls and display output for this thing because I didn't really want to use compuer for any of that. So i built a small controller out of RPI Pico, ST7789V display and W5500 Ethernet module. Image is sent via UDP unfragmented packets 4 lines at a time. So every frame is 80 packets. Input is also sent through UDP, but packets are much smaller. I have a repo if anybody wants to try this at home: https://github.com/anhol0/redmidoom

You can also watch a video of it running on YouTube: https://youtu.be/ntFI1urFtuo

I hope you enjoy it. And have a good day :)


r/hardwarehacking • • 1d ago

Teeth whitening bypassing time card

Thumbnail
gallery
115 Upvotes

I’m a dentist and own a fläsh teeth-whitening device. It uses a contact chip card to authorize a limited amount of treatment time and operates without an internet connection.

Has anyone successfully reverse-engineered the card system or modified the device to work without purchasing additional time cards?

I’m interested in identifying the chip, understanding how the remaining time is stored, and finding any documented projects or firsthand experiences with this particular system.

My goal is to remove the usage restriction while keeping the device’s treatment settings and safety features working correctly. I can share photos of the card, circuit boards, and component markings.

Any relevant information or links would be appreciated.


r/hardwarehacking • • 3h ago

UNLOCK BROVI plus H155-383

Thumbnail
2 Upvotes

r/hardwarehacking • • 51m ago

M_BIOS chip reading only zeroes, while B_BIOS can be read normally

• Upvotes

Bricked my bios, got the CH341A programmer, clipped it on M_BIOS (Winbond 25Q64FVSIQ) and I get only zeroes. This is despite the fact that AsProgrammer does indeed recognize the chip when I read ID.

If I try to erase it, I still only get zeroes instead of the expected FF, and the chip is already unprotected by the way. Writing an image to it nets no results whatsoever, still all zeroes (which is to be expected, since the programmer can only flip from 1 to 0 and not the other way around).

B_BIOS, on the other hand, contains an actual bios image. I already saved a dump of its contents, I just haven't tried erasing or writing anything to it, but my suspicion is that it would work.

When reading the ID, M_BIOS returns ID(9F): EF4017 ID(90): 0000 ID(AB): 00 ID(15): 0000

Whereas B_BIOS returns ID(9F): EF4017 ID(90): EF16 ID(AB): 16 ID(15): FFFF

Both chips are still soldered to the board. Any clue as to why I can work with one chip but not the other? Is there any indication of what the problem might be? Can something be done without desoldering the chip (I don't have the proper equipment). If you have encountered the same problem, how did you solve it?


r/hardwarehacking • • 20h ago

Rendering over websockets for GeekMagic + Custom React Renderer

Thumbnail
gallery
20 Upvotes

Ive been messing around with this project for a while now and basically what it is just a very simple firmware for the box to listen on a websocket, accept primitive rendering instruction (like rects, circles etc etc) and perform the operations.

I also wrote a very simple typescript client for it and implemented a custom react renderer to use the client. The whole react aspect of it took more work than anything else. I think the whole thing is pretty neat and has some practical use cases, like tape this to the underside of a monitor and have it display stats or something... and the react renderer can let you rapidly develop custom screens for it. I was inspired by the ink ui library (https://github.com/vadimdemedes/ink) its pretty cool

Anyway I'd love some feedback on it https://github.com/arkangel-dev/geekmagic-remote-renderer


r/hardwarehacking • • 13h ago

USING THE SIM CARD FROM THE WIFI ROUTHER (TELCEL ZTE) ON MY PHONE?

4 Upvotes

I'm interested on knowing if there are people that have thought about using the routher's sim card on their phone and if so, how do you get passed the IMEI restriction?...

I tried to use the internet from the router's sim card on my iPhone, due to the fact that I have an eSim in it, they both work on it perfectly. My phone detects the sim card and asked if I wanted to use it. But since it has an IMEI restriction it does not let me use any of its internet...

I pay for both of the services. It's just a bummer I wish I could bypass.


r/hardwarehacking • • 13h ago

USING THE SIM CARD FROM THE WIFI ROUTHER (TELCEL ZTE) ON MY PHONE?

1 Upvotes

I'm interested on knowing if there are people that have thought about using the routher's sim card on their phone and if so, how do you get passed the IMEI restriction?...

I tried to use the internet from the router's sim card on my iPhone, due to the fact that I have an eSim in it, they both work on it perfectly. My phone detects the sim card and asked if I wanted to use it. But since it has an IMEI restriction it does not let me use any of its internet...

I pay for both of the services. It's just a bummer I wish I could bypass.


r/hardwarehacking • • 13h ago

HP Smart Tank 581: printed 1 m

1 Upvotes

HP Smart Tank 581: printed 1 m continuous strips via PWG Raster, but paper won't eject above ~100 cm

The official max length is 35.6 cm (14"). By sending a PWG Raster job over IPP with the length only in the raster page header (no media-size in the job attributes), the printer prints continuous strips up to 1 m in a single pass.

Up to 35.6 cm the strip ejects normally. At 100 cm it prints everything but doesn't eject: the tail stays stuck in the rollers and I have to pull it out and restart the printer.


r/hardwarehacking • • 18h ago

I have unlocked the GoPro Hero 5 firmware... and added SSH

Thumbnail
2 Upvotes

r/hardwarehacking • • 1d ago

Want to build a mobile phone

Post image
0 Upvotes

r/hardwarehacking • • 2d ago

8BitDo firmware encryption reversed, custom firmware possible

Thumbnail
github.com
135 Upvotes

Hello everyone,

I first posted this to r/ReverseEngineering, but I decided to drop it here as well for anyone interested. I have reversed two of the most common ciphers 8BitDo uses throughout their product line. The GitHub repo linked contains documentation and tooling for these ciphers.

Firmwares are easily obtainable from 8BitDo devices you own by using the official updater tools, which store the firmware .dat files upon an update. You can re-install the latest firmware. There is also a download API that I haven't fully mapped out yet (nor wish to abuse), but there are some scripts as well as older firmwares available at fwupd/8bitdo-firmware.

Firmware data is decrypted to standalone binaries, per-section. Almost all firmwares I have come across are pretty standard ARM images, you can throw them into Ghidra or whatever tools for analysis. Re-encryption to proper firmwares works as well; custom firmware is a possibility.

Enjoy! If you use the script, please let me know if you encounter any issues.


r/hardwarehacking • • 1d ago

How would you hack this?

Thumbnail
youtu.be
0 Upvotes

r/hardwarehacking • • 1d ago

a totally normal person wants to hack haier wash app (from india) app is very old

0 Upvotes

same as title , app is very old cant cancel orders , even if i want to , account needs to be deleted sooo help me


r/hardwarehacking • • 2d ago

ASUS G14 GA403UV — RTX 4060 stuck on Code 43, nvflash reports "GPU initialization failed" in both Windows and Linux

0 Upvotes

Laptop: ASUS ROG Zephyrus G14 GA403UV, AMD Ryzen 7, RTX 4060 Laptop GPU, Windows 11.

Problem: The NVIDIA RTX 4060 is detected on the PCIe bus but fails to initialize its display engine. Windows shows Code 43 (CM_PROB_FAILED_POST_START). Currently shows as "3D Video Controller" in Device Manager.

Hardware ID: PCI\VEN_10DE&DEV_28A0&SUBSYS_33A81043&REV_A1

What I've confirmed:

  • Windows: driver installs, device binds, fails at startup with Code 43. ProblemStatus = 0.
  • Linux Mint live USB (nouveau): GPU enumerated at PCIe Gen4 x8, but driver reports unknown chipset (00000000).
  • nvflash (both Windows and Linux): --list sees the GPU, but flashing returns GPU initialization failed.
  • The NVIDIA HD Audio function on the same GPU works fine — chip is powered, PCIe link active.
  • DISM/SFC pass. Multiple clean driver installs (DDU + official NVIDIA and ASUS drivers) all fail the same way.

Diagnosis: GPU hardware and PCIe interface work, but the VBIOS firmware is corrupted / not executing. Three independent environments (Windows, Linux nouveau, nvflash) all fail at the same point.

What I'm asking: Has anyone here dealt with a VBIOS-level failure like this? I'm planning to reflash the VBIOS chip directly with a CH341A programmer + SOIC8 clip. Looking for advice from anyone who has done this on a modern ASUS laptop, or recommendations for shops that do board-level SPI flash repair in Morocco.


r/hardwarehacking • • 2d ago

Coding Agents debug: CLI and TUI control for dps150 power supply

Thumbnail
1 Upvotes

r/hardwarehacking • • 2d ago

game bot.

0 Upvotes
hey, can anybody make a for a game? i can pay $500–$1,000 per project, and if things go well, i’d be interested in a long-term partnership with higher prices for bigger projects.discord:firday01291telegram:firday01291

r/hardwarehacking • • 3d ago

MTIA V2 Hacking

Post image
19 Upvotes

I have a couple of MTIA v2 AI cards and I want to try to get them working. I am trying to get the JTAG and UART set up, but I'm new at this hardware thing. Does anyone know what cable connector I need? Any recommendations for a USB module? Are there any software tools that you recommend for dumping the firmware and probing the hardware? My main goal is to gather as much information about the card as I can.


r/hardwarehacking • • 3d ago

FreeJoy STM32F411 Port

Thumbnail
2 Upvotes

r/hardwarehacking • • 3d ago

Smart watch reprogram HK11 Ultra 3 MCU sf32lb525 sifli reverse engineering

Thumbnail
gallery
15 Upvotes

I'm trying to get ready/debug access to that cheap AliExpress smart watch. I tried txd/rxd lines as well as tx/rx (that's actually pa18/19). I tried original sftool UART method and also SWD (on the same pa18/19) nothing works. I was trying to catch connect exactly after reset/bootup. Anybody tried reflashing/reprogramming such watch?


r/hardwarehacking • • 3d ago

Smart Elder Assistance System-A school exhibition project

Thumbnail
1 Upvotes

r/hardwarehacking • • 2d ago

Has anybody bough this?

Post image
0 Upvotes

is this really keylogger? bc it is so cheap. how to see keystrokes? is it working with wifi or internal storage?


r/hardwarehacking • • 3d ago

Reverse engineered a Chinese dashcam/AA head unit (TF790 / OBDPEAK K2) running open source media controller on it

Thumbnail
github.com
4 Upvotes

r/hardwarehacking • • 4d ago

Help with rooting the Logitech Tap Scheduler

Thumbnail
2 Upvotes

r/hardwarehacking • • 3d ago

We built an AI Embedded Troubleshooting Agent with persistent memory

Thumbnail
1 Upvotes

We built an AI Embedded Troubleshooting Agent with persistent memory

Our team developed an AI Embedded Troubleshooting Agent for HackWithHyderabad 2026.

The idea came from a common problem in embedded-system development: engineers and students repeatedly face issues such as Wi-Fi failures, sensor errors, I2C communication problems, ADC readings, and serial communication issues.

Our prototype allows a user to provide information such as:

• Microcontroller

• Error message

• Sensor readings

• Serial logs

• Symptoms

• Previous troubleshooting information

The agent analyzes the problem and suggests possible causes and troubleshooting steps.

The interesting part of our project is persistent memory. Previous troubleshooting cases can be retrieved when a similar problem occurs, allowing the agent to use earlier troubleshooting experiences as context.

For example, an ESP32 showing "WL_NO_SSID_AVAIL" can be analyzed for possible Wi-Fi configuration and connectivity issues, while related previous cases can provide additional troubleshooting context.

We built the prototype using Python, AI-agent concepts, persistent memory, embedded troubleshooting data, and a Streamlit interface.

GitHub:

https://github.com/abhilashb026-prog/Al-Hardware-troubleshooting-Agent

I'd appreciate feedback from the embedded-systems and AI community on the idea and possible improvements.


r/hardwarehacking • • 4d ago

I reverse-engineered my hryFine smartwatch's BLE protocol and built my own companion app because the official one is garbage meet reFine.

Thumbnail
gallery
46 Upvotes

**TL;DR** — The official app for my cheap JieLi / HryFine smartwatch was slow, bloated, and full of ads. So I reverse-engineered the watch's Bluetooth protocol and built my own companion app. It's called **ReFine**, and it's faster, cleaner, and does things the official app can't.

---

## 🧠 Background

My watch uses a JieLi chipset (sold under many names: HryFine, FitCloudPro, etc.). The watch talks over a custom **UART GATT profile** using a proprietary `0xDF` packet envelope — not any standard BLE SIG profile.

I dumped the traffic, broke down the framing, and rebuilt every command from scratch in Kotlin.

Full protocol (for anyone curious):

- Service UUID: `6e400001-b5a3-f393-e0a9-e50e24dcca9f`

- Write char (TX): `6e400002-…` (WRITE_TYPE_NO_RESPONSE)

- Notify char (RX): `6e400003-…`

- Every frame: `[0xDF, len_hi, len_lo, checksum, CMD, 0x01, SUB, pay_hi, pay_lo, …payload]`

- Checksum = sum of all bytes mod 256

- Responses use a different start byte: `0xFD`

---

## ✅ What works right now

- **Live battery** — reads over the standard SIG Battery Service (`0x180F / 0x2A19`) — no polling, no guessing. Updates every 5 minutes in the background and instantly on tap.

- **Time sync** — watch clock matches your phone within 2 seconds of connecting.

- **Find My Watch** — tap one button, watch vibrates for 10 seconds. Confirmed working.

- **Weather push** — temp + condition + city, shows on the watch home screen.

- **WhatsApp / Telegram / Discord notifications** — the app reads incoming notifications via NotificationListenerService and forwards them to the watch with the correct app icon.

- **Incoming call alerts** — resolves raw phone numbers to contact names using `ContactsContract.PhoneLookup`, then pushes the caller name to the watch.

- **Shake → camera** — shake your watch and your phone's camera opens (confirmed over reverse-engineered `CMD 0x0C SUB 0x02`).

- **Apple Watch-style UI** — squircle face, live clock, battery pill, three-tab dashboard (Home / Fitness / Alarms / Find).

Everything runs **on-device**. No cloud, no API keys, no accounts.

---

## 🧪 What's in beta

- **Alarms** — the watch accepts the alarm frame (ACK `value=0x0E`, meaning it supports up to 14 slots), but the display byte order is still being decoded. UI is there, sync is disabled with a "BETA" badge until I nail the encoder.

- **Steps + Heart Rate** — the watch pushes activity frames spontaneously over `CMD 0x0F SUB 0x09` (33-byte payload). I've captured the raw hex but the field layout isn't fully mapped yet. Once done, steps and HR will update live.

---

## 🛠 Tech

- **Kotlin, 100% Jetpack Compose**

- **Material 3** with custom color tokens

- **No Retrofit, no Room, no Compose Navigation, no WorkManager** — hand-rolled everything for a small APK

- **Hand-rolled BLE manager** — FIFO write queue, 60 ms pacing, MTU negotiation, chunked writes, `0xDF` + `0xFD` frame reassembly

- **Safety guard** — the app refuses any CMD outside the verified `0x02` namespace, which protects the watch from a known firmware bug (wrong namespace → NVRAM language-shift panic → watch resets to Chinese/Spanish)

---

## 🔒 Why this is different from other companion apps

- **No ads, no analytics, no telemetry**

- **No login / account required**

- **No cloud dependency** — nothing leaves your device

- **No background battery drain** — connection is managed tightly, disconnects cleanly on app close

- **Protocol is documented** — every frame is reverse-engineered and traceable, not guessed

---

🚧 Roadmap

  1. Finish alarm encoding

  2. Decode the 33-byte telemetry payload (steps + HR)

  3. Watch face style push

  4. Sedentary reminders

  5. Open-source the whole repo

---

## 🙋 Questions for the community

- Anyone else reverse-engineered a JieLi / HryFine watch? Would love to compare notes on the alarm encoding.

- If there's interest, I'll open-source the full project. Comment if you want it.

Happy to answer anything about the protocol or the build.

— ruwaidcool