# NRF52 hack
---

---

---

---

---
是 **NRF**!,開心
型號 NRF5283
---
## 什麼是 NRF
### NordicSemi.com
---

---

---

---
## Reverse engineering
## Dump firmware
---

---

---

---

---

---

---
## Code Readout Protection
---

---

---

---

---
## NRF51 issue (2015)
by Include Security
---

---
**program counter** (pc)
就是 EIP (instruction pointer)
---
NRF51 的問題,當然 NRF52 修掉了
---
## Fault injection
---

---

---

---

---

---

---

---

---
## Todo
* reverse engineering dumped firmware
* porting dumped firmware
* pairing keys
* peripherals driver
* implement custom firmware
---
## Reference
* https://limitedresults.com/2020/06/nrf52-debug-resurrection-approtect-bypass/
* https://limitedresults.com/2020/06/nrf52-debug-resurrection-approtect-bypass-part-2/
* https://www.briandorey.com/post/echo-dot-3rd-gen-digging-deeper
* https://fccid.io/A5MKC-1957/Internal-Photos/Internal-Photos-4619942.iframe
* https://blog.includesecurity.com/2015/11/NordicSemi-ARM-SoC-Firmware-dumping-technique.html
* https://infocenter.nordicsemi.com/pdf/nRF52832_PS_v1.4.pdf
{"metaMigratedAt":"2023-06-15T18:17:40.854Z","metaMigratedFrom":"Content","title":"NRF52 hack","breaks":true,"contributors":"[{\"id\":\"a3283302-4fa2-4474-ace8-9e17aa848aea\",\"add\":2571,\"del\":495}]"}