# NRF52 hack --- ![](https://i.imgur.com/xgGvB8I.jpg) --- ![](https://i.imgur.com/w0FnPG7.png) --- ![](https://i.imgur.com/49Pjbom.jpg) --- ![](https://i.imgur.com/lRS7rb4.jpg) --- 是 **NRF**!,開心 型號 NRF5283 --- ## 什麼是 NRF ### NordicSemi.com --- ![](https://i.imgur.com/8TynOjn.png) --- ![](https://i.imgur.com/GvEAabC.png) --- ![](https://i.imgur.com/rBulCk5.png) --- ## Reverse engineering ## Dump firmware --- ![](https://i.imgur.com/gcI6g0v.jpg) --- ![](https://i.imgur.com/qt2rvrh.jpg) --- ![](https://i.imgur.com/ZE5egyZ.jpg) --- ![](https://i.imgur.com/ywzH8pC.jpg) --- ![](https://i.imgur.com/kXq4I9z.png) --- ![](https://i.imgur.com/kL2Sriv.png) --- ## Code Readout Protection --- ![](https://i.imgur.com/Q7Xtpau.png) --- ![](https://i.imgur.com/ATnRmPM.png) --- ![](https://i.imgur.com/NPOwEKm.png) --- ![](https://i.imgur.com/eaDBR4S.png) --- ## NRF51 issue (2015) by Include Security --- ![](https://i.imgur.com/wJRqbMK.png) --- **program counter** (pc) 就是 EIP (instruction pointer) --- NRF51 的問題,當然 NRF52 修掉了 --- ## Fault injection --- ![](https://i.imgur.com/U8h4hXu.jpg) --- ![](https://i.imgur.com/1jpeY0n.png) --- ![](https://i.imgur.com/bCcZaPY.jpg) --- ![](https://i.imgur.com/sDDreCE.png) --- ![](https://i.imgur.com/18ijb3V.png) --- ![](https://i.imgur.com/bha6G2O.png) --- ![](https://i.imgur.com/J06EY7i.png) --- ![](https://i.imgur.com/v3NTass.png) --- ## Todo * reverse engineering dumped firmware * porting dumped firmware * pairing keys * peripherals driver * implement custom firmware --- ## Reference * https://limitedresults.com/2020/06/nrf52-debug-resurrection-approtect-bypass/ * https://limitedresults.com/2020/06/nrf52-debug-resurrection-approtect-bypass-part-2/ * https://www.briandorey.com/post/echo-dot-3rd-gen-digging-deeper * https://fccid.io/A5MKC-1957/Internal-Photos/Internal-Photos-4619942.iframe * https://blog.includesecurity.com/2015/11/NordicSemi-ARM-SoC-Firmware-dumping-technique.html * https://infocenter.nordicsemi.com/pdf/nRF52832_PS_v1.4.pdf
{"metaMigratedAt":"2023-06-15T18:17:40.854Z","metaMigratedFrom":"Content","title":"NRF52 hack","breaks":true,"contributors":"[{\"id\":\"a3283302-4fa2-4474-ace8-9e17aa848aea\",\"add\":2571,\"del\":495}]"}
    289 views