Showing posts with label Internet Security. Show all posts
Showing posts with label Internet Security. Show all posts

Monday, August 3, 2026

Using Launcher to select between Bruce Halehound Marauder and Ghost

I installed "Launcher" to select between Bruce Halehound Marauder and Ghost.

Its found at "https://bmorcelli.github.io/Launcher/webflasher.html"

This is a video about using "Launcher" https://youtu.be/CqeIo4jXe6A


Finding the ".bin" files for the SD card is not easy.  Here are the versions and date stamps of the ones that I found that worked. Now I realize that some of them do not give a version number!


Ghost does not include the version number.  Here is the location that I found and version that I used.


For the others I just searched my hard drive for the .bin files that I had previously downloaded.  If you can't find them I could post then to the internet somehow?

Saturday, July 4, 2026

Flipper Zero like RF hacking devices compared

Well I started off with a CYD, Cheap Yellow Display, then another then added a Bruce firmware update and now there are eight of them!

Three of them were built me me!  It was not easy.  A CYD is a much easier way to start out.


Then I wanted to try HaleHound, so I made my onn CYD to make all the taping into the circuits a lot easier than using a CYD and adding wires to it..

Now its up to 8 devices.  But all I use them for is for testing remote controls.


Starting from the left is a CYD with Bruce firmware and only one switch because you have to manually change the RF module on the back.
Then there is a CYD with Bruce with lots of switches so the modules do not need to be changed.
Then is the ESP DIV version 1 that uses an esp32 processor.
Then is the ESP DIV version 2 that uses a bigger esp32-S3 processor.
Next is my homemade CYD with Halehound software.
Next is a CYD equiped with Ghost firmware.
Last of all is a CYD with Marauder firmware.
In front of them is my FCFZ, Fully Compatable Flipper Zero.  But it does not work that well in spite of spending many hours on it trying to get it to work.

Comparing RF Devices

Firmware            Marauder Ghost   Bruce  HaleHound  ESP DIV2             

Version               1.4          1.9         1.15        3.6.1        1.7

WIFI                    4/29        7            15           8              7

BLE                     2/12        6            8             7              6

2.4 Ghz                -             -             3             6              2

Sub Ghz               -             -             10           7              3

IR                         -             -              4              -              3

RFID                    -              5            11            6              8

GPS                     -              2            2              1              2

Marauder has sub menu  items

HaleHound adds these:
     SIGINT (Signal Intelligence) – 7
     Radio Test! (Much needed for a DIY)
     Drone – 4 (Much needed these days!

The winners are:
For no soldering: Marauder
For soldering: its a tie between Bruce and Halehound

IF I MISSED FEATURES OR OPTIONS LET ME KNOW AND I WILL UPDATE THIS.

Here is a video comparing them:

Wednesday, May 27, 2026

HaleHound ESP32-DIV and CYD

I have been trying to get a ESP32-DIV running with an ESP32-S3 processor as is required.  So far, after days of trying, all I have is a blank screen.  I have also tried to make a FCFZ (Fully Compatible Flipper Zero) to no avail.  So, out of the blue, I thought I would try the HaleHound software to see what happens. https://github.com/JesseCHale  I was shocked as it worked on the very first try!  It uses an older ESP32 processor.  I did not expect it to work so I just set it up with jumper wires to test it.


Here is a back view of the jumper wires.  The touch screen was somewhat erratic.  I would like a CYD version with push switches for making selections.  

The screen wiring follows the CYD version but the touch screen uses different I/O pins.  In the schematic of the CYD version the touch screen shares three pins with the LCD thus freeing three pins for other stuff.  BUT THAT IS NOT CORRECT!

Here is a screen capture of the successful ESP32 programming screen.
THis is what the final version looks like


Here is the wiring that I used for the jumpers:

DISPLAY PIN  -  ESP32 PIN
---------------------------------
1. VCC - 3v3
2. GND - GND
3. CS - GPIO15
4. RESET     - EN
5. DC - GPIO2
6. SDI(MOSI)    - GPIO13
7. SCK - GPIO14
8. LED - 3v3
9. SDO(MISO)  - GPIO12      

TOUCH       -       ESP32 DIV   -  CYD
-----------------------------------------------
10 .T_CLK - GPIO25     GPIO25
11. T_CS         - GPIO33     GPIO33
12. T_DIN - GPIO32     GPIO32
13. T_DO     - GPIO35     GPIO39/VN
14. T_IRQ - GPIO34     GPIO36/VP

I have the ESP32-DIV-V1 keyboard working!  Here is the schematic for it:

This is the correction to the CYD schematic found everywhere on the Internet:


Here is the back and front view of the ESP32-DIV-V1 so far.  Next is to add the RF modules.



Here is a video about this device:




Tuesday, May 5, 2026

Building a DIY ESP32-Div

I am building a ESP32-DIV to further my collection of Hacking devices.  I am building it on proto boards so I can change it later if needed.  Why not buy the prebuilt models?  For one thing those short cables between the NRF24's and the antennas have a huge loss.  I want them to go directly to the antennas.  For another thing I do not have that kind of money laying around.

Here is my planned layout.  I am using both sides of the board so the sockets are glued in place.



The instructions to upload the firmware are not very clear.  Here are screen captures of what I found and hopefully I got the correct files? This is my setup screen, it is not correct, its missing th boot info.  Look up ARTFOR's instructions on YouTube his instructions work!



This is the instructions with my comments:

This is the text that appeared.  I do not know if it is correct!


After several days of trying to get this to work I concluded the probem is the LCD.  I searched the Internet and discovered that some ILI9341 LCD's are acturally ST7789 powered.  In fact I found an image of my exact same LCD and they had the same problem, it was a ST7789!
NO!  the problem was the instructions see ARTFOR on youtube for the correct instructions.

 Here are three projects that are on my desk.

Here are two documents I am working on
Here is the wiring chart for the ESP32-DIV

Here is the corrected Keyboard schematic:







Wednesday, December 20, 2023

Wireless Bridge CPE for a Link to another building

 I just installed a wireless bridge for a link to another building.  The distance was about 3/4 of a mile.  The results were excellent!  I had no knowledge of how to do this other than using repeaters to pick up internet from a house or two away.  This time I needed to reach a building that was a few blocks away.  

I used google maps to see if there was a straight shot between the locations.  Then I went up on the roofs but could not see all the way to the other end from either direction.  There was nothing visible in the way.  It was a narrow shot as some pine trees surrounded my house but there was a gap in just the right direction.  

I bought a model that has lots of LED's on the side to be able to troubleshoot any issues.  I installed the "A" unit on the roof of my house.  Then the "B" unit (You can change A to B with a switch) was installed on the building.  I was amazed at the results the signal level was 100%!  But there was no internet at the receiving end.  The issue turned out to be that I had two internet cables at my house with a union in the middle and lost a connection somewhere.  Switching to 100 foot exterior grade cables at both ends resolved that issue.

Here is the ad for the bridge on eBay:


This is the receiving unit.  I made a PVC rooftop mounting bracket to hold it on the peak of a roof.


This is the transmitting unit on the roof of my house.


Tuesday, May 22, 2012

How to locate infected computer with a UTM5 or UTM10

I have worked with a number of Firewalls over the years, but the Netgear UTM Series Firewalls are not easy to work with.  After several attempts to find what computer is trying to access an infected web site I made a printout so I could easily find my way there.

Select "Content Filter" set the date back one day and select "Download" to get a copy of the data. It opens with a spreadsheet and then you can look in there to see who the offending computer is.

Tuesday, October 25, 2011

Weather.com is toast, trashed maybe even hacked?

*** UPDATE *** turns out this is a local problem perhaps with our Netgear UTM10 firewall.  Computers connected ahead of the firewall have no problem with www.weather.com.

For some reason www.weather.com is not working and no one is reporting on the problem?  When you try to go to their web page in Firefox you get a "Toast Notification".  In Internet Exploiter it is just plain messed up.


Here is what it looks like in Internet Exploiter:

Wednesday, October 5, 2011

AOL Captcha Hell

When they make me head of Internet security, I have three changes that I will make:

1. BAN JAVA and thus eliminate over 90% of all web viruses.
2. Require logging in before being allowed to send email.
3. Delete all web sites that have a Captcha on them anywhere.

Come on Internet security people these captcha things are all a total waste of time........

OK so I am upset, I spent several hours in "Captcha Hell" trying to set up an AOL IM account.  Sure you say just click on the "Play sound" button?  That does not work either.  I went to YouTube and the sound for the computer is working just fine.  I downloaded the latest 30+ megabytes of Quick Time but there is still no Captcha sound.  I thought "Quick Time" had died a miserable death a long time ago and was buried right next to "Real Audio"?  Who on earth uses Quick Time and for what reason would anyone want to use such an archaic format??  Back at AOL IM, I must have created a half a dozen accounts that I cannot access because it never accepted my information and it never asked for the alternate email account to "send a password reset" to, so no that feature does not work either.  Has anyone at AOL ever tried to create an AOL account?  They would quickly discover "AOL Hell" its right next door to "Captcha Hell".

Good thing no one is asking me to be the head of Internet security, I would work on actually making the Internet safe again.  As I often say:
"The Internet used to be like going to the library to read a book, now its like walking through a mine field".  -Bob Davis

Wednesday, September 21, 2011

More WordPress attacks, some sort of CSS attack?

Notice below that Wordpress is in four of the top 10 Vulnerabilities that are currently under attack!


Note below that there is some sort of CSS attack going on against WordPress sites. I do not know what the CSS vulnerability is that they are trying to exploit. I wonder if going to a plug-in like "Really Static" would be advisable as it hides the Wordpress installation and serves normal HTML files instead?

Tuesday, September 20, 2011

More webmaster attacks

Monday morning I was greeted with about 80 emails from webmaster to myself. I was excited to see what I had written to myself! Needless to say it was all spam!


I made a few changes in Cpanel and they have all gone away. I decided to set it so that company email can only come from our companies IP address. So then here is my number 2 change that I will make when I become "web security czar", you should NEVER allow email to be sent without first logging in! Number 1 would be to BAN JAVA!

Wednesday, September 14, 2011

More Wordpress Attacks going on! Using TimThumb vulnerability

They are really going after the TimThumb vulnerability. There were over 80 attempts to hack one site using the vulnerability this month! I wrote my own version last year, and this year I discovered that TimThumb was still installed so I deleted it as we are not using it.


Here is another strange "insert strange data" attack going on. It looks like a long string of garbage but I am sure it means something to someone?


Now I am thinking of not using WordPress or using a "static" version of WordPress to avoid all vulnerabilities. The biggest problem with totally static web pages is that the search function would not work, it has to have a dynamic response. You can use Google site search to get about the same results.

Thursday, September 1, 2011

More WordPress Hacking / Attacks going on

They are at it again, trying to hack Wordpress. Notice that there were over 5,327 log in attempts to 38 successes.  We are using LoginLockDown, but its logs show nothing, even when I went into the SQL database.  I am not sure why it does not do a better job of tracking the bogus log in attempts?


Here they are trying to guess the theme and then inject a line of code.  Note the addition of "/wp-content/themes/theme name/temp/lots of garbage".

Tuesday, August 30, 2011

More Facebook Fake Freind Requests

They are back at it again.  Lots of spam that are actually a virus.  If you did not get the August 2011 or the 2010 Yearly invoice then you likely still got the fake Facebook messages as seen below:
If you take a close look at the picture above you will see that the link was blocked by the firewall. 

Tuesday, December 21, 2010

PHP website attacks

I looked at our logs recently and was surprised that the normal visitors had jumped from 250 a day to 550 on one day.  Then I checked the error log and found this:
It is a new web site attack targeting PHP and Wordpress.  The evidence is that the lines all end in "//scripts/setup.php".  They attempt to target your PHP version then your WordPress version.

Friday, October 29, 2010

Ban Java!

Some others are picking up on something I have been saying for years... "Microsoft reports 'unprecedented wave' of Java malware exploits"

Here is their link:
http://www.zdnet.com/blog/security/microsoft-reports-unprecedented-wave-of-java-malware-exploits/7474?tag=content;search-results-river


And here is their chart to back it up.