Skip to content

IoT & Hardware Hacking for Beginners – Learn Fundamenta… — Transcript

Beginner's guide to IoT and hardware hacking covering fundamentals, hands-on labs, and practical skills in over 9 hours by Andrew Bolini.

Key Takeaways

  • Understanding electrical engineering basics enhances hardware hacking skills.
  • Hands-on experience with tools like multimeters, logic analyzers, and UART is crucial.
  • Firmware extraction and reverse engineering are key skills for IoT security testing.
  • A general knowledge of Linux is beneficial for working with embedded IoT devices.
  • The course balances theory and practice, making it suitable for beginners aiming to advance.

Summary

  • Introduction by Andrew Bolini (Digital Andrew), an electrical engineer and cybersecurity trainer.
  • Course covers theoretical and practical aspects of electrical engineering and hardware hacking.
  • Hands-on sections include PCB analysis, multimeter use, logic analyzers, UART communication, and hardware reconnaissance.
  • Focus on protocols like UART and SPI for firmware extraction and analysis.
  • Includes reverse engineering firmware to identify vulnerabilities.
  • Course is available partially on YouTube and fully on TCM Security Academy with certification options.
  • Designed as a beginner's course to hardware and IoT hacking but may be intermediate level due to topic complexity.
  • Prerequisites include a general understanding of Linux, especially embedded Linux on IoT devices.
  • Emphasizes the importance of understanding electrical engineering fundamentals for effective hardware hacking.
  • Offers additional resources and certifications like the Practical IoT Pentest Associate (PIPA).

Full Transcript — Download SRT & Markdown

00:00
Speaker A
Welcome to the beginner's guide to IoT and hardware hacking on YouTube. If you are interested in learning about IoT and hardware hacking, then you are absolutely in the right place. We're going to get over to the course very shortly. But before we do, just a quick few items of note. First one is my name is Andrew Bolini. I also go as Digital Andrew and I am the creator of this course. I also have my own YouTube channel, Digital Andrew, that I will drop a link to down below where I'm going to be posting a lot of IoT and hardware hacking content and lessons in 2026. So check it out and if you are interested, make sure you are subscribed. The second thing is this is the YouTube version of the course which is in its entirety on TCM Security Academy. This YouTube version is going to cover the first approximately two-thirds of the course. So if you want to get access to the entire course and those last few sections, then go ahead and check out the TCM Security Academy. I will drop a link to it down below. You'll also get things like a certificate of completion when you complete the course as well. And then finally, we also have a certificate that goes along with this course called the Practical IoT Pentest Associate or PIPA for short. And if you are interested in challenging that or challenging yourself to take that, I will drop a link to all of the details about that down below. So, with that being said, let's actually hop over to the course now. I hope you enjoy it. Welcome everyone to the beginner's guide to IoT and hardware hacking. First off, thank you so much for choosing to take this course. I've got some really exciting material and I cannot wait to get started on it. Before we do, in this video, we're going to cover some of the standard course intro topics such as a brief introduction about myself, a little bit on the course curriculum, and then some of the course prerequisites. So, without further ado, let's get started with the intro. So to start just a little bit about me. My name is Andrew Bellini and my background is in electrical engineering. I have a bachelor's of engineering science focusing on electrical engineering and then more specifically specializing in wireless technology. I'm also a licensed professional engineer in Ontario, Canada. Throughout my career, I've worked as an electrical engineer working across many different industries including SCADA control systems and also embedded systems and electronics for the rail industry. I'm also a TCM student and I actually took the PH course many years ago when it was only available through Udemy and I actually now work as a cybersecurity technical trainer for a cybersecurity company where I train the employees. I generally go by Digital Andrew on my social media and that's how you'll see me in Discord. And the best way to get in touch with me if you want to reach out is through my LinkedIn which I've linked here. You can also reach me on Twitter and then I also have a website. Just a few quick non-technical details about me in case you're interested. I am a dad. I love to play guitar. I play in a band. So if you're any good at Osent, you can probably track me down there. And I also love the outdoors and fishing. Okay, so moving on. Let's take a look at the curriculum for the course. So we're going to begin with Electrical Engineering for Hackers 101. And this is going to be a mostly theoretical section of the course where we will learn about some of the most important fundamentals of electricity, electrical engineering, and electronics. In the second section of the course, we're going to take a hands-on look at PCBs, some of their characteristics and components, and then learn how to use multimeters. We'll then move on to the third section of the course which is a continuation of Electrical Engineering for Hackers where we will continue to learn about some of those fundamental theories of electricity, electrical engineering, and electronics. After that, we'll move on to a hands-on section where we learn about logic analyzers and how we can use those to measure and sniff out UART communication and in doing so learn about UART. We'll then move on to some hardware recon and OSINT where we'll take a look at the various recon we can perform on our hardware and then the additional information that we can find open source on the internet. After that we will hook up to the router with the UART shell that we found and we will actually do some live enumeration of our router. In the next section of the course, we're going to learn about SPI or Serial Peripheral Interface protocol and then we will actually use that protocol to extract the firmware off of the router and then we'll perform some analysis on that firmware. In section 8, we will then actually do some reverse engineering of that firmware and take a look at how we can start to look for vulnerabilities in it. We'll then do a quick course challenge and course wrap-up. Before we move on to the prerequisites of the course, I do just really want to quickly chat about why I've included some theory sections about electrical engineering and electronics in this course. So, one of the questions that I very frequently see asked about ethical hacking is, do I need to understand programming or learn how to program? And you know the answer to that or the one that I kind of think is the best answer is that you know you definitely don't need to fully understand programming or be a programmer to get into ethical hacking. However, you know the more you understand about programming, some of the fundamentals of it and actually, you know, being able to look at code and understand how that code functions, this is of course going to make you a much better ethical hacker and help a lot. So, of course, you know, if you're doing web penetration testing, then you don't need to know how to go and build out a website, you know, from the ground up and understand fully how to do that. However, you should be able to look at the code and have a good understanding of what it's doing. And this is the same for hardware hacking, or at least that's my belief. You don't need to be, you know, a full-fledged electrical engineer, fully understand electronics, or be able to design a circuit from the ground up. However, it's going to benefit you a lot if when you take a look at circuits, you get an idea of, you know, what is going on with that circuit and you're able to identify the different components. And that's why I have included the two theoretical sections on Electrical Engineering for Hackers. So if you are finding that these are too much, you know, like school, you just want to get to the hacking, then of course this course is yours to make what you want with it and you know, I would encourage you to then just move on to some of the hacking sections. But I do think that they will be really beneficial to you if you do want to in the future continue on with hardware hacking. With that being said, let's move on to the course prerequisites. So there aren't actually a lot of prerequisites for this actual course. I have listed it as a beginner's course and I do just want to quickly chat about that. What I mean by beginner is that this is a beginner's course to hardware and IoT hacking. Hardware and IoT hacking in itself is somewhat of a complex topic in that it covers a broad range of different underlying topics. So, you know, I would consider this to probably be like an intermediate level course if you're just looking at it, you know, from an outward lens. And then it's more of a beginner's hardware and IoT hacking course. So with that being said, I think it's going to be really beneficial for you if you have a general understanding of Linux because a lot of the IoT devices that we're going to be looking at and specifically the router that we're going to be working on this course are going to be running embedded Linux and then of course we're going to be...
00:13
Speaker A
shortly. But before we do, just a quick few items of note. First one is my name is Andrew Bolini. I also go as Digital Andrew and I am the creator of this course. I also have my own YouTube
00:27
Speaker A
channel, Digital Andrew, that I will drop a link to down below where I'm going to be posting a lot of IoT and hardware hacking content and lessons on in 2026. So check it out and if you are interested, make sure you are
00:43
Speaker A
subscribed. The second thing is this is the YouTube version of the course which is in its entirety on TCM Security Academy. This YouTube version is going to cover the first approximately twothirds of the course. So if you want
00:58
Speaker A
to get access to the entire course and those last few sections, then go ahead and check out the TCM Security Academy, I will drop a link to it down below.
01:09
Speaker A
You'll also get things like a certificate of completion when you complete the course as well. And then finally, we also have a certificate that goes along with this course called the practical IoT pentest associate or PIPA for short. And if you are interested in
01:28
Speaker A
challenging that or challenging yourself to take that, I will drop a link to all of the details about that down below.
01:36
Speaker A
So, with that being said, let's actually hop over to the course now. I hope you enjoy it.
01:44
Speaker A
Welcome everyone to the beginners's guide to IoT and hardware hacking. First off, thank you so much for choosing to take this course. I've got some really exciting material and I cannot wait to get started on it. Before we do, in this
01:58
Speaker A
video, we're going to cover some of the standard course intro topics such as a brief introduction about myself, a little bit on the course curriculum, and then some of the course prerequisites.
02:09
Speaker A
So, without further ado, let's get started with the intro. So to start just a little bit about me. My name is Andrew Bellini and my background is in electrical engineering. I have a bachelor's of engineering science focusing on electrical engineering and
02:23
Speaker A
then more specifically specializing in wireless technology. I'm also a licensed professional engineer in Ontario, Canada. Throughout my career, I've worked as an electrical engineer working across many different industries including SCADA control systems and also embedded systems and electronics for the
02:40
Speaker A
rail industry. I'm also a TCM student and I actually took the PH course many years ago when it was only available through Udemy and I actually now work as a cyber security technical trainer for a cyber security company where I train uh
02:55
Speaker A
the employees. I generally go by digital Andrew on my social media and that's how you'll see me in Discord. And the best way to get in touch with me if you want to reach out is through my LinkedIn
03:06
Speaker A
which I've linked here. You can also reach me on Twitter and then I also have a website. Just a few quick non-technical details about me in case you're interested. I am a dad. Uh I love to play guitar. I play in a band. So if
03:20
Speaker A
you're any good at Osent, you can probably uh track me down there. And I also love the outdoors and fishing.
03:27
Speaker A
Okay, so moving on. Let's take a look at the curriculum for the course. So we're going to begin with electrical engineering for hackers 101. And this is going to be a mostly theoretical section of the course where we will learn about
03:40
Speaker A
some of the most important fundamentals of electricity, electrical engineering, and electronics. In the second section of the course, we're going to take a hands-on look at PCBs, some of their characteristics and components, and then learn how to use multimeters. We'll then
03:54
Speaker A
move on to the third section of the course which is a continuation of electrical engineering for hackers where we will continue to learn about some of those fundamental theories of electricity, electrical engineering and electronics.
04:06
Speaker A
After that, we'll move on to a hands-on section where we learn about logic analyzers and how we can use those to measure and sniff out UART communication and in doing so learn about UART. We'll then move on to some hardware recon and
04:20
Speaker A
OSENT where we'll take a look at the various recon we can perform on our hardware and then the additional information that we can find open source on the internet.
04:30
Speaker A
After that we will hook up to the router with the UART shell that we found and we will actually do some live enumeration of our router.
04:38
Speaker A
In the next section of the course, we're going to learn about SPI or serial peripheral interface protocol and then we will actually use that protocol to extract the firmware off of the router and then we'll perform some analysis on
04:51
Speaker A
that firmware. In section 8, we will then actually do some reverse engineering of that firmware and take a look at how we can start to look for vulnerabilities in it.
05:01
Speaker A
We'll then do a quick course challenge and course wrap-up. Before we move on to the prerequisites of the course, I do just really want to quickly chat about why I've included some theory sections about electrical engineering and electronics in this course. So, one of
05:16
Speaker A
the questions that I very frequently see asked about ethical hacking is, do I need to understand programming or learn how to program? And you know the answer to that or the one that I kind of think is the best answer is that you know you
05:31
Speaker A
definitely don't need to fully understand programming or be a programmer to get into ethical hacking.
05:37
Speaker A
However, you know the more you understand about programming uh some of the fundamentals of it and actually you know being able to look at code and understand how that code functions this is of course going to make you a much
05:50
Speaker A
better ethical hacker and help a lot. So, of course, you know, if you're doing web penetration testing, then you don't need to know how to go and build out a uh website, you know, from the ground up and understand fully how to do that.
06:04
Speaker A
However, you should be able to uh look at the code and have a good understanding of what it's doing. And this is the same for hardware hacking, or at least that's my belief. You don't need to be, you know, a full-fledged
06:17
Speaker A
electrical engineer, fully understand electronics, or be able to design a circuit from the ground up. However, it's going to benefit you a lot if when you take a look at circuits, you get an idea of, you know, what is going on with
06:30
Speaker A
that circuit and you're able to identify the different components. And that's why I have included the two theoretical sections on electrical engineering for hackers. So if you are finding that these are too much, you know, like school, you just want to get to the
06:43
Speaker A
hacking, then of course this course is yours to make what you want with it and you know, I would encourage you to then just move on to some of the hacking sections. But I do think that they will
06:52
Speaker A
be really beneficial to you if you do want to in the future continue on with hardware hacking. With that being said, let's move on to the course prerequisites. So there aren't actually a lot of prerequisites for this actual
07:05
Speaker A
course. I have listed it as a beginners's course and I do just want to quickly chat about that. What I mean by beginners is that this is a beginners's course to hardware and IoT hacking.
07:18
Speaker A
Hardware and IoT hacking in itself is somewhat of a complex topic in that it covers a broad range of different underlying topics. So, you know, I would consider this to probably be like an intermediate level course if you're just
07:32
Speaker A
looking at it, you know, from an outward lens. and then it's more of a beginners's hardware and IoT hacking course. So with that being said, I think it's going to be really beneficial for you if you have a general understanding
07:44
Speaker A
of Linux because a lot of the IoT devices that we're going to be looking at and specifically the router that we're going to be working on this course are going to be running embedded Linux and then of course we're going to be
07:55
Speaker A
using uh Kali Linux as well as our attack machine. And then also you should have a basic understanding of penetration testing and some of those principles. So if you're not feeling brushed up on these topics enough then I
08:08
Speaker A
would suggest there's a very good uh Linux course in the TCM Academy that would go over everything that you would need to know. And then of course the practical ethical hacking course um by TCM Academy is also an excellent
08:19
Speaker A
precursor to this if you're not feeling brushed up on penetration testing. So then just the things that you do not need to know though is if you don't have any background uh in electrical engineering or knowledge of electricity
08:31
Speaker A
or electronics that's okay we'll cover all of that. You do not need to know how to use any of the tools that we're going to be using. So either software or physical. So things like the multimeter or the logic analyzer. We'll go over all
08:43
Speaker A
that. And then you do not need any specific knowledge on IoT devices. We will cover all of that. So that wraps up this video. I do have a couple of quick videos after this that go over some really important uh notices or topics.
08:57
Speaker A
So, I would really encourage you please watch those before moving on to the course. But that wraps up this video.
09:02
Speaker A
I'll see you over in the next one. Welcome everyone. So, this video I've just got a really quick notice to make about the TPLink router that we're going to be using uh in this course. So, if you're anything like me, you may have
09:13
Speaker A
gone ahead and bought these and you just want to open it up and check everything out. Uh, and that's all good to do, but I just want to quickly show you um one thing that I think most people will
09:21
Speaker A
throw away and we're going to try and keep uh in this course. So, this is not just your standard unboxing video. I just want to really quickly show you something. So, just going to open up the uh box here, actually.
09:32
Speaker A
And then, so inside of the box, there is. Let me just grab it. Should come with a power supply I've got here. And it's just in this baggie. So, I'll pull it out of the baggie.
09:44
Speaker A
Uh, and then you'll notice that the actual cable of the power supply, it's secured with this twist tie here. If I just hold up in front of the camera. Uh, yeah. So, this twist tie when you take this off. So, I'll just take it off
09:55
Speaker A
quickly right now. Just go ahead and, uh, hang hang on to this here. We're going to be using this later on in the course for kind of like a little bit of a hacky way to attach um, some of our
10:06
Speaker A
equipment if you don't want to do soldering. So, I suggest you hang on to this. I mean, if you throw it out, you can probably find these. They're easy to find, but just wanted to keep give you a
10:13
Speaker A
heads up. hang on to this. So that's all for this video. I'll see you over in the next one. Welcome everyone. In this video, we're just going to do a quick reminder about ethical hacking. So if you are familiar with ethical hacking
10:25
Speaker A
and this isn't your first fora or course, then this is something you're probably familiar with and this will just be a quick reminder for you. Uh and if you're not familiar with this, then definitely pay attention.
10:36
Speaker A
So, the first thing that I just want to go over or cover is that of course you should be following all of your local laws and regulations. And that, you know, nothing in this course is meant to violate any laws or regulations. Of
10:48
Speaker A
course, they do vary from region to region. So, make sure you're aware of your regional laws and regulations. And if you're in doubt about any of it, then those should take precedence over anything in this course. The second
11:01
Speaker A
point, this is a really important one, is that we should only be testing, practicing, and hacking on your own uh device. So, in this course, we're going to actually be focusing on IoT devices, and we're actually going to be working
11:14
Speaker A
on real physical IoT devices. We're going to be working on a router. And you should only target your own equipment or equipment that you have permission to test. And this is a really important one because with IoT devices, they are so
11:29
Speaker A
ubiquitous now. Um they're all over the place. A lot of times they can have uh weak security and you know gaps or things like that in them and it can be really tempting to even just poke around um on other people's IoT devices, either
11:43
Speaker A
your neighbors or things like that. And you know, you may think that you can easily get away with it, but the consequences for it are very real and they're very big. So it's not worth it.
11:53
Speaker A
only test and only work on and only practice on either your own device or one that you have specific permission to be testing on. So the next point I want to talk about is practicing responsible disclosure. So this course actually uses
12:07
Speaker A
a real world device for educational purposes. And because of that I'm not actually going to be showing any specific vulnerabilities on it. will just be using it for testing uh and showing techniques. But we're not going to be showing any vulnerabilities
12:20
Speaker A
because of course feel like if I were to show um any of those on this then they would need to then be reported and then patched and the firmware would be out of date already then by the time the course
12:32
Speaker A
starts. However, you know, if you are to uncover um any potential vulnerabilities either on the device that we're working on in this course or when you move on, you know, in your IoT and hardware hacking experiences and you work on
12:44
Speaker A
other devices, then I really encourage you to um practice responsible disclosure if you do come across any of those vulnerabilities. And if you're not sure how to do that, then just, you know, do a quick Google search. There's
12:55
Speaker A
lots of really good videos about how to properly do responsible disclosure. And then just as a final reminder and a catchall, you know, we should be responsible, ethical, and moral in all of our actions. And I think, you know,
13:08
Speaker A
those are just three really good things to follow. And, you know, if we follow those, then that's going to cover, you know, most of what we should be doing.
13:15
Speaker A
So, again, just a really quick reminder of how important these topics are and how important they are that you actually follow them throughout this course and in what you do. Thank you for watching this. That wraps up this video.
13:30
Speaker A
Welcome everyone to the first section of this course, electrical engineering for hackers 101. In this section of the course, we'll be taking a look at some of the key fundamental concepts of both electricity and electrical engineering.
13:45
Speaker A
We're starting out with these theorybased lessons to gain foundational knowledge that will be required to understand the topics and techniques we'll be covering in future lessons on hardware hacking. I've worked my best to condense these lessons into only the
14:01
Speaker A
most important and relevant topics that I learned during my electrical engineering degree along with the knowledge I needed on a day-to-day basis as an electrical engineer working with electronics.
14:13
Speaker A
The lessons in this section and the following 2011 section will get more practical as we progress and we'll have hands-on portions. Before you know it, we'll be directly applying the theory learned in actual hardware hacks. I'm excited to get started and we'll see you
14:29
Speaker A
over in the first lesson. Welcome everyone. Throughout this lesson, we're going to be working to answer the fundamental question, what is electricity? And what are the units that we use to measure and describe it?
14:43
Speaker A
In order to get started, we need to shrink things down all the way to the atomic level. And we're going to start our example by looking at a carbon atom.
14:51
Speaker A
At the center of the atom is the nucleus. And the nucleus is made up of two particles, protons and neutrons.
14:59
Speaker A
Protons are positively charged particles and neutrons are neutral. The protons and neutrons make up most of the mass of the atom and therefore stay close to the center in the nucleus. The amount of protons an atom has is a fixed number
15:14
Speaker A
and this number is actually what determines which element it is. For carbon, which has the elemental number of six, this means that it has six protons. Generally there will be the same amount of neutrons as protons.
15:26
Speaker A
However, this can differ. The third particle of the atom is the electron. Electrons have a negative charge and they are much much lighter than protons and neutrons. As such, they exist around the nucleus. And one way that we can describe how they move
15:42
Speaker A
around the nucleus is what we call orbits or shells. The negative charge on the electron is attracted to the positive charge of the proton and this is what keeps it in these shells.
15:54
Speaker A
This two-dimensional model of the atom with the electrons orbiting in shells is referred to as the Bore Rutherford diagram. I've put an asterisk here because I do want to note that this is not actually an entirely accurate model.
16:08
Speaker A
However, it is good enough for the understanding we need. So, these electrons, as we know, exist in these shells that orbit the nucleus. And each shell can hold a specific set amount of electrons. In the first shell, this is
16:22
Speaker A
two and in the second shell, this is eight. Unlike protons that are fixed to the atom, in some circumstances, electrons are able to move from atom to atom, either leaving an atom and joining another or in the opposite, an atom will
16:37
Speaker A
pull an electron from another atom. When this happens, the atom becomes what is called an ion. And an ion is a negatively or positively charged atoms.
16:47
Speaker A
It either has a surplus or deficit of electrons. In this example, we have what's called a cat ion because we have more electrons than protons and this gives the atom a negative charge.
16:59
Speaker A
The opposite of this is an annion. In this example, we have more protons than electrons and this gives the atom a positive charge.
17:08
Speaker A
This ability of electrons to flow from one atom to another and to also create positively and negatively charged atoms is the fundamental for electricity and how we are able to harness it. Let's take a look at how we can harness the
17:22
Speaker A
flow of these electrons for electricity. We'll start by looking at arguably one of the most common conductors and that is copper. You'll notice that copper only has one electron in its outer shell. This outer shell is called the
17:38
Speaker A
veence shell and the electrons in it are called the veence electrons. Copper's single veence electron is very loosely bonded to its nucleus and this makes it easy to travel from atom to atom. This makes it what we call an
17:52
Speaker A
excellent conductor. Atoms with this looser hold on their veence electrons allow them to move freely from one conducting atom to another.
18:03
Speaker A
If we add a second copper atom closely, we can see that the veence electron can easily move from one copper atom to the other. In fact, in a piece of copper that may have millions to billions of these copper atoms in them, this veence
18:18
Speaker A
electron just flows freely between all of the atoms. At this point, this does not constitute electricity though because we just have this random movement. In order to turn this into electricity, we need to be able to control the flow.
18:32
Speaker A
Let's now take a look at how we can harness this movement of electrons. If we take a look at the cross-section of a copper wire, which could be made up of millions to billions of atoms, we know that each of these atoms has veence
18:43
Speaker A
electrons that can fle freely flow from one to the next. If we are able to control this flow and have it move through the wire in a specific direction, then we can have a flow of electricity or an electrical
18:58
Speaker A
current. And this electrical current is a stream of charged particles, generally electrons, moving through a conductor.
19:05
Speaker A
And we measure this in amps. Now, you'll notice that I have the arrow for the electric current pointing in the opposite direction of the flow of electrons. This is not a mistake, and we'll chat more on this later. Of
19:17
Speaker A
course, at rest, we will not have this electrical current or flow of electrons in any meaningful direction. The movement of the electrons will be random. Let's now take a look at how we can control this flow of electrons.
19:31
Speaker A
In order to move the electrons, we need a force to push them. One great example is a battery. A battery creates a chemical imbalance in electric charges.
19:41
Speaker A
The fundamental rule of nature that opposites attract will cause the negatively charged surplus electrons to want to flow to the positive side of the battery. If we connect a conductor such as a copper wire between these that will
19:53
Speaker A
facilitate this, this negative charge will push the electrons through the wire. This imbalance of charges is what we call electrical potential difference.
20:06
Speaker A
And this is the difference in electrical potential between points and we refer to this as voltage. Commonly this is a buildup of charge and we measure this in volts. Now that we understand how we can control this flow of electrons, how can
20:20
Speaker A
we harness it for power? The movement of an electric charge causes energy to be transferred. If, for example, we just connected this battery with a copper wire, then most, if not all of this energy will just turn into
20:34
Speaker A
heat. This is actually a bad example in real life, and you'll most likely just cause a fire. This is what's called a short circuit. However, if we put an electrical component in the way like a light bulb, then this electrical charge
20:46
Speaker A
will be transferred into other useful forms of energy. In our example, light. We can describe this flow of charge through the circuit's ability to transfer into other meaningful forms of energy as electric power. The electric power is proportional to both the flow
21:03
Speaker A
of electrons and the charge imbalance that is pushing them through. As such the electric power is proportional to the voltage and current. So to calculate power we just multiply the voltage by the current. Now power is not to be
21:18
Speaker A
confused with energy which is a measurement of the amount of power delivered over time.
21:25
Speaker A
You remember previously I was chatting about how I had the arrow drawn backwards and that is because the conventional flow of electricity or how we refer to it is actually opposite to the flow of electrons. The convention for the flow of electricity is from
21:41
Speaker A
positive to negative charges. This may be a little confusing at the start and the reasoning for this is actually because when electricity was first being discovered it was thought that electrons flowed from the positive to negative charge and as such the convention of
21:57
Speaker A
drawing circuits with the electrical flow flowing from the positive charge to the negative charge was set as this direction. Later on it was discovered that electrons flowed in the opposite direction. However, this original convention was kept. In reality, it
22:12
Speaker A
doesn't actually matter that much as long as everyone agrees to use the same notation.
22:19
Speaker A
Of course, way back when we were discovering the atom, we could have just decided that protons would be a negative charge and the electrons would be a positive charge. It is all really relative. The last fundamental concept that we'll discuss now is that of
22:35
Speaker A
electrical resistance. So we know that the voltage pushes the electrons through a conductor which causes an electric current. But how much electric current does this voltage create? Of course, we do know that as we increase the voltage, the electrical current increases. The
22:52
Speaker A
amount of current that flows for a specific voltage is proportional to the resistance of the material that it is flowing through. In copper, we have an excellent conductor and there is very little resistance. Our light bulb though for example has much much more
23:07
Speaker A
resistance than copper and as such resists the flow of electricity. This resistance of the flow of electricity is what causes most of the voltage to be transferred over the light bulb and as such most of the power is transferred
23:20
Speaker A
into the light bulb as opposed to just being lost as heat in the wire. We call this electrical resistance. And the electrical resistance is the measure of an object's opposition to the flow of electric current. It's the opposite of
23:33
Speaker A
conductivity and we measure this in ohms. That wraps up this part of the lesson on our discussion about what electricity is, its fundamental properties, and the units that we use to describe it. We'll pick up in the next lesson talking about
23:49
Speaker A
what electricity is, and using a popular analogy comparing electrical flow to water. I'll see you in the next lesson.
23:58
Speaker A
Welcome everyone. In this first of three videos on electrical engineering fundamentals, we're going to take a look at how we can represent circuits with schematics. What resistors and voltage sources look like in these schematics and in real life. And then we'll wrap up
24:14
Speaker A
with the very first fundamental law of electrical engineering, ohms law. As a very quick recap from our last lesson, some of the key points that we learned about were voltage, which is caused by an imbalance of charge and
24:28
Speaker A
creates a pushing force for electrons through a circuit. This flow of electrons through the circuit is what we call electrical current. And as this electrical current passes over a resistance, it causes a voltage drop, which is turned into power. The power
24:45
Speaker A
can be calculated as the current multiplied by the voltage. This pictographic representation of the circuit that we have is not a very efficient one. So let's take a look at how circuits are commonly drawn.
24:59
Speaker A
Throughout the rest of this lesson, we're going to be drawing our circuits as schematics. Schematics are a visual representation of circuits. A few things to keep in mind about schematics. The wires in schematics are represented by the black lines.
25:14
Speaker A
These wires are what we call ideal conductors. This means that there is no resistance in them and therefore the length of these wires does not matter.
25:23
Speaker A
In fact, schematics are not to scale at all and they do not actually represent how the circuit is physically laid out.
25:30
Speaker A
We use many other symbols in schematics to represent different electrical components and throughout this lesson we're going to be looking at a couple of them. Let's start with how we are representing our voltage. You'll see here how we have V1 representing the
25:45
Speaker A
voltage drawn as a symbol with a circle and then a positive and a negative representing the polarity of each side.
25:52
Speaker A
A real life example of this would be a power adapter that plugs into the wall.
25:57
Speaker A
Here I have pictured the one that comes with our TPLink router. If you look at it closely, you'll notice that there is an output label and the output is for 9 volts. And then we have this symbol here
26:09
Speaker A
which represents direct current, something that we're going to talk about later. And then we have an amperage rating of 0.6 amps. What this output rating tells us is that this adapter operates at 9 volt. So its output is 9
26:22
Speaker A
volt. And then the current we see is not actually the current that's always supplied. This is just a maximum rating.
26:29
Speaker A
So the maximum current that can be supplied. Now that we know the voltage is 9 vol, let's work at trying to actually figure out the current. The first thing that we need to take a look at in order to do so
26:42
Speaker A
is actually the resistance. A resistor is represented in a schematic by the squiggly line that's drawn here.
26:50
Speaker A
In real life on a circuit, they may look something similar to the picture here.
26:54
Speaker A
However, they come in multiple packages. Resistors are one of the most common electrical components in circuits as they are essential to how we control the flow of electricity and can divide voltages.
27:08
Speaker A
For our example here, let's say that our resistor has a resistance of 100 ohms.
27:15
Speaker A
In order to calculate the current, we'll look at the first fundamental electrical engineering law that we're going to introduce in this lesson, which is Ohm's law. Now, Ohm's law states that the voltage is equal to the current time the
27:28
Speaker A
resistance. In this case though, we would like to calculate the current. Using a little bit of simple algebra, we can rework the formula so that it is I= V / R or current is equal to the voltage / the
27:44
Speaker A
resistance. If we plug in our numbers from the circuit, then we get that the current is equal to 9 V / 100 ohms.
27:53
Speaker A
Plugging this into our calculator, we'll get that the current is equal to 0.09 amps or another very common way to write this is as 90 milliamps. Resistors will commonly have a power rating that specifies how much power can safely be
28:08
Speaker A
dissipated across the resistor. If we surpass this power rating, then the resistor may catch fire. Let's look at how we can calculate the power that is dissipated across this resistor.
28:20
Speaker A
You'll recall that the power is equal to the current * the voltage. So in our case, this is equal to 90 milliamps * 9 vol, which is equal to 0.81 W.
28:33
Speaker A
Welcome everyone. In this second video of electrical engineering fundamentals, we're going to take a look at the second fundamental electrical engineering law, Kaw's voltage law. And then we'll take a look at series circuits. Before we move on to looking at the second fundamental
28:50
Speaker A
electrical engineering law, a quick reminder on conservation of energy. So because of conservation of energy, this means that we can't actually lose any electrons. So what that means is that the current is equal throughout an entire closed loop. In our circuit here,
29:07
Speaker A
I've drawn the flow of the current with red. And you'll notice that throughout the whole closed loop, this current is equal throughout the whole thing. the electrons have nowhere to go as they must remain in the conductor and as such
29:20
Speaker A
the flow is equal from one point to another throughout the entire circuit. With this in mind, let's take a look at our second fundamental law of electrical engineering. And that law is Kirchaw's voltage law. Now, Kirchaw's voltage law
29:35
Speaker A
says that the sum of all voltages across a closed loop circuit is equal to zero.
29:41
Speaker A
And in order to better demonstrate that, I'd like to talk about another schematic element. And that is the idea of circuit nodes. So a circuit node is a point or region on a circuit between two circuit elements. And I'll put one up here on
29:56
Speaker A
our schematic. So on our schematic, we actually have two nodes. The first one being right here as we have a joining connection between the positive end of our voltage supply and our resistor. and then the second one being the joining end of the
30:13
Speaker A
negative side of our voltage supply and the resistor. So what Kirchaw's voltage law means for this sum of all voltages across the closed loop circuit is zero is that if we go around this circuit, so you'll notice how I've drawn it here,
30:29
Speaker A
all of the voltages across this have to equal zero. So if we were to measure the voltage across this 100 ohm resistor, we know of course that it's going to equal 9 vol. Now you may be wondering how does
30:42
Speaker A
9 vol 9 vol equals 0. Well in this case using the convention of a current flowing from positive to negative when we have a current that flows through a voltage source. So from this positive to negative that means that this voltage is
30:57
Speaker A
an additive voltage. So we are adding 9 vol. Since the resistor is not actually supplying power rather consuming it, you'll notice that we have the polarity swapped. So this is from positive to negative. As the current flows from a
31:12
Speaker A
positive to negative, we actually have a voltage drop. So one way to write this would actually be as - 9 volt. Now commonly in circuits you won't actually see these voltages as positive and negative and instead you will see the
31:27
Speaker A
voltage source generally labeled as negative to positive and then elements that consume power it's just inferred that it's going to be this positive to negative. So one way that we could actually write this or look at it as
31:40
Speaker A
this is as + 9 vol and then this is as - 9 volt and it equals to zero which satisfies Kaw's voltage law. The next concept we'll chat about is that of a series circuit. So in a series circuit
32:00
Speaker A
components are connected end to end one after another in such a way that they create a single path for current to flow. So you'll notice in our circuit here that we have added an additional resistor but our resistance still is
32:14
Speaker A
equal to 100 ohms and this is because resistances in series can be added together and as such our current is still equal. However, our voltage will be divided amongst these two. Using Ohm's law, we can calculate that the
32:30
Speaker A
first voltage will be equal to 2.7 volt. And then we could either use Kirchaw's voltage law or Ohm's law to calculate that the next voltage will be 6.3 volt.
32:41
Speaker A
Of course, our 2.7 volts in 6.3 volt adds up to our 9 volt to satisfy Kaw's voltage law.
32:49
Speaker A
What happens in our series circuit if we add two voltage sources in series with each other? If we look at Kraw's voltage law, of course, we know that this is going to be 18 volts.
33:02
Speaker A
As our current travels through the circuit in our loop again, when it goes from this minus to positive and this minus to positive, we're going to add 9 volts twice. So, we get 18 volts again.
33:14
Speaker A
Of course, since we've doubled our voltage and our resistance has remained constant, then we know due to Ohm's law that our current will also have doubled.
33:27
Speaker A
Hello everyone and welcome to the third and final video on electrical engineering fundamentals. In this video, we're going to take a look at parallel circuits and Kov's current law.
33:39
Speaker A
We'll begin the lesson by looking at parallel circuits. Parallel circuits are opposite to a series circuit in that components are connected to each other in such a way that current has more than one path to flow. If we look at our
33:53
Speaker A
example circuit here, we can see that we have added an additional 100 ohm resistor in parallel. The current that leaves from our voltage source once it reaches the node here will be able to be split between the two resistors with one
34:08
Speaker A
path flowing through this loop and the other path flowing through the outer loop. Kchaw's voltage law still applies to both of these loops and as such the voltage drop across the outer resistor will still be 9 volt. If we take a look
34:24
Speaker A
at the inner resistor, we'll see that the voltage drop is the same as well.
34:30
Speaker A
For series circuits, you may recall that the current remained the same through both resistors in series while the voltage was split in proportion to the resistance. For parallel circuits, it is the opposite. The voltage remains constant across both circuits in
34:46
Speaker A
parallel. However, the current is split in proportion to the resistance. In our example, the resistances are the same.
34:55
Speaker A
So, the current will be split evenly. As our initial current leaving our voltage source splits at this node, this means that we now actually have three currents. I1, which is the one leaving our voltage source. I2, which is the
35:10
Speaker A
current that travels across the first resistor, and then I3, which is the second current that travels across the outer resistor. The split of these currents brings us to our third and final of the fundamental electrical engineering laws which is Kirchov's
35:25
Speaker A
current law. And Kirchov's current law states that the sum of all currents entering and exiting a node must equal to zero. So in our case that means that I1 is equal to I2 + 3. Since I1 is entering this node and I2 and I3 are
35:42
Speaker A
leaving, we can determine that I1 will have a positive and I2 and I3 will both be negative. Instead of adding resistors in parallel, what happens if we add two voltage sources in parallel? You'll see that we now have I1 and I2 entering the
35:58
Speaker A
node and I3 exiting it. This means that I1 + I2 equal I3. Of course, using both Ohm's law and Kirchaw's voltage law, we can calculate that I3 equals 90 milliamps. As the voltage sources pushing I1 and I2 are both identical,
36:17
Speaker A
and we have no components for voltage drops between the nodes, we know that I1 and I2 must be identical. This allows us to calculate I1 and I2 as 45 milliamps.
36:28
Speaker A
If you didn't follow all the math on this one, that's all right. I just wanted to show here how adding two voltage sources in parallel does not actually increase the voltage. However, it splits the current demand on each
36:41
Speaker A
voltage source. This is important to remember especially when using batteries as we can add multiple batteries in parallel and this will extend the life of the battery as each one of them has a lower current draw. Now that we have an
36:55
Speaker A
understanding of Ohm's law, Kirchaw's voltage law, and Kirchaw's current law, let's take a look at how we can use all three of them in combination to solve out the currents inside of this example circuit. This is a fairly common
37:10
Speaker A
practice when designing circuits as we can choose both voltage sources and resistors from the market or offtheshelf that fit our needs. However, depending on the voltage sources and resistance we choose and how we configure them in the circuit, of course, this will change the
37:26
Speaker A
amount of current. The first step to take when solving our circuit is to label all of our currents in the direction they're flowing in. Of course, we have our main current I1 that is leaving our voltage source. And this
37:39
Speaker A
current is split into three separate currents across our parallel resistors. We have I2 traveling over the 100 ohm resistor. I3 traveling over the 30 ohm resistor. And then I4 that is traveling over a 30 ohm and 10 ohm resistor in
37:54
Speaker A
series. The next step we'll take in solving the circuit is to label out our voltage nodes.
38:01
Speaker A
What these voltage nodes represent is the voltage difference between the top node and the bottom node.
38:11
Speaker A
With our currents and voltage nodes labeled, we can start to write out the formulas that will allow us to solve for the currents in the circuit.
38:20
Speaker A
First, we'll use Kirchov's current law to define that I1 is equal to I2 + I3 + I4. As we know that the current entering the first node must be split into three separate currents and that they will all
38:33
Speaker A
equal the current entering the node. Using Ohm's law, we can calculate that each of the currents I2, I3, and I4 will be equal to the voltage drop over the resistor divided by the resistors. With that in mind, we can add those into our
38:51
Speaker A
first equation. We've substituted I2 for V1 / 100 ohms, I3 for V2 / 30 ohms, and then I4 for V3 / 40 ohms. Notice how we have combined the 30 ohm and 10 ohm resistor in series to equal 40 ohms. Next, we can use
39:13
Speaker A
Kirchaw's voltage law to solve for our voltage nodes. If we draw our first loop throughout this current, then we can determine that the voltage across this resistor is equal to 9 volt. Another way to look at this is that if we actually
39:32
Speaker A
just cross out this 9 volts and we look at this minus end as being zero and then this top end as being 9 volts. This 9 volts actually represents the difference between the two. We then can also write that our
39:52
Speaker A
node up here is 9 volts. And since we know that this node is connected to the negative end zero volts as the current travels in a circle through. So when we travel here from positive to negative we go from 0 to 9.
40:08
Speaker A
So plus 9 volt and then as we travel from this node down to here we go from 9 to 0. So we go through - 9 volt.
40:17
Speaker A
As such we can say that V1 - 9 volt equals 0. And of course if we were rearrange that we can get V1 equals 9 volts.
40:28
Speaker A
In our scenario here these top three nodes we can think of as identical. We know that the wire in between are actually ideal wires. So there's no voltage drop between V_sub_1 or V2. And as such each of these have to equal 9 V.
40:48
Speaker A
Again, if we think of the additional loops, this also satisfies Kirchaw's voltage law. Because of this, we can set V_sub_1 equal to V2 equal to V3.
41:00
Speaker A
With all the values for our unknown variables accounted for, solving for I1 is as easy as plugging the numbers into our calculator.
41:09
Speaker A
We can calculate I1 as equal to 9 vol / 100 ohms + 9 vol / 30 ohms + 9 vol / 40 ohms. If we plug these all in, we'll get that I2 = 90 milliamps, I3 = 300 milliamps, and I4 = 225
41:28
Speaker A
milliamps. If we add these all together, we'll get I1 equal to 615 milliamps, which is actually 0.615 amp.
41:38
Speaker A
For those of you keeping score from our initial look at the voltage source, if this were that same voltage source, then we have actually surpassed the amperage rating or the current rating. So, something to keep in mind when we're
41:51
Speaker A
calculating and designing our circuits. You may have noticed that even for this quite simple and basic circuit, the algebra and math starts to add up.
42:02
Speaker A
Fortunately for us, there are many great circuit simulation tools that can take care of all these calculations for us.
42:09
Speaker A
And this is rarely done by hand. However, it is really important to understand the fundamentals of these three basic laws and how they work in order for us to set these simulations up.
42:21
Speaker A
This wraps up our three-part series on electrical engineering fundamentals. I'll see you in the next lesson.
42:29
Speaker A
Hey everyone. So, we left off at the end of the last lesson chatting about how there's lots of great circuit simulators that can actually do most of these simulations for calculating currents and voltage nodes. And honestly, there's a
42:42
Speaker A
lot more that they can calculate. And in the past, these simulation softwares were pretty expensive, and realistically, you could only get access to them if you work for a company that was going to buy a license. But now,
42:54
Speaker A
there is a few good ones that you can get for free. And this Circuit Lab is one that I just wanted to show everyone quickly. It's pretty cool and it runs right in a browser. Um, so you can get
43:04
Speaker A
to it from circlab.com. And if you want to watch their intro video or get started, feel free to take a look at that. And then if you uh scroll down, there's some great examples and lessons and things like that.
43:18
Speaker A
However, I'm just going to jump right in and show you how we can do a quick simulation. And then maybe if you want to take over and play around, that would be awesome. So, at the time of recording
43:27
Speaker A
this, you don't even need a login or anything like that. You can just go right into Launch Circuit Lab, and it's going to open up their simulator right in the browser. And you can just copy everything here. I'm just going to drag
43:42
Speaker A
and drop, and we'll just delete it all. Uh, and I'm going to quickly lay out that last circuit that we were looking at in the previous lesson. So, we'll start by grabbing our voltage source that we had. And if we just double click
43:54
Speaker A
here, we can edit the voltage here. And we'll make it 9 volts. And I'm just going to make it I'm just going to call it VC source for the voltage source.
44:07
Speaker A
All right. And then we'll add in our resistors. So we had our 100 ohm resistor here. And then we had a 30 ohm resistor here.
44:20
Speaker A
And then we had a 30 ohm and a 10 ohm here. So you just double click on them. You can edit 30 and then 10.
44:35
Speaker A
So now we just need to add our wires in to close this up. You just grab a wire here and you just draw the wire by dragging and clicking, which is awesome.
44:44
Speaker A
You just drag and click. Let's bring these all together. And then the one thing you're always going to have to add for the circuit simulations is we still need a ground um because it all works off of reference
45:11
Speaker A
voltages. So we haven't really talked too much about grounds yet and we will um in upcoming videos, but we need to tie all of our returns to a ground. And this just lets the circuit simulation know that, you know, this negative
45:24
Speaker A
polarity here that all this is tied to um a zero reference voltage as opposed to um it being a floating voltage and it's going to need that in order to solve it. So if you run a simulation without this ground, it's going to fail.
45:38
Speaker A
So the last thing we can do is just add some node names so that it makes it a little bit easier for us to um know what voltages it's talking about when it's solving. So, I'm going to drop in some
45:48
Speaker A
node names. And we had called this one V1 before. And we'll add one here for V2.
46:00
Speaker A
And then we'll add a final one here for V3. You'll see if I hover them already, it's telling me what voltage it is. So, that is pretty cool. Um, just like we suspected. So, we have because of KVL,
46:17
Speaker A
we know that it's going to be 9 volts for all of these reference points. And you may have noticed that actually as soon as I added the ground to the circuit, it satisfied all the conditions for it to run the simulation and it
46:29
Speaker A
automatically actually populated all of the currents and powers and voltages. So, if we just hover over the nodes, we can actually see all of those details.
46:39
Speaker A
If we hover over here for example, of course the voltage is 9 volts and we can see that then we're 90 milliamps. And if we hover over here, um just to give an idea of that voltage drop that I was
46:49
Speaker A
talking about, we can actually see the 0 volts now as we have that full current drop, but the current remains the same.
46:56
Speaker A
Uh and then of course we can also see the power which is kind of cool. If we go through to the other nodes, of course we have 9 volts again and we can see that second current as 300 milliamps. uh
47:08
Speaker A
over here if we look at these resistors of course we have this 225 milliamps and then we can also see uh the voltage drop across each of these resistors.
47:19
Speaker A
Uh and then if we go down over here we can see the source at 650 milliamps.
47:24
Speaker A
This is just a really really basic example and honestly it just scratches the surface of what this software is capable of and it's pretty cool that we're able to get free access to it. So, I'd highly recommend checking it out,
47:38
Speaker A
hopping in here, creating a few circuits yourself, uh, playing around with it, running some simulations, and experimenting.
47:46
Speaker A
Hope you enjoyed this quick demo. I will see you over in the next lesson.
47:51
Speaker A
Welcome everyone to the first lesson on reading schematics. We will pick up again on this topic later on in the course. In this lesson, we're going to be taking a look at the difference between how a circuit may be represented
48:03
Speaker A
in a schematic versus actually physically laid out. We will also take a look at a couple of practical schematic drawings and how they differ from the theoretical schematics that we've been using so far. I've modified the schematic that we were previously using
48:19
Speaker A
to add a few new components. So you'll see here that we have replaced our 9volt power supply with the symbol which represents a battery and the longer line is the positive end and the shorter one is the negative. We've also added in two
48:33
Speaker A
LEDs or light emmitting diodes, a red one and a green one. And we've also added in a switch. This symbol here is a switch and when it's in this position it represents open and when it's like this it represents closed.
48:46
Speaker A
You may recall in one of the previous lectures that I mentioned how a schematic does not actually represent the physical layout of a circuit. And to demonstrate that, we're going to take a look at what is called a wiring diagram.
49:00
Speaker A
And a wiring diagram is a pictographic representation of how a circuit is actually physically laid out or wired up. So you'll see in our wiring diagram here of course we have our 9volt battery and we have this connector to it which
49:14
Speaker A
has a positive and negative leads. Um and our red wire actually represents the positive wire and you know usually wiring diagrams will give like wire lengths and wire colors so that someone can actually build the circuit. The first thing that I'd like to draw your
49:30
Speaker A
attention to is how we do have this split of parallel circuits that splits here. However, instead of here first going to the um red as our inner circle, we actually, you know, split up to our switch and go to the green. And that's
49:44
Speaker A
on the inside. And what I wanted to show by this is that the, you know, the ordering of the components or where they actually are in relation to each other on the schematic doesn't necessarily represent where they are physically laid
49:58
Speaker A
out. Of course, the electrical connections still matter and when, you know, we have them connected by this node. The second thing I'd like to point out is just the length of the wires. So you see here we have some long longer
50:10
Speaker A
wires. And this may be because if this is fitting uh you know this whole wiring wire up is fitting inside some mechanical case or something. We actually need these wires to be longer so they can route to where they need to
50:21
Speaker A
go on a schematic. Of course this does not matter. The other way that we can actually physically lay out circuits is on what's called a PCB or printed circuit board. and we'll be taking a deeper look at that in the hands-on
50:36
Speaker A
section once we open up the router. I've switched back our schematic to our voltage source that we are more familiar with because I want to show a couple of other different items that will happen when we are practically reading a
50:49
Speaker A
schematic. So the way that we have it drawn here, this is a valid way to draw a schematic. And when you're learning about circuits or electronics and especially electricity, you'll see the schematic drawn how it is here. Like if
51:04
Speaker A
you were looking in a textbook, this is a very common way to lay out a circuit when we're teaching. And the reason for that is because when we're talking about those loop currents that we were um with Kaw's voltage law and Kaw's currents
51:17
Speaker A
law, it's very easy to visualize the flow of the circuit. However, when we're actually drawing these schematics out on paper, it starts to take up too much room to show all these return loops and connect, you know, all these wires. So,
51:32
Speaker A
a very common way that you'll see schematics laid out is something like this, where we're representing our 9 volts with this line here. Um, and this isn't actually like a wire or anything.
51:43
Speaker A
It just represents that this is starting at 9 volts. And of course, this is the um exact same circuit here.
51:51
Speaker A
The other thing that I'd like to call out is this notion of ground, which is something that we have not talked about too much yet. And what ground means in these electronic style circuits like this is that this is all 0 volts. So,
52:06
Speaker A
this is just a reference at 0 volts. And we could add a ground here in this schematic and this would be totally valid stating that this is all zero volts. And the reason that you frequently won't see it in this style of
52:19
Speaker A
representation is as we were saying before generally this negative end of the voltage source represents 0 volts and ground also represents 0 volts. So by us having you know all of these tied together even without the ground it
52:34
Speaker A
represents that they are at 0 volts. The last thing on ground here is we can think of all of these grounds. So in a bigger circuit, you will start to see more and more grounds added on. They're all the same point. So it's the same as
52:47
Speaker A
if we took a wire and connected these together and then add one ground in order to reduce space and make the schematic a little bit less cluttered.
52:55
Speaker A
We just connect them all to their own ground as needed. You may also see a schematic like the one on the right laid out like this where we represent 9 volts with this pin style here or you might
53:06
Speaker A
see it like this. So all those are valid representations. The last thing that we'll take a look at in this first part of reading schematics is what happens when our schematics start to expand bigger and take up more
53:18
Speaker A
space. See that we start to have wires that need to run over each other. And there's a few ways that this is handled in schematics. The first one is where if we just consider anytime the wires touch like this that that actually represents
53:33
Speaker A
an electrical conductivity and as such we cannot cross wires like we did here. So we would use these kind of loop styles to demonstrate that this is not electrical connection and in fact this wire is going over. The other style
53:47
Speaker A
that's much more common in CAD style drawings is you will see anywhere there's actually an electrical connection or interconnection will have this circuit node style connection that you're used to drawing and then the wire will actually just go straight through
54:01
Speaker A
the other one. And this is this does not mean an electrical connection. Lastly, unfortunately there is not a set specific standard for all schematics. So you will see things differ between schematics. The one important thing when drawing them and also reading them to
54:18
Speaker A
keep in mind is that they should be uniform or standardized throughout the schematic. So this one is a bad example here where we're using um two different methods to show interconnection and jumping over wires.
54:31
Speaker A
Again, we'll pick up more on reading schematics in the next section, but this should give you enough information to get started on the course challenge.
54:38
Speaker A
I'll see you over there next. Hey everyone, we are nearing the end of the first section of the course and I just wanted to say great job on making it this far. We've covered topics that include math, science, and engineering
54:53
Speaker A
and I know that these are topics that you generally wouldn't find at the start of a hacking course. So, great job on persevering and making it through this section. If everything didn't click the first time on these videos, you had to
55:05
Speaker A
rewatch them a couple times, or even there's still some things that you're not fully understanding, that's okay.
55:12
Speaker A
These are topics and concepts that took me a while to figure out. And we did cover a lot of the topics and core fundamentals that would be covered in first year electrical engineering courses. And we did those pretty
55:24
Speaker A
quickly. If you're interested in these topics and you want to learn more, I'd highly encourage you to seek out some other resources on the internet, I really just scratched the surface of these topics because, well, of course, this is a
55:36
Speaker A
hacking course and I didn't want to take up all of our time with electrical engineering.
55:42
Speaker A
I've designed a fun course challenge that takes some of the theory that we've learned and applies it in a practical setting. So, let's dive right into the challenge briefing right now and take a look at that challenge.
55:53
Speaker A
Okay, welcome to the first challenge of the course. Red team needs your help. Let's take a quick look at the design briefing together.
56:02
Speaker A
It reads, "Ooperator, we require your immediate assistance. We're performing a covert red team operation tomorrow on a sensitive target. One of our field operatives discovered during initial recon that a back door at the site is locked using a smart lock and took some
56:18
Speaker A
pictures of the model. Luckily, we were able to procure some of the locks for testing in our lab. Our hardware team uncovered a transmission output on the board.
56:28
Speaker A
They were able to capture multiple transmissions and sent them over to our software team for analysis and decoding.
56:35
Speaker A
They discovered that at startup, the devices bootloader outputs to the transmit pin, followed by the results of some initialization scripts. One of those outputs contains a hashed version of the locks pin combination. Luckily, the lock is using an outdated hashing
56:52
Speaker A
algorithm that is easily brute forced. This is where we need your help. The software team wrote a script that handles reading output from the PIN and brute forcing the hash. They loaded onto a Raspberry Pi, so our field operative
57:06
Speaker A
only has to open the smart lock and connect one wire from the Pi. He was running through a dry run today on our test locks and uncovered a problem. The Raspberry Pi input output pins can only handle 3.3 volts and the smart lock
57:20
Speaker A
transmits at 5 volts. The hardware team has already left for the day. We need a simple solution to shift the voltage level down from 5 volts to 3.3 volts. Our lab is stocked with pretty much any commercially available standard resistor. Oh, and one
57:37
Speaker A
other thing. The lock has an anti-tamper setting built in that will stop it from being able to open if it detects any output current from its microcontroller pins above 1 milliamp. Make sure your design won't trip this. The Raspberry Pi
57:52
Speaker A
IO has an input resistance of 50 koohms. On the next slide, I'm going to give a starter circuit for the solution and a few tips. So, if you want to go in and solve this completely on your own, then
58:04
Speaker A
close the video now and you can check your solution in the next video. However, if you'd like a little bit of a starter circuit and some tips to get started, I'll see you in the next slide.
58:16
Speaker A
Okay, so here is a starter circuit for us to put our solution in. We have the lock transmit pin. So, TX usually stands for transmit. And then we have the Raspberry Pi receiving pin. And we know that the lock transmits from 0 to 5
58:31
Speaker A
volts. And then we need to drop that down to 0 to 3.3 volt. One thing I want to show here is this notation that you will very frequently see where instead of writing 3.3 volt um we'll actually use the symbol for the units instead of
58:46
Speaker A
the decimal here. And that's just because it makes it less errorprone to reading if you miss the decimal for example especially in things like resistors. Uh so we will put the unit in the decimal and you will commonly see it
58:58
Speaker A
written like this. Um and then also for resistors you'll just see it as you know this K. So 50K means 50 kiloohms.
59:07
Speaker A
When you're solving for this circuit I wouldn't really worry too much about this section right here. Um just focus on what's here and then focus on getting you know your output that we would be able to pull off this at 3.3 volts. And
59:21
Speaker A
one last tip for you, don't worry about treating this challenge like it would be a high school or university exam where you're just going to have to sit down with a pen and paper and solve it. I'd encourage you to use whatever resources
59:33
Speaker A
you would like. So use Google. If you want to use chat GPT, give that a shot.
59:38
Speaker A
If you want to use Circuit Lab, then that would be definitely be a valid way to solve this. And also since we're going for a reall life solution using real life components, you won't need to get your solution to be exactly 3.3
59:52
Speaker A
volts output. Shoot to get it within 5 to 10% of that. The closer you can, the better, but as long as you're within that 5 to 10%, that's great. Good luck with the challenge. I'll see you over in
60:04
Speaker A
the next video where I'll show you my solution. Hey everyone, hope you had fun with this little challenge. So, we're going to go through a solution. Now, the first thing that I usually do when I get a problem
60:15
Speaker A
like this where we had a lot of wording is I'm just going to take out the key design components that are required and I've written them down. So, our key design criteria of course is that our voltage in where we're at the lock
60:27
Speaker A
transmission is 5 volts. Our voltage out has to be 3.3 volts. And then our current out of our transmission pin has to be less than 1 milliamp. And then finally, we have this limitation that we can only use standard resistors. And
60:41
Speaker A
we'll chat a little bit more about that later in the solution. So I'm going to be showing how I would approach and solve this. But as long as your solution fits this design criteria, then that is okay. You may have recalled from our
60:52
Speaker A
previous lecture on series circuits and kaw's voltage law that when we have two resistors in series then we actually are able to split that voltage across the two of them or as some may call it divide that voltage and this is a very
61:07
Speaker A
common circuit called a voltage divider. So if we're not familiar with those though what I would suggest and what I would do is I would just go hop over to Google and look that up. So let's hop over to the browser.
61:20
Speaker A
Just going to hop over to trusty Google here. The first thing I'm going to look up is just a voltage divider.
61:31
Speaker A
And we'll take a look at trusty Wikipedia here. Perfect. So, we're already seeing we got a voltage divider. And if we want to read um a little bit about it, we can do so. And then we can also see the
61:44
Speaker A
mathematical proof here for it if you're interested in seeing that. But we moved on to the engineering solution. So I'm just going to take a straight look at the engineering solution. Um, and I see this little circuit here. This looks
61:57
Speaker A
exactly like what we need. We have a voltage in. We are just using resistors.
62:02
Speaker A
And then we have a V out. And if we look over here at the formula, we even get this handy dandy formula here that just says V out over Vin= R2 over R1 + R2.
62:15
Speaker A
And we already know V out and Vin. So we can just grab this and steal it and solve for R2 and R1 and we'll be able to finish our circuit. So we saw from that Wikipedia page the layout of that
62:29
Speaker A
voltage divider will fit exactly as we need. Uh so I'm just going to grab it and steal it.
62:37
Speaker A
What we've done here is very common, you know, taking a specific circuit element or a few portions of a circuit in kind of like a block format and then using that in our own designs. And this is very common in circuit design. It's
62:52
Speaker A
something to keep in mind when you're either building a circuit or reading a circuit is that we don't necessarily have to reinvent the wheel. There is lots of various circuits that perform a specific small function that we can then
63:06
Speaker A
add together, you know, as building blocks to a bigger circuit to accomplish a bigger overall goal. If you're familiar with programming at all, this is kind of similar in that we would use, you know, libraries and pre-built functions and we would combine all of
63:21
Speaker A
these together. And our job as the programmer is not to reinvent the wheel and rewrite all these libraries and functions. we just kind of have to do the in between code that links all of them together. And that's the same in
63:33
Speaker A
circuits. With that being said, we've taken our voltage divider here and dropped it in. And we know the voltages.
63:41
Speaker A
We just have to solve for R1 and R2. So, what I would do first is add our current to this circuit. And I'm calling it IM for IMAX. And that's the max current that we are able to have coming out of
63:55
Speaker A
our microcontroller pin from the door lock. And you may recall that that was set at 1 milliamp.
64:02
Speaker A
Now what I'm going to do is I'll say that yes, it needs to be less than 1 milliamp. But because this is a real life engineering solution, I'm going to set it to 0.75 milliamps. And we'll give ourselves, you know, that 25% headroom
64:16
Speaker A
there in case we have any extra voltage or anything, a little voltage spike. we don't actually get close to um that 1 milliamp. And this is very common when designing circuits is that you don't want to go right close to the maximum
64:29
Speaker A
because spikes or things can happen. If we put in our equation that we grabbed from Wikipedia, of course, we have V out over Vin= R2 over R1 + R2.
64:42
Speaker A
Since we know the current to simplify that equation, we can use Ohm's law to actually calculate what R1 and R2 are together. So of course using Ohm's law reminder that it is V= IIR. In our case that's going to be 5 V = 0.7 milliamps *
64:59
Speaker A
R1 + R2. If we rearrange that a little bit we'll get R1 + R2 = 5 V over and you'll see here I have written it as 0.0075 amps. So, I'm just converting from milliamps to amps because if you're
65:16
Speaker A
actually doing this in your calculator, these are the actual numbers you would need to punch in if you want to get your resistance in ohms.
65:24
Speaker A
So, we get that R1 + R2 = 6.7 kiloohms. And now we can drop that back into our initial voltage divider equation.
65:35
Speaker A
So, I'll just clear the screen quickly here and we can drop that in. Reminder that the initial formula was V out over Vin = R2 / R1 + R2. We can start plugging some numbers in here. So we have 3.3 vol / 5 volals R2 / 6.7
65:56
Speaker A
kiloohms. We're substituting there the R1 + R2 with the 6.7 kiloohms that we calculated.
66:04
Speaker A
That gives us 0.66 66 = R2 / 6.7 kiloohms. And if we rearrange that formula, we can solve R2 = 6.7 kiloohms * 0.66, which is actually equal to 4.4 kiloohms.
66:22
Speaker A
All right. And we know that R1 + R2 is 6.7 kiloohms. Just a reminder from our calculation before. We can rearrange that. So R1 = 6.7 koohms - 4.4 4 koohms, which gives us an R1 of 2.3 koh.
66:40
Speaker A
Perfect. So that gets us very close. These calculations will give us a nice output voltage of 3.3 volt. However, unfortunately, we can't just buy or get whatever resistor values we want very easily. We are limited generally to what's called a list of standard
66:56
Speaker A
resistors, which are the ones that are actually commonly commercially produced. In order to get a little bit more information on that, let's hop back over to Google. So, just a quick tip on these components that come in different values
67:09
Speaker A
like resistors. You can get tables from the manufacturer. So, I'm just going to look up standard resistor table.
67:18
Speaker A
And if we scroll down here, this one here, um, they've already looked at it is from Vich, which are a manufacturer of a lot of electronic components. So, we're going to take a look at their table.
67:29
Speaker A
And the way that these tables work is they are a logarithmic scale. And the values listed here are in these plus or minus what we call tolerances. So if you um you know look at the values under plus 1% that means that they're
67:44
Speaker A
guaranteed that the resistor will be plus or minus 1% of that value. And then the values in here they can be either in plus or minus 0.5. 0.25 or even 0.1. So you can specify, you know, how exact or
67:57
Speaker A
precise you need it to be. Of course, the more preciseness you are purchasing, then the more expensive those resistors are going to be. And we see all these values. Like you'll see, oh, we only have like 10 ohm, 10.1 ohm. Like how do
68:10
Speaker A
we get resistors of different values? If we scroll down to the bottom here, it actually gives us a little bit of a reading about how that does. And it says standard resistance values are obtained from the decade table by multiplying by
68:23
Speaker A
powers of 10. As an example, 133 13.3 can represent 13.3 ohms, 133 ohms, 1.33 kiloohms, 13.3 kiloohms, 133 kiloohms, all the way up to 1.33 megga ohms. So the way that works is we can multiply it by 1 and that just gives us the ohms
68:45
Speaker A
value and then we can multiply it by 10. can multiply it by 100 um a th00and and so on. So what we're going to look for then is our first resistance value we calculated as needing uh 2.3 kiloohms.
69:00
Speaker A
So if we scroll down this table here, perfect. The closest one we can get to is 23.2 here. This 23.2.
69:11
Speaker A
And if we multiply that by 100. So, if I just open up a calculator quickly and just to show you how this works, if we go 23.2* 100, get 2320, which is equivalent to 2.32 kiloohms. So, pretty close.
69:35
Speaker A
We can do the same for the other one we were looking for was that 4.4 kiloohms.
69:41
Speaker A
So, we scroll down this one here. Perfect. We've got one that's 44.2. Um, and that's the closest we can get. And if we multiply that by 100, we're going to get 4.42 kiloohms.
69:53
Speaker A
So, you may be wondering that these are a little bit off of our calculations in resistance values. And that is okay.
70:00
Speaker A
Just like we designed some tolerance into our max current calculation, it's generally safe to assume that other circuit designers are going to add a little bit of tolerance into their circuits as well. So, for the Raspberry Pi, this means that our voltage is going
70:15
Speaker A
to just be off by a little bit, but that will be okay. Now that we found our standard resistor values, let's hop back over and just make sure that these still work. Okay, so I filled in our resistance values.
70:28
Speaker A
And just a very quick reminder on our notation here where we have filled in this 2K 32 and 4K 42. This K here is representing the point and we can think of moving it over here. So this is
70:41
Speaker A
actually 2.32 kiloohms and this is 4.42 kiloohms. So if we just want to really quickly do the math, of course our current is going to change just a little bit because we have changed those resistances and using Ohm's law of
70:55
Speaker A
course we can divide we can take 5 volts and divide it by the total resistance and that's going to give us 0.74 milliamps which we are pretty close to original one. So we know our voltages are going to be pretty good. Of course,
71:10
Speaker A
our V out is going to be the voltage in minus the voltage drop over that first resistor. And of course, we can use Ohm's law again. And that gives us, if we wanted to punch into our calculator, this 5 volts minus, of course, again, we
71:23
Speaker A
have switched back from the milliamps to the amps. If you want a quick way to do this and the way that I actually like think of it in my head is if the the decimal was here and we're going from
71:35
Speaker A
milliamps to amps. So millie means 1,000. Then I literally just I I draw the things. I move the decimal over three points. And that's how I do it and think about it in my head. So we punch in this calculation. We're going to get
71:49
Speaker A
V out is equal to 3.28 volt which is close enough to 3.3 that will be perfectly fine for our operation. So the last bit that I want to touch on just in case anyone's wondering is you know I
72:01
Speaker A
didn't even really touch this portion of the circuit in our solution and when I was doing the calculations and this is a tip I gave you I said just kind of ignore um this part of the circuit for
72:12
Speaker A
now and we'll just work on dividing our voltage here. Now, the reasoning for that is if you actually crunch the numbers here, you know that, you know, we're supposed to be 3.3 volts all across here. And if you
72:24
Speaker A
punch that in for the circuitry, you're going to get a magnitude of, I believe, 0.06 milliamps. So, we're talking much, much smaller um than the current that we're working with here. And this is by design on these receiving pins for devices
72:42
Speaker A
because, of course, we want to use as little current as possible. We're not powering anything. We're just reading the voltage. So, as little current as we can get away with, we will use. And that's how these are designed with this
72:54
Speaker A
really high, it's what's called input impedance or resistance. Now, if you did actually go back and, you know, solve this whole circuit out, taking into account when we hook up across this input pin, of course, that will change this current just a little
73:08
Speaker A
bit. Um, you know, we'll have an extra little bit of current draw by adding these two resistors in parallel. Even though we're adding a 50 koohm resistor um in parallel, it's actually going to make the combined resistance of these
73:22
Speaker A
two circuits smaller. So if you take the total between these two, it's actually going to be a little bit smaller than this. And of course, that's going to increase our max current just a bit. But luckily, we left a lot of headroom in
73:36
Speaker A
our calculation, giving ourselves that extra 25%. And that's going to be okay. So just to really quickly show how that would affect the circuit if we do take into account that input resistance I've added it here and just to show another
73:52
Speaker A
very valid way of solving this problem I've quickly sketched up our circuit in circuit lab and I did drop in those resistance values that we were using. So we check this node we have 5 volts as expected and our total current has gone
74:05
Speaker A
up to 783.6 micro amps which in milliamps would be 0.78. So, we're definitely still below our 1 milliamp. Of course, cuz we've increased that current, we're going to have a little bit more voltage drop over this resistor. If we look at the voltage
74:19
Speaker A
down here, we can see that it is 3.18 volts. And that is a little bit below our desired 3.3 volts. So, if you did take this into account and you were able to find standard resistors that functioned a little bit better in this
74:33
Speaker A
scenario, then good for you. However, that 3.18 volts is well within the threshold that we would need for a logic shifter. Uh, and we're going to talk a lot more about digital communications in further lessons, and it'll make sense
74:47
Speaker A
why we can be off by that um, you know,.12 volts. We're only off by about 4%. Which is okay. Finally, one other point here. If you use resistance values that are much greater than this, that's okay. And honestly, it may even be a
75:02
Speaker A
better solution because we're going to reduce our overall current draw, which of course is going to lower the amount of power that we're pulling um from the smart lock. So, that actually may be a better design. I just went with the
75:16
Speaker A
lowest number that was underneath our max current. That gave us a little bit of threshold, but you know, you could even increase these even more as long as you use standard resistance values if you wanted. Um, as long as you're
75:28
Speaker A
getting that 3.3 bolts here, then that would be a valid design solution. If you got the solution, great job. That's it for this first section of the course and I'll see you over in the next section where we're going to start with some
75:40
Speaker A
hands-on. I hope you're enjoying the course so far. A really quick reminder to make sure you are subscribed to my YouTube channel which is linked down below. And also make sure you are subscribed to the TCM YouTube channel where you're
75:56
Speaker A
watching this right now. We're almost at 1 million subscribers as I'm recording this. It would be great to hit that mark. So if you are enjoying this video and you've watched to this point, it would really help us if you could
76:09
Speaker A
subscribe. Hello everyone and welcome to the second section of the course where we're going to be doing some hands-on testing and a little bit of hands-on lab work with some of our equipment and the router that we're going to be targeting.
76:25
Speaker A
Before we dive into these hands-on portions though, I want to do a very quick and very important lesson on electrical lab safety and some of the dangers of working with electricity. As I'm sure everyone watching this is aware
76:40
Speaker A
that electricity is can be very dangerous and can also be deadly. However, the things that we're going to be working on in this lab and the testing that we're going to be doing can all be done extremely safely. And in
76:53
Speaker A
order to do that, we just have to follow a few very simple rules. So the first rule and if you're only going to listen to one or follow one is this is the most very important one and that is that we're only going to work on
77:06
Speaker A
low voltage. So what does that mean by low voltage? Well, a good rule of thumb is generally to stick below 30 volts DC.
77:15
Speaker A
That's a pretty common standard for what's considered to be the threshold of low voltage and safe voltage to work at without further proper training on how to handle high voltage. So that means that we're not going to be working on
77:29
Speaker A
anything with the wiring or the outlets or anything like that from our household. In North America, our household voltage is 120 volts. And depending on where you are in the world, that may differ. You might even be up to
77:41
Speaker A
240 volts or 220 volts. So all of that is outside of that safe range. So we're not going to be touching any of this stuff. We're going to leave that to the electricians. uh all the wiring behind it and that also includes anything that
77:54
Speaker A
we plug into it. So in our lab we're going to be using the power supply that comes with our router and of course when we plug it in at this end it's 120 volts and then it gets stepped down to 9 volts
78:07
Speaker A
for us that we're going to work with. But since this whole thing plugs into the wall, that's all we're going to do with it. We're just going to plug it into the wall and into the router. We're not going to open this up. We're not
78:18
Speaker A
going to do any testing on it. We're not going to modify it. We're not going to alter it. Also, if we do come across a power supply that we're using, it has been modified or altered or we see that
78:29
Speaker A
it's damaged, we shouldn't use that. And in addition to that, we should only be using the power supplies that are rated for the equipment that we're using. And the best bet to make sure you're doing this is to use the power supply that was
78:41
Speaker A
included with the equipment. So, just a really quick demonstration of why it's so important for us to leave these higher voltages to the pros. I just want to go over a chart here that shows some of the effects of electrical
78:56
Speaker A
current on the body. And when we see this current, so this is not um like the supply current that the circuit can actually supply. This is, you know, if we were to uh shock ourselves, this is the actual current that would run
79:10
Speaker A
through our body. So you'll see even at 1 milliamp, which is a fairly small current level, we'll start to be able to notice a slight tingle. Even at 10 to 20 milliamps, this is where we'll lose the um our ability to let go. So if you
79:26
Speaker A
know, you were to grab a wire or something like that and you're getting electric shock, uh the current is actually strong enough that it will cause the muscles to contract and we can't let go, which can actually be
79:36
Speaker A
quite dangerous if we aren't able to let go. We'll be continue to receiving that shock. um at 30 milliamps breathing can become difficulty and we start getting you know the increased possibility of death and then once we get to even 100
79:50
Speaker A
milliamps so this 100 to 300 milliamps is when ventricular fibrillation happens. So this is when um the electrical signal through our body actually is able to shut off our heart.
80:00
Speaker A
So like very dangerous and um likely fatal. And then above these levels you're going to get into like really severe burns and lots of nasty stuff. So as I mentioned before this current though is the actual current through the
80:14
Speaker A
body. Now we know from our previous lectures of course that the current is dependent on two things. The voltage and then the resistance. So in our case we can control the voltage. That's why we're only going to be working on these
80:26
Speaker A
low voltage levels. Um and then the other thing that we do have working in our advantage is especially at lower voltage levels um the body has a very high resistance level. So, just to demonstrate that, I want to show like a
80:40
Speaker A
really bad stick drawing I have here um of our little demo person. We'll call him Bob. And Bob has was working and he was working overhead. Um so maybe he made contact with his hand to a live wire that he was working on overhead and
80:56
Speaker A
then he had his other hand touching maybe a ladder um or a railing or something metal. So he's created a path for the electricity to travel through his body and to ground.
81:08
Speaker A
Now we'll say in this scenario Bob has you know dry clean hands without any sores or anything like that on his hands and under that scenario the resistance of the human body and the skin particular is very high. So 100 kiloohms
81:23
Speaker A
is a pretty good estimate for dry undamaged skin. And if we do the really quick math for this using Ohm's law of course the current is equal to the voltage divided by the resistance. So, we get 9 volts over 100,000 ohms, which
81:36
Speaker A
we get 0.09 milliamps. So, Bob wouldn't even feel this one. And that's because we're working with a low voltage level.
81:44
Speaker A
And also, we have this dry, clean hands. However, if we just change this up a little bit. So, a more likely scenario, if he's working at his home or something like that, we have now 120 volts. So, also we'll say that his hands are sweaty
81:59
Speaker A
because it's been hot and he's been working. And under these conditions, the resistance of the skin is actually much much lower. And we'll estimate for this case that it's down to 1 kiloohm, but it can even get lower than this. So if we
82:13
Speaker A
recrunch these numbers now, under this circumstances, we can see that we're actually already up to 120 milliamps. So we're well within this fatal zone. And that's why it's so so so incredibly important for us to leave these higher
82:28
Speaker A
voltages to the pros and only work on the lower voltages. In this course, we're just going to be working generally around 9 volts, which is the what comes out of our power supply. Um, we're not going to be working with that power
82:40
Speaker A
supply at all. We will plug the power supply into the wall and then we'll plug the power supply into the router and we will be working only on the router. The second rule that is just a really really
82:50
Speaker A
good habit to get into is that we're only going to power on circuits when required. So if we need to test them, then we'll power them on and then we'll power them off. And if we don't need to
83:02
Speaker A
actually, you know, be doing any testing that requires a circuit to be on or any work that requires a circuit to be on, then we'll just power the circuit off.
83:12
Speaker A
So at some points in this course, we're going to have to connect things. is we're going to be visually inspecting the board. And at those points, there's no reason for us to have the board on or the router powered on. So, we will power
83:24
Speaker A
it off. And the best way to make sure that you actually have it powered off is we will just physically unplug the power source. So, in our case, it is this brick power supply. We're going to unplug that right from the router. Our
83:37
Speaker A
router doesn't have an onoff switch, but some devices do. Um, even when they do have an onoff switch, my in my opinion, best practice is just to remove the power supply and then you know there's no chance of uh accidentally having any
83:50
Speaker A
electricity coming through to what you're working on. This is just a really really good habit to get into when working with any type of electricity. It can prevent you from getting a shock and also can prevent you from damaging the
84:03
Speaker A
board. So I always get in the habit I'm done working with it, turn it off. If I don't need it turned on, I don't even turn it on.
84:10
Speaker A
Okay, the third rule, a really quick one, is that we're going to remove any jewelry. Uh we were talking about how the resistance of the human body is quite high. So that helps to us to prevent from getting these damaging
84:22
Speaker A
electric shocks because we keep the current low due to that high resistance. Of course, metallic jewelry is a very good conductor generally. So it can actually carry quite a bit of current.
84:32
Speaker A
And what can happen if you make contact with any jewelry even at lower voltages?
84:37
Speaker A
uh it doesn't increase our chance of a shock because that resistance is still high on our skin. But the jewelry can heat up quite hot and you could burn yourself. Um or you can make a spark or something that is a distraction to you
84:51
Speaker A
and causes you to do something else that would be dangerous like swing your hand away and hit it on something. So good rule of thumb really when you're working on anything but especially electronics we should remove any jewelry.
85:03
Speaker A
Okay. Okay. And then the last rule that I want to chat about which is not as applicable for this course but just in case you're going to go um and take what you learned in this course and work on
85:14
Speaker A
other electronics and that rule is to be mindful of capacitors. So we haven't chatted too much about capacitors yet and we will talk about them much more in detail in the 2011 section of electrical engineering for hackers. But just a
85:29
Speaker A
quick rundown on capacitors. They are able to store an electric charge on a circuit kind of in a similar short-term way that a battery would do. Um, and they're actually able to build up a much more powerful charge over time. Um, and
85:44
Speaker A
then dissipate that very quickly. And with larger capacitors like some of the ones that are shown here, they can actually be at a much higher voltage than the rest of the circuit operates at, and they can pack a pretty good
85:58
Speaker A
punch. So, if you're not careful with these guys, you can get a good shock and actually at levels that could possibly dangerous. The other last really important thing to keep in mind with capacitors is that they are able to
86:12
Speaker A
store charges. And some of these capacitors can actually hold onto a charge for a pretty decent amount of time. So this means that even if you're, you know, following rule number two and we've powered the circuit off completely, you've removed the power
86:25
Speaker A
supply, the capacitors can still hold a charge for a pretty good amount of time.
86:30
Speaker A
Um, good circuit designs will have ways to dissipate this uh over time. However, you don't want to trust that someone has put this in. So we always want to be mindful of discharging these capacitors.
86:42
Speaker A
How to do that is a little bit outside of the scope of this course since we're not actually going to be working with any capacitors that are at that dangerous level. So, if you do encounter these large capacitors when you're
86:52
Speaker A
working on something, you know, even in TVs or power supplies for computers or things like that, be very careful of them and maybe do a little bit more further research or learning before you actually dig into using them. Again, in
87:05
Speaker A
this course on the router that we're using, there's not going to be any that are at that high dangerous level. Um, but I just wanted to make sure everyone was aware of that. So, that wraps up this quick lesson on safety. I will see
87:16
Speaker A
you over in the next lesson where we're actually going to start getting our hands dirty and do some hands-on.
87:23
Speaker A
Hey everyone, welcome to this first handson lesson of the course. If you've just unbox your router, one really quick reminder to hang on to the uh plastic twist tie here that I have. It's what holds the power supply together. And
87:39
Speaker A
we're going to be using this guy later on in the course for a little bit of a hack to get a connector connected without soldering. So, make sure to hang on to this. Just set it off to the side
87:48
Speaker A
and hang on to it. So, in this lesson, we're going to be taking a look at our TPLink router.
87:55
Speaker A
That's going to be the target that we are hacking on and doing testing on throughout the course. Now, the one that I'm working with and the model that we're going to be using throughout this, if you just want to double check, it is
88:06
Speaker A
a TLWR841N. And I've chosen this model to be our target for a couple reasons. Um, one of the main ones is it's very cheap at about $20. And it also has a lot of what some people will call features. other
88:23
Speaker A
people would call um security misconfigurations that can help us to learn about hardware hacking and some of the things that we can take advantage of.
88:32
Speaker A
Now, in order for us to get access to most of these hardware hacks or any of the testing, we're actually going to have to open this device up. So, we're going to be in this video taking a look
88:42
Speaker A
at how we can do that. In order to do so, we are going to need a couple of tools. So, one of them is going to be a Phillips screwdriver. I've just got a set here of small um screwdrivers, which
88:54
Speaker A
includes a Phillips screwdriver. And then we're also going to need something to uh pry this open. So, I've got two here, what are called spudging tools, and they are used to pry open uh electronic devices like this. Now,
89:09
Speaker A
you'll see this in many electronic devices where it uses what's called uh a pressure fit to snap together. So, this one's got a couple screws in the back, and I'll just flip it over to show you that right now. So, we've got two screws
89:23
Speaker A
here in the back. And once we take out these screws, though, it's still not going to come apart. It's actually going to be uh held together pretty tightly.
89:31
Speaker A
And the reason for that is most of new electronic devices these days use this pressure fit. So, even things like your phone, if you've ever had to take that apart uh to get your battery out, or laptops, they use this pressure fit.
89:45
Speaker A
And these spudging tools are specifically designed to open that. Um the nice thing about them is they are also not conductive. So we don't have to worry about um any type of shock discharging into our components or shorting anything.
89:59
Speaker A
Picked these ones off off up off Amazon for pretty cheap. Um but if you don't have any or don't have access to them, you can use a small flathead screwdriver. So I've got one right here.
90:09
Speaker A
The only thing with these is to keep in mind they are metal. So, we don't want to make sure we're not shorting um any of the circuits. So, try and be careful when we are using them um not to insert
90:19
Speaker A
them too far into the router themselves. Okay, with that out of the way, let's take a look at how we can open up this router. So, the first thing to do is just to pop these screws out. So, I'm
90:32
Speaker A
going to do that right now. if you haven't done so already. Also, these antennas just fold down. It's much easier to work with them if you fold them criss-cross like I have here. And we'll just take these screws out.
90:57
Speaker A
So, even with these screws taken out, you'll see um the router is still actually together pretty strong. Even though I'm pulling on it with my hands, I can't quite get it open. So, this is where that spudger tool comes in handy.
91:10
Speaker A
On this router specifically, I find it's easiest to, if I just move these antennas out of the way for a second, it's easiest to get started. We can uh kind of slide in here with your tool and pry open. So, that's where I am going to
91:27
Speaker A
start on mine. And if you just get the tool in and just give it a little pry, you can see mine has popped right open.
91:34
Speaker A
And I still have it. It's a little bit stuck on the ends. Um, here I'll I'll flip it up so you guys can see. Still stuck here on the end. So, this is where this tool comes in handy. Can just try
91:45
Speaker A
and pry along. If I just use my hands a little bit. We can just work it along the edges.
92:03
Speaker A
I'm going to come back to this side here. There we go. Okay. So, the one thing you will notice when you're doing this, and you may have heard it there on camera, um, is we do get some kind of snapping, and it does
92:20
Speaker A
sound like it is breaking a little bit. That is to be, um, expected when you are working on these pressure fits. That snapping is okay. Uh, you'll notice like nothing on here actually broke. I've got no broken plastic. And if I wanted to, I
92:34
Speaker A
could just snap this back together by just pushing it uh back together. Just going to set this out of the way here.
92:51
Speaker A
All right. So, we now have our router open and we can start taking a look at working on the internals. I'm going to pause this video here and we'll pick up in the next one where we start taking a
93:02
Speaker A
look uh at the internals and we'll also chat about how to safely handle electronics and make sure that we don't have any electrostatic discharge. That wraps up this video. I will see you over in the next one.
93:16
Speaker A
Welcome everyone. So before we start actually touching and handling and testing our router and the internals of it, I do just want to chat a little bit about electrostatic discharge and how we can safely handle the electronics and
93:32
Speaker A
the PCB. So I'm sure that everyone watching this video has at some point in their life walked across a carpet or some other surface and then touched a doorork knob or another metal object and received an electric shock. And while these shocks
93:47
Speaker A
are not harmful at all to humans, while they may be a little jolting or surprising, they're not actually harmful to us, they can actually be very harmful to electronics and in particular the kind of very small electronics that we
94:02
Speaker A
see on these circuit boards. Now, the reason for that is with an electric shock, you can actually get up to easily 5,000 volts or more. The reason they're not dangerous to humans is, of course, it's for a very, very, very short amount
94:16
Speaker A
of time. So, the amount of energy dissipated is extremely low. The reason this isn't harmful to humans is that it's for such a short period of time, and our large bodies are easily able to just dissipate any of the charge that
94:30
Speaker A
would come from that. However, for small components, if I just grab my pointer, um like some of the ones on this board here, like the chips or the other, um it's even really hard to see small componentry on here. They're so tiny
94:43
Speaker A
that this large uh charge across them can actually do quite a bit of damage.
94:49
Speaker A
The one really concerning thing with electrostatic discharge or shocking these components is that a lot of times the damage won't be noticeable right at the start and everything will function as is. However, we've weakened that component um to the point where it's
95:04
Speaker A
going to fail later on. And this can be a nightmare from a quality assurance standpoint, especially if we're working in a production environment or we're doing testing on a board for a potential customer or something like that. We want
95:18
Speaker A
to make sure that we're not accidentally introducing this damage to the board because then we're not entirely sure if it's something that we did legitimately with our testing or if it's from this electrostatic discharge.
95:30
Speaker A
So, if you're working in a professional setting, depending on where you're working, there's going to be a set of measures that you're probably going to have to follow for electrostatic discharge and to make sure that that doesn't happen. And I just want to go
95:44
Speaker A
over some of those so that everyone is aware. And then when you're working at home, you can kind of make your own risk assessment about which ones you're going to follow. You know, one of the nice things in this course is the router that
95:55
Speaker A
we're working on is relatively cheap. It's only $20. So if we do damage it, then it is easy to replace. And you know, in this scenario, we're not actually um working on a customer's component. So ultimately, it is up to you to decide
96:08
Speaker A
how many ESD precautions you want to take. These are not like a safety precaution for ourselves or injuring ourselves. they are to stop us from uh damaging the board and our equipment.
96:19
Speaker A
All right, so the first thing that I'm doing here is I'm actually working on this um ESD mat. So the way that this works is it's very insulating. It's made of rubber and it has an extremely high surface resistance. Um so that's going
96:33
Speaker A
to help stop dissipate any electric shock because of course it's going to be hard for there to be a path to ground.
96:40
Speaker A
Another thing that we can do before we start working is we can make sure to dissipate any charge on our body. So, what I have done is near me I have a doorork knob that's just off camera that
96:50
Speaker A
I touched before I start working. So, if you have anything similar near you, a doorork knob or like maybe a metal bed frame or anything like that, you can make sure that you've dissipated any of your charge.
97:03
Speaker A
The other thing that we can do that is free is make sure that when we're handling the board, we're not actually touching any of the components unless we absolutely need to. So, if I were going to pick up this board, then I would do
97:14
Speaker A
so from the edges and just touching the edges like so. Um, I wouldn't like actually go and directly touch any of the components because that can relate to a shock going straight into the component. It's why like when I need to
97:28
Speaker A
point out to them, I am using um this tool that is nonconductive so that there is no chance of dissipating shock.
97:35
Speaker A
Okay. So, the other things that I'm going to show here are stuff that's going to cost money. And I'm not going to be using them all cuz I personally feel like it's a little bit overkill for this, but I just wanted to um
97:47
Speaker A
demonstrate in case you are ever in a professional environment, you'll probably need to use those. So the first one is something that you've probably seen and that is these ESD bags. So these bags are non-conductive. They're highly resistant and when we're
98:02
Speaker A
transferring or moving electronics then we should put them in these bags because it stops uh any electric shocks from dissipating throughout them. So these are great for that. You've probably seen them if you've ever bought like any electronic components. They come in
98:14
Speaker A
these bags. The other thing that you will commonly see in a professional setting is a way to actually keep yourself grounded. And I'm just going to show you one way that you can do that.
98:25
Speaker A
So, I have a power bar that's mounted that I'm using for power. Um it's just right here. And on this power bar, of course, um this little pin here, this is just a straight connection to ground. Um so that's generally done for safety
98:39
Speaker A
reasons. If we have a short circuit or anything like that, um all the power will go straight to ground. And this plug that I have here, it's only got one prong and it only just fits into the ground. Um, so I'm going to plug that
98:51
Speaker A
guy in here and then it's going to give us access here. I got it plugged in and I'll just set that here. It's going to give us access to two ground connections. So, what I have here is a wristband and this is a metallic
99:07
Speaker A
like it's got metallic conductive material in here. Um, and it's got this alligator clip here that I can pull off.
99:14
Speaker A
So, this plugs into one of these guys. And then I can just put this wrist strap on.
99:25
Speaker A
All right. So, you just wear it on your wrist like that. And then this, what this does is this makes sure that I'm not actually going to be able to build up any charge because I am constantly grounded. So, there's almost like a zero
99:36
Speaker A
resistance path for any charge to go. And it's going to take the path of least resistance. So instead of, you know, shocking anything, it's going to go through to ground. All right. So I'm just going to take this off cuz it's a
99:46
Speaker A
little hard to film with and I'm not going to be using this because I think it's a little overkill for this lesson.
99:50
Speaker A
But if you're in a professional setting, like when I used to work on electronics in a professional setting, I would wear one of these.
99:59
Speaker A
All right. And then the last thing that you can do um is that we actually can ground the work area that we're working on as well. So I've got another one of these clips right here. And we've got this that
100:11
Speaker A
plugs in on the one end and then it's got this alligator clip here. Um, so I'm just going to clip it onto the side of this mat.
100:18
Speaker A
And then even though this is set to be like a really bad conductor, um, and it's very very highly resistive, just in case, we can also ground this to make sure that there's no chance of any, uh, electrical charge dissipating. It will
100:32
Speaker A
go straight to ground. Um, okay. So I just plugged that in. Again, I'll show you into my power bar that's here. So now if I'm wearing this, I'll just put this back on again quickly.
100:43
Speaker A
All right. So if I'm wearing this now, we can see that um you know, I'm grounded and the area that we're working on is grounded. So it's it's almost impossible for us to have um any sort of electrostatic discharge.
100:57
Speaker A
The last thing that you'll see um in a professional environment and is something that I have had in working areas as well is there will also be special flooring that is very very conductive so that it makes a good path
101:10
Speaker A
to ground and you'll wear special shoes that are ESD protective shoes and they will also um make sure to ground you. So we're then have three points of grounding and it's very unlikely that we're going to have any sort of ESD.
101:26
Speaker A
Now these last three things where we're using, you know, the grounding of the mat and the grounding of the um wrist strap, and obviously no one's going to have this at their home, but the grounding through the shoes are great
101:37
Speaker A
for production environments and we want to be absolutely sure we're not going to do any damage. Um, however, for the home stuff, I would just suggest to, um, sticking with the, you know, touching only the PCB by the edges and trying to
101:51
Speaker A
avoid actually physically touching any of the components themselves. And I also do just ground myself on something metal because it's very easy to do um, before I work with it. That being said, if I was working on something like my
102:04
Speaker A
personal laptop or maybe my phone or something that was worth a lot more money, then maybe it's good practice to follow these. So, I will leave that up to you as the viewer um to choose which options you're going to use for PSD
102:16
Speaker A
protection. With that being said, we can now move on to our first testing and taking a look at the PCB. So, we'll wrap that up for this lesson and I'll see you over the next one.
102:29
Speaker A
Welcome everyone to this lesson on PCBs. So, if you're not already aware, PCB stands for printed circuit board. And in the internals of our router that is this green board here.
102:42
Speaker A
Now you hear PCB used interchangeably to reference both just the bare board. So that is just this green portion of the board and then also what is called the PCB assembly which is actually the bare board. Then with all of the components
102:59
Speaker A
that are soldered and attached to the board. So, generally when people are talking about PCB, they'll use it interchangeably and they'll just call it the board or PCB. Um, and most frequently that will refer to the actual whole board itself, including all of the
103:15
Speaker A
components on it. I'm going to move our target router to the side here and show you an example of just a bare board so that we can look at some of the features of it.
103:24
Speaker A
So, this is called a helping hand. It's just good for holding electronics in place. I'm going to use it just to hold this board a little bit closer to the camera. All right. So, the PCB has two main functions. The first one is that it
103:37
Speaker A
holds all of the components in place. And it does that by we have these um items here. So, here and here and here.
103:45
Speaker A
And there's many of them on the board. And these are called pads. And the components like the resistors and the chips all get soldered to these pads and that helps hold them in place. So on this PCB we actually have two different
103:59
Speaker A
types of pads. The first one are is example is right here and these are called through hole and the reason for that is these are actually uh a hole on the board that have a metal ring of conductive material and the components
104:13
Speaker A
actually go through this hole and then are soldered in place. So you can see I don't know you can see I can actually poke the can actually poke through it here. The second type of pad that we have are these example right here. So we
104:26
Speaker A
have many of these ones as well. And there's no hole here. We just have a metal rectangle of conductive material.
104:32
Speaker A
And the components don't have any leads. They just get soldered directly onto these pads. And that's called a surface mount pad because the components are directly surface mounted on there. So I'll just flash up on the screen here
104:46
Speaker A
quickly to show you an example. On the left here, I have an example of a through hole resistor. These metal wires on the sides of it here are called the leads. And you can see here an example of it on the board. So the leads will
105:00
Speaker A
actually fold. These would be holes that they would slot through. So you can see some examples of those holes right here.
105:06
Speaker A
You push the leads through the holes and then they get soldered in place. That's why it's called through hole. And then on the right hand side, this is an example of a surface mount resistor.
105:16
Speaker A
Instead of leads, we just have these metal edges that are on the sides of it.
105:22
Speaker A
You can see here on the board, they actually just fit onto those pads that we were showing, and they get soldered into place that way. And there's no holes or anything. In commercial boards these days, you're going to be much more
105:35
Speaker A
likely to see mostly surface mount components. And there's many reasons for that. One, they can be made much, much, much smaller. You will see that on the actual router board. And then second, it's much easier to automate the process
105:49
Speaker A
of creating these boards. We can have machines much more easily drop these into place instead of having to bend the leads and push them through the holes.
105:58
Speaker A
And we'll take a closer look on our target PCB of the router as well at how those look. The second function of the PCB is that it actually electrically connects all of the components together to form the actual circuit. And the way
106:14
Speaker A
that it does that is with these green lines that you can see uh drawn on here.
106:19
Speaker A
So these are what are called traces and they are electrically conductive and they perform the function of wires on the PCB. For us as hardware hackers, this is quite important because we can actually start to visually inspect the
106:34
Speaker A
PCB and try and figure out what the circuit is doing and where the signals are routing on the actual PCB. One thing that does make this tricky though is that modern TCBs now have many layers to them. So of course with these traces for
106:49
Speaker A
example like these ones we're not actually able to uh route through them. So if we wanted to cross through here for example we cannot route through these traces. So what we have done in modern PCBs is we actually make them
107:02
Speaker A
multi-layer and that way we can have traces buried in the middle of the PCB and we can also have traces and components on the back. So I'm just going to quickly flip this one over to show you how that looks.
107:20
Speaker A
Okay, so looking at the back of this PCB, you can see that we actually have some traces that are just visible on the back that are connecting um some of our pads. And we also, for example, here this F1, this is a fuse. So we can see
107:32
Speaker A
that it actually uh is only on the back as well. And then the last thing that I want to show here that is really important and unfortunately makes our lives kind of tricky as reverse engineers is we can see that we have
107:46
Speaker A
this D1 here. So, diode one. And you can just make out the traces here, but they don't seem to go anywhere. They just go to these very tiny metal holes that are not actually uh through hole pads. And
108:02
Speaker A
if I just flip the flip the PCB back over. So, if you just keep in mind where this is on the PCB. So, when I flip it over, can see now this is where that was. And there's no traces or signs of anything.
108:20
Speaker A
And we only just have these two metal holes here. So what these are called is they're called VAS. And VAS we can think of as traces that go between the layers.
108:30
Speaker A
So they actually um take the trace and then they transport that electrical signal. So these have conductivity and then they go to layers. So on this PCB that diode's traces, they actually go up and only into the middle layer of this
108:46
Speaker A
which we're not able to see. So that does make it a little bit more challenging for us to reverse engineer.
108:52
Speaker A
However, there are ways that we can get away from this. So just to demonstrate what the VAS look like, I'm going to pop up on the screen here a quick image and chat about them briefly so you can see
109:04
Speaker A
uh in 3D what they look like. On the left here, I have a sample PCB where we can see in the top we've got the assembly. And then on the bottom, just to show what it would look like
109:15
Speaker A
without the components soldered on, we can see just the bare board with the pads. Now, on this board, we have some VAS as well. So, we got a few VAS here, and you can see what those look like on
109:27
Speaker A
the bare board. So, what this would look like if we just do a break apart of this into kind of a 3D look, I've done a drawing. These aren't actually like all of the traces that you'd see on this
109:39
Speaker A
PCB, but just to give you an idea, the VAS run down between the traces. So, there's an actual like metal connection, like metal pipe, you can also almost think of it, and it brings those connections from one layer down to the
109:54
Speaker A
other. And then we can route these circuits. So, this one I've drawn with three, but we can get many, many more layers in actual production PCBs.
110:04
Speaker A
Okay, so we're back here with the target router PCB and I'm just going to lift it out of this bottom part of the enclosure. So, it can just lift right out. There's nothing that's actually holding it in. It's just resting on a
110:15
Speaker A
couple of pegs here. All right. So, I'm just going to lift it out. And then the only thing that's actually uh attaching it is these wires which go to the antennas. So, if we're just gentle, we can lift it out though to work on it.
110:26
Speaker A
And what I'm going to do is I'm just going to quickly put it on the helping hand so that we can get a closer look at the PCB itself.
110:34
Speaker A
So, unfortunately, our target PCB is a little bit more complex than the one we were just looking at. But in case you're getting intimidated by taking a look at this, do not worry. We don't actually need to know everything about this or
110:48
Speaker A
how it works, there's just a few key points that we're going to start taking a look at and learning to identify that are going to help us along our journey with hardware hacking. Now, the couple things I just wanted to show here are
110:59
Speaker A
we're on this board. we are mostly surface mount components and they are so tiny on this board that it is actually very hard to even see some of them uh even on this 1080p camera it's hard to get them in focus of course so we've got
111:14
Speaker A
our chips here and they are surface mount they just rest on top and then they're very hard to see but all of these little items here are actually components so we've got capacitors uh resistors all tucked in there in their
111:28
Speaker A
little surface mount packages Here's a couple that are bigger. And it's really really hard to show these cuz they're they're so small. I'll just put my finger in for reference so you can see like I could fit almost all them on the
111:40
Speaker A
tip of my finger here. Now, we do have a couple throughhole components. So, we've got um these LEDs here that are through hole and then our capacitor that's through hole. And generally things like, you know, your push buttons and these
111:55
Speaker A
Ethernet ports are also throughhole. And the reason for that is one of the advantages of through hole components is they actually hold things in place much better. So for bigger items that might be able to get bumped or we're going to
112:07
Speaker A
be plugging them in and out, you'll usually see through hole used. And I'll just quickly flip the board over so you can see what that looks like on the back.
112:16
Speaker A
So you can see on the back of this, this is actually where these components, their leads stick through and they are actually soldered through those through holes.
112:26
Speaker A
That wraps up this first look at PCBs. I'll see you over in the next lesson where we're going to break out our multimeter and start doing some testing on our PCB.
112:36
Speaker A
Welcome everyone to this video where we're going to be chatting about digital multimeters. I've got the one here that we're going to be using in the course and in this video we're going to be taking a look at it. So digital
112:47
Speaker A
multimeters are arguably one of the most important tools in both an electrical engineer and hardware hacker's toolkit.
112:55
Speaker A
And the reason for that is they are kind of like a Swiss Army knife. They're called a multimeter because they actually perform the function of what used to be multiple meters. So in order to measure voltage in the past we used
113:09
Speaker A
to use what was called a voltmeter. And to measure current or amps we use what was called an ampmeter. And then to measure resistance or ohms, we would use what's called an ometer. So these digital multimeters are able to combine
113:21
Speaker A
all of those measurements plus a couple other functions that we're going to chat about in this video.
113:27
Speaker A
So this meter that we're using in this course, I've selected because it is relatively inexpensive while still being quite accurate and having some great features to it. And it has all the features that we're going to need for
113:38
Speaker A
this course. The one thing that it doesn't have, which you will start to see on more expensive meters, is what's called either auto ranging or autoscaling. So, what that means in that we don't have this auto ranging or autoscaling is that
113:53
Speaker A
we actually have to pick the scale that we want to measure on. Um, so I'm just going to pick this up to show an example of it. All right. So, if we take a look for example here, um, we can see how we
114:04
Speaker A
can make the ammeter measurements. So, this a symbol stands for the ammeter. And then we already know that this symbol here is for direct current. And if we want to make a measurement, for example, that is in the 0ero to 2,00
114:16
Speaker A
micro amp range, then we can use this one. And then if we're going above that 2,000 micro amps, and we're at this 20 milliamps or below, so between this 2,000 micro amps and 20 milliamps, then we would use this measurement. And then
114:29
Speaker A
so on all the way up to the 10 amps. So same thing down here, we have the ohm symbol. So this is where we can use it in the ometer mode to measure resistance. And we can measure the
114:39
Speaker A
resistance all the way from you know 1 ohm up to 200 ohms here from 200 ohms to 2 kiloohms and then all the way up to the 200 megga ohms. Okay. So for voltage we are up here and this is the symbol
114:52
Speaker A
for volts DC. Again same idea with those ranges. And then finally I'll just show you here the symbol in these two measurements. So these are for measuring um volts and alternating current. And we're not going to be touching those in
115:05
Speaker A
this lesson, so no need to use it. So to make measurements with our multimeter, we are of course going to need probes. And these are what are called the probes or sometimes people call them leads. And the way that these
115:20
Speaker A
work is we're able to press these metal leads onto the components or wherever doing our testing and we can make a measurement. And then of course the other end of them. So these ends actually plug into our meter.
115:34
Speaker A
The first one that plugs in, and you guys can do this if you're following along, is the black one, goes into this one, which is labeled comm. And that comm stands for common ground. So this is where the ground goes. And of course
115:45
Speaker A
our black is going to be that. So I'll just plug it in right now.
115:50
Speaker A
All right. And now you will see that we do have two areas where we can plug in the red one.
115:57
Speaker A
And if we look at the first one, it says here volts, ohms, milliamps, and then this squiggly line, which is for our function generator, which is another feature that this multimeter has. And that's where we're going to be using it
116:10
Speaker A
for this course. However, just so you're aware of why we then have one here that says it's for measuring 10 amp max.
116:18
Speaker A
The reason for that is we see here it says fused. So internally on this multimeter, there is what is called a fuse. And what the fuse does is it protects the internal circuitry from if we uh measure a current or something
116:30
Speaker A
that's going to put a current too high through the internal circuitry and it would damage that. Instead, we have the fuse in line and when that current that's too high goes through the fuse, it will burn out the fuse and stop the
116:42
Speaker A
current from flowing. And the fuses are really cheap. It's easy to replace them so we don't actually break um our internal circuit or burn it out. Now the fuse for this one is fused to allow the um milliamps. So we can see here if you
116:57
Speaker A
take a look closely this one is fused at 500 volts max or 500 milliamps. Uh so for everything in this course that's going to be perfectly fine for us. However, if you were you know doing this 10 amp current reading
117:11
Speaker A
here on the ampmeter section you would need to unplug from here and plug into this one. And then we get access to that bigger fuse that's going to allow that measurement. Again, we're not going to be working with anything that high in
117:22
Speaker A
this course, so we don't need to do that. We can just plug it into this one.
117:27
Speaker A
I'm going to do that right now. Plug the red one. All right. And then you can just leave it in these two for the rest of the course. That's all we'll need.
117:37
Speaker A
Two other features that I want to show on the front of this. So, we do have a light here. Now, if I just turn it on here, and then if we push this, then we get a light that lights up. The other
117:46
Speaker A
thing that we have is this button, which is a hold. So, if you're taking a measurement um and you just want to not have to write that down or remember it for a second, if you push this hold
117:54
Speaker A
button, then instead of measuring anymore, it's just going to lock what's on the screen. So, you have that saved.
117:59
Speaker A
Last thing I'll show is on the back, it actually does open up. So, internally of this, there's a 9volt battery and that's what used to power this. If it does die or it stops working, that's where you replace this. And also, the fuses are
118:12
Speaker A
internal in here. So, if you ever blow out a fuse, you can replace it from in here. All right. Finally, one last thing. So, you might hear the digital multimeter referred to as DMM, that abbreviation for it. And I might say
118:23
Speaker A
that a few times as well, cuz it's pretty common to hear that. So, just want to make sure you're aware of that.
118:28
Speaker A
That wraps up this video and I'll see you over in the next one. Welcome everyone. In this video, we're going to be taking our first measurements with our multimeter on the TPLink router board. However, before we get started with those measurements, I
118:45
Speaker A
just really want to quickly show you something important uh and another very important tool, and that is our notebook. So, in this course, I'm going to be taking notes in a paper notebook.
118:55
Speaker A
And this is what I usually do when I'm working on electronics because I may not always have my computer handy. And sometimes I find it very useful to just have a paper notebook because you can also draw circuits or other just quick
119:07
Speaker A
memos in it. Now, I apologize for my very bad handwriting. Uh, but I want to just quickly show you what I have started with writing for notes for so far what we're testing with this TPLink router. All right. So, I've put the
119:20
Speaker A
target here and I've got the router model number and the name of the manufacturer here. So, we have this TPLink TLWR841N.
119:29
Speaker A
And then also very importantly, I have the serial number here. And this is important because if we're testing multiple routers or multiple targets of the same one, then we need to identify what the actual one that we are testing
119:42
Speaker A
on in case we do any damage to it or something happens, we can actually trace back with our testing and see which model and which actual serial number to trace back to that physical piece of equipment. I've also included dates. So,
119:55
Speaker A
I'll be adding these dates in as well so we know when we're doing certain things.
120:00
Speaker A
And I have the first action wrote down here. So, the first thing that we've done is open up the router case with the spudger and visually inspected the PCB.
120:08
Speaker A
And now, as we do more testing, I'm going to be adding these actions and taking notes in here. So, feel free to take notes however you would like. If you prefer to take it, you know, in Oneote or Cherry Tree or some other type
120:20
Speaker A
of digital note-taking app, then go ahead. That's totally acceptable. My preference is just to take these paper notes when I'm doing the measurements.
120:27
Speaker A
All right. So, we'll be coming back to this throughout the course. And then we'll also be visiting these notes when we write up our final report. Just going to put this out of the way and then grab the things that we're going to need for
120:38
Speaker A
taking our first voltage measurements. Okay, so to take our measurements, we are going to need, of course, the router with it opened up cuz we're going to actually need to be probing internally on the board. We're going to need the
120:50
Speaker A
router plugged in for this. So, we will need the power supply. And then we're also going to, of course, need our multimeter. A quick reminder on safety that we're just going to be plugging in the power supply when we need to and
121:02
Speaker A
then we'll unplug it when we don't need it. Just to quickly show you where we're going to be measuring. A lot of times on these boards, if we're measuring the throughhole components, which is what we're going to be starting with, it's
121:12
Speaker A
actually easier to probe them on the bottom. So, I'm just going to flip this over. It just lifts out like this. And then we can flip it over.
121:20
Speaker A
And if we look at the back, we can see again like we identified before, these through hole components. And that's where we're going to be doing the testing. Now, I'm going to be using what's called a third hand to hold this
121:31
Speaker A
up. And it's just a little bit easier to film. You don't need to use one if you don't have one. You can just rest it on the router case like this and do the probing as well. So, I'm just going to
121:39
Speaker A
quickly set up that third hand. And then we'll jump over to testing. I've got everything set up now. And just to show you before we plug it in, the first measurement we're going to be taking is to verify the input voltage. And this is
121:50
Speaker A
something that is always good to test before we do any further testing. Now on the router here, we know we have this input jack right here. So right here and this is where the power supply plugs in.
122:03
Speaker A
And then it is a through hole component. And these are the two pins that come through and are soldered. So we can test the voltage by measuring the drop across these two pins. And on this router, I already know this is the positive one
122:16
Speaker A
and this is the negative one. So we'll put the red lead here and then the black lead here. And that's how we can test.
122:22
Speaker A
and I'll show you how we can how we could figure that out. All right, so I'm going to get the meter set up first. All right, so since we know that we are at looking around 9 volts, I'm going to set it to this 20
122:35
Speaker A
volt DC setting that I have uh here and we can use that for measurement. And I think now that we know where we're probing and we have our meter set up, we can plug it in.
122:54
Speaker A
Okay, so just a little bit out of the shot here, but I can see the lights are starting to light up. Perfect. So I know that we have the power on and we're ready to take our measurement.
123:07
Speaker A
Move this here so it's a little bit more visible. And red lead goes to the top one and black lead goes to the bottom one. And we just press it there.
123:18
Speaker A
All right. And we see it stabilized there at around 9.25 9.26 volts. All right. So if we had them backwards and we So we just want to identify what it would look like if it's backwards. Um, if I do put the positive
123:32
Speaker A
or the red one on this the wrong lead, then we'll see that we actually get a negative measurement. So, that's how we can tell which one is the positive and which one is the negative. And that's important because on this circuit, all
123:47
Speaker A
of our return current is going through this negative end. And we can think of that as being the ground. So, we'll come back to that later.
123:56
Speaker A
So to take these voltage measurements, what we did there is we actually connected the digital multimeter in parallel to make these measurements. And just to make that a little bit more easier to read, I'm going to move this
124:08
Speaker A
uh third hand out of the way and I'll show a quick drawing of the circuit.
124:14
Speaker A
All right, so I've got a drawing here just to quickly illustrate how we're taking that measurement. Now, I've got right here a bad drawing of that input jack. We've got the positive and negative leads of it and then it flows
124:25
Speaker A
through and into the rest of the circuit. Now, what this is called or how I'm representing this is a blackbox equivalent. So, we don't care necessarily about what's in that circuit at all. I'm just showing that, you know,
124:38
Speaker A
the power or the current flows through out of this jack and then it goes through to that whole rest of the circuit, which we don't care about. Now in order for us to take the voltage measurement in parallel what we did is
124:49
Speaker A
we attached these the probes to if we can think of it sorry this way these ends and took that measurement and now if I just set these down to kind of illustrate what we've done when we do that test is
125:05
Speaker A
the power is able to split that's why it's in parallel so our current comes out of the positive end and it can split at this node of course and go through our meter And then also most or if not
125:16
Speaker A
almost all of the current goes to the router circuit. And that's how we take that measurement in parallel for measuring voltage.
125:25
Speaker A
When we are measuring voltage with the multimeter, it has what is called a very very high input resistance. So the resistance internally that's making this measurement is very very high. And what that does is that it allows us to not
125:39
Speaker A
affect the rest of the circuit while we're taking that measurement because we barely take any current to measure that voltage.
125:47
Speaker A
For voltages, which is what we're going to be probably measuring the most on circuits, it's very easy to do. All we need to do is just find the two leads of the component we want to measure the voltage drop over, and we just touch the
125:58
Speaker A
red to the positive and the black to the negative, and we'll get our voltage reading. I'm going to take this drawing away and put the router board back on the third hand. And I'll give you a quick challenge to take a measurement on
126:10
Speaker A
your own. Okay. So, at the very top of this board beside this orange flashing LED, there is a green one that is on constantly. And if you just power it on your board, it does take a few seconds
126:21
Speaker A
for it to come on constant like that. But what my challenge is or what you can pause this video now and do is try to take a voltage measurement of this and make sure you get it to be a positive
126:32
Speaker A
reading. Uh just a hint that of course the leads that come through this is a through hole component. So the leads are on the back you can measure it on the back or if you want you can actually
126:41
Speaker A
measure it on the front. So pause the video here and find out what the voltage drop over that LED is.
126:48
Speaker A
All right did you get it? Let's take a quick measurement and see what I get for the reading of that voltage. Again, I've got mine set still on this 20 volts, which is going to be okay for reading
126:58
Speaker A
this measurement. And I'm just going to touch the two leads here. All right. And I am getting mine at 1.94 volts, which seems about right for this green LED. Again, if you flip these and put it the other way, then you're going
127:14
Speaker A
to see the same reading or similar reading but negative. There are a few other areas on this board where you can measure voltages.
127:25
Speaker A
One of them, a good one to check is the capacitor. Um, so I'm going to stop this video here, but if you want to practice a little bit more, then I think it's a good idea to go through and check some
127:35
Speaker A
of the voltages across other components. can start with the capacitor which the leads are right here.
127:42
Speaker A
That wraps up this video and I will see you in the next one. Welcome everyone to this video on using our digital multimeter to measure resistances or use it as what is called an ohm meter. So on our multimeter we
127:57
Speaker A
are able to measure resistances in the range of all the way from 0 ohms at the 0 to 200 ohms all the way up until this 200 megga ohms. So, we can actually measure a pretty wide range of
128:09
Speaker A
resistors. Now, on our board, unfortunately, the resistors, they're just too small to be able to accurately um get in and take a resistance measurement with these probes. They're too big, these hand probes, to actually measure those very small surface components. And I will
128:25
Speaker A
show later in the course one way that we can take measurements on these small surface mount components. But, we're going to need uh some different equipment. for this lesson just to demonstrate I do have two bags of resistors here that I will show on how
128:38
Speaker A
we can measure. All right, so the first one I've got here is we have a 680 ohm bag of resistors and you see they have one quarter watt rating and they're guaranteed to be within this 5%. So we
128:50
Speaker A
can double check and make sure they are actually at 680 ohms or within that 5%.
128:57
Speaker A
All righty. So, I'm going to set the multimeter to the 200. They will go up to the 2,00 ohm setting, and that should give us a good reading.
129:09
Speaker A
All right. And on these leads, um, you can see there's actually a little ledge in the resistor. Leads just fit nicely into that little ledge. Um, so I'm just going to fit mine in here. All right.
129:23
Speaker A
And if I move my hand out of the way, so we can see that this resistor is measuring at 672 ohms. So we are about 8 ohms off of what the baggie is saying, but that's okay cuz we're within that
129:34
Speaker A
5%. All right. And I've got another bag here that I'm just going to pop open.
129:40
Speaker A
Okay. And this one, actually, I'll just show first. So this one's at 6.2 kiloohms. Again, 1/4 watt and 5% tolerance.
129:52
Speaker A
So same thing. I'm just going to put it into the ledge here that is on these leads.
129:59
Speaker A
And we can just hold it in place. All right. And you'll notice when I do this one, so on our um so on our multimeter, we are just reading one. And the reason for that is this is a 6.2
130:13
Speaker A
koohm resistor and we're just in this up to 2,000 range. So we're over that range. Um, so what I'm going to do is I'm just going to switch it to this 20k range. And then we should be able to
130:23
Speaker A
take our measurement. All right. And if we hold it here, just going to make sure I'm holding it tight to get a good reading.
130:33
Speaker A
Okay. So, we can see that this one's actually off by quite a bit. Um, so we're at 6 point, you know, hovering around 6.03 kiloohms when it's supposed to be a 6.2 koohm resistor. So, we're still within that 5%, but just wanted to
130:47
Speaker A
show how these can vary off by a little bit. Okay. So, if you don't have any of these resistors at home, that's okay. I don't expect you to. Um, but if you do want to make a measurement with your digital
131:00
Speaker A
multimeter to check some resistances, then one thing we can do is we can actually measure the resistance between our hands through our body. We were chatting about in the safety lesson how our bodies actually have quite a high
131:12
Speaker A
resistance. And I just want to show you how you can make that measurement. So I'm not entirely sure what mine are, but I'm expecting I have dry hands and I do have some calluses on my fingers. So I'm
131:20
Speaker A
going to start at the highest reading at 200 megga ohms and if we have to, we can move down from there. Um, so I'm just going to switch mine to this 200 megga ohms.
131:29
Speaker A
What I'm going to do is I'm just going to grab the probes pretty tightly here and we'll see what it goes to. All right, so mine is going to this 1.3 and we know that's in mega ohms. So that's
131:39
Speaker A
1.3 megga ohms. Um, so that's the resistance through my body right now, which is pretty cool that we can measure it as that 1.3 megga ohms.
131:49
Speaker A
I'm just going to lick my fingers here and see how that changes the resistance.
131:58
Speaker A
Okay, so I just licked my fingers to get them a little bit wet. And we can see that even already that's bringing um down the resistance value a bit. And if we if I got them even wetter, then we
132:07
Speaker A
would be able to bring that resistance down even more. So, kind of cool to see that on our board. Unfortunately, as I mentioned before, it was hard. It is too hard to measure the resistance values with these probes. There is some value
132:22
Speaker A
to taking resistance measurements on the board. Sometimes, if we're trying to do reverse engineering and figure out what value resistors are, or if we're trying to match a schematic to a board that doesn't have good markings on it, we can
132:35
Speaker A
kind of identify um the areas of the board by looking at the resistance. If you are making resistance measurements on a board and you actually the resistors are big enough you can probe it, it's best practice to take
132:46
Speaker A
resistance measurements with the board powered off because that way the current that's running through the circuit will not throw off your resistance measurements. Of course, the way that this guy takes resistance measurements is it actually uses a low voltage itself
133:00
Speaker A
and then based on the amount of current that's able to flow, it's able to tell the resistance. So, we don't want to throw that off by having the board have its own current going through it. And also just good safety practice to have
133:12
Speaker A
it off. That wraps up this lesson on using the multimeter as an ohm meter or to measure resistance. I'll see you over in the next video.
133:22
Speaker A
Welcome everyone. In this video, we're going to be taking a look at another one of the very important features of our multimeter, and that is to take a continuity test. So, if I just bring this up closer to the camera to use the
133:35
Speaker A
continuity feature, we actually move this rotary dial to this little symbol right here. And you can see that it's got this marking that looks like it's making a sound. And that's because a lot of people also refer to a continuity
133:47
Speaker A
test as beep testing. And we'll see why in just a second. So, I'm going to switch my row. So, I'm going to switch my meter over to the continuity test setting. And we have it here. And what the continuity test means or tests for
134:02
Speaker A
is that we have electrical continuity between the two points in this probe. So of course if we are able to just touch these together, we'll see that it starts to give us this nice beeping and that indicates to us that there is a path for
134:17
Speaker A
electricity from this probe to this probe, which is something that's very important to be able to test on circuits. Just to give you another idea of what I mean by that, of course, we've got I've got this alligator clip here,
134:28
Speaker A
which is essentially just a straight wire. And if I connect it to this red probe, and then as soon as I touch it to this probe, we get the beeping again because electrical signal or an electrical current is able to flow
134:41
Speaker A
between these two. Now, this is maybe honestly the most important tool and what I use my multimeter for the most when I'm hardware hacking. And this is because this allows us to be able to tell where signals or currents are flowing on the
134:57
Speaker A
boards, especially if we don't have a schematic. We can do what's called beeping it out. So we can, you know, touch from different pins on things like chips to output pins and determine where those are going on the circuit. And we
135:10
Speaker A
can also trace through VAS. So you remember when we were looking at the board, we have those VAS that go down to different layers. So if we're trying to figure out, you know, our signal disappears down a via, then we can go
135:21
Speaker A
and probe the other VAS and trace where that signal is coming through. So now that we have a little bit of an idea about how this beep testing works, I'm just going to move this to the side, bring the board back, and show a few
135:33
Speaker A
areas that we can beep out or start testing on the board. I've got my board upside down here because I do want to make a connection from this ground that we already identified when we were measuring the voltage because one of the first things
135:49
Speaker A
that I'm going to beep out or check is see if I can identify any other grounds on the board. And you don't necessarily need one of these alligator clips or this third hand to do this. Um, I could
136:01
Speaker A
do it without it, but it's kind of hard to show on the camera or film. So, what I'm going to do is I'm actually going to connect this alligator clip to here. And then I don't have to try and reach under
136:12
Speaker A
the board. Uh, and I'll just leave that connected. And I'm just going to flip this board over now.
136:25
Speaker A
All right. So, I've got the board flipped over, and again, I have connected this green jack to the underside of the negative pin on this input voltage jack here. And you can do it by just putting the probe underneath
136:38
Speaker A
here. It's just kind of a pain to film. So, that's why I have this alligator clip. The other thing that I just want to quickly call out in case you didn't notice is we don't have any power supply
136:47
Speaker A
to the board. I have it completely unplugged. And when we're doing these beep tests, we don't want any power. We just want to be checking for the continuity or the electrical signal that comes from our multimeter. So, we'll
136:58
Speaker A
leave the board powered off. I'm going to connect the black end to this here so that it's connected to ground. And when I was visually inspecting the board, and this is something that you'll get used to, I did
137:12
Speaker A
identify this interesting top piece of bare metal pad here. And you generally won't see these bare metal pads left on a board like this unless they're connected to ground. One of the reasons for that is they just can become an
137:28
Speaker A
antenna and add noise or interference. So when I saw this, it stood out to me that I thought that this was ground and I just want to verify that now with the continuity tester. So when we touch to
137:39
Speaker A
this, see that I immediately get a beep and that does confirm for us that that is ground. So, what I'm going to leave as a challenge now for everyone. So, if you want to pause the video after this,
137:51
Speaker A
is to just go through the board and probe out and see if you can find um any other grounds on the board. There's one that's actually labeled. So, you know that there's an easy one, but there's a couple other grounds on here. So, I'll
138:04
Speaker A
just pause it now and see if you can beep out and find some of the grounds.
138:13
Speaker A
All right. Did you find any? I'm just going to show a few of them. So I know for example that there is one over here I believe.
138:28
Speaker A
Yeah. So we know that we have a ground point over here. And then of course we've got one labeled over here that is a ground as well. And we're going to be coming uh back to these guys later because they are going
138:41
Speaker A
to be quite important later on. So, that just goes to show how we can start to test beeping out and checking for continuity. We're going to be using this a bit more throughout the course and helping us to identify where
138:55
Speaker A
different pins and different connections travel on the board itself. That wraps up this lesson and I will see you over in the next video.
139:06
Speaker A
Welcome everyone. In this video, we're going to be chatting about taking a current measurement with our multimeter or using it in the ammeter setting.
139:16
Speaker A
Now, as hardware hackers, it's not as important to be able to take a current measurement. And unfortunately, it is actually pretty difficult to do on a circuit board. And the reason for that is that opposed to how we measured the
139:31
Speaker A
voltage in parallel by measuring you know just across the leads or the pins of the component in order to measure current we actually have to insert our meter in series in such a way that all of the current is going to actually
139:46
Speaker A
travel through the meter. So we take a look back at our original drawing that we did before where I was showing how to measure the voltage in parallel. I've put a break in that circuit here. And if we wanted to measure current, so we'll
140:00
Speaker A
set it to this, I don't know, 200 milliamp reading here. Then we would actually have to put our positive lead here and our negative lead here. And then all of the current, it has nowhere to go. So if I just kind of rest these
140:12
Speaker A
down, you think of them connecting to those points. Then all of the current is going to flow into the positive lead.
140:18
Speaker A
It's going to go all the way through our meter, back out the black one, and then travel through the circuit, and then back to ground.
140:26
Speaker A
So opposite to our input resistance being really really high when we're measuring voltage because we don't want any current to come through and alter the circuit. It is the opposite when we're taking a current measurement. And our input impedance is very very low.
140:42
Speaker A
It's generally in the single uh digits of ohms. And the better your meter is actually, the lower that resistance is cuz we don't want to be having any voltage drop over it and affecting the rest of the circuit by putting something
140:54
Speaker A
in series. So, this is the reason that I'm chatting about this even though it's not something we're going to be taking any measurements with because this is how it's the easiest to actually damage the meter or blow a fuse. Now, the
141:07
Speaker A
reason for that again is the input impedance or input resistance of this is extremely low. So, if we were to close this circuit, so we just draw this closed circuit and we were going to, I don't know, try and
141:22
Speaker A
measure the current that's coming straight out of that jack. And we're just curious about it. Um, and we set, you know, this to our 200 milliamps cuz we know that it's we think it's going to be around that. And we were to just then
141:35
Speaker A
touch our leads here. So, positive and negative. Then I'll just draw out what's going to happen on this circuit. I already took a measurement and I think in the manual if you read this, it's going to tell you what the input
141:47
Speaker A
impedance or the input resistance is. Um, and when I measured it, it was just around 4 ohms. All right. So, I'll just draw out the circuit. We'll say that this is the probe and it's coming down.
141:59
Speaker A
Um, and this resistor will signify our actual multimeter in that current reading setting. and it was 4 ohms.
142:11
Speaker A
I can tell you right now the impedance of the circuit is going to be much much greater. So what's going to happen is when we get our current flow here, it's almost all of it is going to go
142:22
Speaker A
through this top route and it's going to come down our through our meter. Now, if you just do the quick math on this, 9 volts 4 ohms, that is going to give us a current of 2.25 amps, which we already know is much greater
142:42
Speaker A
than our meter is fused for. So, we're just going to blow that fuse immediately. And it's really easy to blow these fuses taking the current measurements if we're not doing them properly and we are doing them in parallel. So, I just really wanted to
142:55
Speaker A
quickly call that out. Now again, so the reason that this is really challenging to take these measurements on the board is we actually need to break the electrical path or the signal path um that that current is taking. And there's
143:09
Speaker A
no really good way for us to do that on a circuit board without actually damaging it. So if we wanted to, for example, interrupt the trace, then we would have to actually, you know, we could take a knife and cut that trace.
143:20
Speaker A
Um or we could, you know, cut off the end of a component and lift it up and then try and connect between that. So, there isn't really a good way to take a non-damaging measurement, and that's why we're not going to be taking any.
143:33
Speaker A
As hardware hackers, this isn't super important. Um, and just a quick reminder, of course, of Ohms law, and that we can usually calculate the currents as needed quickly mathematically. So, I did want to just really quickly demonstrate, you know,
143:45
Speaker A
how you can use the multimeter uh to take a current measurement and just how to do it properly without just using this picture. So, what I'm going to do is I'm going to bring over a quick little very basic circuit and show how
143:56
Speaker A
we can actually take a measurement. Okay. So, what I've got here, this is called a breadboard, and it's used for prototyping circuits. Um, so the way that it works is that on these lines that run uh perpendicular to the length
144:10
Speaker A
of it, these are all electrically interconnected. Um, so I have the power coming and it travels through this whole top line. And then I have the ground on this battery and it travels through this whole line right here. So what I've done
144:23
Speaker A
is I have the LED, the positive end of it comes out to this line here and then the resistor is in another hole. So that means there's a connection here. And then when I tuck this into the ground,
144:36
Speaker A
you can see that the LED lights up. So very very basic circuit. Now, if we want to measure the current from this, what we can do is I can again break this connection.
144:46
Speaker A
And we're just going to grab a couple alligator clips and I'll show you how we can put this meter in series.
144:53
Speaker A
Okay. So, what I've done is I've just broken that connectivity in that circuit and I've connected the alligator clips to each end. So, if I touch these together, we should see this light up.
145:02
Speaker A
Yep, perfectly. It lights up. All right. So, if I put the positive end of our ampmeter in through here and then if I connect through here, this means we have it in series. And we're looking at about 11
145:17
Speaker A
milliamps flowing through this. So, that's how we take that. Again, we if this were on a circuit board, it would be really hard for us to do this because we would actually have to, you know, either desolder these leads and pull
145:27
Speaker A
them out or maybe cut them and then use some sort of jumper. So, there isn't really a good non-destructive way to do it. Before I wrap up this video, just a really quick reminder to be careful when you're taking current measurements. Make
145:40
Speaker A
sure you're sure you have it in series because it is the easiest way for us to blow a fuse or damage our equipment. So, that actually wraps up this section and wraps up electrical engineering for hackers 101. So, great job on making it
145:55
Speaker A
this far. I will see you over in the next video where we will start over in the electrical engineering for hackers 2011 section and we're going to expand on some of these fundamentals and look more in depth at some of the principles
146:09
Speaker A
that we'll need to know for our hardware hacking. Thanks a lot. See you in the next video.
146:15
Speaker A
Welcome everyone to the first video of electrical engineering for hackers 2011. In this video we're going to be talking about alternating current and direct current. Now, in the first 101 section of this course, we actually already have been talking about direct current and
146:31
Speaker A
all of the circuits and everything that we've been looking at. All the formulas have been in reference to direct current. In this lesson, we're going to be adding in alternating current and talking about the difference that this has between direct current and some of
146:45
Speaker A
its important properties. Now, I think using current to describe these is a little bit confusing. And the reason for that is when we're getting power from a power supply, the voltage being supplied is set by that supply and
146:59
Speaker A
then the current is actually proportional to that voltage. And we know that the current is going to be proportional to the voltage and the resistance in the circuit. So I think it's a little bit easier to think of
147:11
Speaker A
this as direct current actually meaning a fixed voltage and then alternating current. What that means is that we actually have a fluctuating voltage. And just to give a little bit of a representation of what I mean by that,
147:24
Speaker A
we're going to go back to this very first image or pictographic representation of a circuit where we have this voltage and the voltage creates a current that goes through our circuit and through our light bulb. And if we look at this as a direct current,
147:40
Speaker A
so in our example, that would be a fixed voltage. One way to actually represent this voltage that will make more sense with these alternating current is in a graph. And on this graph, we would have voltage being the yaxis. So how much
147:55
Speaker A
voltage we have and then on our x-axis is over time. Now with a fixed voltage or a direct current, we can see that this just makes a horizontal line. So in this example, the voltage stays the same. It's just a fixed voltage. And as
148:10
Speaker A
we go through time, that voltage level is the same. Now we know due to Ohm's law that the current is actually going to be proportional to that voltage and it's also going to be a fixed level.
148:23
Speaker A
Of course the value that this current is going to be is proportional to this resistance. However, we know that it's going to be set unless the resistance change is going to be the same current level. If we change this though for an
148:35
Speaker A
alternating current. So we'll say that this is an alternating current. And I'm just going to bring up a marker here to draw on the graph what that might look like. So one example of alternating current that everyone is probably
148:47
Speaker A
familiar with is the voltage that comes to our house. And the way that this voltage changes over time can be represented with a sine wave. So the voltage comes up to its peak voltage and then it comes down to here. And of
149:02
Speaker A
course, if we represented the current at this point, it would come up to here and come down. And of course, this current again is going to be proportional to this resistance. But we know that as far as the graphs go, they're going to
149:17
Speaker A
follow the same shape. Now, what happens when we get to this point on this? So, once we actually start, you know, going the voltage into the negative, then the current is actually going to go into the negative. And we see at that point that
149:31
Speaker A
our voltage actually flips and then the direction of our current changes. So this is kind of where that alternating current terminology comes in because our current is now flowing the opposite direction. So of course if we finish this drawing,
149:46
Speaker A
it's going to look something like this. And our current is going to follow And in the sections where our voltage flips into this negative, of course, our polarity is going to swap here and our current is going to start actually
150:07
Speaker A
flowing in the opposite direction. So, one example of alternating current that everyone is probably familiar with is the power that comes into our house.
150:16
Speaker A
Now, in North America, this operates at 120 volts AC at 60 Hz. And we'll talk about what that means a little bit later in this lesson. Now, you may be wondering why I'm talking about alternating current if we actually are
150:29
Speaker A
not supposed to be touching anything with our household power or the power from our sockets in our house. And that is absolutely correct. Again, shouldn't be working on that. However, we do use this alternating current or fluctuating voltage for a lot of other very
150:44
Speaker A
important things in electronics. So, just to represent that, I'll show this graph here that represents a fluctuating voltage over time. So this waveform here that we have where it goes from this 0 to 5 volts is a good representation of
151:00
Speaker A
something we could see in an IoT device. Many sensors are very good at changing the voltage that they supply based on how they read something. An example of this could be a temperature sensor where as the temperature changes the voltage
151:16
Speaker A
that is output by that sensor would change. So we could see a change in a fluctuating value like this. So, I just want to bring up a second wave here that's going to help bring this point home for why these alternating currents
151:28
Speaker A
are important in our IoT devices and electronics. All right, so I brought up a square wave here and these are very important for how we do digital communications where we will have a high voltage represent a one and a lower
151:40
Speaker A
voltage represent a zero. And even though these are more what we call a square wave, they are still a type of alternating current. And as such they behave differently than if we just have a fixed voltage. So that is why it's
151:54
Speaker A
really important for us to learn a little bit of the fundamentals about how alternating current functions and changes things in our circuit. I'm going to go back to just a plain standard sine wave here so we can talk about some of
152:08
Speaker A
the important ways that we actually describe and measure alternating current. The very first one is what is called amplitude. So the amplitude is the distance between um the zero or the midle if it is going from positive to
152:23
Speaker A
negative to the top of the wave. So this would be the amplitude for this sine wave. The second one we'll talk about is the peak voltage. So this is the um highest voltage that's represented and it's actually the same as the amplitude
152:37
Speaker A
but sometimes you will hear it um called the peak voltage. So generally when we have a sine wave that is not fixed amplitude like the one we saw in the last the peak voltage will be the highest one. So the highest that it can
152:50
Speaker A
get. All right. The next one that we'll talk about is the peakto peak voltage which is VPP and that is the measurement of the top peak to the bottom peak. So it will be um double the amplitude.
153:04
Speaker A
The next measurement or calculation here that I'm going to show is not actually important for this course, but I just really wanted to show it out of curiosity. In case you're wondering, for example, at our household voltage, that's 120 volts AC. Um, which voltage
153:20
Speaker A
is that? Is that this peak voltage or this peakto peak voltage? Well, the answer is that it's actually neither of those. That 120 volts AC is actually what we call the root mean square voltage or RMS. And I'm going to quickly
153:36
Speaker A
show here how to do the RMS voltage calculation for a sine wave. Now, there is a bit of math behind this that I'm not going to show cuz it's outside of the scope of this course. So, just keep
153:47
Speaker A
in mind this is for a sine wave like we use in the North American household voltages. So to calculate RMS it is equal to the peak voltage divided by the square<unk> of 2. And we can actually approximate the square<unk> of 2 as
154:00
Speaker A
1.41. So the peak voltage for North America is actually 170 volt if you were to measure this actual top peak voltage.
154:09
Speaker A
And of course if we do 170 divided by 1.41 and this gives us just around 120 volt AC.
154:18
Speaker A
Now the reason we use this RMS voltage is because if you were to compare its equivalency in DC. So if we think back to our circuit where we have our light bulb uh and if we want to kind of think
154:30
Speaker A
about the brightness of the light bulb or the actual power delivered to that circuit the equivalent AC to DC would be the RMS voltage. So if you have 120 volts DC um then you want to compare this to AC then it would be equivalent
154:45
Speaker A
to that RMS voltage. So that's why we use um this RMS when we're talking about it. And if you ever see, you know, voltage for our household at 120 volts AC, you can know that that's actually in this RMS calculation. Again, we don't
155:00
Speaker A
need to know this for the course. I just thought some people might be curious about that. Okay, so I've brought up a square wave cuz there are a couple specific things we should talk about with regards to square wave. Now, the
155:12
Speaker A
frequency and period and amplitude that we talked about in sine waves, those are all going to be the same for square waves. However, since we do have this wave changed a little bit and how it's formed, there are some different
155:23
Speaker A
characteristics that we use to describe it. Now, the first one is the pulse width and this describes just how long um this like if we think of this as the on portion of the square wave where we're actually applying a voltage, the
155:35
Speaker A
pulse width is how long that pulse goes on for. So we see in this example of this first portion of the square wave, the pulse width is 0.1 seconds. And in this first section of the square wave, we have uniform between how long it's
155:51
Speaker A
off. So it's off for 0.1 seconds and on for 0.1 seconds. Um, and this whole section right here would be one period.
156:01
Speaker A
And then we would know that the frequency for this would actually be 1 over 0.2 two because our period is 02 seconds. So we would have a five Hz frequency.
156:11
Speaker A
Now what happens if we don't have this uniform square wave? So I'll just bring it up here. What happens if we actually um have like a longer resting period than we actually have our on period. Now the way that we describe this is with
156:24
Speaker A
what's called the duty cycle. And the duty cycle explains the ratio of the pulse width or the on duration to the actual resting period in that period. So it is a proportion. In our first example where we have this pulse width that is
156:40
Speaker A
equal to this resting period then we have a duty cycle of 50%. So the duty cycle which is represented generally with a uppercase D is calculated by the pulse width over the period duration. So for example in this one we have 0.1. So
156:57
Speaker A
the pulse width is 0.1 seconds divided by this whole period which is 0.2 2 seconds, which gives us 50%.
157:06
Speaker A
In most of the waves that we're going to be looking at for digital communications, we're just going to be working with a duty cycle of 50% and we're going to have that fixed pulse width. However, I just wanted to show
157:16
Speaker A
these terminologies because you may hear them come up and they're important to how we describe these square waves. That wraps up this lesson. I'll see you over in the next one. Welcome everyone. In this video, we're going to be taking a
157:29
Speaker A
look at capacitors and talking a little bit more about them. Now, we have already chatted a bit about capacitors in the safety lesson and then also when we opened up a router for the first time and we're looking at the PCB, there were
157:43
Speaker A
many capacitors that we would have seen on that board. And we haven't chatted about them fully in depth yet because we needed to have an understanding of alternating currents before all of their functions make sense. So now that we
157:55
Speaker A
understand about alternating currents, let's take a look at cow capacitors function. Okay. So I've got up on the screen here the actual schematic representation of a capacitor. And you'll notice that it is two what we see as like conductors or almost wires that
158:11
Speaker A
are parallel to each other. And we just have some air in between it. So it kind of almost looks like an open circuit.
158:16
Speaker A
And then we've got our leads connected to it. And the reason for that is this actually mimics the construction of an actual capacitor. So if we take a look here at a cross-section of a certain type of capacitor, which we call a
158:30
Speaker A
ceramic disc capacitor or just a ceramic capacitor, you'll notice that on the inside we have what's called the electrode. And it's just a large metal plate with a big surface area. See, we tried to make it as thin as possible and
158:44
Speaker A
make the surface area as big as we can. And this is connected to the actual leads here. And if we looked on the other side coming to this lead, there would be an identical plate to this one.
158:56
Speaker A
And then it's actually uh sandwiched in between we have this ceramic disc. And the ceramic material is what we call a dialectric. And what this means is that it is does not actually conduct any electricity. So, it doesn't allow any
159:10
Speaker A
electrons to flow through it, but it's very good at holding these electric charges on the outside of its material.
159:18
Speaker A
And this is super important for how the capacitor functions. To better understand and see this in action, let's take a look at it in a circuit. I've got a very basic DC circuit here with just a 9V DC power
159:32
Speaker A
supply and a switch that's closed and a capacitor in series with that. So what's going to happen in this circuit when we throw this switch closed is that we will initially get some current that travels through and in this DC circuit what's
159:48
Speaker A
going to happen with those electrons is they're actually going to pile up on those electrodes or plates. And because we have this dialectric in between here, they're not actually going to be able to flow through to this wire. So we will
160:00
Speaker A
get an imbalance of those charges piled up on these plates here. And when we get that steady state and the capacitor is what we call the charge state, then we'll get the matching voltage across this. So if we were to measure the
160:13
Speaker A
voltage over this capacitor, we know of course because of Kaw's voltage law, it's actually going to be that 9 volts.
160:20
Speaker A
And at that steady state, we'll actually get no current through here. Now, of course, in a real life scenario, we wouldn't just hook a capacitor up like this because it really has no function.
160:30
Speaker A
It's basically just creating an open circuit for us. So to give a better representation of what they're actually used for, let's take a look at a more real life applicable scenario.
160:40
Speaker A
So I've added into our circuit here this 350 ohm resistor and an LED that we're going to be lighting up. And let's say in this circuit um the switch is open and it has been open for a very long
160:53
Speaker A
time. So there's actually no charge left in this capacitor. So if we were to measure the voltage here, it would be 0 volts. we have 0 volts over this capacitor and our light would be off.
161:04
Speaker A
When we throw this switch closed, let's see what happens when we throw this switch closed. We're actually going to start to get some current coming through um and it won't actually go through this capacitor. But what's going to happen is
161:17
Speaker A
over time the capacitor is going to charge up and it's actually going to happen fairly quickly. This is going to be um you know almost instantaneous but as it charges we will get some current and the current is not actually
161:30
Speaker A
traveling through the capacitor. What's going to happen though is we're just going to induce a current because we're going to have um you know if we look at it at this time for example right here then we don't have a fully 9 volt charge
161:43
Speaker A
here. We're going to have an imbalance of that voltage and that's going to induce some current. However, once we actually reach this steady state here and we get to that 9 volts, we're not going to have any current here. And our
161:55
Speaker A
circuit's just going to function as it would normally with that series circuit of our resistance and our LED. Our LED will be lighting up and we will be all happy because that's what our circuit is designed to do. Okay. So what happens
162:08
Speaker A
though if we throw open this switch and we do that to simulate maybe we have um a little dip in our voltage supply or the the power cuts for a second. What would happen in that scenario?
162:21
Speaker A
All right. So immediately what's going to happen then is we have this 9 volts here and it actually will function kind of similar to a battery. So we'll see here we actually start having our current being induced because we can
162:34
Speaker A
think of the polarity of this. So we have a minus and a plus here and we can treat it kind of like a battery and it's actually going to power our LED and our circuit for a brief period of time. So
162:46
Speaker A
if we take a look again at the graph for that, it's going to look something similar to this. Now this dotted line here represents when we throw open the switch. So in our steady state, um the voltage here is just happy at 9 volts
163:00
Speaker A
and we're going along in that straight DC. And then when we flip open the switch, what's going to happen is our capacitor is then going to kick in and it's going to discharge very quickly. Um all of its charge and it will actually
163:13
Speaker A
be able to power the circuit for a brief period of time. See here that it actually dips pretty quickly and it follows this um then slowly discharging.
163:24
Speaker A
So, while this isn't a perfect power source for us or voltage source because of course our voltage actually um drops in time pretty quickly and with it so does the current that actually comes through the circuit. It will actually
163:36
Speaker A
help us with some quick dips in our voltage source. So maybe if we only came to here and then we came back on, we'll come right back up to that 9 volts quickly. And that's a lot better than us
163:46
Speaker A
just dropping off this peak. So this is why you'll generally see um these bigger size capacitors in the power supply because they really help to even out if we have any dips or drops in the voltage. Then they can keep our circuit
163:59
Speaker A
running as it should for a brief period of time until that voltage kicks back in, which is a really nice feature. Now the amount of charge that we actually hold is what's going to determine how quickly this capacitor discharges and
164:13
Speaker A
how long we can actually supply some voltage and current. And the property of a capacitor to actually hold onto this charge is what's called capacitance. So you'll see here it's capacitance and we usually denote that with the letter C
164:28
Speaker A
and it's measured in the unit farads. Now one thing to note with farads is this is actually a very large unit and an electronic circuit. So things like our IoT devices, we're generally going to be seeing things in the range of
164:42
Speaker A
microfarads or sometimes even nanoparads or poparads. So those are just very small fractions of the um SI unit which is farads. So this demonstrates how capacitors behave in a DC circuit. And the one really important takeaway for this is that in its steady state,
164:59
Speaker A
there's not going to actually be any current that is able to flow um through the capacitor if it's hooked up to a voltage source. So keep that in mind.
165:07
Speaker A
You can think of it at DC in its steady state that it's basically an infinite amount of resistance. This is not the case however though for alternating circuits. So we're going to take a look at that now. Okay. So I've just brought
165:20
Speaker A
up a very basic circuit here where I am showing what we have an alternating current voltage source. So this little squiggly line inside of the circle. This is what we actually use in our schematics to represent an alternating
165:33
Speaker A
current voltage source. And just for ease of calculation and what we're used to, I'm using our North American um voltage here. So 120 volts at 60 Hz.
165:43
Speaker A
Now, as I just mentioned, if this were a direct current voltage source, then what's going to happen in our steady state is the current's going to come.
165:50
Speaker A
We're going to build up those charges here, and then once we reach that steady voltage that matches our voltage source, then nothing's really going to happen in this circuit, we can kind of just think of this as being an open circuit, and we
166:00
Speaker A
will have no current coming across our resistive load here. For an alternating current, this is actually not the case.
166:08
Speaker A
the alternating current is actually able to interact with this capacitor and transfer its charges over through to it which is actually going to then um create a current on this side here. Now one thing that is important to note is
166:22
Speaker A
that we're not actually still passing electrons through this. This dialectric doesn't allow them. But the alternating voltage here that comes with our alternating current is actually going to um cause this charge to build up and then discharge. And that imbalance of
166:37
Speaker A
charges is going to allow us to transfer the current over to this side and we'll actually have some current through. Now, capacitors still do resist the flow of an alternating current. And the amount that they resist that flow of
166:51
Speaker A
alternating current is what we call reactants. And the calculation for reactants here, we are going to start to get into um a little bit more math. But the calculation for that is it's 1 / 2 pi.
167:04
Speaker A
And this f is frequency. this little f not farads and then c for capacitance.
167:09
Speaker A
Um so the most important takeaway here just to remember is that it is inversely proportional to the frequency and the size of the capacitor. So as we increase this frequency the higher it is then the less that this capacitor is going to
167:24
Speaker A
resist that alternating current and also the greater the size of the capacitor then the less it's going to actually resist this flow of current. So if we were to calculate it for this capacitor, of course we're 1 / 2 pi fc. So if we
167:38
Speaker A
plug in our numbers, we have 60 hertz and then this is 100 microfarads if we just convert it to farads and we're going to get 26.5 ohms. Now one important thing here is we can't actually just add this reactance with a
167:54
Speaker A
resistive with a purely resistive resistance. And unfortunately the math does start to get a little bit complex here about how this works and it requires some trigonometry and I'm just not going to go into that in this course. If you are curious about it then
168:10
Speaker A
I would encourage you to take a look more and study more in depth about it.
168:14
Speaker A
But I'm just going to show some of the formulas here for it and how it works and I'll tell you about the key takeaway. So we want to combine our purely resistive resistance with this reactance. What that's called is and you
168:25
Speaker A
probably heard me mention this a few times uh is called impedance. And we denote impedance with this zed here.
168:33
Speaker A
So for a series RC circuit, and this math only works for a series RC circuit, which is what we're mainly going to be working on. And this RC circuit means we just have a resistor and capacitor in series. We can calculate the impedance
168:46
Speaker A
as the square root of R2 + X^2. So this is our resistance here. And then this is our reactance.
168:54
Speaker A
So for our circuit that's going to be 350 squared, which is this measurement of the resistor. And then we already calculated the reactance as 26. So we'll do this 26^ squ. Um, and I'm just making dropping off that.5 here just to make
169:08
Speaker A
this calculation super simple. And we get this 351 ohm. So the big takeaway here and what I wanted to show is that this 100 microfarad capacitor is really only adding about 1 ohm of impedance to the current. So it's
169:24
Speaker A
really having very very little effect on how much current is actually flowing through the circuit. And if we increase this frequency or we increase this capacitance value then it's going to have even less effect on it. However, if
169:39
Speaker A
we decrease this frequency, so as we get closer and closer and closer down to our DC, which would be, you know, zero hertz, we're going to get more and more and more impedance till we basically reach what is considered an open circuit
169:53
Speaker A
or impedance so high that we're not going to allow any current to travel through the circuit. And this is the most important takeaway for this. So if you don't remember any of the math or what impedance or anything like that is
170:05
Speaker A
just to remember that capacitors at a higher frequency are going to offer very little resistance. And the higher the capacitor value we go is also going to offer very little resistance. Now this is super important for when we're
170:19
Speaker A
working on our IoT devices or really any circuit that's going to be working with alternating currents because what it allows us to do is we can create what are called filters. And what we can do with these filters is that we can
170:32
Speaker A
actually then block certain frequencies from going through to our circuit. And this is going to be really important for when we're working with all these communication signals and we have our square waves with different frequencies and we have interference. We're going to
170:45
Speaker A
need these capacitors to create these filters. And that's why if you recall when you're looking at the board for the router, it was filled with capacitors because this is trying to create a wireless signal. So, we're going to have
170:57
Speaker A
lots of different frequencies going all over on that board. And the capacitors are what actually allow us to filter out and keep only the ones we want. In the next video, we'll actually take a look at how we can create some of these
171:09
Speaker A
filters and simulate them in Circuit Lab. But before we hop over to that, I just want to loop back to our original look at the three capacitors we started this lesson with and just chat a little bit about some of their properties. So,
171:23
Speaker A
on the left here, we have what's called an electrolytic capacitor. And the reason it's called that is because if you were to bust this apart and take a look at the inside of it, instead of just having two simple plates, we
171:34
Speaker A
actually have a sheet, a very thin sheet of metal conductor here. And it's rolled around in a circuit like almost if you think of like one of those like Swiss logs or something like that, those baked goods. It kind of is similar to that.
171:47
Speaker A
And then on the inside where between what is rolled, instead of ceramic for a dialectric, we actually have um an electrolytic compound. like a gel and it's a very very good dialectric. It's better than ceramic and what that allows
172:00
Speaker A
us to do is we actually can make these capacitors much much bigger in capacitance. So if we need a um bigger capacitor or bigger capacitance then we have to use these electrolytic capacitors. Now the one really important thing with these is they actually care
172:16
Speaker A
about polarity. So which one gets hooked up to the negative and positive ends. Um, and the way that we can see that is this will usually almost have a piece of like marking tape or indicator that's the negative one. And then also the lead
172:30
Speaker A
on the negative one will be shorter and the positive lead will be longer. And this is true for a lot of components that have polarity. The the longer lead will be the positive one. And one way that I was taught to think about this
172:43
Speaker A
just to help you if you're ever going to forget that. So, if you think of like a positive symbol and you take like two lines for example and you cross them like this, well, if you uncross those, put them together like as a lead, then
172:53
Speaker A
it's going to be longer than if you just took a negative and put it as the lead.
172:58
Speaker A
So, that's how I always remember that the longer one is the positive one. All right, so the next one that we're going to take a look at is what we've already taken a peek at actually, and that is
173:08
Speaker A
the ceramic capacitor. So, we saw what was on the inside of this one. And these are great if we just need a fairly low capacitance because they are very cheap to make. And also, the other nice thing is we don't care about the polarity on
173:21
Speaker A
them. The last one here is a surface mount capacitor. So, we can make them in that surface mount package. And you'll see lots of those on our router board, for example. And this is actually a ceramic surface mount capacitor. So,
173:34
Speaker A
it's just got a piece of ceramic uh in between two little metal tiny metal plates here. All right. So, the last very important thing about these capacitors is you'll see on them they have two different markings. So, the
173:47
Speaker A
first one just tells us about the capacitance. On this one, it's 100 poparads. And then we'll see this 1,000 volts for example on this one. And this one's rated at 6.3 volts. So this voltage is kind of similar to when we
174:01
Speaker A
had the current for our power supply in that this is not actually the voltage that they operate at or anything like that. This is the maximum voltage they can withstand. So the voltage that the capacitor will be charged at is whatever
174:14
Speaker A
voltage we apply to it. But if we go over a certain voltage that is more than it's rated for then like these guys will actually blow up. You'll see them they'll go pop and they'll blow up. Um and these ones will just burn out. So,
174:26
Speaker A
we got to keep in mind to take a look at that voltage rating. That wraps up this lesson on capacitors.
174:32
Speaker A
I'll see you over in the next one where we're taking a look at circuit lab.
174:36
Speaker A
Welcome everyone. In this video, we're going to be picking up from the last lesson where we were chatting about capacitors and we're going to be doing a quick demo in Circuit Lab to show how we can use just capacitors and resistors to
174:50
Speaker A
create both a highpass and lowass filter. So, if you're following along or you want to follow along in your browser, you can get to Circuit Lab from www.circetlab.com.
175:02
Speaker A
And at the time of recording this, you don't need to create an account or log in. You can use it for free. However, you are limited to a set amount of time per day. So, just keep that in mind. Um,
175:12
Speaker A
I have created an account and purchase their membership. I think the one that I have is about $20 a year. Just wanted to be able to support them and also have that unlimited access. So, if you are enjoying their uh website, consider
175:26
Speaker A
buying that membership. However, you should have enough time and be able to follow along with everything that I'm doing uh with the free version without logging in. So, what I'm going to do is I'm actually just going to dig in here
175:38
Speaker A
and create um a common scenario that we have and what we could use a filter for.
175:44
Speaker A
So, I'm going to add in an alternating current uh voltage source here. So, that's this symbol here if you remember correctly. And I'm gonna make it um one volt amplitude, but I'm gonna make it 60 Hz. So, it's kind of like the voltage
175:57
Speaker A
that's coming from our house. And then I'm actually going to add in a DC voltage source here.
176:05
Speaker A
And I'm going to make this 9 volts, similar to the voltage source that we are using. And then what I'm going to do is I'm just going to add in a single resistor.
176:17
Speaker A
We'll just do a 1k resistor. Add in some grounds here. Going to connect these up with the wire.
176:32
Speaker A
Then I'm going to add these nodes here. So we'll call this one the voltage in.
176:38
Speaker A
And we'll say this is what we're measuring our voltage out over. All right. And for those of you following along at home, you will notice that in this scenario, I mean, these are the same nodes. So, of course, the voltages and
176:53
Speaker A
everything's going to be the same, but you'll see later why I have added those.
176:58
Speaker A
Now, if we use what we previously did to check the currents and voltages here, we can actually see um our 9 volts DC here and we actually have this 9 milliamps.
177:08
Speaker A
However, this is just purely the DC portion of the circuit. So, the part that comes from here. Um however this little bit of sign noise that we have here is actually going to um affect the circuit. In order to see how that
177:23
Speaker A
affects a circuit, we need to take a look at running a simulation for this because of course this voltage source it's going to alter over time and we want to take a look at how that plays out over time. So what we can do is run
177:37
Speaker A
a simulation. So, I'm going to click down here, simulate, and we're going to do a time domain simulation because what this is going to allow us to do is it's going to let us plot the voltages and the currents in graphs over time. That's
177:50
Speaker A
kind of similar to how I've been showing them in the whiteboard lessons that we've been doing. Going to set the start time at 0 seconds. That's just when the plotting is going to start. And I think 100 milliseconds is an okay duration to
178:03
Speaker A
run this. We'll be able to see enough periods of our wave in that. Um, and then this last one is the time step. So that's how frequently we are plotting the graph. So I'm just going to do 10
178:13
Speaker A
microsconds. That's going to give us lots of plots on the graph so that we can see uh nice smooth waveforms.
178:20
Speaker A
And then it's going to ask here for us to add expressions. And this is why I've added these V in and V out.
178:29
Speaker A
And we can just run a time domain simulation now. And we'll actually see that we have this V out which is the orange one. And then the V in if we just actually hide the V out one. See the V
178:41
Speaker A
in is the same as the V out which we were expecting. However, we'll see here we wanted a purely 9V DC signal. I mean if that was our goal and we have this one amplitude um of noise at 60 Hz. And
178:57
Speaker A
in actual circuit designs, if I just hide this, this is something that can happen with poor quality power supplies or if the power supply um itself doesn't take care of this with this 120 volt 60 Hz that comes from our wall. If we're
179:13
Speaker A
plugging, you know, our power supply into the wall and then it's supposed to transform this to DC and step it down to 9 volts. Sometimes what can happen is this signal is so strong that electromagnetically um we can still get interference and we
179:28
Speaker A
can get some of that signal into our power supply. Um or especially if we have like an antenna where we're trying to pick up a wireless signal or something like that. Um we can get a little bit of this 60 Hz signal um
179:41
Speaker A
induced onto our line and that's what I'm simulating here by doing that. So that's why we have that, you know, 1vt is actually a quite a bit of noise on top of our 9volt power supply. So what I
179:52
Speaker A
want to show here is how we can quickly start to get rid of that. So, if we actually I'm what I'm going to do is I'm going to go back to build here and I'm going to grab this resistor. Um, and
180:02
Speaker A
instead of putting it and instead of measuring the voltage out over the resistor, what I'm going to do is I'm just going to drop it in here.
180:10
Speaker A
And I'm going to grab a capacitor and drop this capacitor down into ground. I'm going to set this capacitor. We'll start with 10 microfarads.
180:24
Speaker A
I'm just going to rerun the simulation with these same parameters. All right. So, we can now see that our via out is actually um changing and we're getting closer to, you know, squashing it down to that pure 9V DC
180:39
Speaker A
signal that we want. Um but we still do have a little bit of jitter. We've cut it down to I don't know about here 9.37.
180:46
Speaker A
So, we've cut it down about 60%. But, we still can do better than this as far as just getting a straight line. So I'm going to hide this and then we can go back to the build.
180:57
Speaker A
So the way that I like to think about this or how this filter works is that we have this resistive load here of 1 kiloohm and then we've got our 10 microfarad capacitor and we know to our 60 Hz sine wave these higher frequencies
181:11
Speaker A
that um the impedance or like what we can think of as the resistance of this capacitor is very low. And so essentially what we're doing is we're just allowing the sign portion or the the alternating current portion to pass
181:25
Speaker A
over this with very little impedance. So what that means is that it's actually going to drop most of its voltage over this resistor because the impedance is much greater. And then for this 9V DC signal, of course, it can't even
181:36
Speaker A
actually travel over this because it sees this as an open circuit. Now if we want to improve our filter and get it closer to being that flat line, we have two options. So, we can either increase the resistance um or we can increase the
181:49
Speaker A
capacitance. So, I'm going to increase the capacitance here. Let's just do it another 10 times and bump this up to our 100 microfarads.
181:58
Speaker A
I'm just going to run the simulation again. And we can see now we're getting pretty close to that nice smoothed out straight line. We do still have a very bit of noise in here. We're looking at like 0.05 volts of noise. and our circuit's
182:12
Speaker A
probably going to be able to um handle that if it's looking for a DC at 9 volts. Uh but we can do better. So, let's just hide this and let's pump up our resistance again just to see how
182:21
Speaker A
that affects it. Um so, let's just double this guy to 2 koohm resistor and we'll run the simulation again.
182:32
Speaker A
You can see we're getting even closer and closer to what would be a straight line.
182:39
Speaker A
Now, of course, we can do the opposite here. So, I'm going to do is just click build here. And we can reverse these.
182:44
Speaker A
So, grab this. So, I'll just delete that. Grab this. Rotate it. And just fix up my circuit here.
183:05
Speaker A
Drop this in. 2k. So this circuit it the so the other circuit is what was called low pass filter in that we only were letting those low frequency or in our case just the DC frequency to go by. Um and now if
183:21
Speaker A
we reverse this then this is what's called a highp pass filter because we're only going to be allowing those high frequencies that we want to go by. Um this one is actually maybe even a little bit easier to visualize because of
183:33
Speaker A
course basically just creating um an open circuit here. So none of this DC voltage is going to be able to pass here to where we're reading this out. So if we just simulate this and we run our time domain simulation, we can see that
183:47
Speaker A
our Vout is basically just this one volt and we don't have any of this 9 volts that would have brought it up here and that 9volt DC interfering with it. So we've got a almost perfect filter here where we are bringing it down just to
184:02
Speaker A
the original alternating current sine wave. So hopefully this little demonstration just gives a little bit more details about capacitors and how we can use them as filters. Um we can start to get a lot more complex with what we do with the
184:16
Speaker A
capacitors and our filtering to make what are called band pass filters where we're only going to allow a specific frequency band. So instead of it just being anything over or under a set frequency, we can actually also create
184:29
Speaker A
them. So if we just want a set frequency range, so maybe from like 60 Hz to 120 Hz. So, what I will end on with capacitors is I've really just barely scratched the surface um of the theory that's behind capacitors and how they
184:44
Speaker A
affect signals. There's a lot more if we want to start talking about phase and leading and lagging currents and voltages, but I don't really think all that stuff is super important for us as hardware hackers. The main thing I
184:56
Speaker A
wanted to impass is just what they're usually used for in the circuits that we're going to be looking at and how they can play a role as filters. So, that wraps up this video here and I'll see you over in the next one. Welcome
185:10
Speaker A
everyone. In this video, we're going to be chatting about inductors. Now, when I was putting together the curriculum for this course, I wasn't entirely sure if I was going to include a video on inductors or not. And the reason for
185:22
Speaker A
that is they won't be as frequently seen in small electronics that we're likely to see in IoT devices. However, for both completeness and because some of the science behind why inductors work is important, I've left this video lesson
185:39
Speaker A
in. So, with that being said, let's dive into taking a look at inductors. I've got one on the screen here, and then I've also got the schematic symbol here.
185:49
Speaker A
Now before we chat about conductors, we need to look at another important electrical engineering law. And that law is Ampier's law. And what Ampiier's law says in like the most basic form is that when we pass current through a
186:05
Speaker A
conductor, so we look again at our very basic simple wire and we'll imagine that this one is actually connected to a voltage source. So that's how we're able to pass a current through it. And when we pass this current through the wire,
186:19
Speaker A
it's actually going to create a magnetic field around that wire. And I've got these blue rings here on the screen that represent the magnetic field. But just keep in mind this is a field. So it exists all around the wire. And as we
186:35
Speaker A
get further away from the wire, the magnetic field exists, but it weakens in strength. Now the direction or what we call polarity of that magnetic field is actually proportional to the direction of the current. So if we swap the
186:51
Speaker A
direction of the current, you'll notice here that the polarity or direction of that magnetic field reverses. So Ampear's law is super important actually for how we interact with and use electricity in our day-to-day lives. And one of the reasons for that is that the
187:07
Speaker A
opposite actually also holds true. And that is that magnetic fields actually are also able to induce currents. So you see here I have that same wire from before and I've just shown these rings kind of expanding out to demonstrate how
187:22
Speaker A
that field would propagate outwards. So keep in mind that as we get further and further away from the wire that the magnetic field is actually going to weaken in a strength. Now, if we put another wire inside of this magnetic
187:36
Speaker A
field, what's going to happen is that it's actually able to induce a current onto that wire, which is really, really important actually for a lot of our daily uses of electricity. So, this is kind of one of the fundamentals of how
187:50
Speaker A
we generate electricity. It's also how electric motors work and it's also how we transmit a lot of our wireless signals throughout the air.
188:00
Speaker A
Now the one really important thing to keep in note with how this magnetic field induces currents is that it's not just a magnetic field that induces the current. It's actually a change in magnetic field.
188:14
Speaker A
So when we first put this wire inside of that magnetic field, we're going to induce current for a short period of time. But then we kind once we reach that steady state and if neither of these wires are moving and this current
188:27
Speaker A
is not changing then we're going to lose this current that we're inducing because it's only the changing magnetic field.
188:34
Speaker A
So in order to induce a current if that's what we want we have a couple of options. First of course we can move this wire. So we can move it in and out of the magnetic field. And remembering
188:46
Speaker A
that the magnetic field changes in its strength as we get further from the wire. So this change is going to induce a current. Second is of course we can move this wire so that it makes this further. And then the last thing that is
188:59
Speaker A
really important is we can also use an alternating current. So if we flow an alternating current through this wire that's creating the magnetic field. Of course as we change that current, this magnetic field is going to change in its
189:13
Speaker A
intensity and also possibly its polarity if we have this current going back and forth. And what that's going to do is it's going to induce a current onto this other wire. So something super important to keep in mind.
189:27
Speaker A
With that in mind and a little bit of an understanding of Ampi's law, let's take a look at how we can use this to create inductors.
189:35
Speaker A
So I've got an example of an inductor here on the screen. And really in its most basic configuration or construction, an inductor is just a wire that is coiled up. So you see here in this illustration we have a wire and
189:49
Speaker A
it's coiled around itself many times and you know in this example it's not many coils um just kind of pictoraphically but in reality we're going to have you know up to thousands and thousands of times that this wire coils around
190:03
Speaker A
itself. And when we do this, these magnetic fields are going to form in such a way that they create uh a magnetic field in this kind of pattern where it's the strongest in the center. And what we can
190:16
Speaker A
do with this kind of magnetic field like this is we can actually store energy in it. So when we send a current through the inductor and it travels all the way through it even if it's just a DC
190:27
Speaker A
current when it travels through and it's you know at that instant of it changing it's going to create that magnetic field and then if we actually remove that current and as long as you know we still have a path for current to flow then the
190:43
Speaker A
magnetic field is actually going to recede and it's going to release all of its energy back into the wire. So, in the same way that capacitors were able to store their energy in that electric field, inductors are able to store their
190:57
Speaker A
energy in this magnetic field that can then be released to create current back into the wire. Another thing to keep in mind is that this magnetic field as it's being created or changing actually creates a resistance or impedance on the
191:12
Speaker A
current. So when we apply just a direct current to this wire at the very beginning when it's first being applied as this magnetic field is being created it's going to create some impedance for that current but then once it reaches
191:25
Speaker A
that steady state the magnetic field uh and the current are stable then it's not really going to apply much impedance at all. We can just think of it to that direct current or a very low frequency as almost just being a straight wire.
191:39
Speaker A
However, for an alternating current and especially one that is fluctuating at a very high frequency, then the change in current is going to constantly be trying to um change or fight against this magnetic field. And what that's going to
191:54
Speaker A
do is it's actually going to create quite a bit of impedance for that alternating current. So, we'll take a look at the next slide about how that impedance and reactance is calculated.
192:05
Speaker A
Okay, so I've got a very very basic circuit here. Again, similar to the capacitor and resistance circuit that we are looking at. Now, you'll notice that I have swapped out our voltage source here with a 10 kHz frequency. And that's
192:19
Speaker A
because inductors, they generally interact much more with these higher frequencies and impede the higher frequency. So, I have upped it to make it a little bit more realistic in the actual value of the inductor. So, similar to capacitors, inductors do have
192:35
Speaker A
a measurement for how much energy they can store. And we call this inductance. It's usually measured or denoted with an L. And the unit for it is Henry's.
192:46
Speaker A
Similar to capacitors, Henry is a pretty large unit. So, you're generally not going to see inductors having a measurement of a full Henry. A lot of times, you'll see it in millhenries or maybe even micro Henry's.
193:00
Speaker A
And again like capacitors the amount of resistance that they have to alternating currents is called the reactance. We generally denote this with an XL. And the calculation for it is 2 pi * the frequency times the value of the
193:16
Speaker A
inductor. So the amount of pen's and you'll notice that kind of opposite to capacitors our reactance is directly proportional to the frequency and the size of the inductor. So, as we increase the frequency or as we increase the
193:31
Speaker A
inductor, then we're going to get more reactants. In our example here, we can see if we just run the quick math, we're going to get around 6,283 ohms of reactance. And if we convert that into impedance following the
193:46
Speaker A
similar method that we did for capacitors, I won't go over all of the math again, but if we just really quickly run through this math, you'll see that we're going to be getting an impedance around 6,292 ohms. So adding this inductor in series
194:01
Speaker A
for this um somewhat high frequency is going to add a lot of impedance. And this honestly, this really isn't even that high of a frequency. So, you know, we can get up into the megahertz or gigahertz in signals. So, you can see
194:13
Speaker A
how um at these higher frequencies, these inductors are actually going to start to be almost like uh an open circuit or infinite impedance for these really high frequencies. Just to really quickly circle back to my initial comment from the start of the lesson on
194:29
Speaker A
how we won't see inductors as much in smaller electronics like we're going to see in IoT devices. Now the reason for that is twofold. The first is that inductors themselves are costly to make in comparison to capacitors. So if we
194:47
Speaker A
look at this example here, we've got an inductor um or even this one on the circuit board here, you can see how we actually have to take a wire and then either wrap it around itself or wrap it
194:58
Speaker A
around some other material. And this manufacturing process for this is more expensive. It just costs more to actually do this than a capacitor where we can just take two metal plates and slap them together over top of a ceramic
195:13
Speaker A
disc or some other material. It's a lot easier to make those capacitors. The other reason is if you look at this circuit board, this is kind of an old school circuit board, but just to really demonstrate it, I've got an inductor
195:25
Speaker A
here and then we've got some capacitors here. Now, these are much smaller um like in their ability to store energy.
195:32
Speaker A
And you do see we've got some big capacitors here, but overall inductors are going to be a lot bigger than capacitors and take up more space on the circuit board. And then also, we still have that u magnetic field that we have
195:47
Speaker A
to worry about that inductors create and they can actually be a source of noise on our circuit boards for us. So, if we're not careful about where we put them or if we're shielding them properly, then that magnetic field that
196:00
Speaker A
they create, it can actually bleed out into the rest of the lines on the circuit and it can be a source of noise for us. Now, we did see just in our previous example how inductors could be an excellent filter, especially for
196:16
Speaker A
these high frequency signals and blocking them. But keep in mind that we can actually use a capacitor to block high frequency signals as well. And we demonstrated that in the capacitors lesson where we were able to create what
196:32
Speaker A
we called a lowass filter that just let the low frequencies through and block those high frequencies. And then using that same capacitor and resistor and just switching the order of them in the circuit, we were able to do the
196:45
Speaker A
opposite. So for a lot of applications where we would use an inductor, we can actually use a capacitor instead. And since they're cheaper, smaller, and easier to produce, we just select to use a capacitor. Now, there are some
196:58
Speaker A
specific cases where inductors are better, and I'm not going to go into those, but you will sometimes see them on the board. So, it's something to keep in mind. That being said, inductors also play a really important role in lots of
197:12
Speaker A
other areas of electrical engineering. So if this is a topic that you are interested or you want to learn more about them, I've honestly have really just scratched the surface about both inductors and how Ampier's law functions. So definitely would encourage
197:26
Speaker A
you to dive deeper into that. With that being said, that does wrap up our video on inductors and I'll see you over in the next one.
197:35
Speaker A
Welcome everyone. In this lesson, we're going to be chatting about diodes. So, I've got the schematic symbol for a diode up here and then a picture of a very standard through hole style diode here. Now, they do come in many other
197:49
Speaker A
packages, but this is what the common through hole ones are going to look like. This is another circuit component where it really makes the most sense to take a look at it in an actual circuit.
198:01
Speaker A
So, let's take a look at a basic schematic that has a diode in it. And we're just going to revisit that really basic DC circuit that we were looking at before where we have our 9volt DC power supply and we've just got a resistor
198:14
Speaker A
here and we've dropped a diode in series with it. So just for the explanation of how this diode functions, I'm going to drop in two circuit nodes here and just to help label the polarity of the diode.
198:26
Speaker A
So this end of the diode is the positive one and this one is the negative one here. And you regularly won't see dodes represented like this in schematics. I'm just adding this here because it makes it a little bit easier to understand
198:38
Speaker A
what's going on. If we just bring that picture of the diode back just so you can see. Um, this end is the positive end. So it correlates to this end here.
198:48
Speaker A
And this end is the negative end, the one with the stripe on it. Or the way that I like to think about it is that this is just a negative symbol. And the positive end of a diode is called an
198:59
Speaker A
anode. and the negative end is called a cathode. It's not super important to remember those, but just so you know, that's how they work. The way that I remember it is since anode comes in, you know, alphabetically before a cathode,
199:11
Speaker A
it's the positive one. And the way that diodes function and why we needed to talk about this polarity is they they actually work similar to uh like a valve in water in that they control the flow. In our case, it'll be
199:26
Speaker A
the flow of electricity, so current, in such a way that they're going to allow it to only flow in one direction.
199:34
Speaker A
So if we hook this diode up in such a way like we have here where we have the positive end or the positive lead hooked up to the positive end of our voltage supply and then we also have the
199:45
Speaker A
negative end hooked up to the negative or to ground then this is going to allow current to flow as it would here and it's going to offer very very little resistance to this current.
199:58
Speaker A
If we flip this voltage supply around so you see here now I have flipped this.
200:03
Speaker A
So, you know, we've got this negative to positive, and we're going to actually have our current be trying to flow this direction around our circuit. And of course, we've got the negative end of the diode or the cathode hooked up to
200:15
Speaker A
the positive end of the voltage supply. And this is actually going to block any current from flowing. It's going to basically be like an open circuit. We do have a very, very small amount of current. That's called the leakage
200:27
Speaker A
current come through, but realistically, you can just think of this as being an open circuit. and it's going to block that current from coming through. The really nice thing about the schematic symbol or representation of diodes is that um you know it actually is just an
200:42
Speaker A
arrow that helps remind us what direction they go. So if the current's flowing in the same direction of the arrow, it's going to pass. Um and if it's coming into you know where we have this line that I kind of think of as
200:52
Speaker A
like the negative symbol or like a wall, it's going to block the current. So, this is really, really useful for helping us control the flow of electricity. And there's actually a lot of things that we use diodes for in
201:05
Speaker A
electronics. And I'm not going to go over all of them in this lesson, but just to get you kind of thinking about it. One really basic thing that we use diodes for is to protect our circuits from applying a backwards polarity or
201:20
Speaker A
backwards voltage to those circuits. So, we talked about, you know, different circuit elements like there's types of capacitors or even LEDs, which are actually a type of uh diode. They really don't like having the polarity swapped on them and putting voltage or current
201:36
Speaker A
the wrong way through them. And this is especially true also of lots of like digital components, which we haven't talked about yet, but things like processors or, you know, all the chips inside of our actual electronics, they really don't like having their polarity
201:50
Speaker A
swapped on them. And this can fry all of those components. And you've actually maybe done this before with like a remote or something else that has a battery where you put the battery um in backwards and you realize it was backwards, it didn't
202:03
Speaker A
work, but nothing bad happened. Switch the battery around and everything was okay. And one thing that may be happening in this circuit is that the designers added in some sort of reverse polarity protection and they used a diode to do so. So that if you, you
202:19
Speaker A
know, put the battery in backwards or you hook your voltage up the wrong way, what it's going to do is it's actually just going to block the current from flowing and it's just going to be like, uh, you know, an open circuit and no
202:29
Speaker A
damage will be done. So that is one way that we can use diodes. There's lots of science behind how do diodes work and we're not really going to get into that.
202:38
Speaker A
However, there are some specific characteristics about how they actually function uh, in the real world that we should take a look at. The way that we've been looking at them or talking about them in the last couple circuits
202:49
Speaker A
here is mostly as an ideal diode. And the next couple slides, we're going to take a look at how they actually function in real life.
202:56
Speaker A
All right. So, I've just rearranged the lettering on this schematic here just a bit. It's still the same circuit uh just to help identify this voltage here. So, the first characteristic that we're going to talk about is the forward bias
203:09
Speaker A
voltage. And what this means is, you know, previously we were talking about how if we hook the positive end of our diode up to the positive end of our voltage source, and of course the negative is connected to the negative or
203:21
Speaker A
ground, then we're going to be able to get some current. Now, in reality, this won't happen for all voltages. It's only going to happen if the voltage that we hook up is greater than what is called the forward bias voltage. And on most
203:36
Speaker A
standard diodes, this is going to be at about 0.6 volt. So once this voltage here, you know, we've got it at 9 volt, so that's not going to be a problem.
203:45
Speaker A
But, you know, if this were like 0.4 volts or 0.3 volt, then that's not going to be enough to, you know, the way I think about it is turn the diode on and go over that forward bias voltage and
203:56
Speaker A
actually allow current to flow. Now, in reality, it's, you know, it's not going to be exactly at 0.6. It's going to be, you know, kind of around there and there's going to be a kind of uh region in that where there's, you know, a bit
204:10
Speaker A
of current that can come through and as we get closer to 0.6 and go over it, it's going to um allow all that current to go through. But, you know, 0.6 is a pretty good threshold to think about.
204:20
Speaker A
And there are diodes where this is number is greater or smaller if we need them in our design. So, just keep that in mind. We're not going to look at those today, but you can get different diodes that have um different forward
204:32
Speaker A
bias voltages. The other thing to keep in mind with that forward bias voltage is that we're actually going to get uh you know a voltage drop over this diode when it's in that you know turned on state and that forward bias voltage is
204:46
Speaker A
actually going to be that voltage drop. So for example if we wanted to calculate the current that's going through this circuit this I1 then we would need to take that into account. Just some really quick math then if we wanted to
204:58
Speaker A
calculate that circuit we're going to have to go this 9 volts minus 0.6 6 V divided by the resistance. We're just using a little bit of Kaw's voltage law and Ohm's law here and we're going to get 8.4 milliamps. If you just do some
205:13
Speaker A
really quick top of the mind math for this, which is why I use the 1k resistor. If we didn't have this diode here, then we're going to have 9 volts over this resistor. And of course, we're going to have 9 milliamps. So, because
205:24
Speaker A
of this diode, we're actually going to have a small voltage drop a and a small little bit of less current than we would otherwise. Um, and depending on your circuit, maybe this really isn't going to matter at all. You know, if we're
205:37
Speaker A
operating at 9 volts, maybe that's not going to. Um, but for some electronics, especially where we're getting into logic levels at 3.3 volts, then you can start to see how this may be a consideration that you want to think
205:49
Speaker A
about. Okay, so the next important characteristic that we're going to talk about is if we flip this voltage supply and then we up the voltage. So we were talking previously about how if we put this voltage supply in backwards, we
206:02
Speaker A
have the polarity swapped and we have the positive end of the voltage supply hooked up to the negative end of the diode. We have current trying to flow backwards to the diode. It's going to block this current coming through. So in
206:14
Speaker A
a perfect world, it would just block this for all voltages. You know, in actual real life applications, the diodes, they can only withstand so much voltage before they're going to do what's called breakdown. And the voltage at which they do this is called the
206:27
Speaker A
reverse breakdown voltage. So, on a standard diode, looking at around minus50 volts. However, this one's, you know, not as standard as that forward um voltage drop or the forward bias voltage. So you really should be if you're concerned that you're going to be
206:44
Speaker A
getting to this level or you're designing um your circuit around this then it's really important to actually look at the data sheet for the diode and see what this is and what happens when we go over um that breakdown voltage. So
206:57
Speaker A
if our voltage in is you know in the backwards polarity and then it gets greater than that breakdown voltage we're going to have what's called the diode breakdown. And what's going to happen immediately is this diode is going to switch basically on and offer
207:11
Speaker A
almost no impedance um or resistance. So we're going to get the current rush right through it and then generally what's going to happen is it's going to fail. U it's kind of unpredictable about how it's going to fail but it's probably
207:24
Speaker A
going to like burn up and it may burn up into an open circuit or it may burn up into some kind of closed uh short circuit. It's really unpredictable. It's going to happen. But the important thing to remember is it's probably not going
207:37
Speaker A
to come back from this. It's going to be, you know, broken. It's going to be a burned out component.
207:42
Speaker A
So, we don't want to for most diodes be, you know, approaching or or going over that breakdown voltage. Now, there are some special types of diodes where we actually can um go into or over the breakdown region, and that's actually
207:57
Speaker A
their design of them. Um, but we're not going to talk about those today. But just something to keep in mind that there actually is diodes that can do this. However, most standard ones, you know, once we go into that breakdown
208:07
Speaker A
region, they're they're broken. They're going to burn out and be unusable. So, that kind of covers uh the basics of diodes in a DC circuit. We are going to take a look though at how they affect alternating current voltage sources. And
208:20
Speaker A
to do that, I think it's easiest to jump over into Circuit Lab. So, I'm going to hop over to Circuit Lab and I'll meet you over there. Now that we've popped over into Circuit Lab, let's take a look
208:31
Speaker A
at how diodes interact with alternating currents. So, we'll just start here with our alternating current voltage source.
208:37
Speaker A
I'm going to drop that in. And we'll leave it at 1 kHz sine wave. We'll just leave this all default at 1 volt for now.
208:46
Speaker A
Going to have a add a resistor. So, we've got a load that we can measure over. And then we will grab our PN junction diode. So, that's this one. And we don't need to worry about what that means, but we're just going to put it in
208:59
Speaker A
this direction with the polarity. And we'll connect these up with some wires here. Add in our grounds.
209:14
Speaker A
Then I'm just going to name these nodes so they make it a little bit easier for us. So, we'll call this one voltage in and we'll call this one voltage out or V out.
209:32
Speaker A
Okay. Now, same as before when we were working with the alternating currents, in order for us to see what's going on with these voltages, we're going to need to run a simulation. So, let's do that now. Put this back in the middle. All
209:46
Speaker A
right. We're going to do a time again and we'll set this actually since the waveform is much faster here. We're just going to do 10 milliseconds. And I'm still going to do a 10 microscond step time here. And we'll click on these
210:03
Speaker A
here to add our input and output voltages as expressions. And then let's run that time domain simulation. All right, perfect. So let's let's explain what's going on here. So this blue one again, this is our input voltage. So we
210:19
Speaker A
just have this perfect sine wave with a 1VT amplitude. And we'll see, interestingly enough, um, this is kind of the region where we're actually turning on the diode. And you can see that it's actually clipping quite a bit
210:33
Speaker A
of that signal because we have that for this diode, it's a between, you know, 0.6 and 0.7 volts that we're actually clipping off the top. And then once we go into this negative region, we don't get any because this is where the
210:47
Speaker A
diode's actually turned on. And then as we go back on again, we are still clipping. So I'm just going to hide this. This is kind of what we expected and shows how that diode needs that forward bias voltage and able to turn on
211:00
Speaker A
and how it doesn't let anything in reverse. Let's just hide this. And then let's jump this up just to get a better idea.
211:08
Speaker A
So I'm going to jump this up to 10 volts here. And then let's run the same simulation.
211:17
Speaker A
All right. And now we can see how our output voltage for the portions of the sine wave where it's in the positive region or the currents going in the positive direction, it's more or less unaffected. So we get that positive blip
211:31
Speaker A
and then we actually just get it turned off and we we cancel out the negative voltage portion of the wave or where the current would be trying to flow in the opposite direction. So for these periods here where it's negative I'll just hide
211:44
Speaker A
this. We would have the current trying to come back across this diode and it's not able to turn on. So what this is actually called really basic circuit this is called a halfwave rectifier because we have you know turned off or
211:56
Speaker A
rectified out half of that wave. Just want to show really quickly um just one thing for interest. If I go back to build here and if we grab a capacitor here actually and we put it in parallel, we'll just add a ground here.
212:12
Speaker A
And I'm going to put this up to 100 microfarad capacitor. So it's got a nice amount of ability to hold charge. And if we run this same simulation just really quickly using the same parameters, you can see now actually that we're, you
212:28
Speaker A
know, able to turn this what was a sine wave actually into getting close to being a DC signal here. And we're actually able, if we play around with the resistance values and the capacitance values to get this pretty
212:44
Speaker A
close to being a DC input. And so this is a halfwave rectifier with a capacitor filter in order to make this. Um, and this is actually somewhat of an inefficient way, but really cheap and easy way to turn alternating currents
213:00
Speaker A
into a DC signal. Uh, the reason it's inefficient is because we're just basically wasting all of the power in the second half or the second portion um of the period of the wave. But this is a really cheap and basic way that we can
213:14
Speaker A
create a DC signal. And you know, if you are interested in this or you want a little challenge for yourself, you can look up what's called a full- wave rectifier, which just takes a few more diodes in a capacitor. Uh, and it's a
213:24
Speaker A
much more efficient way. So, if you're curious about that, I would challenge you to, you know, Google the schematic for that and build it out in circuit lab and see how that works. However, for this lesson, hopefully that gives you an
213:35
Speaker A
idea of how diodes function and why they're so critical in circuits. I'm going to wrap up the video here and I'll see you over in the next one.
213:44
Speaker A
Welcome everyone. In this video, we're going to be chatting about transistors. So, this is actually the last electrical component that we're going to be talking about in the electrical engineering for hackers series, and we've arguably left the most important one for last. I've
214:01
Speaker A
heard a lot of people say or make the argument that transistors are the most important invention of the last century.
214:07
Speaker A
And to be honest, I would probably agree with them. More on that in a second. Up on the screen here, I've got the schematic representation or schematic symbol for one specific type of transistor that we're going to look at
214:20
Speaker A
in this lesson. And I've got two throughhole components of it right here. Uh this one is for larger power and current and it's got a heat sink. And then this is just a very very common throughhole transistor style that you
214:33
Speaker A
would see. And then of course these also come in a surface mount design. So in addition to those packages where we would actually be putting transistors into a circuit or onto a printed circuit board, we also use transistors to make
214:48
Speaker A
up the inside of, you know, processors. So inside, you know, your computers or your phones and the integrated circuits or processors in there, they are made up of millions to billions of transistors, which is actually kind of mind-boggling.
215:03
Speaker A
And to just kind of demonstrate how many they are, I've got a chart up here of Moore's law. Um, and Moore's law, it was it started out as kind of like a theory, but has turned into a law over time. And
215:13
Speaker A
it basically just says that every year, the maximum amount of transistors that we can fit on one of these IC's or a single wafer of silicone, the material that they're made out of, is going to double. And it became a law because over
215:27
Speaker A
time that actually did hold true. And you can see we've kind of got this linear progression over the years of the amount of transistors we can fit all the way up to this goes into 2018 and we're at about 50 billion here. Um and you
215:39
Speaker A
know now 5 years later I think we're actually close to 600 billion that we can fit which is pretty insane.
215:46
Speaker A
And the reason that these transistors are so important and allow us to make these computations uh in the CPUs or processors or these ICs that they're in is because one function of transistors is as a switch. And of course, switches
216:00
Speaker A
are very good way for us to electrically represent a one or a zero. They're either on or they're off. Now, this is an extremely complex subject chatting about the construction of processors um down to this level. And we're not
216:16
Speaker A
actually going to dig into that in this course. I just wanted to kind of show for interest and also my explanation of why transistors are so important. Just give you an idea of how they are used.
216:28
Speaker A
So we're actually just going to be looking at one specific type of transistor in this lesson and it is called an NPN bipolar junction transistor. You'll hear that referred to as BJT for short. And we'll chat more on
216:43
Speaker A
what NPN means in just a second. Now, one of the things you may have noticed with the transistor that's different from all of the different circuit components or electrical components that we have looked at so far is it's
216:56
Speaker A
actually got three leads or three inputs to it. But the other items like you know for example the resistors or the capacitors or even the diodes all of them just had the two leads and we inserted them in
217:08
Speaker A
our circuits so that you know they would have an input from one end and an output from the other and we'd have either a current or voltage come through them and they would you know change that in some
217:17
Speaker A
way uh and it would come out the other side. So at the most all we really needed to do was possibly label the polarity of our leads you know one positive one negative. So now that we've got three, this actually completely
217:28
Speaker A
changes um how this circuit componentry works. And in order to keep track of the different leads, we actually name them.
217:35
Speaker A
So in this layout, this NPN BJT, we have the top one is called the collector, the middle is called the base, and then the bottom is called the emitter.
217:45
Speaker A
So before we dig into what these specific pins do, I just want to give a quick overview of what the two basic functions of a transistor are. So the first main one that we already talked about is we can use it as a switch and
217:59
Speaker A
we can use it as an electric switch. So by varying the voltage that goes to the base. You know if we think of this as our switch or a valve, we can open it up all the way and allow a current to flow
218:11
Speaker A
through. And there's a lot of advantages to this that we'll talk about later. The other thing we can do is use it as an amplifier. So to use as an amplifier what we can do is we can open up if we
218:22
Speaker A
think of this as a valve open it up partially in such a way that if we apply a input signal to the base we can have that mirrored um to a greater voltage and current that is coming through the
218:34
Speaker A
collector and the emitter and and we'll chat about that more in depth in the coming slides.
218:41
Speaker A
We're not going to get fully into the nitty-gritty of how transistors work, but we are going to take a look at some circuits and talk more in depth about these two functions. So, if past this, you know, all of that isn't making
218:52
Speaker A
sense. The really the most important and two critical things that I want you to take away from this lesson is just that to remember these two basic functions of the transistor. And when you see them on circuits, you'll know that they're going
219:05
Speaker A
to be performing one of those two functions. Before we get into looking at some circuits and how these transistors actually work, just a quick note on some other schematic symbols that you might see. Um, so I chatted previously about
219:18
Speaker A
that last BJT transistor was in the NPN configuration. Well, we also have what's called the PNP and you'll see that we've flipped the emitter and collector and these function fairly similar to the NPN transistors. You know, a really
219:31
Speaker A
oversimplified way of saying it is that they just kind of work backwards to them. And then the symbol that we have over here, this is for what's called a field effect transistor. And we're not going to actually talk about those uh in
219:42
Speaker A
this lesson, but I just wanted in case you run across a symbol to understand what they are. Um, and they have their own different designations for the pins.
219:50
Speaker A
So the top one is a drain, middle one is called the gate, and then this bottom one here, S, is called the source. And you might hear these referred to as MOSFETs as well. And that MOSS, it just
220:00
Speaker A
stands for the uh how what they're manufactured of. Again, we're not going to talk about these any more in depth in this lesson. I just wanted to make sure you're aware of if you saw the symbols for them that these are what they are.
220:12
Speaker A
So, as long as you understand the core functions of a transistor and what they do, then you know that core functionality or or concepts, they're going to apply uh to these as well. And then it's just really the implementation
220:24
Speaker A
of them that's going to differ. One of the best ways that I find to describe transistors and to visualize how they work is to go back to this water analogy. And I've I've got our transistor up here on the screen just so
220:36
Speaker A
I can set up this analogy and we can see what the different parts of the transistor and circuit are with regards to our water analogy. So the first part is our voltage supply here. We've got this giant tank with the water held up
220:47
Speaker A
high. That's going to represent our voltage um that will allow this water to come down through this pipe. Second thing is we've got this other big uh container here. We'll think of this as our ground that can, you know, receive
220:58
Speaker A
an infinite supply of this water. At the top here, the pipe that's connected to the voltage supply is our collector. And at the bottom, this section of the pipe here is the emitter. And then we've got this valve in the middle that I'm going
221:12
Speaker A
to call the base. So, if you think of this as like if we turned it kind of like you would open your hose, um then that would allow this valve to slide open and let some water through. Now
221:22
Speaker A
that we've got the analogy set up, I just cleared the arrows away to make it a little bit easier to see. So if we were using this transistor in its switching format or as a switch, then what we would do is apply a voltage to
221:35
Speaker A
the base and we would apply that voltage in such a way that it's going to cause the base to fully open up its valve. So when we do that, of course, all of the water is going to rush through this pipe
221:48
Speaker A
and it's going to go down to the ground. So, if we compare that to our transistor here, we apply that voltage. And we'll chat about what that needs to be later.
221:57
Speaker A
Um, but when we apply the correct voltage, that's going to put it in what we call the active region and fully open. We can think of that as, you know, if this was our valve, it's going to fully open and instead of water, we're
222:09
Speaker A
going to get the theoretical maximum amount of current that's going to be pulled from our voltage source uh down to the ground. And of course, the amount of current is going to be dependent on how we design our circuit and any
222:21
Speaker A
resistors that we place in the way. So that's how we use it in the switching setup. So the other setup is that we can actually use it instead as an amplifier.
222:31
Speaker A
You'll see here I've changed the image so that you know we've cranked this open, but we've only cranked it open halfway. And this is how we use as an amplifier because there is a region of operation of the transistor that we're
222:45
Speaker A
going to chat about a little bit more where depending on the voltage that we apply here, it's only going to open this flow partially and that is going to be proportional to the voltage that we input. And that's how we use it as an
222:58
Speaker A
amplifier by kind of sliding open and close this valve to let a certain amount of that water or current come through um that is proportional to the input. but of course much bigger in scale. So with that water analogy out of the way, let's
223:13
Speaker A
take a look at kind of like a pseudo circuit of how we could, you know, use a transistor to do this. And I'm going to call this a pseudo circuit cuz we have no resistors yet in our circuit here,
223:24
Speaker A
which you would generally want to add some in because if you actually were to, you know, hook up your transistor like this, then it would actually uh just catch fire because there would be no current limiting. get infinite current
223:36
Speaker A
and it would just burn up our transistor. So, what I've done is I've hooked the top of our transistor to VCC. Um, and we haven't really chatted about what VCC means, but you'll see this on a lot of
223:47
Speaker A
electronics uh schematics. And what that means is it's like the nominal operating voltage of the circuit. For example, the power supply to our router is 9 volts.
223:57
Speaker A
So, the BCC for that or the standard operating voltage would be 9 volts. And then this VN, we're just, you know, this is just a signal that we're going to be taking into the base. Okay. So, I've added in a couple voltage nodes here
224:10
Speaker A
just to make it a little bit easier to understand how this transistor um functions. So, the first one here, this is the voltage at the base. And then we've got the voltage at the emitter here. And if we were to measure the
224:23
Speaker A
voltage in between these, it's called VBE. Now, when you look at this transistor, you may have noticed that this symbol, it kind of looks like a diode right here. And that's because for the operation of this transistor, we
224:37
Speaker A
actually can think of this as being a diode. And the way that transistors actually are created is is kind of similar to putting two diodes together um back to back. And then the voltage that we apply to the base of it, it will
224:51
Speaker A
actually change the function of this diode and allow current to come through. So you may recall from our previous discussion on diodes that there is this forward bias voltage that we need to surpass in order for that diode to open
225:07
Speaker A
up and and that's how we use the transistor as a switch. What we need to do is set up our circuit such that this VIN is going to cause the the voltage at the base to make this VBE be greater
225:21
Speaker A
than whatever that threshold is. So, you know, for most transistors and diodes, it's around that um.7 volts or 700 molts. And once we go past that region, it's going to fully open up this section of the circuit. And it's going to allow
225:35
Speaker A
our current, you know, that's being driven by this VCC voltage to flow through our circuit. So, for a switching circuit, what we were just talking about, the thing that we have to remember is that we designed the circuit
225:44
Speaker A
such that this VN uh it pushes the BBE into what we call the active region. And that active region of the transistor is when it is fully open. So for amplification, you know, the one thing that you may recall from our diodes
225:56
Speaker A
lesson is there's actually a region of operation of the diode where it's not actually fully open or fully closed. It is, you know, partially open. And in this region is called the saturation region. This is how we can do that
226:11
Speaker A
amplification that we talked about where varying this input voltage is going to vary the amount of current that we allow through this diode. And in order to do that, what we have to do is we have to design our circuit. So for an
226:24
Speaker A
amplification circuit such that this VBE fluctuates in the saturation region or in that region where the transistor is going to allow an amount of current to flow through that's proportional to the signal that we input. And the way that
226:40
Speaker A
we actually set up our circuit to to do that and to you know hold this VBE in that 7ish range is that we do what's called biasing the transistor. And we do that by tying uh the base up to the VCC
226:57
Speaker A
through a set of resistors. So if we need to divide the voltage or just straight through a resistor and we have some voltage drop over that resistor and we can then tie this VBE to that saturation region and then our voltage
227:10
Speaker A
signal can just ride on top of that and cause that fluctuation that allows us to have the amplification.
227:19
Speaker A
Now the design of circuits around transistors and biasing them and you know the different configurations of hooking them up it actually can get quite complex and I'm not going to specifically go into that uh in this course because you know as hardware
227:34
Speaker A
hackers I think it's really just important for us to understand kind of how these transistors are used and when we see them in the circuit we can understand that okay yeah this is being used as a switch or this is being used
227:45
Speaker A
as an amplifier. we don't actually specifically need to know how to design them. Now, if if you do want to learn this, then that's great and there are a lot of awesome resources on the internet for them. However, for
227:56
Speaker A
our example, I think, you know, taking it to this point uh is good enough. With that being said, what I am going to do now is I'm going to hop over into Circuit Lab and I will create two
228:08
Speaker A
circuits, you know, actual circuits with resistors and signals to demonstrate how we can actually build out an amplifier or a switch. So, I will hop over there now and I'll see you there.
228:21
Speaker A
Welcome everyone. So, that last video on transistors was getting too long to be one lesson. So, I split it into two videos. And in this video, we're going to take a look in Circuit Lab at some transistor circuits. So, without further
228:34
Speaker A
ado, we'll jump right over into Circuit Lab right now. Okay. So, this first circuit that we're going to take a look at here is just really a demonstration one to show how we can actually drive this transistor into the active region.
228:49
Speaker A
It's not really a good representation of how an actual circuit would work, but I think the outputs from it uh really help to understand how changing this input voltage can actually trigger or change the amount of current that we let
229:04
Speaker A
through. So, just to really quickly show what we've got going on here, we've got our voltage source up here at 24 volts.
229:10
Speaker A
Uh, and we've got a current limiting resistor here. And if we look at just that DC, we can see that we have uh 237.3 milliamps. So, the reason we don't have that full 240 milliamps is that because is that's because we actually do have a
229:25
Speaker A
small voltage drop. Um, what's from what's called the uh VCE or the collector to the emitter. And if we hover over the transistor, we can actually see that that is 265.1 molts. So that's where we lose that little bit of current from. Just keep in
229:42
Speaker A
mind, so theoretically our max current that we can have come through is that 237.3 milliamps. Now I've got a node here representing the base voltage. And we can see here I have applied um this signal voltage and it is a sine wave at
229:59
Speaker A
1 kHz. So I just click on it quickly so that we can see the properties of it.
230:05
Speaker A
You'll notice I have a 5V ampl amplitude, but I do have a DC offset of 5 volts. So just if you're following along, the reason I've done this is that way it's not actually going to bounce from minus 5 vol to 5 volts. I just want
230:18
Speaker A
this to actually um start at a positive value and only stay um in the positive range cuz it really helps to demonstrate how this transistor functions.
230:29
Speaker A
And what I want you to think about is, you know, this is not an actual um representation of what you would see in a real life circuit. And and don't really think about this as like a signal or anything we're trying to amplify. I
230:40
Speaker A
really just wanted an alternating current that shows what happens with our transistor and how we can use it in this switching region as the input voltage changes. So let's take a look with a quick simulation. So let's leave these
230:54
Speaker A
parameters here. These are the standard ones we've been using. And then what we're actually going to be plotting is I'm curious about the current that we can have come through here and then also this base voltage.
231:07
Speaker A
All right. So let's just run this time domain simulation here. Perfect. So this gives us actually a really great representation of how the voltage change is actually going to you know open up this transistor.
231:21
Speaker A
So we start here. Um you know because of that offset we're actually starting at 1.2 2 volt, but we can see at 1.2 volts here, we're at that theoretical max of the current that we are going to be
231:32
Speaker A
letting through. So that's at that 237 milliamp region. Uh, and of course, as our voltage increases over time, we're still over that um region that's going to open up the transistor. And as such, our current is all the way at that 237
231:50
Speaker A
milliamps. And then you'll notice here once we get right around this region um right here right around 700 that 700 molts or 7 volts we actually drop off we drop off very quickly. Um and once we get below that 7 volts our current is
232:08
Speaker A
all the way down at essentially zero. Uh and as the rest of this signal changes through here we are at zero. And it's not until we just kind of breach that 7 uh.7 volts or that 700 mill volts that we actually go
232:26
Speaker A
back up into that active region. And when we're in that active region, so we don't care now that we're above that active region what that voltage as high as it goes. We're all the way open already at 237
232:40
Speaker A
milliamps. So if I just hide this quickly then. So what that means is that you know we we have a lot of sensors and outputs from microcontrollers um where the voltage we can control how that changes and that's really great because
232:54
Speaker A
then we can design our circuits so that you know as that sensor changes or that voltage output from our microcontroller changes we can use that to drive this and then open it up as we like. I'll give a couple of real life examples here
233:09
Speaker A
just so it helps make sense why we would actually want to do the switching in the circuit. So the first one is if we take that example of a photo resistor where the resistance value changes based on the amount of light that's shining.
233:24
Speaker A
Well, we could make a light that turns on once that photo resistance value gets below a certain level. And this is how a lot of um light sensing circuits work.
233:35
Speaker A
And in that scenario then once the resistance value is changed enough by the light we would design our circuit so that it will fully open uh up the transistor and then it can power a light and turn on that light. Another example
233:49
Speaker A
is if we actually think about that uh smart lock that we were talking about in the very first section of this course.
233:57
Speaker A
You know if you enter in your pin through the smart lock and then it's going to unlock. There's likely going to be some sort of microcontroller, microprocessor that's going to have some logic um that outputs on a pin that
234:11
Speaker A
digital out as a high or a low. That means that the lock should unlock. And when we do that, the current and voltage that's going to come out of that microcontroller or microprocessor is not going to be powerful enough that it
234:24
Speaker A
could actually drive uh you know any kind of mechanical movement where we actually need to you know physically move something to unlock that door. So, one way that we could do that is with a transistor uh and have the transistor
234:39
Speaker A
and you know this VCC or whatever this voltage be set up so that the current and voltage that's supplied when it's in that fully switched on mode would be enough to drive that mechanical motor or whatever we need. And then we tie that
234:52
Speaker A
pin from the microcontroller down to the uh base of that transistor. And we design our circuit such that when the logic says that the correct pin is open, it will set the voltage to open up that switch. All the current will come
235:06
Speaker A
through and drive that mechanical motor. And that's how we do this actual switching. So again, you know, in this example, don't think of this as an input. Um, I just really wanted to show how that voltage changing over time can
235:22
Speaker A
impact the transistor and cause it to kind of open and close in that switching region. Going to just open up another circuit here and we'll take a look at a very basic amplifier.
235:32
Speaker A
Okay, so I've got another basic circuit opened up here and this is what we call a common emitter amplifier because we actually just have the uh emitter of this tied down to the common ground. And we're looking at this circuit and it can
235:48
Speaker A
be a little intimidating looking at it at first. So what we'll just quickly do is break it down into the few different regions. So what we've got here is this is uh actually this sign voltage is representing um an input voltage that we
236:03
Speaker A
would be measuring. So if we just take a quick look at it, you'll notice that I actually have the amplitude set at 5 molts. This is a very very um weak signal and maybe it would be something that would come from like a microphone
236:15
Speaker A
if we were um measuring sound through a microphone. You'll notice we have this capacitor here and we already talked about uh capacitors and the reason that we have this what's called a coupling capacitor here is because we want to set this VB
236:31
Speaker A
uh so we're in that saturation range and in order to do that we can't have any fluctuations in the voltage other than what is actually coming from this sine wave. Now in circuit lab this doesn't really matter because this is actually
236:44
Speaker A
like a a perfect sine wave. But in reality we might have some DC uh leakage coming in and we want this this capacitor is just going to block all that from coming. So the next section of the circuit we'll look at is this one
236:57
Speaker A
right here. So we're actually using 5 volts as our our VCC here. Um so what we're going to do is we're going to you know amplify this 5 molts with that 5V signal. And in order to get this VB so
237:13
Speaker A
that it's going to be sitting right around that 700 molt or.7 volt sweet spot, we're going to steal some of this voltage up here uh and tie it down here.
237:26
Speaker A
And that's where this RB or the the base resistor comes in. We also have this RC which is the collector resistor. And this is what's going to um set the amount of current that comes through here to amplify. And
237:40
Speaker A
if you want to learn more about how to calculate these to get it in this region, then you know there's lots of really good videos or resources uh about that. But this would turn into a really long lesson if we talked about that. So
237:52
Speaker A
I'm just going to leave it at that. You know, these values I've pre-calculated them using some formulas and some characteristics of this transistor. Uh and you know, if we really want to go into that, it would make this video way
238:02
Speaker A
too long. The last section of this circuit here is just this one where I'm simulating uh a load with this resistor. And I'm coupling again with a capacitor to remove the DC bias from the circuit so that that we're actually only getting um
238:19
Speaker A
you know the pure AC signal coming out. So if we run this simulation, let's just run a time simulation. And because we've got some capacitors, I I want to look at it in its steady state and, you know,
238:32
Speaker A
ignore um the initial power on of this circuit. So, I'm just going to start at 100 milliseconds and then go from 100 milliseconds to 110 milliseconds. And we will still use that 10 microcond step.
238:47
Speaker A
And we're going to take a look at the output voltage. Of course, we'll take a look at the input voltage. And then we will also take a look at the base voltage. So, let's run that time simulation. Um, and this one's just
238:58
Speaker A
going to take a little bit longer since we're starting at that 100 milliseconds. Okay, so this graph is actually a great representation of how our amplifier works. Now, the one thing that I should mention is that a common emitter
239:12
Speaker A
amplifier is actually what we call an inverting amplifier. And what that means is that our waveform is going to be flipped. Um, so here when we're at our peak of our input, you'll notice that we flipped it and we have a negative here.
239:26
Speaker A
And if this is going to be a problem for our circuit, you know, depending on our signal, some signals it is, some it isn't. Uh, what we can do is we can add another transistor that we can flip it
239:37
Speaker A
back again as needed. But for this one, just to keep it simplified, um, we'll just look at it in its inverting state.
239:44
Speaker A
So this orange signal right here, this is our input signal. we can see, you know, how weak of a signal that is. We just have that 5 m volts peak. Um, and it's honestly so weak we can barely even
239:57
Speaker A
see it on this graph. So, what I've done here with the transistor base voltage is we can see how by pulling it up into that, you know, 730ish molt region or that 7 volts is putting us right in that saturation sweet spot.
240:15
Speaker A
and we're just riding right around where we're able to partially open and close that transistor. And what that's doing is it's allowing uh you know a portion of that BCC voltage to come through. And you can see by doing that we've actually
240:30
Speaker A
amplified if we look at our peak voltage here you know right around that 5 volts.
240:33
Speaker A
That's about as close as I can probably get it. So we're going from almost 5 molts to about 710 molts. We're looking at about 100 almost 140 times amplification which is pretty good and I think right around the maximum of what
240:48
Speaker A
this transistor is capable to do. So this is how we can use these transistors to actually you know bump up weak uh input voltages from our sensors and we can actually then you know make them more useful to read them.
241:04
Speaker A
So hopefully this gives you a little bit of an idea about how transistors work.
241:07
Speaker A
Again, this is a very um complex subject and you could spend a lot of time, you know, hours and hours even learning about just the basics of this. So, if there's really just, you know, two things you take away from this lesson
241:20
Speaker A
and that's it, it would just be to remember the two basic functions of transistors in that we can use them uh as a switch. So, we can take a smaller input voltage into the bass and then have them to control a much higher
241:33
Speaker A
voltage and current or we can use them as an amplifier again to put a weak signal or lower voltage signal into the base and then have that open up partially open up and close the transistor in such a way that we can
241:48
Speaker A
create a amplified version of that signal passing through the transistor and use that to amplify weak signals. So that wraps up our lesson on transistors.
241:59
Speaker A
I will see you over in the next one. Welcome everyone. In this video, we're going to be talking about electronic communication and signals. So right now for you to be watching this video, there is dozens and dozens of different
242:12
Speaker A
electronic communication and signal paths taking place. Of course, the obvious one is that we've got the network traffic going over the internet and streaming this video data. However, also internally, if you're watching this on your computer um or a tablet or
242:26
Speaker A
something like that, on the motherboard of your device, there is all kinds of different communication signals that are taking place just internally between the different componentry uh on your device and then also out to your monitor for example. So, we can split up electronic
242:41
Speaker A
communication and signals into two main categories. And the first one is as analog signals. and we're not really going to focus a lot on them, but I just want to make you aware that this is one way that we can actually do
242:53
Speaker A
communication. So, here's an example of one of the analog signals that we were talking about previously. And we'll just say that it varies in voltage and also frequency to represent a sound signal.
243:07
Speaker A
And the way that this works is with a microphone, the vibrations that sound make can actually then be translated into a varying voltage. uh and the amplitude and frequency of that signal changes with respect to the sound and
243:21
Speaker A
then we can actually play that back through a speaker which is just actually a microphone in reverse and it will play that sound and we can transmit this signal over a wire and have someone play it back to themselves. So this is like
243:34
Speaker A
one of the very earliest uh types of analog communication when we first invented the phone and it was as basic as that. We may have some components in between to either amplify the signal like transistors that we were looking at
243:48
Speaker A
or other amplification devices and maybe some capacitors or other things to do filtering. But the signal is continuous and there's you know there's no designation of anything like bits or anything like that. We just have a continuous voltage signal. So for this
244:02
Speaker A
course we're not really going to be working much with analog signals. we're going to be more concerned about those signals that are actually internal to our devices and going between the different componentry and those will generally be digital signals. And we've
244:15
Speaker A
looked at this already. Instead of, you know, having this continuous sine wave that represents some sort of signal, we use a square wave or an on andoff pattern to toggle the voltage between some low value and a high value. So,
244:30
Speaker A
generally that would be like 0 volts and then 5 volts. Um, and if we're reading on that line, then we read a 5 volts, we know that that is a one. And if we read the low, then we know that's a zero. And
244:43
Speaker A
this is really the, you know, the basis for all digital communication. Even if, you know, we start thinking of like these higher up, more advanced protocols. If we peel them, you know, all the way back down to at their very
244:57
Speaker A
very most basic level, you know, even if you're thinking of, for example, the OSI model, if you're familiar with that at layer 1, then this is really just, you know, voltages on a line or voltages on a wire. And this is one of the important
245:12
Speaker A
things that I want to drill home for hardware hacking and we're kind of getting into this hardware mentality is that when we boil these protocols, you know, right down to the very basic like there's still they're a voltage signal
245:24
Speaker A
and you know, even though it's not analog in the terms of, you know, we have this fluctuating sine wave, this is still a square wave of alternating current and it still behaves as such.
245:35
Speaker A
So, if we're crafty enough as hardware hackers, then, you know, there's some things that we can do just at the hardware level without even thinking about software, knowing that this communication is actually really just voltages being applied to a wire. So, to
245:47
Speaker A
make sure that we all have a baseline of how these digital communications work and that we can build up on, I want to just introduce and maybe we can try and come up with our own very very basic
245:59
Speaker A
method of doing digital communication uh with hardware. So I want to introduce just you know a super basic circuit here. We have this is our our voltage rail and I have it labeled as V LH. So that LH that stands for logical high. So
246:15
Speaker A
when the voltage is at this voltage level and we don't really care what it is. Could be 3.3 volts, 5 volts. I mean we can make it whatever we want cuz we're making up this you know little protocol ourselves here. And then I've
246:26
Speaker A
got a switch. We've got a resistor here of course just because we don't want to uh have voltage without a resistor. then we're going to, you know, be putting way too much current through and burn out the wire. We don't really care about the
246:36
Speaker A
resistors, but that's why it's there. We have a switch here, so we can toggle on and off that voltage. And then we have this receiving pin that we can put out.
246:46
Speaker A
Um, so it'll be transmitting from this end, and then someone could hook up even just a multimeter to this and read out.
246:53
Speaker A
Uh, and then if we go slow enough with our switching, they could actually decode our message. So, let's pull up a graph of what this uh receiving pin would look like. I'm just graphing this, you know, really basic over time, the
247:07
Speaker A
same way we've been looking at it. Um, so this is the voltage at this pin here or this output. Uh, and then I just have this labeled as this logic high to make it really easy for us to read when we
247:18
Speaker A
have ones and zeros. So, if we close the switch, then we know just, you know, really basic Kra's voltage law, then what we're reading out here is going to be the same as this VLH. So, of course, we get our voltage up here and the
247:31
Speaker A
person who's reading on the other end can say, "Yep, okay, we've got a one." And then if the next thing we want to transmit is a zero, then we just throw open the switch. And you see here our
247:41
Speaker A
voltage drops down to zero and we know we've got a zero. So, the great thing about this is that, you know, all we really need to exchange at this point or all we have is that we'll just determine what we're
247:54
Speaker A
considering to be a high and a low. So in our example, we're saying that you know this VH whatever it is be 3.3 volts or whatever that's going to be our high and then if we get a zero volts or
248:06
Speaker A
around zero then that's going to be zero. So in reality we'll generally have two thresholds you know an upper limit threshold and a lower limit threshold.
248:16
Speaker A
Um and when we go above that upper limit threshold that will be considered a high and when we go below that lower limit threshold that will be considered uh zero. And this just gives us some breathing room in our circuit if we
248:27
Speaker A
have, you know, any tolerances or things like that that throw off the voltage levels. I just left them out of this cuz I think it's cleaner to look at it like this. We'll just assume that we can do
248:36
Speaker A
those perfect voltage levels. Okay. So, in this example, what happens if our transmitter, so whoever is operating this switch has decided they would like to send another zero. So, they leave the switch open, send another zero. Of course, as time passes, we still are
248:51
Speaker A
just at that zero volts. Whoever's reading, if they're just doing, you know, the most basic reading ever, they just have a multimeter here. They're still reading zero.
249:00
Speaker A
How do they know that I'm sending another zero and not it's just a continuation of that same zero, right?
249:09
Speaker A
So, when we look at this graph, it's, you know, it's kind of obvious because you're saying, well, we held this one for the same amount of time, then we held this zero for the same amount of time. So, it would be assumed um that
249:19
Speaker A
this would be held for the same amount of time. And really that that is the foundation of how we're actually going to get past this issue in that we're going to set a specific amount of time that we're going to hold each symbol.
249:31
Speaker A
And that is called the symbol duration. And we represent that generally with this t subscript s. And what that really says is just you know each time I transmit a symbol in our case it's just going to be bits. So a one or a zero.
249:44
Speaker A
I'm going to hold that for a set amount of time. And that way if I transmit you know multiple of the same symbol one after another and you you know kept transmitting zeros then the person on the other end is going to be able to
249:56
Speaker A
decode that. So for example if we're just you know really basic math every second we're going to send a new symbol.
250:02
Speaker A
So the person on the other end would go you know 1 second that's a one next second that's a zero. Next second that's another zero. When we set up these parameters and you know exchange that we're going to be communicating at with
250:14
Speaker A
these different symbol durations, we generally don't actually say the symbol duration. And the reason for that is these get you know very quick. We're not going to be doing 1 second. It's going to be down you know into the
250:24
Speaker A
milliseconds or microsconds. So we're not going to say you know for example oh the symbol duration is going to be 0.1 microsconds. So instead we'll generally communicate this to be the amount of symbols per second that we can do. And
250:36
Speaker A
as long as we're me measuring our symbol duration in seconds, then to get that, we just go one over the symbol duration.
250:43
Speaker A
So one over t subscript s. And the name for this, there's actually a name for this. We call it the baud rate. So the baud rate is the amount of symbols per second. Now in our example, again, our
250:54
Speaker A
symbols are just ones and zeros. So we could call this a bit rate. And sometimes you will see it referred to as a bit rate because realistically now in modern communication is pretty much always going to be ones and zeros and
251:06
Speaker A
bits, but the industry standard is still usually to call baud rate. So keep that in mind. I'm going to use baud rate cuz that's what you'll usually see. You may also see it referred to as speed or the
251:16
Speaker A
communication speed. So just keep that in mind that you may see either one of those. Okay. Okay, so just to bring this full loop now that we've kind of established what our communication protocol is going to be and that we're
251:26
Speaker A
going to send, you know, one bit one after another and we're going to have a high voltage level represent a one, a low voltage level represent a zero. And we're going to send each bit with a specified duration. So we can just say 1
251:39
Speaker A
second here. And I put these ticks on the graph to separate that. So we can think of these each as 1 second. So let's say we want to transmit high. this t subscript x that stands for tx and
251:51
Speaker A
then the same for rx. So the way that we can do this is we can send you know h and i asy characters.
251:58
Speaker A
All right. So the asky representation for h in hex is 0x48. And then if we convert that to binary then it's just 0 1 0 0 1 0 0. So I can transmit onto that line out like an actual, you know, low
252:14
Speaker A
voltage level, high voltage level, low, low, high, low, low. Right? And you're getting the gist. And then the person reading that is able to, you know, read that and then they can decode that back from that binary to the hex to the ASKI
252:27
Speaker A
and see, okay, that's an H. And then we can send an I. So the hex representation for I 0x49. Again, we're just adding one um bit to this. So we're just going to be adding a one on the end. We can just
252:40
Speaker A
transmit this again, right? And then the person receiving they'll receive that as an I. And we have sent a very basic H and I.
252:50
Speaker A
When we're sending data like this, you know, eight bits and we're sending it grouped together like this for one representation, then generally what this is referred to um in this digital communication in this basic format like that is called a frame. So if you're
253:04
Speaker A
familiar with networking then you maybe heard of a packet. So at you know layer three at the network layer what we call like that grouping of data is a packet.
253:13
Speaker A
Well at layer 1 it's actually called a frame. And then even outside of the OSI model just at these you know basic communication protocols where we're just looking at um the voltage on a line and then building up off of that. You know
253:26
Speaker A
this grouping of data we call a frame. So, for those of you that are following along at home, you may have noticed that, you know, we still have some glaring problems in our communication protocol. The first, you know, and maybe
253:40
Speaker A
most obvious one is if, you know, let's just say I'm sitting in one room, someone else is sitting in another room.
253:46
Speaker A
We've run a wire to them. Um, you know, and I have a switch that I'm going to open and close it, and they're sitting on the other end, and they've got their multimeter, and they're going to measure the voltage. Um, and when they see that
253:56
Speaker A
voltage high on the multimeter, whether it's 5 volts, uh, and then when they see it zero volts, they're going to, you know, know it's a one and a zero, and then they can decode that. So, as a good
254:05
Speaker A
example, our very first, you know, symbol or bit that we want transmit is a zero. Well, how do they know that I'm starting to transmit? I mean, if I'm just sitting here with the switch open, um, you know, am I sending zeros all the
254:16
Speaker A
time? When is when does the transmission start? So, there's one problem. The other problem is, you know, how do we tell when a frame ends or like how long a frame is is always going to be eight?
254:27
Speaker A
You know, how how are we going to determine um that, you know, all of this is the H and then it doesn't flow into this one. And then also, what if that person wants to send us back? We just
254:37
Speaker A
have this one wire now. So, I mean, are we going to add a second wire? Are we going to, you know, have some sort of way to say, I'm done with the line. It's your turn. There's a lot of different
254:46
Speaker A
things that we need to kind of sort out. And this is where the various different protocols um that communicate in this method are going to come in play. And they all have their own ways that they kind of solve these issues. And we have
254:58
Speaker A
predetermined things that we agree on or you know set ahead of time between the receiver and transmitter in order to fix these issues. And we're going to build on you know these very basic core concepts of our baud rate and this
255:11
Speaker A
voltage and toggling the voltage on the line uh throughout the rest of the course when we look at those.
255:17
Speaker A
So the other glaring problem that we have and you know this is just kind of a problem with this style of transmission is that we're limited to just sending this one bit one after another. And when we do that what this is called and
255:29
Speaker A
you've probably heard this before is this is called serial communication. And that's literally what serial means. It just means we're sending one bit or one symbol one after another. And this brings us to limitation of speed. you know, we're really just limited um to
255:45
Speaker A
how fast we can actually, you know, turn on these symbols on and off. So, in our example at 1 second, like that's horrible. It'll take forever. Um but even, you know, as we increase the speed to what is really, you know, capable of
255:57
Speaker A
devices to be able to read and transmit, it's going to become a limitation for bandwidth that we just have to send all these symbols one after another.
256:06
Speaker A
So, what we can do to get around that is we can use what's called parallel communication. And in parallel communication, instead of us sending, you know, on one line, one bit after another, we can open up multiple lines
256:21
Speaker A
and we can send, you know, all of that information in parallel to each other.
256:24
Speaker A
So that's why it's called in parallel. Um, you know, so if we just take our example again where we want to say hi.
256:30
Speaker A
So first we're going to send the H. So before we decode this and actually look at these voltage levels, the other thing with parallel communication that I want to bring in is um you know before we were using a speed but what happens you
256:42
Speaker A
know we're all if we set say we're all at a speed but what if we don't start um at the same time right then we can start to get uh our pulses of communication be off from one another. So in parallel
256:52
Speaker A
communication, we also always will generally bring in a clock and that clock will allow us to synchronize and make sure um that all of our communication pulses are together. And the way that the clock works is going to
257:04
Speaker A
differ between, you know, different protocols. But in this one that I'm just kind of making up to demonstrate uh how parallel works, we'll just say that we're going to sample um on the rising and falling edges of the clock. And
257:15
Speaker A
you'll notice that the clock is offset from the actual communication. Um, and that's so that we we're going to force it to sample in what would hopefully be the middle of a transmission. And this way we have the best chance of actually
257:29
Speaker A
being able to capture what, you know, each of these symbols are supposed to be because if it's shifted, you know, left or right a little bit, that's still going to be okay.
257:39
Speaker A
So on our rising edge of the of the clock, we would sample that. Um, and in here, we're going to get, of course, that 0 1 0 0 1 0 0. And that's going to make up an H. So instead of you know
257:51
Speaker A
ascending it one after another if we were just using one channel instead we've sent them all in parallel and essentially you know even if we were doing this just at one second you know we have times 8 our bandwidth right or
258:03
Speaker A
times 8 our speed because we can you know send this at one time and if we want to send our I then on each channel we would then reend our bits again we have 0 1 0 0 1 0 0 1 and this would make
258:17
Speaker A
up an I. So the main difference between parallel and serial that I I want to make sure everyone understands because it can kind of get a little bit confusing for some of the serial protocols is that you will
258:29
Speaker A
see them start to have you know multiple lines and they still may use a clock um for synchronization.
258:37
Speaker A
But the really big differentiator of what still makes those serial is that even if we had four channels, you know, and we were talking serially, each of those channels would send all of their data or their frames on one channel. So,
258:50
Speaker A
you know, channel zero's data would not be intermixed with channel one's data. Whereas in parallel data, you know, each of these frames are split across each of the channels. Um so this whole frame is taken up by all of these channels and
259:05
Speaker A
that's what is considered to be this parallel communication. So in this course we're mostly going to be working with serial communication.
259:13
Speaker A
It's actually still you know very very commonly used for a lot of protocols and especially the protocols for our different components and chips on our device to talk to each other. That wraps up this lesson and actually wraps up our
259:27
Speaker A
theory section for electrical engineering for hackers. So, I'll see you over in the next section where we're actually going to look at our very first serial protocol on our board. Um, and we're going to hook up to that and start
259:38
Speaker A
doing some readings on it. So, I'm looking forward to that. I'll see you over in the lab when we take a look at that. Hey there. Hope you're enjoying the course. We'll get back to it really quickly. But before we do, I wanted to
259:49
Speaker A
call out again to just make sure you are subscribed both to my YouTube channel, which I'll link down below and also to the TCM Security YouTube channel, this one that you're watching the video on.
260:02
Speaker A
So, I would really appreciate it if you just take a second and check. Make sure you're subscribed and if not, hit that subscribe button for us. Thank you.
260:09
Speaker A
Welcome everyone. In this video, we're going to be continuing on our learning about digital serial communications by taking a look at UART. So, UART is a type of circuit or a functionality of a piece of hardware that allows us to do
260:26
Speaker A
asynchronous serial communication. UART itself is not actually a protocol. All it does is it just sets out a method that allows us to asynchronously basically transmit ones and zeros using electricity between either, you know, two circuits or two pieces of hardware.
260:47
Speaker A
So, we're going to start today's lesson by taking a look at what UART stands for and how the connections for it work. And then the rest of the lesson is going to be hands-on, which is why I've got the
260:58
Speaker A
router and the multimeter here. So, if you are following along at home, you'll need both the router and multimeter as we're going to then be taking a look at how we can identify the UART connection on this router and verify the pin out
261:12
Speaker A
for that connection. So, I'm just going to move these to the side for a second here so we can chat a little bit about UART.
261:22
Speaker A
UART stands for universal asynchronous receiver transmitter. And I'm just going to chat quickly about what each of these words mean in our acronym here. So universal, that's because this is a universally and widely used method for asynchronously transmitting uh serial
261:41
Speaker A
data. It's very very widely used. It's it's quite an old method, but you will still see it frequently used on electronics and come across it in hardware hacking. So asynchronous means that we have no clock synchronizing between our two devices that are
261:57
Speaker A
communicating each other. So the transmission and receiving do not have to happen on a clock signal and there's no shared clock. What we do need to do though, similar to that previous serial protocol that we were kind of making up
262:11
Speaker A
in the last lesson, is agree on a baud rate or speed that we're going to be transmitting at. So the receiver can then decode those transmissions.
262:19
Speaker A
And then the receiver transmitter. This one's pretty straightforward. It just stands for that the devices are able to both receive and transmit.
262:28
Speaker A
Now I've drawn out two devices here so we can look at the pin outs for standard UART and how they're connected. So I've got device A here and device B. So generally with UART communication nowadays, it's going to be handled by a
262:42
Speaker A
functionality uh of a processor or some other integrated circuit. So that's why just at its very very base level I've drawn these as chips eight pin chips and generally you're going to have you know many many more pins on the chips and
262:55
Speaker A
you'll have to look at the pin outs for them to see what pins are used for UART and just to simplify it I've just drawn it you know as these eight pin chips. So just to keep in mind also when you're
263:05
Speaker A
looking at this on a circuit generally you're going to have you know this soldered to a PCB and then we'll have traces that go off somewhere maybe to a header or other connections for these pins. So UR generally is going to have
263:18
Speaker A
four pins and they're going to be the TX pin and TX stands for transmission, the RX pin where RX stands for the receiver.
263:27
Speaker A
Then we'll have a ground and a VCC. So just like the TX pin you would expect it to be. This is the pin that transmits out. So, if we want to send out our serial communication, uh, we're going to
263:39
Speaker A
send out those voltage levels and those voltage pulses that we looked out on the transmit pin. The receive pin is we're just going to listen on this pin and measure for changes in voltage levels.
263:52
Speaker A
So, if we are to hook up uh another devices's transmit pin to this receive pin, then we're just going to sit and we'll hold this voltage level here on this until another device is going to uh put it high and then we can read.
264:08
Speaker A
We have a ground because for this serial communication to properly work, we need to make sure that both the devices are sharing a common ground. And the reason for that is we need to make sure that both devices are able to accurately
264:22
Speaker A
measure what that high voltage level is. You know, generally it's going to be 3.3 or 5 volts. So let's just use 3.3 volts for this lesson. You know, if this device is going to be transmitting and reading 3.3 volts, we need to share the
264:35
Speaker A
same reference to measure it from. So they're both on the same page. Finally, we have this VCC for supplying power. And this is generally not used especially in hardware hacking. But where we can use this is if we need to
264:50
Speaker A
supply power from one device. So for example the device A to device B. We could hook this VCC pin up and then supply power to a device that doesn't have its own power supply. So an example of where you might use this is if you
265:03
Speaker A
know you have a sensor or something like that that's using UART communication to send back its data and it's just a small sensor. It doesn't have any power. then we can hook up the VCC and grab some power off that. So, I'll just really
265:16
Speaker A
quickly draw up the lines here to show how generally we hook up two devices.
265:21
Speaker A
The transmit from one device, it actually goes not to the transmit of the other device, of course, but it goes to the receive. So, it's going to go to the receive here.
265:32
Speaker A
And then the opposite is true from the other device. transmit would go here and then it would come over to this devices receive.
265:43
Speaker A
We're going to hook the grounds together. So, that one's nice and easy. And then the VCC, I'm just going to draw an X here. And generally, what X stands for is no connection. So, we don't actually need to connect those on most
265:55
Speaker A
applications. And for what we're going to be doing in this course, we can just leave the BCC unconnected. So just one other quick note here on the transmitting and receiving functions of these devices.
266:09
Speaker A
Depending on how the designer of the software that's running on these devices and the circuitry that they are using, sometimes they'll only just be designed either to transmit or receive. So for example, maybe we don't want to actually
266:24
Speaker A
take in any commands or anything like that on the rece pin. So, it will either just, you know, it won't be connected at all to a header or maybe the software is just going to ignore whatever is on that
266:34
Speaker A
pin and we'll only just transmit data out. And the the opposite is true. Maybe we won't actually transmit anything out and we're just going to be listening to receive data. It's also up to the designers of the circuit to determine
266:49
Speaker A
whether or not we're going to allow both devices to communicate at the same time.
266:53
Speaker A
So UART will allow for this just on how it's set up and with having these two separate lines. We can actually have both devices. So device A and device B transmitting and receiving at the same time. However, it's going to depend on
267:08
Speaker A
how the software is set up whether or not what it's going to be expected is for example for device A to send out a message and then it won't transmit. It will wait until it receives some sort of
267:19
Speaker A
message back from device B. Some protocols enforce this, but remember UART itself, it's not actually a protocol. It's really just a method for us to essentially send ones and zeros from one device to the other device. And then what we do with those
267:36
Speaker A
ones and zeros is really up to the designers of the circuit. whether or not they build a protocol out on top of that or they just use it to send raw data or raw messages like we saw in our last
267:49
Speaker A
example where we just use the ones and zeros to send asy characters and that allowed us to send a message. This should give us enough information now that we can set this aside and we can take a look at our router PCB and try
268:01
Speaker A
and identify the UART connections on there. So, when I'm starting to do some initial recon on a device that I'm going to be testing or doing some sort of hardware hacking on, the very first thing I look for is a UART connection.
268:16
Speaker A
And now, to me, they stand out like a sore thumb when I see them because they're generally a really good source of lowhanging fruit for us or an easy win to get a foothold or some sort of information from the device. Now, the
268:30
Speaker A
UART connection here is this is right here. We've already taken a look at it.
268:34
Speaker A
And what we're generally looking for is some sort of connector or pads or through hole like we have on this device where there's four of them in a row like this. And that doesn't necessarily always signify it's UART, but it's a
268:48
Speaker A
really good spot to start. Now, on this device here, it's actually really good for us. They've labeled the pin out for us. You can see here we have the VCC, the ground, the RX, and then the TX pins
269:01
Speaker A
already labeled. So, this is a really, really good indicator that it is going to be UART. Now, on most devices, they're not going to make it this easy for us. Generally, they won't actually be labeled with a silk screen. So, what
269:15
Speaker A
we need to learn how to do is identify which of these pins are which and actually be able to check and see if this is a UR connection. And we can do that with just a multimeter.
269:28
Speaker A
Another thing that I will say also is even though these are labeled, it's still a really good practice to check our voltage levels and check the pins and make sure they actually match. Later on in this course, we're going to be
269:40
Speaker A
using this UART connection to connect back to our computer. And when I connect anything to my computer off of circuitry, I really like to check the voltage levels and make sure everything is okay because I don't want to damage
269:53
Speaker A
my computer. Luckily, from the previous lessons in this course, we already have all the skills that we need to test these with our multimeter. So, I've got it right here. The first thing that we're going to test with it is I've just put this on
270:06
Speaker A
the continuity setting, and we're going to double check and make sure that this this one, which is labeled ground, is actually a ground connection. You may remember, we actually already tested this, so we're going to do it quickly
270:16
Speaker A
here again. But we also identified this little bare metal pad right here that's denoted with, I believe, a P1. This is a ground connection as well. So, we can just check the continuity really quickly between the ground and this P1.
270:36
Speaker A
So, for continuity, the polarity doesn't matter. So, you can touch either one of the leads to each one. We need to touch one lead to this P1 here and then the other one to ground.
270:46
Speaker A
And I immediately get a beep. So that's perfect. We know that this one is in fact a ground. Now to test these other pins, we're actually going to be measuring the voltage levels. So what we need to do is go ahead and plug in the
270:59
Speaker A
router. And I'm going to do that right now. Okay. So I've powered on my device here and we see that it's looks like it's stabilized in its boot up. And I've just brought my multimeter up a little bit
271:11
Speaker A
closer so that it's in focus and easy to see the voltage we're reading. And I've switched it to the DC voltage setting here at 20 volts. So you'll want to do the same if you're taking this measurement.
271:23
Speaker A
The first thing we're going to check is the VCC voltage. And what that's going to do is give us an indication of what voltage level the UART is operating at.
271:32
Speaker A
We're expecting to see either 3.3 volts or 5 volts here. So to measure that again, we can just do from the VCC pin here with the red lead to that same ground that we've been using.
271:45
Speaker A
And if I hold this on here tightly, we get that perfect at 3.3 volts.
271:52
Speaker A
Perfect. So we know that that BCC pin is labeled correctly and we're operating at 3.3 volts, which is important to check.
272:01
Speaker A
The next pin that we're going to check is the RX pin. And we know that this one should be 0 volts because we're only going to be listening on it. So when we measure the voltage at this one, we're
272:11
Speaker A
going to be expecting 0 volts. So in the same manner as the VCC, we'll check the RX pin here.
272:23
Speaker A
Perfect. It's right at 0 volts and that is what we're expecting. The next pin that we're going to check is the TX pin.
272:31
Speaker A
So unless we happen to catch a transmission, which is pretty unlikely just during this regular operation, then we're expecting to see this at 3.3 volts. So let's check that now.
272:48
Speaker A
Perfect. Right at 3.3 volts. Okay. Okay, so you may be wondering if these weren't labeled, how can we tell the difference between which one is the VCC and the transmit?
273:00
Speaker A
So what we can do is we can force a transmission on the board. And the easiest way to do that is actually just to reboot the router or, you know, unplug the power supply, replug it in.
273:13
Speaker A
You ever watch like your BIOS on your computer when you're starting up? There's a lot of messages that come through. There's a lot of logging that takes place right at startup. there's a lot of important, you know, messages
273:23
Speaker A
printed out. And that's the same with this router as well. If we unplug it and then reboot it up, we should be able to see a bunch of transmission taking place. So, what I'm going to do is I'm
273:34
Speaker A
just going to unplug this and then plug it in. And then pretty quickly, I'm going to try and probe the transmit pin again so we can catch those boot up messages. And what we'll be looking for is we'll be looking for that 3.3 volts
273:48
Speaker A
to drop down to something in the 1vt or 2vt range. And we'll talk about why that's happening in a second here. So, I'm just going to unplug it and plug it back in.
274:07
Speaker A
I'm going to start probing. Now you can see this 3.3 volts is jumping all over the place here. We can see some transmissions happening right there when it drops down.
274:26
Speaker A
Now the reason this is happening is if you remember from when we were looking at the diagrams of that serial communication when we actually have communication it's happening very quickly. we have all these blips of of ones and zeros. So, we're holding the
274:41
Speaker A
line high at 3.3 volts to send the one and then we're drawing it low to send the zero and so on. And this happens really, really quickly in actual UR communication, especially on more modern electronics. Uh, and our multimeter,
274:55
Speaker A
it's just not fast enough to pick up those changes. So what it sees when it's measuring and we have those blips of transmission where we quickly switch from 0 to 1 or from 0 volts to 3.3 volts is we pick up an average of that. So
275:08
Speaker A
that's why we see it coming down into the 1 something volt or 2 point something volt during those transmissions.
275:15
Speaker A
So this is a really exciting finding for us. We visually identified what we thought was a UART connection. we were able to verify the pin out on it with our multimeter. And then during boot up, we were actually able to identify what
275:27
Speaker A
we believe is a transmission taking place. So, what we're going to do in future lessons is look at that transmission and use that to further learn about how UART actually works.
275:40
Speaker A
I'm going to move the router and multimeter out of the way here because we should probably take some notes about what we found here.
275:47
Speaker A
Again, apologies for my really bad handwriting, but I just wanted to quickly show you what notes I've taken for here. So, we visually identified a UART connection. We tested that the voltage level for it is 3.3 volts. We
275:59
Speaker A
then confirm the pin configuration uh that it matches the silk screening. And then we actually identified a transmission during boot up. So, important to keep these notes for our reporting later and to keep track of what we've done. And this is a really
276:13
Speaker A
great finding that we are going to take a look at in more depth in the next videos. So that wraps up this video. I will see you over in the next one.
276:23
Speaker A
Welcome everyone. So before we move on to part two of our intro to UART and start looking at the transmission that we actually discovered when we were probing the router in the next lesson.
276:36
Speaker A
We're going to need to make a slight modification to this router. So, you notice the UART connection. If I just bring it up closer to the camera here, our UAR connection that we identified in the last video, we just have these
276:51
Speaker A
throughhole pads right here. And these aren't going to be very good for us to connect to with the tools that we have.
276:59
Speaker A
So, in the next lesson, actually, what we're going to be doing is we're going to be connecting this protocol analyzer and talking about it in more in depth, and we're going to use this to be able to check what's going on with that
277:10
Speaker A
transmission. And you'll notice to connect to it, we've got these female leads here, which they're not going to connect to what we have on the board.
277:19
Speaker A
And same with this UART to um USB adapter here we're going to be using.
277:24
Speaker A
It's the same thing. So, we're not going to be able to connect these directly to the board. And I'll just move these out of the way because we're going to use them in future lessons.
277:36
Speaker A
So what's happened with this board most likely is that during development and testing, the designers and testers of this board, they would have been using this UART connection to get their logs out and to issue commands to the router
277:50
Speaker A
uh and do various testing that they need to do. And at that point, they would have either manufactured it so that there was a header pin connected to this uh or they would have just added one themselves. And then once it's gone into
278:03
Speaker A
production, so we have a production unit here. They they would remove this header because as consumers, we're not going to be needing to open it up and use this UR connection. Of course, as hardware hackers though, we love that they've
278:16
Speaker A
left this here and we're going to want to use it. So, what we can do is we can add in our own header connection to it.
278:24
Speaker A
And there's two ways that we can do this. The way that I'm going to cover in this video is one way that we can do it without soldering. And then in the next video, what I'll show you, and this is
278:34
Speaker A
totally optional and up to you if you want to do it, is you can solder the header pins to this. So, just a quick note before I get into the details on how we're going to, you know, do the
278:43
Speaker A
method without soldering. I I do want to say that it's not the best option and it's not the best way to do this. The reason for that is if we do this without soldering, we're going to be opening
278:55
Speaker A
ourselves up to potential issues down the road with the connectivity between the header pin and these pads. And this can cause just really annoying nuisances down the road where we're not sure if the problem is with what we're doing uh
279:10
Speaker A
and you know how we're setting up our communication or if we just have a bad connection here and we're not able to properly transmit those electrical signals. So if you are comfortable with it and up for the challenge, I really do
279:22
Speaker A
suggest soldering. You know, if you were doing this in a professional capacity, then you would definitely be soldering this. And if you're wanting to get into more hardware hacking down the line, then it's a really good skill, an
279:34
Speaker A
important skill to have to be able to at least make these throughhole solder connections to either do soldering or remove uh components by desoldering.
279:45
Speaker A
So, with that being said, you still can do everything in this course that I'm going to be doing with this header connection using the solderless method as long as you just keep in mind if you have issues to come back and double
279:56
Speaker A
check that connection and make sure uh your ground connection and voltages are all still proper. So, I'll just set this down and bring over here what we're going to be doing in this lesson. So, I've got the header pins here. Just a
280:09
Speaker A
set of really basic throughhole headers. and they come uh in these strips and then you just break them down to how many you need. So, we'll be snapping this down to the four that we need in a second.
280:22
Speaker A
And then I've also got this twist tie here that it's got a plastic wrap around it, which is perfect. So, it's not going to be conductive and mess anything up our circuit that way. Uh, and it's this twist tie that comes with our router,
280:34
Speaker A
and I have mentioned a couple times to save it. And we're going to use this to actually attach that header down in such a way that it should give us an okay connection. So, I'll just set this aside
280:44
Speaker A
for a second and I'll bring the board closer and I'm just going to pull the PCB out of the plastic container.
280:52
Speaker A
And if I hold it up closer here, just from the edges, you'll notice that we've got this hole. We're kind of lucky. I'm not entirely sure what this hole is here for, but it's drilled into the board right here. And I'll just stick my
281:05
Speaker A
pointer through it so you can see. And again down here, it's drilled through. And we can seat those headers in here just without soldering. Uh, and if we do that, they're going to be too loose to actually have an electrical connection.
281:17
Speaker A
But if we tighten them down by putting the twist tie through here, uh, wrapping it around those header pins, and then twisting that twist tie, we can make it so that there's going to be enough of a connection here. here. And I' I've
281:29
Speaker A
tested this quite a few times. And as long as you know you get the twist tie in here good and you tighten it down, then you're going to be able to get um good communication both through the protocol analyzer and to the USB to UR
281:41
Speaker A
adapter that we're going to be using later. So, I've already used these a couple times and so I've snapped them off. So, they're a little bit shorter than how they come, but it's going to be the same idea. What you can do with them is they
281:55
Speaker A
are perforated and you just grab them and snap them to the length that you want. So, we're going to use four for this. You you may recall that we only actually need three of the pins, but the more we have, the better connection
282:08
Speaker A
physically to the board we're going to get. So, it's better to use that extra one even though we're not going to use it. So, I'm just going to grab it here.
282:14
Speaker A
And I put my thumb, you know, if I just cover up four of the pins, uh, and then just put the pressure on it there, it snaps right at four. So, we've got that four pins here.
282:26
Speaker A
And I'm going to take these and just slide it into the holes to start with in the connection. And it doesn't matter what the orientation of these are.
282:37
Speaker A
Can go either way, but you're going to want the longer ones on the top and then the shorter ones in the bottom.
282:47
Speaker A
All right. So, I'll just drop them into this hole here. All right. So, if you're following along and then if you do this and you notice like they're really loose. They're not like I just touched them and they fell out. So,
283:02
Speaker A
it's not going to be sufficient for us to have any type of electrical connection.
283:08
Speaker A
The one thing I want to show here now and is if I if I just tilt this a little bit here.
283:13
Speaker A
What you're going to want to do to get this connection to be good is you're actually going to want to tilt these on an angle just a little bit like this.
283:20
Speaker A
like I have here. And the reason for that is I'm just going to set this down.
283:25
Speaker A
So, I'm just going to show kind of with my hands what I mean by that and how the pad works. So, I'm just going to set this aside for a second so it's it's a little bit clear. So, if you just think
283:32
Speaker A
of my hand here, this circle being the pad, um, and then my pointer being the actual uh metal lead that's going to go through it. So, right now, what's happening is we're putting that lead through and it's fitting very loosely
283:43
Speaker A
inside of there. So, we're not getting a good connection. And what we should be doing is then, you know, putting some solder in here and that's going to hold that in place and also provide that interconnectivity. But one way we can get around that is, you
283:56
Speaker A
know, the inside of the pads on this router, they actually have that metal connectivity in them. So like it's not just the top pad itself, it's also the inside. So if we bend, you know, this is going to be really extreme, but if we
284:10
Speaker A
bend the pin over, then it's going to force a connection on the inside. And that's actually going to what be what's allows us to have that connection. If you just do it straight up and down like this and you connect it with the zip
284:23
Speaker A
tie, then you're not actually going to get a good connection. So, I'll just bring this back over here.
284:29
Speaker A
Uh, and I'm going to try and show it as best I can on camera, but it's honestly kind of finicky. So, I'll I'll do my best to show it on camera. And if I can't get it on camera, then I'll show
284:36
Speaker A
you the end result. All right. So, I've got it here to where I think I've got a good connection. And, you know, if I touch it lightly, then there's no movement or wiggle, which is what you want to see on this. You don't
285:00
Speaker A
want to give it a big push cuz the tie's not going to hold it that tight. You're going to bump it out. But, as long as you don't have any wiggle, then it's probably going to be good. Um, but what
285:08
Speaker A
I do suggest you do, and this is actually pretty important to test this, is we're going to go back now and actually retest just like we did the first time onto the bare pads. We're going to test at the end of these pins
285:18
Speaker A
cuz that's where we're going to be connecting to and make sure they are still okay and we have that good connection. So, I'm going to put this down, grab the multimeter, and just really quickly test those.
285:29
Speaker A
Okay, I've got it back on the continuity setting, and we're just going to really quickly test the ground. So, same thing we did before, but we're actually just going to test the end of this pin.
285:49
Speaker A
And it's a good thing we checked this because I thought that this was good on here, but I don't actually have that good connection. So, I'm just going to revisit and make sure I'm pulling this down tight enough.
285:59
Speaker A
Okay, I've just tightened this down again. And I'm not really sure if you can see any of the changes I made, but I just made sure to get it a little bit tighter. Uh, and try and exaggerate the
286:06
Speaker A
angle that it was on here and how I have tightened this down. And I'm just going to test that connection again now. So, I'll check the ground again with the continuity tester.
286:20
Speaker A
Perfect. So, I'm getting a beeping immediately. And I'm still going to check the other pins because just because we have that ground one down tight enough doesn't mean that we have the other one seated. So, I'm just going
286:28
Speaker A
to plug it in and we'll at least test the VCC and transmit pins and make sure they're all good as well. All right, so I've got it plugged in. I'm just going to switch my multimeter over to that 20
286:37
Speaker A
volt DC reading again. And we'll test quickly the BCC and ground pins in the same method that we did before.
286:54
Speaker A
Perfect. So VCC is working. And I'm just going to test the transmit pin while I'm here.
287:00
Speaker A
All right. And the transmit pin is working. So just a quick note when you're testing them too, you're going to want to be probing uh fairly lightly on these pins to make sure you have good connection cuz if you're actually, you
287:10
Speaker A
know, pushing really hard down on these pins, and that kind of defeats the purpose of checking for the connection, you want to be simulating as if you were just connecting something to it where there's not going to be any pressure. So
287:20
Speaker A
make sure you are touching lightly. And if you run into communication problems down the road with your UR connection and you did go this method of using the zip tie, then what I would do is just come back and retest every one of these
287:34
Speaker A
pins and make sure they're working as expected with the multimeter because eventually, you know, this is going to loosen up and you're going to lose this connection. So, keep that in mind. With that being said, in the next video, I'm
287:47
Speaker A
going to show how to solder this and make it more permanent so we don't have to worry about that. If you're going to skip over that video, I just want to let you know about that because when you're
287:55
Speaker A
going to see me doing this in the future lessons, you will see this soldered in place cuz I'm going to do it in that video. You won't see this connection.
288:03
Speaker A
So, I have tested quite a few times just to make sure that it's realistically doable. And you can connect the UART to USB adapter and the protocol analyzer to those header pins with this method and reliably get that data as long as you
288:16
Speaker A
make sure you've got it tightened down. So, that wraps up this video. I'll see you either over in the next one where we do some soldering or in the final UR video where we're going to connect our protocol analyzer. So, I'll see you over
288:27
Speaker A
there. Welcome everyone. So, in this video, I'm going to be demonstrating how you can solder those header pins onto the router UART connection in order to not have to use that twist tie method, which is going to produce a much more reliable
288:43
Speaker A
connection if you do choose to solder it. And it's entirely optional if you choose to do that. Again, you can just use the twist tie method that I showed before.
288:53
Speaker A
So, if you're already familiar with soldering and you just want to skip to the part where I actually am soldering the header pins on, then feel free to skip ahead. But I am going to start this lesson with just showing the basics of
289:05
Speaker A
soldering and how we can do through hole soldering in case this is your first time doing any soldering. So, if you do want to follow along here, at a minimum, you're going to need a soldering iron.
289:16
Speaker A
So, I've got mine right here, a soldering station, and then some solder. You're also going to need a few items for safety. So, the first one is, and I'll show right here, I've got these on.
289:28
Speaker A
So, I always wear safety glasses when I'm soldering. And I know that may sound silly to some people, but if you have worked with solder, um, you'll notice that sometimes the way that it drops and splashes, it it can be very erratic in
289:41
Speaker A
how it splashes. And you know, the last thing you want to do when you're looking up close at something to make sure you're getting the solder right is have a piece of hot metal drop into your eye.
289:52
Speaker A
So, also generally when you're soldering, you're going to want to have something to remove away the fumes so you're not directly breathing them in.
289:59
Speaker A
Uh most solder, including the one that I'm using, it has lead in it. So, really nasty stuff to breathe in. So, I don't have my fume remover on right now, actually, just cuz I'm only going to make a couple of solders and the sound
290:10
Speaker A
of it really does mess up the recording quality of the sound, but something to keep in mind that you should also be running that. And then just a couple of other quick safety things. Honestly, this goes without saying, but to be
290:23
Speaker A
honest, I'll raise my hand and say that I've burned myself with a soldering iron before. These things get extremely hot.
290:28
Speaker A
We're going to be, you know, essentially melting metal with it. So, they get very, very hot. And you know, anything that any part of them that is metal gets hot. So even though it's just the very tip of it here, you know, all this area,
290:42
Speaker A
the cage, all of that, that gets super hot and you could burn yourself on it.
290:47
Speaker A
So, you know, you don't want to be like this meme lady that I'm going to pop up on the screen right here.
290:54
Speaker A
And then finally, something to keep in mind is that whatever we are, you know, soldering to, we're going to be touching and heating up as well, and it's going to get hot. So, I've got a couple resistors here that I'm just going to be
291:04
Speaker A
using as test pieces to demonstrate the soldering. And when we're soldering it, like even if you know we're soldering this end and then we're trying to hold it in place on this other end, well, the whole thing is going to get very hot.
291:16
Speaker A
And, you know, I've personally done this myself before where I'm just trying to really quickly hold a piece in and not use a third hand or something else like that. Uh, and and you can burn yourself because the whole actual piece of metal
291:28
Speaker A
is going to get hot. Again, it's designed to conduct electricity, these wires. So, they're also going to be very good conductors of heat. So, something to keep in mind.
291:37
Speaker A
Those couple of safety things uh out of the way, let's get started on our actual soldering. So, what I'm going to do is I've got a piece of proto board here that I, you know, I've broken off and I
291:49
Speaker A
just using this to practice soldering. So, the way these work is I've got a whole one here. I just didn't want to waste a whole one for this practice. is they're kind of like a PCB in that they
292:00
Speaker A
have all these pads on the back like you would see in through hole components on a PCB. And then, you know, there's just nothing on this end. There's the drill holes. And these are designed for prototyping when we're making a circuit
292:12
Speaker A
that we want to be more permanent, but we don't want to actually design a PCB.
292:15
Speaker A
So, we can just put our through hole components in here, solder them onto the back, and then it's up to us to create jumpers instead of having the traces like we would on a lead. And you know, another use for these is they're great
292:27
Speaker A
to practice soldering if you want to get a get a practice in without actually doing it on an actual board where you might cause some damage to anything.
292:37
Speaker A
Okay, so I've got mine here, and you don't necessarily have to use a third hand, but it's going to make your life a lot easier if you have one for soldering. Um, so I'm just going to mount this actually in the third hand
292:49
Speaker A
here. these two. And the nice thing with these four ones is we can actually use these other hands then to hold components in if we need.
293:03
Speaker A
And I've got my resistor here. You can see I've actually been practicing with just a few other before I turn on the camera just to make sure my soldering iron was hot enough. Um, and what you can do with these resistors if you are
293:14
Speaker A
soldering any through hole components like these resistors is we just bend the leads up.
293:21
Speaker A
And I'll just pick a couple holes here to slot this through. It doesn't really matter since we're not, you know, actually putting this resistor anywhere.
293:28
Speaker A
Um, and then with these leads, what we can do is we can just fold them down to hold the resistor in place. So, it's kind of nice with with resistors and other throughhole components when they have these leads. We don't have to worry
293:39
Speaker A
about holding them in place. We can get this to hold it down. So, I'm going to grab some solder here and demonstrate how we actually make these solder connections. So, the first thing you want to do just to check and
293:53
Speaker A
make sure your soldering iron is hot is we're going to do what's called tinning the tip. And what that is is I'm just going to touch a little bit of this solder to the tip of the soldering iron
294:02
Speaker A
and make sure it melts and we get a good connection here. So, perfect. It just immediately melts. And I keep a little bit of that on the tip.
294:11
Speaker A
Now, when we make these solder connections, what you want to do is we actually want to heat up the pad and the component lead. and then touch the solder to those and have the solder melt as opposed to, you know, trying to just
294:26
Speaker A
touch the soldering iron, get the solder to melt and have that, you know, then try and glob onto the leads. So, I think it's easiest if I just show that for the first time. So, what I'm going to do is
294:34
Speaker A
I'm going to hold the soldering iron up to the pad here, uh, and let it get hot and let the lead get hot and then I'm going to touch the solder to that area and pull it away. Okay. And perfect. We
294:48
Speaker A
get a nice solder joint there. And I'll just show on the other one. Again, I'm just touching the solder to the pad and the resistor lead. And then I'm touching the solder to that pad and resistor lead. I'm not necessarily touching it to
295:01
Speaker A
the soldering iron tip itself. You see here we get two nice solder joints. Okay. So, I just moved the prototyping board a little bit closer to the camera so it's really clear what I'm doing. And I've got another resistor here. here.
295:16
Speaker A
And what you can do with these through hole components, if I just show it in front of the camera, is that we could bend over the leads like this and then just slide them into the hole. So that's
295:24
Speaker A
how we solder those in. And I'm just going to pick a couple holes at the top here. And we'll just slot this through.
295:30
Speaker A
It really doesn't matter cuz we're just practicing what ones we do. Okay, we'll do this one um on an angle here. So I get the top one here and then over here.
295:42
Speaker A
I'm just going to pick up my soldering iron here. So, the first thing that you'll want to do when you're making a solder is what's called tinning the tip. And this is a good way also to test that a soldering
295:53
Speaker A
iron is hot enough. So, I'm just going to take just do a really quick just tap of the solder to the end and make sure that it actually melts on there, which it did. So, that shows us that it's hot
296:01
Speaker A
enough. And then what we want to do when we're making these solder connections is we don't actually want to be, you know, melting the solder with the soldering iron. So, it's liquid and then kind of trying to touch that or attach that to
296:13
Speaker A
these leads. What you actually want to be doing is we want to touch the lead and the pad that we want to solder with the soldering iron and let it get hot.
296:21
Speaker A
And then we touch the solder to that pad. And you see here we've got uh you know a really good solder joint by doing that because the way that the solder works is actually going to want to flow
296:30
Speaker A
towards the heat. So what that does is it makes the solder pull nicely around the pad and the component and it doesn't go anywhere that we don't want it to do.
296:39
Speaker A
So I'll do another one here. Right here. Again, you can see I'm actually just touching the lead and the pad. And then I'm going to come in from the side here and do a really quick solder like that.
296:51
Speaker A
And we get a nice solder joint. So, I've got a couple examples of bad solder joints on here from when I was testing.
296:58
Speaker A
Um, and just to show you how those happen. So, you know, for example, here, this is what happened when I was just playing around with dropping the solder on. So, you'll actually get what's called a bridged connection. So, we've
297:09
Speaker A
got this, you know, chunk of solder that goes across too. And we've done that here. So, I just show you here quickly.
297:15
Speaker A
Um, you know, how we can get that if I use these components right here. And I just instead I'm just like kind of melting the solder and trying to put it on.
297:26
Speaker A
See here that it does not honestly it's not sticking very well. I'm getting like these globs. Um, and that's what gives us the bridge and a bad connection. So again, that's why we just want to be touching the soldering iron to the pad
297:37
Speaker A
or the lead and then the solder to that. And that's what lets us get that really nice connection for the throughhole solderers. So if this is your first time soldering, I would really highly recommend getting a couple of these and
297:49
Speaker A
actually soldering them. So what I'm going to do now is I'm actually just going to do a practice as well with the header. I've got a spare header pin here, and we'll just pick a spot here and slot it in.
298:10
Speaker A
So, you'll see I'm making use of the third hand for this because there's actually no really good way for me to, you know, hold this in place with my hand and then solder it. Uh, if you can see it, it's right at the top here,
298:21
Speaker A
these connections. So, I'll just demonstrate a few good solders in how to do those.
298:59
Speaker A
So, the one other thing I will just quickly mention with soldering is you will have noticed there um that I didn't linger when I'm making these solder joints. As soon as I I notice that it's melted and I've got it the solder in the
299:10
Speaker A
spot where I want it to be, then I'm actually pulling it away. And the reason for that is when we're soldering, you know, some components, especially like transistors, diodes, and integrated circuits, the extra heat from the solder gun, it can actually cause them to burn
299:24
Speaker A
out. So, we want to be um, you know, as quick as we can while still getting that good solder joint.
299:30
Speaker A
So, now that we've got a little bit of practice in on that proto board, I'm just going to grab the PCB for the router here, get it set up in the third hand, and then we'll take a look at
299:41
Speaker A
soldering the header into the router PCB. Okay, so I've got the router installed into the third hand here, and I've got it really zoomed in so I can show you how I'm going to make those solder connections. These four pads right here,
299:56
Speaker A
and this is the underside of the PCB. You'll notice that there's, you know, no components or silk screening. This is the underside of that UART header. So, what I'm going to do is I'm just going to stick the header pin into there. And
300:07
Speaker A
I'm going to make use of the third hand tool as well to hold it in place here.
300:19
Speaker A
So, I've just got it snapped in place there with the third hand tool. Uh, you can see the leads are coming through here. And if you don't have a third hand tool, what you can actually do is you
300:29
Speaker A
can hold it in place with a little bit of tape uh or even some sticky tack or something like that so that you don't have to be holding it with your hand.
300:36
Speaker A
So, same as before, I'm just going to test and make sure my soldering iron is hot. Um, best to do this actually not over the board like I was just about to there. So, I'm just going to check it,
300:46
Speaker A
but I'm going to check it out of camera here. All right, mine is hot enough. So, I'm ready to actually get soldering. Again, we're just going to be touching the soldering iron to the pad and the lead and then the solder to those.
301:06
Speaker A
We get a nice clean solder. And I'm going to move on to the next one.
301:14
Speaker A
Nice clean solder. Moving on to the next one. Perfect. And those look good to me. So, what you'll want to check when you are um you know visually inspecting these is to make sure you don't have any bridges.
301:40
Speaker A
So you can see I can actually fit my pointer here through and I don't have any solder that's touching because if we do actually get solder that's going across here, what that's called as a bridge and then we're going to have
301:50
Speaker A
connectivity between the two points and that's not good. That being said, what I am going to do now is I'm going to, you know, move the soldering iron out of the way, turn this off, and we're going to do the same
302:00
Speaker A
thing that we checked when we were using the twist tie method, and we're going to check to make sure all of our connections are still good. We've got that ground connection, and the voltage is as we expect them.
302:12
Speaker A
Okay, so I've got my multimeter here and then same as before, we're going to start by using the continuity setting to do a continuity check between the ground pin and this ground plate down here.
302:28
Speaker A
And I got a beep immediately. So that's perfect. It means we have a good solder joint and we have a good connection. Uh, and I'm just going to check the voltages on the BCC and the transmit pin as well.
302:38
Speaker A
So, plug your router in if you are following along at home. Going to switch my multimeter over to the DC voltage setting again at 20 volts.
302:48
Speaker A
And then the same as we have previously, I'm going to start with the VCC, which is the top pin here, and probe from the VCC to the ground here.
303:00
Speaker A
All right. And I immediately get that 3.3 volts. So, that's as expected. And I'm going to check the TX pin here in the same fashion.
303:09
Speaker A
And we see it at 3.3 volts as well. So that's perfect. If you want, you can check the RX pin. Should be 0 volts.
303:15
Speaker A
Okay, perfect. 0 volts. Just to make sure there's no bridging or anything like that. And perfect. It's at 0 volts.
303:20
Speaker A
So we know that all of our solder connections are good and we are good to go. So if you did take the sold soldering route and this is your first time soldering uh and it all worked out like this, then congratulations and good
303:33
Speaker A
on you. That wraps up this video. I'll see you over in the next one.
303:40
Speaker A
Welcome everyone. In this lesson, we're going to be continuing on learning about UART. And in doing so, we're actually going to take a look at the transmission that we identified on the router PCB that was taking place during bootup.
303:55
Speaker A
Now, to do so, we're going to also be learning about the next tool in our hardware hacking toolkit, which is this device right here, a logic analyzer.
304:05
Speaker A
So, what logic analyzers allow us to do is to connect to the various communication points on a circuit or a PCB and then record any of the digital communications that are going on on that channel as a capture. And then what we
304:22
Speaker A
can do with that capture actually is with the software that comes with these analyzers is we can actually use it to decode those transmissions and figure out what's actually being transmitted.
304:33
Speaker A
Now that's as long as we're able to figure out what you know protocol is being used and the various parameters that are taking place with that communication. Luckily for us, if we understand how the protocols work, then when we look at these captures, we can
304:49
Speaker A
usually get a pretty good idea of what is going on and the different parameters that we'll need to set to decode them.
304:56
Speaker A
So, I think it's easiest if we just jump right into it and get this analyzer set up to capture the traffic from that router. Now, if you chose not to buy one of these, that's okay. You'll be able to
305:09
Speaker A
follow along with most of this lesson. The great thing about the captures that you take with these is they can be saved for analysis later on. And I will save all of the captures that I take and make
305:20
Speaker A
them available so you can open them up with the software still and follow along.
305:25
Speaker A
So on this analyzer right here, we've got a nice picture that just demonstrates the pin outs of the pins right here. H and it's just a transposition. So you know if you you were looking at the top of it like this,
305:37
Speaker A
that's how these pins represent. So, the two most important ones that we've got to take note of are the ground pins.
305:44
Speaker A
Again, we need that ground for our communications to be able to work. So, I'm going to hook my jumper up to that first. And I'm going to use the black wire just because that's generally the one in electronics that's used for
305:56
Speaker A
ground, but you can really use whatever colors you want here. The colors do not matter at all. I'm going to connect my black one to the bottom, one of the bottom two pins. Either one is fine.
306:06
Speaker A
There's two ground connections there. And then for the UART communication, we actually are only going to need to use one channel. And that's because we're just going to be listening to that transmission. Again, you can think of this as being like the receiver, and
306:22
Speaker A
we're going to receive that transmission. So, we just need the one channel. We're not going to be sending anything back or transmitting anything.
306:29
Speaker A
So, we don't need a second channel. And you can use whatever color you want for this. Uh, I would suggest you use channel zero, but realistically you can use any channel except for ground. The nice thing about channel zero is you see
306:42
Speaker A
we've got this power up here at the top and this channel zero down here at the bottom. Well, these are LEDs. So, when you plug this in, you're going to get the power indicating that it's turned on. And then this channel zero LED, it
306:54
Speaker A
will actually light up when there's communication on channel zero. And it only works specifically for that one channel with that indicator, but it will give you a good indication if you've got everything hooked up and you're actually getting data being transmitted. You'll
307:07
Speaker A
see this channel zero flashing. So, that's why I'm going to use channel zero. Uh, and I got the purple one right here. So, I'm going to use that. And it is this top left pin right here. That is
307:18
Speaker A
channel zero. Okay. So, I've got it pushed in. Sometimes these pins can be a little sticky, so you just need to use a little bit of force. But I've got these two hooked up. So, what I'm going to do now
307:30
Speaker A
is I'll just bring the router over here, and we're going to hook them up to the router. Before I do that though, I will just mention, you'll notice I don't have the protocol analyzer plugged in yet to computer. So, don't plug that in yet.
307:41
Speaker A
And also, make sure your router isn't powered on when we're going to be plugging this in. We'll turn it on later once we've got everything set up on our computer and we're ready to make that capture.
307:57
Speaker A
Okay. So, I've got the router here, and I'll just bring these pins up nice and close so we can see them again. Uh, and again, we're just going to be connecting the ground pin. So, that's this one. If
308:07
Speaker A
I can just grab it right here. So, the ground pin and then the transmit pin.
308:13
Speaker A
So, the black will go to the ground and then purple will go to transmit. I'm just going to hook those up quickly right now.
308:32
Speaker A
Okay, so I've got those hooked up. Uh, if you're following along, make sure they're hooked up the same as well. Just do a quick double check. Make sure got black to the bottom ground pin of the analyzer and then purple to channel
308:43
Speaker A
zero. black to the ground on the router and then purple to the transmit pin. I'm going to head over to my computer now and we'll take a look at how to install the software and the drivers for this.
308:57
Speaker A
And then after that's done, we'll plug the analyzer into the computer and then turn the router on. But just really important until we do those, uh, don't power on either of these. Okay, so I'm back over at my computer now. And you
309:09
Speaker A
may have noticed in the past videos when I was on my computer that I'm using a Kali Linux machine and I'm actually running this as a VM using VMware.
309:20
Speaker A
Now I'm not going to go over specifically how to uh set up a Kali VM in this. I'm going to assume if you're watching this through the TCM Academy that you're already familiar with how to set up that VM. Uh I would suggest using
309:34
Speaker A
Kali Linux because it's going to allow us to install or already have all the tools that we'll need for the rest of this course. So before we go on with this lesson, I just want to make a quick
309:44
Speaker A
note about that. With that out of the way, we can get started on installing the software that we're going to need to connect up to our logic analyzer. And what we're going to be making use of is some software offered through the
309:57
Speaker A
Sigrock project. So I'm just going to go check out their website right now. It is sigrock.org.
310:06
Speaker A
Just like that. And if you want to read about their project, it's a pretty cool uh open-source project that allows for us to have access to cheap logic analyzers like the one that we bought and then use make use of some open-
310:20
Speaker A
source firmware and then also their software that's going to connect to the logic analyzer and allow us to actually analyze those captures. So, I just went to this website to check it out. We can actually get their software through the
310:35
Speaker A
aptget repository on Kali Linux. So, what I'm going to do next is we'll just open up a terminal.
310:41
Speaker A
Always a good idea to update your repositories first. So, I'm just going to do that right now and I'll let this run through. Okay. So in order to install this through appget it's going to be pseudoapp get-y install and then it's just sig rock.
311:15
Speaker A
Perfect. So looks like it is installed. Now, the actual specific software we're going to be making use of to view the logic captures and also make those captures is called Pulse View. So, that is the software that's created through
311:28
Speaker A
the SIGRO project. So, I'm just going to launch that up right now. All right. So, this is a software we're going to be getting used to using to take captures with our Logic Analyzer and then also to analyze them. So, I
311:47
Speaker A
have my router powered off now, as you should as well. And I also have my logic analyzer um not connected to my computer through USB. But what we can do now is we're going to connect the logic analyzer to our computer through USB.
312:01
Speaker A
And then if you are using a VM like me, then you'll have to make sure you connect that USB device to your VM as opposed to the host machine. So, I'm just going to plug in the USB cable
312:11
Speaker A
right now to my logic analyzer. All right. And it should show up as this Lake View USB device. And it's perfect that it's just popping up for me. So, I'm going to click okay. So, if you don't get that popup for me, I'm on
312:33
Speaker A
VMware Pro. So, if I come up here uh and I and I do the drop down here and go VM and then removable devices, then you can uh connect or disconnect it through here. So, it's going to show up as this
312:45
Speaker A
lake view logic. Uh, and it's similar if you're not on the pro VMware. And then it's also very similar if you're using virtual box. So, remember to connect those.
312:56
Speaker A
So, I'm just going to make sure mine is connected right now. So, this logic analyzer already actually comes loaded with one of the open source firmwares that's developed through the Sigrock project, which is the FX2 LFW firmware. And the reason we need to know
313:14
Speaker A
that is we're going to need to set up Pulse View to communicate with our new device. So, what we're going to do is just go up here and we're going to click on demo device in the drop down here and
313:25
Speaker A
we're going to connect to a device. And then we're going to have to choose a driver. So from this drop down here, we're going to go and we're going to pick this FX2 LAFW generic driver for FX2 based LAS. So we'll click on it here
313:40
Speaker A
and then we'll just leave it selected as USB. We have it connected through the USB and then we're just going to click on scan for devices and it's going to be this one right here. This SEA logic with
313:51
Speaker A
eight channels is the one that we are going to grab. So, I'm not entirely sure um why the device is named as this. This is the name of another company that makes logic analyzers. So, I don't know if these
314:03
Speaker A
makers at one time were trying to pass this off as a clone or not. But, we're going to be using all of the uh open- source drivers and this open- source software with it.
314:15
Speaker A
So, you can just click okay, and it's going to add that device. Now, if you get an error at this point about the device not being supported, uh, or there's an issue connecting to the device, I've noticed that if you
314:28
Speaker A
have the USB for this logic analyzer plugged in through a USB hub or something like that, uh, it really doesn't like it. So, make sure if you can to just try and plug this directly into the USB uh, on your computer and
314:41
Speaker A
try not to have any hubs or in my case, I had a KVM switch that I was plugging into and it didn't seem to like that.
314:48
Speaker A
So, with our device connected, we're actually almost ready to start taking our first capture. But what we're going to do first is we're just going to make two quick changes here. So, the first one is just how many samples we're going
314:58
Speaker A
to take. And we're going to up this because this is just going to run for 1 second and we want to take a capture longer than a second. So, I usually just put it at 100. And then if we use less
315:08
Speaker A
than that, then that's okay. It just won't stop it ahead of time. If you notice that you're running a capture and it's just stopping, you probably forgot to update this because at at 1m, the default, it's just going to run for a
315:19
Speaker A
second and then stop, which isn't going to be a long long enough for our scenario. So, the next thing we're going to change here is this frequency that we're going to sample at 20 kHz is going to be a little too low for us. I'm going
315:29
Speaker A
to up it to 1 MHz. Our device will support up to 24 MHz, the logic analyzer that we have, but in testing I found that it it honestly it all it can't always uh hold up to 24 MHz and and what
315:43
Speaker A
will happen is it will just stop the capture at that point. 1 MHz is going to be more than enough for this UART capture that we're about to take.
315:52
Speaker A
Okay, so we're almost ready now to start our capture. And what we're trying to capture here is that bootup transmission on the router. So, we're going to want to make sure we have the router ready to be powered on shortly after we start the
316:05
Speaker A
capture. So, what I've done in this case is I have my power brick. It's plugged into the wall and I just have the end of that near the router ready to plug it in. And I've already got my cables
316:17
Speaker A
hooked up from the UART header that we attached on the router to the logic analyzer. And those are connected up how we did in the last video. So, all I need to do is I'm going to hit the run and
316:27
Speaker A
then I'm going to plug in my router. So, we're going to do is this is to start the capture. So, I'm just going to start the capture right now. And then very shortly after, I'm going to plug in my
316:35
Speaker A
router. Okay. And if you just slide this bar over here, can see right here, this is where our I powered on the router. And then as I slide over, can start to see these blips. and if we zoom in on them.
316:56
Speaker A
So, I'm just using my mouse scroll wheel. We start to get some transmissions that we're capturing. So, I probably had it run long enough now, so I'm just going to stop it here.
317:06
Speaker A
And we now have our very first logic analyzer capture of our UART signal. So, if you for whatever reason were not able to get this working or you chose not to purchase a logic analyzer, what I'm going to do right now is I'm actually
317:19
Speaker A
just going to save this capture and then we'll end the video here and in the next video we will open up this capture and we'll take a look at how we can decode this UART signal and some of the
317:30
Speaker A
different characteristics of UART. So, good idea to always save these just for our reporting and so we can have them later. And to save it, we're actually just going to come up here to the save icon. one. I'm going to click save.
317:43
Speaker A
And we'll see here it defaults as this SR zip session file. So that's the one that we want to leave it as. Uh, and I'm just going to save it on my desktop now so I can find it. And we'll just call
317:54
Speaker A
this router. Actually, we should name it TPLink router UART bootup capture. and I will save that. Perfect. So, I'll end this video here and I'll see you over in the next one where we open up that capture and then take a look at
318:17
Speaker A
decoding that UART transmission. Welcome everyone. In this video, we're going to pick up where we left off in the last lesson and open up that capture we took in pulse view of the UART transmission on the router. We're going
318:32
Speaker A
to look at decoding that and then also take a look at some of the characteristics of UART transmission.
318:38
Speaker A
So, let's get started on that right now and open up PulseView. Okay. And we don't actually need to worry about connecting our device or anything this time because we're just going to be looking at that previous capture that we took. So, in order to do
318:57
Speaker A
so, we can just go here and click open. And then if you from this dropown, just go all files. And then we're going to choose this TPLink router UART bootup capture or whatever you saved it as from the last lesson if you're using the one
319:11
Speaker A
that you saved and click open. And then perfect, we can see here we've got that same capture and we left off right where we were at. So if we just zoom in and again I'm using the scroll wheel here to zoom in and you
319:26
Speaker A
can use the mouse uh left button to drag and move it along. So, we can see we've got all of this UART capture going on.
319:35
Speaker A
I'm just scrolling through it right now. Um, but you know, to us, this isn't super useful to try and figure out what's going on by just looking at these raw captures right here like this. So, what I'm going to do is I'm actually
319:48
Speaker A
going to apply a decoder to it. And that's going to help us decode what's going on with the UART. So, to do so, we can click this button right here, which is for decoders.
319:58
Speaker A
And we already know it's UR communications. So, I'm just going to search for a UART one.
320:06
Speaker A
All right. So, what I like to do is I'm just going to grab this and pull it up to the channel that we're working on, which is this D0 channel. And since we don't need the other ones, just to clear
320:15
Speaker A
them out of the way, I'm going to quickly quickly delete them. So, you just right click and delete. You're just going to help clear up our view here a little bit more.
320:25
Speaker A
All right, perfect. Now, you see it's saying here there are no channels assigned to this decoder. So, we'll just click on it here. You can leave it. You change color if you want, but I'm just going to leave it and call it UART. And
320:35
Speaker A
we're going to choose the receive line. So, we are receiving here, remember? So, that's why we're going to choose the receive line. Even though we are connected to the transmitter, we're the receiver.
320:47
Speaker A
And I'm going to set that to D0 here. All right. And then you'll see we have all of these characteristics that we need to set. And I'm just going to leave it here as the defaults because right now our device is actually just using
321:01
Speaker A
the defaults. And I would say honestly about 95% of the IoT devices that I come across that have uh UART enabled on them, they use these defaults as well.
321:11
Speaker A
So good to remember. So that is the baud rate is at 115,200. Data bits are eight, parody is none, stop bits are one. Uh, and then this bit order is this is least significant bit first. The only change I'm going to make
321:26
Speaker A
here is this data format is it's going to display it in hex. But I'm thinking that this transmission is actually probably going to be ASKI data. So if we want to see that ASKI data in plain readable letters, we can just choose
321:40
Speaker A
here ASI. And that is all perfect. So we can just close this. Now, if we pick a pulse here, and I'm just going to scroll out and see where we are in the actual message. All right, let's grab one of
321:53
Speaker A
these ones. This one of the very first ones here. And if we keep scrolling in, and I'm just going to go to the start of this message here, right over here. Maybe we can actually start to see the uh text
322:12
Speaker A
that's being sent out as part of that boot log. So, right here, we're even already starting to get some banner grabbing here. Flash manufacturer ID.
322:21
Speaker A
And then we're starting to get some IDs and even, you know, a warning message here that's coming in about this chip.
322:28
Speaker A
Now, if you're curious, you can scroll through here and take a look at all the boot messages. Again, if we if we scroll out here, like there's a lot of data um that's being sent at bootup and and you
322:40
Speaker A
can read it all through this, but keep in mind this isn't the best way to actually view this data. And generally, that's not what we're going to use this logic analyzer and the decoder for. This is more just for us to get a sense of
322:53
Speaker A
what is going on with that transmission. Uh what the properties are and if we can't get it working to communicate with it, then we can use this logic analyzer and the capture to debug that on our router. You know, it's pretty
323:07
Speaker A
straightforward. The pins were already labeled for us. So, we knew it was UR. We knew which pins were being used. And we're using all standard settings. So, it's pretty easy for us to figure it out. But, it's not always going to be
323:18
Speaker A
like that. And to prevent you from, you know, pulling out your hairs just trying bunch of different combinations when you're trying to connect to the router, sometimes it's easier to get a capture of the data and then just inspect it and
323:31
Speaker A
you can kind of figure out what's going on. Now, in order to figure out what's going on, you probably going to need to understand what is actually going on beneath the hood here with the UART and this decoder. So, that's what we're
323:43
Speaker A
going to take a look at right now. So, I'm just zoom back in on the start of this message right here. H maybe not this one because it's all equals.
323:51
Speaker A
Perfect. So, we'll take a look at this flash manufacturer message and I'm just going to zoom in actually just on the very first part of it right here.
324:03
Speaker A
Okay. So, if I pull back up the UART properties here, the first one we'll talk about is the baud rate. And we've already chatted about this briefly when we were talking about that, you know, imaginary serial protocol that we were
324:17
Speaker A
coming up with, the really basic one. And what this is is this is the speed of the transmission. And essentially, this is the amount of symbols per second that we are going to be sending. And you'll remember both the receiver and the
324:30
Speaker A
transmitter have to agree on that same speed so that we can decode the message.
324:36
Speaker A
Now, if we didn't know what this baud rate was, um, and you know, we tried some of the standard ones and we couldn't figure it out, we can calculate that. So, the first thing in order to calculate it is we're going to actually
324:48
Speaker A
have to take, uh, a look at the symbol width. And in order to do that, we need to find uh, one of these pulses that represents just one symbol. So, what you're going to look for is the smallest
324:59
Speaker A
symbol that repeats itself. And I'm looking here and in this transmission data, you know, I can see, you know, these two here, but it's not super clear sticking out. So, I'm just going to zoom out. Uh, and then, you know, when I
325:10
Speaker A
start looking more, I can see this kind of repeated. Here's one. Here's one. Here's one. Here's one. You know, here's one of this looks to be the lowest width pulse. So, I'll just grab this one right here. And if you click up here on these
325:25
Speaker A
markers, it's actually going to allow us to take a measurement. So, what I'm going to do is I'm just going to drag it over this here.
325:32
Speaker A
And we'll see here that it is 8 microsconds. Uh, and you'll recall that the way to calculate this baud rate is it's one over this time. And we don't have to use the calculator. The pulse view is going to do it for us. And it's
325:45
Speaker A
measuring it as 125 kHz essentially. Now, you'll notice this is off a little bit from the baud rate that we chose.
325:56
Speaker A
And the reason for that is just going to be uh based on the sampling frequency that we chose, it's going to be slightly off. But the beauty of UART is we can actually be off by, you know, plus or
326:06
Speaker A
minus even 10% of that speed and we're still going to be able to decode the message. So perfect. I'm going to clear these markers away just so it's a little bit easier to read. So that takes care of the baud rate. If we just go back to
326:20
Speaker A
this F and zoom in on it, the rest of these UART characteristics that we have to set up, they all pertain to how we are actually going to be sending the data in each what I'll say kind of like
326:35
Speaker A
portion of the transmission. So we already chatted about this a bit, but in networking each, you know, portion of data that we sent, we call that a packet. And that represents, you know, a little bit of information sometimes at
326:47
Speaker A
the start and end in the header. Um, and then it has the data in the middle.
326:52
Speaker A
Well, in these lower end digital hardware communications, you know, UART is not even a protocol in and of itself, we call each individual piece of data that we're sending like this a frame.
327:05
Speaker A
So, in this example right here, from here all the way over to here, this makes up what we call the frame.
327:18
Speaker A
And then inside of that frame, we're going to have a few specific characteristics that help us to send that data and have it be decoded. So, outside of the frame though is the first thing that I want to talk about, and
327:30
Speaker A
that is this area right here. So, you may have noticed when we started up the router that as soon as we powered it on, we saw the UART transmission line go too high. And we also saw that when we were
327:42
Speaker A
probing it with the multimeter that when it wasn't transmitting, it was just kind of in that idle time. Then it was actually just at that 3.3 volts constantly. And what this time is usually referred to when we're not
327:55
Speaker A
transmitting is we actually call it the idle time. And the idle time will will generally almost always hold that voltage uh on the transmission line at the high level.
328:10
Speaker A
And there's a few reasons for this, but the main reason is that it allows us to fail off. And what that means is that if we have some sort of failure on our communication line, so our transmission line gets broken, whether that's a trace
328:23
Speaker A
or something gets unplugged, um, or there's just an error with the transmitter itself, then we can detect that error because the receiver will see that UR line as low. Whereas, if we just held our idle time as low, then we have
328:38
Speaker A
no way to determine whether or not we're just not getting any transmissions because it's not sending anything or there's something broken. So you'll generally see that idle time at that high voltage.
328:48
Speaker A
Now, in order for us to signal that we're actually starting the transmission, we need to have some agreed upon way to do that. And that's what's happening right here. You'll see we have the uh start bit. And the start
329:02
Speaker A
bit in UART is always going to just be one low symbol. So in our case, it's bits. So it's just going to be one single zero or one single low pulse. And that indicates that we're going to then
329:16
Speaker A
start transmitting the data after. So you see here afterwards we have this binary here and this is all of the pulses that make up the data. And usually this is going to be eight bits, but we don't necessarily have to send eight.
329:34
Speaker A
saw in the um UART decoder properties that we can actually change this to you know six or seven bits but usually you're going to see it as eight bits because of course that makes up one bite and then this you know 0 1 1 0 0 1 1 0
329:49
Speaker A
this is what then represents for us this f in the asy so the next parameter that we need to agree on and you may have seen this uh in the decoder there is the stop bit so if we take a look that's
330:01
Speaker A
actually right here this is the stop bit. And it's kind of cut off here, but that's the stop bit.
330:09
Speaker A
And the stop bit, you know, just as the name kind of implies, this signals that this is the end of the frame. And we're going to then either go back to idle time or we're going to, in this case, if
330:20
Speaker A
we're just transmitting right after, we're going to send another start bit, and that's going to start another frame worth of data to be sent. So you'll always have at least one stop bit, but some devices will use more than one. You
330:35
Speaker A
can use, you know, potentially two or three stop bits. Uh, and the reason for that would just be if you maybe need some more time to allow for processing to take place or something like that.
330:45
Speaker A
Um, by default, it's almost always going to be one, but this is changeable. So that's why you will be able to see it uh in those decoder options.
330:55
Speaker A
So the last setting that we'll chat about and it's not being used uh in this transmission and with IoT devices you're very rarely going to see it actually used uh is the par bit and what par does is we can actually
331:08
Speaker A
perform some bitwise math on the data that's actually being sent and then we choose our par bit to be either even or odd. And what that means is that when we perform that bitwise math, um, if we use
331:25
Speaker A
the par bit, then it should make the operation of that bitwise math even or odd depending on what we choose the par bit to be. And if it isn't even or odd, then we know that we have some sort of
331:39
Speaker A
error in our transmission. So, it's kind of like a really really basic way of doing um a check sum for error checking.
331:46
Speaker A
and you won't really frequently see it used. So, I just want to call attention to that. Usually, you'll just see it left as none.
331:54
Speaker A
So, the last characteristic we'll chat about, and this is actually a funny one that we picked this F here now that I'm looking at it, um, is this least significant bit first is sent first. So, the reason for F that that's so
332:05
Speaker A
interesting is that it's almost like a palendrome of itself in that even backwards, it's the same. But what that's essentially saying is that um you know this hex number if you're reading in its binary representation of this 01
332:17
Speaker A
1 0 0 1 1 0 this is the most significant bit here and this is the least significant bit. This one um obviously this represents the the least amount uh if you were to convert this to hex.
332:29
Speaker A
So this one is sent first being the lowest one. So what I'm going to do is I'm just going to clear this writing off actually and we'll just take a look at a different one.
332:36
Speaker A
And what I'm going to do is I just go back quickly back into the UART here and I'm going to switch the the and I'm going to switch it from ASI to actually look at the binary.
332:49
Speaker A
So you'll notice the binary data here, it doesn't actually um match up with these what it's decoding it from. So here we have 0 0 1 1 0 and then here we have 0 1 1 0. And that's how it's
333:03
Speaker A
showing that that least significant bit is being sent first. So it's kind of backwards, right? So here we have zero that matches with this zero. Here we have one that matches with this one.
333:12
Speaker A
Here we have one that matches with this one. This zero and so on. So just something to keep in mind when you're looking at those bits.
333:20
Speaker A
So if you keep in mind these different characteristics of UART transmission and you think you have a UART but you're not able to decode it then what you can do is you know without the decoder we can zoom in and start looking at the bits
333:32
Speaker A
and trying to frame it ourselves and figure out what's actually going on there and you know maybe identify for example that we have a parody bit or something or maybe realize that it's not actually UART that we're looking at and
333:44
Speaker A
it's it's some other uh protocol or type of communication. With that being said, I'm going to wrap up the video here and I'll see you over in the next one.
333:55
Speaker A
Welcome everyone. So, if you're anything like me, then in your spare time, you might like competing in cyber security capture the flag events or CTFs. And one thing I've noticed that's becoming much more common in these Jeopardy style CTFs
334:10
Speaker A
where they have different categories is that they'll actually include a hardware hacking category. Now, of course, with these CTFs, hardware hacking can sometimes be challenging to include because we can't provide everyone with hardware. We have to come up with a
334:24
Speaker A
software solution. So, to overcome that, one of the most frequent things that I see being done is that the challenge will just be to decode a logic analyzer capture. And the flag will be, you know, somehow hidden inside that capture. And
334:39
Speaker A
you know maybe it will be just a standard protocol that you need to understand and then decode it or they'll you know make up some kind of fancy protocol or something like that that you actually have to you know put some
334:50
Speaker A
thought into and analyze. These are a great way to you know practice using the logic analyzer software. And then also if you are just trying to be competitive in CTFs, I I honestly find that these are usually a really easy amount of
335:05
Speaker A
points because I think people are intimidated by them. So not a lot of people try them. But if you understand how to use the logic analyzer software, then you know most people you can usually decode these and score your team
335:15
Speaker A
some easy points. So I put together two challenges here for you to solve. And let's just take a look at the um info for the first one just to get an idea behind what's behind it. So I'll look at
335:27
Speaker A
broken transmission first here. And if you look at the info here, it just says, can you help us decode this transmission? Looks like there was some error during transmission and we can't seem to figure what's going on. And then
335:39
Speaker A
just one hint here that the flags are in this format, HW with the squiggly brackets, and then it's all in this uppercase elite uh format with the underscores in between it. So, if you want to take a shot at solving these
335:52
Speaker A
challenges, there's just the pulse view file right here that you can open up and then try and decode the flag. Again, it's in that format that's in the info.txt. So, if you want to try this on your own, just hit pause on the video
336:04
Speaker A
right now and then when you come back, I will show the solutions. Okay, welcome back. Hopefully, you're able to solve some of these. If not, that is okay. I'm going to go over these solutions right now. So, we will look at
336:18
Speaker A
broken transmission and I'm just going to launch it up right now. So, we can click on the pulse view file here and it should just open it up for us.
336:29
Speaker A
Okay. So, I'm just going to move this over here and zoom in. And when I'm initially looking at this, to me, uh, it's starting to look like UART. Of course, we've just got the one signal here, so we know it has to be
336:40
Speaker A
asynchronous. There's no clock provided or clock signal. Uh, another good clue is that we have this line being held high here. Uh, and then in between transmissions, same thing. We have this line being held high.
336:55
Speaker A
Going to zoom in a little bit more. And I'm seeing again what looks like these blips of UART transmission. So, what I'm going to do is I'm just going to start by adding a UART decoder here.
337:13
Speaker A
and we'll just take a shot in the dark. One thing I'll usually do is I just, you know, we'll pick the channel here and I'll just run with all defaults and see where that gets us. So, we will just
337:21
Speaker A
leave it as all these defaults. The the default baud rate right here, uh, I'm going to zoom in and you see unfortunately we get a framing error.
337:28
Speaker A
So, what that means is that it wasn't able to, you know, find frames that match those characteristics that we set out at. Um, and generally what this means is that you have the baud rate wrong. But it could be any one of those
337:40
Speaker A
other parameters um that we chose like the amount of data bits or the stop bits or the parody for example. What I suggest is, you know, if you have framing errors and you can't figure these out, start with the baud rates and
337:52
Speaker A
exhaust, you know, trying the baud rates and a bunch of different baud rates and your measurements before you start going on to any of these because a lot of times, you know, the data bits, parody, um, stop bits, this least significant
338:03
Speaker A
bits first. These are all going to just stay as standard even in CTF competitions. So, start with the baud rate first.
338:11
Speaker A
With baud rate, you have two options. So you can just start by measuring it, which you know is always a good thing to do with measuring it. Or you can look at a list of standard baud rates because
338:20
Speaker A
there really is um you know only a certain amount of baud rates that are generally used. Now in a CTF someone might be doing something kind of weird or wonky and just running with uh a non-standard baud rate, but a lot of
338:32
Speaker A
times you'll see standard baud rates being used. So for CTFs or not, I always suggest take a peek at those.
338:40
Speaker A
So let's open up my web browser here. I'm just going to go to Wikipedia and I think believe under serial port there is a list of these. So if we just look here uh if you scroll down a little
338:52
Speaker A
bit common serial port speeds and you just see a list of this bit rate or baud rates and you'll see a bunch of the common speeds. So we see here is this 115,200 probably the most common one. The second
339:06
Speaker A
most common one that you'll see a lot is this 9600. Um, so you can try and brute force and just use these these speeds, but what I like to do is I'll use these in conjunction with a measure. So if you
339:18
Speaker A
just jump back to our measurement, uh, and if we zoom out a little bit, I'm seeing this symbol, this short symbol repeating over and over again. So I'm going to zoom in a little bit on it and just take a measurement here.
339:35
Speaker A
Okay, so I'm seeing it as this 14.4928 4928 kHz and that translates to a baud rate of if we just you know take this decimal and move it over 1 2 3 that is 14,492 which that actually lines up if we go
339:52
Speaker A
back to uh here it lines up with this 14,400. So I'm going to give that baud rate a shot because we do remember you know sometimes our measurements can be slightly off for the timing depending on the frequency that it was sampled at.
340:07
Speaker A
We'll just hop back in here and I'm going to put this at this 1 44 4 0 0.
340:16
Speaker A
And I'm also going to not forget to put this in ASI. Generally, you're going to see it in ASI uh in the capture the flag. And if we zoom out here and kill this measurement.
340:28
Speaker A
All right, we got 0x AF. So, looks like some sort of hex code being sent.
340:34
Speaker A
Another hex code being sent. And then uh as we scroll over we start seeing some ASI here. So that's a good sign. Loading firmware firmware version here loaded.
340:44
Speaker A
Handing over to kernel kernel loaded preparing transmission. And then we get the secret code is this HW. We get this left bracket broken underscore and then we get dot dot dot detecting noise on the line falling back to lower transmission speed. And then it
341:06
Speaker A
looks like we got a pause in the transmission and we've got a break here where it looks like now we have another framing error. Uh, and when I look at this, I'm seeing if I just scroll out here, you
341:19
Speaker A
can really see it obviously that these pulses are a lot longer um than these ones. And we did say that it was falling back to a lower speed. So, you know, what can happen sometimes with these transmissions if the processor can't
341:32
Speaker A
handle it or something's going on is that we need to lower the speed in order to not have errors and allow it to process. So, maybe that's what this challenge uh would be mimicking. And I'm just going to zoom in here. And it looks
341:46
Speaker A
like we've got this repeating again of these symbols. So I'm just going to take a measurement of these symbols here.
341:56
Speaker A
All right. And looks like we are at 1.1976 kHz, which if we jump back over to our list again here, we got this 1200. So I'm going to run with that. One of the nice things in pulse view is that we can actually um
342:13
Speaker A
drop in a second UART decoder on that same line. So I'm just going to do that right now.
342:18
Speaker A
We just search for UART again and we can add a second decoder. Just going to get rid of this measurement since we don't need it anymore.
342:35
Speaker A
set this as D0, but we're going to set this as that 1200. And then if we zoom out here, yeah, don't forget to set it to ASI like I did and we're starting to get measurements.
342:51
Speaker A
So, we get this the rest of what appears to be We're going to need to look at this UR.
343:00
Speaker A
So it's hardwarehacking broken underscore and then the seven um which in lead is the T. And if we scroll over and zoom in then we get the rest is transmission received and then it just says end transmission. So perfect. We got the
343:22
Speaker A
solution right there. So hopefully you're able to um figure it out. This is one challenge that I've seen this kind of theme or something very similar used before in hardware hacking CTF. So something to keep in mind and just good
343:36
Speaker A
practice for determining those baud rates and how we can decode the messages. So I'll wrap this one up here, close it, and we're going to take a look at the second challenge.
343:48
Speaker A
Okay, so the next one is this beep beep beep and we'll take a look at that right now. Let's take a look at the info for it.
343:57
Speaker A
All right, the briefing says, "We've interrupted this strange transmission and are trying to figure out what it is.
344:04
Speaker A
Seems like it may be using some ancient communication protocol." Hint, flags are in the format and we give the same format again. However, they may be encoded in the transmission. Cybersh is a great tool for decoding strings during
344:19
Speaker A
CTFs. So, if you're not familiar with how CTFs uh handle hiding the flags, sometimes they will encode the flags in, you know, one of many encodings, hex or URL or B 64. Uh, and there's multiple reasons for that. A lot of times it's
344:35
Speaker A
just so that prevents people from, you know, doing a search or like a grap or something like that on um, you know, the the starting string of the flag. And Cyereersh is a great tool, you know, if you see these strings to figure out
344:47
Speaker A
what's going on. So, hint for that. Just going to close this and let's launch this up.
344:55
Speaker A
Okay. So, I'm looking at this and immediately does not look like UART to me. Um, we're just getting one channel here and there's no clock or anything.
345:04
Speaker A
And I'm seeing that the line is low. And the other thing that I'm seeing is these pulses are, you know, they're pretty long.
345:15
Speaker A
So, in order to solve this, you've kind of got to this is a little of challenge that's a little bit more um out there in terms of not being a standard communication protocol that you're going to see. Um but you you will see this in
345:27
Speaker A
CTS where people use, you know, older protocols or things like this. The name of the challenge gives it away a little bit hopefully as a hint. And then also in the info.txt that what we're actually looking at right here is Morris code. And if you're
345:43
Speaker A
not familiar with Morris code, there's actually just two symbols that are used in Morse code, kind of like binary where we have um what's called a dot. So it's a short uh transmission and then a dash which is a long transmission. And then
345:56
Speaker A
these combinations of dots and dashes, they actually make up letters and numbers. So they make up all of the characters. The cool thing about PulseView is it actually has a Morris code decoder in it. So we can just pop
346:09
Speaker A
this up. And if you you search here for Morris We have a Morris code decoder. So, I'm just going to add that. It's super cool that it's got one of those.
346:20
Speaker A
So, we're going to pick the channel, the data line here. And you'll see here we've got this time unit that we need um to decipher. And the time unit in Morris, if you're not familiar with it, is is it's all based on the length of
346:35
Speaker A
the shortest uh symbol, which is the dot. Because the way that it works is, you know, then every other dot should be the same length as that. And a dash is three the same length as three dots. And
346:50
Speaker A
between words will have a pause that's the same length as a dash or three dots.
346:54
Speaker A
So in order to get this time unit, we just need to measure the pulse width of this single dot, which I'm going to do right now. So we'll just add in a measurement.
347:04
Speaker A
And we can there's one right here. So we'll just grab this one here. If we zoom in on it, looks like it's about 50 milliseconds.
347:18
Speaker A
We can just go back into the Morris decoder here. And I'm going to set this as this is 0.05.
347:27
Speaker A
Perfect. And then if we scroll out, we actually get this word here, which it gives us this Morris word. So, what I'm going to do is I'm just going to go here and I'm going to go copy annotation text
347:39
Speaker A
to clipboard. I'm going to go back into browser here and I'm going to look for cyershe.
347:49
Speaker A
This one right here. Load it up. I'm going to paste it in here. And then, so you're just going to have to get used to this if you want to do CTFs. You can either try um, you know, the different
347:58
Speaker A
encodings. So, when I look at this one, I can just see um right away that this is a hex encoding because we've just got the all of the, you know, hex digits in here, one 0 through 9 and then, you
348:11
Speaker A
know, the letters A through F. So, I'm just going to go, you know, from uh hex here, drop the recipe in here. And then look at that. It gives us the output of the flag is this HW Morse is serial,
348:25
Speaker A
which it is true. Um, you know, Morse code is probably the the first actual implementation of a serial communication where we're just sending, you know, those datas one after another and we almost it's almost still like bits where
348:38
Speaker A
we have only two symbols. We have a dot and a dash. So hopefully you able to figure this one out. If not, that's okay. This one is a little bit more um of a challenging one to solve. With that being said, I hope
348:52
Speaker A
you had fun with these capture the flags as well. wraps up this challenge and I will see you over in the next video.
348:58
Speaker A
Welcome everyone. So, we're going to get hands on the keyboard hacking of our router started very shortly in just a couple lessons. But before we do that, I think it makes the most sense to talk a little bit about IoT penetration testing
349:14
Speaker A
and the methodology that will follow for IoT pen testing and just how that differs a little bit from the regular network penetration testing or maybe web penetration testing that you may be used to. And in doing so, we can chat about
349:29
Speaker A
how our goals will be the same in some areas and in some areas they'll be different. And this is going to help us a lot when we're doing our recon and penetration testing of the router because we'll know what exactly we're
349:41
Speaker A
looking for and what goals we have. I think the best place to start is actually to look at the architecture of an IoT system or ecosystem because there's a lot more components that actually make up this IoT ecosystem than
349:54
Speaker A
just the specific IoT device itself. So, with that being said, I'm just going to hop over to the whiteboard and we're going to take a look back at our smart lock and kind of try and design out all
350:04
Speaker A
of the different uh pieces of that system that we would need to give it the functionality that we'd want in a smart lock. Okay. Okay, so as I mentioned before, we're going to be looking at this kind of imaginary smart lock that
350:16
Speaker A
we were looking at in lesson one, and we'll talk about building out some of the features that's going to take it from just being, you know, a regular pin combination lock into being a nice smart lock that's going to have the features
350:27
Speaker A
that make it attractive as an IoT or smart device. So, of course, at its base level, we've got this pin pad, and then, of course, it's going to connect to the door. And you know at a very basic level
350:38
Speaker A
when you enter the combination maybe 1 2 3 4 then the door opens but that doesn't make it a smart device or really make it super useful outside of just being a regular pin combo. So maybe one of the
350:50
Speaker A
first features that we want to add in is that users can access this through some sort of interface and they can add or manage what pins are available. uh and they can add users for example and give them pins and maybe they want to do that
351:04
Speaker A
through some sort of application. So the next thing I'm going to bring into our design is we'll just bring in a phone to represent that. So I just brought in the mobile phone here and you know you can
351:15
Speaker A
do this from your computer. Sometimes people do it from their computer but I think a lot of people are using their mobile phones for this today. So it's a good representation of how a lot of it functions in the real world. I'm just
351:26
Speaker A
going to draw this little cloud here around us because we'll say that all of this communication here, it's my really bad cloud that this is all happening and this is in the uh wireless local area network. So, we'll say this is the WLAN
351:42
Speaker A
and then we can have communication locally as long as we're both on that same wireless network between the two devices.
351:50
Speaker A
And it's basically just going to be using whatever ports are open on this. So, you know, sometimes you'll see uh SSH being used for these apps. Sometimes there's even TNET. It's kind of the wild wild west of these IoT devices. Um maybe
352:04
Speaker A
this device has like its own little web server that it hosts for configuration or setup. Very common to see that. So maybe we'll see something on port 80.
352:14
Speaker A
And you we're going to look at this more in depth later, but it's just basically, you know, we have this local area connection of, you know, whatever ports are open we can be using.
352:22
Speaker A
So what I'm going to do now that we have kind of our first interface here is we can actually start mapping out our attack surface for these devices. So I'm just going to start keeping a list and as we add more features we can talk
352:33
Speaker A
about how those could be exploited. So the very first thing on our attack surface here list and these are not in any particular order by the way. I'm just kind of listing them by how we add features is that local area network. So we'll
352:49
Speaker A
just call this the internal network. So, so if we're going to be finding exploits or things like this, then it's going to be where someone already has access to that local uh area. Usually, it's going to be a wireless network.
353:09
Speaker A
So, maybe we don't want to actually have to use the Wi-Fi to unlock this lock.
353:14
Speaker A
And this is something that's very common with these smart locks. Maybe we just want to open up the phone and we put it close to uh the lock and then it opens up. So, something that's really common with these smart locks and other IoT
353:26
Speaker A
devices is that we're going to use some other form of what I'm going to just call short range wireless to communicate back and forth.
353:34
Speaker A
And this could be something like maybe we use Bluetooth. So, I'm going to say BT. Maybe we use NFC for example.
353:42
Speaker A
Maybe we use, I don't know, RFID or maybe even some other type of proprietary protocol. So, this is another attack surface for us here. So, I'm going to call this short range wireless here.
353:59
Speaker A
And that gives us another attack vector. So, that covers if we are at home basically or we're close to the lock maybe. You know, we add some really nice features here. And some of these uh smart locks, this is where they'll end.
354:11
Speaker A
they just have that, you know, NFC communication where we can, you know, set it up through the local area network and that's all people want. But maybe, for example, I am at work. I'm away from home and I'm worried that I forgot to
354:23
Speaker A
lock my door and I want to check if it's locked or I want to be able to either lock or unlock it from anywhere.
354:29
Speaker A
Basically, I'm on 4G or I'm on a different network. I want to be able to lock it. So, in order to do that, I'm just going to bring in another phone that we'll say is, you know, outside of
354:37
Speaker A
the WLAN. It's just in the, you know, wider area network. it's out it's out in basically the internet as designers now if we're trying to you know figure out this architecture the one option we have is that we can try and set it up so that
354:50
Speaker A
you know we can come from outside the internet and we're going to try and you know come into this home network um you know through the modem or whatever this gateway is and then inside into the network and you know if you've ever
355:02
Speaker A
tried to do something like this uh at home you may know that this can be a pain to set up there's a lot of security implications to it and for the average consumer it may be something that's you
355:12
Speaker A
know quite tough to set up. So what we're generally going to do is we're not actually going to you know communicate directly you know from our app or whatever outside of the local area network in so what we'll generally do in
355:25
Speaker A
these ecosystems is we'll bring in some sort of of cloud service and then the we're going to initiate some sort of connection you know outside of this WLAN we're going to reach out to that cloud service and then we're going to have
355:37
Speaker A
that communication going back and forth here and generally there's going to be some sort of API endpoint that's communicating here and also probably at this end here.
355:49
Speaker A
So for example, if we wanted to maybe uh you know check the status of the lock, then we could just ask over to the API that's running the cloud service and it would give us the response of the lock
356:00
Speaker A
back and we would have that communication here back and forth between the lock and the server. That's kind of like this polling method of communication where it's constantly updating. Uh, and then for example, so if we wanted to say from the app, hey,
356:13
Speaker A
can you unlock the door? For example, it's going to send that message over into the cloud server. And then when this device pulls, it's going to check and see that it should unlock its itself and then it's going to unlock itself.
356:23
Speaker A
And then we don't actually have to worry about sorting out any of that communication that comes, you know, from this external device directly into the network. So this adds us another two pieces of attack surface that we should
356:35
Speaker A
write down here. So the next one is this mobile app, right? So, we should be taking a look. If there's a mobile app for our R2 device, we should be definitely taking a look at that. And then the fourth one is anything
356:48
Speaker A
external, but I'm just going to put it as API because that's generally what it's going to be. So, we should be taking a look at that external API interface.
356:58
Speaker A
So then there's one other attack surface that we haven't talked about and which is one thing that's kind of unique to IoT devices and that's we haven't really talked about the actual hardware for this smart lock itself. So I'm going to
357:12
Speaker A
use the abbreviation of hardware here. And this is where we have this unique uh attack surface or avenue that we generally may not have in the traditional web penetration testing or network penetration testing where we can actually go out uh and buy this IoT
357:29
Speaker A
device ourselves or if we're doing penetration test is going to be given to us and we have access to the underlying hardware where we can then use that as an additional attack surface. So I'm going to add that here as the fifth one
357:43
Speaker A
and I'm just going to use the abbreviation of hardware here as HW. So in this course this is actually what is going to be the main focus of our IoT hacking is this hardware portion itself the unique aspect. The reason for that
358:00
Speaker A
is because so these other ones so especially you know the internal network uh assessments the mobile app assessments the API and then if we have like you know web server that's being hosted all of those there's really good
358:13
Speaker A
resources if you're coming through TCM academy for specifically you know you've got the the practical ethical hacking course which goes over the internal network and some external network got a great mobile app penetration testing course we've got a good web app
358:26
Speaker A
penetration testing course those are all really covered in detail and for IoT devices in this IoT uh infrastructure and architecture 90% of what's covered in those courses is just going to apply to these. They don't differ too much with a few caveats
358:42
Speaker A
that we will cover in this course. So that's why we're going to be fa focusing mainly on the hardware aspect in this course. Now the one thing I want to point out about the hardware aspect or you know vulnerabilities or exploits
358:55
Speaker A
that we find with the hardware is that depending on the devices functionality and what it does a lot of these hardware what I would call vulnerabilities or exploits or things like that generally a lot of times the manufacturers are not
359:09
Speaker A
going to be as concerned about them. So if we look for example at you know the smart lock this is a good example and why I've brought it in. If we look back at that kind of madeup vulnerability
359:20
Speaker A
that or exploit that we found where in our penetration test we were able to open it up and then there was an exposed UR connector that an attacker could connect to uh and they got the PIN print out from that. So that's a great example
359:32
Speaker A
of you know a purely hardware hack where the vendor is probably going to be concerned about that because you know attacker from the outside of the house could then you know breach the system and unlock it. However, if we look at
359:42
Speaker A
the router we're going to be looking at, and you know, maybe we just take a very similar example where an attacker could open up the router, uh, connect to the UART, and for whatever reason, it outputs the Wi-Fi password, um, and then
359:54
Speaker A
the attacker can get on the Wi-Fi. Well, is that really a vulnerability or an exploit? I mean, the attacker then has to, you know, enter the person's home.
360:02
Speaker A
They have to get to the router, and, you know, a lot of routers, they already have a WPS button on them where you can push them uh, and get access to it. So maybe that's not necessarily considered uh specifically a vulnerability. So
360:15
Speaker A
generally what we're looking to do with these hardware hacks is we're actually looking to take either the access or the information or you know whatever we can find with them to then amplify or make it more efficient to attack these other
360:28
Speaker A
different avenues like you know for example the external API maybe the mobile app or even this internal network hacks. So maybe from our hardware analysis we're able to find for example some bash scripts that we can take a
360:42
Speaker A
look at and reverse engineer or even some sort of executables that we can reverse engineer and then this makes it easier for us to find for example maybe a command injection or a buffer overflow that we can you know abuse either
360:55
Speaker A
through the API or through the mobile app or maybe even just on the internal network. And these are the kind of exploits or vulnerabilities that security researchers and even the you know if we go to the other side the
361:06
Speaker A
black hat hackers are going to be looking for. So if we're doing this as a penetration test then of course it's our responsibility to you know check all of the avenues and report on them. But as security researchers those are kind of
361:19
Speaker A
the big things that they're going to be looking for. So, just to give an example of some of this actually out in the wild, I wanted to share a recent blog post that I found interesting from the Zero Day initiative. So, if you're not
361:32
Speaker A
familiar with the Zero Day initiative, I would definitely recommend checking out their blog and this who we are. But one of the things they run is they actually run this pone to own contest that just recently happened where they invite uh
361:45
Speaker A
security researchers to come bring pieces of hardware or equipment and then they actually if they pone them then they get to own them but now it's changed into actually just getting cash prizes. And this blog here is actually
361:58
Speaker A
chatting about a very recent discovery in another TPLink router. So the TPLink archer and there's two teams that found both a local area so that you know WLAN or that local area they were talking about they also found a a WAN so this
362:13
Speaker A
wide area network or out external entry and they both won cash prizes for this research which is super cool. The other thing that I noted about the vulnerability is actually if you look at the top here um they are observing these
362:26
Speaker A
exploits already be attempted out in the wild by the Marai botnet which is a very famous botnet that is known to target IoT devices. So these exploits that have been found and published they're already being used out in the wild by this
362:40
Speaker A
botnet to get into people's uh internal networks from the external. So not great. The other thing that I wanted to mention too is so sometimes these security research teams afterwards they'll write up how they actually found these exploits. If you look through uh
362:55
Speaker A
the blogs on here, there's lots of great blogs about how these exploits have been found. And very very frequently they're going to start with some sort of hardware hacking or hardware analysis so they can get some sort of internal shell
363:07
Speaker A
to do debugging and also dump the firmware and then reverse engineer that firmware because it just really gives you a leg up in your analysis and looking for these vulnerabilities and bugs if you can start with that shell or
363:20
Speaker A
some sort of connection in the background and then the actual executables that are running in the background to be able to reverse engineer those. So, something to keep in mind. That wraps up this lesson and we'll hop over to the next one where
363:33
Speaker A
we're going to start taking a look at the recon phase. I'll see you over there.
363:38
Speaker A
Welcome everyone. So, we left off our last lesson talking about the TPLink Archer router and the exploits and vulnerabilities that were found through the zeroday initiative. And you may recall that there was actually vulnerabilities for both the uh internal
363:53
Speaker A
network side. So through the local area network and also even scarier through what we call the wide area network which is the uh internet connected side or the internetfacing side of the router. So in our last lesson when we were talking
364:08
Speaker A
about this you know imaginary smart lock that we were coming up with in our design we actually didn't directly expose our IoT device to the internet.
364:18
Speaker A
However, there are a couple scenarios either intentionally or intentionally where this happens. So, I just want to take a quick lesson and chat about those. I've updated our drawing here and I've actually added in a router. So, I'm
364:31
Speaker A
just going to draw again this kind of cloud here and we'll put it at the edge of the cloud.
364:40
Speaker A
And then we'll say everything on this side of the router on the inside. This is that WLAN. So, this is the local area network. uh in our case they're all wireless but this could also just be a LAN 2 wired but the idea is that so
364:52
Speaker A
these are all they all have private IP addresses all of these devices and they're sitting inside of our home network and then on this router we of course have the WAN port which is what connects it either to uh a modem or in some cases
365:06
Speaker A
these routers they are a combination of a router and a modem and they'll do that directly but that actually is then going to connect it out and be internetf facing So what can happen with this wide area network connection side is that
365:21
Speaker A
sometimes you know either uh intentionally or unintentionally we will expose ports out to just the broader internet and this again of course really opens up the attack surface for these devices in that we now have these ports that generally would only be exposed on
365:38
Speaker A
the internal network actually exposed out to the external internet. So outside of having this direct, you know, wide area network connection and ports exposed to the internet, there is another way that we can have devices that communicate, you know, directly
365:56
Speaker A
outside of our local area network to devices that are out on the internet. And before we talk about that, what we should chat about quickly is why we do generally this polling with the cloud-based connections. So, in our
366:10
Speaker A
previous lesson, we chatted about how if we want to have our smart lock, for example, talking out uh to a device that's just out in the internet, like an app or something like that out in the internet, then what we're actually going
366:22
Speaker A
to do is we're going to pull back or initiate this kind of phone home connection to an API endpoint, what's most likely an API endpoint. And we're going to have this device reach from inside the network outwards and initiate
366:36
Speaker A
that connection. And this is much easier to get started than trying to come, you know, just from any device outside of the network and back in. And one of the main reasons for that is, of course, we're going to have uh some sort of
366:48
Speaker A
static IP or we're going to have a domain that's attached and associated with this. So, we don't have to try and figure out uh what the IP is coming back in. Uh, and also if we're going to be, you know,
367:04
Speaker A
sending this request out and then it's just going to be connecting back in, well, generally our firewalls and our devices on the exterior are going to by default uh allow these connections back to us. It's no different than uh if we
367:17
Speaker A
opened up an app on our phone or a web browser and we're just going out to the internet and then we're expecting a response back. So, it's going to allow this back into our network. And then of course from our smartphone then we can
367:28
Speaker A
just talk to the server and it can pass on any data we need through this kind of like polling and phoning home connection.
367:36
Speaker A
So one interesting thing with IoT devices that you know you can sometimes do and and sniff out is just you can see all of the different connections that it's making back. It's going to be a lot of times more than just one of these API
367:49
Speaker A
endpoints or servers. and some concerns with these IoT devices. One particular concern that I have is all of the the privacy concerns and the different stats and things that it's collecting from the internet and, you know, constantly sending those back. So, we're not going
368:02
Speaker A
to really focus on specifically those privacy concerns, but you know, just something of interest is all those connections and phone homes that it makes back out of the network. So this, you know, pulling and opening up this connection and and passing the inter
368:16
Speaker A
information back and forth for our smart lock, you know, this works really well because really we just have very minimal amount of data that we need to send. Um, you know, we just got to kind of say like what's the status of the lock if do
368:28
Speaker A
we need it to be unlocked, locked, maybe there's a little bit of management data, but really we're chatting about very minimal amounts of data. Well, you see I've also added in here an IP camera into the mix. So just your standard IP
368:42
Speaker A
camera and if we were away from home and we want to check you know what's the feed with this IP camera. Well if we're streaming you know even in a like a standard definition that's a lot of data
368:53
Speaker A
to be putting through uh cloud infrastructure and maybe we don't want to do this because that's going to incur like a big monthly fee for us. So we want to have some way to go directly from our phone and we'll just utilize
369:05
Speaker A
our own internet instead of this cloud infrastructure to upload this. So, how can we securely and without having to do too much configuration actually just get this direct connection from outside of the internet and then into our network?
369:19
Speaker A
Well, one very common thing that you'll see for things like IP cameras or other devices where we have to uh either exchange a lot of data or we don't want it to be stored in a cloud server is we
369:30
Speaker A
can use a peer-to-peer method where what we'll do is we'll actually initially have a handshake where we'll reach out still to our cloud infrastructure and we'll ask it you know what how do we get in touch with this IP camera uh and
369:45
Speaker A
the IP camera is also going to constantly be uh in contact with this cloud server pulling back and it's just going to be sharing you know its location and its IP address so how it can be connected to uh and then our
369:59
Speaker A
cloud server is going to then you know pass this information back to whatever this client is and this kind of peer-to-peer handshake so we call this P2P handshake and then once we uh have that handshake then our actual device that's out in the
370:19
Speaker A
internet, it can connect back directly into our device and we can then send that data out. So, this isn't too uncommon, especially for things like IP cameras. And this is definitely another avenue that we can look to uh exploit or
370:35
Speaker A
attack. And this is definitely something that black hat hackers are exploiting out in the wild. So, we're not really going to focus too much on this, you know, exposed to the internet portion uh in this course, but I just want to make
370:47
Speaker A
sure that you're aware that this is also uh another definite attack surface for some IoT devices, and it's definitely one of the more scary ones because it is a really good avenue for um hackers or attackers to be able to breach this
371:01
Speaker A
perimeter of a home network and then get inside. So, the one thing that I do want to show just really quickly is how we can find these devices uh and how hackers are able to find them. And to do
371:11
Speaker A
that, we're going to hop over to the browser and we're going to take a look at Showdan. So, I'll meet you over there.
371:18
Speaker A
So, if you're not familiar with Showdan, it's definitely worth a check out. You can get to it from showdan.io.
371:27
Speaker A
And you don't need an account. Um you you can purchase different subscriptions to this and it's going to uh increase the functionality that you have. But even on the free account, you can, you know, get started and start seeing some
371:37
Speaker A
pretty interesting stuff. So, you see here, it's the search engine for the internet of everything. And it allows us to search for devices that are connected to the internet either intentionally or unintentionally. Um, and it's very interesting for finding various devices
371:56
Speaker A
like routers and IoT devices and really gives an idea of just what's connected out there to the internet and how hackers can uh exploit these vulnerabilities that they find in IoT devices that are actually connected to the internet. So the way that Showdan
372:13
Speaker A
works as a search engine is it actually caches the uh header to responses when it kind of grows out and crawls the internet. So you know if the device manufacturer or its part number or serial number or anything like that uh
372:26
Speaker A
is in the banner of that response then then we can actually search for it. So if we you know pull up for example I was already searching just to check this uh the part number of the router that we're
372:35
Speaker A
experimenting on. Well if we search for that and we just run a search can see that there is actually 33,550 um of these devices that are actually connected to the internet which is pretty crazy. and they and the top port
372:50
Speaker A
is 80. So we have a lot of these um web ports exposed to the internet. So you know hopefully they're using uh good passwords and strong passwords for those. But definitely something uh that's dangerous to be exposed out to
373:04
Speaker A
the internet. And you can see here interestingly too it gives us the country. So we've got almost you know 7,000 of them are in Russia. So, another interesting thing that Showdan is famous for and I will just show you is uh
373:16
Speaker A
finding webcams or IP cams that are directly connected to the internet. And a really popular one is this webcam XP to search for because I believe in its default configuration. So, this is a much older um IP cam or webcam and I
373:32
Speaker A
believe in its default configuration uh it was just generally exposed out to the internet. So people are still running these whether it's known or unknown.
373:41
Speaker A
These are exposed to the internet and you can see showdan actually even caches uh an image of this. So you can actually see what is being displayed here. We got this banner grabbing of the webcam XP.
373:51
Speaker A
And if we scroll down we can start seeing some feeds. So this is this is the current day right here actually right now. Um and we can see some feeds on here. And I'm I'm not even going to
374:01
Speaker A
scroll, you know, any further because you can see some really interesting things on here and find some really interesting things. With that being said, I do just want to give a really quick warning of, you know, the ethical
374:13
Speaker A
hacker spiel and, you know, being really careful about the legality of what you're doing. So, I'm just looking and I would say, you know, for me and for the region I'm at this, you know, kind of hands off just looking. That's okay. It
374:28
Speaker A
can be really tempting though with the things that you find on Showdown and what is actually exposed to the internet to do even more than just looking um and start you know doing some poking around entering default passwords in you know
374:42
Speaker A
all that kind of stuff and and I would be very careful and think twice about you know how you do that or what you're doing and what is legal in your region.
374:52
Speaker A
So, that's all I'm going to say on that and I'll wrap up this lesson here on IoT devices and their exposure to the internet. I'll see you over in the next lesson where we're going to pick up and
375:01
Speaker A
look at some OSENT for our router and how we can figure out some more details about it. So, I'll see you over there.
375:08
Speaker A
Welcome everyone. So, now that we have an understanding of the IoT ecosystem and more importantly the attack surfaces that we have, we can get started with hacking. Similar to other types of penetration testing like network penetration testing or web pen testing
375:25
Speaker A
or you know honestly really any type of pen testing. We're going to kick off with doing our recon. Now when we were learning about electrical engineering in the fundamentals lessons that we were doing, we actually did some phases of
375:39
Speaker A
recon since we're repurposing the router as both a test subject for that learning and also our target. The visual inspection of the PCB, the probing with the multimeter, and then finally the discovery of the UART port with the
375:54
Speaker A
logic analyzers would all be very important parts of recon that we've already done. Now, before we actually get our hands on our target or if we're actually just looking for a target without purchasing something, there's actually quite a bit of things that we
376:09
Speaker A
can look for online or as OSENT and that's what we're going to take a look at in this lesson. So, I'm just going to hop over to my computer and we'll get started on that.
376:18
Speaker A
So, one of the very first places that I like to look when I'm doing hardware OSENT is to take a look at the FCC filings. Now, if you're not familiar with the FCC, stands for Federal Communications Commission. And this is a
376:32
Speaker A
US agency that regulates communications in the US. And one of the big things that they regulate is wireless communications. And that includes, you know, basically anything that can communicate wirelessly or broadcasts any kind of wireless signal. U we're not
376:48
Speaker A
just talking about Wi-Fi. This would also be, you know, any radio signals, things like Bluetooth, RFID, NFC.
376:54
Speaker A
Basically, if it broadcasts anything out into the air, uh, then it's going to be regulated by the FCC. So if these electronic devices want to be sold or manufactured or even used in the US, then they need to comply with these FCC
377:11
Speaker A
regulations. And in order to actually comply with that, they have to submit some details and reports to the FCC. And then the FCC will approve that product.
377:22
Speaker A
And any product that they approve is going to get an FCC ID. So, if you flip over your router on the back, you'll see this label with some details about it.
377:31
Speaker A
Uh, and then if we zoom in and take a look here, you can see that we have this FCC ID here. Uh, and the first three or five digits are for the manufacturer.
377:41
Speaker A
So, in here we have this 2 AXJ uh 4 and that is for TPLink as a manufacturer. And then we've just got the part number here that makes up the FCC ID. Now, we can take this ID and we
377:55
Speaker A
can go look it up and find the filing for this. Or if we don't actually know the ID specifically, we can usually just search with the part number and find it.
378:03
Speaker A
So, we're going to hop over to the browser right now and take a look at what we can find. Okay, so I'm over at the FCC website here, and you can see that it looks like it has not been
378:12
Speaker A
updated since the days of Dialup. However, there is a lot of good information that can be found here for all the different hardware or equipment that we may be interested in hacking.
378:25
Speaker A
Just to make a little bit of sense of this URL, uh I usually just bookmark it if I want to go here cuz it's kind of hard to remember and I will link it below. Uh but this OE that is the office
378:36
Speaker A
of engineering technology and what we're looking up is the equipment authorization. So these are the documents and images and everything that the companies will need to submit in order to get their authorization and we're doing a search on that. So we can
378:51
Speaker A
go in here and the grantee code, this is that uh company code. So it's the first five characters uh in our case of the FCC ID and then we can put this product code in and we can do a search here. So
379:03
Speaker A
you can definitely do a search on the FCC website, but I find that it's actually a little bit easier. There's some uh websites and tools that scrape the data from here and they're actually a little bit easier to use. So, I'm
379:14
Speaker A
going to show one of those and that's the one that I usually use. So, it's called FCC ID.io is the one that I like to use. Uh, and then we can just do an FCC ID search. So, what I'm going to do is I've
379:27
Speaker A
got that FCC ID copied here that we pulled off of the router. And now, if you don't know this or you're looking up and you don't have the router, generally you can just find it through the part number, but we've got
379:39
Speaker A
the whole ID. So, I'm just going to pop that in here. We're going to run a search.
379:46
Speaker A
Perfect. And we've brought back one result here, which is perfect. It's for this TPLink Corporation Limited Wireless and Router with this part number, which is the one that we were looking at. And if we scroll down here, we can see the
380:01
Speaker A
exhibits. And this is what we are specifically looking for. Now with this router, you can see we just have the label location and the external photo which really aren't that useful for us.
380:12
Speaker A
But if we do a little bit more digging here, uh we get this FCC change ID document. So I'm just going to open that up and it will actually preview the PDF on here, which is nice. So we don't have to
380:24
Speaker A
download it to look at it. Uh, and if we read through this PDF, it says that they are looking to change the FCC identifier for currently approved devices from this. So, they are changing, they're just changing the ID
380:38
Speaker A
from previously submitted one. Um, so what I'm going to do is I'm just going to copy this and then I'm going to go back and run another search.
380:50
Speaker A
So, if we just paste this in here with a little bit of digging. All right, perfect. Still the same thing. We got this TPLink technologies 300 megabit per second. This is us.
381:00
Speaker A
Perfect. So, if we scroll down here now, we've got a bunch more documents we can start to take a look at. We got the manual. If we didn't have the manual, this is pretty easy to find, but we've
381:12
Speaker A
got the manual here. Uh, let's take a look at the external photo. Make sure we're working with the proper device.
381:19
Speaker A
Perfect. Just looking at the external photo. This looks like the one that we have.
381:26
Speaker A
And then this is where it starts to get pretty interesting here. So we've got this internal photo. So let's take a look at that. All right. So let's scroll down. Pretty poor resolution photos here. But if we keep scrolling down,
381:41
Speaker A
pretty detailed picture here of the board. And you can actually see, interestingly enough, that it's already sticking out to me. We could identify that there's most likely a UART connection here. And you can see that they actually already have the headers
381:54
Speaker A
here. So, we're either looking at uh an older version of the board that had this header on it or what's most likely happened is this is just a test board and they left this on for the testing.
382:05
Speaker A
So, you scroll down even further. This is great details here. We've got one of the chips here and we've got the manufacturer and then the part number.
382:13
Speaker A
So, what I'm doing right now is I'm going to copy all of this. So, this for sure 100% is good details and and we'll go look at this further. And if we scroll down again, we've got another really high resolution picture here of
382:26
Speaker A
this chip. And again, going to take this manufacturer and this whole part number uh and save it for later for more investigation.
382:35
Speaker A
Another one here. Perfect. Now, so you may be wondering like we already had the router open of course and we could find this information ourselves. Uh but one of the nice things about the FCC filings is I mean if you're doing a penetration test
382:50
Speaker A
and you don't have your hands on the router or your target yet, then you could start here uh and actually get some work done before you get that. Or if you're a security researcher um or you know this is also what the black hat
383:02
Speaker A
hackers are doing and you're looking for a target. Well, this is one place to start. If you don't want to actually go buy or get your hands on a device, you're just looking for something you know that maybe has exposed art or you
383:14
Speaker A
want to find more about it. Well, we can do that for free from the FCC filings.
383:19
Speaker A
If we just go back to the rest of the filings here too, there is one other thing that I want to show you, and that is these three filings right here that are listed as confidential.
383:29
Speaker A
You see, unfortunately, we can't download those, but we have a circuit diagram, a block diagram, and the operation description. So, if we could get our hands on these, that would be great. But unfortunately, they've made these confidential. So, if we just look
383:44
Speaker A
quickly at this confidential letter, it basically just says that these materials are trade secrets and proprietary information. Uh, and they they're asking not to disclose these to the public as they might be harmful. And it looks like the FCC has granted that request.
384:02
Speaker A
Unfortunately, most of the time these will be made confidential, but there have been times where I've come across filings that these aren't confidential.
384:09
Speaker A
So, always worth it to take a look and also see if you can find these. Even still, finding the pictures of the chips and their manufacturers and part numbers will actually give us quite a bit of information to go off into digging
384:22
Speaker A
further without actually having our hands on the device. That wraps up this lesson. I'll see you over in the next one where we take a look at the data sheets for these components that we just identified through the FCC website. I'll
384:34
Speaker A
see you over there. Welcome everyone. So, in the last lesson, we were actually able to identify some of the chips on the board, including their manufacturer and part number. The next logical step for us will be to look up the data sheets and
384:48
Speaker A
see what additional information we can gather from there. Before we do that, I think it makes sense to have a really quick chat about embedded systems and how their hardware and software differentiate between the different designs. Now, this is a
385:04
Speaker A
subject that could have an entire course or maybe even multiple courses on it. So, just keep that in mind that I'm going to be doing a really quick and broad overview uh of these ideas. And of course, there is a lot more information
385:18
Speaker A
and depth and some caveats to what I'm going to say. So, first, if you're not familiar with what an embedded system is or what that means, well, what that's relating to is when we have hardware and software that are specifically designed
385:32
Speaker A
just to work together. And that software has been designed specifically to work on that hardware and we're not going to be loading additional software or other features for the user outside of that system in its regular use. So examples
385:47
Speaker A
of that are our IoT devices where they just have one specific use. Uh and the hardware and software are designed specifically for that. And that's in contrast to for example our personal computers where we can add additional hardware and peripherals and we can
386:02
Speaker A
install you know whatever software we would like as long as the software is designed for uh the operating system we're running.
386:10
Speaker A
So I'm going to split these embedded systems up by the type of software that's designed for them. And I'm going to break that up into three different types. And the first one is what is generally referred to as bare metal. So
386:23
Speaker A
what I mean by bare metal is that you know the designers or makers of the software, they're going to write all of the software themselves. Everything and they're not going to rely on any underlying operating system. So everything that their device is going to
386:38
Speaker A
do has to be handled specifically uh by their software and they're going to compile that and then put that directly onto their device and have it run. Of course, this has some advantages in that we then have the most control over our
386:53
Speaker A
system. However, it also may be the most complex because there are a lot of things underlying that the operating system takes care of us as designers and a lot of times it's easy to take those for granted. So, if you don't want to
387:07
Speaker A
handle, you know, all of those background processes and everything that an operating system takes care of, but you don't want to move up to a full-fledged operating system like the ones you'll be used to with Linux or Windows, the intermediary option is a
387:22
Speaker A
realtime operating system or what is commonly referred to or you'll hear as an arttos. So these are very common in IoT or lightweight systems and these operating systems they still take care of a bunch of the background tasks. So
387:38
Speaker A
things like scheduling of tasks, interrupts, memory management and communication between different portions of the system or functions. However, they are designed for much more specific tasks, which makes them, of course, much lighter weight in their size. And it
387:55
Speaker A
also allows them to run their tasks a lot more predictably, which means we aren't guessing about how long it's going to take to run specific tasks. And running the same task over and over again will give you the same outputs and
388:09
Speaker A
the same amount of time. This differs from, for example, Windows and Linux where if you, you know, clicked on some specific task or to open something up, you may have noticed depending on what's going on in the background, the amount
388:22
Speaker A
of time that it takes to finish that task can vary. Real-time operating systems are a lot less prone to crashing as well. Another really important feature of real-time operating systems that differs from a standard operating system is that we can set the priority
388:38
Speaker A
of tasks so that high priority tasks will be completed before low priority tasks and ensures that they are completed when we need them done. This can be important for critical systems for example robotics. Outside of their just timing and predictability, their
388:54
Speaker A
lightweight size also makes them an excellent choice for IoT devices. So you will see these commonly in IoT devices.
389:02
Speaker A
Now I've grouped these two together, the bare metal and the arts because generally speaking you're going to see these running on a microcontroller.
389:12
Speaker A
So the difference between a microcontroller and what you may be used to in your home computer a microprocessor is that microcontrollers are generally less powerful. However, they will include in them uh some memory and some ROM. So some read only memory
389:28
Speaker A
to store our code. So we can compile uh our code and store it directly onto that microcontroller and then it also has the RAM built in that it can access and we don't need to add those uh externally to
389:42
Speaker A
our design. I've added a picture here of an Arduino as an example. So if you're familiar at all with you know hobbyist electronics, you may have used an Arduino. So this is an example not of a consumer one that
389:56
Speaker A
you would see in IoT devices but just something uh you may be familiar with as a hobby designer. The Arduino is a microcontroller design. This is the microcontroller right here. And then we just have all these other peripherals to
390:08
Speaker A
support you know the inputs and outputs to it. So then the third software category that we will chat about is embedded Linux. So in this scenario the designers will go all the way up to porting a Linux kernel and getting it to
390:20
Speaker A
run on their embedded system. And then we're running a full-fledged operating system or close to the full-fledged Linux that you may be used to using.
390:31
Speaker A
And of course, this offers lots of advantages for us in that the Linux operating system is going to handle all of the things in the background that we are used to it handling. So all of the scheduling, things like networking, it
390:45
Speaker A
can take care of all of that for us. And then as designers, what we can do is just write bash scripts and binaries and have those take care of whatever functionality we need. So this can be a little bit easier on developers as it's
390:58
Speaker A
a little bit closer to just developing for standard Linux. So generally for embedded Linux outside of a few uh edge cases, we're going to be running it on a microprocessor.
391:10
Speaker A
And the microprocessor is different from the microcontroller in that it's usually going to be more powerful. However, with it, we are going to require external RAM and an external ROM. So, we're going to need uh extra chips that we're going to
391:24
Speaker A
have to add onto our board and interface those with our microprocessor because we're going to need uh quite a bit more RAM and quite a bit more ROM to run a full-fledged operating system and we're going to use external specific chips for
391:38
Speaker A
that. So an example for a hobbyist board if you're probably familiar with this the Raspberry Pi. This is running embedded Linux on a single board computer. So embedded Linux is becoming very common in IoT devices just because of its ease to get up and running and
391:55
Speaker A
write software for and our router is running embedded Linux. So now that we have an idea about the hardware that's involved with it, it will make a little bit more sense hopefully when we're looking at the data sheets. So, I'm just
392:05
Speaker A
going to wrap up this lesson here, and in the next one, we will hop over to the browser and try and find the data sheets for these core components of an embedded Linux system that we identified. I'll see you over in the next lesson.
392:18
Speaker A
Welcome everyone. So in the last video we chatted about embedded systems and we actually left off talking about embedded Linux and that the router we are using as a target the TPLink router that I have a picture of here is actually
392:33
Speaker A
running embedded Linux itself. When we were doing our OSINT with the FCC pictures in the FCC application we were able to identify two of the chips their manufacturers and the part numbers. And one of them was this one in the middle
392:48
Speaker A
right here, which is actually the processor. It was that MediaTek chip. And then this bigger one right here, this Zentel chip. This is the RAM. The third one that we weren't able to identify from the pictures is this chip
393:01
Speaker A
right here, which is the ROM. Now, what I've done is I've taken a very high resolution picture with my camera phone.
393:09
Speaker A
And then if we blow it up, which we can see on the right here, actually able to see in pretty good detail to make out the manufacturer in the part number, which is this CF EO N or Cion. And then
393:23
Speaker A
the part number is this QH32B104HIP. So if you just look at this with your bare eye, it's actually really hard to tell that there's even some writing on here. And in the past, we would have used either a microscope or a magnifying
393:38
Speaker A
glass or something to try and read this. But now, the cameras are so powerful and high quality on our phones that I usually just use those. They are an excellent tool for recon and for figuring out what is going on on these
393:52
Speaker A
boards with the traces as well, which is something we'll look at. So, not to be underestimated, the power of taking a good highresolution picture and then just zooming that in on the board. I do it all the time. With that being said,
394:05
Speaker A
now that we've identified the manufacturer and part number for these three core components, we should be able to hop over to the browser and use Google to find the data sheets for them, which is going to give us a lot more
394:17
Speaker A
information about their functionality. So, let's hop over there now. Okay. Okay. So, what I've done is I've just transcribed over the manufacturer and then the part number from those pictures so that I can easily copy them into Google and that I'll also be able to put
394:31
Speaker A
them into my notes. Uh, one thing to call out here is you'll notice so the manufacturer that's easy to identify, but then those chips most of them they had more uh details or you know numbers outside of what I've copied. Now,
394:45
Speaker A
general rule of thumb is that the first, you know, string of characters that's immediately after the manufacturer, um, that's the part number. And then if there's a dash and something after it, then that'll maybe be the part number
394:56
Speaker A
and some options. Uh, and then on the other lines, you'll notice that we did have some other numbers. Um, generally those aren't part of the part number.
395:05
Speaker A
They may differ between different batches of chips and they might, you know, denote something about like what batch they are, where they're made, um, different information for QA. So, we can usually leave those off when we're searching and we just go with the
395:17
Speaker A
manufacturer and then that first string of characters after. So, I'm going to start with this one. This is the processor and I think it makes the most sense to look at first. So, what I'm going to do is I'm just going to copy
395:27
Speaker A
this over and we'll take a look on Google and see what we can find for it.
395:33
Speaker A
Okay, so the first one here that we see that I've already visited actually is this MediaTek website. Um, so if possible, I'll always try and go to the manufacturer first because they should have the most up-to-date data sheets to
395:46
Speaker A
look at. So we'll just hop over to the manufacturer's website. Okay, so on the manufacturer's website, we get some details here. And if we read about this, we'll see that this is actually uh an SOC system on a chip that
396:00
Speaker A
includes all the functionality that you would need to build a router around it. And we can hear see here it's you know it's functions mainly for this N300 style router. So it's interesting to see that there is this uh CPU or chip that
396:14
Speaker A
is designed specifically for building a router. And this is actually something that you're very commonly going to see uh in IoT devices where they follow um you know a specific formula where they have those three core components that we
396:27
Speaker A
talked about. Again, you're going to have a processor. Generally, it's going to be a processor that's only commercially available. And what what I mean by that is only, you know, bigger companies are going to be able to buy
396:36
Speaker A
them in these mass quantities. And then that processor is frequently going to be specifically designed uh for a specific function. So, in this case, we're looking at a router. Uh and then they'll build out an external RAM and ROM off of
396:49
Speaker A
that. So, if we just scroll down here to look at the specifications, we'll see a little bit of interesting information about it. So the one thing that sticks out to me here is we have the CPU type which is MIP. Now if you're not familiar
397:03
Speaker A
with MIPS, this is this MIPS 24K EC. Uh MIP is the architecture of the CPU. So kind of similar to if you are familiar with either uh x86 or x64 architectures or even ARM. Mips is just another architecture like that. It's actually a
397:21
Speaker A
very old architecture and it's not really frequently used outside of these IoT devices. So, you won't really see it much anymore except for these IoT devices. Generally, what you're going to see with IoT devices is they'll either be this M.Y.I.P. style um or more common
397:36
Speaker A
these days is to see it as ARM. So, another thing that I'm going to call out here is we actually see the OSS here and we can see uh it runs this ECOS and also this Linux 2.636 636 which has the SDK
397:48
Speaker A
support and then also this Linux 3.10. We scroll down here. We actually see there isn't much more information. This isn't actually a full data sheet. So this is quite common on these you know only commercially available components.
398:02
Speaker A
Generally you'll have to you know get in touch with the manufacturer and ask for a data sheet but if you do a little bit of digging you can usually find them on the internet. So we go back to the
398:12
Speaker A
Google results. Actually we see just the second one here. Uh this is a data sheet. It's through this seed studio. If you're not familiar with them, they're similar to Arduino in that they make um single board microcontrollers and
398:26
Speaker A
microprocessors and dev boards and things like that that are good for prototyping or for hobbyists and makers.
398:32
Speaker A
So they're a good resource if you ever see them for data sheets. And we'll just take a look at the full data sheet. If we scroll down a little bit, one of the first things that stood out to me kind
398:41
Speaker A
of funny see this is confidential. uh interesting to see that. Of course, we just did a very small amount of digging and found it.
398:49
Speaker A
And on this data sheet, we get a lot more information. So, if we want to look take a look at the overview, it's kind of interesting to read about. And you can also see all of the core features of
398:59
Speaker A
it, including this functional block diagram that gives us a little bit of information about how all of the inputs and outputs work on the system. So, if we just scroll down a little bit here, this is something that's common in data
399:12
Speaker A
sheets in that data sheet will be for a few different part numbers that are very similar, but they'll have different packages. And the package that we're looking at, you'll see the part number is for this one ending in NN. And then
399:24
Speaker A
our package is this DRQFN, 156 pins. Uh, so the last part, this is just how many pins are on that actual chip. And then this DRQFN, this denotes the actual package of how the chip is laid out. So this QFN stands
399:40
Speaker A
for quad flat, no leads. So you remember when we were looking at the picture of it, it has four sides um that have inputs and outputs onto it. And then there actually is no leads or like arms sticking out off this. There's just the
399:54
Speaker A
the pads that are directly on the underside uh of the chip. So we just scroll down a little bit more. or I'm not going to go over the uh entire data sheet, but you're more than welcome to if you want to, but I'm going to call
400:05
Speaker A
out some of the key things that I see on this data sheet. Okay, so again, in the main features, we see this MIPS, which we already saw. So, another thing that stands out to me is this SPI flash. So, we can see that the
400:20
Speaker A
flash for the ROM is communicating with this SPI format. So this is serial peripheral interface and this is another communication protocol that we're going to talk about more in depth. So good to see that and that's how the ROM is
400:32
Speaker A
communicating. And then we also see all of these other communication protocols that it can use. So these are all just different common communication protocols that you'll see in IoT devices. Uh and we're going to chat about more of them
400:46
Speaker A
in detail, but the one here that really stands out we already chatted about is UART. And we can see that there are two UART uh communications on this chip.
400:56
Speaker A
Now, the one important thing to note with all of these other communication protocols is that, you know, just cuz there's pins on the chip and they're supported, that doesn't mean that the underlying software is actually going to be utilizing them. Uh, however, if we
401:09
Speaker A
didn't have a UART header, for example, and we didn't see those pins, well, it's still possible that it is in use and we can actually just go directly to the chip to access it. So, good to see that
401:20
Speaker A
and good to know that if I just scroll down a little bit more, the other thing that I always want to see on data sheets and take a look at is the pin out. And this here is going to give us the pin
401:31
Speaker A
out. Again, just a quick reminder, this there's going to be two pin outs here.
401:36
Speaker A
The first one is for the actual uh format of the chip that we're looking at in that NN. And you'll see here for readability, they've actually split this up into four different quadrants. uh in this one it denotes it as the upper left
401:50
Speaker A
side. When you're looking at chips, generally the upper left side of the chip is going to be denoted either with a circle or a triangle or some sort of tick and that will help you to determine the orientation of the chip and help you to
402:06
Speaker A
figure out where those pins go. So, if I'm just going to scroll down one more so, we can see the bottom left side or the down left side. There's a few different pins on here that I am interested in. First one is we have this
402:19
Speaker A
very first UART connection here. So, we've got the transmit and the receive lines for the UART. And then we've also got all of these SPI signals here. So, all the way from 24 down to what looks like 28. We have these SPI signals that
402:35
Speaker A
we're going to be interested in because they are most likely going to interface with our ROM chip. So, these pinodes are going to be super helpful if we are reverse engineering the board uh and we don't have any labels and we're trying
402:46
Speaker A
to figure out what's going on. So, there's a bunch more interesting information on this data sheet if you want to read through it. But for what we need to get started, this will give us enough information. So, let's move on to
402:57
Speaker A
the next one. We'll take a look at the RAM. All right. So the first result is through Mouser Electronics. So they're a very popular uh seller of electronic components. Mouser Electronics and Digi Key are actually two of the main places
403:18
Speaker A
where I get data sheets because generally uh any of the components that they sell are going to have a data sheet tied to it. So let's hop over there and take a look at the data sheet.
403:31
Speaker A
All right, so we get a little bit information about it. We can see it's a 256 mgabyte uh SD RAM. And if we scroll down here, we can get a little bit of information about its features. And we
403:43
Speaker A
can also see about the pin out. So for us, we're not going to be as concerned about the RAM in this beginners course because any attacks that are going to target the RAM, those are kind of more of an advanced
403:57
Speaker A
technique uh that we're not going to be focusing on. But it is good to have this information. Uh, and sometimes you will target the RAM because that will be the only way to get to certain specific things if they're encrypted. For
404:10
Speaker A
example, maybe they will be unencrypted at bootup and only stored in the RAM. So, if we can dump the RAM, that is one way to get it. Uh, and now we have the data sheet for it. So, even though we're
404:20
Speaker A
not going to use it, still good to find it. And I will be keeping all of these data sheets uh in my notes. Let's take a look at the ROM now. So, just a quick note on what a ROM does if you're not
404:31
Speaker A
familiar with it. Again, that acronym stands for readonly memory. And you'll sometimes hear it referred to as an EPROM as well, which just stands for electronically programmable readonly memory. And generally, these chips are a type of flash memory where we will store
404:47
Speaker A
the underlying operating system and then all of the additional software uh that we have wrote for our systems or embedded systems. And usually what we call this package of software is the firmware. And we're particularly interested in this as hardware hackers
405:03
Speaker A
because if we can dump this firmware and get to it, this is going to contain all of the file system and those binaries that we can then start to reverse engineer.
405:14
Speaker A
All right, so we identified the ROM as this CFON Q32B104 HIPP. Couldn't see it on the chip, but with the pictures, we are able to find it. So, let's again do a quick search through Google for that.
405:30
Speaker A
All right. And the second result here is the one that I found a good data sheet for and it's through this alldasheet.com.
405:38
Speaker A
Um, so before I click on this, I do just want to give a quick heads up about data sheets and data sheet websites. So sometimes for more obscure parts or ones that are, you know, generally only bought through these, you know, big
405:54
Speaker A
commercial quantities, uh, where you got to get the, you know, data sheet, you got to ask through the vendor for it, they're going to be a little bit more tricky to find. And sometimes these, you know, data sheet websites, they're very
406:07
Speaker A
popular. Everyone always wants the data sheets, especially if you're building something, reverse engineering or hacking. And there will always be a website that claims to have a data sheet for everything. If you use like Torrance or in the past you use like peer-to-peer
406:22
Speaker A
downloading software, you may remember like whatever you put in there would be somehow be like some sort of result for it that was like a virus or something.
406:29
Speaker A
Well, just I want to say this. So, just keep an eye out when you're looking at data sheets. You know, use your smart internet uh browsing techniques and just be mindful. So, it's no different than if you're looking for, you know, an
406:41
Speaker A
obscure exploit or something like that. Just keep that in mind. That being said, this all data sheet.com, I have used it in the past and it's usually pretty good for data sheets. Okay, so it looks like that CFON that is part of this Eon
406:54
Speaker A
Silicon Solution Inc. And if we scroll down here, um, we've got this one here that has it's pretty much the whole part number of that right here. And I'm going to take a look at the data sheet for it.
407:07
Speaker A
So looking at some of these main features, the one that sticks out for me here is that it is SPI compatible. So that is again that serial peripheral interface. And this just confirms what we saw on the data sheet for the
407:20
Speaker A
processor. Uh and then if we scroll down a little bit more, we see, you know, it supports these different types of SPI uh and the different signals that are going to be used for it. So we can see a
407:30
Speaker A
little bit of a general description here. And then if we scroll up and we actually just go over to the second page here, we are going to see the pin outs, which of course we always want to know.
407:41
Speaker A
And this is going to be important for us later. We're definitely going to save this because one of the things we're going to do is we're going to try and dump the contents of this ROM so that we
407:50
Speaker A
can read it. A few other things to take note of is if we just go through a few other pages here, then you get some details about the different signals and how they function. Um, so the different SPI signals and we just want to keep
408:03
Speaker A
that in mind. And then also if we just go a couple more pages over here actually. So we're going to get the different address ranges and the sectors. And then if we just go over uh one more page here, we're going to get
408:14
Speaker A
some information about how the SPI functions and the different SPI modes. We're going to chat about this in much more detail in upcoming lessons. So I just want to keep in mind that, you know, it's good that we find these data
408:25
Speaker A
sheets. Uh, and we're definitely going to be using all of this. Just going to hop over really quickly to that highresolution picture that we took of the PCB so we can take a look at how we can actually trace out those different
408:37
Speaker A
traces on the PCB and figure out where they're going. So, another really useful thing to do with these highresolution pictures is you can either use something like paint uh like I've done here or you can actually just physically print them
408:51
Speaker A
out if you have a good enough printer and then just draw the lines on them with a marker or something. But you can actually zoom in enough that you can, you know, trace out these traces to where they are going and then use that
409:03
Speaker A
to reverse engineer what's going on on the board. And this can be super useful if you aren't able to actually get your multimeter in and beep out the continuity. Uh, and it can also just be faster this way. So, if you remember, I
409:17
Speaker A
called out that this top left pin here, the second one down from the top, this was the data out. And again, we just see that little indicator here that indicates the top left. Well, on our processor here, this is the top left.
409:32
Speaker A
And you may recall from the bottom left quadrant that around the top of that bottom left quadrant, we actually had all of the SPI lines. And this one right here, actually, if you count them all out, is what is called the MISO line. So
409:49
Speaker A
that is master in, slave out. So the processor is generally the master in SPI communication and then the peripheral which is the ROM in this case is the slave. So the the slave out would be the same as the data out and it goes into
410:06
Speaker A
the master. And you know we've now traced out this line and we could trace out the rest of all of these lines as well. And we could even go as far as if we didn't know that this header was UR,
410:17
Speaker A
we could trace, you know, all of these lines out as well, and we would be able to figure out that these are going to the UR. And that's one way we can start to determine what's going on with these
410:28
Speaker A
boards and what the different headers and pins are. So, we got a lot of really good information in this lesson and I'm definitely going to be adding all of those data sheets as downloads to my notes and then also keeping track of
410:42
Speaker A
some of that core information that we found because we are definitely going to be using it and relying on it throughout the rest of the course. With that being said, that wraps up this lesson. I'll see you over in the next one. Welcome
410:54
Speaker A
everyone. So, in the last video, we left off taking a look at the data sheet for what turned out to be the flash ROM.
411:03
Speaker A
Now, if we weren't already suspecting this or aware of it, this just confirms to us that there is going to be some sort of firmware that's loaded onto that ROM. If you're not familiar with what firmware is, especially in embedded
411:16
Speaker A
systems, generally this is going to contain the operating system uh and the root file system. And this root file system is going to contain uh you know the file structure for that operating system. And it's going to have all of
411:30
Speaker A
the files in it like the binaries and scripts and configuration files that our device requires to set itself up and also to run. As hardware hackers, one of our main goals is going to be to get our hands on this firmware so we can start
411:47
Speaker A
reversing it and analyzing it because this is going to greatly assist us in figuring out how the device functions and also to find any vulnerabilities in the underlying software. Now, there's a couple ways that we can extract the
412:02
Speaker A
firmware off of the hardware itself and we're going to take a look at those later on. However, sometimes the best way to get this firmware, and the easiest way is to just go out on the internet and look for it. There's a
412:15
Speaker A
couple different places that you will usually find firmware. One of them is on forums or other unofficial sites where people have been able to recover the firmware and then they've uploaded it for other people to use or analyze. And
412:28
Speaker A
then the other one, which is usually the best method, if you can find it, is just to get the firmware directly from the manufacturer. Lots of manufacturers make the firmware available to the public so that they can perform updates to their
412:41
Speaker A
device when new versions are released. And for TPLink, that is generally the case. You can usually find their firmware through the support section of the device. So, Google is usually your friend here. A quick Google search and we can usually find it. So, for our
412:56
Speaker A
router, it's a TPLink 84, this one right here. Uh, and I'll just going to add firmware to it here. First one. And then we've got this download link and it's under the support for our router.
413:13
Speaker A
Okay. So, I'm just going to click on the firmware section here. And if we scroll down quickly, uh just one of the things to note here, we've got the bug fixes and modifications. And if we look at number 10, they've kind of just tucked
413:25
Speaker A
it down here uh at the bottom, we get this enhance device security. Uh so usually when I see this what this means is that you know this version one of the main reasons they release this is probably because there was a CVE or
413:38
Speaker A
other vulnerability disclosed to them in the previous firmware uh and then they fixed it. So just a little bit of foreshadowing to what we're else we're going to be uh looking at. But in the meantime I'm just going to hit uh
413:50
Speaker A
download here. I've already downloaded this before. Um, and I'm going to save this and I'm definitely going to add this link to my notes and add that we found this firmware to my notes so we can use it later in our analysis. That
414:03
Speaker A
wraps up this quick video on Recon and how to locate the firmware. I'll see you over in the next one. Welcome everyone.
414:12
Speaker A
So, in the last few lessons, we took a look at the hardware recon. We were able to identify a few of the core chips, get some data sheets on them, and then get a bunch of important information that
414:24
Speaker A
we're going to use further down the road when we're doing our hacking. The next step that we're going to take is we're going to move on to recon for another attack surface. And the one that we're going to be looking at is that internal
414:38
Speaker A
network that the router hosts. So, you may recall previously I chatted that we're not going to be focusing on this attack surface because there's already a lot of excellent training already through TCM Academy on internal network penetration testing. However, I do think
414:55
Speaker A
it is important for us to at least do uh end mapap scan and see what ports and services are running on the router before we start poking away at the hardware. Now, if you're running a setup similar to me where you have Kali Linux
415:10
Speaker A
as a virtual machine that you're going to be using as your pen testing machine, uh, or you really have any other DRO of Linux or virtual machine running, then you're going to probably need to make a change to your VM settings. So, by
415:25
Speaker A
default, especially if you're going to be using a Cali VM for ethical hacking, you're going to have your network adapter set to NAT. So, this is great for ethical hacking anywhere where we're going to be uh actually, you know,
415:37
Speaker A
running exploits. If we still need internet, but we don't want to be connected to our home network, our host network, then this adds that extra layer of separation from it where we actually won't be on that home network. However,
415:51
Speaker A
what we're going to do is we're going to connect to the router's network, so the one that it creates. And the easiest way for us to then get access to that through our host computer is to set this
416:02
Speaker A
to bridged. So I am personally using VMware Workstation Pro and I'll show you how to set it in that and then we'll take a look at just the regular VMware Workstation Player, the free one and also how to set it in Virtual Box. So,
416:18
Speaker A
what you're going to do in the VMware Workstation Pro is if you just go to the computer lists, and this is the um Linux that I am using. So, I'm just going to double click on it. And then if you go
416:30
Speaker A
in here, network adapter settings, or you can go up into VM and then settings through here. Just going to click on this. And I'm going to set it to uh bridged connected directly to the physical network. Uh and I'm going to
416:43
Speaker A
click okay. Now, if I just go back in there quickly, I do want to show one thing or you'll see here like it's saying um that it's automatic. So, just one thing to keep in mind, and this is only for the VMware
416:56
Speaker A
Workstation Pro. You may need to go into uh your settings and go here and go edit and then virtual network preference.
417:06
Speaker A
And then this virtual network editor will pop up. Uh and you'll see under the auto bridging here, you may need to change your automatic settings here. So, I'm just going to set it. And this is the one where I have my Ethernet port.
417:18
Speaker A
And I'm going to be using uh Ethernet for connecting to the router because then I can still have my Wi-Fi going and I won't get kicked off the internet. Um, so just only select one here and choose whatever you're going to be using. So,
417:30
Speaker A
if you are using your wireless, then make sure only uh your wireless is going to be connected. So, however you're going to connect to your router, pick that from here. Again, this is only for VMware Workstation Pro that you need to
417:42
Speaker A
set this in here. Just going to go cancel and cancel in here because I'm happy with the settings. And I'll just leave it as that for now.
417:51
Speaker A
The next one I'll show quickly is we'll just pop up this VMware Workstation Player. Just drag it over here.
417:58
Speaker A
All right. So, when it launches up, we get this list of the VMs. I've got a Kali Linux one right here. Uh, and you'll notice I actually can go into edit machine settings here.
418:09
Speaker A
And same thing, we'll just set it to bridged. Now, the one thing I've never figured out how to do this or if it's even possible in the free version of VMware.
418:19
Speaker A
I usually only use the pro one, but you'll notice you can't. There's no settings unfortunately for changing the virtual network preference editor.
418:28
Speaker A
That's something that is tied to the pro version. Um, so I believe this is just going to pick one. So, if you do have two networks connected, like you're connected to your regular Wi-Fi, uh, and then Ethernet in to your actual router,
418:43
Speaker A
um, it may not pick that up. So, you might need to just quickly disconnect from one before you start it. So, something to keep in mind. If anyone does know how to um, set this in the nonpro version, then let me know. I'd
418:54
Speaker A
love to know how to do that. Just going to hit cancel here, and then we'll take a look at Virtual Box. So, I'll just drag that one over quickly.
419:04
Speaker A
and in Virtual Box. So again, going to click on the VM we want. I've got this Kali Linux one that I was playing around with. Uh and then if you go into the settings here and we go down to network,
419:15
Speaker A
just go from NAT to bridged. And then the nice thing is in Virtual Box, you can actually just change it right here.
419:20
Speaker A
Um so pick what whatever one you want. So I would pick uh you know, this one is the Ethernet Ethernet adapter that I have on my laptop. You'll pick whatever one you want there. And then you just click okay. I'm not going to I want to
419:32
Speaker A
leave that as NAT. So just go back over to VMware Workstation. And so the one really quick thing I will call out is it's good to have it on this NAT if you're doing other things. You probably don't want um your penetration
419:47
Speaker A
testing VM to be connected to your home network. So just if you are using the same Kali Linux that you use for uh you know other things and connecting to VPNs and all that great stuff that we do as
419:59
Speaker A
ethical hackers remember that you set it to this and then you should set it back to NAT afterwards. What I do is I actually have this VM set up that I only do my hardware hacking on and that's it.
420:09
Speaker A
Um so if I accidentally leave it on that or whatever, it's fine. And then I have another uh Kali Linux where I do my other ethical hacking stuff. So, very quickly, I'm just going to power on the router and then I'm going to plug into
420:22
Speaker A
the Ethernet port on it. I'm going to be using Ethernet to get to it. Um, you can also connect to the Wi-Fi network that it does as well if you want. Uh, the SSID for it and the password are on that
420:33
Speaker A
label on the back of the router by default. So, I'm just going to go plug it in and connect right now. One quick thing to note is we're not actually going to be working with the uh external network in this. So, we're not actually
420:45
Speaker A
going to be hooking it up to the WAN. So, if you are plugging this into the Ethernet ports, pick one of the four orange ones on it and just leave the blue one und disconnected. The blue one's the one that would go to the modem
420:56
Speaker A
and would give us actual internet connection, which we're not going to be using for this testing. So, I'm going to go plug that in right now. All right, I've got mine plugged in and I'm just going to power on the virtual machine
421:07
Speaker A
here. Okay, so now that I'm logged in, I'm just going to do a really quick sanity check and make sure I'm on the right network. I'm going run IPA here.
421:18
Speaker A
Perfect. So I see I've got this 192.168.0100 and I'm on this 192.168.0.0/24 subnet. So that is the default subnet for this TPLink router. Uh for whatever reason you didn't weren't able to find that out, you can find it easily through
421:34
Speaker A
googling it. So now that we know we're actually on this network, the very first thing we're going to do is we're just really going to quickly set up the router and make sure we can access that.
421:44
Speaker A
I'm going to assume that pretty much everyone has probably set up a wireless router. So I'm just really going to quickly gloss over that. Generally what they're going to do is they host a internal web server on port 80 and then
421:56
Speaker A
that's where you go to set them up and they are usually uh the very first you know IP address in that subnet. So this 192.168.0.1 that's the IP address by default for the router. And if we go to it, we get this
422:10
Speaker A
website to log in. And I do just want to call this out that this is nice to see um on routers now that manufacturers are doing this where they they don't just have a default password. They force you
422:22
Speaker A
on the very first setup of it to actually create a login password which is good in case you know we did see a bunch of these were connected out to the internet and so this you know would be
422:33
Speaker A
exposed. So this forces people at least to set some password instead of just rocking with the defaults. So I'm going to make a password here and set this.
422:41
Speaker A
Just going to go with a really secure one two three four qwer. So I can remember it.
422:48
Speaker A
You can set it to whatever you want. So before I click start here, just a quick call out um before this little pop-up goes away that we can also set this up.
422:55
Speaker A
It says through this TPLink tether app and we can scan the QR code here to get it. Um so again, we're not going to be looking at the mobile app in this course because there's already a really good
423:07
Speaker A
course on that. Um, but just a quick call out that of course we do have a mobile app that is part of that IoT ecosystem. Uh, and if we were doing a full scoped penetration test, then this app may be included in that as well. So
423:20
Speaker A
interesting to see that. I'm just going to click start here. Create this password. And then now we can get to all of the settings for the wireless router, which we're not going to change any of these now. I'm just going to leave it uh as
423:34
Speaker A
is. And this gets us to where we can start doing an end mapap scan on this router. So I'm going to wrap up this video here and I'll see you over the next one where we start to run our end
423:44
Speaker A
mapap scans. Welcome everyone. So now that we're on that same network as our router, we can kick off our end mapap scans. So I'm just going to start with the tried and tested method of end mapap scan that TCM
423:59
Speaker A
uses. It will work for us as well. So again, that's just T4 for the speed that we want. We're going to go just all ports on this TCP scan. And we'll ask for all the information. And then we're
424:11
Speaker A
going to target that router, which the default IP address of it is at 192.168.0.1.
424:17
Speaker A
And I'll just let this run. It's going to take a couple minutes. I'll see you back over when it's done running.
424:23
Speaker A
Okay, so our first scan results are back for that TCP scan. And if we take a look, we we see that we have SSH open and we've got the version here. So, it's running this drop bear and then we get
424:35
Speaker A
some versioning as well. So, that's great to see. We've already got um some banner grabbing and versioning that we can take a look at. We already knew this one was open because we already went to the uh web server for it. And this is
424:47
Speaker A
that ADTCP where it's hosting that configuration website. very common to see in IoT devices and especially routers where it hosts a website. That is the UI for changing settings and things like that. And we get some of the
425:02
Speaker A
information and fingerprinting back about that website. And then if we scroll down here, we see that we also have this 1900 open for UPN, which is universal plug and play, which makes sense to see on a router to be open. So
425:20
Speaker A
those other devices on our network, if they are using universal plug and play, they can connect back to the router and ask it to open up the ports that they need in order to function. And nice thing about this is we start to see a
425:35
Speaker A
little bit of banner grabbing here. So we get this UPN uh devices and the SDK versioning number. And then we also see the Linux kernel version that's running here. And it's that 2.6.36 6.36 that we saw from the data sheet on the uh CPU on
425:53
Speaker A
the processor. So then we are able to confirm that version of Linux. And if we just scroll down here, we'll also see a little bit of that fingerprinting that it was able to detect that Linux kernel of 2.636.
426:07
Speaker A
So, when I'm scanning IoT devices in particular, I also always like to look at the UDP ports as well and not just do the TCP ones. Again, with these IoT devices, sometimes it can just be the wild wild west of what they're using.
426:22
Speaker A
And I like to take a look at the UDP ones. So, the next thing we're going to do is we're just going to run a quick end mapap scan to check for the top 100 ports on UDP because this does take uh a
426:32
Speaker A
while. So, I'm just going to quickly run that. If you have never done that before, just keep in mind that you need to do this under pseudo. So it is pseudo end mapap and then it's - s u like this
426:44
Speaker A
lowerase s capital u and then we're going to go dash top dashports equals 100 and we'll set the IP address here and run that.
427:03
Speaker A
This will take a little while since we're doing the top 100 through UDP. So, I'll just pause it here and come back once it's all done.
427:14
Speaker A
Okay, so that took a couple minutes, but we're now done. And we can see at those top 100 ports, we've got the uh DHCP one here, which is uh open, but possibly filtered. And it makes sense that that
427:27
Speaker A
would be there on a router. And then we've also got the UDP port for this UPN as well. So, nothing crazy for this router, but I just want to show this because I think it's really good to always run um the UDP scans on the IoT
427:41
Speaker A
devices just to see what's there and if there's anything out of the ordinary that we can look to attack. So if we were looking at this device purely just from uh an internal network assessment viewpoint u either we're doing an
427:55
Speaker A
internal network assessment and then this has come up in our scope and we think that maybe this is a good target for us to get more access. I mean routers are a a great target if we can get on them because there's so much data
428:08
Speaker A
that comes through them to see. Um or if for example this you know was just a hack the box or something like that and these are all the ports that are open.
428:16
Speaker A
Well, then we're stuck with going through these ports. Uh we would we would do so, you know, in a a methodological format where we check each of them. Um we'll, you know, go through the versioning of them, look for
428:28
Speaker A
common exploits, and then probably end up at the web server itself. So, this port 80 web server and then we're going to do all of the, you know, web app pen testing things that we would do, enumerating the website, directory
428:40
Speaker A
busting, you know, running nicto and fuzzing and all of those things. So on an IoT assessment, you know, it's it's okay to do um all of those. And if we're trying to be really thorough, then it's probably good. We've got some versioning
428:52
Speaker A
here. So, you know, we can go look and see uh if there's any exploits for this, for example, uh or the UN UPN, we've got some versioning as well that we could go and look if there's any exploits for it.
429:03
Speaker A
However, the focus of this course is we're going to actually, you know, still be looking at possibly targeting some of these services, but we're going to do so, you know, from the inside with the aid of the hardware. So, as far as the,
429:16
Speaker A
you know, network recon and assessment go, I'm actually just going to end it here, and we're not going to go, you know, any further into the web server or running any further scans on that web server until we actually have our
429:29
Speaker A
hardware shell. And then we can also see what details we can get from that as well. Again, I would suggest take all of this, add it to your notes, take a screenshot, or just copy and paste it into your notes uh as you would with any
429:41
Speaker A
other testing or assessment. I'll wrap up this video here and I'll see you over in the next one.
429:48
Speaker A
Welcome everyone. So, before we move away from the recon phase, there's just one last thing that I want to quickly show that I find really helpful when looking at these IoT devices. either if you have one picked out that you're
430:01
Speaker A
going to be targeting um or you are performing a penetration test on it or honestly even more importantly if you are looking for a a target that you want to do some security research on I like to go and look at the um vulnerabilities
430:16
Speaker A
that have already been disclosed and patched for that IoT device and then see if there's any you know common themes or things that keep coming up and that gives us an idea if you know it's going to be even really possible or realistic
430:29
Speaker A
for us to find something or what we can specifically look for. So, I just like to use Google for this. Again, Google is your friend. And we will just look up this TP link again. So, it's this router. And then I'm going to look up
430:42
Speaker A
CVE. And we'll get a bunch of results for it. So, the very first one is actually one that I like for IoT devices cuz it makes it really easy to group those exploits for a specific um hardware product,
430:56
Speaker A
which is what we want uh in IoT. But you can use your favorite CVE repository.
431:01
Speaker A
The MITER one's great. Or I'll scroll down. Uh the CVE details, of course, here's the MITER one. These are all good as well. I'm just going to take a look at this one here. So, what I'll do is
431:11
Speaker A
I'll just take a quick browse through and I'll kind of look at the high impact ones and I'll see in the details what what was discovered and if we start to see any common themes. Um so looking at
431:21
Speaker A
this one here for example the vulnerability allows attackers to execute arbitrary code on these affected installations and then it's you know saying we can bypass the authentication and this flaw exists within this ated_TP service and the issue results from lack
431:39
Speaker A
of proper validation of a user supplied string uh before using it to execute a system call. So already we're seeing this lack of proper validation of user strings. Uh, if we scroll down a little bit more here, I want to take a look. We
431:52
Speaker A
got some command injection here. Taking a look at some other ones. Got a buffer overflow on this HTTP Damon. Uh, again, we see the firmware version. We can use an arbitrary get request on the page for the system tools of the Wi-Fi
432:07
Speaker A
network. So, this is again that web server. We can make a get request to it and then have that be passed down into uh this HTTP damon where there's a buffer overflow. So again we're seeing if there's buffer overflow probably not
432:20
Speaker A
proper uh input validation. Scroll down in here we see a stack overflow again you know in this function right here. Uh and if we keep scrolling down here is another one buffer overflow in that HTTP damon again coming up once more with the
432:36
Speaker A
same get request to a configuration page uh that's being hosted on the web server. And if we keep looking here, here's another one. Uh, execute arbitrary code through that TCP or uh, TCP port 80, you know, does not properly
432:50
Speaker A
validate the length of user supplied data. And again, that's led to remote code execution. So, if we keep scrolling through these, we're going to keep seeing that theme um where we don't have proper input validation to things that
433:03
Speaker A
we can supply to that web server and then it's passing in those user inputs through that web server then to underlying services or functions that the router is running. Uh and those are generally wrote in C or C++. And we're
433:17
Speaker A
able to either get some sort of buffer overflow or we're going to get command injection. And we can see that theme being just going over and over and over again. So when I see this, this gives me a heads up of, you know, major thing
433:29
Speaker A
that we should definitely be looking for and helping planning out our attack. Really quickly, I just want to show you two other resources here. So what I'll usually do if I find these CBS that are interesting is then I'll go and see uh
433:42
Speaker A
if there's a blog post or anything about it. One of the really cool things that I love about the cyber security community is how open people are with sharing information uh and passing on how they discovered things and their techniques.
433:54
Speaker A
And you can usually find blogs from the security researchers who found this that outline exactly how they found uh these vulnerabilities. So I've got two pulled up here. This one right here we're going to look at in more depth, but I just
434:06
Speaker A
want to quickly call it out as part of the recon. You know, all the credit to this trans men here who found this and he's wrote up about it. So we just scroll down um we can start to see a
434:14
Speaker A
whole bunch of descriptions and you can start seeing it talks about the vulnerability analysis block diagrams um you know even codes. So really really good details about how we found this.
434:24
Speaker A
And then I also found this one here again all this credit to this Gian Luca Paciella who found this. Um and if we scroll down we can see his assessment and again we're seeing code and he gives us details about you know how this
434:36
Speaker A
function works and how he's able to reverse engineer this. So, a lot of really great details about this. We're definitely going to look at these more in depth, but just wanted to call this out as part of the recon steps because
434:48
Speaker A
this is something that I usually look at when I'm doing recon and I would encourage you to do so as well. So, that wraps up this recon portion. Uh, in the next video, we're just going to do a
434:59
Speaker A
quick overview of the notes that I have so far and then we'll move on to hacking. So, I'll see you over in the next video.
435:08
Speaker A
Welcome everyone. In this video, we're going to be doing a review of the testing notes that I've taken so far during the recon phase of this course.
435:17
Speaker A
I've stressed a couple times about the importance of taking notes and that I will be adding our findings to my notes.
435:23
Speaker A
So, I wanted to give a chance for everyone to see those notes and this will also serve as a good review of all the things that we've taken a look at and discovered so far in our recon phase. If you want to see a copy of
435:36
Speaker A
these notes, they are available in the course GitHub. So, you can also get to them through that and they're in this testing notes folder called testing notes.md.
435:45
Speaker A
As I've mentioned before, I always like to include a few test details in my notes about the equipment that we're testing. So, you can see here I've started out with noting the manufacturer, the part number, and then also the serial number. If you're doing
435:59
Speaker A
this in a professional environment, then keeping track of the specific serial number is going to be important because there might be multiples of the device around at hand and you want to keep track of exactly which one you're
436:11
Speaker A
performing your testing on. I also like to keep a note of the test equipment that was used. Uh for this course, I think it's sufficient just to list out what equipment was being used. But in a professional environment, you may also
436:23
Speaker A
need to keep some details about the actual serial number of that equipment because it's possible that there's calibration data or other testing data that's tied to that equipment to certify that it's okay to use for the testing.
436:36
Speaker A
So, we use that multimeter and I've just listed the manufacturer and part number. Same with the logic analyzer. And I've also taken a note of the software that we used.
436:47
Speaker A
In the initial recon, we started with our visual inspection. We took a look at the router and also the internal PCB on the outside of the router. The one piece of information that stuck out was the FCC ID. So, I copied that ID down and
437:02
Speaker A
I've also added a quick picture of it to my notes. After that, we opened up the router case, and we did so by removing those two Phillips screwdrivers and then snapping open the pressure fit container with the spudger tool. I snapped a quick
437:17
Speaker A
picture of the internals of the router for future reference. I also noted that we saw three chips of interest on the PCB for further inspection, and I've denoted those as A, B, and C on this picture.
437:33
Speaker A
After that, we moved on to the onboard testing. We noted the presence of a test connection that appears to be a UR connection. We based this off the fact that it had four pins and they were labeled with BCC, ground, RX, and TX.
437:45
Speaker A
And this is shown in detail D here. We then verified the operating voltage of the PCB at 9 volts. And we did this by testing the voltage drop across the input jack with the multimeter. We then identified a ground connection on P1,
438:01
Speaker A
which is DTLE here. And we did so by using our multimeter to test the continuity between P1 and the ground on the jack.
438:10
Speaker A
We then moved on to testing the suspected UR connection with the multimeter. We did so so we could verify that the pins match the silk screen and they behaved in a way that we would expect UART to. First, we measured the
438:23
Speaker A
VCC voltage, and we found that to be 3.3 volts, which confirmed the operating voltage of the UART at 3.3 volts, which is really important for us to know for our future testing and the equipment that we're going to use to do so. We
438:36
Speaker A
then verified the ground connection by checking the continuity between the ground pin on the UART, and the continuity test confirmed that that ground is actually in fact a ground. We tested the RX or receive pin by measuring the voltage drop between RX
438:51
Speaker A
and ground was 0 volts just to check that this also wasn't grounded. We did a continuity test between that pin and the ground and there was no continuity which confirmed that it was actually at 0 volts. We then measured the voltage on
439:04
Speaker A
the transmit pin and during standard operation we saw it was approximately 3.3 volts which was to be expected.
439:12
Speaker A
After confirming that pin out and based on the observations of the pins, we suspected that this actually was a York connection, we then checked for an output on that transmission pin during bootup by power cycling the router and
439:24
Speaker A
then measuring the voltage drop over the TX pin during that bootup. I noted a fluctuation on that pin from approximately 1 volt to approximately 3 volts, which suggested a busy and active transmission during bootup. We then soldered our throughhole inline header
439:40
Speaker A
pins to the suspected UR connection which is showing up in this picture here. So you may have soldered them yourself or you may have gone with that twist tie method. Either one is fine. I just kept a note of that. We then
439:54
Speaker A
attached our logic analyzer to the transmit and ground pins of the UART connection and we captured that transmission during bootup. Here I've taken a screenshot of a single frame.
440:05
Speaker A
When we manually inspected the framing of that signal, this confirmed a UART transmission and we noted the start bit, eight data bits, one stop bit, and no par bits. We also measured the baud rate as 125,000. So you remember we measured
440:20
Speaker A
it here or we could calculate it as one over this timing. We then looked up the common baud rates and determined that based on those standard serial baud rates, we suspect that the baud rate for this router is actually 115,200.
440:37
Speaker A
Based on these findings, we then applied a UR decoder to the channel and we used the below settings. So again, that's this baud rate 115,200 data bits 8 par none stop bits one. Just a heads up, you may commonly see this
440:52
Speaker A
referred to as 8 none for how this is set up. It's just very common to, you know, give the UART connection details or serial connection details as baud rate data bits parody and then stop bits, but they won't actually say what
441:09
Speaker A
those are. You would just see it written as 115,200, 8 none 1. Of course, we then decoded that UART signal and we confirmed those UART parameters were correct because we actually got text back in ASKI characters and this showed the presence
441:25
Speaker A
of a bootloadader and boot up logs and we're going to investigate those further. Great finding for us to see these. After that, we moved into our OSEN and online recon. We use that previously located FCC ID to find the
441:40
Speaker A
FCC equipment authorization filing for the router. So, I just linked it here. I think it's always good, and I've done this myself, to download all of the PDFs and everything just in case somehow they go offline or something like that. It's
441:53
Speaker A
good to keep a record of the PDFs, which is something that I have done as well.
441:58
Speaker A
Of course, we noted in that filing that the ID has changed from this previous TE7 and then the part number. I just got a screenshot of that document. So, we then looked in the previous filing and we found those internal photos of the
442:10
Speaker A
router. Unfortunately, the schematics, functional description, and block diagram were redacted as confidential. We got these nice pictures of the internals of the router, including these two that showed a very closeup picture of the some of the chips in question,
442:25
Speaker A
and we were able to pull the manufacturer and part number off of those. Unfortunately, the markers on chip C were not readable in the FCC picture.
442:35
Speaker A
So, we returned back to our test router and we took some highresolution pictures and we were able to blow up those pictures to ID the chip and we IDed it as this Cion QH32B 104 HIPP.
442:50
Speaker A
We then went ahead and looked for the data sheets for the each of the chips.
442:54
Speaker A
So, I've got some notes about the first one, the MediaTek. We noted that it was a system on chip which is commonly referred to as an SOC and this contained the CPU or the processor. Some of the important details included that this is
443:06
Speaker A
a purpose-built SOC for N300 routers and the CPU is this MIPS 24 KEC. We also know the support of these two Linux kernels and also that it interfaces with the flash memory via SPI. Of course, there was lots more important details in
443:21
Speaker A
the data sheet. So, I've included a link here. I also downloaded this myself. We then checked this Zentel chip and noted that it is the RAM and we were able to locate the data sheet for it here.
443:33
Speaker A
Finally, we were able to ID this Sephon chip and the full part number for that is listed here. We noted that it is a flash ROM communicating via SPI and we got the whole data sheet here which importantly contains that SPI
443:46
Speaker A
information and the pin out. Next, we did a search for the firmware that we suspected we would be loaded onto this ROM and we were able to find it on the official support page for the router which I've linked here and I also saved
443:58
Speaker A
a download of that. The next thing we moved on to was the initial network recon. We connected our test computer to the network uh and we found the router IP address as this 192.168.0.1.
444:12
Speaker A
We then performed end mapap scans for both TCP and UDP. Got a screenshot of the TCP scan here.
444:21
Speaker A
We found there was the three ports open. the port 22 which is SSH running the drop air and the version that port 80 was HTTP and we noted that it is hosting the router's configuration web portal and then we also found port 1900 which
444:35
Speaker A
has the UPN and a little bit of versioning for it. One notable detail that we found was that this confirmed our suspicion that the router is running this Linux kernel 2.6.36.
444:47
Speaker A
We also did a UDP scan and we revealed two ports on it. this port 67 which is the DHCPS and the UDP port of this UPN.
444:58
Speaker A
We then wrapped up by doing some scouting on previously disclosed CVEEs. And you may recall in those previously disclosed CVEes, we noted that there was a common theme of a lack of proper user input validation on forms and inputs in
445:11
Speaker A
the web portal that led to either buffer overflow or command injection of an underlying function or service being called. I then put a link to this list on Open CVE of all the CVEEs and the two blogs that we found about the
445:25
Speaker A
interesting CVEes. That wraps up all the notes that I've taken. If you took different things or more details, then good on you. I would say the more details the better for these notes.
445:34
Speaker A
We're definitely going to be relying on these notes and coming back to them frequently throughout the rest of the course. That wraps up this video and also the recon portion of the course.
445:43
Speaker A
I'll see you over in the next one. Hey there. I hope you're enjoying the course. We'll get back to it really quickly. But before we do, I wanted to call out again to just make sure you are subscribed both to my YouTube channel,
445:57
Speaker A
which I'll link down below, and also to the TCM Security YouTube channel, this one that you're watching the video on.
446:04
Speaker A
So, I would really appreciate it if you just take a second and check, make sure you're subscribed, and if not, hit that subscribe button for us. Thank you.
446:12
Speaker A
Welcome everyone. So in the last section of the course, we performed our recon and because of our thorough investigation and testing. We identified this UART connection here where we were able to verify the voltage of it, we checked to make sure all of the pins are
446:29
Speaker A
as they are labeled. And we were also able to identify during bootup that there was a transmission of the bootup logs and potentially other logs coming off of the TX pin on the UART. We also confirmed the baud rate of the UART and
446:45
Speaker A
all of the framing parameters. So, we already know those. We also were able to determine that this router is running a version of Linux. And because of this, it's likely that this UR connection is also listening on its receive pin for
447:01
Speaker A
commands and we may be able to get some sort of remote shell connection through the UART. I mentioned that looking at those bootup logs through the logic analyzer is not the best way for us to interact with that and do this. And in
447:16
Speaker A
this lesson, we're going to take a look at how we can connect this USB to serial adapter that we have to the UR connection and then connect it to our laptop and actually be able to get a terminal session and a remote shell into
447:32
Speaker A
our router. So, hooking this up is pretty straightforward, especially since we already have confirmed out these pins.
447:40
Speaker A
Just one quick reminder for the hookup that the ground of course is going to go to the ground. So, those two match up.
447:47
Speaker A
We do not need to use the VCC on either the USB to serial adapter or the router because they're both going to get power from their own power supplies. Of course, the router through the jack and the USB through this USB portion. Then
448:03
Speaker A
of course we're going to need to cross the transmit and receive wires. So the transmit from this USB to serial adapter is of course going to go to the receiving pin on the router. And the receiving pin of the USB to serial
448:18
Speaker A
adapter is going to go to the transmit pin which is this top one here on the router. It comes with this female to female jumper cable to assist in this connection. So that's one of the reasons why we have soldered on or connected
448:32
Speaker A
with the zip tie this header pin to make it easier to facilitate that connection.
448:37
Speaker A
So I'm going to connect mine right now. Just keep in mind your colors may be different. So you might end up having to use different colors. Uh the the color ultimately does not matter that you use just so long as you remember to
448:49
Speaker A
correctly set the pin outs. Okay. So on my board, I have chose to use brown for the ground. I'm using red for the RX pin on the router and orange for the TX pin on the router. So I'm
449:09
Speaker A
just going to connect those now to the USB to serial adapter here. I'm going to start with the ground, which is the brown one.
449:20
Speaker A
And then I suggest you don't leave the middle one, which is the receive one, to the last. So, I'm going to do that next because it is hard uh to connect those afterwards if you are trying to connect
449:30
Speaker A
it in the middle. So, the receive on this, of course, is going to be the transmit from the router, which is this orange cable here.
449:42
Speaker A
Perfect. And now I'm just going to connect the red one, which is the receiving pin on the uh router, to the transmit pin here on the adapter.
450:06
Speaker A
Okay, so that is how to connect those before you plug this into your laptop, which is what I'm going to do next. I do strongly suggest that you double check these pin outs. Make sure they're okay because we of course are going to be
450:18
Speaker A
plugging this into our laptop. We don't want to cause any damage to that. And we've already tested this on our board and we know it's 3.3 volts. But if you're doing this for any other devices, I strongly strongly suggest you check
450:30
Speaker A
the voltage because the last thing you want to do is hook this up to a higher voltage and then have it damage the internals of your computer. So I'm going to swap over to my computer, plug this in, and we'll leave the router unplugged
450:42
Speaker A
for the time being. So just keep that in mind. I'll see you over at the computer.
450:46
Speaker A
Okay, so I'm just over on my laptop here and I've got my USB to serial adapter plugged into the laptop. I'm just going to do a quick LS USB here to list out my USB devices on the Cali VM. And notice
451:00
Speaker A
here that I do not have um that USB to serial adapter in any of these. So what that means is I need to connect it to my VM. Uh if you're using a VM, you're going to have to do something similar. I
451:12
Speaker A
am on VMware Workstation Pro again. So the steps for that is to go up to here VM removable devices and it is this silicon CP2102 USB to UART bridge controller and I'm going to go connect here which disconnects it from the host which is
451:27
Speaker A
what we want and click okay. If you are using VMware Workstation Player the free one it's the same step and then it's very similar uh in Virtual Box as well. So, if you're not familiar with how Linux handles um devices that
451:44
Speaker A
get plugged in, everything in Linux is either a file or a folder. Um if you just like boil it down to its most basic essence. So, it's no different for devices that get plugged in. Um and they go in the /dev folder. In order for us
451:59
Speaker A
to interact with this device through the terminal, we're going to have to figure out the name of that device file. So to do that we can run this command is ls-l and it's going to be we're looking in
452:10
Speaker A
the dev folder and we're looking for the serial devices and then we can go buy id here. If we run this perfect so we get this list here and we can verify on the left it is this USB silicone lab
452:24
Speaker A
cp2102 USB to bridge controller that we suspected. Uh, and then more importantly here we see that it is this TTY USB1 which is the device name and that's going to be in that slashdev folder.
452:39
Speaker A
So we're going to use a tool called screen to connect to that. So I'll just open up the man page quickly here for screen and just really quickly read it. You can see it is a screen manager with terminal
452:52
Speaker A
emulation. uh and we can get a full screen window manager that multipplexes a physical terminal between several processes typically interactive shells.
453:00
Speaker A
So this is perfect what for what exactly what we need it and we can use it to manage that uh terminal interactive shell between the serial adapter and our laptop. So I'm just going to hit Q here to get out of here. So depending on the
453:15
Speaker A
permissions of the user you're using and how you have your uh root folder permissions set up, you may need to use pseudo to get screen to properly access that device. So I'm going to use pseudo because I'm not logged in as root here
453:26
Speaker A
and I don't give this user um permissions to that root folder. And then I'm just going to run the screen command. Then the next thing we need to do is tell it what device we want to use. So it is at TT1 USB1.
453:42
Speaker A
Make sure to not forget the capitals in Linux. And the only other parameter we need to pass is the baud rate. The reason we don't actually need any of those um other framing parameters is that we are just using the default ones
453:54
Speaker A
on the router. And that is the eight data bits. Uh no par bit and one stop bit. So by default screen will also use those which is nice. So we just need to put the speed in here. But what I want
454:03
Speaker A
to do is to just really quickly show you what happens if we have the wrong speed and what that looks like. So I'm just going to put in 9600 here. another very common baud rate. And then I'm going to
454:13
Speaker A
hit enter. All right, we see nothing here. And that is because I have the router powered off. So what I'm going to do right now is I'm just going to power on the router. So I'm going to plug it
454:22
Speaker A
in. All right. And it's plugged in. And perfect. We start to see um all this garbled messaging here uh that can't be translated. And the reason I wanted to show you this is if you're starting to connect, you know, through serial to a
454:39
Speaker A
bunch of devices, you're eventually going to start seeing something like this. And what this means is that you have some of your serial parameters wrong. So either it's not using that standard of the eight data bits, the no
454:51
Speaker A
par and the one stop bit. So something's wrong in your framing or what's most likely is you have your baud rates wrong and then it's not able to translate that to those asy characters. So what I'm going to do here is I'm going to quit
455:04
Speaker A
out of this. Now you'll notice in screen um you know it's kind of taken over our terminal. So in order to get out of this you can hold controll and a in screen and then you can input other characters
455:15
Speaker A
that will do other things. So one of them is D which is to detach. So if I hold control and A and then hit D it's going to detach from us there. So luckily for us we actually know the
455:25
Speaker A
proper baud rate of this. So I'm going to put that in here and we'll just run the screen cannon again. So pseudo screen and then it is at /dev/tyusb1 for me and we know the speed is 115 2000
455:40
Speaker A
0. Uh and I'm just going to unplug my router here quickly so that we can see the whole boot log when it comes in. Uh so we'll just launch that up. Perfect. And now I'm going to plug the router back in and we
455:53
Speaker A
should be able to see in proper ASI the boot log booting up here. Okay, perfect. So, I'm starting to see um all of this messaging coming through.
456:12
Speaker A
Some really good details in here that we're going to look at in further, but for the time being, I'm just going to let this all scroll through here.
456:25
Speaker A
Okay, so here we see some messages that are just coming through. And if you get past this where it's setting um the drop bear SSH key and some details about that, going to start to see just some of
456:36
Speaker A
the same logs coming over. And what that shows us is that we pass that boot log.
456:41
Speaker A
We've handed over um to the Linux kernel and now we're just getting these regular log messages that we'll see out. Um but we should still be able to get a shell here. So if you hit enter and you're
456:53
Speaker A
going to come up with a shell. So what I'm going to do is I'm just going to quickly try uh who am I and you'll see here I get that who am I not found. So a couple things there that
457:03
Speaker A
happened that I just want to quickly show. Um you'll see like when I was messaging we got another log that came through. Um so like kind of like up here it kind of just kicked me out of the
457:13
Speaker A
shell for a second but since we're in this terminal emulator uh I could just hit the I and then enter. Um, and we do then see that we have this who am I is not found. So, first thing a lot of
457:24
Speaker A
people probably do when they get a shell, myself included, is check this who am I. Well, in these uh embedded systems with Linux running, size is a really big factor. So, they won't include um any of the binaries that
457:38
Speaker A
we're are used to using if they're not absolutely needed and we don't have who am I. So, if we just want to quickly run something though and we hit enter, we can go ls and list it out. So we can see
457:48
Speaker A
here that we are in the root file system there. Now it may be tempting to go through and enumerate this whole device and do your um you know standard Linux enumeration, but since we're on a hardware system here, our goals are
458:02
Speaker A
going to be a little bit different and we should also probably take a look at the bootloader. So, what I'm going to do is I'm going to pause this video here since it's getting long. And then in the
458:10
Speaker A
next one, we will take a look at how we can read through that boot loader and any important information that is in there before we actually move on um to enumerating through the shell connection. So, if you're going to keep
458:22
Speaker A
following along, just leave everything hooked up as it is. I'm just going to pause the video here and I will join you over in the next one. Welcome everyone.
458:30
Speaker A
So, I just got a little interrupted there in the recording, but I'm here on the next day. And in this video, we are going to pick up where we left off with our shell connection through the UART to
458:42
Speaker A
our router. And in this video, we're going to take a look at some of those uh outputs and logging during the bootup.
458:48
Speaker A
And we're also going to learn about how the bootloader works. So, the first thing we're going to want to do is actually scroll up and take a look at what was going on uh during that boot up. And you'll notice if you're using
459:01
Speaker A
screen and you left off where we did last time that there's no way to actually uh scroll up. And if I hit up arrow or page up, it doesn't actually do anything. So in order to access the buffer and be able to go back and look
459:16
Speaker A
at those previous logs, we have to again hit the control A and then while holding control A, it is the left uh square bracket or left squiggly bracket. And if you hit all three of those, it will go
459:28
Speaker A
into copy mode. And then I can scroll up. So what I'm going to do here is I'm just going to page up to the very top of where we started recording.
459:38
Speaker A
Perfect. And yours should start with the same um set of what I believe are memory addresses. And then it gives us du setting cal done.
459:47
Speaker A
So the very first thing that we see here actually is this uboot version. Uboot 1.1.3.
459:55
Speaker A
And then it gives a uh date of when this is released. And then we get a little bit uh of information about what's going on with this bootloader. So Uboot stands for universal bootloadader. It is a very common bootloadader, open source
460:12
Speaker A
bootloader that's used uh in embedded systems. And before we go any further actually with reading these boot logs, I think it makes a little bit of sense if we just chat at a high level about what happens during the boot up of an
460:26
Speaker A
embedded Linux system. So I'm just going to hop over to the whiteboard quickly and we will take a look at that.
460:34
Speaker A
So at a high level, I'm just going to list out that boot sequence. Now, generally the very first thing that's going to be happened is that the CPU is going to run um what some people call the ROM code or it's also referred
460:54
Speaker A
to as the primary program loader. So, I'm just going to call it the primary program loader in our example today.
461:10
Speaker A
And over here, I'm just going to draw out a little bit of the architecture of our system.
461:17
Speaker A
So, we'll start since we're talking about right now with the CPU. Now, you may remember in the CPU I mentioned that generally if it's not a microcontroller, it's just a processor, then it's not really going to have any
461:31
Speaker A
built-in RAM and ROM. Well, that's not entirely true. there's going to be a very small um amount of RAM and read only memory inside the CPU.
461:42
Speaker A
It's not really going to be meaningful for us to you know run much code or anything like that. But what it can do is it can actually hold this primary program loader.
461:54
Speaker A
And this primary program loader this is generally um like already loaded on the CPU and it's written by the CPU manufacturer. So, it's not something we necessarily need to worry about. When the CPU initializes, it's going to have
462:07
Speaker A
the instructions to just jump to the code that's in that primary program loader, and it's going to execute that.
462:14
Speaker A
And what the primary program loader is going to do is it's going to actually then look for what's called the secondary program loader. So, I will just add that to our list here.
462:37
Speaker A
And the secondary program loader is generally then going to live on. We talked about this other component of the ROM.
462:48
Speaker A
And that ROM is generally going to be partitioned up into a few different partitions. So usually it's going to be more than three, but we'll just put three here.
462:59
Speaker A
And in our case and for most embedded Linux systems, that secondary program loader is going to be Uboot, which is what we saw in our bootup screen. So I'll just put a U here for Uboot. So, what that primary program
463:14
Speaker A
loader is going to do is it's just going to um go and then it's going to launch Uboot, which is going to then copy itself over to the RAM.
463:30
Speaker A
So, we've got our third component here of the RAM. And now Uboot I've put it as this drop down here and not just called it the secondary program loader because it can run either in one stage or two stages.
463:48
Speaker A
So if we have just a first stage then all its responsibility is going to be is just to um initialize itself and then it's going to bring over uh again the second stage of Uboot.
464:11
Speaker A
And then that second stage of Uboot is then going to perform that bootup process of loading up the Linux kernel and doing whatever needs to be done to help that Linux kernel get started and then hand over control to that Linux
464:28
Speaker A
kernel. So we've got our Linux kernel here. So I'll just put K here. And that Uboot is going to, you know, load up that Linux kernel, put everything into the memory that needs to be there for it to set itself up. And
464:49
Speaker A
then it will hand over control to that Linux kernel. And then generally what that Linux kernel is going to do is it's going to um unpack the root file system. So I'll call that as RFS and we'll put that as our other
465:05
Speaker A
little chunk here on our ROM. And it's going to run some sort of initialization script. So we'll just call this init.
465:16
Speaker A
So, now that we've got an idea of how this boot sequence works at a really high level, let's hop back over to the terminal so we can make sense of what some of those uh output logs mean and
465:26
Speaker A
what we're seeing taking place there. Back over at the terminal now, hopefully with that quick overview of the embedded system boot process, some of these log messages are going to make more sense to us. So, we left off looking at this
465:41
Speaker A
Uboot 1.1.3. Again, Uboot, this stands for the full name of it is DOSS, universal bootloader. It's that open-source bootloadader, and it's very commonly used as the SPL or secondary program loader in embedded systems. So, when I was very first looking at this message,
465:59
Speaker A
I was thinking that we possibly had a two-stage uh bootloadader here. And really, it doesn't matter if it's one or two stage, it's not going to affect us.
466:07
Speaker A
But um just a reminder that of course, we are doing reverse engineering and there isn't any official documentation on this. So sometimes we just have to make our best guesses at what we're seeing. But what I think we're actually
466:18
Speaker A
seeing here is this RA link versioning that we see below here. RA link Uboot version 4.3.0.0.
466:26
Speaker A
Well, RA link they're a manufacturer of CPUs and chips. They actually got bought by MediaTek and then MediaTek just uh you know absorbed them and they absorbed their software and hardware. Again, just a reminder, the MediaTek is the SoC that
466:42
Speaker A
has the CPU that we are working with on our router. So, I believe what they've done here is, you know, they're just using this Uboot version 1.13, the open source one. They forked that, you know, copied it over, modified it to meet
466:55
Speaker A
their needs, and then they've added this versioning message in um so they can keep track of it, you know, their internal versioning of it.
467:04
Speaker A
If we look down past that message, we get a little bit of information about the board here. And we see, of course, again, that is that SPI flash. And if we scroll down a little bit further here, we see that, you know, it's choosing
467:16
Speaker A
option three here to system boot via the flash. And then we get the address. And this is a hex address of hex 10,000. So off of that flash ROM, we're going to boot off of that address. Now, later on
467:28
Speaker A
in this lesson, we're going to look here. Um, you see here like we just have no line and what it's actually doing is waiting for a quick interrupt there. But since it doesn't see that interrupt, it just boots to the default which is this
467:41
Speaker A
three. So we will look at if how we can interrupt that and potentially choose a different option here. Again, we get that message that we're booting the image from that address. It we're uncompressing the kernel at that point.
467:53
Speaker A
And then we just actually transfer control over to Linux and we give Linux its memory and we get this message starting kernel. So at that point, we're actually just starting the Linux kernel and we've handed over control to the
468:04
Speaker A
Linux. And then the rest of the logs that we see moving forward are actually going to be from that Linux kernel. So if we scroll down a little bit here, there's a few things that we should take note of. Of course, if we didn't already
468:15
Speaker A
know, we see the Linux version there, and we can also see um the date, and we also see how it was built with this build route. So this is a common open- source tool for um building Linux kernels. So we should keep that in mind.
468:28
Speaker A
it is with this build route if we didn't know already the CPU architecture we do they see there it is that MIPS and we see even more um about that MIPS detailing scrolling down a little bit here I just
468:43
Speaker A
want to show the very first thing that I see here that sticks out to me is we have this root fs type is squash fs so we have um our root file system it is squash fs which is a common readonly uh
468:58
Speaker A
file file system that's used in embedded Linux. So, good to keep note. That's the first thing here. I'm going to enter into my notes.
469:06
Speaker A
Scrolling down a little bit here. If I scroll just a little bit further to get down, see again about that squash FS is if I just scroll here, the next section that I'm seeing that sticks out to me
469:17
Speaker A
that I'm definitely going to keep in my notes and take a screenshot of is um all of this information here. And we see here it is creating these five partitions. uh and we see the actual partitions of them. So of course the
469:29
Speaker A
first one is that boot so where that Uboot is stored and then of course we see this kernel here and unsurprisingly it is at that hex location that we saw before. So from this uh 10,000 in hex all the way up to this 100,000x. Then we
469:43
Speaker A
see here the location of the root file system. So definitely something nice to see cuz we're going to want to get this later so we can investigate it. Uh and then we see two other partitions here.
469:52
Speaker A
one for config, which of course we would probably want to get our hands on. Uh, and then this radio one. I'm going to keep scrolling down because there is some other really good information to see here. The next one that I see is
470:03
Speaker A
this starting P29. And we get this / etsy/nit.d/rcs, which this to me looks like an initialization script that's going to be uh setting up other things on the kernel. So definitely something to keep note at. we're going to want to get our
470:19
Speaker A
hands on this and take a look uh at what's going on in there. And then also good to keep track of what's uh running at startup because if we ever wanted to modify this ROM and then either have a
470:30
Speaker A
back door or something like that happen, well, this is something we can modify then to call for example our back door.
470:36
Speaker A
Another thing that sticks out to me here is I see this um Etsy/reduced_datamod.xml. So I see XML files. To me, this looks like also some sort of configuration file. So that might be something that we want to get our hands on and take a look
470:49
Speaker A
at. We're then going to see a lot of information here about the router setting itself up. So we'll see things like DNS and DHCP and setting up all of the if config. Uh and we're just going to skip over those. Again, if you want
471:03
Speaker A
to take a look in more detail, I encourage you to. But we're going to skip over most of those messages. Uh and I'll just show kind of the next thing that I see that's really important here.
471:13
Speaker A
Again, we're just seeing about setting up the all of the wireless and the routing and the IP tables and everything like that. See some config files here that may be of interest.
471:27
Speaker A
And actually, the one that I'm looking for that I saw that I was interest of me is if I scroll all the way down to where we left off here. Yeah. So, we get into where we left off with the drop bear.
471:36
Speaker A
So, of course, this may be of interest to us here. we see this um prepared drop bear and of course we know that the drop bear is the uh SSH that's running on here. But what sticks out to me is we
471:47
Speaker A
are writing out this RSA key uh and we're writing it out to this location.
471:53
Speaker A
And that's signifying to me that you know var/temp or most likely just this /var folder is writable. So if we want to have somewhere where we're going to copy over tools and write them onto this while it's running, well this is a
472:06
Speaker A
location that it's actually writable. So we can do that. So we got a lot of really good details out of this boot log that I'm definitely going to add to our notes and it's going to uh help us when
472:16
Speaker A
we are further enumerating this system and also when we are reverse engineering the firmware. So what I'm going to do here is I'm going to hit escape to actually drop out of this copy mode and we can are back at just you can see
472:28
Speaker A
we've gotten all these messages that are coming in just in standard operation. So the last thing that I want to show here is that sometimes you can actually interrupt uh the bootloader and you can get into a little bit of a shell that
472:40
Speaker A
allows you to have some options to either you know load a different flash or maybe even dump the flash which can be useful to us as hackers. And in order to do that, we're going to have to hit
472:52
Speaker A
uh a set command kind of similar to how you would interrupt your BIOS. And that command is generally varies depending on the manufacturer. So on TPLink devices, the command is just TPL. So just as basic as the characters TPL,
473:06
Speaker A
but you have to be really quick to do it. And we're going to have to do it right when it's, you know, loading up that um Uboot. There's like a millisecond almost delay where you can hit it in and then it just moves on to
473:17
Speaker A
the next one. And if you're going to be unplugging your router and then replplugging it in, it's almost impossible to get your hands back to the keyboard in time. So, what we can do is there's actually a reboot command that
473:29
Speaker A
we can run. So, if I just drop back into the shell, and what's going to happen here is this is going to happen really fast. So, I just want to let you know ahead of time. So, I'm going to type
473:37
Speaker A
reboot, hit enter, and it's going to reboot, and then I'm going to immediately start mashing TPL over and over again. Uh, and and hopefully I'll get it on the first time. Sometimes it takes a couple tries, but that should
473:47
Speaker A
drop us then into the bootloader menu. So, I don't know if you can hear it, but I'm already smashing there. And I was able to get it the first time.
474:01
Speaker A
So, unfortunately, when they have gone and modified this version of Uboot, they have really stripped down this command line interface. And I don't know if that's for security reasons or just to reduce size. But see, even if you go
474:11
Speaker A
help, for example, well, unknown command help, try help. So, there's not much that we can do in here. But if we do pull up really quickly, and I'll just show you, we look up Uboot command line interface.
474:32
Speaker A
So, just going to take a look at their GitHub here and scroll down to the readme. So I'm just going to do a quicktrlf for commands.
474:44
Speaker A
So there we go. We get a list of commands here. And what you can do sometimes from the regular Uboot is we can actually um you know display and read the memory and write from the memory. So if we weren't able to um get
474:55
Speaker A
the firmware through other methods, but we did have this UART shell. Well, if we weren't in this locked down version of Uboot, then sometimes we can actually dump the memory from here, read the memory, and also write to it. The only
475:07
Speaker A
command that we're going to have access to, and I've tried um most of them, is this TFTP boot. And what this allows us to do, and the reason that it's here, is for recovery. If we were to, you know,
475:17
Speaker A
brick our device, and we can still get into the bootloader, then we can set up a trivial file transfer protocol, and we can put an image there for it to boot from and it will boot from that over
475:27
Speaker A
TFTP. So, if we go back to our terminal here, we can run this TFTP boot. you'll see it's going to boot and it's going to actually try uh and run.
475:40
Speaker A
So, it didn't actually find it and it's just doing so it's just booting up the regular method. So, we're now back at that same spot we left off before and I think this is a good spot to end this
475:49
Speaker A
video. We'll pick up in the next one where we will use our Linux shell here to further enumerate this device. I'll see you over in the next video.
475:59
Speaker A
Welcome everyone. In this video, we're going to begin enumerating our router using that UART shell that we located a couple lessons back. Later on in this video, we will need our VM connected to the same network as the router. So, I'm
476:14
Speaker A
just going to run a double check right now and make sure I'm still on that same network. Perfect. And I'm seeing I've got an IP address on that network that the router hosts. If you do not have this, then go back and change your VM
476:27
Speaker A
properties from that to the bridge mode and make sure you are bridging to the network adapter on your computer that you're connecting to the router.
476:37
Speaker A
Lastly, I'm just going to run a very quick check here and make sure that that device file name hasn't changed. So, remember the command for that is ls-l serial by-.
476:49
Speaker A
All right. And mine is still that tty USB1. I have restarted my VM uh since last time I did this. So, always good to just check because this can change. So, I think now we are ready to get that
477:00
Speaker A
terminal session going. So, I'm going to go use screen again and we'll connect again to that same device here. And the baud rate is at 1152000.
477:13
Speaker A
I already have my router started up there, so we didn't see any of those startup logs, but I do have my shell connection. So, you'll probably remember from the first time we got this shell, I tried to run that who am I command,
477:25
Speaker A
which we can try and run again. And of course, we see here we get this who am I um not found. And this is to be expected on embedded Linux systems and something that we're going to frequently have to
477:38
Speaker A
deal with. And and that's not specifically that we won't have who am I, but it's actually that we're not going to have a lot of the tools and binaries that we're used to having in normal Linux systems. And the reason for
477:51
Speaker A
this is that space and memory are really at a premium on these embedded systems.
477:56
Speaker A
They try and reduce them as much as possible to save on costs and for many other reasons.
478:03
Speaker A
So, one of the things that I like to do first when I get a shell on these systems is actually just to go and take a look at what we do have access to. So, similar to standard Linux, the first
478:14
Speaker A
place we should take a look is in the bin folder. So, I'm just going to go over there right now. And if we just list this out here, going to go into copy mode here so we're not just keeping
478:24
Speaker A
scrolling. All right. So, I see a bunch of different commands here. And we see really limited. There's not that many.
478:32
Speaker A
Some that stick out to me here is we do have PS and we also have net stat. So those are good to see to use for enumeration. And then the last one here that I see that sticks out to me that
478:43
Speaker A
you may not be used to if you aren't using embedded Linux is this busy box.
478:47
Speaker A
So if we just get out of this copy mode here and we just run busy box so we can see its help message.
478:57
Speaker A
Very first thing we see here is we've got this busy box is a multi call binary that combines many common Unix utilities into a single executable and we have this list here of those functions that we can use. So busy box is used in
479:11
Speaker A
embedded Linux because what it does by making this multi call binary um is it really reduces the size of these functions and because of that you you'll see this very very commonly. You'll almost always see busy box on embedded
479:24
Speaker A
Linux. So, if you look down here, we actually see a bunch more different functions that we can call. And one of the ones that sticks out to me is we do have access to this trivial file transfer protocol. So, we can use this
479:37
Speaker A
both to bring files or things that we find on the router that are interesting over to our Linux VM so we can analyze them further with all the tools that we have. Or we can also bring tools over
479:50
Speaker A
from our Linux VM to the router using this. And that's really good to see.
479:56
Speaker A
The other thing that I'm seeing here just from my familiarization of using Bizzybox is that the standard Bizzy Box actually has a lot more functions um than this. And one thing that's missing for example here is we don't have
480:09
Speaker A
netcat. So what we can also do and we're going to be doing is we're going to bring over that full busy box onto this router so we can make use of all of those functions and it's going to make
480:21
Speaker A
our enumeration much easier. In order to make use of this TFTP, of course, we're going to need to host a TFTP server ourselves. Now, luckily, Cali already has one built in that we can make use of. So, I'm just going to
480:36
Speaker A
open up a new terminal window here. So, Calli's got built into it ATFPD. It's a mouthful to say, so I'm probably going to mess it up at least once or twice. Um, and just do a quick double check if you have it against that ATFPD
480:50
Speaker A
here. Uh, and if you're not seeing that you have it for whatever reason, you can get it through the apt repository. So, pseudoapp install.
481:06
Speaker A
So, I've already got it and it doesn't need to be upgraded. Um, but if you need to get it, you can get it through that method. The next thing we should do is just take a very quick look at the
481:15
Speaker A
config file for this. So it is in this / etsy default. So we don't need to change anything in here. But the one thing I just wanted to call attention to is we've got this / srv/tftp folder. And this is where we are going
481:37
Speaker A
to be um copying to or copying from files. So, this is the where we're going to need to either stage our files to copy them over or where we're going to um have our files from the client be
481:49
Speaker A
copied to. So, just something to keep in mind. I'm going to escape out of here.
481:55
Speaker A
Okay. So, in order for us to actually have this server be running though, we're going to need to start it. So, to do that, I'm going to go pseudo as atd is d-damon.
482:08
Speaker A
And it should be started now. So, what we're going to do is I'm going to hop back over to our UART shell here on the router.
482:16
Speaker A
Okay. So, the first thing we're going to do is we're just going to bring a file from the router over to our Kali Linux VM. And in order to do that, we should find something interesting that we may
482:26
Speaker A
want to analyze later. So, what I'm going to do is I'm in copy mode here.
482:30
Speaker A
So, I'm just going to get out of copy mode. And I think we should take a look at that Espin folder that we haven't looked at yet.
482:40
Speaker A
just going to head over there and we'll list out the files. So, one that sticks out to me immediately is this init binary that we may want to take a deeper look at and try and reverse engineer.
482:50
Speaker A
So, let's bring that over to our VM. Before we just get started banging out commands with TFTP though, one thing that I like to do in these UART shells is instead of trying to write them in the terminal, and you'll notice we get
483:04
Speaker A
interrupted sometimes and then it splits the lines and it makes it a little messy, is I'll just write out the command in a text editor and then I will copy and paste it over. So in my text editor here, I've just got the help
483:15
Speaker A
messaging from that TFTP to aid us in creating our command. And we see it's pretty basic. We just got these four options. -l for local file, -ash r to specify a remote file, and then either -ash g for get file, or -ashp for put
483:30
Speaker A
file. And we've got an example here of how to do a get. So, we're actually going to be doing a put. So, what I'm going to do is we'll just run tftp.
483:39
Speaker A
And it's already mapped on the router, so we don't need to use busy box. You could put busy box in front of it and it would run fine. Um, but they have mapped it so that we don't need to puty box
483:49
Speaker A
every time. And then we're going to be doing a local file-l. And then we're going to do this sbin slashnit.
483:58
Speaker A
And then we're doing a put of that. And we need to put the IP address then of our Kali Linux VM. So it's0 100 is the one that I had. Um, so this should be good to go. I'm going to copy
484:11
Speaker A
and paste this over into the terminal. get on my copy mode here. Uh, and we are in that spin. So, I'm just going to go up to the root here. And then if we run this here, I'm going to paste it with
484:29
Speaker A
control shiftv. Now, if we run this, so we're getting this TFTP server error access violation number two. So, generally when you'll see this, and I just want to show how to fix this in case this ever comes up with anyone,
484:47
Speaker A
um, is the first thing you should do is just double check the folder permissions in your server. So, if we go back over to the terminal here, our other terminal, um, and if I just do an ls-l, so you see in this TFTP, you should have
485:03
Speaker A
it so that it is, you know, 777's permissions for the folder. Uh so make sure you have read write for everyone here and then the owner of it should be nobody. What you can do is we can go
485:15
Speaker A
jamad and then 77 oops 777 and go dash r as well on that tftp.
485:26
Speaker A
I'm going need to be pseudo to do this. You probably will as well as well. Okay.
485:30
Speaker A
And then if we do this again actually and I'm going to go and change the ownership as well and we're going to change it to nobody. So, mine's already set, but we should also set that to nobody because that's how the TFTP user
485:43
Speaker A
generally runs on the client. Um, so I set mine as well. And then just double check here. LS-l, it's still the same.
485:51
Speaker A
So, make sure yours are set. Now, for us, this isn't going to fix that issue, but I just wanted to show it in case anyone doesn't have their setup like this. And then if we go back over into
486:01
Speaker A
our notepad, actually what I also recommend doing is usually just try and copy um like from the folder that you're in and don't use the full path. A lot easier and I have a lot more success with TFTP running it like this. So we'll
486:15
Speaker A
just copy this back over again here. Go back over to here. And if I just check where I am again.
486:24
Speaker A
Oops. Okay. So if we go into that spin. All right. Now if we copy and paste this in.
486:34
Speaker A
Perfect. It worked. So if we go back over to our other terminal there. And if we just do a cd into that tp check out what we got. We got that init.
486:46
Speaker A
And we can run the file command on it to make sure uh properly copied over and we are getting what we expected.
486:55
Speaker A
All right. And let me just bring this up a little bit here. Okay. So, we see here, of course, it is that executable 32bit least significant bit executable.
487:05
Speaker A
Keep that in mind. That's good information for us that we didn't already have. So, what that means is that this is um little Indian Mips. And we'll talk about that a little bit more what that means. And then, of course,
487:15
Speaker A
we're seeing that it's at MIPS 32bit. And this is exactly what we wanted to see for this. So, this video is getting a little long. I'm going to pause it here. Um, keep this open if you're going to go to the next video because what
487:27
Speaker A
we're going to do in the next one is we'll take a look at how to bring files or tools from our VM over to the router.
487:33
Speaker A
So, that wraps up this video. I'll see you over in the next one. Welcome everyone. In this video, we are going to take a look at how we can use TFTP to bring tools from our VM over to the
487:45
Speaker A
router that we can use. And we're going to start by bringing over the full version of BizzyBox so we can get access to even more binaries and functions. In order to do that, we're going to have to download the full version of BizzyBox to
487:59
Speaker A
our VM. So, that's just why I'm here at the VM settings with my VM powered off because we're going to have to switch it back to NAT so that we can get access to the internet and then we'll have to shut
488:09
Speaker A
it down and switch it back to bridge mode. So, I'm just going to do that right now.
488:14
Speaker A
Okay. Okay. So, we'll start with a quick Google search here to see if we can locate the BYBox uh download binary. So, I'm just going to search for busybox download.
488:26
Speaker A
Perfect. And it is through this busybox.net. And if we scroll down here, we can just get the binaries. Of course, you could always download the source and compile it yourself, but they already have the binaries here. And I remembered that the
488:39
Speaker A
version that we were working off was this 1.19. Um, so we could try and get a more up-to-date one, but I think just for ease of use and making sure that's going to work, we'll just grab that same
488:49
Speaker A
version, but this will be the full one with all of those functions. Okay, so we're granted here with this list of different binaries, and we're going to need to choose the one that is the correct architecture for our CPU, and
489:01
Speaker A
that is this busy box eel or sometimes referred to as MIPel. And this EL that stands for little Indian. And you'll remember that when we took a look at that binary that we copied over in the last lesson that it said it was that
489:16
Speaker A
least significant bit executable first. Well, that stands for little Indian. So, usually you don't necessarily have to worry about the Indianness anymore um because it's actually just set for different architectures. However, MIP is unique in that it can actually be
489:33
Speaker A
configured to be either little Indian or big Indian. So, we need to know the Indianness. And ours is this one right here. Um, so the easiest way to download these is actually I'm just going to go right here and I'm going to go copy
489:45
Speaker A
link. And then I'm going to switch over to the terminal here. And I'm going to switch over to that TFTP folder that we had set up before. And I'm just going to run a wget command so that we can
489:58
Speaker A
download that. I'm going to hit control shiftV to paste in that address. And this may take a second to download.
490:05
Speaker A
Perfect. So then if we just run an ls-l in here, we've got that busy box myip cell and the init file that we copied over. Okay. So now that we have it here, what I'm going to do is I'm just going
490:16
Speaker A
to shut off my VM, switch over to bridge mode, and then power it back on. So if you have to do the same thing, go ahead and do that now and I'll meet you back over here with your VM set to bridge
490:25
Speaker A
mode. Okay, I've restarted my VM here and I've set it back to that bridge mode. So just quick sanity check. Good to double check and make sure. seeing that I'm on that correct network that I want to be. Uh,
490:37
Speaker A
so I'm just going to connect back to that terminal session using screen. Perfect. And we've got a shell here. So the other thing I'm going to do now is I'm just going to open up another window here and we will launch up our TFTP
491:00
Speaker A
server. So the command for that is this pseudoatpd- damon. Perfect. And it's started up here. So if we go back to that other window, then we can now copy over from our VM to the router. The first thing we'll have to do
491:18
Speaker A
though now is we'll have to figure out a place where we can stash our tools and bring them over. So we did actually identify if we just take a look at the root file system here um that we had
491:31
Speaker A
this /var and we thought maybe this is writable or maybe just slashvar /temp is writable because we saw that there was scripts that were writing to that on startup and this is the case so we will be able to move it there but I just
491:45
Speaker A
wanted to show what will happen if we try and copy it to other locations and how we could figure this out if we didn't see that script. So let's just go over for example to um the binary folder. So we'll go to the bin folder
491:59
Speaker A
here. If we just list this out um we do see that we do have this chimod here. So the first thing I want to show is um let's just pick for example uh busy box.
492:08
Speaker A
Like let's say we didn't have the correct permissions on this. We wanted to change something about it. So what I'm going to do is I'm just going to go try and shimod 777 busy box.
492:19
Speaker A
And you see we can't even do that because this is a read only file system.
492:23
Speaker A
And same if we for example wanted to make dur and go test we're going to get that same issue um that this is a read only file system because we did see that most of this file system is that squash
492:33
Speaker A
fs which is a readonly file system. So what we can do is if we go back out here to uh our root and if we run the mount command and I'm just going to pause this so it doesn't keep scrolling. So, what
492:47
Speaker A
sticks out to me here is we're seeing that most of this is this type squash FS um which is read only. However, we do have and if you're not familiar with the file systems, there is this one RAM FS
492:58
Speaker A
down here and it's read write. And generally when you see this um on embedded Linux systems, this is going to be where we have files that are writable. This RAM fs file type is a writable file type. Um I know these
493:11
Speaker A
other ones say they are read writeable, but they're not actually going to be. If you try um and go to either proc or cis, you're going to get errors. But in this RAM FS, so in all of this /far folder,
493:22
Speaker A
um we will be writable. So what I'm going to do is I'm going to get out of this copy mode here. We'll go to that /far folder. It looks like there's already a temp here. So I think we'll
493:32
Speaker A
just use the temp one. We don't necessarily have to. Um but I'm just going to go there and let's list out what's in here. So we do already have some files in here. And this is just personally my own
493:43
Speaker A
convention um of what I like to do on these IoT devices just to make sure when we're doing our enumeration any reverse engineering or anything like that we don't get confused about things that we're bringing over. Um I'll create a
493:57
Speaker A
folder. I'll call it tools or something like that. But I always put an underscore in front of it just so that I know when I'm coming back that that's something that I created. So I'm going to do is I'm just going to make that
494:06
Speaker A
directory called underscore tools. and we'll cd into there. So, just like last time, I'll just write that command out in the notepad to make it a little bit easier for us. So, again, it's going to be TFTP. And we're actually going to
494:20
Speaker A
want a remote file. And it was that busy box-ipell is what it was called. And then we're going to do a - g forget. And of course, we need to put our IP address 192.168.0.
494:34
Speaker A
And mine was 100. Make sure to put whatever you have here. Uh, and this looks good. So, I'm going to copy this here. Copy it over here. Get our shell back. Paste it with control shiftb.
494:49
Speaker A
And this might take just a minute or two to copy. Perfect. So, then if we go uh ls, we should see that we have that busy box. Myip cell. And the last thing that we're going to need to do is just
494:59
Speaker A
remember to uh change our permissions so that we can run it. So, what I'm going to do is I'm just going to go mod 777 on that busy box myip cell. And we do have I should have mentioned this before, but we do
495:12
Speaker A
have tab complete in this, which is kind of nice. Um, so now if we do ls-l wait ls-l here, um, we can see that we are able to execute this. So now if we run this busy box, look at all I'm just going to pause this
495:29
Speaker A
so it's not going to keep scrolling on us, but look at all these extra um functions that we have. So now we're getting closer to what we would have um on a you know regular Linux distribution and this is going to make our
495:41
Speaker A
enumeration um of this machine or this device much easier. Uh so just some core ones that I want to call out. For example, here is you know we have find we even have I believe there's GP on here. Uh if I just look for the G's
495:56
Speaker A
here. Yeah we got GP. So lots of really useful tools that's going to make our lives a lot easier if we want to do enumeration on here. And one that sticks out to me is here we've got netcat. So
496:07
Speaker A
we can use this. Uh, and what I'm going to show right now before we pause this video is if you're not a fan of using this hardware shell uh and you'd rather do it over a different network shell,
496:16
Speaker A
well, we can just use this netcat here to get ourselves a reverse shell. So, that's what I'm going to do right now.
496:20
Speaker A
Let's switch over to our other terminal here. Uh, and I'm just going to set up a quick listener. So, netcat nvlp do it on 444 standard port. Uh, and then if we go back to our other terminal here, and I'm
496:34
Speaker A
going to do the same thing. I think it's makes sense just to write this one out since it's a little bit longer. So we're going to need to do call netcat through um this busy box. So any of the new
496:44
Speaker A
functions here, they're not going to be mapped. So we're going to have to actually call them like this through this busy box.
496:50
Speaker A
Uh and we are going to want to call netcat. And we're going to put the IP address 192.168.0.
497:02
Speaker A
That was port 444. We're go dash E and we're going to go slashbin sh.
497:13
Speaker A
Copy this over here. It's frozen. So generally a good sign. If we just switch back over here.
497:22
Speaker A
Perfect. So let's just see. Perfect. So we are in our netcat shell here. We can look at the present working directory and uh we can actually even run that.
497:33
Speaker A
who am I now if we want to because we have it through here and we are this admin which is the uh route on this router. Perfect. So the purpose of this video was just to demonstrate how we can use that TFTP to
497:49
Speaker A
bring over tools and how that's going to make it a lot easier for us in our enumeration and we're not as restricted in kind of the live off the land that we were stuck in before. It's really really
498:01
Speaker A
common to see TFTP on IoT devices, especially ones running embedded Linux because that functionality is baked into generally a lot of how they will do firmware updates or other um updates is to use that TFTP protocol. You even saw
498:17
Speaker A
how even our bootloader um had that functionality baked into it. So, it's really not that uncommon to find this on your various IoT devices, and we can make use of it as we did here to either bring stuff off or bring over tools to
498:30
Speaker A
use. That wraps up this lesson. I'll see you over in the next one where we use um some of our newfound functionality now to further enumerate this device.
498:41
Speaker A
Welcome everyone. In this video, we're going to be using our shell to hunt down for interesting files and passwords. I'm going to be using the UART shell through screen in this video, but you could also use the netcat one that we previously
498:56
Speaker A
established in the last lesson if you prefer. You may recall that I did previously mention, you know, you could go and try and do a full Linux style enumeration on this router, similar to what you would do um, you know, post initial
499:12
Speaker A
exploitation in a regular network pen test where you have access to a Linux computer. And there's nothing that's not valid about doing that. However, there are some differences on IoT devices that may make us want to consider how we
499:27
Speaker A
approach that and what we use our shell connection for. So to talk about that, I've actually just repulled up uh with this mount command the different file systems that we have on this router. So if you want to run this again, you can
499:41
Speaker A
run mount and it will show these as well. And you may recall that most of our file system is this type squash fs which is a readonly file system.
499:51
Speaker A
And this entire file system, it actually exists as part of the firmware for the router. So we can actually get to this through that firmware we downloaded. And then we can analyze this entirely on our local machine. And since we know it's
500:07
Speaker A
read only, well, there shouldn't be any differences on the live machine from what we have in our firmware. And it's going to be a lot easier to do any analysis on our VM or our local machine because of course we've got all the
500:21
Speaker A
tools that we would ever want and if we need more we can just very easily install them. And then also with IoT devices they're very limited in their processing power and RAM. So it can take a long time or we can even freeze them
500:34
Speaker A
or crash them if we're trying to run for example long graps or fines or things like that.
500:41
Speaker A
Now, we do have these other three different file systems here that we saw. And the one that we talked about and found where we could write to is this RAM FS. Well, if you're not familiar with Linux file systems, um this RAM FS
500:54
Speaker A
is exactly as it sounds. It lives entirely in the RAM. And what that means is that this is a temporary file system.
501:02
Speaker A
So, anything that gets written here while the router is running, well, it's all going to get lost when we reboot. So unfortunately that actually includes all of our tools and anything that we bring over and write to this folder. All the
501:16
Speaker A
contents and setup and everything in this folder. It's all created dynamically when the Linux kernel starts up during that initialization.
501:24
Speaker A
All those initialization functions and scripts they set up everything um in the RAM FS on this /bar folder and they do that by reading from various config files. So what this means for us is that um enumerating and taking a look through
501:39
Speaker A
this /far folder on the live machine can make our lives a lot easier because then we don't have to try and reverse engineer from this uh squash fs read only file system that we have locally and figure out you know what those
501:54
Speaker A
scripts do and how they specifically set up this /far folder. we can just take a look at a live one that we have on our router. And that's what we're going to be doing in this lesson. Just quickly,
502:06
Speaker A
in case you are curious about what these proc file types and folders are, we see you have type CISFS and type proc. Well, these are virtual file systems that are used by the operating system. Proc is for process and CIS is for system. And
502:22
Speaker A
and they're not standard file systems like you would think of with files and folders. These are virtual file systems that are used specifically by the system. So that's why we can't actually write or do anything with them and we're
502:34
Speaker A
not going to be specifically concerned about them in this lesson. What we're going to take a look at is enumerating this /bar folder. So I'm going to do is just head over to that bar folder now and we can start taking a look.
502:48
Speaker A
So cd /bar and what I'm going to do is just open up the notepad again. We'll start crafting our first command and that's going to be to use gp. So I'm going to actually run that busy box through the full path
503:00
Speaker A
because I don't want to just be in that tools uh directory to run this. So it says v. So that's var /temp. We put in underscore tools/busybox dashipell.
503:16
Speaker A
And then we're going to run grep and we're going to look for we're going to do it recursively to search through everything. And we'll start by looking just for the word pass.
503:26
Speaker A
I'll put a dot here. So any file. What this is saying is we'll search recursively through every folder and we'll look at every file uh and if it has the word pass then we'll take a look for a hit and see that line. You could
503:38
Speaker A
use pass or password or you know anything of those pass WD any of those abbreviations. I'm just going to use pass because the nice thing with IoT devices is there's not as many files and things like that as you would um on a
503:52
Speaker A
standard computer. So we can we don't have to be um you know as pinpoint in our search and this will just help us bring back you know anything related to passwords hopefully we can get. So I'm going to get out of copy mode here and
504:05
Speaker A
we'll paste this in here and let it run through. Go back into copy mode so it doesn't scroll on us. And if I just scroll up to the top here. So this is kind of why it's nice that we have this underscore
504:17
Speaker A
tools. So anywhere we see this I'm just going to you know skip over it cuz we know we've added it. Of course, we're getting some hits um through that busy box binary that we brought in. And of course, we don't care about any of that
504:28
Speaker A
because we brought it over. Um but if we scroll down here to the bottom, we're seeing it looks like three config files with this conf uh file type and they have the word password in it. So maybe worth taking a look um at these. And
504:43
Speaker A
then also of you know definite interest to me is it looks like we have the drop air password. So this is the SSH password and it this to me looks like some sort of hash. So what I'm going to
504:54
Speaker A
do is I'm definitely going to save this. I'm going to want to add, you know, all this to our notes, especially even about these config files and the commands we run. Um, but more specifically what I'm going to do with this is I'm actually
505:04
Speaker A
just going to copy this. Uh, and if we go over to the terminal I have here, what I'm going to do is I'm going to make a directory for our router here. So I'm going to call it TP link WR841N.
505:17
Speaker A
We'll cd into there. And I'm actually going to make a directory for hashes. Okay. And what I'm going to do is I'm actually just going to um create a little document here. We'll call it drop bear.hash.
505:36
Speaker A
And I'm going to paste it in here. All right. Save this. And then we have we should have that.
505:48
Speaker A
Yep. Perfect. So we've got this one hash. We'll come back to this later. And let's go back again here and open up the notepad.
505:57
Speaker A
So another good thing to look for here is I'm just going to run one for admin.
506:01
Speaker A
We know the user is that admin. We found that through who am I. And then also a lot of times like the default admin user on routers or different IoT devices is going to be admin or administrator, something like that. So, another really
506:15
Speaker A
good one to search for. So, let's just rerun this again. Paste it in with control shift V.
506:25
Speaker A
And we got a couple hits here. Okay. So, first thing I'm seeing here, and this is actually interesting to see, is we've got this pass WD file with this to me looks like what would be the contents of
506:36
Speaker A
the shadow file. And looks like I guess um it's using the old style where it's in the past WD and for whatever reason it's been copied or I'm not entirely sure why but it is in the var folder.
506:49
Speaker A
But this is a great finding for us because looks to me like this is going to be um the password for the admin account. And if you're not familiar with how the shadow files work so this dollar sign one this means this is going to be
507:02
Speaker A
Unix uh MD5 hash. And if we copy, so all of this right here all the way to this slash is going to be the hash. So let's take this over again to those hash folders. Um, and we're going to go and
507:16
Speaker A
make we'll call this admin.ash. Paste it in here. Save it. We should have those two hashes. Okay, perfect. So let's hop back over. We'll come back to those in a second.
507:31
Speaker A
So you could, you know, add root here. That would be a good thing to look for.
507:35
Speaker A
Another one that I like to look for on IoT devices in particular is to see if there's any hard-coded API keys. So, I'll put something like, you know, API or key. Let's let's start with API though here and take a look and see if we get
507:49
Speaker A
anything back. Okay, so it looks like on this there's nothing. But this is always a really good thing to check to see if you have any hard-coded um API keys or anything like that or API endpoints. Another interesting thing to look for is if
508:04
Speaker A
there's any um URL endpoints or anything like that. So we can also take a look and see for example I don't know maybe.com look for anything with com in it.
508:32
Speaker A
Okay. So, we'll just ignore again any of this busy box tool stuff here. Okay.
508:40
Speaker A
Looks like we've got these uh some XML files here. So, good to know that. Looks like we're using comf and xml for those config files. Um and we've got, you know, this one's not too much interest, but sometimes you can find um
508:53
Speaker A
interesting URLs or subdomains in here. Scrolling down again, you're seeing some more XML files for config. So, nothing huge of interest here, but they can find, you know, very interesting URLs and subdomains and API endpoints and things like that by searching for this
509:10
Speaker A
as well. And, you know, you can do.org.net, all those different ones, um, and see what you can get back. Okay.
509:16
Speaker A
So, the next one we'll do is instead of using GP, we'll use find and we'll see if we can take a look for some files. We saw that they're using that conf and XML for all of the files. So, I'm just going
509:27
Speaker A
to copy this part here so we don't have to retype it out here. Copy this. Paste it. And then we're going to use find instead of GP because we have access to that through this busy box. Um, and
509:39
Speaker A
we're going to look for dash name. And we'll look for any files. And this is just going to help us find anything with that file extension. So, we'll doxml.
509:49
Speaker A
And we should be able to then look for anything in that var folder with this XML. So, let's copy this.
509:57
Speaker A
All right. Okay. Looks like we got some hits in here. Um, so we're seeing a bunch of different XML files. So, good. I'm going to copy all this into my notes um for us to further enumerate and take a look
510:14
Speaker A
through these XML files. Another one we can do that's good to take a look at is we can also look for we saw that we had those cont files as well.
510:30
Speaker A
Perfect. So, we have all of those com files. Again, another thing to take a look for. We've and we should add all these to our notes. Um, so interesting way just to find any like human readable files where there might be interesting
510:43
Speaker A
information. Of course, we could also do a search for .txt and see if there's anything in there as well. So, that wraps up this video. I will see you over in the next one where we take a look and
510:54
Speaker A
see if we can crack either of those hashes. Welcome everyone. In this video, we are going to take a look at some of those interesting files we found in the last lesson using GP and find and then we'll
511:08
Speaker A
take a shot at cracking the two hashes that we also located. So, of course, if we find something interesting with GP, it only shows us one line in that file, and it's worth taking a look at the rest
511:19
Speaker A
of the file. So let's start by looking at that pass WD file that we saw and it was just sitting there in the slashvar.
511:28
Speaker A
So we can cat that out. So if you're familiar with modern Linux then the passd file usually doesn't have the hashes in it for the passwords but this one looks like it does. And for whatever reason it's being moved uh or
511:45
Speaker A
copied uh or remade into the var folder which is interesting to see. But of note to us, of course, we saw this admin hash which we copied over and we can see the other users in here as well. So we have
511:57
Speaker A
the drop bear user for the SSH and then we have this nobody that we already know is for the TFTP. So unfortunately no other hashes or anything. Uh just that one that we did find and we're going to
512:09
Speaker A
try and crack later on in this lesson. So we also saw there was that drop bear password and it was inside a folder in temp here. If we just list it out, there was a drop bear folder in there.
512:23
Speaker A
If we list out the contents of that, we see, of course, we've got this drop bear password file. So, let's take a look at that and see if there's anything more in there.
512:34
Speaker A
Looks like we've just got the one password and hash. So, nothing further to find there. And then the other two files that we see in here, we've got an RSA host key and this DSS host key that are used for the SSH. Uh if you're not
512:45
Speaker A
familiar with these keys for SSH, these aren't the ones um for actually accessing, these are the ones that are the host keys for identifying this router. Um so they're not going to be of any use for us for further access. But
512:58
Speaker A
of course, this drop bear password is something that we're going to try and crack later in this lesson. So I'm not going to show live taking a look at any of those other configuration files, both thexml and conff ones. I have taken a
513:11
Speaker A
look through those and they don't really contain uh anything of interest and that's most likely because we've still got a pretty much factory uh default set router. We haven't set anything on it.
513:22
Speaker A
The config files are for things like the UPN setup and whatnot which we haven't touched. So they are mostly blank. Uh if you want to exercise in using this shell and reading those out though, of course we do have cat on here so you can take a
513:35
Speaker A
look at those and I would encourage you to look through them on your own. At this point, I'm going to switch over to the other terminal here and we will take a look at cracking those two hashes.
513:49
Speaker A
Okay, just to double check on the hashes we have. So, the first one that I'm going to take a shot at is this um admin hash. So, if we just take a look at this, just really quickly looking at
513:58
Speaker A
this hash. So I can identify that it is the MD5 um Unix style hash because for these shadow file or pass WD file hashes this dollar sign and then the one this denotes what type of hash it is in
514:11
Speaker A
dollar sign one that's just a Unix MD5 hash. This hash is very crackable with hashcat and I think anyone that took the PH course should be more than capable of doing that. So, I'm not really going to go over the full details of it. And in
514:24
Speaker A
fact, I'm going to encourage you to pause the video right now and just give it a shot on your own. So, go ahead and pause it right here. And when we come back, I will show how to crack it.
514:34
Speaker A
Okay. So, hopefully you were able to crack it. Uh, if not, I'm just going to quickly show how we can do that. So, first thing I'm going to do is just check in the help and see um what what
514:44
Speaker A
module we need to use for the MD5 Unix. So, I'm just going to run hashcat and I'm go d-help and we'll pipe it into grap looking for MD5.
514:56
Speaker A
And right here we've got this MD5 Unix. This is the one even we see it's got this dollar sign one dollar for the formatting which we have uh in ours here. So, that's going to be exactly what we need. So, we'll just run with
515:08
Speaker A
that one. And then we're going to do dash a0-m is the 500 we just found. And it was the admin.hash.
515:19
Speaker A
And I'm going to use slash I'm just going to use rocku for this one. So that is in user/share word lists slashrou.ext.
515:30
Speaker A
And I'm just going to let this run through. And look at that. cracked it immediately, which even on my VM usually takes a little bit of time to set up, but we got it immediately. And that's because the admin password is 1 2 3 4.
515:45
Speaker A
So, not a very strong password. Wonder why they even have one, but yeah, 1 2 3 4 for that admin password. All right, so let's take a look at the drop bear one now. And I'm just going to pop open the
515:59
Speaker A
hash here. So, that was this one. And looking at this one again, this looks like just a straight up um MD5 hash to me. So let's take a look at how we can uh crack that one. I will mention
516:13
Speaker A
so if you want to go and crack this one on your own um go ahead, but you know you may not be able to crack it and I'll just show you why here. So you mean go ahead and try it if you want on your
516:23
Speaker A
own, but don't expect for sure that you will be able uh to crack it. So let's go back and run that hashcat command. Um, we're just going to switch here to this drop bear.
516:36
Speaker A
And I should remember this one from doing it so many times, but the the straight up MD5 one is just actually zero in um, hashcat. And we'll let this one run through here as well. And Minecraft almost immediately because
516:48
Speaker A
you'll see here um, the password is 1 2 3 4 qwer. And if you don't remember, this is what I set actually as the um admin password to the web portal for the router. That's why I was saying you
517:02
Speaker A
might not be able to crack it because this is going to be dependent on whatever you set that password to. So whether you set it the same as me or you put um your own one in. So, it's kind of
517:11
Speaker A
interesting to see that it looks like that's why this drop bear password is being created dynamically there because it's being picked up from the config file and whatever we set for that admin password. So, if we were conducting a
517:24
Speaker A
pentest or a security audit or anything like that, then these would definitely be um interesting findings for us and we're definitely going to put them in our notes. So, the last thing I want to show quickly here because I'm just sure
517:35
Speaker A
a lot of people will be wondering why we're not using that SSH password we found to log in with the SSH. And there's a couple reasons for that. The first one is just to be honest is that I
517:45
Speaker A
was not able to ever get it working and I'll show you the issue that I ran into.
517:49
Speaker A
So, we can SSH. So, if we just go SSH, we'll just go drop bear at and the IP address 192.168.0.1 0.1 and if I just bring this up so everyone can read it. Okay, so the first thing we
518:05
Speaker A
see here in this error is just this unable to negotiate with and then this the IP of a router. Um we get this no matching key exchange method found and we see the key exchange methods they are offering. Uh and and I want to show this
518:16
Speaker A
because this is something you're going to see with IoT devices frequently that they're running. you know, we have a very old Linux kernel and we're running lots of outdated software and of course we don't have the most up-to-date um key
518:29
Speaker A
exchange methods and cryp cryptography and all that stuff. So these are outdated. They're either deprecated um or broken uh key exchange methods that aren't recommended for use anymore. So if we want to use these, we're going to have to force our SSH to do that. And
518:44
Speaker A
I'll just bring over the command here because it's a little long um to do that just so everyone can see and how we can actually get that working. So I'll just paste it in here. Uh and I'll we'll hit
518:54
Speaker A
enter and then bring it up so you can see. Okay. So we it's going to ask us for a password now which is at least good enough. And we know for me it was 1 2 3 4 qwer
519:05
Speaker A
and we get these these errors. So I'll just bring it up again so everyone can see. So this is the command here and we're just adding these algorithms. So, we're adding both the key exchange. And then if you if you just fix those, then
519:17
Speaker A
it's also going to complain also about the host key algorithms that they're using. So, we need to add those as well.
519:23
Speaker A
Um, so I've just added both of those in here. And then you see we get this pty allocation request failed on channel zero. So, to fix that, and the way that I've seen that fixed is we can add this
519:34
Speaker A
dash t into the command. And again, I'll put the password in. So, just so everyone can see, I move it up. And then we get the shell request failed on channel zero. Um, and then this is as far as I got. I did spend
519:49
Speaker A
quite a bit of time trying to figure this out, but I was never able to. So, if anyone wants to take this as a challenge and figure out how to get this SSH work working. I think that would be
519:58
Speaker A
super cool. If you do some digging, you'll find that the reason this SSH is open is because it's used for that um TPLink tether app and that's how it actually communicates. So, I'm not entirely sure um if they're using some
520:11
Speaker A
special format or how that's working through SSH, but I wasn't able to um log in with it and get a shell. And I also wasn't able to just, you know, how you can send commands with SSH, then you get
520:24
Speaker A
an exact request failed. So, that's definitely something if you want to spend more time on it that you could and try and figure out what's going on there. Maybe even download the app and try and intercept the traffic between
520:35
Speaker A
it. The reason I didn't go any further into it is cuz as far as hardware hacking um and trying to find any vulnerabilities or anything like that, it's really not going to be um you know that useful to us because we do already
520:47
Speaker A
have this hardware shell and then of course we can use netcat to get a shell.
520:52
Speaker A
That's going to wrap it up for this video. I'll see you over in the next one where we continue using the shell to take a look at some of the processes and network connections that are running on our router.
521:05
Speaker A
Welcome everyone. In this video, we're going to continue on with our enumeration and we're going to be using two very common Linux enumeration commands that you're probably familiar with and that is ps and netstat. and we'll take a look at how we can use the
521:20
Speaker A
bus by box that we ported over to run those commands. So, you may actually recall when we were taking a look at the binaries that we initially had access to, if we just head over into that bin folder and list it out here, we actually
521:34
Speaker A
already have PS and netstat here. However, if we just start with PS for example, and we just try and run a help.
521:42
Speaker A
So, -h, we get invalid option. So maybe if we try d-help, well, we see we don't actually get anything printed out. Now, we already know that on this router, it's running a paired down version of BizzyBox that doesn't contain everything. And it looks
522:00
Speaker A
like it's possible that they've even paired down these various binaries that are included as part of BYBox because it looks like they've removed the help command or the help menu at least from this. And because of that, I'm not
522:13
Speaker A
entirely sure what else they have removed. So, I'm going to use the full busy box version that we brought over.
522:18
Speaker A
And I would suggest if you have that option, then it's always better to use that one because then, you know, it has all the commands and everything that's available to us. So, let's just head over there right now. So, mine is in
522:29
Speaker A
this var temp tools. Let me just tab complete it here and just double check it's still there.
522:37
Speaker A
Perfect. So what we can do now is we can run this busy box one that we brought over. And again we're going to do ps and let's just see if we can get the help working in there.
522:47
Speaker A
Okay. So not many options here. We can just list to show the threads which isn't going to be very much use to us.
522:53
Speaker A
And then we also can select which columns we want to display. But if I just pause this for a second here.
522:58
Speaker A
Unfortunately it's not giving us much details about you know which columns that we'd like to display. Maybe we'd like to run something similar to like ps-ogs that you usually run on Linux.
523:09
Speaker A
So, what I did find that you can do to, you know, check what columns here is actually if we just list an invalid column. I actually found this by seeing if I can just run all.
523:19
Speaker A
Let me just bring this up on the screen here. So, we do get these options of these supported arguments. So, in case we want to see any of these, if you try and list them all, you can only list about five
523:30
Speaker A
of them. Um, so pick what five you want if you do want to list them all, but I found just running with the defaults shows enough to get a good idea of what's actually going on. So I'm going
523:41
Speaker A
to rerun this again here. And instead of any options, let's just run it as default. And I'll go into copy mode so we stop scrolling.
523:54
Speaker A
So the very first thing that sticks out to me here is we see that the user that's running everything on here is this admin which we already know is root. So we have root actually running all the processes that we can see listed
524:07
Speaker A
here and this is not surprising just how we've seen kind of the rest of their internal security hygiene but definitely not following that principle of lease privilege here. So, if you're doing an audit uh or a penetration test, then
524:20
Speaker A
definitely something of note to list out as a finding. The other thing that I'll take a look at when I'm looking through the processes is anything that just looks like non-standard Linux that might be interesting to further investigate.
524:35
Speaker A
And when I scroll through here, the one thing that I do see is this COS binary or cause. I'm not entirely sure at this point what this is, but this is of interest to me because it doesn't look
524:46
Speaker A
like a standard Linux or at least anything that I'm used to seeing. If we scroll through the rest of it and take a look down, some other things that are of interest to me is we can see for example um how
524:58
Speaker A
the drop bear is being run. So how that's being executed and then we see a bunch of the other um internal binaries and commands that are running for the networking. Of course, we see this HTTPD one that we already saw when we were
525:13
Speaker A
taking a look at past vulnerabilities. So, good to see that that's running and also of something of further interest.
525:20
Speaker A
Okay, let's take a look for netstat here. So, we'll go dot slasha autocomplete for busyboxell and we'll go net stat.
525:35
Speaker A
Okay, so it looks like in here we have a few different options than the standard Linux one where I would usually run something like netstat- o. We are still going to want to run that a so we can see all sockets. And
525:49
Speaker A
then the other two ones that are interesting to me is we have this dash e for other more information. And then we definitely want to run this -p so we can show p program name and get an idea of
526:01
Speaker A
what's going on with those sockets. So let's run that. We're going to go here and we'll run - AP.
526:09
Speaker A
So, taking a look through the sockets that are open here. Nothing too much of surprise. We're seeing most of those commands and binaries that are being used for the router and then things that we already knew were running. So, of
526:20
Speaker A
course, the drop bear, we see that HTTPD, of course, some things for the UPN. Nothing of surprise there. We do see again this cos or cost binary being called and it's a a raw socket on port 255 which is usually reserved for these
526:36
Speaker A
raw sockets. So maybe something of interest further to see you know why this is opened up and what is listening.
526:43
Speaker A
Other than that nothing too surprising here. We already knew that most of this stuff was running. So we didn't find too much new interesting information from these two commands. But I did just want to quickly show how you can run those
526:56
Speaker A
through BusyBox and that it is a good idea if you do get this shell to take a look at both the processes that are running and then whatever sockets are open. That wraps up this quick video.
527:08
Speaker A
I'll see you over in the next one. Welcome everyone. In this video, we're going to take a look at some of the console log messages that have been streaming into our York connection. And we'll also see how we can trigger
527:21
Speaker A
additional log messages from performing some actions on the router and how these are going to aid us in future reverse engineering.
527:30
Speaker A
So, we haven't chatted too much yet about all of the different messages that have been streaming into our UR connection. And up until now, they have mostly been a nuisance for us as they just interrupt our terminal session when
527:44
Speaker A
we are trying to type. That being said, they do contain a lot of very useful information. So, if I just pause this one here so we can take a look at some of them that are up on the screen. The one that we've been
527:58
Speaker A
seeing stream in very frequently is this one from the util exec system. And all it's doing is just telling us the unset time zone command and how that's being run.
528:11
Speaker A
So this one specifically does not contain a lot of interesting information. But from the format of it, we can see how the other log messages are being written. The first thing that I want to call out here and we can see
528:24
Speaker A
through a few of the different log messages is when the message is being called with this square bracket space and then a function name and then square bracket. Well, these are actually functions that are being called by the
528:38
Speaker A
underlying binaries that are running the functionality of this router. Generally in embedded Linux systems, you're going to have some sort of shared object library that's going to contain most if not all of the functions that are going to be called by the binaries. And
528:56
Speaker A
generally in these shared object libraries, even though they are compiled, you will still have the actual names of the functions be available if we reverse engineer them. So what that means is that we can actually take a look at the logging messages and the
529:14
Speaker A
specific messages that are being printed out and we can then relate these back to functions that we can reverse engineer.
529:22
Speaker A
Of course, when we're just seeing them stream in like this, they don't give us a huge amount of information because we could probably already find these messages. However, one thing that we can do is open up the web portal and then we
529:35
Speaker A
can test some of the functionality in the web portal and see if we're able to find out through the logging what underlying functions are being called.
529:44
Speaker A
Of course, this is of particular interest to us for finding those command injections or buffer overflows because we can then relate what we're doing in the web portal easily to the underlying functions that are actually being called by the router. And then we can try and
530:00
Speaker A
go and take a look at these functions when we are reverse engineering. So the first thing that I'll try here is I we'll just try a quick login. So if we go for me it's 1 2 3 4 qwer.
530:12
Speaker A
And I'm just going to hit login here. And interestingly enough the first thing that we see is we get a message AES_get failed. This AES get key isn't okay. No AES key and IV now. So definitely something of interest about why this is
530:29
Speaker A
failing and what's happening there in the failure if it's, you know, defaulting to not using encryption or some sort of um preset key. So definitely something of interest there.
530:40
Speaker A
The other thing that I'm interested in now is we have all of these different commands that we can run through the web portal and they all offer potential injection points for possibly buffer overflow or command injection. So, the
530:54
Speaker A
first thing I'm going to test is just this quick setup here. And I'm going to choose access point because we don't actually have a WAN port plugged in. So, it'll allow us to set it up as an access point still
531:07
Speaker A
though. We'll need the um WAN port plugged in to do it as a wireless router. So, I'll just hit next here. And I've already set this up once, so I'm just going to go with that same settings here. So, IoT hacking is what I'm using
531:19
Speaker A
for the network name. You can set whatever you want here if you want to put it something differently. Uh, and then I'm going to use this really bad password of 1 2 3 4 5 QWER.
531:29
Speaker A
I'll hit next here. And then we can just run with these defaults here. I'll hit next. And then again, it just plays back those settings for us here. And I'm just going to click uh here to apply those
531:40
Speaker A
settings. And when I click apply or finish here, it's going to start streaming through a bunch of log messages as it applies all of these settings that we did. So, I'm just going to hit uh the button here, and we'll see
531:50
Speaker A
all of those messages start coming through. And if I just pause this now here so we can take a look at some of the interesting things that are coming in.
532:01
Speaker A
And as I scroll up here, let's scroll down. So we can see a bunch of interesting log messages coming through here. First one from this function rsl send app wlan config. And we get the message about this tell tmpd server that
532:18
Speaker A
the wlan guest config has been changed. And then we see a bunch of information from this util_ex system about how we are actually setting all of these details. So this is the first one I see that's really sticks out of interest to
532:32
Speaker A
me because this is something that we actually input. Uh and we're seeing how that SSID of IoT hacking is being set.
532:39
Speaker A
And we're using this oc_wan set wlan basic config to call this command iwpriv a z sets.
532:51
Speaker A
If we scroll down again a little further, you can actually see in this one how the pre-shared key is being set. Again, it's this OAL_WLAN set secret and the command that it's running is this IW priv. So these are of
533:09
Speaker A
specific interest to us because now we know when we perform these inputs on the uh web portal that we can actually see the underlying commands that are being called. So this oc_wan ra set secret and through the util exec
533:23
Speaker A
system this is going to be of interest to us when we do reverse engineering. So one other area of interest that I saw scrolling through the web portal is we have this system tools section which offers a lot of interesting diagnostic
533:36
Speaker A
tools and things that we can update that are potential injection points. So under the system tools I saw this diagnostic here where it allows us to run a ping.
533:47
Speaker A
So, if we just really quickly run, you know, a ping using it as we should be.
533:52
Speaker A
I'm just going to try and run a ping here for what my VM is actually at. So, that's a 192.168.
533:58
Speaker A
Whoops. 168.0100. And I'm just going to put this out of the pause mode so we can see the logs come start streaming through. When I hit start here, it should start running a ping.
534:13
Speaker A
Perfect. And we can see those pings actually come through. So, I'll just pause it again here. So, scrolling up here, the one thing of interest that sticks out to me is we're seeing how this ping is being run. And again, we're
534:25
Speaker A
seeing it from this util exact system function. And we have this ocore start ping command is. And then we're seeing it's, you know, this IP ping, which this is actually one of the binaries that we saw through busy box. And then, of
534:38
Speaker A
course, we're seeing this IP address that we put in here. In case this wasn't already obvious or sticking out when we're seeing this utel exec system being called, this is actually making system calls. So this is running essentially
534:53
Speaker A
shell commands to the system. And in this example, it's this actually showing us what it's running here, which is this IP ping command. And this can generally be dangerous to be doing because this is potentially um an injection especially
535:09
Speaker A
when we're running this command with a user supplied input. So if we aren't doing proper validation of all of these different uh options here then you know this is actually an area where we could do injection. So, what we can go back
535:24
Speaker A
and try manually here, of course, and I'm not going to go over like the full injections or anything, but we could try and just put, you know, a semicolon here. And then if we, for example, I don't know, we have echo, so we could
535:35
Speaker A
just try echo hello and run this. Well, it looks like they're actually doing some validation here. So, good on them. But you know the whole point of this is just to demonstrate about how we can now see if
535:50
Speaker A
we want to you know check and see how this validation's being done and if we can break it. Well instead of just banging our heads on the keyboard opening a burp and trying a bunch of different injection points. Well now we
536:01
Speaker A
can actually go back and try and reverse engineer um these functions and we can try and locate them in the firmware using the labels that we already have for them. And this is going to make our lives a lot easier for us. So, I'm going
536:15
Speaker A
to wrap up this video here. There's of course a lot more different interesting areas to explore in the web portal and I would encourage you to go ahead and do so and just see what log messages you get from the different actions in the
536:29
Speaker A
browser. I'm not going to show all of them on this video. So, I will wrap up this video here and see you over in the next one.
536:37
Speaker A
Welcome everyone. In this video, I'm going to be demonstrating how we can use Python to connect to serial ports. And in doing so, we can actually have our Python script connect to that UART serial shell on our router. And then we
536:51
Speaker A
can have the script automate some tasks. There's really endless possibilities to what we can do with this. And in this video, I'm just going to be demonstrating two scripts to give you an idea of what we can do. I'm going to be
537:03
Speaker A
making the assumption that most people watching this video will at least have a base understanding of Python. And as such, we're not going to be writing out the full scripts. I'm just going to give an idea of what they do and then we will
537:15
Speaker A
run them. If you want to copy or download these scripts, I have hosted them in the course GitHub. So, in the project folder here, I've actually just created a folder for the scripts. So, let's head over there right now. And if
537:28
Speaker A
we list them out, we've got two scripts that I'm going to be demonstrating. one that interrupts the boot process and then another one here that just runs the ps command and then logs the output so that we can see what processes are
537:40
Speaker A
running over time. Before we get started, both of these scripts are going to require the pi serial package. So, this is a Python library that allows us to interact with these serial ports.
537:52
Speaker A
It's already installed by default on Cali, but if you don't have it for whatever reason, you can get it through um pip 3. So, we're going to go pip 3 install and then it's called pi serial.
538:04
Speaker A
Uh, and you'll see I already have it, but just in case you didn't have it, that's where you can get it. So, let's start by taking a look at the script that runs ps and then logs that out. I'm
538:14
Speaker A
going to be using Vim. Uh, you're welcome to use whatever code editor or uh text editor you are most comfortable with. So, we'll take a look at this psor.py.
538:24
Speaker A
So I've created this script really just as an example of how to make the connection and then read and write through that serial connection with Python. Of course you could use this script for example if you thought that
538:36
Speaker A
there was processes that were changing from some cron jobs or other scripts that are running at different times or being triggered and you wanted to be able to capture those. So what we're doing with the script is at first just
538:48
Speaker A
initializing some of the settings that we need. So I've added this port here. This is how we're actually going to connect. It's the same uh as we would do with screen. So, this may change for you depending on where that device is. For
539:02
Speaker A
me, it's TTY USB0 right now. Next thing we're going to do is we're going to open a serial connection on the selected port. And you'll see here we are actually setting um those parameters for our serial connection. We've got the
539:14
Speaker A
baud rate, the bite size, which is the data bits. Uh we have set a timeout here of 1 second to close that connection. If we time out and then we have this uh stop bits equals serial.s stop bits_1 to
539:27
Speaker A
set us as just one stop bit. I needed this empty string here just to hold the contents of what we read. And then we're just using a while true loop here because we just want to continuously run the script over and over again to send
539:41
Speaker A
that ps command. We got the sleep here for 10 seconds. Then we are just writing out to the serial port and we're doing so with in bytes. We need to communicate in bytes. We're just setting ps.
539:54
Speaker A
And then we here, I'll move this up. We're going to read out into that string everything. And you'll see here we're using this read until function. And we're going to read until we see ps. The reason we're doing that is because
540:08
Speaker A
generally if you run a ps command, then the last thing that's going to be um in your list of processes is that ps command that you just ran. So, we're going to be using this read until really useful function um because you'll
540:20
Speaker A
generally have an idea of what you're looking for um when you send out a a write and then you can use this to you know stop your reading once you get the details that you are suspecting to get
540:32
Speaker A
and that's what I'm reading until this PS. Then we're going to print out that serial string. And again, we need to decode it from those bytes into ASI. And then finally, we're just going to open up a log file here. And we'll write
540:44
Speaker A
those into the log file. And then we just wait for 10 seconds until we run it again. So let's take a look at how we can run this script and what it looks like.
540:56
Speaker A
I'm going to need to run it as pseudo just because of the permissions on the dev folder. So I'm going to go pseudo Python 3. And then it is psore log.py. So I'll just run that right now.
541:10
Speaker A
And sometimes it does take a little while for it to um initialize and open up that serial connection. So it might just hang for a second here, but it will start pumping out the results quickly.
541:24
Speaker A
All right. So we'll see it. It's just going to continuously run here. So I'm actually just going to hit control C to stop it.
541:32
Speaker A
And then now if we check the contents of our folder here, we can see we've got this psore log.ext. So I'll just cat that out so we can see how that works.
541:44
Speaker A
Perfect. And we just see here uh I only grabbed one. We did get some of the other messaging, but we can see here we ran that ps command and then we got back the results of that ps command.
541:56
Speaker A
And here's where it ended again at PS. And then we were just waiting and we would run this um again continuously and you can let it run for a while and see if you start seeing any interesting things coming through or changing.
542:08
Speaker A
Again, the idea of this script was just to give an idea of how this works. Okay, the other script that I wanted to take a look at is this boot_inrupt.py.
542:17
Speaker A
So, let's take a look at that right now with Vim. So this is another example script that just demonstrates how we can uh interrupt the bootloadader programmatically with the Python scripting. And what it does is it just reboots the router and then it sends
542:34
Speaker A
that TPL command about 10,000 times over and over again really quickly just to make sure we catch that interrupt and then enter the bootloadader terminal menu.
542:45
Speaker A
The reason for showing this script is because this is actually a really good use of what we can use the Python scripting for because you may recall from the Uboot bootloadader that when we were looking at the the standard Uboot
542:58
Speaker A
which is pretty common on a lot of IoT devices. We have a lot of options in that terminal and one of them is that we can actually read out the memory contents from the ROM and what we can
543:09
Speaker A
have our script do is actually keep calling that memory dump or me display memory command and then we can have it write that out to a log file. Now you could do this just with the terminal and try and output it. But the problem is
543:23
Speaker A
it's going to take a very long time to do this over a serial connection and sometimes you have to only specify blocks of the memory. So you know maybe 1,024 bytes at a time or else it's going to overload the processor and also that
543:40
Speaker A
serial connection. So, one way to frequently overcome that is with some sort of script where we will just manually grab the blocks and then append them to a file and kind of create our own binary file that represents the
543:53
Speaker A
firmware. Let's just take a quick look here at what we're doing. So, the setup for this is the exact same. I'm not going to show it here. The one thing that I did do is I just cleared the
544:03
Speaker A
output buffers from any previously cached reads and writes. This is a good thing. I didn't do in the other script, but just something good to do because what can happen with these scripts is you can have um output being in the
544:14
Speaker A
buffer and especially here where we're writing this TPL out 10,000 times, we might get some stuck in our serial buffer. So, first thing we do here is we just write out that reboot command to actually reboot the router and then we
544:27
Speaker A
just wait for 0.5 seconds to give it a a little bit of time to actually execute that reboot command. Uh, and then what we do is we just start sending this TPL about 10,000 times. And this is just
544:39
Speaker A
kind of trial and error for me to get the timing and the amount of these two send. Uh, and I'm just printing it out so that we can actually see what's going on and how many times we're sending that
544:48
Speaker A
TPL. And then after we send that in this while loop, I'm just reading uh each line to see once we get to that prompt for the Uboot terminal. Uh, and then at this point, this is where we could then
545:00
Speaker A
add in the additional code if we wanted to send the MD command and then read back the contents of that MD command and print it out into a file. Of course, that's locked down on our bootloader, but on other bootloadaders, this is
545:13
Speaker A
definitely a valid process to get the firmware, which is why I wanted to demonstrate it. So, I'm just going to get out of here and we will look at how this script runs.
545:23
Speaker A
So, again, I need to run it with pseudo. So, it's going to be Python 3 and then it was this boot interrupter.py. And I'm going to run it right now.
545:38
Speaker A
Perfect. And we can see that it just, you know, sent that reboot command and then it spams this TPL. And we we overflowed it a little bit here. So, I'm just going to kill this here so we can
545:48
Speaker A
scroll up. And you see that I overflowed it a little bit here. But we then get into the bootloadader. So at this point, this is where we could then send that MD command and read out from the firmware
546:03
Speaker A
almost bit by bit over the serial connection and write it to a file. And then we could essentially download the firmware over this serial connection.
546:12
Speaker A
And this is a definitely a valid way to do this programmatically. Uh it was kind of a last resort option where you should try and exhaust other options, but sometimes this is the only way to get the firmware. So, it's good to see how
546:24
Speaker A
you can do this through a script. So, this really just scratches the surface of what these scripts are possible of doing and and you know what you can have them automate. Off the top of my head, a couple other things that I
546:37
Speaker A
can think of is you could write a script, for example, that automates the TFTP connection, making the directory and downloading those tools if you didn't, for example, want to keep manually transferring over that busy box myipell binary. You could automate that
546:54
Speaker A
all with a Python script. And if you want to, I feel like that would be a really good exercise to go out and try on your own to create a Python script that connects to the serial connection of the router. You know, it makes all of
547:07
Speaker A
the directories that you need in that /bar/temp folder and then automates copying over the busy box binary.
547:15
Speaker A
Another thing we could use for this is potentially trying to brute force a login. So on our shell connection through UART there was no login but sometimes you actually will have a login and maybe we want to try for example the
547:28
Speaker A
top 100 default passwords for IoT devices or something like that. And we could write a brute force type script to attempt all of those login instead of having to manually try them. That wraps up this video here. I'll see you over in
547:42
Speaker A
the next one. Welcome everyone. So throughout this section of the course, we've seen how useful and beneficial it can be to get this UR connection and also the shell through the UR connection to our IoT devices and it's going to greatly aid us
547:59
Speaker A
in reverse engineering and doing further recon on the device. So in our case for our router, they made it very easy for us to get this UR connection. Of course, they even went as far as labeling out all of the pins for us. They were nice
548:14
Speaker A
through hole connections that we were easily able to connect to. And all of the connections from the pads, they actually went directly to where they were supposed to on the microprocessor.
548:24
Speaker A
And then we didn't even have a login or anything. We could just connect directly as root. Unfortunately, this is not going to be the case for all IoT devices. So what I wanted to talk about in this video is what happens when we
548:39
Speaker A
encounter, you know, tricky UR connections or things that designers and manufacturers may do to hinder our ability or users ability to connect to or use these UR connections.
548:52
Speaker A
So on the left here, I've got a picture from a Balcon router that I had. And and what I do actually, and it's something to get in the hang of if you want to get more into hardware and IoT hacking, is
549:02
Speaker A
when people are discarding these electronic devices, I'll actually grab them up and usually they work perfectly fine. They're just outdated or something. And they are a great way to learn for free how to do hardware hacking without having to worry about,
549:15
Speaker A
you know, destroying or bricking anything that you actually care about. Anyway, so on this Bealcon router, I identified these test points here that I suspected were either a UART or JTAG connection, which is just another type of communication protocol. Now, it's
549:32
Speaker A
hard to see in this picture, but these are not throughhole connections. These are actually surface mount test points, and that means that we can't actually connect our header pins like we did on our router. We actually have to do
549:44
Speaker A
something different. There's a couple options for this, but this is what I ended up doing. this scenario and you know for us household hackers where we don't have a lot of expensive gear. So what I ended up doing in this scenario
549:55
Speaker A
is just soldering wires directly to those surface mount pads. So even without you know high-end soldering equipment you can still make a solder connection generally to those pads and it's not going to be the most durable connection but for our testing purposes
550:11
Speaker A
that will work okay. And what I did in this scenario is I just then used alligator clips to connect off these wires to a breadboard. And then I just plugged my header pins into that breadboard and was able to get a
550:23
Speaker A
connection. And and you could also even just solder your header pins probably directly to these pads as well. You could solder them to the wires. You really have a lot of options when you're you know doing this breakout soldering.
550:35
Speaker A
So that is one option. So another option is something like this PC bite device here that I'm showing here. So it's kind of a play on words with PCB and then it works similar to the third hand that I
550:49
Speaker A
was using where it holds the PCB in place. Then you see we have these test probes that come off these fairly stiff but still flexible arms and they're stiff enough that you can actually place these probes up to the test pads. And
551:03
Speaker A
there's usually a little spring connection in here as well. And what that allows us to do is push down and get a connection through this probe. And you'll see coming off the probe, we have here and here just those general
551:16
Speaker A
standard sized header pins that we can then connect whatever measurement device or for example our URB adapter or a protocol analyzer right to those pins.
551:25
Speaker A
You also see in this picture here that they're actually just doing those probes directly onto the leads of the processor. So, that is another option with these devices. I'm not going to go over and show all of the different
551:38
Speaker A
adapters or probes, but just keep in mind also that you can buy a lot of different adapters and probes that can even attach onto your digital multimeter. Just a couple examples that may come in useful is we can get clips
551:52
Speaker A
that clip onto tiny surface mount devices and allow us to take a measurement or we can even get very small hooks that hook onto the leads of surface mount chips like this one here.
552:04
Speaker A
So just something to keep in mind if you're finding these tricky connections and you're not able to do the equipment you have. There is lots of options as far as adapters and things like that go.
552:13
Speaker A
So outside of those tricky connections that just stem from very small surface mount components or surface mount pads, you may also run into scenarios where the manufacturers of the devices want to hinder the ability to connect to those
552:29
Speaker A
UR connections. And what they'll do is they will make modifications to the actual board for the production boards that get shipped out that essentially disable the UR connection through the test pads or the test pins. So looking at this picture here, this is actually
552:47
Speaker A
from another TPLink router. You can see this appears to be a connection. And on this pin here, you can see this trace which most likely just comes from directly off of a pin on the microprocessor.
553:01
Speaker A
It would then go to this pad here where we could then, you know, insert our header pin and connect to the UR session. Well, we see here we're missing two resistors. And one of the resistors, this R24, this is actually an inline
553:14
Speaker A
resistor that's just making an open circuit here. So, we won't actually get any measurement on this pad other than just zero volts. and we won't actually be able to read anything off of it. So to demonstrate what's going on in this
553:26
Speaker A
scenario here and then also something that is not too uncommon to see with these UART headers, I've got a type of, you know, pseudo schematic here to represent what's going on. On the left here, we've got what would be our
553:38
Speaker A
microprocessor. And of course, it would have many more pins than this in the actual one, but all we're really caring about in this is those UART pins. Got the RX, TX, ground, and VCC. And then on the right here, we've got the actual
553:52
Speaker A
test pads that would go out to our York connection just like they did on our TPLink router. So, we'll start with the TX pin. And if you remember what came off of the TX pin on our router, there
554:04
Speaker A
was lots of useful information, especially during bootup. And what we're seeing here is that they put an open circuit and there would be pads here for a resistor or just some sort of straight through connection. And this is actually
554:17
Speaker A
then blocking our ability to read off of this pin. If we read this, we'll get nothing. So generally to fix this, we can actually just bridge this either with a very low impedance resistor or just with a straight wire and see if it
554:31
Speaker A
works. One way that we can test is if we can actually just find the pad here on the other side of where the resistor would go. Then we can actually take a measurement with our multimeter. And if we're seeing the measurement come off at
554:42
Speaker A
3.3 volts or closer, then that's a good indication that we can just bridge this straight across with a wire.
554:49
Speaker A
Another thing that you may see is the usage of either a pull down or pull up resistor. So what a pulld down resistor does is it stops this pin from being what's called a floating pin.
555:02
Speaker A
Now, you may remember when we were talking about our digital communications that we have this threshold for determining whether an input to our pins is either a digital high or digital low depending on the voltage that's applied.
555:16
Speaker A
And usually that threshold is above a specific number and then below a specific number. And if it's anywhere in between, well, we're going to kind of get this randomness of whether it determines it to be a high or low
555:28
Speaker A
voltage. Now, you may expect if we just have nothing connected to this pin, well, it will be at 0 volts.
555:34
Speaker A
Unfortunately, that's not the case. What that's called is a floating pin. And in a floating pin, we'll generally have that voltage fluctuate somewhere in that mid region where then we're just going to get a randomness of the inputs. One
555:48
Speaker A
of the ways to get away from this is to use what we call either a pull down or pull-up resistor. And what we will generally do is we'll connect a very very high resistance resistor to the either the ground or if we have a pullup
556:03
Speaker A
we'll connect it to the VCC voltage and then that will essentially pull this pin when there's nothing connected to it to either ground or high and then it's easier for the designers of the software to determine that it's not actually just
556:17
Speaker A
that floating randomness coming to this pin. It's actually communication. The reason that we use a really high impedance resistance value here is then that doesn't actually affect real transmissions because they're going to be mostly unaffected by this very high
556:31
Speaker A
impedance value and they'll be able to uh have most of their transmission voltage go straight to the receiving pin.
556:40
Speaker A
So what designers of the board can do though is when they go to production, they'll switch this out from a high impedance resistor to a very low impedance resistor or just sometimes connect it directly to ground. And what
556:52
Speaker A
that's going to do is it's going to sync our ability to be able to transmit on this line because essentially everything's just going to go down to ground and it's going to be very high for us to pull the voltage up high
557:04
Speaker A
enough on this RX line to be able to trigger that transmission. So, if that's the case, then we're going to need to go and either just remove this resistor entirely or we'll have to swap it out with a higher ohm resistor. Just the
557:17
Speaker A
presence of seeing this pull down or pull up resistor, that doesn't mean that the transmission line's not going to work. And in some cases, it can actually be required because it needs that stability of being pulled, for example,
557:31
Speaker A
down to ground in order to work. And that's what we're actually seeing over here with this missing resistor. This is most likely a pull down resistor. It looks like it's going to this whole area is a ground pad and it looks like the
557:43
Speaker A
pull down resistor is not here. So to fix this connection, we actually may need to high impedance resistor in here and then a low impedance resistor here.
557:54
Speaker A
So, this is where all of the theory and our testing skills with the multimeter will pay off from electrical engineering for hackers 101 and helping us to sort out these different connections and being able to trace out or beep out
558:07
Speaker A
where the pins are going and identify if we're missing resistors or we have extra resistors that are going to block our connections. So, the last thing I want to talk about is what happens if we get our UR connection working. Think we may
558:20
Speaker A
be able to get a shell. We hit enter and then we are prompted with this login.
558:24
Speaker A
Are we stuck at this point? Well, as hackers, of course, we're not. There's a lot more we can go ahead and do further to be able to try and get logged in. So, the very first thing I would suggest you
558:35
Speaker A
do is Google is of course your friend and a lot of times someone else will have figured out this password or it will have been leaked and you can just easily find the default password for this online and then log in with that.
558:47
Speaker A
The other thing that we can do, and this is kind of skipping ahead a little bit to what we're going to cover in the next lesson, but you will remember that we were able to find the pass WD file and
558:58
Speaker A
we were able to crack the password for that. Well, if you're able to dump the firmware and then extract the file system, you're most likely going to be able to find some sort of hash of the password that you may be able to crack
559:09
Speaker A
and then you can log in with that. The other thing that I do want to quickly talk about as well is that sometimes through the bootloader and the bootloader menu that we uncovered, you will be able to set environment
559:22
Speaker A
variables. And sometimes these environment variables will switch the device to log into some sort of factory mode or factory setting. And in this factory setting, there will be no login.
559:32
Speaker A
Well, how would you figure out about this? Again, this is where this reverse engineering is going to come in handy when we reverse engineer either the bootloadader or those initialization scripts. And we'll take a look at reverse engineering in the next lesson.
559:45
Speaker A
So, there's lots of different things that you may encounter either with the physical connections or the login that make it a little bit more difficult for us, but not to be discouraged. Of course, with a little bit of searching
559:56
Speaker A
and hacking, you can usually get in. With this video, I just wanted to give you some areas where you can get started if you do run into these issues. That wraps up this video. I'll see you over in the next one.
560:08
Speaker A
Welcome everyone. In this video, we're going to take a look at troubleshooting UART connections. So, this is stuff that's just good to know. However, different from our previous video where we were talking about tricky UR connections. These are all going to
560:21
Speaker A
apply specifically to the UR connection that we are establishing to the target router in this course. This video is optional in that if you were able to get everything working with your UR connection and you did not have any
560:34
Speaker A
issues, then you don't necessarily need to watch this video. If you did run into issues with your connection, then I do ask that you try everything in this video first before reaching out over Discord or trying to contact me to get
560:50
Speaker A
some assistance. So, the very first thing we're going to start on is checking our pin out. Now, you'll want to check this. If you are not getting any connection whatsoever, either transmission or receiving. So, if you're having issues either with one of those
561:05
Speaker A
two or both, then you should go and check your pin out and your connections.
561:10
Speaker A
So, what I would suggest to do, and I know this sounds obvious, but I have made this mistake and wasted many hours before without checking this, is go back and double check and make sure all of your wires are going to the proper spot.
561:22
Speaker A
So, we have this handy pin out. I won't go over it again, but just double check and make sure all of your wires are going to the correct spot. After you have verified that and checked it, if it
561:33
Speaker A
did not fix your connection, then I would also suggest you go back, take your multimeter, and double check all of your connections are still good. This is especially important and true if you did not solder your header pins here and you
561:47
Speaker A
are using the twist tie. Over time, that's going to come loose and you're going to get bad or intermittent connections. So what I would suggest is go and take your multimeter and measure at each of these pins and make sure you
562:00
Speaker A
are getting what you expect to. So on VCC you should be seeing 3.3 volts. The ground should have continuity over to this ground or the ground on the input jack. The RX pin should be at 0 volts and not have any continuity to ground.
562:13
Speaker A
And then the transmit pin should be at that 3.3 volts or fluctuating during transmission. I would also suggest going even further and testing those at this point as well. So you can also check the voltages and continuity from these pins
562:29
Speaker A
as well. And that makes sure that you do not have any issues with your connections through the wires or the wires themselves. If you have tested all that and it is working okay, the other nice thing with the one linked package
562:41
Speaker A
of this USB to adapter is that it comes with two. So you can try and swap it out to the other one. Okay, moving on. The next issue that I sometimes run into and I wanted to show is that if your shell
562:52
Speaker A
starts to get messed up and you start seeing things like uh your prompt is moving across the screen or it's not picking up all the letters or it's just starting to get really messed up. What can happen is that there is a buffer in
563:06
Speaker A
the USB to your adapter and it can start to get kind of messed up. And I sometimes see this when screen doesn't properly detach from it. If you just close a terminal window without detaching, sometimes this happens. The
563:19
Speaker A
easiest way and the best way that I have found to fix this is just to power cycle the USB to UART adapter. And to do that, you just need to unplug it from the USB power. And then I also suggest power
563:31
Speaker A
cycling the router. If that doesn't fix it, I would also suggest restarting your VM. So your best bet to fix any of these issues is to power cycle the USB to your adapter, power cycle the router, and restart the VM. And that usually fixes
563:45
Speaker A
these issues with the shells being messed up. Okay, we've already gone over this one, but I just want to go over it again because it is something that I see frequently. If you are getting these messed up characters like this, this
563:57
Speaker A
means that you have something wrong in your UR parameters, most likely your baud rate. So, go back and double check and make sure you're using all of the correct parameters. So, the TPLink router that we're using is that 115,200
564:10
Speaker A
baud rate. Okay. Okay, the next thing I want to show is if you're getting this error where it cannot execute this /dev tty and then your USB no such file or directory. There's two possible issues here. So one is that you have not
564:24
Speaker A
connected the device to your VM. Remember you need to go into the removable devices and then connect that device to the VM from your host computer. The other possible issue is that that file has been renamed. There is another one at for example maybe one
564:39
Speaker A
or zero and it has renamed. So two easy checks is we should run this ls USB and then make sure the UART device is listed here. So it's this one. If it's not, then it's either not plugged in properly
564:50
Speaker A
or you haven't connected it to the VM. After that, we can run this ls-l/dev/ serial/by ID and that will give us that actual device file. And then make sure you're using this for your screen connection.
565:04
Speaker A
Okay, the next one that I want to show is if you are just having your screen session be terminating like this. And this is an issue that I run into. This means that it probably does not have the
565:13
Speaker A
proper permissions to access um this folder, the dev folder. So you need to either go and change the permissions for that or another easy way to get around that is to run it as pseudo. So just a really quick video here on how to
565:26
Speaker A
troubleshoot some of the common UART connections. Hopefully this helped you out if you are having some issues. I'm going to wrap up this video here and I'll see you over in the next one.
565:37
Speaker A
Welcome everyone. In this video, we're going to do a quick review of what I have added to my notes from this section of the course. In doing so, you can compare your notes to mine and then also it will serve as a quick review of what
565:50
Speaker A
we've covered so far in this section of the course. The first thing that I did was add the test equipment here. So, we have this USB to adapter and the manufacturer and part number here. We also used the screen software. So, I've
566:04
Speaker A
added that to our software used. Scrolling past our previous notes from the initial recon. I'll go down to where I started our notes here. And we started our enumeration via that UR connection.
566:16
Speaker A
So the very first thing we wanted to do was review the boot logs. And in order to do that, we of course connected our USB to adapter and we did so with this pin out here. So I think it's good to
566:27
Speaker A
add things like this to the notes because it's going to help anyone who's following along or needs to validate them to be able to follow our steps.
566:35
Speaker A
Another thing that I've added for the same reason is I add copies of the commands that were run so that they can easily be rerun by anyone following along. Of course, the first thing that we saw after powering on the router was
566:46
Speaker A
all of the logs from the bootloadader and Linux initialization. So, I've copied that in its entirety into the notes, which I think is a good thing to do. However, I'm not going to go over them all again here. What I did do
566:58
Speaker A
though is I added in some notes about the very important and key details from there. So the first key detail that we saw was from the bootloadader and that was the versioning of it. It appeared to be a repurposed build of the open-
567:10
Speaker A
source version of Uboot at 1.1.3 and we then saw that there was some internal versioning of the RA link Uboot and we saw the versioning of that. We then noticed the default selection of the bootloader to system boot via the
567:23
Speaker A
flash and we thought that this may be able to be interrupted so we could choose a different option and access the bootloader menu. Moving on from there, we saw lots of good details from the Linux initialization. Of course, the
567:37
Speaker A
first thing that we saw was the Linux versioning and then also the version of build route that was used to compile the Linux kernel. We also got some details about the CPU. So, if we didn't already know it was MIP's architecture, then we
567:50
Speaker A
would now know. We also saw this very important kernel command line. And in this command line, we saw some important details. First we see interestingly this console equals TTYS1 and the baud rate. So this is actually the console session that we were
568:06
Speaker A
connecting to over UART and this is the baud rate. The other important details we saw from here is that we have this root fs type file system of squash fs and then we also saw the initialization binary is in spin/init. So important
568:21
Speaker A
details there. We also got some important details about the boot partition. The first interesting detail that we saw is we actually got the part number of that flash ROM. This is that Cion chip that we were looking at. So if we weren't
568:35
Speaker A
able to identify that through the pictures, this is one other way. We also then got details about the five partitions that are created on the ROM and the specific addresses for those partitions. This is going to come in
568:48
Speaker A
useful later when we are reverse engineering and analyzing this firmware. We then noted the location of what appeared to be another initialization script at this etsy/init.drc.
569:02
Speaker A
We also noted multiple configuration files being used in the initialization and startup. And this one below here at the etsy/reduced_datamod.xml appeared to be one of the main configuration files being used. We also noted some information about drop air
569:21
Speaker A
and one of the initialization logs showed a writing of the drop air RSA key into the var/temp folder. This indicated to us a writable path that we could use later if we needed to bring some tools over. We were then able to perform an
569:37
Speaker A
interrupt of the bootloadader. Through our online research, we were able to discover that the interrupt command for TPLink devices is TPL. And there's a very small window to interrupt this bootloadader. So in order to do so, it's best to just actually reboot it through
569:52
Speaker A
the command prompt using this reboot command. And after that, we could then just type TPL repeatedly. And we are actually able to access the CLI or command line interface for that bootloader. When we tried running some of the known commands for the Uboot
570:10
Speaker A
command line interface, including even help, we noticed that unfortunately the modified version of Uboot that is being run seems to have all of this additional functionality removed. The only functionality that we had left is the TFTP boot. We then moved on to our
570:25
Speaker A
initial enumeration via the UART shell and of course pressing enter revealed that there was shell access with no loon as the root user. Our first quick check over the binaries revealed that we had BYBox available to us. Of course, we
570:39
Speaker A
learned that BYBox is this popular binary used on embedded systems to package many Linux and Unix binaries into one smaller version. When we took a look at the currently defined functions, we noticed that this appears to be a
570:52
Speaker A
reduced version of the full version of Busybox. However, TFTP was still available, so we could probably bring over the full version of BYBox.
571:02
Speaker A
We then went ahead and transferred over that full version. And I just put the steps here. I won't go over them again, but all the commands we run and the steps that we did so that anyone who would like to follow along could do so.
571:12
Speaker A
After transferring over by, we actually used the updated bus by which included GP to start enumering over that /var folder. Again, we only worked on enumerating the /var folder with our shell connection because we are going to do the other read only portions of the
571:30
Speaker A
file system on our actual Linux host computer using the tools that we have when we do our firmware analysis. I've listed the commands that we run in order to GP and look for passwords and we noted the interesting config files and
571:44
Speaker A
those passwords that we found such as the drop bear password and then also the shadow file or pass WD file that we found with the hashes. Of course, we also searched for interesting files with XML and conf.
571:59
Speaker A
We then went ahead and attempted to crack those password hashes. And of course, I have the commands that we run.
572:04
Speaker A
And of course, I showed how we were able to crack these passwords with hashcat.
572:09
Speaker A
Since this is educational purpose notes for everyone in the course to follow along, I've actually put, you know, the screenshots and how everything worked.
572:17
Speaker A
However, if you are doing this for a client, then you may not want to actually put any of the hashes or how they were cracked specifically in your notes. You may want to uh leave those as confidential.
572:30
Speaker A
Of course, we also cracked the drop air one. The next thing we did was check the running processes and network connections. Of course, the first thing we did is run PS and take a look at the processes running. One thing of note is
572:44
Speaker A
that all the processes were running as the admin user and there was no principle of least privilege being followed. Of course, we also used a similar process to check the running processes using netstat. Finally, we then took a look at the console log
572:58
Speaker A
messages that were streaming through and worked to prompt some additional console log messages. When we look through the unprompted console log messages, we did see one repeating that stood out and that was this one from utel exec system
573:11
Speaker A
where it was unsetting the time zone. We noted that this repeated call appeared to be indicated of of a log from a function in a shared object library. It also appeared that this is an exec system call which is a C
573:25
Speaker A
function that allows running of a system command. And of course, these can be dangerous in nature for command injection if the function uses user input. Because of this, we wanted to check and see if we could identify any
573:37
Speaker A
areas where our inputs to the web portal would actually trigger any of these exact system calls or other interesting functions that we could go in reverse.
573:48
Speaker A
to do. So, we started by just doing the wireless setup and we set it with these settings. And once we hit next, we then took a look at the console logs and I put a whole copy of all of those console
574:00
Speaker A
logs here. And we can see numerous times that the exact system function was used for user supplied inputs.
574:09
Speaker A
Of course, primary investigation showed that some user validation was being performed on the inputs. And notably, if we scroll up here and look at the uh pre-shared key, so the wireless password and the SSID, we can see all of this
574:22
Speaker A
individual escaping of characters, which is good practice because this is going to generally thwart any command injection attempts. Of course, further investigation is going to be performed using the function names to trace back and reverse engineer the firmware. So
574:38
Speaker A
now that we are able to trigger those console messages and then trace back and see the underlying function calls that are being made, we're going to use this in the future to aid in our reverse engineering. That wraps up what I have
574:52
Speaker A
added for the notes. Uh if you had them differently or you added extra things, then kudos to you. Really, just any notes you're taking is a great step and it's really important to be taking these notes. I'm going to wrap up this video
575:04
Speaker A
here and I'll see you over in the next section. This brings us to the end of this YouTube version of the course. So, first off, great job on making it this far. I really hope you enjoyed it and you
575:18
Speaker A
learned something. If you want to finish up this course and get the last three sections that go into uh reverse engineering and unpacking the firmware and the end of course challenge, you can get access to those on the TCM Security
575:33
Speaker A
Academy, which again I will link uh down below. And then if you enjoyed this course and you want to see more fulllength courses, make sure you're subscribed to the TCM Security YouTube channel. We're closing in on 1 million
575:47
Speaker A
subscribers and we would love to get there. So would really appreciate it if you check if you are subscribed. Thanks again for watching and I hope you enjoyed. I'll see you again next
Topics:IoT hackinghardware hackingelectrical engineeringfirmware analysisUARTSPI protocolembedded Linuxreverse engineeringcybersecurity trainingTCM Security Academy

Answers

Frequently Asked Questions

Who is the instructor of this IoT and hardware hacking course?

The course is created and taught by Andrew Bolini, also known as Digital Andrew, an electrical engineer and cybersecurity technical trainer.

Do I need programming skills to take this hardware hacking course?

You don't need to be a programmer, but understanding programming fundamentals helps in ethical hacking and analyzing code related to hardware.

What are the prerequisites for this beginner's IoT and hardware hacking course?

The course is beginner-friendly but benefits those with a general understanding of Linux, especially embedded Linux used in IoT devices.

Get More with the Söz AI App

Transcribe recordings, audio files, and YouTube videos — with AI summaries, speaker detection, and unlimited transcriptions.

Or transcribe another YouTube video here →