Willem Melching

140 posts

Willem Melching banner
Willem Melching

Willem Melching

@PD0WM

I take things apart. Sometimes I put them back together. Consulting & Trainings: https://t.co/HDoTb6QsAF

The Netherlands Sumali Haziran 2009
641 Sinusundan2.9K Mga Tagasunod
Mietek Hiding
Mietek Hiding@mietekHiding·
@PD0WM nice. datasheet tables are the worst — multi-column layouts and rotated headers break every generic PDF parser I've tried. what are you using under the hood, pdfplumber?
English
1
0
0
120
Willem Melching
Willem Melching@PD0WM·
I built an MCP server so Claude can properly read PDF datasheets. Not just pdf-to-text, but proper table of contents, search and viewing pages as both text and image. This way it can properly see diagrams and tables. Check it out: github.com/I-CAN-hack/pdf…
Willem Melching tweet mediaWillem Melching tweet media
English
1
3
44
2.9K
Willem Melching
Willem Melching@PD0WM·
@FlUxIuS Don't forget this research into ID code glitching! jerinsunny.github.io/blogs/2024/02/… Also check out Renesas update TN-RH8-B0463A/E, which allows "Prohibition of [...] programmer" and "ID authentication" at the same time. I've seen this in the field, and requires two glitches to bypass.
English
3
0
4
376
Willem Melching nag-retweet
hakstuff
hakstuff@hakstuff·
This blog post ended up being a bit more industry-focused than I would have liked, but I wanted to do the research because I was curious what the adoption of bug bounty programs looked like in automotive! hakstuff.net/blog/car-hacki…
English
0
2
1
450
mansin
mansin@Mankaran32·
@PD0WM Does jlc do this type of pcba? Borad over board
English
1
0
0
62
Willem Melching
Willem Melching@PD0WM·
I created a small PCB that simulates an EV charger connection (IEC 61851) by generating the required ±12V PWM signals. Let me know if this is something you would like to buy from my store!
Willem Melching tweet mediaWillem Melching tweet mediaWillem Melching tweet media
English
4
1
37
2.4K
Willem Melching
Willem Melching@PD0WM·
@Mankaran32 Yes, for sake of prototyping speed this is all hand soldered. If I would sell the boards I would have JLC do PCBA.
English
1
0
1
128
mansin
mansin@Mankaran32·
@PD0WM Wow. Do you hand solder the picos?
English
1
0
0
205
Willem Melching
Willem Melching@PD0WM·
@jbx81 The goal of the project is to also support PPC-VLE, RH850 and maybe some other weird architectures. Those are unfortunately not supported by QEMU. It’s also a fun exercise to write the emulator from scratch, and hopefully it will have some more benefits down the road.
English
0
0
1
147
jbx81
jbx81@jbx81·
@PD0WM Have you tried the QEMU cpu? I did a small instrumentation framework in rust using Unicorn and wasn't super bad, I think it is not under the latest Tricore ISA because that should be closed.
English
1
0
0
169
Willem Melching
Willem Melching@PD0WM·
I'm 2 weeks into writing a custom emulator for some automotive fuzzing experiments. The designers of the Tricore ISA thought it necessary to define four variants of “reg ≥ imm9 → XOR into LSB of reg.” Who asked for this nonsense?
Willem Melching tweet media
English
2
1
20
1.8K
Willem Melching
Willem Melching@PD0WM·
Inspired by @FraktalCyber's Laser Fault Injection rig, I got an xTool F1. I probably need to use some HNO3 to take off the last bit of packaging. The chips no longer work if I go too far, and the die also looks visually damaged.
Willem Melching tweet mediaWillem Melching tweet mediaWillem Melching tweet mediaWillem Melching tweet media
English
0
3
33
2.1K
Willem Melching
Willem Melching@PD0WM·
Congratulations to @_stephandb_ for being the first to solve all the challenges! He also provided an excellent write-up: icanhack.nl/ctf_writeup.pdf. The CTF will stay up for a few more weeks, so don't worry if you haven't been able to finish all the challenges yet.
Willem Melching@PD0WM

I created a small automotive themed CTF! The first person to solve all the challenges will get a free CAN Bus Throwing Star. Check it out at ctf-teaser.icanhack.nl

English
1
0
12
1.3K
Willem Melching
Willem Melching@PD0WM·
I created a small automotive themed CTF! The first person to solve all the challenges will get a free CAN Bus Throwing Star. Check it out at ctf-teaser.icanhack.nl
Willem Melching tweet media
English
2
50
224
19.8K
logan
logan@loosenedspirit·
@PD0WM that's missing one feature i'd buy in a heartbeat. bmw enables an ethernet port in the obd2 port if you bridge 8 & 16 with a 510ohm 1/4w resistor
logan tweet media
English
1
0
0
77
Willem Melching
Willem Melching@PD0WM·
I have opened a hardware shop! Check it out at shop.icanhack.nl The first product is the CAN Bus Throwing star, an easy to use converter to connect to all things CAN bus. Let me know what other products you’d like to see next!
Willem Melching tweet media
English
5
13
64
4.8K
Willem Melching
Willem Melching@PD0WM·
@_MG_ You can also try dumping over CAN using UDS $23 (Read memory by address), XCP or CCP. However then you still need to figure out the flashing protocol to get the firmware onto the other EPS.
English
0
0
1
165
Willem Melching
Willem Melching@PD0WM·
@_MG_ I have looked at quite a few EPSes, but not Mazda. RH850, PPC and Tricore can all be dumped with inexpensive tools. Besides proprietary JTAG there is usually a UART/CAN bootloader. However, from what I’ve heard they contain a per unit calibration. That might not be compatible.
English
1
0
1
302
MG
MG@_MG_·
Auto hackers: has anyone dumped/replaced the firmware on the EPS (power steering motor) in a Mazda? I’m curious if it’s even possible. If so, what tooling is needed. It’s pretty expensive to even start trying, so I’d like to figure out what progress others have made before I start. I haven’t been able to find any info though. My immediate desire is pretty simple: dump the firmware on the EPS from a CX5 made in 2022 or later, then load it onto a pre 2022 EPS.
English
6
2
25
5.6K
Willem Melching
Willem Melching@PD0WM·
@rce_trent They quietly changed the chipset inside, so it no longer works for reading in-circuit.
English
0
0
0
88
rce_trent
rce_trent@rce_trent·
@PD0WM Question why replace rdf5k if it works?
English
1
0
0
122
Willem Melching
Willem Melching@PD0WM·
Did anyone find a worthy replacement of the Transcend RDF5K to read EMMC In-Circuit in 1 bit mode without spending $$$? Bought a bunch of cheap SD card readers from Amazon to test with, but none show up as mmcblk.
Willem Melching tweet media
English
9
0
14
2.9K