I have some very backlogged projects I've decided to just release to get them out of my backlog. The first one is related to aftermarket Apple CarPlay and Android Auto dongles. This release is the majority of my notes, tools, findings, and research artifacts from looking at the Mayton/AutoPro-style dongle ecosystem. It includes documentation, test … Continue reading AutoPro and 3rd Party Carplay/Android Auto Dongle Security Research
Category: Android Hacking
Addition to the $150 Private LTE Network
The first addition, a awesome 4G LTE router that runs a flavor of OpenWRT, anti-forensics blue merle plugin and supports CBRS bands (aka the $150 private LTE network). First documented case of this being supported!
Setting up your own 4G LTE Network (<$150) for your Embedded System & IoT Hacking Lab via Open5GS + CBRS eNodeB on Ubuntu 24.04
Step by Step instructions to setting up your own private LTE network for cheap, great for home labs, hacking and penetration testing.
Fly-By – Device 2: The Falcon/Sparrow – Gated Wireless RCE, Camera Feed, DoS, Information Disclosure and More
Covering the next batch of disclosures in regards to my Flock Safety security research.
Trap Shooter – Flock Safety Sniffer & Alarm
Custom firmware for the M5NanoC6 (ESP32-C6) that sniffs and then alerts you of nearby Flock Safety devices. Will be integrated into a exploit tool releasing on 09/27/25 for Flock Safety devices!
GainSec in the Middle!
Implementation of Man-in-the-Middle (MiTM) Router / Access Point (AP). Great for embedded, IoT, hardware or similar penetration tests, hacks or research. Creates all interfaces and configurations on the fly, integrates other functionality to make TLS stripping, Android use or Burp Suite use more streamlined.
Using a Nexus 6P and QCSuper to Sniff LTE.
Step by step instructions on how to setup and configure a Nexus 6P to sniff portions of the LTE wireless stack.
CVE-2022-37857, CVE-2022-37163, CVE-2022-37164 Hardcoded Credentials/Weak Password Policies
A location sharing open source server and android client was found to hardcode credentials and allow weak passwords by default (including blank passwords!)
Great example of the dangers of an Android app compiled with Debugging enabled
A concrete example of the dangers of compiling an Android application with debugging enabled.
Tool for performing OSINT against Firebase (Mobile Apps)
Best tool for enumeration against FireBase enivornments!







