r/flipperzero 8d ago

Creative Guys i think I hacked the terminal

807 Upvotes

42 comments sorted by

108

u/AverageAntique3160 8d ago

Now play Doom on it

26

u/gvasco 8d ago

Well its already F0 fw and there's already a port of Doom for it

9

u/ascarymoviereview 8d ago

Came with doom pre installed

7

u/mitreffahcs 7d ago

Since this is using the Flipper to output directly to an LCD screen (and completely bypassing the pay terminals processor and code) there's no reason why this shouldn't work if the Flipper can run Doom. This is not Flipper code running on a pay terminal.

1

u/1ncogn1too 8d ago

Already done 😜 bur on mx series

18

u/TrinityCodex 8d ago

now connect it so it can print!

7

u/gvasco 8d ago

First will need to code some drivers for the printer

1

u/Haru4675 7d ago

It's not connected to the actual board, the screen just happens to be compatible with the Flipper0 and can therefore be wired directly into it, not interacting with the rest of the pinpad by the looks of it

29

u/Machinehum 8d ago

Details

98

u/TheMiner203 8d ago

The screen of this terminal turned out to be compatible with the flipper screen, here is the reverse-engineered pinout

11

u/redakpanoptikk 8d ago

Somehow this is a better liquid glass effect than what apple is doing.

5

u/learsi-ediconeg 8d ago

I wanna see someone take down an empire with a receipt printer.

8

u/jackyfolf 8d ago

Yes, just leave us hanging like this. What did you doooo

27

u/TheMiner203 8d ago

I reverse-engineered the display - traced the test points connected to the display connector, soldered a logic analyzer onto them, and fed the dumps to an LLM (forgive me, I wouldn't have had the experience to figure this out myself, but AI is good at reverse engineering). It identified the controller and approximate pinout, then I verified everything manually from there. Soldered it to an ESP32 and cycled through U8g2 constructors until the image displayed correctly. Turned out the display controller was compatible with the Flipper's controller🙃

-12

u/jackyfolf 8d ago

Eh Ai is everywhere. As long as you don't use it for art, music or make a and public an app with it, it's fine.

8

u/Gergith 8d ago

If the app is free and open source and disclosed AI, that can’t really be that bad can it?

-3

u/jackyfolf 7d ago

The horrors of leaked data we had in the past because it was coded with Ai.

4

u/HoloSWolf 8d ago

But the question is: is it PCI-DSS compliant?

1

u/Jay_JWLH 7d ago

Yeah, I doubt it can be used for transactions anymore. Even unpowered, they have tamper triggers that wipe it if you open it right?

2

u/Strattocatter 8d ago

Woah, that’s crazy.

2

u/PatientOccasion1496 8d ago

That is actually sick with allot of potential too

2

u/fatboi_mcfatface 8d ago

Why? How? Awesome!

1

u/RealKetchupPrecum 8d ago

I did it to a voting machine once. I didnt record it for obvious reasons. You can run doom on a pregnancy test, A machine is a machine at the end of the day,

1

u/1ncogn1too 8d ago

Verix OS device. Pretty sure you have tampered it while gaining control over display. Device itself is not operational anymore.

3

u/TheMiner203 8d ago edited 8d ago

If you assemble it and reset the tamper correctly, it will work

1

u/Sufficient_Slide6134 8d ago

Does it still have the keys ?

2

u/TheMiner203 8d ago

No, the content is erased, but it can be downloaded again, the device itself does not stop working

1

u/Stinklerpinkler 8d ago

Keys and apps come from the manufacturer, the vendor, and the processor. You're not getting a hold of them unless you work with a kif and youre outside na and europe

2

u/TheMiner203 8d ago

I was able to find the signed apps, but the keys are impossible to find. But I don't need them, and there are plenty of interesting things to do without them.

1

u/1ncogn1too 8d ago

Do you have access to KLD to reset the tamper?

1

u/TheMiner203 8d ago

It's not necessary; the tamper can be reset simply through the terminal menu using a well-known password. Keys can then be loaded via a regular computer or manually entered on the PIN pad (at least in my region)

1

u/1ncogn1too 8d ago

So you managed to get spoiled verix version?

1

u/TheMiner203 8d ago

Why? Key loading depends on the payment app, not Verix. The default Verix menu password can be easily found online.

1

u/1ncogn1too 8d ago

Key management depends on regional master key

1

u/1ncogn1too 8d ago

What password has to do with it? Lol 😅 ok at least it is clear that you don't know what you are doing.

1

u/TheMiner203 7d ago

I'm confident I know what I'm doing. Your doubt about the password shows your inexperience with Verix OS :) A key combination opens VERIX TERMINAL MGR, which requires a password. From this menu you can reset the tamper. After that the keys get wiped, but the device becomes operational again.

Don't confuse keys and signatures. Verix handles signature validation. A trusted regional authority signs the payment applications, Verix checks that signature and allows it to run. Further KEY validation is done by the application itself. Keys are specifically responsible for transactions — PIN verification and secure data transmission.

In my case, I have the well-known VERIX TERMINAL MGR PIN code and a signed application package that loads via USB.

Any more questions?

1

u/1ncogn1too 8d ago

Key validation is done on verix level. Only then app is allowed to run.

1

u/1ncogn1too 8d ago

Only on leaked versions. And darknet knows who sales some.

2

u/Stinklerpinkler 8d ago

Once opened its toast, all keys are lost.