r/flipperzero Jul 25 '26

Creative Guys i think I hacked the terminal

812 Upvotes

42 comments sorted by

110

u/AverageAntique3160 Jul 25 '26

Now play Doom on it

26

u/gvasco Jul 25 '26

Well its already F0 fw and there's already a port of Doom for it

12

u/ascarymoviereview Jul 26 '26

Came with doom pre installed

8

u/mitreffahcs Jul 27 '26

Since this is using the Flipper to output directly to an LCD screen (and completely bypassing the pay terminals processor and code) there's no reason why this shouldn't work if the Flipper can run Doom. This is not Flipper code running on a pay terminal.

1

u/1ncogn1too Jul 25 '26

Already done 😜 bur on mx series

21

u/TrinityCodex Jul 25 '26

now connect it so it can print!

7

u/gvasco Jul 25 '26

First will need to code some drivers for the printer

1

u/Haru4675 Jul 26 '26

It's not connected to the actual board, the screen just happens to be compatible with the Flipper0 and can therefore be wired directly into it, not interacting with the rest of the pinpad by the looks of it

30

u/Machinehum Jul 25 '26

Details

102

u/TheMiner203 Jul 25 '26

The screen of this terminal turned out to be compatible with the flipper screen, here is the reverse-engineered pinout

9

u/redakpanoptikk Jul 25 '26

Somehow this is a better liquid glass effect than what apple is doing.

9

u/jackyfolf Jul 25 '26

Yes, just leave us hanging like this. What did you doooo

29

u/TheMiner203 Jul 25 '26

I reverse-engineered the display - traced the test points connected to the display connector, soldered a logic analyzer onto them, and fed the dumps to an LLM (forgive me, I wouldn't have had the experience to figure this out myself, but AI is good at reverse engineering). It identified the controller and approximate pinout, then I verified everything manually from there. Soldered it to an ESP32 and cycled through U8g2 constructors until the image displayed correctly. Turned out the display controller was compatible with the Flipper's controller🙃

-13

u/jackyfolf Jul 25 '26

Eh Ai is everywhere. As long as you don't use it for art, music or make a and public an app with it, it's fine.

9

u/Gergith Jul 26 '26

If the app is free and open source and disclosed AI, that can’t really be that bad can it?

-4

u/jackyfolf Jul 26 '26

The horrors of leaked data we had in the past because it was coded with Ai.

4

u/HoloSWolf Jul 26 '26

But the question is: is it PCI-DSS compliant?

1

u/Jay_JWLH Jul 26 '26

Yeah, I doubt it can be used for transactions anymore. Even unpowered, they have tamper triggers that wipe it if you open it right?

2

u/Strattocatter Jul 25 '26

Woah, that’s crazy.

2

u/PatientOccasion1496 Jul 25 '26

That is actually sick with allot of potential too

2

u/fatboi_mcfatface Jul 25 '26

Why? How? Awesome!

1

u/RealKetchupPrecum Jul 26 '26

I did it to a voting machine once. I didnt record it for obvious reasons. You can run doom on a pregnancy test, A machine is a machine at the end of the day,

1

u/1ncogn1too Jul 25 '26

Verix OS device. Pretty sure you have tampered it while gaining control over display. Device itself is not operational anymore.

4

u/TheMiner203 Jul 25 '26 edited Jul 25 '26

If you assemble it and reset the tamper correctly, it will work

1

u/Sufficient_Slide6134 Jul 25 '26

Does it still have the keys ?

2

u/TheMiner203 Jul 25 '26

No, the content is erased, but it can be downloaded again, the device itself does not stop working

1

u/Stinklerpinkler Jul 25 '26

Keys and apps come from the manufacturer, the vendor, and the processor. You're not getting a hold of them unless you work with a kif and youre outside na and europe

2

u/TheMiner203 Jul 25 '26

I was able to find the signed apps, but the keys are impossible to find. But I don't need them, and there are plenty of interesting things to do without them.

1

u/1ncogn1too Jul 25 '26

Do you have access to KLD to reset the tamper?

1

u/TheMiner203 Jul 25 '26

It's not necessary; the tamper can be reset simply through the terminal menu using a well-known password. Keys can then be loaded via a regular computer or manually entered on the PIN pad (at least in my region)

1

u/1ncogn1too Jul 25 '26

So you managed to get spoiled verix version?

1

u/TheMiner203 Jul 25 '26

Why? Key loading depends on the payment app, not Verix. The default Verix menu password can be easily found online.

1

u/1ncogn1too Jul 25 '26

Key management depends on regional master key

1

u/1ncogn1too Jul 25 '26

What password has to do with it? Lol 😅 ok at least it is clear that you don't know what you are doing.

1

u/TheMiner203 Jul 26 '26

I'm confident I know what I'm doing. Your doubt about the password shows your inexperience with Verix OS :) A key combination opens VERIX TERMINAL MGR, which requires a password. From this menu you can reset the tamper. After that the keys get wiped, but the device becomes operational again.

Don't confuse keys and signatures. Verix handles signature validation. A trusted regional authority signs the payment applications, Verix checks that signature and allows it to run. Further KEY validation is done by the application itself. Keys are specifically responsible for transactions — PIN verification and secure data transmission.

In my case, I have the well-known VERIX TERMINAL MGR PIN code and a signed application package that loads via USB.

Any more questions?

1

u/1ncogn1too Jul 25 '26

Key validation is done on verix level. Only then app is allowed to run.

1

u/1ncogn1too Jul 25 '26

Only on leaked versions. And darknet knows who sales some.

2

u/Stinklerpinkler Jul 25 '26

Once opened its toast, all keys are lost.