GOTROOT RESEARCH

Security Blog

Practical red team, penetration testing, vulnerability research, IoT security, and incident response insights from GOTROOT.

  • Should You Read the Firmware Before You Dump It — or After?

    There are two approaches: one is to first download the official firmware and analyze it, and the other is to directly connect via UART and attempt access. In a previous attempt, the UART connection was successful, but no further progress could be made because the Magic Key was unknown. This time, the firmware was downloaded first to attempt Magic Key extraction. Did it succeed?

  • The device that's also in the CEO's living room. it is WiFi. We bought it ourselves and looked right at the PCB.

    A domestically sold Wi-Fi device that has sold in the millions. GOTROOT research team’s hardware analysis record of a unit they purchased themselves and disassembled, done with just a multimeter and no oscilloscope. From measuring pin voltages with a multimeter to understanding how HIGH/LOW bits become UART waveforms. This series explains the prerequisite knowledge for reading it, aimed at someone who has never studied electricity before.

  • Even in the age of AI, IoT still requires physical access.

    A hands-on record of tearing down three widely used real-world devices—an ipTIME router, a domestic Wi-Fi device, and an AI voice speaker—from UART to SPI and NAND.Although we tasked AI with the firmware analysis, when it came to extracting the firmware, holding the soldering iron and interfacing directly with the chips remained a human job. The GOTROOT took on the challenge first-hand.