{"id":664,"date":"2025-12-23T16:00:46","date_gmt":"2025-12-23T15:00:46","guid":{"rendered":"https:\/\/www.hardwaresecurity.it\/?p=664"},"modified":"2025-12-23T16:01:56","modified_gmt":"2025-12-23T15:01:56","slug":"snhack-attack-how-hackers-could-turn-your-smart-pet-feeder-into-an-all-you-can-eat-buffet","status":"publish","type":"post","link":"https:\/\/www.hardwaresecurity.it\/?p=664","title":{"rendered":"SNHACK Attack: How Hackers Could Turn Your Smart Pet Feeder into an All-You-Can-Eat Buffet"},"content":{"rendered":"\n<figure class=\"wp-block-image aligncenter is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"1024\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/e3d24156-f555-4746-b9c3-2b7203d1cf03.png\" alt=\"0 TITLEpng\" class=\"wp-image-681\" style=\"width:305px;height:auto\" title=\"SNHACK Attack: How Hackers Could Turn Your Smart Pet Feeder into an All-You-Can-Eat Buffet\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/e3d24156-f555-4746-b9c3-2b7203d1cf03.png 1024w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/e3d24156-f555-4746-b9c3-2b7203d1cf03-300x300.png 300w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/e3d24156-f555-4746-b9c3-2b7203d1cf03-150x150.png 150w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/e3d24156-f555-4746-b9c3-2b7203d1cf03-768x768.png 768w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/e3d24156-f555-4746-b9c3-2b7203d1cf03-600x600.png 600w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/e3d24156-f555-4746-b9c3-2b7203d1cf03-100x100.png 100w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Recently a Smart Pet Feeder landed in my home. Out of curiosity, I have decided to check how secure this IoT device is and also extended this \u201cresearch\u201d to another brand and model. So far, I have checked the following ones that were purchased on Amazon and got some interesting results&#8230;<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><img decoding=\"async\" src=\"https:\/\/files.gandi.ws\/f6\/eb\/f6ebf144-9b28-4faa-a219-53b5416fe885.jpg\" alt=\"AMAZON COLLAGEjpg\" title=\"SNHACK Attack: How Hackers Could Turn Your Smart Pet Feeder into an All-You-Can-Eat Buffet\" \/><\/figure>\n\n\n\n<p><strong>The DUT (Devices Under Test)<\/strong><\/p>\n\n\n\n<p>As you can see from the images above the DUTs are the so-called BALIMO LENA and the PETLIBRO remotely-controlled IoT Pet Feeders. Both have an embedded camera, speaker and microphone.&nbsp;<\/p>\n\n\n\n<p>Looking closely at the PETLIBRO packaging we can already notice the presence of a FCC ID.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized\"><img decoding=\"async\" src=\"https:\/\/files.gandi.ws\/70\/66\/706616eb-2f8b-4809-9ae7-8caf1c8f0223.JPG\" alt=\"3 PETLIBRO FCC IDJPG\" style=\"aspect-ratio:1.7711653757924877;width:498px;height:auto\" title=\"SNHACK Attack: How Hackers Could Turn Your Smart Pet Feeder into an All-You-Can-Eat Buffet\" \/><\/figure>\n\n\n\n<p>Looking at the FCC database we can clearly see its internal PCB: <a href=\"https:\/\/fcc.report\/FCC-ID\/2A3DE-PLAF203\">https:\/\/fcc.report\/FCC-ID\/2A3DE-PLAF203<\/a> and therefore we can already see what SoC is installed (i.e. a classic Anyka used in many IoT Cameras) and potential pins for UART and JTAG!<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"608\" height=\"658\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/5a915ed7-cf54-47be-84b8-8de21a220073.png\" alt=\"4 PETLIBRO FCC ID Internal Photopng\" class=\"wp-image-671\" style=\"width:373px;height:auto\" title=\"SNHACK Attack: How Hackers Could Turn Your Smart Pet Feeder into an All-You-Can-Eat Buffet\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/5a915ed7-cf54-47be-84b8-8de21a220073.png 608w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/5a915ed7-cf54-47be-84b8-8de21a220073-277x300.png 277w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/5a915ed7-cf54-47be-84b8-8de21a220073-600x649.png 600w\" sizes=\"auto, (max-width: 608px) 100vw, 608px\" \/><\/figure>\n\n\n\n<p><strong>The Mobile Apps<\/strong><\/p>\n\n\n\n<p>Both DUTs do rely on mobile apps for controlling them remotely: BALIMO relies on the official TUYA App called SmartLife (which has remained out of my scope for now), meanwhile the PETLIBRO relies in its PETLIBRO and PETLIBRO LITE apps.<\/p>\n\n\n\n<p>Since my investigation was more focused on the hardware side\u2026 I did not spend any time looking at the APKs nor the cloud APIs (which usually are still an interested target to check. Just saying \ud83d\ude09 ). However, out of curiosity I did ran a quick scan with MobSF and here you can see the results\u2026 Overall no big red flags\u2026<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1231\" height=\"643\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/54e1dc91-4ddb-4543-bf80-5f10fbd841c3.png\" alt=\"5 MOBSF PETLIBRO 1302png\" class=\"wp-image-667\" style=\"aspect-ratio:1.9144862795149968;width:475px;height:auto\" title=\"SNHACK Attack: How Hackers Could Turn Your Smart Pet Feeder into an All-You-Can-Eat Buffet\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/54e1dc91-4ddb-4543-bf80-5f10fbd841c3.png 1231w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/54e1dc91-4ddb-4543-bf80-5f10fbd841c3-300x157.png 300w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/54e1dc91-4ddb-4543-bf80-5f10fbd841c3-1024x535.png 1024w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/54e1dc91-4ddb-4543-bf80-5f10fbd841c3-768x401.png 768w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/54e1dc91-4ddb-4543-bf80-5f10fbd841c3-600x313.png 600w\" sizes=\"auto, (max-width: 1231px) 100vw, 1231px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1228\" height=\"650\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/1443747d-a55e-4f2a-a2d9-28fbec96ae72.png\" alt=\"6 MOBSF PETLIBRO LITE 106png\" class=\"wp-image-666\" style=\"aspect-ratio:1.8892480598999872;width:478px;height:auto\" title=\"SNHACK Attack: How Hackers Could Turn Your Smart Pet Feeder into an All-You-Can-Eat Buffet\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/1443747d-a55e-4f2a-a2d9-28fbec96ae72.png 1228w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/1443747d-a55e-4f2a-a2d9-28fbec96ae72-300x159.png 300w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/1443747d-a55e-4f2a-a2d9-28fbec96ae72-1024x542.png 1024w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/1443747d-a55e-4f2a-a2d9-28fbec96ae72-768x407.png 768w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/1443747d-a55e-4f2a-a2d9-28fbec96ae72-600x318.png 600w\" sizes=\"auto, (max-width: 1228px) 100vw, 1228px\" \/><\/figure>\n\n\n\n<p><strong>Hardware Teardown<\/strong><\/p>\n\n\n\n<p>Now that I got some ideas of what to expect from the hardware side\u2026 I have started the teardown of the DUTs. &nbsp;<\/p>\n\n\n\n<p>Both devices mount an Anyka SoC (System on Chip). To be precise a AK3918EN080 which is a known SoC usually installed on consumer IoT Cameras. On Github there are plenty of repositories were fellow hackers played with it.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"2560\" height=\"2560\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/34448e8e-303d-4c58-9a77-04f318ea420e-scaled.jpg\" alt=\"7 BALIMO TEARDOWN collagejpg\" class=\"wp-image-693\" style=\"width:512px;height:auto\" title=\"SNHACK Attack: How Hackers Could Turn Your Smart Pet Feeder into an All-You-Can-Eat Buffet\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/34448e8e-303d-4c58-9a77-04f318ea420e-scaled.jpg 2560w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/34448e8e-303d-4c58-9a77-04f318ea420e-300x300.jpg 300w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/34448e8e-303d-4c58-9a77-04f318ea420e-1024x1024.jpg 1024w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/34448e8e-303d-4c58-9a77-04f318ea420e-150x150.jpg 150w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/34448e8e-303d-4c58-9a77-04f318ea420e-768x768.jpg 768w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/34448e8e-303d-4c58-9a77-04f318ea420e-1536x1536.jpg 1536w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/34448e8e-303d-4c58-9a77-04f318ea420e-2048x2048.jpg 2048w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/34448e8e-303d-4c58-9a77-04f318ea420e-600x600.jpg 600w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/34448e8e-303d-4c58-9a77-04f318ea420e-100x100.jpg 100w\" sizes=\"auto, (max-width: 2560px) 100vw, 2560px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized\"><img decoding=\"async\" src=\"https:\/\/files.gandi.ws\/11\/ba\/11ba4dda-4a94-458c-994b-c5e045736b59.JPG\" alt=\"8 PETLIBRO_UART_SPIJPG\" style=\"aspect-ratio:1.776759970904977;width:537px;height:auto\" title=\"SNHACK Attack: How Hackers Could Turn Your Smart Pet Feeder into an All-You-Can-Eat Buffet\" \/><\/figure>\n\n\n\n<p><strong>The Bad, The Good &amp; The Ugly<\/strong><\/p>\n\n\n\n<p>Now the questions are two:<\/p>\n\n\n\n<p>1) Where the firmware is stored? (we will see later on is in the SPI Flash)<\/p>\n\n\n\n<p>2) Is there an UART interface enabled?<\/p>\n\n\n\n<p>Looking at the images above we can clearly see the presence of interesting pins, marked with the usual UART values (i.e. RT, TX, GNS, in the case of PETLIBRO).<\/p>\n\n\n\n<p>The next step was to grab the #BRUSCHETTABOARD (<a href=\"https:\/\/github.com\/whid-injector\/BRUSCHETTA-board\">https:\/\/github.com\/whid-injector\/BRUSCHETTA-board<\/a>) &amp; #PIZZABITE (<a href=\"https:\/\/github.com\/whid-injector\/PIZZAbite\">https:\/\/github.com\/whid-injector\/PIZZAbite<\/a>) and check if there is the UART console enabled.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"2560\" height=\"1920\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/d4052c5d-f8b1-4d08-b873-21630733c99f-scaled.jpg\" alt=\"10 BALIMO UART BruschettaJPG\" class=\"wp-image-690\" title=\"SNHACK Attack: How Hackers Could Turn Your Smart Pet Feeder into an All-You-Can-Eat Buffet\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/d4052c5d-f8b1-4d08-b873-21630733c99f-scaled.jpg 2560w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/d4052c5d-f8b1-4d08-b873-21630733c99f-300x225.jpg 300w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/d4052c5d-f8b1-4d08-b873-21630733c99f-1024x768.jpg 1024w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/d4052c5d-f8b1-4d08-b873-21630733c99f-768x576.jpg 768w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/d4052c5d-f8b1-4d08-b873-21630733c99f-1536x1152.jpg 1536w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/d4052c5d-f8b1-4d08-b873-21630733c99f-2048x1536.jpg 2048w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/d4052c5d-f8b1-4d08-b873-21630733c99f-600x450.jpg 600w\" sizes=\"auto, (max-width: 2560px) 100vw, 2560px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"2560\" height=\"1029\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/64c9deba-960a-486a-b1a7-c9dd9f1e8245-scaled.jpg\" alt=\"9 PETLIBRO UART collagejpg\" class=\"wp-image-691\" title=\"SNHACK Attack: How Hackers Could Turn Your Smart Pet Feeder into an All-You-Can-Eat Buffet\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/64c9deba-960a-486a-b1a7-c9dd9f1e8245-scaled.jpg 2560w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/64c9deba-960a-486a-b1a7-c9dd9f1e8245-300x121.jpg 300w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/64c9deba-960a-486a-b1a7-c9dd9f1e8245-1024x412.jpg 1024w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/64c9deba-960a-486a-b1a7-c9dd9f1e8245-768x309.jpg 768w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/64c9deba-960a-486a-b1a7-c9dd9f1e8245-1536x617.jpg 1536w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/64c9deba-960a-486a-b1a7-c9dd9f1e8245-2048x823.jpg 2048w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/64c9deba-960a-486a-b1a7-c9dd9f1e8245-600x241.jpg 600w\" sizes=\"auto, (max-width: 2560px) 100vw, 2560px\" \/><\/figure>\n\n\n\n<p>To my un-surprise\u2026 in both DUTs I was able to get the usual UART console running at the standard 115200 bps. However, I was welcomed by a restricted console asking to login with user\/pass. At this point I could have used multiple approaches to get into\u2026 but I preferred for the faster one\u2026 dump the SPI &gt; Extract Firmware &gt; steal the root\u2019s shadow hash &gt; crack it with hashcat &gt; profit. (I followed this approach also because the device has Telnet open on port 23\/TCP open by default.)<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"768\" height=\"1024\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/0ce213bc-c1d4-43a4-867a-b6e1be3db6f4-1-768x1024.jpg\" alt=\"0ce213bc c1d4 43a4 867a b6e1be3db6f4\" class=\"wp-image-695\" style=\"aspect-ratio:0.7499999748481507;width:310px;height:auto\" title=\"SNHACK Attack: How Hackers Could Turn Your Smart Pet Feeder into an All-You-Can-Eat Buffet\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/0ce213bc-c1d4-43a4-867a-b6e1be3db6f4-1-768x1024.jpg 768w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/0ce213bc-c1d4-43a4-867a-b6e1be3db6f4-1-225x300.jpg 225w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/0ce213bc-c1d4-43a4-867a-b6e1be3db6f4-1-1152x1536.jpg 1152w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/0ce213bc-c1d4-43a4-867a-b6e1be3db6f4-1-600x800.jpg 600w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/0ce213bc-c1d4-43a4-867a-b6e1be3db6f4-1.jpg 1500w\" sizes=\"auto, (max-width: 768px) 100vw, 768px\" \/><\/figure>\n\n\n\n<p>At this point, I just needed to use again #BRUSCHETTABOARD with Flashrom to dump the SPI flash memory and use binwalk to check\/extract it. The images below are self-explanatory.<\/p>\n\n\n\n<p>In the case of BALIMO, I opted to use the SOP8 clip and dump the firmware directly from the PCB. Instead for the PETLIBRO I decided to physically remove the SPI and read it with #BRUSCHETTABOARD and a SOP8-to-DIP8 Socket.<\/p>\n\n\n\n<p>In both cases, I was successfully able to dump their firmware and extract the contents with Binwalk. As usual, for this kind of consumer IoT devices, I was presented with a classic squasfs\/jffs filesystems structure that were easily parsed\/extracted by Binwalk. So far so good.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1170\" height=\"761\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/2c3281fd-07d2-412d-ac26-bc511b40c267.png\" alt=\"13 PETLIBRO SPI Dumppng\" class=\"wp-image-675\" style=\"aspect-ratio:1.5374627997625492;width:676px;height:auto\" title=\"SNHACK Attack: How Hackers Could Turn Your Smart Pet Feeder into an All-You-Can-Eat Buffet\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/2c3281fd-07d2-412d-ac26-bc511b40c267.png 1170w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/2c3281fd-07d2-412d-ac26-bc511b40c267-300x195.png 300w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/2c3281fd-07d2-412d-ac26-bc511b40c267-1024x666.png 1024w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/2c3281fd-07d2-412d-ac26-bc511b40c267-768x500.png 768w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/2c3281fd-07d2-412d-ac26-bc511b40c267-600x390.png 600w\" sizes=\"auto, (max-width: 1170px) 100vw, 1170px\" \/><\/figure>\n\n\n\n<p><strong>Automated Firmware Analysis<\/strong><\/p>\n\n\n\n<p>Since I had access to the firmware, but not much interest in a full bug-hunt I quickly ran EMBA and Bugprove to get a grasp of the security of these two DUTs\u2026 and the results were not a surprise\u2026 usual IoT consumer devices where security is not the first (and not even a second) priority\u2026 This is the overall results from the scan of PETLIBRO firmware with Bugprove:<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1295\" height=\"846\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/5c5152ef-ba4a-4f1f-8726-609d65799576.png\" alt=\"14 BUGPROVE PETLIBRO Overviewpng\" class=\"wp-image-668\" title=\"SNHACK Attack: How Hackers Could Turn Your Smart Pet Feeder into an All-You-Can-Eat Buffet\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/5c5152ef-ba4a-4f1f-8726-609d65799576.png 1295w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/5c5152ef-ba4a-4f1f-8726-609d65799576-300x196.png 300w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/5c5152ef-ba4a-4f1f-8726-609d65799576-1024x669.png 1024w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/5c5152ef-ba4a-4f1f-8726-609d65799576-768x502.png 768w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/5c5152ef-ba4a-4f1f-8726-609d65799576-600x392.png 600w\" sizes=\"auto, (max-width: 1295px) 100vw, 1295px\" \/><\/figure>\n\n\n\n<p>This is the overall results from the scan of BALIMO firmware with Bugprove:<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1528\" height=\"846\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/9dab423a-42d4-451d-bf6f-985b3aa0110f.png\" alt=\"15 BUGPROVE BALIMO Overviewpng\" class=\"wp-image-672\" title=\"SNHACK Attack: How Hackers Could Turn Your Smart Pet Feeder into an All-You-Can-Eat Buffet\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/9dab423a-42d4-451d-bf6f-985b3aa0110f.png 1528w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/9dab423a-42d4-451d-bf6f-985b3aa0110f-300x166.png 300w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/9dab423a-42d4-451d-bf6f-985b3aa0110f-1024x567.png 1024w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/9dab423a-42d4-451d-bf6f-985b3aa0110f-768x425.png 768w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/9dab423a-42d4-451d-bf6f-985b3aa0110f-600x332.png 600w\" sizes=\"auto, (max-width: 1528px) 100vw, 1528px\" \/><\/figure>\n\n\n\n<p>One interesting feature of Bugprove is the 0day detection\/hunting feature\u2026 which actually found some interesting findings automatically (that should be manually checked, time permitting).<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1542\" height=\"888\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/1b4ed726-f7f3-43e6-8e3c-b21ef9937f0f.png\" alt=\"16 BUGPROVE BALIMO ak_tuya_ipc 0days Detailpng\" class=\"wp-image-678\" title=\"SNHACK Attack: How Hackers Could Turn Your Smart Pet Feeder into an All-You-Can-Eat Buffet\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/1b4ed726-f7f3-43e6-8e3c-b21ef9937f0f.png 1542w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/1b4ed726-f7f3-43e6-8e3c-b21ef9937f0f-300x173.png 300w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/1b4ed726-f7f3-43e6-8e3c-b21ef9937f0f-1024x590.png 1024w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/1b4ed726-f7f3-43e6-8e3c-b21ef9937f0f-768x442.png 768w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/1b4ed726-f7f3-43e6-8e3c-b21ef9937f0f-1536x885.png 1536w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/1b4ed726-f7f3-43e6-8e3c-b21ef9937f0f-600x346.png 600w\" sizes=\"auto, (max-width: 1542px) 100vw, 1542px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1527\" height=\"900\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/1b092029-a0ef-4ef4-85ff-30dd094b0c38.png\" alt=\"17 BUGPROVE BALIMO ak_tuya_ipc 0days Detail 2png\" class=\"wp-image-673\" title=\"SNHACK Attack: How Hackers Could Turn Your Smart Pet Feeder into an All-You-Can-Eat Buffet\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/1b092029-a0ef-4ef4-85ff-30dd094b0c38.png 1527w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/1b092029-a0ef-4ef4-85ff-30dd094b0c38-300x177.png 300w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/1b092029-a0ef-4ef4-85ff-30dd094b0c38-1024x604.png 1024w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/1b092029-a0ef-4ef4-85ff-30dd094b0c38-768x453.png 768w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/1b092029-a0ef-4ef4-85ff-30dd094b0c38-600x354.png 600w\" sizes=\"auto, (max-width: 1527px) 100vw, 1527px\" \/><\/figure>\n\n\n\n<p><strong>Firmware Analysis<\/strong><\/p>\n\n\n\n<p>With the extracted firmware at my disposal, I was able to look for some low hanging fruits. Here a quick self-explanatory overview.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"810\" height=\"198\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/c46d7af7-7cec-454a-8e94-6346109ce003.png\" alt=\"18 BALIMO Tokens Leakpng\" class=\"wp-image-674\" title=\"SNHACK Attack: How Hackers Could Turn Your Smart Pet Feeder into an All-You-Can-Eat Buffet\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/c46d7af7-7cec-454a-8e94-6346109ce003.png 810w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/c46d7af7-7cec-454a-8e94-6346109ce003-300x73.png 300w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/c46d7af7-7cec-454a-8e94-6346109ce003-768x188.png 768w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/c46d7af7-7cec-454a-8e94-6346109ce003-600x147.png 600w\" sizes=\"auto, (max-width: 810px) 100vw, 810px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"402\" height=\"222\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/3455bfec-96c2-4658-8a74-d90bfc095ca2.png\" alt=\"19 BALIMO WPA Config Leakpng\" class=\"wp-image-670\" title=\"SNHACK Attack: How Hackers Could Turn Your Smart Pet Feeder into an All-You-Can-Eat Buffet\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/3455bfec-96c2-4658-8a74-d90bfc095ca2.png 402w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/3455bfec-96c2-4658-8a74-d90bfc095ca2-300x166.png 300w\" sizes=\"auto, (max-width: 402px) 100vw, 402px\" \/><\/figure>\n\n\n\n<p>As you see there are plenty of stored credentials, Tuya cloud token, Wifi settings, etc\u2026 but what I was looking for primarly was the root\u2019s shadow hash: root:kRVZynxtm9Jac:0:0:99999:7:::<\/p>\n\n\n\n<p>Here, I noticed immediately an interesting thing\u2026 BOTH targets (i..e supposedly being from TWO different vendors, using different mobile apps and having a different main PCB\u2026 share the same root hash!<\/p>\n\n\n\n<p>With that hash in my hands, I quickly fired hashcat and left it running all night\u2026 the day after I was welcomed by a lovely result. The root password: <strong>AK2040jk<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1179\" height=\"489\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/c9562c50-fdc3-4c53-9e4d-cf6c490d6608.png\" alt=\"20 BALIMO Password Cracking with JtRpng\" class=\"wp-image-687\" title=\"SNHACK Attack: How Hackers Could Turn Your Smart Pet Feeder into an All-You-Can-Eat Buffet\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/c9562c50-fdc3-4c53-9e4d-cf6c490d6608.png 1179w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/c9562c50-fdc3-4c53-9e4d-cf6c490d6608-300x124.png 300w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/c9562c50-fdc3-4c53-9e4d-cf6c490d6608-1024x425.png 1024w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/c9562c50-fdc3-4c53-9e4d-cf6c490d6608-768x319.png 768w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/c9562c50-fdc3-4c53-9e4d-cf6c490d6608-600x249.png 600w\" sizes=\"auto, (max-width: 1179px) 100vw, 1179px\" \/><\/figure>\n\n\n\n<p>Now with this important piece of information we can check with Nmap if Telnet is open (i.e. which was also confirmed being enabled with the command \u201ctelnetd &amp;\u201d contained in the fw\u2019s file \/etc\/init.d\/rcS).<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"627\" height=\"550\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/8ae46706-45ad-4f7e-9906-90d518cfdddb.png\" alt=\"21 BALIMO Nmap-Telnet-Rootpng\" class=\"wp-image-669\" title=\"SNHACK Attack: How Hackers Could Turn Your Smart Pet Feeder into an All-You-Can-Eat Buffet\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/8ae46706-45ad-4f7e-9906-90d518cfdddb.png 627w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/8ae46706-45ad-4f7e-9906-90d518cfdddb-300x263.png 300w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/8ae46706-45ad-4f7e-9906-90d518cfdddb-600x526.png 600w\" sizes=\"auto, (max-width: 627px) 100vw, 627px\" \/><\/figure>\n\n\n\n<p>At this stage of my investigation, it was proved that both DUTs can be reached from LAN and access as root through telnet. A legit question at this point would be\u2026 What about Internet? Well, we will see later on this article that Shodan can help us figure this out.<\/p>\n\n\n\n<p>At this point is clear that both vendors and products could be easily hacked remotely and become part of a IoT botnet in pure Mirai style. But again, this was not the goal for the moment.&nbsp;<\/p>\n\n\n\n<p><strong>The SNHACK ATTACK explained<\/strong><\/p>\n\n\n\n<p>Now that we have two ways to interact with the DUTs (i.e. both UART and telnet) we can start playing around with the live console. My goal, at this point, was to figure out a way to trigger remotely the feeder servo motor in order to overfeed the victims\u2019 pet (i.e. reason why I called this article SNHACK ATTACK).<\/p>\n\n\n\n<p>The initial approach was to hunt for some GPIOs that at-rest are set to a 0 value and when the user triggers the feed routine it will change to value of 1 and thus enable the servo motor.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"745\" height=\"543\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/0514ee00-401c-4956-b46c-adb961a32bd6.png\" alt=\"22 BALIMO PS AUXpng\" class=\"wp-image-682\" title=\"SNHACK Attack: How Hackers Could Turn Your Smart Pet Feeder into an All-You-Can-Eat Buffet\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/0514ee00-401c-4956-b46c-adb961a32bd6.png 745w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/0514ee00-401c-4956-b46c-adb961a32bd6-300x219.png 300w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/0514ee00-401c-4956-b46c-adb961a32bd6-600x437.png 600w\" sizes=\"auto, (max-width: 745px) 100vw, 745px\" \/><\/figure>\n\n\n\n<p>During the investigation I also started checking the main ELFs involved (i.e. ak_tuya_ipc, feedwatchdog, etc.) with Ghidra and IDA but I ended up wasting too much time and eventually focused on another strategy: checking for logs or debug information.<\/p>\n\n\n\n<p>I first started deploying a cross-compiled version of tcpdump on the DUT and then tried to dump some packets while triggering the feeding function through the mobile app.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized\"><img decoding=\"async\" src=\"https:\/\/files.gandi.ws\/b7\/39\/b739970d-51c8-4e95-954a-088f1dc8c121.jpg\" alt=\"23 BALIMO App Feedjpg\" style=\"aspect-ratio:0.46142487309877217;width:232px;height:auto\" title=\"SNHACK Attack: How Hackers Could Turn Your Smart Pet Feeder into an All-You-Can-Eat Buffet\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1477\" height=\"165\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/b8a2438c-8dde-4467-a976-c702abc62d79.png\" alt=\"24 BALIMO Tcpdump Capture and Exfiltrationpng\" class=\"wp-image-686\" title=\"SNHACK Attack: How Hackers Could Turn Your Smart Pet Feeder into an All-You-Can-Eat Buffet\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/b8a2438c-8dde-4467-a976-c702abc62d79.png 1477w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/b8a2438c-8dde-4467-a976-c702abc62d79-300x34.png 300w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/b8a2438c-8dde-4467-a976-c702abc62d79-1024x114.png 1024w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/b8a2438c-8dde-4467-a976-c702abc62d79-768x86.png 768w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/b8a2438c-8dde-4467-a976-c702abc62d79-600x67.png 600w\" sizes=\"auto, (max-width: 1477px) 100vw, 1477px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"948\" height=\"701\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/59ab6237-d596-4ba0-b082-0083d7d4a693.png\" alt=\"25 BALIMO Deploying Tcpdumppng\" class=\"wp-image-684\" title=\"SNHACK Attack: How Hackers Could Turn Your Smart Pet Feeder into an All-You-Can-Eat Buffet\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/59ab6237-d596-4ba0-b082-0083d7d4a693.png 948w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/59ab6237-d596-4ba0-b082-0083d7d4a693-300x222.png 300w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/59ab6237-d596-4ba0-b082-0083d7d4a693-768x568.png 768w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/59ab6237-d596-4ba0-b082-0083d7d4a693-600x444.png 600w\" sizes=\"auto, (max-width: 948px) 100vw, 948px\" \/><\/figure>\n\n\n\n<p>As you see the network dump was not very useful, lot of encrypted traffic encapsulated into UDP stream and lot of TLS traffic, both going to the Tuya Cloud infrastructure. As I already mentioned, I intentionally avoided dealing with Tuya cloud and APIs because only this topic would take days and days of checks and I am a lazy and busy hacker nowadays, so I will leave to some of you the pleasure of playing with this.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1422\" height=\"613\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/617b5248-1cc2-4e66-b3d8-fe4c6087d5d5.png\" alt=\"26 BALIMO Wireshark Exfiltrated from DUTpng\" class=\"wp-image-688\" style=\"aspect-ratio:2.3197070992230735;width:615px;height:auto\" title=\"SNHACK Attack: How Hackers Could Turn Your Smart Pet Feeder into an All-You-Can-Eat Buffet\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/617b5248-1cc2-4e66-b3d8-fe4c6087d5d5.png 1422w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/617b5248-1cc2-4e66-b3d8-fe4c6087d5d5-300x129.png 300w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/617b5248-1cc2-4e66-b3d8-fe4c6087d5d5-1024x441.png 1024w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/617b5248-1cc2-4e66-b3d8-fe4c6087d5d5-768x331.png 768w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/617b5248-1cc2-4e66-b3d8-fe4c6087d5d5-600x259.png 600w\" sizes=\"auto, (max-width: 1422px) 100vw, 1422px\" \/><\/figure>\n\n\n\n<p>While looking around dmesg logs, uboot logs and the debug information printed on screen through UART while triggering the feeding function\u2026 I noticed the following debug data:<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"551\" height=\"309\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/d29a9dcd-73fc-46cd-9aaf-f19463c40f96.png\" alt=\"27 BALIMO Feed Once Serial ttySAK1png\" class=\"wp-image-689\" title=\"SNHACK Attack: How Hackers Could Turn Your Smart Pet Feeder into an All-You-Can-Eat Buffet\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/d29a9dcd-73fc-46cd-9aaf-f19463c40f96.png 551w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/d29a9dcd-73fc-46cd-9aaf-f19463c40f96-300x168.png 300w\" sizes=\"auto, (max-width: 551px) 100vw, 551px\" \/><\/figure>\n\n\n\n<p>It seems that the servo motor is NOT controlled through GPIOs but through a serial connection (note: at this point I could also have checked the PCB to understand if there was involved an external driver connected through serial connection on the SoC\u2026 but at the end I didn\u2019t need to).&nbsp;<\/p>\n\n\n\n<p>At this point, the challenge was to understand what was the device name related with this serial connection\u2026 cross-checking the list in \/dev\/ together with the U-boot logs\u2026 I quickly realized that two serial ports exist: \/dev\/ttySAK0 (i.e. our UART serial console) and \/dev\/ttySAK1.&nbsp;<\/p>\n\n\n\n<p>The next step was to replay those packets to that serial connection and hope!<\/p>\n\n\n\n<p>#Magic command for triggering 1 time the BALIMO feeder servo motor<\/p>\n\n\n\n<p>echo -en &#8220;\\xff\\xff\\x01\\x01\\x00&#8221; &gt; \/dev\/ttySAK1&nbsp;<\/p>\n\n\n\n<p>#Magic command for triggering 1 time the PETLIBRO feeder servo motor<\/p>\n\n\n\n<p>echo -en &#8220;\\x55\\xaa\\x03\\x01\\x00\\x01\\x01\\x05&#8221; &gt; \/dev\/ttySAK1 &nbsp;<\/p>\n\n\n\n<p>This was enough for a PoC. However, if I will have time, I will reverse engineer the serial protocol to forge the correct packet to trigger an max feeding action. For now, I am ok with this. For the overfeeding attack I just need to sending the same packet in loop and I reach the same goal.<\/p>\n\n\n\n<figure class=\"wp-block-embed aligncenter is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"SNHACK ATTACK: How Hackers Could Turn Your Smart IoT Pet Feeder into an All-You-Can-Eat Buffet\" width=\"500\" height=\"281\" src=\"https:\/\/www.youtube.com\/embed\/fOdLG0NFeYs?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n\n\n\n<p><strong>Real Case Scenarios<\/strong><\/p>\n\n\n\n<p>Arrived at this point, I was enough satisfied to stop hacking these DUTs\u2026 mark these IoT Pet Feeder as total crap from a security standpoint\u2026 when I started wondering if someone ever got hacked through them and if there are exposed devices on Internet\u2026<\/p>\n\n\n\n<p>This is what I found\u2026<\/p>\n\n\n\n<p>1) &nbsp; &nbsp; On Reddit some PETLIBRO owners reported being hacked :&#8217;)<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"717\" height=\"679\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/7da54b08-33ca-495a-80f6-5d99d8af5aee.png\" alt=\"29 REDDIT Pet Feeder Camera Hacked r Petlibro - smallpng\" class=\"wp-image-679\" title=\"SNHACK Attack: How Hackers Could Turn Your Smart Pet Feeder into an All-You-Can-Eat Buffet\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/7da54b08-33ca-495a-80f6-5d99d8af5aee.png 717w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/7da54b08-33ca-495a-80f6-5d99d8af5aee-300x284.png 300w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/7da54b08-33ca-495a-80f6-5d99d8af5aee-600x568.png 600w\" sizes=\"auto, (max-width: 717px) 100vw, 717px\" \/><\/figure>\n\n\n\n<p>2) A quick search on Shodan return couple of hundreds of potential DUTs online\u2026 after a quick check it was confirmed some of them being exactly the same devices\u2026<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1340\" height=\"807\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/edf3fd31-a3e6-4eeb-a4ab-35ad22d63f89.png\" alt=\"30SHODAN Overviewpng\" class=\"wp-image-685\" title=\"SNHACK Attack: How Hackers Could Turn Your Smart Pet Feeder into an All-You-Can-Eat Buffet\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/edf3fd31-a3e6-4eeb-a4ab-35ad22d63f89.png 1340w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/edf3fd31-a3e6-4eeb-a4ab-35ad22d63f89-300x181.png 300w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/edf3fd31-a3e6-4eeb-a4ab-35ad22d63f89-1024x617.png 1024w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/edf3fd31-a3e6-4eeb-a4ab-35ad22d63f89-768x463.png 768w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/edf3fd31-a3e6-4eeb-a4ab-35ad22d63f89-600x361.png 600w\" sizes=\"auto, (max-width: 1340px) 100vw, 1340px\" \/><\/figure>\n\n\n\n<p><strong>Conclusions<\/strong><\/p>\n\n\n\n<p>Am I done? Of course not. There are plenty of entry points and attack vectors to check. I will drop here a list of things I would probably check once I will have more spare time. Maybe some readers will take over and play around with this funny NotSoSecure Pet Feeders! Happy Hacking Folks!<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Tuya DB decryption<\/li>\n\n\n\n<li>Tuya APIs<\/li>\n\n\n\n<li>Extract Video Stream<\/li>\n\n\n\n<li>Extract Audio Stream<\/li>\n\n\n\n<li>Inject Audio\u00a0<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading has-text-align-center\"><strong><mark style=\"background-color:#cf2e2e\" class=\"has-inline-color has-ast-global-color-5-color\">WANNA BECOME A CERTIFIED HARDWARE HACKER?<\/mark><\/strong><\/h3>\n\n\n\n<p>The Offensive Hardware Hacking Training is a Self-Paced training including Videos, a printed Workbook and a cool Hardware Hacking Kit. And&#8230; you get everything shipped home Worldwide!<\/p>\n\n\n\n<p class=\"has-text-align-center\">For more info:<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Offensive Hardware Hacking Training\" width=\"500\" height=\"281\" src=\"https:\/\/www.youtube.com\/embed\/zbUuBZJIHkE?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>Recently a Smart Pet Feeder landed in my home. Out of curiosity, I have decided to check how secure this [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":665,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_uag_custom_page_level_css":"","site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[20,22],"tags":[],"class_list":["post-664","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-full-disclosure","category-hardware-hacking"],"uagb_featured_image_src":{"full":["https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/snack.gif",500,281,false],"thumbnail":["https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/snack-150x150.gif",150,150,true],"medium":["https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/snack-300x169.gif",300,169,true],"medium_large":["https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/snack.gif",500,281,false],"large":["https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/snack.gif",500,281,false],"1536x1536":["https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/snack.gif",500,281,false],"2048x2048":["https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/snack.gif",500,281,false],"woocommerce_thumbnail":["https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/snack-300x281.gif",300,281,true],"woocommerce_single":["https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/snack.gif",500,281,false],"woocommerce_gallery_thumbnail":["https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/snack-100x100.gif",100,100,true]},"uagb_author_info":{"display_name":"admin","author_link":"https:\/\/www.hardwaresecurity.it\/?author=1"},"uagb_comment_info":0,"uagb_excerpt":"Recently a Smart Pet Feeder landed in my home. Out of curiosity, I have decided to check how secure this [&hellip;]","_links":{"self":[{"href":"https:\/\/www.hardwaresecurity.it\/index.php?rest_route=\/wp\/v2\/posts\/664","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hardwaresecurity.it\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hardwaresecurity.it\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hardwaresecurity.it\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hardwaresecurity.it\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=664"}],"version-history":[{"count":3,"href":"https:\/\/www.hardwaresecurity.it\/index.php?rest_route=\/wp\/v2\/posts\/664\/revisions"}],"predecessor-version":[{"id":697,"href":"https:\/\/www.hardwaresecurity.it\/index.php?rest_route=\/wp\/v2\/posts\/664\/revisions\/697"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hardwaresecurity.it\/index.php?rest_route=\/wp\/v2\/media\/665"}],"wp:attachment":[{"href":"https:\/\/www.hardwaresecurity.it\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=664"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hardwaresecurity.it\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=664"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hardwaresecurity.it\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=664"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}