JTAG Boundary-Scan Chain: TAP Controller Attack Surface
Drive a real IEEE 1149.1 JTAG Test Access Port state machine by hand, shift bits through a boundary-scan register, and use EXTEST to force chip pins to arbitrary values — the exact debug-port attack used to bypass firmware protections and extract secrets from embedded hardware.
Almost every embedded chip — microcontroller, FPGA, SoC — exposes a four-wire IEEE 1149.1 debug port whose 16-state Test Access Port machine can shift bits through a boundary-scan register wrapped around every pin. This simulator lets you drive that state machine by hand with real TMS pulses, watch a boundary-scan register of 4–16 cells shift a live bit pattern in 3D around a chip die, and switch into EXTEST mode to see exactly how a hardware attacker uses the debug port to force output pins to arbitrary values — bypassing secure boot and every other software protection running on the CPU, because JTAG sits below it.
Drive a real IEEE 1149.1 JTAG Test Access Port state machine by hand, shift bits through a boundary-scan register around a chip die, and switch to EXTEST to see how a debug port lets an attacker force output pins to arbitrary values, bypassing secure boot entirely.
3D · Three.js / WebGL renderer · 60 FPS target · runs fully client-side, no install