|
HOMiE7
|
 |
« on: June 23, 2009, 02:33:34 AM » |
|
Ok then. If c4e wouldn't give us original firmware for Lite-on then we try to dump it like he does. What we need? We need to take of drive's controller from pcb and "undress" it, but which programmator we need to dump spi flash?
P.S. Please do not close this topic.
|
|
|
|
|
Logged
|
|
|
|
|
.ISO
|
 |
« Reply #1 on: June 23, 2009, 02:49:14 AM » |
|
It's a very, VERY complicated process, and the only way to get access to the firmware is to decap the controller with acid, and then wire up those hair thin wires connected to the silicon die to your programmer. It's a lot more different than dumping previous drives. Good luck.
|
|
|
|
« Last Edit: June 23, 2009, 02:51:43 AM by .ISO »
|
Logged
|
you wish gigaturd, as if you even know how to tell the difference between a disassembler and your vagina
Gigabite: A fool who think he is always right, and talk about how useless others are when he is really addressing to himself. Gigabite agreeing with the statement: p.s nice comment in your sig
|
|
|
|
HOMiE7
|
 |
« Reply #2 on: June 23, 2009, 03:11:52 AM » |
|
Can you tell me more about flash type and programmer that support this flash?
|
|
|
|
|
Logged
|
|
|
|
|
.ISO
|
 |
« Reply #3 on: June 23, 2009, 03:28:31 AM » |
|
The embedded flash is a Macronix EEPROM (forgot what model, i'll check later) And as for the programmer, any should work as long as it supports the eeprom model that is used in the liteon drive, which is the one I was talking about above ^ The procedure? Don't even ask.
|
|
|
|
|
Logged
|
you wish gigaturd, as if you even know how to tell the difference between a disassembler and your vagina
Gigabite: A fool who think he is always right, and talk about how useless others are when he is really addressing to himself. Gigabite agreeing with the statement: p.s nice comment in your sig
|
|
|
|
HOMiE7
|
 |
« Reply #4 on: June 23, 2009, 04:42:49 AM » |
|
As JungleFlasher says there are two different types of flash in Lite-on drives. First is: Manufacturer ID: 0xEF Device ID: 0x11 Flash Name: Winbond/NEX(W25P20/NX25P20) Flash Size: 262144 bytes W25P20 DatasheetNX25P20 DatasheetAnd second is: Manufacturer ID: 0xC2 Device ID: 0x11 Flash Name: MXIC(MX25L2005) - it seems this is a Macronix EEPROM that you are talking about Flash Size: 262144 bytes MX25L2005 DatasheetPerhaps there is a third type of embedded flash but I found only these two. --- Next question is about function of wires:  How we can determine which wire is responsible for what? All possible combinations - 8 factorial i.e. 8!=8*7*6*5*4*3*2*1=40320 - it is pretty much...
|
|
|
|
« Last Edit: June 23, 2009, 07:35:08 AM by HOMiE7 »
|
Logged
|
|
|
|
|
xboxtech
|
 |
« Reply #5 on: June 23, 2009, 09:03:02 AM » |
|
Did anyone ever read these yet looking on the net I havent found any tuts on the removal of the epoxy,, that picture you have is that removed from the lite on?
|
|
|
|
|
Logged
|
|
|
|
|
HOMiE7
|
 |
« Reply #6 on: June 23, 2009, 01:04:47 PM » |
|
Did anyone ever read these yet looking on the net I havent found any tuts on the removal of the epoxy,, that picture you have is that removed from the lite on?
We try to make it like c4eva makes. I haven't found tutorials too, but they are not needed. Steps of actions are obvious I think, but advices of knowledgeable people would be very useful to us.
|
|
|
|
|
Logged
|
|
|
|
|
.ISO
|
 |
« Reply #7 on: June 24, 2009, 02:31:38 PM » |
|
@Xboxtech: Use epoxy removal chemical, or our favorite way: heatgun
@HOMiE7 Good luck finding a tutorial, i'll give you $100 if you can. By the way, did you really decap the chip and plan to do this?
|
|
|
|
|
Logged
|
you wish gigaturd, as if you even know how to tell the difference between a disassembler and your vagina
Gigabite: A fool who think he is always right, and talk about how useless others are when he is really addressing to himself. Gigabite agreeing with the statement: p.s nice comment in your sig
|
|
|
|
caster420
|
 |
« Reply #8 on: June 24, 2009, 04:36:06 PM » |
|
All possible combinations - 8 factorial i.e. 8!=8*7*6*5*4*3*2*1=40320 - it is pretty much...
Think outside the box... You know that these leads go to and tie into a leg of the controller. Trace that out and figure out that the potential pinouts are. This is the easy part. The hard part is decapping. Caster.
|
|
|
|
|
Logged
|
|
|
|
|
.ISO
|
 |
« Reply #9 on: June 24, 2009, 06:26:10 PM » |
|
Wait wait, Is that picture from C4E, or did he already decap the chip himself? Also, keep in mind that the flash wires do NOT go on any of the pins
|
|
|
|
|
Logged
|
you wish gigaturd, as if you even know how to tell the difference between a disassembler and your vagina
Gigabite: A fool who think he is always right, and talk about how useless others are when he is really addressing to himself. Gigabite agreeing with the statement: p.s nice comment in your sig
|
|
|
|
caster420
|
 |
« Reply #10 on: June 24, 2009, 06:56:52 PM » |
|
That is the original decap by Team Jungle.
|
|
|
|
|
Logged
|
|
|
|
|
Intersect
|
 |
« Reply #11 on: June 24, 2009, 11:56:49 PM » |
|
I thought there was drive specific info other than the key in the firmware that was part of the reason original firmware hasn't been released?
|
|
|
|
|
Logged
|
|
|
|
|
.ISO
|
 |
« Reply #12 on: June 25, 2009, 12:51:13 AM » |
|
The main reason was due to copyright protections
|
|
|
|
|
Logged
|
you wish gigaturd, as if you even know how to tell the difference between a disassembler and your vagina
Gigabite: A fool who think he is always right, and talk about how useless others are when he is really addressing to himself. Gigabite agreeing with the statement: p.s nice comment in your sig
|
|
|
|
HOMiE7
|
 |
« Reply #13 on: June 25, 2009, 03:37:26 AM » |
|
We have collected all the basic information (I think so). Now we waiting for the new unflashed Lite-on drive... Thank you guys for your help! @Xboxtech: Use epoxy removal chemical, or our favorite way: heatgun
@HOMiE7 Good luck finding a tutorial, i'll give you $100 if you can. By the way, did you really decap the chip and plan to do this?
To be honest, we have not even looked, 'cause we realize that it isn't exists.  When we reach the new unflashed Lite-on drive we'll try to make it. All possible combinations - 8 factorial i.e. 8!=8*7*6*5*4*3*2*1=40320 - it is pretty much...
Think outside the box... You know that these leads go to and tie into a leg of the controller. Trace that out and figure out that the potential pinouts are. This is the easy part. The hard part is decapping. Caster. Thank you for your answer. We will try. Also, could you help us to decrypt firmware or key in it at least? I think you can, because your Firmtool 1.3 can work with crypted iXtreme for Lite-on drive... I thought there was drive specific info other than the key in the firmware that was part of the reason original firmware hasn't been released?
С4E did not give any comments about this, so we can only suspect the reason of keeping original firmware in the team hands...
|
|
|
|
|
Logged
|
|
|
|
|
idog
|
 |
« Reply #14 on: June 25, 2009, 03:54:28 AM » |
|
While you're at it, dump the 83850c as well ? 
|
|
|
|
|
Logged
|
|
|
|
|
HOMiE7
|
 |
« Reply #15 on: June 25, 2009, 04:08:21 AM » |
|
We have all the consoles manufactured in August 2008 in our city. It isn't even Jaspers - it's f***ing Falcons! 
|
|
|
|
|
Logged
|
|
|
|
|
itsfakemon
|
 |
« Reply #16 on: June 25, 2009, 09:37:56 AM » |
|
All possible combinations - 8 factorial i.e. 8!=8*7*6*5*4*3*2*1=40320 - it is pretty much...
Think outside the box... You know that these leads go to and tie into a leg of the controller. Trace that out and figure out that the potential pinouts are. This is the easy part. The hard part is decapping. Caster. don't forget about the encryption  if you have access to a lab (or really just a titration apparatus) and HNO3, you can decap it easily the hard part is connecting the bonding wires to real wires once you have bonded the wires, you can easily find out which is the GND (because of the many GND pads it's connected to) and maybe even find out where VCC is - identifying should be easier from there but why even bother? what are you going to accomplish? find another sploit? don't mind me, you go girl!
|
|
|
|
« Last Edit: June 25, 2009, 09:44:06 AM by itsfakemon »
|
Logged
|
excuse me, I'm French...
|
|
|
|
HOMiE7
|
 |
« Reply #17 on: June 25, 2009, 10:50:25 AM » |
|
don't forget about the encryption  if you have access to a lab (or really just a titration apparatus) and HNO3, you can decap it easily the hard part is connecting the bonding wires to real wires once you have bonded the wires, you can easily find out which is the GND (because of the many GND pads it's connected to) and maybe even find out where VCC is - identifying should be easier from there Thanks for the advice! but why even bother? what are you going to accomplish? find another sploit?
We want to get the original firmware to be able to return drives into stock mode... don't mind me, you go girl!
Errr, what does this mean?
|
|
|
|
|
Logged
|
|
|
|
|
.ISO
|
 |
« Reply #18 on: June 25, 2009, 01:51:43 PM » |
|
To be honest, we have not even looked, 'cause we realize that it isn't exists.  To be honest, just because people think the internet have everything, here is a spoiler. It doesn't. And what do you mean "we"? You should be only addressing to yourself. We want to get the original firmware to be able to return drives into stock mode...
No one really cares about it tbh Honestly, what exactly are you trying to accomplish my dumping the firmware again, it's not going to be a big attraction, and chip decapitation is beyond what most of the users on this forum can accomplish.
|
|
|
|
« Last Edit: June 25, 2009, 01:55:18 PM by .ISO »
|
Logged
|
you wish gigaturd, as if you even know how to tell the difference between a disassembler and your vagina
Gigabite: A fool who think he is always right, and talk about how useless others are when he is really addressing to himself. Gigabite agreeing with the statement: p.s nice comment in your sig
|
|
|
|
HOMiE7
|
 |
« Reply #19 on: June 25, 2009, 03:01:29 PM » |
|
And what do you mean "we"? You should be only addressing to yourself.
We = I + my friends from service...
|
|
|
|
|
Logged
|
|
|
|
|