XboxHacker BBS
 
*
Welcome, Guest. Please login or register.
Did you miss your activation email?
May 24, 2013, 07:37:10 AM


Login with username, password and session length


Pages: 1 2 »
  Print  
Author Topic: Help to dump original firmware for Lite-on  (Read 6555 times)
HOMiE7
Master Hacker
****
Posts: 113



View Profile
« on: June 23, 2009, 02:33:34 AM »

Ok then. If c4e wouldn't give us original firmware for Lite-on then we try to dump it like he does.
What we need? We need to take of drive's controller from pcb and "undress" it, but which programmator we need to dump spi flash?

P.S. Please do not close this topic.
Logged
.ISO
Xbox Hacker
*****
Posts: 734


View Profile
« Reply #1 on: June 23, 2009, 02:49:14 AM »

It's a very, VERY complicated process, and the only way to get access to the firmware is to decap the controller with acid, and then wire up those hair thin wires connected to the silicon die to your programmer. It's a lot more different than dumping previous drives. Good luck.
« Last Edit: June 23, 2009, 02:51:43 AM by .ISO » Logged

you wish gigaturd, as if you even know how to tell the difference between a disassembler and your vagina
Gigabite: A fool who think he is always right, and talk about how useless others are when he is really addressing to himself.
Gigabite agreeing with the statement:
p.s nice comment in your sig
HOMiE7
Master Hacker
****
Posts: 113



View Profile
« Reply #2 on: June 23, 2009, 03:11:52 AM »

Can you tell me more about flash type and programmer that support this flash?
Logged
.ISO
Xbox Hacker
*****
Posts: 734


View Profile
« Reply #3 on: June 23, 2009, 03:28:31 AM »

The embedded flash is a Macronix EEPROM (forgot what model, i'll check later)
And as for the programmer, any should work as long as it supports the eeprom model that is used in the liteon drive, which is the one I was talking about above ^
The procedure? Don't even ask.
Logged

you wish gigaturd, as if you even know how to tell the difference between a disassembler and your vagina
Gigabite: A fool who think he is always right, and talk about how useless others are when he is really addressing to himself.
Gigabite agreeing with the statement:
p.s nice comment in your sig
HOMiE7
Master Hacker
****
Posts: 113



View Profile
« Reply #4 on: June 23, 2009, 04:42:49 AM »

As JungleFlasher says there are two different types of flash in Lite-on drives.

First is:
Manufacturer ID: 0xEF
Device ID: 0x11
Flash Name:  Winbond/NEX(W25P20/NX25P20)
Flash Size:  262144 bytes

W25P20 Datasheet
NX25P20 Datasheet

And second is:
Manufacturer ID: 0xC2
Device ID: 0x11
Flash Name:  MXIC(MX25L2005)   -   it seems this is a Macronix EEPROM that you are talking about
Flash Size:  262144 bytes

MX25L2005 Datasheet

Perhaps there is a third type of embedded flash but I found only these two.

---

Next question is about function of wires:

How we can determine which wire is responsible for what?
All possible combinations - 8 factorial i.e. 8!=8*7*6*5*4*3*2*1=40320 - it is pretty much...
« Last Edit: June 23, 2009, 07:35:08 AM by HOMiE7 » Logged
xboxtech
Hacker
***
Posts: 89


View Profile
« Reply #5 on: June 23, 2009, 09:03:02 AM »

Did anyone ever read these yet looking on the net I havent found any tuts on the removal of the epoxy,, that picture you have is that removed from the lite on?
Logged
HOMiE7
Master Hacker
****
Posts: 113



View Profile
« Reply #6 on: June 23, 2009, 01:04:47 PM »

Did anyone ever read these yet looking on the net I havent found any tuts on the removal of the epoxy,, that picture you have is that removed from the lite on?
We try to make it like c4eva makes. I haven't found tutorials too, but they are not needed. Steps of actions are obvious I think, but advices of knowledgeable people would be very useful to us.
Logged
.ISO
Xbox Hacker
*****
Posts: 734


View Profile
« Reply #7 on: June 24, 2009, 02:31:38 PM »

@Xboxtech: Use epoxy removal chemical, or our favorite way: heatgun

@HOMiE7
Good luck finding a tutorial, i'll give you $100 if you can.
By the way, did you really decap the chip and plan to do this?
Logged

you wish gigaturd, as if you even know how to tell the difference between a disassembler and your vagina
Gigabite: A fool who think he is always right, and talk about how useless others are when he is really addressing to himself.
Gigabite agreeing with the statement:
p.s nice comment in your sig
caster420
Master Hacker
****
Posts: 242



View Profile
« Reply #8 on: June 24, 2009, 04:36:06 PM »

All possible combinations - 8 factorial i.e. 8!=8*7*6*5*4*3*2*1=40320 - it is pretty much...

Think outside the box...  You know that these leads go to and tie into a leg of the controller.  Trace that out and figure out that the potential pinouts are.  This is the easy part.  The hard part is decapping.

Caster.
Logged
.ISO
Xbox Hacker
*****
Posts: 734


View Profile
« Reply #9 on: June 24, 2009, 06:26:10 PM »

Wait wait, Is that picture from C4E, or did he already decap the chip himself?
Also, keep in mind that the flash wires do NOT go on any of the pins
Logged

you wish gigaturd, as if you even know how to tell the difference between a disassembler and your vagina
Gigabite: A fool who think he is always right, and talk about how useless others are when he is really addressing to himself.
Gigabite agreeing with the statement:
p.s nice comment in your sig
caster420
Master Hacker
****
Posts: 242



View Profile
« Reply #10 on: June 24, 2009, 06:56:52 PM »

That is the original decap by Team Jungle.
Logged
Intersect
Master Hacker
****
Posts: 422



View Profile
« Reply #11 on: June 24, 2009, 11:56:49 PM »

I thought there was drive specific info other than the key in the firmware that was part of the reason original firmware hasn't been released?
Logged
.ISO
Xbox Hacker
*****
Posts: 734


View Profile
« Reply #12 on: June 25, 2009, 12:51:13 AM »

The main reason was due to copyright protections
Logged

you wish gigaturd, as if you even know how to tell the difference between a disassembler and your vagina
Gigabite: A fool who think he is always right, and talk about how useless others are when he is really addressing to himself.
Gigabite agreeing with the statement:
p.s nice comment in your sig
HOMiE7
Master Hacker
****
Posts: 113



View Profile
« Reply #13 on: June 25, 2009, 03:37:26 AM »

We have collected all the basic information (I think so). Now we waiting for the new unflashed Lite-on drive... Thank you guys for your help!

@Xboxtech: Use epoxy removal chemical, or our favorite way: heatgun

@HOMiE7
Good luck finding a tutorial, i'll give you $100 if you can.
By the way, did you really decap the chip and plan to do this?
To be honest, we have not even looked, 'cause we realize that it isn't exists. Smiley
When we reach the new unflashed Lite-on drive we'll try to make it.

All possible combinations - 8 factorial i.e. 8!=8*7*6*5*4*3*2*1=40320 - it is pretty much...

Think outside the box...  You know that these leads go to and tie into a leg of the controller.  Trace that out and figure out that the potential pinouts are.  This is the easy part.  The hard part is decapping.

Caster.
Thank you for your answer. We will try.
Also, could you help us to decrypt firmware or key in it at least? I think you can, because your Firmtool 1.3 can work with crypted iXtreme for Lite-on drive...

I thought there was drive specific info other than the key in the firmware that was part of the reason original firmware hasn't been released?
С4E did not give any comments about this, so we can only suspect the reason of keeping original firmware in the team hands...
Logged
idog
Master Hacker
****
Posts: 190


View Profile
« Reply #14 on: June 25, 2009, 03:54:28 AM »

While you're at it, dump the 83850c as well ? Smiley
Logged
HOMiE7
Master Hacker
****
Posts: 113



View Profile
« Reply #15 on: June 25, 2009, 04:08:21 AM »

We have all the consoles manufactured in August 2008 in our city. It isn't even Jaspers - it's f***ing Falcons! Sad
Logged
itsfakemon
Master Hacker
****
Posts: 265


View Profile
« Reply #16 on: June 25, 2009, 09:37:56 AM »

All possible combinations - 8 factorial i.e. 8!=8*7*6*5*4*3*2*1=40320 - it is pretty much...

Think outside the box...  You know that these leads go to and tie into a leg of the controller.  Trace that out and figure out that the potential pinouts are.  This is the easy part.  The hard part is decapping.

Caster.
don't forget about the encryption Smiley
if you have access to a lab (or really just a titration apparatus) and HNO3, you can decap it easily
the hard part is connecting the bonding wires to real wires
once you have bonded the wires, you can easily find out which is the GND (because of the many GND pads it's connected to) and maybe even find out where VCC is - identifying should be easier from there
but why even bother? what are you going to accomplish? find another sploit?

don't mind me, you go girl!
« Last Edit: June 25, 2009, 09:44:06 AM by itsfakemon » Logged

excuse me, I'm French...
HOMiE7
Master Hacker
****
Posts: 113



View Profile
« Reply #17 on: June 25, 2009, 10:50:25 AM »

don't forget about the encryption Smiley
if you have access to a lab (or really just a titration apparatus) and HNO3, you can decap it easily
the hard part is connecting the bonding wires to real wires
once you have bonded the wires, you can easily find out which is the GND (because of the many GND pads it's connected to) and maybe even find out where VCC is - identifying should be easier from there
Thanks for the advice!

but why even bother? what are you going to accomplish? find another sploit?
We want to get the original firmware to be able to return drives into stock mode...

don't mind me, you go girl!
Errr, what does this mean?
Logged
.ISO
Xbox Hacker
*****
Posts: 734


View Profile
« Reply #18 on: June 25, 2009, 01:51:43 PM »

Quote
To be honest, we have not even looked, 'cause we realize that it isn't exists. Smiley

To be honest, just because people think the internet have everything, here is a spoiler. It doesn't.
And what do you mean "we"? You should be only addressing to yourself.

We want to get the original firmware to be able to return drives into stock mode...

No one really cares about it tbh

Honestly, what exactly are you trying to accomplish my dumping the firmware again, it's not going to be a big attraction, and chip decapitation is beyond what most of the users on this forum can accomplish.
« Last Edit: June 25, 2009, 01:55:18 PM by .ISO » Logged

you wish gigaturd, as if you even know how to tell the difference between a disassembler and your vagina
Gigabite: A fool who think he is always right, and talk about how useless others are when he is really addressing to himself.
Gigabite agreeing with the statement:
p.s nice comment in your sig
HOMiE7
Master Hacker
****
Posts: 113



View Profile
« Reply #19 on: June 25, 2009, 03:01:29 PM »

And what do you mean "we"? You should be only addressing to yourself.
We = I + my friends from service...
Logged
Pages: 1 2 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC

Valid XHTML 1.0! Valid CSS! Dilber MC Theme by HarzeM