XboxHacker BBS
 
*
Welcome, Guest. Please login or register.
Did you miss your activation email?
May 22, 2013, 04:48:47 AM


Login with username, password and session length


Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 »
  Print  
Author Topic: 0225/0401/0272 write protection beated by russian hackers !!!  (Read 30185 times)
modguru
Master Hacker
****
Posts: 172


View Profile WWW
« Reply #200 on: August 01, 2011, 09:50:26 AM »

if you decap the ic it is possible to tell us witch pin is the write protect to lift it from the pcb,  and to solder a wire and a double swich to vcc or gnd  depents from the situation ?
thanks ..
Logged

jenipapo
Member
**
Posts: 12


View Profile
« Reply #201 on: August 01, 2011, 10:09:33 AM »

if you decap the ic it is possible to tell us witch pin is the write protect to lift it from the pcb,  and to solder a wire and a double swich to vcc or gnd  depents from the situation ?
thanks ..
Oggy said #36 is the WP.
http://forums.xbox-scene.com/index.php?showtopic=733580
Logged
CoDeFl@sher
Hacker
***
Posts: 89


View Profile
« Reply #202 on: August 01, 2011, 10:14:33 AM »

Hi,
With acid, in a mt1335, i disconnected the wp wire from gnd and wired it to vcc.
I was able to unlock the winbond spi and now i would like to relock it.
I'm wondering if it is possible to modify the russian tool to send the lock cdb?
Regards

which acid did u used, and can u give detail picture of wp wire that need to be cut? if u can pls post high resolution pics and acid that u used.

Will like to try this, and what can i use to secure wires after decaping with acid ? is it ok to use hotglue to secure the pit that is opened with acid?
I don't remember if it is nitric or sulfuric, i'll have a look on the label.
For pictures, i'll do my best, but i only have a 20x magnifier.
The wire i disconnected is the longest one, which we can see on geremia's picture.
I glued a thin wire on the chip and soldered it on the wp wire.
Be careful, acid is highly dangerous and soldering very hard.
On another mt1335 chip, i disconnected wp from gnd and tried the russian tool with an adjustable resistor.
At 1.9 ohms, i was able to unlock the winbond spi.
What i did not understood, is that when i flashed with lt firmware, it was locked again. Backups were working fine.
At this time, i thought that JF relocked the spi, but with the chip unlocked by wiring wp to vcc, it is different.
Saddly, i do not have this drive anymore (used for flash).


Bonx please forgive my lack of faith, but it's hard to believe without evidence. show us something of your work!
Logged
modguru
Master Hacker
****
Posts: 172


View Profile WWW
« Reply #203 on: August 01, 2011, 10:48:17 AM »

ok i have lift the 36 pin  now for that i have read , i must conect a wire on the pin  and to connect it to vcc 3.3 v is that corect ?
Logged

bonx
Member
**
Posts: 23


View Profile
« Reply #204 on: August 01, 2011, 11:44:41 AM »

Hi,
With acid, in a mt1335, i disconnected the wp wire from gnd and wired it to vcc.
I was able to unlock the winbond spi and now i would like to relock it.
I'm wondering if it is possible to modify the russian tool to send the lock cdb?
Regards

which acid did u used, and can u give detail picture of wp wire that need to be cut? if u can pls post high resolution pics and acid that u used.

Will like to try this, and what can i use to secure wires after decaping with acid ? is it ok to use hotglue to secure the pit that is opened with acid?
I don't remember if it is nitric or sulfuric, i'll have a look on the label.
For pictures, i'll do my best, but i only have a 20x magnifier.
The wire i disconnected is the longest one, which we can see on geremia's picture.
I glued a thin wire on the chip and soldered it on the wp wire.
Be careful, acid is highly dangerous and soldering very hard.
On another mt1335 chip, i disconnected wp from gnd and tried the russian tool with an adjustable resistor.
At 1.9 ohms, i was able to unlock the winbond spi.
What i did not understood, is that when i flashed with lt firmware, it was locked again. Backups were working fine.
At this time, i thought that JF relocked the spi, but with the chip unlocked by wiring wp to vcc, it is different.
Saddly, i do not have this drive anymore (used for flash).


Bonx please forgive my lack of faith, but it's hard to believe without evidence. show us something of your work!
I understand.
Here's a few pictures, i did quickly.
http://Http://gbonx.free.fr/spip.php?article36
Logged
bonx
Member
**
Posts: 23


View Profile
« Reply #205 on: August 01, 2011, 11:47:33 AM »

ok i have lift the 36 pin  now for that i have read , i must conect a wire on the pin  and to connect it to vcc 3.3 v is that corect ?
No! It would be too simple.
Spi gnd and mtk gnd are connected on this pin.
If you send vcc on this pin you'll have a short circuit.
Logged
bonx
Member
**
Posts: 23


View Profile
« Reply #206 on: August 01, 2011, 11:56:06 AM »

Really? That worked?

Here's a version of the russian tool that can lock the spi:
http://www.rigid360.co.uk/ccount/click.php?id=11

Note it sends 0x9C to the status register but It should maybe be 0x8C

Let me know if it works

I tried your version, it works great.
I relocked and re-unlocked with no problem.
The spi status was 0x9C instead of 0x8C as you said. Could you compile a version with an input field for status register or change it to 0x8C ?
Regards
Logged
tingedace
Member
**
Posts: 27


View Profile
« Reply #207 on: August 01, 2011, 12:49:26 PM »

Yes, sure. Gimme a couple of hours.
Logged
tingedace
Member
**
Posts: 27


View Profile
« Reply #208 on: August 01, 2011, 01:54:50 PM »

I tried your version, it works great.
I relocked and re-unlocked with no problem.
The spi status was 0x9C instead of 0x8C as you said. Could you compile a version with an input field for status register or change it to 0x8C ?
Regards

Done, just re-download from the same link.
Logged
bonx
Member
**
Posts: 23


View Profile
« Reply #209 on: August 01, 2011, 04:28:25 PM »

Done, just re-download from the same link.
Wouah! Works perfectly.
I was able to lock to 0x8c and unlock again (only when the switch is on vcc)
Logged
_javi_
Member
**
Posts: 19


View Profile
« Reply #210 on: August 01, 2011, 06:28:27 PM »

congrats bonx, it seems u made it!

so cutting the trace for WE inside the decapped chip and doing the russian method with 1.9ohm (for winbond) is all thats needed to flash it?
could you plz explain how to identify that trace in the chip?

well done!
Logged
asapreta
Hacker
***
Posts: 92


View Profile
« Reply #211 on: August 01, 2011, 07:20:33 PM »

congrats bonx, it seems u made it!

so cutting the trace for WE inside the decapped chip and doing the russian method with 1.9ohm (for winbond) is all thats needed to flash it?
could you plz explain how to identify that trace in the chip?

well done!

Yes, he made it, but its not THAT simple to get there.  Grin
As the WE point is grounded together to another point, its not that simple, we can`t lift a pin and make the magic happens.

But for sure its a start.
Logged
_javi_
Member
**
Posts: 19


View Profile
« Reply #212 on: August 01, 2011, 07:48:30 PM »

i know  Wink
sounds easy but it's a difficult task. i know it's not lifting a pin, but cutting a trace from a decapped chip.

time to look for the dremel... like the D2B wii chipset with legs cut, grinded to expose the inner traces.
Logged
bonx
Member
**
Posts: 23


View Profile
« Reply #213 on: August 01, 2011, 08:59:17 PM »

i know  Wink
sounds easy but it's a difficult task. i know it's not lifting a pin, but cutting a trace from a decapped chip.

time to look for the dremel... like the D2B wii chipset with legs cut, grinded to expose the inner traces.
I was not sure if the mtk chip was keeping somewhere the spi status and avoiding any attempt to change status.
I can confirm that changing wp state just before clicking the unlock button is enough.
Logged
misterfly
Hacker
***
Posts: 73



View Profile
« Reply #214 on: August 02, 2011, 12:17:00 AM »

Hi,
With acid, in a mt1335, i disconnected the wp wire from gnd and wired it to vcc.
I was able to unlock the winbond spi and now i would like to relock it.
I'm wondering if it is possible to modify the russian tool to send the lock cdb?
Regards

which acid did u used, and can u give detail picture of wp wire that need to be cut? if u can pls post high resolution pics and acid that u used.

Will like to try this, and what can i use to secure wires after decaping with acid ? is it ok to use hotglue to secure the pit that is opened with acid?
I don't remember if it is nitric or sulfuric, i'll have a look on the label.
For pictures, i'll do my best, but i only have a 20x magnifier.
The wire i disconnected is the longest one, which we can see on geremia's picture.
I glued a thin wire on the chip and soldered it on the wp wire.
Be careful, acid is highly dangerous and soldering very hard.
On another mt1335 chip, i disconnected wp from gnd and tried the russian tool with an adjustable resistor.
At 1.9 ohms, i was able to unlock the winbond spi.
What i did not understood, is that when i flashed with lt firmware, it was locked again. Backups were working fine.
At this time, i thought that JF relocked the spi, but with the chip unlocked by wiring wp to vcc, it is different.
Saddly, i do not have this drive anymore (used for flash).
Lol bonx you decapeed  (and not know the acid?)and soldered inside?HuhHuh? i think you never see 1 decapped,and im sure you not hawe a machine whirebonding for soldering

Gold Whire is 25 micron and see now at 35x


« Last Edit: August 02, 2011, 12:32:47 AM by misterfly » Logged
modguru
Master Hacker
****
Posts: 172


View Profile WWW
« Reply #215 on: August 02, 2011, 12:30:26 AM »

my thoght is that to lift the pin is like to cut the wire from inside exept if the WP it is not going straight to a pin but go to another part of the ic .. can anyone confirm that ?
Logged

misterfly
Hacker
***
Posts: 73



View Profile
« Reply #216 on: August 02, 2011, 12:42:26 AM »

my thoght is that to lift the pin is like to cut the wire from inside exept if the WP it is not going straight to a pin but go to another part of the ic .. can anyone confirm that ?
if you lift the pin is really impossible cut only 1 whire you not know the dept and again the wire is 25 μm impossible cut only this,inside u hawe a lot of other whire to go mt .....really really really small (or invisible whitout microscope)
« Last Edit: August 02, 2011, 12:46:10 AM by misterfly » Logged
glaze83
Xbox Hacker
*****
Posts: 534


View Profile
« Reply #217 on: August 02, 2011, 12:44:54 AM »

grounds are linked internally -- it's really just for heat dissipation
Logged
bluemimmos
Hacker
***
Posts: 70

Its me, me, me and only me...... :D


View Profile
« Reply #218 on: August 02, 2011, 01:41:16 AM »

well, bonx the picture is now not accessible??
can u make the pictures of all the steps you performed, so we can have a look at the comp-lexity?
is removing the chip necessary before doing this step. i think if we remove and decap , then it will be a problem when putting the chip back in board.
Cheesy
anyway your full pictures with step will be a good guide to semi pros.
Logged
bonx
Member
**
Posts: 23


View Profile
« Reply #219 on: August 02, 2011, 02:20:56 AM »

my thoght is that to lift the pin is like to cut the wire from inside exept if the WP it is not going straight to a pin but go to another part of the ic .. can anyone confirm that ?
if you lift the pin is really impossible cut only 1 whire you not know the dept and again the wire is 25 μm impossible cut only this,inside u hawe a lot of other whire to go mt .....really really really small (or invisible whitout microscope)

The wp wire is on the left, and you can see the solder.
I do not have a bondering machine and never said that.
Do you want a video with locking and unlocking steps?
« Last Edit: August 02, 2011, 02:24:44 AM by bonx » Logged
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC

Valid XHTML 1.0! Valid CSS! Dilber MC Theme by HarzeM