XboxHacker BBS
 
*
Welcome, Guest. Please login or register.
Did you miss your activation email?
June 19, 2013, 02:41:22 PM


Login with username, password and session length


Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 »
  Print  
Author Topic: Project to dump the new BenQ drive - VAD6038  (Read 193272 times)
bowser222
Member
**
Posts: 45


View Profile
« Reply #40 on: March 25, 2007, 01:41:00 PM »

hey tmf did you build your reader/writer for the spi?if got schems?also off topic.i pulled my 360 apart today(not the 1st time) and i looked at the southbride and said holy $#!t tmf must be some good with his rework station
c ya Grin
Logged
MODFREAKz
Master Hacker
****
Posts: 440



View Profile
« Reply #41 on: March 25, 2007, 02:09:59 PM »

Quote from: Team MODFREAKz
MTKFLASH get the error status 73 should be 50. but win update programm works fine (only flashing)

sorry for small typo!

MTKFLASH error report is:

Status 73, should be 70.
Logged

bowser222
Member
**
Posts: 45


View Profile
« Reply #42 on: March 25, 2007, 02:27:33 PM »

Is their anything out for the VAD6037?where are the keys stored?and tmf are you using a homemade spi eeprom reader?
''Bowser
Logged
jumba
Master Hacker
****
Posts: 167


View Profile
« Reply #43 on: March 25, 2007, 06:26:57 PM »

Thanx, 10 4 gary. Carn't lay my hands on VAD6038 so can someone trace out the connection between SPI mt1359se. Please post or PM me.
Logged
Iriez
Hacker
***
Posts: 94


View Profile
« Reply #44 on: March 25, 2007, 07:05:41 PM »

got new SATA PC drive again!!!
this time it is a Philips drive, looks like BenQ VAD6038

same laser, chipset and SPI rom

firmware DD01, OD7I and photos will follow!!

MTKFLASH get the error status 73 should be 50. but win update programm works fine (only flashing)


btw. we have now a SPI programmer to dump the firmware, so if someone could send his SPI rom from VAD6038, that would be great!!

Erm, perhaps im misunderstanding? You said this pc sata dvdrom has the same chipset/spi as the VAD6038...if that is the case, would not the VAD6038 be programmable by this same win software? Just not dumpable, correct?

If that is the case, then the winsoftware has the neccessary instructions to communicate with that specific SPI, just needs to be decompiled to be properly understood, so that the instructions can be used in a dumping.

Logged
garyopa
Xbox Hacker
*****
Posts: 582


Oasis Pensive Abacutors


View Profile WWW
« Reply #45 on: March 26, 2007, 10:21:39 AM »

Thanx, 10 4 gary. Carn't lay my hands on VAD6038 so can someone trace out the connection between SPI mt1359se. Please post or PM me.

It looks the same as the PM you send me regarding the 943 SPI usage.

I will PM you the details later today.
Logged

garyopa
Xbox Hacker
*****
Posts: 582


Oasis Pensive Abacutors


View Profile WWW
« Reply #46 on: March 26, 2007, 10:24:24 AM »

got new SATA PC drive again!!!
this time it is a Philips drive, looks like BenQ VAD6038

same laser, chipset and SPI rom

firmware DD01, OD7I and photos will follow!!

MTKFLASH get the error status 73 should be 50. but win update programm works fine (only flashing)


btw. we have now a SPI programmer to dump the firmware, so if someone could send his SPI rom from VAD6038, that would be great!!

Erm, perhaps im misunderstanding? You said this pc sata dvdrom has the same chipset/spi as the VAD6038...if that is the case, would not the VAD6038 be programmable by this same win software? Just not dumpable, correct?

If that is the case, then the winsoftware has the neccessary instructions to communicate with that specific SPI, just needs to be decompiled to be properly understood, so that the instructions can be used in a dumping.



There is about two WIN-based programs which will FLASH the BenQ drive with no problems,
the only problem is both are designed as "Upgraders" or "Updaters" and they only do FLASHing,
and don't have any option to SAVE or BACKUP the firmware, so they have no use since the DVD key would be lost in the process.

There is other WIN-based program which will do both, but only if the drive has a drive letter,
and the BenQ does not add one, but it seems to report the same bad error status like the
Hitachi drives when booting into Slax with a ModeB option, except the ModeB does not of course support BenQ drive.
Logged

bowser222
Member
**
Posts: 45


View Profile
« Reply #47 on: March 26, 2007, 04:36:32 PM »

hey tmf out of topic but i got a 360 mobo if ya want it.it give error 0003.you just gotta pay shipping
c ya
Logged
BurnOmatic
Master Hacker
****
Posts: 197


Administrator


View Profile
« Reply #48 on: March 27, 2007, 02:59:22 PM »

got new SATA PC drive again!!!
this time it is a Philips drive, looks like BenQ VAD6038

same laser, chipset and SPI rom

firmware DD01, OD7I and photos will follow!!

MTKFLASH get the error status 73 should be 50. but win update programm works fine (only flashing)


btw. we have now a SPI programmer to dump the firmware, so if someone could send his SPI rom from VAD6038, that would be great!!

Erm, perhaps im misunderstanding? You said this pc sata dvdrom has the same chipset/spi as the VAD6038...if that is the case, would not the VAD6038 be programmable by this same win software? Just not dumpable, correct?

If that is the case, then the winsoftware has the neccessary instructions to communicate with that specific SPI, just needs to be decompiled to be properly understood, so that the instructions can be used in a dumping.



There is about two WIN-based programs which will FLASH the BenQ drive with no problems,
the only problem is both are designed as "Upgraders" or "Updaters" and they only do FLASHing,
and don't have any option to SAVE or BACKUP the firmware, so they have no use since the DVD key would be lost in the process.

There is other WIN-based program which will do both, but only if the drive has a drive letter,
and the BenQ does not add one, but it seems to report the same bad error status like the
Hitachi drives when booting into Slax with a ModeB option, except the ModeB does not of course support BenQ drive.


so which windows program would that be OPA, so i can go hunt it down ?
Logged

MODFREAKz
Master Hacker
****
Posts: 440



View Profile
« Reply #49 on: March 27, 2007, 05:02:46 PM »

ok here is that drive!!

Philips DROM6316
Chipset:  MediaTek MT1359SE
F/W Chip:  Winbond W25B20A SPI
RAM Chip:  AMIC A428316S-25
Firmware:  DD01 and OD7I
H/W:  00  (A03 is also available)

This drive has also a serial port!!
tried program like MTKTool or Hypertrm without success at the moment.

ach and here is the windows flash tool: FlashTool



       
Logged

jumba
Master Hacker
****
Posts: 167


View Profile
« Reply #50 on: March 27, 2007, 06:05:09 PM »

Looks like this rom is available in Dells. Any chance to post link to hi res pix of pcb?
Logged
caster420
Master Hacker
****
Posts: 242



View Profile
« Reply #51 on: March 27, 2007, 07:04:18 PM »

Click on the image(s).
Logged
bowser222
Member
**
Posts: 45


View Profile
« Reply #52 on: March 29, 2007, 03:29:47 PM »

if anyone here doesnt mind please sned me an spi from your benq as i have a willem with soic adaptor and can dump these chips
C ya
Logged
MODFREAKz
Master Hacker
****
Posts: 440



View Profile
« Reply #53 on: March 29, 2007, 03:43:06 PM »

sorry to say that, but willem programmer does not support 2MBit and 3,3V SPI
Logged

bowser222
Member
**
Posts: 45


View Profile
« Reply #54 on: March 29, 2007, 05:47:17 PM »

Really?i could have swore.anyways.Tmf when you said about how you enable flashing via 2 points with probes and then rx and tx is routed to the unused pins.does this method "work"?have you gotten a dump yet.and are you using a homemade reader?also where are the keys stored at?
Thanks
c ya
''bowser
Logged
garyopa
Xbox Hacker
*****
Posts: 582


Oasis Pensive Abacutors


View Profile WWW
« Reply #55 on: April 24, 2007, 08:32:44 PM »

Really?i could have swore.anyways.Tmf when you said about how you enable flashing via 2 points with probes and then rx and tx is routed to the unused pins.does this method "work"?have you gotten a dump yet.and are you using a homemade reader?also where are the keys stored at?
Thanks
c ya
''bowser

So far I have not see a retail BenQ drive, just the pre-production models, and dumping them is if no use as no AES code and no drive key.

Hopefully someday we will see a real retail BenQ drive here in Canada and we can get to work on more information and better tools.
Logged

garyopa
Xbox Hacker
*****
Posts: 582


Oasis Pensive Abacutors


View Profile WWW
« Reply #56 on: May 01, 2007, 03:38:25 PM »

Thanks to a customer in Vancouver, them mailed me their "Elite" BenQ VAD6038 drive
and I will be dumping this drive ASAP, and suppling the retail firmware needed to the
needed parties.

More news later this week...
Logged

glaze83
Xbox Hacker
*****
Posts: 534


View Profile
« Reply #57 on: May 02, 2007, 01:50:48 AM »

Glad to hear you got it Cheesy
Logged
jelle2503
Xbox Hacker
*****
Posts: 1686


elitist prick


View Profile
« Reply #58 on: May 08, 2007, 06:50:35 AM »

Quote
and they only do FLASHing, and don't have any option to SAVE or BACKUP the firmware, so they have no use since the DVD key would be lost in the process.

so if you were to determine the location of the drivekey in the firmware, wouldn't you be able to make the flashprogram flash around the key and version string sectors, just like the hitachi?
i'm stupid aren't i  Cheesy
Logged

*
caster420
Master Hacker
****
Posts: 242



View Profile
« Reply #59 on: May 08, 2007, 11:09:19 AM »

Quote
and they only do FLASHing, and don't have any option to SAVE or BACKUP the firmware, so they have no use since the DVD key would be lost in the process.

so if you were to determine the location of the drivekey in the firmware, wouldn't you be able to make the flashprogram flash around the key and version string sectors, just like the hitachi?
i'm stupid aren't i  Cheesy

I would take a stab in the dark and say that the key and version strings are probably in or around the same offsets.  However, this doesnt change the way that the firmware is written to the drive.  The reason hitachi's only flash certain sectors is that it was the only workaround that SeventhSon found, using his peek/poke technique.  Flashing a samsung is done in a different method and so to say that we can flash it a different way and only overwrite certain sectors could only be done if such commands were available through the controller on the drive.  Pretty simple to say, but in reality, may not be feasible at all.

Caster.
Logged
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC

Valid XHTML 1.0! Valid CSS! Dilber MC Theme by HarzeM