September 19th, 2013, 10:07
louis wrote:l
to study the unpacking function, I reversed the code in Z Block (so called Kernel Loader). In this firmware, the Flash it's not mapped to the address space (as in dejan's mcu 0xFFF00000...a later model) (from what I saw till now). all the access to flash is done live, by reading the Flash Port. the functions handling reading the flash port (port base 0x100080A0) are at the end of the bootstrap (0xFFFF0000);
September 19th, 2013, 11:33
September 19th, 2013, 14:48
Doomer wrote:If you have SPI flash (aka 8-pin flash chip) that can be the answer
0xFFF00000 is mapped address of built-in flash
Hint: SPI commands are very well documented
September 19th, 2013, 22:32
September 20th, 2013, 3:46
September 20th, 2013, 15:20
September 25th, 2013, 1:55
September 25th, 2013, 3:12
September 30th, 2013, 19:55
March 4th, 2014, 7:13
fayn wrote:After playing with two PCBs for a while they started talking to me bit by bit
MCU's tested: 88i9146 and 88i9045
Speed: 115200 8N1
Have fun!
March 4th, 2014, 7:34
guru wrote:TX/RX also used in SATA interface. Nothing to do with UART RS232
March 25th, 2014, 16:17
March 25th, 2014, 16:31
Galena44 wrote:@louis
Not sure what processor you have. The serial connection is brought out to the jumper header.
April 8th, 2015, 12:27
Powered by phpBB © phpBB Group.