4 ms·
Thanks for the link, I will give it a proper read first thing tomorrow morning. From my very quick skim your attack is far more advanced than what I did. It was
by rft 3y ago
Thanks for the link, I will give it a proper read first thing tomorrow morning. From my very quick skim your attack is far more advanced than what I did. It was enough to just set some registers via the debugger and single step an instruction. With just a single load gadget I could dump the entire ROM. I did not bother with a write gadget as for the Nordic SoC you can just reflash the extracted image without enabling protection and then go from there.
I personally did not know about this article, I have not touched the Cypress eco system much, if at all. I linked to a previous article that this project was based on [1].
What I find interesting is that Cypress uses a similar split ROM as Nordic for some kind of system code and data like calibration values. Really neat to see how other vendors do this.
[1] https://blog.includesecurity.com/2015/11/firmware-dumping-technique-for-an-arm-cortex-m0-soc/ https://blog.includesecurity.com/2015/11/firmware-dumping-te...