3 ms·
I seem to recall that imaging the bootloader ROM straight off the silicon was how the original Gameboy's bootloader was finally pulled out. I just forget who d
by Two9A 13y ago
I seem to recall that imaging the bootloader ROM straight off the silicon was how the original Gameboy's bootloader was finally pulled out.
I just forget who did it, which is unfortunate.
- coldpie 13y agoI spent a fair bit of time trying to find an article or something about this, but came up empty. I was especially curious to know how you can decode the program's bits from the silicon. I found a similar idea here: http://members.iinet.net.au/~lantra9jp1/gurudumps1/decap/index.html http://members.iinet.net.au/~lantra9jp1/gurudumps1/decap/ind... The photo in the upper-right looks like it could reasonably be turned into binary, if you knew what you were looking at. Anyone have any more info about how this actually works?
- jmpe 13y agoCurrently on mobile, will update tomorrow. Start here: http://www.visual6502.org/ http://www.visual6502.org/ Somewhere in that site they detail the step by step process of decapping, delayering photographing and identifying the logic. There's also a JavaScript simulator, check it out. The CCC also had a few lectures about decapping. The most interesting one is about backside scanning the die to bypass the safety features.
- jmpe 13y agoThe CCC backside attack is here: https://www.youtube.com/watch?v=dtviiOJ-2hI https://www.youtube.com/watch?v=dtviiOJ-2hI It contains lots of info and technical details. Another one: https://www.youtube.com/watch?v=KVmpBPbGPsQ https://www.youtube.com/watch?v=KVmpBPbGPsQ This is what an actual ROM looks like: https://docs.google.com/document/d/18IGx18NQY_Q1PJVZ-bHywao9bhsDoAqoIn1rIm42nwo/edit https://docs.google.com/document/d/18IGx18NQY_Q1PJVZ-bHywao9... As the last image shows, the ROM table values are extracted by graphics processing the photo. It's also possible to dump the ROM by reading it byte by byte, but this depends on the architecture (not always possible) and is typically done for mask ROMs that contain data.
- coldpie 13y agoThanks a lot!
- azonenberg 13y agoSee my lecture notes: http://security.cs.rpi.edu/courses/hwre-spring2014/Lecture9_MaskROM.pdf http://security.cs.rpi.edu/courses/hwre-spring2014/Lecture9_...