4 ms·
Currently on mobile, will update tomorrow. Start here: http://www.visual6502.org/ http://www.visual6502.org/ Somewhere in that site they detail the step by s
by jmpe 13y ago
Currently on mobile, will update tomorrow.
Start here:
http://www.visual6502.org/ http://www.visual6502.org/
Somewhere in that site they detail the step by step process of decapping, delayering photographing and identifying the logic.
There's also a JavaScript simulator, check it out.
The CCC also had a few lectures about decapping. The most interesting one is about backside scanning the die to bypass the safety features.
- jmpe 13y agoThe CCC backside attack is here: https://www.youtube.com/watch?v=dtviiOJ-2hI https://www.youtube.com/watch?v=dtviiOJ-2hI It contains lots of info and technical details. Another one: https://www.youtube.com/watch?v=KVmpBPbGPsQ https://www.youtube.com/watch?v=KVmpBPbGPsQ This is what an actual ROM looks like: https://docs.google.com/document/d/18IGx18NQY_Q1PJVZ-bHywao9bhsDoAqoIn1rIm42nwo/edit https://docs.google.com/document/d/18IGx18NQY_Q1PJVZ-bHywao9... As the last image shows, the ROM table values are extracted by graphics processing the photo. It's also possible to dump the ROM by reading it byte by byte, but this depends on the architecture (not always possible) and is typically done for mask ROMs that contain data.
- coldpie 13y agoThanks a lot!