Close

Results 1 to 4 of 4
  1. #1
    DF Probation macmilm's Avatar
    Join Date
    Dec 2000
    Location
    Suffolk, UK
    Posts
    3,817
    Thanks
    1,662
    Thanked:        1,295
    Karma Level
    558

    Info JTAG after kernel 8XXX

    Saw a thread on another forum from a user called 'sdeens' talking about the theoretical possibility of the above and wondered what some of you fellow df'rs thought about this.

    Dont wanna take credit for another blokes theorising so have pasted below most of what he said, pretty interesting and worth a read if nothing else.
    Also posted link to original thread below.

    ---------------------------------

    SDEENS
    "If they are blowing OTP registers in the CPU via these kernel udpates (e-fuses) then theoretcially: YES they can be "jumpered" with a GLITCHING daughter board solution that can glitch past the blow fuses that are disabling the HYNIX TSOP/ nand from running any custom code.

    but the question is: can such a daughter boot loader board be designed and have they traced back the necessary installation solder points on mobo that are tied to the underside of the CPU-BGA?

    Precident:

    We used bootloader daughter boards for our physically damaged or blown satellite TV "H cards" about 10 years ago when DirecTV was blowing OTP/e-fuse registers inside the card. It was called the "Black Sunday" bootloader boards and they simply glitched past the blown e-fuse using a simple Atmel 2313 chip with custom glitching code on board. The europeans first made the discovery...STUDLOVE was the developer.

    So in theory it should be possible with the addition of a 3rd party Boot-Loader daughter board that can "circumvent and spoof" the blown e-fuse via some glitching protocol tied directly to the CPU via a surface MOBO solder point that is traced out. Maybe they have NOT found such solder points after decaping the CPU BGA?
    "

    Link to original thread:

    http://tech-modz.net/showthread.php?t=573

  2. #2
    DF VIP Member raelmadrid's Avatar
    Join Date
    Apr 2002
    Location
    Redmond, WA
    Posts
    4,561
    Thanks
    818
    Thanked:        703
    Karma Level
    536

    Default Re: JTAG after kernel 8XXX

    the 2nd post pretty much sums it up

  3. #3
    DF Super Moderator BIG-TED's Avatar
    Join Date
    May 2001
    Location
    Leics UK
    Posts
    2,022
    Thanks
    447
    Thanked:        881
    Karma Level
    422

    Default Re: JTAG after kernel 8XXX

    This idea has been tossed about for a long time, nothing has ever came from it because of what is involved. The cost will out way the result.

    Ted
    Lots of my repairs and pictures of retro stuff on my twitter.

    https://twitter.com/Big_ted1?t=s9zEZ...Z-npEyeKA&s=09

  4. #4
    DF Probation macmilm's Avatar
    Join Date
    Dec 2000
    Location
    Suffolk, UK
    Posts
    3,817
    Thanks
    1,662
    Thanked:        1,295
    Karma Level
    558

    Default Re: JTAG after kernel 8XXX

    I guess there was a lot more money/incentive with the satellite side of things that made it viable for them...
    Thought it was an interesting idea regardless.
    Just me 2p.

Similar Threads

  1. Jtag Advice
    By ray_46646 in forum Forum Suggestions & Feedback
    Replies: 4
    Last Post: 21st February 2005, 09:33 PM
  2. jtag on sale now
    By DAVEY26 in forum Digital & Cable TV
    Replies: 21
    Last Post: 8th January 2005, 04:23 PM
  3. JTag???
    By satzzz in forum Digital & Cable TV
    Replies: 4
    Last Post: 2nd July 2003, 02:07 PM
  4. Atmel flash chips progger/jtag info?
    By wassapdude in forum Digital Satellite TV
    Replies: 8
    Last Post: 7th January 2003, 04:13 PM
  5. kernel problem
    By n0k1a in forum PC Problems
    Replies: 2
    Last Post: 17th September 2002, 10:45 PM

Social Networking Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •