PDA

View Full Version : JTAG the UTV



The_ChiefGeek
08-12-2003, 09:48 PM
Has any one tried to JTag the UTV box yet?

If so, were you able to save a copy of Flash, ROM, I2C ...

BlueCop
08-14-2003, 01:33 PM
http://www.dealdatabase.com/forum/showthread.php?s=&threadid=23906

as for jtag i don't think anyone has tried it. what purpose do you think it would serve? there is only a rom chip not flashrom so you can'ts change the rom os or fetcher. but the main software element which runs the machine is stored on the harddrive and is modifiable. with the use of tools also available on this forum

also i tried monitoring the IIC bus but everytime i started up the machine would start zeroing my drive. i think it was b/c the eeprom was somehow not read correctly so the password was not generated correctly.

some people have dumped the little 2kb eeprom too and im not sure what they've found.

The_ChiefGeek
08-14-2003, 07:26 PM
ok.

I was not aware that there was no flash. But I was hoping to get the secret key from the 24c01 without lifting a any pins.

Why do I want the secret key? I am hoping that some of the XBox code that unlocks/locks the harddrives with the aid of the XBox EEPROM dump will work with the UTV drives. (LiveInfo)

David Bought
08-20-2003, 11:16 AM
Originally posted by The_ChiefGeek
ok.

I was not aware that there was no flash. But I was hoping to get the secret key from the 24c01 without lifting a any pins.

Why do I want the secret key? I am hoping that some of the XBox code that unlocks/locks the harddrives with the aid of the XBox EEPROM dump will work with the UTV drives. (LiveInfo)

Connecting a logic analyzer to the ide bus will yield the secret key, which can easily be used to unlock the drive without destroying data. The key is transmitted in the clear (i.e. there is no challenge/response mechanism).