Discussion:
weaving machine hacking was:[Re: EPROM / IC Burner]
Yair Reshef
2014-09-24 09:19:48 UTC
Permalink
hey
i was asked by my local college to hack their industrial weaving machine.
the problem
only method to upload patterns to the machine is by export to
image/text file from a pc and write it line by line to the UV EPROM
card > . http://imgur.com/a/TeQcG#8
that means countless hours of writing line by line into the eeprom
writer > http://imgur.com/a/TeQcG#0

what way would you attack this problem?


PDF of EEPROM -
http://www.st.com/web/en/resource/technical/document/datasheet/CD00000515.pdf

On Wed, Sep 24, 2014 at 12:06 PM, Udi Finkelstein
http://blackstufflabs.com/2013/11/18/conversione-programmatore-tl866cs-a-tl866a/?lang=en
http://www.eevblog.com/forum/blog/eevblog-411-minipro-tl866-universal-programmer-review/
notice that there are two models, the TL866 and the TL866CS which lacks
the ICSP programming port, and is cheaper by 10$-15$. there is a hack for
converting a CS model to noon - CS, but since the hack is at least 6 months
old, the manufacturer may have already implemented countermeasures. so if
you don't need ICSP programming, want to save a few bucks, and be
adventurous, pick up the CS model.
Hardcore :-)
I will check the data sheet of the chip,
Ibeleive it needs to be written there.
I think I will also order from Ebay the one you said you have
I had seen the TL866 at about 50$
Thank you very much for the help.
It's not a question of passwords. Usually when a Micro is
read-protected, it simply cannot be read back, period.
The only way to crack these kind of micros is either via an intended
backdoor in the firmware, unsecure code (buffer overflow on your micro??) -
both are unlikely, but the common tricks are to play with the power supply.
sometimes running it on a marginal voltage can be used to bypass the
security uses.
In extreme cases, you can find examples where people have decapped the
IC (using hot nitric acid), shielded part of the die and the exposed it to
UV to clear the security fuse.
http://www.bunniestudios.com/blog/?page_id=40
Thanks Udi,
I will check the numbers of my PICs
and I really don't know if they have password,
I hope not :-(
Hi Gal,
I don't visit TAMI very frequently, I'm mostly active on the mailing
list (not facebook).
As for your PICs, it would help if you specify the exact model you
have.
Do these have a code protection option, and do you know if your PICs
are protected?
If yes, I don't think I can help much (there are techniques for
bypassing that, but they are not straightforward, and I'm not an expert on
the subject).
Udi
Udi,
I would really like to sit with you some time in the close future and
talk about that
or even try to read the info from some pics I have.
When you will have the time.
בתאריך יום שלישי, 23 בספטמבר 2014 16:30:38 UTC+3, מאת Udi
I have two programmers - one is an old Labtool 48, which requires
Windows XP at most and stopped receiving updates years ago, and the other is
a newer chinese TL866
(http://www.eevblog.com/forum/blog/eevblog-411-minipro-tl866-universal-programmer-review/).
They are not at TAMI, but if you have specific needs maybe we can arrange
something. I also have an old EPROM eraser (with a UV lamp), but I've never
checked it.
Ahh... the old days... When I was really young (high school, in the
mid-80's) I used to work on various commodore hardware, mostly adding Hebrew
characters to commodore dot matrix printers. I had a Promenade C1 programmer
for my C64
(http://mikenaberezny.com/hardware/c64-128/promenade-c1-eprom-burner/) , and
my debug cycle was a function of the # of EPROMs I had at hand, and the
cycle time of the EPROM erase UV lamp I had :-)
And remember, you can always write a '1' bit to '0' but not the
other way around, so I would make incremental changes and test them.
I think my biggest achievement was neutralizing a checksum check at
the beginning of the EPROM, with the firmware written for an obscure NEC
8-bit controller. I fed the mnemonics and opcodes into a primitive C64
database I had so I could sort them by opcode and have a more convenient
table for my pencil and paper disassembly.
Udi
Hi Jr,
This is what I am looking for,
I just don't want to buy a new one and using it every two years.
I know it is some sort of ancient history but still, there are many
working things with burned IC's that needs to be replace.
I have some work parts that there are a few PIC chip's that I need
to replace but the manufacturer will not sell them only
a new set that cost about 600 Euro.
I will check it next time I will be at TAMI,
Thanks
there is actually an eprom burner with several vintage IC's having
clear windows on them
i think it was last in the white shelves on left back wall of
hackerspace, around the 3rd/4th shelf
this is ancient tech btw , maybe not what you were looking for??
On Monday, September 22, 2014 4:05:52 AM UTC-4, Udi Finkelstein
What IC do you specifically need to burn?
Hi all,
I am new here and wanted to know if there is an EPROM/IC burner
at TAMI ?
Thanks,
Gal
--
archive and web access
https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת את ההודעה הזו מפני שאתה רשום לקבוצה 'TAMI' של קבוצות
Google.
כדי לבטל את הרישום לקבוצה הזו ולהפסיק לקבל ממנה דוא"ל, שלח דוא"ל
לאפשרויות נוספות, בקר ב-https://groups.google.com/d/optout.
--
archive and web access
https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת את ההודעה הזו מפני שאתה רשום לקבוצה 'TAMI' של קבוצות Google.
כדי לבטל את הרישום לקבוצה הזו ולהפסיק לקבל ממנה דוא"ל, שלח דוא"ל אל
לאפשרויות נוספות, בקר ב-https://groups.google.com/d/optout.
--
archive and web access
https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת את ההודעה הזו מפני שאתה רשום לקבוצה 'TAMI' של קבוצות Google.
כדי לבטל את הרישום לקבוצה הזו ולהפסיק לקבל ממנה דוא"ל, שלח דוא"ל אל
לאפשרויות נוספות, בקר ב-https://groups.google.com/d/optout.
--
archive and web access >https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת את ההודעה הזו מפני שאתה רשום לקבוצה 'TAMI' של קבוצות Google.
כדי לבטל את הרישום לקבוצה הזו ולהפסיק לקבל ממנה דוא"ל, שלח דוא"ל אל
לאפשרויות נוספות, בקר ב-https://groups.google.com/d/optout.
--
archive and web access >https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת את ההודעה הזו מפני שאתה רשום לקבוצה 'TAMI' של קבוצות Google.
כדי לבטל את הרישום לקבוצה הזו ולהפסיק לקבל ממנה דוא"ל, שלח דוא"ל אל
לאפשרויות נוספות, בקר ב-https://groups.google.com/d/optout.
--
archive and web access >https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת את ההודעה הזו מפני שאתה רשום לקבוצה 'TAMI' של קבוצות Google.
כדי לבטל את הרישום לקבוצה הזו ולהפסיק לקבל ממנה דוא"ל, שלח דוא"ל אל
לאפשרויות נוספות, בקר ב-https://groups.google.com/d/optout.
--
***@gmail
050-6301212
tlv, israel
--
archive and web access >https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת הודעה זו מכיוון שאתה מנוי לקבוצה 'TAMI' בקבוצות Google.
כדי לבטל את הרישום לקבוצה הזו ולהפסיק לקבל ממנה דוא"ל, שלח דוא"ל אל hasadna+***@googlegroups.com.
כדי לפרסם הודעות בקבוצה זו, שלח דוא"ל ל-***@googlegroups.com.
לאפשרויות נוספות בקר ב-https://groups.google.com/d/opt
Udi Finkelstein
2014-09-24 10:13:01 UTC
Permalink
the memory on the card is an eprom, not an eeprom which is much smaller
but electrically erasable.

first step is to reverse engineer the eprom data format. should be
straightforwrd since looking at the ancient machine it probably doesn't
implement encryption or compression. just draw a simple pattern, read back
the eprom and compare.

once you find the format, build a new card but replace the eprom with a
similar nor flash (you can pull them out of dead motherboards :-) ) you can
tie the extra address lines to switches and have multiple patterns per
card.

now you can either build your custom programmer out of a high pincount
arduino, or just use an of the shelf programmer and use ZIF sockets on your
new card.
Post by Yair Reshef
hey
i was asked by my local college to hack their industrial weaving machine.
the problem
only method to upload patterns to the machine is by export to
image/text file from a pc and write it line by line to the UV EPROM
card > . http://imgur.com/a/TeQcG#8
that means countless hours of writing line by line into the eeprom
writer > http://imgur.com/a/TeQcG#0
what way would you attack this problem?
PDF of EEPROM -
http://www.st.com/web/en/resource/technical/document/datasheet/CD00000515.pdf
On Wed, Sep 24, 2014 at 12:06 PM, Udi Finkelstein
http://blackstufflabs.com/2013/11/18/conversione-programmatore-tl866cs-a-tl866a/?lang=en
http://www.eevblog.com/forum/blog/eevblog-411-minipro-tl866-universal-programmer-review/
notice that there are two models, the TL866 and the TL866CS which lacks
the ICSP programming port, and is cheaper by 10$-15$. there is a hack
for
converting a CS model to noon - CS, but since the hack is at least 6
months
old, the manufacturer may have already implemented countermeasures. so
if
you don't need ICSP programming, want to save a few bucks, and be
adventurous, pick up the CS model.
Hardcore :-)
I will check the data sheet of the chip,
Ibeleive it needs to be written there.
I think I will also order from Ebay the one you said you have
I had seen the TL866 at about 50$
Thank you very much for the help.
It's not a question of passwords. Usually when a Micro is
read-protected, it simply cannot be read back, period.
The only way to crack these kind of micros is either via an intended
backdoor in the firmware, unsecure code (buffer overflow on your
micro??) -
both are unlikely, but the common tricks are to play with the power
supply.
sometimes running it on a marginal voltage can be used to bypass the
security uses.
In extreme cases, you can find examples where people have decapped the
IC (using hot nitric acid), shielded part of the die and the exposed
it to
UV to clear the security fuse.
http://www.bunniestudios.com/blog/?page_id=40
Thanks Udi,
I will check the numbers of my PICs
and I really don't know if they have password,
I hope not :-(
בתאךיך יום שלישי, 23 בס׀טמבך 2014 22:36:32 UTC+3, מאת Udi
Hi Gal,
I don't visit TAMI very frequently, I'm mostly active on the mailing
list (not facebook).
As for your PICs, it would help if you specify the exact model you
have.
Do these have a code protection option, and do you know if your
PICs
are protected?
If yes, I don't think I can help much (there are techniques for
bypassing that, but they are not straightforward, and I'm not an
expert on
the subject).
Udi
Udi,
I would really like to sit with you some time in the close future
and
talk about that
or even try to read the info from some pics I have.
When you will have the time.
בתאךיך יום שלישי, 23 בס׀טמבך 2014 16:30:38 UTC+3, מאת Udi
I have two programmers - one is an old Labtool 48, which requires
Windows XP at most and stopped receiving updates years ago, and
the other is
a newer chinese TL866
(
http://www.eevblog.com/forum/blog/eevblog-411-minipro-tl866-universal-programmer-review/
).
They are not at TAMI, but if you have specific needs maybe we can
arrange
something. I also have an old EPROM eraser (with a UV lamp), but
I've never
checked it.
Ahh... the old days... When I was really young (high school, in
the
mid-80's) I used to work on various commodore hardware, mostly
adding Hebrew
characters to commodore dot matrix printers. I had a Promenade C1
programmer
for my C64
(
http://mikenaberezny.com/hardware/c64-128/promenade-c1-eprom-burner/) ,
and
my debug cycle was a function of the # of EPROMs I had at hand,
and the
cycle time of the EPROM erase UV lamp I had :-)
And remember, you can always write a '1' bit to '0' but not the
other way around, so I would make incremental changes and test
them.
I think my biggest achievement was neutralizing a checksum check
at
the beginning of the EPROM, with the firmware written for an
obscure NEC
8-bit controller. I fed the mnemonics and opcodes into a
primitive C64
database I had so I could sort them by opcode and have a more
convenient
table for my pencil and paper disassembly.
Udi
Hi Jr,
This is what I am looking for,
I just don't want to buy a new one and using it every two years.
I know it is some sort of ancient history but still, there are
many
working things with burned IC's that needs to be replace.
I have some work parts that there are a few PIC chip's that I
need
to replace but the manufacturer will not sell them only
a new set that cost about 600 Euro.
I will check it next time I will be at TAMI,
Thanks
there is actually an eprom burner with several vintage IC's
having
clear windows on them
i think it was last in the white shelves on left back wall of
hackerspace, around the 3rd/4th shelf
this is ancient tech btw , maybe not what you were looking for??
On Monday, September 22, 2014 4:05:52 AM UTC-4, Udi Finkelstein
What IC do you specifically need to burn?
Hi all,
I am new here and wanted to know if there is an EPROM/IC
burner
at TAMI ?
Thanks,
Gal
--
archive and web access
https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת את ההודעה הזו מ׀ני שאתה ךשום לקבושה 'TAMI' של קבו׊ות
Google.
כדי לבטל את הךישום לקבושה הזו ולה׀סיק לקבל ממנה דוא"ל, שלח
דוא"ל
לא׀שךויות נוס׀ות, בק׹ ב-https://groups.google.com/d/optout.
--
archive and web access
https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת את ההודעה הזו מ׀ני שאתה ךשום לקבושה 'TAMI' של קבו׊ות
Google.
כדי לבטל את הךישום לקבושה הזו ולה׀סיק לקבל ממנה דוא"ל, שלח דוא"ל
אל
לא׀שךויות נוס׀ות, בק׹ ב-https://groups.google.com/d/optout.
--
archive and web access
https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת את ההודעה הזו מ׀ני שאתה ךשום לקבושה 'TAMI' של קבו׊ות Google.
כדי לבטל את הךישום לקבושה הזו ולה׀סיק לקבל ממנה דוא"ל, שלח דוא"ל אל
לא׀שךויות נוס׀ות, בק׹ ב-https://groups.google.com/d/optout.
--
archive and web access >
https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת את ההודעה הזו מ׀ני שאתה ךשום לקבושה 'TAMI' של קבו׊ות Google.
כדי לבטל את הךישום לקבושה הזו ולה׀סיק לקבל ממנה דוא"ל, שלח דוא"ל אל
לא׀שךויות נוס׀ות, בק׹ ב-https://groups.google.com/d/optout.
--
archive and web access >
https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת את ההודעה הזו מ׀ני שאתה ךשום לקבושה 'TAMI' של קבו׊ות Google.
כדי לבטל את הךישום לקבושה הזו ולה׀סיק לקבל ממנה דוא"ל, שלח דוא"ל אל
לא׀שךויות נוס׀ות, בק׹ ב-https://groups.google.com/d/optout.
--
archive and web access >https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת את ההודעה הזו מ׀ני שאתה ךשום לקבושה 'TAMI' של קבו׊ות Google.
כדי לבטל את הךישום לקבושה הזו ולה׀סיק לקבל ממנה דוא"ל, שלח דוא"ל אל
לא׀שךויות נוס׀ות, בק׹ ב-https://groups.google.com/d/optout.
--
050-6301212
tlv, israel
--
archive and web access >https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת הודעה זו מכיוון שאתה מנוי לקבושה 'TAMI' בקבו׊ות Google.
כדי לבטל את הךישום לקבושה הזו ולה׀סיק לקבל ממנה דוא"ל, שלח דוא"ל אל
לא׀שךויות נוס׀ות בק׹ ב-https://groups.google.com/d/optout.
--
archive and web access >https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת הודעה זו מכיוון שאתה מנוי לקבושה 'TAMI' בקבו׊ות Google.
כדי לבטל את הךישום לקבושה הזו ולה׀סיק לקבל ממנה דוא"ל, שלח דוא"ל אל hasadna+***@googlegroups.com.
כדי ל׀ךסם הודעות בקבושה זו, שלח דוא"ל ל-***@googlegroups.com.
לא׀שךויות נוס׀ות בק׹ ב-https://groups.google.com/d/optout.
Udi Finkelstein
2014-09-24 10:18:54 UTC
Permalink
the schematics aren't really readable, are these schemas of the machine or
the programmer? looks like the machine.
given the programmer schematics (does it use pure logic or a micro?) It
might be easier to reverse engineer from there.
overall it looks like an entry level reverse engineering project.
Post by Udi Finkelstein
the memory on the card is an eprom, not an eeprom which is much smaller
but electrically erasable.
first step is to reverse engineer the eprom data format. should be
straightforwrd since looking at the ancient machine it probably doesn't
implement encryption or compression. just draw a simple pattern, read back
the eprom and compare.
once you find the format, build a new card but replace the eprom with a
similar nor flash (you can pull them out of dead motherboards :-) ) you can
tie the extra address lines to switches and have multiple patterns per
card.
now you can either build your custom programmer out of a high pincount
arduino, or just use an of the shelf programmer and use ZIF sockets on your
new card.
Post by Yair Reshef
hey
i was asked by my local college to hack their industrial weaving machine.
the problem
only method to upload patterns to the machine is by export to
image/text file from a pc and write it line by line to the UV EPROM
card > . http://imgur.com/a/TeQcG#8
that means countless hours of writing line by line into the eeprom
writer > http://imgur.com/a/TeQcG#0
what way would you attack this problem?
PDF of EEPROM -
http://www.st.com/web/en/resource/technical/document/datasheet/CD00000515.pdf
On Wed, Sep 24, 2014 at 12:06 PM, Udi Finkelstein
http://blackstufflabs.com/2013/11/18/conversione-programmatore-tl866cs-a-tl866a/?lang=en
http://www.eevblog.com/forum/blog/eevblog-411-minipro-tl866-universal-programmer-review/
notice that there are two models, the TL866 and the TL866CS which lacks
the ICSP programming port, and is cheaper by 10$-15$. there is a hack
for
converting a CS model to noon - CS, but since the hack is at least 6
months
old, the manufacturer may have already implemented countermeasures. so
if
you don't need ICSP programming, want to save a few bucks, and be
adventurous, pick up the CS model.
Hardcore :-)
I will check the data sheet of the chip,
Ibeleive it needs to be written there.
I think I will also order from Ebay the one you said you have
I had seen the TL866 at about 50$
Thank you very much for the help.
It's not a question of passwords. Usually when a Micro is
read-protected, it simply cannot be read back, period.
The only way to crack these kind of micros is either via an intended
backdoor in the firmware, unsecure code (buffer overflow on your
micro??) -
both are unlikely, but the common tricks are to play with the power
supply.
sometimes running it on a marginal voltage can be used to bypass the
security uses.
In extreme cases, you can find examples where people have decapped
the
IC (using hot nitric acid), shielded part of the die and the exposed
it to
UV to clear the security fuse.
http://www.bunniestudios.com/blog/?page_id=40
Thanks Udi,
I will check the numbers of my PICs
and I really don't know if they have password,
I hope not :-(
בתאךיך יום שלישי, 23 בס׀טמבך 2014 22:36:32 UTC+3, מאת Udi
Hi Gal,
I don't visit TAMI very frequently, I'm mostly active on the
mailing
list (not facebook).
As for your PICs, it would help if you specify the exact model you
have.
Do these have a code protection option, and do you know if your
PICs
are protected?
If yes, I don't think I can help much (there are techniques for
bypassing that, but they are not straightforward, and I'm not an
expert on
the subject).
Udi
Udi,
I would really like to sit with you some time in the close future
and
talk about that
or even try to read the info from some pics I have.
When you will have the time.
בתאךיך יום שלישי, 23 בס׀טמבך 2014 16:30:38 UTC+3, מאת Udi
I have two programmers - one is an old Labtool 48, which requires
Windows XP at most and stopped receiving updates years ago, and
the other is
a newer chinese TL866
(
http://www.eevblog.com/forum/blog/eevblog-411-minipro-tl866-universal-programmer-review/
).
They are not at TAMI, but if you have specific needs maybe we
can arrange
something. I also have an old EPROM eraser (with a UV lamp), but
I've never
checked it.
Ahh... the old days... When I was really young (high school, in
the
mid-80's) I used to work on various commodore hardware, mostly
adding Hebrew
characters to commodore dot matrix printers. I had a Promenade
C1 programmer
for my C64
(
http://mikenaberezny.com/hardware/c64-128/promenade-c1-eprom-burner/) ,
and
my debug cycle was a function of the # of EPROMs I had at hand,
and the
cycle time of the EPROM erase UV lamp I had :-)
And remember, you can always write a '1' bit to '0' but not the
other way around, so I would make incremental changes and test
them.
I think my biggest achievement was neutralizing a checksum check
at
the beginning of the EPROM, with the firmware written for an
obscure NEC
8-bit controller. I fed the mnemonics and opcodes into a
primitive C64
database I had so I could sort them by opcode and have a more
convenient
table for my pencil and paper disassembly.
Udi
Hi Jr,
This is what I am looking for,
I just don't want to buy a new one and using it every two years.
I know it is some sort of ancient history but still, there are
many
working things with burned IC's that needs to be replace.
I have some work parts that there are a few PIC chip's that I
need
to replace but the manufacturer will not sell them only
a new set that cost about 600 Euro.
I will check it next time I will be at TAMI,
Thanks
there is actually an eprom burner with several vintage IC's
having
clear windows on them
i think it was last in the white shelves on left back wall of
hackerspace, around the 3rd/4th shelf
this is ancient tech btw , maybe not what you were looking
for??
On Monday, September 22, 2014 4:05:52 AM UTC-4, Udi Finkelstein
What IC do you specifically need to burn?
Hi all,
I am new here and wanted to know if there is an EPROM/IC
burner
at TAMI ?
Thanks,
Gal
--
archive and web access
https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת את ההודעה הזו מ׀ני שאתה ךשום לקבושה 'TAMI' של קבו׊ות
Google.
כדי לבטל את הךישום לקבושה הזו ולה׀סיק לקבל ממנה דוא"ל, שלח
דוא"ל
לא׀שךויות נוס׀ות, בק׹ ב-https://groups.google.com/d/optout.
--
archive and web access
https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת את ההודעה הזו מ׀ני שאתה ךשום לקבושה 'TAMI' של קבו׊ות
Google.
כדי לבטל את הךישום לקבושה הזו ולה׀סיק לקבל ממנה דוא"ל, שלח
דוא"ל אל
לא׀שךויות נוס׀ות, בק׹ ב-https://groups.google.com/d/optout.
--
archive and web access
https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת את ההודעה הזו מ׀ני שאתה ךשום לקבושה 'TAMI' של קבו׊ות
Google.
כדי לבטל את הךישום לקבושה הזו ולה׀סיק לקבל ממנה דוא"ל, שלח דוא"ל
אל
לא׀שךויות נוס׀ות, בק׹ ב-https://groups.google.com/d/optout.
--
archive and web access >
https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת את ההודעה הזו מ׀ני שאתה ךשום לקבושה 'TAMI' של קבו׊ות Google.
כדי לבטל את הךישום לקבושה הזו ולה׀סיק לקבל ממנה דוא"ל, שלח דוא"ל אל
לא׀שךויות נוס׀ות, בק׹ ב-https://groups.google.com/d/optout.
--
archive and web access >
https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת את ההודעה הזו מ׀ני שאתה ךשום לקבושה 'TAMI' של קבו׊ות Google.
כדי לבטל את הךישום לקבושה הזו ולה׀סיק לקבל ממנה דוא"ל, שלח דוא"ל אל
לא׀שךויות נוס׀ות, בק׹ ב-https://groups.google.com/d/optout.
--
archive and web access >https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת את ההודעה הזו מ׀ני שאתה ךשום לקבושה 'TAMI' של קבו׊ות Google.
כדי לבטל את הךישום לקבושה הזו ולה׀סיק לקבל ממנה דוא"ל, שלח דוא"ל אל
לא׀שךויות נוס׀ות, בק׹ ב-https://groups.google.com/d/optout.
--
050-6301212
tlv, israel
--
archive and web access >https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת הודעה זו מכיוון שאתה מנוי לקבושה 'TAMI' בקבו׊ות Google.
כדי לבטל את הךישום לקבושה הזו ולה׀סיק לקבל ממנה דוא"ל, שלח דוא"ל אל
לא׀שךויות נוס׀ות בק׹ ב-https://groups.google.com/d/optout.
--
archive and web access >https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת הודעה זו מכיוון שאתה מנוי לקבושה 'TAMI' בקבו׊ות Google.
כדי לבטל את הךישום לקבושה הזו ולה׀סיק לקבל ממנה דוא"ל, שלח דוא"ל אל hasadna+unsubscribe-/JYPxA39Uh5TLH3MbocFF+G/***@public.gmane.org
כדי ל׀ךסם הודעות בקבושה זו, שלח דוא"ל ל-hasadna-/JYPxA39Uh5TLH3MbocFF+G/***@public.gmane.org
לא׀שךויות נוס׀ות בק׹ ב-https://groups.google.com/d/optout.
Yair Reshef
2014-09-24 10:36:36 UTC
Permalink
schematics are for the big machine, try the full res version. it was
stitched from smaller pics

but the important thing is the
card pinout on the bottom right corner > Loading Image...
and this http://imgur.com/a/TeQcG#4

your thoughts reflect my understanding, still would like to decypher
the pinout, i dont get it.


On Wed, Sep 24, 2014 at 1:18 PM, Udi Finkelstein
Post by Udi Finkelstein
the schematics aren't really readable, are these schemas of the machine or
the programmer? looks like the machine.
given the programmer schematics (does it use pure logic or a micro?) It
might be easier to reverse engineer from there.
overall it looks like an entry level reverse engineering project.
Post by Udi Finkelstein
the memory on the card is an eprom, not an eeprom which is much smaller
but electrically erasable.
first step is to reverse engineer the eprom data format. should be
straightforwrd since looking at the ancient machine it probably doesn't
implement encryption or compression. just draw a simple pattern, read back
the eprom and compare.
once you find the format, build a new card but replace the eprom with a
similar nor flash (you can pull them out of dead motherboards :-) ) you can
tie the extra address lines to switches and have multiple patterns per card.
now you can either build your custom programmer out of a high pincount
arduino, or just use an of the shelf programmer and use ZIF sockets on your
new card.
Post by Yair Reshef
hey
i was asked by my local college to hack their industrial weaving machine.
the problem
only method to upload patterns to the machine is by export to
image/text file from a pc and write it line by line to the UV EPROM
card > . http://imgur.com/a/TeQcG#8
that means countless hours of writing line by line into the eeprom
writer > http://imgur.com/a/TeQcG#0
what way would you attack this problem?
PDF of EEPROM -
http://www.st.com/web/en/resource/technical/document/datasheet/CD00000515.pdf
On Wed, Sep 24, 2014 at 12:06 PM, Udi Finkelstein
http://blackstufflabs.com/2013/11/18/conversione-programmatore-tl866cs-a-tl866a/?lang=en
http://www.eevblog.com/forum/blog/eevblog-411-minipro-tl866-universal-programmer-review/
notice that there are two models, the TL866 and the TL866CS which lacks
the ICSP programming port, and is cheaper by 10$-15$. there is a hack for
converting a CS model to noon - CS, but since the hack is at least 6 months
old, the manufacturer may have already implemented countermeasures. so if
you don't need ICSP programming, want to save a few bucks, and be
adventurous, pick up the CS model.
Hardcore :-)
I will check the data sheet of the chip,
Ibeleive it needs to be written there.
I think I will also order from Ebay the one you said you have
I had seen the TL866 at about 50$
Thank you very much for the help.
בתאריך יום רביעי, 24 בספטמבר 2014 10:07:28 UTC+3, מאת Udi
It's not a question of passwords. Usually when a Micro is
read-protected, it simply cannot be read back, period.
The only way to crack these kind of micros is either via an intended
backdoor in the firmware, unsecure code (buffer overflow on your micro??) -
both are unlikely, but the common tricks are to play with the power supply.
sometimes running it on a marginal voltage can be used to bypass the
security uses.
In extreme cases, you can find examples where people have decapped the
IC (using hot nitric acid), shielded part of the die and the exposed it to
UV to clear the security fuse.
http://www.bunniestudios.com/blog/?page_id=40
Thanks Udi,
I will check the numbers of my PICs
and I really don't know if they have password,
I hope not :-(
בתאריך יום שלישי, 23 בספטמבר 2014 22:36:32 UTC+3, מאת Udi
Hi Gal,
I don't visit TAMI very frequently, I'm mostly active on the mailing
list (not facebook).
As for your PICs, it would help if you specify the exact model you
have.
Do these have a code protection option, and do you know if your PICs
are protected?
If yes, I don't think I can help much (there are techniques for
bypassing that, but they are not straightforward, and I'm not an
expert on
the subject).
Udi
Udi,
I would really like to sit with you some time in the close future and
talk about that
or even try to read the info from some pics I have.
When you will have the time.
בתאריך יום שלישי, 23 בספטמבר 2014 16:30:38 UTC+3, מאת Udi
I have two programmers - one is an old Labtool 48, which requires
Windows XP at most and stopped receiving updates years ago, and
the other is
a newer chinese TL866
(http://www.eevblog.com/forum/blog/eevblog-411-minipro-tl866-universal-programmer-review/).
They are not at TAMI, but if you have specific needs maybe we
can arrange
something. I also have an old EPROM eraser (with a UV lamp), but
I've never
checked it.
Ahh... the old days... When I was really young (high school, in the
mid-80's) I used to work on various commodore hardware, mostly
adding Hebrew
characters to commodore dot matrix printers. I had a Promenade
C1 programmer
for my C64
(http://mikenaberezny.com/hardware/c64-128/promenade-c1-eprom-burner/) , and
my debug cycle was a function of the # of EPROMs I had at hand,
and the
cycle time of the EPROM erase UV lamp I had :-)
And remember, you can always write a '1' bit to '0' but not the
other way around, so I would make incremental changes and test them.
I think my biggest achievement was neutralizing a checksum check at
the beginning of the EPROM, with the firmware written for an
obscure NEC
8-bit controller. I fed the mnemonics and opcodes into a
primitive C64
database I had so I could sort them by opcode and have a more
convenient
table for my pencil and paper disassembly.
Udi
Hi Jr,
This is what I am looking for,
I just don't want to buy a new one and using it every two years.
I know it is some sort of ancient history but still, there are many
working things with burned IC's that needs to be replace.
I have some work parts that there are a few PIC chip's that I need
to replace but the manufacturer will not sell them only
a new set that cost about 600 Euro.
I will check it next time I will be at TAMI,
Thanks
there is actually an eprom burner with several vintage IC's
having
clear windows on them
i think it was last in the white shelves on left back wall of
hackerspace, around the 3rd/4th shelf
this is ancient tech btw , maybe not what you were looking for??
On Monday, September 22, 2014 4:05:52 AM UTC-4, Udi Finkelstein
What IC do you specifically need to burn?
Hi all,
I am new here and wanted to know if there is an EPROM/IC
burner
at TAMI ?
Thanks,
Gal
--
archive and web access
https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת את ההודעה הזו מפני שאתה רשום לקבוצה 'TAMI' של קבוצות
Google.
כדי לבטל את הרישום לקבוצה הזו ולהפסיק לקבל ממנה דוא"ל, שלח
דוא"ל
לאפשרויות נוספות, בקר ב-https://groups.google.com/d/optout.
--
archive and web access
https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת את ההודעה הזו מפני שאתה רשום לקבוצה 'TAMI' של קבוצות
Google.
כדי לבטל את הרישום לקבוצה הזו ולהפסיק לקבל ממנה דוא"ל, שלח
דוא"ל אל
לאפשרויות נוספות, בקר ב-https://groups.google.com/d/optout.
--
archive and web access
https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת את ההודעה הזו מפני שאתה רשום לקבוצה 'TAMI' של קבוצות
Google.
כדי לבטל את הרישום לקבוצה הזו ולהפסיק לקבל ממנה דוא"ל, שלח דוא"ל
אל
לאפשרויות נוספות, בקר ב-https://groups.google.com/d/optout.
--
archive and web access
https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת את ההודעה הזו מפני שאתה רשום לקבוצה 'TAMI' של קבוצות Google.
כדי לבטל את הרישום לקבוצה הזו ולהפסיק לקבל ממנה דוא"ל, שלח דוא"ל אל
לאפשרויות נוספות, בקר ב-https://groups.google.com/d/optout.
--
archive and web access
https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת את ההודעה הזו מפני שאתה רשום לקבוצה 'TAMI' של קבוצות Google.
כדי לבטל את הרישום לקבוצה הזו ולהפסיק לקבל ממנה דוא"ל, שלח דוא"ל אל
לאפשרויות נוספות, בקר ב-https://groups.google.com/d/optout.
--
archive and web access >https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת את ההודעה הזו מפני שאתה רשום לקבוצה 'TAMI' של קבוצות Google.
כדי לבטל את הרישום לקבוצה הזו ולהפסיק לקבל ממנה דוא"ל, שלח דוא"ל אל
לאפשרויות נוספות, בקר ב-https://groups.google.com/d/optout.
--
050-6301212
tlv, israel
--
archive and web access >https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת הודעה זו מכיוון שאתה מנוי לקבוצה 'TAMI' בקבוצות Google.
כדי לבטל את הרישום לקבוצה הזו ולהפסיק לקבל ממנה דוא"ל, שלח דוא"ל אל
לאפשרויות נוספות בקר ב-https://groups.google.com/d/optout.
--
archive and web access >https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת את ההודעה הזו מפני שאתה רשום לקבוצה 'TAMI' של קבוצות Google.
כדי לבטל את הרישום לקבוצה הזו ולהפסיק לקבל ממנה דוא"ל, שלח דוא"ל אל
לאפשרויות נוספות, בקר ב-https://groups.google.com/d/optout.
--
***@gmail
050-6301212
tlv, israel
--
archive and web access >https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת הודעה זו מכיוון שאתה מנוי לקבוצה 'TAMI' בקבוצות Google.
כדי לבטל את הרישום לקבוצה הזו ולהפסיק לקבל ממנה דוא"ל, שלח דוא"ל אל hasadna+unsubscribe-/JYPxA39Uh5TLH3MbocFF+G/***@public.gmane.org
כדי לפרסם הודעות בקבוצה זו, שלח דוא"ל ל-hasadna-/JYPxA39Uh5TLH3MbocFF+G/***@public.gmane.org
לאפשרויות נוספות בקר ב-https://groups.google.com/d/optout.
Udi Finkelstein
2014-09-24 11:42:00 UTC
Permalink
can't get the high res pic on my phone. will try on a desktop later
(probably only next week).

the card pinout should be trivial add there are no other components on it
and you can easily trace the card.
Post by Yair Reshef
schematics are for the big machine, try the full res version. it was
stitched from smaller pics
but the important thing is the
card pinout on the bottom right corner > http://i.imgur.com/mzRD36i.jpg
and this http://imgur.com/a/TeQcG#4
your thoughts reflect my understanding, still would like to decypher
the pinout, i dont get it.
On Wed, Sep 24, 2014 at 1:18 PM, Udi Finkelstein
Post by Udi Finkelstein
the schematics aren't really readable, are these schemas of the machine
or
Post by Udi Finkelstein
the programmer? looks like the machine.
given the programmer schematics (does it use pure logic or a micro?) It
might be easier to reverse engineer from there.
overall it looks like an entry level reverse engineering project.
Post by Udi Finkelstein
the memory on the card is an eprom, not an eeprom which is much smaller
but electrically erasable.
first step is to reverse engineer the eprom data format. should be
straightforwrd since looking at the ancient machine it probably doesn't
implement encryption or compression. just draw a simple pattern, read
back
Post by Udi Finkelstein
Post by Udi Finkelstein
the eprom and compare.
once you find the format, build a new card but replace the eprom with a
similar nor flash (you can pull them out of dead motherboards :-) ) you
can
Post by Udi Finkelstein
Post by Udi Finkelstein
tie the extra address lines to switches and have multiple patterns per
card.
Post by Udi Finkelstein
Post by Udi Finkelstein
now you can either build your custom programmer out of a high pincount
arduino, or just use an of the shelf programmer and use ZIF sockets on
your
Post by Udi Finkelstein
Post by Udi Finkelstein
new card.
Post by Yair Reshef
hey
i was asked by my local college to hack their industrial weaving
machine.
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
the problem
only method to upload patterns to the machine is by export to
image/text file from a pc and write it line by line to the UV EPROM
card > . http://imgur.com/a/TeQcG#8
that means countless hours of writing line by line into the eeprom
writer > http://imgur.com/a/TeQcG#0
what way would you attack this problem?
PDF of EEPROM -
http://www.st.com/web/en/resource/technical/document/datasheet/CD00000515.pdf
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
On Wed, Sep 24, 2014 at 12:06 PM, Udi Finkelstein
http://blackstufflabs.com/2013/11/18/conversione-programmatore-tl866cs-a-tl866a/?lang=en
http://www.eevblog.com/forum/blog/eevblog-411-minipro-tl866-universal-programmer-review/
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
On Sep 24, 2014 12:02 PM, "Udi Finkelstein" <
notice that there are two models, the TL866 and the TL866CS which lacks
the ICSP programming port, and is cheaper by 10$-15$. there is a
hack
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
for
converting a CS model to noon - CS, but since the hack is at least 6 months
old, the manufacturer may have already implemented countermeasures.
so
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
if
you don't need ICSP programming, want to save a few bucks, and be
adventurous, pick up the CS model.
Hardcore :-)
I will check the data sheet of the chip,
Ibeleive it needs to be written there.
I think I will also order from Ebay the one you said you have
I had seen the TL866 at about 50$
Thank you very much for the help.
בתאךיך יום ךביעי, 24 בס׀טמבך 2014 10:07:28 UTC+3, מאת Udi
It's not a question of passwords. Usually when a Micro is
read-protected, it simply cannot be read back, period.
The only way to crack these kind of micros is either via an
intended
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
backdoor in the firmware, unsecure code (buffer overflow on your
micro??) -
both are unlikely, but the common tricks are to play with the
power
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
supply.
sometimes running it on a marginal voltage can be used to bypass
the
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
security uses.
In extreme cases, you can find examples where people have decapped the
IC (using hot nitric acid), shielded part of the die and the
exposed
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
it to
UV to clear the security fuse.
http://www.bunniestudios.com/blog/?page_id=40
Thanks Udi,
I will check the numbers of my PICs
and I really don't know if they have password,
I hope not :-(
בתאךיך יום שלישי, 23 בס׀טמבך 2014 22:36:32 UTC+3, מאת Udi
Hi Gal,
I don't visit TAMI very frequently, I'm mostly active on the mailing
list (not facebook).
As for your PICs, it would help if you specify the exact model
you
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
have.
Do these have a code protection option, and do you know if your PICs
are protected?
If yes, I don't think I can help much (there are techniques for
bypassing that, but they are not straightforward, and I'm not an
expert on
the subject).
Udi
Udi,
I would really like to sit with you some time in the close
future
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
and
talk about that
or even try to read the info from some pics I have.
When you will have the time.
בתאךיך יום שלישי, 23 בס׀טמבך 2014 16:30:38 UTC+3, מאת Udi
I have two programmers - one is an old Labtool 48, which requires
Windows XP at most and stopped receiving updates years ago,
and
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
the other is
a newer chinese TL866
(
http://www.eevblog.com/forum/blog/eevblog-411-minipro-tl866-universal-programmer-review/
).
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
They are not at TAMI, but if you have specific needs maybe we
can arrange
something. I also have an old EPROM eraser (with a UV lamp),
but
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
I've never
checked it.
Ahh... the old days... When I was really young (high school,
in
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
the
mid-80's) I used to work on various commodore hardware, mostly
adding Hebrew
characters to commodore dot matrix printers. I had a Promenade
C1 programmer
for my C64
(
http://mikenaberezny.com/hardware/c64-128/promenade-c1-eprom-burner/) ,
and
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
my debug cycle was a function of the # of EPROMs I had at
hand,
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
and the
cycle time of the EPROM erase UV lamp I had :-)
And remember, you can always write a '1' bit to '0' but not
the
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
other way around, so I would make incremental changes and test
them.
I think my biggest achievement was neutralizing a checksum
check
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
at
the beginning of the EPROM, with the firmware written for an
obscure NEC
8-bit controller. I fed the mnemonics and opcodes into a
primitive C64
database I had so I could sort them by opcode and have a more
convenient
table for my pencil and paper disassembly.
Udi
On Tue, Sep 23, 2014 at 11:57 AM, Gal Bazel <
Hi Jr,
This is what I am looking for,
I just don't want to buy a new one and using it every two
years.
I know it is some sort of ancient history but still, there
are
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
many
working things with burned IC's that needs to be replace.
I have some work parts that there are a few PIC chip's that I
need
to replace but the manufacturer will not sell them only
a new set that cost about 600 Euro.
I will check it next time I will be at TAMI,
Thanks
there is actually an eprom burner with several vintage IC's
having
clear windows on them
i think it was last in the white shelves on left back wall
of
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
hackerspace, around the 3rd/4th shelf
this is ancient tech btw , maybe not what you were looking
for??
On Monday, September 22, 2014 4:05:52 AM UTC-4, Udi
Finkelstein
What IC do you specifically need to burn?
Hi all,
I am new here and wanted to know if there is an EPROM/IC
burner
at TAMI ?
Thanks,
Gal
--
archive and web access
https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת את ההודעה הזו מ׀ני שאתה ךשום לקבושה 'TAMI' של
קבו׊ות
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
Google.
כדי לבטל את הךישום לקבושה הזו ולה׀סיק לקבל ממנה דוא"ל, שלח
דוא"ל
כדי ל׀ךסם בקבושה הזו, שלח דוא"ל אל
לא׀שךויות נוס׀ות, בק׹ ב-
https://groups.google.com/d/optout.
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
--
archive and web access
https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת את ההודעה הזו מ׀ני שאתה ךשום לקבושה 'TAMI' של קבו׊ות
Google.
כדי לבטל את הךישום לקבושה הזו ולה׀סיק לקבל ממנה דוא"ל, שלח
דוא"ל אל
לא׀שךויות נוס׀ות, בק׹ ב-https://groups.google.com/d/optout.
--
archive and web access
https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת את ההודעה הזו מ׀ני שאתה ךשום לקבושה 'TAMI' של קבו׊ות
Google.
כדי לבטל את הךישום לקבושה הזו ולה׀סיק לקבל ממנה דוא"ל, שלח
דוא"ל
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
אל
לא׀שךויות נוס׀ות, בק׹ ב-https://groups.google.com/d/optout.
--
archive and web access
https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת את ההודעה הזו מ׀ני שאתה ךשום לקבושה 'TAMI' של קבו׊ות
Google.
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
כדי לבטל את הךישום לקבושה הזו ולה׀סיק לקבל ממנה דוא"ל, שלח דוא"ל
אל
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
לא׀שךויות נוס׀ות, בק׹ ב-https://groups.google.com/d/optout.
--
archive and web access
https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת את ההודעה הזו מ׀ני שאתה ךשום לקבושה 'TAMI' של קבו׊ות Google.
כדי לבטל את הךישום לקבושה הזו ולה׀סיק לקבל ממנה דוא"ל, שלח דוא"ל אל
לא׀שךויות נוס׀ות, בק׹ ב-https://groups.google.com/d/optout.
--
archive and web access >
https://groups.google.com/forum/#!forum/hasadna
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
---
‏קיבלת את ההודעה הזו מ׀ני שאתה ךשום לקבושה 'TAMI' של קבו׊ות Google.
כדי לבטל את הךישום לקבושה הזו ולה׀סיק לקבל ממנה דוא"ל, שלח דוא"ל אל
לא׀שךויות נוס׀ות, בק׹ ב-https://groups.google.com/d/optout.
--
050-6301212
tlv, israel
--
archive and web access >
https://groups.google.com/forum/#!forum/hasadna
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
---
‏קיבלת הודעה זו מכיוון שאתה מנוי לקבושה 'TAMI' בקבו׊ות Google.
כדי לבטל את הךישום לקבושה הזו ולה׀סיק לקבל ממנה דוא"ל, שלח דוא"ל אל
לא׀שךויות נוס׀ות בק׹ ב-https://groups.google.com/d/optout.
--
archive and web access >https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת את ההודעה הזו מ׀ני שאתה ךשום לקבושה 'TAMI' של קבו׊ות Google.
כדי לבטל את הךישום לקבושה הזו ולה׀סיק לקבל ממנה דוא"ל, שלח דוא"ל אל
לא׀שךויות נוס׀ות, בק׹ ב-https://groups.google.com/d/optout.
--
050-6301212
tlv, israel
--
archive and web access >https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת הודעה זו מכיוון שאתה מנוי לקבושה 'TAMI' בקבו׊ות Google.
כדי לבטל את הךישום לקבושה הזו ולה׀סיק לקבל ממנה דוא"ל, שלח דוא"ל אל
לא׀שךויות נוס׀ות בק׹ ב-https://groups.google.com/d/optout.
--
archive and web access >https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת הודעה זו מכיוון שאתה מנוי לקבושה 'TAMI' בקבו׊ות Google.
כדי לבטל את הךישום לקבושה הזו ולה׀סיק לקבל ממנה דוא"ל, שלח דוא"ל אל hasadna+unsubscribe-/JYPxA39Uh5TLH3MbocFF+G/***@public.gmane.org
כדי ל׀ךסם הודעות בקבושה זו, שלח דוא"ל ל-hasadna-/JYPxA39Uh5TLH3MbocFF+G/***@public.gmane.org
לא׀שךויות נוס׀ות בק׹ ב-https://groups.google.com/d/optout.
Udi Finkelstein
2014-09-24 11:46:38 UTC
Permalink
quick guess :
2 resistors pulldown pins 22 and 20 to Gnd so that ~ce and ~oe are active.
the 2 caps are just for decoupling.

the card just looks like an atari 2600 cart (but that had only 4k or 8k,
not 32k like this one).
maybe even more similar is the Commodore 64 expansion slot
Post by Yair Reshef
schematics are for the big machine, try the full res version. it was
stitched from smaller pics
but the important thing is the
card pinout on the bottom right corner > http://i.imgur.com/mzRD36i.jpg
and this http://imgur.com/a/TeQcG#4
your thoughts reflect my understanding, still would like to decypher
the pinout, i dont get it.
On Wed, Sep 24, 2014 at 1:18 PM, Udi Finkelstein
Post by Udi Finkelstein
the schematics aren't really readable, are these schemas of the machine
or
Post by Udi Finkelstein
the programmer? looks like the machine.
given the programmer schematics (does it use pure logic or a micro?) It
might be easier to reverse engineer from there.
overall it looks like an entry level reverse engineering project.
Post by Udi Finkelstein
the memory on the card is an eprom, not an eeprom which is much smaller
but electrically erasable.
first step is to reverse engineer the eprom data format. should be
straightforwrd since looking at the ancient machine it probably doesn't
implement encryption or compression. just draw a simple pattern, read
back
Post by Udi Finkelstein
Post by Udi Finkelstein
the eprom and compare.
once you find the format, build a new card but replace the eprom with a
similar nor flash (you can pull them out of dead motherboards :-) ) you
can
Post by Udi Finkelstein
Post by Udi Finkelstein
tie the extra address lines to switches and have multiple patterns per
card.
Post by Udi Finkelstein
Post by Udi Finkelstein
now you can either build your custom programmer out of a high pincount
arduino, or just use an of the shelf programmer and use ZIF sockets on
your
Post by Udi Finkelstein
Post by Udi Finkelstein
new card.
Post by Yair Reshef
hey
i was asked by my local college to hack their industrial weaving
machine.
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
the problem
only method to upload patterns to the machine is by export to
image/text file from a pc and write it line by line to the UV EPROM
card > . http://imgur.com/a/TeQcG#8
that means countless hours of writing line by line into the eeprom
writer > http://imgur.com/a/TeQcG#0
what way would you attack this problem?
PDF of EEPROM -
http://www.st.com/web/en/resource/technical/document/datasheet/CD00000515.pdf
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
On Wed, Sep 24, 2014 at 12:06 PM, Udi Finkelstein
http://blackstufflabs.com/2013/11/18/conversione-programmatore-tl866cs-a-tl866a/?lang=en
http://www.eevblog.com/forum/blog/eevblog-411-minipro-tl866-universal-programmer-review/
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
On Sep 24, 2014 12:02 PM, "Udi Finkelstein" <
notice that there are two models, the TL866 and the TL866CS which lacks
the ICSP programming port, and is cheaper by 10$-15$. there is a
hack
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
for
converting a CS model to noon - CS, but since the hack is at least 6 months
old, the manufacturer may have already implemented countermeasures.
so
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
if
you don't need ICSP programming, want to save a few bucks, and be
adventurous, pick up the CS model.
Hardcore :-)
I will check the data sheet of the chip,
Ibeleive it needs to be written there.
I think I will also order from Ebay the one you said you have
I had seen the TL866 at about 50$
Thank you very much for the help.
בתאךיך יום ךביעי, 24 בס׀טמבך 2014 10:07:28 UTC+3, מאת Udi
It's not a question of passwords. Usually when a Micro is
read-protected, it simply cannot be read back, period.
The only way to crack these kind of micros is either via an
intended
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
backdoor in the firmware, unsecure code (buffer overflow on your
micro??) -
both are unlikely, but the common tricks are to play with the
power
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
supply.
sometimes running it on a marginal voltage can be used to bypass
the
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
security uses.
In extreme cases, you can find examples where people have decapped the
IC (using hot nitric acid), shielded part of the die and the
exposed
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
it to
UV to clear the security fuse.
http://www.bunniestudios.com/blog/?page_id=40
Thanks Udi,
I will check the numbers of my PICs
and I really don't know if they have password,
I hope not :-(
בתאךיך יום שלישי, 23 בס׀טמבך 2014 22:36:32 UTC+3, מאת Udi
Hi Gal,
I don't visit TAMI very frequently, I'm mostly active on the mailing
list (not facebook).
As for your PICs, it would help if you specify the exact model
you
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
have.
Do these have a code protection option, and do you know if your PICs
are protected?
If yes, I don't think I can help much (there are techniques for
bypassing that, but they are not straightforward, and I'm not an
expert on
the subject).
Udi
Udi,
I would really like to sit with you some time in the close
future
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
and
talk about that
or even try to read the info from some pics I have.
When you will have the time.
בתאךיך יום שלישי, 23 בס׀טמבך 2014 16:30:38 UTC+3, מאת Udi
I have two programmers - one is an old Labtool 48, which requires
Windows XP at most and stopped receiving updates years ago,
and
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
the other is
a newer chinese TL866
(
http://www.eevblog.com/forum/blog/eevblog-411-minipro-tl866-universal-programmer-review/
).
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
They are not at TAMI, but if you have specific needs maybe we
can arrange
something. I also have an old EPROM eraser (with a UV lamp),
but
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
I've never
checked it.
Ahh... the old days... When I was really young (high school,
in
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
the
mid-80's) I used to work on various commodore hardware, mostly
adding Hebrew
characters to commodore dot matrix printers. I had a Promenade
C1 programmer
for my C64
(
http://mikenaberezny.com/hardware/c64-128/promenade-c1-eprom-burner/) ,
and
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
my debug cycle was a function of the # of EPROMs I had at
hand,
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
and the
cycle time of the EPROM erase UV lamp I had :-)
And remember, you can always write a '1' bit to '0' but not
the
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
other way around, so I would make incremental changes and test
them.
I think my biggest achievement was neutralizing a checksum
check
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
at
the beginning of the EPROM, with the firmware written for an
obscure NEC
8-bit controller. I fed the mnemonics and opcodes into a
primitive C64
database I had so I could sort them by opcode and have a more
convenient
table for my pencil and paper disassembly.
Udi
On Tue, Sep 23, 2014 at 11:57 AM, Gal Bazel <
Hi Jr,
This is what I am looking for,
I just don't want to buy a new one and using it every two
years.
I know it is some sort of ancient history but still, there
are
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
many
working things with burned IC's that needs to be replace.
I have some work parts that there are a few PIC chip's that I
need
to replace but the manufacturer will not sell them only
a new set that cost about 600 Euro.
I will check it next time I will be at TAMI,
Thanks
there is actually an eprom burner with several vintage IC's
having
clear windows on them
i think it was last in the white shelves on left back wall
of
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
hackerspace, around the 3rd/4th shelf
this is ancient tech btw , maybe not what you were looking
for??
On Monday, September 22, 2014 4:05:52 AM UTC-4, Udi
Finkelstein
What IC do you specifically need to burn?
Hi all,
I am new here and wanted to know if there is an EPROM/IC
burner
at TAMI ?
Thanks,
Gal
--
archive and web access
https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת את ההודעה הזו מ׀ני שאתה ךשום לקבושה 'TAMI' של
קבו׊ות
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
Google.
כדי לבטל את הךישום לקבושה הזו ולה׀סיק לקבל ממנה דוא"ל, שלח
דוא"ל
כדי ל׀ךסם בקבושה הזו, שלח דוא"ל אל
לא׀שךויות נוס׀ות, בק׹ ב-
https://groups.google.com/d/optout.
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
--
archive and web access
https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת את ההודעה הזו מ׀ני שאתה ךשום לקבושה 'TAMI' של קבו׊ות
Google.
כדי לבטל את הךישום לקבושה הזו ולה׀סיק לקבל ממנה דוא"ל, שלח
דוא"ל אל
לא׀שךויות נוס׀ות, בק׹ ב-https://groups.google.com/d/optout.
--
archive and web access
https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת את ההודעה הזו מ׀ני שאתה ךשום לקבושה 'TAMI' של קבו׊ות
Google.
כדי לבטל את הךישום לקבושה הזו ולה׀סיק לקבל ממנה דוא"ל, שלח
דוא"ל
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
אל
לא׀שךויות נוס׀ות, בק׹ ב-https://groups.google.com/d/optout.
--
archive and web access
https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת את ההודעה הזו מ׀ני שאתה ךשום לקבושה 'TAMI' של קבו׊ות
Google.
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
כדי לבטל את הךישום לקבושה הזו ולה׀סיק לקבל ממנה דוא"ל, שלח דוא"ל
אל
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
לא׀שךויות נוס׀ות, בק׹ ב-https://groups.google.com/d/optout.
--
archive and web access
https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת את ההודעה הזו מ׀ני שאתה ךשום לקבושה 'TAMI' של קבו׊ות Google.
כדי לבטל את הךישום לקבושה הזו ולה׀סיק לקבל ממנה דוא"ל, שלח דוא"ל אל
לא׀שךויות נוס׀ות, בק׹ ב-https://groups.google.com/d/optout.
--
archive and web access >
https://groups.google.com/forum/#!forum/hasadna
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
---
‏קיבלת את ההודעה הזו מ׀ני שאתה ךשום לקבושה 'TAMI' של קבו׊ות Google.
כדי לבטל את הךישום לקבושה הזו ולה׀סיק לקבל ממנה דוא"ל, שלח דוא"ל אל
לא׀שךויות נוס׀ות, בק׹ ב-https://groups.google.com/d/optout.
--
050-6301212
tlv, israel
--
archive and web access >
https://groups.google.com/forum/#!forum/hasadna
Post by Udi Finkelstein
Post by Udi Finkelstein
Post by Yair Reshef
---
‏קיבלת הודעה זו מכיוון שאתה מנוי לקבושה 'TAMI' בקבו׊ות Google.
כדי לבטל את הךישום לקבושה הזו ולה׀סיק לקבל ממנה דוא"ל, שלח דוא"ל אל
לא׀שךויות נוס׀ות בק׹ ב-https://groups.google.com/d/optout.
--
archive and web access >https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת את ההודעה הזו מ׀ני שאתה ךשום לקבושה 'TAMI' של קבו׊ות Google.
כדי לבטל את הךישום לקבושה הזו ולה׀סיק לקבל ממנה דוא"ל, שלח דוא"ל אל
לא׀שךויות נוס׀ות, בק׹ ב-https://groups.google.com/d/optout.
--
050-6301212
tlv, israel
--
archive and web access >https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת הודעה זו מכיוון שאתה מנוי לקבושה 'TAMI' בקבו׊ות Google.
כדי לבטל את הךישום לקבושה הזו ולה׀סיק לקבל ממנה דוא"ל, שלח דוא"ל אל
לא׀שךויות נוס׀ות בק׹ ב-https://groups.google.com/d/optout.
--
archive and web access >https://groups.google.com/forum/#!forum/hasadna
---
‏קיבלת הודעה זו מכיוון שאתה מנוי לקבושה 'TAMI' בקבו׊ות Google.
כדי לבטל את הךישום לקבושה הזו ולה׀סיק לקבל ממנה דוא"ל, שלח דוא"ל אל hasadna+unsubscribe-/JYPxA39Uh5TLH3MbocFF+G/***@public.gmane.org
כדי ל׀ךסם הודעות בקבושה זו, שלח דוא"ל ל-hasadna-/JYPxA39Uh5TLH3MbocFF+G/***@public.gmane.org
לא׀שךויות נוס׀ות בק׹ ב-https://groups.google.com/d/optout.
Loading...