Author Topic: Sniffing the Rigol's internal I2C bus  (Read 1840404 times)

0 Members and 3 Guests are viewing this topic.

Offline H.O

  • Frequent Contributor
  • **
  • Posts: 821
  • Country: se
Re: Sniffing the Rigol's internal I2C bus
« Reply #825 on: August 12, 2013, 10:41:09 am »
Hi,
Yes, I'm pretty sure you should be able to trig on a specific byte/char, both on the DS2000 (might be an option) and on the DS4000 but again, seeing how slow the decoder is I might have misunderstood it completely....

Take a look at page 5-35 in this DS2000 user guide.
 

Online PA0PBZ

  • Super Contributor
  • ***
  • Posts: 5139
  • Country: nl
Re: Sniffing the Rigol's internal I2C bus
« Reply #826 on: August 12, 2013, 10:53:34 am »
Hi,
Yes, I'm pretty sure you should be able to trig on a specific byte/char, both on the DS2000 (might be an option) and on the DS4000 but again, seeing how slow the decoder is I might have misunderstood it completely....

Take a look at page 5-35 in this DS2000 user guide.

Ah, I see. Must have skipped that part of the page. I think there's still hope, because the trigger and the decode are different functions.
The RS232 trigger is standard available, and to make it work it must be implemented in hardware. The RS232 decode is an option and by looking at the speed it is implemented in software.
Keyboard error: Press F1 to continue.
 

Offline cybernet

  • Regular Contributor
  • *
  • Posts: 247
  • Country: 00
  • pm deactivated, use the search function ...
Re: Sniffing the Rigol's internal I2C bus
« Reply #827 on: August 12, 2013, 02:29:05 pm »
anyone with a DSA around and willing to test some keys ? ... pm me
___________________
"all rights reversed :-)"
R0=-0x18;
UNLINK;
RTS;
 

Offline olsenn

  • Frequent Contributor
  • **
  • Posts: 993
Re: Sniffing the Rigol's internal I2C bus
« Reply #828 on: August 12, 2013, 02:37:55 pm »
Quote
anyone with a DSA around and willing to test some keys ? ... pm me

I have a DSA815-TG. What keys do you have for me?
 

Offline cybernet

  • Regular Contributor
  • *
  • Posts: 247
  • Country: 00
  • pm deactivated, use the search function ...
Re: Sniffing the Rigol's internal I2C bus
« Reply #829 on: August 12, 2013, 02:40:20 pm »
i dont know ;-) i dont have a DSA, but i believe the i have found the private key for it so i could generate keys, other than option 1 (which i was told is the TG) - pm me with serial if u are willing to try.
___________________
"all rights reversed :-)"
R0=-0x18;
UNLINK;
RTS;
 

Offline olsenn

  • Frequent Contributor
  • **
  • Posts: 993
Re: Sniffing the Rigol's internal I2C bus
« Reply #830 on: August 12, 2013, 02:43:45 pm »
Quote
i dont know ;-) i dont have a DSA, but i believe the i have found the private key for it so i could generate keys, other than option 1 (which i was told is the TG) - pm me with serial if u are willing to try.

I'll message you with the serial number as soon as I get back to my desk. I'm assuming this shouldn't de-activate that option 1? I like my tracking generator :)

Is this a model change, or just activation of the add-ons?
 

Offline cybernet

  • Regular Contributor
  • *
  • Posts: 247
  • Country: 00
  • pm deactivated, use the search function ...
Re: Sniffing the Rigol's internal I2C bus
« Reply #831 on: August 12, 2013, 02:44:51 pm »
i dont know because i dont have a DSA - im working from a memory dump - no guarantees, it might blow up or whatever ;-)
no risc no fun.
___________________
"all rights reversed :-)"
R0=-0x18;
UNLINK;
RTS;
 

Offline cybernet

  • Regular Contributor
  • *
  • Posts: 247
  • Country: 00
  • pm deactivated, use the search function ...
Re: Sniffing the Rigol's internal I2C bus
« Reply #832 on: August 12, 2013, 02:50:39 pm »
i dont know because i dont have a DSA - im working from a memory dump - no guarantees, it might blow up or whatever ;-)
no risk no fun.

somebody took the risk - and has now fun ;-) thanks to the tester !
___________________
"all rights reversed :-)"
R0=-0x18;
UNLINK;
RTS;
 

Offline flolic

  • Frequent Contributor
  • **
  • Posts: 386
  • Country: hr
    • http://filiplolic.com/
Re: Sniffing the Rigol's internal I2C bus
« Reply #833 on: August 12, 2013, 02:57:53 pm »
 :-+
 

Offline H.O

  • Frequent Contributor
  • **
  • Posts: 821
  • Country: se
Re: Sniffing the Rigol's internal I2C bus
« Reply #834 on: August 12, 2013, 02:59:51 pm »
Wow, you guys are great. I don't have a SA and I don't really have a need for one but never the less, I'm impressed! Is anyone looking further into the possibillity of unlocking the BW on the DS4000 series?
 

Offline JimmyMz

  • Regular Contributor
  • *
  • Posts: 56
  • Country: us
Re: Sniffing the Rigol's internal I2C bus
« Reply #835 on: August 12, 2013, 03:00:33 pm »
somebody took the risk - and has now fun ;-) thanks to the tester !
WOW  :clap:
If you didn't get this message, let me know, and I'll get you another.
 

Offline olsenn

  • Frequent Contributor
  • **
  • Posts: 993
Re: Sniffing the Rigol's internal I2C bus
« Reply #836 on: August 12, 2013, 03:26:31 pm »
Cybernet: I sent you a PM with my serial number
 

Offline olsenn

  • Frequent Contributor
  • **
  • Posts: 993
Re: Sniffing the Rigol's internal I2C bus
« Reply #837 on: August 12, 2013, 03:47:45 pm »
Son of a bitch! IT WORKS!!!! I have 10Hz RBW now. I haven't tested the others yet

Release your work cybernet... you are the man!
 

Offline dr.diesel

  • Super Contributor
  • ***
  • Posts: 2214
  • Country: us
  • Cramming the magic smoke back in...
Re: Sniffing the Rigol's internal I2C bus
« Reply #838 on: August 12, 2013, 03:51:21 pm »
Release your work cybernet... you are the man!

Agreed,

815 powered up and waiting!

Offline Marc M.

  • Regular Contributor
  • *
  • Posts: 132
  • Country: us
Re: Sniffing the Rigol's internal I2C bus
« Reply #839 on: August 12, 2013, 03:54:50 pm »
Cybernet is the MAN :-+ :-+ :-+


10 Hz RBW!!!  8) 8)   (10 Mhz Sine output from DG4162 @ 400 mVpp)



VSWR Enabled!!!



AMK Enabled !!!!



It's Official!!!!

And it sticks after power cycling.
Don't replace the cap, just empty the filter!
 

Offline cybernet

  • Regular Contributor
  • *
  • Posts: 247
  • Country: 00
  • pm deactivated, use the search function ...
Re: Sniffing the Rigol's internal I2C bus
« Reply #840 on: August 12, 2013, 03:59:22 pm »
enjoy

http://pastebin.com/ghYHnCfT

would not have happend without jtag firmware dump from DL5TOR, ecc help from some guy and testing by marc - thanks guys.


PS: the windows tool makers, might want to integrate that into their tool - only the length of the serial & private key differ, rest is the same ! (RILOL !)
« Last Edit: August 12, 2013, 04:08:39 pm by cybernet »
___________________
"all rights reversed :-)"
R0=-0x18;
UNLINK;
RTS;
 

Offline JimmyMz

  • Regular Contributor
  • *
  • Posts: 56
  • Country: us
Re: Sniffing the Rigol's internal I2C bus
« Reply #841 on: August 12, 2013, 04:12:46 pm »
http://pastebin.com/ghYHnCfT
It would not have happened without:
The jtag firmware dump from DL5TOR
ecc help from some guy
Coding by Cybernet
Testing by Marc M.
I find it very selfless to release all your work for everyone to freely use. Good on all of you  :clap: :-+
« Last Edit: August 12, 2013, 04:16:39 pm by JimmyMz »
If you didn't get this message, let me know, and I'll get you another.
 

Offline olsenn

  • Frequent Contributor
  • **
  • Posts: 993
Re: Sniffing the Rigol's internal I2C bus
« Reply #842 on: August 12, 2013, 04:34:46 pm »
Now let's just see how long before Rigol is forced to release the 10Hz add-on for sale, haha
 

Offline Marc M.

  • Regular Contributor
  • *
  • Posts: 132
  • Country: us
Re: Sniffing the Rigol's internal I2C bus
« Reply #843 on: August 12, 2013, 04:40:43 pm »
Now let's just see how long before Rigol is forced to release the 10Hz add-on for sale, haha
Since this option isn't available outside of China, I'm also wondering what their reaction is going to be.  They certainly won't be very happy about this  :-DD.
Don't replace the cap, just empty the filter!
 

Offline tom66

  • Super Contributor
  • ***
  • Posts: 6722
  • Country: gb
  • Electronics Hobbyist & FPGA/Embedded Systems EE
Re: Sniffing the Rigol's internal I2C bus
« Reply #844 on: August 12, 2013, 05:43:21 pm »
Is the method similar for DS2000? Has that been broken already?
 

Offline dr.diesel

  • Super Contributor
  • ***
  • Posts: 2214
  • Country: us
  • Cramming the magic smoke back in...
Re: Sniffing the Rigol's internal I2C bus
« Reply #845 on: August 12, 2013, 06:09:15 pm »
WooHoo!

Note, for whatever reason compiling this on my Fedora 19 box truncates one character on all 3 variables, not sure why.  Anyhow, Mint 15 worked great.

Thanks again to all involved.

Offline jamesb

  • Regular Contributor
  • *
  • Posts: 54
  • Country: 00
Re: Sniffing the Rigol's internal I2C bus
« Reply #846 on: August 12, 2013, 06:14:56 pm »
Since this option isn't available outside of China, I'm also wondering what their reaction is going to be.  They certainly won't be very happy about this  :-DD.

Serves them right quite frankly :)

I wonder what impact the recent success in hacking the protection schema will have on hardware manufacturers deliberately crippling their products for residual sales. Will they strive to further harden their licensing schemes? Or will they abandon the "pay-for-addons" model realizing that the license scheme will be hacked at some point.
 

Offline olsenn

  • Frequent Contributor
  • **
  • Posts: 993
Re: Sniffing the Rigol's internal I2C bus
« Reply #847 on: August 12, 2013, 06:18:34 pm »
Quote
I  wonder what impact the recent success in hacking the protection schema will have on hardware manufacturers deliberately crippling their products for residual sales. Will they strive to further harden their licensing schemes? Or will they abandon the "pay-for-addons" model realizing that the license scheme will be hacked at some point.

To be fair, most of the people (I imagine) who would have purchased any of these add-ons, still will even though there is an illegal crack available. I think this thread is mostly for us hobbyists who stick to the free-or-nothing model
 

Offline dr.diesel

  • Super Contributor
  • ***
  • Posts: 2214
  • Country: us
  • Cramming the magic smoke back in...
Re: Sniffing the Rigol's internal I2C bus
« Reply #848 on: August 12, 2013, 06:21:43 pm »
To be fair, most of the people (I imagine) who would have purchased any of these add-ons, still will even though there is an illegal crack available. I think this thread is mostly for us hobbyists who stick to the free-or-nothing model

Agreed, the number of people that find this thread, manage to get it compiled and working are not even a blip on the screen for Rigol.  In-fact, for me, it's a reason to keep buying Rigol equipment, which I'll do unless they get real cranky and mess up our fun.

Offline jasonbrent

  • Regular Contributor
  • *
  • Posts: 176
Re: Sniffing the Rigol's internal I2C bus
« Reply #849 on: August 12, 2013, 06:24:39 pm »
To be fair, most of the people (I imagine) who would have purchased any of these add-ons, still will even though there is an illegal crack available. I think this thread is mostly for us hobbyists who stick to the free-or-nothing model

Agreed, the number of people that find this thread, manage to get it compiled and working are not even a blip on the screen for Rigol.  In-fact, for me, it's a reason to keep buying Rigol equipment, which I'll do unless they get real cranky and mess up our fun.

^^ This. I would have just kept "saving" and ordered an Agilent or something if the DS2072 wasn't hackable. :-)

-jbl
 


Share me

Digg  Facebook  SlashDot  Delicious  Technorati  Twitter  Google  Yahoo
Smf