Products > Test Equipment

Sniffing the Rigol's internal I2C bus

<< < (375/899) > >>

JDubU:

--- Quote from: neslekkim on December 10, 2013, 06:30:27 pm ---Maybe I confused myself with this and the earlier talk about the LMH6518, I thought that one was not beeing changed on the hacked models, or is that something else or ?

--- End quote ---

The LMH6518 is the input amplifier IC that can receive commands from the firmware to change both input attenuation and bandwidth.  What commands are available to be sent to this chip by the user interface/firmware is the subject of the hacking efforts.

cosmos:
Storing serial number etc:
There is the Actel ProASIC flash based FPGA.
The A3P030 (and the rest of the family) have a small (1024 bits) flash based memory area "FlashROM" that can be accessed both from JTAG and userspace.

cut from Actel document: http://www.microsemi.com/document-portal/doc_download/130889-proasic3-fpga-fabric-user-s-guide
************
The  FlashROM  content  can  be  changed  independently  of  the  FPGA  core  content.  It  can  be  easily
accessed and programmed via JTAG, depending on the security settings of the device. The SmartGen
core generator enables each region to be independently updated (described in the "Programming and
Accessing FlashROM" section on page 124). This enables you to change the FlashROM content on a
per-part basis while keeping some regions "constant" for all parts. These features allow the FlashROM to
be used in diverse system applications. Consider the following possible uses of FlashROM:
•    Internet protocol (IP) addressing (wireless or fixed)
•    System calibration settings
•    Restoring configuration after unpredictable system power-down
•    Device serialization and/or inventory control
•    Subscription-based business models (e.g., set-top boxes)
•    Secure key storage
•    Asset management tracking
•    Date stamping
•    Version management
************

The security settings seems to refer to 128b AES encryption ... but the AES part is missing from the low end devices that Rigol uses.

Both ds4k and ds2k have the same proASIC and it is tasked with reading the board version number too...
would not be so strange if they put the serial number and maybe model number too in there?
Just next to it is a JTAG connector (not the same as used for Xilinx or Blackfin) so it will be easy to find for the person that programs the model type and puts the sticker on...

neslekkim:

--- Quote from: JDubU on December 10, 2013, 06:39:46 pm ---
--- Quote from: neslekkim on December 10, 2013, 06:30:27 pm ---Maybe I confused myself with this and the earlier talk about the LMH6518, I thought that one was not beeing changed on the hacked models, or is that something else or ?

--- End quote ---

The LMH6518 is the input amplifier IC that can receive commands from the firmware to change both input attenuation and bandwidth.  What commands are available to be sent to this chip by the user interface/firmware is the subject of the hacking efforts.

--- End quote ---

Ok, so this chip behaves, and is controlled exactly same on all models, so one doesnt need to worry about this one to be handled differently through the 2072 - 2302 models?
If so, that makes it easy to chose which model to buy at least..
The price difference between the 2072a-s and 2202a-s is $940 here, and the $358 between the 2072a-s and the 2102a-s..  (in Norway)

cybernet:
thx cosmos - will see if i find code for it.

thetooth:
Just a thought but since theres so much information around and mostly spread across this forum thread i think its time a lot of the facts are consolidated in same way.

Unless someones already done it i can host a wiki on one of my jap based VPS's, has 2TB/month bandwidth thats mostly unused. I'm not in a position to manage it full time though so if you feel like taking it on send a pm with your email or some form of contact and i'll set you up as an admin.

I can also mirror the keygen since its mostly javascript correct? Then eventually setup a firmware archive of sorts...

Navigation

[0] Message Index

[#] Next page

[*] Previous page

There was an error while thanking
Thanking...
Go to full version
Powered by SMFPacks Advanced Attachments Uploader Mod