Fun Box is Open!      Poll What Do You Want for Christmas?      Buy, Sell, & Trade Forum Open!
Hacker Robinsond has open-sourced the schematics sources and details that are required to make your your own PIC interface required to perform the timing attack that allows you to boot the 1888 base kernel. This means even if you have burned fuses and dont know your CPU key, you can boot to the respective kernel and update the exploitable kernel.

Downloads: Schematic / PIC BootLoader / PIC Binary / Documentation

The timing attack is working well now, the software has been released for testing and if no major problems are found then it will be available at the end of the week. The first release will require an Infectus modchip and a "home made" PIC interface. I thought I would release the details of the PIC today to give people a chance to order parts, build and test the hardware.

Parts List:

IC1 LM339
IC2 LM339
IC3 74HC08
IC4 PIC16F876A 20MHz
IC5 MAX232 or equivalent

1 * LED
1 * 20MHz Crystal

16 * 1K 0.25W 5%
1 * 10K 0.25W 5%
1 * 680R 0.25W 5%
1 * 330R 0.25W 5%
1 * 5K6 0.25W 5%

2 * 22pF Ceramic Cap
9 * 100nF Ceramic Cap

Please note, 100nF decoupling caps across every ICs power supply pins seems to reduce the noise on the power supply and VRef lines. Reduced noise = Less jitter in the timing measurements which is a good thing

Tomorrow I will release the tool that will build downgradable flash images. Hopefully by then the 2.0.1888 file set will be available in "the usual places".

(0) Comments   Share   E-Mail Article   PermaLink