http://www.usbjtag.com/vbforum 1212,1212

JTAG (NT) on Cable Boxes

Moderator: justsomeguy

Locked
papaseed
Junior Member
Posts: 5
Joined: Mon Feb 09, 2009 9:39 am

http://www.usbjtag.com/vbforum 1212,1212

Post by papaseed »

Hi I am a newbie. The USBJTAG NT software report for HELP:
copy/paste:
Copyright http://www.usbjtag.com 2008,2009,2010
USB JTAG NT 0.39
-getram firm
Time 00:01:09 (.312)
-getram ram
Time 00:01:09 (.875)
-DETECT
IDCODE 2D424041
STi STi7100
IMPCODE 0104109C
EJTAG V1, V2.0
DMA supoorted
Unknown flash type!
Report these two value to http://www.usbjtag.com/vbforum 1212,1212
UNQUOTE.

Please may I know what is 1212, I have edited the flash into the xml file as below:
</flash>
<flash>
<id1>0x20</id1>
<id2>0x8857</id2>
<name>ST M28W640FSU</name>
<size>0x800000</size>
<protocol>1</protocol>
<block>
<secnum>64</secnum>
<secsize>0x20000</secsize>
</block>
</flash>
<flash>
<id1>0x20</id1>
<id2>0x8858</id2>
<name>ST M28W640FST</name>
<size>0x800000</size>
<protocol>1</protocol>
<block>
<secnum>8</secnum>
<secsize>0x2000</secsize>
<secnum>127</secnum>
<secsize>0x10000</secsize>
</block>
</flash>
<flash>
<id1>0x20</id1>
<id2>0x8859</id2>
<name>ST M28W640FSB</name>
<size>0x800000</size>
<protocol>1</protocol>
<block>
<secnum>127</secnum>
<secsize>0x10000</secsize>
<secnum>8</secnum>
<secsize>0x2000</secsize>
</block>

Unquote.

Is there any other place in the config file need to be edited?
Please help.
Thank you.
CAPONE
Junior Member
Posts: 5011
Joined: Sat Dec 27, 2008 3:25 pm

Post by CAPONE »

Whould be very usefull to know WHAT ARE YOU WORKING ON ?;)
papaseed
Junior Member
Posts: 5
Joined: Mon Feb 09, 2009 9:39 am

1212.1212 problem

Post by papaseed »

Dear Sir TUNDRA,
I am trying to jtag a cable Box CPU STi7100 with Flash ST M28W640FST to get the dump.bin. It is a Top boot 8x2000 and 127x10000 flash chip. My primary aim is to get the BoxKey from this dump.
As the box's Flash chip is FULLY covered by epoxy resin, the best method is jtagging the STB. The above value was extracted by drilling and scraping the very hard epoxy carefully to get a view of the Flash chip. Jtag pinout are correct:
19 - Trst
17 - unknown
15 - Tdo
13 - Tdi
11 - Tck
9 - Tms
7 - unknown
5 - unknown
3 - unknown
1 - unknowm
2 to 20 - GND
I have lifted the CPU and trace the track that the above is correct.
There is also a 4 pin port for DEBUG in the box, any useful procedures required for this extended port?

I dont know how to correctly edit a Test file - T3800HD (name created by me) for this box.
Also I am an OLDMAN Newbie, my progress may not be as fast as youngsters, please bear with me.
Thank you.
usbbdm
Junior Member
Posts: 8974
Joined: Mon Jul 18, 2005 9:33 pm

Post by usbbdm »

I think if you detect first and then read you might get better data. The CPU is DCU3 JTAG and so far NT does not support the write. Read is fine.
papaseed
Junior Member
Posts: 5
Joined: Mon Feb 09, 2009 9:39 am

St dcu 3

Post by papaseed »

Thank you.
usbbdm
Junior Member
Posts: 8974
Joined: Mon Jul 18, 2005 9:33 pm

Post by usbbdm »

I am interested in this target after DCU3 support. I will search to find one of Sti7100 target to play with.
Locked

Who is online

Users browsing this forum: No registered users and 5 guests