PDA

View Full Version : KESS2\K-TAG lpc2478 UNLOCK



EduardNN
15th November, 2015, 04:47 AM
A method of disabling the protection CRP3 microcontroller LPC2478.
This method does not allow the reading of locked memory microcontroller.

https://youtu.be/G2EteKs_haQ

EduardNN
15th November, 2015, 08:26 PM
Details...
350?C

dorofteius
15th November, 2015, 08:41 PM
Good work friend.
Probably the success rate is not 100 %, but it is a good solution.
We thank you alll.

EduardNN
15th November, 2015, 10:09 PM
K-Tag pins. Photography is not mine

pinotec
15th November, 2015, 10:42 PM
try ,but When I connect pin 148 mcu > 3.3v
led red not blink

simaservis1108
16th November, 2015, 02:07 AM
Good find,MCU is susceptible to power glitch.

morgano
16th November, 2015, 10:36 AM
Not that susceptible to power glitch i guess. Thinking how things work, i suspect the trick is that after certain ammount of heat the microprocessor cannot read properly the flash content upon initialization, if just one single bit of the CRP3 pattern gets changed/corrupted the bootloader not enter/obey CRP3 mode inmediately and allow bootmode to kick in. Guess after that, the only operation allowed without recheck for CRP3 pattern again is FULL ERASE, that's why you cannot read MCU content once it cooled and have access to flash again. This is all theory/educated guess, haven't tested myself over a real MCU.

arvedo
16th November, 2015, 12:57 PM
j-link You can read, is to try but always the same failure
no read target memory

valdirld
16th November, 2015, 01:26 PM
have you try with ktag?

arvedo
16th November, 2015, 02:35 PM
I see it takes two tools,
flash magic + j link.
I have only jlink I can do it, or do I need another tool where I can buy, Greetings

EduardNN
16th November, 2015, 05:13 PM
Only rs232 (uart) + flash magic.

pinotec
17th November, 2015, 09:23 PM
need connect 12v ?
my led red always off if not connect 12v

EduardNN
18th November, 2015, 07:14 AM
LED need to monitor the state of the processor and it must be switched by the controller. If you do not have the power on the controller when connected by USB, then connect the other power source.

Dutsov
19th November, 2015, 05:38 PM
Good find, will check soon ;)

Sent from my GT-N7100 using Tapatalk

Dutsov
22nd November, 2015, 04:41 PM
Can i ask for help here, i lifted off one pad from my ktag, and i cant find now where it should connect it to make it work. I marked it with yellow, its one of the pads that should be connected with white wire. i tried to solder wire, but it was too thick, and i lifted the whole pad as marked ... i preheated it i think, and it felt with the wire ;( I need to know where is it going, so i can fix it ...

Dutsov
23rd November, 2015, 09:36 AM
Tried but not working, do you need to give 3.3v somewhere to Ktag, like in Kess? Or just heat and try to connect?

pinotec
23rd November, 2015, 02:59 PM
for kt*g you can try these 2 points

Dutsov
23rd November, 2015, 03:04 PM
Its gnd and 3.3v ... what to wire there?

Sent from my GT-N7100 using Tapatalk

choro
23rd November, 2015, 03:39 PM
hello friends
after reset the CPU then what are the steps?
please post dump for NXP MCU and SD card arhive
thanks

prosec
23rd November, 2015, 03:42 PM
i need ktag lpc2478
bin file
do you have?

pinotec
23rd November, 2015, 04:01 PM
hello friends
after reset the CPU then what are the steps?
please post dump for NXP MCU and SD card arhive
thanks


i need ktag lpc2478
bin file
do you have?

just use the search button forum

pinotec
23rd November, 2015, 04:02 PM
Its gnd and 3.3v ... what to wire there?

Sent from my GT-N7100 using Tapatalk

are the same points that used in the video , just in different location

Dutsov
23rd November, 2015, 05:45 PM
but in the video its kess, no video with ktag and what to do with the 3.3v ...

Dutsov
24th November, 2015, 08:33 PM
So, we solder wire to 3.3v and touch ground?

pinotec
25th November, 2015, 03:04 PM
yes ,and hot air

Gibek
26th November, 2015, 09:25 AM
So, Is it possible to reset tokens as we reflash new firmware to the nxp that was locked and erased ?

hackgsm
27th November, 2015, 02:16 AM
no work with ktag is fake

matteo87
27th November, 2015, 03:00 AM
no work with ktag is fake
:goodnight:

Dutsov
27th November, 2015, 10:48 AM
I also try with ktag now without success, i heat it untill green light stops itself ... then when it power on again, i reset with 3.3v and gnd ... tried alot times, either i make something wrong, or its just not working ...

bersch8688
28th November, 2015, 05:50 PM
Have anyone Hexfile to programm Kess V2 without CRP3???

Dutsov
28th November, 2015, 05:52 PM
You can make your hex from bin with jlink sw

Sent from my GT-N7100 using Tapatalk

valdirld
4th December, 2015, 07:19 PM
unloacked by kess, not write nxp, put nxp in ktag, write ok and work

Dutsov
8th December, 2015, 07:39 AM
So we get one kess for unlock nxp then put in ktag? This mean not only me have no sucess with ktag unlock?

Sent from my GT-N7100 using Tapatalk

xirtam
27th January, 2016, 01:44 AM
nice job:burnout:

gopelhu
27th January, 2016, 05:27 AM
Hi all,

Here are all pinouts.

Regards

Dutsov
4th February, 2016, 11:18 AM
I got problem with my kess ... i tried on 3 kess, no success, the problem is, when i connect the 25pin plug to kess, with the 2 jumped gnds, i dont get my kess tool red light on. If i disconnect the 25pin plug, i got it working. I tried first to plug the kess, to get the red light on, then to plug the 25 pin one ... and after one touch of the 3.3v wire(reset) i again get not lighting red light. Double and tripple checked, made few 25 pin connectors for tests, but when i connect pin1 and pin25 as on the pictures, kess dont start, and pc dont recognise it. I have now 3 laptops, and 3 kess to test, and they all work the same way ... just dont turn on with the 25pin plug in. Anybody know a fix?

valdirld
4th February, 2016, 02:23 PM
you try invert the plug coneection?
i have this issue, inverted the cable and all ok

alcorte
29th February, 2016, 06:57 AM
Hi all,

Here are all pinouts.

Regards
His pcb ktag is reset button , but If the pcb ktag isn?t reset button? Where can I find pinout the two blue wires " reset button"?

Thank you.

Kayhan 17#
20th March, 2016, 01:34 PM
i was directed that i can do this with jlink, but on page 1, eduard tells us that its not working, so my question is now am i be able to glitch with my jlink and reflash or do i ahve to wait for a new uart device?

EduardNN
20th March, 2016, 09:20 PM
To flash the LPC2478 via Jlink, the level of protection should be CRP0, ie protection should be disabled. If security levels CRP1 and CRP2 have the ability to erase and reflash LPC2478 via UART, eg via USB to UART TTL adapter ftdi232 or cp2102 and Flashmagic program.
So buy a new chip or USB to UART TTL adapter.

morcegao
5th April, 2016, 06:34 PM
I used this method yesterday, my NXP was blocked with C555, Kess working again, great job,
Now I do not worry about block nxp

chiptorque
7th April, 2016, 08:17 AM
Hello partners. I tried with 3 KESS make the operation as the videos and I have not been successful. you can tell me how much time and temperature? I tried 300c? and 350?. the red light is off but nothing. there is another type of operation? raise some PIN?


thanks and regards.

jackeldestripador
14th September, 2016, 07:59 PM
TxD and RxD pins are 5v ? just for try with some max232 to rs232 common interface

visio
26th March, 2017, 01:35 AM
Hello from Argentina, i'am need firmware for kess 4.036 and Ktag 2.13 for repair with jlink. The interfaz is dead, after the internet conexion. Thank you.

2xded
26th March, 2017, 07:49 AM
Hi visio!
You do not need to flash the processor. It is necessary to replace the SD-card and update the protocols.
Good luck.

BWF
30th May, 2017, 08:12 PM
After this you can read the NXP?


Is there any way to read the NXP?

29f001
25th September, 2018, 11:00 AM
Good work thanks