Загрузка страницы

Starlink Dishy (Rev2 HW) Teardown Part 1 - UART, Reset, Boot Glitches

Teardown of Starlink Dishy: initial test point mapping including finding UART & reset pins. Experiments with shorting eMMC for pin2pwn style attacks. Note this 'rev2' has a different UART header than previous examples. With input & inspiration thanks to Lennert Wouters - be sure to follow https://twitter.com/LennertWo to catch more analysis (and a blog post at https://www.esat.kuleuven.be/cosic/blog/dumping-and-extracting-the-spacex-starlink-user-terminal-firmware/ now too)! Interesting times:

0:00 Intro
0:50 Snapping plastic open
2:10 Blowtorching to heat glue
3:51 PCB visual inspection
8:32 Probing for UART
14:56 Adding UART header
18:00 eMMC Short (pin2pwn)
22:15 Electromagnetic Fault Injection (EMFI)
27:20 Pin Strapping
30:02 Reset Pin / Header
34:00 Reset Pin Testing
36:00 Header Pinouting
38:17 JTAGulator Failing
39:00 Finishing Stuff

Previous teardowns:
-Mike (Nova Scotia!) UART details (see his earlier full teardown too): https://www.youtube.com/watch?v=38_KTq8j0Nw
-Ken (first to open the can!): https://www.youtube.com/watch?v=iOmdQnIlnRo
-TheSignalPath (RF stuff detailed): https://www.youtube.com/watch?v=h6MfM8EFkGg

Resources:
- $10 eMMC dumping: https://www.youtube.com/watch?v=6ofPbclXuZQ
- Book available soon: https://nostarch.com/hardwarehacking
- eMMC dumping details at: https://www.esat.kuleuven.be/cosic/blog/dumping-and-extracting-the-spacex-starlink-user-terminal-firmware/

Errata:
-POE = power over ethernet (I said 'on' for some reason and didn't notice until now)
-Mid-move so some weirdness of audio/lighting due to setup (like pause at 7:37 when screen froze and I didn't edit out...oops)

Видео Starlink Dishy (Rev2 HW) Teardown Part 1 - UART, Reset, Boot Glitches канала Colin O'Flynn
Показать
Комментарии отсутствуют
Введите заголовок:

Введите адрес ссылки:

Введите адрес видео с YouTube:

Зарегистрируйтесь или войдите с
Информация о видео
5 июля 2021 г. 9:43:07
00:40:07
Яндекс.Метрика