I used this to EMP pulse a locked processor to gain access and extract flash memory from it.
Gave a talk at hardwear.io this year on it. YouTube live stream here: https://youtube.com/live/0tkdst3JE0g
HN user
@BitBangingBytes on X
I Reverse Engineer Smart Meters and anything embedded I can get my hands on.
I used this to EMP pulse a locked processor to gain access and extract flash memory from it.
Gave a talk at hardwear.io this year on it. YouTube live stream here: https://youtube.com/live/0tkdst3JE0g
Have you published anything about this anywhere? I also had to work on the SLEIGH file for the M16C.
Overall it just seemed like the processor definition for Ghidra needed more work.
I don’t know if it was autocorrected or what, but it was SAM when I hit submit.
Edit: seems I could fix it, thanks!
The glitch has to happen within the window shown to you by the microcontroller. It seems to be in a different location for each microcontroller evaluated. The fact that it shows you where depending on which processor you’re attacking is pretty convenient!
All decoupling caps were removed so the voltage fault injection could have maximum effect.
Starting a Reverse Engineering Weekly News Show, second week. All feedback is welcome!
There are two radio’s in the meter, one for zigbee and one for the 900MHz mesh that sends this data back to power company. The zigbee side isn’t used at all here anymore, they killed our ability to view our usage with it.