Proxmark3 community

Research, development and trades concerning the powerful Proxmark3 device.

Remember; sharing is caring. Bring something back to the community.


"Learn the tools of the trade the hard way." +Fravia

You are not logged in.

Announcement

Time changes and with it the technology
Proxmark3 @ discord

Users of this forum, please be aware that information stored on this site is not private.

#1 2017-02-15 00:06:52

0xFFFF
Administrator
From: Vic - Australia
Registered: 2011-05-31
Posts: 632

iCLASS SE Modules BTSmart / OSDP / ...

For those who might be interested in what's under the tin can...

PCB%20Populated%20Top.jpg

IC's:
Nordic Semiconductor nRF51822
Multiprotocol Bluetooth® low energy/2.4 GHz RF System on Chip
http://infocenter.nordicsemi.com/pdf/nR … S_v3.1.pdf

NXP LPC1227
32-bit ARM Cortex-M0 microcontroller; up to 128 kB flash and 8 kB SRAM
http://www.nxp.com/documents/data_sheet/LPC122X.pdf

Linear Technology LTC2852
LCRY
N607
435
http://cds.linear.com/docs/en/datasheet/285012fe.pdf

Offline

#2 2017-02-15 00:10:29

dylanger
Contributor
From: Sydney
Registered: 2016-06-22
Posts: 30

Re: iCLASS SE Modules BTSmart / OSDP / ...

Thoes look like SWD pads to me? Hook her up to a debugger? Maybe it'll allow you do dump the firmware

Offline

#3 2017-02-15 00:47:49

0xFFFF
Administrator
From: Vic - Australia
Registered: 2011-05-31
Posts: 632

Re: iCLASS SE Modules BTSmart / OSDP / ...

It's on my To Do list!
I'm busy de-capping ICs and reversing the R10E PCB ATM.

Offline

#4 2017-02-15 00:49:08

dylanger
Contributor
From: Sydney
Registered: 2016-06-22
Posts: 30

Re: iCLASS SE Modules BTSmart / OSDP / ...

Wholy smokes! Godspeed

Offline

#5 2017-04-09 04:31:11

0xFFFF
Administrator
From: Vic - Australia
Registered: 2011-05-31
Posts: 632

Re: iCLASS SE Modules BTSmart / OSDP / ...

A very uninteresting dump of the Numonyx 25P16 found on the OSDP module.

Connecting to the LPC1227 on the BTSmart module...

Connecting ...
 - Connecting via USB to J-Link device 0
 - J-Link firmware: V1.20 (J-Link ARM V8 compiled Feb  8 2012 14:30:39)
 - JTAG speed: 200 kHz (Auto)
 - Initializing CPU core (Init sequence) ...
    - Initialized successfully
 - JTAG speed: 200 kHz (Auto)
 - CPU clock frequency: 16000 kHz
 - Connected successfully
Reading selected sectors ...
 - 32 of 32 sectors selected, 1 range, 0x0 - 0x1FFFF
 - ERROR: RAM check failed @ address 0x10000000.
 - ERROR: Write: 0x03020100 07060504
 - ERROR: Read: 0x00000000 00000000
 - ERROR: (0 bytes of RAM have been checked successfully)
 - ERROR: Failed to read back target memory

Offline

Board footer

Powered by FluxBB