Kenwood TH-D74A: Difference between revisions

From RECESSIM, A Reverse Engineering Community
Jump to navigation Jump to search
No edit summary
No edit summary
Line 42: Line 42:
</gallery><br />
</gallery><br />


== Reverse Engineering Efforts ==
==Reverse Engineering Efforts==
[[File:Kenwood TH-D74 and JTAGulator.jpg|none|thumb|Kenwood TH-D74 connected to JTAGulator]]
[[File:Kenwood TH-D74 and JTAGulator.jpg|none|thumb|Kenwood TH-D74 connected to JTAGulator]]


=== High level goals ===
===High level goals===


* Obtain a copy of the firmware for analysis/modification
*Obtain a copy of the firmware for analysis/modification
* Understand how the radio works and what test ports are available internally
*Understand how the radio works and what test ports are available internally


==== Obtaining firmware ====
====Obtaining firmware====


* Determine routes of attack
*Determine routes of attack
** JTAG Port
**JTAG Port
** Serial Port
**Serial Port
** Hardware attack - Remove Flash Memory and read directly (possibly encrypted)
**Hardware attack - Remove Flash Memory and read directly (possibly encrypted)


Initially the radio was opened and wires were soldered to test points and a port of interest as seen in the video below.
Initially the radio was opened and wires were soldered to test points and a port of interest as seen in the video below.
<br />
<br /><nowiki><youtube></youtube></nowiki>


==== Understand how the radio works ====
====Understand how the radio works====
<br />
<br />
==Datasheets==
==Datasheets==

Revision as of 23:23, 7 June 2020

Fully Assembled Kenwood TH-D74A

Teardown Video

6 minute video @ 3x playback speed showing full disassembly of the radio with commentary, full length video with no audio here.

Teardown PCB Pictures

Modules and Interconnects


Mechanical Pictures


Reverse Engineering Efforts

Kenwood TH-D74 connected to JTAGulator

High level goals

  • Obtain a copy of the firmware for analysis/modification
  • Understand how the radio works and what test ports are available internally

Obtaining firmware

  • Determine routes of attack
    • JTAG Port
    • Serial Port
    • Hardware attack - Remove Flash Memory and read directly (possibly encrypted)

Initially the radio was opened and wires were soldered to test points and a port of interest as seen in the video below.
<youtube></youtube>

Understand how the radio works


Datasheets

Kenwood TH-D74A Datasheet - IC-701 - DRAM

Kenwood TH-D74A Datasheet - IC-702 - omap-l138

Kenwood TH-D74A Datasheet - IC-705 - FLASH MEMORY

IC-707 - Not exact match but same family - WM8940