Kenwood TH-D74A: Difference between revisions
No edit summary |
No edit summary |
||
| Line 42: | Line 42: | ||
</gallery><br /> | </gallery><br /> | ||
== Reverse Engineering Efforts == | |||
[[File:Kenwood TH-D74 and JTAGulator.jpg|none|thumb|Kenwood TH-D74 connected to JTAGulator]] | |||
=== High level goals === | |||
* Obtain a copy of the firmware for analysis/modification | |||
* Understand how the radio works and what test ports are available internally | |||
==== Obtaining firmware ==== | |||
* Determine routes of attack | |||
** JTAG Port | |||
** Serial Port | |||
** Hardware attack - Remove Flash Memory and read directly (possibly encrypted) | |||
Initially the radio was opened and wires were soldered to test points and a port of interest as seen in the video below. | |||
<br /> | |||
==== Understand how the radio works ==== | |||
<br /> | |||
==Datasheets== | ==Datasheets== | ||
[[:File:Kenwood TH-D74A Datasheet - IC-701 - DRAM.pdf|Kenwood TH-D74A Datasheet - IC-701 - DRAM]] | [[:File:Kenwood TH-D74A Datasheet - IC-701 - DRAM.pdf|Kenwood TH-D74A Datasheet - IC-701 - DRAM]] | ||