General NAS-Central Forums

Welcome to the NAS community
It is currently Mon Oct 16, 2017 10:00 pm

All times are UTC




Post new topic Reply to topic  [ 4 posts ] 
Author Message
 Post subject: Small ROM at 0x40000000
PostPosted: Tue Sep 16, 2008 10:10 pm 
Offline

Joined: Tue Sep 09, 2008 9:56 am
Posts: 39
There is a 1024 bytes ROM area at 0x40000000.

The full purpose of this area is not yet known, but it's called from the DES3 crypto.


Top
 Profile  
 
PostPosted: Tue Sep 16, 2008 10:38 pm 
Offline

Joined: Tue Sep 09, 2008 9:56 am
Posts: 39
The DES3 crypto uses two entry points in this area, which returns blobs in %i0 - %i5

0x400003f0:

0x696c6c47
0x6f49504f
0x496e6672
0x616e7457
0x54727573
0x74474f44

0x400003f8:

0x9635112a
0x7ce09060
0xbed817f7
0x27b728d2
0x91a8468a
0x94b92e42


Top
 Profile  
 
PostPosted: Tue Sep 16, 2008 10:43 pm 
Offline

Joined: Tue Sep 09, 2008 9:56 am
Posts: 39
The layout of the 0x40000000 are is

1. initial bootstrap, loading the first stage bootloader at 0x30000000 from somewhere..

2. Then the crypto related blobs mentioned earlier.

3. A 256 bytes blob of unknown data at 0x40000280 - 0x4000037F

4. The signature "IT3107 ROM1.0" ac 0x400003E0

5. The entry points for the crypto blobs

[end]


Top
 Profile  
 
PostPosted: Thu Sep 18, 2008 6:57 pm 
Offline

Joined: Tue Sep 09, 2008 9:56 am
Posts: 39
The first key if read in "bottom up" (the way it's used during encryption) reads in ASCII:

"TrustGODInfrantWillGoIPO"


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 4 posts ] 

All times are UTC


Who is online

Users browsing this forum: No registered users and 4 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group