Decrypting Bravia Firmware BIN File

This is general talk area for things that NOT RELATED WITH TV! Instead, about internal works like web site, forum, wiki, or talking, etc...

sbav1
Official SamyGO Developer
Posts: 374
Joined: Fri Jan 15, 2010 10:20 am

Re: Decrypting Bravia Firmware BIN File

Post by sbav1 »

coolrecep wrote:what about this one:
U_RS232_RXD
U_RS232_TXD

Pin numbers 96 and 97 on page 88. Connector name CN5000, chip name IC5000.
Not a good place, IMO. IC5000 /MB91F313/ is Fujitsu low-power standby/secondary uC, i.e.: Sony "MIMAS" (Samsung "MICOM" equivalent), not the main SoC.
Certainly not the best place for serial console..

Main chip (Nec EMMA3TH) has 3+ built-in UARTs, see block diagrams & page 68 for details.
My bet is on EMMA3TH URT0TX/RX (M_UART0_RX/TX, "DTT Log", whatever that means). If there is a serial/debug console in that TV (we don't know that for sure; even if there is, it may be locked/disabled/restricted by default), that should be the place to look first, IMO.
You can clearly see the 6 solders left side of the chip. Two of them have trace. Those two traces are U_RS232_RXD and U_RS232_TXD, enoguh to get RS232 to work.
Yeah, it is an serial port, but probably not the right one. I think it's for MIMAS flashing/programming. It's kinda interesting, but (most likely) not really useful for any practical purposes.
I need to attack on the right port.
Keep looking ;), there are as many as 6 (7, 8?) serial ports/interfaces in your TV.
BTW, the TV has to be in the stand by mode right?
For anything to appear on serial console (if any), TV should be powered on, not on standby.
I don't want to fry anything :)
Well, there is an substantial risk you will fry/brick it, but no pain == no gain :). Do not try to connect anything directly to PC RS232 (+/-12V), without proper cable/converter!
P.S. I paid 40 bucks for those manuals :)
They are really nice :). It's the first service manual I've ever seen with the actual SIL9287 application note..
coolrecep
Posts: 18
Joined: Sun Oct 02, 2011 2:15 pm

Re: Decrypting Bravia Firmware BIN File

Post by coolrecep »

Tha helped a lot. I will give the credit to you and erdem when the project kicks off :)

As you and erdem say, the port I have found is not useful. Because it is not the debug port.

PDF says:

UART0_TXD/RXD
UART1_TXD/RXD

So, those ports are DTT Log and PQC Log beacuse they are named UART0 and UART1 respectively.

Image

Now I want to establish a connection to those ports to check whether they have shell or not.

On the other hand, those ports may not be the ports we are looking for. Could you please take a look at that pics.

Image

another one:

Image

I have also searched DTT, it may stand for Debug Test System, debug test target.

//Updated Info

Port name: CN5502 1-774-667-51 CONNECTOR, FFC/FPC 18P

Back sde of the PCB

Image

OK, finally, I think this is our magic port:

Image
User avatar
erdem_ua
SamyGO Admin
Posts: 3126
Joined: Thu Oct 01, 2009 6:02 am
Location: Istanbul, Turkey
Contact:

Re: Decrypting Bravia Firmware BIN File

Post by erdem_ua »

Congratulations, CN5502 is the port you are searching for. :-)
coolrecep
Posts: 18
Joined: Sun Oct 02, 2011 2:15 pm

Re: Decrypting Bravia Firmware BIN File

Post by coolrecep »

Bullseye! All right, now all we need is the proper tools and some knowledge :) BTW, I believe that this port is not disabled. If it was, Sony would not mention it on the PDF...I will PM you some time today erdem. Thanks.
nashagui
Posts: 2
Joined: Thu Jul 02, 2015 10:47 am

Re: Decrypting Bravia Firmware BIN File

Post by nashagui »

I like build a console cable with USB TTL+ FFC cable.

someone can sugest a pinout diagram ?

Is correct?

Image
uyjulian
Posts: 1
Joined: Sun Jan 04, 2026 2:55 pm

Re: Decrypting Bravia Firmware BIN File

Post by uyjulian »

For this TV here is a string dump from the raw flash dump starting at 0x63A70:

Code: Select all

Mar 30 2010
20:18:31
/ms/mssony/abk/bin
exec_
/rom/bin
preboot
autoboot
/rom
/ram
message
macaddr
boardip
netmask
hostip
gateway
SONY       CXD9645GB
NEC        uPD61060
NEC        uPD720102OHCI
NEC        uPD720102EHCI
NS         DP83815D
SONY       CXD9744GA
SONY       CXD9740GA
Toshiba    Tx4927
Toshiba    TC81240
TeraLogic  TL811
TeraLogic  TL850
SONY       PIF3
SONY       VIRGIL
NEC     
   MC10024
SONY       WAGNER
INTEL      i82559
PLX        PCI6152
SONY       BB3
REALTEK    RTL8100C
REALTEK    RTL8110SC
File already open
File not open
File write protected
File not found
Illegal path
Illegal file type
End of file
Write protected
File already exists
FileSystem full
No media
Write error
Read
 error
Erase error
System error
Media error
Format error
Check sum error
Command error
Mode error
Too many file open
Erase hungup upper
Erase hungup lower
Erase time out
Write hungup upper
Write hungup lower
Write time out
Busy error
Protocol error
File exists
Illegal parameter
No data
Device error
Initialize error
Address error
Not found
Time out error
Category error
Version error
Data corrected
ECC corrected
Uncorrectable error
Upper device error
Lower device error
Syntax error
Error : 
%s : 
Interrupt
TLB modification
TLB(load or fetch)
TLB(store)
Address error(load or fetch)
Address error(store)
Bus erro
r(instruction)
Bus error(data)
Syscall
Breakpoint
Reserved instruction
Coprocessor Unusable
Arithmetic Overflow
Trap
Floating-Point
Coprocessor 2
MDMX Unusable
Watch
Machine Check
Cache Error
[NMI]
[Exception]
   status:$12: 0x%08x, 
cause:$13: 0x%08x %s
 badvaddr: $8: 0x%08x, 
[31m
EPC:$14:   0x%08x, 
ErrorEPC:$30: 0x%08x
[register dump]
 at: r1: 0x%08x, 
v0: r2: 0x%08x, 
v1: r3: 0x%08x, 
a0: r4: 0x%08x
 a1: r5: 0x%08x, 
a2: r6: 0x%08x, 
a3: r7: 0x%08x, 
t0: r8: 0x%08x
 t1: r9: 0x%08x, 
t2:r10: 0x%08x, 
t3:r11: 0x%08x, 
t4:r12: 0x%08x
 t5:r13: 0x%08x, 
t6:r14: 0x%08x, 
t7:r15: 0x%08x, 
s0:r16: 0x%08x
 s1:r17: 0x%08x, 
s2:r18: 0x%08x, 
s3:r19: 0x%08x, 
s4:r20: 0x%08x
 s5:r21: 0x%08x, 
s6:r22: 0x%08x, 
s7:r23: 0x%08x, 
t8:r24: 0x%08x
 t9:r25: 0x%08x, 
gp:r28: 0x%08x, 
sp:r29: 0x%08x, 
s8:r30: 0x%08x
 ra:r31: 0x%08x, 
hi:   : 0x%08x, 
lo:   : 0x%08x
/ms/mssony/abk/bin/jigid
NEC EMMA3TH %1d.%1d
NEC EMMA3TH2 %1d%1d
abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789#$
frzkey
%02x
IndexInvalidate_I
IndexWritebackInvalidate_D
IndexLoadTag_I
IndexLoadTag_D
IndexStoreTag_I
InxStoreTag_D
CreateDirtyExclusive_D
HitInvalidate_I
HitInvalidate_D
Fill_I
HitWritebackInvalidate_D
HitWriteback_I
HitWriteback_D
Index
Random
EntryLo0
EntryLo1
Context
PageMask
Wired
BadVAddr
Count
EntryHi
Compare
Status
Cause
PRId
Config
LLAddr
WatchLo
WatchHi
XContext
CacheErr
TagLo
TagHi
ErrorEPC
Scratch
zero
move
blez
bgtz
addi
addiu
slti
sltiu
andi
xori
beql
bnel
blezl
bgtzl
daddi
daddiu
cache
lwc1
lwc2
ldc1
ldc2
swc1
swc2
sdc1
sdc2
sllv
srlv
srav
jalr
movz
movn
syscall
break
sync
mfhi
mthi
mflo
mtlo
dsllv
dsrlv
dsrav
mult
multu
divu
dmult
dmultu
ddiv
ddivu
addu
subu
sltu
dadd
daddu
dsub
dsubu
tgeu
tltu
dsll
dsrl
dsra
dsll32
dsrl32
dsra32
ssnop
rorv
drorv
mulu
muls
mulsu
macc
maccu
msac
msacu
mulhi
mulhiu
mulshi
mulshiu
macchi
macchiu
msachi
msachiu
dror
dror32
madd
maddu
mul64
msub
msubu
dclo
dclz
bltz
bgez
bltzl
bgezl
tgei
tgeiu
tlti
tltiu
teqi
tnei
bltzal
bgezal
bltzall
bgezall
mfps
mfpc
mtps
mtpc
mfc0
dmfc0
cfc0
mtc0
dmtc0
ctc0
mfc1
dmfc1
cfc1
mtc1
dmtc1
ctc1
bc0f
bc0fl
bc0t
bc0tl
bc1f
bc1t
bc1fl
bc1tl
tlbr
tlbwi
tlbwr
tlbp
eret
wait
.word
%08x : %08x
0x%08x
# %c0x%x
-0x%x
0x%x
0x%08x
/.history
serial
locked_by_rng
commonkey
ilin
kkey
dlnakey
podkey
podauthkey
poddhkey
marlinkey
sbbkey
cipluskey
marlinbbkey
ustvid2key
ustvid4key
ustvidseed
/.environment
serial '%s'
%s '%s'
Environment
$mount
UVFAT
Aperios 
ABK     
partition%d : %7d blocks ID %02x
[31mrenaming error : %s/%s 
<<< file-system check >>>
[0m--> recoverd
[31mFAT link error : %s/%s cluster %04x 
[0m--> removed
[31mFAT cluster error : %s/%s cluster %04x 
[31mfile size error : %s/%s %d %d 
FAT[%04x] = %04x, 
[31mdirectory start cluster error : %s/%s
[31mFAT floating entry error : 
.frs
.FRS
.frz
.FRZ
.mot
.MOT
.mip
.MIP
Execute.
Load File : %s
pentry
MIP format Address Error line %d %08x
MIP format Error line %d : %08x : [%s]%s
/dev/serial
octet
blksize
1024
ping
ifconfig
read
F@&1
F@&1
Mar 30 2010
20:18:31
/ms/mssony/abk/bin
exec_
/rom/bin
preboot
autoboot
/rom
/ram
message
macaddr
boardip
netmask
hostip
gateway
SONY       CXD9645GB
NEC        uPD61060
NEC        uPD720102OHCI
NEC        uPD720102EHCI
NS         DP83815D
SONY       CXD9744GA
SONY       CXD9740GA
Toshiba    Tx4927
Toshiba    TC81240
TeraLogic  TL811
TeraLogic  TL850
SONY       PIF3
SONY       VIRGIL
NEC     
   MC10024
SONY       WAGNER
INTEL      i82559
PLX        PCI6152
SONY       BB3
REALTEK    RTL8100C
REALTEK    RTL8110SC
File already open
File not open
File write protected
File not found
Illegal path
Illegal file type
End of file
Write protected
File already exists
FileSystem full
No media
Write error
Read
 error
Erase error
System error
Media error
Format error
Check sum error
Command error
Mode error
Too many file open
Erase hungup upper
Erase hungup lower
Erase time out
Write hungup upper
Write hungup lower
Write time out
Busy error
Protocol error
File exists
Illegal parameter
No data
Device error
Initialize error
Address error
Not found
Time out error
Category error
Version error
Data corrected
ECC corrected
Uncorrectable error
Upper device error
Lower device error
Syntax error
Error : 
%s : 
Interrupt
TLB modification
TLB(load or fetch)
TLB(store)
Address error(load or fetch)
Address error(store)
Bus erro
r(instruction)
Bus error(data)
Syscall
Breakpoint
Reserved instruction
Coprocessor Unusable
Arithmetic Overflow
Trap
Floating-Point
Coprocessor 2
MDMX Unusable
Watch
Machine Check
Cache Error
[NMI]
[Exception]
   status:$12: 0x%08x, 
cause:$13: 0x%08x %s
 badvaddr: $8: 0x%08x, 
[31m
EPC:$14:   0x%08x, 
ErrorEPC:$30: 0x%08x
[register dump]
 at: r1: 0x%08x, 
v0: r2: 0x%08x, 
v1: r3: 0x%08x, 
a0: r4: 0x%08x
 a1: r5: 0x%08x, 
a2: r6: 0x%08x, 
a3: r7: 0x%08x, 
t0: r8: 0x%08x
 t1: r9: 0x%08x, 
t2:r10: 0x%08x, 
t3:r11: 0x%08x, 
t4:r12: 0x%08x
 t5:r13: 0x%08x, 
t6:r14: 0x%08x, 
t7:r15: 0x%08x, 
s0:r16: 0x%08x
 s1:r17: 0x%08x, 
s2:r18: 0x%08x, 
s3:r19: 0x%08x, 
s4:r20: 0x%08x
 s5:r21: 0x%08x, 
s6:r22: 0x%08x, 
s7:r23: 0x%08x, 
t8:r24: 0x%08x
 t9:r25: 0x%08x, 
gp:r28: 0x%08x, 
sp:r29: 0x%08x, 
s8:r30: 0x%08x
 ra:r31: 0x%08x, 
hi:   : 0x%08x, 
lo:   : 0x%08x
/ms/mssony/abk/bin/jigid
NEC EMMA3TH %1d.%1d
NEC EMMA3TH2 %1d%1d
abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789#$
frzkey
%02x
IndexInvalidate_I
IndexWritebackInvalidate_D
IndexLoadTag_I
IndexLoadTag_D
IndexStoreTag_I
InxStoreTag_D
CreateDirtyExclusive_D
HitInvalidate_I
HitInvalidate_D
Fill_I
HitWritebackInvalidate_D
HitWriteback_I
HitWriteback_D
Index
Random
EntryLo0
EntryLo1
Context
PageMask
Wired
BadVAddr
Count
EntryHi
Compare
Status
Cause
PRId
Config
LLAddr
WatchLo
WatchHi
XContext
CacheErr
TagLo
TagHi
ErrorEPC
Scratch
zero
move
blez
bgtz
addi
addiu
slti
sltiu
andi
xori
beql
bnel
blezl
bgtzl
daddi
daddiu
cache
lwc1
lwc2
ldc1
ldc2
swc1
swc2
sdc1
sdc2
sllv
srlv
srav
jalr
movz
movn
syscall
break
sync
mfhi
mthi
mflo
mtlo
dsllv
dsrlv
dsrav
mult
multu
divu
dmult
dmultu
ddiv
ddivu
addu
subu
sltu
dadd
daddu
dsub
dsubu
tgeu
tltu
dsll
dsrl
dsra
dsll32
dsrl32
dsra32
ssnop
rorv
drorv
mulu
muls
mulsu
macc
maccu
msac
msacu
mulhi
mulhiu
mulshi
mulshiu
macchi
macchiu
msachi
msachiu
dror
dror32
madd
maddu
mul64
msub
msubu
dclo
dclz
bltz
bgez
bltzl
bgezl
tgei
tgeiu
tlti
tltiu
teqi
tnei
bltzal
bgezal
bltzall
bgezall
mfps
mfpc
mtps
mtpc
mfc0
dmfc0
cfc0
mtc0
dmtc0
ctc0
mfc1
dmfc1
cfc1
mtc1
dmtc1
ctc1
bc0f
bc0fl
bc0t
bc0tl
bc1f
bc1t
bc1fl
bc1tl
tlbr
tlbwi
tlbwr
tlbp
eret
wait
.word
%08x : %08x
0x%08x
# %c0x%x
-0x%x
0x%x
0x%08x
/.history
serial
locked_by_rng
commonkey
ilin
kkey
dlnakey
podkey
podauthkey
poddhkey
marlinkey
sbbkey
cipluskey
marlinbbkey
ustvid2key
ustvid4key
ustvidseed
/.environment
serial '%s'
%s '%s'
Environment
$mount
UVFAT
Aperios 
ABK     
partition%d : %7d blocks ID %02x
[31mrenaming error : %s/%s 
<<< file-system check >>>
[0m--> recoverd
[31mFAT link error : %s/%s cluster %04x 
[0m--> removed
[31mFAT cluster error : %s/%s cluster %04x 
[31mfile size error : %s/%s %d %d 
FAT[%04x] = %04x, 
[31mdirectory start cluster error : %s/%s
[31mFAT floating entry error : 
.frs
.FRS
.frz
.FRZ
.mot
.MOT
.mip
.MIP
Execute.
Load File : %s
pentry
MIP format Address Error line %d %08x
MIP format Error line %d : %08x : [%s]%s
/dev/serial
octet
blksize
1024
ping
ifconfig
read
write
mkdir
mknod
chmod
chown
format
fsck
more
reset
version
echo
syslog
help
/ms/mssony/abk/bin/
/rom/bin/
ABK>
%08x :              
direct
normal
%08x : %02x != %08x : %02x
%08x :
 %02x
 : %s
 %04x
 %08x
Size %x
root
user
-lbcpsd
%c%s%s%s %s 
%3d,%3d  
%8d 
%04d/%02d/%02d %02d:%02d:%02d 
%-34s
%s -> %s
mount-point      free-size      device-size capacity
%-11s 
%8dKBytes / %8dKBytes
     %3d%%
--------KBytes / --------KBytes
     ---%%
-all
-physical
-partition
%s %dMBytes
CurrentPath : %s
AP-e
<<< ABK Monitor >>>
d[b|w|l] [<Addr>] [<size>]        : dump [byte|word|longword]-access
m[b|w|l] <Addr> [<data>]          : modify [byte|word|longword]-access
f[b|w|l] <start> <end> <data>     : 
fill [byte|word|longword]-access
cm <src> <dist> <size>            : copy memory
c <src> <dist> <size>             : compare memory
a [<Addr>]                        : assemble
l [<Addr>] [<size>]               : disassemble
lr [direct|normal]                : change disassemble register mode
boot [<flags>]                    : execute file
  flags : [-sr|-frz|-elf] [<path>|-tftp <path>|-serial] [-o <option>]
     -sr : S-Record / -frz : FRZ / -elf : ELF(exec type only) /
     <pa
th> : file boot / -tftp <path> : tftp boot /
     -serial : serial boot / -o <option> : option
go <entry> [<arg1>] ..[<arg4>]    : execute function
reset                             : reset system
put <path>                        : TFTP put file
get <path>                        : TFTP get file
ping [<IP address>]               : send ICMP ECHO packets
ifconfig                          : show network configuration
syslog [<IP address>/off]         : control syslog
read <path> <addr>      
          : read file
write <path> <addr> <size>        : write file
ls [-a] <path>                    : list file
      -a : all file
rm [-r] <path>                    : remove file
      -r : recursive
cp [-r] <src_path> <dist_path>    : copy file
mv <src_path> <dist_path>         : move file
df                                : disk free
cd <path>                         : change directory
mkdir <path>                      : make directory
chmod <mode> <file>               : chan0
ge mode
chown <user> <file>               : change owner
    <user> : [root/user]
ln <src> <dist>                   : symbolic link
mknod <file> <type> [<maj> <min>] : make special file
  <type> : [b|c|p|s]
format <device_path> [<flags>]    : format filesystem
  flags : -physical : physical format
          -partition <p0>[,<p1>][,<p2>][,<p3>]
               <pn> : partition size ratio
fsck <device_path>                : file system check
echo [-n] [<arg1>] .. [<argn>]    : print ar
gument
wait                              : wait key
set [<environment>] [<value>]     : environment set
more <path>                       : show text file
pci                               : show PCI bus
version                           : show version
h[elp] | ?                        : show this message
-tftp
-serial
-frz
-elf
ABK Monitor  Version %s built at %s %s
Copyright 1999-2009 Sony Corporation
CPU : %s %3d.%02dMHz
Companion : %s %3d.%02dM
Board : %s %04x %3d.%02dMHz
Main memory : %dMBytes
PCI#%1d-%02d-%d : 
             
%d %s 0x%08x-0x%08x 
       
IRQ%03d 
Unknown(VID=0x%04x/DID=0x%04x) 
[PCI-PCI bridge]
%08x : %02x -> 
%08x : %04x -> 
%08x : %08x -> 
ip address %d.%d.%d.%d netmask %d.%d.%d.%d
gateway address 
%d.%d.%d.%d 
MAC address %02x:%02x:%02x:%02x:%02x:%02x
ping %s: 32 data bytes
32 bytes from %s: icmp_seq = %d, time=%dms
----- %s ping statistics -----
%d packets transmitted, %d packets r
eceived, %d%% packet loss
round-trip times: Minimum = %dms, Maximum = %dms, Average = %dms
Size %d
Fujitsu MBM30LV0128
Toshiba TC58DVM72A1FT00
Toshiba TC58DVM82A1FT00
Toshiba TC58DVM92A1FT00
Toshiba TC58DVG02A1FT00
Samsung K9F2808U0C
Samsung K9F5608U0C
Samsung K9F1208U0B
Samsung K9T1G08U0A
Hynix HY27US08561M
Hynix HY27US08121M
Hynix HY27US081G1M
STMicro NAND128W3A
STMicro NAND256W3A
STMicro NAND512W3A
STMicro NAND01GW3A
BDIF
UNEC VR5500
NEC EMMA3TH
E3TH
M3.009C
E3TH
E3TH
write
mkdir
mknod
chmod
chown
format
fsck
more
reset
version
echo
syslog
help
/ms/mssony/abk/bin/
/rom/bin/
ABK>
%08x :              
direct
normal
%08x : %02x != %08x : %02x
%08x :
 %02x
 : %s
 %04x
 %08x
Size %x
root
user
-lbcpsd
%c%s%s%s %s 
%3d,%3d  
%8d 
%04d/%02d/%02d %02d:%02d:%02d 
%-34s
%s -> %s
mount-point      free-size      device-size capacity
%-11s 
%8dKBytes / %8dKBytes
     %3d%%
--------KBytes / --------KBytes
     ---%%
-all
-physical
-partition
%s %dMBytes
CurrentPath : %s
AP-e
<<< ABK Monitor >>>
d[b|w|l] [<Addr>] [<size>]        : dump [byte|word|longword]-access
m[b|w|l] <Addr> [<data>]          : modify [byte|word|longword]-access
f[b|w|l] <start> <end> <data>     : 
fill [byte|word|longword]-access
cm <src> <dist> <size>            : copy memory
c <src> <dist> <size>             : compare memory
a [<Addr>]                        : assemble
l [<Addr>] [<size>]               : disassemble
lr [direct|normal]                : change disassemble register mode
boot [<flags>]                    : execute file
  flags : [-sr|-frz|-elf] [<path>|-tftp <path>|-serial] [-o <option>]
     -sr : S-Record / -frz : FRZ / -elf : ELF(exec type only) /
     <pa
th> : file boot / -tftp <path> : tftp boot /
     -serial : serial boot / -o <option> : option
go <entry> [<arg1>] ..[<arg4>]    : execute function
reset                             : reset system
put <path>                        : TFTP put file
get <path>                        : TFTP get file
ping [<IP address>]               : send ICMP ECHO packets
ifconfig                          : show network configuration
syslog [<IP address>/off]         : control syslog
read <path> <addr>      
          : read file
write <path> <addr> <size>        : write file
ls [-a] <path>                    : list file
      -a : all file
rm [-r] <path>                    : remove file
      -r : recursive
cp [-r] <src_path> <dist_path>    : copy file
mv <src_path> <dist_path>         : move file
df                                : disk free
cd <path>                         : change directory
mkdir <path>                      : make directory
chmod <mode> <file>               : chan0
ge mode
chown <user> <file>               : change owner
    <user> : [root/user]
ln <src> <dist>                   : symbolic link
mknod <file> <type> [<maj> <min>] : make special file
  <type> : [b|c|p|s]
format <device_path> [<flags>]    : format filesystem
  flags : -physical : physical format
          -partition <p0>[,<p1>][,<p2>][,<p3>]
               <pn> : partition size ratio
fsck <device_path>                : file system check
echo [-n] [<arg1>] .. [<argn>]    : print ar
gument
wait                              : wait key
set [<environment>] [<value>]     : environment set
more <path>                       : show text file
pci                               : show PCI bus
version                           : show version
h[elp] | ?                        : show this message
-tftp
-serial
-frz
-elf
ABK Monitor  Version %s built at %s %s
Copyright 1999-2009 Sony Corporation
CPU : %s %3d.%02dMHz
Companion : %s %3d.%02dM
Board : %s %04x %3d.%02dMHz
Main memory : %dMBytes
PCI#%1d-%02d-%d : 
             
%d %s 0x%08x-0x%08x 
       
IRQ%03d 
Unknown(VID=0x%04x/DID=0x%04x) 
[PCI-PCI bridge]
%08x : %02x -> 
%08x : %04x -> 
%08x : %08x -> 
ip address %d.%d.%d.%d netmask %d.%d.%d.%d
gateway address 
%d.%d.%d.%d 
MAC address %02x:%02x:%02x:%02x:%02x:%02x
ping %s: 32 data bytes
32 bytes from %s: icmp_seq = %d, time=%dms
----- %s ping statistics -----
%d packets transmitted, %d packets r
eceived, %d%% packet loss
round-trip times: Minimum = %dms, Maximum = %dms, Average = %dms
Size %d
Fujitsu MBM30LV0128
Toshiba TC58DVM72A1FT00
Toshiba TC58DVM82A1FT00
Toshiba TC58DVM92A1FT00
Toshiba TC58DVG02A1FT00
Samsung K9F2808U0C
Samsung K9F5608U0C
Samsung K9F1208U0B
Samsung K9T1G08U0A
Hynix HY27US08561M
Hynix HY27US08121M
Hynix HY27US081G1M
STMicro NAND128W3A
STMicro NAND256W3A
STMicro NAND512W3A
STMicro NAND01GW3A
BDIF
UNEC VR5500
NEC EMMA3TH
E3TH
M3.009C
E3TH
E3TH
Unfortunately the rest of the flash appears to be encrypted. Based on the strings contained I suspect it would be MIPS but the beginning of the flash (presumably relocated at 0xBFC00000) doesn't look like MIPS code.

Post Reply

Return to “General”