Practical MC13224 firmware extraction

Travis Goodspeed wrote this article on his blog detailing his extraction of firmware from the MC13224 that had been read protected. This is the same MCU used in the Defcon 18 badge and the Redwire Econotag.

He presents two methods. In one he decaps the SPI flash memory chip using nitric acid, then removes and repackages it. The second method involves accessing Pin 133 of the memory chip, when can be used to initiate a reset and process to provide access to the contents.

Leave a comment

Your email address will not be published. Required fields are marked *

Notify me of followup comments via e-mail. You can also subscribe without commenting.