a new stb with bcm7325 JTAG interface

Discussion in 'VuPlus Solo2 Hardware troubles and Repair support.' started by emmiko, Sep 13, 2019.

  1. emmiko

    emmiko New Member

    Messages:
    10
    Likes Received:
    5
    Trophy Points:
    3
    Gender:
    Male
    hello all
    i have a asia stb
    it use bcm7325 processor
    now i want get the stb dump via JTAG
    but i don't know which ones port is JTAG
    if anyone know please mark in photo
    thanks!
     

    Attached Files:

    Last edited: Sep 13, 2019
    Aliraza63 and toysoft like this.
  2. Johnny B.

    Johnny B. Technical Support Staff Member Moderator

    Messages:
    2,822
    Likes Received:
    1,504
    Trophy Points:
    113
    Gender:
    Male
    Location:
    Netherlands
    Home Page:
    Since pin 1 has 3v, it could be the four pins J132 close to the arrow above on the right.
    To be sure measure the pin 2 and 3, see if you have there the 3.2v, but also see if you can find out if these pin 2 and 3 has a 10kΩ resistor between the cpu and this pins which could be placed on the print side.
    In any case, if so, then you can assume that these are the jtag(I2c) pins.
    Normally starts with 3v pim, then the Scl (pin2) Sda(pin3) and pin four the ground.
    Better is only to use the Scl/Sda and ground pins.
     
    raza05 and Aliraza63 like this.
  3. emmiko

    emmiko New Member

    Messages:
    10
    Likes Received:
    5
    Trophy Points:
    3
    Gender:
    Male
    I uploaded the photo on the board back. you look
    one question
    your mean is not need connect 3V to CY7C68013A 3V , only connect Scl/Sda / ground to CY7C68013A?
     
  4. Johnny B.

    Johnny B. Technical Support Staff Member Moderator

    Messages:
    2,822
    Likes Received:
    1,504
    Trophy Points:
    113
    Gender:
    Male
    Location:
    Netherlands
    Home Page:
    I cannot see if these pins are connected to a resistor on the print side, better is to measure these two pins on the 3.2v voltages.
    And indeed, in most cases has this Cypress board already the 3v, thus to play it save use only the Scl/Sda/Ground.
    By using also the 3v pin you could risk damaging the 3v from the motherboard, not always, but could.
    It depends how this 3v circuit has been build.
     
    raza05 likes this.
  5. emmiko

    emmiko New Member

    Messages:
    10
    Likes Received:
    5
    Trophy Points:
    3
    Gender:
    Male
    ok
    i will frist try only connect Scl/Sda / ground ,if Broadband Studio not Identify it ,then to measure these two pins on the 3.2v voltages
     
  6. emmiko

    emmiko New Member

    Messages:
    10
    Likes Received:
    5
    Trophy Points:
    3
    Gender:
    Male
    hi johnny B.
    now i successful connection jtag by Broadband Studio 3
    but flash Explorer not have my flansh model
    ST M29W128GSH
    What should I do?
     
    toysoft likes this.
  7. Johnny B.

    Johnny B. Technical Support Staff Member Moderator

    Messages:
    2,822
    Likes Received:
    1,504
    Trophy Points:
    113
    Gender:
    Male
    Location:
    Netherlands
    Home Page:
    Yeah good question because I'm not familiar with the type box you have, but I hink, suppose that your box normally were running with the original vu+ solo image files , then you need probably upload the vu+ solo cfe.bin file.
    After it has successfully uploaded, with the bbs3, then, when the cfe fle is correct, you should be able to upload the image file by the regular usb way.
    However, when your box only runs on another special written image files, then yo may need another cfe bin file.
     
    raza05 likes this.
  8. emmiko

    emmiko New Member

    Messages:
    10
    Likes Received:
    5
    Trophy Points:
    3
    Gender:
    Male
    my stb is a asia paytv box
    i need get dump ,not is write cfe.bin
    have any Method ?
    thanks
     
    Johnny B. likes this.
  9. raza05

    raza05 Active Member

    Messages:
    138
    Likes Received:
    217
    Trophy Points:
    43
    Gender:
    Male
    Is this your model ? ...if yes then it's Vietnamese made K+ SMT-S5060 it's not common around ..you must look in Vietnamese sellers or software forums to get the original dump I 'll try to get if i found one i ll post it..BTW if flash explorer doesn't have the XML you cant use it in BBS Tool
     

    Attached Files:

    Last edited: Sep 20, 2019
    toysoft and Johnny B. like this.
  10. Johnny B.

    Johnny B. Technical Support Staff Member Moderator

    Messages:
    2,822
    Likes Received:
    1,504
    Trophy Points:
    113
    Gender:
    Male
    Location:
    Netherlands
    Home Page:
    Thanks Raza05,
    Because as for getting/creating an dump from the box, I've never done, thus also have no experiences with it.
    But when I would have the plans to do it, then I would probably use the Ejtag Mips method and I think that it on your board is the J131 connections close to the Jtag(2C) port.
     
    raza05 and emmiko like this.
  11. toysoft

    toysoft Well-Known Member Staff Member

    Messages:
    443
    Likes Received:
    551
    Trophy Points:
    93
    Gender:
    Male
    Location:
    Switzerland
    Home Page:
    It seems that the JTAG works, so next step would be to find or create the XML file for the Flash chip,... then perhaps he will be able to dump the Flash chip, hoping it's not encrypted or byte shuffled. If its in clear, then looks ok, the hardware seems to be from 2011.

    TS

     
    raza05, Johnny B. and emmiko like this.
  12. emmiko

    emmiko New Member

    Messages:
    10
    Likes Received:
    5
    Trophy Points:
    3
    Gender:
    Male
    yes,you also have the stb ?
     
  13. emmiko

    emmiko New Member

    Messages:
    10
    Likes Received:
    5
    Trophy Points:
    3
    Gender:
    Male
    I already got dump via a programmer to direct desolder read the BGA flash
    but unfortunately dump data is encrypted
    some people said it is encrypted by cpu key
    So maybe via power up stb then root access flash ,will get clear dump?
     
    Johnny B. likes this.
  14. toysoft

    toysoft Well-Known Member Staff Member

    Messages:
    443
    Likes Received:
    551
    Trophy Points:
    93
    Gender:
    Male
    Location:
    Switzerland
    Home Page:
    A read by the CPU thru JTAG could be possible ? Don't know, but yes I have seen that the CPU Key were used in such situations.

    TS
     
    raza05 and Johnny B. like this.
  15. emmiko

    emmiko New Member

    Messages:
    10
    Likes Received:
    5
    Trophy Points:
    3
    Gender:
    Male
    I just guess, actually I am an electronic beginner
    do you have good solution can get clear dump for the stb ?
    thanks
     
  16. toysoft

    toysoft Well-Known Member Staff Member

    Messages:
    443
    Likes Received:
    551
    Trophy Points:
    93
    Gender:
    Male
    Location:
    Switzerland
    Home Page:
    The only way is to extract the key from the CPU, some people were capable of doing it, and if I remember well these chips (Broadcom) weren't secure as also the ST Chipsets from where people were able to extract the keys. But I have no clue how they would extract them.

    TS
     
    raza05 and Johnny B. like this.
  17. raza05

    raza05 Active Member

    Messages:
    138
    Likes Received:
    217
    Trophy Points:
    43
    Gender:
    Male
    No I dont have this model ..But I have seen it .DO you previous boot loader of this ?
     
    Last edited: Sep 21, 2019
  18. emmiko

    emmiko New Member

    Messages:
    10
    Likes Received:
    5
    Trophy Points:
    3
    Gender:
    Male
    can i add your skype?
     
  19. raza05

    raza05 Active Member

    Messages:
    138
    Likes Received:
    217
    Trophy Points:
    43
    Gender:
    Male
    I am sorry I dont use skype ...you can ask here what ever you want to know ...would you like to share from start how this box got at this stage or bricked
     
    Johnny B. likes this.
  20. bibo1

    bibo1 Member

    Messages:
    62
    Likes Received:
    17
    Trophy Points:
    8
    Gender:
    Male
    hi Johnny,
    would You please so kind and provide me with a BCM7352, I needed for jtag a Vu solo original.
    Thank You in advance.