NefMoto

Technical => Reverse Engineering => Topic started by: tritri on July 16, 2017, 04:59:47 AM



Title: Disassembling c167cs ECU sagem s2pm-380, 29F200
Post by: tritri on July 16, 2017, 04:59:47 AM
ROM:00000248 sub_248:                                ; CODE XREF: ROM:00000F20p
ROM:00000248                 and     T01CON, #0FFh
ROM:0000024C                 mov     T01CON, #300h
ROM:00000250                 mov     T5CON, #0F001h
ROM:00000254                 mov     CCM4, #990h
ROM:00000258                 bset    T5R
ROM:0000025A                 bset    T1R
ROM:0000025C                 mov     r1, #0
ROM:0000025E
ROM:0000025E loc_25E:                                ; CODE XREF: sub_248+2Aj
ROM:0000025E                 mov     r0, [r1+4DC4h]  ;from the data in 4DC4h?
ROM:00000262                 mov     [r1+0E1C6h], r0 ;
ROM:00000266                 mov     r0, [r1+4D9Eh]  ;from the data in 4D9Eh?
ROM:0000026A                 mov     [r1+0E1A0h], r0


Hi everyone,

chip Infineon SAK-C167CS-LM
by the address  4DC4h and 4D9Eh (dword_4830) only 0FFFFFFFFh,
help to find the address from which data is copied here 4DC4h and 4D9Eh.
sorry for my English.


ROM:00004830 dword_4830:     dd 0FFFFFFFFh, 0FFFFFFFFh, 0FFFFFFFFh, 0FFFFFFFFh, 0FFFFFFFFh
ROM:00004830                 dd 0FFFFFFFFh, 0FFFFFFFFh, 0FFFFFFFFh, 0FFFFFFFFh, 0FFFFFFFFh


Title: Re: Disassembling c167cs ECU sagem s2pm-380, 29F200
Post by: tritri on July 18, 2017, 01:53:22 AM
the source code in IDA and photos