1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
@@ -1,5 +1,5 @@
-0000000: 0000 0000 00f0 0000 9234 8b5b fc02 0000  .........4.[....
+0000000: 0000 0000 00f0 0000 2298 fd46 fc02 0000  ........"..F....

firmware block checksum (1)

-0000010: 7cf7 0500 0300 0000 3727 0000 4000 0000  |.......7'..@...
+0000010: acf7 0500 0300 0000 3727 0000 4000 0000  ........7'..@...

firmware block size (1)

@@ -29,9 +29,9 @@
-00001f0: ffff ffff ffff ffff ffff ffff 0f46 925b  .............F.[
+00001f0: ffff ffff ffff ffff ffff ffff cfa9 0447  ...............G

header block checksum (1)

-0000200: 0100 0000 00f0 0000 9234 8b5b fc02 0000  .........4.[....
+0000200: 0100 0000 00f0 0000 2298 fd46 fc02 0000  ........"..F....

firmware block size (2)


-0000210: 7cf7 0500 0300 0000 3727 0000 4000 0000  |.......7'..@...
+0000210: acf7 0500 0300 0000 3727 0000 4000 0000  ........7'..@...

firmware block checksum (2)


@@ -61,14 +61,14 @@
-00003f0: ffff ffff ffff ffff ffff ffff 1046 925b  .............F.[
+00003f0: ffff ffff ffff ffff ffff ffff d0a9 0447  ...............G

header block checksum (2)

-0000460: 3801 0000 fc00 0000 0001 0000 0401 0000  8...............
+0000460: 80f7 0500 fc00 0000 0001 0000 0401 0000  ................

address loaded in PC by reset vector (0x138 -> 0x5f780)

@@ -24501,10 +24501,10 @@
-005fb70: 6446 c73f 4452 3edf 12f1 c23f ffff ffff  dF.?DR>....?....
-005fb80: ffff ffff ffff ffff ffff ffff ffff ffff  ................
-005fb90: ffff ffff ffff ffff ffff ffff ffff ffff  ................
-005fba0: ffff ffff ffff ffff ffff ffff ffff ffff  ................
+005fb70: 6446 c73f 4452 3edf 12f1 c23f 3801 0000  dF.?DR>....?8...
+005fb80: 2000 9fe5 0014 90e5 2010 81e3 0014 80e5   ....... .......
+005fb90: 2010 a0e3 8010 80e5 0213 a0e3 0110 51e2   .............Q.
+005fba0: fdff ff1a 30f0 1fe5 0000 0bc8 ffff ffff  ....0...........

injected payload, starts with original address loaded into PC
does button led light + delay loop then branch back to OF

=> no noticeable delay, no button led lit


@@ -983037,4 +983037,4 @@

-0effff0: 1f5a 7152 420b 3476 92cc cf8f 6456 de2a  .ZqRB.4v....dV.*
+0effff0: 1f5a 7152 420b 3476 92cc cf8f 0049 1ac4  .ZqRB.4v.....I..

File global checksum (32bits)