Lost Vape Thelema Quest-nuvoton

Discussion in 'Suggestions' started by tim_buktu, Jan 9, 2022.

  1. tim_buktu

    tim_buktu Member

    Joined:
    Jul 7, 2018
    Messages:
    94
    Likes Received:
    56
    Hello @maelstrom2001
    my ICP-Tool came on friday. After connecting some wires to the factory programming contacts at the bottom side of the PCB, I got this :(:(
    upload_2022-1-9_15-19-1.png

    Bad luck:(. I think we cannot solve it that way. But I had to try...
     
    maelstrom2001, widyahong and DePott like this.
  2. maelstrom2001

    maelstrom2001 Developer
    NFE Team

    Joined:
    May 4, 2017
    Messages:
    1,670
    Likes Received:
    1,541
    Hello @tim_buktu!
    Anyway, thank you for attempt and info on it.
    As I said earlier, probably, there is a chance to found the firmware in SPI EEPROM:
    [​IMG]

    Well, at least, for STM32. How it works on Nuvoton MCUs, we can only guess.
    Yes, it's pretty tricky, but if you have spare time and desire, it is possible to read this EEPROM with CH341A programmer.
    Just a note :)
     
    #2 maelstrom2001, Jan 9, 2022
    Last edited: Jan 9, 2022
    tim_buktu likes this.
  3. tim_buktu

    tim_buktu Member

    Joined:
    Jul 7, 2018
    Messages:
    94
    Likes Received:
    56
    uuuhh! thats crasy, man. I didn't realise that already. This little guy provides 8x64Kbyte, connected to SPI0
    How does that work? The MCU loads code from eeprom o_O, really?!
    How did they manage to create that simple UI out of that?
    Could be possible to use an arduino via SPI to read out the eeprom, but would we get the whole firmware from it?
    It's kinda rocket science in there...:confused:
     
  4. maelstrom2001

    maelstrom2001 Developer
    NFE Team

    Joined:
    May 4, 2017
    Messages:
    1,670
    Likes Received:
    1,541
    Yep:

    I have not disassembled this bundle in new firmwares yet, but it seems that sooner or later I will have to do it.
    I know, this looks strange, but it is definitely the preparation for the release of the firmware updater by Lost Vape.

    The chance of this is still higher than reading a protected MCU :D