Kicking Zynq in the vccint (dumping the bootrom the hard way)
2021-04-02 16:11:24 Author: www.reddit.com(查看原文) 阅读量:192 收藏

level 1

Original Poster9 minutes ago

This kinda documents how I got the bootrom for some of the other work I did and posted here a while back (and also CVE-2021-27208).

Planning to publish the CVE writeup soon, but otherwise there are a few more stones to overturn:

  • fabric boot - basically, the ARM cores spin until the FPGA fabric comes up, then boot off AXI

  • bitstream encryption/decryption (is it possible?)

We'll see which and in what order I eventually get around to those - I'd be plenty happy if someone beat me to it ;)

1


文章来源: https://www.reddit.com/r/ReverseEngineering/comments/mievav/kicking_zynq_in_the_vccint_dumping_the_bootrom/
如有侵权请联系:admin#unsafe.sh