Flash Extractor
© Soft-Center
About     Shop     Downloads     Manual     Library     Forum     Services     Contacts
Recovery at home -- a tale of SD cards and woe...   Search  Register  Log in
Reply to topic
Author Message

Joined: 23 Jun 2012
Posts: 2
Location: Mountain View, CA

PostPosted: Mon Jun 25, 2012 11:47    Post subject: Recovery at home -- a tale of SD cards and woe...
Reply with quote

Hi folks.

I've been browsing the web for the past few days, and it seems like there really is precious little information out there on on-flash formats...

A few weeks ago, I dropped my laptop, and it landed on the SD card sticking out of the side of it, resulting in
a pretty ghastly scene. I figured that since I didn't care about the data all *that* much, I wasn't worried about make things worse, and so I got to work building some hardware to dump the NAND flash out. A bunch of hacking later, I have what seems like a reasonable looking dump of the flash -- the entropy level looks right, and there are definite patterns to it -- but it appears to be arranged in a way that makes very little sense to me, and there are not any of the strings that I expect in it. (You can see the full set of photos from what I did here, if anyone is wondering what people do when they *don't* have real labs to do this all in Very Happy)

Looking around the web, it looks like a handful of these cards are XORed, but when I tried XORing the first 32MB or so with all single-byte combinations, I still didn't get the 'FAT32' string that I expected to be in there. This is using an EN2683B-BA controller; it seems like it's a something along the lines of http://flash-extractor.com/library/SM/EN2683/EN2683__ec_de_d5_7a__2x1 , though I'm not sure exactly what the above maps to. How does the wear leveling work on these? Am I wrong in expecting the 'FAT32' string to be at the beginning? Also, has anyone ever managed to extract a datasheet for the controller out of Silicon Motion?

If anyone can give me a hand with this, I'd be more than happy to share my RTL for the FPGA so that people can dump even tougher flash devices.

(bonus in the link above: my attempts to reconnect with the original flash controller. I bought another two of the same type of SD card -- the same SKU from Amazon, even! -- but it was too late, and they had switched to two packages, presumably with a different firmware on the flash controller. I also attempted to reuse the original flash controller, but I think it probably got fried by a pin-to-pin short when the card originally got crumpled.)

Best regards, and thanks to anyone who might be able to help!
Display posts from previous:   
Reply to topic All times are GMT + 4 Hours
Page 1 of 1


Last added
IS917   45 3a a5 82   1x2 Monolith SD_1   45 3e 9b 92   1x1 20-82-00549   45 3a 95 93   4x4 AU6989   ec d7 94 7e   1x1 Monolith SD_1   45 3e 96 93   1x1 SM3267L-AE   2c a4 64 32   1x1 20-82-00549   45 de 94 93   2x4   v3 SK6211   2c d5 94 3e   2x2 SD_61   2c 64 40 3c   2x2 IS902   2c 38 00 26   2x1
18.10.2017 Power adapter
07.10.2016 Conatiner v9
07.09.2016 VT / Auto - new mode
27.07.2016 CR2 files support
10.04.2016 Processor Cores
Other products
© Soft-Center ltd.