Firmware Hacking

Status
Not open for further replies.

Tebbens

Member
Joined
Apr 29, 2015
Messages
10
Location
Fishkill, NY
I recently pulled apart the Windows Uniden Updater App (BC_VUP_V3_03_00) and found how it pulls the FW from Uniden.... so I pulled the FW manually.

Does anyone know what Processor Uniden uses in their scanners and/or specifically the BCD325P2?
I want to load the FW into a disassembler, but it looks to be packed or obfuscated.
 

RT48

Member
Joined
Apr 6, 2014
Messages
243
Location
Cuyahoga County, Ohio
I recently pulled apart the Windows Uniden Updater App (BC_VUP_V3_03_00) and found how it pulls the FW from Uniden.... so I pulled the FW manually.

Wireshark probably would have told you the same thing which is how I monitored how Sentinel pulls the database updates.
 

Tebbens

Member
Joined
Apr 29, 2015
Messages
10
Location
Fishkill, NY
Pulling apart the FW Updater to see exactly how its coded tells me a lot more about how it all works....and gives me some insight into how it communicates with the device....and a few other things.
 

jonwienke

More Info Coming Soon!
Joined
Jul 18, 2014
Messages
13,409
Location
VA
The firmware is encrypted, to discourage people from altering it to allow monitoring of the cellular bands. Good luck breaking it.
 

Tebbens

Member
Joined
Apr 29, 2015
Messages
10
Location
Fishkill, NY
Anyone who wants to monitor cell can just pick up an SDR .... much of the fw has already has been reversed, its just not going to be released.
 

Ubbe

Member
Joined
Sep 8, 2006
Messages
10,055
Location
Stockholm, Sweden
The firmware is encrypted, to discourage people from altering it to allow monitoring of the cellular bands. Good luck breaking it.
The encryption key have been found and are on that twitter page. If you got lots of spare money to get the hard and software needed and the brains you can do it, and he did. It is solely for his own pleasure and satisfaction and he made a code generator for himself to produce the key codes for DMR, NXDN, ProVoice and Extreme upgrades just to make a proof of concept, not to rob Uniden of their upgrade money.

The only real use of disassembled code are to see how it's structured and coded that migh give some ideas for you own coding work, and perhaps make some special modifications to the original code to better suit your specific needs. I would absolutly welcome a way to edit the code to change the bandplan frequency boundries and alter all the reverse and repeater frequencies.

I think the guy are situated in the eastern european block and even in my country we are allowed to decrypt all transmissions and software and reverse engineer everything as long as it isn't made for profitable purposes like defeating per per view systems and then making it available to the public.

/Ubbe
 
Status
Not open for further replies.
Top