HACKING SD CARD & FLASH MEMORY CONTROLLERS
We hope that a few of our visitors are currently at this year’s Chaos communication Congress (schedule can be discovered here and online streams here), as many fascinating talks are happening. one of them addressed hacking the memory controllers embedded in all memory cards that you may have. As memory storage density increases, it’s more likely that some markets inside the embedded flash are defective. Therefore, all makers add a little microcontroller to their cards (along with additional memory) to invisibly ‘replace’ the defective markets to the operating system.
[Bunnie] as well as [xobs] went around getting many different microSD cards in buy to discover a hackable one. In their talk at 30C3 (slides here), they reported their findings on a specific microcontroller brand, Appotech, as well as its AX211/AX215. By reverse engineering the firmware code they discovered online, they found a simple “knock” sequence transmitted over manufacturer-reserved commands that dropped the controller into a firmware loading mode. From there, they were able to reverse engineer most of the 8051 microcontroller function-specific registers, allowing them to establish book applications for it. Some of the preliminary work was done utilizing a FPGA/i.MX6-based platform that the team developed named Novena, which we hope may be offered for purchase some day. It was, among others, utilized to simulate the FLASH memory chip that the team had previously removed. A video of the talk is embedded below.