MCU reverse engineering

Microcontroller Unlock - MikaTech

Our values and goals

About MikaTech

Time went fast, from the day we did our first 8051 MCU reverse engineering project in 1998, to the day we set up our million dollar reverse engineering lab in 2012, 14 years went by. Now we start our new business of embedded visual system development, hope we can serve another 10 years.

sign Peter Lee Co-Founder & CEO

GAL PAL PALCE PEEL ATF Series PLD Hacking

GAL16V8 PAL16V8 PALCE16V8 PEEL16V8 and ATF16V8, sometimes they looks very confusing, below are the brands that make them

 

Programmable Array Logic (PAL) is a family of programmable logic device semiconductors used to implement logic functions in digital circuits introduced by Monolithic Memories, Inc. (MMI) in March 1978. MMI obtained a registered trademark on the term PAL for use in "Programmable Semiconductor Logic Circuits". The trademark is currently held by Lattice Semiconductor. The Generic Array Logic (GAL) device was an innovation of the PAL and was invented by Lattice Semiconductor. The GAL was an improvement on the PAL because one device was able to take the place of many PAL devices or could even have functionality not covered by the original range. Its primary benefit, however, was that it was eraseable and re-programmable making prototyping and design changes easier for engineers. PEEL (programmable electrically erasable logic) was introduced by the International CMOS Technology (ICT) corporation. Programmable Array Logic CMOS Electrically-Erasable (PALCE), the trademark is currently held by Lattice Semiconductor.

atmel microcontroller hack

Atmel Microcontroller Crack

Atmel Corporation manufactured two mainstream electrically erasable Flash-based programmable logic lines: ATF SPLDs (pin-compatible with GAL/PALCE) and ATF15xx JTAG ISP CPLDs, plus legacy ATV UV-erasable EPLDs. Atmel was acquired by Microchip in 2016, and all discrete PLD products are discontinued. This document lists all standard mass-produced base PLD models, excluding hybrid FPSLIC SOCs and standalone FPGAs.

1. ATF Flash E²CMOS SPLD Family

ATF16V8 20-Pin 8-Macrocell Devices

ATF16V8, ATF16V8B, ATF16V8C

ATF16V8BQ, ATF16V8BQL, ATF16V8CZ

ATF16LV8, ATF16LV8C

ATF20V8 24-Pin 8-Macrocell Devices

ATF20V8, ATF20V8B, ATF20V8C

ATF20V8BQ, ATF20V8BQL

ATF20LV8, ATF20LV8C

ATF22V10 Flagship Variable-Term SPLD

ATF22V10, ATF22V10B, ATF22V10C

ATF22V10CQ, ATF22V10CQZ

ATF22LV10, ATF22LV10C

High-Density Extended SPLDs

ATF28V12, ATF29M16

2. ATF15xx JTAG ISP Complex Programmable Logic Devices (CPLDs)

ATF1500 32 Macrocell Entry CPLD

ATF1500A, ATF1500AL

ATF1502 32 Macrocell Mid-Density CPLD

ATF1502AS, ATF1502ASL, ATF1502ASV, ATF1502ASVL

ATF1504 64 Macrocell Mid-Density CPLD

ATF1504AS, ATF1504ASL, ATF1504ASV, ATF1504ASVL

ATF1508 128 Macrocell High-Density CPLD

ATF1508AS, ATF1508ASL, ATF1508ASV, ATF1508ASVL

Vintage Medium Density CPLDs

ATF750C, ATF750CL, ATF750LVC

ATF2500C, ATF2500CL, ATF2500LVC

3. ATV UV-Erasable Legacy EPLD Series

ATV750, ATV750B

ATV2500, ATV2500B

MMI MCU Dump

Monolithic Memories Inc. (MMI) created the first commercial PAL (Programmable Array Logic) fuse-based one-time programmable SPLD in 1978. Before AMD’s acquisition in 1987, MMI launched four core PLD product lines: standard fuse PALs, high-speed AmPAL, UV-erasable PALC CMOS PALs, and mask-programmed HAL hard array logic. All devices use the programmable AND / fixed OR array architecture for sum-of-products digital logic implementation. This document enumerates all standard mass-production base model numbers designed and manufactured by MMI.

1. 20-Pin Standard Fuse PAL Family

Combinatorial PAL Devices

PAL10H8, PAL10L8, PAL10P8

PAL12H6, PAL12L6, PAL12P6

PAL14H4, PAL14L4, PAL14P4

PAL16C1

PAL16H2, PAL16L2, PAL16P2

PAL16H4, PAL16L4, PAL16P4

PAL16H6, PAL16L6, PAL16P6

PAL16H8, PAL16L8, PAL16P8

Registered Synchronous PAL Devices

PAL16R4, PAL16R6, PAL16R8

PAL16RP4, PAL16RP6, PAL16RP8

XOR Enhanced PAL Devices

PAL16X4, PAL16X6, PAL16X8

2. 24-Pin Standard Fuse PAL Family

Combinatorial 24-Pin PALs

PAL18H4, PAL18L4, PAL18P4

PAL20C1

PAL20H2, PAL20L2, PAL20P2

PAL20L8, PAL20S10

PAL22V10 (Fuse-based original 24-pin variable macrocell PAL)

Registered 24-Pin PALs

PAL20R4, PAL20R6, PAL20R8

XOR 24-Pin PALs

PAL20X4, PAL20X6, PAL20X8

Wide-Bus High-Density PALs

PAL32R16, PAL32X16

3. AmPAL High-Speed Advanced PAL Series

AmPAL16P8

AmPAL20L10

AmPAL22P10

AmPAL22XP1

4. PALC UV-Erasable CMOS PAL

PALC22V10 (UV windowed EPROM-style erasable PAL, MMI’s only erasable pre-acquisition PLD)

5. HAL Mask-Programmed Hard Array Logic (Factory Custom PLDs)

HAL10H8, HAL12H6, HAL14H4

HAL16C1, HAL16H2, HAL16H8, HAL16L2, HAL16L8

HAL18L4, HAL20L2, HAL20L8, HAL20L10

ICT Microcontroller Attack

International CMOS Technology (ICT) was a Taiwan-based secondary supplier of small-scale programmable logic devices. Its entire PLD portfolio consists of second-sourced fuse PAL OTP chips, UV-erasable PALC CMOS PALs, and electrically erasable GAL-compatible SPLDs. ICT never launched proprietary CPLD or FPGA product lines. This document lists all standard mass-production base SPLD models.

1. Fuse-Based OTP TTL PAL Series

20-Pin Combinatorial PAL

PAL10H8, PAL10L8, PAL10P8

PAL12H6, PAL12L6, PAL12P6

PAL14H4, PAL14L4, PAL14P4

PAL16C1

PAL16H2, PAL16L2, PAL16P2

PAL16H4, PAL16L4, PAL16P4

PAL16H6, PAL16L6, PAL16P6

PAL16H8, PAL16L8, PAL16P8

20-Pin Registered PAL

PAL16R4, PAL16R6, PAL16R8

PAL16RP4, PAL16RP6, PAL16RP8

20-Pin XOR PAL

PAL16X4, PAL16X6, PAL16X8

24-Pin Combinatorial PAL

PAL18H4, PAL18L4, PAL18P4

PAL20C1

PAL20H2, PAL20L2, PAL20P2

PAL20L8, PAL20S10

PAL22V10

24-Pin Registered PAL

PAL20R4, PAL20R6, PAL20R8

24-Pin XOR PAL

PAL20X4, PAL20X6, PAL20X8

Wide-Bus PAL

PAL32R16, PAL32X16

2. PALC UV-Erasable CMOS PAL Series

20-Pin PALC Devices

PALC10H8, PALC10L8

PALC12H6, PALC12L6

PALC14H4, PALC14L4

PALC16C1

PALC16H2, PALC16L2, PALC16P2

PALC16H4, PALC16L4, PALC16P4

PALC16H6, PALC16L6, PALC16P6

PALC16H8, PALC16L8, PALC16P8

PALC16R4, PALC16R6, PALC16R8

PALC16RP4, PALC16RP6, PALC16RP8

PALC16X4, PALC16X6, PALC16X8

24-Pin PALC Devices

PALC18H4, PALC18L4

PALC20C1

PALC20H2, PALC20L2, PALC20P2

PALC20R4, PALC20R6, PALC20R8

PALC20X4, PALC20X6, PALC20X8

PALC20S10

PALC22V10

3. GAL E²CMOS Electrically Reprogrammable SPLD Series

GAL16V8

GAL16V8, GAL16V8A, GAL16V8B, GAL16V8D

GAL20V8

GAL20V8, GAL20V8A, GAL20V8B

GAL22V10

GAL22V10, GAL22V10B

Special GAL Models

GAL18V10, GAL20RA10, GAL26CV12

1. PEEL Small-Scale SPLD Series (20/24-pin, GAL/PALCE Drop-In Replacements)

1.1 PEEL18CV8 Family (20-pin, 8 macrocells, replaces ATF16V8 / GAL16V8)

PEEL18CV8

PEEL18CV8Z (ultra-low power standby variant)

PEEL18LV8 (3.3V low voltage core)

PEEL18LV8Z (3.3V ultra-low power)

1.2 PEEL20CG10 Family (24-pin, 8 macrocells, replaces GAL20V8 / ATF20V8)

PEEL20CG10

PEEL20CG10A (enhanced speed variant)

1.3 PEEL22CV10 Flagship 24-pin SPLD (10 variable product-term macrocells, replaces GAL22V10 / ATF22V10)

PEEL22CV10

PEEL22CV10A (standard commercial)

PEEL22CV10AZ (zero-power low standby current)

PEEL22LV10 (3.3V low voltage)

PEEL22LV10AZ (3.3V ultra-low power)

2. PEEL Array High-Density CPLD Series (Multi-macrocell ISP Complex PLDs)

2.1 PEEL153 (Low-density CPLD, compatible with PLS153)

PEEL153

2.2 PEEL173 (Mid-density CPLD, compatible with PLS173 / PAL20L10)

PEEL173

2.3 PEEL253 (Mid-high density array)

PEEL253

2.4 PEEL273 (High-density base array)

PEEL273

atmel microcontroller crack

AMD Integrated Circuit (ic) Copy

PALCE16V8H PALCE16V8Q PALCE16V8Z ...
PALCE20V8H PALCE20V8Q ...
PALCE20RA10 PALCE20RA10H PALCE20RA10Q ...
PALCE22V10 PALCE22V10H PALCE22V10Q PALCE22V10Z ...
PALCE26V12H PALCE26V12H/4 ...

cypress source code recovery

Cypress Integrated Circuit (ic) Crack

Cypress Semiconductor produced two primary categories of programmable logic devices: legacy small-scale SPLDs including UV-erasable PALC, electrically reprogrammable PALCE, and second-sourced fuse OTP PALs; plus high-density JTAG in-system programmable Flash CPLD families (FLASH370i, Ultra37000, MAX340, Quantum38K, Delta39K). This document lists all standard mass-produced base PLD models, excluding PSoC mixed-signal embedded logic and custom mask ICs.

1. Legacy SPLD Series

1.1 PALC UV-Erasable CMOS PAL Devices

20-Pin PALC

PALC10H8, PALC10L8

PALC12H6, PALC12L6

PALC14H4, PALC14L4

PALC16C1

PALC16H2, PALC16L2, PALC16P2

PALC16H4, PALC16L4, PALC16P4

PALC16H6, PALC16L6, PALC16P6

PALC16H8, PALC16L8, PALC16P8

PALC16R4, PALC16R6, PALC16R8

PALC16RP4, PALC16RP6, PALC16RP8

PALC16X4, PALC16X6, PALC16X8

24-Pin PALC

PALC18H4, PALC18L4

PALC20C1

PALC20H2, PALC20L2, PALC20P2

PALC20R4, PALC20R6, PALC20R8

PALC20X4, PALC20X6, PALC20X8

PALC20S10

PALC22V10

1.2 PALCE Electrically Erasable SPLDs

PALCE16V8, PALCE20V8, PALCE22V10, PALCE24V10, PALCE29M16

1.3 Fuse-Based OTP TTL PAL Second-Sourced Models

PAL10H8, PAL10L8, PAL10P8

PAL12H6, PAL12L6, PAL12P6

PAL14H4, PAL14L4, PAL14P4

PAL16C1

PAL16H2, PAL16L2, PAL16P2

PAL16H4, PAL16L4, PAL16P4

PAL16H6, PAL16L6, PAL16P6

PAL16H8, PAL16L8, PAL16P8

PAL16R4, PAL16R6, PAL16R8

PAL16RP4, PAL16RP6, PAL16RP8

PAL16X4, PAL16X6, PAL16X8

PAL18H4, PAL18L4, PAL18P4

PAL20C1, PAL20H2, PAL20L2, PAL20P2

PAL20R4, PAL20R6, PAL20R8

PAL20X4, PAL20X6, PAL20X8

PAL20S10

PAL22V10

PAL32R16, PAL32X16

2. Flash ISP CPLD Families

FLASH370i Generation

CY7C371i, CY7C372i, CY7C373i, CY7C374i, CY7C375i

Ultra37000 Mainstream CPLDs

CY37032, CY37032V

CY37064, CY37064V

CY37128, CY37128V

CY37192, CY37192V

CY37256, CY37256V

CY37384, CY37384V

CY37512, CY37512V

MAX340 Low-Cost CPLDs

CY34032, CY34064, CY34128

Quantum38K High-Speed CPLDs

CY38K032, CY38K064, CY38K128, CY38K256

Delta39K Large-Scale Industrial CPLDs

CY39K064, CY39K128, CY39K256, CY39K512, CY39K1000

STM extract encryption flash memory

STM Integrated Circuit (ic) firmware Attack

GAL16V8 GAL16V8A ... GAL20V8 GAL20V8A ... GAL22V10 ... GAL6001 ...

General Questions About Microcontroller Firmware Extraction


  • Is it safe to send payment to MikaTech ?

    If MikaTech was a bad company, you could find tons of bad reputations about its service on the internet over the 28 years history

    So, the answer is YES! We are good people.

    Why choose Mikatech, please click here to find out


  • Can Mikatech break ics not listed on this site ?

    Different chip manufacturers have different part numbers, but the inner core of the chip can be make with same technology, it would be quite impossible to list all the part numbers where our technology can apply such as MYSON, STK, FEELING, ANALOG, FUJITSU, NOVATEK, LG/HYNDAI.

    Also by the advancing of the technology, everyday we gain more and more experience and develope new methods for reverse engineering for different Intergated Circuit parts. Full list of Integrated Circuit part numbers which is within our scope of capability is always getting bigger, please contact us to find out.

  • Will my privacy be protected ?

    Mikatech Innovative Limited understands the importance of its clients' privacy. At the moment you contact Mikatech, the personal information from you will be put under protection by our management regulations which was developed by our years of practice, Mikatech uses these information to customize its service to you, it will never disclose these information to third party out of any reason.
    Every project we did, we will delete all the data, materials, and codes 60days after deliverig the files, it iwll protect us and protect your privacy.

  • Is it legal to get service from Mikatech ?

    Yes, it is totally legal.
    Mikatech deliver its reverse engineering services for educational purposes only, it can be illegal to use above mentioned services in some coutries or regions, please check your local laws. Mikatech does not take any responsibility in relation to the use of above mentioned services that may be considered illegal.


  • Code Obfuscation and Its Effect on MCU Reverse Engineering

    Code obfuscation transforms the firmware into a form that is difficult to understand. The MCU lockbit lock is not directly obfuscated, but the firmware that interacts with the lock can be obfuscated. This makes microcontroller reverse engineering harder. The attacker who successfully dumps flash and eeprom will obtain obfuscated code. The read-out of an EEPROM processor yields the same obfuscated data. Decapsulation and code recovery will not simplify the code. The attacker must deobfuscate it. Copy contents of crypto memory of the code is possible, but the data is meaningless without deobfuscation. Firmware extraction is the first step. The next step is to analyze the obfuscated binary. Obfuscation techniques include instruction substitution, control flow flattening, and opaque predicates. These increase the complexity of static analysis. The MCU lockbit lock itself may be obfuscated to hide its operation. For example, the lock status might be checked through a series of indirect jumps. The attacker cannot easily determine the lock logic. Dynamic analysis is also hindered. The obfuscated code can include anti-debugging tricks. It can detect breakpoints and alter behavior. The read-out of an EEPROM processor of the code does not reveal these tricks. The attacker must execute the code to observe them. But the MCU lockbit lock may prevent execution if the code is tampered. So obfuscation complements the lock. However, obfuscation is not a security guarantee. Strong attackers can use symbolic execution to break obfuscation. But it raises the cost. The MCU lockbit lock is a hardware barrier. Obfuscation is a software barrier. Together, they form defense-in-depth. The attacker must first bypass the lock to get the code. Then they must deobfuscate the code. This double hurdle is effective. Many MCU vendors provide obfuscation tools. They integrate with the development environment. The lockbit lock ensures that the obfuscated code cannot be read out without authorization. But if the lock is broken, the obfuscation still protects intellectual property. So it is a valuable addition. In conclusion, code obfuscation hinders microcontroller reverse engineering and firmware extraction. It does not prevent read-out of an EEPROM processor or dump flash and eeprom, but it makes the extracted data less usable. The MCU lockbit lock is the first defense; obfuscation is the second.

    microcontroller_hack_time

    Years

    28 +
    microcontroller hack countries

    Countries

    110 +
    microcontroller attack clients

    Clients

    5000 +
    microcontroller projects unlocked

    Projects

    60000 +