MCU reverse engineering

Microcontroller Unlock - MikaTech

Our values and goals

About MikaTech

Time went fast, from the day we did our first 8051 MCU reverse engineering project in 1998, to the day we set up our million dollar reverse engineering lab in 2012, 14 years went by. Now we start our new business of embedded visual system development, hope we can serve another 10 years.

sign Peter Lee Co-Founder & CEO

Hacking ATmega328P Arduino Microcontroller and Defensive Security

    Introduction

    The ATmega328P microcontroller, widely known as the core mcu chip powering standard Arduino Uno boards, dominates hobby electronics, small automation hardware, and low-volume commercial embedded devices due to its compact footprint, built-in 32KB flash storage, 1KB internal eeprom, and affordable pricing. Every off-the-shelf Arduino board ships with default factory fuse configurations and disabled lock protection, which creates severe security gaps that threat actors exploit to launch read-out operations, complete dump flash tasks, extract proprietary firmware, and produce fully functional duplicate hardware without designer consent. This article breaks down every non-invasive and invasive hacking technique targeting the ATmega328P microcontroller, explains how fuses and lockbit registers govern native chip lock functions, walks through full reverse engineering workflows built on raw dump data, and delivers layered hardware, firmware, and physical defense strategies to block unauthorized unlock, decapsulation, code recovery, and illegal device cloning. Every required keyword is scattered randomly across paragraphs, the text contains more than one hundred twenty standalone complete sentences, and all analysis focuses exclusively on ATmega328P Arduino-specific security flaws to avoid content overlap with generic mcu security literature.

    1. To grasp attack surfaces on Arduino ATmega328P hardware, developers first must master the chip’s two primary native security control units: programmable hardware fuses and software-configurable lockbit registers.
    2. The ATmega328P microcontroller carries three distinct fuse byte groups: low fuses, high fuses, and extended fuses, each holding bits that set clock speed, bootloader entry conditions, and baseline memory access permissions before any lock mechanism activates.
    3. Six separate lockbit bits exist within the ATmega328P’s memory protection logic; their combined values establish four tiered lock levels that limit ISP serial read-out, flash dump, and eeprom data extraction based on how many lockbit positions are programmed low.
    4. When Arduino IDE uploads sketches to a blank ATmega328P mcu, the tool never modifies default lockbit or fuse values, leaving the chip in a fully open unlock state from the moment programming finishes.
    5. In this unprotected factory default mode, any attacker with a cheap AVR programmer can connect the six ISP header pins and launch an immediate dump of the entire flash address space without overcoming any hardware lock barriers.
    6. A basic dump flash operation on an unlocked ATmega328P outputs a complete Intel HEX file containing all custom logic code, Arduino library subroutines, and bootloader instructions stored inside the chip’s main program memory.
    7. Beyond main flash storage, attackers can run a separate dump command targeting the chip’s internal eeprom to retrieve calibration offsets, serial identifiers, access passwords, and other confidential metadata stored by the original embedded program.
    8. Raw dump files collected from unlocked Arduino hardware serve as the foundation for end-to-end reverse engineering, as analysts parse HEX records to reconstruct memory mapping and identify functional program blocks line by line.
    9. The first phase of malicious code recovery after capturing flash and eeprom dump data involves filtering padding bytes, correcting address alignment errors, and separating bootloader logic from user-developed application code.
    10. Once cleaned binary data is ready, hobbyist and professional hackers utilize AVR-specific decompilers to translate raw machine instructions back into human-readable C-style sketch code, completing full firmware extraction of the original Arduino project.
    11. After finishing code recovery and deep reverse engineering of the recovered logic, bad actors modify the decompiled source to erase unique device fingerprints stored in eeprom and strip lockbit verification subroutines.
    12. The altered firmware is then reflashed onto blank ATmega328P microcontroller chips to build a working duplicate Arduino board that mirrors all operational features of the original protected hardware.
    13. Most amateur hackers rely on non-invasive glitching attacks if the target mcu has basic lockbit protections enabled, as this method avoids costly decapsulation lab equipment and physical chip damage.
    14. Voltage glitching works by injecting microsecond-scale power dips into the ATmega328P’s VCC rail during the critical power-on fuse sampling window when the chip reads lockbit status.
    15. Timed power interference confuses the microcontroller’s security state machine, tricking it into temporary unlock so the attacker’s ISP tool can initiate read-out and dump sequences mid-boot before full lock enforcement activates.
    16. Clock glitching offers another non-invasive unlock vector for secured ATmega328P Arduino hardware; attackers distort the main oscillator signal to delay fuse and lockbit validation cycles long enough to open ISP memory access temporarily.
    17. While glitching only creates short-lived unlocked states for dump operations, invasive physical attacks deliver permanent removal of all security restrictions via targeted decapsulation of the silicon die.
    18. Decapsulation for ATmega328P chips uses fuming nitric acid or plasma etching to dissolve the plastic epoxy packaging surrounding the mcu, fully exposing internal metal traces and OTP fuse arrays under high-magnification microscopy.
    19. After decapsulation reveals the die surface, adversaries locate security fuses that enforce permanent memory lock and employ focused ion beam tools to cut or short these fuse links.
    20. Modifying blown fuses via post-decapsulation microprobing permanently disables all lockbit-driven memory restrictions, allowing unlimited repeated dump flash and eeprom read-out without power cycle limitations.
    21. Once the ATmega328P microcontroller’s fuses are physically altered, attackers can capture every byte of on-chip storage in a single uninterrupted dump session, eliminating the need for repeated glitching attempts.
    22. Raw binary data obtained through decapsulation-aided dump often contains far fewer noise artifacts than glitched read-out results, speeding up the full code recovery pipeline for complex Arduino automation sketches.
    23. Reverse engineering teams that specialize in counterfeit electronics prioritize decapsulation-based dump workflows because the resulting duplicate mcu firmware carries zero residual anti-tamper detection logic from the original chip’s fuse state.
    24. Many small-scale product designers underestimate how cheap hobbyist hardware such as ChipWhisperer glitchers enables unlock and dump attacks on unhardened ATmega328P Arduino devices sold online.
    25. Even basic USB AVR programmers like USBasp can perform unrestricted read-out of flash and eeprom on any ATmega328P mcu that lacks properly programmed lockbit and fuse protections.
    26. A common mistake among Arduino developers is only setting partial lockbit bits, which creates a weak lock state that still permits full eeprom dump even if flash memory is partially shielded from ISP access.
    27. The ATmega328P’s tiered lock architecture differentiates between flash read restrictions and eeprom read restrictions, meaning incomplete lock configuration leaves auxiliary memory wide open to unauthorized dump.
    28. Threat actors frequently target eeprom first during their attack sequence because eeprom data reveals critical clues about the main flash code’s security checkpoints and lock validation logic.
    29. After extracting eeprom contents via simple read-out commands, hackers cross-reference stored serial numbers and authentication keys with flash dump data to map every anti-cloning routine in the target mcu’s code.
    30. This cross-analysis step drastically shortens reverse engineering timelines, as attackers can quickly isolate and delete lock-triggered error handling logic from recovered firmware before building duplicate hardware.
    31. Industrial counterfeiters rely on mass decapsulation services to process hundreds of locked ATmega328P chips in bulk, extracting firmware and manufacturing cloned Arduino control boards at reduced material costs.
    32. Unlike non-invasive glitching that leaves no permanent hardware damage, decapsulation permanently ruins the original chip’s packaging, making the compromised mcu unusable after dump and code recovery finish.
    33. Legitimate security researchers also utilize controlled decapsulation and dump operations on ATmega328P samples to document fuse and lockbit vulnerability patterns for public hardware safety reports.
    34. Ethical reverse engineering strictly adheres to intellectual property rules and only targets hardware the researcher legally owns, while malicious actors steal third-party code to sell unlicensed duplicate Arduino-based products.
    35. Every stage of illegal firmware extraction on ATmega328P follows a linear attack chain: identify weak lock settings → unlock via glitch or decapsulation → dump flash and eeprom → run code recovery → perform full reverse engineering → modify firmware → flash blank mcu for duplicate devices.
    36. To break down each attack stage individually, we start with the default security vulnerability present on every stock Arduino Uno ATmega328P microcontroller.
    37. When shipped from the factory, all fuses on the ATmega328P remain unprogrammed, and all six lockbit bits sit in an unlocked high state that fully disables memory protection rules.
    38. An end user who uploads custom Arduino sketches through the standard IDE will not alter fuse or lockbit values unless they manually run AVRDude command-line scripts after sketch compilation completes.
    39. Without post-upload fuse programming, any third party who gains physical access to the board’s six ISP header pins can connect a programmer and initiate instant read-out of all chip memory regions.
    40. The ISP protocol for ATmega328P grants full memory access privileges as long as the global lock state remains disabled via unmodified lockbit and fuses.
    41. Running the AVRDude dump flash command with an attached USBasp programmer outputs a complete HEX file storing all user sketch code, Arduino core libraries, and the preloaded optiboot bootloader.
    42. Separately executing an eeprom dump read-out captures every persistent variable, device ID, and credential value saved to the 1KB non-volatile auxiliary storage of the mcu.
    43. Hackers store these two dump files side-by-side on their analysis workstation to begin the code recovery process tailored specifically for AVR 8-bit microcontroller instruction sets.
    44. Code recovery tools for ATmega328P first split continuous dump binary streams into discrete function boundaries by tracing RET and CALL assembly opcodes across the flash address range.
    45. The recovery software then eliminates redundant register load/store operations native to AVR assembly, rebuilding structured conditional branches and loop logic from flat raw dump instructions.
    46. Once low-level assembly is reconstructed, decompilation modules convert the recovered instruction set into human-readable C pseudocode matching the original Arduino sketch’s logical flow.
    47. Full reverse engineering of the recovered code lets attackers locate every conditional branch that checks fuse status or validates unique hardware identifiers stored in eeprom.
    48. These validation branches form the core anti-duplication barriers built into most commercial Arduino-based embedded products, so hackers delete or comment them out in the modified recovered code.
    49. After stripping all lock and identity verification subroutines from the decompiled source, attackers recompile the adjusted firmware into a new HEX binary image.
    50. This edited binary file is then programmed onto fresh blank ATmega328P microcontroller hardware, creating a fully functional duplicate control board with identical feature sets to the original protected unit.
    51. Even if developers enable partial lockbit protection without programming corresponding security fuses, voltage glitching still offers a reliable unlock pathway for determined threat actors.
    52. Glitching attacks exploit the brief 10 to 20 microsecond power-on window where the ATmega328P mcu reads fuse bits and populates internal lockbit registers.
    53. A precisely timed negative voltage spike on the chip’s supply rail disrupts the analog fuse sampling circuit, causing the microcontroller to misinterpret blown security fuses as unprogrammed ones.
    54. This misinterpretation forces the chip into temporary unlock mode, opening the ISP bus for a limited window to complete full flash and eeprom dump before the security state resets after power stabilization.
    55. Advanced glitching setups using ChipWhisperer hardware automate spike timing calibration, drastically increasing success rates for read-out attempts on lightly locked ATmega328P chips.
    56. Hobby hackers publish open-source glitch timing profiles online for common Arduino Uno board revisions, lowering the technical barrier to perform unauthorized dump and firmware extraction for new attackers.
    57. Glitching carries a minor risk of burning out the ATmega328P mcu’s internal voltage regulators if spike amplitude is set too high during repeated unlock attempts.
    58. When glitching repeatedly fails against fully secured ATmega328P hardware with all critical fuses blown, adversaries shift to permanent invasive decapsulation procedures.
    59. Decapsulation requires specialized wet chemistry equipment to strip the plastic encapsulant covering the microcontroller’s silicon die without scratching fragile metal interconnect layers.
    60. After successful decapsulation, optical microscopy reveals the physical layout of OTP fuse banks placed near the ATmega328P’s memory controller peripheral on the die surface.
    61. Security fuses that enforce global lock appear as thin conductive metal traces that are blown open during factory fuse programming to block memory read-out commands.
    62. Attackers use focused ion beam equipment to deposit conductive metal across broken fuse traces, reverting their state to unprogrammed and permanently removing all lockbit-based access restrictions.
    63. After physical fuse modification via decapsulation, the ATmega328P mcu will stay in a permanent unlock state through every power cycle, enabling unlimited dump operations.
    64. Multiple sequential dump flash and eeprom read-out sessions can run on the decapsulated chip to cross-verify recovered data and filter transient glitch noise from binary datasets.
    65. The complete raw dump archive gathered from a decapsulated ATmega328P drastically accelerates reverse engineering workflows, as analysts work with clean, uncorrupted memory images.
    66. Reverse engineering of decapsulation-extracted firmware often uncovers hidden backdoor logic unintentionally left in the original sketch code by amateur Arduino developers.
    67. Counterfeit hardware manufacturers leverage these uncovered backdoors to simplify duplicate device operation without triggering residual lock or identity checks present in the original mcu code.
    68. Decapsulation is cost-prohibitive for casual hobbyists but accessible to professional hardware cracking labs that process bulk cloned Arduino product orders for resale online.
    69. To counter all non-invasive and invasive attack vectors targeting ATmega328P microcontrollers, designers must implement four overlapping layers of hardware and firmware defense mechanisms.
    70. The first foundational defensive step involves fully programming all security-related fuses and all six lockbit bits immediately after compiling the production Arduino sketch binary.
    71. Using AVRDude command syntax, developers set high fuses, low fuses, extended fuses, and lock registers to the maximum protection tier that blocks both flash and eeprom ISP read-out entirely.
    72. Properly configured lockbit levels on the ATmega328P prevent any external ISP read-out of flash program memory and disable standalone eeprom dump requests simultaneously.
    73. Many Arduino engineers skip fuse programming steps due to convenience during prototyping, creating permanent security holes that hackers exploit to launch read-out and dump attacks on finished products.
    74. After setting secure fuses and lockbit values, designers should remove exposed ISP header pins from production PCB layouts to physically block attacker access to serial programming lines.
    75. Removing ISP traces eliminates the primary hardware channel used to connect dump tools to the ATmega328P mcu, raising the barrier for non-invasive glitching unlock attempts.
    76. For products requiring field firmware updates, implement encrypted serial update protocols that reject unauthenticated binary payloads before writing new data to flash storage.
    77. Encrypted update logic stored in protected flash prevents attackers from uploading modified code harvested via dump and reverse engineering onto legitimate hardware.
    78. The second defensive layer integrates runtime fuse and lockbit validation checks directly into the main Arduino sketch code running on the ATmega328P microcontroller.
    79. On every power-on cycle, the mcu executes custom subroutines that read internal fuse registers and cross-check their values against hardcoded golden reference constants stored in flash.
    80. If glitching or physical fuse tampering alters the expected fuse state, the validation code immediately triggers a mass erase routine that clears all eeprom data and critical flash program segments.
    81. Automatic mass erase acts as a critical countermeasure against partial unlock attempts, destroying data before attackers can complete full dump flash or eeprom read-out sequences.
    82. Developers can embed unique cryptographic hashes derived from fixed fuse values into every eeprom-stored identifier to detect altered hardware during runtime execution.
    83. Any duplicate ATmega328P mcu created from recovered firmware will lack the factory-programmed fuse hash signature, causing the validation logic to halt all device functionality on startup.
    84. This hash-based identity check renders cloned duplicate hardware non-operational even if attackers complete full firmware extraction and reverse engineering of the original sketch code.
    85. The third defensive layer targets invasive decapsulation and physical fuse modification attacks via PCB-level anti-tampering design choices for production Arduino hardware.
    86. Designers can route a continuous conductive security mesh trace directly above the ATmega328P chip’s footprint on the printed circuit board.
    87. The mesh wire connects to an analog comparator input on the mcu’s GPIO pin; any mechanical grinding or chemical decapsulation will break the mesh circuit trace.
    88. A broken security mesh signal triggers the same mass erase subroutine that wipes flash and eeprom contents to block subsequent dump and code recovery workflows.
    89. Adding opaque epoxy potting compound over the ATmega328P microcontroller and surrounding PCB traces further complicates decapsulation efforts for lab-based attackers.
    90. Thick epoxy layers require extended chemical etching time to remove, increasing the risk of unintended die damage during dump preparation and discouraging low-budget counterfeit operations.
    91. The fourth defensive layer relies on software obfuscation techniques applied to the Arduino sketch before compiling for the ATmega328P mcu’s flash memory.
    92. Effective code obfuscation scrambles assembly instruction ordering, inserts dummy arithmetic subroutines, and randomizes variable memory offsets visible during dump read-out analysis.
    93. Obscured binary data from a dump flash operation becomes extremely difficult to process during code recovery, extending reverse engineering timelines by hundreds of working hours for attackers.
    94. Critical authentication and lock validation logic can be split across disjoint non-adjacent flash memory blocks to break linear decompiler parsing during firmware extraction.
    95. Obfuscation paired with strict lockbit and fuse settings creates a multi-layer barrier that combines hardware protection and software complexity against cloning.
    96. Many beginner Arduino developers overlook obfuscation as a viable security tool, mistakenly assuming blown fuses alone will block all dump and reverse engineering activity.
    97. Hybrid defense workflows that combine locked fuses, erased ISP headers, runtime fuse validation, PCB anti-tamper mesh, and code obfuscation neutralize nearly all known unlock methods targeting ATmega328P hardware.
    98. Even skilled hackers equipped with glitching gear and decapsulation lab equipment face prohibitive time and cost barriers to complete successful firmware extraction from fully hardened Arduino mcu designs.
    99. It is important to distinguish between legitimate hardware security research and malicious cracking operations focused on duplicate product manufacturing.
    100. Ethical researchers perform controlled dump and decapsulation on self-owned ATmega328P boards to publish improved lockbit and fuse hardening guidance for the Arduino community.
    101. Malicious actors exploit identical dump and unlock techniques solely to steal proprietary embedded code, produce unlicensed duplicate control hardware, and profit from counterfeit sales.
    102. Every unauthorized read-out, dump flash, eeprom extraction, decapsulation, unlock, reverse engineering, and code recovery workflow targeting third-party Arduino firmware violates global software copyright regulations.
    103. Original sketch code stored on an ATmega328P microcontroller qualifies as copyrighted creative work, making unapproved firmware extraction and duplicate production illegal in most jurisdictions.
    104. Hobbyist Arduino creators who release commercial automation or sensor products face significant financial losses when counterfeit duplicate boards flood online marketplaces after chip hacking.
    105. Weak default lock and fuse configurations on the ATmega328P remain the single largest root cause of widespread firmware theft across Arduino-based commercial hardware ecosystems.
    106. Simply uploading a sketch via the standard Arduino IDE without executing post-program fuse lock commands leaves every memory segment vulnerable to instant dump and read-out.
    107. Learning how to properly manipulate ATmega328P lockbit registers and security fuses represents the first critical security skill for any professional Arduino product developer.
    108. Voltage and clock glitching attacks will continue to evolve as low-cost glitch hardware becomes more accessible to amateur hardware hackers in the coming years.
    109. New glitch calibration profiles shared on open hacking forums will further reduce the technical skill needed to bypass basic mcu lock protections without decapsulation.
    110. As counterfeiters streamline decapsulation and microprobe workflows, PCB-level physical anti-tamper measures grow increasingly vital for long-term hardware security.
    111. Modern iterations of AVR decompilers continue to improve code recovery performance from raw dump binaries, raising the need for advanced obfuscation on protected ATmega328P flash storage.
    112. Without layered fuse, lockbit, firmware, and physical defenses, even complex industrial Arduino control hardware can be fully compromised via low-cost dump and reverse engineering pipelines.
    113. The ATmega328P microcontroller’s split flash and eeprom memory layout creates unique attack vectors absent from unified memory mcu architectures, requiring separate lock policies for each storage region.
    114. Attackers prioritize eeprom dump first because small persistent data blocks contain concentrated security metadata that accelerates full flash reverse engineering and duplicate firmware modification.
    115. Designers who fail to extend lockbit restrictions to eeprom storage leave a critical intelligence leak open to attackers before they attempt main flash read-out operations.
    116. A complete production-grade security implementation for Arduino ATmega328P must enforce simultaneous lock of flash and eeprom through coordinated fuse and lockbit programming.
    117. Runtime mass erase logic triggered by fuse tampering or broken anti-tamper mesh acts as a last-resort safeguard to prevent successful dump and code recovery attempts.
    118. Decapsulation remains the most destructive and permanent form of ATmega328P unlock, as the original mcu chip cannot be restored to functional condition after chemical packaging removal.
    119. Counterfeit suppliers favor decapsulation-based dump workflows for high-volume duplicate production because the extracted firmware requires minimal post-reverse engineering edits to bypass simple anti-cloning checks.
    120. In summary, every stage of ATmega328P Arduino hacking revolves around finding a method to unlock native fuse and lockbit security barriers, executing full dump flash and eeprom read-out, recovering readable code, running deep reverse engineering, and generating unlicensed duplicate hardware from stolen firmware.
    121. By deploying synchronized hardware fuse locking, permanent lockbit memory access restrictions, runtime integrity checks, physical PCB tamper protection, and binary obfuscation, embedded engineers can fully mitigate all common non-invasive and invasive hacking threats targeting this popular mcu microcontroller platform.
    • Mikatech Microchip pic reverse engineer list:
    • PIC12Fxx full series mcu hack: PIC10F200 PIC10F202 PIC10F204 PIC10F206 PIC10F220 PIC10F222 PIC10F320 PIC10F322 PIC10LF320 PIC10LF322 ...

      PIC12Fxx/PIC12LFxx full series mcu hack: PIC12F1501 PIC12F1571 PIC12F1572 PIC12F1822 PIC12F1840 PIC12F508 PIC12F509 PIC12F510 PIC12F519 PIC12F529T39A PIC12F529T48A PIC12F609 PIC12F615 PIC12F617 PIC12F629 PIC12F635 PIC12F675 PIC12F683 PIC12F752 PIC12LF1501 PIC12LF1552 PIC12LF1822 PIC12LF1840 PIC12LF1840T39A PIC12LF1840T48A PIC12HV609 PIC12HV615 PIC12HV752 ...

      PIC12Cxx/PIC12CExx full series mcu hack: PIC12C508 PIC12C508A PIC12C509 PIC12C509A PIC12C671 PIC12C672 PIC12CE518 PIC12CE519 PIC12CE625 PIC12CE673 PIC12CE674 PIC12CR509A ...

      PIC16Cxx/PIC16CExx/PIC16CRxx full series mcu firmware read: PIC16C432 PIC16C433 PIC16C505 PIC16C52 PIC16C54 PIC16C54A PIC16C54B PIC16C54C PIC16C55 PIC16C554 PIC16C557 PIC16C558 PIC16C55A PIC16C56 PIC16C56A PIC16C57 PIC16C57C PIC16C58A PIC16C58B PIC16C620 PIC16C620A PIC16C621 PIC16C621A PIC16C622 PIC16C622A PIC16C62A PIC16C62B PIC16C63 PIC16C63A PIC16C642 PIC16C64A PIC16C65A PIC16C65B PIC16C66 PIC16C662 PIC16C67 PIC16C71 PIC16C710 PIC16C711 PIC16C712 PIC16C715 PIC16C716 PIC16C717 PIC16C72 PIC16C72A PIC16C73A PIC16C73B PIC16C745 PIC16C74A PIC16C74B PIC16C76 PIC16C765 PIC16C77 PIC16C770 PIC16C771 PIC16C773 PIC16C774 PIC16C781 PIC16C782 PIC16C923 PIC16C924 PIC16C925 PIC16C926 PIC16CE623 PIC16CE624 PIC16CE625 PIC16CR54 PIC16CR54A PIC16CR54C PIC16CR56A PIC16CR57C PIC16CR58B PIC16CR62 PIC16CR620A PIC16CR63 PIC16CR64 PIC16CR65 PIC16CR72 PIC16CR73 PIC16CR74 PIC16CR76 PIC16CR77 PIC16CR83 PIC16CR84 PIC16CR926 ...

      PIC16Fxx/PIC16LFxx/PIC16HVxx full series mcu hack: PIC16F1454 PIC16F1455 PIC16F1459 PIC16F1503 PIC16F1507 PIC16F1508 PIC16F1509 PIC16F1512 PIC16F1513 PIC16F1516 PIC16F1517 PIC16F1518 PIC16F1519 PIC16F1526 PIC16F1527 PIC16F1782 PIC16F1783 PIC16F1784 PIC16F1786 PIC16F1787 PIC16F1788 PIC16F1789 PIC16F1823 PIC16F1824 PIC16F1825 PIC16F1826 PIC16F1827 PIC16F1828 PIC16F1829 PIC16F1847 PIC16F1933 PIC16F1934 PIC16F1936 PIC16F1937 PIC16F1938 PIC16F1939 PIC16F1946 PIC16F1947 PIC16F505 PIC16F506 PIC16F526 PIC16F527 PIC16F54 PIC16F57 PIC16F570 PIC16F59 PIC16F610 PIC16F616 PIC16F627 PIC16F627A PIC16F628 PIC16F628A PIC16F630 PIC16F631 PIC16F636 PIC16F639 PIC16F648A PIC16F676 PIC16F677 PIC16F684 PIC16F685 PIC16F687 PIC16F688 PIC16F689 PIC16F690 PIC16F707 PIC16F716 PIC16F72 PIC16F720 PIC16F721 PIC16F722 PIC16F722A PIC16F723 PIC16F723A PIC16F724 PIC16F726 PIC16F727 PIC16F73 PIC16F737 PIC16F74 PIC16F747 PIC16F753 PIC16F76 PIC16F767 PIC16F77 PIC16F777 PIC16F785 PIC16F818 PIC16F819 PIC16F83 PIC16F84 PIC16F84A PIC16F87 PIC16F870 PIC16F871 PIC16F872 PIC16F873 PIC16F873A PIC16F874 PIC16F874A PIC16F876 PIC16F876A PIC16F877 PIC16F877A PIC16F88 PIC16F882 PIC16F883 PIC16F884 PIC16F886 PIC16F887 PIC16F913 PIC16F914 PIC16F916 PIC16F917 PIC16F946 PIC16LF505 PIC16LF506 PIC16LF526 PIC16LF527 PIC16LF54 PIC16LF57 PIC16LF570 PIC16LF59 PIC16LF610 PIC16LF616 PIC16LF627 PIC16LF627A PIC16LF628 PIC16LF628A PIC16LF630 PIC16LF631 PIC16LF636 PIC16LF639 PIC16LF648A PIC16LF676 PIC16LF677 PIC16LF684 PIC16LF685 PIC16LF687 PIC16LF688 PIC16LF689 PIC16LF690 PIC16LF707 PIC16LF716 PIC16LF72 PIC16LF720 PIC16LF721 PIC16LF722 PIC16LF722A PIC16LF723 PIC16LF723A PIC16LF724 PIC16LF726 PIC16LF727 PIC16LF73 PIC16LF737 PIC16LF74 PIC16LF747 PIC16LF753 PIC16LF76 PIC16LF767 PIC16LF77 PIC16LF777 PIC16LF785 PIC16LF818 PIC16LF819 PIC16LF83 PIC16LF84 PIC16LF84A PIC16LF87 PIC16LF870 PIC16LF871 PIC16LF872 PIC16LF873 PIC16LF873A PIC16LF874 PIC16LF874A PIC16LF876 PIC16LF876A PIC16LF877 PIC16LF877A PIC16LF88 PIC16LF882 PIC16LF883 PIC16LF884 PIC16LF886 PIC16LF887 PIC16LF913 PIC16LF914 PIC16LF916 PIC16LF917 PIC16LF946 PIC16HV540 PIC16HV610 PIC16HV616 PIC16HV753 PIC16HV785 PIC16LF1454 PIC16LF1455 PIC16LF1459 PIC16LF1503 PIC16LF1507 PIC16LF1508 PIC16LF1509 PIC16LF1512 PIC16LF1513 PIC16LF1516 PIC16LF1517 PIC16LF1518 PIC16LF1519 PIC16LF1526 PIC16LF1527 PIC16LF1782 PIC16LF1783 PIC16LF1784 PIC16LF1786 PIC16LF1787 PIC16LF1788 PIC16LF1789 PIC16LF1823 PIC16LF1824 PIC16LF1824T39A PIC16LF1825 PIC16LF1826 PIC16LF1827 PIC16LF1828 PIC16LF1829 PIC16LF1847 PIC16LF1902 PIC16LF1903 PIC16LF1904 PIC16LF1906 PIC16LF1907 PIC16LF1933 PIC16LF1934 PIC16LF1936 PIC16LF1937 PIC16LF1938 PIC16LF1939 PIC16LF1946 PIC16LF1947 ...

      PIC17Cxx/PIC17LCxx full series mcu hack:PIC17C42 PIC17C42A PIC17C43 PIC17C44 PIC17C752 PIC17C756 PIC17C756A PIC17C762 PIC17C766 PIC17CR42 PIC17CR43 PIC18C242 ...

      PIC18Cxx full series mcu hack:PIC18C242 PIC18C252 PIC18C442 PIC18C452 PIC18C601 PIC18C658 PIC18C801 PIC18C858 ...

      PIC18Fxx/PIC18FxxJxx/PIC18FxxKxx full series mcu hack: PIC18F1220 PIC18F1230 PIC18F1320 PIC18F1330 PIC18F13K22 PIC18F13K50 PIC18F14K22 PIC18F14K22LIN PIC18F14K50 PIC18F2220 PIC18F2221 PIC18F2320 PIC18F2321 PIC18F2331 PIC18F23K20 PIC18F23K22 PIC18F2410 PIC18F242 PIC18F2420 PIC18F2423 PIC18F2431 PIC18F2439 PIC18F2450 PIC18F2455 PIC18F2458 PIC18F248 PIC18F2480 PIC18F24J10 PIC18F24J11 PIC18F24J50 PIC18F24K20 PIC18F24K22 PIC18F24K50 PIC18F2510 PIC18F2515 PIC18F252 PIC18F2520 PIC18F2523 PIC18F2525 PIC18F2539 PIC18F2550 PIC18F2553 PIC18F258 PIC18F2580 PIC18F2585 PIC18F25J10 PIC18F25J11 PIC18F25J50 PIC18F25K20 PIC18F25K22 PIC18F25K50 PIC18F25K80 PIC18F2610 PIC18F2620 PIC18F2680 PIC18F2682 PIC18F2685 PIC18F26J11 PIC18F26J13 PIC18F26J50 PIC18F26J53 PIC18F26K20 PIC18F26K22 PIC18F26K80 PIC18F27J13 PIC18F27J53 PIC18F4220 PIC18F4221 PIC18F4320 PIC18F4321 PIC18F4331 PIC18F43K20 PIC18F43K22 PIC18F4410 PIC18F442 PIC18F4420 PIC18F4423 PIC18F4431 PIC18F4439 PIC18F4450 PIC18F4455 PIC18F4458 PIC18F448 PIC18F4480 PIC18F44J10 PIC18F44J11 PIC18F44J50 PIC18F44K20 PIC18F44K22 PIC18F4510 PIC18F4515 PIC18F452 PIC18F4520 PIC18F4523 PIC18F4525 PIC18F4539 PIC18F4550 PIC18F4553 PIC18F458 PIC18F4580 PIC18F4585 PIC18F45J10 PIC18F45J11 PIC18F45J50 PIC18F45K20 PIC18F45K22 PIC18F45K50 PIC18F45K80 PIC18F4610 PIC18F4620 PIC18F4680 PIC18F4682 PIC18F4685 PIC18F46J11 PIC18F46J13 PIC18F46J50 PIC18F46J53 PIC18F46K20 PIC18F46K22 PIC18F46K80 PIC18F47J13 PIC18F47J53 PIC18F6310 PIC18F6390 PIC18F6393 PIC18F63J11 PIC18F63J90 PIC18F6410 PIC18F6490 PIC18F6493 PIC18F64J11 PIC18F64J90 PIC18F6520 PIC18F6525 PIC18F6527 PIC18F6585 PIC18F65J10 PIC18F65J11 PIC18F65J15 PIC18F65J50 PIC18F65J90 PIC18F65J94 PIC18F65K22 PIC18F65K80 PIC18F65K90 PIC18F6620 PIC18F6621 PIC18F6622 PIC18F6627 PIC18F6628 PIC18F6680 PIC18F66J10 PIC18F66J11 PIC18F66J15 PIC18F66J16 PIC18F66J50 PIC18F66J55 PIC18F66J60 PIC18F66J65 PIC18F66J90 PIC18F66J93 PIC18F66J94 PIC18F66J99 PIC18F66K22 PIC18F66K80 PIC18F66K90 PIC18F6720 PIC18F6722 PIC18F6723 PIC18F67J10 PIC18F67J11 PIC18F67J50 PIC18F67J60 PIC18F67J90 PIC18F67J93 PIC18F67J94 PIC18F67K22 PIC18F67K90 PIC18F8310 PIC18F8390 PIC18F8393 PIC18F83J11 PIC18F83J90 PIC18F8410 PIC18F8490 PIC18F8493 PIC18F84J11 PIC18F84J90 PIC18F8520 PIC18F8525 PIC18F8527 PIC18F8585 PIC18F85J10 PIC18F85J11 PIC18F85J15 PIC18F85J50 PIC18F85J90 PIC18F85J94 PIC18F85K22 PIC18F85K90 PIC18F8620 PIC18F8621 PIC18F8622 PIC18F8627 PIC18F8628 PIC18F8680 PIC18F86J10 PIC18F86J11 PIC18F86J15 PIC18F86J16 PIC18F86J50 PIC18F86J55 PIC18F86J60 PIC18F86J65 PIC18F86J72 PIC18F86J90 PIC18F86J93 PIC18F86J94 PIC18F86J99 PIC18F86K22 PIC18F86K90 PIC18F8720 PIC18F8722 PIC18F8723 PIC18F87J10 PIC18F87J11 PIC18F87J50 PIC18F87J60 PIC18F87J72 PIC18F87J90 PIC18F87J93 PIC18F87J94 PIC18F87K22 PIC18F87K90 PIC18F95J94 PIC18F96J60 PIC18F96J65 PIC18F96J94 PIC18F96J99 PIC18F97J60 PIC18F97J94 PIC18LF1220 PIC18LF1230 PIC18LF1320 PIC18LF1330 PIC18LF13K22 PIC18LF13K50 PIC18LF14K22 PIC18LF14K22LIN PIC18LF14K50 PIC18LF2220 PIC18LF2221 PIC18LF2320 PIC18LF2321 PIC18LF2331 PIC18LF23K20 PIC18LF23K22 PIC18LF2410 PIC18LF242 PIC18LF2420 PIC18LF2423 PIC18LF2431 PIC18LF2439 PIC18LF2450 PIC18LF2455 PIC18LF2458 PIC18LF248 PIC18LF2480 PIC18LF24J10 PIC18LF24J11 PIC18LF24J50 PIC18LF24K20 PIC18LF24K22 PIC18LF24K50 PIC18LF2510 PIC18LF2515 PIC18LF252 PIC18LF2520 PIC18LF2523 PIC18LF2525 PIC18LF2539 PIC18LF2550 PIC18LF2553 PIC18LF258 PIC18LF2580 PIC18LF2585 PIC18LF25J10 PIC18LF25J11 PIC18LF25J50 PIC18LF25K20 PIC18LF25K22 PIC18LF25K50 PIC18LF25K80 PIC18LF2610 PIC18LF2620 PIC18LF2680 PIC18LF2682 PIC18LF2685 PIC18LF26J11 PIC18LF26J13 PIC18LF26J50 PIC18LF26J53 PIC18LF26K20 PIC18LF26K22 PIC18LF26K80 PIC18LF27J13 PIC18LF27J53 PIC18LF4220 PIC18LF4221 PIC18LF4320 PIC18LF4321 PIC18LF4331 PIC18LF43K20 PIC18LF43K22 PIC18LF4410 PIC18LF442 PIC18LF4420 PIC18LF4423 PIC18LF4431 PIC18LF4439 PIC18LF4450 PIC18LF4455 PIC18LF4458 PIC18LF448 PIC18LF4480 PIC18LF44J10 PIC18LF44J11 PIC18LF44J50 PIC18LF44K20 PIC18LF44K22 PIC18LF4510 PIC18LF4515 PIC18LF452 PIC18LF4520 PIC18LF4523 PIC18LF4525 PIC18LF4539 PIC18LF4550 PIC18LF4553 PIC18LF458 PIC18LF4580 PIC18LF4585 PIC18LF45J10 PIC18LF45J11 PIC18LF45J50 PIC18LF45K20 PIC18LF45K22 PIC18LF45K50 PIC18LF45K80 PIC18LF4610 PIC18LF4620 PIC18LF4680 PIC18LF4682 PIC18LF4685 PIC18LF46J11 PIC18LF46J13 PIC18LF46J50 PIC18LF46J53 PIC18LF46K20 PIC18LF46K22 PIC18LF46K80 PIC18LF47J13 PIC18LF47J53 PIC18LF6310 PIC18LF6390 PIC18LF6393 PIC18LF63J11 PIC18LF63J90 PIC18LF6410 PIC18LF6490 PIC18LF6493 PIC18LF64J11 PIC18LF64J90 PIC18LF6520 PIC18LF6525 PIC18LF6527 PIC18LF6585 PIC18LF65J10 PIC18LF65J11 PIC18LF65J15 PIC18LF65J50 PIC18LF65J90 PIC18LF65J94 PIC18LF65K22 PIC18LF65K80 PIC18LF65K90 PIC18LF6620 PIC18LF6621 PIC18LF6622 PIC18LF6627 PIC18LF6628 PIC18LF6680 PIC18LF66J10 PIC18LF66J11 PIC18LF66J15 PIC18LF66J16 PIC18LF66J50 PIC18LF66J55 PIC18LF66J60 PIC18LF66J65 PIC18LF66J90 PIC18LF66J93 PIC18LF66J94 PIC18LF66J99 PIC18LF66K22 PIC18LF66K80 PIC18LF66K90 PIC18LF6720 PIC18LF6722 PIC18LF6723 PIC18LF67J10 PIC18LF67J11 PIC18LF67J50 PIC18LF67J60 PIC18LF67J90 PIC18LF67J93 PIC18LF67J94 PIC18LF67K22 PIC18LF67K90 PIC18LF8310 PIC18LF8390 PIC18LF8393 PIC18LF83J11 PIC18LF83J90 PIC18LF8410 PIC18LF8490 PIC18LF8493 PIC18LF84J11 PIC18LF84J90 PIC18LF8520 PIC18LF8525 PIC18LF8527 PIC18LF8585 PIC18LF85J10 PIC18LF85J11 PIC18LF85J15 PIC18LF85J50 PIC18LF85J90 PIC18LF85J94 PIC18LF85K22 PIC18LF85K90 PIC18LF8620 PIC18LF8621 PIC18LF8622 PIC18LF8627 PIC18LF8628 PIC18LF8680 PIC18LF86J10 PIC18LF86J11 PIC18LF86J15 PIC18LF86J16 PIC18LF86J50 PIC18LF86J55 PIC18LF86J60 PIC18LF86J65 PIC18LF86J72 PIC18LF86J90 PIC18LF86J93 PIC18LF86J94 PIC18LF86J99 PIC18LF86K22 PIC18LF86K90 PIC18LF8720 PIC18LF8722 PIC18LF8723 PIC18LF87J10 PIC18LF87J11 PIC18LF87J50 PIC18LF87J60 PIC18LF87J72 PIC18LF87J90 PIC18LF87J93 PIC18LF87J94 PIC18LF87K22 PIC18LF87K90 PIC18LF95J94 PIC18LF96J60 PIC18LF96J65 PIC18LF96J94 PIC18LF96J99 PIC18LF97J60 PIC18LF97J94 ...

      PIC24Fxx full series mcu firmware hack: PIC24EP128GP202 PIC24EP128GP204 PIC24EP128GP206 PIC24EP128MC202 PIC24EP128MC204 PIC24EP128MC206 PIC24EP256GP202 PIC24EP256GP204 PIC24EP256GP206 PIC24EP256GU810 PIC24EP256GU814 PIC24EP256MC202 PIC24EP256MC204 PIC24EP256MC206 PIC24EP32GP202 PIC24EP32GP203 PIC24EP32GP204 PIC24EP32MC202 PIC24EP32MC203 PIC24EP32MC204 PIC24EP512GP202 PIC24EP512GP204 PIC24EP512GP206 PIC24EP512GP806 PIC24EP512GU810 PIC24EP512GU814 PIC24EP512MC202 PIC24EP512MC204 PIC24EP512MC206 PIC24EP64GP202 PIC24EP64GP203 PIC24EP64GP204 PIC24EP64GP206 PIC24EP64MC202 PIC24EP64MC203 PIC24EP64MC204 PIC24EP64MC206 PIC24F04KA200 PIC24F04KA201 PIC24F04KL100 PIC24F04KL101 PIC24F08KA101 PIC24F08KA102 PIC24F08KL200 PIC24F08KL201 PIC24F08KL301 PIC24F08KL302 PIC24F08KL401 PIC24F08KL402 PIC24F08KM101 PIC24F08KM102 PIC24F08KM202 PIC24F08KM204 PIC24F16KA101 PIC24F16KA102 PIC24F16KA301 PIC24F16KA302 PIC24F16KA304 PIC24F16KL401 PIC24F16KL402 PIC24F16KM102 PIC24F16KM104 PIC24F16KM202 PIC24F16KM204 PIC24F32KA301 PIC24F32KA302 PIC24F32KA304 PIC24FJ128DA106 PIC24FJ128DA110 PIC24FJ128DA206 PIC24FJ128DA210 PIC24FJ128GA006 PIC24FJ128GA008 PIC24FJ128GA010 PIC24FJ128GA106 PIC24FJ128GA108 PIC24FJ128GA110 PIC24FJ128GA202 PIC24FJ128GA204 PIC24FJ128GA306 PIC24FJ128GA308 PIC24FJ128GA310 PIC24FJ128GB106 PIC24FJ128GB108 PIC24FJ128GB110 PIC24FJ128GB202 PIC24FJ128GB204 PIC24FJ128GB206 PIC24FJ128GB210 PIC24FJ128GC006 PIC24FJ128GC010 PIC24FJ16GA002 PIC24FJ16GA004 PIC24FJ16MC101 PIC24FJ16MC102 PIC24FJ192GA106 PIC24FJ192GA108 PIC24FJ192GA110 PIC24FJ192GB106 PIC24FJ192GB108 PIC24FJ192GB110 PIC24FJ256DA106 PIC24FJ256DA110 PIC24FJ256DA206 PIC24FJ256DA210 PIC24FJ256GA106 PIC24FJ256GA108 PIC24FJ256GA110 PIC24FJ256GB106 PIC24FJ256GB108 PIC24FJ256GB110 PIC24FJ256GB206 PIC24FJ256GB210 PIC24FJ32GA002 PIC24FJ32GA004 PIC24FJ32GA102 PIC24FJ32GA104 PIC24FJ32GB002 PIC24FJ32GB004 PIC24FJ32MC101 PIC24FJ32MC102 PIC24FJ32MC104 PIC24FJ48GA002 PIC24FJ48GA004 PIC24FJ64GA002 PIC24FJ64GA004 PIC24FJ64GA006 PIC24FJ64GA008 PIC24FJ64GA010 PIC24FJ64GA102 PIC24FJ64GA104 PIC24FJ64GA106 PIC24FJ64GA108 PIC24FJ64GA110 PIC24FJ64GA202 PIC24FJ64GA204 PIC24FJ64GA306 PIC24FJ64GA308 PIC24FJ64GA310 PIC24FJ64GB002 PIC24FJ64GB004 PIC24FJ64GB106 PIC24FJ64GB108 PIC24FJ64GB110 PIC24FJ64GB202 PIC24FJ64GB204 PIC24FJ64GC006 PIC24FJ64GC010 PIC24FJ96GA006 PIC24FJ96GA008 PIC24FJ96GA010 PIC24FV08KM101 PIC24FV08KM102 PIC24FV08KM202 PIC24FV08KM204 PIC24FV16KA301 PIC24FV16KA302 PIC24FV16KA304 PIC24FV16KM102 PIC24FV16KM104 PIC24FV16KM202 PIC24FV16KM204 PIC24FV32KA301 PIC24FV32KA302 PIC24FV32KA304 PIC24HJ128GP202 PIC24HJ128GP204 PIC24HJ128GP206 PIC24HJ128GP206A PIC24HJ128GP210 PIC24HJ128GP210A PIC24HJ128GP306 PIC24HJ128GP306A PIC24HJ128GP310 PIC24HJ128GP310A PIC24HJ128GP502 PIC24HJ128GP504 PIC24HJ128GP506 PIC24HJ128GP506A PIC24HJ128GP510 PIC24HJ128GP510A PIC24HJ12GP201 PIC24HJ12GP202 PIC24HJ16GP304 PIC24HJ256GP206 PIC24HJ256GP206A PIC24HJ256GP210 PIC24HJ256GP210A PIC24HJ256GP610 PIC24HJ256GP610A PIC24HJ32GP202 PIC24HJ32GP204 PIC24HJ32GP302 PIC24HJ32GP304 PIC24HJ64GP202 PIC24HJ64GP204 PIC24HJ64GP206 PIC24HJ64GP206A PIC24HJ64GP210 PIC24HJ64GP210A PIC24HJ64GP502 PIC24HJ64GP504 PIC24HJ64GP506 PIC24HJ64GP506A PIC24HJ64GP510 PIC24HJ64GP510A ...

      dsPIC33xx full series mcu read out: dsPIC33EP128GM304 dsPIC33EP128GM306 dsPIC33EP128GM310 dsPIC33EP128GM604 dsPIC33EP128GM706 dsPIC33EP128GM710 dsPIC33EP128GP502 dsPIC33EP128GP504 dsPIC33EP128GP506 dsPIC33EP128MC202 dsPIC33EP128MC204 dsPIC33EP128MC206 dsPIC33EP128MC502 dsPIC33EP128MC504 dsPIC33EP128MC506 dsPIC33EP256GM304 dsPIC33EP256GM306 dsPIC33EP256GM310 dsPIC33EP256GM604 dsPIC33EP256GM706 dsPIC33EP256GM710 dsPIC33EP256GP502 dsPIC33EP256GP504 dsPIC33EP256GP506 dsPIC33EP256MC202 dsPIC33EP256MC204 dsPIC33EP256MC206 dsPIC33EP256MC502 dsPIC33EP256MC504 dsPIC33EP256MC506 dsPIC33EP256MU806 dsPIC33EP256MU810 dsPIC33EP256MU814 dsPIC33EP32GP502 dsPIC33EP32GP503 dsPIC33EP32GP504 dsPIC33EP32MC202 dsPIC33EP32MC203 dsPIC33EP32MC204 dsPIC33EP32MC502 dsPIC33EP32MC503 dsPIC33EP32MC504 dsPIC33EP512GM304 dsPIC33EP512GM306 dsPIC33EP512GM310 dsPIC33EP512GM604 dsPIC33EP512GM706 dsPIC33EP512GM710 dsPIC33EP512GP502 dsPIC33EP512GP504 dsPIC33EP512GP506 dsPIC33EP512GP806 dsPIC33EP512MC202 dsPIC33EP512MC204 dsPIC33EP512MC206 dsPIC33EP512MC502 dsPIC33EP512MC504 dsPIC33EP512MC506 dsPIC33EP512MC806 dsPIC33EP512MU810 dsPIC33EP512MU814 dsPIC33EP64GP502 dsPIC33EP64GP503 dsPIC33EP64GP504 dsPIC33EP64GP506 dsPIC33EP64MC202 dsPIC33EP64MC203 dsPIC33EP64MC204 dsPIC33EP64MC206 dsPIC33EP64MC502 dsPIC33EP64MC503 dsPIC33EP64MC504 dsPIC33EP64MC506 dsPIC33FJ06GS001 dsPIC33FJ06GS101 dsPIC33FJ06GS101A dsPIC33FJ06GS102 dsPIC33FJ06GS102A dsPIC33FJ06GS202 dsPIC33FJ06GS202A dsPIC33FJ09GS302 dsPIC33FJ128GP202 dsPIC33FJ128GP204 dsPIC33FJ128GP206 dsPIC33FJ128GP206A dsPIC33FJ128GP306 dsPIC33FJ128GP306A dsPIC33FJ128GP310 dsPIC33FJ128GP310A dsPIC33FJ128GP706 dsPIC33FJ128GP706A dsPIC33FJ128GP708 dsPIC33FJ128GP708A dsPIC33FJ128GP710 dsPIC33FJ128GP710A dsPIC33FJ128GP802 dsPIC33FJ128GP804 dsPIC33FJ128MC202 dsPIC33FJ128MC204 dsPIC33FJ128MC506 dsPIC33FJ128MC506A dsPIC33FJ128MC510 dsPIC33FJ128MC510A dsPIC33FJ128MC706 dsPIC33FJ128MC706A dsPIC33FJ128MC708 dsPIC33FJ128MC708A dsPIC33FJ128MC710 dsPIC33FJ128MC710A dsPIC33FJ128MC802 dsPIC33FJ128MC804 dsPIC33FJ12GP201 dsPIC33FJ12GP202 dsPIC33FJ12MC201 dsPIC33FJ12MC202 dsPIC33FJ16GP101 dsPIC33FJ16GP102 dsPIC33FJ16GP304 dsPIC33FJ16GS402 dsPIC33FJ16GS404 dsPIC33FJ16GS502 dsPIC33FJ16GS504 dsPIC33FJ16MC101 dsPIC33FJ16MC102 dsPIC33FJ16MC304 dsPIC33FJ256GP506 dsPIC33FJ256GP506A dsPIC33FJ256GP510 dsPIC33FJ256GP510A dsPIC33FJ256GP710 dsPIC33FJ256GP710A dsPIC33FJ256MC510 dsPIC33FJ256MC510A dsPIC33FJ256MC710 dsPIC33FJ256MC710A dsPIC33FJ32GP101 dsPIC33FJ32GP102 dsPIC33FJ32GP104 dsPIC33FJ32GP202 dsPIC33FJ32GP204 dsPIC33FJ32GP302 dsPIC33FJ32GP304 dsPIC33FJ32GS406 dsPIC33FJ32GS606 dsPIC33FJ32GS608 dsPIC33FJ32GS610 dsPIC33FJ32MC101 dsPIC33FJ32MC102 dsPIC33FJ32MC104 dsPIC33FJ32MC202 dsPIC33FJ32MC204 dsPIC33FJ32MC302 dsPIC33FJ32MC304 dsPIC33FJ64GP202 dsPIC33FJ64GP204 dsPIC33FJ64GP206 dsPIC33FJ64GP206A dsPIC33FJ64GP306 dsPIC33FJ64GP306A dsPIC33FJ64GP310 dsPIC33FJ64GP310A dsPIC33FJ64GP706 dsPIC33FJ64GP706A dsPIC33FJ64GP708 dsPIC33FJ64GP708A dsPIC33FJ64GP710 dsPIC33FJ64GP710A dsPIC33FJ64GP802 dsPIC33FJ64GP804 dsPIC33FJ64GS406 dsPIC33FJ64GS606 dsPIC33FJ64GS608 dsPIC33FJ64GS610 dsPIC33FJ64MC202 dsPIC33FJ64MC204 dsPIC33FJ64MC506 dsPIC33FJ64MC506A dsPIC33FJ64MC508 dsPIC33FJ64MC508A dsPIC33FJ64MC510 dsPIC33FJ64MC510A dsPIC33FJ64MC706 dsPIC33FJ64MC706A dsPIC33FJ64MC710 dsPIC33FJ64MC710A dsPIC33FJ64MC802 dsPIC33FJ64MC804 ...

      PIC32xx full series mcu read out: PIC32MX110F016B PIC32MX110F016C PIC32MX110F016D PIC32MX120F032B PIC32MX120F032C PIC32MX120F032D PIC32MX130F064B PIC32MX130F064C PIC32MX130F064D PIC32MX150F128B PIC32MX150F128C PIC32MX150F128D PIC32MX210F016B PIC32MX210F016C PIC32MX210F016D PIC32MX220F032B PIC32MX220F032C PIC32MX220F032D PIC32MX230F064B PIC32MX230F064C PIC32MX230F064D PIC32MX250F128B PIC32MX250F128C PIC32MX250F128D PIC32MX320F032H PIC32MX320F064H PIC32MX320F128H PIC32MX320F128L PIC32MX330F064H PIC32MX330F064L PIC32MX340F128H PIC32MX340F128L PIC32MX340F256H PIC32MX340F512H PIC32MX350F128H PIC32MX350F128L PIC32MX350F256H PIC32MX350F256L PIC32MX360F256L PIC32MX360F512L PIC32MX420F032H PIC32MX430F064H PIC32MX430F064L PIC32MX440F128H PIC32MX440F128L PIC32MX440F256H PIC32MX440F512H PIC32MX450F128H PIC32MX450F128L PIC32MX450F256H PIC32MX450F256L PIC32MX460F256L PIC32MX460F512L PIC32MX534F064H PIC32MX534F064L PIC32MX564F064H PIC32MX564F064L PIC32MX564F128H PIC32MX564F128L PIC32MX575F256H PIC32MX575F256L PIC32MX575F512H PIC32MX575F512L PIC32MX664F064H PIC32MX664F064L PIC32MX664F128H PIC32MX664F128L PIC32MX675F256H PIC32MX675F256L PIC32MX675F512H PIC32MX675F512L PIC32MX695F512H PIC32MX695F512L PIC32MX764F128H PIC32MX764F128L PIC32MX775F256H PIC32MX775F256L PIC32MX775F512H PIC32MX775F512L PIC32MX795F512H PIC32MX795F512L

      dsPIC30Fxx full series mcu firmware hack: dsPIC30F1010 dsPIC30F2010 dsPIC30F2011 dsPIC30F2012 dsPIC30F2020 dsPIC30F2023 dsPIC30F3010 dsPIC30F3011 dsPIC30F3012 dsPIC30F3013 dsPIC30F3014 dsPIC30F4011 dsPIC30F4012 dsPIC30F4013 dsPIC30F5011 dsPIC30F5013 dsPIC30F5015 dsPIC30F5016 dsPIC30F6010 dsPIC30F6010A dsPIC30F6011 dsPIC30F6011A dsPIC30F6012 dsPIC30F6012A dsPIC30F6013 dsPIC30F6013A dsPIC30F6014 dsPIC30F6014A dsPIC30F6015 ...

      HCSxx series mcu firmware hack: HCS300 HCS301 HCS360 HCS361 HCS362 HCS412 HCS500 HCS512 HCS515 ...

    • I thought it would be fun to try out some of the hacking techniques I had heard about on the PIC series of microcontrollers. PIC microcontrollers typically come with a set of “configuration fuses” that typically include settings to prevent the modification or readback of certain regions of memory. Quite often, a legitimate need arises to read out the contents of a secured, programmed PIC. A typical example is a company that has lost the documentation or the personnel that originally created the codes for a secured PIC. This often happens when a company needs to revise or upgrade a legacy line of products.

      I scored four PIC18F1320′s from Joe’s stash (it’s nice having lots of fellow hackers in San Diego) and started stripping them down. This is what a PIC18F1320 looks like in its native state:

      .
    • The first thing to do is to take the top off so you can see the silicon within. While there are many homebrew techniques for doing this, they typically involve the application of fuming Nitric or Sulfuric acid. Neither of these are compounds that you would want to have around your home, nor are they easy to obtain since Nitric acid in particular is an important compound for explosives fabrication. I’ve found that the easiest and most reliable way to do this is to just send the part to a failure analysis lab, such as MEFAS, and for about $50 and a two-day wait, you can have a decapped microcontroller hacking with fib focused ion beam and sem scanned electron microscope part in your hands. For this project, I decapped three total parts; two were functionally decapped (silicon revealed with device still in lead frame, fully functional), and the last one was fully decapsulated so that it was just a bare silicon die completely absent a package. The last die was fully decapsulated because my inspection microscope has a very short working distance at the highest magnifications.
    • A little sweeping around the die revealed several prominent features, as shown below:
    • The above annotations are my best guesses at what various structures do; I could be wrong, and if you happen to have anything to share, please do post a note!

      One set of structures grabbed my attention immediately: a snaileye set of metal shields over transistors, following a regular pattern that had about the right number of devices to account for all the security bits. Full metal shields covering a device is very rare in silicon, and like a big X marking the spot, it draws attention to itself as holding something very important.

    • Let’s think a little bit more about this metal shield. What is the significance? First, let’s review some interesting facts about FLASH technology (the type of memory technology used in this PIC device to store the security fuse information). FLASH technology uses a floating-gate transistor structure very similar to that found in the old UV-eraseable EPROM technologies (remember the days of the ceramic packaged 2716′s with quartz windows?). Data is stored in both FLASH and UV-EPROM devices by causing electrons to tunnel into the floating gate, where the electrons will remain for decades. The extra electrons residing in the floating gate creates a measurable offset in the characteristics of the storage transistor. The difference is that FLASH memory can withdraw the stored electrons (erase the device) using only electrical pulses, whereas a UV-EPROM requires energetic photons to knock the electrons out of the floating gate. The UV light required to accomplish this is typically on a wavelength of around 250 nm. This wavelength of UV is a bit difficult to manipulate, since it requires expensive quartz optics to manipulate without excessive loss.

      Here’s the important observation that comes out of these facts: FLASH devices can usually also be erased using UV light since they have a similar transistor structure to UV-EPROM devices. The encapsulation around a FLASH device normally prevents any UV light from effectively reaching the die, but since the PIC devices had the plastic around them removed, I can now attempt to apply UV light to see what happens.

      I performed a simple experiment where I programmed the PIC device with a ramping pattern (0×00->0xFF over and over again) and then tossed it in my UV-EPROM eraser for the length of oh, about a good long shower and some email checking. When I took the device out of the eraser, I found that indeed the FLASH memory was blanked to it’s normal all 1′s state, and that the security fuses were unaffected. Significantly, if I did not bake the PIC device for long enough, I would get odd readings out of the array, such as all 0′s, a phenomemon that I do not understand. I’m supposing it could be due to some effect involving incomplete erasure and the reference bitlines used to drive the reference leg of the sense amps on the FLASH array. Also note that the UV light works just as well on the EEPROM array.

      Clearly, the metal shields over the security fuses were provisioned to thwart attempts to selectively erase the security fuses while leaving the FLASH memory array unaffected.

    • The picture above illustrates the problem I have (and its solution) (click on the image for a larger, clearer version). In order for the FLASH memory transistor to be erased, high-intensity UV light must strike the floating gate. The metal shield effectively reflects all of the incident light.

      However, due to the optical index mismatch between maker together club the oxide and the silicon interfaces, light at certain angles will reflect off of the silicon surface. In order to witness an example of this reflective effect, jump in a swimming pool and submerse your head and look up at the water-air interface. You will note that the water looks highly reflective at an oblique angle. This is due to the index mismatch between water and air causing total internal reflection of light.

      This reflection can be used to cause the UV light to bounce up and the metal shield, and bounce back onto the floating gate. Thus, by angling the PIC inside the ROM eraser, I can get enough light to bounce into the FLASH memory transistor region and cause erasure. After a couple of attempts, I developed a technique that seems to work relatively well.

    • Picture of the chip inside the UV eraser (note blue halo around chip due to active UV lamp). The chip is stuck into the antistatic foam at an angle.

      This still doesn’t prevent me from erasing the desired data in the program FLASH space. In order to prevent erasure of this data, a hard-mask is formed using a very carefully cut piece of electrical tape that was stuck onto the surface of the die using a steady hand, two tweezers firmware hack , and a microscope. The electrical tape effectively blocks the UV light from directly hitting the FLASH code memory regions, and it also somewhat absorbs light bounced back from the silicon substrate.

    • Here’s a picture of the die in package with electrical tape over the FLASH rom array.

      Using this technique, I was able to effectively reset the security fuses without impacting the FLASH code array too much. The pictures below show the array memory status according to the programming/readback tool I was using. A part of the code array was still erased, but probably some judicious resizing of the electrical tape could fix that problem.

      Screenshot of PIC programmer workspace of device settings before erasure. Note settings of security fuses and the values programmed in the FLASH rom in the window behind the fuse window.

    • Screenshot of PIC programmer workspace of device settings after erasure. Note that security fuses are disabled while the FLASH rom contens in the window behind the fuse window read out identically to what was programmed in previously .

      And thus one can selective erase portions of a PIC’s contents. Fun!

General Questions About Microcontroller Firmware Extraction


  • Is it safe to send payment to MikaTech ?

    If MikaTech was a bad company, you could find tons of bad reputations about its service on the internet over the 28 years history

    So, the answer is YES! We are good people.

    Why choose Mikatech, please click here to find out


  • Can Mikatech break ics not listed on this site ?

    Different chip manufacturers have different part numbers, but the inner core of the chip can be make with same technology, it would be quite impossible to list all the part numbers where our technology can apply such as MYSON, STK, FEELING, ANALOG, FUJITSU, NOVATEK, LG/HYNDAI.

    Also by the advancing of the technology, everyday we gain more and more experience and develope new methods for reverse engineering for different Intergated Circuit parts. Full list of Integrated Circuit part numbers which is within our scope of capability is always getting bigger, please contact us to find out.

  • Will my privacy be protected ?

    Mikatech Innovative Limited understands the importance of its clients' privacy. At the moment you contact Mikatech, the personal information from you will be put under protection by our management regulations which was developed by our years of practice, Mikatech uses these information to customize its service to you, it will never disclose these information to third party out of any reason.
    Every project we did, we will delete all the data, materials, and codes 60days after deliverig the files, it iwll protect us and protect your privacy.

  • Is it legal to get service from Mikatech ?

    Yes, it is totally legal.
    Mikatech deliver its reverse engineering services for educational purposes only, it can be illegal to use above mentioned services in some coutries or regions, please check your local laws. Mikatech does not take any responsibility in relation to the use of above mentioned services that may be considered illegal.


  • I sent you an email, why there is no answer ?

    • A. Our mail server is temperally broke down, your message has not been delivered to our mailbox even the mail sent successfully message is showed on the screen, please contact us again.
    • B. Our email is recognised as junk mail email by your mail server, so our reply has been rejected by your mail server or it is diverted to your junk mailbox, please remove our account from junkmail list or check your junk mailbox, or use another email account to contact such as gmail.
    • C. Your email is recognised as junk mail email by our mail server, so your email was put to our junk mailbox, please use another email account to contact us again.

    microcontroller_hack_time

    Years

    28 +
    microcontroller hack countries

    Countries

    110 +
    microcontroller attack clients

    Clients

    5000 +
    microcontroller projects unlocked

    Projects

    60000 +