element14 Community
element14 Community
    Register Log In
  • Site
  • Search
  • Log In Register
  • Community Hub
    Community Hub
    • What's New on element14
    • Feedback and Support
    • Benefits of Membership
    • Personal Blogs
    • Members Area
    • Achievement Levels
  • Learn
    Learn
    • Ask an Expert
    • eBooks
    • element14 presents
    • Learning Center
    • Tech Spotlight
    • STEM Academy
    • Webinars, Training and Events
    • Learning Groups
  • Technologies
    Technologies
    • 3D Printing
    • FPGA
    • Industrial Automation
    • Internet of Things
    • Power & Energy
    • Sensors
    • Technology Groups
  • Challenges & Projects
    Challenges & Projects
    • Design Challenges
    • element14 presents Projects
    • Project14
    • Arduino Projects
    • Raspberry Pi Projects
    • Project Groups
  • Products
    Products
    • Arduino
    • Avnet & Tria Boards Community
    • Dev Tools
    • Manufacturers
    • Multicomp Pro
    • Product Groups
    • Raspberry Pi
    • RoadTests & Reviews
  • About Us
    About the element14 Community
  • Store
    Store
    • Visit Your Store
    • Choose another store...
      • Europe
      •  Austria (German)
      •  Belgium (Dutch, French)
      •  Bulgaria (Bulgarian)
      •  Czech Republic (Czech)
      •  Denmark (Danish)
      •  Estonia (Estonian)
      •  Finland (Finnish)
      •  France (French)
      •  Germany (German)
      •  Hungary (Hungarian)
      •  Ireland
      •  Israel
      •  Italy (Italian)
      •  Latvia (Latvian)
      •  
      •  Lithuania (Lithuanian)
      •  Netherlands (Dutch)
      •  Norway (Norwegian)
      •  Poland (Polish)
      •  Portugal (Portuguese)
      •  Romania (Romanian)
      •  Russia (Russian)
      •  Slovakia (Slovak)
      •  Slovenia (Slovenian)
      •  Spain (Spanish)
      •  Sweden (Swedish)
      •  Switzerland(German, French)
      •  Turkey (Turkish)
      •  United Kingdom
      • Asia Pacific
      •  Australia
      •  China
      •  Hong Kong
      •  India
      •  Japan
      •  Korea (Korean)
      •  Malaysia
      •  New Zealand
      •  Philippines
      •  Singapore
      •  Taiwan
      •  Thailand (Thai)
      •  Vietnam
      • Americas
      •  Brazil (Portuguese)
      •  Canada
      •  Mexico (Spanish)
      •  United States
      Can't find the country/region you're looking for? Visit our export site or find a local distributor.
  • Translate
  • Profile
  • Settings
Community Hub
Community Hub
Documents elf14 presents - Circuit Assembly Tools Giveaway
  • Blog
  • Forum
  • Documents
  • Quiz
  • Events
  • Leaderboard
  • Polls
  • Files
  • Members
  • Mentions
  • Sub-Groups
  • Tags
  • More
  • Cancel
  • New
Join Community Hub to participate - click to join for free!
Actions
  • Share
  • More
  • Cancel
Engagement
  • Author Author: cstanton
  • Date Created: 18 Nov 2020 3:44 PM Date Created
  • Last Updated Last Updated: 15 Jan 2021 11:21 AM
  • Views 8581 views
  • Likes 20 likes
  • Comments 140 comments
Related
Recommended

elf14 presents - Circuit Assembly Tools Giveaway

image
The Circuit Assembly Tools Giveaway!

Engineer and Maker Wishlist | Circuit Assembly Tools Giveaway! | Test and Measurement Giveaway! | Ultimate Raspberry Pi Giveaway! | Project14 Holiday Special

 

 

Unsupported video URL format.

 

Welcome to the elf14 element14 Community!

 

It's the season of gift-giving, so the element14 Community has prepared the Best Circuit Assembly Tools Bundle to giveaway!

 

The below kit will be awarded to the element14 members that add a comment and let us know:

 

What was your best electronics fix or repair?

What 'thing' did you figure out in a project or design, or repair that saved the day?

Tell us your good stories, or if you really don't have any, your best recovered disasters!

 

Contest Opens: 27th November 2020

Contest Closes: 30th December 2020

Winners Announced: After 11th January 2021

 

Register to Enter Now!

 

What We Gave Away!

 

Product NameManufacturerQuantityBuy KitBuy Kit
Wire Kit, Jumper, Male to Male, Solderless, 100 mm - 250 mm, 75 PieceMCM1Buy NowBuy Now
Wire Kit, Jumper, Copper, 0.6 mm Diameter, 350 PieceMCM1Buy NowBuy Now
Anti Static Wrist Strap, Adjustable, 6ft Cord, Blue, Alligator ClipMulticomp1Buy NowBuy Now
Single Channel Soldering Rework Station, 230V, 150WMulticomp Pro1Buy NowBuy Now
Solder Paste Squeege, Synthetic No Clean, PVCChip Quik1Buy NowBuy Now
Solder Paste, Synthetic No Clean, 183 °C, 63, 37 Sn, Pb, 15GChip Quik1Buy NowBuy Now
Solder Flux, Rosin, Soldering, Pen Applicator, 10 ml, 9.3 gMulticomp1Buy NowBuy Now

 

Product NameManufacturerQuantity
element14 presents Prototyping BreadBoardn/a1

 

Congratulations to the Winner!

 

davegsm82 has been chosen, and they have 7 days to respond to the message sent to them!

 

If you do not respond within 7 days, I will have to choose another winner!

 

Terms and Conditions apply.

  • elf14 presents
  • circuit assembly tools
  • circuit assembly tools giveaway
  • holiday season 2020
  • holiday season
  • elf14presents_wishlist
  • Share
  • History
  • More
  • Cancel
  • Sign in to reply

Top Comments

  • magikben
    magikben over 5 years ago +11
    When I was an engineering co-op in college I had a job working with the standby power group of a Cummins distributor. We had a big job putting a 1MW genset in a data center. Awesome unit with a quad turbo…
  • koudelad
    koudelad over 5 years ago +10
    My best electronics repair was a CNG boiler. Long story short: just before the freezing winter, my friend had a control board of a CNG boiler failure. It heated water and all the rooms. He was offered…
  • davegsm82
    davegsm82 over 5 years ago +10
    Just wanted to put this up and say thanks to the folks at element14, I received the prize from the competition and just wanted to put up this pic. The soldering station is amazing, and by happy coincidence…
Parents
  • crowman
    crowman over 5 years ago

    Let me first say I am only a hobbyist self taught and by no means any sort of technician.

     

    My brother owns a very popular manufacturers telescope and suddenly it stopped working and failed to power on.

    As it was out of warranty he asked me to take a look at it due to the cost of the repair was more than the cost of a replacement.

    When I received it from him I soon discovered there was a direct short between ground and the +12v rail in the computerised mount..

    I contacted the manufacturer who wouldnt offer any real assistance, and only kept telling me i need to purchase an upgraded mainboard for the mount.

     

    I dont give up quite so easy image

    I worked my way through the board and soon discovered that there was no real supply protection circuitry within the mount and having tested all of the surface mount caps and regulator which would usually give this type of fault i turned to what was left, just the main IC's.

    i desoldered the 80pin kinetis  MK20DX256VLK10 and replaced it with a blank chip and bingo, the mount powered up.

    obviously it wouldnt work as there was no software on it.

     

    I then contacted the manufacturer of the mount again and explained the issue was the main processor and discussed with them the lack of protection circuitry, they assured me the updated main board has better protection and I would need to still purchase a new board.

     

    I asked them if it was possible to get the firmware for the processor as I could not read it from the damaged chip so I could at least get this board back up and running, they wouldnt help me with it image

     

    As my father always said tho, theres always more than 1 way of skinning a cat image

     

    I know the manufacturer releases bugfix's for their hardware, so I turned my attention to their latest bugfix update package..

    It is released as a java package( im not a computer programmer either by the way)

    but I do know winzip can be used to unpack java,

    I ended up with a full directory of about 100 java files which I started going through to give me some ideas of what and where to look at.

    at the same time I wanted to understand how the package updated the kinetis chip,

    from the update instructions, i knew the software used a serial connection to the hand controller

     

    I made up a serial lead and instead of connecting it to the hand controller i connected it to a raspberry pi,

    i wrote a small python script to capture any binary data from the pc that i was running the update software on,

    it didnt capture very much so i started echong it to the screen using a bin2hex library.

    after a while of looking at it, i noticed there was something common within it, basically a set of 3 bytes,

    i inserted a line break at every occurance of these bytes and soon realised they were basically being used as start and stops.

     

    I looked for these bytes in the java code and then learned that these were indeed the start and stop bytes, the next pair of bytes was an instruction byte followed by the data and then length and then a checksum.

     

    knowing all this, i then connected the raspberry on a seperate serial port to the hand controller, and ran the update again.

     

    i now could see data coming back from the hand controller as well, the hand controller was looking for any attached hardware.

    i knew without any software on the mount it would not see the mount. so i started digging further into the java software.

    I found when it searched for the software on particular responses it would read in some binary files, i managed to figure which binary files was associated with each type of hardware and most importantly which ones was used for the mount i was working on.

     

    each of the binary files had their own file headers and data sections which i was able after many hours to figure out.

    there was in total 7 binary files required for the mount and each file was lightly encrypted with the exception of one.

     

    I read up on the kinetis bootup and found it could be programmed in such a way that the bootloader could be at the top or bottom of memory,

    the mount had a 2nd large flash chip in it which was unharmed, and knowing the way the kinetis chip maps memory and uses a flash chip i knew the bootloader would have to start at address 0x0h and the most it could use was 400 bytes.

     

    i dug into the java many times rerunning and recapturing responses from the hand controller and started inserting my own responses from what i was learning.

    after a few days i finally was able to capture the bootloader being sent from the suspected binary file to the hand controller which should pass it to the motor controller.

    obviously the hand controller couldnt pass it as it was my responses on the raspberry  that triggered it being sent from the upgrade package it wasnt the hand controllers.

    but i had now got the bootloader stored in its binary decrypted format on the raspberry image

     

    now the easy bit

    burn the bootloader to the kinetis chip,

    i found the pads for what should be a jtag interface on the board and tried to burn the bootloader via that, it was quickly apparent that it wasnt working. after some tracing i discovered that it wasnt completely connected and had to solder a thin wire directly to the unconnected pin on the kinetis chip.

    as soon as i did this i was able to program the bootloader in.

    woohoo, getting somewhere image))

     

    fingers crossed now,

    i ran the upgrade package again, still capturing everything on the raspberry.

    bingo!!!!!

    i could now see the hand controller replying to the upgrade software that there is a mount attached.

    i selected the mount and software package within the upgrade application and i was able to fully update the mount with the latest software image)))

     

    My brother is a happy bunny now, his mount completely working again for the price of a £10 chip and some time and patience.

    Im happy as i was able to fix it for him and learned so much in the process image)

     

    I have since connected the raspberry between the hand controller and the mount and captured all the commands on that for its movement and speed controls etc,

    The intention is to write a small program that will interface between an open source PC application and the mount so he can use it connected to the PC as a computer controlled mount for looking at distant galaxies and nebulas.

    • Cancel
    • Vote Up +5 Vote Down
    • Sign in to reply
    • More
    • Cancel
  • 14rhb
    14rhb over 5 years ago in reply to crowman

    Wow, an impressive amount of reverse-engineering in your example. Also you have the satisfaction you can tell the manufacturer (politely) that it's a shame they didn't design mount version 1 properly but you still don't need their upgraded mount.

     

    Another side of me thinks with effort and self-taught skills like that you'll never be out of work or demand !

     

    Feel free to post some blogs on Element14 about any future teardowns or hardware hacks you get up to, they'll make good reading I'm sure image

    • Cancel
    • Vote Up +1 Vote Down
    • Sign in to reply
    • More
    • Cancel
  • crowman
    crowman over 5 years ago in reply to 14rhb

    Thankyou,

    I do get a fair few people bringing me things to fix image 

     

    I have since contacted the manufacturer of the telescope to advise them how I was able to fix my brothers scope, and I know the fault is a common issue from reading the astronomy forums. The manufacturer has actually asked me not to publish the dumped image as they do not want their firmware copied. being honest tho, i would like to publish it so other people could fix their own telescopes mainly because i feel the manufacturer was so unhelpful and was just using the fault as an opportunity to take even more money from their customers. Its not as if these mounts and telescopes come cheap.

     

    while fixing the mount I was also in contact with the UK's largest astronomy shop and their technicians, these guys was at least trying to be helpful, and also a more local small astronomy 2nd hand dealer. I have told both of these how I repaired it but have not given them the firmware. The large store was quite amazed how I did it and have never heard of someone able to repair the fault before.

    The local store has actually asked me to fix one of their mounts for them, they have a larger mount by the same manufacturer with what they believe is a similar issue image

    They are going to drop it to me after Christmas for me to take a look at for them image

    I am pretty sure I can do it the same way as most of the manufacturers mounts use the same software to update their telescopes image

     

    I also now know when the updater completes it does lock the kinetis chip to protect the chip from being read so the manufacturer really does not want people to get their hands on it.

     

    during the final captures i was able to capture all the software for the telescope, including all the star mapping data, location data everything, i have the complete images of both the kinetis chip which is really used just for the bootloader and update control and the extended memory flash chip which stores all the star and location data and configuration settings etc. each type of data is stored at specific memory locations and each block of data has calculated checksums. I have figured out each location and the checksum routines, the checksum is actually a modified crc16 checksum and can be easily reversed so i wrote a small routine to do it image

     

    As for releasing the firmware on the astronomy forums so people can repair their own mounts, I havent done this yet as I really dont understand where I would stand legally and could I get in trouble for releasing it or not in its raw image format decrypted.

    Im sure I am fine explaining how I have done it so others can follow what I have done but as for releasing the actual firmware I think would be a bit of a grey area and I am a bit concerned that i might get in trouble if i was to release it.

    • Cancel
    • Vote Up +3 Vote Down
    • Sign in to reply
    • More
    • Cancel
Comment
  • crowman
    crowman over 5 years ago in reply to 14rhb

    Thankyou,

    I do get a fair few people bringing me things to fix image 

     

    I have since contacted the manufacturer of the telescope to advise them how I was able to fix my brothers scope, and I know the fault is a common issue from reading the astronomy forums. The manufacturer has actually asked me not to publish the dumped image as they do not want their firmware copied. being honest tho, i would like to publish it so other people could fix their own telescopes mainly because i feel the manufacturer was so unhelpful and was just using the fault as an opportunity to take even more money from their customers. Its not as if these mounts and telescopes come cheap.

     

    while fixing the mount I was also in contact with the UK's largest astronomy shop and their technicians, these guys was at least trying to be helpful, and also a more local small astronomy 2nd hand dealer. I have told both of these how I repaired it but have not given them the firmware. The large store was quite amazed how I did it and have never heard of someone able to repair the fault before.

    The local store has actually asked me to fix one of their mounts for them, they have a larger mount by the same manufacturer with what they believe is a similar issue image

    They are going to drop it to me after Christmas for me to take a look at for them image

    I am pretty sure I can do it the same way as most of the manufacturers mounts use the same software to update their telescopes image

     

    I also now know when the updater completes it does lock the kinetis chip to protect the chip from being read so the manufacturer really does not want people to get their hands on it.

     

    during the final captures i was able to capture all the software for the telescope, including all the star mapping data, location data everything, i have the complete images of both the kinetis chip which is really used just for the bootloader and update control and the extended memory flash chip which stores all the star and location data and configuration settings etc. each type of data is stored at specific memory locations and each block of data has calculated checksums. I have figured out each location and the checksum routines, the checksum is actually a modified crc16 checksum and can be easily reversed so i wrote a small routine to do it image

     

    As for releasing the firmware on the astronomy forums so people can repair their own mounts, I havent done this yet as I really dont understand where I would stand legally and could I get in trouble for releasing it or not in its raw image format decrypted.

    Im sure I am fine explaining how I have done it so others can follow what I have done but as for releasing the actual firmware I think would be a bit of a grey area and I am a bit concerned that i might get in trouble if i was to release it.

    • Cancel
    • Vote Up +3 Vote Down
    • Sign in to reply
    • More
    • Cancel
Children
No Data
element14 Community

element14 is the first online community specifically for engineers. Connect with your peers and get expert answers to your questions.

  • Members
  • Learn
  • Technologies
  • Challenges & Projects
  • Products
  • Store
  • About Us
  • Feedback & Support
  • FAQs
  • Terms of Use
  • Privacy Policy
  • Legal and Copyright Notices
  • Sitemap
  • Cookies

An Avnet Company © 2026 Premier Farnell Limited. All Rights Reserved.

Premier Farnell Ltd, registered in England and Wales (no 00876412), registered office: Farnell House, Forge Lane, Leeds LS12 2NE.

Follow element14

  • X
  • Facebook
  • linkedin
  • YouTube