User talk:Ada L0ve Lace/sandbox: Difference between revisions

From PS4 Developer wiki
Jump to navigation Jump to search
mNo edit summary
mNo edit summary
 
(13 intermediate revisions by 3 users not shown)
Line 1: Line 1:
<div style="float:right">[[File:CXD90025G_-_pic05.jpg|200px|thumb|left|[[CXD90025G]] inside die overview]]</div>
<div style="float:right">[[File:CXD90025G_-_pic05.jpg|200px|thumb|left|[[CXD90025G]] inside die overview]]</div>


  [[File:Ambox_deletion.png]] This article (to be moved) is for educational purposes only, do not try to repeat!  [[File:Ambox_deletion.png]]
  [[File:Ambox_deletion.png]] This article is for educational purposes only, do not try to repeat!  [[File:Ambox_deletion.png]]


== References ==
== References ==
Line 16: Line 16:


*http://www.cleanroom.byu.edu/wet_etch.phtml Wet Chemical Etching of Metals and Semiconductors
*http://www.cleanroom.byu.edu/wet_etch.phtml Wet Chemical Etching of Metals and Semiconductors
*http://users.sec.t-labs.tu-berlin.de/~nedos/ccs2013.pdf Breaking and Entering through the Silicon


== Decap a (epoxy packaged) chip, but why? ==
== Decap a (epoxy packaged) chip, but why? ==
Line 28: Line 30:
**to get die numbers
**to get die numbers
**check for counterfeit (e.g. http://www.cti-us.com/pdf/CCAP-101InspectExamplesA6.pdf)
**check for counterfeit (e.g. http://www.cti-us.com/pdf/CCAP-101InspectExamplesA6.pdf)
*microprobing
*microprobing ( e.g.: with ion beam workstation)
*if somehow, you end up here for making explosive things/dispose body, it s not the right place.
*if somehow, you end up here for making explosive things/dispose body, it s not the right place.


Line 67: Line 69:


  You can burn/intoxicate by fumes (like countless of experimented and certified chemists). Chemical burn traumata with nitric acid lead to  
  You can burn/intoxicate by fumes (like countless of experimented and certified chemists). Chemical burn traumata with nitric acid lead to  
  specific yellow- to brown-stained wounds with slower accumulation of eschar and slower demarcation compared with thermal burns; skins stains/coloration can happens later
  specific yellow- to brown-stained wounds with slower accumulation of eschar and slower demarcation compared with thermal burns; skins stains/coloration  
on (8 hours) without you noiticing any traumata/burn on the spot.
can happens later on (8 hours) without you noiticing any traumata/burn on the spot.


*Boiling point:83 °C (181 °F; 356 K) 68% solution boils at 121 °C (250 °F; 394 K)
*Boiling point:83 °C (181 °F; 356 K) 68% solution boils at 121 °C (250 °F; 394 K)
Line 92: Line 94:
  Because of the ability of hydrofluoric acid to penetrate tissue, poisoning can occur. Rinsing off is not enough.  
  Because of the ability of hydrofluoric acid to penetrate tissue, poisoning can occur. Rinsing off is not enough.  
  Accidental exposures can go unnoticed until a day after (too late).
  Accidental exposures can go unnoticed until a day after (too late).
   
 
  Corrosive effect on human tissue, with the potential to damage respiratory organs, eyes, skin, and intestines irreversibly.
 
*http://en.wikipedia.org/wiki/Hydrofluoric_acid#Health_and_safety
*http://en.wikipedia.org/wiki/Hydrofluoric_acid#Health_and_safety
*http://www.ncbi.nlm.nih.gov/pubmed/20512294 Finger burns caused by concentrated hydrofluoric acid, treated with intra-arterial calcium gluconate infusion: case report.


Porcelain etch gel contain low (9.6%) concentration of Hydrofluoric acid
Porcelain etch gel contain low (9.6%) concentration of Hydrofluoric acid


=== Hydrochloric Acid ===
=== Hydrochloric Acid ===
*[[File:Ambox_deletion.png]]  Warning: [[File:Ambox_deletion.png]]
 
*https://en.wikipedia.org/wiki/Hydrochloric_acid#Safety
  Corrosive effect on human tissue, with the potential to damage respiratory organs, eyes, skin, and intestines irreversibly.
 
*https://www.youtube.com/watch?v=YGjd7xxTuZw
 
=== Chlorine ===
[[File:Imbox content.png]]  Warning:
 
Chlorine is a toxic gas that irritates the respiratory system. Used as chemical weapon.
 
  widely used for purifying water owing to its powerful oxidizing properties, especially potable water supplies and water used in swimming pools.  


=== Hydrogen peroxide ===
=== Hydrogen peroxide ===
Line 111: Line 124:
  Can be used for the sterilization of various surfaces/tools or creating organic peroxide based explosive as improvised explosive devices.  
  Can be used for the sterilization of various surfaces/tools or creating organic peroxide based explosive as improvised explosive devices.  
  When diluted H<sub>2</sub>O<sub>2</sub> (between 1.9% and 12%) mixed with ammonium hydroxide is used to bleach human hair.
  When diluted H<sub>2</sub>O<sub>2</sub> (between 1.9% and 12%) mixed with ammonium hydroxide is used to bleach human hair.


=== Rosin ===
=== Rosin ===
Line 140: Line 151:
[[File:Imbox content.png]]  Warning:
[[File:Imbox content.png]]  Warning:


  Ethylenediamine is a skin and respiratory irritant. Unless tightly contained, liquid ethylenediamine will release toxic and irritating vapors into its surroundings,  
  Ethylenediamine is a skin and respiratory irritant. Unless tightly contained, liquid ethylenediamine will release toxic  
  especially on heating. The vapors react with moisture in humid air to form a characteristic white mist, which is extremely irritating to skin, eyes, lungs and mucus
and irritating vapors into its surroundings,  
  membranes. Exposure to a relatively small amount of vapor or mist by inhalation can seriously damage health and may even result in death.
  especially on heating. The vapors react with moisture in humid air to form a characteristic white mist,  
which is extremely irritating to skin, eyes, lungs and mucus membranes.
  Exposure to a relatively small amount of vapor or mist by inhalation can seriously damage health and may even result in death.


=== Ultrasonic bath ===
=== Ultrasonic bath ===
Line 154: Line 167:
=== Microprobing ===
=== Microprobing ===


  Microprobing techniques (invasive attacks) can be used, once the chip is depackaged, to access the chip surface directly, thus we can observe, manipulate, and interfere with integrated circuit.   
  Microprobing techniques (invasive attacks) can be used, once the chip is depackaged, to access the chip surface directly,  
thus we can observe, manipulate, and interfere with integrated circuit.   


  Microprobing workstation: Its major component is a special optical microscope with a working distance of at least 8 mm between the chip surface and the objective lens.  
  Microprobing workstation: Its major component is a special optical microscope with a working distance of at least 8 mm between the chip surface and the objective lens.  
  On a stable platform around a socket for the test package, we install several micropositioners , which allow us to move a probe arm with submicrometer precision over a chip surface. On this arm, we install a probe needle.  
  On a stable platform around a socket for the test package, we install several micropositioners ,  
which allow us to move a probe arm with submicrometer precision over a chip surface. On this arm, we install a probe needle.  
  These elastic probe hairs allow us to establish electrical contact with on-chip bus lines without damaging them.
  These elastic probe hairs allow us to establish electrical contact with on-chip bus lines without damaging them.


== Safety ==
== Safety ==


  Most if the items listed here are Prohibited Items (no fly)-hazardous materials (e.g. http://www.tsa.gov/traveler-information/prohibited-items)
  Most of the items listed here are Prohibited Items (no fly)-hazardous materials (e.g. http://www.tsa.gov/traveler-information/prohibited-items)
  In most of countries, having them/making them/speaking/thinking/dreaming about them (with or without an proper license) is enough to put you in jail and being raped many time
  Having them/making them/speaking/thinking/dreaming about them (with or without an proper license) is enough to put you in jail  
and being raped many time by many people/items.


*before: no fly items - studish/read - ...
*before: no fly items - studish/read - ...
*during: humble state of mind / not high/not drunk - ...
*during: humble state of mind / not high/not drunk - ...
*after: storage/disposal of hazardous items, nearest clinics - ....
*after: storage/disposal of hazardous items, nearest clinics - ....


*proper workplace/labs (not your kitchen table or RV vehicle as acids can cause spontaneous combustion with organics)
*proper workplace/labs (not your kitchen table or RV vehicle as acids can cause [https://en.wikipedia.org/wiki/Spontaneous_combustion spontaneous combustion] with organics)
*Fume Cabinet
*fume Cabinet
*acid-prof gloves
*acid-prof gloves
*protection glasses
*protection glasses
*protective suit
*protective suit and shoes
*wear a cap and tied your hairs
...
...


== Others ways ==
== Others ways ==
<div style="float:right">[[File:Chemistry-hazardous.png|200px|thumb|left|play it safety]]</div>


*the safe way: services
*the safe way: services
Line 182: Line 200:
*the burning way: propane or butane torch (no wires remaining)
*the burning way: propane or butane torch (no wires remaining)
*the Indian way: razzorblade (e.g. [http://www.psdevwiki.com/ps3/File:RSX_die_-_Image_made_by_H%C3%A9ctor_Mart%C3%ADn.jpg RSX die], scraped with razorblade by '''Héctor Martín''' aka '''Marcan''')
*the Indian way: razzorblade (e.g. [http://www.psdevwiki.com/ps3/File:RSX_die_-_Image_made_by_H%C3%A9ctor_Mart%C3%ADn.jpg RSX die], scraped with razorblade by '''Héctor Martín''' aka '''Marcan''')
*the laser way: https://www.youtube.com/watch?v=J00BEGsqIZE
 
*the laser way:  
**https://www.youtube.com/watch?v=J00BEGsqIZE
**https://www.jamiecraig.com/de-encapsulating-ics-with-a-laser-cutter/
**the CO2 laser way: http://hackaday.com/2015/08/29/co2-laser-decapping-to-fix-soldering-mistake/
 
*the portal way: http://www.nordson.com/en-us/divisions/march/support/Literature/Documents/Nordson-MARCH-Mold-Decap-Article-USTech-July2012.pdf vacuum plasma
*the portal way: http://www.nordson.com/en-us/divisions/march/support/Literature/Documents/Nordson-MARCH-Mold-Decap-Article-USTech-July2012.pdf vacuum plasma
*the brute force: way https://www.youtube.com/watch?v=tjjIyJxqOqE brute force (several people apparently insist that this is not decapping but just destroying)
*the brute force: way https://www.youtube.com/watch?v=tjjIyJxqOqE brute force (several people apparently insist that this is not decapping but just destroying)
*the longest way:
...
...



Latest revision as of 23:15, 23 February 2016

CXD90025G inside die overview
Ambox deletion.png This article is for educational purposes only, do not try to repeat!  Ambox deletion.png

References[edit source]

Decap a (epoxy packaged) chip, but why?[edit source]

CXD90025G die numbers


  • to damage (beyond repair) the chip and things around you (including you) and end up ,if lucky, in the great Wall of Shame or much worst (dead, blind & anosmia ...)
  • for fun (then, use razorblade but not as you were going to tearing a part of the human scalp)
  • photograph for forensics purposes:
  • microprobing ( e.g.: with ion beam workstation)
  • if somehow, you end up here for making explosive things/dispose body, it s not the right place.

The Strike Easy Hard Way (be blind & anosmia)[edit source]

Epoxy resin around the chip could be removed using fuming nitric acid (HNO3) (when the solution contains more than 86% HNO3, it is referred to as fuming nitric acid).

Hot fuming nitric acid dissolves the package without affecting the chip. The procedure should preferably be carried out under very dry conditions, as the presence of water could corrode exposed aluminium interconnects.

Alternatives to heated HNO3 (70% concentration is enough) can be with cold white HNO3 (99% concentration), with sulfuric acid (H2SO4) or with (boilting) rosin (for 20 minutes).

The chip is then washed with acetone in an ultrasonic bath, followed optionally by a short bath in deionized water and isopropanol.

After that chip could be glued into a test package and bonded manually. Having enough experience it might be possible to remove epoxy without destroying bonding wires and smartcard contacts.

On the depackaged chip, the top-layer aluminium interconnect lines are still covered by a passivation layer (usually silicon oxide or nitride), which protects the chip from the environment and ion migration.

On top of this, we might also find a polyimide layer that was not entirely removed by HNO3 but which can be dissolved with ethylenediamine.

We have to remove the passivation layer (top layer of the die) before the probes can establish contact.

Wire bonding Gold is immune to attack from the fuming acids used to etch away the mold compound of the package; copper is not.

Passivation layer[edit source]

Growth of an oxide layer on the surface of a semiconductor to provide electrical stability by isolating the transistor surface from electrical and chemical conditions in the environment; this reduces reverse-current leakage, increases breakdown voltage, and raises power dissipation rating.

The most convenient depassivation technique is the use of a laser cutter. The UV or green laser is mounted on the camera port of the microscope and fires laser pulses through the microscope onto rectangular areas of the chip with micrometer precision. Carefully dosed laser flashes remove patches of the passivation layer.

The resulting hole in the passivation layer can be made so small that only a single bus line is exposed. This prevents accidental contacts with neighboring lines and the hole also stabilizes the position of the probe and makes it less sensitive to vibrations and temperature changes.

An other way to remove the passivation layer is by using hydrofluoric acid.

Terminology[edit source]

Nitric acid[edit source]

  • Ambox deletion.png Warning: Ambox deletion.png
You can burn/intoxicate by fumes (like countless of experimented and certified chemists). Chemical burn traumata with nitric acid lead to 
specific yellow- to brown-stained wounds with slower accumulation of eschar and slower demarcation compared with thermal burns; skins stains/coloration 
can happens later on (8 hours) without you noiticing any traumata/burn on the spot.
  • Boiling point:83 °C (181 °F; 356 K) 68% solution boils at 121 °C (250 °F; 394 K)

Sulfuric acid[edit source]

  • Ambox deletion.png Warning: Ambox deletion.png
causing very severe burns, apidly attacks the cornea and can induce permanent blindness if splashed onto eyes.

Hydrofluoric acid[edit source]

  • Ambox deletion.png Warning: Ambox deletion.png
In addition to being a highly corrosive liquid, hydrofluoric acid is also a contact poison. It should therefore be handled with extreme care.
Because of the ability of hydrofluoric acid to penetrate tissue, poisoning can occur. Rinsing off is not enough. 
Accidental exposures can go unnoticed until a day after (too late).
Corrosive effect on human tissue, with the potential to damage respiratory organs, eyes, skin, and intestines irreversibly.

Porcelain etch gel contain low (9.6%) concentration of Hydrofluoric acid

Hydrochloric Acid[edit source]

Chlorine[edit source]

Imbox content.png Warning:

Chlorine is a toxic gas that irritates the respiratory system. Used as chemical weapon.
widely used for purifying water owing to its powerful oxidizing properties, especially potable water supplies and water used in swimming pools. 

Hydrogen peroxide[edit source]

Imbox content.png Warning:

Regulations vary, but low concentrations, such as 6%, are widely available and legal to buy for medical use. 
Most over-the-counter peroxide solutions are not suitable for ingestion. 
Higher concentrations may be considered hazardous
Can be used for the sterilization of various surfaces/tools or creating organic peroxide based explosive as improvised explosive devices. 
When diluted H2O2 (between 1.9% and 12%) mixed with ammonium hydroxide is used to bleach human hair.

Rosin[edit source]

Imbox content.png Warning:

Boil a chip for a few hours in rosin, like used for soldering. Refluxing equipment is ideal. Should eat away the casing. Might be best used with Dremeling or other techniques to remove the majority of the epoxy first. The active ingredient for this is abietic acid.

Acetone[edit source]

Imbox content.png Warning:

Acetone is flammable for everyone (advanced/certified user or not), can enter the body by inhalation, skin contact or ingestion.

Common Products Containing Acetone:

Isopropanol[edit source]

Imbox content.png Warning:

Symptoms of isopropyl alcohol poisoning include flushing, headache, dizziness, CNS depression, nausea, vomiting, anesthesia, and coma.
Poisoning can occur from ingestion, inhalation, or absorption; therefore, well-ventilated areas and protective gloves are recommended. 
Around 15 g of isopropyl alcohol can have a toxic effect on a 70 kg human (the bigger they are the harder they fall).

Ethylenediamine[edit source]

Imbox content.png Warning:

Ethylenediamine is a skin and respiratory irritant. Unless tightly contained, liquid ethylenediamine will release toxic 
and irritating vapors into its surroundings, 
especially on heating. The vapors react with moisture in humid air to form a characteristic white mist, 
which is extremely irritating to skin, eyes, lungs and mucus membranes. 
Exposure to a relatively small amount of vapor or mist by inhalation can seriously damage health and may even result in death.

Ultrasonic bath[edit source]

An ultrasonic cleaning is a process that uses ultrasound (usually from 20–400 kHz) and an appropriate cleaning solvent (sometimes ordinary tap water) to clean items.

Deionized water[edit source]

Deionized water is a type of purified water with mineral ions (salts) removed. Deionized water is created by taking 
conventional water and exposing it to electrically charged resins that attract  and bind to the salts, removing them from the water.

Microprobing[edit source]

Microprobing techniques (invasive attacks) can be used, once the chip is depackaged, to access the chip surface directly, 
thus we can observe, manipulate, and interfere with integrated circuit.  
Microprobing workstation: Its major component is a special optical microscope with a working distance of at least 8 mm between the chip surface and the objective lens. 
On a stable platform around a socket for the test package, we install several micropositioners , 
which allow us to move a probe arm with submicrometer precision over a chip surface. On this arm, we install a probe needle. 
These elastic probe hairs allow us to establish electrical contact with on-chip bus lines without damaging them.

Safety[edit source]

Most of the items listed here are Prohibited Items (no fly)-hazardous materials (e.g. http://www.tsa.gov/traveler-information/prohibited-items)
Having them/making them/speaking/thinking/dreaming about them (with or without an proper license) is enough to put you in jail 
and being raped many time by many people/items.
  • before: no fly items - studish/read - ...
  • during: humble state of mind / not high/not drunk - ...
  • after: storage/disposal of hazardous items, nearest clinics - ....
  • proper workplace/labs (not your kitchen table or RV vehicle as acids can cause spontaneous combustion with organics)
  • fume Cabinet
  • acid-prof gloves
  • protection glasses
  • protective suit and shoes
  • wear a cap and tied your hairs

...

Others ways[edit source]

play it safety

...

Related articles[edit source]

Microwires inside an IC (DualShock 4)

...