A masterclass in low-level hardware recovery that transforms a complex bricking scenario into a streamlined, efficient procedure. By leveraging shadow memory modifications to optimize JTAG access, the author demonstrates a profound understanding of automotive firmware architecture.
Deep Dive
Prerequisite Knowledge
- No data available.
Where to go next
- No data available.
Deep Dive
E39A CAN, BAM,JTAG explained.
Added:This is an ECU E39A.
And when it's working, we should be able to program this device through the canvas on these two connectors here. So when the unit uh paired with this board, I just need to connect the CAN high and CAN low to here.
And then we need to connect the 12 pins.
12 volt.
This is 12 volt.
And then the ground.
Then I am powering on the uh USB. Power on the ECU.
Go to software. We can check the ECU info.
We one more time. And the spin number are there. The very first thing to for any ECU programming is always back up the original one just in case we have something bad, we need to uh recover it.
So the first thing to do is we read the entire flash. So click here. This will put the ECU into the debugger on mode and start backing up the ECU.
So finish the reading.
Let's save this file.
It is also important to read the shadow as well. Um because this is used when the issue get bricked then you can recover it.
So here we read the shadow. So this is its password when we need to do the boot assistant mode and this is also its censorship word. Uh these censorship word tells the this ECU can only do the boot assist mode. The JTAG is disabled.
I'm going to later on show you how to enable the JTAG. Uh currently we just save the the shadow as well as the flash. We can also verify the uh regular we verify the entire flash. And currently we we have good read. Now I'm going to do a programming but in instead of do a full programming I'm going to uh break it. The way I break it is I'm going to erase the flash. So I'm going to click the star here and going to erase the flash.
So now it is uh it is erased and let's just trying to see if it's erased properly. We can do uh verify.
Yeah. So everything is erased. Now if I do power cycle again, power off. You can see the debugger is off now. And I'm going to power on again.
And let's see if we can read the EC info.
No, nothing happens. We can power on the USB and see if we can enter debug on.
Can't. This ECU is break into a lot of eyes and the only way you can recover it now is through the boot assist mode.
Even J-Tech will not work. Okay. So now I'm going to take off and look at the inside of the board and we are going to select the target here called um E39A.
Bam.
And let's point to the the folder this folder here. And the pin out connection is in here.
So give me some time. I'm going to do the solderings here. Wire these wires and I can show you how I connected this one to do the Buddha system mode programming.
This is the back of the ECU E39A.
And for the con canvas connection, I use the the back side of these connectors.
And I'm connecting these two pins can high and camo to the uh uniand and MCP board. Also, I connect two power 12 volt here and then the ground from here.
These pins are important for the band programming. So when I power on the ECU.
So first I power on the ECU I need to take about 10 seconds. 1 2 3 4 5 6 7 8 9 10. Then I power on the unit end.
And for the password we need to get the it from the shadow here.
And then we check the from shadow then hit detect.
Now once we enter the debug on uh we can see if we have the shadow properly uh connect we can verify shadows. Okay. Now since we already erased the entire flash I'm going to program the everything back to the original state so that we can restore this device. So here is the original flash. I just need to click this right and programming.
program finished and everything seem to work.
This is the E39A with the J-Tech pin connected. I have not modified the shadow. So I'm going to show you the JTE in this state is not going to be work.
So I connect the Unink NT uh through this connector here. I also saw this resistor here which is trying to disable the watch. So let's power on the ECU and then power on the unique MT here.
So let's go here and try to see if we can get detect on. We can't. Uh even we set the proper password we cannot detect on it. Now I am able to get this on if I'm going to the boot another boot mode but none of them will have the uh flash enabled. So you cannot read the write the flash. So I'm going to modify the uh shadow uh through the canvas and we can see how we can enable the JTAG. So now I connect the canvas here and uh the other things are everything is the same as regular canvas setup except this one.
I'm not going to waste time to remove it and it will still allow me to modify the shadows. So, I power on the ECU and connect the unit end. Let's select the regular canvas. So, this is a regular canvas.
Power it on and let's read the ECU info and get detect.
So now we are here and let's see we have the shadow here. Now I want to modify the shadow and the current configuration does not allow me to modify shadow. I need to modify the uh the configuration. So go here go to the configure folder.
So I'm going to modify the E39A E39A can. I'm going to edit this file here. The flash uh the shadow is set to one zero. I'm going to modify this to one and make it uh so restart the in NT software.
Restart it. So now if I go to shadow default is FF when this value is zero.
Default is zero. So now let me do this again and detect.
So now I read the shadow.
Now in order to enable the flash I'm going to make the 8811 to 55A.
So after modify those two values then I'm going to write the flash uh write the shadow. There's no right shadow. So I'm going to here right shadow.
Yes.
So we verify shadow. Shadow is verified.
So now read again.
And you can see the value is 55A now.
Okay. I'm going to power off power off this and remove the canvas. So there's no canvas. Now I'm going to use the Ulink NT and connect the So now the canvas is removed and I have the connected the J-Tech properly and make sure this resistor is on and I last uh I was having this loose and the J-Tech is not very stable. So now I power on the uh the ECU and then connect the uh uninkt. So let's try to see if we can get debug on. We can. And we don't even need the password here because I modified the shadow from 55A uh from 8811 to 55 AAA. So now we are in the uh debug on mode and we can get the flash. So let's do a verification verify. And you can see we can achieve about 566 uh 570k bytes of read speed. And let's do a programming. You can see it will be so much faster to do the program. So erase The programming uh only takes 32 seconds. The read only take one 5 seconds. So if you really want the JTAG method, it is possible by modifying the shadow.
Related Videos

Setting up a curved screen with Immersive Calibration Pro 4 and multiple cameras (P3D v4)
FlyerOneZero
23K views•2019-07-21

Robot Learning with Sparsity and Scarcity
allenai
379 views•2025-10-14

Jorge Mendez-Mendez: Unlocking Lifelong Robot Learning With Modularity (2023-10-05)
umassmlfl
237 views•2024-01-06

Northwestern’s MS in Robotics: Student Robotics Projects, 2023
NorthwesternEngineering
1K views•2024-05-31

"Perfect" Turns: Turning by the Gyro - FIRST LEGO League (FLL) SPIKE Prime + EV3 RePlay Programming
ZacharyTrautwein
94K views•2020-10-02

Gorkem Secer: TSLIP-based Deadbeat Running Control of Bipedal Robot ATRIAS
DynamicWalking-wv6qm
298 views•2018-06-22

Self-Driving Cars Need Lessons On Human Drivers | Maddie About Science
skunkbear
26K views•2018-08-21

Milrem Robotics’ THeMIS UGVs used in a live-fire manned-unmanned teaming exercise
MilremRobotics
99K views•2021-05-20
Trending

WOW! Judge TURNS THE TABLES on Trump in His OWN $10B LAWSUIT!!!
MeidasTouch
197K views•2026-07-23

Playstation NO DISC/NO BUY Fight Is Over...
DavidJaffeGames
4K views•2026-07-23

Steam and Xbox Just Dropped The Hammer On PlayStation
OhNoItsAlexx
9K views•2026-07-23

Americans Confused in Australia for 17 Minutes Straight
IWrocker
17K views•2026-07-23