Close

Analysing Device Programmers

A project log for Antique PAL reading system

Dataman device programmer and PC with LPT

keithKeith • 01/10/2026 at 18:30•0 Comments

I looked at another device programmer (the Dataman S3) and found it had microcontroller with a 8085-like core and 4K of mask-programmed ROM. It had an 8K RAM chip.  The ROM is not going to hold much code, and certainly not enough for the long list of devices it supported. I realised that the ROM is probably little more than a bootloader, loading the RAM with code for programming one type of a device at a time.

For the same reason, I expect my Dataman LV48 and many others are doing the same. 

This is very sensible, because there is very little fixed code in the programmer, and the software modules for programming devices are held in the host PC's hard drive. These can be corrected if bugs are found, or new ones added later.

I wonder if they are obfusticated at the PC end in some way, to get in the way of reverse engineers? With a bit of clever circuitry, one could read the programmer RAM to analyse the algorithms. 

It is not worth the time to completely reverse engineer this programmer, because you could earn the money to buy one in far less time. I'm only interested in how it works for the sake of curiosity, and to investigate what may be a bug in the MMI PAL14L4 reading software. For some reason it was not reading the fuses for the 3rd and 4th output pin.

To analyse the firmware, I used the command

d52 -b Dataman_U42.bin -t

 The -t tells it analyse the file, disassemble it, and generate an ASCII control file called Dataman_U42.ctl which can be edited and improved by the user. Don't use the -t option again, as it will overwrite any edits you have made and you will have to start all over again.

The ctl file contains entries like this:

t 1289-12aa    ; ASCII text

 and the disassembly contains:

    db    0f7h
    db    '"LabTool-48 Firmware Version 2.'
X12a8:    db    '00'
    db    0

Edit the ctl file to add a label:

The ctl file contains entries like this:

l 1289 text_LabTool_firmware_version
t 1289-12aa    ; ASCII text

 Then run:

d52 -b Dataman_U42.bin

NB no -t option this time!

And now the disassembly contains the new label:

db    0f7h
text_LabTool_firmware_version:
    db    '"LabTool-48 Firmware Version 2.'
X12a8:    db    '00'

There's a lot more in the online manual here:

https://www.bipom.com/documents/dis51/d52manual.html

I had a quick look through the disassembled code but it does not look simple to decipher. There is just under 16K of code. I think it might be quicker to start by analysing the printer-port traffic to get an idea of what it is doing to start with.

Discussions