On Thu, Feb 2, 2012 at 8:01 AM, wrote: > > I want to get access to the file system on this device, and the only way = seems to be to break the root password, and the only way I can see to do th= at is to remove the NAND chip, read its contents, and see if I can find the= password file, and work from there in dumping it to pass it through a crac= ker. However having followed this discussion I am wondering if there may po= ssibly be another way of getting into it with removing the chip. Hardware wise, it would be JTAG, so if you can find the JTAG header and hook up an adapter, you should be able to read the raw data. Of course, this is probably compressed, but if you have the image, you should be able to mount the image file on a Linux host. Is there any way to interrupt the bootloader and modify the kernel command line? You might be able to boot it in single user mode: http://www.debuntu.org/recover-root-password-single-user-mode-and-grub --=20 http://www.piclist.com PIC/SX FAQ & list archive View/change your membership options at http://mailman.mit.edu/mailman/listinfo/piclist .