Page 1 of 1

Dead PLC recovery (S7-200 SMART v2.01)

Posted: Thu Apr 11, 2019 2:18 pm
by ffstest
Hello,

Unfortunately I have a S7-200 SMART (SR40 CPU) v2.01 on a machine from China that has a dead output. I cannot read nor write to the PLC because of Level 4 protection.

Is it possible to swap the EEPROM to another working PLC (without burned output) of the same model to keep the program and parameters?


The program is level 4 protected and the manufacturer of the machine is out of business.

I hope EEPROM swap could work or is there a way to downgrade to level 3 on the SMART S7-200 v2.01? I could modify the program to use another output which is fine (unused)


Image


I have some tools for the S7-200 to decrypt bin file from EEPROM but I have S7-200 SMART (SR40 CPU) v2.01 will this work on this newer unit??


Any clues will greatly help!

Thank you very much!!!

Steve

Re: Dead PLC recovery (S7-200 SMART v2.01)

Posted: Fri Apr 12, 2019 7:32 am
by cedricliu
If you are in China,you can contact the cracker who can erase the Smart password and upload the program.
The fee is about 1800RMB.
http://www.jiemiplc.com/

Re: Dead PLC recovery (S7-200 SMART v2.01)

Posted: Fri Apr 12, 2019 12:35 pm
by ffstest
Thanks!

I guess this unit is very hard to crack.

Another question... where is the program block / parameters stored in the PLC? On the EEPROM or inside the MCU?

Re: Dead PLC recovery (S7-200 SMART v2.01)

Posted: Mon Jun 03, 2019 1:22 am
by yanzixiang
There are 3 pcb in the box,1 for cpu,1 for IO,and 1 for power,
You can just replace the IO board.