Buy yourself the same device and do it on there first. If you don't know what you are doing its not fair on your client or your own reputation to do it on the original exhibit.
You do not want to flash ANY firmware in a JTAG method. You are looking to download a raw copy of the nand and deduce the hash of the password that way
↧