5,593,401 Members 36,281 Now Online
XDA Developers Android and Mobile Development Forum

A few things on knox / rooting and bootloaders that need more testing / development

Tip us?
 
ryanbg
Old
#51  
Senior Member
Thanks Meter 362
Posts: 260
Join Date: Jan 2008
Location: Minnesota
Quote:
Originally Posted by E:V:A View Post
And where is that? (Do you know what wrote it?)



Any progress? I did something similar for the SGS3, found tons of goodies. I'd like to see what you have if anything new.
Rollback protection information isn't stored in 'actual' QFPROM, but rather the RPMB. Both on Snapdragon and Exynos devices. The warranty bit is controlled by an actual hardware fuse in the MCU, while the Exynos warranty bit is also stored in the RPMB. I believe the RPMB may serve as a shadow register for all fuses also. I'm looking into the patches and ioctl for RPMB. I was dissecting an old unsigned RPMB from a Note 3 engineering build and found an 'SSD Keystore Encryption Key' and 'SSD Auth Key' within the TrustZone blob. Note I have a 160 bit key for both in plaintext, not a .key file. I'm not exactly sure if SSD is referring to the RPMB or the NAND chip itself, but it may be possible to send authenticated messages to TZ kernel/keystore. I can explain more in-depth via gtalk. We've got several theories.
The Following 5 Users Say Thank You to ryanbg For This Useful Post: [ Click to Expand ]
 
david515
Old
#52  
david515's Avatar
Junior Member
Thanks Meter 5
Posts: 16
Join Date: May 2013
Location: Ames
Default Don't know if this helps anybody wth MJE to MI9...

Quote:
Originally Posted by ryanbg View Post
Downgrading is limited to the flag fuse counter values. On MJE, I can downgrade to MI9 boot image and recovery. I was able to downgrade to some pre-release engineering SBL1, RPM, and TZ because they're signed and fuse counter is only 1 for those 3. It's very benign and basic to downgrade. Just use heimdall and try downgrading an individual image. If I figure out what P is, I'll be able to test if I can flash anything related to that flag. For some reason, I can downgrade to MI9 boot and recovery, but not the system.img. I'm just starting to learn a lot about the flags/fuse counters after dissecting aboot further. If you've got any more specific questions, feel free to PM me
I was able to flash from MJE Modem down to MI9, but system Image still on MJE but ever thing else says MI9- ( don't know if that helps anyone)
 
ryanbg
Old
#53  
Senior Member
Thanks Meter 362
Posts: 260
Join Date: Jan 2008
Location: Minnesota
Quote:
Originally Posted by david515 View Post
I was able to flash from MJE Modem down to MI9, but system Image still on MJE but ever thing else says MI9- ( don't know if that helps anyone)
The modem actually has rollback protection, but all modems seem to be '1' value.
 
david515
Old
#54  
david515's Avatar
Junior Member
Thanks Meter 5
Posts: 16
Join Date: May 2013
Location: Ames
Default I'm planning on investing in JTAG...

Quote:
Originally Posted by ryanbg View Post
The modem actually has rollback protection, but all modems seem to be '1' value.
I may be of some better help after I get a Jtag set up hopefully this next week. Thank you everyone for your efforts. J TAG has been something I've been meaning to invest in for a while.
Tags
knox, root
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes