Post Reply
Smile

[Q] NEC Medias W N-05E root? (dual screen phone)

12th January 2014, 03:23 PM   |  #1  
OP Junior Member
Thanks Meter: 0
 
3 posts
Join Date:Joined: Jan 2014
Hi!

Is there a root available or in the works for the dual-screen NEC Medias W N-05E?

The question has been asked (no answer so far) at the end of a thread under the N-05D but that's a quite different model.
I'd like to create a separate thread for this model to give it more visibility. Hope that's ok!

Thanks in advance!
12th January 2014, 04:22 PM   |  #2  
OP Junior Member
Thanks Meter: 0
 
3 posts
Join Date:Joined: Jan 2014
Talking
Quote:
Originally Posted by bohemianRhapsody

Hi!

Is there a root available or in the works for the dual-screen NEC Medias W N-05E?

The question has been asked (no answer so far) at the end of a thread under the N-05D but that's a quite different model.
I'd like to create a separate thread for this model to give it more visibility. Hope that's ok!

Thanks in advance!

OK! I've made some progress on this: the japanese blogger "dupondroid" appears to say that run_root_shell (hosted at github)
successfully gives temp root. At least, that's my necessarily blurry understanding via google translate. Would any japanese readers here be able to post a better translation?

And a thread at r-2ch dot com links to the github commit in run_root_shell which made that possible: it's commit ID 811be8639aed64c158798a72a1d520a4d21e8b8b "Support N-05E"

Code:
+  { "N-05E",  "A1000311",    0xc0094430, 0xc0093ebc }
So it definitely seems temp root is possible.
Sorry for the lack of links but I'm a new user so can't add them for now.
13th January 2014, 01:53 PM   |  #3  
Junior Member
Thanks Meter: 0
 
1 posts
Join Date:Joined: Jan 2014
root is easy
Quote:
Originally Posted by bohemianRhapsody

OK! I've made some progress on this: the japanese blogger "dupondroid" appears to say that run_root_shell (hosted at github)
successfully gives temp root. At least, that's my necessarily blurry understanding via google translate. Would any japanese readers here be able to post a better translation?

And a thread at r-2ch dot com links to the github commit in run_root_shell which made that possible: it's commit ID 811be8639aed64c158798a72a1d520a4d21e8b8b "Support N-05E"

Code:
+  { "N-05E",  "A1000311",    0xc0094430, 0xc0093ebc }
So it definitely seems temp root is possible.
Sorry for the lack of links but I'm a new user so can't add them for now.

root is easy via a tool called impactor.

however it's only temporary, I couldn't get /system mounted for rw. so I made a new recovery image to push.
that didn't work either, although I cannot write to recovery there is no error. recoverybkp was successful.

Also I found that the code to enter in recovery mode is based on your imei.
If I remember correctly digit 2,12,13,14 of your imei.

So possible attack vectors are:
1) kernel module to unlock partitions
2) figure out how update.dat files are constructed.
3) write to recovery partition
Post Reply Subscribe to Thread
Previous Thread Next Thread
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Top Threads in Questions and Answers by ThreadRank