Introducing XDA:DevCon – A Conference For Developers By Developers
XDA Developers Android and Mobile Development Forum
Forgot your password?
 
Post Reply+
Tip us?
 
Nikropht
Old
#1  
Nikropht's Avatar
Member - OP
Thanks Meter 1
Posts: 52
Join Date: Nov 2008
Location: Flower Mound, Texas
Exclamation T-Moobile G1 Nand dumped.

Some guys over in the g1-hackers list managed to code a kernel hack that allows you to dump the nand flash.

So here is the nand flash file...

http://www.2shared.com/file/4394944/b791a62e/nand.html

Have Fun!

-Nikropht
 
ecd
Old
#2  
Junior Member
Thanks Meter 0
Posts: 2
Join Date: Nov 2008
Thanks for sharing this. You are lightning fast in spreading the word...

The trick was actually simple. The linux kernel on the G1 uses the nand flash as partitioned mtd device. As partitioned device only the separate partitions are readable easily from userland. The "hack" was to double-register the whole device next to the partitions and voila we where able to dump the first pages of the nand containing the boot loader.

In case anything got corrupted on it's way here is another link to the file: http://www.mediafire.com/?akjmuueyiii
 
Nikropht
Old
#3  
Nikropht's Avatar
Member - OP
Thanks Meter 1
Posts: 52
Join Date: Nov 2008
Location: Flower Mound, Texas
Well I'm eager to facilitate hacking this device. I'm not totally in love with java and would love to see the G1 run X.

-Nikropht
 
bhang
Old
#4  
bhang's Avatar
Senior Member
Thanks Meter 3
Posts: 441
Join Date: Aug 2006
Location: megalopolis
Question the possible implications of this..?

Im no coder but I do some electronics modding (fones,tivo,consoles,smartcards,hardware hacking) but doesn't this mean that the damn thing is owned/pwned?
So now the bootloader and all the stuff that goog didnt open source is in the wild to be picked apart by the powers that be?

Im just making some assumptions and asking some questions to see just what this does for the g1 and its modding community...


bhang
http://www.geocities.com/sarabhanga/bhang.html
1 mtg3 stock
1 Moto Cliq rooted, pimped (bought opening day also)
2xHTC - DREAM - G1(1bronze,1black)
black, bought 10.22.08 opening day in the us CM6
bronze, cyanogen[out of use]
mytouch slide, bought 1st day of soft-launch, rooted running slideme5r1...for now{brand new one in box on hold for a bit
G2 pimped, many mods, screen rez, battery morphed, pershoots latest, looking to go to CM7 soon
 
Nikropht
Old
#5  
Nikropht's Avatar
Member - OP
Thanks Meter 1
Posts: 52
Join Date: Nov 2008
Location: Flower Mound, Texas
Quote:
Originally Posted by bhang View Post
Im no coder but I do some electronics modding (fones,tivo,consoles,smartcards,hardware hacking) but doesn't this mean that the damn thing is owned/pwned?
So now the bootloader and all the stuff that goog didnt open source is in the wild to be picked apart by the powers that be?

Im just making some assumptions and asking some questions to see just what this does for the g1 and its modding community...


bhang
bhang, this is the low level code that runs before the android os launches. What this does is open the door for a hack that will re-root G1's running Rev30.

-Nik
 
Nikropht
Old
#6  
Nikropht's Avatar
Member - OP
Thanks Meter 1
Posts: 52
Join Date: Nov 2008
Location: Flower Mound, Texas
I noticed something very interesting while looking at the nand dump in my hex editor...
Not only did i see some bits about factory test mode, but at i was scrolling through what seemed to bee all FF's I ran across letters, numbers and symbols made up of the absence of the FF's. This starts at 0x02466B10.

See pic attached.

-Nikropht
Attached Thumbnails
Click image for larger version

Name:	nand chars.jpg
Views:	211
Size:	100.4 KB
ID:	134824  
 
sputnik99
Old
#7  
sputnik99's Avatar
Senior Member
Thanks Meter 6
Posts: 436
Join Date: Aug 2006
so again for slowly me...

there is a chance that I got a modded RC30 even if I am on OTA RC30, now?

That are fantastic news.
 
verbraakje
Old
#8  
Junior Member
Thanks Meter 0
Posts: 20
Join Date: May 2007
Location: Roosendaal
can i make a small smile on my face ?
 
Nikropht
Old
#9  
Nikropht's Avatar
Member - OP
Thanks Meter 1
Posts: 52
Join Date: Nov 2008
Location: Flower Mound, Texas
Quote:
Originally Posted by sputnik99 View Post
so again for slowly me...

there is a chance that I got a modded RC30 even if I am on OTA RC30, now?

That are fantastic news.
OK.. we dumped the boot loader for the G1. (The most common linux boot loader is LILO)
This means that after some crazy disassembly, we could write/hack a replacement boot loader.
This would allow us unlimited access to the hardware and then we can run whatever OS the cpu can run.

-Nik
 
Falcon4ever
Old
#10  
Junior Member
Thanks Meter 0
Posts: 14
Join Date: Nov 2008
Actually there is a lot of plain text in the dump file starting from:

0x0246EE6E

 
Post Reply+
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Go to top of page...

XDA PORTAL POSTS

Boot Animation Paradise for your Android Device

The default boot animations on any device, no matter whichmanufacturer, are generally pretty … more

Flash Custom ROM and Recovery to Samsung Galaxy S 4

After reading about Dan Rosenberg’s bootloader exploit for the Samsung Galaxy S 4,I … more