Search results

  1. TristanLeBoss

    Thread Is it possible to spoof Device Update (Windows Update for Mobile)?

    Hello, I was wondering if it is possible to edit traffic between devices and Windows Update server? (Man-in-the-middle attack) We used this trick before to spoof the traffic between the Windows Insider app and the Windows Insider server. It was possible to do so using Fiddler for a short...
  2. TristanLeBoss

    Thread Download Windows 10 IOT Packages (+ Pro + UWF) from Microsoft

    Hello, If you are searching for Windows 10 IOT packages, you can download them on the Microsoft website: Windows 10 IoT Core http://www.microsoft.com/en-us/download/details.aspx?id=53898 14393.67.160804-2231.rs1_release_amd64fre_IOTCORE_PACKAGES.iso, 2.27 GB You can also download 2 other...
  3. TristanLeBoss

    Post All Windows 10 IOT / Holographic / Mobile CBS and SPKG Packages

    One more update of the databases. Now, the CBS database contains 39 187 CBS packages containing no more than 1 814 515 files and the SPK databases contains 18 960 packages containing 764 091 files.
  4. TristanLeBoss

    Post All Windows 10 IOT / Holographic / Mobile CBS and SPKG Packages

    Here is a zip package containing the "MSOptionalFeatures.xml" file for various versions of the Windows Kits for Windows Mobile 10 free builds (or retail builds). This file should be in this folder: C:\Program Files (x86)\Windows Kits\10\FMFiles\arm\ The included "MicrosoftPhoneFM.xml" file is...
  5. TristanLeBoss

    Post All Windows 10 IOT / Holographic / Mobile CBS and SPKG Packages

    Updated database files. Now feature the package base name in CBS/SPK tables. Tables containing files contained in packages now have directory name (for SPK, the placeholder $(runtime.***) have been replaced by the real directories), file name without extension, filename with extension...
  6. TristanLeBoss

    Post [ROM][Android][Stock] Alcatel One Touch Fierce XL 5054

    No, I have nothing for this phone.
  7. TristanLeBoss

    Post All Windows 10 IOT / Holographic / Mobile CBS and SPKG Packages

    I wanted to create a website with a search engine to go through all the packages but I won't have the time to do it... that's why I am sharing everything. My plan was also to extract all strings from binary files using http://split-code.com/strings2.html, extract VERSION INFO with...
  8. TristanLeBoss

    Post All Windows 10 IOT / Holographic / Mobile CBS and SPKG Packages

    BASE PACKAGE NAMES 5/5: ---------------------------------- qualcomm.qc8952.wcnssperiimage_wcnss qualcomm.qc8952.wifinotifiersrvc qualcomm.qc8952.winsecapp qualcomm.qc8952.wlan qualcomm.qc8952.wlan_caps qualcomm.qc8952.wmril qualcomm.qc8952_mtp.acsp qualcomm.qc8952_mtp.qcaud...
  9. TristanLeBoss

    Post All Windows 10 IOT / Holographic / Mobile CBS and SPKG Packages

    BASE PACKAGE NAMES 4/5: ---------------------------------- mmo.runtimecustomizations.rm-1154_15646_prodconf mmo.runtimecustomizations.rm-1154_15646_variant mmo.runtimecustomizations.rm-1154_15693_application mmo.runtimecustomizations.rm-1154_15693_gsdb...
  10. TristanLeBoss

    Post All Windows 10 IOT / Holographic / Mobile CBS and SPKG Packages

    BASE PACKAGE NAMES 3/5: ---------------------------------- mmo.runtimecustomizations.rm-1127_15173_prodconf mmo.runtimecustomizations.rm-1127_15173_variant mmo.runtimecustomizations.rm-1127_15176_application mmo.runtimecustomizations.rm-1127_15176_gsdb...
  11. TristanLeBoss

    Post All Windows 10 IOT / Holographic / Mobile CBS and SPKG Packages

    BASE PACKAGE NAMES 2/5: ---------------------------------- mmo.runtimecustomizations.rm-1104_12711_operator mmo.runtimecustomizations.rm-1104_12711_prodconf mmo.runtimecustomizations.rm-1104_12711_variant mmo.runtimecustomizations.rm-1104_12744_application...
  12. TristanLeBoss

    Post All Windows 10 IOT / Holographic / Mobile CBS and SPKG Packages

    BASE PACKAGE NAMES 1/5: ---------------------------------- acer.device_info_ap.device_info acer.qc8992.monitorreverse acer.quickguide_app.app acer.service.acersystemservice acerinc.s58.countrytablecommonfiles acerinc.s58.deviceacerphoneinfocommonfiles acerinc.s58.devicehwinfocommonfiles...
  13. TristanLeBoss

    Thread All Windows 10 IOT / Holographic / Mobile CBS and SPKG Packages

    Hello, I share with you a full dump of all CBS[RU] and SPK[GRU] packages available on http://catalog.updates.microsoft.com related to Windows 10 IOT / Holographic / Mobile. It contains URLs of 56 980 unique packages for a grand total of 223 GB (239,601,673,407 bytes). These packages are part of...
  14. TristanLeBoss

    Post [ROM][Android][Stock] Alcatel One Touch Fierce XL 5054

    I have just one ROM for 5056O. I have no idea if its a ROM for retail phones or for production devices but it may still be better than a logo ;)
  15. TristanLeBoss

    Post Rooting Idol4 is possible !!!!

    What are the "Build Number" of 6070 (Idol 4S) and 6055U (Idol 4 Cricket)? Found in "Settings" > "About Phone"
  16. TristanLeBoss

    Post Alcatel 5055w and Android

    Some time ago I uploaded stock ROMs for the 5054N (the Android version of the 5055W): http://forum.xda-developers.com/android/general/rom-alcatel-one-touch-fierce-xl-5054-t3385169 You may want to try them. I have no guarantee on the result: I don't think the flasher will allow you to flash. If...
  17. TristanLeBoss

    Post Alcatel 5055w and Android

    Some time ago I uploaded stock ROMs for the 5054N (the Android version of the 5055W): http://forum.xda-developers.com/android/general/rom-alcatel-one-touch-fierce-xl-5054-t3385169 You may want to try them. I have no guarantee on the result: I don't think the flasher will allow you to flash. If...
  18. TristanLeBoss

    Post Full analysis of Xiaomi Mi4 Windows Mobile 10 ROM

    You figured them :D 1) Ability to disable Secure Boot or to boot an untrusted boot loader 2) Ability to flash in 9008 mode 2a) A file to flash to restore the original OS 2b) Sahara programmer to restore GPT & need boot partitions (MPRGXXXX.hex & XXXX_msimage.mbn) in case we soft brick it 2b)...
  19. TristanLeBoss

    Post Create rawprogram0.xml from FFU file and extract partition as raw file

    Indeed, experimenting with Windows 10 should be done on a phone that you can recover from soft brick. At least, we learned something about Windows Mobile 10. I shared the discoveries in another thread ;)
  20. TristanLeBoss

    Post Create rawprogram0.xml from FFU file and extract partition as raw file

    The phone is soft-bricked: it fails to boot and fallback to the 9008 mode. LG/Google can easily reload the system on it because they have the needed files. But without the MPRG8992.hex and 8992_msimage.mbn files, I don't think we can to recover the phone. Maybe JTAG can come to help but "Nexus...
  21. TristanLeBoss

    Post Full analysis of Xiaomi Mi4 Windows Mobile 10 ROM

    katsuga & iamsubhranil Windows Mobile 10 can theoretically work on all ARM phones. But that's the theory... For example, Secure Boot will be a problem because if the bootloader of your phone is not signed by your manufacturer, your phone won't boot. Some phones like the Google Nexus offer a...
  22. TristanLeBoss

    Post Full analysis of Xiaomi Mi4 Windows Mobile 10 ROM

    Yes, I know you can flip from Android and Windows Mobile as you wish ;) I shared these information to understand how they ported Windows Mobile to an Android phone: it seems you need to keep some partition.
  23. TristanLeBoss

    Post Full analysis of Xiaomi Mi4 Windows Mobile 10 ROM

    Regarding the Firehose flasher: ".\prog_emmc_firehose_8974.mbn" is a SBL (Secondary Boot Loader) file with a 80 bytes header The file is not signed (no signature and no certificate chain). Codeword[4]: d1dc4b84 Magic[4]: 3410d773 Image ID[4]: 0d000000 Reserved 1[4]: ffffffff Reserved 2[4]...
  24. TristanLeBoss

    Post Full analysis of Xiaomi Mi4 Windows Mobile 10 ROM

    Regarding the FFU file itself (10586.1102.3063.Retail.FFU): the image embedded catalog is not signed. I attached it to this post. I also attached the extracted hash table. Indeed, the cat file only contains a SHA1 of the hashtable: it's enough to ensure the data is fine. All the informations...
  25. TristanLeBoss

    Thread Full analysis of Xiaomi Mi4 Windows Mobile 10 ROM

    I have done an extended analysis of the FFU file of Windows Mobile 10 for Xiaomi Mi4. The partition layout is not the same from Android and Windows Phone. But, some partitions have the same starting LBA, ending LBA and size so they are at the same location and have the same size in both...
  26. TristanLeBoss

    Post Create rawprogram0.xml from FFU file and extract partition as raw file

    Yes, the 2 methods from this page: https://boycracked.com/2015/06/03/unbrick-lenovo-a6000/ QFIL will give you a log file (Right click in the "Status" part of the window and "Save log"), post them here. Here is a ZIP file with 5 flashers.
  27. TristanLeBoss

    Post Create rawprogram0.xml from FFU file and extract partition as raw file

    Ok, I created a rawprogram0.xml using the TOT file and the files from the bootloader.img (part of the Google packages). Unzip and put the TOT file (LGH791AT-00-V10f-NXS-XXX-OCT-03-2015-32G-MDA89E-US.tot) from the other thread in the same folder. There is also a simpler version which only uses...
  28. TristanLeBoss

    Post Create rawprogram0.xml from FFU file and extract partition as raw file

    Can you try this tool and see if the "Restore/Upgrade/Download" option works? http://www.wugfresh.com/nrt/ To be sure the programmer doesn't work, you can try to use these tools (and especially QFIL from Qualcomm; the method #2): https://boycracked.com/2015/06/03/unbrick-lenovo-a6000/...
  29. TristanLeBoss

    Post Create rawprogram0.xml from FFU file and extract partition as raw file

    Can you try these commands: emmcdl -p COM1 -gpt Dump the GPT from the connected device so we can check if the GPT is intact and has not been damaged. emmcdl -p COM1 -f prog_emmc_firehose_8994_lite.mbn -d SBL1 -o SBL1_from_Phone.bin Dump the SBL1 partition from the connected device so we can...
  30. TristanLeBoss

    Post Create rawprogram0.xml from FFU file and extract partition as raw file

    Yes, the FFU is just one type of container (TOT is another one). But we can of course create a GPT + BIN files to flash with a rawprogram0.xml. or fastboot... Actually, it depends on how we can flash something on the Nexus 5x... :D
  31. TristanLeBoss

    Post Create rawprogram0.xml from FFU file and extract partition as raw file

    I'm also done identifying each partition: "SBL1" is a SBL (Secondary Boot Loader) file with a 80 bytes header Codeword[4]: d1dc4b84 Magic[4]: 3410d773 Image ID[4]: 15000000 (SBL1_IMG) Reserved 1[4]: ffffffff Reserved 2[4]: ffffffff Image source[4]: 50000000 Image destination pointer[4]...
  32. TristanLeBoss

    Post Create rawprogram0.xml from FFU file and extract partition as raw file

    Flashing the Noki Lumia 950XL FFU as-is to another phone will probably not work: we need to craft a special FFU (or a GPT + bin files) which allows to preserve (DDR, SSD, MODEM_FS1 ("modemst1" on Android), MODEM_FSG ("fsg" on Android), PERSIST) from Android.
  33. TristanLeBoss

    Post Create rawprogram0.xml from FFU file and extract partition as raw file

    Ok, here are the final findings: the partition layout is not the same from Android and Windows Phone. But, some partitions have the same starting LBA, ending LBA and size so they are at the same location and have the same size in both partition layouts. Because the FFU doesn't contain data block...
  34. TristanLeBoss

    Post Create rawprogram0.xml from FFU file and extract partition as raw file

    Xiaomi Mi4 FFU file partitions : Out of the 19 partitions which contains data in the FFU, 6 of them are empty partitions (the data in the FFU is only zeroes). We end up with 13 partitions really containing data. "SBL1" is a Qualcomm Secure Boot file -> "UEFI_BS_NV" is an empty partition ->...
  35. TristanLeBoss

    Post Create rawprogram0.xml from FFU file and extract partition as raw file

    This file exactly match the one from the TOT file. The bootloader.img already contains 11 of these partitions; probably the most important ones.
  36. TristanLeBoss

    Post Create rawprogram0.xml from FFU file and extract partition as raw file

    There is another method using another LG program: http://forum.xda-developers.com/showpost.php?p=63969457&postcount=10 You may also want to try the MiFlash tool which is able to work with 9008 mode... I downloaded all stock images from the Goole page and extracted them all to discover there...
  37. TristanLeBoss

    Post Create rawprogram0.xml from FFU file and extract partition as raw file

    Hum,. the TOT file doesn't contains the SBL1 partition. It only contains 4 partitions: modem, boot, recovery, system. It's probably more an update package :( I found factory images of Google Nexus here: https://developers.google.com/android/nexus/images#bullhead Does any of the versions...
  38. TristanLeBoss

    Post Create rawprogram0.xml from FFU file and extract partition as raw file

    I will exact the SBL1 partition from the TOT file found on the LG UP thread for the H791 32GB. Then, you can always try to reflash to the phone using 9008 mode and the 8992 flasher. This way we will quickly now if the programmer works or not ;) Didn't you get an error message when you first send...
  39. TristanLeBoss

    Post Create rawprogram0.xml from FFU file and extract partition as raw file

    The rawprogram0.xml file contains the information about the GPT. You need to look for the "<program" line who has " start_sector="0"". It's more likely to be at the end of the XML file. <program SECTOR_SIZE_IN_BYTES="512" file_sector_offset="3484160" filename="10586.1102.3063.Retail.FFU"...
  40. TristanLeBoss

    Post Create rawprogram0.xml from FFU file and extract partition as raw file

    I just posted a request for the original partition layout of a Xiaomi Mi4 LTE with stock Android ROM: http://forum.xda-developers.com/mi-4/help/request-partition-table-stock-xiaomi-t3388882 I just want to be sure we are going in the right direction but I think we do ;) Regarding the...
  41. TristanLeBoss

    Thread [Request] Partition table of a stock Xiaomi Mi4 LTE (4G)

    Hello, I'm searching for a partition table dump of a stock Android ROM on a Xiaomi Mi4 LTE (4G). I just need starting LBA, end LBA and partition name. Thanks a lot for your collaboration ;)
  42. TristanLeBoss

    Post Create rawprogram0.xml from FFU file and extract partition as raw file

    You should be able to revive the phone with the tool I posted earlier: LG UP http://forum.xda-developers.com/nexus-5x/help/req-help-to-unbrick-t3251740 How did you do to upload the sbl1? "emmcdl -dumpffu flash.ffu sbl1 -o "bins/"" then "emmcdl -p sbl1 "bins/sbl1.bin""? Which flash programmer...
  43. TristanLeBoss

    Post Create rawprogram0.xml from FFU file and extract partition as raw file

    Here is the partition layout from the Xiaomi Mi4 FFU. The ones with a "->" in front of their names are the ones which are untouched. I will try to grab the GPT from the Android version of the Xiaomi Mi4 to confront my hypothesis...
  44. TristanLeBoss

    Post Create rawprogram0.xml from FFU file and extract partition as raw file

    Okay, my FFU reading tool is now complete. I can read the FFU, locate the GPT, read the GPT and extract untrimmed version of each partition. I used it against the Xiaomi Mi4 ROM and discovered something interesting: the partition table contains 33 partitions but the FFU only contains data for...