about Tizen, SDK, etc...

adfree

Senior Member
Jun 14, 2008
8,898
5,145
243
Maybe I need this info later... or maybe never... :eek:

"JTAG" ... Direct eMMC related.

SM-Z130H Pinout for Boot repair...


After clicking weired around in Internet... found this:
http://www.devicespecifications.com/de/model-cpu/8dc03501

Spreadtrum SC7727S
Code:
Samsung Galaxy V Plus	SM-G318HZ		512 MB RAM	XID
Samsung Galaxy J1 Duos	SM-J110L,SM-J110H	512 MB RAM	CHO,ZTO
Samsung Z1		SM-Z130H		768 MB RAM
After I found this:
https://postimg.cc/image/ul680l5jv/

Info was:
SM-J110H Pinout work with SM-G318HZ...

Now it seems this Pinout work also with SM-Z130H...
Maybe not all PCB Revision... but...

Best Regards
 

adfree

Senior Member
Jun 14, 2008
8,898
5,145
243
Hmmmm.

I am not smart enough to follow these Instructions with success...
https://www.youtube.com/watch?v=Bhim7F8wytA
https://www.youtube.com/watch?v=WyFdxHZi6xo

No idea, maybe Z2/Z3 ACL is little bit different to Z1?
:confused:


Meanwhile I have "updated" to ACL:
2.2.907

And added this powerfull privilege:
Code:
http://tizen.org/privilege/antivirus
:angel:

Now also Root Explorer with SQLite Editor can access more files and folders.... :cool:


2.2.907 also contains interesting APKs...
WA...
Inst...
Mess...


I would laugh, if ACL have "sooon" Come Back for WA... :D :D :D :D


Best Regards

Edit 1.

Seems I can reproduce this Trick with UC Mini and ShareIT with my Z1 and ACL 2.2.907...
I have to copy twice... no idea, after second attempt ShareIT shows Run...
 
Last edited:
  • Like
Reactions: Vikram Dattu

adfree

Senior Member
Jun 14, 2008
8,898
5,145
243
Code:
/usr/share/privilege-manager/.wrt_privilege_info.db
/usr/share/privilege-manager/.core_privilege_info.db
Maybe found something funny...

...inhouse

Best Regards
 
  • Like
Reactions: Vikram Dattu

adfree

Senior Member
Jun 14, 2008
8,898
5,145
243
Code:
http://developer.samsung.com/tizen/privilege/inhouse
This privilege sounds "mighty"... but I have no idea for what I could use it... :D :eek:
First I thought it is kind of Superuser... :eek: :eek: :eek:

It is in Calender app...

No idea what Samsung can change with it...

Later I will add description of this privilege...

Best Regards

Edit 1.
Code:
ACCESSING_RESOURCES_RESTRICTED_FOR_MANUFACTURERS_USE,THIS_APPLICATION_CAN_ACCESS_RESOURCES_RESTRICTED_FOR_USE_BY_THE_MANUFACTURERS_SUCH_AS_[B]CHANGING_THE_INTERNAL_SYSTEM_SETTINGS[/B]
:confused:
Hmmm.... what can Calender app do with this Privilege?
:confused:
Code:
...CHANGING_THE_INTERNAL_SYSTEM_SETTINGS
 
Last edited:
  • Like
Reactions: Vikram Dattu

adfree

Senior Member
Jun 14, 2008
8,898
5,145
243
Tiny progress...

I am now able to start mini-shell without SDB and USB cable. :cowboy:

Again most powerfull Privilege is "Antivirus"... :good:

Attached is little Video...


With help of Terminal App with Antivirus Privilege... I can start now mini-shell and other stuff... :angel:


mini-shell is executed also as User app... not root. :rolleyes: :eek: :eek:
BUT it seems more powerfull...

For instance I can change into folder csa:
Code:
cd csa
cd imei
cat prodcode.dat
Only as example...
Be carefully...

Now I could start to learn some Shell Script stuff... *.sh ...

Need some time... :eek:

The idea is to create few simple Scripts *.sh

And doing some easy tasks...
Copy or compress folders/files...

Best Regards
 

Attachments

adfree

Senior Member
Jun 14, 2008
8,898
5,145
243
Does that infer, that I can flash some Android ROM on my Z3?
As you know... theory and Reality. :D

1.
You have to fight against "few" Security thingies... like Bootloader sboot.bin AND Partition table... PIT.

If Bootloader SBOOT is with simple F%U.ing text string SM-Z300H you have big problems to flash other Firmware...

This is called protection. :D

2.
You bypassed Bootloader crap security... ;)

After you have killed few times your SM-Z300H... :D :D :D

You soldered wires... or bought more devices for tests and research... and/or you bought JTAG Boxes with Direct eMMC support...

then...

3.
You found device with nearly same Chipset... flashed to your SM-Z300H...
Flash success... BUT:

A.
Display is black... as Display Driver different.

:rolleyes:
You need someone who correct Display driver for you... :D

B.
You have luck... You can see Bootlogo...
But this is all... as again FF%&/.ing security

C.
You have more luck...
Z3 booted proper you see Android...
You start to touch your Display...
NOTHING happens...

Touch Driver different... :D :D :D :rolleyes: :silly:



Look here...
My jouney with GT-S8600 bada... I was able to run Android on it... :D
https://forum.xda-developers.com/showthread.php?t=2116846



As you know.
Tizen Hacking Community is similar...
Nearly 0... :crying:


Samsung ever make 10000000000000000000 devices + Variants of these devices... with same Hard + Software...

So chance is not 0 to find Android Firmware for SM-Z300H...

The magic is to find solution... or to create solution.

This require time and skills and (money)...


Money if you need to repair or you need test device etc...

Feel free to make your own experiences. :cool:


Start with similar research... like I did short for SM-Z130H:
https://forum.xda-developers.com/showpost.php?p=71322874&postcount=401


Maybe your findings are so good...
That I am able to find devices for tests in Ebay...

Maybe I could create then my "Z3" device...
And as sideeffect... maybe then Firmware identified for Z3...


But this is an long LONG time project...
MONTHS, yearS

Best Regards
 

adfree

Senior Member
Jun 14, 2008
8,898
5,145
243
SM-Z300H have Spreadtrum Chipset:
Code:
SC7730
You can find this text string in Bootloader:
Code:
sboot.bin

So it seems SM-G531F aka Galaxy Grand Prime VE is wrong... as different Spreadtrum used:
Code:
[COLOR="Red"][B]SC8830[/B][/COLOR]
If my Internet/Google research was correct... :D

But I am pretty sure... there are enough SC7730 devices from Samsung floating around...
We have only to find/identify them... :D

Need some time to find few SC7730 devices from Samsung... :rolleyes:

Best Regards


Edit 1.
Hmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmm... :rolleyes:
Maybe Variant of Galaxy Grand Prime VE with SC7730 exists... need to find exact model name...

Trying to verify with SM-G531Y... Taiwan (BRI) Version...
 
Last edited:

adfree

Senior Member
Jun 14, 2008
8,898
5,145
243
Before I was able only with SDB and USB cable...

With "Antivirus" Privilege it is possible to use these Codes also without attached USB cable... :D :angel:

Attached Example Video...

Maybe "later" I could add few more Codes...
Codes inside testmode Binary....


In theory it could work also with Key Input... But I never found how to enable this... :eek:


Instead via Keys...
Code:
*#197328640#
Simple via Command... :D

Code:
testmode *#197328640#

Best Regards
 

Attachments

  • Like
Reactions: Lrs121

adfree

Senior Member
Jun 14, 2008
8,898
5,145
243
VisualStudioToolsforTizen-preview-3.exe

dotNet Preview 3 now online.


Best Regards

Edit 1.



Self-contained Application. Appliction developers can create and install them to target devices or emulators without pre-installed .NET runtime.
This sounds very usefull...

But I don't know if this means only with Tizen 3 devices... like:
TM1, TM2, SM-Z400F...

:confused:
 
Last edited:

adfree

Senior Member
Jun 14, 2008
8,898
5,145
243
Because Tizen is still very boring... :eek:

I have flashed oldest Combination Firmware I have...
AOC1

No idea why... but the other Combination file... MD5 was wrong... so I was scared to flash... but TAR file extracted without Errors...
Anyway... valid AOC1 shows few testmode Icons...

Here in this Firmware also:
Code:
*#197328640#
Work via Key input...

su is able to call Super User... so not only this Command work:
sdb root on

profile-device.xml in home/developer not work...
As my Serial Number is not auto erased... so DUID is the old...

Only as info.

Best Regards
 

Attachments

adfree

Senior Member
Jun 14, 2008
8,898
5,145
243
I was able to flash also the second Combination Firmware... BPB1...
Both are "only" Tizen 2.3.0.0

But funny to play around... for instance with su... again...

Code:
sh-3.2# su - app
No directory, logging in with HOME=/
chown: cannot access `/dev/video0': Permission denied
chown: changing ownership of `/dev/ion': Operation not permitted
chown: changing ownership of `/dev/sprd_adie_efuse_otp': Permission denied
chown: cannot access `/dev/sprd_dma_copy': Permission denied
chown: changing ownership of `/dev/sprd_dummy_otp': Permission denied
chown: changing ownership of `/dev/sprd_efuse_otp': Permission denied
chown: changing ownership of `/dev/sprd_iommu_gsp': Permission denied
chown: changing ownership of `/dev/sprd_iommu_mm': Permission denied
chown: changing ownership of `/dev/sprd_isp': Permission denied
chown: cannot access `/dev/sprd_jpg': Permission denied
chown: cannot access `/dev/sprd_rotation': Permission denied
chown: cannot access `/dev/sprd_scale': Permission denied
chown: cannot access `/dev/sprd_sensor': Permission denied
chown: cannot access `/dev/sprd_vsp': Permission denied
chown: cannot access `/dev/stty_w12': Permission denied
-su-3.2$ whoami
app
-su-3.2$ su - root
-su-3.2# whoami
root
-su-3.2# su - developer
Cannot execute /bin/false: No such file or directory
-su-3.2# su - system
No directory, logging in with HOME=/
chown: cannot access `/dev/video0': Permission denied
chown: changing ownership of `/dev/ion': Operation not permitted
chown: changing ownership of `/dev/sprd_adie_efuse_otp': Permission denied
chown: cannot access `/dev/sprd_dma_copy': Permission denied
chown: changing ownership of `/dev/sprd_dummy_otp': Permission denied
chown: changing ownership of `/dev/sprd_efuse_otp': Permission denied
chown: changing ownership of `/dev/sprd_iommu_gsp': Permission denied
chown: changing ownership of `/dev/sprd_iommu_mm': Permission denied
chown: changing ownership of `/dev/sprd_isp': Permission denied
chown: cannot access `/dev/sprd_jpg': Permission denied
chown: cannot access `/dev/sprd_rotation': Permission denied
chown: cannot access `/dev/sprd_scale': Permission denied
chown: cannot access `/dev/sprd_sensor': Permission denied
chown: cannot access `/dev/sprd_vsp': Permission denied
chown: cannot access `/dev/stty_w12': Permission denied
-su-3.2$ whoami
system
-su-3.2$ ls
bin   csa  etc   initrd  lost+found  mnt  proc  run   sdcard  srv  tmp  var
boot  dev  home  lib     media       opt  root  sbin  smack   sys  usr
-su-3.2$ cd csa
-su-3.2$ ls
bluetooth  csc  factory  imei  lost+found
-su-3.2$ cd csc
-su: cd: csc: Permission denied
-su-3.2$
Summary...

Combination files are:
1.
For tests...

2.
Rooted... su work also in shell... user switch is easy possible...

3.
Apps are ""minimized""... removed...

For instance Tizen Store not work... similar Behavior like on Reference Devices... RD-PQ... TM1 known...

4.
All Certs for all Privilege Levels... like in Reference Devices...
Code:
Public
Partner
Platform

5.
In theory you can fire up many Shell scripts *.sh and do funny "things"... but I am scared to test them all... :D :eek:

6.
All Codes work via Keyboard input... like:
Code:
*#197328640#
In normal Firmware these action require Root... and SDB to send Command:
Code:
testmode *#197328640#
Still I have no idea how to enable Key input of these Codes... :confused: :eek:

7.
Flag files are in CSC... special 0 Byte files...

Best Regards
 
  • Like
Reactions: Lrs121

adfree

Senior Member
Jun 14, 2008
8,898
5,145
243
TV
http://www.samsung.com/n_africa/support/model/UA40J5500AWXAB?CID=AFL-hq-mul-0813-11000279

No idea if Tizen Firmware...
And no idea if it is possible to extract something for research...

Found Link in TV Forum... this sound svery funny... :D

To keep your TV rooted and/or rootable, it's absolutely necessary to NEVER do any official firmware upgrade. Even if you could think "bigger number is better", these updates never bring any new feature nor anything positive.

Furthermore, on E/F/H series you have to disable OTN support in service menu to prevent automatic online updates to be done without prior notice.
:D :good:


I also hate auto updates...

Best Regards

Edit 1.

Will take an look maybe here:
https://forum.samygo.tv/viewtopic.php?f=94&t=11570&p=99100&hilit=extract+firmware#p99100
 
Last edited:

adfree

Senior Member
Jun 14, 2008
8,898
5,145
243
Code:
NAME=Tizen
VERSION="3.0.0 (Tizen[B][COLOR="Red"]4[/COLOR][/B]/Unified)"
ID=tizen
VERSION_ID=3.0.0
PRETTY_NAME="Tizen 3.0.0 (Tizen4/Unified)"
ANSI_COLOR="0;36"
CPE_NAME="cpe:/o:tizen:tizen:3.0.0"
BUILD_ID=tizen-unified_20170411.2.20170412.171631_mobile-wayland-armv7l-[B]tm1[/B]
Is "Unified" Tizen 3... or Tizen 4... :eek: :cyclops:

I have short downloaded Uboot and Image for TM1...

Looks like dotNet support is inside...

At the moment found nothing really interesting... for me.

Best Regards