Philips Android TV

Search This thread

brigidino

Senior Member
Oct 17, 2017
93
12
No I did not on my PUS6551/12 and also I feel that it's weird there is no microphone at least on the remote to make some voice searches on Youtube for instance.

Yes it is a bit freaky, but for istance sony do the same as philips, they has some remote with mic, the other one use the app. I tried with mine and google now is working nicely, huts wait now the assistant
 

nineoneone24

Member
Apr 19, 2011
40
3

Attachments

  • DSC_0104.jpg
    DSC_0104.jpg
    242.4 KB · Views: 304
  • Like
Reactions: thefiqs

brigidino

Senior Member
Oct 17, 2017
93
12
Hi guys i have a question

It's me i come frome the stone age or with android 7 google had enabled the mouse again?

Because after the upgrade to R2 i start again to attack skygo, then i first tried to connect a usb mouse and i notice that it is working perfectly, and then i have installed skygo succesfully.

I never tried before because i always read everywhere that with android 5 google had disabled all mouse features.
Does mouse is working for you also?
 

anddi

Member
Oct 17, 2013
19
7
49PUS7150/12 R2 Upgrade

Hello everyone, I'd like to share my experiences so far. I live in Finland and have 49PUS7150/12, I noticed from Philips support forums and XDA that they have started to offer hardware upgrades. I've had lots of black screen issues etc. so I put in a service request for my TV. They finally replied today and told me they can indeed do a motherboard swap for this model and following things would change:

- The service will replace the motherboard from 2016 Android TV
- The Android will update from 5 to 6 (and 7 in the future)
- USB ports will update from 2.0 to 3.0
- HDMI ports 3 and 4 will downgrade from 2.0 to 1.4, but two HDMI 2.0 will remain anyhow
- TV model number will have R2 -suffix
- Memory will go from 16 Gb to 8 Gb
- Comes with IR remote instead of Bluetooth

They also mentioned some models will lose 3D, Twin Tuner and will only have one CAM port instead of two.

AFAIK this model will still have Passive 3D after R2 -upgrade, is this correct? Also does anyone have experience with these IR remotes, how are they? Does EasyLink/HDMI-CEC still work? Also I understood HDR will be working after the upgrade?

I am very happy with the Philips customer service so far. I cant wait to get the motherboard swapped, as this TV has had its issues & has been very slow to use and I have read that after the R2 upgrade it will be much faster.
 

admiro

Member
Dec 10, 2010
8
2
- The service will replace the motherboard from 2016 Android TV
- The Android will update from 5 to 6 (and 7 in the future)
- USB ports will update from 2.0 to 3.0
- HDMI ports 3 and 4 will downgrade from 2.0 to 1.4, but two HDMI 2.0 will remain anyhow
- TV model number will have R2 -suffix
- Memory will go from 16 Gb to 8 Gb
- Comes with IR remote instead of Bluetooth

They also mentioned some models will lose 3D, Twin Tuner and will only have one CAM port instead of two.

AFAIK this model will still have Passive 3D after R2 -upgrade, is this correct? Also does anyone have experience with these IR remotes, how are they? Does EasyLink/HDMI-CEC still work? Also I understood HDR will be working after the upgrade?
.

7150R2 upgrade:
- PUS6401 Mother board (QM163e)
- There's Android 7 already
- i think that there's one USB 3.0 port, but poorly powered. The rest is 2.0.
- IR remote, so much better that old one, fast, you don't have to point TV.
- Passive 3D still works
- 7150 had one tuner and one CAM port, nothing changes
- HDR is working
- most import, TV is finally working great!
 

anddi

Member
Oct 17, 2013
19
7
7150R2 upgrade:
- PUS6401 Mother board (QM163e)
- There's Android 7 already
- i think that there's one USB 3.0 port, but poorly powered. The rest is 2.0.
- IR remote, so much better that old one, fast, you don't have to point TV.
- Passive 3D still works
- 7150 had one tuner and one CAM port, nothing changes
- HDR is working
- most import, TV is finally working great!

Thank you for the reply! All of this sounds great, really cant wait to get the mobo swapped! Yes almost two years later finally it'll be working great :)
 

mms99099

Member
Mar 17, 2010
45
2
set option code (display code) for 55pus6401

could somebody help me, I couldnt find my set option code (display code) for 55pus6401/12, its in the back side sticker, I don't need the serial just the code, please help

SerialNumber.jpg
 
Last edited:

GiorgioVa

New member
Jan 28, 2018
4
0
55PUS7100/R2, upgrade from 55PUS7100/12
QM163E_U_0.15.251.1
My TV is just come back from customer service, after the hardware upgrade from 55PUS7100/12.
I have these problems (probably related problems).
Awakening from standby, always try to start, but after 10/15 seconds performs a cold boot (Philips Logo and after that again Philips Logo & Android Logo).
At 4:00 and at 6:00 it has a spontaneous awakening, starting displaying a TV channel.
Maybe there are two tasks starting at those time; wake up bring to a cold boot; cold boots means start TV displaying a channel.
I tried to completely reinstall TV, but nothing change. And just to sleep during the night I have to unplug TV power supply cable.
Somebody can help me?
Could be any missing operation of customer service performing the upgrade?
 

blop135

Senior Member
May 17, 2013
333
54
Toulouse
I bought à Google home mini this weekend and you can’t turn on and off the TV cause it’s not compatible with Android TV but works with Chromecast come on Google seriously?!!!
Also you can’t launch Netflix with it :(
 

Top Liked Posts

  • There are no posts matching your filters.
  • 13
    Guys! To disable Philips Collections bar or also known as Philips Apps Tray at top of Android TV leanback launcher. All you have to do is find leanbackcustomizer in System Apps or Running Apps and turn off its notifications which can be turned off at button of the menu when you click on the service.

    I couldn't find a single source which mentioned these steps to take to disable Philips bloatware. I figured these out on own. I am not aware of any other methods that has the same results.

    Enjoy your less of a pain Android TV by Philips

    Hope this helps.

    ---------- Post added at 02:03 AM ---------- Previous post was at 01:56 AM ----------

    To disable recommendations, disable org.droidtv.nett_launcherapp in system apps or running apps. Hope this also helps debloat your Philips Android TV to a manageable level. However, this doesn't get rid of the recommendations field only apps that shows up.
    11
    firmware decryption + rooting attempts

    #################################
    WARNING: don't look at the following information nor try to use any of it if you have no clue about linux or android as it is most likely that you are going to break your expensive gadget. For every one else: don't blame philips if you brick your device -> think before actually trying. If you post about vulnerabilities and stuff better cover your ass - who knows what the legal department of philips thinks about your cool stuff.
    #################################

    So as you decided to ignore my warning, here we go:

    I already spent plenty of time researching the internals of the device in order to get root privileges. Unluckily without the final breakthrough - but at least I found out some very interesting details.

    You might ask what those extended privileges should be good for? Well in my eyes android - a project available as open source with uncountable possibilities for developers and users - should not be closed down by profit oriented manufacturers. As those are often forcing the users into their own "crappy" software without given them any chance to escape. I like to develop at system base, use the underlying linux tools and most important check what the manufacturer does (behind my back) in my own living room. Hell I bought this expensive device and have no idea and can't nearly control what is sent to Philips nor Google.

    1. I wrote a tool to decrypt the official firmware. It was created via reverse-engineering the "upgrade.bin" arm-file (thanks for the trace, snoerenberg).

    Some interesting details about the used cryptography:
    - openssl library functions
    - used algorithm: aes-256 in CBC mode
    - the encryption key is generated via "EVP_BytesToKey" using only the first 127 byte of the keyfile + an eight byte salt found near the beginning of every input file

    Source-Code: attachment or pastebin_com / z3nA2r3J
    maybe mirroring this paste and the source would be a good idea (Google for the HASH if link is down)

    The decrypted firmware archive contains the following files:

    boot.img.zip: kernel + initrd + ramdisk (unknown file format)
    bootloader.zip: bootloader (unknown file format)
    tzk_normal.img.zip: ? maybe recovery (unknown file format)

    user_setting.zip: content of /user_setting
    system.img.zip: content of /system (ext4-img)
    firmware.img.zip: content of /firmware (ext4-img)

    BackEndBin.zip, EdidBin.zip, fpgaUhdBin.zip, RougeBin.zip: different binary files - supposedly firmware for these components

    As you see I was not able to extract the most interesting part (kernel + ramdisk) - Hopefully some android experts could help!

    The current and some older firmware files could be downloaded at philips_samipupu_com (thanks for hosting)

    2. General information:
    - Kernel version: Linux version 3.4.70+ ([email protected]) (gcc version 4.6.x-google 20120106 (prerelease) (GCC) ) #1 SMP PREEMPT Fri Nov 14 01:52:21 IST 2014
    - Kernel cmd-line: androidboot.hardware=AND1E quiet lpj=11935744 root=/dev/ram0 androidboot.console=ttyS0 console=ttyS0,115200 init=/init vmalloc=448M quiet macaddr=00:00:00:00:00:00 emmc_ts.dev_id=1 emmc_ts.size=16777216 emmc_ts.erasesize=524288 emmc_ts.writesize=512
    - lsmod:
    usb8797 359014 3 - Live 0x00000000
    usb97mlan 290809 1 usb8797, Live 0x00000000 (P)
    mbtusbchar 52685 0 - Live 0x00000000
    usbfwdnld 8530 0 - Live 0x00000000
    fusion 96777 0 - Live 0x00000000 (O)
    tpvinput 7132 2 - Live 0x00000000 (O)
    trcext 333860 0 - Live 0x00000000 (O)
    gal3d 161434 16 - Live 0x00000000
    amp_core 72528 2 - Live 0x00000000 (O)
    tzlogger 1199 0 - Live 0x00000000 (O)
    tzd 32013 30 amp_core,tzlogger, Live 0x00000000 (O)

    3. The trcext module seems to be very interesting as a short look with a disassembler revealed that it might be able to read and manipulate process memory of any process. Maybe someone good at kernel-drivers could take a look?

    4. There are two world-readable directories containing very interesting information:
    - /data/debugdump: stack-traces, process-lists, short memory excerpts based on crashes of the native binaries (could be very helpful for exploiting)
    - /data/anr: davlik crash-dumps of android applications

    5. There are 3 SGUID and 1 SUID binaries (visible):
    -rwxr-s--- root inet 5500 netcfg
    -rwxr-sr-x root net_raw 26072 ping
    -rwsr-s--- root shell 9464 run-as

    6. The recovery menu which could be used to install a "new" firmware if the device does not boot properly could be reached via the following steps:
    - unplug the power
    - press and hold the joypad on the backside of the TV downwards
    - replug
    - release the joypad after 10 sec

    7. There is a Customer-Service-Menu at “123654” which contains read only information about the current firmware and so one. However there is also the real service menu (062?96i) which could be used for much more things. But you need to be really careful with this, i already managed to break booting without changing something important.

    8. The settings-app calls the "su" command inside of CSMActivity. If this is no obsolete debug code (i was not able to trigger this part yet) than there could be a "su" inside /sbin. The Manifest also shows this strange "org.droidtv.tv.tv_power_system_access" permission. Therefore i tried to write my own app with the same permission and call "su" which did however not work out (even if I use the same namespace org.droidtv.?)

    9. Every time you pop in an usb stick android creates an backup folder on it. The filenames are "hidden" via base64 and there are some junk bytes at the beginning of the files which you need to crop in order to read them. However the content is quite boring mostly some sqlite3 databases with configuration parameters.

    10. By default the usb sticks you plug in is read-only for user apps. However there is in option in the settings to re-format it. This will result in an XFS formatted, read-write mounted stick where you could even outsource your apps.

    11. There is a soap (http) service running on port 1925 which is used by the philips remote app and allows different things for example starting one of the installed apps. More details could be found if you decompile the XTV-App.


    Hope some of you guys could do something fancy with those information.
    @snoerenberg(xda): did you manage to send commands over your cable yet - If you do rooting should be quite easy from this point (maybe /system/bin/run-as).

    Cheers,
    5003b4d49cbf7916123271b7b1918f123cca0c09bf1428f4398257751ac6570c

    ps: some of the information were dumped on an older firmware and some with the current one
    10
    Steps for install any APK in 2014 Philips Android TV AND1E

    Hello,

    For install any application in 2014 Philips Android TV AND1E :

    1º You must download "Developer Settings" from "Google Play" and enable "Usb Debugging" in "Developer options".
    2º Connect ADB via WIFI -> adb start-server" , adb connect IP:5555
    3º Install APK -> adb install "app.apk" (download apk from google play with evozzi apk downloader in web or in chrome extension)

    I've tried it in 55PUS8909 and it works!.

    I've tried for root framaroot, towelroot and vroot and exploits not run.
    I've tried all for "Unknown Sources" and nothing.

    sorry for my english....thanks, regards!
    8
    [GUIDE] How to root 2015 Philips Android TV

    [GUIDE] How to root 2015 Philips Android TV moved to separate thread here

    Please vote regardless you were successful with rooting or not...