Страница 1 из 1

MIBSTD2 Signature

Добавлено: Сб окт 14, 2017 6:27 pm
harwin3
Hello,

Anyone know how to skip or calculate the metafile signature?
In the file tsd.mibstd2.system.swdownload in the software there is "SkipSignatureCheck = "true", will not check signature of metainfo2.txt file"

Adding SkipSignatureCheck = "true" to the metafile doesnt work.

Any idea? in IDAPRO i can see the flag but cant find out how to get it to work.

Добавлено: Вс окт 15, 2017 6:42 am
алексей 3012
I tried to modify the MetafileChecksum inside the metainfo2 file to prompt the signing error
Вложение error.jpg больше недоступно

Добавлено: Вс окт 15, 2017 12:29 pm
harwin3
the metafilechecksum is easy to calculate, but after that you need to calculate new signature and thats almost imposible.

https://reverseengineering.stackexchang ... tion/12287 here you find more info about the signature.

in the software donwload part of the firmware tsd.mibstd2.system.swdownload you find SkipSignatureCheck = "true" but adding this to metainfo doenst seem to work.

Добавлено: Ср окт 18, 2017 10:00 am
harwin3
I want to go this way https://forum.xda-developers.com/genera ... st74201158 found the emmc MTFC8GLWDQ-3M AIT Z. someone can get the datasheet of it?

Добавлено: Вт ноя 21, 2017 7:17 pm
mobista
This chip is BGA100 eMMC memory, you can read it with this: https://pl.aliexpress.com/store/product ... 62252.html or simple SD card reader when add correct voltage and connect with good pins :)

Добавлено: Ср ноя 22, 2017 10:57 am
congo
Too much effort just to see that you cant touch anything on these units :(
Thecnisat made it secure, nothing in common with harman or delphi.
Way much easy is to use special SD cards.

Добавлено: Ср ноя 22, 2017 11:10 am
mobista
harwin3 писал(а):I want to go this way https://forum.xda-developers.com/genera ... st74201158 found the emmc MTFC8GLWDQ-3M AIT Z. someone can get the datasheet of it?
Look for "EMMC LFBGA 100 pinout" - soldering is simple, with every tool developed to work with eMMC can read this memory (even simple sd card reader, but U must to add some voltage).

Добавлено: Пн дек 04, 2017 3:53 pm
FRANEK
congo писал(а):Too much effort just to see that you cant touch anything on these units :(
Thecnisat made it secure, nothing in common with harman or delphi.
Way much easy is to use special SD cards.

private keys are usefull for this unit :)

Добавлено: Вт дек 05, 2017 2:39 pm
congo
If you have them yes.

Добавлено: Ср дек 13, 2017 9:41 am
алексей 3012
MetafileChecksum Calculating is easy, it is difficult to calculate the signature, there is no good way

Добавлено: Вт май 22, 2018 1:33 pm
jvkk
How much special the SD card should be?
Any hint?

Добавлено: Пт май 25, 2018 8:45 pm
FRANEK
jvkk писал(а):How much special the SD card should be?
Any hint?

its not for production units

Добавлено: Вт окт 22, 2019 4:51 pm
chris2011
is there a way to get X devl sw on production units ?

Добавлено: Вт дек 24, 2019 11:26 pm
Crash-100
How X soft help you ?

Добавлено: Вт дек 24, 2019 11:27 pm
Crash-100
You will need patch tsd.mibstd2.system.swdownload

Добавлено: Вт дек 24, 2019 11:32 pm
chris2011
Spent already few hours with patching tsd.mibstd2.system.swdownload

But no success till now