• After 15+ years, we've made a big change: Android Forums is now Early Bird Club. Learn more here.

Root [WIP][DEV] Custom Recovery/Bootloader unlocking Work In Progress Thread

Now there's a great question.

PlayfulGod is looking at it, but he needs more info of the device in order to get it to work. He'll probably need a jtag, or someone that knows how to use a jtag.

more like I need bliss's brain!!!!!!!!! ;)
 
Well... I was going to ask him about that exploit, but he has chosen not to receive messages...


EDIT: Anyone know the memory address that the bootloader is loaded at?
 
Well I wanna flash the Verizon Loki on my phone but terminal emulator says the CD command is not found. Tried copying files to root and it says file not found. Sigh
 
Tried upper lower both. O well been sitting on floor with computer lol. Our function doesn't match any of those phones as Loki won't patch our aboot. I'm cross checking partitions I know are sig checked for matching function calls.
 
Sigh. Had alot done last night and left it open on PC when I crashed About 5am. Power went out sometime after and I didn't save :-(. Somebody with a version of Ida pro above 6.1 can have this unlocked in ten minutes....
 
Tried upper lower both. O well been sitting on floor with computer lol. Our function doesn't match any of those phones as Loki won't patch our aboot. I'm cross checking partitions I know are sig checked for matching function calls.

Yea, I talked to bliss some more today. He said the source would have to be edited to work for us.

I also asked if he would want the phone to unlock the bootloader. He said no.
 
My friend told me that his uncle has IDA pro 6.1 and that he was gonna see if he knew how to use it to unlock our phone.
He said he doubts he knows how to though, so don't get high hopes..
 
Taken from android crash report :
Qfuse check on boot: qfuse enabled=1 blowned =1
Also have partition tables for most blocks including Aboot if anyone is interested
 
Not only does our phone keep a complete log in the persist lg block of EVERYTHING our phone runs/installs and does it also apparently reports you for the following :
V/ReportCategory( 2069): Found report category suicide with value Suicide
V/ReportCategory( 2069): Found report category threatViolence with value Threat of violence
V/ReportCategory( 2069): Found report category depictionViolence with value Depictions of violence
V/ReportCategory( 2069): Found report category predatorAlert with value Predator alert
V/ReportCategory( 2069): Found report category childPorn with value Child Pornography
V/ReportCategory( 2069): Found report category sexuallyExplicit with value Sexually explicit material/nudity
V/ReportCategory( 2069): Found report category phishing with value Phishing attack/identity theft
V/ReportCategory( 2069): Found report category cyberBully with value Cyber-bullying or harassment
V/ReportCategory( 2069): Found report category underAge with value User under the age of 13
V/ReportCategory( 2069): Found report category advertising with value Spam/Fake Member
V/ReportCategory( 2069): Found report category virus with value Virus or Malware

Big brother is definitely watching.....
back on topic :
OemFlash_GetPartitionTable : 8,aboot,4a00000,38400000,80000
OemFlash_GetPartitionTable : 9,boot,5000000,3e800000,c00000
OemFlash_GetPartitionTable : 10,recovery,1c9800000,44c00000,c00000
OemFlash_GetPartitionTable : 0,tz,6000000,6400000,80000

What does wallpaper do? I think this will help get rid of it ;-)
<3>[ 3.856981] [WALLPAPER] : Cmdline: console=ttyHSL0,115200,n8 androidboot.hardware=l0 uart_console=disable lge.rev=rev_10 lcd_maker_id=secondary gpt=enable lge.batt_info=ds2704_l lge_handle_panic.hreset_enable=1 androidboot.emmc=true androidboot.serialno=10a4777e lge.signed_image=true androidboot.baseband=msm
<3>[ 3.857408] [WALLPAPER] : lge.signed_image=true
<3>[ 4.114542] [WALLPAPER] : Verify Check Module : /system/app/Videos.apk size : 2044655
<3>[ 4.170120] [WALLPAPER] : Verify check module hash : 0x00 0xDC 0x9F 0xF5 0x9C 0xE7 0xBF 0x2E 0x2B 0xCC 0xF3 0x21 0xEC 0x29 0x5D 0x72
<3>[ 4.174820] [WALLPAPER] : Verify Check Module : /system/lib/liblgdrm.so size : 1169272
<3>[ 4.208606] [WALLPAPER] : Verify check module hash : 0x81 0xB5 0xFC 0x53 0x2D 0x3D 0xC6 0x19 0x56 0x1C 0x35 0xAF 0x01 0xC5 0x35 0x77
<3>[ 4.209552] [WALLPAPER] : Verify Check Module : /system/lib/libdrmframework.so size : 92772
<3>[ 4.213917] [WALLPAPER] : Verify check module hash : 0x60 0x5F 0x44 0x66 0x82 0xCF 0xDE 0xEE 0xED 0x7A 0x47 0x24 0xAA 0x4F 0x0A 0x8A
<3>[ 4.214741] [WALLPAPER] : Verify Check Module : /system/vendor/lib/libwvm.so size : 43648
<3>[ 4.217030] [WALLPAPER] : Verify check module hash : 0x15 0x8E 0x2D 0xE0 0xE6 0x2A 0xB8 0xA5 0x4C 0x0D 0xC5 0x5B 0x58 0x40 0xDC 0xE8
<3>[ 4.217701] [WALLPAPER] : Verify Check Module : /system/vendor/lib/libwvdrm_L1.so size : 72816
<3>[ 4.220998] [WALLPAPER] : Verify check module hash : 0x37 0x29 0x92 0x2E 0x3B 0xE4 0x6F 0xDD 0x01 0xF8 0x3E 0x62 0x9D 0xF2 0x5C 0x81
<3>[ 4.221669] [WALLPAPER] : Verify Check Module : /system/vendor/lib/libWVStreamControlAPI_L1.so size : 2390172
<3>[ 4.287135] [WALLPAPER] : Verify check module hash : 0x02 0x97 0xC2 0x0C 0xE3 0xE4 0x67 0x9D 0x46 0xFB 0x05 0x49 0x7C 0x22 0x4E 0x41
<3>[ 4.288386] [WALLPAPER] : Verify Check Module : /system/vendor/lib/drm/libdrmwvmplugin.so size : 56580
<3>[ 4.291164] [WALLPAPER] : Verify check module hash : 0xDD 0x2D 0x47 0x54 0x4E 0x93 0x54 0xEB 0x76 0xDE 0xAA 0xC9 0x12 0x8A 0xAC 0xBA
<3>[ 4.291347] [WALLPAPER] : Cannot open /system/vendor/lib/libwvdrm_L3.so
<3>[ 4.291591] [WALLPAPER] : Cannot open /system/vendor/lib/libWVStreamControlAPI_L3.so

QFUSING :
<4>[ 5.651487] qfprom_secondary_hwkey_status: hwkey status=0x3
<4>[ 5.667266] qfusing_show:secondary HW key check complete!!!!!
<4>[ 5.667724] qfusing_show: 0x700310 chekc complete
<4>[ 5.667938] qfusing_show: 0x700230 chekc complete
<4>[ 5.668243] qfusing_show: 0x700220 chekc complete
<4>[ 5.668487] qfusing_show: 0x7000a8 chekc complete
<4>[ 5.668792] qfusing_show: 0x7000b0 chekc complete
 
Not only does our phone keep a complete log in the persist lg block of EVERYTHING our phone runs/installs and does it also apparently reports you for the following :
V/ReportCategory( 2069): Found report category suicide with value Suicide
V/ReportCategory( 2069): Found report category threatViolence with value Threat of violence
V/ReportCategory( 2069): Found report category depictionViolence with value Depictions of violence
V/ReportCategory( 2069): Found report category predatorAlert with value Predator alert
V/ReportCategory( 2069): Found report category childPorn with value Child Pornography
V/ReportCategory( 2069): Found report category sexuallyExplicit with value Sexually explicit material/nudity
V/ReportCategory( 2069): Found report category phishing with value Phishing attack/identity theft
V/ReportCategory( 2069): Found report category cyberBully with value Cyber-bullying or harassment
V/ReportCategory( 2069): Found report category underAge with value User under the age of 13
V/ReportCategory( 2069): Found report category advertising with value Spam/Fake Member
V/ReportCategory( 2069): Found report category virus with value Virus or Malware

Big brother is definitely watching.....
back on topic :
OemFlash_GetPartitionTable : 8,aboot,4a00000,38400000,80000
OemFlash_GetPartitionTable : 9,boot,5000000,3e800000,c00000
OemFlash_GetPartitionTable : 10,recovery,1c9800000,44c00000,c00000
OemFlash_GetPartitionTable : 0,tz,6000000,6400000,80000

What does wallpaper do? I think this will help get rid of it ;-)
<3>[ 3.856981] [WALLPAPER] : Cmdline: console=ttyHSL0,115200,n8 androidboot.hardware=l0 uart_console=disable lge.rev=rev_10 lcd_maker_id=secondary gpt=enable lge.batt_info=ds2704_l lge_handle_panic.hreset_enable=1 androidboot.emmc=true androidboot.serialno=10a4777e lge.signed_image=true androidboot.baseband=msm
<3>[ 3.857408] [WALLPAPER] : lge.signed_image=true
<3>[ 4.114542] [WALLPAPER] : Verify Check Module : /system/app/Videos.apk size : 2044655
<3>[ 4.170120] [WALLPAPER] : Verify check module hash : 0x00 0xDC 0x9F 0xF5 0x9C 0xE7 0xBF 0x2E 0x2B 0xCC 0xF3 0x21 0xEC 0x29 0x5D 0x72
<3>[ 4.174820] [WALLPAPER] : Verify Check Module : /system/lib/liblgdrm.so size : 1169272
<3>[ 4.208606] [WALLPAPER] : Verify check module hash : 0x81 0xB5 0xFC 0x53 0x2D 0x3D 0xC6 0x19 0x56 0x1C 0x35 0xAF 0x01 0xC5 0x35 0x77
<3>[ 4.209552] [WALLPAPER] : Verify Check Module : /system/lib/libdrmframework.so size : 92772
<3>[ 4.213917] [WALLPAPER] : Verify check module hash : 0x60 0x5F 0x44 0x66 0x82 0xCF 0xDE 0xEE 0xED 0x7A 0x47 0x24 0xAA 0x4F 0x0A 0x8A
<3>[ 4.214741] [WALLPAPER] : Verify Check Module : /system/vendor/lib/libwvm.so size : 43648
<3>[ 4.217030] [WALLPAPER] : Verify check module hash : 0x15 0x8E 0x2D 0xE0 0xE6 0x2A 0xB8 0xA5 0x4C 0x0D 0xC5 0x5B 0x58 0x40 0xDC 0xE8
<3>[ 4.217701] [WALLPAPER] : Verify Check Module : /system/vendor/lib/libwvdrm_L1.so size : 72816
<3>[ 4.220998] [WALLPAPER] : Verify check module hash : 0x37 0x29 0x92 0x2E 0x3B 0xE4 0x6F 0xDD 0x01 0xF8 0x3E 0x62 0x9D 0xF2 0x5C 0x81
<3>[ 4.221669] [WALLPAPER] : Verify Check Module : /system/vendor/lib/libWVStreamControlAPI_L1.so size : 2390172
<3>[ 4.287135] [WALLPAPER] : Verify check module hash : 0x02 0x97 0xC2 0x0C 0xE3 0xE4 0x67 0x9D 0x46 0xFB 0x05 0x49 0x7C 0x22 0x4E 0x41
<3>[ 4.288386] [WALLPAPER] : Verify Check Module : /system/vendor/lib/drm/libdrmwvmplugin.so size : 56580
<3>[ 4.291164] [WALLPAPER] : Verify check module hash : 0xDD 0x2D 0x47 0x54 0x4E 0x93 0x54 0xEB 0x76 0xDE 0xAA 0xC9 0x12 0x8A 0xAC 0xBA
<3>[ 4.291347] [WALLPAPER] : Cannot open /system/vendor/lib/libwvdrm_L3.so
<3>[ 4.291591] [WALLPAPER] : Cannot open /system/vendor/lib/libWVStreamControlAPI_L3.so

QFUSING :
<4>[ 5.651487] qfprom_secondary_hwkey_status: hwkey status=0x3
<4>[ 5.667266] qfusing_show:secondary HW key check complete!!!!!
<4>[ 5.667724] qfusing_show: 0x700310 chekc complete
<4>[ 5.667938] qfusing_show: 0x700230 chekc complete
<4>[ 5.668243] qfusing_show: 0x700220 chekc complete
<4>[ 5.668487] qfusing_show: 0x7000a8 chekc complete
<4>[ 5.668792] qfusing_show: 0x7000b0 chekc complete

I hopefully for your sake, that's just a list of commands.
 
Not only does our phone keep a complete log in the persist lg block of EVERYTHING our phone runs/installs and does it also apparently reports you for the following :
V/ReportCategory( 2069): Found report category suicide with value Suicide
V/ReportCategory( 2069): Found report category threatViolence with value Threat of violence
V/ReportCategory( 2069): Found report category depictionViolence with value Depictions of violence
V/ReportCategory( 2069): Found report category predatorAlert with value Predator alert
V/ReportCategory( 2069): Found report category childPorn with value Child Pornography
V/ReportCategory( 2069): Found report category sexuallyExplicit with value Sexually explicit material/nudity
V/ReportCategory( 2069): Found report category phishing with value Phishing attack/identity theft
V/ReportCategory( 2069): Found report category cyberBully with value Cyber-bullying or harassment
V/ReportCategory( 2069): Found report category underAge with value User under the age of 13
V/ReportCategory( 2069): Found report category advertising with value Spam/Fake Member
V/ReportCategory( 2069): Found report category virus with value Virus or Malware

Big brother is definitely watching.....
back on topic :
OemFlash_GetPartitionTable : 8,aboot,4a00000,38400000,80000
OemFlash_GetPartitionTable : 9,boot,5000000,3e800000,c00000
OemFlash_GetPartitionTable : 10,recovery,1c9800000,44c00000,c00000
OemFlash_GetPartitionTable : 0,tz,6000000,6400000,80000

What does wallpaper do? I think this will help get rid of it ;-)
<3>[ 3.856981] [WALLPAPER] : Cmdline: console=ttyHSL0,115200,n8 androidboot.hardware=l0 uart_console=disable lge.rev=rev_10 lcd_maker_id=secondary gpt=enable lge.batt_info=ds2704_l lge_handle_panic.hreset_enable=1 androidboot.emmc=true androidboot.serialno=10a4777e lge.signed_image=true androidboot.baseband=msm
<3>[ 3.857408] [WALLPAPER] : lge.signed_image=true
<3>[ 4.114542] [WALLPAPER] : Verify Check Module : /system/app/Videos.apk size : 2044655
<3>[ 4.170120] [WALLPAPER] : Verify check module hash : 0x00 0xDC 0x9F 0xF5 0x9C 0xE7 0xBF 0x2E 0x2B 0xCC 0xF3 0x21 0xEC 0x29 0x5D 0x72
<3>[ 4.174820] [WALLPAPER] : Verify Check Module : /system/lib/liblgdrm.so size : 1169272
<3>[ 4.208606] [WALLPAPER] : Verify check module hash : 0x81 0xB5 0xFC 0x53 0x2D 0x3D 0xC6 0x19 0x56 0x1C 0x35 0xAF 0x01 0xC5 0x35 0x77
<3>[ 4.209552] [WALLPAPER] : Verify Check Module : /system/lib/libdrmframework.so size : 92772
<3>[ 4.213917] [WALLPAPER] : Verify check module hash : 0x60 0x5F 0x44 0x66 0x82 0xCF 0xDE 0xEE 0xED 0x7A 0x47 0x24 0xAA 0x4F 0x0A 0x8A
<3>[ 4.214741] [WALLPAPER] : Verify Check Module : /system/vendor/lib/libwvm.so size : 43648
<3>[ 4.217030] [WALLPAPER] : Verify check module hash : 0x15 0x8E 0x2D 0xE0 0xE6 0x2A 0xB8 0xA5 0x4C 0x0D 0xC5 0x5B 0x58 0x40 0xDC 0xE8
<3>[ 4.217701] [WALLPAPER] : Verify Check Module : /system/vendor/lib/libwvdrm_L1.so size : 72816
<3>[ 4.220998] [WALLPAPER] : Verify check module hash : 0x37 0x29 0x92 0x2E 0x3B 0xE4 0x6F 0xDD 0x01 0xF8 0x3E 0x62 0x9D 0xF2 0x5C 0x81
<3>[ 4.221669] [WALLPAPER] : Verify Check Module : /system/vendor/lib/libWVStreamControlAPI_L1.so size : 2390172
<3>[ 4.287135] [WALLPAPER] : Verify check module hash : 0x02 0x97 0xC2 0x0C 0xE3 0xE4 0x67 0x9D 0x46 0xFB 0x05 0x49 0x7C 0x22 0x4E 0x41
<3>[ 4.288386] [WALLPAPER] : Verify Check Module : /system/vendor/lib/drm/libdrmwvmplugin.so size : 56580
<3>[ 4.291164] [WALLPAPER] : Verify check module hash : 0xDD 0x2D 0x47 0x54 0x4E 0x93 0x54 0xEB 0x76 0xDE 0xAA 0xC9 0x12 0x8A 0xAC 0xBA
<3>[ 4.291347] [WALLPAPER] : Cannot open /system/vendor/lib/libwvdrm_L3.so
<3>[ 4.291591] [WALLPAPER] : Cannot open /system/vendor/lib/libWVStreamControlAPI_L3.so

QFUSING :
<4>[ 5.651487] qfprom_secondary_hwkey_status: hwkey status=0x3
<4>[ 5.667266] qfusing_show:secondary HW key check complete!!!!!
<4>[ 5.667724] qfusing_show: 0x700310 chekc complete
<4>[ 5.667938] qfusing_show: 0x700230 chekc complete
<4>[ 5.668243] qfusing_show: 0x700220 chekc complete
<4>[ 5.668487] qfusing_show: 0x7000a8 chekc complete
<4>[ 5.668792] qfusing_show: 0x7000b0 chekc complete

Lol that does look a bit incriminating :D But yeah, err body watching. Look into the permissions granted to MetroPCS hidden menu. That thing has the clearance to snap and send photos of you. For why, who knows LOL but its there :D
 
Back
Top Bottom