Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

MT6789 boot rom #932

Closed
Mavigsm opened this issue Feb 24, 2024 · 14 comments
Closed

MT6789 boot rom #932

Mavigsm opened this issue Feb 24, 2024 · 14 comments

Comments

@Mavigsm
Copy link

Mavigsm commented Feb 24, 2024

brom_v6_1208.zip

@Shakib-BD
Copy link

Wow. we still can hope for MT6789 . Thanks #758

@bkerler bkerler closed this as completed Feb 25, 2024
@Mavigsm
Copy link
Author

Mavigsm commented Feb 25, 2024

I managed to get a bootrom backup. but it is not like the previous bootroms. This is an exploit from bootrom, only @bkerler can fix it

@hopez13
Copy link

hopez13 commented Feb 25, 2024

from which device you extracted it?

@Mavigsm
Copy link
Author

Mavigsm commented Feb 26, 2024

from which device you extracted it?

Xiaomi Poco M5 (rock)

@rijp
Copy link
Contributor

rijp commented Apr 10, 2024

I managed to get a bootrom backup. but it is not like the previous bootroms. This is an exploit from bootrom, only @bkerler can fix it

Good work! I am researching brom_v6 on RMX3630 now. Can you send how to get brom dump on V6 devices? Probably, there are
similar vulnerabilities that can be exploited in brom mode, like CVE-2024-20042. If I can do it, a new fix from me.

@hopez13
Copy link

hopez13 commented Apr 10, 2024

@bkerler please check this and also please reopen this issue and #758

@hopez13
Copy link

hopez13 commented Apr 10, 2024

MT6789 is affected by these recent ones
CVE-2023-20819 ( EoP CDMA PPP )
CVE-2023-32823 ( EoP rpmb )
CVE-2023-32824 ( EoP rpmb )
CVE-2023-32834 ( EoP secmem )
CVE-2023-32853 ( EoP rpmb )
CVE-2023-32859 (EoP meta )
CVE-2023-32874 (RCE Modem IMS )

CVE-2024-20005 ( EoP da )
CVE-2024-20022 ( EoP lk )
CVE-2024-20032 ( EoP aee )
CVE-2024-20033 ( ID nvram )
CVE-2024-20037 ( EoP pq )
CVE-2024-20038 ( ID pq )
CVE-2024-20039 ( RCE modem )
CVE-2024-20040 ( EoP wlan firmware)
CVE-2024-20041 ( ID da )
there's are many EoP in DA but MT6789 is not affected by all as per MTK security Bulletins

this is not exhaustive list but I think these are more relevant

@bkerler

@hopez13
Copy link

hopez13 commented Apr 10, 2024

@bkerler
Copy link
Owner

bkerler commented Apr 10, 2024

None of these affects the bootrom nor da1. Da2 is useless without da1 signed loaders which aren't available.

@hopez13
Copy link

hopez13 commented Apr 17, 2024

@bkerler any luck with mt6789 brom dump?

this tool might be helpful in detection of CWE-787 etc
https://github.com/fkie-cad/cwe_checker

@hopez13
Copy link

hopez13 commented Apr 19, 2024

from which device you extracted it?

Xiaomi Poco M5 (rock)

i have same device but it's not possible to extract bootrom from it as it has SLA DAA SBC etc all enabled I want to understand the process you followed to extract it !!!

@hopez13
Copy link

hopez13 commented Apr 19, 2024

@bkerler bro atleast please can you share Brom dump if you have extracted it from your GIGASET GX4

@Shakib-BD
Copy link

Shakib-BD commented Apr 21, 2024

@bkerler bro atleast please can you share Brom dump if you have extracted it from your GIGASET GX4

We almost succeeded to made an engineering rom for our device Poco M5 & Redmi 11 Prime 4G (Rock). Now we can unbrick our device without mi auth. But, we have to flash patched preloader.bin ‘including some other images/files’ before brick our device. (We made a script for it). It's still in experimental conditions, not public yet. #757

@hopez13
Copy link

hopez13 commented May 20, 2024

CVE-2024-20056 ( EoP preloader ) affects Mt6789

@bkerler can it be helpful in dumping brom

check here for more https://github.com/advisories?query=preloader+mediatek

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants