fxsheep / firehorse_land

EDL exploit for Redmi 3S
31 stars 7 forks source link

"Patching" the PBL? #3

Open userse31 opened 4 months ago

userse31 commented 4 months ago

Chnage the port number in exploit_mota_boot_release.cmd, clone EMMC contents to a good enough SDCard, insert the card and boot with exploit_mota_boot_release.cmd. This will perform a temporary 'patch' to the PBL and trick it into thinking that secureboot fuses aren't blown, which will allow it to boot an arbitrary-signed SBL1 or EDL loader.

Wait, WHAT!?

Crap, if that could be done on the Alcatel A571VL, I'm going to shit my pants!