stacksmashing / tamarin-firmware

GNU General Public License v3.0
447 stars 52 forks source link

Amazing stuff may I ask the purpose ;)) ?? #15

Closed bbaranoff closed 1 year ago

bbaranoff commented 1 year ago

Got this

af0b11a98ee1c1b:450                                          
af0b11a98ee1c1b:103                                          
af0b11a98ee1c1b:104                                          
af0b11a98ee1c1b:105                                          
af0b11a98ee1c1b:108
af0b11a98ee1c1b:108
4fbf8fe65e3b7c6:346
4fbf8fe65e3b7c6:348
4fbf8fe65e3b7c6:348
4fbf8fe65e3b7c6:348
4fbf8fe65e3b7c6:348
4fbf8fe65e3b7c6:348
4fbf8fe65e3b7c6:348
4fbf8fe65e3b7c6:348
4fbf8fe65e3b7c6:348
4fbf8fe65e3b7c6:348                                                             
4fbf8fe65e3b7c6:1935                                                            
4fbf8fe65e3b7c6:1935                                                            
8d3ff3cd3759614:166                                                             
af714dbce4d39c3:253                                                             
e51893b627f0e6e:540                                                             
e51893b627f0e6e:544                                                             
b5255f381ca81f9:223                                                             
b5255f381ca81f9:509                                                             
b5255f381ca81f9:541                                                             
b5255f381ca81f9:549                                                             
b5255f381ca81f9:557                                                             
b5255f381ca81f9:565                                                             
b5255f381ca81f9:573                                                             
7ab90c923dae682:189                                                             
ec06a4d16c8adb1:505                                                             
ec06a4d16c8adb1:513                                                             
ec06a4d16c8adb1:426                                                             
ec06a4d16c8adb1:428                                                             
ec06a4d16c8adb1:429                                                             
ec06a4d16c8adb1:438                                                             
ec06a4d16c8adb1:440                                                             
8d3ff3cd3759614:166                                                             
image <<PTR>>: bdev <<PTR>> type illb offset 0x0 len 0x161ea6                   
image <<PTR>>: bdev <<PTR>> type logo offset 0x161ea6 len 0x4d10                
image <<PTR>>: bdev <<PTR>> type bat0 offset 0x166bb6 len 0xc9e1                
image <<PTR>>: bdev <<PTR>> type wchf offset 0x173597 len 0x5dc6                
image <<PTR>>: bdev <<PTR>> type bat1 offset 0x17935d len 0x283b                
image <<PTR>>: bdev <<PTR>> type glyP offset 0x17bb98 len 0x4a1b                
image <<PTR>>: bdev <<PTR>> type batF offset 0x1805b3 len 0x1613f               
image <<PTR>>: bdev <<PTR>> type lpw0 offset 0x1966f2 len 0x1870f               
image <<PTR>>: bdev <<PTR>> type chg0 offset 0x1aee01 len 0x44c7                
image <<PTR>>: bdev <<PTR>> type recm offset 0x1b32c8 len 0x5cb57               
image <<PTR>>: bdev <<PTR>> type dtre offset 0x20fe1f len 0xadaf                
image <<PTR>>: bdev <<PTR>> type chg1 offset 0x21abce len 0xa789                
78faf5021313e82:68                                                              
78faf5021313e82:79                                                              
e62f453327738a:149                                                              
ee37000f60f2e6c:128                                                             
e2846af5eb52553:70                                                              
e51893b627f0e6e:2341                                                            
e51893b627f0e6e:2345                                                            
ef3f753e542f4eb:75                                                              
cbd42826dac844e:113                                                             
c3bf8bce75d7900:82                                                              
c3bf8bce75d7900:114                                                             
cbd42826dac844e:103                                                             
cbd42826dac844e:104                                                             
cbd42826dac844e:105                                                             
d6ff466fdb426fd:1172                                                            
a3ca66f2d546829:510                                                             

=======================================                                         
::                                                                              
:: 🔥🌸 Microkernel iBoot for n841, Copyright 2007-2023, Apple Inc.             
::                                                                              
::      Local boot, Board 0xc (n841ap)/Rev 0xf                                  
::                                                                              
::      BUILD_TAG: iBoot-8422.122.1                                             
::                                                                              
::      BUILD_STYLE: RELEASE                                                    
::                                                                              
::      USB_SERIAL_NUMBER: SDOM:01 CPID:8020 CPRV:11 CPFM:03 SCEP:01 BDID:0C EC]
::                                                                              
=======================================                                         

9905b4edc794469:695                                                             
3974bfd3d441da3:1357                                                            
3974bfd3d441da3:1423                                                            
9905b4edc794469:695                                                             
9905b4edc794469:695                                                             
3d8efc6452c6cc3:487                                                             
3d8efc6452c6cc3:487                                                             
3d8efc6452c6cc3:487                                                             
3d8efc6452c6cc3:487                                                             
3d8efc6452c6cc3:487                                                             
3d8efc6452c6cc3:487                                                             
f6ce2cad806de9b:97                                                              
f6ce2cad806de9b:156                                                             
3d8efc6452c6cc3:860                                                             
3d8efc6452c6cc3:865                                                             
3d8efc6452c6cc3:641                                                             
3d8efc6452c6cc3:860                                                             
3d8efc6452c6cc3:865                                                             
3d8efc6452c6cc3:641                                                             
3d8efc6452c6cc3:860                                                             
3d8efc6452c6cc3:865                                                             
3d8efc6452c6cc3:641                                                             
3d8efc6452c6cc3:860                                                             
3d8efc6452c6cc3:865                                                             
3d8efc6452c6cc3:641                                                             
3d8efc6452c6cc3:860                                                             
3d8efc6452c6cc3:865                                                             
3d8efc6452c6cc3:641                                                             
3d8efc6452c6cc3:860                                                             
3d8efc6452c6cc3:865                                                             
1a618789140ad84:882                                                             
a60aa294185a059:588                                                             
a60aa294185a059:591                                                             
e51893b627f0e6e:1453                                                            
3a2af965d49e02c:123                                                             
fce311cf62f0c0e:877                                                             
712294a885c12a9:560                                                             
3bdace14b1a9a68:1358                                                            
3bdace14b1a9a68:1748                                                            
7ab90c923dae682:1142                                                            
7ab90c923dae682:142                                                             
c55cb56b9b1dfaf:203                                                             
8d3ff3cd3759614:427                                                             
8d3ff3cd3759614:439                                                             
8d3ff3cd3759614:469                                                             
8d3ff3cd3759614:481                                                             
======== End of iBoot serial output. ========  

For my XR 16.5.1 What are the possibilties now ?

CarloMara commented 1 year ago

HI Friend,

short answer is "if you know you know". Slightly longer answer is:

The point of Tamarin is to make access to this information easier, but it's doesn't do anything else aside from that. Security researchers can use Tamarin to get better logs but that's beside the point of this project.

The output you posted confirms that your Tamarin is working and doing what's expected from it.

I'll close this issue as there is nothing we can do about it

bbaranoff commented 1 year ago

logo offset 0x161ea6 len 0x4d10 Is it possible to change this since it is in clear and how ?? and will the checksum (or you;) ) be annoyed and to go further can i exec a bin of 0x410 length at address 0x161ea6 for example ? Something close to this https://github.com/lululombard/DCSD-reverse-engineering/blob/master/dump.c