Hello there!
I'd like to show you what I've been working on for the past 8 hours. This is a cert exploit that our device (among many others) is vulnerable to. With this exploit, we can practically modify the LK (Little Kernel) also known as the bootloader to enable/disable features with the usage of fenrir.
I have modified the bootloader string from MBM -> NIG (yes I did that intentionally, it's funny). Moreover I have disabled image authentication verification which verifies all the firmware partitions and I disabled the most annoying feature of all: Preflash validation check. With these modifications, I was able to have a custom bootloader version string, I was able to boot a custom boot logo, I was able to flash partitions in bootloader and the best part of all, I WAS ABLE TO BOOT OSS DTBO!
This is just a teaser, more info (possibly a writeup as well) to come soon™️ :)
Credits are given in the next post (due to telegram's low word limit).
Yours truly,
@cyberknight777
Post #299
12.1K

