Badcaps.net Forum
Go Back   Badcaps Forums > Troubleshooting Hardware & Devices and Electronics Theory > Troubleshooting Laptops, Portable, and Mobile Devices
Register FAQ Calendar Search Today's Posts Mark Forums Read

 
Thread Tools Display Modes
Old 10-20-2019, 06:03 AM   #1
kiknusko
kiknusko
 
Join Date: Jan 2019
City & State: Bratislava
My Country: Slovensko
I'm a: Student Tech
Posts: 19
Default edit toshiba bios image to accept any response code

Hello i am trying to edit toshiba bios image to accept any response code
Attached Images
File Type: png Bez názvu.png (170.3 KB, 50 views)
kiknusko is offline   Reply With Quote
Old 10-20-2019, 01:05 PM   #2
KvnTM
Badcaps Veteran
 
Join Date: May 2018
City & State: Arnstein, Bayern (Bavaria)
My Country: Germany
Line Voltage: 230VAC 50Hz
I'm a: Hobbyist Tech
Posts: 237
Default Re: edit toshiba bios image to accept any response code

Quote:
Originally Posted by kiknusko View Post
Hello i am trying to edit toshiba bios image to accept any response code
What's the point of this?
KvnTM is offline   Reply With Quote
Old 10-21-2019, 01:26 AM   #3
RethoricalCheese
Badcaps Veteran
 
Join Date: Mar 2013
City & State: Tartu
My Country: Estonia
I'm a: Knowledge Seeker
Posts: 301
Default Re: edit toshiba bios image to accept any response code

Quote:
Originally Posted by KvnTM View Post
What's the point of this?
If you have response code generator to share then there is no point. If not, it was to remove bios password on toshibas. Sadly it is signed code so not possible to modify like this.
RethoricalCheese is offline   Reply With Quote
Old 10-21-2019, 03:16 AM   #4
imranromi
Badcaps Veteran
 
Join Date: Jan 2015
City & State: rawalpindi/punjab
My Country: pakistan
Line Voltage: 230v
I'm a: Knowledge Seeker
Posts: 1,121
Default Re: edit toshiba bios image to accept any response code

Quote:
Originally Posted by RethoricalCheese View Post
If you have response code generator to share then there is no point. If not, it was to remove bios password on toshibas. Sadly it is signed code so not possible to modify like this.
Yes correct bios cannot modified if modified laptop no give display.
imranromi is offline   Reply With Quote
Old 10-21-2019, 06:20 AM   #5
KvnTM
Badcaps Veteran
 
Join Date: May 2018
City & State: Arnstein, Bayern (Bavaria)
My Country: Germany
Line Voltage: 230VAC 50Hz
I'm a: Hobbyist Tech
Posts: 237
Default Re: edit toshiba bios image to accept any response code

Thats why I asked. There is no point editing bios files like this. Never had luck modifying bios rom's with a hex editor or disassembler. I believe every bios has at least a checksum check.
I'd rather flash a clean bios with code signing intact. I don't think that it is locked to a cpu serial number or something else. Correct me if I'm wrong though.

It would be interesting to know which device checks the signing. If it is a routine in the bios file itself you could easily manipulate it. if the EC or PCH has a check for it then there is no way around it.
KvnTM is offline   Reply With Quote
Old 10-21-2019, 08:00 AM   #6
RethoricalCheese
Badcaps Veteran
 
Join Date: Mar 2013
City & State: Tartu
My Country: Estonia
I'm a: Knowledge Seeker
Posts: 301
Default Re: edit toshiba bios image to accept any response code

Password stored in ec/kbc so flashing clean bios has no point.

I modify bios files all the time to remove passwords. Even made a modifying tool for HP which only has positive feedback thus far
RethoricalCheese is offline   Reply With Quote
Old 10-21-2019, 08:09 AM   #7
KvnTM
Badcaps Veteran
 
Join Date: May 2018
City & State: Arnstein, Bayern (Bavaria)
My Country: Germany
Line Voltage: 230VAC 50Hz
I'm a: Hobbyist Tech
Posts: 237
Default Re: edit toshiba bios image to accept any response code

Quote:
Originally Posted by RethoricalCheese View Post
Password stored in ec/kbc so flashing clean bios has no point.

I modify bios files all the time to remove passwords. Even made a modifying tool for HP which only has positive feedback thus far
Is this also true for EC's which are non programmable and the firmware is shared with the bios on a single flash chip? Or do they have an EEPROM or something else in it to store the password? Never looked into EC's that far.
KvnTM is offline   Reply With Quote
Old 10-21-2019, 08:15 AM   #8
RethoricalCheese
Badcaps Veteran
 
Join Date: Mar 2013
City & State: Tartu
My Country: Estonia
I'm a: Knowledge Seeker
Posts: 301
Default Re: edit toshiba bios image to accept any response code

Not sure if I understand your question.

EC/KBC can be programmable and not programmable. When it is not programmable, it might have an eeprom next to it. When it is programmable, it has internal eeprom.

When password is stored in EC/KBC (doesnt matter what kind), it is not possible to clear it by flashing a clean bios on main eeprom. Yes, it is possible to clear password from EC/KBC by flashing that with a clean file but this is often difficult because it might not be a soic8 eeprom.
RethoricalCheese is offline   Reply With Quote
Old 10-23-2019, 12:54 PM   #9
drgn997
New Member
 
Join Date: Dec 2011
Posts: 18
Default Re: edit toshiba bios image to accept any response code

@kiknusko
Start with something easy by modifying strings, but as RethoricalCheese or imranromi mentioned, it won't work as it seems that upon powering up, bios checks for firmware integrity.
I tried with a Tecra A9 with legacy bios, after modification it didn't give display output. With UEFI bioses seems easier to modify modules, but I haven't tried.
drgn997 is offline   Reply With Quote
Old 10-24-2019, 04:24 AM   #10
said7002
New Member
 
Join Date: Sep 2013
City & State: laayoune
My Country: maroc
I'm a: Knowledge Seeker
Posts: 15
Default Re: edit toshiba bios image to accept any response code

Password check: BIOS
out_buf = call_EC(
func=0x24,
in_buf=MD5(input)[:8] + pwd_type
)
out_buf[0] == 0 ⇒ success
said7002 is offline   Reply With Quote
Old 10-28-2019, 02:14 AM   #11
przemek_79
New Member
 
Join Date: Dec 2014
City & State: Łódz
My Country: Poland
I'm a: Knowledge Seeker
Posts: 10
Default Re: edit toshiba bios image to accept any response code

Quote:
Originally Posted by said7002 View Post
Password check: BIOS
out_buf = call_EC(
func=0x24,
in_buf=MD5(input)[:8] + pwd_type
)
out_buf[0] == 0 ⇒ success


according to the author, just rewrite this code to python and you can generate the code yourself

https://recon.cx/2018/brussels/resou...ba-Laptops.pdf

Challenge: BIOSout_buf =call_EC(func=0x1A, in_buf=rdtsc()+MD5(pc_serial)[:8])challenge = bytes_to_string(out_buf)


Response: BIOSout_buf =call_EC(func=0x1B, in_buf=string_to_bytes(user_input))out_buf[0]⇒ success/fail
przemek_79 is offline   Reply With Quote
Old 10-29-2019, 03:50 AM   #12
biospwd
Free Help
 
Join Date: Oct 2019
City & State: HueHue
My Country: Ireland
I'm a: Knowledge Seeker
Posts: 47
Default Re: edit toshiba bios image to accept any response code

Quote:
Originally Posted by przemek_79 View Post
according to the author, just rewrite this code to python and you can generate the code yourself

https://recon.cx/2018/brussels/resou...ba-Laptops.pdf

Challenge: BIOSout_buf =call_EC(func=0x1A, in_buf=rdtsc()+MD5(pc_serial)[:8])challenge = bytes_to_string(out_buf)


Response: BIOSout_buf =call_EC(func=0x1B, in_buf=string_to_bytes(user_input))out_buf[0]⇒ success/fail
I tried but It does not work for me.
__________________
Free help, if need my help, send your topic URL on PM
biospwd is offline   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump



Badcaps.net Technical Forums © 2003 - 2019
Powered by vBulletin ®
Copyright ©2000 - 2019, Jelsoft Enterprises Ltd.
All times are GMT -6. The time now is 07:44 PM.
Did you find this forum helpful?