Macbook M1 bypass FMM / EFI Unlock

Collapse
This topic is closed.
X
X
 
  • Time
  • Show
Clear All
new posts
  • curiositymaster
    Member
    • Apr 2021
    • 45
    • Nigeria

    #261
    Re: Macbook M1 bypass FMM / EFI Unlock

    Originally posted by Mario1241
    hello genhack, thank you for your observations.

    I was thinking about the UniversalMac_11.0.1_20B29_Restore.ipsw we can edit it and instead of the diagnostic options we change it to the terminal file what would happen?

    Considering that I can load by DFU. I do not know how to edit it but it is an option that occurs to me, what do you think?

    Cheers!
    Has anyone tried the hidden diagnostic while booting with a jumpstick?

    Comment

    • genhack
      Member
      • Sep 2014
      • 16
      • Italia

      #262
      Re: Macbook M1 bypass FMM / EFI Unlock

      Originally posted by curiositymaster
      @genhack, do you have an idea how I can extract mobileactivationd from a mina-jailbroken t2 mac and how to use it to bypass those with upgraded bridgeOS version?
      If you have a t2 bypassed make a zip with a password of this folder and upload:

      Code:
      /usr/libexec/
      I'm working on T2 latest bridgeOS, can be pwn and i think is possible to bypass!



      Originally posted by Mario1241
      hello genhack, thank you for your observations.

      I was thinking about the UniversalMac_11.0.1_20B29_Restore.ipsw we can edit it and instead of the diagnostic options we change it to the terminal file what would happen?

      Considering that I can load by DFU. I do not know how to edit it but it is an option that occurs to me, what do you think?

      Cheers!
      You can't just edit ipsw like iphone/ipad, devices will refuse the flash. I need an m1 locked and see where we can play around.
      Last edited by genhack; 10-27-2022, 11:36 AM.

      Comment

      • curiositymaster
        Member
        • Apr 2021
        • 45
        • Nigeria

        #263
        Re: Macbook M1 bypass FMM / EFI Unlock

        Originally posted by genhack
        If you have a t2 bypassed make a zip with a password of this folder and upload:

        Code:
        /usr/libexec/
        I'm working on T2 latest bridgeOS, can be pwn and i think is possible to bypass!
        I'll see if I can get my hands on one and share it ASAP.

        Comment

        • fshadow
          New Member
          • Oct 2022
          • 3
          • wonderland

          #264
          Re: Macbook M1 bypass FMM / EFI Unlock

          When you start diagnostics there is dmg image (FieldServiceDiskImagePersonalized) downloded via internet, which contains another dmg image (like 012-94675-003.dmg). That last dmg contains apps, libs, lua scripts and so on, for running diagnostics, but this image is trustcache protected, so if you have control over network it is not possible to change... almost.
          assume, you've found a way to change on this image whatever you want, what would you do?

          Comment

          • genhack
            Member
            • Sep 2014
            • 16
            • Italia

            #265
            Re: Macbook M1 bypass FMM / EFI Unlock

            Originally posted by fshadow
            When you start diagnostics there is dmg image (FieldServiceDiskImagePersonalized) downloded via internet, which contains another dmg image (like 012-94675-003.dmg). That last dmg contains apps, libs, lua scripts and so on, for running diagnostics, but this image is trustcache protected, so if you have control over network it is not possible to change... almost.
            assume, you've found a way to change on this image whatever you want, what would you do?
            I fully agree. Diagnostics do not help the purpose, starting a shell from there wouldn't allow us to do anything.

            Comment

            • VHS
              Member
              • Oct 2020
              • 13
              • United States

              #266
              Re: Macbook M1 bypass FMM / EFI Unlock

              I've got a couple of bypassed T2s and one that won't unlock due to it having Monteray on it.
              I also have a water-damaged M1 that won't charge its battery, and it doesn't seem to have sound but other than that, it's running fine and an identical locked M1 that someone could probably make an easy repair of.

              Comment

              • Mario1241
                Member
                • Jun 2022
                • 24
                • Mexico

                #267
                Re: Macbook M1 bypass FMM / EFI Unlock

                Originally posted by genhack
                Hello Mario,
                In order:

                Code:
                Through DFU I have been able to reverse the firmware of the locked mac I have installed the UniversalMac_11.0.1_20B29_Restore.ipsw even so I have not been able to skip the icloud step.
                You can't edit and flash this ipsw, Bootchain will refuse any mod. so this try is usless untill m1 is pwn (*Like t2* with checkm8).

                Code:
                I have tried to start with linux but the operating system does not recognize me or it does not show me the memory or at least I do not know how to boot the operating system that is already combatable.
                Ok i think you need to check how boot m1m1 by usb. Just a Ps: M1 will refuse to boot other os in activation, secure state is enbaled but you can try.

                Code:
                The hidden diagnostic system allows me to store all the analysis on a usb stick.
                About diagnostic, i check myself and i think there is no way to use external drive for boot something or open app. Diagnostic is designed for just save do that and can't be the skip part of the process, you need to sign binary inside the other volume and make full bypass, this mean if i press activate you go on this flow and do all things you need for boot proper. if mobileactivationd don't make the necessary cert of the devices i think you will never boot inside the real os.
                Originally posted by VHS
                I've got a couple of bypassed T2s and one that won't unlock due to it having Monteray on it.
                I also have a water-damaged M1 that won't charge its battery, and it doesn't seem to have sound but other than that, it's running fine and an identical locked M1 that someone could probably make an easy repair of.
                the important thing is to find how to unlock it.

                Comment

                • curiositymaster
                  Member
                  • Apr 2021
                  • 45
                  • Nigeria

                  #268
                  Re: Macbook M1 bypass FMM / EFI Unlock

                  Originally posted by genhack
                  If you have a t2 bypassed make a zip with a password of this folder and upload:

                  Code:
                  /usr/libexec/
                  I'm working on T2 latest bridgeOS, can be pwn and i think is possible to bypass!.
                  Couldn't upload the whole libexec folder here as it was too large (42mb after compression). However, I have uploaded the mobileactivationd file from the bypassed mac if that is enough for your research.
                  Attached Files

                  Comment

                  • genhack
                    Member
                    • Sep 2014
                    • 16
                    • Italia

                    #269
                    Re: Macbook M1 bypass FMM / EFI Unlock

                    Originally posted by curiositymaster
                    Couldn't upload the whole libexec folder here as it was too large (42mb after compression). However, I have uploaded the mobileactivationd file from the bypassed mac if that is enough for your research.
                    Tsm ill check.

                    Comment

                    • fshadow
                      New Member
                      • Oct 2022
                      • 3
                      • wonderland

                      #270
                      Re: Macbook M1 bypass FMM / EFI Unlock

                      Originally posted by genhack
                      I fully agree. Diagnostics do not help the purpose, starting a shell from there wouldn't allow us to do anything.
                      actually you can get kernel privileges, bypass the FileVault, mount main partition and do whatever you want. I'm on this stage now, and have already booted linux with success. But my goal is to bypass activation lock and install normal macos.
                      Last edited by fshadow; 11-02-2022, 09:30 AM.

                      Comment

                      • kevingill
                        Senior Member
                        • Jun 2013
                        • 152
                        • England

                        #271
                        Re: Macbook M1 bypass FMM / EFI Unlock

                        Oh, interesting. Can you update us with how you've managed to boot Linux?

                        Comment

                        • fshadow
                          New Member
                          • Oct 2022
                          • 3
                          • wonderland

                          #272
                          Re: Macbook M1 bypass FMM / EFI Unlock

                          i'm not gonna expose it right now, because it is huge hole in macos security and seems like nobody know it. at first i'll post a vidio next week with poc without ditails, next i'll contact apple bug bounty(i know it's weak) , next... anyway i'll get profit and then i'll tell u

                          Comment

                          • curiositymaster
                            Member
                            • Apr 2021
                            • 45
                            • Nigeria

                            #273
                            Re: Macbook M1 bypass FMM / EFI Unlock

                            Originally posted by fshadow
                            i'm not gonna expose it right now, because it is huge hole in macos security and seems like nobody know it. at first i'll post a vidio next week with poc without ditails, next i'll contact apple bug bounty(i know it's weak) , next... anyway i'll get profit and then i'll tell u
                            If you weren't going to share how you managed to bypass filevault, why talk about it?

                            Comment

                            • curiositymaster
                              Member
                              • Apr 2021
                              • 45
                              • Nigeria

                              #274
                              Re: Macbook M1 bypass FMM / EFI Unlock

                              Originally posted by genhack
                              Tsm ill check.
                              Kindly update us as your research progresses. Cheers!

                              Comment

                              • Mmsdma
                                New Member
                                • Nov 2022
                                • 1
                                • polan

                                #275
                                Re: Macbook M1 bypass FMM / EFI Unlock

                                Originally posted by ugamazing
                                OK, I found a quick way to pull serial info from locked boards. Going to go through and pull more M1 ROM dumps later this week to check for emails; I still haven't found any in the dumps I've checked (over 25 checked now--including 2 more A2442 boards), but going to play with different scenarios (will take time).
                                hi guys, has anyone managed to find where the sn is recorded?
                                After reading through the entire thread I only found information that it is somewhere on the first nand and you can not get to it.

                                Comment

                                • nomade
                                  New Member
                                  • May 2022
                                  • 6
                                  • Peru

                                  #276
                                  Re: Macbook M1 bypass FMM / EFI Unlock

                                  Hi guys thank you for sharing your findings and questions.
                                  BTW, has anyone managed to install/run a linux or any other OS on a locked M1 MAC PRO? Could you share how you did it?

                                  Thanks.

                                  Comment

                                  • genhack
                                    Member
                                    • Sep 2014
                                    • 16
                                    • Italia

                                    #277
                                    Re: Macbook M1 bypass FMM / EFI Unlock

                                    Originally posted by curiositymaster
                                    Kindly update us as your research progresses. Cheers!
                                    I'm working on, i can't find the original mobileactivationd version for understand where they make the patch. But, i have an idea and in the free time i work on python program, i think this can work easy with a macbook just bypassed. So just for proof of t2 can be pwn:

                                    J40aap key latest bridgeos.

                                    IBSS:
                                    IV: 120402A7168E7AAAC1F94C6A5D58F8F1,
                                    key: 5C1E07A0EA5A8F48D09FA568182172CA74880896761CFA6992006558CDD9981D

                                    IBEC:
                                    IV: 6909A0A0D9675B5BAEFB9ECFAA00386C,
                                    key: C7DA39AF1DB80189C27F5D3A39C01F13D4FD7C7B6453DAADE018DC6188BAD24A


                                    About diagnostic i have no idea how you can boot m1n1 with security on. If you wonna make this a bit of sense send me a pvt thanks.

                                    Comment

                                    • ranzoo
                                      Member
                                      • Jun 2015
                                      • 17
                                      • algeria

                                      #278
                                      Re: Macbook M1 bypass FMM / EFI Unlock

                                      Originally posted by alerm
                                      Here you go
                                      I put in some images for you to see from where I got them (If you don't already have them)
                                      I hope this helps a little bit
                                      u get this file by controle+option+commnad +shit+/:

                                      Comment

                                      • Mario1241
                                        Member
                                        • Jun 2022
                                        • 24
                                        • Mexico

                                        #279
                                        Re: Macbook M1 bypass FMM / EFI Unlock

                                        Originally posted by fshadow
                                        actually you can get kernel privileges, bypass the FileVault, mount main partition and do whatever you want. I'm on this stage now, and have already booted linux with success. But my goal is to bypass activation lock and install normal macos.
                                        Hi fshadow;

                                        Can you share with us how you were able to start in linux?

                                        Comment

                                        • killeur
                                          New Member
                                          • Nov 2022
                                          • 4
                                          • djazayer

                                          #280
                                          Re: Macbook M1 bypass FMM / EFI Unlock

                                          Hello every one,

                                          i want to thank you all for effort and contribution,
                                          I was wondring if any one had tried to replace the ssd nand ships and reset the mac from dfu mode using Apple configurator App ? like replacing a normal ssd would that bypass FMM ? i am new so forgive me if iam saying bullshits.

                                          Regards.

                                          Comment

                                          Related Topics

                                          Collapse

                                          • tobeend
                                            Bypass mdm macbook m2 ventura
                                            by tobeend
                                            1. RESET MACOS WITH IPSW

                                            a. Power off MacBook, press and hold the power button to enter Recovery
                                            b. Open Disk Utility, remove Macintosh HD
                                            c. Reboot, connect to the network to Activate Mac.
                                            d. Plug the C cord in the first port of the MacBook into the other Mac, then power off the MacBook
                                            d. Hold down the Control (L) + Option (L) + Shift (R) + Power key combination for 10 seconds
                                            e. Release the other keys, but keep holding the Power key for another 10 seconds
                                            f. MacBook is returned to DFU, open Apple Configurator 2 on the other Mac, right-click...
                                            05-26-2023, 07:18 AM
                                          • oxonater
                                            Apple MacBook Pro A2141 16" IC BYPASS
                                            by oxonater
                                            Hi everyone hope all are well

                                            I need a little expert advice on a issue I have and seeing as this forum is full of clever people I thought ask here as you never know.
                                            I recently repaired a logic board 820-01700 which belongs to a 16" 2019 Macbook Pro, however I seem to be missing a component near the T2 Rom chip and is U4730.

                                            The schematics say this chip is (M34128-FCS6_P/T) and it also says there is a bypass for it wondered if anyone come across either the IC or the bypass method.
                                            I suppose it's worth noting googling the part package brings up various...
                                            10-23-2024, 11:21 PM
                                          • keats11
                                            T2 Macbook MDM Unlock by S/N change.
                                            by keats11
                                            I was hoping someone could point me to a tutorial on MDM unlock. Basically, I picked up a Macbook (A1989) from someone which did not have OS installed. The guy said it started software update and but did not finish. Long story short, the touchbar on this device has some kind of a short, so after unplugging it, I was able to install the OS on it, when I found out that it is also MDM locked by his company. I tried changing the serial number on the ROM by only changing a couple of digits of the original serial number. Now after installing the ROM back, the Macbook appears dead = DFU mode. When I...
                                            05-15-2023, 06:46 AM
                                          • envym
                                            MacBook Pro 2018 with Activation Lock
                                            by envym
                                            Hi everyone!

                                            I have a 2018 MacBook Pro (with Sequoia OS) that I've been using for years with no problem. I recently received an M2 MacBook Pro so I'm mostly using it and not the 2018 one, but since a friend of mine needs a computer, I thought I could restore my 2018 and give it brand-new-like to my friend.

                                            I tried using the built-in tool to restore the MacBook (Settings > General > Transfer or restore > Delete) but it got stuck when trying to remove the Find Device configuration (it asked me for the password for my old Apple ID -now I use the same account but...
                                            06-27-2025, 08:54 AM
                                          • Manlikeissak
                                            M1 MacBook EFI/FMM unlock
                                            by Manlikeissak
                                            Hello everyone hope you all are doing well, I'm posting here since no was interested in my post on "MacBook unlocked!" Topic, so In short I have found a way to test every possible key combination to try and find the combination to open the terminal on fmm/EFI locked M1/M2 machines, the person who found this still refuses to give info, but if hasn't lied about it being a key combination there's a chance we might find it, so to try Evey key combination I've got a digispark attiny 85 which is a small μController, I've written as script to emulate a keyboard and go thru every possible key...
                                            07-02-2024, 11:28 AM
                                          • Loading...
                                          • No more items.
                                          Working...