Macbook M1 bypass FMM / EFI Unlock

Collapse
This topic is closed.
X
X
 
  • Time
  • Show
Clear All
new posts
  • ebaymonster
    New Member
    • Dec 2021
    • 0
    • Ukraine

    #61
    Re: Macbook M1 bypass FMM / EFI Unlock

    I found here interesting information about the structure of files and where theoretically can be what we need.

    Comment

    • .::iRizwan::.
      Banned
      • Apr 2016
      • 63
      • Pakistan

      #62
      Re: Macbook M1 bypass FMM / EFI Unlock

      Originally posted by bluestone
      How do you get the info from the mac itself? I have A1932. with EFI and Icloud locked but its not erased
      did you manage to jailbreak it?

      Comment

      • betonel
        Member
        • Nov 2015
        • 32
        • romania

        #63
        Re: Macbook M1 bypass FMM / EFI Unlock

        But idea might be good.. On the activation screen I have managed to open log window ( COMMAND + L and other random keys while in startup disk screen.. then I have saved boot log on external usb drive -> attached here)
        Attached Files
        Last edited by SMDFlea; 02-15-2022, 01:32 PM.

        Comment

        • bluestone
          Badcaps Veteran
          • Jun 2011
          • 343
          • Ghana

          #64
          Re: Macbook M1 bypass FMM / EFI Unlock

          Originally posted by .::iRizwan::.
          did you manage to jailbreak it?
          Mine can jailbreak alright but it's having an EFI password which I can remove with AC2 but that will also update the bridge os which will make activation lock impossible to remove.

          Comment

          • betonel
            Member
            • Nov 2015
            • 32
            • romania

            #65
            Re: Macbook M1 bypass FMM / EFI Unlock

            Originally posted by betonel
            But idea might be good.. On the activation screen I have managed to open log window ( COMMAND + L and other random keys while in startup disk screen.. then I have saved boot log on external usb drive -> attached here)
            There is some guy on youtube showing how he open terminal inside activation window on M1/T2 mac.

            keywords: M1 terminal inside Internet recovery MacOS Monterey

            How is this possible? We need to find key combination, for the moment found way to open log window / save logs to usb.

            Comment

            • betonel
              Member
              • Nov 2015
              • 32
              • romania

              #66
              Re: Macbook M1 bypass FMM / EFI Unlock

              One way for bypass M1 will be patching ipsw file, eg. UniversalMac_11.0.1_20B29_Restore.ipsw\022-10604-034\3_Apple_APFS

              KRAActivationAuthViewController



              Similar work has been successfully performed for iphone:

              1. Download the iPSW file you need from the official website: IPSW.
              2. Secondly, convert the iPSW file into a ZIP file by changing the extension and extract it.
              3. Now open the extracted file folder, and you will see 3 different .dmg files in there.
              4. Look for the biggest file and drag it to your desktop. You will notice that the .dmg files will not be able to open in one click. It’s because these files are encrypted.
              5. You would need a firmware key to open this file. For this purpose, direct to “The iPhone WiKi” and find your firmware key.
              6. Once you have the key, it’s time to use ???iDecrypt that is already on your Mac. Simply launch the software and open your .dmg file with it.
              7. You will see a warning message on your screen. Simply click on the “OK” button and select your output folder and paste your key for “RootFilesystem."
              8. Now, you need to click on “Decrypt DMG," and when the process is finished, you will see a success message.
              9. Open the iPSW file that is decrypted and go to the Applications folder. Here, you need to delete the “Setup” file.
              10. Then, exit this folder and right-click on your decrypted file and click on “Eject."
              11. When the file is successfully saved, delete the original file and rename the new decrypted file matching the original file. Then, paste this file into the extracted folder again.
              12. The last step is to compress the folder back to the IPSW format.

              Comment

              • mazoot
                iFixit
                • Jan 2019
                • 41
                • Moldova

                #67
                Re: Macbook M1 bypass FMM / EFI Unlock

                good idea bro! do you manage to bypass on ios 15? On what device did you test that trick?Do you have that FW files for test?
                Last edited by mazoot; 02-17-2022, 02:11 AM.
                Kill the state in yourself and you will be free like a wind...

                Comment

                • bluestone
                  Badcaps Veteran
                  • Jun 2011
                  • 343
                  • Ghana

                  #68
                  Re: Macbook M1 bypass FMM / EFI Unlock

                  Originally posted by betonel
                  One way for bypass M1 will be patching ipsw file, eg. UniversalMac_11.0.1_20B29_Restore.ipsw\022-10604-034\3_Apple_APFS

                  KRAActivationAuthViewController
                  Do you think this could actually work?
                  Last edited by SMDFlea; 02-18-2022, 04:08 AM.

                  Comment

                  • qava
                    Member
                    • Jun 2018
                    • 21
                    • Poland

                    #69
                    Re: Macbook M1 bypass FMM / EFI Unlock

                    Originally posted by ebaymonster
                    Steven, do you think it makes sense to solder ssd from a locked macbook to m1 and read it?
                    I take off nand and put to programmer P11 from JC but get only info about encryption date and can't do anything.

                    Comment

                    • qava
                      Member
                      • Jun 2018
                      • 21
                      • Poland

                      #70
                      Re: Macbook M1 bypass FMM / EFI Unlock

                      Originally posted by qava
                      I take off nand and put to programmer P11 from JC but get only info about encryption date and can't do anything.
                      Originally posted by betonel
                      There is some guy on youtube showing how he open terminal inside activation window on M1/T2 mac.

                      keywords: M1 terminal inside Internet recovery MacOS Monterey

                      How is this possible? We need to find key combination, for the moment found way to open log window / save logs to usb.
                      It's A1706 intel MacBook.

                      Comment

                      • curiositymaster
                        Member
                        • Apr 2021
                        • 45
                        • Nigeria

                        #71
                        Re: Macbook M1 bypass FMM / EFI Unlock

                        Originally posted by qava
                        It's A1706 intel MacBook.
                        We're not talking about A1706 Macbooks here, you don't need to take off NAND to unlock that one.

                        Comment

                        • qava
                          Member
                          • Jun 2018
                          • 21
                          • Poland

                          #72
                          Re: Macbook M1 bypass FMM / EFI Unlock

                          Originally posted by curiositymaster
                          We're not talking about A1706 Macbooks here, you don't need to take off NAND to unlock that one.
                          I don't talk about Unlock A1706 m8.
                          Read my post again.

                          Betonel write:
                          Originally posted by betonel
                          There is some guy on youtube showing how he open terminal inside activation window on M1/T2 mac.

                          keywords: M1 terminal inside Internet recovery MacOS Monterey

                          How is this possible? We need to find key combination, for the moment found way to open log window / save logs to usb.
                          So I go to YouTube use keywords and video shows A1706 MacBook A1706 - not M1.

                          Also:

                          Originally posted by betonel
                          What if you remove nand and run diagnostic mode, I guess you will be able to see SN there. Funny will be that SN is generated from bt mac + wifi mac, and we're looking for something that doesn't exist.

                          Need to compare dumps from SOC rom of M1, @Stephen, can you share some? Will upload mine tomorrow.
                          Than I try to check this. So i put the NAND just to check what happend cuz I heve a programmer where can use to for example upgrade NAND in iPhones and iPads. That was only a test to see. After take off NAND from 820-02020-11 got this information:
                          This NAND model does not support generating and burning encrypted data for the time being!

                          T2 - that all Intel MacBook
                          M1 - that ARM MacBook
                          No solution for now.
                          Got one A2338 If someone know anything I can test.

                          Comment

                          • curiositymaster
                            Member
                            • Apr 2021
                            • 45
                            • Nigeria

                            #73
                            Re: Macbook M1 bypass FMM / EFI Unlock

                            Originally posted by qava
                            I don't talk about Unlock A1706 m8.
                            Read my post again.

                            Can you share the info you got from reading the nand?

                            Comment

                            • qava
                              Member
                              • Jun 2018
                              • 21
                              • Poland

                              #74
                              Re: Macbook M1 bypass FMM / EFI Unlock

                              Originally posted by curiositymaster
                              Can you share the info you got from reading the nand?
                              Originally posted by qava
                              I don't talk about Unlock A1706 m8.
                              Read my post again.

                              After take off NAND from 820-02020-11 got this information:
                              This NAND model does not support generating and burning encrypted data for the time being!
                              Already write this.

                              Comment

                              • betonel
                                Member
                                • Nov 2015
                                • 32
                                • romania

                                #75
                                Re: Macbook M1 bypass FMM / EFI Unlock

                                Originally posted by qava
                                I don't talk about Unlock A1706 m8.
                                Read my post again.
                                You don't need to touch encrypted part of NAND. There is a plain clear partition containing SN/BT-MAC/WIFI-MAC. If we have valid pair it's possible to replace and get rid of activation lock. Can your programmer read raw data from NAND chip? Upload it on mega and share it please.
                                Last edited by SMDFlea; 02-18-2022, 05:32 AM.

                                Comment

                                • SMDFlea
                                  Super Moderator
                                  • Jan 2018
                                  • 20286
                                  • UK

                                  #76
                                  Re: Macbook M1 bypass FMM / EFI Unlock

                                  Originally posted by betonel
                                  You don't need to touch encrypted part of NAND. There is a plain clear partition containing SN/BT-MAC/WIFI-MAC. If we have valid pair it's possible to replace and get rid of activation lock. Can your programmer read raw data from NAND chip? Upload it on mega and share it please.
                                  Files should be posted here,not offsite
                                  All donations to badcaps are welcome, click on this link to donate. Thanks to all supporters

                                  Comment

                                  • qava
                                    Member
                                    • Jun 2018
                                    • 21
                                    • Poland

                                    #77
                                    Re: Macbook M1 bypass FMM / EFI Unlock

                                    Originally posted by betonel
                                    You don't need to touch encrypted part of NAND. There is a plain clear partition containing SN/BT-MAC/WIFI-MAC. If we have valid pair it's possible to replace and get rid of activation lock. Can your programmer read raw data from NAND chip? Upload it on mega and share it please.
                                    I can't take anything from this NAND. I use P11 programmer from JC and is for iPhone and iPad. But the NAND structure from M1 2020 is same like iPhone 11 pro or iPad Pro 11" that's why i try to read by JC programmer but was fail.

                                    Comment

                                    • qava
                                      Member
                                      • Jun 2018
                                      • 21
                                      • Poland

                                      #78
                                      Re: Macbook M1 bypass FMM / EFI Unlock

                                      Ther's 2 NAND and I try only one of them. Today im gonna take off 2nd and put here screenshot.

                                      Comment

                                      • curiositymaster
                                        Member
                                        • Apr 2021
                                        • 45
                                        • Nigeria

                                        #79
                                        Re: Macbook M1 bypass FMM / EFI Unlock

                                        Originally posted by qava
                                        Ther's 2 NAND and I try only one of them. Today im gonna take off 2nd and put here screenshot.

                                        That means we don't have a programmer that can read M1 NAND yet?

                                        Comment

                                        • qava
                                          Member
                                          • Jun 2018
                                          • 21
                                          • Poland

                                          #80
                                          Re: Macbook M1 bypass FMM / EFI Unlock

                                          2nd NAND says

                                          The hard drive is reversed, please re-insert the NAND...Click image for larger version

Name:	bc forum.PNG
Views:	1
Size:	158.6 KB
ID:	2083847

                                          Comment

                                          Related Topics

                                          Collapse

                                          • tobeend
                                            Bypass mdm macbook m2 ventura
                                            by tobeend
                                            1. RESET MACOS WITH IPSW

                                            a. Power off MacBook, press and hold the power button to enter Recovery
                                            b. Open Disk Utility, remove Macintosh HD
                                            c. Reboot, connect to the network to Activate Mac.
                                            d. Plug the C cord in the first port of the MacBook into the other Mac, then power off the MacBook
                                            d. Hold down the Control (L) + Option (L) + Shift (R) + Power key combination for 10 seconds
                                            e. Release the other keys, but keep holding the Power key for another 10 seconds
                                            f. MacBook is returned to DFU, open Apple Configurator 2 on the other Mac, right-click...
                                            05-26-2023, 07:18 AM
                                          • oxonater
                                            Apple MacBook Pro A2141 16" IC BYPASS
                                            by oxonater
                                            Hi everyone hope all are well

                                            I need a little expert advice on a issue I have and seeing as this forum is full of clever people I thought ask here as you never know.
                                            I recently repaired a logic board 820-01700 which belongs to a 16" 2019 Macbook Pro, however I seem to be missing a component near the T2 Rom chip and is U4730.

                                            The schematics say this chip is (M34128-FCS6_P/T) and it also says there is a bypass for it wondered if anyone come across either the IC or the bypass method.
                                            I suppose it's worth noting googling the part package brings up various...
                                            10-23-2024, 11:21 PM
                                          • keats11
                                            T2 Macbook MDM Unlock by S/N change.
                                            by keats11
                                            I was hoping someone could point me to a tutorial on MDM unlock. Basically, I picked up a Macbook (A1989) from someone which did not have OS installed. The guy said it started software update and but did not finish. Long story short, the touchbar on this device has some kind of a short, so after unplugging it, I was able to install the OS on it, when I found out that it is also MDM locked by his company. I tried changing the serial number on the ROM by only changing a couple of digits of the original serial number. Now after installing the ROM back, the Macbook appears dead = DFU mode. When I...
                                            05-15-2023, 06:46 AM
                                          • Manlikeissak
                                            M1 MacBook EFI/FMM unlock
                                            by Manlikeissak
                                            Hello everyone hope you all are doing well, I'm posting here since no was interested in my post on "MacBook unlocked!" Topic, so In short I have found a way to test every possible key combination to try and find the combination to open the terminal on fmm/EFI locked M1/M2 machines, the person who found this still refuses to give info, but if hasn't lied about it being a key combination there's a chance we might find it, so to try Evey key combination I've got a digispark attiny 85 which is a small μController, I've written as script to emulate a keyboard and go thru every possible key...
                                            07-02-2024, 11:28 AM
                                          • tobeend
                                            Bypass iCloud MACBOOK t2 iBridge older 7.0
                                            by tobeend
                                            Does anyone know any solution to bypass the older iBridge?
                                            because everyone now offers bypass only 7.2 and 7.4 as they are not so stable and I don't want to update from 5.5 to 7.5
                                            Please suggest a way out of the situation
                                            05-26-2023, 07:32 AM
                                          • Loading...
                                          • No more items.
                                          Working...