Macbook M1 bypass FMM / EFI Unlock

Collapse
This topic is closed.
X
X
 
  • Time
  • Show
Clear All
new posts
  • Mouad666
    New Member
    • Oct 2022
    • 1
    • Maroc

    #241
    Re: Macbook M1 bypass FMM / EFI Unlock

    Originally posted by ugamazing
    OK, I found a quick way to pull serial info from locked boards. Going to go through and pull more M1 ROM dumps later this week to check for emails; I still haven't found any in the dumps I've checked (over 25 checked now--including 2 more A2442 boards), but going to play with different scenarios (will take time).
    Could you please share the used method

    Comment

    • Mario1241
      Member
      • Jun 2022
      • 24
      • Mexico

      #242
      Re: Macbook M1 bypass FMM / EFI Unlock

      Originally posted by Mouad666
      Could you please share the used method
      https://www.youtube.com/watch?v=I9QOZLY1WHA

      Comment

      • ugamazing
        Senior Member
        • Jun 2013
        • 161
        • usa

        #243
        Re: Macbook M1 bypass FMM / EFI Unlock

        Originally posted by Mouad666
        Could you please share the used method
        Hey, yes, it's simple: Boot to diagnostics. You can now boot to diagnostics on a locked board...couldn't do this on T2 locked board prior. Now you can, on M1.

        Originally posted by Mario1241
        There may be an easier way to access this menu/option: Have you booted to diagnostics, then used the browser/menu to access files from there? You can even use a locked board to go online via diagnostics boot. But your way is quite intuitive! Very nice.

        Comment

        • Mario1241
          Member
          • Jun 2022
          • 24
          • Mexico

          #244
          Re: Macbook M1 bypass FMM / EFI Unlock

          Originally posted by betonel
          One way for bypass M1 will be patching ipsw file, eg. UniversalMac_11.0.1_20B29_Restore.ipsw\022-10604-034\3_Apple_APFS

          KRAActivationAuthViewController



          Similar work has been successfully performed for iphone:

          1. Download the iPSW file you need from the official website: IPSW.
          2. Secondly, convert the iPSW file into a ZIP file by changing the extension and extract it.
          3. Now open the extracted file folder, and you will see 3 different .dmg files in there.
          4. Look for the biggest file and drag it to your desktop. You will notice that the .dmg files will not be able to open in one click. It's because these files are encrypted.
          5. You would need a firmware key to open this file. For this purpose, direct to “The iPhone WiKi” and find your firmware key.
          6. Once you have the key, it's time to use ???iDecrypt that is already on your Mac. Simply launch the software and open your .dmg file with it.
          7. You will see a warning message on your screen. Simply click on the “OK” button and select your output folder and paste your key for “RootFilesystem."
          8. Now, you need to click on “Decrypt DMG," and when the process is finished, you will see a success message.
          9. Open the iPSW file that is decrypted and go to the Applications folder. Here, you need to delete the “Setup” file.
          10. Then, exit this folder and right-click on your decrypted file and click on “Eject."
          11. When the file is successfully saved, delete the original file and rename the new decrypted file matching the original file. Then, paste this file into the extracted folder again.
          12. The last step is to compress the folder back to the IPSW format.

          Hi,

          Do you have any video of this procedure?

          Comment

          • Mario1241
            Member
            • Jun 2022
            • 24
            • Mexico

            #245
            Re: Macbook M1 bypass FMM / EFI Unlock

            Hello, a day ago I found a video where they indicate that it can already be unlocked, if someone knows how we can do it, share it with them.
            Last edited by SMDFlea; 10-14-2022, 02:47 AM.

            Comment

            • SMDFlea
              Super Moderator
              • Jan 2018
              • 20276
              • UK

              #246
              Re: Macbook M1 bypass FMM / EFI Unlock

              Originally posted by Mario1241
              Hello, a day ago I found a video where they indicate that it can already be unlocked, if someone knows how we can do it, share it with them.
              Do not post links to videos when the user is offering paid services.The user in question was banned from here for his bullshit.Don`t post it again.
              All donations to badcaps are welcome, click on this link to donate. Thanks to all supporters

              Comment

              • VHS
                Member
                • Oct 2020
                • 13
                • United States

                #247
                Re: Macbook M1 bypass FMM / EFI Unlock

                Originally posted by Mario1241
                Hello, a day ago I found a video where they indicate that it can already be unlocked, if someone knows how we can do it, share it with them.
                That 'method' in the video is just little-known Apple IT stuff that's been online for years. (shift control option command right period)
                You're entering recoverydiagnose for debugging.
                Fun to play with, but not exactly secret.

                https://derflounder.wordpress.com/20...acos-recovery/

                Comment

                • Mario1241
                  Member
                  • Jun 2022
                  • 24
                  • Mexico

                  #248
                  Re: Macbook M1 bypass FMM / EFI Unlock

                  Originally posted by SMDFlea
                  Do not post links to videos when the user is offering paid services.The user in question was banned from here for his bullshit.Don`t post it again.
                  a thousand apologies I had no idea that it was prohibited I will not do it again.

                  Comment

                  • SMDFlea
                    Super Moderator
                    • Jan 2018
                    • 20276
                    • UK

                    #249
                    Re: Macbook M1 bypass FMM / EFI Unlock

                    Originally posted by Mario1241
                    a thousand apologies I had no idea that it was prohibited I will not do it again.
                    No problem you were only trying to help.
                    All donations to badcaps are welcome, click on this link to donate. Thanks to all supporters

                    Comment

                    • Mario1241
                      Member
                      • Jun 2022
                      • 24
                      • Mexico

                      #250
                      Re: Macbook M1 bypass FMM / EFI Unlock

                      I want to take advantage of the time and I invoke all the connoisseurs. I have 2 m1 teams, one locked and the other unlocked, that I can do so that I can test what options we have that we can do. I am very interested in knowing how to unlock them.

                      Comment

                      • Mario1241
                        Member
                        • Jun 2022
                        • 24
                        • Mexico

                        #251
                        Re: Macbook M1 bypass FMM / EFI Unlock

                        Originally posted by VHS
                        That 'method' in the video is just little-known Apple IT stuff that's been online for years. (shift control option command right period)
                        You're entering recoverydiagnose for debugging.
                        Fun to play with, but not exactly secret.

                        https://derflounder.wordpress.com/20...acos-recovery/
                        It didn't help me at all because it has icloud, I was reading about os bridges but it only works with M1 with T2

                        Comment

                        • 777monah777
                          New Member
                          • Oct 2022
                          • 9
                          • Washington

                          #252
                          Re: Macbook M1 bypass FMM / EFI Unlock

                          Hi. maybe someone knows from the diagnostics section (where safari is available) you can somehow start the terminal? or perhaps there is another way to enable the terminal?

                          Comment

                          • Mario1241
                            Member
                            • Jun 2022
                            • 24
                            • Mexico

                            #253
                            Re: Macbook M1 bypass FMM / EFI Unlock

                            Hello friends, I like research and I found this article, I would like that we could do something. The documentation tells us about the bases of s.o. from mac It has occurred to me to be able to modify the IPSW files of version 11 of mac. Someone is a genius in this that can help us I have the idea that we can change to later make a DFU, but I need to modify the DMG files.

                            https://github.com/vmlemon/understan...OS-Archaeology

                            Who is an expert in IPSW modifications? Whoever contact me I have the idea but I'm not an expert. Hopefully what I have in mind can work.

                            Comment

                            • Mario1241
                              Member
                              • Jun 2022
                              • 24
                              • Mexico

                              #254
                              Re: Macbook M1 bypass FMM / EFI Unlock

                              Hello, does anyone know how to use or how to install PongoOS?

                              https://github.com/checkra1n/pongoOS

                              Comment

                              • Mario1241
                                Member
                                • Jun 2022
                                • 24
                                • Mexico

                                #255
                                Re: Macbook M1 bypass FMM / EFI Unlock

                                Originally posted by 777monah777
                                Hi. maybe someone knows from the diagnostics section (where safari is available) you can somehow start the terminal? or perhaps there is another way to enable the terminal?
                                it can't be done

                                Comment

                                • genhack
                                  Member
                                  • Sep 2014
                                  • 16
                                  • Italia

                                  #256
                                  Re: Macbook M1 bypass FMM / EFI Unlock

                                  hey @Mario1241 pongoOs can be booted on m1 but is useless. if you can't pwn m1 processor (like t2). On m1 we need to understand if 1TR or recovery, when locked can boot other os, and if yes what we can mount without aes engine. if you have another mac i can send you a ways for boot linux and check what we can do. Just a remember we need a full patch or mobileactivationd and a dump of t2 macbook bypassed with minacriss can be the key.

                                  Comment

                                  • Mario1241
                                    Member
                                    • Jun 2022
                                    • 24
                                    • Mexico

                                    #257
                                    Re: Macbook M1 bypass FMM / EFI Unlock

                                    Originally posted by genhack
                                    hey @Mario1241 pongoOs can be booted on m1 but is useless. if you can't pwn m1 processor (like t2). On m1 we need to understand if 1TR or recovery, when locked can boot other os, and if yes what we can mount without aes engine. if you have another mac i can send you a ways for boot linux and check what we can do. Just a remember we need a full patch or mobileactivationd and a dump of t2 macbook bypassed with minacriss can be the key.
                                    Hello genhack , I share with you.

                                    I currently have two m1(A2338) macs, they don't have the T2 chip.
                                    Through DFU I have been able to reverse the firmware of the locked mac I have installed the UniversalMac_11.0.1_20B29_Restore.ipsw even so I have not been able to skip the icloud step.

                                    I have tried to start with linux but the operating system does not recognize me or it does not show me the memory or at least I do not know how to boot the operating system that is already combatable.

                                    I have also experimented opening the hidden menu in the diagnostics but still I can't open the terminal because it doesn't recognize it.

                                    The hidden diagnostic menu lets me store all the scans on a usb stick.

                                    I have also tried to use an external disk with the operating system installed to be able to use it and it does not allow it.

                                    The hidden diagnostic system allows me to store all the analysis on a usb stick.

                                    Tell me how I can experiment with the locked computer, or can you think of any other option.

                                    best regards

                                    Comment

                                    • genhack
                                      Member
                                      • Sep 2014
                                      • 16
                                      • Italia

                                      #258
                                      Re: Macbook M1 bypass FMM / EFI Unlock

                                      Originally posted by Mario1241
                                      Hello genhack , I share with you.

                                      I currently have two m1(A2338) macs, they don't have the T2 chip.
                                      Through DFU I have been able to reverse the firmware of the locked mac I have installed the UniversalMac_11.0.1_20B29_Restore.ipsw even so I have not been able to skip the icloud step.

                                      I have tried to start with linux but the operating system does not recognize me or it does not show me the memory or at least I do not know how to boot the operating system that is already combatable.

                                      I have also experimented opening the hidden menu in the diagnostics but still I can't open the terminal because it doesn't recognize it.

                                      The hidden diagnostic menu lets me store all the scans on a usb stick.

                                      I have also tried to use an external disk with the operating system installed to be able to use it and it does not allow it.

                                      The hidden diagnostic system allows me to store all the analysis on a usb stick.

                                      Tell me how I can experiment with the locked computer, or can you think of any other option.

                                      best regards
                                      Hello Mario,
                                      In order:

                                      Code:
                                      Through DFU I have been able to reverse the firmware of the locked mac I have installed the UniversalMac_11.0.1_20B29_Restore.ipsw even so I have not been able to skip the icloud step.
                                      You can't edit and flash this ipsw, Bootchain will refuse any mod. so this try is usless untill m1 is pwn (*Like t2* with checkm8).

                                      Code:
                                      I have tried to start with linux but the operating system does not recognize me or it does not show me the memory or at least I do not know how to boot the operating system that is already combatable.
                                      Ok i think you need to check how boot m1m1 by usb. Just a Ps: M1 will refuse to boot other os in activation, secure state is enbaled but you can try.

                                      Code:
                                      The hidden diagnostic system allows me to store all the analysis on a usb stick.
                                      About diagnostic, i check myself and i think there is no way to use external drive for boot something or open app. Diagnostic is designed for just save do that and can't be the skip part of the process, you need to sign binary inside the other volume and make full bypass, this mean if i press activate you go on this flow and do all things you need for boot proper. if mobileactivationd don't make the necessary cert of the devices i think you will never boot inside the real os.

                                      Comment

                                      • Mario1241
                                        Member
                                        • Jun 2022
                                        • 24
                                        • Mexico

                                        #259
                                        Re: Macbook M1 bypass FMM / EFI Unlock

                                        Originally posted by genhack
                                        Hello Mario,
                                        In order:

                                        Code:
                                        Through DFU I have been able to reverse the firmware of the locked mac I have installed the UniversalMac_11.0.1_20B29_Restore.ipsw even so I have not been able to skip the icloud step.
                                        You can't edit and flash this ipsw, Bootchain will refuse any mod. so this try is usless untill m1 is pwn (*Like t2* with checkm8).

                                        Code:
                                        I have tried to start with linux but the operating system does not recognize me or it does not show me the memory or at least I do not know how to boot the operating system that is already combatable.
                                        Ok i think you need to check how boot m1m1 by usb. Just a Ps: M1 will refuse to boot other os in activation, secure state is enbaled but you can try.

                                        Code:
                                        The hidden diagnostic system allows me to store all the analysis on a usb stick.
                                        About diagnostic, i check myself and i think there is no way to use external drive for boot something or open app. Diagnostic is designed for just save do that and can't be the skip part of the process, you need to sign binary inside the other volume and make full bypass, this mean if i press activate you go on this flow and do all things you need for boot proper. if mobileactivationd don't make the necessary cert of the devices i think you will never boot inside the real os.

                                        hello genhack, thank you for your observations.

                                        I was thinking about the UniversalMac_11.0.1_20B29_Restore.ipsw we can edit it and instead of the diagnostic options we change it to the terminal file what would happen?

                                        Considering that I can load by DFU. I do not know how to edit it but it is an option that occurs to me, what do you think?

                                        Cheers!

                                        Comment

                                        • curiositymaster
                                          Member
                                          • Apr 2021
                                          • 45
                                          • Nigeria

                                          #260
                                          Re: Macbook M1 bypass FMM / EFI Unlock

                                          @genhack, do you have an idea how I can extract mobileactivationd from a mina-jailbroken t2 mac and how to use it to bypass those with upgraded bridgeOS version?

                                          Comment

                                          Related Topics

                                          Collapse

                                          • tobeend
                                            Bypass mdm macbook m2 ventura
                                            by tobeend
                                            1. RESET MACOS WITH IPSW

                                            a. Power off MacBook, press and hold the power button to enter Recovery
                                            b. Open Disk Utility, remove Macintosh HD
                                            c. Reboot, connect to the network to Activate Mac.
                                            d. Plug the C cord in the first port of the MacBook into the other Mac, then power off the MacBook
                                            d. Hold down the Control (L) + Option (L) + Shift (R) + Power key combination for 10 seconds
                                            e. Release the other keys, but keep holding the Power key for another 10 seconds
                                            f. MacBook is returned to DFU, open Apple Configurator 2 on the other Mac, right-click...
                                            05-26-2023, 07:18 AM
                                          • oxonater
                                            Apple MacBook Pro A2141 16" IC BYPASS
                                            by oxonater
                                            Hi everyone hope all are well

                                            I need a little expert advice on a issue I have and seeing as this forum is full of clever people I thought ask here as you never know.
                                            I recently repaired a logic board 820-01700 which belongs to a 16" 2019 Macbook Pro, however I seem to be missing a component near the T2 Rom chip and is U4730.

                                            The schematics say this chip is (M34128-FCS6_P/T) and it also says there is a bypass for it wondered if anyone come across either the IC or the bypass method.
                                            I suppose it's worth noting googling the part package brings up various...
                                            10-23-2024, 11:21 PM
                                          • keats11
                                            T2 Macbook MDM Unlock by S/N change.
                                            by keats11
                                            I was hoping someone could point me to a tutorial on MDM unlock. Basically, I picked up a Macbook (A1989) from someone which did not have OS installed. The guy said it started software update and but did not finish. Long story short, the touchbar on this device has some kind of a short, so after unplugging it, I was able to install the OS on it, when I found out that it is also MDM locked by his company. I tried changing the serial number on the ROM by only changing a couple of digits of the original serial number. Now after installing the ROM back, the Macbook appears dead = DFU mode. When I...
                                            05-15-2023, 06:46 AM
                                          • Manlikeissak
                                            M1 MacBook EFI/FMM unlock
                                            by Manlikeissak
                                            Hello everyone hope you all are doing well, I'm posting here since no was interested in my post on "MacBook unlocked!" Topic, so In short I have found a way to test every possible key combination to try and find the combination to open the terminal on fmm/EFI locked M1/M2 machines, the person who found this still refuses to give info, but if hasn't lied about it being a key combination there's a chance we might find it, so to try Evey key combination I've got a digispark attiny 85 which is a small μController, I've written as script to emulate a keyboard and go thru every possible key...
                                            07-02-2024, 11:28 AM
                                          • tobeend
                                            Bypass iCloud MACBOOK t2 iBridge older 7.0
                                            by tobeend
                                            Does anyone know any solution to bypass the older iBridge?
                                            because everyone now offers bypass only 7.2 and 7.4 as they are not so stable and I don't want to update from 5.5 to 7.5
                                            Please suggest a way out of the situation
                                            05-26-2023, 07:32 AM
                                          • Loading...
                                          • No more items.
                                          Working...