I'm working on a Dell Latitude 3410 (Wistron Mockingbird-L, CML platform) that had an 8FC8 admin BIOS password lock. The board has two separate SPI flash chips:
- An 8MB chip (XMC XM25QH64AH1G) containing the Intel Flash Descriptor + ME region
- A 16MB chip (XMC XM25QH128AH1G) containing the main BIOS/UEFI volumes
What I did:
- Dumped both chips using an in-circuit clip (board fully powered off, no battery/adapter connected during read/write)
- Verified both dumps were internally consistent (multiple reads, matching MD5, valid Flash Descriptor signature at 0x10, valid
Leave a comment: