Alexey Kovrizhnykh

46 posts

Alexey Kovrizhnykh

Alexey Kovrizhnykh

@a1exdandy

Saint Petersburg, Russia Katılım Eylül 2016
181 Takip Edilen1.2K Takipçiler
Travis Goodspeed
Travis Goodspeed@travisgoodspeed·
@h0t_max @a1exdandy @offzone_moscow I can follow the power-on-reset trick in the third variant and that the UART peripheral is used with DMA to dump Flash during the race window. Without a recording of the lecture, I'm not quite sure whether this requires a voltage glitch or the glitch was ultimately not required.
English
1
0
2
1.1K
Alexey Kovrizhnykh retweetledi
Alexander Ermolov
Alexander Ermolov@flothrone·
For those who asked, a nice alternative for #ghidra by my colleague @TheJokiv github.com/DSecurity/efiS… @MarcoFigueroa , please check this out :)
Alex Matrosov@matrosov

#efiXplorer v1.0 [REcon Editon] released! We try to make UEFI RE easier, current version of IDA plugin supports: - EFI Protocols and Boot/Runtime Services identification - EFI GUID's recogniton Stay tuned more features coming! github.com/binarly-io/efi… @yeggorv @p41ll @isciurus

English
1
17
27
0
Alexey Kovrizhnykh
Alexey Kovrizhnykh@a1exdandy·
Now ported on S5L8940X and S5L8945X as well Thanks to @nyan_satan for support and testing! PoC will be available tomorrow
Alexey Kovrizhnykh tweet media
English
16
27
119
0
Alexey Kovrizhnykh
Alexey Kovrizhnykh@a1exdandy·
Successfully ported checkm8 to S5L8942X using Arduino with MAX3421E-based USB host shield Many thanks to @nyan_satan for debugging on iPad mini 1 EPVT and testing on production devices PoC will be available soon
Alexey Kovrizhnykh tweet mediaAlexey Kovrizhnykh tweet media
English
32
73
401
0
ゆい
ゆい@haiyuidesu·
Happy (late) Birthday @a1exdandy !♪(๑ᴖ◡ᴖ๑)♪
English
1
0
2
0
Alexey Kovrizhnykh retweetledi
matty
matty@moski_dev·
Thanks to @a1exdandy, there is now #checkm8 support for the 6s! I modified his patch slightly to work on CPID:8000 instead of 8003 as I have an 8000 6s. Expect cool things in the near future ;)
matty tweet media
English
6
24
126
0
Alexey Kovrizhnykh retweetledi
ChiptuneXT
ChiptuneXT@chiptunext·
Apple Watch S0 Bootrom successfully dumped! Big thx for @a1exdandy and @axi0mX eta son
ChiptuneXT tweet media
English
3
24
102
0
synackuk
synackuk@synackuk·
@a1exdandy @nyan_satan Well, that probably answers my question. I was wondering specifically how you ported checkm8 to haywire without an SROM dump, but if you were able to dump it somehow I would love to be able to replicate that for A5
English
1
0
1
0
Alexey Kovrizhnykh
Alexey Kovrizhnykh@a1exdandy·
@synackuk @nyan_satan What exectly? By the way, I plan to publish an article on how it was originally possible to dump SecureROM of Haywire with checkm8 without knowing the pointers to any functions or data. It will be next year
English
1
0
2
0
john
john@nyan_satan·
@a1exdandy HAX: change AES options constants to 0x200 and 0x201 respectively to get decryption/encryption working (checked only GID decryption though)
john tweet media
English
2
0
7
0