Home Forum Blog Private Support Courses

My Experience unbricking a dead boot Tecno Pop 7 Pro (BF7)

The device was MediaTek MT6761-powered and running on Android 12 (HiOS). Its build number was BF7-H6127ABCDSTUAdAeAfArAs-S-GL-230719V1237 (this information wasn’t crucial for unbricking although it’s good to always note your software information).

How it got bricked

Its firmware was first dumped using Hydra Tool then its bootloader was unlocked via fastboot (required logging into Tecno ID to enable OEM unlocking) and rooted with Magisk Manager. This unfortunately caused Wi-Fi & Bluetooth to stop working (couldn’t be turned on). The microphone also stopped functioning during phone calls although it worked fine when using the voice recorder and apps like WhatsApp and Telegram.

The boot.img from the firmware was flashed back (to unroot) but same issue. The boot.img and preloader from the dump were then flashed and this caused the device to get stuck in BROM Mode. It wasn’t detected by the PC anymore after a while.

The approach

While we have a collection of DA and Auth. files for Tecno devices and a guide on using SP Flash tool + MTKClient to flash secure boot devices, recent Transsion models like this tend to require an Auth. (local or remote), Preloader Auth. like you would find in paid tools or Carlcare Official Flash Tool. I chose MTKClient (which is a free tool)

The Fix

python mtk.py payload

The objective was simple, flash back the right Preloader to the device. This wasn’t possible using SP flash tool after running the above command because it gave a DA Hash error. Errors in MTKClient caused the USB device not recognized error which only disappeared after leaving the device’s battery to drain completely (you could disassemble and unplug then re-plug the battery to save time).

I then grabbed the Preloader (preloader_bf7_h6127.bin) from the factory firmware and pasted it into the MTKClient folder and ran the command:

python mtk.py w preloader preloader_bf7_h6127.bin --parttype boot1 --preloader=preloader_bf7_h6127.bin

I then held both Volume buttons + Power button and connected (this is only necessary when coming from a drained battery state and not required for a device stuck in BROM Mode).

This was the MTKClient log:

..Port - Device detected :)
Preloader -     CPU:                    MT6761/MT6762/MT3369/MT8766B(Helio A20/P22/A22/A25/G25)
Preloader -     HW version:             0x0
Preloader -     WDT:                    0x10007000
Preloader -     Uart:                   0x11002000
Preloader -     Brom payload addr:      0x100a00
Preloader -     DA payload addr:        0x201000
Preloader -     CQ_DMA addr:            0x10212000
Preloader -     Var1:                   0x25
Preloader - Disabling Watchdog...
Preloader - HW code:                    0x717
Preloader - Target config:              0xe5
Preloader -     SBC enabled:            True
Preloader -     SLA enabled:            False
Preloader -     DAA enabled:            True
Preloader -     SWJTAG enabled:         True
Preloader -     EPP_PARAM at 0x600 after EMMC_BOOT/SDMMC_BOOT:  False
Preloader -     Root cert required:     False
Preloader -     Mem read auth:          True
Preloader -     Mem write auth:         True
Preloader -     Cmd 0xC8 blocked:       True
Preloader - Get Target info
Preloader - BROM mode detected.
Preloader -     HW subcode:             0x8a00
Preloader -     HW Ver:                 0xca01
Preloader -     SW Ver:                 0x200
Preloader - ME_ID:                      E4884188AB966E1162E5B3484E0A39A1
Preloader - SOC_ID:                     C96D13D251A34745EAEA026C3FFD241421A1E9E9FECFCAEE2803D724E3F9E6D1
Preloader
Preloader - [LIB]: ←[33mAuth file is required. Use --auth option.←[0m
DaHandler - Device is protected.
DaHandler - Device is in BROM-Mode. Bypassing security.
PLTools - Loading payload from mt6761_payload.bin, 0x264 bytes
Exploitation - Kamakiri Run
Exploitation - Done sending payload...
PLTools - Successfully sent payload: C:\Users\Enigma\Documents\mtkclient-main\mtkclient\payloads\mt6761_payload.bin
Port - Device detected :)
DAXFlash - Uploading xflash stage 1 from MTK_DA_V5.bin
XFlashExt - Patching da1 ...
Mtk - Patched "Patched loader msg" in preloader
Mtk - Patched "hash_check" in preloader
Mtk - Patched "Patched loader msg" in preloader
Mtk - Patched "get_vfy_policy" in preloader
XFlashExt - Patching da2 ...
XFlashExt - Security check patched
XFlashExt - DA version anti-rollback patched
XFlashExt - SBC patched to be disabled
XFlashExt - Register read/write not allowed patched
DAXFlash - Successfully uploaded stage 1, jumping ..
Preloader - Jumping to 0x200000
Preloader - Jumping to 0x200000: ok.
DAXFlash - Successfully received DA sync
DAXFlash - Sending emi data ...
DAXFlash - DRAM setup passed.
DAXFlash - Sending emi data succeeded.
DAXFlash - Uploading stage 2...
DAXFlash - Upload data was accepted. Jumping to stage 2...
DAXFlash - Boot to succeeded.
DAXFlash - Successfully uploaded stage 2
DAXFlash - DA SLA is disabled
DAXFlash - EMMC FWVer:      0x0
DAXFlash - EMMC ID:         A3A561
DAXFlash - EMMC CID:        d6010341334135363112244e382819a1
DAXFlash - EMMC Boot1 Size: 0x400000
DAXFlash - EMMC Boot2 Size: 0x400000
DAXFlash - EMMC GP1 Size:   0x0
DAXFlash - EMMC GP2 Size:   0x0
DAXFlash - EMMC GP3 Size:   0x0
DAXFlash - EMMC GP4 Size:   0x0
DAXFlash - EMMC RPMB Size:  0x1000000
DAXFlash - EMMC USER Size:  0xe67800000
DAXFlash - HW-CODE         : 0x717
DAXFlash - HWSUB-CODE      : 0x8A00
DAXFlash - HW-VERSION      : 0xCA01
DAXFlash - SW-VERSION      : 0x200
DAXFlash - CHIP-EVOLUTION  : 0x0
DAXFlash - DA-VERSION      : 1.0
DAXFlash - Extensions were accepted. Jumping to extensions...
DAXFlash - Boot to succeeded.
DAXFlash - DA Extensions successfully added
Progress: |██████████| 100.0% Write (0x1E6/0x1E6, ) 1.45 MB/s
Wrote preloader_bf7_h6127.bin to sector 0 with sector count 248812.

Awake at Last

Now that the right Preloader had been flashed, it was time to force the device out of BROM Mode with the command:

python mtk.py plstage --preloader=preloader_bf7_h6127.bin

This was the MTKClient log:

.....Port - Device detected :)
Preloader -     CPU:                    MT6761/MT6762/MT3369/MT8766B(Helio A20/P22/A22/A25/G25)
Preloader -     HW version:             0x0
Preloader -     WDT:                    0x10007000
Preloader -     Uart:                   0x11002000
Preloader -     Brom payload addr:      0x100a00
Preloader -     DA payload addr:        0x201000
Preloader -     CQ_DMA addr:            0x10212000
Preloader -     Var1:                   0x25
Preloader - Disabling Watchdog...
Preloader - HW code:                    0x717
Preloader - Target config:              0xe5
Preloader -     SBC enabled:            True
Preloader -     SLA enabled:            False
Preloader -     DAA enabled:            True
Preloader -     SWJTAG enabled:         True
Preloader -     EPP_PARAM at 0x600 after EMMC_BOOT/SDMMC_BOOT:  False
Preloader -     Root cert required:     False
Preloader -     Mem read auth:          True
Preloader -     Mem write auth:         True
Preloader -     Cmd 0xC8 blocked:       True
Preloader - Get Target info
Preloader - BROM mode detected.
Preloader -     HW subcode:             0x8a00
Preloader -     HW Ver:                 0xca01
Preloader -     SW Ver:                 0x200
Preloader - ME_ID:                      E4884188AB966E1162E5B3484E0A39A1
Preloader - SOC_ID:                     C96D13D251A34745EAEA026C3FFD241421A1E9E9FECFCAEE2803D724E3F9E6D1
Preloader
Preloader - [LIB]: ←[33mAuth file is required. Use --auth option.←[0m
PLTools - Loading payload from mt6761_payload.bin, 0x264 bytes
Exploitation - Kamakiri Run
Exploitation - Done sending payload...
PLTools - Successfully sent payload: C:\Users\Enigma\Documents\mtkclient-main\mtkclient\payloads\mt6761_payload.bin
Port - Device detected :)
Main - Connected to device, loading
Main - Using custom preloader : preloader_bf7_h6127.bin
Mtk - Valid preloader detected.
Mtk - Patched "Patched loader msg" in preloader
Main - Sent preloader to 0x201000, length 0x3cafc
Preloader - Jumping to 0x201000
Preloader - Jumping to 0x201000: ok.
Main - PL Jumped to daaddr 0x201000.
Main - Keep pressed power button to boot.

The battery icon was displayed on the screen; 0% it was. I charged it to 1% then powered up. I got the expected Orange State warning but this didn’t prevent the device from booting to the Home screen.

Conclusion

The Wi-Fi and Bluetooth still can’t be turned on so fixing that will be the next objective.

Leave a Comment

Your email address will not be published. Required fields are marked *

Document
WhTlYt
Scroll to Top