We're hiring! Apply Now

Hovatek Forum MOBILE Android MT8167 non secure device

MT8167 non secure device

MT8167 non secure device

LEENO
LEENO
LEENO
Newbie
2
08-02-2023, 11:56 AM
#1



Hallo i have china tablet cpu mt8167
i have full rom dump and boot1 4mb dump renamed in preloader.bin. Dumps done when device was working

After device war full erased, now can't restore it because not have factory preloader.

Possible to restore full dump without factory preloader?




[Image: 1.jpg]

[Image: 2.jpg]

log when device was working:

============ DRAM Flip Test ============

DRAM Size = 0x40000000 (1024MB/8192Mb)

[FLIP]0% have test offset: 0x00000000
[FLIP]0% have test offset: 0x00A00000
[FLIP]1% have test offset: 0x01400000
[FLIP]2% have test offset: 0x01E00000
[FLIP]3% have test offset: 0x02800000
[FLIP]4% have test offset: 0x03200000
[FLIP]5% have test offset: 0x03C00000

-----------------------------------------------------------------
● Board F716U
● Android Ver 11 (Red Velvet Cake)
● Sec Patch 2021-06-05
● Build Type user
● Hardware mt8168
● Device State locked
● VerifiedBootState green
● Flash_locked 1
● Veritymode enforcing
● CryptState encrypted
● CryptType File Based Encryption (FBE) is present.
● SDKVer 30
● FRP Pst /dev/block/platform/bootdevice/by-name/frp
PGPT:TongueartName proinfo Offset:0x80000 Length:0x300000
PGPT:TongueartName boot_para Offset:0x380000 Length:0x100000
PGPT:TongueartName cam_vpu1 Offset:0x480000 Length:0xf00000
PGPT:TongueartName cam_vpu2 Offset:0x1380000 Length:0xf00000
PGPT:TongueartName cam_vpu3 Offset:0x2280000 Length:0xf00000
PGPT:TongueartName nvram Offset:0x3180000 Length:0x500000
PGPT:TongueartName ITEMS Offset:0x3680000 Length:0x100000
PGPT:TongueartName protect1 Offset:0x3780000 Length:0xa00000
PGPT:TongueartName protect2 Offset:0x4180000 Length:0xa00000
PGPT:TongueartName persist Offset:0x4b80000 Length:0x3000000
PGPT:TongueartName nvcfg Offset:0x7b80000 Length:0x800000
PGPT:TongueartName seccfg Offset:0x8380000 Length:0x40000
PGPT:TongueartName lk Offset:0x83c0000 Length:0x200000
PGPT:TongueartName lk2 Offset:0x85c0000 Length:0x200000
PGPT:TongueartName boot Offset:0x87c0000 Length:0x2000000
PGPT:TongueartName recovery Offset:0xa7c0000 Length:0x2000000
PGPT:TongueartName para Offset:0xc7c0000 Length:0x80000
PGPT:TongueartName logo Offset:0xc840000 Length:0x800000
PGPT:TongueartName dtbo Offset:0xd040000 Length:0x800000
PGPT:TongueartName expdb Offset:0xd840000 Length:0xa00000
PGPT:TongueartName frp Offset:0xe240000 Length:0x100000
PGPT:TongueartName tee1 Offset:0xe340000 Length:0x500000
PGPT:TongueartName tee2 Offset:0xe840000 Length:0x500000
PGPT:TongueartName kb Offset:0xed40000 Length:0x200000
PGPT:TongueartName dkb Offset:0xef40000 Length:0x200000
PGPT:TongueartName metadata Offset:0xf140000 Length:0x2000000
PGPT:TongueartName nvdata Offset:0x11140000 Length:0x400000
PGPT:TongueartName vbmeta Offset:0x11540000 Length:0xb40000
PGPT:TongueartName vbmeta_system Offset:0x12080000 Length:0x400000
PGPT:TongueartName vbmeta_vendor Offset:0x12480000 Length:0x400000
PGPT:TongueartName md_udc Offset:0x12880000 Length:0x1400000
PGPT:TongueartName super Offset:0x13c80000 Length:0xa8000000
PGPT:TongueartName cache Offset:0xbbc80000 Length:0x7000000
PGPT:TongueartName userdata Offset:0xc2c80000 Length:0x2e2f7b000
-------------------------------------------------------------------------------------------------

PTFN : MediaTek USB Port (COM53)
MODE : BOOTROM
PORT : 53
Waiting BOOT ack ...
BROM : Skip ACK verify
BROM : Init BROM
BROM init passed!
    CHIP : MT8167 , SBID : 0x8A00 , HWVR : 0xCB00 , SWVR : 0x0001
    TYPE : MODERN RAPHAEL
BROM : MEID : 96CC4C9C4E7B03D1C3A26048A76A8F3E
BROM : SecLevel : 0x000000E0
BROM : SecMode  : EXT
BROM : BROM|BL  : 0x05|0xFE
BROM : BOOTROM
MODE : 0_LINO : MT8167\MIOTAB 2017 | Manual : Disabled
AGENT : Look for suitable BootChain in DA ...
AGENT : MTK_AllInOne_DA.bin
AGENT : Found MT8167
AGENT : MTK_DOWNLOAD_AGENT
    BROM : Sending 1st DA ...
BROM : DA sent
BROM :Transfer control to DA ...
    DA : AGENT started!
DA : SYNC
    DA : MODE : BROM
DA : EXT_RAM NOT initialized!
    EMI : DEV : MT8167
    EMI : SRC : preloader_m710.bin
    EMI : CNT : 0001
EMI : [00] : DRAM : LP_DDR3 : ID : NOT_DEFINED : VEN : UNKNOWN  | DEV :  : RAM : [ 1,00 GB ]
    EMI : Init EMI from PRELOADER
    EMI : EXT_RAM CFG Passed!
DA : BOOT to 2nd DA ...
DA : 2ND stage confirmed!
DA : SYNC with DA passed!
DA : Receiving HW info

        SRAM: 0x00038000 [ 224,00 KB ]
        DRAM: 0x40000000 [ 1,00 GB ]

        EMMC: 15010041574D4233520196FDBC42B187
        EMMC: VEN : SAMSUNG | OEM : 01 | DEV : AWMB3R
        EMMC:
              BOOT1  : 0x00400000 [ 4,00 MB ]
              BOOT2  : 0x00400000 [ 4,00 MB ]
              RPMB  : 0x00400000 [ 4,00 MB ]
              USER  : 0x3A3E00000 [ 14,56 GB ]

        CHIP : MT8167 , SBID : 0x8A00 , HWVR : 0xCB00 , SWVR : 0x0000 , EVOL : 0x0000

        RNID : 29C2849F493462C7D3B02E575ACA780E

DA : USB : FULL-SPEED
DA : USB : Change Port Speed
PTFN : MediaTek DA USB VCOM (Android) (COM59)
MODE : PRELOADER PORT
PORT : 59

Boot done!

SmartInfo : 0x805657

Format Ok : USERDATA
Format Ok : CACHE
Format Ok : RESET PROTECTION
Format Ok : USERDATA

Done!
maxpayne
maxpayne
maxpayne
Intern
4,288
09-02-2023, 02:07 PM
#2
(08-02-2023, 11:56 AM)LEENO .
Done!

You need to analyze and extract preloader from the raw dump
check WWR https://www.hovatek.com/forum/thread-21970.html

Note!
We have a reply schedule for Free Support. Please upgrade to Private Support if you can't wait.
LEENO
LEENO
LEENO
Newbie
2
09-02-2023, 02:23 PM
#3
(09-02-2023, 02:07 PM)maxpayne
(08-02-2023, 11:56 AM)LEENO .
Done!

You need to analyze and extract preloader from the raw dump
check WWR https://www.hovatek.com/forum/thread-21970.html


[Image: 1.jpg]

[Image: 2.jpg]
Users browsing this thread:
 1 Guest(s)
Users browsing this thread:
 1 Guest(s)
Join us
WhTlYt