Hi is possible on c series tv to get access of uboot and boot the firmware from usb? with the exlink cable is possile to load a custom firmware and boot it?
or maybe load a decrypt fw to hidden partitions of the tv then activate the partition from shell and reboot the tv with that partitons with a different firmware.
I know that the c series tv as 2 partitions with firmware one is hidden and other is active...the tv boot the tv from active partitions right?
When i downgrade my tv i switch the active partitions from first to second partition and then the tv reboot with the fw versions that i choose maybe i think is possible to load one different sw image instead of a different version of the same sw image.
Boot the firmware from usb and custom fw possible?
Re: Boot the firmware from usb and custom fw possible?
At C serie , it is posible by a way to patch kernel at the point where the task wait for authuld replay, after success patch authuld can be killed, after this point , in rootfs you may mount external usb (ext3/xfs) where you have alredy copy each dirs (exe, appext etc.).
in case of paritions 0/1, right, always switch between them at firmware upgrade, active parition is stored in micom eeprom.
in case of paritions 0/1, right, always switch between them at firmware upgrade, active parition is stored in micom eeprom.
Denny - 데니 - 丹尼 (card2000)
UE55C8000 UE55D8000 UE32D6510 BD-C9600 3xDM8000
Reversing HW Demux Drivers and API from Samsung´s TV
UE55C8000 UE55D8000 UE32D6510 BD-C9600 3xDM8000
Reversing HW Demux Drivers and API from Samsung´s TV
- beatfreak
- SamyGO Project Donor
- Posts: 591
- Joined: Tue Aug 23, 2011 9:03 am
- Location: Hamburg
- Contact:
Re: Boot the firmware from usb and custom fw possible?
This could also be a way to get T-VALDEUC running on T-VAL6DEUC Systems with 128M flash...
modifying the bootloader would be a nice way as aou could avoid complications through already running native OS, but there may also occur problems when external kernel was booted and still trys to access internal flash as we mostly will have to get the USB-OS as romdump from other models, cusom fw will be far away since very much sw in TV-OS is closed source and won't be easy to replace... otherwise we already would have a dvbapi ...
another point to grab it would be the instance that creates the block devices at boot time, if we could modify it to first look on USB for flash... but this would require a large amount of reverse engineering i guess...
next point could be mounting, perhaps there is some kind of config file which controls initial mounting of the flash partitions, perhaps the simpliest way, ...if we ignore the authuld thing...
so as Denny has proposed we'll have to do this at a later point of booting process...
i don't have enough linux experience to try it but maybe it could be possible to move over to an external OS via some kind of chrooting...?
modifying the bootloader would be a nice way as aou could avoid complications through already running native OS, but there may also occur problems when external kernel was booted and still trys to access internal flash as we mostly will have to get the USB-OS as romdump from other models, cusom fw will be far away since very much sw in TV-OS is closed source and won't be easy to replace... otherwise we already would have a dvbapi ...
another point to grab it would be the instance that creates the block devices at boot time, if we could modify it to first look on USB for flash... but this would require a large amount of reverse engineering i guess...
next point could be mounting, perhaps there is some kind of config file which controls initial mounting of the flash partitions, perhaps the simpliest way, ...if we ignore the authuld thing...
so as Denny has proposed we'll have to do this at a later point of booting process...
i don't have enough linux experience to try it but maybe it could be possible to move over to an external OS via some kind of chrooting...?
//UE40C6500 @ T-VALDEUC 3011 // rooted manual HotelMode style // PVR to NFS via 18MB on-the-fly sparse XFS //
FYI: you can close your ssh session with SamyGO with
If you can't fix it using dvct tape, you are not using enough dvct tape.
FYI: you can close your ssh session with SamyGO with
Code: Select all
~.
Re: Boot the firmware from usb and custom fw possible?
Interesting if you need one tester i'm here... maybe we can run android or puppy linux or othe native tv-osbeatfreak wrote:This could also be a way to get T-VALDEUC running on T-VAL6DEUC Systems with 128M flash...
modifying the bootloader would be a nice way as aou could avoid complications through already running native OS, but there may also occur problems when external kernel was booted and still trys to access internal flash as we mostly will have to get the USB-OS as romdump from other models, cusom fw will be far away since very much sw in TV-OS is closed source and won't be easy to replace... otherwise we already would have a dvbapi ...
another point to grab it would be the instance that creates the block devices at boot time, if we could modify it to first look on USB for flash... but this would require a large amount of reverse engineering i guess...
next point could be mounting, perhaps there is some kind of config file which controls initial mounting of the flash partitions, perhaps the simpliest way, ...if we ignore the authuld thing...
so as Denny has proposed we'll have to do this at a later point of booting process...
i don't have enough linux experience to try it but maybe it could be possible to move over to an external OS via some kind of chrooting...?
Re: Boot the firmware from usb and custom fw possible?
Could you explain me how to do this how i can patch the fw to do this?Denny wrote:At C serie , it is posible by a way to patch kernel at the point where the task wait for authuld replay, after success patch authuld can be killed, after this point , in rootfs you may mount external usb (ext3/xfs) where you have alredy copy each dirs (exe, appext etc.).
in case of paritions 0/1, right, always switch between them at firmware upgrade, active parition is stored in micom eeprom.
Re: Boot the firmware from usb and custom fw possible?
You have to disasm exeDSP on IDA, research asm code and make modifications you`ll find. This is called "reverse engineering".
When you have your patches, you have to replace patched exeDSP in exe.img image, calculate proper hashes and flash all to proper partitions or TV.
Or you can make native applications (widget with *.so files), where you could apply your patch - inject code in memmory.
When you have your patches, you have to replace patched exeDSP in exe.img image, calculate proper hashes and flash all to proper partitions or TV.
Or you can make native applications (widget with *.so files), where you could apply your patch - inject code in memmory.
LE40B653T5W,UE40D6750,UE65Q8C
Have questions? Read SamyGO Wiki, Search on forum first!
FFB (v0.8), FFB for CI+ . Get root on: C series, D series, E series, F series, H series. rooting K series, exeDSP/exeTV patches[C/D/E/F/H]
DO NOT EVER INSTALL FIRMWARE UPGRADE
Have questions? Read SamyGO Wiki, Search on forum first!
FFB (v0.8), FFB for CI+ . Get root on: C series, D series, E series, F series, H series. rooting K series, exeDSP/exeTV patches[C/D/E/F/H]
DO NOT EVER INSTALL FIRMWARE UPGRADE