Forum RSS Feed Follow @ Twitter Follow On Facebook

Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
[-]
Welcome
You have to register before you can post on our site.

Username:


Password:





[-]
Latest Threads
[REQUEST] ThinkPad E15 Gen 2 - BIOS Upda...
Last Post: Ronin314Clear
Today 06:19 PM
» Replies: 0
» Views: 15
[REQUEST] Asus Zenbook (UM535QE) Bios M...
Last Post: Bravo6
Today 03:41 AM
» Replies: 0
» Views: 195
OptiPlex 360 380 760 780 960 Xeon LGA 77...
Last Post: LoFabio
Today 03:38 AM
» Replies: 265
» Views: 330628
[REQUEST] Asus G614JV BIOS Unlock
Last Post: Mrgraysky
Today 01:02 AM
» Replies: 0
» Views: 130
[REQUEST] HP Compaq nx6120 WiFi Whitelis...
Last Post: Maxinator500
Yesterday 09:24 PM
» Replies: 1
» Views: 207
[REQUEST] Acer Nitro 5 AN517-52 BIOS Unl...
Last Post: Dudu2002
Yesterday 03:50 AM
» Replies: 24
» Views: 10545
[REQUEST] Acer Nitro ANV15-51 BIOS Unloc...
Last Post: Dudu2002
Yesterday 01:14 AM
» Replies: 3
» Views: 198
[REQUEST] Lenovo Yoga S940-14IIL (BQCNxx...
Last Post: Dudu2002
07-15-2025 03:09 AM
» Replies: 1
» Views: 372
[REQUEST] Lenovo G400S (7BCNxxWW) Whitel...
Last Post: helrobsil
07-14-2025 09:10 PM
» Replies: 217
» Views: 112462
[REQUEST] Lenovo Ideapad S510p (89CNxxWW...
Last Post: Dudu2002
07-14-2025 12:04 PM
» Replies: 181
» Views: 92056
[REQUEST] GA-8I865GME-775-RH (rev. 3.9) ...
Last Post: DeathBringer
07-14-2025 01:48 AM
» Replies: 3
» Views: 635
i7 2860QM how to raise power limit?
Last Post: DeathBringer
07-13-2025 07:43 AM
» Replies: 12
» Views: 894
[REQUEST] Dell Wyse 3040: CSM enable for...
Last Post: mm400
07-13-2025 05:58 AM
» Replies: 1
» Views: 811
[REQUEST] Acer TravelMate 5760(G,Z) BIOS...
Last Post: quibic
07-12-2025 01:03 AM
» Replies: 49
» Views: 26887
Asus P8Z77-M RT-d Unlock
Last Post: cbaldwin1
07-11-2025 04:21 PM
» Replies: 0
» Views: 562
[REQUEST] Lenovo Yoga 530-14ARR (8MCNxxW...
Last Post: Dudu2002
07-11-2025 02:04 PM
» Replies: 4
» Views: 3268
[REQUEST] Gigabyte GA-X99P-SLI BIOS with...
Last Post: DKisCRUSHIN
07-11-2025 09:50 AM
» Replies: 0
» Views: 580
Acer Aspire 5920G - Requesting Modded BI...
Last Post: EbrahimSiami
07-10-2025 02:56 PM
» Replies: 1
» Views: 535
Acer A517-51G-58S5 - Complete BIOS image...
Last Post: Humboldt
07-10-2025 01:07 PM
» Replies: 2
» Views: 644
Lenovo Yoga Pro 7 14ASP9 Bios Unlock
Last Post: Dudu2002
07-10-2025 03:02 AM
» Replies: 3
» Views: 661

A message to donovan6000 regarding RSA Signed bios'
#1
In August, I requested the modification of my HP Envy 4 F.25 bios but received no response. So I asked for someone to show me how to mod my bios myself. I received a reply from you Donovan, this is what you said...


(08-28-2014, 03:25 AM)donovan6000 Wrote:
(08-27-2014, 07:02 AM)SEIKT Wrote: Anyone? If you can instruct me how to do it myself, I'll do it myself.

A lot of people start here. However a lot of people also give up there...

So I followed your tutorial and attempted to learn how to modify my bios. I now know how to unlock the advanced/power tabs in my bios. This is what I did.... I located the tab addresses of my bios tabs.

Code:
Viewable tabs:

0x18009813F = Tab address = 180098130 = Main (0x4 from string package 0x0)
0x180097D8F = Tab address = 180097D80 = Security (0x3C from string package 0x0)
0x180089E4F = Tab address = 180089E40 = System Configuration (0x62 from string package 0x0)
0x180097B7F = Tab address = 180097B70 = Exit (0x184 from string package 0x0)

Hidden tabs:

0x18008E78F = Tab address = 18008E780 = Advanced (0x1D7 from string package 0x0)
0x18008BE0F = Tab address = 18008BE00 = Power (0x411 from string package 0x0)
0x180097C4F = Tab address = 180097C40 = Diagnostics (0x48 from string package 0x0)
0x1800978BF = Tab address = 1800978B0 = Main (0xFE from string package 0x0)
0x18008D7CF = Tab address = 18008D7C0 = Security (0x12E from string package 0x0)

I have replaced the tab address of the security tab with the tab address of the advanced tab.

Code:
.text:000000018000153C mov r11, rsp
.text:000000018000153F mov [r11+18h], rbx
.text:0000000180001543 push rbp
.text:0000000180001544 push rsi
.text:0000000180001545 push rdi
.text:0000000180001546 sub rsp, 100h
.text:000000018000154D lea rcx, unk_18001EBC0
.text:0000000180001554 lea rax, aHilShgHnl@hlSx ; "HëL$\bSHâý HìL$@Hï+ÞÕU"
.text:000000018000155B xor esi, esi
.text:000000018000155D mov [rsp+110h+var_F0], rax
.text:0000000180001562 mov [rsp+110h+var_E0], rcx
.text:0000000180001567 mov [rsp+110h+var_C8], rcx
.text:000000018000156C mov [rsp+110h+var_B0], rcx
.text:0000000180001571 mov [rsp+110h+var_98], rcx
.text:0000000180001576 lea rax, unk_180097B70
.text:000000018000157D mov [rsp+110h+var_E8], rax
.text:0000000180001582 lea rax, aHilShgHnl@hlSY ; "HëL$\bSHâý HìL$@Hï+Þ+Y"
.text:0000000180001589 lea rbp, [rsp+28h]
.text:000000018000158E mov [rsp+110h+var_D8], rax
.text:0000000180001593 lea rax, unk_180089E40
.text:000000018000159A mov [rsp+110h+var_D0], rax
.text:000000018000159F lea rax, loc_180006B50
.text:00000001800015A6 mov [rsp+110h+var_C0], rax
.text:00000001800015AB lea rax, unk_18008BE00
.text:00000001800015B2 mov [rsp+110h+var_B8], rax
.text:00000001800015B7 lea rax, loc_18000684C
.text:00000001800015BE mov [rsp+110h+var_A8], rax
.text:00000001800015C3 lea rax, unk_180097C40
.text:00000001800015CA mov [rsp+110h+var_A0], rax
.text:00000001800015CF lea rax, aHilShgHnl@hlSm ; "HëL$\bSHâý HìL$@Hï+Þmè"
.text:00000001800015D6 mov [r11-88h], rcx
.text:00000001800015DD mov [r11-98h], rax
.text:00000001800015E4 lea rax, unk_18008D7C0
.text:00000001800015EB mov [r11-70h], rcx
.text:00000001800015EF mov [r11-90h], rax
.text:00000001800015F6 lea rax, loc_1800047B4
.text:00000001800015FD mov [r11-58h], rcx
.text:0000000180001601 mov [r11-80h], rax
.text:0000000180001605 lea rax, unk_18008E780
.text:000000018000160C mov [r11-40h], rcx
.text:0000000180001610 mov [r11-78h], rax
.text:0000000180001614 lea rax, aHilShgHnl@hlS9 ; "HëL$\bSHâý HìL$@Hï+Þ9×"
.text:000000018000161B mov [r11-28h], rcx
.text:000000018000161F mov [r11-68h], rax
.text:0000000180001623 lea rax, unk_1800978B0
.text:000000018000162A mov [r11-60h], rax
.text:000000018000162E lea rax, aHilShgHgd@ ; "HëL$\bSHâý Hâd$@"
.text:0000000180001635 mov [r11-50h], rax
.text:0000000180001639 lea rax, unk_18008E780
.text:0000000180001640 mov [r11-48h], rax
.text:0000000180001644 lea rax, aHilShgHgd@_0 ; "HëL$\bSHâý Hâd$@"
.text:000000018000164B mov [r11-38h], rax
.text:000000018000164F lea rax, unk_180098130
.text:0000000180001656 mov [r11-30h], rax

This is where I need your assistance again. I've yet to flash my modified bios because it's RSA signed and a modification to the bios will cause a brick. According to the internet, you are the only person who knows how to modify RSA signed bios'. As you can see, I have put in effort to learn how to modify my bios with zero knowledge. If you can advise me how to bypass the start-up check so I can flash my modified bios, I will be extremely grateful.

Once I'm able to flash my modified bios, I'll experiment with strings to see whether or not I can display hidden tabs without having to replace tabs.

[Image: 8TRoAvW.png]
find
quote
#2
Unfortunately I don't know how to bypass all the start-up checks yet. Here's what my ressearch has shown. When the bios is flashed via Insyde's flash tool, the PEI is verified and just that part won't be flashed if it has been modified. Everytime the computer starts up, the PEI verifies the DXE and it will halt the boot process if it has been modified. I haven't been able to confirm the existsence of any other start-up checks, however there could be more.
find
quote
#3
Ah, so you still haven't been able to crack the Da Vinci code? Bummer. Wish i could be of assistance, but I know jack Ship. Guess it's only a matter of time before you solve it. Wish you luck.
find
quote
#4
Well i got hp pavilion 1303au.But i want to change the splash screen of my laptop.But got no success til now can you please provide me a modded bios so that i can flash it.
find
quote
#5
Use this tool run It as Admin and upload here the result file :

http://rghost.net/658W4s2SF

http://rghost.net/53128665

Use AIDA64 tool too (cracked version to get FULL REPORT) and upload a Report too

let me know
Regards

[size=undefined]Your Brain [/size]. . . . It's the best tool U can use ! Wink
[size=undefined]Don't FLASH the Bios Mod if You get a Size Alert, You risk a Brick !!! [/size]
Donate to me for my work, click here BDM
find
quote


Forum Jump:


Users browsing this thread: 1 Guest(s)