Forum RSS Feed Follow @ Twitter Follow On Facebook

Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
[-]
Welcome
You have to register before you can post on our site.

Username:


Password:





[-]
Latest Threads
Foxconn 865G7MF Pinmodded Xeon Support
Last Post: KSM74
Today 04:47 AM
» Replies: 26
» Views: 3770
[REQUEST] X280 Bios Whitelist Removal
Last Post: Dudu2002
Today 01:37 AM
» Replies: 1
» Views: 383
[REQUEST] Lenovo G510 (79CNxxWW) Whiteli...
Last Post: T_A_o_D
Yesterday 07:35 PM
» Replies: 604
» Views: 421114
[REQUEST] HP dv5 / dv6 ID 1657 sp55068 F...
Last Post: Fredd
Yesterday 02:05 PM
» Replies: 1
» Views: 129
[REQUEST] Lenovo ThinkPad X201 (6QETxxWW...
Last Post: CK1968
08-07-2026 10:10 AM
» Replies: 65
» Views: 53460
[REQUEST] Asus Zephyrus GX701GWR Bios un...
Last Post: Elijah Dannel
08-07-2026 05:23 AM
» Replies: 8
» Views: 3863
[Request] Acer Aspire One 751h Bios Unlo...
Last Post: iggd
08-06-2026 12:51 AM
» Replies: 43
» Views: 41898
IBM Aptiva 2168 (Opti Viper) - CPU-Suppo...
Last Post: Geoman
08-04-2026 02:34 PM
» Replies: 0
» Views: 423
[REQUEST] LGA 771 on old ASUS mobo
Last Post: DeathBringer
08-02-2026 12:10 PM
» Replies: 10
» Views: 932
Advent Roma 2000/ECS I50IL1
Last Post: BootlegScarce
08-01-2026 09:05 PM
» Replies: 2
» Views: 5895
[REQUEST] Lenovo G70-70 BIOS Whitelist R...
Last Post: Dudu2002
08-01-2026 05:34 PM
» Replies: 135
» Views: 112121
[Request] Samsung Galaxy Book2 Pro (P12R...
Last Post: RafaelLVX
08-01-2026 01:18 PM
» Replies: 0
» Views: 443
[REQUEST]NEC Versapro VA-B(PC-VK22EAZCB)...
Last Post: mita-710
08-01-2026 05:49 AM
» Replies: 0
» Views: 429
[REQUEST] HP Pavilion DV6-2170 UEFI Bios...
Last Post: bernat77
07-31-2026 06:07 AM
» Replies: 2
» Views: 526
[REQUEST] Lenovo Thinkpad W540 & W541 (G...
Last Post: Profit21
07-31-2026 05:47 AM
» Replies: 52
» Views: 45523
NEC Versapro VA-B unlock&core 2 extreme ...
Last Post: mita-710
07-30-2026 08:45 PM
» Replies: 14
» Views: 1231
ThinkPad x240 bios corrupted
Last Post: grayreighn
07-30-2026 08:48 AM
» Replies: 2
» Views: 3300
[REQUEST] Lenovo ThinkCentre Edge 91z UE...
Last Post: maver3000
07-30-2026 03:10 AM
» Replies: 0
» Views: 535
[QUESTION] Modding an AMI bios to bypass...
Last Post: Machida96
07-29-2026 03:52 PM
» Replies: 11
» Views: 5707
[REQUEST] Acer Nitro 5 AN517-54 BIOS Unl...
Last Post: mistermu
07-29-2026 02:58 PM
» Replies: 30
» Views: 19073

[REQUEST] AMI Aptio BIOS password Advantech UNO-1372G-J (UNOB-2117MB)
#1
Hello everyone,

I'm stuck on a BIOS password issue on an industrial embedded PC and would really appreciate some expert eyes on this. I've done what I can with hex editing but I think the real password check is elsewhere in the firmware, beyond my current skill level.

Hardware:

Device: Advantech UNO-1372G-J (industrial fanless PC / OPC)
Motherboard: UNOB-2117MB REV.A1, made in Taiwan, PN 19A3211703-01
CPU: Intel (embedded SoC, soldered)
Main BIOS flash chip: Winbond W25Q64JW (8MB, SOIC-8, 1.8V)

Problem:
The BIOS requires a password at boot/setup entry. Clearing CMOS (battery pull + CN36 clear-CMOS jumper + shorting battery socket V+/V-) has no effect on the password — as expected, since on these AMI Aptio boards it's stored in SPI flash rather than battery-backed CMOS.

What I've tried so far:


Dumped the main BIOS chip (W25Q64JW) via CH341A + 1.8V adapter + SOIC-8 clip. Read 3 times, MD5-verified identical each time.
Located what appears to be the AMI TSE (Total Setup Edition) password-related NVAR variables in the dump:

AMITSESetup NVAR entry (offset ~0x300281) with all-zero data (looks like a "default/empty" instance)
A second AMITSESetup NVAR entry (offset ~0x302931, size 0x68) containing non-zero data — what I assumed to be password hash material (80 bytes, structured as two overlapping ~40-byte sequences)
An OEMDEFAULTPWDSetup NVAR entry (offset ~0x302999) with a single data byte (0x04, later noticed value 0x70 depending on offset interpretation — I may have made an error here)

Tried zeroing the 64 then 80 bytes of the suspected hash data in the second AMITSESetup NVAR — reflashed, no change, password still requested.
Tried invalidating the NVAR entries entirely by changing the state byte from FF FF FF to 3C FF FF on both AMITSESetup and OEMDEFAULTPWDSetup entries — reflashed, verified the re-dump matched the written image exactly (MD5 identical), so the write itself succeeded with no write-protection issue — but the password prompt is still there.

So the chip write/erase/verify cycle works fine (no WP/lock issue), but neither approach neutralizes the actual password check. My guess is either:

The AMITSESetup varstore I found is just the general Setup form storage (all BIOS settings), not specifically the password, and the real password hash is stored/checked elsewhere (different GUID, different NVAR name, or computed by DXE/PEI driver code rather than a plain stored hash)
There's some checksum/CRC over the NVRAM volume that needs to be recalculated after modification, and an invalid checksum causes the driver to fall back to a "locked" state rather than "no password"

What I'm hoping for:


Guidance on identifying the correct NVAR GUID/variable that AMI Aptio uses for password verification, as opposed to general Setup storage
Whether AMIBCP (AMI BIOS Configuration Program) can open/patch this dump properly, since UEFITool NE reports "Stores not found" on this image
Any known quirks specific to Advantech's AMI Aptio implementation


I have the original untouched dump and full change logs for every attempt. Happy to upload the original .bin if that helps, and I can provide any additional dumps/photos of the board on request.

Thanks in advance for any pointers!
find
quote


Forum Jump:


Users browsing this thread: 1 Guest(s)