Forum RSS Feed Follow @ Twitter Follow On Facebook

Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
[-]
Welcome
You have to register before you can post on our site.

Username:


Password:





[-]
Latest Threads
[REQUEST] Lenovo ThinkPad Edge E330 (H3E...
Last Post: kolnew
Today 08:48 AM
» Replies: 653
» Views: 424169
Dell Optiplex 5070 SFF i9 9900K
Last Post: DeathBringer
Today 01:43 AM
» Replies: 4
» Views: 3560
Extracting BIOS - Samsung Galaxy Book 3 ...
Last Post: mirroreduser
10-02-2026 09:12 AM
» Replies: 0
» Views: 222
[REQUEST] HP Pavilion g6-1b87cl WiFi Whi...
Last Post: AkiNakano6055
10-02-2026 12:32 AM
» Replies: 0
» Views: 165
Asrock Z890-C Bios Mod
Last Post: xul8tr
10-01-2026 12:51 PM
» Replies: 0
» Views: 254
[REQUEST] Lenovo G580 (5ECNxxWW) Whiteli...
Last Post: frozik1990
10-01-2026 11:55 AM
» Replies: 1735
» Views: 1223818
[REQUEST] Acer Aspire VN7-791(G) BIOS Un...
Last Post: Whiter
10-01-2026 06:19 AM
» Replies: 92
» Views: 119104
Modifying Aptio V BIOS to disable non-fa...
Last Post: KappaDev
09-30-2026 09:16 PM
» Replies: 0
» Views: 237
[Unlocked] Acer Aspire One D255E
Last Post: ananinami
09-29-2026 01:26 PM
» Replies: 3
» Views: 6741
FANPEEC S210 i9-10980HK
Last Post: geometryczny@tlen.pl
09-29-2026 07:14 AM
» Replies: 0
» Views: 356
[REQUEST] Lenovo Z410 & Z510 (8DCNxxWW) ...
Last Post: anntoxx
09-28-2026 02:28 PM
» Replies: 504
» Views: 309521
[REQUEST] Lenovo Y70-70 (9ECNxxWW) White...
Last Post: Dooglas
09-27-2026 11:31 AM
» Replies: 92
» Views: 61906
[REQUEST] Lenovo E31-70 (AFCNxxWW) BIOS ...
Last Post: kristian6237455372
09-27-2026 11:04 AM
» Replies: 2
» Views: 569
[REQUEST] HP dv6-6c51ca whitelist remova...
Last Post: johnyn2005
09-26-2026 12:52 PM
» Replies: 20
» Views: 20223
[REQUEST] Lenovo B590 (H5ETxxWW) Whiteli...
Last Post: katri
09-26-2026 02:03 AM
» Replies: 281
» Views: 169161
[Request] Dell Optiplex 3040M 7th Gen CP...
Last Post: DeathBringer
09-25-2026 12:35 AM
» Replies: 10
» Views: 6267
[Untested] Dell OptiPlex 3040 H110 – Cof...
Last Post: gonza20889
09-23-2026 02:02 PM
» Replies: 0
» Views: 772
[REQUEST] Acer TravelMate B113-E BIOS Un...
Last Post: rt400
09-22-2026 07:39 AM
» Replies: 9
» Views: 5739
[REQUEST] Acer Aspire 8930(G) BIOS Unloc...
Last Post: xeper8x8
09-21-2026 10:04 PM
» Replies: 59
» Views: 61118
How To Add SLIC 2.1 To An Intel Motherbo...
Last Post: Argogo
09-21-2026 11:15 AM
» Replies: 75
» Views: 274953

[Request] ThinkPad T470 AES-NI Unlock
#11
OK. I need such screenshot from your friend.
find
quote
#12
Hi, any update on this topic cause I'm also intrested in it.
In my case I own a Chinese version 3rd gen S1 which is the counter part of Yoga 370, with AES-NI disabled.
I've successfully changed the model number to the Yoga 370 one using the HMD usb key, which OP suspects to be the controlling flag.
The result is underwhelming though, AES-NI is still disabled.
So I'm really intrested in what the real magic switch DeathBringer discovered is.
Anyway I'm posting the memory dump at FF89D000 in my box, it may be useless, but just in case.
   
find
quote
#13
veewus
Have you a hardware programmer?
Describe how you "changed the model number".
find
quote
#14
(11-18-2017, 02:28 AM)DeathBringer Wrote: veewus
Have you a hardware programmer?
Describe how you "changed the model number".

Thanks for the reply Smile.
I do not have a hardware programmer, Lenovo has official service tool for the propose.
See this reddit topic. After changing the model number successfuly in this service tool, I can verify it in the BIOS.
find
quote
#15
1. Download original COMMAND.COM from IBM PC DOS 5.0.
2. Put it in HMD usb stick (with replacement).
3. Boot up with HMD usb stick.
4. Type serupdt S data.bin and press Enter.
5. Make a photo of the result.
6. Reboot in Windows and upload data.bin file from HMD usb stick.
find
quote
#16
Replaced the COMMAND.COM file as instructed, but the HMD disk boots to the same interface as before:
   
I'm suspecting it's because I booted with the EFI mode?
For reference I dumped the HMD usb key content as VHD.
Anyway from your instructions I'm guessing that you requested the EEPROM dump, so I made one using the 5th function in the HMD.
My system unit SN is replace with string SERIALNO in this dump. And since changing the model didn't do the trick, I've already changed it back to original before this dump.

.zip   usbkey_and_eeprom_dump.zip (Size: 910.68 KB / Downloads: 17)
Edit: I think it might also be useful to attatch the SiInit PE image of my bios.

.zip   299D6F8B-2EC9-4E40-9EC6-DDAA7EBF5FD9-SiInit.zip (Size: 76.64 KB / Downloads: 5)
find
quote
#17
(11-18-2017, 12:08 PM)veewus Wrote: I'm suspecting it's because I booted with the EFI mode?
Can you boot in DOS?

Attached EEPROM dump doesn't contains the necessary information. So HMD will not help to change bytes in NVRAM.
(11-18-2017, 12:08 PM)veewus Wrote: I think it might also be useful to attatch the SiInit PE image of my bios.
Replace in your SiInit PE image bytes 74 08 83 E0 FD with 74 00 83 E0 FD.
But you can't flash modded BIOS without a hardware programmer. Ask Dudu2002 for the reason of it.
P.S. But if you had a hardware programmer, you could make it easier - just set two bytes to FF.
find
quote
#18
Wink 
Much appreciated for your help DeathBringer!
I have a job in creating software, not deep down into assembly and hardware though.
So could you help me to clear something up to satisfy my inner curiosity?
Quote:Attached EEPROM dump doesn't contains the necessary information. So HMD will not help to change bytes in NVRAM.
In laptops isn't EEPROM equal to NVRAM? or the HMD dumps/maintains only part of the EEPROM/NVRAM so it's not useful?
In my understanding, since the BIOS provided by lenovo is identical across all models worldwide, it must be some bits in the NVRAM/EEPROM that switchs certain functions on and off. So we can find what's lenovo's magic bit for AES-NI by reverse engineering the BIOS, probably the SiInit module right?
Quote:Replace in your SiInit PE image bytes 74 08 83 E0 FD with 74 00 83 E0 FD.
Could you elaborate a bit more on what's been done here? 
I'm learning to read assembly instructions my self currently, in the aim that finding where the BIOS is reading from EEPROM/NVRAM for the AES-NI control bit, is this approach practical?
Quote:But you can't flash modded BIOS without a hardware programmer. Ask Dudu2002 for the reason of it.
P.S. But if you had a hardware programmer, you could make it easier - just set two bytes to FF.
It's a pitty that I don't have a hardware programmer, plus I don't want to risk damaging the board with my limited hardware knowledge.
If direct programming on the BIOS chip is possible, I think that replacing rmsr to noop is enough right?
And one more question, how did you find out the address FF89D000 and where does it points to? the NVRAM I guess?

Really appreciated for your help and time!
find
quote
#19
(11-18-2017, 10:24 PM)veewus Wrote: In laptops isn't EEPROM equal to NVRAM?
HMD doesn't grant access to necessary part of NVRAM.
(11-18-2017, 10:24 PM)veewus Wrote: Could you elaborate a bit more on what's been done here?
No, I'm not a tutor.
(11-18-2017, 10:24 PM)veewus Wrote: And one more question, how did you find out the address FF89D000 and where does it points to? the NVRAM I guess?
By disassembly modules of BIOS.
find
quote
#20
(11-19-2017, 02:07 AM)DeathBringer Wrote:
(11-18-2017, 10:24 PM)veewus Wrote: In laptops isn't EEPROM equal to NVRAM?
HMD doesn't grant access to necessary part of NVRAM.
(11-18-2017, 10:24 PM)veewus Wrote: Could you elaborate a bit more on what's been done here?
No, I'm not a tutor.
(11-18-2017, 10:24 PM)veewus Wrote: And one more question, how did you find out the address FF89D000 and where does it points to? the NVRAM I guess?
By disassembly modules of BIOS.

Sorry for the noise and thank you for the valuable information.
find
quote


Forum Jump:


Users browsing this thread: 1 Guest(s)