Forum RSS Feed Follow @ Twitter Follow On Facebook

Thread Rating:
  • 11 Vote(s) - 4.64 Average
  • 1
  • 2
  • 3
  • 4
  • 5
[-]
Welcome
You have to register before you can post on our site.

Username:


Password:





[-]
Latest Threads
[REQUEST] Acer Aspire E1-531(G) BIOS Unl...
Last Post: AlbertWesker
Yesterday 04:13 PM
» Replies: 104
» Views: 85568
Clevo P775TM1-G BIOS
Last Post: kiratdeluxe
Yesterday 07:30 AM
» Replies: 163
» Views: 147511
Could the ASUS P6T Deluxe be given UEFI ...
Last Post: matthewacbroad
08-23-2026 08:29 AM
» Replies: 0
» Views: 146
PD50SNE-G clevo bios unlock request
Last Post: secretciph3r
08-23-2026 06:04 AM
» Replies: 0
» Views: 197
[Request] Dell 7559 bios fully unlocked
Last Post: RedDeam
08-21-2026 02:20 PM
» Replies: 26
» Views: 33100
Core2Extreme X9000 running amazing on an...
Last Post: Hin
08-21-2026 05:45 AM
» Replies: 2
» Views: 3471
Looking for virgin/clean dev BIOS for HP...
Last Post: Smarty
08-21-2026 04:08 AM
» Replies: 0
» Views: 232
[REQUEST] Lenovo G500 (78CNxxWW) Whiteli...
Last Post: steven1801_
08-21-2026 03:29 AM
» Replies: 1234
» Views: 672419
[REQUEST] Lenovo Ideapad Gaming 3-15ACH6...
Last Post: openg664
08-19-2026 05:35 AM
» Replies: 7
» Views: 9778
[SOLVED] Lenovo E545 (HRETxxWW) WiFi + B...
Last Post: Dudu2002
08-17-2026 01:12 PM
» Replies: 270
» Views: 170568
AMI BIOS modding nvme-boot
Last Post: marktuan
08-17-2026 07:12 AM
» Replies: 1
» Views: 3370
Dell Precision 3490 qwery about dell eps...
Last Post: krzysztoft1
08-17-2026 05:03 AM
» Replies: 0
» Views: 424
[REQUEST] Alienware M15 R7 i7-12700H BIO...
Last Post: stapaible
08-17-2026 04:03 AM
» Replies: 1
» Views: 1743
Bloqueo de bios de Acer aspire 5 15 a515...
Last Post: Emewhi
08-16-2026 12:52 PM
» Replies: 0
» Views: 430
[REQUEST] HP Pavilion dv6-3110ST (XR556E...
Last Post: AhmetBaki
08-15-2026 06:27 PM
» Replies: 0
» Views: 485
Asus Prime Q370M-C: Remove The Password
Last Post: DeathBringer
08-15-2026 11:29 AM
» Replies: 2
» Views: 2121
[REQUEST] Lenovo ThinkCentre M93p Tiny (...
Last Post: Route66Fan
08-15-2026 03:31 AM
» Replies: 58
» Views: 71637
[REQUEST] Lenovo G700 (7ACNxxWW) Whiteli...
Last Post: ManulSibirskiy
08-14-2026 06:22 PM
» Replies: 168
» Views: 120502
[REQUEST] Lenovo Thinkpad T440p (GLETxxW...
Last Post: tsounoi
08-14-2026 01:46 PM
» Replies: 533
» Views: 360380
[REQUEST] Lenovo Thinkpad X230(i) (G2ETx...
Last Post: CK1968
08-13-2026 10:48 AM
» Replies: 1098
» Views: 768770

(UEFI) Dell XPS 15z L511z modded BIOS - and HOWTO
I'll check my original file & let you know Smile

Oh and first post amended - thank you for the reminder!
find
quote
Update: here is the hex string search...

Searching for: 29020A82458A

C:\PhoenixTool\DellA12\DUMP\DUMP\166CD554-8AAE-4617-8FDD-A2E3A5AFD89E_1_1056.ROM: 2
C:\PhoenixTool\DellA12\DUMP\DUMP\4A538818-5AE0-4EB2-B2EB-488B23657022_0_4.ROM: 14
C:\PhoenixTool\DellA12\DUMP\DUMP\CFEF94C4-4167-466A-8893-8779459DFA86_1_1048.ROM: 12
find
quote
oh, relating that hex search, I found 14 at my

4A538818-5AE0-4EB2-B2EB-488B23657022_0_4.rom module

however, all of them are 01 (already enabled I guess)
well, we can try also set some of them 00, maybe some of the menus need to make the condition false to be showed, idk.

there must be something else we are missing, those interesting OC and advanced boot mode strings arent there by mistake, also if we are able to boot the built in EFI shell it would be nice Wink
find
quote
My understanding is that these menus are only enabled via ME registers, unless CodeRush and TW have some other ideas?
find
quote
Probably just ME, or in other words - platform features. These are advanced features that appear in the bios when some conditions are met. So these entries are enabled, but are not visible due to lack of support from the hardware part.. like @jkbuha said originally while we were still hunting for advanced menus and @HairyCube was lurking around inside the AdvancedSetup module.

I for example don't get any battery information in bios, while you @jkbuha seem to have some sort of string related to battery status I believe.. and also the RST, which appears only in crisis boot mode .. ?
find
quote
Yes that's correct @TimeWalker. I'm still stumped why the 15z gets RST only in crisis boot mode. But to your point this is another example of condition-based triggers. Only in Crisis mode does the RST menu enable itself, which clearly shows that we've unlocked all the available menus, and there just need to be an additional set of conditions from hardware (registers) to enable them in the BIOS.

So it looks like we're going to have to dig deeper into the ME region if we are to unlock any overclocking/undervolting...
find
quote
then it looks we are moving again to ME firmware tweaking

even we were unable to move to the ME8 firmware, there are some tweaks we can do at the ME7 firmware, like enable OC

http://forum.techinferno.com/general-not...ptops.html

I think I am going to continue with the suggestions from that topic since I already have the descriptor unlocked and fptw64

I think dumping and editing the current ME image from the laptop should be a good choice Smile

jkbuha, did you also updated the me firmware? I think I dont have the original firmware wich came with the xps 15, however I feel lucky the update package I made didnt screwed the me. so I will work with the updated image.

I attached the fptw64.exe (untouched) of my l502x at this post

(parameters to make the dump are fptw64.exe -ME -d dumpfilename.bin)

did you guys had luck unlocking your descriptor by tweaking the byts or doing the bypass hack on the chip mentionated before by TW and CR?

edit, it looks like I am able to dump or flash the whole chip image from windows with fptw64 if I dont specify a region, that will save me some time taking appart the machine to use the hardware programmer if the machine is not in a bricked status ^^

fptw64 is also really fast to make the dump, like 1 second compared with the 3 mins from the hardware programmer, lol

oh, it seems both dumps are different, not sure if ftpw64 skiped something :o

here are both dumps if you want to compare them.

HW programer dump and fptw64 dump to compare.


Attached Files
.zip   L502X_ME.zip (Size: 558.63 KB / Downloads: 4)
find
quote
mmm tried to open my ME backup with fitc version 8.xxxx , it doesnt even open

tried to open it with version 7.xxxx, it opens fine and it shows "clock source select" as 0x00011A33

so theorically it is posible to hack it acording with this topic

http://forum.techinferno.com/general-not...ptops.html

however I keep getting the following error while trying to build the image (compacted image option already selected) Sad

[Image: errorfo.png]

I remember Tw managed somewhere to skip that error when building the image (I wish I know how Big Grin)

then he sent me the image, I flashed with fptw64, and it caused a big brick.

I thing it is related fptw64 doesnt integrate it at all correctly.

so, it would be posible reintegrate manually like tw tried with the ME8 firmware.

here is it.

http://www.mediafire.com/?byesk5xfqmsbyo4
I am going to get the ME region directly from my bios backup without using fptw64.

acording with what TW said those are the regions

— Flash Devices —

W25Q32BV ID:0xEF4016

Size: 4096KB (32768Kb)

00000000h – 00000FFFh: Flash Descriptor Region

00001000h – 00037FFFh: Common ME Header

00038000h – 0017FFFFh: ME Region

00180000h – 003FFFFFh: BIOS Region

so, if I am right, it would be as easy as selecting
00038000h – 0017FFFFh: from my whole bios backup and saving it as new file, right?

reintegrate the modded ME image would be similar, probably.

let me know what do you guys think

edit: tried opening 00038000h – 0017FFFFh hex part with fitc and it does not work, it seems I did something wrong?

maybe I should include the header too??

00001000h – 00037FFFh: Common ME Header

00038000h – 0017FFFFh: ME Region


so from 00001000h to 0017FFFFh?
find
quote
IIRC I took your dump and cut the ME part out, it allowed me to change stuff on it through FITC.
find
quote
yeah, I managed to get it working now too

the magic thing was so from 1000 to 17FFFF

however I compared the hex obtained dump from the whole backup from the programer, and it is different than the me region dumped from fptw64

what is going on with fptw64? :o

I think I am going to work now only with my programer dumps instead fptw64, I simply dont trusth that,I think caused the brick some time ago by writting on other sections like you said

the fact is that my programmer unbrick my laptop and fptw64 bricks it Big Grin


in the other hand, yeah, the total backup 1000 to 17FFFF is editable with fitc.

but sill getting that annoying error while building it.

can you tell me how do you managed to build it?

any chance you can upload your fitc folder?

maybe my version isnt working properly :/
find
quote


Forum Jump:


Users browsing this thread: 18 Guest(s)