Forum RSS Feed Follow @ Twitter Follow On Facebook

Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
[-]
Welcome
You have to register before you can post on our site.

Username:


Password:





[-]
Latest Threads
[REQUEST] Lenovo ThinkPad Edge E330 (H3E...
Last Post: kolnew
Today 08:48 AM
» Replies: 653
» Views: 424140
Dell Optiplex 5070 SFF i9 9900K
Last Post: DeathBringer
Today 01:43 AM
» Replies: 4
» Views: 3555
Extracting BIOS - Samsung Galaxy Book 3 ...
Last Post: mirroreduser
10-02-2026 09:12 AM
» Replies: 0
» Views: 215
[REQUEST] HP Pavilion g6-1b87cl WiFi Whi...
Last Post: AkiNakano6055
10-02-2026 12:32 AM
» Replies: 0
» Views: 162
Asrock Z890-C Bios Mod
Last Post: xul8tr
10-01-2026 12:51 PM
» Replies: 0
» Views: 250
[REQUEST] Lenovo G580 (5ECNxxWW) Whiteli...
Last Post: frozik1990
10-01-2026 11:55 AM
» Replies: 1735
» Views: 1223763
[REQUEST] Acer Aspire VN7-791(G) BIOS Un...
Last Post: Whiter
10-01-2026 06:19 AM
» Replies: 92
» Views: 119098
Modifying Aptio V BIOS to disable non-fa...
Last Post: KappaDev
09-30-2026 09:16 PM
» Replies: 0
» Views: 235
[Unlocked] Acer Aspire One D255E
Last Post: ananinami
09-29-2026 01:26 PM
» Replies: 3
» Views: 6739
FANPEEC S210 i9-10980HK
Last Post: geometryczny@tlen.pl
09-29-2026 07:14 AM
» Replies: 0
» Views: 352
[REQUEST] Lenovo Z410 & Z510 (8DCNxxWW) ...
Last Post: anntoxx
09-28-2026 02:28 PM
» Replies: 504
» Views: 309507
[REQUEST] Lenovo Y70-70 (9ECNxxWW) White...
Last Post: Dooglas
09-27-2026 11:31 AM
» Replies: 92
» Views: 61903
[REQUEST] Lenovo E31-70 (AFCNxxWW) BIOS ...
Last Post: kristian6237455372
09-27-2026 11:04 AM
» Replies: 2
» Views: 565
[REQUEST] HP dv6-6c51ca whitelist remova...
Last Post: johnyn2005
09-26-2026 12:52 PM
» Replies: 20
» Views: 20217
[REQUEST] Lenovo B590 (H5ETxxWW) Whiteli...
Last Post: katri
09-26-2026 02:03 AM
» Replies: 281
» Views: 169143
[Request] Dell Optiplex 3040M 7th Gen CP...
Last Post: DeathBringer
09-25-2026 12:35 AM
» Replies: 10
» Views: 6262
[Untested] Dell OptiPlex 3040 H110 – Cof...
Last Post: gonza20889
09-23-2026 02:02 PM
» Replies: 0
» Views: 767
[REQUEST] Acer TravelMate B113-E BIOS Un...
Last Post: rt400
09-22-2026 07:39 AM
» Replies: 9
» Views: 5736
[REQUEST] Acer Aspire 8930(G) BIOS Unloc...
Last Post: xeper8x8
09-21-2026 10:04 PM
» Replies: 59
» Views: 61109
How To Add SLIC 2.1 To An Intel Motherbo...
Last Post: Argogo
09-21-2026 11:15 AM
» Replies: 75
» Views: 274947

Unlocking BIOS on An Embeded Device
#1
Unlocking BIOS on An Embeded Device

# The device
Its BIOS reads:
- InsydeH20 Version: APL.1.0.15
- UEFI Version: 2.5

The BIOS has two main interfaces:
- `Front Page`
  The first interface after hitting `ESC` key repeatly right after pressed its power button.
  Please reference the attachment `The device - front page.png`
- `Setup Utility`
  Please refernce the attachment `The device - Setup Utility.png`

Main chips on its board:
- CPU: `Atom Processor E3930`
- BIOS Chip: `MXIC MX, 2SU6473F, M2I-10G, 8E544200, L18489S`
- TPM Chip: `Infineon, SLB 9670, VQ20 30, T6H1839`
- Network Chip: `Marvell, W8997-M1216`

# Whats wanted
There are two limitations on its bios:
  - The booting OS is EFI protected, i.e., only the customized Ubuntu 16.04 OS distributed by its manufactory can be booted.
    Trying to boot from a different OS installation (EFI, not legacy mode) USB stick will leads to `\EFI\BOOT\BOOTx64.EFI has been blocked by the current security policy.`

    So, to my understanding, one need to do sth. like `Clean TPM` to set the TPM status, or disable the protection, before install different OSs.
    However, There is no such option in its BIOS. It seems these options are hidden (ref `Whats tried`).

  - One of the USB 3.0 port is limited to be use as a network access point (like a router).
    Can't find related options in the BIOS neither.

So, wanted:
  - unlocking the options for TPM/Secure boot options
  - unlocking the options for USB Ports settings.

# Whats tried
## Extract the stock BIOS image
Extracted its original BIOS image from the MXIC chip using CH341A Programmer.
Please reference the attachment `Stock BIOS image.bin`.

## A small experiment
After some searching (I am new to BIOS modding), found a tool, `InsydeH2OEZE_x86_WIN_100.00.03.04`, can be used to read the image.
So I tried to make a small change of its `BIOS version` content from `APL.1.0.15` to `APL.1.0.15.toMod`.
Then reflashed the mod bios image back to the MXIC chip.
After that the device can boot to its BIOS and the `Version` reads `APL.1.0.15.toMod`.

## Lets GTD
So I tried to continue.

First, the export result from `H2OEZE`'s `Function`-`other`-`Setup menu`-`Export setup menu`,
  shows there are `TPM` related options exists. So they were just hidden somehow.
  (Please reference the attachment `Export setup menu.csv` for the result.)

Second, some online posts suggested the visibility of the options may controlled by `H2OFormBrowserDxe` module.
So, the module was exported via `H2OEZE`'s `Function`-`BIOS image`-`Components`-`Module`-`Export module`-`9E5DAEB4-.. (H2OFormBrowserDxe)`,
this result the attachment `9E5DAEB4-(H2OFormBrowserDxe).ffs`.
Then using `Universal IFR Extractor v0.5(2014 donovan6000)` to extract its info from it.
However, its extraction, `9E5DAEB4-(H2OFormBrowserDxe) IFR.txt`, provides no usable info -- its almost empty.

Third, as there is a `Setup Utility` interface, so the `SetupUtility` module was exported -`FE3542FE-C1D3.FV04.SetupUtility.ffs`.
Then using the `IFR extractor` to extract it, which results `FE3542FE-C1D3.FV04.SetupUtility IFR.txt`.
There are two things about it:
  - I failed to find 'TPM' or 'secure boot' related options in the result.
  - As an experiment, working on learning how to modify the `ffs` file with the help from the `IFR` txt to enable the options in the module, such as the `SystemConfig`.

Any advices?
Many thanks!


Attached Files
.zip   BIOS Chip-MX25U6435F.zip (Size: 5.28 MB / Downloads: 12)
find
quote


Forum Jump:


Users browsing this thread: 1 Guest(s)