Forum RSS Feed Follow @ Twitter Follow On Facebook

Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
[-]
Welcome
You have to register before you can post on our site.

Username:


Password:





[-]
Latest Threads
M920q BIOS unlock
Last Post: d3vf0x
Today 04:50 PM
» Replies: 0
» Views: 19
[REQUEST] bios unlock for Giabyte G5 KC
Last Post: Mordrigahn
Today 04:48 PM
» Replies: 0
» Views: 16
[REQUEST] Lenovo G500 (78CNxxWW) Whiteli...
Last Post: MAVARACOMPLEX
Today 02:15 PM
» Replies: 1186
» Views: 267422
[REQUEST] Lenovo Thinkpad X240 (GIETxxWW...
Last Post: BOJIKA
Today 01:33 PM
» Replies: 49
» Views: 17167
Fujitsu Esprimo P5710 - unlock [REQUEST]
Last Post: Maxinator500
Today 01:03 PM
» Replies: 5
» Views: 137
[REQUEST] Lenovo Y400 & Y500 (6BCNxxWW) ...
Last Post: Dudu2002
Today 11:17 AM
» Replies: 157
» Views: 54531
[REQUEST] Lenovo G780 (5ECNxxWW) Whiteli...
Last Post: Dudu2002
Today 11:16 AM
» Replies: 877
» Views: 289410
[Removed, sp52359] HP Touchsmart Tm2t-22...
Last Post: OrionDakota
Today 10:04 AM
» Replies: 24
» Views: 21085
[REQUEST] HP Laptop 15-dw3xxx BIOS Unloc...
Last Post: UltraVi0let
Today 09:58 AM
» Replies: 4
» Views: 183
Clevo P775TM1-G BIOS
Last Post: Spacoom
Yesterday 09:09 AM
» Replies: 146
» Views: 58487
[REQUEST] Unlocked BIOS for Gigabyte H51...
Last Post: IsHacker
Yesterday 05:32 AM
» Replies: 0
» Views: 144
[REQUEST] Lenovo G510 (79CNxxWW) BIOS Un...
Last Post: Crazy tech
04-28-2024 09:51 PM
» Replies: 78
» Views: 43009
Analyze java class System Identifier cod...
Last Post: Hasan jeet
04-28-2024 03:44 PM
» Replies: 0
» Views: 128
[REQUEST] Lenovo G710 BIOS Whitelist Rem...
Last Post: sscdimon
04-28-2024 01:53 PM
» Replies: 471
» Views: 133061
[REQUEST] Lenovo Yoga 2 Pro (76CNxxWW) W...
Last Post: cpih
04-28-2024 12:03 PM
» Replies: 846
» Views: 329182
Delete Whitelist HP 15s-eq1000
Last Post: gdefareins
04-28-2024 09:02 AM
» Replies: 3
» Views: 190
[REQUEST] Lenovo Y470 & Y570 (47CNxxWW) ...
Last Post: jabbari74
04-28-2024 03:37 AM
» Replies: 25
» Views: 18231
[REQUEST] Lenovo Thinkpad T420 (83ETxxWW...
Last Post: lucasow
04-28-2024 03:02 AM
» Replies: 315
» Views: 194922
[REQUEST] Asus PRIME B460M-A modding bio...
Last Post: hnoimahi
04-27-2024 08:04 AM
» Replies: 1
» Views: 275
[REQUEST] Lenovo G580 (62CNxxWW) Whiteli...
Last Post: Dudu2002
04-27-2024 05:34 AM
» Replies: 809
» Views: 247678

[REQUEST] ] Unlocking Insyde F.21 Bios options (Guide & tools included)
#1
Information 
Hey,

First, i'd like to salute this community for being all for sharing and progress through collaboration. I'm believe that unlocking the BIOS I have have could help a lot of people, it's on the HP Pavillion 15 cx0056wm laptop, but it's very on other cx00xxx laptops, if not the same, it mentioned the model with [censored] in the BIOS. Hp for some reason decided to not provide an option to access advanced settings, it's not cool, it makes the laptop like a "black box".

Anyways, I started looking for modded BIOS updates, didn't find any for that laptop, but a lot of people are looking for it as mentioned, so I decided to research doing it on my own. I need to disable CFG-Lock to be able to run Mac, because it uses the MSR 0x0E CPU register which is protected by the BIOS by default, that's why I'm using version F.21 and not the latest one, the latest one doesn't seem to have it at all, not sure if that means that it's disabled by default, but I don't want to try and not be able to downgrade.

I found a really cool tool that's been leaked from Intel, they later decided to publish it themselves anyways, it's called Insyder BIOS Editor (InsydeH2O_03.04/H2OEZE) it allows seeing the BIOS menu and replacing different modules, but I don't have a tool to modify the exported file, so I had to find another way. I found out about a cool guide that's especially for Hp laptops, it consists getting the .bin, using PhoenixTool (to get the .rom files, but I used UEFITool to find the GUID since it has search) to export two EFI structures, DXE core and SetupUtility, then using a Hex editor to find the data offsets of the menu tabs and finally using IDA Pro to find the display tabs conditional checks to determine whether to view them or not based on the manufacturer's settings, patching them using a Hex Editor, and loading them into the original bin using the Insyder tool to be ready flashing. I believe that I can just enable the settings through Insyde tools, change the default settings, that is, but i'm interested in solving it for others too, if that works then I could do without patching it, but I rather have all the settings in the BIOS, so it's a win-win.

I'm at the point where I need to find the offsets in the structure using a Hex Editor, but I can't find non of the menu options written in the format mentioned in the guide, with space and 0x00 between bytes, nor through their regular names, I only found Advanced mentioned, but it could be something else, someone more experience might know.

I skipped that step just to try, loaded the .rom into IDA and looked for the byte sequence mentioned in the guide for menu header data and I found them , but I need the tabs offsets to know exactly where to look.

The question is, could the EFI structure data be encrypted on top of the regular compression? I checked the decompress option upon extracting. Why is Hp making it hard on the modding community  Angry

Guide link: https://dlscrib.com/unlock-bios_588a1b8b...3_txt.html
F.21 BIOS update link (for model cx0056wm):  https://ftp.hp.com/pub/softpaq/sp100501-...100754.exe
HxD (Hex Editor): https://mh-nexus.de/en/downloads.php?product=HxD20
IDA Pro (free version): https://www.hex-rays.com/products/ida/su..._freeware/
IFRExtract (could be needed using other methods, like the extract module method using Insyde Editor, the output needed to be modified after, so it need to be decrypted/decompress if it's encrypted/compresses before being able to edit it, and then a way to recompile is needed after, the replace module in Insyde Editor is to be uses after, I left it as an attatchement)

I've attatched the things needed in the process, in case someone wants to try.

I'd appreciate it if anyone could shed some light, i'm still only a beginner when it comes to BIOS modding, I only get the general idea 

P.s: I got the bios bins from the official exe through making a recovery USB, although the USB recovery mode didn't work for me to flash, I used the update feature. The .fd files in BIOSUpdate.exe extracted didn't load in the Insyder Editor. To update later I'll try the USB hotkey method while having the .bin in the USB, seems to be a common option.


Attached Files
.zip   phoenixtool273.zip (Size: 2.83 MB / Downloads: 10)
.zip   UEFITool_NE_A57_win32.zip (Size: 7.51 MB / Downloads: 14)
.zip   ifrextract_v0.3.6_win.zip (Size: 32.65 KB / Downloads: 12)
find
quote
#2
Can anyone shed some light please? I'm trying to finish this ASAP, it shouldn't be hard, just a matter of finding the offsets, I just need to know if the .rom is RSA encrypted or if I shouold find other structures
find
quote


Forum Jump:


Users browsing this thread: 1 Guest(s)