forensics/fixing/flashing - Huawei Nova/Nova Plus Questions & Answers

Hi!
I have Software- and Hardware experience, but not so Android-specific and none Huawei-specific.
A friend asked me to recover the data of a CAN-L11 stuck in a bootloop. (Stock Android 6 EMUI 4.1, OEM locked, build date Fri Nov 18 14:27:21 CST 2016)
My first thought was dumping the eMMC through SDIO - in hindsight I am so glad I didn't go this route as it would be stuck decrypting cryptfs.
I went the EDL route, dumped everything including the userdata-footer (so much easier&faster than direct SDIO).
Now I don't know how to move forward - have some questions in my head:
How to get the Masterkey from the TPM using EDL? Is that feasible? Is there an easier way? I know the PIN.
When is the TPM and userdata cleared? When I flash a signed ROM through EDL? When I flash a UPDATE.APP through fastboot? I found a stock UPDATE.APP on the internet with EMUI 4.1 for CAN-L11 - seems not to be exactly the same as currently flashed though.
Any other ideas?
If someone is interested - the knowledge I have gathered until now:
EDL-Pins for CAN-L11:
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
EDL-Software for Linux: https://github.com/bkerler/edl
Paper about Android encryption: https://www.sciencedirect.com/science/article/pii/S266628172100007X
Regarding ISP/SDIO - mostly from a previous S4 mini recover:
the CMD-Pin seems to always have a Pull-Up
the Raspberry Pi has a unused SDIO-Port which worked flawlessly; my SD-Card-Reader attempt failed
https://www.riverloopsecurity.com/blog/2020/03/hw-101-emmc/
Thanks in advance!
Thomas131

Related

I have a problem phone "Failed to boot 2" please help

Stop the phone on this screen, what should I do
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
Hi,
Same thing happened to me. There are 3 problems;
First is that you do not have enouch battery power to run RDS.
Second is that you have to load SBF file again with RDSLite.
Third is that you have to unlock your bootloader not to have the same situation.
But to make you feel happy, I can say that your phone is not bricked.
We shall go step by step for your problems. First of all, do you have second battery or can you supply it because it is necessary to overcome second and third problem ?
micromedia2011 said:
what should I do
Click to expand...
Click to collapse
Hi,
Please use search.
Thanks,
I'm having the same problem "failed to boot 2". Minus the battery part.
I did all the following steps a few months ago to update to the new gingerbread firmware from http://forum.xda-developers.com/showthread.php?t=1182871
Claims I would have an unlocked bootloader, root, and CWM. Which, I have root, CWM, and evidently still on a locked bootloader per a post I read on androidforums.
I'm lost as I've been reading so much that I've done confused myself on what I should actually do, and feel worse off than I was before I started reading.
Overall, my phone works fine. I just wanted to flash a different ROM. I'm just not sure where to start to fix my problem (redo all the steps in the post I linked up, or flash a whole other SBF file). Any help would be greatly appreciated. Thanks!

Help needef

Point if view 10"-1. This is the name of tablet my friend got yesterday.Unfortunately it looks like something is wrong with it. Like it is not that type of tablet running 1GHz processor.Too slow, slow response on commands. Is there a solution to reinstall software on it, some tutorial or similar? Ill try to get additional info about this tablet installing system info.
Sent from my HTC Desire using XDA App
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
Sent from my HTC Desire using XDA App
Hi There.
Just re-install the stock rom from here: www.pointofview-online.com/default2.php?content_id=36
You can also use the advent vega stock rom from here: www.myadventvega.co.uk/
Good luck.
Just to say I managed only to re-install original firmware. I DL it here http://downloads.pointofview-online.com/Drivers/ . Officialy this is SEC SOC Test board and it is NOT recognised by any of recognised drivers or update softwares. It is easy rooted device with Z4root but it can't be put in recovery mode as It should be. Simply it is not recognised as Nvidia or similar tablet (drivers, too,although they installed correctly) just SEC SOC drivers. Special burning tool is used to burn firmware and OS on it.
If someone knows exact procedure for upgrading it with different ROM i'm here
It use IMG extensions for it's needed software which is delivered by DL package.
Regards,

Need Help Booting In Recovery?

So I know that the oppo find 5 is fairly of a new device and not many people have it, yes there is support from a various users and groups (even the CM team has jumped on nightly builds on it) Anyway I want to write to you guys that in the venture of me trying to port a various "ROM" my oppo find 5 would get stuck on the splash screen Green Oppo Letters.I would try to use fastboot to get it back but I never got anywhere. The main problems were that I couldn't get into my previous ROM or the new one I flashed NOR could i get into recovery since I was stuck on the boot screen.
I found a really nice script on the oppo find 5 bricked thread and I modified it with a more "instructional process" to help us oppo find users get back into recovery after failed attempts of trying to get into a rom.
**Please note that for some odd reason the oppo find 5 takes like 1-2 minutes to boot into recovery after this process. I HAVE NO CLUE WHY.**
Also once you get into recovery in this case TWRP i would definately reccomend doing a back up > mounting SD card and transferring it to your PC.
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
This is only for Windows.
https://docs.google.com/file/d/0Byxlw5J4qbOvRVJDOFhkb2RtWkk/edit?usp=sharing
Extract then run batch file - Good luck! :fingers-crossed:

I got Big Big problem..「Failed tomount '/3rdmodem'(Invalid argument)」

I got Big Big problem..
Always...
「Failed tomount '/3rdmodem'(Invalid argument)」
I’m from Taiwan and my English is not very good. Use google to translate, thank you for your help
I hope you can answer for me. I have studied for more than three days. I still can’t succeed.
I am using Huawei BTV-w09.EMUI 4.0 tablet
Use twrp to flash the machine until Android 7.0 has been failed
Do you know what the problem is, thank you very much
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
You need EMUI 5.x Android Nougat on your device... if you want to use my TWRP in order to flash LineageOS on your device !
EDIT:
And not all EMUI Firmware can be flashed via TWRP, only some of them !
Hi. I finally successfully flashed the machine smoothly.
However, Emui5.0 & Android 7.0 versions were not selected at the time.
I want to delete the system to recharge the phone, but now I can’t delete the system.
How do I update to 5.0? Thank you
I'm having the same problem! i get the 3rdmodem mount failed
distant321 said:
I'm having the same problem! i get the 3rdmodem mount failed
Click to expand...
Click to collapse
It's not a big deal, just ignore this error ... your device it's WiFi Only, that's why you have this issue ! The TWRP it's only one for the both devices WIFI & LTE !
Simba.M said:
I got Big Big problem..
Click to expand...
Click to collapse
In reality it is a very small error that can be ignored !

No-name BMW E60 chinese HA bricked (files/images included)

Hello, I have a HU. I installed a Launcher, set it as default, and now it can't go to the Android menu, the Bluetooth is working fine, just a BMW logo looping. I tried to fix it, accidentally bricked it as well (deleted everything with SPF), because it's now not recognized by my laptop. I got my original firmware from the manufacturer I think (link K2001N.img), but they didn't really tell me how to use it. So currently the reverse cam is working, the original BMW menu is working, the Android part is a huge black screen (with back light). I also tried to find test points, with not much luck. Can someone help me to find the test points, and tell me how to use this .img file? Only one RST button is present. I already tried a few test prints with no luck, maybe I can memory dump this image file?
HU details (so others find it in the future)
Kernel: [email protected]
Build number: full_8227L_demo-userdebug 10 O00019 1610719904 userdebug
Build version: alps-mp-o1.mp5
MCU: HTT_B0_Y8_00_200728B
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
please help stuck in android logo does anyone know how to do a hard reset, i tried with update but it doesn't start .. if anyone knows how to restart again please ... thanks . it's china bmw e60 rockcip 3399

Categories

Resources