Zzz Stuff
153 subscribers
27 photos
4 videos
32 files
21 links
Some useful stuff
So called discussion group: https://t.me/zzzstuffchat
Download Telegram
lk_rui3_locked.zip
1.5 MB
lk_rui2_locked.bin
1.2 MB
lk_rui2_locked.zip
1.5 MB
🀣5πŸ™‰4😁1
❀‍πŸ”₯11🀣4❀1😁1
Notes:
69% of people never read the notes. If you're from the remaining 31% I appreciate that and you may read the notes here.
πŸ”₯6❀2πŸ€·β€β™‚2πŸ’©1
Splash maker kit.zip
36.2 MB
Note: Never flash the autogenerated update.zip file. Edit the updater-script and point out the logo partition properly
lk_rui3_locked_gui.zip
3.3 MB
TLDR; flash the zip from recovery


Yep. It's a "nobody asked" kinda feature. But I like messing up with the LK and so I made it. I just utilised an unused logo show function that is responsible for charger high voltage warning and replaced that particular image (img62.png for rui3 and img4.png for rui2) using logo builder v.1.6 to show Fastboot (GUI - like) menu. You can flash the zip (contains LK and logo) directly from recovery and make use of it. If you're using a custom splash already, make sure to replace that splash manually and flash the new logo. I've added the full kit plus some custom splashes [click to download] required for making your own splash logo or even make your own fastboot splash.

If you're using the lock spoof LK, you must flash this (rui3 only for now cuz nobody is using lock spoof rui2 version so far).

Any suggestions/feedback - dm me @antagonizzzt
lk-rui3-menu-gui.zip
3.3 MB
lk-rui2-menu-gui.zip
3.3 MB
πŸ”₯6❀1πŸ’©1
Zzz Stuff pinned a photo
Hey people. Follow these steps to secure your telegram accounts.
1. Change password (14 to 16 or more digits suggested) and select log out of all devices
2. Enable 2 step verification (add recovery mail)
3. Check your login sessions frequently (as hackers can login to your account even without a password if they steal your account's session tokens/cookies)

[Optional] Never sell your older unused groups/channels to any unknown people. Do you know why they ask older groups even with a single member/message? Because those older groups will be used for many scams/spams as older groups seem to be legitimate for that kinda stuff. If anything went wrong, the one who (of course you) created the group would be responsible if in case of any legal issues. Be smart and be safe.
- The one with social concern
❀14
πŸ€”4
πŸ‘€πŸ©Ό
πŸ‘»6🌚1🀨1πŸ—Ώ1
Introducing "thalaivan" - A PoC exploit that grants access to unrestricted EL3 code execution on vulnerable MediaTek devices.
Source: https://github.com/antagonizzzt/thalaivan
πŸ€”8πŸ’©4❀3
Work in progress..
πŸ”₯12πŸ‘3🀣1
πŸ‘€ next ec private key
πŸ€”5
kaeru_storage.c
3.4 KB
Disclaimer: It's not meant for extracting keybox as of now. If you still dump secure region you might get the leaf certificates in plain text as mentioned in the screenshot but you won't get the EC private key in plain text. Try injecting a custom SVC into the functions that handle heavy math. You'll see some complex multiplication and addition continuously. If your device is older enough your TEE binary will have (armv7 and armv8) mixed codes and TAs loaded from vendor partition are also armv7. So patch accordingly. I can't say anything beyond this. Use it at your own risk. 

https://github.com/antagonizzzt/thalaivan

For those curious people. Here's the updated tool. You can start experimenting with this. Open the rmx2156 board file and include file to begin with. I've commented out how things work. I'm releasing this now. Becuz I won't be available for some days. 

 Also note that, ATF doesn't have a storage driver. So you have to rely on kaeru. Implement this into kaeru. Just call dump_call_smc(). A keypress or a custom fastboot command will do the job.

That's all for now
πŸ”₯1