lk-rui3-menu.img
1.3 MB
What's new 🥳
1. Added a new thread.
2. Removed/Patched fastboot restrictions like
How to flash?
or
Recovery flashable version
Screenshots
1. Added a new thread.
Menu-like feature that runs along with fastboot mode you can just trigger these
Functions while in Fastboot (i.e no need to force power off)
UP - Continue to System
Down - Boot to Recovery
Power - Turns off device
2. Removed/Patched fastboot restrictions like
FAILED (remote: 'not support on security')
fastboot: error: Command failed
So some restricted commands will work
How to flash?
fastboot flash lk lk-rui3-menu.imgor
Recovery flashable version
Screenshots
🔥5❤1
𝙰𝚗𝚝𝚊𝚐𝚘𝚗𝚒𝚣𝚣𝚣𝚝
lk-rui2.img
How to flash .img files without recovery flashable?
Go to your existing fastboot and enter the following command
Or make recovery flashable by replacing the lk.img in this zip with this (rename lk-rui2.img to lk.img)
Go to your existing fastboot and enter the following command
fastboot flash lk lk-rui2.imgTelegram
Zzz Stuff
🔥4
RUI3 - Bin | Zip
RUI2 - Bin | Zip
Sadly both LK works only in stock rom for now and custom roms didn't boot becuz of in-rom spoofs. If you can find a signed custom rom without these spoofs your device may also pass strong.
What works?
What doesn't work?
How to flash?
Precautions:
How it works?
Any issues/bugs:
RUI2 - Bin | Zip
Sadly both LK works only in stock rom for now and custom roms didn't boot becuz of in-rom spoofs. If you can find a signed custom rom without these spoofs your device may also pass strong.
What works?
Both RUI3 & RUI2 patches actually spoofs "bootloader locked" state.
What doesn't work?
RUI3 patch passes strong (as expected) but,
RUI2 patch passes only basic (Even in locked bootloader it passes basic. Most probably becuz of downgrade protection mechanism that prevents users from using older versions after updating to the latest one)
How to flash?
Flash LK using custom recovery or mtk client as your wish (fastboot mode is not preferred). And you MUST wipe personal data else it won't boot.
Wipe md_udc, metadata, userdata if you use mtk client.
Precautions:
Before flashing this LK you must backup all the fw partitions (except userdata, super and cache) for safety purpose. As it may lock your device if done wrong.
You must be aware that if you flash any other LK after flashing this lock spoofed LK, you must do format data and you can't decrypt the existing data (RPMB hash mismatch). Becuz it works in such a way similar to that of real locked device.
How it works?
Normal LK: preloader > reads seccfg (unlocked) > normal LK > pushes unlocked status to RPMB > skips TEE and other security firmware > no root of trust
This lock spoofed LK: preloader > reads seccfg (unlocked) > lock spoofed LK > pushes locked status to RPMB > loads TEE and other security firmware > device gets root of trust
Any issues/bugs:
DM me @antagonizzzt with logs (dump expdb, opporeserve1 and seccfg partitions, put them in a zip and share) You may try at your own risk in custom roms (won't boot btw) if it boots by any miracle tell me.
Last but not least: Thanks @R0rt1z2 for the inspiration
🔥10❤4