OESF | ELSI | pdaXrom | OpenZaurus | Zaurus Themes | Community Links | Ibiblio

IPB

Welcome Guest ( Log In | Register )

 
Reply to this topicStart new topic
> Archospma-430 Bootflash-signature Check' Removed!, ho ho ho
sashz
post Jan 4 2006, 01:31 PM
Post #1





Group: Members
Posts: 388
Joined: 7-December 03
Member No.: 1,058



If you like our work - please consider donating on http://www.pdaxrom.org

Here is the Archos PMA 400/430 flash hack which is avoid the bootloader checksum.

Unlike the Zaurus, the Archos bootloader checks the aimage.img for correct signature. Because it stops people for custom building aimage.img, i hacked flash bootloader for disable signature checkin.

Heres manual:

1) Download http://mail.pdaxrom.org/archos.ru/experime...ack-0.1.tar.bz2
2) Unpack it on PC
3) Check you bootrom to see if its compatible with the bootloader hack need the same flash images by following the next steps
4) Connect PMA to PC
5) From phys directory on the PC copy files phys_m.o, xxx1 to PMA
6) Disconnect PMA from PC
7) Run console on PMA
8) Go in directory where files, probably it will /media :
CODE
cd /media

9) Load kernel module phys_m.o:
CODE
insmod ./phys_m.o

10) Run xxx1 for get your flash rom:
CODE
./xxx1

11) Check md5sum for the flash image and cut some from flash smile.gif :
CODE
cd /tmp
dd if=bios.rom of=bios.rom.part bs=1 count=128000
md5sum bios.rom.part

The checksum must be
CODE
f67a0f5d320be1b0dc8bfa602ca6cdac  bios.rom.part

12) If your md5sum is different, stop here - you cannot use this hack sad.gif gzip rom file and send it me smile.gif
13) If md5sum OK, connect PMA to PC again
14) Copy file flash_m.o to PMA
15) Disconnect PMA
16) Run console on PMA and go to directory where file is placed
17) Load module:
CODE
insmod ./flash_m.o

18) Ohh, there error! hehe , dont worry. It is ok - we just run flash patcher in kernel space and then come back.
19) Run dmesg:
CODE
dmesg

20) There must be messages "Sector 0xD patched!" and "Sector 0xE patched!"
21) DONE!!! Now your PMA wil able run aimage.img with any signature smile.gif

if you got message "Unknown flash chip!", that mean your device uses M29W400BB flash. Go to step 14 and use flash-m29_m.o file for hack your device smile.gif

There russian version PMA-430 system, with custom aimage.img :
http://mail.pdaxrom.org/archos.ru/experime..._rus-050106.zip

If you like our work - please consider donating on http://www.pdaxrom.org
Go to the top of the page
 
+Quote Post
grond
post Jan 5 2006, 02:16 AM
Post #2





Group: Members
Posts: 4
Joined: 26-October 05
Member No.: 8,407



QUOTE(sashz @ Jan 4 2006, 01:31 PM)
Here is the Archos PMA 400/430 flash hack which is avoid the bootloader checksum.


You are my hero!!! Thank you so much, I just followed your instructions and it works. I overwrote the signature with "Hello, Archos, seems like your bootloader isn't as secure as you said!" and my PMA still boots... biggrin.gif

I hope that those other bootroms can soon be hacked too... dry.gif
Go to the top of the page
 
+Quote Post
sashz
post Jan 5 2006, 02:42 AM
Post #3





Group: Members
Posts: 388
Joined: 7-December 03
Member No.: 1,058



Fast guide how build custom aimage)

in flash-hack archive ( http://mail.pdaxrom.org/archos.ru/experime...ack-0.1.tar.bz2 ) look aimage directory.
There 2 utils: extract and build.

extract will write cramfs image and kernel image from exists aimage.img:

CODE
./extract aimage.img


when it will finish you get 2 files: rootfs.bin and zImage

for unpack cramfs you must use cramfs stuff with XIP feature (sticky files is uncompressed), for example this: http://mail.pdaxrom.org/archos.ru/experime...-archos.tar.bz2

CODE
cramfsck -x root rootfs.bin


all files from archos system will in directory root. Now you can hack it and add your own features in system:) for roll new cramfs image use mkcramfs utility:

CODE
mkcramfs root rootfs.bin


New rootfs.bin will created.

QUOTE
Note:
cramfs image must be ~21MB - need better understand aimage header smile.gif


For build aimage.img use build utility. Copy aimage.hdr in directory where your zImage and rootfs.bin and run build:

CODE
./build


that will create new aimage.img
Go to the top of the page
 
+Quote Post
sashz
post Jan 5 2006, 02:47 AM
Post #4





Group: Members
Posts: 388
Joined: 7-December 03
Member No.: 1,058



QUOTE(grond @ Jan 5 2006, 02:16 AM)
QUOTE(sashz @ Jan 4 2006, 01:31 PM)
Here is the Archos PMA 400/430 flash hack which is avoid the bootloader checksum.


You are my hero!!! Thank you so much, I just followed your instructions and it works. I overwrote the signature with "Hello, Archos, seems like your bootloader isn't as secure as you said!" and my PMA still boots... biggrin.gif

I hope that those other bootroms can soon be hacked too... dry.gif
*



hope there no another bootloaders with different md5sum:)
Go to the top of the page
 
+Quote Post
sashz
post Jan 6 2006, 02:39 AM
Post #5





Group: Members
Posts: 388
Joined: 7-December 03
Member No.: 1,058



latest flash-hack tools updated and uploaded smile.gif

http://mail.pdaxrom.org/archos.ru/experime...ack-0.2.tar.bz2

now you can restore default bootloader for archos warranty smile.gif

for SST39VF400A owners: rev-flash_m.o

for M29W400BB owners: rev-flash-m29_m.o
Go to the top of the page
 
+Quote Post
ZDevil
post Jan 6 2006, 02:50 AM
Post #6





Group: Members
Posts: 2,003
Joined: 16-April 04
From: the Netherlands && /dev/null
Member No.: 2,882



That's awesome.... Perhaps if Sharp stops making Zaurii Archos is the way. smile.gif
Go to the top of the page
 
+Quote Post
bam
post Jan 6 2006, 11:32 AM
Post #7





Group: Members
Posts: 1,213
Joined: 9-June 05
From: Gobi Desert, Mongolia
Member No.: 7,306



if sharp quits makeing the z I will buy at least 3 more 3100's for stock smile.gif
Go to the top of the page
 
+Quote Post
sashz
post Jan 11 2006, 07:20 AM
Post #8





Group: Members
Posts: 388
Joined: 7-December 03
Member No.: 1,058



latest custom system http://mail.pdaxrom.org/archos.ru/experime..._rus-110106.zip
Go to the top of the page
 
+Quote Post
Jaffar
post Jan 14 2006, 02:12 PM
Post #9





Group: Members
Posts: 1
Joined: 27-September 03
Member No.: 503



Hi and thanks, works like a charm I can now read my favorite bulgarian web pages. BUT the cyrkeyboard does not work and you have to remove the cyrkeyboard input applet otherwise you get the safe mode until you disable it. Small bug for a great job though. Well done! biggrin.gif
Go to the top of the page
 
+Quote Post
pyknite
post Jan 14 2006, 03:14 PM
Post #10





Group: Members
Posts: 118
Joined: 20-October 05
From: Neuchatel (swiss)
Member No.: 8,354



QUOTE(Jaffar @ Jan 14 2006, 02:12 PM)
Hi and thanks, works like a charm I can now read my favorite bulgarian web pages. BUT the cyrkeyboard does not work and you have to remove the cyrkeyboard input applet otherwise you get the safe mode until you disable it. Small bug for a great job though. Well done! biggrin.gif
*



hum... archos is here wink.gif
Go to the top of the page
 
+Quote Post
sashz
post Jan 15 2006, 10:16 PM
Post #11





Group: Members
Posts: 388
Joined: 7-December 03
Member No.: 1,058



QUOTE(Jaffar @ Jan 14 2006, 02:12 PM)
Hi and thanks, works like a charm I can now read my favorite bulgarian web pages. BUT the cyrkeyboard does not work and you have to remove the cyrkeyboard input applet otherwise you get the safe mode until you disable it. Small bug for a great job though. Well done! biggrin.gif
*


that because settings for keyboard applet in russian backup smile.gif
else i uploaded settings for keyboard there:

http://mail.pdaxrom.org/archos.ru/experimental/keymaps.zip

download and extract it on archos harddrive. There included danish english english-uk german macedonian russian slovak keymaps. Look /media/pda/Applications/cyrillica/russian for example and build bulgarian keymap (i know there different cyrillic chars location than on russian). I had it before when made it for zauruses, but probably lost.
Go to the top of the page
 
+Quote Post
chrissy
post May 10 2006, 01:44 AM
Post #12





Group: Members
Posts: 2
Joined: 10-May 06
Member No.: 9,822



Hi,
I've just got an Archos PMA400 and am interested in playing around with it a little more than designed. Unforunately the flash-hack and cramfs links on this page are leading to a 'page not found' area. Don't suppose anyone has the latest versions of each of these available anywhere?....

Cheers

Chris
Go to the top of the page
 
+Quote Post
sashz
post May 10 2006, 01:48 AM
Post #13





Group: Members
Posts: 388
Joined: 7-December 03
Member No.: 1,058



Hi,
it moved to http://openpma.org/

My PMA400 brocken (fall 0.5 meter) and i stop any development for it.
Go to the top of the page
 
+Quote Post
chrissy
post May 10 2006, 02:02 AM
Post #14





Group: Members
Posts: 2
Joined: 10-May 06
Member No.: 9,822



Hi,
Thanks for the quick reply - unfortunately (unless I'm being very dense) it looks like everywhere on the net that has info related to this boot-flash (or in particular the extract and create bins) links to the same download page on mail.pdaxrom.org/archos.ru/experimental which is down....oh well.


QUOTE(sashz @ May 10 2006, 09:48 AM)
Hi,
it moved to http://openpma.org/

My PMA400 brocken (fall 0.5 meter) and i stop any development for it.
*


That's rough - no plans on replacing it?. I've only had mine a few days but it is impressive (to a point, which is where I want to take it up!). As a system admin, having a proper(ish) hand held wifi linux box is hopefully gonna be pretty useful.

Cheers anyway...
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic
2 User(s) are reading this topic (2 Guests and 0 Anonymous Users)
0 Members:

 



RSS Lo-Fi Version Time is now: 26th October 2014 - 12:31 AM