Okay, fuck hoarding security research data. Here's ours (@G33KatWork and yours truly) .IDC for the Tegra X1 BootROM. Have fun!
https://q3k.org/u/6eac2986691922d02e9b25f3b767fd7ea9c44ca18bf7b792884e5c665df5152a.idc …
-
Show this thread
-
This should save you a lot of time on the boring find-the-register-in-the-TRM work, and also let you understand the gist of the code much easier. No obvious 0dayz, though :).
2 replies 2 retweets 21 likesShow this thread -
-
-
Replying to @q3k
That wasn't clear to me right away. Well, don't worry, me neither (+ glad that someone else thinks that this coldboot bug is not obvious as well ;) ).
1 reply 0 retweets 1 like -
Replying to @bernfroe
Well, now that the bug is out (see parallel branch in this thread), it's obvious in hindsight. We even looked quickly at wLength in USB control, but apparently not well enough! Good CTF, 8/10, would play again.
1 reply 0 retweets 1 like -
Replying to @q3k
yeah :) heh, to me this was 9/10 (never glitched before) still missing the bits how this can be used in a stand-alone way. Either there are more bugs or it never was completely coldboot/ untethered.. ah we'll see soon enough.
2 replies 0 retweets 0 likes
Nobody ever claimed an untethered Boot ROM bug. Coldboot just means on initial power on, not requiring later firmware exploits and/or warmboot resets.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.