How do Mariko modchips work?

mathieulh

Well-Known Member
Member
Joined
Feb 28, 2008
Messages
378
Trophies
0
Website
keybase.io
XP
897
Country
France
In non layman terms: The modchips perform an undervolting which is timed to occur when the memory compare used to compare the hash of the BCT (Boot Configuration Table) RSA Public key is checked, this allows an attacker to insert their own BCT RSA Public key, and thus sign the BCT with their own keypair (which allows to use an artibtrary bootloader).

The timing is calculated using BCT reads from the eMMC controller, that is one of the reason the eMMC controller needs to be connected to the modchip (that and on the fly BCT/Bootloader injection)
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    K3Nv2 @ K3Nv2: https://www.kohls.com/product/prd-6512692/arcade-1-up-infinity-50-games-game-board.jsp?pfm=bdrecs...