Unable to dump OTP.bin

  • Thread starter Thread starter skawo
  • Start date Start date
  • Views Views 12,215
  • Replies Replies 88
i think you should restore that slc and seeprom dump. they are probably fine and it will get you at a state where things should work.

also, could you send me the seeprom? i want to check the boot1 version when i get home nvm you already sent it
 
Last edited by Lazr1026,
If you sent me the SLC and a list of the the ECC errors during the dump I can see which files are affected, so we could narrow down if it is SLC corruption or bad DRAM.
We could also run the memtest to see if the DRAM is good.
Post automatically merged:

Don't restore the SLC yet, because with that we would loose the information about ECC errors
 
The console started out with a blinking blue light, so there was definitely something wrong with it to start with.

I don't have a good SLC dump at all - the initial one was made to the caked SD card, and, a cursory look at one I made just now doesn't look promising. I will send everything I can dump to SDIO, though.
 
Last edited by skawo,
No uncorrectable ECC errors... that is untypical for SLC corruption... Maybe it ha a messed up system.xml but this doesn't look like the typical a SLC page became bad and corrupted the fw.img problem.
 
To be honest, to me it almost looks like someone has just completely wiped the SLC at some point or something - or maybe it hasn't been programmed at all?
 
you are right, I just threw it into a hex editor, and I can't see any superblocks... Just zeros (not even FF, which would be an erased page)
 
S'yeah.

Provided the OTP could be obtained... is that recoverable, or is this just a very slightly notable potato at this point?
 
If we had the keys form the otp, we could recrypt another SLC for this console. But everything on the SLC and MLC would be lost. So we would need the correct files for the devkit or whatever this is.
 
Given the keys, could the files from the mlc not be dumped (if there are any and it wasn't also wiped)?

That said I assume there's very little chance there's anywhere to source the slc stuff from :s
 
Maybe we can get something out of the MLC, depending how much it was used. If we are unlucky something integral to the FS is still in the SCFM
 
I decrypted the seeprom and the bootparams structure is really weird. You can try this though:
Download the attached zip
Copy both to the SD root
Restore the boot1 in minute
Have it fix the SEEPROM values - it should say v8377
Hope PRSHhax works
Post automatically merged:

I could probably re-encrypt my kiosks SLC dump, that could at least get us a starting point. From there you could possibly use mcp_recovery to flash a DDI?
 

Attachments

Code:
Invalid file size: expected 0x21000, got 0x10000

Should I just pad it out with zeroes?
 
let me check if thats viable. i may have chose a bad boot1 to base what to copy off of
Post automatically merged:

try this one
 

Attachments

Last edited by Lazr1026,
Hmm.
"Bad AA55 marker"

Dm0A5LL.jpeg
 
i think we will need to bypass that check, since the seeprom is mostly blank (for some reason?)
 

Site & Scene News

Popular threads in this forum