Related
With PSAS (only FULLversion) it is possible to "decompress" apps_compressed.bin for investigation.
It uses Algo:
TkToolVer:1.6.3
I don't know way to make own apps_compressed.bin.
As Multiloader for instance not accept decrypted apps_compressed.bin
As example some older apps_compressed.bin from S8500.
http://www.megaupload.com/?d=2JIKS8QD
Best Regards
u reache some limit bro........... cant download from RS........but good going
can u write a tutorial
so that other members too can find something
thanx!
gr8 gng mate
PSAS can only decrypt in Full Version.
Costs 30 Euro...
BUT I can upload via Request some decrypted files for study.
I'm not an Seller of PSAS nor I force you to buy PSAS.
But this is the only Tool I know, which decrypt these apps_compressed.bin and bootloader.mbn. Tested by me with:
S5250
S5330
S5750
S7230
S8500
S8530
http://forum.revskills.de/viewtopic.php?f=14&t=700
Wait few minutes. I will upload to megaupload... from S8500 as example.
Best Regards
Edit:
Download example apps_compressed.bin taken from S8500:
http://www.megaupload.com/?d=2JIKS8QD
Same as in first post.
So what did u get inside that?? What was compressed in layman terms pls.......
Expect not too much. Depend on knowledge...
Now file is "human readable"... Ready for Reverse engineering.
Minimum Requirement HEX Editor...
Then you can find Text like this:
Please receive DB2 by TkFileExplorer.exe !!primaryRecord
Click to expand...
Click to collapse
Remember where u saw TkFileExplorer.exe else...
You could search for Textstrings... like:
widget
bondi
.
.
.
So many things to explore.
Best Regards
hi guys I'm working on some bada's modding projects...
is it possible to have an example of uncompressed files?
thank you in advance
edit : I have now seen the uploaded uncompressed file...
I hoped it was more "human" readable...
http://www.megaupload.com/?d=PFWCKTGZ
This is from XXJID... bada 1.2 S8500 stuff.
Best Regards
adfree said:
But this is the only Tool I know, which decrypt these apps_compressed.bin and bootloader.mbn.
Click to expand...
Click to collapse
Hi,
could you upload the decrypted bootloader, too? Maybe someone here will find some exploitable code in that will help "jailbrake"-ing the system, or allow booting unencrypted OS (modified Bada or Android from Galaxy S for exmaple...)
TIA!
@ anghelyi
http://forum.xda-developers.com/showpost.php?p=10304951&postcount=3
Here I have attached some more things about Bootloader... some ELF files included... maybe "easier" for Reversing.
Best Regards
adfree said:
@ anghelyi
http://forum.xda-developers.com/showpost.php?p=10304951&postcount=3
Here I have attached some more things about Bootloader... some ELF files included... maybe "easier" for Reversing.
Best Regards
Click to expand...
Click to collapse
Thanks! I'll check it!
Little overview...
Best Regards
Hi adfree,
Can you say me the name of PSAS software please?
http://psas.revskills.de/
RevSkills is the new name of PSAS.
This feature only in registered Fullversion possible.
NOT in Trial Version.
Best Regards
Thanks but seems to be not compatible with windows 7 64 bits
Will try later, Have a good night adfree
look like that apps_compressed.bin contains a big secret
i flashed amss.bin file & apps_compressed.bin file from spoofable fw as an update for non spoofable fw and the result was getting a spoofable fw with its code name in the about phone menu but i lost all the updates made in the non spoofable fw
can anyone know where is the part in the app_compessed.bin that allow spoofed games run or not?????
To clarify:
I'm NOT support spoofing.
Prior files were not decompressed, "only" decrypted.
But now.
http://rapidshare.com/files/453882158/XXJL2decrypted_apps_decompressed.rar
File is from XXJL2.
Maybe we can find other usefull infos.
Best Regards
Now we can encrypt.
Thanx to ho1od
Any suggestions?
Mabye few things can be enabled or disabled...
TRUE can be found 600 x
FALSE over 700 x
Best Regards
I'm working on decompression QMD, thanks to mijoma
I was looking for the decompressed files of apps_compressed.bin (S8500XXJL2 and S8500XEKC1 only), but the link does not work.
If anyone (or you, adree) can decompress (not only decrypt) those files and upload them somewhere, that would be very kind/nice. Maybe I can work something out and if we are ever able to encrypt the files back, we may have a new better cleaned up version by that time.
Btw, thanks for the efforts, adree and ho1od.
This is a my program for viewing of bada firmware.
This source code
Thanks ho
tried it with simple test
dumped a ShpApp file then save it to another location
and here is the surprise
i did a hash check between both files and they didn't match!!!!!!!
have the same size same name differs in dates and differs in hash check
i think you have to work on your beta app more
keep the good work
and by the way the UI is more simple than trix so i pet it will beat it when it is finished
mylove90 said:
i did a hash check between both files and they didn't match!!!!!!!
Click to expand...
Click to collapse
Thank you for the test
Hash should be different. Programs use different ways to sort the directory
The file will be correct
@ mylove90
Multiloader 5.62 for instance checks without attached handset.
Best Regards
adfree said:
@ mylove90
Multiloader 5.62 for instance checks without attached handset.
Best Regards
Click to expand...
Click to collapse
ok adfree you are so right
i can't argue with you off course
who am i to do it?
sorry but i just wanted to tell the app maker about that maybe he can try to improve that point
MD5 Hash is only "mandatory" for Multiloader. But you can also disable MD5...
NO MD5 Hash needed.
Important is only that structure of created files is valid and content files are not corrupt...
But for instance sort Order from A to Z or from 1-10 or versa vi is not important.
I mean position from content files in created files like FFS...
Example, 3 files:
1
2
3
Second attempt with different sort order:
3
2
1
Both created files are valid, but MD5 differs, NOT equal...
Generally. Hashes like MD5... if only 1 Byte is different. Then Hash complete different.
Sorry, bad english description but I hope you understand what I mean...
Forget MD5.
Anyway. Thank you for testing mylove90.
Best Regards
adfree said:
MD5 Hash is only "mandatory" for Multiloader. But you can also disable MD5...
Click to expand...
Click to collapse
Multiloader does not check the MD5 hash, it checks the signature on the offset 440 bytes from the end of the file. My program calculates and corrects the signature.
New version 0.0.1
New features:
Added drag and drop files to the dump
Added drag and drop files to add the firmware
Added preview ini, txt, xml, jpg, png files
The program can be downloaded in the first post
@ ho1od
Maybe if you have time. You could integrate also RC2.
The Adresses for RAW Pics from S8500 are floating around here.
For the others smaller bada we could little bit research... also S8530 have little differences. But Algo should be the same...
http://forum.xda-developers.com/showpost.php?p=11919036&postcount=24
Thanx in advance.
Minimum support for RC2 could be change Value for Debug Level...
0 1 or 2
Best Regards
Ok, I'll do it
a request for ho1od
can you please examine S8500XXJB6 and make your tool able to extract it??
trix can't do it so if your app could it will be super
any file from that fw will be enough for me
Meanwhile for XXJB6
http://forum.xda-developers.com/showpost.php?p=11070379&postcount=5
To extract *.img take an while...
I do it for every Frame from 48 + 1 Pics... via WinHex.
Best Regards
mylove90 said:
can you please examine S8500XXJB6 and make your tool able to extract it??
Click to expand...
Click to collapse
Where can I download S8500XXJB6 ?
ho1od said:
Where can I download S8500XXJB6 ?
Click to expand...
Click to collapse
Here friend: http://netload.in/datei0M2CPM5V3x.htm
Best Regards, XaToR BadaItalia
Update v 0.0.2
New features:
View images in a file RC2
Replacing images in this file. The file must be BMP 24bpp format
Change debug level
The program can be downloaded in the first post
I used your tool to create a custom SHPApp.app file. But I think multiloader checks the MD5 hash and does not enable me to upload it to the phone. I have read adfree's post on disabling it but I couldn't understand him. So if you could help me in detail, I would be grateful.
Thanks.
astrotom said:
I used your tool to create a custom SHPApp.app file. But I think multiloader checks the MD5 hash and does not enable me to upload it to the phone. I have read adfree's post on disabling it but I couldn't understand him. So if you could help me in detail, I would be grateful.
Thanks.
Click to expand...
Click to collapse
I tested the program and flash the modified files via multiloader V5.64. Everything works fine. Upload your file and give me a link, I'll check it
PS. Signature at end of file, it is not MD5 hash, this is another hash function. I disassemble it from multiloader and inserted into the program. The file is signed correctly
ho1od said:
I tested the program and flash the modified files via multiloader V5.64. Everything works fine. Upload your file and give me a link, I'll check it
PS. Signature at end of file, it is not MD5 hash, this is another hash function. I disassemble it from multiloader and inserted into the program. The file is signed correctly
Click to expand...
Click to collapse
One doubt. Will I have to extract and recompile using your software itself? Because I had extracted the software earlier using trix. So maybe that's making your software not sign it correctly? Also I don't see how I can extract amss and csc files with your software. When I select on your AMSS and CSC tabs, there's nothing. I can't find the fie button which is there on the FFS, PFS and SHPAPP tab.
I can make a separate menu item, for signing the files created in Trix. If need be.
Working with CSC and AMSS files will be in next update
All in One program Gui for Bada
Upload later for change...
Please, what is this?
I'll download, but I need more infos before install...
Thanx.
Best Regards
This is a collection of tools for bada
a screenshot form this program
please remove TriX from you package
Its not mine i dont know how remove it...
What's wrong whit you ?
we can edit rsrc1 file with this pack?
litebass2 said:
we can edit rsrc1 file with this pack?
Click to expand...
Click to collapse
yes RC1Extractor Current version: 0.3.0.0a (ALPHA) is integrated
martinklaus said:
yes RC1Extractor Current version: 0.3.0.0a (ALPHA) is integrated
Click to expand...
Click to collapse
but its not correct decompress and decrypt on S8500 and S8530 firmware, this one works fine on S5830.S5230...
Also in bundle you can use Extractor but not way to recompress...
Last WaveReMaker by Ho1od do it !
TriX is under developement - latest build you can always find at NokiX site - check my homepage link. This really pisses me off that someone says TriX doesn't work etc only because it uses program from unknown source. The second reason mentioned at the beginning is I'm still working on so the badastudio is permanently outdated (this also applies to Wave Remaker - 0.0.71 against 0.06 in badastudio)
Tigrouzen said:
but its not correct decompress and decrypt on S8500 and S8530 firmware, this one works fine on S5830.S5230...
Also in bundle you can use Extractor but not way to recompress...
Last WaveReMaker by Ho1od do it !
Click to expand...
Click to collapse
Yes but with waveremakr we can only decompress Rsrc1 and we cannot compress the files back and build rsrc1 file..
if I mistake tell me how to do it..
litebass2 said:
Yes but with waveremakr we can only decompress Rsrc1 and we cannot compress the files back and build rsrc1 file..
if I mistake tell me how to do it..
Click to expand...
Click to collapse
No way to recompress RC1 for the moment sorry, but this is the way easy to uncompress...
b.kubica said:
TriX is under developement - latest build you can always find at NokiX site - check my homepage link. This really pisses me off that someone says TriX doesn't work etc only because it uses program from unknown source. The second reason mentioned at the beginning is I'm still working on so the badastudio is permanently outdated (this also applies to Wave Remaker - 0.0.71 against 0.06 in badastudio)
Click to expand...
Click to collapse
Oh sorry i dont know about that, i understand. Then what about NokiX ?
NokiX is tool for modify N*kia ARM7TDMI based firmwares. TriX also was designed for N*kia phones but it's very flexible so we can use it with different file types (ELF, PE, mobile firmwares)
If the author really want to include TriX in badastudio he should add small web check feature and download latest build when needed
I 'm the badaStudio author...do you want to say me anything?
badaStudio has been released 1 mounth ago...
the last version of wave remaker was the 0.0.6,
i'm not a mentalist....
the next badaStudio release is for bada2.0 tool...
I have written that the program inside the AIO is property of his author...
TriX is yours... Good..
TriX is not mine - was written by g3gg0 and krisha
I mentioned before TriX is still under development so the statement 'the program inside the AIO is property of his author' is very convenient for you because you aren't responsible for nothing.
Some solution could be integrated 'wget' module to download fresh package from the web. I'm open for suggestions
I have written 'the program inside the AIO is property of his author'
for WinImage (commercial program), for HxD (commercial program) and for WinHex (other commercial program)...
the responsibility is always of those who use the software,
if they download software from unknown source...
TriX was updated when I compiled the first version of badaStudio and
for what I needed it always worked (others have tested badaStudio)...
if you want to develop badaStudio send me a PM ...
it is programmed in Visual Basic.Net
Since when handset can handle oap files?
Never seen before nor tested...
I can see in WinComm some actions...
Best Regards
You have just discovered a method to install applications like .apk for Android?
If yes.... :') i would be so happy!! (we would be!)
A new era could begin.
great work AdFree! as always
I heard that first version of bada (1.0) was able to install *.oap files, but samsung disabled it to prevent from installing piracy apps. Maybe some CSC feature or variable in firmware?
So cool
but I tested both encoded OAP and decoded OAP and none of them works!!!
but a problem is that when i open asphalt6.oap with size of around 400mb it shows error without even 1 second loading
so where is the problem?!!
Well
You need to see this
It is so funny
This is DCF file
Of course it throw on me an error after opening dolfin
Best Regards
Tested short on JL2 ...
oap is not supported file... but DCF same info.
On bada 2.0 DCF leads to wrong site... maybe because this:
http...http...
Later more... need some time to test few things...
I'm now on JL2 and investigate more in certs... certchain...
About oap...
I heard that first version of bada (1.0) was able to install *.oap files, but samsung disabled it to prevent from installing piracy apps.
Click to expand...
Click to collapse
Yeah... Its complete weired at all...
http://developer.bada.com/badaforum...de-sdk&messageId=5584&startPage=94&curPage=96
From may 2010...
But remember... We have to differ between bada SDK (Developer) signed "testapps"... commercial apps from store... and Samsung signed apps...
But please take an look into:
AppEx\Sys\SamsungApps\SamsungApps.oap
Their are 3 more oap (ZIP) which are autorestore if you delete the apps from Osp folder...
Also all transfered files from Kies or from internal Store are oap (ZIP)...
Maybe we have to find correct folder...
Maybe we need license file + oap...
Maybe...
But why Samsung integrate this into handset visible for us?
Samsung has humor like this Andromeda Warp thingie...
An kind of easteregg?
Best Regards
Little progress...
On S8500XPKG5 I saw AppEx/Sys folder with both:
*.oap
AND
*.zip
Install of OAP shows me Error 0108...
Maybe I have an idea... will check more with WinComm...
Best Regards
0108
Installation failed: Failed to find root certificate.
The root certificate is not found on the device.The root certificateis required to build the certificate chain for the application integrity check.
Click to expand...
Click to collapse
...
Best Regards
Okay.
For XPKG5 I have managed to install all 3 types of App via ZIP... OAP.
I can install Samsung internal Apps... like in Firmware.
"Cert A"
I can install Samples like in SDK...
"Cert B" = rootCACert.cer
I can install Apps from store...
"Cert C"
All 3 Installations from SD Card or internal Memory with simple zipped files.
Best Regards
Stotter spotz.. since when does Bada support zip files
So how did you installed apps?
is there a special location we should put special certs there?
OAP Installation only successfully in XPKG5...
In other Firmware blocked...
Not sure yet why...
I will do some more tests...
XPKG5 include ZIP + OAP files... they are not 1 : 1
BDAgent.oap
BDAgent.zip
Maybe OAP need special Flag to work... will try if I am back on other Firmware...
Other method to install, this time in folders structure:
http://forum.xda-developers.com/showpost.php?p=24992809&postcount=35
Best Regards
hi adfree, I long to write to you on this issue with the files. OAP but I forgot as proof that telling the truth I'll add screen and a link to the file to confirm that I have not changed before extensions, i upload this file maybe can be useful to someone. sorry for my english i use google translate
rapidshare.com/#!download|214p1|3925164345|a6tczu9746.oap|24690
adfree said:
OAP Installation only successfully in XPKG5...
In other Firmware blocked...
Not sure yet why...
I will do some more tests...
XPKG5 include ZIP + OAP files... they are not 1 : 1
BDAgent.oap
BDAgent.zip
Maybe OAP need special Flag to work... will try if I am back on other Firmware...
Other method to install, this time in folders structure:
http://forum.xda-developers.com/showpost.php?p=24992809&postcount=35
Best Regards
Click to expand...
Click to collapse
Maybe winmerge is useful for comparing differences of these 2 files
BTW can device handle encoded OAP files?
@ maniek909
Your file is ENcrypted *.oap... During Installation on Wave it will be DEcrypt into "other Format"...
Then second *.oap file is only ZIP Archiv...
@ r_22009
Total Commander can compare 2 file also.
Best Regards
Now i have XPKG5
would you mind telling a short tut to install OAP?
thanks
would you mind telling a short tut to install OAP?
Click to expand...
Click to collapse
Only XPKG5...
1.
Install Certs... start with Cert from bada SDK:
rootCACert.cer
2.
Your app is now in ZIP Format... Check it or create self.
Rename into .oap
Remember, with rootCACert.cer you have to try better with bada SDK signed Apps...
Other 2 Certs came from Firmware... extract them...
Code:
Samsung_RootCA.crt
SamsungSBRootCA.cer
Best Regards
would you mind uploading the first cert as i dont have SDK? thankx
I am little bit paranoid...
I don't think Samsung is my best friend, if I share now their Certs...
To protect myself...
Btw...
Please be sure... you have visit and read some other threads...
As rootCACert.cer is floating around...
Btw 2...
I have forgotten, that Samsung moved in bada 2 to RSA 2048... before most RSA 1024 used in bada 1.x ...
So more Certs possible to try...
@ r_22009
Summary for you...
Use search or Google ...
Input:
rootCACert.cer
Best Regards
S8530 XPKD6 can also handle OAP...
Maybe interesting for research...
Best Regards
Simple question...
But no Answer...
Is there a way to get FOTA firmware files?
I know, download links could be found on the device in *.cfg file...
But is it possible to get these links without cfg file?
@adfree Where are you
If you have an device, where it works...
Then rename it...
You need only 3 incredients...
1.
Product Code
2.
Name of apps_compressed.bin or yesterday found way over CSC...
3.
Name of CSC...
Example.
I have:
S8500XXLG1/S8500DBTLA1 (DBT)
change into, as example
S723EXXLG1/S723EOXALG1 (DBT)
Start FOTA on your device... download file...
NOT update, no danger if you do...
Then check this file for Link
SyncML/2400257.cfg
Without FOTA working device it is posssible to download from Server... very easy.
Only you need to count... add + 1 ...
Problem... you can't search...
And you don't know what is inside the file... only which Product file and model name + date...
Best Regards
Uupsi...
S7230E is not good example...
No idea why. I am not able to find something...
But I can confirm that it work for:
S8530
S8600
S7250 ( I think I have tried... )
If you have only S8500.
Small bada I never tried before and I can't remember I have seen anything...
Maybe other URL ...
Best Regards