Thread: bootldr talk
View Single Post
Old 03-28-2012   #2
defyboy
Member
 
Join Date: Jan 2011
Posts: 161
Likes: 4
Liked 260 Times in 93 Posts
Mentioned: 52 Post(s)
Tagged: 0 Thread(s)
Originally Posted by munky875821417 View Post
couldn't the bootloader be decrypted by just replacing the metldr file in metldr838exploit with a bootldr. Just an idea. I expect someone to just shoot me down but I would like to know why not. I know its too simple to be complicated.
That would be the idea, the metldr exploit re-loads metldr in order to exploit it. The unfortunate thing is, bootldr does not re-load like metldr does, or atleast, we don't know how.

If we can re-load bootldr, indeed we can work on exploiting it, or even dumping the lv0 metadata like math explained.
defyboy is offline   Reply With Quote