01-12-2025, 12:04 PM
(01-12-2025, 11:37 AM)drsnooker Wrote: @b1tninja, I eventually got a clip and managed to get the NAND dumped in situ. However, since we know the root password as well as the algo for the password of user: rma (also with root privileges), it was no longer necessary to figure out how to binwalk the NAND dump, as you can just access the modem over UART.
Unfortunately the newer firmwares seem to prevent downgrade and one of the scripts at startup disables input over the debug port.
I did find a compatible connector for that the uart though which is handy: samtec MEC1-108-02-S-D-A.
Alright well thanks anyway guess I'm on my own I'll report back here when I figure it out