t-hack.com

English - X300T / X301T / DIT9719 / KISS KMM / BT Vision / Bluewin TV-Box / V-BOX/ VIP 1216 or similar Hardware => Software => Topic started by: cuss on 03. Oct 2010, 14:29

Title: Portuguese KMM3010 New Firmware - Can anyone unpack/pack it?
Post by: cuss on 03. Oct 2010, 14:29
Hi all,
can anyone unpack this DRA or give me an unpacker/packer?

I have an KMM3010, i have made some tests with the nk.bin and etc.bin ...

Here are the files that the box requests from our iptv servers:
http://rapidshare.com/files/422866731/From_Our_TFTP_-_KMM3010-PT.zip

- bootstrap
- dra (I wan't to know how to pack and unpack this file, to provide a hacked firmware to normal users)
- sync
Title: Re: Portuguese KMM3010 New Firmware - Can anyone unpack/pack it?
Post by: Mulder3 on 03. Oct 2010, 20:28
I've unpacked the dra file in the past, i don't recall how exactly, but i think it's just signed hashes in ASCII fallowed by a couple of concatenated files, including a WinCE rom(which you can unpack with wince tools viewbin.exe/dumprom.exe) that contains the actual recovery firmware, you can ignore the other files, they're encrypted XPU apps...

Anyway, you can alter the rom contents, but the box will reject it, because if you do that, the rom hash will change(the one included at the top of the dra file) and you will not be able to sign the new hash...

If you're interested you can find the "normal" firmware for MEO boxes at http://194.65.47.50/upgrade/upgrade-files/PKG.DIR
Title: Re: Portuguese KMM3010 New Firmware - Can anyone unpack/pack it?
Post by: mce2222 on 04. Oct 2010, 17:38
yeah. the bootstrap files do not really contain much.
as Mulder already wrote, the main firmware is loaded from the bootstrap process.
Title: Re: Portuguese KMM3010 New Firmware - Can anyone unpack/pack it?
Post by: cuss on 01. Dec 2010, 16:58
Does the PKG.DIR have some hash control?
Title: Re: Portuguese KMM3010 New Firmware - Can anyone unpack/pack it?
Post by: Mulder3 on 01. Dec 2010, 17:36
Yes, it has... You cannot load any non signed firmware unless you have jtag access! Period!