![]() |
|
|
Thread Tools | Display Modes |
![]() |
#1 |
New Member
Join Date: Jun 2021
City & State: Cologne
My Country: Germany
I'm a: Knowledge Seeker
Posts: 13
|
![]() As a lot of older firmware images use the well known, incredibly secure AMI XOR key to encode the supervisor password in the firmware image, I wrote a small Python tool to automate the process of searching through the image and decrypting the key. It is far from perfect but works well enough for me to share.
The tool uses UEFIExtract to dump the entire image, naively search for a folder ending in "AMITSEDecrypt", iterate through the body.bin to find all possible hashes stored in there, decrypt them with the XOR key, remove every second byte, then convert to ASCII. Usage: python3 AMITSEDecrypt <Path/to/image.bin> Hope it'll be of use to someone and excuse my horrible Python skills. |
![]() |
![]() |
![]() |
#2 |
Badcaps Veteran
Join Date: Oct 2012
City & State: kerala
My Country: india
I'm a: Student Tech
Posts: 216
|
![]() good jobe
|
![]() |
![]() |
![]() |
#3 |
Bad Veteran
Join Date: Feb 2018
City & State: Paris
My Country: France
I'm a: Knowledge Seeker
Posts: 394
|
![]() good job, untested for the moment, thanks
|
![]() |
![]() |
![]() |
#4 |
Badcaps Veteran
Join Date: Mar 2020
City & State: PARIS
My Country: France
I'm a: Knowledge Seeker
Posts: 243
|
![]() great job thank you
|
![]() |
![]() |
![]() |
#5 | |
New Member
Join Date: Jun 2021
City & State: Cologne
My Country: Germany
I'm a: Knowledge Seeker
Posts: 13
|
![]() Quote:
|
|
![]() |
![]() |
![]() |
#6 |
Badcaps Veteran
Join Date: Mar 2020
City & State: PARIS
My Country: France
I'm a: Knowledge Seeker
Posts: 243
|
![]() |
![]() |
![]() |
![]() |
#7 |
New Member
Join Date: Jun 2021
City & State: Cologne
My Country: Germany
I'm a: Knowledge Seeker
Posts: 13
|
![]() Glad it's of use to someone. I'd love to keep a list of devices using the AMITSESetup variable if only I could find out how to edit my posts
![]() |
![]() |
![]() |
![]() |
#8 |
Bad Veteran
Join Date: Feb 2018
City & State: Paris
My Country: France
I'm a: Knowledge Seeker
Posts: 394
|
![]() |
![]() |
![]() |
![]() |
#9 |
Member
Join Date: Jun 2015
City & State: Tampa, FL
My Country: USA/Puerto Rico
Line Voltage: Tickles the tongue
I'm a: Knowledge Seeker
Posts: 51
|
![]() this works with some of the Panasonic laptops.. not all tho.
|
![]() |
![]() |
![]() |
#10 |
New Member
Join Date: Jun 2021
City & State: Cologne
My Country: Germany
I'm a: Knowledge Seeker
Posts: 13
|
![]() Confirmed to work with at least those devices, will add more when I have some in:
- Microsoft Surface (Pro) 3 - Advantech MIO-5251 - Medion Lifetab P8912 - ASUS Vivobook Flip 14 TP412 I've noticed there's also a few AMI implementations storing the password in cleartext instead of scancodes, I'll probably add something to parse those aswell. And then there's some that look like SHA1 hashes, so I might at least add some functionality to detect those. |
![]() |
![]() |
![]() |
#11 | |
Banned
Join Date: Nov 2018
City & State: Rio de Janeiro
My Country: Brazil
I'm a: Professional Tech
Posts: 606
|
![]() Quote:
Similar to this here? I'm finishing the script in C++ to make it faster, I'll post it in Badcaps next week. Last edited by SMDFlea; 01-22-2022 at 03:13 AM.. |
|
![]() |
![]() |
![]() |
#12 |
Bad Veteran
Join Date: Feb 2018
City & State: Paris
My Country: France
I'm a: Knowledge Seeker
Posts: 394
|
![]() |
![]() |
![]() |
![]() |
#13 |
Banned
Join Date: Nov 2018
City & State: Rio de Janeiro
My Country: Brazil
I'm a: Professional Tech
Posts: 606
|
![]() |
![]() |
![]() |
![]() |
#14 |
Bad Veteran
Join Date: Feb 2018
City & State: Paris
My Country: France
I'm a: Knowledge Seeker
Posts: 394
|
![]() |
![]() |
![]() |
![]() |
#15 |
Banned
Join Date: Nov 2018
City & State: Rio de Janeiro
My Country: Brazil
I'm a: Professional Tech
Posts: 606
|
![]() |
![]() |
![]() |
![]() |
#16 | |
Banned
Join Date: Nov 2018
City & State: Rio de Janeiro
My Country: Brazil
I'm a: Professional Tech
Posts: 606
|
![]() Quote:
Helping users on the forums or outside of them has always been a hobby, I don't depend on it for a living. I've always liked to share my knowledge, that's the only way we can evolve. |
|
![]() |
![]() |
![]() |
#17 |
Super Moderator
Join Date: Jan 2018
City & State: York
My Country: UK
I'm a: Knowledge Seeker
Posts: 12,731
|
![]() |
![]() |
![]() |
![]() |
#18 |
Member
Join Date: Aug 2020
City & State: Internet
My Country: Poland
I'm a: Knowledge Seeker
Posts: 59
|
![]() I wrote small software for decrypt AMI BIOS Password. Software can read Admin and Boot password, just open file or drag and drop a file.
Enjoy. |
![]() |
![]() |
![]() |
#19 | |
Banned
Join Date: Nov 2018
City & State: Rio de Janeiro
My Country: Brazil
I'm a: Professional Tech
Posts: 606
|
![]() Quote:
Very cool, but it doesn't work!! Needs repairs... Last edited by SMDFlea; 11-04-2022 at 01:46 PM.. |
|
![]() |
![]() |
![]() |
#20 |
Member
Join Date: Aug 2020
City & State: Internet
My Country: Poland
I'm a: Knowledge Seeker
Posts: 59
|
![]() Working, working, but I forgot about this case. Now fixed and working well.
|
![]() |
![]() |
![]() |
Thread Tools | |
Display Modes | |
|
|