![]() |
|
|
Thread Tools | Display Modes |
![]() |
#1 |
New Member
Join Date: Jun 2020
City & State: Dorset
My Country: UK
I'm a: Knowledge Seeker
Posts: 9
|
![]() Hi all,
been lurking for a couple of weeks now, managed to get my hands on a cheap surface 3, UEFI password locked though.. I'm a complete noob at this and i think i've dumped the bios, anyone able to show me how to get the password or upload a clean bios for me to update with? Many thanks to you all! |
![]() |
![]() |
![]() |
#2 |
Badcaps Veteran
Join Date: Mar 2013
City & State: Tartu
My Country: Estonia
I'm a: Knowledge Seeker
Posts: 1,230
|
![]() Your rar file is 2.9KB thus invalid. Use flash programming tool (fptw64.exe -bios -d surface3.bin) to read bios region. Then upload it and I can get the password from there.
I think you need TXE2 flash programming tool for that. |
![]() |
![]() |
![]() |
#3 |
New Member
Join Date: Jun 2020
City & State: Dorset
My Country: UK
I'm a: Knowledge Seeker
Posts: 9
|
![]() Yah, i think i'm getting that issue at the moment, using \Intel ME System Tools v10.0 r7\MEInfo\WIN64>MEInfoWin64.exe
i get the error Error 9460: Unknown or unsupported hardware platform So i assume i have to go right back a version, the TXE2 version? Also thank you for your help and sorry - i'm such a noob. Havent been a windows user since XP.. |
![]() |
![]() |
![]() |
#4 |
Badcaps Veteran
Join Date: Mar 2013
City & State: Tartu
My Country: Estonia
I'm a: Knowledge Seeker
Posts: 1,230
|
![]() Yes, as I said, TXE2 should work.
|
![]() |
![]() |
![]() |
#5 |
New Member
Join Date: Jun 2020
City & State: Dorset
My Country: UK
I'm a: Knowledge Seeker
Posts: 9
|
![]() Thank you - I think i found the correct version and the command you gave me worked!
___________ Intel (R) Flash Programming Tool. Version: 2.0.5.3107 Copyright (c) 2007 - 2015, Intel Corporation. All rights reserved. Platform: Cherry Trail Reading HSFSTS register... Flash Descriptor: Valid --- Flash Devices Found --- MX25U6435F ID:0xC22537 Size: 8192KB (65536Kb) - Reading Flash [0x800000] 4096KB of 4096KB - 100% complete. Writing flash contents to file "surface3.bin"... Memory Dump Complete FPT Operation Passed _________________ Thank you again for your help, i'm learning a lot researching all these ![]() |
![]() |
![]() |
![]() |
#6 |
New Member
Join Date: Jun 2020
City & State: Dorset
My Country: UK
I'm a: Knowledge Seeker
Posts: 9
|
![]() Attachement:
|
![]() |
![]() |
![]() |
#7 |
Badcaps Veteran
Join Date: Mar 2013
City & State: Tartu
My Country: Estonia
I'm a: Knowledge Seeker
Posts: 1,230
|
![]() 1234567890
|
![]() |
![]() |
![]() |
#8 |
New Member
Join Date: Jun 2020
City & State: Dorset
My Country: UK
I'm a: Knowledge Seeker
Posts: 9
|
![]() |
![]() |
![]() |
![]() |
#9 |
Badcaps Veteran
Join Date: Mar 2013
City & State: Tartu
My Country: Estonia
I'm a: Knowledge Seeker
Posts: 1,230
|
![]() It is located in AMITSESetup section but it is slightly encrypted so some decryption is needed.
|
![]() |
![]() |
![]() |
#10 |
New Member
Join Date: Jun 2020
City & State: Dorset
My Country: UK
I'm a: Knowledge Seeker
Posts: 9
|
![]() oh amazing! wow, you sir are a god among men and i cannot thank you enough!!
|
![]() |
![]() |
![]() |
#11 |
Member
Join Date: Dec 2019
City & State: Internet
My Country: WWW
I'm a: Knowledge Seeker
Posts: 60
|
![]() |
![]() |
![]() |
![]() |
#12 |
Badcaps Veteran
Join Date: Mar 2020
City & State: my house
My Country: my workshop
I'm a: Knowledge Seeker
Posts: 1,093
|
![]() |
![]() |
![]() |
![]() |
#13 |
Member
Join Date: Jun 2020
City & State: Netherlands
My Country: Netherlands
I'm a: Knowledge Seeker
Posts: 28
|
![]() Hi!
If i`am correct AMI uses an XOR key to encrypt the SHA1 hash of the stored password (maybe scancode)? Would you provide some more infos how to recover the sha1 hash or password? |
![]() |
![]() |
![]() |
#14 | |
Member
Join Date: Jun 2020
City & State: Netherlands
My Country: Netherlands
I'm a: Knowledge Seeker
Posts: 28
|
![]() Quote:
Code:
3132333435363738393000000000000000000000 ![]() |
|
![]() |
![]() |
![]() |
#15 |
Badcaps Veteran
Join Date: Mar 2013
City & State: Tartu
My Country: Estonia
I'm a: Knowledge Seeker
Posts: 1,230
|
![]() Well done!
![]() |
![]() |
![]() |
![]() |
#16 |
Member
Join Date: Dec 2019
City & State: Internet
My Country: WWW
I'm a: Knowledge Seeker
Posts: 60
|
![]() |
![]() |
![]() |
![]() |
#17 |
Badcaps Veteran
Join Date: Mar 2013
City & State: Tartu
My Country: Estonia
I'm a: Knowledge Seeker
Posts: 1,230
|
![]() Open with uefitool. Open search, write AMITSESetup. You will get maybe 10 of those. Usually only 1 or 2 of them have content.
|
![]() |
![]() |
![]() |
#18 |
Member
Join Date: Jun 2020
City & State: Netherlands
My Country: Netherlands
I'm a: Knowledge Seeker
Posts: 28
|
![]() Check the AMITseSetup variable body with UEFITool, there is:
Code:
00000000000000000000000000000000 00000000000000000000000000000000 00000000000000006A93842622BA584D F2E014744A07E09A0A2EBEC1E95444E8 9F7BFA0E55A2B0350BC9665CC1EF1C83 01 Code:
6A93842622BA584D F2E014744A07E09A0A2EBEC1E95444E8 9F7BFA0E55A2B0350BC9665CC1EF1C83 |
![]() |
![]() |
![]() |
#19 | |
Member
Join Date: Dec 2019
City & State: Internet
My Country: WWW
I'm a: Knowledge Seeker
Posts: 60
|
![]() Quote:
https://md5decrypt.net/Xor/ This site working for decrypt ?? |
|
![]() |
![]() |
![]() |
#20 |
Member
Join Date: Dec 2019
City & State: Internet
My Country: WWW
I'm a: Knowledge Seeker
Posts: 60
|
![]() no one help ?
|
![]() |
![]() |
![]() |
Thread Tools | |
Display Modes | |
|
|