Removing WLAN/WWAN BIOS whitelist on a Lenovo laptop to use a custom Wi-Fi card-程序员宅基地

技术标签: 转载专用  Idapro  Modding  Whitelist  Uefi  Reverse Engineering  

So I had a Lenovo G510 that had a pretty bad Wi-Fi card. Once upon a time I’ve decided that it needs to be replaced, the most importantly to cover 5 GHz band, since the amount of other 2.4 GHz networks was large enough to make me loose the signal in the other room frequently enough. Before buying the card, however, I went on a little search only to find out (besides others also complaining about poor pre-installed Wi-Fi card) that Lenovo had put a whitelist check in BIOS and would only let you run “authorized” cards. What a pity. Following that I did read that BIOS is write-protected and the only way to modify it (in order to remove said whitelist) was to use an SPI programmer. That sounded interesting, so I thought I’ll give it a try and bought one.

I struggled a bit to find any good resources on this topic and it is the reason I’m writing this article. Besides removing whitelist, I also wanted to delete BIOS password that I apparently had set up a long time ago and forgot. Eventually I gave up on the latter, but removing the whitelist proved to be very easy following you know how to access the needed PE image section.

Firstly, some tips related to the SPI programmer stage. Before you do anything, you need to obtain the BIOS dump. It needs to be yours and you need to later flash it on the same laptop. You cannot download a clean image from vendor or a dump from someone else. Or maybe you can, but it could cause some side effects. I personally used CH341A-based device, along with the software that came with it (and SOIC8 clip, so I didn’t have to desolder the chip). Since my exact chip model (25Q064A) wasn’t listed, I was trying both EON EN25Q64 and Winbond W25QBV, both did work for it. Now for the reading part — you should clip the chip and read it with verify, then save the result, at least 2 times. Then compare files’ checksums. That way you will make sure the dump and clipping is correct. Before saving a file, make sure the read contents are not all “FF FF FF …” ‘till the end, because that means it’s empty and the clipping is wrong — re-adjust it and try again.

If you disconnect your clip before flashing, then you want to make sure it reads correctly before that as well (tip: chip contents and checksum will change after a boot, so don’t worry then if checksums differ from your previous dumps, you can flash then still flash their modified version over with no problems). For flashing the mod after it’s complete, load the file and press Auto button. It is going to erase the chip, verify it’s empty, flash new contents and verify they’re saved correctly. Do not flash chip before first erasing its contents, it will not work properly.

For the mod part, get UEFITool. You may want to get both old engine and new engine versions. The former lets you actually replace the body of different parts of your image, so this is required for us, the latter displays names instead of GUIDs in the tree, and it has search function, which you will need.

Open your dump in UEFITool NE and search for our beloved string of “Unauthorized Wireless network card is plugged in” (tick Unicode option).

 

Then open the same file in older branch UEFITool and try finding the same PE32 image section in the tree (you can click in names on NE items to find out what their GUIDs are).

Then right-click it and extract the body. This is what we’ll need to modify. I personally used IDA Pro, but if you follow this tutorial, you might just as well use a hex editor.

The easiest way to find our function in IDA was to search for sequence of bytes (our string):

55 00 6E 00 61 00 75 00 74 00 68 00 6F 00 72 00 69 00 7A 00 65 00 64 00 20 00 57 00 69 00 72 00 65 00 6C 00 65 00 73 00 73 00 20 00 6E 00 65 00 74 00 77 00 6F 00 72 00 6B 00 20 00 63 00 61 00 72 00 64 00 20 00 69 00 73 00 20 00 70 00 6C 00 75 00 67 00 67 00 65 00 64 00 20 00 69 00 6E

Then double-click on the only result to go to IDA View to find out that it was correctly identified as UTF-16LE string. Click on its autogenerated name and press X to go to Xrefs, and open the only function that pops up. Press hotkey for your decompiler if you have it installed.

We see the checks and an infinite while loop under that. This is what physically prevents our PC from booting up once it detects “unauthorized” card. We need to modify it. Go to IDA View and locate the infinite loop. It’s easy to see due to an arrow pointing back to the same location block.

Now press a jz a bit above it that either enters the loop or skips it based on the result of a test instruction above, and press Edit → Patch program → Assemble…

Change the instruction from jz to jmp, that way it will always make the jump to the location after the infinite loop.

You can also go to Hex View and change the highlighted 74 to EB manually.

But we can also see that these functions check the whitelist at all only if these variables are true:

Let’s locate what they are via Xrefs. We went back into _ModuleEntryPoint and we see that they are copied from yet another globals.

Let’s see what they are.

Bingo! Seems like this is global configuration for this module that configures whether WLAN and WWAN whitelists are enabled. It will be as simple as changing these two global bytes from 1 to 0 to mitigate our whitelist completely! Click on the respectable bytes and you will see what they are in Hex View.

To edit these, just right click, click “Edit…”, do edits, then “Apply changes” (or F2). Easy enough, right? If you don’t have IDA Pro, you should be able to reproduce these changes in any generic hex editor. Now to save modified file in IDA, go to Edit → Patch program → Apply patches to input file…

Once that’s done you can replace the image’s body in UEFITool (old engine).

After that press File → Save image file… It will ask you whether you want to load the modified file. Select Yes, and verify there are no errors, then export the modified body again and verify that its checksum matches with the file you created. If it does, you’re ready to flash your new BIOS!

This all worked for me. Definitely let me know if this article did help you in any way as well.

Links:
· https://www.youtube.com/watch?v=2Y06x1f22B0 — very good tutorial on using SPI programmer
· https://github.com/LongSoft/UEFITool — UEFITool
· https://github.com/gdbinit/EFISwissKnife — didn’t use this, but looks like it might be super-useful if I was to do more in-depth modding
· https://github.com/bdutro/ibm_pw_clear — interesting method one person used to clean a password on a server IBM
· https://web.archive.org/web/20120126182637/http://sodoityourself.com/hacking-ibm-thinkpad-bios-password/ — interesting for password retrieval, but old
· https://highside.pl/G510.jpg — location of the BIOS chip on G510’s motherboard (yeah, we need to disassemble pretty much whole laptop to parts in order to access it)
· https://www.bios-mods.com/forum/Thread-General-method-to-remove-whitelist-from-Insyde-BIOS — kind of similar approach, although it used almost 10 year old program to mod BIOS and did modify its memory, where it stored unpacked BIOS, and it only did patch out the infinite loop; I stumbled upon this initially, didn’t work for me, maybe this EzH2O software is just too old now 

版权声明:本文为博主原创文章,遵循 CC 4.0 BY-SA 版权协议,转载请附上原文出处链接和本声明。
本文链接:https://blog.csdn.net/qq1332479771/article/details/103542241

智能推荐

class和struct的区别-程序员宅基地

文章浏览阅读101次。4.class可以有⽆参的构造函数,struct不可以,必须是有参的构造函数,⽽且在有参的构造函数必须初始。2.Struct适⽤于作为经常使⽤的⼀些数据组合成的新类型,表示诸如点、矩形等主要⽤来存储数据的轻量。1.Class⽐较适合⼤的和复杂的数据,表现抽象和多级别的对象层次时。2.class允许继承、被继承,struct不允许,只能继承接⼝。3.Struct有性能优势,Class有⾯向对象的扩展优势。3.class可以初始化变量,struct不可以。1.class是引⽤类型,struct是值类型。

android使用json后闪退,应用闪退问题:从json信息的解析开始就会闪退-程序员宅基地

文章浏览阅读586次。想实现的功能是点击顶部按钮之后按关键字进行搜索,已经可以从服务器收到反馈的json信息,但从json信息的解析开始就会闪退,加载listview也不知道行不行public abstract class loadlistview{public ListView plv;public String js;public int listlength;public int listvisit;public..._rton转json为什么会闪退

如何使用wordnet词典,得到英文句子的同义句_get_synonyms wordnet-程序员宅基地

文章浏览阅读219次。如何使用wordnet词典,得到英文句子的同义句_get_synonyms wordnet

系统项目报表导出功能开发_积木报表 多线程-程序员宅基地

文章浏览阅读521次。系统项目报表导出 导出任务队列表 + 定时扫描 + 多线程_积木报表 多线程

ajax 如何从服务器上获取数据?_ajax 获取http数据-程序员宅基地

文章浏览阅读1.1k次,点赞9次,收藏9次。使用AJAX技术的好处之一是它能够提供更好的用户体验,因为它允许在不重新加载整个页面的情况下更新网页的某一部分。另外,AJAX还使得开发人员能够创建更复杂、更动态的Web应用程序,因为它们可以在后台与服务器进行通信,而不需要打断用户的浏览体验。在Web开发中,AJAX(Asynchronous JavaScript and XML)是一种常用的技术,用于在不重新加载整个页面的情况下,从服务器获取数据并更新网页的某一部分。使用AJAX,你可以创建异步请求,从而提供更快的响应和更好的用户体验。_ajax 获取http数据

Linux图形终端与字符终端-程序员宅基地

文章浏览阅读2.8k次。登录退出、修改密码、关机重启_字符终端

随便推点

Python与Arduino绘制超声波雷达扫描_超声波扫描建模 python库-程序员宅基地

文章浏览阅读3.8k次,点赞3次,收藏51次。前段时间看到一位发烧友制作的超声波雷达扫描神器,用到了Arduino和Processing,可惜啊,我不会Processing更看不懂人家的程序,咋办呢?嘿嘿,所以我就换了个思路解决,因为我会一点Python啊,那就动手吧!在做这个案例之前先要搞明白一个问题:怎么将Arduino通过超声波检测到的距离反馈到Python端?这个嘛,我首先想到了串行通信接口。没错!就是串口。只要Arduino将数据发送给COM口,然后Python能从COM口读取到这个数据就可以啦!我先写了一个测试程序试了一下,OK!搞定_超声波扫描建模 python库

凯撒加密方法介绍及实例说明-程序员宅基地

文章浏览阅读4.2k次。端—端加密指信息由发送端自动加密,并且由TCP/IP进行数据包封装,然后作为不可阅读和不可识别的数据穿过互联网,当这些信息到达目的地,将被自动重组、解密,而成为可读的数据。不可逆加密算法的特征是加密过程中不需要使用密钥,输入明文后由系统直接经过加密算法处理成密文,这种加密后的数据是无法被解密的,只有重新输入明文,并再次经过同样不可逆的加密算法处理,得到相同的加密密文并被系统重新识别后,才能真正解密。2.使用时,加密者查找明文字母表中需要加密的消息中的每一个字母所在位置,并且写下密文字母表中对应的字母。_凯撒加密

工控协议--cip--协议解析基本记录_cip协议embedded_service_error-程序员宅基地

文章浏览阅读5.7k次。CIP报文解析常用到的几个字段:普通类型服务类型:[0x00], CIP对象:[0x02 Message Router], ioi segments:[XX]PCCC(带cmd和func)服务类型:[0x00], CIP对象:[0x02 Message Router], cmd:[0x101], fnc:[0x101]..._cip协议embedded_service_error

如何在vs2019及以后版本(如vs2022)上添加 添加ActiveX控件中的MFC类_vs添加mfc库-程序员宅基地

文章浏览阅读2.4k次,点赞9次,收藏13次。有时候我们在MFC项目开发过程中,需要用到一些微软已经提供的功能,如VC++使用EXCEL功能,这时候我们就能直接通过VS2019到如EXCEL.EXE方式,生成对应的OLE头文件,然后直接使用功能,那么,我们上篇文章中介绍了vs2017及以前的版本如何来添加。但由于微软某些方面考虑,这种方式已被放弃。从上图中可以看出,这一功能,在从vs2017版本15.9开始,后续版本已经删除了此功能。那么我们如果仍需要此功能,我们如何在新版本中添加呢。_vs添加mfc库

frame_size (1536) was not respected for a non-last frame_frame_size (1024) was not respected for a non-last-程序员宅基地

文章浏览阅读785次。用ac3编码,执行编码函数时报错入如下:[ac3 @ 0x7fed7800f200] frame_size (1536) was not respected for anon-last frame (avcodec_encode_audio2)用ac3编码时每次送入编码器的音频采样数应该是1536个采样,不然就会报上述错误。这个数字并非刻意固定,而是跟ac3内部的编码算法原理相关。全网找不到,国内音视频之路还有很长的路,音视频人一起加油吧~......_frame_size (1024) was not respected for a non-last frame

Android移动应用开发入门_在安卓移动应用开发中要在活动类文件中声迷你一个复选框变量-程序员宅基地

文章浏览阅读230次,点赞2次,收藏2次。创建Android应用程序一个项目里面可以有很多模块,而每一个模块就对应了一个应用程序。项目结构介绍_在安卓移动应用开发中要在活动类文件中声迷你一个复选框变量

推荐文章

热门文章

相关标签