{"id":351,"date":"2026-04-08T21:31:39","date_gmt":"2026-04-08T21:31:39","guid":{"rendered":"https:\/\/thered0ne.com\/?p=351"},"modified":"2026-07-01T00:45:57","modified_gmt":"2026-07-01T00:45:57","slug":"reverse-engineering-nokia-beacon-3-1-part-1","status":"publish","type":"post","link":"https:\/\/thered0ne.com\/?p=351","title":{"rendered":"Nokia Beacon 3.1: Reverse Engineering (Part 1)"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n<div class=\"wp-block-image is-style-rounded\">\n<figure class=\"aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"751\" height=\"648\" src=\"https:\/\/thered0ne.com\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-03-104508.png\" alt=\"\" class=\"wp-image-352\" style=\"aspect-ratio:1;object-fit:cover;width:569px;height:auto\" srcset=\"https:\/\/thered0ne.com\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-03-104508.png 751w, https:\/\/thered0ne.com\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-03-104508-300x259.png 300w\" sizes=\"auto, (max-width: 751px) 100vw, 751px\" \/><\/figure>\n<\/div>\n\n\n<h1 class=\"wp-block-heading\">Introduction:<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Hello again, fellow hackers and researchers. Today I\u2019m starting a major series: a deep dive into my reverse engineering journey with the Nokia Beacon 3.1. This router is remarkably hardened, and getting shell access required overcoming significant obstacles. While my research into potential vulnerabilities is ongoing, I\u2019m ready to share the roadmap for accessing root account and exploring the filesystem. If you\u2019re looking to conduct your own security research on this hardware, here is how the journey begins.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">Nokia Beacon 3.1 &#8211; Key Features:<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">This device is typically made for easy whole home Wi-Fi extension and is praised for reliable performance and simple app based setup. It&#8217;s known by its Mesh Networking, its advanced Wi-Fi features. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The internals are:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">1x Gigabit WAN<br>2x Gigabit LAN.<br>Dual core 1.6 Ghz CPU<br>512 Mb DDR.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">The problem &amp; mission<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">At first, I wasn\u2019t very surprised that the UI looked limited and not very user-friendly. I assumed this router was designed for regular users who just want to connect to Wi-Fi and not do much with advanced options. The lack of documentation was also problematic. I found in the user manual that there is a superadmin account, but I didn\u2019t have access to it because each router has its own password, and the same applies to the superadmin account as well.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I called the ISP and asked for the superadmin password. To my surprise, the process was smooth and I obtained it easily. However, the victory was short-lived. once logged in, I found the configuration options were almost identical to the standard user UI. The mission then became clear: I had to find a way to gain true control over the device. It was frustrating to realize that, despite owning the hardware, I was still locked out of my own machine.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">Reconnaissance: Mapping the attack surface<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">A visual inspection reveals this beautiful cup shape:<\/p>\n\n\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"329\" height=\"352\" data-id=\"355\" src=\"https:\/\/thered0ne.com\/wp-content\/uploads\/2026\/04\/image.png\" alt=\"\" class=\"wp-image-355\" style=\"width:284px;height:auto\" srcset=\"https:\/\/thered0ne.com\/wp-content\/uploads\/2026\/04\/image.png 329w, https:\/\/thered0ne.com\/wp-content\/uploads\/2026\/04\/image-280x300.png 280w\" sizes=\"auto, (max-width: 329px) 100vw, 329px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"320\" height=\"345\" data-id=\"357\" src=\"https:\/\/thered0ne.com\/wp-content\/uploads\/2026\/04\/image-2.png\" alt=\"\" class=\"wp-image-357\" style=\"width:280px;height:auto\" srcset=\"https:\/\/thered0ne.com\/wp-content\/uploads\/2026\/04\/image-2.png 320w, https:\/\/thered0ne.com\/wp-content\/uploads\/2026\/04\/image-2-278x300.png 278w\" sizes=\"auto, (max-width: 320px) 100vw, 320px\" \/><\/figure>\n<\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">I was impressed by the build quality. The electronics are packed and supported by a heatsink.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignleft size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"618\" height=\"437\" src=\"https:\/\/thered0ne.com\/wp-content\/uploads\/2026\/04\/image-3.png\" alt=\"\" class=\"wp-image-358\" style=\"aspect-ratio:1.4142238590553924;width:414px;height:auto\" srcset=\"https:\/\/thered0ne.com\/wp-content\/uploads\/2026\/04\/image-3.png 618w, https:\/\/thered0ne.com\/wp-content\/uploads\/2026\/04\/image-3-300x212.png 300w\" sizes=\"auto, (max-width: 618px) 100vw, 618px\" \/><\/figure>\n<\/div>\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"445\" height=\"530\" src=\"https:\/\/thered0ne.com\/wp-content\/uploads\/2026\/04\/image-4.png\" alt=\"\" class=\"wp-image-359\" style=\"width:383px;height:auto\" srcset=\"https:\/\/thered0ne.com\/wp-content\/uploads\/2026\/04\/image-4.png 445w, https:\/\/thered0ne.com\/wp-content\/uploads\/2026\/04\/image-4-252x300.png 252w\" sizes=\"auto, (max-width: 445px) 100vw, 445px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">It\u2019s clear from the outside that this isn&#8217;t a budget router, but does that premium feel extend to the internal software? To truly own this device, I had to find out if the brain was as high performance as the body. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I assume you already know how the UI looks. However, something important I noticed really annoyed me at first: all the payloads in POST methods are encrypted. The frontend is Angular based, and all the traffic between the frontend and the local backend is encrypted. A JavaScript function uses a public key stored in local storage during the browser session to encrypt the data.<br>I asked myself why they did that, since JavaScript can be modified at runtime using DevTools. What\u2019s the purpose of this?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I came up with two possible answers:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Ensure the traffic is secure, since almost all routers use HTTP, which makes traffic visible in clear text on the LAN.<\/li>\n\n\n\n<li>Security through obscurity. I think they also want to make things a little harder for hackers.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">In a standard setup, HTTPS handles the transport, but you can still see the JSON in the clear in your Network tab. Here, they&#8217;ve added a custom application layer encryption that turns every interaction into an unreadable blob of ciphertext. I have to admit this was the first time I saw the body of POST requests encrypted.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"646\" height=\"525\" src=\"https:\/\/thered0ne.com\/wp-content\/uploads\/2026\/04\/image-5.png\" alt=\"\" class=\"wp-image-361\" srcset=\"https:\/\/thered0ne.com\/wp-content\/uploads\/2026\/04\/image-5.png 646w, https:\/\/thered0ne.com\/wp-content\/uploads\/2026\/04\/image-5-300x244.png 300w\" sizes=\"auto, (max-width: 646px) 100vw, 646px\" \/><\/figure>\n<\/div>\n\n\n<h1 class=\"wp-block-heading\">The First Wall : Body Encryption<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">So the idea is simple, when I&#8217;m in front of a router, I try a command injection in ping\/traceroute to see if it&#8217;s vulnerable. This is a classic approach that every hardware hacker knows. However, to achieve that we have to bypass the first wall which the encryption. The approach is intercept the data before encryption, change it and encrypt it after.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I opened devtool and search for encrypt function in the source code and I found the function responsible to encrypt data. I put a breakpoint in the return instruction and I pressed the &#8220;Start test&#8221; in the diagnostics page.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"955\" height=\"1007\" src=\"https:\/\/thered0ne.com\/wp-content\/uploads\/2026\/04\/image-7.png\" alt=\"\" class=\"wp-image-363\" srcset=\"https:\/\/thered0ne.com\/wp-content\/uploads\/2026\/04\/image-7.png 955w, https:\/\/thered0ne.com\/wp-content\/uploads\/2026\/04\/image-7-285x300.png 285w, https:\/\/thered0ne.com\/wp-content\/uploads\/2026\/04\/image-7-768x810.png 768w\" sizes=\"auto, (max-width: 955px) 100vw, 955px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">As you can see, now it is possible to see the body in clear text before encryption. The payload was this:<\/p>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span role=\"button\" tabindex=\"0\" style=\"color:#F8F8F2;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><pre class=\"code-block-pro-copy-button-pre\" aria-hidden=\"true\"><textarea class=\"code-block-pro-copy-button-textarea\" tabindex=\"-1\" aria-hidden=\"true\" readonly>\"encrypted=1&amp;ct=1y8fg4CK9-s-ucdzMEVpPof11ocwCWRThTZUIJFMcJcvG5aOBa3HTKfdAfZOU8IYdUwTSFB8KRN2V4oBb80B8VKK4HzUXwWBZalwAuor7ze_wwcgxOLakq9UdpWaSHFTRkyqe9NmlXA44w2ffmAAO7h7X55guHJq-mwvqMKNYP_1hZLuXNoSjqQMgbPkCl-iNXrSjsNhLy5nlynEAsiqbr5pdAKHz3SQg3DTxtZfOkE&amp;ck=RbfmMshNmk2j111DeZVM9IIvpZ2Zo4U03aODWfcr7Gr6jUO8pUodFfmDZMFuoyA33K2T6LDzVsoGWpyXXzIE9Q79wEJ1YCfWRZFCLk668B5Dopti9Ar2IW06yo2-b6n_hExBoJQWqd8CWCeWUNc00D-xuRKLd8evjQ_7jAu7nZI.\"\n\n\/\/ It becomes this:\n\ndirection=rx&amp;domain=&amp;ipaddress=&amp;lan_port=LAN1&amp;portstatus=Disconnected&amp;status=enable&amp;wan_port=WAN&amp;wan_conlist=1&amp;waninterfacename=lo|id>\/tmp\/red1&amp;csrf_token=yyxOKBJGOAUWbvPW<\/textarea><\/pre><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki monokai\" style=\"background-color: #272822\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #E6DB74\">&quot;encrypted=1&amp;ct=1y8fg4CK9-s-ucdzMEVpPof11ocwCWRThTZUIJFMcJcvG5aOBa3HTKfdAfZOU8IYdUwTSFB8KRN2V4oBb80B8VKK4HzUXwWBZalwAuor7ze_wwcgxOLakq9UdpWaSHFTRkyqe9NmlXA44w2ffmAAO7h7X55guHJq-mwvqMKNYP_1hZLuXNoSjqQMgbPkCl-iNXrSjsNhLy5nlynEAsiqbr5pdAKHz3SQg3DTxtZfOkE&amp;ck=RbfmMshNmk2j111DeZVM9IIvpZ2Zo4U03aODWfcr7Gr6jUO8pUodFfmDZMFuoyA33K2T6LDzVsoGWpyXXzIE9Q79wEJ1YCfWRZFCLk668B5Dopti9Ar2IW06yo2-b6n_hExBoJQWqd8CWCeWUNc00D-xuRKLd8evjQ_7jAu7nZI.&quot;<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #88846F\">\/\/ It becomes this:<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">direction<\/span><span style=\"color: #F92672\">=<\/span><span style=\"color: #F8F8F2\">rx<\/span><span style=\"color: #F92672\">&amp;<\/span><span style=\"color: #F8F8F2\">domain<\/span><span style=\"color: #F92672\">=&amp;<\/span><span style=\"color: #F8F8F2\">ipaddress<\/span><span style=\"color: #F92672\">=&amp;<\/span><span style=\"color: #F8F8F2\">lan_port<\/span><span style=\"color: #F92672\">=<\/span><span style=\"color: #F8F8F2\">LAN1<\/span><span style=\"color: #F92672\">&amp;<\/span><span style=\"color: #F8F8F2\">portstatus<\/span><span style=\"color: #F92672\">=<\/span><span style=\"color: #F8F8F2\">Disconnected<\/span><span style=\"color: #F92672\">&amp;<\/span><span style=\"color: #F8F8F2\">status<\/span><span style=\"color: #F92672\">=<\/span><span style=\"color: #F8F8F2\">enable<\/span><span style=\"color: #F92672\">&amp;<\/span><span style=\"color: #F8F8F2\">wan_port<\/span><span style=\"color: #F92672\">=<\/span><span style=\"color: #F8F8F2\">WAN<\/span><span style=\"color: #F92672\">&amp;<\/span><span style=\"color: #F8F8F2\">wan_conlist<\/span><span style=\"color: #F92672\">=<\/span><span style=\"color: #AE81FF\">1<\/span><span style=\"color: #F92672\">&amp;<\/span><span style=\"color: #F8F8F2\">waninterfacename<\/span><span style=\"color: #F92672\">=<\/span><span style=\"color: #F8F8F2\">lo<\/span><span style=\"color: #F92672\">|<\/span><span style=\"color: #F8F8F2\">id<\/span><span style=\"color: #F92672\">&gt;\/<\/span><span style=\"color: #F8F8F2\">tmp<\/span><span style=\"color: #F92672\">\/<\/span><span style=\"color: #F8F8F2\">red1<\/span><span style=\"color: #F92672\">&amp;<\/span><span style=\"color: #F8F8F2\">csrf_token<\/span><span style=\"color: #F92672\">=<\/span><span style=\"color: #F8F8F2\">yyxOKBJGOAUWbvPW<\/span><\/span><\/code><\/pre><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">We can patch this by injecting a code that will prompt us the payload modifying it and send it again. I also another method to automate this by using Pupperteer automation API for chromium but you got the idea use your imagination or AI \ud83d\ude09<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">The Second Wall: UART<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Locating the UART (Universal Asynchronous Receiver-Transmitter) interface is usually straightforward, typically appearing as a row of <strong>3 or 4 unpopulated pins<\/strong> or pads. To map them without a schematic, you just need a multimeter and a bit of patience.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"603\" height=\"481\" src=\"https:\/\/thered0ne.com\/wp-content\/uploads\/2026\/04\/image-8.png\" alt=\"\" class=\"wp-image-365\" srcset=\"https:\/\/thered0ne.com\/wp-content\/uploads\/2026\/04\/image-8.png 603w, https:\/\/thered0ne.com\/wp-content\/uploads\/2026\/04\/image-8-300x239.png 300w\" sizes=\"auto, (max-width: 603px) 100vw, 603px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">In the image above I found the 3 pads. I connect them using an FTDI. Ensure that you identified the GND first. And for the TX and the RX just try one by one, set the baud rate in your favorite terminal (most of the time is 115200) and voila \u2728 \ud83d\ude80 \ud83e\udd29 \u2728<\/p>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span role=\"button\" tabindex=\"0\" style=\"color:#F8F8F2;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><pre class=\"code-block-pro-copy-button-pre\" aria-hidden=\"true\"><textarea class=\"code-block-pro-copy-button-textarea\" tabindex=\"-1\" aria-hidden=\"true\" readonly>NOTICE: BL31: v1.5(release):gdbd64f1a0-dirty\nNOTICE: BL31: Built : 14:42:03, Jul 8 2024\nWARNING: Using deprecated integer interrupt arrays in gicv3_driver_data_t\nWARNING: Please migrate to using interrupt_prop_t arrays\nNOTICE: boot from serial NAND flash\nNOTICE: BL31: SPI_NAND: MT29F2G01ABAGDWB\/F50L2G41XA\/XT26G02ELGIG\/WSFVC32GBID 0x2c24\nNOTICE: BL31: SPI_NAND: Page 0x800, Block 0x20000, Chip 256MB\nNOTICE: BL31: plane_select=0x40, plane_select_bit=0x1000\nNOTICE: BL31: SECURE DRAM SIZE is 0x00800000\n\nU-Boot 2020.01 (Jul 24 2025 - 18:35:30 +0800) Taurus-SoC (OPTEE)\n\nCortexA55: 1000 MHz\nDDR4-1866: 16-bit mode, 512 MiB\n\nNAND:\n  scan_spi_nand_factory_bad_blocks&#91;899&#93;: found list\nSPI NAND:\n  Model: \n  ID: 0x2c24\n  Spare: 0x80 (128B)\n  Page:  0x800 (2KB)\n  Block: 0x20000 (128KB)\n  Chip:  0x10000000 (256MB)\n  Available: 256MB\n  Mode: S\/S\n  Clock: 100 MHz\n  BBL: Bbl0 from flash\n\nLoading Environment from NAND... OK\n\nenter console_disable_check\ncheck_parts&#91;2110&#93;: not change\nconsole_disable_check&#91;48&#93;: SN: \nserial_enable = 0\n>>>>>>>> Serial console Disabled &lt;&lt;&lt;&lt;&lt;&lt;&lt;&lt;\n\nNOTICE: Booting Trusted Firmware - Realtek Semiconductor Corp.\n\nNOTICE: BL1: v1.5(release): TAURUS_TAPEOUT_2_0\nNOTICE: BL1: Built : 17:13:20, Oct 27 2021\nNOTICE: BL1: CPU Speed 1000 MHz\nNOTICE: GLOBAL_STRAP 0xc0a\nNOTICE: boot from serial NAND flash\n\nNOTICE: BL1: Booting BL2\nNOTICE: BL2: RTL9607DQ\nNOTICE: boot from serial NAND flash\n\n##### DRAM driver version (TAURUS): V0.7.5 #####\nINFO: PKG=BGA15\nINFO: dram_type = 4\nINFO: dram_freq = 933\nINFO: dram_dq = 16\nINFO: DRAM size = 4Gb\nINFO: Done DDR initialization...\nINFO: DRAM test PASS\nINFO: Address toggle PASS\n\nNOTICE: BL2: v1.5(release): gdbd64f1a0-dirty\nNOTICE: BL2: Built : 14:42:03, Jul 8 2024\n\nNOTICE: BL1: Booting BL31\nNOTICE: BL31: v1.5(release): gdbd64f1a0-dirty\nNOTICE: BL31: Built : 14:42:03, Jul 8 2024\nNOTICE: BL31: SECURE DRAM SIZE is 0x00800000\n\nBooting Linux...\n\n&#91;    0.000000&#93; Linux version 5.10.161 (OpenWrt GCC 11.2.0)\n&#91;    0.000000&#93; Machine model: Realtek Taurus ENG Board\n&#91;    0.000000&#93; earlycon: serial0 at MMIO 0xf43291b0\n&#91;    0.000000&#93; Kernel command line:\n  earlycon=serial,0xf43291b0\n  console=ttyS0,115200\n  serial_is_dis=1\n  root=\/dev\/dm-0\n  rootfstype=squashfs\n  dm-verity enabled\n\n&#91;    0.000000&#93; serial_is_dis_setup: will disable serial<\/textarea><\/pre><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki monokai\" style=\"background-color: #272822\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #F8F8F2\">NOTICE: BL31: v1.<\/span><span style=\"color: #AE81FF\">5<\/span><span style=\"color: #F8F8F2\">(release):gdbd64f1a0<\/span><span style=\"color: #F92672\">-<\/span><span style=\"color: #F8F8F2\">dirty<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">NOTICE: BL31: Built : <\/span><span style=\"color: #AE81FF\">14<\/span><span style=\"color: #F8F8F2\">:<\/span><span style=\"color: #AE81FF\">42<\/span><span style=\"color: #F8F8F2\">:<\/span><span style=\"color: #AE81FF\">03<\/span><span style=\"color: #F8F8F2\">, Jul <\/span><span style=\"color: #AE81FF\">8<\/span><span style=\"color: #F8F8F2\"> <\/span><span style=\"color: #AE81FF\">2024<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">WARNING: Using deprecated integer interrupt arrays <\/span><span style=\"color: #F92672\">in<\/span><span style=\"color: #F8F8F2\"> gicv3_driver_data_t<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">WARNING: Please migrate to <\/span><span style=\"color: #66D9EF; font-style: italic\">using<\/span><span style=\"color: #F8F8F2\"> interrupt_prop_t arrays<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">NOTICE: boot from serial NAND flash<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">NOTICE: BL31: SPI_NAND: MT29F2G01ABAGDWB<\/span><span style=\"color: #F92672\">\/<\/span><span style=\"color: #F8F8F2\">F50L2G41XA<\/span><span style=\"color: #F92672\">\/<\/span><span style=\"color: #F8F8F2\">XT26G02ELGIG<\/span><span style=\"color: #F92672\">\/<\/span><span style=\"color: #F8F8F2\">WSFVC32GBID <\/span><span style=\"color: #AE81FF\">0x2c24<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">NOTICE: BL31: SPI_NAND: Page <\/span><span style=\"color: #AE81FF\">0x800<\/span><span style=\"color: #F8F8F2\">, Block <\/span><span style=\"color: #AE81FF\">0x20000<\/span><span style=\"color: #F8F8F2\">, Chip 256MB<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">NOTICE: BL31: plane_select<\/span><span style=\"color: #F92672\">=<\/span><span style=\"color: #AE81FF\">0x40<\/span><span style=\"color: #F8F8F2\">, plane_select_bit<\/span><span style=\"color: #F92672\">=<\/span><span style=\"color: #AE81FF\">0x1000<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">NOTICE: BL31: SECURE DRAM SIZE is <\/span><span style=\"color: #AE81FF\">0x00800000<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">U<\/span><span style=\"color: #F92672\">-<\/span><span style=\"color: #F8F8F2\">Boot <\/span><span style=\"color: #AE81FF\">2020.01<\/span><span style=\"color: #F8F8F2\"> (Jul <\/span><span style=\"color: #AE81FF\">24<\/span><span style=\"color: #F8F8F2\"> <\/span><span style=\"color: #AE81FF\">2025<\/span><span style=\"color: #F8F8F2\"> <\/span><span style=\"color: #F92672\">-<\/span><span style=\"color: #F8F8F2\"> <\/span><span style=\"color: #AE81FF\">18<\/span><span style=\"color: #F8F8F2\">:<\/span><span style=\"color: #AE81FF\">35<\/span><span style=\"color: #F8F8F2\">:<\/span><span style=\"color: #AE81FF\">30<\/span><span style=\"color: #F8F8F2\"> <\/span><span style=\"color: #F92672\">+<\/span><span style=\"color: #AE81FF\">0800<\/span><span style=\"color: #F8F8F2\">) Taurus<\/span><span style=\"color: #F92672\">-<\/span><span style=\"color: #A6E22E\">SoC<\/span><span style=\"color: #F8F8F2\"> (OPTEE)<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">CortexA55: <\/span><span style=\"color: #AE81FF\">1000<\/span><span style=\"color: #F8F8F2\"> MHz<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">DDR4<\/span><span style=\"color: #F92672\">-<\/span><span style=\"color: #AE81FF\">1866<\/span><span style=\"color: #F8F8F2\">: <\/span><span style=\"color: #AE81FF\">16<\/span><span style=\"color: #F92672\">-<\/span><span style=\"color: #F8F8F2\">bit mode, <\/span><span style=\"color: #AE81FF\">512<\/span><span style=\"color: #F8F8F2\"> MiB<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">NAND:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">  scan_spi_nand_factory_bad_blocks&#91;<\/span><span style=\"color: #AE81FF\">899<\/span><span style=\"color: #F8F8F2\">&#93;: found list<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">SPI NAND:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">  Model: <\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">  ID: <\/span><span style=\"color: #AE81FF\">0x2c24<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">  Spare: <\/span><span style=\"color: #AE81FF\">0x80<\/span><span style=\"color: #F8F8F2\"> (128B)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">  Page:  <\/span><span style=\"color: #AE81FF\">0x800<\/span><span style=\"color: #F8F8F2\"> (2KB)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">  Block: <\/span><span style=\"color: #AE81FF\">0x20000<\/span><span style=\"color: #F8F8F2\"> (128KB)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">  Chip:  <\/span><span style=\"color: #AE81FF\">0x10000000<\/span><span style=\"color: #F8F8F2\"> (256MB)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">  Available: 256MB<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">  Mode: S<\/span><span style=\"color: #F92672\">\/<\/span><span style=\"color: #F8F8F2\">S<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">  Clock: <\/span><span style=\"color: #AE81FF\">100<\/span><span style=\"color: #F8F8F2\"> MHz<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">  BBL: Bbl0 from flash<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">Loading Environment from NAND<\/span><span style=\"color: #F92672\">...<\/span><span style=\"color: #F8F8F2\"> OK<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">enter console_disable_check<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">check_parts&#91;<\/span><span style=\"color: #AE81FF\">2110<\/span><span style=\"color: #F8F8F2\">&#93;: not change<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">console_disable_check&#91;<\/span><span style=\"color: #AE81FF\">48<\/span><span style=\"color: #F8F8F2\">&#93;: SN: <\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">serial_enable <\/span><span style=\"color: #F92672\">=<\/span><span style=\"color: #F8F8F2\"> <\/span><span style=\"color: #AE81FF\">0<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F92672\">&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;<\/span><span style=\"color: #F8F8F2\"> Serial console Disabled <\/span><span style=\"color: #F92672\">&lt;&lt;&lt;&lt;&lt;&lt;&lt;&lt;<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">NOTICE: Booting Trusted Firmware <\/span><span style=\"color: #F92672\">-<\/span><span style=\"color: #F8F8F2\"> Realtek Semiconductor Corp.<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">NOTICE: BL1: v1.<\/span><span style=\"color: #AE81FF\">5<\/span><span style=\"color: #F8F8F2\">(release): TAURUS_TAPEOUT_2_0<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">NOTICE: BL1: Built : <\/span><span style=\"color: #AE81FF\">17<\/span><span style=\"color: #F8F8F2\">:<\/span><span style=\"color: #AE81FF\">13<\/span><span style=\"color: #F8F8F2\">:<\/span><span style=\"color: #AE81FF\">20<\/span><span style=\"color: #F8F8F2\">, Oct <\/span><span style=\"color: #AE81FF\">27<\/span><span style=\"color: #F8F8F2\"> <\/span><span style=\"color: #AE81FF\">2021<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">NOTICE: BL1: CPU Speed <\/span><span style=\"color: #AE81FF\">1000<\/span><span style=\"color: #F8F8F2\"> MHz<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">NOTICE: GLOBAL_STRAP <\/span><span style=\"color: #AE81FF\">0xc0a<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">NOTICE: boot from serial NAND flash<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">NOTICE: BL1: Booting BL2<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">NOTICE: BL2: RTL9607DQ<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">NOTICE: boot from serial NAND flash<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">##### DRAM driver <\/span><span style=\"color: #A6E22E\">version<\/span><span style=\"color: #F8F8F2\"> (TAURUS): V0.<\/span><span style=\"color: #AE81FF\">7.5<\/span><span style=\"color: #F8F8F2\"> #####<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">INFO: PKG<\/span><span style=\"color: #F92672\">=<\/span><span style=\"color: #F8F8F2\">BGA15<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">INFO: dram_type <\/span><span style=\"color: #F92672\">=<\/span><span style=\"color: #F8F8F2\"> <\/span><span style=\"color: #AE81FF\">4<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">INFO: dram_freq <\/span><span style=\"color: #F92672\">=<\/span><span style=\"color: #F8F8F2\"> <\/span><span style=\"color: #AE81FF\">933<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">INFO: dram_dq <\/span><span style=\"color: #F92672\">=<\/span><span style=\"color: #F8F8F2\"> <\/span><span style=\"color: #AE81FF\">16<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">INFO: DRAM size <\/span><span style=\"color: #F92672\">=<\/span><span style=\"color: #F8F8F2\"> 4Gb<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">INFO: Done DDR initialization<\/span><span style=\"color: #F92672\">...<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">INFO: DRAM test PASS<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">INFO: Address toggle PASS<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">NOTICE: BL2: v1.<\/span><span style=\"color: #AE81FF\">5<\/span><span style=\"color: #F8F8F2\">(release): gdbd64f1a0<\/span><span style=\"color: #F92672\">-<\/span><span style=\"color: #F8F8F2\">dirty<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">NOTICE: BL2: Built : <\/span><span style=\"color: #AE81FF\">14<\/span><span style=\"color: #F8F8F2\">:<\/span><span style=\"color: #AE81FF\">42<\/span><span style=\"color: #F8F8F2\">:<\/span><span style=\"color: #AE81FF\">03<\/span><span style=\"color: #F8F8F2\">, Jul <\/span><span style=\"color: #AE81FF\">8<\/span><span style=\"color: #F8F8F2\"> <\/span><span style=\"color: #AE81FF\">2024<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">NOTICE: BL1: Booting BL31<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">NOTICE: BL31: v1.<\/span><span style=\"color: #AE81FF\">5<\/span><span style=\"color: #F8F8F2\">(release): gdbd64f1a0<\/span><span style=\"color: #F92672\">-<\/span><span style=\"color: #F8F8F2\">dirty<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">NOTICE: BL31: Built : <\/span><span style=\"color: #AE81FF\">14<\/span><span style=\"color: #F8F8F2\">:<\/span><span style=\"color: #AE81FF\">42<\/span><span style=\"color: #F8F8F2\">:<\/span><span style=\"color: #AE81FF\">03<\/span><span style=\"color: #F8F8F2\">, Jul <\/span><span style=\"color: #AE81FF\">8<\/span><span style=\"color: #F8F8F2\"> <\/span><span style=\"color: #AE81FF\">2024<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">NOTICE: BL31: SECURE DRAM SIZE is <\/span><span style=\"color: #AE81FF\">0x00800000<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">Booting Linux<\/span><span style=\"color: #F92672\">...<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">&#91;    <\/span><span style=\"color: #AE81FF\">0.000000<\/span><span style=\"color: #F8F8F2\">&#93; Linux version <\/span><span style=\"color: #AE81FF\">5.10<\/span><span style=\"color: #F8F8F2\">.<\/span><span style=\"color: #AE81FF\">161<\/span><span style=\"color: #F8F8F2\"> (OpenWrt GCC <\/span><span style=\"color: #AE81FF\">11.2<\/span><span style=\"color: #F8F8F2\">.<\/span><span style=\"color: #AE81FF\">0<\/span><span style=\"color: #F8F8F2\">)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">&#91;    <\/span><span style=\"color: #AE81FF\">0.000000<\/span><span style=\"color: #F8F8F2\">&#93; Machine model: Realtek Taurus ENG Board<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">&#91;    <\/span><span style=\"color: #AE81FF\">0.000000<\/span><span style=\"color: #F8F8F2\">&#93; earlycon: serial0 at MMIO <\/span><span style=\"color: #AE81FF\">0xf43291b0<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">&#91;    <\/span><span style=\"color: #AE81FF\">0.000000<\/span><span style=\"color: #F8F8F2\">&#93; Kernel command line:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">  earlycon<\/span><span style=\"color: #F92672\">=<\/span><span style=\"color: #F8F8F2\">serial,<\/span><span style=\"color: #AE81FF\">0xf43291b0<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">  console<\/span><span style=\"color: #F92672\">=<\/span><span style=\"color: #F8F8F2\">ttyS0,<\/span><span style=\"color: #AE81FF\">115200<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">  serial_is_dis<\/span><span style=\"color: #F92672\">=<\/span><span style=\"color: #AE81FF\">1<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">  root<\/span><span style=\"color: #F92672\">=<\/span><span style=\"color: #E6DB74\">\/dev\/<\/span><span style=\"color: #F92672\">dm<\/span><span style=\"color: #F92672\">-<\/span><span style=\"color: #AE81FF\">0<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">  rootfstype<\/span><span style=\"color: #F92672\">=<\/span><span style=\"color: #F8F8F2\">squashfs<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">  dm<\/span><span style=\"color: #F92672\">-<\/span><span style=\"color: #F8F8F2\">verity enabled<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">&#91;    <\/span><span style=\"color: #AE81FF\">0.000000<\/span><span style=\"color: #F8F8F2\">&#93; serial_is_dis_setup: will disable serial<\/span><\/span><\/code><\/pre><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">If you could see closely there is a huge deception in the logs:<\/p>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span role=\"button\" tabindex=\"0\" style=\"color:#F8F8F2;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><pre class=\"code-block-pro-copy-button-pre\" aria-hidden=\"true\"><textarea class=\"code-block-pro-copy-button-textarea\" tabindex=\"-1\" aria-hidden=\"true\" readonly>>>>>>>>> Serial console Disabled &lt;&lt;&lt;&lt;&lt;&lt;&lt;&lt;<\/textarea><\/pre><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki monokai\" style=\"background-color: #272822\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #F92672\">&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;<\/span><span style=\"color: #F8F8F2\"> Serial console Disabled <\/span><span style=\"color: #F92672\">&lt;&lt;&lt;&lt;&lt;&lt;&lt;&lt;<\/span><\/span><\/code><\/pre><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Serial communication was working at the beginning, and then it suddenly went silent \ud83d\ude14. Something changed and disabled it without any clear reason. Sure it&#8217;s the bootloader. I tried pressing keys, hoping the bootloader would stop and give me a shell, but nothing happened. After the &#8220;Serial console Disabled&#8221; I had just a quiet screen. The device continue its startup process. Now I have to hunt through hidden settings, flags, and boot stages, trying to find what killed the output and bring it back to life \ud83d\udd0d. Pressing random keys was useless, like the system is refusing to talk \ud83d\ude36<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">The Point of No Return: Chip Extraction<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">After checking for JTAG and other interfaces beyond UART, I reached a frustrating point where the only option left was chip extraction. At that moment, it felt like the device was staring back at me, quietly saying \u201cgood luck\u201d \ud83d\ude05. This step is always risky, and it requires extreme care to avoid damaging the board or the memory itself. One wrong move and it\u2019s game over \ud83d\udc80. The goal is simple: extract the firmware and analyze it offline. It\u2019s the hard way, but also one of the most effective when everything else is locked down.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At this stage, it became clear that the device is hardened for a reason, and I wanted to understand that reason. The security layers in place are no joke. Every blocked path felt like another challenge. In fact, I\u2019m already impressed, because it feels like the engineers behind this device knew exactly what they were doing and deliberately closed the obvious paths. It stopped being just troubleshooting\u2026 and started feeling like a real duel between me and the hardware \u2694\ufe0f.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I checked the PCB and googled every chip in the device until I found the one that is a NAND (NW874)<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"620\" height=\"431\" src=\"https:\/\/thered0ne.com\/wp-content\/uploads\/2026\/04\/image-9.png\" alt=\"\" class=\"wp-image-367\" srcset=\"https:\/\/thered0ne.com\/wp-content\/uploads\/2026\/04\/image-9.png 620w, https:\/\/thered0ne.com\/wp-content\/uploads\/2026\/04\/image-9-300x209.png 300w\" sizes=\"auto, (max-width: 620px) 100vw, 620px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">After removing the chip with a heat gun, I didn\u2019t want to take more risks than necessary \ud83d\ude05. My plan was to mount it on an adapter so I could easily reprogram it if something went wrong with the firmware. Once the chip is off, there is no safety net, so having a way back is important. I built a small circuit and carefully soldered wires between the chip pads and the PCB. It was slow and delicate work, and every connection had to be clean. In the end, the setup looked a bit messy, but it gave me control and flexibility in case I needed to recover the firmware later \ud83d\udd27.<\/p>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:100%\">\n<div class=\"wp-block-group\"><div class=\"wp-block-group__inner-container is-layout-constrained wp-block-group-is-layout-constrained\"><div class=\"wp-block-image\">\n<figure class=\"alignleft size-large is-resized\"><img decoding=\"async\" src=\"https:\/\/res.cloudinary.com\/dg9enn12b\/image\/upload\/q_auto\/f_auto\/v1775443941\/PXL_20260317_175652643_qftkyh.jpg\" alt=\"\" style=\"aspect-ratio:0.5625019618511504;width:155px;height:auto\"\/><\/figure>\n<\/div>\n\n<div class=\"wp-block-image\">\n<figure class=\"alignleft size-large is-resized\"><img decoding=\"async\" src=\"https:\/\/res.cloudinary.com\/dg9enn12b\/image\/upload\/q_auto\/f_auto\/v1775441992\/PXL_20260317_175644820_1_iuoa4i.jpg\" alt=\"\" style=\"aspect-ratio:0.5625019618511504;width:154px;height:auto\"\/><\/figure>\n<\/div>\n\n<div class=\"wp-block-image\">\n<figure class=\"alignleft size-large is-resized\"><img decoding=\"async\" src=\"https:\/\/res.cloudinary.com\/dg9enn12b\/image\/upload\/q_auto\/f_auto\/v1775441993\/PXL_20260318_012554294_pg6qjw.jpg\" alt=\"\" style=\"aspect-ratio:0.5625019618511504;width:153px;height:auto\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\"><br><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n<\/div><\/div>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Time to read the chip and see what we will find \ud83d\ude04. This is the part that excites me the most after all the effort. I feel like a child holding a Kinder Surprise, ready to open it and discover what is hidden inside \ud83c\udf6b\ud83c\udf81 The chip is finally about to speak, and I\u2019m watching the process with that mix of curiosity and suspense \ud83d\udd0d\u26a1.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">The firmware landscape:<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Going back to the serial output:<\/p>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span role=\"button\" tabindex=\"0\" style=\"color:#F8F8F2;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><pre class=\"code-block-pro-copy-button-pre\" aria-hidden=\"true\"><textarea class=\"code-block-pro-copy-button-textarea\" tabindex=\"-1\" aria-hidden=\"true\" readonly>NOTICE: Booting Trusted Firmware - Realtek Semiconductor Corp.\n\nNOTICE: BL1: v1.5(release): TAURUS_TAPEOUT_2_0\nNOTICE: BL1: Built : 17:13:20, Oct 27 2021\nNOTICE: BL1: CPU Speed 1000 MHz\nNOTICE: GLOBAL_STRAP 0xc0a\nNOTICE: boot from serial NAND flash\n\nNOTICE: BL1: Booting BL2\nNOTICE: BL2: RTL9607DQ\nNOTICE: boot from serial NAND flash\n\n##### DRAM driver version (TAURUS): V0.7.5 #####\nINFO: PKG=BGA15\nINFO: dram_type = 4\nINFO: dram_freq = 933\nINFO: dram_dq = 16\nINFO: DRAM size = 4Gb\nINFO: Done DDR initialization...\nINFO: DRAM test PASS\nINFO: Address toggle PASS\n\nNOTICE: BL2: v1.5(release): gdbd64f1a0-dirty\nNOTICE: BL2: Built : 14:42:03, Jul 8 2024\n\nNOTICE: BL1: Booting BL31\nNOTICE: BL31: v1.5(release): gdbd64f1a0-dirty\nNOTICE: BL31: Built : 14:42:03, Jul 8 2024\nNOTICE: BL31: SECURE DRAM SIZE is 0x00800000<\/textarea><\/pre><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki monokai\" style=\"background-color: #272822\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #F8F8F2\">NOTICE: Booting Trusted Firmware <\/span><span style=\"color: #F92672\">-<\/span><span style=\"color: #F8F8F2\"> Realtek Semiconductor Corp.<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">NOTICE: BL1: v1.<\/span><span style=\"color: #AE81FF\">5<\/span><span style=\"color: #F8F8F2\">(release): TAURUS_TAPEOUT_2_0<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">NOTICE: BL1: Built : <\/span><span style=\"color: #AE81FF\">17<\/span><span style=\"color: #F8F8F2\">:<\/span><span style=\"color: #AE81FF\">13<\/span><span style=\"color: #F8F8F2\">:<\/span><span style=\"color: #AE81FF\">20<\/span><span style=\"color: #F8F8F2\">, Oct <\/span><span style=\"color: #AE81FF\">27<\/span><span style=\"color: #F8F8F2\"> <\/span><span style=\"color: #AE81FF\">2021<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">NOTICE: BL1: CPU Speed <\/span><span style=\"color: #AE81FF\">1000<\/span><span style=\"color: #F8F8F2\"> MHz<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">NOTICE: GLOBAL_STRAP <\/span><span style=\"color: #AE81FF\">0xc0a<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">NOTICE: boot from serial NAND flash<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">NOTICE: BL1: Booting BL2<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">NOTICE: BL2: RTL9607DQ<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">NOTICE: boot from serial NAND flash<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">##### DRAM driver <\/span><span style=\"color: #A6E22E\">version<\/span><span style=\"color: #F8F8F2\"> (TAURUS): V0.<\/span><span style=\"color: #AE81FF\">7.5<\/span><span style=\"color: #F8F8F2\"> #####<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">INFO: PKG<\/span><span style=\"color: #F92672\">=<\/span><span style=\"color: #F8F8F2\">BGA15<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">INFO: dram_type <\/span><span style=\"color: #F92672\">=<\/span><span style=\"color: #F8F8F2\"> <\/span><span style=\"color: #AE81FF\">4<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">INFO: dram_freq <\/span><span style=\"color: #F92672\">=<\/span><span style=\"color: #F8F8F2\"> <\/span><span style=\"color: #AE81FF\">933<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">INFO: dram_dq <\/span><span style=\"color: #F92672\">=<\/span><span style=\"color: #F8F8F2\"> <\/span><span style=\"color: #AE81FF\">16<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">INFO: DRAM size <\/span><span style=\"color: #F92672\">=<\/span><span style=\"color: #F8F8F2\"> 4Gb<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">INFO: Done DDR initialization<\/span><span style=\"color: #F92672\">...<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">INFO: DRAM test PASS<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">INFO: Address toggle PASS<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">NOTICE: BL2: v1.<\/span><span style=\"color: #AE81FF\">5<\/span><span style=\"color: #F8F8F2\">(release): gdbd64f1a0<\/span><span style=\"color: #F92672\">-<\/span><span style=\"color: #F8F8F2\">dirty<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">NOTICE: BL2: Built : <\/span><span style=\"color: #AE81FF\">14<\/span><span style=\"color: #F8F8F2\">:<\/span><span style=\"color: #AE81FF\">42<\/span><span style=\"color: #F8F8F2\">:<\/span><span style=\"color: #AE81FF\">03<\/span><span style=\"color: #F8F8F2\">, Jul <\/span><span style=\"color: #AE81FF\">8<\/span><span style=\"color: #F8F8F2\"> <\/span><span style=\"color: #AE81FF\">2024<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">NOTICE: BL1: Booting BL31<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">NOTICE: BL31: v1.<\/span><span style=\"color: #AE81FF\">5<\/span><span style=\"color: #F8F8F2\">(release): gdbd64f1a0<\/span><span style=\"color: #F92672\">-<\/span><span style=\"color: #F8F8F2\">dirty<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">NOTICE: BL31: Built : <\/span><span style=\"color: #AE81FF\">14<\/span><span style=\"color: #F8F8F2\">:<\/span><span style=\"color: #AE81FF\">42<\/span><span style=\"color: #F8F8F2\">:<\/span><span style=\"color: #AE81FF\">03<\/span><span style=\"color: #F8F8F2\">, Jul <\/span><span style=\"color: #AE81FF\">8<\/span><span style=\"color: #F8F8F2\"> <\/span><span style=\"color: #AE81FF\">2024<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">NOTICE: BL31: SECURE DRAM SIZE is <\/span><span style=\"color: #AE81FF\">0x00800000<\/span><\/span><\/code><\/pre><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">The bootloader appears to be signed and secure boot is activated. The presence of BL1, BL2, and BL31 strongly suggests a secure boot chain is in place. This means that modifying even a single byte in the bootloader region would likely break the chain of trust and prevent the device from booting.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Instead, I shifted my focus to understanding the NAND layout. My goal was to find references that could reveal how the flash was structured. I started searching for readable strings inside the dump using a hex editor, paying special attention to keywords like &#8220;<strong>mtdparts<\/strong>&#8220;. These strings often expose partition mappings and memory organization, and in this case, they provided valuable clues about how the firmware was arranged across the NAND.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/res.cloudinary.com\/dg9enn12b\/image\/upload\/q_auto\/f_auto\/v1775586117\/42e55253-d28d-4431-a40b-7a316db31a0b.png\" alt=\"\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">After parsing the <code><strong><strong>mtdparts<\/strong><\/strong><\/code>, the flash layout becomes much clearer. Each partition has a defined offset and role in the system:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Partition<\/th><th>Offset<\/th><th>Size<\/th><th>Description<\/th><\/tr><\/thead><tbody><tr><td>boot<\/td><td>0x00000000<\/td><td>4M<\/td><td>Bootloader<\/td><\/tr><tr><td>env<\/td><td>0x00400000<\/td><td>1M<\/td><td>Environment variables<\/td><\/tr><tr><td>env2<\/td><td>0x00500000<\/td><td>1M<\/td><td>Backup environment<\/td><\/tr><tr><td>RI<\/td><td>0x00600000<\/td><td>1536K<\/td><td>Runtime information<\/td><\/tr><tr><td>binfo<\/td><td>0x00800000<\/td><td>2M<\/td><td>Board information<\/td><\/tr><tr><td>image0<\/td><td>0x00A00000<\/td><td>70M<\/td><td>Primary firmware image<\/td><\/tr><tr><td>image1<\/td><td>0x05000000<\/td><td>70M<\/td><td>Secondary firmware image<\/td><\/tr><tr><td>cfg<\/td><td>0x09600000<\/td><td>20M<\/td><td>Configuration storage<\/td><\/tr><tr><td>cfg_bak<\/td><td>0x0AA00000<\/td><td>20M<\/td><td>Configuration backup<\/td><\/tr><tr><td>log<\/td><td>0x0BE00000<\/td><td>15M<\/td><td>Logs<\/td><\/tr><tr><td>extfs<\/td><td>0x0CD00000<\/td><td>5M<\/td><td>Extended filesystem<\/td><\/tr><tr><td>bbt<\/td><td>0x0D200000<\/td><td>2M<\/td><td>Bad block table<\/td><\/tr><tr><td>data<\/td><td>0x0D400000<\/td><td>Remaining<\/td><td>User \/ runtime data<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">I focused on the regions around <strong><code>0x00400000<\/code> <\/strong>and <code><strong>0x00500000<\/strong><\/code>, which correspond to the environment partitions. Those partitions are generally not signed because they contain a CRC to validate the data intergrity. Using the hex editor, I limited the view between these two offsets to avoid noise and concentrate only on relevant data. After scanning carefully, I found that the actual <strong>env1<\/strong> data starts at offset <code><strong>0x00440000<\/strong><\/code>, while <strong>env2<\/strong> begins at <code><strong>0x00550000<\/strong><\/code>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Comparing both regions revealed something interesting: the content was almost identical, with only a single byte difference. This strongly suggests a redundancy mechanism. The bootloader likely validates <strong>env1<\/strong> first, and if something looks wrong, it falls back to <strong>env2<\/strong> as a backup. This explains why two environment partitions exist in the first place.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">From a modification perspective, this means any change must be applied to both <strong>env1<\/strong> and <strong>env2<\/strong>. Since the bootloader could detect the mismatch and revert to the untouched copy. To keep the system consistent, both partitions need to be aligned so the boot process accepts the modified environment without triggering the fallback logic.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/res.cloudinary.com\/dg9enn12b\/image\/upload\/q_auto\/f_auto\/v1775586995\/1ed33083-fdae-49e5-9ef3-e94c94697901.png\" alt=\"\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">I was curious about the first 5 bytes at <strong>0x440000<\/strong>. I asked chatGPT for env format in U-Boot :<\/p>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span role=\"button\" tabindex=\"0\" style=\"color:#F8F8F2;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><pre class=\"code-block-pro-copy-button-pre\" aria-hidden=\"true\"><textarea class=\"code-block-pro-copy-button-textarea\" tabindex=\"-1\" aria-hidden=\"true\" readonly>+------------------+\n| CRC32 (4 bytes)  |\n+------------------+\n| flags (optional) |\n+------------------+\n| key=value\\0      |\n| key=value\\0      |\n| key=value\\0      |\n| ...              |\n| \\0               |\n+------------------+\n| padding (0xFF)   |\n+------------------+\n\n\/\/Structure of the page with CRC - Check page Activate shell and discussion with claude\nstruct env_t {\n      uint32_t  crc;     \/\/ offset +0, 4 bytes\n      uint8_t   flags;   \/\/ offset +4, 1 byte (only with redundant env)\n      uint8_t   data[];  \/\/ offset +5, env key=value pairs\n};<\/textarea><\/pre><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki monokai\" style=\"background-color: #272822\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #F92672\">+------------------+<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F92672\">|<\/span><span style=\"color: #F8F8F2\"> <\/span><span style=\"color: #A6E22E\">CRC32<\/span><span style=\"color: #F8F8F2\"> (<\/span><span style=\"color: #AE81FF\">4<\/span><span style=\"color: #F8F8F2\"> bytes)  <\/span><span style=\"color: #F92672\">|<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F92672\">+------------------+<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F92672\">|<\/span><span style=\"color: #F8F8F2\"> <\/span><span style=\"color: #A6E22E\">flags<\/span><span style=\"color: #F8F8F2\"> (optional) <\/span><span style=\"color: #F92672\">|<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F92672\">+------------------+<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F92672\">|<\/span><span style=\"color: #F8F8F2\"> key<\/span><span style=\"color: #F92672\">=<\/span><span style=\"color: #F8F8F2\">value\\<\/span><span style=\"color: #AE81FF\">0<\/span><span style=\"color: #F8F8F2\">      <\/span><span style=\"color: #F92672\">|<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F92672\">|<\/span><span style=\"color: #F8F8F2\"> key<\/span><span style=\"color: #F92672\">=<\/span><span style=\"color: #F8F8F2\">value\\<\/span><span style=\"color: #AE81FF\">0<\/span><span style=\"color: #F8F8F2\">      <\/span><span style=\"color: #F92672\">|<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F92672\">|<\/span><span style=\"color: #F8F8F2\"> key<\/span><span style=\"color: #F92672\">=<\/span><span style=\"color: #F8F8F2\">value\\<\/span><span style=\"color: #AE81FF\">0<\/span><span style=\"color: #F8F8F2\">      <\/span><span style=\"color: #F92672\">|<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F92672\">|<\/span><span style=\"color: #F8F8F2\"> <\/span><span style=\"color: #F92672\">...<\/span><span style=\"color: #F8F8F2\">              <\/span><span style=\"color: #F92672\">|<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F92672\">|<\/span><span style=\"color: #F8F8F2\"> \\<\/span><span style=\"color: #AE81FF\">0<\/span><span style=\"color: #F8F8F2\">               <\/span><span style=\"color: #F92672\">|<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F92672\">+------------------+<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F92672\">|<\/span><span style=\"color: #F8F8F2\"> <\/span><span style=\"color: #A6E22E\">padding<\/span><span style=\"color: #F8F8F2\"> (<\/span><span style=\"color: #AE81FF\">0xFF<\/span><span style=\"color: #F8F8F2\">)   <\/span><span style=\"color: #F92672\">|<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F92672\">+------------------+<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #88846F\">\/\/Structure of the page with CRC - Check page Activate shell and discussion with claude<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">struct env_t {<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">      uint32_t  crc;     <\/span><span style=\"color: #88846F\">\/\/ offset +0, 4 bytes<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">      uint8_t   flags;   <\/span><span style=\"color: #88846F\">\/\/ offset +4, 1 byte (only with redundant env)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">      uint8_t   data[];  <\/span><span style=\"color: #88846F\">\/\/ offset +5, env key=value pairs<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">};<\/span><\/span><\/code><\/pre><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">The first 4 bytes contain the CRC32 checksum for ENV1. We must generate a new CRC32 for every modified ENV1 to maintain data integrity. Otherwise, the router will continuously reboot or enter fallback mode. The flag indicates to U-Boot which copy is the newest valid version. To decide whether the flag needs updating, I calculate the CRC32 of ENV1 excluding both the flag and the OOB area. I used an AI-generated Python script for this \ud83e\udd74 (Don\u2019t hate me \u2014 it\u2019s fast \ud83e\udd16)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I searched for &#8220;<strong>serial_is_dis<\/strong>&#8221; in the strings, I was thinking if I change it to 0 maybe it will activate the serial but it&#8217;s not the case. Each time I boot I found the <strong>serial_is_dis<\/strong> is equal 1. I have to search further, so the message &#8220;<strong>Serial console Disabled<\/strong>&#8221; is my target. I tried to use Claude to analyse  the binary and understand a bit. In parallel, what I did is to patch once at a time every variable that I can change from 1 to 2 and vice versa and it must be in the ENV offsets.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I search in the hex strings for (&#8220;=0&#8221;, &#8220;=1&#8221;, &#8220;=2&#8221;). I found the variable &#8220;secboot=2&#8221; \ud83e\uddd0 Hmm, I said to myself what happens if I change that to 1 or 0 ? Let&#8217;s do it anyway I have a firmware backup if anything happens I can rollback <strong>\ud83d\udcaa<\/strong><\/p>\n\n\n\n<h1 class=\"wp-block-heading\">Patching the firmware:<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">I create a code that you will find <a href=\"https:\/\/github.com\/warber0x\/NokiaBeacon3.1_Nand_Patcher\/blob\/main\/NokiaBeaconBaker.py\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/github.com\/warber0x\/NokiaBeacon3.1_Nand_Patcher\/blob\/main\/NokiaBeaconBaker.py<\/a> to patch the firmware. The code changes <strong>secboot <\/strong>from 2 to 1, injects <strong>init=\/bin\/sh<\/strong> in the kernel arguments and calculate the CRC.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/res.cloudinary.com\/dg9enn12b\/image\/upload\/q_auto\/f_auto\/v1776782843\/1a1e2951-5362-4c5f-851e-46be9bf50f93.png\" alt=\"\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">After patching it, I write the new firmware back to the NAND. I connect the router to the FTDI and:<\/p>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span role=\"button\" tabindex=\"0\" style=\"color:#F8F8F2;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><pre class=\"code-block-pro-copy-button-pre\" aria-hidden=\"true\"><textarea class=\"code-block-pro-copy-button-textarea\" tabindex=\"-1\" aria-hidden=\"true\" readonly>U-Boot 2020.01 (Jul 24 2025 - 18:35:30 +0800)Taurus-SoC(OPTEE)\n\nCortexA55: 1000 MHz\nDDR4-1866: 16-bit mode, 512 MiB\nNAND:  scan_spi_nand_factory_bad_blocks&#91;899&#93;: found list\nSPI  NAND: MT29F2G01ABAGDWB\/F50L2G41XA\/XT26G02ELGIGA\/WSFVC32GBID (0x2c24)\n    spare: 0x80      (128B)\n     page: 0x800     (2KB)\n    block: 0x20000   (128KB)\n     chip: 0x10000000(256MB)\navailable: 0x10000000(256MB)\n     mode: S\/S\n    clock: 100 MHz\n      BBL: Bbl0 from flash\n   Hidden:\nNAND:  256 MiB\nLoading Environment from NAND... OK\nenter console_disable_check\ncheck_parts&#91;2110&#93;: not change\nconsole_disable_check&#91;48&#93;: SN:\ncheck_parts&#91;2110&#93;: not change\nsecboot is 1\n>>>>>>>> Serial console Enabled &lt;&lt;&lt;&lt;&lt;&lt;&lt;&lt;  \ud83c\udf89\ud83c\udf89\ud83c\udf89\ud83c\udf89\ud83c\udf89\ud83c\udf89\ud83c\udf89\ud83c\udf89\nenter update_basic_args\nupdate_basic_args: enable serial, starbranch buf=earlycon=serial,0xf43291b0 console=ttyS0,115200\nafter update basicargs: earlycon=serial,0xf43291b0 console=ttyS0,115200\neixt update_basic_args\nIn:    serial\nOut:   serial\nErr:   serial\ncheck_parts&#91;2110&#93;: not change\nread boot info from nand success...\nimage0: 3TN00626IJLJ03 image1:3TN00626IJMJ28  crc:0x586a2760\nSystem boot normal !\nBoot fail 0 times...\nreboot_reason reg:0xf4320194 value:0x0.\ncheck_parts&#91;2110&#93;: not change\nErasing at 0x800000 -- 100% complete.\nwrite boot info success...\ncheck_parts&#91;2110&#93;: not change\ncurrent boot partition is image1\n\n\n Write hash key to OTP to enable secboot...\n<\/textarea><\/pre><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki monokai\" style=\"background-color: #272822\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #F8F8F2\">U<\/span><span style=\"color: #F92672\">-<\/span><span style=\"color: #F8F8F2\">Boot <\/span><span style=\"color: #AE81FF\">2020.01<\/span><span style=\"color: #F8F8F2\"> (Jul <\/span><span style=\"color: #AE81FF\">24<\/span><span style=\"color: #F8F8F2\"> <\/span><span style=\"color: #AE81FF\">2025<\/span><span style=\"color: #F8F8F2\"> <\/span><span style=\"color: #F92672\">-<\/span><span style=\"color: #F8F8F2\"> <\/span><span style=\"color: #AE81FF\">18<\/span><span style=\"color: #F8F8F2\">:<\/span><span style=\"color: #AE81FF\">35<\/span><span style=\"color: #F8F8F2\">:<\/span><span style=\"color: #AE81FF\">30<\/span><span style=\"color: #F8F8F2\"> <\/span><span style=\"color: #F92672\">+<\/span><span style=\"color: #AE81FF\">0800<\/span><span style=\"color: #F8F8F2\">)Taurus<\/span><span style=\"color: #F92672\">-<\/span><span style=\"color: #A6E22E\">SoC<\/span><span style=\"color: #F8F8F2\">(OPTEE)<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">CortexA55: <\/span><span style=\"color: #AE81FF\">1000<\/span><span style=\"color: #F8F8F2\"> MHz<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">DDR4<\/span><span style=\"color: #F92672\">-<\/span><span style=\"color: #AE81FF\">1866<\/span><span style=\"color: #F8F8F2\">: <\/span><span style=\"color: #AE81FF\">16<\/span><span style=\"color: #F92672\">-<\/span><span style=\"color: #F8F8F2\">bit mode, <\/span><span style=\"color: #AE81FF\">512<\/span><span style=\"color: #F8F8F2\"> MiB<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">NAND:  scan_spi_nand_factory_bad_blocks&#91;<\/span><span style=\"color: #AE81FF\">899<\/span><span style=\"color: #F8F8F2\">&#93;: found list<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">SPI  NAND: MT29F2G01ABAGDWB<\/span><span style=\"color: #F92672\">\/<\/span><span style=\"color: #F8F8F2\">F50L2G41XA<\/span><span style=\"color: #F92672\">\/<\/span><span style=\"color: #F8F8F2\">XT26G02ELGIGA<\/span><span style=\"color: #F92672\">\/<\/span><span style=\"color: #A6E22E\">WSFVC32GBID<\/span><span style=\"color: #F8F8F2\"> (<\/span><span style=\"color: #AE81FF\">0x2c24<\/span><span style=\"color: #F8F8F2\">)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">    spare: <\/span><span style=\"color: #AE81FF\">0x80<\/span><span style=\"color: #F8F8F2\">      (128B)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">     page: <\/span><span style=\"color: #AE81FF\">0x800<\/span><span style=\"color: #F8F8F2\">     (2KB)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">    block: <\/span><span style=\"color: #AE81FF\">0x20000<\/span><span style=\"color: #F8F8F2\">   (128KB)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">     chip: <\/span><span style=\"color: #AE81FF\">0x10000000<\/span><span style=\"color: #F8F8F2\">(256MB)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">available: <\/span><span style=\"color: #AE81FF\">0x10000000<\/span><span style=\"color: #F8F8F2\">(256MB)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">     mode: S<\/span><span style=\"color: #F92672\">\/<\/span><span style=\"color: #F8F8F2\">S<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">    clock: <\/span><span style=\"color: #AE81FF\">100<\/span><span style=\"color: #F8F8F2\"> MHz<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">      BBL: Bbl0 from flash<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">   Hidden:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">NAND:  <\/span><span style=\"color: #AE81FF\">256<\/span><span style=\"color: #F8F8F2\"> MiB<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">Loading Environment from NAND<\/span><span style=\"color: #F92672\">...<\/span><span style=\"color: #F8F8F2\"> OK<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">enter console_disable_check<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">check_parts&#91;<\/span><span style=\"color: #AE81FF\">2110<\/span><span style=\"color: #F8F8F2\">&#93;: not change<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">console_disable_check&#91;<\/span><span style=\"color: #AE81FF\">48<\/span><span style=\"color: #F8F8F2\">&#93;: SN:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">check_parts&#91;<\/span><span style=\"color: #AE81FF\">2110<\/span><span style=\"color: #F8F8F2\">&#93;: not change<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">secboot is <\/span><span style=\"color: #AE81FF\">1<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F92672\">&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;<\/span><span style=\"color: #F8F8F2\"> Serial console Enabled <\/span><span style=\"color: #F92672\">&lt;&lt;&lt;&lt;&lt;&lt;&lt;&lt;<\/span><span style=\"color: #F8F8F2\">  \ud83c\udf89\ud83c\udf89\ud83c\udf89\ud83c\udf89\ud83c\udf89\ud83c\udf89\ud83c\udf89\ud83c\udf89<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">enter update_basic_args<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">update_basic_args: enable serial, starbranch buf<\/span><span style=\"color: #F92672\">=<\/span><span style=\"color: #F8F8F2\">earlycon<\/span><span style=\"color: #F92672\">=<\/span><span style=\"color: #F8F8F2\">serial,<\/span><span style=\"color: #AE81FF\">0xf43291b0<\/span><span style=\"color: #F8F8F2\"> console<\/span><span style=\"color: #F92672\">=<\/span><span style=\"color: #F8F8F2\">ttyS0,<\/span><span style=\"color: #AE81FF\">115200<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">after update basicargs: earlycon<\/span><span style=\"color: #F92672\">=<\/span><span style=\"color: #F8F8F2\">serial,<\/span><span style=\"color: #AE81FF\">0xf43291b0<\/span><span style=\"color: #F8F8F2\"> console<\/span><span style=\"color: #F92672\">=<\/span><span style=\"color: #F8F8F2\">ttyS0,<\/span><span style=\"color: #AE81FF\">115200<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">eixt update_basic_args<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">In:    serial<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">Out:   serial<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">Err:   serial<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">check_parts&#91;<\/span><span style=\"color: #AE81FF\">2110<\/span><span style=\"color: #F8F8F2\">&#93;: not change<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">read boot info from nand success<\/span><span style=\"color: #F92672\">...<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">image0: 3TN00626IJLJ03 image1:3TN00626IJMJ28  crc:<\/span><span style=\"color: #AE81FF\">0x586a2760<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">System boot normal <\/span><span style=\"color: #F92672\">!<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">Boot fail <\/span><span style=\"color: #AE81FF\">0<\/span><span style=\"color: #F8F8F2\"> times<\/span><span style=\"color: #F92672\">...<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">reboot_reason reg:<\/span><span style=\"color: #AE81FF\">0xf4320194<\/span><span style=\"color: #F8F8F2\"> value:<\/span><span style=\"color: #AE81FF\">0x0<\/span><span style=\"color: #F8F8F2\">.<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">check_parts&#91;<\/span><span style=\"color: #AE81FF\">2110<\/span><span style=\"color: #F8F8F2\">&#93;: not change<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">Erasing at <\/span><span style=\"color: #AE81FF\">0x800000<\/span><span style=\"color: #F8F8F2\"> <\/span><span style=\"color: #F92672\">--<\/span><span style=\"color: #F8F8F2\"> <\/span><span style=\"color: #AE81FF\">100<\/span><span style=\"color: #F92672\">%<\/span><span style=\"color: #F8F8F2\"> complete.<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">write boot info success<\/span><span style=\"color: #F92672\">...<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">check_parts&#91;<\/span><span style=\"color: #AE81FF\">2110<\/span><span style=\"color: #F8F8F2\">&#93;: not change<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">current boot partition is image1<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\"> Write hash key to OTP to enable secboot<\/span><span style=\"color: #F92672\">...<\/span><\/span>\n<span class=\"line\"><\/span><\/code><\/pre><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">The Serial console is enabled and I got a shell : \ud83c\udf89\ud83c\udf89\ud83c\udf89\ud83c\udf89\ud83c\udf89\ud83c\udf89\ud83c\udf89\ud83c\udf89<\/p>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span role=\"button\" tabindex=\"0\" style=\"color:#F8F8F2;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><pre class=\"code-block-pro-copy-button-pre\" aria-hidden=\"true\"><textarea class=\"code-block-pro-copy-button-textarea\" tabindex=\"-1\" aria-hidden=\"true\" readonly>&#91;   10.207898&#93; ubi0 warning: ubi_open_volume.part.0: cannot open device 0, volume 3, ret -16\n&#91;   10.313320&#93; VFS: Mounted root (squashfs filesystem) readonly on device 254:0.\n&#91;   10.320531&#93; Freeing unused kernel memory: 448K\n&#91;   10.361003&#93; Run \/bin\/sh as init process\n\n\nBusyBox v1.35.0 (2023-01-03 00:24:21 UTC) built-in shell (ash)\n\n\/bin\/sh: can't access tty; job control turned off\n\/ #\n<\/textarea><\/pre><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki monokai\" style=\"background-color: #272822\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #F8F8F2\">&#91;   <\/span><span style=\"color: #AE81FF\">10.207898<\/span><span style=\"color: #F8F8F2\">&#93; ubi0 warning: ubi_open_volume.part.<\/span><span style=\"color: #AE81FF\">0<\/span><span style=\"color: #F8F8F2\">: cannot open device <\/span><span style=\"color: #AE81FF\">0<\/span><span style=\"color: #F8F8F2\">, volume <\/span><span style=\"color: #AE81FF\">3<\/span><span style=\"color: #F8F8F2\">, ret <\/span><span style=\"color: #F92672\">-<\/span><span style=\"color: #AE81FF\">16<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">&#91;   <\/span><span style=\"color: #AE81FF\">10.313320<\/span><span style=\"color: #F8F8F2\">&#93; VFS: Mounted <\/span><span style=\"color: #A6E22E\">root<\/span><span style=\"color: #F8F8F2\"> (squashfs filesystem) readonly on device <\/span><span style=\"color: #AE81FF\">254<\/span><span style=\"color: #F8F8F2\">:<\/span><span style=\"color: #AE81FF\">0.<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">&#91;   <\/span><span style=\"color: #AE81FF\">10.320531<\/span><span style=\"color: #F8F8F2\">&#93; Freeing unused kernel memory: 448K<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">&#91;   <\/span><span style=\"color: #AE81FF\">10.361003<\/span><span style=\"color: #F8F8F2\">&#93; Run <\/span><span style=\"color: #F92672\">\/<\/span><span style=\"color: #F8F8F2\">bin<\/span><span style=\"color: #F92672\">\/<\/span><span style=\"color: #F8F8F2\">sh <\/span><span style=\"color: #F92672\">as<\/span><span style=\"color: #F8F8F2\"> <\/span><span style=\"color: #A6E22E; text-decoration: underline\">init<\/span><span style=\"color: #F8F8F2\"> <\/span><span style=\"color: #A6E22E; text-decoration: underline\">process<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">BusyBox v1.<\/span><span style=\"color: #AE81FF\">35.0<\/span><span style=\"color: #F8F8F2\"> (<\/span><span style=\"color: #AE81FF\">2023<\/span><span style=\"color: #F92672\">-<\/span><span style=\"color: #AE81FF\">01<\/span><span style=\"color: #F92672\">-<\/span><span style=\"color: #AE81FF\">03<\/span><span style=\"color: #F8F8F2\"> <\/span><span style=\"color: #AE81FF\">00<\/span><span style=\"color: #F8F8F2\">:<\/span><span style=\"color: #AE81FF\">24<\/span><span style=\"color: #F8F8F2\">:<\/span><span style=\"color: #AE81FF\">21<\/span><span style=\"color: #F8F8F2\"> UTC) built<\/span><span style=\"color: #F92672\">-in<\/span><span style=\"color: #F8F8F2\"> <\/span><span style=\"color: #A6E22E\">shell<\/span><span style=\"color: #F8F8F2\"> (ash)<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #F92672\">\/<\/span><span style=\"color: #F8F8F2\">bin<\/span><span style=\"color: #F92672\">\/<\/span><span style=\"color: #F8F8F2\">sh: can<\/span><span style=\"color: #E6DB74\">&#39;t access tty; job control turned of<\/span><span style=\"color: #F44747\">f<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F92672\">\/<\/span><span style=\"color: #F8F8F2\"> #<\/span><\/span>\n<span class=\"line\"><\/span><\/code><\/pre><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">In this first part, we successfully obtained a shell by analyzing the raw NAND image and understanding the different firmware layers and partition layout \ud83d\udd0d. Through this analysis, we identified how the bootloader environment is structured, why the serial console is disabled by default, and which environment variables are responsible for controlling UART access. After locating these controls, we modified the relevant parameters and patched the firmware while preserving the NAND structure, redundant environment blocks, and CRC integrity \u2699\ufe0f. This allowed us to re-enable the serial console and inject a boot argument that spawns a root shell during the boot process \ud83d\udc1a.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In the second part, I will demonstrate how to physically start the router, walk through the entire boot sequence, and disable the Quagga shell to gain deeper system control \ud83d\ude80. Until then, stay tuned see you soon \ud83d\udc4b.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Introduction: Hello again, fellow hackers and researchers. Today I\u2019m starting a major series: a deep dive into my reverse engineering journey with the Nokia Beacon 3.1. This router is remarkably hardened, and getting shell access required overcoming significant obstacles. While my research into potential vulnerabilities is ongoing, I\u2019m ready to [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":352,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14,20],"tags":[11,12,28,22],"class_list":["post-351","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-iot","category-reverse-engineering","tag-hacking","tag-iot","tag-nokia-beacon","tag-reverse-engineering"],"_links":{"self":[{"href":"https:\/\/thered0ne.com\/index.php?rest_route=\/wp\/v2\/posts\/351","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thered0ne.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thered0ne.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thered0ne.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thered0ne.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=351"}],"version-history":[{"count":24,"href":"https:\/\/thered0ne.com\/index.php?rest_route=\/wp\/v2\/posts\/351\/revisions"}],"predecessor-version":[{"id":402,"href":"https:\/\/thered0ne.com\/index.php?rest_route=\/wp\/v2\/posts\/351\/revisions\/402"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thered0ne.com\/index.php?rest_route=\/wp\/v2\/media\/352"}],"wp:attachment":[{"href":"https:\/\/thered0ne.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=351"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thered0ne.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=351"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thered0ne.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=351"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}