<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Komentarze do: Hakowanie telewizora Samsung &#8211; Seria 7</title>
	<atom:link href="http://aiv-dev.info/2009/06/25/hakowanie-telewizora-samsung-tv-seria-7/feed/" rel="self" type="application/rss+xml" />
	<link>http://aiv-dev.info/2009/06/25/hakowanie-telewizora-samsung-tv-seria-7/</link>
	<description>Ciekawostki programistyczne i tematy związane z bezpieczeństwem</description>
	<lastBuildDate>Mon, 28 Dec 2009 21:34:18 +0100</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Autor: D3LLF</title>
		<link>http://aiv-dev.info/2009/06/25/hakowanie-telewizora-samsung-tv-seria-7/comment-page-1/#comment-404</link>
		<dc:creator>D3LLF</dc:creator>
		<pubDate>Sun, 23 Aug 2009 11:57:40 +0000</pubDate>
		<guid isPermaLink="false">http://aiv-dev.info/?p=34#comment-404</guid>
		<description>I just wanted to tell, that samsung has published source code of used GPL utils in their visual display - check it out:http://www.samsung.com/global/opensource/. IMO Specially interesting is http://www.samsung.com/global/opensource/files/LE46A956.zip which provides e-mail (korean), how opensource is handled in Samsung.</description>
		<content:encoded><![CDATA[<p>I just wanted to tell, that samsung has published source code of used GPL utils in their visual display &#8211; check it out:http://www.samsung.com/global/opensource/. IMO Specially interesting is <a href="http://www.samsung.com/global/opensource/files/LE46A956.zip" rel="nofollow">http://www.samsung.com/global/opensource/files/LE46A956.zip</a> which provides e-mail (korean), how opensource is handled in Samsung.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Autor: dynamic1969</title>
		<link>http://aiv-dev.info/2009/06/25/hakowanie-telewizora-samsung-tv-seria-7/comment-page-1/#comment-369</link>
		<dc:creator>dynamic1969</dc:creator>
		<pubDate>Sat, 08 Aug 2009 13:52:07 +0000</pubDate>
		<guid isPermaLink="false">http://aiv-dev.info/?p=34#comment-369</guid>
		<description>@b457144n

I eventually got a serial console working on the 7 Series. 

The good thing about this is, that it should also work equally on other devices ( also those where we were not yet able to decrypt OpenSSL encrypted FW ). 
See http://www.avsforum.com/avs-vb/showthread.php?p=16964905#post16964905 for further details on the HOWTO.

With the console access, there are many simple ways to directly alter the ( already decrypted ) FW  ;-)

Hope this helps!

Regards
dynamic

mailto: dynamic1969@gmail.com</description>
		<content:encoded><![CDATA[<p>@b457144n</p>
<p>I eventually got a serial console working on the 7 Series. </p>
<p>The good thing about this is, that it should also work equally on other devices ( also those where we were not yet able to decrypt OpenSSL encrypted FW ).<br />
See <a href="http://www.avsforum.com/avs-vb/showthread.php?p=16964905#post16964905" rel="nofollow">http://www.avsforum.com/avs-vb/showthread.php?p=16964905#post16964905</a> for further details on the HOWTO.</p>
<p>With the console access, there are many simple ways to directly alter the ( already decrypted ) FW  <img src='http://aiv-dev.info/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p>Hope this helps!</p>
<p>Regards<br />
dynamic</p>
<p>mailto: <a href="mailto:dynamic1969@gmail.com">dynamic1969@gmail.com</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Autor: b457144n</title>
		<link>http://aiv-dev.info/2009/06/25/hakowanie-telewizora-samsung-tv-seria-7/comment-page-1/#comment-363</link>
		<dc:creator>b457144n</dc:creator>
		<pubDate>Wed, 05 Aug 2009 22:25:03 +0000</pubDate>
		<guid isPermaLink="false">http://aiv-dev.info/?p=34#comment-363</guid>
		<description>@dynamic1969:
thanks for the tarball. Pity it does not contain the secureSWU stuff. 
It would be interesting to see what exeDSP does when you try to feed it a fake secure update for T-CHL7DEUC. Have you ever killed and restarted exeDSP? Is that possible? In that case running it with strace would get us a lot of information. 

Regards,

Bastiaan</description>
		<content:encoded><![CDATA[<p>@dynamic1969:<br />
thanks for the tarball. Pity it does not contain the secureSWU stuff.<br />
It would be interesting to see what exeDSP does when you try to feed it a fake secure update for T-CHL7DEUC. Have you ever killed and restarted exeDSP? Is that possible? In that case running it with strace would get us a lot of information. </p>
<p>Regards,</p>
<p>Bastiaan</p>
]]></content:encoded>
	</item>
	<item>
		<title>Autor: dynamic1969</title>
		<link>http://aiv-dev.info/2009/06/25/hakowanie-telewizora-samsung-tv-seria-7/comment-page-1/#comment-357</link>
		<dc:creator>dynamic1969</dc:creator>
		<pubDate>Mon, 03 Aug 2009 06:47:18 +0000</pubDate>
		<guid isPermaLink="false">http://aiv-dev.info/?p=34#comment-357</guid>
		<description>@b457144n:
Yes, I have telnet access to the device. Have put the desired tar-file here ... http://c2a2b2.com/arm_samsung and also included the &quot;ls -alR&quot; output.
Unforunately secureSWU is empty and there is also no secpub.key in mtd_rwarea.

As far as I can see this directory is only ( mounted or filled ) filled during a secure Update process, which we need to still find out.
As mariusz is saying, the key must be available somewhere in the FW ... but where.

Regards
dynamic1969</description>
		<content:encoded><![CDATA[<p>@b457144n:<br />
Yes, I have telnet access to the device. Have put the desired tar-file here &#8230; <a href="http://c2a2b2.com/arm_samsung" rel="nofollow">http://c2a2b2.com/arm_samsung</a> and also included the &#8220;ls -alR&#8221; output.<br />
Unforunately secureSWU is empty and there is also no secpub.key in mtd_rwarea.</p>
<p>As far as I can see this directory is only ( mounted or filled ) filled during a secure Update process, which we need to still find out.<br />
As mariusz is saying, the key must be available somewhere in the FW &#8230; but where.</p>
<p>Regards<br />
dynamic1969</p>
]]></content:encoded>
	</item>
	<item>
		<title>Autor: b457144n</title>
		<link>http://aiv-dev.info/2009/06/25/hakowanie-telewizora-samsung-tv-seria-7/comment-page-1/#comment-350</link>
		<dc:creator>b457144n</dc:creator>
		<pubDate>Thu, 30 Jul 2009 20:21:22 +0000</pubDate>
		<guid isPermaLink="false">http://aiv-dev.info/?p=34#comment-350</guid>
		<description>@mariusz, 
yes, I&#039;m afraid that those last 256 chars may be some digital signature. exeDSP has stuff like &#039; SWUDsaVerify&#039; and &#039;error readpubkey&#039; :-(
It looks like a lot of parameters related to this are stored in files under /mtd_rwarea/secureSWU/. Also /mtd_rwarea/secpub.key looks interesting. Now to get access to them....
@dynamic1969,
thanks for the link. Looks like the make serious progress. Unfortunately their work is not usable for my TV yet, but maybe it can help breaking the new encryption scheme as well. 
BTW do you have telnet access to your TV already? In that case, could you post a tarball of /mtd_rwarea? Thanks!

Bastiaan</description>
		<content:encoded><![CDATA[<p>@mariusz,<br />
yes, I&#8217;m afraid that those last 256 chars may be some digital signature. exeDSP has stuff like &#8216; SWUDsaVerify&#8217; and &#8216;error readpubkey&#8217; <img src='http://aiv-dev.info/wp-includes/images/smilies/icon_sad.gif' alt=':-(' class='wp-smiley' /><br />
It looks like a lot of parameters related to this are stored in files under /mtd_rwarea/secureSWU/. Also /mtd_rwarea/secpub.key looks interesting. Now to get access to them&#8230;.<br />
@dynamic1969,<br />
thanks for the link. Looks like the make serious progress. Unfortunately their work is not usable for my TV yet, but maybe it can help breaking the new encryption scheme as well.<br />
BTW do you have telnet access to your TV already? In that case, could you post a tarball of /mtd_rwarea? Thanks!</p>
<p>Bastiaan</p>
]]></content:encoded>
	</item>
	<item>
		<title>Autor: dynamic1969</title>
		<link>http://aiv-dev.info/2009/06/25/hakowanie-telewizora-samsung-tv-seria-7/comment-page-1/#comment-345</link>
		<dc:creator>dynamic1969</dc:creator>
		<pubDate>Mon, 27 Jul 2009 10:41:36 +0000</pubDate>
		<guid isPermaLink="false">http://aiv-dev.info/?p=34#comment-345</guid>
		<description>Hi,

telnet access on the Samsung UE46B70xx is now possible and confirmed to be working. 

Check out following Thread ( posting 86 onwards ) for a high level description of approach taken: http://www.avsforum.com/avs-vb/showthread.php?p=16849932

Same concept should be possible on other recent models of Samsung LCD/LED TVs.

Next steps are to get a toolchain/buildroot established ... let&#039;s see what all is possible :-)

Regards
dynamic</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>telnet access on the Samsung UE46B70xx is now possible and confirmed to be working. </p>
<p>Check out following Thread ( posting 86 onwards ) for a high level description of approach taken: <a href="http://www.avsforum.com/avs-vb/showthread.php?p=16849932" rel="nofollow">http://www.avsforum.com/avs-vb/showthread.php?p=16849932</a></p>
<p>Same concept should be possible on other recent models of Samsung LCD/LED TVs.</p>
<p>Next steps are to get a toolchain/buildroot established &#8230; let&#8217;s see what all is possible <img src='http://aiv-dev.info/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>Regards<br />
dynamic</p>
]]></content:encoded>
	</item>
	<item>
		<title>Autor: Mariusz Dalewski</title>
		<link>http://aiv-dev.info/2009/06/25/hakowanie-telewizora-samsung-tv-seria-7/comment-page-1/#comment-340</link>
		<dc:creator>Mariusz Dalewski</dc:creator>
		<pubDate>Tue, 21 Jul 2009 22:44:58 +0000</pubDate>
		<guid isPermaLink="false">http://aiv-dev.info/?p=34#comment-340</guid>
		<description>@b457144n first ideas:
last 3 chars of sec files are the same - 256
if you read 256 chars before this value you got some other value (possible in hex). Maybe it&#039;s checksum, maybe not :) 
Assume that tv need to know kthe ey, key must be stored in firmware package or hardcoded in tv.</description>
		<content:encoded><![CDATA[<p>@b457144n first ideas:<br />
last 3 chars of sec files are the same &#8211; 256<br />
if you read 256 chars before this value you got some other value (possible in hex). Maybe it&#8217;s checksum, maybe not <img src='http://aiv-dev.info/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
Assume that tv need to know kthe ey, key must be stored in firmware package or hardcoded in tv.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Autor: b457144n</title>
		<link>http://aiv-dev.info/2009/06/25/hakowanie-telewizora-samsung-tv-seria-7/comment-page-1/#comment-337</link>
		<dc:creator>b457144n</dc:creator>
		<pubDate>Tue, 21 Jul 2009 21:25:32 +0000</pubDate>
		<guid isPermaLink="false">http://aiv-dev.info/?p=34#comment-337</guid>
		<description>Hi Mariusz,

Thank you for sharing what you figured out. Today Samsung has released updated firmware for the LE40B650T2P variant (= 650 with CI+) as well.  
Unfortunately it uses a new encryption scheme.The files have a &#039;.sec&#039; extension instead of &#039;.enc&#039; and start with the string &#039;Salted&#039;.
Searching exeDSP of the T-CHU7DEUC firmware for this string shows that the new method already has been built into that version. 
Maybe with disassembling exeDSP we can find out the new scheme as well, but it won&#039;t be trivial. 
Also it looks like the updates have been digitally signed, so enhancing the firmware with a telnetd for example won&#039;t be easy :-(

Regards,

Bastiaan</description>
		<content:encoded><![CDATA[<p>Hi Mariusz,</p>
<p>Thank you for sharing what you figured out. Today Samsung has released updated firmware for the LE40B650T2P variant (= 650 with CI+) as well.<br />
Unfortunately it uses a new encryption scheme.The files have a &#8216;.sec&#8217; extension instead of &#8216;.enc&#8217; and start with the string &#8216;Salted&#8217;.<br />
Searching exeDSP of the T-CHU7DEUC firmware for this string shows that the new method already has been built into that version.<br />
Maybe with disassembling exeDSP we can find out the new scheme as well, but it won&#8217;t be trivial.<br />
Also it looks like the updates have been digitally signed, so enhancing the firmware with a telnetd for example won&#8217;t be easy <img src='http://aiv-dev.info/wp-includes/images/smilies/icon_sad.gif' alt=':-(' class='wp-smiley' /> </p>
<p>Regards,</p>
<p>Bastiaan</p>
]]></content:encoded>
	</item>
	<item>
		<title>Autor: dynamic1969</title>
		<link>http://aiv-dev.info/2009/06/25/hakowanie-telewizora-samsung-tv-seria-7/comment-page-1/#comment-329</link>
		<dc:creator>dynamic1969</dc:creator>
		<pubDate>Wed, 15 Jul 2009 08:29:27 +0000</pubDate>
		<guid isPermaLink="false">http://aiv-dev.info/?p=34#comment-329</guid>
		<description>Hi Mariusz,

what you have discovered sounds really interesting! 
It&#039;d be great to see, if one could get a telnet deamon started and then logon via the Network interface.

Curiously watching this thread :-)

Regards
dynamic1969</description>
		<content:encoded><![CDATA[<p>Hi Mariusz,</p>
<p>what you have discovered sounds really interesting!<br />
It&#8217;d be great to see, if one could get a telnet deamon started and then logon via the Network interface.</p>
<p>Curiously watching this thread <img src='http://aiv-dev.info/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>Regards<br />
dynamic1969</p>
]]></content:encoded>
	</item>
	<item>
		<title>Autor: Prof2k</title>
		<link>http://aiv-dev.info/2009/06/25/hakowanie-telewizora-samsung-tv-seria-7/comment-page-1/#comment-320</link>
		<dc:creator>Prof2k</dc:creator>
		<pubDate>Tue, 07 Jul 2009 13:19:59 +0000</pubDate>
		<guid isPermaLink="false">http://aiv-dev.info/?p=34#comment-320</guid>
		<description>No to czekamy, czekamy :)

Serdecznie pozdrawiam
Prof2k</description>
		<content:encoded><![CDATA[<p>No to czekamy, czekamy <img src='http://aiv-dev.info/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Serdecznie pozdrawiam<br />
Prof2k</p>
]]></content:encoded>
	</item>
</channel>
</rss>
