[HSPL] New 2.08.HSPL v1.03 with GEZİ Exploit [Updated: 13/11/2013]

Android development for HTC HD2/Leo
Moderator: Forum Moderator

[HSPL] New 2.08.HSPL v1.03 with GEZİ Exploit [Updated: 13/11/2013]

Postby symbuzzer » Sun Sep 22, 2013 3:01 pm

Hi dear HD2 users. Since a very long time, we are developing Android Roms, Recoveries and Windows Mobile/Phone roms for our Leos. In addition, dear Kokotas has developed and continues to develop his superb bootloader too. This is only "dark-side developed" tool for nowadays. And there is no improvent about hspl's, radio's since 2011.

I am not a developer, coder or hacker ...etc. I had my Leo in 9/2012. So I couldn't see Cotulla's and DFT's works in their own times. I wanted to see these excited days but I was using UIQ based devices those days. But I am using Leo for now and my friends know very well; I am very snoopy;)

I am not going to talking more. I created my own 2.08.HSPL a few days ago and I have been using my own modified aMagldr for a long time. I didn't know how to flash unsigned SPL image via Cotulla's hspl. Because, Cotulla was allowed only unsigned OS and SPLASH images, he wasn't touched SPL and RADIO images. So with hspl we couldn't flash unsigned SPL and RADIO images.

A few days ago, I saw Robbie P's "Bootloader unlocked S-off HD2, HTC developer device" topic in: bootloader-unlocked-s-off-hd2-htc-developer-device-t107.html And I wanted to learn how I can dump HSPL image. I did a research and I wrote this tutorial: how-to-dump-spl-t125.html Also, I could dump Cotulla's 2.08.hspl image. After that I understood which codes was changed by Cotulla and I created my own HSPL as I said above.

Our CustomRUU and AdvancedRUU PC apps, don't flash spl and radios(signed or unsigned). There was another method for it and I tried it. I convert my hspl.nb to leoimg.nbh with a nbh creator and I copied it SDCard and tried to flash via Cotulla's hspl. I got a "flash-loop" so I removed my sd card. But When I turned on my phone, It gave me error and didn't open. I could run my modified spl but I couldn't flash Cotulla's hspl via HSPL4 tool anymore. It gave errors too. At this stage, I tried to flash an unsigned OS image (my modified aMagldr 1.13.05) via AdvancedRUU. And hspl forgot to unsigned spl flash and it worked without a problem:D I put this trick name is "GEZİ Vulnerability"

For information what is GEZİ, please look: http://en.wikipedia.org/wiki/2013_protests_in_Turkey


Pictures:
http://n1309.hizliresim.com/1f/q/sxq54.jpg
http://k1309.hizliresim.com/1f/q/sxq6k.jpg (from 2.08.hspl v1.0)
http://r1309.hizliresim.com/1f/q/sxq85.jpg (from 2.08.hspl v1.0)
http://n1309.hizliresim.com/1f/q/sxq8v.jpg (from aMagldr 1.13.06)

Video:
http://youtu.be/SEj3hrKHUwg (Song: Lana Del Ray - Summertime sadness)

2.08.hspl changelog:
v1.03b (will release)
-Added MFG (Manufacturing/Engineering) feature. So, we can use rtask commands. (For example Sim unlocking, Imei changing etc...)
-Probably not work with aMagldr:(
-Other 1.03 features.
(I posted it on xda for testing. But jtag-guy didnt respond until now. So I will wait testing summary for release)

v1.03
-Removed radio flash protection again. So we can flash shipped radios.
-Fixed/updated "info 7" mtty command.
-Updated Device/Drivers name on Windows mtty interface.
-Added Leo type 512/1024 instead hx/ss strings. With this, you can see your Leo type on spl main screen.
-Updated/removed some strings.

v1.02 (not released)
-Added radio flash protection. With this, users cant flash any shipped or modified radio. This makes Leo unbrickable. (I dont think release it. But if anyone wants it, I will send it.)

v1.01
-Fixed backward compability. - Now you can use cotulla's HSPL4 tool for hspl & unhspl
-Added version info & build date on spl main screen. - Now you can see version number and build date on spl screen.
-Removed unneeded strings.

Initial Release (v1.00):
-Build from original 2.08.0000 spl image (thanks to cotulla, credits symbuzzer)
-Added&Modified some strings for showing walkthrough of GEZİ Exploit (credits symbuzzer)


Features:
-Same as cotulla's 2.08.hspl. But now, we know how to flash our modified hspl's ;)
-You can hspl & unhspl again with Cotulla's HSPL4 tool from v1.01


What will be in next releases:
- I will try to add flashing unsigned radio utility, but I need help.
- I will try to add your requests if I can :)


INSTALLITION TUTORIAL IN 3RD POST
Attachments
2.08.hspl_v1.03.zip
2.08.hspl v1.03 by symbuzzer
(194.24 KiB) Downloaded 3144 times
2.08.hspl v1.01.zip
2.08.hspl v1.01 by symbuzzer
(194.27 KiB) Downloaded 1062 times
1.13.06.zip
aMagldr 1.13.06 by symbuzzer
(146.32 KiB) Downloaded 4413 times
2.08.hspl.zip
2.08.hspl v1.00 by symbuzzer
(194.27 KiB) Downloaded 909 times
symbuzzer
Forum Moderator
 
Posts: 320
Joined: Mon Jun 24, 2013 7:05 am
Country: Turkey (tr)
Has thanked: 176 times
Been thanked: 168 times

Advertisement
 

GEZİ Exploit

Postby symbuzzer » Sun Sep 22, 2013 4:56 pm

-What is Gezi Exploit?
Gezi isn't an exploit technically, It is only a trick which nobody never tried before. But I always want to be hacker so I prefer to say exploit :D

-What does it do?
With this trick, we know how to flash unsigned spl's on our phones.

-So what will happen in the future?
Who knows... :D
But I have plans about flashing unsigned radio images with a bit similar way.

-How did you find this vulnerability?
by chance...

-What is GEZİ?
http://en.wikipedia.org/wiki/2013_protests_in_Turkey

-What can I do for you?
At th moment, I need developers and reengineers for modifying spl.
And maybe a thanks will be good ;)
symbuzzer
Forum Moderator
 
Posts: 320
Joined: Mon Jun 24, 2013 7:05 am
Country: Turkey (tr)
Has thanked: 176 times
Been thanked: 168 times

How to install 2.08.HSPL and aMagldr 1.13.06

Postby symbuzzer » Sun Sep 22, 2013 4:58 pm

HOW TO INSTALL 2.08.HSPL AND AMAGLDR 1.13.06
Note: Needs 2.08.hspl or 3.03.hspl installed on HD2 and magldr drivers (activesync or windows mobile center) and Advanced ROM Update Utility on your PC. For these, please look: how-to-install-android-on-htc-hd2-leo-t52.html
1)Download 2.08.hspl.zip and extrect nbh formatted file.
2)Rename it "leoimg.nbh" and copy root of your SD card.
3)Power off your HD2 and Press VolDown + PowerOff buttons.
4)You will see 4 color screen and a gray menu will appeared after this.
5)Press PowerOff button for flash.
6)After flash is over, phone will automatically restart.
7)Your phone will enter "flash-loop". Don't be afraid.
8)Remove your battery and sd card.
9)Insert only battery again.
10)Press VolDown + PowerOff buttons and connect HD2 to your PC.
11)Download 1.13.06.zip and extract nbh formatted file.
12)Run AdvancedRUU and select RegularRUU (Task28) and 1.13.06.nbh and flash.
13)Phone will be automatically reboot.
symbuzzer
Forum Moderator
 
Posts: 320
Joined: Mon Jun 24, 2013 7:05 am
Country: Turkey (tr)
Has thanked: 176 times
Been thanked: 168 times

Re: How to install 2.08.HSPL and aMagldr 1.13.06

Postby chautruongthinh » Mon Sep 23, 2013 12:47 pm

symbuzzer wrote:


I have just tried it and it's work great!! Thanks symbuzzer
User avatar
chautruongthinh
Junior Member
 
Posts: 106
Joined: Mon Jul 01, 2013 6:06 pm
Location: Ben Tre City
Country: Vietnam (vn)
Has thanked: 35 times
Been thanked: 124 times

Re: How to install 2.08.HSPL and aMagldr 1.13.06

Postby symbuzzer » Mon Sep 23, 2013 12:55 pm

chautruongthinh wrote:
I have just tried it and it's work great!! Thanks symbuzzer


Thanks:) I hope, you like new magldr too.
symbuzzer
Forum Moderator
 
Posts: 320
Joined: Mon Jun 24, 2013 7:05 am
Country: Turkey (tr)
Has thanked: 176 times
Been thanked: 168 times

Re: [DEVS] New 2.08.HSPL v1.01 and aMagldr 1.13.06 with GEZİ Exploit [Updated: 23/09/2013]

Postby symbuzzer » Tue Sep 24, 2013 7:12 am

HSPL Updated:

2.08.hspl changelog:
v1.01
-Fixed backward compability. - Now you can use cotulla's HSPL4 tool for hspl & unhspl
-Added version info & build date on spl main screen. - Now you can see version number and build date on spl screen.
-Removed unneeded strings.

Initial Release (v1.00):
-Build from original 2.08.0000 spl image (thanks to cotulla, credits symbuzzer)
-Added&Modified some strings for showing walkthrough of GEZİ Exploit (credits symbuzzer)


Download link is in 1st post.
symbuzzer
Forum Moderator
 
Posts: 320
Joined: Mon Jun 24, 2013 7:05 am
Country: Turkey (tr)
Has thanked: 176 times
Been thanked: 168 times

Re: [DEVS] New 2.08.HSPL v1.01 and aMagldr 1.13.06 with GEZİ Exploit [Updated: 24/09/2013]

Postby IAMLEGENDZ » Sat Nov 02, 2013 1:22 am

Hi
First of all thank you for your work for htc leo. I want to ask you question which is what the difference between Cotulla's Magldr and yours?
IAMLEGENDZ
Newly Registered Member
 
Posts: 1
Joined: Tue Aug 13, 2013 7:45 pm
Country: Algeria (dz)
Has thanked: 5 times
Been thanked: 0 time

Re: [DEVS] New 2.08.HSPL v1.01 and aMagldr 1.13.06 with GEZİ Exploit [Updated: 24/09/2013]

Postby symbuzzer » Sat Nov 02, 2013 8:43 am

IAMLEGENDZ wrote:Hi
First of all thank you for your work for htc leo. I want to ask you question which is what the difference between Cotulla's Magldr and yours?


Welcome. There is no a lot of differences between them. Only some strings are changed. But I think its faster than original one when booting android and recovery. Maybe this is placebo effect I am not sure. I think its more eye-candy. If you will try, you will see what I mean;)
symbuzzer
Forum Moderator
 
Posts: 320
Joined: Mon Jun 24, 2013 7:05 am
Country: Turkey (tr)
Has thanked: 176 times
Been thanked: 168 times

Re: [DEVS] New 2.08.HSPL v1.01 and aMagldr 1.13.06 with GEZİ Exploit [Updated: 24/09/2013]

Postby contactwajeeh » Sat Nov 02, 2013 9:56 am

Hello Symbuzzer,

Can you make a Magldr with the recovery built in just as in Black cLK??
contactwajeeh
Junior Member
 
Posts: 16
Joined: Wed Sep 25, 2013 8:33 pm
Country: India (in)
Has thanked: 12 times
Been thanked: 6 times

Re: [DEVS] New 2.08.HSPL v1.01 and aMagldr 1.13.06 with GEZİ Exploit [Updated: 24/09/2013]

Postby symbuzzer » Sat Nov 02, 2013 2:18 pm

contactwajeeh wrote:Hello Symbuzzer,

Can you make a Magldr with the recovery built in just as in Black cLK??


It is not possible in my opinion. Because aMagldr hasnt got pre-defined partition table. So, we need to DAF PC tool for this process. And you know that; DAF erases nand memory fully.

Just curious, what do you need it?
symbuzzer
Forum Moderator
 
Posts: 320
Joined: Mon Jun 24, 2013 7:05 am
Country: Turkey (tr)
Has thanked: 176 times
Been thanked: 168 times

Next

Return to HD2 Android Development

Who is online

Users browsing this forum: No registered users and 0 guests

cron