![]() |
*Exclusive* XIP Extractor v1.2
1 Attachment(s)
This is a small tool that will extract the XIP from a HTC payload nb file. This is based of no2chem’s method. As of right now i have only tested it on carrier roms so please leave feedback and bugs.
Quote:
Code:
XIP Extractor v1.2 |
Quote:
Also, how are you finding the IMGFS start region? A note as well, you should rename XIP Extractor to XIPExtractor, command line tools don't work well with spaces. =p Otherwise good work! |
its the second file, which is viewimgfs.c but stripted to just output the start location. and yeah i found when i was going to use it i renamed it :$. anyways a new version with the support to launch xipport when finished will be uploaded very very soon
|
Nice, this is similar to the method I've been using. If it reliably does what we do by hand with a hex editor then it saves a few minutes :) Any time savings is good.
|
just wondering what method do you use, i may incorporate it if its much different
|
Quote:
Open Winhex or xvi32 Most devices have 2 XIP sections: XIP1 & XIP2. Search for the following hex Code:
FE 03 00 EA 00 00 00 00 00 00 00 00 00 00 00 00 00 00Code:
FE 03 00 EA 00 00 00 00 00 00 00 00 00 00 00 00 00 00The rom structure looks like this: |---Header, bootloader, etc---|---XIP1---|---XIP2---|---IMGFS---|... |
I take it that the start of the imgfs is the same for every htc rom? and is this the way imgfstonb uses to find the start?
|
as for the start location of the imgfs, do we need to take the F8 AC 2C 9D offset and - it by 0x40000? doing this will get you the same as imgfstonb. or dose these FF need to goto the XIP2
|
Quote:
Quote:
|
i have been cross referencing it and the only iv been getting the same numbers is by - 0x40000 to the offset, which puts me into padding FF's is there really that much padding in the XIP2, oh and i find like 3 instenses of F8 AC 2C 9D
|
side note for this is for finding the paging pool size, just a note for me
Code:
FF FF FF FF FF FF FF FF 9B 4F FF FF 64 B0 00 00 64 00 00 00Code:
D4 C2 04 80 00 00 80 00 |
REMOVED: blame the 1d10t error. ;)
Nice work, definitely saves a few minutes. Any day I don't have to open HS Wkshop is a good day. - DogGuy |
when i get done with finals, i will update it to allow writing (with no checks for now) back into the payload at the right location by itself.... so just make sure it doesnt run into the flash and were all good :D and of course it will be able to set the pagepool size too!!
|
Looking forward to it.
- DogGuy |
| All times are GMT -4. The time now is 01:17 PM. |
Powered by vBulletin® ©2000 - 2026, Jelsoft Enterprises Ltd.
©2012 - PPCGeeks.com