Podgląd pojedynczego posta
Stary 03.08.2026, 15:53   #1
inheavens
Zarejestrowany
 
Data rejestracji: 24.06.2026
Posty: 1
inheavens w tym momencie nie ma Reputacji dodatnich ani ujemnych <0  pkt>
MT1959 (JB8) firmware integrity checksum - how is the value at 0x1EC054 computed?

I'm modifying a WH16NS58 (MT1959/JB8) firmware and have fully mapped its integrity architecture: a region table at 0x10400 with 16-byte expected hashes per region (verified by a hardware hash engine at 0x04063000), and a 2-byte checksum field at 0x1EC054 in the ID block.
Experiments confirm: any byte change in 0x17000-0x1B801F bricks the drive at boot (enters recovery mode); the ID block and write-strategy area (0x1B8020+) are freely modifiable. MK firmware boots with modified content and its stored checksum updated accordingly.
Using 5 firmware samples I've eliminated every standard algorithm: MD5/MD4/RIPEMD-128 (including custom-IV recovery via round inversion), SHA family truncations, CRC16 with arbitrary polynomial, CRC32, and all additive checksum variants.
How does the MK patcher recompute the integrity value(s)? Is there a tool or documentation for this?
inheavens jest offline   Odpowiedz cytując ten post

  #ads
CDRinfo.pl
Reklamowiec
 
 
 
Data rejestracji: 29.12.2008
Lokalizacja: Sieć globalna
Wiek: 31
Posty: 1227
 

CDRinfo.pl is online