Difference between revisions of "User:Saschaelble"

From Exploitee.rs
Jump to navigationJump to search
Line 39: Line 39:


== Connections / Connectors / Switches ==
== Connections / Connectors / Switches ==
*CN102 - UART (115200 8n1) CPU
/proc/tty/driver # cat serial
*CN203 - UART (115200 8n1) GPU
serinfo:1.0 driver revision:
*CN403 - UART (56700 8n1)
 
*CN202 - UART (115200 8n1) unknown/nc
 
 
*CN102 - UART0:16550A (115200 8n1) CPU - irq:85 tx:300496 rx:10987 brk:9 RTS|DTR
*CN403 - UART1:16550A (56700 8n1) - irq:86 tx:0 rx:0 CTS|DSR|CD|RI
*CN203 - UART2:16550A (115200 8n1) GPU - irq:87 tx:0 rx:0
*CN202 - UART3:16550A (115200 8n1) unknown/nc - irq:85 tx:0 rx:0
 
*CN211 - SPI
*CN211 - SPI
*CN404 - JTAG
*CN404 - JTAG

Revision as of 10:01, 2 February 2021

"Although the information we release has been verified and shown to work to the best our knowledge, we cant be held accountable for bricked devices or roots gone wrong." Placeholder images

Costar01.jpg

This page will be dedicated to the hardware specifications, descriptions, and information related to: D40-D1 D50-D1 D55-D1 D58-D1 D60-D1

M75-C1



Specs

  • Dual Core Cortex A-9 ARM (CPU: ARMv7 Processor [413fc090] revision 0 (ARMv7), cr=10c5387d)
- w/ 1.5GB DDR3 RAM (x3) (K4B4G1646D-BCK0)
  • Quad Core GPU
- w/ 0.5GB DDR3 RAM (x4) (NT5CB64M16FP-DH)
  • 4GB EMMC (THGBMBG5D1KBAIT)
  • 5x HDMI,

Component, Ethernet, Wifi, 4k panel

  • USB 3.0 (2.0 externally)

Mainboard

Connections / Connectors / Switches

/proc/tty/driver # cat serial serinfo:1.0 driver revision:


  • CN102 - UART0:16550A (115200 8n1) CPU - irq:85 tx:300496 rx:10987 brk:9 RTS|DTR
  • CN403 - UART1:16550A (56700 8n1) - irq:86 tx:0 rx:0 CTS|DSR|CD|RI
  • CN203 - UART2:16550A (115200 8n1) GPU - irq:87 tx:0 rx:0
  • CN202 - UART3:16550A (115200 8n1) unknown/nc - irq:85 tx:0 rx:0
  • CN211 - SPI
  • CN404 - JTAG
  • CN403 - USB
  • SW401 - Reboot

All UARTS : Pin1->4 = GND, 3.3v, TX, RX

HDMI 4 is a special port, as it has a demuxer chip (74HC4052D) inline of the SDA and SCL lines, with voltage input on pin #14 to switch between uart0,1,2 and CEC for HDMI

Updates

Vizio uses a custom update method, like on their TV's and Tablets. Specifically the updates are provided thru Update Logic (ULI), and are pulled from the ULI servers, then decrypted. After decryption, the box is booted into recovery, the update is verified (it's a normal CTV update at this point), then installed.

Firmware History

  • 1.3.24 - Initial Factory Version?
- U-Boot 2012.04-sigma-common-00004-g3f6cf79 (Jun 09 2015 - 15:19:12)
- Linux version 3.4.39.13 ([email protected]) (gcc version 4.8.1 (Sourcery CodeBench Lite 2013.11-33) ) #1 SMP Tue Jan 19 11:56:31 CST 2016
  • 1.5.16 - Last update

Kernel Info

  1. cat /proc/iomem

00000000-0bbfffff : System RAM 00008000-006ee593 : Kernel code 00726000-008b745b : Kernel data 15030000-15031fff : SIGMA_Trix_GMAC.0 35900000-3fffffff : System RAM 86600000-9fffffff : System RAM f502f100-f502f2ff : sigma-ehci.0 f502f100-f502f2ff : ehci_hcd f5200000-f5200bff : sigma-xhci.0 f5200000-f5200bff : xhci-hcd fb008100-fb0082ff : sigma-ehci.1 fb008100-fb0082ff : ehci_hcd fb00a000-fb00a0ff : sigma-sdhci.0


  1. grep -H /sys/module/*/parameters/*

/sys/module/8250/parameters/nr_uarts:4 /sys/module/8250/parameters/share_irqs:1 /sys/module/8250/parameters/skip_txen_test:0 /sys/module/alarm_dev/parameters/debug_mask:1 /sys/module/auth_rpcgss/parameters/expired_cred_retry_delay:5 /sys/module/binder/parameters/debug_mask:7 /sys/module/binder/parameters/proc_no_lock:N /sys/module/binder/parameters/stop_on_user_error:0 /sys/module/block/parameters/events_dfl_poll_msecs:0 /sys/module/brd/parameters/max_part:0 /sys/module/brd/parameters/rd_nr:0 /sys/module/brd/parameters/rd_size:16384 /sys/module/cfg80211/parameters/cfg80211_disable_40mhz_24ghz:N /sys/module/cfg80211/parameters/ieee80211_regdom:00 /sys/module/dns_resolver/parameters/debug:0 /sys/module/ehci_hcd/parameters/hird:0 /sys/module/ehci_hcd/parameters/ignore_oc:N /sys/module/ehci_hcd/parameters/log2_irq_thresh:0 /sys/module/ehci_hcd/parameters/park:0 /sys/module/fuse/parameters/max_user_bgreq:255 /sys/module/fuse/parameters/max_user_congthresh:255 /sys/module/hid/parameters/debug:0 /sys/module/hid/parameters/ignore_special_drivers:0 /sys/module/hid_apple/parameters/fnmode:1 /sys/module/hid_apple/parameters/iso_layout:1 /sys/module/hostap/parameters/ap_bridge_packets:1,-1,-1,-1,-1,-1,-1,-1 /sys/module/hostap/parameters/ap_max_inactivity:300,-1,-1,-1,-1,-1,-1,-1 /sys/module/hostap/parameters/autom_ap_wds:0,-1,-1,-1,-1,-1,-1,-1 /sys/module/hostap/parameters/other_ap_policy:0,-1,-1,-1,-1,-1,-1,-1 /sys/module/ipv6/parameters/autoconf:1 /sys/module/ipv6/parameters/disable:0 /sys/module/ipv6/parameters/disable_ipv6:0 /sys/module/kernel/parameters/alignment:2 /sys/module/kernel/parameters/consoleblank:600 /sys/module/kernel/parameters/initcall_debug:N /sys/module/kernel/parameters/nousb:N /sys/module/kernel/parameters/panic:0 /sys/module/kernel/parameters/pause_on_oops:0 /sys/module/keyboard/parameters/brl_nbchords:1 /sys/module/keyboard/parameters/brl_timeout:300 /sys/module/lirc_dev/parameters/debug:N /sys/module/lockd/parameters/nlm_grace_period:0 /sys/module/lockd/parameters/nlm_max_connections:1024 /sys/module/lockd/parameters/nlm_tcpport:0 /sys/module/lockd/parameters/nlm_timeout:10 /sys/module/lockd/parameters/nlm_udpport:0 /sys/module/lockd/parameters/nsm_use_hostnames:N /sys/module/loop/parameters/max_loop:0 /sys/module/loop/parameters/max_part:0 /sys/module/lowmemorykiller/parameters/adj:0,1,6,12 /sys/module/lowmemorykiller/parameters/cost:32 /sys/module/lowmemorykiller/parameters/debug_level:1 /sys/module/lowmemorykiller/parameters/minfree:1536,2048,4096,16384 /sys/module/mac80211/parameters/ieee80211_default_rc_algo:minstrel_ht /sys/module/mac80211/parameters/max_nullfunc_tries:2 /sys/module/mac80211/parameters/max_probe_tries:5 /sys/module/mac80211/parameters/probe_wait_ms:500 /sys/module/mmc_core/parameters/removable:N /sys/module/mmcblk/parameters/perdev_minors:28 /sys/module/mousedev/parameters/tap_time:200 /sys/module/mousedev/parameters/xres:1024 /sys/module/mousedev/parameters/yres:768 /sys/module/nf_conntrack/parameters/acct:N /sys/module/nf_conntrack/parameters/expect_hashsize:1024 /sys/module/nf_conntrack/parameters/hashsize:11999 /sys/module/nf_conntrack_amanda/parameters/master_timeout:300 /sys/module/nf_conntrack_amanda/parameters/ts_algo:kmp /sys/module/nf_conntrack_ftp/parameters/loose:N /sys/module/nf_conntrack_ftp/parameters/ports:21 /sys/module/nf_conntrack_h323/parameters/callforward_filter:Y /sys/module/nf_conntrack_h323/parameters/default_rrq_ttl:300 /sys/module/nf_conntrack_h323/parameters/gkrouted_only:1 /sys/module/nf_conntrack_ipv4/parameters/hashsize:11999 /sys/module/nf_conntrack_irc/parameters/dcc_timeout:300 /sys/module/nf_conntrack_irc/parameters/max_dcc_channels:8 /sys/module/nf_conntrack_irc/parameters/ports:6667 /sys/module/nf_conntrack_netbios_ns/parameters/timeout:3 /sys/module/nf_conntrack_sane/parameters/ports:6566 /sys/module/nf_conntrack_tftp/parameters/ports:69 /sys/module/nfs/parameters/cache_getent:/sbin/nfs_cache_getent /sys/module/nfs/parameters/cache_getent_timeout:15 /sys/module/nfs/parameters/callback_tcpport:0 /sys/module/nfs/parameters/enable_ino64:Y /sys/module/nfs/parameters/max_session_slots:16 /sys/module/nfs/parameters/nfs4_disable_idmapping:Y /sys/module/nfs/parameters/nfs_idmap_cache_timeout:600 /sys/module/nfs/parameters/send_implementation_id:1 /sys/module/oprofile/parameters/timer:0 /sys/module/printk/parameters/always_kmsg_dump:N /sys/module/printk/parameters/console_suspend:Y /sys/module/printk/parameters/ignore_loglevel:N /sys/module/printk/parameters/time:Y /sys/module/psmouse/parameters/proto:auto /sys/module/psmouse/parameters/rate:100 /sys/module/psmouse/parameters/resetafter:5 /sys/module/psmouse/parameters/resolution:200 /sys/module/psmouse/parameters/resync_time:0 /sys/module/psmouse/parameters/smartscroll:Y /sys/module/rc_core/parameters/debug:0 /sys/module/rcutree/parameters/rcu_cpu_stall_suppress:0 /sys/module/rcutree/parameters/rcu_cpu_stall_timeout:60 /sys/module/sch_htb/parameters/htb_hysteresis:0 /sys/module/scsi_mod/parameters/default_dev_flags:0 /sys/module/scsi_mod/parameters/inq_timeout:20 /sys/module/scsi_mod/parameters/max_luns:512 /sys/module/scsi_mod/parameters/max_report_luns:511 /sys/module/scsi_mod/parameters/scan:async /sys/module/scsi_mod/parameters/scsi_logging_level:0 /sys/module/sdhci/parameters/debug_quirks:0 /sys/module/sdhci/parameters/debug_quirks2:0 /sys/module/sg/parameters/allow_dio:0 /sys/module/sg/parameters/def_reserved_size:32768 /sys/module/sg/parameters/scatter_elem_sz:32768 /sys/module/snd/parameters/cards_limit:1 /sys/module/snd/parameters/major:116 /sys/module/snd/parameters/slots:(null),(null),(null),(null),(null),(null),(null),(null) /sys/module/snd_aloop/parameters/enable:Y,N,N,N,N,N,N,N /sys/module/snd_aloop/parameters/id:(null),(null),(null),(null),(null),(null),(null),(null) /sys/module/snd_aloop/parameters/index:-1,-1,-1,-1,-1,-1,-1,-1 /sys/module/snd_aloop/parameters/pcm_notify:0,0,0,0,0,0,0,0 /sys/module/snd_aloop/parameters/pcm_substreams:8,8,8,8,8,8,8,8 /sys/module/snd_dummy/parameters/enable:Y,N,N,N,N,N,N,N /sys/module/snd_dummy/parameters/fake_buffer:Y /sys/module/snd_dummy/parameters/hrtimer:Y /sys/module/snd_dummy/parameters/id:(null),(null),(null),(null),(null),(null),(null),(null) /sys/module/snd_dummy/parameters/index:-1,-1,-1,-1,-1,-1,-1,-1 /sys/module/snd_dummy/parameters/model:(null),(null),(null),(null),(null),(null),(null),(null) /sys/module/snd_dummy/parameters/pcm_devs:1,1,1,1,1,1,1,1 /sys/module/snd_dummy/parameters/pcm_substreams:8,8,8,8,8,8,8,8 /sys/module/snd_pcm/parameters/maximum_substreams:4 /sys/module/snd_pcm/parameters/preallocate_dma:1 /sys/module/snd_pcm_oss/parameters/adsp_map:1,1,1,1,1,1,1,1 /sys/module/snd_pcm_oss/parameters/dsp_map:0,0,0,0,0,0,0,0 /sys/module/snd_pcm_oss/parameters/nonblock_open:Y /sys/module/snd_rawmidi/parameters/amidi_map:1,1,1,1,1,1,1,1 /sys/module/snd_rawmidi/parameters/midi_map:0,0,0,0,0,0,0,0 /sys/module/snd_seq/parameters/seq_client_load:-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1 /sys/module/snd_seq/parameters/seq_default_timer_card:-1 /sys/module/snd_seq/parameters/seq_default_timer_class:1 /sys/module/snd_seq/parameters/seq_default_timer_device:3 /sys/module/snd_seq/parameters/seq_default_timer_resolution:0 /sys/module/snd_seq/parameters/seq_default_timer_sclass:0 /sys/module/snd_seq/parameters/seq_default_timer_subdevice:0 /sys/module/snd_seq_midi/parameters/input_buffer_size:4096 /sys/module/snd_seq_midi/parameters/output_buffer_size:4096 /sys/module/snd_seq_oss/parameters/maxqlen:1024 /sys/module/snd_seq_oss/parameters/seq_oss_debug:0 /sys/module/snd_timer/parameters/timer_limit:4 /sys/module/snd_timer/parameters/timer_tstamp_monotonic:1 /sys/module/snd_ua101/parameters/enable:Y,Y,Y,Y,Y,Y,Y,Y /sys/module/snd_ua101/parameters/id:(null),(null),(null),(null),(null),(null),(null),(null) /sys/module/snd_ua101/parameters/index:-1,-1,-1,-1,-1,-1,-1,-1 /sys/module/snd_ua101/parameters/queue_length:21 /sys/module/snd_usb_6fire/parameters/enable:Y,Y,Y,Y,Y,Y,Y,Y /sys/module/snd_usb_6fire/parameters/id:(null),(null),(null),(null),(null),(null),(null),(null) /sys/module/snd_usb_6fire/parameters/index:-1,-1,-1,-1,-1,-1,-1,-1 /sys/module/snd_usb_audio/parameters/async_unlink:Y /sys/module/snd_usb_audio/parameters/device_setup:0,0,0,0,0,0,0,0 /sys/module/snd_usb_audio/parameters/enable:Y,Y,Y,Y,Y,Y,Y,Y /sys/module/snd_usb_audio/parameters/id:(null),(null),(null),(null),(null),(null),(null),(null) /sys/module/snd_usb_audio/parameters/ignore_ctl_error:N /sys/module/snd_usb_audio/parameters/index:-1,-1,-1,-1,-1,-1,-1,-1 /sys/module/snd_usb_audio/parameters/nrpacks:8 /sys/module/snd_usb_audio/parameters/pid:-1,-1,-1,-1,-1,-1,-1,-1 /sys/module/snd_usb_audio/parameters/vid:-1,-1,-1,-1,-1,-1,-1,-1 /sys/module/snd_usb_caiaq/parameters/enable:Y,Y,Y,Y,Y,Y,Y,Y /sys/module/snd_usb_caiaq/parameters/id:(null),(null),(null),(null),(null),(null),(null),(null) /sys/module/snd_usb_caiaq/parameters/index:-1,-1,-1,-1,-1,-1,-1,-1 /sys/module/soundcore/parameters/preclaim_oss:1 /sys/module/spurious/parameters/irqfixup:0 /sys/module/spurious/parameters/noirqdebug:N /sys/module/sunrpc/parameters/auth_hashtable_size:16 /sys/module/sunrpc/parameters/max_resvport:1023 /sys/module/sunrpc/parameters/min_resvport:665 /sys/module/sunrpc/parameters/pool_mode:global /sys/module/sunrpc/parameters/tcp_max_slot_table_entries:65536 /sys/module/sunrpc/parameters/tcp_slot_table_entries:2 /sys/module/sunrpc/parameters/udp_slot_table_entries:16 /sys/module/tcp_cubic/parameters/beta:717 /sys/module/tcp_cubic/parameters/bic_scale:41 /sys/module/tcp_cubic/parameters/fast_convergence:1 /sys/module/tcp_cubic/parameters/hystart:1 /sys/module/tcp_cubic/parameters/hystart_ack_delta:2 /sys/module/tcp_cubic/parameters/hystart_detect:3 /sys/module/tcp_cubic/parameters/hystart_low_window:16 /sys/module/tcp_cubic/parameters/initial_ssthresh:0 /sys/module/tcp_cubic/parameters/tcp_friendliness:1 /sys/module/usb_storage/parameters/delay_use:1 /sys/module/usb_storage/parameters/option_zero_cd:1 /sys/module/usb_storage/parameters/swi_tru_install:1 /sys/module/usbcore/parameters/authorized_default:-1 /sys/module/usbcore/parameters/autosuspend:2 /sys/module/usbcore/parameters/blinkenlights:N /sys/module/usbcore/parameters/initial_descriptor_timeout:5000 /sys/module/usbcore/parameters/old_scheme_first:N /sys/module/usbcore/parameters/usbfs_memory_mb:16 /sys/module/usbcore/parameters/usbfs_snoop:N /sys/module/usbcore/parameters/use_both_schemes:Y /sys/module/usbhid/parameters/ignoreled:0 /sys/module/usbhid/parameters/mousepoll:0 /sys/module/usbhid/parameters/quirks:(null),(null),(null),(null) /sys/module/uvcvideo/parameters/clock:CLOCK_MONOTONIC /sys/module/uvcvideo/parameters/nodrop:0 /sys/module/uvcvideo/parameters/quirks:4294967295 /sys/module/uvcvideo/parameters/timeout:5000 /sys/module/uvcvideo/parameters/trace:0 /sys/module/videobuf2_core/parameters/debug:0 /sys/module/vt/parameters/cur_default:2 /sys/module/vt/parameters/default_blu:0,0,0,0,170,170,170,170,85,85,85,85,255,255,255,255 /sys/module/vt/parameters/default_grn:0,0,170,85,0,0,170,170,85,85,255,255,85,85,255,255 /sys/module/vt/parameters/default_red:0,170,0,170,0,170,0,170,85,255,85,255,85,255,85,255 /sys/module/vt/parameters/default_utf8:1 /sys/module/vt/parameters/global_cursor_default:-1 /sys/module/vt/parameters/italic:2 /sys/module/vt/parameters/underline:3 /sys/module/xhci_hcd/parameters/config_gpio:y /sys/module/xhci_hcd/parameters/link_quirk:0 /sys/module/xt_qtaguid/parameters/ctrl_perms:438 /sys/module/xt_qtaguid/parameters/ctrl_write_gid:3007 /sys/module/xt_qtaguid/parameters/debug_mask:0 /sys/module/xt_qtaguid/parameters/iface_perms:292 /sys/module/xt_qtaguid/parameters/max_sock_tags:1024 /sys/module/xt_qtaguid/parameters/passive:N /sys/module/xt_qtaguid/parameters/stats_perms:292 /sys/module/xt_qtaguid/parameters/stats_readall_gid:3006 /sys/module/xt_qtaguid/parameters/tag_tracking_passive:N /sys/module/xt_quota2/parameters/event_num:112 /sys/module/xt_quota2/parameters/gid:0 /sys/module/xt_quota2/parameters/perms:420 /sys/module/xt_quota2/parameters/uid:0

Root Demo