Scratch n patch


Rendering Error in layout Widget/Social: Call to a member function exists() on null. Please enable debug mode for more information.
More
8 years 3 months ago - 8 years 3 months ago #2216 by
So I've run the script on a MacBook that was not iCloud locked, it came back with password looks clean and password set 0 times. It didn't give me a modified .bin and I'm assuming this was because there was no password to patch.
Does this mean there is no iCloud associated with the MacBook or it could be linked to an iCloud but it's just not activated?
Last edit: 8 years 3 months ago by .

Please Log in or Create an account to join the conversation.

More
8 years 3 months ago #2239 by thaGH05T
Replied by thaGH05T on topic Scratch n patch
Can you explain what script and how you ran it what you ran it against?

Please Log in or Create an account to join the conversation.

More
8 years 3 months ago - 8 years 3 months ago #2243 by
Ok, it's the rom_scan scratch n patch script on this site. My brother got a 2013 mbp retina on eBay. Said it was a fresh OS X but it wasn't so I did a fresh OS X install for him. After doing this I wondered if it might have a efi lock associated with iCloud or the machine, which at some point could potentially be activated and lock the Mac. So dumped the efi x3, verified with flash rom, then used the script to remove/patch any efi password.
The script ran fine on the dump but when it finished it said that password area looked clean, password was set 0 times (script was ran in SCANONLY=1 mode) and it didn't give a new patched bin which I assume is because there's no password on the machine. So would this indicate that the seller has not set up an efi password and therefore can not lock the Mac at a later date for example.
Hope I've explained it clearly lol

Also it's an EMC2673 2.4 which I see there is no clean bin in the efi repository, so would like to add a clean dump (once I'm 100% that this one is clean) to it for others to use.
How would I go about uploading the dump to the repo please? (Or do I post it and you add it)
Last edit: 8 years 3 months ago by .

Please Log in or Create an account to join the conversation.

More
8 years 3 months ago #2247 by thaGH05T
Replied by thaGH05T on topic Scratch n patch
The Mac needs to be registered with your brother in this case with Apple as well as iCloud to be absolutely sure, but I think you are safe. You can upload your binary here and we will throw it in the repos after we clean it. The scan and patch script looks for multiple signatures and has determined your EFI lock had never been set, so there would be no need for you to modify anything.
The following user(s) said Thank You:

Please Log in or Create an account to join the conversation.

More
8 years 3 months ago - 8 years 3 months ago #2252 by
Thanks for the reply Ghost. I opened the dump in a hex editor and it had a $svs area so i FF'd it like i would normally just incase then flashed back.
Here is the dump (which includes $svs and serial) appreciate it if you could delete this one from the post once you've cleaned and uploaded the new one

File Attachment:

File Name: MBP_i7_2.4...2673.zip
File Size:4,696 KB
Attachments:
Last edit: 8 years 3 months ago by thaGH05T. Reason: I removed the original file uploaded and replaced it with a file that has the password removed and the serial number was replaced with "SerialNumber".

Please Log in or Create an account to join the conversation.

More
8 years 3 months ago #2283 by
Ghost would you mind doing what you need to with the dump and deleting it for me please :)

Please Log in or Create an account to join the conversation.

More
8 years 3 months ago #2284 by thaGH05T
Replied by thaGH05T on topic Scratch n patch
I edited your original post by removing your file and uploading one that's been cleaned.

Please Log in or Create an account to join the conversation.

More
8 years 3 months ago #2285 by thaGH05T
Replied by thaGH05T on topic Scratch n patch
You should see an edited reason under your original post? I may have it restricted to moderators though. Let me know.
The following user(s) said Thank You:

Please Log in or Create an account to join the conversation.

More
8 years 3 months ago #2286 by
Thank you ghost, no there's no 'edited' message on the post though?

Please Log in or Create an account to join the conversation.

More
8 years 3 months ago #2288 by thaGH05T
Replied by thaGH05T on topic Scratch n patch
i must have it turned on for moderators only which is OK in my book. Sorry for the confusion I will add actual text or a reply from now on.

Please Log in or Create an account to join the conversation.

More
8 years 3 months ago #2289 by
No problem buddy and appreciate the help, as always

Please Log in or Create an account to join the conversation.

More
8 years 3 months ago - 8 years 3 months ago #2305 by
So I removed the $svs area and reflashed the dump back, did a fresh install. After he set up the MacBook for the first time and signed into icloud all was fine. After restarting the machine he got a pop up asking if he wanted to setup the device using device enrolment (it gave the name of a company).
He's messaged the guy he bought from but not got any replies.
Does anyone know where this info is stored as the ssd has been formatted and a fresh install done. Could it be linked to serial number or something that's picked up by iTunes?heres a link I've found that states it can't be removed and I wonder if its stored in the efi as says it can only be used on machines after 2011. If so, the dump in this post would contain that info
www.krcs.co.uk/device-enrolment-programme
Last edit: 8 years 3 months ago by .

Please Log in or Create an account to join the conversation.

More
8 years 3 months ago #2306 by
So after some more research I now think it's linked to serial or something stored in the efi as Apple states the DEP enrolment is only interrupted by replacement of the motherboard.
Is anyone able to see anything unusual in the dump? Or if it's serial related can I just edit the serial or does this cause it's own issues?
Here's the apple page regarding DEP with logic board
support.apple.com/en-gb/HT203016

Please Log in or Create an account to join the conversation.

More
8 years 3 months ago #2346 by thaGH05T
Replied by thaGH05T on topic Scratch n patch
I think you should try just removing the serial number and replacing it with a variation of the model you have. I am not sure how the serial number is constructed, but I do know that it is made up of at least 3 different parts to uniquely identifying the Mac, the model, and the revision. I may not be using the correct verbiage, but I am sure it is enough to get you going. Please post your serial number here (hidden from guests) and I will try to see what i can come up with. I also think this is loaded into PRAM and used by iTunes, so clearing your PRAM is needed after reflashing the EFI chip.

Please Log in or Create an account to join the conversation.

More
8 years 3 months ago #2347 by thaGH05T
Replied by thaGH05T on topic Scratch n patch
OK, maybe you guys can expand on this and do some research reporting it back here, but I just verified that the serial number does consist of 3 4 part sections. The first and last section I have not done any research on yet, but they do identify the actual device. The four characters in the middle section are what identifies your device specifically and can be replaced with anything you really want as long as it is alphanumerical.

You can test this theory by replacing your serial number with something like this "c02k0000drvc", and running it against any site that looks up devices by serial numbers such as www.everymac.com . I suggest you use what I have just given you and replace your serial number, clear NVRAM/PRAM, and see how that DEP holds up.
The following user(s) said Thank You:

Please Log in or Create an account to join the conversation.

More
8 years 3 months ago #2354 by lxx33
Replied by lxx33 on topic Scratch n patch
Is that even possible?
Lets say efi lock and iCloud lock on device.

But we cleared the Efi by eprom and pram so iCloud also doesn't come up. After that a fresh install.
Is it than still possible by the previous iCloud user to lock the device?

Please Log in or Create an account to join the conversation.

More
8 years 3 months ago #2358 by
Thanks for the input ghost. I was guessing it may be serial related and had figured out the 4 digits that are pretty much changeable to any combination (I used Everymac to check them). So I re flashed the efi with an edited serial, reset smc and pram, formatted and re installed OS X and no DEP pop ups after signing into iCloud/iTunes etc.
So it seems that apples DEP uses serial as udid.
Appreciate all the help on this post guys and hopefully this'll help someone else out if they encounter the same problem
The following user(s) said Thank You: CygnusX1

Please Log in or Create an account to join the conversation.

More
8 years 3 months ago #2363 by thaGH05T
Replied by thaGH05T on topic Scratch n patch
Thanks for the confirmation fast.flow, this is definitely good information to add to the ole' tool box.

Please Log in or Create an account to join the conversation.

Who's Online

We have 892 guests and no members online

N00BZ

  • ljamal
  • ljamal74
  • mikeg2atest
  • ducchinhbui
  • anjarezt

Cookies