ghassani / qc-tz-es-activated-exploit
A rewrite of laginimaineb MSM8974_exploit as a stand alone kernel module.
☆17Updated 8 years ago
Related projects ⓘ
Alternatives and complementary repositories for qc-tz-es-activated-exploit
- Full TrustZone exploit for MSM8974☆137Updated 8 years ago
- QSEE Privilege Escalation Exploit using PRDiag* commands (CVE-2015-6639)☆117Updated 5 years ago
- Widevine L3 PoC for Android Keybox Recovery, Content Key dump and Netflix Media Download☆86Updated 2 years ago
- ☆114Updated 2 years ago
- Exploit code for CVE-2021-1961☆106Updated 2 years ago
- A tool to trace Widevine execution in Android and dump buffers.☆93Updated 2 years ago
- ☆9Updated 4 years ago
- Modifications in the qseecom driver which enable FuzzZone to operate☆23Updated last year
- Widevine Key Ladder in Python3☆37Updated 2 years ago
- Some stuff for doing insane qc chipset pwning.☆40Updated 2 years ago
- dump Exynos 8890 bootROM from Samsung Galaxy S7☆34Updated 4 years ago
- Qualcomm TrustZone kernel privilege escalation☆59Updated 8 years ago
- A proxy library between Chromium browser and WidevineCDM library.☆28Updated 4 years ago
- Standalone C version of the MSM8974 TrustZone exploit☆26Updated 4 years ago
- Exploiting the Semantic Gap in Trusted Execution Environments☆55Updated 4 years ago
- Fuzzing utility which enables sending arbitrary SCMs to TrustZone☆59Updated 8 years ago
- Small script to unpack the bootloader image format present in Nexus 5 devices☆38Updated 8 years ago
- IDA loader plugin for Qualcomm Bootloader Stages☆40Updated 10 years ago
- Unifies ".mdt" and ".bXX" files into a complete Trustlet☆86Updated 6 years ago
- An IDA file loader for Mobicore trustlet and driver binaries☆58Updated 4 years ago
- Tool based on @gaasedelen's lighthouse frida tool modified for capturing coverage of Android executables.☆18Updated last year
- SafetyNet Jar download & extractor utility☆35Updated 6 years ago
- Some RE work on Apple's Fairplay DRM☆192Updated last year
- The widevine content decryption module private key and blob for System ID 5650☆8Updated 2 years ago
- Rebuilds kallsyms statically from a kernel binary☆41Updated 7 years ago
- ☆18Updated 2 years ago
- A very minimalist smali emulator that could be used to "decrypt" obfuscated strings☆96Updated 7 years ago