You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
@skochinsky it has been quite some years since you looked at it. I found nothing public on the Gen 2 FS, and in one of your presentations (https://recon.cx/2014/slides/Recon%202014%20Skochinsky.pdf) you said that it's complicated due to wear leveling 😅 have you gotten further?
Anyhow, I have a few samples from different devices and upgrade images, and I'll get some more dumps from devices after running for a while to see what changes over time. So far I only have pages and what I think are the actual data chunks, but I cannot make sense of how they are indexed / addressed / marked as live etc..
The EFFS partition in Intel ME containers contains structured data. Parsing would be nice, similar to the NVRAM EFI region parsing request.
The text was updated successfully, but these errors were encountered: