Is it possible to break through the DIAG port on a BREW device ?

Moon164

Well-Known Member
OP
Member
Joined
Nov 21, 2015
Messages
860
Trophies
0
Age
26
XP
2,988
Country
Brazil
A while ago I posted that I was trying to figure out a more efficient way to unlock/jailbreak the Zeebo console by trying to figure out how the 61u.key is generated:

https://gbatemp.net/threads/im-tryi...ay-to-unlock-jailbreak-zeebo-consoles.653809/

But I haven't had much success with it.



So now I'm trying to figure out other alternatives.

The Zeebo has the BREW 4.0.2 operating system (many old cell phones use BREW 3 but I don't know of any that use BREW 4 itself) and there is a DIAG Port behind the console.

It is generally possible to access the console's DIAG Port by placing its 61u.key on an SD Card, many people use JTAG to be able to extract the console's 61u.key (or delete it from the console's memory, so the console cannot you will need it more) and in 1.1 models just place an empty usb.key on the SD Card at boot time and access to the diagnostic port will be active.

I obviously don't have the 61u.key for my console and its version is 1.2 which doesn't work with the usb.key method (I tried) but I still wanted to try to see the result:



RevSkills

After installing the drivers related to Zeebo (the driver that the Zeebo Club community gave me worked without problems, but I noticed that some old Qualcomm drivers also work, the only thing that changes from one to the other is the name "YUGA" or " Qualcomm", both drivers work exactly the same for me with Zeebo)
1713754975270.png

Well, then I tried to proceed the way you usually do when you have a Zeebo with 61u.key/USB.key on the SD Card at boot time.

As expected, RevSkills crashes. (this happens because the console is not allowing access to the diagnostic port)
1713754992752.png

DFS Port Manager

With DFS Port Manager the results were more interesting.



At first the app was just in an infinite loop "Request to Open Port / Waiting for Port..."
1713755025386.png

But then I tried a few more times removing and put tue USB cable to the console at boot time and in one of them the app actually managed to enter the Zeebo.
1713755044244.png

So I tried again a few more times, 99% of the time I was in an infinite loop with the app trying to enter the Zeebo port, but in a few rare moments I managed to enter:

But unfortunately for me, the app didn't provide me with any information, it didn't let me access the console's internal files or anything, so I think that even though I managed to log in, it didn't give me full access.



So I came to ask for help here, considering that BREW was an old Qualcomm operating system that was used on older cell phones, there probably must be some cell phone method that works with Zeebo, right?

Something that allows me to access the diagnostic port even without the 61u.key, or some way for the console to think that I have access.



It is possible ?
 

Quincy

Your own personal guitarist :3
Member
Joined
Nov 13, 2008
Messages
1,609
Trophies
1
Age
29
Location
Your house
Website
youtek.net
XP
1,239
Country
Netherlands
the hell is a zeebo? Never heard of this console (or BREW, fwiw)

If all you are trying to do is access the internal filesystem, assuming it is contained in a single IC/EEPROM, couldn't you just physically dump out the chip with a programmer like CH341A or similar programmers?
 

The Real Jdbye

*is birb*
Member
Joined
Mar 17, 2010
Messages
23,380
Trophies
4
Location
Space
XP
14,005
Country
Norway
the hell is a zeebo? Never heard of this console (or BREW, fwiw)

If all you are trying to do is access the internal filesystem, assuming it is contained in a single IC/EEPROM, couldn't you just physically dump out the chip with a programmer like CH341A or similar programmers?
Apparently some educational game console.
 

Quincy

Your own personal guitarist :3
Member
Joined
Nov 13, 2008
Messages
1,609
Trophies
1
Age
29
Location
Your house
Website
youtek.net
XP
1,239
Country
Netherlands
Apparently some educational game console.
Is that something like those 50-in-one "Zii" thingies you saw back in the Wii-era? 🤣

Edit: I just checked out the topic OP reffers to, and over there OP posted a whole bunch of related technical information regarding the console, this issue and 63key-files, someone with a bit more mathmatical/en-decryptical/cypheral knowledge mifght just be able to reverse-engineer the formula needed from the complete console datasets (console IMEI, serial no, generated key) (also, why do these consoles have an IMEI? Do they contain a celular modem of sorts? IMEIs are pretty much only used on phones and mobile data-modems afaik, for normal systems we usually have the adapter MAC to fulfil the role IMEI has on phones.)

edit 2: I did notice something regarding the s/ns though, which I posted to the topic OP mentions. I'll quote what I said over there here as well just in case

I do not know if you spotted this already regarding the longer serial no, but the longer ones all start with the same string BQAAF01. The s/n will be the same length as the older s/ns once you omit this part from the s/n (namely, 16 characters) so it is safe to assume that during generation either that part is omited from the new s/ns or added to the old s/ns (added to old is unlikely though, if they were going to do that the s/ns would have had that part in front of them from day 1)
 
Last edited by Quincy,
  • Like
Reactions: Moon164

Moon164

Well-Known Member
OP
Member
Joined
Nov 21, 2015
Messages
860
Trophies
0
Age
26
XP
2,988
Country
Brazil
the hell is a zeebo? Never heard of this console (or BREW, fwiw)

If all you are trying to do is access the internal filesystem, assuming it is contained in a single IC/EEPROM, couldn't you just physically dump out the chip with a programmer like CH341A or similar programmers?
As I said in my other post:

https://gbatemp.net/threads/im-tryi...ailbreak-zeebo-consoles.653809/#post-10406085

Zeebo was a Brazilian console launched by TecToy, it was not a success and was only released in Brazil, China, India and Mexico which makes it quite rare.

Here you can check out all the games the console had:


And there are some very interesting videos about the console that I recommend watching if you're interested:

 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • Xdqwerty @ Xdqwerty:
    @Psionic Roshambo, from the shows website?
  • K3Nv2 @ K3Nv2:
    They should've just made it a movie at 50 minutes
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    No from Paramount Plus or whatever it is
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    Psi now has access to every streaming and cable channel out
  • K3Nv2 @ K3Nv2:
    Eh I'd rather just download and delete is it already up on paramount?
  • Psionic Roshambo @ Psionic Roshambo:
    Yeah it's on now
  • Xdqwerty @ Xdqwerty:
    @Psionic Roshambo, why are most new south park episodes half hour specials?
    +1
  • K3Nv2 @ K3Nv2:
    @Psionic Roshambo, let me get a Netflix account I've always been nice to you
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    I made a honey pepper glazed turkey breast for dinner turned out pretty bomb
  • K3Nv2 @ K3Nv2:
    We can Netflix and chill
  • Xdqwerty @ Xdqwerty:
    Nvm not half hour, but hour long
  • Xdqwerty @ Xdqwerty:
    Normal south park episodes are already half hour
  • Psionic Roshambo @ Psionic Roshambo:
    Got 2 free Xumo boxes they work pretty good
  • K3Nv2 @ K3Nv2:
    I'm happy to get anything most series don't make it pass 6 seasons
  • Psionic Roshambo @ Psionic Roshambo:
    Except Stars and Encore those are being a bitch lol
  • K3Nv2 @ K3Nv2:
    I may consider that onn pro box finally a media box with type A ;O
    +1
  • Xdqwerty @ Xdqwerty:
    @K3Nv2, cuz the companies don't want em to
  • K3Nv2 @ K3Nv2:
    No it's revenue and demand south park could argue has a bigger audience than family guy about the same
    +1
  • K3Nv2 @ K3Nv2:
    Family guy is worth 300mill south parks worth 1Bill according to the interwebs
  • Xdqwerty @ Xdqwerty:
    @K3Nv2, probably cuz family guy is more disliked compared to south park
  • K3Nv2 @ K3Nv2:
    It just does the same formula south park can press buttons without going overboard
  • Xdqwerty @ Xdqwerty:
    And bc most of the family guy budget is spent on the voice actors rather than on the animation
  • K3Nv2 @ K3Nv2:
    Southpark could spend 30k on a animated dick and people would laugh at it
    +2
  • K3Nv2 @ K3Nv2:
    lol one prescription to Lizzo
  • Xdqwerty @ Xdqwerty:
    who is lizzo?
    Xdqwerty @ Xdqwerty: who is lizzo?