(08-13-2015, 05:38 AM)Tpad Wrote: Could someone please extract the whitelist information ONLY from this phoenix efi bios
need to know what lenovo FRU 's are allowed (or vendor/dev/subsys)
https://download.lenovo.com/ibmdl/pub/pc...uj11us.exe
currently installed wifi card:
Intel® Centrino® Advanced-N 6235
PCI\VEN_8086&DEV_088F&SUBSYS_52608086&REV_24
many thanks
There are many checks about your WiFi Card and into many Module, this is the inquired :
79E0EDD7-9D1D-4F41-AE1A-F896169E5216_2145.ROM LenovoWmaPolicyDxe.efi
Whitelist Section (0x270h) :
00000000EC102387EC10320700000000
02000000DA0B23A70000000000000000
0000000086808F088680605201000000 86808F08 86806052 PCI\VEN_8086&DEV_088F&SUBSYS_52608086&REV_24 Offset 0x0290h
0000000086808F0886806A5201000000
020000008780DA070000000000000000
01000000DB0B3F190000000000000000
01000000DB0B3E190000000000000000
0100000099111E900000000000000000
0100000099111F900000000000000000
06000000000000000000000000000000
First char is an ID + 3 char filler then PCI / VEN ID
Remove Whitelist Mod :
79E0EDD7-9D1D-4F41-AE1A-F896169E5216_2145.ROM LenovoWmaPolicyDxe.efi
0A60 : 74 43 to 74 00 jz short loc_AA5 to jz $+2
0A73 : 75 1A to 75 00 jnz short loc_A8F to jnz $+2
0A89 : 0F 84 5F 01 00 00 to 90 E9 5F 01 00 00 jz loc_BEE to nop + jmp loc_BEE
0AA3 : 75 C6 to 75 00 jnz short loc_A6B to jnz $+2
0AE5 : 74 BE to 74 00 jz short loc_AA5 to jz $+2
0AF2 : 75 2D to 75 00 jnz short loc_B21 to jnz $+2
0B08 : 75 17 to 75 00 jnz short loc_B21 to jnz $+2
0B1F : 74 1C to 74 00 jz short loc_B3D to jz $+2
0B35 : 0F 84 6A FF FF FF to 0F 84 00 00 00 00 jz loc_AA5 to jz $+6
0B3B : EB B3 to EB 00 jmp short loc_AF0 to jmp $+2
Or in alternative . . .
0AB0 : 79 16 to EB 16 jns short loc_AC8 to jmp short loc_AC8
0AC8 : 48 B8 07 00 00 00 00 00 00 80 to 90 90 90 90 90 90 90 90 90 90 90 mov rax, 8000000000000007h to nop x 10
Regadrs
P.S. Few words someone can copy yet