Hovatek Forum MOBILE Android [Please help] Chip type not match! (0x84010000)
Can't login? Please, reset your password.
Hovatek is recruiting! Apply Now


[Please help] Chip type not match! (0x84010000)

[Please help] Chip type not match! (0x84010000)

morenett
morenett
morenett
Newbie
4
31-05-2021, 02:38 PM
#1



Hello!

I have MT8735 with download agent authorization. I bypass this with the exploit https://github.com/MTK-bypass/bypass_utility (since MT6735 is supported and MT8735 has the same hardware code) and everything goes well.
Then, I try to dump internal memory (tried different areas) using the SP Flash Tool, but the following error appears with the scatter file for MT6735:

> CHIP TYPE NOT match!! target efuse value: 0x84010000

Different scatter files result in an error with DRAM. Scatter file for MT8735 is not supported yet by SP Flash Tool.
Please advise how to deal with this and how to get a dump of the device?
Thank you!
This post was last modified: 01-06-2021, 01:42 AM by morenett.
X3non
X3non
X3non
Recognized Contributor
22,062
01-06-2021, 12:23 PM
#2
(31-05-2021, 02:38 PM)morenett Hello!

I have MT8735 with download agent authorization. I bypass this with the exploit https://github.com/MTK-bypass/bypass_utility (since MT6735 is supported and MT8735 has the same hardware code) and everything goes well.
Then, I try to dump internal memory (tried different areas) using the SP Flash Tool, but the following error appears with the scatter file for MT6735:

> CHIP TYPE NOT match!! target efuse value: 0x84010000

Different scatter files result in an error with DRAM. Scatter file for MT8735 is not supported yet by SP Flash Tool.
Please advise how to deal with this and how to get a dump of the device?
Thank you!

which scatter file are you using? an empty mt6735 scatter file from wwr mtk?
can you post the contents of the scatter file?
morenett
morenett
morenett
Newbie
4
01-06-2021, 06:53 PM
#3
(01-06-2021, 12:23 PM)X3non which scatter file are you using? an empty mt6735 scatter file from wwr mtk?
can you post the contents of the scatter file?

Yes, an empty scatter file from wwr mtk for MT6735 (in attachment).
I also tried to change the device to MT8735 in scatter file, but SP flash tool said that it's not supported.

Is it possible there is some kind of hardware protection against reading the internal memory? (efuses?)
By the way, with the exploit, it's possible to successfully download bootROM of the device - I've done it.
This post was last modified: 04-06-2021, 03:48 AM by morenett.
Attached Files
.txt
MT6735_Android_scatter.txt
Size: 1.01 KB / Downloads: 14
X3non
X3non
X3non
Recognized Contributor
22,062
02-06-2021, 10:47 AM
#4
(01-06-2021, 06:53 PM)morenett ...
Is it possible there is some kind of hardware protection against reading the internal memory? (efuses?)

unlikely, but just to confirm, do you get the same error if you try to readback from different regions? ie emmc_boot1 and emmc_user
alt. you could try backing up firmware using a different tool, you'd require a custom da


(01-06-2021, 06:53 PM)morenett By the way, with the exploit, it's possible to successfully download bootROM of the device - I've done it.

i don't understand what you mean by this
morenett
morenett
morenett
Newbie
4
02-06-2021, 08:08 PM
#5



(02-06-2021, 10:47 AM)X3non unlikely, but just to confirm, do you get the same error if you try to readback from different regions? ie emmc_boot1 and emmc_user
alt. you could try backing up firmware using a different tool, you'd require a custom da

Unfortunately, I don’t have DA.
Yes, I get the same error if I try to readback from different regions :( In this case, does it look like hardware protection, or can you suggest something else? What else could be done to dump the device?
For what purpose does the SP Flash Tool check efuses and can it be ignored in some way?
Thank you for your time!

(02-06-2021, 10:47 AM)X3non
(01-06-2021, 06:53 PM)morenett By the way, with the exploit, it's possible to successfully download bootROM of the device - I've done it.

i don't understand what you mean by this

The exploit that I posted at the beginning has the functionality to dump BootROM of the device, which I managed to do. But it probably doesn't matter in case of dumping the internal memory.
This post was last modified: 04-06-2021, 03:47 AM by morenett.
X3non
X3non
X3non
Recognized Contributor
22,062
03-06-2021, 11:21 AM
#6
(02-06-2021, 08:08 PM)morenett Unfortunately, I don’t have DA.
Yes, I get the same error if I try to readback from different regions Sad In this case, does it look like hardware protection, or can you suggest something else? What else could be done to dump the device?
For what purpose does the SP Flash Tool check efuses and can it be ignored in some way?
Thank you for your time!

you can try a different tool such as miracle thunder or any other hardware dongle / box you might have. some of these hardware boxes now support mtk bypass so you won't necessarily need a custom da


(01-06-2021, 06:53 PM)morenett The exploit that I posted at the beginning (https://github.com/MTK-bypass/bypass_utility) has the functionality to dump BootROM of the device, which I managed to do. But it probably doesn't matter in case of dumping the internal memory.

the tool is only meant to disable mtk secure boot, it can't dump firmware
morenett
morenett
morenett
Newbie
4
03-06-2021, 06:19 PM
#7
(03-06-2021, 11:21 AM)X3non you can try a different tool such as miracle thunder or any other hardware dongle / box you might have. some of these hardware boxes now support mtk bypass so you won't necessarily need a custom da

Do I need some kind of dongle for miracle thunder in case of using it for mtk?

(03-06-2021, 11:21 AM)X3non the tool is only meant to disable mtk secure boot, it can't dump firmware

I'm not sure what exactly you mean by firmware. But the utility can dump the bootROM that runs the preloader and/or EDL. The function doing this is here
This post was last modified: 04-06-2021, 03:34 AM by morenett.
X3non
X3non
X3non
Recognized Contributor
22,062
04-06-2021, 12:28 PM
#8
(03-06-2021, 06:19 PM)morenett Do I need some kind of dongle for miracle thunder in case of using it for mtk?

yes, you'd need the dongle unless you're using the loader version @ https://www.hovatek.com/forum/thread-15700.html
kelvinchinedu
kelvinchinedu
kelvinchinedu
Contributor
1,302
16-06-2021, 08:02 PM
#9
We t happen to me once ,I just generate scatter file with miracle and use spflashtool Version 2020 and my read back was successful and I also try wwr with latest version of sp and successful
Users browsing this thread:
 1 Guest(s)
Users browsing this thread:
 1 Guest(s)
YtWhTl
live chat
whatsapp telegram instagram