爱技术

 找回密码
 注册会员

QQ登录

只需一步,快速开始

微信登录

微信扫一扫,快速登录

搜索
查看: 2501|回复: 12
收起左侧

QMAT作者的愤怒,关于某些国人的行为

[复制链接]
发表于 2009-11-1 14:50:46 | 显示全部楼层 |阅读模式

马上注册,结交更多好友,享用更多功能,让你轻松玩转社区。

您需要 登录 才可以下载或查看,没有帐号?注册会员 微信登录

x
As it seems, some chinese guys cracked QMAT version 5.06.Furthermore those guys told MS that our homepage would sell malware and thus it's blocked in IE.We warned you not to crack QMAT, as otherwise we would stop public development.New versions of QMAT will no more be published for free (as a trial)but will only be given to known customers after address verification.Sorry for that, but some people never seem to learn. :(
发表于 2009-11-1 19:26:52 | 显示全部楼层
QMAT是干什么啊?
回复 支持 反对

使用道具 举报

 楼主| 发表于 2009-11-1 20:11:46 | 显示全部楼层
QMAT - QC Mobile Analysis Tool



What is it ?

It is a development and debugging tool for Qualcomm mobiles


Who may need it ?

Mobile engineers / reverse engineers / cryptoanalysts and forensic labs


Crypto Functions :

- Calculate CRC-30, CRC-32, SHA1, SHA2 (SHA224 + SHA256), MD4 and MD5 of any file


- Calculate AES, DES, TEA, RSA in several ways (ECD,CBC,CFB,OFB etc..)

- Bruteforce bytes to fit CRC-30 needed when qcsblhd_cfgdata.mbn was edited

- Extract Gzipped, LZW and LZMA data

- Generate AKey, FSC, SPC and SPC3 for several providers

- Decrypt and Encrypt any RSA-Message, inclu由于非常钦佩楼主,不得不说声好! ASN-1 / SHA Signatures. (you can add publickeys to publickeys.xml)

- Generate RSA Private Key and create .pvk files

- Check firmware signature given Modulus and Exponent (for HTC and BQS mobiles)

- Extract information from .pvk files

- Search for algorithms in binary files (find cryptomethods + signatures) CRC8, CRC16, CRC32, MD4, MD5, SHARK, HAVAL, GZIP, ZIP, SHA1, ... and much more (you can add cryptosignatures to crypto.xml)


JTAG Interface :

(soon via Segger J-Link)


Functions for all mobiles with AT modes :

1. Send APDUs to SIM card

2. Read out all SMS with all headers

3. Send any AT command



Functions for QC mobiles :

1. Load binary files for :

Extraction of certificates
Extraction of BMPs,GIFs,PNGs, JPGs

2. Load Partition File to get overview about NAND/NOR structure

3. Send any String to a COM/USB Port and backup all your SMS !

4. Make usage of QCs Diag USB/COM Port Interface
(Useful for any QC mobile in the world)


Standard Features :

- Send standard diag commands or any hexadecimal command you want (database included)

- Read out all NVItems (range given)
(all that exist, more than QPST normally extracts)

- Backup and Restore all NVItems

- Read out and Dump Firmware in Memory (SRam)

- Read out complete EFS

- Switch to FTM Mode (or anything else you want)

- Get infos about phone ..... etc ..... a lot more functions

- Generate SimSecure Command to write to SimSecure using given file (may brick your phone when used without knowledge)

- Full Feature EFS Browser


Bootloader / DownloadMode Features :

- Load any file to mobile at any address and execute (bootloader f.e.)

- Read out complete NAND Memory using bootloader (range given) with included MSM6250/A bootloader or any given bootloader
Usage : Take out battery, put in battery, press ON # to enter emergency mode, Execute Loader
or (with SL91,SF71 f.e.) enable FTM mode, Execute Loader

- Use any Download Mode or Bootloader Command to experiment

- Read application memory of newer Diag Ver 6 in Download Mode

- Show complete infos about used NAND after loa由于非常钦佩楼主,不得不说声好! of Bootloader


Flasher Features :

Flash any QC mobile (OBL Multiboot) with given bootloader

- Flash PBL (dangerous), QCSBL, QCSBL Header and Config Bits, Partition, OEMSBL, OEMSBL Header, AMSS, AMSS Header and EFS


Functions for BQS only :

1. Load AMSS to extract files or useful infos
(EF81, E81C, EF91, SXG75, EF82, SF71, SL91 or similiar ones)

Features :
Extract Infos from AMSS : USBID, Product.Nr., SVN, SwBuild, Mobiletype
Extract internal filesystem (mif,bar,sig etc. files)
Extract AMSS signature bytes (if production key)
Show all file references used by mobile

2. Check Firmware validity (signature)



Functions for HTC only :

1. Check validity of HTC firmware (signature check)

2. Cut out signatures from .nbh file

3. Split radio.nb into qualcomm files for analysis

4. Find HTC Public keys using Cryptosearch

5. Generate Security passwords (SPL + radio) for newer HTC

6. Generate NBH Files (you can add any device into devlist.xml)

7. Dump Files from NBH (you can add any type into nbhtype.xml)

8. Fix radio.nb checksum

9. Generic Bootloader / AT Command interface with logging functions



Functions for Network Engineers

Network Calculators :

TDMA (GSM/UMTS) :
--------------------
IMEI
GSM A5-1
GSM A5-2
GSM A5-3
3G ECSD
GEA3 - GPRS
3G SNOW
3G UEA2
3G UIA2
GSM A3/A8 COMP128 V1
GSM A3/A8 COMP128 V2
GSM A3/A8 COMP128 V3
3G Milenage
3G Milenage Resync

CDMA :
-------
CAVE
CAVE Authentication
CAVE CMEA
CAVE EMEA
CAVE EMEA_NF
CAVE Wireless Residential Extension
CAVE Datakey / Look Up Table / Mask
CAVE DTC / DCCH
CAVE KSG
CAVE Long Block
CAVE Short Block
CAVE Enhanced Message
CAVE Enhanced Voice Privacy
CAVE Enhanced Data Mask
and much more ....


Planned in future :

1. Bugfixes
2. EFS Restore to Zip File
3. QC Jtag interface using Segger J-Link ARM
4. LNBS HTC support to replace MTTY 5. CDMA Write Functions 6. Tooltips showing real addresses in graphical window
7. Read out / Write back Addressbook
8. Restore backupped SMS to phone
9. much much more :)

NO UNLOCKING, IMEI or ESN CHANGING ! PLEASE DO NOT REQUEST. THIS PROJECT IS FOR EDUCATIONAL/DEVELOPMENT PURPOSES ONLY, AND NOT TO HARM COMPANIES FOR THEIR EFFORTS.
回复 支持 反对

使用道具 举报

发表于 2009-11-1 20:24:31 | 显示全部楼层
说什么啊
回复 支持 反对

使用道具 举报

发表于 2009-11-2 12:52:50 | 显示全部楼层
貌似用来刷多机的?
回复 支持 反对

使用道具 举报

 楼主| 发表于 2009-11-2 15:43:01 | 显示全部楼层
貌似国内的人把这个东东破解了,用来解锁,刷机。。。。呃,高手还是在深圳吖
回复 支持 反对

使用道具 举报

发表于 2009-11-13 16:29:27 | 显示全部楼层
我当年花20欧买了一个

现在深圳那边的都直接做可以通过验证的ROM直接刷了,现在出货的 touch pro,diamond2,pro2,hd2,touch2全是没解锁直接刷国内那个XDA两个牛人做的ROM
回复 支持 反对

使用道具 举报

发表于 2009-11-13 16:33:20 | 显示全部楼层
后面的版他就没破了啊,鬼佬没有按照他自己说的做,直接就不公开发布新版本的,破这个软件的作者连QMAT干嘛的都不知道呵呵,

LZ哪里的,交流交流企鹅27233五233
回复 支持 反对

使用道具 举报

 楼主| 发表于 2009-11-13 18:51:27 | 显示全部楼层
诶,鬼佬的做法确实不匝地,整了半天放出来的和最初那个帖子里说的都不一样了,看到siemens的 这块没啥直接搞htu的那些,siemens已经明明倒闭了还不放出来siemens的那几个功能,比起其他的国外大虾确实差不少
回复 支持 反对

使用道具 举报

发表于 2010-2-10 12:38:53 | 显示全部楼层
看得半懂半不懂……似懂非懂……
回复 支持 反对

使用道具 举报

发表于 2010-2-10 16:06:58 | 显示全部楼层
破解了..然后做金卡..修复多普达..
回复 支持 反对

使用道具 举报

发表于 2010-2-10 16:33:48 | 显示全部楼层
麻烦高人帮忙汉化一下上面的愤怒!
回复 支持 反对

使用道具 举报

发表于 2010-2-11 00:42:08 | 显示全部楼层
谁能翻译一下,看不太懂啊,当年E语没认真学
回复 支持 反对

使用道具 举报

您需要登录后才可以回帖 登录 | 注册会员 微信登录

本版积分规则

小黑屋|Archiver|手机版|爱技术 ( 沪ICP备08115260号-3 )

GMT+8, 2025-6-7 21:01

Powered by Discuz! X3.4 Licensed

Copyright © 2001-2020, Tencent Cloud.

快速回复 返回顶部 返回列表