Omnimaga

Omnimaga => News => Topic started by: critor on October 31, 2012, 04:10:05 am

Title: 1st dumping of a TI-Nspire CAS+ Boot1
Post by: critor on October 31, 2012, 04:10:05 am
After performing the 1st dump of a TI-Nspire CAS+ OS in may 2012 (http://ourl.ca/16005) and then making those OSes installable (http://ourl.ca/16080), today is another great day!
The next greatest event in TI-Nspire CAS+ history has just occured: the first dumping of a TI-Nspire CAS+ Boot1, performed by myself with Goplat's help!

The Boot1 is the one coming with the P1-EVT2 CAS+ prototype I've had on loan from datamath .org for months/years, which was running OS 1.0.1.0.334T.

The method uses the RS232 console Datalight. This console is disabled on later models, so we'll need to find another method.
(http://tiplanet.org/forum/gallery/image.php?mode=medium&album_id=1&image_id=795)

It's this Boot1 which is showing us "Texas Instruments" instead of "TI-Nspire" when booting on this prototype.
(http://tiplanet.org/forum/gallery/image.php?mode=medium&album_id=1&image_id=792)

The Boot1 is stored in a 512KB Flash NOR ROM, like on later TI-Nspire:
(http://i43.servimg.com/u/f43/13/23/13/53/caspbo10.png)



As already seen in the RS232 bootlog from this prototype, the Boot1 is named "Boot Loader Stage 1" and has no version number - it is simply identified by its build date: 27 February 2006.

Note that the CPU frequency of 78MHz is actually hard-coded into the Boot1.

Note also that Boot1 confirms the possibility of launching a diagnostics software, although its presence have never been confirmed so far on any CAS+.



Now that the first boot1 TI-Nspire CAS+ has finally been dumped, let's go on! ;D(http://www.omnimaga.org/Themes/default/images/gpbp_arrow_up.gif)



Source:
http://tiplanet.org/forum/viewtopic.php?f=43&t=10658
Title: Re: 1st dumping of a TI-Nspire CAS+ Boot1
Post by: DJ Omnimaga on October 31, 2012, 05:00:32 am
That is great! Good job guys! :thumbsup:

By the way was that prototype the one that had even more motion blur than the regular models and also took almost a minute to boot?
Title: Re: 1st dumping of a TI-Nspire CAS+ Boot1
Post by: willrandship on October 31, 2012, 05:11:41 am
sounds like it, judging from the lower clock speed.

Very cool news!
Title: Re: 1st dumping of a TI-Nspire CAS+ Boot1
Post by: critor on October 31, 2012, 05:58:43 am
That is great! Good job guys! ;D(http://www.omnimaga.org/Themes/default/images/gpbp_arrow_up.gif)

By the way was that prototype the one that had even more motion blur than the regular models and also took almost a minute to boot?


Yes, it's the prototype with the worst screen.
And yes, it takes a minute and a half to boot because it does extract/reinstall the OS on each boot.

You've got a good memory ;)
Title: Re: 1st dumping of a TI-Nspire CAS+ Boot1
Post by: critor on October 31, 2012, 01:15:19 pm
Let's go on!

The first TI-Nspire CAS+ Boot2 has just been dumped! ;)
http://tiplanet.org/forum/viewtopic.php?p=131679#p131679
Title: Re: 1st dumping of a TI-Nspire CAS+ Boot1
Post by: Jim Bauwens on October 31, 2012, 02:24:11 pm
Great :)
Title: Re: 1st dumping of a TI-Nspire CAS+ Boot1
Post by: ElementCoder on October 31, 2012, 02:33:39 pm
Wow great job :thumbsup:
[offtopic]So how does a dump like this go like steps etc. Could I find guides to this stuff somewhere?[/offtopic]
Title: Re: 1st dumping of a TI-Nspire CAS+ Boot1
Post by: critor on November 01, 2012, 06:31:50 am
Wow great job ;D(http://www.omnimaga.org/Themes/default/images/gpbp_arrow_up.gif)
[offtopic]So how does a dump like this go like steps etc. Could I find guides to this stuff somewhere?[/offtopic]

Dumping the CAS+ OS is quite easy.

You just have to telnet the CAS+ IP on port 10002, and enter some copy commands to get the OS files in the /documents folder.
(http://i43.servimg.com/u/f43/13/23/13/53/nscp1010.png)
Then, they can be sent like a normal tns documents to the computer.

The Boot1/Boot2 dumping methods rely on the Datalight shell which is enabled on early CAS+ prototypes (EVT) but disabled on later CAS+ prototypes (DVT/PVT).
So in order to dump later/common CAS+ Boot1/Boot2, we'll have to study what we just got and find reusable exploits.
Title: Re: 1st dumping of a TI-Nspire CAS+ Boot1
Post by: apcalc on November 03, 2012, 07:30:06 pm
Cool, great job! :D