Quote:
Originally Posted by dhdurgee
Does this provide a possible JB approach? Assuming the unit can be made to enter fastboot mode, could we not simply set it to boot to diags and then reboot it? Once in diags it should be simple enough to insert the certificates.
Dave
|
I **think** that the system will only enter fastboot mode in the way described if it is hung up in a way that the start-up code can detect.
**think**
It is certainly worth some research time.
Getting the device into 'diags' would be the key.
I am fairly certain 'diags' does not have 'downgrade protection'.
It wouldn't be of much use if it did have such protection, a normally malfunctioning firmware could not then be replaced.
The question of how to create a 'hang' situation from outside of a non-jailbroken Kindle is a question that has been posed before but no answer posted.
Note:
Since that time, it has been noted that the versions of libc the Kindles are using is vulnerable to a stack over-run by overly large DNS reply packets.
That **might** be a way to trash the system enough that it will 'hang' and enable fastboot the next time it restarts.
**might**