One can patch monitor.app to read SD serial from an arbitrary file instead of data from block device.
I have no idea if the protection scheme is complicated or not, I simply patched monitor.app to use an arbitrary file instead of "/sys/block/mmcblk%c/device/serial" (modified the string with an hex editor, put the file accordingly, and in ebrmain filesystem, updated the "pocketbook" link to monitor.app to use the patched version).
Worked on my TL2/626, guess it will work on TL3/626 and certainly other systems.
|