What's new? | Help | Directory | Sign in
Google
qcbqsanalyzer
Analysis of QC BQS mobiles
  
  
  
  
    
Search
for
Updated Feb 11, 2008 by b...@trash-mail.com
DiagSubSys2  
Some infos about DiagSubSys2

Introduction

Diag Subsys has some useful commands, like read out root_key, or write sim_secure.

Main SubSys Routine (CMD check)

ROM:008BD896 03 90                       STR     R0, [SP,#0x28+var_1C]
ROM:008BD898 30 1D                       ADDS    R0, R6, #4
ROM:008BD89A 05 1C                       ADDS    R5, R0, #0
ROM:008BD89C D0 F7 42 EA                 BLX     sub_88DD24
ROM:008BD8A0 03 99                       LDR     R1, [SP,#0x28+var_1C] ; Command Byte
ROM:008BD8A2 67 29                       CMP     R1, #0x67 ; 'g'
ROM:008BD8A4 4E D0                       BEQ     loc_8BD944
ROM:008BD8A6 4B DC                       BGT     loc_8BD940
ROM:008BD8A8 58 29                       CMP     R1, #0x58 ; 'X'
ROM:008BD8AA 4C D0                       BEQ     loc_8BD946
ROM:008BD8AC 30 DC                       BGT     loc_8BD910      ; 5A - read simsecure, jmp
ROM:008BD8AE 51 29                       CMP     R1, #0x51 ; 'Q'
ROM:008BD8B0 4A D0                       BEQ     loc_8BD948
ROM:008BD8B2 1E DC                       BGT     loc_8BD8F2      ; 57 - write sim_secure, jmp
ROM:008BD8B4 0C 29                       CMP     R1, #0xC
ROM:008BD8B6 48 D0                       BEQ     loc_8BD94A
ROM:008BD8B8 0D DC                       BGT     loc_8BD8D6
ROM:008BD8BA 00 29                       CMP     R1, #0
ROM:008BD8BC 46 D0                       BEQ     loc_8BD94C
ROM:008BD8BE 06 29                       CMP     R1, #6
ROM:008BD8C0 45 D0                       BEQ     loc_8BD94E
ROM:008BD8C2 07 29                       CMP     R1, #7
ROM:008BD8C4 44 D1                       BNE     loc_8BD950

Sign in to add a comment