What's new? | Help | Directory | Sign in
Google
qcbqsanalyzer
Analysis of QC BQS mobiles
  
  
  
  
    
Search
for
Updated Apr 12, 2008 by b...@trash-mail.com
FirmwareStructureEF81  
How firmware is structured in EF81

EF81 firmware structure

This Page offers information how QC BQS firmware is structured.

Part Description

OBL      -> OTP Boot Loader
PBL      -> Primary Boot Loader
QCSBL    -> QC Secondary Boot Loader
OEMSBL   -> OEM Secondary Boot Loader
AMSS     -> Advanced Mobile Subscriber Software
EFS2     -> Enhanced File System V2

Details

*Type*     *NAND address*     *Memory address*      *Entrypoint*
-----------------------------------------------------------------
MIBIB
OBL                                  FFFF0000          FFFF00E8
ROOT_KEY             3E0              2500000-2600000, 2FFFED0 
QCSBLHEADER         4000             FFFF553C    
PBL                 8200             FFFF8200          0
Partition          1C200
OEMSBLHEADER       1C600             
AMSSHEADER         1C800
Partition2         20200
OEMSBLHEADER2      20600
AMSSHEADER2        20800
QCSBL              80200              2D4C000          2D4C01C
OEMSBL            140200              2D9C000          02D9C354, (several imports)
OEMSBL2           200200
SIM_SECURE        2C0000
PHONELOCK_HASH    2C001A - 2C0023 (10 bytes)
AMSS              2D0000                    0          0
EFS2             30C0000

Magic Tables for identification


*Name*                                 *Magic Bytes*       *Magic Bytes in file*
--------------------------------------------------------------------------------
QCSBLHEADER                      0x73D71034 0xF4EBB5            3410D773B5EBF400
PARTITION                        0x55EE73AA 0xE35EBDDB          AA73EE55DBBD5EE3
EFS2                             0x34856787 0x92347759          8767853459773492
PBL                              0x12349876 0x5264FEEB          76983412EBFE6452

Sign in to add a comment