Unlock FX after 3 wrong PIN attempts
Posted: 20 Jul 2020, 18:56
Today i try to get where FX is storing "the wrong PIN entered" counter to find out how to recover it from there.
First i only test how it could be made after entering 3 times the wrong PIN. I know after 9 times it should be locked completly, but as this tooks days to run it, i don't think i will test this
My test setup:
- Update FX with latest firmware to have a fresh Flash
- Dump the unmangled flash
- Enter wrong PIN #1 => Dump flash
- Enter wrong PIN #2 => Dump flash
- Enter wrong PIN #3 (displays "Device locked for 1 hour") => Dump flash
1. Test
Write wrong PIN #2 flash back onto device => Device unlocked, can enter another PIN. Oh man, that was too easy ...
Now i examine the Flashdumps to find differences...
First i only test how it could be made after entering 3 times the wrong PIN. I know after 9 times it should be locked completly, but as this tooks days to run it, i don't think i will test this
My test setup:
- Update FX with latest firmware to have a fresh Flash
- Dump the unmangled flash
- Enter wrong PIN #1 => Dump flash
- Enter wrong PIN #2 => Dump flash
- Enter wrong PIN #3 (displays "Device locked for 1 hour") => Dump flash
1. Test
Write wrong PIN #2 flash back onto device => Device unlocked, can enter another PIN. Oh man, that was too easy ...
Now i examine the Flashdumps to find differences...