CompactFlash, SD, MMC, USB flash storage. Anything that does not have moving parts inside.
June 12th, 2019, 16:17
Hi Gurus,
i've got following case:
damaged Medion-Laptop with 64GB eMMC-Flash. I can't repair the machine, so i desoldered the Flash and read the eMMC. After mounting the Image, there are 3 partitions.
- 100MB EFI/BOOT (not encrypted)
- 58GB System/User Data (encrypted)
- 500MB Recovery (not encrypted)
System-Partition is encrypted, we tried alle passphrases, that the owner ever used. Owner didn't activate any password for his user-account in the past. There is no Recovery-Key in Microsoft-Account stored.
So my question is - how does this self-decryption while booting work? Is the recovery-key stored in BIOS or EFI-partition?
On the EFI-partition i found two files with certificates - boot.stl and winsipolicy.p7b
If ther's any chance to find this key in BIOS i'll try to find it with grep. But what should i look for? 32 character alphanumerical string?
Thanks a lot.
Boerge
June 12th, 2019, 21:34
It may turn out to be easier to repair the laptop. What is the model number? I may be able to locate a service manual for you.
June 13th, 2019, 3:28
I may have a better Idea here (but should be done in our Lab)
eMMC FULL dump i mean...
let me know if you are interested...
June 13th, 2019, 7:51
fzabkar wrote:It may turn out to be easier to repair the laptop. What is the model number? I may be able to locate a service manual for you.
Model number is MD60250 / E2228T / MSN 30022190
Logic board numbers are EM_NT16H-MED_V1.0A / 14D13276 / 10770WCF / FHD Z8300 4+64
but i don't think, that there's any schematic available
June 13th, 2019, 7:56
einstein9 wrote:I may have a better Idea here (but should be done in our Lab)
eMMC FULL dump i mean...
let me know if you are interested...
What du you mean with "FULL dump" ? I have a full dump (imaged whole eMMC with PC3K).
June 13th, 2019, 19:45
boerge wrote:fzabkar wrote:It may turn out to be easier to repair the laptop. What is the model number? I may be able to locate a service manual for you.
Model number is MD60250 / E2228T / MSN 30022190
I checked elektrotanya.com, but your model isn't listed. :-(
June 15th, 2019, 4:29
boerge wrote:einstein9 wrote:I may have a better Idea here (but should be done in our Lab)
eMMC FULL dump i mean...
let me know if you are interested...
What du you mean with "FULL dump" ? I have a full dump (imaged whole eMMC with PC3K).
I mean, if you have the full dump maybe we can do it here (in our lab) means again upload your full eMMC dump to us if your agree and will try it..
not remotely..
June 15th, 2019, 5:56
Hi, Please connect/open drive/image and try TRIAL version of UFS Explorer Professional Recovery
Does it detect metadata of bitlocker? If so you may see like this :
https://youtu.be/m0nEz9-oBPA?t=197If not, need to look another solutions...
Powered by phpBB © phpBB Group.