How to root an Android G1 phone

Wednesday, October 14, 2009 by BBTUNA

First off, I take no credit for this guide, this is straight from the xda-developers forums, which is an excellent place to learn about HTC phone hacking. So let’s get started. Make sure you backup anything important on your phone as this will erase everything. There are several apps in the Market that will backup apps, SMS, and other data for you. So don’t complain if you’ve lost your data. Your contacts and email should still synch with Google once you reinstall the new OS.

If you have US-RC30/UK-RC8 or higher, you will first need to downgrade your phone to a previous version. (Skip these steps otherwise)

  1. Format your phone’s SD card to FAT32 mode:
    • Hook your phone up to your computer using a USB cable and then wait for the notification to show up in your title bar of your phone.
    • Click the notification, and then click “Mount”.
    • A new removable disk should show up on your computer. Right click it and select Format, and select FAT32 as the file system type.
  2. Download and unzip the RC29 or RC7 image file. Copy the DREAMIMG.nbh file to the SD card. (RC29 for US, RC7 is for UK)
  3. Turn the device power off.
  4. Hold Camera button, and press Power button to entry bootloader mode. You should see a gray/white screen with instructions to flash your phone with the update on your SD card. If you don’t see that, make sure you followed the instructions properly.
  5. As per the on-screen instructions, press the Power button to start upgrade procedure.DO NOT DO ANYTHING TO INTERRUPT THIS PROCESS.
  6. After it is finished, perform the restart your phone.

Once you are running RC29 firmware:

  1. Download recovery.img and copy it to your SD card (see the previous instructions on how to copy from your computer to your Phone’s SD card).
  2. Download the Hard SPL and copy the zip file to the SD card.
  3. All files must be on the root of your SD card.
  4. Restart your phone. Wait for your phone to start up fully and show the home screen.
  5. After your phone starts up, hit the enter key twice, type “telnetd” and press enter. (Yes, it will start up a contact search, don’t worry. Just type it.)
  6. Download an Android “Telnet” application from the Market and connect to localhost.
  7. If you connect successfully, you will have a root prompt “#”.
  8. Type the following into Telnet (these commands will give you root access easier in the future):
    • mount -o rw,remount -t yaffs2 /dev/block/mtdblock3 /system
    • cd sdcard
    • flash_image recovery recovery.img
    • cat recovery.img > /system/recovery.img

Now you have root!
Now that you have root, you will want to apply “Hard SPL” to your phone. HardSPL is what will allow you to apply flash images from other regions (like UK on US phones, and vice versa), create full backups of your phone, install the latest build from the Android source, and usually resurrect your phone if it is “bricked”. You have already downloaded the file to your SD card, so now you can apply it.

  1. Power off your phone.
  2. Start up in recovery mode by holding home and pressing power.
  3. You will now enter recovery mode. You should see an exclamation.
  4. If you do not see a menu on screen, press Alt-L to show the menu.
  5. Press Alt-S to apply the update from the SD card.
  6. After the update is complete, hold Home and press Back to restart.

And now, the last step! You are still running an old version of Android, but you want to upgrade to the latest and greatest update! You can do this, and not lose root by downloading modified versions of the updates.

Download one of the latest ROMs to install, I recommend JF1.5:

JesusFreke 1,51

Haykuro Builds

The Dude’s Cupcake 1.2 Full
The Dude’s Cupcake 1.1a Lite (No 3rdparty/dev apps/Manup Blue Theme)

You will also want to apply the latest radio update from HTC. Install the same way as the system image:

HTC Downloads Page

To install the latest build (instructions from Haykuro):

1. Gain root (follow the various threads available on the forums to accomplish this).
2. Download the latest build above.
3. Copy to your sdcard as update.zip
4. Power off your phone.
5. Hold the Home button, and power on the device. (This should send you into recovery mode).
6. Press ALT+B to create a nandroid backup (if you wish to fall back without losing any data later, if you do go back to RC33 [or any other firmware 1.0 update] you will need to reflash your radio, users have reported problems using the new radio on the old firmwares.)
7. Press ALT+W, then ALT+S.
8. wait for it to finish, then home+back.

There you have it. I hope I gave proper credit and backlinks to the awesome people that make this possible. Now you can brag about your new Cupcake and also do all the cool stuff with root, like install full Linux distros, tether your phone, and install apps on the SD card.

Posted in | 0 Comments »

How to get guest VMs MAC addresses

by BBTUNA

I noticed an IP conflict today on a windows box hosted on the ESXi. In the events viewer under system I checked the MAC address of the system trying to hijack my IP address. I wanted to find a quick way and check if this mac address is in my existing ESXi Virtual Machines or it’s outside somewhere..
I wanted to find a quick and dirty way to check this since there is number of machines on the ESXi host.
Here is what I did…

I opened VMWare VI-TOOLKIT. After I connected I decided to try some commands that I regularly use such as get-vm and get-vmguest. After I found nothing interesting I checked out the CI Toolkit Cmdlets Reference Document.

And there it was… the perfect command for what I wanted..

Get-NetworkAdapter … Wooohoo!

[VI Toolkit] C:\Program Files\VMware\Infrastructure\VIToolkitForWindows> Get-NetworkAdapter -vm (get-vm *)|select MacAddress

MacAddress
———-
07:0c:29:11:61:6a
07:0c:29:6a:4a:db
07:0c:29:a4:ae:6f
07:0c:29:0c:c7:4c
07:0c:29:d5:8c:4f
07:0c:29:27:4d:84
07:0c:29:7c:e9:23
07:0c:29:52:52:aa
07:0c:29:eb:e3:e6
07:0c:29:17:66:50
07:0c:29:21:09:70
07:0c:29:81:89:3d
07:0c:29:0e:d6:ce
07:50:56:3f:51:02
07:0c:29:ad:60:61
07:0c:29:40:84:06
07:0c:29:40:84:10
07:0c:29:ce:89:9c
07:50:56:3f:51:01
00:1b:29:a0:ff:fe
00:1b:29:e2:ea:d5
00:1b:29:e2:ea:df
00:1b:29:e2:ea:e9
00:1b:29:07:f1:f9
00:1b:29:07:f1:03
00:1b:29:e8:8b:dd
00:1b:29:e8:8b:e7
00:1b:29:e8:8b:f1
00:50:56:3f:51:03
00:1b:29:ba:4c:b9
00:1b:29:84:2b:62
00:1b:29:2c:9d:6c
00:1b:29:7d:98:0e
00:1b:29:6a:1a:a5
00:1b:29:5a:82:cf
00:1b:29:26:23:bf
00:1b:29:df:87:1c

The MAC I was looking for was not here but this is a proof that none of the machines in my control is attempting the hijacking.

Posted in | 0 Comments »

VMware ESX 3.5 server bios update

Monday, September 28, 2009 by BBTUNA

Since I have a number of Dell ESX 3.5 hosts managed by a dedicated Virtual Center server each Dell ESX host needed firmware updates. Here are the steps I took to update the servers without using a floppy drive:

  1. Go to the Dell support site at http://support.dell.com and go to the drivers and downloads section for your server. Choose Red Hat Linux 4 as the OS type.
  2. In this case we’ll update the system bios, so expand the Bios section and download the Update Package for Red Hat Linux which should be a .BIN file (like PE2950_BIOS_LX_2.3.1_1.BIN) to your local machine.
  3. Next, download and install WinSCP (http://www.winscp.net) on your local machine.
  4. Open WinSCP on your local machine and enter the ESX server IP or hostname, username of root (or, if you were smart, a user you configured with less privileges), and the user’s password.
  5. Once you’ve logged into ESX, switch to the /tmp directory and create a directory called “dell” (or whatever you want).
  6. Upload the .BIN file to the dell folder on the ESX host.
  7. Migrate all the VM’s off the host you’re about to update and place the ESX host into maintenance mode as a reboot will be required after the following update.
  8. Now, log into the ESX server console using Putty (http://www.chiark.greenend.org.uk/~sgtatham/putty/) and switch to the root user (if you logged in under a different account) by typing “su -” and entering the root password.
  9. Switch to the dell directory you created above by typing “/tmp/”.
  10. Type “ls” or "ls -a" and make sure your .BIN file is in the /tmp/ directory.
  11. Give the .BIN file execute privileges by typing “chmod +x filename.BIN” where filename.BIN is the exact (case sensitive) file that you uploaded.
  12. Now execute the update by typing “./filename.BIN”. This will start a Dell dialog that you should read. When you’re done reading type “q” and it should execute the update.

You can run this same procedure for any other firmware updates you need to do. See, short and painless.

Posted in | 0 Comments »

Changing the IP on your ESX 3.x

Wednesday, August 19, 2009 by BBTUNA

If you want to change the IP address of the service console in ESX 3.x you can using a command in the service console and if you are like me and know that console is most powerful thing to know about ESX then read on.

To change the IP address of the ESX 3.x host, you need to change the configuration of the vswif. By default this is vswif0 and this is assumed in this document. Login to the service console with root permissions, either by using root or doing a su - to get the permissions.

Once in the service console runt the command "esxcfg-vswif -d vswif0". This command deletes the existing vswif0. Don't worry if you get a message about nothing to flush. Then you need to run the command to change the ip address, subnet mask and broadcast address. They are also specified in that order when the command is given. An example command is below.

"esxcfg-vswif -a vswif0 -p Service\ Console -i 10.1.1.1 -n 255.255.255.0 -b 10.1.1.255"

In this command the -a switch is to add a vswif, the \ in the Service\ Console is deliberate, the -i is the ip address, the -n is the netmask and the -b is the broadcast address.

You now need to change your default gateway, you can do this by editing the network file located at /etc/sysconfig/network. To do this at the command prompt, follow the steps below.

"cd /etc/sysconfig"
"nano network"
Then while in the nano editor, go to the location of the default gateway using the arrow keys.
Change the default gateway to your liking.
Hit Ctrl+X and Y to save

At this point you can run some commands to restart the vmware management, but I prefer to restart the server and will recommend you do that. Note that after you do change the main IP to your box you will have to change URL startup screen:

/etc/hosts
/etc/sysconfig/network
/usr/lib/vmware-mui/apache/conf/httpd.conf
When editing the hosts file, include the fully qualified domain name (FQDN).
Example: ip.address.of.server host.domain.com host
Note the order of the terms in the example above. If the FQDN and the alias are reversed, the remote console parameters will use the alias only.

In the httpd.conf file change the ServerName configuration setting to reflect the new FQDN.
Example: ServerName host.domain.com

After editing the files listed above, run the "hostname" command with the new FQDN to have the name change to take effect without a reboot.

Posted in | 0 Comments »

Securing VMware ESX

Tuesday, August 11, 2009 by BBTUNA
VMWare implementations can be done incorrectly if you just do your typical next > next > next .... reboot, very few people take the time to secure their VMware ESX infrastructure and that is when I recomend to them to get started a great little pice of freeware called Configcheck from Tripwire. The only thing missing in it is report generation in a PDF or HTML format but other than that if you have a VMWare ESX 3.x infrastructre use this great tool to give it a quick check. So for all you out there implementing ESX environments remember to lock down your system.
Posted in | 0 Comments »

How to set VMWare ESX Switch Security

by BBTUNA
One of the things I like about VMWare ESX is the security in their Layer 2 Virtual Swicthes. They will not permit them be joined together so loops is not an issue and they let you apply 3 policy settings to secure the vSwitches this are:
This settings will prevent the virtual machines that use the switch from acting as a sniffer, changing their mac address or forging traffic with fake mac address thous protecting the rest of the virtual machines in the case of a compromise of a VM from it being used to conduct Man In the Middle Attacks, ARP Poison Attacks or being used to sniff traffic. To set the Policy on Reject on a virtual switch it can be done both from the Service Console or thru the VI Client. On the VI Client:

  1. Log into the VMware VI Client and select the server from the inventory panel.The hardware configuration page for this server appears.
  2. Click the Configuration tab, and click Networking.
  3. Click Properties for the vSwitch whose Layer 2 Security policy you want to edit.
  4. In the Properties dialog box for the vSwitch, click the Ports tab.
  5. Select the vSwitch item and click Edit.
  6. In the Properties dialog box for the vSwitch, click the Security tab.
  7. Select reject on the drpdown boxes for all 3 Policy Exceptions.
  8. Click OK
From the CLI just SSH into the Server and su to have root privilege and run

  • vmware-vim-cmd hostsvc/net/vswitch_setpolicy --securepolicy-macchange=false
  • vmware-vim-cmd hostsvc/net/vswitch_setpolicy --securepolicy-forgedxmit=false
Promiscuous is already set to reject by default.
Posted in | 0 Comments »

Enabling network hints on VMware ESX for CDP

Wednesday, July 8, 2009 by BBTUNA
If you've ever had to manually trace the multiple cat5e cables from ESX hosts to network switches you probably were not happy about it. The good news is that if you have ESX 3.5 and Cisco switches you can identify the switch ports that each VMNic is connected into by using Cisco Discovery Protocol (CDP). You won't even need access to the network switch and get all port information from the VI Client.

First we need to configure the host by logging into the Service Console as root (either by SSH, remote console, or physical access).
Next we need to verify current CDP settings for the desired virtual switch (vSwitch1 will be used in this post)
Type:
[root@server root]#esxcfg-vswitch -b vSwitch1 down (The output of down indicates CDP is currently not implemented)

Now set the CDP status for a given vSwitch (possible values are down, listen, advertise, or both) by typing:
[root@server root]#esxcfg-vswitch -B both vSwitch1

Verify the new settings by typing:
[root@server root]#esxcfg-vswitch -b vSwitch1 both

Be sure to repeat the commands for every vSwitch on the ESX host. Now using the VI Client you can go into the "Configuration" tab of a host and select "Networking" on the left pane. To the right of each vSwitch you find a comment looking box colored in a light blue. Clicking on the icon will brind up the switch port information.

Now lets say you want to extract CDP information for all VMNics at once. You can achieve this by going to the command line and typing:
[root@server root]#vmware-vim-cmd hostsvc/net/query_networkhint

Leave feedback in the comments. I would love to answer your questions if any arise.
Posted in | 0 Comments »

About Me

Blog Archive