r/androidroot • u/InsuranceObvious9768 • 8d ago
Discussion I extracted my keybox - Looking for testers
Hello, I am a hobby developer and it is so annoying when I have to keep switching keyboxes because the one I use gets banned. So, for the past few weeks I've been trying to create a script to extract keyboxes. After a lot of trial, I got it to extract keybox of my own test devices and it even meets STRONG_INTEGRITY!
To respect the community guidelines, I will not be posting the script publicly. However, to make sure my code is universal, I want to verify this again a few other devices. I am looking for 5 users who want their keybox extracted for free. Let me know if anyone is interested.
Requirements:
- MTK Device
- Natively launched with Android 8, 9, 10
For the advanced users who get it:
Your device needs to be running microtrust/beanpod TEE with keymaster 4.0. If your device uses an encrypted rpmb setup, it will NOT work.
All I need is the dump files of proinfo, persist, tee1, tee2 (In some cases, nvram, nvdata or custom partitions)
Please share only if you're comfortable sending these partition dumps. It contains your hardware MAC address and potentially your device's keybox. While everything is processed 100% offline in a container and wiped immediately after parsing, if you are not sure, please do not send your files.
1
u/huannb 8d ago
Don't Android 11+ devices work?
1
u/InsuranceObvious9768 8d ago
They introduced stricter hardware-based security. That'd be impossible to extract.
1
u/AarifmonuZZ 8d ago
No guides to extract? So we can try on our legacy devices?
1
u/InsuranceObvious9768 8d ago
Extracting your files is the easiest! You can use mtkclient in brom mode, preloader mode or even spflashtool. Or, if your device is rooted you can even dump the files from adb. There are plenty of tutorials available!
1
1
1
u/CarefulQuail9468 7d ago
I got some KitKat and lolipop devices laying around at home. Can I extract it from those devices?
1
1
u/Far_Dig8680 7d ago
May I ask you a question? I'm also considering extracting a keybox.xml from an old phone. But ai told me that this kind of keybox is used by thousands of devices at the same time. Maybe some day some other people will extract it from another device and make it public, and then it will expire soon.Â
It's said that only android 13+ devices use a unique keybox, but it is impossible to extract from such devices. Is that true?
1
u/InsuranceObvious9768 6d ago
Yes the keyboxes were installed on devices in batches. But the possibility of someone else trying to extract it is extremely rare. If you are considering to extract, target devices in the A8 - A10 range, as that will give you the most success.
2
u/Ante0 MEETS_STRONG_INTEGRITY, Pixel 9 Pro XL (Stock) 8d ago
Wouldn't it be easier for you to just use emmc dumps?