{"id":27219882,"url":"https://github.com/wuseman/acer_chromebook_c720","last_synced_at":"2025-10-15T01:44:19.177Z","repository":{"id":306153357,"uuid":"944196449","full_name":"wuseman/Acer_Chromebook_C720","owner":"wuseman","description":"This repository is created for To share with me knowledge and everything is done for educational purposes","archived":false,"fork":false,"pushed_at":"2025-03-07T00:11:20.000Z","size":14596,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":1,"default_branch":"main","last_synced_at":"2025-07-24T00:59:50.573Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/wuseman.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null}},"created_at":"2025-03-07T00:10:16.000Z","updated_at":"2025-03-07T00:13:05.000Z","dependencies_parsed_at":"2025-07-24T00:59:53.663Z","dependency_job_id":"b5f76804-98ed-48f1-a943-f21751e21bdb","html_url":"https://github.com/wuseman/Acer_Chromebook_C720","commit_stats":null,"previous_names":["wuseman/acer_chromebook_c720"],"tags_count":null,"template":false,"template_full_name":null,"purl":"pkg:github/wuseman/Acer_Chromebook_C720","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/wuseman%2FAcer_Chromebook_C720","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/wuseman%2FAcer_Chromebook_C720/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/wuseman%2FAcer_Chromebook_C720/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/wuseman%2FAcer_Chromebook_C720/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/wuseman","download_url":"https://codeload.github.com/wuseman/Acer_Chromebook_C720/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/wuseman%2FAcer_Chromebook_C720/sbom","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":268689953,"owners_count":24291080,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-08-04T02:00:09.867Z","response_time":79,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["acer","bios","c720","chromebook","chromium","google","hacking","reverse"],"created_at":"2025-04-10T06:10:55.094Z","updated_at":"2025-10-15T01:44:14.160Z","avatar_url":"https://github.com/wuseman.png","language":null,"funding_links":[],"categories":[],"sub_categories":[],"readme":"# Acer C720\n\nHow to hack any Acer C7(4)20 Chromebook that has been locked remotely by admin and how easy it is to take control over a chromebook\n\n![Screenshot](1.jpg)\n\nWhole process from the first time we start this device until device will enter enrollment and there is nothing we can do more then see the process happening and then its out of our control (if we are not the admin)\n\n![Screenshot](2.jpg)\n\n![Screenshot](3.jpg)\n\n![Screenshot](4.jpg)\n\n![Screenshot](5.jpg)\n\n![Screenshot](6.jpg)\n\n![Screenshot](7.jpg)\n\n![Screenshot](8.jpg)\n\n* So, are we pwned? Of course not nothing is impossible!! Now let us hack this device\n\n* First of all, you must unscrew all screws and then when you opened the bottom of the laptop you must now remove the write-protection screw. Also, remove the battery:\n\n![Screenshot](battery.jpg)\n\n![Screenshot](battery2.jpg)\n\n* Now, with your bios/eeprom programmer you can read and overwrite the current bios. The bíos chip is the below one:\n\nOnce clip is conncted and your programmer found the clip, backup the current data on the chip:\n\n```bash\nflashrom -p ch341a_spi -r acer_c720p-locked.bin\n```\n\n### Write a clean bios to the chip:\n\n```bash\nflashrom -p ch341a_spi -w new_bios.bin\n```\n\n#### Kernel commandline:\n\n```bash\ncros_secure console= loglevel=7 init=/sbin/init cros_secure root=PARTUUID=7154669e-fca8-7e42-a967-fb4d9fa17343/PARTNROFF=1 rootwait rw dm_verity.error_behavior=3 dm_verity.max_bios=-1 dm_verity.dev_wait=0 dm=\"1 vroot none ro 1,0 2539520 verity payload=ROOT_DEV hashtree=HASH_DEV hashstart=2539520 alg=sha1 root_hexdigest=9c99ef74f8143304bad67f5ca941b0c0ccda3b0f salt=e5c44164a1e83b080c2d60e769953ba0a6138c654da4e929a1500825363be829\" noinitrd vt.global_cursor_default=0 kern_guid=7154669e-fca8-7e42-a967-fb4d9fa17343 add_efi_memmap boot=local noresume noswap i915.modeset=1 tpm_tis.force=1 tpm_tis.interrupts=0 nmi_watchdog=panic,lapic iTCO_vendor_support.vendorsupport=3 \n```\n\n#### Modules\n\nDefault modules for c720\n\n```bash\nModule                  Size  Used by\ncmac                   12903  2\nrfcomm                 28294  4\ni2c_dev                13075  0\nuinput                 17359  0\nmemconsole             12517  0\nath3k                  16819  0\nsnd_hda_codec_realtek    36389  1\nbtusb                  38875  0\nbtrtl                  12493  1 btusb\nbtbcm                  12876  1 btusb\nbtintel                13157  1 btusb\nbluetooth             316837  33 ath3k,btbcm,btrtl,btusb,rfcomm,btintel\nzram                   17580  1\nzsmalloc               13082  1 zram\nsnd_hda_codec_hdmi     35766  1\nuvcvideo               70677  0\nvideobuf2_vmalloc      12897  1 uvcvideo\nvideobuf2_memops       12617  1 videobuf2_vmalloc\nvideobuf2_core         31555  1 uvcvideo\nsnd_hda_intel          39591  5\nsnd_hda_codec         138464  3 snd_hda_codec_realtek,snd_hda_codec_hdmi,snd_hda_intel\nsnd_hwdep              13442  1 snd_hda_codec\nsnd_pcm                76877  3 snd_hda_codec_hdmi,snd_hda_codec,snd_hda_intel\nsnd_page_alloc         17260  2 snd_pcm,snd_hda_intel\nfuse                   70564  2\nnf_conntrack_ipv6      13689  2\nnf_defrag_ipv6         12884  1 nf_conntrack_ipv6\nip6table_filter        12540  1\nip6_tables             21995  1 ip6table_filter\nsnd_seq_midi           12848  0\nsnd_seq_midi_event     13511  1 snd_seq_midi\nsnd_rawmidi            22993  1 snd_seq_midi\nsnd_seq                53235  2 snd_seq_midi_event,snd_seq_midi\nsnd_seq_device         13234  3 snd_seq,snd_rawmidi,snd_seq_midi\nsnd_timer              27201  2 snd_pcm,snd_seq\nath9k_btcoex          120187  0\nath9k_common_btcoex    12819  1 ath9k_btcoex\nath9k_hw_btcoex       375415  2 ath9k_btcoex,ath9k_common_btcoex\nath                    22041  3 ath9k_btcoex,ath9k_hw_btcoex,ath9k_common_btcoex\nmac80211              377318  1 ath9k_btcoex\ncfg80211              159864  3 ath,ath9k_btcoex,mac80211\njoydev                 17112  0\n```\n\n#### lspci\n\n```bash\n00:00.0 Host bridge: Intel Corporation Haswell-ULT DRAM Controller (rev 0b)\n00:02.0 VGA compatible controller: Intel Corporation Haswell-ULT Integrated Graphics Controller (rev 0b)\n00:03.0 Audio device: Intel Corporation Haswell-ULT HD Audio Controller (rev 0b)\n00:14.0 USB controller: Intel Corporation 8 Series USB xHCI HC (rev 04)\n00:15.0 DMA controller: Intel Corporation 8 Series Low Power Sub-System DMA (rev 04)\n00:15.1 Serial bus controller [0c80]: Intel Corporation 8 Series I2C Controller #0 (rev 04)\n00:15.2 Serial bus controller [0c80]: Intel Corporation 8 Series I2C Controller #1 (rev 04)\n00:1b.0 Audio device: Intel Corporation 8 Series HD Audio Controller (rev 04)\n00:1c.0 PCI bridge: Intel Corporation 8 Series PCI Express Root Port 1 (rev e4)\n00:1f.0 ISA bridge: Intel Corporation 8 Series LPC Controller (rev 04)\n00:1f.2 SATA controller: Intel Corporation 8 Series SATA Controller 1 [AHCI mode] (rev 04)\n00:1f.3 SMBus: Intel Corporation 8 Series SMBus Controller (rev 04)\n00:1f.6 Signal processing controller: Intel Corporation 8 Series Thermal (rev 04)\n01:00.0 Network controller: Qualcomm Atheros AR9462 Wireless Network Adapter (rev 01)\n```\n\n### SSHD\n\nsshd is already installed and running but you wont be able to ssh into the device from another device because iptables is active and is set to DROP everything as default:\n\n```bash\nChain INPUT (policy DROP)\ntarget     prot opt source               destination         \nACCEPT     all  --  anywhere             anywhere             state RELATED,ESTABLISHED\nACCEPT     all  --  anywhere             anywhere            \nACCEPT     icmp --  anywhere             anywhere            \nACCEPT     udp  --  anywhere             224.0.0.251          udp dpt:mdns\nACCEPT     udp  --  anywhere             239.255.255.250      udp dpt:1900\nNFQUEUE    udp  --  anywhere             anywhere             NFQUEUE num 10000\nACCEPT     tcp  --  anywhere             anywhere             tcp dpt:ssh\n\nChain FORWARD (policy DROP)\ntarget     prot opt source               destination         \n\nChain OUTPUT (policy DROP)\ntarget     prot opt source               destination         \nNFQUEUE    udp  --  anywhere             224.0.0.251          udp dpt:mdns NFQUEUE num 10001\nNFQUEUE    udp  --  anywhere             239.255.255.250      udp dpt:1900 NFQUEUE num 10001\nACCEPT     all  --  anywhere             anywhere             state NEW,RELATED,ESTABLISHED\nACCEPT     all  --  anywhere             anywhere    \n```\n\nJust allow port 22 or clear iptables:\n\n```bash\niPV4=\"$(grep . /proc/net/fib_trie)\"\niPV6=\"$(grep  '.' /proc/net/if_inet6)\"; \n\nif [[ -n \"${iPV4}\" ]]; then \nprintf \"%25s\\n\" | tr ' ' '-'\nprintf \"%s\\n\" \"Removing all ipv4 rules\"\niptables -P INPUT ACCEPT \niptables -P FORWARD ACCEPT\niptables -P OUTPUT ACCEPT\niptables -t nat -F \u0026\u003e /dev/null\niptables -t mangle -F \u0026\u003e /dev/null\niptables -F\niptables -X\nprintf \"%s\\n\" \"...Done\"\nfi\n\nif [[ -n \"${iPV6}\" ]]; then \nprintf \"%25s\\n\" | tr ' ' '-'\nprintf \"%s\\n\" \"Removing all ipv6 rules\"\nip6tables -P INPUT ACCEPT\nip6tables -P FORWARD ACCEPT\nip6tables -P OUTPUT ACCEPT\nip6tables -t nat -F \u0026\u003e /dev/null\nip6tables -t mangle -F \u0026\u003e /dev/null\nip6tables -F\nip6tables -X\nprintf \"%s\\n\" \"...Done\"\nfi\nprintf \"%25s\\n\" | tr ' ' '-'\n```\n\nTry ssh again, root works fine.\n\nNOTICE: You must set a root password before you can ssh into the device\n\n### Set chromeos devpassword:\n\n```bash\nPASSWD_FILE='/mnt/stateful_partition/etc/devmode.passwd'\npass=$(openssl passwd -1)\n\nmkdir -p \"${PASSWD_FILE%/*}\"\nchmod 600 \"${PASSWD_FILE}\"\necho \"chronos:${pass}\" \u003e \"${PASSWD_FILE}\n```\n\n### VPD:\n\nThis is funny. The remote lock is locking devices via the serial number and as root we can list the currect info about device via vpd -l and we are also allowed to write new serial number without any hacking needed, the screw must be removed (see the top of post, WP-Screw)\n\n```bash\nvpd -i RO_VPD -s serial_number=xxxxxxx\n```\n\n* Hit enter, verify that our new serial has been written:\n\n```bash\n* vpd -l\n\n```\n\nRead more about VPD and how it works on url: https://chromium.googlesource.com/chromiumos/platform/vpd/\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fwuseman%2Facer_chromebook_c720","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fwuseman%2Facer_chromebook_c720","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fwuseman%2Facer_chromebook_c720/lists"}