<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.exploitee.rs/index.php?action=history&amp;feed=atom&amp;title=Vizio_CoStar_LT_%28ISV-B11%29%E2%80%8B</id>
	<title>Vizio CoStar LT (ISV-B11)​ - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.exploitee.rs/index.php?action=history&amp;feed=atom&amp;title=Vizio_CoStar_LT_%28ISV-B11%29%E2%80%8B"/>
	<link rel="alternate" type="text/html" href="https://wiki.exploitee.rs/index.php?title=Vizio_CoStar_LT_(ISV-B11)%E2%80%8B&amp;action=history"/>
	<updated>2026-05-06T15:29:34Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.45.0-alpha</generator>
	<entry>
		<id>https://wiki.exploitee.rs/index.php?title=Vizio_CoStar_LT_(ISV-B11)%E2%80%8B&amp;diff=2582&amp;oldid=prev</id>
		<title>Resno: Text replacement - &quot;gtvcom-20&quot; to &quot;exploiteers-20&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.exploitee.rs/index.php?title=Vizio_CoStar_LT_(ISV-B11)%E2%80%8B&amp;diff=2582&amp;oldid=prev"/>
		<updated>2016-02-07T01:22:41Z</updated>

		<summary type="html">&lt;p&gt;Text replacement - &amp;quot;gtvcom-20&amp;quot; to &amp;quot;exploiteers-20&amp;quot;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 01:22, 7 February 2016&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l7&quot;&gt;Line 7:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 7:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Purchase ==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Purchase ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Buying devices is expensive and, in a lot of cases our testing leads to bricked equipment. If you would like to help support our group, site, and research please use one of the links below to purchase your next device.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Buying devices is expensive and, in a lot of cases our testing leads to bricked equipment. If you would like to help support our group, site, and research please use one of the links below to purchase your next device.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[http://www.amazon.com/gp/product/B00FRD1H4S/ref=as_li_tl?ie=UTF8&amp;amp;camp=1789&amp;amp;creative=390957&amp;amp;creativeASIN=B00FRD1H4S&amp;amp;linkCode=as2&amp;amp;tag=&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;gtvcom&lt;/del&gt;-20&amp;amp;linkId=THBZKBDSQA3B2X3Z Purchase the Vizio CoStar LT media player at Amazon]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[http://www.amazon.com/gp/product/B00FRD1H4S/ref=as_li_tl?ie=UTF8&amp;amp;camp=1789&amp;amp;creative=390957&amp;amp;creativeASIN=B00FRD1H4S&amp;amp;linkCode=as2&amp;amp;tag=&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;exploiteers&lt;/ins&gt;-20&amp;amp;linkId=THBZKBDSQA3B2X3Z Purchase the Vizio CoStar LT media player at Amazon]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Disassembly ==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Disassembly ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;

&lt;!-- diff cache key gtvhack_wiki:diff:1.41:old-2230:rev-2582:php=table --&gt;
&lt;/table&gt;</summary>
		<author><name>Resno</name></author>
	</entry>
	<entry>
		<id>https://wiki.exploitee.rs/index.php?title=Vizio_CoStar_LT_(ISV-B11)%E2%80%8B&amp;diff=2230&amp;oldid=prev</id>
		<title>Zenofex at 11:00, 17 August 2014</title>
		<link rel="alternate" type="text/html" href="https://wiki.exploitee.rs/index.php?title=Vizio_CoStar_LT_(ISV-B11)%E2%80%8B&amp;diff=2230&amp;oldid=prev"/>
		<updated>2014-08-17T11:00:23Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 11:00, 17 August 2014&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l60&quot;&gt;Line 60:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 60:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* If you are hijacking init to gain root you will need to run &amp;quot;/etc/rc.mount&amp;quot; prior to modifying &amp;quot;/etc/commonStart.sh&amp;quot;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* If you are hijacking init to gain root you will need to run &amp;quot;/etc/rc.mount&amp;quot; prior to modifying &amp;quot;/etc/commonStart.sh&amp;quot;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;== Demo ==&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;{{#ev:youtube|2oFaIEOopPA}}&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== U-Boot Env ==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== U-Boot Env ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;

&lt;!-- diff cache key gtvhack_wiki:diff:1.41:old-2198:rev-2230:php=table --&gt;
&lt;/table&gt;</summary>
		<author><name>Zenofex</name></author>
	</entry>
	<entry>
		<id>https://wiki.exploitee.rs/index.php?title=Vizio_CoStar_LT_(ISV-B11)%E2%80%8B&amp;diff=2198&amp;oldid=prev</id>
		<title>Zenofex: 1 revision: Moving from DC22 to main site.</title>
		<link rel="alternate" type="text/html" href="https://wiki.exploitee.rs/index.php?title=Vizio_CoStar_LT_(ISV-B11)%E2%80%8B&amp;diff=2198&amp;oldid=prev"/>
		<updated>2014-08-17T08:22:51Z</updated>

		<summary type="html">&lt;p&gt;1 revision: Moving from DC22 to main site.&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 08:22, 17 August 2014&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;4&quot; class=&quot;diff-notice&quot; lang=&quot;en&quot;&gt;&lt;div class=&quot;mw-diff-empty&quot;&gt;(No difference)&lt;/div&gt;
&lt;/td&gt;&lt;/tr&gt;
&lt;!-- diff cache key gtvhack_wiki:diff:1.41:old-2197:rev-2198 --&gt;
&lt;/table&gt;</summary>
		<author><name>Zenofex</name></author>
	</entry>
	<entry>
		<id>https://wiki.exploitee.rs/index.php?title=Vizio_CoStar_LT_(ISV-B11)%E2%80%8B&amp;diff=2197&amp;oldid=prev</id>
		<title>Zenofex: /* Exploiting The Vizio CoStar LT For Root */</title>
		<link rel="alternate" type="text/html" href="https://wiki.exploitee.rs/index.php?title=Vizio_CoStar_LT_(ISV-B11)%E2%80%8B&amp;diff=2197&amp;oldid=prev"/>
		<updated>2014-08-06T12:16:53Z</updated>

		<summary type="html">&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;Exploiting The Vizio CoStar LT For Root&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;__FORCETOC__&lt;br /&gt;
{{Disclaimer}}&lt;br /&gt;
[[File:VizioCoStarLT.jpg|200px|left|thumb]]&lt;br /&gt;
[[Category:Media Players]]&lt;br /&gt;
This page will be dedicated to a general overview, descriptions, and information related to the Vizio CoStar LT media player.&lt;br /&gt;
&lt;br /&gt;
== Purchase ==&lt;br /&gt;
Buying devices is expensive and, in a lot of cases our testing leads to bricked equipment. If you would like to help support our group, site, and research please use one of the links below to purchase your next device.&lt;br /&gt;
[http://www.amazon.com/gp/product/B00FRD1H4S/ref=as_li_tl?ie=UTF8&amp;amp;camp=1789&amp;amp;creative=390957&amp;amp;creativeASIN=B00FRD1H4S&amp;amp;linkCode=as2&amp;amp;tag=gtvcom-20&amp;amp;linkId=THBZKBDSQA3B2X3Z Purchase the Vizio CoStar LT media player at Amazon]&lt;br /&gt;
&lt;br /&gt;
== Disassembly ==&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File: Vizio_CoStar_LT_000.JPG&lt;br /&gt;
File: Vizio_CoStar_LT_001.JPG&lt;br /&gt;
File: Vizio_CoStar_LT_003.JPG&lt;br /&gt;
File: Vizio_CoStar_LT_004.JPG&lt;br /&gt;
File: Vizio_CoStar_LT_005.JPG&lt;br /&gt;
File: Vizio_CoStar_LT_006.JPG&lt;br /&gt;
File: Vizio_CoStar_LT_007.JPG&lt;br /&gt;
File: Vizio_CoStar_LT_008.JPG&lt;br /&gt;
File: Vizio_CoStar_LT_009.JPG&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== UART ==&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:Vizio_CoStar_LT_UART.JPG&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Exploiting The Vizio CoStar LT For Root ==&lt;br /&gt;
On booting the Vizio CoStar LT&amp;#039;s bootloader checks for a &amp;quot;FS.sys&amp;quot; and a &amp;quot;safe-kernel.Img1&amp;quot; file on a FAT32 formatted thumb drive. &lt;br /&gt;
&lt;br /&gt;
* &amp;quot;FS.sys&amp;quot; - This file is a u-boot script file. This is a text file with u-boot commands in it compiled with mkimage. The exact compilation arguments for mkimage are as follows. &amp;lt;pre&amp;gt;mkimage -A arm -T script -d &amp;lt;SOURCE&amp;gt; &amp;lt;OUTPUT&amp;gt;&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &amp;quot;safe-kernel.Img1&amp;quot; - This is a kernel uImage.&lt;br /&gt;
&lt;br /&gt;
For this particular tutorial we are going to use the u-boot script file &amp;quot;FS.sys&amp;quot; to [[Hijacking_Kernel_Init Hijack Kernel Init]]. &lt;br /&gt;
&lt;br /&gt;
# Connect a USB-To-TTL adapter to the Vizio CoStar LT&lt;br /&gt;
# Format a USB drive to the &amp;quot;FAT32&amp;quot; format&lt;br /&gt;
# Add the following output to a file named FS.sys.txt &amp;lt;pre&amp;gt;setenv cmdline &amp;quot;mem=218M mem=32M@676M mem=26M@742M console=ttyS0,115200n8 MTD_NAME=mtd1,0,c8M MTD_NAME=mtd2,c8M,64M MTD_NAME=mtd3,12cM,12cM MTD_NAME=mtd4,258M,64M MTD_NAME=mtd5,2bcM,12cM MTD_NAME=mtd6,3e8M,12cM MTD_NAME=mtd7,514M,258M MTD_NAME=mtd8,76cM,90M MTD_NAME=mtd9,7fcM,4M ubi.mtd=2 ubi.mtd=3 ubi.mtd=6 ubi.mtd=7 ubi.mtd=8 init=/bin/sh&amp;quot;&lt;br /&gt;
run bootcmd&amp;lt;/pre&amp;gt;&lt;br /&gt;
# Compile the FS.sys.txt file with the following command. &amp;lt;pre&amp;gt;mkimage -A arm -T script -d fs.sys.txt fs.sys&amp;lt;/pre&amp;gt;&lt;br /&gt;
# Copy the fs.sys file to the root of the FAT32 formatted USB drive.&lt;br /&gt;
# Insert the USB drive into the Vizio CoStar LT.&lt;br /&gt;
# Restart the Vizio CoStar LT by unplugging and re-plugging in the power adapter.&lt;br /&gt;
# After the kernel boots it will drop your UART connection to a root shell.&lt;br /&gt;
&lt;br /&gt;
* NOTE: hijacking the kernel init stops the kernel prior to it running crucial scripts. In most cases you will need to finish running the scripts within /etc/init.d prior to being able to access the entire file system.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Gaining Persistent Root Access&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
After gaining root from the above method you can gain persistent root access by having the device boot a telnet root shell (or your choice of server) on boot. To do this you must find a write-able file on the device that is called on boot. &lt;br /&gt;
&lt;br /&gt;
Lucky for us &amp;quot;/etc/commonStart.sh&amp;quot; is just that file. You can modify this file to do anything you&amp;#039;d like to happen on each boot.&lt;br /&gt;
&lt;br /&gt;
For example adding:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
telnetd -l /bin/sh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
after &amp;quot;#!/bin/sh&amp;quot; will start a telnet server on each boot.&lt;br /&gt;
&lt;br /&gt;
* If you are hijacking init to gain root you will need to run &amp;quot;/etc/rc.mount&amp;quot; prior to modifying &amp;quot;/etc/commonStart.sh&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== U-Boot Env ==&lt;br /&gt;
Below is the u-boot environment output from the &amp;quot;printenv&amp;quot; u-boot command.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Logo_A=ubi read 82000000 Logo 3bc4e;showLogo 82000000 3bc4e&lt;br /&gt;
Logo_B=ubi read 82000000 Logo 3bc4e;showLogo 82000000 3bc4e&lt;br /&gt;
baudrate=115200&lt;br /&gt;
bootcmd=ubi part systemA_1;run Logo_A;ubi read 80100000 Kernel 800000;start_kernel&lt;br /&gt;
bootcmd_A=ubi part systemA_1;run Logo_A;ubi read 80100000 Kernel 800000;start_kernel&lt;br /&gt;
bootcmd_B=ubi part systemB_1;run Logo_B;ubi read 80100000 Kernel 800000;start_kernel&lt;br /&gt;
bootdelay=1&lt;br /&gt;
cmdline=quiet mem=218M mem=32M@676M mem=26M@742M console=ttyS0,115200n8 MTD_NAME=mtd1,0,c8M MTD_NAME=mtd2,c8M,64M MTD_NAME=mtd3,12cM,12cM MTD_NAME=mtd4,258M,64M MTD_NAME=mtd5,2bcM,12cM MTD_NAME=mtd6,3e8M,12cM MTD_NAME=mtd7,514M,258M MTD_NAME=mtd8,76cM,90M MTD_NAME=mtd9,7fcM,4M ubi.mtd=2 ubi.mtd=3 ubi.mtd=6 ubi.mtd=7 ubi.mtd=8&lt;br /&gt;
cmdline_A=quiet mem=218M mem=32M@676M mem=26M@742M console=ttyS0,115200n8 MTD_NAME=mtd1,0,c8M MTD_NAME=mtd2,c8M,64M MTD_NAME=mtd3,12cM,12cM MTD_NAME=mtd4,258M,64M MTD_NAME=mtd5,2bcM,12cM MTD_NAME=mtd6,3e8M,12cM MTD_NAME=mtd7,514M,258M MTD_NAME=mtd8,76cM,90M MTD_NAME=mtd9,7fcM,4M ubi.mtd=2 ubi.mtd=3 ubi.mtd=6 ubi.mtd=7 ubi.mtd=8&lt;br /&gt;
cmdline_B=quiet mem=218M mem=32M@676M mem=26M@742M console=ttyS0,115200n8 MTD_NAME=mtd1,0,c8M MTD_NAME=mtd2,c8M,64M MTD_NAME=mtd3,12cM,12cM MTD_NAME=mtd4,258M,64M MTD_NAME=mtd5,2bcM,12cM MTD_NAME=mtd6,3e8M,12cM MTD_NAME=mtd7,514M,258M MTD_NAME=mtd8,76cM,90M MTD_NAME=mtd9,7fcM,4M ubi.mtd=4 ubi.mtd=5 ubi.mtd=6 ubi.mtd=7 ubi.mtd=8&lt;br /&gt;
console=console=ttyS0,115200n8&lt;br /&gt;
ethact=FTMAC100&lt;br /&gt;
ethaddr=00:9c:0a:c6:98:9c&lt;br /&gt;
fileaddr=80100000&lt;br /&gt;
filesize=1BA&lt;br /&gt;
ip=172.16.60.66:172.16.60.166:172.16.60.1&lt;br /&gt;
ipaddr=172.16.60.233&lt;br /&gt;
macaddr=macaddr=00:12:34:56:78:34&lt;br /&gt;
mem_layout=mem=128m&lt;br /&gt;
mtddevname=boot&lt;br /&gt;
mtddevnum=0&lt;br /&gt;
mtdids=nand0=nand0&lt;br /&gt;
mtdparts=mtdparts=nand0:200M(boot),100M(systemA_1),300M(systemA_2),100M(systemB_1),300M(systemB_2),300M(etc),600M(rwdata),4M(bbt)&lt;br /&gt;
netmask=255.255.0.0&lt;br /&gt;
nfs=root=/dev/nfs nfsroot=172.16.60.166:/opt/bk_nfs/rootfs_fusion&lt;br /&gt;
partition=nand0,0&lt;br /&gt;
reflash=usb start; fatload usb 0 80100000 fs.sys;source 80100000; fatload usb 0 82000000 safe-kernel.img1;crc_start_kernel 82000000 fscmdline&lt;br /&gt;
serverip=172.16.60.125&lt;br /&gt;
stderr=serial&lt;br /&gt;
stdin=serial&lt;br /&gt;
stdout=serial&lt;br /&gt;
tftp_update=set update_method TFTP;tftp fs.sys;source 80100000;tftp 82000000 safe-kernel.img1;crc_start_kernel 82000000 fscmdline&lt;br /&gt;
update_method=USB&lt;br /&gt;
usb_update=set update_method USB;usb start;if fatload usb 0 80100000 fs.sys;then source 80100000;else run bootcmd ;fi; if fatload usb 0 82000000 safe-kernel.img1;then crc_start_kernel 82000000 fscmdline;else run bootcmd;fi&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Zenofex</name></author>
	</entry>
</feed>