Sh1mmer - Mercury Workshop
Website: https://sh1mmer.me/
GitHub: https://github.com/MercuryWorkshop/sh1mmer
Shim downloading has been taken down by Google. Use this rehosted link - https://dl.darkn.bio/ - to get a shim for your board.
Shady Hacking 1nstrument Makes Machine Enrollment Retreat:
-> SH1MMER is an exploit capable of completely unenrolling enterprise-managed Chromebooks.
-> It was found by the Mercury Workshop team and was released on January, Friday the 13th, 2023. For more info, check out the Writeup.
-> If this isn't working for you, you're probably on v111+. If you are on v111 - v113, use https://github.com/S-PScripts/chromebook-utilities/blob/main/Exploits/Sh1mmer%20v111%20-%20v113
What you will need:
-> A USB with at least 8GB of storage
-> A personal computer or chromebook; note that you need admin perms on Windows/MacOS
Writing to USB:
-> First, you'll need to find your managed Chromebook's board name.
This can be done by going to chrome://version on your Chromebook and copying the word after stable-channel, or with a variety of other methods.
-> If your board name is in the list below, your board has a publicly leaked RMA shim. If it's not, you'll have to source it on your own.
brask, brya, clapper, coral, corsola, dedede, enguarde, glimmer, grunt, hana, hatch, jacuzzi, kukui, nami, octopus, orco, pyro, reks, sentry, stout, strongbad, tidus, ultima, volteer, zork
-> First, you need to download a SH1MMER bin. Download a shim at dl.sh1mmer.me, and build it with the SH1MMER web builder.
-> Once you've obtained a MODIFIED SHIM (NOT A RAW SHIM), you can continue.
-> Download the Chromebook Recovery Utility extension on your personal computer as well.
-> Once the downloads are complete, launch the recovery utility and plug your USB into your personal computer.
-> Note: Your USB will be completely cleared and partitioned.
-> In the recovery utility window, click the settings icon and press "Use local image".
-> Select your shim file, identify your USB, and start the writing process. This will take about 10 minutes.
Executing on Chromebook:
-> Once writing is complete, enter recovery mode on your Chromebook.
This is done by pressing the power button (⏻), reload key (↻), and escape key at the same time.
-> Press Ctrl+D on this screen, then press enter.
-> It will now say something about "returning to secure mode" or that "OS verification is off".
You will most likely not actually be in dev mode, but the exploit will work regardless.
-> On this screen, press the power button (⏻), reload key (↻), and ESC key at the same time again! This is very important and cannot be skipped.
-> Once it re-shows the original recovery screen, plug your shimmed USB into your Chromebook, and press the power button (⏻), reload key (↻), and ESC key again.
After a brief black-and-white loading screen, you should be in the SH1MMER menu.
-> Play around with the UI, exit, and reboot.
Aftermath:
-> You will now be able to, among other things, unenroll your Chromebook. It will now behave entirely as if it is a personal computer and no longer contain spyware or blocker extensions.
After you do this and get past the "determining device configuration" screen, you will be able to actually turn dev mode on.
-> Note that while unenrolled, it is recommended to add your personal account first, then add your school account, then switch between the two as needed.
Mercury Workshop does not condone the use of SH1MMER or unenrolling to cheat in school.
-> The biggest challenges with unenrolling are connecting to the school network and taking state or national exams (since there are no kiosk apps anymore).
-> There are many methods to get a school Wi-Fi password while enrolled, including the policy netlog trick.
While on a school account and unenrolled, you can bypass Wi-Fi blocks by using a secure DNS such as Cloudflare 1.1.1.1 from chrome://os-settings/osPrivacy.
It is also recommended to enable "MAC Address Randomization" in chrome://flags to stay hidden.
-> To take a kiosk exam, the safest option is to re-enroll temporarily. Instructions for doing that are hosted at https://sh1mmer.me/kiosks.txt.
Saving a copy of this file for future reference is probably a smart move.
CryptoSmite is an exploit capable of completely unenrolling enterprise-managed Chromebooks. It was found by FWSmasher and released on March 9th, 2024.
It uses stateful files to unenroll.
How it works:
It uses stateful backups that allow changing the encrypted contents of the stateful partition to arbritary contents.
This data is useful for enrollment status, so it was changed to make the device appear unenrolled.
On the OOBE, it starts the AutoEnrollmentController, which chains into the ash ownership system, and then the ownership system checks for a file.
If this file exists, it removes firmware management parameters (FWMP).
This exploit has been patched since Chrome OS 120.
The kernel version of your Chromebook must end with 0, 1, or 2 to perform this exploit.
Finding Kernver:
If you're on v120 or higher, you need to downgrade in order to use CryptoSmite. To do this, you first need to check your kernver= in Recovery Mode.
1. Boot into Recovery Mode
-> Hold ESC + Refresh + Power for 2 or 3 seconds.
-> You should be on an "Insert Recovery Media" or "Let's step you through the recovery process" screen.
2. Press TAB and look at the last digit of the kernver= line
kernver= ends with a 0 or 1!
-> Congratulations, you can downgrade to any version! Follow the instructions on the file "Downgrade Versions" in this repo
kernver= ends with a 2!
-> Congratulations, you can downgrade to v112-v119! Follow the instructions on the file "Downgrade Versions" in this repo
kernver= ends with a 3!
-> Sorry, you can't downgrade to v119 or lower. Wait for a new unenrollment exploit or do a dangerous hardware modification (https://blog.darkn.bio/blog/3-the-tsunami).
Using CryptoSmite:
1. Download a SH1MMER Prebuilt image here: https://dl.darkn.bio/SH1mmer/Prebuilt/
2. Disable OS verification (blocked or not, doesn't matter), and boot into the shim.
3. Navigate to Payloads and navigate to CryptoSmite using the arrow keys, then press Enter.
4. Type in Y then press enter, and it'll automatically reboot upon completion.
5. Proceed through the setup partially till you get to the Add Account Screen.
-> If you see an update prompt, reboot then press CTRL + ALT + E on the Wi-Fi screen.
-> This should allow skipping the update, or make it not appear at all.
6. Powerwash the Chromebook at the "Add Account" screen. Afterwards, it'll be fully unenrolled.
Further Reading:
Repository: https://github.com/FWSmasher/CryptoSmite
Source: https://raw.githubusercontent.com/FWSmasher/CryptoSmite/main/cryptosmite.sh
Website: https://docs.google.com/presentation/d/1MciRMbDEb3RJomH2gYW9C5qRVjS4P92o2s4QepoCSgY
Official Blogspot: https://exploitingchromium.blogspot.com/
Information in this file are all from https://github.com/BinBashBanana/badrecovery!
BadRecovery:
-> BadRecovery (formerly OlyBmmer) is an exploit for ChromeOS devices, leveraging a vulnerability in recovery images to get arbitrary code execution or to chain to other exploits.
-> BadRecovery unenrolls ALL devices that are EOL before 2024, and can unenroll current supported devices on kernel version 3 or lower.
-> The exploit and writeup were released to the public on October 5th, 2024.
-> You can read the writeup here: https://github.com/BinBashBanana/badrecovery/blob/master/writeup.md
How to use:
You will need:
-> A USB drive or SD card (8 GB or larger)
-> Something to flash the image (dd, rufus, chromebook recovery utility, etc.)
-> A ChromeOS device that has not received the patch (see patch)
Preparing an image:
You can build an image or you can use a prebuilt image.
Using a prebuilt:
-> Go to [https://dl.darkn.bio/BadRecovery]
-> Find your board
-> Download the image
-> Go to the section below for flashing the image
Building an image:
-> First, you must download an official recovery image for your device.
-> You can download them from ChromiumDash [https://chromiumdash.appspot.com/serving-builds?deviceCategory=Chrome%20OS] or Chrome100 [https://chrome100.dev/]
-> See modes of operation for which version you'll need, usually r124 or older.
-> Be sure you've downloaded the correct image for your device.
-> Make sure to unzip the recovery image before proceeding to the next step!
-> Next, you must modify the recovery image using the script included in the repository.
-> You can use the web version [https://binbashbanana.github.io/badrecovery/builder.html] of the builder, though it is a fair bit slower.
-> To get the script, run these commands on a linux machine:
git clone https://github.com/BinBashBanana/badrecovery
cd badrecovery
-> To modify a recovery image using the script, run
sudo ./build_badrecovery.sh -i
(Replace
-> The script may prompt you to install required dependencies.
-> You can specify the mode using the --type argument (-t for short).
-> If left unspecified, the script will automatically determine the best option based on the version and features of the recovery image.
Example:
sudo ./build_badrecovery.sh -i image.bin -t postinst
-> The script would fail if it detected that the supplied recovery image does not meet the requirements for postinst mode (see table below).
-> The recovery image is now modified, and is ready to be flashed to a USB drive or SD card.
Flashing the image:
-> You can use many tools for this, e.g. balena etcher, dd, etc. but the choice you will probably want to use is Chromebook Recovery Utility
-> Steps for using CRU:
1. Install Chromebook Recovery Utility onto your personal computer.
(https://chrome.google.com/webstore/detail/chromebook-recovery-utili/pocpnlppkickgojjlmhdmidojbmbodfm)
2. Open the extension, click on the settings button in the top right-hand corner, and click "Use local image".
3. Select the recovery image you downloaded from chrome100.
4. Plug in the USB you wish to use, and follow the prompts on the screen.
5. On your Chromebook, press Esc+Reload+Power and follow the prompts.
6. On the checking for updates screen, press Ctrl+Shift+E to skip it.
Running on ChromeOS device:
1. First, enter recovery mode. See this article [https://support.google.com/chromebook/answer/1080595#enter] for instructions to enter Recovery.
2. If you are not using the unverified payload, skip to step 5. The unverified payload will not work on devices that disallow developer mode (most school devices).
3. ONLY if you are using the unverified payload, you will have to enter Developer Mode by pressing Ctrl+D on the recovery screen.
4. If you are using unverified payload, DO NOT follow the prompts to re-enable verified mode. Instead, press Ctrl+D to get around these screens.
5. If you are not using unverified, you are already in recovery. Otherwise, re-enter recovery.
6. On the "Connect a recovery device" screen, plug in your BadRecovery drive.
7. Profit?
Important:
-> On the unverified payload, you must also enter developer mode, and then enter recovery mode again for BadRecovery to work.
-> On Cr50 devices (most devices manufactured in 2018 or later), you must NOT be in developer mode for unenrollment to work. Ensure you are in verified mode recovery.
-> In any other case, you can use either verified or developer mode recovery.
-> Plug in the prepared USB drive or SD card. On the unverified payload, BadRecovery will start in only a few seconds if you've done everything correctly.
-> On any other payload, the system will recover first. This may take a while depending on the speed of your drive.
-> On postinst and postinst_sym payloads, BadRecovery will start partway through the recovery process.
Note:
-> If using postinst_sym and BadRecovery does not start, the path to the internal drive is incorrect.
-> On basic or persist payloads, reboot into verified mode after recovery completes.
-> Optionally, you can look at VT3 and reboot early to skip postinst and save some time.
-> On the persist payload, BadRecovery will start within a few seconds of ChromeOS booting.
-> On basic, you must proceed through setup and the device will unenroll using cryptosmite [https://github.com/FWSmasher/CryptoSmite]
-> When BadRecovery finishes, you will usually be able to skip the 5 minute developer mode delay by immediately switching back into recovery mode to get to developer mode. (This is not required.)
Modes of operation:
Mode Requirements Description
postinst
86 ≤ version ≤ 124 AND disk layout v1 or v2
ROOT-A (usb) overflows into ROOT-A (internal). Not supported on disk layout v3 (devices with minios). Replaces postinst with a custom payload and grants code execution in recovery.
postinst_sym
34 ≤ version ≤ 124 AND (kernel ≥ 4.4 OR year < 2038)
ROOT-A (usb) overflows into STATE (internal). Stateful installer copies payload (usb) to a symlink in STATE (internal) which points to ROOT-A (internal). Replaces postinst with a custom payload and grants code execution in recovery.
Caveat: internal disk device path must be known.
persist
26 ≤ version ≤ 89 (untested below 68)
ROOT-A (usb) overflows into STATE (internal). Encrypted data persisted through cryptosmite, code execution given in ChromeOS through crx-import.
basic
26 ≤ version ≤ 119 (untested below 68)
ROOT-A (usb) overflows into STATE (internal). Standard cryptosmite unenrollment payload.
unverified
version ≤ 41 / version ≤ 47 (WP off) / any version (developer mode NOT blocked)
Unverified ROOT-A, developer mode only! Use this for very old devices or for testing. This is an intended feature, not a bug.
-> All images will be larger than 2 and smaller than 8 GB, except unverified, which is almost always less than 1 GB.
Note:
For persist and basic, on version 86 and above (when postinst is available), built images are large (8.5 GB) for the legacy/v1 disk layout and even larger (17 GB) for disk layout v2.
postinst should always be preferred anyway. If you choose to use either of these modes anyway, some different steps must be taken while installing the recovery image.
Patch:
-> R125 recovery images and newer are not vulnerable to this (except unverified).
-> To determine if you can use this, follow these in order:
-> Was your device EOL before 2024? → YES
-> Are you on ChromeOS version 124 or lower? → YES
-> Was your device released after mid-2024? → NO
-> Does your device show 03 or lower as the last digits of the kernver (kernel version) on the recovery screen (press TAB, look at the line that starts with "TPM")? → YES
-> Higher than 03? → NO
Credits:
-> OlyB/BinBashBanana - most of the work here
-> Writable - cryptosmite [https://github.com/FWSmasher/CryptoSmite] vulnerability
-> Rory McNamara - encrypted_import vulnerability
-> Bomberfish - the name BadRecovery
-> joshuajohncohen (Helped me with this file)
Testers:
Big thanks to the testers:
-> Juliet (celes)
-> M_Wsecond (lars)
-> Kelpsea Stem (peppy, nissa)
-> Kxtz (relm)
-> Desvert (peach-pi)
-> WeirdTreeThing (trogdor)
-> cmxci (gnawty)
Dedications:
-> Percury Mercshop
-> Blake Nelsen (kinda)
-> Rory McNamara
GO HERE INSTEAD: https://br1ck.vercel.app/
BR1CK By Copernicium [https://discord.gg/Pb6qUkacpj]
What is BR1CK?
BR1CK was an exploit released October 27th, 2024 which takes advantage of an oversight while creating FWMP in the TPM.
It is capable of unenrolling all devices without platform FWMP on any version below v132.
How does it work?
The exploit works because of an issue that these chromebooks have when enrolling.
If you EC reset[1] ↻+⏻ at just the right time, it will corrupt some data in the FWMP TPM space[2], resulting in an unreadable FWMP, meaning we can unenroll since we aren't under it's control[3] (besides WP).
This allows us to boot into sh1mmer, unenroll, and fix the brick with gsctool -a -o
1. EC reset = the 2 keys used to forcefully restart the chromebook
2. FWMP TPM space = the data used by ChromeOS for enrollment related stuff
3. While FWMP is applied, protections are made to stop it from getting removed. These protections are from blocking debug cables to blocking resetting of the TPM (where it is stored)
How was this found?
While trying to do CRSH2TTY[1], Copernicium ended up bricking their device multiple times (a total of four).
One time, they randomly tried to disable write protection while unbricking with a SuzyQ (debug cable), and surprisingly, it worked!
This led to the discovery that FWMP doesn't apply while FWMP is corrupted. This functionality is stored in the read-only firmware,
which means Google would have to produce updated Chromebooks with the fix to stop this.
All of their exploits have been made due to CRSH2TTY in some way.
1. CRSH2TTY was a (now patched) unenrollment exploit that required resetting at specific times, similar to BR1CK
What do you need to do this?
1. Luck (or skill, because you can get it consistently)
2. A board that is CR50 and not TI50
As of October 29, 2024, if you have one of the boards listed below, you cannot do the exploit:
brya, brask, cherry, guybrush, skyrim, rex, nissa (maybe?), corsola, staryu, geralt
How do I find my board name?
Go to chrome://version, click Ctrl + F and search for "stable-channel" the word after that is your board
3. (PREFERABLY) access to chrome://network#logs
4. A leaked shim, a USB drive, and another pc to flash it
4.1. If you have a keyrolled dedede then you can buy a suzy qable [https://www.ebay.com/itm/335130747039]
(This seller is highly recommended, Copernicium bought from them and they're highly reputable)
and use alternative steps Copernicium can provide/walk you through.
How do you perform this exploit?
-> Backup anything that is not sync'd to your google account (mainly files)
-> It is a good idea to read these instructions on another device like a phone, you will not be able to access this guide on the chromebook you are using
[RECOMMENDED] For users with chrome://network#logs (can't be policy blocked, can't use OOBESCAPE):
1. Go to the section below this one (finding the reset times), go through the process, and memorize the time it gives you, then continue
2. Powerwash again by signing out, pressing Ctrl+Alt+Shift+R
3. Proceed through the setup, when "Getting device ready" pops up, get a stopwatch ready and wait for the next "Enterprise enrollment" screen.
4. When "Enterprise enrollment" pops up, start your stopwatch.
5. Wait until you're in the ranges of time (I would go for the higher end) the file uploader gave you, perform an EC-Reset by ↻+⏻.
6. If chrome turns back on and you get one of the following screens (on website), proceed, otherwise, keep trying (this may take ages but most people can get it in 2-20 tries)
[if you click tab on either of these, under recovery reason it should say something about an error in the TPM]
7. Once bricked, get a shim (this guide will be using legacy)
If you don't know your board name and still went on with these steps, you can look it up by entering the model name at the bottom on a site like cros.tech
8. Press CTRL + D, then enter to enable developer mode (It doesn't matter if it's blocked), and then ESC + ↻ + ⏻ to enter recovery mode.
9. Plug in your shim USB
If you get a screen saying "the device does not contain ChromeOS"/"no valid image" you either chose the wrong shim for your board, didn't go into developer mode, bad flash, bad file, or you've been keyrolled (and cannot continue)
10. When the shim boots, type D to select "Deprovision"
11. Next, type B to open a bash shell, this is where we'll unbrick
12. Type the following command:
gsctool -a -o
Press the power button whenever it spams "Press PP button now!" (this will take awhile) whenever it says "Another press will be required" it is telling you to wait, you may have to wait for a minute or even more.
13. Once you're at the end of that process you should reboot and you'll be back at the "Welcome!" screen. (if you don't reboot/gsctool doesn't work, proceed to the bottom section, "errors while unbricking")
14. Get back into developer mode by pressing ESC + ↻ + ⏻, then CTRL + D, then enter.
15. Either press CTRL + D if you're on a "OS verification is OFF" white screen, or enter if you're on a "You are in developer mode" black screen.
(keep this in mind if you want to stay in developer mode, you will have to do this each time you power it on)
16. You may get a "Your system is transitioning into Developer Mode" screen, wait for the 5 minute timer to finish, then follow step 15 again to boot into ChromeOS.
17. Start setting up your chromebook in OOBE by clicking Get Started, going through WiFi, and continuing. You should enroll.
18. Enter VT2 ctrl + alt + →
19. In VT2 type the following command: vpd -i RW_VPD -s check_enrollment=0
20. Powerwash or return to secure mode and once you go back through OOBE setup you should be unenrolled!
If you aren't, contact byte (check the credits for where to contact) for help.
[REALLY HARD AND LUCK BASED] For users WITHOUT chrome://network#logs
1. Powerwash by signing out, pressing Ctrl+Alt+Shift+R, and following the instructions.
2. Proceed with the setup until you get to the "Getting device ready" screen.
3. Get a stopwatch ready and wait for the "Enterprise enrollment" screen.
3.5. Start your stopwatch and record how long it took for enrollment to finish
4. Take the time it took, take around 1-1.5 seconds off the time it took to enroll, proceed
5. Powerwash again by following step 1, go through the setup, and when you get to the "Enterprise enrollment" screen, start your stopwatch and wait for the time you got from step 4, perform an EC-Reset by ↻+⏻.
6. If chrome turns back on and you get one of the following screens (on website), proceed, otherwise, keep trying (this may take ages but most people can get it in 2-20 tries)
[if you click tab on either of these, under recovery reason it should say something about an error in the TPM]
7. Once bricked, get a shim (this guide will be using legacy)
If you don't know your board name and still went on with these steps, you can look it up by entering the model name at the bottom on a site like cros.tech
8. Press CTRL + D, then enter to enable developer mode (It doesn't matter if it's blocked), and then ESC + ↻ + ⏻ to enter recovery mode.
9. Plug in your shim USB
If you get a screen saying "the device does not contain ChromeOS"/"no valid image" you either chose the wrong shim for your board, didn't go into developer mode, bad flash, bad file, or you've been keyrolled (and cannot continue)
10. When the shim boots, type D to select "Deprovision"
11. Next, type B to open a bash shell, this is where we'll unbrick
12. Type the following command:
gsctool -a -o
Press the power button whenever it spams "Press PP button now!" (this will take awhile) whenever it says "Another press will be required" it is telling you to wait, you may have to wait for a minute or even more.
13. Once you're at the end of that process you should reboot and you'll be back at the "Welcome!" screen. (if you don't reboot/gsctool doesn't work, proceed to the bottom section, "errors while unbricking")
14. Get back into developer mode by pressing ESC + ↻ + ⏻, then CTRL + D, then enter.
15. Either press CTRL + D if you're on a "OS verification is OFF" white screen, or enter if you're on a "You are in developer mode" black screen.
(keep this in mind if you want to stay in developer mode, you will have to do this each time you power it on)
16. You may get a "Your system is transitioning into Developer Mode" screen, wait for the 5 minute timer to finish, then follow step 15 again to boot into ChromeOS.
17. Start setting up your chromebook in OOBE by clicking Get Started, going through WiFi, and continuing. You should enroll.
18. Enter VT2 ctrl + alt + →
19. In VT2 type the following command: vpd -i RW_VPD -s check_enrollment=0
20. Powerwash or return to secure mode and once you go back through OOBE setup you should be unenrolled!
If you aren't, contact byte (check the credits for where to contact) for help.
Finding the reset times:
How to use this?
1. Powerwash (this seems unnecessary but it'll remove potential errors and make it more accurate).
2. Go to chrome://network#logs.
2. Under the options section, check all of the boxes.
You can just select the bottom 2 options if you care.
3. Place the combined-logs.tar.gz file into the dropzone in the website at the top of this file.
IF YOU SEE "Could not parse for 'Show enrollment screen", PLEASE CHECK THE ERRORS SECTION. IF ISSUES PERSIST, PLEASE DM @appleflyer FOR THIS (other issues go to byte).
4. The reset timing will appear below the dropzone.
Please report bugs to @ubyte on discord
Errors:
Q: Could not parse for 'Show enrollment screen'
A: Powerwash and try again, if you continue to see this ask for help in Titanium Network [.gg/unblock] or Copernicium>
Q: gsctool -a -o immediately exits with no output and doesn't reboot
1. Run gsctool -a -k
2. Run gsctool -a -o
Q: gsctool -a -o isn't rebooting, but you went through the pp process
1. boot into the shim
2. go into the factory install part of sh1mmer with f + enter
3. select the option corressponding to tpm reset
4. do that twice
5. boot back into the shim
6. run the following: Deprovision, Disable Dev Block, Allow booting from USB
7. open the bash terminal with b
8. run gsctool -a -k followed by gsctool -a -o
Q: still enrolling after completing the guide
1. stay in dev mode (DON'T LEAVE OR U MIGHT BE COOKED!) 2. contact byte for help lol
HELP PLEASE I'M STUCK ON STEP 8
(check website for video)
if these don't work, please report the error to @ubyte on discord
Credits:
Byte - Pioneering the development of this, making the website, and coming up with the log consistency idea.
OlyB - Found out when we were supposed to restart, all we had left was figuring out when that was.
silk - Reproducing the bug first and confirming Byte wasn't insane
Kilo - Even if he didn't reproduce, he tested SO much (literal hours), major respect to him 🫡
doxr - Existing (also cleaning up the website, don't read the source)
peap - Gave Byte logs which made it possible to reproduce (it was a whole second inaccurate before him)
appleflyer - Adding direct log archive parsing functionality for calculating timings and bytes emotional support + helping a lil :>
Windows XP - Making the guide easier to read and skid-friendly. Also a Whale Inc. member.
TNTCrazyError - That video.
Pencil Method - Unenroll by bridging pins on the motherboard.
The proper guide was created by Darkn: https://blog.darkn.bio/blog/3-the-tsunami#bypassing-instructions
!!! This can harm your Chromebook if done incorrectly. Use at your own risk. !!!
Requirements:
-> Conductive material (staple, tin foil, paperclip, etc.)
-> Scissors
-> Tape (optional, recommended)
-> USB drive or SD card with Sh1mmer flashed
-> Screwdriver corresponding to the screws of your Chromebook
Dismantling Hardware & Bridging Pins - Instructions:
1. With a screwdriver, remove each screw from the bottom of your Chromebook.
2. Disconnect the battery. The battery cable placement varies between models.
3. On the motherboard, find the 8-pin chip with pins sticking out or in. It likely has winbond or GigaDevice branding, and it may show 25Q64[xx] or 25Q128[xx] below the branding.
It may be located on the back of the motherboard.
4. Shape a piece of your conductive material long enough to connect to both sides of the chip and small enough to not make contact with multiple pins on either side of the chip.
5. Place one end of the conductive material on pin 3 (WP). [SOIC-8] [WSON-8]
6. Place the other end of the conductive material on pin 8 (VCC). [SOIC-8] [WSON-8]
7. If necessary, place tape on top of the chip to keep the conductive material on the pins. [SOIC-8] [WSON-8]
8. Connect the battery.
Performing the Exploit - Instructions:
1. Boot into Sh1mmer with the USB.
2. In the Sh1mmer menu, navigate to Utilities.
3. Select Un-Enroll Device. This is necessary even if the process fails.
4. In the Utilities menu, select Open Bash.
5. In the bash shell, run the following commands:
flashrom --wp-disable
/usr/share/vboot/bin/set_gbb_flags.sh 0x8090
If the commands fail, the pins are not bridged correctly.
6. Reboot the Chromebook by pressing Refresh ↻ + Power ⏻.
7. Press Ctrl + D to bypass the OS verification screen.
8. Boot into Chrome OS.
9. Press Ctrl + Alt + F2 to enter the VT2 shell.
10. Log in to the shell as root.
11. Run the following commands:
tpm_manager_client take_ownership
cryptohome --action=remove_firmware_management_parameters
12. Press Ctrl + Alt + F1 to exit the VT2 shell.
13. Press Ctrl+Alt+Shift+R.
14. Click Powerwash.
Credits:
Darkn | https://darkn.bio
https://chrose.netlify.app/detail/pencil%20method/ | AshtonDavies
I stole this from the community xd, i didnt create the methods