The Fire TV Stick has been rooted by directly interfacing with the device’s 8GB eMMC storage chip. This is a hardware root that involves soldering leads to specific points on the Fire TV Stick’s circuit board; not a software root like we had with towelroot on the original Amazon Fire TV. Due to the complexity and skill involved, it is unlikely that many people will replicate this rooting procedure.
The guys over at GTVHacker have posted details about this rooting method and a video demonstrating the procedure. The process involves soldering connections between the Fire TV Sticks 8GB eMMC storage chip and an SD sniffer board. This then allows you to mount the Fire TV Stick’s file system on a computer using a standard SD card reader. Once the file system is directly accessible via the SD card reader, you simply copy an SU binary file to the Fire TV Stick file system and set the appropriate permissions.
As I already mentioned, most people won’t be attempting to reproduce this method. However, achieving root in any form is great news as it may lead to a software root being discovered.
Is it possible to post on how to for programming? Connection is straight forward. Thank you
Is this a repeatable thing, or is this like the AFTV where no one else can repeat what they did?
looks like nothing to program…
solder up the sniffer, mount the filesystem like any SD card, drop SU on the filesystem…. profit!
The pinouts are posted, that’s all you need.
Not being a proficient Android hacker, what do you mean by “drop SU on the filesystem”?
Copy the SU binary onto the firetv internal memory chip.
A basic understanding of linux and android is required. It looks like this is an outline of the commands.. It looks like you can use the below commands:
./adb push su/system/bin/su /sdcard/su
cat /sdcard/su > /system/xbin/su
ln -s /system/xbin/su /system/bin/su
chmod 6755 /system/xbin/su
not sure if those are exact, but you get the idea.
This would be my preferable method. I do love hardware hacking, any excuse the break out the soldering iron!
Nice work on finding the pinout!
Is this also doable on an unrootable AFTV?
Yes I’m very interested in this method on the firetv box. Great job guys!
They are not using the SD sniffer board pictured here. They are using a Low Voltage e-MMC Adapter. If a SD sniffer will work please provide the information for that. Thanks
So, with this method, I could allow any updates Amazon pushes out and still re-root it?
Yes, pretty much.
So does this method work with the SD Sniffer board in the post?
I would like to know if the SD Sniffer board will work too since I cannot seem to find a VCCQ or D4 points on it.
Id like to know this too, the SD sniffer board doesn’t have a VCCQ or D4 points on it.
where would the VCCQ and D4 wires go into the SD sniffer board?
Exactly, no Vccq and D4.
They may want to pull the image and link.
I know someone out there, other than myself, has ordered the SD Sniffer board because of this post. (which my own fault, for just skimming through the original post, from the source of the topic)
It Seems like a simple straight forward project, so I just overlooked the difference in the board.
I’ve removed the old board reference.
Same here, now I need to find a use for the SD sniffer board lol.
hopefully maximus64 will get some of his Low Voltage e-MMC Adapters in stock soon.
Surprised the chinese have not made a FireTV stick rooter that does not require soldering like the old xbox mods using a jig of some sort and spring loaded pins.
Unfortunately this isn’t like the old days of J-tagging a satellite receiver where the pins could be the size of small nails…. The soldering points on this smt board are small! A spring loaded pin device would never come close to cutting it!
im sorry but the soldering on this is simple.
if u can solder then break out your tools and have some fun.
Can this still be done with the latest update 18.104.22.168_user_110041020 …
or does software ver. not matter for this root method?
The Fire Stick can not being used with a DVI Adapter….
because of the hardware handshake (hdcp).
(see: http://amzn.to/1O5CNI7 )
Is it possible with the rooting to make this working?
How does the D0-D4 and VCC map to the breakout board? I assume the clk and cmd pins are being mapped to D0-D4? There is no 5-bit mode so there is no way D0-D4 is all data lines. I tried looking for a cross reference but nothing is matching this pin out? Any ideas how the picture above maps to the Exploitee.rs Low Voltage eMMC Adapter?
Also, the part when you connect to gnd the cpu is that achieved with the gnd on the eMMC or it has to be gnd on the fire stick? if is the last, Where can we get the gnd on the fire stick? ?
On either of 4 soder joints of usb power port,I’m assuming.
Interesting. Have a Fire TV stick at home. May give it a try.