diff --git a/Radius-PowerView-Commands.md b/Radius-PowerView-Commands.md index 11626f6..87da39b 100644 --- a/Radius-PowerView-Commands.md +++ b/Radius-PowerView-Commands.md @@ -125,6 +125,10 @@ C9 comes repeatedly during a long spurt at startup. Command: `CA 00 00 00 00 50 01 E0 00 00 00` Function: ***Unknown at this time*** +Currently guessing that this updates the framebuffer. +- The messages come at different sizes. Some huge, some tiny. +- Where I *think* the screensaver was showing the screensaver (Pyro fireworks), it was sending mostly FFFFFFF, with a few zeros sprinkled throughout. +- I also think that a huge buffer of all F's was sent (approximately size 96D7 bytes). This happens to be approximately (640x480)/8 bits (with one bit color) Type: XXXXInput (Transitions to DATAOUT) @@ -188,6 +192,91 @@ Data out: 10: 5555AAAA 5555AAAA 5555AAAA 5555AAAA ``` +Command: `CA 00 D3 94 00 0E 00 64 00 84 00` +Dataout: +``` +00: FFFFFFFF FFFFFFFF FFFFFFFF FFFFFFFF +10: FFFFFFFF FFFFFFFF FFFFFFFF FFFFFFFF +20: FFFFFFFF FFFFFFFF FFFFFFFF FFFFFFFF +30: FFFFFFFF FFFFFFFF FFFFFFFF FFFFFFFF +40: FFFFFFFF FFFFFFFF FFFFFFFF FFFFFFFF +50: FFFFFFFF FFFFFFFF FFFFFFFF FFFFFFFF +60: FFFFFFFF FFFFFFFF FFFFFFFF FFFFFFFF +70: FFFFFFFF FFFFFF7F FFFFFFFF FFFFFFFF +... +// There were some non-FF fields in this data +... +520: FFFFFFFF FFFFFFFF FFFFFFFF FFFFFFFF +530: FFFFFFFF FFFFFFFF FFFFFFFF FFFFFFFF +540: FFFFFFFF FFFFFFFF FFFFFFFF FFFFFFFF +550: FFFFFFFF FFFFFFFF FFFFFFFF FFFFFFFF +560: FFFFFFFF FFFFFFFF FFFFFFFF FFFFFFFF +570: FFFFFFFF FFFFFFFF FFFF +``` + +Command: `CA 00 00 00 00 50 01 E0 00 00 00` +Dataout: (Note that 640x480/8 = 38400 = 0x9600) +``` +00: FFFFFFFF FFFFFFFF FFFFFFFF FFFFFFFF +10: FFFFFFFF FFFFFFFF FFFFFFFF FFFFFFFF +... +96C0: FFFFFFFF FFFFFFFF FFFFFFFF FFFFFFFF +96D0: FFFFFFFF FFFFFF +``` +*This block was mostly 0xFF. There were a couple non-FF values, but those could have been hiccups with the capture software* + + + +Lots of udpates.... +Command: `CA011AE6 00020003 009C00` +Dataout: `FE7FFF3F FF3F` + +Command: `CA011EA8 00010003 009E00` +Dataout: `FFFFFF` + +Command: `CA011A46 00020002 009C00` +Dataout: `FE7FFE7F` + +Command: `CA011D68 00010003 009E00` +Dataout: `FFFFFF` + +Command: `CA011906 00020003 009C00` +Dataout: `FE7FFE7F FE7F` + +Command: `CA011C28 00010003 009E00` +Dataout: `FFFFFF` + +Command: `CA0117C6 00020003 009C00` +Dataout: `FE7FFE7F FE7F` + +Command: `CA011AE6 00020003 009C00` +Dataout: `FFFFFFFF FFFF` + +Command: `CA011686 00020003 009C00` +Dataout: `FE7FFE7F FE7F` + +Command: `CA011A46 00020002 009C00` +Dataout: `FFFFFFFF` + +Command: `CA0115E6 00020002 009C00` +Dataout: `FE7FFE7F` + + + + + + + + + +### Work +Guess: `CA
. +Command: `CA 00 00 00 00 50 01 E0` - Size: 96C0 +Command: `CA 00 00 00 00 50 01 E0` - Size: 96B4 +Command: `CA 00 00 00 00 02 00 10 00 9C 00` - Size: 0020 +Command: `CA 00 D3 94 00 0E 00 64 00 84 00` - Size: 57A0 +Command: `CA 00 00 00 00 50 01 E0 00 00 00` - Size: 96D7 + ## **UNKNOWN** (CB) Command: CB 00 00 00 01 00