Baseband Bootrom

This is the first code that runs on the baseband.

S-Gold 2
The bootrom here is located at 0x400000. It was initially dumped using exploits in java on other S-Gold 2 phones. It allows unsigned code to be uploaded using Baseband Bootrom Protocol. On non debug variants of the chip, it requires Fakeblank to run that code

X-Gold 608
The bootrom hasn't been dumped on this chip yet. This is a vital step in searching for an unlock from boot. It is believed to be located at 0x400000 as well. It checks the signature of the bootloader in the flash.