View Single Post
Old 09-17-2009, 13:37   #5 (permalink)
ja_palma
Freak Poster
 
Join Date: Jul 2002
Location: Spain
Age: 51
Posts: 120
Member: 13716
Status: Offline
Thanks Meter: 8
Hi, I downgrade to v25, write bak rpl, and unlock.... see log:

Code:
MCU Version	V ICPR72_09w20.5
MCU Date	16-06-09
Product		RM-356
Manufacturer	(c) Nokia
IMEI		354183025283447
Mastercode	5445644022
IMEI Spare	3A45810352824304
IMEI SV		3345810352824344F3000000
PSN		CZB492346
Product Code	0559051
Basic Product Code	0578897
PSD		0000000000000000
LPSN		0
WLAN MAC	00247D390D8A
APE SW		V 30.0.011
APE Variant	V 30.0.011V 30.0.011 V 30.0.011 
APE Test		eno_version
APE HW		256
APE ADSP	256
RETU		16
TAHVO		22
AHNE		11
HW		1101
RFIC		17141715
DSP		ICPR72_09w19_1
Simlock Server	SIMLOCK SERVER
Simlock Key	2140300000000000
Simlock Profile	8000000000000000
Simlock Key Cnt	0
Simlock FBUS Cnt	0
Simlock [1,1]	State: CLOSED	Type: MCC-MNC	Data: 21403F
Scanning avaiable products...
Processing C:\Archivos de programa\Nokia\Phoenix\Products\...
Found 61 products, Filtering BB5 Products - wait...
1 Products left after filtering. Ready.
Retrieving Variants for Product RM-356 - wait...
60 Variants Retrieved
Processing pre flash tasks...
Backing up RPL...
RPL Creation started...
Processing CMT Part...
Storing Product Code...
Storing PSN...
Storing HWID...
Simlock Store not supported, not a PA_SL2 Phone
WMDRM Store not supported
Booting RAP...
CMT_SYSTEM_ASIC_ID:	 000000010000022600010006400C192101031103
CMT_EM_ASIC_ID:		 00000296
CMT_EM_ASIC_ID:		 00000B22
CMT_PUBLIC_ID:		 1080011815710052F573870A13F922C3A4DFA78C
CMT_ASIC_MODE_ID:	 00
CMT_ROOT_KEY_HASH:	 CAEEBB65D3C48E6DC73B49DC5063A2EE
CMT_ROM_ID:		 4B9B75103E691FF8
RAPIDOv11_2nd.fg, Type: 2nd Boot Loader, Rev: 0.1.37.1, Algo: BB5
Flashbus Write baud set to 1.0Mbits
Flashbus Read baud set to 98Kbits
FlashChip[0,CMT]: 0x00EC004000800121, Samsung, ONENAND
FlashContent[0,CMT]: 00000000000000000000000000000000, ONENAND
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
Transmission Mode Requested: Single Line, 8 bit, Accepted: Single Line, 8 bit
RAPIDOv11_algo.fg, Type: Algorithm, Rev: 0.1.40.0, Algo: XSR 1.5
Flashbus Write baud set to 2.0Mbits
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
Box VPP disabled
Internal CMT Phone VPP Enabled
PAPUBKEYS Hash for CMT: 76A20187051C30162EE91C77AE5E6011F5F1BA61
APE Subsystem Not Found
Flashbus Write baud set to 5.0Mbits
Storing NPC...
Storing CCC...
Storing HWC...
CMT VARIANT Not Found
Restarting MCU...
RPL Saved OK
RPL backup thread finished, continuing...
Backing up simlock...
MCU Version	V ICPR72_09w20.5
MCU Date	16-06-09
Product		RM-356
Manufacturer	(c) Nokia
IMEI		354183025283447
Mastercode	5445644022
Simlock backup OK, saved to RM-356_354183025283447_17092009_141954.SLBackup.PM
Backup simlock thread finished, continuing...
Pre flash tasks finished, continuing...
Processing RM-356_21.0.025_prd.core.C00 (CMT)...
Booting RAP...
CMT_SYSTEM_ASIC_ID:	 000000010000022600010006400C192101031103
CMT_EM_ASIC_ID:		 00000296
CMT_EM_ASIC_ID:		 00000B22
CMT_PUBLIC_ID:		 1080011815710052F573870A13F922C3A4DFA78C
CMT_ASIC_MODE_ID:	 00
CMT_ROOT_KEY_HASH:	 CAEEBB65D3C48E6DC73B49DC5063A2EE
CMT_ROM_ID:		 4B9B75103E691FF8
RM-356_21.0.025_prd.core.C00, Type: Flash Image, Algo: XSR 1.5, BB5
RAPIDOv11_2nd.fg, Type: 2nd Boot Loader, Rev: 0.1.37.1, Algo: BB5
Flashbus Write baud set to 650Kbits
Flashbus Read baud set to 98Kbits
FlashChip[0,CMT]: 0x00EC004000800121, Samsung, ONENAND
FlashContent[0,CMT]: 00000000000000000000000000000000, ONENAND
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
Transmission Mode Requested: Single Line, 8 bit, Accepted: Single Line, 8 bit
RAPIDOv11_algo.fg, Type: Algorithm, Rev: 0.1.40.0, Algo: XSR 1.5
Flashbus Write baud set to 2.0Mbits
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
Box VPP disabled
Internal CMT Phone VPP Enabled
PAPUBKEYS Hash for CMT: 76A20187051C30162EE91C77AE5E6011F5F1BA61
Flashbus Write baud set to 5.0Mbits
Sending Certificates...
Certificates OK
Partitioning...
Partitioning OK
Started group flash erase
EraseArea[0,CMT]: 0x00040000-0x00082FFF, ONENAND
EraseArea[0,CMT]: 0x00083400-0x003FFFFF, ONENAND
EraseArea[0,CMT]: 0x00400000-0x007FFFFF, ONENAND
EraseArea[0,CMT]: 0x00800000-0x00D5FFFF, ONENAND
EraseArea[0,CMT]: 0x00D60000-0x09E5FFFF, ONENAND
Erase Partition (CMT)
Waiting 320s for erasure finish...
Erase taken 0.875s
Writing all blocks...
Writing CMT ADA Certificate...
Writing CMT KEYS Certificate...
Writing CMT PRIMAPP Certificate...
Writing CMT RAP3NAND Certificate...
Writing CMT PASUBTOC Certificate...
Writing CMT PAPUBKEYS Certificate...
Writing CMT SOS*UPDAPP Certificate...
Writing CMT SOS*ENO Certificate...
Writing CMT SOS*DSP0 Certificate...
Writing CMT SOS*ISASW Certificate...
Writing CMT SOS+CORE Certificate...
Writing CMT SOS+ROFS1 Certificate...
Programming Status OK!
All blocks written OK! Time taken 124.828s
Restarting MCU...
Processing RM-356_21.0.025_prd.core.C00 (APE)...
Processing RM-356_21.0.025_prd.rofs2.V09 (CMT)...
Booting RAP...
CMT_SYSTEM_ASIC_ID:	 000000010000022600010006400C192101031103
CMT_EM_ASIC_ID:		 00000296
CMT_EM_ASIC_ID:		 00000B22
CMT_PUBLIC_ID:		 1080011815710052F573870A13F922C3A4DFA78C
CMT_ASIC_MODE_ID:	 00
CMT_ROOT_KEY_HASH:	 CAEEBB65D3C48E6DC73B49DC5063A2EE
CMT_ROM_ID:		 4B9B75103E691FF8
RM-356_21.0.025_prd.rofs2.V09, Type: Flash Image, Algo: XSR 1.5, BB5
RAPIDOv11_2nd.fg, Type: 2nd Boot Loader, Rev: 0.1.37.1, Algo: BB5
Flashbus Write baud set to 650Kbits
Flashbus Read baud set to 98Kbits
FlashChip[0,CMT]: 0x00EC004000800121, Samsung, ONENAND
FlashContent[0,CMT]: 00000000000000000000000000000000, ONENAND
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
Transmission Mode Requested: Single Line, 8 bit, Accepted: Single Line, 8 bit
RAPIDOv11_algo.fg, Type: Algorithm, Rev: 0.1.40.0, Algo: XSR 1.5
Flashbus Write baud set to 2.0Mbits
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
Box VPP disabled
Internal CMT Phone VPP Enabled
PAPUBKEYS Hash for CMT: 76A20187051C30162EE91C77AE5E6011F5F1BA61
Flashbus Write baud set to 5.0Mbits
Started group flash erase
EraseArea[0,CMT]: 0x06560000-0x0915FFFF, ONENAND
Waiting 320s for erasure finish...
Erase taken 0.234s
Writing all blocks...
Writing CMT SOS+ROFS2 Certificate...
Programming Status OK!
All blocks written OK! Time taken 44.625s
Restarting MCU...
Processing RM-356_21.0.025_prd.rofs2.V09 (APE)...
Processing RM-356_21.0.025_C01_prd.rofs3.fpsx (CMT)...
Booting RAP...
CMT_SYSTEM_ASIC_ID:	 000000010000022600010006400C192101031103
CMT_EM_ASIC_ID:		 00000296
CMT_EM_ASIC_ID:		 00000B22
CMT_PUBLIC_ID:		 1080011815710052F573870A13F922C3A4DFA78C
CMT_ASIC_MODE_ID:	 00
CMT_ROOT_KEY_HASH:	 CAEEBB65D3C48E6DC73B49DC5063A2EE
CMT_ROM_ID:		 4B9B75103E691FF8
RM-356_21.0.025_C01_prd.rofs3.fpsx, Type: Flash Image, Algo: XSR 1.5, BB5
RAPIDOv11_2nd.fg, Type: 2nd Boot Loader, Rev: 0.1.37.1, Algo: BB5
Flashbus Write baud set to 650Kbits
Flashbus Read baud set to 98Kbits
FlashChip[0,CMT]: 0x00EC004000800121, Samsung, ONENAND
FlashContent[0,CMT]: 00000000000000000000000000000000, ONENAND
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
Transmission Mode Requested: Single Line, 8 bit, Accepted: Single Line, 8 bit
RAPIDOv11_algo.fg, Type: Algorithm, Rev: 0.1.40.0, Algo: XSR 1.5
Flashbus Write baud set to 2.0Mbits
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
Box VPP disabled
Internal CMT Phone VPP Enabled
PAPUBKEYS Hash for CMT: 76A20187051C30162EE91C77AE5E6011F5F1BA61
Flashbus Write baud set to 5.0Mbits
Started group flash erase
EraseArea[0,CMT]: 0x09160000-0x09E5FFFF, ONENAND
Waiting 320s for erasure finish...
Erase taken 0.78s
Writing all blocks...
Writing CMT SOS+ROFS3 Certificate...
Programming Status OK!
All blocks written OK! Time taken 1.844s
Restarting MCU...
Processing RM-356_21.0.025_C01_prd.rofs3.fpsx (APE)...
Processing RM356_20.0.010_008_xxx_U01.uda.fpsx (CMT)...
Booting RAP...
CMT_SYSTEM_ASIC_ID:	 000000010000022600010006400C192101031103
CMT_EM_ASIC_ID:		 00000296
CMT_EM_ASIC_ID:		 00000B22
CMT_PUBLIC_ID:		 1080011815710052F573870A13F922C3A4DFA78C
CMT_ASIC_MODE_ID:	 00
CMT_ROOT_KEY_HASH:	 CAEEBB65D3C48E6DC73B49DC5063A2EE
CMT_ROM_ID:		 4B9B75103E691FF8
RM356_20.0.010_008_xxx_U01.uda.fpsx, Type: Flash Image, Algo: XSR 1.5, BB5
RAPIDOv11_2nd.fg, Type: 2nd Boot Loader, Rev: 0.1.37.1, Algo: BB5
Flashbus Write baud set to 650Kbits
Flashbus Read baud set to 98Kbits
FlashChip[0,CMT]: 0x00EC004000800121, Samsung, ONENAND
FlashContent[0,CMT]: 00000000000000000000000000000000, ONENAND
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
Transmission Mode Requested: Single Line, 8 bit, Accepted: Single Line, 8 bit
RAPIDOv11_algo.fg, Type: Algorithm, Rev: 0.1.40.0, Algo: XSR 1.5
Flashbus Write baud set to 2.0Mbits
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
Box VPP disabled
Internal CMT Phone VPP Enabled
PAPUBKEYS Hash for CMT: 76A20187051C30162EE91C77AE5E6011F5F1BA61
Flashbus Write baud set to 5.0Mbits
Started group flash erase
EraseArea[0,CMT]: 0x09E60000-0x0F71FFFF, ONENAND
Waiting 320s for erasure finish...
Erase taken 0.468s
Writing all blocks...
Programming Status OK!
All blocks written OK! Time taken 7.188s
Restarting MCU...
Processing RM356_20.0.010_008_xxx_U01.uda.fpsx (APE)...
All images processed OK! Processing post flash tasks...
Reading info...
MCU Version	V ICPR72_09w06.2
MCU Date	03-03-09
Product		RM-356
Manufacturer	(c) Nokia
IMEI		354183025283447
Mastercode	5445644022
IMEI Spare	3A45810352824304
IMEI SV		3345810352824344F1000000
CNT		v 20.0.010_008_xxx_U01, 21-01-09, vanilla, RM356
PSN		CZB492346
Product Code	0559051
Basic Product Code	0578897
PSD		0000000000000000
LPSN		0
WLAN MAC	00247D390D8A
APE SW		V 21.0.025
APE Variant	V 21.0.025V 21.0.025 V 21.0.025 
APE Test		eno_version
APE HW		256
APE ADSP	256
RETU		16
TAHVO		22
AHNE		11
HW		1101
RFIC		17141715
DSP		tube_ICPR72_09w06_p1
Failed to read info -> Failed to read SP info
Read info thread finished, continuing...
Post flash tasks finished!
Flashing successfully finished!
Skipping RPL decryption...
Parsing decrypted RPL...
Processing FBUS Part...
Writing Product Code... 
Writing PSN... 
Writing HWID... 
Processing FLASHBUS Part...
Booting RAP...
CMT_SYSTEM_ASIC_ID:	 000000010000022600010006400C192101031103
CMT_EM_ASIC_ID:		 00000296
CMT_EM_ASIC_ID:		 00000B22
CMT_PUBLIC_ID:		 1080011815710052F573870A13F922C3A4DFA78C
CMT_ASIC_MODE_ID:	 00
CMT_ROOT_KEY_HASH:	 CAEEBB65D3C48E6DC73B49DC5063A2EE
CMT_ROM_ID:		 4B9B75103E691FF8
RAPIDOv11_2nd.fg, Type: 2nd Boot Loader, Rev: 0.1.37.1, Algo: BB5
Flashbus Write baud set to 1.0Mbits
Flashbus Read baud set to 98Kbits
FlashChip[0,CMT]: 0x00EC004000800121, Samsung, ONENAND
FlashContent[0,CMT]: 00000000000000000000000000000000, ONENAND
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
Transmission Mode Requested: Single Line, 8 bit, Accepted: Single Line, 8 bit
RAPIDOv11_algo.fg, Type: Algorithm, Rev: 0.1.40.0, Algo: XSR 1.5
Flashbus Write baud set to 2.0Mbits
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
Box VPP disabled
Internal CMT Phone VPP Enabled
PAPUBKEYS Hash for CMT: 76A20187051C30162EE91C77AE5E6011F5F1BA61
APE Subsystem Not Found
Flashbus Write baud set to 5.0Mbits
CMT NPC Erased
CMT NPC Written
CMT HWC Erased
CMT HWC Written
CMT CCC Erased
CMT CCC Written
Restarting MCU...
Processing FBUS Part...
Writing Product Code... 
Writing PSN... 
Writing HWID... 
Processing FLASHBUS Part...
Booting RAP...
CMT_SYSTEM_ASIC_ID:	 000000010000022600010006400C192101031103
CMT_EM_ASIC_ID:		 00000296
CMT_EM_ASIC_ID:		 00000B22
CMT_PUBLIC_ID:		 1080011815710052F573870A13F922C3A4DFA78C
CMT_ASIC_MODE_ID:	 00
CMT_ROOT_KEY_HASH:	 CAEEBB65D3C48E6DC73B49DC5063A2EE
CMT_ROM_ID:		 4B9B75103E691FF8
RAPIDOv11_2nd.fg, Type: 2nd Boot Loader, Rev: 0.1.37.1, Algo: BB5
Flashbus Write baud set to 1.0Mbits
Flashbus Read baud set to 98Kbits
FlashChip[0,CMT]: 0x00EC004000800121, Samsung, ONENAND
FlashContent[0,CMT]: 00000000000000000000000000000000, ONENAND
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
Transmission Mode Requested: Single Line, 8 bit, Accepted: Single Line, 8 bit
RAPIDOv11_algo.fg, Type: Algorithm, Rev: 0.1.40.0, Algo: XSR 1.5
Flashbus Write baud set to 2.0Mbits
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
Box VPP disabled
Internal CMT Phone VPP Enabled
PAPUBKEYS Hash for CMT: 76A20187051C30162EE91C77AE5E6011F5F1BA61
APE Subsystem Not Found
Flashbus Write baud set to 5.0Mbits
CMT NPC Erased
CMT NPC Written
CMT HWC Erased
CMT HWC Written
CMT CCC Erased
CMT CCC Written
Restarting MCU...
Write RPL Finished!
MCU Version	V ICPR72_09w06.2
MCU Date	03-03-09
Product		RM-356
Manufacturer	(c) Nokia
IMEI		354183025283447
Mastercode	5445644022
IMEI Spare	3A45810352824304
IMEI SV		3345810352824344F1000000
CNT		v 20.0.010_008_xxx_U01, 21-01-09, vanilla, RM356
Product Code	0559051
Basic Product Code	0578897
PSD		0000000000000000
LPSN		0
WLAN MAC	00247D390D8A
APE SW		V 21.0.025
APE Variant	V 21.0.025V 21.0.025 V 21.0.025 
APE Test		eno_version
APE HW		256
APE ADSP	256
RETU		16
TAHVO		22
AHNE		11
HW		0559
RFIC		17141715
DSP		tube_ICPR72_09w06_p1
Failed to read info -> Failed to read SP info
BB5 Unlock Started...
MCU Version	V ICPR72_09w06.2
MCU Date	03-03-09
Product		RM-356
Manufacturer	(c) Nokia
IMEI		354183025283447
Mastercode	5445644022
Warning: Failed to read SP Info, Assuming defaults
Simlock Server	SIMLOCK SERVER
Simlock Key	2140300000000000
Simlock Profile	8000000000000000
Simlock Key Cnt	0
Simlock FBUS Cnt	0
Reading Security Block...
Security block OK!
Determining PA Simlock...
Booting RAP...
CMT_SYSTEM_ASIC_ID:	 000000010000022600010006400C192101031103
CMT_EM_ASIC_ID:		 00000296
CMT_EM_ASIC_ID:		 00000B22
CMT_PUBLIC_ID:		 1080011815710052F573870A13F922C3A4DFA78C
CMT_ASIC_MODE_ID:	 00
CMT_ROOT_KEY_HASH:	 CAEEBB65D3C48E6DC73B49DC5063A2EE
CMT_ROM_ID:		 4B9B75103E691FF8
RAPIDOv11_2nd.fg, Type: 2nd Boot Loader, Rev: 0.1.37.1, Algo: BB5
Flashbus Write baud set to 1.0Mbits
Flashbus Read baud set to 98Kbits
FlashChip[0,CMT]: 0x00EC004000800121, Samsung, ONENAND
FlashContent[0,CMT]: 00000000000000000000000000000000, ONENAND
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
Transmission Mode Requested: Single Line, 8 bit, Accepted: Single Line, 8 bit
RAPIDOv11_algo.fg, Type: Algorithm, Rev: 0.1.40.0, Algo: XSR 1.5
Flashbus Write baud set to 2.0Mbits
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
Box VPP disabled
Internal CMT Phone VPP Enabled
PAPUBKEYS Hash for CMT: 76A20187051C30162EE91C77AE5E6011F5F1BA61
APE Boot skipped on user request
Flashbus Write baud set to 5.0Mbits
Restarting MCU...
Determined PA Simlock: PA_SL2
Checking for Rootkey Hash support...
Booting RAP...
CMT_SYSTEM_ASIC_ID:	 000000010000022600010006400C192101031103
CMT_EM_ASIC_ID:		 00000296
CMT_EM_ASIC_ID:		 00000B22
CMT_PUBLIC_ID:		 1080011815710052F573870A13F922C3A4DFA78C
CMT_ASIC_MODE_ID:	 00
CMT_ROOT_KEY_HASH:	 CAEEBB65D3C48E6DC73B49DC5063A2EE
CMT_ROM_ID:		 4B9B75103E691FF8
RAPIDOv11_2nd.fg, Type: 2nd Boot Loader, Rev: 0.1.30.0, Algo: BB5
Flashbus Write baud set to 1.0Mbits
Flashbus Read baud set to 98Kbits
Exploiting - running preloader...
Preloader running OK, Running Custom Loader...
Custom loader running OK! Working...
BB5 Unlock Failed -> Failed to get Lock Key (6, 5)
please help

Last edited by acyl2000; 11-09-2009 at 11:26. Reason: wrap [code]
 
The Following User Says Thank You to ja_palma For This Useful Post:
 
Page generated in 0.12573 seconds with 7 queries