View Single Post
Old 12-03-2009, 17:21   #1 (permalink)
ronzinio
Insane Poster
 
Join Date: Jul 2005
Location: London, UK
Age: 38
Posts: 91
Member: 164504
Status: Offline
Thanks Meter: 17
Nokia E71 Unlock Failed - BB5 Unlock Failed -> Failed to get Lock Key (6, 5)

Hi guys,

Got one E71 in today which I needed to debrand and Unlock. Started for flashing the handset with the Generic software which worked fine. Handset was originally on the 3 network.

But, when I went to Unlock it afterwards, the phone generated the error "BB5 Unlock Failed -> Failed to get Lock Key (6, 5)".

I have since downgraded the phone back to sw: 100.07.76 but still the handset won't unlocked and now, the original 3 sim card is not valid in the phone.

Can someone help me please? Log is below.


Code:
Processing pre flash tasks...
Backing up RPL...
RPL Creation started...
Processing CMT Part...
Storing Product Code...
Storing PSN...
Storing HWID...
Trying to store Simlock...
Reading Configuration Key...
Hashing...
Reading SHA1-RSA Signature...
Reading SHA1-HMAC Signature...
Storing Simlock...
Trying to store WMDRM RPL...
Reading Keys...
Storing WMDRM PD...
Booting RAP...
CMT_SYSTEM_ASIC_ID:	 000000010000022600010006400C192101031103
CMT_EM_ASIC_ID:		 00000296
CMT_EM_ASIC_ID:		 00000B22
CMT_PUBLIC_ID:		 0CD0000428318B52D0432B802A4F4B44F47906D1
CMT_ASIC_MODE_ID:	 00
CMT_ROOT_KEY_HASH:	 CAEEBB65D3C48E6DC73B49DC5063A2EE
CMT_ROM_ID:		 4B9B75103E691FF8
RAPIDOv11_2nd.fg, Type: 2nd Boot Loader, Rev: 0.1.37.1, Algo: BB5
Flashbus Write baud set to 1.0Mbits
Flashbus Read baud set to 98Kbits
FlashChip[0,CMT]: 0x00EC004000800121, Samsung, ONENAND
FlashContent[0,CMT]: 00000000000000000000000000000000, ONENAND
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
Transmission Mode Requested: Single Line, 8 bit, Accepted: Single Line, 8 bit
RAPIDOv11_algo.fg, Type: Algorithm, Rev: 0.1.40.0, Algo: XSR 1.5
Flashbus Write baud set to 2.0Mbits
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
Box VPP disabled
Internal CMT Phone VPP Enabled
PAPUBKEYS Hash for CMT: 52570A2086C79E6965175815B5388535CDD5C6F7
APE Subsystem Not Found
Flashbus Write baud set to 5.0Mbits
Storing NPC...
Storing CCC...
Storing HWC...
CMT VARIANT Not Found
Restarting MCU...
RPL Saved OK
RPL backup thread finished, continuing...
Backing up simlock...
MCU Version	V ICPR71_08w44.2
MCU Date	19-11-08
Product		RM-346
Manufacturer	(c) Nokia
IMEI		358240030057483
Mastercode	446233637
Simlock backup OK, saved to RM-346_358240030057483_03122009_160503.SLBackup.PM
Backup simlock thread finished, continuing...
Applying downgrade patch...
Downgrade patch OK!
Pre flash tasks finished, continuing...
Processing rm346_100.07.76_prd.c00 (CMT)...
Booting RAP...
CMT_SYSTEM_ASIC_ID:	 000000010000022600010006400C192101031103
CMT_EM_ASIC_ID:		 00000296
CMT_EM_ASIC_ID:		 00000B22
CMT_PUBLIC_ID:		 0CD0000428318B52D0432B802A4F4B44F47906D1
CMT_ASIC_MODE_ID:	 00
CMT_ROOT_KEY_HASH:	 CAEEBB65D3C48E6DC73B49DC5063A2EE
CMT_ROM_ID:		 4B9B75103E691FF8
rm346_100.07.76_prd.c00, Type: Flash Image, Algo: BB5, XSR 1.5
RAPIDOv11_2nd.fg, Type: 2nd Boot Loader, Rev: 0.1.37.1, Algo: BB5
Flashbus Write baud set to 650Kbits
Flashbus Read baud set to 98Kbits
FlashChip[0,CMT]: 0x00EC004000800121, Samsung, ONENAND
FlashContent[0,CMT]: 00000000000000000000000000000000, ONENAND
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
Transmission Mode Requested: Single Line, 8 bit, Accepted: Single Line, 8 bit
RAPIDOv11_algo.fg, Type: Algorithm, Rev: 0.1.40.0, Algo: XSR 1.5
Flashbus Write baud set to 2.0Mbits
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
Box VPP disabled
Internal CMT Phone VPP Enabled
PAPUBKEYS Hash for CMT: 52570A2086C79E6965175815B5388535CDD5C6F7
Flashbus Write baud set to 5.0Mbits
Sending Certificates...
Certificates OK
Partitioning...
Partitioning OK
Started group flash erase
EraseArea[0,CMT]: 0x00040000-0x007FFFFF, ONENAND
EraseArea[0,CMT]: 0x00A00000-0x0759FFFF, ONENAND
EraseArea[0,CMT]: 0x0F1C0000-0x0F8BFFFF, ONENAND
Erase Partition (CMT)
Erase Partition (CMT)
Erase Partition (CMT)
Waiting 320s for erasure finish...
Erase taken 0.843s
Writing all blocks...
Writing CMT ADA Certificate...
Writing CMT KEYS Certificate...
Writing CMT PRIMAPP Certificate...
Writing CMT RAP3NAND Certificate...
Writing CMT PASUBTOC Certificate...
Writing CMT PAPUBKEYS Certificate...
Writing CMT SOS*UPDAPP Certificate...
Writing CMT SOS*DSP0 Certificate...
Writing CMT SOS*ISASW Certificate...
Writing CMT SOS*CORE Certificate...
Writing CMT SOS+ROFS Certificate...
Programming Status OK!
All blocks written OK! Time taken 106.984s
Restarting MCU...
Processing rm346_100.07.76_prd.c00 (APE)...
Processing rm346_100.07.76_prd.v01 (CMT)...
Booting RAP...
CMT_SYSTEM_ASIC_ID:	 000000010000022600010006400C192101031103
CMT_EM_ASIC_ID:		 00000296
CMT_EM_ASIC_ID:		 00000B22
CMT_PUBLIC_ID:		 0CD0000428318B52D0432B802A4F4B44F47906D1
CMT_ASIC_MODE_ID:	 00
CMT_ROOT_KEY_HASH:	 CAEEBB65D3C48E6DC73B49DC5063A2EE
CMT_ROM_ID:		 4B9B75103E691FF8
rm346_100.07.76_prd.v01, Type: Flash Image, Algo: BB5, XSR 1.5
RAPIDOv11_2nd.fg, Type: 2nd Boot Loader, Rev: 0.1.37.1, Algo: BB5
Flashbus Write baud set to 650Kbits
Flashbus Read baud set to 98Kbits
FlashChip[0,CMT]: 0x00EC004000800121, Samsung, ONENAND
FlashContent[0,CMT]: 00000000000000000000000000000000, ONENAND
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
Transmission Mode Requested: Single Line, 8 bit, Accepted: Single Line, 8 bit
RAPIDOv11_algo.fg, Type: Algorithm, Rev: 0.1.40.0, Algo: XSR 1.5
Flashbus Write baud set to 2.0Mbits
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
Box VPP disabled
Internal CMT Phone VPP Enabled
PAPUBKEYS Hash for CMT: 52570A2086C79E6965175815B5388535CDD5C6F7
Flashbus Write baud set to 5.0Mbits
Started group flash erase
EraseArea[0,CMT]: 0x05420000-0x0759FFFF, ONENAND
Erase Partition (CMT)
Waiting 320s for erasure finish...
Erase taken 0.312s
Writing all blocks...
Writing CMT SOS+ROFX Certificate...
Programming Status OK!
All blocks written OK! Time taken 50.531s
Restarting MCU...
Processing rm346_100.07.76_prd.v01 (APE)...
Processing rm346_100.07.76.02U (CMT)...
Booting RAP...
CMT_SYSTEM_ASIC_ID:	 000000010000022600010006400C192101031103
CMT_EM_ASIC_ID:		 00000296
CMT_EM_ASIC_ID:		 00000B22
CMT_PUBLIC_ID:		 0CD0000428318B52D0432B802A4F4B44F47906D1
CMT_ASIC_MODE_ID:	 00
CMT_ROOT_KEY_HASH:	 CAEEBB65D3C48E6DC73B49DC5063A2EE
CMT_ROM_ID:		 4B9B75103E691FF8
rm346_100.07.76.02U, Type: Flash Image, Algo: BB5, XSR 1.5
RAPIDOv11_2nd.fg, Type: 2nd Boot Loader, Rev: 0.1.37.1, Algo: BB5
Flashbus Write baud set to 650Kbits
Flashbus Read baud set to 98Kbits
FlashChip[0,CMT]: 0x00EC004000800121, Samsung, ONENAND
FlashContent[0,CMT]: 00000000000000000000000000000000, ONENAND
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
Transmission Mode Requested: Single Line, 8 bit, Accepted: Single Line, 8 bit
RAPIDOv11_algo.fg, Type: Algorithm, Rev: 0.1.40.0, Algo: XSR 1.5
Flashbus Write baud set to 2.0Mbits
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
Box VPP disabled
Internal CMT Phone VPP Enabled
PAPUBKEYS Hash for CMT: 52570A2086C79E6965175815B5388535CDD5C6F7
Flashbus Write baud set to 5.0Mbits
Started group flash erase
Erase Partition (CMT)
Waiting 320s for erasure finish...
Erase taken 1.328s
Writing all blocks...
Programming Status OK!
All blocks written OK! Time taken 10.969s
Restarting MCU...
Processing rm346_100.07.76.02U (APE)...
All images processed OK! Processing post flash tasks...
Reading info...
MCU Version	V 100.71.821.4
MCU Date	06-06-08
Product		RM-346
Manufacturer	(c) Nokia
IMEI		358240030057483
Mastercode	446233637
IMEI Spare	3A85420003504708
IMEI SV		3385420003504708F1000000
PPM		100.07.76j100.07.76100.07.76_v01kRM346ENO7411718214.N32n256o256¥0(100.07.76, 08-06-2008, RM-346, (c)Nokia , 
PSN		MGE493049
Product Code	0569999
Basic Product Code	0552256
PSD		0000000000000000
LPSN		0
WLAN MAC	1886AC7E61EC
APE SW		100.07.76
APE Variant	100.07.76100.07.76_v01
APE Test		RM346ENO7411718214.N32
APE HW		256
APE ADSP	256
RETU		16
TAHVO		22
AHNE		11
HW		0912i, 100.07.76j100.07.76100.07.76_v01kRM346ENO7411718214.N32n256o256¥0(100.07.76, 08-06-2008, RM-346, (c)Nokia , 
PCI		i, 100.07.76j100.07.76100.07.76_v01kRM346ENO7411718214.N32n256o256¥0(100.07.76, 08-06-2008, RM-346, (c)Nokia , 
UEM		100.07.76j100.07.76100.07.76_v01kRM346ENO7411718214.N32n256o256
UPP		100.07.76j100.07.76100.07.76_v01kRM346ENO7411718214.N32n256o256
RFIC		17141715
DSP		L07w15PB_08w20i, 100.07.76j100.07.76100.07.76_v01kRM346ENO7411718214.N32n256o256
LCD		100.07.76j100.07.76100.07.76_v01kRM346ENO7411718214.N32n256o256¥0(100.07.76, 08-06-2008, RM-346, (c)Nokia , 
BT		100.07.76j100.07.76100.07.76_v01kRM346ENO7411718214.N32n256o256¥0(100.07.76, 08-06-2008, RM-346, (c)Nokia , 
ADSP Sw		100.07.76j100.07.76100.07.76_v01kRM346ENO7411718214.N32n256o256¥0(100.07.76, 08-06-2008, RM-346, (c)Nokia , 
ADSP DevID		100.07.76j100.07.76100.07.76_v01kRM346ENO7411718214.N32n256o256¥0(100.07.76, 08-06-2008, RM-346, (c)Nokia , 
ADSP RevID		100.07.76j100.07.76100.07.76_v01kRM346ENO7411718214.N32n256o256
AEM		100.07.76j100.07.76100.07.76_v01kRM346ENO7411718214.N32n256o256
Flip MCUSW		100.07.76j100.07.76100.07.76_v01kRM346ENO7411718214.N32n256o256
Failed to read info -> Failed to read SP info
Read info thread finished, continuing...
Post flash tasks finished!
Flashing successfully finished!
BB5 Unlock Started...
MCU Version	V 100.71.821.4
MCU Date	06-06-08
Product		RM-346
Manufacturer	(c) Nokia
IMEI		358240030057483
Mastercode	446233637
Warning: Failed to read SP Info, Assuming defaults
Simlock Server	SIMLOCK SERVER
Simlock Key	2440700000000000
Simlock Profile	0000000000000000
Simlock Key Cnt	0
Simlock FBUS Cnt	0
Reading Security Block...
Security block OK!
Determining PA Simlock...
Booting RAP...
CMT_SYSTEM_ASIC_ID:	 000000010000022600010006400C192101031103
CMT_EM_ASIC_ID:		 00000296
CMT_EM_ASIC_ID:		 00000B22
CMT_PUBLIC_ID:		 0CD0000428318B52D0432B802A4F4B44F47906D1
CMT_ASIC_MODE_ID:	 00
CMT_ROOT_KEY_HASH:	 CAEEBB65D3C48E6DC73B49DC5063A2EE
CMT_ROM_ID:		 4B9B75103E691FF8
RAPIDOv11_2nd.fg, Type: 2nd Boot Loader, Rev: 0.1.37.1, Algo: BB5
Flashbus Write baud set to 1.0Mbits
Flashbus Read baud set to 98Kbits
FlashChip[0,CMT]: 0x00EC004000800121, Samsung, ONENAND
FlashContent[0,CMT]: 00000000000000000000000000000000, ONENAND
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
Transmission Mode Requested: Single Line, 8 bit, Accepted: Single Line, 8 bit
RAPIDOv11_algo.fg, Type: Algorithm, Rev: 0.1.40.0, Algo: XSR 1.5
Flashbus Write baud set to 2.0Mbits
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
Box VPP disabled
Internal CMT Phone VPP Enabled
PAPUBKEYS Hash for CMT: 52570A2086C79E6965175815B5388535CDD5C6F7
APE Boot skipped on user request
Flashbus Write baud set to 5.0Mbits
Restarting MCU...
Determined PA Simlock: PA_SL2
Checking for Rootkey Hash support...
Booting RAP...
CMT_SYSTEM_ASIC_ID:	 000000010000022600010006400C192101031103
CMT_EM_ASIC_ID:		 00000296
CMT_EM_ASIC_ID:		 00000B22
CMT_PUBLIC_ID:		 0CD0000428318B52D0432B802A4F4B44F47906D1
CMT_ASIC_MODE_ID:	 00
CMT_ROOT_KEY_HASH:	 CAEEBB65D3C48E6DC73B49DC5063A2EE
CMT_ROM_ID:		 4B9B75103E691FF8
RAPIDOv11_2nd.fg, Type: 2nd Boot Loader, Rev: 0.1.30.0, Algo: BB5
Flashbus Write baud set to 1.0Mbits
Flashbus Read baud set to 98Kbits
Exploiting - running preloader...
Preloader running OK, Running Custom Loader...
Custom loader running OK! Working...
BB5 Unlock Failed -> Failed to get Lock Key (6, 5)
Failed to read info -> Phone not detected

Last edited by ptt; 05-21-2010 at 18:26. Reason: add code tag
 
 
Page generated in 0.13347 seconds with 7 queries