View Single Post
Old 05-17-2011, 18:37   #1 (permalink)
ZIYAAD STRYKER
No Life Poster
 
ZIYAAD STRYKER's Avatar
 
Join Date: Aug 2005
Posts: 3,187
Member: 175945
Status: Offline
Sonork: ziiyyaad
Thanks Meter: 704
n8 & 5230 decrypted ok!!!

MCU: V 92PS1_10w34.3 10-09-10 RM-596 (c) Nokia
IMEI: 355944044120491
Model : Nokia N8-00
Product Serial Number: CAQ960857
Product Code : 059C6P7
Basic Production Code: 0596826
Default SN Type : 0
PPM Version : V 92PS1_10w34.3 10-09-10 RM-596 (c) Nokia
HW Version : 7450
RFIC Version : |Alli_4.3.4
DSP Version : TB92PS1_10w34.1
APE BT Version : HCI Version 12 (rev. 64). LMP Version 36 (rev. 64). Manufacturer 1920.
AHNE Version : 11
APE SW Core Version : 011.012
APE Variant Version : 011.012.00.01011.012.18.01011.012.232.03
APE Test Version : rm596_ENO_2010wk46v141
Retu Version : 35
Tahvo Version : 00
APE HW Version : 256
APE ADSP SW Version : 256

******** Reading SimLock ********
CONFIG KEY: 8000000000000000
PROVIDER KEY: 5050600042465540
Provider : Hutchinson 3G;Australia
Counters : 0/3 , 0/10
Block [1] 1:Close
Block [2] 1:Close
Block [3] 1:Close
SP Lock Status : Locked

SIMLOCK_TYPE : PA_SL3 (15-digit NCK)
SIMLOCK_TEST : PASSED
SECURITY_TEST : PASSED
SECURITY_CODE : ENCRYPTED
PHONE_MODE : UNKNOWN

PM 120 Found...
PM 308 Found...
SimLock Certificate Saved to : C:\AdvanceBox Turbo Flasher\Nokia\Backup\355944044120491\SL3_certifica te_V 92PS1_10w34.3 10-09-10 RM-596 (c) Nokia_355944044120491_Locked_93448.pm

MCU: V 92PS1_10w34.3 10-09-10 RM-596 (c) Nokia
IMEI: 355944044120491
Model : Nokia N8-00
Product Serial Number: CAQ960857
Product Code : 059C6P7
Basic Production Code: 0596826
Default SN Type : 0
PPM Version : V 92PS1_10w34.3 10-09-10 RM-596 (c) Nokia
HW Version : 7450
RFIC Version : |Alli_4.3.4
DSP Version : TB92PS1_10w34.1
APE BT Version : HCI Version 12 (rev. 64). LMP Version 36 (rev. 64). Manufacturer 1920.
AHNE Version : 11
APE SW Core Version : 011.012
APE Variant Version : 011.012.00.01011.012.18.01011.012.232.03
APE Test Version : rm596_ENO_2010wk46v141
Retu Version : 35
Tahvo Version : 00
APE HW Version : 256
APE ADSP SW Version : 256

******** Reading SimLock ********
CONFIG KEY: 8000000000000000
PROVIDER KEY: 5050600042465540
Provider : Hutchinson 3G;Australia
Counters : 0/3 , 0/10
Block [1] 1:Close
Block [2] 1:Close
Block [3] 1:Close
SP Lock Status : Locked

SIMLOCK_TYPE : PA_SL3 (15-digit NCK)
SIMLOCK_TEST : PASSED
SECURITY_TEST : PASSED
SECURITY_CODE : ENCRYPTED
PHONE_MODE : UNKNOWN


================================================== =
Decrypt SL3 PM 120 HASHES for Brute Force Unlock
================================================== =
Decrypting PM 120...
(This may take upto 30 Seconds on New RAPIDO HASH)

PM 120 HASHES Extracted Successfully

627E59E1B91E178AF375C06F84369030E4AF6044
222D678190C5DFFDFF035F280B7B189837A7A6EA
DC9BC28E41BE69998D2814827195D26B49C20234
3B53599242711D41A8BE1C9ABE3F4C0E231476C7
1AECE17EF8F03EA233F488E3F6A00F6D1BDB1301
3431BA42D3E85CC318D799A12A97187CFB3CD64A
C4729F14E4AFD4FF7B8C24C103C5CC7A5B87E79C
94CDEC3C6271521C24DBE673C2E98506754DC53F



Log Files for Local Brute Force Saved to:
C:\AdvanceBox Turbo Flasher\Nokia\Bruteforce\355944044120491\355944044 120491.log
C:\AdvanceBox Turbo Flasher\Nokia\Bruteforce\355944044120491\355944044 120491.bcl
C:\AdvanceBox Turbo Flasher\Nokia\Bruteforce\355944044120491\355944044 120491.sha

Command Line for ighashgpu:
Saved as MS Batch File: 355944044120491_ighashgpu.bat

Command Line for oclHashcat-lite64 (AMD Cards 64-Bit OS):
Saved as MS Batch File: 355944044120491_AMD_oclHashcat_64-bit.bat

Command Line for oclHashcat-lite32 (AMD Cards 32-Bit OS):
Saved as MS Batch File: 355944044120491_AMD_oclHashcat_32-bit.bat

Command Line for cudaHashcat-lite64 (NVIDIA Cards 64-Bit OS):
Saved as MS Batch File: 355944044120491_NVIDIA_cudaHashcat_64-bit.bat

Command Line for cudaHashcat-lite32 (NVIDIA Cards 32-Bit OS):
Saved as MS Batch File: 355944044120491_NVIDIA_cudaHashcat_32-bit.bat

Process Done!



AdvanceBox SendBootCodeEx
InitialiseBootstrap_DCT5 DIR
BootFlashMode_DCT5

************************************************** ****
TIME STARTS HERE
************************************************** ****

BootFlashModeDCT5Ex Succeeded First Time
SYSTEM_ID_RESPONSE_BB5 (0xC0) - 0 (0x00) bytes returned
Number of Sub Blocks 7 (0x07)
1 SYSTEM_ASIC_ID 01
Block Length : 21 (15)
BB ASIC Index : 0 (00) CMT
ID DWORD 0 : 00000001
ID DWORD 1 : 00000226
ID DWORD 2 : 00010006
ID DWORD 3 : 400C1921
ID DWORD 4 : 01051103
2 ROM_ID 15
Block Length : 5 (05)
BB ASIC Index : 0 (00) CMT
ID DWORD 0 : 00000296
3 ROM_ID 15
Block Length : 5 (05)
BB ASIC Index : 0 (00) CMT
ID DWORD 0 : 00000B22
4 PUBLIC_ID 12
Block Length : 21 (15)
BB ASIC Index : 0 (00) CMT
ID DWORD 0 : 10C00015
ID DWORD 1 : 029B0052
ID DWORD 2 : 8F57AB7A
ID DWORD 3 : EDD97AD8
ID DWORD 4 : 2E6F1120
5 ASIC_MODE_ID 13
Block Length : 2 (02)
BB ASIC Index : 0 (00) CMT
Mode Id : 00
6 ROOT_KEY_HASH 14
Block Length : 17 (11)
BB ASIC Index : 0 (00) CMT
Hash : 47 9C 6D DE 39 42 E1 2C 42 9C 1D 6A DE D8 03 71
7 ROM_ID 15
Block Length : 9 (09)
BB ASIC Index : 0 (00) CMT
CRC 0 : 4B9B7510
CRC 1 : 3E691FF8
Checksum 8D

SearchForBootstrap_DCT5..
C:\AdvanceBox Turbo Flasher\Nokia\BB5_Loader\New\RAPIDOv11_2nd.fg
Boot File - Version 010.050.00
Boot File - Revision 0x0002 (2)
eBB5ProtocolType == New
PrepareBootstrapFile_DCT5 replaced "SILO" with "2ND\0"
PrepareBootstrapFile_DCT5 replaced "BOOT_MEDIAX" with "BOOT_MEDIA0"
SearchForBootstrap_DCT5 : No Error - 0 (0x00)
Secondary Loader Sent...
TransmissionTypeRequest_DCT5_NewProtocol
TRANSMISSION_TYPE_REQUEST_BB5 GET_PROTOCOLS_BB5
TRANSMISSION_TYPE_REQUEST_BB5 : 59 01 3E 00 C0
TransmissionTypeRequest_DCT5_NewProtocol
FPIF_TRANSMISSION_MODE_LIST_BB5 using default mode 04 DDRand2TX
TRANSMISSION_TYPE_REQUEST_BB5 : 59 02 41 02 04 00 36 03 00 00 61 1C
Transmission Type Request Sent...
ConfigurationRequest_DCT5 (RAM_SIZE_BB5 0x0000)..
MCU_CONFIGURATION_RESPONSE_BB5:
MessageID : 06
SubBlocks : 06
1 Sub Block ID : 10 STORAGE_DEVICE_ID_BB5
Block Length : 0B
BB ASIC Index : CMT 00
Device Type : RAM 05
Device Index : 00
Manufacturer Code : 0000 -> Flash
Device ID : 0000 -> not detected
Extended/Fixed ID : 0000
Revision ID : 0000
2 Sub Block ID : 10 STORAGE_DEVICE_ID_BB5
Block Length : 0B
BB ASIC Index : CMT 00
Device Type : MMC 04
Device Index : 00
Manufacturer Code : FFFF -> Flash
Device ID : 0000 -> BAD FLASH TYPE
Extended/Fixed ID : 0000
Revision ID : 0000
3 Sub Block ID : 10 STORAGE_DEVICE_ID_BB5
Block Length : 0B
BB ASIC Index : CMT 00
Device Type : NOR 00
Device Index : 00
Manufacturer Code : 0400 -> Flash
Device ID : 0000 -> Type not in database
Extended/Fixed ID : 0000
Revision ID : 0000
4 Sub Block ID : 10 STORAGE_DEVICE_ID_BB5
Block Length : 0B
BB ASIC Index : CMT 00
Device Type : NOR 00
Device Index : 01
Manufacturer Code : 0000 -> SPANSION
Device ID : 0001 -> not used
Extended/Fixed ID : 0000
Revision ID : 0000
5 Sub Block ID : 10 STORAGE_DEVICE_ID_BB5
Block Length : 0B
BB ASIC Index : CMT 00
Device Type : MuxOneNAND 03
Device Index : 00
Manufacturer Code : 00EC ->
Device ID : 0040 -> KAT00F00RA
Extended/Fixed ID : 0000
Revision ID : 0231
6 Sub Block ID : 35 NAND_DRIVER_VERSION_BB5
Block Length : 09
BB ASIC Index : CMT 00
Data : XSR 1.6
Checksum : 13
SearchForBootstrap_DCT5 : No Error - 0 (0x00)
FLS1SendAlgoCodeEx..
SendAlgoCode_DCT5..
SearchForAlgorithm_DCT5..
Looking for ALL Devices...
Searching Algorithm Files MuxOneNAND (03) ManID :00EC DevID :0040 ExtID :0000 RevID :0231
Flash Descriptor
Manufacturer Code : 00EC
Device ID : 0040
Extended/Fixed ID : 0000
Revision ID : 0000
Size : 10000000 (256 MB)
VPP Info : 0000
Erase10s : 1E
Block1s : 32
BErase1s : 02
Reserved0 : 00
Reserved1 : 00
Reserved2 : 00
C:\AdvanceBox Turbo Flasher\Nokia\BB5_Loader\New\RAPIDOv11_XSR17_alg.f g
Algorithm File - Version 010.050.00
Algorithm File - Revision 0x0002 (2)
eBB5ProtocolType == New
Algo Loader Sent...
SendCodeStart_NewProtocol :
SendCodeStart_NewProtocol_DCT5 : No Error - 0 (0x00)
TransmissionTypeRequest_DCT5_NewProtocol
TRANSMISSION_TYPE_REQUEST_BB5 GET_PROTOCOLS_BB5
TRANSMISSION_TYPE_REQUEST_BB5 : 59 01 3E 00 C0
TransmissionTypeRequest_DCT5_NewProtocol
FPIF_TRANSMISSION_MODE_LIST_BB5 using default mode 04 DDRand2TX
TRANSMISSION_TYPE_REQUEST_BB5 : 59 02 41 02 04 00 36 03 00 00 61 1C
SendAlgoCodeFile_DCT5 : No Error - 0 (0x00)
FUR_Control_AddClient_BB5() ASIC_INDEX_CMT (Ready)
FUR control Ok...
VPP Enabled by Software
Using Internal VPP
VPP Enabled by Software
FLASH_VOLTAGE_INIT_BB5 : 5C 01 26 04 00 00 00 00 D4
Pabub KEY Request
PhoneInfoRequest_BB5 (Asic Index 00 )
PHONE_INFO_RESPONSE_BB5
PAPUB_KEYS_HASH_RESP_BB5 2A
BB Asic Index : 00
CMT PAPUBKEYS HASH:
7DC72D3FDC552426A4479BC820097D304CFB6C15

Scanning Simlock Applet Type...
OK

=================================================
PA_SL3 Applet detected
=================================================

* Firmware Version Downgrade will KILL PHONE !!!
* Manual Full Erase WILL KILL PHONE!!!
* Simlocks are in PM 120 Only...
* PM 308 is Write Protected...

FlashInfo.RestartMode : 2

MCU: V ICPR72_10w04.5 22-03-10 RM-588 (c) Nokia
IMEI: 353763042724662
Model : Nokia 5230
Product Serial Number: 00E3F8EAA
Product Code : 0596559
Module Code : 0204359
Basic Production Code: 0584528
Default SN Type : 0
PPM Version : V ICPR72_10w04.5 22-03-10 RM-588 (c) Nokia
HW Version : 0512
RFIC Version : 17141716
DSP Version : simon_ICPR72_10w05
Content Pack Version : 20.0.005_001_U293
AHNE Version : 11
APE SW Core Version : V 20.0.005
APE Variant Version : V 20.0.005V 20.0.005 20.0.005.293.02
APE Test Version : rm588_ENO_x_09wk43v0.050
Retu Version : 16
Tahvo Version : 22
APE HW Version : 256
APE ADSP SW Version : 256

******** Reading SimLock ********
CONFIG KEY: 0000000000000000
PROVIDER KEY: 2720200000000000
Provider : 02 - Esat Digifone-code 7;Ireland
Counters : 0/3 , 0/10
Block [1] 1:Close
Block [2] 1:Close
SP Lock Status : Locked

SIMLOCK_TYPE : PA_SL3 (15-digit NCK)
SIMLOCK_TEST : PASSED
SECURITY_TEST : PASSED
SECURITY_CODE : ENCRYPTED
PHONE_MODE : TEST MODE



AdvanceBox SendBootCodeEx
InitialiseBootstrap_DCT5 DIR
BootFlashMode_DCT5

************************************************** ****
TIME STARTS HERE
************************************************** ****

BootFlashModeDCT5Ex Succeeded First Time
SYSTEM_ID_RESPONSE_BB5 (0xC0) - 0 (0x00) bytes returned
Number of Sub Blocks 7 (0x07)
1 SYSTEM_ASIC_ID 01
Block Length : 21 (15)
BB ASIC Index : 0 (00) CMT
ID DWORD 0 : 00000001
ID DWORD 1 : 00000226
ID DWORD 2 : 00010006
ID DWORD 3 : 400C1921
ID DWORD 4 : 01051103
2 ROM_ID 15
Block Length : 5 (05)
BB ASIC Index : 0 (00) CMT
ID DWORD 0 : 00000296
3 ROM_ID 15
Block Length : 5 (05)
BB ASIC Index : 0 (00) CMT
ID DWORD 0 : 00000B22
4 PUBLIC_ID 12
Block Length : 21 (15)
BB ASIC Index : 0 (00) CMT
ID DWORD 0 : 10C00015
ID DWORD 1 : 029B0052
ID DWORD 2 : 8F57AB7A
ID DWORD 3 : EDD97AD8
ID DWORD 4 : 2E6F1120
5 ASIC_MODE_ID 13
Block Length : 2 (02)
BB ASIC Index : 0 (00) CMT
Mode Id : 00
6 ROOT_KEY_HASH 14
Block Length : 17 (11)
BB ASIC Index : 0 (00) CMT
Hash : 47 9C 6D DE 39 42 E1 2C 42 9C 1D 6A DE D8 03 71
7 ROM_ID 15
Block Length : 9 (09)
BB ASIC Index : 0 (00) CMT
CRC 0 : 4B9B7510
CRC 1 : 3E691FF8
Checksum 8D

SearchForBootstrap_DCT5..
C:\AdvanceBox Turbo Flasher\Nokia\BB5_Loader\New\RAPIDOv11_2nd.fg
Boot File - Version 010.050.00
Boot File - Revision 0x0002 (2)
eBB5ProtocolType == New
PrepareBootstrapFile_DCT5 replaced "SILO" with "2ND\0"
PrepareBootstrapFile_DCT5 replaced "BOOT_MEDIAX" with "BOOT_MEDIA0"
SearchForBootstrap_DCT5 : No Error - 0 (0x00)
Secondary Loader Sent...
TransmissionTypeRequest_DCT5_NewProtocol
TRANSMISSION_TYPE_REQUEST_BB5 GET_PROTOCOLS_BB5
TRANSMISSION_TYPE_REQUEST_BB5 : 59 01 3E 00 C0
TransmissionTypeRequest_DCT5_NewProtocol
FPIF_TRANSMISSION_MODE_LIST_BB5 using default mode 04 DDRand2TX
TRANSMISSION_TYPE_REQUEST_BB5 : 59 02 41 02 04 00 36 03 00 00 61 1C
Transmission Type Request Sent...
ConfigurationRequest_DCT5 (RAM_SIZE_BB5 0x0000)..
MCU_CONFIGURATION_RESPONSE_BB5:
MessageID : 06
SubBlocks : 06
1 Sub Block ID : 10 STORAGE_DEVICE_ID_BB5
Block Length : 0B
BB ASIC Index : CMT 00
Device Type : RAM 05
Device Index : 00
Manufacturer Code : 0000 -> Flash
Device ID : 0000 -> not detected
Extended/Fixed ID : 0000
Revision ID : 0000
2 Sub Block ID : 10 STORAGE_DEVICE_ID_BB5
Block Length : 0B
BB ASIC Index : CMT 00
Device Type : MMC 04
Device Index : 00
Manufacturer Code : FFFF -> Flash
Device ID : 0000 -> BAD FLASH TYPE
Extended/Fixed ID : 0000
Revision ID : 0000
3 Sub Block ID : 10 STORAGE_DEVICE_ID_BB5
Block Length : 0B
BB ASIC Index : CMT 00
Device Type : NOR 00
Device Index : 00
Manufacturer Code : 0400 -> Flash
Device ID : 0000 -> Type not in database
Extended/Fixed ID : 0000
Revision ID : 0000
4 Sub Block ID : 10 STORAGE_DEVICE_ID_BB5
Block Length : 0B
BB ASIC Index : CMT 00
Device Type : NOR 00
Device Index : 01
Manufacturer Code : 0000 -> SPANSION
Device ID : 0001 -> not used
Extended/Fixed ID : 0000
Revision ID : 0000
5 Sub Block ID : 10 STORAGE_DEVICE_ID_BB5
Block Length : 0B
BB ASIC Index : CMT 00
Device Type : MuxOneNAND 03
Device Index : 00
Manufacturer Code : 00EC ->
Device ID : 0040 -> KAT00F00RA
Extended/Fixed ID : 0000
Revision ID : 0231
6 Sub Block ID : 35 NAND_DRIVER_VERSION_BB5
Block Length : 09
BB ASIC Index : CMT 00
Data : XSR 1.6
Checksum : 13
SearchForBootstrap_DCT5 : No Error - 0 (0x00)
FLS1SendAlgoCodeEx..
SendAlgoCode_DCT5..
SearchForAlgorithm_DCT5..
Looking for ALL Devices...
Searching Algorithm Files MuxOneNAND (03) ManID :00EC DevID :0040 ExtID :0000 RevID :0231
Flash Descriptor
Manufacturer Code : 00EC
Device ID : 0040
Extended/Fixed ID : 0000
Revision ID : 0000
Size : 10000000 (256 MB)
VPP Info : 0000
Erase10s : 1E
Block1s : 32
BErase1s : 02
Reserved0 : 00
Reserved1 : 00
Reserved2 : 00
C:\AdvanceBox Turbo Flasher\Nokia\BB5_Loader\New\RAPIDOv11_XSR17_alg.f g
Algorithm File - Version 010.050.00
Algorithm File - Revision 0x0002 (2)
eBB5ProtocolType == New
Algo Loader Sent...
SendCodeStart_NewProtocol :
SendCodeStart_NewProtocol_DCT5 : No Error - 0 (0x00)
TransmissionTypeRequest_DCT5_NewProtocol
TRANSMISSION_TYPE_REQUEST_BB5 GET_PROTOCOLS_BB5
TRANSMISSION_TYPE_REQUEST_BB5 : 59 01 3E 00 C0
TransmissionTypeRequest_DCT5_NewProtocol
FPIF_TRANSMISSION_MODE_LIST_BB5 using default mode 04 DDRand2TX
TRANSMISSION_TYPE_REQUEST_BB5 : 59 02 41 02 04 00 36 03 00 00 61 1C
SendAlgoCodeFile_DCT5 : No Error - 0 (0x00)
FUR_Control_AddClient_BB5() ASIC_INDEX_CMT (Ready)
FUR control Ok...
VPP Enabled by Software
Using Internal VPP
VPP Enabled by Software
FLASH_VOLTAGE_INIT_BB5 : 5C 01 26 04 00 00 00 00 D4
Pabub KEY Request
PhoneInfoRequest_BB5 (Asic Index 00 )
PHONE_INFO_RESPONSE_BB5
PAPUB_KEYS_HASH_RESP_BB5 2A
BB Asic Index : 00
CMT PAPUBKEYS HASH:
7DC72D3FDC552426A4479BC820097D304CFB6C15

Scanning Simlock Applet Type...
OK

=================================================
PA_SL3 Applet detected
=================================================

Dumping RSA Modulus...
OK

=================================================
RSA Modulus OK
=================================================
FlashInfo.RestartMode : 2

================================================== =
Decrypt SL3 PM 120 HASHES for Brute Force Unlock
================================================== =
Decrypting PM 120...
(This may take upto 30 Seconds on New RAPIDO HASH)

PM 120 HASHES Extracted Successfully

2F05D74B7899960F495B2FF26095324D158E9E77
89917C778A48F59C1BC86B1474B8234685E8BB62
34B3B319135F54E32CAA08BC5AEAE2EBB6AB6C7B
7AC4F6470769CDCA14CF53F12D470BA1DB85F9B6
0BD7158AE53C3C4346144D0F5A371F62FF301F8E
1C7A2A5307A1838DF2D7D34B7C0C7BE93C4473D7
6208D924C2B1748908D774F5F4F975ED6CE55979
F193EFDB1C9E77E2641A0CEF7D0DCDFC8A172B4D



Log Files for Local Brute Force Saved to:
C:\AdvanceBox Turbo Flasher\Nokia\Bruteforce\353763042724662\353763042 724662.log
C:\AdvanceBox Turbo Flasher\Nokia\Bruteforce\353763042724662\353763042 724662.bcl
C:\AdvanceBox Turbo Flasher\Nokia\Bruteforce\353763042724662\353763042 724662.sha

Command Line for ighashgpu:
Saved as MS Batch File: 353763042724662_ighashgpu.bat

Command Line for oclHashcat-lite64 (AMD Cards 64-Bit OS):
Saved as MS Batch File: 353763042724662_AMD_oclHashcat_64-bit.bat

Command Line for oclHashcat-lite32 (AMD Cards 32-Bit OS):
Saved as MS Batch File: 353763042724662_AMD_oclHashcat_32-bit.bat

Command Line for cudaHashcat-lite64 (NVIDIA Cards 64-Bit OS):
Saved as MS Batch File: 353763042724662_NVIDIA_cudaHashcat_64-bit.bat

Command Line for cudaHashcat-lite32 (NVIDIA Cards 32-Bit OS):
Saved as MS Batch File: 353763042724662_NVIDIA_cudaHashcat_32-bit.bat

Process Done!
  Reply With Quote
 
Page generated in 0.13333 seconds with 7 queries