GSM Shop GSM Shop
GSM-Forum  

Welcome to the GSM-Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features.
Only registered members may post questions, contact other members or search our database of over 8 million posts.

Registration is fast, simple and absolutely free so please - Click to REGISTER!

If you have any problems with the registration process or your account login, please contact contact us .

Go Back   GSM-Forum > Other Gsm/Mobile Related Forums > GSM Programming & Reverse Engineering


GSM Programming & Reverse Engineering Here you can post all Kind of GSM Programming and Reverse Engineering tools and Secrets.

Reply
 
LinkBack Thread Tools Display Modes
Old 03-05-2010, 16:43   #1 (permalink)
No Life Poster
 
Souhail's Avatar
 
Join Date: Aug 2005
Age: 45
Posts: 1,028
Member: 173741
Status: Offline
Thanks Meter: 986
Modem Unloker Free For All


Modem Unloker Free For All

List Models :

[Huawei]

E156
E155
E1550
E1552
E156G
E160
E160G
E161
E166
E169
E169G
E170
E172
E176
E1762
E180
E182E
E196
E226
E270
E271
E272
E510
E612
E618
E620
E630
E630+
E660
E660A
E800
E870
E880
EG162
E880
EG162
EG162G
EG602
EG602G

[Vodafone]

K2540
K3515
K3520
K3565
K3520
K3565



B,r Souhail_gsm

B,r Maverick_lp28
Attached Files
File Type: rar Huawei Unloker.rar (162.9 KB, 5177 views)
  Reply With Quote
The Following 64 Users Say Thank You to Souhail For This Useful Post:
Show/Hide list of the thanked
Old 03-05-2010, 17:09   #2 (permalink)
Freak Poster
 
mouradsamsung's Avatar
 
Join Date: Dec 2005
Location: TUNISIA
Posts: 228
Member: 208914
Status: Offline
Thanks Meter: 396
Quote:
Originally Posted by Souhail View Post
Modem Unloker Free For All

List Models :

[Huawei]

E156
E155
E1550
E1552
E156G
E160
E160G
E161
E166
E169
E169G
E170
E172
E176
E1762
E180
E182E
E196
E226
E270
E271
E272
E510
E612
E618
E620
E630
E630+
E660
E660A
E800
E870
E880
EG162
E880
EG162
EG162G
EG602
EG602G

[Vodafone]

K2540
K3515
K3520
K3565
K3520
K3565



B,r Souhail_gsm

B,r Maverick_lp28
wht's about source code ??????,,,,
  Reply With Quote
Old 03-05-2010, 19:00   #3 (permalink)
Freak Poster
 
Join Date: May 2009
Location: Sweden
Posts: 208
Member: 1039343
Status: Offline
Sonork: Dont have sonork
Thanks Meter: 54
it's not protected so why dont obtain the source code self?
  Reply With Quote
Old 03-05-2010, 20:11   #4 (permalink)
Freak Poster
 
Join Date: Jun 2009
Location: !!!! AWAY FROM BOARD, STUDY !!
Posts: 363
Member: 1055354
Status: Offline
Thanks Meter: 252
also uses "hwe620datacard" / "e630upgrade" constant, like all others...

but anyone reversing this would see would not do the extra work.

its clear, that these constants are non need. execution time and code size
can be shortened if you directly use the always constant results.

maybe its not important on modern PCs, but in small MCUs this is very important.

The only needed constants are:
unsigned char cs_unlock[] = "5E8DD316726B0335";
unsigned char cs_flash[] = "97B7BC6BE525AB44";
  Reply With Quote
The Following 7 Users Say Thank You to sergeymkl For This Useful Post:
Show/Hide list of the thanked
Old 03-05-2010, 21:23   #5 (permalink)
No Life Poster
 
Join Date: Aug 2005
Location: 突尼斯
Age: 38
Posts: 1,734
Member: 172136
Status: Offline
Sonork: 100.1574973
Thanks Meter: 777
Quote:
Originally Posted by sergeymkl View Post
also uses "hwe620datacard" / "e630upgrade" constant, like all others...

but anyone reversing this would see would not do the extra work.

its clear, that these constants are non need. execution time and code size
can be shortened if you directly use the always constant results.

maybe its not important on modern PCs, but in small MCUs this is very important.

The only needed constants are:
unsigned char cs_unlock[] = "5E8DD316726B0335";
unsigned char cs_flash[] = "97B7BC6BE525AB44";
join me in sonork
  Reply With Quote
Old 03-05-2010, 21:27   #6 (permalink)
Freak Poster
 
adamsquall's Avatar
 
Join Date: May 2008
Location: philippines
Age: 45
Posts: 235
Member: 771806
Status: Offline
Thanks Meter: 51
very big thanks for this mate.....
  Reply With Quote
Old 03-06-2010, 23:16   #7 (permalink)
Registered User
 
Join Date: Apr 2005
Age: 46
Posts: 74
Member: 136427
Status: Offline
Thanks Meter: 15
souhail where do you find it ?
i know only 1 person use this mod!!!!
  Reply With Quote
Old 03-07-2010, 02:01   #8 (permalink)
Freak Poster
 
Join Date: Jun 2009
Location: !!!! AWAY FROM BOARD, STUDY !!
Posts: 363
Member: 1055354
Status: Offline
Thanks Meter: 252
here's how the unneeded constants are derived:
MD5 ("hwe620datacard") = a32fe72c5e8dd316726b0335d5513ba0
MD5 ("e630upgrade") = aa91cee297b7bc6be525ab44cdc63be0
  Reply With Quote
The Following User Says Thank You to sergeymkl For This Useful Post:
Old 03-07-2010, 04:12   #9 (permalink)
Banned
 
Join Date: Sep 2006
Location: Mumbai
Posts: 36
Member: 354362
Status: Offline
Thanks Meter: 18
unlock free

Quote:
Originally Posted by Souhail View Post
Modem Unloker Free For All

List Models :

[Huawei]

E156
E155
E1550
E1552
E156G
E160
E160G
E161
E166
E169
E169G
E170
E172
E176
E1762
E180
E182E
E196
E226
E270
E271
E272
E510
E612
E618
E620
E630
E630+
E660
E660A
E800
E870
E880
EG162
E880
EG162
EG162G
EG602
EG602G

[Vodafone]

K2540
K3515
K3520
K3565
K3520
K3565



B,r Souhail_gsm

B,r Maverick_lp28
tankxxxxxxxxxxxxx verryyyyyyyyyyy much
  Reply With Quote
Old 03-07-2010, 05:14   #10 (permalink)
Product Manager
 
TestBox2's Avatar
 
Join Date: May 2008
Location: Ukraine
Age: 45
Posts: 3,234
Member: 772096
Status: Offline
Sonork: 100.69222
Thanks Meter: 8,277
Arrow

Quote:
Originally Posted by sergeymkl View Post
also uses "hwe620datacard" / "e630upgrade" constant, like all others...

This two constant take it from Oroginal Huawei Update tools .

so also : "hwe620datacard" / "e630upgrade" Use for verification acccess to upgradefirmware ordashboard.

also checking working is FW ID Modem not = Update Tool FW ID.

also possible disable this procedure of verification by Replace WF ID on Update too with value as in Modem FW ID.

And you can upgrade wf w/o insert flash code .



Step2:


If you want to make Ur KeyGen of Flashing code = you can replace hash password on Execute Firmware Upgrader 'e630upgrade';

As replace value 'e630upgrade' to 'e999upgrade' and you get FW Upgrade Tool with different hash password who need different value for calculate ittem.



B.R. TestBox2 team.
  Reply With Quote
Old 03-07-2010, 05:18   #11 (permalink)
Product Manager
 
TestBox2's Avatar
 
Join Date: May 2008
Location: Ukraine
Age: 45
Posts: 3,234
Member: 772096
Status: Offline
Sonork: 100.69222
Thanks Meter: 8,277
Wink

Step3:

Getting Unknown value for bruteforce needed hash password by reversing IMEI + NCK to Hash Password.

This methode you can use for found needed value for calculate validate codes.



B.R. TestBox2 team
  Reply With Quote
Old 03-07-2010, 05:25   #12 (permalink)
Freak Poster
 
Join Date: Jun 2009
Location: !!!! AWAY FROM BOARD, STUDY !!
Posts: 363
Member: 1055354
Status: Offline
Thanks Meter: 252
@Dorian:
I already know algo from v4mpire reversing, see here:
http://bb5.at/huawei.php?imei=123456789012347


some more infos for YUMERA:


now he has almost all he need to know algo...
but i can't ruin the challenge totally
  Reply With Quote
The Following User Says Thank You to sergeymkl For This Useful Post:
Old 03-07-2010, 13:24   #13 (permalink)
Insane Poster
 
Join Date: Feb 2010
Location: SLx
Posts: 60
Member: 1240703
Status: Offline
Thanks Meter: 40
Quote:
Originally Posted by TestBox2 View Post
Step3:

Getting Unknown value for bruteforce needed hash password by reversing IMEI + NCK to Hash Password.

This methode you can use for found needed value for calculate validate codes.



B.R. TestBox2 team
Thanks! Now, i got the Hash Password the first and last 8 digits need to discard?
  Reply With Quote
Old 03-07-2010, 13:28   #14 (permalink)
Freak Poster
 
Join Date: Jun 2009
Location: !!!! AWAY FROM BOARD, STUDY !!
Posts: 363
Member: 1055354
Status: Offline
Thanks Meter: 252
Nothing needs to be bruteforced...
What is "Hash password" are you all talking about?
  Reply With Quote
Old 03-07-2010, 13:39   #15 (permalink)
Insane Poster
 
Join Date: Feb 2010
Location: SLx
Posts: 60
Member: 1240703
Status: Offline
Thanks Meter: 40
Quote:
Originally Posted by sergeymkl View Post
Nothing needs to be bruteforced...
What is "Hash password" are you all talking about?
as what he said in step 3 IMEI + const HASH = HASH Password
  Reply With Quote
Reply

Bookmarks


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
KULANKENDI Ver 2.70 All modems totally free for KKBox/Dongle users gsminfo Kulankendi Box / Dongle 6 03-09-2010 21:08
02.03.2010 New FW and SW for modems added free for all Kulankendi Users ! gsminfo Kulankendi Box / Dongle 2 03-07-2010 21:36
KULANKENDI Ver 2.70 All modems totally free for KKBox/Dongle users gsminfo Service Products News & Updates 0 03-04-2010 16:41
panasonic gd 87 new unloker free 4 all vist sunnyc Panasonic 15 04-19-2004 09:46

 



All times are GMT +1. The time now is 22:49.



Powered by Searchlight © 2024 Axivo Inc.
vBulletin Optimisation provided by vB Optimise (Pro) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
- GSM Hosting Ltd. - 1999-2023 -
Page generated in 0.32795 seconds with 10 queries

SEO by vBSEO