|
|
![]() |
| |||||||
| Infineon C16X M51 & ARM7 M52 BASED MYxxx: MY3078, MY3026, MY3027 MWxxx: MW3052, MW3042, MW3040, MW3020, MW936, MW939, MW939, MW930, MW940, MW3026, MW3027 MCxxx: MC3000, MC959, MC950, MC940, MC939,MC936, MC932, MC912, MC850, MC825, MC820, MC922 RCxxx: RC922, RC750, RC730 WAxxx: WA3050 |
![]() |
| | LinkBack | Thread Tools | Display Modes |
| | #1 (permalink) |
| No Life Poster ![]() ![]() ![]() ![]() Join Date: Feb 2002 Location: china
Posts: 457
Member: 9315 Status: Offline Thanks: 0
Thanked 0 Times in 0 Posts
| software support h17 sagem 9xx hi, a lot of soft can unlock or calculate sagem 9xx,302x , but they nearly all that don't support h17. where have soft support h17 phone? thanx Last edited by raino; 10-31-2002 at 02:49. |
|
| | #5 (permalink) |
| No Life Poster ![]() ![]() ![]() ![]() ![]() Join Date: Mar 2002
Posts: 774
Member: 10175 Status: Offline Thanks: 0
Thanked 0 Times in 0 Posts
| Hi Raino... Whats the Problem with your phone? If it is "only" simlocked, all standard unlockers should work. - If its something else, get your PhoneID with Sagem Loader Pro - Calculate your new fields 251 252 253 with values 00, 0000000000000000000000 and 0000000000000000. How to do this, i explained here, several times (Search a little bit the forum). If this does not help, correct the checksums with sagemdr. |
|
| | #7 (permalink) |
| No Life Poster ![]() ![]() ![]() ![]() ![]() Join Date: Mar 2002
Posts: 774
Member: 10175 Status: Offline Thanks: 0
Thanked 0 Times in 0 Posts
| hi giorgi.. I never had a Hash 17 phone in my hands,.. What is special with them? If that are the checksums, that are not acessable with sagemdr (With known datacable commands) , its hard... Have you software that can do this (without directly programming the eeprom)? |
|
| | #9 (permalink) |
| No Life Poster ![]() ![]() ![]() ![]() ![]() Join Date: Mar 2002
Posts: 774
Member: 10175 Status: Offline Thanks: 0
Thanked 0 Times in 0 Posts
| I think, the data from fields 191/251 are incorrect with both phones... Do you have normal simlock or simlock before entering the PIN / simlock without SIM? To get the PhoneID id absolutly no problem from the second phone. It is included in the log... [1:2600249508f7bec60834c87505aa9bda11a5da 11a5da1100000000000000000000000000000000] -> Crypted ID = 9508F7BEC60834C87505AA9B -> ID= 033171006D08 For the first Phone, this should be no problem , too, because the ID "crypted by logger" 959f067de1c0 is included. For this, i suppose the MW Bootstraptool, to get the correct ID. If you have the ID for both, you can repair your phone... You are right... Sagemdr has not hash 17 (I never noticed that). So, you have to repair it by hand... Tell me fields 251 252 253 for both phones. I hope you haven't tried to correct the checksums with sagemdr.. If you did, its some more work :-) |
|
| | #11 (permalink) |
| No Life Poster ![]() ![]() ![]() ![]() ![]() Join Date: Mar 2002
Posts: 774
Member: 10175 Status: Offline Thanks: 0
Thanked 0 Times in 0 Posts
| IN these log - files,the phoneID is crypted (a little bit), so you cannot use it directly to calculate the code with it. Read the ID with MWbootstraptool-> ANd now you can calculate the code the well known way... |
|
| | #12 (permalink) |
| No Life Poster ![]() ![]() ![]() ![]() Join Date: Feb 2002 Location: china
Posts: 457
Member: 9315 Status: Offline Thanks: 0
Thanked 0 Times in 0 Posts
| Hi, what is the correct ID? the MWbootstraptool can't read ID. why do you know the ID is wrong? If use your sw clac3.4.3, what mode i must select? if enter these ,is it right? uncrypted field: 41 crypted field: 05e1bcf19f20 mode is 1 thanks |
|
| | #13 (permalink) |
| No Life Poster ![]() ![]() ![]() ![]() ![]() Join Date: Mar 2002
Posts: 774
Member: 10175 Status: Offline Thanks: 0
Thanked 0 Times in 0 Posts
| 083A23421121463139 -> PhoneID = 101B0B61E440 (Lock level 13) 083A23321821603468 -> PhoneID = 16115329E340 (Lock level 13) But you are right.. Theres no free soft, that can handle these LOG files, because that dammed logger did not give the plain phoneID. every byte can be XORed by 0x80... So you have to to brute force in 64 steps :-) But i think, the bootstraptool should be able to handle these phones. The logger can do, too. What kind of logger did you use? |
|
| | #15 (permalink) |
| No Life Poster ![]() ![]() ![]() ![]() ![]() Join Date: Mar 2002
Posts: 774
Member: 10175 Status: Offline Thanks: 0
Thanked 0 Times in 0 Posts
| As theres no soft available that can handle these hash17 logged IDs, i included an option for this in my calc. Here's my calc 4.1 http://www.cbot-gsm.de/wbboard/misc2...tachmentid=430 33224111268304- 9 -> 90888be1e4c0 With XOR 80, i mean the phoneID... In the log, the ID is 90888be1e4c0 now, the first byte can be 90 or 90 XOR 80 -> 90 or 10 second byte can be 88 or 08 third byte cn be 8B or 0B fourth byte can be BE or 3E fifth byte can be E4 or 64 sixth byte can be c0 or 40 Now you have to try it out... decrypt field 191. If the checksum is correct->you have chhsen the correct combination. If not, you have to choose another combination. |
|
![]() |
| Bookmarks |
| Thread Tools | |
| Display Modes | |
| |