|
Welcome to the GSM-Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. Only registered members may post questions, contact other members or search our database of over 8 million posts. Registration is fast, simple and absolutely free so please - Click to REGISTER! If you have any problems with the registration process or your account login, please contact contact us . |
|
Register | FAQ | Donate | Forum Rules | Root any Device | ★iPhone Unlock★ | ★ Direct Codes ★ | Direct Unlock Source | Mark Forums Read |
| LinkBack | Thread Tools | Display Modes |
02-21-2013, 08:37 | #1 (permalink) |
No Life Poster Join Date: Feb 2007 Location: India
Posts: 1,221
Member: 449060 Status: Offline Sonork: 100.1670591 Thanks Meter: 260 | 7210s read SP info (Solved) MCU Date 17-07-09 Product RM-436 (Nokia 7210 Supernova) Manufacturer (c) Nokia IMEI 359310027322999 Mastercode 7510517632 IMEI Spare 3A95130072239209 IMEI SV 3395130072239249F0000000 PPM V 07.23, 17-07-09, RM-436, (c) Nokia , MR CNT Content: mr_ny, V 07.23, 17-07-09, RM-436, (c) Nokia , PSN DTD161510 Product Code 0572571 Module Code 0203868 Basic Product Code 0563951 PSD 0000000000000000 LPSN 0 RETU 15 TAHVO 22 AHNE 30 HW 1001 RFIC 064c0601 DSP ICPR72_09w17 LCD SEIKO BT 2222-143C Failed to read info -> Failed to read SP info |
02-21-2013, 11:41 | #3 (permalink) |
No Life Poster Join Date: Feb 2007 Location: India
Posts: 1,221
Member: 449060 Status: Offline Sonork: 100.1670591 Thanks Meter: 260 | BB5 Unlock Started... MCU Version V 07.23 MCU Date 17-07-09 Product RM-436 (Nokia 7210 Supernova) Manufacturer (c) Nokia IMEI 359310027322999 Mastercode 7510517632 Warning: Failed to read SP Info, Assuming defaults Simlock Server Simlock Key 88DD610350335F03 Simlock Profile 6E000000F0324300 Simlock Key Cnt 0 Simlock FBUS Cnt 0 Reading Security Block... Security block OK and saved to "RM-436_359310027322999_2212013_40946 PM.SecurityBlock.PM" "090001163C827C567208C482A0D1FA4878FCCFE3.B0000EF5 " Exists, That is good... Checking for Rootkey Hash support with selected Unlock Method... Selected Unlock Method: RPL Calculation Asking box to calculate RPL... Received RPL from Box OK! Writing Simlock... BB5 Unlock Failed -> Simlock NOT ACCEPTED ! Maybe is SL help any other soluction sir |
02-21-2013, 13:55 | #5 (permalink) |
No Life Poster Join Date: Feb 2007 Location: India
Posts: 1,221
Member: 449060 Status: Offline Sonork: 100.1670591 Thanks Meter: 260 | downgrade to v5 no local mode now Processing pre flash tasks... Backing up RPL... RPL Creation started... Processing CMT Part... Storing Product Code... Storing PSN... Storing HWID... Simlock Store not supported, not a PA_SL2 Phone Trying to store WMDRM RPL... Reading Keys... Failed to read WMDRM Key Reading Security Block... Security block OK and saved to "RM-436_359310027322999_2212013_61322 PM.SecurityBlock.PM" "090001163C827C567208C482A0D1FA4878FCCFE3.B0000EF5 " Exists, That is good... Storing Additional Data... Checking Superdongle Key... Encrypting Superdongle Key... Storing Superdongle Key... Checking CMLA Key... CMLA Key Store Problem -> Failed to decode Security Section, Box Reported: Security Section Not Found (SL3 phone?) Booting CMT... CMT_SYSTEM_ASIC_ID: 000000010000022600010006030C192101033000 CMT_EM_ASIC_ID: 00000295 CMT_EM_ASIC_ID: 00000B22 CMT_PUBLIC_ID: 090001163C827C567208C482A0D1FA4878FCCFE3 CMT_ASIC_MODE_ID: 00 CMT_ROOT_KEY_HASH: 9DDBFCFE6E73CED7D8C6268C8EB85723 CMT_BOOT_ROM_CRC: 273F6D55 CMT_SECURE_ROM_CRC: DFAAF68F CMT Ready! Searching for BootCode: DualLine 32Bit RAP3Gv3_2nd.fg, Type: 2nd Boot Loader, Rev: 0.10.42.0, Algo: BB5 Flashbus Write baud set to 1.0Mbits Flashbus Read baud set to 98Kbits Using OLD BB5 FLASHING PROTOCOL If software STUCK HERE with box TX LED lit, that means: 1. You have not attached yellow TX2 Adapter (IT IS REQUIRED FOR BB5 PHONES WHEN USING JAF/UFS CABLES!) 2. Your cable is not TX2 Enabled! 3. Transmission error occured, try again In either cases, you need to reconnect your box from USB. FlashChip[0,CMT]: 0x0089898200008A31, Intel, NOR FlashContent[0,CMT]: 00000000000000000000000000000000, NOR FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC Transmission Mode Requested: Single Line, 8 bit, Accepted: Single Line, 8 bit Searching for BootCode: DualLine 32Bit FlashChip 0x00898982 (Intel), Size: 64MBytes, VPP: 9V RAP3Gv3_algo.fg, Type: Algorithm, Rev: 0.10.40.0, Algo: BB5 ALGORITHM Flashbus Write baud set to 2.0Mbits Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit Box TX2 Data Pin set to: Service Pin 3 Box VPP disabled Internal CMT Phone VPP Enabled PAPUBKEYS Hash for CMT: F1DCA5EA5203CD30A64D4D95ABCD621F4AB23026 APE Subsystem Not Found Flashbus Write baud set to 5.0Mbits Storing NPC... Storing CCC... Storing HWC... CMT VARIANT Not Found CMT PARTNERC Not Found Restarting MCU... RPL Saved OK RPL backup thread finished, continuing... Backing up simlock... MCU Version V 07.23 MCU Date 17-07-09 Product RM-436 (Nokia 7210 Supernova) Manufacturer (c) Nokia IMEI 359310027322999 Mastercode 7510517632 Simlock backup OK, saved to RM-436_359310027322999_2212013_61342 PM.SLBackup.PM Backup simlock thread finished, continuing... Applying downgrade patch... Apply downgrade patch failed -> Failed to write patched PM 308 Pre flash tasks finished, continuing... Processing rm436__05.20.mcusw (CMT)... Booting CMT... CMT_SYSTEM_ASIC_ID: 000000010000022600010006030C192101033000 CMT_EM_ASIC_ID: 00000295 CMT_EM_ASIC_ID: 00000B22 CMT_PUBLIC_ID: 090001163C827C567208C482A0D1FA4878FCCFE3 CMT_ASIC_MODE_ID: 00 CMT_ROOT_KEY_HASH: 9DDBFCFE6E73CED7D8C6268C8EB85723 CMT_BOOT_ROM_CRC: 273F6D55 CMT_SECURE_ROM_CRC: DFAAF68F CMT Ready! rm436__05.20.mcusw, Type: Flash Image, Algo: BB5, BB5 ALGORITHM Searching for BootCode: DualLine 32Bit RAP3Gv3_2nd.fg, Type: 2nd Boot Loader, Rev: 0.10.42.0, Algo: BB5 Flashbus Write baud set to 1.0Mbits Flashbus Read baud set to 98Kbits Using OLD BB5 FLASHING PROTOCOL If software STUCK HERE with box TX LED lit, that means: 1. You have not attached yellow TX2 Adapter (IT IS REQUIRED FOR BB5 PHONES WHEN USING JAF/UFS CABLES!) 2. Your cable is not TX2 Enabled! 3. Transmission error occured, try again In either cases, you need to reconnect your box from USB. FlashChip[0,CMT]: 0x0089898200008A31, Intel, NOR FlashContent[0,CMT]: 00000000000000000000000000000000, NOR FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC Transmission Mode Requested: Single Line, 8 bit, Accepted: Single Line, 8 bit Searching for BootCode: DualLine 32Bit FlashChip 0x00898982 (Intel), Size: 64MBytes, VPP: 9V RAP3Gv3_algo.fg, Type: Algorithm, Rev: 0.10.40.0, Algo: BB5 ALGORITHM Flashbus Write baud set to 2.0Mbits Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit Box TX2 Data Pin set to: Service Pin 3 Box VPP disabled Internal CMT Phone VPP Enabled PAPUBKEYS Hash for CMT: F1DCA5EA5203CD30A64D4D95ABCD621F4AB23026 Flashbus Write baud set to 5.0Mbits Sending Certificates... Certificates OK Started group flash erase EraseArea[0,CMT]: 0x00000000-0x000006BF, NOR EraseArea[0,CMT]: 0x000006C0-0x0001FFFF, NOR EraseArea[0,CMT]: 0x00040000-0x000BFFFF, NOR EraseArea[0,CMT]: 0x000C0000-0x0013FFFF, NOR EraseArea[0,CMT]: 0x00140000-0x0119FFFF, NOR EraseArea[0,CMT]: 0x011A0000-0x0133FFFF, NOR Waiting 320s for erasure finish... Erase taken 90.875s Writing all blocks... Initializing TurboCache... TurboCache Loaded! Writing CMT NOLO Certificate... Writing CMT KEYS Certificate... Writing CMT PRIMAPP Certificate... Writing CMT PASUBTOC Certificate... Writing CMT PAPUBKEYS Certificate... Writing CMT UPDAPP Certificate... Writing CMT DSP0 Certificate... Writing CMT MCUSW Certificate... Programming Status OK! All blocks written OK! Time taken 47.187s Flashing Speed: 3200.36 kBit/S Restarting MCU... Processing rm436__05.20.mcusw (APE)... Processing rm436__05.20.ppm_mr (CMT)... Booting CMT... CMT_SYSTEM_ASIC_ID: 000000010000022600010006030C192101033000 CMT_EM_ASIC_ID: 00000295 CMT_EM_ASIC_ID: 00000B22 CMT_PUBLIC_ID: 090001163C827C567208C482A0D1FA4878FCCFE3 CMT_ASIC_MODE_ID: 00 CMT_ROOT_KEY_HASH: 9DDBFCFE6E73CED7D8C6268C8EB85723 CMT_BOOT_ROM_CRC: 273F6D55 CMT_SECURE_ROM_CRC: DFAAF68F CMT Ready! rm436__05.20.ppm_mr, Type: Flash Image, Algo: BB5, BB5 ALGORITHM Searching for BootCode: DualLine 32Bit RAP3Gv3_2nd.fg, Type: 2nd Boot Loader, Rev: 0.10.42.0, Algo: BB5 Flashbus Write baud set to 1.0Mbits Flashbus Read baud set to 98Kbits Using OLD BB5 FLASHING PROTOCOL If software STUCK HERE with box TX LED lit, that means: 1. You have not attached yellow TX2 Adapter (IT IS REQUIRED FOR BB5 PHONES WHEN USING JAF/UFS CABLES!) 2. Your cable is not TX2 Enabled! 3. Transmission error occured, try again In either cases, you need to reconnect your box from USB. FlashChip[0,CMT]: 0x0089898200008A31, Intel, NOR FlashContent[0,CMT]: 00000000000000000000000000000000, NOR FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC Transmission Mode Requested: Single Line, 8 bit, Accepted: Single Line, 8 bit Searching for BootCode: DualLine 32Bit FlashChip 0x00898982 (Intel), Size: 64MBytes, VPP: 9V RAP3Gv3_algo.fg, Type: Algorithm, Rev: 0.10.40.0, Algo: BB5 ALGORITHM Flashbus Write baud set to 2.0Mbits Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit Box TX2 Data Pin set to: Service Pin 3 Box VPP disabled Internal CMT Phone VPP Enabled PAPUBKEYS Hash for CMT: F1DCA5EA5203CD30A64D4D95ABCD621F4AB23026 Flashbus Write baud set to 5.0Mbits Started group flash erase EraseArea[0,CMT]: 0x01340000-0x01BDFFFF, NOR Waiting 320s for erasure finish... Erase taken 35.906s Writing all blocks... Initializing TurboCache... TurboCache Loaded! Programming Status OK! All blocks written OK! Time taken 16.984s Flashing Speed: 3589.72 kBit/S Restarting MCU... Processing rm436__05.20.ppm_mr (APE)... Processing rm436__05.20.image_mr (CMT)... Booting CMT... CMT_SYSTEM_ASIC_ID: 000000010000022600010006030C192101033000 CMT_EM_ASIC_ID: 00000295 CMT_EM_ASIC_ID: 00000B22 CMT_PUBLIC_ID: 090001163C827C567208C482A0D1FA4878FCCFE3 CMT_ASIC_MODE_ID: 00 CMT_ROOT_KEY_HASH: 9DDBFCFE6E73CED7D8C6268C8EB85723 CMT_BOOT_ROM_CRC: 273F6D55 CMT_SECURE_ROM_CRC: DFAAF68F CMT Ready! rm436__05.20.image_mr, Type: Flash Image, Algo: BB5, BB5 ALGORITHM Searching for BootCode: DualLine 32Bit RAP3Gv3_2nd.fg, Type: 2nd Boot Loader, Rev: 0.10.42.0, Algo: BB5 Flashbus Write baud set to 1.0Mbits Flashbus Read baud set to 98Kbits Using OLD BB5 FLASHING PROTOCOL If software STUCK HERE with box TX LED lit, that means: 1. You have not attached yellow TX2 Adapter (IT IS REQUIRED FOR BB5 PHONES WHEN USING JAF/UFS CABLES!) 2. Your cable is not TX2 Enabled! 3. Transmission error occured, try again In either cases, you need to reconnect your box from USB. FlashChip[0,CMT]: 0x0089898200008A31, Intel, NOR FlashContent[0,CMT]: 00000000000000000000000000000000, NOR FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC Transmission Mode Requested: Single Line, 8 bit, Accepted: Single Line, 8 bit Searching for BootCode: DualLine 32Bit FlashChip 0x00898982 (Intel), Size: 64MBytes, VPP: 9V RAP3Gv3_algo.fg, Type: Algorithm, Rev: 0.10.40.0, Algo: BB5 ALGORITHM Flashbus Write baud set to 2.0Mbits Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit Box TX2 Data Pin set to: Service Pin 3 Box VPP disabled Internal CMT Phone VPP Enabled PAPUBKEYS Hash for CMT: F1DCA5EA5203CD30A64D4D95ABCD621F4AB23026 Flashbus Write baud set to 5.0Mbits Started group flash erase EraseArea[0,CMT]: 0x01BE0000-0x01F7FFFF, NOR EraseArea[0,CMT]: 0x01F80000-0x03FBFFFF, NOR Waiting 320s for erasure finish... Erase taken 63.156s Writing all blocks... Initializing TurboCache... TurboCache Loaded! Programming Status OK! All blocks written OK! Time taken 17.828s Flashing Speed: 3650.92 kBit/S Restarting MCU... Processing rm436__05.20.image_mr (APE)... All images processed OK! Processing post flash tasks... Setting Factory Defaults... Sending User Abort Signal... Sending User Abort Signal... CBUS Request Error -> User abort Sending User Abort Signal... Sending User Abort Signal... Sending User Abort Signal... Sending User Abort Signal... Sending User Abort Signal... Sending User Abort Signal... Sending User Abort Signal... Sending User Abort Signal... Sending User Abort Signal... Sending User Abort Signal... CBUS Request Error -> User abort Failed to enable VBAT -> No answer from CBUS Sending User Abort Signal... Factory defaults OK Failed to Process all Image files -> User Abort |
02-21-2013, 14:48 | #7 (permalink) |
No Life Poster Join Date: Feb 2007 Location: India
Posts: 1,221
Member: 449060 Status: Offline Sonork: 100.1670591 Thanks Meter: 260 | PAPUBKEYS Hash for CMT: F1DCA5EA5203CD30A64D4D95ABCD621F4AB23026 Flashbus Write baud set to 5.0Mbits Sending Certificates... Certificates OK Started group flash erase EraseArea[0,CMT]: 0x00000000-0x000006BF, NOR EraseArea[0,CMT]: 0x000006C0-0x0001FFFF, NOR EraseArea[0,CMT]: 0x00040000-0x000BFFFF, NOR EraseArea[0,CMT]: 0x000C0000-0x0013FFFF, NOR EraseArea[0,CMT]: 0x00140000-0x0119FFFF, NOR EraseArea[0,CMT]: 0x011A0000-0x0133FFFF, NOR Waiting 320s for erasure finish... Erase taken 94.47s Writing all blocks... Initializing TurboCache... TurboCache Loaded! Writing CMT NOLO Certificate... Writing CMT KEYS Certificate... Writing CMT PRIMAPP Certificate... Writing CMT PASUBTOC Certificate... Writing CMT PAPUBKEYS Certificate... Writing CMT UPDAPP Certificate... Writing CMT DSP0 Certificate... Writing CMT MCUSW Certificate... Programming Status OK! All blocks written OK! Time taken 51.781s Flashing Speed: 2925.65 kBit/S Restarting MCU... Processing rm436__07.23.mcusw (APE)... Processing rm436__07.23.ppm_mr (CMT)... Booting CMT... CMT_SYSTEM_ASIC_ID: 000000010000022600010006030C192101033000 CMT_EM_ASIC_ID: 00000295 CMT_EM_ASIC_ID: 00000B22 CMT_PUBLIC_ID: 090001163C827C567208C482A0D1FA4878FCCFE3 CMT_ASIC_MODE_ID: 00 CMT_ROOT_KEY_HASH: 9DDBFCFE6E73CED7D8C6268C8EB85723 CMT_BOOT_ROM_CRC: 273F6D55 CMT_SECURE_ROM_CRC: DFAAF68F CMT Ready! rm436__07.23.ppm_mr, Type: Flash Image, Algo: BB5, BB5 ALGORITHM Searching for BootCode: DualLine 32Bit RAP3Gv3_2nd.fg, Type: 2nd Boot Loader, Rev: 0.10.42.0, Algo: BB5 Flashbus Write baud set to 1.0Mbits Flashbus Read baud set to 98Kbits Using OLD BB5 FLASHING PROTOCOL If software STUCK HERE with box TX LED lit, that means: 1. You have not attached yellow TX2 Adapter (IT IS REQUIRED FOR BB5 PHONES WHEN USING JAF/UFS CABLES!) 2. Your cable is not TX2 Enabled! 3. Transmission error occured, try again In either cases, you need to reconnect your box from USB. FlashChip[0,CMT]: 0x0089898200008A31, Intel, NOR FlashContent[0,CMT]: 00000000000000000000000000000000, NOR FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC Transmission Mode Requested: Single Line, 8 bit, Accepted: Single Line, 8 bit Searching for BootCode: DualLine 32Bit FlashChip 0x00898982 (Intel), Size: 64MBytes, VPP: 9V RAP3Gv3_algo.fg, Type: Algorithm, Rev: 0.10.40.0, Algo: BB5 ALGORITHM Flashbus Write baud set to 2.0Mbits Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit Box TX2 Data Pin set to: Service Pin 3 Box VPP disabled Internal CMT Phone VPP Enabled PAPUBKEYS Hash for CMT: F1DCA5EA5203CD30A64D4D95ABCD621F4AB23026 Flashbus Write baud set to 5.0Mbits Started group flash erase EraseArea[0,CMT]: 0x01340000-0x01BDFFFF, NOR Waiting 320s for erasure finish... Erase taken 38.360s Writing all blocks... Initializing TurboCache... TurboCache Loaded! Programming Status OK! All blocks written OK! Time taken 16.500s Flashing Speed: 3610.18 kBit/S Restarting MCU... Processing rm436__07.23.ppm_mr (APE)... Processing rm436__07.23.image_mr (CMT)... Booting CMT... CMT_SYSTEM_ASIC_ID: 000000010000022600010006030C192101033000 CMT_EM_ASIC_ID: 00000295 CMT_EM_ASIC_ID: 00000B22 CMT_PUBLIC_ID: 090001163C827C567208C482A0D1FA4878FCCFE3 CMT_ASIC_MODE_ID: 00 CMT_ROOT_KEY_HASH: 9DDBFCFE6E73CED7D8C6268C8EB85723 CMT_BOOT_ROM_CRC: 273F6D55 CMT_SECURE_ROM_CRC: DFAAF68F CMT Ready! rm436__07.23.image_mr, Type: Flash Image, Algo: BB5, BB5 ALGORITHM Searching for BootCode: DualLine 32Bit RAP3Gv3_2nd.fg, Type: 2nd Boot Loader, Rev: 0.10.42.0, Algo: BB5 Flashbus Write baud set to 1.0Mbits Flashbus Read baud set to 98Kbits Using OLD BB5 FLASHING PROTOCOL If software STUCK HERE with box TX LED lit, that means: 1. You have not attached yellow TX2 Adapter (IT IS REQUIRED FOR BB5 PHONES WHEN USING JAF/UFS CABLES!) 2. Your cable is not TX2 Enabled! 3. Transmission error occured, try again In either cases, you need to reconnect your box from USB. FlashChip[0,CMT]: 0x0089898200008A31, Intel, NOR FlashContent[0,CMT]: 00000000000000000000000000000000, NOR FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC Transmission Mode Requested: Single Line, 8 bit, Accepted: Single Line, 8 bit Searching for BootCode: DualLine 32Bit FlashChip 0x00898982 (Intel), Size: 64MBytes, VPP: 9V RAP3Gv3_algo.fg, Type: Algorithm, Rev: 0.10.40.0, Algo: BB5 ALGORITHM Flashbus Write baud set to 2.0Mbits Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit Box TX2 Data Pin set to: Service Pin 3 Box VPP disabled Internal CMT Phone VPP Enabled PAPUBKEYS Hash for CMT: F1DCA5EA5203CD30A64D4D95ABCD621F4AB23026 Flashbus Write baud set to 5.0Mbits Started group flash erase EraseArea[0,CMT]: 0x01BE0000-0x01F7FFFF, NOR EraseArea[0,CMT]: 0x01F80000-0x03FBFFFF, NOR Waiting 320s for erasure finish... Erase taken 70.219s Writing all blocks... Initializing TurboCache... TurboCache Loaded! Programming Status OK! All blocks written OK! Time taken 18.765s Flashing Speed: 3692.40 kBit/S Restarting MCU... Processing rm436__07.23.image_mr (APE)... All images processed OK! Processing post flash tasks... Setting Factory Defaults... Factory defaults OK Reading info... MCU Version V 07.23 MCU Date 17-07-09 Product RM-436 (Nokia 7210 Supernova) Manufacturer (c) Nokia IMEI 359310027322999 Mastercode 7510517632 IMEI Spare 3A95130072239209 IMEI SV 3395130072239249F0000000 PPM V 07.23, 17-07-09, RM-436, (c) Nokia , MR CNT Content: mr, V 07.23, 12-08-09, RM-436, (c) Nokia , PSN DTD161510 Product Code 0572571 Module Code 0203868 Basic Product Code 0563951 PSD 0000000000000000 LPSN 0 RETU 15 TAHVO 22 AHNE 30 HW 1001 RFIC 064c0601 DSP ICPR72_09w17 LCD SEIKO BT 2222-143C Failed to read info -> Failed to read SP info Read info thread finished, continuing... Post flash tasks finished! Flashing successfully finished! ------------------------------------------------------------------------------ Step 1, Dumping Unique Data "090001163C827C567208C482A0D1FA4878FCCFE3.B0000EF5 " Exists, That is good... Step 2, Reading Full PM Starting PM read in range 0-512... [1] Reading 15 records [1,0] Reading 12 bytes [1,2] Reading 70 bytes [1,3] Reading 70 bytes [1,4] Reading 70 bytes [1,6] Reading 276 bytes [1,7] Reading 276 bytes [1,8] Reading 276 bytes [1,10] Reading 384 bytes [1,11] Reading 384 bytes [1,12] Reading 384 bytes [1,14] Reading 384 bytes [1,15] Reading 384 bytes [1,16] Reading 384 bytes [1,17] Reading 32 bytes [1,19] Reading 16 bytes [4] Reading 9 records [4,1] Reading 800 bytes [4,3] Reading 10 bytes [4,4] Reading 8 bytes [4,5] Reading 8 bytes [4,6] Reading 8 bytes [4,9] Reading 5 bytes [4,18] Reading 80 bytes [4,19] Reading 4 bytes [4,28] Reading 2 bytes [8] Reading 8 records [8,0] Reading 2 bytes [8,1] Reading 16 bytes [8,2] Reading 16 bytes [8,3] Reading 128 bytes [8,4] Reading 128 bytes [8,8] Reading 8 bytes [8,9] Reading 8 bytes [8,10] Reading 24 bytes [11] Reading 75 records [11,0] Reading 4 bytes [11,1] Reading 4 bytes [11,2] Reading 4 bytes [11,3] Reading 4 bytes [11,4] Reading 1 bytes [11,5] Reading 6 bytes [11,6] Reading 2 bytes [11,7] Reading 1 bytes [11,8] Reading 1 bytes [11,9] Reading 1 bytes [11,10] Reading 1 bytes [11,11] Reading 1 bytes [11,12] Reading 1 bytes [11,13] Reading 1 bytes [11,14] Reading 2 bytes [11,15] Reading 2 bytes [11,16] Reading 2 bytes [11,17] Reading 2 bytes [11,18] Reading 16 bytes [11,19] Reading 32 bytes [11,20] Reading 32 bytes [11,21] Reading 2 bytes [11,22] Reading 2 bytes [11,23] Reading 2 bytes [11,24] Reading 2 bytes [11,25] Reading 2 bytes [11,26] Reading 2 bytes [11,27] Reading 2 bytes [11,28] Reading 2 bytes [11,29] Reading 2 bytes [11,30] Reading 2 bytes [11,31] Reading 2 bytes [11,32] Reading 2 bytes [11,33] Reading 2 bytes [11,34] Reading 2 bytes [11,35] Reading 2 bytes [11,36] Reading 2 bytes [11,37] Reading 2 bytes [11,38] Reading 2 bytes [11,39] Reading 2 bytes [11,40] Reading 2 bytes [11,41] Reading 2 bytes [11,42] Reading 2 bytes [11,43] Reading 2 bytes [11,44] Reading 2 bytes [11,45] Reading 2 bytes [11,46] Reading 2 bytes [11,47] Reading 2 bytes [11,48] Reading 2 bytes [11,49] Reading 2 bytes [11,50] Reading 2 bytes [11,51] Reading 2 bytes [11,52] Reading 2 bytes [11,53] Reading 2 bytes [11,54] Reading 2 bytes [11,55] Reading 2 bytes [11,56] Reading 2 bytes [11,57] Reading 2 bytes [11,58] Reading 2 bytes [11,59] Reading 2 bytes [11,60] Reading 2 bytes [11,61] Reading 2 bytes [11,62] Reading 2 bytes [11,63] Reading 2 bytes [11,64] Reading 2 bytes [11,65] Reading 2 bytes [11,66] Reading 4 bytes [11,67] Reading 1 bytes [11,68] Reading 4 bytes [11,69] Reading 4 bytes [11,70] Reading 4 bytes [11,71] Reading 4 bytes [11,72] Reading 16 bytes [11,73] Reading 4 bytes [11,74] Reading 2 bytes [31] Reading 1 records [31,4] Reading 14 bytes [54] Reading 1 records [54,0] Reading 2 bytes [96] Reading 1 records [96,0] Reading 2 bytes [193] Reading 4 records [193,2] Reading 8 bytes [193,3] Reading 32 bytes [193,4] Reading 32 bytes [193,9] Reading 64 bytes [308] Reading 7 records [308,0] Reading 1 bytes [308,1] Reading 8192 bytes [308,2] Reading 1 bytes [308,3] Reading 1 bytes [308,4] Reading 1 bytes [308,6] Reading 1 bytes [308,7] Reading 1 bytes [309] Reading 9 records [309,0] Reading 4 bytes [309,1] Reading 2 bytes [309,2] Reading 12 bytes [309,4] Reading 12 bytes [309,5] Reading 12 bytes [309,7] Reading 12 bytes [309,8] Reading 12 bytes [309,17] Reading 12 bytes [309,22] Reading 12 bytes [322] Reading 1 records [322,0] Reading 1 bytes [341] Reading 1 records [341,0] Reading 1 bytes [354] Reading 1 records [354,0] Reading 3 bytes [356] Reading 1 records [356,0] Reading 2 bytes PM Read OK, Time taken 13.407s Step 3, Dumping RPL RPL Creation started... Processing CMT Part... Storing Product Code... Storing PSN... Storing HWID... Simlock Store not supported, not a PA_SL2 Phone Trying to store WMDRM RPL... Reading Keys... Failed to read WMDRM Key Reading Security Block... Security block OK and saved to "RM-436_359310027322999_2212013_65658 PM.SecurityBlock.PM" "090001163C827C567208C482A0D1FA4878FCCFE3.B0000EF5 " Exists, That is good... Storing Additional Data... Checking Superdongle Key... Encrypting Superdongle Key... Storing Superdongle Key... Checking CMLA Key... CMLA Key Store Problem -> Failed to decode Security Section, Box Reported: Security Section Not Found (SL3 phone?) Booting CMT... CMT_SYSTEM_ASIC_ID: 000000010000022600010006030C192101033000 CMT_EM_ASIC_ID: 00000295 CMT_EM_ASIC_ID: 00000B22 CMT_PUBLIC_ID: 090001163C827C567208C482A0D1FA4878FCCFE3 CMT_ASIC_MODE_ID: 00 CMT_ROOT_KEY_HASH: 9DDBFCFE6E73CED7D8C6268C8EB85723 CMT_BOOT_ROM_CRC: 273F6D55 CMT_SECURE_ROM_CRC: DFAAF68F CMT Ready! Searching for BootCode: DualLine 32Bit RAP3Gv3_2nd.fg, Type: 2nd Boot Loader, Rev: 0.10.42.0, Algo: BB5 Flashbus Write baud set to 1.0Mbits Flashbus Read baud set to 98Kbits Using OLD BB5 FLASHING PROTOCOL If software STUCK HERE with box TX LED lit, that means: 1. You have not attached yellow TX2 Adapter (IT IS REQUIRED FOR BB5 PHONES WHEN USING JAF/UFS CABLES!) 2. Your cable is not TX2 Enabled! 3. Transmission error occured, try again In either cases, you need to reconnect your box from USB. FlashChip[0,CMT]: 0x0089898200008A31, Intel, NOR FlashContent[0,CMT]: 00000000000000000000000000000000, NOR FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC Transmission Mode Requested: Single Line, 8 bit, Accepted: Single Line, 8 bit Searching for BootCode: DualLine 32Bit FlashChip 0x00898982 (Intel), Size: 64MBytes, VPP: 9V RAP3Gv3_algo.fg, Type: Algorithm, Rev: 0.10.40.0, Algo: BB5 ALGORITHM Flashbus Write baud set to 2.0Mbits Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit Box TX2 Data Pin set to: Service Pin 3 Box VPP disabled Internal CMT Phone VPP Enabled PAPUBKEYS Hash for CMT: F1DCA5EA5203CD30A64D4D95ABCD621F4AB23026 APE Subsystem Not Found Flashbus Write baud set to 5.0Mbits Storing NPC... Storing CCC... Storing HWC... CMT VARIANT Not Found CMT PARTNERC Not Found Restarting MCU... RPL Saved OK Step 4, Full Erase Booting CMT... CMT_SYSTEM_ASIC_ID: 000000010000022600010006030C192101033000 CMT_EM_ASIC_ID: 00000295 CMT_EM_ASIC_ID: 00000B22 CMT_PUBLIC_ID: 090001163C827C567208C482A0D1FA4878FCCFE3 CMT_ASIC_MODE_ID: 00 CMT_ROOT_KEY_HASH: 9DDBFCFE6E73CED7D8C6268C8EB85723 CMT_BOOT_ROM_CRC: 273F6D55 CMT_SECURE_ROM_CRC: DFAAF68F CMT Ready! Searching for BootCode: DualLine 32Bit RAP3Gv3_2nd.fg, Type: 2nd Boot Loader, Rev: 0.10.42.0, Algo: BB5 Flashbus Write baud set to 1.0Mbits Flashbus Read baud set to 98Kbits Using OLD BB5 FLASHING PROTOCOL If software STUCK HERE with box TX LED lit, that means: 1. You have not attached yellow TX2 Adapter (IT IS REQUIRED FOR BB5 PHONES WHEN USING JAF/UFS CABLES!) 2. Your cable is not TX2 Enabled! 3. Transmission error occured, try again In either cases, you need to reconnect your box from USB. FlashChip[0,CMT]: 0x0089898200008A31, Intel, NOR FlashContent[0,CMT]: 00000000000000000000000000000000, NOR FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC Transmission Mode Requested: Single Line, 8 bit, Accepted: Single Line, 8 bit Searching for BootCode: DualLine 32Bit FlashChip 0x00898982 (Intel), Size: 64MBytes, VPP: 9V RAP3Gv3_algo.fg, Type: Algorithm, Rev: 0.10.40.0, Algo: BB5 ALGORITHM Flashbus Write baud set to 2.0Mbits Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit Box TX2 Data Pin set to: Service Pin 3 Box VPP disabled Internal CMT Phone VPP Enabled PAPUBKEYS Hash for CMT: F1DCA5EA5203CD30A64D4D95ABCD621F4AB23026 APE Subsystem Not Found Flashbus Write baud set to 5.0Mbits Erasing flash chip... Started group flash erase EraseArea[0,CMT]: 0x00000000-0x03FFFFFF, NOR Waiting 640s for erasure finish... Erase taken 209.266s Restarting MCU... BB5 Full Erase Finished! Step 4, Full Flash Processing pre flash tasks... Pre flash tasks finished, continuing... Processing rm436__05.20.mcusw (CMT)... Booting CMT... CMT_SYSTEM_ASIC_ID: 000000010000022600010006030C192101033000 CMT_EM_ASIC_ID: 00000295 CMT_EM_ASIC_ID: 00000B22 CMT_PUBLIC_ID: 090001163C827C567208C482A0D1FA4878FCCFE3 CMT_ASIC_MODE_ID: 00 CMT_ROOT_KEY_HASH: 9DDBFCFE6E73CED7D8C6268C8EB85723 CMT_BOOT_ROM_CRC: 273F6D55 CMT_SECURE_ROM_CRC: DFAAF68F CMT Ready! rm436__05.20.mcusw, Type: Flash Image, Algo: BB5, BB5 ALGORITHM Searching for BootCode: DualLine 32Bit RAP3Gv3_2nd.fg, Type: 2nd Boot Loader, Rev: 0.10.42.0, Algo: BB5 Flashbus Write baud set to 1.0Mbits Flashbus Read baud set to 98Kbits Using OLD BB5 FLASHING PROTOCOL If software STUCK HERE with box TX LED lit, that means: 1. You have not attached yellow TX2 Adapter (IT IS REQUIRED FOR BB5 PHONES WHEN USING JAF/UFS CABLES!) 2. Your cable is not TX2 Enabled! 3. Transmission error occured, try again In either cases, you need to reconnect your box from USB. FlashChip[0,CMT]: 0x0089898200008A31, Intel, NOR FlashContent[0,CMT]: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF, NOR FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC Transmission Mode Requested: Single Line, 8 bit, Accepted: Single Line, 8 bit Searching for BootCode: DualLine 32Bit FlashChip 0x00898982 (Intel), Size: 64MBytes, VPP: 9V RAP3Gv3_algo.fg, Type: Algorithm, Rev: 0.10.40.0, Algo: BB5 ALGORITHM Flashbus Write baud set to 2.0Mbits Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit Box TX2 Data Pin set to: Service Pin 3 Box VPP disabled Internal CMT Phone VPP Enabled Warning: PAPUBKEYS Hash Missing! Flashbus Write baud set to 5.0Mbits Sending Certificates... Certificates OK Started group flash erase EraseArea[0,CMT]: 0x00000000-0x000006BF, NOR EraseArea[0,CMT]: 0x000006C0-0x0001FFFF, NOR EraseArea[0,CMT]: 0x00040000-0x000BFFFF, NOR EraseArea[0,CMT]: 0x000C0000-0x0013FFFF, NOR EraseArea[0,CMT]: 0x00140000-0x0119FFFF, NOR EraseArea[0,CMT]: 0x011A0000-0x0133FFFF, NOR Waiting 320s for erasure finish... Erase taken 0.282s Writing all blocks... Initializing TurboCache... TurboCache Loaded! Writing CMT NOLO Certificate... Writing CMT KEYS Certificate... Writing CMT PRIMAPP Certificate... Writing CMT PASUBTOC Certificate... WARNING: CMT PAPUBKEYS Hash is Empty, writing first found PAPUBKEYS Writing CMT PAPUBKEYS Certificate... Writing CMT UPDAPP Certificate... Writing CMT DSP0 Certificate... Writing CMT MCUSW Certificate... Programming Status OK! All blocks written OK! Time taken 55.594s Flashing Speed: 2716.40 kBit/S Restarting MCU... Processing rm436__05.20.mcusw (APE)... Processing rm436__05.20.ppm_mr (CMT)... Booting CMT... CMT_SYSTEM_ASIC_ID: 000000010000022600010006030C192101033000 CMT_EM_ASIC_ID: 00000295 CMT_EM_ASIC_ID: 00000B22 CMT_PUBLIC_ID: 090001163C827C567208C482A0D1FA4878FCCFE3 CMT_ASIC_MODE_ID: 00 CMT_ROOT_KEY_HASH: 9DDBFCFE6E73CED7D8C6268C8EB85723 CMT_BOOT_ROM_CRC: 273F6D55 CMT_SECURE_ROM_CRC: DFAAF68F CMT Ready! rm436__05.20.ppm_mr, Type: Flash Image, Algo: BB5, BB5 ALGORITHM Searching for BootCode: DualLine 32Bit RAP3Gv3_2nd.fg, Type: 2nd Boot Loader, Rev: 0.10.42.0, Algo: BB5 Flashbus Write baud set to 1.0Mbits Flashbus Read baud set to 98Kbits Using OLD BB5 FLASHING PROTOCOL If software STUCK HERE with box TX LED lit, that means: 1. You have not attached yellow TX2 Adapter (IT IS REQUIRED FOR BB5 PHONES WHEN USING JAF/UFS CABLES!) 2. Your cable is not TX2 Enabled! 3. Transmission error occured, try again In either cases, you need to reconnect your box from USB. FlashChip[0,CMT]: 0x0089898200008A31, Intel, NOR FlashContent[0,CMT]: 00000000000000000000000000000000, NOR FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC Transmission Mode Requested: Single Line, 8 bit, Accepted: Single Line, 8 bit Searching for BootCode: DualLine 32Bit FlashChip 0x00898982 (Intel), Size: 64MBytes, VPP: 9V RAP3Gv3_algo.fg, Type: Algorithm, Rev: 0.10.40.0, Algo: BB5 ALGORITHM Flashbus Write baud set to 2.0Mbits Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit Box TX2 Data Pin set to: Service Pin 3 Box VPP disabled Internal CMT Phone VPP Enabled PAPUBKEYS Hash for CMT: F1DCA5EA5203CD30A64D4D95ABCD621F4AB23026 Flashbus Write baud set to 5.0Mbits Started group flash erase EraseArea[0,CMT]: 0x01340000-0x01BDFFFF, NOR Waiting 320s for erasure finish... Erase taken 0.110s Writing all blocks... Initializing TurboCache... TurboCache Loaded! Programming Status OK! All blocks written OK! Time taken 17.79s Flashing Speed: 3569.76 kBit/S Restarting MCU... Processing rm436__05.20.ppm_mr (APE)... Processing rm436__05.20.image_mr (CMT)... Booting CMT... CMT_SYSTEM_ASIC_ID: 000000010000022600010006030C192101033000 CMT_EM_ASIC_ID: 00000295 CMT_EM_ASIC_ID: 00000B22 CMT_PUBLIC_ID: 090001163C827C567208C482A0D1FA4878FCCFE3 CMT_ASIC_MODE_ID: 00 CMT_ROOT_KEY_HASH: 9DDBFCFE6E73CED7D8C6268C8EB85723 CMT_BOOT_ROM_CRC: 273F6D55 CMT_SECURE_ROM_CRC: DFAAF68F CMT Ready! rm436__05.20.image_mr, Type: Flash Image, Algo: BB5, BB5 ALGORITHM Searching for BootCode: DualLine 32Bit RAP3Gv3_2nd.fg, Type: 2nd Boot Loader, Rev: 0.10.42.0, Algo: BB5 Flashbus Write baud set to 1.0Mbits Flashbus Read baud set to 98Kbits Using OLD BB5 FLASHING PROTOCOL If software STUCK HERE with box TX LED lit, that means: 1. You have not attached yellow TX2 Adapter (IT IS REQUIRED FOR BB5 PHONES WHEN USING JAF/UFS CABLES!) 2. Your cable is not TX2 Enabled! 3. Transmission error occured, try again In either cases, you need to reconnect your box from USB. FlashChip[0,CMT]: 0x0089898200008A31, Intel, NOR FlashContent[0,CMT]: 00000000000000000000000000000000, NOR FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC Transmission Mode Requested: Single Line, 8 bit, Accepted: Single Line, 8 bit Searching for BootCode: DualLine 32Bit FlashChip 0x00898982 (Intel), Size: 64MBytes, VPP: 9V RAP3Gv3_algo.fg, Type: Algorithm, Rev: 0.10.40.0, Algo: BB5 ALGORITHM Flashbus Write baud set to 2.0Mbits Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit Box TX2 Data Pin set to: Service Pin 3 Box VPP disabled Internal CMT Phone VPP Enabled PAPUBKEYS Hash for CMT: F1DCA5EA5203CD30A64D4D95ABCD621F4AB23026 Flashbus Write baud set to 5.0Mbits Started group flash erase EraseArea[0,CMT]: 0x01BE0000-0x01F7FFFF, NOR EraseArea[0,CMT]: 0x01F80000-0x03FBFFFF, NOR Waiting 320s for erasure finish... Erase taken 0.359s Writing all blocks... Initializing TurboCache... TurboCache Loaded! Programming Status OK! All blocks written OK! Time taken 17.766s Flashing Speed: 3663.66 kBit/S Restarting MCU... Processing rm436__05.20.image_mr (APE)... All images processed OK! Processing post flash tasks... Setting Factory Defaults... Factory defaults OK Reading info... MCU Version V 05.20 MCU Date 15-10-08 Product RM-436 (Nokia 7210 Supernova) Manufacturer (c) Nokia IMEI 12345610654321? IMEI Spare 1A32541660452301 IMEI SV 1332541660452311F9000000 PPM V 05.20, 15-10-08, RM-436, (c) Nokia , MR CNT Content: mr, V 05.20, 15-10-08, RM-436, (c) Nokia , PSN 0 PSD 0000000000000000 LPSN 0 RETU 15 TAHVO 22 AHNE 30 RFIC 064c0601 DSP ICPR72_08w37 LCD SEIKO BT 2222-143C Failed to read info -> Failed to read SP info Read info thread finished, continuing... Post flash tasks finished! Flashing successfully finished! Step 5, RPL Write Skipping RPL decryption... Parsing decrypted RPL... Processing FBUS Part... Writing Product Code... Failed to Write RPL File -> Product Code not accepted Failed to Proceed with New Downgrade -> Failed to Wr now imei ?????????????????? what next |
02-22-2013, 15:34 | #9 (permalink) |
No Life Poster Join Date: Feb 2007 Location: India
Posts: 1,221
Member: 449060 Status: Offline Sonork: 100.1670591 Thanks Meter: 260 | i update file with v5.61 Internal CMT Phone VPP Enabled PAPUBKEYS Hash for CMT: F1DCA5EA5203CD30A64D4D95ABCD621F4AB23026 APE Subsystem Not Found Flashbus Write baud set to 5.0Mbits Looking NPC for 090001163C827C567208C482A0D1FA4878FCCFE3... Found 090001163C827C567208C482A0D1FA4878FCCFE3.Downgrade Repair.NPC.CMT.crt Backup current NPC... Written to "090001163C827C567208C482A0D1FA4878FCCFE3_2222013_ 75920 PM.Recovery.NPC.CMT.crt" Erasing NPC... Writing NPC... IMEI Recovery Finished --------------------------------------------- MCU Version V 05.61 MCU Date 10-12-08 Product RM-436 (Nokia 7210 Supernova) Manufacturer (c) Nokia IMEI 359310027322999 Mastercode 7510517632 IMEI Spare 3A95130072239209 IMEI SV 3395130072239229F6000000 PPM V 05.61, 10-12-08, RM-436, (c) Nokia , D CNT Content: d_mk, V 05.61, 10-12-08, RM-436, (c) Nokia , PSN 0 PSD 0000000000000000 LPSN 0 RETU 15 TAHVO 22 AHNE 30 RFIC 064c0601 DSP ICPR72_08w47 LCD SEIKO BT 2222-143C Failed to read info -> Failed to read SP info BB5 Unlock Started... MCU Version V 05.61 MCU Date 10-12-08 Product RM-436 (Nokia 7210 Supernova) Manufacturer (c) Nokia IMEI 359310027322999 Mastercode 7510517632 Warning: Failed to read SP Info, Assuming defaults Simlock Server SIMLOCK SERVER Simlock Key 0000000000000000 Simlock Profile Simlock Key Cnt 0 Simlock FBUS Cnt 0 Reading Security Block... Read Security Block Problem -> Failed to read PM 308, this is critical BB5 Unlock Failed -> Failed to read Security Block -------------------------------- v5 done i select rpl calucation direct unlok not work what next sir |
02-23-2013, 03:58 | #10 (permalink) |
No Life Poster Join Date: Feb 2009 Location: CMB/Ceylon
Posts: 8,096
Member: 962029 Status: Offline Sonork: OEM Lock : ON Thanks Meter: 4,126 | Use other tool and delete pm 308,1 308,2 308,3 308,4 And direct unlock with cyclone by tick rpl calculation |
The Following User Says Thank You to Mr.3. For This Useful Post: |
02-23-2013, 08:13 | #11 (permalink) | |
No Life Poster Join Date: Feb 2007 Location: India
Posts: 1,221
Member: 449060 Status: Offline Sonork: 100.1670591 Thanks Meter: 260 | Quote:
sir it camera problem when i remove camera show sp info i erase pm with other tool now it show security test fail what can do with cyclone ? info logo Initializing FBUS... All initialized - Ready to work MCU Version V 07.23 MCU Date 17-07-09 Product RM-436 (Nokia 7210 Supernova) Manufacturer (c) Nokia IMEI 359310027322999 Mastercode 7510517632 IMEI Spare 3A95130072239209 IMEI SV 3395130072239249F0000000 PPM V 07.23, 17-07-09, RM-436, (c) Nokia , MR CNT Content: mr, V 07.23, 12-08-09, RM-436, (c) Nokia , PSN DTD161510 Product Code 0572571 Module Code 0203868 Basic Product Code 0563951 PSD 0000000000000000 LPSN 0 RETU 15 TAHVO 22 AHNE 30 HW 1001 RFIC 064c0601 DSP ICPR72_09w17 LCD SEIKO BT 2222-143C Simlock Server SIMLOCK SERVER Simlock Key 2440700000000000 Simlock Profile 0000000000000000 Simlock Key Cnt 0 Simlock FBUS Cnt 0 Simlock [1,1] State: OPENED Type: MCC-MNC Data: FFFFFF Simlock [1,2] State: OPENED Type: GID Data: FFFF Simlock [1,3] State: OPENED Type: GID Data: FFFF Simlock [1,4] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF Simlock [1,5] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF Simlock [2,1] State: OPENED Type: MCC-MNC Data: FFFFFF Simlock [2,2] State: OPENED Type: GID Data: FFFF Simlock [2,3] State: OPENED Type: GID Data: FFFF Simlock [2,4] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF Simlock [2,5] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF Simlock [3,1] State: OPENED Type: MCC-MNC Data: FFFFFF Simlock [3,2] State: OPENED Type: GID Data: FFFF Simlock [3,3] State: OPENED Type: GID Data: FFFF Simlock [3,4] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF Simlock [3,5] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF Simlock [4,1] State: OPENED Type: MCC-MNC Data: FFFFFF Simlock [4,2] State: OPENED Type: GID Data: FFFF Simlock [4,3] State: OPENED Type: GID Data: FFFF Simlock [4,4] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF Simlock [4,5] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF Simlock [5,1] State: OPENED Type: MCC-MNC Data: FFFFFF Simlock [5,2] State: OPENED Type: GID Data: FFFF Simlock [5,3] State: OPENED Type: GID Data: FFFF Simlock [5,4] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF Simlock [5,5] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF Simlock [6,1] State: OPENED Type: MCC-MNC Data: FFFFFF Simlock [6,2] State: OPENED Type: GID Data: FFFF Simlock [6,3] State: OPENED Type: GID Data: FFFF Simlock [6,4] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF Simlock [6,5] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF Simlock [7,1] State: OPENED Type: MCC-MNC Data: FFFFFF Simlock [7,2] State: OPENED Type: GID Data: FFFF Simlock [7,3] State: OPENED Type: GID Data: FFFF Simlock [7,4] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF Simlock [7,5] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF Auto Selecting Flash Files on User Request... Product Code: 0572571 Scanning avaiable products... Processing F:\nokia firmware\Products\... Found 335 products, Filtering DCT4 Products - wait... 9 Products left after filtering. Ready. This is Valid BB5 Product Variant found for readen Product Data! | |
02-23-2013, 08:14 | #12 (permalink) |
No Life Poster Join Date: Feb 2007 Location: India
Posts: 1,221
Member: 449060 Status: Offline Sonork: 100.1670591 Thanks Meter: 260 | This is Valid BB5 Product Variant found for readen Product Data! Started Phone Security Analysis... MCU Version V 07.23 MCU Date 17-07-09 Product RM-436 (Nokia 7210 Supernova) Manufacturer (c) Nokia IMEI 359310027322999 Mastercode 7510517632 Reading Security Block... Security block OK and saved to "RM-436_359310027322999_2232013_124312 PM.SecurityBlock.PM" Step 1 : Testing SIMLOCK SIMLOCK SEFLTEST PASSED OK! Step 2 : Testing SECURITY -- SECURITY PROBLEM -- Phone have failed SECURITY Test, that means Superdongle Area is DAMAGED! To repair it, simply slick "SX4 Authorization / SD Repair" button. After SX4/SD Repair, don't forget to write PM file with fields 1,309 (if SW don't do this automatically) Additionaly, Checking HWC/CCC Certs... Booting CMT... CMT_SYSTEM_ASIC_ID: 000000010000022600010006030C192101033000 CMT_EM_ASIC_ID: 00000295 CMT_EM_ASIC_ID: 00000B22 CMT_PUBLIC_ID: 090001163C827C567208C482A0D1FA4878FCCFE3 CMT_ASIC_MODE_ID: 00 CMT_ROOT_KEY_HASH: 9DDBFCFE6E73CED7D8C6268C8EB85723 CMT_BOOT_ROM_CRC: 273F6D55 CMT_SECURE_ROM_CRC: DFAAF68F CMT Ready! Searching for BootCode: DualLine 32Bit RAP3Gv3_2nd.fg, Type: 2nd Boot Loader, Rev: 0.10.42.0, Algo: BB5 Flashbus Write baud set to 1.0Mbits Flashbus Read baud set to 98Kbits Using OLD BB5 FLASHING PROTOCOL If software STUCK HERE with box TX LED lit, that means: 1. You have not attached yellow TX2 Adapter (IT IS REQUIRED FOR BB5 PHONES WHEN USING JAF/UFS CABLES!) 2. Your cable is not TX2 Enabled! 3. Transmission error occured, try again In either cases, you need to reconnect your box from USB. FlashChip[0,CMT]: 0x0089898200008A31, Intel, NOR FlashContent[0,CMT]: 00000000000000000000000000000000, NOR FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC Transmission Mode Requested: Single Line, 8 bit, Accepted: Single Line, 8 bit Searching for BootCode: DualLine 32Bit FlashChip 0x00898982 (Intel), Size: 64MBytes, VPP: 9V RAP3Gv3_algo.fg, Type: Algorithm, Rev: 0.10.40.0, Algo: BB5 ALGORITHM Flashbus Write baud set to 2.0Mbits Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit Box TX2 Data Pin set to: Service Pin 3 Box VPP disabled Internal CMT Phone VPP Enabled PAPUBKEYS Hash for CMT: F1DCA5EA5203CD30A64D4D95ABCD621F4AB23026 APE Subsystem Not Found Flashbus Write baud set to 5.0Mbits HWC Looks OK! CCC Looks OK! Restarting MCU... -- SECURITY PROBLEM -- Step 3 : Analyzing Security Block "090001163C827C567208C482A0D1FA4878FCCFE3.B0000EF5 " Exists, That is good... Checking SUPERDONGLE... SUPERDONGLE FOUND AND CHECKSUM OK! PASSED! Checking SIMLOCK... SIMLOCK FOUND AND CHECKSUM OK! PASSED! Checking MCU&DSP TIMESTAMPS... MCU&DSP TIMESTAMPS FOUND AND CHECKSUM OK! PASSED! Checking CMLA KEYS... Failed to decode Security Section, Box Reported: Security Section Not Found (SL3 phone?) Checking ECC KEYS... Failed to decode Security Section, Box Reported: Security Section Not Found (SL3 phone?) Checking DIV KEYS... DIV KEYS FOUND AND CHECKSUM OK! PASSED! Analyze finished! |
02-23-2013, 08:26 | #13 (permalink) |
No Life Poster Join Date: Feb 2007 Location: India
Posts: 1,221
Member: 449060 Status: Offline Sonork: 100.1670591 Thanks Meter: 260 | done done done done now other tool not solve security test always fail but cyclone working grate just do SX4 Authorization / SD Repair Procedure auto select pm file (if read info error just do one time remove camera & do all steps share by Mr.3) thanks sir for fast support add also erase pm opction in cyclone box next update SX4 Authorization / SD Repair Procedure Started.... Failed to obtain Phone Unique Data, Will use Server and Original Card MCU Version V 07.23 MCU Date 17-07-09 Product RM-436 (Nokia 7210 Supernova) Manufacturer (c) Nokia IMEI 359310027322999 Mastercode 7510517632 SX4 Status: Not authorized (74) Started mutual authenthication with card... Cyclone Server (2.0.0.54), Cyclone Box Team 2008-2012 - Ready. Receiving Phone Seed 1... Phone Seed 1 Received Sending calculated Data 1, and expecting Seed 2... Calculated Data 1 accepted, Phone Seed 2 Received Sending calculated Data 2 Calculated Data 2 sent, Checking Authorization Status again Authorization successfully finished! Looking for Virgin PM In Database... Found, writing... [1,0] Written, Length: 12 bytes, Status: OK [1,2] Written, Length: 70 bytes, Status: OK [1,3] Written, Length: 70 bytes, Status: OK [1,4] Written, Length: 70 bytes, Status: OK [1,6] Written, Length: 276 bytes, Status: OK [1,7] Written, Length: 276 bytes, Status: OK [1,8] Written, Length: 276 bytes, Status: OK [1,10] Written, Length: 384 bytes, Status: OK [1,11] Written, Length: 384 bytes, Status: OK [1,12] Written, Length: 384 bytes, Status: OK [1,14] Written, Length: 384 bytes, Status: OK [1,15] Written, Length: 384 bytes, Status: OK [1,16] Written, Length: 384 bytes, Status: OK [1,17] Written, Length: 32 bytes, Status: OK [1,19] Written, Length: 16 bytes, Status: OK [309,0] Written, Length: 4 bytes, Status: OK [309,1] Written, Length: 2 bytes, Status: OK [309,2] Written, Length: 12 bytes, Status: OK [309,4] Written, Length: 12 bytes, Status: OK [309,5] Written, Length: 12 bytes, Status: OK [309,7] Written, Length: 12 bytes, Status: OK [309,8] Written, Length: 12 bytes, Status: OK [309,17] Written, Length: 12 bytes, Status: OK [309,22] Written, Length: 12 bytes, Status: OK Write PM Finished, Record written OK: 24, Record written NOT OK: 0 Disconnected from Cyclone Server MCU Version V 07.23 MCU Date 17-07-09 Product RM-436 (Nokia 7210 Supernova) Manufacturer (c) Nokia IMEI 359310027322999 Mastercode 7510517632 IMEI Spare 3A95130072239209 IMEI SV 3395130072239249F0000000 PPM V 07.23, 17-07-09, RM-436, (c) Nokia , MR CNT Content: mr, V 07.23, 12-08-09, RM-436, (c) Nokia , PSN DTD161510 Product Code 0572571 Module Code 0203868 Basic Product Code 0563951 PSD 0000000000000000 LPSN 0 RETU 15 TAHVO 22 AHNE 30 HW 1001 RFIC 064c0601 DSP ICPR72_09w17 LCD SEIKO BT 2222-143C Simlock Server SIMLOCK SERVER Simlock Key 2440700000000000 Simlock Profile 0000000000000000 Simlock Key Cnt 0 Simlock FBUS Cnt 0 Simlock [1,1] State: OPENED Type: MCC-MNC Data: FFFFFF Simlock [1,2] State: OPENED Type: GID Data: FFFF Simlock [1,3] State: OPENED Type: GID Data: FFFF Simlock [1,4] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF Simlock [1,5] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF Simlock [2,1] State: OPENED Type: MCC-MNC Data: FFFFFF Simlock [2,2] State: OPENED Type: GID Data: FFFF Simlock [2,3] State: OPENED Type: GID Data: FFFF Simlock [2,4] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF Simlock [2,5] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF Simlock [3,1] State: OPENED Type: MCC-MNC Data: FFFFFF Simlock [3,2] State: OPENED Type: GID Data: FFFF Simlock [3,3] State: OPENED Type: GID Data: FFFF Simlock [3,4] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF Simlock [3,5] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF Simlock [4,1] State: OPENED Type: MCC-MNC Data: FFFFFF Simlock [4,2] State: OPENED Type: GID Data: FFFF Simlock [4,3] State: OPENED Type: GID Data: FFFF Simlock [4,4] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF Simlock [4,5] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF Simlock [5,1] State: OPENED Type: MCC-MNC Data: FFFFFF Simlock [5,2] State: OPENED Type: GID Data: FFFF Simlock [5,3] State: OPENED Type: GID Data: FFFF Simlock [5,4] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF Simlock [5,5] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF Simlock [6,1] State: OPENED Type: MCC-MNC Data: FFFFFF Simlock [6,2] State: OPENED Type: GID Data: FFFF Simlock [6,3] State: OPENED Type: GID Data: FFFF Simlock [6,4] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF Simlock [6,5] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF Simlock [7,1] State: OPENED Type: MCC-MNC Data: FFFFFF Simlock [7,2] State: OPENED Type: GID Data: FFFF Simlock [7,3] State: OPENED Type: GID Data: FFFF Simlock [7,4] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF Simlock [7,5] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF Auto Selecting Flash Files on User Request... Product Code: 0572571 This is Valid BB5 Product Variant found for readen Product Data! Selftests to proceed: 29 Passed ST_EAR_DATA_LOOP_TEST Passed ST_SIM_CLK_LOOP_TEST Passed ST_SIM_IO_CTRL_LOOP_TEST Passed ST_SLEEP_X_LOOP_TEST Passed ST_UEM_CBUS_IF_TEST Passed ST_KEYBOARD_STUCK_TEST Failed ST_CAMERA_IF_TEST Passed ST_BACKUP_BATT_TEST Passed ST_LCD_TEST Passed ST_LPRF_IF_TEST Passed ST_LPRF_AUDIO_LINES_TEST Passed ST_CURRENT_CONS_TEST Passed ST_RADIO_TEST Passed ST_BACKLIGHT_TEST Passed ST_SIM_LOCK_TEST Passed ST_SECURITY_TEST Passed ST_BT_WAKEUP_TEST Failed ST_HOOKINT_TEST Passed ST_TAHVOINT_TEST Passed ST_BTEMP_TEST Passed ST_IIC_TEST Passed ST_EXT_DEVICE_TEST Passed ST_CDSP_SLEEPCLK_FREQ_TEST Passed ST_CDSP_SLEEPCLOCK_FREQ_TEST Passed ST_CDSP_RF_BB_IF_TEST Passed ST_CDSP_RF_SUPPLY_TEST Passed ST_CDSP_TX_PLL_PHASE_LOCK_TEST Passed ST_CDSP_RX_IQ_LOOP_BACK_TEST Passed ST_CDSP_GSM_TX_POWER_TEST Selftests done, Tests total: 29, Tests passed: 27, Tests not passed: 2 Setting factory defaults of: Factory set full Factory defaults set OK |
Bookmarks |
Thread Tools | |
Display Modes | |
| |
|