GSM-Forum

GSM-Forum (https://forum.gsmhosting.com/vbb/)
-   Cyclonebox (https://forum.gsmhosting.com/vbb/f528/)
-   -   Nokia 5800 Korea Show...!!! Unlock Help Please [ SL3 Phone - Use BF Method ] (https://forum.gsmhosting.com/vbb/f528/nokia-5800-korea-show-unlock-help-please-sl3-phone-use-bf-method-1352134/)

slboy 09-23-2011 21:25

Nokia 5800 Korea Show...!!! Unlock Help Please [ SL3 Phone - Use BF Method ]
 
Dear friends,

I'm having a nokia 5800 (RM-356), this has a SP lock, Its service Provider is Korea Show (KTF) MCC = 450 MNC = 08 ,

I bought a cyclone Unlock box to unlock this Nokia 5800, But Its not support for that unlocking,

As many threads mentioned its Root Hash not support yet,

Here are some logs..

Code:

MCU Version    V ICPR72_10w25.3
MCU Date    11-10-10
Product        RM-356 (Nokia 5800 XpressMusic)
Manufacturer    (c) Nokia
IMEI        353xxxxxxxxxxxxxxx
Mastercode    6246543551
IMEI Spare    3A35870124813107
IMEI SV        3335870124813177F0000000
PSN        MNH909948
Product Code    0588613
Module Code    0204538
Basic Product Code    0592754
PSD        0000000000000000
LPSN        0
WLAN MAC    D4CBAFBAA239
RETU        16
TAHVO        22
AHNE        11
HW        1104
RFIC        17141716
DSP        ICPR72_10w16
Simlock Server    SIMLOCK SERVER
Simlock Key    4500000088401881
Simlock Profile    8000000000000000
Simlock Key Cnt    0
Simlock FBUS Cnt    0
Simlock [1,1]    State: CLOSED    Type: 7FFF6F07FFFFFFFF @ E000    Data: 450FFF
Auto Selecting Flash Files on User Request...
Product Code: 0588613
Scanning avaiable products...
No flash paths set! Go to Settings -> Paths and set them!
Scanning avaiable products...
No flash paths set! Go to Settings -> Paths and set them!
No Flash Datapackage installed for this Phone!


================================================================

Started Phone Security Analysis...
MCU Version    V ICPR72_10w25.3
MCU Date    11-10-10
Product        RM-356 (Nokia 5800 XpressMusic)
Manufacturer    (c) Nokia
IMEI        353xxxxxxxxxxxx
Mastercode    6246543551
Reading Security Block...
Security block OK and saved to "RM-356_353781042181378_09242011_15149 AM.SecurityBlock.PM"
Step 1 : Testing SIMLOCK
SIMLOCK SEFLTEST PASSED OK!
Step 2 : Testing SECURITY
SECURITY SEFLTEST PASSED OK!
Step 3 : Analyzing Security Block
WARNING: "16400014F6A1005283F464D3C132F40556B529C5.C000795A" Not Exists, Will read it...
Reading CYC file from phone...
Booting CMT...
CMT_SYSTEM_ASIC_ID:    000000010000022600010006400C192101051103
CMT_EM_ASIC_ID:        00000296
CMT_EM_ASIC_ID:        00000B22
CMT_PUBLIC_ID:        16400014F6A1005283F464D3C132F40556B529C5
CMT_ASIC_MODE_ID:    00
CMT_ROOT_KEY_HASH:    479C6DDE3942E12C429C1D6ADED80371
CMT_BOOT_ROM_CRC:    4B9B7510
CMT_SECURE_ROM_CRC:    3E691FF8
CMT Ready!
New_RAPIDOv11_2nd.fg, Type: 2nd Boot Loader, Rev: 512.11.16.0, Algo: BB5
Flashbus Write baud set to 1.0Mbits
Flashbus Read baud set to 98Kbits
Using NEW BB5 FLASHING PROTOCOL
Default Transmission Mode Requested by Loader: Dual Line, 32 bit, Overriding
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
If software STUCK HERE with box TX LED lit, that means:
1. You have not attached yellow TX2 Adapter (IT IS REQUIRED FOR BB5 PHONES WHEN USING JAF/UFS CABLES!)
2. Your cable is not TX2 Enabled!
3. Transmission error occured, try again
In either cases, you need to reconnect your box from USB.
FlashChip[0,CMT]: 0x0000000000000000, Unknown, RAM
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
FlashChip[0,CMT]: 0x0400000000000000, Unknown, NOR
FlashChip[1,CMT]: 0x0000000100000000, Unknown, NOR
FlashChip[0,CMT]: 0x00EC004000000121, Samsung, ONENAND
Requested Algorithm: XSR 1.5 (CMT)
Sending Auxiliary Loader...
Auxiliary Loader Sent!
If software STUCK HERE with box TX LED lit, that means:
1. You have not attached yellow TX2 Adapter (IT IS REQUIRED FOR BB5 PHONES WHEN USING JAF/UFS CABLES!)
2. Your cable is not TX2 Enabled!
3. Transmission error occured, try again
In either cases, you need to reconnect your box from USB.
Loader: RAPxx CommonBoot v1.06 (C) 2011 KarwosLabs
Custom loader running OK! Working...
Readed OK, Saving to "16400014F6A1005283F464D3C132F40556B529C5.C000795A"
Checking SUPERDONGLE...
SUPERDONGLE FOUND AND CHECKSUM OK! PASSED!
Checking SIMLOCK...
Failed to decode Security Section, Box Reported: Security Section Not Found (SL3 phone?)
Checking MCU&DSP TIMESTAMPS...
MCU&DSP TIMESTAMPS FOUND AND CHECKSUM OK! PASSED!
Checking CMLA KEYS...
Failed to decode Security Section, Box Reported: Security Section Not Found (SL3 phone?)
Checking ECC KEYS...
Failed to decode Security Section, Box Reported: Security Section Not Found (SL3 phone?)
Checking DIV KEYS...
DIV KEYS FOUND AND CHECKSUM OK! PASSED!
Analyze finished!

=======================================================================

Started Reading MCU & DSP Timestamps...
MCU Version    V ICPR72_10w25.3
MCU Date    11-10-10
Product        RM-356 (Nokia 5800 XpressMusic)
Manufacturer    (c) Nokia
IMEI        353xxxxxxxxxxxx
Mastercode    6246543551
Reading Security Block...
Security block OK and saved to "RM-356_353781042181378_09242011_15229 AM.SecurityBlock.PM"
"16400014F6A1005283F464D3C132F40556B529C5.C000795A" Exists, That is good...
Booting CMT...
CMT_SYSTEM_ASIC_ID:    000000010000022600010006400C192101051103
CMT_EM_ASIC_ID:        00000296
CMT_EM_ASIC_ID:        00000B22
CMT_PUBLIC_ID:        16400014F6A1005283F464D3C132F40556B529C5
CMT_ASIC_MODE_ID:    00
CMT_ROOT_KEY_HASH:    479C6DDE3942E12C429C1D6ADED80371
CMT_BOOT_ROM_CRC:    4B9B7510
CMT_SECURE_ROM_CRC:    3E691FF8
CMT Ready!
Searching for BootCode: DualLine 32Bit
RAPIDOv11_2nd.fg, Type: 2nd Boot Loader, Rev: 512.11.24.0, Algo: BB5
Flashbus Write baud set to 1.0Mbits
Flashbus Read baud set to 98Kbits
Using NEW BB5 FLASHING PROTOCOL
Default Transmission Mode Requested by Loader: Dual Line, 32 bit, Overriding
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
If software STUCK HERE with box TX LED lit, that means:
1. You have not attached yellow TX2 Adapter (IT IS REQUIRED FOR BB5 PHONES WHEN USING JAF/UFS CABLES!)
2. Your cable is not TX2 Enabled!
3. Transmission error occured, try again
In either cases, you need to reconnect your box from USB.
FlashChip[0,CMT]: 0x0000000000000000, Unknown, RAM
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
FlashChip[0,CMT]: 0x0400000000000000, Unknown, NOR
FlashChip[1,CMT]: 0x0000000100000000, Unknown, NOR
FlashChip[0,CMT]: 0x00EC004000000121, Samsung, ONENAND
Requested Algorithm: XSR 1.5 (CMT)
Searching for BootCode: DualLine 32Bit
FlashChip 0x00EC0040 (Samsung), Size: 256MBytes, VPP: Not Supported
RAPIDOv11_XSR15_alg.fg, Type: Algorithm, Rev: 512.11.24.0, Algo: XSR 1.5
Initializing TurboCache...
TurboCache Loaded!
Writing CMT PASUBTOC Certificate...
Writing CMT ALG Certificate...
CMT Algorithm Ready!
Default Transmission Mode Requested by Loader: Dual Line, 32 bit, Overriding
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
Adding FUR Client (CMT, State: Ready)...
CMT FUR Ready!
Box VPP disabled
Internal CMT Phone VPP Enabled
PAPUBKEYS Hash for CMT: 76A20187051C30162EE91C77AE5E6011F5F1BA61
APE Boot skipped on user request
Flashbus Write baud set to 5.0Mbits
Reading MCUSW...
Reading DSP0...
Restarting MCU...
------ SECURITY BLOCK TIMESTAMPS ------
Timestamp Slots Detected: 4
Timestamp[1] "AENO", 10/18/2010 5:02:16 PM
Timestamp[1] Hash "BD57CF4E34A49C86A6FCE8D99D23790D154C48D3"
Timestamp[1] Factory MCUSW Timestamp 01/01/1970 5:30:00 AM
Timestamp[1] Dejan Hack Detected
Timestamp[1] ValidAfter Factory MCUSW Test Passed OK!
Timestamp[2] "CMCU", 10/18/2010 5:02:22 PM
Timestamp[2] Hash "690F4A5718AF757260FBED2352DF78553C6EBF28"
Timestamp[2] Factory MCUSW Timestamp 06/09/2009 3:09:26 PM
Timestamp[2] ValidAfter Factory MCUSW Test Passed OK!
Timestamp[3] "CDSP", 10/18/2010 5:02:19 PM
Timestamp[3] Hash "C1859CCF95942CCD09146A5BED6FFF24F559A71C"
Timestamp[3] Factory MCUSW Timestamp 06/09/2009 3:09:26 PM
Timestamp[3] ValidAfter Factory MCUSW Test Passed OK!
Timestamp[4] "AMCU", 10/18/2010 5:02:25 PM
Timestamp[4] Hash "129650BDCC385901AAF91CB9D72E32C633B63885"
Timestamp[4] Factory MCUSW Timestamp 06/09/2009 3:09:26 PM
Timestamp[4] ValidAfter Factory MCUSW Test Passed OK!
-------------------------------------
------ ACTUAL FLASH TIMESTAMPS ------
MCUSW Timestamp 10/18/2010 5:02:22 PM
Flash MCUSW Timestamp synchronized with Security Block MCUSW Timestamp OK!
DSP Timestamp 10/18/2010 5:02:19 PM
Flash DSP Timestamp synchronized with Security Block DSP Timestamp OK!
-------------------------------------
Finished, MCU and DSP Timestamps looks good!



Please hope to get help on this from you guys....

moulnisky 09-23-2011 22:00

This mobile must be unlocked via Bruteforce: it is sl3
Supported since long time

BR

Alex

ptt 09-23-2011 22:06

@slboy

Please do some SEARCH before post

http://img7.imageshack.us/img7/7972/searchmw.png

http://forum.gsmhosting.com/vbb/f528...er-bf-1344008/

http://forum.gsmhosting.com/vbb/f528...ml#post7244445


All times are GMT +1. The time now is 17:56.


vBulletin Optimisation provided by vB Optimise (Pro) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
- GSM Hosting Ltd. - 1999-2023 -

Page generated in 0.10282 seconds with 6 queries

SEO by vBSEO