| No Life Poster
Join Date: Aug 2005 Location: romania-bm Age: 29
Posts: 1,421
Member: 174315
Status: Offline
Thanks: 161
Thanked 123 Times in 98 Posts
| so i made like this:
1. full erase.
2. flashed same product code.
4. write rpl Quote:
Skipping RPL decryption...
Erasing Security...
Booting CMT...
CMT_SYSTEM_ASIC_ID: 000000030000022600010007600C192102031104
CMT_EM_ASIC_ID: 00000C35
CMT_EM_ASIC_ID: 00000C30
CMT_PUBLIC_ID: 1A70011183EE58407398CD61C1E32B58E0FFCFB4
CMT_ASIC_MODE_ID: 00
CMT_ROOT_KEY_HASH: 916F75217F32081248B15C38DFC8E81B
CMT_BOOT_ROM_CRC: E693EF0D
CMT_SECURE_ROM_CRC: AC22615B
CMT Ready!
Searching for BootCode: DualLine 32Bit
RAPUv11_2nd.fg, Type: 2nd Boot Loader, Rev: 768.11.48.0, Algo: BB5
Flashbus Write baud set to 1.0Mbits
Flashbus Read baud set to 98Kbits
Using NEW BB5 FLASHING PROTOCOL
Default Transmission Mode Requested by Loader: Dual Line, 32 bit, Overriding
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
If software STUCK HERE with box TX LED lit, that means:
1. You have not attached yellow TX2 Adapter (IT IS REQUIRED FOR BB5 PHONES WHEN USING JAF/UFS CABLES!)
2. Your cable is not TX2 Enabled!
3. Transmission error occured, try again
In either cases, you need to reconnect your box from USB.
FlashChip[0,CMT]: 0x0000000000000000, Unknown, RAM
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
FlashChip[0,CMT]: 0x0000000000000000, Unknown, NOR
FlashChip[1,CMT]: 0x0000000100000000, Unknown, NOR
FlashChip[0,CMT]: 0x00EC005000000232, Samsung, ONENAND
Requested Algorithm: XSR 1.6 (CMT)
Searching for BootCode: DualLine 32Bit
FlashChip 0x00EC0050 (Samsung), Size: 512MBytes, VPP: Not Supported
RAPUv11_XSR17_alg.fg, Type: Algorithm, Rev: 768.11.48.0, Algo: XSR 1.6
Initializing TurboCache...
TurboCache Loaded!
Writing CMT PASUBTOC Certificate...
Writing CMT ALG Certificate...
CMT Algorithm Ready!
Default Transmission Mode Requested by Loader: Dual Line, 32 bit, Overriding
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
Adding FUR Client (CMT, State: Ready)...
CMT FUR Ready!
Box VPP disabled
Internal CMT Phone VPP Enabled
PAPUBKEYS Hash for CMT: D172C32473AE199B213465ABB3853246F9631231
APE Boot skipped on user request
Flashbus Write baud set to 5.0Mbits
CMT NPC Erased
Restarting MCU...
Parsing decrypted RPL...
Processing FBUS Part...
Writing Simlock...
Handling as SL3 Simlock Data
Handling as SIMLOCK2 Format
Reading Security Block...
Security block OK and saved to "RM-596_12345610654321_5292012_114031 PM.SecurityBlock.PM"
15 Digits NCK Found
Simlock ACCEPTED OK !
Writing Superdongle key...
Superdongle Key ACCEPTED OK !
Writing CMLA key...
CMLA Key NOT ACCEPTED !
Writing WMDRM PD Data...
WMDRM PD Data NOT ACCEPTED !
Processing FLASHBUS Part...
Booting CMT...
CMT_SYSTEM_ASIC_ID: 000000030000022600010007600C192102031104
CMT_EM_ASIC_ID: 00000C35
CMT_EM_ASIC_ID: 00000C30
CMT_PUBLIC_ID: 1A70011183EE58407398CD61C1E32B58E0FFCFB4
CMT_ASIC_MODE_ID: 00
CMT_ROOT_KEY_HASH: 916F75217F32081248B15C38DFC8E81B
CMT_BOOT_ROM_CRC: E693EF0D
CMT_SECURE_ROM_CRC: AC22615B
CMT Ready!
Searching for BootCode: DualLine 32Bit
RAPUv11_2nd.fg, Type: 2nd Boot Loader, Rev: 768.11.48.0, Algo: BB5
Flashbus Write baud set to 1.0Mbits
Flashbus Read baud set to 98Kbits
Using NEW BB5 FLASHING PROTOCOL
Default Transmission Mode Requested by Loader: Dual Line, 32 bit, Overriding
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
If software STUCK HERE with box TX LED lit, that means:
1. You have not attached yellow TX2 Adapter (IT IS REQUIRED FOR BB5 PHONES WHEN USING JAF/UFS CABLES!)
2. Your cable is not TX2 Enabled!
3. Transmission error occured, try again
In either cases, you need to reconnect your box from USB.
FlashChip[0,CMT]: 0x0000000000000000, Unknown, RAM
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
FlashChip[0,CMT]: 0x0000000000000000, Unknown, NOR
FlashChip[1,CMT]: 0x0000000100000000, Unknown, NOR
FlashChip[0,CMT]: 0x00EC005000000232, Samsung, ONENAND
Requested Algorithm: XSR 1.6 (CMT)
Searching for BootCode: DualLine 32Bit
FlashChip 0x00EC0050 (Samsung), Size: 512MBytes, VPP: Not Supported
RAPUv11_XSR17_alg.fg, Type: Algorithm, Rev: 768.11.48.0, Algo: XSR 1.6
Initializing TurboCache...
TurboCache Loaded!
Writing CMT PASUBTOC Certificate...
Writing CMT ALG Certificate...
CMT Algorithm Ready!
Default Transmission Mode Requested by Loader: Dual Line, 32 bit, Overriding
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
Adding FUR Client (CMT, State: Ready)...
CMT FUR Ready!
Box VPP disabled
Internal CMT Phone VPP Enabled
PAPUBKEYS Hash for CMT: D172C32473AE199B213465ABB3853246F9631231
APE Subsystem Not Found
Flashbus Write baud set to 5.0Mbits
CMT NPC Erased
CMT NPC Written
CMT HWC Erased
CMT HWC Written
CMT CCC Erased
CMT CCC Written
Restarting MCU...
Write RPL Finished!
| 5. read pm ( attached here) Quote:
Starting PM read in range 0-512...
[2] Reading 1 records
[2,0] Reading 2808 bytes
[8] Reading 10 records
[8,0] Reading 2 bytes
[8,1] Reading 16 bytes
[8,2] Reading 16 bytes
[8,3] Reading 128 bytes
[8,4] Reading 128 bytes
[8,8] Reading 8 bytes
[8,9] Reading 8 bytes
[8,10] Reading 32 bytes
[8,11] Reading 4 bytes
[8,12] Reading 4 bytes
[11] Reading 5 records
[11,0] Reading 4 bytes
[11,1] Reading 4 bytes
[11,2] Reading 4 bytes
[11,3] Reading 4 bytes
[11,4] Reading 1059 bytes
[12] Reading 1 records
[12,0] Reading 8 bytes
[31] Reading 1 records
[31,4] Reading 10 bytes
[44] Reading 1 records
[44,0] Reading 1 bytes
[50] Reading 1 records
[50,0] Reading 2 bytes
[54] Reading 1 records
[54,0] Reading 2 bytes
[96] Reading 2 records
[96,0] Reading 2 bytes
[96,1] Reading 20 bytes
[120] Reading 4 records
[120,0] Reading 56 bytes
[120,1] Reading 160 bytes
[120,2] Reading 130 bytes
[120,3] Reading 112 bytes
[153] Reading 6 records
[153,0] Reading 68 bytes
[153,1] Reading 68 bytes
[153,2] Reading 68 bytes
[153,3] Reading 68 bytes
[153,4] Reading 68 bytes
[153,5] Reading 68 bytes
[193] Reading 4 records
[193,2] Reading 8 bytes
[193,3] Reading 32 bytes
[193,4] Reading 32 bytes
[193,9] Reading 64 bytes
[217] Reading 1 records
[217,0] Reading 32 bytes
[239] Reading 4 records
[239,0] Reading 2 bytes
[239,1] Reading 3817 bytes
[239,2] Reading 3817 bytes
[239,6] Reading 218 bytes
[291] Reading 1 records
[291,0] Reading 92 bytes
[308] Reading 7 records
[308,0] Reading 1 bytes
[308,1] Reading 8192 bytes
[308,3] Reading 1 bytes
[308,4] Reading 1 bytes
[308,6] Reading 1 bytes
[308,7] Reading 1 bytes
[308,9] Reading 40 bytes
[322] Reading 1 records
[322,0] Reading 1 bytes
[329] Reading 1 records
[329,0] Reading 8392 bytes
[334] Reading 1 records
[334,0] Reading 1 bytes
[341] Reading 3 records
[341,0] Reading 1 bytes
[341,3] Reading 4 bytes
[341,4] Reading 4516 bytes
[354] Reading 1 records
[354,0] Reading 8 bytes
[356] Reading 1 records
[356,0] Reading 2 bytes
[360] Reading 2 records
[360,0] Reading 1 bytes
[360,1] Reading 2 bytes
[369] Reading 1 records
[369,0] Reading 40 bytes
PM Read OK, Time taken 14.390s | analyze security: Quote:
Started Phone Security Analysis...
MCU Version V 92_11w37
MCU Date 14-09-11
Product RM-596 (Nokia N8)
Manufacturer (c) Nokia
IMEI 357919040927121
Mastercode 1267435461
Reading Security Block...
Security block OK and saved to "RM-596_357919040927121_5292012_114557 PM.SecurityBlock.PM"
Step 1 : Testing SIMLOCK
-- SIMLOCK PROBLEM --
Phone have failed SIMLOCK Test, that means Simlock Area is DAMAGED!
To repair simlock area, Select Unlock method : "RPL CALCULATION",
And then click DIRECT UNLOCK. SL Area will be re-formatted.
-- SIMLOCK PROBLEM --
Step 2 : Testing SECURITY
-- SECURITY PROBLEM --
Phone have failed SECURITY Test, that means Superdongle Area is DAMAGED!
To repair it, simply slick "SX4 Authorization / SD Repair" button.
After SX4/SD Repair, don't forget to write PM file with fields 1,309 (if SW don't do this automatically)
Additionaly, Checking HWC/CCC Certs...
Booting CMT...
CMT_SYSTEM_ASIC_ID: 000000030000022600010007600C192102031104
CMT_EM_ASIC_ID: 00000C35
CMT_EM_ASIC_ID: 00000C30
CMT_PUBLIC_ID: 1A70011183EE58407398CD61C1E32B58E0FFCFB4
CMT_ASIC_MODE_ID: 00
CMT_ROOT_KEY_HASH: 916F75217F32081248B15C38DFC8E81B
CMT_BOOT_ROM_CRC: E693EF0D
CMT_SECURE_ROM_CRC: AC22615B
CMT Ready!
Searching for BootCode: DualLine 32Bit
RAPUv11_2nd.fg, Type: 2nd Boot Loader, Rev: 768.11.48.0, Algo: BB5
Flashbus Write baud set to 1.0Mbits
Flashbus Read baud set to 98Kbits
Using NEW BB5 FLASHING PROTOCOL
Default Transmission Mode Requested by Loader: Dual Line, 32 bit, Overriding
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
If software STUCK HERE with box TX LED lit, that means:
1. You have not attached yellow TX2 Adapter (IT IS REQUIRED FOR BB5 PHONES WHEN USING JAF/UFS CABLES!)
2. Your cable is not TX2 Enabled!
3. Transmission error occured, try again
In either cases, you need to reconnect your box from USB.
FlashChip[0,CMT]: 0x0000000000000000, Unknown, RAM
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
FlashChip[0,CMT]: 0x0000000000000000, Unknown, NOR
FlashChip[1,CMT]: 0x0000000100000000, Unknown, NOR
FlashChip[0,CMT]: 0x00EC005000000232, Samsung, ONENAND
Requested Algorithm: XSR 1.6 (CMT)
Searching for BootCode: DualLine 32Bit
FlashChip 0x00EC0050 (Samsung), Size: 512MBytes, VPP: Not Supported
RAPUv11_XSR17_alg.fg, Type: Algorithm, Rev: 768.11.48.0, Algo: XSR 1.6
Initializing TurboCache...
TurboCache Loaded!
Writing CMT PASUBTOC Certificate...
Writing CMT ALG Certificate...
CMT Algorithm Ready!
Default Transmission Mode Requested by Loader: Dual Line, 32 bit, Overriding
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
Adding FUR Client (CMT, State: Ready)...
CMT FUR Ready!
Box VPP disabled
Internal CMT Phone VPP Enabled
PAPUBKEYS Hash for CMT: D172C32473AE199B213465ABB3853246F9631231
APE Subsystem Not Found
Flashbus Write baud set to 5.0Mbits
HWC Looks OK!
CCC Looks OK!
Restarting MCU...
-- SECURITY PROBLEM --
Step 3 : Analyzing Security Block
WARNING: "1A70011183EE58407398CD61C1E32B58E0FFCFB4.C0001D4E " Not Exists, Will read it...
Reading CYC file from phone...
Booting CMT...
CMT_SYSTEM_ASIC_ID: 000000030000022600010007600C192102031104
CMT_EM_ASIC_ID: 00000C35
CMT_EM_ASIC_ID: 00000C30
CMT_PUBLIC_ID: 1A70011183EE58407398CD61C1E32B58E0FFCFB4
CMT_ASIC_MODE_ID: 00
CMT_ROOT_KEY_HASH: 916F75217F32081248B15C38DFC8E81B
CMT_BOOT_ROM_CRC: E693EF0D
CMT_SECURE_ROM_CRC: AC22615B
CMT Ready!
New_RAPUv11_2nd.fg, Type: 2nd Boot Loader, Rev: 768.10.48.1, Algo: BB5
Flashbus Write baud set to 1.0Mbits
Flashbus Read baud set to 98Kbits
Using NEW BB5 FLASHING PROTOCOL
Default Transmission Mode Requested by Loader: Dual Line, 32 bit, Overriding
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
If software STUCK HERE with box TX LED lit, that means:
1. You have not attached yellow TX2 Adapter (IT IS REQUIRED FOR BB5 PHONES WHEN USING JAF/UFS CABLES!)
2. Your cable is not TX2 Enabled!
3. Transmission error occured, try again
In either cases, you need to reconnect your box from USB.
FlashChip[0,CMT]: 0x0000000000000000, Unknown, RAM
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
FlashChip[0,CMT]: 0x0000000000000000, Unknown, NOR
FlashChip[1,CMT]: 0x0000000100000000, Unknown, NOR
FlashChip[0,CMT]: 0x00EC005000000232, Samsung, ONENAND
Requested Algorithm: XSR 1.6 (CMT)
Sending Auxiliary Loader...
Auxiliary Loader Sent!
If software STUCK HERE with box TX LED lit, that means:
1. You have not attached yellow TX2 Adapter (IT IS REQUIRED FOR BB5 PHONES WHEN USING JAF/UFS CABLES!)
2. Your cable is not TX2 Enabled!
3. Transmission error occured, try again
In either cases, you need to reconnect your box from USB.
Loader: RAPxx CommonBoot v1.06 (C) 2011 KarwosLabs
Custom loader running OK! Working...
Readed OK, Saving to "1A70011183EE58407398CD61C1E32B58E0FFCFB4.C0001D4E "
Checking SUPERDONGLE...
SUPERDONGLE FOUND AND CHECKSUM OK! PASSED!
Checking SIMLOCK...
Failed to decode Security Section, Box Reported: Security Section Not Found (SL3 phone?)
Checking MCU&DSP TIMESTAMPS...
MCU&DSP TIMESTAMPS FOUND AND CHECKSUM OK! PASSED!
Checking CMLA KEYS...
CMLA KEYS FOUND AND CHECKSUM OK! PASSED!
Checking ECC KEYS...
ECC KEYS FOUND AND CHECKSUM OK! PASSED!
Checking DIV KEYS...
Failed to decode Security Section, Box Reported: Security Section Not Found (SL3 phone?)
Analyze finished!
| write your pm file: Quote:
[120,0] Written, Length: 56 bytes, Status: OK
[120,1] Written, Length: 160 bytes, Status: OK
[120,2] Written, Length: 154 bytes, Status: OK
[120,3] Written, Length: 112 bytes, Status: OK
Write PM Finished, Record written OK: 4, Record written NOT OK: 0
| |