GSM-Forum

GSM-Forum (https://forum.gsmhosting.com/vbb/)
-   MXKEY Nokia Flasher and Unlocker (by Alim Hape) (https://forum.gsmhosting.com/vbb/f550/)
-   -   HTI On USB, what this box can do? (https://forum.gsmhosting.com/vbb/f550/hti-usb-what-box-can-do-1443542/)

gbluez 03-15-2012 10:27

HTI On USB, what this box can do?
 
For those who didn't noticed.
HTI can do BACKUP/RESTORE RPL, SX4 AUTH, SUPER SD AUTH, REPAIR SD, BB5 SL3 phones by using only USB cable.

Support USB just like on FBUS for RAPUv1, RAPUv2, BCM21351, RAP3Gv4.


Example, let's play with backup-erase-downgrade.

Step 1.
Connect phone ALIVE to USB. Select phonet device as interface.
Launch Nokia Module, press SCAN

http://forum.gsmhosting.com/vbb/atta...3&d=1331791849

!! Make sure flash files are loaded after phone scanned !!

Step 2.
After phone is scanned, Read PM


http://forum.gsmhosting.com/vbb/atta...4&d=1331791849

Step 3.
Preceed to Backup RPL


http://forum.gsmhosting.com/vbb/atta...5&d=1331791849

Disconnect phone. Close phonet. Choose Nokia USB ROM

Step 4.
Do erase phone.



http://forum.gsmhosting.com/vbb/atta...7&d=1331791931

Click ABORT after erasing is done.

That erase file is nasty, will erase the flash chip fully. Applicable for all BB5 single CPU with NAND flash chip.

After this, you will need to close mobileex, and re-open it. Or simply right click on title bar, choose "Restart App"
Now choose USB ROM as interface


:::: Phone is erased. Now flash any version ::::::

Code:

MXKEY [MxKey Team HTI PLUS Flasher Interface 0], SN: C0696666
Using device: USB ROM  and HTI, FW ver: 00.50, SN: 01001EF9
Connection status: NUSB3XHC:NUSB3HUB::USB 2.00 (High-speed)
Driver: NMWCD, ver: 7.1.32.73
Module ver: 1.0.0.20454(13-03-2012), Library ver: 1.0.0.13962(12-03-2012)
Processing MCU file: rm614__03.35.mcusw
 [BB5,XSR 1.6]  size: 27.66 MB
 Supported Ids: 2200050920030000, 22000509200C0000
Make sure USB cable, Battery and charger are removed from device.
Insert USB cable, Battery back to device(make sure to have fully charged battery).
Insert Charger or Press phone's power button(if flashing doesnt start automatically)
Waiting for USB ROM device ...
CMT SYSTEM ASIC ID: 000000000000000022000509200C0000 [BCM213x1 ver: 1.0]
CMT EM0 ID: 00005361
CMT PUBLIC ID: 0000000000104BBD512FD69E4686046DD0DBD26F
CMT ASIC MODE ID: 00
CMT ROOT KEY HASH: 1B0D74C532CA1C6133940C740E8C786E
CMT ROM ID: DE56D582BDDE7A3A
Loading CMT secondary boot code
 SecondaryBoot: BCM21351_usb2nd.fg [BB5]  version: 11.14.0 revision: 2.1 size: 0x3940
 Supported Ids: 22000209200C0000, 2200020920030000, 22000509200C0000, 2200050920030000
eBB5ProtocolType: NEW
Secondary boot loaded.
Storage0: 0000 0000  - 0000 0000  type: RAM, asic:CMT
Storage1: FFFF 0000  - 0000 0000  type: MMC, asic:CMT
Storage2: FFFF FFFF  - 0000 0000 [unused/removed] type: FLASH,NOR, asic:CMT
Storage3: 0000 0001  - 0000 0000 [unused/removed] type: FLASH,NOR, asic:CMT
Storage4: 00EC 0030  - 0000 0431 [Samsung K5W1G13ACM-DJ60,1 Gbits] type: FLASH,MuxOneNAND, asic:CMT
Suggested algorithm: XSR 1.6
Loading CMT update server data
 Algorithm: BCM21351_XSR16_usbalg.fg [XSR 1.6]  version: 11.14.0 revision: 2.1 size: 0x8FC7D
 Supported Ids: 22000209200C0000, 2200020920030000, 22000509200C0000, 2200050920030000
Update server code loaded.
Waiting for USB device removal ...OK
Waiting for USB device arrival ...OK
Device connected: nmwcdnsucx64\Nokia USB Flashing Generic, PORT_ID: 106B0A9
FUR: Adding Asic CMT as client OK.
CMT PAPUBKEYS is blank/erased.
Storing certificate [NPC, CCC, HWC, RND, R&D] ...OK
Partitioning....
Partitioning complete
Erase size: 33.88 MB
CMT FLASH,MuxOneNAND area [00000000-0001FFFF]
CMT FLASH,MuxOneNAND area [00020000-000203FF]
CMT FLASH,MuxOneNAND area [00060000-012FFFFF]
CMT FLASH,MuxOneNAND area [01300000-01DFFFFF]
CMT FLASH,MuxOneNAND area [02600000-029FFFFF]
Formating partition ...
Flash programming ...
CMT KEYS block sent
CMT ADA block sent
CMT PRIMAPP block sent
CMT RAP3NAND block sent
CMT PASUBTOC block sent
Selecting first CMT PAPUB block with matching RootKey.
CMT PAPUBKEYS: 697F7477 [RAP Certificate v1 232] sent
CMT UPDAPP block sent
CMT MCUSW block sent
CMT MCUSW1 block sent
CMT GENIO_INIT block sent
CMT ISA+DYNSW block sent
Programming completed in 5.842 s
Processing PPM file: rm614__03.35.ppm_x
 [BB5,XSR 1.6]  size: 7.16 MB
 Supported Ids: 2200050920030000, 22000509200C0000
Erase size: 8 MB
CMT FLASH,MuxOneNAND area [01E00000-025FFFFF]
Flash programming ...
Programming completed in 1.489 s
Processing CNT file: rm614__03.35.image_x_0598883
 [BB5,XSR 1.6]  size: 12.36 MB
 Supported Ids: 2200050920030000, 22000509200C0000
Erase size: 75.31 MB
CMT FLASH,MuxOneNAND area [02A00000-0753FFFF]
Formating partition ...
Flash programming ...
Programming completed in 2.723 s
Total time for flashing process(boot+erase+write) was 18.090 s
Waiting for USB device removal ...OK
Waiting for USB device arrival ...OK
[RebootFromFlashMode] Please press "OK" or "Accept" on your phone (if SIM Card is not inserted to the phone) !
 
Waiting for device boot up ...
Device connected: nmwcdc\Nokia C3-00 USB Phonet, PORT_ID: 1FCB7364
Verifying communication to device OK.
 
 
Phone type: RM-614 (C3-00)
SW version: V 03.35 15-05-10 RM-614 (c) Nokia           
Imei plain: 12345610654321-?
Product code: 059G6Z1
Battery voltage: 3983 mV, current: 162 mA
Language Pack:
- not available.

SLPA ver[4]: PA_SL3/PA_SIMLOC30 (15 digit NCK)
warning: avoid SW Downgrade & manual erase to this phone !
Camera config: NI00BC0000040102F201, ver: 001.006
 
SIMLOCK invalid!
SUPERDONGLE_KEY seems to be valid
WMDRM_PD seems to be valid
SIMLOCK_TEST passed
SECURITY_TEST passed
 
 
Imei plain is invalid !!!
SIMLOCK_DATA corrupted!
SIMLOCK_DATA corrupted!

http://forum.gsmhosting.com/vbb/atta...8&d=1331791931


Step 5.
Phone is alive, with corrupted security. Time to restore.
Write readed PM backup on first step.


http://forum.gsmhosting.com/vbb/atta...9&d=1331791931

LAST STEP
Restore IMEI


Code:

RPL: "C:\mobileEx\3.5\data\backup\BB5_35536604659684_BACK.rpl"
Imei: 35536604659684
Updating PRODUCTCODE (059G6Z1)... OK
Updating PSN (752E236AI)... OK
Updating HWID (2009)... OK
Updating SIMLOCK(PA_SL3)...error 0x17
Trying to write SIMLOCK as PM(PA_SL3)...OK
Updating WMDRM_PD ...OK
MXKEY [MxKey Team HTI PLUS Flasher Interface 0], SN: C0696666
Using device: USB Phonet  and HTI, FW ver: 00.50, SN: 01001EF9
Connection status: NUSB3XHC:NUSB3HUB:USB 2.00 (High-speed)
Driver: nmwcdc, ver: 7.1.32.73
Module ver: 1.0.0.20454(13-03-2012), Library ver: 1.0.0.13962(12-03-2012)
Battery voltage: 4011 mV
Phone type: RM-614 (Nokia C3-00)
Product code: 059G6Z1
SW version: V 03.35 - 15-05-10 - RM-614 - (c) Nokia
LanguagePkg version: 5 - 15-05-10 - RM-614 - (c) Nokia            - X
Waiting for USB device removal ...OK
Waiting for USB device arrival ...OK
CMT SYSTEM ASIC ID: 000000000000000022000509200C0000 [BCM213x1 ver: 1.0]
CMT EM0 ID: 00005361
CMT PUBLIC ID: 0000000000104BBD512FD69E4686046DD0DBD26F
CMT ASIC MODE ID: 00
CMT ROOT KEY HASH: 1B0D74C532CA1C6133940C740E8C786E
CMT ROM ID: DE56D582BDDE7A3A
Loading CMT secondary boot code
 SecondaryBoot: BCM21351_usb2nd.fg [BB5]  version: 11.14.0 revision: 2.1 size: 0x3940
 Supported Ids: 22000209200C0000, 2200020920030000, 22000509200C0000, 2200050920030000
eBB5ProtocolType: NEW
Secondary boot loaded.
Storage0: 0000 0000  - 0000 0000  type: RAM, asic:CMT
Storage1: FFFF 0000  - 0000 0000  type: MMC, asic:CMT
Storage2: 0000 0000  - 0000 0000 [unused/removed] type: FLASH,NOR, asic:CMT
Storage3: 0000 0001  - 0000 0000 [unused/removed] type: FLASH,NOR, asic:CMT
Storage4: 00EC 0030  - 0000 0431 [Samsung K5W1G13ACM-DJ60,1 Gbits] type: FLASH,MuxOneNAND, asic:CMT
Suggested algorithm: XSR 1.6
Loading CMT update server data
 Algorithm: BCM21351_XSR16_usbalg.fg [XSR 1.6]  version: 11.14.0 revision: 2.1 size: 0x8FC7D
 Supported Ids: 22000209200C0000, 2200020920030000, 22000509200C0000, 2200050920030000
Update server code loaded.
Waiting for USB device removal ...OK
Waiting for USB device arrival ...OK
Device connected: nmwcdnsucx64\Nokia USB Flashing Generic, PORT_ID: 106B0A9
FUR: Adding Asic CMT as client OK.
Updating CMT  NPC ...OK
Updating CMT  CCC ...OK
Updating CMT  HWC ...OK
Waiting for USB device removal ...OK
Waiting for USB device arrival ...OK
[RebootFromFlashMode] Please press "OK" or "Accept" on your phone (if SIM Card is not inserted to the phone) !
 
Waiting for device boot up ...
Device connected: nmwcdnsucx64\Nokia USB Flashing Generic, PORT_ID: 106B0A9
Waiting for USB device removal ...
Device connected: nmwcdc\Nokia C3-00 USB Phonet, PORT_ID: 18ECCDC1
Verifying communication to device OK.
 
 
Phone type: RM-614 (C3-00)
SW version: V 03.35 15-05-10 RM-614 (c) Nokia           
Imei plain: 35536604659684-3
Product code: 059G6Z1
Battery voltage: 4011 mV, current: 1 mA
Language Pack:
- not available.

SLPA ver[4]: PA_SL3/PA_SIMLOC30 (15 digit NCK)
warning: avoid SW Downgrade & manual erase to this phone !
Camera config: NI00BC0000040102F201, ver: 001.006
 
SIMLOCK seems to be valid
SUPERDONGLE_KEY seems to be valid
WMDRM_PD seems to be valid
SIMLOCK_TEST passed
SECURITY_TEST passed
 
 
Imei net: 355366046596843
Version: SIMLOCK SERVER
Counter: 0/3, 0/10
 
CONFIG_DATA: 2440700000000000
PROFILE_BITS: 0000000000000000
 
BLOCK1: 1=OPEN, 2=OPEN, 3=OPEN, 4=OPEN, 5=OPEN
BLOCK2: 1=OPEN, 2=OPEN, 3=OPEN, 4=OPEN, 5=OPEN
BLOCK3: 1=OPEN, 2=OPEN, 3=OPEN, 4=OPEN, 5=OPEN
BLOCK4: 1=OPEN, 2=OPEN, 3=OPEN, 4=OPEN, 5=OPEN
BLOCK5: 1=OPEN, 2=OPEN, 3=OPEN, 4=OPEN, 5=OPEN
BLOCK6: 1=OPEN, 2=OPEN, 3=OPEN, 4=OPEN, 5=OPEN
BLOCK7: 1=OPEN, 2=OPEN, 3=OPEN, 4=OPEN, 5=OPEN

http://forum.gsmhosting.com/vbb/atta...0&d=1331792110

:::::::::: BACKUP-ERASE-DOWNGRADE-RESTORE DONE ::::::::::::


Can i Repair SD by USB? YES! You can!

How to repair SD by USB

http://forum.gsmhosting.com/vbb/atta...1&d=1331792110

Step 1.
Connect phone ALIVE to USB. Select phonet device as interface.
Launch Nokia Module, press SCAN

!! Make sure flash files are loaded after phone scanned !!

Step 2.
As usual, nothing special :)


http://forum.gsmhosting.com/vbb/atta...2&d=1331792110

ALL DONE

http://forum.gsmhosting.com/vbb/atta...8&d=1331792308
limited to using 10 images


All mentioned functions above are actually exist long time ago. Made this post for those who didn't noticed

These work applicable for RAPUv1, RAPUv2, BCM21351, RAP3Gv4.
Precaution on RAP phone with DCC, you might be will need FBUS to write DCC in this version.

BR

gbluez 03-15-2012 10:28

1 Attachment(s)
Almost forgot.
here is the nasty erase file.

this file can be use with OTHER FLASHER. placed as MCU.


use on your own risk

will post later more tips by USB ;)

gbluez 03-15-2012 10:30

===== reserved page for next tips ==========

raditya 03-15-2012 10:44

firs in the world?by mx key

specta 03-15-2012 11:02

Quote:

Originally Posted by raditya (Post 8233342)
firs in the world?by mx key

i guess rev 1.5 already support this feature... :D






br

marsiyem 03-15-2012 11:19

so simple so strong,,,,,

gbluez 03-15-2012 11:44

Quote:

Originally Posted by specta (Post 8233411)
i guess rev 1.5 already support this feature... :D






br

That kind USB protocols exist since version 3.4.
But new routines for newer phones was added later after that.

pshycoboy 03-15-2012 11:51

nice share om mbul ;);)

HENDRA AMIER 03-15-2012 14:34

explanation is very simple and clear bro
was still much too well aware of and has not been any excess usb

jaggerdude 03-16-2012 02:04

very clear although for newbie like me.
Keep on share

shak409 03-16-2012 11:46

i think you should sticky this

rio_wp 03-16-2012 23:10

Hopefully also apply to other types :)

rizalaa 03-17-2012 00:26

How about if offline,for sx4 for This type RAPUv1, RAPUv2, BCM21351, RAP3Gv4.

tq,

gbluez 03-17-2012 01:20

Quote:

Originally Posted by rio_wp (Post 8238450)
Hopefully also apply to other types :)

Yes, all types on mentioned baseband support only by 100% USB.
Even RAPIDO. But will need help from HTI FBUS after ;)


Quote:

Originally Posted by rizalaa (Post 8238521)
How about if offline,for sx4 for This type RAPUv1, RAPUv2, BCM21351, RAP3Gv4.

tq,

Riza,
For stand alone mode, no need internet.
You can always use Repair SD + Super SD Auth button anytime from your computer.
Same function as SX4


BR

rizalaa 03-17-2012 01:46

Quote:

Originally Posted by gbluez (Post 8238554)

Riza,
For stand alone mode, no need internet.
You can always use Repair SD + Super SD Auth button anytime from your computer.
Same function as SX4


BR

this is a solution... for Mx-key user so do not to be afraid to delete all data in the mobile phone nokia.

thank's kang for replay my question....;);)


All times are GMT +1. The time now is 04:37.


vBulletin Optimisation provided by vB Optimise (Pro) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
- GSM Hosting Ltd. - 1999-2023 -

Page generated in 0.20210 seconds with 6 queries

SEO by vBSEO