|
![]() |
|
Welcome to the GSM-Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact contact us. |
| |||||||
| Register | FAQ | Donate | Forum Rules | ★. iPhone Unlock .★ | -= JTAG BOOM =- | Search | Today's Posts | Mark Forums Read |
![]() |
| | LinkBack | Thread Tools | Display Modes |
| | #1 (permalink) | |
| Product Supporter ![]() ![]() ![]() Join Date: Dec 2006 Location: Karachi, Pakistan Age: 22
Posts: 12,735
Member: 643472 Status: Offline Sonork: 100.96901 Thanks: 6
Thanked 14,156 Times in 3,473 Posts
| How to RECOVER SL3 SIMLOCK DATA from Full Flash for FREE !! Greetings. Here are the steps to RECOVER SIMLOCK DATA from FULL FLASH backup. 1. Read FULL FLASH via ATF Box 2. You must know phone's original Product Code. It can be seen on back side of phone at it's lable or from NPC DATA. NPC can be backup EVEN phone is dead... In my case Product Code is: "059H5S3" 3. Search for your Product Code in Nokia Data Package or Navifirm. Its important because it will tell you phone's original PM120,0. In my case: "RM-775 MEA-7 DARK URDU" So, my phone is Factory unlocked by Nokia and it's Provider Key is: 2440700000000000. Now some Hex work ;-) 4. Use any good HexEditor, I uses HxD. drag and drop FLASH_DUMP.bin to HxD 5. Press Ctrl + F, Search for: "2440700000000000" and DataType: Hex-values We found PM120,0 512 byte(s). But it should be 944 byte(s) if phone have 24407 provider key... If we will look upper, will find the rest 432 byte(s) DATA, too. 512+432 = 944 byte(s). That's mean now our PM120,0 is 100% Oki. Now look little upper, we'll get PM120,2 = 130 byte(s). It will always have "0100" in the end or "01000000" in the end if phone is 20-digits NCK... ![]() Again look upper, and we'll get PM120,1 = 160 byte(s). ![]() So, now we have recovered PM120,0 - PM120,1 and PM120,2. Left PM120,3. We can simply put "000000000000000000000000" of 112 byte(s) ... Since phone was factory unlocked, it will always have "00000000000000000". Few things about PM120: - If phone was Factory unlocked than it will have PM120 like this: PM120,0 = 944 byte(s). PM120,1 = 160 byte(s). PM120,2 = 130 byte(s). or 132 byte(s). If phone is using 20-digit NCK PM120,3 = 112 byte(s). and all ZERO "000000000000000000000000" - If phone was network locked before and u or customer made a unlock of it than look for the original product code and it will tell you what PM120,0 it should have inside and it's length... Also, PM120,3 will be changed here NOT all ZEROs. It will contain your phone's UNLOCK CODE(s). For example PM120,3 112 byte(s): 00000000000000000000000000000000 <---- LEVEL 1 CODE(s) are stored here 00000000000000000000000000000000 <---- LEVEL 2 CODE(s) are stored here 00000000000000000000000000000000 <---- LEVEL 3 CODE(s) are stored here 00000000000000000000000000000000 <---- LEVEL 4 CODE(s) are stored here 00000000000000000000000000000000 <---- LEVEL 5 CODE(s) are stored here 00000000000000000000000000000000 <---- LEVEL 6 CODE(s) are stored here 00000000000000000000000000000000 <---- LEVEL 7 CODE(s) are stored here If phone was locked before, you'll see codes instead of ZEROs. This PM120,3 can also be found near PM120,0 like we found PM120,1 and PM120,2. If it have stored unlock codes inside, else, can put ZEROs of 112 byte(s). Here is the PM120 I recoverd from FullFlash backup: Quote:
Code: 18:45:07 : ================================================ 18:45:07 : Basic Phone Information 18:45:07 : ================================================ 18:45:07 : MCU Version: V 07.32 08-12-11 RM-775 (c) Nokia 18:45:07 : IMEI Plain : 357399045545626 18:45:07 : IMEI Spare : A357399045545620 18:45:07 : IMEI SV : 33573990455456251F 18:45:07 : Category : Phone 18:45:07 : Phone Type : RM-775 18:45:07 : 18:45:07 : ================================================ 18:45:07 : Extended Phone Information 18:45:07 : ================================================ 18:45:07 : Product Serial Number: 0 18:45:07 : Long Production SN : 0 18:45:08 : PPM SW Version : V 07.32 08-12-11 RM-775 (c) Nokia MEC 18:45:08 : BT MCM Version : 4217-v924 18:45:08 : MCU SW Version : V 07.32 08-12-11 RM-775 (c) Nokia 18:45:08 : RFIC Version : |Alli_4.b.1 18:45:08 : DSP Version : 92_PM2_7.32 18:45:08 : LCD Version : TPO 18:45:08 : Content Pack Version : Content: meac_059H5S3 V 07.32 03-02-12 RM-775 (c) Nokia 18:45:08 : AHNE Version : 21 18:45:08 : RETU Version : 51 18:45:08 : TAHVO Version : 00 18:45:08 : Wireless LAN ID : 94:3A:F0:14:FA:7A 18:45:08 : Bluetooth ID : 94:3A:F0:14:AC:5A 18:45:08 : CS Type : GSM850, GSM900, GSM1800, GSM1900, WCDMA I, WCDMA II, WCDMA V, WCDMA VIII 18:45:08 : 18:45:08 : ================================================ 18:45:08 : Simlock Information 18:45:08 : ================================================ 18:45:08 : Unable to read SP Data.. 18:45:08 : SECURITY_TEST : PASSED 18:45:09 : SECURITY_CODE : 12345 18:45:09 : PHONE_MODE : TEST 18:45:09 : 18:45:09 : ================================================ 18:45:09 : Dynamic Camera Configuration 18:45:09 : ================================================ 18:45:09 : DCC ID : 0A4E2007 18:45:09 : DCC Ver: 008005 18:45:09 : Status : OK Logs after write recovered PM120: Code: 18:46:19 : ================================================ 18:46:19 : Basic Phone Information 18:46:19 : ================================================ 18:46:19 : MCU Version: V 07.32 08-12-11 RM-775 (c) Nokia 18:46:19 : IMEI Plain : 357399045545626 18:46:19 : IMEI Spare : A357399045545620 18:46:19 : IMEI SV : 33573990455456251F 18:46:19 : Phone Model: Nokia X3-02.5 18:46:19 : Category : Phone 18:46:19 : Phone Type : RM-775 18:46:19 : 18:46:19 : 18:46:19 : Field : 120 Sub : 0 Byte(s): 944 - Ok 18:46:19 : Field : 120 Sub : 1 Byte(s): 160 - Ok 18:46:19 : Field : 120 Sub : 2 Byte(s): 130 - Ok 18:46:19 : Field : 120 Sub : 3 Byte(s): 112 - Ok 18:46:20 : PM Upload Done!... 18:46:25 : 18:46:25 : Scanning USB Ports... 18:46:25 : 18:46:25 : ================================================ 18:46:25 : Basic Phone Information 18:46:25 : ================================================ 18:46:25 : MCU Version: V 07.32 08-12-11 RM-775 (c) Nokia 18:46:25 : IMEI Plain : 357399045545626 18:46:25 : IMEI Spare : A357399045545620 18:46:25 : IMEI SV : 33573990455456251F 18:46:25 : Phone Model: Nokia X3-02.5 18:46:25 : Category : Phone 18:46:25 : Phone Type : RM-775 18:46:25 : 18:46:25 : ================================================ 18:46:25 : Extended Phone Information 18:46:25 : ================================================ 18:46:25 : Product Serial Number: 0 18:46:25 : Long Production SN : 0 18:46:25 : PPM SW Version : V 07.32 08-12-11 RM-775 (c) Nokia MEC 18:46:25 : BT MCM Version : 4217-v924 18:46:26 : MCU SW Version : V 07.32 08-12-11 RM-775 (c) Nokia 18:46:26 : RFIC Version : |Alli_4.b.1 18:46:26 : DSP Version : 92_PM2_7.32 18:46:26 : LCD Version : TPO 18:46:26 : Content Pack Version : Content: meac_059H5S3 V 07.32 03-02-12 RM-775 (c) Nokia 18:46:26 : AHNE Version : 21 18:46:26 : RETU Version : 51 18:46:26 : TAHVO Version : 00 18:46:26 : Wireless LAN ID : 94:3A:F0:14:FA:7A 18:46:26 : Bluetooth ID : 94:3A:F0:14:AC:5A 18:46:26 : CS Type : GSM850, GSM900, GSM1800, GSM1900, WCDMA I, WCDMA II, WCDMA V, WCDMA VIII 18:46:26 : 18:46:26 : ================================================ 18:46:26 : Simlock Information 18:46:26 : ================================================ 18:46:26 : CONFIG KEY : 0000000000000000 18:46:26 : PROVIDER KEY : 2440700000000000 18:46:26 : NETWORK NAME : Nokia Default;Finland 18:46:26 : LOCK COUNTERS : KEYPRESS 0/3, FBUS 0/10 18:46:26 : SIMLOCK TABLE : 18:46:26 : Block [1] 1:Open 2:Open 3:Open 4:Open 5:Open 18:46:26 : Block [2] 1:Open 2:Open 3:Open 4:Open 5:Open 18:46:26 : Block [3] 1:Open 2:Open 3:Open 4:Open 5:Open 18:46:26 : Block [4] 1:Open 2:Open 3:Open 4:Open 5:Open 18:46:26 : Block [5] 1:Open 2:Open 3:Open 4:Open 5:Open 18:46:26 : Block [6] 1:Open 2:Open 3:Open 4:Open 5:Open 18:46:26 : Block [7] 1:Open 2:Open 3:Open 4:Open 5:Open 18:46:26 : SIMLOCK STATE : Not Locked 18:46:26 : 18:46:26 : SIMLOCK_TYPE : PA_SL3 (15-digit NCK) 18:46:26 : SIMLOCK_TEST : PASSED 18:46:26 : SECURITY_TEST : PASSED 18:46:26 : SECURITY_CODE : 12345 18:46:27 : CMLA_KEY : ABSENT 18:46:27 : SUPER_DONGLE_TEST : PASSED 18:46:27 : 18:46:27 : ================================================ 18:46:27 : SL3 Phone detected 18:46:27 : ================================================ 18:46:27 : 18:46:27 : * Firmware Version Downgrade will KILL PHONE !!! 18:46:27 : * Manual Full Erase WILL KILL PHONE!!! 18:46:27 : * Simlocks are in PM 120 Only... 18:46:27 : * PM 308 is Write Protected... 18:46:27 : 18:46:27 : PHONE_MODE : TEST 18:46:27 : 18:46:27 : ================================================ 18:46:27 : Dynamic Camera Configuration 18:46:27 : ================================================ 18:46:27 : DCC ID : 0A4E2007 18:46:27 : DCC Ver: 008005 18:46:27 : Status : OK | |
| | #2 (permalink) |
| Product Supporter ![]() ![]() ![]() Join Date: Dec 2006 Location: Karachi, Pakistan Age: 22
Posts: 12,735
Member: 643472 Status: Offline Sonork: 100.96901 Thanks: 6
Thanked 14,156 Times in 3,473 Posts
| Hi, Phone was X3-02 RM-775 wrong flashed by Aamir_Zia's brother to RM-639. Logs are available in post # 1. As well I did other flash size(s) phones... 64MB, 128MB, 256MB and 512MB are tested by me... PM120 is not always at same place, different size flash will have different places for simlock... But the method is same for all Flash chips.. I posted above... 1024MB chip will test later when I get phones on hands. Sometime, need look deeper, more complex. But not impossible. As well as NPC, CCC, HWC can be recovered easily... - Bus check phone with ATF and see the CMT_PAPUBEKYS - length: 20 byte(s). - Search for CMT_PAPUBKEYS inside full flash - HexValues, you'll directly get NPC CERTIFICATE.. And after CCC and HWC - just need remove FFFFF between NPC, HWC, CCC.. - Since it can be readout EVEN from DEAD phones, so, no need to waste time.. Better read - much faster than recovering. ;-) BR Last edited by ..::Angel::..; 05-21-2012 at 19:59. Reason: amend post |
| The Following 9 Users Say Thank You to ..::Angel::.. For This Useful Post: |
| | #4 (permalink) | |
| Product Supporter ![]() ![]() ![]() Join Date: Dec 2006 Location: Karachi, Pakistan Age: 22
Posts: 12,735
Member: 643472 Status: Offline Sonork: 100.96901 Thanks: 6
Thanked 14,156 Times in 3,473 Posts
| Quote:
This is important because.. if phone is locked to Vodafone UK: than PM120, 0 - off course will be "2341500000000" and if you'll be searching for "244070000" than even thousands of hours u will spend without results.. ;-) Search for any voda uk product code in Nokia Data Package. You will see like "RM-XXX EURO-VODA UK" - that's mean now we need to find PM120,0 for "23415000000" and also not 944 byte(s). Because its 56 bytes only and You will maybe find these 56 byte(s) few times inside flash. BR | |
| The Following User Says Thank You to ..::Angel::.. For This Useful Post: |
| | #5 (permalink) | |
| Product Supporter ![]() ![]() ![]() Join Date: Dec 2006 Location: Karachi, Pakistan Age: 22
Posts: 12,735
Member: 643472 Status: Offline Sonork: 100.96901 Thanks: 6
Thanked 14,156 Times in 3,473 Posts
| Quote:
5 mins or less job to recover simlock... ;-) And FREEE now If u can't do it than you'll have to buy it... BR | |
| The Following 6 Users Say Thank You to ..::Angel::.. For This Useful Post: |
| | #6 (permalink) |
| Insane Poster ![]() ![]() ![]() Join Date: Apr 2012
Posts: 68
Member: 1751722 Status: Offline Thanks: 205
Thanked 11 Times in 7 Posts
| Very Gud Update from A great team .................thnx but there are many Questions will come after this update ........ 1) how to know phone was locked or unlocked 2) how can we get exact 0,1,2,3 sections of PM120 in ur post u shown end point and length it will b more easy if u mention exact hex values from which value to which is section 0,1,2,3 3) more important how can we get network unlock key if its unlocked by any Oprator ........... thank you Mr.Angel for this gud update Br .::GSMUnlock::. |
| | #7 (permalink) |
| Product Supporter ![]() ![]() ![]() Join Date: Dec 2006 Location: Karachi, Pakistan Age: 22
Posts: 12,735
Member: 643472 Status: Offline Sonork: 100.96901 Thanks: 6
Thanked 14,156 Times in 3,473 Posts
| @.::GSMUnlock::. 1. Search by Product Code.. if you found that phone's original Product code's flash files are like "RM-XXX EURO H3G UK" or any other operator. Than it must be lock/unlock phone by Network unlock for BruteForce ... When you'll get PM120,0 - nearby little more search upper or lower, you'll also get PM120,3. CODE(s) are stored there... If phone is unlock by network codes. LEVEL 1 field will be used. But it can also be BruteForce unlock, mostly, users uses LEVEL 7 for BF unlock.. So, it will be in the end where LEVEL 7 written. You can simply copy these fields AS IS and write as PM. Phone will remain unlocked as it was before. 00000000000000000000000000000000 <---- LEVEL 1 CODE(s) are stored here 00000000000000000000000000000000 <---- LEVEL 2 CODE(s) are stored here 00000000000000000000000000000000 <---- LEVEL 3 CODE(s) are stored here 00000000000000000000000000000000 <---- LEVEL 4 CODE(s) are stored here 00000000000000000000000000000000 <---- LEVEL 5 CODE(s) are stored here 00000000000000000000000000000000 <---- LEVEL 6 CODE(s) are stored here 00000000000000000000000000000000 <---- LEVEL 7 CODE(s) are stored here In simple: You found flash files for XXX Network = phone can be locked or unlocked.. To determine it - you need to look in PM120,3 - if all 112 byte(s) are ZEROs and Flashes you found are appear to be AS XXX Network. Than phone must be LOCKED... And if you found flash files for XXX Network = phone can be locked or unlocked.. To determine it - you need to look in PM120,3 - if all 112 byte(s) are NOT ZERO and first or last 16 byte(s) looks like CODES. Than its unlocked phone by Network or BruteForce... 2. They are NOT always in correct order. Sometime, you'll find PM120,0 first and other in last or sometime you'll find PM120,0 in last and other before it... But the method is: Just hit to ProviderKey and little more search will lead you to other PM120 fields. Need some brain to analyze PMs. If you will success few times - it will become more easy for other next times. 3. I wrote about it in point # 1. CODES are in Hex can easy convert... Well, I had just installed HxD before few days only. And found something USEFULL...so, shared here with all of you. BR |
| The Following 5 Users Say Thank You to ..::Angel::.. For This Useful Post: |
| | #8 (permalink) | |
| Product Supporter ![]() ![]() ![]() Join Date: Mar 2003 Location: Russian NCK, Logs, RPL Server Age: 43
Posts: 3,102
Member: 23684 Status: Offline Sonork: 1582723 Thanks: 314
Thanked 647 Times in 290 Posts
| Quote:
You spent the X-th hours, Y of nerves, Z... , and put result of your hard work for free. Any work should be paid. Would be more reasonable to add function of extraction of SLD from FF to ATF-Box for credits. WBR! | |
| The Following 3 Users Say Thank You to moldovan For This Useful Post: |
| | #10 (permalink) | |
| Product Supporter ![]() ![]() ![]() Join Date: Dec 2006 Location: Karachi, Pakistan Age: 22
Posts: 12,735
Member: 643472 Status: Offline Sonork: 100.96901 Thanks: 6
Thanked 14,156 Times in 3,473 Posts
| Quote:
No... It WILL NOT REPAIR Contact Service.. For example - you have phone in DEAD condition and flash cannot make power on mobile. You can read the Full Flash first.. EXTRACT Full PM120 and RPL you can backup even phone is dead... After EraseFlash and if phone is powered on - u can easy repair SIMLOCK and RPL to make phone fully working. Many phones around which have problem like Vibrate, BlankDisplay, Dead etc... but after Full ERASE/FLASH can power up, so, this is the method to readout PM120 before.... BR | |
| The Following User Says Thank You to ..::Angel::.. For This Useful Post: |
| | #13 (permalink) |
| No Life Poster ![]() ![]() ![]() ![]() ![]() Join Date: May 2005 Location: Mirpur Azad Kashmir.
Posts: 679
Member: 149010 Status: Offline Sonork: 100.1611929 Thanks: 263
Thanked 801 Times in 133 Posts
| I conferm that this is a working method............... the people who cant manage it, will ask for video etc............ |
| | #14 (permalink) |
| Product Supporter ![]() ![]() ![]() Join Date: Dec 2006 Location: Karachi, Pakistan Age: 22
Posts: 12,735
Member: 643472 Status: Offline Sonork: 100.96901 Thanks: 6
Thanked 14,156 Times in 3,473 Posts
| Hi, Open ATF SW... Flashing->ReadFlash->Read Full Flash... File will be saved to: C:\AdvanceBox Turbo Flasher\Nokia\Recovered\Flash_Dump.bin Drag and drop this file to HexEditor and search for SIMLOCK DATA... When you found - save it to .txt and after change .txt to.pm file... You can easy write this PM to phone via simple Write PM function. BR |
| The Following 4 Users Say Thank You to ..::Angel::.. For This Useful Post: |
| | #15 (permalink) | |
| No Life Poster ![]() ![]() ![]() ![]() ![]() Join Date: Aug 2005 Location: Somewhere in Spacetime Age: 37
Posts: 617
Member: 168364 Status: Offline Thanks: 244
Thanked 167 Times in 125 Posts
| Quote:
Very clever, Mr. Ali! It's time to buy my own ATF! ![]() GSM unlock. If phone was previously unlocked by NCK, that must be stored in rpl data. If it's not damaged. That must be the network unlock key. You may also ask information about whether if the phone is factory unlocked/free or not in a Nokia care by IMEI. If PM120 data is damaged, You shall not know information about the phone's last capable configuration's simlock state in normal mode. Invalid data. (Usually Locked I think, because somebody tried to tamper data - if it was not a bad flashing as it was in the first post.) The last address minus length is equal to the start address. You must be careful because of the difference between 15 and 20 digit NCK length. 1 set of 100 is has 20 digit NCK. This method is for recovering w/o buying rpl files. No NCK can be calculated from these data. First recover the read log and calculate key as usual. B R | |
![]() |
| Bookmarks |
| Thread Tools | |
| Display Modes | |
| |
Similar Threads | ||||
| thread | Thread Starter | Forum | Replies | Last Post |
| How to add a language in 51xx/61xx | tati | Nokia Legacy Phones ( DCT-1 , DCT-2 , DCT-3 , DCT-L ) | 8 | 05-21-2013 19:20 |
| Need software upgrade for Nokia 5110 | ptkrf | Nokia Legacy Phones ( DCT-1 , DCT-2 , DCT-3 , DCT-L ) | 26 | 09-25-2012 02:41 |
| How to upload a new firmware... | Brand | Nokia Legacy Phones ( DCT-1 , DCT-2 , DCT-3 , DCT-L ) | 28 | 08-30-2012 03:40 |
| Seeking for flash nokia 5110 old version (3 version) can exchange for new | Tomas | Nokia Legacy Phones ( DCT-1 , DCT-2 , DCT-3 , DCT-L ) | 7 | 11-17-2011 17:08 |