GSM Shop GSM Shop
GSM-Forum  

Welcome to the GSM-Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features.
Only registered members may post questions, contact other members or search our database of over 8 million posts.

Registration is fast, simple and absolutely free so please - Click to REGISTER!

If you have any problems with the registration process or your account login, please contact contact us .

Go Back   GSM-Forum > Product Support Sections > Hard/Software Products (official support) > 7ICE Team > Mkey - Modem Unlock Key


Reply
 
LinkBack Thread Tools Display Modes
Old 12-20-2018, 14:55   #1 (permalink)
Junior Member
 
Join Date: Oct 2001
Location: Ireland ,Clonmel
Posts: 19
Member: 6809
Status: Offline
Thanks Meter: 2
MF920T can't unlock


Here is a log :

15.49.15 : --------------- Read device information -----------------------
15.49.17 : Found :2.5.0B17P02-28-PC7
15.49.17 : Version :BD_RLFUAMF920TV1.0.0B01
15.49.18 : Firmware :BD_RLFUAMF920T1AV1.0.1B01
15.49.18 : Dashboard :BD_RLFUAMF920TV1.0.0B01
15.49.18 : Unknown sygnature! : ERROR FW

Please help me.
  Reply With Quote
Old 12-22-2018, 12:50   #2 (permalink)
Product Manager
 
TestBox2's Avatar
 
Join Date: May 2008
Location: Ukraine
Age: 45
Posts: 3,234
Member: 772096
Status: Offline
Sonork: 100.69222
Thanks Meter: 8,276
T-version we not unlock directly. Possible try via flashing, but for sure i need get locked samples for researh.
  Reply With Quote
Old 11-27-2019, 08:38   #3 (permalink)
Product Manager
 
TestBox2's Avatar
 
Join Date: May 2008
Location: Ukraine
Age: 45
Posts: 3,234
Member: 772096
Status: Offline
Sonork: 100.69222
Thanks Meter: 8,276
Now we can unlock MF920T

http://forum.gsmhosting.com/vbb/f695/
  Reply With Quote
Old 11-27-2019, 11:52   #4 (permalink)
Freak Poster
 
alirazamanzoor's Avatar
 
Join Date: Apr 2016
Location: Huawei Router/Modem Developer
Age: 33
Posts: 314
Member: 2562113
Status: Offline
Sonork: alirazamanzoor
Thanks Meter: 89
Donate money to this user
Quote:
Originally Posted by TestBox2 View Post
T-version we not unlock directly. Possible try via flashing, but for sure i need get locked samples for researh.
modify only the fs section of the jffs2 modem "ufi_jffs2.img" the remaining sections are saved unchanged.
press the power button on the modem for 10-12 seconds until it is completely turned off and connect the modem by wire to the PC without a SIM card
Must go firmware. If this does not happen, reconnect the modem, run the SCSI.exe utility from the archive and the firmware will start it will take 1-minute in my case it take 2 mint .
  Reply With Quote
Old 11-27-2019, 12:35   #5 (permalink)
Product Manager
 
TestBox2's Avatar
 
Join Date: May 2008
Location: Ukraine
Age: 45
Posts: 3,234
Member: 772096
Status: Offline
Sonork: 100.69222
Thanks Meter: 8,276
Quote:
Originally Posted by alirazamanzoor View Post
modify only the fs section of the jffs2 modem "ufi_jffs2.img" the remaining sections are saved unchanged.
press the power button on the modem for 10-12 seconds until it is completely turned off and connect the modem by wire to the PC without a SIM card
Must go firmware. If this does not happen, reconnect the modem, run the SCSI.exe utility from the archive and the firmware will start it will take 1-minute in my case it take 2 mint .
Exist to much easy way, just replace RSA and auth by yourself keys ;-)

The not Qualcomm where RSA stored in CPU Bootrom, but.. in so0n ZTE this blackdoor will be fixed ..
  Reply With Quote
Old 11-28-2019, 09:04   #6 (permalink)
Freak Poster
 
alirazamanzoor's Avatar
 
Join Date: Apr 2016
Location: Huawei Router/Modem Developer
Age: 33
Posts: 314
Member: 2562113
Status: Offline
Sonork: alirazamanzoor
Thanks Meter: 89
Donate money to this user
Quote:
Originally Posted by TestBox2 View Post
Exist to much easy way, just replace RSA and auth by yourself keys ;-)

The not Qualcomm where RSA stored in CPU Bootrom, but.. in so0n ZTE this blackdoor will be fixed ..
maybe it will possible to get RSA Key Pairs and auth ,But according to my knowledge ,Hash of root certificate in code signature is checked first like qualcomm Phones(new sec) ,It is compared to hash that is stored in onchip OTP memory (qfprom). This check is implemented in PBL (initial platform bootloader, stored in chip's ROM) code. If hashes match then metadata in OEM certificate is checked,same as zong 21.318 sec you can check via UART. Next step is to check code's signature. There's no way to overcome this protection. The only way to produce bootable code that may pass the SB authentication is to sign it with OEM private key from the pair generated by CA with root certificate . But such "OEM" keys are really secret, there's no way to get them.
  Reply With Quote
Old 11-30-2019, 02:00   #7 (permalink)
Product Manager
 
TestBox2's Avatar
 
Join Date: May 2008
Location: Ukraine
Age: 45
Posts: 3,234
Member: 772096
Status: Offline
Sonork: 100.69222
Thanks Meter: 8,276
mf920t-mf903-mf833ft-need-test UNLOCK!
  Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


 



All times are GMT +1. The time now is 13:53.



Powered by Searchlight © 2024 Axivo Inc.
vBulletin Optimisation provided by vB Optimise (Pro) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
- GSM Hosting Ltd. - 1999-2023 -
Page generated in 0.13282 seconds with 8 queries

SEO by vBSEO