|
Welcome to the GSM-Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. Only registered members may post questions, contact other members or search our database of over 8 million posts. Registration is fast, simple and absolutely free so please - Click to REGISTER! If you have any problems with the registration process or your account login, please contact contact us . |
|
Register | FAQ | Donate | Forum Rules | Root any Device | ★iPhone Unlock★ | ★ Direct Codes ★ | Direct Unlock Source |
| LinkBack | Thread Tools | Display Modes |
06-18-2015, 21:43 | #16 (permalink) |
Insane Poster Join Date: Nov 2014 Location: Chicago,IL
Posts: 63
Member: 2295165 Status: Offline Thanks Meter: 15 | Last edited by mrhunter13; 06-18-2015 at 21:51. |
06-18-2015, 21:49 | #17 (permalink) |
Freak Poster Join Date: Jul 2007
Posts: 106
Member: 554699 Status: Offline Thanks Meter: 52 | @mrhunter13, are you ok with sharing your findings here so that those on the same boat can apply your method to get 3G working on S5's and above? Myself, personally, since I'm on Cricket already, I won't be able to use it...but I'm always interested in learning new things. Thanks. |
06-19-2015, 02:00 | #18 (permalink) |
No Life Poster Join Date: Oct 2014 Location: Guatemala
Posts: 620
Member: 2273678 Status: Offline Thanks Meter: 293 | mrhunter13 it would be deeply appreciated if you may share your knowledge here. As AlpineMan mentioned, it's interesting to learn new things especially for the LG. These were the only devices that gave me a hard time for the keys to stick, honestly never stuck onto the device. I do want to thank you AlpineMan, though I had to learn on my own about brute forcing and using pESN, it is deeply appreciated that you've provided the solution here also to flash onto Boost. Had to do my own digging here and there about a year and a half ago until I got it. Glad to see that you're sharing your knowledge without asking anything but charity donation in return. May you always be blessed for as we give shall we receive. Cheers brother! |
The Following User Says Thank You to F_X For This Useful Post: |
06-19-2015, 04:08 | #19 (permalink) | |
Banned Join Date: Nov 2013 Location: Chicago, IL
Posts: 995
Member: 2076039 Status: Offline Thanks Meter: 648 | Quote:
| |
06-19-2015, 09:41 | #20 (permalink) |
Freak Poster Join Date: Jul 2007
Posts: 106
Member: 554699 Status: Offline Thanks Meter: 52 | We appreciate you sharing @mrhunter13! On a Sprint Galaxy S3 w/ stock Sprint 4.1.3 ROM, you're able to read keys easily. So this is a good phone to pull keys from. I believe the steps below is what needs to be done to get consistent 3G working on flashed Sprint S5's and above. 1. Acquire the brute forced MEID from your S5, S6, etc. via DFS. 2. I'm just going to assume here that you've successfully activated this MEID on Boost. 3. Flash this MEID on the S3 (or another donor that you're able to read keys from). Don't worry about the 32 character AAA key of your S5, S6'etc. (not sure on this one yet). You should know what steps are involved here. If not, see post #1. 4. Reboot the phone. 5. Connect to WiFi. Do an update profile on the S3 or run the Sprint Zone app and activate the S3. 6. If successful, you should be able to read Profile 1 username and AAA key from the S3 using your favorite flashing tool. DFS, QPST, etc. 7. Flash this Profile 1 username and AAA key to your S5, S6, etc. 8. Don't touch your S5, S6's, etc's Profile 0. If my understanding is right, this should get you 3G w/o using a donor. Well...technically you used a donor to pull the keys. On a side note...when you flash an S3 and you forget to backup NV Item 1192, it's funny that you can recover the original value by simply putting the original MEID back on the phone and doing a ##786# reset. This tells me that the original NV Item 1192 is stored somewhere, or perhaps even more intriguing...it may be a calculated value. If it's a calculated value, this means you can put ANY MEID on your S3, do a ##786# reset, and you're able to generate and read NV Item 1192 that's associated with ANY MEID. Again, this is only readable on Android 4.1.3 or below on the Sprint S3. Unfortunately, I do not have edit privileges of my older posts. This means it may be a little harder to piece things together as we discover errors here and there or new things to streamline any steps. Last edited by AlpineMan; 06-19-2015 at 09:48. |
The Following User Says Thank You to AlpineMan For This Useful Post: |
06-19-2015, 13:36 | #21 (permalink) | |
Banned Join Date: Nov 2013 Location: Chicago, IL
Posts: 995
Member: 2076039 Status: Offline Thanks Meter: 648 | Quote:
You can get a S3 higher than 4.1.2 but then youre adb logcatting the keys out of the phone. You cant generate 32 character keys by changing the MEID and doing a RTN. Itll give you the wrong one. I assume its calculated based on HWID (and other variables; not just MEID). It will however restore the ORIGINAL 32 character password. And as far as i know the MEID in the HDR AN long and Profile 0 settings have to be active. Most phones being flashed are blacklisted meaning their MEIDs cannot be active. Therefore if the original MEID is kept in thise settings and the rest of the phone is flashed, itll show 3G, but itll only be on 1xRTT. You need an ACTIVE MEID attached to the HDR AN long and Profile 0 settings to get EVDO Rev.A | |
06-19-2015, 15:51 | #23 (permalink) | |
Insane Poster Join Date: Nov 2014 Location: Chicago,IL
Posts: 63
Member: 2295165 Status: Offline Thanks Meter: 15 | Quote:
| |
06-19-2015, 16:41 | #24 (permalink) | |
Banned Join Date: Nov 2013 Location: Chicago, IL
Posts: 995
Member: 2076039 Status: Offline Thanks Meter: 648 | If you're able to update the profile using the same MEID (the Sprint one) then the phone is still active on Sprint. EVDO Rev.A will work...until that account is no longer in service then you will drop down to 1xRTT. The MEID in the HDR AN long and Profile 0 usernames ([email protected]) NEED to be active for you to get EVDO Rev.A or else you'll just get 1xRTT. Also.... Quote:
| |
06-19-2015, 16:59 | #25 (permalink) | |
Insane Poster Join Date: Nov 2014 Location: Chicago,IL
Posts: 63
Member: 2295165 Status: Offline Thanks Meter: 15 | Quote:
| |
The Following 2 Users Say Thank You to mrhunter13 For This Useful Post: |
06-19-2015, 17:34 | #26 (permalink) |
Freak Poster Join Date: Jul 2007
Posts: 106
Member: 554699 Status: Offline Thanks Meter: 52 | From what @mrhunter13 showed me, post #21 is accurate (except for Android 4.1.3...needs to be 4.1.2) and has all the steps needed to get a unique Profile 1 to get 3G working. It is the same idea that Pageplus flashers use to get keys OTA. |
Bookmarks |
| |
|