GSM Shop GSM Shop
GSM-Forum  

Welcome to the GSM-Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features.
Only registered members may post questions, contact other members or search our database of over 8 million posts.

Registration is fast, simple and absolutely free so please - Click to REGISTER!

If you have any problems with the registration process or your account login, please contact contact us .

Go Back   GSM-Forum > Other Gsm/Mobile Related Forums > GSM Programming & Reverse Engineering


GSM Programming & Reverse Engineering Here you can post all Kind of GSM Programming and Reverse Engineering tools and Secrets.

Reply
 
LinkBack Thread Tools Display Modes
Old 05-05-2011, 22:08   #1 (permalink)
Junior Member
 
Join Date: Jan 2011
Location: Poland
Posts: 3
Member: 1488550
Status: Offline
Thanks Meter: 0
BB5 S40 MCU modyfing?


Hi all.
I tried to modify mcusw in nokia (*#0000# - change name of mcu etc). Flashing process ok but effect? Phone doesn't boot up. Some controllers? I think any byte in mcu is not codded by any security (faid, fsig and fsig_ext probably are not used, only rsa/aes but where?). Some areas in mcu should can be modded without any problems. Next attempt - I modify any byte in mcu. when i flashing:

Code:
Asic CMT: Start programming 49221 KB...
Asic CMT: Programming data sent: 0%
Asic CMT: Programming data sent: 10%
Asic CMT: Programming data sent: 20%
Asic CMT: Programming data sent: 30%
Asic CMT: Programming data sent: 40%
FUR: ALGO reported error in Control Frame. Unable to continue.
ERROR: Programming error reported for asic CMT
-- Error Type        0x05
-- Error Specifier   0x08
-- Of*****ng Addr    0x01A8C400
-- Expected content  0x00008683
-- Detected content  0x0000868D
Error sending programming command 0x8400A814
ERROR Sending status request to Algo! 0x8400A814
Error while programming CMT!
Error when flashing Algo (0x84012283)
Unable to flash phone 0x84012283


Mcusw is file with some sectors:



Every sector as you seen on screen has a hash - it is rap hash, but 11 sector - papubkeys has one more hash - I don't know what hash it's. Sector 11 is not mapped in memory. Sectors which haven't hashes are I think block headers.
Generally: I think papubkeys is "controller" for the mcu, which not allow to boot phone.


Any ideas? Tips? Corrects for me? Thanks a lot and sorry for my language.
  Reply With Quote
Old 08-29-2011, 21:45   #2 (permalink)
No Life Poster
 
kevin168's Avatar
 
Join Date: Sep 2005
Location: INDONESIA
Age: 38
Posts: 795
Member: 183921
Status: Offline
Sonork: 100.1590817
Thanks Meter: 205
did u used trix for that?

br,
  Reply With Quote
Old 08-30-2011, 07:13   #3 (permalink)
No Life Poster
 
g-gabber's Avatar
 
Join Date: Oct 2005
Location: Yes
Posts: 521
Member: 192652
Status: Offline
Sonork: No
Thanks Meter: 121
The firmware is signed by rsa, there is no way to patch bb5 firmware at this moment.
  Reply With Quote
Old 08-30-2011, 20:33   #4 (permalink)
Insane Poster
 
Join Date: Jul 2007
Posts: 77
Member: 542244
Status: Offline
Thanks Meter: 4
u can't only a modified mcu to patcher BB5,coz must read hardware too.
  Reply With Quote
Old 09-01-2011, 22:01   #5 (permalink)
No Life Poster
 
kevin168's Avatar
 
Join Date: Sep 2005
Location: INDONESIA
Age: 38
Posts: 795
Member: 183921
Status: Offline
Sonork: 100.1590817
Thanks Meter: 205
Quote:
Originally Posted by g-gabber View Post
The firmware is signed by rsa, there is no way to patch bb5 firmware at this moment.
How about the Nokia Editor spread on the net?
it can edit some firmware part and repack it.

br,
kevin168
  Reply With Quote
Old 09-02-2011, 04:39   #6 (permalink)
No Life Poster
 
Dzirt's Avatar
 
Join Date: Nov 2009
Location: Syberia
Age: 34
Posts: 12,508
Member: 1157320
Status: Offline
Thanks Meter: 6,192
PPM and CNT are not signed.
  Reply With Quote
The Following User Says Thank You to Dzirt For This Useful Post:
Old 09-02-2011, 22:20   #7 (permalink)
No Life Poster
 
kevin168's Avatar
 
Join Date: Sep 2005
Location: INDONESIA
Age: 38
Posts: 795
Member: 183921
Status: Offline
Sonork: 100.1590817
Thanks Meter: 205
Quote:
Originally Posted by Dzirt View Post
PPM and CNT are not signed.
So not all part in mcu are signed?
as the tool can repack ROFS from Core fspx.

CMIIW

Br,
kevin168
  Reply With Quote
Old 09-03-2011, 02:50   #8 (permalink)
No Life Poster
 
Dzirt's Avatar
 
Join Date: Nov 2009
Location: Syberia
Age: 34
Posts: 12,508
Member: 1157320
Status: Offline
Thanks Meter: 6,192
ROFS repack done funny
If we made TOC change - phone will no longer check it in new FW versions.
I already check some parts - as usual nokia not cover full certs with it, just ROFS1, ROFS2 and ROFS3 part can be changed. If we make other change - phone dead.
And most important - rofs is just a fs image, not a FW part, so, it not secured as weel.

Last edited by Dzirt; 09-03-2011 at 03:00.
  Reply With Quote
The Following User Says Thank You to Dzirt For This Useful Post:
Reply

Bookmarks


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Need full flash 6110 newest mcu Mr_Skoku Nokia Legacy Phones ( DCT-1 ,2 ,3 ,L ) 4 09-11-2001 09:28
PPM and MCU flash boxes - lower prices Zorz Main Sales Section 1 04-14-2001 22:49
MCU EEPROM contents: failed phr3ak Nokia Legacy Phones ( DCT-1 ,2 ,3 ,L ) 0 02-12-2001 15:58
NSB-1 PPM+MCU Sw needed JBU-5_PKD-1 Nokia Legacy Phones ( DCT-1 ,2 ,3 ,L ) 0 01-29-2001 12:55
I want to Byi Solution for Flashing MCU Nokia , for change Version Software!!!!! TNT Wanted Products 0 09-26-2000 17:48

 



All times are GMT +1. The time now is 03:43.



Powered by Searchlight © 2024 Axivo Inc.
vBulletin Optimisation provided by vB Optimise (Pro) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
- GSM Hosting Ltd. - 1999-2023 -
Page generated in 0.26355 seconds with 9 queries

SEO by vBSEO