GSM Shop GSM Shop
GSM-Forum  

Welcome to the GSM-Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features.
Only registered members may post questions, contact other members or search our database of over 8 million posts.

Registration is fast, simple and absolutely free so please - Click to REGISTER!

If you have any problems with the registration process or your account login, please contact contact us .

Go Back   GSM-Forum > Other Gsm/Mobile Related Forums > GSM Programming & Reverse Engineering


GSM Programming & Reverse Engineering Here you can post all Kind of GSM Programming and Reverse Engineering tools and Secrets.

Reply
 
LinkBack Thread Tools Display Modes
Old 02-23-2015, 15:56   #1 (permalink)
Moderator
 
Join Date: May 1999
Location: Blagoevgrad, Bulgaria
Age: 52
Posts: 1,056
Member: 73
Status: Offline
Thanks Meter: 537
Donate money to this user
HTC Codes!!!


Anyone to have idea from following:

Why factory codes are different from real unlock codes.


Example:

HTC Desire 310

imei: 351912064140446
factory code: 20164128
real unlock code: 75897934
__________________
You'll die as you lived in a flash of the blade,
in a corner forgotten by no one
You lived for the touch for the feel of the steel
One man, and his honor.

Last edited by Victor; 02-23-2015 at 16:59.
  Reply With Quote
Old 02-24-2015, 23:34   #2 (permalink)
No Life Poster
 
Join Date: Jun 2004
Location: USA
Age: 39
Posts: 1,142
Member: 67927
Status: Offline
Thanks Meter: 108
Some carriers change code in phone that comes from factory. Maybe that's why?
  Reply With Quote
Old 02-25-2015, 06:06   #3 (permalink)
Moderator
 
Join Date: May 1999
Location: Blagoevgrad, Bulgaria
Age: 52
Posts: 1,056
Member: 73
Status: Offline
Thanks Meter: 537
Donate money to this user
Quote:
Originally Posted by dest View Post
Some carriers change code in phone that comes from factory. Maybe that's why?
Yes I know that. And asking if anybody dig in that mathematics.


Here is the question:

- Operator change code? (no logic in this)
- Or Phone come from factory with code and PREPARED LOCK.
- Or phone have automatic mechanism to self change code as HTC ONE S.


Regards: Victor
__________________
You'll die as you lived in a flash of the blade,
in a corner forgotten by no one
You lived for the touch for the feel of the steel
One man, and his honor.
  Reply With Quote
Old 02-26-2015, 00:34   #4 (permalink)
No Life Poster
 
Join Date: Mar 2009
Location: Europe Wienna
Posts: 1,269
Member: 984046
Status: Offline
Thanks Meter: 255
Htc phones are branded and simlocked in regional rework ASC's.


Haltec
  Reply With Quote
Old 03-04-2015, 17:47   #5 (permalink)
102
Insane Poster
 
Join Date: Jan 2013
Posts: 65
Member: 1876160
Status: Offline
Thanks Meter: 30
Quote:
Originally Posted by Victor View Post
Yes I know that. And asking if anybody dig in that mathematics.


Here is the question:

- Operator change code? (no logic in this)
- Or Phone come from factory with code and PREPARED LOCK.
- Or phone have automatic mechanism to self change code as HTC ONE S.


Regards: Victor
What’s a ‘branded’ phone then?
A branded phone will have your carrier’s logo during boot (usually), and it will also usually have apps which are installed by the carrier and cannot be removed.

Then I think Operator changed this code.
  Reply With Quote
Old 03-04-2015, 20:01   #6 (permalink)
No Life Poster
 
jodge's Avatar
 
Join Date: Apr 2004
Posts: 753
Member: 61389
Status: Offline
Thanks Meter: 193
I'v already asked earlier my direct code supporter (local carrirer employee). They don't do anything with the phones. It's a factory business
  Reply With Quote
Old 03-07-2015, 14:14   #7 (permalink)
Banned
 
Join Date: Nov 2013
Location: Chicago, IL
Posts: 995
Member: 2076039
Status: Offline
Thanks Meter: 648
Donate money to this user
Quote:
Originally Posted by 102 View Post
What’s a ‘branded’ phone then?
A branded phone will have your carrier’s logo during boot (usually), and it will also usually have apps which are installed by the carrier and cannot be removed.

Then I think Operator changed this code.
The boot logo can be changed easily. The apps can too. These both relate to The AP side of things whereas SIM locks are on the CP/BP side of the phone.
  Reply With Quote
Old 03-07-2015, 16:32   #8 (permalink)
Cheater -Don't Deal with him-
 
Join Date: Dec 2013
Location: XK
Age: 26
Posts: 1,479
Member: 2089356
Status: Offline
Sonork: Threema: 3N5W6VV9
Thanks Meter: 520
Donate money to this user
Also victor, I have same question like you, some of htc codes always fail, and replay i get is operator changed codes ! and i also talked directly to my sources inside operator ! they are to bassic on encoding ! they don't change anything, and also i wonder ! how some get complete htc database ! how they taken !
i am glad victor for opening this thread, i am sure we will get an answer. !
  Reply With Quote
Old 03-08-2015, 01:38   #9 (permalink)
Freak Poster
 
loniryan's Avatar
 
Join Date: Oct 2014
Location: efs
Age: 33
Posts: 496
Member: 2279944
Status: Offline
Sonork: not avaliable
Thanks Meter: 167
this code writen on ''htc p51'' partition.. near imei area..i can acces it via jtag...it has written by htc ''manufecter'' during first flash in hex format...alsohtc is sharing sim locks and factory codes with operators which buy this models from (High Tech Computers)HTC.

simlock code is NCK CODE
  Reply With Quote
Old 03-09-2015, 16:43   #10 (permalink)
Freak Poster
 
Join Date: Feb 2012
Posts: 304
Member: 1720169
Status: Offline
Thanks Meter: 77
factory code unlocks all level access
and real code or carrier code is only one level code
  Reply With Quote
Old 03-09-2015, 17:57   #11 (permalink)
Moderator
 
Join Date: May 1999
Location: Blagoevgrad, Bulgaria
Age: 52
Posts: 1,056
Member: 73
Status: Offline
Thanks Meter: 537
Donate money to this user
Quote:
Originally Posted by amitgoody View Post
factory code unlocks all level access
and real code or carrier code is only one level code
Not 100% but is similar. Factory codes are as default codes on all levels. And lock is with customized code.
__________________
You'll die as you lived in a flash of the blade,
in a corner forgotten by no one
You lived for the touch for the feel of the steel
One man, and his honor.
  Reply With Quote
Old 03-09-2015, 23:34   #12 (permalink)
No Life Poster
 
jodge's Avatar
 
Join Date: Apr 2004
Posts: 753
Member: 61389
Status: Offline
Thanks Meter: 193
Quote:
Originally Posted by loniryan View Post
this code writen on ''htc p51'' partition.. near imei area..i can acces it via jtag...it has written by htc ''manufecter'' during first flash in hex format...alsohtc is sharing sim locks and factory codes with operators which buy this models from (High Tech Computers)HTC.

simlock code is NCK CODE
not always stored in the p51. Just If the phone QC based (Tegra and MTK not the same at all) just the old desire series...the ONE series using different partition and encoding... etc
The p51 business is just a small part.

The nck-imei-cid are simple plain text. No crc, no any kind protection The simlock area sometimes encoded with AES128 like the desireX Or the desire300 sometimes not like the desire500 and desireC. I belive it's a simple bug. And lot more bugs (I'v seen some interesing things in IDA )

If you have root acces you don't need jtag. In this case you able to dump all partitions.
  Reply With Quote
The Following User Says Thank You to jodge For This Useful Post:
Old 03-10-2015, 00:16   #13 (permalink)
Freak Poster
 
loniryan's Avatar
 
Join Date: Oct 2014
Location: efs
Age: 33
Posts: 496
Member: 2279944
Status: Offline
Sonork: not avaliable
Thanks Meter: 167
İ think i have to learn from you how to dump partition with just root acces and a little commands,
  Reply With Quote
Old 03-10-2015, 00:21   #14 (permalink)
Moderator
 
Join Date: May 1999
Location: Blagoevgrad, Bulgaria
Age: 52
Posts: 1,056
Member: 73
Status: Offline
Thanks Meter: 537
Donate money to this user
... Another pair!

Code:
GBKey 1.72
Model selected : HTC Desire 310
Power off the phone and insert USB cable now...
Detected : PreLoader USB VCOM Port (COM13)
Waiting response...
Detected : Gadget CDC VCOM Driver (COM29)
Connecting...
Reading info...
IMEI  : 351912063566211
Connecting...
Connected to server Ok
Checking GBKey...
GBKey Ok

Model       : HTC Desire 310
IMEI        : 351912063566211
NW  Lock    : OPEN   Code : 30096139 <<<<<------------ CUSTOMIZED CODE
NS  Lock    : OPEN   Code : 09844488 <<<<<------------ FACTORY CODE
SP  Lock    : OPEN   Code : 09844488
CP  Lock    : OPEN
SIM Lock    : OPEN
Writing info...

Unlocked Ok
__________________
You'll die as you lived in a flash of the blade,
in a corner forgotten by no one
You lived for the touch for the feel of the steel
One man, and his honor.
  Reply With Quote
Old 03-10-2015, 08:53   #15 (permalink)
No Life Poster
 
jodge's Avatar
 
Join Date: Apr 2004
Posts: 753
Member: 61389
Status: Offline
Thanks Meter: 193
yepp as a said the MTK platform totally different

here is a qc platform desire500 p51 screenshot

https://www.dropbox.com/s/ukda4qs442gvmqu/hexa.PNG?dl=0
there is just the provider and the nck nothing more

@loniryan

Code:
adb shell
su
dd if=/dev/block/mmcblk0p7 of=/sdcard/htc.bin
  Reply With Quote
The Following 2 Users Say Thank You to jodge For This Useful Post:
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


 



All times are GMT +1. The time now is 03:38.



Powered by Searchlight © 2024 Axivo Inc.
vBulletin Optimisation provided by vB Optimise (Pro) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
- GSM Hosting Ltd. - 1999-2023 -
Page generated in 0.24161 seconds with 8 queries

SEO by vBSEO