GSM Shop GSM Shop
GSM-Forum  

Welcome to the GSM-Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features.
Only registered members may post questions, contact other members or search our database of over 8 million posts.

Registration is fast, simple and absolutely free so please - Click to REGISTER!

If you have any problems with the registration process or your account login, please contact contact us .

Go Back   GSM-Forum > Other Gsm/Mobile Related Forums > GSM Programming & Reverse Engineering


GSM Programming & Reverse Engineering Here you can post all Kind of GSM Programming and Reverse Engineering tools and Secrets.

Reply
 
LinkBack Thread Tools Display Modes
Old 01-29-2007, 23:03   #1 (permalink)
Freak Poster
 
dorian2004's Avatar
 
Join Date: May 2004
Location: Ukraine-Lugansk
Age: 44
Posts: 473
Member: 67246
Status: Offline
Thanks Meter: 70
Cool Nok BB-5 Unlock idea !


Hi by All users of this forum.


This methode is not original and i think this methode we posible used as templaty unlock solution .

When you ask me about why i say the - i am repeat about i am not a first have this idea . This idea have realiced from software engineer from our country . In fact i not publish hes name and i know this way from he opened BB5 unlock solution.


************************************************** ********

How to want to make uunlock ? - from next 4x thread i write .

This unlock work to be fine via Flash patch and no more .

I need 20 locked phones and 20 unlock codes .
I need UP 1024 device and 2-4 monts of job .


How to work ! >

In first i want desoldered flash and put to UP 1024 programmer .
New i have extract flash file from chip.

Next we soldering flash chip to phone and unlock via code.


After we new make extract flash chip and disasemple sourse code .


When we seen algo - we make patch addon .

************************************************** ********

What you think about this idea ?

my ICQ 333-414-824

Sonork 100.69222

[email protected]


BR. Dr.Mobile
  Reply With Quote
Old 01-30-2007, 00:23   #2 (permalink)
No Life Poster
 
Join Date: Oct 2004
Age: 44
Posts: 2,115
Member: 88333
Status: Offline
Thanks Meter: 48
man learn how to write in english before making a plan
  Reply With Quote
Old 01-30-2007, 01:08   #3 (permalink)
Freak Poster
 
PhonePlus's Avatar
 
Join Date: Jul 2004
Location: Sousse - Tunisia
Posts: 474
Member: 71620
Status: Offline
Thanks Meter: 8
it can be done try !
  Reply With Quote
Old 01-30-2007, 01:37   #4 (permalink)
No Life Poster
 
mobileland's Avatar
 
Join Date: Feb 2003
Location: www.X-SIM.me
Age: 45
Posts: 2,424
Member: 22955
Status: Offline
Sonork: 67574 - Not use it
Thanks Meter: 584
It is allready done.
Nokia 6280 from 3 UK with version 3.36 appeared here in my country.And guess what?
Those phones are not unlocked by Dejan Team, but by someone else.
And off course,after you flash such phone(each phone have software faults) you get total 100% working BUT LOCKED phone.

Best Regards!
  Reply With Quote
Old 01-30-2007, 03:44   #5 (permalink)
No Life Poster
 
Join Date: Jul 2004
Age: 42
Posts: 935
Member: 72851
Status: Offline
Thanks Meter: 28
Quote:
Originally Posted by mobileland View Post
It is allready done.
Nokia 6280 from 3 UK with version 3.36 appeared here in my country.And guess what?
Those phones are not unlocked by Dejan Team, but by someone else.
And off course,after you flash such phone(each phone have software faults) you get total 100% working BUT LOCKED phone.

Best Regards!
But the weird part are the phone can be downgrade after upgrade!! 5.92 -->3.36
Some phone still can be use even the imei is corrupted without 2 minute restart!!



Does that mean this version have very weak security measurement compare to other version??


BR
  Reply With Quote
Old 01-30-2007, 06:18   #6 (permalink)
Freak Poster
 
Join Date: Mar 2004
Location: China SZ
Age: 50
Posts: 260
Member: 58924
Status: Offline
Sonork: 1583810
Thanks Meter: 57
Hi friend
ur idea is not bad but
can done if you make same operation in RAP3G r/w
this cpu Good luck.
  Reply With Quote
Old 01-30-2007, 16:15   #7 (permalink)
GFI
No Life Poster
 
GFI's Avatar
 
Join Date: Jun 2006
Location: Inside Blackberry
Posts: 1,036
Member: 288462
Status: Offline
Thanks Meter: 87
Hopefully we can see the solution been done and released

Regards
GFI-Team
  Reply With Quote
Old 01-30-2007, 16:54   #8 (permalink)
No Life Poster
 
Zaihtam's Avatar
 
Join Date: Dec 2004
Location: 0x001FD00
Posts: 1,285
Member: 98572
Status: Offline
Thanks Meter: 36
The unlocked phone doesn't change the firmware i think, it just have the right key at at the right place. so far i knew it is stored in the PM area. if i not wrong.


Good Luck...
  Reply With Quote
Old 01-30-2007, 17:09   #9 (permalink)
Freak Poster
 
OCTOPUS d.o.o.'s Avatar
 
Join Date: Aug 2003
Location: Seher
Age: 47
Posts: 329
Member: 37750
Status: Offline
Thanks Meter: 10
give me your adress I send you 20 phones for test.But after you give me source code for free,....
  Reply With Quote
Old 01-30-2007, 18:01   #10 (permalink)
Freak Poster
 
Join Date: May 2003
Location: Poland
Age: 36
Posts: 233
Member: 29897
Status: Offline
Thanks Meter: 3
@mobileland: have you HW to read out flash from one's of these phones ?

Yes, I think that BB5 phone flash can be easy patched to unlock phone. But you must known that this patched flash can't be written via cable ! Flash files are signed by certificates. Only way to write patched flash is to use external programmer. This is the easiest way to unlock BB5 - but it's difficult in use and risky(desolderning BGA chips) and can't be protected.
  Reply With Quote
Old 01-30-2007, 18:06   #11 (permalink)
No Life Poster
 
shaaker's Avatar
 
Join Date: Mar 2003
Location: One step before you ;)
Age: 42
Posts: 1,599
Member: 23695
Status: Offline
Sonork: 100.64383
Thanks Meter: 12
This solution maybe working with the GA628 and lower Ericson
  Reply With Quote
Old 01-30-2007, 18:12   #12 (permalink)
Freak Poster
 
Join Date: May 2003
Location: Poland
Age: 36
Posts: 233
Member: 29897
Status: Offline
Thanks Meter: 3
@shaaker: Before you comment somethink better think twice if you are right. I know what I am writing, I have seen a lot of disassembled Nokia BB5 firmware, I know how is working this Symbian platform. So if you don't have any ideas to post plase don't post useless posts ..
  Reply With Quote
Old 01-30-2007, 19:08   #13 (permalink)
No Life Poster
 
crusher's Avatar
 
Join Date: Dec 2001
Location: [winscard.SCardTransmit]
Posts: 1,835
Member: 8023
Status: Offline
Thanks Meter: 13
please always remember that our friend sent to him some hundred bucks once and did not receive nothing valuable

so please send your stuff to him and wait and leave honest people like shaaker alone...
  Reply With Quote
Old 01-30-2007, 19:45   #14 (permalink)
Freak Poster
 
dorian2004's Avatar
 
Join Date: May 2004
Location: Ukraine-Lugansk
Age: 44
Posts: 473
Member: 67246
Status: Offline
Thanks Meter: 70
Quote:
Originally Posted by adihack View Post
@mobileland: have you HW to read out flash from one's of these phones ?

Yes, I think that BB5 phone flash can be easy patched to unlock phone. But you must known that this patched flash can't be written via cable ! Flash files are signed by certificates. Only way to write patched flash is to use external programmer. This is the easiest way to unlock BB5 - but it's difficult in use and risky(desolderning BGA chips) and can't be protected.


Ofcourse the easy method of patched to unlock , i tool you about this methode is not original and this methode we possible used as template unlock in some time .

So about Flash files are signed by certificates - i know about some sertificates have bug, for example mathematik function * to 0 , if you have dct4/bb5 flash sourse - maybe you know about the better.


This methode is cheap with buyed external programmer from Dedjan or buyed RAP 3g MCU.


*OCTOPUS d.o.o.
In fact if some peoples send me nokias and hardware - i give he all result as free for partner .


BR.
  Reply With Quote
Old 01-30-2007, 20:30   #15 (permalink)
No Life Poster
 
Zaihtam's Avatar
 
Join Date: Dec 2004
Location: 0x001FD00
Posts: 1,285
Member: 98572
Status: Offline
Thanks Meter: 36
@adihack
are you sure about the possiblility of writing a patched code right into the flash IC is applicable? (using a hardware flash programmer). I haven't tried it but the UP1024 can do it i think.

Do you think the unlock can be done in the NAND flash IC? how about the RAP 3G Nor Flash where the certificates stuff?

Good Luck...
  Reply With Quote
Reply

Bookmarks


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Genie-Universal BB-5 Rapido SL2 logs and Unlimited BB-5+ Unlock availible NOW! John_Doe Main Sales Section 0 03-07-2009 21:02
Bb-5 unlock ahamed imran Nokia Base Band 5 ( BB-5 ) 0 01-22-2009 10:30
Video Manual Bb-5 Unlock With Hwk Wasim007 HWK 3 06-28-2008 19:25

 



All times are GMT +1. The time now is 20:02.



Powered by Searchlight © 2024 Axivo Inc.
vBulletin Optimisation provided by vB Optimise (Pro) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
- GSM Hosting Ltd. - 1999-2023 -
Page generated in 0.26135 seconds with 9 queries

SEO by vBSEO