GSM Shop GSM Shop
GSM-Forum  

Welcome to the GSM-Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features.
Only registered members may post questions, contact other members or search our database of over 8 million posts.

Registration is fast, simple and absolutely free so please - Click to REGISTER!

If you have any problems with the registration process or your account login, please contact contact us .

Go Back   GSM-Forum > Other Gsm/Mobile Related Forums > GSM Programming & Reverse Engineering


GSM Programming & Reverse Engineering Here you can post all Kind of GSM Programming and Reverse Engineering tools and Secrets.

Reply
 
LinkBack Thread Tools Display Modes
Old 08-30-2014, 23:58   #1 (permalink)
Freak Poster
 
LoneWolf37's Avatar
 
Join Date: Nov 2008
Location: İstanbul , of course.
Age: 36
Posts: 167
Member: 896616
Status: Offline
Sonork: 100.1604239
Thanks Meter: 30
Repair imei on new qualcomm devices.


How to repair/change imei on new type qualcomm devices ?
i have some pantech , alcatel , lenovo etc.. brands devices.
can we do something within qpst ?and how to open diag port on that devices ?

note : i have a lot of pcs lenovo k910 (Qualcomm Snapdragon 800 MSM8274 v1) for repair imei , if anybody have a any tool feel free to contact me
  Reply With Quote
Old 09-05-2014, 13:26   #2 (permalink)
No Life Poster
 
Join Date: Nov 2009
Location: Barisal
Age: 44
Posts: 1,302
Member: 1427033
Status: Offline
Sonork: 100.1596688
Thanks Meter: 1,204
Donate money to this user
Quote:
Originally Posted by LoneWolf37 View Post
How to repair/change imei on new type qualcomm devices ?
i have some pantech , alcatel , lenovo etc.. brands devices.
can we do something within qpst ?and how to open diag port on that devices ?

note : i have a lot of pcs lenovo k910 (Qualcomm Snapdragon 800 MSM8274 v1) for repair imei , if anybody have a any tool feel free to contact me
you have to write QCN file aslike NV file.
  Reply With Quote
The Following User Says Thank You to Dooha_Bd For This Useful Post:
Old 09-06-2014, 05:49   #3 (permalink)
No Life Poster
 
armany99's Avatar
 
Join Date: Oct 2004
Location: USA
Posts: 547
Member: 85637
Status: Offline
Sonork: 100.100.529
Thanks Meter: 139
That's right and the boot after the root is easy
But still there is something we need to know about this files !!
  Reply With Quote
Old 09-07-2014, 20:32   #4 (permalink)
Freak Poster
 
LoneWolf37's Avatar
 
Join Date: Nov 2008
Location: İstanbul , of course.
Age: 36
Posts: 167
Member: 896616
Status: Offline
Sonork: 100.1604239
Thanks Meter: 30
bro i accepted ur friendship wants from skype , still waiting or pm me please.i will try.

also everyone can be try that :

1st , enable diagnostic port by model (search google etc..)
2nd , read nvm from qpst.
3rd edit nvm imei then upload back.but that option cant be possible on nvm secured phones.i m researching now
  Reply With Quote
Old 09-11-2014, 04:12   #5 (permalink)
Junior Member
 
Join Date: Jun 2007
Location: Vietnam
Posts: 31
Member: 532123
Status: Offline
Thanks Meter: 7
@omarb1989

I have Q-smart s20 chip Qualcomm and lost Imei,flash some Rom but stiil null Imei, i don't know how to repair it.
Can you send me tool for repair, my yahoo = nick forum, thanks.
  Reply With Quote
Old 09-13-2014, 22:36   #6 (permalink)
Freak Poster
 
Join Date: May 2013
Location: Russia
Posts: 101
Member: 1940428
Status: Offline
Sonork: 100.1647873
Thanks Meter: 35
The same topic question. Does anyone have any info about Qualcomm CEFS? I mean modemst1, modemst2, fsg with following signatures inside - IMGEFS1X, IMGEFS2Y. Is any way to decrypt it? May be some tools or direction how to start dig (reverse) decryption proc? Any advices, hints, examples?
  Reply With Quote
Old 09-14-2014, 10:48   #7 (permalink)
No Life Poster
 
Join Date: Jan 2004
Location: Unknown
Age: 39
Posts: 9,227
Member: 49752
Status: Offline
Sonork: QQ:1474246528
Thanks Meter: 6,085
Quote:
Originally Posted by Decker82 View Post
The same topic question. Does anyone have any info about Qualcomm CEFS? I mean modemst1, modemst2, fsg with following signatures inside - IMGEFS1X, IMGEFS2Y. Is any way to decrypt it? May be some tools or direction how to start dig (reverse) decryption proc? Any advices, hints, examples?
Hello
No details so far public or private. only vendors know.
There was one info but as qualcomm always send copy right latter to remove it.

But there is way to dump CEFS raw format with qpst and command bug.
qpst method is on google already.

Regards,
Chevli
  Reply With Quote
Old 09-15-2014, 06:59   #8 (permalink)
No Life Poster
 
Join Date: Jun 2004
Location: USA
Age: 39
Posts: 1,142
Member: 67927
Status: Offline
Thanks Meter: 108
Quote:
Originally Posted by stanner_austin View Post
Hello
No details so far public or private. only vendors know.
There was one info but as qualcomm always send copy right latter to remove it.

But there is way to dump CEFS raw format with qpst and command bug.
qpst method is on google already.

Regards,
Chevli
You have this info? or a cached version of the page?
  Reply With Quote
Old 09-30-2014, 16:38   #9 (permalink)
Banned
 
Join Date: Nov 2013
Location: Chicago, IL
Posts: 995
Member: 2076039
Status: Offline
Thanks Meter: 648
Donate money to this user
I shouldn't post this and make it public (so that qualcomm can patch it...) but to repair the IMEI you must first clear the EFS partitions. This doesn't mean the /efs folder. I mean the EFS data partitions which are modemst1, modemst2, and FSG. On most GSM phones this is mmcblk0p12, mmcblk0p13, and mmcblk0p18. They can be wrote to if can adb shell into your phone using root. Use the dd if command to pull one of the partitions to your computer, take note of the exact byte size, make a new hex file that size. It'll be full of zeros, that's fine. Send it to the phone. Write this zeroed out file to the three EFS data partitions with the dd if command through adb shell. Reboot the phone. Your IMEI (and network) are gone. At this point the protection is removed and the IMEI can be wrote to (either through the diag port or through AT commands over the modem/UART).

I hope you took a NV backup of your phone (minus nv item 550) to restore the network after the IMEI repair ;-)

Yes, this is exactly how all box companies are doing this for Samsung and LG (some of them clear the efs through download mode. I prefer to run a batch file through adb; although root is necessary for the adb method).
  Reply With Quote
The Following 4 Users Say Thank You to ecs87 For This Useful Post:
Show/Hide list of the thanked
Old 09-30-2014, 17:13   #10 (permalink)
Junior Member
 
Join Date: Oct 2006
Posts: 29
Member: 372813
Status: Offline
Thanks Meter: 1
Quote:
Originally Posted by ecs87 View Post
I shouldn't post this and make it public (so that qualcomm can patch it...) but to repair the IMEI you must first clear the EFS partitions. This doesn't mean the /efs folder. I mean the EFS data partitions which are modemst1, modemst2, and FSG. On most GSM phones this is mmcblk0p12, mmcblk0p13, and mmcblk0p18. They can be wrote to if can adb shell into your phone using root. Use the dd if command to pull one of the partitions to your computer, take note of the exact byte size, make a new hex file that size. It'll be full of zeros, that's fine. Send it to the phone. Write this zeroed out file to the three EFS data partitions with the dd if command through adb shell. Reboot the phone. Your IMEI (and network) are gone. At this point the protection is removed and the IMEI can be wrote to (either through the diag port or through AT commands over the modem/UART).

I hope you took a NV backup of your phone (minus nv item 550) to restore the network after the IMEI repair ;-)

Yes, this is exactly how all box companies are doing this for Samsung and LG (some of them clear the efs through download mode. I prefer to run a batch file through adb; although root is necessary for the adb method).

Doing this cancels the check msl?
  Reply With Quote
Old 10-05-2014, 22:16   #11 (permalink)
Freak Poster
 
LoneWolf37's Avatar
 
Join Date: Nov 2008
Location: İstanbul , of course.
Age: 36
Posts: 167
Member: 896616
Status: Offline
Sonork: 100.1604239
Thanks Meter: 30
Quote:
Originally Posted by ecs87 View Post
I shouldn't post this and make it public (so that qualcomm can patch it...) but to repair the IMEI you must first clear the EFS partitions. This doesn't mean the /efs folder. I mean the EFS data partitions which are modemst1, modemst2, and FSG. On most GSM phones this is mmcblk0p12, mmcblk0p13, and mmcblk0p18. They can be wrote to if can adb shell into your phone using root. Use the dd if command to pull one of the partitions to your computer, take note of the exact byte size, make a new hex file that size. It'll be full of zeros, that's fine. Send it to the phone. Write this zeroed out file to the three EFS data partitions with the dd if command through adb shell. Reboot the phone. Your IMEI (and network) are gone. At this point the protection is removed and the IMEI can be wrote to (either through the diag port or through AT commands over the modem/UART).

I hope you took a NV backup of your phone (minus nv item 550) to restore the network after the IMEI repair ;-)

Yes, this is exactly how all box companies are doing this for Samsung and LG (some of them clear the efs through download mode. I prefer to run a batch file through adb; although root is necessary for the adb method).
Bro thanks ; those informations are great for beginner of programmers.well , if we clear that 3 partitions , network Will come after process to new type imei cert phones ?(like note 3 n900x series ,s5 etc..)

Last edited by LoneWolf37; 10-05-2014 at 22:23.
  Reply With Quote
Old 10-07-2014, 16:29   #12 (permalink)
Banned
 
Join Date: Nov 2013
Location: Chicago, IL
Posts: 995
Member: 2076039
Status: Offline
Thanks Meter: 648
Donate money to this user
You must make a QCN backup (or more commonly referred to as a nv item backup) of the phone BEFORE resetting the EFS. If you dont, you risk having no network after the IMEI repair.
  Reply With Quote
Old 11-02-2014, 17:00   #13 (permalink)
Junior Member
 
Join Date: Aug 2014
Posts: 2
Member: 2242067
Status: Offline
Thanks Meter: 0
Quote:
Originally Posted by ecs87 View Post
I shouldn't post this and make it public (so that qualcomm can patch it...) but to repair the IMEI you must first clear the EFS partitions. This doesn't mean the /efs folder. I mean the EFS data partitions which are modemst1, modemst2, and FSG. On most GSM phones this is mmcblk0p12, mmcblk0p13, and mmcblk0p18. They can be wrote to if can adb shell into your phone using root. Use the dd if command to pull one of the partitions to your computer, take note of the exact byte size, make a new hex file that size. It'll be full of zeros, that's fine. Send it to the phone. Write this zeroed out file to the three EFS data partitions with the dd if command through adb shell. Reboot the phone. Your IMEI (and network) are gone. At this point the protection is removed and the IMEI can be wrote to (either through the diag port or through AT commands over the modem/UART).

I hope you took a NV backup of your phone (minus nv item 550) to restore the network after the IMEI repair ;-)

Yes, this is exactly how all box companies are doing this for Samsung and LG (some of them clear the efs through download mode. I prefer to run a batch file through adb; although root is necessary for the adb method).
Trying to do this on an SGH-I717. Attempted to message ECS but PM is disabled. Could anyone please elaborate a little bit on this process for me? I've been grinding away trying to get my phone working for months and would really appreciate any help.
  Reply With Quote
Old 11-08-2014, 16:53   #14 (permalink)
Junior Member
 
Join Date: Aug 2014
Posts: 2
Member: 2242067
Status: Offline
Thanks Meter: 0
Well I figured it out. Atleast as much as I need.
If your phone is anything like my Samsung Note SGH-I717 you can access service mode with a code and then wipe all 3 efs partitions directly from the phone.
Good luck folks! Hope your adventure ends the same as mine.
  Reply With Quote
Old 11-09-2014, 08:45   #15 (permalink)
Banned
 
Join Date: Jun 2014
Posts: 81
Member: 2206276
Status: Offline
Thanks Meter: 46
Quote:
Originally Posted by ecs87 View Post
I shouldn't post this and make it public (so that qualcomm can patch it...) but to repair the IMEI you must first clear the EFS partitions. This doesn't mean the /efs folder. I mean the EFS data partitions which are modemst1, modemst2, and FSG. On most GSM phones this is mmcblk0p12, mmcblk0p13, and mmcblk0p18. They can be wrote to if can adb shell into your phone using root. Use the dd if command to pull one of the partitions to your computer, take note of the exact byte size, make a new hex file that size. It'll be full of zeros, that's fine. Send it to the phone. Write this zeroed out file to the three EFS data partitions with the dd if command through adb shell. Reboot the phone. Your IMEI (and network) are gone. At this point the protection is removed and the IMEI can be wrote to (either through the diag port or through AT commands over the modem/UART).

I hope you took a NV backup of your phone (minus nv item 550) to restore the network after the IMEI repair ;-)

Yes, this is exactly how all box companies are doing this for Samsung and LG (some of them clear the efs through download mode. I prefer to run a batch file through adb; although root is necessary for the adb method).
I understand how to wipe efs folder via adb but cannot figure out how to do it through download mode. I know this is how spt and bst are doing it. I can flash the nvrebuild1.bin and nvrebuild2.bin with no problems, But when I try to flash the fsg.bin I always get the "Secure Check Fail : apnonhlos" message on the phone when I flash it via odin. Do you have any ideas?

Last edited by hellothere777; 11-09-2014 at 08:50.
  Reply With Quote
The Following 2 Users Say Thank You to hellothere777 For This Useful Post:
Reply

Bookmarks


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


 



All times are GMT +1. The time now is 20:47.



Powered by Searchlight © 2024 Axivo Inc.
vBulletin Optimisation provided by vB Optimise (Pro) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
- GSM Hosting Ltd. - 1999-2023 -
Page generated in 0.37220 seconds with 8 queries

SEO by vBSEO