Care Unlock  
Your online unlock store
GSM-Forum  

Welcome to the GSM-Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact contact us.

Go Back   GSM-Forum > Other Gsm/Mobile Related Forums > GSM Programming & Reverse Engineering

GSM Programming & Reverse Engineering Here you can post all Kind of GSM Programming and Reverse Engineering tools and Secrets.

Reply
 
LinkBack Thread Tools Display Modes
Old 04-06-2011, 07:00   #1 (permalink)
Junior Member
 
Join Date: Apr 2002
Location: Transylvania/Romania/Tg-Mures
Age: 37
Posts: 36
Member: 11351
Status: Offline
Thanks: 11
Thanked 2 Times in 2 Posts
Exclamation SL3 + ighashgpu + input data: /uh /salt /h

Hello, can someone with real knowledge explain the meaning and extracting of these data from the phones? I am interested about the input of /uh /salt and maybe of the /h switches!!! Thanks in advance!
  Reply With Quote
The Following User Says Thank You to dragon7 For This Useful Post:
Old 04-06-2011, 10:44   #2 (permalink)
No Life Poster
 
KrzychuG's Avatar
 
Join Date: Apr 2003
Location: Torun, Poland
Age: 29
Posts: 538
Member: 25996
Status: Offline
Thanks: 2
Thanked 30 Times in 29 Posts
ighashgpu -t:sha1 -salt:00_IMEI_15_digits_0 -h:HASH -uh:00010203040506070809 -min:15 -max:15

That's it, example:

ighashgpu -t:sha1 -salt:003582560396627500 -h:5F0D0ABEB59E67A779D15B8EA431FF45D648F985 -uh:00010203040506070809 -min:15 -max:15
  Reply With Quote
Old 04-06-2011, 10:45   #3 (permalink)
No Life Poster
 
MOURAD™'s Avatar
 
Join Date: Mar 2007
Location: Guangzhou-China
Posts: 1,270
Member: 468587
Status: Offline
Sonork: 100.1612429
Thanks: 318
Thanked 677 Times in 404 Posts
if you are Romanian, its easy to ask orbita or zulea......
  Reply With Quote
Old 04-06-2011, 13:58   #4 (permalink)
No Life Poster
 
angel25dz's Avatar
 
Join Date: Jul 2006
Location: ..::DZ-25::..
Posts: 542
Member: 315181
Status: Offline
Sonork: 100.1593455
Thanks: 162
Thanked 310 Times in 174 Posts
Quote:
Originally Posted by KrzychuG View Post
ighashgpu -t:sha1 -salt:00_IMEI_15_digits_0 -h:HASH -uh:00010203040506070809 -min:15 -max:15

That's it, example:

ighashgpu -t:sha1 -salt:003582560396627500 -h:5F0D0ABEB59E67A779D15B8EA431FF45D648F985 -uh:00010203040506070809 -min:15 -max:15
imei only 14 digits

br
  Reply With Quote
The Following User Says Thank You to angel25dz For This Useful Post:
Old 04-06-2011, 16:36   #5 (permalink)
No Life Poster
 
MOURAD™'s Avatar
 
Join Date: Mar 2007
Location: Guangzhou-China
Posts: 1,270
Member: 468587
Status: Offline
Sonork: 100.1612429
Thanks: 318
Thanked 677 Times in 404 Posts
Code:
ighashgpu -t:sha1 -salt:00[imei]00 -h:[hash] -uh:00010203040506070809 -min:15 -max:15



[imei] = 14 digits.

[hash] = hash readed with mxkey.


put this line in notepad file and change extension *.txt to *.cmd

Put this *.cmd file to IGHASHGPU folder and double click to start bruteforce.



Hope its clear now.

Last edited by MOURAD™; 04-06-2011 at 16:46.
  Reply With Quote
Old 04-06-2011, 20:19   #6 (permalink)
Junior Member
 
Join Date: Apr 2002
Location: Transylvania/Romania/Tg-Mures
Age: 37
Posts: 36
Member: 11351
Status: Offline
Thanks: 11
Thanked 2 Times in 2 Posts
One more question remain for me...

This read out hash is equal with CMT_ROOT_KEY_HASH + CMT_SECURE_ROM_CRC or it is some other data form PM120? For example in the file below (after a LBF done with the code in the end) where is the hash???
359370036240079
9B485686BFD39D4B35D358C4E82C05AC876C5ED5FA20EF0080 204F31E618767A947C6C9A9B8CF9322EBA04115487ED122B32 219F64B5C5B514023344D0A55D16507D6A7CD11534A3773C7D 606135D47344C07827C3711451B7941A3D74770735181D8FD5 C55A5155B20D556B7CA4D8499361318B88F41FA977A89F6842 B54017B612A246FB565263F18299DA512387159D707CACC244 0EA57E90D5DF3EBD9133
972798506488412

This phone has a CMT_ROOT_KEY_HASH: 9DDBFCFE6E73CED7D8C6268C8EB85723 and CMT_SECURE_ROM_CRC: DFAAF68F if I read info from phone. Thanks for all who answered the topic!
  Reply With Quote
Old 04-06-2011, 21:17   #7 (permalink)
No Life Poster
 
MOURAD™'s Avatar
 
Join Date: Mar 2007
Location: Guangzhou-China
Posts: 1,270
Member: 468587
Status: Offline
Sonork: 100.1612429
Thanks: 318
Thanked 677 Times in 404 Posts
[hash] =SHA1(mastersp+salt+00+imei+00)



imei must be 14 digits.
  Reply With Quote
Old 04-07-2011, 07:59   #8 (permalink)
Junior Member
 
Join Date: Apr 2002
Location: Transylvania/Romania/Tg-Mures
Age: 37
Posts: 36
Member: 11351
Status: Offline
Thanks: 11
Thanked 2 Times in 2 Posts
Exclamation things brighten up! Thanks!

And where is this hash stored? In PM120? When I read PM120 wich bytes are the right ones for this? Has PM120 to be modifyed to see these datas? Thanks and sorry for insistence!
  Reply With Quote
Old 04-07-2011, 10:03   #9 (permalink)
No Life Poster
 
angel25dz's Avatar
 
Join Date: Jul 2006
Location: ..::DZ-25::..
Posts: 542
Member: 315181
Status: Offline
Sonork: 100.1593455
Thanks: 162
Thanked 310 Times in 174 Posts
Quote:
Originally Posted by dragon7 View Post
And where is this hash stored? In PM120? When I read PM120 wich bytes are the right ones for this? Has PM120 to be modifyed to see these datas? Thanks and sorry for insistence!
Hash is stored in PM120 subfield 1 and crypted with AES 128, u must decrypt data to get the correct hash.

/br
  Reply With Quote
Old 04-07-2011, 10:04   #10 (permalink)
No Life Poster
 
MOURAD™'s Avatar
 
Join Date: Mar 2007
Location: Guangzhou-China
Posts: 1,270
Member: 468587
Status: Offline
Sonork: 100.1612429
Thanks: 318
Thanked 677 Times in 404 Posts
Re-read this again: SL3 + ighashgpu + input data: /uh /salt /h

You need only mastersp.








Best regards.

Last edited by MOURAD™; 04-07-2011 at 10:10.
  Reply With Quote
Old 04-07-2011, 19:01   #11 (permalink)
Freak Poster
 
yusniel's Avatar
 
Join Date: Mar 2011
Location: HELL
Posts: 240
Member: 1537172
Status: Offline
Sonork: 100.1612064
Thanks: 238
Thanked 20 Times in 19 Posts
Question Hi

I need to know if i can extract the hash with an usb conection...Mt Box Sl3 Usb Reader gives me this information...

MODEL: NOKIA 2730 CLASSIC (CLASSIC PHONE)
SW: V 10.45 05-07-10 RM-578 (C) NOKIA
IMEI: 354343044xxxxxx
Product Code: 0584996
Life timer: 50490000 <> 000005:12
--------------------------------------------------------------------------
ST_SIM_LOCK_TEST: PASSED
ST_SECURITY_TEST: PASSED
ST_SUPERDONGLE_TEST: PASSED
--------------------------------------------------------------------------
PROVIDER KEY: 0000000000000000
CONFIG KEY: 2440700000000000
PROVIDER: AT&T;U.S.A. (3650)
KEY CODE COUNT: 0 , FBUS CODE COUNT: 0
--------------------------------------------------------------------------
APE: none
--------------------------------------------------------------------------
CMT: 89820089
CMT PUBLIC ID: 0F300009BCB501568FE23BF8AB00D618BE3B33DF
CMT ROOT KEY HASH: 9DDBFCFE6E73CED7D8C6268C8EB85723
CMT PAPUBKEYS HASH: 8669C77551AE1280331BBAE6FD0C7CB3D3F44CC1
--------------------------------------------------------------------------

My question is: this software gives me the hash that i need??
  Reply With Quote
Old 04-08-2011, 14:28   #12 (permalink)
No Life Poster
 
MOURAD™'s Avatar
 
Join Date: Mar 2007
Location: Guangzhou-China
Posts: 1,270
Member: 468587
Status: Offline
Sonork: 100.1612429
Thanks: 318
Thanked 677 Times in 404 Posts
Quote:
And where is this hash stored? In PM120? When I read PM120 wich bytes are the right ones for this? Has PM120 to be modifyed to see these datas? Thanks and sorry for insistence!

You can find it in PM120,4 Contain:

- simlock
- sha1
- rsa signature.


When you extract an decrypt sha1 hash.

example:

imei: 356918031143509

sha1 Hash: 8D1C71F10A3F36FAFCFEB60B8B3D10E341E4B78D

Brutforce:

sha1 hash = 8D1C71F10A3F36FAFCFEB60B8B3D10E341E4B78D = SHA1(mastersp+salt+00+35691803114350+00)

mastersp: [000000000000000~999999999999999]

Salt : [0~9999]
  Reply With Quote
The Following 2 Users Say Thank You to MOURAD™ For This Useful Post:
Old 04-09-2011, 16:06   #13 (permalink)
No Life Poster
 
MOURAD™'s Avatar
 
Join Date: Mar 2007
Location: Guangzhou-China
Posts: 1,270
Member: 468587
Status: Offline
Sonork: 100.1612429
Thanks: 318
Thanked 677 Times in 404 Posts
Here small example about Bruteforce calcul:


Hash find OK:

SHA1 TEST [35691803114350] = 8D1C71F10A3F36FAFCFEB60B8B3D10E341E4B78D
SHA1 Hash [35691803114350] = 8D1C71F10A3F36FAFCFEB60B8B3D10E341E4B78D
Mastersp = 065222098608403


Best Regards
Mourad

Last edited by MOURAD™; 04-09-2011 at 16:15.
  Reply With Quote
The Following 6 Users Say Thank You to MOURAD™ For This Useful Post:
Old 04-09-2011, 17:43   #14 (permalink)
Crazy Poster
 
Join Date: Nov 2008
Age: 23
Posts: 51
Member: 907738
Status: Offline
Thanks: 43
Thanked 26 Times in 16 Posts
Quote:
Originally Posted by Mrd07 View Post
Here small example about Bruteforce calcul:


Hash find OK:

SHA1 TEST [35691803114350] = 8D1C71F10A3F36FAFCFEB60B8B3D10E341E4B78D
SHA1 Hash [35691803114350] = 8D1C71F10A3F36FAFCFEB60B8B3D10E341E4B78D
Mastersp = 065222098608403


Best Regards
Mourad

nice info sir ..

but why mx-key not support to brute force with ati hd 6990 ??
  Reply With Quote
Old 04-09-2011, 17:57   #15 (permalink)
Junior Member
 
Join Date: Apr 2002
Location: Transylvania/Romania/Tg-Mures
Age: 37
Posts: 36
Member: 11351
Status: Offline
Thanks: 11
Thanked 2 Times in 2 Posts
Quote:
Originally Posted by crushader8 View Post
nice info sir ..

but why mx-key not support to brute force with ati hd 6990 ??
According to Ivan Golubev author of the brute force attack program (included in mx tool): HD68xx are supported only by ighashgpu_v0.90.17.3 but from that version the SHA1 cracking was disabled because the mx team: they violated the licence agrement. Read this:
More about ATI 6XXX - Ivan Golubev's blog
and
Đ¡Đ¿Đ¸$дили - Ivan Golubev's blog
Last remark: You can use maybe Fenix key with HD6xxx. Chec them out.
Best regards!
  Reply With Quote
The Following User Says Thank You to dragon7 For This Useful Post:
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
thread Thread Starter Forum Replies Last Post
3310 problem display disappears after input pin simonb Nokia Legacy Phones ( DCT-1 , DCT-2 , DCT-3 , DCT-L ) 8 01-09-2009 09:37
how to input unlock code??? skedone Infineon C16X M51 & ARM7 M52 BASED 1 08-07-2002 11:45
How to input nck by keyboard? ren777 Mitsubishi 2 02-16-2002 14:47
restore T9 text-input siemens S35 baronx x1x to x45/x50 0 01-03-2002 22:16
Nck input problems, on mc9224.1m dollyb Infineon C16X M51 & ARM7 M52 BASED 0 04-05-2001 21:27


All times are GMT +1. The time now is 03:20.



Powered by Searchlight © 2013 Axivo Inc.
- GSM Hosting Ltd. - 1999-2013 -
Page generated in 0.40440 seconds with 11 queries

SEO by vBSEO