GSM Shop GSM Shop
GSM-Forum  

Welcome to the GSM-Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features.
Only registered members may post questions, contact other members or search our database of over 8 million posts.

Registration is fast, simple and absolutely free so please - Click to REGISTER!

If you have any problems with the registration process or your account login, please contact contact us .

Go Back   GSM-Forum > Other Gsm/Mobile Related Forums > GSM Programming & Reverse Engineering


GSM Programming & Reverse Engineering Here you can post all Kind of GSM Programming and Reverse Engineering tools and Secrets.

Reply
 
LinkBack Thread Tools Display Modes
Old 04-26-2011, 15:20   #1 (permalink)
No Life Poster
 
angel25dz's Avatar
 
Join Date: Jul 2006
Location: ..::DZ-25::..
Posts: 529
Member: 315181
Status: Offline
Sonork: 100.1593455
Thanks Meter: 301
SL3: question


hi all, I saw in some box's logs: dumping RSA modulus !! can someone tell us where this modulus is stored ??
  Reply With Quote
Old 04-26-2011, 22:17   #2 (permalink)
No Life Poster
 
crusher's Avatar
 
Join Date: Dec 2001
Location: [winscard.SCardTransmit]
Posts: 1,835
Member: 8023
Status: Offline
Thanks Meter: 13
Should anyone know I doubt will tell.
However, if you'd specify which "box", maybe someone could have a look after it.
Otherwise, do not wonder if this thread just disappears (like the previous I commented in.. )
  Reply With Quote
Old 04-27-2011, 09:32   #3 (permalink)
No Life Poster
 
MOURAD™'s Avatar
 
Join Date: Mar 2007
Location: Guangzhou-China
Posts: 1,289
Member: 468587
Status: Offline
Sonork: 100.1612429
Thanks Meter: 681
Quote:
Originally Posted by crusher View Post
Should anyone know I doubt will tell.
However, if you'd specify which "box", maybe someone could have a look after it.
Otherwise, do not wonder if this thread just disappears (like the previous I commented in.. )
in AdvanceBox Turbo Flasher "ATF".

All this in Permanent memory (120/0,1,2,3), dumping RSA in PM120/4 to extract and Decrypt sha1 hash, like this log:

Code:
..
....
Scanning Simlock Applet Type...
OK

=================================================
PA_SL3 Applet detected
=================================================

Dumping RSA Modulus...
OK

=================================================
RSA Modulus OK
=================================================
FlashInfo.RestartMode : 2

================================================== =
Decrypt SL3 PM 120 HASHES for Brute Force Unlock
================================================== =
Decrypting PM 120...
(This may take upto 30 Seconds on New RAPIDO HASH) 
PM 120 HASHES Extracted Successfully

39C05A2C79C7839FF413DD41C5077A4445F1C9F0
1D8CF08D8A7A793FFFD1166FCA50A9626E544AEF
16C5ED98F9E2BFBA46CF1D186F20C329E7ED842E
1BC23BB82252CF1165CAAD4D6D5F4CDAAEEA52AA
280E70C587D5DBD4A8B42AF59DDE8AC64D4C8F0C
3260876EF714284A553C6C7C58E4657728B7836C
EA169D4AB8280D7767BDB095C5CE4254444CB710
A54510E30F480D6FEF2C18DA38241DC264DB4963
...




Best Regards.

Last edited by MOURAD™; 04-27-2011 at 09:37.
  Reply With Quote
The Following User Says Thank You to MOURAD™ For This Useful Post:
Old 04-27-2011, 10:12   #4 (permalink)
No Life Poster
 
angel25dz's Avatar
 
Join Date: Jul 2006
Location: ..::DZ-25::..
Posts: 529
Member: 315181
Status: Offline
Sonork: 100.1593455
Thanks Meter: 301
Quote:
Originally Posted by crusher View Post
Should anyone know I doubt will tell.
However, if you'd specify which "box", maybe someone could have a look after it.
Otherwise, do not wonder if this thread just disappears (like the previous I commented in.. )
I haven't this box, otherwise i don't ask
  Reply With Quote
Old 04-27-2011, 11:14   #5 (permalink)
No Life Poster
 
angel25dz's Avatar
 
Join Date: Jul 2006
Location: ..::DZ-25::..
Posts: 529
Member: 315181
Status: Offline
Sonork: 100.1593455
Thanks Meter: 301
Quote:
Originally Posted by Mrd07 View Post
in AdvanceBox Turbo Flasher "ATF".

All this in Permanent memory (120/0,1,2,3), dumping RSA in PM120/4 to extract and Decrypt sha1 hash, like this log:

Best Regards.
RSA modulus is not in PM

PM120,0 : simlock
PM120,1 : Crypted HASH's (AES)
PM120,2 : RSA Signature
PM120,3 : HWD ID +11 digits + lock level (each level have its place ) when phone is unlocked, for locked phone only "0" (16x7) bytes

./br
  Reply With Quote
The Following 2 Users Say Thank You to angel25dz For This Useful Post:
Old 04-27-2011, 12:34   #6 (permalink)
No Life Poster
 
MOURAD™'s Avatar
 
Join Date: Mar 2007
Location: Guangzhou-China
Posts: 1,289
Member: 468587
Status: Offline
Sonork: 100.1612429
Thanks Meter: 681
Quote:
Originally Posted by angel25dz View Post
RSA modulus is not in PM

PM120,0 : simlock
PM120,1 : Crypted HASH's (AES)
PM120,2 : RSA Signature
PM120,3 : HWD ID +11 digits + lock level (each level have its place ) when phone is unlocked, for locked phone only "0" (16x7) bytes

./br
PM field 120,4 have simlock, sha1, rsa sign - which can be rewritten - no need RPL format

Here: http://forum.gsmhosting.com/vbb/7144358-post12.html
&
here: http://forum.gsmhosting.com/vbb/7148878-post17.html
  Reply With Quote
The Following User Says Thank You to MOURAD™ For This Useful Post:
Old 04-27-2011, 12:42   #7 (permalink)
No Life Poster
 
angel25dz's Avatar
 
Join Date: Jul 2006
Location: ..::DZ-25::..
Posts: 529
Member: 315181
Status: Offline
Sonork: 100.1593455
Thanks Meter: 301
My question is about RSA MODULUS (PxQ) not about PM or about hash or about signature.....etc, just i'm curious about ATF log, they really dump this modulus ??
  Reply With Quote
Old 04-27-2011, 12:51   #8 (permalink)
Crazy Poster
 
Join Date: Jun 2004
Location: Shenzhen, China
Age: 44
Posts: 51
Member: 69997
Status: Offline
Thanks Meter: 15
Quote:
Originally Posted by angel25dz View Post
hi all, I saw in some box's logs: dumping RSA modulus !! can someone tell us where this modulus is stored ??
inside "PAPUBKEYS"... (index 0x50410008)
  Reply With Quote
The Following 3 Users Say Thank You to UniSoft For This Useful Post:
Show/Hide list of the thanked
Old 04-27-2011, 12:53   #9 (permalink)
No Life Poster
 
angel25dz's Avatar
 
Join Date: Jul 2006
Location: ..::DZ-25::..
Posts: 529
Member: 315181
Status: Offline
Sonork: 100.1593455
Thanks Meter: 301
Quote:
Originally Posted by UniSoft View Post
inside "PAPUBKEYS"... (index 0x50410008)
thanks, that's what i need
  Reply With Quote
Old 04-27-2011, 12:57   #10 (permalink)
No Life Poster
 
MOURAD™'s Avatar
 
Join Date: Mar 2007
Location: Guangzhou-China
Posts: 1,289
Member: 468587
Status: Offline
Sonork: 100.1612429
Thanks Meter: 681
Quote:
Originally Posted by angel25dz View Post
My question is about RSA MODULUS (PxQ) not about PM or about hash or about signature.....etc, just i'm curious about ATF log, they really dump this modulus ??

waiting ..::Angel::.., for more explain if possible.




Best regards.
  Reply With Quote
Old 04-27-2011, 13:09   #11 (permalink)
No Life Poster
 
..::Angel::..'s Avatar
 
Join Date: Dec 2006
Location: Karachi, Pakistan
Age: 33
Posts: 16,237
Member: 643472
Status: Offline
Sonork: 100.96901
Thanks Meter: 16,589
Quote:
Originally Posted by Mrd07 View Post
waiting ..::Angel::.., for more explain if possible.




Best regards.
Hello.
I dunno, how RSA module dumps. Where it stored? - answered by @UniSoft !
  Reply With Quote
The Following User Says Thank You to ..::Angel::.. For This Useful Post:
Old 04-27-2011, 17:55   #12 (permalink)
No Life Poster
 
neilthirumuttam's Avatar
 
Join Date: Sep 2002
Location: KERALA, india
Age: 55
Posts: 1,237
Member: 15903
Status: Offline
Sonork: 100.1583162
Thanks Meter: 1,046
may seek answers 4 a foolish doubt here?

without any help from tool makers and supporters
end users or common ppl will learn RSA module dumps. Where it stored?

linux ....
hit ...storm ... android
washing off nude kings.

and enjoying news paper 4 2days hits between chips - makers and programmers

os war in courts
but lowe end users make the resullt
not BRUTUAL FORCE..
  Reply With Quote
The Following User Says Thank You to neilthirumuttam For This Useful Post:
Old 04-28-2011, 09:14   #13 (permalink)
No Life Poster
 
Bph&co's Avatar
 
Join Date: Feb 2000
Location: UK
Posts: 3,186
Member: 1024
Status: Offline
Thanks Meter: 5,510
Quote:
Originally Posted by angel25dz View Post
My question is about RSA MODULUS (PxQ) not about PM or about hash or about signature.....etc, just i'm curious about ATF log, they really dump this modulus ??
Hi,

There is very easy way to get this modulus:

1. Read SW version from the phone screen
2. Open NaviFirm and download MCU for this version
3. Open the file as it is in WinHex
4. Go to the end of the file
4. Search Menu, Find Hex Values, enter: 0300000000004000, direction: UP
5. Press enter and stop on the first found value
6. Select the 128 bytes after found string

This is the simlock signer key for your phone.

Hope this helps

73
  Reply With Quote
The Following 16 Users Say Thank You to Bph&co For This Useful Post:
Show/Hide list of the thanked
Old 05-07-2011, 07:24   #14 (permalink)
No Life Poster
 
..::Rizwan::..'s Avatar
 
Join Date: May 2008
Location: P@Ki$t@n
Posts: 3,165
Member: 777415
Status: Offline
Sonork: 1589702
Thanks Meter: 1,420
Donate money to this user
Quote:
Originally Posted by Bph&co View Post
Hi,

There is very easy way to get this modulus:

1. Read SW version from the phone screen
2. Open NaviFirm and download MCU for this version
3. Open the file as it is in WinHex
4. Go to the end of the file
4. Search Menu, Find Hex Values, enter: 0300000000004000, direction: UP
5. Press enter and stop on the first found value
6. Select the 128 bytes after found string

This is the simlock signer key for your phone.

Hope this helps

73
I need little more explanation after all this proccess i got simlock signer key. now this md5 hash can help me to Unlock Sl3 With brute force instantly Or not.

Like this example screen shoot












if yes then how can ?
  Reply With Quote
The Following User Says Thank You to ..::Rizwan::.. For This Useful Post:
Old 05-07-2011, 11:05   #15 (permalink)
No Life Poster
 
angel25dz's Avatar
 
Join Date: Jul 2006
Location: ..::DZ-25::..
Posts: 529
Member: 315181
Status: Offline
Sonork: 100.1593455
Thanks Meter: 301
First begin to understand how to make difference between bit and byte ......

About ur question, NO it not help

Last edited by angel25dz; 05-07-2011 at 11:10.
  Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
One last question dario Nokia Legacy Phones ( DCT-1 ,2 ,3 ,L ) 1 01-24-2001 19:10
Questions about Dejan's flasher interface SashaM Nokia Legacy Phones ( DCT-1 ,2 ,3 ,L ) 9 01-15-2001 09:31
8890 questions spongebob Nokia Legacy Phones ( DCT-1 ,2 ,3 ,L ) 2 01-10-2001 01:04
Silly question!! Why is it impossible to read out the mastercode of Nokia phones???? MyKe Nokia Legacy Phones ( DCT-1 ,2 ,3 ,L ) 0 09-26-1999 14:31
Question about 51xx/61xx Comic Nokia Legacy Phones ( DCT-1 ,2 ,3 ,L ) 1 07-06-1999 23:47

 



All times are GMT +1. The time now is 19:20.



Powered by Searchlight © 2024 Axivo Inc.
vBulletin Optimisation provided by vB Optimise (Pro) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
- GSM Hosting Ltd. - 1999-2023 -
Page generated in 0.41665 seconds with 9 queries

SEO by vBSEO