GSM Shop GSM Shop
GSM-Forum  

Welcome to the GSM-Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features.
Only registered members may post questions, contact other members or search our database of over 8 million posts.

Registration is fast, simple and absolutely free so please - Click to REGISTER!

If you have any problems with the registration process or your account login, please contact contact us .

Go Back   GSM-Forum > GSM & CDMA Phones / Tablets Software & Hardware Area > Nokia > Nokia Base Band 5 ( BB-5 )


Nokia Base Band 5 ( BB-5 ) Baseband-5 Phones: 2700 Classic , 2730 Classic , 3109c , 3110c , 3120c , 3250 , 3500c , 3600s , 3610 Fold , 3710 Fold , 3720 Classic , 5130 XpressM , 5200 / 5200b , 5220 XpressM , 5230 XpressM , 5300 / 5300b , 5310 / 5310b , 5320 , 5500 , 5530 XpressM , 5610 , 5630 XpressM , 5700 , 5730 XpressM , 5800 , 6085 / 6086 , 6110n , 6120c , 6121c , 6124c , 6125 , 6126 / 6133b , 6131 / 6133 , 6131 (NFC) , 6136 , 6151 , 6208 Classic , 6210n , 6212c , 6220c , 6233 , 6234 , 6260 Slide , 6263 , 6267 , 6270 , 6280 / 6288 , 6282 , 6290 , 6300 , 6300i , 6301 , 6303 Classic , 6500 Classic , 6500 Slide , 6555 , 6600 Fold , 6600 Slide , 6630 , 6650 Fold , 6680 , 6681 , 6682 , 6700 Classic , 6710 Navigator , 6720 Classic , 6730 Classic , 6760 Slide , 6790 Surge , 7210c , 7310c , 7370 , 7373 , 7390 , 7500 , 7510c , 7610c , 7900 , 8600 , 8800 arte , E50 , E51 , E52 , E55 , E60 , E61 , E61i , E62 , E63 , E65 , E66 , E70 , E71 , E72 , E75 , E90 , N70 , N71 , N72 , N73 , N75 , N76 , N77 , N78 , N79 , N80 , N81 , N82 , N85 , N86 , N90 , N91 , N92 , N93 , N93i , N95 , N95 8GB , N96 , N97 , N97 Mini , X3 , X6

Reply
 
LinkBack Thread Tools Display Modes
Old 01-31-2007, 19:28   #1 (permalink)
Freak Poster
 
Join Date: Feb 2001
Posts: 213
Member: 3354
Status: Offline
Thanks Meter: 3,948
BB5 downgrade


Best method is FULL FLASH erase and restoring with original Nokia rpl file!

Otherwise....

I didn't play much with that problem but you can try...
All test are made with 6630, probably it works with other BB5

MCU & DSP signatures are stored in 308,1 field on subblock
"ab0fbd96af2ac271d26264af dead 06 00"

That subblock is crypted by AES algorithm, and you have to know 16bytes key
or to use attack to make change on that subblock.
But...

To make simple SW update Nokia made some backdors.
Rap is testing that subblock and if new SW is newer than SW signature in
that subbblock RAP will update subblock with newer SW signature.
Otherwise, if new SW is older, RAP will STOP.
BUT if that subblock is corupted RAP will write default current SW signature!!!

So, procedure is next:

Power your BB5 phone.
After few sec. read field 308,1
Find in readed field 308,1 bytes "ab0fbd96af2ac271d26264afdead0600"
and after that header fill next 16 bytes with zeros.
Write back that new field 308,1 to phone.
Well why Nokia made that after writing new fild 308,1 it is not tested...
Anyway new field is stored in FLASH and it will be tested on NEXT phone reset!!!
Here is more critical part.
You have to flash phone with older SW before phone SW reset!!!
You have to find flasher that allows very fast entering phone in FLASH mode!!!
(if flasher after powering phone gives to much time to RAP start SW testing,
SW downgrade will faill!)
If every thing goes ok after flashing ,RAP will find corrupted subblock
and will authorise previous wrote downgraded SW!

That's it.

B.R.
Dejan
  Reply With Quote
The Following 5 Users Say Thank You to Dejan Kaljevic For This Useful Post:
Show/Hide list of the thanked
Old 01-31-2007, 19:46   #2 (permalink)
Freak Poster
 
Join Date: Oct 2005
Location: China
Posts: 118
Member: 191046
Status: Offline
Sonork: 100.84351
Thanks Meter: 7
do i need to read the area for each phone every time or one time i read then use the same file for other phone
  Reply With Quote
Old 01-31-2007, 19:47   #3 (permalink)
Freak Poster
 
DeDaMrAz's Avatar
 
Join Date: May 2002
Location: Serbia
Age: 42
Posts: 257
Member: 11604
Status: Offline
Thanks Meter: 7
@Dejan

Could you address that problem on gsm-serbia??? (So we can talk normaly )
  Reply With Quote
Old 01-31-2007, 20:18   #4 (permalink)
No Life Poster
 
moldovan's Avatar
 
Join Date: Mar 2003
Location: NCK, Logs, Server
Posts: 3,252
Member: 23684
Status: Offline
Sonork: 1582723
Thanks Meter: 684
Quote:
Originally Posted by Dejan Kaljevic View Post
...
You have to find flasher that allows very fast entering phone in FLASH mode!!!
...
Fine , theory is clear.
What flasher You can recommend ?
WBR !
  Reply With Quote
Old 01-31-2007, 20:23   #5 (permalink)
No Life Poster
 
..::ArchitRaj::..'s Avatar
 
Join Date: Sep 2005
Location: Uttaranchal
Age: 35
Posts: 2,504
Member: 181696
Status: Offline
Sonork: 100.107830
Thanks Meter: 5,406
Quote:
Originally Posted by moldovan View Post
Fine , theory is clear.
What flasher You can recommend ?
WBR !
Hi

I think MT is good


BR
Archit Raj

Last edited by ..::ArchitRaj::..; 02-02-2007 at 05:04.
  Reply With Quote
Old 01-31-2007, 20:32   #6 (permalink)
No Life Poster
 
Join Date: Jul 2001
Location: Spinning on my OWN Orbit
Posts: 968
Member: 5358
Status: Offline
Thanks Meter: 211
Dejans theory is true but the question is can we use the the back up RPL to rewrite after downgrade or we need to buy RPL from nokia server and write it to the downgraded phone.

F1 is not too fast flasher must better mt-box flasher. If dejan bb5 unlocker is available much better but until now there is no picture of that amazing box.
  Reply With Quote
Old 01-31-2007, 20:40   #7 (permalink)
Temporary banned !!
 
Join Date: May 2005
Age: 39
Posts: 257
Member: 148045
Status: Offline
Thanks Meter: 17
i hope it is work

good luck
  Reply With Quote
Old 01-31-2007, 21:46   #8 (permalink)
Freak Poster
 
Join Date: May 2005
Location: Serbia
Age: 45
Posts: 269
Member: 146744
Status: Offline
Thanks Meter: 25
why you need a picture.. you can put it in anybox.. and paint it and write anything that you like on it.. it's not important how it looks like so you can see it....
  Reply With Quote
Old 01-31-2007, 21:47   #9 (permalink)
Freak Poster
 
Join Date: Feb 2001
Posts: 213
Member: 3354
Status: Offline
Thanks Meter: 3,948
Using this method to downgrade SW, you do NOT need rpl file, but phone
must be 100% working.

About flasher. Well after this post in day or two all flasher will support
SW downgrade using this method

B.R.
Dejan

Quote:
Originally Posted by eivoig View Post
Dejans theory is true but the question is can we use the the back up RPL to rewrite after downgrade or we need to buy RPL from nokia server and write it to the downgraded phone.

F1 is not too fast flasher must better mt-box flasher. If dejan bb5 unlocker is available much better but until now there is no picture of that amazing box.
  Reply With Quote
Old 01-31-2007, 21:50   #10 (permalink)
Junior Member
 
Join Date: Jan 2007
Posts: 1
Member: 443261
Status: Offline
Thanks Meter: 0
dejan I need your help, look your mail please
tanks
  Reply With Quote
Old 01-31-2007, 21:51   #11 (permalink)
Freak Poster
 
Join Date: May 2005
Location: Serbia
Age: 45
Posts: 269
Member: 146744
Status: Offline
Thanks Meter: 25
why you need a picture?.. you can put it in any box.. and paint it and write anything that you like on it.. it's not important how it looks like but it's important what it does...
  Reply With Quote
Old 01-31-2007, 22:04   #12 (permalink)
Freak Poster
 
Join Date: May 1999
Posts: 123
Member: 8
Status: Offline
Thanks Meter: 21
Hi Dejan,

nice to see You here, how are You doing?
  Reply With Quote
Old 01-31-2007, 22:06   #13 (permalink)
No Life Poster
 
OvidelGSM's Avatar
 
Join Date: Jan 2005
Location: Worldwide
Posts: 1,433
Member: 103544
Status: Offline
Sonork: 100.75677
Thanks Meter: 155
Quote:
Originally Posted by Dejan Kaljevic View Post
Using this method to downgrade SW, you do NOT need rpl file, but phone
must be 100% working.

About flasher. Well after this post in day or two all flasher will support
SW downgrade using this method

B.R.
Dejan

sorry for off-topic ... what about that promissed boxes from you?
  Reply With Quote
Old 01-31-2007, 22:12   #14 (permalink)
Insane Poster
 
Join Date: Jan 2004
Location: Rostov-Don
Posts: 61
Member: 48356
Status: Offline
Thanks Meter: 3
Quote:
Originally Posted by Dejan Kaljevic View Post
You have to find flasher that allows very fast entering phone in FLASH mode!!!
Possible in detail?
If possible, what flasher from known
  Reply With Quote
Old 01-31-2007, 22:22   #15 (permalink)
No Life Poster
 
Kashif Khan's Avatar
 
Join Date: Oct 2004
Location: Holland China Brazil
Age: 43
Posts: 3,815
Member: 88016
Status: Offline
Thanks Meter: 320
Welcome back sir Dejan,
I read your solution i know it will work 100% but i have another question for you ,According to people's and my thinking herez only one person in this world who can provide us BB5 unlocking solution and thats you.
Why you leaved the forum?
why you don't make the box?
And when you are giving us the solution?
And who deleted your posts?

BR
Kashif Khan
  Reply With Quote
Reply

Bookmarks


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
--- BB5 Downgrade Problem - Finally Solved! --- Bph&co Nokia Base Band 5 ( BB-5 ) 76 11-18-2007 10:15
BB5 downgrade without any box!!! heydi Nokia Base Band 5 ( BB-5 ) 4 01-12-2007 03:53
-- BB5 Downgrade Procedure -- Bph&co Federal One 0 01-09-2007 22:31
bb5 downgrade samanthe Nokia Base Band 5 ( BB-5 ) 3 05-19-2006 20:24

 



All times are GMT +1. The time now is 08:58.



Powered by Searchlight © 2024 Axivo Inc.
vBulletin Optimisation provided by vB Optimise (Pro) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
- GSM Hosting Ltd. - 1999-2023 -
Page generated in 0.23209 seconds with 10 queries

SEO by vBSEO