GSM Shop GSM Shop
GSM-Forum  

Welcome to the GSM-Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features.
Only registered members may post questions, contact other members or search our database of over 8 million posts.

Registration is fast, simple and absolutely free so please - Click to REGISTER!

If you have any problems with the registration process or your account login, please contact contact us .

Go Back   GSM-Forum > GSM & CDMA Phones / Tablets Software & Hardware Area > Nokia > Nokia Base Band 5 ( BB-5 )


Nokia Base Band 5 ( BB-5 ) Baseband-5 Phones: 2700 Classic , 2730 Classic , 3109c , 3110c , 3120c , 3250 , 3500c , 3600s , 3610 Fold , 3710 Fold , 3720 Classic , 5130 XpressM , 5200 / 5200b , 5220 XpressM , 5230 XpressM , 5300 / 5300b , 5310 / 5310b , 5320 , 5500 , 5530 XpressM , 5610 , 5630 XpressM , 5700 , 5730 XpressM , 5800 , 6085 / 6086 , 6110n , 6120c , 6121c , 6124c , 6125 , 6126 / 6133b , 6131 / 6133 , 6131 (NFC) , 6136 , 6151 , 6208 Classic , 6210n , 6212c , 6220c , 6233 , 6234 , 6260 Slide , 6263 , 6267 , 6270 , 6280 / 6288 , 6282 , 6290 , 6300 , 6300i , 6301 , 6303 Classic , 6500 Classic , 6500 Slide , 6555 , 6600 Fold , 6600 Slide , 6630 , 6650 Fold , 6680 , 6681 , 6682 , 6700 Classic , 6710 Navigator , 6720 Classic , 6730 Classic , 6760 Slide , 6790 Surge , 7210c , 7310c , 7370 , 7373 , 7390 , 7500 , 7510c , 7610c , 7900 , 8600 , 8800 arte , E50 , E51 , E52 , E55 , E60 , E61 , E61i , E62 , E63 , E65 , E66 , E70 , E71 , E72 , E75 , E90 , N70 , N71 , N72 , N73 , N75 , N76 , N77 , N78 , N79 , N80 , N81 , N82 , N85 , N86 , N90 , N91 , N92 , N93 , N93i , N95 , N95 8GB , N96 , N97 , N97 Mini , X3 , X6

Reply
 
LinkBack Thread Tools Display Modes
Old 06-08-2009, 07:54   #1 (permalink)
No Life Poster
 
moulnisky's Avatar
 
Join Date: Jan 2009
Location: England
Age: 59
Posts: 17,681
Member: 947561
Status: Offline
Thanks Meter: 14,052
Unlock any PM308 write protected SL2 using RPL: possible?


Spent last night doing experiments about RPL.
Reading the logs of Genie RPL generator to solve the SP corrupted data I saw the RPL generate by their server are in this structure..

CERT_PROG_DATA_OUT_CMT]
SIMLOCK_DATA_1=8D15652AF81FAD349B84440CEAAD97D8DD1 7601F0000000000000000244070000000000000180700
SIMLOCK_DATA_2=000000000050000005FFFFFF00B4000005F FFFFF0118000005FFFFFF017C000005FFFFFF01E00000
SIMLOCK_DATA_3=05FFFFFF0244000005FFFFFF02A8000005F FFFFF000000007FFF6F07FFFFFFFFF800030C03000503
SIMLOCK_DATA_4=000000007FFF6F3EFFFFFFFFC000030F020 00103000000007FFF6F3FFFFFFFFFC000031102000103
SIMLOCK_DATA_5=000000007FFF6F07FFFFFFFF07FE0313080 00503000000007FFF6F07FFFFFFFF07FE031B08000503
SIMLOCK_DATA_6=000000007FFF6F07FFFFFFFFF8000323030 00503000000007FFF6F3EFFFFFFFFC000032602000103
SIMLOCK_DATA_7=000000007FFF6F3FFFFFFFFFC0000328020 00103000000007FFF6F07FFFFFFFF07FE032A08000503
SIMLOCK_DATA_8=000000007FFF6F07FFFFFFFF07FE0332080 00503000000007FFF6F07FFFFFFFFF800033A03000503
SIMLOCK_DATA_9=000000007FFF6F3EFFFFFFFFC000033D020 00103000000007FFF6F3FFFFFFFFFC000033F02000103
SIMLOCK_DATA_10=000000007FFF6F07FFFFFFFF07FE034108 000503000000007FFF6F07FFFFFFFF07FE034908000503
SIMLOCK_DATA_11=000000007FFF6F07FFFFFFFFF800035103 000503000000007FFF6F3EFFFFFFFFC000035402000103
SIMLOCK_DATA_12=000000007FFF6F3FFFFFFFFFC000035602 000103000000007FFF6F07FFFFFFFF07FE035808000503
SIMLOCK_DATA_13=000000007FFF6F07FFFFFFFF07FE036008 000503000000003F007F206F07FFFFF800036803000503
SIMLOCK_DATA_14=000000003F007F206F3EFFFFC000036B02 000103000000003F007F206F3FFFFFC000036D02000103
SIMLOCK_DATA_15=000000003F007F206F07FFFF07FE036F08 000503000000003F007F206F07FFFF07FE037708000503
SIMLOCK_DATA_16=000000003F007F206F07FFFFF800037F03 000503000000003F007F206F3EFFFFC000038202000103
SIMLOCK_DATA_17=000000003F007F206F3FFFFFC000038402 000103000000003F007F206F07FFFF07FE038608000503
SIMLOCK_DATA_18=000000003F007F206F07FFFF07FE038E08 000503000000003F007F206F07FFFFF800039603000503
SIMLOCK_DATA_19=000000003F007F206F3EFFFFC000039902 000103000000003F007F206F3FFFFFC000039B02000103
SIMLOCK_DATA_20=000000003F007F206F07FFFF07FE039D08 000503000000003F007F206F07FFFF07FE03A508000503
SIMLOCK_DATA_21=FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
SIMLOCK_DATA_22=FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
SIMLOCK_DATA_23=FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
SIMLOCK_DATA_24=FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
SIMLOCK_DATA_25=FFFFFFFF
SIMLOCK_KEY_DATA_1=BFD40CB1E072BBF403BF77BB5BD50374461E725A0ACAB74315 ACB0EE116D7015883EF239C8C06DC4
SIMLOCK_KEY_DATA_2=0E4F95D145B267B3411D1C8DD154FDE7683328135F908012B3 4FD914ADC2986318F06A036CB21D03
SIMLOCK_KEY_DATA_3=B1AA4DA5023E3E2A8EE4F102467321416E8ED560


The first part (SIMLOCK_DATA_1 to 25) is always the same.. (is just a PM120 field 0 unlocked with provvider key 24407)
The second part (SIMLOCK_KEY_DATA_1 to 3) is just the fields 1 and 2 of the mobile field 120

[120]
0=800000000000000000101000000000000018010000000000 0020000001FFFFFF000000007FFF6F07FFFFFFFFF800003403 00050300101FFF
1=BFD40CB1E072BBF403BF77BB5BD50374461E725A0ACAB74315 ACB0EE116D7015883EF239C8C06DC40E4F95D145B267B3411D1C8DD154FDE7683328135F908012B3 4FD914ADC2986318F06A036CB21D03
2=B1AA4DA5023E3E2A8EE4F102467321416E8ED560

Considering today all the boxes can read a PM120 and can write an RPL using this 2 informations create an RPL like this is an easy job.
We can write an RPL in all the rapido SL2 phone without problem included in those which have the PM308 write protected.
The rpl in this structure, generate by the Genie universal server, once written in the mobile give the mobile unlocked!
So, if we create, as sample, for a nokia 5800, reading the PM120 in it, an RPL like this and we write it in the mobile will be it unlocked?

Tests and logs will follow shortly..

BR

Alex
  Reply With Quote
The Following 15 Users Say Thank You to moulnisky For This Useful Post:
Show/Hide list of the thanked
Old 06-09-2009, 13:55   #2 (permalink)
Freak Poster
 
Join Date: Sep 2005
Posts: 283
Member: 182413
Status: Offline
Thanks Meter: 351
Is possible................but at the moment i dont have any phone to try..
  Reply With Quote
Old 09-13-2009, 22:32   #3 (permalink)
No Life Poster
 
JAVA Good's Avatar
 
Join Date: May 2004
Age: 54
Posts: 2,440
Member: 66136
Status: Offline
Thanks Meter: 200
hello mister moulnisky

because I'am verry bad in english, I need some reply from you and help you.

this RPL file is generated by Genie clip for unlock phone, can you tell me for wich phone pls ?

if I good understand, all the box, for unlock a BB5 SL2, read the field 120 and 308, generate a RPL and write it ?, I tell this because on some phone the 308 is protected, I think N96, 5800.

I have an experience on a RM-320 N95 8GB :
some one of my friend unlock this phone, and put it in Contact Reteiler, I find the original full pm and compair,
after read the PM of phone, I see this :
1) on PM 120 they have only first line changed : 0 = xxxxxxx101
2) but about field 308 it's all changed

I just change the first line of PM120 and all field 308, and phone is ok, SO after this I can understand the phone change 120 and 308 for unlocking.

but I have a small question if you know, what is the best RPL backup, because on some RPL backup files the name is for exemple :

356XXXXXXXXXXX_CRT_backup_718286, and inside this file I have this line :
[CERT_PROG_DATA_OUT_CMT]

and some time I have too this :
[CERT_PROG_DATA_OUT_APE]

but I am some confused, with a same phone I don't have all the time the same size of RPL backup, so I 'am not sure if I have a good backup.

Best Regards,
JAVA Good.
  Reply With Quote
The Following User Says Thank You to JAVA Good For This Useful Post:
Old 09-13-2009, 22:56   #4 (permalink)
No Life Poster
 
CooLer55555's Avatar
 
Join Date: Jul 2003
Location: Austria
Age: 43
Posts: 1,122
Member: 35153
Status: Offline
Thanks Meter: 64
but how to create this 3 lines?
  Reply With Quote
Old 09-13-2009, 23:32   #5 (permalink)
No Life Poster
 
JAVA Good's Avatar
 
Join Date: May 2004
Age: 54
Posts: 2,440
Member: 66136
Status: Offline
Thanks Meter: 200
if you speack about 3 line of field 120, it's specific for the phone, you can't create it and if you write a field 120 of other phone you lose this 3 line and sure need an RPL files for repair this,

but about the first line in field 120 like 0 = 8xxxxxxxxxxxxxx101
or 0= 00000000000028001 this line can be maded with JAU software.

and about field 308, this is an other world, I just know on SL2 phone the line 0 of field 120 and all field 308 is changed.

Best Regards,
JAVA Good.
  Reply With Quote
The Following User Says Thank You to JAVA Good For This Useful Post:
Old 09-14-2009, 03:14   #6 (permalink)
No Life Poster
 
free1600's Avatar
 
Join Date: Mar 2007
Location: /Fr/Ch\Ro\
Age: 39
Posts: 1,334
Member: 467911
Status: Offline
Thanks Meter: 351
some one tested ?

br,
free1600
  Reply With Quote
Old 09-14-2009, 04:19   #7 (permalink)
No Life Poster
 
toutou_gsm's Avatar
 
Join Date: Nov 2007
Location: inside nck
Posts: 3,886
Member: 628112
Status: Offline
Sonork: 100.1589052
Thanks Meter: 3,726
i think its a good idea may be a good solution for sl2 phones


b.r toutou_gsm
  Reply With Quote
The Following User Says Thank You to toutou_gsm For This Useful Post:
Old 09-14-2009, 07:54   #8 (permalink)
No Life Poster
 
CooLer55555's Avatar
 
Join Date: Jul 2003
Location: Austria
Age: 43
Posts: 1,122
Member: 35153
Status: Offline
Thanks Meter: 64
Quote:
Originally Posted by free1600 View Post
some one tested ?

br,
free1600
no. but i will test it today on a n96
  Reply With Quote
The Following User Says Thank You to CooLer55555 For This Useful Post:
Old 09-14-2009, 08:08   #9 (permalink)
No Life Poster
 
JAVA Good's Avatar
 
Join Date: May 2004
Age: 54
Posts: 2,440
Member: 66136
Status: Offline
Thanks Meter: 200
after unlocking :

- the first line of field 120 changed,

- and all line of 308 is changed, just some line in the end of this fiel it's only 0000000000, and this don't change, but for exemple with my exemple I find 2 big 0000000 line.

- and I haven't a good software and easy to use for compaire PM, but I see a small modification on all field, but I think this is not importante, because all peopel tell you can write a good PM on phone, so this other field is universal for the same phone model.

I share the Full locked PM and Full unlocked PM of a RM-320 if some one need compaire.

Best Regards,
JAVA Good.
Attached Files
File Type: rar RM-320 Full locked and unlock PM by JAVA Good.rar (21.1 KB, 191 views)
  Reply With Quote
The Following User Says Thank You to JAVA Good For This Useful Post:
Old 09-14-2009, 11:52   #10 (permalink)
Freak Poster
 
Join Date: May 2008
Posts: 157
Member: 766582
Status: Offline
Thanks Meter: 17
Quote:
Originally Posted by moulnisky View Post
Spent last night doing experiments about RPL.
Reading the logs of Genie RPL generator to solve the SP corrupted data I saw the RPL generate by their server are in this structure..

CERT_PROG_DATA_OUT_CMT]
SIMLOCK_DATA_1=8D15652AF81FAD349B84440CEAAD97D8DD1 7601F0000000000000000244070000000000000180700
SIMLOCK_DATA_2=000000000050000005FFFFFF00B4000005F FFFFF0118000005FFFFFF017C000005FFFFFF01E00000
SIMLOCK_DATA_3=05FFFFFF0244000005FFFFFF02A8000005F FFFFF000000007FFF6F07FFFFFFFFF800030C03000503
SIMLOCK_DATA_4=000000007FFF6F3EFFFFFFFFC000030F020 00103000000007FFF6F3FFFFFFFFFC000031102000103
SIMLOCK_DATA_5=000000007FFF6F07FFFFFFFF07FE0313080 00503000000007FFF6F07FFFFFFFF07FE031B08000503
SIMLOCK_DATA_6=000000007FFF6F07FFFFFFFFF8000323030 00503000000007FFF6F3EFFFFFFFFC000032602000103
SIMLOCK_DATA_7=000000007FFF6F3FFFFFFFFFC0000328020 00103000000007FFF6F07FFFFFFFF07FE032A08000503
SIMLOCK_DATA_8=000000007FFF6F07FFFFFFFF07FE0332080 00503000000007FFF6F07FFFFFFFFF800033A03000503
SIMLOCK_DATA_9=000000007FFF6F3EFFFFFFFFC000033D020 00103000000007FFF6F3FFFFFFFFFC000033F02000103
SIMLOCK_DATA_10=000000007FFF6F07FFFFFFFF07FE034108 000503000000007FFF6F07FFFFFFFF07FE034908000503
SIMLOCK_DATA_11=000000007FFF6F07FFFFFFFFF800035103 000503000000007FFF6F3EFFFFFFFFC000035402000103
SIMLOCK_DATA_12=000000007FFF6F3FFFFFFFFFC000035602 000103000000007FFF6F07FFFFFFFF07FE035808000503
SIMLOCK_DATA_13=000000007FFF6F07FFFFFFFF07FE036008 000503000000003F007F206F07FFFFF800036803000503
SIMLOCK_DATA_14=000000003F007F206F3EFFFFC000036B02 000103000000003F007F206F3FFFFFC000036D02000103
SIMLOCK_DATA_15=000000003F007F206F07FFFF07FE036F08 000503000000003F007F206F07FFFF07FE037708000503
SIMLOCK_DATA_16=000000003F007F206F07FFFFF800037F03 000503000000003F007F206F3EFFFFC000038202000103
SIMLOCK_DATA_17=000000003F007F206F3FFFFFC000038402 000103000000003F007F206F07FFFF07FE038608000503
SIMLOCK_DATA_18=000000003F007F206F07FFFF07FE038E08 000503000000003F007F206F07FFFFF800039603000503
SIMLOCK_DATA_19=000000003F007F206F3EFFFFC000039902 000103000000003F007F206F3FFFFFC000039B02000103
SIMLOCK_DATA_20=000000003F007F206F07FFFF07FE039D08 000503000000003F007F206F07FFFF07FE03A508000503
SIMLOCK_DATA_21=FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
SIMLOCK_DATA_22=FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
SIMLOCK_DATA_23=FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
SIMLOCK_DATA_24=FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
SIMLOCK_DATA_25=FFFFFFFF
SIMLOCK_KEY_DATA_1=BFD40CB1E072BBF403BF77BB5BD50374461E725A0ACAB74315 ACB0EE116D7015883EF239C8C06DC4
SIMLOCK_KEY_DATA_2=0E4F95D145B267B3411D1C8DD154FDE7683328135F908012B3 4FD914ADC2986318F06A036CB21D03
SIMLOCK_KEY_DATA_3=B1AA4DA5023E3E2A8EE4F102467321416E8ED560


The first part (SIMLOCK_DATA_1 to 25) is always the same.. (is just a PM120 field 0 unlocked with provvider key 24407)
The second part (SIMLOCK_KEY_DATA_1 to 3) is just the fields 1 and 2 of the mobile field 120

[120]
0=800000000000000000101000000000000018010000000000 0020000001FFFFFF000000007FFF6F07FFFFFFFFF800003403 00050300101FFF
1=BFD40CB1E072BBF403BF77BB5BD50374461E725A0ACAB74315 ACB0EE116D7015883EF239C8C06DC40E4F95D145B267B3411D1C8DD154FDE7683328135F908012B3 4FD914ADC2986318F06A036CB21D03
2=B1AA4DA5023E3E2A8EE4F102467321416E8ED560

Considering today all the boxes can read a PM120 and can write an RPL using this 2 informations create an RPL like this is an easy job.
We can write an RPL in all the rapido SL2 phone without problem included in those which have the PM308 write protected.
The rpl in this structure, generate by the Genie universal server, once written in the mobile give the mobile unlocked!
So, if we create, as sample, for a nokia 5800, reading the PM120 in it, an RPL like this and we write it in the mobile will be it unlocked?

Tests and logs will follow shortly..

BR

Alex


You mean if we write like above lines in a manner in Notepad (Simlosk data 1..2....3...........4.....5 etc.)
and SIMLOCK_KEY_DATA_1 edit with field 120
AND SAVE IN NOTEPAD.........................THEN it is a your phones RPL ...
Are you sure that this way we calculate RPL.............
  Reply With Quote
Old 09-14-2009, 13:16   #11 (permalink)
No Life Poster
 
moulnisky's Avatar
 
Join Date: Jan 2009
Location: England
Age: 59
Posts: 17,681
Member: 947561
Status: Offline
Thanks Meter: 14,052
Is an old Idea I had 3 months ago which i gave to the software developers (I'm not one of them).
The idea been used in different ways by some Coders (SP area rebuild or 9dd unlock).
I just used the idea to make my own "sp_area rebuild system" which i use in my workshop.
Obviously what you can read in my original post (early june) was really an early stage.. lot of studies and work been done afterward.

BR

Alex
  Reply With Quote
Old 09-14-2009, 14:53   #12 (permalink)
No Life Poster
 
JAVA Good's Avatar
 
Join Date: May 2004
Age: 54
Posts: 2,440
Member: 66136
Status: Offline
Thanks Meter: 200
hello all,

@gr8ice

use search button man, and don't put a same message in like this thread pls.

Best Regards,
JAVA Good.
  Reply With Quote
Old 09-14-2009, 22:39   #13 (permalink)
No Life Poster
 
CooLer55555's Avatar
 
Join Date: Jul 2003
Location: Austria
Age: 43
Posts: 1,122
Member: 35153
Status: Offline
Thanks Meter: 64
so, i taked my unlocked n96 and writed only the simlock key data from the locked phone to the phone and now it is locked and have no problems. so i think it is also possible to unlock a phone.
  Reply With Quote
Old 09-14-2009, 23:55   #14 (permalink)
No Life Poster
 
moulnisky's Avatar
 
Join Date: Jan 2009
Location: England
Age: 59
Posts: 17,681
Member: 947561
Status: Offline
Thanks Meter: 14,052
I think too.. we made some tests abut with oOXTCOo in that period but been stopped has he was busy with the JAU project (A really great tool) and I got busy with family situations so the idea been used only in part.
If I rebrush up it again I will post here the updates

BR

Alex
  Reply With Quote
The Following 2 Users Say Thank You to moulnisky For This Useful Post:
Old 09-15-2009, 01:32   #15 (permalink)
No Life Poster
 
oOXTCOo's Avatar
 
Join Date: Dec 2000
Location: J.A.U - Just Another Unlocker
Age: 43
Posts: 3,498
Member: 2878
Status: Offline
Thanks Meter: 9,123
Quote:
Originally Posted by moulnisky View Post
I think too.. we made some tests abut with oOXTCOo in that period but been stopped has he was busy with the JAU project (A really great tool) and I got busy with family situations so the idea been used only in part.
If I rebrush up it again I will post here the updates

BR

Alex
yes i researched it!

if simlockkeys okay, you can write your own rpl per hand and write this simlock rpl, this repairs pm308 also.

but this is mostly useless cause pm308 is mostly not demaged, mostly user overwrite the simlockkeys, and if user not overwrite the simlockeys it can repaired just by J.A.U with rebuild pm120 subblock 0.

you can only write another simlock table (locked or unlocked, number of blocks, provider... all can be changed) but this need recalculated simlockkeys for the new simlocktable.

thats the problem and thats the reason way i have stopped researching this... i have a idea how to calculate this simlockkeys, but for this i need someone with very good asm skills...
  Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
..:: FREE for ALL JAF Virtual PKEY V4 - UNLOCK any SL1, SL2 using JAF 1.98.65 ::.. zulea Nokia Base Band 5 ( BB-5 ) 384 01-25-2011 07:11
FAQ about downgrading new Firmware V30 on mobiles with PM308 Write Protected dimbo33 Cyclonebox 149 03-12-2010 21:05
Did anyone success writing protected pm308 with sx4 ??? oOXTCOo Nokia Base Band 5 ( BB-5 ) 18 08-20-2009 08:49

 



All times are GMT +1. The time now is 21:39.



Powered by Searchlight © 2024 Axivo Inc.
vBulletin Optimisation provided by vB Optimise (Pro) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
- GSM Hosting Ltd. - 1999-2023 -
Page generated in 0.30169 seconds with 10 queries

SEO by vBSEO