GSM-Forum

GSM-Forum (https://forum.gsmhosting.com/vbb/)
-   Infinity-Box (https://forum.gsmhosting.com/vbb/f296/)
-   -   Motorola XT-2097-7 SP unlock (https://forum.gsmhosting.com/vbb/f296/motorola-xt-2097-7-sp-unlock-2999181/)

Leonelle 12-26-2021 18:47

Motorola XT-2097-7 SP unlock
 
Hello...
I'm unable to unlock Moto XT-2097-7 or even identify the device in all modes using CM2MT2, here is log using flash mode:

Code:

Operation : SP Unlock [ v2.32 ]
Mode : FLASH

1. Make sure device is powered off. Power off, if need. Wait 20 seconds after
2. Insert USB cable in phone
Waiting for device connection ...

PTFN : MediaTek PreLoader USB VCOM (Android) (COM106)
MODE : PRELOADER PORT
PORT : 106
Waiting BOOT ack ...
PRELOADER : ACK confirmed!
BROM : Init BROM
BROM init passed!
    CHIP : MT6765 , SBID : 0x8A00 , HWVR : 0xCA00 , SWVR : 0x0000
    CODE : Cervino
    TYPE : MODERN [RAPHAEL]
BROM : SecLevel : 0x00000005
BROM : SecMode  : SBC+SDA
BROM : BROM|BL  : 0xFF|0x03
BROM : PRELOADER PORT
AGENT : 0_base : BASE_v2112 | Manual : Disabled
AGENT : Look for suitable BootChain in DA ...
AGENT : DA_PL.bin
AGENT : Found MT6765
AGENT : MTK_DOWNLOAD_AGENT
    BROM : Sending 1st DA ...
    BROM : Reset Interface!
PTFN : MediaTek PreLoader USB VCOM (Android) (COM106)
MODE : PRELOADER PORT
PORT : 106
Waiting BOOT ack ...
PRELOADER : ACK confirmed!
BROM : Init BROM
BROM init passed!
    CHIP : MT6765 , SBID : 0x8A00 , HWVR : 0xCA00 , SWVR : 0x0000
    CODE : Cervino
    TYPE : MODERN [RAPHAEL]
BROM : SecLevel : 0x00000005
BROM : SecMode  : SBC+SDA
BROM : BROM|BL  : 0xFF|0x03
BROM : PRELOADER PORT
AGENT : 0_base : BASE_v2112 | Manual : Disabled
AGENT : Look for suitable BootChain in DA ...
AGENT : DA_PL.bin
AGENT : Found MT6765
AGENT : MTK_DOWNLOAD_AGENT
    BROM : Sending 1st DA ...

  BROM  : 0x00007024 : DA SEND ERROR!
  ERROR : SECURE BOOT : SELECTED DA NOT SUPPORTED IN CURRENT DEVICE STATE!
  INFO : PRELOADER Level : CORRECT DA required : PL/PL_CRYPTO/SWSEC

Error : Fail to init protocol!
>>> Remove battery, cable. Check cable/connection/driver! Check SW hint! Repeat operation!

Reconnect Power/Cable!

Unlock log using META mode:

Code:

Operation : SP Unlock [ v2.32 ]
Mode : META

1. Make sure device is powered off. Power off, if need. Wait 20 seconds after
2. Insert USB cable in phone
Waiting for device connection ...

PTFN : MediaTek PreLoader USB VCOM (Android) (COM106)
MODE : PRELOADER PORT
PORT : 106
Waiting BOOT ack ...
PRELOADER : ACK confirmed!
INIT : META confirmed!

Boot done!

AP_CHIP : MT6765
AP_SWTM : Tue Sep 14 15:43:58 CST 2021
AP_SWVR : alps-mp-q0.mp1-V9.135_ontim.q0mp1.k61v1.64.bsp_P16

Error : Modem didn't started! Unlock not possible!

Error : SPLock identification failed!
>>> Send log and report.log (if exists) to support! Include device info also!

Reconnect Power/Cable!


Leonelle 12-26-2021 20:00

Here is flash tool configuration:

Code:

<?xml version="1.0" encoding="UTF-8" ?>
<flashtool-config version="2.0">
    <general>
        <chip-name>MT6765</chip-name>
        <storage-type>EMMC</storage-type>
        <download-agent>SP_FLASH_TOOL_DIR\MTK_AllInOne_DA-Malta-md.bin</download-agent>
        <scatter>RECOVERY_FILE_DIR\MT6765_Android_scatter.txt</scatter>
        <authentication></authentication>
        <certification></certification>
        <rom-list>
            <rom index="0" enable="false">RECOVERY_FILE_DIR\preloader_malta.bin</rom>
            <rom index="16" enable="true">RECOVERY_FILE_DIR\logo-verified.bin</rom>
            <rom index="17" enable="true">RECOVERY_FILE_DIR\md1img-verified.img</rom>
            <rom index="18" enable="true">RECOVERY_FILE_DIR\md2img-verified.img</rom>
            <rom index="19" enable="true">RECOVERY_FILE_DIR\md4img-verified.img</rom>
            <rom index="20" enable="true">RECOVERY_FILE_DIR\md5img-verified.img</rom>
            <rom index="21" enable="true">RECOVERY_FILE_DIR\md6img-verified.img</rom>
            <rom index="22" enable="true">RECOVERY_FILE_DIR\md7img-verified.img</rom>
            <rom index="25" enable="true">RECOVERY_FILE_DIR\md1dsp-verified.img</rom>
            <rom index="26" enable="true">RECOVERY_FILE_DIR\spmfw-verified.img</rom>
            <rom index="27" enable="true">RECOVERY_FILE_DIR\scp-verified.img</rom>
            <rom index="28" enable="true">RECOVERY_FILE_DIR\sspm-verified.img</rom>
            <rom index="30" enable="true">RECOVERY_FILE_DIR\lk-verified.img</rom>
            <rom index="31" enable="true">RECOVERY_FILE_DIR\boot.img</rom>
            <rom index="32" enable="true">RECOVERY_FILE_DIR\dtbo-verified.img</rom>
            <rom index="33" enable="true">RECOVERY_FILE_DIR\tee-verified.img</rom>
            <rom index="34" enable="true">RECOVERY_FILE_DIR\vbmeta.img</rom>
            <rom index="35" enable="true">RECOVERY_FILE_DIR\vbmeta_system.img</rom>
            <rom index="36" enable="true">RECOVERY_FILE_DIR\vbmeta_vendor.img</rom>
            <rom index="54" enable="true">RECOVERY_FILE_DIR\super.img</rom>
            <rom index="59" enable="true">RECOVERY_FILE_DIR\elabel.img</rom>
            <rom index="61" enable="true">RECOVERY_FILE_DIR\userdata.img</rom>
        </rom-list>
        <connection type="BromUSB" high-speed="true" power="AutoDetect" da_log_level="Info" da_log_channel="UART" timeout-count="3600000" com-port="" storage_life_cycle_check="false" />
        <checksum-level>both</checksum-level>
        <!--log_on: log switch, enable log if true, otherwise false;
                        log_path: the directory in which the log files has been stored;
                        clean_hours: the time setting to delete log files regularly, the unit is hours.-->
        <log-info log_on="true" log_path="C:\ProgramData\SP_FT_Logs" clean_hours="744" />
    </general>
    <commands>
        <download-only>
            <da-download-all />
        </download-only>
    </commands>
</flashtool-config>


Leonelle 12-27-2021 00:29

Hello, I've got some files, I'll do the experiments and post the results here...

Leonelle 12-27-2021 12:01

Well, I found proper DA file for this model but I wasn't able to unlock it here are logs:

Code:

Operation : SP Unlock [ v2.32 ]
Mode : FLASH

1. Make sure device is powered off. Power off, if need. Wait 20 seconds after
2. Insert USB cable in phone
Waiting for device connection ...

PTFN : MediaTek PreLoader USB VCOM (Android) (COM119)
MODE : PRELOADER PORT
PORT : 119
Waiting BOOT ack ...
PRELOADER : ACK confirmed!
BROM : Init BROM
BROM init passed!
    CHIP : MT6765 , SBID : 0x8A00 , HWVR : 0xCA00 , SWVR : 0x0000
    CODE : Cervino
    TYPE : MODERN [RAPHAEL]
BROM : SecLevel : 0x00000005
BROM : SecMode  : SBC+SDA
BROM : BROM|BL  : 0xFF|0x03
BROM : PRELOADER PORT
AGENT : 0_base : BASE_v2112 | Manual : Enabled
AGENT : Look for suitable BootChain in DA ...
AGENT : MTK_AllInOne_DA-Malta-md.bin
AGENT : Found MT6765
AGENT : MTK_DOWNLOAD_AGENT
    BROM : Sending 1st DA ...
BROM : DA sent
BROM :Transfer control to DA ...
    DA : AGENT started!
DA : SYNC
    DA : MODE : PRELOADER
DA : EXT_RAM initialized!
DA : BOOT to 2nd DA ...
DA : 2ND stage confirmed!
DA : SYNC with DA passed!
DA : Receiving HW info

        SRAM: 0x00070000 [ 448.00 KB ]
        DRAM: 0x80000000 [ 2.00 GB ]

        EMMC: CID : 1501003458364B4D420360C1CE1948BD
        EMMC: VEN : SAMSUNG : OEM : 0 : ID : 3458364B4D42
        EMMC: VEN : SAMSUNG : 4X6KMB
        EMMC: SNN : 1623313945 ( 0x60C1CE19) , MF : 4/2021

        EMMC:
              BOOT1  : 0x00400000 [ 4.00 MB ]
              BOOT2  : 0x00400000 [ 4.00 MB ]
              RPMB  : 0x00400000 [ 4.00 MB ]
              USER  : 0x747C00000 [ 29.12 GB ]

        CHIP : MT6765 , SBID : 0x8A00 , HWVR : 0xCA00 , SWVR : 0x0000 , EVOL : 0x0000

        RNID : 3D54F50533EA77986D5CE5D131758AA5

DA : USB : HIGH-SPEED

Boot done!

[Info] : Unsupported security type in selected mode! Repeat operation in META mode!
INFO : Generating and send report data ...
INFO : Report sent!


Done!
Elapsed: 00:00:17

I identify log:
Code:

Operation : Identify [ v2.32 ]

Mode : FLASH

1. Make sure device is powered off. Power off, if need. Wait 20 seconds after
2. Insert USB cable in phone
Waiting for device connection ...

PTFN : MediaTek PreLoader USB VCOM (Android) (COM119)
MODE : PRELOADER PORT
PORT : 119
Waiting BOOT ack ...
PRELOADER : ACK confirmed!
BROM : Init BROM
BROM init passed!
    CHIP : MT6765 , SBID : 0x8A00 , HWVR : 0xCA00 , SWVR : 0x0000
    CODE : Cervino
    TYPE : MODERN [RAPHAEL]
BROM : SecLevel : 0x00000005
BROM : SecMode  : SBC+SDA
BROM : BROM|BL  : 0xFF|0x03
BROM : PRELOADER PORT
AGENT : 0_base : BASE_v2112 | Manual : Enabled
AGENT : Look for suitable BootChain in DA ...
AGENT : MTK_AllInOne_DA-Malta-md.bin
AGENT : Found MT6765
AGENT : MTK_DOWNLOAD_AGENT
    BROM : Sending 1st DA ...
BROM : DA sent
BROM :Transfer control to DA ...
    DA : AGENT started!
DA : SYNC
    DA : MODE : PRELOADER
DA : EXT_RAM initialized!
DA : BOOT to 2nd DA ...
DA : 2ND stage confirmed!
DA : SYNC with DA passed!
DA : Receiving HW info

        SRAM: 0x00070000 [ 448.00 KB ]
        DRAM: 0x80000000 [ 2.00 GB ]

        EMMC: CID : 1501003458364B4D420360C1CE1948BD
        EMMC: VEN : SAMSUNG : OEM : 0 : ID : 3458364B4D42
        EMMC: VEN : SAMSUNG : 4X6KMB
        EMMC: SNN : 1623313945 ( 0x60C1CE19) , MF : 4/2021

        EMMC:
              BOOT1  : 0x00400000 [ 4.00 MB ]
              BOOT2  : 0x00400000 [ 4.00 MB ]
              RPMB  : 0x00400000 [ 4.00 MB ]
              USER  : 0x747C00000 [ 29.12 GB ]

        CHIP : MT6765 , SBID : 0x8A00 , HWVR : 0xCA00 , SWVR : 0x0000 , EVOL : 0x0000

        RNID : 3D54F50533EA77986D5CE5D131758AA5

DA : USB : HIGH-SPEED

Boot done!

Product Brand  : motorola
Product Device : malta
Product Model  : moto e(7)
Product Name  : malta
Patch Level    : QOLS30.288-39-2
Display ID    : QOLS30.288-39-2 release-keys
Ver. CodeName  : REL
Ver. Release  : 10
Sec. Patch    : 2021-09-05
Build Time    : 14.09.2021
Product Info  : malta
Display ID    : QOLS30.288-39-2
Product Board  : malta
Board Platform : mt6765
Product Manfct : motorola

USERDATA : FILESYSTEM : F2FS  with FBE ( File-Base Encryption )

NVRAM : 0xA108CF31
NVRAM : State : Ok!
NVRAM : SecLv : Vendor Signed
INFO  : WiFi MAC : 441C7FC800DD
INFO  : BlTh MAC : 441C7FC83B75
INFO  : IMEI[1] : 357722570470862
INFO  : IMEI[2] : FFFFFFFFFFFFFFF


Backup sensetive data [ 17 ]
Backup path : Backup\MT6765__3D54F50533EA77986D5CE5D131758AA5\
[15] Read : NVRAM
[7] Read : NVDATA
[14] Read : PROINFO
[6] Read : NVCFG
[9] Read : PROTECT1
[1] Read : PGPT
[12] Read : PERSIST
[0] Read : PRELOADER
Backup done!


STORAGE : Life Status : eMMC : OK!
STORAGE : OTP Status : UNLOCKED!
STORAGE : RPMB Status : eMMC : RPMB  KEY PROGRAMMED [UNUSABLE]

PRELOADER : DEVICE :
 DEV : MT6765
 NME : preloader_malta.bin
 CNT : 000B
 EMI : [00] : DRAM : LP_DDR4X : ID : NOT_DEFINED : VEN : UNKNOWN  | DEV :  : RAM : [ 512.00 MB ]
 EMI : [01] : eMMC : DDR3 : ID : 150100525036344D42 : VEN : SAMSUNG  | DEV : RP64MB : RAM : [ 4.00 GB ]
 EMI : [02] : eMMC : DDR3 : ID : 13014E53304A394E38 : VEN : MICRON    | DEV : S0J9N8 : RAM : [ 4.00 GB ]
 EMI : [03] : eMMC : LP_DDR4X : ID : 700100474E424C5141 : VEN : KINGSTON  | DEV : GNBLQA : RAM : [ 2.00 GB ]
 EMI : [04] : eMMC : LP_DDR4X : ID : 150100445036444142 : VEN : SAMSUNG  | DEV : DP6DAB : RAM : [ 4.00 GB ]
 EMI : [05] : eMMC : LP_DDR4X : ID : 1501003458364B4D42 : VEN : SAMSUNG  | DEV : 4X6KMB : RAM : [ 2.00 GB ]
 EMI : [06] : eMMC : LP_DDR4X : ID : 13014E47314A395238 : VEN : MICRON    | DEV : G1J9R8 : RAM : [ 4.00 GB ]
 EMI : [07] : eMMC : LP_DDR4X : ID : 90014A684339615033 : VEN : HYNIX    | DEV : hC9aP3 : RAM : [ 4.00 GB ]
 EMI : [08] : eMMC : LP_DDR4X : ID : 90014A68423861503E : VEN : HYNIX    | DEV : hB8aP> : RAM : [ 2.00 GB ]
 EMI : [09] : DRAM : LP_DDR4X : ID : NOT_DEFINED : VEN : UNKNOWN  | DEV :  : RAM : [ 2.00 GB ]
 EMI : [0A] : DRAM : LP_DDR4X : ID : NOT_DEFINED : VEN : UNKNOWN  | DEV :  : RAM : [ 2.00 GB ]
PRELOADER saved to : Backup\PRELOADER\preloader_malta.bin

Done!
Elapsed: 00:00:26


Leonelle 12-27-2021 14:55

Is there any NVRAM file available or anyway to unlock this gadget...

JayDi 12-27-2021 15:39

Device uses additional security layer, not sure yet. We will check it.
Writing anything from another device will just kill it.

Leonelle 12-27-2021 15:51

Quote:

Originally Posted by JayDi (Post 14497183)
Device uses additional security layer, not sure yet. We will check it.
Writing anything from another device will just kill it.

Thanks for reply...
I wiped the device and flashed it again, the device read the network and after restore security files, it got locked again

rochater 03-22-2022 16:57

you need malta DA mt6575


All times are GMT +1. The time now is 14:43.


vBulletin Optimisation provided by vB Optimise (Pro) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
- GSM Hosting Ltd. - 1999-2023 -

Page generated in 0.22651 seconds with 6 queries

SEO by vBSEO