GSM-Forum

GSM-Forum (https://forum.gsmhosting.com/vbb/)
-   GSM Programming & Reverse Engineering (https://forum.gsmhosting.com/vbb/f83/)
-   -   How SL3 Unlock Codes are Calculated? (https://forum.gsmhosting.com/vbb/f83/how-sl3-unlock-codes-calculated-1079689/)

Haltec 08-26-2010 14:50

And can someone tell what that ASCII is !!!



Quote:

Originally Posted by geohot (Post 5713093)
@german_gsm_team Because the iPhone jailbreaks and unlocks go directly to the end users. DCT4 stuff would just go to unlockers.



AND OMG I DONT BELIEVE I MISSED THIS

Code:

00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 01 42 8A 2F 98 D7 28 AE 22 3D DA
B6 DF FC 72 73 92 F7 1C B6 00 00 00 CB E7 2D A1
69 B4 99 42 E8 BB 59 87 CD FE 73 07 F5 16 26 FF



Cube it. "SHA" placeholder is ASCII.


So even if you can fully decrypt PM120, you'll still won't know the code beacouse it is multiplied with 0-1000 range integer? hmpf....


All of guys involving in this (won't name count them here - bcos don't wan't to accidentally forgot anyone) doing really cool stuff behind our GUI unlock button.


But how (and how) much closer DM3 get...

(by speed reported, it seems that they doesn't use BF at all)

@shadab_a4u - looks that way....




BR


Haltec

josedavido 08-26-2010 15:55

Still a mistery Mr. Shadab.

i guess this work is more simple it seems, but without a little of light from programmers, will be hard for us.

..::Angel::.. 08-26-2010 15:55

Quote:

Originally Posted by Haltec (Post 6257502)
And can someone tell what that ASCII is !!!






So even if you can fully decrypt PM120, you'll still won't know the code beacouse it is multiplied with 0-1000 range integer? hmpf....


All of guys involving in this (won't name count them here - bcos don't wan't to accidentally forgot anyone) doing really cool stuff behind our GUI unlock button.


But how (and how) much closer DM3 get...

(by speed reported, it seems that they doesn't use BF at all)

@shadab_a4u - looks that way....




BR


Haltec

Hi,

Before few days ago i checked UB SL3 unlock average at their web and it was 5 mins only. So, i think DM3 also uses bruteforce or if DM3 does not use bruteforce then i would say UB has somehow connection with DM3 team :D

BR

JHUN PANABO 08-26-2010 16:13

Quote:

Originally Posted by ..::Angel::.. (Post 6257723)
Hi,

Before few days ago i checked UB SL3 unlock average at their web and it was 5 mins only. So, i think DM3 also uses bruteforce or if DM3 does not use bruteforce then i would say UB has somehow connection with DM3 team :D

BR

maybe they connected, that's why mxkey untill now, they don't had the
solution,co's they can't afford the service...

Haltec 08-26-2010 16:20

Isn't DM3 is about 5-10 sec per phone ? - about same, as standalone rsa dct4 unlock....

Don't know if they (DM3) unlock 479C...

And I saw pictures of Griffin "Plant" on other forum. Serious job.

Would be great to see some pics from other teams too...

So in production of SL3 codes - nokia multiplied every produced code with 0-1000 and let ASIC to do the math.?




Good trick. Have to admit.


Maybe DM3 have way to force phone to accept their PM120 an then just enter respective code?




BR


Haltec

dualtrace 08-26-2010 16:22

Hi,

[120]
2=6AA06D79590AD984B3A89BF148C4F4C7359E675DD7D8F
835CEA93C8DBDFE489D10B3AECB108BFE14067A9A413865
92865801F796BD355B60EC9DEBAB610CF91955E33B226FD4
B0611FE410253693B308763461031F607FCF7630C8305CAA
ABA031D909A6B1C7E41BFA3DEFEA11F0E93D7D0AE16A15E
10FBCCB11DEAD266470490100


On the above SL3 PM120,2 data sample, anyone who can guide locate the sha1 hash for LEVEL 7 unlock code?


Br,

dualtrace

..::Angel::.. 08-26-2010 17:42

Quote:

Originally Posted by Haltec (Post 6257829)
Isn't DM3 is about 5-10 sec per phone ? - about same, as standalone rsa dct4 unlock....

Don't know if they (DM3) unlock 479C...

And I saw pictures of Griffin "Plant" on other forum. Serious job.

Would be great to see some pics from other teams too...

So in production of SL3 codes - nokia multiplied every produced code with 0-1000 and let ASIC to do the math.?




Good trick. Have to admit.


Maybe DM3 have way to force phone to accept their PM120 an then just enter respective code?




BR


Haltec

Hi,

I believe that DM3 and all other team uses bruteforce to unlock SL3 phones. And they have invested alot of money in this project.

Btw, if DM3 force phone to accept their own PM120 then unlock result would be any other config key not as unlock by codes. They could also offer simlock repairs.

Well, future will tell what's method being used to unlock SL3 phone. At the moment, it seems DM3 also uses BF method..!

BR

GSM Parts 08-26-2010 17:58

Quote:

Originally Posted by ..::Angel::.. (Post 6258148)
Hi,

I believe that DM3 and all other team uses bruteforce to unlock SL3 phones. And they have invested alot of money in this project.

Btw, if DM3 force phone to accept their own PM120 then unlock result would be any other config key not as unlock by codes. They could also offer simlock repairs.

Well, future will tell what's method being used to unlock SL3 phone. At the moment, it seems DM3 also uses BF method..!

BR

In 10 seconds Bruteforce?
Not makeable i am sure !

Regards GSM Parts

angel25dz 08-26-2010 22:17

Quote:

Originally Posted by dualtrace (Post 6257836)
Hi,

[120]
2=6AA06D79590AD984B3A89BF148C4F4C7359E675DD7D8F
835CEA93C8DBDFE489D10B3AECB108BFE14067A9A413865
92865801F796BD355B60EC9DEBAB610CF91955E33B226FD4
B0611FE410253693B308763461031F607FCF7630C8305CAA
ABA031D909A6B1C7E41BFA3DEFEA11F0E93D7D0AE16A15E
10FBCCB11DEAD266470490100


On the above SL3 PM120,2 data sample, anyone who can guide locate the sha1 hash for LEVEL 7 unlock code?


Br,

dualtrace

good question that's what we need to try :-)

dualtrace 08-27-2010 04:43

Hi,

Quote:

And can someone tell what that ASCII is !!!
This is what he mean by his post.

'6675636B206D61746800DEAD0067656F686F74FF : f*ck math....geohot.'




Br,

dualtrace

oOXTCOo 08-27-2010 10:10

Quote:

Originally Posted by dualtrace (Post 6257836)
Hi,

[120]
2=6AA06D79590AD984B3A89BF148C4F4C7359E675DD7D8F
835CEA93C8DBDFE489D10B3AECB108BFE14067A9A413865
92865801F796BD355B60EC9DEBAB610CF91955E33B226FD4
B0611FE410253693B308763461031F607FCF7630C8305CAA
ABA031D909A6B1C7E41BFA3DEFEA11F0E93D7D0AE16A15E
10FBCCB11DEAD266470490100


On the above SL3 PM120,2 data sample, anyone who can guide locate the sha1 hash for LEVEL 7 unlock code?


Br,

dualtrace



to decrypt this block, some more data is needed then just the pm block ;)

angel25dz 08-27-2010 10:18

Quote:

Originally Posted by oOXTCOo (Post 6260425)
to decrypt this block, some more data is needed then just the pm block ;)

it's crypted with AES encryption ???

angel25dz 08-29-2010 00:08

Quote:

Originally Posted by angel25dz (Post 6260446)
it's crypted with AES encryption ???

It was stupid from me :(

there is no SHA1 Hash in PM120,2

[120]
2=6AA06D79590AD984B3A89BF148C4F4C7359E675DD7D8F
835CEA93C8DBDFE489D10B3AECB108BFE14067A9A413865
92865801F796BD355B60EC9DEBAB610CF91955E33B226FD4
B0611FE410253693B308763461031F607FCF7630C8305CAA
ABA031D909A6B1C7E41BFA3DEFEA11F0E93D7D0AE16A15E
10FBCCB11DEAD26647049
0100

RSA-1024 bit signature = 128 bytes
fixed 02 bytes


That's what I think, if i'm wrong correct me :)

german gsm team 08-29-2010 02:27

Quote:

Originally Posted by ..::Angel::.. (Post 6251979)
Hi,

I think no. It does not depend on MCC, MNC! They generates level7 codes which removes all restriction in phone. So, no matter which level phone is locked to. If any phone does not accept level7 code or phone is not locked to appropriate level then in this case is not possible to unlock phone with generated level7 code. - Telcel Maxico phones :)

BR

IMHO codes are still calculated by SX-5 algo (with MCC, MNC and configuration key)

Telcel phones aren't unlockable due to byte 1 is set zo 1 in profile bits .

Therfore: No cable unlock, no keypad unlock - even with correct code.

Since simlock data (including profile bits) is RSA-signed there is no way to unlock without Nokia SX-4T card and online variant change.

dualtrace 08-29-2010 03:03

Quote:

there is no SHA1 Hash in PM120,2

[120]
2=6AA06D79590AD984B3A89BF148C4F4C7359E675DD7D8F
835CEA93C8DBDFE489D10B3AECB108BFE14067A9A413865
92865801F796BD355B60EC9DEBAB610CF91955E33B226FD4
B0611FE410253693B308763461031F607FCF7630C8305CAA
ABA031D909A6B1C7E41BFA3DEFEA11F0E93D7D0AE16A15E
10FBCCB11DEAD266470490100

RSA-1024 bit signature = 128 bytes
fixed 02 bytes


That's what I think, if i'm wrong correct me

So it is in PM120,1 which is 0xA0 bytes, maybe it is similar with
DCT4+ which is encrypted, but I dont think BB5 will use SAFER-64 :) .


All times are GMT +1. The time now is 18:07.


vBulletin Optimisation provided by vB Optimise (Pro) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
- GSM Hosting Ltd. - 1999-2023 -

Page generated in 0.23435 seconds with 6 queries

SEO by vBSEO