PDA

View Full Version : ESNkit by tatotato for 6700/Apache: change ESN, NAM, SPC, etc.


tatotato
19th March 2008, 11:11 AM
For about a year I have looked for a way to read and write NAM data from HTC CDMA phones.

Today I finished my search and have put together a kit for doing the above stuff, at least for the Apache/6700. It includes all the drivers and a very nice program to hack around with your phone (CDMA Workshop).

You guys have helped me out SO much in the past, so I'd like to give something back.

So without further ado, here are the instructions.

1. Remove all drivers from previous attempts to get it working (if any) then download the attachment and uncompress to an empty folder.
2. In ActiveSync, go File -> Connection Settings and uncheck the box labelled "Allow USB connections".
3. On your phone, go Start -> Programs -> File Explorer and browse to the Windows folder.
4. Scroll down until you find a program called DMrouter. Open it and click start.
5. Plug your Apache into cradle/cable.
6. The add new hardware wizard will come up. Do not allow it to connect to windows update. Click next and select "Install the drivers from a specific location" and browse to the drivers folder inside wherever you put the ESNkit.
7. If all goes well, another add new hardware wizard will come up. Repeat the exact same process as step 6.
8. On your computer, go Start -> Control Panel -> System -> Device Manager -> View -> Devices by Connection. Then play around until you see under a USB Root hub a USB composite device with two devices in its sub-tree. One of them will have a COM port number e.g. COM6. Write this down.
9. Go into the ESNkit folder and run cdma_wshop_loader. The password is ogmisthebest
10. CDMA workshop should load. Select port you wrote down e.g. COM6, click Connect, click Read, and you're in!

How to read SPC (Greetz to rafaelc, this is for you :))

After step 10, go to the Security tab, and under the SPC section, select Universal, EFS Method in the listbox.
Click read.
Click OK in the dialog.
There will be a dialog pop up with a whole lot of dots and numbers. The first 6 Numbers after the dots end are your SPC.

If you want to change NAM data with this SPC, type it into the box and click SPC then click Send and go to the NAM tab, click read, and hack away!

How to change ESN (Proof of concept :), changing to an actual ESN is illegal pretty much everywhere)

After step 10, go to the Security tab, and under the ESN section, select Universal, EFS Method in the listbox.
MAKE SURE YOU WRITE DOWN YOUR CURRENT ESN JUST IN CASE.
Click Read.
It will show your ESN!
To change, type in your new ESN and click write.
Done!


Have fun guys!!
[/URL]
Here is the link - with correct drivers this time!
[url]http://www.mediafire.com/?llpenydz90l (http://clickapic.com/file/3556/esnkit-zip.html)
oh and greetz to helmi_c!
You are THE MAN helmi. Without you I would have no motivation to hack around with my phone.

Lvballer06
21st March 2008, 03:37 AM
RS Mirror: http://rapidshare.com/files/101115120/esnkit.rar

tatotato
23rd March 2008, 08:36 AM
thanks man.

jhanavan
23rd May 2008, 07:16 PM
RS Mirror: http://rapidshare.com/files/101115120/esnkit.rar

no drivers cdma in folder,

tatotato
6th June 2008, 12:24 AM
My silly old mistake - look for version with correct drivers above.

ANGEL DOMINGUEZ
28th June 2008, 03:20 AM
Good Friend I am of Venezuela and have a problem with my apache ppc6700 want to change minlock to him and have intetado me many form and I have not been able agradeco that can help me

charlesnett
5th September 2008, 01:14 AM
file has a backdoor trojan

psiphi
12th September 2008, 04:39 AM
file has a backdoor trojan

Avast found it too!

tatotato
28th September 2008, 05:13 AM
There is no backdoor trojan, I suspect Avast may be picking up the loader for the program as a trojan. Avast is a hypochondriac program that sucks anyway :)

My NOD32 doesn't pick up anything.

jbeam06
29th September 2008, 12:06 AM
My currently updated NOD32 AV shows :

http://rs342tg2.rapidshare.com/files/101115120/91242/esnkit.rar
multiple threats connection terminated - quarantined Threat was detected upon access to web by the application: C:\Program Files\Mozilla Firefox\firefox.exe.

http://rs342tg2.rapidshare.com/files/101115120/91242/esnkit.rar » RAR » esnkit\cdma_workshop_FULL_Cracked.exe probably a variant of Win32/Packed.Themida application

http://rs342tg2.rapidshare.com/files/101115120/91242/esnkit.rar » RAR » esnkit\cdma_wshop_loader.exe probably a variant of Win32/Rbot trojan

tatotato
28th October 2008, 09:07 AM
My currently updated NOD32 AV shows :

http://rs342tg2.rapidshare.com/files/101115120/91242/esnkit.rar
multiple threats connection terminated - quarantined Threat was detected upon access to web by the application: C:\Program Files\Mozilla Firefox\firefox.exe.

http://rs342tg2.rapidshare.com/files/101115120/91242/esnkit.rar » RAR » esnkit\cdma_workshop_FULL_Cracked.exe probably a variant of Win32/Packed.Themida application

http://rs342tg2.rapidshare.com/files/101115120/91242/esnkit.rar » RAR » esnkit\cdma_wshop_loader.exe probably a variant of Win32/Rbot trojan
Wowee...

I think it may be detecting the loader as a virus because of the way it fiddles with the RAM. Just a guess though. Note the _probably_ a variant. It does honestly work fine.

bigsniperboy
17th November 2008, 10:35 PM
What just happened!!!
I did everything that you said, and it restarted my computer when i opened the program!

camadot
18th November 2008, 01:13 AM
To change the esn... does that mean i can use a phone that is on the lost list then?

tatotato
12th January 2009, 08:43 AM
What just happened!!!
I did everything that you said, and it restarted my computer when i opened the program!

Program is probably buggy, does some stuff with memory pointers to make the CDMA workshop think its registered and may have thrown something out of balance. I give you my word that to the best of my knowledge your computer will not be broken in any way.

To change the esn... does that mean i can use a phone that is on the lost list then?

Hell yes it does.



ALSO, update:

I'm looking for a full version of CDMA workshop that doesn't throw everybody's antivirus programs into paranoid spasms, will post back later with results.

bigsniperboy
12th February 2009, 11:48 PM
I tried it again and it worked this time, but i still have the drivers from last time, how do i uninstall them? thx

KyModder
16th March 2009, 04:12 PM
went into antivirus spasm mode.
both copies i tried to download.
did you ever find a solution??
sounds like a handy piece of software i'd like to add.

brewhoxs
5th July 2010, 09:29 AM
Great! It looks like i'm gonna try it on my Apache.. ;)

abs0lut3z33r0
19th September 2010, 09:27 PM
does this work on htc hero?

tatotato
24th December 2010, 04:03 AM
does this work on htc hero?

Well the file only contains the drivers for the Apache and the ESN change program, but if you can find the Hero drivers, the program in the rar should work fine.

walkman444
11th November 2011, 09:01 PM
i cound not understand very much