FORUMS

Analysis & Opinion

Top Forum Discussions

DEV ONLY - NAND access + Full Unlock for Lumia 710 & 800

1,056 posts
Thanks Meter: 3,758
 
By biktor_gj, Senior Member on 7th April 2012, 09:40 PM
Post Reply Subscribe to Thread Email Thread
3rd May 2012, 11:51 PM |#781  
ombadboy's Avatar
Senior Member
London
Thanks Meter: 26
 
Donate to Me
More
Quote:
Originally Posted by crnkoj

guys i dont want to spam, but i cant find it elsewhere, i have a 2.3 hw lumia with 12070, that was never flashed with ncs (at least to my knowledge) and the vol up +power button combo dont work, but if i try to flash an older (11414 firmware) with NCS to it, it finds a qualcomm cdma technologies MSM device and cannot get the driver for it, picture of it http://dl.dropbox.com/u/24268926/lumiancs.jpg , if i then take the phone and connect it to a linux device and do a dmesg i get this http://pastebin.ca/2143265 , it does seem to me that it actually has the qualcomm and not the nokia dload bootloader, or am i mistaken and if i am not, what am i doing wrong or why will it not boot up into the nand mode after using that combo?
thanks

could you please attach the firmware that you flashed? (11414)
 
 
4th May 2012, 04:29 AM |#782  
Senior Member
Flag mumbai
Thanks Meter: 134
 
Donate to Me
More
Quote:
Originally Posted by ombadboy

could you please attach the firmware that you flashed? (11414)

this maybe the firmware we are looking for, but he says he TRIED flashing which gives him qualcomm, for HW rev. 2.3, and we are already on 2.4.
Last edited by surya467; 4th May 2012 at 04:31 AM.
4th May 2012, 07:14 AM |#783  
Member
Thanks Meter: 16
 
More
Quote:
Originally Posted by crnkoj

so i tried to get this working, but cannot get the driver for it

You didnt try the driver i had posted earlier in this thread, did you? For me QPST is working fine on windows 7 both with lumia 710 and 800.
Last edited by bleh815; 4th May 2012 at 07:17 AM.
4th May 2012, 07:38 AM |#784  
Senior Member
Thanks Meter: 369
 
More
Quote:
Originally Posted by bleh815

You didnt try the driver i had posted earlier in this thread, did you? For me QPST is working fine on windows 7 both with lumia 710 and 800.

Hmm, sorry I didn't find it earlier, thanks for the link. I'll try later today.

Edit: I tried it and had to modify the driver USB\VID_05C6&PID_9006&REV_0000&MI_00
USB\VID_05C6&PID_9006&MI_00 to erase the &MI_00 part, than it recognised it (had to go into test mode on win7 aswell), now i get this, the phone is apparently recognised as Qualcomm HS-USB Diagnostics 9006 , but qpst doesnt see it when connected, here a picture of it all http://dl.dropbox.com/u/24268926/lumiaQPST.jpg
any ideas ?

Edit2: thanks for the help guys, i somehow managed to get the 11414 firmware flashed with nss with "refurbish". phone restarted at least 10 times and than it started flashing, after this i can use the vol up + power button combo (it gives a short vibration unlike the long one before), but it now says Nokia DLOAD when i do it and connect to the linux pc, guess im out of luck =/ Might be the previous owner actually used NCS for flashing the 12070 update ...
thanks again all for the help.
Last edited by crnkoj; 4th May 2012 at 03:21 PM.
4th May 2012, 07:44 AM |#785  
Senior Member
Thanks Meter: 369
 
More
Quote:
Originally Posted by ombadboy

could you please attach the firmware that you flashed? (11414)

It's just the firmware for the country code for my phone from navifirm+, I'll try to set up a link later, so you can play around. I do think there is a "bug" with my phone though, as it won't short vibrate when I press vol up + power (tried it on my gf's lumia 800, that has 2.3 and 12070 and it immediately made the short vibrate and went black screen, I didn't have a pc to test if it went into qualcomm or nokia dload though - but I assume it went into qualcomm, since it's one of the first batches and was never ncs flashed.
Edit: here is the link http://dl.dropbox.com/u/24268926/059L7F7.7z
Last edited by crnkoj; 4th May 2012 at 09:04 AM.
4th May 2012, 10:59 AM |#786  
ombadboy's Avatar
Senior Member
London
Thanks Meter: 26
 
Donate to Me
More
Quote:
Originally Posted by crnkoj

It's just the firmware for the country code for my phone from navifirm+, I'll try to set up a link later, so you can play around. I do think there is a "bug" with my phone though, as it won't short vibrate when I press vol up + power (tried it on my gf's lumia 800, that has 2.3 and 12070 and it immediately made the short vibrate and went black screen, I didn't have a pc to test if it went into qualcomm or nokia dload though - but I assume it went into qualcomm, since it's one of the first batches and was never ncs flashed.
Edit: here is the link http://dl.dropbox.com/u/24268926/059L7F7.7z

Cheers.. Ill have a look at it and report back..
4th May 2012, 11:53 AM |#787  
Member
Thanks Meter: 4
 
More
Hey guys, can't you make an .exe for windows, so we can easily root our windows phones? Regards.

Sent from my Windows Phone 7.5 using Board Express
4th May 2012, 01:53 PM |#788  
beidl's Avatar
Senior Member
Flag Purbach
Thanks Meter: 180
 
Donate to Me
More
Quote:
Originally Posted by GeBoe

Hey guys, can't you make an .exe for windows, so we can easily root our windows phones? Regards.

Sent from my Windows Phone 7.5 using Board Express



So, I tried reconstructing the SplashScreen.dll and other GFX driver files (from XIP), but either I miss something or I just absolutely suck at using OSBuilder.
Must be useful for getting the right memory addresses and GPIOs for LK.
Could someone tell me how to get this done?
The Following 4 Users Say Thank You to beidl For This Useful Post: [ View ]
4th May 2012, 05:01 PM |#789  
biktor_gj's Avatar
OP Senior Member
Thanks Meter: 3,758
 
Donate to Me
More
Quote:
Originally Posted by beidl



So, I tried reconstructing the SplashScreen.dll and other GFX driver files (from XIP), but either I miss something or I just absolutely suck at using OSBuilder.
Must be useful for getting the right memory addresses and GPIOs for LK.
Could someone tell me how to get this done?

My friend, that is hard as hell without haret sniffing data while you power cycle the screen..


Sent from my GT-I9100 using XDA
The Following User Says Thank You to biktor_gj For This Useful Post: [ View ]
4th May 2012, 06:17 PM |#790  
Senior Member
Flag mumbai
Thanks Meter: 134
 
Donate to Me
More
Quote:
Originally Posted by ombadboy

Cheers.. Ill have a look at it and report back..


mine is a 2.4, made no difference
4th May 2012, 08:07 PM |#791  
donpromillo's Avatar
Member
Thanks Meter: 15
 
More
Quote:
Originally Posted by biktor_gj


Attached:
ULZ files.zip:
* FFU update with updateWP, failing when checking the file after it has erased the OS & data partitions
* Nokia OSBL firmware update (the recovery) after having erased the flash.
And updatewp's own log, it's in spanish (native language) but easy enough to read (or use translate.google.com)

Those .ulz files are opened with USBlyzer. They have a fully functional trial version. Sorry for using proprietary software but it was the only fully working solution I found that worked (and don't want to be messing around passing all this through ethernet to sniff it with linux wireshark): http://www.usblyzer.com/

Hi biktor_gj,

I tried to open your usb-sniffs, but it failes, cause my usblyzer is ver 2.0 Build 25 and reports, that your files are older, unsupported version. Which one do u use?

BTW: Did not have the chance (and time) to sniff the second part after reboot yet. There is a difficulty to manage the device change, when the nokia boots into the service mode. USBLyzer doesn't care about the newly created device and I'm not fast enough to change it to sniff that device, so I did not get the first handshake pakets, which are so important to get (possibly) the cert and private key that decrypt the mtpz-session.


Regards


BTW2: Have a crazy thought: What would be, if the encryption of the snapshot made by zune before update, is only the encryption done by mtpz, nothing more. Then it should be as simple as to find the encryption scheme and parameters of that encryption process to decrypt such a backup to original data stream and store into a imgfs-partition. If further a tool exists, that can extract files from that imgfs-partition and rebuild it after changing something (something like OSbuilder, enhanced with a feature to extract and rebuild the "user"-part of dumps), you should be able to change any file in that backup, which does not have a signature. The (offline in backup) stored registry-files shouldn't have a signature, because registry is dynamically merged from different parts at runtime, and changes with any newly installed app. so interop unlock could be possible and also the restore of all settings, app, mails, sms ... all in one. What a dream!

Read More
Post Reply Subscribe to Thread

Tags
android, bootloader, full unlock, interopunlock, nand
Previous Thread Next Thread
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes