24th January 2013, 12:04 AM
(Last edited by TripNRaVeR; 24th January 2013 at 12:09 AM .)
Senior Member
Thanks Meter
10734
Posts: 1,845
Join Date: Jun 2010
Location: Stevensweert
DONATE TO ME
I have gained access to some neat tools!
The tool is also able to boot into diag58, currently i'm running it userspace and can freely set everything i want. I tried entering diag58 but it was waiting on modem. Going to try to read the secure key, it has basicly acces to everything.
If you like my work.. you may always buy me a ice cold beer
join #TripNDroid on IRC server: freenode
The Following 69 Users Say Thank You to TripNRaVeR For This Useful Post: [ Click to Expand ]
*$M3RT$* (24th January 2013),
2WildFirE (24th January 2013),
aardappel12 (24th January 2013),
adamnz (24th January 2013),
adarshmk (24th January 2013),
alpina0707 (24th January 2013),
basd43 (24th January 2013),
bbeanss (24th January 2013),
BeciMester (24th January 2013),
Black-FR (25th January 2013),
blueboiiz (24th January 2013),
Braindamage1989 (24th January 2013),
clyder (24th January 2013),
craig82 (24th January 2013),
danielgek (24th January 2013),
deadwilder (24th January 2013),
Dottcent (24th January 2013),
Drefsab (24th January 2013),
Drew Peacock (24th January 2013),
drziddo (27th January 2013),
eboye (24th January 2013),
eirikgu (24th January 2013),
ejnreon (24th January 2013),
FCDHBubbles (24th January 2013),
feraay (24th January 2013),
Fraize1 (24th January 2013),
galaxys2Tav (24th January 2013),
ghori1989 (24th January 2013),
glen.ricky (24th January 2013),
Goku80 (24th January 2013),
gorannn (24th January 2013),
Gormsen (24th January 2013),
H89P (24th January 2013),
heslo.rb26 (24th January 2013),
Juanig (24th January 2013),
Kwisatz89 (11th February 2013),
lenthele (24th January 2013),
lms24 (24th January 2013),
luiejongen (24th January 2013),
MarckX (24th January 2013),
marclooman9 (24th January 2013),
mariusdroid (24th January 2013),
MrT69 (24th January 2013),
Mr_S (24th January 2013),
myself11 (24th January 2013),
m_atze (24th January 2013),
n1kos (24th January 2013),
navalynt (24th January 2013),
nazfalas (24th January 2013),
neandertaler19 (24th January 2013),
nitrous² (24th January 2013),
Patrics83 (24th January 2013),
sindziq (24th January 2013),
SQr17 (24th January 2013),
superchilpil (24th January 2013),
svabandrei (24th January 2013),
Synoptex (24th January 2013),
Thant (24th January 2013),
The5alodi (24th January 2013),
TheJokah (24th January 2013),
thunder07 (24th January 2013),
tomascus (25th January 2013),
ugrubni (24th January 2013),
Vcek (24th January 2013),
vcrp94 (24th January 2013),
vincenzo697 (24th January 2013),
wILLRoiD (24th January 2013),
wph (24th January 2013),
zedmarcus (26th January 2013)
24th January 2013, 07:01 AM
Senior Member
Thanks Meter
256
Posts: 252
Join Date: May 2006
Location: Odelzhausen
Re: Goal: S-off HOX+ and maybe the HOX (TEGRA3)
Found this:
http://a500bootloaderflash.tk/sbkcalc/
May be lcd047 could help at this point also for the HOX.
Sent from my EndeavorU using xda app-developers app
The Following User Says Thank You to MrT69 For This Useful Post: [ Click to Expand ]
24th January 2013, 11:27 AM
Recognized Contributor / Recognized Developer
Thanks Meter
1025
Posts: 956
Join Date: Sep 2007
DONATE TO ME
Quote:
Originally Posted by
MrT69
unfortunately our sbk is very much different,
" It should be a 16 character long string containing only hexadecimal characters"
our only CPUID is one number long :/
i think ours is referred to as sbk v2 as well and it's yet to be cracked.
i know guys i'm shooting down everything you're coming up with..
but i have to before someone starts a discussion & fill the thread with it...
i've been there and tried ALOT of stuff
The Following 4 Users Say Thank You to thunder07 For This Useful Post: [ Click to Expand ]
24th January 2013, 11:49 AM
Senior Member
Thanks Meter
10734
Posts: 1,845
Join Date: Jun 2010
Location: Stevensweert
DONATE TO ME
Set odm production mode from 0x00000001 to 0x00000000 and we have what we want. How?
Well that isnt as easy as expected..
Somewhere during boot there is a check if we are in production mode or not. If we are in production mode then all locks are set. If we arent in production mode all locks are off and we have s-off.
Then we remove the check and its done. We know that the flag can be set in the fuse directory. However it requires a kernel patch, the write protection can be turned of for that section.
Where to find it?
Look at nv-tegra git, there is bootloader source and try to find it (probably htc renamed it)
If you like my work.. you may always buy me a ice cold beer
join #TripNDroid on IRC server: freenode
The Following 32 Users Say Thank You to TripNRaVeR For This Useful Post: [ Click to Expand ]
aardappel12 (24th January 2013),
alpina0707 (24th January 2013),
BeciMester (24th January 2013),
Black-FR (25th January 2013),
clyder (24th January 2013),
craig82 (24th January 2013),
eirikgu (24th January 2013),
ejnreon (24th January 2013),
FCDHBubbles (24th January 2013),
galaxys2Tav (24th January 2013),
Gormsen (24th January 2013),
Juanig (24th January 2013),
lms24 (24th January 2013),
MarckX (24th January 2013),
marclooman9 (24th January 2013),
MemAllocatoR (24th January 2013),
mido.fayad (24th January 2013),
myself11 (24th January 2013),
nazfalas (24th January 2013),
niksssss (24th January 2013),
nitrous² (24th January 2013),
Patrics83 (24th January 2013),
retschy (24th January 2013),
shree.cse (25th January 2013),
SQr17 (24th January 2013),
Synoptex (24th January 2013),
thecknt (24th January 2013),
thf1973 (24th January 2013),
vcrp94 (24th January 2013),
vincenzo697 (24th January 2013),
wILLRoiD (31st January 2013),
wph (24th January 2013)
24th January 2013, 02:49 PM
Senior Member
Thanks Meter
254
Posts: 269
Join Date: Jan 2011
Quote:
Originally Posted by
TripNRaVeR
Set odm production mode from 0x00000001 to 0x00000000 and we have what we want. How?
Well that isnt as easy as expected..
Somewhere during boot there is a check if we are in production mode or not. If we are in production mode then all locks are set. If we arent in production mode all locks are off and we have s-off.
Then we remove the check and its done. We know that the flag can be set in the fuse directory. However it requires a kernel patch, the write protection can be turned of for that section.
Where to find it?
Look at nv-tegra git, there is bootloader source and try to find it (probably htc renamed it)
tried that back in may, but i couldn't get the fuses to be writeable, tried this instead;
Code:
endeavoru-2.6.39-86aa44d/arch/arm/mach-tegra/tegra_odm_fuses.c
static bool fuse_odm_prod_mode(void)
{
u32 odm_prod_mode = 0;
clk_enable(clk_fuse);
get_fuse(ODM_PROD_MODE, &odm_prod_mode);
clk_disable(clk_fuse);
return false;
return (odm_prod_mode ? true : false);
}
The Following 3 Users Say Thank You to blubbers For This Useful Post: [ Click to Expand ]
24th January 2013, 02:56 PM
(Last edited by TripNRaVeR; 24th January 2013 at 03:03 PM .)
Senior Member
Thanks Meter
10734
Posts: 1,845
Join Date: Jun 2010
Location: Stevensweert
DONATE TO ME
Quote:
Originally Posted by
blubbers
tried that back in may, but i couldn't get the fuses to be writeable, tried this instead;
Code:
endeavoru-2.6.39-86aa44d/arch/arm/mach-tegra/tegra_odm_fuses.c
static bool fuse_odm_prod_mode(void)
{
u32 odm_prod_mode = 0;
clk_enable(clk_fuse);
get_fuse(ODM_PROD_MODE, &odm_prod_mode);
clk_disable(clk_fuse);
return false;
return (odm_prod_mode ? true : false);
}
You also need to have the vdd_fuse voltage line enabled to gain write acces, you can find the source in my kernel tree on github
Edit:
https://github.com/TripNRaVeR/tripnd...52d4ea27624646
Somehow this brings the device into APX mode when u have a ENG kernel, these bricks somehow could be usefull to gain s-off.
If we write the fuses correctly it is done.
If you like my work.. you may always buy me a ice cold beer
join #TripNDroid on IRC server: freenode
The Following 26 Users Say Thank You to TripNRaVeR For This Useful Post: [ Click to Expand ]
adamnz (24th January 2013),
alpina0707 (24th January 2013),
altbla (24th January 2013),
anomalos (24th January 2013),
basd43 (24th January 2013),
craig82 (24th January 2013),
ejnreon (24th January 2013),
galaxys2Tav (24th January 2013),
Gormsen (24th January 2013),
lenthele (24th January 2013),
MemAllocatoR (24th January 2013),
MrT69 (24th January 2013),
nazfalas (24th January 2013),
nitrous² (24th January 2013),
Nubzori (24th January 2013),
One-X-master (24th January 2013),
onelynx (24th January 2013),
Patrics83 (24th January 2013),
shree.cse (25th January 2013),
Synoptex (24th January 2013),
Thant (24th January 2013),
thf1973 (24th January 2013),
ugrubni (24th January 2013),
vcrp94 (24th January 2013),
wILLRoiD (31st January 2013),
wph (24th January 2013)
24th January 2013, 05:46 PM
Senior Member
Thanks Meter
256
Posts: 252
Join Date: May 2006
Location: Odelzhausen
Also for the A500 Series - but Tegra chipset.
Some interesting informations and also the links within:
http://projects.pappkartong.se/a500/
The Following User Says Thank You to MrT69 For This Useful Post: [ Click to Expand ]
24th January 2013, 06:10 PM
Senior Member
Thanks Meter
10734
Posts: 1,845
Join Date: Jun 2010
Location: Stevensweert
DONATE TO ME
And another thing that also belongs here, have full acces to my device right now during APX mode.
http://forum.xda-developers.com/show...postcount=4973
If you like my work.. you may always buy me a ice cold beer
join #TripNDroid on IRC server: freenode
The Following 50 Users Say Thank You to TripNRaVeR For This Useful Post: [ Click to Expand ]
2WildFirE (24th January 2013),
adamnz (24th January 2013),
altbla (24th January 2013),
anomalos (24th January 2013),
BeciMester (24th January 2013),
Black-FR (25th January 2013),
bobmarsh72 (24th January 2013),
bruno_123 (24th January 2013),
Chezbel (25th January 2013),
clyder (24th January 2013),
davitox87 (24th January 2013),
deadwilder (25th January 2013),
Dottcent (24th January 2013),
ejnreon (24th January 2013),
FCDHBubbles (24th January 2013),
flakz0r (24th January 2013),
ghori1989 (24th January 2013),
gorannn (24th January 2013),
Gormsen (24th January 2013),
H89P (24th January 2013),
jo3bar (24th January 2013),
Juanig (24th January 2013),
lenthele (24th January 2013),
luuranko3 (24th January 2013),
marclooman9 (24th January 2013),
MrT69 (24th January 2013),
mutil (24th January 2013),
m_atze (24th January 2013),
n1kos (24th January 2013),
Nilepiels (24th January 2013),
nitrous² (24th January 2013),
Nubzori (24th January 2013),
One-X-master (24th January 2013),
Patrics83 (24th January 2013),
Pointlol (24th January 2013),
POWERK (24th January 2013),
restralla (24th January 2013),
retschy (24th January 2013),
SQr17 (24th January 2013),
superchilpil (24th January 2013),
svabandrei (24th January 2013),
SvenSSSvensson (24th January 2013),
Synoptex (25th January 2013),
Thant (24th January 2013),
thf1973 (24th January 2013),
thunder07 (24th January 2013),
Vcek (25th January 2013),
vcrp94 (24th January 2013),
wph (24th January 2013),
_Lapis_ (24th January 2013)
24th January 2013, 07:24 PM
Senior Member
Thanks Meter
10734
Posts: 1,845
Join Date: Jun 2010
Location: Stevensweert
DONATE TO ME
Got this key out of the 0.40 hboot
0x15d15b4fb63ee0b
If you like my work.. you may always buy me a ice cold beer
join #TripNDroid on IRC server: freenode
The Following 56 Users Say Thank You to TripNRaVeR For This Useful Post: [ Click to Expand ]
adamnz (24th January 2013),
alpina0707 (24th January 2013),
altbla (24th January 2013),
anomalos (24th January 2013),
bbeanss (24th January 2013),
Black-FR (25th January 2013),
BlueSingA (24th January 2013),
bruno_123 (24th January 2013),
cjoliver (24th January 2013),
clyder (25th January 2013),
craig82 (24th January 2013),
davitox87 (24th January 2013),
Dottcent (24th January 2013),
Drew Peacock (24th January 2013),
ejnreon (24th January 2013),
galaxys2Tav (24th January 2013),
gffmac (24th January 2013),
ghori1989 (24th January 2013),
gorannn (24th January 2013),
Gormsen (24th January 2013),
H89P (24th January 2013),
hassan89 (24th January 2013),
ilustre (24th January 2013),
johns1982 (24th January 2013),
Juanig (24th January 2013),
Jump1ng (24th January 2013),
lenthele (24th January 2013),
lms24 (24th January 2013),
luuranko3 (24th January 2013),
marclooman9 (24th January 2013),
meleelord (24th January 2013),
MemAllocatoR (24th January 2013),
mido.fayad (24th January 2013),
MrT69 (24th January 2013),
Mr_S (24th January 2013),
m_atze (24th January 2013),
nitrous² (24th January 2013),
Nubzori (24th January 2013),
Patrics83 (24th January 2013),
Pointlol (24th January 2013),
POWERK (24th January 2013),
restralla (24th January 2013),
retschy (24th January 2013),
robocik (25th January 2013),
sahhar1993 (24th January 2013),
shree.cse (25th January 2013),
SQr17 (24th January 2013),
superchilpil (24th January 2013),
svabandrei (24th January 2013),
Synoptex (25th January 2013),
Thant (24th January 2013),
thecknt (24th January 2013),
thf1973 (24th January 2013),
tomascus (25th January 2013),
wph (24th January 2013),
_Lapis_ (24th January 2013)
24th January 2013, 09:30 PM
Recognized Developer
Thanks Meter
1768
Posts: 5,296
Join Date: Aug 2006
Location: Eindhoven
DONATE TO ME
Re: Goal: S-off HOX+ and maybe the HOX (TEGRA3)
Quote:
Originally Posted by
TripNRaVeR
Got this key out of the 0.40 hboot
0x15d15b4fb63ee0b
I got 2 ENG and 2 MFG HBOOTs for you as .img to play with.
Sent from my HTC One X using xda app-developers app
The Following 18 Users Say Thank You to xmoo For This Useful Post: [ Click to Expand ]
adamnz (24th January 2013),
Black-FR (25th January 2013),
clyder (25th January 2013),
Cristianop (24th January 2013),
deadwilder (25th January 2013),
FCDHBubbles (24th January 2013),
ghori1989 (25th January 2013),
Gormsen (24th January 2013),
Jump1ng (24th January 2013),
lenthele (24th January 2013),
marclooman9 (24th January 2013),
mido.fayad (24th January 2013),
Mr_S (25th January 2013),
n1kos (24th January 2013),
robocik (25th January 2013),
thecknt (24th January 2013),
tomascus (25th January 2013),
TripNRaVeR (24th January 2013)
Thread Tools
Search this Thread
Display Modes
Linear Mode
Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
Go to top of page...
Most Thanked In This Thread
69 I have gained access to
some neat tools! … 56 Got this key out of the
0.40 hboot … 50 And another thing that
also belongs … 43 Update on fuse protection:
10 Sorry in advance if this
isn't strictly … 6 thread locked for
cleaning! as people … 5 Some guy in Israel sent in
his HOX to a … 3 This was removed as it was
felt that the … 3 Moderator Update
Please
not this …