[How-to] R800x Root

Search This thread

ace518

Senior Member
Dec 10, 2008
166
2
Upstate NY
OK, i'm trying to see whats going wrong in the logcat from running gingerbreak.

can anyone get me a logcat of gingerbreak running successfully on another phone. preferably on another version of the xperia play. i want to compare outputs to get a pointer towards where its going wrong. Not entirely sure where to start, but i'm gonna try to learn and get this going. We need root on this phone and its taking way too long.
 
  • Like
Reactions: gwaine

Mozza2k11

Senior Member
Apr 21, 2011
296
93
OK, i'm trying to see whats going wrong in the logcat from running gingerbreak.

can anyone get me a logcat of gingerbreak running successfully on another phone. preferably on another version of the xperia play. i want to compare outputs to get a pointer towards where its going wrong. Not entirely sure where to start, but i'm gonna try to learn and get this going. We need root on this phone and its taking way too long.

Whats going wrong is the hole gingerbreak used before to attain root has been closed in the 2.3.3 update. But it seems any usa model has had this hole patched before the unit went on sale. 2.3.2 is rootable (r800i) but 2.3.2 on the R800x, R800a, R800at seems to have been updated.
 

ace518

Senior Member
Dec 10, 2008
166
2
Upstate NY
Whats going wrong is the hole gingerbreak used before to attain root has been closed in the 2.3.3 update. But it seems any usa model has had this hole patched before the unit went on sale. 2.3.2 is rootable (r800i) but 2.3.2 on the R800x, R800a, R800at seems to have been updated.

Yeah, got that. Still want to see the differences. I don't know a whole lot about this yet, but I have a weekend to kill, and I'd like to try and learn a bit and perhaps give a shot at rooting this device. It doesn't seem like any dev's are giving this device much love yet. So I figured I'd give it a go.
 

radio five

Member
Feb 12, 2011
49
10
Well, I admire your enthusiasm and wish you the best of luck. Does anyone know if the developer of gingerbreak has mentioned anything about a new version with a fix?

Sent from my R800x using XDA App
 

Mills00013

Senior Member
Oct 12, 2007
593
131
Good luck. Ya know another avenue to pursue, since you have all weekend and all, would be to try and screw around with gingersnap. Seems its successfully rooted stuff in the past that gingerbreak couldnt. Lot of people use it for the optimus.

Sent from my R800x using XDA App
 

Logseman

Senior Member
Nov 22, 2010
2,513
651
35
Tenerife
logseman.svbtle.com
Yeah, got that. Still want to see the differences. I don't know a whole lot about this yet, but I have a weekend to kill, and I'd like to try and learn a bit and perhaps give a shot at rooting this device. It doesn't seem like any dev's are giving this device much love yet. So I figured I'd give it a go.

Is the Logcat for a R800i with a rooted 2.3.3 image good for you? Do you need a specific logcat, as in booting e.g?

Enviado desde mi R800i
 

ace518

Senior Member
Dec 10, 2008
166
2
Upstate NY
He wants the 50-60 page logcat of gingerbreak running, so any volunteer would need to unroot their phone, adb logcat piped to a file, and then execute gingerbreak or gingersnap. Whatever he plans on trying to debug.

Yeah, what he said. And I don't know that I "plan" on anything. Just gonna look around and see where I can get.
 

Mills00013

Senior Member
Oct 12, 2007
593
131
I certainly think the comparison will be a good start. It will be interesting to see exactly where the differences in the break happen. Like it was previously mentioned, there is a good chance the hole is completely plugged, and a logcat wont allow you around that, but if its something really simple like addressing the wrong memory address or something, that might be easily fixable.

We have to remember that besides the model number being different, this is another whole set of hardware internals. Memory addresses could have been changed to accommodate the CDMA radio.
 

Mills00013

Senior Member
Oct 12, 2007
593
131
Got another mildly quirky idea that could require some more advanced hardware dev's to help figure this out. I don't know exactly how the IMEI table is populated in most phones, but I imagine that the IMEI is probably hardcoded against the hardware like an ESN is at the time of the chip manufacture. It's no secret that we have a SIM card slot and GSM radio in the R800x. What tool would be required to get the IMEI out of the hardware layer? It cant be read or detected through android, since firmware is probably disabling it, but if any hardware devs knew of a way to read the chip at that level, and we were able to get the programmed IMEI number from the disabled GSM radio, maybe thats the key to unlocking the bootloader...

Again just a thought...
 

zaith1234

Senior Member
Aug 28, 2010
67
4
OK so these are the things that I have tired so far. To unlock and root.
ADB Devices tried the first 14 #'s to get an unlock code the unlock code didn't work found out later the ADB Devices only returns the serial # of your phone.
Also had the Hex MEID # converted into ESN # and used the first 14 #'s and got a different unlock code that didn't work either. I have installed an app called Network info II which gives and IMSI # used that to get yet another unlock code still no go. Also there is an Android ID Hex that I tried as the unlock code no go with that either.

For root I have tried gingersnap, gingerbreak, and super one click using both gingerbreak and psnueter exploits none of them worked.

http://www.gsm-security.net/faq/imei-international-mobile-equipment-identity-gsm.shtml

The above site has the format of a IMEI # and I was thinking if some of the GSM users would be so kind to post their IMEI #'s maybe we could build something off of the similarities. Also for those user that haven't gotten an unlock code yet it take the 14 digit #'s and turns it into a 16 digit HEX for the unlock code.
 
Last edited:

gergenhime

Member
Oct 24, 2009
22
0
someone else has already posted this but if we could get the imei number from the gsm radio built in to the verizon version but disabled in android maybe that would give us our bootloader unlock code....i mean if every other play has a gsm radio and the imei number for all of those is the key needed to figure bootloader decryption on those wouldn't it just make sense?

Sent from my Xoom using XDA Premium App
 

ace518

Senior Member
Dec 10, 2008
166
2
Upstate NY
OK so these are the things that I have tired so far. To unlock and root.
ADB Devices tried the first 14 #'s to get an unlock code the unlock code didn't work found out later the ADB Devices only returns the serial # of your phone.
Also had the Hex MEID # converted into ESN # and used the first 14 #'s and got a different unlock code that didn't work either. I have installed an app called Network info II which gives and IMSI # used that to get yet another unlock code still no go. Also there is an Android ID Hex that I tried as the unlock code no go with that either.

For root I have tried gingersnap, gingerbreak, and super one click using both gingerbreak and psnueter exploits none of them worked.

http://www.gsm-security.net/faq/imei-international-mobile-equipment-identity-gsm.shtml

The above site has the format of a IMEI # and I was thinking if some of the GSM users would be so kind to post their IMEI #'s maybe we could build something off of the similarities. Also for those user that haven't gotten an unlock code yet it take the 14 digit #'s and turns it into a 16 digit HEX for the unlock code.

I've had no luck either. But, I'm running out of app memory... even using app2sd.. we need a root soon man.
 

zaith1234

Senior Member
Aug 28, 2010
67
4
I've had no luck either. But, I'm running out of app memory... even using app2sd.. we need a root soon man.

Just to add to one of the other things I tried. I used the hex to decimal converter from
http://easycalculation.com/hex-converter.php
and converted my MEID to decimal then used the first 14 digits to get another unlock code. My buddy has giving me an old Tmobile sim card I was thinking I could use it to get a true MIEI but it seems GSM is not available on the R800x.
Also has anyone noticed that the SD unmounts when you remove the battery plate because of a little white switch off to the side.
 

Mills00013

Senior Member
Oct 12, 2007
593
131
Just to add to one of the other things I tried. I used the hex to decimal converter from
http://easycalculation.com/hex-converter.php
and converted my MEID to decimal then used the first 14 digits to get another unlock code. My buddy has giving me an old Tmobile sim card I was thinking I could use it to get a true MIEI but it seems GSM is not available on the R800x.
Also has anyone noticed that the SD unmounts when you remove the battery plate because of a little white switch off to the side.

This is an awesome idea, trouble is, though, that Decminal MEID's cannot be calculated by standard means. It uses a special algorithmic sequence to get them. Check out this article on hofo for more info: http://www.howardforums.com/showthread.php/1433623-How-to-Calculate-MEID-DEC-and-P(ESN)

I did however try to do the exact same thing with the correctly calculated Decimal and its still no go. Good idea though for sure.

On an related note: how hard would it be to use a script to run through the possible combinations? I know that there are a ton of possibilities: 16^16 if my math is correct. Which is something like 1.844674407×10^19. But its completely instant with its checking, so I think it would probably only take a week to grab the right code with a fast computer. Maybe I'm way off though.
 

axiomjunglist

Senior Member
Apr 12, 2011
222
27
If someone is really desperate and/or ballsy enough, they could try flashing the R800i generic UK 2.3.2 firmware using Flashtool. Apparently you don't need an unlocked bootloader, as someone in the forums was able to successfully flash a locked R800a on Rogers to the R800i generic UK 2.3.2 firmware. That build is confirmed rootable.

http://xdaforums.com/showthread.php?t=1108239

But, it could potentially brick the CDMA radio and/or other fuctions. Plus, there's no flashtool images out there for the Verizon model so there's no backup in case it goes to hell.

But, could potentially work...
 
Last edited:

Mills00013

Senior Member
Oct 12, 2007
593
131
Im so torn over whether thats a great idea or the absolute craziest. The only thing that i can think of that would stop the process would be getting your phone into the flash mode. I can reboot and hold the search button like im supposed to, and then it recognizes in windows as the usb flash mode for about ten seconds and then fails and restarts. Has anyone successfully done this? It shouldnt be that hard to get the system image from seus like all the other phones if we can just get into this mode.

Sent from my R800x using XDA App
 

axiomjunglist

Senior Member
Apr 12, 2011
222
27
Im so torn over whether thats a great idea or the absolute craziest. The only thing that i can think of that would stop the process would be getting your phone into the flash mode. I can reboot and hold the search button like im supposed to, and then it recognizes in windows as the usb flash mode for about ten seconds and then fails and restarts. Has anyone successfully done this? It shouldnt be that hard to get the system image from seus like all the other phones if we can just get into this mode.

Sent from my R800x using XDA App

It should be the back button, not search. Same method as when updating within SEUS.

http://xdaforums.com/showpost.php?p=13313088&postcount=2
 

zaith1234

Senior Member
Aug 28, 2010
67
4
Im so torn over whether thats a great idea or the absolute craziest. The only thing that i can think of that would stop the process would be getting your phone into the flash mode. I can reboot and hold the search button like im supposed to, and then it recognizes in windows as the usb flash mode for about ten seconds and then fails and restarts. Has anyone successfully done this? It shouldnt be that hard to get the system image from seus like all the other phones if we can just get into this mode.

Sent from my R800x using XDA App

Let us know how this goes.
 

Top Liked Posts

  • There are no posts matching your filters.
  • 13
    We can no longer unlock your bootloader with codes. Please do not ask me or ash for bootloader unlock codes. We can not help you.

    This thread is now here for historical purposes representing times when people were free to do what they wanted with their devices. Fsck yourself with a rake, Verizon.


    The bootloader has been unlocked. Let's get our freaking root on.

    Disclaimer: Read through these instructions in their entirety. If these don't make sense to you, you do not need to be rooting your phone. Nobody here has the time required to teach you how to use cmd in Windows. We will not baby step you through how to use ClockworkMod Recovery. Root is not a mythical land with fairies and unicorns where nothing ever goes bad. If you don't know how to properly install a driver in Windows, you probably don't need an Android device to begin with, let alone a rooted one.

    These instructions are intentionally left vague. Do your research on these terms. Understand what you are doing before you do it.

    tldr: if you fsck your phone up, it's on you and only you.


    Easy Way (YRMV!)

    This is by far the easiest method. You will have to read between the lines here. I will not detail all the steps. Please record your experiences in this thread and let me know how it all goes! We're all still learning. This is basically copied from Bin4ry's CWMR Thread so thanks go to him! The easy steps below assume a lot of basic knowledge steps. Like unlocking the bootloader. If you're unsure of what to do, you probably shouldn't be doing it.

    1. Download the CWM recovery from multiupload
    2. Boot off of that file (DO NOT FLASH): fastboot boot recoveryPLAY.img
    3. Copy this to your memory card and flash it with the booted recovery
    4. Reboot and test root


    Second Method: Advanced User Instructions
    1. Unlock your bootloader. Check out Ash's thread: thread
    2. Download Doom's all in one kernel from here
    3. Use fastboot to "hot boot" the kernel: fastboot boot boot.img
    4. Your phone may or may not boot. It doesn't matter. Let it be for a while, then power it off.
    5. Doom's kernel will have rooted your stock system.


    If You're On A Mac...

    Or maybe just need some general help with some more detailed insturctions than are labeled here, check out the awesome post that Cubsfan3493 made for everyone. He's even got a downloadable PDF with pictures. Go give him some thanks at his post!
    4
    R800x Rootk Tutotial (Mac)

    R800X Root Tutorial
    By: Cubsfan3493

    DOWNLOAD THE ATTACHED PDF FOR THE GOOD GUIDE.
    Edit: I couldn't attach it at the bottom so I decided to post a link here. Ended up being too big of a file...
    Link: http://www.mediafire.com/file/h1ia2ow33e42mvu/R800X Root Tutorial.pdf

    Today I am going to share a total N00b guide on how to unlock the bootloader as well as root the Verizon Wireless Xperia Play (R800X). This is now possible now thanks to the help of Blagus, Mills00013 and ashergray from the XDA-Developers forums. So all credit for the bootloader unlock as well as the root goes to them! However you are going to need them again…so now is the time to sign up to be on the XDA Developers website. My tutorial is using a Apple Macintosh computer, one of the recommended platforms for unlocking any phone because the command prompt is so simple. * IF YOU ARE AFRAID OF USING COMMAND LINES, THEN YOU DO NOT HAVE THE RIGHT TO ROOT. YOU ARE A FAILURE AND YOU SHOULD IMMEDIATELY TURN AWAY FROM THIS PAGE AND GO BUY YOURSELF AN IPHONE. END OF STORY. HOWEVER, I AM NOT RESPONSIBLE FOR ANY CORRUPTION OF DATA OR LOSS OF IMPORTANT INFORMATION DON’T LET ME PRESSURE YOU INTO DOING THIS BECAUSE YOU BELIEVE THAT IT IS THE COOL THING TO DO, IT IS JUST UNCOOL NOT TO. * Let’s get started.

    TO START OFF, ALL FILES USED I WILL ARE INCLUDED IN THE LINK HERE. THERE IS ONE FOR MAC, AND ONE FOR WINDOWS.
    Mac: http://www.mediafire.com/file/0dxuba7u94pu605/Xperia Play Root for Mac.zip
    Windows:
    http://www.mediafire.com/file/y4mo5ie17zs79y3/Xperia Play Root for Windows.zip

    1. (Step 1 in Folder) This is by far the most important step. Private message either Mills00013 or ashergray. The links to their public profiles on XDA Developers are these
    Mills00013: http://xdaforums.com/member.php?u=643928
    ashergray: http://xdaforums.com/member.php?u=4180335

    Ask them for the Unlock Code. You will have to give them the MEID HEX key. Make it easy and just send this all to them in the first message…The MEID HEX key can be found by removing the back cover and the battery from the back of the phone. It will be at the bottom. Copy the code exactly and forward the MEID number to either Mills00013 or ashergray and ask them for the Unlock code. Be patient though, they have lives too. They are working on a more desirable way to get your codes but for now, you have to PM (Private Message) them. Once they send your code back, you need to save this to your computer for future use. Do not lose this!!! EVER!!!

    (You will have to have a XDA Developers account to do this. But it is necessary to go any further.)

    2. a) (Step 2 in Folder) Now you should download the Android SDK (May not be necessary I am not sure. I have this anyway.) It can’t hurt. This can be done by going to http://developer.android.com/sdk/index.html
    Save this to the Desktop of your computer.


    b) Now in that new downloaded folder to tools navigate to /tools/android
    Open this and this page should come up.
    Navigate to the Available Packages and check both boxes for the Android repository and the third-party Add-ons. Then click install and install again.

    3. (Step 3 in folder) Now you need to download something called fastboot. This can be found at http://developer.htc.com/adp.html#s2 Download that and put it on the Desktop. Or just drag it to the Desktop from the entire folder that I have made for you. Agree and download.

    Now you need to do one thing with your phone before we get started. Turn the power OFF and unplug from computer. Now hold the search (magnifying glass) button
    4. Lets get started on some command prompt. Make sure fastboot-mac is on the desktop. Open Terminal on the Mac. Here is where it gets fancy. Type this.
    /Users/*Your Username*/Desktop/fastboot-mac –i 0x0fce oem unlock 0x**************
    (The ************** is your key that you got in step 1)

    It will now be unlocked (it said failed because I was already unlocked.)

    WOOHOO! YOUR BOOTLOADER IS UNLOCKED! BUT WAIT THERE’S STILL MORE TO DO…

    5. (Step 5 in folder) Also get Doomlord’s all in one kernel. That can be downloaded from here. http://xdaforums.com/showthread.php?t=1176502
    Named as
    “boot.img: (v03) (flash this file via fastboot to install this kernel)
    Play Prerooted + Recovery + OC Kernel 3.0.1.A.0.145”

    NOW Make sure both the fastboot-mac file and boot.img file are placed on the desktop.
    Now put in the command (all at one time)
    /Users/*Your Username*/Desktop/fastboot-mac –i 0x0fce flash boot /Users/*Your Username*/Desktop/boot.img

    now type:

    /Users/*Your Username*/Desktop/fastboot-mac –i 0x0fce reboot




    The phone may reboot to a battery logo. If that is the case, unplug it from the computer and turn it on manually. THIS WILL MAKE IT EXTREMELY EXTREMELY SLOW TO USE, AND RENDER IT A COMPLETELY UNUSABLE PHONE, BUT ITS ALL OKAY!!! WE ARE GONNA FIX THAT. =)

    6. (Step 6 in folder) Put the phone back into the mode that you did earlier. Turn off completely, hold search and plug in and blue light will come on. Time for ClockworkMod recovery. Now let’s flash the recoveryPLAY.img, downloaded from
    Using fastboot once again, type:

    /Users/*Your Username*/Desktop/fastboot-mac –i 0x0fce flash boot /Users/*Your Username*/Desktop/recoveryPLAY.img


    Now
    /Users/*Your Username*/Desktop/fastboot-mac –I -0x0fce reboot
    7. (Step 7 in folder) Your phone should (after a minute or 2) come up in ClockworkMod Recovery.
    • FIRST, Make a backup. Using the volume buttons and search button, navigate to backup and restore. Then make a backup. May take a few minutes
    • Once it is finished, navigate to the Mounts and storage menu. Then navigate to Mount SD card. Not format…(*I had a noob moment…*). Make sure it is mounted.
    • Then navigate to Mount USB Storage. Do the same. Once it shows up on the computer, put the RootXperia.zip (Step 7 in Folder) folder on the root of the memory card (or any other folder it really doesn’t matter—just remember where you put it.).
    • Go back
    • Navigate to apply update from sd card
    • Update from the RootXperia.zip folder.
    • Let it finish.
    Now pop the battery out (easiest way to turn it off) and unplug it, and put the battery back in. Put it into the fastboot mode one more time…(search, plug, blue light).
    8. (Step 8 in folder) Final step!!!
    Use fastboot to flash one more thing. It is the stock kernel. This will make it completely rooted, without the bootloader lock.
    Command
    /Users/*Your Username*/Desktop/fastboot-mac –i 0x0fce flash boot /Users/*Your Username*/Desktop/kernel.sin


    Finally,
    /Users/*Your Username*/Desktop/fastboot-mac –I 0x0fce reboot


    Once it boots, go and install Superuser, Titanium Backup and whatever else you want for your ROOTED device! Congrats on the ROOT! If you read for this long…you really needed to. Hahahahahahaha


    !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
    !!!!!!!THIS GUIDE WAS INTENDED FOR THE TOTAL NOOB LIKE ME. COMPLETE!!!!!!!!!!!!!!!!!!!!!!!
    !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! STEP BY STEP GUIDE.!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
    !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

    Again, I would like to extend a thanks to the people who made this possible. Mainly Mills00013 and ashergray. Blagus also had a major part in the development of this root. Many more people over the times have helped, and their names deserve to be mentioned. This is my small way of giving back to them and the community.
    Sincerely,
    Cubsfan3493
    1
    OK, i'm trying to see whats going wrong in the logcat from running gingerbreak.

    can anyone get me a logcat of gingerbreak running successfully on another phone. preferably on another version of the xperia play. i want to compare outputs to get a pointer towards where its going wrong. Not entirely sure where to start, but i'm gonna try to learn and get this going. We need root on this phone and its taking way too long.
    1
    Tryed to flash the UK FW [PROT_VER="03";DATE="20110217";TIME="15:47:00";VER="R4A066";CXC="1234-5769";TYPE="S1_LOADER";UNIQUE_DEV_ID="EF5222F8EF219C7E30E2AB8A48BDED6E772911F3";SEC_LOCK_STATUS="LOCKED";OTP_DATA="4B6D71004714040816040028CDD880EEB001002000000000";IMEI="A1000017112429";AID_VERSION="0004";EROM_AID="0001";LOADER_AID="0001";SW_AID="0001";CUST_AID="0001";SIM_LOCK_AID="0001";HWCONF_AID="0001";PROD_ID="0002";ACTIVE_LOADER_AID="0001";MEMDEVS="02:00:002C:00B3:0000:00002000:00020000:00000800:00000040,03:03:0003:5344:0080:0003B598:00010000:00000200";MAN_ID="002C";DEV_ID="00B3";SIN_VER="0001";AID_TAMP="NOT_TAMPERED";MAX_PKT_SZ="00010000";AUTH_LEVEL="NONE";AUTH_MET="0001";CARD_PRESENT="YES";CARD_SIZE="16GB";CARD_DATA="UHJvZE5vPTEyNDktMjcwOQ1Qcm9kUmV2PVI2QQ1Db3BpZWRCeXRlcz0yMjA5MjcxMjU2DUNvcGllZEZpbGVzPTMwNjcNQ29waWVkRGlycz01OQ1PcmRlcj05MDE2OTUxLTEwDQ==";LOADER_ROOT="S1_Loader_Root_773f";EROM_ROOT="S1_EROM_Root_d601";SW_ROOT="S1_SW_Root_883f";CUST_ROOT="S1_Cust_Root_9603";SIM_LOCK_ROOT="S1_SL_Root_c422";HW_CONF_ROOT="S1_HWConf_Root_08af";BIM_STATE="DISABLED";] and then got an error on [Flashing adsp.sin]
    1
    has anyone tried the steps i suggested (hot boot and then reboot after some time)?

    did it work?