This is NOT in relation to changing IMEI/ESN as that is ILLEGAL! This thread is about enabling our baseband/modems to operate on different frequencies/couriers.
Trying the VZW unlock thread first HERE
I'm flashing a VZW ROM right now to check APN menu, etc. Sprint even with hack doesn't show APN.
There are several threads on how to unlock Verizon/Tmobile/ATT modems to work on each other with varying levels of success. I feel that we have a iPhone 4s/5 like device that has the same chipset just different locks around the software to prevent unlocking. I was moved by the community's involvement in adding a SIM card slot to the Note 2 and want this mod to work on US couriers.
Basically put, I want to make any US variant S3/Note 2 an international version. The hardware is the same, it's the NVRAM/Firmware prohibiting us.
This is the SIM card mod for the SPR N2:
http://xdaforums.com/showthread.php?t=1959005
Enabling AWS (T-Mobile) on ATT Note 2:
http://xdaforums.com/showthread.php?p=35933247
Verizon S3 on T-Mobile:
http://xdaforums.com/showthread.php?t=2013647
Verizon S3 on world GSM:
http://xdaforums.com/showthread.php?t=1809314
The primary method of unlocking modem bands is flashing a QCN file that modifies NVRAM params. In the ATT T-Mobile thread the hack works by flashing over a ESN/IMEI stripped T-Mobile qcn backup file.
I tried following this process but was blocked by a "Roaming Lists could not be read" error at 16% when trying to backup my NVRAM using QPST. I attempted flashing the file anyway and received a "Could not Communicate in Diagnostic Mode" error. My modem then would not see any networks. I then flashed a ATT modem which bootlooped my device.
I feel the Roaming List could not be read is the main issue into how Sprint locked down this device for US GSM. In SIM tech, the courier provides a preferred list of up to 80 couriers the phone is to connect to first when roaming due to courier roaming agreements instead of the strongest signal first. As the Spr model uses a chip for a SIM it's possible that the "SIM" could not be read to provide roaming lists and GSM could be blacklisted in this chip as it is more sophisticated then a SIM smartcard. Now that I flashed a ATT modem I'm going to try to download the NVItems again using QPST.
I restored my TWRP backup and sideloaded a SPR modem, back at stock all working.
The alternative is to use the "IMEI/ESN" backup tool:
http://xdaforums.com/showthread.php?t=1867442
I will continue experimenting and will report progress.
When writing back my NVRAM dump I get this list of readonly/locked items:
(NV Items http://xdaforums.com/showthread.php?t=1954029)
Writing NV-items from a file:
Unsuccessfully written NV-items:
00000 (0x0000) - Password (16 digits) is required
0^"Electronic Serial Number"^"Security*"
00001 (0x0001) - Read only item
1^"Electronic Serial Number Checksum"^"Security*"
01943 (0x0797) - Password (16 digits) is required
797^"DCS TX Burst Ramp Down Index 11"^"GSM*"
05597 (0x15DD) - Read only item
05598 (0x15DE) - Read only item
These two are unknown but people get them when doing AWS unlocks:
http://xdaforums.com/showpost.php?p=36078971&postcount=81
Found a AWS/ATT modified TXT file, I flashed it and reset
http://xdaforums.com/showpost.php?p=36008901&postcount=49
Mobile networks show a previously unselectable item WCDMA only as selected which is not in the menu, the network status is unknown. I have a feeling the nv-item is trying to reference a menu item that is not in my ROM.
Next I'm going to ODIN the stock ATT rom over and see what happens.
FAIL! modem.bin won't flash.
Flashed Stock AIO modem+firmware+rom, etc odin to phone and flashed LJC modem manually. No data and was reporting WCDMA only from the last NV items hack. It seems NV-ITEMS are persistent across a complete and total stock restore+modem flash (twice) wipes and bricks. I restored my backup TXT for nv items and stock network has returned.
I'm flashing CM next for Sprint as it has "- Removed preset Network mode/selection (allows for more network modes)"
http://xdaforums.com/showthread.php?t=2047667
Hopefully with the NV Items hack and a ROM without network modes locked w/ a SIM card board I should be gold.
Here is NV Items when flashing on stock ODIN:
Writing NV-items from a file:
Unsuccessfully written NV-items:
00000 (0x0000) - Password (16 digits) is required
00001 (0x0001) - Read only item
00005 (0x0005) - Command failed
00018 (0x0012) - Command failed
00031 (0x001F) - Command failed
00032 (0x0020) - Read only item
00033 (0x0021) - Read only item
00034 (0x0022) - Command failed
00035 (0x0023) - Command failed
00036 (0x0024) - Command failed
00037 (0x0025) - Read only item
00048 (0x0030) - Command failed
00049 (0x0031) - Command failed
00050 (0x0032) - Command failed
00176 (0x00B0) - Read only item
00177 (0x00B1) - Read only item
00178 (0x00B2) - Command failed
00209 (0x00D1) - Read only item
00210 (0x00D2) - Command failed
00211 (0x00D3) - Command failed
00212 (0x00D4) - Command failed
00213 (0x00D5) - Command failed
00215 (0x00D7) - Command failed
00258 (0x0102) - Command failed
00259 (0x0103) - Command failed
00260 (0x0104) - Command failed
00261 (0x0105) - Command failed
00262 (0x0106) - Read only item
00263 (0x0107) - Read only item
00264 (0x0108) - Read only item
00265 (0x0109) - Read only item
00266 (0x010A) - Read only item
00296 (0x0128) - Command failed
01943 (0x0797) - Password (16 digits) is required
05597 (0x15DD) - Read only item
05598 (0x15DE) - Read only item
Done.
1/10/13 6:17pm
http://xdaforums.com/showthread.php?t=2016575
Trying new international ATT rom. CM10 didn't have what I needed for network selections.
I have successfully detected a GSM network type although it's going to need some work.. I got to go home and eat.
1/11/13 11:14am
Using the RF NV editor from QPST I can edit all NV-Items with no roaming lists error.
Trying the VZW unlock thread first HERE
I'm flashing a VZW ROM right now to check APN menu, etc. Sprint even with hack doesn't show APN.
There are several threads on how to unlock Verizon/Tmobile/ATT modems to work on each other with varying levels of success. I feel that we have a iPhone 4s/5 like device that has the same chipset just different locks around the software to prevent unlocking. I was moved by the community's involvement in adding a SIM card slot to the Note 2 and want this mod to work on US couriers.
Basically put, I want to make any US variant S3/Note 2 an international version. The hardware is the same, it's the NVRAM/Firmware prohibiting us.
This is the SIM card mod for the SPR N2:
http://xdaforums.com/showthread.php?t=1959005
Enabling AWS (T-Mobile) on ATT Note 2:
http://xdaforums.com/showthread.php?p=35933247
Verizon S3 on T-Mobile:
http://xdaforums.com/showthread.php?t=2013647
Verizon S3 on world GSM:
http://xdaforums.com/showthread.php?t=1809314
The primary method of unlocking modem bands is flashing a QCN file that modifies NVRAM params. In the ATT T-Mobile thread the hack works by flashing over a ESN/IMEI stripped T-Mobile qcn backup file.
I tried following this process but was blocked by a "Roaming Lists could not be read" error at 16% when trying to backup my NVRAM using QPST. I attempted flashing the file anyway and received a "Could not Communicate in Diagnostic Mode" error. My modem then would not see any networks. I then flashed a ATT modem which bootlooped my device.
I feel the Roaming List could not be read is the main issue into how Sprint locked down this device for US GSM. In SIM tech, the courier provides a preferred list of up to 80 couriers the phone is to connect to first when roaming due to courier roaming agreements instead of the strongest signal first. As the Spr model uses a chip for a SIM it's possible that the "SIM" could not be read to provide roaming lists and GSM could be blacklisted in this chip as it is more sophisticated then a SIM smartcard. Now that I flashed a ATT modem I'm going to try to download the NVItems again using QPST.
I restored my TWRP backup and sideloaded a SPR modem, back at stock all working.
The alternative is to use the "IMEI/ESN" backup tool:
http://xdaforums.com/showthread.php?t=1867442
I will continue experimenting and will report progress.
When writing back my NVRAM dump I get this list of readonly/locked items:
(NV Items http://xdaforums.com/showthread.php?t=1954029)
Writing NV-items from a file:
Unsuccessfully written NV-items:
00000 (0x0000) - Password (16 digits) is required
0^"Electronic Serial Number"^"Security*"
00001 (0x0001) - Read only item
1^"Electronic Serial Number Checksum"^"Security*"
01943 (0x0797) - Password (16 digits) is required
797^"DCS TX Burst Ramp Down Index 11"^"GSM*"
05597 (0x15DD) - Read only item
05598 (0x15DE) - Read only item
These two are unknown but people get them when doing AWS unlocks:
http://xdaforums.com/showpost.php?p=36078971&postcount=81
Found a AWS/ATT modified TXT file, I flashed it and reset
http://xdaforums.com/showpost.php?p=36008901&postcount=49
Mobile networks show a previously unselectable item WCDMA only as selected which is not in the menu, the network status is unknown. I have a feeling the nv-item is trying to reference a menu item that is not in my ROM.
Next I'm going to ODIN the stock ATT rom over and see what happens.
FAIL! modem.bin won't flash.
Flashed Stock AIO modem+firmware+rom, etc odin to phone and flashed LJC modem manually. No data and was reporting WCDMA only from the last NV items hack. It seems NV-ITEMS are persistent across a complete and total stock restore+modem flash (twice) wipes and bricks. I restored my backup TXT for nv items and stock network has returned.
I'm flashing CM next for Sprint as it has "- Removed preset Network mode/selection (allows for more network modes)"
http://xdaforums.com/showthread.php?t=2047667
Hopefully with the NV Items hack and a ROM without network modes locked w/ a SIM card board I should be gold.
Here is NV Items when flashing on stock ODIN:
Writing NV-items from a file:
Unsuccessfully written NV-items:
00000 (0x0000) - Password (16 digits) is required
00001 (0x0001) - Read only item
00005 (0x0005) - Command failed
00018 (0x0012) - Command failed
00031 (0x001F) - Command failed
00032 (0x0020) - Read only item
00033 (0x0021) - Read only item
00034 (0x0022) - Command failed
00035 (0x0023) - Command failed
00036 (0x0024) - Command failed
00037 (0x0025) - Read only item
00048 (0x0030) - Command failed
00049 (0x0031) - Command failed
00050 (0x0032) - Command failed
00176 (0x00B0) - Read only item
00177 (0x00B1) - Read only item
00178 (0x00B2) - Command failed
00209 (0x00D1) - Read only item
00210 (0x00D2) - Command failed
00211 (0x00D3) - Command failed
00212 (0x00D4) - Command failed
00213 (0x00D5) - Command failed
00215 (0x00D7) - Command failed
00258 (0x0102) - Command failed
00259 (0x0103) - Command failed
00260 (0x0104) - Command failed
00261 (0x0105) - Command failed
00262 (0x0106) - Read only item
00263 (0x0107) - Read only item
00264 (0x0108) - Read only item
00265 (0x0109) - Read only item
00266 (0x010A) - Read only item
00296 (0x0128) - Command failed
01943 (0x0797) - Password (16 digits) is required
05597 (0x15DD) - Read only item
05598 (0x15DE) - Read only item
Done.
1/10/13 6:17pm
http://xdaforums.com/showthread.php?t=2016575
Trying new international ATT rom. CM10 didn't have what I needed for network selections.
I have successfully detected a GSM network type although it's going to need some work.. I got to go home and eat.
1/11/13 11:14am
Using the RF NV editor from QPST I can edit all NV-Items with no roaming lists error.
Last edited: