• Introducing XDA Computing: Discussion zones for Hardware, Software, and more!    Check it out!

[S-Off] Facepalm S-Off for HTC Evo 4g LTE

Search This thread

jcase

Retired Forum Mod / Senior Recognized Developer
Feb 20, 2010
6,331
15,773
Sequim WA
Edit dfownloads removed as the host started serving malware.

I dont have these files anymore, sorry, please dont ask for them




For other HTC devices supported by FacePalm, please see this thread: http://forum.xda-developers.com/showthread.php?t=2155069

Welcome to Facepalm S-Off for modern HTC phones.

Credits and terms:


Exploit by beaups, full guide, testing, and concept by jcase and beaups. Thanks to dsb9938 and dr_drache for support and testing. Thanks also to all of the regulars at teamandirc. Additional thanks to indirect for Evo LTE testing.

Both beaups and jcase will collect the applicable active bounties. Further donations are greatly appreciated and can be sent to:

beaups - [email protected] - http://forum.xda-developers.com/donatetome.php?u=711482
jcase - [email protected] - http://forum.xda-developers.com/donatetome.php?u=2376614
dsb9938 - [email protected] - http://forum.xda-developers.com/donatetome.php?u=2963256
dr_drache - [email protected] - https://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&hosted_button_id=6LRSY8MT8P3A6

You can also come by irc for support or just to say thanks: #FacePalm http://chat.andirc.net:8080/?channels=facepalm

While this process shouldn’t be too risky, bricks can happen. None of us will be accountable. If you are worried, don’t do it.

This is a pretty simple method, however, you will need to have a working adb and fastboot environment. This method will work on any operating system that supports adb and fastboot. You should understand how to use a terminal window in your O/S. If you don’t understand adb and fastboot, you probably don’t need S-off.

Lastly, the work herein should not be stolen, repackaged, one clicked, bat’d, etc. soffbin3 is not GPL and may not be reused, integrated into other work, reposted, or redistributed without our permission.

For this to work, you must be rooted and have superCID (unlock/custom recovery is optional), see the threads below for help and information regarding obtaining superCID, unlock, root, etc. Note these threads are provided for convenience only. Please look for support for them in each respective thread if you need it, do NOT clutter this thread with support requests regarding obtaining superCID and/or root! If you try this process without superCID, it will not work, and you may have issues!:

SuperCID for HTC Evo 4G LTE:

Code:
adb shell
su
echo -ne "22222222" | dd of=/dev/block/mmcblk0p5 bs=1 seek=20


1)
Code:
adb reboot bootloader

2)
Code:
fastboot oem rebootRUU

(wait for black HTC Screen)

3)
Code:
fastboot flash zip PJ7510000-EvoLTE.zip


After a while, You should see the following error “FAILED (remote: 92 supercid! please flush image again immediately)

7) Immediately issue the following command:

Code:
fastboot boot EvoLTE-rescue.img
(this is fastboot boot, NOT fastboot flash!)

8) Allow device to boot (may not fully boot on some custom roms)

Code:
adb reboot bootloader

9) You should see what you are looking for!

If you need help or just care to say thanks, join us on IRC: #FacePalm http://chat.andirc.net:8080/?channels=facepalm

Enjoy.
 
Last edited:

BB15

Senior Member
May 25, 2010
372
34
Help! I'm bricked.


C:\android-sdk-windows\platform-tools>fastboot devices
HT25KS405806 fastboot

C:\android-sdk-windows\platform-tools>adb reboot bootloader

C:\android-sdk-windows\platform-tools>fastboot oem rebootRUU
...
(bootloader) Start Verify: 3
OKAY [ 0.059s]
finished. total time: 0.062s

C:\android-sdk-windows\platform-tools>fastboot flash zip PJ7510000-EvoLTE.zip
sending 'zip' (35863 KB)...
OKAY [ 2.435s]
writing 'zip'...
(bootloader) adopting the signature contained in this image...
FAILED (remote: 92 supercid! please flush image again immediately)
finished. total time: 3.450s

C:\android-sdk-windows\platform-tools>fastboot boot EvoLTE-rescue.img
downloading 'boot.img'...
OKAY [ 0.853s]
booting...
OKAY [ 0.005s]
finished. total time: 0.862s

Then my phone never booted back up.
 
  • Like
Reactions: baknblack

jcase

Retired Forum Mod / Senior Recognized Developer
Feb 20, 2010
6,331
15,773
Sequim WA
Hold power for 40 seconds, nothing in that should be causing bricks.

EDIT:

Apparently you were not bricked, we can only support stock roms, can't control how it behaves on AOSP, given it should still work, but it might not until you do a reboot. Please next time confirm that you are bricked before posting that you are.

[23:24:30] <BB15> I'm actually not bricked. I got it to boot back up and I'm s-off, but now I get prompted to activate my phone

Help! I'm bricked.


C:\android-sdk-windows\platform-tools>fastboot devices
HT25KS405806 fastboot

C:\android-sdk-windows\platform-tools>adb reboot bootloader

C:\android-sdk-windows\platform-tools>fastboot oem rebootRUU
...
(bootloader) Start Verify: 3
OKAY [ 0.059s]
finished. total time: 0.062s

C:\android-sdk-windows\platform-tools>fastboot flash zip PJ7510000-EvoLTE.zip
sending 'zip' (35863 KB)...
OKAY [ 2.435s]
writing 'zip'...
(bootloader) adopting the signature contained in this image...
FAILED (remote: 92 supercid! please flush image again immediately)
finished. total time: 3.450s

C:\android-sdk-windows\platform-tools>fastboot boot EvoLTE-rescue.img
downloading 'boot.img'...
OKAY [ 0.853s]
booting...
OKAY [ 0.005s]
finished. total time: 0.862s

Then my phone never booted back up.
 
Last edited:

BB15

Senior Member
May 25, 2010
372
34
Hold power for 40 seconds, nothing in that should be causing bricks.

EDIT:

Apparently you were not bricked, we can only support stock roms, can't control how it behaves on AOSP, given it should still work, but it might not until you do a reboot. Please next time confirm that you are bricked before posting that you are.

[23:24:30] I'm actually not bricked. I got it to boot back up and I'm s-off, but now I get prompted to activate my phone

Yeah, I wasn't bricked. After waiting for some time for my phone to reboot after running FacePalm I unplugged the USB and held the power button and it booted right up. Rebooted the bootloader and verified that I was s-off. Then I ran into the activation problem. Just flashed MeanBean and ran through the activation, now all is good. Your work on this is much appreciated.
 
Last edited:

ocnbrze

Senior Member
Jul 11, 2010
83
19
los angeles

Rxpert

Senior Member
Sep 12, 2011
1,714
687
So for clarity, the superCID commands are run from the phone while booted? or in bootloader? It looks from the way its written thats its meant to be done while the device is booted

Edit:
Thanks OCN :p
 

LAELOW615

Member
Oct 19, 2010
8
0
Finally have s-off!!!!

Thx to Facepalm S-Off I now have s-off. Finally,after a long year and a half of trying to get s-off.....
I must have been doing a few things wrong this whole time or Facepalm S-Off has done it right...
 

jshow816

Senior Member
Jun 23, 2012
76
16
Wow, this was incredibly easy. Soff in less than 2 minutes. I just followed the directions and flashed stock rom to be safe. $$ coming to you guys on payday!!
 

Top Liked Posts

  • There are no posts matching your filters.
  • 89
    Edit dfownloads removed as the host started serving malware.

    I dont have these files anymore, sorry, please dont ask for them




    For other HTC devices supported by FacePalm, please see this thread: http://forum.xda-developers.com/showthread.php?t=2155069

    Welcome to Facepalm S-Off for modern HTC phones.

    Credits and terms:


    Exploit by beaups, full guide, testing, and concept by jcase and beaups. Thanks to dsb9938 and dr_drache for support and testing. Thanks also to all of the regulars at teamandirc. Additional thanks to indirect for Evo LTE testing.

    Both beaups and jcase will collect the applicable active bounties. Further donations are greatly appreciated and can be sent to:

    beaups - [email protected] - http://forum.xda-developers.com/donatetome.php?u=711482
    jcase - [email protected] - http://forum.xda-developers.com/donatetome.php?u=2376614
    dsb9938 - [email protected] - http://forum.xda-developers.com/donatetome.php?u=2963256
    dr_drache - [email protected] - https://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&hosted_button_id=6LRSY8MT8P3A6

    You can also come by irc for support or just to say thanks: #FacePalm http://chat.andirc.net:8080/?channels=facepalm

    While this process shouldn’t be too risky, bricks can happen. None of us will be accountable. If you are worried, don’t do it.

    This is a pretty simple method, however, you will need to have a working adb and fastboot environment. This method will work on any operating system that supports adb and fastboot. You should understand how to use a terminal window in your O/S. If you don’t understand adb and fastboot, you probably don’t need S-off.

    Lastly, the work herein should not be stolen, repackaged, one clicked, bat’d, etc. soffbin3 is not GPL and may not be reused, integrated into other work, reposted, or redistributed without our permission.

    For this to work, you must be rooted and have superCID (unlock/custom recovery is optional), see the threads below for help and information regarding obtaining superCID, unlock, root, etc. Note these threads are provided for convenience only. Please look for support for them in each respective thread if you need it, do NOT clutter this thread with support requests regarding obtaining superCID and/or root! If you try this process without superCID, it will not work, and you may have issues!:

    SuperCID for HTC Evo 4G LTE:

    Code:
    adb shell
    su
    echo -ne "22222222" | dd of=/dev/block/mmcblk0p5 bs=1 seek=20


    1)
    Code:
    adb reboot bootloader

    2)
    Code:
    fastboot oem rebootRUU

    (wait for black HTC Screen)

    3)
    Code:
    fastboot flash zip PJ7510000-EvoLTE.zip


    After a while, You should see the following error “FAILED (remote: 92 supercid! please flush image again immediately)

    7) Immediately issue the following command:

    Code:
    fastboot boot EvoLTE-rescue.img
    (this is fastboot boot, NOT fastboot flash!)

    8) Allow device to boot (may not fully boot on some custom roms)

    Code:
    adb reboot bootloader

    9) You should see what you are looking for!

    If you need help or just care to say thanks, join us on IRC: #FacePalm http://chat.andirc.net:8080/?channels=facepalm

    Enjoy.
    13
    Thread cleaned. Going forward let's see about keeping it respectful in here.
    7
    Took me all of 2 minutes to get s-off.

    Extra info: This works on 3.16 firmware and subsequently 3.15 as well.

    Probably worked on 3.16 for you as you already had supercid, I'm guessing the recent 3.16 update prevents changing the CID.
    6
    Captain_Throwback fixed the firmware problem concerning the bricks as far as I recall

    Sent from my PoS MoPho :p
    Yes; yes he did ;).
    4
    Hold power for 40 seconds, nothing in that should be causing bricks.

    EDIT:

    Apparently you were not bricked, we can only support stock roms, can't control how it behaves on AOSP, given it should still work, but it might not until you do a reboot. Please next time confirm that you are bricked before posting that you are.

    [23:24:30] <BB15> I'm actually not bricked. I got it to boot back up and I'm s-off, but now I get prompted to activate my phone

    Help! I'm bricked.


    C:\android-sdk-windows\platform-tools>fastboot devices
    HT25KS405806 fastboot

    C:\android-sdk-windows\platform-tools>adb reboot bootloader

    C:\android-sdk-windows\platform-tools>fastboot oem rebootRUU
    ...
    (bootloader) Start Verify: 3
    OKAY [ 0.059s]
    finished. total time: 0.062s

    C:\android-sdk-windows\platform-tools>fastboot flash zip PJ7510000-EvoLTE.zip
    sending 'zip' (35863 KB)...
    OKAY [ 2.435s]
    writing 'zip'...
    (bootloader) adopting the signature contained in this image...
    FAILED (remote: 92 supercid! please flush image again immediately)
    finished. total time: 3.450s

    C:\android-sdk-windows\platform-tools>fastboot boot EvoLTE-rescue.img
    downloading 'boot.img'...
    OKAY [ 0.853s]
    booting...
    OKAY [ 0.005s]
    finished. total time: 0.862s

    Then my phone never booted back up.