Unlocking 2011 XPERIAs’ Bootloader without losing DRM

Search This thread

illus4

Member
Aug 26, 2009
34
67
As some ones of you including me still have not unlocked the bootloader at unlockbootloader.sonyericsson.com simply because not willing to lose the functionality of DRM and the TrackID, here comes another solution.

***WARNING***
The following operations may harm your device and your warranty may be void.
Neither I nor any other forum members mentioned below will be responsible for any of your loss.
Continue reading at your own risk!

***WARNING***


[requirements]
  • A 2011 Sony Ericsson XPERIA device with a still looked bootloader (this should work on all the 2011 XPERIA models but I have only tested on an XPERIA ray)

[referencing links]
  • Reading all the links below before conducting any operation is strongly recommended.

[unlocking your bootloader]
  • Find the test point of your device (see the referencing links, you may have to register an ID at support.setool.net to view some of the attachments)
  • Download s1tool from this thread and extract the 7z file
  • Turn off your phone
  • Connect the USB cable shield and the test point with a paperclip or some other wire
  • Attach the USB cable to your PC, when Windows finds a new device, disconnect the test point and manually install the driver contained in the s1tool.7z archive
  • Run s1tool.exe, click “Patch SEMCBoot” then follow the instructions on the screen and your bootloader will be unlocked

After the bootloader is unlocked, you can flash custom kernels or do something else like rooting your phone etc.

I am using an XPERIA ray* and I have unlocked my bootloader then rooted it. The TrackID works and no side effects found yet. Currently I have no idea about how to relock the bootloader so do this at your own risk.

Below is my s1tool log:
Code:
01/10/2011 22:36:09 Welcome to S1 tool.
01/10/2011 22:36:09 That is small and crippled subset of SETOOL2 service tool.
01/10/2011 22:36:12  
01/10/2011 22:36:12 DETACH USB CABLE FROM PHONE
01/10/2011 22:36:12 REMOVE BATTERY FROM PHONE
01/10/2011 22:36:12 ATTACH TESTPOINT
01/10/2011 22:36:12 PRESS "READY", THEN ATTACH USB CABLE TO PHONE
01/10/2011 22:36:12  
01/10/2011 22:36:50 PROCESSING ...
01/10/2011 22:36:51 REMOVE TESTPOINT NOW, THEN PRESS "READY"
01/10/2011 22:36:51  
01/10/2011 22:36:56  
01/10/2011 22:36:56 TO CONNECT NEXT PHONES
01/10/2011 22:36:56 X10 Xperia,E10 Mini,E15 Xperia X8,U20 Mini Pro
01/10/2011 22:36:56 LT15 Xperia ARC,MT15 Xperia NEO,R800 Xperia PLAY
01/10/2011 22:36:56 PRESS AND HOLD "BACK" BUTTON...
01/10/2011 22:36:56  
01/10/2011 22:36:56 ST18 Xperia RAY,ST15 Xperia Mini,SK17 Xperia Mini Pro
01/10/2011 22:36:56 PRESS AND HOLD "Volume Down" BUTTON...
01/10/2011 22:36:56  
01/10/2011 22:36:56 PLEASE ATTACH TURNED OFF PHONE NOW
01/10/2011 22:36:56 
01/10/2011 22:36:57  
01/10/2011 22:36:57 RUNNING S1_LOADER VER "R4A062"
01/10/2011 22:36:57 LOADER AID: 0001
01/10/2011 22:36:58 FLASH ID: "0098/00B3"
01/10/2011 22:36:58 LOADER VERSION: "r4A069"
01/10/2011 22:36:58  
01/10/2011 22:36:58  
01/10/2011 22:36:59 SEMC SIMLOCK CERTIFICATE, PROCEEDING
01/10/2011 22:36:59 FINISHED
01/10/2011 22:36:59 Elapsed:46 secs.

(*Updated 10 Dec 2011: According to the replies below, this method may not work on branded phones.)
 
Last edited:

illus4

Member
Aug 26, 2009
34
67
And the Service Menu still says that Bootloader unlock allowed: Yes
 

Attachments

  • screenshot_2011-10-02_0116.jpg
    screenshot_2011-10-02_0116.jpg
    17.6 KB · Views: 13,979
  • Like
Reactions: mozil177 and XRBW

Top Liked Posts

  • There are no posts matching your filters.
  • 38
    As some ones of you including me still have not unlocked the bootloader at unlockbootloader.sonyericsson.com simply because not willing to lose the functionality of DRM and the TrackID, here comes another solution.

    ***WARNING***
    The following operations may harm your device and your warranty may be void.
    Neither I nor any other forum members mentioned below will be responsible for any of your loss.
    Continue reading at your own risk!

    ***WARNING***


    [requirements]
    • A 2011 Sony Ericsson XPERIA device with a still looked bootloader (this should work on all the 2011 XPERIA models but I have only tested on an XPERIA ray)

    [referencing links]
    • Reading all the links below before conducting any operation is strongly recommended.

    [unlocking your bootloader]
    • Find the test point of your device (see the referencing links, you may have to register an ID at support.setool.net to view some of the attachments)
    • Download s1tool from this thread and extract the 7z file
    • Turn off your phone
    • Connect the USB cable shield and the test point with a paperclip or some other wire
    • Attach the USB cable to your PC, when Windows finds a new device, disconnect the test point and manually install the driver contained in the s1tool.7z archive
    • Run s1tool.exe, click “Patch SEMCBoot” then follow the instructions on the screen and your bootloader will be unlocked

    After the bootloader is unlocked, you can flash custom kernels or do something else like rooting your phone etc.

    I am using an XPERIA ray* and I have unlocked my bootloader then rooted it. The TrackID works and no side effects found yet. Currently I have no idea about how to relock the bootloader so do this at your own risk.

    Below is my s1tool log:
    Code:
    01/10/2011 22:36:09 Welcome to S1 tool.
    01/10/2011 22:36:09 That is small and crippled subset of SETOOL2 service tool.
    01/10/2011 22:36:12  
    01/10/2011 22:36:12 DETACH USB CABLE FROM PHONE
    01/10/2011 22:36:12 REMOVE BATTERY FROM PHONE
    01/10/2011 22:36:12 ATTACH TESTPOINT
    01/10/2011 22:36:12 PRESS "READY", THEN ATTACH USB CABLE TO PHONE
    01/10/2011 22:36:12  
    01/10/2011 22:36:50 PROCESSING ...
    01/10/2011 22:36:51 REMOVE TESTPOINT NOW, THEN PRESS "READY"
    01/10/2011 22:36:51  
    01/10/2011 22:36:56  
    01/10/2011 22:36:56 TO CONNECT NEXT PHONES
    01/10/2011 22:36:56 X10 Xperia,E10 Mini,E15 Xperia X8,U20 Mini Pro
    01/10/2011 22:36:56 LT15 Xperia ARC,MT15 Xperia NEO,R800 Xperia PLAY
    01/10/2011 22:36:56 PRESS AND HOLD "BACK" BUTTON...
    01/10/2011 22:36:56  
    01/10/2011 22:36:56 ST18 Xperia RAY,ST15 Xperia Mini,SK17 Xperia Mini Pro
    01/10/2011 22:36:56 PRESS AND HOLD "Volume Down" BUTTON...
    01/10/2011 22:36:56  
    01/10/2011 22:36:56 PLEASE ATTACH TURNED OFF PHONE NOW
    01/10/2011 22:36:56 
    01/10/2011 22:36:57  
    01/10/2011 22:36:57 RUNNING S1_LOADER VER "R4A062"
    01/10/2011 22:36:57 LOADER AID: 0001
    01/10/2011 22:36:58 FLASH ID: "0098/00B3"
    01/10/2011 22:36:58 LOADER VERSION: "r4A069"
    01/10/2011 22:36:58  
    01/10/2011 22:36:58  
    01/10/2011 22:36:59 SEMC SIMLOCK CERTIFICATE, PROCEEDING
    01/10/2011 22:36:59 FINISHED
    01/10/2011 22:36:59 Elapsed:46 secs.

    (*Updated 10 Dec 2011: According to the replies below, this method may not work on branded phones.)
    4
    Ok I am quite confused right now regarding what I have to connect and whatnot. So I connect the TP with the usb shield using a wire right? Do I use a second cable to connect the tp with the batyery negative? Im not a 100% noob I just dont want to fry the phone I have been waiting for so long :p

    Edit: thank for the photo. Just to make sure... When holding the phone upright its the 3rd point on the bottom row of the 4x2 from the right. Correct?

    Sent from my ST17i using XDA App

    Updated picture with all of test point pin.
    Here i upload neddle TP that i uses.
    4
    Xperia Active Test Point location

    Look at green cricle.i haven't pull the sticker yet.i use neddle and wire to connect Test Point and Battery Negative Connector.

    Edit : updated picture.

    Edit2 : Update picture with full test point pin.
    3
    SO, using "restore" function in s1tool, make your brick XMP because update from SE with unlock bootloader, can fix it right.
    After use restore function, does the bootloader locked or unlock ?

    Is there anyone try, after unlock using TP and s1tool, then use restore function, and update from SE (PCCompantion or SEUS), its work or its still make XMP brick ?

    After i did the TP / s1tool unlock. I accepted an update and thereby "bricked" the phone. Well i could start it in flashmode but neither in normal or fastboot.

    After i used the restore function in s1tool, witch is done in flashmode, the phone worked like nothing have ever been done to it. I could flash the phone after that, running 4.0.A.2.377 witch was the update i accepted.

    The bootloader is also LOCKED after the restore function in s1tool, because when i tried to flash a unsecure kernel in fastboot mode, i got an error.

    So, i did the TP / s1tool unlock again and after that i just flashed my unsecure kernel to the phone. Used gingerbreak and rooted the sucker..

    I think i actually could lock the bootloader now with no problem, but i am not going to try since if something goes wrong, i have to start my mod of the phone from square 1 again.

    So, yes, if you use the restore, you lock the bootloader and you can use SEUS to update the phone.

    Fastduck,

    do you mean that 'restore' - either using PC companion or using s1tool - is a solution to get rid of the bricking after accepting an update, AND allows us to update OTA (even if we need to 'restore' afterwards)?

    Or did you 'restore' back to the situation before you updated?

    Thanks for clarifying... I'm holding off from rooting because I want to know for sure that there will be a way to get official SE updates (not too keen on flashing user provided 'stock' roms, since I don't have a normal international QWERTY unit)

    Also, after restoring, were you still rooted/unlocked?

    I think most answers to your questions are listed up here. The restore i talk about is the restore in s1tool that lock the bootlader again and then you can use restore from SEUS.

    As far as i know, the only way you can se that i used this method on the device is a very small hole in the label over the testpoint under the battery where i pricked a needle trough..

    Iam a happy Duck.. I got the root that i want so i can mod the framework in the colors i want and i still have my DRM so i can enjoy the 7mio music numbers my carrier provide for me for free.. As long as the DRM is working.
    3
    tp for st15i

    ok goddamnit i took a photo :D

    wmhsh5.jpg