Home User CP Donate Chat Register Today!  
  Get New posts Faq / Help?
   


Go Back   Hackint0sh > Projects and Hacks > iPhone > General > Turbo-, Supersim and Simcloning Solution

Reply
 
LinkBack Thread Tools Display Modes
  #71 (permalink)  
Old 08-01-2008, 09:29 AM
ColSanders
Status: Offline
Junior Member
 
Join Date: Jul 2008
Posts: 29
Rep Power: 0
ColSanders is on a distinguished road
Default

@Zf_

This may be a dumb question, but you seem to be the least blinded by the hope of an unlock.... How do these things actually work?
I would think just spoofing the MCC MNC to the phone would be sufficient, but apparently there is more to it than that, right?
Otherwise I would expect that data wouldn't fail, and they wouldn't stop working after a while.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #72 (permalink)  
Old 08-01-2008, 09:48 AM
Zf_
Status: Offline
iPhone Dev Team
 
Join Date: Jul 2007
Posts: 717
Rep Power: 43
Zf_ will become famous soon enoughZf_ will become famous soon enough
Default

Quote:
Originally Posted by ColSanders View Post
@Zf_

This may be a dumb question, but you seem to be the least blinded by the hope of an unlock.... How do these things actually work?
I would think just spoofing the MCC MNC to the phone would be sufficient, but apparently there is more to it than that, right?
Otherwise I would expect that data wouldn't fail, and they wouldn't stop working after a while.
nah it's not a dumb question, it's important to understand what's going on.

You're right, spoofing the MCC+MNC is enough to fool the phone SIM locking algorithms.

Now the problem is, what about your actual connection ? Let's sum it up roughly

The MCC/MNC is part of the IMSI, which is your login to the mobile network.

The previous exploits relied on the fact that the baseband was quite dumb and read the IMSI more than once - once for the unlock module, and the other times for the real baseband operations. So sending a fake IMSI with the correct sequence was enough to unlock the baseband and still have an happy network, since that fake IMSI never made it to the network.

Now the baseband is smarter and reads the IMSI only once - so from now on, when you're trying to login to the network, you'll show a bad login. You can then use a lot of tricks to make the network ask you again for your login/pass, or make it use old valid credentials (still suming it up very badly here, but you got the general idea). Problem is, those tricks are temporary, not reliable, and most of all, highly illegal in most countries.

That's the sad state of proxy SIM unlocking right now ...
__________________
char dumbass[128]="pasta.dat";
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #73 (permalink)  
Old 08-01-2008, 09:51 AM
ColSanders
Status: Offline
Junior Member
 
Join Date: Jul 2008
Posts: 29
Rep Power: 0
ColSanders is on a distinguished road
Default

So basically, when it stops working, your network got tired of you being a jackass?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Sponsored links Remove advertisements
Advertisement
Advertisement

  #74 (permalink)  
Old 08-01-2008, 10:27 AM
Zf_
Status: Offline
iPhone Dev Team
 
Join Date: Jul 2007
Posts: 717
Rep Power: 43
Zf_ will become famous soon enoughZf_ will become famous soon enough
Default

yeah ... for the moment it's temporary ... but they could very well ban you or even sue you (and we're talking about laws close to counter-terrorism here, not small charges) ... of course those new xsim sellers don't care, they have a take the monies and run fast business, and it's up to you to handle the mess waiting to happen
__________________
char dumbass[128]="pasta.dat";
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #75 (permalink)  
Old 08-01-2008, 12:00 PM
nvidia2008
Status: Offline
Senior Member
 
Join Date: Jul 2008
Posts: 136
Rep Power: 8
nvidia2008 is on a distinguished road
Default

Quote:
Originally Posted by deco View Post
nvidia,
The correct code is **5005*78283#
And send me those files!!
I hit a wall, like I mentioned without the ability to program the Boost mode my Yessim is dead in the water.

It starts of well for like 5 minutes, then goes to "Searching" then a few hours later goes to "No Service"... Basically the network saying F*K YOU as it learns and adapts to the hack, much like an evil Matrix-esque pseudo-neural organism. (See I should be a writer not a hacker). :hack:

I had to pull out my normal sim so I can, like, use my regular SonyE phone.

So... sorry mate, I've got no useful new logs until this RJ45 dealie-o is sorted out. I am going to Belgium and Netherlands next week so I really want to be able to use something with one of those non-roaming Europe-wide simcard things.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #76 (permalink)  
Old 08-01-2008, 12:56 PM
nvidia2008
Status: Offline
Senior Member
 
Join Date: Jul 2008
Posts: 136
Rep Power: 8
nvidia2008 is on a distinguished road
Default

Quote:
Originally Posted by deco View Post
nvidia,
The correct code is **5005*78283#
And send me those files!!
Okay with this number and running launchctl unload /System/Library/LaunchDaemons/com.apple.DumpBasebandCrash.plist I got some good logs now.

First one with AT&T locked, "No service" on UK networks will be sent to you. Trying again, turn phone off, turn phone on, baseband dump. 2nd Log file will be sent.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Sponsored links Remove advertisements
Advertisement
Advertisement

  #77 (permalink)  
Old 08-01-2008, 02:51 PM
pytey
Status: Offline
iPhone DevTeam
 
Join Date: Aug 2007
Posts: 22
Rep Power: 0
pytey is on a distinguished road
Default Scans or high quality images of the xSIM or Yesim?

Hello,

I've been talking to team-mate Zf about the xSIM stuff and would be interested in getting some high quality scans of the xSIM and yesim and any other variants or clones of the TurboSIM type "unlocking" devices to investigate further.

If anyone could take a close up macro shot of the front and the back of their Yesim, xSIM or whatever they have it would be appreciated.

Please send to blog@iphone-dev.com

-- pytey
iPhone DevTeam.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #78 (permalink)  
Old 08-01-2008, 06:31 PM
nvidia2008
Status: Offline
Senior Member
 
Join Date: Jul 2008
Posts: 136
Rep Power: 8
nvidia2008 is on a distinguished road
Default

Coming up soon. Scans
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #79 (permalink)  
Old 08-01-2008, 06:32 PM
mattmartincouk
Status: Offline
Senior Member
 
Join Date: Sep 2007
Posts: 152
Rep Power: 10
mattmartincouk is on a distinguished road
Default

Quote:
Originally Posted by Zf_ View Post
nah it's not a dumb question, it's important to understand what's going on.

You're right, spoofing the MCC+MNC is enough to fool the phone SIM locking algorithms.

Now the problem is, what about your actual connection ? Let's sum it up roughly

The MCC/MNC is part of the IMSI, which is your login to the mobile network.

The previous exploits relied on the fact that the baseband was quite dumb and read the IMSI more than once - once for the unlock module, and the other times for the real baseband operations. So sending a fake IMSI with the correct sequence was enough to unlock the baseband and still have an happy network, since that fake IMSI never made it to the network.

Now the baseband is smarter and reads the IMSI only once - so from now on, when you're trying to login to the network, you'll show a bad login. You can then use a lot of tricks to make the network ask you again for your login/pass, or make it use old valid credentials (still suming it up very badly here, but you got the general idea). Problem is, those tricks are temporary, not reliable, and most of all, highly illegal in most countries.

That's the sad state of proxy SIM unlocking right now ...
Another major thing which you've not added. The SIM card belongs to your provider.

They could also claim that you 'playing' with it is against their T&C. I've not had any problems with that now but something I have been thinking is this.

Once a network sees these attempts - I wonder if they apply some monitoring to it.

The reason I say this is fairly straight forward. My voda sim worked on a certain brand of proxy sim. Alwys worked - even if only for outbound calls/texts. But now it simply refuses to work at all when paired with a proxy sim. Strange.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Sponsored links Remove advertisements
Advertisement
Advertisement

  #80 (permalink)  
Old 08-01-2008, 07:00 PM
nvidia2008
Status: Offline
Senior Member
 
Join Date: Jul 2008
Posts: 136
Rep Power: 8
nvidia2008 is on a distinguished road
Default

Quote:
Originally Posted by nvidia2008 View Post
Coming up soon. Scans
I was too late. :p Mattmartincouk is the man!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +2. The time now is 12:52 AM.



Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.3.2 Ad Management by RedTyger
follow us on Twitter!

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105