Home User CP Donate Chat Register Today!  
  Get New posts Faq / Help?
   


Go Back   Hackint0sh > Projects and Hacks > iPhone > iPhone "2G" (Rev. 1) > Hardware Unlock

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 08-06-2008, 02:00 PM
Tamagochi
Status: Offline
Junior Member
 
Join Date: Aug 2007
Posts: 14
Rep Power: 0
Tamagochi is on a distinguished road
Default Baseband 1.45 International (Unlocked) and AT&T (locked) Compare.

Hi all,
I had the chance to have 2 iPhones 3G. One is from 3 Hong Kong, and one is from AT&T. The one from Hong Kong of course is SIM Free (unlocked) and another is stucked with AT&T.
I have dumped both the Intel NOR flash chips which are holding the basebands using a hardware programmer and carefully compared them with the hope to find some ways to unlock.
What I could found here are:
- The flash size is 4 times bigger than the old one (16Mb instead of 4Mb).
- The bootloader 5.8 size is 0x40000 bytes instead of 0x20000 bytes that of Bootloader 3.9 and 4.6. Baseband starts at 0x40000
- Both dumped files are identical from 0x000000 to 0xE40000 which is the end of basebands.
- I was not capable to find any bug but have done following: Wrote the whole unlocked baseband to the locked chip and soldered back. In the result, I got IMEI 0049xxx, it was predictable because of wrong IMEI and CHIPID. Next, I did the same but kept the seczone intact. In the result, I got IMEI, S/N, MAC address back but still got No Service.
So, The posibilities here are:
- The lock state is in the seczone, and its position depends on the combination of IMEI+NORID, wrong modification may cause to 0049xx IMEI.
- The lock state is in the Proccessor X-Gold 608 not in the Intel NOR flash. Taking it out of the board and read it is much harder than that with the Intel NOR flash.

Any one can help to find ways to unlock, feel free to contact me. I can give both dumped files, I can modify, patch these files, rewrite the NOR chip and solder them back with no problem.
Curious people please just wait for professionals
Thanks
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #2 (permalink)  
Old 08-06-2008, 02:12 PM
ta_mobile's Avatar
ta_mobile
Status: Offline
Senior Member
 
Join Date: Sep 2007
Location: HaNoi - VietNam
Posts: 120
Rep Power: 19
ta_mobile has a spectacular aura aboutta_mobile has a spectacular aura aboutta_mobile has a spectacular aura about
Send a message via MSN to ta_mobile Send a message via Yahoo to ta_mobile Send a message via Skype™ to ta_mobile
Default

haha, bro. Finally found 1 guy do the Dev's laughing things like me

I just done all you did and more, put in and out many time the X-Gold Same result but more information.

Pls contact me. We will share more information.

@Dev team: pls dont forget us.

PS: Tamagochi, dont you think 0xE80000 to the FCFC01 is insteresting ?

Last edited by ta_mobile; 08-06-2008 at 02:15 PM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #3 (permalink)  
Old 08-06-2008, 02:28 PM
deco
Status: Offline
iPhone Moderator
 
Join Date: Dec 2007
Posts: 153
Rep Power: 9
deco is on a distinguished road
Default

Nice work guys. Keep it up!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Sponsored links Remove advertisements
Advertisement
Advertisement

  #4 (permalink)  
Old 08-06-2008, 05:53 PM
ta_mobile's Avatar
ta_mobile
Status: Offline
Senior Member
 
Join Date: Sep 2007
Location: HaNoi - VietNam
Posts: 120
Rep Power: 19
ta_mobile has a spectacular aura aboutta_mobile has a spectacular aura aboutta_mobile has a spectacular aura about
Send a message via MSN to ta_mobile Send a message via Yahoo to ta_mobile Send a message via Skype™ to ta_mobile
Default

Quote:
Originally Posted by Tamagochi View Post
Hi all,
I had the chance to have 2 iPhones 3G. One is from 3 Hong Kong, and one is from AT&T. The one from Hong Kong of course is SIM Free (unlocked) and another is stucked with AT&T.
I have dumped both the Intel NOR flash chips which are holding the basebands using a hardware programmer and carefully compared them with the hope to find some ways to unlock.
What I could found here are:
- The flash size is 4 times bigger than the old one (16Mb instead of 4Mb).
- The bootloader 5.8 size is 0x40000 bytes instead of 0x20000 bytes that of Bootloader 3.9 and 4.6. Baseband starts at 0x40000
- Both dumped files are identical from 0x000000 to 0xE40000 which is the end of basebands.
- I was not capable to find any bug but have done following: Wrote the whole unlocked baseband to the locked chip and soldered back. In the result, I got IMEI 0049xxx, it was predictable because of wrong IMEI and CHIPID. Next, I did the same but kept the seczone intact. In the result, I got IMEI, S/N, MAC address back but still got No Service.
So, The posibilities here are:
- The lock state is in the seczone, and its position depends on the combination of IMEI+NORID, wrong modification may cause to 0049xx IMEI.
- The lock state is in the Proccessor X-Gold 608 not in the Intel NOR flash. Taking it out of the board and read it is much harder than that with the Intel NOR flash.

Any one can help to find ways to unlock, feel free to contact me. I can give both dumped files, I can modify, patch these files, rewrite the NOR chip and solder them back with no problem.
Curious people please just wait for professionals
Thanks
Lastest news: after making some modifications on the so called International phone BB, mine is seem to be locked forever even I made the backup full dumped and restored it. So you should be very carefull.

here is the proof.



Anyone feel sorry to my 1400$
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #5 (permalink)  
Old 08-06-2008, 08:23 PM
Number_41
Status: Offline
Jedi Admin
 
Join Date: Sep 2007
Location: sao paulo, brasil
Posts: 1,233
Rep Power: 10
Number_41 has much to be proud ofNumber_41 has much to be proud ofNumber_41 has much to be proud ofNumber_41 has much to be proud ofNumber_41 has much to be proud ofNumber_41 has much to be proud ofNumber_41 has much to be proud ofNumber_41 has much to be proud ofNumber_41 has much to be proud of
Default

ta

I hear you can get the fls files through the tmp when doing pwnage.

N41
__________________
MSN/AIM? PM me
If you want to become a Hackint0sh supporter click here.
I DO READ PM's

"Just because I'm losing
Doesn't mean I'm lost
Doesn't mean I'll stop
Doesn't mean I will cross

Just because I'm hurting
Doesn't mean I'm hurt
Doesn't mean I didn't get what I deserve
No better and no worse "
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #6 (permalink)  
Old 08-07-2008, 01:48 AM
shorty6boy1
Status: Offline
Junior Member
 
Join Date: Aug 2008
Posts: 6
Rep Power: 0
shorty6boy1 is on a distinguished road
Default

ouch thats some sad money ta
thanks for everything tho, keep it coming and I'm sure we soon got an software-unlock:hack::hack:
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Sponsored links Remove advertisements
Advertisement
Advertisement

  #7 (permalink)  
Old 08-07-2008, 01:51 AM
ChronicProductions
Status: Offline
Respected Member
 
Join Date: Sep 2007
Posts: 693
Rep Power: 51
ChronicProductions is a jewel in the roughChronicProductions is a jewel in the roughChronicProductions is a jewel in the rough
Default

i put up the 2.1 5f90 keys here if anyone wants them. you want the restore ramdisk one because the firmware is in there

http://www.theiphonewiki.com/wiki/in...MG3_Keys_/_IVs

use 'xpwntool' to decrypt them if you use openssl its messy
__________________
Chronic Dev Blog

The iPhone Wiki
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #8 (permalink)  
Old 08-07-2008, 09:03 AM
Tamagochi
Status: Offline
Junior Member
 
Join Date: Aug 2007
Posts: 14
Rep Power: 0
Tamagochi is on a distinguished road
Default

@ta: I did not find anything interesting in 0xE80000:FCFC01, its out of the seczone and I had overwriten by the International version. I dont think it plays any important role.
In your case I think you have damaged some other parts in the commboard or did not solder the NOR chip properly. It cannot be "locked forever" since you can restore the original dump file. Lets try again man!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #9 (permalink)  
Old 08-07-2008, 09:27 AM
ta_mobile's Avatar
ta_mobile
Status: Offline
Senior Member
 
Join Date: Sep 2007
Location: HaNoi - VietNam
Posts: 120
Rep Power: 19
ta_mobile has a spectacular aura aboutta_mobile has a spectacular aura aboutta_mobile has a spectacular aura about
Send a message via MSN to ta_mobile Send a message via Yahoo to ta_mobile Send a message via Skype™ to ta_mobile
Default

Quote:
Originally Posted by Tamagochi View Post
@ta: I did not find anything interesting in 0xE80000:FCFC01, its out of the seczone and I had overwriten by the International version. I dont think it plays any important role.
In your case I think you have damaged some other parts in the commboard or did not solder the NOR chip properly. It cannot be "locked forever" since you can restore the original dump file. Lets try again man!
Thanks. But you know or not with the inter-phone in 2 conditions: iTunes Active dumped and Pwned active dumped ? The area from 0xE8 to 0xFC will be changed bro. Isn't it interesting ?

And if you think my hw skill is not enough to sure about the block, u can try this and dont tell me I harm your phone: Put the pair X-Gold and Nor from 1 locked in the Inter-phone then restore DFU 2.0 origin, sync itunes... after that, put back the original. Tell me the result pls

Last edited by ta_mobile; 08-07-2008 at 09:32 AM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Sponsored links Remove advertisements
Advertisement
Advertisement

  #10 (permalink)  
Old 08-07-2008, 01:56 PM
Tamagochi
Status: Offline
Junior Member
 
Join Date: Aug 2007
Posts: 14
Rep Power: 0
Tamagochi is on a distinguished road
Default

Quote:
Originally Posted by ta_mobile View Post
Thanks. But you know or not with the inter-phone in 2 conditions: iTunes Active dumped and Pwned active dumped ? The area from 0xE8 to 0xFC will be changed bro. Isn't it interesting ?

And if you think my hw skill is not enough to sure about the block, u can try this and dont tell me I harm your phone: Put the pair X-Gold and Nor from 1 locked in the Inter-phone then restore DFU 2.0 origin, sync itunes... after that, put back the original. Tell me the result pls
@ta: I respect your hardware skill, yes I know not everyone can do that . I will try to do as your advice, dont tell me that my International 3G will become AT&T locked or locked forever . Actually, when you do a full restore there will be some log information in the NOR flash. In my opinion it does not effect any thing in the lock state.

Last edited by Tamagochi; 08-07-2008 at 02:02 PM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +2. The time now is 02:20 AM.



Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.3.2 Ad Management by RedTyger
follow us on Twitter!

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105