Discuss [Baseband][3G] 1.45.00 bootloader 5.8 full dumped ! at the Hardware Unlock - Hackint0sh.org; Hi all !
I've dumped full bb of the white 16G 3G, hoping it will ...
-
Senior Professional
Array
-
-
-
-
Senior Professional
Array

Originally Posted by
XianLi
Hey Ta, it's been a long time !
Very nice job and help for the community !

Im still around here bro, haha, just hoping smthing simple like this will be found out 

Originally Posted by
Dev Team Wiki Simple Unlock
From the S-Gold's perspective, here are the fundamentals of unlocking basebands. A simple byte sequence search combined with a neutered baseband are all you need. (The s5l8900 CPU imposes other restrictions beyond this discussion.)
The secpack is at ICE*.fls offset 0x1a4 (0×800 bytes long)
The baseband is at ICE*.fls offset 0x209a4
The baseband length is at ICE*.fls offset 0×20 (subtract 0×20000)
Due to gray's initial RCE of the baseband, and combined with a neutered bootloader, unlocking recent and future basebands has been reduced to a simple byte search.
Search for the byte sequence “ff 90 a0 e3 ff 00 00 e2 02 00 50 e3” in the baseband. You should find just once such sequence, and the next four bytes will be “02 00 00 1a”. Change these four bytes to all zeros to unlock your baseband.
Firmware Baseband fls offset
1.1.3 4.03.13 0x9a4+0x238150 = 0x238af4 (2329332)
1.1.4 4.04.05 0x9a4+0x2395cc = 0x239f70 (2334576)
2.0 beta1 4.05.00 0x9a4+0x239884 = 0x23a228 (2335272)
2.0 beta2 4.05.01 0x9a4+0x238f38 = 0x2398dc (2332892)
2.0 beta3 4.05.01 0x9a4+0x238f38 = 0x2398dc (2332892)
2.0 beta4 4.05.02 0x9a4+0x239194 = 0x239b38 (2333496)
2.0 beta5 4.05.03 0x9a4+0x23925c = 0x239c00 (2333696)
2.0 beta6 4.05.04 0x9a4+0x23925c = 0x239c00 (2333696)
2.0 beta7 4.05.04 0x9a4+0x23925c = 0x239c00 (2333696)
2.0 beta8 4.05.04 0x9a4+0x23925c = 0x239c00 (2333696)
2.0 release 4.05.04 0x9a4+0x23925c = 0x239c00 (2333696)
If you have a neutered bootloader, the following patches achieve the anySIM unlock. Just patch the .fls and feed both the .fls and .eep to the bbupdater that gets installed in /Applications/BootNeuter.app/bin by the Dev Team IPSW Builder.
dd if=/dev/zero of=ICE04.03.13_G.fls bs=1 seek=2329332 count=4 conv=notrunc
dd if=/dev/zero of=ICE04.04.05_G.fls bs=1 seek=2334576 count=4 conv=notrunc
dd if=/dev/zero of=ICE04.05.00_G.fls bs=1 seek=2335272 count=4 conv=notrunc
dd if=/dev/zero of=ICE04.05.01_G.fls bs=1 seek=2332892 count=4 conv=notrunc
dd if=/dev/zero of=ICE04.05.02_G.fls bs=1 seek=2333496 count=4 conv=notrunc
dd if=/dev/zero of=ICE04.05.03_G.fls bs=1 seek=2333696 count=4 conv=notrunc
dd if=/dev/zero of=ICE04.05.04_G.fls bs=1 seek=2333696 count=4 conv=notrunc
-
-
-
thanks great job.you have perfect hardware skills.
-
Chief of Administration
iPhone Dev Team
Array
Hey bro
Nice work done, repspectable hardware skills.
-
-
Hi,
Great job! Can you please post hi res picture of the cleaned pcb ? Is any of the
flash bus exposed or all is routed in the internal layer ?
BR
-
-
-
What i was waiting for.
As always, job well done
Cheers, GSMVN
N41
MSN/AIM? PM me
If you want to become a Hackint0sh supporter click here. I DO READ PM's
"Just because I'm losing
Doesn't mean I'm lost
Doesn't mean I'll stop
Doesn't mean I will cross
Just because I'm hurting
Doesn't mean I'm hurt
Doesn't mean I didn't get what I deserve
No better and no worse "
-
Senior Professional
Array
-
Similar Threads
-
By strangerms in forum Ultrasn0w (3G(S)/iPhone 4 unlock)
Replies: 4
Last Post: 10-27-2009, 12:30 AM
-
By ta_mobile in forum Hardware Unlock
Replies: 10
Last Post: 09-14-2008, 01:58 PM
-
By DJ McG in forum General
Replies: 1
Last Post: 02-09-2008, 06:36 PM
-
By iphonewiz in forum iPhone "2G" (Rev. 1)
Replies: 1
Last Post: 11-25-2007, 03:27 AM
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
Bookmarks