Page 1 of 5 12345 LastLast
Results 1 to 10 of 48
Discuss [Baseband][3G] 1.45.00 bootloader 5.8 full dumped ! at the Hardware Unlock - Hackint0sh.org; Hi all ! I've dumped full bb of the white 16G 3G, hoping it will ...
  1. #1
    Senior Professional Array ta_mobile's Avatar

    Join Date
    Sep 2007
    Location
    HaNoi - VietNam
    Posts
    120
    Post Thanks / Like
    Downloads
    0
    Uploads
    0
    Rep Power
    23

    Default [Baseband][3G] 1.45.00 bootloader 5.8 full dumped !

    Hi all !

    I've dumped full bb of the white 16G 3G, hoping it will help for software unlocking a little bit. Who need it for hacking pls contact me.

    Who dont know about this pls do not spam. Thanks









  2. #2
    Former Bender
    Guest

    Default

    Hey Ta, it's been a long time !

    Very nice job and help for the community !

  3. #3
    Senior Professional Array ta_mobile's Avatar

    Join Date
    Sep 2007
    Location
    HaNoi - VietNam
    Posts
    120
    Post Thanks / Like
    Downloads
    0
    Uploads
    0
    Rep Power
    23

    Default

    Quote Originally Posted by XianLi View Post
    Hey Ta, it's been a long time !

    Very nice job and help for the community !
    Im still around here bro, haha, just hoping smthing simple like this will be found out

    Quote Originally Posted by Dev Team Wiki
    Simple Unlock

    From the S-Gold's perspective, here are the fundamentals of unlocking basebands. A simple byte sequence search combined with a neutered baseband are all you need. (The s5l8900 CPU imposes other restrictions beyond this discussion.)

    The secpack is at ICE*.fls offset 0x1a4 (0800 bytes long)
    The baseband is at ICE*.fls offset 0x209a4
    The baseband length is at ICE*.fls offset 020 (subtract 020000)
    Due to gray's initial RCE of the baseband, and combined with a neutered bootloader, unlocking recent and future basebands has been reduced to a simple byte search.

    Search for the byte sequence “ff 90 a0 e3 ff 00 00 e2 02 00 50 e3” in the baseband. You should find just once such sequence, and the next four bytes will be “02 00 00 1a”. Change these four bytes to all zeros to unlock your baseband.

    Firmware Baseband fls offset
    1.1.3 4.03.13 0x9a4+0x238150 = 0x238af4 (2329332)
    1.1.4 4.04.05 0x9a4+0x2395cc = 0x239f70 (2334576)
    2.0 beta1 4.05.00 0x9a4+0x239884 = 0x23a228 (2335272)
    2.0 beta2 4.05.01 0x9a4+0x238f38 = 0x2398dc (2332892)
    2.0 beta3 4.05.01 0x9a4+0x238f38 = 0x2398dc (2332892)
    2.0 beta4 4.05.02 0x9a4+0x239194 = 0x239b38 (2333496)
    2.0 beta5 4.05.03 0x9a4+0x23925c = 0x239c00 (2333696)
    2.0 beta6 4.05.04 0x9a4+0x23925c = 0x239c00 (2333696)
    2.0 beta7 4.05.04 0x9a4+0x23925c = 0x239c00 (2333696)
    2.0 beta8 4.05.04 0x9a4+0x23925c = 0x239c00 (2333696)
    2.0 release 4.05.04 0x9a4+0x23925c = 0x239c00 (2333696)
    If you have a neutered bootloader, the following patches achieve the anySIM unlock. Just patch the .fls and feed both the .fls and .eep to the bbupdater that gets installed in /Applications/BootNeuter.app/bin by the Dev Team IPSW Builder.

    dd if=/dev/zero of=ICE04.03.13_G.fls bs=1 seek=2329332 count=4 conv=notrunc
    dd if=/dev/zero of=ICE04.04.05_G.fls bs=1 seek=2334576 count=4 conv=notrunc
    dd if=/dev/zero of=ICE04.05.00_G.fls bs=1 seek=2335272 count=4 conv=notrunc
    dd if=/dev/zero of=ICE04.05.01_G.fls bs=1 seek=2332892 count=4 conv=notrunc
    dd if=/dev/zero of=ICE04.05.02_G.fls bs=1 seek=2333496 count=4 conv=notrunc
    dd if=/dev/zero of=ICE04.05.03_G.fls bs=1 seek=2333696 count=4 conv=notrunc
    dd if=/dev/zero of=ICE04.05.04_G.fls bs=1 seek=2333696 count=4 conv=notrunc

  4. #4
    iPhone Moderator Array

    Join Date
    Dec 2007
    Posts
    153
    Post Thanks / Like
    Downloads
    0
    Uploads
    0
    Rep Power
    14

    Default

    Great job TA.

  5. #5
    Rookie Array

    Join Date
    Oct 2007
    Posts
    25
    Post Thanks / Like
    Downloads
    0
    Uploads
    0
    Rep Power
    0

    Default

    thanks great job.you have perfect hardware skills.


  6. #6
    sam
    sam is offline
    Chief of Administration
    iPhone Dev Team
    Array sam's Avatar

    Join Date
    Jun 2007
    Posts
    1,852
    Post Thanks / Like
    Downloads
    35
    Uploads
    277
    Rep Power
    10

    Default

    Hey bro Nice work done, repspectable hardware skills.
    If you just want to support hackint0sh.org with a donation click here.
    Follow me on twitter: http://twitter.com/sam_hackint0sh

  7. #7
    Professional Array

    Join Date
    Jul 2007
    Location
    UK
    Posts
    51
    Post Thanks / Like
    Downloads
    0
    Uploads
    0
    Rep Power
    9

    Default

    Hi,

    Great job! Can you please post hi res picture of the cleaned pcb ? Is any of the
    flash bus exposed or all is routed in the internal layer ?

    BR

  8. #8
    Supporter Array

    Join Date
    Sep 2007
    Posts
    232
    Post Thanks / Like
    Downloads
    0
    Uploads
    0
    Rep Power
    19

    Default

    Thanks TA!
    Nice pics

  9. #9
    Jedi Admin Array

    Join Date
    Sep 2007
    Location
    sao paulo, brasil
    Posts
    1,242
    Post Thanks / Like
    Downloads
    0
    Uploads
    0
    Rep Power
    10

    Default

    What i was waiting for.

    As always, job well done
    Cheers, GSMVN
    N41
    MSN/AIM? PM me
    If you want to become a Hackint0sh supporter click here.
    I DO READ PM's

    "Just because I'm losing
    Doesn't mean I'm lost
    Doesn't mean I'll stop
    Doesn't mean I will cross

    Just because I'm hurting
    Doesn't mean I'm hurt
    Doesn't mean I didn't get what I deserve
    No better and no worse "

  10. #10
    Senior Professional Array iHack's Avatar

    Join Date
    Sep 2007
    Location
    New York, NY
    Posts
    242
    Post Thanks / Like
    Downloads
    0
    Uploads
    0
    Rep Power
    19

    Default

    Very sexyyy

    sweet pics


 

 
Page 1 of 5 12345 LastLast

Similar Threads

  1. Baseband Bootloader v. 06.04
    By strangerms in forum Ultrasn0w (3G(S)/iPhone 4 unlock)
    Replies: 4
    Last Post: 10-26-2009, 11:30 PM
  2. [Baseband][3G]1.45 and 1.48 full dumped free download !
    By ta_mobile in forum Hardware Unlock
    Replies: 10
    Last Post: 09-14-2008, 01:58 PM
  3. Replies: 1
    Last Post: 02-09-2008, 05:36 PM
  4. BIG NEWS or OLD NEWS BOOTLOADER 4.6 Dumped
    By iphonewiz in forum iPhone "2G" (Rev. 1)
    Replies: 1
    Last Post: 11-25-2007, 02:27 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Powered by vBulletin®
Copyright © 2014 vBulletin Solutions, Inc. All rights reserved.
Search Engine Friendly URLs by vBSEO
(c) 2006-2012 Hackint0sh.org
All times are GMT +2. The time now is 12:59 PM.
twitter, follow us!