PDA

View Full Version : F305 Tampered



Mr.Fl@sher
02-11-2010, 01:54 PM
Hello,
i got f305 dead since month maybe , this is identify log


v0.915058/UNI
CARD SERIAL: 0000xxxx
Loaded 51 flash descriptors
SIGNED MODE (USING SERVER)
CFG:100000000000
PLEASE ATTACH TURNED OFF PHONE NOW

EROM "R7A024" AID: 0001
SOFTWARE AID: 0001
SIMLOCK STATE: "TAMPERED"
LOADER AID: 0002
FLASH ID: "00EC/220C"
LOADER VERSION: "R3A011"

PHONE IMEI:356535xxxxxxxx
MODEL (from GDFS): W302
FACTORY CXC: 1207-7713 R7A024
CURRENT CXC: 1207-2375_R1BB002
CURRENT CDA: 1211-0583_R6A
CURRENT FS: 1207-2469_FS_NORDIC_R1BB002
LANGUAGE: AH
Elapsed: 8 secs.

so i managed to write trim area and then imei repair then signture unlock
i started with trim area write , failed writing and 1 credit gone !!!

here is log :


v0.915058/UNI
CARD SERIAL: 0000xxxx
Loaded 51 flash descriptors
SIGNED MODE (USING SERVER)
ALTERNATIVE SECURITY BYPASS ENABLED
CFG:110000000000
PLEASE ATTACH TURNED OFF PHONE NOW

EROM "R7A024" AID: 0001
SOFTWARE AID: 0001
SIMLOCK STATE: "TAMPERED"
LOADER AID: 0002
FLASH ID: "00EC/220C"
LOADER VERSION: "R3A011"

PHONE IMEI:356535xxxxxxxx
GOT SEED:69FBD20788014002268B2B5F
P96 AUTH PASSED
writing "E:\SETool\v0.915058\gdfs_in_ssw_format\S1\W302_TA. SSW"
can't get S1 command header
error while uploading DATA block
error while flashing "E:\SETool\v0.915058\gdfs_in_ssw_format\S1\W302_TA. SSW"
Elapsed: 203 secs.

so what to do now ? its erom problem and new solution can help ?
if so how many extra credits will need ?

Thank You

bigboy85
02-11-2010, 01:59 PM
perform full csca everything should be ok after that

but remember S1 signature doesn´t works on weekends

the_laser
02-11-2010, 02:51 PM
if simlock tampered and imei intact (your case) user SHOULD NOT write trim area or touch trim area at all.
instead, user should unlock phone using FULL SIGNATURE UNLOCK.

Mr.Fl@sher
02-11-2010, 04:24 PM
if simlock tampered and imei intact (your case) user SHOULD NOT write trim area or touch trim area at all.
instead, user should unlock phone using FULL SIGNATURE UNLOCK.

1st ,thx for replay

2nd ,imei intact mean that imei is same one on back sticker (in my case readed imei in NOT same back sticker) or imei intact mean setool read vaild imei not corrupted one ?

3rd, to repair my phone now make full signature unlock with 2 credits and nothing more or i may need extra work with extra credits ?

last , i think its useful to add this case to S1 FAQ

Thanks

the_laser
02-11-2010, 07:44 PM
imei intact=imei not damaged.
you can fix imei to original before full unlock or you can do full unlock as is.
finally, that is already in faq, check "working with odm phone" section

Mr.Fl@sher
02-13-2010, 12:45 PM
i did full signuture unlock with 2 credits

SIGNED MODE (USING SERVER)
CFG:100001000000
PLEASE ATTACH TURNED OFF PHONE NOW

EROM "R7A024" AID: 0001
SOFTWARE AID: 0001
SIMLOCK STATE: "TAMPERED"
LOADER AID: 0002
FLASH ID: "00EC/220C"
LOADER VERSION: "R3A011"

PHONE IMEI:35653502162996
MINOR ERROR "MISC_ERROR (No_such_unit)" IN "MISC_CLASS"
Checking for signature...
Waiting for calculation process...
RESPONSE: "SUCCESS" [2331]
GOT SEED:9768677C88014002268B2B5F
P96 AUTH PASSED
Unlock DONE
Elapsed: 21 secs.


result is phone cant recognize on usb and with
fbus cable become cant get imei


SIGNED MODE (USING SERVER)
CFG:100000000000
PLEASE ATTACH TURNED OFF PHONE NOW
PRESS "POWER ON" BUTTON SHORTLY...

EROM "R7A024" AID: 0001
SOFTWARE AID: 0001
SIMLOCK STATE: "TAMPERED"
LOADER AID: 0002
FLASH ID: "00EC/220C"
LOADER VERSION: "R3A011"

Can't get IMEI
MINOR ERROR "MISC_ERROR (TA_invalid,_format_may_be_required)" IN "MISC_CLASS"
Elapsed: 43 secs.


so i try to write trim area and extra 1 credit and result is fail in writing

SIGNED MODE (USING SERVER)
ALTERNATIVE SECURITY BYPASS ENABLED
CFG:110000000000
PLEASE ATTACH TURNED OFF PHONE NOW
PRESS "POWER ON" BUTTON SHORTLY...

EROM "R7A024" AID: 0001
SOFTWARE AID: 0001
SIMLOCK STATE: "TAMPERED"
LOADER AID: 0002
FLASH ID: "00EC/220C"
LOADER VERSION: "R3A011"

Can't get IMEI
GOT SEED:9BE3FE9388014002268B2B5F
P96 AUTH PASSED
writing "E:\SETool\v0.915060\gdfs_in_ssw_format\S1\W302_TA. SSW"
can't get S1 command header
error while uploading DATA block
error while flashing "E:\SETool\v0.915060\gdfs_in_ssw_format\S1\W302_TA. SSW"
Elapsed: 200 secs.


and now back to tampered state

SIGNED MODE (USING SERVER)
CFG:100000000000
PLEASE ATTACH TURNED OFF PHONE NOW

EROM "R7A024" AID: 0001
SOFTWARE AID: 0001
SIMLOCK STATE: "TAMPERED"
LOADER AID: 0002
FLASH ID: "00EC/220C"
LOADER VERSION: "R3A011"

PHONE IMEI:35653502162996
MODEL (from GDFS): W302
FACTORY CXC: 1207-7713 R7A024
CURRENT CXC: 1207-2375_R1BB002
CURRENT CDA: 1211-0583_R6A
CURRENT FS: 1207-2469_FS_NORDIC_R1BB002
LANGUAGE: AH
Elapsed: 9 secs.


until now 4 credits used and same result and all procedure done as your FAQ , please i need my credits back .

Thanks

the_laser
02-13-2010, 02:32 PM
obviously, your phone has damaged flash chip, that was initial reason of all problems.
we do not refund credits in case of hardware problems.

gbluez
02-13-2010, 04:34 PM
boss, is there any otherway to determind original ta?
i mean, you can change your server policy regarding this odm logs consumtion.

since this phone doesn't has otp, server can easily cheat by script?

the_laser
02-13-2010, 05:20 PM
for s1 phones, server will take credit each time. exactly because of that.

burgeronly
02-23-2010, 05:04 AM
Mr.laser...like Mr.Fl@sher problem...after replace new flash..can program it back? if can..show me the way..tq

the_laser
02-24-2010, 12:16 PM
setool2 does not support emptyboard fill of s1 phones, support is not planned.