Simlock.exe validation. - MDA II, XDA II, 2060 ROM Development

Hi,
I read this post a while ago and dismissed it thinking that its obvious that the simlock program checks the code and write something into the device to unlock it....
http://forum.xda-developers.com/viewtopic.php?t=3932&highlight=simlock
But... after simlock validates the first time, does the device check the simlock area, or just accept the return code from simlock?
That post demonsrates that you can rename some file to simlock.exe and make it run. Could it be possible for this program to 'pretend' to exit like simlock, and so validate the first time round.
Has anyone dismantled simlock to see exactly what it does, or in fact if we could reverse engineer its code validation algorithm (which should be a one way hash if they are sensible!)
Toxic

Hi,
check is done in GSM ROM...
Simlock.exe is only UI component to enter value.
John

hi,
Ok so the check is done in rom, if failed call simlock.exe
makes sense!
toxic

Related

HELP with G4 Unlocking project!!!!

It was suggested in this thread that those unlocking their Wizard devices through IMEI Check, download USB-Monitor (available HERE free for 30 days as shareware) and run it BEFORE RUNNING THE IMEI CHECK SOFTWARE ON THEIR DEVICE!
Then post the results to the FORUM.
I propose that we use this thread to do that, so a SIMPLE AND FREE unlock method can be found!
Before you start in on me about taking one for the team, I PAID TO UNLOCK MY G3 WITH IMEI CHECK TOO! (And if I'd have known I could have helped by doing this, I would have!)
I feel it would be an excellent way to repay the entire wizard community for their wonderful time and effort!
And NO, this is NOT something I'm doing myself, I'm just trying to get the ball rolling!
i will gladly post dumped info after imei check unlocking procedure. cuz i think its too expensive . im planing to do this in abt two weeks.
blazoner said:
It was suggested in this thread that those unlocking their Wizard devices through IMEI Check, download USB-Monitor (available HERE free for 30 days as shareware) and run it BEFORE RUNNING THE IMEI CHECK SOFTWARE ON THEIR DEVICE!
Then post the results to the FORUM.
I propose that we use this thread to do that, so a SIMPLE AND FREE unlock method can be found!
Before you start in on me about taking one for the team, I PAID TO UNLOCK MY G3 WITH IMEI CHECK TOO! (And if I'd have known I could have helped by doing this, I would have!)
I feel it would be an excellent way to repay the entire wizard community for their wonderful time and effort!
And NO, this is NOT something I'm doing myself, I'm just trying to get the ball rolling!
Click to expand...
Click to collapse
i have been working on this with another member,i will post my findings later,i also plan to ask for help from 2 members that undestand more that me about rom unlocking logs.
Thanks for taking notice, Faria!
It's some of the discussion about your 3.0.0.0 ROM's that has inspired me to get this started.
I figure the more objective (system provided) information we have, the closer we are to a simple solution.
Looking forward to any findings!
faria said:
i have been working on this with another member,i will post my findings later,i also plan to ask for help from 2 members that undestand more that me about rom unlocking logs.
Click to expand...
Click to collapse
hello mine is cid unlocked but if you need me to try anything give me a bell
iam on g4
spl/ipl 2.21
faria rc1 12mb
ext v3
rom 3.0
radio02.47.11
Mine is CID unlocked using the IMEI site:
G4 - i-mate k-jam
IPL/SPL 2.16.0001
ROM Faria RC1 8mb
ExtROM v3
Radio 2.47.11
Happy to help if i can
Not going to work
I just tried to run the IMEI software again while run USB monitor, but the IMEI software can not connect to the phon with the monitor program running. I tried 5 times
still cid locked here. I plan to unlock as soon as I get done getting all the crumb-snatcher's xmas shopping done . I will be sure to to what I can to help with logs/etc.
cptcafne said:
I just tried to run the IMEI software again while run USB monitor, but the IMEI software can not connect to the phon with the monitor program running. I tried 5 times
Click to expand...
Click to collapse
Bad news
Somebody else ?
usb-monitor log file
hello,
i've just unlocking my Wizard devices through IMEI Check...And i've log file from usb-monitor !!
But file size is over 2mb !
fla242 said:
hello,
i've just unlocking my Wizard devices through IMEI Check...And i've log file from usb-monitor !!
But file size is over 2mb !
Click to expand...
Click to collapse
Cool! I was just about to assume that the IMEI Check software checked for usb monitor, etc. and disallowed running the two together.
Can you zip the file and upload it?
If you don't have a zip program, google winzip, or winrar.
If the file is text based, it shoul zip nice!
Forgive the spelling, I'm sitting on the side of the road waiting on a tow-truck....
oops!
NIX THAT! DON'T POST YOUR IMEI INFO!!
We'll get in touch and make arrangements!
blazoner said:
NIX THAT! DON'T POST YOUR IMEI INFO!!
We'll get in touch and make arrangements!
Click to expand...
Click to collapse
That's what i'm tell me
Mine is Locked
Have a look at this thread in order to understand how this was done in the Hermes:
Reverse engineering the HERMES imei-check unlocker
The bootloader commands for the Hermes are explained in these wiki pages, you _really_ need to do something similar for the wizard:
Hermes Bootloader Information
Hermes Radio Bootloader and AT command interpreter
Some hints that may help you:
1. You can run the unlocker as many times as you want, it doesn't matter if you've already cid unlocked your device, the imei-check unlocker will behave the same.
2. In order for the USB monitor capture to be useful, you need to click on the "COMPLETE" tab and when you have captured it, export it as ANSI TEXT.
3. If the app fails (communication error) you need to create 2 admin users, 1 for running usb monitor and the other for running the unlocker. Use right click, "run as..." and then select the other admin user. You need to repeat this process several times until you can successfully get the log.
4. be careful on what you post here, as imei-check has intelectual property rights on their work. Do not "copy" their solution, but reimplement it in another way.
look its not intellectual property simply because its a solution around a software lock put on by the manufacturer ...this voids the warrantee anyway. post it simply because you can don't worry about intellectual property
goldcard
and what about goldcard(http://forum.xda-developers.com/showthread.php?t=270952)? is it way to flash whithout unlockCID?
docdoc8 said:
look its not intellectual property simply because its a solution around a software lock put on by the manufacturer ...this voids the warrantee anyway. post it simply because you can don't worry about intellectual property
Click to expand...
Click to collapse
It's intellectual property simply because it's their solution. DON'T post it, unless you want to be named in their lawsuit! Furthermore, DON'T post it because none of us can afford having xda-developers closed down because they are getting sued!
The trick is that the ultimate solution was designed by HTC. IME Check just exploits it.
Therefore, if we can see what IMEI Check is doing, we can find a different way of doing the same thing!
As an example:
IMEI Check rolls a ball by pushing it with a stick, so we blow on it to make it move, or we dig under it to make it roll downhill.
Either way, we can't be accused of doing it the same way they are, but we're still rolling the ball.
if anyone will sue xda developers it will not be IMEI Check it will be the HTC or the companies involved in making the phones/MDA's. Remember its the company who made the phone G4 so people couldn't mod it.
i doubt IMEI check has the money for lenghy court costs.
plus if you reverse engineer IMEI's way of Unlocking but change the order of doing it your essentially copying them anyway.
Just my opinion.
anyway this site is great, keep up the good work fellas.
Is there a way of checking if you're PDA is locked o not?

G4 SIM Unlocker

I need some assistance in UNlocking my 8125. I sent my phone into at&t for repairs, they sent the phone back locked. I am an old ATTWS customer, I have been waiting for one week for my unlock code. I recently purchased an 8525 and SIM/CID Unlocked that phone, but I need assistance with this phone. I have run the lokiwiz03a several times, but it keeps giving me "The system cannot find the path specified" on all the lines of the program. Of course at the end it does not provide an unlock code, It repeats the message.
I think you are not doing it proper,I may be wrong,but most probably you have to copy and paste two cab files 'Cert_SPCS' and 'EnableRapi' in the phone somewhere and execute them in the phone,then after that run 'lokiwizMSL' on your pc.
Cheers!
I loaded both .cab files on the 8125, they both ran succesfully. I have the phone connected to active sync. I am at a loss on this. I have no clue why this is not working. I have flashed numerous ROM's on phones, this one seems to be a pain the in the behind. At&t just returned the phone from repairs, could they have installed something to block this?
hmmm,
really strange though,may be they have put some kinda special code on it.what repairs were carried on it ?
btw,have you tried to sim unlock with WST 4.2 tool,ask mestrini,if it might do the trick.
Cheers!
I ran the WST as you requested. It is telling me that the DOC chip is write protected. When I run the CID Action and Run Super CID it returns that message. When I run SIM unlock it generates all the data from the phone and produces LOCKED in the status. At the bottom of all the data it returns DOC chip is write protected. I may be running this tool wrong, your info is appreciated.
WST simlock tool doesn't work on G4.
Easiest way:
1. Run flight mode.
2. Turn off your Wizard and insert "bad" simcard.
3. Turn on your Wizzard copy Two cabs Cert_SPCS' and 'EnableRapi'
4. Install it on device memory.
5. Turn on phone (in commanager)
6. Run lokiwiz, it should work!
How do I turn on the phone with the wrong SIm in the phone, it keeps going back to the SIM lock page. I am able to turn on the flight mode, but I can not do anything else, it keep srefering back to the SIMlock page.
simlock screen = run lokiwiz and enter generated code. It must work
Everyline on the screen reports "The system cannot find the path specified" I think at&t has protected this from unlocking?
same happens to me
try running lokiwiz from c:\
make sure that two cabs are installed
wizard is an old model I think at&t is taking care over iphone now ;p

[Q] Using our own Unlock_Code.bin a possibility? (Dev's please see this)

I was wondering if anyone has thought about looking into how htc takes our device id tokens and turns them into the unlock code? or is the unlock code just a generic "everybody gets the same thing" kinda deal? Call me crazy, but if each device needs a specific unlock code, couldn't we in theory compile id tokens and corresponding unlock codes and try to figure out how htc gets from A (id token) to B (unlock code). If anything, the least I could see coming out of this would be being able to unlock 1.5 without htc having a device id

[Q] [q] great questions to try to unlock bootloader ¡¡help!!

My story is that I had a xperia x8 to make s1tool Identify came with this "SEMC SIMLOCK CERTIFICATE" and the battery is 11 w25 successfully unlock the bootloader using "msm7227_semc.exe".
I had custom kernel, custom rom android 2.3 until a technician take to release him for the two companies of my country, and actually released it flashing as I leave the factory.
Now to make a sale s1tool Identify with this
Attached Thumbnails
Try to unlock the bootloader in the same way that the first time with "msm7227_semc.exe" died completely and even take technical and revived him from ayi not tried more.
Without in bariums However lei in forums and also in this that if he was released with setool2 devo use this "msm7227_setool2.exe" and not this "msm7227_semc.exe". Maybe that's why? Died?
Looking for more information read that if you leave this message "NOT RECOGNIZED SIMLOCK CERTIFICATE" in no way attempting Devia, But I also read in a forum that if came Indonesian "NOT RECOGNIZED SIMLOCK CERTIFICATE" and nothing came devia to use this "msm7227_setool2. exe "
I'm about to try again with "msm7227_setool2.exe" but first wanted to consult with you to clear up doubts me ... any comments are welcome ... THANKS
respond with complete words because my English is too poor and I have to use translators ... thanks

Understanding network unlocking

Why does each of us have to pay to unlock their phone model from a network when only one of us could unlock and then help others ?
Thats why I think we need to understand how phone unlocking works. I've searched and could not find any tutorial. I suggest this to be general advice and not any specific device.
So questions:
When I insert the unlock code into an android device, what files or partitions are modified ? Then could we not clone that and share the image with other users ?
It doesn't work like that. Each IMEI gets its own code by the carriers. It's not even an Android thing as all software come to the carrier unlocked and the carrier then adds in its own stuff excluding then lock codes.
We all know that each phone has its own IMEI. But to be more clear in byte-code language, we need to understand, how does the phone itself know "am I a locked phone or an unlocked one ?" Or in other words, do those who own websites to unlock code break the algorithm themselves or do they buy it from producers ?
Actually some have discovered that it's mmcblk0p6 in their case that changes when applying the unlock code, and using tools such as "string -n 8" to read that partition. But we need to uncover more than that, we don't know the partition name that need to be changed in other cases.

Categories

Resources