[SM-N900*] CF-Auto-Root - Galaxy Note 3 Original Android Development

PLEASE TEST IF YOU HAVE THE multitouch issue BEFORE ROOTING, AS ROOTING WILL VOID YOUR WARRANTY Read this post: http://forum.xda-developers.com/showpost.php?p=46293575&postcount=279. I have not had time to look into this myself unfortunately, as I'm travelling. Better safe than sorry.
Check your device model ! Settings -> About device -> Model number. See the third post for exact supported model numbers. If your device is a totally different model, it will not work (may even brick) !
CF-Root is the root for "rooting beginners" and those who want to keep as close to stock as possible. CF-Root is meant to be used in combination with stock Samsung firmwares, and be the quickest and easiest way for your first root.
Donate
CF-Root has been available for many devices (Galaxy S1, Galaxy Tab 7", Galaxy S2, Galaxy Note, Galaxy Nexus, Galaxy S3, and many more) and has clocked over 16 million downloads. This is not even counting custom ROMs that already include it. Don't be a leech, buy me a beer (and use the "Thanks" button!). Imagine if every CF-Root user has donated me $1...
What's installed
- SuperSU binary and APK
- Stock recovery
Installation and usage
Flash the CF-Auto-Root package as PDA in ODIN (details on how to do that are in next post), and your device should reboot into a modified recovery (signified by a large red Android logo) and it will install SuperSU for you and restore the stock recovery, and reboot back into Android.
If you don't get to the red Android logo, boot into recovery manually ("adb reboot recovery", or boot while holding Power+VolUp+Home).
Did you see the red Android logo during rooting, but SuperSU does not appear? This may sometimes occur due to left-over files and settings, however, you can usually install SuperSU from Google Play at this stage and it'll just work.
Flash counters and KNOX warranty
Using this root method sets current binary and system status to custom. Additionally, it will also trigger the KNOX warranty void status.
This device store the traditional flash counter. Nor is is possible with Triangle Away to reset the current binary status. You will need to flash a stock kernel and stock recovery to reset the binary status.
The KNOX warranty status change is permanent, and a service center may deny warranty based on this flag - even if the other flags are reset correctly. The KNOX flag being tripped may also prevent certain Samsung KNOX features from working (enterprise security features). If this is something you care about, use a root method not based on custom kernels or recoveries, like a modified system partition. These are possible, but I don't personally make them, so look around!
Why isn't this just called CF-Root
The traditional CF-Root's included a custom recovery (CWM, TWRP, etc) and were meant for devices that had a single kernel/recovery combination. CF-Auto-Root doesn't include a custom recovery and is meant for devices that have kernel and recovery separate (so you can manually install any custom recovery you wish). The Auto part comes from the fact that a large part of the process is automated (though it constantly needs adjusting)
Not included - Triangle Away
Unfortunately, Triangle Away cannot currently be used on this device to reset the binary status or KNOX warranty void. It can still usually reset the system status, but that is of limited use.
Not included - adbd Insecure TODO: STILL UNDER DEVELOPMENT. Hopefully I'll get this to work soon.
As this CF-Root does not include a custom kernel, adb shell does not have root access by default (you can still get it by typing su inside the shell), nor is adb remount supported, nor will adb push and adb pull work on system files. adbd Insecure can be used to remedy this situation. (No idea what this is about ? Don't worry about it !)
CF-Auto-Root homepage
http://autoroot.chainfire.eu/
CF-Auto-Root main thread
[CENTRAL] CF-Auto-Root
For requests for new roots and generic discussion - please keep device specific discussion in the thread you are viewing now.

Follow these instructions to the letter. Do not touch any buttons or checkboxes that are not listed below to touch!
- Download and unzip the CF-Auto-Root-....zip file (see posts below this one)
- If you end up with a recovery.img and cache.img file, you've extracted twice. You need to end up with a .tar.md5 file - don't extract that one
- (USB) Disconnect your phone from your computer
- Start Odin3-vX.X.exe
- Click the PDA button, and select CF-Auto-Root-....tar.md5
- Put your phone in download mode (turn off phone, then hold VolDown+Home+Power to boot - if it asks you to press a button to continue, press the listed button, or run adb reboot download command)
- (USB) Connect the phone to your computer
- Make sure Repartition is NOT checked
- Click the Start button
- Wait for Android to boot
- Done (if it took you more than 30 seconds, you need practise!)
NOTE: Sometimes the device does *not* boot into recovery mode and root your device. Just do the entire procedure again if this happens. If it still will not install root and such, make sure that in Odin "Auto Reboot" is not checked. Then after flashing, pull the battery, and boot with VolUp+Home+Power button to boot into recovery manually. This will start the install process.
New to Samsung? Unfamiliar with Odin? Think all the above is a hassle? Get used to it. It's very simple, and us Samsung folk use Odin (or Mobile ODIN ) for everything! It's so very very convenient once you get used to it. Notice the 30 second comment above? For experienced users, the entire process indeed takes only 30 seconds!
You may now optionally want to install and run Triangle Away to reset the flash counter.

Download
SM-N900 (International Exynos): CF-Auto-Root-ha3g-ha3gxx-smn900.zip
SM-N9005 (International Qualcomm): CF-Auto-Root-hlte-hltexx-smn9005.zip
(only works on 4.4 bootloaders, if you're still on 4.3 use the old version which you can find here: http://d-h.st/J32)
SM-N900T (T-Mobile US): CF-Auto-Root-hltetmo-hltetmo-smn900t.zip
SM-N900P (Sprint): CF-Auto-Root-hltespr-hltespr-smn900p.zip
SM-N900R4 (US Cellular): CF-Auto-Root-hlteusc-hlteusc-smn900r4.zip
SM-N900W8 (Canadia): CF-Auto-Root-hltecan-hlteub-smn900w8.zip
SM-N900S (Korea): CF-Auto-Root-hlteskt-hlteskt-smn900s.zip
SM-N9002 (China): CF-Auto-Root-hlte-h3gduoszn-smn9002.zip
SM-N9006 (China): CF-Auto-Root-hlte-h3gzc-smn9006.zip
SM-N9008 (China): CF-Auto-Root-hlte-h3gzm-smn9008.zip
SM-N9009 (China, untested): CF-Auto-Root-hlte-h3gduosctc-smn9009.zip
Untested versions: please let me know if they work!
Other models
T-Mobile US thread: http://forum.xda-developers.com/showthread.php?t=2467369
Sprint thread: http://forum.xda-developers.com/showthread.php?t=2469904
CF-Auto-Root is not yet available for all carrier-specific Note3's. Link me to stock firmwares for these devices as they appear, and I might be able to make a device-specific CF-Auto-Root.

What is happening Chainfire? The dev are working on some solution for the knox efuse? I am thinking about a software which can restore that flag or a software which skips triggering while rooting.. for this you guys need to sign the modified stuff which is hard. How you see the things at the moment? This is the only thing what is holding me back to buy the note 3 at the moment...

wooohooo... finally.. waiting for SM-n900 version

Waiting your great work for the Exynos model as well...
You asked for a stock firmware link here is one for N900 model: http://www.hotfile.com/dl/247435453/e638485/N900XXUBMI5_N900OJVBMI1_XFU.zip.html
Actually I need for N9000Q model but on Sammobile there were just N900 model, i hope those are same since both of them are for the same device (Exynos).

waiting sm-n9000Q root

Here is some mirrors for N900 stock firmware:
https://disk.yandex.ru/public/?hash=6S6f3t8/YXndZY264OWRBWExcagIsZ3qpLlgSQchtXE=
http://uploaded.net/file/heepon2s
http://hotfile.com/dl/248328141/19b7fd7/SER-N900XXUBMI5-20131001102120.zip.html

Many thanks man ????
Sent from my SM-N9005 using XDA Premium 4 mobile app

Thanks Chainfire, just in time for my N9005 arriving from Vodafone tomorrow

I hope someone could find a solution to reset Knox counter. I need root but also my warranty
Inviato dal mio SM-N9005 con Tapatalk 4

mouse100 said:
I hope someone could find a solution to reset Knox counter. I need root but also my warranty
Inviato dal mio SM-N9005 con Tapatalk 4
Click to expand...
Click to collapse
I was gonna hold off from rooting, but then just thought to myself, any time my previous Samsung phones have had a fault, like with the charging port, or head phone socket, I've just bought the part from eBay and fixed it myself. The only time it's gone back to Samsung was when my Note 2 had the sleep of death.
In which case, they would not be able to tell anything from it as the emmc screwed itself over. In light of this I probably will root it now the big guy @Chainfire has done his magic.
I'm currently still waiting for a response from Samsung about whether warranty on the hardware would still be void if the Knox counter read anything other than 0x0.
Sent from my SM-N9005 using Tapatalk 4

RavenY2K3 said:
I was gonna hold off from rooting, but then just thought to myself, any time my previous Samsung phones have had a fault, like with the charging port, or head phone socket, I've just bought the part from eBay and fixed it myself. The only time it's gone back to Samsung was when my Note 2 had the sleep of death.
In which case, they would not be able to tell anything from it as the emmc screwed itself over. In light of this I probably will root it now the big guy @Chainfire has done his magic.
I'm currently still waiting for a response from Samsung about whether warranty on the hardware would still be void if the Knox counter read anything other than 0x0.
Sent from my SM-N9005 using Tapatalk 4
Click to expand...
Click to collapse
No everyone is able to repair their own smartphone with hw parts, like you however please post samsung answer about warranty if Knox counter is voided. I think it's important for everyone to understand their policy about this.
Galaxy Note 3 | SM-9005 | Tapatalk

mouse100 said:
No everyone is able to repair their own smartphone with hw parts, like you however please post samsung answer about warranty if Knox counter is voided. I think it's important for everyone to understand their policy about this.
Galaxy Note 3 | SM-9005 | Tapatalk
Click to expand...
Click to collapse
Lol, it honestly isn't difficult in the slightest. Think of it as a jigsaw puzzle. Samsung's are one of the easiest manufacturer of devices to repair. "If" Sammy are so kind to respond to me, I'll be posting the reply as soon as it comes through.
Sent from my SM-N9005 using Tapatalk 4

RavenY2K3 said:
I was gonna hold off from rooting, but then just thought to myself, any time my previous Samsung phones have had a fault, like with the charging port, or head phone socket, I've just bought the part from eBay and fixed it myself. The only time it's gone back to Samsung was when my Note 2 had the sleep of death.
In which case, they would not be able to tell anything from it as the emmc screwed itself over. In light of this I probably will root it now the big guy @Chainfire has done his magic.
I'm currently still waiting for a response from Samsung about whether warranty on the hardware would still be void if the Knox counter read anything other than 0x0.
Sent from my SM-N9005 using Tapatalk 4
Click to expand...
Click to collapse
For me warranty still important. Because last time i use galaxy note 1, while change rom from cm10 to miui my note bricked. Then samsung replace my board to new one without pay anything
Sent from my SM-N900 using xda premium

monyozt said:
For me warranty still important. Because last time i use galaxy note 1, while change rom from cm10 to miui my note bricked. Then samsung replace my board to new one without pay anything
Sent from my SM-N900 using xda premium
Click to expand...
Click to collapse
That's what my point is about, sort of, if you brick your phone to the point where you get absolutely no output whatsoever, they wouldn't be able to tell what had happened anyway, and would have to change it.
Sent from my SM-N9005 using Tapatalk 4

Will this method work with my phone
Model SM -N9005
Baseband - N9005XXUBMI6
Build - JSS15J.N9005XXUBMI7
I got the phone through Vodafone and i believe it has thier own firmware on there as it had Vodafone bundled apps on it.
And can i just check all this about KNOX warranty... It doesnt stop the phone working in anyway at all..... all it does it void the warranty? can i still use KNOX?
Thanks Guys

Amazing thank u so much waitin for n900 version
Sent from my SM-N900 using Tapatalk 4

DTMHibbert10 said:
Will this method work with my phone
Model SM -N9005
Baseband - N9005XXUBMI6
Build - JSS15J.N9005XXUBMI7
I got the phone through Vodafone and i believe it has thier own firmware on there as it had Vodafone bundled apps on it.
And can i just check all this about KNOX warranty... It doesnt stop the phone working in anyway at all..... all it does it void the warranty? can i still use KNOX?
Thanks Guys
Click to expand...
Click to collapse
No, if you root you can also not use Knox anymore. May be never!

Thanks Dude! waiting for SM-n900 version
Envoyé avec Gnote 3 SM-N 900

Related

[Q] [I9000]Warranty even if once rooted

Hello fellow XDA user
I have recently bought a the I9100 internation version and I am really pleased, however I do know the power of a ROM and how much it could improve or brick your phone.
However I came from the Galaxy S i9000, I never managed to recover the phone, so it would be recognized by kies, it did recognize my phone, but it said that 'Kies didn't support any upgrades for it'. Meaning if I would like to return it for garantee reasons, the shop or manufacturer will see I have been messing with my phone, which excludes my warranty.
Therefore I wonderd if there was a possibility to install roms or root your phone and unroot it, so kies would regonize it again.
Thanks alot and feel free to suggest any rom
Intensity007 said:
Hello fellow XDA user
I have recently bought a the I9100 internation version and I am really pleased, however I do know the power of a ROM and how much it could improve or brick your phone.
However I came from the Galaxy S i9000, I never managed to recover the phone, so it would be recognized by kies, it did recognize my phone, but it said that 'Kies didn't support any upgrades for it'. Meaning if I would like to return it for garantee reasons, the shop or manufacturer will see I have been messing with my phone, which excludes my warranty.
Therefore I wonderd if there was a possibility to install roms or root your phone and unroot it, so kies would regonize it again.
Thanks alot and feel free to suggest any rom
Click to expand...
Click to collapse
yes there is a way cfroot to which will give you superuser access and also CWM recovery by then swapping back to stock kernel will unroot also if you using odin to flash this wil increase binary counter look for a app called triangle away this will reset the binary counter but only works on ics.
this is just basics to answer quickly your question please still search within the sgs2 forum sections most of all new users questions have been answered and there is many guides for new users to refer to in development sections prior to installing customs roms etc
DJBoxer said:
yes there is a way cfroot to which will give you superuser access and also CWM recovery by then swapping back to stock kernel will unroot also if you using odin to flash this wil increase binary counter look for a app called triangle away this will reset the binary counter but only works on ics.
this is just basics to answer quickly your question please still search within the sgs2 forum sections most of all new users questions have been answered and there is many guides for new users to refer to in development sections prior to installing customs roms etc
Click to expand...
Click to collapse
I know about CF root .. but as I said before, I managed to restore the stock functionality of my Galaxy S, but I never managed to get support from Kies again. ('Kies doesn't support updates for your phone'). I don't know if the Galaxy S II method might diffrentiate from that .. but I do want to be on the safe side with my warranty and I don't want another bad to happen to my phone.
Quik Recap
1) Prepare Odin --> Go download Mode (Power + volume down + home button)
2) Flash Phone --> Odin --> Install CF Root Kernel
3) Mount Phone ---> USB --> Download Rom ---> Boot ClockWorkRecovery (Power + volume up + home button)
4) Enjoy Rom --> Enjoy Xda Power
5) How to Revert?, will kies regonize it and support it
Code:
[URL="http://forum.xda-developers.com/showpost.php?p=20075898&postcount="]CF Root Kernals By Chainfire[/URL]
Can someone please answer my post above, I really want to start modding, but I also want to be able to get back to an unrooted version with Kies support
Check out the links in my signature, especially the one about going back to stock. That should satisfy your request.
Long story short, reset your flash counter and flash stock rom. But make sure you READ
OK. The experience on here over the past 6 mths or so goes something like this. About 50% of people who go back to stock firmware for their region after using custom roms or stock firmware not for their region seem to be able to get OTA updates via Kies OK. For some reason(s), the other 50% or so of these people seem not to be able to get OTA updates to work despite flashing a full stock rom for their region (with correct CSC).
Why doesn't it seem to work for some people ? Who knows ? I don't think I've seen a single answer that could cover even a small majority of those cases.
Regardless, if you find you ever go back to stock with the intention of getting OTA firmware updates & they don't work, do what plenty of people on here do & flash them via Odin. Easy fixed.
The bottom line with warranties is this. The moment you start rooting your phone or flashing non-stock firmware on it, you should forget about/lose all expectations of warranty service/replacement should something go wrong with your phone. At the end of the day, you mess with your phone, why should Samsung/your telco foot the bill ?
Having said that, if you format everything, go back to stock & reset the flash counter, again, the experience on here is many people seem to get warranty service OK.
What you seem to be looking for is a 100% iron-clad guarantee.
There isn't any. If potentially borking your phone & having to pay to have it repaired/replaced yourself frightens you, best advice would be simply don't mess with it. Stay on stock. That's the only way you're getting 100% guarantees. If you've only ever been on stock/OTA updates & never rooted/flashed custom firmware and the phone borks, they pay to fix it.
Pretty simple really.

How the new GT-I9500 Binary Counter security works.

I am writing this to provide further understanding on how Samsung is preventing tools such as Triangle Away from tricking the Service Centers employees into thinking that your phone only ever ran Samsung approved binaries/roms.
This protection is enabled on newer Exynos based devices such as the GT-I9500, the Qualcomm chipset based devices seem to have been spared from it at the moment, most likely because the eMMC hardware is different.
The GT-I9500 bootloader is now setting the /sys/block/mmcblk0boot0/ro_lock_until_next_power_on flag at boot.
This is an eMMC feature that effectively locks the partition to read only until the eMMC hardware is restarted (basically until you reboot your phone)
While the /sys/block/mmcblk0boot0/ro_lock_until_next_power_on is software triggered, the lock itself is enforced by the eMMC hardware, once it is set, there is no getting around it.
Because this is set in the bootloader long before a kernel starts, and therefore long before we get to run our own code, and that the partition is locked by the eMMC hardware afterward, the only way to write the counter back is to do it at the bootloader level before the flag gets set, this means either exploiting the bootloader or replacing it by an older (engineering) version that would not set that particular flag (however an older bootloader may not support future components of the phone as they get replaced in the future, such as a newer OLED panel for instance)
Seems like a lot of trouble just to be keeping a warranty intact.
I hope this post shed some more light on the matter, this may also give you an idea of what awaits in the future in terms of security on future handsets.
mathieulh said:
I am writing this to provide further understanding on how Samsung is preventing tools such as Triangle Away from tricking the Service Centers employees into thinking that your phone only ever ran Samsung approved binaries/roms.
This protection is enabled on newer Exynos based devices such as the GT-I9500, the Qualcomm chipset based devices seem to have been spared from it at the moment, most likely because the eMMC hardware is different.
The GT-I9500 bootloader is now setting the /sys/block/mmcblk0boot0/ro_lock_until_next_power_on flag at boot.
This is an eMMC feature that effectively locks the partition to read only until the eMMC hardware is restarted (basically until you reboot your phone)
While the /sys/block/mmcblk0boot0/ro_lock_until_next_power_on is software triggered, the lock itself is enforced by the eMMC hardware, once it is set, there is no getting around it.
Because this is set in the bootloader long before a kernel starts, and therefore long before we get to run our own code, and that the partition is locked by the eMMC hardware afterward, the only way to write the counter back is to do it at the bootloader level before the flag gets set, this means either exploiting the bootloader or replacing it by an older (engineering) version that would not set that particular flag (however an older bootloader may not support future components of the phone as they get replaced in the future, such as a newer OLED panel for instance)
Seems like a lot of trouble just to be keeping a warranty intact.
I hope this post shed some more light on the matter, this may also give you an idea of what awaits in the future in terms of security on future handsets.
Click to expand...
Click to collapse
So are you saying there is no way that we can reset the counter going forward or are you saying That one of our Smart XDA Developers are going to crack it ?
matrix.bharath said:
So are you saying there is no way that we can reset the counter going forward or are you saying That one of our Smart XDA Developers are going to crack it ?
Click to expand...
Click to collapse
Nah, i saw too many complicated things get Cracked,Hacked... Moded... its only a matter of time
basicly a bootloader exploit is a solution but on the other hand its always too risky to flash them as not every I9500 is 100% identical to another some behave in a good way other make trouble depends on the chip.
still the best solution is to disable that mechanism protection so that the counter is never set. in one way you won't mind any custom ROM installation and you can be happy counter doesn't raise up the one thing is the users which are already running custom and have a binary lock these can't do a thing for now, the only issue here is the SU being place on the system partition triggers is, and basicly any app such as TriangleAway requires it so even if you think to restore stock and it works you can't reset counter since it needs root --> and again LOCK.
I wouldn't worry about it ...
> still the best solution is to disable that mechanism protection so that the counter is never set. in one way you won't mind any custom ROM installation and you can be happy counter doesn't raise up the one thing is the users which are already running custom and have a binary lock these can't do a thing for now, the only issue here is the SU being place on the system partition triggers is, and basicly any app such as TriangleAway requires it so even if you think to restore stock and it works you can't reset counter since it needs root --> and again LOCK.
well, not really correct. you can temproot system, using some android exploit.
you install stock after using triangleaway on rooted rom = counter is 0
if you temproot wthout kernel flash - counter is 0
So if I'm reading this correctly, there is no way at this stage to reset counter.
I have a faulty i9500 that I need to send back under warranty but I have flashed a custom ROM.
Does this mean I have a brand new S4 that is useless & no way to fix it?
KTM690 said:
So if I'm reading this correctly, there is no way at this stage to reset counter.
I have a faulty i9500 that I need to send back under warranty but I have flashed a custom ROM.
Does this mean I have a brand new S4 that is useless & no way to fix it?
Click to expand...
Click to collapse
Read post #4 ...
Sent from my GT-I9500
Gillion said:
Read post #4 ...
Sent from my GT-I9500
Click to expand...
Click to collapse
I did, but not sure what Chainfire meant by "I wouldn't worry about it ..."
Hopefully he means he will have a fix shortly
Hope, ChainFire could resolve :fingers-crossed:
KTM690 said:
I did, but not sure what Chainfire meant by "I wouldn't worry about it ..."
Hopefully he means he will have a fix shortly
Click to expand...
Click to collapse
If he said we don't need to worry everything is under control
Chainfire said:
I wouldn't worry about it ...
Click to expand...
Click to collapse
Please break the suspense .. is there a way ?
actually, i've posted similar article sometime ago:
http://forum.xda-developers.com/showthread.php?t=2290238
But since i've asked for workaround, moderators threw away my thread to Q/A section and made that topic orphaned >8-E
Engineering bootloader works fine and allows to write to boot block and reset the counter.
Not sure what Chainfire means. Is there a way to cycle power on eMMC to reset the flag? Otherwise, only engineering bootloader will allow to reset counter and flags.
I've got the feeling. This is the last ever Samsung phone I've bought I will happily move to other manufacturer now. No reason to love Samsung phones now. HUGE DISAPPOINTMENT.. Spent like $800 for this device and it has very very less REAL DEVELOPMENT ROOM.. No sources, crap architecture engineering, unfinished ROMS.. Nothing is good..
hardware is damn good but Samsung failed it
Rahulrulez said:
I've got the feeling. This is the last ever Samsung phone I've bought I will happily move to other manufacturer now. No reason to love Samsung phones now. HUGE DISAPPOINTMENT.. Spent like $800 for this device and it has very very less REAL DEVELOPMENT ROOM.. No sources, crap architecture engineering, unfinished ROMS.. Nothing is good..
hardware is damn good but Samsung failed it
Click to expand...
Click to collapse
To be honest, the same things happen on the htc one, if you want to unlock its bootloader, you forfeit its warranty. Nothing new here.
Sent from my GT-I9505 using xda premium
sorg said:
actually, i've posted similar article sometime ago:
http://forum.xda-developers.com/showthread.php?t=2290238
But since i've asked for workaround, moderators threw away my thread to Q/A section and made that topic orphaned >8-E
Engineering bootloader works fine and allows to write to boot block and reset the counter.
Not sure what Chainfire means. Is there a way to cycle power on eMMC to reset the flag? Otherwise, only engineering bootloader will allow to reset counter and flags.
Click to expand...
Click to collapse
Oh ! I never saw that thread before. I was just wondering back then why TA wouldn't work on the phone and started looking.
It's nice to see that someone else has researched this issue
To be quite honest with you though, I use the GT-I9505 as my daily driver.
Sent from my GT-I9500 using xda premium
Honestly, i don't see a reason to always keep the counter at 0.
For the warranty purpose there is a way to revert everything back:
1) flash official firmware through Odin
2) flash custom recovery with accessible mmcblk0boot0.
3) backup whole mmcblk0boot0
4) flash engineering bootloader
6) in any hex editor: reset the counter and flags in mmcblk0boot0 dump.
7) in recovery: flash the mmcblk0boot0 with your zero-counter dump. Don't reboot yet!
8) in recovery: flash recovery partition with official recovery. Don't reboot yet!
9) perform the factory reset.
10) reboot.
Now you have innocent I9500 device
sorg said:
Honestly, i don't see a reason to always keep the counter at 0.
For the warranty purpose there is a way to revert everything back:
1) flash official firmware through Odin
2) flash custom recovery with accessible mmcblk0boot0.
3) backup whole mmcblk0boot0
4) flash engineering bootloader
6) in any hex editor: reset the counter and flags in mmcblk0boot0 dump.
7) in recovery: flash the mmcblk0boot0 with your zero-counter dump. Don't reboot yet!
8) in recovery: flash recovery partition with official recovery. Don't reboot yet!
9) perform the factory reset.
10) reboot.
Now you have innocent I9500 device
Click to expand...
Click to collapse
Wowww Great.. Can you Give us some detailed setup i or Ash will Probably make a Tutorial Video of it with the right info, for now its all thanks to you.. can you also provide links to the above Custom Recovery Files etc. that are needed to get the above working?
matrix.bharath said:
Wowww Great.. Can you Give us some detailed setup i or Ash will Probably make a Tutorial Video of it with the right info, for now its all thanks to you.. can you also provide links to the above Custom Recovery Files etc. that are needed to get the above working?
Click to expand...
Click to collapse
That's rough walk-through, using some quick-made kernel and perform most steps in command line through adb in shell. I believe there are some kernels with mmcblk0boot0 are floating around. It needs to be polished and easier to repeat for generic user. I'm sure someone will make more user-friendly guide with all necessary files.
sorg said:
Honestly, i don't see a reason to always keep the counter at 0.
For the warranty purpose there is a way to revert everything back:
1) flash official firmware through Odin
2) flash custom recovery with accessible mmcblk0boot0.
3) backup whole mmcblk0boot0
4) flash engineering bootloader
6) in any hex editor: reset the counter and flags in mmcblk0boot0 dump.
7) in recovery: flash the mmcblk0boot0 with your zero-counter dump. Don't reboot yet!
8) in recovery: flash recovery partition with official recovery. Don't reboot yet!
9) perform the factory reset.
10) reboot.
Now you have innocent I9500 device
Click to expand...
Click to collapse
Great work sorg.
Any chance of a noobs guide to this?
Bytheway, is it possible to flash bootloader(sboot.bin) on cwm recovery?
I've tried to include bl in rom zip
Sent from my SHV-E300S using XDA Premium HD app

[SM-G900*] CF-Auto-Root

Check your device model ! Settings -> About device -> Model number. See the third post for exact supported model numbers. If your device is a totally different model, it will not work (may even brick) !
CF-Root is the root for "rooting beginners" and those who want to keep as close to stock as possible. CF-Root is meant to be used in combination with stock Samsung firmwares, and be the quickest and easiest way for your first root.
Donate
CF-Root has been available for many devices (Galaxy S1, S2, S3, S4, Galaxy Note, Note2, Note3, dozens of Tab models, etc!) and has clocked over 22.5 million downloads. This is not even counting custom ROMs that already include it. Don't be a leech, buy me a beer (and use the "Thanks" button!). Imagine if every CF-Root user has donated me $1...
What's installed
- SuperSU binary and APK
- Stock recovery
Installation and usage
Flash the CF-Auto-Root package as PDA in ODIN (details on how to do that are in next post), and your device should reboot into a modified recovery (signified by a large red Android logo) and it will install SuperSU for you and restore the stock recovery, and reboot back into Android.
If you don't get to the red Android logo, boot into recovery manually ("adb reboot recovery", or boot while holding Power+VolUp+Home).
Using this root increases your flash counter and trips the KNOX warranty flag!
Did you see the red Android logo during rooting, but SuperSU does not appear? This may sometimes occur due to left-over files and settings, however, you can usually install SuperSU from Google Play at this stage and it'll just work.
CF-Auto-Root homepage
http://autoroot.chainfire.eu/
CF-Auto-Root main thread
[CENTRAL] CF-Auto-Root
For requests for new roots and generic discussion - please keep device specific discussion in the thread you are viewing now.
ODIN Installation (detailed)
Follow these instructions to the letter. Do not touch any buttons or checkboxes that are not listed below to touch!
- Download and unzip the CF-Auto-Root-....zip file (see posts below this one)
- If you end up with a recovery.img and cache.img file, you've extracted twice. You need to end up with a .tar.md5 file - don't extract that one
- (USB) Disconnect your phone from your computer
- Start Odin3-vX.X.exe
- Click the PDA button, and select CF-Auto-Root-....tar.md5
- Put your phone in download mode (turn off phone, then hold VolDown+Home+Power to boot - if it asks you to press a button to continue, press the listed button, or run adb reboot download command)
- (USB) Connect the phone to your computer
- Make sure Repartition is NOT checked
- Click the Start button
- Wait for Android to boot
- Done (if it took you more than 30 seconds, you need practise!)
NOTE: Sometimes the device does *not* boot into recovery mode and root your device. Just do the entire procedure again if this happens. If it still will not install root and such, make sure that in Odin "Auto Reboot" is not checked. Then after flashing, pull the battery, and boot with VolUp+Home+Power button to boot into recovery manually. This will start the install process.
New to Samsung? Unfamiliar with Odin? Think all the above is a hassle? Get used to it. It's very simple, and us Samsung folk use Odin (or Mobile ODIN ) for everything! It's so very very convenient once you get used to it. Notice the 30 second comment above? For experienced users, the entire process indeed takes only 30 seconds!
Download
SM-G900F (International Qualcomm): CF-Auto-Root-klte-kltexx-smg900f.zip
SM-G900H (International Exynos): CF-Auto-Root-k3g-k3gxx-smg900h.zip
SM-G900I (Oceania?): CF-Auto-Root-klte-kltedv-smg900i.zip
SM-G900L (Korea): CF-Auto-Root-kltelgt-kltelgt-smg900l.zip
SM-G900M (Middle and South America?): CF-Auto-Root-klte-klteub-smg900m.zip
SM-G900R4 (US Cellular): CF-Auto-Root-klteusc-klteusc-smg900r4.zip
SM-G900T (T-Mobile US): CF-Auto-Root-kltetmo-kltetmo-smg900t.zip
SM-G900P (Sprint): CF-Auto-Root-kltespr-kltespr-smg900p.zip
SM-G900T1 (Metro PCS): CF-Auto-Root-kltemetropcs-kltemetropcs-smg900t1.zip
SM-G900W8 (Canada): CF-Auto-Root-kltecan-kltevl-smg900w8.zip
SM-G900S (Korea?): CF-Auto-Root-klteskt-klteskt-smg900s.zip
SM-G901F: http://download.chainfire.eu/481/CF-Root/CF-Auto-Root/CF-Auto-Root-kccat6-kccat6xx-smg901f.zip
SM-G906K: http://download.chainfire.eu/539/CF...to-Root-lentisltektt-lentisltektt-smg906k.zip
SM-G906L: http://download.chainfire.eu/540/CF...to-Root-lentisltelgt-lentisltelgt-smg906l.zip
SM-G906S: http://download.chainfire.eu/541/CF...to-Root-lentislteskt-lentislteskt-smg906s.zip
Other models
CF-Auto-Root is not yet available for all models - one stock firmwares for these models become available, let me know, and I'll make the corresponding CF-Auto-Roots. Make sure to check the main CF-Auto-Root site as well, as models may be listed there that are not listed here.
Proudly the 1st one to be rooted after your release CF
Sent from my SM-G900F using Tapatalk
bravo!
this root files g9006v can't working//
Now I will surely buy S5.
Thanks to Chainfire!
Great Job.
you beast, bravo!
I love you Chainfire! You are amazing. Definitely the first method I go to when rooting a device that your tool supports. I hope the AT&T S5 isn't super locked down.
Kudos yet again chainfire. Simply my go to dev for everything root.
Sent from my SGH-I337M using Tapatalk
you gotta be kidding,,
you rooted S5
this device isn't available on my country yet
Oh, wow!
And you did it again!
You rock, man!
Now i will buy the Galaxy S5.
Thank you, for your great work!
Sent from my HTC One (M7) with Tapatalk App
Hello my [now celebrity] friend, been a long time. Congratulations for this latest development!
@Chainfire you seriously make me wet (and im a guy..) every time i see your name come up on XDA. Your genius has no boundaries Rock on dude! Never stop being awesome!!
Cool beans :good:
S5 here I come.
Xda should implement a "Most Influential Member" award. Without @Chainfire most devices wouldn't have any lifespan longer than the next upgrade.
Chainfire = beast! Pure genius! Chainfire just gave me another reason to buy the S5. Big ups!
Chainfire said:
Check your device model ! Settings -> About device -> Model number. See the third post for exact supported model numbers. If your device is a totally different model, it will not work (may even brick) !
CF-Root is the root for "rooting beginners" and those who want to keep as close to stock as possible. CF-Root is meant to be used in combination with stock Samsung firmwares, and be the quickest and easiest way for your first root.
Donate
CF-Root has been available for many devices (Galaxy S1, Galaxy S2, S4, S4, Galaxy Note, Note2, Note3, dozens of Tab models, etc!) and has clocked over 22.5 million downloads. This is not even counting custom ROMs that already include it. Don't be a leech, buy me a beer (and use the "Thanks" button!). Imagine if every CF-Root user has donated me $1...
What's installed
- SuperSU binary and APK
- Stock recovery
Installation and usage
Flash the CF-Auto-Root package as PDA in ODIN (details on how to do that are in next post), and your device should reboot into a modified recovery (signified by a large red Android logo) and it will install SuperSU for you and restore the stock recovery, and reboot back into Android.
If you don't get to the red Android logo, boot into recovery manually ("adb reboot recovery", or boot while holding Power+VolUp+Home).
Using this root increases your flash counter and trips the KNOX warranty flag!
Did you see the red Android logo during rooting, but SuperSU does not appear? This may sometimes occur due to left-over files and settings, however, you can usually install SuperSU from Google Play at this stage and it'll just work.
CF-Auto-Root homepage
http://autoroot.chainfire.eu/
CF-Auto-Root main thread
[CENTRAL] CF-Auto-Root
For requests for new roots and generic discussion - please keep device specific discussion in the thread you are viewing now.
Click to expand...
Click to collapse
Rockstar
:highfive:​
Awesome...

Root I605VRUFND7 4.4.2 by CF-Root

hi everyone
this is my first post in these web
a new massage yesterday showed from chinfire
A whole bunch of devices' CF-Auto-Roots have been updated from older firmware bases to 4.4.x firmware bases. Means these CFAR's work again on the latest bootloaders, primarily.
A large number of devices have been added as well. Together these total well over one hundred updates.
I've also made some small changes to the page, like adding base firmware version information and MD5s.
i find a new root phones and my verizone note 2 .I605VRUFND7 4.4.2
i hope that help us
you can download the root from the web site autorootcom
download it to your phone by odin
best regards
Root file Zip in attachment
Instructions
Extract (unzip) the root file
Open Odin
Reboot phone in Download Mode (press and hold Home + Power + Volume Down buttons)
Connect phone and wait until you get a blue sign in Odin
Add the root file to AP / PDA
Click the start button, sit back and wait
Mohammed Aledreesi said:
Root file Zip in attachment
Instructions
Extract (unzip) the root file
Open Odin
Reboot phone in Download Mode (press and hold Home + Power + Volume Down buttons)
Connect phone and wait until you get a blue sign in Odin
Add the root file to AP / PDA
Click the start button, sit back and wait
Click to expand...
Click to collapse
Will this unlock the bootloader?
Mohammed Aledreesi said:
Root file Zip in attachment
Instructions
Extract (unzip) the root file
Open Odin
Reboot phone in Download Mode (press and hold Home + Power + Volume Down buttons)
Connect phone and wait until you get a blue sign in Odin
Add the root file to AP / PDA
Click the start button, sit back and wait
Click to expand...
Click to collapse
@Mohammed Aledreesi
Can you confirm that you have successfully used this root method on a stock Verizon SCH-I605 running 4.4.2 ND7?
I looked at Chainfire's website HERE, and there are a couple of warnings that I thought should be noted....
"UNLOCK BOOTLOADERS
If you have locked bootloaders, flashing one of these will probably brick your device - with the exception of Nexus devices, which will usually automatically "OEM unlock" and wipe your data !"
"KNOX WARRANTY
If you have a KNOX-enabled device, using CF-Auto-Root will trip the KNOX WARRANTY VOID status !"
I figured since im looking for a Note 4 soon I had nothing to lose and gave it a try and it failed to even try and work. I ended up going back and redoing my phone and cleaning things up and using ghettoroot. So I couldn't do anything, maybe others have had success I wouldn't waste my time at this point with this.
Matttrix said:
I figured since im looking for a Note 4 soon I had nothing to lose and gave it a try and it failed to even try and work. I ended up going back and redoing my phone and cleaning things up and using ghettoroot. So I couldn't do anything, maybe others have had success I wouldn't waste my time at this point with this.
Click to expand...
Click to collapse
That's cool that you tried this and thanks for letting others know how it turned out. Too bad it didn't work, but good it didn't brick your phone. Do you know if it tripped your Knox status? It will be interesting to see if the OP provides any further clarification on his experience with this.
mattnmag said:
That's cool that you tried this and thanks for letting others know how it turned out. Too bad it didn't work, but good it didn't brick your phone. Do you know if it tripped your Knox status? It will be interesting to see if the OP provides any further clarification on his experience with this.
Click to expand...
Click to collapse
My knox status was already tripped and my phone is already out of warranty anyways from testing some other stuff a couple weeks ago. So it didn't really matter to me. I was able to boot back into the phone as if nothing happened after it failed from Odin on the CF Root, I just wanted to redo things as the newer updates for Ghettoroot seem to be a bit more stable in setup. As I still had the original and still had some force close issues but now things are smooth and everything is working 10000%.
Unfortunately, it doesn't work!
So Ghettoroot is working on 4.4.2 with ND7 baseband? I've visited that thread several times and it seems some have root with 4.4.2 update and some don't. Leaves it unclear to my mind.
AA far as I can tell, neither Chainfire or Adam Outler have working roots for this new update.
Sent from my Galaxy Note 2 using Tapatalk
jtsmall said:
So Ghettoroot is working on 4.4.2 with ND7 baseband? I've visited that thread several times and it seems some have root with 4.4.2 update and some don't. Leaves it unclear to my mind.
AA far as I can tell, neither Chainfire or Adam Outler have working roots for this new update.
Sent from my Galaxy Note 2 using Tapatalk
Click to expand...
Click to collapse
Just wanted to confirm that ghettoroot for indeed work
Thanks. I surely be elated with root once again. Last smartphone rooted was Droid OG. Too long!
Sent from my Galaxy Note 2 using Tapatalk
Update 11/9/14. I used the 15 Seconds ADB Installer rather than the full SDK. ADB devices cmd revealed the Note 2 finally, but unauthorized. Following a simple uncheck of USB debug followed by a recheck then authorization was immediate. I then used GhettoRoot, a one click version of TowelRoot.
Root with no hiccups a day later. Root enabled apps like Root Explorer and Titanium Backup working as is BusyBox. Android 4.4.2 baseband ND7 (Verizon).

[ROM][STOCK][SGH-I527M] Rooted Stock 4.4.2 I527MVLUCNE5 Kitkat Firmware

Lately people have been reporting issues with not being able to restore to 4.4.2 due to Samsung not releasing a stock firmware file. This can be a problem if you tried to downgrade to 4.2.2 and have issues like no sound, no IMEI/baseband, no WiFi. Time to fix that!
Here is a prerooted stock image for the SGH-I527M, made and tested by me. It's based on the latest 4.4.2 NE5 firmware (build KOT49H.I527MVLUCNE5) and is Odin-flashable.
DO NOT FLASH IF YOUR DEVICE IS NOT THE CANADIAN SGH-I527M
It contains the following components from build NE5:
-System (Rooted w/ SuperSu installed)
-Kernel
-Modem
-TZ (Trust Zone)
Steps if coming from a non-Samsung ROM (CM):
-Wipe /data and /cache from recovery (factory reset)
-Reboot into download mode
-Flash with Odin
-Wait AT LEAST 3min, first boot will take a while
-Done!
This package does *not* include any bootloaders, so it will not install Knox. However, if Knox is already present it will trip the warranty flag. Since it is prerooted, you will see the message "Set warranty bit: system" and it will set Knox Warranty Void to 0x1.
Note: If you are still on the 4.2.2 non-Knox bootloader, the ROM will work but you will not be able to charge the phone while off. Updating to the latest bootloader (aka Knox) is currently required for that function. Without it, your phone will turn on when plugged in, instead of showing a charging animation. All other functionality will work fine.
If you would like to update to the latest bootloader (Knox included), here is a link:
BL_I527MVLUCNE5_REV00_user_low_private_NO_CERT.tar.md5
Now, I've never asked for donations before, but a couple weeks ago my house was broken into, and my main PC, laptop, along with a bunch of other stuff, was stolen. I'd appreciate any donations that may come my way to soften the loss:
My PayPal:
Regardless, and without further ado, here is the link for the download:
ROOT_KOT49H.I527MVLUCNE5.tar.md5
Enjoy!
Not working for me
-Wipe /data and /cache from recovery (factory reset)->done
-Reboot into download mode->done
-Flash with Odin 3.09
AP->checked with file
auto reboot -> unchecked to be able to wait for 3min
"Set warranty bit: system" and it will set Knox Warranty Void to 0x1. ->yes it did
result : keeps rebooting
Keep in mind riginal problem comes from a repaired screen that trigger a Samsung update... I am gonna keep trying those solutions and YES! I'll be happy to donate to get my Canadian Samsung galaxy Mega SGH-1527M Back...
Your issue is likely due to a non-genuine screen replacement rather than a software issue. The 4.4.2 update will not allow any third-party digitizers to work. Make sure your touchscreen ribbon cable has a genuine Synaptics controller.
This sounds like a good one to have. So my question is I'm using right now CM11 4.4.4 and it's a different kernel I am using for my phone. My phone is a I527M but it's using a American IME. So if I load your tomorrow here like you described will my phone be stocked again? And will it change my kernel without probs?
Sent from my GT-I9205 using XDA Premium 4 mobile app
That's correct.
Holy crap!!!!! It works!!!! I have been wanting to go on stock again for awhile now. Everything works perfectly. Thank you for this. Great job!
Sent from my SGH-I527M using XDA Premium 4 mobile app
My imei and baseband is unknown on 4.4.2
How to fix it guys?
I need nvm file of this model..
I527m nvm file...
Please help me
Dude you are so awesome. Thanks so much. My phone is dead for like 4 months and you really save my life. It's time to go back to mega. Really appreciate that
OK one problem here with this. Works good but when phone is powered off and charging the battery, it won't charge! Phone turns back on and you have to charge with the phone on. It's not right.
Sent from my SGH-I527M using XDA Premium 4 mobile app
Sounds like the new bootloader is required for the kernel to load from a charging state, then.
There is a link for that in the Q&A tab, if you are willing to upgrade to it, let me know if it fixes your issue and I will add it to the OP.
I will upgrade too it then. I'll wait for you to make the fix. Other than that it works great.
Sent from my SGH-I527M using XDA Premium 4 mobile app
Awesome, thanks for the fix for my Galaxy Mega that has been sitting in a ziplock for the past few months ))) WiFi and Data are back up again!
The new BOOTLOADER fixed the problem alright. The phone now charges when it's turned off! Everything works PERFECTLY now. Thank you!
@thebreezer Good to hear
@verticleman76 Thanks for confirming! I'll add that info to the OP.
Hi, may I ask that when installing this rom, is my phone unlocked ? Thanks
lehuutai130 said:
Hi, may I ask that when installing this rom, is my phone unlocked ? Thanks
Click to expand...
Click to collapse
If you mean carrier unlocked, NO, it wont
Thanks for this, the phone wifi and base band is back, but back to the original problem of touch screen not responding, The screen was replaced before the 4.4.2 update, is there any work around to make it usable again? is there any custom roms that i could try that will keep wifi and base band but have touch screen working?
Thanks for any reply hopeful to get this phone usable again
Yippee
You are my hero man. I've been trying to find a way to root this mega for days. Your firmware works perfectly, thank you!
Hi guyz! Im really eager to try this since my Mega is useless for months now. Problem is Odin only detects my device when its booted and not in download mode, anyone have this problem?
(EDIT) I've tried on another PC and it worked so im doing it right now I'll post the results.
So the results is : The phone boots with the new rom, i see in the top right corner that it now have a cell signal and all BUT no touchscreen at all so i cant even unlock and browse in it.
---------- Post added at 09:24 PM ---------- Previous post was at 08:45 PM ----------
Xyphir said:
Thanks for this, the phone wifi and base band is back, but back to the original problem of touch screen not responding, The screen was replaced before the 4.4.2 update, is there any work around to make it usable again? is there any custom roms that i could try that will keep wifi and base band but have touch screen working?
Thanks for any reply hopeful to get this phone usable again
Click to expand...
Click to collapse
Im in the same boat as you my friend. Right now it's either touchscreen but no sound and no wifi or everything but touchscreen hahaha
The quickest way to fix the no touch issue would be to order a genuine touchscreen. I am working on patching the kernel to fix this, but unfortunately it will probably take quite some time, as I've never modified system-level drivers, and I have exams and other priorities to attend to.
For anybody else that can contribute, the offending code is probably in synaptics_rmi4_i2c.c specifically fwu_start_reflash() function. The driver attempts to update the firmware, but fails to do so due to the IC not being made by Synaptics (in my case, following messages are generated):
Code:
fwu_check_skip_reflash:FW_version Bin:0x1A, FW_version IC:0x19
fwu_wait_for_idle: Timed out waiting for idle status
fwu_start_reflash: Failed to do reflash
...
synaptics_rmi4_query_device: Non-Synaptics device found, manufacturer ID = 14
...
synaptics_rmi4_i2c: probe of 3-0020 failed with error -110
I am guessing we can remove the firmware updater system so that no errors are generated. I don't want to risk forcing through the firmware update and bricking the already flaky Chinese TSP controllers on everybody's screens
It's possible that a firmware update is required for the TSP to work, but the code suggests otherwise as there are exceptions made for factory firmwares and old panel revisions. The only sure solution right now is to buy genuine parts.

Categories

Resources