Regarding Prophet - Flash process - Windows Mobile Development and Hacking General

Hi its me again.
I'm now in the process of developing a flash tool for the Prophet (s200).
Things i've noticed, is a change in protocol compared to the other phones.
Firstly it sends some of the initializing commands 1 byte at a time.
At some point it sends the command "ruustart". After that, all output from the phone stops. To me it seems like, after this step its up to the phone to keep up, you dont have any means of knowing if the phone got your message or not.
Well just thought i wanted to share this with you. If any of you have any questions regarding this phone, feel free to post in this thread.

If anyone is interested i've figured out the decryption of the header.

Related

Wizard Unlocking

http://forum.xda-developers.com/showthread.php?t=305225
I am trying to follow this tutorial but the links for the button rom and lokiwiz dont work can anyone link me one that works?
Thanks
read the 'read first' sticky in the wizard upgrading forum, everything is in there
That would be great advice if those links worked. But they don't work for me. Actually the problem I am having is identical to wind_sun's post in March. I will just copy and paste as I dont know if I could word it better. And it goes a lil something like this:
Dr. P:
I have been doing the unlocking SIM and CID for several rounds and no luck so far. So I am thinking that I would put up a message here for helps from you and others. Here is the related info:
tmobile USA MDA
IPL /SPL 2.26
GSM 02.25.11
OS 2.26.10.2
I downloaded CUSTOM__RUU_Wizard_1050412_WWE_101_11210_WWE and extracted into a folder and start the downgrade process by double click ROMUpdateUtility_Wizard_NoID since it is G3 with 2.XX ROM.
The verify screen reads:
From:
Model ID: WIZARD
Image Version: 1.2.0.0
Language: ENGLISH
To:
Model ID: Prodigy
Image version:
Language: WWE
Everything goes smooth until I get to 98% done. The tool complained:
ERROR[302]: UPDATE ERROR (My situation is different in the computer goes to 100% then states it has to close for some problem. It prompts me to send or don't send to Microsoft. The phone remains at 98%)
and ask me to recover by disconnecting usb cable and taking out battery, which I did.
After I put back battery, the MDA screen comes back with 3 color bootloader display. The screen still show IPL/SPL 2.26 version at this time. I did see USB on the left bottom of the screen when I reconnect USB cable.
Then follow the instruction to rerun the ROMUpdateUtility_Wizard_NoID on PC.
It errored out at the 98% AGAIN and shows me the SAME error messages.
Repeat the process and it always errored out at the same point with the same error message.
Of course I was able to rescue my MDA by reflashing it with the T-Mobile 2.26 ROM with no problem.
But I still want to downgrade so that I can unlock and upgrade. There was no reply to this thread by wind_sun. A lil help? Thanks in advance.
Babyexp said:
That would be great advice if those links worked. But they don't work for me.
Click to expand...
Click to collapse
I just checked this thread and all the links work
are you saying that you can't flash the button rom?
BBOBECKYJ,
Exactly. Exactly as stated above. I am having the same problem wind_sun had. Hangs at 98%. Thanks again.
Babyexp said:
Exactly. Exactly as stated above. I am having the same problem wind_sun had. Hangs at 98%. Thanks again.
Click to expand...
Click to collapse
I've not read the thread - i didn't need to, I followed the instructions exactly and it worked
I'm confused about what you're saying, firstly that the links to the roms didn't work, (so i gave you those links). Now it seems you are saying that the roms won't flash yet you also say you still can't download those same roms
i believe the guide i linked (not the one you were using) is foolproof, and if you follow each step exactly you can't go wrong.
also if you're having problems, you should post in that thread and not create a new thread - as it is monitored by the thread creator who may be able to help you.
I am having the same problem wind_sun had
Click to expand...
Click to collapse
so what was the response to that problem? (if any) does that not solve yours?
First, I apologize. I do not post often. The result is my forum etiquette is poor. This thread belonged to someone else. Initially, I was backing them up in stating that the first reply to this thread was incorrect and was not valid at the time of the posting. I knew this as I had tried those same links in the past 24 hours. My mistake was stating my problem in this thread in the same post obviously. That was poor mannered in hindsight. Second, being that I do not post to forums often I forget how excruciatingly detailed a post or thread has to be. Everyone is not always on my frequency. Even so, with matters of the technical sort, people probe and ask questions. In the future, I will try to do better.
Babyexp said:
First, I apologize. I do not post often. The result is my forum etiquette is poor. This thread belonged to someone else. Initially, I was backing them up in stating that the first reply to this thread was incorrect and was not valid at the time of the posting. I knew this as I had tried those same links in the past 24 hours. My mistake was stating my problem in this thread in the same post obviously. That was poor mannered in hindsight. Second, being that I do not post to forums often I forget how excruciatingly detailed a post or thread has to be. Everyone is not always on my frequency. Even so, with matters of the technical sort, people probe and ask questions. In the future, I will try to do better.
Click to expand...
Click to collapse
LOL i didn't notice that the third post - yours - was not the same person as post one, that explains my confusion
however, as he/she didn't post back again (yet) i assume that the link in my first post works, so try that if you have not yet done so
BBOBECKYJ,
I was only agreeing with THESCREENSAVERS about the ANTC thread. I took it light that if two people found the links to be broken ANTC might look into it. I was not clear in separating that from my own issue or that it was ANTC's advice/tutorial my initial post referenced. You are correct. I was stating ANTC's links did not work. Another great tutorial(minus links). I OBTAINED THE ROMS LAST NIGHT. After navigating through our excellent forums, for 24 hours I found the links for the tools mentioned in ANTC's thread in DR. PUTTINGHAM'S thread that you suggested. Thank you for that. I should have done that initially for THESCREENSAVERS instead of switching to my own frustrating issue. I tried to kill two birds(issues) with one sloppy hand grenade(post). Selfish me. What a mess it is that I have to apologize and clean up the mess I made with 3 more posts(and counting). Now my friend, I am so glad that DR. PUTTINGHAM'S tutorial worked well for you. The wording in your last post makes me less than a fool though or a fool that has proven DR. PUTTINGHAM'S post to not be foolproof. The ROMS DO NOT FLASH FOR ME. I have gone wrong. And wind_sun too. Which, by search is wind_sun's only post...nearly two months ago. But since we are here now. Again, I still want to downgrade so that I can unlock and upgrade. There was no reply to this thread by wind_sun. A lil help? Thanks in advance. CAN ANYONE HELP?
P.S. How did you follow the instructions if you did not read the thread?
No avatar, no gif's, no kewl one-liner...I'm so lame....
To answer your last question first, I used Faria's unlocking guide first. Dr P simplified and explained in more detail the same things in his thread. I read only the first post of the Dr P thread when I got stuck with the Faria one.
I am not aware that anyone would be unable to flash the button rom, (which is not to say it couldn't happen) and just to be very clear, you are using this guide?
Dr P thread is stickied, for amongst other reasons - I think he monitors it and helps anyone with questions. (ANTC is probably busy cooking another wm6 rom atm LOL)
ps try to break up your posts, it is hard reading very long blocks of text (and harder to reply to question within it)
pps don't apologize for posting - that's what forums exist for. it is annoying when it is obvious that someone has not read anything and then expects everything done for them, but you did read and had a go
I'd just like to add my 2 cents here if you don't mind
@ Babyexp
Have you tried downloading Button ROM again as it might be corrupted even though the download completed successfully? That's why some sites like Linux distros ftp have a file with the result of a checksum (SHA1,MD5,CRC32,etc...) so that users know the file isn't corrupted
The other option is to use another PC to see if the RUU crashes same way
cheers
Awesome posts. I feel like I got something accomplished. Then, I didn't. I'm back to WM5. Wish I could lift my chin a little like you guys with WM6....
Are you telling me about reading? I always seem to have the quirks/problems noone else has. I've been browsing the forums for the better part of two days! I'm squinting so much now I look Chinese! LOL. Thanks again. Can I get a link Mestrini?
Babyexp said:
Awesome posts. I feel like I got something accomplished. Then, I didn't. I'm back to WM5. Wish I could lift my chin a little like you guys with WM6....
Are you telling me about reading? I always seem to have the quirks/problems noone else has. I've been browsing the forums for the better part of two days! I'm squinting so much now I look Chinese! LOL. Thanks again. Can I get a link Mestrini?
Click to expand...
Click to collapse
It's past 3am here and my brain cells can't follow what the eyes send them, sorry please be more clear about the... zzzzzzzzzz... link and the reading parts
cheers
hi guys
I'll be quick - as babyexp says, we're not trying to hijack teh thread, but having multiple people with the same issue in one thread, then if someone comes to resolution, is a good thing, imo.
I've been also trying to upgrade an htc wizard to wm6. I've re-downloaded the latest files for button 1.05 (from rapidshare) and lokiwiz, and have been following ANTC's guide. In step 3, he says run button, and let it complete, but when I run it, it also progresses up to 98% on the Wizard and my laptop, then pauses. After 3-4 minutes, the laptop updates to 99%, leaving the Wizard at 98% (red progress bar on the wizard), and stops again. I've left it for about 30 minutes at this point, but now on my 4th try at flashing, it hasn't completed once yet.
After removing the battery, and restarting to the colorbanded screen, I've been able to reapply the tmobile rom (RUU_TMobile_US_226102_22610105_022511_WWE_Ship) to get the phone active again. However, attempting to put button on brings me to up to this 98% hang behavior
I've tried installing the wm6 rom directly on top of the tmobile one, which completes, but on restart, prompts for screen calibratrion, does customization, then is still running wm5 after the restart - even teh start/calibration screens look to be wm5. Strange behavior - my hermes upgraded with no issues, compared to this. Should I perhaps run lokiwiz first before button, and ensure that I run both a U(unlock) and C(Supercid unlock) ?
any pointers appreciated.
tks,
dwight.
dwightery said:
any pointers appreciated.
tks,
dwight.
Click to expand...
Click to collapse
yep, use the original unlocking guide, ANTCs is simplified i think. I linked it in my first post in this thread
ok thanks bbobeckyj - I'll give that a try on monday when i'm back in the office.
btw, "if at first you dont' succeed, try try again" isn't the best plan for these phones . I kept trying to reflash mine, and after about a dozen attempts, the battery died, and that was the end of that. ohh, i thought i had a brick there, as it wouldnt' charge via usb cable (i don't think).
I left it over night on a wall charger, and when i checked this am again, it was back to the colored bar screen, and I was able to put the tmobile base rom back on it. whew!
dwight.
Easy solution to ALLLL of these problems.
go to IMEI-CHECK .. pay the 40 dollars to unlock ur phone.. Update to WM6.. Easy.. Stop being cheap.

DX Bootloader encryption key idea

So I had an idea today...I'm sure the geniuses that have gotten the Dx and D2 this far have already tried it; but I cannot find any information on it. What if we tried the good old fashioned trick of cold booting:
Google princeton cold boot. I cannot paste links.
I am going to make my best efforts to try this, but I know there are many people that are far better than I. I will let you know of my results, if I ever achieve any.
I think this is an interesting idea, and have read a lot about this being done on laptops... would be interested to see if this works for the android system...
It would only work if the keys are stored in RAM tho... and I think the keys are hard coded into a chip (thought I heard this somewhere...could be 100% wrong)
Anyways...would be interested to see some of the devs try this...
No idea if this would work but if this could be pulled off it would be a pretty epic hack
This looks to rely on the ability to run custom OS/Software. Since our current hacks involve loading *after* the kernel, I doubt this would work.
Kinda like a chicken before the egg problem.
It requires custom rims on another host. Realistically all you need is for the princeton program to read the ram from a different partition. Im sure it can be modified to mount the phone and read the ram from there.
Kinda as an acknowledgement/off-shoot of what zaphod has said...
What if a second init process could be kicked off to hijack the boot process kinda like what koush did..
If the ram could be dumped quick enough... Would this work? I'm not a dev, but do a lot of sys admin work and understand many of the concepts for kernels, and boot processes...
Just trying to help throw out ideas and get the creative juices florin for those who can develop.
Ps, zaphod, thnx for all ur contributions on this forum, many of ur posts have helped me.a TON
Just Chiming In
That's kind of what unrevoked did:
I know we have completely different phones, but this is basically how they cracked HTC:
They found out that in the booting of the phone, during the init, adb would start, but then immediately get killed off by HTC's init. what they did then was found out that if they inserted an SD card into the phone at the precisely exact time (between when ADB started and got killed off by MOTO) so that it would be read right before ADB was killed by MOTO, it would hang MOTO's init, so they had full adb access during the init process, which allowed them to run the phones STOCK recovery alongside ADB. Firstly it allowed them to get root, then once they got root what they basicall did was kick off a LEGIT system update through the phones recovery and then SWAP it for a payload right in between when the phone finished the key checks and started writing the new system....
I know that we have two different things going on here.... but if they did this, I'm sure we could pull something like swapping kernels during load.....
MAN I wish Unrevoked got and tried to crack the X, but they focus on HTC phones.
Any way to send this idea the devs' way without looking pushy? I think from a technical stand-point this is a worthwhile idea to look into...or at least give some thought to it...
thinking about it further
After thinking about this more I think the answer has to lay in this exploit. We are right in stating that the key is actually burnt into a chip somewhere. However, we must remember that there is some key generation going on during the bootloader phase. Thus: at some point the correct key is stored in memory as the phone correctly boots. If the phone boots, the key is laying someplace in memory. It's just a matter of finding it.
I haven't had time to play with this yet, hopefully I will have some time this week or weekend. I am very confident that this will work, it's just a matter of figuring out how to get the program that reads the memory to look at my phone, not my computer.
lilott8 said:
After thinking about this more I think the answer has to lay in this exploit. We are right in stating that the key is actually burnt into a chip somewhere. However, we must remember that there is some key generation going on during the bootloader phase. Thus: at some point the correct key is stored in memory as the phone correctly boots. If the phone boots, the key is laying someplace in memory. It's just a matter of finding it.
I haven't had time to play with this yet, hopefully I will have some time this week or weekend. I am very confident that this will work, it's just a matter of figuring out how to get the program that reads the memory to look at my phone, not my computer.
Click to expand...
Click to collapse
Liliott,
I'm really glad you are looking into this. I've read about this hack for pc's and think there may actually be something to this. I feel like if we could have something that hijacked the boot process real similar to Koush's recovery then if someone could write a program that would dump NVRAM (I think this is the equivalent to the phone RAM) this would work. With this said, I believe that the devs originally working on cracking the bootloader were able to get NVRAM into "engineering mode" (don't remember the exact terminology off the top of my head)....but I still am thinking this idea should definitely be given more credit and looked into.
I would love to help, but I don't have any dev experience, so I'm somewhat at a loss there....Thanks for pursuing this!
The key you need (presumably an RSA key) wont be stored anywhere on the phone at all.
What happens is that Motorola produce new software for the phone and sign it with their private key (that only Motorola have). This is then sent to the phone. (OTA or whatever they do) The phone verifies the signature using a public key burned into the ROM of the phone (i.e. you cant change it without physically modifying the hardware somehow)
The best hope to break the bootloader on this phone is to reverse engineer it and look for an explot, as has been done on Moto phones in the past (various Motorola MOTOMAGX linux phones have been cracked open this way)
jfwfreo said:
The key you need (presumably an RSA key) wont be stored anywhere on the phone at all.
What happens is that Motorola produce new software for the phone and sign it with their private key (that only Motorola have). This is then sent to the phone. (OTA or whatever they do) The phone verifies the signature using a public key burned into the ROM of the phone (i.e. you cant change it without physically modifying the hardware somehow)
The best hope to break the bootloader on this phone is to reverse engineer it and look for an explot, as has been done on Moto phones in the past (various Motorola MOTOMAGX linux phones have been cracked open this way)
Click to expand...
Click to collapse
Question:
Ok, I know that this will pretty much fall flat, but I have to ask. The Milestone, and OG Droid are pretty much the same phone. Do they have the same boot loader, just unlocked? If so is it the same as the X? The reason I'm asking is it might be easier to crack the Droid since it's already unlocked?
It might be like looking at the lock from inside out trying to figure out how it opens, vs trying to open the lock by looking at it from the outside.
Also, does the MOTO use "goldkeys" like HTC did at one point in time, or have they moved on from that?
On another point, MOTO changed their keys from 2.1 to 2.2, and the phone accepted them. That tells me that it's possible. How much time that will take, I don't know.
Finally, is there any way to "intercept" the process like unrevoked did? I mean if we could get adb working while recovery is working, we could start the recovery process using a legit OTA, and overwrite the zip through adb AFTER verification and before the actual copying. That shouldn't set off the fuse, right?
ideas?
dreamersipaq said:
Question:
Ok, I know that this will pretty much fall flat, but I have to ask. The Milestone, and OG Droid are pretty much the same phone. Do they have the same boot loader, just unlocked? If so is it the same as the X? The reason I'm asking is it might be easier to crack the Droid since it's already unlocked?
It might be like looking at the lock from inside out trying to figure out how it opens, vs trying to open the lock by looking at it from the outside.
Also, does the MOTO use "goldkeys" like HTC did at one point in time, or have they moved on from that?
On another point, MOTO changed their keys from 2.1 to 2.2, and the phone accepted them. That tells me that it's possible. How much time that will take, I don't know.
Finally, is there any way to "intercept" the process like unrevoked did? I mean if we could get adb working while recovery is working, we could start the recovery process using a legit OTA, and overwrite the zip through adb AFTER verification and before the actual copying. That shouldn't set off the fuse, right?
ideas?
Click to expand...
Click to collapse
The Milestone has a locked bootloader, and hasn't been cracked for a year.
Sent from Eris with Froyo
TheSonicEmerald said:
The Milestone has a locked bootloader, and hasn't been cracked for a year.
Sent from Eris with Froyo
Click to expand...
Click to collapse
I really am not trying to sound (too) rude when I say this, but
Did you even READ my whole post?
Yes, the Milestone is locked, but the Droid (the Milestone's US twin) is not.
*Golf clap*
Gotta love it when people reply to a post without even reading a few sentances of the post they are directly replying to. It is understood that the Milestone's bootloader is locked, he was questioning how close the hardware and programming were between the OD (Original Droid) and Milestone aside from the lock being activated in the Milestone. It is the general consensus that the same lock and efuse functions exist in the OD but they are not activated. If this is true then it might be beneficial to see if any of the developers out there with a spare OD test to see if they can figure out how to activate the lock on an OD and then potentially have a better understanding of what might be involved with de-activating it.
Thanks!!!
JinxtPhoto said:
*Golf clap*
Gotta love it when people reply to a post without even reading a few sentances of the post they are directly replying to. It is understood that the Milestone's bootloader is locked, he was questioning how close the hardware and programming were between the OD (Original Droid) and Milestone aside from the lock being activated in the Milestone. It is the general consensus that the same lock and efuse functions exist in the OD but they are not activated. If this is true then it might be beneficial to see if any of the developers out there with a spare OD test to see if they can figure out how to activate the lock on an OD and then potentially have a better understanding of what might be involved with de-activating it.
Click to expand...
Click to collapse
rant
*Bow*
I'm glad that there are still people out there that have a reading comprehension above that of a wet mop. I won't insult them and say they have a low IQ though
I hate it when you take the time to put something that you though about up and someone comes along, reads the first sentence, and (without making any effort to finish the paragraph or REALLY think about what the person is trying to say) spew up crap equivalent to that of the "First" post on blog comment boards.....
/rant
Any haxzors? is this liable, possible, waste of time?
*please don't reply with "waste of time". give us some reasoning, otherwise your post does not help us at all*
The reason it might now
The reason why it actually might not fail is this:
When the system boots, it runs it magic RSA/PGP/AES encryption. It then takes that and compares that to its bootloader routine that it loads. Where does it store the bootloader encryption result to compare to the system boot key? If you guessed memory you would be correct. Now if it stays in memory we will have the golden ticket. If Motorola is smart, and wipe that part of the memory upon OS boot, then it's a matter of timing. If we can get that key, we can, potentially, intercept the bootloader, present the key that we stole and boot our own bootloader/cooked rom.
I think there is quite a bit of potential here.
*Clapping continued...*
I'm glad to see more people finally chiming in on this topic. Call me naive...but when it comes to the dev communities, it seems like "where there's a will...there's a way"
They had made decent progress on cracking this (kinda...) maybe this idea is one that should be looked into (probably said this like 5x in this thread now...oh well)
Thank you to dreamerispaq and Jinxt, appreciate you guys throwing some comments in here
did the release of the 2.2 SBF help at all? If there was a kernel change from 2.1 to 2.2, wouldn't a method be inside of the SBF? Is there any way to hijack the SBF to allow installation of a custom Kernel and ROM?
Shouldn't there basically be an entire phone image inside of the SBF file? If so, would it be possible to alter pieces of that to create some kind of exploit, or use RSD Lite itself and altered SBF's to load up custom kernels and ROMS?
I'm just chucking stones blindly here, I know this is way above my skill level, but I can't help thinking that a full SBF should help similar to the way you can pull the system image from an HTC RUU.
giventofly17 said:
did the release of the 2.2 SBF help at all? If there was a kernel change from 2.1 to 2.2, wouldn't a method be inside of the SBF? Is there any way to hijack the SBF to allow installation of a custom Kernel and ROM?
Shouldn't there basically be an entire phone image inside of the SBF file? If so, would it be possible to alter pieces of that to create some kind of exploit, or use RSD Lite itself and altered SBF's to load up custom kernels and ROMS?
I'm just chucking stones blindly here, I know this is way above my skill level, but I can't help thinking that a full SBF should help similar to the way you can pull the system image from an HTC RUU.
Click to expand...
Click to collapse
Unfortunately, I don't think so. The issue is that both sets of keys are probably hashed and encrypted.... so even if we pulled out the private key out of the SBF that motorolla used, we'd have to brute force it to decrypt it. If, let's say they were smart and used something like RSA as stated above, it'd take a super computer a couple of decades to crack it.
A brute force attack is not going to be helpful here I'm afraid. I'ts going to be more of a lets look at the code, and see if we can find a flaw somewhere in moto's coding that we can use to our advantage.
That's why I recommended looking at the OD. If it shares the same bootloaded, it's already uncloked. Maybe we could take it, reverse engineer it, and look at the calls it makes, where it looks for files, what order it loads things in, etc.... THIS would be more beneficial IMHO.

Enabling USB Debugging with completely unuseable screen

I know there's a lot of threads on this, and some guides, but they're all so vague. It seems like a lot of people are making suggestions based on assumptions that the people having the problem have a slight idea of what to do.
I don't. At all. All I know is there's a program that lets you control your phone with your PC, but you have to do something that NORMAL people DO NOT think to do with their phone. (Enable USB Debugging.)
Now I'm stuck with an entirely, repeat, entirely non-functioning screen. As in, no display, no response to touch, nothing.
What I want to get off the phone, as far as I know, can't be done just by copying and pasting the files to my computer.
I have some game save files on there that I didn't upload to Cloud, so I can't exactly get them back.
It's really irritating to start games over constantly, and I had a fair bit of progress on a number of them, so I really DON'T want to start over again.
If someone could PLEASE help me with this, properly, with more detailed instructions, I would be grateful. I already downloaded [email protected], but again, since I don't have USB Debugging enabled, and NO WAY to do so by means of the phone, it's kind of useless.
I had a similair situation myself and I just gave up.
You need to enable it in the build.prop and you need to disable rsa signature.
The only way you can do that is by flashing it trough a custom recovery. But you cannot select the file. Thus unless you can figure out a way to flash that trough Odin.....
See, now if it's possible, it would be great to get a walkthrough of how to do so.
Either that, or just be told how to grab the save files of my mobile games so I don't have to start over again.

qcom tools

Works nice , easy to get into , the file explorer shows up to 3 Sims, crap full of information yet I don't see anyone posting info around this topic. I would assume that the DT2 XT1585 Verizon users would have a extensive thread on the subject. If there is one on xda then would someone please post the link. I have been in this models internal drives/storage/sims and probably know it better then my wife's body, BUT as for hitting the button for Qfuse off seems way to easy. The only thing I am stuck on is "Enter Service Code" in which it's asking for a 6 digit code. As the other 3 parts of the tool pack work with the standard "000000"
the Qfuse button acts like it's doing something then the program is forced off line. As qcom tools uses it's own server program (included) to connect with the phones main chip I find it wierd that DT2 will self disconnect as if some security protocol on the phone is acting as a mediator, only letting the chip maker to do certain changes. Although useing it to read or flash is not a problem.
Interesting
What does this mean?
Your OP isn't actually a question, or isn't very clear, and I don't know that I've ever run into anyone on Xda who didn't know what ROOT means.
This thread will remain closed until I receive a PM with a more clear OP that asks an obvious question.

Having trouble with my unlock token download

I went through the T-Mobile and OnePlus process to get an unlock token download, but the link is a little screwy. When I try downloading I get an error whether I use Windows, Linux, or Android that says:
SyntaxError: JSON.parse: unexpected character at line 1 column 1 of the JSON data
I tried saving that file anyway but in fastboot I get signature verification errors that way.
Next I went to the raw data and copied that then tried pasting into a terminal but then I just get a prompt that starts with bquote> and I have no idea what to do.
Any ideas?
BreenyBaby said:
I went through the T-Mobile and OnePlus process to get an unlock token download, but the link is a little screwy. When I try downloading I get an error whether I use Windows, Linux, or Android that says:
SyntaxError: JSON.parse: unexpected character at line 1 column 1 of the JSON data
I tried saving that file anyway but in fastboot I get signature verification errors that way.
Next I went to the raw data and copied that then tried pasting into a terminal but then I just get a prompt that starts with bquote> and I have no idea what to do.
Any ideas?
Click to expand...
Click to collapse
So a bit more research since posting this, termite is a good terminal in Arch Linux for copy/paste and bquote is some kind of tool to process commands that use parenthesis. None of that helps me figure this out, though.
I'm guessing that downloading the raw data from that file OnePlus provided isn't going to work out. I did send them a message about the download link error I'm getting but it took them 7 days to send that so my hopes aren't really high.
I expect there are people around here who know what I need to do. I saw several posts on converting to global from T-Mobile and I paid cash for the phone and have it sim unlocked, so I might go that route
I got the phone for my wife, but she filled up the 128 GB memory with photos and didn't like having me copy the pics to hard drive and clearing her memory up. Actually every phone she's had has frustrated her when she has a problem that I have to work out. I'm a habitual tinkerer, was in engineering in the Navy a long time ago and recently finished a bachelor's in computer info systems. I'm no expert and not at the level of someone with a computer science degree, CIS was at least half business classes and much of the computer side was basic networking, database, and systems analysis and design but I can usually manage unlocking the bootloader even when obstacles are in the way. I used to work for a big US carrier and always found ways to get around their OS to sdo what I wanted with a phone.
Anyway, got a new iPhone for her and wanted to put something with Android 11 for my son to use on the old 6T. OnePlus and T-Mobile aren't going to develop anything beyond Android 10 for this phone so I was thinking LineageOS. Gotta have the bootloader unlocked, first.
Thanks for any help!
BreenyBaby said:
I went through the T-Mobile and OnePlus process to get an unlock token download, but the link is a little screwy. When I try downloading I get an error whether I use Windows, Linux, or Android that says:
SyntaxError: JSON.parse: unexpected character at line 1 column 1 of the JSON data
I tried saving that file anyway but in fastboot I get signature verification errors that way.
Next I went to the raw data and copied that then tried pasting into a terminal but then I just get a prompt that starts with bquote> and I have no idea what to do.
Any ideas?
Click to expand...
Click to collapse
Is it an official link from Oneplus? It takes a week to get your unlock token from Oneplus. We had no issues
BreenyBaby said:
So a bit more research since posting this, termite is a good terminal in Arch Linux for copy/paste and bquote is some kind of tool to process commands that use parenthesis. None of that helps me figure this out, though.
I'm guessing that downloading the raw data from that file OnePlus provided isn't going to work out. I did send them a message about the download link error I'm getting but it took them 7 days to send that so my hopes aren't really high.
I expect there are people around here who know what I need to do. I saw several posts on converting to global from T-Mobile and I paid cash for the phone and have it sim unlocked, so I might go that route
I got the phone for my wife, but she filled up the 128 GB memory with photos and didn't like having me copy the pics to hard drive and clearing her memory up. Actually every phone she's had has frustrated her when she has a problem that I have to work out. I'm a habitual tinkerer, was in engineering in the Navy a long time ago and recently finished a bachelor's in computer info systems. I'm no expert and not at the level of someone with a computer science degree, CIS was at least half business classes and much of the computer side was basic networking, database, and systems analysis and design but I can usually manage unlocking the bootloader even when obstacles are in the way. I used to work for a big US carrier and always found ways to get around their OS to sdo what I wanted with a phone.
Anyway, got a new iPhone for her and wanted to put something with Android 11 for my son to use on the old 6T. OnePlus and T-Mobile aren't going to develop anything beyond Android 10 for this phone so I was thinking LineageOS. Gotta have the bootloader unlocked, first.
Thanks for any help!
Click to expand...
Click to collapse
Is it an official link from Oneplus? It takes a week to get your unlock token from Oneplus. We had no issue with 2 of them we downloaded. Not sure if I am allowed to post the link to the download pag
BreenyBaby said:
So a bit more research since posting this, termite is a good terminal in Arch Linux for copy/paste and bquote is some kind of tool to process commands that use parenthesis. None of that helps me figure this out, though.
I'm guessing that downloading the raw data from that file OnePlus provided isn't going to work out. I did send them a message about the download link error I'm getting but it took them 7 days to send that so my hopes aren't really high.
I expect there are people around here who know what I need to do. I saw several posts on converting to global from T-Mobile and I paid cash for the phone and have it sim unlocked, so I might go that route
I got the phone for my wife, but she filled up the 128 GB memory with photos and didn't like having me copy the pics to hard drive and clearing her memory up. Actually every phone she's had has frustrated her when she has a problem that I have to work out. I'm a habitual tinkerer, was in engineering in the Navy a long time ago and recently finished a bachelor's in computer info systems. I'm no expert and not at the level of someone with a computer science degree, CIS was at least half business classes and much of the computer side was basic networking, database, and systems analysis and design but I can usually manage unlocking the bootloader even when obstacles are in the way. I used to work for a big US carrier and always found ways to get around their OS to sdo what I wanted with a phone.
Anyway, got a new iPhone for her and wanted to put something with Android 11 for my son to use on the old 6T. OnePlus and T-Mobile aren't going to develop anything beyond Android 10 for this phone so I was thinking LineageOS. Gotta have the bootloader unlocked, first.
Thanks for any help!
Click to expand...
Click to collapse
You say it is official Oneplus download? It sounds like the file is corrupt from them. Have you tried different browsers? I am assuming you have. I downloaded to unlock files and had no issue at all with them.
It is from them. I bought the device in 2018 at TMobile and went through all the appropriate steps. Friday was 7 days from request and their email arrived. I've been in contact with them, they want me to let them remote in but I am not doing that, just want the unlock token .bin file not wanting anyone remoting into my computers and network. If they won't then I'll take steps to get around it until I either succeed or brick the phone, I'm fine with that it's all on me but I am not giving anyone remote access to my computers or network.
That is just strange that they would want to remote in. I would not let them do it either. Good call! It is still strange that the file will not download correctly. I will tell you this, if you have Verizon for a carrier you will have trouble with the device. I don't know why, but everyone I know, whether LineageOS or OxygenOS has trouble with the device on Verizon. I think it is a provisioning issue on Verizon's end, but getting them to own up to it is pretty hard to do.
I think their server is down. Someone on the forums posted about this and I am experiencing the same issue. Unable to download any of my past .bin files.
Sucks cause I just MSM'd my OP9P and can't unlock bootloader cause I imaged my computer prior and didn't back it up xD
I'm having the same issue. Any new information?
Same here--I follow the link in edge or chrome and get gibberish, follow it in firefox and get "SyntaxError: JSON.parse: unexpected character at line 1 column 1 of the JSON data."
OnePlus told me other users were having trouble too and to try in 4 or 5 days.
I still have a few days to go.
EDIT: Later, that same day..., link to download unlock token is working.
It is as OP support said--there was an issue with the website.
joeliberty said:
That is just strange that they would want to remote in. I would not let them do it either. Good call! It is still strange that the file will not download correctly. I will tell you this, if you have Verizon for a carrier you will have trouble with the device. I don't know why, but everyone I know, whether LineageOS or OxygenOS has trouble with the device on Verizon. I think it is a provisioning issue on Verizon's end, but getting them to own up to it is pretty hard to do.
Click to expand...
Click to collapse
I was told that OnePlus 6t should be registered as a 'CDMA-less' on Verizon system to use it.
Still having issues. Sad. I just wanna go back to flashing stuff. The kernel on the op9p sucks. I'm ready for better battery life.
Link to download unlock token is working now.
It is as OP support said--issues with website.

Categories

Resources