Unlock CID in a smt5600 - HTC Typhoon

Hello
How do I unblock the CID in a smt5600????
And how do I program another rom???

neb2567 said:
Hello
How do I unblock the CID in a smt5600????
And how do I program another rom???
Click to expand...
Click to collapse
Read Karhoe's first post and follow it entirely. It is the first topic labled 'STICKY" on the Typhoon page. Read everything first, download everything you need. Read everything again, then follow it exactly.

raskell said:
Read Karhoe's first post and follow it entirely. It is the first topic labled 'STICKY" on the Typhoon page. Read everything first, download everything you need. Read everything again, then follow it exactly.
Click to expand...
Click to collapse
Thanks....
But in the Step 9 show me this:
------------------------------------------------------------------
*Image Download Finish
OEMFlashWrite(82040000h,8C080000h,01B00000h)
Update BINFS offset 0x00000000 length 0x01B00000 ...
Write BinFS Offset add=0x0 Length=0x1B00000 Checksum=0x95EA3E42
Write to BINFS partition from sector 4, length 28311552, 55296 sectors...
Can't write to DiskOnChip, status=27
Flash BINFS failed.
Download Fails !!!
OEMFlashWrite error(12)
Error : DownloadImage return error (code = 0xFFFFFFFF)
------------------------------------------------------------------
Help becouse the smartphone isn't turn on

neb2567 said:
Thanks....
But in the Step 9 show me this:
------------------------------------------------------------------
*Image Download Finish
OEMFlashWrite(82040000h,8C080000h,01B00000h)
Update BINFS offset 0x00000000 length 0x01B00000 ...
Write BinFS Offset add=0x0 Length=0x1B00000 Checksum=0x95EA3E42
Write to BINFS partition from sector 4, length 28311552, 55296 sectors...
Can't write to DiskOnChip, status=27
Flash BINFS failed.
Download Fails !!!
OEMFlashWrite error(12)
Error : DownloadImage return error (code = 0xFFFFFFFF)
------------------------------------------------------------------
Help becouse the smartphone isn't turn on
Click to expand...
Click to collapse
U fried ur phone.......
have U checked again by pressing camera button and then inserting cable.....
no sign of life???
IF YES then ur phone is not more than a paper weight.....
I followed all steps as prescribed in kar hoe's blog, and did seuccessfull upgrade......but revived back to WM2003SE coz of RAM s**king and battery draining......

dark_prince said:
U fried ur phone.......
have U checked again by pressing camera button and then inserting cable.....
no sign of life???
IF YES then ur phone is not more than a paper weight.....
I followed all steps as prescribed in kar hoe's blog, and did seuccessfull upgrade......but revived back to WM2003SE coz of RAM s**king and battery draining......
Click to expand...
Click to collapse
Neb's phone is back online. It was not bricked. Karhoe's instructions (which I think are excellent) does not say to copy the os.bin to the root directory of c:, it infers by its command line structure that you need to put it there.

raskell said:
Neb's phone is back online. It was not bricked. Karhoe's instructions (which I think are excellent) does not say to copy the os.bin to the root directory of c:, it infers by its command line structure that you need to put it there.
Click to expand...
Click to collapse
Yes, very thanks Raskell
The problem was the file bin....
Only write a version of windows mobile 5.0...
The others have the problem....
Thanks

neb2567 said:
Yes, very thanks Raskell
The problem was the file bin....
Only write a version of windows mobile 5.0...
The others have the problem....
Thanks
Click to expand...
Click to collapse
If you have problems to flash WM6 then try again to unlock your phone. Sounds like the CID or application unlock procedure did not take correctly. The reason you can flash WM5 is most likely because it is the OEM ROM version.
http://selberg.org/2005/07/22/unlock-an-audiovox-5600-for-free/
This link is the one I used to unlock my Cingluar Audiovox SMT5600. It may help you as well

Hello, I believe that the problem that I have is to try to put it in supercid, because when I want to change it at cid=11111 he doesn't make it

Related

write the nb1 file to SD card directly from the PPC device !

hello..
is there a chance to do it ?
writting the nb1 file to SD card directly from the PPC device its self without need to buy a card writer/reader ?
why not ? out PPC can write & read the card, so any chance to do it ?
best regards
Yes, this possibility exists. Nobody has written code to do it though.
We're toying woth the idea of a whole new tool which allows many more operations directly to the device. If only we could find either a lot of time, or some sharp volunteer coders with too little on their hands...
yes, it is possible. just didn't have the time to write a program to do it yet.
I did write some test code, to see how it works
source + exe here
btw, warning - the write function will erase what ever was on your sdcard.
hello again..
well thank u all XDA developers, i wanna know is it just a raw writting of nb0 & nb1 on SD card starting from block 0 to the end of nb1 ?
best regards
for 5.14, 5.15, 5.22 the first sector contains a string specifying the cardtype:
"HTC$WALLABY00" - bootloader ( nb0 )
"HTC$WALLABY11" - wince image (nb1)
"HTC$WALLABY22" - bootloader(nb0) + wince image(nb1)
"HTC$WALLABY33" - diagnostics card(nb2)
"HTC$WALLABY44" - gsm
"HTC$WALLABY55" - gsm + wince image
starting at the 2nd sector, the data is written.
these last 2 we have not experimented with yet.
for 5.17 the layout is a bit different, the first sectory contains the string 'HTC FLASH KEY', the 2nd sector starts with the md5sum of the cardid, the 3rd sector has a 4 byte counter value, the 4th the md5sum of this counter, the 5th contains 'N'
starting at the 6th the about HTC$WALLABY string + bootloader/wince images are written.
a bootloader is always 512 512byte blocks or 256k
a os image is always 65024 blocks, or 31.75M
see xdarit source for more details
thanx alot XDA developer
my WALLABY boot loader is v5.15
I'm on my way to write xdirt for PPC, many thanx for ur information.
best regards
Hi...
Can't wait to get my hands on your code...hoping it works with 5.17.
Is the idea behind your program to prepare the SD card with the .NB0 / .NB1 files so we can upgrade our PPC's to 2003 through an ActiveSync connection?...yes, I'm a complete novice at this...sorry
G

[Universal] How to d2s (dump) the ROM

All right... GOOD NEWS story for today!!!
There is no doubt, that our gods are helping us...
Here's what happened to me yesterday.
Yesterday I was dreaming about editing the ROM of Universal/Exec but as you may know, 'd2s' command doesn't work. It just quits with "Not allow operation".
But suddenly, my china god of wisdom whispered to me:
GOD: "hey buzz, you wanna dump the thing? why do you use that old fashioned 'd2s' command to dump it?"
me: "well, that always worked... so what else should i use?"
GOD: "OK, here's a little present for you ) just try 'task 32' )) "
Code:
USB>task 32
SD:Waiting for card insert.........
CMD3 for SD, it's OK, ready to get RCA from response.
SD:Detected one card
SD:ready for transfer OK
d.total_lba=1DC00
d.block_size=200
d.RCA=EC7E
d.drv_type=40000000
d.busWidth=1
Total card size=3B80000
So here it is !!!!
... and LET THE FUN BEGIN!!!
The above story is 100% true, i've made up maybe two words myself...
BTW, this might also work on other "password protected" devices.
THANX
buzz
Buzz, that's great, where the heck did you find that command?
But now that bal666 has that decrypt/encrypt utility of the original NBK files, what would be the benefit of dumping the ROM to the SD card?
Can you restore back to the device from the SD card?
Going by the way of the SD card to dump, extract, modify, write back, then flash may be safer than the Upgrade Utility that keeps my device stuck in Bootloader mode until I go through the whole NK/MS, then Radio upgrade.
So, what's the opposite of 'task 32?'
Thanks!
i'm dumping at the moment, but i would say, that it would be enough to insert the SD card back into the slot and reboot into bootloader mode.
Then you have to wait few seconds till "press power to flash" message appears.
But so far i didn't test it, yet...
Testing right now...
))
buzz
buzz_lightyear said:
i'm dumping at the moment, but i would say, that it would be enough to insert the SD card back into the slot and reboot into bootloader mode.
Then you have to wait few seconds till "press power to flash" message appears.
But so far i didn't test it, yet...
Testing right now...
))
buzz
Click to expand...
Click to collapse
Buzz, it is really good news. At this moment some of Universal (e.g. T-mobile) providers have not released an update yet. So if people can dump their roms on a SD, we at least have a fall back. In case of repairs the Universal will need to be updated again with a rom from the provider.
That is really a fantastic news!
If the restore test is successful, please just let all of us know.
Oh, and look forward to a complete dump backup/restore guide. :wink:
BeyondtheTech said:
But now that bal666 has that decrypt/encrypt utility of the original NBK files, what would be the benefit of dumping the ROM to the SD card?
Click to expand...
Click to collapse
From what I've seen his tool incorrectly decrypts NBF, some blocks are mixed.
hmmm.....
i think that the "task 32' commande needs a little bit more tweaking...
Till now it was just saying OK... ready.. etc., but actually did not the dump... (
Code:
USB>task 32
SD:Waiting for card insert.........
CMD3 for SD, it's OK, ready to get RCA from response.
SD:Detected one card
SD:ready for transfer OK
d.total_lba=F1F00
d.block_size=200
d.RCA=80CA
d.drv_type=40000000
d.busWidth=1
Total card size=1E3E0000
Level = FF
USB>
Well, "Level = FF" sounds like an error to me....
hmmm....
buzz
Another very interesting command and it's output:
Code:
USB>info 2
SD:Waiting for card insert.........
CMD3 for SD, it's OK, ready to get RCA from response.
SD:Detected one card
SD:ready for transfer OK
d.total_lba=F1F00
d.block_size=200
d.RCA=80CA
d.drv_type=40000000
d.busWidth=1
Total card size=1E3E0000
HTCSDOPOD601 «Jú½HTCE
USB>
Code:
USB>info 7
HTC Integrated Re-Flash Utility for bootloader Version : 1.40h, UNIVERSAL HW Version : 1.00
Built at: Sep 2 2005 15:14:29
Copyright (c) 1998-2005 High Tech Computer Corporation
Turbo=312, Run=208
Memory Frequency = 208 MHz
SDRAM Frequency = 104 MHz
Board ID is: 5
USB>
buzz
buzz_lightyear said:
Code:
Board ID is: 5
Click to expand...
Click to collapse
Hi Buzz,
is it possible to make memory dumps
in the bootloader without entering a password ?
cr2 said:
buzz_lightyear said:
Code:
Board ID is: 5
Click to expand...
Click to collapse
Hi Buzz,
is it possible to make memory dumps
in the bootloader without entering a password ?
Click to expand...
Click to collapse
not in bootloader...
but i'm able to dump DOC and memory using RapiEnabler and itsutils.
buzz
buzz_lightyear said:
but i'm able to dump DOC and memory using RapiEnabler and itsutils.
Click to expand...
Click to collapse
Hmm. What part of the DoC ? All 128 MB ?
There is also OTP and other stuff.
As you can guess, i'd like to dump the whole 64MB RAM (or as much as possible) while the bootloader is running, not
in wince.
Maybe you should try 'r2sd' ?
mamaich said:
BeyondtheTech said:
But now that bal666 has that decrypt/encrypt utility of the original NBK files, what would be the benefit of dumping the ROM to the SD card?
Click to expand...
Click to collapse
From what I've seen his tool incorrectly decrypts NBF, some blocks are mixed.
Click to expand...
Click to collapse
He stated that as long as you don't change the header information, it will encrypt and decrypt properly.
As a precaution, I took the NK.NBF, decrypted it to NK.FAT, then reencrypted it and did a successful byte-comparison.
I did the same with my modified NK.FAT file with my injected custom splash image and it encrypted and decrypted properly.
The biggest test was flashing it, and man, I was sweating buckets during the process. But, the flash came through successful for me and now I have the first custom splash screen on the Universal.
It's fun to break news or be the first guinea pig to try it out, just as long as it comes out successful! :lol:
The password doesn't seem do do anything.
The level of access is determined by your CID.
If your CID is 11111111 you have a SuperCID, which enables all the operations. I'm trying to track down where the CID is stored.
Bye,
Ricardo
go beyoundthetech !!!!
now only if you could post a step by step for all us goofs out here...
also im wondering with your genius if you could use the recently posted tools here to make custom universal rom (minus the ie explorer, file explorer etc) and teach us how to do that aswell!!!!
buzz_lightyear said:
i'm dumping at the moment, but i would say, that it would be enough to insert the SD card back into the slot and reboot into bootloader mode.
Then you have to wait few seconds till "press power to flash" message appears.
But so far i didn't test it, yet...
Testing right now...
))
buzz
Click to expand...
Click to collapse
My 9000 has a SuperCID. I managed to dump and flash the rom using these techniques.
Bye,
Ricardo
BeyondtheTech said:
He stated that as long as you don't change the header information, it will encrypt and decrypt properly.
As a precaution, I took the NK.NBF, decrypted it to NK.FAT, then reencrypted it and did a successful byte-comparison.
I did the same with my modified NK.FAT file with my injected custom splash image and it encrypted and decrypted properly.
Click to expand...
Click to collapse
I decrypted nk.nbf to nba with his tool, and decrypted the same file with alpinenbfdecode.pl script. Files are different after some offset. So there should be a bug in his util, because alpinenbfdecode.pl is known to produce working files. I had no time for more tests.
buzz_lightyear said:
Another very interesting command and it's output:
Click to expand...
Click to collapse
Hi buzz,
i can run "rbmc", but don't get where is this c:\test\mem.nb located.
Is it used by the mtty download protocol ?
I can't test it because mtty is not working
for me in windowz
cr2 said:
buzz_lightyear said:
Another very interesting command and it's output:
Click to expand...
Click to collapse
Hi buzz,
i can run "rbmc", but don't get where is this c:\test\mem.nb located.
Is it used by the mtty download protocol ?
I can't test it because mtty is not working
for me in windowz
Click to expand...
Click to collapse
looks like rbmc is running up to the point, where it should start saving the dump (
same as task 32
(
buzz
OK, so here is, how it should be:
Dump Bootloader:
Code:
USB>task 32
USB>d2s 70000000 80000
OS ROM + splash:
Code:
USB>d2s 70100000 3FA0000
XtendedROM:
Code:
USB>d2s 74100000 A00000
Radio ROM:
Code:
USB>d2s 60000000 a24200
If you want to have them all on single SD card, you must add "sd a" at the end of each command except the first one.
Example to dump/backup OS + XtendedROM + Radio:
Code:
USB>d2s 70100000 3FA0000
USB>d2s 74100000 A00000 sd a
USB>d2s 60000000 a24200 sd a
buzz

I think I screwed up something using task29 with Mitty

I followed directions as posted on:
http://winmo.techparaiso.com/mtty-heaven-for-flash-junkies-on-windows-mobile-phone-devices/
on the CMD I typed set 14 0
Then typed task 29
Then task 8
Then disconnected and held the vol down and end, came back to the tri color screen,
Connected the USB, ran Kwbr_Topix_1.5.7 ROM (ROMUpdateUtility.exe)
It went fine, the phone rebooted, and all I get is
Stick together logo
R 2.08.50 08~2
G 15.34.50.07u
D 1.72.82124
Waited for 30 min and still no progress on booting,
I even did a hard reset, and still the same above issue.
PLEASE HELP !!!
richsark said:
I followed directions as posted on:
http://winmo.techparaiso.com/mtty-heaven-for-flash-junkies-on-windows-mobile-phone-devices/
on the CMD I typed set 14 0
Then typed task 29
Then task 8
Then disconnected and held the vol down and end, came back to the tri color screen,
Connected the USB, ran Kwbr_Topix_1.5.7 ROM (ROMUpdateUtility.exe)
It went fine, the phone rebooted, and all I get is
Stick together logo
R 2.08.50 08~2
G 15.34.50.07u
D 1.72.82124
Waited for 30 min and still no progress on booting,
I even did a hard reset, and still the same above issue.
PLEASE HELP !!!
Click to expand...
Click to collapse
you have the wrong radio. flash either 2.07.51.22 or 2.09.51.03_2 and you will be fine.
Try and flash also the radio again! When you used mtty you also formated the radio and now you need it! The phone is fine, but try to read carefully the How to flash.....here http://forum.xda-developers.com/showthread.php?t=609477 .
Even if you think you know everythin....learn before you flash!
Thanks guys... I am back up now .... heehhhhh I soiled my pants
viperd said:
When you used mtty you also formated the radio and now you need it!
Click to expand...
Click to collapse
not true, mtty doesn't touch the radio.
samsamuel said:
not true, mtty doesn't touch the radio.
Click to expand...
Click to collapse
task 29 formats the drive partition of the device where the ROM (.nbh) file resides
jigners said:
task 29 formats the drive partition of the device where the ROM (.nbh) file resides
Click to expand...
Click to collapse
correct. just the system partition and not the radio partition.
____
I got this when running task 29 and Mitty
Cmd>set 14 0
crc=0xD2C8DA7F.
HTCST ÚÈÒHTCE
Cmd>task 29
Format BINFS start
Fill RSVD information for block 497 to 530
CE start start block=530, total block=7662
erase_page - error bad status: 0xB791E960
ERASE block 460 FAIL !!!
TAG NOT FOUND !!! NOT CLEAR STORAGE !!!
Format BINFS end
Cmd>
Did I miss an important step? I think I may have not moved a necessary file??
yea that looks correct for task 29 output.nothing wrong there.
just type task 8 next and the phone will reboot.if you hold vol down straight awayit will return to boot loader ready to flash your rom.
samsamuel said:
yea that looks correct for task 29 output.nothing wrong there.
just type task 8 next and the phone will reboot.if you hold vol down straight awayit will return to boot loader ready to flash your rom.
Click to expand...
Click to collapse
ok, so the errors are ok??
BTW.. I did type task 8, but did not show that.. my bad.
richsark said:
ok, so the errors are ok??
BTW.. I did type task 8, but did not show that.. my bad.
Click to expand...
Click to collapse
Yep. These errors are normal and show up every time. The process is correct.
pablo11 said:
Yep. These errors are normal and show up every time. The process is correct.
Click to expand...
Click to collapse
Ok then !
Issue closed. Thanks a Mill !
To the OP,
If you need further help please post directly in the MTTY thread.
WB

Hero Root

Hi,
I have an Hero with 2.73.85.41 Build Number, and I can't Root it, can anyone help me please?
I've had enough waiting for the promised official ROM upgrade :S
Thanks
I think you may have to use the GOLDCARD method. Use BTDAG's guide as linked in my signature.
Thanks, I'll try that, but I've already tried the Unlockr method with no success
I have a 8Gb Kingston SD card, do you think this could be the problem?
Thanks
"can't root" and "no success", now that is a detailed error report...
Use the guide I said check the "Goldcard" you've already made,...
btdag said:
12. Click on the Goldcard.img tab and press Ctrl + A (select all) Then Ctrl + C (copy).
13. Click on the Removable Disk tab (Your SD Card) and select the complete lines from 00000000 to 00000170 then press Ctrl + V (paste).
14. Click on File then click Save.
15. Close the Hex Editor.
16. Reboot the phone.
Try to open the memory card on the computer (i.e. mount the drive), if it lets you, you are all set. If it asks/tells you to reformat the card, then try steps 13 – 19 again. If it gives you the same error again, then try a different memory card. You can confirm that it has worked by opening the Removable Disk in the hex editor again and making sure the code you pasted in has stayed but this shouldn't be necessary.
Click to expand...
Click to collapse
or does this apply to you,... It's the FIRST thing in his FAQ
btdag said:
FaQ
I get [ERROR 000: ArghArghArgh] when installing the exe, what can I do?
First thing's first - check that your goldcard has stuck. Load up the Hex editor and open your SD card in it again and make sure it still has the goldcard data at the beginning of it.
Second - follow the "Bootloader Driver" section of my ADB/Sync Driver Guide
Third - Use Windows XP instead (you can do this through VirtualBOX or VMWare)
Click to expand...
Click to collapse
Read, read, then read some more.
And yeah,... Giving details of error messages you get or where exactly you get stuck at might take out some of the guess work.
Or you could try my guide
http://forum.xda-developers.com/showthread.php?t=662964
ddotpatel - not a word from you please

[Help]stuck with spl 3.03 boot screen

Hello
I tried to install a rom 3.14 on a htc hd 2 sfr (French operator) from the SD card! I find myself with an spl 3.3 that refuses to install another rom! sfr never gives an offcial rom! Now when I start my htc I end up with the boot loader screen!
impoissble to make a gold card because no way to get the CID from ans sd card!
i need your help plz
please i dont want to throw from the window!
Have you tried flashing the 3.14 rom through usb instead of the sd card
yes got an invalid vendor id! the probleme is that sfr is a **** operator! not even the original rom released ti the public
my hope is to get an hsp4 but nobody is working on it
Did you have hspl on the rom before flashing if so you need to remove the hspl and then flash the 3.14 rom if you look in the threads there is a how to i use the artemis rom which is 3.14 based and can be flashed with sspl
projektk said:
impoissble to make a gold card because no way to get the CID from ans sd card!
Click to expand...
Click to collapse
use a friends phone to get the cid, or a laptop, or any other winmo device. Doesnt have to be YOUR phone.
samsamuel said:
use a friends phone to get the cid, or a laptop, or any other winmo device. Doesnt have to be YOUR phone.
Click to expand...
Click to collapse
i have a laptop with an sd card readrer! do you knwo how to get the CID with it?
ps: i cant use sspl iam stuck in bootloader screen
i managed to get this infos using a c# program
C:\Users\acer\Desktop>ReadCID.exe
\\.\PhysicalDrive1 F:\
--------------------
Raw CID Bytes: 96-00-B5-3C-88-A0-38-47-32-30-44-53-4D-54-02-00
--------------------
Manufacturer ID: 2
OEM ID: TM
Product Name: SD02G
Product Revision: 3.8
Product Serial Number: a0883cb5
Manufacture Date: 6/2009
--------------------
Raw CSD Bytes: 00-80-16-80-FF-FF-FF-A9-83-5A-5B-5A-00-2E-00-00
--------------------
CSD Version 2 bit value: CSD Version 1.0
Data Read Access Time 1 (TAAC): 2ms
Data Read Access Time 2 (NSAC): 0
Max Data Transfer Rate: 50Mbit/s
Card Command Classes: 010110110101
Max Read Data Block Length: 10
Partial Blocks For Read Allowed: True
Write Block Misalignment: False
Read Block Misalignment: False
DSR Implemented: False
Device Size: 3751
Max Read Current @ VDD Min: 100mA
Max Read Current @ VDD Max: 200mA
Max Write Current @ VDD Min: 100mA
Max Write Current @ VDD Max: 200mA
Device Size Multiplier: 15
Erase Single Block Enable: True
Erase Sector Size: 128
Write Protect Group Size: 1
Write Protect Group Enable: False
Write Speed Factor: 32
Max Write Data Block Length: 2^10
Partial Blocks For Write Allowed: False
File Format Group: False
Copy Flag (OTP): False
Permanent Write Protection: False
Temporary Write Protection: False
File Format: 0
can some one please make me a gold card?
please i need your help! iam desperate
not sure if the format for the cid is correct (i remember reading it should be reversed when not using psas) so i did both.
9600B53C88A03847323044534D540200
0002544d534430324738a0883cb50096
thanks ! you make happy! havent triy it yet! but what you done is enough
send you a little something for your help
how to write the img file to sd card without the phone! ujsing a laptop sd readrer?
projektk said:
how to write the img file to sd card without the phone! ujsing a laptop sd readrer?
Click to expand...
Click to collapse
well, therein lies the problem. If you managed to get the correct CID, then you should be OK. If it turns out you have a USB type card reader it wont work.
gotta go, sick child, ill write a fuller response in an hour or so
OK, as mentioned in your PMs, you have a PCI reader, so you should be good to go.
have a look at THIS for how to write the img to sd card, but switch reference to phone in hard disk for your card in card reader. the process is the same.
Start at the line 'Get HxD Hex Editor, '
samsamuel said:
well, therein lies the problem. If you managed to get the correct CID, then you should be OK. If it turns out you have a USB type card reader it wont work.
gotta go, sick child, ill write a fuller response in an hour or so
Click to expand...
Click to collapse
hope nothing serious for the kid!
i was trying to write it using winhex but some windows 7 compatibilie issues! i will try HxD Hex Editor and post the result
thanks alot
Rom is updating right now! gold card creation succesful! i will create a post with a tutorial for other people with the same probleme !
thanks sam for your help!
a few tips to solve the probleme
http://forum.xda-developers.com/showthread.php?t=874304
use hspl2 .
flash hspl 2.08
flash a coustom rom, other that 3.14 made.
i got the same problem ... solved like this
hspl2 dont work with spl 3.03

Categories

Resources