Because its still a mess here at the wp8 Hack&Dev Forums I will dedicate this thread for Clearing what is already capable with our wp8 phones and what is still a "in Progress"
Dev unlock:
Interop unlock:
Modded boot loader:
UEFI Hacking:
Custom Rom:
Flashing:
Full Unlock:
You can make an dev account at MS.
http://forum.xda-developers.com/showthread.php?t=2395398
[XAP][GUIDE] Interop Unlock for WP8 + all Capabilities
It's currently limited to SAMSUNG phones
http://forum.xda-developers.com/showthread.php?t=2435697.
At this point, you will be able to sideload any capability, even the ones used for built-in apps and services
However, there appear to still be restrictions, even with a capability such as ID_CAP_BUILTIN_TCB. Heathcliff74 and GoodDayToDie are working to overcome these restrictions
This list is *just* the ones from Interop-unlock; it does not unclude the ones from EnableAllSideloading
•ID_CAP_CALLMESSAGING_FILTER
•ID_CAP_CAMERA
•ID_CAP_CELL_API_COMMON
•ID_CAP_CELL_API_LOCATION
•ID_CAP_CELL_API_OEM_PASSTHROUGH
•ID_CAP_CELL_API_UICC
•ID_CAP_CELL_API_UICC_LOWLEVEL
•ID_CAP_CELL_WNF
•ID_CAP_CSP_FOUNDATION
•ID_CAP_CSP_MAIL
•ID_CAP_CSP_OEM
•ID_CAP_CSP_W4_APPLICATION
•ID_CAP_CSP_WIFI_HOTSPOT
•ID_CAP_DEVICE_MANAGEMENT
•ID_CAP_DEVICE_MANAGEMENT_ADMIN
•ID_CAP_DEVICE_MANAGEMENT_BOOTSTRAP
•ID_CAP_DEVICE_MANAGEMENT_SECURITY_POLICIES
•ID_CAP_DU_MIGRATOR_STATUS_OEM
•ID_CAP_OEM_DEPLOYMENT
•ID_CAP_INTERNET_EXPLORER_FAVORITES
•ID_CAP_INTERNET_EXPLORER_SEARCH_PROVIDER_KEYS_HKCU
•ID_CAP_INTEROPSERVICES
•ID_CAP_KIDZONE_CUSTOMIZATION
•ID_CAP_MAP_WRITE
•ID_CAP_MEDIALIB_PHOTO_FULL
•ID_CAP_NETWORKING_ADMIN
•ID_CAP_OEM_ADC
•ID_CAP_OEMPUBLICDIRECTORY
•ID_CAP_PEOPLE_EXTENSION
•ID_CAP_PEOPLE_EXTENSION_IM
•ID_CAP_PEOPLE_EXTENSION_MOBILE
•ID_CAP_PERSONAL_INFORMATION_IMPORT
•ID_CAP_RUNTIME_CONFIG
•ID_CAP_SMS_INTERCEPT_AGENT
•ID_CAP_SMS_INTERCEPT_RECIPIENT
•ID_CAP_SYNC_EXTENSION
•ID_CAP_VOICEMAIL
•ID_CAP_WALLET_SECUREELEMENT
•ID_CAP_WIFI_BASIC
Modded Boot loader (I mean Retail) isn't there yet for real wp8 phones.
A NON public bootloader/magldr/UEFI is made by Cotulla for the HD2.
UEFI Hacking/Extracting is a work in progress ( http://forum.xda-developers.com/htc-8x/development/htc-8x-wp8-gdr2-uefi-extracted-cab-t2843827 )
Custom rom is there for only 1 phone and that is the Huawei W1
this is in REALLY beta state and not public
http://forum.xda-developers.com/showthread.php?t=2321642
Flashing isn't a work in progress because there isn't a real need for it as of now
Full Unlock is in early progress but non public
Links to reg hack threads.
Samsung ativ s - registry hacks
http://forum.xda-developers.com/showthread.php?t=2434959
WP8 Diagnostics and Hidden Apps Thread
http://forum.xda-developers.com/showthread.php?t=2311626
Tools&App's
(FFU) ImgMount Tool v.1.0.15
http://forum.xda-developers.com/showthread.php?t=2066903
[XAP] SamWP8 Tools. System tools for Samsung. Based on Diagnosis.
http://forum.xda-developers.com/showthread.php?t=2435673
[XAP] Interop Unlock Helper app for Samsung WP8 phones
http://forum.xda-developers.com/showthread.php?t=2434884
[PROXY] Everything at once
http://forum.xda-developers.com/showthread.php?t=2400715
[TOOLS] Samsung WP8 ROM extracting/packing Tools
http://forum.xda-developers.com/showthread.php?t=2429741
[XAP][SOURCE] Native Toast Notification Launcher
http://forum.xda-developers.com/showthread.php?t=2398275
[XAP][Source] Webserver v0.4.6 (bugfixes, MultiStrings, permissions, NativeAccess)
http://forum.xda-developers.com/showthread.php?t=2355034
[XAP][SOURCE] WP8 Registry Tools
http://forum.xda-developers.com/showthread.php?t=2395480
[EXE] [1.7.5] Store OEM Changer
http://forum.xda-developers.com/showthread.php?t=2412713
Nokia Developer - Remote Device Access (Diag Tools for Lumias)
http://forum.xda-developers.com/showthread.php?t=2450684
[XAP][01.10.2013] Update: PDF to Office V1.2 for interop-unlocked Samsung devices
http://forum.xda-developers.com/showthread.php?t=2462257
[XAP][TOOL] EXPERIMENTAL: WPH Tweaks
http://forum.xda-developers.com/showthread.php?t=2486387
Rom's & Update package links
[CAB] Windows Phone 8 update packages
http://forum.xda-developers.com/showthread.php?t=2409330
Nokia's Rom thread
http://forum.xda-developers.com/showthread.php?t=1971150
Samsung ATIV S I8750 Rom flashing!
http://forum.xda-developers.com/showthread.php?t=2391138
WP8 BootLoader Background.
WP8* phones MUST be Q-fuse protected by MS (retail), this means that potential holes must go through a road that isn't there anymore.
then IF you found a way to get in the phone the chain of trust starts.
PBL:
Code:
PBL
• RPM processor starts executing PBL in boot ROM
• PBL determines cold boot or warm boot
• PBL increases RPM clock speed from XO to 60 MHz
• RPM processor start address is 0x0
• For cold boot, next step is to detect Flash device that chip will boot from,
based on the boot options
• When detected, PBL downloads SBL1 (RPMSBL) from Flash to System IMEM
• SBL1 authenticates SBL2 (Krait PBL)
• RPM uses Crypto Engine 4.0 to authenticate images
• SBL1 jumps to start of SBL2 (Krait PBL)
SBL1
• SBL1 configures MIMEM and GMEM, then loads and authenticates the SBL2 there;
MIMEM is 192 KB, so when SBL2 grows, it will spill to GMEM
• SBL1 takes Krait out of reset
• SBL1 waits for signal from Krait SBL
• When desired signal is received, SBL1 executes RPM firmware,
which is downloaded by SBL2
• If RPM firmware image authentication/download fails, Krait SBL2 resets MSM and
enters into Boot ROM Emergency Download mode
SBL2
• After being taken out of reset, Krait jumps to start of SBL2
- Krait boot address is software-configurable via register APCS_START_ADDR
• SBL2 increases Krait clock speed
• SBL2 downloads TZ image to TZ-dedicated system IMEM
- TZ image occupies at least 188 KB in system IMEM
- TZ image sets up security environment (configures xPU, etc.)
• SBL2 authenticates TZ image
- SBL2 uses CE-4.0 to perform authentication
• SBL2 downloads RPM firmware to Code RAM and authenticates it
• SBL2 configures DDR
• SBL2 sends RPM firmware-ready signal to RPM and lets RPM continue to
execute RPM firmware
• SBL2 jumps to SBL3
SBL3
• SBL3 bumps the system clock
• SBL3 loads and authenticates APPSBL
• SBL3 waits for the RPM process ready interrupt
• Once the interrupt is coming, SBL3 jumps to APPSBL
the primary processor boots first, executing the Primary Boot Loader (PBL) from on-board ROM.
The MSM platform has the facility to force Secure Boot using the status of the FORCE_TRUSTED_BOOT Qfuse on-chip or a high-state BOOT_SCUR pin connected to GPIO95. In this mode the PBL verifies the signature of the SBL/OSBL before executing it,which verifies the REX/AMMS signature in the same way.
(AMSS is the Qualcomm radio software (radio/baseband).
(AMSS is the Advanced Mobile Subscriber Software that runs on the ARM9 CPU in our phones, it is a complete embedded OS using the L4 microkernel and controls the RF interface, power management and some other things)
PBL reads the Device Boot Loader (DBL) from the first partition of the flash memory device.
DBL is part of Qualcomm's SecureBoot, which uses cryptography to guarantee that the boot-loader images haven't been tampered with. DBL configures the Cryptographic Look-aside Processor (CLP), a dedicated cryptographic co-processor, and other hardware sufficient to load and execute the Secondary Boot Loader (SBL)
The SBL, also known as the Operating System Boot Loader (OSBL), is loaded.
It provides an Extensible Firmware Interface (EFI) -like environment for controlling the boot process.
After doing more hardware configuration including UARTs and USB (for potential remote console connections to the monitor) it loads the Applications processor Secondary Boot Loader (APPSBL) on the ARM11 applications processor
It then loads and executes the combined REX/AMSS
Finally on the ARM9 REX executes the Advanced Mobile Subscriber Software (AMSS).
After the SoC Vendor part is done the second part starts:
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
Now the OS gets loaded, and the real fun starts
Nothing is unbreakable, but MS has 20 years NT kernel dev time in it (wp8* uses the same kernel as win) and made it damn bulletproof.
the thing is that we are not even in the phone jet , No bootloader hack.
JTAG is nice but only a few will ever do that , and nobody will hack the whole OS just for JTAG that actually no one will use.
Some background information and data sheets:
The Secure Boot 3.0 Process
http://forum.xda-developers.com/showpost.php?p=31087442&postcount=5
Lots of useful documents and manuals
http://forum.xda-developers.com/showpost.php?p=24100141&postcount=1968
MSM8960 Info, Architecture and Bootloader(s)
http://forum.xda-developers.com/showthread.php?t=1856327
The Secure Boot Loaders
http://forum.xda-developers.com/showpost.php?p=30055671&postcount=241
http://forum.xda-developers.com/showpost.php?p=30056934&postcount=242
How to temporarily turn on/off Secure Boot Authentication using JTAG
http://forum.xda-developers.com/showpost.php?p=30062504&postcount=247
http://forum.xda-developers.com/showpost.php?p=30148348&postcount=296
http://wp7roottools.com/index.php/developer-blog
On the HTC 8x xboxmod found a hole, by flashing a "bad" uefi.
the phone boots into Emergency Download mode ( because its a soft brick)
This (only found on htc because it lets you flash unsigned files) "COULD" be a potential thing to explore !!!
But as you can see this is pretty dangerous to do because you actually NEED to brick your phone to get there.
next to know is that xboxmod needed to sent his phone to the repair center to repair it again !!!
Code:
• If RPM firmware image authentication/download fails, Krait SBL2 resets MSM and
enters into Boot ROM Emergency Download mode
so the conclusion of this is :
WE HAVE A LONG LONG WAY TO GO
First post updated , this post is also a Place holder for later.
Related
Hi there boys and girls ... for those interested ....
QC BQS Ana*lyzer 3.0
What is it ?
-----------
Let's call it the ultimate BQS / QC swiss knife and very special Crypto Tool (RSA Signature Calc can be used for any mobile):
BQS only :
----------
1. Load AMSS to extract files or useful infos
(EF81, E81C, EF91, SXG75, EF82, SF71, SL91, M7 or similiar ones)
Features :
Extract Infos from AMSS : USBID, Product.Nr., SVN, SwBuild, Mobiletype
Extract internal filesystem (mif,bar,sig etc. files)
Extract certificates
Extract all BMPs,GIFs,PNGs, JPGs
Extract AMSS signature bytes (if production key)
Show all file references used by mobile
2. Sim_Secure extraction/decryption (non-public)
3. Master-/Usercode/Unlock extraction and direct unlock (non-public)
All QC :
--------
1. Load Partition File to get overview about NAND/NOR structure
2. Make usage of QCs Diag Interface .... to do nice things
(Useful for any QC mobile in the world)
Standard Features :
-------------------
- Send standard diag commands or any hexadecimal command you want (database included)
- Read out all NVItems (range given)
(all that exist, more than QPST normally extracts)
- Backup and Restore all NVItems
- Read out and Dump Firmware in Memory (IRam)
- Read out complete EFS
- Switch to FTM Mode (or anything else you want)
- Get infos about phone ..... etc ..... a lot more functions
- Generate SimSecure Command to write to SimSecure using given file (may brick your phone when used without knowledge)
Bootloader / DownloadMode Features :
-------------------------------------
- Load any file to mobile at any address and execute (bootloader f.e.)
- Read out complete NAND Memory using bootloader (range given) with included MSM6250/A bootloader or any given bootloader
Usage : Take out battery, put in battery, press ON # to enter emergency mode, Execute Loader
or (with SL91,SF71 f.e.) enable FTM mode, Execute Loader
- Use any Download Mode or Bootloader Command to experiment
- Read application memory of newer Diag Ver 6 in Download Mode
- Show complete infos about used NAND after loading of Bootloader
Flasher Features :
-----------------
Flash any QC mobile (OBL Multiboot) with given bootloader
- Flash PBL (dangerous), QCSBL, QCSBL Header and Config Bits, Partition, OEMSBL, OEMSBL Header, AMSS, AMSS Header and EFS
3. Crypto Function :
-----------------
- Calculate CRC-30, SHA1 and MD4 of any file
- Bruteforce bytes to fit CRC-30 needed when qcsblhd_cfgdata.mbn was edited
- Decrypt any RSA-Message, including ASN-1 / SHA Signatures.
- Check firmware signature given Modulus and Exponent
4. Sim_Secure extraction/decryption (non-public)
5. Full Feature JTAG Interface (non-public)
Although it is still a bit buggy and things have to be speeded up ...
it is the successor of AMSS Analyzer .... but more reliable and even much faster
Planned in future :
-----------------
1. Bugfixes
2. Tooltips showing real addresses in graphical window
3. EFS2 Directory Browsing
4. Elimination of extracted files in amss.mbn for better understanding
5. Simple NVItems Editor
6. Porting NVM hack already working with JTAG to COM/USB
7. AMSS signature hack, Exploit for Signature (this will be a tough task)
8. Read out SMS / Addressbook via Diag Interface
NO UNLOCKING ! PLEASE DO NOT REQUEST. THIS PROJECT IS FOR EDUCATIONAL PURPOSES ONLY, NOT TO HARM COMPANIES FOR THEIR EFFORTS.
What we need :
----------------
- Any contribution to the project is welcome.
- Donations for new hardware and software for further development of this tool.
- We need support in programming and documentation XD
Link to the project files :
------------------------
Version 3.00 Fruit Assassin (Major Release)
http://code.google.com/p/qcbqsanalyzer/downloads/list
Cya and keep on reversing,
Viper BJK
For full source, see project homepage.
If you think my tool is useful and you would like to donate some money for further development, feel free to do so :
http://viperbjk.beepworld.de/
great stuff, I admire your work, this has been used to partially unbrick a htc titan (work in progress still, as it crashes on some bit of code in init god knows why).
Hi.
New Version supports MSM7200.
Maybe take an look.
Code:
New version 3.42 out
--------------------
What's new ?
-------------
- Find public keys in HTC SPL.nb via Cryptosearch
- Added Public Keys for [B]HTC[/B] Firmware (Diamond, Kaiser, Raphael)
- Exponent bugfixes
- New RSA Decryption interface
Feedback are welcome.
Thanx.
Best Regards
Forbidden
Your client does not have permission to get URL /p/qcbqsanalyzer/downloads/list from this server.
bad link
Link to the project files :
------------------------
Version 3.00 Fruit Assassin (Major Release)
http://code.google.com/p/qcbqsanalyzer/downloads/list
Does this software works on new phones, or is there any similar software?
This is a research & development thread for building your own bootloaders on a
number of modern Qualcomm based devices, utilizing extracted partitions and
corresponding partition table information. We'll focus in particular on those
devices using the Snapdragon SoC/PoP chipset.
Code:
Thread difficulty: [B][COLOR=Red]Hard[/COLOR][/B]
Thread type: Development
Thread completeness: Fair
Building your own Bootloaders on Qualcomm Devices
Table of Content:
Introduction
Qualcomm/Intel HEX files
<WIP> QFIT (Qualcomm Factory Image Tools)
<WIP> The MBR Image
<TBD> BoToX (Bootloader Tool Box)
<WIP> Building for Windows Phone 8
<TBA> Compiling Bootloaders
<WIP> References
INTRODUCTION
All modern Qualcomm mobile chipsets contain some functionality for sideloading
binary code from an external source in case the normal boot procedure fails or
is interrupted by some other HW signal, like JTAG or other JIG debug
connection. In addition this side loading functionality is crucial for the
programming and formatting of additional memory devices like eMMC and SD cards
that are external to the processor and it's accompanying PoP memory. It is
also used by OEMs to revive soft-bricked devices and update the many
bootloaders used in the Qualcomm bootloader chain. However, all these features
and their various functionality are closely guarded secrets usually kept from
the public by very strict NDA for their company employees. Thus it has been
very difficult for the developer community to try to understand, use and
benefit from these most useful functions. Instead the dark side of mobile
phone community have made continuous profits in reversing the manufacturer
schemes by providing their own hacks and programs to offer mobile owners
various solutions for a charge, that is often out of proportion for what is
actually done. This is especially true for services requiring debricking by
various JIGs (such as the proprietary Anyway Jig and various JTAG solutions.)
All these solution rely on the possession of some inside information about the
device in question.
This thread is an attempt to alleviate this situation and allow anyone who
wishes, to freely flash and take charge of their own hardware, in the true
spirit of the XDA community. Here I will present information about how
Qualcomm put together their own bootloaders and how you could do the same, if
you only had the source code or talent to write your own or modify already
existing such. Although, there is one big hitch. Most new chipsets are using
a very secure authentication scheme (Secure Boot 3.0) to prevent
non-developers from flashing and using arbitrary boot code.
The information herein have been collected from older available Qualcomm tools
such as QPST and QXDM, and from pieces of their documents found around the
internet. Another important and challenging source have been the many Chinese
websites where people have managed to get some of this working and actually
bothered writing/blogging about it. Thank you China!
I will not go into details about the various bootloaders as they are already
covered elsewhere, for example, in this thread. I have also chosen to focus
primarily on the Qualcomm Snapdragon processor/modem SoC series, as they are
the most popular chips used in most mid- to upper-level smartphones today.
These devices typically include the MSM8x60 series consisting of the widely
popular MSM8660 and MSM8960 SoCs, currently found around the world. Another
highly relevant chipset is that of MSM8260A which is found in many Windows
Phone's, in particular in WP8.
...REFERENCES
<WIP>==================================================
If you find any errors or have any relevant additional information
that can be important for the correctness and content of this thread.
Please let me know by either posting here or sending me a PM.
Also, please do not ask any questions that is not of direct relevance
or help in the discussions in this thread . They will not be answered
and removed.
==================================================
Enjoy!
Qualcomm/Intel HEX files
This is a text-based (ASCII) file format originally introduced by Intel to
distribute PROM code, that include error checking for redundancy. Today
Qualcomm use this file format to distribute their modem/processor boot code
used in downloading bootloaders in the OEM build-processes or for emergency
download modes etc. There are several dozens of variations on the HEX format,
so we will not go into the details of other formats or uses, but only for that
used in the Qualcomm bootchain.
To convert the Qualcomm provided Intel-HEX files into binaries, you can either
use the simple pre-compiled windows and linux binary hex2bin (src), or you can
compile the much more flexible and complete EPROM file-converter utilities of
srecord, which can handle many more HEX formats including hex-diffing and
hex-merging etc. One of the Qualcomm image build "toolkit" programs, the
"emmcswdownload.exe" already contain a hex-to-bin converter, but it is usually
appending more than one binary file as described in the required XML partition
file. For details about this see the next section about QFIT.
Next we jump right into describing the Qualcomm (aka Intel-32) HEX-file
format. The content of a typical HEX-file, let's say the MPRG8660.HEX are as
follows:
Code:
:020000042A00D0
:10000000D1DC4B843410D773FFFFFFFFFFFFFFFFEE
:10001000FFFFFFFF500000005000002A348802005C
:10002000348802008488022A000000008488022AA2
...
:108850001CAF012A000000005CC4012A8CC4012A5C
:1088600000000000FCBF012AFCC0012A04C0012A4C
:10887000BCC2012AC4C2012ACCC2012A00000000E5
:0488800000000000F4
:040000052A000000CD
:00000001FF
Let's break this down. First things to know are that:
Each line is a record.
Hexadecimal values are always in uppercase.
The sum of all the bytes in each record should be 00 (modulo 256).
So for example, a typical record can be broken down as:
Code:
[SIZE=2]
:[B][COLOR=DarkRed]10[/COLOR]0020[COLOR=Blue]00[/COLOR][/B][COLOR=Green]348802008488022A000000008488022A[/COLOR][COLOR=Red][B]A2[/B][/COLOR]
: 10 0020 00 348802008488022A000000008488022A A2[/SIZE] [SIZE=2]
| | | | ----------------+--------------- |
| | | | | +-- Checksum (1 byte)
| | | | +-------------------- Data (0-255 bytes, here 16)
| | | +--------------------------------------- Record type (1 byte)
| | +------------------------------------------- Address (2 bytes)
| +----------------------------------------------- Data Byte Count (1 byte, here 16)
+-------------------------------------------------- Start of record delimiter[/SIZE]
There are 6 record types defined (for Intel-32 HEX):
'00' = Data Record
'01' = End Of File (EOF) Record
'02' = Extended Segment Address Record
'03' = Start Segment Address Record
'04' = Extended Linear Address Record
'05' = Start Linear Address Record
But only 4 are used for Qualcomm processor/modem HEX-files:
00: Data Record
01: End Of File (EOF) Record
04: Extended Linear Address Record
05: Start Linear Address Record
Where "04" (Extended Linear Address Record) allow for 32 bit addressing (up to
4GiB). The address field is 0000, the byte count is 02. The two data bytes
(two hex digit pairs in big-endian order) represent the upper 16 bits of the
32 bit address for all subsequent 00 type records until the next 04 type
record comes. If there is not a 04 type record, the upper 16 bits default to
0000. To get the absolute address for subsequent 00 type records, the address
specified by the data field of the most recent 04 record is added to the 00
record addresses.
While the "05" (Start Linear Address Record), contain the address that is
loaded directly into the program counter (PC / R15) of the ARM processor. The
address field is 0000, the byte count is 04. The 4 data bytes represent the
32-bit value loaded into the register.
NOTE: The data field endianness may be byte-swapped.
Qualcomm use the following convention for naming their HEX boot-loader
"programmer" files. This is especially true when used in conjunction with
their emmcswdownload.exe. (See this section.)
yPRGxxxx.HEX
where "y" is one of the following:
Code:
[SIZE=2]N = NAND
A = NOR
M = eMMC
arm = Is used to bypass automatic selection by QPST by renaming a custom version to "armprg.hex"
flash = ??
[/SIZE]
<< Here Be More Dragons >>
<< Here Be Snap Dragons 2 >>
<< Here Be Snap Dragons 3 >>
<< Here Be Snap Dragons 4 >>
<< Here Be Snap Dragons 5 >>
<< Here Be Snap Dragons 6 >>
one more awesome guide from E:V:A
It would be cool if someone made a synalysis grammar for the hex codes E:V:A documented above.
For those of us hacking on our Mac OS X machines.
I'm closing this thread until I can actually fulfill my promises.
Sorry! Stay tuned.
I wanted to create a thread so as to report any unique findings from the internet realm regarding the Nvidia Tegra Note OEM Tablet.
Please post your own discoveries and updates!!!
Bootloader Partition Images
WARNING ONLY ADJUST PARTITIONS IF YOUR DEVICE HAS A WORKING BOOTLOADER WITH FASTBOOT
(Some early devices have a limited bootloader with no menu and no fastboot mode. If this is so, do not modify your partitions unless certain of your actions. A bootloader is a special device starting partition that later starts the extended boot partition. The bootloader should give fastboot access allowing you to re-partition or correct mistakes.)
Buttons: Power-Button + Top-Volume. Release after a few second..
= Bootloader menu should show, allowing fastboot 'on' switch
= or Blank Screen Bootloader possibly with fastboot (read above warning)
To partition your device you do need it unlocked it. The command below should do this. You need a fastboot commandline service which is usually supplied from the bootloader level. The computer used to control the changes also needs its own ADB and FASTBOOT protocol utilities.
After the below command is issued your device will reboot and user data wiped! You device should then be open for partition changes.
Code:
fastboot oem unlock
Recovery Partition Images
TWRP Recovery (Team Win Recovery Project)
Shaky Builds and Source Code
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
You can Root your device by installing SuperSu from the recovery mode if the zip installer allows unsigned zips.
Vendor System Recovery Images
https://developer.nvidia.com/gameworksdownload
Vendor Released Over-The-Air Based Updates
Consider:Updates can remove apps that have been moved into system partition! Example AdAway, SuperSu, Link2SD, DroidWall, etc.
Files are ripped from the below directory once downloaded and before confirming an upgrade;
Code:
/sdcard/nvidia/app/ota/download/ROM/
or direct link;
Code:
/storage/sdcard0/nvidia/app/ota/download/ROM/
(July, 2015 OTA 5.1 Lollipop. EVGA Version 3.0) 446.3MB
tegra_note_7_system_update_3.0__5.1.zip
ERROR NOTICE. The first release of lollipop consumes most of the system folder. Those trying to install further items will experience an out of storage error. A remedy is to use a root mode utility like Link2sd to remove unwanted system apps.
Example
Code:
Filesystem Size Used Free Blksize
/dev 444.8M 40.0K 444.8M 4096
/sys/fs/cgroup 444.8M 12.0K 444.8M 4096
/mnt/asec 444.8M 0.0K 444.8M 4096
/mnt/obb 444.8M 0.0K 444.8M 4096
/system 755.9M 754.3M 1.6M 4096 <<<
/cache 755.9M 12.8M 743.2M 4096
/data 12.6G 1.0G 11.6G 4096
/mnt/factory 15.7M 4.0M 11.7M 4096
/lbh 252.0M 51.0M 201.0M 4096
USB
Device USB Coding
Code:
ID 0955:7535 Rev. 0102 NVidia Corp. APX
ID 0955:CF00 Rev. 0232 NVidia Tegra Note
Linux users are well supported for USB access. They also can easily install latest ADB and Fastboot from distribution repositories.
ADB and Fastboot (Client) Executables
XDA-Developers Thread
Microsoft Windows USB Drivers from Nvidia
NvidiaUSBDrivers_Rel20131017
UART Ability?
After an inspection I can't see any points to which one could easily tap into an 'exposed console' with a USB UART setup. This could indicate there is no allocation to access a terminal from a tapped in serial port or pins off the minute and well protected chipsets. Obviously those that want to software repair these tablets have access to NvFlash/APX mode, in dire situations.
NVFLASH/APX
NvFlash_v3p08p1700_RipV2 (Executables for; Linux, Mac, Microsoft)
Buttons: Power-Button + Top-Volume + Bottom-Volume. Release Power-Button only once you see branding. Release others after few seconds.
= Screen should remain black. USB connection should see Nvidia APX Device (USB ID 0955:7535).
Linux Users should copy their executable to the below directory so that it's globally available from all bash points
Code:
/usr/local/bin
NVFLASH/APX BASED RECOVERY (POSSIBLE FIX FOR BRICKED DEVICES)
Advent Computers APX Recovery
Linux users can add the nvflash executables shared above. Put the device in APX mode and issue the below command. You can replace the images in the folder to suit a different recovery or boot, etc.
Window's users can execute 'flash_signed.bat' from the command line to start the process. If you get ID errors, then perform the Linux command below without the 'sudo' section at front.
Unplug any other device. Do not use this unless your tablet is bricked as it will tailor the tablet to a particular brand and therefore hardware may not work correctly.
Code:
sudo nvflash --blob blob.bin --bct flash_signed.bct --setbct --odmdata 0x4069E000 --odm limitedpowermode --configfile flash_signed.cfg --create --bl bootloader_signed.bin --reset normal 0
Standard Blob Image (includes unpacked items)
TegraNote_blobrip_4p4rip.zip
TegraNote_blobrip_4p3p1p1.zip
Standard Boot Image (includes unpacked items)
TegraNote_bootimg_4p4rip.zip
TegraNote_bootimg_4p3p1rip.zip
RESTORE DEVICE WITH FASTBOOT IMAGES
Rootjunkysdl's Firmware Downloads
KERNEL SOURCE
http://nv-tegra.nvidia.com/gitweb/
Guides
Tomsgt has made various video tutorials on how to root-mode your device, among other topic. See here for videos..
Tom hosts his own array of core files;
Rootjunkysdl.com
ALTERNATIVE SYSTEMS
CHALLENGE CHALLENGE CHALLENGE CHALLENGE CHALLENGE
No one has yet customised another operating system for the Tegra Note 7.
* Ubuntu Touch
* Firefox OS
* Sailfish
* Plasma Active
* Tizen
Known Vendors of the Tegra Note Tablet
Advent Tegra Note 7 (http://www.adventcomputers.co.uk/)
Colorful Tegra Note 7 (http://en.colorful.cn/)
Colorfly T709 (?)
EVGA Tegra Note 7 (http://www.evga.com/)
Gigabyte Tegra Note 7(http://www.gigabyte.com.au/)
Gradiente Tegra Note 7(http://www.gradiente.com.br/)
Granville Flyone Homecare Tegra Note 7 P1640 (http://www.huiweipad.com/)
PNY Tegra Note 7 (http://www.pny.com/)
Oysters Tegra Note 7 (?)
XOLO Play Tegra Note 7 (http://www.xolo.in/xolo-play-tegra-note/)
Zotec Tegra Note 7 (http://www.zotac.com/)
***** POWER USERS *****
Install F-Doid App Store
F-droid is a safe repository of open source code Android Apps. Many Apps unavailable from Google's Store.
Recommend
~~~~~~~~~~
* AdAway (Removes Ads from Apps by blocking content)
* Hackers Keyboard
* AFWall (IPTable Firewall)
* VLC Player (official release) VideoLan
Xposed Installer
Xposed is a framework for modules that can change the behavior of the system and apps without touching any APKs. That's great because it means that modules can work for different versions and even ROMs without any changes (as long as the original code was not changed too much). It's also easy to undo. As all changes are done in the memory, you just need to deactivate the module and reboot to get your original system back. There are many other advantages, but here is just one more: Multiple modules can do changes to the same part of the system or app. With modified APKs, you to decide for one. No way to combine them, unless the author builds multiple APKs with different combinations.
.
Installing Google Play on Nvidia Tegra Note.
0. Get a powerful Recovery partition image on your Tablet.
1. Obtain a Google Apps pack, usually termed GAPPS suited to your Android version.
2. Use Recovery's install zip mode to install.
Lollipop Fresh Installation + Tweaking
(for those with basic knowledge of Android manipulation)
* Make sure your tablet is OEM unlocked. Then flash a sophisticated recover image version like TWRP. This will allow root-mode enabling via a patch.
To obtain fastboot-mode, you need another computer as the debugging/command platform via USB. Holding the POWER-BUTTON and UP-VOLUME on the boot and shortly after releasing the POWER-BUTTON and later the other, will bring up a bootloader menu that can deploy fastboot protocol/mode or get to recovery-mode. This is where you can flash, oem unlock, and erase partitions, with the data coming from your command-platform. You can't format nor erase partitions till you oem-unlock the device, noting an oem unlock clears your device's user data.
Your command-platform (controlling computer used to upgrade the Tegra Note) also needs its own version of ADB (Android Debugging Bridge) and FASTBOOT protocols so as to be able to talk and understand the conversation over the USB.
RootJunky also has versions of TWRP and other recovery image versions.
* Put the tablet into fastboot-mode and flash RootJunky's shared Lollipop restore image instead of the upgrade over the air (OTA). Good idea to erase particular partition before flashing.
* Boot to the recovery stage. Install latest SuperSu.zip using sideloader or having it already on a SD. This will enable root mode.
https://download.chainfire.eu/740/SuperSU (Get Beta if available.)
* Start system. Remove Apps from system partition unneeded, or that can be moved or installed to user directory instead. This frees up vital space. Example Lollipop only leaves a few megabytes left in the system partition after installation. Consider using Link2SD. Example get Google+, Google Play, Google Magazine, etc into the user partition and any other big App off your system partition. The system partition should only have important apps needed to be retained if a factory wipe is enacted.
* Then go through all your system settings make sure you tweak them to suit both power saving and your own desires.
* Use a start-up tool like ES Task Manager to remove apps starting that don't need to be running from system boot.
* Install all Google Apps wanted. This can help to configure the system how it's meant to be.
* You could install Google Now into the system partition and remove the Launcher3 App.
* The system should now run smooth and use little battery.
.
Nice bro....keep me posted... Pre ordered xolo tegra note
Edit : got my tegra note 7
Wow fantastic find! Seriously psyched for the recovery. One step closer to roms!
Very good
Enviado do meu Moto X usando Tapatalk
[RESERVED]
.
[RESERVED]
I can not download the files to install the Play store ... Somebody help me?
Enviado do meu Moto X usando Tapatalk
ezequielbsb said:
I can not download the files to install the Play store ... Somebody help me?
Enviado do meu Moto X usando Tapatalk
Click to expand...
Click to collapse
http://forum.xda-developers.com/showthread.php?t=2397942
Get 4.3 versions since still Jellybean.
The Cydia Impactor just successfully rooted my Slate 8 (Tegra 4 platform, v. similar to the Note)
Might be worth a go?
Discussed here:
http://forum.xda-developers.com/showthread.php?t=2386677
I am looking for the drivers for this device I am on windows and cant get the adb drivers installed. Please Help
Cydia Impactor
roustabout said:
The Cydia Impactor just successfully rooted my Slate 8 (Tegra 4 platform, v. similar to the Note)
Might be worth a go?
Discussed here:
http://forum.xda-developers.com/showthread.php?t=2386677
Click to expand...
Click to collapse
Worked within 20 seconds. Even loaded the USB drivers for me!
Tomsgt said:
I am looking for the drivers for this device I am on windows and cant get the adb drivers installed. Please Help
Click to expand...
Click to collapse
I had the same problem when I was trying to use Helium to restore some apps. Windows 7 64 bit was able to install two of the three component 'parts' of the tablet but not the final driver. After the device installer had finished in opened Control Panel on the PC and then the Device Manager. The Note should be listed in Device Manager with a yellow exclamation mark. Right click on it and select 'update driver'. In the next window choose to install the driver yourself, then opt to choose from a list of drivers manually. Next choose the entry called 'Android Phone', then select 'composite ADB device' from the list on the right. I'm saying this from memory I may have missed a step so tread carefully. I already had the desktop Helium app installed on my PC which installation ADB drivers (they'll appear under Clockwork Mod in the driver list I mentioned). I'm away from my PC for now so it'll be a while before I can refine these instructions.
These are just basic observations, but I've playing around with the Note connected to a TV and USB hub etc
http://forum.xda-developers.com/showthread.php?p=48416270#post48416270
I haven't tried wireless display yet. I hope to by a Miracast/DLNA compatible adapter for my TV soon so I can see what works. Full screen mirroring is what I'm aiming for.
becksvector said:
Worked within 20 seconds. Even loaded the USB drivers for me!
Click to expand...
Click to collapse
Did you already have the drivers downloaded and installed to your machine, or did it use its own drivers?
that'd be great if folks no longer need to get the drivers manually set up and override the crying about mismatches.
My Tegra Note Homecare Fly One does not connect on my PC ..
Does anyone have the drivers?
thank you
I made a discovery.....Battery drain issue.....battery drains really fast even when on power save settings with prism and running on 1 core..... Even when im not even using it like the memory is clean and cache is clear and everything.......After 100% charge it barely lasts me 6 hours of a day at college when im using it on and off....Like word processing and taking a couple of photos thats it.....
So after a few days since I got it the battery started getting better and better......So what was 6 hours of on and off usage of my tablet is not almost 24 hours of the same kinds of usage with still 45% ish of battery remainig!!!!! So I guess the way we charge our devices makes a difference as well....Batery doctor has a feature that charges the device in a specific way like as fast as possible to 80% then slows current down to prelong battery life. I want to see how long my battery will last and will upload screenshots while im doing so.....Right now it is 10:26 pm and battery is at 43% with 22 hours and 2 mins on battery.
Working with a Developer on CWM recovery for this device
Root video if anyone needs help
http://youtu.be/0521gm9ajz4
Been looking for a game stream apk or mod if anyone has it.
roustabout said:
Did you already have the drivers downloaded and installed to your machine, or did it use its own drivers?
that'd be great if folks no longer need to get the drivers manually set up and override the crying about mismatches.
Click to expand...
Click to collapse
I had some element of a connection as my computer could see the tablet for transferring media. But after pressing the USB button I had the lot!
Advanced Box
Mostly this tool contains
AABox Specialification No need root for all adb options. Need Root Only for Send Files to system and build.prop editor Pattern unlock
Update File New 20/11/2017 17.09v Direct from server official no Serial No Passwords
# Features #
Frp Unlock tool
Adb Toolkit
Flashing and Recovery
Boot loop and boot repairs
FRP Unlock Qual, SPD, SPRD, MTK,
Aboot and boot img adb enable
Fastboot toolkit
First Time Oneclick and frp add gmail for 6.0.1 +
SNAPSHOT
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
Supported Vendor and ID
Acer 0502, ASUS 0b05, Dell 413c, Foxconn 0489, Fujitsu 04c5, Fujitsu, Toshib 04c5 ,Garmin , Asus 091e, Google 18d1, Haier201E,
Hisense109b, HTC 0bb4, Huawei 12d1,Intel 8087,K-Touch 24e3,KT Tech 2116,Kyocera 0482,Lenovo 17ef,LG 1004,Motorola 22b8,
MTK 0e8d,NEC 0409,Nook 2080,Nvidia 0955,OTGV 257,Pantech 10a9,Pegatron 1d4d,Philips 0471,PMC-Sierra 04da,
Qualcomm 05c6,SK Telesys 1f53,Samsung 04e8,Sharp 04dd,Sony 054c,Sony Ericsson 0fce,Sony Mobile Communications 0fce,Teleepoch 2340,Toshiba 0930,ZTE 19d2,
Version Log List in order
1. Artiven Box 1.148.0 Alpha [ 01-08-2014 ]
# First Release
# Fixed fastboot codes for lg
# Fixed bootloader unlock
# New tusk
2. Artiven Box 1.149.6 Beta [ 06-09-2014 ]
# Fixed Auto close
# Fixed backup options
# Fixed outfixed apps
# Root for mtk updated and update zip
# data wipe
# pattern unlock
# flash img, cwm flashing, reboot mode all.
3. Aabox 2 stable (CMD) Commander [ 05-05-2015 ]
How to install..!
1) a) You must install aabox alpha or suite pack 1.148 or 149
b) download aabox 2c updater 2.157
2) unrar or unzip file you will get only 1 exe file.
2) b) copy it to c:\artiven\aabox\ = replace it with old file or paste just and open it to use...
3) when open it as adminstrator .. use get full access to aabox.
# Update Pack for 1.149.6
# 5 features Added
4. AABOX ( 2 16.1 ) ( Dardbread ) [ 2016.11.11 ]
After a big Gap and nearly 8 months from CMD Screen-shots at fb page [
# Fastboot Flash added
# Sony Unlock Bootloader Tested and Success
# Sony feature added
# Dir Style Changed (because making a windows UI - bt dont know when)
4. AABOX ( 2017 - 17.1v ) ( Exyno ) [ 2017.1.10]
After along Push- ViT Team Build a GUI based Tool
# New Unlocks and Repair Tools
# Lenovo Features Added
# MT6592 Added
# Dir Search in Mtk for unbooting to boot)
# Auto Repair
# IP Connect Adb
# adb full Controls
# Easy for Mobile Repairs
# ADB Installers-Reboot-Boot files-Find Phone
# AABOx Flasher v2
# Fastboot recovery Fixed
Download link will be at 2017-01-10
5. AABOX ( 2017 - 17.6v ) ( Froyo ) [ 2017.6.15]
All in 1 adb and frp tool
# MTK chipsets added
# Lenovo A319 Features Added
# FRP unlock Knox 2.6 Added
# Com port added)
# mtk frp unlock
# Frp 6.0.1 for samsung
# adb full Control Spreadrum
# Fixed adb bugs and hanging
# ADB Installers
# AABOx Frp
# Fastboot boot.bin
AABox2 ( 2017 - 17.7v ) ( GoD ) [ 2017.8.20]
All in 1 adb and frp tool
#SPD Surported
#MTK Wipe ADDED
#More Android devices scripts
#UI Changes with High powerfull expoits
#Adb.exe bug fix
#Android Direct kernel inject expoits
#Power to com ports SAM and LG QUALCOMM
#UNLOCK via Bootloader and FrP
#MTK Module alpha version with pack
AABox2 ( 2017 - 17.7.1v ) ( GoD ) [ 2017.8.30] Only Update
All in 1 adb and frp tool
#re connect adb bug fixed
#all gui overlap fixed
#Radio-button stay fixed
#CMD pop up freeze fixed
#error 016 at frp lenovo fixed
AABox2 ( 2017 - 17.8v ) ( HotFire ) [ 2017.9.21] Full StandaloneVersion
#Box Detect Bug Fixed
#Base board detector added
#FRP KNOX 2.7 bypass added
#FRP gmail Browser bypass added
#adb disconnect bug fixed
#Added new dll files for expoit
#Script errors fixed
#.Net updated for 4.X +
#Com Port dial helper for FRP bug fixed
#Stability application improved
#New Testing coding added for trace KNOX
#System hack for gmail bypass apk added
AABOX2 17.8.1v Hotfire Standalone
---------------------------------
#Expoit 2.3v for KNOX 2.6 updated
#Expoit Andoid 6.0.1 Fixed errors
#ADB net framework error fixed
#Browser Gmail added new scripts
#Fixed error 0x023 and 0x024
#Refreshed File Builds
AABox2 ( 2017 - 17.09v ) ( HotFire 2 ) [ 2017.11.20] Full StandaloneVersion
#New UI Updated
#fresh Full version Files added
#MTK Module 0.3v added 1711v Build
#brom updated for boot.img repack
#AndroidCtrl.dll updated
#Welcome Screen added with online
#Keyboard for android adb
#Hard and soft keys added via adb
#Update.exe added for online
#Online Script fixed
#Needed Internet
#2017 Frp Scripts added online
17.09v TODAY
Update File New 20/11/2017 17.09v Direct from server official no Serial No Passwords
Next VerSion :
Release [2017-xx] | Codename [ --- ] | Build [17xxx] | ViT [xxx]
17.8 RELEASE TODAY UPDATED TO XDA AND DOWNLOAD LINKS WILL BE AVAILABLE ON 20-11-17 ONWARDSREAD POST 2nd before install or downloading for Help
Official Site
Official Facebook Page
All Downloads And Version Here at
This tool/box/software build for helping a dev or repairer for more experience and shorted for cmd long commands. If you use this tool u will never use a software box for frp or system repairs, most of features added for easy tasking. Reading and knowing it would help to repair as said and must read 2nd Post for any details
This tool is also being continued in Win32 GUI tool As a DEVPROJECT
IN XDA Forum - Click here to Link in xda --------- AABOX New Page download
Wait:: Note Before Download
Read 2nd post before download... always download latest download available below AAbox2 17.09v is a stable all in one installer for now!Dear Friends i would like see my thanks been pressed.. If you like to have more versions with more features Please give me a thank
Thank You
THANK you
I'm trying to unlock bootloader and root a Kyocera C6740 Hydro Wave.. Can I use this for that?
thnx
thnx
thank you, i have mtk and try to unlock frp. and it goes ok and success.
Dear Dev.,
thanks that you helped a lot of People with this Toolbox.
Is there anything new in work or comming?
Asking because for Oreo it doesnt seem to work for me, because of Stage3-Bootbin/loader, and a FW-Downgrade is not possible for me?! oO
Thx in advance for your Reply!
Greetz - Tox
https://www.virustotal.com/#/file/2...132a10354bfeafec31b134f33994aba28be/detection warning
hassanhassan said:
https://www.virustotal.com/#/file/2...132a10354bfeafec31b134f33994aba28be/detection warning
Click to expand...
Click to collapse
I was also thinking how in fiddle f*ck is this legal.
Can't download. It just keeps sending me to a page that asks to send me notifications over and over again.
Thread Closed.
Thanks
SacredDeviL666.
Hi all xda users
We previously released v1.0.0 version of this tool on this topic, And many users were demanding to make a new version of the tool
Today we release new version of our software gsd android tool v1.0.1 with new ui and more ability , You can follow the Tools capabilities with this Topic
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
Gsd android tool is a tool for Android phone service
The unique features of this tool will definitely attract your attention
Click to expand...
Click to collapse
Impact Tools features
Part of samsung > Unlock This option is called Samsung, but you can also use it for other Brand.
1 - scan and full information In Selected Mode
2 - Reset Frp Adb Mode
3 - Reset Frp dial Mode
4 - Bypass All Screen Lock In Frp = On Or of and Oem = on Or Of encrypted data partition and uncrypted Need Flash Eng-root
5 - Bypass All Screen Lock In Adb Mode = need Root Access
6 - Bypass All Screen Lock In Twrp Mode = No need Root and More ...
7 - Bypass All Screen Lock In sideload Mode = Custom Recovery Data Modification Method
8 - Bypass All Screen Lock In Sildeload Mode = Custom Recovery Need (encrypted data Partition)
9 - Important Make RvSecuRity use Boot.img for Unlock = No need Root Or any Think Just Need Boot.img
What is RvSecuRitY?
We succeeded in 2014 by modifying the kernel, unlocking the Android device without clearing the data
Then we began mass production of these kernels for each Android device We put the names of these kernels "RvSecuRitY" (Remove Security)
We added the button for making these kernels to this software. you can drop boot.img to input section and get remove screen lock kernel very easy And write it by flasher(Odin , Spflashtool, and more ... ) on the device
This tool unlock all encrypted data partition w/o data loss
This method no need to twrp or root , you just need orginal boot.img (that you can extract from orginal firmware)
Click to expand...
Click to collapse
samsung > Android Part You can use some of the options for this brand for other brands.
1 - Read Full Information
2 - exit Safe And Factory Mode = Need Root Access
3 - Full Format Device = Need Root Access
4 - enable Multi Language Samsung = Need Root access
5 - ٍٍEnable Call recording (The main functionality hidden in Samsung.)= Need Root access
6 - Enable Blacklist (The main functionality hidden in Samsung.) = need root Access
7 - ٍEnable Hardware Version In About Phone(The main functionality hidden in Samsung.) = Need Root Access
8 - disable update System Notification = Need Root access
9 - disable Anti-Malware Application Samsung = need Root Access
10 - Enable Camera Shutter (The main functionality hidden in Samsung.)
11 - reboot Device In Normal , download , recovery , Bootloader Mode
12 - Write File (flash) In sideload Mode
13 - Important Read (backup) automatically boot , cache , efs , hidden , param , recovery , system partition = dd backup in Adb Mode Need Root Access
14 - Important Restore (backup) automatically boot , cache , efs , hidden , param , recovery , system partition = dd backup restore in Adb Mode Need Root Access
Click to expand...
Click to collapse
Other Brands > Main Menu
1 - Read Full Information on Device = Adb Mode
2 - Read Package Name System and Non=system Applocation = adb mode
3 - Bypass all Screen Lock = Need Adb and Root Access
4 - Full Format Device = adb Mode Need Root Access
5 - Enable Multi Language Htc Devices = adb Mode Need Root Access
6 - Important Get Length and Begin Address For Reset Frp Mediatek Devices (you can unlock Frp by using Length and Begin Address)
7 - Backup Nvrm Mediatek Device = adb mode Need Root Access
8 - write Nvrm Mediatek Backup = adb Mode Need Root Accesss
9 - Important
10 - adb Reboot Device To Edl mode , recovery , Fastboot , Normal Mode
11 - Find Country Device Use imei Phone
Click to expand...
Click to collapse
Other Brand > Fastboot Part
1 - Read Full Information Device !
2 - Read Full Information Hisilicon Devices Emmc
3 - Frp Reset = Need Bootloader Unlocked
4 - Full Format Device = Need Bootloader Unlock
5 - Relock Bootloader Unlocked
6 - Erase Partition Menu (Erase Boot , Recovery ,System , Data ,cache Partition)
7 - unlock Bootloader menu (Unlock Bootloader Use Code Sony , Huawei and more ... and Unlock Bootloader Htc Device Use Unlock.bin)
8 - reboot fastboot in edl mode , bootloader , RUU , Normal Mode
9 - Flash Single File + Erase (Flash boot , recovery , system , splash , radio , data )
10 - advanced Menu Flasher (Flash Multi file zip File , Boot , Recovery , Recovery2 , system , data , splash , radio , Modem , Cache , cust , Fastboot , Nvme files)
11 - Nokia X , Xl , X+ Flasher Menu (system , boot , recovery , variant , data , cache , Preload)
Click to expand...
Click to collapse
Important Developer Tools > System.img Tools
1 - Read Full Information System.img File
2 - Unpack any System.img 2.3 to 7.x
3 - Repack System Folder 2.3 to 7.x
4 - Convert Sparse Header System.img To 32
5 - Make System.img Flashable In flashers On You Device (Need Root Access)
Click to expand...
Click to collapse
Important Developer Tools > kernel Tools
1 - Unpack Recovery , Boot.img
2 - Repack Unpacked Kernel
3 - Convert File_Contexts.bin To File_Contexts For Repack system Extracted Folder
4 - Important Make RvSecurity Kernel For Bypass All Code = Need Boot.img
5 - Make adb Enabler Kernel = need boot.img
6 - Important make Pre-root Kernel (Chainfire Instructions) = need Boot.img
7 - Make Dm-verity Error Fixer = need Boot.img
Click to expand...
Click to collapse
End of capability definition
To help you use this tool , We added a "Tooltip" for guidance , You can move your mouse over the button and see the functionality of the button.
If I had an empty time. In the future, I will try to get the full tutorial on how to use this tool in the next section
If you have any problems, please report this topic . This tool is portable Version No Need Install
Prerequisite for using this software:
NetFramework3.5
download links :
Gsd_Android_Tool_V1.0.1_Release_Portable
MediaFire is a simple to use free service that lets you put all your photos, documents, music, and video in a single place so you can access them anywhere and share them everywhere.
www.mediafire.com
enjoy.:highfive:
asgharSo said:
Hi all xda users
We previously released v1.0.0 version of this tool on this topic, And many users were demanding to make a new version of the tool
Today we release new version of our software gsd android tool v1.0.1 with new ui and more ability , You can follow the Tools capabilities with this Topic
Impact Tools features
Part of samsung > Unlock This option is called Samsung, but you can also use it for other Brand.
samsung > Android Part You can use some of the options for this brand for other brands.
Other Brands > Main Menu
Other Brand > Fastboot Part
Important Developer Tools > System.img Tools
Important Developer Tools > kernel Tools
End of capability definition
To help you use this tool , We added a "Tooltip" for guidance , You can move your mouse over the button and see the functionality of the button.:angel:
If I had an empty time. In the future, I will try to get the full tutorial on how to use this tool in the next section
If you have any problems, please report this topic . This tool is portable Version No Need Install
Prerequisite for using this software:
NetFramework3.5
ِDonate Me
download links :
Gsd Android Tool V1.0.1 Release Download - Mediafire Link
Gsd Android Tool V1.0.1 Release Download - gsm-developers Link
Gsd Android Tool V1.0.1 Release Download - 4Shared Link
enjoy.:highfive:
Click to expand...
Click to collapse
thank you so much for the good tools ??
9jarom said:
it's a Great Tool but nothing new
...only if it can remove Samsung frp 7.0 in download mode or switch from MTP to ADB
Click to expand...
Click to collapse
hi dear
This tool has better functionality
unlock s6,s7,s8 one5 ,not5 and more without losing data in the case of frp = on and oem = on
And there are dozens of other features that are not included in any of the free tools.
thanks
problemathic said:
downloaded it but cant use it. just having the tool is only loading. why?
Click to expand...
Click to collapse
if solutions not work for you,use this tool
Replace this tool on gsd android tool.exe
Code:
http://www.mediafire.com/file/tn8x4s4ecen5cew/Gsd%20Android%20Tool.zip
Very Well Crafted....Kudos!
Having tinkered with well over a dozen similar tools over the past couple of years....I can only say.....Kudos to all involved in this project! It is very well crafted indeed and covers a very respectable gamut of tools while managing to be quite expeditious throughout the process. Most importantly...it works like a Swiss watch....precisely and reliably. Are there other things it could do?...Well...that's like asking a muscle car owner if there are any other bolt-ons his car could accomodate....right?
Again...Awesome Job!!...but a wise man once told me...when you start to break ahead of the pack...that's when you need to run twice as fast....
asgharSo said:
Hi all xda users
We previously released v1.0.0 version of this tool on this topic, And many users were demanding to make a new version of the tool
Today we release new version of our software gsd android tool v1.0.1 with new ui and more ability , You can follow the Tools capabilities with this Topic
Impact Tools features
Part of samsung > Unlock This option is called Samsung, but you can also use it for other Brand.
samsung > Android Part You can use some of the options for this brand for other brands.
Other Brands > Main Menu
Other Brand > Fastboot Part
Important Developer Tools > System.img Tools
Important Developer Tools > kernel Tools
End of capability definition
To help you use this tool , We added a "Tooltip" for guidance , You can move your mouse over the button and see the functionality of the button.:angel:
If I had an empty time. In the future, I will try to get the full tutorial on how to use this tool in the next section
If you have any problems, please report this topic . This tool is portable Version No Need Install
Prerequisite for using this software:
NetFramework3.5
ِDonate Me
download links :
Gsd Android Tool V1.0.1 Release Download - gsm-developers Link
Gsd Android Tool V1.0.1 Release Download - 4Shared Link
enjoy.:highfive:
Click to expand...
Click to collapse
the greatest free and paid tools for samsung i had seen ever!!!
a great thanks to you brother:good::laugh:
Open Source
is this available on github?
nice work btw
VirtualBornSkiller said:
is this available on github?
nice work btw
Click to expand...
Click to collapse
No sir, This is not open source
good luck
Thnks much.....
where should i flash the revsecurity file in odin ?
in ap or bl ?
salamkonaziz said:
where should i flash the revsecurity file in odin ?
in ap or bl ?
Click to expand...
Click to collapse
No difference
But it's better to put it in ap.
asgharSo said:
No difference
But it's better to put it in ap.
Click to expand...
Click to collapse
Why always AP?? oh well, Im not complaining. Listen, thank you guys for making such a great tool and sharing it!!! Blow away! May innovation be like a sister to you and yours. Question though.... so basically I can flash and tweak phones with what chip support? I missed it. Qualcomm (obviously because of Samsung) but MediaTek too? Also, how difficult would it be to port this to a Linux OS, if I used something like CrossOver or Wine or similar?
-Bad Rx__
BadRx said:
Why always AP?? oh well, Im not complaining. Listen, thank you guys for making such a great tool and sharing it!!! Blow away! May innovation be like a sister to you and yours. Question though.... so basically I can flash and tweak phones with what chip support? I missed it. Qualcomm (obviously because of Samsung) but MediaTek too? Also, how difficult would it be to port this to a Linux OS, if I used something like CrossOver or Wine or similar?
-Bad Rx__
Click to expand...
Click to collapse
Hi dear
If you put the file in bl, it will be writed
Odin software write it to the device based on the kernel name or file system in the tar file.So it's not important to put in either ap or in bl
You can use this method for any processor or brand.Only your device must accept custom binary.(boot.img RvSecurity)
For the Linux version, I try to write the next version
thanks and good luck
Gsd Android Tool Open Error
Gsd Android Tool Open Error How to Solve
這是一個很棒的工具
我見過的三星最好的免費和付費工具!!!
Well first things first.. i have no idea for what are 90% of options there BUT i somehow know it is CORE app now to unlock galaxy s7 edge.. but now the part where i need to ask anybody to lead me step by step (TOTALLY) how can i (and if i can) install custom recovery using this tool? Problem with my device is my volume buttons are totally non functional this is why i never was able to switch from Odin mode to recovery instantly by buttons combination (in result - always locked device and had to flash stock rom). I am on Stock Android 8.0 for S7 Edge G935F. Sorry for typing like a noob (a actually rooted/unlocked a lot of devices sometimes spending a lot of time on it but without volume buttons I am in dead point) PS. Last time i had to make 300kOhm device to get my phone into download mode so I am able to get into download but i am not able to use volume keys. And again thanks for any tips/tutorials etc
MavericzeK said:
Well first things first.. i have no idea for what are 90% of options there BUT i somehow know it is CORE app now to unlock galaxy s7 edge.. but now the part where i need to ask anybody to lead me step by step (TOTALLY) how can i (and if i can) install custom recovery using this tool? Problem with my device is my volume buttons are totally non functional this is why i never was able to switch from Odin mode to recovery instantly by buttons combination (in result - always locked device and had to flash stock rom). I am on Stock Android 8.0 for S7 Edge G935F. Sorry for typing like a noob (a actually rooted/unlocked a lot of devices sometimes spending a lot of time on it but without volume buttons I am in dead point) PS. Last time i had to make 300kOhm device to get my phone into download mode so I am able to get into download but i am not able to use volume keys. And again thanks for any tips/tutorials etc
Click to expand...
Click to collapse
DId you get this done? Im in same situation except i have the Samsung S7 GM 930W8
legendzj said:
DId you get this done? Im in same situation except i have the Samsung S7 GM 930W8
Click to expand...
Click to collapse
Well for me worked out flashing TWRP(in twrp turn off auto reboot) and i was able to turn off phone by myself by unplugging the battery (yea unplug when in download mode after flashing TWRP then flash back into download mode (i used USB JIG made by myself) and then through twrp i flashed eng-root with autoreboot and it flashed directly to the twrp BUT i dont know if this will work also for you keep that in mind
MavericzeK said:
Well first things first.. i have no idea for what are 90% of options there BUT i somehow know it is CORE app now to unlock galaxy s7 edge.. but now the part where i need to ask anybody to lead me step by step (TOTALLY) how can i (and if i can) install custom recovery using this tool? Problem with my device is my volume buttons are totally non functional this is why i never was able to switch from Odin mode to recovery instantly by buttons combination (in result - always locked device and had to flash stock rom). I am on Stock Android 8.0 for S7 Edge G935F. Sorry for typing like a noob (a actually rooted/unlocked a lot of devices sometimes spending a lot of time on it but without volume buttons I am in dead point) PS. Last time i had to make 300kOhm device to get my phone into download mode so I am able to get into download but i am not able to use volume keys. And again thanks for any tips/tutorials etc
Click to expand...
Click to collapse
first write eng-root then bypass use this tool
i'm developing new version of Gsd android Tool
we add many Option For bypassing Screen Lock (android 7,8__)
Screen Shot Of new version :
https://twitter.com/ILYA20_GSD/status/1054027375816724481
Cooming Soon ... !
asgharSo said:
first write eng-root then bypass use this tool
i'm developing new version of Gsd android Tool
we add many Option For bypassing Screen Lock (android 7,8__)
Screen Shot Of new version :
https://twitter.com/ILYA20_GSD/status/1054027375816724481
Cooming Soon ... !
Click to expand...
Click to collapse
Haha thanks for respond anyway I managed to get it working then but for now my S7 Edge is dead (screen flickering after drop). Thanks for respond and tutorial for others anyway! Have a nice day