Note5 radio frequency HW hack - Hardware Hacking General

Hello,
I'm new to the forum, and having a real hard time identifying what is, and isn't possible regarding hardware manipulation. I have a Samsung Galaxy Note5 SM-N9208, which originated in Taiwan. I am on T-Mobile in the U.S., and I would like to make this device fully compatible with T-MOBILE's network. I am new to rooting, and flashing, so I don't have a strong enough understanding of the capabilities of such things. I was led to believe that it was possible to root, unlock the bootloader, change the CID, and flash the radio to the correct baseband/firmware (sorry if this sounds ridiculous). I have heard, however, that the different models will not accept firmware from different models. I don't understand what prohibits this activity, because the internals seem to all be the same. If anyone can explain this to me, or provide me with a way to accomplish this, if possible, I would be incredibly grateful.

Bootloader signing... do not crossflash. I did and now I'm buying a new logic board.
The latest DFS lets you change the frequency/band a la atheros wifi card + athtool... menu will let you pick bands and write to the phone. That is the only thing I saw besides changing bands from the programming menu.

Well hardware is not limiting you. Its the software. Some of the things just cant be done ex you can run .exe on windows directly but not .apk bcoz apk for android and .exe for winndows. Similarly some of flashing and apps and mod wont work unless they are compatible. Sometimes a mobile has different models which has a little difference but it makes things large. Ex. My mom's grand 2 is SM-G7102 but there is another version SM-G7108 both have identical physique , same circuit but software has +/- additional features. I guess u got it. This is marketing technique. Dont lose hope. You can succeed just gain a little more knowledge. Im 17 nd ive gained knowledge by self exploration. Keep it up. If there is any problem ask other XDA membera

Related

direct GSM access?

I am particularly interested in the wizard, however on a fundamental level WM will most likely operate the same across most models in respect to this issue (or at least that is the theory).
I realize that most GSM boards have processors on them which do things like channel syncing (which is fairly time sensitive since its tdma&fdma), a5, gsm framing, and all that. You more or less connect a sim, speaker and mic, and treat the gsm rf board as a black box.
I am hoping that somewhere someone has unearthed something that allows more direct control over the gsm board on these phones. I am aware of engineering mode, however that is not quite what I wanted.
I would like to be able to at the very least set the call parameters before a call goes out. For example, lets say that I want to disable A5, sinec there are 3 standard levels one being no encryption, and the tower and the phone negotiate and agree upon the highest common, something in the phone somewhere has to say that it supports encryption.
I am just uncertain if all that is burried away in a 'black box' somewhere and its not a software problem from within WM.
If anyone has any ideas I would greatly appreciate it, even if they are pointers to research material that may help me out a bit.
On WinMobile GSM part is isolated from the windows part, like in normal PCs modem hardware is isolated from mainboard. GSM part has its own CPU, RAM, ROM, operating system, and communicates with Windows via COM-port (or USB port in Universal). For example Universal has Qualcomm MSM6250 chip with some proprietary OS. HTC Himalaya had a different chip (I don't remember it now), and OS was based on nucleus RTOS. Anextek SP200 communicator had Siemens MC45 modem inside.
GSM hardware is a black box for WinMobile OS. MS specifies only some recomendations for OEMs, and controlling encryption is not among them. You can control it if GSM vendor supports some AT command, or some other proprietary method (maybe via dev_specific RIL command).
In the case of Universal, its GSM can be controlled from a PC with the usual Qualcomm diagnostic software (QXDM, QPST, etc), when you setup the device as a pass-through bridge between PC and GSM module. But I don't know any methods of doing the same from inside WinMobile.
mamaich said:
GSM hardware is a black box for WinMobile OS.
...
You can control it if GSM vendor supports some AT command, or some other proprietary method (maybe via dev_specific RIL command).
In the case of Universal, its GSM can be controlled from a PC with the usual Qualcomm diagnostic software (QXDM, QPST, etc), when you setup the device as a pass-through bridge between PC and GSM module. But I don't know any methods of doing the same from inside WinMobile.
Click to expand...
Click to collapse
That is what I was afraid of. Most of the GSM radio boards (or individual chips) are set up to act that way, and since its faster and cheaper I really dont know of anyone that hasnt done that in any phone that was made in the last few years.
At any rate, is there any documentation that discusses how to locate which com port or other method is used to access the GSM device within a wizard (or any other htc model, odds are many of them are similar, if not identical with this subcomponent).
Are there any known AT commands? my first project is to write something similar to the gsm engineer mode program, obtaining BTS information. I am unsure if this is obtained only via AT commands or if its something more involved, but welcome any information on this.
Found what appears the be half the answer at http://wiki.xda-developers.com/index.php?pagename=RIL While that gives me access to the radio for some stuff (location data app that can work with gsmloc.org for example) it does not appear to enable me to set any parameters for a new call.
So if anyone knows of any tricks that would help say for example disable a5 crypto (on a per call basis idealy) or something similar to the setup of a call I would still appreciate hearing about that.
I know that Typhoon ( spv c500 / i-mate sp3 /Dopod 565) memory block with gsm info data. I am trying to find it in Magican - but no results. I dont know how Typhoon place this info in mem.

Unlocking (X1A)

I realize that I'm likely to get instantly bashed for asking about this, but please let me preface my post with saying that I have done about 6 hours of research, here and elsewhere, but have not found a definitive answer to my question(s).
I recently purchased an xperia x1a. To my vast disappointment, the speeds i'm getting online are incredibly low (~200k). I know it has nothing to do with my service because if I pop my SIM into another phone, i get ~1000k generally.
My phone came "unlocked" and unbranded. I am in the US on ATT, and I can connect to HSPDA without a problem (isp.cingular as my AP).
I would like to try installing another radio on my phone to see if it might resolve my problems, but from all of my research, it sounds as though doing this requires security unlocking (CID) the phone.
First off, is there any chance my phone, brand new, came "security unlocked"? If so, is there any way to tell?
If I must security unlock my phone, it sounds like the code to do so is floating around, but since it's for sale places, no one is willing to give it away for free (or is it somehow linked to your IMEI?). I'm not altogether unwilling to pay to unlock my phone, although if there is any other route for upgrading to a better radio without having to pay, obviously that would be ideal.
I've got the radio I want, I've hex edited it so that it should work on my phone, but I'm very leery about bricking it by installing a radio that won't work. As I said, I have done a HUGE amount of research on this topic (flashing a new radio) and haven't found much that's definitive. On my last phone, a Diamond, I had no such issues (I purchased it retail, also unlocked and unbranded).
If anyone can shed some light on some of these questions, I would really appreciate it. I've been over to htccode and it sounds like they have a solution (at least for the X1, not sure about the X1A), but I would really like to understand this entire issue better.
Also, my current radio is 1.06.25.29. Can I simply cleanly upgrade to one of the newer radios found here: http://forum.xda-developers.com/showthread.php?t=477801 without having to worry about unlocking? are the radios for the X1 and X1A the same?
I promise, I've searched.
YUP 200 Kb only ???
My provider is TIGO and, same as you I assume, I use a "security locked" X1a under the HSDPA 850MHz band
If you are not getting better speeds with your current radio, I guess a Radio upgrade wouldn't help because I've been gettin' up to 3,500 Kbps downloads without any worries or special tweaks, and yes I started with Radio 1.06.xx.xx
Some possibilities:
1- Try checking your advanced network config (under start->settings->connections) to check if HSDPA is enabled
2- It could be an operator-config dependant issue; check your parameters in your otehr phone against the parameters auto-configured in the XPERIA
3- Check if your phone is REALLY X1a: remove the battery and the white label must say "X1a", not just "X1"
Finally, ALL RADIOS and EVERYTHING posted here @ xda-devs work for ALL X1, it doesn't matter if it is X1a or X1i
PS: The "security unlock" is ONLY required to flash Radios from OTHER HTC devices (but we have already managed to make them compatible by hex-editiing them )
hope this helps
I've tried everything i can think of and I'm banging my head against the wall. The phone's next. Actually, I think that I'm going to go ahead and get a new SIM from AT&T and see if that helps any, since I'm now having some issues with my blackjack all of a sudden....

Orange Touch 3G flash

Hi all,
I recently got hold of a Touch 3G for a friend, and he is having a few issues with the Unique / UMA connectivity (surprise).
My question, do any of the other Touch 3G ROMS out there (like the vanilla HTC one) have the UMA / Unique feature? or would we lose that function with a reflash?
Anyone out there done such a thing, there seems to be little info about UMA / Unique anywhere, I am surprised.
Thanks in advance,
Mark
there is little info on the unique stuff because it's fairly pointless and not very well done by orange.
I reflashed mine to a custom rom to get rid of all the orange customizations like that
Unique seemed a little pointless to me. I flashed to a normal HTC WWE ROM and was done with it. Obviously I still have wifi etc, and really, unique seemed pointless. In order to get the phone and not pay a fortune for it, you needed to get an expensive contract with lots of minutes anyway so you might as well use them.
Thanks for the responses
... but the reason for using Unique is NO cellphone signal at home, or in fact for a large region of the local area (you would not think we lived in the South East of England would you.)
So I take it that there is no UMA functionality in any of the better alternative ROMs for the Touch 3G/Jade, pity.
I know that there are a number of other threads on the subject, but any other thoughts on how to get the best out of it rather than abandon it altogether???
Cheers
MS
I would imagine that the unique part is just a few apps, I don't see a reason why one of the developers couldn't pull it out for you. and then you would just install the app on a cutom rom.
I don't know if this would work but i see no reason why it shouldn't it's just a matter of getting the right apps, in fact you could do it yourself.
if you look at the kitchen i think it tells you have to download you current rom and extract it, then find the right apps and try to install a custom rom and then install the apps.
it might work and you could alwasy go back if it doesn't.
I think i would keep the unique stuff on the phone if it wasn't for that fact that it makes the wifi so hard to use.
UMA on T-Mobile
Anyone figured out how to do UMA on T-Mobile?

[Q] SM-G900F 4g/lte frequencies hard wired or soft wired?

Please forgive me if I am re-paving old parking lots here, but I *have* done a lot of research (although I am admittedly a noobie), and I have found a lot of conflicting information that I have not been able to glean a confirmation from.
I have recently mistakenly purchased (my mistake 100%) a generic factory unlocked SM-G900F that came with lollipop on it, and I am very happy with just about everything except that ATT is my carrier, they transmit lte at least primarily on frequency 700, and the SM-G900F does not support that frequency, at least out of the box.
So, there is my question: are the frequencies "hardwired" in in some way so there is no changing them short of (mythically) physically changing modems or something like that (which would essentially mean that I'm stuck)? Or alternatively are the frequencies "softwired" in such way that rooting then flashing something in or changing/adding code could get my 900F to receive ATT's 4g/lte transmissions???
Thanks in advance-
kfbc
Well, OK then...If the answer to that question isn't here, can anyone tell me where to look?

Manually Select/Disable/Enable Bands

Hello everyone! I am trying to find out how to enable/disable certain bands. My company installs cell phone boosters for people that have poor signal, and i need to be able to select a single band at a time to do speed tests.
I know this is possible with Samsung devices, but was wondering if anyone found a way to lock to a single frequency.
This is possible with Samsung devices but unaware of any way to do this with a Oneplus 8. I think its even possible to do it on the tmobile version?
Any help would be greatly appreciated. (I am also rooted if that helps.)
Wow. I may be onto something. Anyone want to test this out?
**Disclaimer** Do it at your own risk.
I found this. Seems to let me change to whatever band I choose. But the only way I can seem to get back to "all bands" or "automatic" is by selecting all of the ones I use.
Or by typing *#*#4636#*#* and selecting the second from bottom
Download quickshortcutmaker from play store.
Look for: com.oneplus.engmode.bandmode
It was almost all the way down at the bottom for me. (My search doesn't seem to work)
I don't think this requires root or how I found it but it's working! (But, I am rooted, Android 11, stock room)
not sure who else could use this but I hope it helps someone!
Should all be unlocked from begin with, we should have access to all the bands as we're paying to access our networks not Oneplus
You must not have read the op.... He wanted to lock onto a single band to do a speed test for signal booster purposes. Your respknce was a waste of time.
Op, nice job on the work around for yourself
Good information and screen shots! cheers

Categories

Resources