FRP Bypass for 7.1.1 (November Security Update) - Moto Z Play Guides, News, & Discussion

After 12 hours straight of messing around with the internals of this phone, I've finally managed to bypass Google's "Factory Reset Protection" on the Moto Z Play DROID (i.e. Verizon variant, XT1635-01).

cheers bro, would be most helpful :good:

bro drop tutorial, for us to learn
 @jamesalynch

Here's a thought, sign out of your Google account before factory resetting? I don't see how this information is useful to anyone unless they are planning to steal Android phones from people.

jamesalynch said:
After 12 hours straight of messing around with the internals of this phone, I've finally managed to bypass Google's "Factory Reset Protection" on the Moto Z Play DROID (i.e. Verizon variany XT1635-01).
Click to expand...
Click to collapse
I would love to be able to bypass from on my motoz. Can you please share?

salemtim said:
I would love to be able to bypass from on my motoz. Can you please share?
Click to expand...
Click to collapse
Not from, FRP

Related

[REQUEST] Help Remove Ads from Amazon Moto G4 Play

Hey y'all thanks for taking a peek at this thread.
We, the people over at the forum for the Moto G4 Play, have had a lot of trouble figuring out how to remove the Amazon ads from our XT1607. You guys have found that simply flashing your gpt.bin and oem.img from a non-amazon XT1625 to an amazon XT1625 works simply enough.
Problem is with our device the amazon oem.img is sparsed into two different chunks, but the non-amazon device has a single oem.img. We have tried many different routes to remove the Amazon Ads from our device but haven't been successful at all. Now we've hit a roadblock and can't figure out how to get around it; and we'd love for the developers of this subforum to help us out.
Check out our progress in this post I made.
Thanks!
be aware that Amazon G4 owners (me included) who used RootJunky's Amazon debloating method cannot receive updates. attempts to flash the stock Amazon ROM (to get updates) results in bricked phones. so de-Amazon'd G4 owners with locked bootloader are stuck. we may not be able to install the Nougat update.
HKSpeed said:
be aware that Amazon G4 owners (me included) who used RootJunky's Amazon debloating method cannot receive updates. attempts to flash the stock Amazon ROM (to get updates) results in bricked phones. so de-Amazon'd G4 owners with locked bootloader are stuck. we may not be able to install the Nougat update.
Click to expand...
Click to collapse
Damn. We really need to figure out a way to root this device without unlocking the bootloader.
Ditto on this thread! ... Love my G4 play but not the AMAZON bloatware, want to delete it! ... Please help us get rid of this waste of space...
A.Fitz said:
Damn. We really need to figure out a way to root this device without unlocking the bootloader.
Click to expand...
Click to collapse
That won't happen no matter how hard you figure. It was done on the older Qualcomm chipsets and since then the RSA key has been beefed up to the point that if someone could break what they call the Qfuse and unlock the phone, they would be doing a lot more than just unlocking phones. There have been lame attempts in the near past that didn't go well for those trying so don't count on unlocking the bootloader without Amazon's or Lenovo's blessings.
This is now working (ended up not having to affect the systemui files, it was even simpler).
I am thinking about rolling up the solution into an apk so you guys can run it easily.
This thread seems pretty dead though. Anyone interested in an apk?
Still Interest
Hey...like me, I'm sure there is a lot of interest if there is a workable method to unlock the boot loader.
tnx...
ledothis said:
This is now working (ended up not having to affect the systemui files, it was even simpler).
I am thinking about rolling up the solution into an apk so you guys can run it easily.
This thread seems pretty dead though. Anyone interested in an apk?
Click to expand...
Click to collapse
ksdst1 said:
Hey...like me, I'm sure there is a lot of interest if there is a workable method to unlock the boot loader.
tnx...
Click to expand...
Click to collapse
Removing ads and unlocking the bootloader are two completely different things. The bootloader on the Amazon phone will never be unlocked until Amazon allows it.
YEs! Show me how....
ledothis said:
This is now working (ended up not having to affect the systemui files, it was even simpler).
I am thinking about rolling up the solution into an apk so you guys can run it easily.
This thread seems pretty dead though. Anyone interested in an apk?
Click to expand...
Click to collapse
I"M INTERESTED IN UNDERSTANDING HOW YOU DID IT, yes!
graboz said:
I"M INTERESTED IN UNDERSTANDING HOW YOU DID IT, yes!
Click to expand...
Click to collapse
check out the link in the original post. He works through it over there.

Unlocking Bootloader now trips SafetyNet

Its been reported that merely having an unlocked bootloader now trips safetynet. Google has officially turned their backs on developers and enthusiasts.
I never had a problem with xposed or magisk tripping safetynet; but an unlocked bootloader is by no means a security risk. So I'm not happy having to choose between snapchat and an unlocked bootloader.
Sources: https://www.reddit.com/r/Android/comments/587ss9/psa_android_safetynet_now_tripped_by_unlocking/
https://www.reddit.com/r/Nexus6P/comments/586bq7/android_pay_stopped_working_on_nonrooted_device/
Discuss.
Well RIP AP....
Pixel and now this, I guess Google is becoming Apple 2.0
can confirm, I have unrooted stock 7.0 as my primary on multirom and is tripping safetynet, no more AP for me I guess since I'm NOT locking the bootloader, nice play Google
Sent from my Nexus 6 using Tapatalk
IIRC chainfire DID warn us about this..saying if we keep trying to hide root, they'll keep trying to make it harder for us to do so.
Doing it to the pixel? Fine..but to a nexus phone? Kinda murders the whole selling point of Nexus.
Either way elgoog has been making some really odd decisions this past month or so.
I have an unlocked bootloader with everything stock and no root and I got past safety net for Pokemon Go.
biggiesmalls657 said:
I have an unlocked bootloader with everything stock and no root and I got past safety net for Pokemon Go.
Click to expand...
Click to collapse
Last I heard pokemon go isn't working with safetynet properly right now. Download SafetyNet Helper Sample from the PlayStore, it'll tell you whether you pass or not.
geokhentix said:
Last I heard pokemon go isn't working with safetynet properly right now. Download SafetyNet Helper Sample from the PlayStore, it'll tell you whether you pass or not.
Click to expand...
Click to collapse
Well I guess that a smartphone isn't for me, I'm gonna get a dumb phone again. Google can suck it. This is so ridiculous.
geokhentix said:
IIRC chainfire DID warn us about this..saying if we keep trying to hide root, they'll keep trying to make it harder for us to do so.
Doing it to the pixel? Fine..but to a nexus phone? Kinda murders the whole selling point of Nexus.
Either way elgoog has been making some really odd decisions this past month or so.
Click to expand...
Click to collapse
The only pixel that is locked is the Verizon version
holeindalip said:
The only pixel that is locked is the Verizon version
Click to expand...
Click to collapse
Yeah, that one isn't a part of this as its not unlockable. I'm talking about the Google Pixel.
This f's people who just want to install the latest factory image too; non power users who don't root and just want the latest OS..considering you need an unlocked boot loader to flash the images.
geokhentix said:
Yeah, that one isn't a part of this as its not unlockable. I'm talking about the Google Pixel.
This f's people who just want to install the latest factory image too; non power users who don't root and just want the latest OS..considering you need an unlocked boot loader to flash the images.
Click to expand...
Click to collapse
Not if you side load the latest ota files posted the same day:good:
By the way, does re-locking bootloader wipe data or internal? Factory image page says that "Locking bootloader will wipe the data on some devices. ".
Pretty sure on the n6, we wipe everything on both unlock & relock.
I'm planning on getting a new Nexus 6. Is it not the right time? I'm afraid this issue will make me unable to customize my new phone.
jesuajovan said:
I'm planning on getting a new Nexus 6. Is it not the right time? I'm afraid this issue will make me unable to customize my new phone.
Click to expand...
Click to collapse
You can still customize. You just can't do crap that you probably shouldn't be worrying about anyway. Android pay is a sham, since your credit card has an RF chip in it that works on the same scanner... but ONE FEWER companies get to track all your purchases when you use it since it leaves google out of the loop.
Indeed; also as long as you log into Snapchat once before you install root, it seems to continue to work after root / magisk installation.
I'm on 7.0 stock, rooted and unlocked bootloader and snapchat works fine.
pharpe said:
I'm on 7.0 stock, rooted and unlocked bootloader and snapchat works fine.
Click to expand...
Click to collapse
I just want to say that Snapchat is one of the worst coded apps ever
For Snapchat to work, you have to login before rooting your device, just don't log out lol
holeindalip said:
I just want to say that Snapchat is one of the worst coded apps ever
Click to expand...
Click to collapse
Amen.
I wonder what the hook is that it uses to check if the bootloader is locked...? It *must* go through the kernel, so maybe this is as simple as telling the kernel to LIE about it.
Well, that is simple conceptually, but not necessarily *easy* to implement.

Unlocking Account Google Moto G4 Plus XT1640 / A: 7.0 / Patch security December 1,

Hi everyone, congratulations for the really great site. Now answer me if you already have the unlock / removal procedure of the google account of the Motorola Moto XT1640 Android 7.0 Nougat and security patch December 1, 2016 ???? Because I've tried everything, app test dpc, terminal, dirtycow, and nothing ... If you can not think nobody else, except for the technical assistance, Thanks and congratulations.
digaoartes said:
Hi everyone, congratulations for the really great site. Now answer me if you already have the unlock / removal procedure of the google account of the Motorola Moto XT1640 Android 7.0 Nougat and security patch December 1, 2016 ???? Because I've tried everything, app test dpc, terminal, dirtycow, and nothing ... If you can not think nobody else, except for the technical assistance, Thanks and congratulations.
Click to expand...
Click to collapse
You mean you are locked out of your Google account? If this is the case you need to wait for 72 hours.
any solution for 1st nov patch , m also stucked in frp ... although m able to access the phone through sidebar but oem is locked , dirtycow is not working showing "cannot execute binary file " plss help me out
cooldudekapz said:
any solution for 1st nov patch , m also stucked in frp ... although m able to access the phone through sidebar but oem is locked , dirtycow is not working showing "cannot execute binary file " plss help me out
Click to expand...
Click to collapse
You have to use your last synced google id, or if you had multiple ids then try with each one of those. I had frp too 2-3 times but it lets me proceed after entering the correct google id & password
Dirtycow, dpc etc..all these will probably fail because google fixes it by releasing monthly security updates.
Can't you boot into bootloader and make a factory reset?
Sent from my Motorola Moto G4 Plus using XDA Labs
djumie said:
Can't you boot into bootloader and make a factory reset?
Sent from my Motorola Moto G4 Plus using XDA Labs
Click to expand...
Click to collapse
Nope FRP still exists. It's something from google's end, you either remember your google id & password or else find a way to bypass FRP
lCrD512 said:
Nope FRP still exists. It's something from google's end, you either remember your google id & password or else find a way to bypass FRP
Click to expand...
Click to collapse
Oh, ok! Sorry if it sounds like a dumb question but may I ask what FRP means?
Sent from my Motorola Moto G4 Plus using XDA Labs
djumie said:
Oh, ok! Sorry if it sounds like a dumb question but may I ask what FRP means?
Sent from my Motorola Moto G4 Plus using XDA Labs
Click to expand...
Click to collapse
Full form is Factory reset protection. You can get detail info by google search
lCrD512 said:
Full form is Factory reset protection. You can get detail info by google search
Click to expand...
Click to collapse
Really? I never knew about this! I'll research for better understanding. Thank you!
Sent from my Motorola Moto G4 Plus using XDA Labs
Small tip that everyone forgets:
if you keep the setting 'OEM unlocking' in developer options enabled then you desable this FRP. (in this case it's too late of course).
Droidphilev said:
Small tip that everyone forgets:
if you keep the setting 'OEM unlocking' in developer options enabled then you desable this FRP. (in this case it's too late of course).
Click to expand...
Click to collapse
oem is also locked .. i tried to unlock oem by adb .. but its not working
cooldudekapz said:
oem is also locked .. i tried to unlock oem by adb .. but its not working
Click to expand...
Click to collapse
what do you mean?
What i mean is that if you keep te switch "OEM unlocking" in developer options is enabled you cannot get locked out for 72 hours IN THE FUTURE. it won't help WHILE being locked out of course.
Droidphilev said:
what do you mean?
What i mean is that if you keep te switch "OEM unlocking" in developer options is enabled you cannot get locked out for 72 hours IN THE FUTURE. it won't help WHILE being locked out of course.
Click to expand...
Click to collapse
unable to switch on developer mode , developer mode is locked in nov patch
cooldudekapz said:
unable to switch on developer mode , developer mode is locked in nov patch
Click to expand...
Click to collapse
Have you tried to contact Google, see if you can recover your credentials to log into the device? Seems you're running head long into Android's anti-theft security measures.

Amazon E4 Bootloader Unlock/Root?

Is there a way to root the amazon ads version of this phone or are we stuck in the same boat as the verizon version?
Bump
I've been reading up on the Moto G4 Play forums and I am wondering if initroot is possible with the Moto E4. I've run the sunshine APK and it says the pretests have passed and that temproot is needed to continue. So would initroot + sunshine = unlock? Or are sunshine and initroot patched. Do I have this all wrong or??? Would love some input, thanks.
EDIT: Appears SunShine doesn't support the E line of devices, may still work though...
this tethered vulnerability was fixed back in June ...moto e4 comes out of the box with higher than June security patch .......
KevMetal said:
this tethered vulnerability was fixed back in June ...moto e4 comes out of the box with higher than June security patch .......
Click to expand...
Click to collapse
So are SOL then?
Sent from my Moto E4 using XDA Labs
TheJAYpoop said:
So are SOL then?
Click to expand...
Click to collapse
hard to say with finality but definitely SOL if uour security patch is higher than June in regards to the exploits you want to use
TheJAYpoop said:
Is there a way to root the amazon ads version of this phone or are we stuck in the same boat as the verizon version?
Click to expand...
Click to collapse
Have you entered your code on moto site to see if it can be unlocked? Just curious. I thought I saw someone with that amazon ads version unlock the bootloader. I could be wrong though.
madbat99 said:
Have you entered your code on moto site to see if it can be unlocked? Just curious. I thought I saw someone with that amazon ads version unlock the bootloader. I could be wrong though.
Click to expand...
Click to collapse
Yeah i've tried it a few times but unfortunately it doesn't work, for some people it works for some reason. Hopefully someone can find a temp root solution then sunshine MIGHT work.
madbat99 said:
Have you entered your code on moto site to see if it can be unlocked? Just curious. I thought I saw someone with that amazon ads version unlock the bootloader. I could be wrong though.
Click to expand...
Click to collapse
I think that was just a tutorial on how to disable ads/bloatware with fastboot.
volatile1 said:
I think that was just a tutorial on how to disable ads/bloatware with fastboot.
Click to expand...
Click to collapse
I've already removed the ads when I got it.
Sent from my Moto E4 using XDA Labs
It would be cool if someone created an unofficial Android 8 update for the e4's based on the stock kernel and everything so we could flash it without unlocked bootloader. Or is that not possible...
Sent from my Moto E4 using XDA Labs
TheJAYpoop said:
It would be cool if someone created an unofficial Android 8 update for the e4's based on the stock kernel and everything so we could flash it without unlocked bootloader. Or is that not possible...
Click to expand...
Click to collapse
without an unlocked bootloader you can',t flash files they don't get written unless signed by manufacturer so your Oreo would have to come from LenovoMoto
http://www.openwall.com/lists/oss-security/2017/11/30/1
root
I need root with this vulnerability, then I think you can change the firmware to another version
not an amazon
Well I dont feel like waiting for a bootloader unlock that will most likely never happen, I'm sending my Amazon e4 back and getting a normal version. Good luck to you all!
Sent from my Moto E4 using XDA Labs
madbat99 said:
Have you entered your code on moto site to see if it can be unlocked? Just curious. I thought I saw someone with that amazon ads version unlock the bootloader. I could be wrong though.
Click to expand...
Click to collapse
I just tried this with the bootloader unlock code from my Amazon Moto E4 on Motos website..."Your device does not qualify for bootloader unlocking"...F*ckers...lol...
amazon just canceled the ad program, all devices will have the ads removed...
http://www.zdnet.com/article/amazon-removing-lockscreen-offers-and-ads-from-prime-exclusive-phones/
wonder if it would affect the bootloader unlock policy
djdevin said:
amazon just canceled the ad program, all devices will have the ads removed...
http://www.zdnet.com/article/amazon-removing-lockscreen-offers-and-ads-from-prime-exclusive-phones/
wonder if it would affect the bootloader unlock policy
Click to expand...
Click to collapse
Not a chance. Zero incentive for Amazon to change the status quo.
its been a few months since ive tried to unlock my amazon e4's bootloader, so i tried it again... IT WORKED. I bought this phone on Aug. 26, 2017...so not quite a year old, but i was able to unlock it following the instructions on motos website.
It figures too...I just picked up a Pixel XL for $200 too...oh well. If you guys are still interested in unlocking, give it a try now before Amazon or Moto change their minds!
juggalofr33k said:
its been a few months since ive tried to unlock my amazon e4's bootloader, so i tried it again... IT WORKED. I bought this phone on Aug. 26, 2017...so not quite a year old, but i was able to unlock it following the instructions on motos website.
It figures too...I just picked up a Pixel XL for $200 too...oh well. If you guys are still interested in unlocking, give it a try now before Amazon or Moto change their minds!
Click to expand...
Click to collapse
I am truly shocked! The cost/effort to maintain an exclusion list of device identifiers must have outweighed the business benefit (Amazon ecosystem lockin) assuming it was not an inadvertent disclosure. That leaves Verizon (XT1767) as the only major that can't be bootloader unlocked.
I noticed the price gap between 'prime' and 'standard' variants has narrowed of late - perhaps in recognition of revenue loss due to lack of lock screen ads (Amazon policy change) and/or more freedom to root and remove Amazon exclusive content - aka 'bloat'.
got excited, but sad to report it didn't work for me.

Anyone able to bootloader unlock?

Option is greyed out on mine ... it's a Google Store phone. purchased from Google specifically so I would be able to unlock.
And I can't. I'm p*ssed. Very unhappy.
Are you saying you can't check on the OEM unlocking option under Developer Options?
I just checked and I was able to do it.
Yes, that's exactly what I'm saying. It's greyed/disabled.
and per Google, I have a VZW branded phone.
So now it's going back. $900 wasted.
_litz said:
and per Google, I have a VZW branded phone.
So now it's going back. $900 wasted.
Click to expand...
Click to collapse
Did you buy from Verizon or Google store?
dubt17 said:
Did you buy from Verizon or Google store?
Click to expand...
Click to collapse
Google Store. They are selling 3 models of Pixel 4 : unlocked, VZW locked, and Google Fi.
They sent me a VZW one.
I was able to unlock mine no problem. I bought the unlocked version from Google even though I'm on Verizon. I put my Verizon sim in, skipped all the setup, ticked to allow oem unlocking, rebooted to bootloader and unlocked no problem.
That's a bummer yo.
_litz said:
Google Store. They are selling 3 models of Pixel 4 : unlocked, VZW locked, and Google Fi.
They sent me a VZW one.
Click to expand...
Click to collapse
Are you just going to return and cancel or are they exchanging it for you?
That sucks..
For those who unlock. Do you use something for Google Pay? (That magisk thing?)
Also...do you know if device theft protection still works if stolen?
I recently tried to root my Pixel 2 but then I rolled back because I wasn't sure of these two things.
Sent from my Pixel 4 using Tapatalk
does this mean we can flash magisk root if we unlock the bootloader?
thesebastian said:
That sucks..
For those who unlock. Do you use something for Google Pay? (That magisk thing?)
Also...do you know if device theft protection still works if stolen?
I recently tried to root my Pixel 2 but then I rolled back because I wasn't sure of these two things.
Sent from my Pixel 4 using Tapatalk
Click to expand...
Click to collapse
I haven't unlocked in years but I do read about it. I think you only need Magisk if you're going to root. Bootloader unlock only needs a kernel to bypass the unlock check. But since there are no kernels yet you can't use GP if you unlock the P4.
Until Google releases the factory images for the P4, it may be hard to install Magisk. Without TWRP, we need to use the boot image modification method. Unless you are competent enough to find and extract the boot.img from your phone, you will have to wait until the factory images are released to get your hands on it.
So while it is probably technically possible to root right now, the ave person that isn't an Android OS expert probably won't have the technical skills to do it.
To those asking ... yes, I bought from google store. They sent me the verizon variant instead of the unlocked variant.
re: google pay/etc (anything requiring safetynet), Magisk can provide root, and its Magiskhide component can hide that root from SafetyNet. Installing Xposed inside Magisk, however, cannot be hidden.
re: installing magisk if you unlock the bootloader - that's a yes.
Anyone in here extracted the boot.img from the factory image yet?
I'm on a mac right now so I was hoping to just download someone elses.
My OEM unlock is available. I'm waiting for root. The only thing I want right now is hotspot. I was hoping that since it's an unlocked phone that it would work straight out of the box. I've been with LG since the G4 and I've always bought mine unlocked and the hotspot works without having to go through Verizon and pay for the subscription. I'm on the old grandfathered unlimited data plan. I'd hate to have to return this phone and go with the G8 but I don't have internet where I live and I have to have hotspot.
Spookymyo said:
My OEM unlock is available. I'm waiting for root. The only thing I want right now is hotspot. I was hoping that since it's an unlocked phone that it would work straight out of the box. I've been with LG send the G4 and I've always bought mine unlocked and the hotspot works without having to go through Verizon and pay for the subscription. I'm on the old grandfathered unlimited data plan. I'd have to have to return this phone and go with the G8 but I don't have internet where I live and I have to have hotspot.
Click to expand...
Click to collapse
You know w have root right? You don't need a custom recovery when you can use the patched boot method from magisk along with fastboot.
cntryby429 said:
You know w have root right? You don't need a custom recovery when you can use the patched boot method from magisk along with fastboot.
Click to expand...
Click to collapse
?? ...I did not... I'll do a search
cntryby429 said:
You know w have root right? You don't need a custom recovery when you can use the patched boot method from magisk along with fastboot.
Click to expand...
Click to collapse
Would you mind sharing your unpatched boot.img?
Shponglized said:
Would you mind sharing your unpatched boot.img?
Click to expand...
Click to collapse
You can get it with the system images that are available from Google. It'd be hesitant to give you the one I downloaded in case you have one of the other 2 variants of the October release (this assumes that the boot.img's are even different which in not sure).
I got a tester device so it was already unlocked. I'm just waiting for TWRP before I start messing with it.

Categories

Resources