PDA

View Full Version : Future of unlocking!



DavieB
09-04-2002, 06:34 PM
Well, thinking about recent discussions on DCT4 I've been considering what else we can do to get our minds goin..
Although flash research is coming on well, I was thinking about another thing we could do :smile:

OK, Why don't we start designing "open source/scheme" clips?!
Someone has already produced one which will unlock, repair broken imei, rewrite preprogrammed imei if the imei isn't there, lock code reset, and more!

Its just an idea :/
These clips are sold for £250 each so I'm assuming there isn't vast amounts of work involved in the construction!

To be honust I do not have much skills on this subject but am very willing to help as much as I can and even try to learn even more to help make progress!
I obviously can't do it alone, even if I spent a year or so learning ALL I needed - we would need source to do it! Source of a program such as eeprom tools 3.1... That is why I am bringing the idea to the forum

Even if someone here cracks/decompiles/disassembles it and programs the source for the pic/atmel themselves and leaves the rest to the others I think it'd be a great item!

Requitement suggestions:
Must be easy to construct
Must rely on micros like PIC or Atmel as these can be programmed with cheap/homemade programmer
Must at least unlock, other functions can come later
Expansion functions must not require redesign of the unit, rather rewriting of the chip with new hex
Must have free/open schemes, source for the pic/atmel could be open and commented to help further development, or closed - as long as it is free and usable!
Must use ps2 style connectors which are shipped with flash cables and mbus cables, as most users already have these


Maybe my idea sucks, or I'm talking crap here.. but I really think it could work and would be a fun item to construct and work on!

Anyway, think about it, seems like it will be the height of DCT3 (second to flash edits that it...)

Best Regards,
D.C.B.

Doc
09-04-2002, 09:19 PM
Hi DavieB!

Such a clip is in fact really easy to build. Just the program of the uPC is critical cos it#s doing all the job.

U just need a suitable connector (u already suggested the PS2 stuff, then perfect)

The uPC is connected to the pins of the phone and does it's work when detecting it#s being connected (also by button...)
The PIC16F84 (the best one to use I think is cheap and has 12+1 I/O pins fully configurable.

As soon as u tell me how to communicate with a phone (let#s say a 6210 or 61xx for ex.) and what to write to which location in the phone (E2P Flash the rest is just peanuts!)

Doc

DavieB
09-04-2002, 09:38 PM
Excellent! We're gettin somewhere!
So, -tek- or someone else with sources.. Can you give the mbus commands, hash's, or even better - sources!?!
We need them! If we can get these we'll have clips soon if Doc does his magic!

Come on folks.. This will make a good project :smile:

Leandros
10-04-2002, 01:37 AM
hi Davie!
greetings!

schematics for this thingie and hex for the IC are floating around, had them allready on my HD, but I think I've deleted them.

if I'm not remembering wrong Abe posted that some time ago.

doesn't have all the functionalities you're talking about but does all unlocking work and I think it does FAID calculation also.

but it's a good idea to initiate work und outher fields; how about allowing other platforms than win32 Nokia flashing ;-)

best regards,

Leandros

Leandros
10-04-2002, 01:39 AM
@Doc

hey Doc

wenn du Sourcen für die Kommunikation brauchst kann ich sie dir geben!
schreib mich via ICQ an!

schöne Grüße,

Leandros

DavieB
10-04-2002, 04:22 AM
@Leandros:
No man, the old hex is ok but has minimal functions (unlock only) which is OK but its only for old style (e.g. dct2 and early dct3 firmware like 3210 < 6.00)

Here is a link to the recent post by Teleway : http://64.239.47.45/vbb/showthread.php?s=&threadid=38317

From what I gather Teleway are a pretty well known and reputable group.. We don't want to focus on their clip too much, we can't exactly coax then into giving us design schemes and hex for free anyway!
But, if they can do it then it is possible (actually, it has been for a while, just a little more complicated now...)

Here is a copy of the related part of the Teleway post:



Exclusive product: DCT3 MAGIC CLIP with IMEI repair

Features:

- reset mobile to factory settings
- unlock SP lock
- reset SEC code (also on 6210 and 7110)
- repair 4 locks closed
- repair damaged imei number
(if ????????????4 IMEI will be replaced by a programmed number, if imei is ok it keeps the original IMEI)
- calculate FAID
- works also on msid 81 !!! (51/61 series without damage the phone)




If we use this as a base, it will let us know which functionallity we can ultimately go for!

But please, as I mentioned before, it will be MUCH easier if we have someone design the hardware (e.g. Doc who seems to know some on it!!!) then we won't have hardware changes at all..
This was we can simply reblast cheap PIC or Atmel to update the features.

Sorry I keep goin on about this point but for such mass "testing" we don't all have the time (or skill!) to constantly change the design - reblasting on the otherhand takes seconds..

B.r.
D.C.B.

Liam
10-04-2002, 11:17 PM
thats a VERY good idea about the clip. i dont think anything of this scale has been done before, i hope it works out

Graham
12-04-2002, 09:31 AM
Built the clip for the earlier nokias.
I still have the hardwar and software / schematics somewhere.
Its all down to the programing rearly.
Be nice to just unlock without using the computer.
Can find the early schematic if this helps?
I like building thies little projects and geting them to work.
haven't done anything new since the dejan box so someone have a go please.
Hats of to you guys who write the code.

DavieB
12-04-2002, 01:29 PM
Thats the spirit guys!
I've uploaded the old schems/hex
Maybe one of you progger/builders could take a look?

Now I'm getting excited on this one :smile:

In the instructions is says "Phone sends 7bytes, Clip replys with 7 bytes -phone is unlocked!"
Lets hope we just need to change the 7 bytes :smile:

Uploaded file: allnokiaclip.zip (/download.php?file=allnokiaclip.zip)

DavieB
14-04-2002, 07:19 PM
Argh!
Nothing yet? The topic is slipping.. :sad:

Graham
14-04-2002, 07:50 PM
Here's the old clip with hex
Using a pic16c84


Uploaded file: allnokiaclip.zip (/download.php?file=allnokiaclip.zip)

man0n
15-04-2002, 07:17 PM
I have uploaded again

Unique
28-08-2002, 09:40 PM
Glad to see something like this.

For the past two weeks I have been trying to build a clip that unlocks

Samsung N100/R2xx
Samsung A300/A400
Nokia DCT3
Panasonic GD52/92/93

I want to unlock more say DCT4, Ericsson and sony, has anyone got the source for any of these.

I am willing to give the finished clip for beta testing to those who help.

Thanks

KnOeFz
21-09-2002, 10:29 AM
Any news on this topic yet?


-=K=-

69Brothers
17-10-2002, 10:39 AM
The project have stopped?

Unique
17-10-2002, 02:08 PM
I have stopped it to do the PKD project. I'll resume it after the FLS box is made.

I lost interest after they started chnaging the way DCT4 is unlocked:rolleyes:. But I'll still make the clip.