XARiUS
14-05-2002, 02:14 AM
Hi ppl!
Today i started thinking why some phones have some active menus, and others same sw don't! So i start messing with my mobile..
I think that MCU and PPM it NOT modified by mobile itself, so i started making some research at EEPROM!
I found some addresses:
EEPROM 1st Checksum: 0x144
EEPROM 2nd Checksum: 0x27C
IMEI: 0x32
Security Code: 0x136
Security IMEI: 0x162 <- This one is XORed with 0x65
Production Code: 0x146
Base Product ion Code: 0x157
hw version: 0x15E
PCI: 0x160
Production Date: 0x16A
Product Serial: 0x14E
Note: I don't know what this all is! I got these names and offsets with the help of flashanalyzer! Oh the offsets are relative to EEPROM Base!
Other note: IF you alter something between the second eeprom checksum and the end of the flash, you do NOT need to correct any checskum and your mobile will NOT display CONTACT SERVICE! So this make's me thinking that somewhere between EEPROM beggining and the offset 0x27c we have some bytes (or bits) that made some of the menus on/off!
Can anyone confirm this (that is really in those first 0x27c bytes that the phone stores the information about wich menus the user have) ?
Oh BTW how many times can i flash a mobile?? does it have limmit? i hope not!
Cheers...
Today i started thinking why some phones have some active menus, and others same sw don't! So i start messing with my mobile..
I think that MCU and PPM it NOT modified by mobile itself, so i started making some research at EEPROM!
I found some addresses:
EEPROM 1st Checksum: 0x144
EEPROM 2nd Checksum: 0x27C
IMEI: 0x32
Security Code: 0x136
Security IMEI: 0x162 <- This one is XORed with 0x65
Production Code: 0x146
Base Product ion Code: 0x157
hw version: 0x15E
PCI: 0x160
Production Date: 0x16A
Product Serial: 0x14E
Note: I don't know what this all is! I got these names and offsets with the help of flashanalyzer! Oh the offsets are relative to EEPROM Base!
Other note: IF you alter something between the second eeprom checksum and the end of the flash, you do NOT need to correct any checskum and your mobile will NOT display CONTACT SERVICE! So this make's me thinking that somewhere between EEPROM beggining and the offset 0x27c we have some bytes (or bits) that made some of the menus on/off!
Can anyone confirm this (that is really in those first 0x27c bytes that the phone stores the information about wich menus the user have) ?
Oh BTW how many times can i flash a mobile?? does it have limmit? i hope not!
Cheers...