Re: Nokia N73 Security status: Security Damaged :(
#16
Цитата:
Сообщение от $tas
Если не ошибаюсь, то проблема в том, что у вас повреждены CCC/HWC key в BackUp RPL.
Попробуйте сделать BackUp RPL с другого исправного аппарата с таким же Product code и вырезать из него CCC/HWC, затем записать их в свой аппарат с дальнейшей записью 1 и 309 полей PM с SX4 авторизацией.
|
Записывал, не помогает. Вот лог Cyclone
Код:
SIMLOCK SEFLTEST PASSED OK!
Step 2 : Testing SECURITY
-- SECURITY PROBLEM --
Phone have failed SECURITY Test, that means Superdongle Area is DAMAGED!
To repair it, simply slick "SX4 Authorization / SD Repair" button.
After SX4/SD Repair, don't forget to write PM file with fields 1,309 (if SW don't do this automatically)
Additionaly, Checking HWC/CCC Certs...
Booting CMT...
APE_SYSTEM_ASIC_ID: 17100708
APE_ASIC_MODE_ID: 00
APE_PUBLIC_ID: 776B50EEC3E9AAA27967A7425133FB7B926A8E78
APE_ROOT_KEY_HASH: 49A97E826B93BA20B7ED0B082475C00500000000
APE_BOOT_ROM_CRC: 1DFD6613
APE_SECURE_ROM_CRC: 2C872FD4
CMT_SYSTEM_ASIC_ID: 000000010000022600010006010C192101003000
CMT_EM_ASIC_ID: 00000295
CMT_EM_ASIC_ID: 00000B22
CMT_PUBLIC_ID: 0BD001055EDC0154E77D2AE290113B6DEC107DC1
CMT_ASIC_MODE_ID: 00
CMT_ROOT_KEY_HASH: BAF3A9C3DBFA8454937DB77F2B8852B1
CMT_BOOT_ROM_CRC: 273F6D55
CMT_SECURE_ROM_CRC: DFAAF68F
CMT Ready!
Searching for BootCode: DualLine 32Bit
RAP3Gv3_2nd.fg, Type: 2nd Boot Loader, Rev: 0.10.42.0, Algo: BB5
Flashbus Write baud set to 1.0Mbits
Flashbus Read baud set to 98Kbits
Using OLD BB5 FLASHING PROTOCOL
If software STUCK HERE with box TX LED lit, that means:
1. You have not attached yellow TX2 Adapter (IT IS REQUIRED FOR BB5 PHONES WHEN USING JAF/UFS CABLES!)
2. Your cable is not TX2 Enabled!
3. Transmission error occured, try again
In either cases, you need to reconnect your box from USB.
FlashChip[0,CMT]: 0x00EC22E800006921, Samsung, NOR
FlashContent[0,CMT]: 00000000000000000000000000000000, NOR
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
Transmission Mode Requested: Single Line, 8 bit, Accepted: Single Line, 8 bit
Searching for BootCode: DualLine 32Bit
FlashChip 0x00EC22E8 (Samsung), Size: 16MBytes, VPP: 9V
RAP3Gv3_algo.fg, Type: Algorithm, Rev: 0.10.40.0, Algo: BB5 ALGORITHM
Flashbus Write baud set to 2.0Mbits
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
Box VPP disabled
Internal CMT Phone VPP Enabled
PAPUBKEYS Hash for CMT: 5E8D0D504A0902E261268C14FCD8A2C9093523BC
Searching for BootCode: DualLine 32Bit
helen3_2nd.fg, Type: 2nd Boot Loader, Rev: 0.1.35.0, Algo: BB5
If software STUCK HERE with box TX LED lit, that means:
1. You have not attached yellow TX2 Adapter (IT IS REQUIRED FOR BB5 PHONES WHEN USING JAF/UFS CABLES!)
2. Your cable is not TX2 Enabled!
3. Transmission error occured, try again
In either cases, you need to reconnect your box from USB.
FlashChip[0,APE]: 0x00EC00A100800015, Samsung, NAND
FlashContent[0,APE]: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF, NAND
Searching for BootCode: DualLine 32Bit
FlashChip 0x00EC00A1 (Samsung), Size: 128MBytes, VPP: 21V
h3_sam_nand_xsr.fg, Type: Algorithm, Rev: 0.1.49.0, Algo: OMAP1710 UNISTORE-II-1.2.1 ALG
Box VPP disabled
Internal APE Phone VPP Enabled
PAPUBKEYS Hash for APE: 5E8D0D504A0902E261268C14FCD8A2C9093523BC
Flashbus Write baud set to 5.0Mbits
!!!!! HWC IS EMPTY, ANOTHER REASON OF SECURITY TEST FAILED !!!!!
!!!!! CCC IS EMPTY, ANOTHER REASON OF SECURITY TEST FAILED !!!!!
Restarting MCU...
-- SECURITY PROBLEM --
Step 3 : Analyzing Security Block
WARNING: "0BD001055EDC0154E77D2AE290113B6DEC107DC1.C0000604" Not Exists, Will read it...
Reading CYC file from phone...
Booting CMT...
APE_SYSTEM_ASIC_ID: 17100708
APE_ASIC_MODE_ID: 00
APE_PUBLIC_ID: 776B50EEC3E9AAA27967A7425133FB7B926A8E78
APE_ROOT_KEY_HASH: 49A97E826B93BA20B7ED0B082475C00500000000
APE_BOOT_ROM_CRC: 1DFD6613
APE_SECURE_ROM_CRC: 2C872FD4
CMT_SYSTEM_ASIC_ID: 000000010000022600010006010C192101003000
CMT_EM_ASIC_ID: 00000295
CMT_EM_ASIC_ID: 00000B22
CMT_PUBLIC_ID: 0BD001055EDC0154E77D2AE290113B6DEC107DC1
CMT_ASIC_MODE_ID: 00
CMT_ROOT_KEY_HASH: BAF3A9C3DBFA8454937DB77F2B8852B1
CMT_BOOT_ROM_CRC: 273F6D55
CMT_SECURE_ROM_CRC: DFAAF68F
CMT Ready!
RAP3Gv3_2nd.fg, Type: 2nd Boot Loader, Rev: 0.1.30.0, Algo: BB5
Flashbus Write baud set to 1.0Mbits
Flashbus Read baud set to 98Kbits
Using OLD BB5 FLASHING PROTOCOL
Exploiting - running preloader...
Preloader running OK, Running Custom Loader...
Custom loader running OK! Working...
Old Loader Detected
Readed OK, Saving to "0BD001055EDC0154E77D2AE290113B6DEC107DC1.C0000604"
Checking SUPERDONGLE...
SUPERDONGLE FOUND AND CHECKSUM OK! PASSED!
Checking SIMLOCK...
SIMLOCK FOUND AND CHECKSUM OK! PASSED!
Checking MCU&DSP TIMESTAMPS...
MCU&DSP TIMESTAMPS FOUND AND CHECKSUM OK! PASSED!
Checking CMLA KEYS...
Failed to decode Security Section, Box Reported: Security Section Not Found (SL3 phone?)
Checking ECC KEYS...
Failed to decode Security Section, Box Reported: Security Section Not Found (SL3 phone?)
Checking DIV KEYS...
DIV KEYS FOUND AND CHECKSUM OK! PASSED!
Analyze finished!
Skipping RPL decryption...
Parsing decrypted RPL...
Processing FBUS Part...
Processing FLASHBUS Part...
Booting CMT...
APE_SYSTEM_ASIC_ID: 17100708
APE_ASIC_MODE_ID: 00
APE_PUBLIC_ID: 776B50EEC3E9AAA27967A7425133FB7B926A8E78
APE_ROOT_KEY_HASH: 49A97E826B93BA20B7ED0B082475C00500000000
APE_BOOT_ROM_CRC: 1DFD6613
APE_SECURE_ROM_CRC: 2C872FD4
CMT_SYSTEM_ASIC_ID: 000000010000022600010006010C192101003000
CMT_EM_ASIC_ID: 00000295
CMT_EM_ASIC_ID: 00000B22
CMT_PUBLIC_ID: 0BD001055EDC0154E77D2AE290113B6DEC107DC1
CMT_ASIC_MODE_ID: 00
CMT_ROOT_KEY_HASH: BAF3A9C3DBFA8454937DB77F2B8852B1
CMT_BOOT_ROM_CRC: 273F6D55
CMT_SECURE_ROM_CRC: DFAAF68F
CMT Ready!
Searching for BootCode: DualLine 32Bit
RAP3Gv3_2nd.fg, Type: 2nd Boot Loader, Rev: 0.10.42.0, Algo: BB5
Flashbus Write baud set to 1.0Mbits
Flashbus Read baud set to 98Kbits
Using OLD BB5 FLASHING PROTOCOL
If software STUCK HERE with box TX LED lit, that means:
1. You have not attached yellow TX2 Adapter (IT IS REQUIRED FOR BB5 PHONES WHEN USING JAF/UFS CABLES!)
2. Your cable is not TX2 Enabled!
3. Transmission error occured, try again
In either cases, you need to reconnect your box from USB.
FlashChip[0,CMT]: 0x00EC22E800006921, Samsung, NOR
FlashContent[0,CMT]: 00000000000000000000000000000000, NOR
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
Transmission Mode Requested: Single Line, 8 bit, Accepted: Single Line, 8 bit
Searching for BootCode: DualLine 32Bit
FlashChip 0x00EC22E8 (Samsung), Size: 16MBytes, VPP: 9V
RAP3Gv3_algo.fg, Type: Algorithm, Rev: 0.10.40.0, Algo: BB5 ALGORITHM
Flashbus Write baud set to 2.0Mbits
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
Box VPP disabled
Internal CMT Phone VPP Enabled
PAPUBKEYS Hash for CMT: 5E8D0D504A0902E261268C14FCD8A2C9093523BC
Searching for BootCode: DualLine 32Bit
helen3_2nd.fg, Type: 2nd Boot Loader, Rev: 0.1.35.0, Algo: BB5
If software STUCK HERE with box TX LED lit, that means:
1. You have not attached yellow TX2 Adapter (IT IS REQUIRED FOR BB5 PHONES WHEN USING JAF/UFS CABLES!)
2. Your cable is not TX2 Enabled!
3. Transmission error occured, try again
In either cases, you need to reconnect your box from USB.
FlashChip[0,APE]: 0x00EC00A100800015, Samsung, NAND
FlashContent[0,APE]: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF, NAND
Searching for BootCode: DualLine 32Bit
FlashChip 0x00EC00A1 (Samsung), Size: 128MBytes, VPP: 21V
h3_sam_nand_xsr.fg, Type: Algorithm, Rev: 0.1.49.0, Algo: OMAP1710 UNISTORE-II-1.2.1 ALG
Box VPP disabled
Internal APE Phone VPP Enabled
PAPUBKEYS Hash for APE: 5E8D0D504A0902E261268C14FCD8A2C9093523BC
Flashbus Write baud set to 5.0Mbits
CMT VARIANT Erased
CMT VARIANT Written
Restarting MCU...
Write RPL Finished!
Повторный Analise Security тоже самый лог