Hi, latest bomb for Cyclone Box is ready
Update is 100% free and standalone for CycloneBox users;-)
- Added FIRST IN THE WORLD, FREE, STANDALONE SL3 UNLOCK by BF FOR LATEST TI BASED NOKIA PRODUCTS (RAPUV2 CPU) this includes Nokia 500, Nokia 600, Nokia 700, Nokia 701 and probably more coming !!!!!! These products are 15 NCK chars so not to worry.
- Added FIRST IN THE WORLD, FREE, STANDALONE SUPERDONGLE REPAIR for RAPUv2 Based Phones
- Added FIRST IN THE WORLD, FREE, STANDALONE SX4 AUTHORIZATION for RAPUv2 Based Phones
- Added FIRST IN THE WORLD, FREE, STANDALONE "FULL RPL" BACKUP (include SUPERDONGLE) for latest RAPUv2 phones
- Added FIRST IN THE WORLD, FREE, STANADLONE DOWNGRADE CAPABILITY for latest RAPUv2 phones
- Added FIRST IN THE WORLD, FREE, STANDALONE Full Security analysis for RAPUv2 phones
- Supported interfaces: USB and FBUS
- Small bug fixes, i.e. PM protection is now unticked by default
Nokia 701, reading sl3 log file
Code:
[Nokia USB Phonet]: Port opened OK!
Reading SL3 LOG File...
[Nokia USB Phonet]: Port opened OK!
MCU Version V 79u_11w31.4
MCU Date 16-08-11
Product RM-774 (Nokia 701)
Manufacturer (c) Nokia
IMEI 358272040230347
Mastercode 752474040
Analyzing Profile Bits...
Phone can be NCK unlocked using KEYPAD
Phone can be NCK unlocked using FBUS
15 Digits NCK Found
WARNING: "EC130000FFFF7C40D88E7ED917D36D2FC8DAFF43.C0004AAC " Not Exists, Will read it...
Reading CYC file from phone...
Booting CMT...
[Nokia USB Phonet]: Port opened OK!
Switching to RAW Mode...
[Nokia USB Flashing Generic]: Port opened OK!
Old ROM Detected
CMT_SYSTEM_ASIC_ID: 000000030000022600010007400C192103032108
CMT_EM_ASIC_ID: 00001040
CMT_EM_ASIC_ID: 00001030
CMT_PUBLIC_ID: EC130000FFFF7C40D88E7ED917D36D2FC8DAFF43
CMT_ASIC_MODE_ID: 00
CMT_ROOT_KEY_HASH: 3AB5DB70B45D23F1ADEEBB5734160706
CMT_BOOT_ROM_CRC: 2CAC45E2
CMT_SECURE_ROM_CRC: 3BC33C8B
CMT Ready!
RAPUv21_2nd.fg, Type: 2nd Boot Loader, Rev: 768.11.16.0, Algo: BB5
Using NEW BB5 FLASHING PROTOCOL
Waiting for USB Boot ROM Answer...
ROM Ret: 0xFFFD125D
ROM CMT dwAddr: 0x10004FF0
ROM CMT dwLength: 0x00627837
Seems ROM Initialized OK!
Transmission Mode Requested: Control USB, Accepted: Control USB
FlashChip[0,CMT]: 0x0000000000000000, Unknown, RAM
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
FlashChip[0,CMT]: 0x0000000000000000, Unknown, NOR
FlashChip[1,CMT]: 0x0000000100000000, Unknown, NOR
FlashChip[0,CMT]: 0x00EC006000000032, Samsung, ONENAND
Requested Algorithm: XSR 1.6 (CMT)
Sending Auxiliary Loader...
Auxiliary Loader Sent!
Loader: RAPxx CommonBoot v1.07 (C) 2011 KarwosLabs
Custom loader running OK! Working...
If phone doesn't powering into Local Mode now for some reason do following:
1. Re-insert battery
2. Power it on, when asked use Ovi/Pc Suite Mode
Readed OK, Saving to "EC130000FFFF7C40D88E7ED917D36D2FC8DAFF43.C0004AAC "
Success!
Nk701 detailed security analysis
Code:
Started Phone Security Analysis...
[Nokia USB Phonet]: Port opened OK!
MCU Version V 79u_11w31.4
MCU Date 16-08-11
Product RM-774 (Nokia 701)
Manufacturer (c) Nokia
IMEI 358272040230347
Mastercode 752474040
Reading Security Block...
Security block OK and saved to "RM-774_358272040230347_2011-10-04_022815.SecurityBlock.PM"
Step 1 : Testing SIMLOCK
SIMLOCK SEFLTEST PASSED OK!
Step 2 : Testing SECURITY
SECURITY SEFLTEST PASSED OK!
Step 3 : Analyzing Security Block
"EC130000FFFF7C40D88E7ED917D36D2FC8DAFF43.C0004AAC " Exists, That is good...
Checking SUPERDONGLE...
SUPERDONGLE FOUND AND CHECKSUM OK! PASSED!
Checking SIMLOCK...
Failed to decode Security Section, Box Reported: Security Section Not Found (SL3 phone?)
Checking MCU&DSP TIMESTAMPS...
MCU&DSP TIMESTAMPS FOUND AND CHECKSUM OK! PASSED!
Checking CMLA KEYS...
CMLA KEYS FOUND AND CHECKSUM OK! PASSED!
Checking ECC KEYS...
ECC KEYS FOUND AND CHECKSUM OK! PASSED!
Checking DIV KEYS...
DIV KEYS FOUND AND CHECKSUM OK! PASSED!
Analyze finished!
Nk 701, full RPL
Code:
RPL Creation started...
Processing CMT Part...
[Nokia USB Phonet]: Port opened OK!
Storing Product Code...
Storing PSN...
Storing HWID...
Trying to store Simlock...
Reading Configuration Key...
Hashing...
Reading SHA1-RSA Signature...
Reading SHA1-HMAC Signature...
Storing Simlock...
Trying to store WMDRM RPL...
Reading Keys...
Storing WMDRM PD...
Reading Security Block...
Security block OK and saved to "RM-774_358272040230347_2011-10-04_022831.SecurityBlock.PM"
"EC130000FFFF7C40D88E7ED917D36D2FC8DAFF43.C0004AAC " Exists, That is good...
Storing Additional Data...
Checking Superdongle Key...
Encrypting Superdongle Key...
Storing Superdongle Key...
Checking CMLA Key...
Storing CMLA Key...
Booting CMT...
[Nokia USB Phonet]: Port opened OK!
Switching to RAW Mode...
[Nokia USB Flashing Generic]: Port opened OK!
Old ROM Detected
CMT_SYSTEM_ASIC_ID: 000000030000022600010007400C192103032108
CMT_EM_ASIC_ID: 00001040
CMT_EM_ASIC_ID: 00001030
CMT_PUBLIC_ID: EC130000FFFF7C40D88E7ED917D36D2FC8DAFF43
CMT_ASIC_MODE_ID: 00
CMT_ROOT_KEY_HASH: 3AB5DB70B45D23F1ADEEBB5734160706
CMT_BOOT_ROM_CRC: 2CAC45E2
CMT_SECURE_ROM_CRC: 3BC33C8B
CMT Ready!
Searching for BootCode: DualLine 32Bit
RAPUv21_2nd.fg, Type: 2nd Boot Loader, Rev: 768.11.24.0, Algo: BB5
Using NEW BB5 FLASHING PROTOCOL
Waiting for USB Boot ROM Answer...
ROM Ret: 0xFFFD125D
ROM CMT dwAddr: 0x10004FF0
ROM CMT dwLength: 0x00627837
Seems ROM Initialized OK!
Transmission Mode Requested: Control USB, Accepted: Control USB
FlashChip[0,CMT]: 0x0000000000000000, Unknown, RAM
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
FlashChip[0,CMT]: 0x0000000000000000, Unknown, NOR
FlashChip[1,CMT]: 0x0000000100000000, Unknown, NOR
FlashChip[0,CMT]: 0x00EC006000000032, Samsung, ONENAND
Requested Algorithm: XSR 1.6 (CMT)
Searching for BootCode: DualLine 32Bit
FlashChip 0x00EC0060 (Samsung), Size: 1024MBytes, VPP: Not Supported
RAPUv21_XSR17_alg.fg, Type: Algorithm, Rev: 768.11.24.0, Algo: XSR 1.6
Initializing TurboCache...
TurboCache Loaded!
Writing CMT PASUBTOC Certificate...
Writing CMT ALG Certificate...
CMT Algorithm Ready!
Transmission Mode Requested: Bulk USB, Accepted: Bulk USB
Box TX2 Data Pin set to: Service Pin 3
Waiting for FUR Client become avaiable...
[Nokia USB Flashing Generic]: Port opened OK!
FUR Avaiable!
Adding FUR Client (CMT, State: Ready)...
CMT FUR Ready!
Overriding VPP Setting, USB can't use VPP
Box VPP disabled
Internal CMT Phone VPP Enabled
PAPUBKEYS Hash for CMT: FEB3BB7481D3E5D0EAC907335A4402A071493D53
APE Subsystem Not Found
Storing NPC...
Storing CCC...
Storing HWC...
CMT VARIANT Not Found
Storing PARTNERC...
Restarting MCU...
RPL Saved OK
Standalone SX4 operation
Code:
SX4 Authorization / SD Repair Procedure Started....
[Nokia USB Phonet]: Port opened OK!
"EC130000FFFF7C40D88E7ED917D36D2FC8DAFF43.C0004AAC " Exists, That is good...
[Nokia USB Phonet]: Port opened OK!
MCU Version V 79u_11w31.4
MCU Date 16-08-11
Product RM-774 (Nokia 701)
Manufacturer (c) Nokia
IMEI 358272040230347
Mastercode 752474040
Reading Security Block...
Security block OK and saved to "RM-774_358272040230347_2011-10-04_022851.SecurityBlock.PM"
SX4 Status: Not authorized (74)
Started mutual authenthication with card...
Receiving Phone Seed 1...
Phone Seed 1 Received
Sending calculated Data 1, and expecting Seed 2...
Calculated Data 1 accepted, Phone Seed 2 Received
Sending calculated Data 2
Calculated Data 2 sent, Checking Authorization Status again
Authorization successfully finished!
Looking for Virgin PM In Database...
Virgin PM Not found in local database, obtain one (with fields 1 and 309) and write it using "Write PM" Button
Copying our loaders will affect in cracks/clones in market shortly and maybe Broadcom Unlocking business destroy.
At least firmware 1.74 needed (update isn't needed at all).
Don't forget to have installed latest v1.16 installer (http://www.karwos.hk/CycloneBoxInstaller.exe), so Autoupdate module will do the job.
Best Regards,
Cyclone Team