Leshiy07
12.07.2012, 03:18
И так прошу помощи тело ведет себя совсем не ординарно :
Делаю еразе с помощью циклона
Booting CMT...
[Nokia C6-01 USB Phonet]: Port opened OK!
Switching to RAW Mode...
[Nokia USB Flashing Generic]: Port opened OK!
Old ROM Detected
CMT_SYSTEM_ASIC_ID: 000000030000022600010007600C192102031104
CMT_EM_ASIC_ID: 00001040
CMT_EM_ASIC_ID: 00001030
CMT_PUBLIC_ID: 1A300110747B574055D894BC0DCE9B56B482F3C5
CMT_ASIC_MODE_ID: 00
CMT_ROOT_KEY_HASH: 916F75217F32081248B15C38DFC8E81B
CMT_BOOT_ROM_CRC: E693EF0D
CMT_SECURE_ROM_CRC: AC22615B
CMT Ready!
Searching for BootCode: DualLine 32Bit
RAPUv11_2nd.fg, Type: 2nd Boot Loader, Rev: 768.12.11.0, Algo: BB5
Using NEW BB5 FLASHING PROTOCOL
Waiting for USB Boot ROM Answer...
ROM Ret: 0xFFFD125D
ROM CMT dwAddr: 0x10004FF0
ROM CMT dwLength: 0x00627837
Seems ROM Initialized OK!
Transmission Mode Requested: Control USB, Accepted: Control USB
FlashChip[0,CMT]: 0x0000000000000000, Unknown, RAM
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
FlashChip[0,CMT]: 0x0000000000000000, Unknown, NOR
FlashChip[1,CMT]: 0x0000000100000000, Unknown, NOR
FlashChip[0,CMT]: 0x00EC006800000131, Samsung, ONENAND
Requested Algorithm: XSR 1.6 (CMT)
Searching for BootCode: DualLine 32Bit
FlashChip 0x00EC0068 (Samsung), Size: 1024MBytes, VPP: Not Supported
RAPUv11_XSR17_alg.fg, Type: Algorithm, Rev: 768.12.11.0, Algo: XSR 1.6
Initializing TurboCache...
TurboCache Loaded!
Writing CMT PASUBTOC Certificate...
Writing CMT ALG Certificate...
CMT Algorithm Ready!
Transmission Mode Requested: Bulk USB, Accepted: Bulk USB
Box TX2 Data Pin set to: Service Pin 3
Waiting for FUR Client become avaiable...
[Nokia USB Flashing Generic]: Port opened OK!
FUR Avaiable!
Adding FUR Client (CMT, State: Ready)...
CMT FUR Ready!
Overriding VPP Setting, USB can't use VPP
Box VPP disabled
Internal CMT Phone VPP Enabled
PAPUBKEYS Hash for CMT: C436DE8B3DEA6D6C6CCE9CBE15F7C501BB822D02
APE Subsystem Not Found
Erasing flash chip...
Started group flash erase
EraseArea[0,CMT]: 0x00000000-0x3FFFFFFF, ONENAND
Waiting 640s for erasure finish...
Erase taken 4.181s
Restarting MCU...
BB5 Full Erase Finished!
После прошиваю :
RM-718_014.002_01.01_79.92_prd.uda.fpsx
RM-718_014.002_04.01_Russian_79.92_prd.rofs2.fpsx
RM-718_014.002_79.92_prd.core.fpsx
RM-718_014.002_00.01_79.92_prd.rofs3.fpsx
И беру файл ено (по совету Левши) ето спрошивки 025.007_00.01_79.92 RM601_APE_ONLY_ENO_11wk15_PS2_v0.063.fpsx
(мной было проексперементировано с ено фалами других прошивок они к сожелению не подходят . и обнаружено что на rm-718 ено файлов не существует)
После перезагрузки аппарата имеем локал моде благодаря ено
Лог прошивки
Processing pre flash tasks...
Pre flash tasks finished, continuing...
Processing RM-718_014.002_79.92_prd.core.fpsx (CMT)...
Booting CMT...
[Nokia USB Flashing Generic]: Port opened OK!
Old ROM Detected
CMT_SYSTEM_ASIC_ID: 000000030000022600010007600C192102031104
CMT_EM_ASIC_ID: 00001040
CMT_EM_ASIC_ID: 00001030
CMT_PUBLIC_ID: 1A300110747B574055D894BC0DCE9B56B482F3C5
CMT_ASIC_MODE_ID: 00
CMT_ROOT_KEY_HASH: 916F75217F32081248B15C38DFC8E81B
CMT_BOOT_ROM_CRC: E693EF0D
CMT_SECURE_ROM_CRC: AC22615B
CMT Ready!
RM-718_014.002_79.92_prd.core.fpsx, Type: Flash Image, Algo: XSR 1.6, BB5
Searching for BootCode: DualLine 32Bit
RAPUv11_2nd.fg, Type: 2nd Boot Loader, Rev: 768.12.11.0, Algo: BB5
Using NEW BB5 FLASHING PROTOCOL
Waiting for USB Boot ROM Answer...
ROM Ret: 0xFFFD125D
ROM CMT dwAddr: 0x10004FF0
ROM CMT dwLength: 0x00627837
Seems ROM Initialized OK!
Transmission Mode Requested: Control USB, Accepted: Control USB
FlashChip[0,CMT]: 0x0000000000000000, Unknown, RAM
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
FlashChip[0,CMT]: 0xFFFFFFFF00000000, Unknown, NOR
FlashChip[1,CMT]: 0x0000000100000000, Unknown, NOR
FlashChip[0,CMT]: 0x00EC006800000131, Samsung, ONENAND
Requested Algorithm: XSR 1.6 (CMT)
Searching for BootCode: DualLine 32Bit
FlashChip 0x00EC0068 (Samsung), Size: 1024MBytes, VPP: Not Supported
RAPUv11_XSR17_alg.fg, Type: Algorithm, Rev: 768.12.11.0, Algo: XSR 1.6
Initializing TurboCache...
TurboCache Loaded!
Writing CMT PASUBTOC Certificate...
Writing CMT ALG Certificate...
CMT Algorithm Ready!
Transmission Mode Requested: Bulk USB, Accepted: Bulk USB
Box TX2 Data Pin set to: Service Pin 3
Waiting for FUR Client become avaiable...
[Nokia USB Flashing Generic]: Port opened OK!
FUR Avaiable!
Adding FUR Client (CMT, State: Ready)...
CMT FUR Ready!
Overriding VPP Setting, USB can't use VPP
Box VPP disabled
Internal CMT Phone VPP Enabled
Warning: PAPUBKEYS Hash Missing!
Sending Certificates...
Certificates OK
Partitioning...
Partitioning OK
Started group flash erase
EraseArea[0,CMT]: 0x00040000-0x0007FFFF, ONENAND
EraseArea[0,CMT]: 0x000C0000-0x008BFFFF, ONENAND
EraseArea[0,CMT]: 0x00DC0000-0x0DAFFFFF, ONENAND
EraseArea[0,CMT]: 0x2E100000-0x3E5FFFFF, ONENAND
Erase Partition (CMT)
Waiting 320s for erasure finish...
Erase taken 2.13s
Writing all blocks...
Initializing TurboCache...
TurboCache Loaded!
Writing CMT ADA Certificate...
Writing CMT KEYS Certificate...
Writing CMT PRIMAPP Certificate...
Writing CMT RAP3NAND Certificate...
Writing CMT SOS+PMML Certificate...
Writing CMT PASUBTOC Certificate...
WARNING: CMT PAPUBKEYS Hash is Empty, writing first found PAPUBKEYS
Writing CMT PAPUBKEYS Certificate...
Writing CMT GENIO_INIT Certificate...
Writing CMT SOS*UPDAPP Certificate...
Writing CMT SOS*DSP0 Certificate...
Writing CMT LDSP Certificate...
Writing CMT SOS*ISASW Certificate...
Writing CMT SOS+CORE Certificate...
Writing CMT SOS+ROFS1 Certificate...
Programming Status OK!
All blocks written OK! Time taken 17.909s
Flashing Speed: 54900,94 kBit/S
Processing RM-718_014.002_79.92_prd.core.fpsx (APE)...
Processing RM-718_014.002_01.01_79.92_prd.uda.fpsx (CMT)...
RM-718_014.002_01.01_79.92_prd.uda.fpsx, Type: Flash Image, Algo: XSR 1.6, BB5
PAPUBKEYS Hash for CMT: C436DE8B3DEA6D6C6CCE9CBE15F7C501BB822D02
Started group flash erase
EraseArea[0,CMT]: 0x0DB00000-0x2E0FFFFF, ONENAND
Waiting 320s for erasure finish...
Erase taken 2.153s
Writing all blocks...
Initializing TurboCache...
TurboCache Loaded!
Programming Status OK!
All blocks written OK! Time taken 13.837s
Flashing Speed: 55868,10 kBit/S
Processing RM-718_014.002_01.01_79.92_prd.uda.fpsx (APE)...
Processing RM-718_014.002_04.01_Russian_79.92_prd.rofs2.fpsx (CMT)...
RM-718_014.002_04.01_Russian_79.92_prd.rofs2.fpsx, Type: Flash Image, Algo: XSR 1.6, BB5
PAPUBKEYS Hash for CMT: C436DE8B3DEA6D6C6CCE9CBE15F7C501BB822D02
Started group flash erase
EraseArea[0,CMT]: 0x090C0000-0x0CBFFFFF, ONENAND
Waiting 320s for erasure finish...
Erase taken 0.250s
Writing all blocks...
Initializing TurboCache...
TurboCache Loaded!
Writing CMT SOS+ROFS2 Certificate...
Programming Status OK!
All blocks written OK! Time taken 4.992s
Flashing Speed: 65489,51 kBit/S
Processing RM-718_014.002_04.01_Russian_79.92_prd.rofs2.fpsx (APE)...
Processing RM-718_014.002_00.01_79.92_prd.rofs3.fpsx (CMT)...
RM-718_014.002_00.01_79.92_prd.rofs3.fpsx, Type: Flash Image, Algo: XSR 1.6, BB5
PAPUBKEYS Hash for CMT: C436DE8B3DEA6D6C6CCE9CBE15F7C501BB822D02
Started group flash erase
EraseArea[0,CMT]: 0x0CC00000-0x0DAFFFFF, ONENAND
Waiting 320s for erasure finish...
Erase taken 0.62s
Writing all blocks...
Initializing TurboCache...
TurboCache Loaded!
Writing CMT SOS+ROFS3 Certificate...
Programming Status OK!
All blocks written OK! Time taken 0.266s
Flashing Speed: 147,73 kBit/S
Processing RM-718_014.002_00.01_79.92_prd.rofs3.fpsx (APE)...
Processing RM601_APE_ONLY_ENO_11wk15_PS2_v0.063.fpsx (CMT)...
RM601_APE_ONLY_ENO_11wk15_PS2_v0.063.fpsx, Type: Flash Image, Algo: XSR 1.6, BB5
PAPUBKEYS Hash for CMT: C436DE8B3DEA6D6C6CCE9CBE15F7C501BB822D02
Sending Certificates...
Certificates OK
Started group flash erase
EraseArea[0,CMT]: 0x008C0000-0x00DBFFFF, ONENAND
Waiting 320s for erasure finish...
Erase taken 0.47s
Writing all blocks...
Initializing TurboCache...
TurboCache Loaded!
Writing CMT SOS*ENO Certificate...
Programming Status OK!
All blocks written OK! Time taken 0.827s
Flashing Speed: 48024,76 kBit/S
Processing RM601_APE_ONLY_ENO_11wk15_PS2_v0.063.fpsx (APE)...
Restarting MCU...
All images processed OK! Processing post flash tasks...
Post flash tasks finished!
Flashing successfully finished!
В итоге имеем почему rm 601 (наверно изза не правльного ПМ) ну и понятно что Сп инфо мертвое
[Nokia C6-01 USB Phonet]: Port opened OK!
MCU Version V 92PS1_10w46.9
MCU Date 01-03-11
Product RM-601 (Nokia C6-01)
Manufacturer (c) Nokia
IMEI 12345610654321?
IMEI Spare 1A32541660452301
IMEI SV 1332541660452311F0000000
PSN 0
PSD 0000000000000000
LPSN 0
APE SW 014.002
APE Variant 014.002.00.01014.002.04.01014.002.00.01
APE Test 0.063
APE HW 256
APE ADSP 256
APE BT HCI Version 4 (rev. 0). LMP Version 4 (rev. 7455). Manufacturer 13.
RETU 40
TAHVO 00
AHNE 11
RFIC |Alli_4.3.4
DSP TB92PS1_10w46.4
Failed to read info -> Failed to read SP info
По логике вещей нужно прописать РПЛ. Имеем труп который входил в локал но включаеться постоянная перезагрузка
[Nokia C6-01 USB Phonet]: Port opened OK!
MCU Version V 92PS1_10w46.9
MCU Date 01-03-11
Product RM-601 (Nokia C6-01)
Manufacturer (c) Nokia
IMEI 353759045161126
Mastercode 1665771210
IMEI Spare 3A35570954611102
IMEI SV 3335570954611112F0000000
PSN 0
PSD 0000000000000000
LPSN 0
WLAN MAC 90CF155823E4
APE SW 014.002
APE Variant 014.002.00.01014.002.04.01014.002.00.01
APE Test 0.063
APE HW 256
APE ADSP 256
APE BT HCI Version 4 (rev. 0). LMP Version 4 (rev. 7455). Manufacturer 13.
RETU 40
TAHVO 00
AHNE 11
RFIC |Alli_4.3.4
DSP TB92PS1_10w46.4
Simlock Server SIMLOCK SERVER
Simlock Key 2440700000000000
Simlock Profile 0000000000000000
Simlock Key Cnt 0
Simlock FBUS Cnt 0
Simlock [1,1] State: OPENED Type: MCC-MNC Data: FFFFFF
Simlock [1,2] State: OPENED Type: GID Data: FFFF
Simlock [1,3] State: OPENED Type: GID Data: FFFF
Simlock [1,4] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Simlock [1,5] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Simlock [2,1] State: OPENED Type: MCC-MNC Data: FFFFFF
Simlock [2,2] State: OPENED Type: GID Data: FFFF
Simlock [2,3] State: OPENED Type: GID Data: FFFF
Simlock [2,4] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Simlock [2,5] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Simlock [3,1] State: OPENED Type: MCC-MNC Data: FFFFFF
Simlock [3,2] State: OPENED Type: GID Data: FFFF
Simlock [3,3] State: OPENED Type: GID Data: FFFF
Simlock [3,4] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Simlock [3,5] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Simlock [4,1] State: OPENED Type: MCC-MNC Data: FFFFFF
Simlock [4,2] State: OPENED Type: GID Data: FFFF
Simlock [4,3] State: OPENED Type: GID Data: FFFF
Simlock [4,4] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Simlock [4,5] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Simlock [5,1] State: OPENED Type: MCC-MNC Data: FFFFFF
Simlock [5,2] State: OPENED Type: GID Data: FFFF
Simlock [5,3] State: OPENED Type: GID Data: FFFF
Simlock [5,4] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Simlock [5,5] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Simlock [6,1] State: OPENED Type: MCC-MNC Data: FFFFFF
Simlock [6,2] State: OPENED Type: GID Data: FFFF
Simlock [6,3] State: OPENED Type: GID Data: FFFF
Simlock [6,4] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Simlock [6,5] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Simlock [7,1] State: OPENED Type: MCC-MNC Data: FFFFFF
Simlock [7,2] State: OPENED Type: GID Data: FFFF
Simlock [7,3] State: OPENED Type: GID Data: FFFF
Simlock [7,4] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Simlock [7,5] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Проходим сх4 авторизацию (просто бред)
SX4 Authorization / SD Repair Procedure Started....
[Nokia C6-01 USB Phonet]: Port opened OK!
Failed to obtain Phone Unique Data, Will use Server and Original Card
[Nokia C6-01 USB Phonet]: Port opened OK!
MCU Version V 92PS1_10w46.9
MCU Date 01-03-11
Product RM-601 (Nokia C6-01)
Manufacturer (c) Nokia
IMEI 353759045161126
Mastercode 1665771210
SX4 Status: Not authorized (74)
Started mutual authenthication with card...
Cyclone Server (2.0.0.44), Cyclone Box Team 2008-2012 - Ready.
Receiving Phone Seed 1...
Phone Seed 1 Received
Sending calculated Data 1, and expecting Seed 2...
Calculated Data 1 accepted, Phone Seed 2 Received
Sending calculated Data 2
Calculated Data 2 sent, Checking Authorization Status again
Authorization successfully finished!
Looking for Virgin PM In Database...
Virgin PM Not found in local database, obtain one (with fields 1 and 309) and write it using "Write PM" Button
Disconnected from Cyclone Server
После прописи Пм от u5oq перезагрузка и контакт реталиер ((( и нормальный продукт
Проходим уже по человечески СХ4 авторизацию
MCU Version V 92PS1_10w46.9
MCU Date 01-03-11
Product RM-718 (Nokia C6-01)
Manufacturer (c) Nokia
IMEI 353759045161126
Mastercode 1665771210
SX4 Status: Not authorized (74)
Started mutual authenthication with card...
Cyclone Server (2.0.0.44), Cyclone Box Team 2008-2012 - Ready.
Receiving Phone Seed 1...
Phone Seed 1 Received
Sending calculated Data 1, and expecting Seed 2...
Calculated Data 1 accepted, Phone Seed 2 Received
Sending calculated Data 2
Calculated Data 2 sent, Checking Authorization Status again
Authorization successfully finished!
Looking for Virgin PM In Database...
Found, writing...
[Nokia C6-01 USB Phonet]: Port opened OK!
[1,0] Written, Length: 10 bytes, Status: OK
[1,1] Written, Length: 94 bytes, Status: OK
[1,2] Written, Length: 110 bytes, Status: OK
[1,4] Written, Length: 10 bytes, Status: OK
[1,6] Written, Length: 110 bytes, Status: OK
[1,7] Written, Length: 450 bytes, Status: OK
[1,8] Written, Length: 10 bytes, Status: OK
[1,13] Written, Length: 110 bytes, Status: OK
[1,15] Written, Length: 30 bytes, Status: OK
[1,16] Written, Length: 30 bytes, Status: OK
[1,17] Written, Length: 30 bytes, Status: OK
[1,18] Written, Length: 30 bytes, Status: OK
[1,19] Written, Length: 30 bytes, Status: OK
[1,22] Written, Length: 24 bytes, Status: OK
[1,26] Written, Length: 10 bytes, Status: OK
[1,27] Written, Length: 36 bytes, Status: OK
[1,28] Written, Length: 110 bytes, Status: OK
[1,29] Written, Length: 10 bytes, Status: OK
[1,30] Written, Length: 36 bytes, Status: OK
[1,31] Written, Length: 24 bytes, Status: OK
[1,32] Written, Length: 216 bytes, Status: OK
[1,33] Written, Length: 36 bytes, Status: OK
[1,35] Written, Length: 24 bytes, Status: OK
[1,36] Written, Length: 24 bytes, Status: OK
[1,38] Written, Length: 216 bytes, Status: OK
[1,39] Written, Length: 36 bytes, Status: OK
[1,40] Written, Length: 24 bytes, Status: OK
[1,41] Written, Length: 216 bytes, Status: OK
[1,43] Written, Length: 36 bytes, Status: OK
[1,44] Written, Length: 216 bytes, Status: OK
[1,45] Written, Length: 216 bytes, Status: OK
[2,0] Written, Length: 2240 bytes, Status: OK
[309,0] Written, Length: 4 bytes, Status: OK
[309,1] Written, Length: 2 bytes, Status: OK
[309,2] Written, Length: 12 bytes, Status: OK
[309,3] Written, Length: 36 bytes, Status: OK
[309,4] Written, Length: 12 bytes, Status: OK
[309,7] Written, Length: 12 bytes, Status: OK
[309,17] Written, Length: 12 bytes, Status: OK
Write PM Finished, Record written OK: 39, Record written NOT OK: 0
Disconnected from Cyclone Server
В итоге имеем Failed ST_SECURITY_TEST Как его побороть ???
ПС если перед восстановлением рпл пролить какой либо хороший ПМ( тот который product rm718) то он не востанавливает …
Делаю еразе с помощью циклона
Booting CMT...
[Nokia C6-01 USB Phonet]: Port opened OK!
Switching to RAW Mode...
[Nokia USB Flashing Generic]: Port opened OK!
Old ROM Detected
CMT_SYSTEM_ASIC_ID: 000000030000022600010007600C192102031104
CMT_EM_ASIC_ID: 00001040
CMT_EM_ASIC_ID: 00001030
CMT_PUBLIC_ID: 1A300110747B574055D894BC0DCE9B56B482F3C5
CMT_ASIC_MODE_ID: 00
CMT_ROOT_KEY_HASH: 916F75217F32081248B15C38DFC8E81B
CMT_BOOT_ROM_CRC: E693EF0D
CMT_SECURE_ROM_CRC: AC22615B
CMT Ready!
Searching for BootCode: DualLine 32Bit
RAPUv11_2nd.fg, Type: 2nd Boot Loader, Rev: 768.12.11.0, Algo: BB5
Using NEW BB5 FLASHING PROTOCOL
Waiting for USB Boot ROM Answer...
ROM Ret: 0xFFFD125D
ROM CMT dwAddr: 0x10004FF0
ROM CMT dwLength: 0x00627837
Seems ROM Initialized OK!
Transmission Mode Requested: Control USB, Accepted: Control USB
FlashChip[0,CMT]: 0x0000000000000000, Unknown, RAM
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
FlashChip[0,CMT]: 0x0000000000000000, Unknown, NOR
FlashChip[1,CMT]: 0x0000000100000000, Unknown, NOR
FlashChip[0,CMT]: 0x00EC006800000131, Samsung, ONENAND
Requested Algorithm: XSR 1.6 (CMT)
Searching for BootCode: DualLine 32Bit
FlashChip 0x00EC0068 (Samsung), Size: 1024MBytes, VPP: Not Supported
RAPUv11_XSR17_alg.fg, Type: Algorithm, Rev: 768.12.11.0, Algo: XSR 1.6
Initializing TurboCache...
TurboCache Loaded!
Writing CMT PASUBTOC Certificate...
Writing CMT ALG Certificate...
CMT Algorithm Ready!
Transmission Mode Requested: Bulk USB, Accepted: Bulk USB
Box TX2 Data Pin set to: Service Pin 3
Waiting for FUR Client become avaiable...
[Nokia USB Flashing Generic]: Port opened OK!
FUR Avaiable!
Adding FUR Client (CMT, State: Ready)...
CMT FUR Ready!
Overriding VPP Setting, USB can't use VPP
Box VPP disabled
Internal CMT Phone VPP Enabled
PAPUBKEYS Hash for CMT: C436DE8B3DEA6D6C6CCE9CBE15F7C501BB822D02
APE Subsystem Not Found
Erasing flash chip...
Started group flash erase
EraseArea[0,CMT]: 0x00000000-0x3FFFFFFF, ONENAND
Waiting 640s for erasure finish...
Erase taken 4.181s
Restarting MCU...
BB5 Full Erase Finished!
После прошиваю :
RM-718_014.002_01.01_79.92_prd.uda.fpsx
RM-718_014.002_04.01_Russian_79.92_prd.rofs2.fpsx
RM-718_014.002_79.92_prd.core.fpsx
RM-718_014.002_00.01_79.92_prd.rofs3.fpsx
И беру файл ено (по совету Левши) ето спрошивки 025.007_00.01_79.92 RM601_APE_ONLY_ENO_11wk15_PS2_v0.063.fpsx
(мной было проексперементировано с ено фалами других прошивок они к сожелению не подходят . и обнаружено что на rm-718 ено файлов не существует)
После перезагрузки аппарата имеем локал моде благодаря ено
Лог прошивки
Processing pre flash tasks...
Pre flash tasks finished, continuing...
Processing RM-718_014.002_79.92_prd.core.fpsx (CMT)...
Booting CMT...
[Nokia USB Flashing Generic]: Port opened OK!
Old ROM Detected
CMT_SYSTEM_ASIC_ID: 000000030000022600010007600C192102031104
CMT_EM_ASIC_ID: 00001040
CMT_EM_ASIC_ID: 00001030
CMT_PUBLIC_ID: 1A300110747B574055D894BC0DCE9B56B482F3C5
CMT_ASIC_MODE_ID: 00
CMT_ROOT_KEY_HASH: 916F75217F32081248B15C38DFC8E81B
CMT_BOOT_ROM_CRC: E693EF0D
CMT_SECURE_ROM_CRC: AC22615B
CMT Ready!
RM-718_014.002_79.92_prd.core.fpsx, Type: Flash Image, Algo: XSR 1.6, BB5
Searching for BootCode: DualLine 32Bit
RAPUv11_2nd.fg, Type: 2nd Boot Loader, Rev: 768.12.11.0, Algo: BB5
Using NEW BB5 FLASHING PROTOCOL
Waiting for USB Boot ROM Answer...
ROM Ret: 0xFFFD125D
ROM CMT dwAddr: 0x10004FF0
ROM CMT dwLength: 0x00627837
Seems ROM Initialized OK!
Transmission Mode Requested: Control USB, Accepted: Control USB
FlashChip[0,CMT]: 0x0000000000000000, Unknown, RAM
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
FlashChip[0,CMT]: 0xFFFFFFFF00000000, Unknown, NOR
FlashChip[1,CMT]: 0x0000000100000000, Unknown, NOR
FlashChip[0,CMT]: 0x00EC006800000131, Samsung, ONENAND
Requested Algorithm: XSR 1.6 (CMT)
Searching for BootCode: DualLine 32Bit
FlashChip 0x00EC0068 (Samsung), Size: 1024MBytes, VPP: Not Supported
RAPUv11_XSR17_alg.fg, Type: Algorithm, Rev: 768.12.11.0, Algo: XSR 1.6
Initializing TurboCache...
TurboCache Loaded!
Writing CMT PASUBTOC Certificate...
Writing CMT ALG Certificate...
CMT Algorithm Ready!
Transmission Mode Requested: Bulk USB, Accepted: Bulk USB
Box TX2 Data Pin set to: Service Pin 3
Waiting for FUR Client become avaiable...
[Nokia USB Flashing Generic]: Port opened OK!
FUR Avaiable!
Adding FUR Client (CMT, State: Ready)...
CMT FUR Ready!
Overriding VPP Setting, USB can't use VPP
Box VPP disabled
Internal CMT Phone VPP Enabled
Warning: PAPUBKEYS Hash Missing!
Sending Certificates...
Certificates OK
Partitioning...
Partitioning OK
Started group flash erase
EraseArea[0,CMT]: 0x00040000-0x0007FFFF, ONENAND
EraseArea[0,CMT]: 0x000C0000-0x008BFFFF, ONENAND
EraseArea[0,CMT]: 0x00DC0000-0x0DAFFFFF, ONENAND
EraseArea[0,CMT]: 0x2E100000-0x3E5FFFFF, ONENAND
Erase Partition (CMT)
Waiting 320s for erasure finish...
Erase taken 2.13s
Writing all blocks...
Initializing TurboCache...
TurboCache Loaded!
Writing CMT ADA Certificate...
Writing CMT KEYS Certificate...
Writing CMT PRIMAPP Certificate...
Writing CMT RAP3NAND Certificate...
Writing CMT SOS+PMML Certificate...
Writing CMT PASUBTOC Certificate...
WARNING: CMT PAPUBKEYS Hash is Empty, writing first found PAPUBKEYS
Writing CMT PAPUBKEYS Certificate...
Writing CMT GENIO_INIT Certificate...
Writing CMT SOS*UPDAPP Certificate...
Writing CMT SOS*DSP0 Certificate...
Writing CMT LDSP Certificate...
Writing CMT SOS*ISASW Certificate...
Writing CMT SOS+CORE Certificate...
Writing CMT SOS+ROFS1 Certificate...
Programming Status OK!
All blocks written OK! Time taken 17.909s
Flashing Speed: 54900,94 kBit/S
Processing RM-718_014.002_79.92_prd.core.fpsx (APE)...
Processing RM-718_014.002_01.01_79.92_prd.uda.fpsx (CMT)...
RM-718_014.002_01.01_79.92_prd.uda.fpsx, Type: Flash Image, Algo: XSR 1.6, BB5
PAPUBKEYS Hash for CMT: C436DE8B3DEA6D6C6CCE9CBE15F7C501BB822D02
Started group flash erase
EraseArea[0,CMT]: 0x0DB00000-0x2E0FFFFF, ONENAND
Waiting 320s for erasure finish...
Erase taken 2.153s
Writing all blocks...
Initializing TurboCache...
TurboCache Loaded!
Programming Status OK!
All blocks written OK! Time taken 13.837s
Flashing Speed: 55868,10 kBit/S
Processing RM-718_014.002_01.01_79.92_prd.uda.fpsx (APE)...
Processing RM-718_014.002_04.01_Russian_79.92_prd.rofs2.fpsx (CMT)...
RM-718_014.002_04.01_Russian_79.92_prd.rofs2.fpsx, Type: Flash Image, Algo: XSR 1.6, BB5
PAPUBKEYS Hash for CMT: C436DE8B3DEA6D6C6CCE9CBE15F7C501BB822D02
Started group flash erase
EraseArea[0,CMT]: 0x090C0000-0x0CBFFFFF, ONENAND
Waiting 320s for erasure finish...
Erase taken 0.250s
Writing all blocks...
Initializing TurboCache...
TurboCache Loaded!
Writing CMT SOS+ROFS2 Certificate...
Programming Status OK!
All blocks written OK! Time taken 4.992s
Flashing Speed: 65489,51 kBit/S
Processing RM-718_014.002_04.01_Russian_79.92_prd.rofs2.fpsx (APE)...
Processing RM-718_014.002_00.01_79.92_prd.rofs3.fpsx (CMT)...
RM-718_014.002_00.01_79.92_prd.rofs3.fpsx, Type: Flash Image, Algo: XSR 1.6, BB5
PAPUBKEYS Hash for CMT: C436DE8B3DEA6D6C6CCE9CBE15F7C501BB822D02
Started group flash erase
EraseArea[0,CMT]: 0x0CC00000-0x0DAFFFFF, ONENAND
Waiting 320s for erasure finish...
Erase taken 0.62s
Writing all blocks...
Initializing TurboCache...
TurboCache Loaded!
Writing CMT SOS+ROFS3 Certificate...
Programming Status OK!
All blocks written OK! Time taken 0.266s
Flashing Speed: 147,73 kBit/S
Processing RM-718_014.002_00.01_79.92_prd.rofs3.fpsx (APE)...
Processing RM601_APE_ONLY_ENO_11wk15_PS2_v0.063.fpsx (CMT)...
RM601_APE_ONLY_ENO_11wk15_PS2_v0.063.fpsx, Type: Flash Image, Algo: XSR 1.6, BB5
PAPUBKEYS Hash for CMT: C436DE8B3DEA6D6C6CCE9CBE15F7C501BB822D02
Sending Certificates...
Certificates OK
Started group flash erase
EraseArea[0,CMT]: 0x008C0000-0x00DBFFFF, ONENAND
Waiting 320s for erasure finish...
Erase taken 0.47s
Writing all blocks...
Initializing TurboCache...
TurboCache Loaded!
Writing CMT SOS*ENO Certificate...
Programming Status OK!
All blocks written OK! Time taken 0.827s
Flashing Speed: 48024,76 kBit/S
Processing RM601_APE_ONLY_ENO_11wk15_PS2_v0.063.fpsx (APE)...
Restarting MCU...
All images processed OK! Processing post flash tasks...
Post flash tasks finished!
Flashing successfully finished!
В итоге имеем почему rm 601 (наверно изза не правльного ПМ) ну и понятно что Сп инфо мертвое
[Nokia C6-01 USB Phonet]: Port opened OK!
MCU Version V 92PS1_10w46.9
MCU Date 01-03-11
Product RM-601 (Nokia C6-01)
Manufacturer (c) Nokia
IMEI 12345610654321?
IMEI Spare 1A32541660452301
IMEI SV 1332541660452311F0000000
PSN 0
PSD 0000000000000000
LPSN 0
APE SW 014.002
APE Variant 014.002.00.01014.002.04.01014.002.00.01
APE Test 0.063
APE HW 256
APE ADSP 256
APE BT HCI Version 4 (rev. 0). LMP Version 4 (rev. 7455). Manufacturer 13.
RETU 40
TAHVO 00
AHNE 11
RFIC |Alli_4.3.4
DSP TB92PS1_10w46.4
Failed to read info -> Failed to read SP info
По логике вещей нужно прописать РПЛ. Имеем труп который входил в локал но включаеться постоянная перезагрузка
[Nokia C6-01 USB Phonet]: Port opened OK!
MCU Version V 92PS1_10w46.9
MCU Date 01-03-11
Product RM-601 (Nokia C6-01)
Manufacturer (c) Nokia
IMEI 353759045161126
Mastercode 1665771210
IMEI Spare 3A35570954611102
IMEI SV 3335570954611112F0000000
PSN 0
PSD 0000000000000000
LPSN 0
WLAN MAC 90CF155823E4
APE SW 014.002
APE Variant 014.002.00.01014.002.04.01014.002.00.01
APE Test 0.063
APE HW 256
APE ADSP 256
APE BT HCI Version 4 (rev. 0). LMP Version 4 (rev. 7455). Manufacturer 13.
RETU 40
TAHVO 00
AHNE 11
RFIC |Alli_4.3.4
DSP TB92PS1_10w46.4
Simlock Server SIMLOCK SERVER
Simlock Key 2440700000000000
Simlock Profile 0000000000000000
Simlock Key Cnt 0
Simlock FBUS Cnt 0
Simlock [1,1] State: OPENED Type: MCC-MNC Data: FFFFFF
Simlock [1,2] State: OPENED Type: GID Data: FFFF
Simlock [1,3] State: OPENED Type: GID Data: FFFF
Simlock [1,4] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Simlock [1,5] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Simlock [2,1] State: OPENED Type: MCC-MNC Data: FFFFFF
Simlock [2,2] State: OPENED Type: GID Data: FFFF
Simlock [2,3] State: OPENED Type: GID Data: FFFF
Simlock [2,4] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Simlock [2,5] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Simlock [3,1] State: OPENED Type: MCC-MNC Data: FFFFFF
Simlock [3,2] State: OPENED Type: GID Data: FFFF
Simlock [3,3] State: OPENED Type: GID Data: FFFF
Simlock [3,4] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Simlock [3,5] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Simlock [4,1] State: OPENED Type: MCC-MNC Data: FFFFFF
Simlock [4,2] State: OPENED Type: GID Data: FFFF
Simlock [4,3] State: OPENED Type: GID Data: FFFF
Simlock [4,4] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Simlock [4,5] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Simlock [5,1] State: OPENED Type: MCC-MNC Data: FFFFFF
Simlock [5,2] State: OPENED Type: GID Data: FFFF
Simlock [5,3] State: OPENED Type: GID Data: FFFF
Simlock [5,4] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Simlock [5,5] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Simlock [6,1] State: OPENED Type: MCC-MNC Data: FFFFFF
Simlock [6,2] State: OPENED Type: GID Data: FFFF
Simlock [6,3] State: OPENED Type: GID Data: FFFF
Simlock [6,4] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Simlock [6,5] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Simlock [7,1] State: OPENED Type: MCC-MNC Data: FFFFFF
Simlock [7,2] State: OPENED Type: GID Data: FFFF
Simlock [7,3] State: OPENED Type: GID Data: FFFF
Simlock [7,4] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Simlock [7,5] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Проходим сх4 авторизацию (просто бред)
SX4 Authorization / SD Repair Procedure Started....
[Nokia C6-01 USB Phonet]: Port opened OK!
Failed to obtain Phone Unique Data, Will use Server and Original Card
[Nokia C6-01 USB Phonet]: Port opened OK!
MCU Version V 92PS1_10w46.9
MCU Date 01-03-11
Product RM-601 (Nokia C6-01)
Manufacturer (c) Nokia
IMEI 353759045161126
Mastercode 1665771210
SX4 Status: Not authorized (74)
Started mutual authenthication with card...
Cyclone Server (2.0.0.44), Cyclone Box Team 2008-2012 - Ready.
Receiving Phone Seed 1...
Phone Seed 1 Received
Sending calculated Data 1, and expecting Seed 2...
Calculated Data 1 accepted, Phone Seed 2 Received
Sending calculated Data 2
Calculated Data 2 sent, Checking Authorization Status again
Authorization successfully finished!
Looking for Virgin PM In Database...
Virgin PM Not found in local database, obtain one (with fields 1 and 309) and write it using "Write PM" Button
Disconnected from Cyclone Server
После прописи Пм от u5oq перезагрузка и контакт реталиер ((( и нормальный продукт
Проходим уже по человечески СХ4 авторизацию
MCU Version V 92PS1_10w46.9
MCU Date 01-03-11
Product RM-718 (Nokia C6-01)
Manufacturer (c) Nokia
IMEI 353759045161126
Mastercode 1665771210
SX4 Status: Not authorized (74)
Started mutual authenthication with card...
Cyclone Server (2.0.0.44), Cyclone Box Team 2008-2012 - Ready.
Receiving Phone Seed 1...
Phone Seed 1 Received
Sending calculated Data 1, and expecting Seed 2...
Calculated Data 1 accepted, Phone Seed 2 Received
Sending calculated Data 2
Calculated Data 2 sent, Checking Authorization Status again
Authorization successfully finished!
Looking for Virgin PM In Database...
Found, writing...
[Nokia C6-01 USB Phonet]: Port opened OK!
[1,0] Written, Length: 10 bytes, Status: OK
[1,1] Written, Length: 94 bytes, Status: OK
[1,2] Written, Length: 110 bytes, Status: OK
[1,4] Written, Length: 10 bytes, Status: OK
[1,6] Written, Length: 110 bytes, Status: OK
[1,7] Written, Length: 450 bytes, Status: OK
[1,8] Written, Length: 10 bytes, Status: OK
[1,13] Written, Length: 110 bytes, Status: OK
[1,15] Written, Length: 30 bytes, Status: OK
[1,16] Written, Length: 30 bytes, Status: OK
[1,17] Written, Length: 30 bytes, Status: OK
[1,18] Written, Length: 30 bytes, Status: OK
[1,19] Written, Length: 30 bytes, Status: OK
[1,22] Written, Length: 24 bytes, Status: OK
[1,26] Written, Length: 10 bytes, Status: OK
[1,27] Written, Length: 36 bytes, Status: OK
[1,28] Written, Length: 110 bytes, Status: OK
[1,29] Written, Length: 10 bytes, Status: OK
[1,30] Written, Length: 36 bytes, Status: OK
[1,31] Written, Length: 24 bytes, Status: OK
[1,32] Written, Length: 216 bytes, Status: OK
[1,33] Written, Length: 36 bytes, Status: OK
[1,35] Written, Length: 24 bytes, Status: OK
[1,36] Written, Length: 24 bytes, Status: OK
[1,38] Written, Length: 216 bytes, Status: OK
[1,39] Written, Length: 36 bytes, Status: OK
[1,40] Written, Length: 24 bytes, Status: OK
[1,41] Written, Length: 216 bytes, Status: OK
[1,43] Written, Length: 36 bytes, Status: OK
[1,44] Written, Length: 216 bytes, Status: OK
[1,45] Written, Length: 216 bytes, Status: OK
[2,0] Written, Length: 2240 bytes, Status: OK
[309,0] Written, Length: 4 bytes, Status: OK
[309,1] Written, Length: 2 bytes, Status: OK
[309,2] Written, Length: 12 bytes, Status: OK
[309,3] Written, Length: 36 bytes, Status: OK
[309,4] Written, Length: 12 bytes, Status: OK
[309,7] Written, Length: 12 bytes, Status: OK
[309,17] Written, Length: 12 bytes, Status: OK
Write PM Finished, Record written OK: 39, Record written NOT OK: 0
Disconnected from Cyclone Server
В итоге имеем Failed ST_SECURITY_TEST Как его побороть ???
ПС если перед восстановлением рпл пролить какой либо хороший ПМ( тот который product rm718) то он не востанавливает …