About The New Way To Unlock Bootloader - Google Pixel XL Guides, News, & Discussion

Two days ago,I posted a new way to unlock bl.First, Its my mistake that I posted it ambiguous.
But the way really existed.I didnt lied.Beause I am not good at English.I just hope someone can hack it but I didnt express my idea exactly.My firend unlocked his bl by a specilist that controling remotely his computer. Maybe he used a tool like a Hard solution tool of HTC excetpt these adb cmd shared by me. He may shared his tool to my firend PC by Usbover(not sure).He would not publish his way.So my firend payed him money.But my firend took photos secretively when he was controling his computer.He firstly rewrited CID then downgraded to 7.1.1 from 7.1.2 by adb cmd (Maybe he used the special tool among the period.Then he flashed the ROM pacaged in a new way. he made it specially .Finally he unlocked bl. And all these steps was disussed by a group people not myself.We just dont have that tool. I have the address of the special ROM .[emoji40] Hoping someone can make it
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
from taptalk

Those screenshots dont make sense on a Pixel. The CID commands do not work on a Pixel.

chenery said:
Two days ago,I posted a new way to unlock bl.First, Its my mistake that I posted it ambiguous.
But the way really existed.I didnt lied.Beause I am not good at English.I just hope someone can hack it but I didnt express my idea exactly.My firend unlocked his bl by a specilist that controling remotely his computer. Maybe he used a tool like a Hard solution tool of HTC excetpt these adb cmd shared by me. He may shared his tool to my firend PC by Usbover(not sure).He would not publish his way.So my firend payed him money.But my firend took photos secretively when he was controling his computer.He firstly rewrited CID then downgraded to 7.1.1 from 7.1.2 by adb cmd (Maybe he used the special tool among the period.Then he flashed the ROM pacaged in a new way. he made it specially .Finally he unlocked bl. And all these steps was disussed by a group people not myself.We just dont have that tool. I have the address of the special ROM .[emoji40] Hoping someone can make it
from taptalk
Click to expand...
Click to collapse
Okay, responding to this, there are a few problems, and some interesting things.
The initial tool you mentioned must play a hell of an important role here.
By default, no Pixel has cid/mid read/write oem commands, and I don't know of a Pixel bootloader that does. This makes it odd. He then also uses htc_fastboot to flash "zip" which is a way to flashed signed RUU's on HTC phones. It is also worth noting he flashes NDE63H which was the first 7.1 build that shipped on the Pixel (vulnerable to DePixel8 at that point).
Our current bootloader doesn't support flashing "zip" either. It does oddly have a remnant oem rebootRUU command that does absolutely nothing, but we can't flash an RUU.
It is possible that there is some leaked signed HTC internal stuff being used here, which would explain the added HTC commands, and ability to flash an RUU. The only thing this wouldn't explain is why the rollback protection didn't block this (maybe their RUU doesn't include the older bootloader).
I don't know, additional information would be necessary to conclude anything about this.

I know this,my Verizon xl has been unlocked by the method.but the skill I don't have.days ago I buy the service from a merchant.the main method is downgrade the Android to 7.1.maybe someone can hack it.
---------- Post added at 09:54 AM ---------- Previous post was at 09:49 AM ----------
But in fact.i cannot get the img and he must have some documents to crack the cid to 111111.than it will go to htc download mode.

jackzhu said:
I know this,my Verizon xl has been unlocked by the method.but the skill I don't have.days ago I buy the service from a merchant.the main method is downgrade the Android to 7.1.maybe someone can hack it.
---------- Post added at 09:54 AM ---------- Previous post was at 09:49 AM ----------
But in fact.i cannot get the img and he must have some documents to crack the cid to 111111.than it will go to htc download mode.
Click to expand...
Click to collapse
Where did you buy the service from?

I'm still very dubious about this.
If there was a way, I've a feeling our developers would be aware of it here.
also, why is everything labelled HTC ?

Milly7 said:
Where did you buy the service from?
Click to expand...
Click to collapse
Taobao

y2grae said:
I'm still very dubious about this.
If there was a way, I've a feeling our developers would be aware of it here.
also, why is everything labelled HTC ?
Click to expand...
Click to collapse
I agree.. and HTC is the phone's manufacturer.

@jcase any ideas as this may be a good way for those to unlock the bootloader?

jackzhu said:
I know this,my Verizon xl has been unlocked by the method.but the skill I don't have.days ago I buy the service from a merchant.the main method is downgrade the Android to 7.1.maybe someone can hack it.
---------- Post added at 09:54 AM ---------- Previous post was at 09:49 AM ----------
But in fact.i cannot get the img and he must have some documents to crack the cid to 111111.than it will go to htc download mode.
Click to expand...
Click to collapse
Remember The name g-2pimg_m1_whl_n70_htc_generic_nde63h_user_release_r adio_not_specify_release_485606_2_4.zip exclusive

jackzhu said:
Remember The name g-2pimg_m1_whl_n70_htc_generic_nde63h_user_release_r adio_not_specify_release_485606_2_4.zip exclusive
Click to expand...
Click to collapse
I would try
from taptalk

It looks like the file in question can be found here: http://www.easy-firmware.com/index.php?a=browse&b=category&id=16647
My GoogleFU is strong.
I am at work and cannot download to find out what is in it, as anything else I try to do on the site is blocked. I do not think this firmware is for the Pixel, but if someone with an idea how our phone works can download the file, we can see what's inside and if it looks applicable. I find the entire thing VERY dubious, but if there's a way we can write the CID on our Verizon models, believe me, I WILL change mine.
Edit: I found the file on two other websites. All of them had it behind a paywall, but I found a different file with the same naming convention on another site that wasn't paywalled. I downloaded that file just now and will see if it is even software for our phones. I suspect this might be fore the HTC One Mini, but I'll see what's in this zip.

PWn3R said:
It looks like the file in question can be found here: http://www.easy-firmware.com/index.php?a=browse&b=category&id=16647
My GoogleFU is strong.
I am at work and cannot download to find out what is in it, as anything else I try to do on the site is blocked. I do not think this firmware is for the Pixel, but if someone with an idea how our phone works can download the file, we can see what's inside and if it looks applicable. I find the entire thing VERY dubious, but if there's a way we can write the CID on our Verizon models, believe me, I WILL change mine.
Click to expand...
Click to collapse
It's one of the process,I cannot remember all the steps

Could you please put up link to service that unlocks bootloader

So the other file that I downloaded with a similar name: G-2PIMG_M1_WHL_N70_HTC_Generic_NMF26U_user_release_Radio_Not_Specify_release_493363_2 contains a _VERY_ weird set of zip files inside. Inside atleast one of the zip files is a signed bootloader. There's an Android file that has model descriptor numbers that match the Pixel XL per what I found here: https://www.techwalls.com/google-pixel-pixel-xl-model-number-differences/
Inside the file that has the signed BL image is a file that contains what looks like a list of steps that tell it to wipe every partition on the device. I have no idea what program would be used to flash this firmware in the format it's in (the system image is chopped up into small chunks, and there are other oddities). I am posting the file in question on my Google Drive. Can @jcase look at this or someone who's got more knowledge than I do about how these phones work?
File can be downloaded here: https://drive.google.com/open?id=0B6BaDxaggle2YndJU2Ywd3BHRkk
FOR THE LOVE OF GOD AND ALL THAT IS GOOD, DO NOT FLASH ANYTHING FROM THIS ZIP UNTIL WE KNOW WHAT WE ARE LOOKING AT. IF YOU BRICK YOUR DEVICE, I WILL DIE LAUGHING

PWn3R said:
So the other file that I downloaded with a similar name: G-2PIMG_M1_WHL_N70_HTC_Generic_NMF26U_user_release_Radio_Not_Specify_release_493363_2 contains a _VERY_ weird set of zip files inside. Inside atleast one of the zip files is a signed bootloader. There's an Android file that has model descriptor numbers that match the Pixel XL per what I found here: https://www.techwalls.com/google-pixel-pixel-xl-model-number-differences/
Inside the file that has the signed BL image is a file that contains what looks like a list of steps that tell it to wipe every partition on the device. I have no idea what program would be used to flash this firmware in the format it's in (the system image is chopped up into small chunks, and there are other oddities). I am posting the file in question on my Google Drive. Can @jcase look at this or someone who's got more knowledge than I do about how these phones work?
File can be downloaded here: https://drive.google.com/open?id=0B6BaDxaggle2YndJU2Ywd3BHRkk
FOR THE LOVE OF GOD AND ALL THAT IS GOOD, DO NOT FLASH ANYTHING FROM THIS ZIP UNTIL WE KNOW WHAT WE ARE LOOKING AT. IF YOU BRICK YOUR DEVICE, I WILL DIE LAUGHING
Click to expand...
Click to collapse
i tried flashing the file you uploaded* and now my phone won't turn on.. do you know why or can you fix it for me? lmao
jokes aside, thanks for looking so far into this, especially when it could have been a malicious file.

fatapia said:
i tried flashing the file you uploaded* and now my phone won't turn on.. do you know why or can you fix it for me? lmao
jokes aside, thanks for looking so far into this, especially when it could have been a malicious file.
Click to expand...
Click to collapse
can you go into bootloader mode? If so, try running some htc commands

lucky_strike33 said:
can you go into bootloader mode? If so, try running some htc commands
Click to expand...
Click to collapse
I havent tried flashing it, I need my phone for day-to-day purposes at work so I can't risk bricking it. only made a joke because of the necessary disclaimer

fatapia said:
I havent tried flashing it, I need my phone for day-to-day purposes at work so I can't risk bricking it. only made a joke because of the necessary disclaimer
Click to expand...
Click to collapse
Missed that joke! Lol

After looking at this a bit, I don't have a good way to figure out if this bootloader is valid, and I'm not sure I want to buy a new phone if I brick my Pixel. If this actually does work, here's what I suspect was done. The file in question (possibly the specific version this guy used, maybe even the one I downloaded) is a version of the bootloader for our phone that supports additional commands. The guy installed the other version of the bootloader, changed the CID and other information then unlocked the bootloader. If I had a pixel laying around that had a broken screen or something, I would be willing to try to do what I think needs to be done to test this. That said someone else with more expertise may know of a way to check if the bootloader image is signed or check other things. I support the Beanstalk ROM on the Nexus 6 still but have not tried to make a build for the Pixel yet. While I am capable of making that happen, I am a retard compared to @jcase and others when it comes to this stuff.

Related

How to Peform a rom Dump

Hey guys,
I'm another happy member who bricked his Herald . I didn't unlock the thing before the flash and that is where it went wrong i think... not having an original rom, i'm stuck with a nice colorfull bootloader screen...
Now, for the good news, i have a friend, with an Herald from the exact same provider, bought 1 week later as i did... now my question:
How do i get his rom on my pda?
(if i manage to get the rom, i'll be happy to post it up here (Dutch vodafone WM5 )
Cheers
Daanoz
Daanoz said:
Hey guys,
I'm another happy member who bricked his Herald . I didn't unlock the thing before the flash and that is where it went wrong i think... not having an original rom, i'm stuck with a nice colorfull bootloader screen...
Now, for the good news, i have a friend, with an Herald from the exact same provider, bought 1 week later as i did... now my question:
How do i get his rom on my pda?
(if i manage to get the rom, i'll be happy to post it up here (Dutch vodafone WM5 )
Cheers
Daanoz
Click to expand...
Click to collapse
No chance.
You cannot flash a dump to a bricked device. You need the original RUU.
Because you cannot signe the dump os.nb to a .nbh and therefore the dump is useless.
Sorry. But check the wiki if there is an RUU for you. Normally there should be all you need!!
what about Sprite Clone?
It's an imaging tool that works like Ghost or Acronis True Image, but is designed for mobile phones. It says you can take an image of a device and dump it to another device, just like you would with a desktop PC.
If it works, then it would be the best way I can think of do a complete backup and restore of your phone (or phone to phone) provided it doesn't require an agent on the phone, or some other OS-level operation to work (meaning the phone would have to already be working).
Down side, though, is that they appear to only sell it for a minimum of 20 devices at 300 dollars a pop....
@papamopps : tried them all....
@psyop1 : damn that app sounds nice, couldn't get it form my "sources" though, so requested a trail version... lets see where it gets me
Cloning tool
Daanoz said:
@papamopps : tried them all....
@psyop1 : damn that app sounds nice, couldn't get it form my "sources" though, so requested a trail version... lets see where it gets me
Click to expand...
Click to collapse
Dannoz: I'd be interested in hearing how it works, because it may be the solution to many problems with phone dumps/backups!

[Tutorial] Why my IMEI missing & NO network?

Your IMEI (International Mobile Equipment Identity) is transmitted to the Network provider the moment you switch ON your phone
It is used by your Network to identify the following
1) The first two numbers is RBI (Reporting Body Identifier) = who registered that type of phone ( verify here )
2) The next four numbers is TAC (Type Allocation Code) = what type of unit and its complete specifications
3)The next two numbers is FAC (Final Assembly Code) = who manufacture it
example :-
01 AEG
04 Samsung
07 Motorola
10 Nokia
30 Ericsson
41 Siemens
50 Bosch
51 Sony
4) The next six numbers is the Serial Number of the Phone
5) The last number is sort of a check sum, that verifies the previous numbers
Combined a total of 15 numbers is used by your network to get the complete information about your phone that is used against their database of Blacklisted phones and final approval to connect to their network, IF they were inaccurate or had complaints (like being stolen, not paid telecoms dues etc) it will be rejected and BLOCKED immediately from connecting to that Network
You can verify all this by entering you IMEI here and here
And also here to check if it is blacklisted
Your IMEI is also needed for networks to BLOCK your phone when needed as well as ANTI theft apps.
Hence if your IMEI changes or gets lost, it may fail to connect to the network, depending on the restrictions of that network provider.
It is clear that Flashing custom ROMS can cause your IMEI to Change or get deleted as they may be ported from another manufacturer or from another version of the same manufacturer as the IMEI embedded in the chip of your phone.
IF you want to AVOID this problem, safe you EFS folder the moment you think of Flashing any ROM that is NOT the original Firmware for that phone
It is noted that to resolve this problem you have to return to its original firmware to recover your embedded IMEI and do a progressive upgrade . eg. from GingerBread to ICS before going on to Jelly Bean
For ways to resolve IMEI problems visit EFS Problems and Solutions or My Android Solutions
Check this out!You , YES! you are an " Android ". Not your phone but U.
You Must watch this documentary concerning your privacy Terms & Conditions we had agreed to, by using a PC or Smartphone
How to say Thank you? *If you find any post helpful on XDA, please click on the Thanks button
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
If you are using XDA App or Tapatalk, long press on the post and select :good: Thanks Its easier to give "Feedback" in this manner than make an additional post.​
This post is linked to Pit Stop
I will add that information on their own IMEI number check here http://www.imei.info/
similarly, you can also recover your IMEI using this method: http://forum.xda-developers.com/showthread.php?t=1264021
nice jobe OP!
Good job in explaining what it is!
Confused
TotallydubbedHD said:
Good job in explaining what it is!
Click to expand...
Click to collapse
You have the FAC 04 as Samsung which is correct but, HTC is also 04
mikaelel said:
I will add that information on their own IMEI number check here
Click to expand...
Click to collapse
I tested this site with my Nokia E71, and it's reporting my phone as Nokia 100
awaaas said:
I tested this site with my Nokia E71, and it's reporting my phone as Nokia 100
Click to expand...
Click to collapse
My Galaxy S3 appears as a Huawei U7510 on http://www.imei.info/, but http://imei-number.com/imei-number-lookup/ shows the correct information...
Taysider said:
You have the FAC 04 as Samsung which is correct but, HTC is also 04
Click to expand...
Click to collapse
I believe this is also possible as some of the manufacturers are using more than one FAC (Final Assembly Code) and some do have the same FAC....end of the day only the manufacturer would have chosen what they wish to use, on the other hand the checksum of the 15 numbers in total, should give the correct model and specs to the network .
saywhatt said:
similarly, you can also recover your IMEI using this method: http://forum.xda-developers.com/showthread.php?t=1264021
nice jobe OP!
Click to expand...
Click to collapse
My P500 LG Optimus is showing as KP500 LG Cookie.
[email protected] said:
My P500 LG Optimus is showing as KP500 LG Cookie.
Click to expand...
Click to collapse
lol :laugh:, which url did you use?, the one post by mikaelel
http://www.imei.info/, seems to giving some wrong info.
xsenman said:
lol :laugh:, which url did you use?, the one post by mikaelel
http://www.imei.info/, seems to giving some wrong info.
Click to expand...
Click to collapse
Funny lol
Sent from my LG-P970 using xda app-developers app
Apparently I have a Samsung Xperia Play.
It is noted that to resolve this problem you have to return to its original firmware to recover your embedded IMEI and do a progressive upgrade . eg. from GingerBread to ICS before going on to Jelly Bean
Click to expand...
Click to collapse
I had this very problem tonight. Flashed back to stock to try and fix a camera problem, then just installed cm10 to fix the partitions and applied my JB backup.
That's when I hit the imei problem. When I copied the efs folder across and rebooted it didn't fix it, came up some error. Then I manually copied the imei folder across, and then manually copy/replaced the loose files from my efs backup across into efs, leaving the extra files that were there from the install.
Meaning instead of completely replacing the efs folder with my backed up one, just adding all the files from the backup folder into the installed efs folder, replace any with identical names though.
Rebooted and it worked fine saving me having to go back to GB and progressively work my way back up. Nice..
Sent from my GT-I9000 using Tapatalk 2
knuckles1978 said:
Rebooted and it worked fine saving me having to go back to GB and progressively work my way back up. Nice..
Click to expand...
Click to collapse
All solutions for IMEI recovery are detailed here http://forum.xda-developers.com/showpost.php?p=26827676&postcount=4512"
Sorry I'm new please try and bear with me..
Are you saying I should write it up nice and post it in there??
Sent from my GT-I9000 using Tapatalk 2
knuckles1978 said:
Sorry I'm new please try and bear with me..
Are you saying I should write it up nice and post it in there??
Click to expand...
Click to collapse
Nope...what you did has already been written and advised as a way, to resolve IMEI recovery by me in June 2012 and other methods were recently deleted by MODs as they can sort of edit the IMEI (which is illegal to do) ..so, no problem, you have done it in one way ( because you had a backup) and there are other ways too...all compiled on that link as well as My Android Solutions, link below
Just had a proper read through that thread. Thanks
I thought that the way I did it was a little different because it didn't work when I tried replacing the installed efs folder with my backed up one, maybe not though.
Sent from my GT-I9000 using Tapatalk 2
Note!
http://www.imei.info/ -I found the address in Chinese Wikipedia -
http://zh.m.wikipedia.org/wiki/IMEI -but I confirm that falsifies information.
nice info, I should try to look on those given threads about retrieving imei because I got one who's got unknown imei due to a noob upgrade without even backing up efs folder
Sent from my year one phone using Tapatalk
xsenman said:
Your IMEI (International Mobile Equipment Identity) is transmitted to the Network provider the moment you switch ON your phone
It is used by your Network to identify the following
1) The first two numbers is RBI (Reporting Body Identifier) = who registered that type of phone ( verify here )
2) The next four numbers is TAC (Type Allocation Code) = what type of unit and its complete specifications
3)The next two numbers is FAC (Final Assembly Code) = who manufacture it
example :-
01 AEG
04 Samsung
07 Motorola
10 Nokia
30 Ericsson
41 Siemens
50 Bosch
51 Sony
4) The next six numbers is the Serial Number of the Phone
5) The last number is sort of a check sum, that verifies the previous numbers
Combined a total of 15 numbers is used by your network to get the complete information about your phone that is used against their database of Blacklisted phones and final approval to connect to their network, IF they were inaccurate or had complaints (like being stolen, not paid telecoms dues etc) it will be rejected and BLOCKED immediately from connecting to that Network
You can verify all this by entering you IMEI here and here
And also here to check if it is blacklisted
Your IMEI is also needed for networks to BLOCK your phone when needed as well as ANTI theft apps.
Hence if your IMEI changes or gets lost, it may fail to connect to the network, depending on the restrictions of that network provider.
It is clear that Flashing custom ROMS can cause your IMEI to Change or get deleted as they may be ported from another manufacturer or from another version of the same manufacturer as the IMEI embedded in the chip of your phone.
IF you want to AVOID this problem, safe you EFS folder the moment you think of Flashing any ROM that is NOT the original Firmware for that phone
It is noted that to resolve this problem you have to return to its original firmware to recover your embedded IMEI and do a progressive upgrade . eg. from GingerBread to ICS before going on to Jelly Bean
For ways to resolve IMEI problems visit EFS Problems and Solutions or My Android Solutions
This post is linked to Pit Stop
Click to expand...
Click to collapse
I have updated my Galaxy NOte N7000 with Some Custom ROMS , after that it changed my IMEI number ..
I cant use this mobile in INDIA i cant make and receive calls and TEXT but Internet data is working fine
. Please let know how can i change my IMEI number
I have Not taken any backup of EFS folder can i use other galaxy note files
Thanks

Enabling HSPA+ on 1700 AWS on non T-Mobile Variants

Hi All, I was reviewing this chart from this thread:
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
and I noticed that the following variants all share the same hardware:
AT&T
T-Mobile
Telus
Bell
Rogers
Virgin
Developer
How come only the T-Mobile variant has access to the HSPA 1700 AWS Band? I've been perusing some of the threads all around XDA, and I was wondering if we could apply similar methods to the HTC One to obtain this hidden band.
[GUIDE] Enable AWS on Samsung Galaxy IV AT&T i337 & Canadian i337M
[Bounty Completed] Enable 3G on TMobile AWS 1700MHz for ATT Galaxy S3 i747
Enable AWS band (3g/4g Tmobile) on ATT Note 2 stock baseband
or what if we had S-Off for the HTC One?
[S-OFF] revone - DEVELOPER EARLY ACCESS PREVIEW EDITION
Could we try changing the CID (SuperCID) first and then try flashing a complete T-Mobile Rom/Radio/Modem onto one of the other Carrier Variants?
Just curious if anyone has given this shot.
MegaMan X said:
Could we try changing the CID (SuperCID) first and then try flashing a complete Flash T-Mobile USA Radio In Recovery onto one of the other Carrier Variants?
Click to expand...
Click to collapse
There are already a few threads, but I don't think any progress so far. I'm interested in this as well, but we'd need the TMO RUU first...
As mentioned, there are a few other threads on this but no progress has been made yet.
The Samsung process requires enabling the DIAG mode (which only works on Sprint model) to enable RNDIS connectivity -- otherwise the Qualcomm software won't work.
WorldIRC said:
As mentioned, there are a few other threads on this but no progress has been made yet.
The Samsung process requires enabling the DIAG mode (which only works on Sprint model) to enable RNDIS connectivity -- otherwise the Qualcomm software won't work.
Click to expand...
Click to collapse
hey nice to see you here ,always saw you on hofo
Since S-OFF is out, its possible to enable qdxc (cant remember the exact) via fastboot,
I have hope now
I'm checking the threads several times a day just so someone can find the fix. I have an att One but I'm with tmobile network so I desperately need this to work.
Sent from my Nexus 4
ytwytw said:
hey nice to see you here ,always saw you on hofo
Since S-OFF is out, its possible to enable qdxc (cant remember the exact) via fastboot,
I have hope now
Click to expand...
Click to collapse
Find out!!
Sent from my HTC One
I hope this works soon as I need that aws band like everybody else on T-mobile with a non htc one branded phone.
So is it a myth when people say these bands are hardware based and for att only ?
Sent from my HTC One XL using xda app-developers app
ceo4eva said:
So is it a myth when people say these bands are hardware based and for att only ?
Sent from my HTC One XL using xda app-developers app
Click to expand...
Click to collapse
There have been some HTC reps who said the TMO version had different hardware. But it was never confirmed (and doesn't really make any sense).
stevedebi said:
There have been some HTC reps who said the TMO version had different hardware. But it was never confirmed (and doesn't really make any sense).
Click to expand...
Click to collapse
I think that is true otherwise the Google edition would have been pentaband hspa+ correct? Basically the Google edition, att version, HTC Dev edition are same hardware and T-Mobile different. Not sure why HTC does that, makes sense to disable bands thru software like Samsung does.
Sent from my HTC One using Tapatalk 2
has anyone tried to do the following on a a stock recovery & rom?
1.) Unlock Bootloader & Root
http://forum.xda-developers.com/showthread.php?t=2260376
2.) S-Off
http://forum.xda-developers.com/showthread.php?t=2314582
3.) Change CID to SuperCID (11111111)
http://forum.xda-developers.com/showthread.php?t=2315319
4.) Change ro.cid to match CID
http://forum.xda-developers.com/showpost.php?p=42351491&postcount=35
5.) change efuse to 4NSL. Check efuse using terminal command getprop ro.boot.efuse_info
http://forum.xda-developers.com/showpost.php?p=31340199&postcount=1912
6.) Flash T-Mobile RUU / T-Mobile Nandroid / T-Mobile Radio/Modem
http://forum.xda-developers.com/showthread.php?t=2207874
http://forum.xda-developers.com/showthread.php?p=40745177
MegaMan X said:
has anyone tried to do the following on a a stock recovery & rom?
1.) Unlock Bootloader & Root
http://forum.xda-developers.com/showthread.php?t=2260376
2.) S-Off
http://forum.xda-developers.com/showthread.php?t=2314582
3.) Change CID to SuperCID (11111111)
http://forum.xda-developers.com/showthread.php?t=2315319
4.) Change ro.cid to match CID
http://forum.xda-developers.com/showpost.php?p=42351491&postcount=35
5.) change efuse to 4NSL. Check efuse using terminal command getprop ro.boot.efuse_info
http://forum.xda-developers.com/showpost.php?p=31340199&postcount=1912
6.) Flash T-Mobile RUU / T-Mobile Nandroid / T-Mobile Radio/Modem
http://forum.xda-developers.com/showthread.php?t=2207874
http://forum.xda-developers.com/showthread.php?p=40745177
Click to expand...
Click to collapse
As of yet, no T-mobile RUU has been released and a Nandroid would likely not contain the radio partition. We need someone to dump their entire eMMC partition table and then clone it onto a dev edition (AT&T phone) to start to make any progress.
sassafras
I'm interested in this as well and I, too, have been tracking a few other posts. I believe I've seen people documenting the T-Mobile US model as PN0713000 (ro.aa.modelid), whereas the US Developer Edition and the AT&T edition have a modelid of PN0712000. I have no idea whether this indicates different hardware or if it's just an indicator that's used elsewhere in the code. Exactly what's used to determine whether to enable the additional T-Mobile frequencies, is still TBD but a good start would be to set correct modelid and CID on a T-Mobile ROM, preferably an RUU. A failure on anything short of that is not, in my opinion, definitive. That's not to say experiments on other than a T-Mobile RUU are worthless -- we may stumble on the correct settings. At a minimum, though, I'd try setting all of
- a T-Mobile US model id
- a T-Mobile US CID
- maybe even using a stock T-Mobile build.prop
short/y said:
I'm interested in this as well and I, too, have been tracking a few other posts. I believe I've seen people documenting the T-Mobile US model as PN0713000 (ro.aa.modelid), whereas the US Developer Edition and the AT&T edition have a modelid of PN0712000. I have no idea whether this indicates different hardware or if it's just an indicator that's used elsewhere in the code. Exactly what's used to determine whether to enable the additional T-Mobile frequencies, is still TBD but a good start would be to set correct modelid and CID on a T-Mobile ROM, preferably an RUU. A failure on anything short of that is not, in my opinion, definitive. That's not to say experiments on other than a T-Mobile RUU are worthless -- we may stumble on the correct settings. At a minimum, though, I'd try setting all of
- a T-Mobile US model id
- a T-Mobile US CID
- maybe even using a stock T-Mobile build.prop
Click to expand...
Click to collapse
That was the first thing I tried after S-Off. Flashed radio via bootloader, changed CID and all IDs. No dice.
PcFish said:
That was the first thing I tried after S-Off. Flashed radio via bootloader, changed CID and all IDs. No dice.
Click to expand...
Click to collapse
Did you happen to use a stock T-Mobile ROM?
short/y said:
Did you happen to use a stock T-Mobile ROM?
Click to expand...
Click to collapse
Yeah, stock, odexed and relocked my bootloader. Everything I could possibly do to make it T-Mo without an RUU.
PcFish said:
Yeah, stock, odexed and relocked my bootloader. Everything I could possibly do to make it T-Mo without an RUU.
Click to expand...
Click to collapse
Dang! OK, thanks. It's not looking good but there still may be something we're not seeing.
Again, we haven't really made any definitive answers because we don't have a T-Mo RUU or an eMMC dump from a t-mo device. The radio partition itself may not be all that is required.
There are other partitions which seem to suggest they play a role in setting up the radio characteristics.
sassafras
Tell me how!
I have both the T-Mobile version and the Dev version. Tell me how to do those dumps and I'll do it.
sassafras_ said:
Again, we haven't really made any definitive answers because we don't have a T-Mo RUU or an eMMC dump from a t-mo device. The radio partition itself may not be all that is required.
There are other partitions which seem to suggest they play a role in setting up the radio characteristics.
sassafras
Click to expand...
Click to collapse
ohiosux said:
I have both the T-Mobile version and the Dev version. Tell me how to do those dumps and I'll do it.
Click to expand...
Click to collapse
The basic method is to use the "dd" command from adb shell or a terminal emulator session. To grab the radio you do
Code:
dd if=/dev/block/mmcblk0p31 of=/sdcard/radio.img
p31 is the partition where the radio's stored. "if=" is the input file or, in this case, the partition. "of=" is where the output is written. Once you get the list of partitions, you can just loop through them on both devices.

Rollback to all devices that upgraded to 4.x

HELLO ALL,
The OTA 4.1.1 & later 4.5.1 was pushed to Apollo & Saturn (NEW GEN HDX 8.9") Devices adding firefly functionality along with other functionality (WHICH ARE CRAP ACCORDING TO ME)
So in order to get the device back to JB ie.. 3.X version Contact amazon customer services and Say that the Kindle is not working properly after the updates & roll back to the 3.x version.
have the device fullly charged 80% or more and they will initiate a Rollback.
Remember the device will never Get any OTA after this !!
Also it would be a lot lot helpful if some one can locate the ota file downloaded (via ES file explorer) so that we can copy it & share on XDA & help other fellow men.
Also I'd request you to contact Amazon via Phone for Source Code & bootloader info & get the call escalated to higher officials so that there are possibilities of getting info.
I'd request all the devs & members to file a petition (Change.org) with regards to the bootloader and simultaneously work on development
All active members & Ashamed owners of HDX's (Ashamed because with marvellous hardware we have a Crappy OS) include or add devs in this sections via PM or replies so that they can look over this & find a solution soon.
Also I'm thinking that a manual roll back can be done but it needs testing & i need some help in that as well
I believe all the magic is with build.prop & ota.prop that checks the versions.
Interested members can carry on the work here and update the results as well
In the mean time any suggestions are also appreciated
Anyone who will do the rollback, please root device and place file /cache/recovery/last.log (something like that) here.
Thank you.
ONYXis said:
Anyone who will do the rollback, please root device and place file /cache/recovery/last.log (something like that) here.
Thank you.
Click to expand...
Click to collapse
What will that have?
Give as much as info possible please.
Another observation : As manual update via bin file can be done on Kindle, I opened the file via WinRar & was able to see contesnts as a Zip File so why cant we add su and required root files then update kindle ???
As far as the bin file check is concerned..build.prop edit will work
This give to us name and location of rollback file and some other information about upgrade (downgrade) process.
It is necessary to start somewhere...
About your observation - we can''t flash modified bin in any way.
Btw during upgrade latest firmwares check not only build.prop but keys that located in system recovery. So modifying build.prop is not enough.
Well thanks a lot for the info mate I didn't knew that!!
Just for curiosity how will that file lead. Just need more info about it... I might get that file to you and will that file be even after s factory reset is performed?
ONYXis said:
This give to us name and location of rollback file and some other information about upgrade (downgrade) process.
It is necessary to start somewhere...
About your observation - we can''t flash modified bin in any way.
Btw during upgrade latest firmwares check not only build.prop but keys that located in system recovery. So modifying build.prop is not enough.
Click to expand...
Click to collapse
Do you have a HDX?
Which one n will there be any problem if I get thor's file? Does it need to be specific?
Can get the file n other stuff within 2 days to you..
Let me also know about keys n. Bin stuff... Atleast point me to some info thread I'll read...
btw a rollback editing bin file worked! I tried to do the same but on 4.5 os now
Any one on 4.3 can try opening 4.5.bin file adding root and then updating...may b can try atleast!?
rollback file is "mod-update-kindle-thor-13.3.2.6_user_713326020.bin"
it is all I know at this moment.
And "NO" again, every editing of original bin corrupts CRC, and file do not pass checking. Do not waste the time. Do you think that no one tried for a year to do it?
Sorry if this is a dumb question but has anyone tried calling the support and asking them to rollback and had success? I just want to make sure that they will do it before I try it
Yes. Guy from my russian forum successfully rolled back after contacting support. So it possible. And he sent me logs of this downgrade in which I saw name of rollback-file - mod-update-kindle-thor-13.3.2.6_user_713326020.bin
Got the Kindle on 14.3.2.7_user_372002520
Unable to root it ! ADB doesn't recognizes device anymore....
I was curious on .bin mod. (Yes i can imagine people trying to edit .bin but i needed an explanation thats it.....)
Now let me know what next !!! ??
How do i proceed ??
maxster95 said:
Sorry if this is a dumb question but has anyone tried calling the support and asking them to rollback and had success? I just want to make sure that they will do it before I try it
Click to expand...
Click to collapse
Tell me if they deny !!!!
They will surely !!! No questions asked !
HELP.
Can anyone explain me how to downgrade? I got the update-kindle-13.4.1.1_user_411010320.bin and update-kindle-13.3.2.5_user_325001120.bin. But when I try to flash the rom the mentioned way it sais that it isn't possible because there is a newer rom installed. how can I circumvent this problem? Any ideas?
You need to contact Customer Support.
At this moment only they can initiate downgrade.
BTW be careful. Maybe now downgradable version is 13.3.2.7 and its not rootable. But I'm not sure.
ONYXis said:
You need to contact Customer Support.
At this moment only they can initiate downgrade.
BTW be careful. Maybe now downgradable version is 13.3.2.7 and its not rootable. But I'm not sure.
Click to expand...
Click to collapse
Rooting works !
yesss I did it!
I did it ! ish :/
With good acting i made up some drama and called support and had them roll me back to OS 4.1.1 B] like a boss
now what shoud i do or edit ...am not familiar with the Bin file language or the kindle fire :/
standard AOSP
BenDroid1 said:
I did it ! ish :/
With good acting i made up some drama and called support and had them roll me back to OS 4.1.1 B] like a boss
now what shoud i do or edit ...am not familiar with the Bin file language or the kindle fire :/
standard AOSP
Click to expand...
Click to collapse
What are you looking for exactly?
There's really nothing you can do with 4.1.1 — rooting, custom ROMs, etc. require you be on 14/13.3.2.6 or lower.
AmazonLeaker said:
.
Remember the device will never Get any OTA after this !!
Click to expand...
Click to collapse
Okay, why is that? Is there more information on that? I also read a response from the Amazon support posted on another (German) board which warned about the same thing and that further updates might require help from customer support.... I just don't understand why you loose OTA capability? Even if it doesn't update automatically (which most people prefer a anyway, I guess), wouldn't you be able to just initiate an OTA by clicking on it in system preferences ?
Thanks!
Gave it a go, here is my experience:
I started a chat and asked to roll back to 14/13.3.2.6, the person was happy to help and did not dig into they wy. The steps they had me follow:
- factory reset
- re-register device (was still on 4.5.1 as would be expected)
- they pushed something, I saw a system update in the notify tray but it was only there for a brief moment
- They then had me check for updates
- I told them it did not find anything
- I took a look at my kindle storage and there were 6 nameless files that showed up. When I looked at their properties there was no name or file type on them. I tried to copy them off the device but it would not let me, got a generic access message about not being able to copy the files.
- I was then told that 4.5.1 can not be rolled back and that I should return the tablet for a refund (they did say 4.1.1 can be rolled back). I think this was to be expected based on the "kill switch" code that was found in the new update. I can't find the post/link to the conversation now but I think it was code found in the kernel. Not sure Kill switch is the right term either.
- They are providing me a free shipping label
- Will likely get a 2013 Nexus 7
I'm sorry I'm new to how these forums work and replies and all that. Is there a way to downgrade from 4.5.1 to be able to root? It would be really helpful if someone could give me a straight answer as to if it can be done or not. Thanks!

[Q&A] LG Spirit H440n general thread

Q&A for LG Spirit H440n general thread
Some developers prefer that questions remain separate from their main development thread to help keep things organized. Placing your question within this thread will increase its chances of being answered by a member of the community or by the developer.
Before posting, please use the forum search and read through the discussion thread for LG Spirit H440n general thread. If you can't find an answer, post it here, being sure to give as much information as possible (firmware version, steps to reproduce, logcat if available) so that you can get help.
Thanks for understanding and for helping to keep XDA neat and tidy!
Hello, i hope you can help me. I have the LgH420 Spirit 3g. I need the kdz stock rom file. I can`t find anything on Google etc.
Only on chinese websites, but without download link. I need the stock rom to flash it.
The lg support tool tells me that i have the latest firmware installed. Factory reset doesn`t work for me, i have still no wifi or other network connection. I`am from germany, sorry for my bad english. But you are my last hope. I can`t understand that the support of our devices is so bad.
---------- Post added at 11:29 AM ---------- Previous post was at 11:18 AM ----------
Hello, i hope you can help me. I have the LgH420 Spirit 3g. I need the kdz stock rom file. I can`t find anything on Google etc.
Only on chinese websites, but without download link. I need the stock rom to flash it.
The lg support tool tells me that i have the latest firmware installed. Factory reset doesn`t work for me, i have still no wifi or other network connection. I`am from germany, sorry for my bad english. But you are my last hope. I can`t understand that the support of our devices is so bad.
toller Typ said:
[/COLOR]Hello, i hope you can help me. I have the LgH420 Spirit 3g. I need the kdz stock rom file. I can`t find anything on Google etc.
Only on chinese websites, but without download link. I need the stock rom to flash it.
The lg support tool tells me that i have the latest firmware installed. Factory reset doesn`t work for me, i have still no wifi or other network connection. I`am from germany, sorry for my bad english. But you are my last hope. I can`t understand that the support of our devices is so bad.
Click to expand...
Click to collapse
Hello. I think we don't have a kdz file other than the T-Mobile Croatia for H440n. I tried to navigate the chinese site many times, but in vain. I think the only thing to do now is wait, until you 're willing to flash the H440n system.img, something that is kind of risky for now.
Please update us with your progress!
polfrank said:
Hello. I think we don't have a kdz file other than the T-Mobile Croatia for H440n. I tried to navigate the chinese site many times, but in vain. I think the only thing to do now is wait, until you 're willing to flash the H440n system.img, something that is kind of risky for now.
Please update us with your progress!
Click to expand...
Click to collapse
Hello Friend, thank you so far. If i get new information i`ll let you know. Good luck and i hope we will supported very soon from LG. Have a nice evening.
There is a 2 new firmware updates,I'll try it and tell you if something is changed.
---------- Post added at 02:33 PM ---------- Previous post was at 02:25 PM ----------
H440n10b_00.kdz and H440n10e_00.kdz
---------- Post added at 02:39 PM ---------- Previous post was at 02:33 PM ----------
The first one is Poland Plus Edition and the second one is Hungary.
i posted a new firmwares in genereal thread
New firmwares can't be rooted with one click root.Maybe somebody rooted already?
pavaczek said:
i posted a new firmwares in genereal thread
Click to expand...
Click to collapse
Hi friend, i am still searching for the lg-h420 firmware. I am still searching. I can't understand that lg does'nt have this firmware on their servers. I hope i will get it soon. I keep on searching.
Is it only me or does this phone has a bad GPS?
I hardly get a fix and it only lasts for a few seconds, not accurate at all.
Does it work definitly on Spirit H440n?
---------- Post added at 04:41 PM ---------- Previous post was at 04:36 PM ----------
deni-brasco said:
New firmwares can't be rooted with one click root.Maybe somebody rooted already?
Click to expand...
Click to collapse
Yes I rooted succesfully using oneclickroot
Randar EST said:
Yes I rooted succesfully using oneclickroot
Click to expand...
Click to collapse
You mean version 10e? Did you do something special? Because I can't get root on 10e.
Edit: Nevermind, I managed to root with KingRoot.
It is locked or unlocked?
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
Wysłane z mojego LG-H440n
temintyd said:
Is it only me or does this phone has a bad GPS?
I hardly get a fix and it only lasts for a few seconds, not accurate at all.
Click to expand...
Click to collapse
I had two h440n units. First one returned after 12 days. GPS progressively became worse and worse. Hardly got a fix which is strange because Snapdragon 410 has a very good GPS core.
2nd unit seemed to be working fine for one day. GPS started to degrade on the second day and I returned it because I had a 14 days evaluation period.
Now I have a Vodafone Smart 6 Prime, same Snapdragon 410, also HD display 1GB RAM and 8GB ROM and a much, much better GPS. Most of the times the fix is achieved in under 3-4 seconds.
I believe the H440n as some serious problems regarding GPS. Perhaps a buggy firmware with bad gps configuration allied to a bad antenna perhaps...
toller Typ said:
Hi friend, i am still searching for the lg-h420 firmware. I am still searching. I can't understand that lg does'nt have this firmware on their servers. I hope i will get it soon. I keep on searching.
Click to expand...
Click to collapse
Here you go...
http://csmgdl.lgmobile.com/dn/downloader.dev?fileKey=FWD1CA503257A60030DBDBE/H42010D_00.kdz
Hi can anyone help me i tried alomst every thing to root this phone, i know pretty much about android i had a s4 i9505 and i had cyamogenmod modified for myself but I just can't root this phone and if its rooted do anyone knows if xposed framework works without bootloader being unlocked and did someone tried geefree app?
Thanks for reading this all and put your time it this so here is a cookie
Hello from Spain companions, I have a problem with my lg H440n spirit.
It is that I've inserted a 32gb sd
real racing 3 and install additional game data is not in the external sd installan and go without any space in the internal memory.
I would like if anyone knows how to remove that restriction to be installed on the external sd I would greatly appreciate it
thank you very much
jpg350 said:
Hello from Spain companions, I have a problem with my lg H440n spirit.
It is that I've inserted a 32gb sd
real racing 3 and install additional game data is not in the external sd installan and go without any space in the internal memory.
I would like if anyone knows how to remove that restriction to be installed on the external sd I would greatly appreciate it
thank you very much
Click to expand...
Click to collapse
Use es explorer and try to copy something to ur sd then es file explorer asks you to get sd card permissions and you'll find it
Mikxx said:
Use es explorer and try to copy something to ur sd then es file explorer asks you to get sd card permissions and you'll find it
Click to expand...
Click to collapse
could you explain a little better how to do it please
jpg350 said:
could you explain a little better how to do it please
Click to expand...
Click to collapse
first u go to google play then search es file explorer download it and open(es file explorer explains how to use) then go to internal sd and longpress something no mather what a picture for example then choose move or copy to sd and then es file explorer says lollypop has restrictions and he asks to do something then it opens a build in recents app (the same thing that opens with alot of apps when you add a pictute there open menu and in the menu tick show sd card then choose sdcard and btw where on ur sdcard stands the gamedata? Hit like if i helped u
Mikxx said:
first u go to google play then search es file explorer download it and open(es file explorer explains how to use) then go to internal sd and longpress something no mather what a picture for example then choose move or copy to sd and then es file explorer says lollypop has restrictions and he asks to do something then it opens a build in recents app (the same thing that opens with alot of apps when you add a pictute there open menu and in the menu tick show sd card then choose sdcard and btw where on ur sdcard stands the gamedata? Hit like if i helped u
Click to expand...
Click to collapse
no and gotten it to work me in that way the game is the brodthers in arms 3 Aug what you say but when I start the game not abut data and tells me I have to re-download not act now to remove this restriction from external sd .
copy the folder that is on the route:
/ android / obb ...... and / android / data .....
if you could do me a tutorial to make it work you would appreciate

Categories

Resources