Please, I need prog_emmc_firehose_8996.mbn (.elf) for QFIL [I offer donation] - Hardware Hacking General

Hello, thank you very much for reading, I hope you can help me. I need one or more files to be able to recover my phone: Samsung Galaxy S7 Active.
These are the files that I need:
prog_emmc_firehose_8996.mbn (.elf)
rawprogram0.xml
patch0.xml
I do not know if I would also need these:
MPRG8996.hex
rawprogram_unsparse.xml
I think these files are the same as prog_emmc_firehose_8996.mbn (.elf):
8996_msimage.mbn
MSM8996.mbn
How did I make a brick my phone? Installing the first official version:
SM-G891A_G891AUCU1APG7_ATT_Full_Repair_Frimware
Previously I used this version without any problem:
G891AUCS2API2_CL8737252_QB10881022_REV02_user_low_ship_MULTI_CERT

I wish someone could help me, I have read more than 50 pages, but I have not been able to solve the problem.

Please.

Can anybody help me?

hey.... i'm on the same situation..
i need zuk Z2 pro/ prog_ufs_firehose_8996_ddr_zuk.mbn but i only have elf....
it's to remove this stupid frp lock from someone who forgot his first mail... :/
keep going we are going to find out the solution

yakine13 said:
hey.... i'm on the same situation..
i need zuk Z2 pro/ prog_ufs_firehose_8996_ddr_zuk.mbn but i only have elf....
it's to remove this stupid frp lock from someone who forgot his first mail... :/
keep going we are going to find out the solution
Click to expand...
Click to collapse
I hope someone helps us.

HEY!
I found a way!!!
...for me:/
why you want this emmc_firehose_8996.mbn?
actually, i think that you don't need that file especially, it doesn't exist from where i've searched.
if it's to flash your phone all you need is odin and a flashable file of your phone firmware
i had a zuk z2 pro and was locked with frp when i wanted to setup custom rom AOSP 9.0.0 for example.
but i managed to unlock it by flashing a custom rom without gapps in the first place to no get locked out.
tell me how your phone is reacting, what do you have access to, and your initial step before brick

yakine13 said:
hey.... i'm on the same situation..
i need zuk Z2 pro/ prog_ufs_firehose_8996_ddr_zuk.mbn but i only have elf....
it's to remove this stupid frp lock from someone who forgot his first mail... :/
keep going we are going to find out the solution
Click to expand...
Click to collapse
yakine13 said:
HEY!
I found a way!!!
...for me:/
why you want this emmc_firehose_8996.mbn?
actually, i think that you don't need that file especially, it doesn't exist from where i've searched.
if it's to flash your phone all you need is odin and a flashable file of your phone firmware
i had a zuk z2 pro and was locked with frp when i wanted to setup custom rom AOSP 9.0.0 for example.
but i managed to unlock it by flashing a custom rom without gapps in the first place to no get locked out.
tell me how your phone is reacting, what do you have access to, and your initial step before brick
Click to expand...
Click to collapse
Hello, sorry for my bad English. My phone is a Samsung Galaxy S7 Active (SM-G891A). I will try to explain what happened.
I had this version of Android 6 installed (via Odin) on the phone:
G891AUCS2API2_CL8737252_QB10881022_REV02_user_low_ship_MULTI_CERT
With that version my phone was fine, but then I tried to install the first version of Android 6 (official) via Odin:
SM-G891A_G891AUCU1APG7_ATT_Full_Repair_Frimware
When the installation was completed (Odin said the installation was successful), the phone never restarted. There is no way to turn it on with any combination of buttons, nor with a microSD with a debrick.img. A USB JIG has not worked for me either.
Windows detects my phone in Qualcomm 9008 mode. Odin does not detect it.

did you find a solution?
actually it look like to be a hard brick but as it's snapdragon 820 you can recover from it

I'm waiting for the day when noobs and half-noobs (no offense, all of us have been there) will start reading before writing and stop assuming that their 1st aid kit will revive a kitten ran over by a train.
It's okay not to know, but before writing a spam reply, just consider for a second that the user already tried your solution and is already a step ahead.
Listen guy, go to Halab Tech. They have certain firmwares for what you need, but they ask money.
Those type of firmwares have a prefix "DEBUG_EMERGENCY_DOWNLOAD_FA....'
In my case it's "DEBUG_EMERGENCY_DOWNLOAD_FA70_G955U1SQU6ASG1_CL12542406_QB24669289_REV00_user_mid_noship_MULTI_CERT.tgz"
As I consider that a bastard move (since they are selling Samsung's intellectual property as their own, stuff that should be public in the first place), I encourage you to share the files if you buy them, so that we can all use them and screw over these monopoly playing-intellectual property stealing bastards.
I'm now working on a recovery of my G955U1 (S8+ Qualcomm USA). I paid $25 for a god damn firmware and I'm gonna post it in next couple of days.
I'm personally having trouble of flashing the firmware (because not many flash tools support flashing .elf flash loaders), but I used one FRP tool (Octoplus FRP tool) to check the loader and it managed to send it, receive the "hello" packet, read partitions and erase the FRP partition (I assume it worked by the log), but I don't have a way to flash other partitions yet.
You people should have in mind one thing: even though certain devices have the same chipset, doesn't mean that you can use the same firehose flash loader, since manufacturers create different loaders for them and write their digital signatures into the chip (don't know is it hardwired or flashed), meaning that you cannot use Xiaomi's prog_ufs_firehose_8998_ddr.elf (just an example) to flash a Samsung device with MSM8992 chipset.
In fact, I think that each phone model and possibly even it's different firmware revisions have unique loaders, since I didn't manage to get a successful response from my G955U1 by sending G955U2 loader, and the loader which I managed to send is actually stated to be for G955U1U6 (U6 is the bootloader revision number, while U1 is the part of the model number).
Best of luck, contact me if you need help.

Related

Bootloader

Hi all,
Thinking about this phone, what is bootloader like, unlockable? Can fastboot be accessed?
Looked all over for info, most Chinese forums are bashing the phone, but the reason is not clear to me (seems mostly joking that it is just a knock off of the Nexus they produced). Chinese is not my first language, that is probably most of the problem.
I am interested in getting some development going on here, but I need to know if it is worth the trouble even trying. Huawei does release source, but it is really not easy to find. Also, source for this phone seems to not be released yet. If you google "huawei open source" you get some sources, but not for this device. If anyone can point me in a better direction I would appreciate it.
I followed step 1 of this guide: http://forum.xda-developers.com/showthread.php?p=68280798 to get my bootloader unlock code.
I haven't been able to find a version of TWRP for this phone yet and KingoRoot hasn't been able to achieve root either ?
Sent from my HUAWEI MLA-L03 using Tapatalk
You might try this for root: http://www.huaweishuaji.com/112.html
Supports many other Huawei devices, but I cannot guarantee as I have never used it, so use at your own risk. There are also some Chinese guides for unbricking out there. It involves putting the stock image onto the external SD card and running a flash from the phone. Seems it would be fairly easy to build TWRP for the the device if there was a little more info about it, such as partitions. Unfortunately, I do not have the device and need to upgrade my PC before I can start building anything again.
Bored today, so been digging. Seems it would be fairly easy to port the zenfone 3 twrp over, as the specs are similar.
I can't try to build as I need to upgrade, and don't have the phone to test anyway.
Here is the git, looks like only a few changes to make: https://github.com/shakalaca/android_device_asus_ze520kl
Here is a link with how to flash the zenfone: http://www.asus-zenfone.com/2016/10/how-to-root-asus-zenfone-3-ze520kl-and.html
If it was me I would give it a go booting the z017d one, but make sure you "fastboot boot filename.img" and not flash. I would take the risk, but not saying anyone else should.
Not going to have anything to build with until around Christmas, so hopefully someone can give it a go building for the phone. I might get the phone around Christmas too, lets see how development goes.
can anyone try to load the twrp from p9 lite? The hardware specs are just as much the same
"fastboot boot recovery recovery_twrp.img"
maybe it works...
It's a no go booting either of those recoveries. Each flash while successful, ends in a boot loop.
I also don't have the time right now to dedicate to build TWRP from source.
Sent from my HUAWEI MLA-L03 using Tapatalk
thisizM1 said:
I followed step 1 of this guide: http://forum.xda-developers.com/showthread.php?p=68280798 to get my bootloader unlock code.
I haven't been able to find a version of TWRP for this phone yet and KingoRoot hasn't been able to achieve root either
Sent from my HUAWEI MLA-L03 using Tapatalk
Click to expand...
Click to collapse
Mine was bricked after trying the KingoRoot. Any chance I can unbrick it somehow?
P/S: Yes I am an idjit because I didn't make any kind of backup. :crying::crying:
Seems the Huawei unlock code generator is down. I entered my phones data, but the unlock code never appears. I only get an error message when I enter wrong data (i.e., CAN-L11 instead of HUAWEI CAN-L11), so seems the data is validated. When did you create your code, @wangdaning?
Regards,
sebastian
Don't have the phone, I think an earlier poster did get an unlock. I was speculating about what might be possible.
wangdaning said:
Don't have the phone, I think an earlier poster did get an unlock. I was speculating about what might be possible.
Click to expand...
Click to collapse
Sorry, my fault. thisisMZ1 was the lucky guy with the unlock code.
@thisisMZ1: did you try to boot the image without flashing it first? Don´t know if that makes a difference, but one never knows.
For the unlock code, I got an unhelpful reply from the support team ("please use the form provided on..."). My replies on this haven´t been answered yet, so I´m waiting... Will keep you updated.
Regards,
Sebastian
Hi again,
I managed to unlock the bootloader: I created the Huawei ID on the wron (Asian) website. I created a new ID via the German website and was able to use the website for unlocking code with the new ID.
Regards,
Sebastian
sebixvi said:
Sorry, my fault. thisisMZ1 was the lucky guy with the unlock code.
@thisisMZ1: did you try to boot the image without flashing it first? Don´t know if that makes a difference, but one never knows.
For the unlock code, I got an unhelpful reply from the support team ("please use the form provided on..."). My replies on this haven´t been answered yet, so I´m waiting... Will keep you updated.
Regards,
Sebastian
Click to expand...
Click to collapse
I tried both, booting and flashing, neither worked.
Sent from my Nexus 6P using Tapatalk
sebixvi said:
Hi again,
I managed to unlock the bootloader: I created the Huawei ID on the wron (Asian) website. I created a new ID via the German website and was able to use the website for unlocking code with the new ID.
Regards,
Sebastian
Click to expand...
Click to collapse
Hi,
could you leave us the links to the websites you used? Thank.
TWRP has been released in Chinese http://www.netded.com/a/jingpinshouji/2016/1108/32373.html
m00h said:
Hi,
could you leave us the links to the websites you used? Thank.
Click to expand...
Click to collapse
https://uniportal.huawei.com/accounts/register.do?method=toRegister&regsiterMethod=byPhone ist the page I used to create my ID.
Regards,
Sebastian
wangdaning said:
TWRP has been released in Chinese http://www.netded.com/a/jingpinshouji/2016/1108/32373.html
Click to expand...
Click to collapse
i installed this on my Nova Plus and then changed the language to english
works, however when trying to backup the files it says invalid argument. no matter what it tries to mount
soliditalstud said:
i installed this on my Nova Plus and then changed the language to english
works, however when trying to backup the files it says invalid argument. no matter what it tries to mount
Click to expand...
Click to collapse
Wonder if it is only for the nova and not the nova plus. I did not make it and have neither phone to test, just passing it along. Unfortunately, they seem to have not used github.
Does anyone have a link to the factory recovery.img?
I flashed the Recovery to the Nova (not the plus) and I got exactly the same error. If I try to flash the superSU, I got a error that it couldnt Mount data and after a Reboot the root doesnt work.
I guess their could be several variants of the phone, which does not bod well for hopes of development.
Something new?
The chinese recovery boots but has problems to mount the partitions.... Its for the CAN-L01 and on my CAN-L11 is a different fstab. I have not the skills to compile a working one.

Need IMG file for SM-950U

Can someone please connect their rooted S8 via adb and run the following commands:
adb shell
su
dd if=/dev/block/mmcblk0 of=/storage/sdcard1/unbrick.img bs=512 count=30535646
Make sure you have an empty 16+ GB sd card inserted into your phone.
unbrick.img should be in your SD card.
Please zip the file and share it with me so I can unbrick my S8.
Thank you so much!!
I will make a guide once the device is successfully unbricked.
thehaXor said:
Can someone please connect their rooted S8 via adb and run the following commands:
adb shell
su
dd if=/dev/block/mmcblk0 of=/storage/sdcard1/unbrick.img bs=512 count=30535646
Make sure you have an empty 16+ GB sd card inserted into your phone.
unbrick.img should be in your SD card.
Please zip the file and share it with me so I can unbrick my S8.
Thank you so much!!
I will make a guide once the device is successfully unbricked.
Click to expand...
Click to collapse
1) that comand is wrong. This would back up their entire ssd which would give you all their files. Don't do this.
2) there are plenty of root methods on this vs very site. If you could apply to kind of image your can use one of them
Partcyborg I had your rom installed on my s8, but I hardbricked it by running xposed. Now all I see is "qualcomm hs-usb qdloader 9008" when I plug in my s8 but the phone is unresponsive no download mode and no recovery. I read on another posting on
https://forum.xda-developers.com/yureka/help/question-qualcomm-download-mode-k-t3068040
That if someone provides me with a img I can use it to revive my phone.
Please help me.
thehaXor said:
Partcyborg I had your rom installed on my s8, but I hardbricked it by running xposed. Now all I see is "qualcomm hs-usb qdloader 9008" when I plug in my s8 but the phone is unresponsive no download mode and no recovery. I read on another posting on
https://forum.xda-developers.com/yureka/help/question-qualcomm-download-mode-k-t3068040
That if someone provides me with a img I can use it to revive my phone.
Please help me.
Click to expand...
Click to collapse
Hello
I can make you a backup of my device.
Yes true some of the files from my device could be bad for you to have.
Like the EFS partition that contains the IMEI number Serial number ect.
Im not too worried about that but if you have a dump of your efs partition that would be very helpful.
Now the thread you linked too is a way of unbricking some of the devices that arent so heavily secured.
Unless you have the Samsung Signed Firehose i dont think it will work.
Good news is that there is a way to make a debrick image that you burn to a sd card.
Then putting the sd card in the device gets it booted into download mode.
The bad news is I dont know exactly how to create the unbrick.img.
Currtently i am trying to do this for my Galaxy Tab E.
If someone knows how to make the debrick.img I have all the files needed.
Someone out here please help us make a debrick.img
This all seems really complicated its not really. U want that partition? Download es file explorer and follow me... Thumbnails below. Your device must be rooted.
BigCountry907 said:
Hello
I can make you a backup of my device.
Yes true some of the files from my device could be bad for you to have.
Like the EFS partition that contains the IMEI number Serial number ect.
Im not too worried about that but if you have a dump of your efs partition that would be very helpful.
Now the thread you linked too is a way of unbricking some of the devices that arent so heavily secured.
Unless you have the Samsung Signed Firehose i dont think it will work.
Good news is that there is a way to make a debrick image that you burn to a sd card.
Then putting the sd card in the device gets it booted into download mode.
The bad news is I dont know exactly how to create the unbrick.img.
Currtently i am trying to do this for my Galaxy Tab E.
If someone knows how to make the debrick.img I have all the files needed.
Someone out here please help us make a debrick.img
Click to expand...
Click to collapse
thehaXor said:
Partcyborg I had your rom installed on my s8, but I hardbricked it by running xposed. Now all I see is "qualcomm hs-usb qdloader 9008" when I plug in my s8 but the phone is unresponsive no download mode and no recovery. I read on another posting on
https://forum.xda-developers.com/yureka/help/question-qualcomm-download-mode-k-t3068040
That if someone provides me with a img I can use it to revive my phone.
Please help me.
Click to expand...
Click to collapse
There is no way you hardbricked running xposed. If you Google there is a recovery img that is out there for 9008 u2 bootloader
thehaXor said:
Partcyborg I had your rom installed on my s8, but I hardbricked it by running xposed. Now all I see is "qualcomm hs-usb qdloader 9008" when I plug in my s8 but the phone is unresponsive no download mode and no recovery. I read on another posting on
https://forum.xda-developers.com/yureka/help/question-qualcomm-download-mode-k-t3068040
That if someone provides me with a img I can use it to revive my phone.
Please help me.
Click to expand...
Click to collapse
Ok a few things:
1) this did not happen because of "Xposed". This is literally impossible. Xposed only modifies things in /system, this can not cause you to be stuck in 9008. Only bad modifications to bootloader files can do this, which again, Xposed doesn't touch.
2) you don't need someones system image, in fact system images aren't what you need all. You need to flash a working set of bootloaders using the firehose programmer. If you were on my rom then you're in luck, the v2 programmer is out there so doing this is possible.
All you need is a copy of the stock rom, and the firehose programmer with xmls. I think they were shared around here before, if not I can post them for you. Just make sure the stock bl files you upload are for 950u v2 ONLY, or you might not be able to root anymore, or it won't fix it
Depending on what rev bootloader you are on I have the EDL Files.
The official samsung edl files to unbrick your s8.
The sd card trick don't work on the newer samsungs.
You need to use the edl files and flash in edl mode.
Let me know what bootloader you are on.
BigCountry907 said:
Depending on what rev bootloader you are on I have the EDL Files.
The official samsung edl files to unbrick your s8.
The sd card trick don't work on the newer samsungs.
You need to use the edl files and flash in edl mode.
Let me know what bootloader you are on.
Click to expand...
Click to collapse
Probably the ones I shared In my groups....
I have a whole automated script to fix it But I still want to know what this guy was really doing
TheMadScientist said:
Probably the ones I shared In my groups....
I have a whole automated script to fix it But I still want to know what this guy was really doing
Click to expand...
Click to collapse
There is the possibility that the files I have may have originated by you.
But they did not come from XDA they came from a very different source.
I do agree with you that the only way to truly brick the device is to mess with the bootloaders.
Even mixing bootloaders can cause the brick.
I believe the bat file your referring to was released along with the EDL bootloaders.
But you could have easily wrote it it's not very complicated.
I'm just grateful that these files got leaked no matter where they came from.
At one point they were made by samsung at samsung factory without any doubt.
Either a samsung employee or an authorized samsung repair center that had them Leaked the files.
Unless you have samsungs private Key. Actually 3 of them considering the bootloaders are signed using 3 different certs.
If you have that then we should all be running unlocked devices. Please share.
I have been working on unlocking the bootloader for the N950U. Or at least finding a way to load a custom kernel. I believe the EDL bootloaders may have more ability than the stock or combination bootloaders.
We would need to pull the signatures from all the bootloaders and first determine if there using a 2 cert or 3 cert signing scheme. Then by looking at how certain bits of the device serial and other data in the signature we can determine if the debug level is set higher. Like Jtag access and what not.
I do have a copy of the msm8998 Source Code that was leaked. Its a very recent version. There are some things we can use it for but ultimately it would be nice to have the KEY. I'd be happy just to have the private key for signing the boot.img.
BigCountry907 said:
There is the possibility that the files I have may have originated by you.
But they did not come from XDA they came from a very different source.
I do agree with you that the only way to truly brick the device is to mess with the bootloaders.
Even mixing bootloaders can cause the brick.
I believe the bat file your referring to was released along with the EDL bootloaders.
But you could have easily wrote it it's not very complicated.
I'm just grateful that these files got leaked no matter where they came from.
At one point they were made by samsung at samsung factory without any doubt.
Either a samsung employee or an authorized samsung repair center that had them Leaked the files.
Unless you have samsungs private Key. Actually 3 of them considering the bootloaders are signed using 3 different certs.
If you have that then we should all be running unlocked devices. Please share.
I have been working on unlocking the bootloader for the N950U. Or at least finding a way to load a custom kernel. I believe the EDL bootloaders may have more ability than the stock or combination bootloaders.
We would need to pull the signatures from all the bootloaders and first determine if there using a 2 cert or 3 cert signing scheme. Then by looking at how certain bits of the device serial and other data in the signature we can determine if the debug level is set higher. Like Jtag access and what not.
I do have a copy of the msm8998 Source Code that was leaked. Its a very recent version. There are some things we can use it for but ultimately it would be nice to have the KEY. I'd be happy just to have the private key for signing the boot.img.
Click to expand...
Click to collapse
Actually a friend wrote the bat lol Pm me I have a telegram group not much activity but several s8 devs
including some well known fellars in it
Im pretty sure they use 3 keys But Several of us have looked into it quite extensively....
You are more than welcome to join the group and shoot the crap

Make ENG boot(adb enable file)

Hello.
I try to make ENG-boot file from ENG ROM (combination)
I uncompress Combination File and take sboot.bin , boot.img file to make .tar
And I flash that file show adb enable message but phone is Infinite boot
Then stuck in samsung galaxy S8 LOGO
How can I make adb enable file
Model : korea g950
jumam21 said:
Hello.
I try to make ENG-boot file from ENG ROM (combination)
I uncompress Combination File and take sboot.bin , boot.img file to make .tar
And I flash that file show adb enable message but phone is Infinite boot
Then stuck in samsung galaxy S8 LOGO
How can I make adb enable file
Model : korea g950
Click to expand...
Click to collapse
Why dont you flash with odin? Easier plus you can easily select a suitable firmware package from one of the sites?
Sent from my SM-G950U1 using Tapatalk
Re
rudimenta said:
Why dont you flash with odin? Easier plus you can easily select a suitable firmware package from one of the sites?
Sent from my SM-G950U1 using Tapatalk
Click to expand...
Click to collapse
I mean How can I make ADB enable file from combination File.
jumam21 said:
I mean How can I make ADB enable file from combination File.
Click to expand...
Click to collapse
Exynos? I hope so because there is no sboot file for snapdragon ?
You don't need the factory boot for exynos. Just enable OEM unlocking
partcyborg said:
Exynos? I hope so because there is no sboot file for snapdragon
You don't need the factory boot for exynos. Just enable OEM unlocking
Click to expand...
Click to collapse
He most likely cannot access that due to having his phone google locked. If that is the case. More than likely is by what he is asking. There is a program called FRP Hijacker by Hagard that allows making an adb enabled boot.img but it never works for me at least on newer android OS 7+. Havent checked logs yet to see why. The file flashes fine but of course is not adb enabled. Im thinking signing and other issues. for some. If anybody knows a solid way please post here. I am researching so probably will find my solution soon i hope.. Reason for the need that most have is due to not having a combination file (engneering firmware) for a certain device to pull the boot.img or boot.img + system.img to flash when enabling ADB and settings on a specific binary Samsung FRP (Google Locked) device.
noidodroid said:
He most likely cannot access that due to having his phone google locked. If that is the case. More than likely is by what he is asking. There is a program called FRP Hijacker by Hagard that allows making an adb enabled boot.img but it never works for me at least on newer android OS 7+. Havent checked logs yet to see why. The file flashes fine but of course is not adb enabled. Im thinking signing and other issues. for some. If anybody knows a solid way please post here. I am researching so probably will find my solution soon i hope.. Reason for the need that most have is due to not having a combination file (engneering firmware) for a certain device to pull the boot.img or boot.img + system.img to flash when enabling ADB and settings on a specific binary Samsung FRP (Google Locked) device.
Click to expand...
Click to collapse
Frp bypass is not a kosher topic here as it's most common use case is to unlock stolen hardware. If that is his problem he should either give the phone back to its original owner, it if it's his account go through the password recovery process with Google
partcyborg said:
Frp bypass is not a kosher topic here as it's most common use case is to unlock stolen hardware. If that is his problem he should either give the phone back to its original owner, it if it's his account go through the password recovery process with Google
Click to expand...
Click to collapse
This has also been told to me by a mod ive spoke with time to time but the others really don't seem to mind as long as it is to help others and such. Which is what i do when i put up a manual tutorial. I usually do all by freestyling (no looking into anything unless really needed). If the same PartyCyborg from Android Forum Community. We don't know each other but I have used your work past and present and had a swell time finding through archives but this i enjoy. Very cool work man esp the last bit i asked you about on i believe an older Samsung 2014? device to action with your Rom's latest. Alright back to AndroidForum Community I have explained my whole outlook & debated the whole FRP issue with phones today. It's a challenge and it's helpful to those that aren't running masses of stolen phones through boxes (hey even stolen hardware once seized returns back to the community and has to be delt with.. i as do others get some devices from LEA property) and also that huge majority of people who quickly create accounts without jotting down and remembering info. Then i could go back into bulk onto stores who legally obtain (auction for example) then have to either a) find a way to fix frp and or 2) resell these devices 3) part out as google locked LB's etc. Google Lock and FRP in general is a VERY good thing IMHO. I want to see us make a move to more secure reliable FRP locks such as iClouds. We also have a security section here on XDA where all sorts of the latter and even deeper is discussed. Win Win for Security overall if you think about it all and take it in. I've said this before in other Areas of the internet I am from and I will say it again in similar words "they build it, we bypass it, they improve it.......(reversing.. updating.. learning.. phase) and the process continues.". We are improving security on everything be it my old days email filters (especially the old ways) or be it Google Lock Security & FRP and the countless other companies small and big across the globe with related protection put in place. Don't put a dark hat on it all.. at least just yet. -not directed toward you by any means or anyone else.. just my quickie worth of that whole 2 cents for what its worth.

SM-S727VL Root and Recovery

I cannot for the life of me get this phone rooted or a recovery installed. Odin always fails and ADB doesn't recognize the device. Does anyone have any info on rooting this device? I really just want to at least be able to update this thing to nougat.
Nobody knows much about this device since it's not that popular. Some team named TWRP builder built a twrp for the SM-S727VL but it cannot be flashed even when converting to .tar.md5 or .tar.
Also I believe the bootloader on this phone is locked and CROM service does not function (if I am correct) on this device. CROM service will show it being unlocked but it seems to be lying to you.
djared704 said:
Nobody knows much about this device since it's not that popular. Some team named TWRP builder built a twrp for the SM-S727VL but it cannot be flashed even when converting to .tar.md5 or .tar.
Also I believe the bootloader on this phone is locked and CROM service does not function (if I am correct) on this device. CROM service will show it being unlocked but it seems to be lying to you.
Click to expand...
Click to collapse
Well that figures, im willing to use my device to work at it if anyone knows where to start.
I have 3 of these... not a noob but not an expert...say Pre-elite lol. I'm wanting to learn how to go further than use everybody else's solutions to root my phone's if somebody can give me some advice as to where to start as in I know how to root put it that way I was one of the people back in the day with the Evo when it was actually difficult no worries most of them were fine but these files we keep flashing these ROMs these kernels these firmwares where does one start when a phone like this 727 VL is obscure supposedly and nobody is doing anything to be able to root them I have everything that I need I'm sure and if I don't get it. It's somebody point me to a person or in the right direction to get started on what I need to due to learn how to write for I mean what where's the first step on these I've always just use everybody else's files. If that even makes any sense to anybody and anybody can give me a hand or show me the right way I'd be willing to do the work from there on I just need somebody to stick up a finger and say go there.... I mean if we have a twrp written, and we have OEM unlock, then why can't one of us do this I've been around long enough I've read long enough I've never once posted in these forms but I've read them daily... I know I got the skills I just need to know which ones to use. Odin fails like he said, fastboot for some reason still won't recognize, I actually made it one step with one of mine but it has to be a little incorrect because the only thing noticeable is it pops up with vo LTE at the top instead of just regular LTE like this one I'm on now. I was able to flash it with Odin believe it or not with what seems to be possibly just stock S727VLUDU2AQG1_ENG_boot_boxwares.tar
BUT the point is I was able to flash it with Odin and also it did change something because my phone now says there's been unauthorized changes and it wants me to restart it all the time so it can correct itself however it does not, it stays whatever it is, yes I know this is pretty vague however I got to the point where I just started trying anything on one of these phones to see if I could get any kind of anything to work and it did.. kind of.
I will say the USB drivers that's you find every where now do not work you have to go back to looks like version 1.5.5 1.0 SAMSUNG-USB-Driver-for-Mobile-Phones-15510.
With these drivers fast boots if I remember correctly will recognize it when you do fastboot devices however it still hangs on waiting on device. I'm sure I got more information my brains just a little foggy at the moment it is like 3 in the morning and I hope I didn't break any rules posting.
I did try flashing from SD card with no success yet nothing at all just error after error. I have tried twrp however it's supposed to be for this 727 VL I'm sure it's the same one everybody's got because it's only in one place that I've found but it comes up twrp-3.2.1-j7popqltefnvzw-201 and it will not flash.
I realize I have been pretty obscure however there's no reason why if all 5 of us with this VL stick together we can't get it rooted because I'm not going to give up LOL
Keep up the good work
I to have a j7 sky Pro, we need to figure out how to get this bootloader unlocked I would love the links to any from builds or twerp builds you have for this j7POPQLTEFNVZW
twrp
[email protected] said:
I to have a j7 sky Pro, we need to figure out how to get this bootloader unlocked I would love the links to any from builds or twerp builds you have for this j7POPQLTEFNVZW
Click to expand...
Click to collapse
I have a twrp that I managed to find on the internet but i have heard that it was for an older version of the phone. meaning it has to be updated somehow. I do know that the phone had a security patch update on June 1, 2018. I am currently trying to figure out if how to update the twrp or something, but I think I might need a little assistance. Because I am no expert ROM developer or anything of the sort but I am trying to learn, so I can eventually build a custom ROM for this phone.
Masterx4020 said:
I have a twrp that I managed to find on the internet but i have heard that it was for an older version of the phone. meaning it has to be updated somehow. I do know that the phone had a security patch update on June 1, 2018. I am currently trying to figure out if how to update the twrp or something, but I think I might need a little assistance. Because I am no expert ROM developer or anything of the sort but I am trying to learn, so I can eventually build a custom ROM for this phone.
Click to expand...
Click to collapse
Like I said in another thread about this issue, We are not to that bridge yet. The bootloader is locked and we cannot flash it yet.
Justin1198 said:
Like I said in another thread about this issue, We are not to that bridge yet. The bootloader is locked and we cannot flash it yet.
Click to expand...
Click to collapse
Okay, have you tried anything to unlock it. If so can you tell me what you have tried so I can see what doesn't work.
Masterx4020 said:
Okay, have you tried anything to unlock it. If so can you tell me what you have tried so I can see what doesn't work.
Click to expand...
Click to collapse
See post #11 on thread https://forum.xda-developers.com/galaxy-j7/how-to/sm-s727vl-analysis-partition-table-t3858632
Justin1198 said:
See post #11 on thread https://forum.xda-developers.com/galaxy-j7/how-to/sm-s727vl-analysis-partition-table-t3858632
Click to expand...
Click to collapse
Is there a way to tell if the bootloader is locked? (Sorry if I am asking noobish questions. I am just trying to learn.)
You can tell the Bootloader is locked because you get “Secure Check Failed” if you try to flash anything that has been modified. For example; The TWRP recovery file. We need root to bypass the Bootloader.
Allow
allow what
I feel like you're telling me to do something that's way over my head cuz I do not understand what do you mean by allow
I have read write access to root files now !!
I can now access all files on my 2nd of 3 J7s. I am attaching pics. When I try to duplicate and copy on my other J7 ,the factory ones, I get check file permissions access denied. However I've passed it on this one particularly. It also now gives me a security notice on the lock screen of unauthorised actions have been detected please restart phone to correct them. However even when you restart the phone it stays so it isnt temporary. I have actually even going to factory reset to see believe it or not it stays. So the next step would be one in which I need some input to know which files I need to modify to be able to install BusyBox Superuser and from their custom recovery excetra and we're in I believe correct me if I'm wrong.
Can't post pics yet so someone get at me here and I will send them to you to post. Or on my FB at Mighty.Whity.Titan
You can send them to me if you like.
No problem how do I not familiar with these forms
josh0426 said:
You can send them to me if you like.
Click to expand...
Click to collapse
One b a d d a d d i e i o and that said the old Google Mail you know if you want to send me an email I can forward them all to you cuz I can't post them and that's about the best I can do
Pre-Elite said:
One b a d d a d d i e i o and that said the old Google Mail you know if you want to send me an email I can forward them all to you cuz I can't post them and that's about the best I can do
Click to expand...
Click to collapse
[email protected]
Pre-Elite said:
I can now access all files on my 2nd of 3 J7s. I am attaching pics. When I try to duplicate and copy on my other J7 ,the factory ones, I get check file permissions access denied. However I've passed it on this one particularly. It also now gives me a security notice on the lock screen of unauthorised actions have been detected please restart phone to correct them. However even when you restart the phone it stays so it isnt temporary. I have actually even going to factory reset to see believe it or not it stays. So the next step would be one in which I need some input to know which files I need to modify to be able to install BusyBox Superuser and from their custom recovery excetra and we're in I believe correct me if I'm wrong.
Can't post pics yet so someone get at me here and I will send them to you to post. Or on my FB at Mighty.Whity.Titan
Click to expand...
Click to collapse
Can you please share the method that you used to gain read/write access? If you indeed have temp access, I can make it permanent also what firmware build are you on?
Absolutely
I'm not home right now but I'm headed there I'll be there in a couple hours I can if somebody wants to give you their email or email me because I can't post links or anyting I have the file that I used the wrong and I have the driver for Samsung for Odin that I used which I think I've mentioned in my original or previous post and by the way it is not temporary. This is permanent. I did a factory reset and it stays. I just need to know which permissions which file to go to to get my Superuser installed because it's still will not let me install that. But email me or tell me how to send it on here or something that way I can let you guys know or give you guys what I got. I'll tell you this I did not flash it with a v l ROM. I flashed it using a Verizon ROM the only thing that didn't work was my wife I which I think I originally and said back when I made my first comment on this thread I haven't done anything else I set my phone down and it was done clear back there I just didn't realize it. But it is not a VL ROM it's a Verizon ROM a v not a straight talk and my wife I would not which turned out to be something unrelated. I'm in no way trying to keep this from anybody because I know just how much we all want these damn things. But I would sure love to finish the job that I started but I do not mind handing over what I've got.
---------- Post added at 02:53 AM ---------- Previous post was at 02:40 AM ----------
Josh I just emailed you six pictures I just now seen your email in your post and Justin as soon as I get home if you can shoot me an email or get in contact somehow or I can send you everything I got so far once I get there
Here are the pictures

Seeking advice on rooting Smart Tab M10 FHD Plus 2nd Gen

Dear and knowledgeable readers!
Being a longtime lurker, your tireless work and dedication to the community have enabled me to unlock and root many different android devices over the years and I am deeply grateful this place exists.
Right now, I plan on adding the recently released
Lenovo Smart Tab M10 FHD Plus 2nd Gen [ZA5T0302SE / TB-X606F, I believe]
in the WLAN/4GB/64GB variant to my collection. Having grown accustomed to the luxury of root access, I was wondering if anyone already had some experience with rooting the device and would be willing to share his / her knowledge with me.
Especially, I was wondering if this guide for the TB-X605F, which I have successfully used in the past for my older model, would (in principle) be applicable, as long as I could obtain the corresponding firmware for the newer one, which might be available here (as soon as GD wills it).
Any advice / support would be highly appreciated!
[Sidenote]: To my best ability, I wasn’t able to find an existing thread on the topic of rooting the device in question and I hope to have chosen the right forum to post it in (or if the general Q&A would have been the better fit?). If not, dear mods, please be lenient with me and simply move the thread to the proper subforum.
Brotinger said:
Dear and knowledgeable readers!
Being a longtime lurker, your tireless work and dedication to the community have enabled me to unlock and root many different android devices over the years and I am deeply grateful this place exists.
Right now, I plan on adding the recently released
Lenovo Smart Tab M10 FHD Plus 2nd Gen [ZA5T0302SE / TB-X606F, I believe]
in the WLAN/4GB/64GB variant to my collection. Having grown accustomed to the luxury of root access, I was wondering if anyone already had some experience with rooting the device and would be willing to share his / her knowledge with me.
Especially, I was wondering if this guide for the TB-X605F, which I have successfully used in the past for my older model, would (in principle) be applicable, as long as I could obtain the corresponding firmware for the newer one, which might be available here (as soon as GD wills it).
Any advice / support would be highly appreciated!
[Sidenote]: To my best ability, I wasn’t able to find an existing thread on the topic of rooting the device in question and I hope to have chosen the right forum to post it in (or if the general Q&A would have been the better fit?). If not, dear mods, please be lenient with me and simply move the thread to the proper subforum.
Click to expand...
Click to collapse
If you download the lmsa tool, plug in the tablet and go to recovery it will download the full stock firmware. Then you can find it c/program data/LMSA/downloads.
I did that then downloads magisk manager. Extract the boot.img from firmware and put in storage of tablet. Then used magisk manager and patch the boot.img it will tell where it is stored. Extract from tablet and put it in same folder as adb/fast boot. Then put tablet in fastboot and fastboot flash boot magisk-patched.img. then fastboot reboot. The will be rooted with magisk
I forgot. You must unlock bootloader to do this.
Dear 11mackey11,
thank you so very much for caring enough to share your knowledge with me!
So the guide I mentioned earlier is pretty much applicable for the newer model as well? What a relief!
I am also grateful for the hint on how to obtain the stock firmware. For all the dirty things I did to my devices in the past, it never became necessary to put the LMS-Assistant to use, but I will gladly change that now.
As soon as my device arrives, I will try to root it as you suggested and will report back how I fared.
Again, many thanks!
It took me some time to finally get to it … delivery problems with the device … busy work schedule …
… anyhow, I now took the leap and am happy to report that, thanks to your advice, I was able to add another rooted device to my ever-growing collection. “Worked like a charm”, as they use to say.
To repeat myself, I am very grateful for you taking the time to respond to my question and reassuring me that this was the path to follow.
Honestly, thanks!
Brotinger said:
It took me some time to finally get to it … delivery problems with the device … busy work schedule …
… anyhow, I now took the leap and am happy to report that, thanks to your advice, I was able to add another rooted device to my ever-growing collection. “Worked like a charm”, as they use to say.
To repeat myself, I am very grateful for you taking the time to respond to my question and reassuring me that this was the path to follow.
Honestly, thanks!
Click to expand...
Click to collapse
Hi. I just purchased the same tablet. I would appreciate it if you could write up a guide on this forum. It would be a help for everyone.
I'm not even sure how you unlock the bootloader on this thing!
Hi and congratulations on your purchase! The TB-606F is a solid device in my book.
Although I have by now rooted more than a dozen android devices and guess I have at least somewhat of an idea of what I am doing, I am by far no pro on the issue. Basically, I consider myself more a “guide user” than a “guide creator”, still.
But as I have benefited from the kind- and helpfulness of this community many times before, I can’t leave this call for help unanswered.
The thing is, nonetheless, I would really like to refer anyone poised to root their TB-606F to the guide for the TB-605F which I linked to in my initial post. Rooting the TB-606F, in principle, demands the user to undertake the same steps as for rooting the TB-605F.
There are, from the top of my head, only two noticeable differences or variations from that guide which I discovered:
1) firmware
As I still haven’t found a reliable source to obtain the necessary stock firmware by download from the web, the advice of fellow user 11mackey11 comes in very handy who, in response to my initial post, pointed me to the LSMA to download the firmware from your very own device.
2) unlocking bootloader
At least with my device, the fastboot commands known to me to usually unlock the bootloader (as are “fastboot oem unlock-go”, “fastboot oem unlock” or “fastboot flashing unlock”) did not do the trick. I had to resort to the command line of “fastboot flashing unlock” to finally make some progress. This might be an outlier with me device, though, as 11mackey11 did not mention the issue.
Again, I will gladly provide any assistance I can offer, but as for writing up a guide, I would mostly carbon copy turboperson123’s guide for the TB-605F mentioned above anyhow and it does not seem right to take credit for his contributions.
But if you had any specific question, please don’t hesitate to ask and I will answer it to my best knowledge (which might not be much).
Tutorial
I found this tutorial specific to the X606F https://forum.frandroid.com/topic/2...u-lenovo-tab-m10-fhd-plus-tb-x606f-sans-twrp/ alas in French but Google translate makes a decent job out of it
b4nd0ler0 said:
I found this tutorial specific to the X606F https://forum.frandroid.com/topic/2...u-lenovo-tab-m10-fhd-plus-tb-x606f-sans-twrp/ alas in French but Google translate makes a decent job out of it
Click to expand...
Click to collapse
I want to apply it to my device, have you tried this method?
Yes, tried and failed miserably. The tablet is not correctly rooted as reported by Root Checker. The su binary is there and shows it's Magisk but no root proper.
Will try again and report back when done.
b4nd0ler0 said:
Yes, tried and failed miserably. The tablet is not correctly rooted as reported by Root Checker. The su binary is there and shows it's Magisk but no root proper.
Will try again and report back when done.
Click to expand...
Click to collapse
thanks, I'm waiting for news from you. The tablet is sold very much in our country. like this in the world. I'm sure the developers will do something about this device.
b4nd0ler0 said:
I found this tutorial specific to the X606F https://forum.frandroid.com/topic/2...u-lenovo-tab-m10-fhd-plus-tb-x606f-sans-twrp/ alas in French but Google translate makes a decent job out of it
Click to expand...
Click to collapse
I rooted my device with this method
this method doesn't work
Hello dear Android users...
I've got the 3/64GB version of this device (ZA5T0300US) and this method of rooting did not work for me. When I check root in Magisk Manager, it says ctsProfile:false & basicIntegrity:true, so root doesn't work. I tried multiple times and every time had this same result. My ROM version is TB_X606F_USR_S100055_2001030016_V5.196_BMP_ROW (extracted ROM folder name). Are you sure your root actually 100% worked? What is your ROM version?
adroid_user said:
Hello dear Android users...
I've got the 3/64GB version of this device (ZA5T0300US) and this method of rooting did not work for me. When I check root in Magisk Manager, it says ctsProfile:false & basicIntegrity:true, so root doesn't work. I tried multiple times and every time had this same result. My ROM version is TB_X606F_USR_S100055_2001030016_V5.196_BMP_ROW (extracted ROM folder name). Are you sure your root actually 100% worked? What is your ROM version?
Click to expand...
Click to collapse
This method is working!
Use the Official Lenovo website to access your original "rom" file and get the "boot.img" file.
Program: Lenovo Rescue And Smart Assistant https://lnv.gy/3d8FHLi
For an article on how to download the Rom file via the program, see here. (Step 3)
https://bit.ly/2yE1nQf
Good Luck!
adroid_user said:
Hello dear Android users...
I've got the 3/64GB version of this device (ZA5T0300US) and this method of rooting did not work for me. When I check root in Magisk Manager, it says ctsProfile:false & basicIntegrity:true, so root doesn't work. I tried multiple times and every time had this same result. My ROM version is TB_X606F_USR_S100055_2001030016_V5.196_BMP_ROW (extracted ROM folder name). Are you sure your root actually 100% worked? What is your ROM version?
Click to expand...
Click to collapse
You did not enable Magisk Hide
mingkee said:
You did not enable Magisk Hide
Click to expand...
Click to collapse
That was it! Thanks! You're smarter & more helpful than Google!!! ))
Hi.
After i root the tablet, i tried to delete youtube and gdrive. Then i restart the tablet but it stuck in fastboot mode. Not booting.
i couldn't install stock rom. What i must do
I did this..
i patched the boot img from the lenovo program. and i like to shut down my devices when i dont use them and now i cant make it boot. im stuck in a bootloop and its says orange alert when i boot the device. i can only get into the fastboot menu. when i try to boot with vol + and power nothing happens and when i release it starts up again in a bootloop. i cant shut it down either. it just loops and loops. cant do the rescue thing with the program either.. anybody that knows how i can fix this?
I have an out of topic question regarding this tablet.
Can The Lenovo M10 Plus (2nd Gen) 10.3" TB-X606F Output Display via HDMI to TV ???
I tried using a powered USB-C to HDMI adapter to output/mirror the tablet to a TV, but it didn't work.
Brotinger said:
Hi and congratulations on your purchase! The TB-606F is a solid device in my book.
Although I have by now rooted more than a dozen android devices and guess I have at least somewhat of an idea of what I am doing, I am by far no pro on the issue. Basically, I consider myself more a “guide user” than a “guide creator”, still.
But as I have benefited from the kind- and helpfulness of this community many times before, I can’t leave this call for help unanswered.
The thing is, nonetheless, I would really like to refer anyone poised to root their TB-606F to the guide for the TB-605F which I linked to in my initial post. Rooting the TB-606F, in principle, demands the user to undertake the same steps as for rooting the TB-605F.
There are, from the top of my head, only two noticeable differences or variations from that guide which I discovered:
1) firmware
As I still haven’t found a reliable source to obtain the necessary stock firmware by download from the web, the advice of fellow user 11mackey11 comes in very handy who, in response to my initial post, pointed me to the LSMA to download the firmware from your very own device.
2) unlocking bootloader
At least with my device, the fastboot commands known to me to usually unlock the bootloader (as are “fastboot oem unlock-go”, “fastboot oem unlock” or “fastboot flashing unlock”) did not do the trick. I had to resort to the command line of “fastboot flashing unlock” to finally make some progress. This might be an outlier with me device, though, as 11mackey11 did not mention the issue.
Again, I will gladly provide any assistance I can offer, but as for writing up a guide, I would mostly carbon copy turboperson123’s guide for the TB-605F mentioned above anyhow and it does not seem right to take credit for his contributions.
But if you had any specific question, please don’t hesitate to ask and I will answer it to my best knowledge (which might not be much).
Click to expand...
Click to collapse
Hey, thanks for all this useful info. I'm a noob when it comes to rooting. I have hit an issue, that you guys could probably easily advice me. I have got up to where you enter "fastboot flashing unlock" it comes back with something like "waiting for any device". How do I get past this point? I have tried pressing volum up as I saw on a guide however no luck.
unlock not possible
CMX939 said:
Hey, thanks for all this useful info. I'm a noob when it comes to rooting. I have hit an issue, that you guys could probably easily advice me. I have got up to where you enter "fastboot flashing unlock" it comes back with something like "waiting for any device". How do I get past this point? I have tried pressing volum up as I saw on a guide however no luck.
Click to expand...
Click to collapse
I have the same issue, "waiting for device" and adb dies.
I assume, the latest lenovo updates (Android 9) block unlocking.
The current! LMSA tool does not allow to restore an old separately downloaded firmware

Categories

Resources