Main objective: Find any way to enabling application transfer from internal storage to external storage.
The device has 16 GB of internal memory, which is definitely not enough to use additional applications. It looks like the option to transfer apps from internal storage to external storage for this particular model is forbidden. This situation makes it practically impossible to use this device any longer. I have tried many ways to resolve the problem. Unfortunately i failed. Therefore, I am asking for help from specialists from this forum if there is any way to make it possible way to do this taking into consider the inability to obtain the code from the site, which I am writing about below.
What i have tried already:
Enabling programmer mode and therefore changing the option that is blocking transfer to external storage. Unfortunately switching is not possible in this case. Enabling this option automatically forces return to the previous state.
Installing applications that are supposed to enable such transfer. Most of them are crap and scam.
Attempting to upgrade system with a built-in option and with Hi Suite. There is no option to upgrade firmware or downgrade by using this options.
Attempting to upgrade system with Firmware Finder for Huawei. I don't think I can get anything more than just downloading the firmware using this app. The idea was to force the installation of a newer version of the operating system by forcing some changes in the built-in updater.
Root and open firmware attempts:
At first, I was looking for a way to gain root access with the app available (kingRoot, KingoRoot etc.). Neither of them worked
I tried to install custom recovery. I turned on usb debugging, disabled the OEM lock and I was able to set the connection to the device.
When I tried to upload a custom recovery I got a message saying that this method is forbidden.
I was looking for information about the problem and so I found out that the botlooader is locked and that I need a special key to unlock him.
Next I found information that it is possible to obtain this key using paid applications and I'm skeptical about them.
Another option was to try to get this code from the manufacturer. It turned out that it was actually possible, but for some time Huawei as a manufacturer no longer provides these codes, which was confirmed to me by a person employed on the HelpDesk hotline.
Device information
Device nameHUAWEI MediaPad T3 10ModelAGS-L09S/NHEKNU19103105947Product ID89046711External SD card:64 GB
System information
Android System Version7.0EMUI version5.1.3Compilation:AGS-L09C100B279
Have you tried this steps - https://www.droidguides.com/unlock-bootloader-install-twrp-recovery-huawei-mediapad-t3-10/
Also trying this, Tempted to just throw the device out the window, think next time I will stick with Samsung.
Viro251 said:
Main objective: Find any way to enabling application transfer from internal storage to external storage.
The device has 16 GB of internal memory, which is definitely not enough to use additional applications. It looks like the option to transfer apps from internal storage to external storage for this particular model is forbidden. This situation makes it practically impossible to use this device any longer. I have tried many ways to resolve the problem. Unfortunately i failed. Therefore, I am asking for help from specialists from this forum if there is any way to make it possible way to do this taking into consider the inability to obtain the code from the site, which I am writing about below.
What i have tried already:
Enabling programmer mode and therefore changing the option that is blocking transfer to external storage. Unfortunately switching is not possible in this case. Enabling this option automatically forces return to the previous state.
Installing applications that are supposed to enable such transfer. Most of them are crap and scam.
Attempting to upgrade system with a built-in option and with Hi Suite. There is no option to upgrade firmware or downgrade by using this options.
Attempting to upgrade system with Firmware Finder for Huawei. I don't think I can get anything more than just downloading the firmware using this app. The idea was to force the installation of a newer version of the operating system by forcing some changes in the built-in updater.
Root and open firmware attempts:
At first, I was looking for a way to gain root access with the app available (kingRoot, KingoRoot etc.). Neither of them worked
I tried to install custom recovery. I turned on usb debugging, disabled the OEM lock and I was able to set the connection to the device.
When I tried to upload a custom recovery I got a message saying that this method is forbidden.
I was looking for information about the problem and so I found out that the botlooader is locked and that I need a special key to unlock him.
Next I found information that it is possible to obtain this key using paid applications and I'm skeptical about them.
Another option was to try to get this code from the manufacturer. It turned out that it was actually possible, but for some time Huawei as a manufacturer no longer provides these codes, which was confirmed to me by a person employed on the HelpDesk hotline.
Device information
Device nameHUAWEI MediaPad T3 10ModelAGS-L09S/NHEKNU19103105947Product ID89046711External SD card:64 GB
System information
Android System Version7.0EMUI version5.1.3Compilation:AGS-L09C100B279
Click to expand...
Click to collapse
Have you had any look so far?
Not possible without unlock the bootloader.
Im very angry with Huawei.
----Edit----
Unlock bootloader but pay 49$ with octoplus huawei tool, now tried install lineageOs
I unlocked for 4 Euro with HCU Client. I buy the credit on DC-Unlocker.
krisy0243 said:
I unlocked for 4 Euro with HCU Client. I buy the credit on DC-Unlocker.
Click to expand...
Click to collapse
Thanks for the tips I was able to unlock my AGS-W09 for 4 euro too (I would not have paid 40 euros for this device!).
I just lost several hours to understand and find the way to the "manufacter mode" on a tablet !
For those looking how to: launch the calc app and enter ()()2846579()()
an hidden menu will popup and you will be able to setup USB ports.
tuxfamily said:
Thanks for the tips I was able to unlock my AGS-W09 for 4 euro too (I would not have paid 40 euros for this device!).
I just lost several hours to understand and find the way to the "manufacter mode" on a tablet !
For those looking how to: launch the calc app and enter ()()2846579()()
an hidden menu will popup and you will be able to setup USB ports.
Click to expand...
Click to collapse
I launch the Calc app as you advised but nothing happened..! Pls help a brother..! How can I buy this 4euro bootloader tool..?
aobaro said:
I launch the Calc app as you advised but nothing happened..! Pls help a brother..! How can I buy this 4euro bootloader tool..?
Click to expand...
Click to collapse
Sorry, it wasn't mine, I don't have it anymore.
As I remember, It was the stock calc app, in landscape mode in order to have the "()" but that's all.
But the firmware is very important: it should be Android 7, and not the 8 (I don't remember the exact firmware version).
This said, I wasted my time rooting this tablet, it's pretty useless. Apart removing two stock apps and installing AdAway, I was not able to do much more. Unfortunately, there are no custom rom to give a new youth to device.
I got all the prerequisites, try to flash twrp in recovery but get the error: the partition table doesn't exist. Is there any solutions for this?
Related
OK IMEI-CHECK charge £20 to unlock the phone, and I say fair enough. Why am I posting this? Did you know that their method is probably writing a NEW locking code using some other algorithm? If you run their software, it will inflate and write (about 4K of data if i remember correctly) in the part of the Radio ROM, where you only get access from the bootloader (memory address h'0' to h'10000'). Now here's the thing: I bet if I call T-mobile and ask for the unlocking code, it won't work in my phone, as these guys are actually modifying the Radio ROM without even telling you. Have you guys thought about insurance? For those who don't pay £9.99 or whatever extra cover, what if you pricey and precious pda goes bonkers? I think they should tell you *before* doing anything, about any possible problems.
Come on you guys, someone said he has compiled a few logs/imei numbers. Let's crack this thing, it has been done before for xda I and II, why can't we do it for IIs/IIi?
If that's the case, then I wonder what's in those .uif files they ask you to send back to them? Could it be a backup of the sections of the radio ROM that they're replacing?
Also, if they're writing a fixed set of data to the radio ROM, how come everyone seems to have different unlock codes? Could they be replacing the actual algorithm that calculates the unlock code so that it only accepts certain combinations of codes from them?
-no1
Just had another thought - what if they're replacing code in the radio ROM with code from the Himalaya so that the unlock process then works in the same way as the Himalaya?
Has anyone tried using the xda2unlock tool after running the program from IMEI-Check??? I can't test this just now, so it's just a guess.
-no1
Could they be replacing the actual algorithm that calculates the unlock code so that it only accepts certain combinations of codes from them?
Click to expand...
Click to collapse
Yes I believe that's what they actually do. I tried to run their utility with a debugger but it does not allow execution as long as a debugger is running, nice one IMEI-CHECK. However, I have done a full USB port logging when the utility runs and I found out that they write a new image between addresses 0 and 10000 of the radio rom, and that they also read from 3FC000 the first 4000 bytes, and from FFFEF000 the first 20 bytes.
Yesterday I discovered something odd...after running their application, and by inserting a different SIM card, the attempts counter for the unlocking code had a negative value of several millions. Now I suspect that by writing in adresses 0-10000, i think they replace the default unlocking utility which allows to enter the code.
Another idea I will try will be to run a debugger in the PDA (if I can find one) and see if I can capture the memory address with which it compares the input code.
Come on guys, especially you who did the unlocking utility for XDA II!! Give us some help here!!!!
Zouganelis,
That's excellent that you've been able to sniff the USB traffic. Keep up the investigations!
I wonder why they'd need to read sections of the ROM? If they're replacing the calculation algorithm section of the ROM with their own code, then they should already know how to calculate the unlock code - i.e. they shouldn't need the user to send them back the .uif file.
This makes me wonder if the code they are replacing is just a copy of the code from another device e.g. the Himalaya.
If they are replacing with code from the Himalaya then the unlock process may revert back to how it works on the Himalaya.
Has anyone been able to test this by running the xda2unlock tool for the Himalaya *after* running the IMEI-Check program?
Does anyone have the source code for xda2unlock by the way? I tried searching for it, but it doesn't seem to be available.
-no1
Another thing, does anyone know if it's possible to back up and restore this secret area of the radio ROM using the backup to SD method? I assume that when you dump your radio ROM to SD card it's not including this part of the ROM???
I want to be able to fully restore any bits that the IMEI-Check tool is changing, just in case.
-no1
Come on guys, anyone else trying to crack this thing? We need someone who knows how to disassamble/reverse engineer this log file. It can't be that hard! Also, I think the key to understanding what their little proggy does, is to manage to run a debugger when the unlock program runs. It has some mechanism of detecting a running debugger and it quits if you have a debugger running at the same time. I bet my MDA III that some experienced programmer can overcome this and fool their application? I am running out of ideas guys and I am really against paying these thieves 20 quid for nothing. They MUST have done this using the previous unlocking methods for XDA I and II. Does any1 know who did those unlockign utilities? These guys must help us!!!
Have you tried to run OllyDbg as a debugger tool to see what is happening? Your earlier findings were very interesting...let me study this and get back to you all...
One remark upfront though: I do not think they are modifying your Radio ROM....this would mean that if you upgrade/replace your current Radio ROM, you would be SIM-lock free...and I do not think that is the case...
OK, some initial observations:
1. Lousy software...hard to use for novices...why have the phone enter BL mode automatically (using enterBL.exe)...I think we can do better!
2. Since the phone must be in BL mode, I do think it extracts some info from the radio ROM, but the SIM-Lock could also reside in the Extended ROM, since this is usually customized by the provider?
3. Interesting to see that the same proggie and procedure is used for all XDA-X models
4. Can anyone post a file (output of the proggie) of what they have mailed these folks, as an example?
5. I was always under the impression that the SIM-Lock resides in the SIM itself, so this is a software workaround? What happens if you upgrade your ROMs...you need to go through this process again? Does anyone have experience with this?
Thanks, and let's get this thing cracked!
HappyGoat,
My understanding is that SIM lock is implemented by the phone itself rather than the SIM card.
In the case of our HTC devices, there seems to be a small area of the radio ROM that does not get written to (even when you upgrade your ROM). This area is where the SIM lock is located, and probably other information such as your IMEI number.
This is probably why your IMEI and SIM lock information never get replaced when you upgrade your ROMs. I seem to remember that an older version of the xda2unlock tool was able to change your IMEI number but it got pulled for legal reasons.
When I unlocked my Himalaya, it stayed unlocked even after later upgrading the ROMs, so the state of the SIM lock is being stored somewhere. It can't be on the SIM because what if you change your SIM after you unlock it? The phone would need to be able to read your old SIM to check if the phone is locked!
Zouganelis,
Have you got any idea if it's possible to back up the areas of the radio ROM you mentioned to SD card? Like the current SD card backup method, but getting ALL of it?
-no1
Happygoat and no1,
i am pretty sure they write to the radio ROM some data they inflate from their "unlocking" executable file. How do I know this? Well, when I put a different SIM into my XDA IIs, after I enter the pin code, the simlock application comes up (simlock.exe under \windows\) which checks for the correct unlocking code. Now usually, you have 3 attempts available to do this, before the phone locks and says "contact customer services" or whatever. After I run their application, the counter had a value of -2billion or something, making it impossible to lock it. Interestingly enough, the memory adresses to which they WRITE, are between 0 and 10000. Is it a coincidence the simlock.exe application is 10.5kB? I don't think so!! i think they write their own simlock application to reset the counter, and then they read from 3FC000 the first 4000 bytes, and from FFFEF000 the first 20 bytes. The simlock code MUST be here!! i will post the log from the USB port sniffing tomorrow, as I don't have these files right now. It's pretty obvious to see how the bootloader works. Anyone with past experience especially with CE based devices will be able to figure out how to read these last two chunks of the radio rom.
Here's a link with some interesting files, RED has posted in the past:
http://www.pgwest.com/phone-files/
Username: xda
Passwrod: blueangel
I do agree with no1 regarding the simlock, I think this is exactly the way it works.
no1, I don't know how to do any backup to the SD card, but if you really know what you are doing in the bootloader, try reading from the memory addresses I mentioned earlier.
Keep it up guys, i think we know what their software does, we now need to find out how to read properly the output log.
Regards,
Zouga
Hi zouganelis and no1,
Thanks for the explanations and comments...all makes sense to me now, excellent.
Zouganelis, thanks for the website...that is the stuff I was looking for, cheers!
I do indeed think we are close...will report back later.
So... if they need the .uif file AND the IMEI number, could it just be a case of using the IMEI code to decrypt the contents of the .uif file? In other words the IMEI code is the decryption key??? But what kind of encryption are they using?
I think they used simple XORing in the past for encrypting the radio, OS, and extended ROMs, but this changed slightly for the Blueangel. I wonder if they used a similar method?
-no1
Interesting thought...and a simple one...which explains they can turn around a request so quickly...
You might be correct...the IMEI could bear the encrypted code for simlock or not. Nowadays, encryption standards are:
DES
MD5
SHA
DES is relatively easy to "crack", SHA being the hardest...they are one-way encryptions, which mean they can not be reversed. The only way to get a match is to try...I have numerous proggies for this and will explore this option...
OK, did some more googling, found the following. There appear to be only 3 companies or people who can do this, which makes it even more interesting...
1. www.imei-check.com (UK)
- Download proggie
- Send them back the output and EMEI number
- Receive unlock code
2. Ebay guy (Canada): http://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem&category=43312&item=5763970199&rd=1&ssPageName=WDVW
- Sends you software
- You will run this software and it will generate a log file (data cable required).
- You'll need to email us this log file and we will send you the unlock code with instructions as soon as possible
Looks like same procedure as EMEI-CHECK
3. www.UnLockItNow.com (Company in Malta): http://www.unlockitnow.com/remote/unlock/by_cable/Pocket_PC/unlock/XDA_IIs_unlock.php
Not sure what process they use, but looks the same.
-----------------------------------------
Then I also came across this interesting story: http://www.modaco.com/index.php?showtopic=200968
This guy writes (edited):
I happend across an official O2 email address that I sent an (abbreviated) SIM unlock request, briefly stating why I needed my XDA IIs to be SIM unlocked, and providing my O2 account number and the handset IMEI number. 30 minutes later and I was emailed back an unlock code.
No ifs, no buts, no questions asked and no payment required.
I placed my Orange SIM card in the IIs, waited for it to boot, entered the code and was greeted with "Unlock Code Accepted." Both dialling out and receiving calls on my Orange account no problemo.
...
Bearing the above in mind, I'm not going to directly post the email address, but will gladly pass it on via PM.
Click to expand...
Click to collapse
The interesting part here is that he only had to give his EMEI number, nothing else...and received an unlock code.
If you take the official route of unlocking your phone through your network provider, all they need is your IMEI number because they can calculate your unlock code from that.
I'm not 100% certain how the process works, but I'm fairly sure the algorithm they use to generate the unlock code is different for each handset manufacturer. I think the network provider either has to send your IMEI to the handset manufacturer for them to calculate the unlock code, or possibly the provider is given a database of unlock codes for all the handsets they purchase. This might explain why it sometimes takes them a few days or weeks to get back to you with the unlock code.
So figuring out how they convert the IMEI number to the unlock code would be another way to attack the problem. Although, I think it would probably be very difficult to figure out what hashing algorithm they're using to generate the code. But if it can be done, then it would certainly make things a hell of a lot easier!
-no1
SH*TE I have been writing a post for about half an hour now explaining the files and as soon as I logged in it was lost. :evil: :evil: :evil: :evil: :evil:
Anyways, here we go again. I am posting the files I promised yesterday. The are three JPEGs which are handwritten notes from the first time I run their application, and a log file from the second time I run the application. Here's the thing: the first time, the software send a read command for the addresses 0-10000 of the radio rom (rrbmc x 0 10000) and store in the x variable. Then it probably compared the checksum with their data, and it didn't match, so they deleted this part of the rom (rerase 0 10000) and they written their own version of it stored in a vector called data (rw data 0 10000). So far so good.
The second time I run the software, it sent again the rrbmc command but this time it didn't erase or written anything, so I guess it does actually what I said before with the checksum.
Another important remark:
The first time I run the software, the software requested some information from the device (rinfo) and the xda replied:
BlueAngel B120 C6B23C704A59520150993080051FF87B
After it finished writing, it sent the same command once more and this time the xda replied:
BlueAngel B120 C6 BE3A709999541E509810802FD775B0
Now the second time I run the application, the rinfo command returned:
BlueAngel B120 C6BC3C70B329B2B1509980809FE49B11
Can these be some form of HEX encryption keys or something?
Happygoat maybe you could use them in your nice proggies?
Anyhow, I think this is all for now. The commands in the logs should be straight forward to understand, it's just the data part which needs real decoding of some sort.
Hope it helps, regards Zouga
Zouga,
Thanks alot for the info...and your patience!
I downloaded a program called USB Monitor, which supposedly logs all data transferred via the USB port...is that the proggie you used as well?
What I want to do is run the IMEI-CHECK program on my device a few times in a row..since it was never SIMLOCKED, I wonder what the output will be...and if they will be different.
I suggest other people run this software as well with a USB port logger, so we can compare logs, and perhaps figure out precisely what we need to do.
Regarding the encryption, I will have a look. I do not think that the data you gave me (C6BC3C70B329B2B1509980809FE49B11) is encrypted...looks like plain ol' HEX to me...will do some more research.
What I think would be the ultimate solution, is to develop an app that calculates the unlock code based upon IMEI number...easy to use, no workarounds, and something I understand: Encryption...
Yes, I am biased...but I am reading up on ass'y code right now to get my arms around this thing...so bare with me...
Hi HappyGoat,
It's good that finally you guys got interested in this! Yes it is the same piece of software I used to sniff the port, it would be interesting to see the output of your unlocked device. Could you please post it as soon as you have it? I hope we can crack this!!
Come on guys, don't just complain for the £20 charge, give us some help here!! We should all run the software and log the data to compare them, as HappyGoat suggested. Then we should all be HappyXdaUsers
Looking forward to some news,
Zouga
Zouga,
Can't download the zip file (bottom one) for some reason...reports that file can not be found...can you try again please?
Cheers,
HG
I have a lumia 800 with DLOAD so I cant flash a custom rom but I was wondering if it was possible to side load applications, Previously I used the windows phone and app hub on dreamspark but ive read its been axed.
Can anyone more familiar with the os point me in the direction of its replacement ? I have a verified dreamspark account and am aware of the 10 application limit
Well, the only method that I know that works it is developer unlock, wich allow you sideload until 10 apps (they must be signed). Look over Google for some tutorial.
I think it's 3 applications
I have made a tuto fro 10 apps, PM me
This tread is referring to a S7-721u version in Malaysia with Gr8 bundled pre-installed.
Unfortunately, I lost my Gr8 activation code and unable to login to the device anymore after a factory reset. After some research, I have managed to flash it with the original firmware. Yes, I lost me Gr8 code, so I don't have the access to the daily subscription anymore, but I got my Huawei Mediapad back without unwanted pre-installed apps.
I am sharing this guideline so that it would be easier for people who faced the same issue like me. For people already got your Huawei Mediapad, keep your Gr8 code safe and remember where you keep it.
Prepare an microSD card with any storage size larger than 1GB.
Format microSD card.
Download Huawei official release firmware (S7-721u, Android4.3, C232B008, General).
Unzip downloaded firmware.
Delete file “au_temp.cfg” in dload folder.
Copy dload folder with UPDATA.APP in it.
Paste dload folder in your microSD card.
Power Off Huawei Mediapad. Insert microSD card.
Press Power + volume up + volume down keys together. The phone automatically enters the upgrade mode, and then begin the upgrade. Release the keys.
Once the progress bar reaches 100%, the phone will automatically restart. DONE!
What is new version C232B008 or C264B001? My tablet is on C264B001.
mugy said:
What is new version C232B008 or C264B001? My tablet is on C264B001.
Click to expand...
Click to collapse
No idea. Sorry.
Deleting the au_temp.cfg.
sunnysardine said:
This tread is referring to a S7-721u version in Malaysia with Gr8 bundled pre-installed.
Unfortunately, I lost my Gr8 activation code and unable to login to the device anymore after a factory reset. After some research, I have managed to flash it with the original firmware. Yes, I lost me Gr8 code, so I don't have the access to the daily subscription anymore, but I got my Huawei Mediapad back without unwanted pre-installed apps.
I am sharing this guideline so that it would be easier for people who faced the same issue like me. For people already got your Huawei Mediapad, keep your Gr8 code safe and remember where you keep it.
Prepare an microSD card with any storage size larger than 1GB.
Format microSD card.
Download Huawei official release firmware (S7-721u, Android4.3, C232B008, General).
Unzip downloaded firmware.
Delete file “au_temp.cfg” in dload folder.
Copy dload folder with UPDATA.APP in it.
Paste dload folder in your microSD card.
Power Off Huawei Mediapad. Insert microSD card.
Press Power + volume up + volume down keys together. The phone automatically enters the upgrade mode, and then begin the upgrade. Release the keys.
Once the progress bar reaches 100%, the phone will automatically restart. DONE!
Click to expand...
Click to collapse
How important is it to delete that file. Is that the reason why when i install the update it says "update.app is a invalid package"? Thanks mate.
Hi. I just reinstall the software, but how do I get back my e papers subscriptions?
Is there any costum rom, and i have this tablet locked on one network ,is there a solution to run other network.thanks in advance.
I did all as you said, but now my tablet is completely dead.
Thanks it worked.
Provide the download link for the firmware please?
Thx Sunnysardine, it works for me.
Just to add a bit for my experience.
The process 1 - 8 MUST be followed exactly. I tried putting the update.app w/o the load folder, it did not work
For process 10, it takes a bit of time. the Huawei logo showed up for quite long before it power up to 1st screen. after that, all well. So got to be patient a little bit
Thanks man
I followed ur instructions exactly and it works, nice
If not for this, I would have thrown away my mediapad, it totally not login-able/ unusable without Gr8 code
Thanks again!
it is work for me.. thanks for sharing
Hi there, I found a way to remove GR8 app without installing the update. I found out that due to the device cannot detect the update in my sd card.
1) turn on the Huawei media pad s7-721u, unlock the screen
2) plug in to computer/laptop windows 7,8 or windows 10
3) on the Huawei media pad screen, it will pop up usb setting, select hiSuite usb type option
4) at the andoid setting, please go to about table setting, then enable developer mode by taping 7 times at Build number
5) still at android setting, go to security, make sure your android Screen lock setting is set under Huawei unlock,the go to shortcut setting, need to set to google app and android setting app.
6) install HiSuite to your computer - this is the Huawei official computer device managed software tool
7) install iRoot software to your computer. careful with this installation, it full of bloatware, but don't worry it don't have a virus.
8) run the iRoot and it will root your device. It will restart your Huawei pad multiple times.
9) after it root complete, unlock your device then go to google play ( as your android unlock setting option have the google play as describe in step 5)
10) install System app remover from google play
11) open the app, go to inside the app setting, remove setting Hide core system app
12) go to the main menu of the app remover, under manager, select system app, now you can find gr8 gallery app. Removed that app then restart the device.
13) you will have multiple error in android, just reboot and the error gone. DONE
This is where you can download the firmware
[email protected]@/download/downloadCenter?downloadId=27805&version=51115&siteCode=pk
Wrong Firmware
sunnysardine said:
This tread is referring to a S7-721u version in Malaysia with Gr8 bundled pre-installed.
Unfortunately, I lost my Gr8 activation code and unable to login to the device anymore after a factory reset. After some research, I have managed to flash it with the original firmware. Yes, I lost me Gr8 code, so I don't have the access to the daily subscription anymore, but I got my Huawei Mediapad back without unwanted pre-installed apps.
I am sharing this guideline so that it would be easier for people who faced the same issue like me. For people already got your Huawei Mediapad, keep your Gr8 code safe and remember where you keep it.
Prepare an microSD card with any storage size larger than 1GB.
Format microSD card.
Download Huawei official release firmware (S7-721u, Android4.3, C232B008, General).
Unzip downloaded firmware.
Delete file “au_temp.cfg” in dload folder.
Copy dload folder with UPDATA.APP in it.
Paste dload folder in your microSD card.
Power Off Huawei Mediapad. Insert microSD card.
Press Power + volume up + volume down keys together. The phone automatically enters the upgrade mode, and then begin the upgrade. Release the keys.
Once the progress bar reaches 100%, the phone will automatically restart. DONE!
Click to expand...
Click to collapse
How can I fix the tablet after being flashed with wrong firmware?
It doesn't turn on and in QPST or QFIL it was in download mode.
I have correct firmware and its dump.
vcREG is a registry editor for lumia windows phones that has SYSTEM level access to the registry. the tool also has the ability to unlock all app capabilities for third party apps(interop unlock), and give SYSTEM level access to most of the filesystem through MTP.
new in version 1.7: thanks to @gus33000 for pointing out some registry values set for the interop unlock that may cause versions of rs1+ to break compatibility with WP8 apps. this has been fixed. For interop unlock, i suggest you use @gus33000 Interop Tools as his tool is more likely to have better support for changes in the future, as i am too bogged down with other projects.
thanks to @Wack0Distractor for sharing the idea and the acer service that makes this unlock for the X50 series phones possible. also thanks to @ngame for providing the test devices and the many hours of debugging, and @djamol for the main reason any of these unlocks are possible.
Instructions for X50 series phones like the 550,950/XL
ndtk_acer_services.zip uploaded below contains acer.service.acersystemservice.spkg, NdtkSvc.dll, and newndtksvc.dll.
1.Go to settings and turn on developer mode.
2a. For APPX version, download vcregUWP_1.7+dependencies.zip,unzip, install dependencies, then install the vcreg appx
2b. For XAP version, Sideload vcREG_1_7.xap using
WP8 xap deployer
C:\Program Files (x86)\Microsoft SDKs\Windows Phone\v8.0\Tools\XAP Deployment\Xapdeploy.exe
or
WP Power Tools
https://wptools.codeplex.com/
3.Go to the app bar, then choose x50 series unlock. You will receive an error about the acer service not running. That's ok for now. Click step 1 and it will tell you to install the acer system service and copy some files. To install the acer system service, use iutool [rs and newer builds,this version is essential,old versions will probably not work] (can be found here. thanks @Wack0Distractor ).
run this command as administrator
iutool -v -p "path to the file acer.service.acersystemservice.spkg"
if you receive error 0x80070490, disconnect your phone from usb, go to control panel on your pc, devices and printers, find your windows phone and remove device. reconnect the usb to your phone,and after it reinstalls the drivers automatically, run iutool command above again.
if you receive error 0x8024a110, your phone should reboot to the gears UI in a minute. if not, run the command again. if it still doesnt auto reboot, manually reboot your phone. It should reboot into the gears UI, then back into the OS. if it still fails and doest show gears, give you phone a rest for 5-10 minutes and retry(usually needed after a new rom flash).
4.When you're back in the phone OS, copy newndtksvc.dll and ndtksvc.dll to your documents folder on your phone through USB
5.Go to the app bar, then choose x50 series unlock. You should no longer receive the error about the acer service. Now click step 2 and follow the rest of the instructions from the app.
6.If you've taken the silent extras/advanced+info update, or updated that app manually, be sure to choose the option "Restore NDTK 950/XL" in the "x50 series unlock" page and reboot to regain access to the elevated features. It basically means if it suddenly stops working, apply this setting.
Instructions for older devices
1.Go to settings and turn on developer mode.
2a. For APPX version, download vcregUWP_1.7+dependencies.zip,unzip, install dependencies, then install the vcreg appx
2b. For XAP version, Sideload vcREG_1_7.xap using
WP8 xap deployer
C:\Program Files (x86)\Microsoft SDKs\Windows Phone\v8.0\Tools\XAP Deployment\Xapdeploy.exe
or
WP Power Tools
https://wptools.codeplex.com/
3.Go to the app bar, then choose classic unlock
3.If you've taken the silent extras+info update, or updated that app manually, be sure to choose the option "Restore NDTK" in the "classic unlock" page and reboot to regain access to the elevated features. It basically means if it suddenly stops working, apply this setting.
@vcfan thanks for mention
Not bad to add this that Our New hack for X50 series tested on both RS1 and TH2 (10586.107 to 14393.67) and these OS Versions are tested and supported Thanks for you and @djamol's hard work and other guys who helped in this hack .
Also here is a video that show you I added work with gloves on my 950XL to my phone and it work and etc.
http://www.aparat.com/v/HoCbk
Sorry for my bad English
Guys Do not TRY Full FILESYSTEM ACCESS ON X50 Series .
If you want to Change your X50/XL device font please try this app :
http://forum.xda-developers.com/showpost.php?p=68465197&postcount=46
Universal Interop Unlock is Coming :
http://forum.xda-developers.com/showpost.php?p=68467581&postcount=56
Wow, wow, wow! Great news! Thank you guys, @vcfan and @djamol, and @ngame and all guys who worked on this hack! xda rulez!
Awesome job! Any chance we can get some documentation on the methods?
G.moe said:
Awesome job! Any chance we can get some documentation on the methods?
Click to expand...
Click to collapse
@G.moe, what kind of documentation are you looking for? Have you tried to press large gray buttons saying "CLICK TO SHOW CONTENT" at @vcfan post? :laugh:
Or you are looking for the source code and hack method concept? Use reflector or any other .net disasms to get the app's sources
Thanks works fine.
I have trying MTP and now 950 XL charging only on PC.
Someone have original values in registry?
titi66200 said:
Thanks works fine.
I have trying MTP and now 950 XL charging only on PC.
Someone have original values in registry?
Click to expand...
Click to collapse
Guys in the video I recorded I tell do not try mtp hack it won't work also sftp doesn't work at least for me. If we can handle it at last we let you know.
Only concentrate on Interop and capability unlock and public registry hacks.
Also you can add work with gloves and double tap to your devices .
We are still working on many things to handle
i still try to get "gears" :crying:
tried few times...
dxdy said:
i still try to get "gears" :crying:
tried few times...
Click to expand...
Click to collapse
After Hard reset, Same for me
titi66200 said:
After Hard reset, Same for me
Click to expand...
Click to collapse
my 950XL have 14393.67 and also make HR two weeks ago...
SUPER GREAT !!!! WORKS LIKE A CHARM !!!
Many many many thanks..
works on Microsoft Lumia 950XL - RM-1085 -059X4X5
only MTP / full filesystem does not work but as i understand they are busy with it
vcfan said:
vcREG is a registry editor for lumia windows phones that has SYSTEM level access to the registry. the tool also has the ability to unlock all app capabilities for third party apps(interop unlock), and give SYSTEM level access to most of the filesystem through MTP.
thanks to @Wack0Distractor for sharing the idea and the acer service that makes this unlock for the X50 series phones possible. also thanks to @ngame for providing the test devices and the many hours of debugging, and @djamol for the main reason any of these unlocks are possible.
Instructions for X50 series phones like the 550,950/XL
1.Go to settings and turn on developer mode.
2.Sideload vcREG_1_6_W10.xap using
WP8 xap deployer
C:\Program Files (x86)\Microsoft SDKs\Windows Phone\v8.0\Tools\XAP Deployment\Xapdeploy.exe
or
WP Power Tools
https://wptools.codeplex.com/
3.Go to the app bar, then choose x50 series unlock. You will receive an error about the acer service not running. That's ok for now. Click step 1 and it will tell you to install the acer system service and copy some files. To install the acer system service, use iutool (can be found here. thanks @souma_rox).
run this command as administrator
iutool -v -p "path to the file acer.service.acersystemservice.spkg"
if you receive error 0x80070490, disconnect your phone from usb, go to control panel on your pc, devices and printers, find your windows phone and remove device. reconnect the usb to your phone,and after it reinstalls the drivers automatically, run iutool command above again.
if you receive error 0x8024a110, thats ok. your phone should reboot to the gears UI in a minute. if not, run the command again. if it still doesnt auto reboot, manually reboot your phone. It should reboot into the gears UI, then back into the OS. if it still fails, give you phone a rest for 5-10 minutes and retry(usually needed after a new rom flash).
4.When you're back in the phone OS, copy newndtksvc.dll and ndtksvc.dll to your documents folder on your phone through USB
5.Go to the app bar, then choose x50 series unlock. You should no longer receive the error about the acer service. Now click step 2 and follow the rest of the instructions from the app.
6.If you've taken the silent extras/advanced+info update, or updated that app manually, be sure to choose the option "Restore NDTK 950/XL" in the "x50 series unlock" page and reboot to regain access to the elevated features. It basically means if it suddenly stops working, apply this setting.
Instructions for older devices
1.Go to settings and turn on developer mode.
2.Sideload vcREG_1_6_W10.xap using
WP8 xap deployer
C:\Program Files (x86)\Microsoft SDKs\Windows Phone\v8.0\Tools\XAP Deployment\Xapdeploy.exe
or
WP Power Tools
https://wptools.codeplex.com/
3.Go to the app bar, then choose classic unlock
3.If you've taken the silent extras+info update, or updated that app manually, be sure to choose the option "Restore NDTK" in the "classic unlock" page and reboot to regain access to the elevated features. It basically means if it suddenly stops working, apply this setting.
Click to expand...
Click to collapse
dxdy said:
i still try to get "gears" :crying:
tried few times...
Click to expand...
Click to collapse
Double check this registry value using CustomPFD
HKLM\System\Platform\DeviceTargetingInfo
PhoneManufacturer
It must be in type (String) and it's value should be ACERINC to be able to deploy acer spkg.
If it's not you didn't do Step1 of VCreg correctly .
OK.
If you get 0x8024a110, you're probably on 14393 / anniversary update / Redstone1/whatever.
If so, you NEED to use iutool from the 14393 WDK. No ifs, no buts. Use that or you WILL get that error.
Here's a download of just the WP-tools (iutool, getdulogs, ffu creation etc etc) direct from MS: https://download.microsoft.com/down...5524A95/wdk/Installers/WP_CPTT_NT-x86-fre.msi
Mirrored it here just in case.
Works again for me.
I am stupid because "acer.service.acersystemservice.spkg" still installed after H.R.
titi66200 said:
Works again for me.
I am stupid because "acer.service.acersystemservice.spkg" still installed after H.R.
Click to expand...
Click to collapse
OH Yes guys . Good to say
After Hard reset you do not need to do many reboots because our ndtksvc is place in system32 (it didn't gone)
So you only need to go to x50 series page and check Live interop/cap unlock and apply it . that's it .
ngame said:
Double check this registry value using CustomPFD
HKLM\System\Platform\DeviceTargetingInfo
PhoneManufacturer
It must be in type (String) and it's value should be ACERINC to be able to deploy acer spkg.
If it's not you didn't do Step1 of VCreg correctly .
Click to expand...
Click to collapse
yes, ACERINC is there but still no luck...
---------- Post added at 02:11 PM ---------- Previous post was at 02:03 PM ----------
Wack0Distractor said:
OK.
If you get 0x8024a110, you're probably on 14393 / anniversary update / Redstone1/whatever.
If so, you NEED to use iutool from the 14393 WDK. No ifs, no buts. Use that or you WILL get that error.
Here's a download of just the WP-tools (iutool, getdulogs, ffu creation etc etc) direct from MS: https://download.microsoft.com/down...5524A95/wdk/Installers/WP_CPTT_NT-x86-fre.msi
Mirrored it here just in case.
Click to expand...
Click to collapse
installed and run iutool and now get gears!!!! thanks!!!
p.s.
interop is applied but.. still no use of AppDataManageTool or Adblock tool???
Great work!
Random question, probably a dumb one, but does this work on the M8FW? Or is it dependent on a x50 device exploit? Cause maybe I'm reading this wrong but it seems kinda universal
Thanks A lot!!!!
@dxdy
"Adblock tool" use "Nokia.SilentInstaller.Runtime" who seems not working on x50.
AlvinPhilemon said:
Great work!
Random question, probably a dumb one, but does this work on the M8FW? Or is it dependent on a x50 device exploit? Cause maybe I'm reading this wrong but it seems kinda universal
Click to expand...
Click to collapse
It's not intended for non-Microsoft/Nokia devices. NdtkSvc.dll is Nokia/Microsoft specific.....
Interested in pulling all the data off of a Pixel XL that has a broken screen. It lights up in some places, but doesn't respond to touch. The fingerprint on the back responds but since the phone has been restarted, it requires a keypin. I have all google cloud/backup services disabled.
Is there a way I can manipulate the screen with a dev kit or other software while it's connected to my PC? I know the pin, obviously, but I can't enter it to enable file transfer for USB.
Thanks
@garrisonxci
If ADB ( read: USB debugging ) is enabled on phone, then several PC tools are available to bypass and/or even remove FRP lock via ADB, e.g TenorShare 4ukey.
jwoegerbauer said:
@garrisonxci
If ADB ( read: USB debugging ) is enabled on phone, then several PC tools are available to bypass and/or even remove FRP lock via ADB, e.g TenorShare 4ukey.
Click to expand...
Click to collapse
4ukey deletes all data from the device, that doesn't help at all but I appreciate your reply.
garrisonxci said:
Interested in pulling all the data off of a Pixel XL that has a broken screen. It lights up in some places, but doesn't respond to touch. The fingerprint on the back responds but since the phone has been restarted, it requires a keypin. I have all google cloud/backup services disabled.
Is there a way I can manipulate the screen with a dev kit or other software while it's connected to my PC? I know the pin, obviously, but I can't enter it to enable file transfer for USB.
Thanks
Click to expand...
Click to collapse
I've heard of the apps called "Broken Android Data Extraction"
I think it made for recover the data of the broken android phone. Hope this one will help!
Techguy455 said:
I've heard of the apps called "Broken Android Data Extraction"
I think it made for recover the data of the broken android phone. Hope this one will help!
Click to expand...
Click to collapse
This is for Samsung phones only and it costs money. This doesn't help either, but thanks for your reply
b u m p
Actually you would need to disassemble the device and to a JTAG to the eMMC. It does cost money to get everything and some skill is required as it's no easy task. Any other method may be troublesome trying to retrieve data