Сообщение от
kos
WARNING, THIS MIGHT DAMAGE YOUR PHONE...
it did not damaged 3 phones that i tested though, so it's worth a shot
1. read locked 6630 pm fields 0-309 (not 0-255), save this as backup.
2. read locked 6630 pm field 308, save this as quick simlock backup.
3. read non-locked 6630 pm field 308,
4. write non-locked pm 308 file to locked 6630 phone
5. do not turn on the phone yet, run phoenix, connect phone and turn it on
6. quickly make a product scan, then go to Testing --> SIM Lock Status Test
7. click read surprised?
*** at this point, phone might display "Phone Start-Up Failed, Contact..."
but wait...
8. disconnect phone and put battery and turn it on
*** at this point, Contact retailer message is gone...
9. remove battery then connect it to phoenix again
10. read simlock status again... ;-( you knew it was too good to be true...
*** AVOID making factory resets and system formats...
to revive phone, just write old pm field 308.
after a few test with different pm 308 from different phone, the locked
phone might no longer go back to it's original lock status even after
writing it's original pm 308 backup... for this you will need to write the
whole pm backup 0-308... and start all over again with your testing.
warning, overtesting might result to a lock status of FFFFFFFFFFF,,,
i tried upto 8 times and the phone is still ok... for now
this test implies that it "might" be possible to unlock bb5 phones via
modifying pm field 308... of course this means you need to analyze
more than 4000 bytes of the 308 field... which is like finding a needle
in a hay stack the size of jupiter.
Вот такую пишут инфу, давайте попробуем разобраться