***************
*13-08-2009* Next Bulk Update, *RAPU-YAMA* supported for *FBUS Flash*
- Introduced support for FBUS Flashing RAPU YAMA phones (*5630, 6700, 6303*)
- GUI Stability improved ; updated Skins Stack
- Fixed Algoboot for BB5 phones in some configurations
- SingleLine BB5 Flashing Speed improved (upgraded to 5.5mbits from 4mbits)
- BB5 Multi-CRT Write bug fixed (mismatched certs when writing more than 1 certs at one time)
- Improved Phone LOCAL/TEST Mode Entry algorithms during unlock and FBUS operatinos
- Access Violation in some configurations, when changing BB5 Vpl / Dct4 Vpl Variant/Product - fixed
- "Set factory defaults - BB5" are now default unticked after flash (useless in case of BB5 phones)
- Repower on boot inverted ; accoring to firmware v1.0.5 , BB5 Phones are now default re-powered on boot
- By default - USE DEFAULT PROFILE while unlocking DCT4Plus is unticked
- DCT4Plus unlock routines rewritten - patch file is now applied before unlocking
- Fixed problems upon unlocking some units of DCT4(plus) phones, when Initial SP Area is corrupted
- When SIMLOCK IS NOT ACCEPTED during BB5 RPL Write, software trying to write FBUS part again after FLASHBUS part, so if NPC is corrupted, the SL will be restored anyway
- Please don't use "Erase Security" function when writing BB5 PA_SL2 RPL, because SIMLOCK will not be accepted in such case! In order of simlock rebuild, NPC MUST BE CORRECT!
- Improved BB5 RPL Write, when HWC can't be written (N96 - example), other certs being written and whole procedure is not being skipped
- After sending Simlock and Superdongle data, delay added, so PA_SL can recalculate SP and Recreate 308 if needed (previously it wasn't working all times)
- During BB5 Configuration Parse (flash chips, status), now RAM chip is displayed instead of UNKNOWN
- DCT4Plus Security Status is now being displayed upon unlock - either TAMPERED or NOT TAMPERED
- When DCT4Plus Security is NOT TAMPERED, Cyclone automatically makes Security Backup
- When user trying to unlock phone which have protected PM308 Security Block against modification, and there is message "Failed to write Security Block" software is now automaticlly writing back NPC backup - IMEI
- Erase Security while writing RPL is now by default disabled
- SX4 Bypass during PA_SL2 unlock is now by default disabled
- IMEI 1234567890?, and "?" is not valid integer bug fixed
- Cyclone Box HW Rev A113 support added
- Cyclone Box HW Rev A114 support added
- Cyclone Box HW Rev A115 support added
*Example 5630 RAPU Flashed:*
Scanning avaiable products...
Processing C:\Program Files\Nokia\Phoenix\Products\...
Processing C:\Program Files\Common Files\Nokia\DataPackage\Products\...
Found 114 products, Filtering BB5 Products - wait...
36 Products left after filtering. Ready.
Retrieving Variants for Product RM-431 - wait...
53 Variants Retrieved
Processing pre flash tasks...
Pre flash tasks finished, continuing...
Processing rm431_012.008_prd.core.fpsx (CMT)...
Booting RAP...
CMT_SYSTEM_ASIC_ID: 000000030000022600010007600C192102011104
CMT_EM_ASIC_ID: 00000C34
CMT_EM_ASIC_ID: 00000C30
CMT_PUBLIC_ID: 1CE001126A2F0344C02621363B888F748DD36748
CMT_ASIC_MODE_ID: 00
CMT_ROOT_KEY_HASH: 25B977A055BE9B5DEC0C38A2A279C695
CMT_ROM_ID: 3E273BF637BE26FA
rm431_012.008_prd.core.fpsx, Type: Flash Image, Algo: XSR 1.6, BB5
RAPUv11_2nd.fg, Type: 2nd Boot Loader, Rev: 0.1.37.1, Algo: BB5
Flashbus Write baud set to 650Kbits
Flashbus Read baud set to 98Kbits
FlashChip[0,CMT]: 0x00EC004000800121, Samsung, ONENAND
FlashContent[0,CMT]: 00000000000000000000000000000000, ONENAND
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
Transmission Mode Requested: Single Line, 8 bit, Accepted: Single Line, 8 bit
RAPUv11_algo_xsr16.fg, Type: Algorithm, Rev: 0.1.40.0, Algo: XSR 1.6
Flashbus Write baud set to 2.0Mbits
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
Box VPP disabled
Internal CMT Phone VPP Enabled
PAPUBKEYS Hash for CMT: 8B5237A1F5B38048C11FB4A6B04AE1CDD3C480E2
Flashbus Write baud set to 5.0Mbits
Sending Certificates...
Certificates OK
Partitioning...
Partitioning OK
Started group flash erase
EraseArea[0,CMT]: 0x00020000-0x0003FFFF, ONENAND
EraseArea[0,CMT]: 0x00060000-0x004DFFFF, ONENAND
EraseArea[0,CMT]: 0x008E0000-0x0A87FFFF, ONENAND
Erase Partition (CMT)
Waiting 320s for erasure finish...
Erase taken 0.922s
Writing all blocks...
Writing CMT ADA Certificate...
Writing CMT KEYS Certificate...
Writing CMT PRIMAPP Certificate...
Writing CMT RAP3NAND Certificate...
Writing CMT SOS+PMML Certificate...
Writing CMT PASUBTOC Certificate...
Writing CMT PAPUBKEYS Certificate...
Writing CMT GENIO_INIT Certificate...
Writing CMT SOS*UPDAPP Certificate...
Writing CMT SOS*DSP0 Certificate...
Writing CMT LDSP Certificate...
Writing CMT SOS*ISASW Certificate...
Writing CMT SOS+CORE Certificate...
Writing CMT SOS+ROFS1 Certificate...
Programming Status OK!
All blocks written OK! Time taken 107.469s
Restarting MCU...
Processing rm431_012.008_prd.core.fpsx (APE)...
Processing rm431_012.008_06.01_Euro3_prd.rofs2.fpsx (CMT)...
Booting RAP...
CMT_SYSTEM_ASIC_ID: 000000030000022600010007600C192102011104
CMT_EM_ASIC_ID: 00000C34
CMT_EM_ASIC_ID: 00000C30
CMT_PUBLIC_ID: 1CE001126A2F0344C02621363B888F748DD36748
CMT_ASIC_MODE_ID: 00
CMT_ROOT_KEY_HASH: 25B977A055BE9B5DEC0C38A2A279C695
CMT_ROM_ID: 3E273BF637BE26FA
rm431_012.008_06.01_Euro3_prd.rofs2.fpsx, Type: Flash Image, Algo: XSR 1.6, BB5
RAPUv11_2nd.fg, Type: 2nd Boot Loader, Rev: 0.1.37.1, Algo: BB5
Flashbus Write baud set to 650Kbits
Flashbus Read baud set to 98Kbits
FlashChip[0,CMT]: 0x00EC004000800121, Samsung, ONENAND
FlashContent[0,CMT]: 00000000000000000000000000000000, ONENAND
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
Transmission Mode Requested: Single Line, 8 bit, Accepted: Single Line, 8 bit
RAPUv11_algo_xsr16.fg, Type: Algorithm, Rev: 0.1.40.0, Algo: XSR 1.6
Flashbus Write baud set to 2.0Mbits
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
Box VPP disabled
Internal CMT Phone VPP Enabled
PAPUBKEYS Hash for CMT: 8B5237A1F5B38048C11FB4A6B04AE1CDD3C480E2
Flashbus Write baud set to 5.0Mbits
Started group flash erase
EraseArea[0,CMT]: 0x06480000-0x09A7FFFF, ONENAND
Waiting 320s for erasure finish...
Erase taken 0.297s
Writing all blocks...
Writing CMT SOS+ROFS2 Certificate...
Programming Status OK!
All blocks written OK! Time taken 57.484s
Restarting MCU...
Processing rm431_012.008_06.01_Euro3_prd.rofs2.fpsx (APE)...
Processing rm431_012.008_C03.01_BLUE_prd.rofs3.fpsx (CMT)...
Booting RAP...
CMT_SYSTEM_ASIC_ID: 000000030000022600010007600C192102011104
CMT_EM_ASIC_ID: 00000C34
CMT_EM_ASIC_ID: 00000C30
CMT_PUBLIC_ID: 1CE001126A2F0344C02621363B888F748DD36748
CMT_ASIC_MODE_ID: 00
CMT_ROOT_KEY_HASH: 25B977A055BE9B5DEC0C38A2A279C695
CMT_ROM_ID: 3E273BF637BE26FA
rm431_012.008_C03.01_BLUE_prd.rofs3.fpsx, Type: Flash Image, Algo: XSR 1.6, BB5
RAPUv11_2nd.fg, Type: 2nd Boot Loader, Rev: 0.1.37.1, Algo: BB5
Flashbus Write baud set to 650Kbits
Flashbus Read baud set to 98Kbits
FlashChip[0,CMT]: 0x00EC004000800121, Samsung, ONENAND
FlashContent[0,CMT]: 00000000000000000000000000000000, ONENAND
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
Transmission Mode Requested: Single Line, 8 bit, Accepted: Single Line, 8 bit
RAPUv11_algo_xsr16.fg, Type: Algorithm, Rev: 0.1.40.0, Algo: XSR 1.6
Flashbus Write baud set to 2.0Mbits
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
Box VPP disabled
Internal CMT Phone VPP Enabled
PAPUBKEYS Hash for CMT: 8B5237A1F5B38048C11FB4A6B04AE1CDD3C480E2
Flashbus Write baud set to 5.0Mbits
Started group flash erase
EraseArea[0,CMT]: 0x09A80000-0x0A87FFFF, ONENAND
Waiting 320s for erasure finish...
Erase taken 0.79s
Writing all blocks...
Writing CMT SOS+ROFS3 Certificate...
Programming Status OK!
All blocks written OK! Time taken 4.953s
Restarting MCU...
Processing rm431_012.008_C03.01_BLUE_prd.rofs3.fpsx (APE)...
Processing rm431_012.008_U000.000_prd.uda.fpsx (CMT)...
Booting RAP...
CMT_SYSTEM_ASIC_ID: 000000030000022600010007600C192102011104
CMT_EM_ASIC_ID: 00000C34
CMT_EM_ASIC_ID: 00000C30
CMT_PUBLIC_ID: 1CE001126A2F0344C02621363B888F748DD36748
CMT_ASIC_MODE_ID: 00
CMT_ROOT_KEY_HASH: 25B977A055BE9B5DEC0C38A2A279C695
CMT_ROM_ID: 3E273BF637BE26FA
rm431_012.008_U000.000_prd.uda.fpsx, Type: Flash Image, Algo: XSR 1.6, BB5
RAPUv11_2nd.fg, Type: 2nd Boot Loader, Rev: 0.1.37.1, Algo: BB5
Flashbus Write baud set to 650Kbits
Flashbus Read baud set to 98Kbits
FlashChip[0,CMT]: 0x00EC004000800121, Samsung, ONENAND
FlashContent[0,CMT]: 00000000000000000000000000000000, ONENAND
FlashChip[0,CMT]: 0xFFFF000000000000, Unknown, MMC
Transmission Mode Requested: Single Line, 8 bit, Accepted: Single Line, 8 bit
RAPUv11_algo_xsr16.fg, Type: Algorithm, Rev: 0.1.40.0, Algo: XSR 1.6
Flashbus Write baud set to 2.0Mbits
Transmission Mode Requested: Dual Line, 32 bit, Accepted: Dual Line, 32 bit
Box TX2 Data Pin set to: Service Pin 3
Box VPP disabled
Internal CMT Phone VPP Enabled
PAPUBKEYS Hash for CMT: 8B5237A1F5B38048C11FB4A6B04AE1CDD3C480E2
Flashbus Write baud set to 5.0Mbits
Started group flash erase
EraseArea[0,CMT]: 0x0A880000-0x0F63FFFF, ONENAND
Waiting 320s for erasure finish...
Erase taken 0.421s
Writing all blocks...
Programming Status OK!
All blocks written OK! Time taken 13.688s
Restarting MCU...
Processing rm431_012.008_U000.000_prd.uda.fpsx (APE)...
All images processed OK! Processing post flash tasks...
Reading info...
MCU Version V ICPR82_09w24.1
MCU Date 15-06-09
Product RM-431
Manufacturer (c) Nokia
IMEI 359350021136722
Mastercode 3226214523
IMEI Spare 3A95530012317602
IMEI SV 3395530012317632F1000000
PSN CKN036964
Product Code 0564244
Basic Product Code 0559784
PSD 0000000000000000
LPSN 0
WLAN MAC 0025CFDD214E
APE SW 012.008
APE Variant 012.008012.008.06.01012.008.C03.01
APE Test rm431_2009wk10v0.010
APE HW 256
APE ADSP 256
RETU 34
TAHVO 00
AHNE 11
HW 0417
RFIC |Vapaus_5.1 | ???
DSP ICPR82_09w24_RIO
Simlock Server SIMLOCK SERVER
Simlock Key 2440700000000000
Simlock Profile 0000000000000000
Simlock Key Cnt 0
Simlock FBUS Cnt 0
Simlock [1,1] State: OPENED Type: MCC-MNC Data: FFFFFF
Simlock [1,2] State: OPENED Type: GID Data: FFFF
Simlock [1,3] State: OPENED Type: GID Data: FFFF
Simlock [1,4] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Simlock [1,5] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Simlock [2,1] State: OPENED Type: MCC-MNC Data: FFFFFF
Simlock [2,2] State: OPENED Type: GID Data: FFFF
Simlock [2,3] State: OPENED Type: GID Data: FFFF
Simlock [2,4] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Simlock [2,5] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Simlock [3,1] State: OPENED Type: MCC-MNC Data: FFFFFF
Simlock [3,2] State: OPENED Type: GID Data: FFFF
Simlock [3,3] State: OPENED Type: GID Data: FFFF
Simlock [3,4] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Simlock [3,5] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Simlock [4,1] State: OPENED Type: MCC-MNC Data: FFFFFF
Simlock [4,2] State: OPENED Type: GID Data: FFFF
Simlock [4,3] State: OPENED Type: GID Data: FFFF
Simlock [4,4] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Simlock [4,5] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Simlock [5,1] State: OPENED Type: MCC-MNC Data: FFFFFF
Simlock [5,2] State: OPENED Type: GID Data: FFFF
Simlock [5,3] State: OPENED Type: GID Data: FFFF
Simlock [5,4] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Simlock [5,5] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Simlock [6,1] State: OPENED Type: MCC-MNC Data: FFFFFF
Simlock [6,2] State: OPENED Type: GID Data: FFFF
Simlock [6,3] State: OPENED Type: GID Data: FFFF
Simlock [6,4] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Simlock [6,5] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Simlock [7,1] State: OPENED Type: MCC-MNC Data: FFFFFF
Simlock [7,2] State: OPENED Type: GID Data: FFFF
Simlock [7,3] State: OPENED Type: GID Data: FFFF
Simlock [7,4] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Simlock [7,5] State: OPENED Type: IMSI Data: FFFFFFFFFFFFFFFF
Read info thread finished, continuing...
Post flash tasks finished!
Flashing successfully finished!
---------
*Note on flashing RAPU units:* make sure you obtained CORRECT FBUS CABLE! UFC No.2 (As we tested) NOT working with RAPU phones, because MBUS line is duplicated. We recommend to use GPG FBUS cables, as we done our tests using their cables.
*This is BULK UPDATE, that means* you need to download EXE file and click INSTALL. All previously released updates (few days before, rapido nck calc, etc) will be applied automaticlly, loaders will be purged too. You need have only installed installer (this one released in May, avaiable in http://www.cyclonebox.com/downloads/CycloneBoxInstaller.exe
*Download new update from:* http://rapidshare.com/files/267002877/CycloneBulkUpdate13082009.exe
Источник: http://forum.gsmhosting.com/vbb/showthread.php?p=4745815#post4745815
***************
Bulk update 11-09-2009 for Cyclone Box is READY.
Added support for unlock/relock/autolock of DCT4+ Asic 3168 phones, supported models/versions for now:
7100s RM-438 v5.22
7100s RM-438 v5.41
7100s RM-438 v6.31
2330c RM-512 v6.46
2330c RM-512 v6.75
2323c RM-543 v8.20
2323c RM-543 v6.75
2323c RM-543 v6.46
2630 RM-298 v57.20
2720 RM-519 v8.20
Not supported model/version of ASIC3168 phone here? Send us MCU File and we will update it !
Unlocking is FREE.
It is FIRST standalone solution (without usage of internet).
Before usage it is very important to UPGRADE YOUR BOX FIRMWARE (to version 1.07).
However, we added new service called "Super DCT4" inside a box.
To unlock ASIC 3168 phones, your box needs be "Super DCT4" activated (this will also let you change DCT4/plus IMEI in future).
The activations is done automaticlly in "Credits" tab and cost 50 credits - keep note that with box, comes 100 credits that mean if you haven't spend all logs on DCT4 RPLs, activation is FREE.
Download link: http://rapidshare.com/files/278378463/CycloneBulkUpdate11092009.exe
Best Regards,
Cyclone Team.
Installer v1.03 02.01.2010
=====================
- Добавлен новый метод Разблокировки/Блокировки/Автоблокировки/Восстановления BB5 телефонов с помощью генерации RPL. Процедура использует сервер и стоит 10 кредитов (требуется наличие на аккаунте Вашего Cyclone Box как минимум 100 кредитов).
- Поддерживаются ВСЕ телефоны PA_SL2 (как RAPv3 так и RAPIDO) со следующими хэш:
9A28E119033B91D14D22838C86D0D53C
9DDBFCFE6E73CED7D8C6268C8EB85723
38F312750F686F9FC9B1B3778774A195
BAF3A9C3DBFA8454937DB77F2B8852B1
CAEEBB65D3C48E6DC73B49DC5063A2EE
F2D76DFAFD66C7F195F278417DF05888
F682624FFB08F6D955DBE7D9C0485084
FCB5C510AF7F09F313D9BDE85A707CC0
- Перед разблокировкой программа уточнит (когда это возможно) нужно ли рассчитывать RPL. Если не требуется разблокировка с помощью RPL, просто нажмите No и будет использоваться старый бесплатный способ разблокировки (пересчет PM308+120, дамп Secure RAM и расчет NCK на телефонах RAPIDO PA_SL2, и т.д.) Однако имеются телефоны, которые можно разблокировать только новым способом (9DDB - 3600,5220,7310, или новые 5800 >v.30, новые N96, и т.д.)
- После разблокировки требуемый RPL файл сохраняется в папке STORED FILES, он может использоваться в дальнейшем после стирания телефона как и обычная бэкап
- Для Автоблокировки/Блокировки используйте функцию "Import SL5" и укажите файл SL5-массива в папке "UnlockData". В программу включено несколько рассчитанных файлов
- Если Вам нужен SL5 файл для вашей сети, нажмите кнопку "Create SL5" и введите MCC-MNC, будет сгенерирован файл SL5 и вы сможете заблокировать телефон
- Для SL2 телефонов может быть восстановлена SL область с помощью кнопки UNLOCK
- Исправлена ошибка записи RPL ("simlock not accepted" после нескольких попыток)
- Исправлена проблема пути "/"
- Менеджер памяти обновлен до версии v4.94
- Представлен новый менеджер скинов (6.53) - исправлена ошибка выбора flash-файлов
- Незначительно переработан GUI
- Nokia Connectivity Cable Driver обновлен до версии v7.1.22
- Добавлена Разблокировка/Блокировка 2760h RM-391 v06.83
- Добавлена Разблокировка/Блокировка 2330c RM-512 v09.55
- Добавлена Разблокировка/Блокировка 2330c-b RM-513 v09.55
- Добавлена Разблокировка/Блокировка 2720f RM-519 v08.42
- Добавлена Разблокировка/Блокировка 2720f-b RM-519 v08.42
- Добавлена Разблокировка/Блокировка 2720f RM-519 v09.55
- Добавлена Разблокировка/Блокировка 2720f-b RM-519 v09.55
- Во время разблокировки BB5 больше не используется обход SX4
- Исправлено зависание стека USB на некоторых конфигурациях Windows из-за неверных hex-кодов
- После Super DCT4 активации во вкладке Кредиты страница безопасности обновляется автоматически, не нужно делать вручную
- Представлена новая прошивка v01.15 - бокс может сам переключатся из режима MAIN в BOOT (не требуется USB переподключение)
- Исправлен бутинг 6220c,3600s на новых прошивках
- Представлен новый Secure bootloader v02.10
- Новый бутлоадер поддерживает больше типов смарт-карт (autobaud, PTS protocol negotiation, и т.д.)
- В новой прошивке представлен Secure BootAgent v1.00
- Прошивка RTOS Code обновлена до версии v6.0.1
- В новой прошивке немного оптимизирован код и повышена стабильность
- Обновление Secure Bootloader вводится после обслуживания бокса (box maintenance)
- Добавлена поддержка следующих ревизий Cyclone box HW: A116, A117, A118, A119, A11A, A11B, A11C
Благодарим kragel за перевод опубликованый на MCRF http://www.mcrf.ru/forum/showpost.php?p=190817&postcount=42