Sunday, November 4, 2007

List of models

Hello again,

It looks like there's a quick-fix from Nokia to prevent installer modification of E90 07.40.1.2 firmware. I guess it's no longer reading swipolicy.ini even though the file is there, but instead has hardcoded the capabilities somewhere - inside the exe perhaps? The image though is still modifiable, no real protection there.

And since Nokia says "most recent phones are not affected", I though I'd list a few models where I have somewhat reliable confirmation of successful modifications. If you have more results, please post comments with version numbers.

E50
E60
E61
E65
E90 (07.24.0.3, on 07.40.1.2 swipolicy not used?)
N71
N73
N76
N80

My own feeling about "devices affected" is that all the devices can be modified, but it's a bit difficult to prove it without the devices. Bricking the device is also easy, if you don't check the results of your modifications. And using pop-port, it's easy to brick even with standard updates =)

Labels: ,

21 Comments:

Anonymous Anonymous said...

I Succeed on N73

Any one Succeed on N95?

November 04, 2007  
Anonymous Anonymous said...

My E50 version was 0736. And yes.. could you please give short instructions of creating FExplorer seflsigned sis. I am too noob :)

http://www.gosymbian.com/FE_beta_download_3ed.html

November 05, 2007  
Anonymous Anonymous said...

Ok.. I set AllowUnsigned and installed FExplorer... this give me more power :)

November 05, 2007  
Anonymous Anonymous said...

Here goes FExplorer .pkg file
----------------------------
;Languages
&EN

; Installation header
#{"fexplorer"},(0xa00012df),1,0,0

%{"Vendor-EN"}
:"Vendor"

; Unique Vendor name
:"Vendor"

;Supports Series 60 v 3.0
[0x101F7961], 0, 0, 0, {"S60ProductID"}

"sys\bin\FExplorer.exe"-"!:\sys\bin\FExplorer.exe"
"private\10003a3f\import\apps\FExplorer_reg.rsc"-"!:\private\10003a3f\import\apps\FExplorer_reg.rsc"
"resource\apps\FExplorer_reg.mif"-"!:\resource\apps\FExplorer_reg.mif"
"resource\apps\FExplorer.rSC"-"!:\resource\apps\FExplorer.rSC"
"private\a00012df\FExplorer.mbm"-"!:\private\a00012df\FExplorer.mbm"
"private\a00012df\FEapp.ini"-"!:\private\a00012df\FEapp.ini"
"private\a00012df\FEftp.ini"-"!:\private\a00012df\FEftp.ini"
"private\a00012df\FEgen.ini"-"!:\private\a00012df\FEgen.ini"
"private\a00012df\settings.loc"-"!:\private\a00012df\settings.loc"

November 06, 2007  
Blogger [wl] said...

how about e61i?

November 11, 2007  
Anonymous Anonymous said...

I Succeed on E61i

November 16, 2007  
Anonymous SteelBlade said...

I failed on N80 V5.0719.0.2, now the phone is bricked, but looking at the log the cause doesn't seem to be the change of swipolicy (I was using Phoenix), did anyone succeded with N80 and firmware V5.0719.0.2??

November 25, 2007  
Anonymous Anonymous said...

No problems with N80 v5.0719.0.2

November 27, 2007  
Anonymous Anonymous said...

I am just wondering have anyone tried using phonix or any other ways as an alternative to NSU?
I am sure that not many of us got mobiles to throw it away but someone with a Griffin box or others might want to give this a shot
But when we are able to do such thing on other alternatives we might get such thing like SX1 firmwares (anyone remember? ;)

November 30, 2007  
Anonymous Anonymous said...

There is also somethings interested , i was searching for uboot loader (which looks like someone ported it for symbian) , so i guess we could even patch t into the main firmware and get linux to our mobiles

December 01, 2007  
Blogger MartY3 said...

failed on n95 several times now :(

i keep trying tho

December 10, 2007  
Anonymous Anonymous said...

And what about N93i?
Does it work on it???
thx for answers

December 19, 2007  
Blogger roy-eye said...

It anyone success in 3250 ?

December 19, 2007  
Blogger debanjan basu said...

works flawlessly on n93 i even modified some other files........will like to know how you can change the dll and exe uid to support unsigned installation....untrusted supplier...or error something like that in a lot of apps.....

December 24, 2007  
Anonymous Anonymous said...

debanjan basu, u have to modify file "installserver.dll" for this, by IDAPro and WinHEX

December 27, 2007  
Blogger debanjan basu said...

yesssssssssssss dude you are right installserver.dll has been successfully breached and modified...

December 30, 2007  
Anonymous Anonymous said...

Heh, I found this stuff just a bit too late -- I just updated my E90 to firmware 7.40.1.2 yesterday. I'll not dare attempt a downgrade since supposedly it will brick a phone unless you follow a fairly specified sequence which requires service hardware & software (just google for bb5+downgrade, E90 is a BB5 phone). I guess Nokia intentionally made firmware downgrades hard just in case something like this happens. :-)

Anyway, if someone finds out how to hack the new 7.40.1.2 FW then I'd be really really interested. The previous posts are a pointer into the right direction I guess. I can't find the string "installserver.dll" inside the firmware image, but "installserver.exe" is there, I guess this is the file to hack? But where is it located in the firmware image? Kinda hard to find out without knowing the specs of the internal filesystem. Not that I'd have the prerequisite ARM binaryhacking knowledge anyway.

Thanks for an interesting read nonetheless, I hope I can soon do whatever I please on MY (not Nokia's unlike what they seem to think) 890€ device.

January 06, 2008  
Anonymous SteelBlade said...

Can someone succeeded on N80 v5.0719.0.2 post the used swipolicy.ini ??

January 12, 2008  
Blogger Udon said...

I Succeed on E61 and E70.
But I unsucceed on E61i ver4.
I will try to E61i ver1.

February 06, 2008  
Anonymous Darkmen said...

Tested N73_4.0735.3.0.2 and N80_5.0719.0.2
Works installation unprotected UIDs.
Protected failed w\o cert.

February 12, 2008  
Blogger phoenix said...

Can somebody help me do this on my phone nokia e51?? my e-mail: korennoj@gmail.com
please send it to me

March 12, 2008  

Post a Comment

Subscribe to Post Comments [Atom]

Links to this post:

Create a Link

<< Home