View Full Version : HACK TO OVERRIDE ALL PERMESSION on s60v3 devices by FCA00000


Pages : 1 [2] 3

jaywhy13
1st April 2008, 23:29
I have an N82 and this has not worked for me... Does anyone with an N82 got this hack to work successfully?

PapaDocta
1st April 2008, 23:30
guys make sure you are using windows xp... i have tried it on vista but didn't work..

yashrg
1st April 2008, 23:47
My OS is windows xp lite. I am running it as virtual machine on my macbook pro. I would try it on parallels if I had it. but right now, I am stuck with vmware fusion.

starsalzma
2nd April 2008, 00:39
i have xp os and im trying to perform the hack on my n81 with 8gb. i get to the part where i need to run the hack_perms_s60v3_fp1.py file and then my phone locks up and restarts. anyone know what im doing wrong?

i connect the phone to my computer press connect pc suite then i go to apptk connect with it and then i run the file. it runs for a second i get some text and then my phone locks up and restarts

yashrg
2nd April 2008, 01:13
I updated firmware on my phone. now will try again. I went from firmware 1.XXXXXX to 3.XXXXXXX I saw the catalog thing was new. I feel wifi connection etc was faster as well.

blesio
2nd April 2008, 01:35
Anyone with 6120c tried this method and can do me a favour?

I need z:\private\10207114\import and z:\resource\skins folders please.

Would be very grateful.

best regards

blesio

yashrg
2nd April 2008, 02:03
Yay! it worked this time! I can now access the system folders! And I put the files in sys/bin and sys/hash folders to make it permanent. but haven't tested out that part yet.

bAsem
2nd April 2008, 02:08
Yay! it worked this time! I can now access the system folders! And I put the files in sys/bin and sys/hash folders to make it permanent. but haven't tested out that part yet.

see i knew u would get it . If u follow the steps . . Congrats to u man

wap
2nd April 2008, 03:48
wondering why we don't post the ready made sisx file and just install to phone and it done? Please post the sisx one.

PHoeZies
2nd April 2008, 04:14
Nope.. at the moment u must use FCA's trick thru pc 2do all tis..
But Im sure they're working on it.. :)

eks_are
2nd April 2008, 04:38
does it work with 5700??...pls sum one answers me...

starsalzma
2nd April 2008, 04:54
so i updated the firmware on my n81 8gb and tried again and i was able to save this pic just before the window closed itself

http://img291.imageshack.us/img291/3201/phonehackzs6.jpg

bAsem
2nd April 2008, 07:16
so i updated the firmware on my n81 8gb and tried again and i was able to save this pic just before the window closed itself



did u install pyserial and pywin .. if not then install them if ur not sure jut reinstall them ..

arieonline
2nd April 2008, 07:32
great it's work

using Nokia E51.

it's take for about 2 hour... most of part is downloading pc suite and phyton... :)

PHoeZies
2nd April 2008, 08:32
Anyone with 6120c tried this method and can do me a favour?

I need z:\private\10207114\import and z:\resource\skins folders please.

Would be very grateful.

best regards

blesio

here bro.. I posted in ur thread http://www.ipmart-forum.com/showpost.php?p=1916586&postcount=69
hope u like it & pls create the sis version... ;)

starsalzma
2nd April 2008, 09:14
everytime i try to install pywin it says that i need vr. 2.6 ive installed pyserial just fine and im going to try it again in the morning

thanks for the advice ill post the results as soon as i test it

arieonline
2nd April 2008, 09:27
@starsalzma
u must download pywin ver 2.5 not 2.6

manxkat
2nd April 2008, 12:13
does it work with 5700??...pls sum one answers me...

Yes, it works like a charm. Just make sure you get all the FP1 files.

eks_are
2nd April 2008, 13:25
Yes, it works like a charm. Just make sure you get all the FP1 files.

mate...dunno which part i'm doing wrong...everytime i run TRK app. my phone reboot...can u guide me which file should i take??...thanks in advances...

Kays
2nd April 2008, 14:09
mate...dunno which part i'm doing wrong...everytime i run TRK app. my phone reboot...can u guide me which file should i take??...thanks in advances...

install s60_3_1_app_trk_2_7.sisx and not s60_3_0_app_trk_2_7.sisx
the same thing happend to me on my 5700

takashiro
2nd April 2008, 14:33
Hmm i have been trying for the whole night and i still can't get it to work on my nokia N93... anyway thanks for all the tutorials...

One thing now since the security system can be breached... Maybe it is also the Viruses time as well... so watch out this issue...

rafi300
2nd April 2008, 15:57
For Some Unknown reason my phone wont get hacked to override all permissions... it runs the script perfectly but doesnt find anything to edit or whatever...
:(
Some help?
i tried it 3 4 times...
Could having latest firmware update installed mingle with this hack??
I have a Nokia N80 firmware 4.0623.0.42??

yashrg
2nd April 2008, 16:24
takashiro and rafi, are you sure you installed hello carbide on the phone? After installing you also have to paste the hello carbide Exe file in the c drive of the phone.

sky178
2nd April 2008, 16:39
you are a very intelegent man

manxkat
2nd April 2008, 17:00
install s60_3_1_app_trk_2_7.sisx and not s60_3_0_app_trk_2_7.sisx
the same thing happend to me on my 5700

install s60_3_1_app_trk_2_7.sisx didn't work for me at first.
So I downloaded and installed s60_3_1_app_trk_2_8_5.sisx.
Worked like a charm.

jaywhy13
2nd April 2008, 17:29
Someone PLEASE help me!!!!! I really want this thing to work.

My phone only reboots after I get the error in the image shown.

I've got python2.5.2
pywin32-210.win32-py2.5
pyserial-2.2.win32
hack_perms_s60v3_FP1
s60_3_0_app_trk_2_7
I exit PC Suite before I run the hack but my phone reboots itself... 'A device attached to the system is not functioning properly'

My N82 shows up as N82 USB... I have to go into Advanced Ports where it shows me that it's COM32

Running latest firmware on my phone
V 11.0.117
10-12-07
RM-313

PapaDocta
2nd April 2008, 17:33
what version of TRK are you using jaywhy13?

jaywhy13
2nd April 2008, 17:34
I'm using s60_3_0_app_trk_2_7

bAsem
2nd April 2008, 17:54
I'm using s60_3_0_app_trk_2_7

u need to use s60_3_1_app_trk_2_8 posted in my thread aswell . Under "alternative trk for n82" coz ur phone is fp1

rafi300
2nd April 2008, 20:41
Yes, I've Hellocarbide installed on my phone, and also placed it in the main directory of C:/ in my phone as well.
I'm using Python 2.5.2 and the correct version of TRK but still no idea.. Attached is the log that was generated by Python.


PythonWin 2.5.2 (r252:60911, Feb 21 2008, 13:11:45) [MSC v.1310 32 bit (Intel)] on win32.
Portions Copyright 1994-2006 Mark Hammond - see 'Help/About PythonWin' for further copyright information.
>>> Using port:
COM4
>Ping
sending message number 00
Frame does not end with 0x7E:-1
showFrameChecksum-incorrect:-1
received message number -1
>Connect
sending message number 01
Frame does not end with 0x7E:-1
showFrameChecksum-incorrect:-1
received message number -1
>SupportMask
sending message number 02
Frame does not end with 0x7E:-1
showFrameChecksum-incorrect:-1
received message number -1
ProcessID=0001 ThreadID=0001
Read memory without process. Only when DS_PROTOCOL<3 . In this case, DS_PROTOCOL=-1
sending message number 03
Frame does not end with 0x7E:-1
showFrameChecksum-incorrect:-1
received message number -1
Read Memory SEGMENTED without process. Only when DS_PROTOCOL<3 . In this case, DS_PROTOCOL=-1
sending message number 04
Frame does not end with 0x7E:-1
showFrameChecksum-incorrect:-1
received message number -1
>Scanning memory
Read Memory at 60000000=60 00 00 00
sending message number 05
Frame does not end with 0x7E:-1
showFrameChecksum-incorrect:-1
received message number -1
Read Memory 60000000=-1 -1 -1 -1
Read Memory 60000004=-1 -1 -1 -1
Read Memory 60000008=-1 -1 -1 -1
Read Memory 6000000C=-1 -1 -1 -1
Read Memory 60000010=-1 -1 -1 -1
Read Memory 60000014=-1 -1 -1 -1
base address 60000000 doesn't look correct
Read Memory at 60000100=60 00 01 00
sending message number 06
Frame does not end with 0x7E:-1
showFrameChecksum-incorrect:-1
received message number -1
Read Memory 60000100=-1 -1 -1 -1
Read Memory 60000104=-1 -1 -1 -1
Read Memory 60000108=-1 -1 -1 -1
Read Memory 6000010C=-1 -1 -1 -1
Read Memory 60000110=-1 -1 -1 -1
Read Memory 60000114=-1 -1 -1 -1
base address 60000100 doesn't look correct
Read Memory at C2000000=C2 00 00 00
sending message number 07
Frame does not end with 0x7E:-1
showFrameChecksum-incorrect:-1
received message number -1
Read Memory C2000000=-1 -1 -1 -1
Read Memory C2000004=-1 -1 -1 -1
Read Memory C2000008=-1 -1 -1 -1
Read Memory C200000C=-1 -1 -1 -1
Read Memory C2000010=-1 -1 -1 -1
Read Memory C2000014=-1 -1 -1 -1
base address C2000000 doesn't look correct
Read Memory at C2000100=C2 00 01 00
sending message number 08
Frame does not end with 0x7E:-1
showFrameChecksum-incorrect:-1
received message number -1
Read Memory C2000100=-1 -1 -1 -1
Read Memory C2000104=-1 -1 -1 -1
Read Memory C2000108=-1 -1 -1 -1
Read Memory C200010C=-1 -1 -1 -1
Read Memory C2000110=-1 -1 -1 -1
Read Memory C2000114=-1 -1 -1 -1
base address C2000100 doesn't look correct
Read Memory at C8000000=C8 00 00 00
sending message number 09
Frame does not end with 0x7E:-1
showFrameChecksum-incorrect:-1
received message number -1
Read Memory C8000000=-1 -1 -1 -1
Read Memory C8000004=-1 -1 -1 -1
Read Memory C8000008=-1 -1 -1 -1
Read Memory C800000C=-1 -1 -1 -1
Read Memory C8000010=-1 -1 -1 -1
Read Memory C8000014=-1 -1 -1 -1
base address C8000000 doesn't look correct
Read Memory at C8000100=C8 00 01 00
sending message number 0A
Frame does not end with 0x7E:-1
showFrameChecksum-incorrect:-1
received message number -1
Read Memory C8000100=-1 -1 -1 -1
Read Memory C8000104=-1 -1 -1 -1
Read Memory C8000108=-1 -1 -1 -1
Read Memory C800010C=-1 -1 -1 -1
Read Memory C8000110=-1 -1 -1 -1
Read Memory C8000114=-1 -1 -1 -1
base address C8000100 doesn't look correct
>Stop
sending message number 0B
Frame does not end with 0x7E:-1
showFrameChecksum-incorrect:-1
received message number -1
>Ack Notify Stopped
sending message number 02
>Disconnect
sending message number 0C
Frame does not end with 0x7E:-1
showFrameChecksum-incorrect:-1
received message number -1
>Close
>End+Exit



Hope some1 helps out...

bAsem
2nd April 2008, 21:20
whats ur phone model .. please and please make sure u installed pywin and pyserial and the pc suite is killed and ur on xp

thanks


here is the page for u to know if ur phone is prefp1 or fp1 or fp2 from nokia ..

http://www.forum.nokia.com/devices/matrix_s60_3ed_1.html

suprotik333
2nd April 2008, 21:48
guys need help! My n95 8gb restarts as soon as i do step 8.1.. that is as soon as i execute the .py file from my pc.. i get this error!
C:\Documents and Settings\Kaushik\Desktop\abc\hack_perms_s60v3>hack_perms_s60v3.
py
Using port:
COM6
>Ping
sending message number 00
<kDSReplyACK
received message number 00
kDSReplyNoError
>Connect
sending message number 01
Frame does not end with 0x7E:-1
showFrameChecksum-incorrect:-1
received message number -1
>Create Item
sending message number 02
Traceback (most recent call last):
File "C:\Documents and Settings\Kaushik\Desktop\abc\hack_perms_s60v3\hack _perm
s_s60v3.py", line 376, in <module>
sendFrame(ser,encodeHeaderCKFrame([0x40,iCommand,0x00,0x00,0x00,0x00,0x15,0x
43,0x3A,0x5C,0x48,0x65,0x6C,0x6C,0x6F,0x43,0x61,0x 72,0x62,0x69,0x64,0x65,0x2E,0x
65,0x78,0x65,0x00,0x00,-1])) # Create Item
File "C:\Documents and Settings\Kaushik\Desktop\abc\hack_perms_s60v3\hack _perm
s_s60v3.py", line 180, in sendFrame
ser.write(chr(i))
File "C:\Python25\Lib\site-packages\serial\serialwin32.py", line 220, in write

err, n = win32file.WriteFile(self.hComPort, s, self._overlappedWrite)
pywintypes.error: (31, 'WriteFile', 'A device attached to the system is not func
tioning.')

C:\Documents and Settings\Kaushik\Desktop\abc\hack_perms_s60v3>

rafi300
2nd April 2008, 22:06
I mentioned what phone i have in my previous post.. but :) again for u basem,
I have a Nokia N80 and i already know what phone operating class it is, Its Prefp1
I have both pywin and serial installed.. and i installed hellocarbide in my phone too.. dont know what it does though.. just installed it and copied it to my c:/ phone memory folder too.... So now??

suprotik333
2nd April 2008, 22:06
oops! i missed the tk for fp1.. sorry!
I installed it and connected and now it got executed but didn't found anything called Candidate!!!
this is my log:
C:\Documents and Settings\Kaushik\Desktop\abc\hack_perms_s60v3>hack_perms_s60v3.
py
Using port:
COM6
>Ping
sending message number 00
<kDSReplyACK
received message number 00
kDSReplyNoError
>Connect
sending message number 01
<kDSReplyACK
received message number 01
kDSReplyNoError
>Create Item
sending message number 02
<kDSReplyACK
received message number 02
kDSReplyOsError
ProcessID=-1-1 ThreadID=-1-1
>Read Memory 0x60000100
Read Memory at 60000100=60 00 01 00
sending message number 03
<kDSReplyNAK !!!!!!!!!!!!!!!!!!
received message number 03
kDSReplyPacketSizeError
Read Memory 60000100=-1 -1 -1 -1
Read Memory 60000104=-1 -1 -1 -1
Read Memory 60000108=-1 -1 -1 -1
Read Memory 6000010C=-1 -1 -1 -1
Read Memory 60000110=-1 -1 -1 -1
Read Memory 60000114=-1 -1 -1 -1
Read Memory 60000118=-1 -1 -1 -1
Read Memory 6000011C=-1 -1 -1 -1
Read Memory 60000120=-1 -1 -1 -1
Read Memory 60000124=-1 -1 -1 -1
Read Memory 60000128=-1 -1 -1 -1
Read Memory 6000012C=-1 -1 -1 -1
Read Memory 60000130=-1 -1 -1 -1
Read Memory 60000134=-1 -1 -1 -1
Read Memory 60000138=-1 -1 -1 -1
Read Memory 6000013C=-1 -1 -1 -1
Read Memory 60000140=-1 -1 -1 -1
Read Memory 60000144=-1 -1 -1 -1
Read Memory 60000148=-1 -1 -1 -1
Read Memory 6000014C=-1 -1 -1 -1
Read Memory 60000150=-1 -1 -1 -1
Read Memory 60000154=-1 -1 -1 -1
Read Memory 60000158=-1 -1 -1 -1
Read Memory 6000015C=-1 -1 -1 -1
Read Memory 60000160=-1 -1 -1 -1
Read Memory 60000164=-1 -1 -1 -1
Read Memory 60000168=-1 -1 -1 -1
Read Memory 6000016C=-1 -1 -1 -1
Read Memory 60000170=-1 -1 -1 -1
Read Memory 60000174=-1 -1 -1 -1
Read Memory 60000178=-1 -1 -1 -1
Read Memory 6000017C=-1 -1 -1 -1
Read Memory 60000180=-1 -1 -1 -1
Read Memory 60000184=-1 -1 -1 -1
Read Memory 60000188=-1 -1 -1 -1
Read Memory 6000018C=-1 -1 -1 -1
Read Memory 60000190=-1 -1 -1 -1
Read Memory 60000194=-1 -1 -1 -1
Read Memory 60000198=-1 -1 -1 -1
Read Memory 6000019C=-1 -1 -1 -1
Read Memory 600001A0=-1 -1 -1 -1
Read Memory 600001A4=-1 -1 -1 -1
Read Memory 600001A8=-1 -1 -1 -1
Read Memory 600001AC=-1 -1 -1 -1
Read Memory 600001B0=-1 -1 -1 -1
Read Memory 600001B4=-1 -1 -1 -1
Read Memory 600001B8=-1 -1 -1 -1
Read Memory 600001BC=-1 -1 -1 -1
Read Memory 600001C0=-1 -1 -1 -1
Read Memory 600001C4=-1 -1 -1 -1
Read Memory 600001C8=-1 -1 -1 -1
Read Memory 600001CC=-1 -1 -1 -1
Read Memory 600001D0=-1 -1 -1 -1
Read Memory 600001D4=-1 -1 -1 -1
Read Memory 600001D8=-1 -1 -1 -1
Read Memory 600001DC=-1 -1 -1 -1
Read Memory 600001E0=-1 -1 -1 -1
Read Memory 600001E4=-1 -1 -1 -1
Read Memory 600001E8=-1 -1 -1 -1
Read Memory 600001EC=-1 -1 -1 -1
Read Memory 600001F0=-1 -1 -1 -1
Read Memory 600001F4=-1 -1 -1 -1
Read Memory 600001F8=-1 -1 -1 -1
Read Memory 600001FC=-1 -1 -1 -1
>Stop
sending message number 04
<kDSReplyNAK !!!!!!!!!!!!!!!!!!
received message number 04
kDSReplyPacketSizeError
>Ack Notify Stopped
sending message number 02
>Disconnect
sending message number 05
<kDSReplyACK
received message number 05
kDSReplyNoError
>Close
>End+Exit

C:\Documents and Settings\Kaushik\Desktop\abc\hack_perms_s60v3>


Also am not able to understand what to do next! pls anyone can help!

rafi300
3rd April 2008, 00:47
i keep on getting error saying base address doesn't look correct, i've posted my log on pg 33 :( but no luck... Please if some1 know how's to help, would be greatly appreciated.. Thanks.

starsalzma
3rd April 2008, 04:05
i got it to work i was using the wrong hack_perms file needed the fp1 one

eks_are
3rd April 2008, 04:08
now it works...thanks to Kays...rep. ++

tipu
3rd April 2008, 13:09
Allfiles + hash made easy!

Right... My first guide for this forum. Let's hope it works Smile

So you've got a hacked phone. Nice, but every time you restart, you have to rehack or the folders are hidden again. How do you convert your preferred file browser into an Allfiles version?

Download this file. It contains all you'll need. Petran, a hex editor and the hashtab program. Run and install the hex editor and the hashtab programs.
http://rapidshare.com/files/102971174/Allfiles.rar

Editing privileges.
1. Let's say you want Y-Browser to have full privileges. Install it like you would normally do to C:\. Hack the phone and use the Y-Browser to navigate to C:\Sys\Bin, where most programs are installed.

2. Find the exe called YuccaBrowser.exe and copy it to the memory card. Then copy the file to the PC using a USB cable or whatever.

3. Create a folder containing YuccaBrowser.exe and Petran.exe, which you downloaded earlier. Open a Commando prompt and CD into this folder.

4. Paste this string into the Command Prompt window
petran.exe -capabilities NetworkServices+LocalServices+ReadUserData+WriteUs erData+UserEnvironment+AllFiles YuccaBrowser.exe

5. Move the patched file back onto the phone memory card and use Y-Browser to paste it into the C:\Sys\Bin folder.

Creating the hash file.
1. Navigate to the file you need to create a hash for. The file you pacthed above, for example. Right click and select Properties.

2. Select the 'File Hashes' tab. Right click on the SHA-1 hash and select 'Copy'. Close the Properties window.

3. Run WinHex. Select 'Edit/Clipboard Data/Paste Into New File'. In the window 'Choose Clipboard Format' you select 'ASCII Hex'. Save the file using the same name as the exe, like YuccaBrowser.exe and move it to the memory card of your phone.

4. Use Y-Browser to copy the file to the C:\Sys\Hash folder. Done!

Actually you don't need the hash file when installing to drive C:\ because it is expected to be protected (!), but now you know how to do it anyway Smile

Is there any way to do it with activefile because I tried this and it does not work, though it is working with xplorer and ybrowser

xhominx
3rd April 2008, 17:10
doesnt work on n73 v4.07 firmware =D

rafi300
3rd April 2008, 19:17
I think those ppl who patched their firmwares to latest editions this hack doesn't work on thier phones..
I've Nokia N80 V4.0623.0.42

bAsem
3rd April 2008, 19:39
I think those ppl who patched their firmwares to latest editions this hack doesn't work on thier phones..
I've Nokia N80 V4.0623.0.42

hey rafi i have n80 v5 and mr.FCA000000 himself has a nokia n80 so DONT tell me the hack isnt working .. its u who cant make it work man ..

jut follow the steps and it will work

bAsem
3rd April 2008, 19:42
"WARNING"
I started this as a new thread also in the apps section 2 tell u this.....

Be aware gang.....

The hack won't work anymore....

I have tried it with the latest firmware (V20.016 for the N95 8GB)......

Nokia wins round 2!!!! :hysteria:

PROBLEM FIXED!!

drBubu
3rd April 2008, 20:28
Don't u know that mr FCA00000 has been hired by Nokia (of course with great $$$) now? Lucky for him, bad news for us. So, say goodbye to our ally. N don't upgrade ur phone.

bAsem
3rd April 2008, 20:35
Don't u know that mr FCA00000 has been hired by Nokia (of course with great $$$) now? Lucky for him, bad news for us. So, say goodbye to our ally. N don't upgrade ur phone.

lol really .. i dont think he did ... and please stop the off topic

EDIT:/// http://finestfones.blogspot.com/2008/04/nokia-strikes-again-fca00000-hired.html

oh my god it is NOT true ... !!!!!!!!!!!!

http://www.youtube.com/watch?v=NMShvQa4SI0

PHoeZies
3rd April 2008, 20:49
Offtopic:
No FCA doesnt join Nokia, it was April Fools ;)
Ok back in topic again..

bAsem
3rd April 2008, 20:55
looooooooloooooooool .. thats sick ..

well maybe i should keep it for a while

i totally beleived it hahahahaaaaaaa

i was like wtf what are we gonna do now ..

phew :hysteria:


and yes ur right .. :D enough offtopic

drBubu
3rd April 2008, 21:13
I'm sorry, :LoL: I was fooled too. Okay then, still the warning not to upgrade ur phone is important, until mr FCA00000 make the new solution. Cheers.

rafi300
4th April 2008, 03:07
hmmm... Well i'll give it another try again..
i don't understand what could be wrong though..
I'll uninstall trk and hellocarbide from phone and python from comp and reinstall em and run em again.By the way,. What does hellocarbide do in the phone once installed? And copied to the c: main folder.. And does it matter if trk is installed in phone memory or memory card?

bAsem
4th April 2008, 05:15
hmmm... Well i'll give it another try again..
i don't understand what could be wrong though..
I'll uninstall trk and hellocarbide from phone and python from comp and reinstall em and run em again.By the way,. What does hellocarbide do in the phone once installed? And copied to the c: main folder.. And does it matter if trk is installed in phone memory or memory card?

well the carbide is a dump app . But it doesnt matter if u put it . . So install it and copy the exe file to the main directory . . And trk goes to the phone memory .

paulofolivei
4th April 2008, 05:24
Hello,

I tried this on my E90 (7.40.1.2) and it didn't work :(

EDIT: Sorry, my mistake, i wasn't using the FP1 version ;)

EDIT2: It worked on E90! :egdance:


I still have on question: Can i uninstall now "HelloCarbide" ?

Tnx!

bAsem
4th April 2008, 08:12
yes u can .. but why would u do that its only a couple of kb in size .. very harmless

and gratz on making it work

gauravgi
4th April 2008, 10:32
hello..

i cant get this thing to work...
here's the trace of the python program


Using port:
\\.\COM13
>Ping
sending message number 00
<kDSReplyACK
received message number 00
kDSReplyNoError
>Connect
sending message number 01
<kDSReplyACK
received message number 01
kDSReplyNoError
>Create Item
sending message number 02
<kDSReplyACK
received message number 02
kDSReplyNoError
ProcessID=013F ThreadID=0140
>Read Memory 0x60000100
Read Memory at 60000100=60 00 01 00
sending message number 03
<kDSReplyACK
received message number 03
kDSReplyOsError
Read Memory 60000100=-1 -1 -1 -1
Read Memory 60000104=-1 -1 -1 -1
Read Memory 60000108=-1 -1 -1 -1
Read Memory 6000010C=-1 -1 -1 -1
Read Memory 60000110=-1 -1 -1 -1
Read Memory 60000114=-1 -1 -1 -1
Read Memory 60000118=-1 -1 -1 -1
Read Memory 6000011C=-1 -1 -1 -1
Read Memory 60000120=-1 -1 -1 -1
Read Memory 60000124=-1 -1 -1 -1
Read Memory 60000128=-1 -1 -1 -1
Read Memory 6000012C=-1 -1 -1 -1
Read Memory 60000130=-1 -1 -1 -1
Read Memory 60000134=-1 -1 -1 -1
Read Memory 60000138=-1 -1 -1 -1
Read Memory 6000013C=-1 -1 -1 -1
Read Memory 60000140=-1 -1 -1 -1
Read Memory 60000144=-1 -1 -1 -1
Read Memory 60000148=-1 -1 -1 -1
Read Memory 6000014C=-1 -1 -1 -1
Read Memory 60000150=-1 -1 -1 -1
Read Memory 60000154=-1 -1 -1 -1
Read Memory 60000158=-1 -1 -1 -1
Read Memory 6000015C=-1 -1 -1 -1
Read Memory 60000160=-1 -1 -1 -1
Read Memory 60000164=-1 -1 -1 -1
Read Memory 60000168=-1 -1 -1 -1
Read Memory 6000016C=-1 -1 -1 -1
Read Memory 60000170=-1 -1 -1 -1
Read Memory 60000174=-1 -1 -1 -1
Read Memory 60000178=-1 -1 -1 -1
Read Memory 6000017C=-1 -1 -1 -1
Read Memory 60000180=-1 -1 -1 -1
Read Memory 60000184=-1 -1 -1 -1
Read Memory 60000188=-1 -1 -1 -1
Read Memory 6000018C=-1 -1 -1 -1
Read Memory 60000190=-1 -1 -1 -1
Read Memory 60000194=-1 -1 -1 -1
Read Memory 60000198=-1 -1 -1 -1
Read Memory 6000019C=-1 -1 -1 -1
Read Memory 600001A0=-1 -1 -1 -1
Read Memory 600001A4=-1 -1 -1 -1
Read Memory 600001A8=-1 -1 -1 -1
Read Memory 600001AC=-1 -1 -1 -1
Read Memory 600001B0=-1 -1 -1 -1
Read Memory 600001B4=-1 -1 -1 -1
Read Memory 600001B8=-1 -1 -1 -1
Read Memory 600001BC=-1 -1 -1 -1
Read Memory 600001C0=-1 -1 -1 -1
Read Memory 600001C4=-1 -1 -1 -1
Read Memory 600001C8=-1 -1 -1 -1
Read Memory 600001CC=-1 -1 -1 -1
Read Memory 600001D0=-1 -1 -1 -1
Read Memory 600001D4=-1 -1 -1 -1
Read Memory 600001D8=-1 -1 -1 -1
Read Memory 600001DC=-1 -1 -1 -1
Read Memory 600001E0=-1 -1 -1 -1
Read Memory 600001E4=-1 -1 -1 -1
Read Memory 600001E8=-1 -1 -1 -1
Read Memory 600001EC=-1 -1 -1 -1
Read Memory 600001F0=-1 -1 -1 -1
Read Memory 600001F4=-1 -1 -1 -1
Read Memory 600001F8=-1 -1 -1 -1
Read Memory 600001FC=-1 -1 -1 -1
>Stop
sending message number 04
showFrameChecksum-incorrect:-1
<kDSReplyACK
received message number 04
kDSReplyNoError
>Ack Notify Stopped
sending message number 02
>Disconnect
sending message number 05
<kDSReplyACK
received message number 05
kDSReplyNoError
>Close
>End+Exit


here's the trace with v0.2 of the program for s60v3 [not FP1]

Using port:
\\.\COM13
>Ping
sending message number 00
<kDSReplyACK
received message number 00
kDSReplyNoError
>Connect
sending message number 01
<kDSReplyACK
received message number 01
kDSReplyNoError
>SupportMask
sending message number 02
<kDSReplyACK
received message number 02
kDSReplyNoError
Level=DS_PROTOCOL_RTOS. (OS-level debugger)
ProcessID=0001 ThreadID=0001
Read memory without process. Only when DS_PROTOCOL<3 . In this case, DS_PROTOCOL
=03
sending message number 03
<kDSReplyACK
received message number 03
kDSReplyUnsupportedOptionError
Read Memory SEGMENTED without process. Only when DS_PROTOCOL<3 . In this case, D
S_PROTOCOL=03
sending message number 04
<kDSReplyACK
received message number 04
kDSReplyUnsupportedOptionError
>Scanning memory
Read Memory at 60000000=60 00 00 00
sending message number 05
<kDSReplyACK
received message number 05
kDSReplyOsError
The OS reported an error :-(
Read Memory at 60000100=60 00 01 00
sending message number 06
<kDSReplyACK
received message number 06
kDSReplyOsError
The OS reported an error :-(
Read Memory at C2000000=C2 00 00 00
sending message number 07
<kDSReplyACK
received message number 07
kDSReplyOsError
The OS reported an error :-(
Read Memory at C2000100=C2 00 01 00
sending message number 08
<kDSReplyACK
received message number 08
kDSReplyOsError
The OS reported an error :-(
Read Memory at C8000000=C8 00 00 00
sending message number 09
<kDSReplyACK
received message number 09
kDSReplyOsError
The OS reported an error :-(
Read Memory at C8000100=C8 00 01 00
sending message number 0A
<kDSReplyACK
received message number 0A
kDSReplyOsError
The OS reported an error :-(
>Stop
sending message number 0B
<kDSReplyACK
received message number 0B
kDSReplyOsError
>Ack Notify Stopped
sending message number 02
>Disconnect
sending message number 0C
<kDSReplyACK
received message number 0C
kDSReplyNoError
>Close
>End+Exit


i'm trying this on an N73 ME with fw v 4.0750.31.2.1
phone is on port 13, corresponding change has been made to the py script..
using TRK s60_3_0_app_trk_2_7.sisx
installed HelloCarbide to c: and copied the HelloCrabide.exe to c:

using all correct files as described in the readme..

tried it under both windows vista and xp with the same trace in both cases..

did kill pc suite software before connecting the phone in pc suite mode..

could somebody please point me in the correct direction.. maybe i'm doing something wrong.. has anyone got it to work with N73 ME with latest fw?

thank you..

Rol@N95d
4th April 2008, 11:44
More info on the hack not working since upgrading the N95 8Gb 2 V.20.0.016:

Tried agian last night 2 hack it with using the python method.....
Now the python hack won't work anymore (1st time it states !!!!candidate!!!!) but now the screen opens, runs a script very quick and dissapears.....

This getting weirder by the hour!!!!

Rol@N95d
4th April 2008, 14:07
Hi gang.....

Just got of on a private helpdesk session with swankyleo....
He helped me out and got me right back on track using the FCA00000 hack.
It seems - and i feel really stupid saying this and posting it over all the forums that it won't work anymore- that the problem was that I used the new TRK app (wich was not good) and that i didn't disconnect the App trk app when pulling out the USB. Ther4 the hack didn't work anymore ....

I now have caps on and off running.
Everything is fine again....

So again....
Sorry 4 all the mix-ups...
Swanky will post a new thread using his new method without the Python use...
mayB that was the problem with my latest firmware...

Or am i covering up my actions b4?

Once again.... sorry and keep up the good work (FCA00000 and Swankyleo)

bAsem
4th April 2008, 18:35
Hi gang.....

Just got of on a private helpdesk session with swankyleo....
He helped me out and got me right back on track using the FCA00000 hack.
It seems - and i feel really stupid saying this and posting it over all the forums that it won't work anymore- that the problem was that I used the new TRK app (wich was not good) and that i didn't disconnect the App trk app when pulling out the USB. Ther4 the hack didn't work anymore ....

I now have caps on and off running.
Everything is fine again....

So again....
Sorry 4 all the mix-ups...
Swanky will post a new thread using his new method without the Python use...
mayB that was the problem with my latest firmware...

Or am i covering up my actions b4?

Once again.... sorry and keep up the good work (FCA00000 and Swankyleo)


ok mr.rolan95d thanks for clearing things up .. and as i said no need to be sorry .. i just put the warning just to be safe ...

:)

s1s1s1
4th April 2008, 20:28
hi
can someone help me i get this when i run the script
i have E65

Using port:
COM6
>Ping
sending message number 00
<kDSReplyACK
received message number 00
kDSReplyNoError
>Connect
sending message number 01
<kDSReplyACK
received message number 01
kDSReplyNoError
>Create Item
sending message number 02
<kDSReplyACK
received message number 02
kDSReplyOsError
ProcessID=-1-1 ThreadID=-1-1
>Read Memory 0x60000100
Read Memory at 60000100=60 00 01 00
sending message number 03
<kDSReplyNAK !!!!!!!!!!!!!!!!!!
received message number 03
kDSReplyPacketSizeError
Read Memory 60000100=-1 -1 -1 -1
Read Memory 60000104=-1 -1 -1 -1
Read Memory 60000108=-1 -1 -1 -1
Read Memory 6000010C=-1 -1 -1 -1
Read Memory 60000110=-1 -1 -1 -1
Read Memory 60000114=-1 -1 -1 -1
Read Memory 60000118=-1 -1 -1 -1
Read Memory 6000011C=-1 -1 -1 -1
Read Memory 60000120=-1 -1 -1 -1
Read Memory 60000124=-1 -1 -1 -1
Read Memory 60000128=-1 -1 -1 -1
Read Memory 6000012C=-1 -1 -1 -1
Read Memory 60000130=-1 -1 -1 -1
Read Memory 60000134=-1 -1 -1 -1
Read Memory 60000138=-1 -1 -1 -1
Read Memory 6000013C=-1 -1 -1 -1
Read Memory 60000140=-1 -1 -1 -1
Read Memory 60000144=-1 -1 -1 -1
Read Memory 60000148=-1 -1 -1 -1
Read Memory 6000014C=-1 -1 -1 -1
Read Memory 60000150=-1 -1 -1 -1
Read Memory 60000154=-1 -1 -1 -1
Read Memory 60000158=-1 -1 -1 -1
Read Memory 6000015C=-1 -1 -1 -1
Read Memory 60000160=-1 -1 -1 -1
Read Memory 60000164=-1 -1 -1 -1
Read Memory 60000168=-1 -1 -1 -1
Read Memory 6000016C=-1 -1 -1 -1
Read Memory 60000170=-1 -1 -1 -1
Read Memory 60000174=-1 -1 -1 -1
Read Memory 60000178=-1 -1 -1 -1
Read Memory 6000017C=-1 -1 -1 -1
Read Memory 60000180=-1 -1 -1 -1
Read Memory 60000184=-1 -1 -1 -1
Read Memory 60000188=-1 -1 -1 -1
Read Memory 6000018C=-1 -1 -1 -1
Read Memory 60000190=-1 -1 -1 -1
Read Memory 60000194=-1 -1 -1 -1
Read Memory 60000198=-1 -1 -1 -1
Read Memory 6000019C=-1 -1 -1 -1
Read Memory 600001A0=-1 -1 -1 -1
Read Memory 600001A4=-1 -1 -1 -1
Read Memory 600001A8=-1 -1 -1 -1
Read Memory 600001AC=-1 -1 -1 -1
Read Memory 600001B0=-1 -1 -1 -1
Read Memory 600001B4=-1 -1 -1 -1
Read Memory 600001B8=-1 -1 -1 -1
Read Memory 600001BC=-1 -1 -1 -1
Read Memory 600001C0=-1 -1 -1 -1
Read Memory 600001C4=-1 -1 -1 -1
Read Memory 600001C8=-1 -1 -1 -1
Read Memory 600001CC=-1 -1 -1 -1
Read Memory 600001D0=-1 -1 -1 -1
Read Memory 600001D4=-1 -1 -1 -1
Read Memory 600001D8=-1 -1 -1 -1
Read Memory 600001DC=-1 -1 -1 -1
Read Memory 600001E0=-1 -1 -1 -1
Read Memory 600001E4=-1 -1 -1 -1
Read Memory 600001E8=-1 -1 -1 -1
Read Memory 600001EC=-1 -1 -1 -1
Read Memory 600001F0=-1 -1 -1 -1
Read Memory 600001F4=-1 -1 -1 -1
Read Memory 600001F8=-1 -1 -1 -1
Read Memory 600001FC=-1 -1 -1 -1
>Stop
sending message number 04
<kDSReplyNAK !!!!!!!!!!!!!!!!!!
received message number 04
kDSReplyPacketSizeError
>Ack Notify Stopped
sending message number 02
>Disconnect
sending message number 05
<kDSReplyACK
received message number 05
kDSReplyNoError
>Close
>End+Exit

I just successfully got this to work on my E65 with firmware:
2.0633.65.01
03-10-07
RM-208
Nokia E65

Step 1:
I have the exact same output as yours above using http://www.ipmart-forum.com/showpost.php?p=1903987&postcount=86 approach.
RESULT = FAILED.

Step 2:
Next I tried the http://www.ipmart-forum.com/showpost.php?p=1896661&postcount=2 approach including the HelloCarbide approach outline in step 7.1, not too sure what it does anyway.
RESULT = FAILED.

Step 3:
Thereafter I tried the Profiler steps.
RESULT = FAILED

Step 4:
Lastly I repeat Step 1 above on the PY script. One thing for sure, I did not see any "candidate" result. The PY output was different this time from the above. Something like this with FF rather than -1.
.
.
Read Memory 600001F4=FF FF FF FF
Read Memory 600001F8=FF FF FF FF
Read Memory 600001FC=FF FF FF FF
.
.
.
RESULT = SUCCESS! Run X-plore to confirm C:\Sys\bin is accessible.

Step 5:
Copy CProfDriver_SISX.ldd to C:\Sys\bin\CProfDriver_SISX.ldd. (using preFP1 version)

Step 6:
Install CapsOnOff and after several reboots of testing. I can access C:\Sys\bin anytime with CapsOnOff features.

I am just glad it works now! :excited:

bAsem
4th April 2008, 20:41
wow o it worked for ya at the end .. good for u dude

rudko
4th April 2008, 21:39
:ilove::ilove::ilove: thanx work E65

kevinh
4th April 2008, 23:01
i try using f-explorer it work well bu when i using
x-plore
i didn't find any private folder either in phone memory or memory card
could you help me?

bAsem
4th April 2008, 23:17
yeah press 0 in x-plore to get to the settings and then check "show hidden files"
and "show system files/folders" now u should be able to view them if u have applied the hack correctly

Fannybaws
5th April 2008, 04:17
I've got an N95. I'm going to try this. Just a couple of questions about the data on the phones memory and the settings? Are these lost if the phone is flashed or does the phone remain unchanged just no permissions

sylencegsm
5th April 2008, 04:22
And in e90 works?

Embehu
5th April 2008, 08:52
8.2) If you have CodeWarrior and know how to use it, it is better.
Load any program you have (HelloWorld.mmp is perfect) and start a mobile debugging session:
The target should be GCCE UDEB .
In its settings->Remote Debugging->Connection = Symbian Metro TRK
Same window->Edit Connection->Connection Type=Serial ; Port = COM6
Same window->Remote dowload path = c:\
settings->Remote Download-> Remove any file here
Remember that, because of security, applications can't be downloaded into c:\sys\bin , so they
need to be installed before. I do this manually.

i'm sorry 4 my poor english but i don't understand this step. how can i down load mobile debugging program. I can't down CodeWarrior or symbian from home site. anyone can attach these file 2 me!
thanks so much!

bAsem
5th April 2008, 09:07
they are not needed for the hack .. its just for advanced users .. skip that step

abhi_6680
5th April 2008, 12:01
yup it works on my n95 21.0.016 and i am having problems with capsonoff app , it doesn't turn caps on or off , i wonder why , probably i installed it with caps off so some hash calc error might be the cause , will figure it out soon

PHoeZies
5th April 2008, 12:41
caps on/off not a problem if u can use profiler instead.. same function.

tolive
5th April 2008, 16:22
thx mate working well on N95-1 & N95-2
with also last xplore "patched" no more using capsoff (except for network sharing :d).
great share +++

aera
5th April 2008, 18:44
help p-lz how can save my hack...

aera
5th April 2008, 18:44
after restart i lost all

wojtaliban
5th April 2008, 18:53
U have to use modded ver of x-plore + modo apps uploaded by Disabled :)

aera
5th April 2008, 19:18
Can U More Info Modo Apps????? What>??? Other Modo App,,,,,, And I Install Modded Where Can Find It>>??

amirmumtaz
5th April 2008, 21:42
Hey guys.. I need some help here......

After installing the TRK file... I ran it and it came up with the bluetooth error thing......
Now I went into the options and changed the bluetooth to USB..
The port was 1 by default........now here where I screwed up.....
I accidently changed the value from 1 to 18 and now the application wont work......
As soon as I try to run it, my phone hangs up and reboot. I have uninstalled it many times and tried to install it back and run, still same problem........
Any help would be appreciated ........ I am using N76!
Thanks guys!

bAsem
5th April 2008, 21:49
very weird issue .. but i dont think its the cause of the restarts .. do u have caps on and off installed .. if u do try removing them ..

amirmumtaz
5th April 2008, 21:51
I am sorry bro.... what is caps on and off? :(
So I guess I dnt have it installed...... I dont even know what it is...

amirmumtaz
5th April 2008, 21:53
It was working fine when I installed it for the first time, it started acting up as soon as I changed the port from 1 to something else..... couldnt get it back... cant even start the application so I would change the port back to 1

amirmumtaz
5th April 2008, 22:00
Is there anyway to start your phone in some kind of safe mode like windows so that I might be able to run that application and try to figure something out??? hELPPPPPP

aera
5th April 2008, 22:04
thes problem is caps??? on off?

bAsem
5th April 2008, 22:05
well first of all stop spamming the thread with multiple posts .. second i dont think there is a safe mode .. third if ur really disperate to get it to work then u could format ur phone memory and start fresh .. sorry i cant help u more because its the first time i heard that complaint .. maybe u could try reinstalling to memory card > restart and then reinstall to phone memory again .. try it

chatanoog
5th April 2008, 22:39
can sumone help me please...i have a E61, ive been trying to get this working for days now. After i run the script it ends but doesnt work...heres my log can any one help?



thanks

robgc
5th April 2008, 23:23
Hi There, i own a Nokia E65 latest Firmware version. Iīve seen hack is possible with such mobile and firmware version, but i have the following problem. i hope someone can help me:
Iīve installed MetroTRK and it has no icon (weird). I run it and the there is no try of the program to connect, itīs not freezed but it doesnīt work. in settings i have USB, Bluetooth, itīs the same..... no connection procedure... no error in ports, nothing! and iīve seen in tutorials screenshots with a "moon", and my program have no "moon" icon.iīve tried with 2.7 and 2.85 version... unsuccessfully :-( everyone can get this software to work, but i canīt.
Thank you in advance for your replies.
Best,
Robreto.

bAsem
6th April 2008, 01:50
e65 is prefp1 so use the prefp1 trk .. i think that is ur problem buddy

amirmumtaz
6th April 2008, 03:35
@basem......
Hey brother relax....
People, I would like to officially announce that my brother basem here helped me with everything.... I was able to do the crack, and its perfectly working on my N76!
Thanks a lot basem and other helpers...
Long live IPMART!

bAsem
6th April 2008, 03:52
@basem......
Hey brother relax....
People, I would like to officially announce that my brother basem here helped me with everything.... I was able to do the crack, and its perfectly working on my N76!
Thanks a lot basem and other helpers...
Long live IPMART!

lol . Am very relaxed thank u bro . . Its just that it took u 3 posts to describe ur problem . . And am very glad it worked for u man . . Could u please tell us what exactly fixed ur problem

amirmumtaz
6th April 2008, 05:22
yeah sure...... actually what happened was that I was trying to run the (hack_perms_s60v3_FP1.py) file through python compiler.... and for some reasons it was not changing the values that you mentioned in your post...
so all I did was instead of opening (hack_perms_s60v3.py) with the compiler... I just simply double clicked it and it ran perfectly and patched the destination.. Offcourse I had to edit the above mentioned file first in the compiler to give the proper serial port...
and I followed the rest of the procedure very very carefully and voila!
Caps on/Caps off are working perfectly fine too.

Thanks again man! I really appreciated your help... already got webgate advanced device lock working on my phone perfectly!
Thank u thank u thank u! file through python compiler.... and for some reasons it was not showing the values that you mentioned in your post...
so all I did was instead of opening hack_perms_s60v3.py with the compiler... I just simply double clicked it and it ran perfectly and patched the destination.. Offcourse I had to edit the above mentioned file first in the compiler to give the proper serial port...
and I followed the rest of the procedure very very carefully and voila!
Thanks again man! I really appreciated your help... already got webgate advanced device lock working on my phone perfectly!
Thank u thank u thank u!:friends:

kalechristos
6th April 2008, 08:40
here is what u need .. also a quote from mr.FCA00000 at SF forums ... i just wanted to share this great news with all ipmart users ...


"" First of all: you can get the needed files from

http://fca00000.googlepages.com/hack_perms_s60v3.rar(i attached them here)




Hi
after the connection goes well i run hack_perms_s60v3.py
and i get this log:
PythonWin 2.5.1 (r251:54863, May 1 2007, 17:47:05) [MSC v.1310 32 bit (Intel)] on win32.
Portions Copyright 1994-2006 Mark Hammond - see 'Help/About PythonWin' for further copyright information.
>>> Using port:
COM8
>Ping
sending message number 00
<kDSReplyACK
received message number 00
kDSReplyNoError
>Connect
sending message number 01
<kDSReplyACK
received message number 01
kDSReplyNoError
>Create Item
sending message number 02
<kDSReplyACK
received message number 02
kDSReplyNoError
ProcessID=06CB ThreadID=06CC
>Read Memory 0x60000000
Read Memory at 60000000=60 00 00 00
sending message number 03
<kDSReplyACK
received message number 03
kDSReplyOsError
Read Memory 60000000=-1 -1 -1 -1
Read Memory 60000004=-1 -1 -1 -1
Read Memory 60000008=-1 -1 -1 -1
Read Memory 6000000C=-1 -1 -1 -1
Read Memory 60000010=-1 -1 -1 -1
Read Memory 60000014=-1 -1 -1 -1
Read Memory 60000018=-1 -1 -1 -1
Read Memory 6000001C=-1 -1 -1 -1
Read Memory 60000020=-1 -1 -1 -1
Read Memory 60000024=-1 -1 -1 -1
Read Memory 60000028=-1 -1 -1 -1
Read Memory 6000002C=-1 -1 -1 -1
Read Memory 60000030=-1 -1 -1 -1
Read Memory 60000034=-1 -1 -1 -1
Read Memory 60000038=-1 -1 -1 -1
Read Memory 6000003C=-1 -1 -1 -1
Read Memory 60000040=-1 -1 -1 -1
Read Memory 60000044=-1 -1 -1 -1
Read Memory 60000048=-1 -1 -1 -1
Read Memory 6000004C=-1 -1 -1 -1
Read Memory 60000050=-1 -1 -1 -1
Read Memory 60000054=-1 -1 -1 -1
Read Memory 60000058=-1 -1 -1 -1
Read Memory 6000005C=-1 -1 -1 -1
Read Memory 60000060=-1 -1 -1 -1
Read Memory 60000064=-1 -1 -1 -1
Read Memory 60000068=-1 -1 -1 -1
Read Memory 6000006C=-1 -1 -1 -1
Read Memory 60000070=-1 -1 -1 -1
Read Memory 60000074=-1 -1 -1 -1
Read Memory 60000078=-1 -1 -1 -1
Read Memory 6000007C=-1 -1 -1 -1
Read Memory 60000080=-1 -1 -1 -1
Read Memory 60000084=-1 -1 -1 -1
Read Memory 60000088=-1 -1 -1 -1
Read Memory 6000008C=-1 -1 -1 -1
Read Memory 60000090=-1 -1 -1 -1
Read Memory 60000094=-1 -1 -1 -1
Read Memory 60000098=-1 -1 -1 -1
Read Memory 6000009C=-1 -1 -1 -1
Read Memory 600000A0=-1 -1 -1 -1
Read Memory 600000A4=-1 -1 -1 -1
Read Memory 600000A8=-1 -1 -1 -1
Read Memory 600000AC=-1 -1 -1 -1
Read Memory 600000B0=-1 -1 -1 -1
Read Memory 600000B4=-1 -1 -1 -1
Read Memory 600000B8=-1 -1 -1 -1
Read Memory 600000BC=-1 -1 -1 -1
Read Memory 600000C0=-1 -1 -1 -1
Read Memory 600000C4=-1 -1 -1 -1
Read Memory 600000C8=-1 -1 -1 -1
Read Memory 600000CC=-1 -1 -1 -1
Read Memory 600000D0=-1 -1 -1 -1
Read Memory 600000D4=-1 -1 -1 -1
Read Memory 600000D8=-1 -1 -1 -1
Read Memory 600000DC=-1 -1 -1 -1
Read Memory 600000E0=-1 -1 -1 -1
Read Memory 600000E4=-1 -1 -1 -1
Read Memory 600000E8=-1 -1 -1 -1
Read Memory 600000EC=-1 -1 -1 -1
Read Memory 600000F0=-1 -1 -1 -1
Read Memory 600000F4=-1 -1 -1 -1
Read Memory 600000F8=-1 -1 -1 -1
Read Memory 600000FC=-1 -1 -1 -1
>Stop
sending message number 04
showFrameChecksum-incorrect:-1
<kDSReplyACK
received message number 04
kDSReplyNoError
>Ack Notify Stopped
sending message number 02
>Disconnect
sending message number 05
<kDSReplyACK
received message number 05
kDSReplyNoError
>Close
>End+Exit
Using port:
COM8
>Ping
sending message number 00
<kDSReplyACK
received message number 00
kDSReplyNoError
>Connect
sending message number 01
<kDSReplyACK
received message number 01
kDSReplyNoError
>Create Item
sending message number 02
<kDSReplyACK
received message number 02
kDSReplyNoError
ProcessID=06CE ThreadID=06CF
>Read Memory 0x60000000
Read Memory at 60000000=60 00 00 00
sending message number 03
<kDSReplyACK
received message number 03
kDSReplyOsError
Read Memory 60000000=-1 -1 -1 -1
Read Memory 60000004=-1 -1 -1 -1
Read Memory 60000008=-1 -1 -1 -1
Read Memory 6000000C=-1 -1 -1 -1
Read Memory 60000010=-1 -1 -1 -1
Read Memory 60000014=-1 -1 -1 -1
Read Memory 60000018=-1 -1 -1 -1
Read Memory 6000001C=-1 -1 -1 -1
Read Memory 60000020=-1 -1 -1 -1
Read Memory 60000024=-1 -1 -1 -1
Read Memory 60000028=-1 -1 -1 -1
Read Memory 6000002C=-1 -1 -1 -1
Read Memory 60000030=-1 -1 -1 -1
Read Memory 60000034=-1 -1 -1 -1
Read Memory 60000038=-1 -1 -1 -1
Read Memory 6000003C=-1 -1 -1 -1
Read Memory 60000040=-1 -1 -1 -1
Read Memory 60000044=-1 -1 -1 -1
Read Memory 60000048=-1 -1 -1 -1
Read Memory 6000004C=-1 -1 -1 -1
Read Memory 60000050=-1 -1 -1 -1
Read Memory 60000054=-1 -1 -1 -1
Read Memory 60000058=-1 -1 -1 -1
Read Memory 6000005C=-1 -1 -1 -1
Read Memory 60000060=-1 -1 -1 -1
Read Memory 60000064=-1 -1 -1 -1
Read Memory 60000068=-1 -1 -1 -1
Read Memory 6000006C=-1 -1 -1 -1
Read Memory 60000070=-1 -1 -1 -1
Read Memory 60000074=-1 -1 -1 -1
Read Memory 60000078=-1 -1 -1 -1
Read Memory 6000007C=-1 -1 -1 -1
Read Memory 60000080=-1 -1 -1 -1
Read Memory 60000084=-1 -1 -1 -1
Read Memory 60000088=-1 -1 -1 -1
Read Memory 6000008C=-1 -1 -1 -1
Read Memory 60000090=-1 -1 -1 -1
Read Memory 60000094=-1 -1 -1 -1
Read Memory 60000098=-1 -1 -1 -1
Read Memory 6000009C=-1 -1 -1 -1
Read Memory 600000A0=-1 -1 -1 -1
Read Memory 600000A4=-1 -1 -1 -1
Read Memory 600000A8=-1 -1 -1 -1
Read Memory 600000AC=-1 -1 -1 -1
Read Memory 600000B0=-1 -1 -1 -1
Read Memory 600000B4=-1 -1 -1 -1
Read Memory 600000B8=-1 -1 -1 -1
Read Memory 600000BC=-1 -1 -1 -1
Read Memory 600000C0=-1 -1 -1 -1
Read Memory 600000C4=-1 -1 -1 -1
Read Memory 600000C8=-1 -1 -1 -1
Read Memory 600000CC=-1 -1 -1 -1
Read Memory 600000D0=-1 -1 -1 -1
Read Memory 600000D4=-1 -1 -1 -1
Read Memory 600000D8=-1 -1 -1 -1
Read Memory 600000DC=-1 -1 -1 -1
Read Memory 600000E0=-1 -1 -1 -1
Read Memory 600000E4=-1 -1 -1 -1
Read Memory 600000E8=-1 -1 -1 -1
Read Memory 600000EC=-1 -1 -1 -1
Read Memory 600000F0=-1 -1 -1 -1
Read Memory 600000F4=-1 -1 -1 -1
Read Memory 600000F8=-1 -1 -1 -1
Read Memory 600000FC=-1 -1 -1 -1
>Stop
sending message number 04
showFrameChecksum-incorrect:-1
<kDSReplyACK
received message number 04
kDSReplyNoError
>Ack Notify Stopped
sending message number 02
>Disconnect
sending message number 05
<kDSReplyACK
received message number 05
kDSReplyNoError
>Close
>End+Exit

Please let me know what the problem is.
My Phone is N93i

Thanks

PHoeZies
6th April 2008, 09:37
@christos: check ur port settings.Also check ur trk n the hackperms. Make sure u use the correct one with ur phone type.

Ru Vain
6th April 2008, 14:11
Excelenta assitance !

Ru Vain
6th April 2008, 14:12
Excelent assitance

amirmumtaz
6th April 2008, 15:38
@basem....

Hey mate, I have got a question?
Some applications are giving me errors!
Like webgate advance auto lock does not let me change the default password and always executes an error saying "Unable to execute file for security reasons"Another one, webgate voice inbox wont let me turn on the answering machine and executes the same error...
I was wondering whats up with that? Does it has something to do with the hack or do u think that the applications are corrupted or something???
Help would be appreciated, like always!
Keep Ipmart rocking!:ilove:

bAsem
6th April 2008, 17:32
If u signed it with ur own certificate then maybe u can sign it using the tuto made by SWANKYLEO . Go to the third post on the first page for the link if u dont know it already.

Trasho
6th April 2008, 17:59
Hi!

Anybody can help me, how can i write to the Z: in N95-1 ? Because i wanna re-write some files. :) Thx the Help!

bAsem
6th April 2008, 18:31
well i dont think u can actually write to z: but i think FCA00000 is trying to make a patch to write z: to ram .. which he says is very difficult so ur gonna have to wait a while for it

Trasho
6th April 2008, 18:37
Understand. Thx. I wait for a patch : )

amirmumtaz
6th April 2008, 18:42
@basem.....

Bro I already did that... I have the caps on and caps off perfectly working on my phone........

This is my theory... I think the problem is with the crack!
Any application that comes with a crack.sis file along with it is creating problems... Other apps with keygens are working perfectly!

Any suggestions?

apung
6th April 2008, 20:10
work to 6120c ( FP1 )

nice .....

johnmacca
6th April 2008, 20:35
guys do i need to run the python script everytime i reboot phone?.... got it so i can see the files in private and sys\bin folder but when i restart phone not showing up then.

thanks guys

etucneib
6th April 2008, 20:43
not at all .. i just did it all in less than 20 minutes man ...

if there are any queries please ask maybe i can help ..


hey mate i tried everything it on my nokia e90 communicator but i failed...
i try to download and intalll it on my phone the trk.. it is connected and try to change the com port to 10 in hack perm .py but when i double click it, its just stay and read the memory and after disconnect theres no -----candidate---- which is the sign of success.. what did i do wrong?

etucneib
6th April 2008, 20:49
Hi
after the connection goes well i run hack_perms_s60v3.py
and i get this log:
PythonWin 2.5.1 (r251:54863, May 1 2007, 17:47:05) [MSC v.1310 32 bit (Intel)] on win32.
Portions Copyright 1994-2006 Mark Hammond - see 'Help/About PythonWin' for further copyright information.
>>> Using port:
COM8
>Ping
sending message number 00
<kDSReplyACK
received message number 00
kDSReplyNoError
>Connect
sending message number 01
<kDSReplyACK
received message number 01
kDSReplyNoError
>Create Item
sending message number 02
<kDSReplyACK
received message number 02
kDSReplyNoError
ProcessID=06CB ThreadID=06CC
>Read Memory 0x60000000
Read Memory at 60000000=60 00 00 00
sending message number 03
<kDSReplyACK
received message number 03
kDSReplyOsError
Read Memory 60000000=-1 -1 -1 -1
Read Memory 60000004=-1 -1 -1 -1
Read Memory 60000008=-1 -1 -1 -1
Read Memory 6000000C=-1 -1 -1 -1
Read Memory 60000010=-1 -1 -1 -1
Read Memory 60000014=-1 -1 -1 -1
Read Memory 60000018=-1 -1 -1 -1
Read Memory 6000001C=-1 -1 -1 -1
Read Memory 60000020=-1 -1 -1 -1
Read Memory 60000024=-1 -1 -1 -1
Read Memory 60000028=-1 -1 -1 -1
Read Memory 6000002C=-1 -1 -1 -1
Read Memory 60000030=-1 -1 -1 -1
Read Memory 60000034=-1 -1 -1 -1
Read Memory 60000038=-1 -1 -1 -1
Read Memory 6000003C=-1 -1 -1 -1
Read Memory 60000040=-1 -1 -1 -1
Read Memory 60000044=-1 -1 -1 -1
Read Memory 60000048=-1 -1 -1 -1
Read Memory 6000004C=-1 -1 -1 -1
Read Memory 60000050=-1 -1 -1 -1
Read Memory 60000054=-1 -1 -1 -1
Read Memory 60000058=-1 -1 -1 -1
Read Memory 6000005C=-1 -1 -1 -1
Read Memory 60000060=-1 -1 -1 -1
Read Memory 60000064=-1 -1 -1 -1
Read Memory 60000068=-1 -1 -1 -1
Read Memory 6000006C=-1 -1 -1 -1
Read Memory 60000070=-1 -1 -1 -1
Read Memory 60000074=-1 -1 -1 -1
Read Memory 60000078=-1 -1 -1 -1
Read Memory 6000007C=-1 -1 -1 -1
Read Memory 60000080=-1 -1 -1 -1
Read Memory 60000084=-1 -1 -1 -1
Read Memory 60000088=-1 -1 -1 -1
Read Memory 6000008C=-1 -1 -1 -1
Read Memory 60000090=-1 -1 -1 -1
Read Memory 60000094=-1 -1 -1 -1
Read Memory 60000098=-1 -1 -1 -1
Read Memory 6000009C=-1 -1 -1 -1
Read Memory 600000A0=-1 -1 -1 -1
Read Memory 600000A4=-1 -1 -1 -1
Read Memory 600000A8=-1 -1 -1 -1
Read Memory 600000AC=-1 -1 -1 -1
Read Memory 600000B0=-1 -1 -1 -1
Read Memory 600000B4=-1 -1 -1 -1
Read Memory 600000B8=-1 -1 -1 -1
Read Memory 600000BC=-1 -1 -1 -1
Read Memory 600000C0=-1 -1 -1 -1
Read Memory 600000C4=-1 -1 -1 -1
Read Memory 600000C8=-1 -1 -1 -1
Read Memory 600000CC=-1 -1 -1 -1
Read Memory 600000D0=-1 -1 -1 -1
Read Memory 600000D4=-1 -1 -1 -1
Read Memory 600000D8=-1 -1 -1 -1
Read Memory 600000DC=-1 -1 -1 -1
Read Memory 600000E0=-1 -1 -1 -1
Read Memory 600000E4=-1 -1 -1 -1
Read Memory 600000E8=-1 -1 -1 -1
Read Memory 600000EC=-1 -1 -1 -1
Read Memory 600000F0=-1 -1 -1 -1
Read Memory 600000F4=-1 -1 -1 -1
Read Memory 600000F8=-1 -1 -1 -1
Read Memory 600000FC=-1 -1 -1 -1
>Stop
sending message number 04
showFrameChecksum-incorrect:-1
<kDSReplyACK
received message number 04
kDSReplyNoError
>Ack Notify Stopped
sending message number 02
>Disconnect
sending message number 05
<kDSReplyACK
received message number 05
kDSReplyNoError
>Close
>End+Exit
Using port:
COM8
>Ping
sending message number 00
<kDSReplyACK
received message number 00
kDSReplyNoError
>Connect
sending message number 01
<kDSReplyACK
received message number 01
kDSReplyNoError
>Create Item
sending message number 02
<kDSReplyACK
received message number 02
kDSReplyNoError
ProcessID=06CE ThreadID=06CF
>Read Memory 0x60000000
Read Memory at 60000000=60 00 00 00
sending message number 03
<kDSReplyACK
received message number 03
kDSReplyOsError
Read Memory 60000000=-1 -1 -1 -1
Read Memory 60000004=-1 -1 -1 -1
Read Memory 60000008=-1 -1 -1 -1
Read Memory 6000000C=-1 -1 -1 -1
Read Memory 60000010=-1 -1 -1 -1
Read Memory 60000014=-1 -1 -1 -1
Read Memory 60000018=-1 -1 -1 -1
Read Memory 6000001C=-1 -1 -1 -1
Read Memory 60000020=-1 -1 -1 -1
Read Memory 60000024=-1 -1 -1 -1
Read Memory 60000028=-1 -1 -1 -1
Read Memory 6000002C=-1 -1 -1 -1
Read Memory 60000030=-1 -1 -1 -1
Read Memory 60000034=-1 -1 -1 -1
Read Memory 60000038=-1 -1 -1 -1
Read Memory 6000003C=-1 -1 -1 -1
Read Memory 60000040=-1 -1 -1 -1
Read Memory 60000044=-1 -1 -1 -1
Read Memory 60000048=-1 -1 -1 -1
Read Memory 6000004C=-1 -1 -1 -1
Read Memory 60000050=-1 -1 -1 -1
Read Memory 60000054=-1 -1 -1 -1
Read Memory 60000058=-1 -1 -1 -1
Read Memory 6000005C=-1 -1 -1 -1
Read Memory 60000060=-1 -1 -1 -1
Read Memory 60000064=-1 -1 -1 -1
Read Memory 60000068=-1 -1 -1 -1
Read Memory 6000006C=-1 -1 -1 -1
Read Memory 60000070=-1 -1 -1 -1
Read Memory 60000074=-1 -1 -1 -1
Read Memory 60000078=-1 -1 -1 -1
Read Memory 6000007C=-1 -1 -1 -1
Read Memory 60000080=-1 -1 -1 -1
Read Memory 60000084=-1 -1 -1 -1
Read Memory 60000088=-1 -1 -1 -1
Read Memory 6000008C=-1 -1 -1 -1
Read Memory 60000090=-1 -1 -1 -1
Read Memory 60000094=-1 -1 -1 -1
Read Memory 60000098=-1 -1 -1 -1
Read Memory 6000009C=-1 -1 -1 -1
Read Memory 600000A0=-1 -1 -1 -1
Read Memory 600000A4=-1 -1 -1 -1
Read Memory 600000A8=-1 -1 -1 -1
Read Memory 600000AC=-1 -1 -1 -1
Read Memory 600000B0=-1 -1 -1 -1
Read Memory 600000B4=-1 -1 -1 -1
Read Memory 600000B8=-1 -1 -1 -1
Read Memory 600000BC=-1 -1 -1 -1
Read Memory 600000C0=-1 -1 -1 -1
Read Memory 600000C4=-1 -1 -1 -1
Read Memory 600000C8=-1 -1 -1 -1
Read Memory 600000CC=-1 -1 -1 -1
Read Memory 600000D0=-1 -1 -1 -1
Read Memory 600000D4=-1 -1 -1 -1
Read Memory 600000D8=-1 -1 -1 -1
Read Memory 600000DC=-1 -1 -1 -1
Read Memory 600000E0=-1 -1 -1 -1
Read Memory 600000E4=-1 -1 -1 -1
Read Memory 600000E8=-1 -1 -1 -1
Read Memory 600000EC=-1 -1 -1 -1
Read Memory 600000F0=-1 -1 -1 -1
Read Memory 600000F4=-1 -1 -1 -1
Read Memory 600000F8=-1 -1 -1 -1
Read Memory 600000FC=-1 -1 -1 -1
>Stop
sending message number 04
showFrameChecksum-incorrect:-1
<kDSReplyACK
received message number 04
kDSReplyNoError
>Ack Notify Stopped
sending message number 02
>Disconnect
sending message number 05
<kDSReplyACK
received message number 05
kDSReplyNoError
>Close
>End+Exit

Please let me know what the problem is.
My Phone is N93i

Thanks



i think this is same what is happening on my E90 anyone help us pla.... thanks

s1s1s1
6th April 2008, 21:25
guys do i need to run the python script everytime i reboot phone?.... got it so i can see the files in private and sys\bin folder but when i restart phone not showing up then.

thanks guys

Good to hear that your PY script works for you. You only need to run the PY script once to gain access to c:\sys\bin.

1. Run the PY script to gain access to "C:\sys\bin".

2. I assume you are using X-plore. Confirmed you have access to "C:\sys\bin\", extract those files (CProfDriver_SISX.ldd, CapsOn.sisx & CapsOff.sisx) that apply to you either from folder preFP1 of FP1. Download from http://FCA00000.googlepages.com/CapsOnOFF.rar

3. copy the right CProfDriver_SISX.ldd from CapsOnOff.RAR into "C:\sys\bin\"

4. Set the attribute of "C:\sys\bin\CProfDriver_SISX.ldd" to READ ONLY.

5. install CapsOn.sisx (running CapsOn means in normal mode)

6. install CapsOff.sisx (running CapsOff means hacked mode and you can access C:\sys\bin.)

You should be able to access without running the PY script anymore.

Cheers,
S1

aera
6th April 2008, 22:24
Good to hear that your PY script works for you. You only need to run the PY script once to gain access to c:\sys\bin.

1. Run the PY script to gain access to "C:\sys\bin".

2. I assume you are using X-plore. Confirmed you have access to "C:\sys\bin\", extract those files (CProfDriver_SISX.ldd, CapsOn.sisx & CapsOff.sisx) that apply to you either from folder preFP1 of FP1. Download from http://FCA00000.googlepages.com/CapsOnOFF.rar

3. copy the right CProfDriver_SISX.ldd from CapsOnOff.RAR into "C:\sys\bin\"

4. Set the attribute of "C:\sys\bin\CProfDriver_SISX.ldd" to READ ONLY.

5. install CapsOn.sisx (running CapsOn means in normal mode)

6. install CapsOff.sisx (running CapsOff means hacked mode and you can access C:\sys\bin.)

You should be able to access without running the PY script anymore.

Cheers,
S1

bro u install profile?>?what tk 2.7(01) or 2.85 ..... cabride ?????

amirmumtaz
6th April 2008, 23:36
Originally Posted by kalechristos
Hi
after the connection goes well i run hack_perms_s60v3.py
and i get this log:

<kDSReplyACK
received message number 05
kDSReplyNoError
>Close
>End+Exit

Please let me know what the problem is.
My Phone is N93i

Thanks


Mates...... Make sure you are using the right version of hack permissions..... If u tried the hack perm for Fp1 phones and it displayed this log, try using the hack perm for PreFp1 phones..... I hope it will resolve your issues...

piroxicam
7th April 2008, 01:58
Hi all!
Yesterday I've managed to apply successfully this hack. But today, this hack does not work any more. I use the CapsOff and CapsOn icons but the trick does not work. I've tried to apply again the initial hack, and I still get the message "!!!!!!!!!!!!!!!!candidate!!!!!!!!!!!!!!!" but when I go to X-plore, I do not have access to the private folders.

Does anyone have had a similar problem? I have a N80.

amirmumtaz
7th April 2008, 02:04
@piroxicam........

mate.... I am not sure about this problem...
Its funny I never get to see that candidate message and yet my hack is working perfect!
I hope someone more senior might help! Good luck!

s1s1s1
7th April 2008, 02:43
bro u install profile?>?what tk 2.7(01) or 2.85 ..... cabride ?????

As Johnmacca already had success with the hack, I did not elaborate further on the steps to get the PY script to work.

To prepare my PC to be able to execute PY script, I install:
1. ActivePython-2.5.1.1-win32-x86.msi in my PC.
2. pyserial-2.2.win32.exe in my PC.
3. Modify the hack_perms_s60v3.py according to my COM port setting.

For me on Nokia E65 (preFP1) I need to:
1. Install s60_3_0_app_trk_2_7.sisx in my phone memory c:

2. Install Carbide.sis in my phone memory c:

3. copy carbide.exe to my phone memory c:\ (Root of C: drive).

4. Ensure phone is connected via the USB cable and connected via PC Suite mode. Run TRK app on my phone. Change setting to USB connection instead of USB.

5. Run hack_perms_s60v3.py on the PC. The hack will be a success, as long as the "Read memory are all 00 00 00 00 or FF FF FF FF and not -1 -1 -1 -1 from my experience. I never had !!!candidate!!! thus far, the PY hack to access the c:\sys\bin folder was successful.

6. I assume you are using X-plore. Confirmed you have access to "C:\sys\bin\", extract those files (CProfDriver_SISX.ldd, CapsOn.sisx & CapsOff.sisx) that apply to you either from folder preFP1 of FP1. Download from http://FCA00000.googlepages.com/CapsOnOFF.rar

7. copy the right CProfDriver_SISX.ldd from CapsOnOff.RAR into "C:\sys\bin\"

8. Set the attribute of "C:\sys\bin\CProfDriver_SISX.ldd" to READ ONLY.

9. install CapsOn.sisx (running CapsOn means in normal mode)

10 install CapsOff.sisx (running CapsOff means hacked mode and you can access C:\sys\bin.)

You should be able to access without running the PY script anymore.

Cheers,
S1

s1s1s1
7th April 2008, 03:19
Hi all!
Yesterday I've managed to apply successfully this hack. But today, this hack does not work any more. I use the CapsOff and CapsOn icons but the trick does not work. I've tried to apply again the initial hack, and I still get the message "!!!!!!!!!!!!!!!!candidate!!!!!!!!!!!!!!!" but when I go to X-plore, I do not have access to the private folders.

Does anyone have had a similar problem? I have a N80.

Yo piroxicam,

I had this problem too. I am running on E65. I discovered that for whatever reason, the CProfDriver_SISX.ldd was missing from the c:\sys\bin\ folder. I was uninstalling the TRK and Carbide app on my phone earlier, not too sure if that removed the CProfDriver_SISX.ldd file.

You might want to confirm by:

1. Re-apply your hack to gain access to your phone again as you did successfully previously. (Sorry I am not too sure why you are not able to access when you have the !!!candidate!!! result. As for me I never had the !!!candidate!!! result, just make sure that your read memory output is 00 00 00 00 or FF FF FF FF. If it is -1 -1 -1 -1, chances are the hack failed.)

2. Once you get the initial hack successfully. Copy the right CProfDriver_SISX.ldd from CapsOnOff.RAR into "C:\sys\bin\"

3. Set the attribute of "C:\sys\bin\CProfDriver_SISX.ldd" to READ ONLY.

4. Reinstall CapsOn or CapsOff if you have uninstalled it earlier. Your phone should be back to "normal".

5. As I have set the attribute to READ ONLY, I uninstalled my TRK and Carbide app on my phone again and verify that the file C:\sys\bin\CProfDriver_SISX.ldd is still there. Rebooted twice and so far so good.

Hope this can help you solve your problem,
S1

kalechristos
7th April 2008, 04:14
@christos: check ur port settings.Also check ur trk n the hackperms. Make sure u use the correct one with ur phone type.

@PHoeZies:thanks 4 ur fast response.But i even used different com port settings
to ensure my problems.And about the correctness of the files i used the pre FP1 files,isn't Nokia N93 Pre FP1?

Thanks Alot

deilyn
7th April 2008, 12:06
help, ayuda, sos, n95-3 how create i not working plece (ayudenme no puedo entrar a la carpeta sys nada me ha funcionado)

tipu
7th April 2008, 12:52
Is there any way to do it with activefile because I tried this and it does not work, though it is working with xplorer and ybrowser

Can anyone tell how to install Activefile with manufactures abilities or unlock hidden files in it.

tipu
7th April 2008, 16:26
Can anyone tell how to install Activefile with manufactures abilities or unlock hidden files in it.

I have got it.
For everyone to install unsigned applications or with manufacture capabilities
http://www.ipmart-forum.com/showthread.php?&p=1913935#post1913935

jamesf1985
7th April 2008, 16:32
hi i have tried this ocer 10 times and still no success i am on firmware V21.0.016 RM-159 the latest i think can some one please help me Thanks in advance james

etucneib
7th April 2008, 18:18
is this working on e90? anybody here who hacked his e90? pls tell me what to do thanks.

fenerli47
7th April 2008, 19:14
i cant see my port number in my pc with n95 8gb. in my port number write this Port_#0001.Hub_#0002 USB plz help what can i do :(((

rkd
7th April 2008, 20:03
is this working on e90? anybody here who hacked his e90? pls tell me what to do thanks.

Yes, works fine :)

fenerli47
7th April 2008, 21:22
i cant see my port number in my pc with n95 8gb. in my port number write this Port_#0001.Hub_#0002 USB plz help what can i do :(((

cant anybody help:?????!:alasno::alasno:

etucneib
7th April 2008, 22:19
Yes, works fine :)



pls tell me how? and whats the file to use? is it the file for n95? pls help me i did all i could but i failed..

bAsem
7th April 2008, 22:37
pls tell me how? and whats the file to use? is it the file for n95? pls help me i did all i could but i failed..

e90 is fp1 so get the fp1 files .. should work for ya

etucneib
7th April 2008, 23:16
e90 is fp1 so get the fp1 files .. should work for ya


everything seems working thats what i did.. but when i go to xplore i cant open sys and private.... shame...

bAsem
7th April 2008, 23:51
did u remember to close the nokia pc suite .. could u post ur log out of python .

bAsem
8th April 2008, 00:24
attached a how to for dummies in the first page .. check it out .. could be usefull to u

aftek1
8th April 2008, 02:36
when running py scrip hack perms with trk running handset restarts n95 8gb v15
any ideas, tried diiff coms plus cables

rkd
8th April 2008, 03:02
cant anybody help:?????!:alasno::alasno:

Which Windows version do you use?
Normally you can get port number in device manager.
For WinXP it is: Start -> Control panel -> System -> Hardware -> Device Manager. Just expand COM & LPT and you'll get port number if it's connected properly.

rkd
8th April 2008, 03:13
pls tell me how? and whats the file to use? is it the file for n95? pls help me i did all i could but i failed..

I did following (for all steps use FP1 files!):
- installed python on PC
- connected E90 via USB in PC Suite mode
- installed and configured TRK-App on E90
- edited python script "hack_perms_s60v3_FP1.py" to right port number of E90 (check windows device manager for port number)
- ran hack_perms_s60v3_FP1.py
- copied CProfDriver_SISX.ldd for FP1 on phone to C:\sys\bin with Y-Browser
- installed CapsOff and CapsOn apps on phone
- uninstalled TRK-App, because no longer needed

That's it! For further detailed information please read instructions which came with needed files...

Click9666
8th April 2008, 07:29
How can I install "pyserial-2.2.win32" and "pywin32-210.win32-py2.5"
When I install the both app it so the dialog as pic attach..Could u hlep me ...
Which file that I must download to hack my 5700 XM ?and please check my pic for the serial port as picture attach.Is it right?Please detail for me I think I can try it...Thank for advance.....

Click9666
8th April 2008, 07:33
My serial port that I see when I disable PC suite...

Kays
8th April 2008, 07:38
How can I install "pyserial-2.2.win32" and "pywin32-210.win32-py2.5"
When I install the both app it so the dialog as pic attach..Could u hlep me ...
Which file that I must download to hack my 5700 XM ?and please check my pic for the serial port as picture attach.Is it right?Please detail for me I think I can try it...Thank for advance.....

You are missing this step

8.1) I made a program called hack_perms_s60v3.py
It is written in pyhton, so you need Python25 from www.python.org

direct link to python 2.52
http://www.python.org/ftp/python/2.5.2/python-2.5.2.msi

install this first and then "pyserial-2.2.win32" and "pywin32-210.win32-py2.5"

Click9666
8th April 2008, 12:09
You are missing this step


direct link to python 2.52
http://www.python.org/ftp/python/2.5.2/python-2.5.2.msi

install this first and then "pyserial-2.2.win32" and "pywin32-210.win32-py2.5"

I completed step 8.1.
And I don't know how to edit python script.
My phone is 5700XM. when I run python script it show"ser = serial.Serial(5) # I have COM6" What should I change to? Chagne Serial.Serial(5) to my port number...

Kays
8th April 2008, 13:12
I completed step 8.1.
And I don't know how to edit python script.
My phone is 5700XM. when I run python script it show"ser = serial.Serial(5) # I have COM6" What should I change to?

try this way to find your port number

LE: so U have COM2; edit the script and on the line ser = serial.Serial(5) # I have COM6 modify ser = serial.Serial(5) to ser = serial.Serial(1)

ShaWneS
8th April 2008, 14:34
Hey mates, I tried to hack N95-2 (FW 15), using Python 2.5.1.1 + pyserial + pywin32, running hack_perms_s60v3_fp1.py, I have running TRK on my phone ofcourse... My log:

>>> Using port:
COM3
>Ping
sending message number 00
<kDSReplyACK
received message number 00
kDSReplyNoError
>Connect
sending message number 01
<kDSReplyACK
received message number 01
kDSReplyNoError
>SupportMask
sending message number 02
<kDSReplyACK
received message number 02
kDSReplyNoError
Level=DS_PROTOCOL_RTOS. (OS-level debugger)
ProcessID=0001 ThreadID=0002
>Test 0xC8xxxxxx
Read Memory at C0000148=C0 00 01 48
sending message number 03
<kDSReplyACK
received message number 03
kDSReplyNoError
Read Memory C0000148=10 00 00 00
!!!!!!!!!!!!!!!!!!!!!!!!!!!candidate!!!!!!!!!!!!!! !!!
>Write Memory C0000148
write Memory at C0000148=C0 00 01 48
sending message number 04
<kDSReplyACK
received message number 04
kDSReplyNoError
>Disconnect
sending message number 05
<kDSReplyACK
received message number 05
kDSReplyNoError
>Close
>End+Exit

As you can see, I have candidate message, but I can't see hidden folders using X-Plore 1.22 or Active File... Any solution for my problem? Thanx very much!

:ilove:

bAsem
8th April 2008, 14:46
Try the other trk 2.8 . See if it helps

ShaWneS
8th April 2008, 15:01
Yeah I'm using 2.8, but still the same (hacking is ok, problem was in x-plore) I installed Sexplorer and it can view Private folder on C:\, but I can't write or copy to :-( how to do it able? Different file explorer?

bAsem
8th April 2008, 15:58
u could try modo .. see if it works for ya .. although xplore should be working fine ...

maybe u forgot to enable view of system and hidden files in xplore .. by pressing 0 in xplore

takashiro
8th April 2008, 16:14
can u tell me what is wrong with this ?

i follow all instruction but it appears like this ..what should i do with it ..i am using nokia n93

bAsem
8th April 2008, 16:18
i read on sf forums that that hack doesnt work on n93 i think ..

MatteoX
8th April 2008, 16:37
the hack work whit new firmware v20 of n82??

bAsem
8th April 2008, 16:44
yea it should .. why dont u try and tell us .. !!!!!!!!!!!!

ShaWneS
8th April 2008, 16:46
maybe u forgot to enable view of system and hidden files in xplore .. by pressing 0 in xplore

Yes, that was it! Now it works great! Thanks from Czech mate!!

bAsem
8th April 2008, 16:52
ur welcome buddy .. sometimes its the most obvious things that are difficult

mtaki
8th April 2008, 17:07
When I run "hack_perms_s60v3_FP1.py" my phone restarts! Can anybody help? plz
Model: Nokia N95
Firmware: v20.0.015

Edit: Now it works. Anybody having the same problem check your MetroTRK version only v2.8.5 worked for me.

r3g1st3r
8th April 2008, 18:13
Confirmed to work on 6120 classic (it's an FP1). :LoL:

I confirm also that the hack doesn't run correctly under vista, you need an XP.

reg

amirmumtaz
8th April 2008, 18:20
For people who are successful with the hack......

Since we have hacked our firmware and are able to access any file we want, I was wondernig if there was any way to change the NOKIA default keypad tone? You know the TON TON we are all sick of... Now my question is, is it possible to access the file that holds the information to that tone? Is it possible to replace that file with the one we want? I am pretty sure that file has to be an audio file. I wanna replace it with the sony ericsson tick ticks.... Please let me know if anyone has any info about this issue........
Thanks for your time!
cheers!

bAsem
8th April 2008, 18:29
For people who are successful with the hack......

Since we have hacked our firmware and are able to access any file we want, I was wondernig if there was any way to change the NOKIA default keypad tone? You know the TON TON we are all sick of... Now my question is, is it possible to access the file that holds the information to that tone? Is it possible to replace that file with the one we want? I am pretty sure that file has to be an audio file. I wanna replace it with the sony ericsson tick ticks.... Please let me know if anyone has any info about this issue........
Thanks for your time!
cheers!

well back in the day when i had my siemens sx1(greatest phone ever) siemens only symbian device attempt . That was possible via some firmware hacking and patching of z: to ram . But i dont think the new symbian can accept such hack . But maybe someone will succeed in that. Until that happens just dont use the keypad tones like me lol

waxzus
8th April 2008, 20:27
Hi all !

The hack using python or profiler application on the phone works fine. But I have never managed to make the two apps Capson and capsoff worked :-( I tried all the possible versions for FP1 in this topic and some others in the forum.

someone can help me ?

kamson
8th April 2008, 21:59
I've made the hack under vista so no need to install xp;)

mc22
8th April 2008, 23:09
very nice tips & application....thanks very much

eng_meds
9th April 2008, 00:36
I hope you can help me please
I have N80 but the app TRK did not connect and did not ask for connection even though the phone is connected in PC Suite mode to the computer and I followed the steps exactly

amirmumtaz
9th April 2008, 02:16
well back in the day when i had my siemens sx1(greatest phone ever) siemens only symbian device attempt . That was possible via some firmware hacking and patching of z: to ram . But i dont think the new symbian can accept such hack . But maybe someone will succeed in that. Until that happens just dont use the keypad tones like me lol

Yeah man I know.. I dont know why nokia dont think of something newer or better... you know, keyboard tone suck now!

My phone does not play that tone either... I like it mute:)

bAsem
9th April 2008, 03:26
I hope you can help me please
I have N80 but the app TRK did not connect and did not ask for connection even though the phone is connected in PC Suite mode to the computer and I followed the steps exactly

trk By default tries to use BlueTooth, so it might give an error because no available ports.
Options->Settings->Connection=USB
Options->Settings->Port=1
Options->Settings->Baud Rate=115200
Options->Connect should tell:
Welcome to TRK for Symbian OS
Status: Connected
PDD: NONE
LDD: EUSBC
CSY: ECACM
Port Number: 1
Baud rate: 115200

This is the most difficult step.
If you get
'Failed to open port.Error Code: -21'
this means that your PC is not talking to the mobile. This is the case when the driver is not installed.

so this means ur either using the wrong trk or u have not installed ur drivers correctly

Salford
9th April 2008, 04:18
When I run "hack_perms_s60v3.py" it runs some code in the cmd window then my phone restarts.

Any ideas what I'm doing wrong? Using a N95 as well. Changed the COM and serial to the correct numbers.

Click9666
9th April 2008, 06:04
Now I do success all step...Thank for all

Click9666
9th April 2008, 06:11
Hey mates, I tried to hack N95-2 (FW 15), using Python 2.5.1.1 + pyserial + pywin32, running hack_perms_s60v3_fp1.py, I have running TRK on my phone ofcourse... My log:

>>> Using port:
COM3
>Ping
sending message number 00
<kDSReplyACK
received message number 00
kDSReplyNoError
>Connect
sending message number 01
<kDSReplyACK
received message number 01
kDSReplyNoError
>SupportMask
sending message number 02
<kDSReplyACK
received message number 02
kDSReplyNoError
Level=DS_PROTOCOL_RTOS. (OS-level debugger)
ProcessID=0001 ThreadID=0002
>Test 0xC8xxxxxx
Read Memory at C0000148=C0 00 01 48
sending message number 03
<kDSReplyACK
received message number 03
kDSReplyNoError
Read Memory C0000148=10 00 00 00
!!!!!!!!!!!!!!!!!!!!!!!!!!!candidate!!!!!!!!!!!!!! !!!
>Write Memory C0000148
write Memory at C0000148=C0 00 01 48
sending message number 04
<kDSReplyACK
received message number 04
kDSReplyNoError
>Disconnect
sending message number 05
<kDSReplyACK
received message number 05
kDSReplyNoError
>Close
>End+Exit

As you can see, I have candidate message, but I can't see hidden folders using X-Plore 1.22 or Active File... Any solution for my problem? Thanx very much!

:ilove:

Did you enable Show hidden files and Show system file/folders in X-plore?

knblmmn
9th April 2008, 13:42
Hi,

Congrats for the work.
Finally full access to our phones.

But here's the thing.
For me it didn't work on N81, FP1 with latest firmware 11.0.045 (29 november 2007)

Let me explain what I've done/tried so far.

1) I was feeling lucky so I tried to do it via Bluetooth (not having the cable with me).
Apparently no serial port was available to run the .py (seemed to be linked to used bluetooth stack).

2) Since the "lucky" feeling apparently was wrong I started the described procedure via USB.

Installed PC suite
Installed Python on other pc
Modified .py with correct com
Installed TRK v1 on N81
Copied carbide to c:\ on N81
Connected with usb
Detected the com port
Closed PC suite
Ran TRK v1 on N81
Change to USB
Status connected
Run .Py Script
Here's the info returned when running the script:

Microsoft Windows XP [version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.

C:\Documents and Settings\...>hack_perms_s60v3_FP1.py
Using port:
COM6
>Ping
sending message number 00
<kDSReplyACK
received message number 00
kDSReplyNoError
>Connect
sending message number 01
Frame does not end with 0x7E:-1
showFrameChecksum-incorrect:-1
received message number -1
>SupportMask
sending message number 02
Traceback (most recent call last):
File "C:\Documents and Settings\...\hack_perms_s60v3_FP1.py", line
360, in <module>
sendFrame(ser,encodeHeaderCKFrame([0x05,iCommand,-1])) # SupportMask
File "C:\Documents and Settings\...\hack_perms_s60v3_FP1.py", line
197, in sendFrame
ser.write(chr(i))
File "C:\Python25\Lib\site-packages\serial\serialwin32.py", line 220, in write

err, n = win32file.WriteFile(self.hComPort, s, self._overlappedWrite)
pywintypes.error: (31, a device connected to your system does not work)

Then my N81 reboots.

Can somebody give me an idea of what is happening?

It seems to go wrong when receiving unexpected frame.

It looks like the .py tries to write to my N81, but receives an unexpected error that it cannot write and interprets it as a code 31 (device not working).

Does the .py script check for available memory?
Is the TRK not ok, not providing access?

Salford
9th April 2008, 14:12
Hi,

Congrats for the work.
Finally full access to our phones.

But here's the thing.
For me it didn't work on N81, FP1 with latest firmware 11.0.045 (29 november 2007)

Let me explain what I've done/tried so far.

1) I was feeling lucky so I tried to do it via Bluetooth (not having the cable with me).
Apparently no serial port was available to run the .py (seemed to be linked to used bluetooth stack).

2) Since the "lucky" feeling apparently was wrong I started the described procedure via USB.

Installed PC suite
Installed Python on other pc
Modified .py with correct com
Installed TRK v1 on N81
Copied carbide to c:\ on N81
Connected with usb
Detected the com port
Closed PC suite
Ran TRK v1 on N81
Change to USB
Status connected
Run .Py Script
Here's the info returned when running the script:


Then my N81 reboots.

Can somebody give me an idea of what is happening?

It seems to go wrong when receiving unexpected frame.

It looks like the .py tries to write to my N81, but receives an unexpected error that it cannot write and interprets it as a code 31 (device not working).

Does the .py script check for available memory?
Is the TRK not ok, not providing access?

I had problems last night and couldn't get it to work either. Then this morning I had another go at it, I thought it was something to do with python serial application as it just didn't seem to work.

So, I went to C:\Python25\Lib\site-packages\serial\ and then double clicked on serialwin32.py. Then I ran hack_perms_s60v3_FP1.py and all worked fine :D

So try going to that folder and enabling the serial python app, hopefully that will sort it out for you!!!

EDIT:
By the way, my problem was exactly the same as yours, having re-read what you put :) So you should be sorted if you do that mate.

knblmmn
9th April 2008, 14:35
Thanks Salford.

I will most certainly try it :-)

toadpole
9th April 2008, 16:26
Hey,

I'm having some problems connecting my phone to USB. My phone is an E70 2.0618.07.10, on Windows XP SP2. Here's what I'm doing:


Install App Trk on phone from s60_3_0_app_trk_2_8_7
Connect USB cable, select PC Suite mode on phone
Look in device manager for the Port number of my phone
Open App Trk on phone
Cancel the bluetooth search
Open settings
Select Port Number / USB Mode / Match Baud rate
Select Options -> ConnectOutput is:
Status: Not connected

Failed to open port.
Error Code: -21
Have tried:


Restarting Phone / PC
Removing port drivers and re-installing
Changing port numbers
Using the modem port number instead of the serial port number
Changing Baud rates to different values
Exiting PC Suite
Stopping PC Suite servicesNothing works. Am I doing something wrong? Do I need to configure any additional software on the phone / PC to make it work?

Would appreciate any insights. Thanks!

Salford
9th April 2008, 16:34
Hey,

I'm having some problems connecting my phone to USB. My phone is an E70 2.0618.07.10, on Windows XP SP2. Here's what I'm doing:


Install App Trk on phone from s60_3_0_app_trk_2_8_7
Connect USB cable, select PC Suite mode on phone
Look in device manager for the Port number of my phone
Open App Trk on phone
Cancel the bluetooth search
Open settings
Select Port Number / USB Mode / Match Baud rate
Select Options -> ConnectOutput is:
Status: Not connected

Failed to open port.
Error Code: -21
Have tried:


Restarting Phone / PC
Removing port drivers and re-installing
Changing port numbers
Using the modem port number instead of the serial port number
Changing Baud rates to different values
Exiting PC Suite
Stopping PC Suite servicesNothing works. Am I doing something wrong? Do I need to configure any additional software on the phone / PC to make it work?

Would appreciate any insights. Thanks!

When you plug your USB cable in, I presume you have then selected "Data Suite" on your phone?

Cause when this connection is made Trk will then be able to see your phone.

It is the USB connection which is vital to you.

toadpole
9th April 2008, 16:49
I think you mean 'PC Suite', not 'Data Suite', yes, I'm selecting PC Suite.

When you plug your USB cable in, I presume you have then selected "Data Suite" on your phone?

Cause when this connection is made Trk will then be able to see your phone.

It is the USB connection which is vital to you.

knightct
9th April 2008, 17:12
Does this hack have any other practical use eg turning off the flash on an N73/95 which many have complained about...?

Salford
9th April 2008, 17:16
I think you mean 'PC Suite', not 'Data Suite', yes, I'm selecting PC Suite.

My bad, I meant PC Suite. So you can use PC Suite as well when connected?

I just closed down all the icons related to pc suite in my system tray, and it connected without a problem.


Does this hack have any other practical use eg turning off the flash on an N73/95 which many have complained about...?

The ability to self sign applications using this hacked method, rather that going to Symbian Signed has to be the biggest practical use.

PHoeZies
9th April 2008, 17:31
toadpole bro, u forget to change the port in the py script.. Please check again the FAQ..

Salford
9th April 2008, 17:39
toadpole bro, u forget to change the port in the py script.. Please check again the FAQ..

He's not up to that stage, he's trying to connect "App Trk" first.

dnbfreak
9th April 2008, 18:52
Script on nokia n81 8gb don't work or i don't no.....
checksum incorrect....
please help....
http://promodj.ru/personell/27125/g44484/9ce7b37b74b5a3eeb9069f530bc27cb2.jpg

dnbfreak
9th April 2008, 19:12
Hack don't work on NOKIA 81 8gb
Script error (checksum incorrect)
http://promodj.ru/personell/27125/g44484/9ce7b37b74b5a3eeb9069f530bc27cb2.jpg

symbiansucks
9th April 2008, 20:39
Anyone can help make the PY script work with new E61 firmware?

FW 3.0633.09.04?

PY Script cant read memory.. returns all -1 values

PapaDocta
9th April 2008, 21:11
mate there is a thread discussing this hack... if you have any problems post it there, no need to create a new thread! thread merged

aug11
9th April 2008, 23:39
hi everyone! i'm new here. i was wondering where i can download this hack that everyone's talking about. i hope to hear from you guys soon.

PapaDocta
9th April 2008, 23:41
hi everyone! i'm new here. i was wondering where i can download this hack that everyone's talking about. i hope to hear from you guys soon.

all the files you need is in this post http://www.ipmart-forum.com/showpost.php?p=1896661&postcount=2

aug11
9th April 2008, 23:55
all the files you need is in this post http://www.ipmart-forum.com/showpost.php?p=1896661&postcount=2

THANKS HEAPS! i hope i'll d ok with hacking. :)

-miniME-
10th April 2008, 00:01
hi

anyone with a n80 pls send me the z:\sys\bin\ekern.exe !

ciao

bAsem
10th April 2008, 03:52
hi

anyone with a n80 pls send me the z:\sys\bin\ekern.exe !

ciao


here u go but why would u want that file ?????

-miniME-
10th April 2008, 04:35
hi

Want to learn from fca crack. He uses a n80 - so i will see which part i have to change on ekern.exe of my n95. Then i mod the firmware of my n95 - voila - burn via nsu (there is still the possibility).

Ciao

here u go but why would u want that file ?????

109place
10th April 2008, 08:20
Hi there - im trying this on an E65, using Vista. Can someone confirm whether this hack has worked for me please?

I have SysExplorer, but i cannot see a 'private' folder under Z: drive.

Under C:\System i see 5 folders (Apps, Data, dmgr, Install, temp) and 1 file (System.ini)

I,ve completed all the steps as described (except im using VISTA) upto step 8.1, the end of the analysis does say "Close End+Exit" and i do see something similar to this "Read Memory 60000148=1E 00 00 00 candidate!!!" on the trace

Any help please? Oh - and can i ask if e65 is prefp1 or fp1? (and what's fp1?!)

Had my e65 for about a month - sorry if i've asked something silly!:D

AnujaMadusha
10th April 2008, 08:35
It worked. yeah

Much easy. i thought it will be hard. but it is not

no errors occured. Try it all.

aug11
10th April 2008, 14:11
all the files you need is in this post http://www.ipmart-forum.com/showpost.php?p=1896661&postcount=2

i can't seem to download anything from http://www.python.org/ftp/python/2.5.2/python-2.5.2.msi where else can i download it? thanks.

enroberte
10th April 2008, 15:13
Hi!
I have N80 and I did exactly as described in the instructions. I have Vista.

I attached snapshot of running py file. What am I doing wrong?

knblmmn
10th April 2008, 16:44
Tried it again on the n81,and ran the serialpy32.py but no success.
Same error stays.

I don't see anyone with an n81 who has been able to make it work (or am I wrong?)

Anyway last time my phone did not boot normally, so I'm giving up as lons as there is no easier way of getting access.

bAsem
10th April 2008, 20:56
Hi!
I have N80 and I did exactly as described in the instructions. I have Vista.

I attached snapshot of running py file. What am I doing wrong?


i said ONE MILLION TIMES DONT USe VISTA .. omg cant anybody read

deilyn