BruteForce WM2003 nbf Password - PDA2, XDA IIi, 2020i General

Hi all,
Is someone capable / willing to make a program to bruteforce WM2003 nbf files? Since the chance it's only a number-string the changes are big to succeed I guess.
Did really no-one managed to decode, edit en encode a nbf file for this device?
Using drivers from other PX272 chipsets can be the solution to create other ROMs, right? The same was done with Himalaya, WM5 was never released for it too, and a Wizard base rom was used with modified drivers (wich we have, since we know the specifications, the universal is the best base-rom).

Related

ipaq 3850 downgrade from WM2003

Can I use any of the tools available here, or are there others I can use to downgrade an ipaq 3850 from wm2003, (upgraded by usb bootloader), the problem is that the ipaq wireless pack just will not work with this configuration, when I try to flash an earlier rom I get the error because 3850 isnt supposed to have WM2003. Any help greatly appreciated.
Download the BIOS version 1.20 on this site http://h18007.www1.hp.com/support/files/HandheldiPAQ/us/locate/71_2594.html
You should extract the CAB file and place it on your Pocket PC. Then execute it, after it's complete you will be back to Pocket PC 2002. By the way can you post the 2003 ROM up here, I would like to run a Kitchen on it and see if we can customize it. Possibly even correct the problems your currently having. Hope this helps!!
How do I upload a file? The wm2003 works fine but it seems to have a problem with the wireless gsm/gprs sleeve, the sleeve attempts to initialise but stalls, I think it is even corrupting the files in rom/ram on the sleeve as I have had to open the case twice to disconnect the battery after trying to use it with the 3850 wm2003, it then wont be seen by any other ipaq, weird.
Hi cruisin-thru !
Try this:
In order to downgrade to PPC2002 you must follow this : Download the 2002 ROM and extract the ROM file. This ROM file is 16 bytes bigger than the 2003 one. The 16 bytes difference in the 2002 ROM is header information. With a HEX editor strip the first 16 bytes. Both 2003 and 2002 files are now equal in size. Rename the 2002 file to the same name as the 2003 file, and follow the same instructions as you used for upgrading to 2003.
Regards,
Sebi
You can post a link to it or I can give you an FTP address to post it to. I currently have the 3870 ROM and do not want to mess up the Bluetooth stack on it, the 3850 ROM does not have this built in so it should be easier to work with using the XDA kitchen. As for the download from the link I gave you, apparently the FTP server at HP is down at this time. :?
I have downloaded that 1.2 rom, I have copied the unpacked files to my pocket pc, none of them will execute, what is it am I supposed to do.
Oh by the way, the rom file I have in the 3850 does have bluetooth features.
The extracted files should contain a file with a .CAB file extension, this is the one you want to execute. As for the 2003 ROM I'll see if I can find one for the 3835 series since they shouldn't have the Bluetooth stack in the ROM. Hope this helps!
There is no cab file contained within the 1.2 file, do you have a link to anywhere I can get the file you are referring to.?
I found a 2002 rom cab file, I put it on my ppc and it says "This rom update is for ppc version 3.0.11178 but this device is pocket pc version 4.20.13100. Installation cannot procedd."
Sounds like the only way to do this is a SD card install, unfortunantly, I'm not sure how the Ipaq accomplishes this.
I am at a loss how to revert to original 3850 rom, I have another 3850 here that I can get a backup rom from, but no way of putting it back in the other 3850 that has been flashed with WM2003. I looked at the Asset viewer and it says my wm2003 ipaq 3850 has not got a color screen either, I think maybe this rom wm2003 is for 3870 bluetooth version :?
Hi !!!
Try this !!! It is working !!! I try it, I use it !!!
In order to downgrade to PPC2002 you must follow this : Download the 2002 ROM and extract the ROM file. This ROM file is 16 bytes bigger than the 2003 one. The 16 bytes difference in the 2002 ROM is header information. With a HEX editor strip the first 16 bytes. Both 2003 and 2002 files are now equal in size. Rename the 2002 file to the same name as the 2003 file, and follow the same instructions as you used for upgrading to 2003.
Thanks for that Sebi, but the rom for WM2003 was a lot bigger than the 2002 rom, the rom I need is 31.745 kb the rom I flashed is 32.768 kb, does that make any difference? I think the rom I flashed is probably the 3870 rom as the bluetooth stuff is in there.
For anybody interested, I managed to downgrade ok. I downloaded an upgrade file from HP, ran the program with a "normal" 3850 in the cradle, it asked did I want to upgrade or backup existing rom, I did a backup. I then ran the program again, when it asked me if I wanted to backup, upgrade or restore, I told it I wanted to restore the file that I had just backed up, it then told me to put my ipaq in bootloader mode, instead of putting the "normal" ipaq in bootloader, I switched machines for the one I needed to downgrade, I put this in bootloader mode, put it in the cradle and away it went. I now have a 3850 running wm2002 instead of wm2003 which for some reason doesnt want to operate with ipaq wireless pack.
cruisin-thru said:
For anybody interested, I managed to downgrade ok. I downloaded an upgrade file from HP, ran the program with a "normal" 3850 in the cradle, it asked did I want to upgrade or backup existing rom, I did a backup. I then ran the program again, when it asked me if I wanted to backup, upgrade or restore, I told it I wanted to restore the file that I had just backed up, it then told me to put my ipaq in bootloader mode, instead of putting the "normal" ipaq in bootloader, I switched machines for the one I needed to downgrade, I put this in bootloader mode, put it in the cradle and away it went. I now have a 3850 running wm2002 instead of wm2003 which for some reason doesnt want to operate with ipaq wireless pack.
Click to expand...
Click to collapse
You did what I was going to suggest to you. FYI there are no WM2003 drivers for the GSM/GPRS Wireless Pack.
Historical Product Need Some Help !
Gentlemen, knowing these posts were years ago. Appreciate if you guys still have the PPC 2003 for Ipaq 3850 or tell me where to get it. I have one in the store room and would like to upgrade it for my kid.
Please let me know ([email protected])
regards,
tc

DumpROM and NBF files

Is there a newer version of DumpROM exist to unpack ROMs for Magneto devices?
The original dumprom hangs on the .nbf files extracted from ROM upgrade utility.
I'm bumping this thread, even thought there's not much to bump up to... this forum is quiet.
I want to dump the ROM, but mamaich gave me a link to source code that I can't compile. He says the HTC Typhoon dumper should work.
Can anyone extract and decode (if necessary) the ROM files from the K-JAM firmware upgrade utility?
I want to see if it could possibly be looking for a file to replace the splash screens, much like we found out that splashX.nb did wonders for JAM, PDA2k, and so forth.
I'm sure there's a way to customize the splash screens.

Extracting CABs from a ROM

Anyone on here know how to Extract a CAB file from a ROM/Extended ROM? ive been trying to find something about this on here and cant seem to find anything that pertains to it. there are several programs that are included in roms and extended roms that i have and i wold like to be able to put them on my 8125 with the ROM i have now. Thanks in Advance!
Corey
If you already have a cabfile that resides in the extended rom the process is quite easy... just use total commander and copy the file from there to a place on your device where you can later use it...
If you don't have a cabfile but just a program, say arcsoft mms composer that's already integrated into the rom, the process gets a little more complicated, but not impossible. You will, however, need to know all the files that the program uses, dll's, imagefiles, exe's and registry posts, copy them from rom to your windows pc and from there use a program like ce cab manager to create a cabfile for it (if you want. you can merely transer all the files and registry posts to your current rom without creating a cab)
_Nomad_ said:
If you already have a cabfile that resides in the extended rom the process is quite easy... just use total commander and copy the file from there to a place on your device where you can later use it...
If you don't have a cabfile but just a program, say arcsoft mms composer that's already integrated into the rom, the process gets a little more complicated, but not impossible. You will, however, need to know all the files that the program uses, dll's, imagefiles, exe's and registry posts, copy them from rom to your windows pc and from there use a program like ce cab manager to create a cabfile for it.
Click to expand...
Click to collapse
cool, thanks for the info, what program do i need to use to unpack the NBF so i can access the files? I tried to use the one in the wiki (typho5) but i cant seem to get it to work.
for dumping rom's read through this thread
You'll probably want to read it all and I'm sure that it wont make that much sense to begin with but it'll come to you
For converting a nbf to nb files use:
Code:
typho5.exe -x nk.nbf
typho5.exe -x nk.nbf does NOT make it a .nba file!
It extracts the contents of the rom (OS, Extended Rom, Radio, Splash Screen, IPL/SPL) into .nb files.
The Extended Rom file can be opened with WinImage.
Molski
Thanks...i just checked out that thread..looks like ive got some studying ahead of me lol thanks for the help.
thanks Molski, you must have posted that just after i read the post above yours lol. thanks for the info i have another question for you here though. http://forum.xda-developers.com/showthread.php?t=291847 As smart as you guys are im sure theres a reason you havent done it though

NBH Generator

I made small program which can merge .NBs into .NBH. Generated .NBH, of course, is not properly signed but enough for feeding SSPL.
Give small script which contains .NB filenames, model name, CID and so, to the program. Output file is RUU_signed.nbh.
Sample script included.
C:\>nbhgen sample.txt
NBH Generator ver0.1 by bot
00_IPL.nb
01_SPL.nb
02_MainSplash.nb
03_SubSplash.nb
04_ExtROM.nb
05_GSM.nb
06_OS.nb
Completed.
enjoy,
bot
Hi
Sorry, but your tool didn't generate an .nbh file.
I've tried to run this script:
HERM300
HTC__001
1.23.707.6
USA
100,00_IPL.nb
200,01_SPL.nb
600,02_MainSplash.nb
601,03_SubSplash.nb
900,04_ExtROM.nb
300,05_GSM.nb
400,06_OS.nb
Click to expand...
Click to collapse
Your tool starts, but there is no .nbh. edit: It's my mistake.Ignore my post.Sorry.
What's the use of "100,00_IPL.nb ?
Great work, it is the missing link for using SSPL with RadioBoorloader 0108 for the Hermes!
Thanks a lot!
Really Great work!
Great work!
Where I can find tools for sign *.nb?
Can you made patch for mamaich tools? Now addfile.exe not working
I confirm this tool as working. Just had breeze radio successfully flashed (one more time). And it is much more handy than manual assembling
thanx.
ps 2scorpio16v:
What's the use of "100,00_IPL.nb ?
Click to expand...
Click to collapse
http://wiki.xda-developers.com/index.php?pagename=Hermes_NBH
Des said:
I confirm this tool as working. Just had breeze radio successfully flashed (one more time). And it is much more handy than manual assembling
thanx.
ps 2scorpio16v:http://wiki.xda-developers.com/index.php?pagename=Hermes_NBH
Click to expand...
Click to collapse
Thanks, now I understand
Hi bot
Thanks !I think you may do universal NBF generator .
You may add in sample.txt one parameter packet size ( Trynity Hermes 64 ) in Atremis 1024 etc
Great tool and very useful, thanks!
does nbhgen work on Artemis and Herald?
wlinsong said:
does nbhgen work on Artemis and Herald?
Click to expand...
Click to collapse
On Artemis the singature size is 1024, no idea about Herald.... i think it will not work but haven't tested it.
To make the signature 1024 you can do it like this (at least until bot releases a version which allows you to modifi the sig. size):
Code:
nbhgen.exe file.txt
perl nbh2dbh.pl RUU_signed.nbh RUU_signed.dbh
ImageHash.exe -raw RUU_signed.dbh RUU_signedNEW.nbh 1024
It will popup a window asking you to select the proper certificate to sign your file, if you don't have one you can import for example a test certificate from windows mobile SDK.
Any one guide for artemis...so that many people who hv bricked their Orbit can make them alive..
is there a possibility to use this nbhgen.exe for making a backup of the current Excalibur ROM?
I have a german XDA Cosmo running the original XDA Cosmo ROM.
And I also managed to make a backup with bkondisk
BUT what I have not been able to find out so far:
how to make an installable package out of that?
this nbhgen sounds good but how (if ever) can I use it for the Excalibur?
Do I have to sign the resulting .nbh or maybe will it work unsigned with the engineering SPL 1.11???
I want to have a backup before flashing other ROMs - and believe me I want flashing the Dash ROM (or the german MDA Mail ROM) sooo bad since I've heard that TomTom 6 runs perfectly on it (unlike on Cosmo ROM where it's nearly unusable )
I'm sorry, but I stil don't get it and can not find anything inside the wiki. How is this tool supposed to work when I have an OS.nb for example?
Do you leave fields blank if you don't want to perform that part of the upgrade? For example if you were not going to upgrade anything other than the OS would you leave everything except the last line blank like this (sample sample):
TRIN100
HTC__001
1.23.707.6
USA
400,06_OS.nb
Also, can the the first lines be anything? I assume they are descriptors on line one and two followed by your own version #.
hdubli said:
Any one guide for artemis...so that many people who hv bricked their Orbit can make them alive..
Click to expand...
Click to collapse
I second that thought.
It seems to not work on Windows vista.
Any idea ?
Hi,
I have a nb0 file that I want to turn into a nbh. Is a nb0 file simply a nb but the OS part?
Can this tool do what I am looking for? The problem is I don't want to add a IPL, SPL etc - nor do I want to go to SP1.01.
thanks!
@daveh85: nb0 is the same as nb. Yes, you can convert it to nbh using this tool.
Hi,
I don't understand how to make the sample.txt.
I'm trying to create a Big Storage of the last LVSW's ROM.
I have the following files :
00_MainSplash.bmp
00_MainSplash.nb
01_SubSplash.bmp
01_SubSplash.nb
02_ExtROM.nb
03_OS.nb
How do I create a sample.txt file to create the RUU_signed.nbh file to flash on a Hermes 200 ??
Thanks for enlighting me
This would be your "sample.txt":
Code:
HERM***
SuperCID
Murcielago
WWE
600,00_MainSplash.nb
601,01_SubSplash.nb
700,02_ExtROM.nb
400,03_OS.nb

Finally able to extract imgfs and xip from Stock Rom

For everyone who has an LG Quantum, I was finally able to extract the xip and imgfs from the stock rom and see what the insides look like. To do it, I modified the lgextract program, which was written for the LG KS20, whose rom image is similar in format to the quantum's. I will post my version of lgextract either later today or tomorrow for your amusement. From there, you can use the latest version of the htc rom editor to get the imgfs.bin and xip.bin. As of now, there is no way to piece it all back together for flashing, so custom roms are, unfortunately, not possible yet. The only annoyance (you could also call it a bug if you wanted to), is that you have to remove the rom header manually with a hex editor to make it work with the htc rom editor (but I am currently working on a version to do it automatically).
On another note, I did find out that the manufacturer program can read and write to the registry, so I could also write a program to view and edit the registry if there is enough need as to do registry editing on the quantum.
Update: I have fixed the program to do all the extraction automatically so you can automatically just open up the nb file in the HTC Rom Image Editor and see what goods are inside. However, there's still no way to create custom roms yet. As for the registry editor, I can't do anything until I get back in school and I have a chance to talk to the CS department at school about getting my quantum developer unlocked via Microsoft Dreamspark.
download: http://www.easy-share.com/1914181345/DZExtract_v1.0.rar
You can use the dz file found in one of the other LG Quantum threads here with the program. If you have any questions, feel free to post or pm me.
--reserved--
Very nice! Just a question, is this similar to using a hex editor to edit the seed files from the old razr phones? Or a registry editer like wm6.5? Just wondering.
can you update system files in anyway or read and wright or deleat registry edits?
I have a custom rom but I don't see what good it will do. if the bootloader is not unlocked.
might be able to copy parts of it over to the device but am unsure. can you sideload anything?:cyclops:
edit!!!!!!!! LINK IS DEAD!
File not foundZExtract_v1.0.rar

Categories

Resources