Please give me advice~
I am using i897, while I updating it(Odin), I wrongly unplug it. And now what happen on my phone:
Power / 3 Key - no thing happen
Tried send to one of the mobile fix shop(they tell me they tried Jig) and still can't fix it.
Plug in to computer - no feedback of both side
I did a bit research of it , I think it is about the boot-loader is empty
I know I have been stupid this time, just want to try any thing I can do.
P.S. I don't know soldering iron so I can't do the UnBrickable Mod
Any one know any way/place to fix it (in Aus-Melbourne)?
Thx for your time to read my problem, plz help me if you have any suggestions~
UnBrickable Mod is here to save the day.... http://forum.xda-developers.com/showthread.php?t=1206216
That or JTAG.
Thx, however I don't know how to do step 4&5 for the UnBrickable Mod><
Also I am not really know where can I find any shop have JTAG to do it for me.
P.S. I am a high school student. In many area I am also have less experiences. I want to try on it, but......><
Send http://www.mobiletechvideos.com/blog/donate-2/ a email, he has great success on Jtag. I believe he can install the UnBrickable Mod as well. Not sure on the second part but you never know. Keep in mind Jtag service (and probably the mod not sure) cost $40 + shipping
Edit: He does offer UnBrickable Mod for $40.
Thank-you! However is it that mean I can't fix it myself>< ??
chujoshua said:
Thank-you! However is it that mean I can't fix it myself>< ??
Click to expand...
Click to collapse
No. UnBrickable mod is the DIY method. It's as easy as it gets. Rebellos and I have already taken care of the assembly language, signatures, working in the linux command prompt, research and everything... You just need to replace a resistor with a wire and run the software.
AdamOutler said:
No. UnBrickable mod is the DIY method. It's as easy as it gets. Rebellos and I have already taken care of the assembly language, signatures, working in the linux command prompt, research and everything... You just need to replace a resistor with a wire and run the software.
Click to expand...
Click to collapse
Although I agree, the physical mod part requires decent soldering skills.
Thx for your attention ^^
the place I am not sure is 4.and 5.
Although I know it is trouble for you,but will you have the chance to make a video of the real step by step,thx very much!!(or a clear pic also is good!!)
Related
I'm pretty sure my phone is bricked. But are they any ways to test to make sure this is true? Like pressing any buttons as the phone boots up to see if I get a response?
ste1164 said:
I'm pretty sure my phone is bricked. But are they any ways to test to make sure this is true? Like pressing any buttons as the phone boots up to see if I get a response?
Click to expand...
Click to collapse
Turn off phone. Hold the camera button in while pressing power.
If you get to fastboot, you're not bricked.
No fastboot, bricked.
If camara and power and home and power dont work, you still have blue light mode. Turn it on by holding down the trackball and power, and the blue led will turn on. To my knowledge, 2 people have sufficient JTAG knowledge to unbrick phones through blue light mode. That's probably worthless to you because you don't know where they live thought =p
JTAG is pretty common across many electronic devices, i know of way more than 2 people who know how/ what their doing. i have JTAG recovered many routers, and other electronics. a special adaptor for the PC will make it MUCH easier, however its still not easy. the information is out there, and it obviously do able. id probably feel somewhat comfortable doing it, but fortuantly its not nessicary
mejorguille said:
To my knowledge, 2 people have sufficient JTAG knowledge to unbrick phones through blue light mode. That's probably worthless to you because you don't know where they live thought =p
Click to expand...
Click to collapse
That is both inaccurate as well as extremely insulting. Just because YOU are incompetent does NOT mean that others are as well.
ive also read a few posts that XDA member EZTERRY has been known to JTAG phones (for compensation of course) send him a PM (no more than one, remember we all have lives outside of the interwebs right??????) but hes in Canada, and it will involve shipping your phione
lbcoder said:
That is both inaccurate as well as extremely insulting. Just because YOU are incompetent does NOT mean that others are as well.
Click to expand...
Click to collapse
Sorry if I was being ignorant or insulting, I guess you can't see sarcasm easily online=p I know JTAG can be done on more then just our phones, but as far as I know only ezterrty has been able to completely unbrick a DREAM, and I think I read about another person in the thread that was able to do the same. And I love how you always use caps in your posts, it makes me feel like if your screaming at me lol.
mejorguille said:
Sorry if I was being ignorant or insulting, I guess you can't see sarcasm easily online=p I know JTAG can be done on more then just our phones, but as far as I know only ezterrty has been able to completely unbrick a DREAM, and I think I read about another person in the thread that was able to do the same. And I love how you always use caps in your posts, it makes me feel like if your screaming at me lol.
Click to expand...
Click to collapse
Sigh* You completely contradicted yourself in this post.
and because ezterry is the only one who has advertised that he has fixed it doesnt mean that there arent others.... and theres probably a good precentage of us that would be able to succesfully do it if the situation were to arise.... i personally dont have a bricked Dream, wont brick it on purpose to try it, and dont feel like buying a used one off ebay.... someone send me a free one... i'll prove this guy wrong... :rollseyes:
it just boils down to the fact that only a very few dreams were bricked because we didnt know what we were doing.... most bricks occurred after the reason was discovered, and people were to dumb to read some instructions... therefore the likelihood that anyone with a bricked dream at this point has it as a result of their own stupidity..... that reduces the likelihood that said individual would have the sufficient skills to JTAG and unbrick their device seeing as they didnt have sufficient skills (or patience) to read some damn instructions....
Hi,
i've been following the progress on Milestone hacking quite a while now.
Some days ago i started intensive research on the Milestone hardware myself
So here's the some interesting discovery.
Thanks goes out to XVilka for putting this down on the wiki so fast
Of course this is just the starting point for a new hunting....
As you might see many signals are not identified yet.
Essential:
TDO
TDI
TMS
TCK
RTCK
Possible:
EMU0
EMU1
Optional:
DEBUG_UART_RX
Someone needs unsolder the CPU and trace these signals on the mainboard.
So if you got a broken mainboard it would be welcome for scientific examination
This of course would not give us an open bootloader, but might open the door for some promising attempts to debug the platform more intensely.
UPDATE:
All signals had been identified. Unfortunately JTAG access to ARM core and other units is blocked.
EDIT:
O.k. now that xvilka had put my detailed pics in the droid-developers wiki, no need to hide it anymore
Find my updated pics attached.
In fact JTAG access is blocked by the security mechanism on the Milestone.
So all that is accessible is the main TAP controller... everything else is blocked.
No access to the ARM core... nothing except ID could be retrieved.
Have a look at my resignation post here:
http://forum.xda-developers.com/showpost.php?p=11759352&postcount=54
Anyway the journey was a fun thing and i learned a lot of the ARM core internals including TAP units inside OMAP
The craziest thing was, to realize that all this incredible security stuff really depends on one hard-coded bit... called the "HS-Bit".
If you need more infos tell me!!
Cheers,
scholbert
Software tool
We might use the famous OpenOCD for debugging, once we got the full pinout.
Look here for further details about it:
http://elinux.org/BeagleBoardOpenOCD
Have fun!
scholbert
This looks very much fun, but how is this going to benefit an end user?
^^ How does "unlocked bootloader" sound to you
Well said and nice to see some reaction here also.
Sure that's fun... at least for me... and it's to widen your knowledge
I've joined this forum some time ago and it is still called xda-developers.
Maybe i'm little old-fashioned but that's what is still driving me... development
By initiating this thread i was aware there's no benefit for the end user right now,
but the more people stumble over here, the more there's a chance to find some other enthusiasts following this path.
I'm aware that the magic parts are missing.
We need someone willing to do wicked stuff and equipped with professional equipment to unsolder parts from the mainboard.
Once to the remaining signals could be traced, there's a lot play with.
Unlike other devices the core elements of the hardware residing in the Milestone are pretty well documented and lot of software tools exist.
I'm pretty sure there's a way to find a nicer backdoor on this locked down device.
The market is fast though and maybe some day there'll be a device you could use to fly with... even as an end user
Anyway, would be nice to talk about.
Best regards,
scholbert
if thats true, then that'd be great. but the guy says "This of course would not give us an open bootloader" in his first post.
good luck scholbert!!
AbdouRetro said:
if thats true, then that'd be great. but the guy says "This of course would not give us an open bootloader" in his first post.
Click to expand...
Click to collapse
Yes, having a working JTAG is not going to open the bootloader. But will give something very important - access to the CPU and flash without having any working code - read "bootloader development".
Sent from my Milestone using Tapatalk
scholbert, if u have flash access then u can write to some very privileged areas, does that mean u can make the processor boot into general purpose mode?
AbdouRetro said:
scholbert, if u have flash access then u can write to some very privileged areas, does that mean u can make the processor boot into general purpose mode?
Click to expand...
Click to collapse
Privileged areas is a nice word
....but yes, if it's in NAND you may access it easily using JTAG.
AFAIK the HS mode is hard coded into OMAP3430, so booting into GP mode will never happen i guess.
EDIT:
Just had a short glimpse at the OMAP3430 TRM, there's the register CONTROL_PRODUCTION_ID @ 0x4830_A210 to check for GP mode (ID = 0xF0).
On milestone this ID is obviously different and it is hardcoded with efuse.
The ROM bootloader checks this register and could not be rewritten because it's OTP.
Regards,
scholbert
scholbert said:
Privileged areas is a nice word
....but yes, if it's in NAND you may access it easily using JTAG.
AFAIK the HS mode is hard coded into OMAP3430, so booting into GP mode will never happen i guess.
EDIT:
Just had a short glimpse at the OMAP3430 TRM, there's the register CONTROL_PRODUCTION_ID @ 0x4830_A210 to check for GP mode (ID = 0xF0).
On milestone this ID is obviously different and i guess it's hardcoded.
The ROM bootloader checks this register and could not be rewritten because it's OTP.
Regards,
scholbert
Click to expand...
Click to collapse
Sir, I was wondering if a bricked device would be okay for this (by bricked I mean someone [not me of course ] flashed some ****ty firmware and it doesn't boot now), if it is so then I think I visit a few shops and ask around in the "black" market for a bricked device.
I don't think motorola has the capacity to manufacture things so different for the milestone and droid. its enough cost that they use different radios!!
I'm hoping its an external chip/trace that controls which mode it boots.
in the chip block diagram on the site, there's an internal boot rom, do we have that??
reminds me of the xbox360...
Quintasan said:
Sir, I was wondering if a bricked device would be okay for this (by bricked I mean someone [not me of course ] flashed some ****ty firmware and it doesn't boot now), if it is so then I think I visit a few shops and ask around in the "black" market for a bricked device.
Click to expand...
Click to collapse
Sure a bricked device would do, even a partly physical damaged device will do. As i said before the CPU needs to be unsoldered to trace some signals.
EDIT: Just a remark, because you talk about "black" market.... please don't buy any stolen phones or something.
AbdouRetro said:
I don't think motorola has the capacity to manufacture things so different for the milestone and droid. its enough cost that they use different radios!!
I'm hoping its an external chip/trace that controls which mode it boots.
in the chip block diagram on the site, there's an internal boot rom, do we have that??
Click to expand...
Click to collapse
Of course there's a boot ROM, all modern OMAP got this OTP memory implemented.
Have a look at:
https://www.droid-developers.org/wiki/Main_Page
You'll find very interesting and useful information....
Concerning capacities...
Sure they have and obviously Motorola is one of the big customers of Ti.
Apart form the device ID there are also different boot ROMs for different platforms.
This is simply called customizing
TI does it, Qualcomm does it, whoever builds ARM SoC's may do it.
Also Ti's eFuse technology gives the customer (e.g. Motorola) the opportunity to block certain parts of the chip by software setup.
And that's what they did on the Milestone.
Regards,
scholbert
when i said "do we have that"
i meant, do we have a dump of that code that is disassembled and looked into.
by checking here
Code:
droid-developers.org/wiki/Booting_chain
its obvious this has already been done
Hi again,
seems less interest here.... sure this is a very technical thread....
Anyway, see this picture of the mainboard.
https://www.droid-developers.org/images/d/dd/Photo-1.jpg
Seems to be taken from one of the first mass production units, or even a developers phone.
You see there's a FPC connector soldered on the mainboard (underneath the microSD connector).
After doing a little research, it seems that these connectors are used for professional environment:
http://www.hirose.co.jp/cataloge_hp/e58004008.pdf
Part.-No. FH19C-17S-0.5SH
Cheers,
scholbert
I have a dead phone. If someone can provide me with a pinout for the processor, I will be glad to trace out the rest of the jtag header.
Hi eustice!
eustice said:
I have a dead phone. If someone can provide me with a pinout for the processor, I will be glad to trace out the rest of the jtag header.
Click to expand...
Click to collapse
Wow, that 's great, let's crack that nut
I just created a map, bit small though, but i think everything could located...
BTW, on Milestone they seem to have used a OMAP3430 in CBC (S-PBGA-N515) package with POP-memory (see attached datasheet of the package).
Had to digg a little to find that out...
Tell me if you need further information!
Please be careful while removing the CPU, these little pads will easily rip of...
Good luck!!
scholbert
scholbert said:
Hi eustice!
Wow, that 's great, let's crack that nut
I just created a map, bit small though, but i think everything could located...
BTW, on Milestone they seem to have used a OMAP3430 in CBC (S-PBGA-N515) package with POP-memory (see attached datasheet of the package).
Had to digg a little to find that out...
Tell me if you need further information!
Please be careful while removing the CPU, these little pads will easily rip of...
Good luck!!
scholbert
Click to expand...
Click to collapse
Sir, well, I'm not sure if this is of intrest to us but
http://allegro.pl/okazja-jak-nowa-motorola-droid-i1386494285.html
This guys sell's DROIDs for 200 polish zloty, it's cheap. The main problem is that the guy says they were flooded during the transport, he also claims that they were not switched on since then. Are we interested in getting one and disassembling it?
Hey Qintasan,
thanks for the link!
Quintasan said:
This guys sell's DROIDs for 200 polish zloty, it's cheap. The main problem is that the guy says they were flooded during the transport, he also claims that they were not switched on since then. Are we interested in getting one and disassembling it?
Click to expand...
Click to collapse
Indeed the price is nice, but it's your decision, wether to buy one or not.
Personnally i got two working devices and i'm not willing to rip them apart.
By starting this thread i intended to draw some interest about this JTAG stuff and to collect information to gain access on the Milestone.
It is yet unknown, if it will ever work on this platform.
It might also be possible that the JTAG signals are physically connected, but had been disabled by e-fuses on the production units.
..... but if no one ever tries we'll never know.
Best regards,
scholbert
milestone jtag board and connector pic
attached are the pics for the jtag board and the connector on the phone.
Hello all!!
I have recently tried to flash my Galaxy and me being the most useless person with technology must have done something wrong and now cannot work the phone.
Im pretty sure the message (now cant remember what it said) means it has ROM or something (please excuse my limited knowldege)
Anyway because I played around with it, its not under warranty hence they have to charge me.
However they have asked for $400 to fix the phone. Now I bought my phone for $900..??
I do accept my fault for breaking the phone in the first place, however I think $400 is a bit too much..
Now to my main question, is there a way for me to fix this myself?? or is there a cheaper place where I can fix this because this has gone way too far..
Living without my Android is like hell..
Can someone please help me!!!!
argh!!
I will try to get a better description of the fault if I can.
try reading some manuals and stuff like that on the forum
if it is rom related i think all u will need to do is flash a new rom from odin
just read and dig
if its software no problem to fix
i am learning my self too i had my phone not booting and stuff but after reading all good.
Ya, I got my phone bricked also, but managed to fix it. Basically search more info and tutorials for your particular problem and ways to fix it and you`ll find a way.
Did you drop it or?
If yes, you should repair it and pay :/
If not, setup adb and reflash your android!
yochankr said:
Hello all!!
I have recently tried to flash my Galaxy and me being the most useless person with technology must have done something wrong and now cannot work the phone.
Im pretty sure the message (now cant remember what it said) means it has ROM or something (please excuse my limited knowldege)
Anyway because I played around with it, its not under warranty hence they have to charge me.
However they have asked for $400 to fix the phone. Now I bought my phone for $900..??
I do accept my fault for breaking the phone in the first place, however I think $400 is a bit too much..
Now to my main question, is there a way for me to fix this myself?? or is there a cheaper place where I can fix this because this has gone way too far..
Living without my Android is like hell..
Can someone please help me!!!!
argh!!
I will try to get a better description of the fault if I can.
Click to expand...
Click to collapse
My advise pay few dollars buy jig ebay flash with odin save yoursef 390+ dollars it is usb download jig very cheep believe it is exactly what you need
Sent from my GT-I9000 using XDA App
One the beginning as always .
Can you access download mode via 3 button or even recovery mode .
If so the probability is you can flash a stock rom to at least have a phone covered under warranty.If not working 100%.
jje
I'm looking for a busted captivate for research. I belive we may be able to boot from a micro SD card.
I have to remove the processor and reverse engineer the board in order to find the power supply to the line called XOM5 in the processor manual. Once this line is found, it may be as simple as shorting, slicing the line, or popping a resistor off the board.
Repairing the phone afterwards would be beyond my capabilities.. I can't perform ball soldering. That takes some highly specialized tools. You would be doing a great service to everyone with a GalaxyS phone.
The phone does not need to work, and can be in horrible condition. It can be water damaged or physically broken. The only thing I need is the main board inside the phone.
bump......
Sorry man only got my every day phone. Ill keep an eye out in the island see if i can help with your project.
hey i have a 1008 phone. screen busted. possibly stuck in bootloop. its in a couple peices.
bulletproof1013 said:
hey i have a 1008 phone. screen busted. possibly stuck in bootloop. its in a couple peices.
Click to expand...
Click to collapse
can i just send you the main board?
Yes! that's all I need. I'll send you a PM.
AdamOutler said:
I'm looking for a busted captivate for research. I belive we may be able to boot from a micro SD card.
I have to remove the processor and reverse engineer the board in order to find the power supply to the line called XOM5 in the processor manual. Once this line is found, it may be as simple as shorting, slicing the line, or popping a resistor off the board.
Repairing the phone afterwards would be beyond my capabilities.. I can't perform ball soldering. That takes some highly specialized tools. You would be doing a great service to everyone with a GalaxyS phone.
The phone does not need to work, and can be in horrible condition. It can be water damaged or physically broken. The only thing I need is the main board inside the phone.
Click to expand...
Click to collapse
I would like to learn more how a CB works and how to trace certain things on a board as well as other parts. Any books or reference guides besides schematics that could help me? PM me if you will. Infact anyone that knows anything could help me, please PM. Thanks.
Jmurph3 said:
I would like to learn more how a CB works and how to trace certain things on a board as well as other parts. Any books or reference guides besides schematics that could help me? PM me if you will. Infact anyone that knows anything could help me, please PM. Thanks.
Click to expand...
Click to collapse
A better place for a newbie to start would be circuit bending... hopping electricity from one point on a circuit board to another to alter the operating state. This would be a great place to start... http://hackaday.com/2011/01/11/intro-to-circuit-bending/
Once you get familiar with how things work on a circuit board, start examining the individual components in greater detail. There's some datasheets in here http://forum.xda-developers.com/showthread.php?t=1111866 which you could use to understand how a couple of the major players on our phone works. Speciffically, the USB controller (FSA9480) and the Processor (S5PC110). It really takes some additional education to start reading processor manuals....
You could always start with something simpler like Arduino platform. The Arduino platform allows you to create a basic program which runs on a microprocessor and take inputs and outputs from it. I like the Arduino because it's so darn quick to pick up.
here's some of the stuff I programmed on the Arduino
Contest entry http://www.hyundaiaftermarket.org/f...utlers-hackaday-santa-pede-competition-entry/
Silly candle http://www.hyundaiaftermarket.org/forum/blog/3/entry-27-digital-candle/
This one would be a great first project. http://www.hyundaiaftermarket.org/forum/blog/3/entry-26-arduino-ef-meter/
If you really want to understand how a circuit board works, the best way is to go to school, or start playing with one... You could get started pretty cheap http://www.google.com/search?client...gc.r_pw.&fp=d4257c808144b93c&biw=1333&bih=651 or you can get a better one like in the Android Open Acessory Kit (it's actually an Arduino Mega with additional sensors) http://www.google.com/search?client...gc.r_pw.&fp=d4257c808144b93c&biw=1333&bih=651
So yeah... Learning electronics is reading, playing and doing.
AdamOutler said:
A better place for a newbie to start would be circuit bending... hopping electricity from one point on a circuit board to another to alter the operating state. This would be a great place to start... http://hackaday.com/2011/01/11/intro-to-circuit-bending/
Once you get familiar with how things work on a circuit board, start examining the individual components in greater detail. There's some datasheets in here http://forum.xda-developers.com/showthread.php?t=1111866 which you could use to understand how a couple of the major players on our phone works. Speciffically, the USB controller (FSA9480) and the Processor (S5PC110). It really takes some additional education to start reading processor manuals....
You could always start with something simpler like Arduino platform. The Arduino platform allows you to create a basic program which runs on a microprocessor and take inputs and outputs from it. I like the Arduino because it's so darn quick to pick up.
here's some of the stuff I programmed on the Arduino
Contest entry http://www.hyundaiaftermarket.org/f...utlers-hackaday-santa-pede-competition-entry/
Silly candle http://www.hyundaiaftermarket.org/forum/blog/3/entry-27-digital-candle/
This one would be a great first project. http://www.hyundaiaftermarket.org/forum/blog/3/entry-26-arduino-ef-meter/
If you really want to understand how a circuit board works, the best way is to go to school, or start playing with one... You could get started pretty cheap http://www.google.com/search?client...gc.r_pw.&fp=d4257c808144b93c&biw=1333&bih=651 or you can get a better one like in the Android Open Acessory Kit (it's actually an Arduino Mega with additional sensors) http://www.google.com/search?client...gc.r_pw.&fp=d4257c808144b93c&biw=1333&bih=651
So yeah... Learning electronics is reading, playing and doing.
Click to expand...
Click to collapse
Hey, thanks a lot. I'm sure I'll be able to get something out of it. Hopefully this will help with my job some too!
Hey , when and If your able to boot from micro sd...will this method be like the nook color?
bulletproof1013 said:
Hey , when and If your able to boot from micro sd...will this method be like the nook color?
Click to expand...
Click to collapse
Basically. that's the idea. perform a slight hardware modification, then boot from SDCard from then on. Of course, first, I'll be focusing on just recovering a bricked phone by providing the phone a PBL/SBL/SBL2 on a MMC card.
Any progress?
crispy1805 said:
Any progress?
Click to expand...
Click to collapse
Yes. the project is completed. Thank you Bulletproof1013.
See here: http://forum.xda-developers.com/showthread.php?t=1242466
Ok well I've had this Galaxy S and decided to follow a tutorial from a reputable website (not gonna name which one) and after following it, it led to the freezing of odin and as a result a hard bricking of my galaxy S. tried so many things read so many threads on this forum, ive even ordered a jig to try to use despite people saying that it won't work. then finally accepted the fact that it was screwed unless i used a jtagbox. now im not the best with that sort of stuff but just wanted to know if anyone knows any PROPER EXPERIENCED technicians in Australia if possible (in Sydney even more preferable) that can carry out the proper procedure for jtag. obviously if theres noone nearby im willing to post the phone out to them . what sort of price am i looking at for the procedure?
thanks in advance guys
there is an mobile repair shop next to Bankstown.
I don't know what u mean by Jtagbox, but my phone f**ked up so took it to him however I ended up getting a new phone for xmas lol
cheers
If you are really considering JTAG as your last resort, then better consider this first http://www.xda-developers.com/andro...wered-device-by-creating-your-own-bootloader/
dhiru1602 said:
If you are really considering JTAG as your last resort, then better consider this first http://www.xda-developers.com/andro...wered-device-by-creating-your-own-bootloader/
Click to expand...
Click to collapse
well im not sure. IS a jtag my last resort? if its not turning on at all no matter what button combos i press or remove and replace battery and charge, what else could i do? any advice appreciated. and with that guide, im not ashamed to admit that i dont know as much as i'd like to about that sort of stuff i wouldnt wanna risk anything if i dont have sufficient knowledge.
deadey3 said:
there is an mobile repair shop next to Bankstown.
Click to expand...
Click to collapse
where abouts next to bankstown? can i get a store name and i'll try to check it out. i live about 5 minutes away from bankstown.
deadey3 said:
I don't know what u mean by Jtagbox, but my phone f**ked up so took it to him however I ended up getting a new phone for xmas lol
Click to expand...
Click to collapse
was your phone hardbricked completely? wait so did your phone get repaired or not?
merry xmas
bump, please any advice guys