Results 1 to 5 of 5

8130 & 8330 ESN/MEID Repair without CDMA Workshop


Android Thread, 8130 & 8330 ESN/MEID Repair without CDMA Workshop in CDMA Section; This is copied from the BLOG made by missing|No BlackBerry 8130: ESN Repair, the hard and free way ESN Changing ...
               Bookmark and Share
  1. #1
    Banned
    Points: 19,827, Level: 97
    Level completed: 32%, Points required for next Level: 273
    Overall activity: 55.0%
    Achievements:
    Recommendation First ClassOverdrive10000 Experience PointsThree Friends1 year registered
    Awards:
    User with most referrers

    Join Date
    Mar 2011
    Posts
    1,312
    Points
    19,827
    Level
    97
    Blog Entries
    230
    Thanks
    0
    Thanked 71 Times in 46 Posts
    Status
    Offline

    Smile 8130 & 8330 ESN/MEID Repair without CDMA Workshop

    This is copied from the BLOG made by missing|No

    BlackBerry 8130: ESN Repair, the hard and free way



    ESN Changing Made... somewhat easy
    A guide made with love and experience by missing|No

    There's a reason I made this guide: CDMA Workshop isn't something I can afford - and nobody even bothers to crack newer editions stating "oh, it's only $100 and it pays for itself!!!1" or they make fake loaders and throw viruses in them then tell you that all cracks have viruses no matter what. If I had a paid copy, sure, I wouldn't have to resort to this complex guide and a lot of my work would be easier, but nope.

    (And to those of you saying "it's only $100", do you buy, say, your other software? I bet a few of you people out there have pirated software elsewhere.)

    Prerequisites
    I'd highly recommend the following software for this:

    * CDMA Workshop 3.4, demonstration version
    * UniCDMA (I use the 2005 varient)
    * QPST/QxDM
    * Xvi32
    * JL_Cmder
    * MFI Multiloader (MML)
    * Blackberry Device Manager
    * The earliest available BB OS revision for your device (ie, 4.3)
    * The latest BB OS revision (4.5 for the Pearl 8130)
    * Pen and paper
    * Windows Calculator, in scientific mode


    Making your Blackberry squeaky clean

    1. You'll need to wipe your OS to begin. Open JL_Cmder and select option 4 (Wipe).
    2. Once this is done and your Blackberry reports a 507 Error, you'll need to downgrade your OS. Open the early OS revision you have downloaded (in my case, OS 4.3) and install it to your device. Yes, this takes a while.
    3. And then wipe it again in JL_Cmdr. Do not re-load the OS until the end of this tutorial. This re-opens memory regions not normally available in OS 4.5.


    Preparation of liquid delight

    1. Ensure Blackberry Desktop Manager is running. This creates, and keeps open, two RIM Virtual COM ports. Make a note of what these ports are via Device Manager on your workstation. Mine were COM4 and COM3, however these vary from machine-to-machine.
    2. Open up the demonstration edition of CDMA Workshop. As much as it's a demo, we only need one luckily open feature. Go to the Memory tab and scan for all readable areas - with a step of 1024. Not doing this will skip over a delicate boundary that you will likely miss in the 0x10000000 region of the memory.
    3. During the scan, you will note two locations in the 0x10000000 area that are open. Mine were 0x10000000 to 0x101165F8 and 0x1011C000 to 0x10D30000. Please note! These numbers will be different depending on your OS!


    Time to calculate.

    1. You'll need the Windows Calculator open for this. Set the calculator into Hex mode and enter in your hex numbers - for me, enter 101165F8, and subtract 10000000. This gives you 1165F8, in hexidecimal.
    2. Select the Decimal mode again and it will indicate a result. Write this down. You'll need this number.
    3. Do this for your next values - for me, it was 10D30000-1011C000, then write that down as well.


    UniCDMA, ahoy

    1. Open up UniCDMA now, and connect to your COM port that the Blackberry is detected on.
    2. Select the Memory operations, and begin dumping from your start address.
    3. For my example, I will enter 0x10000000 as my start address, and for the length in bytes, I use the numbers obtained above. So, I will tell UniCDMA to dump the first ~1140216 bytes.
    4. Save this dump file and continue to the next dump. For this next dump, I needed to dump 12664832 bytes.


    What the hex?

    1. Open XVI32 and your first dump file.
    2. Begin a search for your ESN, in reverse (DE AD BE EF becomes EF BE AD DE).
    3. Note every location in Hex mode of where your ESN is found. For me, this was 6 locations in my second dump: 5AD980, 5F01D*, 85DE94, 862FE5, 93DD0C, and A224EF.
    4. Got those 6-8 locations? Good. Time for MORE calculations!


    Calculations, redux

    1. Take your first location and the dump file it was located in. Because I name my files after their starting location in memory, this makes it easy: knowing 5AD980 was in the file 0x1011C000.bin that I dumped, I can use Windows Calculator again and just add 5AD980 to 1011C000, getting my first ESN location. Do this for each location and jot it down somewhere.


    Run to the hills

    1. Open QxDM and connect to your device.
    2. Open the Memory Viewer.
    3. Tell the memory viewer to show the first location your ESN is located at. It should look just as it did in the hex dump.
    4. Overwrite it with 00 00 00 00. Do this for every location. I hit Write, then re-zero it, then Write again - three times total - to make sure it's written.
    5. Afterwards, open the NV Browser and open Item 0 (esn).
    6. Hit "Read". If it reports 0x00000000, the ESN is now zeroed out.
    7. From there, simply input your new ESN in Input (say, 0xDEADBEEF), and hit Write. It should happily reply back NV Item Written.
    8. You're done. Issue a "mode reset" in the command interpreter and the phone should commit changes and have its' new ESN in memory.


    Finishing up
    All that's really needed now is to install the latest Blackberry OS to your phone - so while it's still at Error 507, you can simply install a new OS via any means you'd like.

  2. #2
    Banned
    Points: 19,827, Level: 97
    Level completed: 32%, Points required for next Level: 273
    Overall activity: 55.0%
    Achievements:
    Recommendation First ClassOverdrive10000 Experience PointsThree Friends1 year registered
    Awards:
    User with most referrers

    Join Date
    Mar 2011
    Posts
    1,312
    Points
    19,827
    Level
    97
    Blog Entries
    230
    Thanks
    0
    Thanked 71 Times in 46 Posts
    Status
    Offline
    Now I added that this works for the 8330.
    The above method works for 8130, 8130m, 8330, 8330m...

    You can skip a few steps. I am not going into detail on this...

    1st, use unicdma and do a mem scan for readable areas, if it is readable, scan readable areas and save bins (keep note of memory range for each file).
    If not readable, load the oldest OS on the blackberry you can find, then do the mem scan...

    after saving the mem dumps, I use winhex to locate the ESN or pESN & MEID in reverse (endian). I then create a list of all mem locations.

    I then use QXDM to zero out all locations, then read ESN or MEID in NV Browser, if it shows zeros, put in your new MEID or ESN and write it.

    I have found that when I zero out the memory locations that when I go from smallest to greater memory locations that some of the ESN/pESN are not there, I then have to rescan mem locations to find the few that moved... The fix I have found is to start with the ESNs or pESNs and start at greater working to smaller, then zero out MEID if MEID based doing greatest mem location to least......

    If your do get all 0's when you read in NV Browser, DO NOT RESTART THE PHONE BEFORE WRITING NEW ESN OR MEID...

    Now load whatever OS you want...

    Best of luck...

  3. #3
    Newbie
    Points: 5, Level: 1
    Level completed: 9%, Points required for next Level: 45
    Overall activity: 0%

    Join Date
    Nov 2011
    Posts
    1
    Points
    5
    Level
    1
    Thanks
    0
    Thanked 0 Times in 0 Posts
    Status
    Offline
    i try to do that and got stuck at
    2. Open the Memory Viewer.
    3. Tell the memory viewer to show the first location your ESN is located at. It should look just as it did in the hex dump.

    when i open the memory viewer it just show
    Memory Viewer.jpg
    do you have any idea what is wrong??

    then you said at point 3 to tell the memory viewer to show the first location your ESN is located at.
    how could i do that?

    sorry im just newbie in this write esn thing..
    please help

  4. #4
    Super Moderator
    Points: 7,435, Level: 60
    Level completed: 43%, Points required for next Level: 115
    Overall activity: 0%
    Achievements:
    OverdriveThree Friends1 year registeredRecommendation First Class5000 Experience Points

    Join Date
    Mar 2011
    Posts
    429
    Points
    7,435
    Level
    60
    Blog Entries
    2
    Thanks
    0
    Thanked 102 Times in 80 Posts
    Status
    Offline
    I think you need to search for the ESN

    did you follow all the instructions? did you use the right OS
    I think its much easier if you use CDMA workshop if you are going to work with cdma phones

    Quote Originally Posted by laruku View Post
    i try to do that and got stuck at
    2. Open the Memory Viewer.
    3. Tell the memory viewer to show the first location your ESN is located at. It should look just as it did in the hex dump.

    when i open the memory viewer it just show
    Memory Viewer.jpg
    do you have any idea what is wrong??

    then you said at point 3 to tell the memory viewer to show the first location your ESN is located at.
    how could i do that?

    sorry im just newbie in this write esn thing..
    please help
    Best Regards,
    Adam Aidy
    UnlockIndustry.com

  5. #5
    Newbie
    Points: 122, Level: 2
    Level completed: 44%, Points required for next Level: 28
    Overall activity: 9.0%
    Achievements:
    31 days registered100 Experience Points

    Join Date
    Jan 2017
    Posts
    13
    Points
    122
    Level
    2
    Thanks
    0
    Thanked 0 Times in 0 Posts
    Status
    Offline

    8130 8330 ESN/MEID Repair without CDMA Wor

    Ive not had any trouble lagging or otherwise with Mobizen, as for the watermark there is an option to turn it off. And as for the A-Z recorder my tablet isnt compatible.
    <a href=https://www.youtube.com/channel/UCrZgHqhrkuQukmJuhJZoxCw>Смотреть мультик Вспыш и чудо машинки</a>


Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •