Posted: Sat Feb 19, 2005 8:09 pm Post subject: Allservice Software - What's new.
- R24RF08 2.0b + Add-Ons (Freeware) - reader for ATMEL 24rf08 eeproms used in IBM ThinkPad.
The kit includes now the R24C01 (24C01 reader) and ITester (interface testing utility).
- W24RF08 2.1a (30 US$) - writer for ATMEL 24RF08 (CRC recovery assistance. TCG/TCPA chip reset)
- PC8394T programming tools ($110) - Software for flashing TPM/secure storage chips in new TP models.
Suitable for R52, R60, T43, T60, X60, Z60 series, Z61 series.
- IBMpass 2.1 Lite (Freeware) - Scancode editor/decoder for eeprom dumps. Can be used for IBM, Dell, Sony Vaio, etc.
- SPEG -Universal Serial Flash Programmer ($89) - Software for programming Serial Flash BIOS chips used in modern PCs. Suitable to unlock Lenovo SL300/400/500 series, HP laptops, and more. SPEG is also the recommended tool for BIOS repair and we offer support for Thinkpad BIOS recovery (4 beeps error, 0192 error, etc) for SPEG licensees.
Posted: Mon Jun 06, 2005 10:16 pm Post subject: IBMpass 2.0
We can announce a new release - IBMpass 2.0
IBMpass 2.0 Professional is a complete tool for editing eeprom dumps. The free version IBMpass 2.0 Lite is available to download.
Many thanks also to all friends who tested the beta version.
Updated feb.2006
Now includes support for ACER and SONY VAIO password encoding. This option is available only in IBMpass Professional for the moment.
IBMpass 2.0 beta preview .
Last edited by victor on Mon Feb 27, 2006 7:14 pm; edited 3 times in total
Posted: Thu Jul 07, 2005 6:30 pm Post subject: New versions
We are pleased to introduce you the version 2.0 of the well known 24RF08 tools, by now. The main changes for R24RF08 and W24RF08 are:
-Improved support for other serial interfaces with the possibility to adjust the logical level for SDA and SCL signals.
-Some issues with the timer that have been solved.
-A new improved eeprom reset procedure.
Many thanks to my colleagues and also to the testers.
Posted: Wed Jun 14, 2006 4:37 pm Post subject: Thinkpad T43 and R52 Unlocking software
We are glad to announce other two releases:
RPC8394 and WPC8394 are the first versions of two software designed for reading and respecively writing
the PC8394T-VJG super IO & TPM chip. That is used in T43 and R52 Thinkpads to store the supervisor password.
It was confirmed that PC8394 Tools are suitable to read/write the security chips in Z60t/Z60m. The following Thinkpad models can be unlocked using RPC8394/WPC8394:
-T43/p
-R52
-T60/p
-Z60t/m
IBMpass can reveal the password from the chips binary. However, a new version, IBMpass 2.1 is to be launched soon and will be presented in two versions, freeware and commercial.
Posted: Fri Mar 07, 2008 8:00 pm Post subject: Unlocking new models R61, T61, X61, X300 (1), T400, t500...
Updated: May 2013
Reason: More pics added
We have the confirmation for newer R61, T61 and X61. They don't use a TPM system like T43/R60/X60/T60, they dropped back to P24S08 (24RF08 clone).
Pictures added (as we unlocked them) for: L412, L512, SL410, SL510, R400, R500, T400, T410, T420, T500, T510, T520, T530, X1, X100e, X121e, X201, X300(X200), X220, X301, W500, W510, W520, W530, W701, Edge 13-14-15, Edge E120, Edge E320.
For eeprom 24RF08/P24S08 and variations like PS08 and L08 you must use R24RF08 - the free 24RF08 eeprom reader - and IBMpass 2.1 lite.
Note: If IBMpass Lite cannot reveal the passoword, then is 100% TCPA locked, in which case W24RF08 (eeprom writer) and our TCPA reset service is required. TCPA algo is changed, is not the same used in the previous models.
If you like us to assist you or to verify the TCPA lock status in order to confim the need of W24RF08 and the TCPA service, simply send the eeprom binary dumps to support@allservice.ro
R61:
P24S08 (8pin) is usually located on the frontside of the mainboard, under the keyboard. Is quite easy to get access there.
For 14' widescreen models, the eeprom is on the backside (second picture). 15' 4/3 models have the eeprom under PCcard cage on the frontside.
Courtesy R. Katz - USA, for the new T61p images and for all support.
X61:
This is using a small factor PS08 eeprom (24RF08 clone), its position is below the "M" key. It requires the keyboard, front bezel and the modem sub-board to be taken apart.
I wish to express our gratitude to S. Helie (UK) who helped us with the first X61 works, and last but not least, to S. Cyiako (Sweden) who mailed us a perfect X61 mainboard for the tests.
[Updated]
X300, X301, X200 and X201, X220, X100e, X120e, X121e, X1...done. They use the same 24RF08 clone like the other 61's (appart from Z61 series that still use TPMs). For X300, the eeprom has alternate connection points located underneath, near the memory socket. X100e has the PS08 mini eeprom like the X61 and X121e features the L08 (same eeprom).
We've tested on 2 mainboards and TCPA algo is again different.
Great thanks to V. Rikalovic (Serbia) and M. Yang (USA) for the nice shots.
R400, R500, W500 and W700 - R400 and W500 have the eeprom underneath. For R500 is the same 24RF08 clone located on the upper side of the motherboard, under the PCcard/ExpressCard cage. The board must be removed form the Mg frame and you have to peel the black sticker that covers the area
SL410 & SL510 - Looks like the new SL series switched from AMI to Phoenix FirstBIOS so our old friend (24RF08 - PS08) is back in business once again. R24RF08/W24RF08 is the right software, as usual.
*The older SL400/SL500 still need the SPEG programmer to be unlocked.
T420, T420s, T520, T530
All of them use the tiny L08 eeprom. These models have passprase always active, and they require TCPA unlock service and W24RF08. T530 has the eeprom covered by the black stickers
Note:
All images are property of allservice.ro or their authors passed the publishing rights to allservice.ro. _________________ Victor Voinea
ALLservice HQ, Romania.
Last edited by victor on Thu May 16, 2013 1:11 pm; edited 44 times in total
Posted: Sat Jul 25, 2009 5:24 pm Post subject: SPEG - Universal serial flash programmer
We are proud to announce our new release for programming Serial Flash BIOS ROMs.
[Edit]
SPEG is available now!
Special thanks to R. Katz (USA) for his impressive work on testing the package with Lenovo T and R series BIOS and B. Nguyen (USA) for all support and ideas. Many thanks to the support team as well.
[/Edit]
The program is SPEG - Universal serial flash programmer and is able to process almost all new serial flashes used nowadays for BIOS in almost everything, even in iphone 3G.
We've paid a special attention to SST chips, they are a bit different from the rest.
Note: SPEG is the right solution to unlock Lenovo SL300, SL400, SL500 and G550. These models keep the password in BIOS serial flash that must be read, cleaned up and reflashed. We offer a free cleaning service/ BIOS repair service with every SPEG purchase.
Surely, you've heard of Intel Anti-Theft system. This new technology used in latest Thinkpads is very similar to Computrace and despite they claim that has no relation with the AMT, this is not exactly true. Here is an example of one disabled machine we received from a customer (It's a T400 model wired up on an external monitor)
Well, now we can recover the Thinkpads from this thing. The laptop needs a serious BIOS code rework (and also the eeprom 24RF08/P24S08 must be modified, in some cases) and it will be like new. The service is available for SPEG users now. _________________ Victor Voinea
ALLservice HQ, Romania.
We can announce now that all HP models, based on serial flash BIOS can be unlocked by our team and that is final. The required software is SPEG programmer in order to read the BIOS and email us the binary to be fixed.
We also worked on various models coming from Fujitsu. We mean those that couldn't be unlocked via codes such as the new models with 6x4 digits hash. All of them could be unlocked after we patched the BIOS.
Some other news is that we could unlock some Macbook Pro in the same manner.
Tests will be carried out so if you have any questions contacts us. _________________ Victor Voinea
ALLservice HQ, Romania.
Last edited by victor on Thu May 16, 2013 1:22 pm; edited 1 time in total
Posted: Tue Apr 09, 2013 1:16 pm Post subject: Macbook Pro and Air unlocked.
We finished the tests on unlocking MAcbook Pro and Air, models 2008-2013 (that includes late 2013 retina models) succesfully. We can reset the firmware lock (firmware password and pin lock) without altering the orignal BIOS code or credentials.
Some issue fixed with the fonts in Win Vista/7 and up, where special characters were not displayed correctly in unicode. _________________ Victor Voinea
ALLservice HQ, Romania.
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum