|
CDMA Workshop Full Version!!! http://rapidshare.com/files/96843950/CDMA_Workshop_2.7.rar CDMA WORKSHOP MANUAL- Reference Guide Here Main
Main section contains COM port settings, DM mode, AT commands, Phone connect, disconnect and phone mode settings.
http://www.cdma-ware.com/pic/spec/workshop_1.gif
Terminal
This is a low-level terminal which allows you to send internal commands and receive answer from a handset in Hex or ASCII format. It useful in different investigation and custom situations, for example it allow you to repair damaged SPC (0x00, 0x00... 0x00 for example) when a handset does not accept any SPC. It has a counter of total amount of bytes in commands, automatic CRC calculation and commands history, in order to facilitate usage.
http://www.cdma-ware.com/pic/spec/workshop_2.gif
Nam Programming
In order to program handsets to a necessary network you must write network settings such as Mcc, Mnc, Sid-Nid pairs, Primary/Secondary channels and other. You can write these parameters here, as well as read existing network settings from a handset.Note that some networks with enabled roaming function are required to be programmed with valid IMSI also. Otherwise, incoming calls will fail. You can write valid "True IMSI" to phone in this window also.
http://www.cdma-ware.com/pic/spec/workshop_3.gif
Memory / Eeprom
Read/Write/Scan - it is the Peek/Poke based functions. At first, you can scan memory by using the "Scan Memory" function, in order to get a memory map and find readable addresses. After that, you can use Read/Write functions with the valid addresses. Note that some models will restart when you try to get access to no readable areas.
"NV Items" section - You can backup /restore any amount of NV items here. Doing so you can backup / restore all phone settings: user settings, network settings, RF calibrations, etc.
http://www.cdma-ware.com/pic/spec/workshop_4.gif
Security
"ESN" section - You can change ESN (Electronic Serial Number) here, this function is useful for repair damaged ESN or write new one in order to make clone phones. Note that some brands and models will allow you to write new ESN by using "default" method after entering internal security password (16 digits, see below) only.
- "Universal RAM" method will search all ESN addresses in RAM and save it to file, after that it will use these addresses to write new ESN directly. This method is very useful to use for brands and models which are not supported by other methods, for example non-native Motorola models (t182, c210, etc), Epsilon, Compal, Aiko, ZTE, Axesstel and many other brands and models.
- "Universal EFS" method will work on the majority modern models based on EFS (Embedded File System), such as latest Samsung Sprint/Verizon models, Treo 700, Audiovox/UtStarcom models (6600, 6700, 120sp, 7025sp, etc), Kyocera new models, new LG models, Samsung V, S-series, Motorola MS-series (ms400, ms500, etc) and many other brands and models.
You can see ESN prefix (ESN owner or phone manufacturer) in pop-up hint by moving mouse cursor to the ESN field here also. This feature is very useful to see - is the current ESN original or it already has once been changed.
• "SPC" section - You can read/write and send SPC (Service Provider Code, 6 digits) unlock code to a phone here. Note that some brands and models will allow you to read current SPC by using "default" method after entering internal security password (16 digits, see below) only.
All CDMA handsets are locked by SPC and it will ask for a valid SPC at trying of change Nam settings (network settings), PRL, NV items, etc. CDMA Workshop will show a notification message about it automatically. You can send current SPC to the phone to unlock it by using "SPC - Send" button.
- "Universal RAM" method will read all 6-digit security codes (SPC, MSL, FSC, OTKSL, etc) directly from RAM. This method is very powerful and useful in order to extract security codes for brands and models which not have EFS support, old models, or models which have locked EFS (for example new Sanyo models and others)
- "Universal EFS" method will work on the majority modern and old models based on any versions of EFS and will read all 6-digit and 4-digit (user lock) security codes.
- "Kyocera Minlock (SPC3)" - This is a universal automatic method, used to read Minlock unlock code (also known as SPC3 and Master code) on Kyocera models based on old version of EFS (se44, se47, kx/ke424, etc)
• "Password (16 digits)" section - Some brands and models are protected by internal security password (16 digits), you must send a valid password to the handset by "Send" button for such models. These models will ask such password at trying of change ESN, reading/writing memory, etc. CDMA Workshop will show a notification message about it automatically in this case.
For example Kyocera, Sanyo, LG, etc does not use this kind of protection in their models. Samsung Sprint models use the same password for all models, it called "Samsung - (default)" in the list of passwords, same password is used in most other Samsung models from other countries and regions (Latin America, Asia and Oceania, etc). You can add very easily your own passwords to the general list of passwords also. But even if you dont know password or it does not present in the list, you can read SPC, Cave settings (A-key, etc) and change ESN by using "Universal EFS" methods.
• "User Lock" section - You can read/write 4-digit user lock here, as well as enable/disable it.
http://www.cdma-ware.com/pic/spec/workshop_5.gif
Cave
"Cave" section - The A-key is used in many CDMA networks in authentication process (besides a basic parameters ESN and phone number), security of the A-key is critical in such CDMA systems. To make clone phones A-key, Ssd_a (Ssd_b) must be also programmed in such networks. You can read original Cave (Cellular Authentication and Voice Encryption) settings and write new ones on this tab. "Universal EFS" method will read these settings on the majority modern and old models based on any versions of EFS. "A-Key Calculator" section - You can generate a valid A-Key with 6-digit checksum here. This is sometimes required for testing the phone's A-Key entry function as well as for the phone's activation. It used to be possible to obtain a valid A-Key with checksum only from the cellular operator itself, now everyone can easily generate the secret checksum value, enter those numbers into the phone just using the phone's keypad. When you want to program the new A-Key into the phone over the keypad you must enter 26 digits (20 digits A-Key in DEC + 6-digit checksum).
http://www.cdma-ware.com/pic/spec/workshop_6.gif
Other
You can read and write PRL (Preferred Roaming List) here, clear available timers, change R-Uim settings and make rebuild Eeprom/EFS on this tab. Rebuild Eeprom is designed for Samsung models only, but this method is works for most other brands also, such as Withus, Epsilon, Compal, etc.
http://www.cdma-ware.com/pic/spec/workshop_7.gif
Monitor
The "real-time network monitor" function is allow you to observe online/ ffline phone activity and status. This function is very useful to finding and solving problems with non-correct phone programming when phone cannot make calls or cannot find network.
http://www.cdma-ware.com/pic/spec/workshop_9.gif
* thanks to cdma workshop !
Редактировал felix - 09 Мар 2008 14:53
|
|
How to Change Your ESN Number! In this How-To I will show you how to change your ESN number on a CDMA phone. Things You’ll Need: CDMA Phone USB Data Cable QPST (any version) Cell Phone Modem Drivers ESN Checksum Calculator XVI32 Hex Editor Step 1: First you need to learn your MSL(SPC) Code. To get this you will need to call up your Service Provider and ask for it. I have found that telling them that you are activating your phone and you need to complete the activation, that they will be more inclined to give it to you.
Step 2: Software Needed Second, you will need to download QPST (any version), An ESN Checksum Calculator, and XVI32 Hex Editor. I currently use QPST 2.7 I have attached some of the harder to find ones at the bottom.
Step 3: Modem Drivers Next, you need to get the Modem Drivers for you computer and connect your phone to your computer. These modem drivers can be found usually on the Carriers Website. I know that on Sprint if you access your account, click on "Phone and Plan", Then "Phone Details", and go to "Software Downloads", you can download the package that includes all drivers for all Sprint phones.
Step 4: Device Manager After you install the drivers and have your phone connected, go to "Device Manager". You can access this by right-clicking on "My Computer "and going to "Properties." Find out what Com Port Your Phone Is Using
Step 5: QPST COM Port After you learn the Com Port, open up QPST and click "Add New Port." Select your COM Port and click "OK".
Step 6: QPST Config Now if everything worked right you should see this.
Step 7: $SYS.ESN Now Click Your Phone and then "Start Clients", then "EFS Explorer". You will be prompted to enter an "SPC" which is the MSL Code you got earlier. Wait for the phones NVM to load then navigate to: "NVM" > "$SYS.ESN" Copy "$SYS.ESN" somewhere on your computer.
Step 8: Checksum Now open up "ESN Checksum Calculator". Enter the (HEX) ESN from the new ESN you want to use. If you only have the 11 digit number go to this website. http://www.elfqrin.com/esndhconv.html Click "Calculate" to get your "Checksum"
Step 9: XVI32 Alright, Now open up XVI32. Using XVI32 open the $SYS.ESN file you saved earlier. Inside will be a whole bunch of numbers. Your ESN and Checksum numbers are inside here. The ESN number is the first 4 boxes on the last row, and the Checksum is the next 4 boxes on the last row. The way you have to enter them is weird so pay attention. In my case my ESN number is AB2B3C4F So in the first 4 boxes I put 4F3C2BAB, and the same thing with the Checksum. Refer to the picture. So by breaking the ESN number into sections of 2 it is much easier. Original- AB 2B 3C 4F Afterwards- 4F 3C 2B AB That makes it much easier to see.
Step 10: After you finish that, save the $SYS.ESN and then copy it back into EFS File Explorer, and let it overwrite the old one. After that, you are all done. Unplug your phone and restart it. When you do you will have a new ESN number! Tips & Warnings ESN Checksum Calculator -http://rapidshare.com/files/37876222/ESN_Checksum.exe.htm XVI32 - http://rapidshare.com/files/37876407/XVI32.exe.html This Information is for knowledge purposes only. It is not legal in the US to change your ESN number, SO DONT DO IT! By cac9478
Редактировал felix - 09 Мар 2008 15:33
|