[Completed] Telcast X80 plus dual boot support - XDA Assist

It is dual boot Windows 10 Genuine plus Android 5.1
It Definitely made a mistake by buying this tablet and i will detail my problems in detail
When i first bought this tablet, it went OK and two many Chinese apps were installed and uninstalled.
My problem started after almost 1 week of usage when my tablet started showing error for my memory card SAFE TO REMOVE android. i tried inserting multiple memory cards but no use. Windows partition never detected memory card till date.
As i bought from gearbest i raised dispute, after that they offered me two options.
First was that i have to send this tablet to China and bear shipping cost of around 25-30 USD (approx rate from India) also after receiving item they will give me full refund, i declined to bear shipping as God knows they will ever say that they have received tablet back or not.
Second they offered me partial refund, initially which started from 30 USD, finally i agreed for 50 USD dollar refund for purchase of 91 USD. guess windows partition was working flawlessly expect for memory card issue.
(NOW THE TECHNICAL PART FOR WHICH I NEEDED URGENT HELP)
After receiving refund i started going through various sites to check how to fix this issue(worse Mistake i believe)
i rooted my tabled( android) with tool .by spzjulien. tablet got rooted but now it is almost not working, touching is not responding, screen is also upside down, almost unable to do anything on android part.
After that i downloaded intel phone flash tool 5.3.4 as it was said for teclast website also i downloaded new android stock rom file Android 5.1 v1.06 for my tablet serial number H5C5. strickly followed procedure but i am facing error as sharing log file below and image of tablet and screenshot of intel phone flash tool i will send you in messages as i am unable to post here.
First i installed iSocUSB-Driver-Setup-1.2.0.exe, then IntelAndroidDrvSetup1.5.0.exe and in last PhoneFlashTool_5.3.2.0_win32.exe.
Then i opened "Phone Flash Tool" , clicked “Browser”button, in pop-up window and loaded the android burning file, then changed “Configuration” content as “update”, enabled development mode and usb debugging, then i connected tablet, it gets detected and then i clicked Start to Flash, tablet gets restart and almost after 4%, it gives me error as log code shared. fastboot error. i dont know how to fix fastboot error.
Kindly please help
Already Posted this Link so many days ago.
http://forum.xda-developers.com/x98...oot-device-t3378613/post66840332#post66840332
No replies please provide any type of assistance as soon as possible.
LOG FILES of intel phone flash FOR ERROR ONLY
05/14/16 01:26:08.975 ERROR : [Auto Update] No update download available
05/14/16 01:27:48.619 ERROR : [Port 1/1/2] Command `"C:\Program Files (x86)\Intel\Phone Flash Tool\fastboot.exe" "-s" " " "flash" "osloader" "C:\teclast x80 H5C5\X80 Plus DualOS(H5C5)-Android5.1-V1.06\Android 固件\loader.efi"` failed
05/14/16 01:27:48.619 ERROR : [Port 1/1/2] Flash failed (Command type: Fastboot)
05/14/16 01:28:07.144 ERROR : [Port 1/1/2] Failed to reboot the device
05/14/16 02:06:12.623 ERROR : [Port 1/1/2] Command `"C:\Program Files (x86)\Intel\Phone Flash Tool\fastboot.exe" "-s" "Default0string" "flash" "bootloader" "C:\teclast x80 H5C5\X80 Plus DualOS(H5C5)-Android5.1-V1.06\Android 固件\bootloader"` failed
05/14/16 02:06:12.623 ERROR : [Port 1/1/2] Flash failed (Command type: Fastboot)

Hello and thank you for using XDA Assist,
you asked the same question in the correct section:
Need help for my teclast x80 plus dual boot device
Thread closed, since XDA Assist is only for pointing members to the correct section and not to give support with the problems.
You're free to bump your other thread.
Kind regards
Trafalgar Square
XDA Assist

Related

[HELP!] Velocity Cruz T301 Full Brick Recovery

Hi XDA,
so basically i bought a Velocity Cruz T301 recently and followed the known procedures for rooting, flashing ClockworkMod Recovery and custom rom (SJHill Rom v0.3).
before the full brick my device was at ClockworkMod 5 and rooted with SJHill Rom v0.3.
i installed CWM by flashing the zip in stock recovery, then succesfully rooted the device, finally wiped and flashed my custom rom
after major dissapointment in this tablets performance i decided i wanted to get rid of it.
So i downloaded the stock rom, wipe and flashed it onto the tablet...
the tablet turned off when it was finished (i think it was attempting to reboot) and never turned back on again...EVER! :good:
i cant even get to recovery
i tried flashing with adb and fastboot but the device is never even presents itselft to the computer.
i found out that you can boot the device into USB boot mode where you hold the "VOL -" (Volume Down) button and press the reset button and while connected to the computer (windows only) a "JZ4760 USB Boot Device" appears.
i did some googling and also found out that the T301 is based on similar tech to a bunch of tablets and they can all be modified by some software released by Ingenic called USBBootTool.exe
the tool is written in chinese and i cant decypher it all, though i found out how to use it based on its usage for other Ingenic based tablets
1.) you will need to disable driver signature verification (press F8 on boot of windows and toggle the setting, i hate rebooting too but it has to be done)
2.) boot your tablet into USB Boot Mode (hold down Vol - and press Reset button)
3.) install the driver for your device (included in the files below)
4.) with the tablet disconnected you would open the USBBootTool.exe
5.) select your tablet in the options and fill each box with the files needed to flash (files included below)
6.) reconnect the tablet while still in USB Boot Mode and the software will flash your device on detection
everything goes fine for me except when i get to the flashing part in the end.
when USBBootTool detects my tablet, it attempts to flash and gives me a stream of errors and never flashes my device.
i dont know what to do at this point. i have provided direct links to all the software im using and also links to where i got them.
any help would be appreciated, thank you to the XDA community in advance
>------------------- DOWNLOADS ------------------------<
USBBootTool.exe / Tablet Drivers (4725 / 4725B / 4740 / 4750 / 4755 / 4760 / 4770)
http://dl.dropbox.com/u/79196608/burn_tools_3.0.16.rar
obtained from - http://forum.xda-developers.com/showthread.php?t=1720621
Velocity Cruz T301 Update.zip (contains the system.img / data.img / mbr-xboot.bin files)
http://www.cruztablet.com/T301update.zip
obtained from - http://www.cruztablet.com/Article_861.php
SJHill Rom v0.3
http://www.androidfilehost.com/?fid=9390362690511176486
obtained from - http://www.slatedroid.com/topic/27583-rom-t301-sjhill-rom-17-feb-2012-download-link-updated/
ClockworkMod 5
http://files.androtab.info/ingenic/cwm/20120514/T301-recovery-signed.zip
obtained from - http://androtab.info/mips/ingenic/clockworkmod/
I have the same situation. I have gone through every menu in the USB Boot tool and to no avail am I able to recover my T100.
gmick is redoing the software because the coding is set up wrong. Once he gets that figured out there should be a fool proof unbricking method that we can follow. He is posting information over on Slate Droid if you want to take a look.
feyerbrand said:
gmick is redoing the software because the coding is set up wrong. Once he gets that figured out there should be a fool proof unbricking method that we can follow. He is posting information over on Slate Droid if you want to take a look.
Click to expand...
Click to collapse
ok post the link to the thread, and ill add it to the first post as a solution if its found to be a working one
JustSayTech said:
ok post the link to the thread, and ill add it to the first post as a solution if its found to be a working one
Click to expand...
Click to collapse
*Cross Post from SlateDroid* (but I can't post the link because XDA won't allow it)
I found out why the USB boot isn't working. Well, more appropriately I know where it fails but not exactly "why".
The USB Boot tool works like this:
1) Send x00 command (Get CPU Info)
2) Device responds with "JZ4760V1"
3) Host sends two binaries, stage1 and stage2. Stage 1 sets up memory stuff, and Stage 2 sets up USB flashing functions.
4) Host checks that the binaries executed by issuing another x00 command (Which serves as an "Are you still there?" function)
5) If the response is good, the host will flash the images, if the response is bad, it will abort.
Our devices are failing at step 4. The linux usb boot tools (xburst-tools) fail in an identical fashion.
I know that the first stage binary transfers and executes fine because if it didn't the device would be limited to 16k. The second stage is 120K and is transferred successfully. Once the second stage "execute" command is sent, the device crashes.
The second stage is also unique to the CPU type. I've used all of the binaries for JZ4760 I could find on the net and when that failed I cross compiled my own binary from source and it still crashed.
At this point I highly doubt I'll ever be able to fix it, and this completely explains why no one could get any usb recovery tool to work while others using similar devices could. I guess our board is modified just enough for ingenic's stock binaries to fail. Without knowing what's changed (getting Velocity Micro's source) we're SOL.
I can open it up again and solder on the serial header but I'm betting it's going to give me some generic "couldn't execute" message that isn't going to help me. I'll probably do this anyway though because I've come this far so what's the loss.
wow, i learned alot from that post, seems like writing a usbboottool-like application that can send the commands but also log and possibly bypass security checks etc but that def would take sometime. thank you for your insight, seems youve come the closest to cracking the case, actually you found the fault, hopefully your methods can eventually bring about a fix
JZ 4770
gmick said:
*Cross Post from SlateDroid* (but I can't post the link because XDA won't allow it)
I found out why the USB boot isn't working. Well, more appropriately I know where it fails but not exactly "why".
The USB Boot tool works like this:
1) Send x00 command (Get CPU Info)
2) Device responds with "JZ4760V1"
3) Host sends two binaries, stage1 and stage2. Stage 1 sets up memory stuff, and Stage 2 sets up USB flashing functions.
4) Host checks that the binaries executed by issuing another x00 command (Which serves as an "Are you still there?" function)
5) If the response is good, the host will flash the images, if the response is bad, it will abort.
Our devices are failing at step 4. The linux usb boot tools (xburst-tools) fail in an identical fashion.
I know that the first stage binary transfers and executes fine because if it didn't the device would be limited to 16k. The second stage is 120K and is transferred successfully. Once the second stage "execute" command is sent, the device crashes.
The second stage is also unique to the CPU type. I've used all of the binaries for JZ4760 I could find on the net and when that failed I cross compiled my own binary from source and it still crashed.
At this point I highly doubt I'll ever be able to fix it, and this completely explains why no one could get any usb recovery tool to work while others using similar devices could. I guess our board is modified just enough for ingenic's stock binaries to fail. Without knowing what's changed (getting Velocity Micro's source) we're SOL.
I can open it up again and solder on the serial header but I'm betting it's going to give me some generic "couldn't execute" message that isn't going to help me. I'll probably do this anyway though because I've come this far so what's the loss.
Click to expand...
Click to collapse
for my JZ4770 Earlier USB tool was flashing .img without any problem but for now it is saying "load cfg failed". "API downlaod failed' like dialogues and doesnt flash anything. Any idea? Thanks in advance!!
First restart your computer (actually restart it) then redownload the USB boot tool and save it in a completely new directory and use a different USB port
Sent from my Pokeball
Yes, I did
JustSayTech said:
First restart your computer (actually restart it) then redownload the USB boot tool and save it in a completely new directory and use a different USB port
Sent from my Pokeball
Click to expand...
Click to collapse
Yes, I tried with this suggestion. Rather I reinstalled xp and the tried again. But the dialogues are same. The history is like this. Was having ICS on JZ 4770. Formatted with usb tool and put JB updates. It was not sensing touch so reflashed another JB updates. Now the tab boots, it reaches to boot logo for around 12 seconds and restarts in stock recovery. While it is in booting stage it get detected by windows and adb also. In stock recovery mode it get detected by windows and in turn by adb also. If I tried to install updates through SD card it shows it had installed and reboots after completion. But again the same way it goes to boot logo and then back to stock JB recovery. It also boots in ingenic boot device mode and gets detected by USB burn tools. But when try to flash any of the ROM it gives the same dialogues "check cfg failed" "api download failed" "boot. fw failed" and cant flash anything.
Is there any tool which can be flashed or a script which can be used from SD card for completely formatting flash memory so that USB burn tool can flash required ROM?
can you flash the stock rom in recovery?
Managed using USB BOOT TOOL for ingenic JZ 4770 board in English
JustSayTech said:
can you flash the stock rom in recovery?
Click to expand...
Click to collapse
thanks man but I managed to boot the device. I used following USB BOOT TOOL for ingenic 4770 boards. The goodness with this tool, this is completely in English. You will know what you are doing. Even after opening the main window of the tool you can right click and then get another options(yes again in English). My problem with this device was bad blocks at 1024. In the options there is chance to force erase whole the nand partitions which I used and erased all the partitions thereby made all the partions available for flashing and readable by the tool. Then from File option selected stock rom files and flashed them. While flashing selected JZ4770 iNanad.ini file in manual configuration. This tool has really helped me to come out of the issue and will be useful for guys using JZ 4770 board.
http://www.4shared.com/rar/m1BUV5r2/USBBurnTool_20120401_for_relea.html
Got USBBootTool.exe kind of working.
1. Download the following file from Ingenic.
ftp * ingenic * cn/3sw/01linux/tmp/jz4770-20110610.rar
2. Download Applocale from Microsoft.
www * microsoft * com/en-us/download/details.aspx?id=13209
3. Extract the jz4770-20110610.rar and find the folder. (Using 7zip should keep the UTF encoding in Chinese)
20110610\04burn\20110524_4770_Programmer
4. Copy the folder 20110524_4770_Programmer to location you want to use it in.
5. Install Microsoft Applocale (Just in case, I don't think it is required)
Now Start Applocale and create a shortcut to USBbootTool.exe inside 20110524_4770_Programmer
中文(简体) is simplified Chinese option and should let you view the GUI correctly.
6. Now with the Applocale Shortcut created for USBbootTool.exe you can start the application with correct fonts.
Now this is where is breaks down.
TABLET-8 NAND FINAL BSP(S3 TEST) will allow you to read from it and write to it, but the CFG is off.
\tool_cfg\tablet-8-nand-final.ini is the configuration for it.
DO NOT CONNECT THE DEVICE WITH ANY OPTIONS CHECKED OR LOAD ANY FILES.
See Attached Images.
Next to the Read button is some Boot Option menu. I am not fulling aware of what this does.
What I need is a someone to help me fix/correct the ini/cfg files in
\20110524_4770_Programmer\tool_cfg\.ini
\20110524_4770_Programmer\4760\
to correctly match the files of the NAND.
Also if anyone has a copy (dd to img) or (cat to img) of the block devices.
That would help a ton.
# cat /proc/partitions
# cat /proc/mtd
I would also love another T10x Tablet for cheap.
I want to start building things like new bootloader, kernel, system image,
performance libraries to take full use of the Ingenic JZ4760 (www * ingenic * cn/product.aspx?CID=11)
I also bring Christmas gifts
2 APKS. You can place them in /system/app or /data/app.
Google Play will crash now and again, but it will load and work. (Vending.apk)
Secondly I bring the gift of performance increase, just by a slight bit.
edit the line of the heapsize in /system/build.prop dalvik.vm.heapsize=96m
Remember to make sure the permissions are set back to 666 or 644.
Original Vending.Apk before updates came from here: (Incase you are paranoid)
code * google * com/p/ics-nexus-s-4g/source/browse/trunk/system/app/Vending.apk?spec=svn20&r=18
ics-nexus-s-4g * googlecode * com/svn-history/r18/trunk/system/app/Vending.apk
To prevent spam on the XDA forums, ALL new users prevented from posting outside links in their messages. After approximately 10 posts, you will be able to post outside links. Thank you for
Click to expand...
Click to collapse
Stupid. how do you expect real people to help post Tech Docs? That is bad Moderating and Administrating.
Make sure to replace the Asterisk's with spaces to normal dots.
Requesting Block Images.
Does anyone have a copy of it they can send me for a T10x?
block images......
IceGryphon said:
Does anyone have a copy of it they can send me for a T10x?
Click to expand...
Click to collapse
Which block images do you want?
...also is there a way to rip the stock images off the jz4760 in the t301.
Such as:
Can i usethe ingenic uboot tool?
Anybody find the jtag pins?
Is the 4 pin conn next 2 the batt for serial?
.......i guess ill try to take a look this weekend
Ics would be really nice, but probably slower than stock..... especially with the limited ram
I unpacked the stock rom. I also unpacked an ics rom for a jz4770, and repo sync'd the aosp and mips 3.0.8 android kernel.
I'm still trying to figure out specs for the processor though. I know that its mips32 - el- fp- r1, but i cannot figur out the dsp version ... if it has one?
Error in erasing nand
nanachitang420 said:
thanks man but I managed to boot the device. I used following USB BOOT TOOL for ingenic 4770 boards. The goodness with this tool, this is completely in English. You will know what you are doing. Even after opening the main window of the tool you can right click and then get another options(yes again in English). My problem with this device was bad blocks at 1024. In the options there is chance to force erase whole the nand partitions which I used and erased all the partitions thereby made all the partions available for flashing and readable by the tool. Then from File option selected stock rom files and flashed them. While flashing selected JZ4770 iNanad.ini file in manual configuration. This tool has really helped me to come out of the issue and will be useful for guys using JZ 4770 board.
http://www.4shared.com/rar/m1BUV5r2/USBBurnTool_20120401_for_relea.html
Click to expand...
Click to collapse
I used english ingenic tool to erase bad blocks but m nt able erase bad blocks live suit is giving eror id=0x4848

Chinese Note II clone problem (Star S7100 - MTK6577)

Hi,
I have just bought a chinese Note II clone.
Code:
www dot cellphonemic dot com/mtk6577-android-phones/s7100-mtk6577
The phone seems to be unable to handle SIM properly. On every start I get the error message:
com.android.phone stopped
Click to expand...
Click to collapse
SIM Toolkit is also unable to start. When I start or receive a call, the display goes blank or just flashes up for a moment. (This problem is resolved already, see here)
I was told it is most likely a firmware error. On searching, I didn't find this model or similar in the forum. I also tried several rooting methods described here without success.
Here are some details I could get from the phone:
Code:
BuildInfos
Android version : 4.1.1
Release Codename : REL
API LEVEL : 16
CPU ABI : armeabi-v7a
Manufacturer : alps
Bootloader : unknown
CPU ABI2 : armeabi
Hardware : mt6577
Radio : unknown
Board : e1901_v77_jbla668_9p017
Brand : alps
Device : e1901_v77_jbla668_9p017
Display : e1901_v77_jbla668_9p017_20121120
Fingerprint : alps/e1901_v77_jbla668_9p017/e1901_v77_jbla668_9p017:4.1.1/JRO03C/1353390730:user/test-keys
Host : agold-w12345-desktop
ID : JRO03C
Model : e1901_v77_jbla668_9p017
Product : e1901_v77_jbla668_9p017
Tags : test-keys
Type : user
User : root
I asked the chinese merchant I bought the phone from but he seems quite uncertain, although he promised to send a new ROM.
Can anybody help? Thanks in advance
Unfortunately is often quite difficult to get support for those Chinese clone devices. I hope you'll find someone that can help you but I think your best bet is to ask the seller for a replacement.
Sent from my HTC One X using xda app-developers app
At least I could root. Then I could try some custom ROM at my own risk.
Don't install ROMs from Galaxy Note II threads beacuse chinese versions of phones isn't the same that samsung's devices! You may brick the phone
farmer92 said:
Don't install ROMs from Galaxy Note II threads beacuse chinese versions of phones isn't the same that samsung's devices! You may brick the phone
Click to expand...
Click to collapse
It was never in my mind. This is why I posted here. But the question is still academic, since firmware update requires rooting (as far as I know) and I am unable even to root.
Proximity sensor
The problem of blank/flashing screen during calls has been resolved. The proximity sensor needed a proper calibration. I did the calibration many times so far, but not the correct way. I have just figured out how it should be done effectively.
pls teach me.
Gorcsev.hu said:
The problem of blank/flashing screen during calls has been resolved. The proximity sensor needed a proper calibration. I did the calibration many times so far, but not the correct way. I have just figured out how it should be done effectively.
Click to expand...
Click to collapse
Hi, can you teach me how to calibrate?
utchti per
mridzuan85 said:
Hi, can you teach me how to calibrate?
Click to expand...
Click to collapse
It is actually a simple process. Locate your proximity sensor, it is a small LED-like thing next to the speaker, on either side. Look for calibration of proximity sensor, you can find it usually amongst the display options. Tap on it, target-like concentric circles appear and the application asks you to place some obstacles over the sensors. The easiest way is to hold your palm above the sensor approx. 5 cm (2 inches) apart. Touch the Start button, and then try to complete the process with your hand motionless. The whole process takes a few seconds. If you did everything right, during a call, holding the phone to your ear the screen goes blank, and the phone application re-appears when moving the phone away.
Ealps e1901_v77_jbla668_9p017
I have a device that if I need to send you the rom Ealps e1901_v77_jbla668_9p017 Model:N7100+ 1GB
Gorcsev.hu said:
Hi,
I have just bought a chinese Note II clone.
Code:
www dot cellphonemic dot com/mtk6577-android-phones/s7100-mtk6577
The phone seems to be unable to handle SIM properly. On every start I get the error message:
SIM Toolkit is also unable to start. When I start or receive a call, the display goes blank or just flashes up for a moment. (This problem is resolved already, see here)
I was told it is most likely a firmware error. On searching, I didn't find this model or similar in the forum. I also tried several rooting methods described here without success.
Here are some details I could get from the phone:
Code:
BuildInfos
Android version : 4.1.1
Release Codename : REL
API LEVEL : 16
CPU ABI : armeabi-v7a
Manufacturer : alps
Bootloader : unknown
CPU ABI2 : armeabi
Hardware : mt6577
Radio : unknown
Board : e1901_v77_jbla668_9p017
Brand : alps
Device : e1901_v77_jbla668_9p017
Display : e1901_v77_jbla668_9p017_20121120
Fingerprint : alps/e1901_v77_jbla668_9p017/e1901_v77_jbla668_9p017:4.1.1/JRO03C/1353390730:user/test-keys
Host : agold-w12345-desktop
ID : JRO03C
Model : e1901_v77_jbla668_9p017
Product : e1901_v77_jbla668_9p017
Tags : test-keys
Type : user
User : root
I asked the chinese merchant I bought the phone from but he seems quite uncertain, although he promised to send a new ROM.
Can anybody help? Thanks in advance
Click to expand...
Click to collapse
wapcell said:
I have a device that if I need to send you the rom Ealps e1901_v77_jbla668_9p017 Model:N7100+ 1GB
Click to expand...
Click to collapse
Hi,
thanks for the response. How is your ROM working? Is it fully functioning, rooted or not etc.
How should it be installed? From SD card or by flashing application?
Send it anyway, having itself doesn't do any matter.
Thanks in advance
I have the exact same phone as you but mine seems to be working fine. I've tried to root it and there is no way I can find to root it. Especially since my boot menu is in Chinese! I would give you my ROM if I knew how.
I guess buyers should run the risk when buying clone phone. Asking replacement seems to be the answer.
Gorcsev.hu said:
Hi,
thanks for the response. How is your ROM working? Is it fully functioning, rooted or not etc.
How should it be installed? From SD card or by flashing application?
Send it anyway, having itself doesn't do any matter.
Thanks in advance
Click to expand...
Click to collapse
I bought it new, this operating normally not installed anything bought for resale in my store, the menu it is in recovery mode chines do not know how to back up if you know tell me that I send to you.
S7100
gog3219 said:
I have the exact same phone as you but mine seems to be working fine. I've tried to root it and there is no way I can find to root it. Especially since my boot menu is in Chinese! I would give you my ROM if I knew how.
Click to expand...
Click to collapse
I have the same phone as well rooted and fully english ! I can upload my rom to dropbox i u guys are interested ?
same phone after root prosess death bricked any help
hi
i have same phone e1901_v77_Vjbla668_ mtk6577 model s7100
i have root prossess via sp tool phone no display death condition any idea for solve issue ???
pls hlp me
Gorcsev.hu said:
Hi,
I have just bought a chinese Note II clone.
Code:
www dot cellphonemic dot com/mtk6577-android-phones/s7100-mtk6577
The phone seems to be unable to handle SIM properly. On every start I get the error message:
SIM Toolkit is also unable to start. When I start or receive a call, the display goes blank or just flashes up for a moment. (This problem is resolved already, see here)
I was told it is most likely a firmware error. On searching, I didn't find this model or similar in the forum. I also tried several rooting methods described here without success.
Here are some details I could get from the phone:
Code:
BuildInfos
Android version : 4.1.1
Release Codename : REL
API LEVEL : 16
CPU ABI : armeabi-v7a
Manufacturer : alps
Bootloader : unknown
CPU ABI2 : armeabi
Hardware : mt6577
Radio : unknown
Board : e1901_v77_jbla668_9p017
Brand : alps
Device : e1901_v77_jbla668_9p017
Display : e1901_v77_jbla668_9p017_20121120
Fingerprint : alps/e1901_v77_jbla668_9p017/e1901_v77_jbla668_9p017:4.1.1/JRO03C/1353390730:user/test-keys
Host : agold-w12345-desktop
ID : JRO03C
Model : e1901_v77_jbla668_9p017
Product : e1901_v77_jbla668_9p017
Tags : test-keys
Type : user
User : root
I asked the chinese merchant I bought the phone from but he seems quite uncertain, although he promised to send a new ROM.
Can anybody help? Thanks in advance
Click to expand...
Click to collapse
bhudev2dave said:
hi
i have same phone e1901_v77_Vjbla668_ mtk6577 model s7100
i have root prossess via sp tool phone no display death condition any idea for solve issue ???
pls hlp me
Click to expand...
Click to collapse
You may try to flash the original factory ROM via Flash Tool, if your phone still can be recognized.
Btw. root access can be gained by replacing the Chinese recovery with CWM recovery, then installing SU from CWM recovery.
Successfully rooted
I have just successfully rooted my phone. The process was as follows:
I replaced the Chinese factory recovery mode with CWM recovery via Flash Tool.
Started the phone with CWM recovery and installed a superuser package from it.
If anybody interested, I can provide links to files needed along with description of the process.
Hi just joined this group
Can you post how you rooted the S7100 please
Been trying all day with Root_with_Restore_by_Bin4ry_v18
but phone will not root that way
Thanks Jigsey
Gorcsev.hu said:
I have just successfully rooted my phone. The process was as follows:
I replaced the Chinese factory recovery mode with CWM recovery via Flash Tool.
Started the phone with CWM recovery and installed a superuser package from it.
If anybody interested, I can provide links to files needed along with description of the process.
Click to expand...
Click to collapse
Tell me the info please, I have been trying to root mine for days
Flashing CWM Recovery and install root
Download CWM_and_root_flash.rar from here.
Unpack the archive with its folder structure to a path not containing any special characters.
Flashing CWM Recovery:
Turn off the phone without connected to the computer.
Take out the battery and insert it back after a few seconds.
(If the driver is already installed, continue with step 5) Connect the phone to the computer with USB cable. The operating system will detect a new device - direct the wizard to the folder containing the driver (for your version of OS)
[*]When driver is installed, disconnect the cable from the computer.
Run the program SP Flash Tool.
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
Push the button Scatter-loading and select the file MT6577_Android_scatter_emmc.txt (it is in the folder CWM Recovery).
IMPORTANT! Make sure, only RECOVERY is selected in the image list, otherwise the phone could stop working!
Push the button Download.
Connect the phone to the computer. The program should recognize it and start flashing.
If the phone is not detected, then unplug it from the computer, remove and insert the battery and re-connect to the computer.
Also the new hardware wizard may pop up again - just let it install the driver automatically.
When flashing is complete, disconnect the phone.
Boot the phone normally to check everything works properly.
Installing root (Superuser):
Save MT6577 blk0p3 Root by CWM-SuperSU 0.99 angelobiz.zip on SD card (internal SD card is preferred).
Turn off the phone and reboot it in recovery mode by keeping pressed Volume+ and Power buttons simultaneously.
You enter CWM-based Recovery v6.0.1.2 you have just flashed. (Navigate with V+/- and choose with PWR)
Choose "install zip from sdcard" from the main menu.
Either select "choose zip from sdcard" from the next menu if you saved the zip on the external SD card
or select "choose zip from internal sdcard" if you saved the zip on the internal SD card.
Navigate to the zip and press the Power button. When the installation process is complete, reboot the phone normally.
Superuser application is now installed and you can check the root status with a root checker application.

Intel Android Devices Root / Temp Recovery Session

Intel Android Devices Root / Temp Recovery Session
social-design-concepts said:
Disclaimer:
Before you proceed to the rooting instructions below, please read this disclaimer:
XDA-DEVELOPERS.COM and I are not responsible for what you are doing to your device. You understand and agree that you are doing this at your own risk.
as for warranty the rule of thumb is if you root you should always consider your warranty voided : i will make no claim otherwise on the subject.
i am just a simple hobbyist from Cinti. OH USA i have no intention to buy devices or users getting mad that they were under some impression this wouldn't void the warranty.
if you root you should always consider your warranty voided
Click to expand...
Click to collapse
Tethered Temporary CWM / TWRP Recovery Session :
Note : This is a Temporary CWM / TWRP Recovery Session for some Intel Devices with locked bootloaders.
This recovery is not installed to the devices and has to be launched from a computer ( tethered ) each time you need to access the CWM / TWRP Recovery. . .
WARNING : This Temporary CWM / TWRP Recovery Session is for some Intel Devices with locked boot loaders.
It is not intended for installing custom roms as if the devices has a locked bootloader the device will fail to boot the unsigned images
Intel Fastboot Tethered Temporary Recovery Session Launcher download :
Current Version : IntelAndroid-FBRL-07-24-2015.7z
Generic Instructions for use better instructions coming later just wanted to get the thread up :
notes :
make sure you have downloaded and installed the adb / fastboot drivers for your device . . .
make sure you have enabled developer options / adb debugging under settings on your device . . .
make sure you have download the latest : UPDATE-SuperSU-vX.Xx.zip and place it on your internal or external_sd
1 : download and extract IntelAndroid-FBRL-07-24-2015.7z some where on your computer.
2 : double click the launcher.bat file to start , type " ACCEPT " case sensitive without quotes to continue
check that the tool is reporting as either :
DEVICE STATUS: ADB-ONLINE
DEVICE STATUS: FASTBOOT-ONLINE
If " DEVICE STATUS: UNKNOWN " please check your cable connection and driver installation under Windows Device Manager
If " DEVICE STATUS: UNAUTHORIZED " please check if your devices is displaying an authorization prompt be sure to check Always allow from this computer and then press ok
3 : select the trigger to launch the Temporary CWM Recovery Session support fastboot oem triggers are :
T1 oem startftm ( very few devices support this command , but its the original used so )
devices supported : coming soon
T2 oem backup_factory ( limited devices support this command )
devices supported : coming soon
T3 oem stop_partitioning ( should work on alot of kitkat builds )
devices supported : coming soon
T4 oem stop_partitioning ( probably works on all devices that are supported (Jellybean , KitKat , Lollipop) )
devices supported : coming soon
4 : after selecting the trigger your device should reboot in to fastboot and begin to copy files to your device
note : if your device hangs at the waiting-for-device screen and you see droidboot CMD Waiting on your devices double check that the fastboot driver installed correctly.
note : if you see unknown oem command the trigger isn't supported by your device.
5 : The temporary cwm recovery session should be started at this point select install zip from the recovery menu using vol up / vol down to navigate and power to select
6 : select install zip from sdcard / external_sd depending on where you placed the file and select the UPDATE-SuperSU-vX.Xx.zip you downloaded earlier
7 : confirm the installation
8 : after install completes reboot your device
note :
some devices have limited space under /system and the supersu app wont install
if you don't see the supersu app on your device attempt to install it from the playstore
more than likely the su binary installed correctly but there want enough room on the device for the app.
This recovery uses the CWM Recovery @vampirefo built for the Dell Venue 8 3830 NoModem original thread : Dell Venue 8, CWM, unsecure boot/recovery
You know it's annoying to find this on so many other forums. with other people taking credit for it. sad face : (
APPRECIATE MY WORK, I DON'T DRINK, SO CLICK HERE DONATE NOW AND BUY ME COFFEE
XDA:DevDB Information
Intel Android FBRL, Tool/Utility for the Android General
Contributors
social-design-concepts
Version Information
Status: Stable
Created 2015-07-28
Last Updated 2015-07-28
Supported Devices List / Trigger
Supported Devices List / Trigger
Acer :
B1-730 T2
B1-730HD T2
A1-830
A1-840FHD T3
A1-840 (HD) T3
Asus :
ME170C T2 & T3
ME176C T2 & T3
Dell :
Venue 7 3730 / Venue 8 3830 All Triggers Should Work
Venue 7 3740 / Venue 8 3840 T3
Venue 7 3741 / T3
Venue 8 7840 T3
Iview :
i700 T2 & T3
Kurio :
Xtreme 7 Only had a chance to test trigger T3
Odys :
intellitab 7
Nabi:
Dreamtab model IN08A trigger T3 reported working
Prestigio :
MultiPad Thunder 7.0i
Tesla :
L7 Tablet T3
Tesco :
Op3n Dott 8 T2 & T3
Toshibia :
Excite 7 T3
Links to devices specific threads / forums
Links to devices specific threads / forums
If you have created a devices specific thread / forum for your devices please PM the link so that i can post a link to it here to make it easier to help new users . . . . Please put Intel Device Specific Thread in the supject . Thank You .
The Concept / Source Code
The Concept / Source Code
Collected Device Dumps / Captured OTA Updates
Collected Device Dumps / Captured OTA Updates
Generic / Tips for Unbricking
Generic / Tips for Unbricking
Ahh!
Just my luck lol. Had a feeling I would end up bricked for some reason, maybe I jinxed myself.
Anyways... everything was going ok, I selected trigger 3 to try first, reboots to droidboot (with "waiting for fastboot command") then I select recovery and get android dude laying down with a red exclamation point coming out his belly and it just said "no command" now I am soft bricked, only getting the USB symbal with the white line under it. Please help!
GeeKerGurL said:
Just my luck lol. Had a feeling I wouls end up beicked for some reason, maybe I jinxed myself.
Try to manually boot to droidboot
Anyways... everything was going ok, I selected trigger 3 to try first, reboots to droidboot (with "waiting for fastboot command") then I select recovery and get android dude laying down with a red exclamation point coming out his belly and it just said "no command" now I am soft bricked, only getting the USB symbal with the white line under it. Please help!
Click to expand...
Click to collapse
We can remote around 1130pm est and I'll get you running v8 correct?
Sent from my XT907 using XDA Free mobile app
social-design-concepts said:
We can remote around 1130pm est and I'll get you running v8 correct?
Sent from my XT907 using XDA Free mobile app
Click to expand...
Click to collapse
Yeah 3830. Thanks a bunch. Now what do I have to do to remote? I am on a win7 PC with 1gig that is so slow I wanna scream. Also I am in another timezone so how long would that be from now?
GeeKerGurL said:
Yeah 3830. Thanks a bunch. Now what do I have to do to remote? I am on a win7 PC with 1gig that is so slow I wanna scream. Also I am in another timezone so how long would that be from now?
Click to expand...
Click to collapse
1 hour 30 minutes
Sent from my XT907 using XDA Free mobile app
social-design-concepts said:
1 hour 30 minutes
Sent from my XT907 using XDA Free mobile app
Click to expand...
Click to collapse
Okie dokie. Ill be here.
social-design-concepts said:
We can remote around 1130pm est and I'll get you running v8 correct?
Sent from my XT907 using XDA Free mobile app
Click to expand...
Click to collapse
Woot!!!YA! no need, I got it back all by myself just had to boot with vol down and go back through the process and everything copied fine and worked this time! :good: thanks a ton for offering to help me though buddy!
BTW trigger 3 works for the 3830 V8 no modem
WOOOHOOOOHOOOOWOOOO! root check cleared, I am SOO happy to finally have root on this thing. Besides my minor hiccup for whatever reason this method was pie too! YAHOO. I went from about to cry to jumping around happy like a crazy person haha.
recovery fstab
What needs to be change for jb 4.2.2?
I am able to open and edit the file.
b.g.
whgarner said:
What needs to be change for jb 4.2.2?
I am able to open and edit the file.
b.g.
Click to expand...
Click to collapse
recovery.fstab may or may not need to be edited for some devices especially if the device doesn't use by label partitioning. What device do you have?
Sent from my XT907 using XDA Free mobile app
asus aa3-600
I have an asus aa3-600-ur10
android 4.2.2
Intel Celeron J1850 Quad-core 2 GHz
21.5" Full HD (1920 x 1080) 16:9
Intel HD Graphics with Shared Memory
2 GB, DDR3 SDRAM
500 GB HDD
The problem I'm having is no usb debugging, only debugging via lan. I can get adb to work but not working with fastboot in the bootloader(droidboot). I have a post about it in this section, search for "aa3-600"
b.g.
Hi, SDC
I know this has been ask before, I searched and couldn't find the answer though, I would like to get the source code for the launchers , I use the Linux version of this method, cause I don't have windows, and would like to convert the recovery.launcher triggers and so forth into a shell script rather that use binary file.
If you have a shell script already can you post it if not, can you post or give me a link to your binary files source code?
tomtom1265 said:
Hi, SDC
I know this has been ask before, I searched and couldn't find the answer though, I would like to get the source code for the launchers , I use the Linux version of this method, cause I don't have windows, and would like to convert the recovery.launcher triggers and so forth into a shell script rather that use binary file.
If you have a shell script already can you post it if not, can you post or give me a link to your binary files source code?
Click to expand...
Click to collapse
I'm going to post the source after I finish getting the thread put together I just wanted to get it up yesterday.
As for doing it through shell scripts the reason its binary is because if /system is mounted or any prebuilt binary has a dependency on a shared library it makes it extremely difficult some times impossible to stop services and unmount /system and such.
But I hope to have everything finish by the end of the day.
Sent from my XT907 using XDA Free mobile app
whgarner said:
I have an asus aa3-600-ur10
android 4.2.2
Intel Celeron J1850 Quad-core 2 GHz
21.5" Full HD (1920 x 1080) 16:9
Intel HD Graphics with Shared Memory
2 GB, DDR3 SDRAM
500 GB HDD
The problem I'm having is no usb debugging, only debugging via lan. I can get adb to work but not working with fastboot in the bootloader(droidboot). I have a post about it in this section, search for "aa3-600"
b.g.
Click to expand...
Click to collapse
You use Linux or windows? If Linux, you may need to use my fastboot binary, anyway if using Linux while in fastboot mode use terminal type lsusb.
Do you see your device listed?
Sent from my T1 using XDA Free mobile app
Root!
Thank you for this!
I successfully rooted my V8 3830 KK4.4 V1.33 no modem with T3 - in about 4 mins. tops.
FYI:
I connected and launched the launcher from the IntellAndroid-FBRL folder. Typed ACCEPT and got the green screen. Chose T3. The tablet rebooted into fastboot and files where loaded, But then fastboot turned red and said "device unauthorized" when CWM popped onto my tablet. (maybe it's suppose to do that, DK) and yes, US debugging was on, I flashed the SU zip, rebooted, all is well. SU updated and working fine. I was able to remove all the crapwear. :laugh:
thank you SDC!
Quick question - Do any of the intel devices have unlocked bootloader?? Thought I read somewhere somebody was able to install a factory 4.3 or 4.2 on a Dell venue and the bootloader unlocked?

Linux ISO - Unbrick the Fire HD6/HD7 [Video] [Testers Wanted]

Testers wanted: Anyone who uses this method, let me know if you can access stock recovery after this method.
Summery
Thanks to the amazing work by our active member @bibikalka, a method was found to unbrick these devices Thread link here. The method he found was slightly tedious for some people, so I've decided to put together a Linux iso that you can boot into on your computer with everything you need to get your device running again. It uses the same methods proposed but makes things easier. This comes with all the necessary drivers, scripts to do everything you need, all the img files needed to flash, a hex editor for advanced users, and more. Before the scripts included in this OS, determining the option (A, B, or C) to take in order to unbrick the device required .part files to be evaluated manually. Now with the custom script, it can quickly evaluate what option to take.
Video Instructions
Brief Instructions
1. Download the Linux iso:
Linux ISO
2. Burn the iso to a USB drive or cd
3. Boot into the operating system
4. Type "root" at the login prompt
5. Right click on the desktop and choose file manager. Go to "aftv2-tools" folder
6. Right click on file manager and press "open in terminal"
7. From device turned off, enter command "./handshake.py", then plug in device. You may need to do this a couple times to get a connection. Try pressing volume keys & power etc to get it connected. See video if you have problems
8. After handshake is complete, run "./reader.sh"
9. After all addresses are read in, run "./determineOption.sh". You should get back a result of A, B, or C
10. Depending on the option returned (A,B,or C), run "./readerSpecialOptionA.sh", "./readerSpecialOptionB.sh", or "./readerSpecialOptionC.sh". This is an optional step but may be useful if you want to back up part files or their were no options available. Back up part files to a usb drive if you want to be safe.
11. Now the actual unbricking. Run "./unbrickOptionA.sh", "./unbrickOptionB.sh", or "./unbrickOptionA.sh" depending on your option. This can take about 40 minutes
12. hold volume up and run "./complete.sh" at the same time to get into TWRP
13. boot into your default operating system on your computer
BE VERY CAREFUL FROM NOW ON
13. We will be installing Fire OS 5.3.1. If you are not installing this ROM, make sure you know what you are doing. Download the ROM:
update-kindle-20.5.5.2_user_552153420.bin
14. Download 5.4.1_1133_stock_recovery_uboot.zip: 5.4.1_1133_stock_recovery_uboot.zip. Without this you could turn your device into a paperweight. This installs stock recovery and a uboot version that MUST be installed. This file was taken from the thread here: how-to-upgrade-to-lollipop-root-gapps
15. Rename the ROM extension from .bin to .zip
16. Transfer the two files to the Fire
17. Do a factory reset. Flash the ROM and uboot&recovery file
18. Reboot! Your device should now be working. It will take about 15 mins to boot up.
Big thanks to @bibikalka for helping work everything out and for the initial unbrick method.
Edit 10/13/21: Fixed Google Drive Link
Linux ISO Changelog
Updated 10/5/16:
*Optomized scripts
*Added "complete.sh" This reboots the device
Updated 9/27/16:
*Added script to auto-detect which unbrick option to use (determineOption.sh)
*Added scripts to write img files to correct addresses ( unbrickOptionA.sh, unbrickOptionB.sh, and unbrickOptionC.sh)
*Added scripts to read in and label part files (readerSpecialOptionA.sh, readerSpecialOptionB.sh, and readerSpecialOptionC.sh)
*Nemo open in terminal fixed
*.part files set to open with ghex by default
Updated 9/24/16:
*Nemo as default file manager
*Updated html page with instructions from forum
well, after seriously struggling with the parent thread mentioned in the OP I've managed to get to TWRP & am just waiting for my win10 machine to install it's updates before attempting to adb push the uboot & zip files for installation back to fireOS.
feels great to see the screen displaying something other than the looping amazon logo after months of frustration. I do not have the words to express my gratitude for @powerpoint45 for an excellent & well thought through tool and walkthrough. special mention also goes out to @bibikalka
gascomm said:
well, after seriously struggling with the parent thread mentioned in the OP I've managed to get to TWRP & am just waiting for my win10 machine to install it's updates before attempting to adb push the uboot & zip files for installation back to fireOS.
feels great to see the screen displaying something other than the looping amazon logo after months of frustration. I do not have the words to express my gratitude for @powerpoint45 for an excellent & well thought through tool and walkthrough. special mention also goes out to @bibikalka
Click to expand...
Click to collapse
great to hear! I hope everything works for you! After you get everything done, can you check if you can get into recovery.
after flashing both zips & rebooting I've now got my working fire (OS 5.3.1.0) back. thank you Mr PowerPoint!
i tried rebooting to recovery & it now takes me to the stock amazon recovery not TWRP..... which is unfortunate.
I did get asked if I wanted to install SuperUser which was a no-brainer YES. although I'm staying offline until I identify a functional (fast) flavour of android to flash. suggestions welcome.
gascomm said:
after flashing both zips & rebooting I've now got my working fire (OS 5.3.1.0) back. thank you Mr PowerPoint!
i be tried rebooting to recovery & it now takes me to the stock amazon recovery not TWRP..... which is unfortunate.
I did get asked if I wanted to install SuperUser which was a no-brainer YES. although I'm staying offline until I identify a functional (fast) flavour of android to flash. suggestions welcome.
Click to expand...
Click to collapse
Good to hear everything is working. Ya TWRP does not work with 5.x bootloader. Good to hear you can get into stock recovery because I had some incidents where I could not get into it. Thanks for responding. The only custom ROM ATM is CM13.
powerpoint45 said:
The only custom ROM ATM is CM13.
Click to expand...
Click to collapse
sorry to trouble you again but do you know where I can find a guide/walkthrough of how to root via adb & install twrp or cwm to allow flashing of a rom & gapps..
I can only find the kingroot method & the CM11 rom discussion. where might I find the CM13 you mentioned?
I have searched fruitlessly. I guess I just need a little guidance to avoid running straight into another brick.
cheers.
gascomm said:
sorry to trouble you again but do you know where I can find a guide/walkthrough of how to root via adb & install twrp or cwm to allow flashing of a rom & gapps..
I can only find the kingroot method & the CM11 rom discussion. where might I find the CM13 you mentioned?
I have searched fruitlessly. I guess I just need a little guidance to avoid running straight into another brick.
cheers.
Click to expand...
Click to collapse
I meant to say CM11. This guide is probably one of the best http://forum.xda-developers.com/fire-hd/general/how-to-upgrade-to-lollipop-root-gapps-t3163950/page1
This is a bit older one: http://forum.xda-developers.com/fire-hd/general/how-to-downgrade-to-4-5-3-root-device-t3139351/page1
In order to have TWRP, you must have a 4.x bootloader so CM11 would work with it.
Thank you
I have a question I can work downgrade from 5.3.1 to 4.5.3
I'm currently on version 5.3.1
PRInCEI7 said:
Thank you
I have a question I can work downgrade from 5.3.1 to 4.5.3
I'm currently on version 5.3.1
Click to expand...
Click to collapse
yes you should be fine doing that
Unfortunately, did not respond
I worked
MacBook-Air-2:ROOT IP$ ./handshake.py
Waiting for preloader...
Found port = /dev/cu.usbmodem1420
Handshake complete!
In the second step does not respond to the order ./reader.sh
Also tried
/.read_mmc.py 0x0000000 0x1000 0x0000000.part
Does not respond
By the way tried way on more than one device
And tried through the system Max os x and the system arch-custom-firehd67-unbrick100516.iso did not work and also the same result
MY device Amazon Fire HD 6 version 5.3.1 All functions work, but I need to work downgrade to 4.5.3
Is there a solution to my problem
[/SIZE]
@powerpoint45 thanks for the pointers. I am now the proud owned of an hd6 booting straight into cm11 & it's been well worth the wait. I am forever in your digital debt.
gascomm said:
@powerpoint45 thanks for the pointers. I am now the proud owned of an hd6 booting straight into cm11 & it's been well worth the wait. I am forever in your digital debt.
Click to expand...
Click to collapse
sweet!!!
PRInCEI7 said:
Unfortunately, did not respond
I worked
MacBook-Air-2:ROOT IP$ ./handshake.py
Waiting for preloader...
Found port = /dev/cu.usbmodem1420
Handshake complete!
In the second step does not respond to the order ./reader.sh
Also tried
/.read_mmc.py 0x0000000 0x1000 0x0000000.part
Does not respond
By the way tried way on more than one device
And tried through the system Max os x and the system arch-custom-firehd67-unbrick100516.iso did not work and also the same result
MY device Amazon Fire HD 6 version 5.3.1 All functions work, but I need to work downgrade to 4.5.3
Is there a solution to my problem
[/SIZE]
Click to expand...
Click to collapse
I am also getting the same results with my HD 7 4th gen. The handshake completes just fine, but the reader just hangs. When I'm in recovery, I get errors saying the /cache folder failed to mount. I'm thinking the memory is corrupt and there is no way to fix this.
nai1ed said:
I am also getting the same results with my HD 7 4th gen. The handshake completes just fine, but the reader just hangs. When I'm in recovery, I get errors saying the /cache folder failed to mount. I'm thinking the memory is corrupt and there is no way to fix this.
Click to expand...
Click to collapse
Unfortunately it appears that with the latest bootloader on the latest Amazon update that they have disabled these commands (such as reading and writing). Unfortunately if you can't get into recovery with (vol+ & power) then it is currently unrecoverable. Best option for an unrecoverable device would be to buy another motherboard from eBay or some place. They are pretty cheap and easy to replace. I've had to do it a couple times now.
Confused
First you say it should be OK to downgrade:
powerpoint45 said:
PRInCEI7 said:
Thank you
I have a question I can work downgrade from 5.3.1 to 4.5.3
I'm currently on version 5.3.1
Click to expand...
Click to collapse
yes you should be fine doing that
Click to expand...
Click to collapse
Although, it's unclear how, since reports indicate that sideloading older
firmware bricks the device (or, does that only apply to 5.x?).
Then, we learn that the preloader trick (from aftv2-tools) doesn't work anymore:
Code:
[[email protected] aftv2-tools]# ./handshake.py
Waiting for preloader...
Found port = /dev/ttyACM0
Handshake complete!
[[email protected] aftv2-tools]# ./reader.sh
^CTraceback (most recent call last):
File "./read_mmc.py", line 355, in <module>
if msdc_dma_status():
File "./read_mmc.py", line 146, in msdc_dma_status
return False if sdr_read32(MSDC_CFG) & MSDC_CFG_PIO else True
File "./read_mmc.py", line 82, in sdr_read32
check(dev.read(2), b'\x00\x00') # arg check
File "/usr/lib/python3.5/site-packages/serial/serialposix.py", line 450, in read
ready, _, _ = select.select([self.fd, self.pipe_abort_read_r], [], [], timeout)
KeyboardInterrupt
^CTraceback (most recent call last):
File "./read_mmc.py", line 355, in <module>
if msdc_dma_status():
File "./read_mmc.py", line 146, in msdc_dma_status
return False if sdr_read32(MSDC_CFG) & MSDC_CFG_PIO else True
File "./read_mmc.py", line 82, in sdr_read32
check(dev.read(2), b'\x00\x00') # arg check
File "/usr/lib/python3.5/site-packages/serial/serialposix.py", line 450, in read
ready, _, _ = select.select([self.fd, self.pipe_abort_read_r], [], [], timeout)
KeyboardInterrupt
^Z
[1]+ Stopped ./reader.sh
[[email protected] aftv2-tools]# kill %1
[[email protected] aftv2-tools]#
[1]+ Terminated ./reader.sh
[[email protected] aftv2-tools]#
The above is for a 4th gen HD7 with this device showing in 'lsusb':
Code:
Bus 001 Device 006: ID 0e8d:3000 MediaTek Inc.
powerpoint45 said:
Unfortunately it appears that with the latest bootloader on the latest Amazon update that they have disabled these commands (such as reading and writing). Unfortunately if you can't get into recovery with (vol+ & power) then it is currently unrecoverable. Best option for an unrecoverable device would be to buy another motherboard from eBay or some place. They are pretty cheap and easy to replace. I've had to do it a couple times now.
Click to expand...
Click to collapse
BTW, are we sure that this is *disabled* as opposed to _tweaked_?
(e.g. by changing the protocol slightly by, say, requiring an extra byte
or two "confirmation" before execution? has anyone bothered reversing
the bootloader? [Please excuse my ignorance, but would this be handled
by UBOOT, TEE1, or some other component?])
So, what's the current best option for 5.3.1?
---------- Post added at 11:23 ---------- Previous post was at 10:58 ----------
draxie said:
BTW, are we sure that this is *disabled* as opposed to _tweaked_?
(e.g. by changing the protocol slightly by, say, requiring an extra byte
or two "confirmation" before execution? has anyone bothered reversing
the bootloader?
Click to expand...
Click to collapse
OK. So, I found this post by @zeroepoch,
which makes it very clear that said exercise has been performed for the AFTV2...
No reason to believe that this would be different for the Fire HD7...
draxie said:
First you say it should be OK to downgrade:
Although, it's unclear how, since reports indicate that sideloading older
firmware bricks the device (or, does that only apply to 5.x?).
Then, we learn that the preloader trick (from aftv2-tools) doesn't work anymore:
The above is for a 4th gen HD7 with this device showing in 'lsusb':
BTW, are we sure that this is *disabled* as opposed to _tweaked_?
(e.g. by changing the protocol slightly by, say, requiring an extra byte
or two "confirmation" before execution? has anyone bothered reversing
the bootloader? [Please excuse my ignorance, but would this be handled
by UBOOT, TEE1, or some other component?])
So, what's the current best option for 5.3.1?
---------- Post added at 11:23 ---------- Previous post was at 10:58 ----------
OK. So, I found this post by @zeroepoch,
which makes it very clear that said exercise has been performed for the AFTV2...
No reason to believe that this would be different for the Fire HD7...
Click to expand...
Click to collapse
My understanding is that you only need to worry about bricking if You are downgrading to another lollypop ROM. We found out that the device has a fuse that is set in later lollypop ROMs where it will check against the current version. But this check only seems to be on lollipop ROM's. As for the aftv2 protocol, you might be right but I don't know enough about that yet to know. Currently we have no unbrick method for latest bootloader. If you can get into recovery then you could sideload but most can't get into recovery during brick.
I've followed the steps but not into twrp, only screen amazon and reset. I'm not good at English
error trying to unbrick hd6
[[email protected] aftv2-tools]# ./complete.sh
1: 0xd1
4: 0x00 0x00 0x00 0x00
4: 0x00 0x00 0x00 0x01
Traceback (most recent call last):
File "/usr/lib/python3.5/site-packages/serial/serialposix.py", line 468, in read
'device reports readiness to read but returned no data '
serial.serialutil.SerialException: device reports readiness to read but returned no data (device disconnected or multiple access on port?)
During handling of the above exception, another exception occurred:
Traceback (most recent call last):
File "./read32.py", line 69, in <module>
ret = read32(addr, size)
File "./read32.py", line 45, in read32
print_hex_byte(dev.read(2)) # status
File "/usr/lib/python3.5/site-packages/serial/serialposix.py", line 475, in read
raise SerialException('read failed: {}'.format(e))
serial.serialutil.SerialException: read failed: device reports readiness to read but returned no data (device disconnected or multiple access on port?)
[[email protected] aftv2-tools]#
kingwill101 said:
[[email protected] aftv2-tools]# ./complete.sh
1: 0xd1
4: 0x00 0x00 0x00 0x00
4: 0x00 0x00 0x00 0x01
Traceback (most recent call last):
File "/usr/lib/python3.5/site-packages/serial/serialposix.py", line 468, in read
'device reports readiness to read but returned no data '
serial.serialutil.SerialException: device reports readiness to read but returned no data (device disconnected or multiple access on port?)
During handling of the above exception, another exception occurred:
Traceback (most recent call last):
File "./read32.py", line 69, in <module>
ret = read32(addr, size)
File "./read32.py", line 45, in read32
print_hex_byte(dev.read(2)) # status
File "/usr/lib/python3.5/site-packages/serial/serialposix.py", line 475, in read
raise SerialException('read failed: {}'.format(e))
serial.serialutil.SerialException: read failed: device reports readiness to read but returned no data (device disconnected or multiple access on port?)
[[email protected] aftv2-tools]#
Click to expand...
Click to collapse
You are on any version.
You can access to recovery now

Newbie - No Chroot on Nexus 5 Installation

New User, so apologies if this post is in the incorrect format :fingers-crossed:
Sorry if TL,DR: but the more information on my issue I give you the less chance your advice encounters any variables.
Recently got into ethical Hacking / pentesting.
Wanting to use a nethunter ROM on my Nexus 5 so when I inevitably break something its replaceable and not my gaming rig.
I did the following:
- Installed Nexus Root Toolkit on my laptop.
-Unlocked the boot loader from this first.
-Then installed Root Permissions and TWRP
These initial steps seemed to have worked.
Boot loader marked as unlocked, SU app installed upon booting new ROM, checks as rooted, and TWRP was being interacted with on the next step.
I then selected the 'advanced' menu in the Nexus Root Toolkit.
And flashed the .zip file for the hammerhead nethunter build version 3.0
There was advice to do several things during this step which I have ignored due to not understanding the process.
- installing gapps. I believe the gapps version for hammerhead is 6.0 however it's listed purpose was to allow access to Google play apps which I have so I discarded this step.
- installing over cryogenmod 14.1 as my Android build is marshmallow 6.0.1. This is the advice I received on the official Kali site, that Nethunter was designed to be used over CM, and perhaps my issue as I flashed it over the stock OS for the phone.
Once the nethunter zip file was flashed through the root Toolkit, I rebooted my phone and logged on. After the initial setup I had all of the applications and the background for the KL Nethunter build, however I encounter a major issue trying to set them up.
When I go to set up the Chroot. I select download option, and then "full Chroot install".
I am then prompted with a message saying bad handshake / server error and I am unable to get past this stage.
The error message is " javax.net.sslSSL handshake exception" no valid pins found in chain.
I am not using a mobile carrier only Wi-Fi.
This is killing me because obviously it means I basically don't have nethunter lmao :laugh: really not funny but any human input you guys can offer with this challenge would be immensely appreciated. I want to begin hooking this up to a TP Link Wi-Fi receiver and I'm extremely demoralised by the fact I can't complete what is essentially " the easy bit ".
Disclaimer - I will follow any suggested links to the letter but for the record. I have combed YouTube. Google. XDA and several other sources for a fix to this. I am aware I need a Kali " arm-hf" file however can't find a repository for such a download or I would download it to the Sd and try to mount it manually!
I just pretty much completed the same process on my nexus 7 (2012) which resulted in me being stuck at the same point. Doing a search has lead me here for possible resolution to our issues.
"The error message is " javax.net.sslSSL handshake exception" no valid pins found in chain."
UPDATE:
I was able to locate the file within the zip file we had flashed to install kali.
Full path was /data/local/kalifs-full.tar.xz
I manually extracted and copied to /emulated/sdcard and ran the chroot wizard and chose to install from sd, it's extracting now.
I'll update once extraction has completed (this tablet has the slowest writes, ever..)
Here is the link to kali chroot.
8point6 said:
I just pretty much completed the same process on my nexus 7 (2012) which resulted in me being stuck at the same point. Doing a search has lead me here for possible resolution to our issues.
"The error message is " javax.net.sslSSL handshake exception" no valid pins found in chain."
UPDATE:
I was able to locate the file within the zip file we had flashed to install kali.
Full path was /data/local/kalifs-full.tar.xz
I manually extracted and copied to /emulated/sdcard and ran the chroot wizard and chose to install from sd, it's extracting now.
I'll update once extraction has completed (this tablet has the slowest writes, ever..)
Click to expand...
Click to collapse
build.nethunter.com/kalifs/kalifs-latest/kalifs-i386-full.tar.xz
I see they dropped support for the nexus 7 2012, likely due to lack of space. I was able to get a full extract done, but hope enough info has been relayed to get you and anyone else past the error we had received. If I pick up where I left off, I'll try to provide an update on this, tabled for now.

Categories

Resources