HOW TO BYPASS FRP on GALAXY S7 and possibly more 6.0.1 and 7.0 - Samsung Galaxy S7 Questions and Answers

Complettly Remove FRP , ie return YOUR fone to original state ie as if just bought and unregistered, without triping KNOX or any other signs Tamper switches etc being Shown!! , Current binary, official, system status = official, Secure download = enabled, Warranty Void = 0 (0x0000), AP SWREV b:1 k:0 s:0, this last bit i don't know what it is but this is the same numbers it outputted to my download screen when I first Factory Reset the fone after setting up google , making sure adb was off as OEM etc in settings, setting up a fingerprint and a 4 digit pin, and set it to activate before the fone boots.. I tried to make it as hard as i could to break, but ends up it doesnt matter anyway as all the info is in the PERSISTENCE partition, and if wiped, it thinks its never been registered, Again this comes down to security by obscurity hiding a txt file with your google details on it on a partition or anywhere just hoping no one will look there as its buried quite, well kinda deepish, is not security it laziness i forgot to dd the partition to my pc and looked to see if the info was even encrypted and what else was there in that partition as google thought it was impenetrable, just like apple does with "find my iphone" & icloud, but they are getting better am struggling with there new version, but anyway this is android here and
THIS IS HOW I DONE IT!
First Hold [Power} [HOME] and [VOLUME DOWN] all at once until a blue screen appears with stuff about non stock images et, then press [volume up], next Use ODIN.exe, which ive provided as well as every thing else needed, and flash your model version of the .tar file (included) by clicking the [BL} button on ODIN then make sure its has a tick next to it, if not click the box to tick it, then run the RUN_ME.bat file and that's that. Next just flash the STOCK version of your boot file in the way as before in the [BL] tab, sometimes a full new flash is needed via odin, but only rarely, then thats it phones like new, As in never owned before, as the script wipes the partition (PERSISTENT) that holds the username lock files.
this can be done manually as i found the files that lock the fone to the google account are in the PERSISTENCE Partition, it can be in different places per fone or model but usually in /dev/block/PERSISTENCE, or /dev/sda11 or somewhere in the /by-name/PERSISTENCE, just ls /dev/ and worm your way down till you see a PERSISTENCE then dd it by dd if=/dev/zero of=/dev/block/PERSISTENCE or wherever the partition is, simple,
if this works for youn hit hit thanks, or buy me a beer via paypal, cheers, sonnettie
Any Questions Ill answer you, Im very busy with a lot of projects just now and i just had brain surgery after been hit by a bus on a dual carriageway last year, and was in 3 hospitals in surgery for 70 hours, then a comma for six weeks,
PS, This will NOT trigger KNOX as its done at the lowest level below KNOX and before any services or apps start om the phone,
The BOOT loader you flash, all that does is start the system at its lowest level so we can run basic commands from the LINUX base of the fone, like ls, dd, df, mount, , basically like busybox when linux fails to load correctly, This is what the boot file does, first it start adb from its end then it loads only so far, not even to the point where the android flashes, it halts at the Galaxy S7, logo before the loading screen, so nothing loads at all.
The files can be downloaded from here... Files For Removing FRP, Knox Trip=NO, FRP=OFF, ALL Official!!
THIS IS PoC and some files and info to proof it, this was just to show how i was the first person do do this and not charge you for it, yes it need alterations for alternative fones if you cant figure how to do that dont just plug your fone into your pc and start pressing random buttons switches command etc again its PoC for this fone with info on "How to" with other android 6/7 fones thats all if you need a push one button flashy tool im not here for that only to help some one else do that ive done the technical part a app coder can make you a a plug and unlock tool, that was not my intention just to help and stop someone else finding this first and charging every one for it as this can be done remotely if you understand how it works using an apk but whatever........

sonnettie said:
Use ODIN.exe which ive provided as well as every thing else needed to flash your model version of the .tar file (included) the run the RUN_ME.bat file , that's it FRP=OFF , Then just flash the STOCK version of your boot file in the [BL] tab, sometimes a full new flash is needed via odin, but only rarely, then thats it phones like new, As in never owned before, as the script wipes the partition (PERSISTENT) that holds the username lock files.
this can be done manually as i found the files that lock the fone to the google account are in the PERSISTENCE Partition, it can be in different places per fone or model but usually in /dev/block/PERSISTENCE, or /dev/sda11 or somewhere in the /by-name/ folder just ls /dev/ and worm your way in till you see a PERSISTENCE and dd it by dd if=/dev/zero of=/dev/block/PERSISTENCE or wherever the files are, simple,
if this work hit thanks, cheers, sonnettie
PS this is for people that bought a fone and reset it and cant contact the owner or setup a google account on the spot and cant remember any of it, IT IS NOT to be used for STOLEN fones or ILLEGAL USES, and you should never have had to pay for this!!!!
The files can be downloaded from here... https://drive.google.com/open?id=0ByZUWMZ-VMvtMVJ1TE5memt5c0U
Click to expand...
Click to collapse
Hi
Unfortunately this will be use for illegal purposes........
You say to flash the boot file of the phone before running the bat file , why ? what boot file is that?
Do i need to be root?
If not root , will this trigger knox 0x 1 ?

mistake sorry.....

MAX 404 said:
Hi
Unfortunately this will be use for illegal purposes........
You say to flash the boot file of the phone before running the bat file , why ? what boot file is that?
Do i need to be root?
If not root , will this trigger knox 0x 1 ?
Click to expand...
Click to collapse
No no need for root to do this, and no it triggers nothing as the fone doesn't get a chance to boot while its done, hope this helps
and yes, just as the factory reset salute before FRP was, and the screwdriver, knife, car, printer, computer, even fones can be used for illegal purposes, but that NOT US, and we discourage that were helping people that as i see happening a very lot people buy a new fone set up google with anything that comes to mind cos the got a yahoo, or hotmail email, or maybe don't even use them so the just type any random sh!t into the fone thinking they will never use it, then some thing like this happens, before all you had to do was the three finger salute (factory reset) for them and try to warn them use memorable email passwords etc or even write them down in a book somewher, bad sec, but if it a 75 yr old woman coming to you every day coz she cant access here play store to get facebook, or whatever, then its better this way don't you think, with the obvious exception tell them not to use internet banking or there credit card online.

sonnettie said:
No no need for root to do this, and no it triggers nothing as the fone doesn't get a chance to boot while its done, hope this helps
and yes, just as the factory reset salute before FRP was, and the screwdriver, knife, car, printer, computer, even fones can be used for illegal purposes, but that NOT US, and we discourage that were helping people that as i see happening a very lot people buy a new fone set up google with anything that comes to mind cos the got a yahoo, or hotmail email, or maybe don't even use them so the just type any random sh!t into the fone thinking they will never use it, then some thing like this happens, before all you had to do was the three finger salute (factory reset) for them and try to warn them use memorable email passwords etc or even write them down in a book somewher, bad sec, but if it a 75 yr old woman coming to you every day coz she cant access here play store to get facebook, or whatever, then its better this way don't you think, with the obvious exception tell them not to use internet banking or there credit card online.
Click to expand...
Click to collapse
Hi Mate
why we need to flash another boot loader?

the bootloader activates ADB and only boot so far into the system before the Android Virtual Machine starts so we are running on pure linux so no KNOX or any other checkers are running and never know whats going on or happened as its as if they where in a comma at the time lol,
any other questions please ask, sonnettie

Does the latest security patch fix this flaw?

Nope still works

From what i read and what i understood, with this can you restore Knox to 0x0 from 0x1?

Thanks for posting this fix- i literally spent the last day trying to remove the frp lock off a legitimate purchase from ebay. Google has managed to close all the exploits out there on ****-tube and nothing other than paying some other programmer to do this (probably exact thing for a profit) This is why I keep coming back to xda developers. I'm not here for profit or nefarious reasons. I want my phone to work the way it's supposed to without all the bloatware and bull****. You rock and I appreciate it!

Hello,
I think no one has try this unlock method.
Because i think it cant work.
I have seen in the runme.bat there is script error at the end,
where it should be
dd if=/dev/zero of=/dev/block/...
Anyways, it is maybe just a fake when frp unlock methods was fixed?

FLash the boot file then run bat, then while running bat flash the recovery file?
First flash the recovery or the boot? Then run the bat, while running the bat flash the recovery? Please explaina little as I am having trouble with g935usa.

the boot file included in the file i left here

andrei1412 said:
From what i read and what i understood, with this can you restore Knox to 0x0 from 0x1?
Click to expand...
Click to collapse
yes u can, makes it a new fone electronically

XDALies said:
This is a complete load of bull****! The OP claims to have given all the files needed to get around the FRP, but ironically there are no files for the AT&T S7 or the SM-G930A ! If you're too stupid to bypass FRP on the AT&T Variant, just admit it!
Click to expand...
Click to collapse
look at the amount of people how have followed my instructions including ME! and it works on any android frp locked or ox1 fone , Muppet

AMAZING!!!
Finally a slution!! Thanks a lot mate! Feel better!

sonnettie said:
t FRP=OFF ,
First Hold [Power} [HOME] and [VOLUME DOWN] all at once until a blue screen appears with stuff about non stock images et, then press [volume up], next Use ODIN.exe, which ive provided as well as every thing else needed, and flash your model version of the .tar file (included) by clicking the [BL} button on ODIN then make sure its has a tick next to it, if not click the box to tick it, then run the RUN_ME.bat file and that's that. Next just flash the STOCK version of your boot file in the way as before in the [BL] tab, sometimes a full new flash is needed via odin, but only rarely, then thats it phones like new, As in never owned before, as the script wipes the partition (PERSISTENT) that holds the username lock files.
Click to expand...
Click to collapse
I just used Odin with the 930 Boot.tar file. And my phone is now in a permanent restart loop. What did I do wrong? And what do I do now to get it out of loop?
~~Fixed that problem. Still don't know what happened, but I didn't bypass FRP. My phone is sm-g930p. And I used the "G930_USA_(QUALCOMM)_BOOT" file first. Instructions were very unclear.

how to I do this to a SM-G930W8 model as i cannot get them files to work with it.

Since i am a newbie in flashing phones ...
What Zip do i need to select in Odin for the SM-930F (there are two versions of it in there both marked with "stock")

Does this work on the G930A? I assume latest update (7.1 possibly?).

Related

Need help with screen lock or removing data from screen locked i535

I'm sure it's been beaten like a dead horse... Yes I have searched all over XDA and other resources. It seems every time I think I find something... I'm one setting short or one model away from what would work.
Been working on this way too long and now I ask for your help.
I have a client who lost her daughter. (She drown). She has her phone (S3 I535 verizon) but no idea what the lock pin would be and has tried a couple but none work. Unfortunately she's on attempt 8/10 so two more tries and the phone factory resets and all is lost.
She really wants to recover her daughter's pictures and if possible remove the screen lock without losing data (either works for her if it can be done).
I've tried everything I can find.
While she has her gmail and password, when we logged in device manager listed no active devices. (was able to recover some pictures from a backup, but it appears gmail didn't back up more than a couple from a couple years ago.)
Logged into samsung to remote unlock it, but again, no devices on account.
ADB is a no-go because USB debugging is OFF
Tried to put TWRP on it but odin failed
(Found a thread here that seems to be quality but can't load the program in stock recovery and cant get CWM or TWRP on it without debugging.)
Any ideas?
I do not know the android version, but I suspect it is the newest. I used my old S3 to replicate it so I could try these things without damaging her phone and losing the data, and it's running 4.4.2
If you couldn't flash a recovery using Odin then you're probably right about it being on one of the newer versions(your phone), the boot loader got locked up tight and the only recovery we have available is Safestrap. This is a tough one. I'm no expert by far, take what I'm saying with a grain of salt and do your own researching before taking any action after reading this! I see two ways of recovering some or all data if the bootloader is locked(and the device storage isn't encrypted)
1. If you don't have equipment to directly read/write to the internal storage then point her somewhere that specializes in data recovery on smart phones.
2. Factory reset the device, try to recover "deleted" data.
If the bootloader wasn't/isn't locked down then you could probably flash a rom that didn't have the lock screen pin/pattern ect implemented. I don't have the i535 but I know that the prepaid version checks the system partition when flashing via Odin so this probably wouldn't work if it's locked but I can't confirm wether or not this is checked on the i535
Can you enter the stock recovery on the daughters phone just to verify if its updated or not. Should be a string near the top. If it ends with ne1 its on 4.4.2 and I don't recall the one for 4.3. If you're unable to enter the recovery because you have to enter the pin before there's an actual lock screen(with the clock, status bar, wallpaper ect) then it's likely encrypted and there's nothing that you can do about that.
OpenSourcererSweg said:
If you couldn't flash a recovery using Odin then you're probably right about it being on one of the newer versions(your phone), the boot loader got locked up tight and the only recovery we have available is Safestrap. This is a tough one. I'm no expert by far, take what I'm saying with a grain of salt and do your own researching before taking any action after reading this! I see two ways of recovering some or all data if the bootloader is locked(and the device storage isn't encrypted)
1. If you don't have equipment to directly read/write to the internal storage then point her somewhere that specializes in data recovery on smart phones.
2. Factory reset the device, try to recover "deleted" data.
If the bootloader wasn't/isn't locked down then you could probably flash a rom that didn't have the lock screen pin/pattern ect implemented. I don't have the i535 but I know that the prepaid version checks the system partition when flashing via Odin so this probably wouldn't work if it's locked but I can't confirm wether or not this is checked on the i535
Can you enter the stock recovery on the daughters phone just to verify if its updated or not. Should be a string near the top. If it ends with ne1 its on 4.4.2 and I don't recall the one for 4.3. If you're unable to enter the recovery because you have to enter the pin before there's an actual lock screen(with the clock, status bar, wallpaper ect) then it's likely encrypted and there's nothing that you can do about that.
Click to expand...
Click to collapse
I can enter recovery mode and I do believe it is 4.4.2.
because of the delicate nature of her phone (being her passed on daughter's and she used 9 of 10 attempts to guess her pin) I pulled my S3 out of the drawer (coincidentally I stopped using it about 2 weeks after she passed) and everything is identical down to the recovery string at the top. I know it's running the same software and I have all kinds of old pictures and texts on it like she would have and I am logged into gmail on it like she is. I locked the screen on MINE and I know the PIN on MINE. I also saved a backup of my stuff so I'm using my phone as the tester since I was able to put in in the identical situation
I have room to play because of that. Once I have success on mine, I'll try what worked on mine on hers.
So far I've tried...
play.google unlock... While I have now been able to get her device to appear on device manager on google's site, they changed it so that when I remote lock it the screen lock pin does NOT change.
I called Google, Samsung, and VERIZON. None have the ability to change or remove lock screen pin.
I tried ADB, but it doesn't detect any devices when I ADB shell or ADB device.
USB DEBUGGING IS OFF (or we wouldn't be having this convo)
It has stock recovery and not CWM or TWRP (again if I could get one of those on there, we wouldn't be having this convo) (tried ODIN flashing TWRP on, but fails)
---------------------------
Every direction I head I hit a brick wall.
I've never heard of being able to recover data from internal SDcard after reset. Didn't think that was possible.
FYI. recovery mode string is...
ANDROID system recovery <3e>
KOT49H.I535VRUDNE1
Wking46 said:
I can enter recovery mode and I do believe it is 4.4.2.
because of the delicate nature of her phone (being her passed on daughter's and she used 9 of 10 attempts to guess her pin) I pulled my S3 out of the drawer (coincidentally I stopped using it about 2 weeks after she passed) and everything is identical down to the recovery string at the top. I know it's running the same software and I have all kinds of old pictures and texts on it like she would have and I am logged into gmail on it like she is. I locked the screen on MINE and I know the PIN on MINE. I also saved a backup of my stuff so I'm using my phone as the tester since I was able to put in in the identical situation
I have room to play because of that. Once I have success on mine, I'll try what worked on mine on hers.
So far I've tried...
play.google unlock... While I have now been able to get her device to appear on device manager on google's site, they changed it so that when I remote lock it the screen lock pin does NOT change.
I called Google, Samsung, and VERIZON. None have the ability to change or remove lock screen pin.
I tried ADB, but it doesn't detect any devices when I ADB shell or ADB device.
USB DEBUGGING IS OFF (or we wouldn't be having this convo)
It has stock recovery and not CWM or TWRP (again if I could get one of those on there, we wouldn't be having this convo) (tried ODIN flashing TWRP on, but fails)
---------------------------
Every direction I head I hit a brick wall.
I've never heard of being able to recover data from internal SDcard after reset. Didn't think that was possible.
Click to expand...
Click to collapse
With HDDs I know it's possible as I have done it before. The only issue is not overwriting the data when reinstalling a operating system ect. Flash is abit dififfrent but still doesnt overwrite deleted data as soon as its deleted. If you're willing to try it on your gs3 first then go for it. Since the data is very important, I would have her take it to someone who specializes in data recovery instead of trying to wipe it and get the data off it just in case.
Are you able to remotely install applications though the Google Play site or by other means? Might be able to get a shell from one of the ssh server apps if they run the server on startup. If you can get a shell you should be able to work from there.
OpenSourcererSweg said:
With HDDs I know it's possible as I have done it before. The only issue is not overwriting the data when reinstalling a operating system ect. Flash is abit dififfrent but still doesnt overwrite deleted data as soon as its deleted. If you're willing to try it on your gs3 first then go for it. Since the data is very important, I would have her take it to someone who specializes in data recovery instead of trying to wipe it and get the data off it just in case.
Are you able to remotely install applications though the Google Play site or by other means? Might be able to get a shell from one of the ssh server apps if they run the server on startup. If you can get a shell you should be able to work from there.
Click to expand...
Click to collapse
I can remotely install apps via google play site. If I could find a shell that works on startup... please let me know what that does for me?
Wking46 said:
I can remotely install apps via google play site. If I could find a shell that works on startup... please let me know what that does for me?
Click to expand...
Click to collapse
SSH access may let you transfer some files on the device to another machine. (Assuming that it will connect to known wifi networks while locked)
OpenSourcererSweg said:
SSH access may let you transfer some files on the device to another machine. (Assuming that it will connect to known wifi networks while locked)
Click to expand...
Click to collapse
No such luck. Looks like all of them would need me to log in to set them up, which defeats the purpose.
I may have to wait and see if tech changes over time and keep trying until it does.
Wking46 said:
No such luck. Looks like all of them would need me to log in to set them up, which defeats the purpose.
I may have to wait and see if tech changes over time and keep trying until it does.
Click to expand...
Click to collapse
Take a look at this, https://www.nowsecure.com/blog/2015/06/16/remote-code-execution-as-system-user-on-samsung-phones/ may be able to remove the pin. Sorry if discussion about this isn't allowed or frowned upon. Seems like a pain and it may not work for the s3
OpenSourcererSweg said:
Take a look at this, https://www.nowsecure.com/blog/2015/06/16/remote-code-execution-as-system-user-on-samsung-phones/ may be able to remove the pin. Sorry if discussion about this isn't allowed or frowned upon. Seems like a pain and it may not work for the s3
Click to expand...
Click to collapse
Doesn't effect S3 vzw. only S4 and up
Wking46 said:
Doesn't effect S3 vzw. only S4 and up
Click to expand...
Click to collapse
Ah I read "swift" as Swype and my Prepaid Verizon GS3 came with Swype preinstalled.
I have an idea, perhaps try the Verizon repair software "repair" the device to back up data while in Odin mode? I don't recall if it will require a password or anything.I don't believe it required USB debugging to be enabled, don't know if it works while in Odin mode. I don't know if the backups are encrypted or not. You can try using sandboxie to see where it keeps the backed up data. I don't know if it will backup data while you're in Odin mode though. Worth trying I suppose. Don't have time try my The self or I would. Sorry for the rushed message, I'll be home in about an hour though.

FRP Lock on Marshmallow Cracked!!! [UPDATED w/ How-To]

Went through hell this evening after factory resetting my phone to find out that I needed to use my previous Google login to get back in. I had just changed my password which triggered a 72 hour lockout so I was unable to get back into my phone. I got online and researched how to get around this, only to find that Samsung had patched all most of the methods.
After 5 hours of work I was finally able to break through the restriction and get back into my phone without having to use my Google login. I am currently working on a how-to with all of the files necessary to recover and will consider posting it.
I am not sure how many people out there may need this, but please let me know if you do.
[Update]
Just to be clear I spent hours trying to find a workaround to this issue and after being unsuccessful many times I finally found a method that worked. I really only know a small amount about flashing ROM's on phones so there are most likely steps that aren't necessary or easier ways of doing this workaround, but there was no way in hell I was going to re lock my phone to try again. And yes I know this technically isn't a "crack" more of a workaround, its just that it was 3am and I hadn't slept in almost 24hrs and I finally made it in, so I got a little excited.
Things you will need
Computer
OTG Cable
Flash Drive
Required Software
Odin 3
N920PSPTAO16
SM-N920P_OK3_BOOTLOADER.tar
Google Bypass USB OTG.apk
N920PSPT2BPC3
Instructions
-Boot into download mode. (Power+VolDwn+Home)
-Flash N920PSPTAO16 with Odin.
-Allow phone to reset and complete at least one reboot loop.
-Boot into recovery (Power+VolUp+Home) and factory reset phone.
-Allow phone to reset and complete at least one reboot loop.
-Boot into download mode again (Power+VolDwn+Home) and flash SM-N920P_OK3_BOOTLOADER.tar with Odin.
-Allow phone to boot all the way to Google sign-in.
-Insert OTG Cable and Flash Drive with Google Bypass USB OTG.apk into phone.
-Install and open apk to gain access to settings.
-Go to "Backup and Reset" and click "Factory Data Reset", complete prompts to reset the phone.
-Phone should now be fully accessible.
To return to Marshmallow
-Boot into download mode. (Power+VolDwn+Home)
-Ensure "FRP LOCK" says OFF.
-Use Odin to flash N920PSPT2BPC3.
You're Done. Enjoy your unlocked phone.
I have to see this to believe it. Lol
Why not just post it here ? Like above, I have to see it to beleive it.
Im interested... post it
I am going to delete the files posted on here from my Drive account in the next few days. Please download and re-host it if you would like to, or show me where I can host it for free.
cac9478 said:
I am going to delete the files posted on here from my Drive account in the next few days. Please download and re-host it if you would like to, or show me where I can host it for free.
Click to expand...
Click to collapse
Just delete the big factory tars that are taking up all of your space and tell users to get them from sammobile.com or somewhere else.
Thanks I will do that.
Reveting back to OI6 was the only way I could get past the FRP lock myself. I thought you had a crack for Marshmallow. That is why I said I had to see it. Lol It's still a great post because a lot of people don't know that you can unlock by reverting the bootloaders. Thank you for sharing. If you take the latest PD1 update, you can't revert any more. Beware!!! Lol
are you sure that downgrading the firmware will not brick my phone?
i heard that downgrading the firmware will cause your phone to death. help plz?
If you have upgraded to PD1 or beyond you can no longer use this method. PC3 is the last one that worked for me.
skyrio said:
are you sure that downgrading the firmware will not brick my phone?
i heard that downgrading the firmware will cause your phone to death. help plz?
Click to expand...
Click to collapse
You can downgrade just fine so long as you follow the instructions.
MrMike2182 said:
You can downgrade just fine so long as you follow the instructions.
Click to expand...
Click to collapse
is there any away once you are on PD1?
the sboot method cant be used anymore?
Dont have to downgrade. I just unlock my N920I easily done un 15 mins.
All the methods shown on youtube or by rootjunky does not work in the straight forward manner as patch by Samsung took care of all that. But have to improvise a bit and it still works.
ndmuni said:
Dont have to downgrade. I just unlock my N920I easily done un 15 mins.
All the methods shown on youtube or by rootjunky does not work in the straight forward manner as patch by Samsung took care of all that. But have to improvise a bit and it still works.
Click to expand...
Click to collapse
How you unlocked your frp locked n920i?
ndmuni said:
Dont have to downgrade. I just unlock my N920I easily done un 15 mins.
All the methods shown on youtube or by rootjunky does not work in the straight forward manner as patch by Samsung took care of all that. But have to improvise a bit and it still works.
Click to expand...
Click to collapse
Are you willing to help a bit here?
It work. Wish i seen this post but i figured it out by myself two days ago.I was like if the hack came out a few months ago maybe if i downgrade to a different firmware i would be able to get the otg method to work. And it did.
Will these files work on a note5 n920g?
New to this
I'm locked out of my phone by frp s7 edge sprint sm g935p. I don't know what updates it has exactly, but would the downgrading work or is they're another way?
Loc0 said:
I'm locked out of my phone by frp s7 edge sprint sm g935p. I don't know what updates it has exactly, but would the downgrading work or is they're another way?
Click to expand...
Click to collapse
use rootjunky new method.. you need to use realterm to get into the dialer then use that to get into browser then use that to open samsung app store then use that to dl es file explorer then use that to dl and install Google Account Manager the frp bypass apk and use browser sign in and youreset
cac9478 said:
Went through hell this evening after factory resetting my phone to find out that I needed to use my previous Google login to get back in. I had just changed my password which triggered a 72 hour lockout so I was unable to get back into my phone. I got online and researched how to get around this, only to find that Samsung had patched all most of the methods.
After 5 hours of work I was finally able to break through the restriction and get back into my phone without having to use my Google login. I am currently working on a how-to with all of the files necessary to recover and will consider posting it.
I am not sure how many people out there may need this, but please let me know if you do.
[Update]
Just to be clear I spent hours trying to find a workaround to this issue and after being unsuccessful many times I finally found a method that worked. I really only know a small amount about flashing ROM's on phones so there are most likely steps that aren't necessary or easier ways of doing this workaround, but there was no way in hell I was going to re lock my phone to try again. And yes I know this technically isn't a "crack" more of a workaround, its just that it was 3am and I hadn't slept in almost 24hrs and I finally made it in, so I got a little excited.
Things you will need
Computer
OTG Cable
Flash Drive
Required Software
Odin 3
N920PSPTAO16
SM-N920P_OK3_BOOTLOADER.tar
Google Bypass USB OTG.apk
N920PSPT2BPC3
Instructions
-Boot into download mode. (Power+VolDwn+Home)
-Flash N920PSPTAO16 with Odin.
-Allow phone to reset and complete at least one reboot loop.
-Boot into recovery (Power+VolUp+Home) and factory reset phone.
-Allow phone to reset and complete at least one reboot loop.
-Boot into download mode again (Power+VolDwn+Home) and flash SM-N920P_OK3_BOOTLOADER.tar with Odin.
-Allow phone to boot all the way to Google sign-in.
-Insert OTG Cable and Flash Drive with Google Bypass USB OTG.apk into phone.
-Install and open apk to gain access to settings.
-Go to "Backup and Reset" and click "Factory Data Reset", complete prompts to reset the phone.
-Phone should now be fully accessible.
To return to Marshmallow
-Boot into download mode. (Power+VolDwn+Home)
-Ensure "FRP LOCK" says OFF.
-Use Odin to flash N920PSPT2BPC3.
You're Done. Enjoy your unlocked phone.
Click to expand...
Click to collapse
can i apply this script to my one...without any risk...
i am on (N920CXXS3BPK3)6.0.1
please suggest.....
Thanks

Hard bricked

I just hard bricked my phone, and I'm hoping I can try to get it working again.
I have made backups using flashfire in the past. (I had a few different backups I made).
Prior to getting hard bricked, I was running the PIA firmware, but I was trying to restore from a backup that I had through flash fire, and due to a total rookie move I ended up restoring (or attempting to) restore to a PG1 unintentionally, and well now I can't do anything.
I think I may have a jig at home from a previous samsung phone (I believe an S3), would that work for my S7?
I also came across this thread: http://forum.xda-developers.com/showthread.php?t=2476353
Would that work for me?
I have a macbook pro I can use terminal with, I have a microSD card and reader, and I already have the stock PIA rom on my hard drive.
Is there hope still?
Right now regardless of what key combination I hold down my phone has a black screen.
Any help would greatly be appreciated.
Thanks in advance!
If you can't get into download mode then you don't have much to lose by trying what the other thread suggested.
@sacnotsack, thanks for the response, and that is my intention, however I am missing 1 crucial part to that thread and that is the debrick.img
Can someone with the PIA (G930TUVU4APIA) rom please post a dump of a partial system img for me? If I'm not mistaken, you can dump it with these commands in ADB.
adb shell
dd if=/dev/block/sda20 of=/sdcard/debrick.img bs=4096 count=128
Just to clarify...
sda20 should be the system partition. Any way that's what it is for me.
You can check yourself by doing typing this in ADB:
ls -al /dev/block/bootdevice/by-name
You will get something like this:
lrwxrwxrwx root root 2016-01-08 10:35 system -> /dev/block/sda20
And to get the block size you would type this:
blockdev --getbsz /dev/block/sda20
So the command
"dd if=/dev/block/sda20 of=/sdcard/debrick.img bs=4096 count=128"
If I get this working, I'll compile a nice tut for S7 users and post all the results with files in case anyone else runs into this issue.
Thank you in advance
I don't mean to be an annoyance, but does anyone have any thoughts or could point me to some direction? I know there are a lot of you that are much more knowledgable in this than I am, and all I'm hoping I can get assistance for is if someone can just make a dump of the debrick.img file so I can try to load it on my SD card.
Thanks
Hi, the easiest way to restore back to stock is to download Odin. I think it's Windows exclusive so you'll need bootcamp and install windows. After that, download Odin and extract it. Download stock firmware from androidfilehost.com, then extract. Open Odin and you'll see the options BL, AP, CP, and CSC. The firmware will have 4 or 5 files and will include these labels. Put each respective files into each options in odin. (Sometimes Odin will freeze, but let it do it's thing) After that, go into download mode (hold Volume down, Power, and Home whole turning on). Wait for Odin to recognize your device, if it doesn't, then download Samsung drivers. After it recognizes, press start and wait for the process to finish. That's it! Hopefully I was able to help.
MetalPhoenix45 said:
Hi, the easiest way to restore back to stock is to download Odin. I think it's Windows exclusive so you'll need bootcamp and install windows. After that, download Odin and extract it. Download stock firmware from androidfilehost.com, then extract. Open Odin and you'll see the options BL, AP, CP, and CSC. The firmware will have 4 or 5 files and will include these labels. Put each respective files into each options in odin. (Sometimes Odin will freeze, but let it do it's thing) After that, go into download mode (hold Volume down, Power, and Home whole turning on). Wait for Odin to recognize your device, if it doesn't, then download Samsung drivers. After it recognizes, press start and wait for the process to finish. That's it! Hopefully I was able to help.
Click to expand...
Click to collapse
MetalPhoenix45, thanks for your response. I have a Windows computer as well and I am very familiar with ODIN. The issue is, that in your explanation my guess is you are thinking the phone is in a "soft bricked" mode. The difference between a hard brick phone and a soft brick phone is that in a hard brick phone nothing is recognized when plugged in, it doesn't power on and it also doesn't show any sign of charge when it's plugged into the power.
In a soft brick mode, your phone can be stuck in a boot loop, or at the very least it still shows signs of it getting power. In which case I can just force into download mode and do what you stated above. I don't think that the things you mentioned above would work for me because when I have my phone plugged in to my computer, in device manager it doesn't detect anything. It doesn't even say unknown device or unrecognized hardware. It doesn't see it at all, and I have loaded the Samsung drivers on my pc because ODIN recognized the device prior to my issue.
I do have the stock firmware and everything on my machine, but I just can't get my phone to power or on into download boot even with a JIG.
m0d hipp¥ said:
I just hard bricked my phone, and I'm hoping I can try to get it working again.
I have made backups using flashfire in the past. (I had a few different backups I made).
Prior to getting hard bricked, I was running the PIA firmware, but I was trying to restore from a backup that I had through flash fire, and due to a total rookie move I ended up restoring (or attempting to) restore to a PG1 unintentionally, and well now I can't do anything.
I think I may have a jig at home from a previous samsung phone (I believe an S3), would that work for my S7?
I also came across this thread: http://forum.xda-developers.com/showthread.php?t=2476353
Would that work for me?
I have a macbook pro I can use terminal with, I have a microSD card and reader, and I already have the stock PIA rom on my hard drive.
Is there hope still?
Right now regardless of what key combination I hold down my phone has a black screen.
Any help would greatly be appreciated.
Thanks in advance!
Click to expand...
Click to collapse
Have you had any luck on fixing s7 I've got same issue I've even got device broken down minus the charger port due to cost of screen replacement! Not sure exactly how to test battery itself but every combination of testing battery externally I've nothing any ideas? I'd rather replace the battery vs charger port or is it completely done? This is.the first root I've ever had go wrong and haven't found any solutions yet and been looking since November
Thanks in advance for any advice
On rooted 910v now have a 920t rooted but let's just say my temper got the best of me and we'll will be replacing screen? Oddly enough as many times as the note 4 has been dropped either by myself or son not even a single scratch s7 definitely a pot more brittle!!
crazynate121 said:
Have you had any luck on fixing s7 I've got same issue I've even got device broken down minus the charger port due to cost of screen replacement! Not sure exactly how to test battery itself but every combination of testing battery externally I've nothing any ideas? I'd rather replace the battery vs charger port or is it completely done? This is.the first root I've ever had go wrong and haven't found any solutions yet and been looking since November
Thanks in advance for any advice
On rooted 910v now have a 920t rooted but let's just say my temper got the best of me and we'll will be replacing screen? Oddly enough as many times as the note 4 has been dropped either by myself or son not even a single scratch s7 definitely a pot more brittle!!
Click to expand...
Click to collapse
Unfortunately, I had no luck. I ended up haing to replace the PCB to fix the issue. Basically I learned the hard way that samsung isn't very "dev friendly". I don't blame them, but for any phone enthusiasts that plan on tinkering with their phone if you get the snapdragon version of the S7 vs the exynos version, you WILL run into trouble.
This is because the bootloader can't be unlocked on the SD models. Furthermore, if you get flagged for custom roms your warranty gets void. Over the years I've noticed Samsung is getting more and more strict about this. Honestly if you want a phone that will play nice with modding it, you should look into the google variants, Nexus, or the OnePlus. I can tell you from personal experience, OnePlus plays well with dev users. In fact they don't void the warranty for using custom roms or anything like that; in fact they're very pro and open about supporting the user base and providing a phone that the user is happy with.
Any way, that was my experience. I don't want to go off topic here, so if you have any questions you can PM me if you like, but the short answer is, if you're hard bricked then you will need to replace the motherboard/pcb. I even contacted places to see if they can jtag or jig or anything and they're not able to do it with the snapdragon S7.
bah double post, sorry I can't delete this
Funny you said nexus just ordered 2 two days ago older 7 but 4g and and what not strictly for experimental and ethical purposes of course was actually shocked at the still high priced note 5 Screen tbh but we live and learn!! SOMETIMES? LOL
m0d hipp¥ said:
Unfortunately, I had no luck. I ended up haing to replace the PCB to fix the issue. Basically I learned the hard way that samsung isn't very "dev friendly". I don't blame them, but for any phone enthusiasts that plan on tinkering with their phone if you get the snapdragon version of the S7 vs the exynos version, you WILL run into trouble.
This is because the bootloader can't be unlocked on the SD models. Furthermore, if you get flagged for custom roms your warranty gets void. Over the years I've noticed Samsung is getting more and more strict about this. Honestly if you want a phone that will play nice with modding it, you should look into the google variants, Nexus, or the OnePlus. I can tell you from personal experience, OnePlus plays well with dev users. In fact they don't void the warranty for using custom roms or anything like that; in fact they're very pro and open about supporting the user base and providing a phone that the user is happy with.
Any way, that was my experience. I don't want to go off topic here, so if you have any questions you can PM me if you like, but the short answer is, if you're hard bricked then you will need to replace the motherboard/pcb. I even contacted places to see if they can jtag or jig or anything and they're not able to do it with the snapdragon S7.
Click to expand...
Click to collapse
I am in the same boat, and considering your experience after this sore event, maybe you can help a lot of us guys here in the same situation.
My case is even worst, because, here in my country, there are NO Snapdragons, just G930F Equinoxes.
You may help im providing us lames the debrick.img file, but you must be rooted to do so. This would ve much appreciated.
Another way is to insert a blank 16GB+ SD card on the phone and format it through Odin. You just insert the card on the slot, enter download mode in the phone and load all files in Odin including the .pit. In Odin options select "Re-format" and "T Flash" that will say to the phone to format the ExtSDCard and use the ExtSDCard as destination instead of the internal emmc!
Post the image of the SD, that you can extract it with the Win32DiskImage, and you and your family will be blessed for ten generations. Also save the file in case you mess things again.
There is one method using QFil,but i'm stil trying to asemble all required files and don't now if it will even work. Should work...!!!
Anyway, can you please help us?
Best regards..
PadsPCB said:
I am in the same boat, and considering your experience after this sore event, maybe you can help a lot of us guys here in the same situation.
My case is even worst, because, here in my country, there are NO Snapdragons, just G930F Equinoxes.
You may help im providing us lames the debrick.img file, but you must be rooted to do so. This would ve much appreciated.
Another way is to insert a blank 16GB+ SD card on the phone and format it through Odin. You just insert the card on the slot, enter download mode in the phone and load all files in Odin including the .pit. In Odin options select "Re-format" and "T Flash" that will say to the phone to format the ExtSDCard and use the ExtSDCard as destination instead of the internal emmc!
Post the image of the SD, that you can extract it with the Win32DiskImage, and you and your family will be blessed for ten generations. Also save the file in case you mess things again.
There is one method using QFil,but i'm stil trying to asemble all required files and don't now if it will even work. Should work...!!!
Anyway, can you please help us?
Best regards..
Click to expand...
Click to collapse
Unfortunately, I won't be of much help. If you have the exynos S7, you would need to ask someone else with the same version of your phone for the software because the SD versions would run on different software due to different hardware.
Is there a reason why you don't try sending it out to get serviced so they can replace your PCB ?
I tried to get the debrick.img file a while back as well, but had no luck in doing so and actually I don't have my S7 phone anymore. I bought the OnePlus 3T and it's been working much better for my needs. I'm sorry to say this, but If you have any intention of modding a phone you have 2 options. 1. Get a phone that supports modding and allows you to unlock the bootloader 2. Get the unlocked variant of the phone.
If I have learned anything from my experience, it's that it is incredibly important to do your research. Not only look at the specs of the phone, but look at reviews from other users with the phone. Also if you plan on modding it, go through some threads and see how easy/difficult it is to mod that version of phone you're interested in.
m0d hipp¥ said:
Unfortunately, I won't be of much help. If you have the exynos S7, you would need to ask someone else with the same version of your phone for the software because the SD versions would run on different software due to different hardware.
Is there a reason why you don't try sending it out to get serviced so they can replace your PCB ?
I tried to get the debrick.img file a while back as well, but had no luck in doing so and actually I don't have my S7 phone anymore. I bought the OnePlus 3T and it's been working much better for my needs. I'm sorry to say this, but If you have any intention of modding a phone you have 2 options. 1. Get a phone that supports modding and allows you to unlock the bootloader 2. Get the unlocked variant of the phone.
If I have learned anything from my experience, it's that it is incredibly important to do your research. Not only look at the specs of the phone, but look at reviews from other users with the phone. Also if you plan on modding it, go through some threads and see how easy/difficult it is to mod that version of phone you're interested in.
Click to expand...
Click to collapse
Then i think got stuck, beacause in these forums there is no one willing/able/interested in helping anyone.
I said i'm in the SAME boat == I got an SM-G930T (from T-Mobile) that has a SnapDragon cpu but HERE in my country THERE ARE NO Snapdragons only Equinoxes. If we had such phones here surely i would have done this already, but G930F's won't do, as i have already tried.
So, as you know how i feel about a brand new SM-G930T Bricked, you wold be my last hope. There is no way to send it back to Samsung beacause it was bought from a friend and surely no warranty.
Anyway, best regards and rest in peace
Oh sorry, I misunderstood you. I'd like to think that it's not so much people don't want to try to help out, it's just that there is nothing that can be done for users on the snapdragon device so no one bothers unfortunately. Sorry to hear about this, and it really is unfortunate that you had to go through the same thing I went through with no help. Trust me, if I was able to do anything to provide any guidance I would.
Good luck!

Odin root flash not working

Hi guys,
Not started a thread on XDA for years but I really am stumped.
I have claimed my girlfriends s6 (SM-G920F) after she upgraded and intended to root it and maybe try a few Oreo ROMs etc. After investigation I saw that (I think this is right) I don't need to OEM unlock this version of the device and rooting via Odin is the best way to do it. BTW if I do need to OEM unlock then that might be the solution to my issue, so if some one could clarify that'd be great.
So a week ago I downloaded Odin and also my old favourite CF-AutoRoot after putting in the device details. The package was generated, I unzipped and put it in a folder in my desktop
After putting the device in download mode I run Odin as administrator and plug it in. The device is recognised and I get the blue box to show this.
I then click the AP box and select the image file and click start, everything runs as expected to this point and I get PASS displayed in the info bar. On the phone the progress bar looks like it has not completed and I can see a small portion still to run. On the first try I left phone like this waiting for it reboot for over an hour. I was expecting 5he device to reboot and get the android with the red exclamation point. At this point I restarted manually and saw during the boot process an error message saying Recovery not SE Enforcing in red.
I have read a few posts saying this can be caused by the wrong image being used, so I downloaded the Auto root package again and made sure that it was all correct, but the same thing occurred.
I have been looking and reading for the last week to find a solution, but I'm still in the same position. Can anyone help or point me in the right direction?
If you need any more info let me know.
Thanks in advance
Jon
im in exacltly the same boat pal. was running nanorom on my rooted s6, but had no vr capability and just got some galaxy gear goggles. tried to reflash arter97 kernal and lost my whole setup. ive been in and out of hard brick for last 24hrs and am back now to where you are, i can access download and recoveries via three button combo, but any packages i flash with odin just fail out right.
ive been here before though and usually get out once i find the right stock rom and csc's for my version. iof i find anything ill come back and share it with you pal.
Cheers mate, it's really frustrating. I'll keep looking too and post back if I have any success.
Hi guys, this thread hasn't been responded to so I thought I'd just replied to it to give it a little bump up. I'd much appreciate it if anybody could help me out here.
Thanks again,
Jon
copernicus666 said:
Hi guys, this thread hasn't been responded to so I thought I'd just replied to it to give it a little bump up. I'd much appreciate it if anybody could help me out here.
Thanks again,
Jon
Click to expand...
Click to collapse
Just try bro to reflash full stock rom again by odin and after flash it , reflash cf-autoroot again
also , can you provide more information about your android version and your csc stock rom ?
what a f**k about!!!!
Right then Jon,
sorry for my delay but not the greatest at reponding to things at the best of times, but with my own s6 in a right old state, and a 7y.o and 4 month old in the house, my pc time is limited.
anyways, im guessing you're a bit like me, and you've had your fair share of flashing roms and roots since the days of old! (Galaxy thru and thru for me s 1,3,4,6, plus tabs and watches).
this s6 gt-920f is a completely different kettle of fish mate. where you're at at the minute, if your still stuck in bootloop with no recovery, your gonna want to find twrp recovery, as you know mate, google will be your guide. you flash this just like a rom or the old cwm, download a zip, bang it in ap/pda in odin and let it flash. KEY NOTE IS MAKE SURE ODIN HAS ~"AUTO-REBOOT"~ UNTICKED, UNCHECKED, NO MARK IN THE BOX. THIS IS KEY TO THE RESTORATION PROCESS GOING FORWARD. Once odin shows that the file has flashed and passed, get ready to perform a three button power reset, Home button, Vol DOWN and Power for 8 seconds. when your pc makes the badong sound and the screen goes off, IMMEDIATELY SWITCH TO Vol UP, Home and Power, thus straight into recovery mode, AND WAIT.
You should see the blue and silver TWRP splash screen and then the recovery options. Firstly, wipe and format everything, dalvik, caches and perform a factory reset. twrp should ask you to type yes to confirm, do it, there's nothing there yet any ways. if you get any issues about cant mount data or some jazz, DONT PANIC, use twrp to reformat the partition to ext4, your pc should ping to show reconnection to the phone.
Now whilst still in twrp, nav to the reset options and reboot into download mode. if all has go well, the scren should have the regular greenish odin screen but without all the samsung odin mode in at the top. odin should show the phone as a connected device, you should be able to access your memory card from your pc to transfer rom zips etc and get the phone back up the way you are used to.
if on the other hand you want to get back to vanila stock style android, with the expense of a tonload of bloatware and crapps, you're gonna wanna take a goggle at stuff like "G920F Repair Firmware X.X UK YYY) , Where X.X is 5.1, 6.1, 7.1, depending on the original android version your brick was on, and YYY is your carrier or network operator, off the top of my head they are VOD, TMO, O2U, H3G.
AGAIN A KEY POINT IF YOUR GOING THIS ROUTE, THESE FILES ARE MADE FOR INDIVIDUAL MODELS OF S6 (THERES ABOUT 12 MODEL NUMBERS -YOURS IS AND ALWAYS WILL BE SM-G920F - SO DO NOT EVER STRAY FROM THAT NUMBER!!!! ) THAT MEANS YOU NEED TO BE FINDING FILES LIKE "G920XXU5EXUE 4 files repair firmwares", THESE ARE YOUR SAVIOUR. GET THE ONE THAT MATCHES YOUR PHONE AND CARRIER OR ONE THAT IS AS NEAR AS DAMMIT, AND AGAIN PLEASE MAKE SURE FOR THE LOVE OF YOUR PHONE THAT YOU ONLY GET FILES MARKED G920, ANYTHING ELSE WILL RESULT IN VERY SERIOUS ERRORS.
YOUR ALSO GOING TO NEED SOMETHING CALLED A PIT FILE, EASY TO FIND, LOOK FOR " S6 ZEROFLTE HIDDEN IMG FILE" IN GOOGLE.
USE OUR OLD BUDDY ODIN TO FLASH THE FOUR FILES YOU GOT FROM THE REPAIR FIRMWARE ZIP, WHICH ARE USUALLY LABEL AP, BL, CP AND CSC.. NOW TAP THE PIT TAB IN ODIN (IGNORE THE WARNING) AND NAVIGATE TO THE HIDDEN.IMG FILE YOU GOT AND BANG IT HERE. ON THE OPTIONS TAB YOU WANT TO TICK AUTO REBOOT, REPARTITION, and NAND ERASE ALL. i know, i know, you probably never use it out of some shear panic but right now its kosher.
start the flash and take a break. like a big break. the process is gonna wipe the phone in totalilty, rewrite every bit of code and software and reload like new after about forty minutes.
now, if it doesnt, there are a few things we can look at but am gonna leave it here and hope you can make some use of the ramblings of a lost man. my 6 is currently in an inverted touch bug where if i touch one side of the screen, the opposite side responds so its a proper nightmare, typing anything means that a becomes l, s becomes k etc. thisis down to me drunk flashing the wrong roms for and s6 edge, g925f, hence all my warnings earlier. anyways, i need a reefer and a scran after all this, God, allah, buddah i hope it helps someone.
shiko2007 said:
Just try bro to reflash full stock rom again by odin and after flash it , reflash cf-autoroot again
also , can you provide more information about your android version and your csc stock rom ?
Click to expand...
Click to collapse
Hi, thanks for replying.
I'm on the original stock, I've not flashed any thing just yet. To be honest, I'm not sure it'd work.
The android version is 7.0 and the build is NRD90M.G920FXXS5EQH6
Be glad if you have any advise.
Thanks
copernicus666 said:
Hi, thanks for replying.
I'm on the original stock, I've not flashed any thing just yet. To be honest, I'm not sure it'd work.
The android version is 7.0 and the build is NRD90M.G920FXXS5EQH6
Be glad if you have any advise.
Thanks
Click to expand...
Click to collapse
if your not root yet just download latest your carrier/country firmware
from sammobile
and flash it by odin
but you are probably trip knox so you must root
so the steps you should do :
1-download your carrier/country firmware from sammobile
2-flash it by odin
3-flash cf-auto root to pass bootloop
or
download twrp recovery of g920f and flash it by odin to replace stock recovery then after flash it ,wipe delvik cash then flash su binary
DagsyMc said:
Right then Jon,
sorry for my delay but not the greatest at reponding to things at the best of times, but with my own s6 in a right old state, and a 7y.o and 4 month old in the house, my pc time is limited.
anyways, im guessing you're a bit like me, and you've had your fair share of flashing roms and roots since the days of old! (Galaxy thru and thru for me s 1,3,4,6, plus tabs and watches).
this s6 gt-920f is a completely different kettle of fish mate. where you're at at the minute, if your still stuck in bootloop with no recovery, your gonna want to find twrp recovery, as you know mate, google will be your guide. you flash this just like a rom or the old cwm, download a zip, bang it in ap/pda in odin and let it flash. KEY NOTE IS MAKE SURE ODIN HAS ~"AUTO-REBOOT"~ UNTICKED, UNCHECKED, NO MARK IN THE BOX. THIS IS KEY TO THE RESTORATION PROCESS GOING FORWARD. Once odin shows that the file has flashed and passed, get ready to perform a three button power reset, Home button, Vol DOWN and Power for 8 seconds. when your pc makes the badong sound and the screen goes off, IMMEDIATELY SWITCH TO Vol UP, Home and Power, thus straight into recovery mode, AND WAIT.
You should see the blue and silver TWRP splash screen and then the recovery options. Firstly, wipe and format everything, dalvik, caches and perform a factory reset. twrp should ask you to type yes to confirm, do it, there's nothing there yet any ways. if you get any issues about cant mount data or some jazz, DONT PANIC, use twrp to reformat the partition to ext4, your pc should ping to show reconnection to the phone.
Now whilst still in twrp, nav to the reset options and reboot into download mode. if all has go well, the scren should have the regular greenish odin screen but without all the samsung odin mode in at the top. odin should show the phone as a connected device, you should be able to access your memory card from your pc to transfer rom zips etc and get the phone back up the way you are used to.
if on the other hand you want to get back to vanila stock style android, with the expense of a tonload of bloatware and crapps, you're gonna wanna take a goggle at stuff like "G920F Repair Firmware X.X UK YYY) , Where X.X is 5.1, 6.1, 7.1, depending on the original android version your brick was on, and YYY is your carrier or network operator, off the top of my head they are VOD, TMO, O2U, H3G.
AGAIN A KEY POINT IF YOUR GOING THIS ROUTE, THESE FILES ARE MADE FOR INDIVIDUAL MODELS OF S6 (THERES ABOUT 12 MODEL NUMBERS -YOURS IS AND ALWAYS WILL BE SM-G920F - SO DO NOT EVER STRAY FROM THAT NUMBER!!!! ) THAT MEANS YOU NEED TO BE FINDING FILES LIKE "G920XXU5EXUE 4 files repair firmwares", THESE ARE YOUR SAVIOUR. GET THE ONE THAT MATCHES YOUR PHONE AND CARRIER OR ONE THAT IS AS NEAR AS DAMMIT, AND AGAIN PLEASE MAKE SURE FOR THE LOVE OF YOUR PHONE THAT YOU ONLY GET FILES MARKED G920, ANYTHING ELSE WILL RESULT IN VERY SERIOUS ERRORS.
YOUR ALSO GOING TO NEED SOMETHING CALLED A PIT FILE, EASY TO FIND, LOOK FOR " S6 ZEROFLTE HIDDEN IMG FILE" IN GOOGLE.
USE OUR OLD BUDDY ODIN TO FLASH THE FOUR FILES YOU GOT FROM THE REPAIR FIRMWARE ZIP, WHICH ARE USUALLY LABEL AP, BL, CP AND CSC.. NOW TAP THE PIT TAB IN ODIN (IGNORE THE WARNING) AND NAVIGATE TO THE HIDDEN.IMG FILE YOU GOT AND BANG IT HERE. ON THE OPTIONS TAB YOU WANT TO TICK AUTO REBOOT, REPARTITION, and NAND ERASE ALL. i know, i know, you probably never use it out of some shear panic but right now its kosher.
start the flash and take a break. like a big break. the process is gonna wipe the phone in totalilty, rewrite every bit of code and software and reload like new after about forty minutes.
now, if it doesnt, there are a few things we can look at but am gonna leave it here and hope you can make some use of the ramblings of a lost man. my 6 is currently in an inverted touch bug where if i touch one side of the screen, the opposite side responds so its a proper nightmare, typing anything means that a becomes l, s becomes k etc. thisis down to me drunk flashing the wrong roms for and s6 edge, g925f, hence all my warnings earlier. anyways, i need a reefer and a scran after all this, God, allah, buddah i hope it helps someone.
Click to expand...
Click to collapse
Legendary post! Cheers mate you just made my morning. I knew the XDA guys would pull through.
I'm on my way to work, but I'll give it a crack later.
Cheers bud - Kudos

AT&T Radiant Core (Tinno U304AA) - Modding Discussion

Picked up an AT&T Radiant Core for cheap at a store around me. I don't intend to use it with AT&T, it was just such a low price that I figured I'd get it and see if I can break into it just for fun. It's an MTK6739 chipset phone, so in theory it should be easy to pull partitions from this thing with something like SPFT (or Miracle Box, if you paid for it) and do a dirty port of TWRP to get root privileges on it. But this is harder than it seems.
I need an auth file to do anything with SPFT. Apparently this has to do with some kind of "secure boot" mechanism that MediaTeks sometimes have now. There's no stock firmware for this device online from what I can find, nor for the generic version of the device, the Tinno U304AA (AT&T just rebranded it). If I had a stock firmware image, maybe I could risk wiping the partitions and reflashing the stock firmware to get rid of the secure boot stuff.
I saw a guide for how to access the bootloader on the Tinno U304AA generic version, but on the AT&T version of the phone there's no option in the boot select menu (Vol. UP + Power) to get to the bootloader to run a fastboot oem unlock. All the AT&T version has is recovery and normal boot. I'm not sure what I can do to maybe reset this to get the other options. Maybe if I had the stock firmware for the generic version of the phone I could overwrite it and get access to those other options.
Either way, just posting this up for anyone else that got one of these and wants to collaborate/contribute. Maybe with enough collective brainpower we can make something happen.
UPDATE: found a stock system image dump, thank you to @lopestom for directing me to this. This guy's been the MediaTek king for as long as I can remember.
It appears to be a dtbo and system partition dump. It also has the vendor partition and a (partial?) boot image dump. Not sure if things like the full boot and recovery images are stored somewhere in here, I didn't look too deeply into it yet. I have no idea how whoever this is managed to pull these partitions... they either got root access somehow, or they found a proper Download Agent and Auth file to pull it all. Either one of these would be awesome. I reached out to the user to ask them how they did it, we will see what they say if they want to share how they did it.
https://git.rip/dumps/att/u304aa
jasonmerc said:
Picked up an AT&T Radiant Core for cheap at a store around me. I don't intend to use it with AT&T, it was just such a low price that I figured I'd get it and see if I can break into it just for fun. It's an MTK6739 chipset phone, so in theory it should be easy to pull partitions from this thing with something like SPFT (or Miracle Box, if you paid for it) and do a dirty port of TWRP to get root privileges on it. But this is harder than it seems.
I need an auth file to do anything with SPFT. Apparently this has to do with some kind of "secure boot" mechanism that MediaTeks sometimes have now. There's no stock firmware for this device online from what I can find, nor for the generic version of the device, the Tinno U304AA (AT&T just rebranded it). If I had a stock firmware image, maybe I could risk wiping the partitions and reflashing the stock firmware to get rid of the secure boot stuff.
I saw a guide for how to access the bootloader on the Tinno U304AA generic version, but on the AT&T version of the phone there's no option in the boot select menu (Vol. UP + Power) to get to the bootloader to run a fastboot oem unlock. All the AT&T version has is recovery and normal boot. I'm not sure what I can do to maybe reset this to get the other options. Maybe if I had the stock firmware for the generic version of the phone I could overwrite it and get access to those other options.
Either way, just posting this up for anyone else that got one of these and wants to collaborate/contribute. Maybe with enough collective brainpower we can make something happen.
Click to expand...
Click to collapse
OMG! So excited to see this here! My Mom gave my nephew this phone and niece has one. So I've been trying my best to get the thing to at least be a decent phone! I installed a launcher on it, changed the icons and wallpaper and made it look good at least. It will be nice to have someone to talk to about this. The thing has been beyond frustrating! First off though how did you get the computer to recognize it? I can't get Windows or Linux to recognize it and couldn't find any drivers. If you managed that much you got further than I did. I haven't tried with my nieces though. It might just be his phone. She's 13 so it took awhile to pry it from her long enough to find out what kind it was, but I'm willing to try to get it from her once again if the phone can be improved.
sjjtnj said:
OMG! So excited to see this here! My Mom gave my nephew this phone and niece has one. So I've been trying my best to get the thing to at least be a decent phone! I installed a launcher on it, changed the icons and wallpaper and made it look good at least. It will be nice to have someone to talk to about this. The thing has been beyond frustrating! First off though how did you get the computer to recognize it? I can't get Windows or Linux to recognize it and couldn't find any drivers. If you managed that much you got further than I did. I haven't tried with my nieces though. It might just be his phone. She's 13 so it took awhile to pry it from her long enough to find out what kind it was, but I'm willing to try to get it from her once again if the phone can be improved.
Click to expand...
Click to collapse
Linux should just work, plug in the thing and the "drivers" if you will should be there already. Check the phone's settings for USB Debugging in the Developer Options if there's further trouble.
Don't get me wrong too, this phone is, was, and will always be a piece of junk. There's no getting around a screen this bad and 1GB of RAM. I'm actively trying to find a Download Agent and Auth File combo to get this thing to work with SPFT so I can try to port a custom recovery to get us Magisk root permissions at least. Root will make the phone slightly better, but it will still be junk. Unless we can get kernel source for it as well to mess with things like clock speeds and CPU governors (which LEGALLY we are supposed to be guaranteed, but good luck convincing a Chinese company to give it to you) everything we do, if we CAN do anything, will be like deodorant on a turd. It'll smell a little better, but it's still a turd.
jasonmerc said:
Linux should just work, plug in the thing and the "drivers" if you will should be there already. Check the phone's settings for USB Debugging in the Developer Options if there's further trouble.
Don't get me wrong too, this phone is, was, and will always be a piece of junk. There's no getting around a screen this bad and 1GB of RAM. I'm actively trying to find a Download Agent and Auth File combo to get this thing to work with SPFT so I can try to port a custom recovery to get us Magisk root permissions at least. Root will make the phone slightly better, but it will still be junk. Unless we can get kernel source for it as well to mess with things like clock speeds and CPU governors (which LEGALLY we are supposed to be guaranteed, but good luck convincing a Chinese company to give it to you) everything we do, if we CAN do anything, will be like deodorant on a turd. It'll smell a little better, but it's still a turd.
Click to expand...
Click to collapse
Right, I'm considering giving him my current phone when I get a new one. It doesn't seem like I'm going to be able to unlock and root it so I want a phone I can. Mainly for space personally. He's young so he doesn't need it rooted, but I'm thinking if I can root it then I might be able to use it to root my phone. Speaking of rooting I think I found a way to root this phone. It took me a couple days to get the phone since he said he couldn't find it, but I have it now. It just needs to charge, but the battery sucks so it takes forever. I did find out that it does have a decent recovery. I had booted it into recovery and then I was messing around with the keys after the little passed out green guy popped up and suddenly it loaded stock recovery. It had an option to mount the system and flash with adb and everything. The only problem is I kept booting it by messing with keys. So I honestly don't know which ones worked. I kept booting into it last night by messing with them, but now I can't seem to get it to boot into the right recovery now that I'm trying to figure out the right key combination. I will figure it out though (eventually) and let you know what you have to click, but if you get the chance just mess with it and hopefully you'll find it like I did.
Also I was looking up the phones variants and downloaded a couple stock roms that I felt had all the right specs I'm going to try to flash one if I can get it plugged in. I downloaded custom twrp image's for them as well, and even found one twrp that I was able to download in the app. If you used it then you know that it takes you to a download page if you are downloading the wrong twrp.img. So the fact it let me download it in the app meant it tricked twrp into thinking it was that phone. So I'm going to try that stock rom first. Maybe we'll be able to change it to another model. It really needs something flashed, because it's a mess. I thought he messed it up, but after reading what you said maybe it's just the phone. He's young so it doesn't matter as much to him, but I feel bad for my niece. I really need to look into at least getting her another phone. I'm going to work on it later today and see what I can do. First I got to get it to work on the computer, but I may be able to root it without the computer. I'll keep you updated with my progress.
any luck with this?
Yeh, is there a status update?
Sorry, I got a concussion and haven't been able to do much, but really I'm stuck because I can't get it to connect to the computer at all. Not in Windows or Linux. I think he's messed it up beyond repair at this point. The offline root gave me an error around the mounting of the system, but that can be done if you can get the recovery to show up. It's one of the options. I was trying this method. HERE see if you can get it plugged in and to work. Also, Kingoroot gets to 90% on the apk alone. So the computer app might do the trick. Then you can switch it to su. Really a rooted phone can get a lot done with apps like flashify and flashfire that we can't do right now. If you can get even a temp root let me know and I'll tell you what I found out about the apps to unlock the bootloader, flash TWRP, Flash Magisk, then flash ROMs. If you want to try the variant route I was trying then just do a search on google. Some sound just as bad, but other similar phones seem better. You can pick which one you want to try. The phone I have got to a point that it kept deleting applications and stuff on the phone and has trouble with the sd card. So I don't have the stuff I had saved on it anymore. I'm giving him my current phone when I get a new one. It's too messed up to salvage. I hope you have more luck.
sjjtnj said:
Sorry, I got a concussion and haven't been able to do much, but really I'm stuck because I can't get it to connect to the computer at all. Not in Windows or Linux. I think he's messed it up beyond repair at this point. The offline root gave me an error around the mounting of the system, but that can be done if you can get the recovery to show up. It's one of the options. I was trying this method. HERE see if you can get it plugged in and to work. Also, Kingoroot gets to 90% on the apk alone. So the computer app might do the trick. Then you can switch it to su. Really a rooted phone can get a lot done with apps like flashify and flashfire that we can't do right now. If you can get even a temp root let me know and I'll tell you what I found out about the apps to unlock the bootloader, flash TWRP, Flash Magisk, then flash ROMs. If you want to try the variant route I was trying then just do a search on google. Some sound just as bad, but other similar phones seem better. You can pick which one you want to try. The phone I have got to a point that it kept deleting applications and stuff on the phone and has trouble with the sd card. So I don't have the stuff I had saved on it anymore. I'm giving him my current phone when I get a new one. It's too messed up to salvage. I hope you have more luck.
Click to expand...
Click to collapse
I need to unlock my phone U304AA
Ok boys and girls, in case anyone is still wondering here is how to root this sucker.
https://drive.google.com/file/d/1--Ul1ae73zcejNuJ1a7ftq5sTo2VP8Ya/view?usp=drivesdk
Comes with two files. Mtksu amd magisk be sure to use the magisk version included in the zip. Install mtksu then wmagisk, open mtksu and install the top magisk option. Reboot then open magisk hit install when it asks. Now open mtksu scroll to the bottom and hit activate and reboot again. Should be good too go at this point. Oh yeah be sure to click apply at boot in mtksu. Not sure if this had been posted before or not. Now, to find a way to unlock bootloader and install twrp.
Thank you, I tried Mtksu on mine and it didn't work, but it might've been the phone. I don't have one of these anymore, but I hope you all the best of luck. For the bootloader and Twrp try Flashfire or flashify.
MTK bypass method released by some smart dudes out there. I will test if we can use SPFT on this phone now. Stay tuned. This could mean root & recovery in a matter of minutes.
EDIT: It ALMOST works. Technically it bypassed the auth file as advertised. The only thing left now is finding a compatible preloader/scatter file to use.
Used a modified Moto E6 Play scatter file to pull images from the device. Tried flashing over stuff and got an error. Long story short my U304AA is now permanently bricked, so I'm tapping out of this project here
I do have recovery and boot images that (supposedly) work if anyone else wants to try and take over Keep in mind these were pulled with a scatter file from a DIFFERENT phone that's of the same chipset, so not everything is guaranteed to work. For example, the preloader was pulled with the specified parameters but I do NOT know if it's functional
Because I'm tapping out, and because nobody else seems to have anything on this, I'm uploading everything I can. Some pulls are too big to upload and some just won't work for some reason, but use whatever you'd like for anything you can. Hope I did something helpful
I have searched in Google Search and the tutorials forum but not found a tutorial
_____________
Sent from my website: https://topsanphamhay.com/kem-chong-nang-danh-cho-da-dau-mun.html - https://topsanphamhay.com/kem-chong-nang-innisfree-perfect-uv-protection-cream-co-tot-khong.html - https://topsanphamhay.com/kem-chong...ifying-face-fluid-dry-touch-co-tot-khong.html using Iphone X
Well AT&T is giving away lots of Radiant Core devices because of their 3G shutdown: https://www.xda-developers.com/att-3g-shutdown-free-phone/
My wife and I just got one, so now I have two of these but I'm not sure I trust AT&T enough to use the "free" phone that they sent.
It would be great if someone can pickup this project, especially since so many phones are now flooding the market.
I just got 3 of these "free" from AT&T. In fact I don't really need them, I just happen to have phones with an IMEI number that AT&T cannot decipher, so they sent me new phones just in case I can't use 4G.
Anyway, I'm trying to use mine as spare Google assistants scattered around the house, but because they run that crappy Android Go, the Go version of Assistant won't listen to me until I long-press the home button. I would also like to use them when I travel as a spare.
These things are essentially throw-away, so I'm OK to risk bricking one of them.
What I really want to do is install a real version of Android on here, has anyone managed to crack this yet?
I personally have been writing and reading using this tool https://github.com/bkerler/mtkclient, which is much simpler than the others
Its a little rough around the edges, but it certainly works
My final problem is disabling secure boot (I already have a boot.img patched with magisk)
It appears that fastboot is simply not a mode for booting on this model, so I was wondering if anyone knows how to disable AVB by hand with just partition images
kayshinonome said:
I personally have been writing and reading using this tool https://github.com/bkerler/mtkclient, which is much simpler than the others
Its a little rough around the edges, but it certainly works
My final problem is disabling secure boot (I already have a boot.img patched with magisk)
It appears that fastboot is simply not a mode for booting on this model, so I was wondering if anyone knows how to disable AVB by hand with just partition images
Click to expand...
Click to collapse
if it's possible to downgrade the firmware to before the october 2019 patch, it might be possible to mtk-su the device: https://www.att.com/device-support/article/wireless/KM1376142/ATT/ATTU304AA
might be another alternative to trying to disable avb on a locked bootloader
luridphantom said:
if it's possible to downgrade the firmware to before the october 2019 patch, it might be possible to mtk-su the device: https://www.att.com/device-support/article/wireless/KM1376142/ATT/ATTU304AA
might be another alternative to trying to disable avb on a locked bootloader
Click to expand...
Click to collapse
Not possible to do, already tried before when I didn't brick it
KJ7LNW said:
Well AT&T is giving away lots of Radiant Core devices because of their 3G shutdown: https://www.xda-developers.com/att-3g-shutdown-free-phone/
Click to expand...
Click to collapse
Just got mine from this. I'd like to install something like NixOS mobile, but I've never used an android phone before. Will that be possible on this phone? If so, is there a good guide for newbs like myself?

Categories

Resources