Thank you to the guys at HEGE supporting Badcaps [ HEGE ] [ HEGE DEX Chart ]

Announcement

Collapse
No announcement yet.

Lenovo Thinkpad Ec Pwd Bypass

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Lenovo Thinkpad Ec Pwd Bypass

    Hello everyone.

    Here is the bypass solution for several Lenovo ECs.
    This has worked on many ECs.
    Only works if password is contained in EC

    I succeeded on many models
    https://www.badcaps.net/forum/troubl...86#post3217086
    https://www.youtube.com/channel/UCeF...t_adKcguvynjeA

    I shorten the LPC bus, with the LAD0:3 and Gnd.

    you can use the dedicated ports where you connect directly to the track.
    (Be careful, resistors may be missing on the path)
    look at the diagrams

    example x390 npce388


    The communication being cut off, corrupted,
    it cannot read information contained in EC and therefore continues.
    then simply clean by rewriting after access.

    Don't save with F10, just clean Pwd with enter twice.
    If the serial, uuid etc. information is corrupted, you are saving the wrong information
    Like the old way with sda/scl.

    The method is delicate, there is always a risk of bricking or try failed.
    ITE and Nuvoton is easy, Mec16 is more delicate (many try necessary).
    Timing is important
    watch videos to understand

    works on Mec1633 / Mec1653 / Mec1663 / IT8186VG / IT5261VG / NPCE68B / NCPE288/388 and surely others

    but my tests failed with the Mec1503
    The LPC bus is no longer used, it has been replaced by eSPI

    Attached some connection diagrams for tested models

    Edit
    -----------------------
    EC PWD eeprom location

    NCPE68B
    Dmi start from 0x5C120 and 0x5D120
    Pwd 0x5C420 - 0x5C56F and 0x5D420 - 0x5D56F replace with 00

    NCPE288/388
    Dmi start from 0x30000
    Pwd
    0x36000 - 0x3604F
    0x36080 - 0x360CF
    0x36100 - 0x3614F
    0x36180 - 0x361CF
    0x36200 - 0x3624F
    0x36280 - 0x362CF
    0x36300 - 0x3634F
    0x36380 - 0x363CF
    0x36400 - 0x3644F
    0x36480 - 0x364CF
    0x36500 - 0x3654F
    0x36580 - 0x365CF
    0x36600 - 0x3664F
    0x36680 - 0x366CF
    replace with 00

    Mec1663 Dmi start from 0x00
    Pwd 0x300 - 0x34F replace with FF

    search for this shape
    Click image for larger version  Name:	ec pwd.png Views:	0 Size:	310.0 KB ID:	3237274
    Last edited by Maxpower3; 03-17-2024, 01:05 PM.

    #2
    Thanks for sharing and as always good job!
    ----------------------------------------------------------------------------------------------------------------------------------------------------------------------
    Due to a lack of donations, server free space at a critical level, and possible closure of Bios Requests
    all donations are welcome,
    see the donate button at the bottom of the page, or
    >>>>>
    click on this link to donate via PayPal. <<<<<
    Every donation made will go towards server fees and maintenance costs.
    ----------------------------------------------------------------------------------------------------------------------------------------------------------------------

    Comment


      #3
      Originally posted by Maxpower3 View Post

      but my tests failed with the Mec1503
      The LPC bus is no longer used, it has been replaced by eSPI
      Thank you MxP
      Yesterday I discovered what you posted, I immediately realized the solution and thought straight to Mec1503
      What is the difference between eSPI and LPC? Only speed?

      Comment


        #4
        I don't know yet, I haven't looked closely yet. the post is also there for research
        Click image for larger version

Name:	vs.jpg
Views:	1310
Size:	451.8 KB
ID:	3237265
        Attached Files

        Comment


          #5
          On the diagram, communication is identical!


          Click image for larger version  Name:	espi.jpg Views:	3 Size:	79.5 KB ID:	3237276

          .

          Comment


            #6
            During my tests, freezing and overconsumption of the PC.
            need to cut off the power
            I couldn't do many tests because I don't have a lot of Mec15,
            like Ncpx, I couldn't test

            Comment


              #7
              Originally posted by Maxpower3 View Post
              During my tests, freezing and overconsumption of the PC.
              need to cut off the power
              I couldn't do many tests because I don't have a lot of Mec15,
              like Ncpx, I couldn't test
              I don't have a 1503 or ncpx at the moment.
              Frezing in logo? or before logo?

              Comment


                #8
                Originally posted by CraterM View Post

                I don't have a 1503 or ncpx at the moment.
                Frezing in logo? or before logo?
                as soon as you touch it's over

                Comment


                  #9
                  Click image for larger version

Name:	pfff.jpg
Views:	1263
Size:	50.8 KB
ID:	3237309
                  Hello, Please, Thanks Lost in space .....?
                  it's over DXE

                  Comment


                    #10
                    Like I said, tested on P53 and P1 gen 2, thus works fine on ncpx.

                    Which model has mec1503?

                    Comment


                      #11
                      Originally posted by RethoricalCheese View Post
                      Which model has mec1503?
                      T14S gen 2
                      https://www.badcaps.net/forum/troubl...m-d362-rev-3-0

                      thank you for your well feedback
                      Last edited by Maxpower3; 03-17-2024, 03:19 PM.

                      Comment


                        #12
                        Originally posted by RethoricalCheese View Post
                        Like I said, tested on P53 and P1 gen 2, thus works fine on ncpx.

                        Which model has mec1503?
                        Working because use LPC.

                        But these use eSPI
                        Lenovo T16 Gen.1 NPCX997
                        Lenovo L15 Gen.3 NPCX997
                        ThinkPad X1 Yoga 6th gen MEC1503
                        X1 Carbon 10th / X1 Yoga 7th gen - MEC1723

                        Comment


                          #13
                          which point you short circuit to reset the password

                          Comment


                            #14
                            Originally posted by miansh621 View Post
                            which point you short circuit to reset the password
                            Click image for larger version

Name:	Pff2.jpg
Views:	1226
Size:	18.4 KB
ID:	3237640
                            afterwards people ask me why I don't want to share.
                            Damn, make an effort and look for everything indicated.​

                            stop private messages without any form of politeness too



                            Comment


                              #15
                              ok sorry bro

                              Comment


                                #16
                                Originally posted by RethoricalCheese View Post
                                Like I said, tested on P53 and P1 gen 2, thus works fine on ncpx.
                                Click image for larger version

Name:	image.png
Views:	1150
Size:	8.4 KB
ID:	3237663

                                find schematics or boardview

                                Comment


                                  #17
                                  Originally posted by CraterM View Post

                                  Working because use LPC.

                                  But these use eSPI
                                  Lenovo T16 Gen.1 NPCX997
                                  Lenovo L15 Gen.3 NPCX997
                                  ThinkPad X1 Yoga 6th gen MEC1503
                                  X1 Carbon 10th / X1 Yoga 7th gen - MEC1723
                                  I've got a few ones with NPCX997. Will try them in a couple of days.
                                  P1 Gen 4/5
                                  P16s Gen 1

                                  Not sure if I have any MEC1503. Shall see.

                                  Comment


                                    #18
                                    Originally posted by RethoricalCheese View Post

                                    I've got a few ones with NPCX997. Will try them in a couple of days.
                                    P1 Gen 4/5
                                    P16s Gen 1

                                    Not sure if I have any MEC1503. Shall see.
                                    If you can do it on NPCX997, I think it works on 1503

                                    Comment


                                      #19
                                      NM B911 E490 It8227 (not tested)
                                      Attached Files
                                      Last edited by Maxpower3; 03-18-2024, 02:25 PM.

                                      Comment


                                        #20
                                        T480S NM-B471
                                        Tested Ok
                                        Cliquez sur l'image pour la voir en taille r?elle   Nom : 		T480s Nm-B471.jpg  Affichages :	0  Taille :		473,9 Ko  ID : 			3238407

                                        Comment

                                        Working...
                                        X