Lenovo Thinkpad Ec Pwd Bypass

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • claudio21s
    Member
    • Nov 2022
    • 28
    • chile

    #401
    Hello, could someone help me to bypass an L14 GEN3 AMD?
    Attached Files

    Comment

    • Maxpower3
      Bad Veteran
      • Feb 2018
      • 1155
      • France

      #402
      Originally posted by claudio21s
      Hello, could someone help me to bypass an L14 GEN3 AMD?
      Click image for larger version

Name:	image.png
Views:	1305
Size:	99.0 KB
ID:	3481048

      Comment

      • rediii
        h???, spurrrn
        • Mar 2018
        • 485
        • somewhere in europe

        #403
        Originally posted by Maxpower3

        Click image for larger version

Name:	image.png
Views:	1305
Size:	99.0 KB
ID:	3481048
        it won't work. the device is using the espi bus.

        Comment

        • claudio21s
          Member
          • Nov 2022
          • 28
          • chile

          #404
          Originally posted by rediii

          it won't work. the device is using the espi bus.
          Yes, I tried and it didn't work, thanks anyway

          Comment

          • Halpert
            New Member
            • Oct 2024
            • 3
            • United States

            #405
            Hello, I need help with a T14 Gen1 with a MEC 1663 and NM-931.

            I watched the video but couldn't get the timings from the video. I have tried many many times and have gotten errors but still haven't gotten anything at all. Could you help out with the timings? Or is this impractical? Should I try to desolder the EC and replace it?

            Cheers.

            Comment

            • Andreasbest
              Badcaps Legend
              • Aug 2014
              • 1132
              • Hellas ( Greece )

              #406
              Originally posted by Halpert
              Hello, I need help with a T14 Gen1 with a MEC 1663 and NM-931.

              I watched the video but couldn't get the timings from the video. I have tried many many times and have gotten errors but still haven't gotten anything at all. Could you help out with the timings? Or is this impractical? Should I try to desolder the EC and replace it?

              Cheers.
              In my case ( P52, T480s, T490s ) i found the correct timing at the beginning of Lenovo logo, very short and fast short to ground and all fine.

              Comment

              • Halpert
                New Member
                • Oct 2024
                • 3
                • United States

                #407
                Originally posted by Andreasbest

                In my case ( P52, T480s, T490s ) i found the correct timing at the beginning of Lenovo logo, very short and fast short to ground and all fine.
                What did you use to ground? I'm trying to use a probe connected to a usb drive in the always on port and have gotten some errors, but is there a better way to do this?

                Cheers.

                Comment

                • Andreasbest
                  Badcaps Legend
                  • Aug 2014
                  • 1132
                  • Hellas ( Greece )

                  #408
                  Originally posted by Halpert

                  What did you use to ground? I'm trying to use a probe connected to a usb drive in the always on port and have gotten some errors, but is there a better way to do this?

                  Cheers.
                  I made a simple circuit with a button, usb plug and probe. USB is always connected and probe on pin 4 or 6. Then i try with random button press but i found out that near or at Lenovo logo works.

                  Comment

                  • feherhollo
                    Senior Member
                    • Nov 2019
                    • 110
                    • Hungary

                    #409
                    Still no solution for T14 Gen 3? Based on MEC1723

                    Thanks

                    Comment

                    • Faheem khan
                      New Member
                      • Sep 2023
                      • 2
                      • united arab emirates

                      #410
                      hi good morning
                      i have lenovo yoga 6th gen motherboard part number is nm-d341 i have to remove bios password plz if any one have bypass point in this motherboard thanks

                      Comment

                    • ok escape
                      New Member
                      • Oct 2024
                      • 3
                      • NL

                      #411
                      Originally posted by Usering
                      Share experience
                      1)
                      very Risk method lpc on espi board
                      killed 2 laptop cpu short
                      nm-d362 io mec1503
                      nm-981 io npcx997
                      I would have made a little money, now I would have paid over $500 for the board on aliexpress .

                      2)
                      regarding changing the chip, you must be a professional because the chip is glued from the inside with a black substance that can spoil the welding place and also the source of purchasing the chip.
                      maybe add a 10K resistor on your short loop, that way you limit the current and less likely to damage anything.

                      Comment

                      • ok escape
                        New Member
                        • Oct 2024
                        • 3
                        • NL

                        #412
                        Originally posted by rediii

                        it won't work. the device is using the espi bus.
                        I just started researching this today as I am looking to potentially buy some P1G6, have no schematic and no idea of what's inside but I'm tempted the test.
                        My humble opinion is that this not working has nothing to do with the eSPI itself basically by shorting the LPC or any bus at the time the bootloader tries to read the bios it makes it fail. this is actually patchable via software an I think if any laptop with an EC (even the ones that worked previously) has a updated FW it might not work.
                        This might need some serious reverse engineering, basically plug into the bus, listen and decode. the thing is while the previous versions with a ROM chip were encrypted the communication on the bus is most likely not. it takes time and experience, if someone is willing to collaborate I'm happy to give a hand with the HW side of things

                        Comment

                        • rediii
                          h???, spurrrn
                          • Mar 2018
                          • 485
                          • somewhere in europe

                          #413
                          Originally posted by ok escape

                          I just started researching this today as I am looking to potentially buy some P1G6, have no schematic and no idea of what's inside but I'm tempted the test.
                          My humble opinion is that this not working has nothing to do with the eSPI itself basically by shorting the LPC or any bus at the time the bootloader tries to read the bios it makes it fail. this is actually patchable via software an I think if any laptop with an EC (even the ones that worked previously) has a updated FW it might not work.
                          This might need some serious reverse engineering, basically plug into the bus, listen and decode. the thing is while the previous versions with a ROM chip were encrypted the communication on the bus is most likely not. it takes time and experience, if someone is willing to collaborate I'm happy to give a hand with the HW side of things
                          this could be right. the p1 g6 won't work with the "classic lpc method” either, but nice to hear that you are willing to help.
                          the most elegant method would be to modify the main bios in a way, that the ec chip would erase or reset its eeprom content, so that the mainboard is like factory new. the u1 golden key tool is working with the newer thinkpad generations as well, so you can erase/reset the eeprom flash via initialization with the help of this tool.
                          i tried to modify the main and ec bios for hours (t15 g2i) and end up with nothing. thanks for the input though.
                          and i think you are right, the espi bus is most likely not the culprit, it's the logic design (new EC, EC AND MAIN BIOS + new bus system).

                          Comment

                          • Usering
                            Member
                            • Sep 2024
                            • 43
                            • Germany

                            #414
                            Originally posted by ok escape

                            I just started researching this today as I am looking to potentially buy some P1G6, have no schematic and no idea of what's inside but I'm tempted the test.
                            My humble opinion is that this not working has nothing to do with the eSPI itself basically by shorting the LPC or any bus at the time the bootloader tries to read the bios it makes it fail. this is actually patchable via software an I think if any laptop with an EC (even the ones that worked previously) has a updated FW it might not work.
                            This might need some serious reverse engineering, basically plug into the bus, listen and decode. the thing is while the previous versions with a ROM chip were encrypted the communication on the bus is most likely not. it takes time and experience, if someone is willing to collaborate I'm happy to give a hand with the HW side of things
                            I agree with you, because Victor, the Romanian Allservice team, uses a patch on UEFI to break the security BIOS, the new generation gen 2, gen 3, gen4, patch.

                            Comment

                            • azanwaqas771
                              Member
                              • Feb 2019
                              • 48
                              • Pakistan

                              #415
                              Originally posted by Usering

                              I agree with you, because Victor, the Romanian Allservice team, uses a patch on UEFI to break the security BIOS, the new generation gen 2, gen 3, gen4, patch.
                              no have anyupdate at allservices web site about new model unlocking gen2 gen3 gen 4 with patch

                              Comment

                              • rediii
                                h???, spurrrn
                                • Mar 2018
                                • 485
                                • somewhere in europe

                                #416
                                Originally posted by ok escape

                                I just started researching this today as I am looking to potentially buy some P1G6, have no schematic and no idea of what's inside but I'm tempted the test.
                                My humble opinion is that this not working has nothing to do with the eSPI itself basically by shorting the LPC or any bus at the time the bootloader tries to read the bios it makes it fail. this is actually patchable via software an I think if any laptop with an EC (even the ones that worked previously) has a updated FW it might not work.
                                This might need some serious reverse engineering, basically plug into the bus, listen and decode. the thing is while the previous versions with a ROM chip were encrypted the communication on the bus is most likely not. it takes time and experience, if someone is willing to collaborate I'm happy to give a hand with the HW side of things
                                at least you can use the stock bios to use the machine. with secure boot set off (natively), you are even able to boot the u1 golden key tool. i've done some tests: the eeprom is software locked as soon as you set a svp. in the sixth block (1st line) of the eeprom dump hex code block 00 00 is set to e2 e2. if you don't enter the pw at startup you won't be able to read the full eeprom (error reading code block 6,7) bin AND can't initialize/erase (error writing block 0,1 etc.) it either. it is possible to set the machine type model, but nothing else. this is at least the case for mec1503.

                                Comment

                                • rediii
                                  h???, spurrrn
                                  • Mar 2018
                                  • 485
                                  • somewhere in europe

                                  #417
                                  Originally posted by Usering

                                  I agree with you, because Victor, the Romanian Allservice team, uses a patch on UEFI to break the security BIOS, the new generation gen 2, gen 3, gen4, patch.
                                  wrong

                                  Comment

                                  • Usering
                                    Member
                                    • Sep 2024
                                    • 43
                                    • Germany

                                    #418
                                    Originally posted by rediii

                                    wrong
                                    True, it has a bios patch for the 32mb chip, all models and all generation .
                                    Victor is the only person who was able to unlock the via driver dxe uefi

                                    Comment

                                    • electro01
                                      New Member
                                      • Mar 2018
                                      • 6
                                      • rabat

                                      #419
                                      Hello, could someone help to bypass an L14 GEN 3 AMD?

                                      Comment

                                      • Andreasbest
                                        Badcaps Legend
                                        • Aug 2014
                                        • 1132
                                        • Hellas ( Greece )

                                        #420
                                        Originally posted by Usering

                                        True, it has a bios patch for the 32mb chip, all models and all generation .
                                        Victor is the only person who was able to unlock the via driver dxe uefi
                                        DXE patch worked until Intel 7th gen Lenovo.
                                        Not working on 8th gen and above.

                                        Comment

                                        Related Topics

                                        Collapse

                                        • Document Archive
                                          Lenovo ThinkPad X1 Carbon + ThinkPad USB 3.0 Pro Dock Notebook X Specification for Upgrade or Repair
                                          by Document Archive
                                          This specification for the Lenovo ThinkPad X1 Carbon + ThinkPad USB 3.0 Pro Dock Notebook can be useful for upgrading or repairing a laptop that is not working. As a community we are working through our specifications to add valuable data like the X1 Carbon + ThinkPad USB 3.0 Pro Dock boardview and X1 Carbon + ThinkPad USB 3.0 Pro Dock schematic. Our users have donated over 1 million documents which are being added to the site. This page will be updated soon with additional information. Alternatively you can request additional help from our users directly on the relevant badcaps forum. Please...
                                          09-06-2024, 11:40 AM
                                        • Document Archive
                                          Lenovo ThinkPad X1 Carbon + ThinkPad USB 3.0 Pro Dock Notebook X Specification for Upgrade or Repair
                                          by Document Archive
                                          This specification for the Lenovo ThinkPad X1 Carbon + ThinkPad USB 3.0 Pro Dock Notebook can be useful for upgrading or repairing a laptop that is not working. As a community we are working through our specifications to add valuable data like the X1 Carbon + ThinkPad USB 3.0 Pro Dock boardview and X1 Carbon + ThinkPad USB 3.0 Pro Dock schematic. Our users have donated over 1 million documents which are being added to the site. This page will be updated soon with additional information. Alternatively you can request additional help from our users directly on the relevant badcaps forum. Please...
                                          09-06-2024, 11:40 AM
                                        • Document Archive
                                          Lenovo ThinkPad X1 Carbon + ThinkPad USB 3.0 Pro Dock Notebook X Specification for Upgrade or Repair
                                          by Document Archive
                                          This specification for the Lenovo ThinkPad X1 Carbon + ThinkPad USB 3.0 Pro Dock Notebook can be useful for upgrading or repairing a laptop that is not working. As a community we are working through our specifications to add valuable data like the X1 Carbon + ThinkPad USB 3.0 Pro Dock boardview and X1 Carbon + ThinkPad USB 3.0 Pro Dock schematic. Our users have donated over 1 million documents which are being added to the site. This page will be updated soon with additional information. Alternatively you can request additional help from our users directly on the relevant badcaps forum. Please...
                                          09-06-2024, 11:40 AM
                                        • Document Archive
                                          Lenovo ThinkPad X1 Carbon + ThinkPad USB 3.0 Pro Dock Notebook X Specification for Upgrade or Repair
                                          by Document Archive
                                          This specification for the Lenovo ThinkPad X1 Carbon + ThinkPad USB 3.0 Pro Dock Notebook can be useful for upgrading or repairing a laptop that is not working. As a community we are working through our specifications to add valuable data like the X1 Carbon + ThinkPad USB 3.0 Pro Dock boardview and X1 Carbon + ThinkPad USB 3.0 Pro Dock schematic. Our users have donated over 1 million documents which are being added to the site. This page will be updated soon with additional information. Alternatively you can request additional help from our users directly on the relevant badcaps forum. Please...
                                          09-06-2024, 11:40 AM
                                        • Document Archive
                                          Lenovo ThinkPad X1 Carbon + ThinkPad USB 3.0 Pro Dock Notebook X Specification for Upgrade or Repair
                                          by Document Archive
                                          This specification for the Lenovo ThinkPad X1 Carbon + ThinkPad USB 3.0 Pro Dock Notebook can be useful for upgrading or repairing a laptop that is not working. As a community we are working through our specifications to add valuable data like the X1 Carbon + ThinkPad USB 3.0 Pro Dock boardview and X1 Carbon + ThinkPad USB 3.0 Pro Dock schematic. Our users have donated over 1 million documents which are being added to the site. This page will be updated soon with additional information. Alternatively you can request additional help from our users directly on the relevant badcaps forum. Please...
                                          09-06-2024, 11:40 AM
                                        • Loading...
                                        • No more items.
                                        Working...