Announcement

Collapse
No announcement yet.

Lenovo Thinkpad Ec Pwd Bypass

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Originally posted by Usering View Post

    The old nvram patch method no longer works on the new updated generation, I said it can be erased and reset via new patch, because the code is also saved on npcx998.
    you can reset the password via editing the main bios nvram region activating mpm. there are alot of threads on this forum. pls lets concentrate on thinkpads only here.

    Comment


      Originally posted by rediii View Post

      you can reset the password via editing the main bios nvram region activating mpm. there are alot of threads on this forum. pls lets concentrate on thinkpads only here.
      Yes, just a question and a note, since the new generation of HP G9 G10 uses main BIOS to crack the BIOS on npcx998, so we have hope for a way one day on thinkpad, regarding the link you shared with me yesterday, there is a person with us in the forum and in the current topic, who succeeded in unlocking the t14s gen 2, can he share his ideas with us? Thanks.
      Attached Files

      Comment


        https://www.badcaps.net/forum/troubl...nkpad-t14-gen2

        Comment


          Originally posted by Usering View Post
          Yes, just a question and a note, since the new generation of HP G9 G10 uses main BIOS to crack the BIOS on npcx998, so we have hope for a way one day on thinkpad, regarding the link you shared with me yesterday, there is a person with us in the forum and in the current topic, who succeeded in unlocking the t14s gen 2, can he share his ideas with us? Thanks.
          1. hp architecture =/= lenovo architecture (even if the sio is the same)
          2. no, he won't tell us even if he managed to unlock it

          wait 2.: it was/is mmccomputer, who wrote this in the thread (https://www.badcaps.net/forum/troubl...nkpad-t14-gen2). this guy just wrote yesterday (https://www.badcaps.net/forum/troubl...12#post3494795), that he shipped these devices to algeria for unlocking service. sooo...
          Last edited by rediii; 10-30-2024, 02:08 PM.

          Comment


            About some motherboards have mec15xx and npcx9xx there is a solution here in Algeria without hardware or software i confirm

            Comment


              to make things clear, the solution I talked about in the thread ''Unlock SVPLenovo Thinkpad T14 Gen2"
              is different from the solution of the guy from Algeria
              the first is functional on certain Mec1503 (and I cannot share it because I do not have authorization of its owner and it requires a hardware modification)
              the second is functional and concerns mec15xx mec17xx (but not all) and some npcx9xx and it cost me around 100 euros (transport and service)

              Comment


                I`ll just remind everyone of the rules https://www.badcaps.net/forum/troubl...before-posting
                All donations to badcaps are welcome, click on this link to donate. Thanks to all supporters

                Comment


                  hy brother, Can the L490 password be bypassed via EC? IT8227E-256-AX_LQFP128_14X14

                  Comment


                    I want to try this method on a thinkpad T480.
                    J5 is available for this, should I put a resistor in series to limit current when shorting to ground?

                    Comment


                      Originally posted by Zombi3002 View Post
                      I want to try this method on a thinkpad T480.
                      J5 is available for this, should I put a resistor in series to limit current when shorting to ground?
                      No need, just short the LPC_AD0:3 to ground.

                      Comment


                        Originally posted by anhbanxoi View Post

                        No need, just short the LPC_AD0:3 to ground.
                        Alright, thank you for the fast response.

                        Comment


                          I have a t14s gen mec 1663. It has a supervisor password. Pressing just enter doesnt let me in view bios in general user. Instead it says i have 2 tries left. I have the jumper installed as per the image provided. However pressing the switch during boot doesnt get me into bios. After several tries it go to a screen saying bios self heal process. Then i try again.

                          any help appreciated.
                          Last edited by thinkpadg6; 11-08-2024, 10:48 AM.

                          Comment


                            Originally posted by thinkpadg6 View Post
                            I have a t14s gen mec 1663. It has a supervisor password. Pressing just enter doesnt let me in view bios in general user. Instead it says i have 2 tries left. I have the jumper installed as per the image provided. However pressing the switch during boot doesnt get me into bios. After several tries it go to a screen saying bios self heal process. Then i try again.

                            any help appreciated.
                            Actually it must be the auora of this group. Since I posted next try worked.

                            Now i have invalid machine, type serial and board serial.

                            Any idea how to fix that.

                            Comment


                              Originally posted by thinkpadg6 View Post

                              Actually it must be the auora of this group. Since I posted next try worked.

                              Now i have invalid machine, type serial and board serial.

                              Any idea how to fix that.
                              https://www.badcaps.net/forum/troubl...r-bootable-usb

                              Comment


                                Thank you. Will check there.

                                Comment


                                  Originally posted by Maxpower3 View Post
                                  Hello everyone.

                                  Here is the bypass solution for several Lenovo ECs.
                                  This has worked on many ECs.
                                  Only works if password is contained in EC

                                  I succeeded on many models
                                  https://www.badcaps.net/forum/troubl...86#post3217086
                                  https://www.youtube.com/channel/UCeF...t_adKcguvynjeA

                                  I shorten the LPC bus, with the LAD0:3 and Gnd.

                                  you can use the dedicated ports where you connect directly to the track.
                                  (Be careful, resistors may be missing on the path)
                                  look at the diagrams

                                  example x390 npce388


                                  The communication being cut off, corrupted,
                                  it cannot read information contained in EC and therefore continues.
                                  then simply clean by rewriting after access.

                                  Don't save with F10, just clean Pwd with enter twice.
                                  If the serial, uuid etc. information is corrupted, you are saving the wrong information
                                  Like the old way with sda/scl.

                                  The method is delicate, there is always a risk of bricking or try failed.
                                  ITE and Nuvoton is easy, Mec16 is more delicate (many try necessary).
                                  Timing is important
                                  watch videos to understand

                                  works on Mec1633 / Mec1653 / Mec1663 / IT8186VG / IT5261VG / NPCE68B / NCPE288/388 and surely others

                                  but my tests failed with the Mec1503
                                  The LPC bus is no longer used, it has been replaced by eSPI

                                  Attached some connection diagrams for tested models

                                  Edit
                                  -----------------------
                                  EC PWD eeprom location

                                  NCPE68B
                                  Dmi start from 0x5C120 and 0x5D120
                                  Pwd 0x5C420 - 0x5C56F and 0x5D420 - 0x5D56F replace with 00

                                  NCPE288/388
                                  Dmi start from 0x30000
                                  Pwd
                                  0x36000 - 0x3604F
                                  0x36080 - 0x360CF
                                  0x36100 - 0x3614F
                                  0x36180 - 0x361CF
                                  0x36200 - 0x3624F
                                  0x36280 - 0x362CF
                                  0x36300 - 0x3634F
                                  0x36380 - 0x363CF
                                  0x36400 - 0x3644F
                                  0x36480 - 0x364CF
                                  0x36500 - 0x3654F
                                  0x36580 - 0x365CF
                                  0x36600 - 0x3664F
                                  0x36680 - 0x366CF
                                  replace with 00

                                  Mec1663 Dmi start from 0x00
                                  Pwd 0x300 - 0x34F replace with FF

                                  search for this shape
                                  Click image for larger version Name:	ec pwd.png Views:	0 Size:	310.0 KB ID:	3237274




                                  Another t480 unlocked with this method, it took me like 4 attempts.

                                  Also, I used some electric tape to isolate the other jumper contacts at J5. This helped me quite a bit with aiming (the contacts are kinda small) and timing.
                                  This t480 can now be turned into the little beast that is supposed to be. Without this method and this manual this wouldn't have been possible, so thank you and everyone else very much for making this possible!

                                  Comment


                                    Originally posted by Usering View Post
                                    Has anyone tried the segger programmer before?
                                    Is it true that Segger programmer can program MEC1503, MEC1723 chip?
                                    thanks
                                    segger programing CHIP USE SPI

                                    Comment


                                      [QUOTE=cgtec;n3506745]

                                      segger programing CHIP USE SPI [/QUOT

                                      Segger claims all their flashers, except the Segger one, supports Mec1503
                                      Not sure if i miss something here.
                                      https://www.segger.com/supported-dev...rochip/mec15xx

                                      Attached Files

                                      Comment


                                        Hello, could someone help me with bypass to my Thinkpad L390 Model: 20NSS2GF00 - NPCE288GA0DX?

                                        Click image for larger version

Name:	PHOTO-2024-11-17-00-14-20.jpg
Views:	536
Size:	800.7 KB
ID:	3508901

                                        Comment


                                          Originally posted by Sr_Osorio View Post
                                          Hello, could someone help me with bypass to my Thinkpad L390 Model: 20NSS2GF00 - NPCE288GA0DX?

                                          Click image for larger version

Name:	PHOTO-2024-11-17-00-14-20.jpg
Views:	536
Size:	800.7 KB
ID:	3508901
                                          post ec bios and snid

                                          Comment

                                          Working...
                                          X