Originally posted by Usering
View Post
Announcement
Collapse
No announcement yet.
Lenovo Thinkpad Ec Pwd Bypass
Collapse
X
-
Originally posted by rediii View Post
you can reset the password via editing the main bios nvram region activating mpm. there are alot of threads on this forum. pls lets concentrate on thinkpads only here.
Comment
-
Originally posted by Usering View PostYes, just a question and a note, since the new generation of HP G9 G10 uses main BIOS to crack the BIOS on npcx998, so we have hope for a way one day on thinkpad, regarding the link you shared with me yesterday, there is a person with us in the forum and in the current topic, who succeeded in unlocking the t14s gen 2, can he share his ideas with us? Thanks.
2. no, he won't tell us even if he managed to unlock it
wait 2.: it was/is mmccomputer, who wrote this in the thread (https://www.badcaps.net/forum/troubl...nkpad-t14-gen2). this guy just wrote yesterday (https://www.badcaps.net/forum/troubl...12#post3494795), that he shipped these devices to algeria for unlocking service. sooo...Last edited by rediii; 10-30-2024, 02:08 PM.
Comment
-
to make things clear, the solution I talked about in the thread ''Unlock SVPLenovo Thinkpad T14 Gen2"
is different from the solution of the guy from Algeria
the first is functional on certain Mec1503 (and I cannot share it because I do not have authorization of its owner and it requires a hardware modification)
the second is functional and concerns mec15xx mec17xx (but not all) and some npcx9xx and it cost me around 100 euros (transport and service)
Comment
-
I`ll just remind everyone of the rules https://www.badcaps.net/forum/troubl...before-posting
Comment
-
I have a t14s gen mec 1663. It has a supervisor password. Pressing just enter doesnt let me in view bios in general user. Instead it says i have 2 tries left. I have the jumper installed as per the image provided. However pressing the switch during boot doesnt get me into bios. After several tries it go to a screen saying bios self heal process. Then i try again.
any help appreciated.3 PhotosLast edited by thinkpadg6; 11-08-2024, 10:48 AM.
Comment
-
Originally posted by thinkpadg6 View PostI have a t14s gen mec 1663. It has a supervisor password. Pressing just enter doesnt let me in view bios in general user. Instead it says i have 2 tries left. I have the jumper installed as per the image provided. However pressing the switch during boot doesnt get me into bios. After several tries it go to a screen saying bios self heal process. Then i try again.
any help appreciated.
Now i have invalid machine, type serial and board serial.
Any idea how to fix that.
1 Photo
Comment
-
Originally posted by thinkpadg6 View Post
Actually it must be the auora of this group. Since I posted next try worked.
Now i have invalid machine, type serial and board serial.
Any idea how to fix that.
Comment
-
-
Originally posted by Maxpower3 View PostHello everyone.
Here is the bypass solution for several Lenovo ECs.
This has worked on many ECs.
Only works if password is contained in EC
I succeeded on many models
https://www.badcaps.net/forum/troubl...86#post3217086
https://www.youtube.com/channel/UCeF...t_adKcguvynjeA
I shorten the LPC bus, with the LAD0:3 and Gnd.
you can use the dedicated ports where you connect directly to the track.
(Be careful, resistors may be missing on the path)
look at the diagrams
example x390 npce388
The communication being cut off, corrupted,
it cannot read information contained in EC and therefore continues.
then simply clean by rewriting after access.
Don't save with F10, just clean Pwd with enter twice.
If the serial, uuid etc. information is corrupted, you are saving the wrong information
Like the old way with sda/scl.
The method is delicate, there is always a risk of bricking or try failed.
ITE and Nuvoton is easy, Mec16 is more delicate (many try necessary).
Timing is important
watch videos to understand
works on Mec1633 / Mec1653 / Mec1663 / IT8186VG / IT5261VG / NPCE68B / NCPE288/388 and surely others
but my tests failed with the Mec1503
The LPC bus is no longer used, it has been replaced by eSPI
Attached some connection diagrams for tested models
Edit
-----------------------
EC PWD eeprom location
NCPE68B
Dmi start from 0x5C120 and 0x5D120
Pwd 0x5C420 - 0x5C56F and 0x5D420 - 0x5D56F replace with 00
NCPE288/388
Dmi start from 0x30000
Pwd
0x36000 - 0x3604F
0x36080 - 0x360CF
0x36100 - 0x3614F
0x36180 - 0x361CF
0x36200 - 0x3624F
0x36280 - 0x362CF
0x36300 - 0x3634F
0x36380 - 0x363CF
0x36400 - 0x3644F
0x36480 - 0x364CF
0x36500 - 0x3654F
0x36580 - 0x365CF
0x36600 - 0x3664F
0x36680 - 0x366CF
replace with 00
Mec1663 Dmi start from 0x00
Pwd 0x300 - 0x34F replace with FF
search for this shape
Another t480 unlocked with this method, it took me like 4 attempts.
Also, I used some electric tape to isolate the other jumper contacts at J5. This helped me quite a bit with aiming (the contacts are kinda small) and timing.
This t480 can now be turned into the little beast that is supposed to be. Without this method and this manual this wouldn't have been possible, so thank you and everyone else very much for making this possible!
Comment
-
[QUOTE=cgtec;n3506745]
segger programing CHIP USE SPI [/QUOT
Segger claims all their flashers, except the Segger one, supports Mec1503
Not sure if i miss something here.
https://www.segger.com/supported-dev...rochip/mec15xx
Comment
Comment