Lenovo Thinkpad Ec Pwd Bypass

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • rediii
    h???, spurrrn
    • Mar 2018
    • 485
    • somewhere in europe

    #481
    Originally posted by Usering

    The old nvram patch method no longer works on the new updated generation, I said it can be erased and reset via new patch, because the code is also saved on npcx998.
    you can reset the password via editing the main bios nvram region activating mpm. there are alot of threads on this forum. pls lets concentrate on thinkpads only here.

    Comment

    • Usering
      Member
      • Sep 2024
      • 43
      • Germany

      #482
      Originally posted by rediii

      you can reset the password via editing the main bios nvram region activating mpm. there are alot of threads on this forum. pls lets concentrate on thinkpads only here.
      Yes, just a question and a note, since the new generation of HP G9 G10 uses main BIOS to crack the BIOS on npcx998, so we have hope for a way one day on thinkpad, regarding the link you shared with me yesterday, there is a person with us in the forum and in the current topic, who succeeded in unlocking the t14s gen 2, can he share his ideas with us? Thanks.
      Attached Files

      Comment

      • Usering
        Member
        • Sep 2024
        • 43
        • Germany

        #483
        https://www.badcaps.net/forum/troubl...nkpad-t14-gen2

        Comment

        • rediii
          h???, spurrrn
          • Mar 2018
          • 485
          • somewhere in europe

          #484
          Originally posted by Usering
          Yes, just a question and a note, since the new generation of HP G9 G10 uses main BIOS to crack the BIOS on npcx998, so we have hope for a way one day on thinkpad, regarding the link you shared with me yesterday, there is a person with us in the forum and in the current topic, who succeeded in unlocking the t14s gen 2, can he share his ideas with us? Thanks.
          1. hp architecture =/= lenovo architecture (even if the sio is the same)
          2. no, he won't tell us even if he managed to unlock it

          wait 2.: it was/is mmccomputer, who wrote this in the thread (https://www.badcaps.net/forum/troubl...nkpad-t14-gen2). this guy just wrote yesterday (https://www.badcaps.net/forum/troubl...12#post3494795), that he shipped these devices to algeria for unlocking service. sooo...
          Last edited by rediii; 10-30-2024, 02:08 PM.

          Comment

          • lktech
            Member
            • Jan 2021
            • 39
            • algeria

            #485
            About some motherboards have mec15xx and npcx9xx there is a solution here in Algeria without hardware or software i confirm

            Comment

            • mmccomputer
              Senior Member
              • Jan 2018
              • 71
              • France

              #486
              to make things clear, the solution I talked about in the thread ''Unlock SVPLenovo Thinkpad T14 Gen2"
              is different from the solution of the guy from Algeria
              the first is functional on certain Mec1503 (and I cannot share it because I do not have authorization of its owner and it requires a hardware modification)
              the second is functional and concerns mec15xx mec17xx (but not all) and some npcx9xx and it cost me around 100 euros (transport and service)
              ​

              Comment

              • SMDFlea
                Super Moderator
                • Jan 2018
                • 20272
                • UK

                #487
                I`ll just remind everyone of the rules https://www.badcaps.net/forum/troubl...before-posting
                All donations to badcaps are welcome, click on this link to donate. Thanks to all supporters

                Comment

                • Mahesa09
                  Senior Member
                  • Nov 2021
                  • 63
                  • jakarta

                  #488
                  hy brother, Can the L490 password be bypassed via EC? IT8227E-256-AX_LQFP128_14X14

                  Comment

                  • Zombi3002
                    New Member
                    • Oct 2024
                    • 3
                    • Germany

                    #489
                    I want to try this method on a thinkpad T480.
                    J5 is available for this, should I put a resistor in series to limit current when shorting to ground?

                    Comment

                    • anhbanxoi
                      Senior Member
                      • Sep 2021
                      • 168
                      • VN

                      #490
                      Originally posted by Zombi3002
                      I want to try this method on a thinkpad T480.
                      J5 is available for this, should I put a resistor in series to limit current when shorting to ground?
                      No need, just short the LPC_AD0:3 to ground.

                      Comment

                      • Zombi3002
                        New Member
                        • Oct 2024
                        • 3
                        • Germany

                        #491
                        Originally posted by anhbanxoi

                        No need, just short the LPC_AD0:3 to ground.
                        Alright, thank you for the fast response.

                        Comment

                        • thinkpadg6
                          New Member
                          • Nov 2024
                          • 4
                          • Canada

                          #492
                          I have a t14s gen mec 1663. It has a supervisor password. Pressing just enter doesnt let me in view bios in general user. Instead it says i have 2 tries left. I have the jumper installed as per the image provided. However pressing the switch during boot doesnt get me into bios. After several tries it go to a screen saying bios self heal process. Then i try again.

                          any help appreciated.
                          Last edited by thinkpadg6; 11-08-2024, 10:48 AM.

                          Comment

                          • thinkpadg6
                            New Member
                            • Nov 2024
                            • 4
                            • Canada

                            #493
                            Originally posted by thinkpadg6
                            I have a t14s gen mec 1663. It has a supervisor password. Pressing just enter doesnt let me in view bios in general user. Instead it says i have 2 tries left. I have the jumper installed as per the image provided. However pressing the switch during boot doesnt get me into bios. After several tries it go to a screen saying bios self heal process. Then i try again.

                            any help appreciated.
                            Actually it must be the auora of this group. Since I posted next try worked.

                            Now i have invalid machine, type serial and board serial.

                            Any idea how to fix that.

                            Comment

                            • rediii
                              h???, spurrrn
                              • Mar 2018
                              • 485
                              • somewhere in europe

                              #494
                              Originally posted by thinkpadg6

                              Actually it must be the auora of this group. Since I posted next try worked.

                              Now i have invalid machine, type serial and board serial.

                              Any idea how to fix that.
                              https://www.badcaps.net/forum/troubl...r-bootable-usb

                              Comment

                              • thinkpadg6
                                New Member
                                • Nov 2024
                                • 4
                                • Canada

                                #495
                                Thank you. Will check there.

                                Comment

                                • Zombi3002
                                  New Member
                                  • Oct 2024
                                  • 3
                                  • Germany

                                  #496
                                  Originally posted by Maxpower3
                                  Hello everyone.

                                  Here is the bypass solution for several Lenovo ECs.
                                  This has worked on many ECs.
                                  Only works if password is contained in EC

                                  I succeeded on many models
                                  https://www.badcaps.net/forum/troubl...86#post3217086
                                  https://www.youtube.com/channel/UCeF...t_adKcguvynjeA

                                  I shorten the LPC bus, with the LAD0:3 and Gnd.

                                  you can use the dedicated ports where you connect directly to the track.
                                  (Be careful, resistors may be missing on the path)
                                  look at the diagrams

                                  example x390 npce388


                                  The communication being cut off, corrupted,
                                  it cannot read information contained in EC and therefore continues.
                                  then simply clean by rewriting after access.

                                  Don't save with F10, just clean Pwd with enter twice.
                                  If the serial, uuid etc. information is corrupted, you are saving the wrong information
                                  Like the old way with sda/scl.

                                  The method is delicate, there is always a risk of bricking or try failed.
                                  ITE and Nuvoton is easy, Mec16 is more delicate (many try necessary).
                                  Timing is important
                                  watch videos to understand

                                  works on Mec1633 / Mec1653 / Mec1663 / IT8186VG / IT5261VG / NPCE68B / NCPE288/388 and surely others

                                  but my tests failed with the Mec1503
                                  The LPC bus is no longer used, it has been replaced by eSPI

                                  Attached some connection diagrams for tested models

                                  Edit
                                  -----------------------
                                  EC PWD eeprom location

                                  NCPE68B
                                  Dmi start from 0x5C120 and 0x5D120
                                  Pwd 0x5C420 - 0x5C56F and 0x5D420 - 0x5D56F replace with 00

                                  NCPE288/388
                                  Dmi start from 0x30000
                                  Pwd
                                  0x36000 - 0x3604F
                                  0x36080 - 0x360CF
                                  0x36100 - 0x3614F
                                  0x36180 - 0x361CF
                                  0x36200 - 0x3624F
                                  0x36280 - 0x362CF
                                  0x36300 - 0x3634F
                                  0x36380 - 0x363CF
                                  0x36400 - 0x3644F
                                  0x36480 - 0x364CF
                                  0x36500 - 0x3654F
                                  0x36580 - 0x365CF
                                  0x36600 - 0x3664F
                                  0x36680 - 0x366CF
                                  replace with 00

                                  Mec1663 Dmi start from 0x00
                                  Pwd 0x300 - 0x34F replace with FF

                                  search for this shape
                                  Click image for larger version Name:	ec pwd.png Views:	0 Size:	310.0 KB ID:	3237274




                                  Another t480 unlocked with this method, it took me like 4 attempts.

                                  Also, I used some electric tape to isolate the other jumper contacts at J5. This helped me quite a bit with aiming (the contacts are kinda small) and timing.
                                  This t480 can now be turned into the little beast that is supposed to be. Without this method and this manual this wouldn't have been possible, so thank you and everyone else very much for making this possible!

                                  Comment

                                  • cgtec
                                    Senior Member
                                    • Feb 2014
                                    • 54
                                    • algeria

                                    #497
                                    Originally posted by Usering
                                    Has anyone tried the segger programmer before?
                                    Is it true that Segger programmer can program MEC1503, MEC1723 chip?
                                    thanks
                                    segger programing CHIP USE SPI

                                    Comment

                                    • Andreasbest
                                      Badcaps Legend
                                      • Aug 2014
                                      • 1132
                                      • Hellas ( Greece )

                                      #498
                                      [QUOTE=cgtec;n3506745]

                                      segger programing CHIP USE SPI [/QUOT

                                      Segger claims all their flashers, except the Segger one, supports Mec1503
                                      Not sure if i miss something here.
                                      https://www.segger.com/supported-dev...rochip/mec15xx

                                      Attached Files

                                      Comment

                                      • Sr_Osorio
                                        Frying chicken
                                        • Oct 2024
                                        • 2
                                        • Brazil

                                        #499
                                        Hello, could someone help me with bypass to my Thinkpad L390 Model: 20NSS2GF00 - NPCE288GA0DX?

                                        Click image for larger version

Name:	PHOTO-2024-11-17-00-14-20.jpg
Views:	721
Size:	800.7 KB
ID:	3508901

                                        Comment

                                        • shiyab
                                          Badcaps Legend
                                          • Sep 2023
                                          • 1213
                                          • india

                                          #500
                                          Originally posted by Sr_Osorio
                                          Hello, could someone help me with bypass to my Thinkpad L390 Model: 20NSS2GF00 - NPCE288GA0DX?

                                          Click image for larger version

Name:	PHOTO-2024-11-17-00-14-20.jpg
Views:	721
Size:	800.7 KB
ID:	3508901
                                          post ec bios and snid

                                          Comment

                                          Working...