Thank you to the guys at HEGE supporting Badcaps [ HEGE ] [ HEGE DEX Chart ]

Announcement

Collapse
No announcement yet.

mec 16xx dump with info block

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Re: mec 16xx dump with info block

    any idea about Lenovo X13 gen 10 jtag pin

    Comment


      Re: mec 16xx dump with info block

      Originally posted by 69d0b913 View Post
      After a lot of persistence I managed to remove the T14 bios password! I believe that few here know how to do it and no one shares it, I understand that certain types of information are not shared and are sold! But I persisted, and I come to inform you that the (Thinkpad T14 1st 20S1) was unlocked by an RT809H the only programmer I have, as I don't have access to a vertyanov. Here are the photos in the attachment, now I just need to invert the bios information, but I had taken a photo before.

      Please how did manage to solve the T14 problem

      Comment


        I have a Lenovo X13 Gen 1 (i5 10th gen) with Supervisor Password and a Mec1663 that I was able to read it with my SVOD3 and I followed the usual steps to unlock it (I have already done it on other models) but this time the password does not remove, every time he comes back
        MB : NM-C891 Rev 1.0
        SN: PC-1Y3HPX

        Comment


          Hello,

          I finally managed to unlock my T590 using the JTAC method with SVOD4. Unfortunately I did not choose eeprom but main. So now I have to add the dmi information.
          I have now tried various maintenace tools, but it keeps giving me the error: "error: drive not found to format". What can I do? And what dmi information do I have to enter, just the serial number?

          Thank you

          Comment


            I have read the EEPROM area of MEC1663.
            Where and how should I edit the BIN file to remove only the BIOS password?"
            Thank you in advance.

            X1 Carbon Gen8 20UA
            Attached Files

            Comment


            Originally posted by monolith-2001 View Post
            I have read the EEPROM area of MEC1663.
            Where and how should I edit the BIN file to remove only the BIOS password?"
            Thank you in advance.

            X1 Carbon Gen8 20UA
            try
            Attached Files

            Comment


            • monolith-2001
              monolith-2001 commented
              Editing a comment
              I apologize for forgetting to provide the serial number.
              The serial number is PF-2BA1AW.

              Thank you for creating the 00.bin and FF.bin files.
              I will report the results at a later date.

            Mec16 translated
            Click image for larger version  Name:	386453902_1041202147221888_1671781784116666234_n.jpg Views:	5 Size:	746.3 KB ID:	3162076
            Last edited by Maxpower3; 12-13-2023, 11:29 AM.

            Comment


            • monolith-2001
              monolith-2001 commented
              Editing a comment
              Thanks to your support, the unlocking was successful.
              I tried using FF.bin, and I was able to erase only the password without losing information such as the model number.
              I truly appreciate your assistance.
              ***Although you kindly created 00.bin for me, I did not try it.

              By the way, I'm amazed that you can translate Mec16—it's truly a divine skill.

            Originally posted by Maxpower3 View Post
            Mec16 translated
            Click image for larger version Name:	386453902_1041202147221888_1671781784116666234_n.jpg Views:	5 Size:	746.3 KB ID:	3162076
            Amazing, how you pls translate this hex?

            Comment


            • AAAC
              AAAC commented
              Editing a comment
              Just XOR the original file with FF(h), use an Hex editor that perform that operation.
              What's the value that repeats most? It's FF, so that's the value we use for the XOR operation.

            Attempting to read MEC1663 blocks JTAG and prevents the read operation.
            s there a way to unblock JTAG and continue reading?

            Programmer:SUCCESSOR BASE2
            X1 Carbon Gen8
            20UA
            PF-1SJ5XP
            Click image for larger version  Name:	MEC1663.jpg Views:	0 Size:	52.1 KB ID:	3170421
            Last edited by monolith-2001; 12-30-2023, 09:32 AM.

            Comment


              When tested with RT809H, all read data was zero.
              What is the difference between MEC1663 devices that are unlocked and those that are locked, even if they are the same model?

              Comment


                Hello everybody, i successfully flashed the mec1663 chip of a lenovo thinkpad x390 (20Q1 Model) after the notebook wasn't turning on at all.
                So far all good but i realised that the product number is missing(is showing invalid).
                i was able to get bios DMI information back via Lenovo Maintenance Utility v1.10 . However product number on windows or Lenovo Vantage is invalid.
                Had someone the same problem and how can i resolve it ?
                Thank you.






                Attached Files

                Comment


                  i need the rom file for this mec 1663 nm-c881

                  Comment


                  Hey there,

                  While attempting to relocate the 10k resistor in order to enable jtag, I lost the resisor.
                  Does anyone know the specifications of the resistor so that I can order a new one?
                  Also do I have any other options instead of adding the resistor?
                  I have read somewhere that you can enable jtag by adding a certain amount of voltage so a specific part of the board.
                  Any ideas about how to do this?

                  Many thanks in advance, PT.

                  Comment


                    RT809F The process is complete. This is how it is done.

                    Comment


                      Originally posted by volinakis View Post
                      Re: mec 16xx dump with info block

                      I want to share my 1st experience with MEC1663 from Yoga X1 4th gen.

                      Many thanks to AAAC, RethoricalCheese, EvilBzyk, their shared knowledge helped me a lot.

                      1. Connected jtag pins as in picture, no pull up resistor needed. Moved 10k resistor from pull-down to pull-up. Chose MEC1633#ISP. power on motherboard.
                      2. Got message "Chip may be damaged or encrypted, the data is not valid" I did try other options, MEC1653#ISP, MEC1633_256k, same result.
                      3. I hit "Erase" and laptop stops working, no power on/charge led lit.
                      4. I took EC file from bios update and trim 32bytes, the same version it was in bios (I took a photo of info in bios before pulling off the motherboard) wrote the file into EC then power off motherboard. Waited few minutes an power on motherboard, power on/charge led lit. Moved the 10k resistor to pull down.
                      5. schematics IS WRONG! TP1 IS REVERSED WITH TP5.
                      I did it your way. For Thinkpad X1 Carbon Gen 7th "FX90 NM-B861 Rev: 1.0". I can read the EC dump but it's only 192 Kb
                      Unluckily, I blew out this resistor. I re-soldered it but the laptop couldn't boot up.
                      Does anyone know the value of this resistor?
                      Thank you
                      Attached Files

                      Comment


                        R86151 1/20W_0_5%_0201 schematic and boardview:
                        https://www.badcaps.net/forum/troubl...32#post1680232

                        Chose MEC1633_256k if you have RT809H
                        ----------------------------------------------------------------------------------------------------------------------------------------------------------------------
                        Due to a lack of donations, server free space at a critical level, and possible closure of Bios Requests
                        all donations are welcome,
                        see the donate button at the bottom of the page, or
                        >>>>>
                        click on this link to donate via PayPal. <<<<<
                        Every donation made will go towards server fees and maintenance costs.
                        ----------------------------------------------------------------------------------------------------------------------------------------------------------------------

                        Comment


                          Originally posted by volinakis View Post
                          R86151 1/20W_0_5%_0201 schematic and boardview:
                          https://www.badcaps.net/forum/troubl...32#post1680232

                          Chose MEC1633_256k if you have RT809H
                          Thank you so much. I have successfully removed the password

                          Comment


                            Sharing my experience. I have two t490 that need svp removal. I have the rt809f programmer.

                            the first one did not give me problems. Read erase write and svp is gone.

                            however, the second one I cannot even recognize the mec chip. The programmer reported 0xCDCDCDCD as the mec chip id. This is the same as if the chip is disconnected from the programmer (i actually tried it with out any pins attached to the programmer, it also reported this chip id).

                            I wonder what could be the cause of this discrepancy in the chips response. The one without problem has it's BIOS dated back to 2021 while the one giving me problems has BIOS dating back to 2022 (so it's newer).

                            anyone can help? Thanks.

                            Comment


                              I have successfully removed EC password. The system has received complete information. But when starting the laptop there is still message 2202: Product name is invalid.
                              I used the Gold key to re-enter the information but the problem was not resolved.
                              Has anyone solved this problem yet?
                              Thanks,
                              Attached Files

                              Comment


                                Originally posted by vuquanghoanh View Post
                                I have successfully removed EC password. The system has received complete information. But when starting the laptop there is still message 2202: Product name is invalid.
                                I used the Gold key to re-enter the information but the problem was not resolved.
                                Has anyone solved this problem yet?
                                Thanks,
                                did you update the product brand to thinkpad T**?

                                Comment

                                Working...
                                X