ThinkPad T14 Supervisor password

Collapse
X
 
  • Time
  • Show
Clear All
new posts

  • simkard
    replied
    Re: ThinkPad T14 Supervisor password

    Hello everyone,

    Any update on how to remove supervisor password in EC / ITE ?
    Pretty sure it's just a procedure similar to MacBooks with replacing "FF" to some region in the dump.

    Thanks !

    Leave a comment:


  • datodati962@gmail.com
    replied
    Re: ThinkPad T14 Supervisor password

    Originally posted by echow2001
    I've got the ryzen/AMD model of t14 gen 1 (board number NM-C801) on the way and apparently the pw also stored in EC ITE8300 and there's no JTAG connector. Can't find too much info on this chip online but RT809H seems to support programming it in circuit.

    http://www.ifix.net.cn/thread-56902-1-1.html has some stuff on pinout

    found this similar p/n online with more info IT8320

    chromium OS source: https://chromium.googlesource.com/ch..._chip_it8320.h
    https://chromium.googlesource.com/ch...il/iteflash.md

    https://www.ite.com.tw/en/product/view?mid=96
    Can you share more information about t14 Gen1 the way correct how to make remove supervisor password and how to read with rt809h,if is possible to be more specific,thanks!

    Leave a comment:


  • onizzbox
    replied
    Re: ThinkPad T14 Supervisor password

    Originally posted by am123321
    I am your companion in misfortune. Help me, please.
    @am123321
    Not being money or solving the war in Ukraine, we can try to help them.

    Leave a comment:


  • am123321
    replied
    Re: ThinkPad T14 Supervisor password

    I am your companion in misfortune. Help me, please.
    Last edited by SMDFlea; 03-29-2022, 10:44 AM.

    Leave a comment:


  • SMDFlea
    replied
    Re: ThinkPad T14 Supervisor password

    Originally posted by Verlengsnoer
    Can someone unlock my t14?
    i tryed the autopatcher but keeps flying away, and dont get any patched file,

    hope someone can help
    Read through some of the previous posts, only possible via JTAG ,as far as i know.

    Leave a comment:


  • Verlengsnoer
    replied
    Re: ThinkPad T14 Supervisor password

    Can someone unlock my t14?
    i tryed the autopatcher but keeps flying away, and dont get any patched file,

    hope someone can help
    Attached Files

    Leave a comment:


  • b4rdock
    replied
    Re: ThinkPad T14 Supervisor password

    Originally posted by 69d0b913
    After a lot of persistence I was able to remove the bios password from T14! I believe that few here know how to do it and no one shares it, I understand that certain types of information are not shared and are sold! But I persistently come to inform you that the (Thinkpad T14 1st 20S1) was unlocked by an RT809H the only programmer I have. Here are photos in the attachment, now all that remains is to reverse the bios information, but I had taken a photo first of all.

    after read mec , how you unlock the bin file ?

    regards

    Leave a comment:


  • andrew25
    replied
    Re: ThinkPad T14 Supervisor password

    Originally posted by 69d0b913
    what would be a "prom dmi utility" the EC has already been extracted and edited from the bios downloaded from the site.
    can you share me the ec file please... its urgent

    Leave a comment:


  • echow2001
    replied
    Re: ThinkPad T14 Supervisor password

    Originally posted by echow2001
    no JTAG connector
    looks like this IC is programmed by parallel port interface rather than jtag, too many pin to practically solder, best to have breakout on keyboard zif

    from datasheet of similar ITE embedded controller:
    7.18.3.2 In-System Programming Operation
    In-system programming takes place when VSTBY is supplied (other power is don’t-care) and both EC chip and
    the flash are soldered on PCB. Parallel port interface occupies the same interface pins as KBS to use the
    existing KBS connector.
    IT8511 enters in-system programming mode if it detects parallel port signals when VSTBY power on or
    hardware strap pin PPEN is pulled high. It can be disabled by OVRPPK/OVRPPEN bit in the KSICTRLR
    register
    If Parallel Port cable is detected by internal hardware strap, the following functions will be disabled.
    1. ROM Address Match Interrupt
    2. Internal/External Watchdog
    will also have to see if the IT8300 uses internal or external flash for EC, if its external itll be ez just dump it with any 25xx flash tool like tl866ii, ch341a, rt809x etc etc
    Last edited by echow2001; 03-01-2022, 08:48 PM.

    Leave a comment:


  • echow2001
    replied
    Re: ThinkPad T14 Supervisor password

    I've got the ryzen/AMD model of t14 gen 1 (board number NM-C801) on the way and apparently the pw also stored in EC ITE8300 and there's no JTAG connector. Can't find too much info on this chip online but RT809H seems to support programming it in circuit.

    http://www.ifix.net.cn/thread-56902-1-1.html has some stuff on pinout

    found this similar p/n online with more info IT8320

    chromium OS source: https://chromium.googlesource.com/ch..._chip_it8320.h
    https://chromium.googlesource.com/ch...il/iteflash.md

    https://www.ite.com.tw/en/product/view?mid=96
    Last edited by echow2001; 03-01-2022, 08:23 PM. Reason: add info

    Leave a comment:


  • echow2001
    replied
    Re: ThinkPad T14 Supervisor password

    just did a lot of t14 intel with rt809H programmer, use the provided pinout and solder jumper to the jtag. move the 10k resistor to enable jtag program and then dump EC memory, erase, write.

    Leave a comment:


  • cgtec
    replied
    Re: ThinkPad T14 Supervisor password

    the size corece of MEC1663 is 290K the program svod or vertyanov or rt809h can read just 288K or 256K ... the 4k have all information of laptop.

    Leave a comment:


  • dycc
    replied
    Re: ThinkPad T14 Supervisor password

    Originally posted by simkard
    Thanks for your precisions/details on that one.
    Anyway, couldn't find out what is behind the acronym "LMU" ; May I ask for your help on that ?
    https://www.youtube.com/watch?v=Bt-sblFhxCM

    Leave a comment:


  • evserv
    replied
    Re: ThinkPad T14 Supervisor password

    DMI information and password is stored in eeeprom. Only programmer Vertyanov can work with eeprom. That is, you read the eeprom, delete the password, write the modified eeprom back to the chip. After that, you have an unlocked laptop and all DMI information is intact.

    Leave a comment:


  • Maxpower3
    replied
    Re: ThinkPad T14 Supervisor password

    Originally posted by 69d0b913
    yes, at least in T14 the information is lost, and it is necessary to write back using the LMU to repair.
    have you many EC dump of differents machines ?

    information is cryted, but SER# is présent in bios and EC . it's a mirror map

    you need several dumps to compare(bios +EC)
    Attached Files
    Last edited by Maxpower3; 01-28-2022, 07:35 PM.

    Leave a comment:


  • simkard
    replied
    Re: ThinkPad T14 Supervisor password

    Originally posted by 69d0b913
    after doing the MEC16xx writing procedure the machine loses the information, so when using the LMU to write back, just writing some information fills the others, just start writing back the SN then the SN of the motherboard, vera that some other information will already be there, the UUID code is generated automatically by the LMU, that is, you only need to know the SN of the motherboard, the SG and the machine model, nothing more.
    Thanks for your precisions/details on that one.
    Anyway, couldn't find out what is behind the acronym "LMU" ; May I ask for your help on that ?

    Leave a comment:


  • 69d0b913
    replied
    Re: ThinkPad T14 Supervisor password

    Originally posted by simkard
    So just to sum it up and be sure that I've totally understood how these new models are built/working regarding the supervisor password removal :

    After reading/writing MEC16xx chip with a blank/empty dump, there are some things that needs to be reconfigured.

    Technically, from my understanding, MEC16xx chip contains these informations (nothing else to declare ?) :
    • Machine type
    • Model Type
    • Country code
    • S/N / Serial Number
    • BIOS/Supervisor password
    • Computrace informations maybe ?


    While using the Lenovo HMD (Hardware Maintenance Diskette) v1.90, there are ways to fulfill these informations using option 20 or C0 and typing this sequency : 1STTTTMMMMCCSSSSSSSS which is composed of :
    • TTTT > Machine type
    • MMMM > Model Type
    • CC > Country code
    • SSSSSSSS > S/N / Serial Number


    So chronologically, steps would be :
    1. Solder wires on JTAG pins (close to the MEC16xx chip on the motherboard)
    2. Write an free from password dump of a MEC16xx chip
    3. Boot on the Lenovo HMD (hopefully no BIOS errors will be preventing from booting on an USB stick at that time)
    4. Use the option "20" or "C0" to fulfill the informations into the MEC16xx chip memory
    5. That's it ?


    Am I correct ?
    after doing the MEC16xx writing procedure the machine loses the information, so when using the LMU to write back, just writing some information fills the others, just start writing back the SN then the SN of the motherboard, vera that some other information will already be there, the UUID code is generated automatically by the LMU, that is, you only need to know the SN of the motherboard, the SG and the machine model, nothing more.

    Leave a comment:


  • 69d0b913
    replied
    Re: ThinkPad T14 Supervisor password

    Originally posted by Maxpower3
    you lose your info when you flash the "Mec16XXX".

    may want to reprogram better before the info!
    instead of using the maintenance diskette

    give me 2/3 dump for compare
    yes, at least in T14 the information is lost, and it is necessary to write back using the LMU to repair.

    Leave a comment:


  • simkard
    replied
    Re: ThinkPad T14 Supervisor password

    So just to sum it up and be sure that I've totally understood how these new models are built/working regarding the supervisor password removal :

    After reading/writing MEC16xx chip with a blank/empty dump, there are some things that needs to be reconfigured.

    Technically, from my understanding, MEC16xx chip contains these informations (nothing else to declare ?) :
    • Machine type
    • Model Type
    • Country code
    • S/N / Serial Number
    • BIOS/Supervisor password
    • Computrace informations maybe ?


    While using the Lenovo HMD (Hardware Maintenance Diskette) v1.90, there are ways to fulfill these informations using option 20 or C0 and typing this sequency : 1STTTTMMMMCCSSSSSSSS which is composed of :
    • TTTT > Machine type
    • MMMM > Model Type
    • CC > Country code
    • SSSSSSSS > S/N / Serial Number


    So chronologically, steps would be :
    1. Solder wires on JTAG pins (close to the MEC16xx chip on the motherboard)
    2. Write an free from password dump of a MEC16xx chip
    3. Boot on the Lenovo HMD (hopefully no BIOS errors will be preventing from booting on an USB stick at that time)
    4. Use the option "20" or "C0" to fulfill the informations into the MEC16xx chip memory
    5. That's it ?


    Am I correct ?

    Leave a comment:


  • Maxpower3
    replied
    Re: ThinkPad T14 Supervisor password

    Originally posted by 69d0b913
    If you have access to the data, it's easier, but if you don't, this information is on the machine itself, the serial number is on the label, the motherboard number is on the board itself.
    you lose your info when you flash the "Mec16XXX".

    may want to reprogram better before the info!
    instead of using the maintenance diskette

    give me 2/3 dump for compare
    Last edited by Maxpower3; 01-27-2022, 05:29 PM.

    Leave a comment:

Related Topics

Collapse

Working...