RT809H worked for me for T14 Gen 2 via JTAG, but unfortunately secure boot is grayed out in bios. Please can someone help with the bios molding ? I'll post my back if needed
hello friend, Could you post pictures or schematic of the jtag in this model?
Hey guys got a T14s with locked bios password. Was able to read the bin file from Windbond chip but no clue what I am looking for to edit the file with Hxd64. can anyone help with removing password?
Has anyone read the EC IT8300 chip, from thinkpad T14 AMD, using RT809? Mine is giving an error and even with everything right, would there be any other modification on the board that I do to make the reading? I don't have vertyanov and I don't have svod.
Hi bro ,
Can you tell me what is that Black cable staying above the PCB board near the GND writing? or it was just accidentally put there?
I have the same parts (received with RT809H) that I want to try with RT809H and KBC to remove the password from Lenovo Thinkpad T14 Gen1 model
Also can you tell us the position of the R/W resistor on this model of laptop?
After a lot of persistence I was able to remove the bios password from T14! I believe that few here know how to do it and no one shares it, I understand that certain types of information are not shared and are sold! But I persistently come to inform you that the (Thinkpad T14 1st 20S1) was unlocked by an RT809H the only programmer I have. Here are photos in the attachment, now all that remains is to reverse the bios information, but I had taken a photo first of all.
Can you send JTAG pinouts please or can I use KBC connector? I have RT809H and want to try it...
My motherboard is this in picture, anybody know pinouts for JTAG or can I use KBC connector with RT809H?
Can you send JTAG pinouts please or can I use KBC connector? I have RT809H and want to try it...
My motherboard is this in picture, anybody know pinouts for JTAG or can I use KBC connector with RT809H?
Laptop model is T14 GEN1 with Ryzen processor
Thanks
Yes , sorry, but I saw that my board doesn't fit in coolshrimps tutorial as it has MEC chips, but this board of mine has ITE chips and seems that it can be done via KBC connector only, and the R/W resistor which I am not knowing the position of that resistor.
Yes , sorry, but I saw that my board doesn't fit in coolshrimps tutorial as it has MEC chips, but this board of mine has ITE chips and seems that it can be done via KBC connector only, and the R/W resistor which I am not knowing the position of that resistor.
I don`t think you have to move any resistors for the ITE chip, don`t know for sure never worked on one of these.
Will have to look in the RT809H forums as there I see that even RT809 can write these EC or chips or what are these, otherwise I don't believe that just SVOD or Vertyanov can handle these chips and RT809H no.
But the worst thing is that the forums are in Chinese and I am not managing to even register on there, but I am just translating the sites with Google....
So just to sum it up and be sure that I've totally understood how these new models are built/working regarding the supervisor password removal :
After reading/writing MEC16xx chip with a blank/empty dump, there are some things that needs to be reconfigured.
Technically, from my understanding, MEC16xx chip contains these informations (nothing else to declare ?) :
Machine type
Model Type
Country code
S/N / Serial Number
BIOS/Supervisor password
Computrace informations maybe ?
While using the Lenovo HMD (Hardware Maintenance Diskette) v1.90, there are ways to fulfill these informations using option 20 or C0 and typing this sequency : 1STTTTMMMMCCSSSSSSSS which is composed of :
TTTT > Machine type
MMMM > Model Type
CC > Country code
SSSSSSSS > S/N / Serial Number
So chronologically, steps would be :
Solder wires on JTAG pins (close to the MEC16xx chip on the motherboard)
Write an free from password dump of a MEC16xx chip
Boot on the Lenovo HMD (hopefully no BIOS errors will be preventing from booting on an USB stick at that time)
Use the option "20" or "C0" to fulfill the informations into the MEC16xx chip memory
That's it ?
Am I correct ?
Question Simkard ---> If the serial number and/or the model type &/or machine type are in the ballpark (i.e. from a T-14 Gen 1) but not the exact one for the machine being fixed, what happens then? Would it affect things like the proper functioning of the power button for example?? I have a case where a T-14S Gen1 machine is functioning properly in every way after a Supervisor Password delete utilizing a Vertyanov Successor programmer but the serial number, model number and machine type numbers are wrong. The physical power button does not work. Also, the shutdown function in W10 Pro does not work but sleep does as well as restart. I am able to use the Microsoft Update function (was able to load and update W10 pro through various update iterations no problem) so that means the machine does completely shutdown but doesn't remain shut. I have already removed Fast Restart from Windows. Can you provide any help whether tinkering with the EC has somehow now disabled the power button?
Hello guys
There some informations about lenovo thinkpad new generation laptop
I1st option is usual jtag
2nd one is that you can modify bios bin in certain lines addresses and those modifications can delete the password
I found this on the internet maybe it's possible maybe it's not
If someone Can confirm that
Hello guys
There some informations about lenovo thinkpad new generation laptop
I1st option is usual jtag
2nd one is that you can modify bios bin in certain lines addresses and those modifications can delete the password
I found this on the internet maybe it's possible maybe it's not
If someone Can confirm that
Modifying the bios is only possible on old models. This topic is for the T14 which requires MEC1663 JTAG and a programmer compatible with it
Can someone please help remove Supervisor password,
I tried lenovo patcher ver 0.2 with no success on 3 of my backups i have installed also python 3.8 I drag the dump to the patcher but nothing gets generated
Can someone please help remove Supervisor password,
I tried lenovo patcher ver 0.2 with no success on 3 of my backups i have installed also python 3.8 I drag the dump to the patcher but nothing gets generated
Lenovo T14 Gen 1
Model type : 20S1-S73B0B
SN: PF-2PK27T
Password in SIO. you need vertyanov successor or Svod 4 programmer.
Comment