• RSS
  • Twitter
  • FaceBook

Security Forums

Log in

FAQ | Search | Usergroups | Profile | Register | RSS | Posting Guidelines | Recent Posts

[FAQ] IBM ThinkPad Unlock Supervisor Password

Users browsing this topic:0 Security Fans, 0 Stealth Security Fans
Registered Security Fans: None
Goto page Previous  1, 2, 3, 4, 5, 6, 7  Next
Post new topic   This topic is locked: you cannot edit posts or make replies.   Printer-friendly version    Networking/Security Forums Index -> Hardware // Upgrades

View previous topic :: View next topic  
Author Message
allservice
Trusted SF Member
Trusted SF Member


Joined: 24 Oct 2004
Posts: 5
Location: @your.service

Offline

PostPosted: Fri Sep 02, 2005 3:47 pm    Post subject: Reply with quote

IF you have the password then I am sure you verified if that works so you couldn't have the CRC 2 error at that time. Or is about other machine? What model it is? because for this 600e you already have the dump

To correct the error you have to read the eeprom, correct & write back.
Back to top
View user's profile Send private message Visit poster's website
cornelius
Just Arrived
Just Arrived


Joined: 02 Sep 2005
Posts: 0
Location: Earth

Offline

PostPosted: Mon Sep 05, 2005 11:46 am    Post subject: Reply with quote

hi
would it be possible to create the circut on a breadboard like the one here http://www.iguanalabs.com/breadboard.htm.
Back to top
View user's profile Send private message MSN Messenger
allservice
Trusted SF Member
Trusted SF Member


Joined: 24 Oct 2004
Posts: 5
Location: @your.service

Offline

PostPosted: Tue Sep 06, 2005 8:13 am    Post subject: Reply with quote

The schematic diagrams are coming with the eeprom reader or writer. Just install and look for simple-i2cprog.pdf and driven-i2cprog.pdf.
I hope this will eliminate any confusion for the future.
Back to top
View user's profile Send private message Visit poster's website
Digitalman
Just Arrived
Just Arrived


Joined: 02 Sep 2005
Posts: 0


Offline

PostPosted: Tue Sep 06, 2005 2:42 pm    Post subject: Some help!!!!(2) Reply with quote

Thanks ALL SERVICE for your fast answer...
My TP600E is 2646type.
And yes, i read the EEPROM and password but something must be change
when i read that, because when i ingress the password the machine show me OK, and then stop with ERROR188 message(BAD EEPROM CRC#1)
This is because the checksum of the memory and the checksum store in the BIOS are not the same(CRC ERROR)
You are right, i must correct something in the EEPROM but WHAT???(I dont have the original dump)
May be updating the BIOS the checksum store in that will be erased???
Thanks again and sorry for me english...
Digitalman
Back to top
View user's profile Send private message
allservice
Trusted SF Member
Trusted SF Member


Joined: 24 Oct 2004
Posts: 5
Location: @your.service

Offline

PostPosted: Tue Sep 06, 2005 4:41 pm    Post subject: Reply with quote

you said you read the eeprom then you have the dump. This dump is the original eeprom content that must be write into eeprom. CRC error is displayed before the password prompt so you didn't have such error at that time. This error appeared after you successfully unlocked the eeprom and not in the same power cycle. Well you have the dump...
Until you program the eeprom with this dump. you'll not be able to perform any task on your machine (including BIOS update-this will not solve this kind of problems).
Back to top
View user's profile Send private message Visit poster's website
Digitalman
Just Arrived
Just Arrived


Joined: 02 Sep 2005
Posts: 0


Offline

PostPosted: Thu Sep 08, 2005 2:09 pm    Post subject: Some helppp!!!(3) Reply with quote

Sorry, first of all the machine show me 188, then go on and display the
password prompt(I ingress that and show me OK) and then(other screen) the machine stop witch 188ERROR.

I dont understand one thing.....When the machine ask me the password I read the eeprom and get the DUMP...ok!!
You say that I must re-write the eeprom(witch this DUMP) after the machine stop witch 188ERROR???

What program can I use to write?
I use the PonyProg to read....is secure to write???

Thanks AGAIN Smile
Back to top
View user's profile Send private message
allservice
Trusted SF Member
Trusted SF Member


Joined: 24 Oct 2004
Posts: 5
Location: @your.service

Offline

PostPosted: Thu Sep 08, 2005 2:59 pm    Post subject: Reply with quote

If you used PonyProg to read then you need a good dump indeed.
Back to top
View user's profile Send private message Visit poster's website
joker77
Just Arrived
Just Arrived


Joined: 09 Sep 2005
Posts: 0


Offline

PostPosted: Fri Sep 09, 2005 9:12 pm    Post subject: Reply with quote

Allservice I also have a R32 which has been a door stop for over a year. It would be nice to clear the bios and supervisor password. Could you please send me your solution (schematic/software)...

AT: crazy_spic@msn.com
OR : concho12@hotmail.com


thanks
Back to top
View user's profile Send private message
allservice
Trusted SF Member
Trusted SF Member


Joined: 24 Oct 2004
Posts: 5
Location: @your.service

Offline

PostPosted: Fri Sep 09, 2005 9:59 pm    Post subject: Reply with quote

Please, read the entire thread even if is a bit larger now. I already specified here the links where you could get the software. The schematics are coming with the eeprom reader or writer, just install R24rf08 and see the pdfs.
So. visit http://www.serviceforum.lx.ro/viewforum.php?f=12 or http://home.ripway.com/2005-7/365678/


Last edited by allservice on Thu Feb 09, 2006 2:16 pm; edited 4 times in total
Back to top
View user's profile Send private message Visit poster's website
Tom Bair
SF Boss
SF Boss


Joined: 10 Aug 2002
Posts: 16776955
Location: Portland, Oregon USA

Offline

PostPosted: Sat Sep 10, 2005 2:21 am    Post subject: Reply with quote

To our members and visitors:

allservice has provided links above to download the needed items to solve your IBM Password problem.

Please do not post in this FAQ asking for that which you can now download Smile Any such posts will be deleted without notification to the poster.

If you have problems, or fail to understand the instructions; please PM (Private Message) allservice concerning such.

Thank you in advance for your understanding and cooperation.
Back to top
View user's profile Send private message Visit poster's website
Digitalman
Just Arrived
Just Arrived


Joined: 02 Sep 2005
Posts: 0


Offline

PostPosted: Mon Sep 12, 2005 10:35 pm    Post subject: Why not PonyProg? Reply with quote

Hello ALL SERVICE Smile))
My notebook is a tp600e
I build the driven-i2cprog interfase, but when I trie to use your
software(r24rf08 v2.0a) witch /x/d/i, only get:
ERROR: Eeprom not available!
I tire witch the patcher /x/d/i too

If I use the PonyProg can read the 24rf08 and then ibmpass2 to see the
password....Why you software cant read?
Back to top
View user's profile Send private message
allservice
Trusted SF Member
Trusted SF Member


Joined: 24 Oct 2004
Posts: 5
Location: @your.service

Offline

PostPosted: Tue Sep 13, 2005 11:54 am    Post subject: Reply with quote

You must use spaces between /x /d /i got that?. PonyProg doesn't work with this interface unless you invert the logics for the signals in setup menu ( i bet you knew that). And of course PonyProg cannot read 24rf08 properly, otherwise why are you still asking help in this thread?

To be clear, you must run the reader with parameters:
-Open a console window start > run and type "cmd" or "command" and press <Enter>
- switch to program folder, usualy c:\allservice\24rf08"
with this command:
"cd c:\allservice\24rf08", you should see the prompt "c:\allservice\24rf08>"
-now, type "r24rf08 filename.bin /x /d /i" - for driven-i2c programmer or simply "r24rf08 filename.bin" for SIPROG and pres <Enter>. don't forget to put spaces between parameters like this:
r24rf08<sp>filename.bin<sp>/x<sp>/d<sp>/i

If you are prompted with "eeprom not found" then something is wrong. I am not there to tell you what that might be.


Last edited by allservice on Fri Sep 16, 2005 8:46 pm; edited 1 time in total
Back to top
View user's profile Send private message Visit poster's website
loppan
Just Arrived
Just Arrived


Joined: 13 Oct 2005
Posts: 0


Offline

PostPosted: Thu Oct 13, 2005 1:47 pm    Post subject: Reply with quote

Hi Allservice
I have tried your method of solving SVP password on a TP T21.
I reached the eeprom with the max232 circuit and got a dump file.
But... the dump file contains nothing but zeros.

What is wrong?

Hope you can help me.

loppan
Back to top
View user's profile Send private message
allservice
Trusted SF Member
Trusted SF Member


Joined: 24 Oct 2004
Posts: 5
Location: @your.service

Offline

PostPosted: Fri Oct 14, 2005 8:05 pm    Post subject: Hacking Reply with quote

Maybe you can PM me with some details. Anyway the main reason seems to be the SDA line that is held Low all the time.

Last edited by allservice on Sat Oct 15, 2005 1:07 am; edited 1 time in total
Back to top
View user's profile Send private message Visit poster's website
noromamai
Just Arrived
Just Arrived


Joined: 21 Oct 2005
Posts: 0


Offline

PostPosted: Fri Oct 21, 2005 9:03 pm    Post subject: Reply with quote

i have a bricked tp r52 and was glad to find out there was a free way to get it all working again.

i bought the parts for the reader and have taken apart the tp, but have not been able to find the location of the atmel chip. the maintenance manual does mention a security chip, but i assume that's not the one i need. i did find the location on the main board of that chip, but it doesn't seem right.

can someone point out to me where i can find the atmel chip on the main board?

any help would be appreciated.
Back to top
View user's profile Send private message
allservice
Trusted SF Member
Trusted SF Member


Joined: 24 Oct 2004
Posts: 5
Location: @your.service

Offline

PostPosted: Sun Oct 23, 2005 12:59 pm    Post subject: Reply with quote

It is a 8 pin eeprom. remove the top cover with keyboard and touch pad. It is just near the intel southbridge chip.
It is marked as "U53" on the PCB if I remember well.


Last edited by allservice on Thu Oct 27, 2005 10:33 am; edited 1 time in total
Back to top
View user's profile Send private message Visit poster's website
Display posts from previous:   

Post new topic   This topic is locked: you cannot edit posts or make replies.   Printer-friendly version    Networking/Security Forums Index -> Hardware // Upgrades All times are GMT + 2 Hours
Goto page Previous  1, 2, 3, 4, 5, 6, 7  Next
Page 2 of 7


 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum

Community Area

Log in | Register