T-Mobile US / G710TM10N KDZ - LG G7 ThinQ ROMs, Kernels, Recoveries, & Other De

Here is the latest T-Mobile US KDZ: G710TM10N.
Changelog only indicates November security update.
Download URL: here
Google Drive mirrors:
- KDZ
- DLL

@Joe199799 Did you see this? @ChazzMatt Also @culot did you already try to install this and if so what was the result? Also, was not able to get this extracted/decompiled as well.

Dvalin21 said:
@Joe199799 Did you see this? @ChazzMatt
Click to expand...
Click to collapse
I did yes, I should say I keep up with this stuff and know a decent amount about the front end of Android but I'm f****ing clueless about the backend, all the information I've told people is just paraphrasing from other threads on here

Dvalin21 said:
@Joe199799 Did you see this? @ChazzMatt Also @culot did you already try to install this and if so what was the result? Also, was not able to get this extracted/decompiled as well.
Click to expand...
Click to collapse
This was just pulled from LG Bridge as it updated my device.
No, I was not able to extract contents of the dz file. Someone could try to add the header info to that LG kdz python program on github maybe? A while back that used to be simple to accomplish.

Guys here is the boot_a/b for the firmware you posted here. Thanks goes out to @runningnak3d who made updates to @emdroidle's work. (KDZ extractor: Here)Amazing work guys. boot_a/b
Update: Currently trying to upload the system_a/b folders already unpacked. Ill post the link as soon as its finished
Update System_a/b Here

Been lurking and leeching since my first android, trying to contribute on this G7, just upgraded to G710TM10N on this sim-locked G7, if I can provide anything to help anywhere. I can try to pull the same files if redundancy helps

danag94 said:
Been lurking and leeching since my first android, trying to contribute on this G7, just upgraded to G710TM10N on this sim-locked G7, if I can provide anything to help anywhere. I can try to pull the same files if redundancy helps
Click to expand...
Click to collapse
Thank you sir, see if you can try to pull the recovery.img. The firmware didnt seem to include one. I may try and download an older firmware and see if i can recover it from there instead. If everyone can help with this search, it could prove important.

Recovery is included in boot_a, boot_b in system A/B phones which the LG G7 has. It is included there so phone can update without needing a reboot.

mprovi_15 said:
Recovery is included in boot_a, boot_b in system A/B phones which the LG G7 has. It is included there so phone can update without needing a reboot.
Click to expand...
Click to collapse
While you are correct that recovery is in boot, it is not needed for the A/B updates. The only rational reason they stuck recovery in boot is to make our lives difficult. Also, not all A/B phones ditched the recovery partition, just the majority of phones with Qualcomm processors that use their reference abl.
FYI - the much easier way will be to incorporate TWRP into laf ... or just forgo download mode completely, and use the laf partition.
Lastly, now that I can decompile abl -- stay tuned for ablsploit (to be used in conjunction with lafsploit). I am not saying with certainty that it is possible yet, but I am feeling confident.
Oh, one last thing for real this time -- don't think about cross flashing ANY model G7. I have downloaded all available KDZs for each model, and LG got smart and they all have different RSA certs.
-- Brian

Dvalin21 said:
Thank you sir, see if you can try to pull the recovery.img. The firmware didnt seem to include one. I may try and download an older firmware and see if i can recover it from there instead. If everyone can help with this search, it could prove important.
Click to expand...
Click to collapse
I kept hitting security key issues, possibly due to my limited usage of adb and fastboot. My phone had already updated so I don't see the download anywhere, I guess to the A/B partition setup.
and good luck to you, runningnak3d

Guys I need help! can someone drop me a dump of LG g7 G710tm. just hardbricked neeed dump to revive my phone!!!!

kumasi_kg said:
Guys I need help! can someone drop me a dump of LG g7 G710tm. just hardbricked neeed dump to revive my phone!!!!
Click to expand...
Click to collapse
you can find them here:
https://lg-firmwares.com/lg-lmg710tmp-firmwares/
Does anyone know how to change the certificates between firmwares?

Related

[Q] Need LG Panther & Samsung Taylor Users' Help For Updates

So it seems like we'll need to fight over at the Microsoft forums if we're to try to stay up-to-date. I need you to contribute to my post over at msdn here: http://forums.create.msdn.com/forums/p/78753/476964.aspx#476964
Maybe if enough of us hit'em, we can get some kind of answer. Dev phones should have been the first to be updated.
Still no updates for Taylor.
It says in the forums that you linked to that there will be no updates for the Samsung Taylor phones.
the92playboy said:
It says in the forums that you linked to that there will be no updates for the Samsung Taylor phones.
Click to expand...
Click to collapse
Seems like there won't be and update for LG Panthers either.
Anyone wanna trade for an Android device?
Might be a newb question here but....
Did people have to pay for these developer phones? Or did MS just send them out to registered/respected developers?
I suppose, you can flash your phone with the Omnia 7/Quantum ROM at your own risk.
the92playboy said:
Might be a newb question here but....
Did people have to pay for these developer phones? Or did MS just send them out to registered/respected developers?
Click to expand...
Click to collapse
Yup, Microsoft just sent them out.
day2die said:
I suppose, you can flash your phone with the Omnia 7/Quantum ROM at your own risk.
I would like to give th Quantum ROM a try , but I do not know where to start. I am a Bell user in Canada so I think they have the Quantum. I used to flash old WM and Android Devices all the time, but WP7 is new to me. Anyone have a thread or no if anyone has sucessfully flashed a LG Panther to anything else? I can get into a bootloader, but it is probably just Microsofts bootloader.
Click to expand...
Click to collapse
NevinM said:
day2die said:
I suppose, you can flash your phone with the Omnia 7/Quantum ROM at your own risk.
I would like to give th Quantum ROM a try , but I do not know where to start. I am a Bell user in Canada so I think they have the Quantum. I used to flash old WM and Android Devices all the time, but WP7 is new to me. Anyone have a thread or no if anyone has sucessfully flashed a LG Panther to anything else? I can get into a bootloader, but it is probably just Microsofts bootloader.
Click to expand...
Click to collapse
Looks like it's really possible, because i succesfully connected to the phone using QXDM, and even downloaded NAND's image (it's raw, so for extracting page size required, because size in the partition table is relative to page size). Though may flash it, i think bootloader will work. But you probably can get bricked device. Unfortunally i have no enough time for explorations.
Click to expand...
Click to collapse
Useless guy said:
Looks like it's really possible, because i succesfully connected to the phone using QXDM, and even downloaded NAND's image (it's raw, so for extracting page size required, because size in the partition table is relative to page size). Though may flash it, i think bootloader will work. But you probably can get bricked device. Unfortunally i have no enough time for explorations.
Click to expand...
Click to collapse
I think flashing the unbranded Optimus 7 ROM would be the best bet for us. There is a registry key named "HasKeyboard" that's defaulted to 0 that we can change to 1. That might be the way to go. Also I'm wondering if we'd have to go the goldcard method to move over to a Quantum or Optimus rom.
The problem is I don't have another phone and there's no MTTY process to unbrick our phones so I'm a little hesitant to try.
fb401 said:
Useless guy said:
I think flashing the unbranded Optimus 7 ROM would be the best bet for us. There is a registry key named "HasKeyboard" that's defaulted to 0 that we can change to 1. That might be the way to go. Also I'm wondering if we'd have to go the goldcard method to move over to a Quantum or Optimus rom.
The problem is I don't have another phone and there's no MTTY process to unbrick our phones so I'm a little hesitant to try.
Click to expand...
Click to collapse
Goldcard isn't required. Only HTC devices require it.
I've dumped my ROM, so if bootloader will work (i hope), device can be easily flashed.
Is anyone wanna to try? QPST can flash certain partitions (looks like only dsp1 and efs are required for succesful update). Unfortunally i can't risk my phone, because i'm developing an application.
Click to expand...
Click to collapse
Not being rude, but are people complaining that a phone that they received for free is not getting the update and not being continued? If you never paid anything for it in the first place, what are you out then?
the92playboy said:
Not being rude, but are people complaining that a phone that they received for free is not getting the update and not being continued? If you never paid anything for it in the first place, what are you out then?
Click to expand...
Click to collapse
Not every got it free.
Me to...
I am not sure if it is worthwhile attempting a flash. The problem is we are all developers and having no device is probably not worth the risk. I have not flashed anything WP7 so I am pretty hesitant. Is this the link to flashing info you guys are considering?
http://forum.xda-developers.com/showthread.php?t=935605
In reading the other threads, there is no real confirmation on the Panther not getting updated. It is clear the the Taylor will not. I am curious if we are running the exact ROM that another device is? If so, ROM from those devices may work. I am trying to remember what the download name was (was it Pacific or something?). I deleted the file. If I still had it I would consider giving flashing a try. I wish Microsoft had not shut down the microsoft connect site for these phones. Any thoughts?
the92playboy said:
Not being rude, but are people complaining that a phone that they received for free is not getting the update and not being continued? If you never paid anything for it in the first place, what are you out then?
Click to expand...
Click to collapse
I got mine off of eBay due to it being the best keyboard phone out at the time (the Quantum is a joke), so it wasn't free for me. Once we get a HTC 7 Pro here that's compatible with AT&T's 3G bands, I'll switch over to that.
NevinM said:
I am not sure if it is worthwhile attempting a flash. The problem is we are all developers and having no device is probably not worth the risk. I have not flashed anything WP7 so I am pretty hesitant. Is this the link to flashing info you guys are considering?
http://forum.xda-developers.com/showthread.php?t=935605
In reading the other threads, there is no real confirmation on the Panther not getting updated. It is clear the the Taylor will not. I am curious if we are running the exact ROM that another device is? If so, ROM from those devices may work. I am trying to remember what the download name was (was it Pacific or something?). I deleted the file. If I still had it I would consider giving flashing a try. I wish Microsoft had not shut down the microsoft connect site for these phones. Any thoughts?
Click to expand...
Click to collapse
I was thinking more the Europe Open Optimus 7 rom here: http://forum.xda-developers.com/showthread.php?t=935578
Like you said, I can't be without a device so I'm really hesitant to try flashing
Well there is going to be a point where and update or feature will make our phones aka gw910 or Taylor completely useless as for development or testing, so this is something to consider.
Yeah connect has been down since a long time ago I have been struggling to find the FW file provided in the msdn/connect/internet forums, I’m guessing the only way now is to contact either a developer/evangelist/god/msdn who has that file available in storage, with the firmware we can create our own updated custom FW way easier than creating one from scratch and/or experiment with other FW like the optimus 7/Q.
And idea can we consider spoofing the gw910 to an optimus 7/Q .7004 using the registry editor? Making ZUNE update just the components needed.
also im willing to give it a go flashing mi gw910 UsellesGuy any info on how can i dump mi firmware. and posible explanation as in how to recover.I read the bootloader post before but is there anything else i need ?
dragoxt said:
Well there is going to be a point where and update or feature will make our phones aka gw910 or Taylor completely useless as for development or testing, so this is something to consider.
Yeah connect has been down since a long time ago I have been struggling to find the FW file provided in the msdn/connect/internet forums, I’m guessing the only way now is to contact either a developer/evangelist/god/msdn who has that file available in storage, with the firmware we can create our own updated custom FW way easier than creating one from scratch and/or experiment with other FW like the optimus 7/Q.
And idea can we consider spoofing the gw910 to an optimus 7/Q .7004 using the registry editor? Making ZUNE update just the components needed.
also im willing to give it a go flashing mi gw910 UsellesGuy any info on how can i dump mi firmware. and posible explanation as in how to recover.I read the bootloader post before but is there anything else i need ?
Click to expand...
Click to collapse
Microsoft delivers updates using binary patches, they apply only to concrete file version, else they will be broken (or updating will be failed).
Thank you, but i think better way is to wait a bit, until situation about updates will clear up. If update will be not received - i'll begin my work
Useless guy said:
Microsoft delivers updates using binary patches, they apply only to concrete file version, else they will be broken (or updating will be failed).
Thank you, but i think better way is to wait a bit, until situation about updates will clear up. If update will be not received - i'll begin my work
Click to expand...
Click to collapse
On twitter I've tired contacting @winphonesupport as far as our phones being updated. They replied: "Let us see if our team knows and we'll get back to you. ^EB"
I haven't gotten another answer back yet. I doubt I'll get one at all honestly.
quick question about updating a developer device
Hi
I'm a complete newby about wp7.
I've two Optimus 7 in my possession that seem to be developer devices.
Here the phones info:
OS Version: 6516Mainline
SW Version: LG-E900AT-00-V08d-ORG-UK-JUL-24-2010
HW Version: E
More info:
OS Version: 6516Mainline (buildlab).20100713-1228
Firmware revision number: 0.8.4.10
Hardware revision number: 0.1.5.0
Bootloader version: 1.4.1.0
Chip SOC version: 0.30.2.0
Now I've tried to update the firmware like in this post:
http://forum.xda-developers.com/showthread.php?t=935578
But it doesn't work (LGDP2 connect to phone start the update but give the error 1002)
Is there a way to flash these phones to be like normal phones? (I don't intent to develop on them) Or my hardware version is to old (prototype)
Thanks for the help
fb401 said:
I think flashing the unbranded Optimus 7 ROM would be the best bet for us. There is a registry key named "HasKeyboard" that's defaulted to 0 that we can change to 1. That might be the way to go. Also I'm wondering if we'd have to go the goldcard method to move over to a Quantum or Optimus rom.
The problem is I don't have another phone and there's no MTTY process to unbrick our phones so I'm a little hesitant to try.
Click to expand...
Click to collapse
so you are relying on a dev phone that MS was gracious enough to give you as your only device and are complaining that you didn't get the update???
edit: after reading your replies, this wasn't a publicly released phone, so if you don't get the updates, I don't feel you have a complaint.

H634 Cricket Stylo system.img Or KDZ?

Ok is there still no true root method, system.img or KDZ or recovery for our device? Is there no development? Ive had mine bricked now for a few months and waiting for an update or unbrick method has proven fruitless, can someone pull a system.img or help users with this device somehow? Thanks in advance
Need help too
packydavis said:
Ok is there still no true root method, system.img or KDZ or recovery for our device? Is there no development? Ive had mine bricked now for a few months and waiting for an update or unbrick method has proven fruitless, can someone pull a system.img or help users with this device somehow? Thanks in advance
Click to expand...
Click to collapse
I need the kdz or tot file for cricket stylo as well. Please let me know if you figure this out.
help please??
GFlexin said:
I need the kdz or tot file for cricket stylo as well. Please let me know if you figure this out.
Click to expand...
Click to collapse
same , anyone had luck on unbricking the h634??
packydavis said:
Ok is there still no true root method, system.img or KDZ or recovery for our device? Is there no development? Ive had mine bricked now for a few months and waiting for an update or unbrick method has proven fruitless, can someone pull a system.img or help users with this device somehow? Thanks in advance
Click to expand...
Click to collapse
I started working on my lg stylo from cricket with no idea what I was doing. All ive really done is allow root, and have supersu with busybox. Other than that I've just been pulling my hair out because of lg bootloader lock. I've found some things about adb straight on the device to bypass bootloader. One thing I have found through my research is a guide with the "factory firmware". I haven't had a chance to try it, but I will post it for those who can try it out.
Also I too have a lot of questions specifically about the lg g stylo. I have h634 (from cricket) and want to work on roms/kernels and remove ALL bloatware. Most importantly, I would like to learn how to set the external sd card as "default" storage.
If you have useful info on the cricket variant of the stylo or know of anything that might help, you can send it my way. Also, I do have much more I have found about the stylo and love to share. Don't be afraid to ask me something. I will do my best to help you, as I too will be learning while trying to help.
If you want the link for the guide, just send me a personal message or simply reply to this post. I apparently can't post outside links until I've made 10 posts on the site. With this being my very first post, I guess I have 9 more to go lol.
Remember to follow instructions carefully and use at your own risk. I have not tried this and cannot vouch for it. Good luck and let me know how it goes.
Guide with Firmware
Hey Mooose-Nuckle. I really need that link for the guide and firmware. If you can pm it to me i would be very thankful.
Mooose-Nuckle said:
I started working on my lg stylo from cricket with no idea what I was doing. All ive really done is allow root, and have supersu with busybox. Other than that I've just been pulling my hair out because of lg bootloader lock. I've found some things about adb straight on the device to bypass bootloader. One thing I have found through my research is a guide with the "factory firmware". I haven't had a chance to try it, but I will post it for those who can try it out.
Also I too have a lot of questions specifically about the lg g stylo. I have h634 (from cricket) and want to work on roms/kernels and remove ALL bloatware. Most importantly, I would like to learn how to set the external sd card as "default" storage.
If you have useful info on the cricket variant of the stylo or know of anything that might help, you can send it my way. Also, I do have much more I have found about the stylo and love to share. Don't be afraid to ask me something. I will do my best to help you, as I too will be learning while trying to help.
If you want the link for the guide, just send me a personal message or simply reply to this post. I apparently can't post outside links until I've made 10 posts on the site. With this being my very first post, I guess I have 9 more to go lol.
Remember to follow instructions carefully and use at your own risk. I have not tried this and cannot vouch for it. Good luck and let me know how it goes.
Click to expand...
Click to collapse
Mooose-Nuckle said:
I started working on my lg stylo from cricket with no idea what I was doing. All ive really done is allow root, and have supersu with busybox. Other than that I've just been pulling my hair out because of lg bootloader lock. I've found some things about adb straight on the device to bypass bootloader. One thing I have found through my research is a guide with the "factory firmware". I haven't had a chance to try it, but I will post it for those who can try it out.
Also I too have a lot of questions specifically about the lg g stylo. I have h634 (from cricket) and want to work on roms/kernels and remove ALL bloatware. Most importantly, I would like to learn how to set the external sd card as "default" storage.
If you have useful info on the cricket variant of the stylo or know of anything that might help, you can send it my way. Also, I do have much more I have found about the stylo and love to share. Don't be afraid to ask me something. I will do my best to help you, as I too will be learning while trying to help.
If you want the link for the guide, just send me a personal message or simply reply to this post. I apparently can't post outside links until I've made 10 posts on the site. With this being my very first post, I guess I have 9 more to go lol.
Remember to follow instructions carefully and use at your own risk. I have not tried this and cannot vouch for it. Good luck and let me know how it goes.
Click to expand...
Click to collapse
Can I get that link?
could i get that link
Could I get the link pls.. (PM sent also) Thanks
Mooose-Nuckle said:
I started working on my lg stylo from cricket with no idea what I was doing. All ive really done is allow root, and have supersu with busybox. Other than that I've just been pulling my hair out because of lg bootloader lock. I've found some things about adb straight on the device to bypass bootloader. One thing I have found through my research is a guide with the "factory firmware". I haven't had a chance to try it, but I will post it for those who can try it out.
Also I too have a lot of questions specifically about the lg g stylo. I have h634 (from cricket) and want to work on roms/kernels and remove ALL bloatware. Most importantly, I would like to learn how to set the external sd card as "default" storage.
If you have useful info on the cricket variant of the stylo or know of anything that might help, you can send it my way. Also, I do have much more I have found about the stylo and love to share. Don't be afraid to ask me something. I will do my best to help you, as I too will be learning while trying to help.
If you want the link for the guide, just send me a personal message or simply reply to this post. I apparently can't post outside links until I've made 10 posts on the site. With this being my very first post, I guess I have 9 more to go lol.
Remember to follow instructions carefully and use at your own risk. I have not tried this and cannot vouch for it. Good luck and let me know how it goes.
Click to expand...
Click to collapse
[TOT and dll] Cricket H634 LG G Stylo STOCK Firmware via Bit-Torrent Here
packydavis said:
Ok is there still no true root method, system.img or KDZ or recovery for our device? Is there no development? Ive had mine bricked now for a few months and waiting for an update or unbrick method has proven fruitless, can someone pull a system.img or help users with this device somehow? Thanks in advance
Click to expand...
Click to collapse
I bought the .TOT and .dll files from some non-LG site online; files over 1gb give me a lot of trouble to upload to Gdrive or Dropbox, and Mega.nz seems to give problems over time, so I've uploaded and am seeding (along with several others who are getting it from me) a zipped archive containing the .TOT & .dll files for the Cricket H634 LG G Stylo STOCK Firmware! Here's a link and also I've attached the torrent file in case the link dies : https://kat.cr/cricket-lg-g-stylo-h634-firmware-android-5-1-1-t12571867.html
Also I wrote a readme.txt containing instructions for how I did it, with programs too (LG Flash Tool 2014). It took me a while, so be sure to read it!
Peace
torrent download failed
please can anyone upload the files to a download server like MEGA or MEDIAFIRE, most of us cant download files from a torrent. Please help us!!!!. Upload the files to MEGA. DROPBOX or MEDIAFIRE!!!
thanks in advance...
Ok, so this will be the TOT and dll, you will need to install lgflashtool to flash it. Be glad, I had to hunt for hours for these. https://drive.google.com/open?id=0B9AUqOIj9fgTSDlLNDJHcUlINjg . Enjoy ladies and gents. https://drive.google.com/open?id=0B9AUqOIj9fgTVmZHb0s0YjJTTFE lgflashtool 2014
THANK YOU!!!!!!
you are greaaaaaaaaaaattttttt!!!!!!!!!!!!!!!!!!!!!!!
coldelectric said:
i bought the .tot and .dll files from some non-lg site online; files over 1gb give me a lot of trouble to upload to gdrive or dropbox, and mega.nz seems to give problems over time, so i've uploaded and am seeding (along with several others who are getting it from me) a zipped archive containing the .tot & .dll files for the cricket h634 lg g stylo stock firmware! Here's a link and also i've attached the torrent file in case the link dies : https://kat.cr/cricket-lg-g-stylo-h634-firmware-android-5-1-1-t12571867.html
also i wrote a readme.txt containing instructions for how i did it, with programs too (lg flash tool 2014). It took me a while, so be sure to read it!
Peace
Click to expand...
Click to collapse
Thanks
did anyone check the torrent software to ensure that it works? If so, totally awesome
Yes, it works like a champ.
Sent from my SM-S920L using XDA-Developers mobile app
Hey my name is Brian and i have a lg stylo from cricket that i have bricked while trying to root through a xda developers web site. Can you please help with detailed instructions on how to unbrick? Its stuck on the initial sign into google page and keyboard doesnt even come up. Reach me by email please... [email protected]
Thanks for any help
wolf20043 said:
Yes, it works like a champ.
Sent from my SM-S920L using XDA-Developers mobile app
Click to expand...
Click to collapse
can anyone tell me what this flash does?? been trying to find a root method to install a different rom on my girlfriends lg from cricket (or if its even possible). thanks in advance
Hotwheel6661 said:
can anyone tell me what this flash does?? been trying to find a root method to install a different rom on my girlfriends lg from cricket (or if its even possible). thanks in advance
Click to expand...
Click to collapse
This restores your device to factory. As of now there are no custom roms or custom recovery. To root, you can use Kingroot.
I have downloaded all of the drivers and lg flashtool as well as the .tot and .dll files. Moved everything where it needs to be, but when I enter download mode and connect the phone to my computer it isn't detected. It is detected any other time as in when my phone is booted up normally. Can someone please point me in the right direction. I have tried different drivers.
I've got the cricket LG G Stylo and I've managed to find the OEM Unlock. Has anyone else found it? Isn't that is what's needed to unlock bootloader?

[RESEARCH|MT8127] Bootloader hack ideas for LeapFrog Epic

I dunno, but I thought maybe I could make a separate thread about a possible way to poke into the LeapFrog Epic's preloader so it could accept unsigned images. LeapFrog won't spill the beans for us, as their staff (falsely) claims to know next to nothing about it, so unless we somehow managed to social-engineer them into giving us a signed ROM or an unlocked bootloader, our only chance is to patch it so it would ignore the lack of digital signatures.
What I've done so far is to run a strings check on the preloader and uboot binaries - fastboot seems watered down somehow as it lacked references to "oem unlock" and so on, but none of that Amazon Fire-style failsafe seems present from what I can tell.
Preloader: http://pastebin.com/H9QbzqC0
lk: http://pastebin.com/kSxRKYna
Boot files from the latest firmware revision are attached here, so if anyone is interested, please please please let me know so we can fix bricked units and finally port TWRP to this underrated kids' tablet.
blakegriplingph said:
I dunno, but I thought maybe I could make a separate thread about a possible way to poke into the LeapFrog Epic's preloader so it could accept unsigned images. LeapFrog won't spill the beans for us, as their staff (falsely) claims to know next to nothing about it, so unless we somehow managed to social-engineer them into giving us a signed ROM or an unlocked bootloader, our only chance is to patch it so it would ignore the lack of digital signatures.
Click to expand...
Click to collapse
Bumping the thread.
Would also like to know is this is possible
If I may ask, how did you extract the strings from preloader and lk? Did you use a hexeditor or there is another app?
Gibz97 said:
Bumping the thread.
Would also like to know is this is possible
If I may ask, how did you extract the strings from preloader and lk? Did you use a hexeditor or there is another app?
Click to expand...
Click to collapse
I used this utility to do a strings dump off an Epic ROM:
http://split-code.com/strings2.html
It did turn up some interesting stuff but I was wondering if a binwalk or perhaps an IDA disassembly analysis would do wonders so we can finally poke into this tablet.
blakegriplingph said:
I used this utility to do a strings dump off an Epic ROM:
http://split-code.com/strings2.html
It did turn up some interesting stuff but I was wondering if a binwalk or perhaps an IDA disassembly analysis would do wonders so we can finally poke into this tablet.
Click to expand...
Click to collapse
Thanks for the tool but I cannot seem find a way to use it.
 @gursewak.10 or @smartmanvartan please chime in to help us because they were able to hack the preloader of k4 note and lk of RCA Viking Pro respectively
I also know a friend who is willing to donate a spare Epic, if that helps.
As for using Strings2, the following batch script should work:
Code:
@echo off
strings2 %1 > test.txt
pause
Just drag a binary to be analysed into the batch file, and a resulting text file with strings and stuff should be generated.
Hello friend
You need to tweak lk to unlock bootloader . i am giving you my phone's both files(.you can easily compare them.
on unlocked bootloader u can flash unsigned images via write memory option of SP flash tool .
Try HxD hex editor
gursewak.10 said:
Hello friend
You need to tweak lk to unlock bootloader . i am giving you my phone's both files(.you can easily compare them.
on unlocked bootloader u can flash unsigned images via write memory option of SP flash tool .
Try HxD hex editor
Click to expand...
Click to collapse
Hmm, I can flash the preloader to my leapfrog via SPFT, but not anything else. Write memory works, and I can flash stuff one at a time to it, but I couldn't get the tablet to force itself out of flash/download mode and into normal mode. There's no reset button, and not even taking the battery off does the trick.
However, on my working Epic, I can alter the demo system image, flash it back using Write Memory and still end up with a working device, just as long as the preloader isn't messed with in any way. Right now I am at a loss as to how to revive my other Epic, short of taking it apart and shorting KCOLO and GND. It also didn't help that the testpoints aren't labeled at all. :/
Also, I did a quick logcat while running the FOTA utility, and I managed to get a few URLs off the said logs. Problem is that while the ZIPs may be of some use, they're incremental and there doesn't seem to be a full scatter/zip image to restore a faulty unit. There definitely needs to be a way to patch the bootloader so we can do whatever we want to it, but is there any one of you guys who are experts when it comes to MTK modding?
Any more ideas?
Anyone, please?
Bumping in case there's anyone interested in poking into this.
Now this is interesting let us see what we can do.
Warrior1988 said:
Now this is interesting let us see what we can do.
Click to expand...
Click to collapse
You happen to have an Epic with you? Please let me know if you need more than just the firmware images. I've tried contacting LeapFrog regarding this issue to no avail. They did give my friend and I the kernel sources, but it's no use as the bootloader has to be unlocked for custom boot or recovery images to be used.
Is anyone willing to test if SP Flash Tool 5.1532.00 works on the Epic? I managed to flash a complete system image to a bricked Epic but I was unable to revive it as it has been bricked prior due to a botched preloader flash. The ROM's on my main Epic discussion thread, but one should take note to flash just the boot, recovery and system images and see if the device still works.
im also poking around in this since my volume up button doesnt work in bootloader mode
i have a figo gravity x55l
i can also upload the stock rom files that can be checked if needed
SP6RK said:
im also poking around in this since my volume up button doesnt work in bootloader mode
i have a figo gravity x55l
i can also upload the stock rom files that can be checked if needed
Click to expand...
Click to collapse
Are you able to muck around with LK or sbchk using IDA Pro or some other tool? Makes me wonder if merely deleting /system/bin/sbchk would disable boot-time checks or if there's more to it than just that.
blakegriplingph said:
Are you able to muck around with LK or sbchk using IDA Pro or some other tool? Makes me wonder if merely deleting /system/bin/sbchk would disable boot-time checks or if there's more to it than just that.
Click to expand...
Click to collapse
well i tried hex editors but lk.bin isnt decoded for my rom so half of my lk file is not showing me anything exept weird characters but i can see some of the other half.
if you delete the file...will it brick?...will it even boot?
GREAT NEWS I MANAGED TO GET ROOT WITHOUT UNLOCKING THE BOOTLOADER ALL YOU NEED IS TO
1.download your firmware and extract it
2.extract the boot.img from the firmware and put it on your phone REMEMBER WHERE YOU PUT IT SINCE YOU WILL NEED THIS!
3download magiskmanager install it and open it.
4click install and choose the boot.img it will install magisk into it
5.put it back in your firmware folder on your pc
6 look for a file that says Checksum_gen and run it
7 once that completes use spflash tool and load your scatterfile and flash JUST THE BOOT.IMG wait for the reboot and you have root!
THANK YOU DEVELOPERS OF MAGISKMANAGER!
SP6RK said:
GREAT NEWS I MANAGED TO GET ROOT WITHOUT UNLOCKING THE BOOTLOADER ALL YOU NEED IS TO
1.download your firmware and extract it
2.extract the boot.img from the firmware and put it on your phone REMEMBER WHERE YOU PUT IT SINCE YOU WILL NEED THIS!
3download magiskmanager install it and open it.
4click install and choose the boot.img it will install magisk into it
5.put it back in your firmware folder on your pc
6 look for a file that says Checksum_gen and run it
7 once that completes use spflash tool and load your scatterfile and flash JUST THE BOOT.IMG wait for the reboot and you have root!
THANK YOU DEVELOPERS OF MAGISKMANAGER!
Click to expand...
Click to collapse
What device are you referring to? Is this for an MT8127 tablet?
blakegriplingph said:
What device are you referring to? Is this for an MT8127 tablet?
Click to expand...
Click to collapse
i have a figo gravity x55l ? and it is not a tablet
it is a mt6753 great phone btw!
im a starting developer and got this phone so i can learn from my mistakes of course?
but this should work on any device that you can get a hold of its boot.img from its firmware

Someone has found the 9008 test point

I don't know if this was known or not but this could help some users if they could possibly make some program to fix hard bricks.
https://www.reddit.com/r/lgv20/comm...mm_9008_test_point/?utm_source=reddit-android
I'm gessing it's too late for this development.
faeterov said:
I'm gessing it's too late for this development.
Click to expand...
Click to collapse
No!! It's still not too late. Qualcom 9008 hack will save v20 community.
CrUxXxX said:
No!! It's still not too late. Qualcom 9008 hack will save v20 community.
Click to expand...
Click to collapse
How?
faeterov said:
How?
Click to expand...
Click to collapse
I'm not sure how? I'm not developer. Here's link
https://www.google.com/search?q=ins...#imgdii=IFxd7gUm4M6ZWM:&imgrc=ezDFnWnop-1xqM:
This sounds like the useless firehouse that people have been posting on xda for months and it's already been stated by several respected devs it won't work on the V20 and or it will put your phone in a state that is less than desirable
Sent from my LG-H910 using XDA Labs
Only in very rare cases will a hardbrick not result in 9008-mode. For those that have that problem, and if the phone can be restored with a "gps fix box" - then this will be helpful.
I'm wondering if it's possible to manipulate this TP to enter 9006-mode. Disturbingly I've never seen it mentioned anywhere a msm8996+ soc (or perhaps it's about the UFS storage) which has entered 9006.
Yes, the test point for 9008 on LG V20 is actually working....i tried on my phone....I need to find firehose for LG V20 to restore my phone....I accidentally chose wrong aboot version and hard bricked it.... Then tried this test point and it detected.
If any one has 8996 lge elf file, please share....
DroneJC said:
Yes, the test point for 9008 on LG V20 is actually working....i tried on my phone....I need to find firehose for LG V20 to restore my phone....I accidentally chose wrong aboot version and hard bricked it.... Then tried this test point and it detected.
If any one has 8996 lge elf file, please share....
Click to expand...
Click to collapse
I have no idea if you'll be able to get one if you aren't working for LG. Hopefully there's a 3rd party tool for sale or something
askermk2000 said:
Only in very rare cases will a hardbrick not result in 9008-mode. For those that have that problem, and if the phone can be restored with a "gps fix box" - then this will be helpful.
I'm wondering if it's possible to manipulate this TP to enter 9006-mode. Disturbingly I've never seen it mentioned anywhere a msm8996+ soc (or perhaps it's about the UFS storage) which has entered 9006.
Click to expand...
Click to collapse
Yea, 9006 mode is a thing of the past -- I want to say the 8x74 (SD800) was the last model to have it, but the 8992 (SD808) may have as well. Bottom line is that SD820 does not.
DroneJC said:
Yes, the test point for 9008 on LG V20 is actually working....i tried on my phone....I need to find firehose for LG V20 to restore my phone....I accidentally chose wrong aboot version and hard bricked it.... Then tried this test point and it detected.
If any one has 8996 lge elf file, please share....
Click to expand...
Click to collapse
Is that ALL you flashed was aboot? Is you abootbak still valid? If so, there is a firehose that you can use to change the boot LUN to boot from the *bak partitions. You don't want to use it to flash your phone, or, well, you won't really have a phone anymore. It would boot, but that would be about it.
EDIT: also, the firehose will work on any model v20 *except* the H918. Firehoses are RSA signed, just like the firmware.
-- Brian
runningnak3d said:
Yea, 9006 mode is a thing of the past -- I want to say the 8x74 (SD800) was the last model to have it, but the 8992 (SD808) may have as well. Bottom line is that SD820 does not.
Is that ALL you flashed was aboot? Is you abootbak still valid? If so, there is a firehose that you can use to change the boot LUN to boot from the *bak partitions. You don't want to use it to flash your phone, or, well, you won't really have a phone anymore. It would boot, but that would be about it.
EDIT: also, the firehose will work on any model v20 *except* the H918. Firehoses are RSA signed, just like the firmware.
-- Brian
Click to expand...
Click to collapse
Yes I have flashed aboot and device config also from other model rom, just usual fiddling with phone like any other
When phone booted, blank screen...only boot vibration felt.
You said that a RSA signed firehose is available, Mine is H990DS. If possible can you share the file or the link???
Cheers!!!
DroneJC said:
Yes I have flashed aboot and device config also from other model rom, just usual fiddling with phone like any other
When phone booted, blank screen...only boot vibration felt.
You said that a RSA signed firehose is available, Mine is H990DS. If possible can you share the file or the link???
Cheers!!!
Click to expand...
Click to collapse
Here you go...
So, good news, and bad news. I hadn't looked at this thing in a while -- so I figured I would take one more look now that I have a far greater understanding of Quallcomm security.
It turns out this is NOT a debug firehose -- it is perfectly normal firehose that can be used to rescue any v20 (except the H918 -- RSA mismatch, and LS997 (if it is ARB 1) -- this is an ARB0 firehose) with zero side effects.
Now the bad news.... because it isn't a debug firehose, you can't use it to change the boot LUN, so you will have to completely reflash your device. Well, you don't have to, but it is just as easy to make the files for a single partition as it is for the entire device.
Now the really bad news. This is just the programmer -- you are still going to need partition layout XML files, and I don't have time to make them for you.
-- Brian
runningnak3d said:
Now the really bad news. This is just the programmer -- you are still going to need partition layout XML files, and I don't have time to make them for you.
-- Brian
Click to expand...
Click to collapse
Apparently you don't have to. With QFIL you can fetch the partition table automatically from the phone, and manually select each partition to flash. Kind of like LGUP.
Here's a demonstration video: https://www.youtube.com/watch?v=gwMpDXPQLo8
It's by that aaya888 guy. Someone told me he "bought" firehoses from lg factory, and that he can unbrick H918, but he never replied to my inquiries.
Anyway that method above should work if the firehose works.
runningnak3d said:
Here you go...
So, good news, and bad news. I hadn't looked at this thing in a while -- so I figured I would take one more look now that I have a far greater understanding of Quallcomm security.
It turns out this is NOT a debug firehose -- it is perfectly normal firehose that can be used to rescue any v20 (except the H918 -- RSA mismatch, and LS997 (if it is ARB 1) -- this is an ARB0 firehose) with zero side effects.
Now the bad news.... because it isn't a debug firehose, you can't use it to change the boot LUN, so you will have to completely reflash your device. Well, you don't have to, but it is just as easy to make the files for a single partition as it is for the entire device.
Now the really bad news. This is just the programmer -- you are still going to need partition layout XML files, and I don't have time to make them for you.
-- Brian
Click to expand...
Click to collapse
Thanks Mate!!! thats a good help from your end. Do you have program that can create partition xml files....may be from the firmware i would try doing that...
If you have software from your end which could help me in creating the files....it would be great!!!
Cheers Mate!!!:good::good:
DroneJC said:
Thanks Mate!!! thats a good help from your end. Do you have program that can create partition xml files....may be from the firmware i would try doing that...
If you have software from your end which could help me in creating the files....it would be great!!!
Cheers Mate!!!:good::good:
Click to expand...
Click to collapse
Watch the video that @askermk2000 linked to in the post above. I had never used QFIL in flat mode before ... gotta love learning things.
The bottom line is as long as you haven't wiped out your partition tables, you don't need the XML partition definition files.
-- Brian
runningnak3d said:
Watch the video that @askermk2000 linked to in the post above. I had never used QFIL in flat mode before ... gotta love learning things.
The bottom line is as long as you haven't wiped out your partition tables, you don't need the XML partition definition files.
-- Brian
Click to expand...
Click to collapse
askermk2000 said:
Apparently you don't have to. With QFIL you can fetch the partition table automatically from the phone, and manually select each partition to flash. Kind of like LGUP.
Here's a demonstration video: https://www.youtube.com/watch?v=gwMpDXPQLo8
It's by that aaya888 guy. Someone told me he "bought" firehoses from lg factory, and that he can unbrick H918, but he never replied to my inquiries.
Anyway that method above should work if the firehose works.
Click to expand...
Click to collapse
runningnak3d said:
Here you go...
So, good news, and bad news. I hadn't looked at this thing in a while -- so I figured I would take one more look now that I have a far greater understanding of Quallcomm security.
It turns out this is NOT a debug firehose -- it is perfectly normal firehose that can be used to rescue any v20 (except the H918 -- RSA mismatch, and LS997 (if it is ARB 1) -- this is an ARB0 firehose) with zero side effects.
Now the bad news.... because it isn't a debug firehose, you can't use it to change the boot LUN, so you will have to completely reflash your device. Well, you don't have to, but it is just as easy to make the files for a single partition as it is for the entire device.
Now the really bad news. This is just the programmer -- you are still going to need partition layout XML files, and I don't have time to make them for you.
-- Brian
Click to expand...
Click to collapse
Finally, I restored my V20 H990DS, thanks to Brian and askermk2000 for sharing the right firehose and the tutorial.
Really, I love my V20, and restoring it through your help...made my day
Cheers to Both!!!:good::good::good::good::good::good::highfive::highfive::highfive::highfive::highfive:
DroneJC said:
Finally, I restored my V20 H990DS, thanks to Brian and askermk2000 for sharing the right firehose and the tutorial.
Really, I love my V20, and restoring it through your help...made my day
Cheers to Both!!!:good::good::good::good::good::good::highfive::highfive::highfive::highfive::highfive:
Click to expand...
Click to collapse
Thank you for verifying that all ARB 0 v20s (except the H918) are now unbrickable. Even if you mess up your phone so bad that it won't go into 9008 mode, we now have the test points.
I will be genning up the XML files that are needed in case someone messes their phone up SO BAD that they blow away the partition tables.
Glad you got your phone back!
-- Brian
RESTORE BRICKED-QDLOADER-9008-LG V20 H990DS, H990N, and other H990 Mobos.
Hi all V20 Owners...
CREDITS: ALL THE POINTS, REFERENCES, LINKS MENTIONED HERE ARE COLLECTION OF THREADS THROUGH WHICH I RESTORED. ALL CREDITS GO TO THE ORIGINAL AUTHORS OF RESPECTIVE THREADS AND DEVELOPERS.
If any one had fiddled with their phone and hard bricked them, here is the solution, which I rtried and Succedded in bringing back my phone.
Scenario: Being impatient for Oreo release for H990DS Indian variant, I have flashed H990N Oreo rom. Then VOLTE did not work. In order to gain that, i tried flashing modem from Nougat rom, then finger print stopped working... Then i flashed aboot, thinking that it would restore any security related issue and my FPR could be restored.
Boom!!! Device did not boot.
Then my research started from this XDA and Google. Found this below thread and tried everything in the order as described.
1. FINDING TEST POINT:
https://www.reddit.com/r/lgv20/comm...mm_9008_test_point/?utm_source=reddit-android
2. FINDING FIRE HOSE FOR V20 8996 SIGNED.
Googled all other forums on net and youtube. It was found that only latest QFIL can program it. But for that I needed firehose file.
Then followed everything on this link....
https://forum.xda-developers.com/v20/how-to/9008-test-t3855777
My special thanks to Brian for sharing the firehose file.....
BUT BE CAREFUL IN SHORTING THE TEST POINTS. ANY LITTLE TOUCH TO DIODES OR CPU HEAT SHIELD BESIDE MAY RENDER BOARD USELESS. I USED COPPER LEAD FROM NETWORK CABLE, WHICH EXACTLY MATCHES THE SPACE AND SHORT POINTS.
I know little knowledge on it so tried it.
Once again....I thank everyone who helped me to restore my Fav Phone...and Good Luck to all who would try this!!!!
I am getting hopeful about my download mode - stuck H910PR with "unknown device" error on patched LGUP.
I'd love to get my phone back up and running like a normal again. Is there a way out yet? I still have the v20... I even ordered AT&T board for it but that came with its own antenna connectors and has no service for GSM/3G/4G.
I stuck with no cellular H910 board or download-mode-stuck H910PR board. If there is a clear guide on how to do things to recover the H910PR board back up and running I'll be immensely grateful!
dark_prince said:
I am getting hopeful about my download mode - stuck H910PR with "unknown device" error on patched LGUP.
I'd love to get my phone back up and running like a normal again. Is there a way out yet? I still have the v20... I even ordered AT&T board for it but that came with its own antenna connectors and has no service for GSM/3G/4G.
I stuck with no cellular H910 board or download-mode-stuck H910PR board. If there is a clear guide on how to do things to recover the H910PR board back up and running I'll be immensely grateful!
Click to expand...
Click to collapse
How is your device getting recognised as in the windows device manager??? In ports&LPT, if it is shown as "
AndroidNet USB serial port", then follow this guide...
https://forum.xda-developers.com/v20/how-to/guide-lg-v20-to-life-t3827732
Cus, if LGUP recognises your device as Unknown, then the device must be recognised as above.
Try going through the process, you should be able to succeed.

[ROM] ZTE Visible R2 Stock firmware

Here is the stock firmware including the firehose needed to flash it
B10 Firmware
Here
B12 Firmware
Here
ZPI file for ZTE SalesMultiDL tool
Here
Here is a step by step guide on how to flash the stock rom with QFIL and by extension any image.
Download and install the Qualcomm drivers from here
Download the firmware from above
Extract the firmware to a folder that you can easily access them from like your desktop
Download and install QPST from here
Open the QFIL application (Find it in your start menu)
In the "Select Build Type" field select Flat Build
In the "Select Programmer" field navigate to the folder you extracted the firmware and support files to and select the prog_emmc_firehose_8917.mbn file
Select the "Load XML" button and navigate to the folder you extracted the firmware and support files to and select the rawprogram0.xml and then the patch0.xml when prompted.
Plug in your tablet
Run the following adb command "adb reboot edl" (Now the screen should be blank but the led light should be red)
If the text at the top of the QFIL application says "No Port Available" click the "Select Port..." option and pick your device. If your device isn't showing up there you didn't install the drivers properly.
Click the Download Button to begin flashing your device
Here is the Stock wallpapers in case anyone wants them
https://www.androidfilehost.com/?fid=1395089523397903558
I just got this device a couple days ago and was hoping I could use PDANet/Foxfi to connect more than one device at a time to wifi hotspot but they've evidently blocked the apps.. Do you have any insight to that?
pegb856 said:
I just got this device a couple days ago and was hoping I could use PDANet/Foxfi to connect more than one device at a time to wifi hotspot but they've evidently blocked the apps.. Do you have any insight to that?
Click to expand...
Click to collapse
I don't own this device sadly just grabbed the firmware for a friend of mine and posted it here in case anyone in the future wants it.
deadman96385 said:
I don't own this device sadly just grabbed the firmware for a friend of mine and posted it here in case anyone in the future wants it.
Click to expand...
Click to collapse
Ok thank you for the reply.
deadman96385 said:
I don't own this device sadly just grabbed the firmware for a friend of mine and posted it here in case anyone in the future wants it.
Click to expand...
Click to collapse
If you WANT to own this device it's currently $19 out the door on visible.com. No Trade required.
https://slickdeals.net/f/13221781-visible-r2-is-now-19-without-service-or-trade-in-requred
I'm gonna see if I can flash Chinese firmware to unlock the bands
Bowsa2511 said:
I'm gonna see if I can flash Chinese firmware to unlock the bands
Click to expand...
Click to collapse
Good Luck finding the A0722 firmware (that's the model androidpolice thinks this is a renamed version of).
famewolf said:
Good Luck finding the A0722 firmware (that's the model androidpolice thinks this is a renamed version of).
Click to expand...
Click to collapse
https://imgur.com/yOe0vIx
Your elite google-fu obviously exceeded my own. Please make that sharable if you can....megaupload.nz would hold it and is free.
famewolf said:
Your elite google-fu obviously exceeded my own. Please make that sharable if you can....megaupload.nz would hold it and is free.
Click to expand...
Click to collapse
https://mega.nz/#!aRo0CaBA!nm37c3V11tr2260V23wIxb4yZufD5-_f6gID8i3HjSY
Let me know if it's helpful
DISREGARD. Looks like out of date info.
Any of you able to get fastboot working on it? ADB works, but my fastboot doesn't detect the phone.
Nice looking out, just ordered one.
Using one of the hidden activities app from the play store. There is an option to change from LTE to 2G/3G/4G under one of the phone settings. But calling still did not work with either AT&T or T-Mobile.
famewolf said:
Good Luck finding the A0722 firmware (that's the model androidpolice thinks this is a renamed version of).
Click to expand...
Click to collapse
Just a heads-up: even if you found the files for the A0722, you'd brick your R2 if you managed to flash them. The chassis and screen seem to be the same, but they're completely different specs-wise. Given that the A0722 has a different SoC and an eMMC chip 2-4x larger, I doubt you'd get real far in the flashing process in the first place.
FEGuy said:
Just a heads-up: even if you found the files for the A0722, you'd brick your R2 if you managed to flash them. The chassis and screen seem to be the same, but they're completely different specs-wise. Given that the A0722 has a different SoC and an eMMC chip 2-4x larger, I doubt you'd get real far in the flashing process in the first place.
Click to expand...
Click to collapse
In my case my main goal was to use it and the factory software to learn about mbn files. I've dealt with LG's TOT and KDZ files but not the mbn's. Thanks for giving folks the warning though.
Would it be possible for someone to grab the download URL for whatever OTA update is available for the device? I don't think it's anything major but I'd like to poke around at it; the firmware uploaded here seems to be from launch.
FEGuy said:
Would it be possible for someone to grab the download URL for whatever OTA update is available for the device? I don't think it's anything major but I'd like to poke around at it; the firmware uploaded here seems to be from launch.
Click to expand...
Click to collapse
I've got a logcat recorder queued up to be installed and will try to grab an url by starting the download. If that fails there are a couple of alternatives....someone who has DONE the upgrade could rip the rom and make it available if @deadman96385 can point to some instructions on how to rip the rom.
Also you can always let your own upgrade occur because he's already provided the original software and QFIL which would let you restore to original factory and get the update again.
As a last resort I can grab the log from my ROUTER that the phone is connected to and try to get the url that way which I've had to do with SOME devices.
I'll probably end up taking the OTA again anyways as I've been messing around with the firmware from the first post. Honestly, I'd really recommend staying away from flashing it without a good reason. Even when the flasher works, either the logging and/or the flasher hangs and it's close to impossible to tell which without unplugging your phone. If a partial flash leaves you in a state where you can't get to ADB to boot to EDL mode, you'll have to boot into diagnostics mode, use a piece of Chinese software to boot from there back to EDL, and within five seconds or so, close that software and start the flashing process from QFIL before the com port stops responding to requests, leaving you to reboot the phone and start again.
I've been trying to get non-LTE networks and calling working, but it's entirely impossible to tell whether my tweaks are having unintended side effects or if the flashing just crapped out partway through, even when I'm just flashing single partitions.

Categories

Resources