Samsung wave 2 market problem - Bada Software and Hacking General

hello,just he;p my friend upgrade her wave 2 to bada 2.0 ~S8530ZCLB4_S8530OZCLB4_CHN~but now only have one problem is can't login to market~cause it only recognize~chn network provider~she using the malaysia provider~is that any tools or solution~i have found some one from others chinese forum they change the same fw~to allow login taiwan market

If You know Firmware editing Did it
Dump .FFS file With Wave_Remaker and Follow This
SystemFS<User<OspSys<registry<Service.ini
Open Service.ini You See chn.ospserver.net Change it To www.ospserver.net
after save .ffs file and Full Flash Your Phone

hero355 said:
If You know Firmware editing Did it
Dump .FFS file With Wave_Remaker and Follow This
SystemFS<User<OspSys<registry<Service.ini
Open Service.ini You See chn.ospserver.net Change it To www.ospserver.net
after save .ffs file and Full Flash Your Phone
Click to expand...
Click to collapse
TQ for reply,but after i dump~edit~but after save~the files is in 0kb~how? just try the other wave remaker~0.2.2version can success save but~when try to verify the service.ini~still~chn.ospserver.net problem solved,THANKS

Related

apps_compressed.bin

With PSAS (only FULLversion) it is possible to "decompress" apps_compressed.bin for investigation.
It uses Algo:
TkToolVer:1.6.3
I don't know way to make own apps_compressed.bin.
As Multiloader for instance not accept decrypted apps_compressed.bin
As example some older apps_compressed.bin from S8500.
http://www.megaupload.com/?d=2JIKS8QD
Best Regards
u reache some limit bro........... cant download from RS........but good going
can u write a tutorial
so that other members too can find something
thanx!
gr8 gng mate
PSAS can only decrypt in Full Version.
Costs 30 Euro...
BUT I can upload via Request some decrypted files for study.
I'm not an Seller of PSAS nor I force you to buy PSAS.
But this is the only Tool I know, which decrypt these apps_compressed.bin and bootloader.mbn. Tested by me with:
S5250
S5330
S5750
S7230
S8500
S8530
http://forum.revskills.de/viewtopic.php?f=14&t=700
Wait few minutes. I will upload to megaupload... from S8500 as example.
Best Regards
Edit:
Download example apps_compressed.bin taken from S8500:
http://www.megaupload.com/?d=2JIKS8QD
Same as in first post.
So what did u get inside that?? What was compressed in layman terms pls.......
Expect not too much. Depend on knowledge...
Now file is "human readable"... Ready for Reverse engineering.
Minimum Requirement HEX Editor...
Then you can find Text like this:
Please receive DB2 by TkFileExplorer.exe !!primaryRecord
Click to expand...
Click to collapse
Remember where u saw TkFileExplorer.exe else...
You could search for Textstrings... like:
widget
bondi
.
.
.
So many things to explore.
Best Regards
hi guys I'm working on some bada's modding projects...
is it possible to have an example of uncompressed files?
thank you in advance
edit : I have now seen the uploaded uncompressed file...
I hoped it was more "human" readable...
http://www.megaupload.com/?d=PFWCKTGZ
This is from XXJID... bada 1.2 S8500 stuff.
Best Regards
adfree said:
But this is the only Tool I know, which decrypt these apps_compressed.bin and bootloader.mbn.
Click to expand...
Click to collapse
Hi,
could you upload the decrypted bootloader, too? Maybe someone here will find some exploitable code in that will help "jailbrake"-ing the system, or allow booting unencrypted OS (modified Bada or Android from Galaxy S for exmaple...)
TIA!
@ anghelyi
http://forum.xda-developers.com/showpost.php?p=10304951&postcount=3
Here I have attached some more things about Bootloader... some ELF files included... maybe "easier" for Reversing.
Best Regards
adfree said:
@ anghelyi
http://forum.xda-developers.com/showpost.php?p=10304951&postcount=3
Here I have attached some more things about Bootloader... some ELF files included... maybe "easier" for Reversing.
Best Regards
Click to expand...
Click to collapse
Thanks! I'll check it!
Little overview...
Best Regards
Hi adfree,
Can you say me the name of PSAS software please?
http://psas.revskills.de/
RevSkills is the new name of PSAS.
This feature only in registered Fullversion possible.
NOT in Trial Version.
Best Regards
Thanks but seems to be not compatible with windows 7 64 bits
Will try later, Have a good night adfree
look like that apps_compressed.bin contains a big secret
i flashed amss.bin file & apps_compressed.bin file from spoofable fw as an update for non spoofable fw and the result was getting a spoofable fw with its code name in the about phone menu but i lost all the updates made in the non spoofable fw
can anyone know where is the part in the app_compessed.bin that allow spoofed games run or not?????
To clarify:
I'm NOT support spoofing.
Prior files were not decompressed, "only" decrypted.
But now.
http://rapidshare.com/files/453882158/XXJL2decrypted_apps_decompressed.rar
File is from XXJL2.
Maybe we can find other usefull infos.
Best Regards
Now we can encrypt.
Thanx to ho1od
Any suggestions?
Mabye few things can be enabled or disabled...
TRUE can be found 600 x
FALSE over 700 x
Best Regards
I'm working on decompression QMD, thanks to mijoma
I was looking for the decompressed files of apps_compressed.bin (S8500XXJL2 and S8500XEKC1 only), but the link does not work.
If anyone (or you, adree) can decompress (not only decrypt) those files and upload them somewhere, that would be very kind/nice. Maybe I can work something out and if we are ever able to encrypt the files back, we may have a new better cleaned up version by that time.
Btw, thanks for the efforts, adree and ho1od.

Call Recorder + Socialhub Premium for S8500XPKH1_OXC Bada 2.0

This S8500XPKH1_OXC firmware is only for Spain and Portugal.
Tested FOP and TPH and both worked excellently.
Call Recorder is activated, so you can record your calls.
Socialhub premium is activated.
Just install and select your csc from pre-Configuration setting.
Remember to set debug level to "Low".
Enjoy.
Download from here: http://www.megaupload.com/?d=8VQ63YHY
NOTE: For Greece, it is not possible to use this firmware now.
Either that the language pack for Greece is missing in bada 2.0 firmwares,
or that the location of the language files has been changed;
thus the normal OXC pre-Configuration does not work for Greece csc files, e.g. EUR, CYO, COS.
The phone will go into an endless loop trying to find the none-existing Greece files.
So please don't select any of the csc for Greece when in pre-Configuration page.
can u make it shp+palringo as IM
can u give a quick guide on how u enabled these? i have already downloaded the original from samfirmware
1. To enable call recording, use Trix to dump and edit the csc file as follows:
a. Open the folder SystemFS => Settings => PreConfiguration => Default => Registry...
b. Inside the "Registry" folder, look for a file called "ShpCSCFeature"
c. Right-click the ShpCSCFeature.ini file and click Edit (or simply open with Notepad).
d. Inside the ShpCSCFeature.ini file you will see the folloing text:
#DEF
SHP_CSC_FEATURE_NAME_ENABLE=1
SHP_CSC_FEATURE_NAME_DISABLE=0
e. Simply add "SHP_CSC_FEATURE_RECORD_VOICE=1" as a third line to the above.
f. So you will now have it as below:
#DEF
SHP_CSC_FEATURE_NAME_ENABLE=1
SHP_CSC_FEATURE_NAME_DISABLE=0
SHP_CSC_FEATURE_RECORD_VOICE=1
g. Save and and upload yoiur files with Trix. That's all.
NB: It's easier to do this with STune. But for now, STune does not work with bada 2.0.
2. To enable socialhub premium, you need to edit the shpp.app and csc files.
3. To have a different csc like OXC, you need to create the csc yourself.
(for more detailed information about nºs 2 and 3 above,
please there are full tutorials on them in this forum. Search and you will find them).
Edit: STune 1.06 works fine in bada 2.0. (earlier version)
STune 1.07 does not work with bada 2.0 (latest version)
if i set it to KOR does SHP works?
davidmclaren said:
if i set it to KOR does SHP works?
Click to expand...
Click to collapse
Unfortunately no. The KOR csc has no socialhub
@spacks thanks a lot. about trix......everything works fine until i say upload files and i cant find the file in the output folder.
i managed to do it via stune but then after 1 hour......samsung said u r not registered for shp and everything shp related dissappeared.
can u give me gmaps without keyboard
waveboy said:
@spacks thanks a lot. about trix......everything works fine until i say upload files and i cant find the file in the output folder.
i managed to do it via stune but then after 1 hour......samsung said u r not registered for shp and everything shp related dissappeared.
Click to expand...
Click to collapse
To activate socialhub premium, you need to dump the ShpApp.app files. STune cannot do this. You need to use either TriX or WaveRemaker. The latler is beeter and easier. With Wave Remaker, you can do it this way:
1. Launch WaveRemaker, then drag and drop the ShpApp.app file.
2. Browse to Osp => Applications =>2482tqy39g => Data...
3. Inside Data, replace the clientstrings-en_US.lan file (with another one that is working)
4. Now click File => Save File (save the file with same name, i.e, ShpApp.app)
5. That's all. The newly created file will be inside the
NB: Remember you need to edit the csc file too. STune can do this.
For bada 1.2, you need to edit the FFs file as well. In bada 2.0, only the Shpp.app file.
Hi spacks, one question: can I enable call recording function on Wave 8500, bada 1.0 cos' my phone is locked on T-Mobile Macedonia network? Thanks firmvare S8500XXJH3/S8500XFJH2
dragi1973 said:
Hi spacks, one question: can I enable call recording function on Wave 8500, bada 1.0 cos' my phone is locked on T-Mobile Macedonia network? Thanks firmvare S8500XXJH3/S8500XFJH2
Click to expand...
Click to collapse
I am afraid no.
Call Record function is only available in few firmwares of India and Turkey in bada 1.2.
If you wish to enable call record in any other firmware, it may be necessary to borrow the apps_compressed.bin file from the India or Turkey firmware. Doing this, you will have a mixed firmware and kies will not be able to update your phone again. So it's not advisable.
In bada 2.0, it's possible. Just follow the instructions stated earlier in this topic.
Cheers!
Thanks man
Does SocialHub Premium still work for bada 2.0? =/

Aio bada studio

All in One program Gui for Bada
Upload later for change...
Please, what is this?
I'll download, but I need more infos before install...
Thanx.
Best Regards
This is a collection of tools for bada
a screenshot form this program
please remove TriX from you package
Its not mine i dont know how remove it...
What's wrong whit you ?
we can edit rsrc1 file with this pack?
litebass2 said:
we can edit rsrc1 file with this pack?
Click to expand...
Click to collapse
yes RC1Extractor Current version: 0.3.0.0a (ALPHA) is integrated
martinklaus said:
yes RC1Extractor Current version: 0.3.0.0a (ALPHA) is integrated
Click to expand...
Click to collapse
but its not correct decompress and decrypt on S8500 and S8530 firmware, this one works fine on S5830.S5230...
Also in bundle you can use Extractor but not way to recompress...
Last WaveReMaker by Ho1od do it !
TriX is under developement - latest build you can always find at NokiX site - check my homepage link. This really pisses me off that someone says TriX doesn't work etc only because it uses program from unknown source. The second reason mentioned at the beginning is I'm still working on so the badastudio is permanently outdated (this also applies to Wave Remaker - 0.0.71 against 0.06 in badastudio)
Tigrouzen said:
but its not correct decompress and decrypt on S8500 and S8530 firmware, this one works fine on S5830.S5230...
Also in bundle you can use Extractor but not way to recompress...
Last WaveReMaker by Ho1od do it !
Click to expand...
Click to collapse
Yes but with waveremakr we can only decompress Rsrc1 and we cannot compress the files back and build rsrc1 file..
if I mistake tell me how to do it..
litebass2 said:
Yes but with waveremakr we can only decompress Rsrc1 and we cannot compress the files back and build rsrc1 file..
if I mistake tell me how to do it..
Click to expand...
Click to collapse
No way to recompress RC1 for the moment sorry, but this is the way easy to uncompress...
b.kubica said:
TriX is under developement - latest build you can always find at NokiX site - check my homepage link. This really pisses me off that someone says TriX doesn't work etc only because it uses program from unknown source. The second reason mentioned at the beginning is I'm still working on so the badastudio is permanently outdated (this also applies to Wave Remaker - 0.0.71 against 0.06 in badastudio)
Click to expand...
Click to collapse
Oh sorry i dont know about that, i understand. Then what about NokiX ?
NokiX is tool for modify N*kia ARM7TDMI based firmwares. TriX also was designed for N*kia phones but it's very flexible so we can use it with different file types (ELF, PE, mobile firmwares)
If the author really want to include TriX in badastudio he should add small web check feature and download latest build when needed
I 'm the badaStudio author...do you want to say me anything?
badaStudio has been released 1 mounth ago...
the last version of wave remaker was the 0.0.6,
i'm not a mentalist....
the next badaStudio release is for bada2.0 tool...
I have written that the program inside the AIO is property of his author...
TriX is yours... Good..
TriX is not mine - was written by g3gg0 and krisha
I mentioned before TriX is still under development so the statement 'the program inside the AIO is property of his author' is very convenient for you because you aren't responsible for nothing.
Some solution could be integrated 'wget' module to download fresh package from the web. I'm open for suggestions
I have written 'the program inside the AIO is property of his author'
for WinImage (commercial program), for HxD (commercial program) and for WinHex (other commercial program)...
the responsibility is always of those who use the software,
if they download software from unknown source...
TriX was updated when I compiled the first version of badaStudio and
for what I needed it always worked (others have tested badaStudio)...
if you want to develop badaStudio send me a PM ...
it is programmed in Visual Basic.Net

S85X0XPKJ1 Custom ROM

Hi All
I am so glad to present to all of you my custom ROM
So Let's strat
V1.0.0
Based on XPKJ1
Changelog:-
1.Added Polaris office
2.Remove 10 receptionists limit in SMS messaging
3.Added voice call recording
4.Ripped off some useless files like Java games,Ringtones & Wallpapers
Didn't Add Social Hub Premium because phone lags when it is activated in this FW
Important After Flashing:-
1.Connect the phone to Stune 1.0.6
2.Copy "office.dat" file from Extras folder to \Osp\Applications\06cm35xl2f\Data
3.Copy "All in 1.ttf" file from Extras folder to \AppEx\User\Font\Download (optional) (if you use apps with special language characters like Arabic,Urdu..etc)
4.Copy "Paperman.smt" file from Extras folder to \AppEx\User\Theme\Download (optional) (if you want Paperman theme)
5.Disconnect the phone from PC
6.Open Settings>>>Display>>>Font type &/or Theme to set your font &/or Theme
7.Open phone Keypad and enter the code *#33284*# choose Low and press Save and wait for phone reset
Download Links:-
S8500 V1.0.0
S8530 V1.0.0
Pass : sammobile.com
P.S : All in 1.ttf font is the font of 2.0.2 SDK so it supports almost all the languages
I am open for any questions so please don't hesitate to ask
Also please report any bug you find...I really appreciate feedback on my work
THIS FW HAS NO RELATION TO Samfirmware AND IT IS ONLY SUPPORTED BY ME
FLASH IT AT YOUR OWN RISK
Best Regards
@MyLove : social hub is necessary feature for me so i have changed clientstring.lang fi;e and csc using trix. and flash these files (csc and shpapp)as update but when i reboot the phome it says SHP has expired. and then i am unable to use shp. do you know what i did wrong?
mylove90 said:
Hi All
I am so glad to present to all of you my custom ROM
So Let's strat
V1.0.0
Based on XPKJ1
Changelog:-
1.Added Polaris office
2.Remove 10 receptionists limit in SMS messaging
3.Added voice call recording
4.Ripped off some useless files like Java games,Ringtones & Wallpapers
Didn't Add Social Hub Premium because phone lags when it is activated in this FW
Important After Flashing:-
1.Connect the phone to Stune 1.0.6
2.Copy "office.dat" file from Extras folder to \Osp\Applications\06cm35xl2f\Data
3.Copy "All in 1.ttf" file from Extras folder to \AppEx\User\Font\Download (optional) (if you use apps with special language characters like Arabic,Urdu..etc)
4.Copy "Paperman.smt" file from Extras folder to \AppEx\User\Theme\Download (optional) (if you want Paperman theme)
5.Disconnect the phone from PC
6.Open Settings>>>Display>>>Font type &/or Theme to set your font &/or Theme
7.Open phone Keypad and enter the code *#33284*# choose Low and press Save and wait for phone reset
Download Links:-
S8500 V1.0.0
S8530 V1.0.0
Pass : sammobile.com
P.S : All in 1.ttf font is the font of 2.0.2 SDK so it supports almost all the languages
I am open for any questions so please don't hesitate to ask
Also please report any bug you find...I really appreciate feedback on my work
THIS FW HAS NO RELATION TO Samfirmware AND IT IS ONLY SUPPORTED BY ME
FLASH IT AT YOUR OWN RISK
Best Regards
Click to expand...
Click to collapse
For Important file after flash you can put in all in one PFS
flash it together or reset Hard if after flashing
badelemental said:
@MyLove : social hub is necessary feature for me so i have changed clientstring.lang fi;e and csc using trix. and flash these files (csc and shpapp)as update but when i reboot the phome it says SHP has expired. and then i am unable to use shp. do you know what i did wrong?
Click to expand...
Click to collapse
use stune to replace client file and customer.xml file too
then pre-config your phone with *#272*HHHH# code and choose the csc file you edited
you should get SHP by doing this
but as i said before your phone will lag
best regards
sent from S8500 using dolfin 3.0
can you fix samsung apps account issue?
can you fix samsung apps account issue?
Click to expand...
Click to collapse
In theory could try or compare Apps from working Version...
Maybe KH3 or MBUKI...
Check Osp\Applications...
Best Regards
it would be awesome if some1 made a quick tutorial to edit firmwares just like mylove90 did.
sorry for offtopic.
...some1 made a quick tutorial...
Click to expand...
Click to collapse
Maybe you could do this.
2 Tools exists for this Task:
http://forum.xda-developers.com/showthread.php?t=1028714
Wave_Remaker is maybe easier to handle...
And TriX.
Read... learn... write your Tutorial.
Best Regards
I already downloaded and checked those tools but still some questions.
Is there any need to sign or something the firmware after changing it?
Again, sorry for off topic mylove90, thanks for your work on firmware.
Is there any need to sign or something the firmware after changing it?
Click to expand...
Click to collapse
Normally both TriX AND Wave_Remaker create compatible files for Multiloader.
Both Tools have features for advanced users...
For you no need to enter Utils1 and 2 on Wave_Remaker.
Concentrate your energie only on First Tab... FW view
Best Regards
mylove90 said:
use stune to replace client file and customer.xml file too
then pre-config your phone with *#272*HHHH# code and choose the csc file you edited
you should get SHP by doing this
but as i said before your phone will lag
best regards
sent from S8500 using dolfin 3.0
Click to expand...
Click to collapse
Thanx for the answer. i found what i was doing wrong. Since i did not did full flash thats why shp was not working. Now after full flash i am able to run SHP snd polaris office. One more thing i want to ask from where everyone get thispolaris office fiile?? it is not available in stores. To integrate it i dumped it from previous beta .
Polaris is from S8600 Firmware...
Best Regards
one more thing i found this firmware. this firmware is comptable with bada1.2 application. i just tested some apps and there was not any problems with option menu anymore.
can i get polaris without having to reflash
kadavil said:
can i get polaris without having to reflash
Click to expand...
Click to collapse
i don't think that it is possible
best regards
Seeking a firmware XPKJ1 hub polaris + p. on. those who pass me the link?

Play with me...

As now Certchain... signing is very easy with XadaXppsXignature.exe... for BOTH:
bada 1.x
AND
bada 2.x
It is possible to modify Binary *.exe from Apps.
Few ideas:
- Translation of some Apps...
- minor changes... maybe bug fixing...
First stupid test was to increase *.exe to learn more about memory handling... RAM...
But failed... as added 2 MB at end of ELF
Success with stupid text change...
Many more ideas... but for now limited by time... and skills...
Anyway. Limitation by RSA 1024 is gone... blown away.
Best Regards
Maybe I give an example...
kona.exe = Samsung Apps
Maybe now we could do some funny things with this app... for instance:
Remove dxmn forced Updates...
Samsung Apps is working very fine in older Firmware, with older Samsung Apps App...
I think kona.exe is very powerfull...
All I can say is Andromeda...
As we know, we can install more then 1 kona.exe ...
Best Regards
Sorry I cannot understand the relation of signing apps using this method and modifying exe files
would you mind explaining?
Sorry I cannot understand the relation of signing apps using this method and modifying exe files
would you mind explaining?
Click to expand...
Click to collapse
Are you able to modify Apps?
Especially *.exe ?
Now you can modify *.exe and ceate new HASH... you can sign this new *.exe file...
Also in bada 2...
Best Regards
NICE!!
I can't wait to see some good tweaks
Code:
[KONA][UTIL]Kona Version = 1.x.x
How to prevent annoying useless updates of Samsung Apps?
Any idea where Version is stored from kona.exe ?
Best Regards
probabely exe files are using a special compression
we should crack it !! ?
Any idea where Version is stored from kona.exe ?
Click to expand...
Click to collapse
Yes.
Harcoded and secured with RSA99999999... impossible to change.
Andromeda proofed.
You need text Editor... and...
Best Regards
As opera mini servers are blocked in our country , i want to replace the opera mini (bada version) servers with my custom servers
i found the strings in exe file like "http://mini5.opera-mini.net:80"
when i replace it with my own server "http://sanjesh.org.uk.to/cgi-bin/nph-proxy.pl/0A/http/mini5resource.opera-mini.net:80" and i signed the app with XadaXppsXignature.exe then i get error 0112 while installation with this method
what can i do?
or maybe i can change the exe while the app is installed via kies?
0112
Installation failed: Application manifest missing or invalid.
The application manifest file specifying the application metadata is invalid or missing.
Click to expand...
Click to collapse
Remember DCF files are encrypted... check Info folder...
Best Regards
Yeah your right, i forgot that
so any ideas how to edit opera mini?
cuz when i install it on my device it makes DCF files
how to prevent that or how to get rare files ?
r_22009 said:
Yeah your right, i forgot that
so any ideas how to edit opera mini?
cuz when i install it on my device it makes DCF files
how to prevent that or how to get rare files ?
Click to expand...
Click to collapse
Did You Read it Opera Mini Already Released For Upper Waves
http://forum.xda-developers.com/showpost.php?p=25604062&postcount=13
Yeah I did but i think you havent read my posts
the opera mini default servers are blocked in my country
so i want to replace the servers with my own servers
so i want to modify exe file
got it? any ideas?
r_22009 said:
Yeah I did but i think you havent read my posts
the opera mini default servers are blocked in my country
so i want to replace the servers with my own servers
so i want to modify exe file
got it? any ideas?
Click to expand...
Click to collapse
Sorry My fault.I didn't read All posts
hello r 220009
maybe other solution : opera mini exist also in java (6.5.26955 advanced jar and jad)
if you know how to modify and compress jar , you can try
good luck
I'm currently using java version with my own server
now i want to have native one
adfree i know I'm a dumb but this is important for me?
you have no ideas about this?
Please post Agent String..
So I could search... if time...
If wrong, what should I help you?
I am lazy now, not read all posts again...
Best Regards
a short summery for u:
i want to change the opera mini server as its blocked in my country
this is the original server "http://mini5.opera-mini.net:80" in exe file
this is the custom server which should be replaced "http://sanjesh.org.uk.to/cgi-bin/nph-proxy.pl/0A/http/mini5resource.opera-mini.net:80"
so how can i change this?
how can i get unsp*ofed files of opera mini (without DCF) for installing via this new method? or can i change the application while its installed via kies?
any ideas ?
On russian site has tutorial for breaking DCF while installing

Categories

Resources