Long road almost there, error 67 :( calls & text ) but no data :( [evo on boost]
THE GOOD AND BAD NEWS... THE GOOD NEWS FIRST! i got my evo4g over to boost mobile with my boost account i already had open i can outgoing text and recieve text (no mms right now) i can call out and get calls in, works great shows my boost cell phone number on my evo and everything..
NOW THE PROBLEM...
my DATA doesn't work at all... i get the error 67
I TRIED THESE INSTRUCTIONS AFTER SEEING MY DATA DIDNT WORK..
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
If data is not working move on to the next steps...
(Note: These are steps not verified by me as I still dont have neither 1x nor Evdo working but some people say 1 or 2 or all of these following steps combined worked for them, so i guess it depends on the network you are trying to get on)
1. First attempt to update your profile if it can or update PRL
Menu>Settings>About Phone>System Updates>Update Profile
Reboot and see if data works....
2. If still no Data, plug in your Hero to the computer, dial ##3424#, go to QPST folder and open QPST Configuration app.
Under the Ports Tab if the active COM port your phone is on is not in that list Click Add Port and add it.
Then go to Active Phones Tab, select the phone and then go to Start Clients>Service Programming
A new window opens, hit ok, then click Read From Phone on the bottom left, its gonna ask you for your MSL type it in
Then go to the M.IP Tab and under user profiles click on profile 0, click edit, and then deselect Profile Enabled, hit ok, then click Write to Phone.
Close the program unplug your hero, reboot it, and try your data again.
3. If still no data, plug in your old phone to the computer, open up QXDM
check Connections and make sure your COM port is being read.
Go to View>New>Common>NV Browser , in the Category Filter drop down menu, filter only Data
Then scroll down to ID numbers 1192 and 1194
Click read and copy down all the values in there until u reach 0x00
Then unplug your old phone and plug in your hero, dial in ##3424# and go to NV Browser
navigate to the same ID numbers 1192 and 1194, (just to be safe copy all the values here so you can revert back to the originals)
Then double click each value under the input column and it becomes changeable and change all the values to the ones from your old phone and hit write
Close QXDM unplug and reboot your hero, test Data again
4. If still no data, plug in your old phone to the computer, open up QXDM
check Connections and make sure your COM port is being read.
Go to View>New>Common>NV Browser , in the Category Filter drop down menu, filter only Data
Then scroll down to ID numbers 465 and 466
Click read and copy down all the values in there until u reach 0x00
Then unplug your old phone and plug in your hero, dial in ##3424# and go to NV Browser
navigate to the same ID numbers 465 and 466, (just to be safe copy all the values here so you can revert back to the originals)
Then double click each value under the input column and it becomes changeable and change all the values to the ones from your old phone and hit write
Close QXDM unplug and reboot your hero, test Data again
NONE OF IT WORKED.... SO I WENT TO THE SECOND SET OF INSTRUCTIONS.
Run the QPST config and plug in your phone, make sure your phone is detected in the COM port list. If not click Add New Port and add the one that it has detected your phone on. What it says may vary but USB will often be in the description.
Run QXDM click Options -> Communications and set the Target Port for the same one QPST config listed for your phone.
In the command box at the top type "spc 000000"
Note: If your SPC is not 000000 then you need to use the correct number instead!
If successful you will see a window titled "Command Output" that will output some text with the final line reading "SPC Result = Correct"
Next in the command box type "requestnvitemread ds_mip_ss_user_prof"
This will get you a lot of stuff in the Command Output window. It will start with the "DIAG TX item" section, ignore this one, we are interested in the "DIAG RX item" part.
The actual keys are 16 lines and marked in the output as 0-15. You will notice that quite handily both HA and AAA are both there. Take the part after the "0x" and that is actual key data. Just write down (or use word, notepad, whatever) to record this for safe keeping.
If you are doing this right then you have a long string of 30 characters all strung together for each key. DOUBLE CHECK YOUR COPYING! A single mistake will cause this to fail.
Putting the keys back into the phone:
Load QPST service programming, go to the M.IP tab. Double click profile 0 (in the white box) and use "Enter hex value" to enter your backups of your HA and AAA keys.
Write to phone.
Soft reset. (may not be required but I do it for good measure)
do "requestnvitemread ds_mip_ss_user_prof" for the sprint info and "requestnvitemread ds_mip_ss_user_prof 1" for the boost info
I'm telling you.. If you're getting the error 67, the following these steps above will fix it.. I'm on the Sprint network and the problem i was having was, in "Profile 0" The username which began with A000000 (this is actually your ESN #) Was from the original phone, not the donar phone... So i took the battery out the donor phone and looked at the ESN (not DEC) and began to type A00000 etc.
Then i used the steps above to get AAA Shared Secret from the Donor phone.. My AAA Shared Secret was 32 Alpha numeric characters...
i did that and still no dice.... i got the AAA key and the HA key .. both were 32 characters...
i even went as far as to get the profile info from the incognito phone, for profile 0 and 1, and made it exactly the same on my evo and addresses for the HA and alternate HA ADDRESS... still no dice.. i went into debug mode on my evo and even hit the restore to start fresh , and let it download the data via the servers... still didnt work...
i even re-entered the profile info and etc, for profile 0 and 1, and still not working
i know im close i just need to finish the puzzle please help.
oh yea, and when i go into debug mode it shows the authentication as failed.. i dont know how thats even possible I've triple checked the HA AND AAA keys via QXDM and they are the correct keys from the incognito boost phone.
I am going to show you how to get the epic 4g to to metropcs.
First thins is first, you need to get the esn added to metropcs.
If you cant add the esn in the inventory it will not work.
You can how ever use a boost mobile tutorial to clone the esn from your phone, just look on you tube.
The short bit of cloning is that its very very easy, you have to zero out, then use qxdm to load a new one.
Thats all i have to say about that.
Things you are going to need.
A computer with administrative acess
CDMA workshop 2.7
QPSP that can read the phone
HTML:
http://thepiratebay.org/torrent/6388346/Qualcomm
Metropcs prl
HTML:
http://www.corolada.com/prl/metropcs/02001.prl
samsung drivers
HTML:
http://downloadcenter.samsung.com/content/SW/201009/20100901010102890/Samsung_Mobile_Driver_V1.3.800_For_SPH-d700_Epic_4G.zip
A samsung epic with a data cable, not all cables are equal. Keep several handy.
First were going to change the msl to 000 so that metropcs Over The Air activation can work.
Turn your phone one and dial ##8778# and select modem under usb, and under uart modem.
Once you do this your phone will be readable by qpst and cdma workshop.
Drivers and Com Ports
Install the samsung drivers, once that finishes you can plug the phone in and the drivers will install.
You will need to find out what port your phone is under, and posibly change it to any open port under 25
Go to the start menu, then my computer and right click on it, select manage.
In vista/seven allow administrative acess. A window live this appear.
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
Click on device manager then under modems you should see Samsung Mobile Modem.
Right click on that and then select properties
Once this opens click on 2 then select advanced port settings.
This will be your port number for cdma workshop and QPSt. If you notice on my computer its at 32.
I need to change it to any number below 25 so that cdma workshop 2.7 will open it.
click on where 3 is pointing to and select a port from the list below 25. Then close that out
CDMa Workshop msl change
What ever port you had from the previous section we need to enter it on CDMA Workshop
Open CDMA WS.
4 Select your comport
5 Click connect, on my screenshot i was already connected so it says disconnect.
6 Read from them phone and information on the side will appear like your phone number when its connected.
7 Go to the security tab
8 in the spc field put 000000 (six zeros)
9 CLick on SPC Write.
Once that done you can close CDMA Workshop, it will ask you to reset.
Do it .
With part done you can slip the esn change here from the boost tutorial
QPST, PRL, INTERNET
Install QPST
Go to the start menu, all programs, QPST, then QPST Configurator
10 Go to the ports tab
11 Add New Port
12 Click on Show Serial USB/QC Diagnostic ports
13 You should see something like COM32-USB/QC Data Modem. Select it and clikc ok
14 you should see a phone in the list
15 go to Start Clients
16 Select Service Programming
A new windows will open up
17 on the phone selection windows make sure your phone is selected
18 click on ok to enter programing on selected phone.
19 Once the window opens click on read from phone
20 make sure the spc is 000000, we changed it in CDMA WS
21 click ok to
22 go to the CDMA tab
23 if you cloned your esn put your mdn or min here I dont know which is which
24 if you cloned your esn put your mdn or min here I dont know which is which
25 Select the roam tab
26 click browse and select your metropcs prl downloaded from colorado prl
27 select the display tab
28 Change the Banner to Metropcs or what ever you want. You can even leave it at sprint
29 click on the right arrow to reveal more tabs on top
30 Select the M.I.P. tab
31 Change mobile Ip to Simple Ip only
32 Change the Initial Registration to 1750ms
33 Click on RF2002 authentification calculation
34 Change registration Retries to 2
35 Change deregistration Retries 1
36 Change Lifetime-expiry registration 0
37 Now double click on user profile 0 and change to steps 39-49
38 double click on user profile 1 and change to steps 50-59
39 Change the nai to [email protected] or [email protected]
40 Change Tethered nai to [email protected] or [email protected]
41 On Ha shared secret click on enter text string
42 enter metropcs
43 on AAA shared secret select enter text string
44 enter metropcs
45 MIN HA SPI change to 12C
46 MIN-AAA SPI change to 2
47 Change the primary HA adress to 0.0.0.0
48 Change the Secondary HA adress to 0.0.0.0
49 click ok
50 Change the nai to [email protected] or [email protected]
51 Change Tethered nai to [email protected] or [email protected]
52 On Ha shared secret click on enter text string
53 enter metropcs
54 on AAA shared secret select enter text string
55 enter metropcs
56 MIN HA SPI change to 12C
57 MIN-AAA SPI change to 2
58 Change the primary HA adress to 0.0.0.0
59 Change the Secondary HA adress to 0.0.0.0
60 click ok
61 there is no 61 i skipped a number, but i know someone is going to notice. I know
62 Now click on PPP Config tab
63 in the rm tab change config tries of all 3 to 20
64 make sure the request time out is 1000 on all 3
65 make sure NAK tries are 3 on all 3
66 make sure terminate tries are 2 on lcp 3 on ipcp and 3 on ipcpv6
67 make sure request time out is 3000 on lcp and 1000 on ipcp and ipcpv6
68 click on compression setting for ipcpv6 to ignore
69 make sure require pw enc is enabled/checked
70 make sure ppp detect is enable/checked
71 change retries to 5
I seem to have lost the rest of my captures thanks to acronis!!! so i will continue with blodykiller86's pics which are not labeled
72 make sure you click on Um
73 in the Um tab change config tries on lcp 20 ipcp 20 and ipcpv6 to 0
74 make sure the request time out is 1000 on lcp and ipcp, but on ipcpv6 change it to 0
75 make sure NAK tries are 2 on lcp and ipcp but on ipcpv6 change it to 28
76 make sure terminate tries are 2 on lcp 3 on ipcp and 0 on ipcpv6
77 make sure request time out is 3000 on lcp and 1000 on ipcp and 0 on ipcpv6
78 Click on compression setting for ipcp to disable
79 click on compression setting for ipcpv6 to ignore
80 make sure Optimized domant handoff is enabled/checked
81 change retries on ppp authentication to 5
82 change tethered nai on ppp authentication to [email protected] or [email protected]
83 change User ID on ppp authentication to [email protected] or [email protected]
84 go to http://www.whiterabbit.org/android/ and put your esn where it says "Enter 1 MEID/ESN per line in the text area to your left, then click the calculate button."
The ESN is on the top of your qpst windows, copy the short number that starts with an 8 and calculate.
It will return a six digit metropcs msl code.
85 take the generated code and put it in the password
86 click on AN
73 in the AN tab change config tries on lcp 20 ipcp 20 and ipcpv6 to 0
74 make sure the request time out is 1000 on lcp and ipcp, but on ipcpv6 change it to 0
75 make sure NAK tries are 2 on lcp and ipcp but on ipcpv6 change it to 28
76 make sure terminate tries are 2 on lcp 3 on ipcp and 0 on ipcpv6
77 make sure request time out is 3000 on lcp and 1000 on ipcp and 0 on ipcpv6
78 Click on compression setting for ipcp to disable
79 click on compression setting for ipcpv6 to ignore
81 change retries on ppp authentication to 5
82 change tethered nai on ppp authentication to [email protected] or [email protected]
83 CHange the password to the msl code you got from white rabbit a six digit code.
Then just click write to phone, wait for the phone to reboot before closing qpst.
The if you want to activate your phone if its not in your account already just dial *228
to enter Over The Air activation, it will ask for english or spanish. select either
once it gets past that it will ask why you called.
Dial 2 to change number, dial 1 proced, then 1 to proced, enter your phone number, enter your security code (usually birthdate of account holder), and follow the rest of what she says.
1 is for yes 2 is for no, i usually mute the microphone.
and then its activated to an account.
Next make sure you dial *228 this time select 5 to update your prl and reboot.
All done.
I dont know how to get the mms working yet., I have tried u2nl. wap, proxies, flashing zips that change the mms settings and no luck yet.
ill let you know when i get it working or if anything comes up in the thread.
I stay very busy, so dont be surprised if i dont answer, but if you send me a message it should get to my email.
P.S. to all you cricket people i am so sorry for forgetting about you when i started writing this, please change all apropriate settings but it should work.
I will change them asap, right now though i gots to go.
P.s.s. I cant post in the development section because of the stupid stupid stupid stupid stupid stupid (you get the point) post count rules.
Update: Mms
Okay ibfound out something very useful on how to get mms to WORK, basically I sent myself a small 46k pic to gmail. But I kept messing with the phone, without even realizing I had it working. Basically before I knew it I has killed it.
Here is what I used to get it work.
Autostart.sh
#######
export PATH=$PATH:/data/local/bin
IP_ADDR="10.223.2.4"
chmod 755 /data/local/iptables
chmod 755 /data/local/u2nl
/data/local/u2nl $IP_ADDR 3128 127.0.0.1 8888 &
/data/local/iptables -t nat -o ppp0 -A OUTPUT -p tcp -d ! $IP_ADDR -j REDIRECT --to-port 8888
/sbin/remount rw
cat /data/local/telephony.db > /data/data/com.android.providers.telephony/databases/telephony.db
cat /data/local/Mms.apk > /system/app/Mms.apk
sleep 5
kill `ps | /data/local/busybox grep autostart | /data/local/busybox awk {'print $2'}`
##########
I will post post iptables binary once I figure out where to upload it. For now if you need it just msg me.
Also to be clear if you use the autostart.sh you won't have a working messages apk. In other words no text or mms untill you factory reset.
Mms
Okay i got mms, but first to vent.
First of all In my experiences with this phone, its not worth the hazle.
Get an evo or a shift.
also this phone should be defecated on, and flushed down the toiled.
The keyboard is cheap, the amoled screen is not noticeably better than evo(unlike iphone4, and not worth the 100 part price), the keyboard is cheap, gps is half decent, ui is horrible. The epic is by no means an evo killer, i have had it for 2 months and all the time i have been cursing this phone. I have bricked it 2-3 times while at work to where cw recovery wont help you any.
Then there is the issue of the kernel, you need a kernel that has iptables support.
You guessed it the stock kernel doesn't have such a thing, so compiling is the best option. Until you go to the samsung page and cant download the source. I tried opera, firefox, marthon, ie, chrome, and UC. When i get my hands on the source code i will provide the a kernel.
Next up is get a rom that has a kernel with support, oh yeah that sounds easy.
No luck so far, i have reason to think that epic experience has iptables support.
But its become abandoned and its not updated to work with the new version of clockwork recovery (edify). Just so you know simply aosp does not have support
Do yourself a favor and sell it, but if youre like me and have 2 of then.
This phone cannot be flashed just like any other phone, you always have to jump trough hoops.
Okay so lets say you got an old cw , flashed experience and were able to get a kernel with iptables.
you would get this
http://www.4shared.com/file/yofYy6uB/epic_4g.html
it comes with
u2nl
autostart.sh
iptables
telephony.db
Mms.apk
apn back up xml file.
what you need
Autostart
es file explorer and enable the root features
apn backup and restore
busybox installer
first off you need to do what the autostart.sh says.
copy u2nl, iptables, telephony.db, Mms.apk, and a copy of busybox to /data/local
then copy autostart.sh to /data/opt and you need to create the folder called opt make the autostart.sh executable. You should run the autostart.sh manually on the terminal like so ./autostart.sh. If you get a FIX ME!, it means your kernel doesnt do iptables.
the last thing is to restore the apn with apn backup and restore with the one i provide, but you need to edit it with your phone number.
edit this file acordingly in the apn xml
mmsc="http://mms.metropcs.net/mmsc?X-Device-MIN=5555555555
rerplace with your phone number like so
<apn type="null" mmsc="http://mms.metropcs.net/mmsc?X-Device-MIN=2222222222
then resotore it.
that should be ready.
I dont have it right now like i said because of stupid problems.
but like i have said, i have sent AN mms once already. But right after that i bricked the phone so i had to delete everything.
Thanks for the post missingxtension. Looking at the posted files they all seem to contain Sprint info within each file. The telephony.db file, autostart files, apns file and so on. Was this an accident or....??
I know you said you bricked your phone so i'm not sure if you meant all files are coming soon or it should work as it minus the apns-config. I was so excited until I looked in each of them.. lol
sorry to necro an old thread but i followed your steps exactly. for some reason my phone wont connect to a metro tower. i then went back into qpst and changed the sid and still cant connect to a metro tower. what am i missing?
I am one of the few, if not only members on XDA who has their Epic to MetroPCS.
If you're having issues with the internet, there's a file foating on the net that calculates the metropcs wap password needed in order to be online. Its calculated based off of your MEID.
My phone was flashed as the 2nd poster said. With the autostart u2nl crap. It sucked. My phone did not last long and the autostart was hogging my battery. It was possible with Shiziopunk's Epic Experience 2.1 eclair. (Outdated) though sine I've moved, MetroPCS towers no longer reach me in the state of Oregon so I roam 24/7. Using wifi and third party apps for mms and whatnot. I use EG22 deodexed stock now. Still have service. I still have the MetroPCS rom backed up in clockwork mod, but unless I was instructed on how to strip my personal data from it, I'm not sharing.. Donations would be appreciated to any interested. Afterall I did pay 75$ for my rom.
Shinydude100 said:
I am one of the few, if not only members on XDA who has their Epic to MetroPCS.
If you're having issues with the internet, there's a file foating on the net that calculates the metropcs wap password needed in order to be online. Its calculated based off of your MEID.
My phone was flashed as the 2nd poster said. With the autostart u2nl crap. It sucked. My phone did not last long and the autostart was hogging my battery. It was possible with Shiziopunk's Epic Experience 2.1 eclair. (Outdated) though sine I've moved, MetroPCS towers no longer reach me in the state of Oregon so I roam 24/7. Using wifi and third party apps for mms and whatnot. I use EG22 deodexed stock now. Still have service. I still have the MetroPCS rom backed up in clockwork mod, but unless I was instructed on how to strip my personal data from it, I'm not sharing.. Donations would be appreciated to any interested. Afterall I did pay 75$ for my rom.
Click to expand...
Click to collapse
im not worried about internet or anything like that yet. i need to get the phone to connect to a metro tower first. ill figure out mms and internet afterwards. i also plan on doing a metropcs version of any syndicate rom i do. it will be what the rom is plus all the **** to make the phone run on metropcs smoothly
Honestly if all that worried you was getting it to connect to a metro tower, then get your esn added with Metro. That simple.
Shinydude100 said:
Honestly if all that worried you was getting it to connect to a metro tower, then get your esn added with Metro. That simple.
Click to expand...
Click to collapse
like i mentioned before i follwed the steps in the op. one of the first steps was to clone the esn or get it added to metropcs. i cloned my esn and still cant connect to a metro tower.
Again. You need to add it to MetroPCS's ESN database, cloning over your Boost ESN is retarded. Boost Mobile is owned by Sprint. Nothing to do with Metro pcs.
ESN must be a metro esn or ported esn
MysteryEmotionz said:
like i mentioned before i follwed the steps in the op. one of the first steps was to clone the esn or get it added to metropcs. i cloned my esn and still cant connect to a metro tower.
Click to expand...
Click to collapse
I might be able to help on getting a metro esn pm me.
Also about the sprint stuff, I am 100 percent sure that the only problem i am having is a crappy kernel. I still cant download the source code to give a shot at netfilter.
I can send mms no problem, so if i send "hey" to [email protected] it goes thru no problem.
The picture messages are the problem.
I was able to install epic experience 1.9 and it didn't boot.
I downgraded the recovery to 2.5 and it looked promising.
I am not done working on this, but luckily i am to the point to where i can already start using my shift again.
I am currently also working on an evo 3d and nexus s 4g.
Again once i find out, i will post all the information I have.
Also sorry about the pictures, I took a lot of time to write and make screen shots.
But i got the thumbnail links, ill update the links asap.
I will keep an eye out on this thread, its not dead at all.
Also if you pm me, i do get a message on email.
Hey Shiny, can you pm me with info about your epic on MetroPCS? My wife has her phone already on MetroPCS, and all the basics work just fine, but her eclair has bugs, and I wanted to try to upgrade her Rom. Just wanted yours or anyone else's input. Thanks
Sent from my PG06100 using xda premium
You can upgrade her rom, but in the process, you'll more than likely lose Metro's 3G service with only 1x working (due to iptables I believe) so no picture messaging, or internet if upgraded. You should use clockworkmod for a nand backup an upgrade it once its backed up. I upgraded mine because MetroPCS is non-existent in Oregon but they have roaming here, so I wasn't going to be needing to stay on the MetroPCS friendly rom when I have wifi at home for internet/picture emailing. I'm on EH17 GB and loving it.
Unfortunatly, we do not have 3g here yet, so i guess i'll tackle that when time comes. What is the difference with the GB17? Do you have a link or should i just google it, or is it in a forum? Thanks for your help again
Sent from my PG06100 using xda premium
cbernardo13 said:
Unfortunatly, we do not have 3g here yet, so i guess i'll tackle that when time comes. What is the difference with the GB17? Do you have a link or should i just google it, or is it in a forum? Thanks for your help again
Sent from my PG06100 using xda premium
Click to expand...
Click to collapse
It still has issues but they are VERY miniscule now. Here is my own Changelog on differences.
Major GPS Lock Improvement.
On Froyo & GB: Adobe Flash Player 10.3 Works Excellent.
Apps 2 SD. (This is a *big* plus, you won't be hoggin the internal Memory Space on her Epic.)
Graphical User Interface Upgraded. The Icons in the settings Menu are now color, instead of the old Eclair look.
Battery Use now has a Graph showing your Battery Life.
Battery Life should improve after you upgrade to EH17, compared to Eclair.
~There are a few more nice things you can get, but you need to upgrade to EH17 before they will work.~ Like CRT Off animation when your screen turns off on her Epic. And a Battery Percentage inside the battery Icon in the Android Status Bar.
Make sure you get clockworkmod installed, nandroid backup her Metro Rom, before you flash anything, that rom is valuable.
Once you decide to upgrade you'll need:
-Samsung Drivers Installed.
If Windows Vista/7 it should install using your internet. If Windows XP, you'll need to look online for the Samsung Drivers. If you're on a 32-bit computer, get the X86 drivers, if on 64-Bit, get the X64 Drivers.
You'll need to download Odin, found in the the Epic Section Titled "Android Development" You can also find it online..
Once you have that, you'll need to power off her Epic, slide open the keyboard, hold down the "1" key and the power button, you'll be in Download mode. Find clockworkmod, follow the instructions and flash that using Odin. (Notice your computer should pick up her Epic as Modem, etc.) Odin will show COM1, 2..3..4.. a diff # for all of us, that's just the port assigned by your computer. Once you flash clockworkmod, next is the nandroid backup.
Turn the phone off it Odin rebooted it. Hold the down button, camera button, and power button. (Have a firm grip, don't let go until the clockworkmod recovery comes up, (should be purple if you odin'd the latest one) go to advanced/backup. Hit yes, and the Nandbackup will begin. This will save you from semi-bricking your girl's epic in the future.
Next you'll want to pick a rom to Flash, you can go with whatever you want, but I reccommend you startoff with roms using the RFS file format until you get the hang of flashing. I'm personally usng Deca's EH17 deodexed rom. Its stock. It has minor reboots, but they aren't too often. Good luck & happy flashing.
MysteryEmotionz said:
sorry to necro an old thread but i followed your steps exactly. for some reason my phone wont connect to a metro tower. i then went back into qpst and changed the sid and still cant connect to a metro tower. what am i missing?
Click to expand...
Click to collapse
When you dial *228 does it give you MetroPCS or Another Carriers Prompt? If another carriers prompt then you need to download the MetroPCS .prl to the phone. Thats how the phone locates the towers.
Exactly. And I was assuming you had flashed your phone with metro PCS already, which would have included the PRL, if you're in a rural area, it is possible to hear a diff operator if roaming. Bu if its sprint, then the prl isn't there.
I have Cricket and have everything working on the $45 plan...except MMS. Guess I'll read through some of these solutions and give em a try.
Thanks!
up-yours said:
ok cricket is going national on sept 25 2011.
i have an epic 4g and want to use it on cricket.
their are no coporate or other cricket stores here.
i will have to flash it my self right?
were do i get a cricket prl?
i can follow the guide here and hopes it all works....
any advice?
http://www.androidcentral.com/cricket-goes-national-new-phones-best-buy-stores-sept-25
Click to expand...
Click to collapse
You have to get your esn added to Cricket's system one way or another, wether that be finding a source who will add it for you for a fee, or getting a phone pre-programmed to cricket, sold to you by someone who lives near a cricket location and shipped to you. If you get the esn added, you can use google to find the appropriate prl, and if you get it preprogrammed or flashed at a location outside your area, prl will be included.
Does anyone have issues with youtube playing on wifi, but not on the 3G?
tried to clone my half broken motorola photon to epic 4g, but when i execute
scp xxxxxx
requestnvitemread ds_mip_ss_user_prof
requestnvitemread ds_mip_ss_user_prof 1
i get
15:29:20.748DIAG RX item:
15:29:20.763SPC Result = Correct
15:29:37.725requestnvitemread ds_mip_ss_user_prof
15:29:37.850DIAG TX item:
15:29:37.850index = 0
15:29:37.850mn_ha_shared_secret_length = 0x00
15:29:37.850mn_ha_shared_secret[0] = 0x00
15:29:37.850mn_ha_shared_secret[1] = 0x00
15:29:37.850mn_ha_shared_secret[2] = 0x00
15:29:37.850mn_ha_shared_secret[3] = 0x00
15:29:37.850mn_ha_shared_secret[4] = 0x00
15:29:37.850mn_ha_shared_secret[5] = 0x00
15:29:37.850mn_ha_shared_secret[6] = 0x00
15:29:37.850mn_ha_shared_secret[7] = 0x00
15:29:37.850mn_ha_shared_secret[8] = 0x00
15:29:37.850mn_ha_shared_secret[9] = 0x00
15:29:37.850mn_ha_shared_secret[10] = 0x00
15:29:37.850mn_ha_shared_secret[11] = 0x00
15:29:37.850mn_ha_shared_secret[12] = 0x00
15:29:37.850mn_ha_shared_secret[13] = 0x00
15:29:37.850mn_ha_shared_secret[14] = 0x00
15:29:37.850mn_ha_shared_secret[15] = 0x00
15:29:37.850mn_aaa_shared_secret_length = 0x00
15:29:37.850mn_aaa_shared_secret[0] = 0x00
15:29:37.850mn_aaa_shared_secret[1] = 0x00
15:29:37.850mn_aaa_shared_secret[2] = 0x00
15:29:37.850mn_aaa_shared_secret[3] = 0x00
15:29:37.850mn_aaa_shared_secret[4] = 0x00
15:29:37.850mn_aaa_shared_secret[5] = 0x00
15:29:37.850mn_aaa_shared_secret[6] = 0x00
15:29:37.850mn_aaa_shared_secret[7] = 0x00
15:29:37.850mn_aaa_shared_secret[8] = 0x00
15:29:37.850mn_aaa_shared_secret[9] = 0x00
15:29:37.850mn_aaa_shared_secret[10] = 0x00
15:29:37.850mn_aaa_shared_secret[11] = 0x00
15:29:37.850mn_aaa_shared_secret[12] = 0x00
15:29:37.850mn_aaa_shared_secret[13] = 0x00
15:29:37.850mn_aaa_shared_secret[14] = 0x00
15:29:37.850mn_aaa_shared_secret[15] = 0x00
15:29:37.850DIAG RX item:
15:29:37.850requestnvitemread - Error response received from target
15:29:56.938requestnvitemread ds_mip_ss_user_prof 1
15:29:57.063DIAG TX item:
15:29:57.063index = 1
15:29:57.063mn_ha_shared_secret_length = 0x00
15:29:57.063mn_ha_shared_secret[0] = 0x00
15:29:57.063mn_ha_shared_secret[1] = 0x00
15:29:57.063mn_ha_shared_secret[2] = 0x00
15:29:57.063mn_ha_shared_secret[3] = 0x00
15:29:57.063mn_ha_shared_secret[4] = 0x00
15:29:57.063mn_ha_shared_secret[5] = 0x00
15:29:57.063mn_ha_shared_secret[6] = 0x00
15:29:57.063mn_ha_shared_secret[7] = 0x00
15:29:57.063mn_ha_shared_secret[8] = 0x00
15:29:57.063mn_ha_shared_secret[9] = 0x00
15:29:57.063mn_ha_shared_secret[10] = 0x00
15:29:57.063mn_ha_shared_secret[11] = 0x00
15:29:57.063mn_ha_shared_secret[12] = 0x00
15:29:57.063mn_ha_shared_secret[13] = 0x00
15:29:57.063mn_ha_shared_secret[14] = 0x00
15:29:57.063mn_ha_shared_secret[15] = 0x00
15:29:57.063mn_aaa_shared_secret_length = 0x00
15:29:57.063mn_aaa_shared_secret[0] = 0x00
15:29:57.063mn_aaa_shared_secret[1] = 0x00
15:29:57.063mn_aaa_shared_secret[2] = 0x00
15:29:57.063mn_aaa_shared_secret[3] = 0x00
15:29:57.063mn_aaa_shared_secret[4] = 0x00
15:29:57.063mn_aaa_shared_secret[5] = 0x00
15:29:57.063mn_aaa_shared_secret[6] = 0x00
15:29:57.063mn_aaa_shared_secret[7] = 0x00
15:29:57.063mn_aaa_shared_secret[8] = 0x00
15:29:57.063mn_aaa_shared_secret[9] = 0x00
15:29:57.063mn_aaa_shared_secret[10] = 0x00
15:29:57.063mn_aaa_shared_secret[11] = 0x00
15:29:57.063mn_aaa_shared_secret[12] = 0x00
15:29:57.063mn_aaa_shared_secret[13] = 0x00
15:29:57.063mn_aaa_shared_secret[14] = 0x00
15:29:57.063mn_aaa_shared_secret[15] = 0x00
how can i read password out of this phone??
I've searched around for the past couple days trying to figure out how to pull the AAA key from profile 1 on my OG EVO and I didn't have any luck finding what I need.
I've tried using QXDM:
I unlocked the phone using "spc 'msl'"
It confirms that the phone is unlocked
I entered "requestnvitemread ds_mip_ss_user_prof 1"
the result is all 0's
I've tried running "adb logcat > c:\dump.txt" and ##DATA# in edit mode.
I edited the user and the aaa shared secret and pressed cancel
Looked through the log and I'm not seeing anything jumping out at me.
I did a search for what I already know as the HA key in hex and ascii and I'm not seeing it in the log either.
I've heard you can pull the profile 1 aaa key from nv item 466.
I took a look at the one that came off my phone and it's all 00'd out.
I downloaded the DFS demo and I can read almost everything on that phone except the keys.
My question is how can I pull the proflie1 - 6-digit Sprint key from an EVO?
edit: I originally said I was looking for profile 0 key - I already have that - I'm looking for the profile 1 aaa key.
-thanks Klown80 for pointing that out.
xdapark said:
I've searched around for the past couple days trying to figure out how to pull the AAA key from profile 0 on my OG EVO and I didn't have any luck finding what I need.
I've tried using QXDM:
I unlocked the phone using "spc 'msl'"
It confirms that the phone is unlocked
I entered "requestnvitemread ds_mip_ss_user_prof"
the result is all 0's
I've tried running "adb logcat > c:\dump.txt" and ##DATA# in edit mode.
I edited the user and the aaa shared secret and pressed cancel
Looked through the log and I'm not seeing anything jumping out at me.
I did a search for what I already know as the HA key in hex and ascii and I'm not seeing it in the log either.
I've heard you can pull the profile 0 aaa key from nv item 466.
I took a look at the one that came off my phone and it's all 00'd out.
I downloaded the DFS demo and I can read almost everything on that phone except the keys.
My question is how can I pull the proflie0 - 6-digit Sprint key from an EVO?
Click to expand...
Click to collapse
Profile 0 will be a 32 digit key, pro 1 is a 12 digit key. Does data work on the Evo currently? If so try going to settings, system updates, update profile.then try reading the profile 0 again.
Klown80 said:
Profile 0 will be a 32 digit key, pro 1 is a 12 digit key. Does data work on the Evo currently? If so try going to settings, system updates, update profile.then try reading the profile 0 again.
Click to expand...
Click to collapse
you're right - it's the profile 1 key im looking for.
I updated my post and title to reflect that.
I just did a profile update and it shows all 00's
then i tried this:
factory reset and a ##RTN# reset - reboot - OTA activated - updated profile and ran "requestnvitemread ds_mip_ss_user_prof 1"
still shows all 00's
for what it's worth profile 0 and profile 1 ha and aaa keys show up as 00's in QXDM
I restored back to the original factory image (baseband 2.15.00.11.19) I made before I ever rooted the phone to see if that makes a difference.
it didn't
Can anybody confirm that QXDM 3.11.36 can read the profile keys from an EVO?
Im using some HTC Diag drivers that only seem to work with XP even though a 32 and 64 bit driver was included in the zip.
Is there any way I can do some kind of memory dump to locate it?
xdapark said:
you're right - it's the profile 1 key im looking for.
I updated my post and title to reflect that.
I just did a profile update and it shows all 00's
then i tried this:
factory reset and a ##RTN# reset - reboot - OTA activated - updated profile and ran "requestnvitemread ds_mip_ss_user_prof 1"
still shows all 00's
for what it's worth profile 0 and profile 1 ha and aaa keys show up as 00's in QXDM
I restored back to the original factory image (baseband 2.15.00.11.19) I made before I ever rooted the phone to see if that makes a difference.
it didn't
Can anybody confirm that QXDM 3.11.36 can read the profile keys from an EVO?
Im using some HTC Diag drivers that only seem to work with XP even though a 32 and 64 bit driver was included in the zip.
Is there any way I can do some kind of memory dump to locate it?
Click to expand...
Click to collapse
As long as you have a working profile 0, you can get the phone to OTA and write your profile 1 for you completely. Are you on Boost or Sprint? Unfortunately it sounds like your keys may have got erased somehow, if it does not read in QXDM, DFS, or NV items (Item 466 or 1192 should have it). Does your data work right now? Try just using "requestnvitemread ds_mip_ss_user_prof" that should read your profile 0 key, if we can get at least the profile 0 info the phone will take care of the rest. I have another idea we can try if you can not read profile 0 info. I also have htc drivers that work just fine for me on Win 7 32 bit if you want them, I have a 64 bit Win 7 driver too but have not used it yet so cant confirm it works. I have QXDM 3.09.19 and I know for sure it reads the profile keys, looks like you have a newer version so I assume it would work too.
Klown80 said:
As long as you have a working profile 0, you can get the phone to OTA and write your profile 1 for you completely. Are you on Boost or Sprint? Unfortunately it sounds like your keys may have got erased somehow, if it does not read in QXDM, DFS, or NV items (Item 466 or 1192 should have it). Does your data work right now? Try just using "requestnvitemread ds_mip_ss_user_prof" that should read your profile 0 key, if we can get at least the profile 0 info the phone will take care of the rest. I have another idea we can try if you can not read profile 0 info. I also have htc drivers that work just fine for me on Win 7 32 bit if you want them, I have a 64 bit Win 7 driver too but have not used it yet so cant confirm it works. I have QXDM 3.09.19 and I know for sure it reads the profile keys, looks like you have a newer version so I assume it would work too.
Click to expand...
Click to collapse
I had a working profile 0 - I couldnt' pull the key using "requestnvitemread ds_mip_ss_user_prof"
FWIW - I could retrieve it from 1192 and by running "requestnvitemread hdr_an_auth_passwd_long"
Out of curiosity - is there a similar command that pulls from 1?
my 466 was completely 00'd out.
I'm not too worried about it anymore - my issue is resolved now.
My problem was I couldn't get 3g working on my gnex.
You let me know the aaa key would be written as long as I had a working profile 0 so I looked for the key on my gnex.
I ran logcat on the gnex and I was able to see the key I was looking for.
I ran around for a few days with no 3g.
After I pulled the key from the gnex and re-wrote it to that same gnex - 3g started working.
Then I made a test call and got error 16.
After I talked to the sprint rep and rebooted - everything worked fine.
thanks for everything - looks like I'm good to go now.:victory:
AAA Help
xdapark said:
I had a working profile 0 - I couldnt' pull the key using "requestnvitemread ds_mip_ss_user_prof"
FWIW - I could retrieve it from 1192 and by running "requestnvitemread hdr_an_auth_passwd_long"
Out of curiosity - is there a similar command that pulls from 1?
my 466 was completely 00'd out.
I'm not too worried about it anymore - my issue is resolved now.
My problem was I couldn't get 3g working on my gnex.
You let me know the aaa key would be written as long as I had a working profile 0 so I looked for the key on my gnex.
I ran logcat on the gnex and I was able to see the key I was looking for.
I ran around for a few days with no 3g.
After I pulled the key from the gnex and re-wrote it to that same gnex - 3g started working.
Then I made a test call and got error 16.
After I talked to the sprint rep and rebooted - everything worked fine.
thanks for everything - looks like I'm good to go now.:victory:
Click to expand...
Click to collapse
Maybe you can help me out, everything on the phone works except for 3g in debug under evdo protocol it says an-aaa fail and i tried:
requestnvitemread hdr_an_auth_passwd_long and requestnvitemread ds_mip_ss_user_prof both give me:
Request:
0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000015407E
Response:
004F6374203136203230313232333A31343A34384F637420303120323031324C3731302E31340041414141414E415A3A06FF70000206B1EE307E
where do i go from here any ideas?
thewire1o1 said:
Maybe you can help me out, everything on the phone works except for 3g in debug under evdo protocol it says an-aaa fail and i tried:
requestnvitemread hdr_an_auth_passwd_long and requestnvitemread ds_mip_ss_user_prof both give me:
Request:
0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000015407E
Response:
004F6374203136203230313232333A31343A34384F637420303120323031324C3731302E31340041414141414E415A3A06FF70000206B1EE307E
where do i go from here any ideas?
Click to expand...
Click to collapse
If it says AN-AAA = fail then your profile 0 info is not correct. Make sure username and AAA is correct HA will be 736563726574. Look in NV item 466 or 1192 to see if your pro 0 32 digit AAA is in there, it will start after the "10"
Same boat
xdapark said:
I had a working profile 0 - I couldnt' pull the key using "requestnvitemread ds_mip_ss_user_prof"
FWIW - I could retrieve it from 1192 and by running "requestnvitemread hdr_an_auth_passwd_long"
Out of curiosity - is there a similar command that pulls from 1?
my 466 was completely 00'd out.
I'm not too worried about it anymore - my issue is resolved now.
My problem was I couldn't get 3g working on my gnex.
You let me know the aaa key would be written as long as I had a working profile 0 so I looked for the key on my gnex.
I ran logcat on the gnex and I was able to see the key I was looking for.
I ran around for a few days with no 3g.
After I pulled the key from the gnex and re-wrote it to that same gnex - 3g started working.
Then I made a test call and got error 16.
After I talked to the sprint rep and rebooted - everything worked fine.
thanks for everything - looks like I'm good to go now.:victory:
Click to expand...
Click to collapse
hello I'm on the same step you were, could you please post how did you pulled the key from the Gnex? was it with ETS? Thanks a bunch!!