Announcement

Collapse
No announcement yet.

mec 16xx dump with info block

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    mec 16xx dump with info block

    Hi,

    anyone can share a (256kb) MEC dump with info block? (containing SER#,CON#,USR#...) or share the SVP offset (e.g. for DXE mapped its 0x1F400)? With SVP would be great.
    thanks

    #2
    Re: mec 16xx dump with info block

    If you want to unlock lenovo, use the patch method instead.

    Comment


      #3
      Re: mec 16xx dump with info block

      doesnt work on t490 and above

      Comment


        #4
        Re: mec 16xx dump with info block

        Okay, thats where you should have started sadly I have no information on what you asked.

        I think there is a checksum aswell. So if you want to delete SVP, got to consider that aswell. But since I have not modified mec-s, I am not sure if it is important or even true

        Anyway, good luck with trying and let us know how it goes.

        Comment


          #5
          Re: mec 16xx dump with info block

          i only need a dump with this block, e.g. v**fix has but i dont wanna buy it...

          FYI: erasing+rewriting MEC to get rid of SVP works like a charm, unfortunately UUID,SN and such are "lost" due to the fact that this info block seems to be read protected in mec1663, with the offsets avail i could skip this block during erase/write and then I wouldnt need to rewrite it... so any dump should do thus i didnt mention T490 and later
          Last edited by superhansi; 02-25-2020, 02:53 AM. Reason: typo

          Comment


            #6
            Re: mec 16xx dump with info block

            Hy. I also have a T490s. Did you remove the chip or connected the programmer via wires to the motherboard? I can't find schematic or where the pins are. Also, did you succeed in removing SVP ?

            Comment


              #7
              Re: mec 16xx dump with info block

              Originally posted by xmasterboss View Post
              Hy. I also have a T490s. Did you remove the chip or connected the programmer via wires to the motherboard? I can't find schematic or where the pins are. Also, did you succeed in removing SVP ?
              try this try to find jtag1 connector name on the board only space will be there without connector !!
              Attached Files

              Comment


                #8
                Re: mec 16xx dump with info block

                Originally posted by Aditya11ttt View Post
                try this try to find jtag1 connector name on the board only space will be there without connector !!
                Thanks. Did you find the MEC Dump you were looking for? even if it's for sale i will buy and share it with you.

                Comment


                  #9
                  Re: mec 16xx dump with info block

                  On these if you replace the mec ic will that solve the password ?
                  remove ic and put another one in ?
                  Is that confirmed solution ?

                  Comment


                    #10
                    Re: mec 16xx dump with info block

                    Originally posted by Aditya11ttt View Post
                    try this try to find jtag1 connector name on the board only space will be there without connector !!
                    Do you know which or where is the RST#? It's a T490 with the MEC1663
                    Any help is really appreciated.

                    Comment


                      #11
                      Re: mec 16xx dump with info block

                      Where is point to connect?
                      picture add of T490S
                      Attached Files

                      Comment


                        #12
                        Re: mec 16xx dump with info block

                        @black0hackers
                        Upload another picture of complete motherboard, as most of the JTAG signals may be already in a connector pads.
                        • So the JTAG signal wires will need to be soldered to this connector pads.
                        • You will need to move a very tiny PULL-UP resistor and make it a PULL-DOWN resistor to enable JTAG interface.
                        • Then you will need to locate RST# signal somewhere around MECxxxx chip by looking at schematic for this T490S, or by looking at another model schematic that uses the same MECxxxx chip part number (although I've read that this signal is not needed, someone with more JTAG experience may confirm/deny this).

                        Comment


                          #13
                          Re: mec 16xx dump with info block

                          There is a photo t490 jtag1 and pins ,can someone draw the connection ?
                          Attached Files

                          Comment


                            #14
                            Re: mec 16xx dump with info block

                            Looks like JTAG reset resistor is marked in red box. Move the resistor next to that capacitor on the empty pads.

                            I will test it tomorrow.
                            Attached Files

                            Comment


                              #15
                              Re: mec 16xx dump with info block

                              The resistor in my last picture was indeed correct. I can read/write MEC now.

                              The problem is, looks like my SAS JIG (which doesnt have MEC1663 in support list) is not able to clear the write-only area for some reason. What programmer should be used?
                              Last edited by RethoricalCheese; 04-16-2021, 01:04 AM.

                              Comment


                                #16
                                Re: mec 16xx dump with info block

                                Originally posted by RethoricalCheese View Post
                                The resistor in my last picture was indeed correct. I can read/write MEC now.

                                The problem is, looks like my SAS JIG (which doesnt have MEC1663 in support list) is not able to clear the write-only area for some reason. What programmer should be used?
                                A Vertyanov jig or SVOD3
                                All donations to badcaps are welcome, click on this link to donate. Thanks to all supporters

                                Comment


                                  #17
                                  Re: mec 16xx dump with info block

                                  @RethoricalCheese
                                  In your last post you mention you can read/write MEC now, but you describe your problem as is not able to clear the write-only area... have you tried to disconnect all sources of energy for 2-3 minutes? seems like this area is temporarily copied to volatile memory too (ram), so removing energy for a couple of minutes will do the trick.
                                  After this you will have to use Lenovo UEFI Maintenance utility to write Model Number, Serial Number, TYPE and other data for ThinkPad to be left as it was before programming MEC chip.
                                  Last edited by AAAC; 04-17-2021, 07:47 AM.

                                  Comment


                                    #18
                                    Re: mec 16xx dump with info block

                                    Thanks, will try. Did not try removing power for more than a few seconds.

                                    Comment


                                      #19
                                      Re: mec 16xx dump with info block

                                      Hi

                                      I have question. I use svod3 for program this mec and when i read few times mec dump in hxd i see all dump are different. When i try write my clean ec dump i have error in veryfiication. Any idea how solve of my problem ?

                                      Comment


                                        #20
                                        Re: mec 16xx dump with info block

                                        @keczuk
                                        Upload a picture of your setup. Have you added PULL-UP resistors to JTAG signals.
                                        At the time we did this one we couldn't find a schematic for T490, but X1 Carbon 6th Gen (T480s and others) have same MEC1663 EC/KBC chip so we used them as reference.

                                        Attached Files
                                        Last edited by AAAC; 04-18-2021, 04:33 PM.

                                        Comment

                                        Working...
                                        X