【天堂论坛】玩机到天堂 买机找海洋西门子 6688……黑白经典.MP3机王 → 【转】一卡多号kvSIM_1.2修改RAM地址
查看完整版本:【转】一卡多号kvSIM_1.2修改RAM地址
2008/8/8 10:39:25
用debugger观察了内存情况,原内存地址确实有问题,当时未用debugger观察。
现在使用37:A005开始地址,天堂3.8正式版此处是一片空白。现在解决了音调设置死机的BUG。再请大家测试。

;一卡多号kvSIM_1.2修改RAM地址
;for 6688v5508
;作者:Konca
;修改:ljmstock,2008.08.06
;说明:1.只对与1.0版不同部分做说明。本版本实现换号不重启。在不同运营商之间换号有时不正常,与短信中心转换相同问题,有时间再解决。
;2.不再使用5200块,从本版开始使用5508中闲置BLOCK 5100、5101、5102、5103、5104,借用上网相关BLOCK,不需自己再建立BLOCK。需要用小8上网者用1.0版。
;3.kvSIM_Data资料加载到5103、5104块中,使用5103.bin、5104.bin(1.0版使用5200.bin)。制作说明附后。5103.bin和5104.bin的区别为颠倒了其中的号码顺序。
;4.将附件中的 0门号存换 文件夹拷入MMC中,其中为GSM参数和换号bin菜单。不重启换号放在MMC中,可以做成快捷方式,刷入机子。
;撤销1.0版,刷好补丁后,开机运行MMC中的5103.bin、5104.bin文件,加载资料到EEP中。
;但此时5100块无数据,所以需运行一次138change.bin(或159change.bin),加载资料到5100块中。
;重启后默认使用物理卡,按密码进入选号,选159号,自动重启。为获得TMSI、KC等参数重启。
;重启后当前号为159,运行159save.bin,保存GSM参数。再按密码进入选号,选138号,自动重启。重启后当前号为138,运行138save.bin,保存GSM参数。
;至此,准备工作完成。接着就可以运行159change.bin,换号为159;运行138change.bin,换号为138。
;5.bin文件名可以改成自己容易记的。没有使用自动保存GSM参数,有兴趣的可以修改。
;将换号bin刷入机子,配合待机时交错运行换号函数,可以做到自动短时转换,即双号待机。
;6.销毁函数调整为 DABF30CB,ERASE.bin
;7.5100工作块,参数块5101、5102,资料块5103、5104。由于5100~5106的size都只有332,因此改为1卡5号(1+4)。主程序不作修改。
;8.采用模块化结构,尽量详细说明,便于大家修改。

;入口
0x1FCB20: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF DABF30C8DABFF6D0DB00CC00CC00CC00
;开机加载工作块5100数据到RAM地址:37:0968;size:288 V
0x1fc830: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E6F4F6F9E00C88C088C088C0E6FC2001; size:288
0x1fc840: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 88C0E6FCEC13E6FDA005E6FE3700E00F; EC13=5100
0x1fc850: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E6F5B400DAC788EE06F00800DB00FFFF
;保存159号码GSM 32:05B8到参数块5101 size:208。159saveV
0x1fc860: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E00C88C0E00DE00E88E088D0E6FFD000; size:208
0x1fc870: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 88F0E6FCED13E6FDB805E6FE3200E00F; ED13=5101
0x1fc880: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF DAB44AFA06F00800E6FD1E05DAB55AD4; DAB55AD4振动函数
0x1fc890: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF DB00
;保存138号码GSM 32:05B8到参数块5102 size:208。138saveV
0x1fc8a0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E00C88C0E00DE00E88E088D0E6FFD000; size:208
0x1fc8b0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 88F0E6FCEE13E6FDB805E6FE3200E00F; EE13=5102
0x1fc8c0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF DAB44AFA06F00800E6FD1E05DAB55AD4
0x1fc8d0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF DB00
;换号加载资料块5103数据到RAM地址:37:0968;size:288 138change1V
0x1fc8e0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E6F4F6F9E00C88C088C088C0E6FC2001; size:288
0x1fc8f0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 88C0E6FCEF13E6FDA005E6FE3700E00F; EF13=5103
0x1fc900: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E6F5B400DAC788EE06F00800DB00
;换号加载5102块数据到RAM 32:05B8。138change2V
0x1fc910: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E6F4F6F9E00C88C088C088C0E6FCD000; size:208
0x1fc920: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 88C0E6FCEE13E6FDB805E6FE3200E00F; EE13=5102
0x1fc930: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E6F5B400DAC788EE06F00800DB00
;换号加载资料块5104数据到RAM地址:37:0968;size:288 159change1V
0x1fc950: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E6F4F6F9E00C88C088C088C0E6FC2001; size:288
0x1fc960: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 88C0E6FCF013E6FDA005E6FE3700E00F; F013=5104
0x1fc970: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E6F5B400DAC788EE06F00800DB00
;换号加载5101块数据到RAM 32:05B8。159change2V
0x1fc980: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E6F4F6F9E00C88C088C088C0E6FCD000; size:208
0x1fc990: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 88C0E6FCED13E6FDB805E6FE3200E00F; ED13=5101
0x1fc9a0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E6F5B400DAC788EE06F00800DB00
;换号保存37:0968到5100块 size::288。change2V
0x1fc9c0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E00C88C0E00DE00E88E088D0E6FF2001; size::288
0x1fc9d0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 88F0E6FCEC13E6FDA005E6FE3700E00F; EC13=5100
0x1fc9e0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF DAB44AFA06F00800E6FD1E05DAB55AD4; DAB55AD4振动函数
0x1fc9f0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF DB00


;kvSIM_0.9程序修改
0x1FCD22: DABFF6D0 DABF20CB

;kvSIM_0.9程序部分因数据地址改变进行地址移植
0x1FDAAE: 200B A005
0x1FDAB2: FF02 3700
0x1FCD5E: 300B B005 ;%offset
0x1FCD62: FF02 3700 ;/page
0x1FCD9C: 400BFF02 C0053700
0x1FD9D0: 400BFF02 C0053700

;销毁函数 DABF30CB,将5100、5103、5104块置0
;重启函数DABF84DE,可以直接用DA000000死机函数。
0x1FCB30: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF DABF90CADABF84DEDB00CC00CC00CC00
0x1FCB40: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E00C88C0E00DE00E88E088D0E6FF2001
0x1FCB50: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 88F0E6FCEC13E6FD3400E6FE2000E00F
0x1FCB60: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF DABF90CADABF84DEDB00CC00CC00CC00
0x1FCB70: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E00C88C0E00DE00E88E088D0E6FF2001
0x1FCB80: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 88F0E6FCEF13E6FD3400E6FE2000E00F
0x1FCB90: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF DAB44AFA06F00800E6FD1E05E00C88C0
0x1FCBA0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E00DE00E88E088D0E6FF200188F0E6FC
0x1FCBB0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF F013E6FD3400E6FE2000E00FDAB44AFA
0x1FCBC0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 06F00800E6FD1E05DB00

;保存和换号菜单
;将附件中文件夹拷入MMC中,文件夹内的.bin文件为保存和换号菜单:138save.bin,159save.bin,138change.bin,159change.bin。
;为了便于识别和记忆,文件名自己可以改。.bin文件内容为函数调用:
;159save.bin  :DABF60C8DB00;5101,0x1fc860
;138save.bin  :DABFA0C8DB00;5102,0x1fc8a0
;138change.bin:DABFE0C8DABF10C9DABFC0C9DB00;5103,0x1fc8e0,0x1fc910,0x1fc9c0
;159change.bin:DABF50C9DABF80C9DABFC0C9DB00;5104,0x1fc950,0x1fc980,0x1fc9c0
;该菜单可以做成快捷方式,刷入机子,有兴趣的机油可以作修改。

----------------------------------------------------------------------------------------------------------------------------
;以下补丁用于制作5200.bin,不是刷入机子的。
;制作5103.bin的VK
;以下文件头,用户不要修改:
0x56312C: FFFFFFFF E00C88C0
0x563130: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E00DE00E88E088D0E6FF200188F0E6FC;288=2001字节
0x563140: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF EF13E6FD3400E6FE2000E00FDAB44AFA;EF13=5103,3400用户资料开头
0x563150: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 06F00800E6FD1E05DAE6A804DB00CC00
;以下为 kvSIM_Data.vkp 复制过来内容,用自己的SIM资料修改:
0x563160: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E79C9FE5AE9EE58DA100000000000000
; Password: 111100
0x563170: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 31313131303000000000000000000000
; Data of Virtual Card 1 - 159
0x563180: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 31353900000000000000000000000000
0x563190: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 08490000000000000000000000000000
0x5631A0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 00DE743A9F0000000000000000000000
0x5631B0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 08916831080000000000000000000000

; Data of Virtual Card 2 - 138
0x5631C0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 31333800000000000000000000000000
0x5631D0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 08490600000000000000000000000000
0x5631E0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 3F382500000000000000000000000000
0x5631F0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 08916800000000000000000000000000
; Data of Virtual Card 3 - 132
0x563200: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 31333200000000000000000000000000
0x563210: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 08490000000000000000000000000000
0x563220: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FC4CAD00000000000000000000000000
0x563230: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 08916800000000000000000000000000
; Data of Virtual Card 4 - 135
0x563240: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 31333500000000000000000000000000
0x563250: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 08490000000000000000000000000000
0x563260: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF D9BA8000000000000000000000000000
0x563270: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 08916800000000000000000000000000

;5104块的制作:
;以下文件头,用户不要修改:
0x56312C: FFFFFFFF E00C88C0
0x563130: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E00DE00E88E088D0E6FF200188F0E6FC;288=2001字节
0x563140: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF F013E6FD3400E6FE2000E00FDAB44AFA;F013=5104,3400用户资料开头
0x563150: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 06F00800E6FD1E05DAE6A804DB00CC00
;以下为 kvSIM_Data.vkp 复制过来内容,用自己的SIM资料修改:
0x563160: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E79C9FE5AE9EE58DA100000000000000
; Password: 111100
0x563170: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 31313131303000000000000000000000
; Data of Virtual Card 1 - 138
0x563180: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 31333800000000000000000000000000
0x563190: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 08490600000000000000000000000000
0x5631A0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 3F382500000000000000000000000000
0x5631B0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 08916831080000000000000000000000
; Data of Virtual Card 2 - 159
0x5631C0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 31353900000000000000000000000000
0x5631D0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 08490000000000000000000000000000
0x5631E0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 00DE743A9F0000000000000000000000
0x5631F0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 08916800000000000000000000000000

; Data of Virtual Card 3 - 132
0x563200: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 31333200000000000000000000000000
0x563210: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 08490000000000000000000000000000
0x563220: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FC4CAD00000000000000000000000000
0x563230: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 08916800000000000000000000000000
; Data of Virtual Card 4 - 135
0x563240: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 31333500000000000000000000000000
0x563250: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 08490000000000000000000000000000
0x563260: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF D9BA8000000000000000000000000000
0x563270: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 08916800000000000000000000000000

;如果在线转换159和138号码,将159和138的资料部分交换,不修改地址。即:原来卡1为159的资料改为138的资料,卡2为138的资料改为159的,其他部分不修改。
2008/8/8 14:31:10
这个已测试成功,喜欢研究的机友可以试试,小8的又一重大突破,感谢ljmstock为大家开发这么好的补丁。
2008/8/8 15:26:54
这补丁主要有什么作用?希望简单说明一下
2008/8/8 17:08:28

seacore:
这补丁主要有什么作用?希望简单说明一下

不用重启手机,两个虚拟号之间在线切换,配合接收短信执行任务的补丁还可以远程销毁一卡多号数据,达到保密的作用。这是目前该补丁能达到的功能。

若再继续开发,双号待机也将可以实现。

详情参阅:

http://mobile.0110.cn/viewthread.php?tid=377302&extra=page%3D1

http://mobile.0110.cn/viewthread.php?tid=378153&extra=page%3D1&page=1

 

[此帖子已被 xjwsyxy 在 2008-8-8 17:15:43 编辑过]

2008/8/8 18:12:40

海洋落伍了

是最近6688论坛讨论的火热的不重启在线切换一卡多号

集成版是没法刷的,因为需要自己做数据BIN文件

2008/8/8 18:51:12

呵呵,看来要大家自己研究一下。。

把这个加精,方便大家查阅

2008/8/9 10:23:09
具体怎么用呢,我在用0.9的,如何升级到1.2呢?
2008/8/9 16:16:25

这是ljmstock8月9日更正的销毁函数:

;销毁函数 DABF30CB,将5100、5103、5104块置0
;重启函数DABF84DE,可以直接用DA000000死机函数。
0x1FCB30: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF DABF40CBDABF84DEDB00
0x1FCB40: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E00C88C0E00DE00E88E088D0E6FF2001
0x1FCB50: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 88F0E6FCEC13E6FD3400E6FE2000E00F
0x1FCB60: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF DAB44AFA06F00800E6FD1E05E00C88C0
0x1FCB70: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E00DE00E88E088D0E6FF200188F0E6FC
0x1FCB80: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF EF13E6FD3400E6FE2000E00FDAB44AFA
0x1FCB90: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E00C88C0E00DE00E88E088D0E6FF2001
0x1FCBA0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 88F0E6FCF013E6FD3400E6FE2000E00F
0x1FCBB0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF DAB44AFA06F00800E6FD1E05DB00

2008/8/9 19:10:51

期待6688双卡双待时代的到来

2008/8/11 16:08:21

是的,他们正在研究双卡双待,7秒切换一次

 

2008/8/14 2:45:25
个人认为在不在线换号无所谓,要是能实现多卡同时待机就牛了
2008/8/14 22:14:41

再次修正后的销毁函数,天堂3.8测试通过:

0x1FCB30: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF DABF40CBDABF84DECC00CC00CC00CC00
0x1FCB40: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E00C88C0E00DE00E88E088D0E6FF2001
0x1FCB50: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 88F0E6FCEC13E6FD3400E6FE2000E00F
0x1FCB60: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF DAB44AFA06F00800E6FD1E05E00C88C0
0x1FCB70: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E00DE00E88E088D0E6FF200188F0E6FC
0x1FCB80: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF EF13E6FD3400E6FE2000E00FDAB44AFA
0x1FCB90: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 06F00800E6FD1E05E00DE00E88E088D0
0x1FCBA0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E6FF200188F0E6FCF013E6FD3400E6FE
0x1FCBB0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 2000E00FDAB44AFA06F00800E6FD1E05
0x1FCBC0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF DB00

2008/8/21 13:47:55

8.14号更新内容:

用debugger观察了内存情况,原内存地址确实有问题,当时未用debugger观察。
现在使用37:A005开始地址,天堂3.8正式版此处是一片空白。现在解决了音调设置死机的BUG。再请大家测试。

;一卡多号kvSIM_1.2修改RAM地址
;for 6688v5508
;作者:Konca
;修改:ljmstock,2008.08.06
;说明:1.只对与1.0版不同部分做说明。本版本实现换号不重启。在不同运营商之间换号有时不正常,与短信中心转换相同问题,有时间再解决。
;2.不再使用5200块,从本版开始使用5508中闲置BLOCK 5100、5101、5102、5103、5104,借用上网相关BLOCK,不需自己再建立BLOCK。需要用小8上网者用1.0版。
;3.kvSIM_Data资料加载到5103、5104块中,使用5103.bin、5104.bin(1.0版使用5200.bin)。制作说明附后。5103.bin和5104.bin的区别为颠倒了其中的号码顺序。
;4.将附件中的 0门号存换 文件夹拷入MMC中,其中为GSM参数和换号bin菜单。不重启换号放在MMC中,可以做成快捷方式,刷入机子。
;撤销1.0版,刷好补丁后,开机运行MMC中的5103.bin、5104.bin文件,加载资料到EEP中。
;但此时5100块无数据,所以需运行一次138change.bin(或159change.bin),加载资料到5100块中。
;重启后默认使用物理卡,按密码进入选号,选159号,自动重启。为获得TMSI、KC等参数重启。
;重启后当前号为159,运行159save.bin,保存GSM参数。再按密码进入选号,选138号,自动重启。重启后当前号为138,运行138save.bin,保存GSM参数。
;至此,准备工作完成。接着就可以运行159change.bin,换号为159;运行138change.bin,换号为138。
;5.bin文件名可以改成自己容易记的。没有使用自动保存GSM参数,有兴趣的可以修改。
;将换号bin刷入机子,配合待机时交错运行换号函数,可以做到自动短时转换,即双号待机。
;6.销毁函数调整为 DABF30CB,ERASE.bin
;7.5100工作块,参数块5101、5102,资料块5103、5104。由于5100~5106的size都只有332,因此改为1卡5号(1+4)。主程序不作修改。
;8.采用模块化结构,尽量详细说明,便于大家修改。

;入口
0x1FCB20: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF DABF30C8DABFF6D0DB00CC00CC00CC00
;开机加载工作块5100数据到RAM地址:37:0968;size:288 V
0x1fc830: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E6F4F6F9E00C88C088C088C0E6FC2001; size:288
0x1fc840: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 88C0E6FCEC13E6FDA005E6FE3700E00F; EC13=5100
0x1fc850: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E6F5B400DAC788EE06F00800DB00FFFF
;保存159号码GSM 32:05B8到参数块5101 size:208。159saveV
0x1fc860: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E00C88C0E00DE00E88E088D0E6FFD000; size:208
0x1fc870: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 88F0E6FCED13E6FDB805E6FE3200E00F; ED13=5101
0x1fc880: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF DAB44AFA06F00800E6FD1E05DAB55AD4; DAB55AD4振动函数
0x1fc890: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF DB00
;保存138号码GSM 32:05B8到参数块5102 size:208。138saveV
0x1fc8a0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E00C88C0E00DE00E88E088D0E6FFD000; size:208
0x1fc8b0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 88F0E6FCEE13E6FDB805E6FE3200E00F; EE13=5102
0x1fc8c0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF DAB44AFA06F00800E6FD1E05DAB55AD4
0x1fc8d0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF DB00
;换号加载资料块5103数据到RAM地址:37:0968;size:288 138change1V
0x1fc8e0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E6F4F6F9E00C88C088C088C0E6FC2001; size:288
0x1fc8f0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 88C0E6FCEF13E6FDA005E6FE3700E00F; EF13=5103
0x1fc900: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E6F5B400DAC788EE06F00800DB00
;换号加载5102块数据到RAM 32:05B8。138change2V
0x1fc910: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E6F4F6F9E00C88C088C088C0E6FCD000; size:208
0x1fc920: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 88C0E6FCEE13E6FDB805E6FE3200E00F; EE13=5102
0x1fc930: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E6F5B400DAC788EE06F00800DB00
;换号加载资料块5104数据到RAM地址:37:0968;size:288 159change1V
0x1fc950: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E6F4F6F9E00C88C088C088C0E6FC2001; size:288
0x1fc960: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 88C0E6FCF013E6FDA005E6FE3700E00F; F013=5104
0x1fc970: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E6F5B400DAC788EE06F00800DB00
;换号加载5101块数据到RAM 32:05B8。159change2V
0x1fc980: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E6F4F6F9E00C88C088C088C0E6FCD000; size:208
0x1fc990: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 88C0E6FCED13E6FDB805E6FE3200E00F; ED13=5101
0x1fc9a0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E6F5B400DAC788EE06F00800DB00
;换号保存37:0968到5100块 size::288。change2V
0x1fc9c0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E00C88C0E00DE00E88E088D0E6FF2001; size::288
0x1fc9d0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 88F0E6FCEC13E6FDA005E6FE3700E00F; EC13=5100
0x1fc9e0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF DAB44AFA06F00800E6FD1E05DAB55AD4; DAB55AD4振动函数
0x1fc9f0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF DB00


;kvSIM_0.9程序修改
0x1FCD22: DABFF6D0 DABF20CB

;kvSIM_0.9程序部分因数据地址改变进行地址移植
0x1FDAAE: 200B A005
0x1FDAB2: FF02 3700
0x1FCD5E: 300B B005 ;%offset
0x1FCD62: FF02 3700 ;/page
0x1FCD9C: 400BFF02 C0053700
0x1FD9D0: 400BFF02 C0053700

;销毁函数 DABF30CB,将5100、5103、5104块置0
;重启函数DABF84DE,可以直接用DA000000死机函数。
0x1FCB30: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF DABF40CBDABF84DECC00CC00CC00CC00
0x1FCB40: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E00C88C0E00DE00E88E088D0E6FF2001
0x1FCB50: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 88F0E6FCEC13E6FD3400E6FE2000E00F
0x1FCB60: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF DAB44AFA06F00800E6FD1E05E00C88C0
0x1FCB70: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E00DE00E88E088D0E6FF200188F0E6FC
0x1FCB80: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF EF13E6FD3400E6FE2000E00FDAB44AFA
0x1FCB90: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 06F00800E6FD1E05E00DE00E88E088D0
0x1FCBA0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E6FF200188F0E6FCF013E6FD3400E6FE
0x1FCBB0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 2000E00FDAB44AFA06F00800E6FD1E05
0x1FCBC0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF DB00


;保存和换号菜单
;将附件中文件夹拷入MMC中,文件夹内的.bin文件为保存和换号菜单:138save.bin,159save.bin,138change.bin,159change.bin。
;为了便于识别和记忆,文件名自己可以改。.bin文件内容为函数调用:
;159save.bin  :DABF60C8DB00;5101,0x1fc860
;138save.bin  :DABFA0C8DB00;5102,0x1fc8a0
;138change.bin:DABFE0C8DABF10C9DABFC0C9DB00;5103,0x1fc8e0,0x1fc910,0x1fc9c0
;159change.bin:DABF50C9DABF80C9DABFC0C9DB00;5104,0x1fc950,0x1fc980,0x1fc9c0
;该菜单可以做成快捷方式,刷入机子,有兴趣的机油可以作修改。

----------------------------------------------------------------------------------------------------------------------------
;以下补丁用于制作5200.bin,不是刷入机子的。
;制作5103.bin的VK
;以下文件头,用户不要修改:
0x56312C: FFFFFFFF E00C88C0
0x563130: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E00DE00E88E088D0E6FF200188F0E6FC;288=2001字节
0x563140: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF EF13E6FD3400E6FE2000E00FDAB44AFA;EF13=5103,3400用户资料开头
0x563150: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 06F00800E6FD1E05DAE6A804DB00CC00
;以下为 kvSIM_Data.vkp 复制过来内容,用自己的SIM资料修改:
0x563160: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E79C9FE5AE9EE58DA100000000000000
; Password: 111100
0x563170: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 31313131303000000000000000000000
; Data of Virtual Card 1 - 159
0x563180: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 31353900000000000000000000000000
0x563190: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 08490000000000000000000000000000
0x5631A0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 00DE743A9F0000000000000000000000
0x5631B0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 08916831080000000000000000000000

; Data of Virtual Card 2 - 138
0x5631C0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 31333800000000000000000000000000
0x5631D0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 08490600000000000000000000000000
0x5631E0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 3F382500000000000000000000000000
0x5631F0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 08916800000000000000000000000000
; Data of Virtual Card 3 - 132
0x563200: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 31333200000000000000000000000000
0x563210: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 08490000000000000000000000000000
0x563220: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FC4CAD00000000000000000000000000
0x563230: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 08916800000000000000000000000000
; Data of Virtual Card 4 - 135
0x563240: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 31333500000000000000000000000000
0x563250: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 08490000000000000000000000000000
0x563260: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF D9BA8000000000000000000000000000
0x563270: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 08916800000000000000000000000000

;5104块的制作:
;以下文件头,用户不要修改:
0x56312C: FFFFFFFF E00C88C0
0x563130: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E00DE00E88E088D0E6FF200188F0E6FC;288=2001字节
0x563140: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF F013E6FD3400E6FE2000E00FDAB44AFA;F013=5104,3400用户资料开头
0x563150: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 06F00800E6FD1E05DAE6A804DB00CC00
;以下为 kvSIM_Data.vkp 复制过来内容,用自己的SIM资料修改:
0x563160: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E79C9FE5AE9EE58DA100000000000000
; Password: 111100
0x563170: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 31313131303000000000000000000000
; Data of Virtual Card 1 - 138
0x563180: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 31333800000000000000000000000000
0x563190: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 08490600000000000000000000000000
0x5631A0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 3F382500000000000000000000000000
0x5631B0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 08916831080000000000000000000000
; Data of Virtual Card 2 - 159
0x5631C0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 31353900000000000000000000000000
0x5631D0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 08490000000000000000000000000000
0x5631E0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 00DE743A9F0000000000000000000000
0x5631F0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 08916800000000000000000000000000

; Data of Virtual Card 3 - 132
0x563200: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 31333200000000000000000000000000
0x563210: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 08490000000000000000000000000000
0x563220: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FC4CAD00000000000000000000000000
0x563230: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 08916800000000000000000000000000
; Data of Virtual Card 4 - 135
0x563240: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 31333500000000000000000000000000
0x563250: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 08490000000000000000000000000000
0x563260: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF D9BA8000000000000000000000000000
0x563270: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 08916800000000000000000000000000

;如果在线转换159和138号码,将159和138的资料部分交换,不修改地址。即:原来卡1为159的资料改为138的资料,卡2为138的资料改为159的,其他部分不修改。

2008/8/25 8:31:08

在线流畅切换

<div class=t_msgfont id=postmessage_4419718>首先感谢mygod999所做的工作,让大家有机会体验小8双待机的效果。
正如mygod999所测试的那样,在线切换打出没有任何问题,打进时,第一二次不流畅。这是因为没有完整保留GSM参数的原因。
现在作了完善。将RAM 32:0AE6保存到5105、5106块中,并在切换时恢复。现在可以流畅切换了。
值得注意的是,bin菜单和save、change必须对应。切换时如果159change不能换号,就使用138change,自己做测试啦。
代码还有很大的压缩空间,为了便于大家阅读和理解,目前不压缩。请大家测试!
-------------------------------------------------------------------------------------------------------------------------------------------------
;以下是在1.2版(RAM修改)基础上刷入,同时修改bin菜单。
;保存159号码GSM 32:0AE6到参数块5105 size:32。159save2V
0x1fca00: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E00C88C0E00DE00E88E088D0E6FF2000; size:32
0x1fca10: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 88F0E6FCF113E6FDE60AE6FE3200E00F; F113=5105
0x1fca20: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF DAB44AFA06F00800E6FD1E05DB00
;保存138号码GSM 32:0AE6到参数块5106 size:32。138save2V
0x1fca30: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E00C88C0E00DE00E88E088D0E6FF2000; size:32
0x1fca40: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 88F0E6FCF213E6FDE60AE6FE3200E00F; F213=5106
0x1fca50: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF DAB44AFA06F00800E6FD1E05DB00
;换号加载5105块数据到RAM 32:0AE6。159change3V
0x1fca60: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E6F4F6F9E00C88C088C088C0E6FC2000; size:32
0x1fca70: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 88C0E6FCF113E6FDE60AE6FE3200E00F; F113=5105
0x1fca80: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E6F5B400DAC788EE06F00800DB00
;换号加载5106块数据到RAM 32:0AE6。138change3V
0x1fca90: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E6F4F6F9E00C88C088C088C0E6FC2000; size:32
0x1fcaa0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 88C0E6FCF213E6FDE60AE6FE3200E00F; F213=5106
0x1fcab0: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF E6F5B400DAC788EE06F00800DB00

;159save.bin  :DABF60C8DABF00CADB00;5101,0x1fc860
;138save.bin  :DABFA0C8DABF30CADB00;5102,0x1fc8a0
;138change.bin:DABFE0C8DABF10C9DABFC0C9DABF60CADB00;5103,0x1fc8e0,0x1fc910,0x1fc9c0
;159change.bin:DABF50C9DABF80C9DABFC0C9DABF90CADB00;5104,0x1fc950,0x1fc980,0x1fc9c0

------------------------------------------------------------------------------------------------------------------------------------------
6688 V5508 BLOCK大全:
块名大小描述块名大小描述
13485035240MissedCallsNoType1
23485036240MissedCallsNoType1
332GSM5037228CBS_IMSI_dependent_1_Struct
432GSM503842Voice
532GSM503944RTC
632GSM504050UI_Organizer_Alarm_List_Struct
732GSM5041240UI_Organizer_Alarm_Struct
832GSM5042240UI_Organizer_Alarm_Struct
932GSM5043240UI_Organizer_Alarm_Struct
1032GSM5044240UI_Organizer_Alarm_Struct
1132GSM5045240UI_Organizer_Alarm_Struct
1232GSM5046240UI_Organizer_Alarm_Struct
1332GSM5047150UI
1432GSM5048150UI
1532GSM5049150UI
1632GSM5050150UI
1732GSM5051150UI
1832GSM5052150UI
1932GSM5053150UI
2032GSM5054150UI
2132GSM5055150UI
2232GSM5056150UI
2332GSM5057180UI_ME_Ext_Type1_Struct
2432GSM5058116Calculator
2532GSM5059676Business_Card_Struct
2632GSM50616920perator
2732GSM506290GamesData
2832GSM50642Data-Services
2932GSM50674RR-Full-Configuarion
3032GSM506812WAP
3132GSM507022Ext.
3232GSM50711806User
3332GSM5072240WAP-Profil
3432GSM5073240WAP-Profil
3532GSM50742CellBroadcast-Card
3632GSM50758MMI-Options
3732GSM507632Greeting
3832GSM5077232
3932GSM507844Menu-mode
4032GSM50791024Tegic
4132GSM508022
4232GSM5081242Stoppuhr
4332GSM5082200Pictures
4432GSM5083310Menu-Profiles
4532GSM5084172Dialup
4632GSM5085202EEFULL_SCRIPT_PARAMETERS
4732GSM5087148WAP
4832GSM5088148WAP
4932GSM5089148WAP
5032GSM5090148WAP-Profil
5132GSM509212RTC
5232Bootprotection509328Battery
5332Gain5094240WAP-Profil
54135095240WAP-Profil
55145096240WAP-Profil
5648swichchannellist(for tuna/IFX)509716Special_SMS_Message_Indication
5748StartValueList5098332WAP-Bookmark
58451PGCGainDeviationFloatFix5099332Browser
6492ReceptionGapFrequencyControl5100332WAP-Bookmark
6540DSP5101332WAP-Bookmark
668Audio-Initialisierung5102332WAP-Bookmark
6720Measurement5103332WAP-Bookmark
692560AcousticParameters5104332WAP-Bookmark
71200Factory5105332WAP-Bookmark
726RR_Config_Block5106332WAP-Bookmark
733202Ringer511928
744Emergency512016
7546512156
761051226
14082Ringer/keyclick setting51234
1418Soundchip5138402SMS
14238TXPWM5142240UI_Organizer_Alarm_Struct
14448Bias51432UI_Organizer_Alarm_Struct
14785144240UI_Organizer_Alarm_Struct
14820Display5145240UI_Organizer_Alarm_Struct
500114EXIT-Code51461048Switch
500264memory manager/FFS(erase counts)51471048Switch
5004140EXIT51481048Switch
500564Initialisation51491048Switch
50063451501048Switch
50074Display-Initialization51511048Switch
500822451521048Switch
50091051531048Switch
50104Entwicklungsflags51541048Switch
50118ServiceInfo51551048Switch
501212Battery515698Please
501336Accessories515798Please
501516SMS515898Please
501656History515998Please
5024171516098Please
502520Charge516198Please
502676Mobile516298Please
502844UI_IMSI_independent_FDK_Struct51634data for sofware update concept/bootabbruch-erkennu
50297851644MP3 player-settings/world clock
503016UI_IMSI_dependent_1_Struct5200480kvSIM_1.0
5031216RedialNumbersType1520596L3Gprs_History
5032216RedialNumbersType15209360User
5033240CallbackNoType152132Dial
5034240
</div>
2008/8/28 11:02:49

简单教程

<div class=t_msgfont id=postmessage_4422062>为了让更多的机油参与测试,在此做个汇总。
一、准备工作
1.要刷过读RAM小说(.bin)的补丁,集成版本中都有。如果机子没刷过这些补丁,自己想办法吧。
2.刷过一卡多号0.9的,要撤销“用户修改部分”;如果没刷,只要刷入“非用户修改部分”就可以了。
二、制作5103.bin、5104.bin
使用“.bin”文件加载“用户修改部分”--即自己的SIM卡资料,是本修改的特点。作用是可以通过短信销毁这些绝密资料,同时为在线切换号码打下基础。
112楼提供了“5103.bin、5104.bin”的模板,是VK版的,要转换成 .bin版,有几种方法。
winming专门提供了转换成 .bin版的小程序,详见:
http://mobile.0110.cn/viewthread ... &extra=page%3D1
这两个文件都有一个文件头,文件头不要修改,SIM资料需要用自己的资料修改。注意5103.bin和5104bin中,将需要在线切换的两个号码 对调位置。
三、刷补丁
刷入112楼和166楼补丁。
四、菜单问题
本人只提供了 .bin模式的菜单,mygod999已经提供了刷入机子的快捷方式,详见:
http://mobile.0110.cn/viewthread ... page%3D1&page=3,48楼
mygod999也提供了双号待机的补丁。
五、使用
云MM有很详细的使用报告,详见:
http://mobile.0110.cn/viewthread ... &extra=page%3D3</div>
Powered by BBSXP 2007 ACCESS © 1998-2024
Processed in 0.02 second(s)