ALLservice Service Forum
support board, PC repair, unlocking solutions
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

Unlocking all new Thinkpads T440..T495, P53, X1 Extreme, etc

 
Post new topic   This topic is locked: you cannot edit posts or make replies.    Service Forum Forum Index -> IBM/Lenovo ThinkPad Password Help Center (EN)
View previous topic :: View next topic  
Author Message
victor
S.F. Boss


Joined: 07 Mar 2004
Posts: 2546
Location: Staff

PostPosted: Mon Oct 12, 2015 10:17 am    Post subject: Unlocking all new Thinkpads T440..T495, P53, X1 Extreme, etc Reply with quote

These models listed below are using SMSC MEC1633L (or equivalents) to store the Supervisor password. Maybe Lenovo will come around with another chip for the next models, so we will update the list with all those we tested already.

What we unlocked so far: see a more detailed list in the next post (scroll down more):

Unlocking solution is finally available and requires SPEG programmer to be able to flash the BIOS.

The process is:
1. Reading the BIOS and create a valid dump. In a Thinkpad, the BIOS is married to the internal TPM chip and contains a unique signature of it, so it is important that the original BIOS to be a correct read out for the success of the whole operation and to restore the BIOS afterwards.

2. Patching the BIOS binaries and inject a small allservice.ro UEFI program. This program will read the secure eeprom, reset TPM certificate and password, write secure eeprom and reconstruct all data.

3. Write the patched BIOS dump (this will only function in that TP btw), start the laptop and generate a Hardware ID. We will send you a unique key that will activate the Allservice BIOS, while the BIOS is loading it will execute the unlock routine and unlock the SVP and TPM.

4. Finally, write the original BIOS dump back for normal operations and enjoy the laptop.

We can also disable Computrace or change the SN/UUID and reset RFID checksum error by using our UEFI program in the same manner, if necessary

The unlock service price is per machine (like we do for the Macbook/iMac, HP, Acer, etc) For service price and availability please read the next post below. You may contact support@allservice.ro for any inquiry.


We shall be able to also provide, for service shops only, a software solution that is able to dump/flash the MEC controller secure area from an USB device, and to have more control of the security operations, more like the usual way. Though this solution is still in progress..
_________________
Victor Voinea
ALLservice HQ, Romania.


Last edited by victor on Wed Aug 26, 2020 12:35 pm; edited 62 times in total
Back to top
View user's profile Send private message
victor
S.F. Boss


Joined: 07 Mar 2004
Posts: 2546
Location: Staff

PostPosted: Wed Oct 21, 2015 3:48 pm    Post subject: Allservice unlock solution. UEFI DXE Driver Reply with quote

October 2015 - onwards.
The very final DXE driver version is finished and can do everything automatically: read MEC1633L secure eeprom, reset the SVP and certificate, write the secure eeprom, then reset TPM and de-activate Computrace (if active) and set the correct checksums. All in one step, you have to only load the patched BIOS and fire it up. All will be done in a few seconds.

UPDATED Aug 2023

We tested it with the follwing (all submodels included. The list might be outdated!):
A275, E450, E460, E470, E570, E480, E570, E550, E560, L450, L460, L560, T440, T440s, T440p, T450, T450s, T450p, T540, T540p, T550, W540, W541, W550s, X240, X250, X1 carbon gen2..gen6, Helix new gen, Thinkpad Yoga 11e, 12 and Yoga 15(with Compal Embedded Controller*), Lenovo 13, P40, P50, P51 and P70. We also unlocked the latest Yoga 260, Yoga 370, Yoga 460, X260, X270, X280, T460, T460s, T560, T470, T470s, T480, T480s, T570, T580, X1 Tablet G1, G2 & G3, all featuring the new ACM and BootGuard Key Manifest. Unlocked also Thinkpad P40 Yoga, P51, P52 P53 and Lenovo 13 and X1 carbon gen6, X1 Yoga gen 3, X380 Yoga, P1, X1 Extreme G1, T490, T495, X390, L390, L13 and L13 Yoga, T14s, X13, A475, A485

-------------------------------------------------------------------------------------
Demo with a X1 gen 6 booting our BIOS faster than the original. No beeping or other errors. Of course, this is a temporary boot on for the unlocking operation only.
https://www.allservice.ro/forum/images/IMG_8535.MOV
And unlocking X280, X380 Yoga with Bootguard active and the latest Allservice firmware.
https://www.allservice.ro/forum/images/IMG_2154.MOV
https://www.allservice.ro/forum/images/IMG_2155.MOV

-------------------------------------------------------------------------------------
*The solution will work in any new models including those with Compal EC.

Since Oct 2015, our service is also available "per machine", you can buy one unlock only, meaning the original patched BIOS will only work once and only on the locked laptop (naturally, the BIOS contains the unique TCG/TPM signature), based on a unique Hardware ID. Our support team will prepare the BIOS for you.

Updated price list for current models

  • EURO 20: A275, E450, E460, E470, E550, E560, L460, L560, T440, T440s, T440p, T450, T450s, T450p, T540, T540p, T550, W540, W541, W550s, X240, X250, X1 carbon gen2..gen3, Helix new gen, Thinkpad Yoga 11e, 12 and Yoga 15.
  • EURO 25: E480, E580, Lenovo 13, L470, L570, P40, P50, P70, X1 Yoga gen1..gen2, Yoga 260, Yoga 370, Yoga 460, X260, X270, X1 carbon gen4..gen5, X1 Tablet Gen1, T460, T460s, T560, T470, T470s, T570.
  • EURO 30: A475, P51, P51s, P52, T480, T580, X280, X1 carbon gen6, X1 Tablet Gen2, X1 Yoga gen3, X380 Yoga
  • EURO 55: P1, X1 Tablet Gen3, L390, X390, P53, T490, T495, T590, X1 Extreme Gen1, X1 Carbon Gen7, X1 Carbon G8, X1 Yoga Gen4, X1 Yoga Gen5, L13 and L13 Yoga, T14s, X13, A485, X1 Fold Gen1- some of these momentarily only available in our store https://www.allservice.ro/shopall/product-category/services/lenovo/
    Contact us at support@allservice.ro if you have any questions.


To order the unlock service:

1.a. If you have a SPI flash programmer then read the laptop's BIOS (8pin SOIC) and obtain a valid dump. Note that some models, i. e. T440p/T540p, have two BIOS chips so we need both of them.
1.b. If you don't have such device, then you may order SPEG in our store
https://www.allservice.ro/shopall/product-category/products/
This service is NOT INCLUDED with SPEG, therefore is not a bonus for buying SPEG programmer!

2. Send the payment for the service (See price list above) via PayPal to support@allservice.ro (or buy the service in our store and finalize the checkout with PayPal) then email the BIOS dump to the same email address, also email us the S/N and LAN MAC that is located on the RAM socket stickers.

Note: if you want us to email you a complete invoice for SPEG + service then contact us at support@allservice.ro

3. We will verify the BIOS integrity, we will check the MAC and TCPA sig to see if they are genuine then patch the BIOS with our Allservice UEFI DXE (boot service driver) modules and send it to you along with the activation key for your laptop.

BEWARE of counterfeits. IF IT AIN'T FROM US THEN IS 100% NOT ORIGINAL!
We professionally provide our unlocking/BIOS repair service for over 80 service centers worldwide, and we are the ONLY ONES selling OUR software or services online, here at allservice.ro. We do not have agreements and we do not allow third parties to resell our service over the Internet!
Therefore if you see some websites or individuals claiming that they can unlock latest Lenovo models and sell you an "Allservice" BIOS then they are scam or they send you a counterfeit or pirated Allservice BIOS file!
And because our BIOS firmware is serial numbered and particularly signed for each laptop, it is a high risk that this will make your Thinkpad security chip INOPERABLE and is too late to come back to us for help, your laptop might be bricked forever!

If you think you're a victim of a counterfeit/scam then claim your money back. NEVER feed the hackers/scammers/counterfeiters.
Make sure you use PayPal whenever possible to be covered just in case..

You may contact us at support@allservice.ro for any question or support.


Screenshot of the BIOS POST on T440s motherboard with initial version and P52 with latest release.
Also see below (scroll down more) the BIOS location for all mentioned models.

T440s motherboard with initial release.



Yoga 260


T470s


X280


P52


Keep in mind that this list might be outdated as we service new models every day. Not all models we unlocked are in the list or pictured below. Email us at support@allservice.ro if you have any question regarding your model.

Lenovo E470
https://www.allservice.ro/forum/images/E470_bios.jpg

Lenovo E560
https://www.allservice.ro/forum/images/E560_bios.jpg

Lenovo L450, L460, L560*
https://www.allservice.ro/forum/images/L450_bios.jpg
https://www.allservice.ro/forum/images/L460_bios.jpg
https://www.allservice.ro/forum/images/L560_bios.jpg

*Both models may have only one 16Mbyte chip or 2x8Mbyte chips.

Lenovo L470
https://www.allservice.ro/forum/images/L470_bios.jpg

Helix new generations
https://www.allservice.ro/forum/images/helix_newgen_bios.jpg

T440/T440s
https://www.allservice.ro/forum/images/T440s_bios.jpg

T450/T450S
https://www.allservice.ro/forum/images/T450_bios.jpg
https://www.allservice.ro/forum/images/T450s_bios.jpg

T460/T460s
https://www.allservice.ro/forum/images/T460_bios.jpg
https://www.allservice.ro/forum/images/T460s_bios.jpg

T470/T470s
https://www.allservice.ro/forum/images/T470_bios.jpg
https://www.allservice.ro/forum/images/T470s_bios.jpg

T480
https://www.allservice.ro/forum/images/T480_bios.jpg

T490/T490S
https://www.allservice.ro/forum/images/T490_bios.jpg
https://www.allservice.ro/forum/images/T490s_bios.jpg

T495/T495S
https://www.allservice.ro/forum/images/T495s_bios.jpg

T540/T540p
https://www.allservice.ro/forum/images/W540_T540_bios.jpg
https://www.allservice.ro/forum/images/T540p_bios.jpg

T550/W550
https://www.allservice.ro/forum/images/T550_bios.jpg

T560
https://www.allservice.ro/forum/images/T560_bios.jpg

T570
https://www.allservice.ro/forum/images/T570_bios.jpg

T580
https://www.allservice.ro/forum/images/T580_bios.jpg

W540/W541
https://www.allservice.ro/forum/images/W540_T540_bios.jpg
https://www.allservice.ro/forum/images/W541_bios.jpg

X1 Carbon/X1 Yoga
https://www.allservice.ro/forum/images/X1gen3-bios.jpg
https://www.allservice.ro/forum/images/X1_Yoga_bios.jpg

X1 Tablet G1/G2/G3
https://www.allservice.ro/forum/images/X1TabletG2_bios.jpg
https://www.allservice.ro/forum/images/X1TabletG3_bios.jpg

X240/X250/X260
https://www.allservice.ro/forum/images/X240_bios.jpg
https://www.allservice.ro/forum/images/X250_bios.jpg
https://www.allservice.ro/forum/images/X260_bios.jpg

X280
https://www.allservice.ro/forum/images/X280_bios.jpg

X380 Yoga
https://www.allservice.ro/forum/images/X380Yoga_bios.jpg

P50/P51/P52/P70
https://www.allservice.ro/forum/images/P50_bios.jpg
https://www.allservice.ro/forum/images/P50_bios1.jpg

https://www.allservice.ro/forum/images/P51_bios.jpg
https://www.allservice.ro/forum/images/P52_bios2.jpg

https://www.allservice.ro/forum/images/P70_bios.jpg
https://www.allservice.ro/forum/images/P70_bios_short.jpg

P40 Yoga
https://www.allservice.ro/forum/images/P40_Yoga_bios.jpg

Thinkpad Yoga 12 and Yoga 15
https://www.allservice.ro/forum/images/Thinkpad_Yoga12_bios.jpg

Yoga 260, Yoga 370, Yoga 470
https://www.allservice.ro/forum/images/Yoga260_bios.jpg
https://www.allservice.ro/forum/images/Yoga370_bios.jpg

Lenovo 13
https://www.allservice.ro/forum/images/Lenovo13_bios.jpg

Lenovo A275
https://www.allservice.ro/forum/images/A275_bios.jpg

Lenovo X1 Fold Gen1
https://www.allservice.ro/forum/images/X1FoldG1_Bios.jpg


All images are property of www.allservice.ro
_________________
Victor Voinea
ALLservice HQ, Romania.
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   This topic is locked: you cannot edit posts or make replies.    Service Forum Forum Index -> IBM/Lenovo ThinkPad Password Help Center (EN) All times are GMT + 2 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



Powered by phpBB © 2001, 2005 phpBB Group