Huawei P9 (PRA-LX1)...
 
Notifications
Clear all

Huawei P9 (PRA-LX1) Screen Lock Bypass

24 Posts
8 Users
1 Reactions
9,179 Views
(@mshibo)
Trusted Member
Joined: 7 years ago
Posts: 35
 

The EFT dongle or similar solutions won't work, since you can't change the boot.img or the kernel.

Although i never actually tried it, i think EFT uses a SystemUI method for Huawei so it "patches" system partition image and doesn't touch boot.img at all. Personally, i was unable to flash any single Huawei in fastboot with EFT.

Yes, it uses this method actually but as I said before not all models supported. It's all about disabling SystemUI so you see no more passcode as there's no UI at all.
It just interests me how they do it as when you even do "temp bl unlock", Huawei phones executes Factory Reset operation and you can't do normal boot unless you let the phone complete it.


   
ReplyQuote
(@arcaine2)
Estimable Member
Joined: 9 years ago
Posts: 239
 

It just interests me how they do it as when you even do "temp bl unlock", Huawei phones executes Factory Reset operation and you can't do normal boot unless you let the phone complete it.

The exploit they uses doesn't execute factory reset. I often write firmware to Huawe with DC-Phoenix tool and it has an ability to exclude some partitions, like userdata for example, and it works. I was able to fix system related errors and keep user data. That exploits temp unlocks bootloader but you're still limited to images signed by Huawei and phone stays in fastboot all the time.

There's also new method used for writing firmware directly in "firmware upgrade mode" without temp unlocking bootloader in fastboot from what i noticed. I"m not sure if it can be used to write modified system though.

Fun fact, even reading bootloader code from Huawei phones directly might lead to factory reset now. I had Y7 2018 yesterday and i used HCU Tool to read bootloader code (no root, just with default connection) and it just wiped itself the moment HCU read the code, then it wiped again once i unlocked bootloader.


   
ReplyQuote
(@mshibo)
Trusted Member
Joined: 7 years ago
Posts: 35
 

The exploit they uses doesn't execute factory reset. I often write firmware to Huawe with DC-Phoenix tool and it has an ability to exclude some partitions, like userdata for example, and it works. I was able to fix system related errors and keep user data. That exploits temp unlocks bootloader but you're still limited to images signed by Huawei and phone stays in fastboot all the time.

I do have DC-Phoenix but never tried the Advanced mode which allow me to exclude some partitions if I wanted to but it's really precious tip that I got from you and I'll try it asap wink

There's also new method used for writing firmware directly in "firmware upgrade mode" without temp unlocking bootloader in fastboot from what i noticed. I"m not sure if it can be used to write modified system though.

Yeah, it uses "Rescue Recovery" method and I can definitely tell that it won't flash any modified binaries.

Fun fact, even reading bootloader code from Huawei phones directly might lead to factory reset now. I had Y7 2018 yesterday and i used HCU Tool to read bootloader code (no root, just with default connection) and it just wiped itself the moment HCU read the code, then it wiped again once i unlocked bootloader.

Actually, I don't understand why it does that! it happened with me before and I still can't get it for what the factory reset but I hope one day I'll understand )


   
ReplyQuote
(@henrynicolas)
Active Member
Joined: 6 years ago
Posts: 10
 

In this moment test by EFT dongle pro this tool offet remove screen lock by fastboot


   
ReplyQuote
(@bogus)
New Member
Joined: 5 years ago
Posts: 3
 

@henrynicolas

I know it has been a while but I'll take a chance.

Ok, i have EFT Pro but it supports PRA-LX1 with 8.0.0 security version only. Mine has 5.0.0 (probably) and doesn't cooparates.

Any suggestions?

 

 


   
ReplyQuote
(@arcaine2)
Estimable Member
Joined: 9 years ago
Posts: 239
 

It can't have 5.0.0. PRA-LX1 was released with 7.0. It is possibile to update the phone to 8.0 without wiping it, essentially by deselecting userdata partition while flashing the phone with EFT Pro and then this method will work. Keep in mind that EFT is very pick picky about drivers and it's recommended to use the one they suggest (there's a link on gsmhosting forum) or you may be stuck without a lockscreen and abiltiy to retry the process.


   
ReplyQuote
passcodeunlock
(@passcodeunlock)
Prominent Member
Joined: 9 years ago
Posts: 792
 

I can make a decrypted full filesystem dump of it, no matter if the user lock is known or not, the FRP is locked or not or the phone BL is locked or not!!!


   
ReplyQuote
(@bogus)
New Member
Joined: 5 years ago
Posts: 3
 

@arcaine2

Thank you @arcaine2.

With all due respect but accordingly to EFT this phone has  PRA-LX1C432B162 software version which indicates EMUI 5.

Have you ever practiced upgrading firmware or it’s just theory?

And one more question.

I assume you have experience with EFT so, I have pattern locked ANE-LX1 with “ANE-LX18.0.0.180(C432)”. To unlock EFT needs “UPDATE.APP firmware that matches device version & security”. But their FTP doesn’t offer exactly such a firmware. Which one would you use?

Best regards.


   
ReplyQuote
passcodeunlock
(@passcodeunlock)
Prominent Member
Joined: 9 years ago
Posts: 792
 

@bogus: I found another way around it, without the need to flash anything, forget EFT or other "promising", but mostly not working tools...


   
ReplyQuote
(@bogus)
New Member
Joined: 5 years ago
Posts: 3
 

@passcodeunlock Congrats but I  presume I cannot afford for your services 🙁


   
ReplyQuote
Page 2 / 3
Share: