Thinkpad T440 and BIOS/UEFI passwords

@catsay

Do you think these exploits can help or is a DXE Driver mandatory or the easiest way?


How do you write the small DXE Driver? It’s the hardest part.
Hopefully you can provide some more information to us.

@catsay , so the only thing that we have to find is the DXE driver ?

I have a T440 which is locked, from the company that i bought it from , and appearantly it was a scam , so they didn’t provide me extra with the SVP code.

I have previously restored many BIOS, from T410 all the way to T430 ,and even the “s” .
But for the T440 is a challenge.

P.S:About the romanian guy ,when i had contacted him ,requesting for a service etc. he was not polite at all ,so i don’t trust him,nor his services.

How did you downgrade bios if there was no post? i’m in the same situation

hi, I’m from Poland. He works in a company that sells used laptops bought from companies, many of them have SVP. Such as T440, T450 etc. I have been trying to break that password for some time, but without a result. I am happy to help you solve this problem :). My last idea is try to read eprom from MEC1633L, but I do not know how to do it.

@Soeryobadja your programmer is reporting an error because you did not desolder the BIOS chip. When you connect your motherboard programmer it takes too much electricity and your programmer stops operations.

So the best solution , would be to find a programmer that can take the MEC1633L off, and re-program it ?

This is not about the main MEC1633 memory but about the small EEPROM it can be read by the i2c bus, I think. I do not know how to do it, I guess you can use Arduino. There is one problem, it is called TMP (TRUSTED PLATFORM MODULE) I am not sure but it can encrypt data from MEC1633L.

Yeah , but again what will you program on it? :frowning:

I have access to other T440 etc. I can replace the contents of EEPROM with SVP to those that are not blocked.

I have aswell access to T440p etc. but we have to find a suitable programmer, to program the EEPROM or the [SMSC MEC1633L]

@catsay Can you shine some light over here ? :slight_smile:

Actualy you cannot write the mec 1633 fully with programmer. The “easyest” or known solution would be to change the mec chip and rewrite it.
The mec chip has a 2kb memory that stores the information of laptop and supervisor password. I rewrited it a couple times but password still there. I can only erase that 2kb part, but the laptop dies. There is on the net a patched bios, stollen from allservice, i have it, but it gives the id code and that need a unlock code too. every time you start the laptop it generates another 7 digit id that require a 7 digit password. i have 3 digit with password, i bought them from the web, but unfortunately i cannot break that password. if somewone knows what i am talking about and want and can help, please pm me. You need c++ knowlege withc unfortunately i don’t have

apparently there was a leak about 2 months ago on a public forum with all needed files, but the moderator deleted it. They just want to make money for themselves

how do you know @alecs_ro?

this is the link where was the leak: https://www.ghostlyhaks.com/forum/rom-eeprom-bios-efi-uefi/2681-lenovo-t460-unlock-with-bot

You can read more about it here: https://www.ghostlyhaks.com/forum/rom-eeprom-bios-efi-uefi/2631-newer-lenovo-bios-password-unlock

If links are not allowed, please forgive me and delete post.

Dear friend i’m working on lenovo generator Key (key.exe) can u provide me file edited by allservice for extrating the driver dxe mail me the file if you have it thanks.

Give me your email

I did that… apparently i bricked mine :frowning:

@Meziane_AbdelJalil i have such a file. what is your email?

i flash an older BIOS onto the chip, it involves opening the laptop and accessing the chip with a hardware programmer

Thanks for the explaination.