KMX1 unlocks TP

 

Home
Up
Read this First
KeyMaker X1
KeyMaker LCD
Buy Now
Delivery times
Firmware Update
Functionality Upgrade
Damaged Board
Safety Precautions
User's Guides
EEPROM Locations
Customer Feedback
Reference Docs
New Page 3

Up Activate KMX1 Activate KMX1PRO Activate KMX1PROS KMX1 unlocks TP KMX1 Zap KMX1 + KMX-LCD KMX1 + PC 93C46 Connections Save EEPROM Write EEPROM KMX1 Diagnostic FTDI Driver Install

Safety Precautions to ensure that your KeyMaker Board and ThinkPad are not damaged

In order to avoid damage to your KeyMaker Board as well as the ThinkPad you are using it on, there are certain precautions you MUST observe.

If you ignore these precautions you will join the 3% of customers who bought a KeyMaker board - ignored these precautions and damaged their KeyMaker Board  by being careless - then had to pay to have it replaced - and lost a lot of time in the process.

Your KeyMaker has electrical contacts on both sides, you must ensure that no part of your KeyMaker USB board comes into contact with any conductive surfaces such as bare metal or bare wires.

You should place down a piece of paper and place your KeyMaker USB on top of it in order to avoid any electrical contact which may damage your KeyMaker.

There is no danger of receiving an electrical shock from your KeyMaker USB as the highest voltage anywhere on the board is 5 Volts which is a safe voltage to touch.

If you prefer you can place your KeyMaker USB board inside an Anti-Static  plastic bag during use, the board does not get warm at all, so there is no issue with ventilation.

The same precautions apply to your ThinkPad when you are performing any operation and BEFORE your ThinkPad is switched ON, you must ensure that nothing can short out by coming into contact with other parts, you can use sheets of plastic or plain paper to make sure things remain electrically isolated.

You MUST NOT allow the SDA and SCL leads from any KeyMaker KMX1 or KMX2 to come into contact with ANYTHING other than the correct SDA and SDA EEPROM connections points and ONLY AFTER;

You have traced the wire you are using for your probe right back to the label on the I2C header on the KeyMaker board which reads SDA for YOUR SDA lead and reads SCL for YOUR SCL lead.

You have absolutely confirmed that you have correctly identified the SDA and SCL connection points on your ThinkPad System Board.

3% of customers who purchased a KeyMaker Board have somehow managed to damaged their KeyMaker board.

NOT ONE of those customers can tell me exactly what he or she did to damage it.

I have tried all sorts of seriously ridiculous ways to damage a KeyMaker board and I have NOT BEEN ABLE TO DAMAGE ONE !

I only tried MILDLY STUPID THINGS like connecting a solid 9 Volt source to SDA and SCL - theoretically that should have damaged the I/O pin on that KeyMaker powered from 3.3 Volts, IT DIDN'T.

Your KeyMaker board is a delicate piece of equipment, treat it with respect.

Do NOT experiment or connect to anything if you are not certain you have the correct connection points identified.

There are voltages much higher than 3.3 Volts inside your ThinkPad, in fact up to 20 Volts. 

20 Volts is not a danger to YOU but it is to the KeyMaker KMX1 or KMX2.

Connect SDA and SCL leads ONLY if you have double checked and are CERTAIN you have correctly identified SDA and SCL connection points

The above is VERY IMPORTANT - don't ignore it else you WILL damage your KeyMaker KMX1 or KMX2 board and that is expensive, wastes a lot of time and is not much fun.

Read more on Safety Precautions here

Before you can use KMX1 to unlock any TP you must first Activate it

If the Activity LED on your KMX1 is flashing continuously that means
it has not been Activated

Put simply, do not waste your time trying to use the KMX1 series board until after it has been Activated.

The following videos use earlier board revisions with Red colour
Activity LED, current V4 board has Blue Activity Led

NOT activated KMX1 flashing Activity LED
 

KMX1 hardware revision can be one of the 4 boards depicted below which are functionally identical

KeyMaker KMX1 can Recover or Clear the SVP in 3 different ways

KMX1 Zap 

KMX1 powered by a USB Port on the locked TP, using the Zap SVP button on KMX1. Works with TP models which on the EEPROM Locations webpage it states to "treat as 24RF08" or "treat as LSI"

KMX1 Zap SVP button unlocking a Pass phrase SVP from an R60
 

KMX1 + LCD   

KMX1 used together with the KMX-LCD board powered by a USB Port on the locked TP, using the Joystick to scroll through menus and select nearly all possible operations with excellent status display. 

KMX-LCD board plugs in on top of the KMX1 board, the KMX-LCD has an I2C connector which includes the protection resistors, KMX-LCD is controlled by the user operating the Joystick.

The secondary Zap SVP button on the KMX-LCD can also be used to Zap SVP on TP models which on the EEPROM Locations webpage it states to "treat as 24RF08" or "treat as LSI", the LCD provides additional status information not available without the KMX-LCD.

Photo depicts an early prototype of KMX-LCD

KMX-LCD displaying recovered SVP ready to type in on a QWERTY 'US' keyboard, you can also select to display the recovered SVP for typing in on a  German or French keyboard. The KMX-LCD also displays the 5 second delay countdown after the ZAP SVP button is pressed, delay can be set to 0,5,10 or 15 seconds.

Video - KMX1 working together with [prototype]  KMX-LCD recovering and Clearing Supervisor Password from a Lenovo R60
NOTE: There are in fact 2 ITEMS, a KMX1 with the KMX-LCD plugged in on top of the KMX1.
KMX-LCD on its own does NOTHING!

 

KMX1 + PC 

KMX1 powered by a USB Port on ANOTHER PC or Laptop, using Terminal Software on the PC to display KMX1 menus and status. Works with all TP models. 

With KMX1PRO and also KMX1PROS the PC can be used to save Intel HEX files of complete EEPROMS which can also be written back to the EEPROM in the TP

KMX1 PRO S offers the additional feature of displaying the last 55 SVP [saved in Non Volatile Memory within the KMX1PRO] that have been Recovered or Cleared including those cleared with the Zap SVP button.

NOTE: Another PC or Laptop is required, NOT the locked TP which obviously cannot be used to run any software before it is unlocked.

 

Recover 24RF08 SVP



-- US English QWERTY Keyboard selected --
SVP  -> ABCDEFG <-NSC- hex 1E 30 2E 20 12 21 22 F1
CSVP-> ABCDEFG <-NSC- hex 1E 30 2E 20 12 21 22 F1



ONLY if you are all done,

Disconnect SDA first
Disconnect SCL next
Disconnect GND last


======== Joe in Australia KeyMaker KMX1 ============
Serial Number: KMX1-92517
All rights reserved copying is not permitted
Joe in Australia tpx20@ja.axxs.net www.ja.axxs.net
===================================================


KMX1 24RF08 menu - 5 second delay -

1 .. Recover 24RF08 SVP
2 .. Clear 24RF08 SVP

X .. EXIT to main menu

Type a command number->

TRANSLATION to other languages 

To translate the information on this website to other languages, you may try the following links;

http://www.freetranslation.com/    translates entire web pages, practically unlimited.

 

Up Activate KMX1 Activate KMX1PRO Activate KMX1PROS KMX1 unlocks TP KMX1 Zap KMX1 + KMX-LCD KMX1 + PC 93C46 Connections Save EEPROM Write EEPROM KMX1 Diagnostic FTDI Driver Install

Disclaimer

I make no warranty that any of my information is correct, or safe, or does or does not breach any warranty clause,  or anything else, it is up to you to decide if you will follow all or any of the instructions to recover the Supervisor Password from a TP. It is up to you to decide, I am not responsible for the results or for any consequential or incidental damages whatsoever.

If you have any questions, email Joe at

Hit Counter