Hovatek Forum DEVELOPMENT Android [Please help] Rooting wiko Y80 (locked unisoc bootloader)
Can't login? Please, reset your password.
Hovatek is recruiting! Apply Now


[Please help] Rooting wiko Y80 (locked unisoc bootloader)

[Please help] Rooting wiko Y80 (locked unisoc bootloader)

gerard1085
gerard1085
gerard1085
Newbie
3
18-02-2021, 10:48 PM
#1



Hello all,
I absolutely need to root my phone (i bought it only to install andrax over it Smile )
So now i know more about this stuff (and i'm begining to reget buying it)
Its a spreadtrum unisoc device powered by Unisoc SC9863A.

Ok, i got adb & fastboot tools with adequates drivers (adb & fastboot).
I understood the bootloader need to be unlocked by an adequate tool (the fastboot modified version).

So ok , i'm using a linux into virtualbox, everything work ok (adb devices Ok , fastboot devices Ok).
But i can't unlock the bootloader with it, probably because the private key bundled with the tools is not enough for my wiko y80.

So , is there an other way to root it ??
I get some interesting files gathered over internet , it seems to be some private keys.
But i can't use them with fastboot too Sad

Got any idea ?
Attached Files
.zip
Android_key_V720_9.0_WIK_SUN_CH_10.bin.zip
Size: 7.39 KB / Downloads: 25
X3non
X3non
X3non
Recognized Contributor
22,062
19-02-2021, 09:35 AM
#2
(18-02-2021, 10:48 PM)gerard1085 Hello all,
I absolutely need to root my phone (i bought it only to install andrax over it Smile )
So now i know more about this stuff (and i'm begining to reget buying it)
Its a spreadtrum unisoc device powered by Unisoc SC9863A.

Ok, i got adb & fastboot tools with adequates drivers (adb & fastboot).
I understood the bootloader need to be unlocked by an adequate tool (the fastboot modified version).

So ok , i'm using a linux into virtualbox, everything work ok (adb devices Ok , fastboot devices Ok).
But i can't unlock the bootloader with it, probably because the private key bundled with the tools is not enough for my wiko y80.

So , is there an other way to root it ??
I get some interesting files gathered over internet , it seems to be some private keys.
But i can't use them with fastboot too Sad

Got any idea ?

what's the output of info_image on your vbmeta ; see https://www.hovatek.com/forum/thread-32666.html
only interested in the output of algorithm i.e SHA256_RSA****
gerard1085
gerard1085
gerard1085
Newbie
3
19-02-2021, 12:47 PM
#3
(19-02-2021, 09:35 AM)X3non
(18-02-2021, 10:48 PM)gerard1085 Hello all,
I absolutely need to root my phone (i bought it only to install andrax over it Smile )
So now i know more about this stuff (and i'm begining to reget buying it)
Its a spreadtrum unisoc device powered by Unisoc SC9863A.

Ok, i got adb & fastboot tools with adequates drivers (adb & fastboot).
I understood the bootloader need to be unlocked by an adequate tool (the fastboot modified version).

So ok , i'm using a linux into virtualbox, everything work ok (adb devices Ok , fastboot devices Ok).
But i can't unlock the bootloader with it, probably because the private key bundled with the tools is not enough for my wiko y80.

So , is there an other way to root it ??
I get some interesting files gathered over internet , it seems to be some private keys.
But i can't use them with fastboot too Sad

Got any idea ?

what's the output of info_image on your vbmeta ; see https://www.hovatek.com/forum/thread-32666.html
only interested in the output of algorithm i.e SHA256_RSA****

Ok , my build and phone versions are :
build PPR1.180610.011
version w-v720-eea-v01.38.20.9.0-gbl
I can't extract the vmbeta from my phone since it is not rooted and bootloader is locked.
But i managed to get the firmware upgrade v1.180610.011 / v.01.38.2.9.0 from wiko official site, and extracted content of pac file in a temporary directory.
My phone is already on build 1.180610.011/ v01.38.20.9.0 so i'm sure its the same vmbeta file into it.

So here what i get :
Minimum libavb version: 1.0
Header Block: 256 bytes
Authentication Block: 576 bytes
Auxiliary Block: 13504 bytes
Public key (sha1): 77527123b17b956a8da8b3ccd921bc0ec9d97b59
Algorithm: SHA256_RSA4096

Its the same public key from the wiko y80sun firmware found on the internet wich package the miscellaneous private keys (in my zip attachment).
Maybe something interesting could be done with that ??
This post was last modified: 19-02-2021, 12:49 PM by gerard1085.
X3non
X3non
X3non
Recognized Contributor
22,062
19-02-2021, 10:23 PM
#4
(19-02-2021, 12:47 PM)gerard1085 ...
Maybe something interesting could be done with that ??

it surely seems so. turns out that the bin file is actually an xml file that includes an rsa4096 key! you could open the bin file using a text editor e.g notepad++ to view the contents. i've copied the rsa key out into the code tag below if you don't find it within the bin
save the rsa key and use it to attempt unlocking bootloader, lets know if it works or not

Code:

-----BEGIN RSA PRIVATE KEY-----
MIIG5QIBAAKCAYEA4I/kv8YbrJ4ij4ziqMxzkHGGBlxj1sQMVM7TmkFJViQqD9Uf
+fA0L2qVjI1QOczkg1EWhgZLyU/RAYpYt1THUE6bCZ3cnl4gutDUS0hqRuj2ma01
2GzriTnH0hsZ13mrehxJeyhVp4Dp1fYWT7jjASL9xoSBuJHnpy+LGp/OImrEwZLP
07Q2YNc2lUkSj2YCa3vvCi0sgu7ol/j6EdG12TxjeUIQpFydXU/Hmpci080pKtm4
lttfVTdEbUhxPX2m7qYCryoxDBc3g+eS5LvHO0wQBAyapwVguFB7E6WSu5TZG/JI
2D1L/IhtiTC9bI13FUegA3HGoS+KoZkbKP5EUQrfaWLGrsn7uLzXxxnyfby2gen3
rK3houyTS9S/tI6b1ZBce2mnA8NBsuRSfS6S0vxbCTetrazPjq04pe1f5zNso1Mj
NrwWww6CC4YiWnmOJ8lpzifZ3CK0B0JX9VB/1bislQKcpEQFrjky4WDCCDOvdMqQ
V9oUpYLiendjCjN5AgMBAAECggGBANgEM3TzGn4DpJVYXlUoT2a8fcOyrmvTLVWL
m+wAL47IvRl72AWzNlAChJeu/GSNn6heoX8NoWum9xQ3RD4fNJgg9WzbyXUicPOk
nQNKRsmtokKUZ36o0C6yQXDwlvw7U2PkwB7T3wmBre8fibjozp2yTlLf9nVZDXE6
/+H9pepfsKPRGVC6Q7EGdcBHia4d3+gLURgF+pJ9RYujetMXW4n8WGg10BJ78Pjp
HMat6le6PIa256Veo6cywgUqMZyIN/YhbRgnVgJOtTurtxdiAa1oMRkxbkWvCkfW
rzfYWKY+OHPozPPyMkGOc7y9Kj6/6KvdI22BKKCUU2inVwUtTQwxWxhBCCREq3E6
JgQX32e5wn3MjmTDV31tmA2ieHkPGpjLizkhlDmq0ZDL4iecziluPYCVIU3oiOYr
573Lmk1WEu3vmAu6zYE023Z2jrUsypAYO31odRCx37coauVL0rPeaYs6dzz2LvWx
penSvpxEyTi5AFbY5qeW9ViDcA9nAQKBwQD5olq5+ukoekJAS4OHPnpK3+4P4TIF
cwSk0vsDEoYTT082Vp7XNmC+GO3aQ3nY7tX6Ft0ANC/ceSzHAo/X4rf+yMf4ED5N
UhM4avXlJjDrIOwu/vLbRvFH0dP0SugOHade4LqKA0Jshr7/F1NW6YBTsQpIsgTw
k7p5PTuILxECAv2uGDRdrk4hY6P4UsNrgvX8qrkm1rQNxdUVfmqHQyD4uiOJhA51
nKZx1u162RDUy0XyD4co39xgFyQQTwjnI+ECgcEA5kndcoA24VUHQGXViTw2BM29
/2IUkuIAsr9uDJrT6RClG3XWym0MnasywqNQcxBxBSQ7twfZTOF1gv7K1zQXGC0R
bBVjjH0Jvy1qhVTnHZ1N2S53c2jg/r9C8eWAIqsjagD9MmFjgGHoqh9Lpbtfx6ie
bzEBeS7ecJfiuxhMI2bnIX+AnT59uS5+NleRQUauVhyPUxwratrl0a5ZPCzwSHDD
AD8B3cp8QiKsdresAdEVVoZSyvTzddSOKczWXgKZAoHBAPcUDLx7bf7UU3KTy1E3
M4+caGJrQDlIiFYjRLLbyLygCQT9YyYb+lDtF66qjpV6f2uS6ZbkEGMlxH4NORYy
nm6dh98tJJ0fGUsEAvGVhWGUKnCxguoqI3I0apcm9NvT2e78e2VSqJIGJFETYzdo
0c0EM+uT13POpAiP5LZ771eQYknIRzxZ45cEqiyErkthSduVlsCsTXY8UxV9FC9g
7+d/ROE9RZp/O/b9BfxLkG8t6sMVP2/jcpnhDZ7euy8bwQKBwQCUQA0NfzjVSvXG
IUicdmSYJxMfazavcErex5nDB5FQQuTnjq7d1eH/Ro0A/D34NSdtFexTYfwkICiU
Ug6nB+OuLqU+nW5erMgviL9AYm3+hJvvKpi/dU8S8HHaY9JffyjnPwfA/S0fIuiz
TD5YzQ1V7VlBX50BNIkCluThaTzqtX4p9HkJwYcSRbn+pdTe3u+wg+ZIrKPOwGie
2cycjpmJKP6AFA/Rhl8D/GpmasuSx9UixIpcGeD5hAKZKkL+dlECgcBrgCDW50V/
LeoFZ6dvGe4w0g2i02iwDz0sQT7Yb97l+KsrNv5ZRadxet8Il2uMozoVsz4Ly3l0
5ZMtuLhTnvqfsR13bXJ2pOdG9Tc9nh6L1jua6jcbtlRa7sPwERHfrItzOgTCQ3dS
vt0Z5wBO09LV2lhSFzpnNTJWusA1LFtJySG7lBAA9bBUGnSrTHpgj696oxO+EAbW
dfNTrGWEdaOj6cDsRREkRAYgu/sWjfY9TJuz/tiE3Soog1bWbtaAig8=
-----END RSA PRIVATE KEY-----
gerard1085
gerard1085
gerard1085
Newbie
3
19-02-2021, 10:47 PM
#5



(19-02-2021, 10:23 PM)X3non
(19-02-2021, 12:47 PM)gerard1085 ...
Maybe something interesting could be done with that ??

it surely seems so. turns out that the bin file is actually an xml file that includes an rsa4096 key! you could open the bin file using a text editor e.g notepad++ to view the contents. i've copied the rsa key out into the code tag below if you don't find it within the bin
save the rsa key and use it to attempt unlocking bootloader, lets know if it works or not

Code:

-----BEGIN RSA PRIVATE KEY-----
MIIG5QIBAAKCAYEA4I/kv8YbrJ4ij4ziqMxzkHGGBlxj1sQMVM7TmkFJViQqD9Uf
+fA0L2qVjI1QOczkg1EWhgZLyU/RAYpYt1THUE6bCZ3cnl4gutDUS0hqRuj2ma01
2GzriTnH0hsZ13mrehxJeyhVp4Dp1fYWT7jjASL9xoSBuJHnpy+LGp/OImrEwZLP
07Q2YNc2lUkSj2YCa3vvCi0sgu7ol/j6EdG12TxjeUIQpFydXU/Hmpci080pKtm4
lttfVTdEbUhxPX2m7qYCryoxDBc3g+eS5LvHO0wQBAyapwVguFB7E6WSu5TZG/JI
2D1L/IhtiTC9bI13FUegA3HGoS+KoZkbKP5EUQrfaWLGrsn7uLzXxxnyfby2gen3
rK3houyTS9S/tI6b1ZBce2mnA8NBsuRSfS6S0vxbCTetrazPjq04pe1f5zNso1Mj
NrwWww6CC4YiWnmOJ8lpzifZ3CK0B0JX9VB/1bislQKcpEQFrjky4WDCCDOvdMqQ
V9oUpYLiendjCjN5AgMBAAECggGBANgEM3TzGn4DpJVYXlUoT2a8fcOyrmvTLVWL
m+wAL47IvRl72AWzNlAChJeu/GSNn6heoX8NoWum9xQ3RD4fNJgg9WzbyXUicPOk
nQNKRsmtokKUZ36o0C6yQXDwlvw7U2PkwB7T3wmBre8fibjozp2yTlLf9nVZDXE6
/+H9pepfsKPRGVC6Q7EGdcBHia4d3+gLURgF+pJ9RYujetMXW4n8WGg10BJ78Pjp
HMat6le6PIa256Veo6cywgUqMZyIN/YhbRgnVgJOtTurtxdiAa1oMRkxbkWvCkfW
rzfYWKY+OHPozPPyMkGOc7y9Kj6/6KvdI22BKKCUU2inVwUtTQwxWxhBCCREq3E6
JgQX32e5wn3MjmTDV31tmA2ieHkPGpjLizkhlDmq0ZDL4iecziluPYCVIU3oiOYr
573Lmk1WEu3vmAu6zYE023Z2jrUsypAYO31odRCx37coauVL0rPeaYs6dzz2LvWx
penSvpxEyTi5AFbY5qeW9ViDcA9nAQKBwQD5olq5+ukoekJAS4OHPnpK3+4P4TIF
cwSk0vsDEoYTT082Vp7XNmC+GO3aQ3nY7tX6Ft0ANC/ceSzHAo/X4rf+yMf4ED5N
UhM4avXlJjDrIOwu/vLbRvFH0dP0SugOHade4LqKA0Jshr7/F1NW6YBTsQpIsgTw
k7p5PTuILxECAv2uGDRdrk4hY6P4UsNrgvX8qrkm1rQNxdUVfmqHQyD4uiOJhA51
nKZx1u162RDUy0XyD4co39xgFyQQTwjnI+ECgcEA5kndcoA24VUHQGXViTw2BM29
/2IUkuIAsr9uDJrT6RClG3XWym0MnasywqNQcxBxBSQ7twfZTOF1gv7K1zQXGC0R
bBVjjH0Jvy1qhVTnHZ1N2S53c2jg/r9C8eWAIqsjagD9MmFjgGHoqh9Lpbtfx6ie
bzEBeS7ecJfiuxhMI2bnIX+AnT59uS5+NleRQUauVhyPUxwratrl0a5ZPCzwSHDD
AD8B3cp8QiKsdresAdEVVoZSyvTzddSOKczWXgKZAoHBAPcUDLx7bf7UU3KTy1E3
M4+caGJrQDlIiFYjRLLbyLygCQT9YyYb+lDtF66qjpV6f2uS6ZbkEGMlxH4NORYy
nm6dh98tJJ0fGUsEAvGVhWGUKnCxguoqI3I0apcm9NvT2e78e2VSqJIGJFETYzdo
0c0EM+uT13POpAiP5LZ771eQYknIRzxZ45cEqiyErkthSduVlsCsTXY8UxV9FC9g
7+d/ROE9RZp/O/b9BfxLkG8t6sMVP2/jcpnhDZ7euy8bwQKBwQCUQA0NfzjVSvXG
IUicdmSYJxMfazavcErex5nDB5FQQuTnjq7d1eH/Ro0A/D34NSdtFexTYfwkICiU
Ug6nB+OuLqU+nW5erMgviL9AYm3+hJvvKpi/dU8S8HHaY9JffyjnPwfA/S0fIuiz
TD5YzQ1V7VlBX50BNIkCluThaTzqtX4p9HkJwYcSRbn+pdTe3u+wg+ZIrKPOwGie
2cycjpmJKP6AFA/Rhl8D/GpmasuSx9UixIpcGeD5hAKZKkL+dlECgcBrgCDW50V/
LeoFZ6dvGe4w0g2i02iwDz0sQT7Yb97l+KsrNv5ZRadxet8Il2uMozoVsz4Ly3l0
5ZMtuLhTnvqfsR13bXJ2pOdG9Tc9nh6L1jua6jcbtlRa7sPwERHfrItzOgTCQ3dS
vt0Z5wBO09LV2lhSFzpnNTJWusA1LFtJySG7lBAA9bBUGnSrTHpgj696oxO+EAbW
dfNTrGWEdaOj6cDsRREkRAYgu/sWjfY9TJuz/tiE3Soog1bWbtaAig8=
-----END RSA PRIVATE KEY-----

No it doesn't work better, i already tried with this key.
I think i need to go deeper , every device is rootable , i have to find the way.
For now, i'm even not sure how to handle those cryptographic tools, how can i check if this private key is correct ?
Is there a way to debug what is doing fastboot ?
Actually i get :
downloading 'unlock_message'...
OKAY [ 0.016s]
unlocking bootloader...
FAILED (remote: Unlock bootloader fail.)
finished. total time: 0.124s

Which is everyone get. There is something i haven't checked actually, i got the official firmware upgrade tool from wiko.
But i can't use it , because my phone firmware is already the one from the tool.
I can extract the pac given with the firmwar package, i already did it.
Maybe if there is a way to trick the tool , or use one of the upgradeTool, researchTool, factoryTools ??? or whatever.
Surely there is a way to force an upgrade , and so if it works with the tool , i just have to exchange boot.img with one i modified in magisk...
Maybe..
I really don't know how to get it works, but its surely possible.
X3non
X3non
X3non
Recognized Contributor
22,062
20-02-2021, 10:09 AM
#6
(19-02-2021, 10:47 PM)gerard1085 No it doesn't work better, i already tried with this key.

and you forgot to mention it earlier when you posted the bin


(19-02-2021, 10:47 PM)gerard1085 For now, i'm even not sure how to handle those cryptographic tools, how can i check if this private key is correct ?

you already did, if it's the right key then bootloader will be unlocked, if it's the wrong key then bootloader unlock will fail


(19-02-2021, 10:47 PM)gerard1085 Is there a way to debug what is doing fastboot ?
Actually i get :
downloading 'unlock_message'...
OKAY [ 0.016s]
unlocking bootloader...
FAILED (remote: Unlock bootloader fail.)
finished. total time: 0.124s

wrong private key


(19-02-2021, 10:47 PM)gerard1085 Which is everyone get. There is something i haven't checked actually, i got the official firmware upgrade tool from wiko.
But i can't use it , because my phone firmware is already the one from the tool.
I can extract the pac given with the firmwar package, i already did it.
Maybe if there is a way to trick the tool , or use one of the upgradeTool, researchTool, factoryTools ??? or whatever.
Surely there is a way to force an upgrade , and so if it works with the tool , i just have to exchange boot.img with one i modified in magisk...
Maybe..
I really don't know how to get it works, but its surely possible.

all this has been tested on a different device, it doesn't work
unless you unlock bootloader and create a custom signed vbmeta, you just won't be able to flash any custom boot or recovery.img
Users browsing this thread:
 1 Guest(s)
Users browsing this thread:
 1 Guest(s)
YtWhTl
live chat
whatsapp telegram instagram