Password for CDM1550LS
Moderator: Queue Moderator
Password for CDM1550LS
Recently purchased a CDM1550ls+ and tried to program it for LMR use and am met with a request for a password in order to read or shoot a new program. What can be done about this? I've waited > 15 minutes after attempt. Can mother Motorola fix this?
Thanks
Thanks
Natan Huffman
Is the clock running ? There are posts in model specific info about this
problem. If the internal battery is bad or the crystal is bad the clock
wont run and therefore no more 15 minutes go by. Go read that section
and you may gain some info that will help. Phrawg
problem. If the internal battery is bad or the crystal is bad the clock
wont run and therefore no more 15 minutes go by. Go read that section
and you may gain some info that will help. Phrawg
BBbzzzzz... ZAP.. GULP !!! ahhhh GOOD fly !
How to get around this is posted in another thread here... it's not had - it's stored in plain text... I think you can use winhex ram editor to read it.
-Alex
-Alex
The Radio Information Board: http://www.radioinfoboard.com
Your source for information on: Harris/Ma-Comm/EFJ/RELM/Kenwood/ICOM/Thales, equipment.
Your source for information on: Harris/Ma-Comm/EFJ/RELM/Kenwood/ICOM/Thales, equipment.
I believe that only refers to the radio keypad lock issue, not the CPS password issue.phrawg wrote:Is the clock running ? There are posts in model specific info about this
problem. If the internal battery is bad or the crystal is bad the clock
wont run and therefore no more 15 minutes go by. Go read that section
and you may gain some info that will help. Phrawg
And yes, the password is in plain text in Windows memory when the CPS reads it.
The easiest way to learn is to practice.
Download Winhex...free trial version works fine.
Password protect one of your codeplugs with an easy to find password...a curse word works great. Fire up Winhex. Now try & read your codeplug with CPS...when the password field comes up, switch over to Winhex.
Use the RAM editor function on the memory used by the CPS program. Use the search feature to find your password. It'll pop up in several different places. Get to know where it comes up, and what "other variables" might precede or come after it (a specific text string, for instance).
Try this with several different passwords. Once you're comfortable, try finding the password by searching for your "other variable".
Once you've done that a few times, you'll be able to find any password.
Works for every CPS that I know of...some are easier than others...the "other variable" is different for the various radio CPS and probably different between revisions.
No trees were harmed in the posting of this message...however an extraordinarily large number of electrons were horribly inconvenienced.
Welcome to the /\/\achine.
Welcome to the /\/\achine.
How to modify CPS for "off" check of the password
On example CPS R06.03.02 for ProfRadio Waris MDC.
HexWorkshop is required or any hex editor.
Open for editing file ProRadio.exe from folder with install CPS R06.03.02
Go to the offset 00240EEA from the beginning of a file.
There you will see value 741C. Replace on EB1C.
Save a file.
)) for CPS R06.01.00 goto to the offset 00239F2A))
After that if necessary input of the password in CPS you can enter any combination of digits and the program will always allow you to get access to the data of radio.
BR!
HexWorkshop is required or any hex editor.
Open for editing file ProRadio.exe from folder with install CPS R06.03.02
Go to the offset 00240EEA from the beginning of a file.
There you will see value 741C. Replace on EB1C.
Save a file.
)) for CPS R06.01.00 goto to the offset 00239F2A))
After that if necessary input of the password in CPS you can enter any combination of digits and the program will always allow you to get access to the data of radio.
BR!
SAVED BY [b]slavik[/b]
slavik I would like to say THANK YOU for your information.
It pointed me in just that right direction to find what I needed.
Have a good festive season.
Regards,
Keith
It pointed me in just that right direction to find what I needed.
Have a good festive season.
Regards,
Keith
- The Pager Geek
- Posts: 1250
- Joined: Fri Jun 21, 2002 10:31 pm
- What radios do you own?: Disney FRS
Re: How to modify CPS for "off" check of the passw
For those with Current Pro Series CPS 6.05.03slavik wrote:On example CPS R06.03.02 for ProfRadio Waris MDC.
HexWorkshop is required or any hex editor.
Open for editing file ProRadio.exe from folder with install CPS R06.03.02
Go to the offset 00240EEA from the beginning of a file.
There you will see value 741C. Replace on EB1C.
Save a file.
)) for CPS R06.01.00 goto to the offset 00239F2A))
After that if necessary input of the password in CPS you can enter any combination of digits and the program will always allow you to get access to the data of radio.
BR!
ProRadio.exe
Address 0024429A: Change 741C to EB1C
When the Password Screen comes up, just press enter. Go into the CPS password config menu and the password is displayed.
tpg
Experienced Provider of Useless Information
For:
================================
CPS R06.04.00
Address 002412AA: Change 741C to EB1C
================================
================================
and
<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<
CPS ELP R02.01.02-AZ
Address 001316B1: Change 741C to EB1C
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<
INDONESIA....
[BALI, SANUR Beach, KUTA Beach, TOBA Lake, BOROBUDOR Temple,
ACEH Tsunami, BROMO Mountain.........]
@MAHSU% .... AZ LA MD AA FD
================================
CPS R06.04.00
Address 002412AA: Change 741C to EB1C
================================
================================
and
<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<
CPS ELP R02.01.02-AZ
Address 001316B1: Change 741C to EB1C
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<
INDONESIA....
[BALI, SANUR Beach, KUTA Beach, TOBA Lake, BOROBUDOR Temple,
ACEH Tsunami, BROMO Mountain.........]
@MAHSU% .... AZ LA MD AA FD
Last edited by bram380 on Sun Dec 25, 2005 10:02 pm, edited 1 time in total.
The Winhex method works for all CPS...Astro/25/CP-CM/MTS/MCS/etc...it'll do until we figure out the 'everything valid' mod for all of them.
Todd
Todd
No trees were harmed in the posting of this message...however an extraordinarily large number of electrons were horribly inconvenienced.
Welcome to the /\/\achine.
Welcome to the /\/\achine.
- The Pager Geek
- Posts: 1250
- Joined: Fri Jun 21, 2002 10:31 pm
- What radios do you own?: Disney FRS
Pretty much every CPS...even the 1225 could be password protected, I believe. I don't recall the MTR2000 having it, but everything else Windows based does.The Pager Geek wrote:I'll tell you what.. list the software that has a CPS password option...
tpg
Todd
No trees were harmed in the posting of this message...however an extraordinarily large number of electrons were horribly inconvenienced.
Welcome to the /\/\achine.
Welcome to the /\/\achine.
- The Pager Geek
- Posts: 1250
- Joined: Fri Jun 21, 2002 10:31 pm
- What radios do you own?: Disney FRS
MCS Doesn't (recanted)
PR1500's Don't
Astro Spectra Doesn't
tpg
PR1500's Don't
Astro Spectra Doesn't
tpg
Last edited by The Pager Geek on Sat Dec 24, 2005 3:46 pm, edited 1 time in total.
Experienced Provider of Useless Information
- HLA
- Posts: 2334
- Joined: Mon Jul 11, 2005 8:15 pm
- What radios do you own?: HT1550's, X9000's, CDM1550's
my MCS2000 is password protected.
HLA
I never check PM's so don't bother, just email me.
I won't reply to a hotmail, gmail, aol or any other generic free address, if you want me to reply use a real address.
STOP ASKING ME FOR SOFTWARE OR FIRMWARE, I JUST FORWARD ALL OF THE REQUESTS TO THE MODERATORS
I never check PM's so don't bother, just email me.
I won't reply to a hotmail, gmail, aol or any other generic free address, if you want me to reply use a real address.
STOP ASKING ME FOR SOFTWARE OR FIRMWARE, I JUST FORWARD ALL OF THE REQUESTS TO THE MODERATORS
- The Pager Geek
- Posts: 1250
- Joined: Fri Jun 21, 2002 10:31 pm
- What radios do you own?: Disney FRS
- HLA
- Posts: 2334
- Joined: Mon Jul 11, 2005 8:15 pm
- What radios do you own?: HT1550's, X9000's, CDM1550's
i'm not shure of the version, it's at work but it's the new one that does mts and mcs.
HLA
I never check PM's so don't bother, just email me.
I won't reply to a hotmail, gmail, aol or any other generic free address, if you want me to reply use a real address.
STOP ASKING ME FOR SOFTWARE OR FIRMWARE, I JUST FORWARD ALL OF THE REQUESTS TO THE MODERATORS
I never check PM's so don't bother, just email me.
I won't reply to a hotmail, gmail, aol or any other generic free address, if you want me to reply use a real address.
STOP ASKING ME FOR SOFTWARE OR FIRMWARE, I JUST FORWARD ALL OF THE REQUESTS TO THE MODERATORS
The Pager Geek wrote:MCS Doesn't (recanted)
PR1500's Don't
Astro Spectra Doesn't
tpg
Picky, picky
The PR1500 I just assumed it did since it was the same CPS as the XTS2500/5000.
The Astro Spectra I also assumed. I wonder of the Astro25 Mobile can be? I'll have to check on that when I get back to work.
No trees were harmed in the posting of this message...however an extraordinarily large number of electrons were horribly inconvenienced.
Welcome to the /\/\achine.
Welcome to the /\/\achine.
- Johnno
- Batboard $upporter
- Posts: 86
- Joined: Fri Oct 18, 2002 7:09 pm
- What radios do you own?: XTL2.5K,XTS2.5k, P25 stuff....
CPS 06.00.00AZ
Does anyone have the hex address that requires modification to solve the password issue for CPS 06.00.00AZ?
- smile@2006
- Posts: 54
- Joined: Thu Jan 26, 2006 7:51 pm
- What radios do you own?: XTS2500 XTL2500 ATS2500
Trick to dissable password:
1). Dis-assembler *.exe file to make *.txt file.
2). Locate StringData "INCORRECT PASSWORD" in *.txt
3). Locate 74xx "INCORRECT PASSWORD".
4). Write to paper the address of 74xx.
5). Open *.exe with HexWorkshop.
6). Change command JNE (Jump If Not Equal) to JMP (Jump).
JNE = 75 , JMP = BE
7). Locate 75xx in *.exe, replace with EBxx.
------------------------------------------------------------------------------
@MAHSU%
1). Dis-assembler *.exe file to make *.txt file.
2). Locate StringData "INCORRECT PASSWORD" in *.txt
3). Locate 74xx "INCORRECT PASSWORD".
4). Write to paper the address of 74xx.
5). Open *.exe with HexWorkshop.
6). Change command JNE (Jump If Not Equal) to JMP (Jump).
JNE = 75 , JMP = BE
7). Locate 75xx in *.exe, replace with EBxx.
------------------------------------------------------------------------------
@MAHSU%
Last edited by smile@2006 on Sat Nov 11, 2006 10:02 pm, edited 3 times in total.
-
- Posts: 8
- Joined: Sat Aug 28, 2004 3:11 pm
- What radios do you own?: XTS5000, HT1550XLS, CDM1550
I used PE Explorer to dis-assemble the proradio.exe and export the strings to a text file. I found the following string but I cannot find this address in Hexworkshop?
00643CAA 741C jz L00643CC8
00643CBC 68A4F97A00 push SSZ007AF9A4_Incorrect_Password
00643CC8 8BCD mov ecx,ebp
I'm using CPS R06.05.00AA
00643CAA 741C jz L00643CC8
00643CBC 68A4F97A00 push SSZ007AF9A4_Incorrect_Password
00643CC8 8BCD mov ecx,ebp
I'm using CPS R06.05.00AA
- smile@2006
- Posts: 54
- Joined: Thu Jan 26, 2006 7:51 pm
- What radios do you own?: XTS2500 XTL2500 ATS2500
For CPS R06.05.00:
Address of dissable password is 00452ABC (Hex offset of *.exe).
Change 75xx to FDxx
------------------------------------------
@MAHSU%
Address of dissable password is 00452ABC (Hex offset of *.exe).
Change 75xx to FDxx
------------------------------------------
@MAHSU%
Last edited by smile@2006 on Sat Nov 11, 2006 10:06 pm, edited 2 times in total.
- HLA
- Posts: 2334
- Joined: Mon Jul 11, 2005 8:15 pm
- What radios do you own?: HT1550's, X9000's, CDM1550's
ok this is kinda the opposite question. how would i go about enabling the cps password on a codeplug that has that box greyed out? i can enable and use the keypad lock. anyone ever tried that?
HLA
I never check PM's so don't bother, just email me.
I won't reply to a hotmail, gmail, aol or any other generic free address, if you want me to reply use a real address.
STOP ASKING ME FOR SOFTWARE OR FIRMWARE, I JUST FORWARD ALL OF THE REQUESTS TO THE MODERATORS
I never check PM's so don't bother, just email me.
I won't reply to a hotmail, gmail, aol or any other generic free address, if you want me to reply use a real address.
STOP ASKING ME FOR SOFTWARE OR FIRMWARE, I JUST FORWARD ALL OF THE REQUESTS TO THE MODERATORS
-
- Posts: 27
- Joined: Sun Feb 26, 2006 10:24 pm
- What radios do you own?: More than you can ever imagine
RE: Locked CDM1550
Try programimng the radio with another, correct, codeplug. I have done this when I have gotten locked out of both 1225 and CDM radios.
I also bought a CDM off of eBay that was locked. I didn't have an archive of the correct radio but I got someone to send an archive for that EXACT MODEL NUMBER, programmed it in and PRESTO! It was unlocked.
I recall that SERIAL NUMBERS are a non-issue with WARIS radios. There is no CLONE feature, just read and program but again:
You must have the EXACT MODEL NUMBER!!!
I also bought a CDM off of eBay that was locked. I didn't have an archive of the correct radio but I got someone to send an archive for that EXACT MODEL NUMBER, programmed it in and PRESTO! It was unlocked.
I recall that SERIAL NUMBERS are a non-issue with WARIS radios. There is no CLONE feature, just read and program but again:
You must have the EXACT MODEL NUMBER!!!
- smile@2006
- Posts: 54
- Joined: Thu Jan 26, 2006 7:51 pm
- What radios do you own?: XTS2500 XTL2500 ATS2500
New info...
Dissable password CPS R06.06.00
Change to BDxx from 75xx
address: 0036ABCA
@MAHSU%
Dissable password CPS R06.06.00
Change to BDxx from 75xx
address: 0036ABCA
@MAHSU%
Last edited by smile@2006 on Sat Nov 11, 2006 10:08 pm, edited 2 times in total.
-
- Posts: 28
- Joined: Sat Jan 14, 2006 7:53 pm
I am confused as to what I am doing. I need to access a couple Ht1250ls+ without losing all the data but they are passworded. I have Professional Radio CPS R06.04.00 but I am lost as what I want to import into my hex editor. I have a codeplug from a cdm1250 I have been trying to play with to get experiance but it isn't making a lot of sense when I load the codeplug into the hexeditor I am not finding any of the strings like you guys are talking about. Can someone step me through this?
Fire Department Lieutenant
- HLA
- Posts: 2334
- Joined: Mon Jul 11, 2005 8:15 pm
- What radios do you own?: HT1550's, X9000's, CDM1550's
it's not the codeplug, it's in the .exe file for the program. open that one.
HLA
I never check PM's so don't bother, just email me.
I won't reply to a hotmail, gmail, aol or any other generic free address, if you want me to reply use a real address.
STOP ASKING ME FOR SOFTWARE OR FIRMWARE, I JUST FORWARD ALL OF THE REQUESTS TO THE MODERATORS
I never check PM's so don't bother, just email me.
I won't reply to a hotmail, gmail, aol or any other generic free address, if you want me to reply use a real address.
STOP ASKING ME FOR SOFTWARE OR FIRMWARE, I JUST FORWARD ALL OF THE REQUESTS TO THE MODERATORS
-
- Posts: 28
- Joined: Sat Jan 14, 2006 7:53 pm
-
- Posts: 28
- Joined: Sat Jan 14, 2006 7:53 pm
Help
Ok, I'm completely new and ignorant to using winhex. I have found the proradio.exe file but I can't figure out the offset. I'm using Professional radio CPS R06.04.00. I see the offsets, but they start with 00400000. How do I go about editing this to bypass a password problem.
I've also tried the other method of finding the password, but I can't come up with a common variable to track it.
Any help is appreciated
I've also tried the other method of finding the password, but I can't come up with a common variable to track it.
Any help is appreciated
Aaron Slaughter
Communications Coordinator
City of Lockhart
Lockhart, Texas
aslaughter@lockhart-tx.org
Communications Coordinator
City of Lockhart
Lockhart, Texas
aslaughter@lockhart-tx.org
help
I've dis-assembled the cps.exe for a cm200 - a search for "password" yields no clues. Anyone know which hex address controls the password option for a cm200?
TIA
TIA
No, but the CM200 is one of the easiest to use the Winhex method on...just type in any word for a password to get the error window to come up, then do a search for that word in the Winhex RAM editor...the real password shows up a few lines below the incorrect password.
No trees were harmed in the posting of this message...however an extraordinarily large number of electrons were horribly inconvenienced.
Welcome to the /\/\achine.
Welcome to the /\/\achine.
we put in a guess for a password, used winhex, opened the exe file, and then opened the ram file and searched the physical memory for our guess. Our guess and several subsequent guesses all show up, but there is no other evidence of any password below.
Are we looking in the correct spot (physical memory - of the ram file - alt-f9 option in winhex)?
Thanks
Are we looking in the correct spot (physical memory - of the ram file - alt-f9 option in winhex)?
Thanks
-
- No Longer Registered
- Posts: 872
- Joined: Tue Feb 22, 2005 7:03 am
I haven't delved into the 'anything valid' side of things, just strictly using Winhex to see the password. From my notes for Astro25 CPS:RESCUE161 wrote:Has anyone made the Astro 25 CPS work for "anything valid"?
I am finding the "wrong" passwords (my intentional wrong entries), but I can't seem to find the actual password.
Are the passwords on the Astro 25 CPS encrypted?
All readings taken with Winhex 11.8
XTS5000: CPS version 4.01.01
Open CPS, read codeplug, when prompted for password, go to the Winhex screen. Go to ‘tools’-> ‘open RAM’. A window will pop up listing all current applications running. Choose ‘patport’ (should be the last one in the list, since it’s the last program you opened), then ‘primary memory’.
Search (CTRL+F) for text string: microsoft\windows\ includes the slashes.
There will many instances of the text string, press F3 to continue searching. At the 4th occurrence, the password should almost immediately precede the text string.
Now, the above was figured out through testing with a "known" password, and figuring out what text was nearby it when searching, then using that text as the search parameter on a codeplug with an "unknown" password. Works great, except the text can change with each CPS version, so you have to re-figure it out again every release.
Todd
No trees were harmed in the posting of this message...however an extraordinarily large number of electrons were horribly inconvenienced.
Welcome to the /\/\achine.
Welcome to the /\/\achine.
- RESCUE161
- Batboard $upporter
- Posts: 2062
- Joined: Wed Jan 16, 2002 4:00 pm
- What radios do you own?: Too many!
Thank you! Works great!!!
[edit]
Works great, but make sure you test it out first. I tried different size passwords and ones that were fairly long, it would cut off the first part of "Microsoft", so I just used the next word over - "Windows\CurrentVersion".
Awesome work guys!
[edit]
Works great, but make sure you test it out first. I tried different size passwords and ones that were fairly long, it would cut off the first part of "Microsoft", so I just used the next word over - "Windows\CurrentVersion".
Awesome work guys!
Scott
KE4FHH
Religion: Kills folks dead!
KE4FHH
Religion: Kills folks dead!
- Flatbush97
- Posts: 87
- Joined: Tue Sep 04, 2001 4:00 pm
- smile@2006
- Posts: 54
- Joined: Thu Jan 26, 2006 7:51 pm
- What radios do you own?: XTS2500 XTL2500 ATS2500
Disable Password CDM
Hi,
Disassembler cps,
change optinon JNZ to JE to disable password.
or,
Delete Dialog Password from cps structure.
Successfully to carck:
CPS R06.07.04-AZ (GP328/GP338)
CPS ELP R02.01.02-AZ (GP308)
CPS ELM R05.05-AZ (GM3188/GM3688/GP3188/GP3688).
smile@2006
AZ-AA-LA-MD-FD
HUMAS@%&
INDONESIA
Disassembler cps,
change optinon JNZ to JE to disable password.
or,
Delete Dialog Password from cps structure.
Successfully to carck:
CPS R06.07.04-AZ (GP328/GP338)
CPS ELP R02.01.02-AZ (GP308)
CPS ELM R05.05-AZ (GM3188/GM3688/GP3188/GP3688).
smile@2006
AZ-AA-LA-MD-FD
HUMAS@%&
INDONESIA
Last edited by smile@2006 on Thu Jan 04, 2007 6:53 pm, edited 2 times in total.
I want to thank the board for this thread... I finally got around to working on my CDM1550LS+, and hit the password roadblock as soon as I tried to read the radio. After my panic subsided, I looked at Batlabs, and there was the solution, right in front of me. I downloaded Hex Workshop, and edited hex code for the first time in many years. I apparently followed instructions well, because I was able to get around the password and read the radio.
Thank you!
Thank you!
Steve
http://www.CrownVic.net
http://www.CrownVic.net
-
- Posts: 27
- Joined: Thu Aug 24, 2006 6:03 pm
- What radios do you own?: Ht1250,MTX9250,XPR6550,MCS2000
dissable password
In CPS R06.07.04
The offset is
00244CF0
just change the
741C
To
EB1C
and your all set
Karl N2RLD
The offset is
00244CF0
just change the
741C
To
EB1C
and your all set
Karl N2RLD
Re: Password for CDM1550LS
anyone whos is successful in applying the method in kenwood???? I can't do it in kenwood...
Re: Password for CDM1550LS
For R06.08.05 I found it at offset: 02380650
change 741C to EB1C
that should take care of the problem!
change 741C to EB1C
that should take care of the problem!