Reader schematic.
From the site where I first get the information about hacking this BIOS password, it is suggested that we solder two wire to EEPROM pins to connect the reader. I thought it will be disasterous and would void the warranty.
.jpg)
Photo #1: EEPROM Reader,
all component soldered to d-sub female connector
So, I soldered a needdle to the wire from the reader, one for SDA and one for SCL. For the GND wire, I suggest you attach a aligator clip to clip the GND wire to any GND point on the mainboard. For my case, I clip the GND to the jacket of USB port near the EEPROM.
With this method, you need to have a very steady finger to hold the needdle in place. I used both hand to hold the needdle. One needdle in one hand. You have no more hand to operate the PC. Get your buddy's help. I ask my wife to press ENTER.
The Location of AMTEL 24RF08CN on R40
EEPROM Chip AMTEL 24RF08 is located beneath the plastic protective sheet under the harddrive compartment.
Photo #2: Harddrive compartment
Remove the aluminum cover. You have to remove two screws. One in the small hole at the bottom of the picture and the other one is on the bottom right side of the cover.
Photo #3: Plastic Protective Sheet
You have to peel the plastic sheet to uncover the EEPROM. Be very careful not to tear off the sheet. We need to replace is later on the board. The sheet is fastened with double sided tape on the audio jack. Peel it from there.
Photo #4: ATMEL location and pin connections
I've mark the SDA and SCL pin in Photo #4. Look where I slip in my GND wire. "Saya klip GND kat kulit port USB ini" meaning "I have clip my GND wire at this USB port sleeve."
Figure #2: ATMEL 24RF08 Pinouts
(In direction match the Photo #4) .jpg)
Photo 5: Protective Sheet peeled.
The protective sheet has been peeled and attact to PCMCIA slot to give us a clear view to the EEPROM.
Reading Procedures
To complete this procedure, you need to have another pc (secondary pc) with spared COM Port.
Step 1:
Attact EEPROM Reader to COM Port (other pc or laptop with COM Port), then open up Command Prompt. (Under Windows XP, Click on Start-->Run then type in CMD then press ENTER. Go to the folder where r24rf08 is installed.
C:\>cd C:\ALLservice\24RF08 then ENTER
type at the command prompt
C:\ALLservice\24RF08>r24rf08.exe r40dump.bin
Don't hit ENTER yet. (C:\ALLservice\24RF08 is where your r24rf08.exe located)
Step 2:
Turn on your ThinkPad (Please be really careful). Wait until your ThinkPad is prompt you to enter password (when big padlock icon appear).
Step 3:
With precaution (be really careful, bro), attach GND wire to any GND on the board then attach or touch the two needdles which connect to SDA and SCL on the ATMEL 24RF08CN EEPROM.
Step 4:
Now, press ENTER (my wife did -- both my hand holding the needdle), white for a moment until reading finish (appox. 10 to 20 seconds). In the same folder as r24rf08.exe, a new file named r40dump.bin has been created. Now you can power off the ThinkPad and reassemble the unit.
Langkah 5:
Run IBMpass 2.1 Lite that you have installed. Click Start --> ALLservice --> IBMpass 2.1 Lite. Open the file r40dump.bin from the C:\ALLservice\24RF08. Scroll down to address 0x330, you could read the password right there. If you can not read the password, make sure you click on the icon "AA off" to "AA on". That's all.

Photo #6: IBMpass 2.1 Lite Screen Shoot
Type in the password at ThinkPad, in my case, the password is KHALIF. I have succesfully boot this ThinkPad.
ps: Sorry for the bad quality of the images. Those images taken using Nokia 6600 camera phone. To seek more help from me, please send short text message to +6o-12-96o82o8 and email me at spokdogol AT gmail DOT com
References:
http://sodoityourself.com/hacking-ibm-thinkpad-bios-password
http://www.allservice.ro/
Feature Readings:
1. ATMEL 24RF08 datasheet
NOTICE: I did not take responsibility for any loses due to the usage of the information from this blog post. Please take extreme precaution while following this procedure. Thank You.