| Re: keyroll ecm and the fix (code it ur self) Quote:
Originally Posted by cydine_ This is exactly the part I was stuck on back in april.
Let's work with the rom 10 code. I am working with rom images for dbox etc but this is relevant to the opos etc as well.
1. There's not really space to insert a patch anywhere so just overwrite some stuff that is not relevant to an emulated card - I use a section referencing the backdoor key. This stuff is not required for softcams.
2. Open the rom10 disassembled listing in your text editor and look for the call to jump to the emm buffer - hint look for a BD 81 jsr EMMBUFF01.
Patch the call before this - CD XX XX to jump to your patch. |
Is step 2 done using hex editor,is there a way to search for BD 81? i've opened the rom10 disassem but i'm struggling at this point.
Its like trying to get on a carousel at the right point,lol.Probably a distinct possibility i'm pissing in the wind also.
__________________ It matters not how strait the gate. How charged with punishments the scroll,I am the master of my fate,I am the captain of my soul. |