Nagra Hex block Decryption

Status
Not open for further replies.
I have unlocked CFE for BCM 7356.
This unlocked CFE not have 017c block.
I can decryptpk and cryptpk .. block 016c.

Without block 017c.. to mod block 0000016c in BCM 7356 make use o nuid !

Nothing with block 017c.
 
BLOC = 00 00 01 6C
IRD = 68D08D6E
Padding = 0303
 
alexndrem
stealing is not the same as helping i think

sorry for the offtopic chookey but this member registers once again with fake nick to obtain free infos , First of all it's linked to payserver , and 2 the guy stole from viper x PC files without autorization, so this kind of people should not be here in the forum sorry.

So on topic now
i share a dump who i can't find the 16c.
it's maybe very well hidden.
Share so people can study.

I think the block is encrytep..
 
I agree !
All nick maked in long time and only one post is fake!
It´s is only one guy inside of ****
 
That this file looks like to analyze. I dont found block 16*c, . Its posible that this is encrypted o fake dump or "game over" with extraction, or this posible with someone method..... thanks..
File
 
Do you know which STB is the easiest way to extract a dump frimware without needing to solder the chip? Of course I think about RSA nad BK extraction. Can you point to any of these?
- Samsung DSB-H370G HD, Samsung DSB-S305G
- Echostar DSB-7100 HD, Echostar DSB-7200 HD, Echostar HDS-400E HD
- Echostar DVR-747, Echostar DSB-717, Echostar DSB-717A, Echostar DSB-616, Echostar DSB-606

Or maybe you just point to the STB from which it is the easiest way to do the dump flash. ... Thanks
 
Samsung DSB-H370G is easy to extract flash and read , the others don't know .
Direct methods for dump without soldering are welcome.
Some STB like pace have models you can upgrade firmware over usb and dump it once upgrade process is done.
 
Hi.

Can anyone help me? i have a dump file from southamerica. Provider Claro is possible to extract rsa key from this dump?

the dump i will send you by skype or email.

Please contact me
 
i have the dump file of this model AF-8013H... and i have other model but this not have dump to read the model is AF-5012S.
Anyone can help me?? Both boxes are Claro Provider 61w South America.
 
i have the dump file of this model AF-8013H... and i have other model but this not have dump to read the model is AF-5012S.
Anyone can help me?? Both boxes are Claro Provider 61w South America.
AF-5012S ??? HE?? this model NOT HD ?? or is 8012?
you do not have af-5210vhd model first HD model with cpu sti7111....
 
i have pace 7151, looking way to read cpu key, i have telenet access
offtopic i find access to kaon 1300 but need user & pass , cpu bcm97358 i try whit bcm studio no connection tru i2c
 
i have pace 7151, looking way to read cpu key, i have telenet access
offtopic i find access to kaon 1300 but need user & pass , cpu bcm97358 i try whit bcm studio no connection tru i2c
Kaon
user-root
pass-******
In pace with old firmware piece is possibly open uart port...
 
Hello

Can me only help? I have 2 dumps from upc modul Caid 1862. I need cak7 keys and oscam to run! Have you never for me pls?
 
Last edited:
I have the NOCS and libnexus.so to open and close i2c debug interface and other keyladder emulation, aka ram2ram engine, keyladder , otp bits read , dvrkey, nuid check number, in BCM cpu. NUID + CRC + XXXXX generate nuid check number.. CASN +CRC+XXXXXX generate casn check number. and otherrrrrrrrrrsssssssssssss
 
I have the NOCS and libnexus.so to open and close i2c debug interface and other keyladder emulation, aka ram2ram engine, keyladder , otp bits read , dvrkey, nuid check number, in BCM cpu. NUID + CRC + XXXXX generate nuid check number.. CASN +CRC+XXXXXX generate casn check number. and otherrrrrrrrrrsssssssssssss

So you can read the BCM cpu???
 
Status
Not open for further replies.
Back
Top