anyone want to do some testing??

yes m8 it unlocked at 5 past 5

sorry to have been so long been busy but
nice one m8
 
so does anyone actually have vista installed on there pc's lol, i realise its not great but would be nice to see if we can get someone having a go on a vista operating system.


tbc
 
just checked mine
the image u posted was this

C000: 17 0A 01 12 58 48 0E 00 2F 00 00 00 00 00 00 FF | ....XH../......ÿ
C010: FF FF FF FF FF FF FF FF FF FF FF FF 0B 01 F4 00 | ÿÿÿÿÿÿÿÿÿÿÿÿ..ô.
C020: 00 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
C030: 00 00 00 00 00 00 00 00 54 AB 00 00 00 00 00 00 | ........T«......

after the unlock this was it

C000: 37 97 20 1A 60 1E B0 00 29 00 00 00 00 00 00 FF | 7— .`.°.)......ÿ
C010: FF FF FF FF FF FF FF FF FF FF FF FF 0B 01 F4 00 | ÿÿÿÿÿÿÿÿÿÿÿÿ..ô.
C020: 02 00 00 00 00 20 00 00 00 00 00 00 00 00 00 00 | ..... ..........
C030: 00 00 00 00 00 00 00 00 5C A3 00 00 00 00 00 00 | .........£......
 
the otp is not written by nagraedit, so to check your otp you would have to read the donor card before you write to it. obviously as edcase say's earlier the marking is done by nagraedit when writting the locked image to the card, i can think of no method by which the unlocking is marking it.


tbc
 
Yes, nagra is marking them as you relock the card, this is because it attempts to write the backdoor key block C040-C07F after the C080-C0BF block which contains the bugtable size.

edcase
are there any other programs which write to the card using a different method? or would it need to be run through a script similar to this exe or the rom11 unlocker that would set the numbugs to original? Hope this makes sense
 
the otp is not written by nagraedit, so to check your otp you would have to read the donor card before you write to it. obviously as edcase say's earlier the marking is done by nagraedit when writting the locked image to the card, i can think of no method by which the unlocking is marking it.


tbc
ok as a test just read a rom11 unlocked

got this

C000: 77 33 41 20 60 FD AE 00 25 00 00 00 00 00 00 FF | w3A `ý®.%......ÿ
C010: FF FF FF FF FF FF FF FF FF FF FF FF 0B 01 F4 00 | ÿÿÿÿÿÿÿÿÿÿÿÿ..ô.
C020: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
C030: 00 00 00 00 00 00 00 00 5C A3 00 00 00 00 00 00 | .........£......

wrote rom11 locked image this is it

C000: 17 0A 01 12 58 48 0E 00 2F 00 00 00 00 00 00 FF | ....XH../......ÿ
C010: FF FF FF FF FF FF FF FF FF FF FF FF 0B 01 F4 00 | ÿÿÿÿÿÿÿÿÿÿÿÿ..ô.
C020: 00 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
C030: 00 00 00 00 00 00 00 00 54 AB 00 00 00 00 00 00 | ........T«......

unlocked this is now

C000: 77 33 41 20 60 FD AE 00 25 00 00 00 00 00 00 FF | w3A `ý®.%......ÿ
C010: FF FF FF FF FF FF FF FF FF FF FF FF 0B 01 F4 00 | ÿÿÿÿÿÿÿÿÿÿÿÿ..ô.
C020: 02 00 00 00 00 20 00 00 00 00 00 00 00 00 00 00 | ..... ..........
C030: 00 00 00 00 00 00 00 00 5C A3 00 00 00 00 00 00 | .........£.....

it has changed ???
 
so does anyone actually have vista installed on there pc's lol, i realise its not great but would be nice to see if we can get someone having a go on a vista operating system.


tbc
I have vista x64 ultimate installed on my htpc but that is lying in bits under the bed and if I start pulling that out now the gf will crack up lol If it can wait a few days, i'll give it a go on that but not very hopeful of the usb-->serial I don't have a vista x64 driver for that. It does have 2 real comports though :)
 
ok as a test just read a rom11 unlocked

got this

C000: 77 33 41 20 60 FD AE 00 25 00 00 00 00 00 00 FF | w3A `ý®.%......ÿ
C010: FF FF FF FF FF FF FF FF FF FF FF FF 0B 01 F4 00 | ÿÿÿÿÿÿÿÿÿÿÿÿ..ô.
C020: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
C030: 00 00 00 00 00 00 00 00 5C A3 00 00 00 00 00 00 | .........£......

wrote rom11 locked image this is it

C000: 17 0A 01 12 58 48 0E 00 2F 00 00 00 00 00 00 FF | ....XH../......ÿ
C010: FF FF FF FF FF FF FF FF FF FF FF FF 0B 01 F4 00 | ÿÿÿÿÿÿÿÿÿÿÿÿ..ô.
C020: 00 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
C030: 00 00 00 00 00 00 00 00 54 AB 00 00 00 00 00 00 | ........T«......

unlocked this is now

C000: 77 33 41 20 60 FD AE 00 25 00 00 00 00 00 00 FF | w3A `ý®.%......ÿ
C010: FF FF FF FF FF FF FF FF FF FF FF FF 0B 01 F4 00 | ÿÿÿÿÿÿÿÿÿÿÿÿ..ô.
C020: 02 00 00 00 00 20 00 00 00 00 00 00 00 00 00 00 | ..... ..........
C030: 00 00 00 00 00 00 00 00 5C A3 00 00 00 00 00 00 | .........£.....

it has changed ???

hi davidh

it has not changed nagra does not write to the otp area so when you read it the first time it will be the same as the second time you read it . ONLY IN THE OTP AREA .
 
hi davidh

it has not changed nagra does not write to the otp area so when you read it the first time it will be the same as the second time you read it . ONLY IN THE OTP AREA .
is there a difference in card 1 and card 3?????????????
THIS
C000: 77 33 41 20 60 FD AE 00 25 00 00 00 00 00 00 FF | w3A `ý®.%......ÿ
C010: FF FF FF FF FF FF FF FF FF FF FF FF 0B 01 F4 00 | ÿÿÿÿÿÿÿÿÿÿÿÿ..ô.
C020: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
C030: 00 00 00 00 00 00 00 00 5C A3 00 00 00 00 00 00 | .........£......
AND THIS

C000: 77 33 41 20 60 FD AE 00 25 00 00 00 00 00 00 FF | w3A `ý®.%......ÿ
C010: FF FF FF FF FF FF FF FF FF FF FF FF 0B 01 F4 00 | ÿÿÿÿÿÿÿÿÿÿÿÿ..ô.
C020: 02 00 00 00 00 20 00 00 00 00 00 00 00 00 00 00 | ..... ..........
C030: 00 00 00 00 00 00 00 00 5C A3 00 00 00 00 00 00 | .........£.....
 
is there a difference in card 1 and card 3?????????????
THIS
C000: 77 33 41 20 60 FD AE 00 25 00 00 00 00 00 00 FF | w3A `ý®.%......ÿ
C010: FF FF FF FF FF FF FF FF FF FF FF FF 0B 01 F4 00 | ÿÿÿÿÿÿÿÿÿÿÿÿ..ô.
C020: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
C030: 00 00 00 00 00 00 00 00 5C A3 00 00 00 00 00 00 | .........£......
AND THIS

C000: 77 33 41 20 60 FD AE 00 25 00 00 00 00 00 00 FF | w3A `ý®.%......ÿ
C010: FF FF FF FF FF FF FF FF FF FF FF FF 0B 01 F4 00 | ÿÿÿÿÿÿÿÿÿÿÿÿ..ô.
C020: 02 00 00 00 00 20 00 00 00 00 00 00 00 00 00 00 | ..... ..........
C030: 00 00 00 00 00 00 00 00 5C A3 00 00 00 00 00 00 | .........£.....
Hi mate I think it's just related to the earlier post by edcase. Nagraedit isn't writing in the opt area, it's the security in the card being triggered by the re-writing of the backdoor keys and marking the card - when the image has had it's bugcatchers restored
 
Hi mate I think it's just related to the earlier post by edcase. Nagraedit isn't writing in the opt area, it's the security in the card being triggered by the re-writing of the backdoor keys and marking the card - when the image has had it's bugcatchers restored
yes m8 i read that was just pointing out it had changed
lol
 
added automatic scan for comport that the loader is attached to, removed config file < was always a pants thing lol. fixed card not logged in bug and some other problems.

tbc
 
Last edited:
ok made a change try this with your programmer on a port as well.

tbc
 
Last edited:
damn it!

sorry tbc, I just noticed i didn't have an LED on the unlocker, damn gf had switched of the socket which my psu was plugged into!! ffs lol
It's working fine mate!
 
i am a dumbass lol, it should still not have seen the loader and reported the loader error - i found the problem now try this one


tbc
 
a hopefully final solution to fake vcp comport detection lol.

tbc
 
Back
Top