N3 extract

jspk

Inactive User
Joined
Jun 15, 2019
Messages
6
Reaction score
0
Hi guys, I really need your help.

I extracted successfully 0000016C (BK, RSA)
The IRD is OK and complies.
However with BK and RSA entered in OScam I get the error in oscam:

  • 2019/06/15 22:08:22 24884C5C h (webif) WebIf: Origin checked. Result: access from 192.168.1.222 => allowed
  • 2019/06/15 22:08:22 290AA88E r (reader) Ziggo [internal] ATR: 3F FF 95 00 FF 91 81 71 FE 47 00 44 4E 41 53 50 31 31 30 20 52 65 76 41 30 37 12
  • 2019/06/15 22:08:22 290AA88E r (reader) Ziggo [internal] Init card protocol T1, FI=9, F=512, D=16, N=255
  • 2019/06/15 22:08:22 290AA88E r (reader) Ziggo [internal] Calculated work ETU is 7.11 us reader mhz = 450
  • 2019/06/15 22:08:22 24884C5C h (webif) WebIf: Origin checked. Result: access from 192.168.1.222 => allowed
  • 2019/06/15 22:08:25 290AA88E r (reader) Ziggo [internal] Buffers readed 0 bytes total time_us 3099437
  • 2019/06/15 22:08:26 290AA88E r (reader) Ziggo [internal] PLL Reader: ATR Fsmax is 5 MHz, clocking card to 4.50 Mhz (nearest possible mhz specified reader->mhz)
  • 2019/06/15 22:08:26 290AA88E r (reader) Ziggo [internal] Card responded ok for ifsd request of 251
  • 2019/06/15 22:08:27 290AA88E r (reader) Ziggo [internal] detect native nagra card
  • 2019/06/15 22:08:27 290AA88E r (reader) Ziggo [internal] Negotiate sessionkey was not successful! Please check rsa key and boxkey
  • 2019/06/15 22:08:27 290AA88E r (reader) Ziggo [internal] card system not supported
  • 2019/06/15 22:08:27 290AA88E r (reader) Ziggo [internal] Normal mode failed, reverting to Deprecated Mode
The boxkey and rsa key are correct.
(Its driving me nuts)

Can somebody shine a light on this weird phenomenon ?
 
DNASP110 RevA07?!
Maybe this only start in cak7...
who know!
 
Crap, yes it is a DNASP110 RevA07
I presume this is a bad thing.

I there a workaround (Oh man I really hope so) ?
 
It appears so ..

Block Header: 0000016C
MAGIC Data:
IRD = 0x 6636XXXX
IRD = 17148XXXX
key(2008) = 58751C0D3CA58C8B
key(3008) = 979E945EC1FE8D00
key(3140) == (RSA) = D4ADDEACC5EE93F0DD690402877DFFFBE8EE4C236D78AF39C721BCDFD04290EB3B1FA527F8D1DD21E2AEC5A63391F5BD32241FBE1136B7B9C3C8875935D13257
key(3310) = CE6C6A044954D8FB34424158CE2CB41A
key(3460) = 8C4685B67E82A000DFD26C10DA4E400DE8A33579ED103B9861D73D3655CD7223C519B15440EA081FB101EA094A9188DA847D71C17DE9CBC9719258F4A3466C4C8E1CB4F6073DF41FFC1E72C1BC0B3F69937CC563943740CF4648EF6D467E29AD
key(3588) = 189FA03EA255209588F9BD03165F4DF9E7443D48D800B02518FD2B575B76C4E3A250AC6E6335E6C63AAAAE775F5692933FC51C0B87EA15F6BC833FC8A03EC8D1026F668D1F71500AC897CE05D1A63BC774B7579BF38D874CF70A5CF4FF4E69B0DD82FBC7E47AB15AE87702C9292BCF5F101B7DDC04F377EACD88DCB024C2B0CC30D272CE3BBDEEE0
key(D008) = 238E89B365XXXXXX
key(E002) = 0001
key(D008) XOR key(3008) == (BoxKey) = B410XXXXXXXXXXXX

So what you are saying is, that if the initial card that came with the box was not a DNASP110 RevA07 , but was replaced, this behaviour would be logical ?
 
OK, card was not married with settop box intended, problem solved.
 
It appears so ..

Block Header: 0000016C
MAGIC Data:
IRD = 0x 6636XXXX
IRD = 17148XXXX
key(2008) = 58751C0D3CA58C8B
key(3008) = 979E945EC1FE8D00
key(3140) == (RSA) = D4ADDEACC5EE93F0DD690402877DFFFBE8EE4C236D78AF39C721BCDFD04290EB3B1FA527F8D1DD21E2AEC5A63391F5BD32241FBE1136B7B9C3C8875935D13257
key(3310) = CE6C6A044954D8FB34424158CE2CB41A
key(3460) = 8C4685B67E82A000DFD26C10DA4E400DE8A33579ED103B9861D73D3655CD7223C519B15440EA081FB101EA094A9188DA847D71C17DE9CBC9719258F4A3466C4C8E1CB4F6073DF41FFC1E72C1BC0B3F69937CC563943740CF4648EF6D467E29AD
key(3588) = 189FA03EA255209588F9BD03165F4DF9E7443D48D800B02518FD2B575B76C4E3A250AC6E6335E6C63AAAAE775F5692933FC51C0B87EA15F6BC833FC8A03EC8D1026F668D1F71500AC897CE05D1A63BC774B7579BF38D874CF70A5CF4FF4E69B0DD82FBC7E47AB15AE87702C9292BCF5F101B7DDC04F377EACD88DCB024C2B0CC30D272CE3BBDEEE0
key(D008) = 238E89B365XXXXXX
key(E002) = 0001
key(D008) XOR key(3008) == (BoxKey) = B410XXXXXXXXXXXX

So what you are saying is, that if the initial card that came with the box was not a DNASP110 RevA07 , but was replaced, this behaviour would be logical ?
not put your BK.RSA on here, card will block easy by your supplier
 
My box is dreambox 800HDse run cak7 card irdeto caid 0664!!!!!!!!!!!!!!!!!!
 
Because CAK7 is a Product by Nagravision S.A.
and Irdeto is another Company and a completely different CA.
 
I believe that the German hacker Colibri Noah to a possible version of which extracted cak7. Search for this version CSA-Rainbow-Table-Tool_V1.23 ;)
 
Back
Top