nagra 2 keys

Hi guys I managed to get hold of one of the new upc cards can they be opened
to get what we need of it
 
I wouldnt have a clue how to do this would anyone in Dublin have what we need to try open it
 
Just stick it in a standard phoenix type programmer and use a program like NagraEdit to get the ATR (Dont try anything else).

The ATR will tell you card revision.

If the card has been online in a box anytime in the last 6 months or so then it will almost certainly of updated itself to A07 so not much you can presently do with it.
 
I wouldnt have a clue how to do this would anyone in Dublin have what we need to try open it

pop it in ur pheonix proggy as nozzer said open nagraedit 4.1 and click on reset and this is wat u will see


Opening of COM1 was successful
ATR String: 3F FF 95 00 FF 91 81 71 FE 47 00 44 4E 41 xx xx
xx xx xx xx xx xx xx xx xx xx xx
ROM Revision: 110
EEPROM Revision: RevA07
Closing of COM1 was successful



as u can see mine is RevA07 so of no use yet
if someone has an A05 it can be used so wat u need is a upc silver box
that hasnt been plugged in for 6 months, its a tall order but i bet
someone out there has one
 
pop it in ur pheonix proggy as nozzer said open nagraedit 4.1 and click on reset and this is wat u will see


Opening of COM1 was successful
ATR String: 3F FF 95 00 FF 91 81 71 FE 47 00 44 4E 41 xx xx
xx xx xx xx xx xx xx xx xx xx xx
ROM Revision: 110
EEPROM Revision: RevA07
Closing of COM1 was successful



as u can see mine is RevA07 so of no use yet
if someone has an A05 it can be used so wat u need is a upc silver box
that hasnt been plugged in for 6 months, its a tall order but i bet
someone out there has one

box order filled...
have silver box that hasnt been plugged in for 2 years ...
..if its of use ???
 
Last edited:
box order filled...
have silver box that hasnt been plugged in for 2 years ...
..if its of use ???

Hi m8, not sure if the nag2 cards were out in dublin 2 years ago
can u check the rev as per directions in my last post
if it is an A05 were in business
 
Hi m8, not sure if the nag2 cards were out in dublin 2 years ago
can u check the rev as per directions in my last post
if it is an A05 were in business

Hi guys I am looking for someone in Dublin to do this as I dont have any of the equipment to do this were would I get a card reader
 
Hi

Moved into my house 8 months ago, Was given a upc media box from upc. The big silver one. With the upc card.

Never even plugged it in. Put it straight up to attic.

So based on information here, it has to be a rev 5 card.

2 Questions though. It was only for the digital basic pakage, and not the full service. So is it any good.

Can I be tracked down, If I decide to mess around with it, and help our situation out.

P.S was talking to a friend from Upc and there has been no firm decision to go nag 3. They are testing the waters with both ecryptions (nag2 and nag3), and maynot go with nag3 because of costs.
 
I wouldnt have a clue how to do this would anyone in Dublin have what we need to try open it

I'd be a bit more paranoid than usual with giving out your details at the moment. You can buy a phoenix usb programmer for approx 30-40 euro off ebay.
 
I'd be a bit more paranoid than usual with giving out your details at the moment. You can buy a phoenix usb programmer for approx 30-40 euro off ebay.


Yeh ur right mate ill have a luk on ebay
 
Hi

Moved into my house 8 months ago, Was given a upc media box from upc. The big silver one. With the upc card.

Never even plugged it in. Put it straight up to attic.

So based on information here, it has to be a rev 5 card.

2 Questions though. It was only for the digital basic pakage, and not the full service. So is it any good.

Can I be tracked down, If I decide to mess around with it, and help our situation out.

P.S was talking to a friend from Upc and there has been no firm decision to go nag 3. They are testing the waters with both ecryptions (nag2 and nag3), and maynot go with nag3 because of costs.



Hi

As I said before my card is almost certainly Rev A05.

Will this do the job eBay.ie: Phoenix Smartmouse Programmer (item 110377611257 end time 22-Apr-09 21:10:05 BST).

Also can anyone answer my two questions before I go ahead. I read somewhere, that they can tell if you have read the card, it becomes marked or something, and its only for the basic digital package.

Cheers Lads
 
Last edited:
I believe you would need to Unloop it 1st with an unlooper and a RevA05 script, which isnt public i think.
 
hi guys i have a phoniex programmer and glitcher also have ao7 card and a non active ao5 card the next i need to know is is there a scropt to unlock this card if so i can do it for you
 
hi guys i have a phoniex programmer and glitcher also have ao7 card and a non active ao5 card the next i need to know is is there a scropt to unlock this card if so i can do it for you

Leave it with me mate. I saw it only last night somewhere on the net. Just got to remember where.


Is this a Upc A05 card you have.
 
hi guys i have a phoniex programmer and glitcher also have ao7 card and a non active ao5 card the next i need to know is is there a scropt to unlock this card if so i can do it for you

Doesn't really matter whether its active or not. Chances are it will still contain the keys you are after. Its only the channel tiers that will have expired (or been removed).
 
As I said before my card is almost certainly Rev A05.

Will this do the job eBay.ie: Phoenix Smartmouse Programmer (item 110377611257 end time 22-Apr-09 21:10:05 BST).

Also can anyone answer my two questions before I go ahead. I read somewhere, that they can tell if you have read the card, it becomes marked or something, and its only for the basic digital package.

The Phoenix/Smartmouse will only allow you to read the ATR to confirm the card version. Its of no use for anything else.

N2 cards are rather different than N1 cards. You cant unlock them - you can only dump them via glitching. If you want to dump them again then you have to glitch them again. You mostly cannot write to them (no Mosc's)

As no backdoor methods are used glitching N2 cards with a half decent script will not mark them in any way. The only possiblity is that you will completely loop the card and make it inoperable (happens quite a lot with N2 cards)

Package doesn't matter. The same basic keyset is used for all packages. Its simply the channel tiers that decide whether or not to allow a certain channel.
 
Last edited:
N2 cards are rather different than N1 cards. You cant unlock them - you can only dump them via glitching. If you want to dump them again then you have to glitch them again. You mostly cannot write to them (no Mosc's)

As no backdoor methods are used glitching N2 cards with a half decent script will not mark them in any way. The only possiblity is that you will completely loop the card and make it inoperable (happens quite a lot with N2 cards)

@nozzer u said "mostly" cannot write to them, so in theory if i had n2 card and i wanted it to work in an ex subbed box how do u create tiers and mod card like we do for n1 cards
 
@nozzer u said "mostly" cannot write to them, so in theory if i had n2 card and i wanted it to work in an ex subbed box how do u create tiers and mod card like we do for n1 cards

The cards are far more highly paired than N1 cards with each card and box having a set of matching RSA keys. The box can encrypt messages that only one single card can decrypt and vice-versa. Without the RSA keys from the original card you are stuffed !

The cards RSA key does not exist on the box so you cant get it in a similar way to a boxkey. The correct encrypt/decrypt keys only exists in two places. UPC's database and on the card.

Also, because of the a large proportion of the cards EEprom image is digitally signed, you have little chance of moving an image from one card to another. There is no such concept as a standard image. Every single image is unique.

So, that means the only card you could even think about modifying is the original card that is paired to the box.

Now, remember that you cant actually unlock one of these cards so it MUST be glitched for every operation (read or write). That means chances are you will destroy the card before you've finished.

About the only thing you could think about changing is the channel tiers. You could potentially change dates etc and potentially add extra tiers BUT if you no longer subscribe then the card will be constantly receiving "switchoff" emm's which will deleting channel tiers.........

Blockers etc, well, you cant really do this on card because of the method of firmware signing thats used. Change the firmware and the card is looped. You could possibly do it via an addon box between the card and stb that intercepts and checks every packet but that would require a very fast processor to do the necessary calculations.

So, from the above I think you'll see that Mosc'ing N2 cards is probably going to be beyond most people..........

An alternative, that may work to a limited point (depending on the providers not changing thing too often) would be an OPOS type N2 emulator programmed with the data from the original paired N2 card.

oh, forgot to mention. You could only do this with an A05 card. The A07's are locked and will likely remain so for the forseeable future. So, any box you play with would have had to of been in storage for at least the last 8+ months. If its been online since then the card is A07 !
 
Last edited:
Leave it with me mate. I saw it only last night somewhere on the net. Just got to remember where.


Is this a Upc A05 card you have.

yes the both of the cards are upc in the south east of ireland
if you can find the script it would be worth ago but nozzer seems to know what he is talkin about prob no good to us but a worth a try cant see it been this easy tho
 
Back
Top