Nagra Hex block Decryption

Status
Not open for further replies.
Here's a dump for studies, ird, boxkey, rsa have changed and also the set top box no longer exists.
Download thomson.zip from Sendspace.com - send big files the easy way
Can we work step by step in this dump to get the whole process for fun and learning.

This is the Block from the dump:

0000016C12345678030376DC831C6E3B
A3F329247E101C76577320CB035449F4
F53C502A464E8FF5FFFA404E3F594D29
B4AC14E1BE7D2F9DF22B224E44B13B2A
BF568593EFFAE796D9512D3E6D1CB85A
F632A1BFF083670EB5CF1C6F5AA9B930
AC48C7E8471CA1B0B9592FAB157FBE99
C728E4DDE3D5520F21D64A8911BE66CA
314E681A3DD1AE66CC41A5CCF499EB01
BBB46D5011041B4D27D133808B9C32BF
26EEC1E2CB2879B570449A463F5C038F
96D50EACCA4AE503B96ED10E524EEBB0
83A972F846BD3AACAC073216F37AA547
F532F91B90BFB9FF84F946E5489088E3
A016D581E4A7C00235FC6F46C9A268A5
BDC754960C0DF9EF219D615E09A13B33
4F331CF45F5F402B99F2EF7D6E16A086
2741276872952C8ECB4FA7B9234ED187
6B37996973D6AD51C1D60DE783CB32DF
FA45E74B2B93C89BBDED6D1012A4083F
A43DCF6E158D14A6E949EE2DF0390DBC
D8F6E8A174B474667F8AF49101E29319
38A26E92EDB085E01CFF92792CB7965F
3DD233466B9BDA6C05A7EFBD444000C9
870E1F3F0BDF5C43B3CAFD821F3691F9
F65EAA2A4C339D22F1029490334D52ED
5917F4556DF8FEF749EBDD6921C9787A
AC600815A77B63CFFBCDAC9BCE8D3C27
60FF0F393FB495968F08D689C962F03E
A6FE77A71FD1019FAD098290C62B2DCA
5C8C432286DAE5D28499970300BBFFFF
FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF

Code:
You don't have permission to view the code content. Log in or register now.

Can we studies like toddler ???

Thanks in advanced.
 
IDEA-key ********101924314051647990A9C4E2 is this correct ?? from what information i have been reading it should be ********101924314051647990A9C4E1 ??


You are right the correct KEY is:

10 19 24 31 40 51 64 79 90 A9 C4 E1

not the

10 19 24 31 40 51 64 79 90 A9 C4 E2

and the ird# is:

12 34 56 78


Thanks again.
 
hi buddy, thank you very much for the example. How can i get the idea key? I was looking for information on internet but i couldn't find it.
Thanks in advance.

Best regards
paul.

1234567?
3df5f130e17d85e?
349ee90aaa6d3c477d7c69b89381bcf9607531b731ce2dce3bdf7bed1fd5a894b453610eb54144d63724dcacdfff368c6fd32d436121740aa5908591438e155¿
 
Sorry to say that this person does not cooperate at all ..
We exchanged some information. and when you are asked to help anything ..
false promises .. (scammer)

nicovil care .. ..

hi nicovil i have some knowledge about your nagra cak7 problem and emu programmation with 1 cwpk and 2 cwpk
send me pm your skype i
we talk more details i have some question about conax hw pairing if you can help
 
In other words . . . this is the key thats we need to use to decrip the block, right ?

{ I R D # } { C o n s t a n t N u m b e r }
{12 34 56 78}{ 10 19 24 31 40 51 64 79 90 A9 C4 E1} = 16bytes IDEA-KEY

Block Size = 016Ch = 364 bytes

Where start the block with the byte to decrip?

Next to the IRD# ???

Next to 0303 ?


Thankz in advanced.
 
All nagra block is somethings like this
016c ird 0303 and after 0303 is data where you have to decrypt.
 
Now thats I have the IDEA-Key:

12 34 56 78 10 19 24 31 40 51 64 79 90 A9 C4 E1

What is the Next Step ??

What I do with this number ?

Any Public Utility to play with this number ?

I found this utily:

"IDEA Block Chiper Calculator"

is a jar file and work fine to encrypt/decrypt with the IDEA algo.

work beautiful, here a example:

Code:
You don't have permission to view the code content. Log in or register now.


Thankz in advanced.
 
Last edited:
Hi guys,
I have flash dump from M?25L3?55D , it's provid 2111 and box N?100?HD. There is not problem to find block 00000097 as the follows :
block header: 00000097
NUID: 8?7?4?D?
0001 Max Number of Provider IDs
provider id: AA70
CWPK active: 05
00 Security Architecture:
CW Key descriptor: 0181 = 0x81 hexa bytes = 129 bytes (containing the cwpk encrypted keys)
Storage table length: 10 = 10 hexadecimal bytes = 16 bytes header CWPK key sizes
CWPK0 encrypted: A9D67213A767E73973CFA3CAAD7C417F
CWPK1 encrypted: 5555067E7DBD32EEA6621DD24CBF8FD6
CWPK2 encrypted: 18D2C9CE4352368ED18E81B588860D0C
CWPK3 encrypted: 5650877A47EA77296A279CB69278DC52
CWPK4 encrypted: C591162D5C409F94A9133B2F1C500F90
CWPK5 encrypted: 2F26DF988FDACD1E68A7B589F4149B41
CWPK6 encrypted: 602E02174C3487D6DCDBF2967423344F
CWPK7 encrypted: C5D91F4A2B3C218110D697552EB3B5DA
0B381EAAFFFD
but I can not to identify the block 0000016C , I've find some similar blocks 0000016A and 0000017C and tried to decrypt them ((IDEA(IRD+1019.....E1 as key > 00 - 02C)) XOR orig.data) , but without success to find block size xx08 , xx40 for the RSA identifiing and data needed for Boxkey XOR. This dump is from non active receiver and I can to send it to anyone for the investigation , for that , please contact me by PM. I've tried also some blocks with 009882 with bit swapping to find 016C and also without success. Could anyone to help me with this ?
Hi buddy, could you decrypt the block 000097?
Best Regards
 
Conax use mod1,mod2,mod3,boxkey 16 bytes,data50 and mod50,
if you know about cak7 then you must have the base of his!lol

Nice to know CA vendors are cloning each others now :hubbahubba: keep up the good work.
 
Nice to know CA vendors are cloning each others now :hubbahubba: keep up the good work.
It is a version of conax used only in my house!:Cheers:
I saw you are out!It is good to know...
Now you can show me the right way to cmd03!loly
 
can anybody help me?
as I can get Boxkey, Rsa, Cwpk and other data?
I read everything but still not successful
 
Hello

can someone help me for get working CAK7 NARGA 1811 CSAT

IRD: 68D08D6E

i have
BOXKEY
RSA KEY
cwpk 3des

8 CWPK KEY

i can't find any Oscam can work with this


Thanks
 
Hello

can someone help me for get working CAK7 NARGA 1811 CSAT

IRD: 68D08D6E

i have
BOXKEY
RSA KEY
cwpk 3des

8 CWPK KEY

i can't find any Oscam can work with this


Thanks
I think your card use generic pairing,the good news is that the mod1 is easy to take.. for the rest good luck to find the solution!:Mad2:
 
I think your card use generic pairing,the good news is that the mod1 is easy to take.. for the rest good luck to find the solution!:Mad2:


sbox 5.3 solution cak7 global pairing .

but for two need oscam merlin .. any has version ?
 
Status
Not open for further replies.
Back
Top