Nagra Hex block Decryption

Status
Not open for further replies.
hi bro free I want to watch on a device dreambox808 se or a different brand

there is a module in my hand nds 092b turksat caid dsmart
 
hi bro I want cccam or oscam to look like in this regard, please help need oscam cak7 all caid kart work version
 
don't have anyone to help me , the Grand Masters please I'm looking for knowledgeable hearted
 
Hi ! I have dump of my full 256 mb of ram.. and kcore !
I not found 00000097 decrypted block. I found 00016c decrypted .. I have sessionkey.. and emm cw .dcw. How to find cwpk in ram ?
 
Hi ! I have dump of my full 256 mb of ram.. and kcore !
I not found 00000097 decrypted block. I found 00016c decrypted .. I have sessionkey.. and emm cw .dcw. How to find cwpk in ram ?

If it's like mine, you will not find them in plaintext, you'll find them in a second block on the ram but they're also encrypted!

89 00 00 00 84 00 00 00----->ECK
 
Last edited:
Thanks for trying to help!
I have not found anything in the ram yet.
One person told me that there is 5 cmd that extracts the cpukey from bcm7358, it wants to sell for 700 $, does it even exist?

I have telnet open, can I copy / dev / mem dev / urandom / dev / random / dev / kmem

A good question for professionals:

My block 0000016c in "bga24" is encrypted by a key!

This key decrypts the block and sends it to ram and then decrypts with ird + idea + xor!

The question is?

The key that decrypts the block 0000016c in bga24 is the cpukey?

And i have the info for cpu register:

_BUFFER_SIZE] =
{
0x00000010,
0x00000088,
0xABCDEF00,
0xD455AA2B, / SESSION_SET_VICH_REG

My CFE have:

00 00 02 08
00 00 00 10
00 00 00 98
AB CD EF 00
F8 55 AA 07
78 9A 00 94
00 00 00 01
00 01 05 01

0 x F8 55 AA 07 / SESSION_SET_VICH_REG how to send this cmd in telnet ?
 
telnet 192.168.1.162

(none) login: root

I have loaded new busybox for mipsel,

this have poke cmd with error, applet not found

# ./busybox mw , applet not found !
 
telnet 192.168.1.162

(none) login: root

I have loaded new busybox for mipsel,

this have poke cmd with error, applet not found

# ./busybox mw , applet not found !
Humm, maybe dd cmd done job...
 
I have :

dd and hexdump !

# cat /proc/cpuinfo
system type : BCM7346B2 STB platform
processor : 0
cpu model : Broadcom BMIPS5000 V1.1 FPU V0.1
BogoMIPS : 868.35
cpu MHz : 1305.025
wait instruction : yes
microsecond timers : yes
tlb_entries : 64
extra interrupt vector : yes
hardware watchpoint : no
ASEs implemented :
shadow register sets : 1
core : 0
VCED exceptions : not available
VCEI exceptions : not available

processor : 1
cpu model : Broadcom BMIPS5000 V1.1 FPU V0.1
BogoMIPS : 651.26
cpu MHz : 1305.025
wait instruction : yes
microsecond timers : yes
tlb_entries : 64
extra interrupt vector : yes
hardware watchpoint : no
ASEs implemented :
shadow register sets : 1
core : 0
VCED exceptions : not available
VCEI exceptions : not available
 
F*** that my busybox is vunerable!
Kaon Box...
BusyBox v1.2.1 (2009.08.14-06:03+0000) multi-call binary
env x='() { :;}; echo vulnerable' bash -c "echo this is a test"
vulnerable
this is a test
 
How to run CFE from memory ram ?

I can read and edit my memory ram, need to know how to execute my edited CFE from ram.

is Possible ?
 
I found my eck encryted in ram:

88000000 84000000, i believe this swap in 32 bit !
 
Status
Not open for further replies.
Back
Top