bought my t911 this morning, flashed it and it seems to be working fine. I installed winexplorer and loaded up a b0c script (I have 3 b0c cards here locked). Tried to unlock the first card and after about 10 minutes it comes up with hit our glitch a couple of times, telling me card is unlocked and to try logging into it with nagra. When I load up nagra I just get 'Error reading backdoor 0', restoring decrypt keys. I have tried several different scripts, but after the first time they just seem to zoom through and hit the glitches straightaway, so it seem pointless to keep trying to open the card. The card wont read in romstudio or xncs with my pheonix(no atr sent or something along those lines). So it seems im stuck there doesnt seem to be anything else to try. Any of you guys know what the problem could be? HEres what I get in the respective programs :
Winexplorer
---------------
Executing Script: C:\Documents and Settings\Chris\Desktop\XNCS1[1][1][1].8\Scripts\rom11 boc script multiproviders+4801.xvb
TX Data : A0
TX Data : A1
TX Data : 07 0E 03 10 01 03 9A 00
RX Data : 07 1B
RX Data : 3F FF 95 00 FF 91 81 71 A0 47 00 44 4E 41 53 50
30 31 31 20 52 65 76 42 30
TX Data : 14 03 10 15 AB 21 00 08 A0 CA 00 00 02 12 00 06
55 0E 03 87 00
RX Data : 14 08
RX Data : 12 00 08 92 04 24 74 B4
TX Data : 17 15 B0 21 00 0D A0 CA 00 00 07 21 05 01 03 FF
FF 00 28 4F 0E 03 88 00
RX Data : 17 09
RX Data : 12 60 20 A1 26 54 01 00 01
Now we will try 16FF delay
TX Data : B0 30
TX Data : 07 0E 03 10 01 03 9A 00
RX Data : 07 1B
TX Data : 47 15 E0
TX Data : 21 00 3D A0 CA 00 00 37 03 35 54 01 10 31 05 27
05 0D 0B 0D 38 79 1D 11 C7 66 29 BB C2 07 92 11
03 2B 23 DB F2 BE 84
TX Data : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 05 0A
TX Data : 0E 05 8A 00
RX Data : 47 0B
RX Data : 12 00 07 83 03 B1 01 01 90 00 B4
TX Data : 53 15 E8
TX Data : 21 00 45 A0 D7 10 80 40 1F F0 26 40 5B FB 22 5E
A0 90 94 A5 76 73 5D 84 58 F6 A4 9B 6D 8E 67 CE
5C BB C8 FB CD 32 E0
TX Data : AB 5A 96 CA 3F 3A ED 45 C5 58 4F A2 A0 C4 C3 5E
44 0C 94 43 21 8B 04 DB 40 7C
TX Data : A4 8C B0 9A F4 E5 5B 4C 20 16 FF 06 0E 05 85 00
RX Data : 53 06
RX Data : FF FF FF FF FF
-
*********** we hit our bug *************
9000 was our loggin = good loggin, D7 packet 1 wrote to cam
1240029000
===========================================
90 was hit at 16FF delay ----VCC WAS 31 , our GlitchType was 08
*********** we hit our bug *************
9000 was our loggin = good loggin, D7 packet 2 wrote to cam
1240029000
===========================================
90 was hit at 16FF delay ----VCC WAS 31 , our GlitchType was 08
TX Data : 07 0E 03 10 01 03 9A 00
RX Data : 07 1B
RX Data : 3F FF 95 00 FF 91 81 71 A0 47 00 44 4E 41 53 50
30 31 31 20 52 65 76 42 30
10
TX Data : 60 15 F6
TX Data : 21 00 53 A0 CA 00 00 4D 00 4B 54 01 02 53 41 8D
70 D1 9A F0 7B 43 4F 1A 76 61 96 89 69 05 36 4B
76 5F 4B 3D 7A F9 59 B9 82 E6 57 80 C3 40 78 42
25 38 1D 90 6E EE 22 C1 B8 C2 10 51 55 BB 5B 56
92 7D F9 C9 87 55 89 4A 58 92 FB D5 16 B6 67 B1
88 73 85 77 B8 05 9C
TX Data : 20 00 FF 0E 05 85 00
RX Data : 60 06
RX Data : 12 00 07 80 03 B1
********************************
* NTL C&W ROM11 B0C EMM sent *
* ROM11 B0C cam should be open *
* test in Nagra to see. *
* if not, try again. *
********************************
XNCS
-------
Opening of port was sucessfull.
No atr sent from card.
Sorry...Not Dumping card.
Nagra 4.1
------------
Opening of COM1 was successful
ATR String: 3F FF 95 00 FF 91 81 71 A0 47 00 44 4E 41 53 50
30 31 31 20 52 65 76 42 30 43 3B
ROM Revision: 011
EEPROM Revision: RevB0C
ProviderID: 54
CamID: 24 74 B4 93
Using BD3 Key: 4E 69 70 50 45 72 20 49 73 20 61 20 62 75 54 74
Attempting to login to BD3
BackDoor login verified
Dumping Dataspace
Error getting BackDoor 0 key
Write error encountered, attempting to restore original decrypt keys
ProviderID: 54
CamID: 24 74 B4 93
Attempting to login to BD3
Decrypt keys successfully restored
Reading ROM11 failed
Closing of COM1 was successful
----------------
Any Ideas guys ?
Winexplorer
---------------
Executing Script: C:\Documents and Settings\Chris\Desktop\XNCS1[1][1][1].8\Scripts\rom11 boc script multiproviders+4801.xvb
TX Data : A0
TX Data : A1
TX Data : 07 0E 03 10 01 03 9A 00
RX Data : 07 1B
RX Data : 3F FF 95 00 FF 91 81 71 A0 47 00 44 4E 41 53 50
30 31 31 20 52 65 76 42 30
TX Data : 14 03 10 15 AB 21 00 08 A0 CA 00 00 02 12 00 06
55 0E 03 87 00
RX Data : 14 08
RX Data : 12 00 08 92 04 24 74 B4
TX Data : 17 15 B0 21 00 0D A0 CA 00 00 07 21 05 01 03 FF
FF 00 28 4F 0E 03 88 00
RX Data : 17 09
RX Data : 12 60 20 A1 26 54 01 00 01
Now we will try 16FF delay
TX Data : B0 30
TX Data : 07 0E 03 10 01 03 9A 00
RX Data : 07 1B
TX Data : 47 15 E0
TX Data : 21 00 3D A0 CA 00 00 37 03 35 54 01 10 31 05 27
05 0D 0B 0D 38 79 1D 11 C7 66 29 BB C2 07 92 11
03 2B 23 DB F2 BE 84
TX Data : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 05 0A
TX Data : 0E 05 8A 00
RX Data : 47 0B
RX Data : 12 00 07 83 03 B1 01 01 90 00 B4
TX Data : 53 15 E8
TX Data : 21 00 45 A0 D7 10 80 40 1F F0 26 40 5B FB 22 5E
A0 90 94 A5 76 73 5D 84 58 F6 A4 9B 6D 8E 67 CE
5C BB C8 FB CD 32 E0
TX Data : AB 5A 96 CA 3F 3A ED 45 C5 58 4F A2 A0 C4 C3 5E
44 0C 94 43 21 8B 04 DB 40 7C
TX Data : A4 8C B0 9A F4 E5 5B 4C 20 16 FF 06 0E 05 85 00
RX Data : 53 06
RX Data : FF FF FF FF FF
-
*********** we hit our bug *************
9000 was our loggin = good loggin, D7 packet 1 wrote to cam
1240029000
===========================================
90 was hit at 16FF delay ----VCC WAS 31 , our GlitchType was 08
*********** we hit our bug *************
9000 was our loggin = good loggin, D7 packet 2 wrote to cam
1240029000
===========================================
90 was hit at 16FF delay ----VCC WAS 31 , our GlitchType was 08
TX Data : 07 0E 03 10 01 03 9A 00
RX Data : 07 1B
RX Data : 3F FF 95 00 FF 91 81 71 A0 47 00 44 4E 41 53 50
30 31 31 20 52 65 76 42 30
10
TX Data : 60 15 F6
TX Data : 21 00 53 A0 CA 00 00 4D 00 4B 54 01 02 53 41 8D
70 D1 9A F0 7B 43 4F 1A 76 61 96 89 69 05 36 4B
76 5F 4B 3D 7A F9 59 B9 82 E6 57 80 C3 40 78 42
25 38 1D 90 6E EE 22 C1 B8 C2 10 51 55 BB 5B 56
92 7D F9 C9 87 55 89 4A 58 92 FB D5 16 B6 67 B1
88 73 85 77 B8 05 9C
TX Data : 20 00 FF 0E 05 85 00
RX Data : 60 06
RX Data : 12 00 07 80 03 B1
********************************
* NTL C&W ROM11 B0C EMM sent *
* ROM11 B0C cam should be open *
* test in Nagra to see. *
* if not, try again. *
********************************
XNCS
-------
Opening of port was sucessfull.
No atr sent from card.
Sorry...Not Dumping card.
Nagra 4.1
------------
Opening of COM1 was successful
ATR String: 3F FF 95 00 FF 91 81 71 A0 47 00 44 4E 41 53 50
30 31 31 20 52 65 76 42 30 43 3B
ROM Revision: 011
EEPROM Revision: RevB0C
ProviderID: 54
CamID: 24 74 B4 93
Using BD3 Key: 4E 69 70 50 45 72 20 49 73 20 61 20 62 75 54 74
Attempting to login to BD3
BackDoor login verified
Dumping Dataspace
Error getting BackDoor 0 key
Write error encountered, attempting to restore original decrypt keys
ProviderID: 54
CamID: 24 74 B4 93
Attempting to login to BD3
Decrypt keys successfully restored
Reading ROM11 failed
Closing of COM1 was successful
----------------
Any Ideas guys ?