provider 40

jasper post what you can read of the card m8
a few basic details will help
 
jasper - run vcc analyser on the card mate - it doesn't look to be talking to the loader!
 
_Phat_ said:
Try these 2

Here are the results from the two scripts T911 used with NEWD11 HEX...............
________________Setting up WinExplorer_________________

Executing Script: C:\DOCUME~1\Mike\LOCALS~1\Temp\Rar$DI14.844\Mike_rom11 boc script multiproviders.xvb
TX Data : A0
TX Data : A1
TX Data : 07 0E 03 10 01 03 9A 00
RX Data : 07 1B
RX Data : 3F FF 95 00 FF 91 81 71 A0 47 00 44 4E 41 53 50
30 31 30 20 52 65 76 41 33
TX Data : 14 03 10 15 AB 21 00 08 A0 CA 00 00 02 12 00 06
55 0E 03 87 00
RX Data : 14 08
RX Data : 12 00 08 92 04 00 00 00
TX Data : 17 15 B0 21 00 0D A0 CA 00 00 07 21 05 01 03 FF
FF 00 28 4F 0E 03 88 00
RX Data : 17 09
RX Data : 12 60 20 A1 26 5C 01 00 01

Now we will try 16FF delay
TX Data : B0 30
TX Data : 07 0E 03 10 01 03 9A 00
RX Data : 07 1B
TX Data : 47 15 E0
TX Data : 21 00 3D A0 CA 00 00 37 03 35 5C 01 10 31 05 27
05 0D 0B 0D 38 79 1D 11 C7 66 29 BB C2 07 92 11
03 2B 23 DB F2 BE 84
TX Data : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 05 00
TX Data : 0E 05 8A 00
RX Data : 46 04
TX Data : 53 15 E8
TX Data : 21 00 45 A0 D7 10 80 40 1F F0 26 40 5B FB 22 5E
A0 90 94 A5 76 73 5D 84 58 F6 A4 9B 6D 8E 67 CE
5C BB C8 FB CD 32 E0
TX Data : AB 5A 96 CA 3F 3A ED 45 C5 58 4F A2 A0 C4 C3 5E
44 0C 94 43 21 8B 04 DB 40 7C
TX Data : A4 8C B0 9A F4 E5 5B 4C 20 16 FF 06 0E 05 85 00
RX Data : 03 00
! ! ! ! ! ! ! ! ! ! ! ! ! !

Sc.Read: Timeout Reading Data From Card - 2 Bytes Requested, 0 Bytes Read, Continuing Script

Script Error on Line 176
Sc.GetByte: Requested Byte Exceeds Last Read Request

XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

Second Script


________________Setting up WinExplorer_________________

Executing Script: C:\DOCUME~1\Mike\LOCALS~1\Temp\Rar$DI00.781\Mike2_rom11 boc script multiproviders.xvb
TX Data : A0
TX Data : A1
TX Data : 07 0E 03 10 01 03 9A 00
RX Data : 45 00
TX Data : 14 03 10 15 AB 21 00 08 A0 CA 00 00 02 12 00 06
55 0E 03 87 00
RX Data : 14 08
RX Data : FF FF FF FF FF FF FF FF
TX Data : 17 15 B0 21 00 0D A0 CA 00 00 07 21 05 01 03 FF
FF 00 28 4F 0E 03 88 00
RX Data : 17 09
RX Data : 12 20 20 A1 26 5C 01 00 01

Now we will try 16FF delay
TX Data : B0 30
TX Data : 07 0E 03 10 01 03 9A 00
RX Data : 07 1B
TX Data : 47 15 E0
TX Data : 21 00 3D A0 CA 00 00 37 03 35 5C 01 10 31 05 27
05 0D 0B 0D 38 79 1D 11 C7 66 29 BB C2 07 92 11
03 2B 23 DB F2 BE 84
TX Data : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 05 00
TX Data : 0E 05 8A 00
RX Data : 46 04
TX Data : 53 15 E8
TX Data : 21 00 45 A0 D7 10 80 40 1F F0 26 40 5B FB 22 5E
A0 90 94 A5 76 73 5D 84 58 F6 A4 9B 6D 8E 67 CE
5C BB C8 FB CD 32 E0
TX Data : AB 5A 96 CA 3F 3A ED 45 C5 58 4F A2 A0 C4 C3 5E
44 0C 94 43 21 8B 04 DB 40 7C
TX Data : A4 8C B0 9A F4 E5 5B 4C 20 16 FF 06 0E 05 85 00
RX Data : 03 00
!

Sc.Read: Timeout Reading Data From Card - 2 Bytes Requested, 0 Bytes Read, Continuing Script

Script Error on Line 176
Sc.GetByte: Requested Byte Exceeds Last Read Request



No Luck as yet!

Regards
BM :Cheers:
 
Last edited:
try to send this to the card with the t911 then try to open it
 
Last edited:
TWOBEERCANS said:
try to send this to the card with the t911 then try to open it

Thanks TWOBEERCANS
It would seem that you are trying to send packet 3 only, I have tried to do this but with no luck. I have used your script just in case I missed something out.......

Results from Nagra4.1 after using T911 & Winexplorer...........

Opening of COM2 was successful
ATR String: 3F FF 95 00 FF 91 81 71 A0 47 00 44 4E 41 53 50
30 31 31 20 52 65 76 42 30 43 3B
ROM Revision: 011
EEPROM Revision: RevB0C
ProviderID: 40
CamID: CC CC CC CC
Using BD3 Key: 4E 69 70 50 45 72 20 49 73 20 61 20 62 75 54 74
Attempting to login to BD3
BD3 login failed
Reading ROM11 failed
Closing of COM2 was successful


I don't have a copy of Backdoor Buster!! do you think this might help



Regards
BM :drink:
 
brighton mike said:
Thanks TWOBEERCANS
It would seem that you are trying to send packet 3 only, I have tried to do this but with no luck. I have used your script just in case I missed something out.......

Results from Nagra4.1 after using T911 & Winexplorer...........

Opening of COM2 was successful
ATR String: 3F FF 95 00 FF 91 81 71 A0 47 00 44 4E 41 53 50
30 31 31 20 52 65 76 42 30 43 3B
ROM Revision: 011
EEPROM Revision: RevB0C
ProviderID: 40
CamID: CC CC CC CC
Using BD3 Key: 4E 69 70 50 45 72 20 49 73 20 61 20 62 75 54 74
Attempting to login to BD3
BD3 login failed
Reading ROM11 failed
Closing of COM2 was successful


I don't have a copy of Backdoor Buster!! do you think this might help



Regards
BM :drink:

mike i don't think the card is actually stream locked mate - use romstudio/backdoor/dumpcard login apprendz
if that fails see my post on rom10 image to rom11 in mosc section.

if nagra doesn't report the backdoor disabled/card may contain update then the cam is likely open already.
 
carwash said:
By changing to this

if provider = &H40 then
lrc = &H02
end if

You will need the login Nipper for provider 4001 and the D7 packets already written in script If not it will show error at all times

found this for rom10 4001
LOGIN COMMAND FOR PROVIDER 4001:
210025A0CA00001F031D40011099054E697050457220497320 612062755474260000000000000005FD

First package:

210045A0D7100040D2494F5507028A15E56D84AAA45514A26C B49169898EA748203FE4FD61F7A7B119BBA91AF160958F0858 FB707DC75C9D974DCA7062CED925794E9FC767A9FD72D3

Second package:

210045A0D71040406FB17889E45F45585F8228AA50403B463F DDB3F5EF72F53470DF29DCA8BD072B032ED910B29F0EACA340 FE50093EFC1598F637FB7A436801F4B3BC8921EF667B88

Third package:

210045A0D710804072AC3EA575E0649DA9F9A5B9EDE5A356C2 C1C6EF84E3D0662D4DB7ACA940D9ADA55E5C59F4184292CA3F 7EE0A3DEF1E33CF75F054B3EDADC32D69A3F3D4CFA6FC7

Fourth package:

210045A0D710C040C531B9969926E8D98EE7D3A48ADC4A5B04 B13B7D93902E6A7CD1BDFEAAF9051C77145FCA0640C4BF3931 BA2FF952F90991A3A01FFC4A88CC7FC6F28B4673132922

Fifth package:

210045A0D7110040B52D581FCDC768418D69037884B93049C5 B8816DD57FE32B1A9DBE062200F6D49FA26B43DAB93AED5244 5C164B29A882866C8BF7D0303D15D42C2420C5DBEA83C9

Sixth package

210045A0D7114040AEFBE93767B4B38A3D3B0C0165F8AF165B CF626F5528B89152D2921DB5342309335B0E0444190DC2E33C 67F88A6A80856CA2D18FEBF82A26F16B9394C4813B2E32

Seventh package:

210045A0D7118040D6C7C21A07FC89A0BEE92C9F0F61EE0463 38A0194EE47DE1C7B7819E9D38663834B7B6C698DF09F68AAE D7D9A315913580AE9074BFC99621AF64B473DCC38C829C
 
Opening of COM1 was successful
ATR String: 3F FF 95 00 FF 91 81 71 A0 47 00 44 4E 41 53 50
30 31 30 20 52 65 76 41 30 30 4A
ROM Revision: 010
EEPROM Revision: RevA00<<<<<<<<<<<<<<<<<<<<<<< This has now chagned since i last read the card
ProviderID: 40
CamID: 1B 83 F0 D8
Using BD3 Key: 4E 69 70 50 45 72 20 49 73 20 61 20 62 75 54 74
Attempting to login to BD3
BD3 login failed
Reading ROM10 failed
Closing of COM1 was successful


The sad thing the card hit a bug but would not open in nagra edit so i got the bk number off it using xncs

thanx guys
 
@jasperconran mate i don't think the card is locked - goto my thread in mosc section rom10 image on a rom 11 card - find the backdoor key and try to get into the card using romstudio and write a fresh image to it.

if the cam was locked i'm sure it should say reported disabled/card may contain update
 
Having spent a good few weeks on this card, I have to say that it must be "unlocked" (was 5c01 rom11 ver B0C but changed to provider ID 4001) but can't get into it.

Would like to try backdoor buster as XNCS keeps asking for BD 3 and I don't know what the key is.

Does anyone have a copy of Backdoor Buster? or know of anyway I can get or reset the backdoor keys so I can try XNCS again..........

Regards
BM :nopity:
 
mike post the nagra screen - also backdoor buster is for rom10's
i take it you tried xncs - goto settings check every thing - dump card - eeprom date line c040=bd0 and c070=bd3 !
 
TWOBEERCANS........... I can now get into the rom11 with Nagra edit 4.1 and have changed it to ROM Revision: 011
EEPROM Revision: RevB04
CAM Date: 1962 using a blank 11 image
I can change my details ie box & ird and can save the file but cannot write to card as I have a backdoor 3 error

If you don't mind I'll continue this tomorrow as I'm a bit "cream crackered" and I don't want to make any mistakes..

Best regards
BM

:grayyawn:
 
try rom studio nagra write method to write to the card ! you will need to enter the bd0 to do this. it is in line c040
here's a b01 blank
 
Last edited:
Twobeercans

TWOBEERCANS firstly here are some shots of the card using XNCS

The file from you won't load into rom studio, it will load into Nagra edit but i't a supplier 54 not 5C ( not that this matters at the moment)

The eeprom shot looks wrong!

Regards
BM
 
Last edited:
Close the thread please

Got the ROM11 card off rev B0C supplier ID 4001 at last...
Hard work or what!!

Thanks to all for your input, special thanks to TWOBEERCANS for his help

The card is now ROM11 rev B04 suplier 5C 01

with full service......

Best regards and don't give up!!

BM

:Cheers:
 
load the blank into nagra and then save as a bin it will then load into romstudio < just for the thread because i see your now sorted 'welldone mate'
 
for future reference
u cannot just change the login (especially if u don't calculate the correct lrc) and expect a script to work on a different provider. packet 3 is also provider specific and u must make up a completely new packet to change the provider support (as the provider id is also in the encrypted part of the packet)
it's also not terribly productive to use existing rom 11 scripts on a rom 10 - however if u modified packet 3 then they should work (the card type nibble needs altering in the raw emm)
rom 11 provider 40 support has been built into the latest script - atm I have no plans to add rom 10 provider 40 support into existing scripts as rom 10 scripts currently aren't compatible with my methods

the latest script is here http://www.digidudez-forums.co.uk/showthread.php?t=1177 and here http://www.unlocker-forums.co.uk/showpost.php?p=160561&postcount=2 and here http://www.world-of-digital.com/forums/showthread.php?t=55953
 
Thanks WONKO

WONKO,

Thank you for your work on the new script with provider 40 support.

You have my admiration and grateful thanks, and I'm sure, the thanks of many other members........

Best regards
BM
:mexican:
 
Back
Top