rom11 unlocking?!

blaszczyk

Inactive User
Joined
Dec 6, 2008
Messages
17
Reaction score
0
Right finally got hold of a box with a paired card and i cant afford to fry the card on this one so i need your help peeps.
First question, to unlock the card is it best to use:MIKEDATA & CHARTMAN A86 AND BOD SCRIPT MAY 2007 A86, OR MIKEDATA & CHARTMAN BOD SCRIPTJan 2008 OR MIKEDATA'S JULY 2008 ROM 10 A86 A88 A82 final OR MIKEDATA Jan2008 ROM 10 Modded 2801 final OR rom11 unlocker? which ones best?
Second question is: when card has been successfully unlocked and i read card in phoenix what do i look for that tells me its been unlocked succesfully?
question 3: if i use sidewinder, how do you change com port that it reads from? i use com1 but it keeps readin com2 and cant seem to change it! thanks peeps
 
Which unlocker you use depends on which card you have. If you have a Rom10 then obviously you want to use a Rom10 unlocker. If its a Rom11 then a Rom11 unlocker is the thing.

Some of the unlockers are combined so will do both.

Generally speaking, the later the date, the more refined the unlocker as long as you stay away from test versions.

Checking your card version is usually quite simple. The digibox itself will often tell you in either in the setup menu or the engineering menu. Alternatively, you could look at the card itself - they usually have a number stamped on them somewhere that tells you the version and provider (ie 0115C01P04 - Rom 011 for provider 5C01 (exCW) ). Another method is to use NagraEdit and a phoenix reader. Just do a "card>reset card" and that will give you the ATR. Dont attempt to read the card at this stage - just get the ATR.

Q2, if the card reads in NagraEdit then its open. If it doesn't then its not (or your incorrectly configured). Its really as simple as that.
 
So i read the card in nagra (reset card) and came up with my atr and what not, does this means its already unlocked then?
 
no u need to glitch the card with a unlocker to open it and get the keys
 
Sorry, my answer to Q2 was a bit vague but I answered it in the context that you asked it. (...when card has been successfully unlocked .....) so yes, you still need to glitch the card to unlock it.

Getting the ATR was simply so you could determine what kind of card it was (Rom10 or 11) and what revision of firmware it has (RevA86, RevB0D etc)
 
ok glitched card no probs, its gave me a fake bk key, starts 6D 56, what do i do now?
 
the t911 is a pretty good one m8 not much good for the a86 but as an unlocker they are ok
 
Would help if you told us what box the original card is from.Alot easier when you start off by jtagging the box or led sim and getting your box details that way you can buy a 5 quid funcard and get going that way.
 
but all ive done is unlocked the card i havent done owt else, why have i got a afke bk?
 
the box was prob left onstream wen the sub was cancelled , therefore the info was sent to the card , hence the false bk
 
VM attempt to protect their property by removing information from a card when the subscription expires. The 2110 is one of the few boxes where the required information cannot be extracted by other means.

For a 2110 box the only way to guarantee correct information from the card is to remove it from the cable connection BEFORE the subscription expires. The card must not be connected to the datastream AFTER subscription termination at all.
 
Last edited:
sorry to jump in but i need to get bk from a locked rom11 bod
which unlooper and software will i need
thanks
 
the providers do not erase the box key from the card when it is de-sub'd. an easy test for this is simply put the card in the reciever, if the receiver boots then it is married, also try to put any other smart card in the same receiver, see the difference?

if you have the original rom11 that goes with the receiver dumped, thats all you need. i am not sure what you mean by false box keys? i have never seen an encrypted box key on a N1 cam. even if it is by some stoke of god, just xor the encrypted box key with the idea key.

by the way, can you post some VERY GOOD QUALITY pictures of the inside of the receiver? especially the cpu chip, the system flash chip (ysop or bga), and nvram chips.

lastly, if all else fails i am not sure what provider you are on, but if your provider does month to month service, put a backdoor on the rom11, then activate it for 1 month, that will give you all your info.

cheers
disco
 
the providers do not erase the box key from the card when it is de-sub'd. an easy test for this is simply put the card in the reciever, if the receiver boots then it is married, also try to put any other smart card in the same receiver, see the difference?

if you have the original rom11 that goes with the receiver dumped, thats all you need. i am not sure what you mean by false box keys? i have never seen an encrypted box key on a N1 cam. even if it is by some stoke of god, just xor the encrypted box key with the idea key.

by the way, can you post some VERY GOOD QUALITY pictures of the inside of the receiver? especially the cpu chip, the system flash chip (ysop or bga), and nvram chips.

lastly, if all else fails i am not sure what provider you are on, but if your provider does month to month service, put a backdoor on the rom11, then activate it for 1 month, that will give you all your info.

cheers
disco
i don't know where you got that info from but the providers here put fake box keys in when you cancell your sub the IRD of the box is all 00000000 but you can get that from the box .the box keys are put in fake
what NOZZER said is 100% right he knows what he;s talking about.
 
Back
Top