Unlocking A82 card with new B0D script

bammy

Inactive User
Joined
Nov 29, 2004
Messages
1,510
Reaction score
3
Tried to open an A82 card with the new B0D script, set it off at about 10:30 last night and nine hours later it was still going - is this normal? What's the longest anyone has seen with the new script - or indeed has anyone unlocked an A82 using it? I'm now running it with the mrmp1.5 script to see if that gives any success.
 
bammy said:
Tried to open an A82 card with the new B0D script, set it off at about 10:30 last night and nine hours later it was still going - is this normal? What's the longest anyone has seen with the new script - or indeed has anyone unlocked an A82 using it? I'm now running it with the mrmp1.5 script to see if that gives any success.


I,ll try 1 now mate and post the results
 
fatblerk said:
i thought it was for r11's only as well?



my a82 card i have never been able to open it is probably kaput anyway just a little experiment
 
tried the bod script on a reva82 card just out of interest left it on for 24 hours and it was still running so doesnt work on rom 10 reva82 im affraid
 
Thanks for the replies guys - looks like I got the wrong end of the stick, I thought it did both 10 & 11:)
 
Its very Rom11 specific. The particular payloads used will only ever work on a Rom11 card. To stand any chance on a Rom10 card you would have to rewrite the payloads AND find a relevant glitch point that could be used !
 
The new flash likes A82's though. Popped one an hour ago in less than 10 mins using the multiprovider A82 script.
 
I have a r11 B09 i cant get back into

ByteMaster said:
The New Bod Script Is Only For Rom 11 Cards....
I have a Rom 11 B09 I can't get back into I have tried the new BOD script is says Glitch Success!! ROM 11 BUGS ZEROED
BootLoader 90 00 RSP Received!!
VCC = 12 (~0.34757647058823 vdc)
Glitch Delay = 00F4
Glitch type 08
Developed @ http://www.sky-digital.org/

But when i read it in Nagra i get the follwing message
Opening of COM2 was successful
ATR String: 3F FF 95 00 FF 91 81 71 A0 47 00 44 4E 41 53 50
30 31 31 20 52 65 76 42 30 39 41
ROM Revision: 011
EEPROM Revision: RevB09
ProviderID: 5C
CamID: 19 77 77 91
Using BD3 Key: 4E 69 70 50 45 72 20 49 73 20 61 20 62 75 54 74
Attempting to login to BD3
BackDoor login verified
Dumping Dataspace
Backdoor retrieval has been blocked
Attempting to login to BD3
Attempting to login to BD0
Unable to login, bad password detected
Attempting to login to BD0
Unable to login, bad password detected
Login attempt aborted
Reading ROM11 failed
Closing of COM2 was successful

I have read the card in XNCS & copied the BD keys but it still will not let me in, any help appreciated thanks
 
Hi
sounds like a bad image
use the bd key and rom studio
its covered in my tut but dont use the images
they aint been fixed as yet in download sec
ive been busy in the arcade lol
 
As I think cracherchalk is suggesting, just load a clean rom11 image into romstudio and write it to the card. You will need to rename the image with a .bin extension first.
 
bammy said:
As I think cracherchalk is suggesting, just load a clean rom11 image into romstudio and write it to the card. You will need to rename the image with a .bin extension first.

Bammy I have done what u have suggested but it is asking for a password I have tried the ones i got from XNCS originally but it still wont let me in.
 
try using the repair function in mrom then try reading in xncs they keys might have changed, worked for me before
 
use rev7 from downloads to repair ur card it works perfect and restores ur bd keys to nagra standard

then just write another good image through nagra

:Cheers: :Cheers: :Cheers: :Cheers:
 
Hate to contridict you guys but after changing the cmd in the script to one posted by nick-a on unlockers i opened an a82 that i couldnt open for 8 months, the one glitch method is something we dont know much about at the moment and after changing the command i was shocked that it opened it, in the script i changed the cmd to this


cmd = "210035A0CA00002F032D5401102905CD7AB7C0A1A600B7B8949A6E3EA17741509E4A91546C62F3A723B1C1E94DA68CA723B1C1E94DA68C05"

I couldnt believe it and have been testing other cards now particularly A86 im testing timing for it at the moment
 
Hi all :BLOBBY:
Sorry for the change of subject but
this card u opened what was wrong with it?
Cos i have one that wont write to the cam!
finds the bug quick and says its unlocked
but no write to the cam as expected
pdev55 said:
Hate to contridict you guys but after changing the cmd in the script to one posted by nick-a on unlockers i opened an a82 that i couldnt open for 8 months, the one glitch method is something we dont know much about at the moment and after changing the command i was shocked that it opened it, in the script i changed the cmd to this


cmd = "210035A0CA00002F032D5401102905CD7AB7C0A1A600B7B8949A6E3EA17741509E4A91546C62F3A723B1C1E94DA68CA723B1C1E94DA68C05"

I couldnt believe it and have been testing other cards now particularly A86 im testing timing for it at the moment
Could i have the same prob cos ill dig it out the a82 i mean
cos its still locked and has been a few months now:proud:
 
Back
Top