Add us on Follow us on Facebook Follow us on Twitter Watch us on YouTube
Register
+ Log in or register to post
Page 1 of 2 12 LastLast
Results 1 to 20 of 40
Like Tree1Likes

Nagra 3 exploit using a blocker.

This is a discussion on Nagra 3 exploit using a blocker. within the General Cable TV. forums, part of the DVB Cable Discussions category; Now firstly this does work; however its not a reverse engineering of ...

  1. #1
    Member Mr_Spark's Avatar

    Nagra 3 exploit using a blocker.

    Now firstly this does work; however its not a reverse engineering of the ROM:

    Anyone considered this ?

    When we cancel a subscription VM send a CMD#04 out to turn our card off; now hows about we block just that cmd ?

    We could alter the Spanish Code fairly easily and use a AVR 8515 card similar too >

    Tarjeta Universal THT v1.4 ( AVR8)

    Using this as the logger that filters to our card and allow the rest of the data flow ( altho` we dont know what the rest do without the Encryption key ); will keep our card alive.

    Or we could use a Dreambox and disable cmd#04 in the CAM - this way we need pairing details.

    Now this will work and I guess when we do this we are watching free TV without dirty c/s.

    Where we fall down is that tiers will probably expire ( time unknown but I guess and its only a guess is a few months )

    A bit of food for thought ....

    S

  2. Thanks sinno thanked for this post
  3. #2
    VIP Member sinno's Avatar
    Mr_Spark,great to see thoughts other than dirty c/s,could this be used with the itgate box also
    Sin:no
    Software is like sex, it's better when it's free. - Linus Torvalds

  4. #3
    Techkings Addict j4v3d's Avatar
    Mr_Spark you are too technical for me trying to understand what you wrote, you sound like a tech guru

  5. #4
    Member Mr_Spark's Avatar
    Quote Originally Posted by sinno View Post
    Mr_Spark,great to see thoughts other than dirty c/s,could this be used with the itgate box also
    Yes in theory using the card slot the Linux could be altered to use the CAM with a blocked CMD#04 but you would beed the DT08 etc to code up.

    S

  6. Thanks sinno thanked for this post
    Likes sinno Like
  7. #5
    VIP Member sinno's Avatar
    Appreciate the info and will enjoy researching it
    Sin:no
    Software is like sex, it's better when it's free. - Linus Torvalds

  8. #6
    Wii Addict/Tech junkie wheelo's Avatar
    Thinking outside the box is what is going to get around this thing that is nagra 3. I like your thinking Mr. Sparks

  9. #7
    Techkings Addict j4v3d's Avatar
    i always enjoy reading mr sparks comments on here, very technical and straight to the point, im glad you share your intelligence with us

  10. #8
    Member Mr_Spark's Avatar
    Quote Originally Posted by j4v3d View Post
    i always enjoy reading mr sparks comments on here, very technical and straight to the point, im glad you share your intelligence with us
    We have to understand that what we are doing here is an avenue of interest and with a softcam we can fairly easily block any CMD we want; the work as already been done overseas in underground places. Of course it works (allegedly) and I realise there is little chance of a really major breakthrough; we can assume with a bit of confidence that the new codespace tier structure will be identical to other flavours of Nagra. But let`s see how long it lasts . Its kind of ols skool to be not subscribing, not using card share and watching TV on a standard VM box or soft cam alternative.

    When we look at the cards I am sure we all realise that N1 was indeed compromised with info gained from a dump/file in Spain (when you look back it`s amazing how long the UK took to realise we could use all there tools ). As for the Nipper login used in various bits of code like Nagra Edit; yes without a dump how did we know ? Lots of theories of things reverse engineered by other parties and leaked...

    From what I can see, other avenues of a “real” hack look @ dumping the N3 card; we know from other places that we can fault the CAM; however we all realise that the RAM protection and indeed timing of code exe along with encryption keys we have no idea about, make things ahem - challenging! I truly believe that we are not going to hack N3 without serious equipment in a LAB environment. We can`t write anything to the card let alone know any addressing until this is done; this requires breaking the ROM down structure by structure, gate by gate to reverse engineer the code.

    To coin a phrase we need the key(s) and yes blocking a cmd to turn off our card works ( but for how long ? ); but all we are doing is taking a large bat and pitching the cmd#04 away from the card – Very novice and very blunt. I realised a long time ago that I am in the haxing world wet behind the ears and a complete novice.

    S
    Last edited by Mr_Spark; 25-10-2011 at 02:58 PM.
    To trade what others give for free is true evil

  11. Thanks andy g, j4v3d, sinno thanked for this post
  12. #9
    TK Veteran leemoo's Avatar
    Quote Originally Posted by Mr_Spark View Post
    We have to understand that what we are doing here is an avenue of interest and with a softcam we can fairly easily block any CMD we want; the work as already been done overseas in underground places. Of course it works (allegedly) and I realise there is little chance of a really major breakthrough; we can assume with a bit of confidence that the new codespace tier structure will be identical to other flavours of Nagra. But let`s see how long it lasts . Its kind of ols skool to be not subscribing, not using card share and watching TV on a standard VM box or soft cam alternative.

    When we look at the cards I am sure we all realise that N1 was indeed compromised with info gained from a dump/file in Spain (when you look back it`s amazing how long the UK took to realise we could use all there tools ). As for the Nipper login used in various bits of code like Nagra Edit; yes without a dump how did we know ? Lots of theories of things reverse engineered by other parties and leaked...

    From what I can see, other avenues of a “real” hack look @ dumping the N3 card; we know from other places that we can fault the CAM; however we all realise that the RAM protection and indeed timing of code exe along with encryption keys we have no idea about, make things ahem - challenging! I truly believe that we are not going to hack N3 without serious equipment in a LAB environment. We can`t write anything to the card let alone know any addressing until this is done; this requires breaking the ROM down structure by structure, gate by gate to reverse engineer the code.

    To coin a phrase we need the key(s) and yes blocking a cmd to turn off our card works ( but for how long ? ); but all we are doing is taking a large bat and pitching the cmd#04 away from the card – Very novice and very blunt. I realised a long time ago that I am in the haxing world wet behind the ears and a complete novice.

    S
    Is it me or is that typing in invisible ink?

  13. #10
    VIP Member sinno's Avatar
    Are you aware of the ProgSkeet Mr_Spark and is it of any use,i still have the original boxes which i was given when i took out my service,they were'nt changed only the cards were changed,i dont get the sports or movies just everything else,im just wondering could the Progskeet be used to garner some information from the box itself as to how it handles the card
    Very much a novice here to
    Sin:no
    Software is like sex, it's better when it's free. - Linus Torvalds

  14. #11
    Member Mr_Spark's Avatar
    Quote Originally Posted by sinno View Post
    Are you aware of the ProgSkeet Mr_Spark
    Good idea but I am afraid it can flash prog but its of little use with Nagra.

  15. #12
    Wii Addict/Tech junkie wheelo's Avatar
    Quote Originally Posted by leemoo View Post
    Is it me or is that typing in invisible ink?
    we just don't want you to know we are talking about you leemoo I imagine what happened is that your skin has the same colour as Sparks' text, just highlight it as if you were going to copy and paste it

  16. #13
    Member Mr_Spark's Avatar
    Interesting - this is still working without any top tier loss; has kudelski messed up with N3 and not realised this could be done and left a gaping hole :-)

  17. Thanks sinno thanked for this post
    Likes sinno Like
  18. #14
    Techkings Addict j4v3d's Avatar
    Quote Originally Posted by Mr_Spark View Post
    Interesting - this is still working without any top tier loss; has kudelski messed up with N3 and not realised this could be done and left a gaping hole :-)
    i see your hard at work Mr Sparks, any sparks flying at the moment regarding nagra 3 ?

  19. #15
    Member Mr_Spark's Avatar
    Quote Originally Posted by j4v3d View Post
    i see your hard at work Mr Sparks, any sparks flying at the moment regarding nagra 3 ?
    I think we have found at least a hole - I am ( allegedly ) watching TV on a VM box and Dreambox without cardshare - like old times ...

  20. Thanks wheelo, sinno thanked for this post
    Likes sinno Like
  21. #16
    VIP Member sinno's Avatar
    Quote Originally Posted by Mr_Spark View Post
    I think we have found at least a hole - I am ( allegedly ) watching TV on a VM box and Dreambox without cardshare - like old times ...
    Sounds like a very large hole in Nagra 3 Mr_Spark one i hope to exploit myself
    Sin:no
    Software is like sex, it's better when it's free. - Linus Torvalds

  22. #17
    Member Mr_Spark's Avatar
    I have had a few PM`s about this; any questions please on open forum then anyone can join in or input answer.

    This is still working with no loss of channels - so tiers are obv still all ok.

    I have also learnt that we probably do not have any keychanges on N3 (at the moment)

    S

  23. Thanks axxxo, dee, sinno, ferguj1 thanked for this post
    Likes sinno, hadmad Like
  24. #18
    Techkings Addict j4v3d's Avatar
    Quote Originally Posted by Mr_Spark View Post
    I think we have found at least a hole - I am ( allegedly ) watching TV on a VM box and Dreambox without cardshare - like old times ...
    does it work on any other boxes? which VM box do you have? and how did you get it to work? i'd love to enjoy it while it lasts

  25. #19
    Member Mr_Spark's Avatar
    Quote Originally Posted by j4v3d View Post
    does it work on any other boxes?
    Yes of course, any box that wil take a ROM; most boxes are the same be it the quality of components and all but the odd one are LINUX based with fairly portable code. With a VM box we need to filter the ROM with an inline device like the 1 I pointed out. Any oher box just needs CMD#4 blocking in the CAM/Code for that particular box; ok if the box does not have source code for using a ROM its going to be more difficult but not that hard.

    S

  26. Likes hadmad Like
  27. #20
    Techkings Addict j4v3d's Avatar
    this will probably annoy you but please forgive me - can you explain that in layman terms?

    so the old starview boxes that went off - can they be activated somehow or the old virgin media silver box?

  •   
 

 

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  


About Us

    Techkings is an online community based on Technology - Digital Media - Cable and Satellite. Everything discussed on this forum is for experimental and educational purposes only. We accept no liability to anything damaged by using the information given here. Use ANY information at your own risk!.

Follow us on

Twitter Facebook youtube Flickr DavianArt Dribbble RSS Feed