Follow Us On Follow us on Facebook Follow us on Twitter Watch us on YouTube
Register
Page 1 of 4 123 ... LastLast
Results 1 to 10 of 40
Like Tree1Likes

Nagra 3 exploit using a blocker.

This is a discussion on Nagra 3 exploit using a blocker. within the General Cable TV. forums, part of the DVB Cable Discussions category; Now firstly this does work; however its not a reverse engineering of the ROM: Anyone considered this ? When we ...

  1. #1
    Mr_Spark's Avatar
    Member

    Status
    Offline
    Join Date
    Dec 2009
    Posts
    54
    Rep Power
    7

    Default Nagra 3 exploit using a blocker.

    Now firstly this does work; however its not a reverse engineering of the ROM:

    Anyone considered this ?

    When we cancel a subscription VM send a CMD#04 out to turn our card off; now hows about we block just that cmd ?

    We could alter the Spanish Code fairly easily and use a AVR 8515 card similar too >

    Tarjeta Universal THT v1.4 ( AVR8)

    Using this as the logger that filters to our card and allow the rest of the data flow ( altho` we dont know what the rest do without the Encryption key ); will keep our card alive.

    Or we could use a Dreambox and disable cmd#04 in the CAM - this way we need pairing details.

    Now this will work and I guess when we do this we are watching free TV without dirty c/s.

    Where we fall down is that tiers will probably expire ( time unknown but I guess and its only a guess is a few months )

    A bit of food for thought ....

    S

  2. Thanks sinno thanked for this post

    • Advertising

      advertising
      Techkings.org
      has no influence
      on advertisings
      that are displayed by
      Google Adsense


        
       

  3. #2
    sinno's Avatar
    VIP Member

    Status
    Offline
    Join Date
    Apr 2009
    Location
    ireland
    Posts
    1,339
    Rep Power
    83

    Default

    Mr_Spark,great to see thoughts other than dirty c/s,could this be used with the itgate box also
    Sin:no
    Software is like sex, it's better when it's free. - Linus Torvalds

  4. #3
    j4v3d's Avatar
    Techkings Addict

    Status
    Offline
    Join Date
    Aug 2010
    Location
    Unknown - Top Secret
    Age
    23
    Posts
    3,250
    Rep Power
    174

    Default

    Mr_Spark you are too technical for me trying to understand what you wrote, you sound like a tech guru

  5. #4
    Mr_Spark's Avatar
    Member

    Status
    Offline
    Join Date
    Dec 2009
    Posts
    54
    Rep Power
    7

    Default

    Quote Originally Posted by sinno View Post
    Mr_Spark,great to see thoughts other than dirty c/s,could this be used with the itgate box also
    Yes in theory using the card slot the Linux could be altered to use the CAM with a blocked CMD#04 but you would beed the DT08 etc to code up.

    S

  6. Thanks sinno thanked for this post
    Likes sinno Like
  7. #5
    sinno's Avatar
    VIP Member

    Status
    Offline
    Join Date
    Apr 2009
    Location
    ireland
    Posts
    1,339
    Rep Power
    83

    Default

    Appreciate the info and will enjoy researching it
    Sin:no
    Software is like sex, it's better when it's free. - Linus Torvalds

  8. #6
    wheelo's Avatar
    Wii Addict/Tech junkie

    Status
    Offline
    Join Date
    Jun 2009
    Location
    Dublin
    Age
    41
    Posts
    9,046
    Rep Power
    489

    Default

    Thinking outside the box is what is going to get around this thing that is nagra 3. I like your thinking Mr. Sparks

  9. #7
    j4v3d's Avatar
    Techkings Addict

    Status
    Offline
    Join Date
    Aug 2010
    Location
    Unknown - Top Secret
    Age
    23
    Posts
    3,250
    Rep Power
    174

    Default

    i always enjoy reading mr sparks comments on here, very technical and straight to the point, im glad you share your intelligence with us

  10. #8
    Mr_Spark's Avatar
    Member

    Status
    Offline
    Join Date
    Dec 2009
    Posts
    54
    Rep Power
    7

    Default

    Quote Originally Posted by j4v3d View Post
    i always enjoy reading mr sparks comments on here, very technical and straight to the point, im glad you share your intelligence with us
    We have to understand that what we are doing here is an avenue of interest and with a softcam we can fairly easily block any CMD we want; the work as already been done overseas in underground places. Of course it works (allegedly) and I realise there is little chance of a really major breakthrough; we can assume with a bit of confidence that the new codespace tier structure will be identical to other flavours of Nagra. But let`s see how long it lasts . Its kind of ols skool to be not subscribing, not using card share and watching TV on a standard VM box or soft cam alternative.

    When we look at the cards I am sure we all realise that N1 was indeed compromised with info gained from a dump/file in Spain (when you look back it`s amazing how long the UK took to realise we could use all there tools ). As for the Nipper login used in various bits of code like Nagra Edit; yes without a dump how did we know ? Lots of theories of things reverse engineered by other parties and leaked...

    From what I can see, other avenues of a “real” hack look @ dumping the N3 card; we know from other places that we can fault the CAM; however we all realise that the RAM protection and indeed timing of code exe along with encryption keys we have no idea about, make things ahem - challenging! I truly believe that we are not going to hack N3 without serious equipment in a LAB environment. We can`t write anything to the card let alone know any addressing until this is done; this requires breaking the ROM down structure by structure, gate by gate to reverse engineer the code.

    To coin a phrase we need the key(s) and yes blocking a cmd to turn off our card works ( but for how long ? ); but all we are doing is taking a large bat and pitching the cmd#04 away from the card – Very novice and very blunt. I realised a long time ago that I am in the haxing world wet behind the ears and a complete novice.

    S
    Last edited by Mr_Spark; 25-10-2011 at 02:58 PM.
    To trade what others give for free is true evil

  11. Thanks j4v3d, sinno thanked for this post
  12. #9
    leemoo's Avatar
    Member

    Status
    Offline
    Join Date
    Oct 2009
    Posts
    82
    Rep Power
    7

    Default

    Quote Originally Posted by Mr_Spark View Post
    We have to understand that what we are doing here is an avenue of interest and with a softcam we can fairly easily block any CMD we want; the work as already been done overseas in underground places. Of course it works (allegedly) and I realise there is little chance of a really major breakthrough; we can assume with a bit of confidence that the new codespace tier structure will be identical to other flavours of Nagra. But let`s see how long it lasts . Its kind of ols skool to be not subscribing, not using card share and watching TV on a standard VM box or soft cam alternative.

    When we look at the cards I am sure we all realise that N1 was indeed compromised with info gained from a dump/file in Spain (when you look back it`s amazing how long the UK took to realise we could use all there tools ). As for the Nipper login used in various bits of code like Nagra Edit; yes without a dump how did we know ? Lots of theories of things reverse engineered by other parties and leaked...

    From what I can see, other avenues of a “real” hack look @ dumping the N3 card; we know from other places that we can fault the CAM; however we all realise that the RAM protection and indeed timing of code exe along with encryption keys we have no idea about, make things ahem - challenging! I truly believe that we are not going to hack N3 without serious equipment in a LAB environment. We can`t write anything to the card let alone know any addressing until this is done; this requires breaking the ROM down structure by structure, gate by gate to reverse engineer the code.

    To coin a phrase we need the key(s) and yes blocking a cmd to turn off our card works ( but for how long ? ); but all we are doing is taking a large bat and pitching the cmd#04 away from the card – Very novice and very blunt. I realised a long time ago that I am in the haxing world wet behind the ears and a complete novice.

    S
    Is it me or is that typing in invisible ink?

  13. #10
    sinno's Avatar
    VIP Member

    Status
    Offline
    Join Date
    Apr 2009
    Location
    ireland
    Posts
    1,339
    Rep Power
    83

    Default

    Are you aware of the ProgSkeet Mr_Spark and is it of any use,i still have the original boxes which i was given when i took out my service,they were'nt changed only the cards were changed,i dont get the sports or movies just everything else,im just wondering could the Progskeet be used to garner some information from the box itself as to how it handles the card
    Very much a novice here to
    Sin:no
    Software is like sex, it's better when it's free. - Linus Torvalds

 

 
Page 1 of 4 123 ... LastLast

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •