| N3 Chat Discussions on the new N3 Rollout. |
![]() |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Member
Join Date: May 2008
Posts: 48
Thanks: 7
Thanked 1 Time in 1 Post
|
Lads and Lassies.
The source code for n3 has been found and tested Last edited by G77; 12-02-11 at 09:35 AM. Reason: removed attached file - hacking material (useless of not) is not to be made available on techwatch |
|
|
|
|
|
#2 (permalink) |
|
Senior Member
Join Date: May 2008
Posts: 2,129
Thanks: 1,215
Thanked 801 Times in 635 Posts
|
The source code above which you have posted was tested back in 2001 and I doubt it has any relevance at all for the present, if memory serves me right they attempted a crack on the sat side and never worked out.
If a hack / crack was going to come out I would have imagined that it would have come out by now. Infact it would have been out 10 yrs ago. I could be wrong but am sure someone will shed more light in regards to this. Also looking at the source code its for Rom102Rev241 to Rom102Rev242 .. Am no expert at this but kudelski are using Rom 180, SO I would have imagine that its useless to even look at the code. But as I said am not a expert.. And its a wild Guess. Infact to me these codes dont make any sense @ all.
Last edited by unadkat; 12-02-11 at 05:17 AM. |
|
|
|
|
|
#3 (permalink) |
|
Underground Crew Member
Join Date: May 2009
Location: Undrground
Posts: 2,149
Thanks: 15
Thanked 1,691 Times in 933 Posts
|
Rom102 was also N2, not N3 !
The Rom102 was heavily used in the US several years ago and was hacked to hell - almost as much as our Rom10/11 cards. Its far less advanced even than the old Irish Rom110 card. In terms of N3 functionality the dumps have next to zero usefulness. If you actually want a dump of any of the 101/102/103 series of cards they are readily available as are full disassembly listings. They can be quite interesting if you want to start to learn about nagra card pairing. |
|
|
|
| The Following 3 Users Say Thank You to TheCoder For This Useful Post: |
|
|
#4 (permalink) |
|
Senior Member
Join Date: Feb 2007
Location: Belfast
Posts: 347
Thanks: 23
Thanked 56 Times in 50 Posts
|
Not my work but just a brief description of rsa and sk and the process which has been covered before by the coder
If Using DT08 (0a) on the card : The Dt08 (0a datatype on card) is created by the provider and sent to the card at sub time. The dt08 contains the Cam N public rsa key along with ird/boxkey. The dt08 is IDEA encrypted with the Idea Key made from ird/boxkey/inverted ird. The dt08 is RSA encrypted using Ird N (public rsa key) and Ird D (private key and uknown by anyone but provider). Ird N = N1 xored N2 Ird N1= A4E9B585932F90282FD70C908176E8605E6B2CE629335A0FC1 5B31DAB0BFC6FEEB88CFC69649994CD3FE039C9965C620C4D5 828E9153998EE4AE0E8C25644DF3 xor Ird N1= 237280AAB36BE4B21FC71FBF08218E532A545E744D7B007FF8 69BA426831C4AC653F3825ADE9358FCD1F0239EC447CBC2765 CC0AEBE437AF2270FC461C2FA042 Ird N = 879B352F2044749A3010132F89576633743F729264485A7039 328B98D88E02528EB7F7E33BA0ACC31EE101A57521BA9CE3B0 4E847AB7AE21C6DEF2CA394BEDB1 The Ird N1,N2,Ideakey exist in the tsop. Ird E = 3 Ird D = UKNOWN, this is the reason you can't create your own dt08 without changing the N1/N2 on the tsop, you must know Ird D. DT08 (0A) = IdeaEncrypt(CamN/Ird#/Boxkey/Idea Signature,Ird_Ideakey) ^ D mod Ird N. Ird requests DT08. Card sends back the dt08 (0a) Ird decrypts the dt08. Decrypted dt08 = IdeaDecrypt(DT08,Ird_IdeaKey) ^ 3 mod Ird N. It checks the ird # and boxkeys in the Decrypted 08 if they match what is on ird, it stores the Cam N in the decrypted 08 in ird memmory. If Using Secondary Key (SK) on the Ird. Ird checks for SK exists on the ird, if it does, the dt08 will never be requested/ignored from the card. Ird validates the SK with idea signature in the SK (using IIIIIIII01924314051647990A9C4E1 where I = irdnumber). Ird takes the Cam N in the SK and puts it in ird memmory Note : Cam N is not even encrypted in the sk, very weak method compared to dt08. Later, establish session key (0C datatype on the card): Ird requests 2a data from card. Random 2a is sent from card to ird. Ird performs some Idea signing (leave it to you to look up 2a/2b routines) Ird comes up with session key from the 2a message sent from Cam. Ird encrypts the session key with rsa. Encrypted 2B = (2B data with 16 byte session idea key) ^ 3 mod Cam N. Sends encrypted data back to card in 2b message. Cam decrypts 2B with Cam N, Cam D. Decrypted 2B = (Encrypted 2B) ^ Cam D mod Cam N. If valid, store session key in ram and on card for later use. This all happens as ird boots. When you select a channel. Ird sends Cmd 07 ECM message with control words encrypted. Cam decrypts the control words rencrypts them with Idea encryption using the session key established above. The ird then requests the control words. The Cam sends them back in the 1C response. The ird decrypts the control words with with Idea encryption using the session key established above. Sends the control words to the mpeg decoder. 8 seconds of video. Repeat 07/1C process over and over. This is all done from memmory, excuse any oversites/exclusions/errors. Not exhaustive on each step by any means, just a quick overview. |
|
|
|
|
|
#5 (permalink) |
|
Underground Crew Member
Join Date: May 2009
Location: Undrground
Posts: 2,149
Thanks: 15
Thanked 1,691 Times in 933 Posts
|
wow, falls off chair and suffers great shock to system !
A technical post - didn't think I would live long enough to see one of those ! |
|
|
|
| The Following User Says Thank You to TheCoder For This Useful Post: | kerrywez (15-02-11) |
|
|
#7 (permalink) | |
|
Member
Join Date: Mar 2010
Posts: 31
Thanks: 6
Thanked 20 Times in 9 Posts
|
Quote:
|
|
|
|
|
| The Following User Says Thank You to CG121 For This Useful Post: | kerrywez (15-02-11) |
|
|
#8 (permalink) |
|
Grumpy Old Sat Man
Join Date: Sep 2007
Location: Co. Kerry, Ireland
Posts: 2,471
Thanks: 2,973
Thanked 639 Times in 505 Posts
|
Both N1 and N2 were hacked and and we had a great run with them, but there will never be a hack for N3, just my opinion. You guys on the cable side have got to remember that the best have been trying for some 2 1/2 or 3 years now and they have got nowhere so what makes the OP think that something as old as the rubbish he has posted, will have any relevance to N3? It was the Spanish and Portuguese who cracked N1 and N2, so take a hint and go look in those countries for a hack, when you find one come back with something that is at least from the last 1 to 3 years then I might take notice.
Regards Wez
__________________
Dreambox 7025, 250HDD, Dreambox 500s, 110 X 90Cm Hirschmann on Clarketech rotor, 1.2 Mtr. Channel Master. AZBox HD Running on E2. TM6900 super combo. |
|
|
|
|
|
#9 (permalink) | |
|
Senior Member
Join Date: Feb 2007
Location: Belfast
Posts: 347
Thanks: 23
Thanked 56 Times in 50 Posts
|
Quote:
OLd posts they maybe but everything has relevance if you to begin to understand the updated Nagravision encryption. SO as you call Nagra1 and 2 are both a good place to start especially for those looking to card share and begin to understand the pairing process. Once they understand how things work they they will have a fair idea of the information they need and how to get that. And for the spanish and portuguese lot while it wouldn't have all been possible if they get help from another company who had their own vested interests. p.s The whole cable sat thing gets a bit boring after a while. Perhaps you could even say the sat crew aren't as good as they thought they were given the time they have had. But then again I would be talking rubbish, am I? tt |
|
|
|
|
| The Following User Says Thank You to timetrex For This Useful Post: | PerryCox (16-02-11) |
|
|
#10 (permalink) |
|
28:2e:29:28:2e:29
Join Date: Mar 2009
Posts: 502
Thanks: 111
Thanked 202 Times in 139 Posts
|
If I could, I'd thank you twice for that post.
It's so annoying the way questions on here get shot down. "It can't be done" "What do you want to know for, you can't do it" "Accept that it's not going to get hacked" "Don't ask questions" "Sat couldn't do it so cable can't" "You're talking **** and you're a moron" (Ok, maybe not quite that, but not far off sometimes). Not many on techwatch have any kind of hacking skills, and not many are interested beyond getting immediate free TV - but when there is a bit of technical debate going on, the uninterested are the first ones in to shoot someone down. So what if someone asks about how ITVDig "gold cards" were programmed. Yes it's old, yes it's no longer about, yes, no providers use it. That doesn't mean the person asking, or anyone reading, won't learn something. So what if someone asks about something you don't believe can be done - your opinion is worth the square root of feck all in a technical debate. If someone posts a question which you can't see the relevance of, please don't jump in with a post to question their motives/mock them. Just wait, and see if someone more knowledgeable answers. I haven't worded myself very well, but I hope my meaning is understood. To recklessly butcher and old saying, if you haven't got anything constructive to add, don't post anything. |
|
|
|
| The Following User Says Thank You to PerryCox For This Useful Post: | mikie64 (16-02-11) |
![]() |
| Bookmarks |
| Thread Tools | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| clarity tv code | chris31560 | Home Media | 0 | 18-10-10 02:34 PM |
| Ps3 mods | remote matt | Sony Playstation | 162 | 10-10-10 05:54 PM |
| unlock code Samsung mobile phone - C3050 | portmadic2 | Mobile Phones | 0 | 18-08-10 09:38 PM |
| Ofcom file-sharing code not up to scratch says ORG | Internet News | Internet | 0 | 22-07-10 06:10 PM |
| code to open SV box? | carraig | Starview | 4 | 04-06-10 09:55 AM |
| LinkBack |
LinkBack URL |
About LinkBacks |
| Bookmark & Share |
Digg this Thread! |
Add Thread to del.icio.us |
Bookmark in Technorati |
Tweet this thread |
