Hacking CA system challenge *Tandberg [ NO Keys Allowed in Chat Section/s ]*

barney115

Donating Member
Staff member
Administrator
Messages
24,827
3946 v 7120 Asiasat 5 Tandberg

AESkey found more internet before have feed test Tandberg v3, 20AESkey will not work 1000%
Thank you i just hope some working AES keys can be leaked or found again or possibly can extract this AES Keys somehow like previous times with poc.exe tool :confused:
 

harshy

Well Known Member
Messages
746
Only way to make this work is to bypass the aes keys but I think that’s not even possible this upgrade too reliant on AES Keys
 

barney115

Donating Member
Staff member
Administrator
Messages
24,827
no problem with Ecm key 84
but Big Problem is AES Key 100% right @ campag5242
Nothing i try so far has worked it really is down to working AES Key missing .
the list @ Anubis_IR gave us already expired !
 

Wilb

Registered
Messages
24
It wouldn't surprise me if there were 38 sets of keys issued, one before each round of fixtures.

Sent from my MI 5 using Tapatalk
 

harshy

Well Known Member
Messages
746
no problem with Ecm key 84
but Big Problem is AES Key 100% right @ campag5242
Nothing i try so far has worked it really is down to working AES Key missing .
the list @ Anubis_IR gave us already expired !

I dont even understood where those AES keys came from in the first place, was that in the extracted firmware, either way we are screwed theres no hope im afraid.:mecry:
 
C

campag5242

Hi vtcc. What's the length of the key written in the xml file? It may be padded with checksums, may or may not be plaintext etc. I've kinda given up testing ideas there, not knowing whether I had a valid key to start with...
 

Wilb

Registered
Messages
24
Only options I see are someone leaks the keys every week or some big GPU instances brute forcing the keys every time they're rotated. The former seems unlikely and the latter is probably impossible due to the size of the keyspace, frequency of the rotation and the sporadic availability of test material to brute against.

Sent from my MI 5 using Tapatalk
 
C

campag5242

I think it’s aes keys per match for the muxx feeds, weekly updates for the core feed.
Look at the dates & filenames in the webif capture: it's one bundle of 32 keys per week, generated on a Tuesday, hitting the box usually on a Friday or early hours Saturday, just in time for the day's events.

So yes, enough keys for one per match if they feel the need. Not much of a time window for them to be leaked :(

Bit of a hiccup around the weekend of the 23/09/2017... keys didn't hit the box until the following Monday :confused: I guess ASIA should (must) be weekly too, just missing from the log.
 
C

campag5242

Could someone look in their enigma2 webif for that channel's s_ref (Arqiva HD3?) so that I can remotely get my box to zap to it and start logging?
 
Top