Hacking CA system challenge *Tandberg [ NO Keys Allowed in Chat Section/s ]*

DEPORTIVO

Registered
Messages
289
Today I have stupid problem.When I go to IMG3 EU vPlug pull biss key and said to me that is biss crypt for this channel.
:confused:

 

Dave5118

Feed Hunter
Messages
1,147
Today I have stupid problem.When I go to IMG3 EU vPlug pull biss key and said to me that is biss crypt for this channel.
:confused:


Yes, it is BISS most of the time, only use Tandberg when they are transmitting something from Premier League...... or updating firmware ;)
 

barney115

Donating Member
Staff member
Administrator
Messages
24,808
Still on Biss and TEST Card now
Key should change Soon ..
This Biss key is still active as i type => http://www.sat-universe.com/showpost.php?p=2036715048&postcount=480

IMG3_EU_28_10_2016_10_8_28.jpg
 

Ragnarok

Donating Member
Messages
336
i have try this after 500000kb on NAT GEO HD
with the last tanberg + poc from anubis
BUT DONT WORK

you need 82 70 92 emm's to get the Ram keys like
Code:
 82 70 92 00 65 17 E3 F0 8C E4 8A 01 FE 4F A8 42 54 EE 45 CA 2D A2 0B D9 FE 34 62 E8 17 2D A9 B5 B1 A7 E1 2E 24 20 F1 E6 8B F1 4D 4D A9 01 CB CB 79 74 A2 5F 2F 2C CC A0 5C 60 00 2D B3 9F AB 22 F3 29 1F 26 34 3D E2 F0 B3 AB 20 3B 13 E5 98 22 2F DC 42 46 5E 94 E4 FA A0 82 F9 AB 37 99 4B B7 0C B4 4C 03 CD 01 29 CD F0 50 D0 9B 3D 0D 60 63 62 24 FA C2 0B A9 29 04 E1 0C F6 C5 8A F7 0C 50 D9 C3 64 68 94 A9 B2 6F 81 4F 65 EE 9C 89 23 09 00 51 5B 84 D4

You then need 83 70 22 or 83 70 44 emms with the E1 nano which contain the encryped ECM key.

Code:
83 70 22 00 20 14 2C F0 1C E1 1A 00 00 06 91 01 BC D5 EB D0 62 86 EF BB 96 1D xx xx xx xx xx xx xx xx xx xx 

83 70 48 02 EF FF F5 FF FF FF 68 0B 23 04 31 20 1B 1B E2 DF EF 0E 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 B9 63 F0 1C E1 1A 00 00 06 9B 01 58 12 16 38 xx xx xx xx xx xx xx xx xx xx xx xx xx xx xx xx

edited out the encrypted keys.

in order to get these keys if they have changed, if these EMM's are not in the stream, they will have to be brute forced again!
 
Last edited:

vladan !!

Registered
Messages
197
you need 82 70 92 emm's to get the Ram keys like
Code:
 82 70 92 00 65 17 E3 F0 8C E4 8A 01 FE 4F A8 42 54 EE 45 CA 2D A2 0B D9 FE 34 62 E8 17 2D A9 B5 B1 A7 E1 2E 24 20 F1 E6 8B F1 4D 4D A9 01 CB CB 79 74 A2 5F 2F 2C CC A0 5C 60 00 2D B3 9F AB 22 F3 29 1F 26 34 3D E2 F0 B3 AB 20 3B 13 E5 98 22 2F DC 42 46 5E 94 E4 FA A0 82 F9 AB 37 99 4B B7 0C B4 4C 03 CD 01 29 CD F0 50 D0 9B 3D 0D 60 63 62 24 FA C2 0B A9 29 04 E1 0C F6 C5 8A F7 0C 50 D9 C3 64 68 94 A9 B2 6F 81 4F 65 EE 9C 89 23 09 00 51 5B 84 D4

You then need 83 70 22 or 83 70 44 emms with the E1 nano which contain the encryped ECM key.

Code:
83 70 22 00 20 14 2C F0 1C E1 1A 00 00 06 91 01 BC D5 EB D0 62 86 EF BB 96 1D xx xx xx xx xx xx xx xx xx xx 

83 70 48 02 EF FF F5 FF FF FF 68 0B 23 04 31 20 1B 1B E2 DF EF 0E 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 B9 63 F0 1C E1 1A 00 00 06 9B 01 58 12 16 38 xx xx xx xx xx xx xx xx xx xx xx xx xx xx xx xx

edited out the encrypted keys.

in order to get these keys if they have changed, if these EMM's are not in the stream, they will have to be brute forced again!
thanks for the replay !!
the only think to have that is to make rec 24-48 hours to see what going on .
the point is that we dont do nothing , the poc do the job and we talk here what we find , at list from the rec i make on 7E work very fast , let see on weekend whats going to be !!!
 

abed1988

VIP
Messages
5,438
i try poc 1.6 new
with record file ts in arena sport 2 in 39 e

with in file " run.bat " this word " Poc 1.ts 464 out.ts "

i have result this :

poc 1.6_mod
TS mode
[Emu] info: FFDecsa parallel mode = 32
[Emu] stream found pmt pid: 8AF
[Emu] stream found emm_pid: 81
[Emu] stream found pcr_pid: 8AD
[Emu] stream found ecm_pid: D19
[Emu] stream found video pid: 8AD
[Emu] stream found audio pid: 8AE
emm:
82 70 B4 01 DE 1D 82 01 BF 4A E1 01 08 00 01 17
E3 F0 2C E0 2A FF 01 00 00 00 10 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01
DE 1D 83 01 05 45 E1 01 08 00 01 28 24 F0 2C E0
2A FF 01 00 00 00 10 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 01 DE 1D 83 01
D5 34 E1 01 08 00 01 61 94 F0 2C E0 2A FF 01 00
00 00 10 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00
[Emu] got EMM nano tag E0 (EMM_TAG_RECEIVER_ALLOCATION_DESCRIPTOR) for the first time
ecm:
80 70 18 EE 16 00 00 00 02 A6 3E 88 3C A8 EB 57
40 F7 CF 14 85 FE 13 0F 11 33 3C
[Emu] active entitlement: 2
emm:
82 70 B4 01 DE 1D 83 01 88 33 E1 01 08 00 01 7D
63 F0 2C E0 2A FF 01 00 00 00 10 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01
DE 1D 83 01 D6 50 E1 01 08 00 01 D7 E3 F0 2C E0
2A FF 01 00 00 00 04 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 01 DE 1D 83 01
C2 4E E1 01 08 00 01 17 E3 F0 2C E0 2A FF 01 00
00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00
emm:
82 70 B4 01 DE 1D 83 01 7C 45 E1 01 08 00 01 EF
63 F0 2C E0 2A FF 01 00 00 00 04 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01
DE 1D 83 01 E9 40 E1 01 08 00 01 3B 0C F0 2C E0
2A FF 01 00 00 00 04 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 01 DE 1D 83 01
7C 1E E1 01 08 00 01 AF 63 F0 2C E0 2A FF 01 00
00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00
emm:
82 70 B4 01 DE 1D 83 01 AC 1C E1 01 08 00 01 BB
63 F0 2C E0 2A FF 01 00 00 00 04 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01
DE 1D 83 01 6D 62 DC 01 08 00 01 D7 E3 F0 2C E0
2A FF 01 00 00 00 02 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 01 DE 1D 83 01
6E 2F E1 01 08 00 01 DB 92 F0 2C E0 2A FF 01 00
00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00
emm:
82 70 8A 00 54 91 2C F0 84 E4 82 FF FC 4C A8 9C
93 7B 82 08 55 D9 51 1D E1 A9 70 AD 0B E2 30 45
DA 50 DB FB F0 C7 61 81 11 E8 30 92 AF C5 03 43
40 B6 7F 30 5D EB 20 FF 22 79 76 97 6D 3B 84 6C
9E D8 95 99 2C 6F 3C 0F F4 CF B6 09 18 98 36 01
85 AF D0 89 E9 66 F7 BA E7 16 82 B4 43 96 1F 60
89 EC DE AC 0A DC F6 61 D6 4D E3 38 BF 17 75 14
7F E0 5D 3D 71 CD 25 9F C4 A5 97 A7 50 13 A9 24
F4 ED 1D D6 14 8C C1 EB 39 F4 2F E4 B1
[Emu] got EMM nano tag E4 (EMM_TAG_SECURITY_TABLE_DESCRIPTOR) for the first time
[Emu] nano 0xE4, mode FF
[Emu] GetEMMKey: key_index(54), keySet: 1
[Emu] Keys found in EMM: new nano E4 ram keys 0 to F
ecm:
80 70 18 EE 16 00 00 00 02 A6 3E 88 3C A8 EB 57
40 F7 CF 14 85 FE 13 0F 11 33 3C
 
O

ooOO_SORGOS_OOoo

i give you error - Errrrrrrrrrrrrr

i dont undertand it

i did try dm 820 hd
my hd tv sat card

i did save .ts video / ram emm log bin

i dont find it

sorry guys

F**k!!! Fox network Gr!!!

 

harshy

Registered
Messages
746
i am sure it took two or so weeks before it even arrived on oscam, hopefully they can fix it quick, i prefer dreamboxs picture over dvbdream anyday.
 

marrakr

Registered
Messages
293
I noticed now that keys for old and upgraded Tandberg can have the same entitlement id but CW is different e.g. for IMG:
there was known key:
T 6AE 01 3XXX0
and now there is active:
T 6AE 01 CXXX0

I guess channels with the same entitlement id and using old and new version of encription may not work at the same time due to this issue.
May this be resolved by any chance? Thx.
 

kebien

Registered
Messages
1,329
I noticed now that keys for old and upgraded Tandberg can have the same entitlement id but CW is different e.g. for IMG:
there was known key:
T 6AE 01 3XXX0
and now there is active:
T 6AE 01 CXXX0

I guess channels with the same entitlement id and using old and new version of encription may not work at the same time due to this issue.
May this be resolved by any chance? Thx.
It should work ok,since the emu should read the encryption tag and know the ECM use new or old algorithm.
 
Top