Hacking CA system challenge *Tandberg [ NO Keys Allowed in Chat Section/s ]*

O

ooOO_SORGOS_OOoo

We know index 62 and Index 63 keyset 2 value but
I think poc exe can not find ecm keys and

I think new tandberg vmodule can not update emm keys with ecm keys
Thank you @Anubis_IR
 

Anubis_Ir

Senior Member
Messages
370
I see emmkey when use my ts file.

[Emu] GetEMMKey: key_index(66), keySet: 2
emmKey:
26 3E 76 9E 6B 16 C7 A7
It's a 2 step operation:
- Step 1: `[Emu] nano 0xE4, mode 1` sets the RAM keys.
- Step 2: `[Emu] nano 0xE1, mode 1` uses one of these RAM keys to produce the final ECM key.

You have only step-1.
 

kebien

Well Known Member
Messages
1,329
So,going by the new keys posted and the logs it looks like they are updating keys using same entitlement ID?
 

Anubis_Ir

Senior Member
Messages
370
I've updated the `poc` to report the new *maybe* keys correctly.
Also its `Raw EMM` mode has been updated to avoid an endless loop.

Tip:
- You can record a raw emm log file (not a large full .ts file) and then analyze it with poc this way:
Code:
> poc.exe EmmFileName.Bin
- To record a raw emm log file with vPlug:
- Select the `AutoCAT` option.
- Highlight the EMM-pid in the `CA-Info` section.
- Right click on the selected PID to select the `record selected emm pid` option.
 

fiji

Well Known Member
Messages
1,098
I tested new poc and new keys. But keys not correctly on 42e fox networks.

Same Here Got Only EMM Keys No ECM Keys With New POC Mod2
Code:
[Emu] got EMM nano tag E4 (EMM_TAG_SECURITY_TABLE_DESCRIPTOR) for the first time
[Emu] nano 0xE4, mode 1
[Emu] GetEMMKey: key_index(64), keySet: 2
emmKey:
[COLOR="Magenta"]B3 XX XX XX XX XX XX XX[/COLOR] 
[Emu] Keys found in EMM: new nano E4 ram keys 20 to 2F
emm:
82 70 B4 01 DE 1D 82 01 33 0C DA 02 08 00 20 D7 
E3 F0 2C E0 2A FF 01 00 00 40 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 
DE 1D 82 01 66 28 91 02 08 00 20 26 63 F0 2C E0 
2A FF 01 00 00 20 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 01 DE 1D 82 01 
BA 15 91 02 08 00 20 99 63 F0 2C E0 2A FF 01 00 
00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00
 

fiji

Well Known Member
Messages
1,098
PID 13110

Here Test ts File Turksat42E Fox Network

FOX LIFE HD PID : 13110

[Emu] active entitlement: C9

For Searching Save This Line In .bat File
Code:
Poc 2.ts 13110 out.ts

Full Transponder Download
 
Last edited:

Anubis_Ir

Senior Member
Messages
370
@fiji
Try the `raw emm` mode, instead of full .ts mode. in this case, you can record a one hour log (which is not too large) and then analyze it (don't record .ts files anymore. record an emm.bin file for about an hour).
 

vladan !!

Senior Member
Messages
197
i have try this after 500000kb on NAT GEO HD
with the last tanberg + poc from anubis
BUT DONT WORK
EMM after :
82 70 B4 01 DE 1D 82 01 24 11 DA 02 08 00 20 FE
76 F0 2C E0 2A FF 01 00 00 10 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01
DE 1D 82 01 24 77 DA 02 08 00 20 24 76 F0 2C E0
2A FF 01 00 00 80 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 01 DE 1D 82 01
40 7B DA 02 08 00 20 7A EA F0 2C E0 2A FF 01 00
00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00
EMM before :
82 70 92 00 6A E3 7E F0 8C E4 8A 01 FE 39 76 B1
A5 4A 80 0A 31 12 4B AC 16 F4 FC FD 47 04 15 FA
12 19 31 8B 3E 24 E4 CE 64 53 BA F2 41 54 87 37
10 EA 95 DC 31 EE 8A 5C 6A C9 3E 50 57 FC 5B B0
2A 7F 74 0B 5A 61 C9 61 03 36 93 73 D6 B5 2A A7
E7 4A 47 DF 11 B1 46 04 4F 44 EA 83 3D CA 5F 5F
9C 0A 70 7E D6 66 5A FC FE FE 1A FB 12 60 64 C4
57 3F 7C 6E D2 BE 64 8D 92 09 D0 65 B0 EF 5D 2F
85 11 11 82 A4 99 87 DD 56 F3 24 ED 8D 1D D4 56
8E B1 C7 F7 A9
[Emu] got EMM nano tag E4 (EMM_TAG_SECURITY_TABLE_DESCRIPTOR) for the first time
[Emu] nano 0xE4, mode 1
[Emu] GetEMMKey: key_index(6A), keySet: 2
emmKey:
F2 XX XX XX XX XX XX BF
[Emu] Keys found in EMM: new nano E4 ram keys 20 to 2F
 
Top