Hacking CA system challenge *Tandberg [ NO Keys Allowed in Chat Section/s ]*

dale_para_bajo

Well Known Member
Messages
646
I know that one of the forces here is that this thread all ready morph from learning and discovery to give me the keys to view tv. But in conclusion, that I know there is no solution for transponders in America. And now that they know it will be more harder to find that 0x83.

...-Off-topic-
I was wondering why you got so negative responses to your "slow learners" thread, now I know.
-Off-topic-

Just put your self in my situation. Time after time after time insinuations or plain clear comments are given or used against you. So you defend 1, 2 ,3 and I guess that is OK. But it gets to a point when you will not tolerate that! Now the sad part is that this come from recognized and admired members of this forum. That's make one look real bad. But I know and I hope we can move on. You already are treating me as another member of the forum. Right. I will try to learn and find a twick. If I get any info please be sure I will share with you all. But If I do not, do understand that failure is an option.

...I used transedit ...

... transedit have a tool called analyze ts file and with that you can record again choice pids you want to record etc....

At last a nice tool, very appreciated.


Now, Can I get this pleaseeeeeeeee
Code:
PID: 515h Crypt8:7C 90 54 33 D2 AB 0D 4E  [E] Count:2

PID: 521h Crypt8:B6 10 6E B4 CF 95 F8 9E  [O] Count:99
PID: 521h Crypt8:05 75 45 F3 7A BD 3F F6  [E] Count:90

Listen guys I am not s7up1d. I am not looking for the cw to watch that channel! As colibri already posted the needed ECM KEY.

And even we ALL know all the available cws

Code:
[B][COLOR="Red"]KEYS NOT ALLOWED IN CHAT Section/s[/COLOR][/B]

So you can be sure I do not need any precious TEMPORARY (they lasted only 10sec and are gone) cws, they are in the open.

But I need to understand how crypt8 relates to cw and most important to match a Clear vs Encrypted pair of CW.

Can some one help me with that? Please.


PD.
Listen for this example WE - ALL do know all the crypted vs Clear cw pairs. We do have the ECM Key to do that. SO please do not tell me that. But under NORMAL circumstances like in America that is exactly what we do not know and looking!
 

abra26

Senior Member
Messages
263
But I need to understand how crypt8 relates to cw and most important to match a Clear vs Encrypted pair of CW.

Example:

ECM Key for decrypting:
T 2706 01 D22DxxxxxxxxB200

Encrypted ECM log:
80 7018 EE 16 00002706 DBB9AF8B558369C6 1103DC6B18ECAC85 7363 010100

...where red parts are encrypted CW keys.

If we decrypt encrypted CW key with ECM key (D22D...B2) via DEC (ECB) in CrypTool software, we will get decrypted CW key which we can find via CSA Rainbow Table Tool.

If we encrypt decrypted CW key with ECM key (D22D...B2) via DEC (ECB) in CrypTool software, we will get encrypted CW key which we can find in encrypted ECM log.

 

dale_para_bajo

Well Known Member
Messages
646
abrakadabra26

You get the Idea, only that we do not know the ECM Key. If we do there is no need to bruteforce. What you show is the method when we know ECM Key.

Or are you saying that you know the ECM Key for Carracol? If you do please send me the PM to test it.
 

dale_para_bajo

Well Known Member
Messages
646
Transedit is a real winner. Thanks okidokios Below is the detail instructions for a Newbie like me. This allow us to have a very small piece of video with clear cw that we can watch. And its matching encrypted video that we can then use for brute-force. This is a resume of all what has been said without my interruptions. Sorry for those.

I know, this is basic stuff nothing new to the BISS project guys. But for the most part is all new to me.

1-Using DVBDream record FULL TS using Module TSWriter2, Simple Menu>Modules>TSWriter2 then select where to save and hit Record. I did 12 seconds.
Posted file at: http://www78.zippyshare.com/v/q4hOyKhe/file.html. File name is: FTS-Caracol_Alterno_3785_H_5200_20160702_2033_VPID_301.ts. As many has noted this contains 2 channels.

2-Use CSA-Rainbow-Table-Tool posted here results. And thanks to MaRwAn26 we received the resulted cws.
STOP IGNORING FORUM RULEZ
NO KEYS ALLOWED IN CHAT Section/s !

*Note: Please moderators accept this as a key exception as this are in fact unuseful temporary 10 sec expired keys that for the most part worth nothing.


3-Now we use Transedit. Thanks okidokios We use Transedit to create a Single Channel Video Encrypted.

a) Open Transedit. Go to Menu>Analyzer> And in output Directory browse to where you have the original file:
FTS-Caracol_Alterno_3785_H_5200_20160702_2033_VPID_301.ts.

Let say C:\Caracol_Test\ FTS-Caracol_Alterno_3785_H_5200_20160702_2033_VPID_301.ts

b) Hit [Save][Close]
c) Now Press F10 or go to Menu>Scan>Analyze TS File
d) Navigate to your File
C:\Caracol_Test\ FTS-Caracol_Alterno_3785_H_5200_20160702_2033_VPID_301.ts
e) Let it run for the 12 seconds it last. TS Analyzer will Populate with info gathered while running.
f) Now lets select what we want to record. I will select Channel/Sid 2 as it is lower resolution. To do this I look in the left Side of TS_Analizer.

1) Now Expand PAT PID = 0, You will see Service ID 1 & 2.
2) Click over “ServiceID = 2 Caracol Alterno” It Change to Brown
3) Now Right-Click and choose “Select Pids”. You will notice that in the Right Side All PIDs Associated to 1 single Channel gets Selected and change color to Brown. Nice.
4) Now You will Notice At the bottom that [Start Recording] button can be selected!
5) Hit [Start Recording]. Now at this time your 12 second play are stopped so hitting the [Start Recording] do in fact nothing. For that we need now to Hit [Restart]. You will notice the file replay and ts gets populated as before. Let the 12 seconds pass.
6) Hit [Stop Recording]. Now look in the C:\Caracol_Test folder. There we have it a new record with only the Pids associated to that channel. Niceeeeee!.

C:\Caracol_Test\FTS-Caracol_Alterno_3785_H_5200_20160702_2033_VPID_301 07-06 01-25-46.ts. This file is only 4megs compare to the original 12Megs.
4-Now we use ModySat or tsdec same program.
a) First we prepare our require cw file. Go to C:\Caracol_Test and now Open NotePad and copy and past the required cws for that small 12 sec record.

C&P
Code:
[B][COLOR="Red"]NO KEYS Allowed in Chat Sections ![/COLOR][/B]

Now if you see this are the last 2 cw MaRwAn26 posted for us. Only 2 because it only 1 channel. The first Byte 00 means Even 01 mean ODD.

Save as C:\Caracol_Test\ModySat.cwl

b) Open ModySat
c) On Top Dropdown Select and navigate to:

C:\Caracol_Test\FTS-Caracol_Alterno_3785_H_5200_20160702_2033_VPID_301 07-06 01-25-46.ts.

d) On the Bottom Dropdown Select and navigate to:
C:\Caracol_Test\ModySat.cwl

e) Hit Decrypt. As result you end up with:

C:\Caracol_Test\FTS-Caracol_Alterno_3785_H_5200_20160702_2033_VPID_301 07-06 01-25-46_decrypted.ts

f) Now you can play the file. In my case it play for 8 seconds. Nice.

Conclusion Up to here We have obtain a smaller unencrypted file that prove that our Clear CW works. And we have a smaller TS that seems to contain a encrypted 8 seconds and even wen I have not look at the ECM contained in the encrypted file Transedit, yes you can then go back to Transedit, show that the file contains both the ECM and EMMs. I expect that the EMMS contains have not much info as to short of a record but we only need the ECMs. Hopefully I can work with that.

Before Full TS Video

By9j2uC.jpg


After Decrypted 1 Channel Video

71M7YCq.jpg


So Thanks to all that had help. Please see that I admired all of you just give me the time to show I can probe useful.
 

dale_para_bajo

Well Known Member
Messages
646
Now when I did do the Mody-Sat I got:
Code:
"C:\Caracol_Test\ModySat.cwl": 2 lines, 2 cws loaded.
writing decrypted stream to C:\Caracol_Test\FTS-Caracol_Alterno_3785_H_5200_20160702_2033_VPID_301 07-06 01-25-46_decrypted.ts
trying to sync...
sync at packet 37. using CW #0 "0 0D 9F 61 0D 72 A8 0A 24"
packet 18324. using CW #1 "1 [b]33 7C 87 36 EF D3 FF C1[b]"
no more CWs available for decryption! CWL file too short?

If you see program seems to use 1rst CW to sync. The uses nest CW to decrypt and next. But as we have only 2, then it decrypted what was left of 2nd cw. Now Second cw is "1 33 7C 87 36 EF D3 FF C1" and 1 means ODD.

Now using transedit againg I then select ECM pid ONLY and Record again. I get a File of 6K only. Editing with Hex_Workshop_v6.0.1 and C&P as Hex to a Notepad I get 29 lines of:
47 43 86 19 00 80 70 18 EE 16 00 00 00 0C 3E 01 A0 CA BB 97 8A FF B1 22 8E 7B 22 EC E2 FE 57 E3

So using colibri's posted info 1rst one is the odd. So I will expect that encrypted
3E 01 A0 CA BB 97 8A FF
is 33 7C 87 36 EF D3 FF C1

Now the previous "0D 9F 61 0D 72 A8 0A 24" cw not use is the past.

I been said that ECM carry the current CW and the Future CW. So I will expect that encrypted CW B1 22 8E 7B 22 EC E2 FE is NOT equal Clear CW "0D 9F 61 0D 72 A8 0A 24".

So I really need to go back and look in the original 2 channel File for the previous ECM in order to have Both CW in a single ECM!.
 

dale_para_bajo

Well Known Member
Messages
646
So I think my last deduction was wrong!!

It do say:
using CW #0 "0 0D 9F 61 0D 72 A8 0A 24"
using CW #1 "1 33 7C 87 36 EF D3 FF C1"

So it is using two cw! What I think is confusing me is that I do not see extra video from last cw. My best explanation is that the limited amount of ts data was not enoght to provide extra video!. Just an Idea.

Looking at the Full ECM Log I have:

29
47 43 86 19 00 80 70 18 EE 16 00 00 00 0C 3E 01 A0 CA BB 97 8A FF B1 22 8E 7B 22 EC E2 FE 57 E3

Pluss 5
47 43 86 1D 00 81 70 18 EE 16 00 00 00 0C 3E 01 A0 CA BB 97 8A FF 15 1B 38 66 59 B1 AB 42 0C C2

So my best guess now is that encrypted
B1 22 8E 7B 22 EC E2 FE is 0D 9F 61 0D 72 A8 0A 24
3E 01 A0 CA BB 97 8A FF is 33 7C 87 36 EF D3 FF C1

Any Ideas or corrections?
 
Last edited:

gotya

Moderator
Messages
7,200
SU people! Please can anybody help to tune wimbledon feed with tandberg encryption? I would be grateful :)

Screehshot: http://f3.s.qip.ru/GSrg86Zb.png

7e 12726V30000
Code:
D22D9D72FBB4B200

the reason why it's black screen because you have the wrong ECM Key

the right key is this
T 2705 01 3AXXXXXXXXXXEC00 ;

just download my latest updated v_key.db and replace it with the one you have in vplug folder
ie: C:\dvbdream\Plugins\pip00\vplug

here is the latest update
http://www.sat-universe.com/showpost.php?p=2036683963&postcount=4

Cheers !!!
 

ViaHussun

Donating Member
Messages
4,098
@ dale_para_bajo see please

42E 12468 H 9580 DVB-S2 8PSK MPEG4
Nat Geo Wild HD

500 mb record

http://s2.dosya.tc/server2/da2udd/debug.rar.html


File length: 508 MByte
UsingFileLen: 532762108 bytes
Reading file ...
Searching ...
Using payload size: 184
PID: B91h B8h-Crypt8:3B 4C 7B 14 6A 8F BB DB [E] Count:1068
PID: B91h B8h-Crypt8:61 F6 BF B1 9A D2 AC AF [E] Count:560

Time for searching Crypt8 = 1 sec.


You control please
Thanks :)
 
Last edited:

fiji

Well Known Member
Messages
1,098
@ dale_para_bajo see please
42E 12468 H 9580 DVB-S2 8PSK MPEG4
Nat Geo Wild HD

500 mb record

http://s2.dosya.tc/server2/da2udd/debug.rar.html
File length: 508 MByte
UsingFileLen: 532762108 bytes
Reading file ...
Searching ...
Using payload size: 184
PID: B91h B8h-Crypt8:3B 4C 7B 14 6A 8F BB DB [E] Count:1068
PID: B91h B8h-Crypt8:61 F6 BF B1 9A D2 AC AF [E] Count:560
Time for searching Crypt8 = 1 sec.

You control please
Thanks :)
- Need EMM-Keys For Regular Run This Channel

Here Is Program Said too short? CWs [ ECM-Keys ]



Provided CW For 5 To 10 Second
 
Last edited:

gotya

Moderator
Messages
7,200
@ dale_para_bajo

today I learnt something new from you that I could select all the pids package of one channel from TransEdit tool and save it as a single encrypted ts file so I can watch the picture so clearly with my discovered CWs from my CSA-Rainbow-Table-Tool

yes I know how to inject the keys in *.cwl and I was succeeded to watch your 12 sec ts file but the video was glitchy and thanks to okidokios who warned us about the 2 video pids which we missed

and thanks to mauricelugher for confirming that the Offline decrypting works well with modySat.

finally this is the other output *.ts file that created from FTS-Caracol_Alterno_3785_H_5200_20160702_2033_VPID_301 07-06 15-36-39.ts and I did changed the VPID to 201 which is PID 00C9 HEX for the other VPID and become FTS-Caracol_Alterno_3785_H_5200_20160702_2033_VPID_201 07-06 16-30-25.ts

and I did use these Cws I found from this post here http://www.sat-universe.com/showpost.php?p=2036685092&postcount=564

and I put them in the *.cwl file of Modysat tool or tsdec tool

Code:
PID:  [B]C9h[/B] 
C3 66 38 C6 5D 49 5D 03  #CW:93 XX XX XX XX XX XX 6D   #[E] PID:00C9h
57 D9 F7 25 5F AC E5 6B  #CW:80 XX XX XX XX XX XX 89   #[O] PID:00C9h

after decryption a new *.ts file was created and named as
FTS-Caracol_Alterno_3785_H_5200_20160702_2033_VPID_201 07-06 16-30-25_decrypted.ts

here's the picture of it :thum:
 
Last edited:

snowbars

Registered
Messages
22

dale_para_bajo

Well Known Member
Messages
646
Wao busy morning. Lets start

1) @ViaHussun and possible many more in the future.

Please Note that we have no BruteForce implementation that we can use to do the requested action. So no need to PM or send request as we CAN NOT do anything yet.

We are, or at least I am trying to figure out the method and the time may take to bruteforce. But we have nothing. Only we did is to create a method as to match or pair: Encrypted VS Clear CWs.

*So next we Build our 1rst prototype brute force.
**Then we time how long it takes to Crypt/decrypt 8bytes.
***Then finally theoretically we calculate how long it will take to do full range. That will be the maximum time it will take, like for ever! hehehehe

2) @MaRwAn26

You see master, trust a little in me, give me time we will get there. We all learn with this.

And people there is nothing new in what I posted. There all existing tools that we all used. It is only a resume of the step in one place.

But guys okidokios suggestion of transedit is a hit. I TOTALLY forgot about that one. But Many thanks to all that have posted.


3) Now this makes me feel SAD.
Code:
[B][COLOR="Red"]NO KEYS Allowed in Chat Sections ![/COLOR][/B]

Code:
[B][COLOR="Red"]STOP IGNORING FORUM RULEZ
NO KEYS ALLOWED IN CHAT Section/s ![/COLOR][/B]

I am a person that really try to follow all forum rules where I go. And try to respect all moderators. But I want you to defend my self yes another time. Please note that I said:
Code:
*Note: Please moderators accept this as a key exception as this are in fact unuseful temporary 10 sec expired keys that for the most part worth nothing.

Listen the LAW has to be follow, But a Judge has to use his intellect to know when to made an exception. So they do, they send a Bad guy 10 years to prison for the same crime they send 6 moth to house arrest to a kid that was cut innocently in a situation.

Now imagine that I write this numbers:
Code:
00 00 00 00 00 00 00 00
or 
00 01 02 03 04 05 06 07

Nothing wrong with that, right. All Rules are follow. Now I tell you those are ECM Keys for my imaginary X-Tv program. Now suddenly It is a violation. But for same act.

But you judges have to use your intellect as to know what situation applies here.

We all agree that there is a key area for easy search of all those. And we are starting to post using text as to prevent easy google search for those keys in our intent to prevent this keys to proliferate on other pages. Or to even prevent an operator to find out easily that his key has been breach.

Wao All that I agree and are very happy with its implementation.

But as a judge you have to see that my "imaginary X-Tv program" does not fit that description. There is no need for that key as the TV-program does not exist!

Now the keys Y post ALL are Expired 10 sec cw changing keys that for the most part will NEVER be used again. Will those meet your description.

Most important all those keys are posted at the beginning of this thread by other members. Yes they are not mine they are C&P. And they are in the open without any STOP IGNORING FORUM RULEZ NO KEYS ALLOWED IN CHAT Section/s ! .

So an even when I think rules do not apply to changing cw's as they are unuseful. I respectful ask for a waver as placing the keys where I did will make the Tutorial I post Easy to follow. Now a slow learner like me my get confused as to where he will be searching for those.

But I know instead of recognizing that I may be ok, I will get another high rank member of the forum upset, and more to follow. Sad situation I am.
 

gotya

Moderator
Messages
7,200
So I think my last deduction was wrong!!

It do say:

using CW #0 "0 0D XX XX XX XX XX XX 24"
using CW #1 "1 33 XX XX XX XX XX XX C1"

So it is using two cw! What I think is confusing me is that I do not see extra video from last cw. My best explanation is that the limited amount of ts data was not enoght to provide extra video!. Just an Idea.

Looking at the Full ECM Log I have:

29
47 43 86 19 00 80 70 18 EE 16 00 00 00 0C 3E 01 A0 CA BB 97 8A FF B1 22 8E 7B 22 EC E2 FE 57 E3

Pluss 5
47 43 86 1D 00 81 70 18 EE 16 00 00 00 0C 3E 01 A0 CA BB 97 8A FF 15 1B 38 66 59 B1 AB 42 0C C2

So my best guess now is that encrypted
B1 22 8E 7B 22 EC E2 FE is 0D XX XX XX XX XX XX 24
3E 01 A0 CA BB 97 8A FF is 33 XX XX XX XX XX XX C1

Any Ideas or corrections?

i will start over to let others follow

I used TransEdit tool to create a new *.ts file that has it's own pids separated from the original posted *.ts file http://www78.zippyshare.com/v/q4hOyKhe/file.html

this is the other ECM for the other channel Vpid { pid 201 Dec / C9 Hex } taking from Hex_Workshop application

47 43 85 1E 00 80 70 18 EE 16 00 00 00 0B 1E 4A E7 F9 A4 F9 CC 33 6B 76 B5 5C F2 41 CE 16 96 08
ECM_for_Caracol_Alterno_3785_H_5200.jpg


according to Colibri.DVB these mean
Code:
47 43 85 1E: TS header
00: Offset
80: Table ID
70 18: & 0x0FFF -> Section length
EE: Tag ECM_TAG_CW_DESCRIPTOR
16: Length
00 00 00 0B: Entitlement ID
1E 4A E7 F9 A4 F9 CC 33: encrypted CW
6B 76 B5 5C F2 41 CE 16: encrypted CW
96 08: Checksum

after using the Modysat tool or tsdec tool and I decrypt the ts file with the CW keys I got and posted here http://www.sat-universe.com/showpost.php?p=2036685092&postcount=564

trying to sync...
sync at packet 56. using CW #0 "0 93 XX XX XX XX XX XX 6D"
packet 26931. using CW #1 "1 80 XX XX XX XX XX XX 89"
no more CWs available for decryption! CWL file too short?

so I guess the odd CW is in use

does it mean then that these encrypted CW matches with these CW keys
1E 4A E7 F9 A4 F9 CC 33 = 80 XX XX XX XX XX XX 89
6B 76 B5 5C F2 41 CE 16 = 93 XX XX XX XX XX XX 6D

Is it right ?? :confused:
 
Last edited:
Top