BK&RSA

Status
Not open for further replies.

sambas33

Registered
Messages
37
Flash encrypted AES 128bits key, good luck its all i can say to you...


also quick note......



bye....
something like?!
KLAD Algo : 3DES
K3 : D4 0E 2B 70 74 ED 8C 1D 39 82 AB D6 AB 73 61 8F
EK2 : BE F9 B0 67 13 B8 BC 87 BC FB B2 69 13 BA BE 8B
K2 : 46 B9 69 51 D9 9C 7F 86 CE CF AE 1F 71 0E D9 91
EK1 : 0F 09 A2 06 19 88 B6 89 28 EB 90 2E B2 36 18 88
K1 : 79 0F BA 2F 80 52 9A 96 0D FB 4C FF 05 BA 04 F9
 

n3bk

Registered
Messages
34
something like?!
KLAD Algo : 3DES
K3 : D4 0E 2B 70 74 ED 8C 1D 39 82 AB D6 AB 73 61 8F
EK2 : BE F9 B0 67 13 B8 BC 87 BC FB B2 69 13 BA BE 8B
K2 : 46 B9 69 51 D9 9C 7F 86 CE CF AE 1F 71 0E D9 91
EK1 : 0F 09 A2 06 19 88 B6 89 28 EB 90 2E B2 36 18 88
K1 : 79 0F BA 2F 80 52 9A 96 0D FB 4C FF 05 BA 04 F9


wrong that is standar keyllader mode from public pdf file online , CAS providers use custom data added so not 100% the same


http://www.etsi.org/deliver/etsi_TS/103100_103199/103162/01.01.01_60/ts_103162v010101p.pdf
 

4th_gen

Registered
Messages
6
No big deal

506163655F445843353030304B4E425F3134313033303130 = Pace_DXC5000KNB_14103010

NETvirtua Brasil cable prov, flash encrypted AES with cpu key, bye bye 016c decryption block ;) good luck and good studies :D on secret provider

It already getting done and shared by someone in spain he does loads of peoples rsa key he is also now doing the encrypted versions.(for a price of course from the bga24 chips. so it can be done
 

Onsitbin

Registered
Messages
18

# binwalk flash.bin

DECIMAL HEXADECIMAL DESCRIPTION
--------------------------------------------------------------------------------
29 0x1D Zlib compressed data, default compression
10703383 0xA35217 Unix path: /hdd0apps/crash_logs/daily_logs/log%02d.txt
11522584 0xAFD218 JPEG image data, JFIF standard 1.01
11522614 0xAFD236 TIFF image data, little-endian offset of first image directory: 8
11523100 0xAFD41C Copyright string: "Copyright (c) 1998 Hewlett-Packard Company"
11857776 0xB4EF70 JPEG image data, JFIF standard 1.01
12124720 0xB90230 JPEG image data, JFIF standard 1.01
12389688 0xBD0D38 JPEG image data, JFIF standard 1.01
12644676 0xC0F144 JPEG image data, JFIF standard 1.01
12897664 0xC4CD80 JPEG image data, JFIF standard 1.01
12897694 0xC4CD9E TIFF image data, little-endian offset of first image directory: 8
12898198 0xC4CF96 Copyright string: "Copyright (c) 1998 Hewlett-Packard Company"
13117068 0xC8268C JPEG image data, JFIF standard 1.01
13324352 0xCB5040 JPEG image data, JFIF standard 1.01
13324382 0xCB505E TIFF image data, little-endian offset of first image directory: 8
13324868 0xCB5244 Copyright string: "Copyright (c) 1998 Hewlett-Packard Company"
13518552 0xCE46D8 JPEG image data, JFIF standard 1.01
13555724 0xCED80C JPEG image data, JFIF standard 1.01
13584429 0xCF482D JPEG image data, JFIF standard 1.01
13588428 0xCF57CC JPEG image data, JFIF standard 1.01
13611741 0xCFB2DD JPEG image data, JFIF standard 1.01
13611771 0xCFB2FB TIFF image data, little-endian offset of first image directory: 8
13629816 0xCFF978 JPEG image data, JFIF standard 1.01
13829784 0xD30698 Unix path: /hdd0apps/crash_logs/daily_logs/log%02d.txt
29386816 0x1C06840 Copyright string: "Copyright 1984-2004 Wind River Systems, Inc."
29387025 0x1C06911 Zlib compressed data, default compression


A raw copy of the flash chip data from the chip; every 2 bytes are swapped.
A raw copy of the flash chip data, with the swapped bytes corrected.The main RTOS firmware image, as extracted from flash.bin
An IDA database file containing the disassembly work performed thusfar.
An IDAPython script to rename the symbols/functions found in the RTOS symbol table.


hxxxs://mega.co.nz/#!fJgBjCZa!t0aqF_vRB8P2dTxklPq7ww5YHOphBbBJSTuOi3oj6P0


Flash.bin extracted :D:D:D:D:D:D
Dank crzyfngrz
 

hdev134

Registered
Messages
3
Change * To * hex after rsa not work oscam

000060600103010043C5C4540002A70BC3E3095A4BFC1ADC2869D557FFFCA699719966B53CEC01C10EB0C75DB50220832FA0A7B2C0A759DEF67B0D97A3AC2B2F5F7C1CC429F98BF830DA432023B70000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000*100000020001*0000
 

mtssouza

Registered
Messages
1
Good Afternoon!

I have a flash memory dump BGA, the PACE HDC 74x1 , and must draw Boxkey and RSAKEY could help me ?

I'm from Brazil
 
Status
Not open for further replies.
Top