View Full Version : How to mod your Kickass Clone to unlock dish cards.
lightning0009
09-29-2004, 08:11 PM
Here is how I modded my Kickass Clone H card unlooper so it would be able to unloop dish rom 10 rev a23's. Pull out the max232 chip and bend leg 10 up. Solder the bent up leg to one side of a switch. Solder from underneath the board on leg 10 to the other side of the switch. With the switch closed you can program your atmel, with it open, you can unlock cards. Now take out the 74HC00N chip. Bend legs 4 and 9 up. Solder a wire to leg 4 and run it to leg 18 of the amtel 2313. Now solder a wire to pin 9 of the 74HC00N and run it to pin 9 of the 74HC74AN. Now you can hook one of the outer legs of your 5k pot to pin 7 of the 74HC4053 chip(not the other 74HC4053) that is closest to the atmel 2313 chip. Hook the middle leg of the 5k pot to pin 4 of the same 74HC4053. Ok, you are now done with the mods to the top side of the kickass clone unlooper. On the bottom side, solder a wire from pin 14 of the 2313 atmel to pin 13 of the 74HC00N. Now solder a real short one from pin 9 to pin 12 of the 74HC00N. Now solder a wire from pin 11 of the 74HC00N to pin 11 of the same 74HC4053 chip that you hooked your 5k pot to. I was able to unlock a stream locked rom 10 a23 with switch 4 on.
Executing Script: C:\winexplorer5\Rom10-A23 OPENworks.XVB
TX Data : A0
TX Data : A0
TX Data : A1
TX Data : 07 0E 03 10 01 03 9A 00
RX Data : 06 00
TX Data : 12 15 AB 21 00 08 A0 CA 00 00 02 12 00 06 55 0E
03 85 00
RX Data : 11 00
Now we will try 1252 delay
RESET FFFFFFFFFFFF6F6F6F6FFFFFFFFFFF6FFFFFFFFFFFFF6F6FFF FF RESET FFFFFF6F6F6FFFFFFFFFFFFF6FFF6F6FFFFFFF6FFFFFFFFFFF FFFF6FFFFFFFFFFFFFFF6F6FFFFFFFFFFFFF6FFFFFFF6FFFFF FF6FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF6FFFFFFF6FFFFFFF FFFFFFFFFFFFFFFF6F6FFF6FFFFFFFFF6F6F6FFFFFFFFFFF6F FFFFFFFFFFFFFF6F6F6FFFFFFFFFFFFFFFFFFFFFFFFFFFFF6F FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF6FFFFFFFFFFFFF6F6F6F FFFFFFFFFFFFFFFFFFFFFFFFFF6F6FFFFFFFFFFFFF6F6FFFFF FFFFFFFFFF6FFF6FFFFFFFFFFFFFFFFFFFFFFFFF6F6F6FFFFF FFFFFFFFFFFFFFFFFFFFFF6F6F6FFFFFFFFFFF6FFFFF6FFFFF FFFF6FFFFFFFFFFFFFFFFF6FFFFFFFFFFFFF6FFFFFFFFFFFFF FF6FFFFFFFFFFFFFFF6FFFFFFFFFFFFFFF6FFF6F RESET FFFFFFFF
now we will try 1253 delay
6FFFFFFFFF6FFFFFFF6FFFFFFFFFFFFF6FFFFFFFFFFFFFFFFF 6F6FFF RESET FFFFFF6F6FFFFF6FFFFFFFFF RESET FFFFFFFFFFFF6F6FFFFFFFFFFFFFFF6FFFFFFFFFFFFFFF6FFF FFFF6FFFFF6F6FFFFFFFFFFFFFFFFFFFFFFFFFFFFF RESET 6FFFFFFFFFFFFF6F6FFFFFFFFFFFFF6F6F6FFFFFFFFFFF6FFF FFFFFFFFFFFFFFFF6F6FFFFFFFFFFFFFFFFFFFFFFFFF6FFFFF 6FFFFFFFFF6FFFFFFFFFFFFFFF6F6FFFFFFFFFFFFF6FFF6FFF FFFFFFFFFF6FFFFFFFFFFFFF6FFFFFFFFFFFFFFFFF6FFFFF6F FFFFFFFF6FFFFFFFFFFFFF6FFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFF6FFFFFFFFFFFFFFFFFFFFFFF6FFFFFFFFFFFFFFF 6FFFFFFF6FFFFFFFFF6FFFFFFF6FFFFFFF6FFFFFFFFFFFFF6F FFFFFFFFFFFFFFFF6F6FFFFFFFFFFF
now we will try 1254 delay
6F6FFFFFFFFFFFFF6FFF RESET 6FFFFFFFFF6F6FFF6F6FFFFFFF6FFF6FFFFFFFFFFF6F6F6F6F FFFFFFFF6F6F6F6FFFFFFFFF6FFFFF6FFFFFFFFF6FFF6F6FFF FFFFFF6F6F6FFF6FFFFFFF6F6FFFFFFFFF6FFF6FFFFF6F6FFF FFFF6FFFFFFFFFFFFFFF6FFF6FFFFF6FFFFF6FFF6FFF6FFFFF FF6F6F6FFFFF6FFFFF6F6FFFFF6FFFFFFF6F6FFF6FFFFF6FFF 6F6F6F6F6FFFFFFF6F6FFFFFFF6F6FFFFFFFFFFFFFFF6FFF6F FF6FFF6FFF6FFF6F6F6FFF6FFFFFFF6F6F6F6FFFFFFFFF6F6F 6FFF RESET FFFFFF6F6FFFFF6F6FFFFF6F6FFF6FFF6FFFFF6F6FFFFF6FFF FFFF6FFF6FFF6FFFFFFF6F6F RESET FFFFFFFF6F6FFF6FFFFFFFFFFF6F6FFFFFFFFFFFFF6F6F6FFF FFFFFFFF6F6F6F6FFFFF6FFF6F6F6FFFFFFFFFFF6F6F6F6FFF FFFFFF6FFF6F6FFFFFFFFF6FFFFFFFFFFFFFFF6F6F6FFF6FFF FFFF
now we will try 1255 delay
6F6F6FFFFFFFFFFF6F6FFF6FFFFFFFFFFF6F6FFFFFFFFF6F6F FFFFFFFFFFFFFF6F6F6FFF6FFFFFFF6F6F6FFFFF6FFFFF6F6F FFFF6FFFFFFF6F6F6F6FFFFFFFFF6F6FFFFF6F6FFFFF6FFF6F 6FFF6FFFFF6F6F6F6FFF6FFFFFFF6FFF6F6FFFFFFF6F6F6F RESET FFFFFFFF6F6F6F6FFFFFFFFF6F6F6FFFFFFFFFFF6F6F6F6FFF FFFFFF6F6FFFFF6FFFFFFF6F6FFF6FFFFFFFFF6F6F RESET FF6FFFFFFF6FFFFF6FFFFFFFFF6F6F6F6F6FFFFFFF6F6FFFFF 6FFFFFFF6F6FFFFFFFFFFFFF6FFFFF6FFFFFFFFF6FFF6FFF6F FFFFFF6F6F6FFFFFFFFFFF6FFFFFFF6FFFFFFF6F6F6F6F RESET FFFFFF6F6FFF6FFFFFFFFF6FFF6FFFFFFFFFFF6F6FFFFFFF6F FFFF6F6F6FFFFFFF6FFF6F6FFF6F6FFFFFFF6FFFFFFFFFFFFF FF6F6FFF6FFFFFFFFF6F6F6FFF6FFFFFFF6F6FFF6FFFFFFFFF 6F6FFF RESET FFFFFFFF6F
now we will try 1256 delay
6F6FFFFFFFFFFF6F6FFF6FFFFFFFFF6FFFFFFFFFFFFFFF6F6F FF6F6FFFFFFF6F6FFFFF6FFFFFFF6F6F6F6F6FFFFFFF6F6FFF 6FFFFFFF6F6FFFFFFF6FFFFFFF6FFF RESET 6FFFFFFFFF6F6FFFFFFFFFFFFF6F6FFF6FFFFFFFFF6F6F6F6F 6FFFFFFF6F6F6FFFFFFFFFFF6F6F6FFFFFFFFFFF6F83
*********** we hit our bug *************
1200078303
===========================================
83 was hit at 1256 delay ----VCC WAS 19
TX Data : 0A 15 A3 21 92 00 B3 0E 03 85 00
RX Data : 0A 06
RX Data : 12 92 00 80 21
***************************
* A23 CAM should be OPEN *
* test in Nagra to see. *
* if not, try again. *
***************************
Script C:\winexplorer5\Rom10-A23 OPENworks.XVB Transmission Completed
petedog
10-01-2004, 09:16 AM
Thanks lightning0009 for the KAC mod and as soon as I figure out how to Flash it I will make the changes and give it a try. If you would post or PM me a step-by on Flashing this sucker I sure would appreciate it very much. Thanks again for your work on the KAC clone mod!
:BoomSmili
I have a kickass clone unlooper also. Could you send a pic or so to go along with your description? I would love to try this. can u upload the flash or tell me where to find it?
csalmon
10-01-2004, 07:31 PM
I would also love to see some pics of that mod. Please post if you can.
Thanks
lightning0009
10-01-2004, 08:04 PM
Ok, the yellow arrows are where I bent the pin up and soldered the wire to the bent up pin. The red arrows are where I just pushed the wire down in the slot with the pin still there. The flashes can be found on this site in the other unlocking threads. One flash for rom3's and a different one for rom10's. You program the 2313 with the switch closed. Open the switch for unlooping. I used xpatmel to program the unlooper.
nofear
10-02-2004, 06:13 AM
Is it possible to provide a schematic with your mod. I dont have the kickass unlooper, but would love to try your mod with some of the older Little red unloopers.
lightning0009
10-02-2004, 08:59 AM
It's Pengras mod for unlocking. It's number ten in the rom files in the download section. Rom10unlocker-Glitcher.zip it is called. It has the tucker schematic with the modified sections highlighted. That is the mod I did to this kickass clone. I just figured out how to do it from the schematic for this unlooper.
Eldune
10-02-2004, 05:19 PM
Is it possible to provide a schematic with your mod. I dont have the kickass unlooper, but would love to try your mod with some of the older Little red unloopers.
ME TOO on the little Red! Or the Timeshift Repair Station Thanks
petedog
10-02-2004, 09:18 PM
lightning0009 Well after I got this sucker Flashed I noticed you and I must have different KAC Clones! The only socketed chip on mine is the 2313 Atmel, yet you say remove 232. and the 74HC00N. You also say some wires you just put in the slot! With no socket,no place to push the wires in! Is yours socketed or are you de-soldering and removing? Thanks for your help!
:BoomSmili
debauche
10-02-2004, 10:24 PM
Ya, its nice to see what is actually supposed to happen when it runs... I let it go for hours with all OOOooooOoooOoOo until I tried it with no card in it and got the same thing, and changed some things around.
I have a different loader not talked about here, and got 2 rom3 softlocked, spoofed 383 to unlock in about 1 second apiece. I have one other stream locked R3 that will not unlock. Should I let this run or should I look at changing the resistance? When I run the test on the open cards, it ends fast so I don't know if it is saving the 'right' points or what....wish there was more documentation on it.
lightning0009
10-02-2004, 11:09 PM
My Kickass clone has all socketed chips. I recommend going from the schematic and figuring it out from there if yours is different than mine. The main thing with mine that was different than Pengras schematic modifications was with the 74HC00 chip. In the original tucker schematic that Pengra used to show his changes from the pins used for the 74HC00 chip were 2,1,3 and 4,5,6. My kickass clone used pins 9,10,8 and 5,4,6. I figured this out using an ohm meter and metering out the pins on the chips and wrote everything down kind of making my own schematic for my kickass, but only the parts that were different and that was the only part. So basically I took the two gates that were coming out of the clock divider switch and changed there input so they are now coming out of the 74HC74 like Pengra showed in his modded schematic to do only my pins were a little different. Everything else schematic wise was pretty much the same pertaining to the modifications that needed to be done, so I just figured out how to do the mod to this kickass the easiest way possible but with socketed chips because that is what this one has.
lightning0009
10-02-2004, 11:15 PM
lightning0009 Well after I got this sucker Flashed I noticed you and I must have different KAC Clones! The only socketed chip on mine is the 2313 Atmel, yet you say remove 232. and the 74HC00N. You also say some wires you just put in the slot! With no socket,no place to push the wires in! Is yours socketed or are you de-soldering and removing? Thanks for your help!
:BoomSmili
Petedog,
If I had your unlooper I would just desolder the one leg and bend it up and then solder a wire to the bent up leg and run it over to the leg on the other chip and solder it to that or you could run it around and underneath the board and solder it to the underside of the chip leg. Or you could cut traces underneath or you could take out the whole chip and put in a socket.
petedog
10-02-2004, 11:53 PM
Yea, it looks like I am going to cut some traces, which shouldn't be a problem. I just found out that the clones are not the same. Thanks alot lightning0009, you get all my Atta-Boy points for a good job!
:BoomSmili
Wizkid
10-03-2004, 02:01 AM
Have you been able to open a rom3 or get good test glitches with the test bin?
sugadaddy
10-05-2004, 04:53 AM
I have about 10 KAC unloopers and would love to get rid of them all but one. They were very solid pieces back in the H and HU days.
vtails
10-05-2004, 05:20 PM
I have a KAC Mikobu Glitcher Rev.B (bLACK), that is almost the same as a Mik3 but I have a 20 pin Ic behind the serial port plug,it looks just like the Atmel,the Mik3 has a Sip232 16pin behide the serial port anyone tried to mod this,or would know which Ic would be the 232 on this.
all 6f6f6f6f6f6f6f6f6f nothing else any ideas
Crazy1_79
10-15-2004, 12:04 AM
I have a old hu wild 2000 loader, "I believe it is a wildthing clone but am not sure" I need mods for this, I am going to tackle it.
Crazy1_79
10-15-2004, 12:05 AM
If someone can post a link or have any idea about these please let me know, I didn't at first think it would be possible to mod becuase of the lack of dip switches, but after seeing the mikobu three mod I see now that maybe it is possible. Any help would be appreciated, I use this loader strictly for sorrynagra so I know it does work.
lightning0009
10-15-2004, 12:34 AM
Crazy, I seen a bunch of different pics of different unloopers and even one guy posted one like mine wanting to know how to mod it, all at cardcoders. I am not familiar with the one you got, so not sure, but it probably can be.
Crazy1_79
10-15-2004, 12:37 AM
you aren't going to believe this lightning, I followed the mods you did on yours, except I didn't have a 5K trimmer, So I stuck a 2.2k ohm resistor in there just to make the connection, this is what I have in running the script, although I am unable to flash the atmel as of this time. (I already had it flashed)
Executing Script: C:\Documents and Settings\nathan\My Documents\Rom 3 unlocking mods\3-TESTFILES\TESTglitchFIND.XVB
TX Data : A0
TX Data : A1
TX Data : 07 0E 03 10 01 03 9A 00
RX Data : 07 1B
RX Data : 0C FF 95 00 FF 91 81 71 64 47 00 44 4E 41 53 50
30 30 33 20 52 65 76 33 37
OVERFLOW WAS SENT TO 00 E050, READ CAM LATER WITH NAGRA EDIT TO SEE E050
CHANGED FROM FF TO 00. IF IT DID WE KNOW OVERFLOW IS WORKING.
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAA--- try to hit 0C bug at 10A5
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAA--- try to hit 0C bug at 10A6
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAA--- try to hit 0C bug at 10A7
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAA--- try to hit 0C bug at 10A8
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
petedog
10-19-2004, 02:29 PM
Well I have started the "mod" on the old KAC WTII , cut the 232 and C00N out, installing sockets , drilling hole for wires, installing "Red Oak Socket Towers" etc.,he! he!, and hope to build a fire in it Wednesday evening. If it don't go UP in smoke, I will post the results, and a Pic of the "Towers" later in the week "The BranchRanch Mod" Hello!
Thanks again for your mod on that "Letter" getter!
You have PM !
lightning0009
10-19-2004, 08:15 PM
Petedog, for this old H unlooper I decided to cut the traces on the bottom. They are the purple lines I drew in these pics. THe layout was different than the KAC, but the pinouts were the same. It didn't have a jumper switch installed. #2 on the jumper switch was always on, so I cut that with a razor on the topside, that's the only cut on the topside of the board,(I marked it on the bottom in the pic) all the rest were on the bottom. I then installed the switch on the top. #3 on worked for me for rom3 testglitching. I glue gunned the 5k pot to the top of the 4053 and just pushed the wires down into slots 4 and 7. I took out the white Led on this one. I installed the switch for programming the atmel.
lightning0009
I have the same as you have but have an iso programmer attatched to it also.Can you show a better diagram of the wiring diagram..I Mean i see a switch and a knob there.Im alittle lost..thanks
lightning0009
10-20-2004, 07:03 AM
Here is how to mod your kickass clone if you don’t have socketed chips.
On the top side you will need to cut the trace that goes from the switch to the 74HC00 chip. It is directly below the O in the OFF letters on the switch. There are two other traces that run right next to the one you need to cut and they are closer to the card socket. Don’t cut those.That is the only trace that needs to be cut on the top side of the board. On the bottom side there are two traces to cut. Look at the picture. Now on the max232 chip Solder from underneath the board on leg 10 to one side of the switch. The other side of the switch solder a wire and run it to pin 18 of the 2313 atmel chip. There will be two wires you will need to solder to this pin so you should do both at the same time. The other wire will go from pin 18 of the 2313 atmel chip to pin 4 of the 74HC00 chip. With the switch closed you can program your atmel, with it open, you can unlock cards.
Now the 74HC00N chip. Solder that other wire from pin 18 of the 2313 atmel chip to leg 4 of the 74HC00 chip. Now solder a wire from pin 9 of the 74HC00 chip to pin 9 of the 74HC74 chip. Now solder a wire from pin 11 of the 74HC00 chip to pin 11 of the 74HC4053 chip. Now solder a wire from pin 12 of the 74HC00 chip to the pin that’s labeled 1 on the rocker switch. Now solder a wire from pin 13 of the 74HC00 chip to pin 14 of the 2313 atmel chip
Now you will need to hook your 5k potentiometer to pins 4 and 7 of the 74HC4053 chip. The center wire from the pot is postive and would go to pin 4 of the chip and one of the outer legs of the pot would go to pin 7. Now you can push the wire down in the slot if you chip is socketed or you can solder wires underneath to the pins and run them to the topside to your pot. I took out the white LED labeled D2 on my board, you can too.
lightning0009
lightning0009
Thanks so much for the work you went threw to help me out.Im done adding the wires just 2 more things i would like to add is the 2 wires you got going to a switch...What is that for and what flash do i use to flash my chip..Oh ya and that know you use where can i find one of them...thanks again for the help.. :)
lightning0009
10-20-2004, 08:27 AM
The switch is to enable programing the atmel 2313 chip with the newd6 flash for rom3 unlocking or the newd7, 8, or 9 for rom10 a23 unlocking. They can be found in the file download area or in other unlocking threads so I ain't gonna attach them here. You will need that switch so you might as well put it in. You should read all the different threads on unlocking, even the ones about other unlooper mods because they all have good info on all this stuff and a bunch of the files you will need.
Can someone tell me how to flash a newb6.asm fileit says you must flash with new6b.hex and newb6.asm but i cant load the asm file.Any help would be great
lightning0009
10-20-2004, 12:00 PM
Gold, you only flash the newb6.hex file to your unlooper. Use the UP16flasher program. Click the verify button after you flash it to make sure it flashed correctly. In the other threads or in the files download there are other versions of the newb6.hex file for xpflasher if you want to use that to flash with.
Steventoo
10-20-2004, 03:13 PM
Can anyone tell me if one of these h/hu unloopers has a mod for them. If so...what can I do to get into my rom10 a.23 card? The green one is a ALL-IN-ONE and the red one is a SU.
petedog
10-22-2004, 05:37 PM
lightning0009 I think I almost have the Mod finished on the KAC , but the question I have is what goes to the board side at #4 after you lift the pin of the 74HC00N? There is a jumper for #9 , but I see nothing for #4 on the C00N, board side that is!
Thanks again!
You have PM!
lightning0009
10-22-2004, 08:15 PM
Petedog, that is because pin 4 of the 74HC00N used to come from pin 9 of the 74HC74. You should have bent up pin 9 of the 74HC74 and soldered a wire from that to pin 9 of the 74HC00N. Now the bent up pin 4 of the 74HC00N goes to pin 18 of the 2313. Basically that line that was there is now not being used so it doesn't matter with the socketed chips mod version of this mod. I went ahead and modded mine further by cutting a few traces on the bottom and changing the mod so I don't have to bend up any pins on my KAC like I stated in post 25 of this thread. Both mods work, The mod with socketed like post number one or the mod without the sockets(post 25) as long as you follow the directions. If you want to learn more about why and all that, I recommend getting the original tucker schematic and the modded schematic and comparing them to your unlooper. Remember this KAC has a different pin number usage than the original tucker or the mod tucker schematic and I figured those changes out with an ohm meter and with my eyes and modded the schematics I had printed out to correspond with those changes so I could visualize what needed to be done to do this properly and that always helps.
petedog
10-22-2004, 08:55 PM
Petedog, that is because pin 4 of the 74HC00N used to come from pin 9 of the 74HC74. You should have bent up pin 9 of the 74HC74 and soldered a wire from that to pin 9 of the 74HC00N. Now the bent up pin 4 of the 74HC00N goes to pin 18 of the 2313. Basically that line that was there is now not being used so it doesn't matter with the socketed chips mod version of this mod. I went ahead and modded mine further by cutting a few traces on the bottom and changing the mod so I don't have to bend up any pins on my KAC like I stated in post 25 of this thread. Both mods work, The mod with socketed like post number one or the mod without the sockets(post 25) as long as you follow the directions. If you want to learn more about why and all that, I recommend getting the original tucker schematic and the modded schematic and comparing them to your unlooper. Remember this KAC has a different pin number usage than the original tucker or the mod tucker schematic and I figured those changes out with an ohm meter and with my eyes and modded the schematics I had printed out to correspond with those changes so I could visualize what needed to me done to do this properly and that always helps.
Thanks again lightning009 for letting me see that "nuthin" connects to the item in question!
No More Pm's
Thanks again!
petedog
10-23-2004, 02:45 PM
Well lightning0009 :) the 1st post on the KAC mod of yours, you say "Now solder a wire to pin 9 of the 74HC00N and run it to pin 9 of the 74HC74AN." O.K. this KAC is using a 74HCT0431, instead of the 74HC74AN! Could this cause a TimeOut? Will the one I have be O.K., or do I need to cut it out and socket a 74HC74AN to the PCB?
Its giving me the old TimeOut ! :cry: I know it can be a lot of things including a Cold Solder Joint! Hello! Using 450 PC, Windows 98 second edition and configured WinEx from the A23unlocker-glitcher script and now have the TimeOut Prob! All suggestions Welcomed!
Thanks lightning0009 and All !
thehutch
10-25-2004, 08:00 AM
Hello,i did the mod on my kac it has no sockets i dont have a 5k trimmer {rat shack was out}so i put a 2.2k resistor on pin 4 and 7 of 4053 closest to 2313 but i cant get nothing but oFFoFFoFFoFFoFF on rom3 script,could it be that i need a 5k trimmer or is something else ?on a rom10 i just get all FFFFFFFFFFFFF or reset reset reset resetreset.
i use the newd6 for rom3 and the newd7,8on the rom10 still nothing.
lightning0009
10-25-2004, 09:11 AM
Hutch, On rom 3 I had best results with switch 3 on and my pot set at about 600 ohms which would be .6 K. For rom10 I had switch 4 on and my pot set at about 600 ohms also. I used a 9v 300 milliamp powersuppy. You could try a 600 ohm resistor. I also would unplug and plug the power back in to the unlooper right before each unlooping attempt.
thehutch
10-30-2004, 03:46 PM
i have the 5k pot on with dip 3 on i get o04FFo6F i can ajust the pot up and get o6Fo6Fo6F i do not get any AAFF on rom 3 it still will not pop.
on the rom10 i can only ger reset reset reset reset no matter how i ajust the pot.
bowman
11-06-2004, 04:16 PM
I am using lights second KAC mod ,,,on my KAC mod ,,,,,,all i get is 00000000000000000000000 in win - explore ?
Bow
thehutch
11-08-2004, 02:27 AM
i am getting o6Fo6Fo6Fo6Fo6F 0n my rom3,on my rom10 i get reset reset reset reset or FFFFFFFFFFFFFF it will pop but in nagra edit it said cam contains updates still locked. used 2nd directions on my last kac the chips are not socket just the 2313 and 74an are.
lightning0009
11-08-2004, 04:07 AM
Hutch, are you moving you 5k pot while you are glitching? That's what I do with rom10's till I get the FFF6FFF6FFF6 thing. I found it works best with switch 4 on the unlooper on and about 600 ohms on the pot. 9 volt 300 milliamp power supply is also what worked for me.
bowman
11-08-2004, 05:30 AM
lightning0009,,,,, on the mod without removable chips ,, do i have to take out the white led (D2) ??
Bow
thehutch
11-08-2004, 11:16 AM
yes i move the pot on the rom10 it is not stream locked it is blocker with lost password,on my rom3 i have ran the test glitch with dip 4 on i can get glitch points like this vcc=37 delay=0032 glitch type=06 vcc=4b delay=002f glitch type=06 vcc=3f delay=002c type=07 i can put these values in and not mess with my pot i get o6fo6fo6fo6fo6fo6fo6fo6fofo6fo6fo6f but rom3's will not pop.
lightning0009
11-09-2004, 02:17 AM
Hutch I used rompopper to open a blockered rom10 myself with an iso reader writer. I get the same o6f thing for rom3's and just let it run for an hour or so and it always pops with my pot set to about 600ohms with switch 4 on and a 9 volt 300 miliamp power supply.
thehutch
11-09-2004, 02:40 AM
i have let the rom3 run for 4-8- hours it still dont pop i have a 6 volt 400 miliamp and a 9 volt 600 miliamp it still will not pop.i can get the FFFFFFFFAAAAFFFFFFFF and i can get hits like
vcc=37
delay= 0032
glitch type 06
vcc=4B
delay=002F
glitch type=06
vcc=3F
delay=002C
glitch type=07
vcc=40
delay=002C
glitch type=07
vcc=49
delay=002C
glitch type=07
vcc=4F
delay= 002F
glitch type=06
this is with the rom3 newd6 i have used all of these settings still no go.i have no way of telling what my pot is set at it has no marks i can ajust it to go from all ooooooo to o6Fo6Fo6Fo6F or all FFFFFFFFFFFF
yes the D2 led is taken off on mine i have just the red led {D1} it stays on.
bowman
11-09-2004, 02:42 AM
hutch,,,,Thats all i get is 0000000000000,,,, did you take the white led (D2) off you board ?,
Bow
thehutch
11-11-2004, 01:10 AM
i can unlock rom10's pretty easy with my kac,i have only got 1 rom3 to unlock the vcc start and limit that i had to use was vcc start=10 vcc limit=25.
bowman
11-11-2004, 03:38 AM
thehutch.,,,,
i modded my kac, and thats all i get are 00000000000 at 600 ohm's,,or if i trun the resistance down i will get 0101010101010101010,, my does not have the removeable chips , can you think of anything i might have done wrong ,,??? and when i do a vcc check i get nothing but this = 0 ,,,?
Bow
bowman
11-11-2004, 11:01 PM
i have gotten rom10's a23 to say,,, we have hit our bug and should be open now , but when i go to nagraedit they are still closed , have re-ran they 4- -5 times ,,, does any one know what could be wrong ????
i just modded my kickass clone and i cant flash my chip..HELP please
thehutch
11-12-2004, 03:42 AM
i have 1 rom 10 like that myself the card seems to be messed up,i am just having trouble with rom3 cards.
No dude i cant flash my atmel chip.it wont flash i dont know what i did wrong .everything seems ok..
xprezz
11-25-2004, 05:00 PM
I did the mode to my kac but this is what I get
Executing Script: C:\Documents and Settings\j.g\Desktop\powersyncUnlockRom3ver1a.XVB
TX Data : A0
TX Data : A1
TX Data : 07 0E 03 10 01 03 9A 00
RX Data : 07 1B
RX Data : 3F FF 95 00 FF 91 81 71 64 47 00 44 4E 41 53 50
30 30 33 20 52 65 76 33 38
o6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6 Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6F--- try to hit 0C bug at 10A5
And it it just keeps going if I play with the pot I will get all 0 but nothing else . Any help here would be great.
bowman
11-25-2004, 05:18 PM
i wish i could get the ,,,60f06f660f60f, on my modded kac,,,, i get every other number ???? This is what it looks like ,,825df2565d222227f8956f26548754628885000025645544 55814110 ,,ect,ect,ect ???? antone have a clue why i can not get the 6f6f06f06f06f ?
Bow
xprezz
11-25-2004, 07:21 PM
Bowman,
Is the o6fo a good sighn I have let it run for 1 hour and the card will not pop .I am using new6 flash and I have also tried the new7 . this a rom3 card stream locked at 383.
As far as your reading I would look over your soldering and double check your wiring .
bowman
11-25-2004, 07:37 PM
xprezzz you have to use the new -6 only for the rom 3'ss the 7-8-9- are for the rom 10's,,
Bow
xprezz
11-25-2004, 08:09 PM
Yes, I am using the new 6 but I had read on a nother site that the new 7 may work on rom 3 but it did not work for me.
Do you know if the reading I am getting from my rom 3 is a good one or do I have something set wrong I am getting o6fo6fo and so on.
xprezz
11-26-2004, 11:15 PM
Can any one tell me if I am on the right track here with this reading from my rom 3 at 383 using new6 flash on my kac unlooper. the script just keeps running I have tried every postion on the 5k pot and I have changed the vcc start and limit with no luck the only change I get is all 0o0o0o0o. Any help would be great.
Executing Script: C:\Documents and Settings\j.g\Desktop\powersyncUnlockRom3ver1a.XVB
TX Data : A0
TX Data : A1
TX Data : 07 0E 03 10 01 03 9A 00
RX Data : 07 1B
RX Data : 3F FF 95 00 FF 91 81 71 64 47 00 44 4E 41 53 50
30 30 33 20 52 65 76 33 38
o6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6 Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6F--- try to hit 0C bug at 10A5
lightning0009
11-27-2004, 03:27 AM
Switch 4 on only on the unlooper.
My 5k pot set to about 600 ohms.
9v, 300 miliamp power supply.
Settings I used for the unlockrom3.xvb
Sub Main()
DelayStart = &h10A3
DelayLimit = &h10A7
VCCStart = &h30 'YOU CAN CHANGE THIS FROM 20 TO 50-SET TO TEST BIN
VCCLimit = &h1A 'YOU CAN CHANGE THIS FROM 1A TO 30-SET TO TEST BIN
GlitchType = &h06
TryCnt = 1
TryLimit = 2
Delay = DelayStart
VCC = VCCStart
Executing Script: C:\winexplorer5\unlockrom3worked.XVB
TX Data : A0
TX Data : A1
TX Data : 07 0E 03 10 01 03 9A 00
RX Data : 07 1B
RX Data : 3F FF XX XX XX XX XX XX XX XX XX
XX XX XX XX XX XX
o6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6 Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6F--- try to hit 0C bug at 10A5
o6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6 Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6F--- try to hit 0C bug at 10A6
o6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6 Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6F--- try to hit 0C bug at 10A7
o6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo00o63
=========================
= CAM IS OPEN NOW !!!!! =
=========================
Script C:\winexplorer5\unlockrom3worked.XVB Transmission Completed
bowman
12-03-2004, 08:55 PM
lighting ,,,,,,i have got my kac ( with your mod ) to give me 6fffffffffffffffffffff6fffffff6fffffffffffff6f on rom10's but will-not open,, ran for hours and hours,,? and on the rom3' i can get it to catch the bugs,,but will not catch the oc bug ??? , any sugestions ?
Bow
lightning0009
12-04-2004, 02:00 AM
Bow, for rom10's I popped a few no problems and then had some I couldn't get the FFF6FFF6 thing going at all even turning the pot while running. I then changed the VCC start to 50 and the VCC limit to 46 I think then I popped two in row. I would say try different VCC starts and VCC limits and run it and move your pot till you get the FFF6 thing looking good.
bowman
12-04-2004, 04:04 AM
Thanks light , will give it a shot
Bow
bowman
12-05-2004, 12:48 AM
no go light,,, if you can think of anything else let me know and i willl try it,,,K,.. thanks again
Bow
Kurt Angle
12-06-2004, 08:32 PM
do you guys have a part # for the 5k pot at rat shack? my searching abilities seem to not be functioning this AM.
xprezz
01-10-2005, 01:26 AM
Petedog, for this old H unlooper I decided to cut the traces on the bottom. They are the purple lines I drew in these pics. THe layout was different than the KAC, but the pinouts were the same. It didn't have a jumper switch installed. #2 on the jumper switch was always on, so I cut that with a razor on the topside, that's the only cut on the topside of the board,(I marked it on the bottom in the pic) all the rest were on the bottom. I then installed the switch on the top. #3 on worked for me for rom3 testglitching. I glue gunned the 5k pot to the top of the 4053 and just pushed the wires down into slots 4 and 7. I took out the white Led on this one. I installed the switch for programming the atmel.
Lightning0009 ,
I used your mode on my old h unlooper that is labled super unlooper with no dip switches . It is the same unit that you have pic. in this very post . I have tried everything but only get as far as.
TX Data : A0
TX Data : A1
TX Data : 07 0E 03 10 01 03 9A 00
RX Data : 07 1B
RX Data : 3F FF 95 00 FF 91 81 71 64 47 00 44 4E 41 53 50
30 30 33 20 52 65 76 33 38
o6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6 Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6F--- try to hit 0C bug at 10A5
o6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6 Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6F--- try to hit 0C bug at 10A6
o6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6 Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6Fo6F--- try to hit 0C bug at 10A7 ( 25 hrs of this on more then one card.)
.I have tried using 5volts to 9v I have also tried puting the 5k pot. on the 74hc4053 closest to the atmel and also the other 74hc4053 . I have tried almost everything with no luck any more help would be great.
lightning0009
01-10-2005, 06:11 PM
Looks like your trying to unlock a rom3. Hard to set up your unlocker to unlock a rom 3 unless you program up a good rom 3 with the testglich bin and then run the testglich script to find the best settings and such. Otherwise looks like you are real close. I get that same exact o6F06F thing when I unlock rom3's and just let it run and sometimes I turn the 5k pot a little and then it pops. Keep trying you'll get it if the mods are right.
xprezz
01-11-2005, 12:29 AM
Looks like your trying to unlock a rom3. Hard to set up your unlocker to unlock a rom 3 unless you program up a good rom 3 with the testglich bin and then run the testglich script to find the best settings and such. Otherwise looks like you are real close. I get that same exact o6F06F thing when I unlock rom3's and just let it run and sometimes I turn the 5k pot a little and then it pops. Keep trying you'll get it if the mods are right.
That is the thing I have used the test bin and have run the test glitch and it will error out and when I check card the FF has turned to 00 . I still have no luck with the unlock though when using the settings.
One other thing what 74hc4053n do you put the pot on the one closest to the atmel or the other one?
lightning0009
01-11-2005, 01:42 AM
You can put the pot on the chip farthest from the atmel. Middle leg of pot to pin 4 and one of the outer legs of the pot to pin 7. I hooked my pot up with some wires to the underside of the unlooper to pin one on the cardslot pins and the other wire to ground. If you look at the schematic that is what the pot hooks to so either will work. I suspect mabey your problem is that you don't have switch 4 turned on on your unlooper cause you said you didn't have the switch. I have only had luck unlocking with switch 4 on for both rom3's and rom10's. You should be able to put in a jumper wire so it's like switch 4 is on and make sure you cut any other jumpers that might be hooked up for the other three switches that aren't there.
Actually, if you have the jtek unlooper and not the kickass clone. I ain't sure what chip to hook the unlooper to, but It is marked in that pic I posted up above. When I did the jtek mod mine didn't have a switch either and switch 2 I think had a permament jumper on one side of the board and I cut that and then put in a switch, but you could just jump pin 4.
lightning0009
12-14-2005, 04:19 AM
Whoo hoo!!!!! Popped a 102, Delay was 316. I'll post more settings as i pop more.
lightning0009
01-13-2006, 02:39 AM
rom 102 settings switch 1 only on.
VCCStart = &h2f 'h25 is standard, script is auto vcc dont change 90
VCCLimit = &h02 'h05 is standard, script is auto vcc dont change 02
DelayStart = &h32d 'h385 is standard, try 375, 350 has been known to hit too.
DelayLimit = &h38a 'h385 is standard, try 395
GlitchMax = 8 '7 is standard - 7, 8, or 9
GlitchMin = 6 '7 is standard - 6, or 7
trys = 120 '100 is standard
mix = 0.5 '0.5 is standard - try 0.1 to 1.2 use for +-+-+-+- mix
if VCC < VCCLimit then
VCC = &h2f
print " hit VCCLimit, back up to &h2f vcc "
end if
TX Data : 90
RX Data : 4E 44 31 33
Let the 102 Glitching begin....
+---+---+---+---+---+---+---+-
TX Data : A1
===========================================
Glitch Success!! A0FF-INTERCEPT IS ON
BootLoader 6F 00 RSP Received!!
VCC = 26 (~0.745098039215686 vdc)
Glitch Delay = 032D
Glitch type 07
===========================================
TX Data : 90
RX Data : 4E 44 31 33
Let the 102 Glitching begin....
+-+--+---+-+-
TX Data : A1
===========================================
Glitch Success!! A0FF-INTERCEPT IS ON
BootLoader 6F 00 RSP Received!!
VCC = 2C (~0.867647058823529 vdc)
Glitch Delay = 032D
Glitch type 06
===========================================
ericchile
01-17-2006, 06:56 PM
I have a KAC h unlooper non socketed, modded acording to diagrams here. It has the iso reader on the side. I can't use xpflasher to flash atmel with new13. Does this mean that the mod is bad?
lightning0009
01-18-2006, 02:46 AM
Ericchile, did you put in the switch so you could flip the switch so you could flash it? You'll need that switch if you didn't put it in to flash the atmel.
ericchile
01-19-2006, 06:19 AM
Yup the switch is there. I will try to get some pics... How do you know if you have done the mod correct? Even if I flash the atmel out side of the unit...
lightning0009
01-19-2006, 07:03 PM
I'd say to check if the mod is right, you have to try and unlock a dish card and see if you are getting the right responses. What rom card are you trying to unlock?
ice9393
01-23-2006, 09:46 PM
Will this also work on Rom101
lightning0009
01-24-2006, 02:18 AM
Ice0303, yes I have unlocked two rom101's with my kickass clone so far. I've unlocked rom3's, rom10's, rom101's and rom102's with it.
ericchile
02-13-2006, 11:47 PM
i just modded my kickass clone and i cant flash my chip..HELP please
Did yours have an iso reader and pic programmer on the side also? Mine does and I have checked all the connections... and I can't get the thing to flash. But I remember that it never did flash when it was new except in the pic programmer on the side. Maybe that is the problem.
I flashed the atmel in the pic programmer but when I run scripts it always says the ATR is 000000000, but I know the card gives a valid atr in a DISH Iso reader.
Any ideas? Has anyone gotten the KAC H unlooper like in this post to work that also has a pic programmer and ISO reader?
Shark2ua
02-07-2008, 12:20 AM
I have a Absolute 1 premier edition loader and a Rom 102 card that is locked from a previous owner. My reciever has been flashed and I have watched T.V. with my AVR board. I am very new at this and am trying to figure out how to program either of these cards....any help would be GREATLY appreciated...billybobis@shaw.ca
Thanks..
vBulletin® v3.7.0, Copyright ©2000-2008, Jelsoft Enterprises Ltd.