View Full Version : Rom 10 backdoor missing in Action???
Loopey1
10-07-2004, 09:38 AM
OK folks this is what I have done. I only have one rom 10 card so I thought..... OK try it I downloaded a file called dish-formula-rom10-freeware.zip edited boxkeys and IRD wrote to card fine. but something went wrong reciever said not valid for this reciever. OOPS must have put in wrong key or something.
SO I open niagra 4.1 try to clean Nothing.... this is what I get.
ATR String: 3F FF 95 00 FF 91 81 71 A0 47 00 44 4E 41 53 50
30 31 30 20 52 65 76 41 32 33 4B
ROM Revision: 010
EEPROM Revision: RevA23
ProviderID: 00
CamID: 00 AD 1E BF
Using BD3 Key: 4E 69 70 50 45 72 20 49 73 20 61 20 62 75 54 74
Attempting to login to BD3
BD3 login failed
Reading ROM10 failed
Closing of COM2 was successful
Now there is a text doc that says the backdoor password so thinking that is a card Unlock code I enter it there Nothing again this is what I get.
Opening of COM2 was successful
Removing card lock
Closing of COM2 was successful
Bad password or BackDoor not present
Check Eprom c600 on the bin file and that code IS the code it is supposed to be to get backdoor access.
Any Ideas what I have done wrong?
:cry:
littlelarryjr
10-07-2004, 01:39 PM
EEPROM Revision: RevA23
You just answered your own question. This card is stream locked A23. You'll have to build a unlocker, or go to a dealer. Next time use a good blocker.
Crazy1_79
10-07-2004, 01:44 PM
loopey already has the unlocker, looks like another one to open! lol
littlelarryjr
10-07-2004, 02:03 PM
almost done mine, should be sometime thursday.
Loopey1
10-07-2004, 06:00 PM
How can it be stream locked when it never made it to the stream? When I redo a card I always remove the Sat Line.
Has anyone else used
dish-formula-rom10-freeware.zip in the files section?? can You get into your card after applying it??
Dang it this really bums me out. :cry:
Eldune
10-07-2004, 06:14 PM
How can it be stream locked when it never made it to the stream? When I redo a card I always remove the Sat Line.
Has anyone else used
dish-formula-rom10-freeware.zip in the files section?? can You get into your card after applying it??
Dang it this really bums me out. :cry:
I have one also. I did not use that file but I have been trying to unlock for 24 hours. You will get 69696969ffffffff696969696969ffffff Good Luck
xprezz
10-07-2004, 06:28 PM
This card is not stream locked but it is password locked.Did you read the read me that came with the file it has a lock at c600 .Just open your backed up image of the card write down the first 16 dig at line c600 and enter in to the remove lock tap of Nag.. If you don't have your card backed up try this password 9FD7E24355B74444.
coolwind
10-07-2004, 09:08 PM
I need Help with a rom 10 card @ A21 has BD3 login failed Bought card & cant get into it may have a unknown password on it !
Is their a How to for viagra & camwhisler to open this card
TKS Cool
Loopey1
10-07-2004, 10:06 PM
This card is not stream locked but it is password locked.Did you read the read me that came with the file it has a lock at c600 .Just open your backed up image of the card write down the first 16 dig at line c600 and enter in to the remove lock tap of Nag.. If you don't have your card backed up try this password 9FD7E24355B74444.
Been there done that No GO at all that is the password for the back door but it did not work for me. Man I feel so dumb right now. :heads_or_ c600 has the same backdoor password as the one you posted nothing.
Well I guess it is time to try the mod on a rom 10, Anyone have any luck popping these yet?
Nupc1
10-07-2004, 10:19 PM
check your private messages.
xprezz
10-08-2004, 12:07 AM
Been there done that No GO at all that is the password for the back door but it did not work for me. Man I feel so dumb right now. :heads_or_ c600 has the same backdoor password as the one you posted nothing.
Well I guess it is time to try the mod on a rom 10, Anyone have any luck popping these yet?
Did you back up your bin? If so try to write your bin back to card after you enter the password, do not try to one step clean or one step back up just write to card.If this does not work clean your backed up bin and try to write to card.
I have tested this bin and with the password I am able to renter my card with no problem .If you have done something different from what you have already posted please repost so I can get an idea as to why it would lock your card.
starc
10-08-2004, 12:20 AM
Hopefully this will help, I used these the other day and it corrected the same problem. Use with an iso and click on "Reparar"
Eldune
10-08-2004, 12:20 AM
loopey1, Let me know if you get in with the unlocker I have had no luck.
Loopey1
10-08-2004, 02:26 AM
Hopefully this will help, I used these the other day and it corrected the same problem. Use with an iso and click on "Reparar"
Did as directions said did not work
first 2 commands said ok but 3rd one error
I can only assume that this is the BD3 key that error out.
Loopey1
10-08-2004, 02:29 AM
loopey1, Let me know if you get in with the unlocker I have had no luck.
As far as the loader glitching card the only way I even get ATR is almost 0 ohms on pot then back off till I get FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF but that only lasts short time then reset reset reset ect...
If I edit the start voltage in the script to 110A then I can get it to 696969FFFF6969FFFF6969FF696969 FFFF but then again only for a short time then reset reset ect.
Still trying though I have high hopes for this.
Loopey1
10-08-2004, 02:30 AM
Did you back up your bin? If so try to write your bin back to card after you enter the password, do not try to one step clean or one step back up just write to card.If this does not work clean your backed up bin and try to write to card.
I have tested this bin and with the password I am able to renter my card with no problem .If you have done something different from what you have already posted please repost so I can get an idea as to why it would lock your card.
Tells me the BD3 hole is closed sorry.
xprezz
10-08-2004, 04:04 AM
Well sorry to read that you can not get back in. It does happen that some card just will not pop. The bin that you wrote to your card does use a bad type of lock but, if you have a back up of your card you may be able to get back in.
What does Nag. tell you when you put the password in ?
I would also try what is at C700 as a password this may be it but I dout it.
One other thing are you shore that you appled this bin to your card you may have not and, the old bin is still on the card ? You can try the old passwords at line C600 or line C700 to get back in but seeing as how Nag is telling you that it can not log into BD3 tells me that it is locked at one of the other lines of code. You can go crazy and try every 16 dig # letter combo that was writen to your card to get it to pop.
Loopey1
10-08-2004, 05:04 AM
Opening of COM2 was successful
ATR String: 3F FF 95 00 FF 91 81 71 A0 47 00 44 4E 41 53 50
30 31 30 20 52 65 76 41 32 33 4B
ROM Revision: 010
EEPROM Revision: RevA23
ProviderID: 00
CamID: 00 AD 1E BF
Using BD3 Key: 4E 69 70 50 45 72 20 49 73 20 61 20 62 75 54 74
Attempting to login to BD3
BD3 login failed
Reading ROM10 failed
Closing of COM2 was successful
This is what I got after trying both C600 and C700
off the Card Image.
anyone notice anything wierd??
provider ID is 00???
Loopey1
10-08-2004, 06:30 AM
Here is the latest... Do not know what is going on but Hope someone knows.
Executing Script: C:\rom10unlocker-glitcher\Rom10-A23 OPEN.XVB
TX Data : A0
TX Data : A0
TX Data : A1
TX Data : 07 0E 03 10 01 03 9A 00
RX Data : 07 1B
RX Data : 3F FF 95 00 FF 91 81 71 A0 47 00 44 4E 41 53 50
30 31 30 20 52 65 76 41 32
TX Data : 12 15 AB 21 00 08 A0 CA 00 00 02 12 00 06 55 0E
03 85 00
RX Data : 12 06
RX Data : 12 00 08 92 04 00
Now we will try 123E delay
FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF69 FFFFFF69FFFFFF69FFFFFF69FF696969FF696969FF696969FF 696969FFFF6969FFFF6969FF696969FF696969FFFF6969FF69 6969FF6969696969696969696969FF696969FF696969FF6969 6969696969FF69696969696969 RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF 69FFFFFF69FFFFFF69FFFFFF6969FF696969FFFF6969FFFF69 69FF69696969696969FFFF696969FF6969FF69696969696969 6969696969FF696969FF6969
now we will try 123F delay
69FF69FF69FF696969FF696969696969696969FF696969FF69 6969FF696969FFFF6969FF696969FF696969FF696969FF6969 69FF696969FF69696969696969FF696969FFFF6969FF696969 FF69696969FF69696969696969696969696969FFFF696969FF 696969FFFF6969696969696969696969696969696969696969 696969FF6969696969696969696969FF69696969696969FF69 FF6969696969FF696969FF696969FF6969FFFF696969FF69FF 69FF696969FF69FF69FF696969FF696969FF69FF69FF69FF69 FF69FF69FF696969FF6969696969FF69FF69FF69FF69FFFF69 696969FF69FF696969FF69696969696969FF696969FF696969 FF696969 RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET RESET FFFFFFFFFFFFFFFFFFFFFFFFFF6969FFFF69FFFFFF6969FFFF 6969FF69696969696969696969696969696969696969
now we will try 1240 delay
69696969696969696969696969696969696969696969696969 69696969696969696969696969696969696969696969696969 69696969696969696969696969696969696969696969696969 696969696969696969FF6969696969696969696969FF696969 69696969696969696969696969696969696969696969696969 69696969696969696969696969696969696969696969696969 69696969696969696969696969696969696969696969696969 69696969696969696969696969696969696969696969696969 69696969696969696969696969696969696969696969696969 69696969696969696969FF6969696969696969696969696969 69696969696969696969696969696969696969696969696969 69696969696969696969696969696969696969696969696969 69
now we will try 1241 delay
69696969696969696969696969696969696969696969696969 69696969696969696969696969696969696969696969696969 69696969696969696969696969696969696969696969696969 69696969696969696969696969696969696969696969696969 69696969696969696969696969696969696969696969696969 696969696969696969696969FF696969696969696969696969 69696969696969696969696969696969696969696969696969 69696969696969696969696969696969696969696969FF6969 696969696969696969696969696969696969FF696969696969 69696969696969696969696969696969696969696969696969 69696969696969696969696969696969696969696969696969 69696969696969696969FF6969696969696969696969696969 69
now we will try 1242 delay
69696969696969696969696969696969696969696969696969 69696969696969696969696969696969696969696969696969 69696969696969696969696969696969696969696969696969 69696969696969696969696969696969696969696969696969 69696969696969696969696969696969696969696969696969 69696969696969696969696969696969696969696969696969 69696969696969696969696969696969696969696969696969 69696969696969696969696969696969696969696969696969 696969696969696969696969696969696969FF696969696969 69696969696969696969696969696969696969696969696969 69696969696969696969696969696969696969696969696969 69696969696969696969696969696969696969696969696969 69
now we will try 1243 delay
696969696969696969696969696969696969696969696969FF 69696969696969696969696969696969696969696969696969 69696969696969696969696969696969696969696969696969 696969696969696969FF696969696969696969696969696969 69696969696969696969696969696969696969696969696969 69696969696969696969696969696969696969696969696969 69696969696969696969696969696969696969696969696969 69696969696969696969696969696969696969696969696969 69696969696969696969696969696969696969696969696969 69696969696969696969696969696969696969696969696969 69696969696969696969696969696969696969696969696969 69696969696969696969696969696969696969696969696969 69
now we will try 1244 delay
vBulletin® v3.8.4, Copyright ©2000-2009, Jelsoft Enterprises Ltd.