View Full Version : Finally Rom 10 A23 POPPED!!!
Crazy1_79
11-06-2004, 08:41 PM
I finally had success with a rev A23, It wasn't either of my two that I have but I finally did open a A23, the strange thing was that is gave me 69ff69ff69ffff instead of the 6f, it was last in the data stream November 3 and it was a A2013 that is about all I can say, I did the test glitch, took those setting and put them into the unlocking program and then lowered the delay all the way to 1100 and all the way to 127A it only took about a minute and a half, now I'm onto the other cards I need to unlock and they seem to be back to the 6fff reading, will post if I have any luck.
LuckLarry
11-06-2004, 10:23 PM
Good job...I find A23 the easiest, A81 more difficult, and 383's impossible. Don't really care about rom3, because I only have a few. Popped 40 plus rom 10's now.VCC is everything!
Crazy1_79
11-06-2004, 10:28 PM
I agree, I ran test glitch just like you said, put those number in the unlock script and opened the delays to min and max, took only a minute or two, now I am back to struggling with the other cards
majdiaz
11-07-2004, 12:07 AM
I agree, I ran test glitch just like you said, put those number in the unlock script and opened the delays to min and max, took only a minute or two, now I am back to struggling with the other cards
OK, guys, can you tell me how to proceed from scratch? I mean what program are u using and what steps????
Thanks!!!
LuckLarry
11-07-2004, 12:08 AM
OK, guys, can you tell me how to proceed from scratch? I mean what program are u using and what steps????
Thanks!!!
Do you have a modded loader? If so, what kind? Nothing will work unless you have a modded loader.
majdiaz
11-07-2004, 01:12 AM
Do you have a modded loader? If so, what kind? Nothing will work unless you have a modded loader.
NO, not yet: you answered my question> Thanks!!!
bendoverdave
11-07-2004, 01:22 AM
Dujaa from another testing site said that you can glitch an A23 locked rom 10 with just jumping a 220 ohm 1/2 watt .5% tolerance resistor at ATMEL chip on pins 6 and 8 and then testing scripts with adjusting the VCC and delay starts.
I know, know. Far fetched huh?
It's all about testing....
LuckLarry
11-07-2004, 02:26 AM
I don't think thats too likely. One of the things the mod does is change the clock cycle, and a simple resistor mod can't do that.
bendoverdave
11-07-2004, 08:54 AM
I fixed my card and IRD about 1 1/2 weeks ago from the last ECM. I had used the nomore64-7 and unlocked my card with a personal password. I then cleaned and added new channel tiers with no PPV and then added (by accident) the nomore64-7ppvmaster blocker and for some reason when I inserted into IRD, my CAMID was all zeros.
So I went back to cleaning the card and after I entered the password for the blocker, it gave the "BD3 login failed" error in NagraEdit. I checked the ATR and said "CAM date request failed".
So here I am. I was trying to mod my Ultra T911 with all the information floating around but it's kinda confusing.
Oh well, that's testing.
chip2004
11-10-2004, 06:54 PM
crazy...you have a pm
Crazy1_79
11-10-2004, 10:28 PM
chip you have a pm, well guys, I got one out of 5 cards to pop, can't get the other ones for the life of me, I can pop rom 3's but not rom 10's except for the above one, I used flash 7 to do that one, on the other ones, I can't get flash seven to get anything but resets, so I have to use 9, I also tried 8, but just can't get anywhere, I have changed resistance vcc settings, delays, you name it I tried it, If anyone can think of anything else, please let me know.
t160hq
11-11-2004, 12:21 AM
Try
vcc start &H60
vcc limit &H50
Most of the rom 10's i popped I used the default settings on a AIO and they popped in minutes.
Only one gave me problems and using the settings above it popped in minutes. I was using flash 8 on the atmel. I then adjusted the pot for a nice mix of 6F and FF with maybe the occacional RESET.
It popped in about 15 minutes.
t160hq
Crazy1_79
11-11-2004, 12:25 AM
T160HQ, it is funny you said that, I just entered 61 and 4F into my winexplorer script using flash 8 right as I got email that you posted this, I have the script running now, I will post results. Thank you. Glith analyzer gave me those two settings, I am using that new script in the download section that has the analyzer and opener all in one script, has anyone tried this script? I am hoping it is not a hoax. but it looks legit,
ismarhadzia
11-11-2004, 02:11 AM
Anybody knows how to resolve this problem.
This was initialy Stream locked card.
I tried running new unlockers for Rev81 with moded loaders.
but this A81 shows CamID: 00 00 00 00 which is weard and I dont have any success while unlocking.
I am using A81/A23 unlocker V 1.0
I was successful on my other card revA23 wich opened with no porblem in few minutes.
Opening of COM1 was successful
ATR String: 3F FF 95 00 FF 91 81 71 A0 47 00 44 4E 41 53 50
30 31 30 20 52 65 76 41 38 31 43
ROM Revision: 010
EEPROM Revision: RevA81
ProviderID: 08
CamID: 00 00 00 00
Using BD3 Key: 4E 69 70 50 45 72 20 49 73 20 61 20 62 75 54 74
Attempting to login to BD3
BD3 login failed
Reading ROM10 failed
Closing of COM1 was successful
brownman
11-11-2004, 06:54 AM
anyone in here selling the moded t911 ? please send me an pm with the price
Crazy1_79
11-14-2004, 07:31 PM
Just to update everyone, after a few weeks of pulling my hair out and trying every variation off resitance and vcc limit that I could possibly think of, I have popped two more A23's making it a grand total of 3. Here is my findings on all of it, Using the t911 black board in the clear case with a single turn 5 K trimmer from rat shack. I used newd9 for the flash, this is where it gets tricky, I could glitch into rom 3's at 378 ohms getting a good mixture of aaaafffff's therefore allowing me to pop all rom 3's I had laying around, I was using a 9volt 300MA power supply, now with the rom 10's I could only get 6f's at 378 ohms so I had to lower the resistance to around 100 ohms to get a good mix of 6f,ff's It looked great but it wouldn't open them, Finally after weeks of playing with voltage, resistance, and DC power input I have come to this, I set the pot for 348 ohms, 7.5 volts, 300 MA input to the loader, flash newd9 and using 10 for the vcc start and FFFF for the limit I have popped two cards in about 5 minutes or less. Regardless of what the script was giving me they still opened.
anthony101
11-15-2004, 05:52 AM
crazy email me the flashes and what not and a quick how too i finally got mine modded and curios to see how it works i could read and read but i know you could sum it up for me would you please
sukh77
11-15-2004, 06:06 AM
A little off topic from T911. Guys I have an Iso programmer. I had a rom10 that I could not open with my password it was at A23. I tried a winexplorer script that is posted in the files section labeled (PowersyncUnlockRom10ver3.zip) I ran it for little bit it was set to echostar programmer in winexplorer and it was running the various voltage tests I think. I aborted it during the third variation I think. Then the next day tried to see where the card was did a reset on the card the rev was at A21. Then I used the A21 rom popper script to unlock it from there and it worked. I don't know what the deal was. I have few other rom10 that I didn't program but are at rev A23 but have yet to unlock those I ran the same process on one so far but no success. Anyone else experience this or did I just get lucky.
alwayswatching
11-15-2004, 06:44 AM
I finally had success with a rev A23, It wasn't either of my two that I have but I finally did open a A23, the strange thing was that is gave me 69ff69ff69ffff instead of the 6f, it was last in the data stream November 3 and it was a A2013 that is about all I can say, I did the test glitch, took those setting and put them into the unlocking program and then lowered the delay all the way to 1100 and all the way to 127A it only took about a minute and a half, now I'm onto the other cards I need to unlock and they seem to be back to the 6fff reading, will post if I have any luck.
hey how are you doing long time since ive been here hope everything is ok with you and yours any way the reason im back is that i tryed that t911 mod but nowmy t911 is not being reconized i was wondering with those mods do you have to lift any of the pins on those chips we connect to like 7or 4 or any one my t911 is not doing anything when i try ti get the vcc measurements it says please insert your card and the card is already in there any info you can give me would be appreciated thanks again i hope to talk to you soon take care bud
Crazy1_79
11-17-2004, 01:42 PM
no pins need to be lifted, are you using the black board, clear case model? or are you using a different model. With the blue board and the black board no pins need to be lifted. but I would triple check your trace cuts around the pin near the front the loader that has the jumper going to to the atmel chip and to the dip switches, I was getting time out errors untill I recut those. also make sure you are getting a good flash. What flash program are you using? if you are using xpatmel right click on the bar right below the window where the flashes are shown and it will ask if you want to show timing settings. click on that and change the timing to 60/50/1, make sure you change your settings in winex to the loader 2 setting in the readme that comes with the flashes. Throw me a few more details brother, exactly what are you getting. are you not recognized when you try to flash the chip? 1 and 5 are the dips that have to down to flash, 2 and 5 need to be down to unlock.
zakolo
11-18-2004, 02:05 PM
Guys,
Can any expert or a blind man like myself tell us how to mod a t911 in a step by step using simple language....TX:)
blknite
11-18-2004, 02:29 PM
no pins need to be lifted, are you using the black board, clear case model? or are you using a different model. With the blue board and the black board no pins need to be lifted. but I would triple check your trace cuts around the pin near the front the loader that has the jumper going to to the atmel chip and to the dip switches, I was getting time out errors untill I recut those. also make sure you are getting a good flash. What flash program are you using? if you are using xpatmel right click on the bar right below the window where the flashes are shown and it will ask if you want to show timing settings. click on that and change the timing to 60/50/1, make sure you change your settings in winex to the loader 2 setting in the readme that comes with the flashes. Throw me a few more details brother, exactly what are you getting. are you not recognized when you try to flash the chip? 1 and 5 are the dips that have to down to flash, 2 and 5 need to be down to unlock.
Crazy,
I have the t911 black board. I think it is referred to as a Nexus T911. I haven't been able to pop cards with this thing for the life of me. I was using the blue board and popped all rom10 cards I tried. But, in the mod instructions I followed for the black board I had to lift 2 pins. Pin 4 and 5 of the 74hc00 if I remember correctly. Are you sure that they are not suppose to be lifted? Here is the mod I followed.
DrSagan
11-18-2004, 06:05 PM
You guys need to stop worrying what color the board is, pay more attention to the layout of the chips and of course the traces.
blknite, I modded one of those and it is very hard to lift those pins and get all the trace solder out from under the pins, check that very carefully with a magnifying glass. Are you trying with rom10 or 3?
blknite
11-18-2004, 10:54 PM
All I did was test for continuity after the pin was lifted. Both were fine. I have noticed that with the first bunch of cards that I did with my other modded t911 popped almost immediately, but the last 5 or 6 cards that I have been working on I can't get them to pop for the life of me. All are rom10 a23's and are returning 6f6f6f6f6f etc. I am using a 10k single turn pot. Once I hit like 300 I start to get 6f's but I then can continue up to 5,6,7k and I still get 6f's. Anything bleow 300 or so just reset's. Change vcc, delay's etc. Not sure but was there anything else in the stream that was updated to change the areas that were glitching?? I have also changed flashes. I am lost as to why these won't pop. I have let them run as long as 3 days and still just get 6f's. Any help or input would be greatly appreciated.
BlkNite
DrSagan
11-19-2004, 12:06 AM
A little lost here, are you saying this loader used to work and now doesn't or ??
blknite
11-19-2004, 01:58 AM
I have 2 modded t911's. One is a typical blue board t911. The other 1 I have is a Nexus t911 or black board. The blue board t911 used to work very well. Then I started to have a few problems getting into cards. It was taking quite a while (hours) but would open them. I had a Nexus sitting around so I decided to mod it. I followed 1 of the schematics and double checked everything. It works just as it is suppose to as far as flashing and responses just doesn't open the cards. I ended up hooking the blue board back up and giving it a whirl again. Just having some issues with getting the last few cards open. 4 are returning 6f6f6f6f and the other is 69696969 which I have read is usually a blockered card.
DrSagan
11-19-2004, 02:07 AM
I don't have an answer for you, sorry. If you have a voltmeter, you might poke around and make sure the 7805 is still sending 5v and something hasn't happened to it and/or your power supply. I would bet you are using the same power supply for both. Wish I could help more...I haven't had a failure on mine yet so I don't know where to start looking :(
blknite
11-19-2004, 02:09 AM
Thanks for the help anyway. I did get 2 more cards today that popped within 5 minutes on my original t911. Just these other cards that I need to work on. I will check the voltage regulator though and make sure all is good.
BlkNite
t160hq
11-25-2004, 07:47 PM
I set the pot for 348 ohms, 7.5 volts, 300 MA input to the loader, flash newd9 and using 10 for the vcc start and FFFF for the limit I have popped two cards in about 5 minutes or less. Regardless of what the script was giving me they still opened.
Thanks Crazy1_79.
After reading this post I tried something similar on the only rom3 I have that just would not pop no matter what I tried. Figgured I had nothing to lose.
I used a modded wildthing with a 2.2k resistor instead of a pot. Flash was newd6. I used the orginal unlockrom3.xvb. The only changes I made in the script were:
VCCStart = &h10
VCCLimit = &hFF
Started up the script. I forget what the window was showing but it wasen't the usual readout for glitch tries. I just ignored it and let it run. Took about 3 hours then the card should be open message popped up in the winexplorer window.
Switched to nagra and tried to read the cam. Nagra reported it was still closed. Just on a whim I hit it with Nagra bug buster set for 512 a couple of times.
Tried reading again and it worked. Wrote a clean image and I'm using it now. So far it works like a champ.
t160hq
Crazy1_79
11-25-2004, 08:01 PM
t160hq, glad I could be of help, I have opened a couple more rom 10's, I have 2 that I just can't get open. have been playing with vcc's start and limit and ignoring what the script is giving me, I am getting all 6f's but that is what I got when I popped those two, all 6f6f6f6f and they still opened. I did get cocky and let one of my good rom 10 get streamlocked without a blocker and now that is one of them I can't get back open. I am still playing with it though.
stealth_315
11-28-2004, 03:35 PM
Do you have a modded loader? If so, what kind? Nothing will work unless you have a modded loader.
i have a t911 modded ..i just need to know what program to run to open rom 10 a23
and rom 3 383 cards ..and if you could step by step ..
thank you //
Can someone tell me where do i put the VCC cieling settings into and the floor..thanks
Executing Script: C:\DOCUME~1\jerry\LOCALS~1\Temp\Rar$DI00.203\VCC Analyzer v2.xvb
TX Data : 02 03 00
TX Data : 02 02 00
TX Data : 07 0E 03 10 01 03 9A 00
RX Data : 06 00
TX Data : 12 15 AB 21 00 08 A0 CA 00 00 02 12 00 06 55 0E
03 8B 00
RX Data : 03 00
VCC 30: XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX 6F = 0% FF = 0%
VCC 2F: XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX------------------------------------------------------------ 6F = 0% FF = 60%
VCC 2E: ---------------------------------------------------------------------------------------------------- 6F = 0% FF = 100%
VCC Ceiling: 32
VCC Floor..: 2C
ryanloon
12-01-2004, 10:34 AM
I have kickass clone programmer can i mod it and how ? Please help if possible. thank you.
Crazy1_79
12-01-2004, 10:37 AM
do a search for "how to mod your kickass clone" someone on this site has done it and posted the how too, I remember reading it.
lips905
12-01-2004, 11:49 AM
I finally had success with a rev A23, It wasn't either of my two that I have but I finally did open a A23, the strange thing was that is gave me 69ff69ff69ffff instead of the 6f, it was last in the data stream November 3 and it was a A2013 that is about all I can say, I did the test glitch, took those setting and put them into the unlocking program and then lowered the delay all the way to 1100 and all the way to 127A it only took about a minute and a half, now I'm onto the other cards I need to unlock and they seem to be back to the 6fff reading, will post if I have any luck.
Crazy1 You just opened a c700 password locked rom 10 bud :)
lips905
12-01-2004, 11:50 AM
Can someone tell me where do i put the VCC cieling settings into and the floor..thanks
Executing Script: C:\DOCUME~1\jerry\LOCALS~1\Temp\Rar$DI00.203\VCC Analyzer v2.xvb
TX Data : 02 03 00
TX Data : 02 02 00
TX Data : 07 0E 03 10 01 03 9A 00
RX Data : 06 00
TX Data : 12 15 AB 21 00 08 A0 CA 00 00 02 12 00 06 55 0E
03 8B 00
RX Data : 03 00
VCC 30: XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX 6F = 0% FF = 0%
VCC 2F: XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX------------------------------------------------------------ 6F = 0% FF = 60%
VCC 2E: ---------------------------------------------------------------------------------------------------- 6F = 0% FF = 100%
VCC Ceiling: 32
VCC Floor..: 2C
Ceileing=====START
Floor===========Limit
Crazy1_79
12-01-2004, 04:45 PM
Crazy1 You just opened a c700 password locked rom 10 bud :)
Well that's what I thought on the one card too lips, but here's a little food for thought, I had this other card I got from this guy, he cannot guarantee it was not password locked but was fairly certain it wasn't. Locked tighter than a drum at rev a23, he was using anarchy program to unlcock it, getting all 6f6f6f6fffffff6f6fff6fff and couldn't pop it. I took it home and stuck it in mine using winexplorer and I started seeing 6969ff69ff and popped it in a few minutes. Was it password locked? I don't know for certain but the discrepancies in the programs just ignite my curiousity just a bit. BTW, I seen the 6f6f6fffff in the anarchy program with my own two eyes so I know that is what it was doing.
lips905
12-01-2004, 09:00 PM
Well that's what I thought on the one card too lips, but here's a little food for thought, I had this other card I got from this guy, he cannot guarantee it was not password locked but was fairly certain it wasn't. Locked tighter than a drum at rev a23, he was using anarchy program to unlcock it, getting all 6f6f6f6fffffff6f6fff6fff and couldn't pop it. I took it home and stuck it in mine using winexplorer and I started seeing 6969ff69ff and popped it in a few minutes. Was it password locked? I don't know for certain but the discrepancies in the programs just ignite my curiousity just a bit. BTW, I seen the 6f6f6fffff in the anarchy program with my own two eyes so I know that is what it was doing.
I've unlocked a lot of password lock cards all of them give me the same response.69f. Some cards will take longer but one thing i guarantee is that pengas script will unlock any password lock,I had a card i loaded with st long ago and i coulden't get back in but now its open..
If you ever get these responses just let the card run ex:6f96f9
atr ok
fffffffffff
atr ok
6f96f9 and so on let it run
rubberman
12-02-2004, 09:31 PM
tell me how to pop an A21 rom10? i used all those programs and they say is its good to go but Niagra says its still closed.
Crazy1_79
12-02-2004, 10:30 PM
if you have a loader you can use sorry nagra, check the download section for any other files that will pop a rev 21, you can do that with a simple iso with some programs.
Crazy1_79
12-08-2004, 02:05 AM
Just to update, I have popped a couple more A23's, lost count of the grand totol, only ran across one that wouldn't pop, tried and tried but no go.
Crazy1_79
12-08-2004, 02:06 AM
Just to update, I have popped a couple more A23's, lost count of the grand totol, only ran across one that wouldn't pop, tried and tried but no go. just to let you know, I just acquired these cards yesterday, so I haven't had any to pop for awhile, I haven't had the nose to the grindstone like I did, I even made it through the forums a few times to answer some questions and to ask a couple. lol
Cid6.7
12-08-2004, 03:13 AM
There yah go Braggin again ..lol ;)
Crazy1_79
12-08-2004, 03:40 AM
hey, if you're good, you're good!
Crazy1_79
12-11-2004, 03:02 AM
Ok guys, I have to report the stubborn ass A23 I had, my buddy popped it with his loader using the Unlockallromver5 with the flashes that come with it and the delay set to the dealer locked setting. So between my buddy and me, we have popped all cards between us, He asked me to mention that he had a card that may have been blocker locked because it would only return 696969696969, it wouldn't return any ff even with resistance lowered and vcc lowered, even though it only returned 6969 it still popped for him using the ver5 unlocker and I believe he told me the dealer locked settings as well, He changed something else in Winexplorer but right now I am having a brain fart and will be damned if I can remember what it was set too. I will update when I find out, So hey guys, if you don't have that ver5 unlockanything program, get it, the flashes are updated and seem to be the shit. Thanks Cid for sending them to me.
Dr Zapola
12-11-2004, 03:13 AM
Where do we get Unlockallromver5
ZAPOLA
Crazy1_79
12-11-2004, 04:22 PM
here it is, the rom 10 is ver5 the unlockall is ver 2, I guess I missed that, I had big success with the unlockallver2. You also have to use the flashes with this program instead of the original flashes, so you need to put them into your flash program.
Dr Zapola
12-11-2004, 06:33 PM
Thanx for the proge man. I guess Iam a little slow but I got flashed d6 with switchs 1 and 6 on then I changed to switches 2 and 5 on, inserted the card open the winex proge, exacuite script, a windo pops up asking to choose Rom3/aslize/abort, I choose rom3, then it says insert card. So I opened switch5 and it started what seams to be working. It asked to inter some settings 4 times then started o6fo6fo6fo6fo6fo6f. Also iI tried with ass the switches off and it did the same. My question is can it work with the dip switches like this or am I just going mad. By the way I am using a NEXUS MODED T911.
ZAPOLA
Cid6.7
12-12-2004, 05:08 PM
Np Crazy Good to hear its workin fer yah..!!
stealth_315
12-12-2004, 08:25 PM
i have tried it but it wants me to enter (please enter VCC high ) what would i put .? and also (VCC LOW) help please
stealth_315
12-12-2004, 08:44 PM
I got it it tells you what to put thanks
Crazy1_79
12-12-2004, 09:26 PM
Thanx for the proge man. I guess Iam a little slow but I got flashed d6 with switchs 1 and 6 on then I changed to switches 2 and 5 on, inserted the card open the winex proge, exacuite script, a windo pops up asking to choose Rom3/aslize/abort, I choose rom3, then it says insert card. So I opened switch5 and it started what seams to be working. It asked to inter some settings 4 times then started o6fo6fo6fo6fo6fo6f. Also iI tried with ass the switches off and it did the same. My question is can it work with the dip switches like this or am I just going mad. By the way I am using a NEXUS MODED T911.
ZAPOLA
with the nexus mod it may be different than the other t911's I'm not sure, I use 2 and 5 to glitch but I also forgot to flip the switches and left it at 1 and 5 to program and it popped a card, if you are getting 6f06f060f you are on the right track, let it run for a few hours and see what happens.
Dr Zapola
12-12-2004, 10:28 PM
Nothing but FFFFFFFFFFFFFFFFFFFFFFFFFFFFF OR 6F6F6F6F6F6F6F6F6F6F6 OR F6F6F6F6F6F6F6F6RESET 6F6F6F6F6F6F6F6F6F6F6F6RESET 6F6F6F6F6F6. I dont want to change my pot setting of 2.2k so hell I am lost. Thanx
ZAPOLA
Crazy1_79
12-12-2004, 10:47 PM
I have the T911 black board clear case model, I hit the bugs on test glitch at 378 ohms, I have popped rom tens at 144 ohms. I am not certain what loader you have but I am just showing you that 2.2k ohms is a starting point, it isn't chiseled in stone, If you have a ohm meter you can put it back whenever you want.
stealth_315
12-14-2004, 11:49 PM
i am still trying to pop a23 rom 10 ...
what flash do we use and please what are the settings ...
Crazy1_79
12-15-2004, 01:57 AM
Hey stealth I have been meaning to pop in here with my new findings. Using the flash D9 with the powersyncunlockallver2a I have popped several rom 10's, but here is the kicker when you put in your maximum delay setting, (127E is suppose to be the max) and the program gets to your max, it just keeps going. I have the setting here that I used to popped the last three, I must first say I have the T911 black board clear case model so my resistance was around 145-155 ohms for all of these, I had one card pop at Vcc of 0A and a delay of 129B, another at Vcc 0A delay of 13E3 and a third one at vcc of 07 and a delay of 12E9 I use 10 for my start and 0 for my limit when I start the program, as you can see these three cards popped well beyond 127E but they are falling open for me so I will take it, Just thought I would update everyone on this strange phenomenom!! LOL
stealth_315
12-15-2004, 04:00 AM
i have tried it and all i get is this
FFFFFFFFFFFFFFFFF RESET FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
PowersyncUnlockRom10ver5a Testing Chuck Rom10
now we will try 1246 delay
FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF RESET FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF RESET FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF RESET FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF RESET FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
PowersyncUnlockRom10ver5a Testing Chuck Rom10
now we will try 1247 delay
FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF RESET FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFF
PowersyncUnlockRom10ver5a Testing Chuck Rom10
now we will try 1248 delay
FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFF RESET FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF RESET RESET RESET FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF RESET FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFF
PowersyncUnlockRom10ver5a Testing Chuck Rom10
now we will try 1249 delay
FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFF RESET FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
PowersyncUnlockRom10ver5a Testing Chuck Rom10
now we will try 124A delay
FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFF RESET RESET RESET FFFFFFFFFFFFFFFFFF RESET FF RESET
Script Error on Line 427
Script Aborted By User
whats wrong ....?????
Cid6.7
12-15-2004, 04:09 AM
Turn up your VCC Setting's..I was just getting that aswell
If you have a POT on your loader turn it up untill you get 6F's..I just popped my 1st A23 in about 10 minutes.It took me longer to get it to A23 then it did to unlock it..lol
Dark_1
12-15-2004, 06:54 AM
I am new to alot of this and dont have a programming background, but I have popped 2 a23's and have a buddy that is going to send me a couple 383's to try. A few questions.
I modded my t911(blue case and board) set the 5k trim pot to 2.2k and ran the powersync unlocker ver 3 with flash 9 and my power supply set at 7.5 volts...got both cards within minutes. I didnt change anything else, the replays were mostly 6f's with a few resets, no ff's. I am not one to complain about dumbluck, but would just like to be better armed if I run into some tougher cards. So my questions are...
What are the vcc changes actually doing?
Does the power supply voltage setting matter?
What is the pot resistance changing? and anything else that you can throw at me to expand my brain...
I also want to take a minute and say, this hobby ROCKS!, sure free TV is good, but the best part of it is the challenge/learning and the commeradery that is shown between testers.
Thanks to all that contribute and educate!
Crazy1_79
12-15-2004, 09:59 PM
The vcc setting actually the voltage going to the card, the higher the vcc the more voltage, these are minute changes that can't be measured with a voltmeter, but a little helps.
You loader has a 5 volt voltage regulator that will maintain it at 5 volts or right around there so voltage shouldn't be much of a issue although I have seen where stubborn cards will pop if you drop the voltage from 9 to 7.5, don't know why but people have posted that.
Changing the resistance to the pot will also raise or lower the voltage to the card, it is doing something similiar to the VCC settings, try working with settings before adjusting the pot if at all possible.
bowman
12-15-2004, 10:39 PM
crazy,,,,, with your modded t911 can youpop Rom-3" ? ,,
Bow
Cid6.7
12-16-2004, 01:02 AM
Yes I believe he said he can do it..I'm waiting on a couple cards to try mine out..Should be here in a few day's..W()()T
If their not locked when I get them I'll update just to unlock as I did with my ROM10..lol
bowman
12-16-2004, 03:21 AM
i can do rom 10's with mine t911 but cain't get the rom 3 to hit the oc bug ,, ?
Bow
Crazy1_79
12-16-2004, 04:00 AM
yes I can pop rom 3's but it takes a hour or more a card
lips905
12-16-2004, 09:11 AM
Hey crazy1 .You sure wish you held on to those cards you sent me HEH!!! (loL) :) :p
Crazy1_79
12-16-2004, 02:12 PM
Hey crazy1 .You sure wish you held on to those cards you sent me HEH!!! (loL) :) :p
I needed the box keys of one, and I'm sure I donated to the cancer society through you, so what the hell lips, no harm no foul. oh yah one more thing, they weren't for me, they were someone I know wo it didn't cost me anything! So I guess I didn't really donate, but I made the sale that did!
bowman
12-16-2004, 03:56 PM
hello crazy1,, i for some-reason can't get the oc bug to hit , i get all kinds of of bugs , any sugestions you might have ??
Bow
Cid6.7
12-16-2004, 04:05 PM
bowman have tried powersyncunlockallver2a.xvb ??
Crazy1_79
12-16-2004, 04:10 PM
So you hit the of bug? try a minor adjustment to your pot, about 5 ohms higher I would guess if that don't work, try about 5 ohms lower.
bowman
12-16-2004, 04:31 PM
thanks crazy1 , will give it a shot ,,
Bow
Crazy1_79
12-16-2004, 04:34 PM
also bowman, maybe you have a bad flash to the chip, if you are using xpatmel make sure you set the timing settings to 60/50/1 respectively.
bowman
12-16-2004, 11:27 PM
crazy1 are you using 2 and 5 on the dip switch'es ?
Bow
Dr Zapola
12-16-2004, 11:32 PM
Crazy1_79 when I went to that area in the flash and it has an analyze button so I hit it and it came up with a different set up. Should I still use your suggestion or the analyzed one?
ZAPOLA
Cid6.7
12-17-2004, 12:01 AM
Crazy's outa town for a bit tryin his luck in Vega's..
Dips 2 & 5 should be on yes...Dr Zapola in XPAtmel right click just under the top window right about where it says COM1: right click & a window will appear that says show timing setting's click on it the 3 small windows will apear... type in 60 50 1 in that order..then flash..
bowman
12-17-2004, 01:56 AM
Finally got it !!!!!!!!!! Thanks alot guys ,, crazy1 ,,cid6.7 ,, the biggest mistake i was making was ,,turring the pot up to far ,,started at 2.2,, did what crazy1 told me to do turned it down a little 2.14 and bam it hit ,,,,, a big thanks again guys !!!!!!!!
Bow
Cid6.7
12-17-2004, 02:07 AM
right on glad I could help..
lips905
12-17-2004, 04:37 AM
I needed the box keys of one, and I'm sure I donated to the cancer society through you, so what the hell lips, no harm no foul. oh yah one more thing, they weren't for me, they were someone I know wo it didn't cost me anything! So I guess I didn't really donate, but I made the sale that did!
Hey crazy you know I'm just fucking around. :)
Dr Zapola
12-17-2004, 04:46 AM
Got one guys. Even with this reset stuff. What the Fuuuu THANX a million.
ZAP
now we will try 1244 delay
FFFF6F6F6F RESET FFFFFF6FFFFF6F RESET FFFFFF6FFFFF6F6FFFFF6FFF6FFFFF6F RESET 6F RESET FFFFFFFFFFFF6FFFFFFF6F RESET FFFF6FFF6F RESET 6FFFFF6F RESET 6F RESET FF6F6FFF6F RESET 6F RESET FFFFFF6F RESET FFFFFF6F RESET FFFFFFFFFF6F RESET FF6F RESET FFFFFF6F RESET 6F RESET 6F6F6F RESET FF6F RESET FF6F RESET FF6FFFFFFFFF6FFFFFFFFF6F RESET FFFFFFFF6F RESET FFFF6FFFFFFFFFFF6F RESET FFFF6F RESET 6F RESET FF6F RESET FFFFFF6F RESET 6F RESET FFFFFFFFFF6F6F RESET 6F RESET FF6F RESET 6F RESET FFFFFFFF6F RESET 6F6F RESET FFFF6F RESET 6F RESET 6F RESET 6FFFFFFF6F RESET FF6FFF6F RESET FF6F RESET 6F RESET FFFFFFFFFF6F RESET FF6F RESET 6F RESET FF6F RESET FFFFFF6F RESET FFFFFFFFFF6F RESET FFFFFF6F RESET FF6F RESET 6F RESET FF6F RESET FFFFFF6F RESET 6F RESET FF6F RESET FFFFFF6F RESET FFFFFF6F RESET FFFF6F RESET 6FFFFFFF6FFF6FFF6F RESET FFFF6FFFFFFFFF6F RESET FFFFFFFF6F RESET 6F RESET FFFF6F RESET 6F6F RESET 6F RESET 6F RESET FFFFFF6F RESET FF6F RESET FFFFFF6F6F RESET FFFF6F RESET FFFFFF6F RESET FF6F RESET 6F RESET FFFFFF6F RESET 6F RESET FF6F RESET FFFF RESET 6F RESET 6F RESET FF6F6F RESET 6F RESET 6F RESET FFFFFF6F RESET FFFFFF6FFFFFFFFF6F RESET FFFFFFFFFFFFFF6F RESET 6F RESET FFFF6F RESET FFFFFFFFFF
now we will try 1245 delay
6F RESET FFFFFFFF6FFF6FFFFFFFFF6F RESET FF6FFF6FFFFFFFFF6F RESET FFFFFF6F RESET FFFFFFFFFFFFFFFF6F RESET FFFFFF6F RESET FFFFFF6F RESET 6F RESET FF6F RESET FFFFFF6F RESET FFFFFF6F RESET FFFFFFFFFFFFFFFF6FFFFFFFFF6F RESET FFFFFF6F RESET FFFFFFFF6F RESET FF6F RESET 6FFFFFFF6F RESET FFFFFF6F6F RESET FFFF6FFF6F RESET FFFF6F RESET FF6FFFFFFFFFFF6F RESET FF6F RESET 6F RESET 6F6F RESET 6F RESET FFFFFF6F RESET 6F RESET FF6F RESET FF6F RESET 6FFFFFFF6F RESET FF6F RESET FFFFFFFFFFFFFF6F RESET 6F RESET FFFFFFFFFFFFFFFFFFFFFF6F RESET 6F RESET 6F RESET 6FFFFF6F RESET 6FFF6F RESET 6F RESET FFFFFF6F RESET FFFFFFFFFFFFFF6F RESET FFFFFF6F RESET FF6F RESET 6F6F6F RESET FF6F RESET FFFFFFFFFFFFFFFFFF6F RESET FF6F RESET FF6F RESET 6F RESET 6F RESET FFFF6F RESET 6FFFFF6F RESET 6F RESET FF6F RESET FF6F RESET FFFFFF6F RESET 6F RESET 6F RESET FF6FFF6F RESET FF6F RESET FF6FFF6FFFFFFFFF6F6F RESET FFFF6F RESET FFFF6FFFFF6F RESET FF6F RESET FFFFFFFFFFFFFFFF6F RESET 6FFFFFFFFFFFFFFF6F RESET FF6F RESET 6F RESET 6FFFFF6F RESET FFFFFFFFFF6F RESET FFFFFF6F RESET FFFFFF6F RESET FFFF6F RESET FF6F RESET 6F RESET 6F RESET FF6F RESET FFFF6F RESET 6FFFFF6F RESET FF6F RESET 6F RESET FF
now we will try 1246 delay
FFFFFFFF6FFFFF6F RESET 6F RESET FFFFFFFFFF6F RESET FF6F RESET FF6F RESET FFFFFF6F RESET FFFFFF6FFFFFFFFF6F RESET FFFFFF6F RESET FFFFFF6F RESET FFFFFFFFFFFFFFFFFF6F RESET FFFFFFFF6FFFFF6F RESET FF6F RESET 6F6F RESET FFFFFFFF6F RESET FF6F RESET FF6F RESET FFFF6F RESET FF6F RESET 6F6F RESET 6F RESET 6F6F RESET 6F RESET 6F RESET FF6F RESET FFFFFFFF6F RESET FFFF6F RESET FFFFFFFFFF6F RESET FF6FFF6F RESET 6F RESET FF6F RESET FF6F RESET FF6F RESET 6F RESET 6F RESET 6F RESET FFFFFFFF6F RESET FFFFFF6F RESET 6F RESET FF6F RESET 6F RESET FFFFFFFF6F RESET FF6F RESET FFFF6F RESET 6F RESET FF6F RESET 6F RESET FFFF6F6F RESET 6F RESET FFFFFFFF6F RESET FFFFFFFFFFFFFFFFFF6F RESET 6F RESET FFFFFF6F RESET 6F6F RESET FFFFFFFF6FFF6F RESET FFFFFFFFFF6F RESET 6F RESET 6F RESET FFFFFF6F RESET 6FFFFF6FFFFFFFFF6F RESET 6F RESET FFFF6F RESET 6F RESET 6F RESET 6F RESET FF6F RESET FFFFFF6F RESET FFFFFF6F RESET 6F RESET FFFFFFFFFFFF6FFF6F RESET FFFF6F RESET 6F RESET 6F RESET 6FFFFF6F RESET FFFF6F RESET FFFFFFFF6FFFFFFFFFFFFF6F RESET 6F RESET 6FFFFFFF6F RESET 6F RESET FF6F RESET FFFFFF6F RESET 6F RESET FF6FFFFFFFFF6F RESET FFFFFF6F RESET 6F RESET FFFF6F RESET FFFFFFFF6F RESET FF6F RESET FF6F RESET 6F RESET FFFFFFFFFFFFFFFF6F RESET 6F RESET FF6F RESET 6F RESET FF6F RESET FF
now we will try 1247 delay
6F RESET FFFFFFFFFFFF6F RESET FFFFFFFFFFFFFF6F RESET 6FFF6F RESET FFFF6F RESET 6F RESET FF6F RESET FF6F RESET FFFF6F RESET FFFFFF6FFFFF6F RESET FF6FFFFFFFFF6F RESET 6F RESET 6F RESET 6F6F RESET 6F RESET FF6F RESET 6F RESET FFFFFF6F RESET FFFFFF6FFFFFFFFF6F RESET FFFFFF6F RESET FFFFFF6F RESET 6F RESET FF6F RESET FFFFFF6F RESET 6F RESET FF6F RESET FF6F RESET 6FFFFF6F RESET FF6F RESET FFFFFF6F RESET FFFF6F RESET 6FFF6F RESET FF6F RESET FF6F RESET 6FFFFF6F RESET FFFF6F6FFFFFFFFFFF6F RESET FFFF6FFFFF6F RESET FFFF6F RESET FF6F RESET FF6F RESET FFFFFFFFFFFFFF6F RESET FFFF6F RESET FFFF6F RESET FFFFFFFF6F RESET FFFF6F6FFFFFFF6F RESET FFFFFF6F RESET 6F RESET FF6F RESET FF6F RESET 6FFFFFFFFF6F RESET 6F RESET 6F RESET FFFFFFFF6F RESET 6F RESET FFFF6F RESET 6F RESET 6F RESET FF6F RESET FFFFFFFFFFFFFF6F RESET FFFF6FFFFF6F RESET FFFFFF6F RESET 6F RESET FFFF6F RESET FFFFFF6F RESET FF6F RESET FF6F RESET 6F RESET FF6F RESET FF6F RESET FF6FFFFF6F RESET FFFFFF6F RESET FFFFFF6F RESET 6F6F RESET 6F RESET FFFFFF6F RESET 6F RESET FF6F6F RESET FFFF6F6F RESET FFFF6F RESET 6F RESET FF6F RESET FF6F RESET 6F RESET FF6F RESET 6FFF6F RESET 6F RESET 6F RESET FFFFFFFFFFFFFF6F RESET 6F RESET FFFFFF6FFFFF6F RESET FFFFFF6F RESET FFFFFFFFFFFFFFFF6F RESET FFFFFF6F
now we will try 1248 delay
RESET FFFF6F6F RESET FFFFFF6F RESET FFFFFFFFFF6F RESET FFFFFF6F RESET FF6F6F RESET FFFF6F6F RESET FFFF6F RESET 6F RESET FFFFFFFF6F RESET FF6F RESET 6F RESET 6F RESET FFFFFF6FFFFFFFFFFFFFFFFFFFFF6F RESET FFFF6F RESET FFFFFFFF6F RESET FFFFFF6F RESET 6F RESET 6FFFFF6F RESET 6F RESET 6F RESET FF6F RESET FFFFFF6F RESET 6F RESET FF6F RESET 6F RESET FFFF6F RESET 6FFF6F RESET 6F RESET FF6F RESET 6F RESET FFFF6F RESET FFFF6F RESET 6F RESET FF6F RESET FFFFFF6F6FFFFFFF6F RESET FFFFFFFFFFFFFFFFFF6FFF6F RESET 6F RESET FFFFFFFFFFFFFF6F RESET 6F RESET FFFF6F RESET 6F6F RESET FF6F RESET FFFF6F RESET FFFFFF6F RESET FFFFFF6F RESET FFFFFF6F RESET 6FFFFF6F RESET FFFFFF6F RESET 6F RESET FFFFFF6F RESET FF6F RESET FFFFFF6F RESET FFFFFFFFFF6F RESET FF6F RESET FFFFFF6F RESET FFFFFF6F RESET FFFFFFFF6F RESET FFFFFF6F RESET 6F RESET FF6F RESET FFFF6F RESET FFFFFF6F RESET 6F RESET 6FFFFFFFFFFF6F RESET FFFFFFFFFFFFFFFF6F RESET 6F RESET FF6F RESET 6F RESET FF6F RESET 6F RESET FF6F RESET 6F RESET FFFFFF6F RESET FF6F RESET 6F RESET 6F RESET FFFFFFFF6F RESET FF6FFF6F RESET FFFF6F RESET 6F RESET FF6F RESET FFFF6F RESET FF6F RESET 6FFF6F RESET 83
*********** we hit our bug *************
1200078303
===========================================
83 was hit at 1248 delay ----VCC WAS 23
TX Data : 0A 15 A3 21 92 00 B3 0E 03 85 00
RX Data : 0A 06
RX Data : 12 92 00 80 21
***************************
* A23 CAM should be OPEN *
* test in Nagra to see. *
* if not, try again. *
***************************
lips905
12-17-2004, 04:49 AM
Glad to see that Dr .Keep up the good work
Cid6.7
12-17-2004, 06:06 AM
Dr if you get reset again turn the pot up untill the rest stops
Dr Zapola
12-17-2004, 07:46 AM
The wild thing is I did at diffrent points. This is what so fucked up about this modded stuff, nothing is never the same. Its like luck of the draw. I adjusted the pot to stop the resets and is was clear when I left the computer but when I came back to check about one and a half houres later it had opened this way. Seeing all these resets flip me out because it was my understanding that it only happened when there is somehow a bad glitch. Hell who knows.
ZAPOLA
Cid6.7
12-18-2004, 06:04 AM
No 2 cards are going to glitch exactly the same so I dont understand how the testglitch is supposed to work...When you get the settings for the OPEN card who's to say its gonna work on the locked card.. :D
DrSagan
12-18-2004, 09:15 PM
It just gives you a decent starting point on your rom3's.
stinkfist
12-18-2004, 09:50 PM
I bought a Mikobu 111 that has been modded. I have not had any luck with it with my rom 10 a23 cards. I have flashed it to newd8 flash that they gave me. I have let it try for two hours now and nothing. I have read that you need to change the VCCstart and VCClimit and try again. But I am not sure what to change to. In the winexplorer script that they gave me has this in it.
VCCStart = &h1A 'YOU CAN CHANGE THIS FROM 18-30
VCCLimit = &h13 'YOU CAN CHANGE THIS FROM 10-20
DelayStart=&h123E 'DISH A23 is 123E- could be as low as 1100
DelayEnd = &H125A 'DISH A23 IS 125A- could be as high as 127A
TryCnt = 300 'Number of tries per delay FROM 5-50000
TestMode = 0 'TestMode, 1 = ON, 0 = OFF
'TestMode is used to find a glitch point on A81 cam. once you find the
'delay and vcc settings on cam then set TestMode = 0, and open the cam
But I have read in this thread that you should change the VCCstart to 50 and the VCClimit to 60. But the script I have will not let me go this high just to 30 and 20. What setting would you recomend and should I try the newd9 flash?
DrSagan
12-18-2004, 11:12 PM
forget what it says about the limits.... you should run vcc analyser and see what vcc's your loader/cards like.
stinkfist
12-18-2004, 11:48 PM
Where is the VCC analyzer? Thanks :) :)
Cid6.7
12-19-2004, 12:11 AM
Where is the VCC analyzer? Thanks :) :)
Right here...I wont leave it up long...
stinkfist
12-19-2004, 12:43 AM
Great thanks. :) What parameter settings do I put the script on. Same as the rom opener? Do I need to leave the card in?
stinkfist
12-19-2004, 01:09 AM
Ok this is what I got with the vcc analyzer.VCC Ceiling: 26 VCC Floor..: 10. Is the Ceiling the vcc start and the VCC floor the vcc limit? All I get when I run the opener is RESET RESET over and over. Is this what it should be doing. Thanks :) :)
stinkfist
12-19-2004, 06:36 AM
I want to thank everyone for the great help I popped all but one. :) :) :) The one I cannot get gives me this.
now we will try 1240 delay
FFFFFF69FFFFFF69FF RESET FFFFFFFFFF RESET FF RESET FFFF RESET FFFFFF RESET 696969FF RESET FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF6969FF RESET 69FFFFFF RESET FFFFFF RESET FFFFFFFFFF RESET FFFF RESET FFFF69FF RESET FF69FF RESET FFFFFF RESET FFFFFFFF RESET FFFF RESET 69FFFFFF69FF69FFFFFFFFFF RESET FFFFFFFFFFFFFFFF RESET 69FFFF RESET FFFFFF RESET FF RESET FFFFFFFFFFFF RESET FFFF6969FF69FF RESET 69FFFFFFFFFF RESET FFFFFFFFFF RESET FFFF RESET FF69FFFFFF RESET FFFF RESET FFFFFFFFFFFFFF RESET FFFFFFFFFFFFFF69FFFFFFFFFFFFFFFFFF RESET FFFFFFFF RESET FF696969FF RESET FFFFFFFFFFFFFFFFFF RESET FF RESET FFFFFF RESET 69FF6969FF69696969FFFFFFFF RESET FF RESET FFFFFFFFFF6969FF RESET 69FF RESET FF RESET FFFF RESET FF RESET FFFF RESET FF RESET FF RESET 6969FFFF69FF RESET 69FFFFFFFF RESET FFFFFFFF RESET FFFFFFFFFF6969FFFF RESET FF RESET FFFF RESET FFFFFF RESET FFFFFF RESET FF RESET FF6969FFFFFFFFFF RESET FFFFFFFF RESET FF RESET FF RESET FFFFFF6969FF6969FF RESET FF RESET FF RESET FFFFFFFFFF RESET FFFFFF696969FFFF69FFFFFF RESET FFFFFFFFFFFF RESET FFFFFFFFFF69FF RESET 6969
@@@@@@@@@@@@@2 Testing Chuck Rom10 @@@@@@@@@@@@@
now we will try 1241 delay
69FFFFFFFFFF RESET FFFFFFFFFFFFFFFFFF RESET FF6969FFFFFFFFFF RESET FFFFFFFF RESET FF RESET FFFFFFFFFF69FF6969FFFFFF RESET FFFFFFFFFFFF RESET FFFFFFFFFF6969FF RESET FFFFFFFF RESET FFFFFFFFFFFFFFFF RESET FFFFFF6969FF69FFFF RESET FFFFFFFFFFFFFFFFFF RESET FFFFFF69FF RESET FF RESET FF69FFFFFFFF RESET FFFFFFFFFFFFFFFF RESET FF RESET 69FF69FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF RESET FF6969FF RESET FFFFFFFFFF RESET FFFFFFFFFFFFFFFFFF RESET 6969FF6969FF69FFFFFFFFFFFFFF RESET FFFF RESET FFFF RESET 6969FF69FF RESET FFFFFFFFFFFFFFFFFFFFFFFFFFFF RESET 6969FFFF69FFFFFFFFFFFFFFFFFFFF
Any ideas? Looped?
Cid6.7
12-19-2004, 07:27 AM
Turn your trimmer up a bit...Untill the resets stop...
DrSagan
12-19-2004, 11:37 PM
That appears to be a blocker locked card, lower your delays to ~1100......I usually set my delay to 1050-1150 on the blocker locked, your mileage may vary ;) Also newd9 flash helps with the reset issue.
stinkfist
12-20-2004, 01:11 AM
Great thanks again that worked. :) :) :)
Crazy1_79
12-20-2004, 05:45 PM
Glad to hear it bowman.
bowman
12-23-2004, 11:27 PM
crazy, i am not haveing any-luck with the rom 3's, with my nexus-t911, maby you might stear me in the right direction , thanks
Bow
Crazy1_79
12-23-2004, 11:38 PM
Hey bowman, if you can get the oc bug then you can unlock a rom 3. run testglitch again, when you get the oc hit, it will tell you delay and vcc, now when you run the unlocker on a locked card, keep resistance the same, start your vcc about 4 or 5 higher than the vcc that you hit your oc bug on. the same goes for limit, put it about 4 or 5 lower than the vcc you hit the bug at. Do the same thing with the delay, a little up and a little down. Be patient, don't be afraid to let the card run for 3 hours or more. If it doesn't pop then make the minute ohm adjustment we spoke about earlier, just 5 ohms or so. up or down, take your pick. if it don't hit, then try 5 below what you started with. The main key with rom 3's is patience, I know I stated a hour or so a card, but I have had them take 3 hours as well. I usually let it run while I sleep so I cannot give a precise time line so I am guessing merely by the lenght of the data from script. I know it is pages upon pages long. So don't rush it, patience is key.
derick881
12-24-2004, 12:11 AM
I loaded an open Rom 3 with the test glitch and am running the test program now (T911 flashed w/newd 6). I have tried two versions of the test program and both seem to be running incorrectly. all I am getting as far as output is "---try to hit OC bug at 10A2" This goes up to 10B5 and starts over again. Running for several hours and not getting any other type of output. I have tried pengas improved and powersyncallinone. It looks to me like they are in a loop but I can't tell if they are trying different Vcc's or delay timings. Anything I am missing here?
I am not a visual basic programmer but used to do Fortran and some basic in Dos ( I guess that ages me) and I have not been able to follow the logic in the program very well, I see in there somewhere where it should print "-" and "+" at some point . but I am not getting anything but the above so far after several hours running. I am thinking about getting ahold of a VB manual and see if I can't get some intermediate feedback in the program so I can see that it is working. It's just my impression that the program is in a loop somehow.
I am beginning to feel that it is in my T911. I bought it premodded from DM. I have checked and double checked the wiring and it matches up with photos posted here. I did find a couple of problems with the wiring popped lose from the traces and one trace maybe not cut completely thru. But I fixed those but have still not been able to pop one Rom or even get output like everyone is posting here. I have tried Rom 3 and Rom 10's.
I know I am running on but it seems like I am banging my head against a wall over the last couple of weeks. I will chalk it up to education if I can finally get it to work.
I have another question about xpamtel programming. I have always flashed with dips 1 and 5 on but I saw some thread that says dips 1 and 6 on to flash. Which is it. My flashes have all seemed to go well, even without changing parameters to 60,50,1 like advise given. It just doesn't seem to make any difference.
Crazy1_79
12-24-2004, 12:16 AM
lower you resitance, you need to do the 60/50/1 for atmel flash, it will tell you flashed successfully but will give you problems if you don't , dips 1 and 6, 1 and 5, 1 and 4, don't really see a difference on my end. Just dip 1 flashes as well. Lower your vcc, lower your trimmer, or try raising it. you should be getting responses from card, not just what you are getting, depending on what script you use you can get +++++------- or 6fo6f06f0 have even seen some weird 4040404 stuff but you are on the right track, If my resistance is too high I get what you are getting right now.
Crazy1_79
12-24-2004, 12:41 AM
I want to thank everyone for the great help I popped all but one. :) :) :) The one I cannot get gives me this.
now we will try 1240 delay
FFFFFF69FFFFFF69FF RESET FFFFFFFFFF RESET FF RESET FFFF RESET FFFFFF RESET 696969FF RESET FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF6969FF RESET 69FFFFFF RESET FFFFFF RESET FFFFFFFFFF RESET FFFF RESET FFFF69FF RESET FF69FF RESET FFFFFF RESET FFFFFFFF RESET FFFF RESET 69FFFFFF69FF69FFFFFFFFFF RESET FFFFFFFFFFFFFFFF RESET 69FFFF RESET FFFFFF RESET FF RESET FFFFFFFFFFFF RESET FFFF6969FF69FF RESET 69FFFFFFFFFF RESET FFFFFFFFFF RESET FFFF RESET FF69FFFFFF RESET FFFF RESET FFFFFFFFFFFFFF RESET FFFFFFFFFFFFFF69FFFFFFFFFFFFFFFFFF RESET FFFFFFFF RESET FF696969FF RESET FFFFFFFFFFFFFFFFFF RESET FF RESET FFFFFF RESET 69FF6969FF69696969FFFFFFFF RESET FF RESET FFFFFFFFFF6969FF RESET 69FF RESET FF RESET FFFF RESET FF RESET FFFF RESET FF RESET FF RESET 6969FFFF69FF RESET 69FFFFFFFF RESET FFFFFFFF RESET FFFFFFFFFF6969FFFF RESET FF RESET FFFF RESET FFFFFF RESET FFFFFF RESET FF RESET FF6969FFFFFFFFFF RESET FFFFFFFF RESET FF RESET FF RESET FFFFFF6969FF6969FF RESET FF RESET FF RESET FFFFFFFFFF RESET FFFFFF696969FFFF69FFFFFF RESET FFFFFFFFFFFF RESET FFFFFFFFFF69FF RESET 6969
@@@@@@@@@@@@@2 Testing Chuck Rom10 @@@@@@@@@@@@@
now we will try 1241 delay
69FFFFFFFFFF RESET FFFFFFFFFFFFFFFFFF RESET FF6969FFFFFFFFFF RESET FFFFFFFF RESET FF RESET FFFFFFFFFF69FF6969FFFFFF RESET FFFFFFFFFFFF RESET FFFFFFFFFF6969FF RESET FFFFFFFF RESET FFFFFFFFFFFFFFFF RESET FFFFFF6969FF69FFFF RESET FFFFFFFFFFFFFFFFFF RESET FFFFFF69FF RESET FF RESET FF69FFFFFFFF RESET FFFFFFFFFFFFFFFF RESET FF RESET 69FF69FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF RESET FF6969FF RESET FFFFFFFFFF RESET FFFFFFFFFFFFFFFFFF RESET 6969FF6969FF69FFFFFFFFFFFFFF RESET FFFF RESET FFFF RESET 6969FF69FF RESET FFFFFFFFFFFFFFFFFFFFFFFFFFFF RESET 6969FFFF69FFFFFFFFFFFFFFFFFFFF
Any ideas? Looped?
It's not looped, password protected, try the delay settings of 0C20 and 0C40 if that don't work try 1100 and let it go from there, don't care what your limit is as long as you start from 1100,
bowman
12-24-2004, 01:33 AM
thanks crazy,, here i my setting's,,, could you give me an idea ,,,,,,,,,,,,,,,,, vcc=h03
glitch type=h05
glitch delay=h10A5
thanks
Bow
booya
12-24-2004, 03:02 AM
Anybody near Arizona that can pop a few rom 10's Two are streamlocked "card may contain update" and one the backdoor is closed... I also have three rom 3 383 from the june ECM----can they be fixed---?
Crazy1_79
12-24-2004, 03:50 AM
booya, I pm'd you about the cards. in case you didn't get it.
Bowman, try vcc 8 and vcc 0 delay 10A8 and delay 10A2 don't be afraid to let it run.,
udntcme
12-24-2004, 04:40 AM
Some "CAM'S" will not pop...! when I first built my loader....all the cam's popped within 2-3 min's no-prob...then I have two "CAM'S from HELL" one 383,one a23, ...Now i've poped appox 10 a23's and a couple of 383's but some cam's are directly "FROM HELL" They woud'nt pop if a m-80 was lite and ready to explode under them....!!!! I think there should be a consideration for a separate area on this site for "UNPOPPable" cam's ....been at this game for a good while and believe me, I have tried everything that can be found (and some that's hard to find}and does not matter if you call them soft ,hard locked ,stream locked, blockered, curse of the "Mummy" ,The evil eye, or any other consideration....this deserves more discussion,....most of us have one or two of these ,...even if we don't like to admit it...! I don't even use plastic ...I'm a "MEGA MAN", but it's my hobby so I like trying to solve or fix thing's If anyone has anything that is not on the local board's or already "Hashed over" a million time's please by all mean's post it.
udntcme
12-24-2004, 04:46 AM
Or Looped...!!!
Crazy1_79
12-24-2004, 04:47 AM
you won't get a read from them while glitching if they are looped, I glitched a rom 3 that I believe is stream looped and all it gave me was 00000000000000000
Dr Zapola
12-25-2004, 04:05 AM
Iam trying test glitch on a locked rom8 rev381 (dont have any open) and this is what I get 3FFF9500
===========================================
FF
===========================================
VCC = 09-0410AE GLITCHED past 0C BUG
3FFF9500
===========================================
FF
===========================================
VCC = 04-0510AE GLITCHED past 0C BUG
3FFF9500
===========================================
FF
===========================================
VCC = 18-0610AE GLITCHED past 0C BUG
3FFF9500
===========================================
FF
===========================================
VCC = 13-0710AE GLITCHED past 0C BUG
3FFF9500
===========================================
FF
===========================================
VCC = 0E-0410AE GLITCHED past 0C BUG
3FFF9500
===========================================
FF
===========================================
VCC = 09-0510AE GLITCHED past 0C BUG
3FFF9500
===========================================
FF
===========================================
VCC = 04-0610AE GLITCHED past 0C BUG
3FFF9500
===========================================
is this correct. It continues to run . Will it stop with an answer.
ZAPOLA
Crazy1_79
12-25-2004, 04:26 AM
it won't stop, your hitting oc bugs, you can open rom 3's just like that, if you were in open mode it would be open. to get 10's I think you have to have OF bugs and oc bugs, a of bug looks like this
Success on Glitch Try #1
VCC = 22 (~0.666666666666667 vdc)
Glitch Delay = 002B
Glitch type 06
READ 20-23 OF bug glitch C64E41
Glitched on high clock phase
Dr Zapola
12-25-2004, 05:03 AM
Sorry Craz Iam not following you. Are you saying that I can run rom3 opener with standerd settings and it should open.
ZAAP
Crazy1_79
12-25-2004, 05:06 AM
yeah, let it roll, you have enough oc hits in so many places defualt should be good
fearlss-1
12-25-2004, 05:07 AM
Yep...if your ready to let it run its course...it will pop after sometime.
Dr Zapola
12-25-2004, 05:15 AM
Right On. Ill Keep You All Posted.
ZAPED
Cid6.7
12-25-2004, 05:17 AM
Some "CAM'S" will not pop...! when I first built my loader....all the cam's popped within 2-3 min's no-prob...then I have two "CAM'S from HELL" one 383,one a23, ...Now i've poped appox 10 a23's and a couple of 383's but some cam's are directly "FROM HELL" They woud'nt pop if a m-80 was lite and ready to explode under them....!!!! I think there should be a consideration for a separate area on this site for "UNPOPPable" cam's ....been at this game for a good while and believe me, I have tried everything that can be found (and some that's hard to find}and does not matter if you call them soft ,hard locked ,stream locked, blockered, curse of the "Mummy" ,The evil eye, or any other consideration....this deserves more discussion,....most of us have one or two of these ,...even if we don't like to admit it...! I don't even use plastic ...I'm a "MEGA MAN", but it's my hobby so I like trying to solve or fix thing's If anyone has anything that is not on the local board's or already "Hashed over" a million time's please by all mean's post it.
What were you getting from the A23..? For some reason I seem to have horse shoes or something I've popped every card I ran except for 3 problem cards 2 looped & 1 BD3 Login failure..
Let me know what you were getting & how long they ran..
Thanks
cocomunk
12-26-2004, 07:09 PM
had 3 A23 that would give me BD3 Login failure .Run it with glitcher and all i could get was a hole bunch off ffffffffff6969fffffffffff69ffff69ffffffff69ff69696 9ffffffff ect..but all 3 pop with in 15 minutes.This is what i use.
VCC Ceiling: 1B
VCC Floor..: 10
Delay Start &h123e
Del End &h125a
Running on 7.5 volts and roughly around 1.7 to 2.5 k on my pote depending of the card.I just set the pote till i didnt have no more reset .Didnt matter what kind of pattern i had with the ff69 and all 3 pop.
cocomunk
Dr Zapola
12-26-2004, 07:28 PM
I just posted this
Man Ive worked my ass off got all my Rom10s open then the super fight with the Rom3s. I have a Nexus T911 Modded loader set the NEW6 with 60/50/1 and I did the glitch test and the VCC1 then set the rom3glitcher and let her ripe. It says
o00o00o00o00o00o00o00o00o00o00o00o00o00o00o00o00o0 0o00o00o00o00o00o00o00o00o00o00o00o00o00--- try to hit 0C bug at 10A5
o00o63
=========================
= CAM IS OPEN NOW !!!!! =
=========================
I have open Cam on 5 cards with this. BUT.........when I go to Nagra4 it says
Opening of COM1 was successful
ATR String: 3F FF 95 00 FF 90 81 71 00 47 00 44 4E 00 53 50
30 30 33 20 50 65 76 3038 32 F4
ROM Revision: 003
EEPROM Revision: Rev382
Logging into card
Checking for BackDoor
BackDoor appears to be closed, aborting
Error reading image from card
Closing of COM1 was successful
Bug buster didnt help
Anybody getting the same or have any ideas.
ZAPOLA
Crazy1_79
12-26-2004, 07:47 PM
the 00000000 wories me because it isn't reading back the proper glitch info of 6F. There is a D2C file for popping 382's have you ever tried that? The 383's I would run again and maybe try to get some 6F06F0's
Dr Zapola
12-26-2004, 10:24 PM
NO it does the 06F06F06f think for houres befor it does the o0o000o00 thing. It only does the o0o00000othing befor it gives a Cam Open. Even if I try to run them agian it goes right to the
o00o63
=========================
= CAM IS OPEN NOW !!!!! =
=========================
so evertime I try to rerun them it says that there open allready. And yes I did try the D2C before and after the mod glitching.
Thanx
ZAPED
cocomunk
12-27-2004, 01:06 AM
About your rom3,had the same result with a couple of cards.somehow the iso i was using would only give me those reading to.Tried the other iso that i had and all was open.So not sure what is wrong with the first iso ,why i can read that far and give me a bad door close.Try another iso just incase your having the same problem.The iso will work on other cards but not those one so dont know why but all is ok with the other iso.But with the first one even after writing a bin to the cards it steal give me back door close. Go figure, weird cards i guess.
derick881
01-01-2005, 03:27 AM
Just wanted to report that after 3 weeks of trying, I finally got my first card to pop! It was a ROM 10 at A23 and popped after running the script for about 2 hours on a Modified Mikobu III. I finally received the Mikobu yesterday and modded myself last night. After running Vcc Analyzer I plugged in the parameters and got a good mix of FF and 6F right away. I started out 3 weeks ago with a Modded T911 that I bought premodded and have still not been able to get the mix of output like it did with this one without having to tweak the pot or anything.
Here is a sample of the output:
xecuting Script: C:\Documents and Settings\Butch\Desktop\Win2000\A23\Unlock A23\Rom10-A23 OPEN.XVB
TX Data : A0
TX Data : A0
TX Data : A1
TX Data : 07 0E 03 10 01 03 9A 00
RX Data : 06 00
TX Data : 12 15 AB 21 00 08 A0 CA 00 00 02 12 00 06 55 0E
03 85 00
RX Data : 03 00
Now we will try 123E delay
RESET 6F6FFFFFFF6F6FFF6F6FFF6F6F6F6FFF6FFF6F6F6FFF6FFF6F FF6FFFFF6F6FFF6FFF6F6FFF6F6FFFFF6F6FFFFFFFFFFF6F6F 6FFFFF6F6F6FFFFF6F6FFF6F6F6F6FFFFFFF6F6F6FFF6F6FFF 6F6F6F6FFF6FFFFF6F6FFFFF6FFF6FFFFF6FFFFFFF6FFFFFFF 6F6FFFFF6F6F6F6FFFFF6F6FFFFF6F6FFFFF6FFFFF6FFF6F6F FF6FFFFF6FFF6F6F6F6F6F6FFF6F6FFFFFFF6FFFFF6FFFFF6F 6F6F6F6F6F6FFFFF6F6FFF6FFF6F6FFF6F6FFFFF6F6FFFFF6F FF6FFFFF6F6FFF6F6FFF6FFFFF6FFFFFFFFFFFFF6FFFFFFFFF
************************************************** ************************************************** ******************************************
now we will try 125A delay
FF6FFF6FFF6FFF6F6F6F6F6FFF6F6F6FFFFFFF6FFFFF6FFF6F 6F6F6F6F6FFF6FFF6F6FFFFFFF6FFFFF6F6FFF6FFF6F6FFFFF 6F6FFF6FFF6F6FFF6FFF6F6FFF6F6FFF6F6F6FFF6FFF6FFFFF FF6F6FFFFF6FFFFFFFFF6F6FFF6FFF6F6FFFFF6F6F6FFF6F6F 6FFF6F6FFF6F6F6FFFFFFF6FFF6F6F6FFF6FFFFF6F6FFFFF6F FFFFFF6F6F6F6FFF6F6F6F6F6F6F6FFF6F6F6FFF6FFF6FFF6F 6FFFFF6FFFFFFF6F6F6FFFFFFF6FFF6F6F6FFF6F6F6FFF6F6F 6FFF6FFF6F6FFFFF6F6F6F6FFFFF6FFF6F6FFF6F6F6F6F6F6F FF
now we will try 123E delay
FF6F6FFF6F6F6F6F6F6F6F6F6FFFFFFF6FFFFFFFFF6FFFFF6F 6F6F6FFF6F6FFFFF6FFFFFFF6F6F6F6F6F6F6F6FFFFF6FFF6F FF6FFF6F6F6FFF6FFF6F6F6FFFFF6F6FFFFFFF6F6F6F6FFF6F FF6F6FFFFF6F6F6F6F6F6F6F6FFFFFFFFFFF6FFFFFFFFF6FFF 6F6FFF6FFFFF6F6FFF6FFFFFFFFFFFFF6F6F6FFF6FFFFF6F6F 6F6FFF6F6F6FFF6FFF6FFFFF6F6F6F6FFFFF6FFF6F6F6FFF6F 6FFFFF6F6FFF6F6FFFFF6F6FFFFFFF6F6F6F6FFF6FFF6F6F6F FF6FFF6F6F6F6F6F6F6F6F6FFF6FFFFFFF6F6F6FFF6FFF6F6F 6F
now we will try 123F delay
FFFF6FFFFF6FFFFFFF6FFFFFFFFFFFFF6FFFFF6F6F6FFF6F6F FFFFFFFF6FFFFF6FFF6F6F6F6F6F6F6F6FFF6F6F6FFF6FFFFF 6FFF6F6F6F6F6F6FFFFF6FFF6FFFFF6F6F6FFF6FFFFF6F6F6F 6FFF6FFF6FFF6FFF6FFF6F6F6FFF6F6F6FFF83
*********** we hit our bug *************
1200078303
===========================================
83 was hit at 123F delay ----VCC WAS 49
TX Data : 0A 15 A3 21 92 00 B3 0E 03 85 00
RX Data : 0A 06
RX Data : 12 92 00 80 21
***************************
* A23 CAM should be OPEN *
* test in Nagra to see. *
* if not, try again. *
*
Cam now shows Rev 16 in Niagra.
Just wanted to let everyone know that it does work if you persevere. Thanks for everyone's advise and help on this board!
Now back to the lab to try another card.
shvlhed
01-01-2005, 11:41 PM
I got my hands on a t911 about a week ago and did the mod as instructions said have opened seven cards so far 3 rom3 383 and 4 rom10 at A23. flashed with xpatmel with no problem but was wondering if ther is a program that will let me flash loader using windows 98 that works as good as xpatmel does in windows xp. As I'm using a old computer with 98 to run loader.
derick881
01-02-2005, 01:11 AM
Well I popped the other A23 last night with essentially the same settings I used last night for the first card. Set it to run and when I woke up early this am it was cracked.
Now to try my ROM 3 card that has foiled me for the last 3 weeks. Reflashed my loader with Newd6 and tried pengas glitch finder but did not get any results after several hours so I decided to go ahead and run the script blind. Set the delays down to the 10A3/10A9 range and let her run. Got steady oF6 from the get go. Checked a couple of hours later and it was popped!
two-dogs
01-03-2005, 03:32 AM
I have a moded t911 with green board I have flashed with the XpAtmel and am using the d-d9 and all is ok with the flash. now I open the vcc analyzer v2 and I get this.
VCC 30: --??--??----??----?? 6F = 0% FF = 60%
VCC 2F: ??------????--??--?? 6F = 0% FF = 50%
VCC 2E: ----??--????----??-- 6F = 0% FF = 60%
VCC 2D: ????----??--??--??-- 6F = 0% FF = 50%
VCC 2C: ------????----??---- 6F = 0% FF = 70%
VCC 2B: ??------------------ 6F = 0% FF = 90%
VCC 2A: -------------------- 6F = 0% FF = 100%
VCC Ceiling: 33
VCC Floor..: 2D
This is my question when I open the script powersyncunlockallver2a do I need to scroll down in the window script where it says ' VCCStart = &h20 'YOU CAN CHANGE THIS FROM 20 TO 50
' VCCLimit = &h1a 'YOU CAN CHANGE THIS FROM 1A TO 30
and put the VCC ceiling for the start and the VCC floor for the limit. What I have been doing is just run the script. Then it ask me for provider and I put in chuck Then it says put in test vcc high is this where I put in the ceiling that was in the vcc analyzer? I then put in what it says 1a next it says Please inter vcc low is this the vcc floor? I put in the default which is 10 then it goes through with a bunch of ?????-------??? then it comes up a ceiling of 1b and a floor of 10 then at the same time a box comes up that says try using 123e so I use that, then it says please inter Delay end I use the default of 125a then the scirpt runs and I get 69696969696969 so I adjust the pot to where I get 69FF6969FFFF6969FFFF6969FFFFFF696969696969FFFFFF69 6969FFFFFF69FFFFFF69FF69
is this right any help would be appreciated be gentle I am new at this thanks .........two-dogs
Crazy1_79
01-03-2005, 03:50 AM
the 69 is a blockered cam, or so it is thought, I wonder if some cards return that 69 from the stream, you should try the same vcc as you did with glitch analyzer, try 35 and 2A, but you don't need to do that cuz glitch analyzer is built right into powersync, make sure you are getting a mixture of ??-- just think of the ?? as ++ cuz that is the celing hits, and as far as your other questions, you are right on, but run your vcc high enough to get 69 and FF's not just FF,
two-dogs
01-03-2005, 04:18 AM
Thanks Crazy 1 79 for answering my post you said to use 35 and 2a is that in the boxes that pop up or in the script where it says ' VCCStart = &h20 'YOU CAN CHANGE THIS FROM 20 TO 50
' VCCLimit = &h1a 'YOU CAN CHANGE THIS FROM 1A TO 30 thanks .............two-dogs
Crazy1_79
01-03-2005, 05:20 AM
when the box pops up just put it in there, if you are using the powersync version, that automatically installs it into the script so it is unecessary to put it in there manually. if you don't get a good mix of 69FF's then either change those setting or change your pot, get a good mix of numbers and then let the script roll don't adjust the pot while it is running unless it runs forever and doesn't pop then you may try a small adjustment.
giove
01-03-2005, 05:34 AM
hello guys im lookeng for site .for programming atmega card....for dish........big thank.....................
giove
Crazy1_79
01-03-2005, 05:36 AM
try the atmega section of this site. Do you mean to program it yourself or are you looking for someone to do it for you?
Crazy1_79
01-03-2005, 05:40 AM
I believe the dishnetwork avr/atmega section is about two doors down from here! LMAO
Godfather1971
03-02-2005, 07:29 AM
I got a real problem, I must be really stupid. I have a mikobu 3 modded. Flashed it using newd9, now I'm trying to pop 2 rom 10's a81 and one dish a23......Having no luck with either......PLEASE HELP.............
sukh77
03-02-2005, 09:38 AM
How long did you let it run for?
Are u getting some sort of errors?
Cid6.7
03-02-2005, 02:37 PM
Let us know what kind of responce your getting from the cards aswell.
BirdieMod
03-02-2005, 04:46 PM
Cid, Click on your bottom pic right click and check properties, Make sure that url cannot be tracked to you.
Moving this to unlocking section now that we have it.
Cid6.7
03-02-2005, 06:21 PM
Its linked to a free photo site no personal info
vBulletin® v3.7.0, Copyright ©2000-2008, Jelsoft Enterprises Ltd.