View Full Version : Rom3 Rev 367
nra man
07-05-2005, 02:36 AM
I have an old rom 3 that has been out of the stream for a long time. It is at rev 367. All posts that I have found deal with higher revs. This card has not been tampered with. Raw & virgin. A search of "rev 367" has 3 threads that cannot help me get the backdoor opened.
I hope that some one with more experience than myself can lead me in the right direction.
THANKS!!!
barabbas
07-05-2005, 06:08 AM
Rev 367 isn't locked. Cards weren't stream locked until later revs of 372.
You need a 3.68mhz programmer, or a 3.57mhz programmer and the dos
program freetalk 1.2c to read/write that rev.
A 3.57mhz programmer will read/write a rom10 fine, but not a rom3.
nra man
07-05-2005, 06:30 AM
I have a iso that I have used for all of my rom10 with no problems, I also have a programer that I used for dave that I have not & was told was not used for what I was trying to do.
A rom3 has been trouble for me but not a 10.
3 10s wo a prob. 2 3s with much prob.
I have 2 older 3s that I cannot get in the backboor.
Backdoor closed.
Cimba
07-05-2005, 06:50 AM
There is a program called 382 updater-unlocker for updating/unlocking rom 3's prior to rev 382; it only mentions rev 372 as a starting point but there is a chance it could work, there is also a chance it could frig up the card; I DON'T KNOW 4 SURE. So if you were to try it don't blame me 4 mishaps, use at own risk as always.
nra man
07-05-2005, 08:01 AM
It has been tried with no results.
THANKS CIMBA !!!!
C H I L L
07-05-2005, 08:27 AM
There are problems with some iso that work flawlessly with some roms and will not work with other roms. If you have another iso that should correct the problem.
Caddylover
07-05-2005, 05:22 PM
If it were me, i'd streamlocked it at 383 (that is if it's with it's married receiver) and then pop it open and clean it to 372.
barabbas
07-05-2005, 05:31 PM
Why lock an unlocked card just to unlock it again?
You still won't be able to program it with the wrong
programmer.
Use the correct programmer or freetalk 1.2c.
nra man
07-05-2005, 08:54 PM
I do not have the wrong programmer. My programmer works very well with rom 10. Maybe it just doesn't like rom3s.
barabbas
07-05-2005, 09:50 PM
Like I keep saying, a 3.57mhz programmer will read/write a rom10 fine, but not
rom3. Rev367 was not a locked rev. That is the exact symptom of a programmer
with the wrong freq. xtal. If you stream update it, you are going to make matters
worse.
Caddylover
07-05-2005, 11:03 PM
Let me set my statement straight. I have a modded loader and 3.68 ISO programmer. I can streamlock it and pop it open. This does not mean that you should try this without a modded loader. As barabbas said, it will not help you to streamlock it without a loader.
You may want to look for the program, rom3popper, which should update that sucker to 372. It's a Winexplorer program. Set your settings to xtal 3.68.
Although the more that I think about it, the more we may be overlooking the obvious. I've never had a rev 367 before, but if it is open and it's giving you a backdoor, then why don't you just write a good rom 3 bin at rev 372 onto it?
Just a thought.
Caddy
Cimba
07-06-2005, 02:22 AM
I am trying to understand where your card is at, can you post a read card log from Nagra, x out your ATR of course if it is valid.
nra man
07-06-2005, 05:01 AM
This is my 3
Opening of COM1 was successful
ATR String: xxxxxxxx
ROM Revision: 003
EEPROM Revision: Rev367
Logging into card
Checking for BackDoor
BackDoor appears to be closed, aborting
Error reading image from card
Closing of COM1 was successful
nra man
07-06-2005, 05:11 AM
This is my 10.
My ISO will do every 10 I have thrown at it, which hasn't been many but NO problems.
Opening of COM1 was successful
ATR String: xxxxxxxxxxxxxxxxxxxxxxx
ROM Revision: 010
EEPROM Revision: RevA24
ProviderID: 00
CamID: xx xx xx xx xx xx
Using BD3 Key: 4E 69 70 50 45 72 20 49 73 20 61 20 62 75 54 74
Attempting to login to BD3
BackDoor login verified
Dumping Dataspace
Using BD0 Key: 98 0E 0F 1B AB 63 96 ED 94 6F 89 76 3C E1 9A 62
Attempting to login to BD3
Attempting to login to BD0
BackDoor login verified
Dumping CodeSpace
Reading ROM10 successful
Card read successfully
Efficiency: 100.0%, Packets: 141, Retries: 0, Time: 16.34s
Closing of COM1 was successful
Rom 10 has never given me a problem. I have had 3 ram 10 all A21 that I have opened. I cannot do any thing with a rom3. I have tried 2. One was a 372 and this 367. I am afraid that it is something simple that I am not seeing that will make me look foolish. I am not a virgin to that. Or a quitter either. Or scared of things that I am a virgin to.
Just some pointing in the right way.
THANKS
#40Fan
07-06-2005, 05:17 AM
x out your Cam id.
nra man
07-06-2005, 05:31 AM
x out your Cam id.
Done & thanks.
iggypop
07-06-2005, 05:33 AM
nra- did you try a few diff versions of nagra? you should try writing a clean bin to the card- you could also try xcel- how about bugbuster- have you tried that? just a few thoughts- iggy
nra man
07-06-2005, 05:37 AM
Nagra 4.1 3.0 & 2.0
Bugbuster in all.
Can I write a clean bin to a card that I cannot get into or clean?
iggypop
07-06-2005, 05:39 AM
i've done it with xcel on a rom2 when it would not let me clean in nagra- take a look at the crystal on your programmer- it should be a 3.68 mhz- 3.68 should be stamped on the top you should double check that too- iggy
nra man
07-06-2005, 05:50 AM
3.868 is printed on it.
THANKS
nra man
07-06-2005, 06:02 AM
I am a little different into this hoby thay many others. I have
1 Tv
9 recievers
11 cards of different rom & rev
1 ISO programmer- the only one I have ever seen
there has only been 7 people who have ever seen my dish tv
3 knew it was hacked
I have never seen anyone elses hacked dishtv
this ia a real hoby to me
I am watching tv with 2 others ready to hookup
I want to know why can't I do this one?
Cimba
07-06-2005, 06:16 AM
Maybe it would be simpler if we knew what programs you have tried on this card. As a starting point anyway, I'll try to find any reference to that rev in the places I haunt.
1) Bugbuster in NE 4.1 @ 512 packets....repeatedly....Read cam after each run..It'll open ...512 packets is perfect for 367.
2) Send DC2 packets @ 3 times each ....File is in file section.
3) Rom 3 smart unlocker ...
4) Unlocker V101.
5) Last option, Opensesame...might be marked afterwards..
G'L
nra man
07-06-2005, 06:35 AM
Maybe it would be simpler if we knew what programs you have tried on this card. As a starting point anyway, I'll try to find any reference to that rev in the places I haunt.
The only things I have trie are bugbusters. Everything I can find is for higher revs. It is an older rev & everything seems to be for 372 or higher.
A search of rev367 on this and 3 others reveals little.
THANKS
#23 2 Minutes Ago
110º Online:
Registered User Join Date: Apr 2005
Last Seen: 1 Minute Ago (03:20 AM)
Posts: 25
1) Bugbuster in NE 4.1 @ 512 packets....repeatedly....Read cam after each run..It'll open ...512 packets is perfect for 367.
2) Send DC2 packets @ 3 times each ....File is in file section.
3) Rom 3 smart unlocker ...
4) Unlocker V101.
5) Last option, Opensesame...might be marked afterwards..
G'L
Something to work on & report results
THANKS
Cimba
07-06-2005, 06:50 AM
Ya never know, the only references I could find were scarce. One was a list of emm update packages from 365 up but I have no idea if and how these can be used. The other was by an admin at another site who had the same error message exactly and he recommended open sesame, but I have heard of this program looping cards or marking them. Also saw the bugbusters run, pull, reinsert, pull, reinsert,pull etc. method mentioned.
The only other option might be a modded loader.
iggypop
07-06-2005, 08:16 AM
perhaps you could send it out to someone with a modded loader- i traded 2 locked cards for an unlocked one- there are many trusted testers with modded loaders that could help- but if you are determined to crack it yourself- modded loader- btw- hope it was a typo when you reported your crystal freq- cause it should be 3.686- i believe- shoot if i had a modded loader i'd be glad to pop it myself, but all i have is an iso- any other members here willing to give it a whack? i know there are a few over @ testers that would- iggy
Caddylover
07-06-2005, 05:12 PM
If you want me to take a look at it, I would be happy to do that. Send me a PM. I have everything needed to get any card open.
Caddy
Lynard
07-08-2005, 03:22 AM
This is my 3
Opening of COM1 was successful
ATR String: xxxxxxxx
ROM Revision: 003
EEPROM Revision: Rev367
Logging into card
Checking for BackDoor
BackDoor appears to be closed, aborting
Error reading image from card
Closing of COM1 was successful
I have seen this before:)
Old trick
NagraEdit will report, BackDoor appears to be closed, if line E020 is
00 11 22 33 44 55 66 77 88 99 AA BB CC DD EE FF
you will have to use a program like freetalk, to fix this.
SorryShakes is an easy program to fix with.
just change line E020 to anything except what is above.
Then you will be able to use nagraedit with this card again:)
if anyone would like to try this just write a clean bin from horrays rev update list and you will see.
Old trick to make ppl think card is locked when in fact it's not:)
hope this helps
Lynard
barabbas
07-08-2005, 03:59 AM
If freetalk works, he should be able to use it to write a clean rev372 bin
to the card.
Freetalk has a calibration ritual you have to do first, then try dumping
the card.
toober
07-08-2005, 07:10 AM
Dishmonkey has always worked for me. Set it to run about 10 times and reset at about 10 seconds. It shouldn't loop the card unless you leave it running after the card is open.
nra man
07-08-2005, 07:36 AM
I think I have problems with my ISO. I can do NOTHING to a rom 3 with it. I have now tried to open 2 @ 381 with rompopper viagra rompuke &others. I have found 10s to be too easy, I have done saveral 10 @A21 without problems. But I cannot do anything with 3s. I am traveling Saturday to someone else with ISO to give them a try.
I may be interested in someone in the southeast USA trying them with a modded loader if all else fails.
iggypop
07-08-2005, 07:40 AM
i bet you could pick up your own modded loader for $30-$50 at this stage of the game- or send them off to a trusted member for unlocking- iggy
vBulletin® v3.8.4, Copyright ©2000-2009, Jelsoft Enterprises Ltd.