View Full Version : Rom 102 Glitching/Loading
joesnuffy
12-04-2005, 07:49 PM
Anyone had any luck with a rom 102? I have done a couple rom 101s with a Mik3 loader. I have the rom102readeeprom script and flash but have had no luck getting into a rom 102. I looked at the D2c script and it said that I needed to glitch in with v18 or V19 first. Could anyone that has had luck give me some pointers?
Thanks,
Joe
markt52
12-04-2005, 08:36 PM
use v20 and set pot on 80 ohms I opened 12 in 30 minutes
joesnuffy
12-04-2005, 09:06 PM
Thanks,
I have the V20 script and I can set the pot to 80 ohms and try that. How did you fine tune to 80 ohms? and did you tweak anything else in the script?
Joe
markt52
12-04-2005, 11:11 PM
you use the pot that sets between the power plug and your dip switches on the modded loaders and use a ohms meter to set it by turning the little screw looking top of it
talldark1
12-04-2005, 11:48 PM
Where can you get version 20, I have been looking for it and can not find it, but then again I have been told I am blind more than once by my significant other :p , will someone show me the way to the link? I would greatly appreciate that.
Thanks
joesnuffy
12-05-2005, 01:11 AM
http://dssftp.com/filedownload/generate_php/rom_10x_files.php
Number 4 right now.
Does anyone know if 2 chips must be changed on modded loader for rom 102? If so which ones or where can I get a self help file?
Thanks,
Joe
Did mine in about two minutes with a t911. I set the pot at .850 ohm. I also set the VCC Start at &h320. Delay Limit &h375. Glitch Max 9. Glitch Min 7. Leave the rest the same. The two chips don't have to be modded. V20 will set the intercepter and then you run the D2C and it will dump the eeprom. Find ECGS102F_ROM102_NO1B4ME_ND13_DUMPROM_V5. This one will dump the ROM part.
joesnuffy
12-05-2005, 01:31 AM
Thanks Dogbreath,
I have a Mik 3 but it should work. Thanks for the values you used I will try them.
Joe
Sorry I just check my trim pot was at 85 ohms. Also when you try the D2C it will look like Nagra Edit frooze up but let it goo. It takes like ten minutes. It is working even though it looks froze.
dj007
12-05-2005, 01:33 AM
does anyone have a 3m bin we can write to a rom 102, or can we use the 101 bin?
no this is just for dumping the card. Don't write the rom101 stuff to the rom102.
markt52
12-05-2005, 02:16 AM
here you go
markt52
12-05-2005, 02:19 AM
well i don,t know why the attachment didn,t show up
joesnuffy
12-05-2005, 02:22 AM
Dogsbreath,
Thanks for all the help. I can't seem to get the +++++------- . All I can seem to get is -------- I have played with all the values but can't seem to get it to alternate. I was mainly working on this for latter but I really enjoy the challenge. My buddy has a t911 I may need to borroww it. On the Mik3 mod a resistor is put into it with like 220 ohms. I have also put in a variable resisotor in on the back of the board that I use to adjust it works very well on all the other cards just haven't seemed to figure this thing out.
Thanks,
Joe
just let it run. People have had to let it run hours. As long as you are getting + and -- it is working. I have heard off people running it all night. Also I have not been able to get a Rom dump sence I put the intercepter on the card to run the D2C. So run S102F_ROM102_NO1B4ME_ND13_DUMPROM_V5 first. That way you dont run into any problems. It should be able to work after you put the intercepter on but not for me. So do that first just incase so you don't have problems I am glad I did it first.
I just read your post again, you have to get that 220 lowwer. I have notice the same results when the trim pot on mine is to high all I get is----------. Borrow your buddys loader if you can and then try the settings that I gave you.
What do you get when you adjust the one on the back that you put in. Ohm it out and set it 85 ohms.
joesnuffy
12-05-2005, 03:19 AM
I put the pot at 85 and didn't have any luck getting the +++++------ mix. I was still only getting --------- minus's only. I think what I will do is remove the resistor then and put a pot there and tune both of them into 85 ohms. I will get on that tommorrow. I am running the no1b4me script right now maybe it will pop it. This is the only card I haven't been able to get into. Thanks for the help and I will post results.
Joe
Newfygarge
12-05-2005, 03:37 AM
:) Thanks dog breath been at my 102 all day.Saw your settings and tried. opened in 16 min. THANX. Now on to reading & finding a 3m
joesnuffy
12-05-2005, 04:10 AM
Dogbreath,
Thanks also, got the +++++------. Mine is going +-+-+-+-+- I guess that is correct. Going to let it run a while with your settings. Mine was about 20 ohms to get the mix but its a Mik 3 that might help someone else.
Joe
joesnuffy
12-05-2005, 03:57 PM
Thanks Dogbreath,
Got in 2 rom 102s in 5 minutes a piece. Thats after I had the loader dialed in. Here are the values I used with a Mikobu 3 modded loader. I did notice that a rom 102 at rev 103 was easier (took less time) to get in than a rom 102 at rev 105.
1. Pulled the 2.2 K resistor (used for mod)off the board and replaced with variable resistor put to 18.3 ohms. I figured this out using the V20 script adjusting the variable resistor until I got -+-+-+-+-+ which turned out to be 18.3 ohms.
2. Used the No1b4me ECGS102s winex script in the rom10x download section to read the rom 102s I changed the User Values in the script to Delay Start 325, delay limit 375, Vcc Start 48 Vcc limit 46,glitch type 9, glitch limit 7. Just let it run then. It will run a while then like stop like something is wrong then you will see all these blue numbers its trying to insert into the card then it will read the card.
Now I wonder if a 102 file can be cloned? Has someone succesfully done that?
Good Luck,
Joe
dj007
12-05-2005, 11:33 PM
did u mean 18.3k or 18.3 ohm???
joesnuffy
12-06-2005, 02:53 AM
It was only 18.3 ohms.
Joe
dj007
12-06-2005, 08:49 AM
man i am having no luck whats so ever, the only thing i got goin for me looks like this. -+-+-+-+norsp+-+-+-+-+-+norsp+-+-+-+norsp. and thats with 2.2k and only dip 1 on using modded t911. any suggestions anyone, tried pot with less results
ZABOO
12-06-2005, 05:55 PM
let it run..... adjust script settings
talldark1
12-06-2005, 06:02 PM
Hi, what are the settings you use, just getting:
NO ATR Rcv'd, trying 2nd ATR...
NO 2nd ATR Rcv'd, continue reset, back to first atr
think my settings are wrong. have it flashed with newdt 13 or is nd 13 different?
thanks
sukh77
12-06-2005, 06:03 PM
You need to adjust your pot. I'm using Unlooper settings, But I havn't had much luck popping one yet.
ZABOO
12-06-2005, 06:06 PM
DelayStart = &h320
DelayLimit = &h375
VCCStart = &h45
VCCLimit = &h05
GlitchType = 9
GlitchMin = 7
i used v20 to get the pot trimmed --+--+--+--+--+
then styopped that and ran v5
ZABOO
12-06-2005, 06:07 PM
3 r 101s unlocked with mik3
5 out of 7 r102s unlocked with t911 clone
dj007
12-06-2005, 06:08 PM
i wioll try those settings, but i want to install the intercept not dump the card
joesnuffy
12-06-2005, 06:09 PM
Cut and past this into your winex script box where the script normally is I have already changed the values to the ones that worked for me and other folks. Let it run a while. When it loads it will tell you it loaded but look like their has been an error but their has not if you see the Successfully Loaded words. Put your modded loader in the configuration that was giving you +-+-+-+-+- let it run. I have now done 101,102 with Mikobu 3.
joe
'
' New VB Script File - Created 11/28/2005
'
'Execute Code Glitch FOR A0FF-INTERCEPT ROM 102, ALL IN ONE
'AUTO FIND VCC
'USE ON REVS 105 AND UNDER. OR KNOW WHAT YOUR REPLACING.
'YOU COULD LOOP YOUR CARD.
'
'Fine tune all values for your loader in
'User selectable options
'
'Notes:
'This script REQUIRES ND13 and it will check for it!!!
'
'THANKS TO: NO1B4ME, BobsBigBoy, lynard, dytene, silverman, and many others.
'
'Good Luck!
'penga
OPTION EXPLICIT
Dim FileName
Dim Dump
Dim OutFile
' You can set your own settings or use these ones.
' remove ' to use these ones in script
' CALL setupunlocker()
Sub Main()
Dim BootStrapCmd04
Dim BSCLen
Dim BSCRSP
Dim BSACK
Dim CmdToGlitch
Dim CTGLen
Dim CTGRSP
Dim CS
Dim Bytes
Dim BytesRead
Dim Bytes1
Dim Bytes2
Dim DelayStart
Dim DelayLimit
Dim VCCStart
Dim VCCLimit
Dim GlitchType
Dim GlitchMax
Dim GlitchMin
Dim Delay
Dim VCC
Dim Dot
Dim ATRrsp
Dim loopctr
Dim AddrHiStart
Dim AddrHiEnd
Dim RomAddr
Dim PageSet
Dim trys
Dim mix
clearoutputwindow
Sc.Verbose = TRUE
loopctr = 0
if CheckChipVer <> 1 then
Sc.MsgBox("You need chip version ND13 to run this script" & VbCr & "Flash your Atmel chip with NewD13.hex")
Exit Sub
End if
Sc.Verbose = False 'Turn echo on - False = turns it off
VCCStart = &h90 'h25 is standard, script is auto vcc dont change 90
VCCLimit = &h02 'h05 is standard, script is auto vcc dont change 02
'================================================= ==
'================================================= ==
'User selectable options
'================================================= ==
'================================================= ==
DelayStart = &h325 'h385 is standard, try 375, 350 has been known to hit too.
DelayLimit = &h375 'h385 is standard, try 395
GlitchMax = 9 '7 is standard - 7, 8, or 9
GlitchMin = 7 '7 is standard - 6, or 7
trys = 100 '100 is standard
mix = 1.2 '0.5 is standard - try 0.1 to 1.2 use for +-+-+-+- mix
'************************************************* *************************
'************************************************* *************************
'******* This Section is FOR ADVANCE USERS ONLY **********
'************************************************* *************************
'************************************************* *************************
'This Packet can be changed however you like and the script will generate
'the correct loader packet. Do not include the Checksum byte at the end.
'Cmd 04 without checksum byte - Check will be calculated and inserted
'Loads the RAM dumper code to EMM buffer
'
'Dumper and serial code curtesy of Lynard - Thank you
'
'-------------------------------------------------------------------------------
'NO1'S BOOTSTRAP
'------------------------------------------------
' ROM/EEPROM DUMPER!!!
' all in one
' add $8219:17 63 A1 CA 26 03 CC 60 EC CC 7D 99
' $317F write our bug in table 60DB 8219
BootStrapCmd04 = "21 00 6D A0 CA 00 00 67 04 65 01 01 86 00 AA 9D 9D 9D 9D 9D 9D 9D 9D A6 4B B7 6B 18 64 CD 7C 16 82 19 BE 0C A6 4B B7 6B 18 64 CD 7C 16 31 7F A5 04 CC 7A 99 60 DB 82 19 9D 9D 9D 9D 9D 9D 9D 9D 9D 9D 9D 9D 9D 9D 9D 9D 9D 9D 9D BC 80 17 63 A1 CA 26 03 CC 60 EC CC 7D 99 9D 9D 9D 9D 9D 9D 9D 9D 9D 9D 9D 9D 9D 9D 9D 9D 9D 9D 9D 9D BC 80 02"
'--------------------------------------------------------------------------------------
BSCRSP = 8 'Expected Response = 12 00 04 84 00 90 00 02
'Length = 8 bytes
BSACK = &H80 'Boot Strap running Acknowledge byte
'************************************************* *************************
'************************************************* *************************
'************************************************* *************************
'This Packet can be changed however you like and the script will generate
'the correct loader packet.
'The acutal packet that we're going to glitch without Checksum
CmdToGlitch = "21 00 08 A0 CA 00 00 02 15 00 86"
CTGRSP = 6 'Length in bytes of expected response WERE LOOKING FOR 6F
'Expected Response = 12 40 02 6F 00 3F
'************************************************* *************************
'************************************************* *************************
'************************************************* *************************
BSCLen = GetPacketLen(BootStrapCmd04)
if (BSCLen AND 1) = 1 then
Sc.MsgBox("Bad BootStrapCmd04 packet")
sc.print BSCLen
Exit Sub
End if
BSCLen = BSCLen / 2
BSCLen = BSCLen + 1 'add Checksum byte to packet length
CTGLen = GetPacketLen(CmdToGlitch)
if (CTGLen AND 1) = 1 then
Sc.MsgBox("Bad CmdToGlitch packet")
Exit Sub
End if
CTGLen = CTGLen / 2
CTGLen = CTGLen + 1 'add Checksum byte to packet length
CS=DoCheckSum (BootStrapCmd04) 'Calculates BootStrapCmd04 Checksum
BootStrapCmd04 = BootStrapCmd04 + CS 'add checksum to packet
CS=DoCheckSum (CmdToGlitch) 'Calculates packet Checksum
CmdToGlitch = CmdToGlitch + CS 'add checksum to packet
GlitchType = GlitchMax
Delay = DelayStart
VCC = VCCStart
Sc.Print "Let the 102 Glitching begin...." & VbCr
Dot = 0 'Dot progress counter if Sc.Verbose = False
Do
Do
sc.delay(5)
Sc.Write("A2")
Sc.Write("B0" & HexString(VCC, 2)) 'set glitch VCC
sc.delay(10)
Sc.Write("06 10 01 03 50 1A 00") 'reset card
Sc.Read(02)
ATRrsp = Sc.Getbyte(1)
if ATRrsp = &h1B then 'check card reset ok
Sc.Read(ATRrsp)
Exit Do
else
print VbCr & "NO ATR Rcv'd, trying 2nd ATR..."
sc.delay(100)
Sc.Write("B0" & HexString(VCC, 2)) 'set glitch VCC
sc.delay(30)
Sc.Write("08 10 01 01 01 03 50 1A 00") 'reset card
Sc.Read(02)
ATRrsp = Sc.Getbyte(1)
if ATRrsp = &h1B then 'check card reset ok
Sc.Read(ATRrsp)
Exit Do
else
print VbCr & "NO 2nd ATR Rcv'd, continue reset, back to first atr" & VbCr
'exit Do
sc.delay(100)
Sc.Write("04 01 01 01 00") 'reset card
end if
End if
loop
Sc.Write("02 15 00") 'set Tx/Rx to 32 cycles per bit
Sc.Read(02)
sc.delay(5)
'Send dirty EMM (Cmd04) with our ram dump code
Sc.Write(HexString((BSCLen + 5), 2) & "60" & HexString((BSCLen - 1), 2) & BootStrapCmd04 & "50" & HexString((BSCRSP - 1), 2) & "00")
Sc.Read(2)
Bytes = Sc.Getbyte(1)
if Bytes > 0 then
Bytes = Sc.Read(Bytes)
Bytes1 = Sc.Getbyte(0)
Bytes2 = Sc.Getbyte(5)
'--------check response to make sure = 12 00 04 97 00 90 00 11--------
if Bytes1 = &h12 and Bytes2 = &h90 then
sc.verbose = false
else
print VbCr & "Bad CMD04 response......" & VbCr
exit sub
end if
else
print VbCr & "Bad CMD04 response....." & VbCr
exit sub
End if
sc.delay(20)
'loader glitch packet
Sc.Write(HexString((CTGLen + 10), 2) & "15 60" & HexString((CTGLen - 1), 2) & CmdToGlitch & "20" & HexString(Delay, 4) & HexString(GlitchType, 2) & "50" & HexString((CTGRSP - 1), 2) & "00")
Sc.Read(2)
Bytes = Sc.Getbyte(1)
if Bytes > 4 then
Bytes = Sc.Read(Bytes)
Bytes1 = Sc.Getbyte(3)
Bytes2 = Sc.Getbyte(0)
'--------check response to SEE IF = 6F 00--------
if Bytes1 = &h6F then
sc.verbose = true
Sc.Write("A1")
Sc.Print VbCr
Sc.Print "===========================================" & VbCr
Sc.Print "Glitch Success!! A0FF-INTERCEPT IS ON" & VbCr
Sc.Print "BootLoader 6F 00 RSP Received!!" & VbCr
Sc.Print "VCC = "& HexString(VCC, 2) & " (~" & ((5/255) * VCC) &" vdc)" & VbCr
Sc.Print "Glitch Delay = "& HexString(Delay, 4) & VbCr
Sc.Print "Glitch type " & HexString(GlitchType, 2) & VbCr
Sc.Print "===========================================" & VbCr
Exit Sub
end if
if Bytes2 <> &h12 then
Vcc = Vcc + .25
print "+"
end if
else 'if bytes >4
print "NoRsp+"
VCC = VCC + .75
End if 'if bytes >4
VCC = VCC - mix
print "-"
GlitchType = GlitchType - 1
if VCC < VCCLimit then
VCC = &h40
print " hit VCCLimit, back up to &h40 vcc "
end if
if GlitchType < GlitchMin then
GlitchType = Glitchmax
end if
loopctr = loopctr +1
if loopctr > trys then
clearoutputwindow
loopctr = 0
Delay = Delay + 1
if Delay > DelayLimit then
Delay = DelayStart
end if
Sc.Print "Let the 102 Glitching continue...." & VbCr
Sc.Print " LETS TRY NEW DELAY " & VbCr
Sc.Print "Glitch Delay = "& HexString(Delay, 4) & VbCr
Sc.Print "VCC = "& HexString(VCC, 2) & VbCr
Sc.Print " " & VbCr
end if
loop
End Sub
Function GetPacketLen (Packet)
Dim Length
Dim Temp
Dim PK
Dim i
PK = ""
Length = Len(Packet) 'get packet length with spaces
for i = 1 to Length
Temp = Mid(Packet, i, 1)
if Temp <> " " then 'remove all spaces in packet
PK = PK + Temp
End if
next
GetPacketLen = Len(PK) 'return packet length without spaces
End Function
Function DoCheckSum (Packet)
Dim Temp
Dim Length
Dim PK
Dim CheckSum
Dim i
PK=""
Length = Len(Packet) 'get packet length with spaces
for i = 1 to Length
Temp = Mid(Packet, i, 1)
if Temp <> " " then 'remove all spaces in packet
PK = PK + Temp
End if
next
Length = Len(PK) 'get packet length without spaces
CheckSum = 0
for i = 0 to Length
i=i+1 'Simulate Step 2 in VB scripting
Temp = Mid(PK, i, 2)
CheckSum = CheckSum XOR Hex2Dec(Temp) 'Calc Checksum
next
DoCheckSum = HexString(CheckSum, 2) 'convert checksum to a hex strimg and return it to caller
End Function
Function Hex2Dec(HexNumber)
' This function takes 1 argument, a string containing a hex value of any digit length
' and returns the decimal equivalent
Dim DecimalValue
Dim DigitCount
Dim Digit
Dim HexDigit
HexNumber = Replace(UCase(HexNumber), " ", "")
DigitCount = Len(HexNumber)
For Digit = 1 To DigitCount
HexDigit = Mid(HexNumber, Digit, 1)
If Asc(HexDigit) < 58 Then
DecimalValue = HexDigit * 16 ^ (DigitCount - Digit)
Else
DecimalValue = (Asc(HexDigit) - 55) * 16 ^ (DigitCount - Digit)
End If
Hex2Dec = Hex2Dec + DecimalValue
Next
End Function
Function HexString(Number,Length)
' This function takes 2 arguments, a number and a length. It converts the decimal
' number given by the first argument to a Hexidecimal string with its length
' equal to the number of digits given by the second argument
Dim RetVal
Dim CurLen
RetVal=Hex(Number)
CurLen=Len(RetVal)
If CurLen<Length Then
RetVal=String(Length-CurLen,"0") & RetVal
End If
HexString=RetVal
End Function
Function CheckChipVer()
CheckChipVer = 1
sc.write("90")
delay(80)
if sc.read(4) <> 4 then
CheckChipVer = 0
Exit Function
End if
if getbyte(0) <> &H4E then CheckChipVer = 0
if getbyte(1) <> &H44 then CheckChipVer = 0
if getbyte(2) <> &H31 then CheckChipVer = 0
if getbyte(3) <> &H33 then CheckChipVer = 0
End Function
Function setupunlocker()
sc.print "________________Setting up WinExplorer_________________" & VbCr
Wx.BaudRate = 115200
Wx.ResetBaudRate = 115200
Wx.Parity = 0 ' 0 = None, 1 = Odd, 2 = Even, 3 = Mark, 4 = Space
Wx.StopBits = 0 ' 0 = 1 stop bit, 1 = 1.5 stop bits, 2 = 2 stop bits
Wx.DTRControl = 0 ' Initial state of DTR 0 = off, 1 = on
Wx.RTSControl = 1 ' Initial state of RTS 0 = off, 1 = on
Wx.ResetDelay = 100 ' In microseconds
Wx.ByteDelay = 10 ' In microseconds
Wx.RxByteTimeout = 500 ' In milliseconds
Wx.ResetMode = 2 ' 0 = No Resets, 1 = ISO Reset (Expect a ATR), 2 = Device Reset (No ATR)
Wx.ResetLine = 1 ' 0 = Toggle RTS for Reset, 1 = Toggle DTR for Reset
Wx.ByteConvention = 1 ' 0 = Inverse, 1 = Direct
Wx.FlushEchoByte = 0 ' 0 = no flush, 1 = flush - A Phoenix interface will echo each byte transmitted.
Wx.FlushBeforeWrite = 1 ' 0 = no flush, 1 = flush - Flush the receive buffer before each write to strip off Null bytes.
Wx.IgnoreTimeouts = 1 ' 0 = Abort script on a receive timeout, 1 = Ignore all receive timeouts
Wx.ResetAfterTimeout = 0 ' 0 = Don't reset after a timeout, 1 = do a reset after a timeout - Not used if "IgnoreTimeouts=0"
Wx.LogTransactions = 0 ' 0 = Don't log transactions, 1 = log transactions
Wx.DisplayUSW = 0 ' Display USW after script complete 0 = no, 1 = yes
Wx.DisplayFuse = 0 ' Display Fuse after script complete 0 = no, 1 = yes
End function
ZABOO
12-06-2005, 06:10 PM
the win explorer settings are in the script
jackson8989
12-07-2005, 01:47 PM
How do you mod MIKOBU III as a loader for ROM 102?
I see there are files in the file download section for modifying T911,
but could not find any info for modifying MIKOBU III such as where
to add the pot/trimmer etc.
Any info or help will be much appreciated. Thanks.
Cimba
12-07-2005, 04:39 PM
How do you mod MIKOBU III as a loader for ROM 102?
I see there are files in the file download section for modifying T911,
but could not find any info for modifying MIKOBU III such as where
to add the pot/trimmer etc.
Any info or help will be much appreciated. Thanks.
I have a pic of the mod, it does not use a pot in this particular mod but a 2k (resistor)? I am not familiar with electronics but it's in the picture. I assume a pot would go in the same place. It is uploaded to the files section, may take awhile to actually appear there so go to this page and you'll find it along with a how-to. A simple search would have saved us both alot of time.
http://www.dssftp.com/forum/showthread.php?t=44611
ZABOO
12-07-2005, 05:37 PM
i used adhocs read me......
ZABOO
12-07-2005, 05:55 PM
here ya go
Caddylover
12-07-2005, 06:17 PM
Just popped my one and only 102 last night with blue modded t911. I really had to play with my pot settings to get a good mix of +-+---+-NoResp-+++---++++--+--+ etc. Took about 5 minutes or so to get it running well and then it just popped. Reset the ATR in N2Edit and saved the image. Haven't had a chance to run the 3m or d2c scripts on it yet as my atmega was working fine and my DTV working perfectly.
These are popping quicker than most of the N1 cards from what I'm reading.
Caddy
joesnuffy
12-07-2005, 07:45 PM
I have been succesful in cloning a sub'd rom 102. It works in the original receiver which is a 301-013. Now I am trying to clone the receiver from a 301-013 to 301-010 and can't find my hex editor. Can someone pm me so I can get it via email.
Also to set up a mik 3 use the pic of cimba's and he is correct you place the pot where the resistor goes. I used a 15 turn 10k pot from rat shack works very well. I jb welded it under the cover and melted a hole for access with a screwdriver to fine tune.
Joe
sukh77
12-08-2005, 02:34 AM
Hex editor is available free online. Search with google.
sukh77
12-09-2005, 12:11 PM
Did this trick and pops the cards seconds.
For people with T911 that cant glitch ++---++
--------------------------------------------------------------------------------
I have a Mik and T911 the mik works fine but I got steady resistance, as for the t911 i got a 5k Pot
do as they all say bring your pot down till BAD CMD04, then raise till you get ------- VERY tiny bits
This should fix your issue:
Hello I saw a few people in here who state their t911 is not doing +++---++++--NoRsp+---++---++ I had similar problem come to find out that pin 1 of HCT has bad contact possibly was defective shipement, this is why it took long for some cards (r10) to pop and some where quick, it was not efficient, so I decide to take the casing off my loader and start the script, as I was holding it in my hand I went from --------------------- to +----+++----++ I put the loader on the table back to -------------------- I grab it again same issue..
So.. the only wire I was psychially touching was the Switch 6 to pin 1 of HCT wire , it was properly soldered. As a test I applied pressure to the pin then started to get ++++---+++---++ NoRsp+ etc... i let go back to --------- so i said ok.. I removed the chip soldered it back on with the hot air pencil then resoldered my wire in place and well I got ++++---+++ continously
Let the 102 Glitching continue....
LETS TRY NEW DELAY
Glitch Delay = 0329
VCC = 1B
-+---+--
TX Data : A1
===========================================
Glitch Success!! A0FF-INTERCEPT IS ON
BootLoader 6F 00 RSP Received!!
VCC = 19 (~0.485294117647059 vdc)
Glitch Delay = 0329
Glitch type 06
===========================================
Script C:\unzipped\ROM102_ND13_A0FF-INTERCEPT-autoVCC_20\ROM102_ND13_A0FF-INTERCEPT-autoVCC_20.XVB Transmission Completed
Read Successfull in N2Editb4
now My friend calls me hes getting same issue I told him to apply pressure to pin one of HCT and voila.. there she blows for him so he simply told me he had lifted the pin just a little, heated the pad underneath with a dab of solder then reposition the pin in place and voila..
+++--+++-- for him too and he popped 8 cards I only had one rom 102 i just have a few 101's but no 102's
joesnuffy
12-09-2005, 06:24 PM
Sukh77,
Good Post,
Most likely explains why I never got my damn t911 modded properly. Oh well its in the trash now for 8 months.
Joe
Nagra1
12-09-2005, 08:51 PM
Modded T911 Blue board
VR Pot set to 15 ohms
Dip switches 1,2,5 On
9v at 300ma power supply
=======================================
ROM102_ND13_A0FF-INTERCEPT-autoVCC_20 Setting
DelayStart = &h320
DelayLimit = &h38a
GlitchMax = 8
GlitchMin = 6
trys = 100
mix = .5
=======================================
Unlocked 102's rev 103 in less than 1 min
Unlocked 102's rev 105 in less than 3 mins
=======================================
Adjust the resistor pot until you see +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-when gliching....
ZABOO
12-09-2005, 09:08 PM
Let the 102 Glitching continue....
LETS TRY NEW DELAY
Glitch Delay = 0389
VCC = 0A
+-+--+-+-NoRsp+-+-+--+-+-NoRsp+-+-+--+-+--+-+--+-+--+-+-NoRsp+-+-+--+-+-- hit VCCLimit, back up to &h2f vcc +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-NoRsp+-+-+-
TX Data : A1
===========================================
Glitch Success!! A0FF-INTERCEPT IS ON
BootLoader 6F 00 RSP Received!!
VCC = 2A (~0.818627450980392 vdc)
Glitch Delay = 0389
Glitch type 06
and now i have no more cards to unlock script ran about10 mins
sukh77
12-10-2005, 12:24 PM
I forgot to put that I found the fix at another site. Not my work, but worked for me.
vBulletin® v3.8.4, Copyright ©2000-2009, Jelsoft Enterprises Ltd.