View Full Version : New Unlocker 102- Rev106-107-242-243
woods
04-12-2006, 05:34 AM
c/p from rom 10x
************************************************** ****************************
****************************USE AT YOUR OWN RISK***********************************
************************************************** *****************************
Please read whole document before glitching
This is for rev 106 - 107 and 242 - 243
Credit for This goes to The Rom10x Coder Team
1: Only Use 4619 chips they are the only ones that seem to be working.
2: Only glitch type 7 seems to be successful
* DO NOT USE Pin 1 and 5 down. It will loop your card*
3: It seems that cards are only popping when added resistance is used (IE: pins 2 and 5 down). It seems that when people use combinations like 1 and 5, or just pin one down that they're looping their cards.
4: It seems that using a higher ohm setting is successful. IE: 215 ohms
Thanks to everyone that helped.. You know who you are.
Rom10x Coder team
/cp
i can confirm that this script works. cant seem to upload it so find it elsewhere till i or someone else can up it
woods
Wyzzard
04-12-2006, 05:46 PM
Thanks Woods......if you say it works I will give it a try.....Now I just need a ROM 102 unlooper!
woods
04-12-2006, 08:01 PM
np, popped a 106 in under a minute.
woods
Pyotr
04-13-2006, 12:41 AM
So,now we all have to buy new expensive Nexus Orange loaders?Crap. Anyone please report succes with other types of glitchers.
muleman
04-13-2006, 01:58 AM
I have the blue nexus with 2&5 down run the program 5 min the it when to fine first atr and it just run no go so i guess my card is looped now, if some one noi what do do let me no.
woods
04-13-2006, 03:37 AM
do not use with out the 4619 chips as stated. if your not sure open your loader and look next to the card slot there should be 2 chips. and no you dont have to buy the expensive nexus if you have soldering skills. you can get the chips from digikey for cheep and install them yourself. i put them in my t911 blue case myself back in december.
woods
pytor
modded t911 blue case. self installed 4619
221 ohms
2 and 5 down
newd 13
ran for less then 1 minute and poped
Modify_inc
04-13-2006, 04:18 AM
do not use with out the 4619 chips as stated. if your not sure open your loader and look next to the card slot there should be 2 chips. and no you dont have to buy the expensive nexus if you have soldering skills. you can get the chips from digikey for cheep and install them yourself. i put them in my t911 blue case myself back in december.
woods
pytor
modded t911 blue case. self installed 4619
221 ohms
2 and 5 down
newd 13
ran for less then 1 minute and poped
What about using on a Powersync loader, they only require 1 dip switch on or off. The instructions say not to use more than 1 dip switch at a time that it can damage the loader.
Anyways I tried it with just 1 down, and it pop'd in about 20 minutes, but it will not open. Here is what I got:
Let the 102 Glitching continue....
AVR delay = 03
Glitch Delay = 3A12
VCC = 1C
RX Data : D8 00 02 6F 00 B5
--
RX Data : D8 00 02 6F 00 B5 --
RX Data : D8 00 02 6F 00 B5 --
RX Data : D8 00 02 6F 00 B5 --
RX Data : D8 00 02 6F 00 B5 --
RX Data : D8 00 02 6F 00 B5 --
RX Data : D8 00 02 6F 00 B5 --
RX Data : D8 00 02 6F 00 B5 --
RX Data : D8 00 02 6F 00 B5 --
RX Data : D8 00 02 6F 00 B5 --
RX Data : D8 00 02 6F 00 B5 --
RX Data : D8 00 02 6F 00 B5 --
RX Data : D8 00 02 6F 00 B5 --
RX Data : D8 00 02 6F 00 B5 --
RX Data : D8 00 02 6F 00 B5 --
RX Data : D8 00 02 6F 00 B5 --
RX Data : D8 00 02 6F 00 B5 --
RX Data : D8 00 02 6F 00 B5 --
RX Data : D8 00 02 6F 00 B5 --
RX Data : D8 00 02 6F 00 B5 --
RX Data : D8 00 02 6F 00 B5 --
RX Data : D8 00 02 6F 00 B5 --
RX Data : D8 00 02 6F 00 B5 --
RX Data : D8 00 02 6F 00 B5 --
RX Data : D8 00 02 6F 00 B5 --
RX Data : D8 00 02 6F 00 B5 --
RX Data : D8 00 02 6F 00 B5 --
RX Data : D8 00 02 6F 00 B5 --
RX Data : D8 91 00 49 8D 00 NoRsp+-
RX Data : D8 00 02 6F 00 B5 --
RX Data : D8 00 02 6F 00 B5 --
RX Data : DE CA FE C0 FF EE
===========================================
Glitch Success!! DE CA FE C0 FF EE
Card is Unlocked!!!
VCC = 0C (~0.235294117647059 vdc)
Glitch Delay = 3A12
Glitch type 07
===========================================
--- Eeprom Read Failed, A0FF intercept is not installed, Or card locked. ---User Aborted!
Script C:\Unzipped\ROM10X Reader-Writer-Unlocker\ROM10X Reader-Writer-Unlocker.xvb Transmission Completed
**N2Edit Beta 9
ATR: 3F FF 95 00 FF 91 81 71 FF 47 00 44 4E 41 53 50 31 30 32 20 52 65 76 31 30 36 61
CAM Type: ROM102 Rev106
Setting IFS
Provider: Unknown
Reading Card image...
Failed to read card. (Retries: 17)
Now when I try to reglitch it I get this:
Let the 102 Glitching begin....
RX Data :
-
RX Data : -
RX Data : -
RX Data : D8 91 00 49 NoRsp+-
RX Data : -
RX Data : -
RX Data : -
RX Data : -
RX Data : Increasing AVR delay to 04
-
RX Data : -
RX Data : -
RX Data : -
RX Data : -
RX Data : Increasing AVR delay to 05
-
RX Data : -
RX Data : -
RX Data : -
RX Data : -
RX Data : Increasing AVR delay to 06
-
RX Data : -
RX Data : -
Sc.Read: Timeout Reading Data From Card - 2 Bytes Requested, 0 Bytes Read, Continuing Script
Script Error on Line 223
Sc.GetByte: Requested Byte Exceeds Last Read Request
I also tried the RebelSerf 102 OmniUnlocker force fubar 106 107 242 243 and it detects the best type of unlocking, tells me I have a Rom 102 rev 106, then times out.
Initial Parameters = Delay:03C0 VCC:0A Glitch Type:06
Sc.Read: Timeout Reading Data From Card - 2 Bytes Requested, 0 Bytes Read, Continuing Script
Script Error on Line 117
Sc.GetByte: Requested Byte Exceeds Last Read Request
What happen, and what can I do to lessen the chance of it happening again. The card still appears to have a valid ATR, since I can put it in the IRD, and it still recongizes the card.
Mike
blacksmith9696
04-14-2006, 05:54 PM
I have a milikobu unlocker will it work with this script or with any of the new 106 107 unlocker scripts ??
haris2k7
04-15-2006, 07:31 PM
can you please give me a digikey part number..
I looped my 102 rev 106 than i found your post my bad luck do u know if any unlooping script for 102 rev 106>???
thanKs
do not use with out the 4619 chips as stated. if your not sure open your loader and look next to the card slot there should be 2 chips. and no you dont have to buy the expensive nexus if you have soldering skills. you can get the chips from digikey for cheep and install them yourself. i put them in my t911 blue case myself back in december.
woods
pytor
modded t911 blue case. self installed 4619
221 ohms
2 and 5 down
newd 13
ran for less then 1 minute and poped
Newfygarge
04-15-2006, 11:57 PM
Darn got orange Nexus but chips are 4053
haris2k7
04-17-2006, 08:59 PM
do not use with out the 4619 chips as stated. if your not sure open your loader and look next to the card slot there should be 2 chips. and no you dont have to buy the expensive nexus if you have soldering skills. you can get the chips from digikey for cheep and install them yourself. i put them in my t911 blue case myself back in december.
woods
pytor
modded t911 blue case. self installed 4619
221 ohms
2 and 5 down
newd 13
ran for less then 1 minute and poped
Whats the Digikey part number wood???
haris2k7
04-17-2006, 09:00 PM
do not use with out the 4619 chips as stated. if your not sure open your loader and look next to the card slot there should be 2 chips. and no you dont have to buy the expensive nexus if you have soldering skills. you can get the chips from digikey for cheep and install them yourself. i put them in my t911 blue case myself back in december.
woods
pytor
modded t911 blue case. self installed 4619
221 ohms
2 and 5 down
newd 13
ran for less then 1 minute and poped
Whats the Digikey part number wood???
studmonkey76
04-17-2006, 11:25 PM
Id like to know what the part number is as well
studmonkey76
04-17-2006, 11:37 PM
i believe its this
woods
04-18-2006, 12:50 AM
that is the incorrect part number. also do not use live links as stated all over the board
hxxp://www.digikey.com/scripts/DkSearch/dksus.dll?Criteria?Ref=321682&Site=US&Cat=33620664
woods
studmonkey76
04-18-2006, 12:57 AM
didnt use a live link...used hxxp as u can see
woods
04-18-2006, 02:22 AM
didnt use a live link...used hxxp as u can see
it was a live link. anylink you can click that takes you to a site is a live link. you need to unparse html when you post an addy. i click your link and it took me to their site. just an fyi, no disrespect intented.
woods
couch patato
04-18-2006, 03:17 PM
woods
i thought you said not to put 2 and 5 down. this will loop card. then in your post on how you fixed card you stated 2 and 5 down. not being smart just don't to make matters worse for myself and others. thanks, please forgive if i got this wrong.
couch patato
04-18-2006, 03:19 PM
sorry put my glasses on and read again. old age is a b*^$#
lightning0009
04-18-2006, 07:44 PM
After you unlock your rev 106 card you can read it in n2edit, but it will be provider unknown. To fix that Click on the eeprom tab and right click on the 30C0 line and click edit and change the first two bits of the 30C0 line from BF to A7 for dishnetwork. Now you can click on clean codespace and it will clean to rev103 and then save image. This is your bin now and can be programmed up with tiers and a blocker. You can also just write a good clean bin to it, but if you need to use the original bin, then you need to do this to fix it.
$30C0=A7BF0000000000000000000000000000
Example of what the first two bits should be- A7 for Dishnetwork, bev is different.
woods
04-19-2006, 01:54 AM
After you unlock your rev 106 card you can read it in n2edit, but it will be provider unknown. To fix that Click on the eeprom tab and right click on the 30C0 line and click edit and change the first two bits of the 30C0 line from BF to A7 for dishnetwork. Now you can click on clean codespace and it will clean to rev103 and then save image. This is your bin now and can be programmed up with tiers and a blocker. You can also just write a good clean bin to it, but if you need to use the original bin, then you need to do this to fix it.
$30C0=A7BF0000000000000000000000000000
Example of what the first two bits should be- A7 for Dishnetwork, bev is different.
you only need to fix that line if you want to write the image back without any changes. if you clean codespace that also seems to correct the problem.
i read bin, cleaned codespace wrote back and provider unknown was fixed.
woods
lightning0009
04-19-2006, 05:05 AM
Woods,
I couldn't clean codespace on mine until I fixed the provider unknown first. It would not clean codespace until I changed that then I could. I tried to clean codespace before fixing the provider and it said no valid bin loaded. I did read that all you had to do was clean codespace, but I couldn't as it was, so I changed it then I could.
vBulletin® v3.8.4, Copyright ©2000-2009, Jelsoft Enterprises Ltd.