View Full Version : Locked out of Card.. pls help
farenheit
12-04-2006, 05:55 PM
Hi,
To start with, i appologise if i have posted in the wrong forum, but see-ing as tho' you people over the pond have moved over to N2 & are using Rom 102's us here in the UK are still on N1, i couldnt find the appropriate room.
Well, nuff said, I was hoping some knowledgeable member here could help me out.
I was faffing around with a ROm 10 and wrote this image (see attached). just rename Rom-A3E.txt to Rom-A3E.bin and remove the txt at the end of Rom_A3E.zip.txt.
Ok, Now that you have the file infront of yourselves. my question is, how do i get back in to the card after i have wrote it?
Everytime i try to read it in Nagraedit, i get:
"Backdoor reported disabled, card may contain update.. etc"
Does this have a blocker implemented into it or a lock that i am unaware of.
Any one? :-(
Ta
FH
I cant get your bin to open.
farenheit
12-04-2006, 06:28 PM
Ok, erm...
try here :
http://rapidshare.com/files/6042033/Rom10-A3E.zip.html
Regards
FH
Still no luck. Open it with nagra edit 4.1 and look at D0D6. Thats where password is or should be.
farenheit
12-04-2006, 06:37 PM
Still no luck. Open it with nagra edit 4.1 and look at D0D6. Thats where password is or should be.
You mean here:
D0D0: 4A 3F B6 E3 92 6E 72 68 30 63 77 48 EE 8A 07 38
Ive just checked file and its ok.
Download and open with Nagraedit 4.1 as rom10 image and it opens fine.
So taking above pswd shud be:
72 68 30 63 77 48 EE ?
FH
If you guys used the same hook that we used, that would be correct password.
farenheit
12-04-2006, 06:58 PM
Tried that to no avail. :-(
The file i used is for for provider 40. (so not for us.)
Card works tho' but im out of cam.
Is there any coding guru around. i have a proposition for em.
FH
Try This.
;jc 0020
;rs
;dl 0150
tx 21C101BF5E
dl 0200
rx
jf failed
js unlock
:failed
mg Script*failed...
jp end
:unlock
rs
dl 0200
mg** BUG **
tx 210025A0CA00001F031D40011099054E697050457220497320 612062755474260000000000000005FD
dl 0200
rx
mg** writing of the emmkeys $D7**
tx 210045A0D7100040C641A186C6E565830F76F4DDAED63AA9C1 D2CBD646106C5847E3C7F6453B3BDF89335FEB65CA1CE3A0EA F2275E2432A17C99278866BBE77080683506169203961C
dl 0200
rx
tx 210045A0D71040405DEA791B57F8D74622E3DEFA9CB727215B 90046DCD02AB3972B426B2F901E320FAEBAA614B1FE9DCC5E0 B697746D0B13F06DE47A9D14D205D865B4339D77D71C4E
dl 0200
rx
tx 210045A0D7108040BCAB16DB0ABA24842173ABFDB156D5EC54 FB8F903B32030B68B6F71023A68E7A4AE0BD1770311A903ABA CEA06A02267B93D00D89F404283A48DD00BDCB8576DDD2
dl 0200
rx
tx 210045A0D710C040180EF52E352BBBD83FC5B74A086A099A51 DB415C7BA95DA3BBA2875629F6871491B0743965E1734BA170 A6F8AF2AF52B58C5497935D0C2450FA48136D74190F3D8
dl 0200
rx
mg**Emms deactivates to bugcatcher **
tx 210053A0CA00004D004B4001429763FE7C8DA6624A866E0F46 5901850F1EC9BB098DB204582D9637A8105E3AF986F3B5058F AF8CA557F8E927297FEC46C3FE50B247000C8CC6C00E52BAE0 B764502DDB3B1447A6600523
dl 0200
rx
tx 210053A0CA00004D004B400142FED3CF7AFC3AB2FFCED23089 E20DCFC73CDEAB2AA4EB52042357DA237346E7D909C2EFE7AA 2BA11391BC07972B8E627546D3F7919650CB21EAC06A0E1EB8 C5534386DB49E621D67005DD
dl 0200
rx
mg****** Emms to write the backdoors ******
tx 210053A0CA00004D004B400142815D538301835BE839812571 D1D4FF49C39560A22B1A06B2FD17755CE8A37D463E8D9CEA4E 776BF8F32DDD2D60AC11E216EAB6B307B409D32C5EC705F6CD C05176DA4C148CB8758D0514
dl 0200
rx
jp success
:success
mg was_SUCCESSFULL
mg BackdoorB66B0766026239A6A434F66950FE6607
:end
mg*Script_Finished*
Use it as a D2C file
Open it under comm. tab, test, if no errors run.
farenheit
12-04-2006, 07:11 PM
Isnt that for a ROm 11?
FH|
farenheit
12-04-2006, 07:35 PM
Ok...
Tried that. No Luck.
Guess i'll have to use it on my windscreen in the morning...
FH
s_gm06
12-04-2006, 10:43 PM
20 44 44 44 44 44 44 44
or 44 44 44 44 44 44 44 44
farenheit
12-04-2006, 10:54 PM
20 44 44 44 44 44 44 44
or 44 44 44 44 44 44 44 44
Tried that also, but didnt work.
Appreciate the help guys :)
FH
vBulletin® v3.8.4, Copyright ©2000-2009, Jelsoft Enterprises Ltd.