View Full Version : rom103 rev388 unlocked!
lightning0009
12-25-2006, 07:05 AM
Blue Nexus rev388 switches 2 and 5. 7.5 volts 500ma. No loop diode. 10 watt 5 ohm resistor and 25 ohm wire wound ceramic pot set about 20 ohms. Started glitching at 32E0.
Ram Intercept Installed. Trying to Open the 103.... Delay:32F0 VCC:14 Glitch Type:07
Elapsed = 00:06:43
-----07Rst13------------+ !!!!!!!
TX Data : A1
******* Good response received! *********
55
===========================================
55 was hit at: Delay:32F0 VCC:11 GlitchType:07
Elapsed: 00:06:47
VCC Resolution: 0.25
Delay Range: 32E0 to 32FF
lump72
05-18-2008, 11:29 PM
lighting what scrip did you use on your rev388 ? thanks
kellie
05-18-2008, 11:52 PM
please tell what script
skinerd
05-19-2008, 02:05 AM
Look at date of original post. I doubt a 388 was unlocked.......
ggjayjay
05-19-2008, 06:30 AM
for a Nexus Try 4 down only set your pot at 4 K and let her run if you don't see a + + every now any then stop and set your OHMS higher a good zone is 4k to 6K I use the ORG reb 306-388 unlocker with the NewRS Flash!! you can also set your start delay in the script Rev388 cards seem to like it down there!! Good luck!
ggjayjay
05-19-2008, 06:32 AM
I myself use a Green cyclone and they are very much if not the same unlocker!!
lump72
05-19-2008, 12:14 PM
for a Nexus Try 4 down only set your pot at 4 K and let her run if you don't see a + + every now any then stop and set your OHMS higher a good zone is 4k to 6K I use the ORG reb 306-388 unlocker with the NewRS Flash!! you can also set your start delay in the script Rev388 cards seem to like it down there!! Good luck!
ggjayjay ,, were can i find the,,Reb's 306-388 ORG scrip ,i've looked all-over and can't find ,,,and you say 4k ,would tha be 00.4 ohms or 40 ohms , or 400 ohms ? , thanks
tmb100
05-19-2008, 12:43 PM
4k = 4000 ohms, the k means thousand.
Hope this helps,
T
skinerd
05-19-2008, 01:14 PM
Why is it NO-ONE and I mean NO-ONE else reports a 388 unlocked?
pecker88
05-19-2008, 04:44 PM
edit:
sorry, shouldn't have opened my trap w/out first looking at my files!!
lump72
05-19-2008, 04:46 PM
pecker you know were i can get that scrip ,Reb's 306-388 ORG scrip ?,,,,, thanks bro
skinerd
05-19-2008, 05:10 PM
rev388 is unlockable. rev389+ is NOT
Why is it I read of 387 being the highest opened then?
Anyone else have a popped 388 to report on??
pecker88
05-19-2008, 06:11 PM
Why is it I read of 387 being the highest opened then?
Anyone else have a popped 388 to report on??
Sorry, I *thought* rev388 was unlockable, but i'm not so sure now.
To confirm, all i know is to look at the header of all .vxb scrips. Reb usually
notes what rev it will unlock.
ggjayjay
05-19-2008, 10:29 PM
I have poped Like 10 Rev 388 Now rev 389 that another story!! But Rev 386 threw Rev 388 can be unlocked and has been for like 1 year now!! I would have thought you would Have known that!! If you want me to find some logs on rev 388 Poping Im sure I can!!
Wiley-X
05-19-2008, 11:46 PM
I have successfully unlocked several ROM 103 Rev 385. I have run every script I can get my hands on for higher Revs. I have yet to unlock ANY Rev 388 or 389 BGAs. I have run several different BGAs through several different unlockers using several different scripts (as well as RM-1C).
I have come to the conclusion that anything higher than Rev 385 is not unlockable.
The Lizard King
05-19-2008, 11:51 PM
I have successfully unlocked several ROM 103 Rev 385. I have run every script I can get my hands on for higher Revs. I have yet to unlock ANY Rev 388 or 389 BGAs. I have run several different BGAs through several different unlockers using several different scripts (as well as RM-1C).
I have come to the conclusion that anything higher than Rev 385 is not unlockable.
I've unlocked a rev 387 with the high rev RebelSerf rom 103 script in WinExplorer.
TLK :cool:
http://static.flickr.com/115/315008142_a64d4ac152_o.gif
lump72
05-20-2008, 12:05 AM
does any-one have the RebelSerf rom 103 script in WinExplorer , that does Rev388 ?
gobtool
05-20-2008, 02:56 AM
I wish I knew what needed to be changed in the unlocking script to have a chance at unlocking 388 or 389 revs. I guess the info needed is in the part of the card we don't have a dump on. I would try anything on my 389, my 625 receiver in three or four pieces is taking up too much room and I might not remember how to put it back into one piece if I did get the icam unlocked. I'm too cheep to buy something unlockable.
gobtool
05-20-2008, 03:30 AM
I'm sure you lose cards and icams getting the unlocker programs to work. It's a lot of trouble removing the icam or wiring to these receivers to experiment, and they aren't as many of these as there are plastic 102's and 103's. I would like to send Rebelsurf or PGM a donation, if I knew how to do it safely.
ggjayjay
05-20-2008, 03:41 AM
Wow This is Strange No one But me here poped a Rev 388 wow Now I fell like a God Lmao!! No Guys I am No 1 post wonder what I say is true!! If you need me to Mod the script for ya I will. But Its Not hard The start delay is good to start at 3100 Hey shi$ if you guys don't beleve me I will buy all your Rev 388 lol!! Well goodluck!!
ggjayjay
05-20-2008, 03:45 AM
shi$ My bad Start delay set to 3100 Not 3000 Pin 4 on only and set the pot to 4k or highter don't go over 6k. let her run for like 25 - 30 min and Power supply is 9v or 12v
ggjayjay
05-20-2008, 03:56 AM
Option Explicit
Dim Shell
Set Shell = CreateObject("WScript.Shell")
Dim StartDate
Dim FileName
Dim OutFile
Dim BuffFlg
Dim bytes2
Dim LoopCntr
Dim RstFlg
Dim DlFlg
Dim bytes
Dim Dump
Dim Uflg
Dim Acnt
Dim Mix
Dim VS1
Dim VT1
Dim DS1
Dim LP1
Dim LP2
Dim T1
Dim T2
Dim T3
Dim T4
Dim T5
Dim T6
Dim T7
Dim VG
Dim DD
Dim RT
Dim GT
LP1 = 1
Dump = 18432
BuffFlg = 0
LoopCntr = 0
RstFlg = 1
DlFlg = 0
Uflg = 0
VT1 = 2
DS1 = &h31F0 <--- Change this to 3100 Thats it!!!!
DD = &h3260
GT= 7
RT = DS1
lump72
05-20-2008, 05:01 AM
ggjayjay ,, does this look right , and allso the scrip runs slow ,stops on every ,,07Rst20-,, for a couple sec's or so ? thanks
Rom 103, Rev 388 found.
Initial Parameters = Delay:3100 VCC:20 Glitch Type:07
-07Rst20-------07Rst1E----07Rst1E-07Rst1E----07Rst1D----07Rst1C----07Rst1B--07Rst1B07Rst1B-------------07Rst1807Rst18---07Rst18----07Rst17--07Rst17-
niceman99
05-20-2008, 07:01 AM
me too ill pay for unlocking a rev 389
kellie
05-20-2008, 07:14 AM
Rom103_Omniunlocker
send it to me i will do it
kellie
05-20-2008, 07:15 AM
if not pm and i will send you 103 scripts i have
if you feel lucky
kellie
05-20-2008, 07:18 AM
RebelSerf 103_Rev307_387 Unlocker_Reader_newdRS_B
that is what your looking for
kellie
05-20-2008, 07:25 AM
this is a few file names your looking for try them
CCR FM 103 Interceptor TEST 1
103D2C (great tool )
Mikobu unlockers 102s & 103s
pecker88
05-20-2008, 07:13 PM
i know for a FACT that rev389, 38B and 38C is currently NOT UNLOCKABLE using ANY public script.
Rumors:
1. The above high rev rom103's are privately unlockable, but the loop rate was around 60%...too high for public consumption
2. High rev rom103's are unlockable, but...the unlocking script that is required reveals other secrets that the public should NOT know about yet. IMHO *other secrets* probably refers to Sox, 206 or 240 unlocking.
All in all, their is DEFINITLY a reason as to why we havn't seen a public high rev rom103 unlocker in over 1.5 years. As soon as rom102 revs are streamed, an unlocker magically gets *leaked* or released seemingly overnight.
Now...why hasn't this been the case for rom103 cams??? Things that make you go hummmmmmmmmmmmmm
lump72
05-20-2008, 11:13 PM
ggjayjay, does this look right ? allso the scrip runs SLOW , is that right allso ? i get a-lot of,,, Rst's ? thanks
07Rst14-07Rst14--07Rst1407Rst14-07Rst14-07Rst1407Rst14-07Rst14-07Rst14-----07Rst1
407Rst14-07Rst14--07Rst14-07Rst1407Rst1407Rst14-07Rst14-------07Rst12--07Rst12-------07Rst1107Rst11---07Rst10
------07Rst0F----07Rst0E-07Rst0E--------07Rst0D---07Rst0C07Rst0C---07Rst0C07Rst0C07Rst0C07Rst0D----07Rst0C07Rst0C-----
07Rst0B07Rst0C----07Rst0B07Rst0B-----07Rst0A-07Rst0A07Rst0A--07Rst0A07Rst0A---07Rst0A--07Rst0A07Rst0A07Rst0A-07Rst0A07Rst0A
-------07Rst09-07Rst09---+-----
ggjayjay
05-21-2008, 06:12 AM
whats your Ohms set to? I see a + thats good But there should be at least 5 10 per delay!! Guys Rev388 or Lower!! Try to pop your Rev 389 or 38B you will loop it!! So Don't!! We are only talking Rev 388 and Lower!!
ggjayjay
05-21-2008, 06:14 AM
The last 388 I poped was 2 months ago! I just got a 522 but the cards at Rev 386 or I would pop it and post my setting!!! Some will loop and some will pop just like any high rev!!
ggjayjay
05-21-2008, 06:14 AM
And Lump Resets are not a bad thing just the same reset over and over is!!
pecker88
05-21-2008, 06:46 AM
maybe the high rev 103's would pop easier if powerpirate would upload his rev38C unlocker!!!!!
J/K his claims are ill supported!!!
lump72
05-22-2008, 01:40 AM
Holly Cow ,, It pop'ed !!!!!!!!!! :) thank you ggjayjay for all your HELP !!!!! :) Rom103 Rev388 yes thats right rev388
powersync
sw-4
NO POT < advice from a friend i took it OFF , it work'ed
12v 300 ma
Ram Intercept Installed. Trying to Open the 103.... Delay:31DD VCC:18 Glitch Type:07
Elapsed = 01:40:34
07Rst18----------------------07Rst13--------07Rst1207Rst12------07Rst10----------07Rst0E07Rst0E--------07Rst0D--07Rst0C---
--07Rst0C---------07Rst0A--07Rst09---------07Rst07--07Rst0707Rst07-07Rst07-07Rst07--------------07Rst04------+ !!!!!!!
TX Data : A1
******* Good response received! *********
55
===========================================
55 was hit at: Delay:31DD VCC:03 GlitchType:07
Elapsed: 01:41:11
VCC Resolution: 0.25
Delay Range: 3150 to 32F0
EEPROM SAVED AS C:\Documents and Settings\HOHO\My Documents\522
********************************
* REV 306/386 CAM NOW OPEN!! *
* PROCEED AS NORMAL *
* GOOD LUCK! :-) *
********************************
Script C:\Documents and Settings\HaHA\Desktop\RebelSerf_103_Rev307_387_Unl ocker_Reader_newdRS_B.xvb Transmission Completed
ggjayjay
05-22-2008, 06:00 AM
Great to hear!!!;)
SEARCHY4
05-22-2008, 09:35 AM
i was just about to say why the creater of this thread has not came back in. glad to hear other people steped in to risk ther cams to someone posting and leaving. some of you have balls. good job. it's nice to know.
onewish
05-23-2008, 11:30 PM
Good to see you can get into a 388, but does anyone know where a bev rev 3C4 fits into the picture. What's it equal to in the Dish revisions?Thanks for any info you can send my way.
ggjayjay
05-24-2008, 12:25 AM
Funny thing is that we been able to get in them Rev 388 for over a year now!!
lightning0009
06-05-2008, 02:33 AM
My balls must be the biggest then cause I was the first one to post I unlocked one way back when. Up to rev388 can be unlocked with public scripts. Anybody need to know anything else from me? Anybody who says they could unlock your high rev rom103 for sure is blowing smoke up your arse. As far as me leaving? I've been here since 2003. Why don't you PM me if you need anything specific? I don't check in here at Millis everday anymore. Geeeez. And Skinard, you know if I posted I unlocked it I did. I posted to let other people know it's possible. You know me, I like to be first.
Also if you look at the date, it was a year and a half ago I popped my first 388, so ya.
Lightning
ggjayjay
06-06-2008, 03:32 AM
Not going to happen!! If there is Underground It will stay there!! There will be No Unlocker there would have by now!!
jayel
06-15-2008, 09:39 PM
I have successfully unlocked several ROM 103 Rev 385. I have run every script I can get my hands on for higher Revs. I have yet to unlock ANY Rev 388 or 389 BGAs. I have run several different BGAs through several different unlockers using several different scripts (as well as RM-1C).
I have come to the conclusion that anything higher than Rev 385 is not unlockable.
I unlocked a couple of 386's probably 3 yrs. ago, been using one for emulation on a 522 since then.
zman1858
10-24-2008, 02:51 AM
RebelSerf 103_Rev307_387 Unlocker_Reader_newdRS_B
that is what your looking for
will this work on rom103 rev388 can anyone confirm
lightning0009
10-24-2008, 08:21 PM
I used this one for 388
'************************************************* *************************************
'* New VB SCRIPT CREATED BY REBELSERF - 3/25/06 *
'* *
'* FOR STREAM LOCKED ROM 103'S REVISION 306/386 OR HIGHER. *
'* USES ONLY NEWDRS.HEX WITH LOADER *
'* LOADER MUST USE MAX4619 OR ADG733 SWITCHES FOR RELIABLE UNLOCKING *
'* *
'* HAPPY UNLOCKING AND GOOD LUCK!! *
'* *
'************************************************* *************************************
Option Explicit
Dim Shell
Set Shell = CreateObject("WScript.Shell")
Dim StartDate
Dim FileName
Dim OutFile
Dim BuffFlg
Dim bytes2
Dim LoopCntr
Dim RstFlg
Dim DlFlg
Dim bytes
Dim Dump
Dim Uflg
Dim Acnt
Dim Mix
Dim VS1
Dim VT1
Dim DS1
Dim LP1
Dim LP2
Dim T1
Dim T2
Dim T3
Dim T4
Dim T5
Dim T6
Dim T7
Dim VG
Dim DD
Dim RT
Dim GT
LP1 = 1
Dump = 18432
BuffFlg = 0
LoopCntr = 0
RstFlg = 1
DlFlg = 0
Uflg = 0
VT1 = 2
DS1 = &h32E0
DD = &h32FF
GT= 7
RT = DS1 'Do not change any values above this line
'^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ ^^^^^^^^^^^^^^^^^^^^^^^
Sub Main()
Setupunlocker()
If CheckChipVer <> 1 then
Sc.MsgBox("Flash Version NDRS needed to run this script" & VbCr & "Flash your Loader with NewdRS.hex")
Exit Sub
End if
' These, AND ONLY THESE :), are the variables you can change for rom 103 any revision up to 307/387
LP1 = 40 'Number of tries per delay FROM 20-100 in multiples of 20
VS1 = 32 'YOU CAN CHANGE THIS FROM 02-255 = semi-automatic VCC range - Loader dependent
Mix = 0.25 'Glitch VCC resolution - attempts per VCC = 1/mix
'^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ ^^^^^^^^^^^^^^^^^^^^^^
VG = VS1
sc.verbose = 0
Sc.Write("A0") ' turn led off
Clearoutputwindow
Call GetFileName()
If ChkCard() = 0 then
Fs.FileClose(OutFile)
exit sub
End If
If T7 = 1 then
Sc.MsgBox("Card not present or is unresponsive." & VBCr & " Unable to continue.")
Fs.FileClose(OutFile)
Exit Sub
End If
sc.verbose = 0
Sc.Write("06 0E 03 01 03 9A 00") 'reset card
sc.read(02)
bytes = sc.getbyte(1)
sc.read(bytes)
sc.delay(16)
Sc.write("2A 6023 210020A0CA00001A041801018600AA9D9D9D9D9D9D9D9D9DAE 69CC76D800000000000079 0E108500")
Sc.Read(2)
bytes = sc.getbyte(1)
If bytes > 5 then
sc.read(bytes)
bytes = sc.getbyte(0)
bytes2 = sc.getbyte(3)
If bytes = 18 and bytes2 = 132 then
Sc.MsgBox("Revision 306/386 or higher code not active on the card." & VbCr & " Card may be open or revision masked." & VBCr & " Unable to continue.")
Fs.FileClose(OutFile)
exit sub
End if
End If
StartDate = Now()
Print "Initial Parameters = Delay:" & HexString(RT, 4) & " VCC:" & HexString(VG, 2) & " Glitch Type:" & HexString(GT, 2)& vbcr & vbcr
Do
'sc.verbose = 1
Sc.Write("B5" & HexString(VG, 4))
Sc.Write("A0")
Acnt = 0
Do
Sc.Write("06 0E 03 01 03 9A 00") 'reset card
Sc.Read(02)
Bytes = Sc.Getbyte(1)
If Bytes > 25 then
Sc.Read(27)
Exit Do
End if
Acnt = Acnt + 1
If Acnt > 5 then
Sc.MsgBox(" Check Loader Settings. Invalid or no atr. Card may be looped." & vbcr & " Unable to continue.")
Fs.FileClose(OutFile)
exit sub
End If
Loop
'sc.verbose = 1 'debug the packets
Sc.Delay(5)
Sc.write("0B 03 15 6004 21C1018869 84 00")
Sc.Read(2)
bytes = sc.getbyte(1)
sc.read(bytes)
Sc.write("0B 03 15 6004 21C10103BC 83 00")
sc.read(2)
Bytes = Sc.Getbyte(1)
Sc.Read(Bytes)
Sc.Write("39 702E 8D009E00000000000000000000000000050000770100801105 71809CA64BB76B1864CD7E0031BD8008AE55CC76D846 20" & HexString(RT,4) & HexString(GT,2) & "0E13 85 00")
Sc.read(2)
bytes = sc.getbyte(1)
If bytes > 5 then
sc.read(bytes)
bytes = sc.getbyte(0)
bytes2 = sc.getbyte(3)
If bytes = &hD8 and bytes2 = &h55 then
Sc.verbose = 1
UFlg = 1
End If
If bytes = &hD8 and bytes2 = &h6F then
Print "-"
VG = VG - mix
RstFlg = 0
Else
Print "+"
RstFlg = 1
VG = VG + mix
End If
Else
PRINT HexString(GT, 2) & "Rst" & HexString(VG, 2)
RstFlg = 1
VG = VG + mix
End if
If Uflg = 1 then
Print " !!!!!!!" & VBCr
Sc.Write("A1")
Shell.Run "%comspec% /c echo " & Chr(07) & Chr(07) & Chr(07) & Chr(07) & Chr(07), 0, True
Sc.delay(500)
print
print "******* Good response received! *********"& VbCr
PRINT " " & HEXSTRING(bytes2,2) & VbCr
Sc.Print "===========================================" & VbCr
print " " & HexString(bytes2, 2) & " was hit at: Delay:" & HexString(RT, 4) & " VCC:" & HexString(VG, 2) & " GlitchType:" & HexString(GT, 2) &VBCr
print " Elapsed: " & TimeDiff(StartDate,Now())& vbcr
Print " VCC Resolution: " & mix & vbcr
Print " Delay Range: " & HexString(DS1, 4) & " to " & HexString(DD, 4) & VBCr
print
Call SaveEeprom()
PRINT "EEPROM SAVED AS " & Filename & VBCR
SC.DELAY(700)
PRINT "********************************" & VBCR
PRINT "* REV 306/386 CAM NOW OPEN!! *" & VBCR
PRINT "* PROCEED AS NORMAL *" & VBCR
PRINT "* GOOD LUCK! :-) *" & VBCR
PRINT "********************************" & VBCR
exit sub
End If
If VG < VT1 then
VG = VS1
End If
LP2 = LP2 + 1
If LP2 > LP1 / mix then
ClearOutputWindow
RT = RT + 1
LP2 = 0
print
print "" &vbcr
print "Ram Intercept Installed. Trying to Open the 103.... Delay:" & HexString(RT, 4) & " VCC:" & HexString(VG, 2) & " Glitch Type:" & HexString(GT, 2) & VBCr & vbcr
sc.print "Elapsed = " & TimeDiff(StartDate,Now())& vbcr & vbcr
If RT > DD then
RT = DS1 - 1
End If
End If
If VS1 >= 254 then
exit sub
End If
If VG =< 1 then
VG = VS1
End if
GT = GT - 1
If GT =< 6 then
GT = 7
End If
Loop
End Sub
Sub SaveEEprom()
Dim ByteCount
Dim RcvdBytes
Dim i
ByteCount = 0
sc.verbose = 0
Sc.Write("06 0E 03 01 03 9A 00") 'reset card
sc.read(02)
bytes = sc.getbyte(1)
sc.read(bytes)
sc.delay(16)
Sc.write("56 604F 21004CA0CA000046044401018600AA9D9D9D9D9D9D9D9DCD7B BC718092C6BE3CBF26023CBECD45239BB6BEA1C02713A13826 04A680B7BEAE05A6FF4A26FD5A26F920D9CD7BC7CD7B5DCC76 D29D3000A0 0E10 87 00")
Sc.Read(2)
Bytes = Sc.getbyte(1)
Sc.read(bytes)
Sc.write("13 0E25 600A 210007A0FF000002480033 55" & HexString(dump,4) & "00")
For i = 1 to Dump step 1
sc.read(1)
RcvdBytes = Sc.getbyte(0)
call Fs.FilePutc(OutFile, RcvdBytes)
Call Sc.ProgressBox ("Reading Eeprom", ByteCount, Dump, "Saving Bin...")
ByteCount = ByteCount + 1
Next
Fs.FileClose(OutFile)
end sub
Sub GetFileName()
FileName = Fs.FileSaveDialog("", "Please select a name for the dumped bin", "*.bn103")
If FileName <> "" Then
OutFile = Fs.FileCreate(FileName)
end if
end sub
Function HexString(Number,Length)
Dim RetVal
Dim CurLen
RetVal=Hex(Number)
CurLen=Len(RetVal)
If CurLen<Length Then
RetVal=String(Length-CurLen,"0") & RetVal
End If
HexString=RetVal
End Function
Function CheckChipVer()
CheckChipVer = 1
sc.write("90")
delay(80)
If sc.read(4) <> 4 then
CheckChipVer = 0
Exit Function
End if
If getbyte(0) <> &H4E then CheckChipVer = 0
If getbyte(1) <> &H44 then CheckChipVer = 0
If getbyte(2) <> &H52 then CheckChipVer = 0
If getbyte(3) <> &H53 then CheckChipVer = 0
End Function
Function TimeDiff (StartTime, EndTime)
Dim Hours, Minutes, Seconds
Seconds = DateDiff("s", StartTime, EndTime)
If Seconds > 90000 Then Seconds = 90000
If Seconds < 0 Then Seconds = 0
Minutes = Seconds / 60
Minutes = Fix(Minutes)
Seconds = Seconds - (Minutes * 60)
Hours = Minutes / 60
Hours = Fix(Hours)
Minutes = Minutes - (Hours * 60)
Seconds = CStr(Seconds)
Minutes = CStr(Minutes)
Hours = CStr(Hours)
If Len(Seconds) = 1 Then Seconds = "0" + Seconds
If Len(Minutes) = 1 Then Minutes = "0" + Minutes
If Len(Hours) = 1 Then Hours = "0" + Hours
TimeDiff = Hours & ":" & Minutes & ":" & Seconds
End Function
Function ChkCard()
sc.verbose = 0
ChkCard = 1
Print ""
Print " Checking Card's Eeprom Revision ......." & VBCr
sc.delay(2000)
ClearOutputWindow
Sc.Write("06 0E 03 01 03 9A 00") 'reset card
sc.read(02)
bytes = sc.getbyte(1)
If bytes < 27 then
T7 = 1
ClearOutputWindow
Exit Function
End If
sc.read(bytes)
sc.delay(16)
T1 = chr(sc.getbyte(16))
T2 = chr(sc.getbyte(17))
T3 = chr(sc.getbyte(18))
T4 = chr(sc.getbyte(23))
T5 = chr(sc.getbyte(24))
T6 = chr(sc.getbyte(25))
T1 = T1+T2+T3
T4 = T4+T5+T6
If asc(T4) = 0 then
T4 = "000"
End If
Print " Rom " & T1 & ", Rev " & T4 & " found." & VBCR
print
Sc.delay(1500)
If left(T4, 2) = 24 then
If mid(T4, 3,1) > 4 or mid(T4, 3,1) < 2 then
ChkCard = 0
exit function
End If
End If
If left(T4, 2) = 10 then
If mid(T4, 3,1) > 8 or mid(T4, 3,1) < 6 then
ChkCard = 0
exit function
End If
End If
If T1 <> "103" then
ChkCard = 0
exit function
End If
End Function
Function setupunlocker()
Wx.BaudRate = 115200
Wx.ResetBaudRate = 115200
Wx.Parity = 0 ' 0 = None, 1 = Odd, 2 = Even, 3 = Mark, 4 = Space
Wx.StopBits = 0 ' 0 = 1 stop bit, 1 = 1.5 stop bits, 2 = 2 stop bits
Wx.DTRControl = 0 ' Initial state of DTR 0 = off, 1 = on
Wx.RTSControl = 1 ' Initial state of RTS 0 = off, 1 = on
Wx.ResetDelay = 100 ' In microseconds
Wx.ByteDelay = 10 ' In microseconds
Wx.RxByteTimeout = 3000 ' In milliseconds
Wx.ResetMode = 2 ' 0 = No Resets, 1 = ISO Reset (Expect a ATR), 2 = Device Reset (No ATR)
Wx.ResetLine = 1 ' 0 = Toggle RTS for Reset, 1 = Toggle DTR for Reset
Wx.ByteConvention = 1 ' 0 = Inverse, 1 = Direct
Wx.FlushEchoByte = 0 ' 0 = no flush, 1 = flush - A Phoenix interface will echo each byte transmitted.
Wx.FlushBeforeWrite = 1 ' 0 = no flush, 1 = flush - Flush the receive buffer before each write to strip off Null bytes.
Wx.IgnoreTimeouts = 1 ' 0 = Abort script on a receive timeout, 1 = Ignore all receive timeouts
Wx.ResetAfterTimeout = 0 ' 0 = Don't reset after a timeout, 1 = do a reset after a timeout - Not used if "IgnoreTimeouts=0"
Wx.LogTransactions = 0 ' 0 = Don't log transactions, 1 = log transactions
Wx.DisplayUSW = 0 ' Display USW after script complete 0 = no, 1 = yes
Wx.DisplayFuse = 0 ' Display Fuse after script complete 0 = no, 1 = yes
End function
ggjayjay
10-24-2008, 11:34 PM
I would say the Start delay is to high I start mine at 3100!! My 2cents But I pop them all the time at that start and only in a few min!! shortest is 3sec longest 1hr and 19 min!!
lightning0009
10-30-2008, 09:05 PM
Good call as I adjusted this scripts delay for my loader, so you might want to lower the delay start.
This line up near the top.
DS1 = &h32E0
Change 32E0 to 3100 or your choice. The delay end is right below.
vBulletin® v3.8.4, Copyright ©2000-2009, Jelsoft Enterprises Ltd.