View Full Version : Partial crack in Europe?Anyone
BigVWman
12-12-2008, 03:13 AM
Anyone have any details on the alleged partial compromise in europe over the last 60 days? Any truth to any of it?
Zerokill
12-12-2008, 10:22 AM
Dreamboxes are cardsharing...but that isn't "new"...and it's not without faults. Some servers have been seized and sometimes they go days before another server pops up.
The N3 encryption & smartcard has NOT been "cracked" or compromised. They are still relying on the cards responses to various stimuli to feed other Dreamboxes (cardsharing).
Dreamboxes are cardsharing...but that isn't "new"...and it's not without faults. Some servers have been seized and sometimes they go days before another server pops up.
The N3 encryption & smartcard has NOT been "cracked" or compromised. They are still relying on the cards responses to various stimuli to feed other Dreamboxes (cardsharing).
This question was posted in the Dave forums, so we should assume he's asking about NDS based encryption.
I'll ask you again zerokill. What was your user name prior to September 2008?
Zerokill
12-12-2008, 05:56 PM
Didn't see where you asked me the first time...but I just registered in Sept 2008.
BigVWman
12-14-2008, 02:21 AM
yes I was talking dave, not sure how different they made their in house p4 and d1 but the NDS stuff in europe is rumored to be having some security issues on say viasat and skyitalia. I figured if anyone knows the real scop it would be someone here. also helps that this is the only forum i still belong to!! With the impending n3 issues maybe its time to take a look back at dave?
wizrdeye
12-14-2008, 03:59 PM
Still kinda newbie DTv tester got my HU audio card going working on trying to read the P4 D1 card like others have said, just read nothing else. I was wondering though, looking at card readers programmers are Europe ones any different? Like the Duolabs Dynamite +plus, and Cas Interface 3 +Plus, then ours? I have the old Absolute 1 Premier which worked great with Extreme HU for the HU card, I haven't been able to get WinExplorer to recognize it.
I wouldn't get too excited if NDS 'VideoGuard' has been partially compromised. Dave is still using NDS encryption but their own firmware to secure the card. :-(
LeeGibling
11-18-2009, 03:11 AM
This is a c&p from a recent post making the rounds on many European forums:
e.g. h++p://www.eurocardsharing.com/f68/reason-sky-italia-hack-not-public-190095
There has been quite a lot of interest in the changed CAM crypt that Sky Italia recently started using.
Here we will detail what will be happening in the upcoming weeks.
Today we will just start with some simple facts:
* The initialization sequence to the card now seems to require ZKT (D0 4A and D0 5A) *
* The control words received from the card need to go through an extra hashing process *
A working solution exists.
You may ask why the solution has not been made public yet and here are some of the reasons for that:
1. All the whining in various forums has not encouraged a public release.
2. It was expected that Sky UK would have implemented the same counter measure and there was no reason to impact those plans.
3. The counter measure opens up for 3 different post processing modes where only the first one has been put to use.
All 3 methods involve hashing and method 2 and 3 were not fully understood until recently.
When method 1 is released we may see a change to method 2 or 3.
Stay tuned for more information soon.....
(16-November-2009 06:01)
C&P
The whining bit is especially relevant, it is driving most of the old skool into the underground..............
As some people have noticed the part of the ECM destined for the STB has been changed.
More specifically 0x80 0x01 0x03 0xb0 0x01 0x01 was added in the part of the ECM named CA flags.
To make a correct solution it is necessary to parse both the CW flags and CA flags of the ECM and dig out the just mentioned data.
But before getting started with all this, ZKT seems to be needed in the initialization sequence of the card.
Luckily this is rather simple if you do not plan on doing the full verification, and the information needed
can easily be found on various forums or determined by logging the start-up sequence on an original STB.
We all know that Christmas is over a month away and therefore you cannot have any presents without doing a little work yourself.
When OSCam has been extended with simple support for D0 4A and D0 5A then it will make sense to continue.
Also it would be a good idea to start working on a parser for the Cw and Ca flags of the ECM.
Stay tuned for more information soon.....
Angels-of-Fire
vBulletin® v3.8.4, Copyright ©2000-2009, Jelsoft Enterprises Ltd.