Welcome to Mili's Marauders.
Header

 
ViP211 modded HDTV IRD

ViP211 modded receiver

Slinger ready
Free shipping

SALE PRICE: $349!!!
RomCode DishTV Subscription

RomCode DishTV Subscription

FROM: $69.00
Slinger IKS Kit
FREE SHIPPING

Slinger kit
PRICE: ONLY $199!!!
CLICK
HERE FOR INSTRUCTIONS
ViP622 modded HDTV IRD

ViP622 modded receiver

Slinger ready
Free Canada shipping

PRICE: ONLY $549!!!
BGA TSOP programming for ViP722 IRD

BGA tsop programming services for ViP722 receivers

PRICE: $144.00
FREE CANADA SHIPPING
Buffered JTAG Programmer

JTAG programmer

 PRICE: $39.00
MaxMel Emulator
MaxMel Emulator
PRICE: $59.00
FREE SHIPPING
SB5101 Diagnostics Modem

VIP downloads
PRICE
: $149.00
ViP722 modded HDTV IRD

ViP722 modded receiver

Slinger ready
Free Canada shipping

PRICE: ONLY $649!!!
BGA TSOP programming for most IRDs
BGA tsop programming services

PRICE: $124.00
FREE CANADA SHIPPING
Latest developments:
Slinger IKS boxes are now in store. All porn open, all premium chanels open. Hindi, Latino, Urdu Internationals. Running on Nagra 3 already and right now. Get them today HERE

Router Configuration

Slinger FAQ

Slinger Instructions

Files and VIP

VID Mod Instructions

JTAG-ing

Mili's Marauders » mili's Forums » General Forums » XM Hardware and Software » Factual Information on Sony XM01 Receivers

Notices


XM Hardware and Software All Aspects of reception, hardware and hacking the XM Satellite Radio

Reply
Thread Tools vBmenu Seperating Image
Factual Information on Sony XM01 Receivers
Old 02-20-2004   #1
dssdude
 
Status: Guest
Posts: n/a
Lightbulb Factual Information on Sony XM01 Receivers

There is NO receiver ID # information on the
Serial EEPROM OR the TSOP Flash.
It appears as though the ID# does not exist on the
the smart chip(ST19AF08) either. After swap out of chips from identical receivers - there was no change in reported ID number.

Where else could the data be stored? If anyone has some ideas/thoughts, I'd love to hear them.
  Reply With Quote
Old 04-08-2004   #2
minghia
 
Status: Guest
Posts: n/a
So I guess this effort has died?
  Reply With Quote
Old 04-09-2004   #3
 
Status: Guest
Posts: n/a

Last edited by BossMonkey; 04-09-2004 at 03:56 AM..
  Reply With Quote
Old 04-09-2004   #4
dssdude
 
Status: Guest
Posts: n/a
Quote:
Originally Posted by BossMonkey
The subscription is stored on the flash. That's why that cloning hack works.
Key Changes are where Im running into trouble I do belive But I could be wrong.
Ok... provide some proof of your theory. If two flash dumps from two identical xm radio's are compared, where are the differences found?
  Reply With Quote
Old 04-09-2004   #5
 
Status: Guest
Posts: n/a

Last edited by BossMonkey; 04-09-2004 at 05:00 AM..
  Reply With Quote
Old 04-09-2004   #6
dssdude
 
Status: Guest
Posts: n/a
Quote:
Originally Posted by BossMonkey
To be honest I dont know I havent tried dumping the flash. But with ability to clone one unit from another that just seems to be the logical choice to me. Dish dose it that way & that experience is what Im drawing my assumption from. Am I wrong? I know you put more thinking into this than I have. And like you Im only trying to find a way in...

P.S They might have put it in Ram on the Cpu or in the added on Static RAM not the best way to get things done. I read in the datasheet that they can mask memory Or you maybe dumping something other than rom Is that possable?
RAM is temporary storage... The CPU has no data storage capability...
Subscription is stored in ST19AF08. Keep reading as most other information found about XM hacking is bogus & doesn't work.
Getting into the ST19AF08 is beyond my capability right now. Perhaps the answer is through firmware modification?
  Reply With Quote
Old 04-09-2004   #7
 
Status: Guest
Posts: n/a

Last edited by BossMonkey; 04-09-2004 at 05:29 AM..
  Reply With Quote
Old 04-09-2004   #8
 
Status: Guest
Posts: n/a
  Reply With Quote
Old 04-09-2004   #9
dssdude
 
Status: Guest
Posts: n/a
Quote:
Originally Posted by BossMonkey
One thing is for sure I think you & I can find away to do this. This is not out of the realm of possibility. And I can also see using what we learn put to practical use in charlies world...
My flash dumps were taken directly from the chip using an eeprom programmer - no jtag was used. That method is a waste of time and will more than likely cause the average electronics tinkerer to destroy both an xm receiver & a dish receiver. Not recommended. XM has almost no similarities with dish other than being a satellite receiver.
Different stream encryption routines + different smart card processor(CAP)
Keep thinking - I'm open to suggestions & will try them if you can come up with a valid idea.
  Reply With Quote
Old 04-09-2004   #10
 
Status: Guest
Posts: n/a
  Reply With Quote
Old 04-09-2004   #11
 
Status: Guest
Posts: n/a
  Reply With Quote
Old 04-09-2004   #12
dssdude
 
Status: Guest
Posts: n/a
Quote:
Originally Posted by BossMonkey
Lets also get this out in the open I read they use the method as dish to decrypt keys is that verifiable? Or do they use the dtv side tiers & experatition dates?
Can you provide a link to that reference? My best guess is their subscription level structure is completely different than either dish or dtv. I have not been able to read the ST19AF08 so I couldn't tell you for sure.
Keep in mind that this chip was approved for financial transactions as such, it is probably one of the most secure chips available. Getting into the ST19AF08 family would leave a gap far and wide that could effect the financial market if ported to a credit card/debit card. I don't know for sure if they actually use this smart card for financial purposes or not. Either way, who would be liable if a comprimise was released? I sure as hell wouldn't want it to be me.
  Reply With Quote
Old 04-09-2004   #13
 
Status: Guest
Posts: n/a
  Reply With Quote
Old 04-09-2004   #14
dssdude
 
Status: Guest
Posts: n/a
Quote:
Originally Posted by BossMonkey
Yes I can provide a link its old info but one of many links I have found on the subject

http://www.river-lemon.org/xm.htm
I remember that one... all they're posting here is secondhand information that wasn't verified. The flash cannot hold the subscription. You can discard this link as bogus.
  Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump


All times are GMT +2. The time now is 05:22 AM.

[Output: 74.55 Kb. compressed to 67.67 Kb. by saving 6.88 Kb. (9.23%)]