ViP211
modded HDTV IRD![]() Slinger ready Free shipping SALE PRICE: $349!!! |
RomCode DishTV Subscription
FROM: $69.00 |
Slinger IKS Kit FREE SHIPPING ![]() PRICE: ONLY $199!!! CLICK HERE FOR INSTRUCTIONS |
ViP622 modded HDTV IRD![]() Slinger ready Free Canada shipping PRICE: ONLY $549!!! |
BGA TSOP programming for ViP722 IRD
PRICE: $144.00 FREE CANADA SHIPPING |
Buffered JTAG Programmer![]() PRICE: $39.00 |
MaxMel Emulator
PRICE: $59.00 FREE SHIPPING |
SB5101 Diagnostics Modem
PRICE: $149.00 |
ViP722 modded HDTV IRD![]() Slinger ready Free Canada shipping PRICE: ONLY $649!!! |
BGA TSOP programming for most IRDs
PRICE: $124.00 FREE CANADA SHIPPING |
| Latest developments: |
| Notices |
| Nagra Glitching and Unlocking Discussions on unlocking ROM 3-11 cards, unlocker how tos, modifications and hopefully Nagra 2 glicthing |
![]() |
| Thread Tools | ![]() |
|
|
#1 |
|
Status: Registered User
Join Date: Oct 2003
Posts: 148
|
Stubborn Rom 10A81
I've been tring to pop this rom10 a81 for almost 3 days and no luck i've tried a few differnt flashes as well as different scripts.
Has anyone had much luck with rom 10's? Are there any new flashes that people are using other than newd7 and 8 ? Thanks for the help STP |
|
|
|
|
|
#2 |
|
Status: Registered User
Join Date: Apr 2004
Location: ontario
Posts: 250
|
I use newd8 and have you also tried using delay start of 0D00?
I also run it through vcc analizer 2 first |
|
|
|
|
|
#3 |
|
Status: Registered User
Join Date: Jul 2004
Location: Over Here
Posts: 844
|
Some A81 are a Beotch..
Here is my setting's of mine.. 83 was hit at 142C delay ----VCC WAS 99
__________________
Too often we lose sight of lifes simple pleasures. Remember when someone annoys you it takes 42 muscles to frown, BUT it only takes 4 muscles to extend your arm and B*^&$ slap that Mother %&*#@! upside the head. |
|
|
|
|
|
#4 |
|
Status: Registered User
Join Date: Jun 2004
Posts: 239
|
got one running right now thats the same way will not pop im thinking my loader is going bad though i have 3 cards here it wont pop i have popped a ton of them untill lately
|
|
|
|
|
|
#5 |
|
Status: Registered User
Join Date: Jul 2004
Location: Over Here
Posts: 844
|
Are you guys in Canada?
__________________
Too often we lose sight of lifes simple pleasures. Remember when someone annoys you it takes 42 muscles to frown, BUT it only takes 4 muscles to extend your arm and B*^&$ slap that Mother %&*#@! upside the head. |
|
|
|
|
|
#6 |
|
Status: Registered User
Join Date: Jun 2004
Posts: 239
|
im in the states
|
|
|
|
|
|
#7 |
|
Status: Registered User
Join Date: Jul 2004
Location: Over Here
Posts: 844
|
What scripts have you tried..?
I can give them a whirl if you'd like gimme a pm..
__________________
Too often we lose sight of lifes simple pleasures. Remember when someone annoys you it takes 42 muscles to frown, BUT it only takes 4 muscles to extend your arm and B*^&$ slap that Mother %&*#@! upside the head. |
|
|
|
|
|
#8 |
|
Status: Guest
Posts: n/a
|
Try This
Try changing the top vcc setting in the script to 50 and the bottom vcc setting to 30. Set the voltage on the wall transformer to 7.5 volts direct current vdc. Flash loader with flash 9 not 7 or 8. Works for me on those hard rom 10 cards bev or dish just choose the A81 Bev winex script or A23 Dish script whichever the card is streamlocked at. I hope this helps.Joe Last edited by JOE SNUFFY; 02-14-2005 at 03:56 AM.. |
|
|
|
#9 |
|
Status: Registered User
Join Date: Jun 2004
Posts: 239
|
cid pm bud
|
|
|
|
|
|
#10 |
|
Status: Registered User
Join Date: Oct 2003
Posts: 148
|
JOE, i'm trying your settings as I write this i'll let you know if it works.
Thanks for the info. STP |
|
|
|
|
|
#11 | |
|
Status: Guest
Posts: n/a
|
Sounds Good
Quote:
You can put the card in the freezer for like an hour also then wipe it off the smart chip really well then put in loader as the smart chip warms up it helps to pop themby slowing the processor in the smart chip. Joe ![]() |
|
|
|
|
#12 |
|
Status: Registered User
Join Date: Oct 2003
Posts: 148
|
I know that this might sound like a stupid question but do I have to flash the loader every time I disconnect the power??
Thanks |
|
|
|
|
|
#13 |
|
Status: Registered User
Join Date: May 2004
Posts: 89
|
Nop...you dont have to reflash the loader whenever you disconnect power.I use NewD8 or D8 and I am yet to lay my hands on any rom 10 I didnt open.Most I pop under 30 - 45 secs ...the longest run for about 4-5 mins after running vcc analyzer(as long as they have valid atr and non BD3/BD0 issues).I have since lost count of how many cards I have popped
If you got those stubborn cards that needs to be opened send me a PM(Canada only plz) |
|
|
|
|
|
#14 |
|
Status: Registered User
Join Date: Jul 2004
Location: Over Here
Posts: 844
|
fearlss have you found anything on your journeys might be helpfull for them BDO-BD3 errors..?
I havent came across anything yet.. What loader do you use to pop them that fast..?? Wich Pot etc..
__________________
Too often we lose sight of lifes simple pleasures. Remember when someone annoys you it takes 42 muscles to frown, BUT it only takes 4 muscles to extend your arm and B*^&$ slap that Mother %&*#@! upside the head. |
|
|
|
|
|
#15 | |
|
Status: Guest
Posts: n/a
|
Quote:
After you modded your loader did you use a rom3 with the test script to dial in the 5K pot? I try and get an even mix of FFFFF/AAAAAs sometimes you have to increase or play with the vcc settings (in the winex script) and the wall voltage transformer to fine tune it to get the best mix. I have found after modding several that those vcc settings and the wall transformer voltage normally will work well when you go to popping cards. Getting FFFFF/AAAAAs even mix which they will be at random but the key is your getting some of each not just all FFFFFs or just all AAAAAs then your going to be able to pop cards. If your not getting some of each you won't be popping any cards. To check your set-up, Load the test script on a rom 3 and run with the winex test script see what your getting that may be your problem. Increase or decrease wall voltages first to see if you can dial it in that way before changing the 5k pot setting. I normally use 6 or 7.5 volts as a starting voltage when dialing in a pot to get the FFFF/AAAS Note: These test scripts can be found in the downloads section under Dish Rom Files number 115 if you scroll down named rom3unlocker-glitcher2.zip or I can email it to you if you pm me. Once you have perfected your skills you will be able to pop them quick. It used to take me 15 mins normal time using an old 667mhz processor. Now I built a new computer with 2.7ghz I can pop them in under 60 seconds but thats with a lot of work and writing down which voltages and vcc setting work well for Rom 3s and Rom 10s which once I pop one I make a not of the settings on the actual loader so I won't lose them. The key is to get the even mix of FFFs and AAAs you do that when setting up the loader. I had a friend that ordered a pre-modded loader thinking he could just start popping cards but they didn't send a transformer so I knew it had to be dialed in a little time will save you a lot of time once its dialed in it might take 12 hours to pop (especially the bitch card) a card but it will pop if your getting the even mix it might not be in a few seconds making it pretty but you pop it and thats what the goal was. I hope this helps, Joe Last edited by JOE SNUFFY; 02-14-2005 at 05:07 PM.. |
|
|
|
|
#16 | |
|
Status: Registered User
Join Date: May 2004
Posts: 89
|
Quote:
I use a T911 (dips 2 and 4 on)with a trimmer(2k)...7.5 volts.The thing is I have popped more than a thousand cards with my loader that i know what vcc range to use.Once I have the right vcc settings the cards pop in seconds.Rom 3 or 10 it doesnt matter.I have popped a couple of rom 11's...and also looped some too.I dont really do peoples rom 11 unless the person agrees if it loops I wont be held responsible.The rom 11's take longer...almost 1-5 hours. |
|
|
|
|
|
|
#17 |
|
Status: Registered User
Join Date: Oct 2003
Posts: 148
|
Thanks for the info Joe, I kind of figured that you wouldn't have to flash the lodder every time but I just wanted to be sure .
The settings that you suggested worked it took about half an hour which was great, The only thing is that when I check it in Nagra edit and do a one step clean, i get this: Opening of COM1 was successful ATR String: 3F FF 95 00 FF 91 81 71 A0 47 00 44 4E 41 53 50 30 31 30 20 52 65 76 41 38 31 43 ROM Revision: 010 EEPROM Revision: RevA81 ProviderID: 08 CamID: 01 39 15 AE Using BD3 Key: 4E 69 70 50 45 72 20 49 73 20 61 20 62 75 54 74 Attempting to login to BD3 BackDoor login verified Dumping Dataspace Backdoor retrieval has been blocked Attempting to login to BD3 Attempting to login to BD0 Unable to login, bad password detected Login attempt aborted Reading ROM10 failed Closing of COM1 was successful Error detected, One Step Clean incomplete Is there any thing that I can do about a bad password?? Thanks for any advice. STP |
|
|
|
|
|
#18 | |
|
Status: Guest
Posts: n/a
|
Try This
Quote:
If you can't read the card then if you have the last file that was loaded to the card go click on eeprom and go to C040 line and enter those numbers as your bdo keys give that a try enter the numbers on that line till you don't need any more (I can't remeber how many you enter just enter till you don't need any more starting left to right). Try these lines also if that doesn't work same concept c050, co60, and c070 If that doens't work try this last step Open a rom 10 file for a receiver you know is working and click on load to card. Put the card in rec see if it works sometimes you will get the bdo error message but the write took place. 1 out of 10 cards maybe. Lastly if those don't work try and re-open the card with the modded loader I suspect it will pop quickly but you will still get the error message. If you do it most likely is not fixable if you tried everything I stated above. One last thing you might do is put it in the rec it came out and let it stay in the stream a few days it might fix itself then try and clean it. I hope you fix it, Joe Last edited by JOE SNUFFY; 02-15-2005 at 04:05 AM.. |
|
|
|
|
#19 |
|
Status: Registered User
Join Date: Oct 2003
Posts: 148
|
Well, no luck so far I tried the BDO Retriever and all I get are zero's.
I checked the last file that was loaded onto the card and tried from C040 to C0A0 and nothing . I'll try to load a file on the card and plug it back into the IRD for the night and try to read tomorrow night. If that doesn't work i'll leave in the IRD for a couple of days and see if anything happens. Thanks for all the usefull info. STP |
|
|
|
|
|
#20 |
|
Status: Registered User
Join Date: Oct 2003
Posts: 148
|
Finally got it repaired
I finally got that stubborn card repaired. It took a lot of reading and a few days but this is how I did it .I can not take any credit for any of the programs or the guide. But it worked great.
A Guide for Restoring Backdoor Keys on the Rom 10 The method described here has worked for myself, and hopefully works for you. Alright, this is the method used to restore the Backdoor 0 Key and Backdoor 3 key on a Rom 10 Rev A1D Provider 0001 (Dish Network)..also works with BEV. First we must convert the card over to Provider 4001 (Via digital). This will allow us to install backdoor keys to gain entry into the card. Once we get into the card we can write a valid Dish Network EEPROM (BIN) and return the card back to working order. First we need to convert the card to provider ID 4001 (Via Digital): Step 1A or Step 1B Second we will install known backdoor keys. : Step 2 Third we will test the card to see if it is fixed and restore it to the provider we need. You will need either Viagra or Backdoor Buster and Camwisler Official. Step 1A: Using Backdoor Buster to change provider ID. A. Load Backdoor Buster B. Click on the "Reset" button. After clicking the "Reset" button look at the area labeled "Card Information." Where it says "ROM Version" you should see something like the following: DNASP010 RevA16 DNASP010 RevA1B DNASP010 RevA1D Your information may vary but should look something like that. If you see garbage in that area then try clicking on the "Reset" button multiple times. If you still get garbage then try adjusting the timing under settings then click the "Test Timing" button until you find a setting that works for you. C. Now this is where some people have trouble and may need to use Viagra. If you cannot get this part to work after about 5 or 6 tries then skip to Step 1B. Click on the "Load Bug" button. You should see a response formatted like the following: 12 XX 05 71 01 YY (90 0X) ZZ XX=Will be one of these two numbers 00 or 40. YY=Will increment by one each time you press the "Load Bug" Button. ZZ=Checksum Byte, this will also change. (90 0X)=90 00 for a GOOD Response. (90 0X)=90 01 for a BAD Response. Now keep clicking the "Load Bug" button until YY = 29. You may need to try clicking on the button fast or slow to make this step work. If you do not get to YY=29 and stop getting a response then go back to Step 1A: B and try again. If you do not succeed after 5 or 6 tries then goto Step 1B. D. Now if you have successfully made it to this step then click each "Packet-X" Buttons once and in order. Where X = 1,2,3, and 4. E. Now click the "Write Keys 1" button next. You should see a response formatted like the following: 12 XX 07 80 B1 29 (90 0X) ZZ XX=Will be one of these two numbers 00 or 40. ZZ=Checksum Byte, this will vary. (90 0X)=90 00 for a GOOD Response. (90 0X)=90 01 for a BAD Response. If your response does not fit the above then click the "Write Keys 1" until it matches the above. F. Click on the "Reset" button. G. Click on the "Test Nipper 4001" button. If you get the response "Nipper Login Successfull!" then Step 1A: was successful and go to Step 2. You may need to click it more than once. Step 1B: Using Viagra to change provider ID. A. Load Viagra for Rom 10 B. Click on the button that looks like a "Blue Book" A window will pop up to open a file. Select the file named "rom10-TheWholeBug.cfg" Then click the "Open" Button. C. Click on the Tab Labeled "Card." D. Click on the button "Open Port." E. Click on the button "Reset." F. Double Click where it says "000-Cmd41 Packet" You should see a response formatted like the following: 12 XX 05 71 01 YY (90 0X) ZZ XX=Will be one of these two numbers 00 or 40. YY=Will increment by one each time you press the "Load Bug" Button. ZZ=Checksum Byte, this will also change. (90 0X)=90 00 for a GOOD Response. (90 0X)=90 01 for a BAD Response. Now keep double clicking where it says "000-Cmd41 Packet" until YY = 29. G. Double Click where it says "001-after 29 response packet1" H. Double Click where it says "002-packet2" I. Double Click where it says "003-packet3" J. Double Click where it says "004-packet4" K. Close Viagra and go to Step 2. Step 2: Using Camwisler official to install Backdoor Keys for the provider 4001 (Via Digital) A. Load Camwisler B. Click the "Calibrate" button. C. Click the "Reset CAM" button. Look where it says "Provider:" in red type. It should have 4001 next to it. If not then click the "Reset CAM" button until you see the correct provider # 4001. You may have to repeat steps 2B. and 2C. several times. (If you used Viagra in Step 1B and cannot get a provider ID 4001 then go back to Step 1B and repeat those steps.) D. When you have the correct Provider ID 4001 then look for where it says, "Packet to send goes here." This is where you will be pasting some packets. E. You will not be able to paste info into the packet window using your mouse. To paste text into the packet window highlight whatever is in the window with the mouse and press the "Delete" Key. Then highlight the text from this file that you need to paste and press "Control"+"C" to copy. In Camwisler click on the packet window with the mouse and press "Control"+"V" to paste the text. F. Login Packet: This packet allows you to login to a Via Digital Card (4001). Copy and paste this packet as I instructed in step E. 210025A0CA00001F031D40011099054E697050457220497320 612062755474260000000000000005FD Next to the packet window in camwisler click on the "Send button. Look where it says "Response RX". You should see a response formatted like the following: 12 XX 07 83 03 B1 01 01 (90 0X) ZZ XX=Will be one of these two numbers 00 or 40. ZZ=Checksum Byte, this will vary. (90 0X)=90 00 for a GOOD Response. (90 0X)=90 01 for a BAD Response. G. Packet 1 Copy and paste this packet as I instructed in step E. 210045A0D71000406A9A5ED124D2B33E9DD69408D17448BD69 C6DE48966E9FCFDF6744147D2666D5B7C145C0B0AF8775AF05 261038EA95C8C2668432AC0042FD0EB957B7E592E68D16 Next to the packet window in camwisler click on the "Send button. Look where it says "Response RX". You should see a response formatted like the following: 00 XX 02 (90 0X) ZZ XX=Will be one of these two numbers 00 or 40. ZZ=Checksum Byte, this will vary. (90 0X)=90 00 for a GOOD Response. (90 0X)=90 01 for a BAD Response. H. Packet 2 Copy and paste this packet as I instructed in step E. 210045A0D7104040F6DDE717F945B98AFCB6506524A206F299 8CA630CE320E8D19349C5ADE974179698E587C188BA3A3A430 08730CC9D608E9A80C4BE6AC3D762B3A469EEC4F37EF2D Next to the packet window in camwisler click on the "Send button. Look where it says "Response RX". You should see a response formatted like the following: 00 XX 02 (90 0X) ZZ XX=Will be one of these two numbers 00 or 40. ZZ=Checksum Byte, this will vary. (90 0X)=90 00 for a GOOD Response. (90 0X)=90 01 for a BAD Response. I. Packet 3 Copy and paste this packet as I instructed in step E. 210045A0D710804072AC3EA575E0649DA9F9A5B9EDE5A356C2 C1C6EF84E3D0662D4DB7ACA940D9ADA55E5C59F4184292CA3F 7EE0A3DEF1E33CF75F054B3EDADC32D69A3F3D4CFA6FC7 Next to the packet window in camwisler click on the "Send button. Look where it says "Response RX". You should see a response formatted like the following: 00 XX 02 (90 0X) ZZ XX=Will be one of these two numbers 00 or 40. ZZ=Checksum Byte, this will vary. (90 0X)=90 00 for a GOOD Response. (90 0X)=90 01 for a BAD Response. J. Packet 4 Copy and paste this packet as I instructed in step E. 210045A0D710C040C531B9969926E8D98EE7D3A48ADC4A5B04 B13B7D93902E6A7CD1BDFEAAF9051CB73E782E8BE597897F66 FE699F4809F71431570830FC53D4410D2B35D2CE7ACA58 Next to the packet window in camwisler click on the "Send" button. Look where it says "Response RX". You should see a response formatted like the following: 00 XX 02 (90 0X) ZZ XX=Will be one of these two numbers 00 or 40. ZZ=Checksum Byte, this will vary. (90 0X)=90 00 for a GOOD Response. (90 0X)=90 01 for a BAD Response. K. Backdoor Keys-Packet 1: Packet to restore Backdoor Keys Copy and paste this packet as I instructed in step E. 210053A0CA00004D004B4001026992FDB10D58F0A41CB6C8D7 6839ABC25C1F2831FD5B7D4D75B5F07E046F4E228EE71C4064 0C8FCFB5741A5E08B66DDBABDFD8620183007A98A01035E96F FAEBC4A20FBD6DA2E1380508 Next to the packet window in camwisler click on the Send" button. Look where it says "Response RX". You should see a response formatted like the following: 12 XX 07 80 03 B1 01 02 (90 0X) ZZ XX=Will be one of these two numbers 00 or 40. ZZ=Checksum Byte, this will vary. (90 0X)=90 00 for a GOOD Response. (90 0X)=90 01 for a BAD Response. L. Backdoor Keys-Packet 2: Packet to restore Backdoor Keys Copy and paste this packet as I instructed in step E. 210053A0CA00004D004B4001028D5894CB4AFD0D78D57880DA ECC0E72C3DFBF52F6A288DF1F58A5764C12CD62210E22A1B58 16F6BC874DA7ADF49FA97469B344C94C7334428AEADB5F0CB7 7272263A41EBBE88BCB6050D Next to the packet window in camwisler click on the "Send" button. Look where it says "Response RX". You should see a response formatted like the following: 12 XX 07 80 03 B1 01 03 (90 0X) ZZ XX=Will be one of these two numbers 00 or 40. ZZ=Checksum Byte, this will vary. (90 0X)=90 00 for a GOOD Response. (90 0X)=90 01 for a BAD Response. M. Click the "Reset CAM" button. Look where it says "Provider:" in red type. It should have 4001 next to it. If not then click the "Reset CAM" button until you see the correct provider # 4001. N. Look where it says "IRD:" in red type. It should have 33333333 next to it. If not then go to Step 2C. and repeat steps 2C through 2N. O. Close Camwisler Step 3: Restoring the card to your provider using Nagra Edit 3.0. A. Open Nagra Edit 3.0. B. Press "Control"+"R" If everything worked correctly your backdoor keys should be restored and the card should read successfully. C. If your card reads successfully then obtain a copy of clean ROM10 BN10 file for your provider(ie. BellExpressvu,> Dishnetwork,) edit your info and write it to the card. This will restore it to the provider of your choice. I hope this file helps you and others restore your backdoor keys. And then I downloaded a program called Mrom V6.0 and reset the card . And now it's a clean ROM10 A16 ready to programed Hope that this can hepl thows people with BDO issues. Good Luck STP |
|
|
|
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
|
|