Welcome to Mili's Marauders.
Header

 
ViP211 modded HDTV IRD

ViP211 modded receiver

Slinger ready
Free shipping

SALE PRICE: $349!!!
RomCode DishTV Subscription

RomCode DishTV Subscription

FROM: $69.00
Slinger IKS Kit
FREE SHIPPING

Slinger kit
PRICE: ONLY $199!!!
CLICK
HERE FOR INSTRUCTIONS
ViP622 modded HDTV IRD

ViP622 modded receiver

Slinger ready
Free Canada shipping

PRICE: ONLY $549!!!
BGA TSOP programming for ViP722 IRD

BGA tsop programming services for ViP722 receivers

PRICE: $144.00
FREE CANADA SHIPPING
Buffered JTAG Programmer

JTAG programmer

 PRICE: $39.00
MaxMel Emulator
MaxMel Emulator
PRICE: $59.00
FREE SHIPPING
SB5101 Diagnostics Modem

VIP downloads
PRICE
: $149.00
ViP722 modded HDTV IRD

ViP722 modded receiver

Slinger ready
Free Canada shipping

PRICE: ONLY $649!!!
BGA TSOP programming for most IRDs
BGA tsop programming services

PRICE: $124.00
FREE CANADA SHIPPING
Latest developments:
Slinger IKS boxes are now in store. All porn open, all premium chanels open. Hindi, Latino, Urdu Internationals. Running on Nagra 3 already and right now. Get them today HERE

Router Configuration

Slinger FAQ

Slinger Instructions

Files and VIP

VID Mod Instructions

JTAG-ing

Mili's Marauders » mili's Forums » Dish Network and Bell ExpressVU » Nagra Glitching and Unlocking » help rom 10

Notices


Nagra Glitching and Unlocking Discussions on unlocking ROM 3-11 cards, unlocker how tos, modifications and hopefully Nagra 2 glicthing

Reply
Thread Tools vBmenu Seperating Image
help rom 10
Old 03-11-2005   #1
thekiss777
 
Status: Guest
Posts: n/a
help rom 10

have a rom 10 can not open however i used prtg_cm ver 1.5a and reset card and it loaded ghoast and read my rom 10 rev a23 at the time it was unlocked because i was trying to change it from a bev to dish using viagra and instructions i downloaded anyway her what it looks like in nagra

Opening of COM1 was successful
ATR String: 3F FF 95 00 FF 91 81 71 A0 47 00 44 4E 41 53 50
30 31 30 20 52 65 76 41 32 33 4B
ROM Revision: 010
EEPROM Revision: RevA23
ProviderID: 40
CamID: 11 11 11 11
Using BD3 Key: 4E 69 70 50 45 72 20 49 73 20 61 20 62 75 54 74
Attempting to login to BD3
BackDoor login verified
Dumping Dataspace
Backdoor retrieval has been blocked
Attempting to login to BD3
Attempting to login to BD0
Unable to login, bad password detected
Login attempt aborted
Reading ROM10 failed
Closing of COM1 was successful

It prompts me to input password for backdoor o key which of course i don't have but it did do a back up of what is on the card in the prtm_cm is the backdoor key 0 anywhere on the eeprom file contained on the file thats in the card if so where at what location can i find it ? just new to this thanks for your patients and any advise
  Reply With Quote
Old 03-11-2005   #2
littlelarryjr
 
Status: Guest
Posts: n/a
c600 I believe, but not totally sure
  Reply With Quote
Old 03-11-2005   #3
thekiss777
 
Status: Guest
Posts: n/a
thats where my password is not the BDO password but thanks for trying
  Reply With Quote
Old 03-11-2005   #4
Cid6.7
 
Cid6.7's Avatar
 
Status: Registered User
Join Date: Jul 2004
Location: Over Here
Posts: 844
You popped it with a modded loader?
__________________
Too often we lose sight of lifes simple pleasures. Remember when someone annoys you it takes 42 muscles to frown, BUT it only takes 4 muscles to extend your arm and B*^&$ slap that Mother %&*#@! upside the head.
Cid6.7 is offline   Reply With Quote
Old 03-11-2005   #5
rambo41
 
Status: Guest
Posts: n/a
A modded Hu Loader should pop the card for you and don't use Viagra that is what messed your card up to begin with, all you need to use is Nagra and you can convert the card back and forth from Bev to Dish with it, no need to use any other program.....
  Reply With Quote
Old 03-11-2005   #6
thekiss777
 
Status: Guest
Posts: n/a
No the card is not open i found out that the backdoor key is usualy at C-040 on all other of my rom 10 cards, in this case the backdoor key has written itself to all 00000000000 now what do i do because i need to log into card and it will not read until i put in the backdoor key 0 which at present is all 00000 but when i enter all 000000 says bad password see below what i am up against.
Opening of COM1 was successful
ATR String: 3F FF 95 00 FF 91 81 71 A0 47 00 44 4E 41 53 50
30 31 30 20 52 65 76 41 32 33 4B
ROM Revision: 010
EEPROM Revision: RevA23
ProviderID: 40
CamID: 11 11 11 11
Using BD3 Key: 4E 69 70 50 45 72 20 49 73 20 61 20 62 75 54 74
Attempting to login to BD3
BackDoor login verified
Dumping Dataspace
Backdoor retrieval has been blocked
Attempting to login to BD3
Attempting to login to BD0
Unable to login, bad password detected
Login attempt aborted
Reading ROM10 failed
Closing of COM1 was successful
As you can see backdoor has been blocked until i enter the backdoor key o which i don't know what it is!!!! IS there a method to restore backdoor key 0 i tryed entering a key 32 digits long but no go!!
  Reply With Quote
Old 03-11-2005   #7
thekiss777
 
Status: Guest
Posts: n/a
If my provider is 08 how do i change it in nagra edit 4 to change to provider 00? It is bell and want to write a dish file to it? I did one of those change from bev to dish and that is how this whole thing got going last time i'll use a script that is suppose to change the provider over. meesed up the card now can't read or write to the card till i figure out how to restore backdoor key 0
  Reply With Quote
Old 03-11-2005   #8
thekiss777
 
Status: Guest
Posts: n/a
Rambo how can i change the card back and forth between providers please? using nagraedit 4.
  Reply With Quote
Old 03-11-2005   #9
Cid6.7
 
Cid6.7's Avatar
 
Status: Registered User
Join Date: Jul 2004
Location: Over Here
Posts: 844
Read this thread..

http://www.dssftp.com/forum/showthread.php?t=40860
__________________
Too often we lose sight of lifes simple pleasures. Remember when someone annoys you it takes 42 muscles to frown, BUT it only takes 4 muscles to extend your arm and B*^&$ slap that Mother %&*#@! upside the head.
Cid6.7 is offline   Reply With Quote
Old 03-11-2005   #10
rambo41
 
Status: Guest
Posts: n/a
Get yourself a good clean A16 image for both providers...Write which ever image you need to the card with Nagra then get your blocker file for either provider and write that to the card.....

As I said earlier a modded Hu loader should allow you back into the card from there write a good clean image back to it and you should be good to go again....

Last edited by rambo41; 03-11-2005 at 06:27 PM..
  Reply With Quote
Old 03-11-2005   #11
thekiss777
 
Status: Guest
Posts: n/a
I found this script posted by dk night 420 it worked execellent open the card and restored it in 2 seconds he the man thanks guys for your help HAPPY KISS777
Here is the link to the thread http://www.dssftp.com/forum/showthre...005#post244005

Opening of COM1 was successful
ATR String: 3F FF 95 00 FF 91 81 71 A0 47 00 44 4E 41 53 50
30 31 30 20 52 65 76 41 32 33 4B
ROM Revision: 010
EEPROM Revision: RevA23
ProviderID: 69
CamID: 11 11 11 11
Using BD3 Key: 4E 69 70 50 45 72 20 49 73 20 61 20 62 75 54 74
Attempting to login to BD3
BackDoor login verified
Dumping Dataspace
Attempting to restore BackDoor 0 key
Attempting to login to BD3
Attempting to login to BD0
BackDoor login verified
Dumping CodeSpace
Reading ROM10 successful
Card read successfully
Efficiency: 100.0%, Packets: 142, Retries: 0, Time: 18.09s
Closing of COM1 was successful

This is what success looks like YAH HOOOOOO
  Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +2. The time now is 11:12 AM.

[Output: 70.28 Kb. compressed to 64.64 Kb. by saving 5.64 Kb. (8.02%)]