Seems is no good. The eeprom is probably ok but the PIC is wrong. This might be a bit more useful. =========================================================== Thanks to whoever wrote this. Irdeto keys, Irdeto key or Satellite IRDETO KEYS. Satellite Keys updated every day. Notorious hacker Chris Tarnovsky opens his underground laboratory to WIRED, providing a peek into the world of satellite television smart-card hacking. Pay-TV smartcard hacking – how easy is it. That’s difficult to crack without employing lots of. To your Android device’s software). ![]() No name so can't credit. Dave Smartcard Exploration: Introduction: Tools: Smartmouse3 smartcard reader - Phoenix mode (Reset LOW) - quartz at 3,579 Mhz SEASON Interface (self powered) - NOKIA 9800S - THOMSON - SAGEM decoders Decrypt 2.45 & Windecrypt 1.05 SCIntegrator for the first tests WINEXPLORER 4.3 (by Dexter) under WINDOWS 98 SCAM, STEST et SIO under LINUX TPS Viaccess smartcard (FRENCH BOUQUET) Aim - Disclaimer: These notes are for educational purposes only. ![]() The aim is to understand the viaccess communication protocol between a digital decoder (MPEG2) and a smartcard. All the tools used for this purpose are in public domain and the reference books are sold in France, in every good electronics shops. No subscription or participation in any forbidden group or organisation has been realised. Eventually, a brute force key search will be done with the aim to validate the knowledge acquired during this study. This study is not a pirate attack against TPS, for what I pay a subscription. The TPS Viaccess card is here only one element of a global system, which uses the viaccess protocol. I could not be held responsible for the use or misuse that people could do with these information. A glossary is at the end of this document. Progress has to be shared Generality: Viaccess cards are BULL PC2 or PC3 models. They may be built under BULL's license. WinExplorer 4.3 parameters: PHOENIX mode (Reset Low). 9600 Bds Parity: ODD PROGRAM SETTINGS options: none inverse convention Protocol Format: CLA INS P1 P2 LEN CLA: class INS: instruction P1: Parameter N01 P2: Parameter N02 LEN: Data Length All dialog between card and computer is in hexadecimal. ATR (Answer to reset): The ATR is the smartcard signature. It defines the convention used (direct or inverse) and the protocol for the communication establishment between the smartcard and the decoder. Classic ATR: 3F 77 18 25 00 29 14 00 62 68 90 00 This ATR is observed not only on TPS smartcards, but also on SRGSSR (Swiss) and NTV+ (Russia). It is totally independent from TPS, and it seems to be the viaccess standard ATR. 3F Inverse convention 77 7 historical bytes TA1, TB1, TC1 transmitted TD1 not transmitted. 18 TA1 25 TB1 Vpp = 5 V, 50 mA max 00 TC1 Guard delay / 2 bits TD1 not transmitted Protocole T=0 asynchrone in half-duplex 9600 bds 29 14 00 62 68 historical bytes 90 00 End of transmission - ok Specific ATR: 3F 27 17 C4 01 2C 29 14 00 62 68 90 00 This ATR was seen only on a TPS card, when using it in a THOMSON decoder (rented in a TPS pack). We can notice that the same card used in a NOKIA 9800S decoder send the classic ATR (3F 77 18 25 00 29 14 00 62 68 90 00) and not this one (3F 27 17 C4 01 2C 29 14 00 62 68 90 00). Moreover, the same card gives also the normal ATR when it is used in a SAGEM decoder (also rented in a TPS pack).
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. Archives
December 2018
Categories |