For people with N3 cards!!!

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • sakiblateef
    DK Veteran
    • Jul 2008
    • 311

    #1

    For people with N3 cards!!!

    I'm posting this info I found on another forum orginally posted by the coder and thought it would be useful to see what responses are received.

    Mods feel free to remove this post if I'm breaking any rules.


    Originally Posted by TheCoder
    There are three different pairing methods used N3 boxes presently. These are DT06, DT08 and Secondary key.

    The DT06 method transfers a compressed form of an rsa pq keyset from which the CAM public/private rsa keyset and its associated modulus can be derived.

    The DT08 method transfers the cam modulus along with the IRD number of the married box. The public rsa key is not transferred but it is implied that the box already knows this value.

    The Secondary key method does not involve a transfer. It imples that the box already knows the cards matching CAM modulus and rsa public key value.

    Various boxes, depending on make/model, may use any of the above pre-pair key transfer methods but it could be useful to know which box uses which method.

    So, for you guys in Ireland/Leeds/Others that have N3 cards and are willing to experiment the following two simple NagraEdit scripts will attempt to dump the relevant tiers from your cards. These scripts wont harm your card - they simply replicate some commands your stb issues to the cards when it first boots.

    Instructions:

    1 Stick your N2/N3 card in your card reader
    2 Run NagraEdit - DO NOT ATTEMPT TO READ YOUR CARD !!!
    3 Select the Comm Tab. This should give you an upper and lower text pane
    4 Cut/Paste the scriptt below into the top pane
    5 Press the "Send D2C" button/icon
    6 Results should appear in bottom pane
    7 Interpret your results based on info below.
    Script - Read DT06/DT08

    rs
    Code:
    tx 21 C1 01 FE 1F
    rx
    tx 21 00 08 A0 CA 00 00 02 12 00 06 55 
    dl 02 00
    rx
    dl 02 00
    tx 21 00 09 A0 CA 00 00 03 22 01 00 1C 7E 
    dl 02 00
    rx
    dl 02 00
    mg *
    mg *** DT06 info ***
    tx 21 00 09 A0 CA 00 00 03 22 01 06 13 **
    dl 02 00
    rx
    mg DT06 response1
    dl 02 00
    tx 21 40 09 A0 CA 00 00 03 22 01 86 13 **   
    dl 02 00
    rx
    dl 02 00
    mg DT06 response2
    mg *** End DT06 info ***
    mg *
    mg *** DT08 info ***
    tx 21 40 09 A0 CA 00 00 03 22 01 08 13 **     
    dl 02 00
    rx
    mg DT08 response1
    dl 02 00
    tx 21 00 09 A0 CA 00 00 03 22 01 C8 55 **   
    dl 02 00
    rx
    dl 02 00
    mg DT08 response2
    tx 21 40 09 A0 CA 00 00 03 22 01 88 55 **     
    dl 02 00
    rx
    mg DT08 response3
    dl 02 00
    mg *** End DT08 info ***
    Originally Posted by TheCoder
    The responses you get back will be along the line of -

    Code:
    ***DT06INFO***
    TX: 21 00 09 A0 CA 00 00 03 22 01 06 13 77
    RX: 12 00 15 A2 11 08 E0 00 00 00 5E 01 20 00 00 00
        00 00 00 00 00 00 90 00 B3
    DT06RESPONSE1
    TX: 21 40 09 A0 CA 00 00 03 22 01 86 13 B7
    RX: 12 40 15 A2 11 00 00 00 00 00 00 00 00 00 00 00
        00 00 00 00 00 00 90 00 64
    DT06RESPONSE2
    ***ENDDT06INFO***
    and

    Code:
    ***DT08INFO***
    TX: 21 40 09 A0 CA 00 00 03 22 01 08 13 39
    RX: 12 00 15 A2 11 00 00 00 00 00 00 00 00 00 00 00
        00 00 00 00 00 00 90 00 24
    DT08RESPONSE1
    TX: 21 00 09 A0 CA 00 00 03 22 01 C8 55 FF
    RX: 12 40 57 A2 53 00 00 00 00 00 00 00 00 00 00 00
        00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        00 00 00 00 00 00 00 00 90 00 64
    DT08RESPONSE2
    TX: 21 00 09 A0 CA 00 00 03 22 01 88 55 BF
    RX: 12 40 57 A2 53 00 00 00 00 00 00 00 00 00 00 00
        00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
        00 00 00 00 00 00 00 00 90 00 64
    DT08RESPONSE3
    
    ***ENDDT08INFO***
    in both of the above cases, you can see the returned data contains lots of 00's. This signifies that the cards doesn't use DT06 or DT08 packets so its likely to use a secondary key pairing method

    The idea is to run the script, look at the results and decide which pairing method your box/card uses

    If the DT06 response contains lots of 00's then its NOT DT06 pairing
    If the DT08 response contains lots of 00's then its NOT DT08 pairing
    If its not DT06 or DT08 then its probably secondary key.

    When you've done, post up your box type and what you think the pairing method is.

    DONT post the actual responses
    Last edited by sakiblateef; 12 January, 2010, 00:09.
  • sakiblateef
    DK Veteran
    • Jul 2008
    • 311

    #2
    A bit more info to add to the above post.

    Just to clarify:

    The important bits your looking at are the DT06/DT08 responses (the bits that start with Rx: )

    ie RX: 12 00 15 A2 11 08 E0 00 00 00 5E 01 20 00 00 00
    00 00 00 00 00 00 90 00 B3

    RX: 12 40 15 A2 11 00 00 00 00 00 00 00 00 00 00 00
    00 00 00 00 00 00 90 00 64

    RX: 12 00 15 A2 11 00 00 00 00 00 00 00 00 00 00 00
    00 00 00 00 00 00 90 00 24

    and

    RX: 12 40 57 A2 53 00 00 00 00 00 00 00 00 00 00 00
    00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
    00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
    00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
    00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
    00 00 00 00 00 00 00 00 90 00 64


    If the responses vary significantly from the above, with the 00's replaced with some varying data, then its likely your card had the specified tier and is probably using the corresponding pairing method.


    Come on lads in Leeds/Ireland get posting thoes results.

    Comment

    • gerald5445
      Top Poster
      • Sep 2009
      • 143

      #3
      in simple terms what does this mean?

      Comment

      • dctyper
        V.I.P. Member
        • Jun 2008
        • 2539

        #4
        i think they are reading the cards, which normaly cannot be done
        Wavefield Ds 55cm at 13E 19E and 28E receiving everything out there on 2 dm800hd

        previous life dm800hd and 500c on cable screw you nag3


        Comment

        • gerald5445
          Top Poster
          • Sep 2009
          • 143

          #5
          me mate has a samsung vm box wa his viewing card sorted if u no what i mean will that be fxxxed too when n3 kicks in? anyone know when scotland gets it thanks again folks

          Comment

          • dctyper
            V.I.P. Member
            • Jun 2008
            • 2539

            #6
            yes, because the card has to be paired with the box, if he gets an n3 card and is able to read it to pair it then he will be ok, highly unlikely though
            Wavefield Ds 55cm at 13E 19E and 28E receiving everything out there on 2 dm800hd

            previous life dm800hd and 500c on cable screw you nag3


            Comment

            • gerald5445
              Top Poster
              • Sep 2009
              • 143

              #7
              [QUOTE=dctyper;422336]yes, because the card has to be paired with the box, if he gets an n3 card and is able to read it to pair it then he will be ok, highly unlikely though[ THANKS 4 THAT

              Comment

              • Dr Evil
                Newbie
                • Aug 2008
                • 16

                #8
                What the Original Poster was trying to acheive was to find out what pairing methods were being used for each VM receiver (nagra 3 only). This will help with developing solutions to maybe get boxes up and working again after nagra 3 has been implimented. If you have a n3 VM box help the dev's.
                Running the above will not make any diff to a receiver and will not stop a receiver going down when n3 hits your area.
                Hope this clarifies for all.

                Cheers,

                Evil

                Comment

                • barboy
                  Newbie
                  • Apr 2010
                  • 3

                  #9
                  to sakiblateef r ya still wantin d info i can get nx week am i ok to post on ere dont want t brake any rules

                  Comment

                  • loncell
                    DK Veteran
                    • Jun 2008
                    • 625

                    #10
                    so basically is this method to retrieve the BK from an N3 card ? ( nothing to do with encryption ) so CS can be implemented ?.

                    Comment

                    Working...