Information on 240 / 241 Hack, Way to go Canadians.

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • ecm153
    Newbie
    • Feb 2009
    • 9

    #1

    Information on 240 / 241 Hack, Way to go Canadians.

    C/P

    The hack is available for sale very soon. Here is what happened. The hack was developed in Canada for the rom24X. However the rom241 and rom240 are the same card. The rom is 100% the same, the only difference is the eeprom. They got into the card by exploiting the cmd26/27 session key mechanism which is the same as cmd2a/2b in single tuners, by signing their own 27s using the boxkey. What was required was the boxkey, a dt08 on the card and some understanding of how to encrypt your own cmd27 based off those variables. Int21h is the one that hacked into the s0x,rom206 and rom240 using this technique. I heard he said he used a ground glitch to get into the rom24X. However according to some smart people the card can only be current glitched and ground glitching will not work. So all you coders out there, look into designing a loader that can control the current and you will find a way to fault the cam. Also do not start by attacking big cmds like cmd26/27. First attack a small cmd like an IFS and see if you can make it respond with bad LRC or bad len. When you do you wIlL have a repeatable ability to fault the cam. Then you can use it to attack bigger cmds. Never start with trying to put a bootloader into the ram, start with doing simple things to prove you can fault it. Int21h said he will release the rom code for everyone too, so just wait to look at areas to load ram but for now attack an IFS to prove the fault technique.

    So the question is how do we current glitch a cam? We need to leave voltage at 5volts and only control current. God's gift wasn't women, it was nagra. no.1
    from the card coder site.
  • alunfennell
    V.I.P. Member
    • Oct 2008
    • 1525

    #2
    I was only reading about this yesterday but the information was very sketchy and to be honest I didnt understand any of it ! as it was so vague...

    Thanks for the Information..... the down side is .... its a commericial hack ... this wont work so well in Europe as C/S or cardsharing has sprung up covering most providers supplying many hundreds of thousands of Hobbiest, who are unlikle to pay for anything if we have other ways of get these encryption open freely...

    Hopefully after launch you can give us the low down on this situation and keep us Europeans up to date on developments ecm153, hopefully it will end up open for all and eventualy on Emulators Softcams and Keys in the not to distant future.

    Thanks ecm153 Great post....

    Regards:
    Alun
    **The Worlds Best Interactive F1 Strategy Game**
    sigpic

    Comment

    • ecm153
      Newbie
      • Feb 2009
      • 9

      #3
      will do bro ,regards nag.

      Comment

      • .: JaCkPoT :.
        Retired Sat TV Addict
        • Aug 2008
        • 5607

        #4
        nice to have a american here who can keep us up to date on things over there...cheers

        Read the Rules here; they apply to Everyone.

        ___________________
        In the good old days, I had
        DM800s HD
        Openbox S10
        TM500
        DM500s
        90cm FortecStar dish
        Maxx 110cm Dish
        Technomate 2300 Motors

        sigpic

        Comment

        • ecm153
          Newbie
          • Feb 2009
          • 9

          #5
          .:|SaDiQ999uK|:. sorry bro im not american im canadian ,from newfoundland. the east coast of canada..

          Comment

          • caveman_nige
            V.I.P. Member
            • Feb 2008
            • 4920

            #6
            fpmsl nice one Sadiq.....

            Comment

            • .: JaCkPoT :.
              Retired Sat TV Addict
              • Aug 2008
              • 5607

              #7
              Ooops..well i never mentioned united states of america though!

              Read the Rules here; they apply to Everyone.

              ___________________
              In the good old days, I had
              DM800s HD
              Openbox S10
              TM500
              DM500s
              90cm FortecStar dish
              Maxx 110cm Dish
              Technomate 2300 Motors

              sigpic

              Comment

              • ecm153
                Newbie
                • Feb 2009
                • 9

                #8
                ok.bro i guess worse happens,.

                Comment

                • mikemt
                  Newbie
                  • Feb 2012
                  • 1

                  #9
                  intresting,,, 3 years later and the rom 24x are still locked up tight in North America. Atleast to the general public. Many here are still trying to glitch the cam and write tiers, but who knows if it will ever happen........

                  Comment

                  Working...