Google
Web forums.dsstester.com

View Full Version : Rom3 ECM????


FaCkEnBaSsTaRd
10-14-2004, 04:07 PM
Hey guys I just had 2 people call and said there getting (Access Card Not Inserted Properly) Is there an ECM going on? Hopefully there not looped, but I doubt it :( Anybody else having problems?

Ctech
10-14-2004, 04:30 PM
Emu still going here :yes:
Sound like there looped :no: also reports of atmegas rom2's and rom10s are down people are saying they cant read there rom10's now and rom3's are looped
So if your still running I would pull cards if you have not been hit yet until things settle :D
unlocker who said unlocker dam charlies pissed :wacko:

rainbow99
10-14-2004, 04:36 PM
atmega still running right now still.

Ctech
10-14-2004, 04:51 PM
Just checked mine its black screen
what fix are you useing

dwm3568
10-14-2004, 04:58 PM
everything going great in the buckeye. pri support been up for 3 months without a glitch

rainbow99
10-14-2004, 04:59 PM
will upload it for ya and give it a try

Ctech
10-14-2004, 05:05 PM
thanks bro will do now :beer:

Ctech
10-14-2004, 05:20 PM
working thanks :yes:

metalwork
10-14-2004, 06:07 PM
my rom3 and rom10 were up running wide open 3m and ppv on 301.010 with gcsb. pulled em to make image and save it.will wait to see what is being targeted here

circusboy
10-14-2004, 06:57 PM
heard that the hash was targeting the dead in deadbeefbaadf00d password ill see if i cant find the post with the command that came down




heres the c+p


Here you go

--------------------------------------------------------------------------------

0081: C6 C0 86 lda $C086 ; Load in A
0084: A1 32 cmp #$32 ; Compare with A
0086: 26 19 bne $A1 ; Branch if <>
0088: C6 C0 87 lda $C087 ; Load in A
008B: A1 33 cmp #$33 ; Compare with A
008D: 26 12 bne $A1 ; Branch if <>
008F: C6 C0 A0 lda $C0A0 ; Load in A
0092: 27 03 beq $97 ; Branch if =
0094: 4C inca ; a++
0095: 26 0A bne $A1 ; Branch if <>
0097: CD 7A B7 jsr GET2PARMSTORC1 ; Put 2 bytes in RC1H:L
009A: .dw C0 24 ; New value of RC1
009C: A6 01 lda #$01 ; Load in A
009E: CD 54 E6 jsr $54E6 ; Go to subroutine
00A1: 81 rts ; Return from subroutine
BYTES DUMP:
---------------------
00A2: DE AD 00 00 00 00 00 00
00AA: 00 00 00 00 00 00 00 00
00B2: 00 00 00 00 00 00 00 00
00BA: 00 00 00
__________________

Whats going on here is Charlie is looking for the DEAD" in the "DEADBEEFBADF00D" default passwords that many blockers are using.
__________________

hope this helps :beer:

Hacktor
10-14-2004, 07:14 PM
Rom 2 Live and kicking ...

Hacktor....

cableguy31
10-15-2004, 04:00 AM
rom 3 was at 372 now looped

Ctech
10-15-2004, 05:56 AM
rom 3 was at 372 now looped

what blocker were you useing?are what was the password if you had one?

Mas
10-15-2004, 06:39 AM
There were many reports that Charlie had LOOP Rom3 and Rom 10 card, so for the members who testing with Rom card, has to becareful for next few days.

Nintendo Master
10-15-2004, 09:39 AM
Atmega w/ rom3 cam still running good here. :beer:

Tomico-ind
10-15-2004, 11:44 AM
still up here rom 10 and 11 no glitch

DaVo
10-15-2004, 12:59 PM
Peep's that are too lazy to make up their on password deserve what they get.

DaVo

ws6toto
10-15-2004, 01:34 PM
really,why mine is still working with deadbeedbaadf00d password.

fatboytrav
10-15-2004, 02:03 PM
still up here with rom10 and rom3 with know glitch but you never know what Charlie is up to he can hit theme anytime he wonts...

lectronicman
10-15-2004, 02:06 PM
rom3,rom10 both with gcsb still going with wide open ppv.

atmega still ok.

avr still ok.

nothing has missed a beat here. is it confirmed there was an ecm????

FaCkEnBaSsTaRd
10-15-2004, 02:11 PM
Peep's that are too lazy to make up their on password deserve what they get.

DaVo

My looped cards did have there own password, still didnt matter.

newbie09
10-15-2004, 06:23 PM
I am still up with my private software, actually only been hit one time in over a year.

dwm3568
10-15-2004, 06:55 PM
Sounds great might give ya a shot. how about prices.
Thanks for hooking me up with @#$##$#@

newbie09
10-15-2004, 07:37 PM
I cant discuss prices here at this great site, but you can pm me

nohash
10-16-2004, 12:34 PM
TCFD still up with no problems here

Ctech
10-16-2004, 09:42 PM
Black Screen on Rom10 and 11 after fixing unlocking cards from recent ecm's.

--------------------------------------------------------------------------------
as posted by NagraGuy, super coder.

Well I have bad news folks. I have heard of a few reports of people who after the recent ecm's pulled there cards when there tv went black. Some who we're able to get back into them, knowing the bd0 on the cam, after fixing them noticed that they could not get video no matter what they tried.

CHECK YOUR CAM. I'll bet dollars to donuts, you have #$FF at $C008. While I cannot see a single emm that does ONLY this, my guess is that the looping ecm just didn't quite write properly. As a result, you cam has had it's crypto processor disabled. Your cam in short is useless. I seriously doubt you will see a map fix on the 10/11 like on the rom3, since that area of rom is known to anyone. The rom10/11 hacks were not done through probing, and that area of rom cannot be dumped from rom/ram/eeprom. Let alone that for security purposes the ST19 may not allow calls to those areas from eeprom or ram. This also brings into perspective that rom10/11 unlooping is useless since the map is killed in looped cards.

This is grim news indeed for all looped 10/11's as well as non looped cards that were marked at C008 with #$FF.

Cheers
NagraGuy

munro_d44
10-17-2004, 10:22 AM
C&P from elsewhere...


Credit for this goes to: dteyn @ DN

If your card is marked, it means that it's simply "flagged". As JorgeAcc mentioned, there is an area of the EEPROM called the OTP (One Time Programmable) area. Because of the card's operating system, the values in the OTP range (E010-E01F on Rom 3, C020-C03F on Rom 10) can only be incremented. This means that you can change it from 00 to 01, 01 to 02, etc, but you can never decrease the value... in other words, you can never 'unmark' a card. Once the OTP value gets to FF, it is as marked as can get and nothing can be done about it (short of modifying the card's behaviour with custom software patches).

You can tell if your card is marked by reading it, and in the EEPROM editor, look at the OTP area... for Rom 3, look for line E010.. for Rom 10, it's line C020 and C030. If you see anything other than '00' in any of those values, your card is marked at that location.

Note: This is quite different from what most people refer to as 'E007 marked Rom 3' cards. These cards have a value of FF at E007, and because of the way the software on the cards work, they out-and-out will not function unless a patch to fix the mark is added to the card. These OTP marks are completely different: they are simply marks, and nothing more.

However, the marks can be used as targets for future countermeasures... for instance, in the latest Rom 10 countermeasure, they checked for cards that are running blockerless. If the card's EEPROM revision level said 'A23', and the card had an invalid cyclebyte (if C0A0 = FF), or a cleared numbugs (if C0A1 = 00), the card would be marked at location C024 in the OTP. There were also other packets that checked for changes on line C600 (where the password is normally stored), and other areas in codespace which are normally empty on a virgin Rom 10 A23. If the checks fail, the card gets marked at C024.

In other words, if you had a blocker on your card, then unlocked it, changed something, and forgot to re-lock the card by either re-applying the blocker, or manually changing numbugs (C0A1) back to it's normal value, your Rom 10 will get looped.

This is because the blocker is not active with a 00'd numbugs value, and the marking packets will mark your card if you have a 00'd numbugs value... then the final packet checks for marks at C024, and if one exists, your card gets put into a very, very tight loop. If this happened to your card, you would not get an ATR. Your card would be as looped as can be.. and unless you have an extremely accurate glitcher (HU likely won't cut it), you'll likely never get an ATR from the card ever again.

With that said, if your card is simply marked but you can still read it, your card is not looped. Simply apply a blocker (I recommend Nomore64 v7 or GCSB), make sure it's applied properly, and you should be fine. The current blockers will block these marking/looping EMM's, so long as it's applied properly.

And, as always, if you choose to run the card blockerless, well then it's your own fault if it gets looped. Remember, it's all fun and games until someone loses a CAM.

Hope this clears things up.

TRUMP
10-17-2004, 11:44 PM
You never know what Dish's up to next. Private rom files will keep you up forever, the blockers are second to none. A rom 3 with a private blocker, practically unstoppable, but we're all about freeware aren't we ... DSSTESTER !!!!!!!!!