Posts by ilikenwf

    fairbird sorry to ping you but I think that nano01 may actually be an optional use of AES256, but more importantly, the addition of an 8 byte UA instead of just a 4 byte UA...see the example posted earlier in the thread with the nano00 vs nano01 comparison...the 4 extra bytes appear to just be the new use of longer UA's?

    I only know this from a high level view right now, is this something we could pound out/test/investiagate? I wonder if this thread may need to be private or if instead we should talk on TG or Discord?

    This one...it had a sticker on top with the UA of the receiver (which is a new addition - this is PowerVu Plus and nano01 most likely! - AES 128 + using the UA in the hash somehow) - see Colibri's work on what this thing is. I'm sure it probably speaks the same protocol (logic analyzer may be easier than a custom board?)


    If we can poke these and figure out the hashing method and reproduce everything in a softcam with a given UA, then for any given stream, the cracking method would involve using CUDA and a capture of the TS with EMM's to test every possible 8 byte UA until we find one that is authorized...I theorize anyway.


    I know enough to be dangerous but we may need some help from people who have done a lot in this space in order to figure it out.


    pasted-from-clipboard.pngpasted-from-clipboard.png

    After reskimming Colibri's work and looking at these dumps, I suspect this thing runs some kind of MIPS RTOS. There's not any truly discernable binaries at a cursory look that do a lot in terms of encryption, I believe the ISC (integrated security chip) is responsible for that.

    In the PowerVuSecrets.pdf by colibri he shows how he managed to talk to the ISC.


    Has anyone tried getting in touch with Colibri about this before?

    Do not share the information you have accessed or are trying to access in the open area and share the file in an encrypted form as WinRAR. If others see it and leak information to the center, the administrators will take precautions and patch it, it is always like this.

    Those are exposed on google search already - but if firmware dumps are shared we may be better off doing that via DM or a private thread if possible.

    Mad scientists are what this hobby is all about!


    So it does have a JTAG? If I can get root access that will be almost as if not more interesting as it should allow finding a way to get into the trustzone key storage and such.


    Thanks for sharing! I really hope UPS doesn't act like USPS and deliver 1+ week late - they usually do better so it should be here tomorrow.

    You've got the cisco receiver? How are you, by chance, dumping the flash image/firmware? Or is this some other software/box? If you have the binaries responsible for doing decryption you could toss them into ida+hex rays or ghidra and then have some pseudo-c code that we could pick apart or have an AI look at.


    edit:oh - that's just oscam-emu output?

    I guess with a D9865-D, that either dumping the firmware if possible or having it auto update downloading the firmware from an MTN satellite, and then dumping that, might give us something to look at since it is still powervu, meaning that no conditional access module is likely to be used...that said they are probably whitelisting receiver IDs...which we should be able to handle with EMMs, so I suppose I'll grab one of these on ebay.

    I don't think this is an actual encryption issue as much as it is some kind of hashing issue. It's not a huge thing but still something worth digging into.

    If anyone can confirm a box - commercial or professional that works, we can probably find the firmware to dump and get some clues at the least anyway.