هذا وجدته 2 الارديتو الموضوع على منتدى آخر لا أعرف المؤلف
on an arabic forum i got some information how to decrypt ird*to2 EMM_s with an v_2*2 card, but i don't have one.
after decryption it is possible to get an Nano structure and keys used for showtime and ART from the decrypted String .
Strings that are adressed with C3 HS HS HS or CB HS HS HS and Len 36
HS = H_E_X_S_E_R_I_A_L
Looks decrypted like that:
the Header:01 01 00 00 00
36 C3 HS HS HS 30 30 <- is the Len of the crypted Block
E1 19 <- Garbage Header
68 24 <- Nano CMD 0x68 with len 0x24
00 <- Sector 0 from Card has to be updated
K1 K1 K1 K1 K1 K1 K1 K1 K1 K1 K1 K1 K1 K1 K1 K1 <- Key1 for Provider ID.eg key index 08 81aaf2b2c0e74eb6714d1fdf414eb741
K2 K2 K2 K2 K2 K2 K2 K2 K2 K2 K2 K2 K2 K2 K2 K2 <- Key2 for Provider ID.eg key index 06 77817f090fdec9711453aeedd6701290
PI PI PI <- the 3 Bytes Provider ID
86 12 CC 2B D2 79 2A 29 <-- the 8 Byte Signature
Also there are Nanos like 10 11 for Keyupdates
40 02 for setting Date on the card and so on.
on an arabic forum i got some information how to decrypt ird*to2 EMM_s with an v_2*2 card, but i don't have one.
after decryption it is possible to get an Nano structure and keys used for showtime and ART from the decrypted String .
Strings that are adressed with C3 HS HS HS or CB HS HS HS and Len 36
HS = H_E_X_S_E_R_I_A_L
Looks decrypted like that:
the Header:01 01 00 00 00
36 C3 HS HS HS 30 30 <- is the Len of the crypted Block
E1 19 <- Garbage Header
68 24 <- Nano CMD 0x68 with len 0x24
00 <- Sector 0 from Card has to be updated
K1 K1 K1 K1 K1 K1 K1 K1 K1 K1 K1 K1 K1 K1 K1 K1 <- Key1 for Provider ID.eg key index 08 81aaf2b2c0e74eb6714d1fdf414eb741
K2 K2 K2 K2 K2 K2 K2 K2 K2 K2 K2 K2 K2 K2 K2 K2 <- Key2 for Provider ID.eg key index 06 77817f090fdec9711453aeedd6701290
PI PI PI <- the 3 Bytes Provider ID
86 12 CC 2B D2 79 2A 29 <-- the 8 Byte Signature
Also there are Nanos like 10 11 for Keyupdates
40 02 for setting Date on the card and so on.



تعليق