View Single Post
  #7 (permalink)  
Old 10-24-2005
007.4 007.4 is offline
Registered User
 
Join Date: Jan 2005
Posts: 114
Thanks: 1
Thanked 2 Times in 2 Posts
007.4 is on a distinguished road
Re: Cloning with an UnLooper

Any unlooper (Wildthing included) is just a device for sending voltage or timing "glitches" to a card to make it do unexpected things. If a card can be "glitched" at just the exact right time it can be made to dump its contents or set or unset a flag bit etc. This is extremely difficult to do without a detailed knowledge of the card cpu and OS.
Only when you have a complete dump of a card can any attempt be made at cloning it.
The latest card versions all have inbuilt glitch protection so basic glitching techniques do not work.
I'm interested in testing scripts that anyone may have (not nagra unlocking scripts). The classic one from a few years ago was the F**KS*y script which dumped the P1 n-d_s UK card eeprom. Unfortunately n-d_s were aware that the early editions of this card could be compromised and later versions of that card were then glitch protected.
I'm pretty certain the P2 card is also very well protected - but would like to know (via PM) if anyone has made any progress with this.
I've got an original Wildthing unlooper (from years ago) and one of the new Trunker Unlooper from D**labs - for testing purposes only ;-)

@fkp
The early sec@ cards were also easy to glitch into. See the secarom dumps on HomeAlone's site. The last public dump was v6.00. But as I've just stated the newer ones are much more difficult. Possibly only the professional labs could have any chance of doing it and they may use other techniques such as micro-probing or DPA.
Reply With Quote
 
Page generated in 0.12687 seconds with 9 queries