PDA

View Full Version : How to find ASK -> RPL algorithm (part 1)


zulea
12-23-2004, 00:45
Hi,

Just downlaod HEX dump from TDS-6 and start disassembling.
The algorithm for calculate RPL data from ASK files is there.
The HEX file of TDS-6 box can be free downloaded here:
http://www.zulea.ro/TDS6.BIN

Just use IDA and select processor "Hitachi H8/300H".
Good luck :rolleyes:

If I will have enough free time, more interesting info soon in "part 2".

Best regards,
Zulea

vule
12-23-2004, 01:18
:eek: :D

Santa Zulea coming earlier this year ???

BR

Vule

mobileland
12-23-2004, 01:22
hehehehehe!!!
As Vule said, Zulea is going to give us the best gift from all!

Best Regards!

cyber6
12-23-2004, 04:30
hope that will not make a new santa war ;)


regards
dixie

*merry xmas to everyone specialy to manole and zulea :D *

Prima
12-23-2004, 07:40
@Zulea.
About yes I have a lot of time but I badly went to school. Do not postpone pleasure make. ( ne ebi nam mozgi napishi cam etot kalkulator )

Surej
12-23-2004, 09:24
That's a cool gift...

WBR

Surej

Alinus
12-23-2004, 10:06
this is long term move with lots of efects :)
zulea's playing chees with lots of ppl now

er2000
12-23-2004, 10:09
Hi,

Just downlaod HEX dump from TDS-6 and start disassembling.
The algorithm for calculate RPL data from ASK files is there.
The HEX file of TDS-6 box can be free downloaded here:
http://www.zulea.ro/TDS6.BIN

Just use IDA and select processor "Hitachi H8/300H".
Good luck :rolleyes:

If I will have enough free time, more interesting info soon in "part 2".

Best regards,
Zulea

how on earth did this happen? :D :D :D :p

ssatcom
12-23-2004, 10:31
@Zulea
Thanks For the best gift.............

yousha
12-23-2004, 12:01
waiting for the part (2)

he he

Invisible
12-23-2004, 12:06
hi

thanks a lot, btw, could you upload sch too?, would be interesting take a look deep inside TDS6

best regards
Invisible

Bph&co
12-23-2004, 12:33
how on earth did this happen? :D :D :D :p You mean the accidental change of 'D' to 'S' at 0x11A33 ?

Hehe :)

gsnbhagawan
12-23-2004, 12:55
its a end for dct4

new algos
new technology come soon


thanks zulea for sharing.......

legija
12-23-2004, 17:10
Hehehehe -;)
This is part 2 of "Just for the record" lol. I just wondering where Zuki got this free "bin" (it's free for almost two years) :D :D :D

asmar
12-24-2004, 00:55
As I Know Mr Zulea Always Give Us A Good Free Solution
One Time From Him Directly & The Other By The Laser (crack His Soft)
So In The 2 Way Thank's Alot Mr Zulea
Waiting Part2
Br

alnasser
12-24-2004, 02:28
hehe


finaly since two year..........will be back to see part 2

..::Neo::..
12-24-2004, 05:12
how is every one is waiting for part 2 and we did't see any useful post or inofrmation till now :D:D:D:D

kiriazy
12-24-2004, 06:00
Hi,

Just downlaod HEX dump from TDS-6 and start disassembling.
The algorithm for calculate RPL data from ASK files is there.
The HEX file of TDS-6 box can be free downloaded here:
http://www.zulea.ro/TDS6.BIN

Just use IDA and select processor "Hitachi H8/300H".
Good luck :rolleyes:

If I will have enough free time, more interesting info soon in "part 2".

Best regards,
Zulea
it is such a great thing at last to repair to ask files but

COULD U EXPLAIN CLEARER PLEASE

thanx ZULEA

MiKa
12-26-2004, 17:29
Hello,
Who have disassembled this file?
Where is reset vector for this CPU?
MiKa

toddz
12-27-2004, 07:01
Any chance of giving us the EEPROM binary file to go along with the processor binary file?

Todd

MiKa
12-28-2004, 12:49
TO Zulea:
Please send more info about disassembing this file...
I have problem with IDA... (need sppecial settings??? )
B.R:
MiKa

toddz
12-29-2004, 06:41
@MiKa

Just choose H8300A as the processor type and then the defaults for memory size. After that, you will have to examine the vector area to figure out where the code starts. Vectors start at address 0x00000000 and are 4 bytes (long type).

Todd

Zanzamar
12-29-2004, 10:46
Hehe, if you have problems finding vector table, definitely you'll have much bigger problems finding algo itself, coz i don't see any strings like "ASK/RPL algo entry point here" inside that dump :D:D:D

John_Doe
12-29-2004, 13:44
Hehe, if you have problems finding vector table, definitely you'll have much bigger problems finding algo itself, coz i don't see any strings like "ASK/RPL algo entry point here" inside that dump :D:D:D

hehehe, good one :D

however, as bph&co already told here, no algo for calculation DATA1/DATA2 inside that dump...

legija
12-29-2004, 14:15
But Zuki is smart, he will "find" something for sure, lol :D

TechPhone
12-29-2004, 14:24
waiting.......................

mayer
12-29-2004, 17:30
But Zuki is smart, he will "find" something for sure, lol :D

would be better not to force him to proof how smart he is and what he really can find by himself. this wouldnt affect onlz the griffin-boyz ;)

toddz
12-30-2004, 04:48
john doe, bph&co,

Can either of you please verify that this binary file is actually TDB-6 instead of TDS-6? The code looks good at first glance, but it could have been changed slightly.

Todd

John_Doe
12-30-2004, 04:56
john doe, bph&co,

Can either of you please verify that this binary file is actually TDB-6 instead of TDS-6? The code looks good at first glance, but it could have been changed slightly.

Todd

verified. zulea was probably "bull****ed" by somebody...

toddz
12-31-2004, 18:38
So could this file be used to make a TDB-6 box from a TDF-4 box, they seem to be exactly the same box just with different code? Of course I assume that the TDB-6 box would need to be activated, and programmed to support the configuration keys for a specific provider. Also the closing lock password and the security box password would have to be known. Finally you would also have to have a PKD-1SA+.

Todd

John_Doe
12-31-2004, 21:43
So could this file be used to make a TDB-6 box from a TDF-4 box, they seem to be exactly the same box just with different code? Of course I assume that the TDB-6 box would need to be activated, and programmed to support the configuration keys for a specific provider. Also the closing lock password and the security box password would have to be known. Finally you would also have to have a PKD-1SA+.

Todd

tdb-6 hardware is a little bit different than the tdf-4, so it´s not possible just to put tdb-6 mcu inside tdf-4. maybe possible if you make some changes to tdf-4 box hardware and dump, but i´m not sure.
as for the activation and config keys, this dump is working and activated(need external eeprom dump too) and in order to get it working for all providers just need to change 6 bytes inside the dump.
moreover it´s also possible to find out the sec. password and the correct PKD-1 serial number(must also match the box) in order to get it working. if you have this then you can write it to any other pkd-1 and make a 1SA+ out of it.
but the main question is why the heck you want to do this? wouldn´t it be easier to extract the tables or use any other 200usd box/software in order to unlock/lock nokia phones?? :)

regards,

toddz
01-02-2005, 04:36
It was mainly out of curiosity and the fact that I have a couple TDC-4 boxes (same as TDF-4 but with flash based mcu) which can be easily reprogrammed through the serial port. I though maybe I could convert them but I guess it just isn't that easy. I have some 3rd party unlocker/flasher boxes already but this just sounded like a cool item.

Thanks for the information :)

Todd

John_Doe
01-02-2005, 15:46
It was mainly out of curiosity and the fact that I have a couple TDC-4 boxes (same as TDF-4 but with flash based mcu) which can be easily reprogrammed through the serial port. I though maybe I could convert them but I guess it just isn't that easy. I have some 3rd party unlocker/flasher boxes already but this just sounded like a cool item.

Thanks for the information :)

Todd

wow, nice stuff, i didn´t even know that something like this(TDC) exists :)
could you might PM me your email adress? would like to exchange some info´s with you...

regards,

willy
01-03-2005, 14:11
or todd are talking about for "TDD4" !

regards

toddz
01-03-2005, 19:20
@willy,

The TDC-4 is actually different than the TDD-4. The TDC-4 has a flash memory mcu and is labled 'COMBOX'. The TDD-4 has a OTP memory mcu and is labled 'DEFAULT SECURITY BOX'. Other than those and a few other features, they are very similar.

Todd

senkron24
01-08-2005, 19:31
süüper

what is with part 2 wen coming ??

yousha
01-09-2005, 15:22
süüper

what is with part 2 wen coming ??

PART 2 ALREADY OUT

http://forum.gsmhosting.com/vbb/showthread.php?t=181358

..::Neo::..
01-09-2005, 15:31
oh really when is part 3 , still no usefull information

zulea
01-13-2005, 23:59
oh really when is part 3 , still no usefull information

Part 3 is here:

http://forum.gsmhosting.com/vbb/showthread.php?p=989752#post989752

Best regards,
Zulea

woodschang
01-15-2005, 10:26
Good, learn a lot.
Thanks to all masters

BR
Woods

vladutstoian
03-11-2005, 06:28
whare is part2 I'm waiting:)))

NoEnd
10-04-2005, 22:54
What about TDS-4 dump, anyone has it?

turkgsmteam
10-05-2005, 00:11
part2 I'm waiting :D :D :D :D :D :D :D

danilo_nop
10-14-2005, 21:29
where I can get free deassemler or crack for trace32(t32mh83,www.lauterbach.com) for h8/3002

tega
10-14-2005, 22:31
Good job,please upload link, can download.

babaunlocker
11-30-2005, 20:11
Hi,
Just downlaod HEX dump from TDS-6 and start disassembling.
The algorithm for calculate RPL data from ASK files is there.
The HEX file of TDS-6 box can be free downloaded here:
http://www.zulea.ro/TDS6.BIN
Just use IDA and select processor "Hitachi H8/300H".
Good luck :rolleyes:
If I will have enough free time, more interesting info soon in "part 2".
Best regards,
Zulea

Plz give me a access to this BIN file for downloading

With Best Regards

linwspps
12-03-2005, 07:14
Who can help I chase the ASK- RPL!Very grateful you!

chiragp
12-03-2005, 07:45
link is breaked friends share the bin chirag7_9@hotmail.com

dikey
12-18-2005, 12:23
link is breaked friends share the bin chirag7_9@hotmail.com

t00 dikey@tut.by or worked link!

.::Gsmdenis::.
12-18-2005, 16:41
zulea will be fix this problem soon , and i think just have more news from he!

BR.,

denis

bmv
12-24-2005, 12:32
how contact with zulea.
email not working.

npl
04-26-2006, 18:57
is anybody have that bin file? please, contact me... ( pltemp@inbox.ru )

asmar
04-27-2006, 13:30
here is ur file bin lets hear a good news ;) :D

workaround
12-11-2006, 00:11
Any news about reversing TDS6??