Dump for PCMCIA Nagravision CAM

for NOKIA IRD Receivers

 

1) Ambition

 

The present document describes the alteration of the printed circuit board of a PCMCIA Nagravision of GEM PLUS with object to preserve it against the manipulation of the emission supplier. It is necessary to consider that manipulation of the PCMCIAs existing is property of the supplier of services, reason why his illegal sera manipulation. However, they exist consuming with IRD's "free", bought by them in its totality, and who contain PCMCIAs (CAM's) also own. In this case, we doubted the legality of the operation that him supplier of services can carry out on firmware of this PCMCIA. In any case, and before the reasonable doubt on the legality of this manipulation, the Patel group does not become person in charge of the performances that pure to make the user on its equipment or any other, being this and single east the unique to which falls this responsibility. On the other hand, this single document has experimental character, and it does not have to be used with reason illegal or presumably illegal.

 

2) Description

 

The PCMCIA is the one in charge to decide if the user deserves or not the access to certain service that the supplier emits. Said PCMCIA it consists of a complete computer with his CPU and programs, firmware, which goes lodged in a flash 29F400. Like all flash, this memory can be rewritten, and the CPU can conduct this operation when the supplier of services, through satellite, ace decides it. In first firmware’s which they were placed in the market the usury tapeworm the option to qualify or to not novation of said firmware it, but this option has been eliminated by the supplier of services. In order to avoid this novation a decontamination by hardware is made necessary, which consisted in the elimination of the possibility that the CPU can qualify the writing of the flash. This effective by means of disconnection physic of the line of writing (WE) of the flash with the CPU, and activating this line, that after disconnection the air has left "", to a potential of +5v, being in way of eternal reading. This work is of extreme complicate. It becomes necessary of the instruments and the suitable experience of the personnel to the nature of the work. If he sweats of his preparation, our advice is that he does not follow ahead. In opposite case, we recommended to him STRONGLY that IT READS the TOTALITY OF THIS DOCUMENT before beginning, and that eliminates all doubt before acting. The work this extremely to be followed, and must be followed, exactly. The work this thought so that misfortune can return at previous  moment in case of arising align. It does not eliminate steps. This publication has not been made to the light one, and is the result of the joint work of the 5 people who we integrated the Patel.

 

3) Preparations

 

A professional welder with VERY FINE end uses. He needed fine flat Needed stickers paper, non plastic. He needed thread fine copper, we we have used of 0,2 mm. WITHOUT varnishing. Do 1 hour of footing, a shower and another hour yoga, with transcendental meditation including. If after this he decides to follow ahead, is that this so lucky as we.

 

4) Vaccination

 

A)

PCMCIA this supported and closed by a brass plate nickel-plated electro sol dada in 4 points. A flat and fine disordering between two welded plates eliminates these welds inserting. Nothing of blows. One does not worry about these welds, despise we will close the PCMCIA of another form. Open the PCMCIA, their sera aspect like the one of the photo.

When opening it to find certain resistance to exist something of glue, but is viscous and not this totally mincemeat, reason why it is possible to be eliminated with facility.

 

B)

Sequa the plate, which this supported by the lateral ones of the plastic. Haggle with care, that plastic sees embed. Once it has the plate locates the flash (TSOP), the CPU, and the points P1, p2 and P3.

 




 

 

P1 connects with pin 11 of the flash (compruebelo), and ademas this together with (sigua the track) P3, which continuous by the face of components until the CPU (It looks for the pin). P2 this together with to pin 47 of TSOP (BYTE) and a resistance that this very near (compuebelo). The other point of the resistance goes to +5. The point BYTE of the STOP is the one that serves us to polarize WE (pin 11, writing rating) of the +5 TSOP to v. since this point BYTE this ALWAYS at this level. The plan is, therefore, - to unite P1 with P3 (that is, WE with +5 to travels of resistance) - To cut the union of P1 with P2.

 

C)

Vamoose to create a protected zone of work. For it we used the paper stickers (paper is used because not derider when astral to him the soldering iron). Corneas in strips, and creates a way between P1 and P3. Use but strips of near paper to cover via but. (Via is the drills that unites the two faces of the plate, although this plate has but expensive, but in any case, if you do not know what via is one..... better is than it forgets everything). The result of this camouflage the side in < thread, jpg >. Now it comes to place the lead ELT, like which it is seen in the photo.

 

D)

Corte a thread that has 4 mm but long that the existing distance between via P1 and Double P3. an end of the thread 2 mm and introducible in P1. Hagar the same operation in P3. Recurred, the ends of the thread has to be put in via.

 

E)

Clean the end of the soldering iron very thoroughly. Use a blade for it, as like a rag hummed. The end has to shine of esta.o clean. And now we are going to weld. It is necessary to weld with the amount minima of esta.o. Approach the thread of esta.o via, and plique the end of the soldering iron. NONCMas OF 1 SECOND. sufficient time but that. Verify the cleaning of the work with a good magnifying glass. After it, it verifies with tester the perfect electrica union of the points P1, P2 and P3.

 

F) To continuation fijese in the photo

Aqui side the cut point coloquese so that the connector of the moved away PCMCIA this but of you. Like side, the track to cut this closely together, by above, of other tracks, but not by down. Use a new blade, you place the end of the blade between the track to cut and the immediately superior one and cut downwards. Asi tendra security of which not da.a nothing but. Verify with tester that this cut is effective.

 

G) Tape to the lead ELT with an insulating tape, like side in the photo

Deletion mark the return to the plate and verifies: 1 Pin 11 of the TSOP this together with Pin 47 2 Pin 11 of the Tsop NOT THIS together with any of the CPU.

 

H)

Invert the process that use to disassemble. He is facial, single has to have present that the face of tracks (where the components do not estan) gives the face of the plate that puts Nagravision. To see photo.

Not fuerze nothing. If it does not enter it is that not this put good. In order to close the PCMCIA, and considering that there are broken the closing welds, tape can be used to sprint, but it does not use the brown one, that are terrible, l to transparency nor note. The closing does not tighten much either or the card did not enter. Sera now impossible that they alter firmware of his PCMCIA.