Page 1 of 3 123 LastLast
Results 1 to 15 of 39

Thread: Digital signature in crypto chip

  1. #1
    Join Date
    Jun 2001
    Posts
    88

    Digital signature in crypto chip

    Folks,

    Seems like to spoof subscribtion on Dtivo is not and issue,
    problem is coming down in modifing certain system files.
    Since they are signed in atmel crypto chip system automaticly recover them from I dont know where...
    setting imune bit helps but looking forward this may break stuff so now is the time to fix it..
    I will release hack for service spoof as soon as somebody will help me out with crypto chip.

    Eel sushi rules!

  2. #2
    Join Date
    Jun 2001
    Posts
    28
    Sounds like you have done a lot of digging in the DirecTiVo. Do you know how the "you haven't called TiVo in 30 days" nag system works. I already have a lifetime sub, but I want to stop calling in every month.

    It would be nice to start a technical conversation about the authentication system. If I can get the new small backup software to work on the DirecTiVo I will finally be able to start hacking it, and I don't want to retrace steps others have already taken.

    -GhostInTheMachine

  3. #3
    Join Date
    Jun 2001
    Posts
    3,108
    What type of info are you looking for on that crypto chip. I have a directivo, and a knack for finding info when its needed. I would definitely be interested in your service spoof hack, so I am willing to learn what I need to in order to help as best I can. Time to put those comp sci classes to work.

    Of course, a small backup of the directivo would be very useful in this sort of endeavor.

  4. #4
    Join Date
    Jun 2001
    Posts
    19

    Thumbs up

    Count me in also, I will help out anyway I can. I love to tinker with this stuff

  5. #5
    Join Date
    Jun 2001
    Posts
    88
    sorry for long wait guys, I've been busy with some personal issue
    but here is deal...
    directivo use digital signatures for IMPORTATNT files and it check them every time it boots
    i.e. if you modify your rc.sysinit it will check checksum in crypto chip and if it's doesn't much it will recover file from the backup
    don't ask me where the backup... I don't have a clue
    however today you can fix this by setting immune bit on the file (ext2 filesystem feature). but tommorow they may do something and to check signature, attemp to recover, hand on failure...
    so we gonna even lose ability to get a bash prompt on it...
    so NOW is the time figure how to modify files and store changes back to crypto chip....
    Eel sushi rules!

  6. #6
    Join Date
    Jun 2001
    Location
    Dallas
    Posts
    588

    Smile I think your looking in the wrong place

    It actually mounts an image filesystem on bootup that contains a file with an MD5 sum of all the important files that it checks. When the files do not match that MD5 sum it deletes them and replaces them with the correct files that are also located on the image. It will also remove any files that you add to the filesystem that are not in it's MD5 sum file. None of this actually has anything to do with the crypto chip though. I have had a lot of experience with getting around this and dealing with this because I was able to get a TivoNet card into a DirecTivo using some pci extender boards and such to locate it on the other side of the HD braket. I was fine in the beginning, but then my tivo went over the net and updated my software and prom blowing out everything I had done.

    So, if you know what files I can change and then chattr +i to make it not want to dial in ever again, I would be happy. I allready changed it to lifetime service, but in another 5 days it is going to wat to dial in again.

    I have no intention of ever letting it dial into Tivo again. If the new 2.5 software actually adds the second tuner support and doesn't add encryption, then I may let it upgrade.
    Information wants to be free....

  7. #7
    Join Date
    Jun 2001
    Posts
    88
    post your e-mail and I will email it to you...
    but still I need way to get around chattr +i
    this is temporary solution
    Eel sushi rules!

  8. #8
    Join Date
    Jun 2001
    Posts
    88
    BTW this signatore stored in crypto chip and it calculate MD5 SIGNATURE and checksums and store them them in crypto chip
    Eel sushi rules!

  9. #9
    Join Date
    Jun 2001
    Location
    Dallas
    Posts
    588

    pm

    I snet a PM to you with my email address.
    Information wants to be free....

  10. #10
    Join Date
    Jun 2001
    Posts
    3,108
    do we have the part number on the chip? that would seem like a good place to start getting info

  11. #11
    Join Date
    Apr 2000
    Location
    Bergen County, NJ.
    Posts
    701
    I'd recommend reading TiVo Hacking, ZipWeep posted a way that changes it.
    - Vadim
    Administrator

  12. #12
    Join Date
    Jul 2001
    Posts
    46

    I'm Confused

    All this talk about the files being replaced if they have an invalid hash has me confused. I modified my sysinit and it wasn't replaced. Where are you running into this issue?

    Also, can someone elaborate on the Setup_Bypass mod for bypassing the interactive setup? I am having no success...

  13. #13
    Join Date
    Jun 2001
    Posts
    88

    Re: I'm Confused

    Originally posted by Lord Magnus
    All this talk about the files being replaced if they have an invalid hash has me confused. I modified my sysinit and it wasn't replaced. Where are you running into this issue?

    Also, can someone elaborate on the Setup_Bypass mod for bypassing the interactive setup? I am having no success...
    directivo
    Eel sushi rules!

  14. #14
    Join Date
    Jul 2001
    Posts
    46

    Re: Re: I'm Confused

    Originally posted by eel-sushi

    directivo
    Yea, I am working with a DirecTiVio

  15. #15
    Join Date
    Jun 2001
    Location
    Dallas
    Posts
    588
    It doesn't start happening until your DirecTivo calls in and get the update to 2.0.1-001-001. Mine used to work fine too. You probably can't mount your /dev/hda4 partition either right? This isn't created until after the first upadte is taken. At least that has been my experience on a 2 drive philips directivo.
    Information wants to be free....

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •