Card Reader 1) Your smartcard decrypts this key (using a special sub processor in the card called the ASIC), checks if you have a legitimate subscription set in the card and if yes it returns it to your receiver in an Instruction 54. A 3M modifies the check in 2) so that the card never checks if your card is a legitimate subscription and always returns the key. In order to do this it has to MODIFY the software in the card. An Emulator SIMULATES the code in the card and forces the key to be sent, however it still needs the ASIC in a real card to actually decrypt the key. In actual fact Instruction 40 contains more than just the encrypted key Ė It also includes dynamic code. This is some extra code which executes after the key has been decrypted. This is where hashing comes into play. Firstly letís look at a 3m. Assume a section of the code in your card located at address 0000 is 11 22 33 44 55 66 77 88. An instruction 40 could include dynamic code which says after the key has been decrypted ADD whatever is at 0000 onto the key. a) In an unmodified card 11 22 33 44 55 66 77 88 will be added and will create the actual key used to encrypt your picture. b) In a 3míd card the code at 0000 has been changed to modify the check in (2) and so this modified code will get added to the key. As you can see you will not result in the same key as a) Since your 3míd card has responded with an incorrect key, your picture canít be decoded and you will get a black screen or a freeze. Now letís take a look at an emulator. An Emulator tries to simulate a real card. Since the dynamic code can contain ANYTHING, it could contain instructions that a real card can perform, but the author of the emulator didnít know about when he wrote it. The emulator may crash or perform this code incorrectly, which will corrupt your key and cause blackout/freeze. Think of PS2 emulator running on your PC. It never works with all games does it? A more serious problem comes from the fact that you can NEVER 100% simulate anything. There are always small timing or functional discrepancies, and these are exploited. Dynamic code could execute a write to memory in the smartcard but not give it enough time to actually burn into the EEPROM. An emulator would have no idea how long it takes to write to the EEPROM, and would perform the write regardless. [Incidentally this exact same attack was used against an emulator for the H card]. These are but a few examples of how emulators can be exploited. You may find it surprising to learn that dynamic code can change every 6 or 7 seconds. That means that a new dynamic Ďhashí could be executed every 6 or 7 seconds. So how many different tests can be performed to check if your card has been modified in one hour? Thatís right, over 500! The Avenger SE never modifies the code on your card, nor simulates any portions of the card. Your card always remains unmodified. As a result there are no differences that the dynamic code can detect! I have a 'sub" card, do i need to remove it from the Avenger SE and insert it into the receiver directly to receive updates? No! Your card will continue to receive all official updates while in the Avenger SE. You may use your 'Sub' card without the Avenger SE at any time if you wish, but you do not have to. Does the Avenger SE work with the No-ZKT/303 mod? Yes! The NO-ZKT/303 mod simply prevents the Zero Knowledge Test from actually being performed. they will not be wiped. With this bootloader you will be able to load a 'dead / blacklisted' BIN file to your HU card and you will not get the 744 and 745 error messages. It will also work with P4 and P5 cards, if you have a current subscription with DirecTV you can insert this device then call DirecTV and cancel your service and you will still get all your TV channels. Change the Time Zone to the time zone your are located in Set a 6 digit Zip code that is valid in the Area selected by the Locals Byte Click OK Red Dragon + Infinity3m 6 months support Dual Atmel Unlooper Loader This awesome piece of hardware for the loading and unlooping, fixes 4b, 5b, 6b and 7b cards with ease. It Unloops 4b, 5b, 6b and 7b unlike any other Unlooper Loads all difficult to write to cards. Repairs otherwise un-glitchable card. Switch from: Detonator XP unlooper to Ul4S with in a flip. One toggle switch on the back allows you to switch from loading your HU with Extreme Hu to unlooping the HU card with The Detonator XP software. It unloops cards in 10-40 seconds average. It even unloop with Extreme HU (ul4s) for that 1 in 20 card that won't unloop in the Detonator. Features No dips or jumpers! Fully in-line flashable to every known flash 1st glitch programmer LED In a custom built Protective Case Unloop, program and clean HU cards Free - All cables needed are included! By entering this web site, you hereby and without exception agree to the following terms and conditions of use and legal restrictions.; 1) You understand that this web site, and all directly associated web sites are wholly owned, operated and hosted in the sovereign province and nation of British Columbia, Canada and are operated in accordance to the applicable laws and statutes of Canada and British Columbia. We make no representation that the materials on this site are appropriate for use outside Canada. 2) You understand that this web site's intended audience are residents of Canada and other countries where use of test cards is considered legal. You understand that the worldwide nature of the Internet makes it impossible to regulate the audience and it is possible to access this web site in countries where use of test cards is illegal. You understand that it is your responsibility to check your local laws before committing any information on this web site for any given practical use. We do NOT condone signal theft and you are absolutely prohibited from putting ANY information on this site to any illegal use. Any individuals indicating illegal intent are subject to loss of any and all privileges given to them by this web site. 3) You understand that use, possession, distribution, manufacture or importation of test cards is illegal in the United States. If you are a U.S. resident, you are required by law to subscribe and the use or sale of test cards of any kind is unlawful and constitutes signal theft and is subject to criminal and civil penalties according to U.S. law. We do not condone the use or sale of test cards to U.S. residents. In addition, use of test cards may also be considered illegal in any country or jurisdiction where the U.S. based services of Directv Inc. and Echostar

