PDA

View Full Version : other dump, other question , Sentinel


gus
11-12-2009, 05:44 AM
i dump sentinel dongle but show this :

Number of Query Cells = 13
0x08 0x0A 0x0C 0x0E 0x1C 0x1E 0x20 0x22 0x24 0x26 0x30 0x34 0x36

DevID = 0xXXXX
Serial = 0xXXXX
WP = 0x0000

Cell 0x08 : enhanced, sig=13811
*************
Descriptor = 0xD4C363A4 C6 = 0x944A

Cell 0x0A : enhanced, sig=14188
********************
Descriptor = 0xDEE40674 C6 = 0x944A

Cell 0x0C : standard, sig=251
----------------------------------------------------------------
************************************************** **************
Cell 0x0C not solved

Cell 0x0E : standard, sig=0

Cell 0x0E is Inactive (no data in dump)

Cell 0x1C : standard, sig=179
----------------------------------------------------------------
************************************************** **************
Cell 0x1C not solved

Cell 0x1E : standard, sig=0

Cell 0x1E is Inactive (no data in dump)

Cell 0x20 : standard, sig=0

Cell 0x20 is Inactive (no data in dump)

Cell 0x22 : standard, sig=0

Cell 0x22 is Inactive (no data in dump)

Cell 0x24 : standard, sig=0

Cell 0x24 is Inactive (no data in dump)

Cell 0x26 : standard, sig=0

Cell 0x26 is Inactive (no data in dump)

Cell 0x30 : standard, sig=0

Cell 0x30 is Inactive (no data in dump)

Cell 0x34 : enhanced, sig=14745
**
Descriptor = 0xF13B68BF C6 = 0x944A

Cell 0x36 : standard, sig=199
----------------------------------------------------------------
****************************************
Descriptor = 0x97970588 WP = 0xAD1D

Processing time 134.438 seconds

Writing MultiKey Registry file...


now put reg file and install multikey 18.1 , install , detect hardware , all ok but......

y test soft , "error no dongle" ???
y test pva 3.3 for test dump and all ok, and no detect dongle ¿ LOL ?
i try with other dump, no dump ??? ,
test usbsearch , detect dongle sentinel ultrapro its ok
other test, edgehasp option sentinel . dump and ok

as possible?
possible solution?
thanks

Git
11-12-2009, 06:33 AM
There is no public emulator for UltraPro

Git

gus
11-12-2009, 07:57 AM
ok, again ultrapro :(

thanks

Git
11-12-2009, 08:40 AM
I don't know for sure, you said it was UltraPro. You also said UsbDSearch said it was UltraPro, but as far as I know, UsbDSearch uses the PID and VID to find out the dongle type, and the PID and VID are the same for SuperPro and UltraPro. So I don't know how it can tell the difference.

I will take a look at the dump if you want.

Git

SonofabiT
11-12-2009, 10:25 AM
@ Git - Let us preassume that people dump their Sentinel SuperPro dongle with pva 3.3 dumper (Brute WP option-UNSELECTED).

Could you explain how we can identify the dongle is sspro or ultrapro from the pva3.3-dumped files ?

Git
11-12-2009, 10:57 AM
Well theoretically, it should fail, as it is a superpro dumper, not an ultrapro dumper. In practice, I don't know what it does. There are several tricks it could use, for example calling GetKeyInfoEx and analysing returned info.

If you have in your hand a 64 cell dump in PVA format, all access codes are 0, 1, 2 or 3, then I know of no way to tell if it came from ultrapro or superpro, but there is a good chance it is superpro. If some of the access codes are bigger than 3, or if cell 7 is not 0, then there is more chance it is an ultrapro. Only the author can properly answer the question. Maybe pivasik has something to add.

For my own dumper, I exit with an error code if I find an ultrapro, because it is a superpro dumper.

Git

pivasik
11-12-2009, 04:35 PM
Ok, some notes on PVA 3.3.
At first, the sources has been moved to public more than year ago. So, everybody may take a look and find that tool use old SuperPro API. UltraPro can be dumped using SuperPro API because it is almost the same key. If UltraPro has more than 64 cells only first 64 cells will be dumped.
If you want to dump full UltraPro memory, you may use the latest SuperPro/UltraPro dumper from http://nodongle.biz/files/supapi.zip

Using this tool you may check type of your key SSP/ULP and memory size.

2 topic starter: your key is SuperPro (99.9%) because at least 1 algo has been solved.

gus
11-12-2009, 04:58 PM
.......

2 topic starter: your key is SuperPro (99.9%) because at least 1 algo has been solved.


ok thanks, i download ,


I have tried with same results f1_nodongle + ssp2reg

today tried with spapi

SonofabiT
11-13-2009, 05:44 AM
2 topic starter: your key is SuperPro (99.9%) because at least 1 algo has been solved.
@ pivasik - Agree ! The dongle is Sentinel Super Pro but it has cell more than 64. I wonder the dongle is Sentinel SuperPro XM.

i dump sentinel dongle but show this :
Cell 0x0C not solved
@ gus - I think it's depend upon the solver that you used. The dmp2mkey v2.3 did NOT solve the cell 0x0C and cell 0x1C, consequently dmp2mkey.exe copy 0x0000 to these two cells in your reg. See below :

1. dmp2mkey.exe ver 2.3
C:\solver\dmp2mkey.exe spro_RNBO_SPN_DRIVER_ea6e_0.dmp
Number of Query Cells = 13
0x08 0x0A 0x0C 0x0E 0x1C 0x1E 0x20 0x22 0x24 0x26 0x30 0x34 0x36

DevID = 0xEA6E
....
Cell 0x0C : standard, sig=251
*******-***********-**********************************-*********
Cell 0x0C not solved
....
Cell 0x1C : standard, sig=179
******-************************************************** *******
Cell 0x1C not solved
....
********--------********--------********--------********--------
Descriptor = 0x97970588 WP = 0xAD1D

Processing time 700.187 seconds

Writing MultiKey Registry file...

Meanwhile, tch2000's f1_nodongle.exe solver has been solved the cell0x0C=cell0x0D=0x8674 and cell0x1C=cell0x1D=0x8674. See below :

2. f1_nodongle.exe
C:\solver\f1_nodongle.exe spro_RNBO_SPN_DRIVER_ea6e_0.dmp
13 algo:
08 0a 0c 0e 1c 1e 20 22 24 26 30 34 36
....
cell 0c std. algo Cell_0c = 8674 Cell_0d = dee4 WP = 0008
....
cell 1c std. algo Cell_1c = 8674 Cell_1d = dee4 WP = 0008
....
file ea6e.ssp is created. Press any key.

I sugest you to convert the ssp file which is generated by tch2000's solver and then try to find a suitable emualator. As i know, the multikey emulator from ver 0.16.0.1-0.18.1.0 could NOT emulate the Sentine Super Pro dongle which has cell more than 64.

Refers to tch2000's solver, basicly try to use the following reg entries :
"sntMemory"=hex:\
..,..,6E,EA,00,00,00,00,1D,AD,00,00,4A,94,00,00,\
A4,63,C3,D4,74,06,E4,DE,74,86,E4,DE,00,00,00,00,\
CA,CB,CE,CF,CB,FF,FF,FF,4B,69,00,00,00,00,00,00,\
02,00,00,00,00,00,02,00,74,86,E4,DE,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
84,6D,D4,23,BE,44,44,44,35,33,00,38,93,8A,69,47,\
00,00,00,00,01,00,C8,00,BF,68,3B,F1,88,05,97,97,\
63,00,63,00,63,00,63,00,00,01,00,01,00,01,00,01

The possible solutions are :
1. Wait until the future release of multikey able to emulate sspro dongle which has cells more than 64 such as SuperPro XM. :)
2. Get WinDDK and do something with vusbbus source code. But i don't know yet how to do it. :D
3. Ask gamebit in order to public his emulator. ;)
4. Or.......... :D

gus
11-13-2009, 05:51 AM
ok, i dump with spapi

file 341 Kb
dump with SPAPI:
LOL 256 CELLs

01010101010101010303030303030303010101010000000001 03030203030303030303030303030301010101010100000303 02020303030302020202020202020101010101010101010101 01010101010101010101010101010101010101010103030303 03030303030303030303030303030303030303030303030303 03030303030303030303030303030303030303030303030303 03030303030303030303030303030303030303030303030303 03030303030303030303030303030303030303030303030303 03030303030303030303030303030303030303030303030303 030303030303030303030303030303...................

dump with pva 3.3
only 64 cells
01010303030303030303030303030303010101010000000001 03030203030303030303030303030301010101010100000303 0202030303030202020202020202

any solver for spapi ??


i no read sonofabit, thanks for info ;)

SonofabiT
11-13-2009, 05:58 AM
ok, i dump with spapi

file 341 Kb
dump with SPAPI:
LOL 256 CELLs
Well, your dongle is sentinel Super Pro XM. :)

any solver for spapi ??
tch2000's solver is the good one. :) BUT you need to edit the .dmp file which is generated by spapi.exe (nodongle's team dumper v 4.1). You need a better vusbus-base emulator. May be gamebit emulator is the good chooice (if it is available for public). ;)

@ all
I am talking about Sentinel Super Pro dongle (64 cell). Please CORRECT me if i am wrong.

Eventhough many people have used f1_nodongle to solve the pva 3.3-dumped files (spro_RNBO...dmp), but i wonder that f1_nodongle.exe is NOT be released to solve pva3.3 dumped files. It seems the name of solver deal with the author of dumper such as :
f1___spor --> The solver of sporaw's dumper version v1.4m.
f1__gla1 --> The solver of glasha's dumper version 0.3.
f1_nodongle --> The solver of nodongle's dumper. I think NOT for spapi.exe ver 4.1.
f1_pva --> The solver of pva dumper. If the solver realy ever been released.

Sometimes i found people get a famous WP=0x0008 when they use f1_nodongle to solve pva3.3 dumped files. Honestly, I NEVER FOUND A PUBLIC STATEMENT by tch2000 who said that f1_nodongle.exe is a solver of pva 3.3 dumped-files. Meanwhile, i found a rumor that there is a solver called f1_pva.

However, if people still want to use f1_nodongle.exe to solve pva3.3 dumped files, there is a useful hint here : http://reteam.org/board/showpost.php?p=14451&postcount=5
It is not nesessary bruteforce WP for PVA dumper

Next, we should get correct WP and then manualy insert it into the .ssp file in order to get the proper REG.

There are several method to get the correct WP such as Disassembling the s/w, The use of Toro's sentmon v2.01b and Re-dump again the dongle with Brute WP option enabled.

To place the correct WP into .ssp file, we should familiar with SafeKey SuperPro (SSP) emulator file format. There is a clear hint here : http://reteam.org/board/showpost.php?p=7534&postcount=7
*.ssp - a safekey SuperPro emulator format
That's mean that sometimes we need manualy edit/copy/place the correct WP in the right address inside .SSP file so our file will realy represent as the CORRECT SafeKey SuperPro (SSP) Emulator file format.

If the SSP (input) is CORRECT, then the Sataron's Unidump2Reg and y8y8y8y's ssp2reg will give us the suitable REG (output) for the use of vusbbus and multikey emulator.

These two hints will prevent us to get the famous WP=0x0008 in the REG.

by the way, let us see the following dumper :
C:\sspro_dumper>spapi.exe -h

* Backup tools. Console manager.
* Version 1.0, nodongle.biz team (c) 2004-2007
* E-mail: support@nodongle.biz, Web: www.nodongle.biz

* Sentinel SuperPro backup module. Version 4.1 (public)
* Greetings to chucha66, Dmit, HarmEr, tch2000.

* Use:
spapi.exe [-w] devId
w - Brute write password (WP)
h - Show help


* Have a nice day.

I am looking for the several old release of this dumper (nodongle's team sspro dumper) which has release LOWER than release 4.1.

If these old release ever available, Could anyone upload them please ?

Git
11-13-2009, 09:47 AM
With SDHK, one of the ways of interogating the dongle will always return a capacity of 256 cells, because the SDHK is *capable* of 256 cells. That does NOT mean that the current implementaion actually uses 256 cells. The Toolkit will default to usin g standard 64 cells for SuperPro mode unless you specifically request 256 cells.

It depends on the method of interrogation that a specific dumper uses how many cells are reported. Personally, I have not yet see an SDHK in SuperPro mode that uses anything other than 64 cell mode.

As for f1_nodongle.exe rewsults, look at the solved WP. Whenever you see WP = 8, you can know that is f1_nodongle.exe's way of telling you it could not solve the cell and those values for the Descriptor are random and meaningless. Cells C and 1C on this dongle are examples of where the statistical nature of solving simply fails, whichever solver you use. Always check for WP = 0008 and discard the results of that cell if you see it.

Git

pivasik
11-14-2009, 05:09 AM
I am looking for the several old release of this dumper (nodongle's team sspro dumper) which has release LOWER than release 4.1.

If these old release ever available, Could anyone upload them please?
They are internal versions.

gus
11-14-2009, 07:09 AM
I will try the emulator "gamebit" found it on the forum called multi 3_1
I have also found another sentinel emulator created by "mete0" which has option to Q / A
It proves on Monday,
thank you for pointing SonofabiT try the version of sonofabit
Klopschik thanks for saying it was the emulator file gamebit

write the test on Monday

SonofabiT
11-14-2009, 08:31 AM
If UltraPro has more than 64 cells only first 64 cells will be dumped.
Do you mean that basicly any Sspro, Ultrapro and SDHK in ssp/ulp which had cells > 64 can be emulated by means of writing only the first 64 cell ?

If you want to dump full UltraPro memory, you may use the latest SuperPro/UltraPro dumper from http://nodongle.biz/files/supapi.zip

Using this tool you may check type of your key SSP/ULP and memory size.
well, very useful post! Thank's you very much. :)

2 topic starter: your key is SuperPro (99.9%) because at least 1 algo has been solved.
When none of algo solved, do you have any comment about ultrapro solver ?

They are internal versions.
Well, Eventhough f1_nodongle.exe able to solve pva3.3 dumped file but actualy f1_nodongle is a solver of another nodongle's sspro dumper, isn't it ?

pivasik
11-14-2009, 10:18 AM
Do you mean that basicly any Sspro, Ultrapro and SDHK in ssp/ulp which had cells > 64 can be emulated by means of writing only the first 64 cell ?It is wrong.

When none of algo solved, do you have any comment about ultrapro solver ?If none solved, I don't know public solutions.

Well, Eventhough f1_nodongle.exe able to solve pva3.3 dumped file but actualy f1_nodongle is a solver of another nodongle's sspro dumper, isn't it ?I don't know what f1_nodongle.exe is. So, I can't comment this product.

SonofabiT
11-15-2009, 09:04 AM
If none solved, I don't know public solutions.
I wonder the next release of multikey will support another MODEL of sentinel dongle.;) . I have found interesting post by r-Elite in http://forum.ru-board.com/topic.cgi?forum=35&topic=44888&start=680
добавил в шапку дампер sspro/upro, муль с доработаным сентом + ультра скоро будет
PS. перезалито
btw, there is a sspro/ultrapro dumper link in ru-board forum.
Дампер SENTINEL SPro/UPro от Elite (http://rapidshare.com/files/305677028/SSUMD.rar.html)

Could anyone re-upload this dumper please ?

r-Elite! Spasiba :)

Git
11-15-2009, 09:29 AM
Latest version of multiKey 18.2.0 supports UltraPro (Win32 XP only at the moment) :

http://rapidshare.com/files/307082707/mk18_2.rar
http://rapidshare.de/files/48684717/mk18_2.rar.html

dumper :

http://rapidshare.com/files/305677028/SSUMD.rar.html
http://rapidshare.de/files/48684708/SSUMD.rar.html

passwords : ru-board

Both the emulator and the dumper are too big to upload here. Can you really not download from rapidshare.com ?

Git

gus
11-15-2009, 01:35 PM
thanks git
thanks eliter

gnerogeem
11-15-2009, 03:34 PM
Thanks Git.

besoeso
11-16-2009, 03:25 AM
very good and great contribution dear Git.

gus
11-17-2009, 05:45 AM
again thanks git


today use new dump, thanks elite

the program directly created the reg file, has not created any dmp, is it normal?
insert the reg file and install version 18.2 , run the software, I hope a few seconds and does not work :(

execute "sentinel monitor and test again
I find that works better, leaving Q / A on the display of "sentinel monitor, but the software does not work correctly.
proves today to use "monitor sentinel" + original dongle, store Q / A and add it to the reg file
thanks for the contributions

reg file 256 cells , ok

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\MultiK ey\Dumps\0000XXXX]
"Name"=""
"CopyLeft"="(c)Elite"
"DongleType"=dword:00000003
"Type"=dword:00000001
"CellType"=hex:\
01,01,03,03,03,01,03,01,\
03,03,03,03,03,03,03,03,\
01,01,01,01,00,00,00,00,\
01,03,03,02,03,03,03,03,\
03,03,03,03,03,03,03,03,\
01,01,01,01,01,01,00,00,\
03,03,02,02,03,03,03,03,\
02,02,02,02,02,02,02,02,\
01,01,01,01,01,01,01,01,\
01,01,01,01,01,01,01,01,\
01,01,01,01,01,01,01,01,\
01,01,01,01,01,01,01,01,\
03,03,03,03,03,03,03,03,\
03,03,03,03,03,03,03,03,\
03,03,03,03,03,03,03,03,\
03,03,03,03,03,03,03,03,\
03,03,03,03,03,03,03,03,\
03,03,03,03,03,03,03,03,\
03,03,03,03,03,03,03,03,\
03,03,03,03,03,03,03,03,\
03,03,03,03,03,03,03,03,\
03,03,03,03,03,03,03,03,\
03,03,03,03,03,03,03,03,\
03,03,03,03,03,03,03,03,\
03,03,03,03,03,03,03,03,\
03,03,03,03,03,03,03,03,\
03,03,03,03,03,03,03,03,\
03,03,03,03,03,03,03,03,\
03,03,03,03,03,03,03,03,\
03,03,03,03,03,03,03,03,\
00,00,00,00,00,00,00,00,\
03,03,00,00,01,00,00,00

"sntMemory"=hex:\
XX,XX,XX,XX,00,00,00,00,00,00,00,00,00,00,51,00,\
00,00,00,00,00,00,00,00,01,00,01,00,00,00,00,00,\
CA,CB,CE,CF,CB,FF,FF,FF,4B,69,00,00,00,00,00,00,\
02,00,00,00,00,00,02,00,01,00,01,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
84,6D,D4,23,BE,44,44,44,35,33,00,38,93,8A,69,47,\
00,00,00,00,01,00,C8,00,00,00,00,00,00,00,00,00,\
63,00,63,00,63,00,63,00,00,01,00,01,00,01,00,01,\
D5,23,18,A3,94,2B,38,D6,C7,14,59,F0,67,B5,A8,48,\
28,48,47,4B,F3,93,F2,28,BD,60,43,22,E6,63,B3,55,\
EE,79,D1,78,6D,E9,DC,BD,3C,F1,B7,27,32,4D,58,2E,\
F4,4F,62,40,25,B3,5D,E4,8F,3A,73,27,E9,14,A6,4A,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,80,93,02,00,00,00,00,00,00,00,00,00


EDIT: any solver for more 64 Cells ??? f1_nodongle ? o dmp2mkey new version ???

Git
11-17-2009, 08:21 AM
You won't find a solver for >64 cells. I believe "Type"=dword:00000001 means the dongle is an UltraPro (or it may mean 256 cells, not sure), and you cannot solve AES encrypted algo cells unless you have a Cray and a few million years to spare.

Git

SonofabiT
11-17-2009, 01:37 PM
@ gus - What about gamebit emulator ?
Extract and use only the first 64 cell, then try gamebit emulator.

Look the different in the CellType 5 and 7 between the release of Multikey.
1. Multikey 0.16.0.1-0.18.1.0 and gamebit emulator :
"CellType"=hex:\
01,01,03,03,03,03,03,03,\
....

2. Multikey 0.18.2.0
""CellType"=hex:\
01,01,03,03,03,01,03,01,\
....

I wonder that the new release Multikey (ver. 0.18.2.0) is trying to improve the effect of the final emulation result. We may refer to the following post :
http://reteam.org/board/showpost.php?p=15063&postcount=14
@Git, I have little bit long time haven't touch SuperPro but as I remember I meet almost same problem early, I solved it by compare the original dongle logs that by USBTrace. Sometimes Cell5/Cell7 should effect the final emulation result but almost 98% software don't care it.
My suggestion was use USBTrace to log the original dongle then you can see details.
http://reteam.org/board/showpost.php?p=15047&postcount=9
@Klop, your problem was caused by mkey emulator but not reg file. Little bugs exist at mkey such as read/process cell5/cell7 etc. For sure Gamebit release was more perfect than mkey.

gus
11-18-2009, 05:14 AM
Finish all ok

thanks to SonofabiT for send me multiples reg files for test,
only run with vbusbus of gamebit0 , (in this forum multi_3.rar)
Reg file is simple ,no indicate type: 3 , is type :1
and only cells 64 cells, not 128/256


I test with multikey 18.2 no run , dumper from elite , create only reg file . no create dmp file , ¿ bug ? , the reg file no include "algos" .

if r_elite need reg file o dmp send me MP

thanks

SonofabiT
11-18-2009, 07:07 AM
@ gus - Your sentinel dongle has 256 cell and we have extracted only the first 64 cell for the use of gamebit emulator. These 64 cells have been written in this post : http://reteam.org/board/showpost.php?p=17281&postcount=9

Are you sure that the last-reg (64 cell) for gambit emulator that i send you work OK ?

gus
11-18-2009, 07:44 AM
soft 2 versions

version 2009 run ok
version 2010 no run. testing and see logs today


sonofabit, 2 reg files is ok.

SonofabiT
11-18-2009, 09:22 AM
@ gus - Work with version 2010 of your s/w. In the Toro's sentmon2.01b, get two files such as LOG.txt and DONGLEINFO.txt of your actual dongle.

gus
11-21-2009, 05:59 AM
yes , run ok version 2010,
thanks sonofabit

pivasik
12-06-2009, 02:45 PM
--deleted--