View Full Version : AACS Keys - A program revealing all AACS Keys needed to decrypt (HD DVD and Blu-ray)
Pages :
1
2
3
4
5
6
7
8
9
10
[
11]
12
monk3y
5th October 2011, 17:11
I got the same with the Apocalypse Now Full DISCLOSURE 3-DISC DELUXE EDITION
~user:computer: aacskeys -v /media/APOCALYPSE_NOW_DISC1/
aacskeys 0.4.0 by arnezami, KenD00
Current path: /usr/share/aacskeys
...
The given Host Certficate / Private Key has been revoked by your drive.
ERROR: SENDHOSTCHAL: SK: 0x5, ASC: 0x6F, ASCQ: 0x00, errnr: -2
Thanks in advance
monk3y
ro-ee
6th October 2011, 09:39
On June 9th 2011, mbrp published a list of VUKs and of a new Host Certificate for AACSkeys in the "Post Blu-ray Volume Unique Keys here" thread.
Is that Host Certificate in use? or is it an older one?
monk3y
6th October 2011, 10:27
The download link (http://forum.doom9.org/showthread.php?p=1506970#post1506970) posted here is already used by an newer uploader from August 2011. Any other source for the hcert you are talking about ?
Should i post my used hcert here ?
Thanks in advance
monk3y
ro-ee
6th October 2011, 11:04
The download link (http://forum.doom9.org/showthread.php?p=1506970#post1506970) posted here is already used by an newer uploader from August 2011. Any other source for the hcert you are talking about ?
Should i post my used hcert here ?
Thanks in advance
monk3y
[previous nonsense deleted]
I see the original info isn't there anymore. I don't have the HCert available right now, maybe later this day. It might be enough posting the first few bytes to see if that certificate is used.
monk3y
6th October 2011, 17:39
8C8...08C
0200005CFFFF000000AE00004142A5411...CF72E49668DAF1DB9
Thats the Hcert iam using, the processing keys are from here (http://ysk.orz.hm/BD/DeviceKey_MediaKey/).
monk3y
ro-ee
8th October 2011, 11:25
8C8...08C
0200005CFFFF000000AE00004142A5411...CF72E49668DAF1DB9
Thats the Hcert iam using, the processing keys are from here (http://ysk.orz.hm/BD/DeviceKey_MediaKey/).
monk3y
That's the host certificate I have here since the olden days. I don't find the file on my computer anymore, but it was definitively another HCert, and most likely a newer one.
jyavenard
17th November 2011, 02:02
Following an attempt to play a BD disk (Pink Floyd The Dark Side of the moon)
Any attempts to read another disk is now failing with an error "The given Host Certficate / Private Key has been revoked by your drive."
aacskey returns the same errors.
Been over a month now.... No answer.
What can I do to go around the issue with my drive invalidating the key that most seem to use?
setarip_old
17th November 2011, 03:08
@jyavenard
Hi!
Have you tried using DVDFab, MakeMKV, or AnyDVDHD?
ro-ee
17th November 2011, 14:40
For those who know: if a host certificate is revoked (active revocation) and the drive doesn't accept it even with older disk, does a new certificate unlock the drive again?
I don't have the file posted previously anymore, but in there was a newer host certificate, perhaps someone who has downloaded (and not deleted) the file can post it again.
setarip_old
17th November 2011, 18:19
@ro-ee
Click on the following link:
http://www.makemkv.com/forum2/viewtopic.php?p=16597#p16597
vnu007dl
5th April 2012, 19:58
Hi
Last time I ve bought bd drive Liteon BLU-RAY iHBS112. I am Linux user. Kubuntu 11.10. I can watch movies from BD only via makemkv and VLC, and it works fine. But I try to watch without make mkv, only with libbluray, libaacs, and VLC, and KEYDB.cfg file. But in database there is no keys for a new movies, so I tried to do it myself with aacskeys.
darek@darek-kubuntu:~/aacskeys-0.4.0c$ aacskeys -va "/media/1920 BITWA WARSZAWSKA/"
aacskeys 0.4.0 by arnezami, KenD00
Current path: /home/darek/aacskeys-0.4.0c
MKBv: 25
Processing key: C32238976FF44A51E2D33553CFE85772
Encrypted C-value: DED130D0412F6B3543BC435E94E847C3
Corresponding uv: 00000384
Decrypted C-value: 14B7CE0E6F166D2EA394BB544642BD85
Media key: 14B7CE0E6F166D2EA394BB544642BE01
Encrypted verification data: 2B91AFE35112997CD33E72500F84FEFB
Decr verif data should be: 0123456789ABCDEF
Decrypted verification data: 0123456789ABCDEF5CFB8C65BC1FE8B0
Drive FW info: PL022011/11/11 16:53
AACS Version: 01
Number of concurrent AGIDs: 2
Supports BN generation: NO
BN Block Count: 0
Inserted medium AACS protected: YES
Host Private Key (Hpriv): 8C8647FE2A70EF0388EA9E43F432CC441C6B108C
Host certificate (Hcert): 0200005CFFFF000000AE00004142A5411F1E63F1
85581C876B939FB40B523BF69C004CA69E047606
EE5183C0ABEF1E7D04CB6E65260677E7B0573D08
E60957935503ED78F7E27B190B4A7CAFCBAFF4A2
836453ECF72E49668DAF1DB9
Host Nonce (Hn): 2923BE84E16CD6AE529049F1F1BBE9EBB3A6DB3C
AGID: 00
The given Host Certficate / Private Key has been revoked by your drive.
ERROR: SENDHOSTCHAL: SK: 0x5, ASC: 0x6F, ASCQ: 0x00, errnr: -2
darek@darek-kubuntu:~/aacskeys-0.4.0c$
What is wrong. Could you help me? How to get the keys?
BlurayDecrypter
8th April 2012, 07:35
Host Private Key and Host certificate have been revoked. there is no new keys public,now.
vnu007dl
8th April 2012, 09:58
So, I understand that for now there is no possible to crack this BD Discs? The only tool for now is makemkv? What about public keys? Is there any soft on this forum to crack public keys?
Guest
8th April 2012, 14:45
You can try AnyDVD HD.
vnu007dl
9th April 2012, 07:41
I am Linux user so I can not use AnyDVD - it doesnt works under Wine. Only tool for Linux is Makemkv. Do You know any recipe how to get keys from Makemkv?
2400NV
9th April 2012, 10:09
For a v25 disc, such as the one you're asking about, I'd first use dumpvid combined with makemkv to get the vid and then aacskeys to get the actual disc key. I run dumpvid in a virtualbox with windows — I've been told that wine works too — and everything else as linux programs. The process is a bit slow and annoying but it works for me.
vnu007dl
10th April 2012, 19:25
I already tryied use dumpvid via Wine, but it doesn works
darek@darek-kubuntu:~/AACS$ wine dumpvid.exe d
DumpVID 0.3 by KenD00 (adapted for bluray testing)
Drive type is recognised as CDROM/DVD.
Sending SPC1 Test Unit CDB6 command..done.
Returned good status.
Press ENTER to start hammering
Hammering drive...
But nothing happen even after few hours. I do not understand how to get key from makemkv? My drive is Liteon iHBS112
ro-ee
14th April 2012, 14:33
Is there a way to find out if a Blu-ray will have an update host certificate list, which will lead to the drive being unable to use the old HC anymore? Besides doing it on the drive, actually?
I'm wary buing newly released Blu-rays will lock out my drive b/c I currently have only the host certificate that starts with 0x0200005CFFFF (and the private key that starts with 0x8C8)
derbaer
17th January 2013, 13:43
http://ysk.orz.hm/BD/DeviceKey_MediaKey/ProcessingDeviceKeysSimple.rar
What is the password for the RAR-archive? Does anyone know it?
monk3y
28th January 2013, 16:01
If i try to open the folder it says the folder name is "ProcessingDeviceKeysSimple(-V30)",so there could be the missing v29 and v30 inside, someone should share the pw please.
Zombiedeth
1st February 2013, 18:03
v29 and v30 use the same key as v25 so there's nothing new there even if he added a password to the file.
if you find the original file ProcessingDeviceKeysSimple.txt
and change the last line from ;V23/25 to ;V23/V25-V30 the CRC matches the password protected file it's simply a documentation change.
monk3y
3rd February 2013, 19:53
Thanks for the info i thought the v25 key only works till v28, is there a source for this information?
patul
4th February 2013, 04:54
I can confirm Zombiedeth's information, with a little google, you can easily get the pwd btw.
sl1pkn07
4th February 2013, 05:48
password found!
i agree patul Zombiedeth
PD: seriussly, little google?? :rolls:
Rudde
3rd December 2013, 20:26
Hi, I get this error when I try to run this program, I have VID and a patched drive.
ERROR: PROCESSMKB, errnr: -3
dizzier
4th December 2013, 17:12
Hi, I get this error when I try to run this program, I have VID and a patched drive.
ERROR: PROCESSMKB, errnr: -3
You need proper processing key or device keys to decrypt this disc.
Rudde
4th December 2013, 20:29
You need proper processing key or device keys to decrypt this disc.
I gave it the device number, what is a processing key`?
dizzier
4th December 2013, 22:05
I gave it the device number, what is a processing key`?
I really have no idea what do you mean by "device number". The explanation of how AACS works and what is a processing key can be found on this forum (http://forum.doom9.org/showthread.php?t=122363).
And just to save you time, currently there are no processing keys available for MKBv31 and later.
dizzier
13th December 2013, 15:53
New host certificate and key, already revoked but works up to MKBv43, might still be of use for some people:
88B245EA25315F46E6E99D9D521EB1194454A82D
0201005CFFFF800000C400005BF6843ED1AA9C9DEEFEAD8174479C72AB5457691EEB75669105BB195D4B9133069A18FD5357797116CEC22D7FE8F366C2A092E1D00DB770E9E01DB687456B6FBFA28C962D88F05DD43F584ECC821AF7
Zombiedeth
15th December 2013, 08:03
I think it must be revoked at MKBv43 or earlier because it's already revoked for me and i haven't used any discs newer then MKBv43.
dizzier
15th December 2013, 11:58
I think it must be revoked at MKBv43 or earlier because it's already revoked for me and i haven't used any discs newer then MKBv43.
I've just double checked that it is not present in revocation list on MKBv43. This is a certificate with bus encryption bit set, you need aacskeys 0.4.0e in order to use it (it is floating around for a while), 0.4.0c available on this forum will not work.
Zombiedeth
15th December 2013, 13:18
I've just double checked that it is not present in revocation list on MKBv43. This is a certificate with bus encryption bit set, you need aacskeys 0.4.0e in order to use it (it is floating around for a while), 0.4.0c available on this forum will not work.
I see i tried it with Videolan but the precompiled libaacs doesn't support bus encryption. Maybe that's why it says the certificate is revoked.
dizzier
15th December 2013, 13:33
I see i tried it with Videolan but the precompiled libaacs doesn't support bus encryption. Maybe that's why it says the certificate is revoked.
It doesn't matter, libaacs supports bus encryption capable certificates just fine (even old versions). Then only thing it is not capable of is actually using bus encryption (unless you use latest version from git), but this requires disc support and such discs are right now extremely rare.
aacskey 0.4.0c doesn't work because it blindly assumes that the second byte in the certificate is 0, 0.4.0e fixes it simply by allowing 1 in there.
Anyway, it is hard to say why exactly it is not working for you. You probably should try aacskeys 0.4.0e first.
Zombiedeth
15th December 2013, 14:21
It worked with aacskeys 0.4.0e and i got it working with Videolan also there was a error in my KEYDB.cfg preventing it from working.
candela
21st December 2013, 21:56
Is there also any new processing key known to go with the host certificate? And does anyone were to get a compiled version of VLC libaacs 0.7.0
dizzier
24th December 2013, 13:10
And does anyone were to get a compiled version of VLC libaacs 0.7.0
You can try the ones attached. Choose proper version (32 or 64 bit) depending on the VLC version you have. I've tested 64 bit version and it seems to be working fine, unfortunately I am currently unable to test 32 bit version (hopefully it will work too).
EDIT: Got back to my Windows PC, both versions verified to be working fine with VLC 2.1.2 on Windows 7.
DarthM
3rd January 2014, 00:37
Hi everyone especially dizzier,
i have a patched LG-GGC-H20L and can bypass the revocation stuff, but i still need a proccessing key right?
for discs with mkbv30 and lower it is working but with discs v31 and above i can't get it working because i'm missing a processing key, i already updated the hostkey file with your posted stuff
so how do you do that?
i've seen in another topic for volume keys here you can calculate the VUK till atleast v40
i tried aacskeys 0.4.0c and e (both linux, x64)
i only get accskeys to dump the Volume ID, but that's all
man i hate that stupid stuff, the guys who just wanna watch their legally bought blurays without dumping everything need to hack and the other ones who are loading their stuff from the net, just double click their files : /
so it would be very nice if someone could give me a hint (even per pm), how to get these discs with newer mkb versions working
Big Thanks in advance
DarthM
dizzier
3rd January 2014, 01:29
Hi everyone especially dizzier,
i have a patched LG-GGC-H20L and can bypass the revocation stuff, but i still need a proccessing key right?
for discs with mkbv30 and lower it is working but with discs v31 and above i can't get it working because i'm missing a processing key, i already updated the hostkey file with your posted stuff
so how do you do that?
i've seen in another topic for volume keys here you can calculate the VUK till atleast v40
i tried aacskeys 0.4.0c and e (both linux, x64)
i only get accskeys to dump the Volume ID, but that's all
man i hate that stupid stuff, the guys who just wanna watch their legally bought blurays without dumping everything need to hack and the other ones who are loading their stuff from the net, just double click their files : /
so it would be very nice if someone could give me a hint (even per pm), how to get these discs with newer mkb versions working
Big Thanks in advance
DarthM
There is no processing key for MKBv31 or later so you cannot decrypt those discs. I have no idea how to handle that.
You can always extract VUKs from rippers, but this does not solve the problem and is rather inconvenient.
DarthM
20th January 2014, 16:56
hi again,
sorry for my late response and thank you for your lightning one.
so, we still need a processing key.
is it possible to calculate the used processing key of discs with mkbv31 and higher which you have posted VUKs for?
i mean to calculate these VUKs, a valid processing key had to be used right?
so we don't have one but the ripper had to have one right again?
i took a short look on the aacskeys source and the processing key is used for decrypting the encrypted C value right?
is it also possible to get both values from rippers?
another idea in my head is to put every possible processing key into the file and let it run
aacskeys returns the one which was successful
i know, it would be a long list and i don't want to think about the time frame : )
i guess an opencl port with endless threads would be awesome
guys with aacs-bypass drives wouldn't have a problem to let every possible key be checked right? only these with normal drives and countermeasures
or i just buy a standalone player ............ but that suxxx ......... a lot .......
dizzier
20th January 2014, 20:47
hi again,
sorry for my late response and thank you for your lightning one.
so, we still need a processing key.
is it possible to calculate the used processing key of discs with mkbv31 and higher which you have posted VUKs for?
i mean to calculate these VUKs, a valid processing key had to be used right?
so we don't have one but the ripper had to have one right again?
i took a short look on the aacskeys source and the processing key is used for decrypting the encrypted C value right?
is it also possible to get both values from rippers?
Yes, you are right, processing key needs to be extracted from a ripper or a player. That's the theory. Practice is not that easy. Some rippers simply ask their servers to provide them proper VUK (or Media Key), that means the processing key is never present on your computer at all. Others have processing keys (or device keys) heavily protected and times when processing key appeared in plain, not obfuscated way, in memory are long gone with 2007/2008. Of course you can still try if you want, please share any findings you have;)
another idea in my head is to put every possible processing key into the file and let it run
aacskeys returns the one which was successful
i know, it would be a long list and i don't want to think about the time frame : )
i guess an opencl port with endless threads would be awesome
guys with aacs-bypass drives wouldn't have a problem to let every possible key be checked right? only these with normal drives and countermeasures
or i just buy a standalone player ............ but that suxxx ......... a lot .......
Unfortunately that's just plain stupid. There are 2^128 possible keys. If you would be able to check a million keys every second (which is highly unlikely even with OpenCL) checking 1% of them would take about 107.902.830.708.060.141.889.705 years. I believe the universe will end well before we find anything useful;)
Fahzuu
21st February 2014, 15:04
If you would be able to check a million keys every second (which is highly unlikely even with OpenCL)
While this will hardly put a scratch into your reasoning, you are mildly underestimating the speed of CPUs nowadays.
A 5 year old Intel i7 can test roughly 10 million AES keys per second with a simple AES implementation in C/C++.
If you make use of its AES-NI instruction set, it will easily do - sit tight - 300 million per second.
But this will only remove a couple of digits from your number, so subjectively nothing really changes :)
dizzier
21st February 2014, 20:38
While this will hardly put a scratch into your reasoning, you are mildly underestimating the speed of CPUs nowadays.
A 5 year old Intel i7 can test roughly 10 million AES keys per second with a simple AES implementation in C/C++.
If you make use of its AES-NI instruction set, it will easily do - sit tight - 300 million per second.
But this will only remove a couple of digits from your number, so subjectively nothing really changes :)
Verifying processing key is not a single AES operation. Unless you know the position of the key in subset-difference tree you must do over 500 AES operations to test one processing key with a single version of MKB. And you have currently 46 MKB versions (not all use different processing keys though). So in the very worst case scenario you must do 23.000 AES decryptions to verify that a given key is not a processing key.
But yeah, that really does not change anything, even if we get hardware capable of doing trillions of AES operations per second:)
Fahzuu
21st February 2014, 21:32
Verifying processing key is not a single AES operation. Unless you know the position of the key in subset-difference tree you must do over 500 AES operations to test one processing key with a single version of MKB.
Actually, it is a single operation. There are roughly 500 entries, each requiring a different processing key, leading to the same media key. All you need is one, you wouldn't be looking to find all 500. Also it's only a single MKB you'd be examining.
Well, and then there is another aes op required to verify, but that's all. 2^129 aes operations to verify all possible processing keys for any chosen one of the "slots" or whatever they are called.
dizzier
22nd February 2014, 14:22
Well, OK, that depends on the approach (examining multiple subset-difference trees might be a better idea as you already have performed a key schedule for the given processing key you are testing). Anyway, you still get a processing key for a single MKB (or few, but not all, depends which tree you happen to crack).
Zombiedeth
23rd February 2014, 16:31
What about using OpenCL and Distributed computing? each person participating would only handle a small portion of the key range at a time.
dizzier
23rd February 2014, 17:34
Please read my reply with the calculations. OpenCL does not change anything at all, it is not a "magic technology that makes anything fast".
Anyway, even if you get a billion machines each verifying billions keys per second you would still not be able to get anything before the sun explodes, Earth is destroyed and universe ends. Even if you can get it a billion times faster with OpenCL it would still not be enough.
ghefgpq
27th May 2014, 13:01
Do you know the Media Key or Processing Key AACSv42 and AACSv43
dizzier
27th May 2014, 13:09
No, I don't.
pvh1987
5th July 2014, 16:23
I just got a portable BD drive for my Macbook Pro. It is a Samsung SE-506CB. When I run aacskeys it says
The given Host Certficate / Private Key has been revoked by your drive.
Then I found a newer Host Certificate and now it says
Problem with verifying the drive signature.
I am not sure what to do about this. On my Linux PC with an older Pioneer BD drive, aacskeys usually work fine. I think I might have patched this drive several years ago. I cannot find a patch for my Samsung drive, though.
Do I need a patch or could the problem be something else?
Thanks in advance :-)
dizzier
7th July 2014, 22:32
aacskeys 0.4.0c does not work with host certificates that have Bus Encryption Capable bit set, which is located in the second byte of the host cert. In short, aacskeys 0.4.0c does not support host certificates that start with 0201 (basically all recent ones).
However, the fix is trivial to make. In the aacskeys source code, locate file aacs_ecdsa.cpp. You will find 'aacs_set_cert' function there. Simply remove the first 'if' block (or modify it to allow second byte not to be zero) and recompile aacskeys, it should work.
I believe there was also aacskeys 0.4.0e floating around, hacked by someone, that has this fix applied.
vBulletin® v3.8.11, Copyright ©2000-2026, vBulletin Solutions Inc.