View Full Version : AACS Keys - A program revealing all AACS Keys needed to decrypt (HD DVD and Blu-ray)


arnezami
11th March 2007, 22:04
MODERATOR NOTE: arnezami and KenD00 are apparently no longer active in maintaining this software. New versions can be found at cyberside (http://cyberside.net.ee/ripping/BD_DeviceKeys/).

Thank you, arnezami, for your pioneering work!

Original contents of this post follow...

----------------------------------------

Finally.

Here is my program that gives a list of all keys used for aacs decryption for one disc. Currently I'm too tired to go into this deeply but I need people to test this. Especially the Blu-ray owners: I have no Blu-ray burner/player so I'm "flying blind" when it comes to programming stuff for Blu-ray. I think I've read the Blu-ray specs right and hope it all works. But it really has to be tested.

Anyway. As promised the program itself: aacskeys.exe v0.2.5 (http://www.sendspace.com/file/3e8bzt) (fixed for Blu-ray now :))

Go here for the new v0.2.8 version (http://forum.doom9.org/showthread.php?p=1018060#post1018060).

Its still in the early stages of development so there are probably some bugs in it.

Here is a screenshot (King Kong):

http://img110.imageshack.us/img110/4728/aacskeyspicfu1.jpg

Thats gotta put a smile on your face :D :D

Keep in mind there are three types of views now: normal (n), verbose (v) and sensitive (s). But you'll figure it out ;).

When I iron some things out I will release the source (of course) but this will take at least a couple of days (maybe next week). There are still a couple of things to do (Hk, VID MAC, BK, TKFMAC, Device Keys etc). But I want it to work first and there is where you guys come in :).

So if you can test if it works please do. Any feedback is welcome.

Thanks already :thanks:

Regards,

arnezami

Pelican9
11th March 2007, 22:15
It works.
Or these are burned-in values... :)
Processing key: 09F911029D74E35BD84156C5635688C0
Encrypted C-value: 6D02CAC67B1A7E95C216EFD4C92809CF
Corresponding uv: 00000001

Decrypted C-value: 074E1FC88FB9B780A225CAA23BC3DB57
Media key: 074E1FC88FB9B780A225CAA23BC3DB56

Encrypted verification data: 87B8A2B7C10B9FADF8C4361E238659E5
Decr verif data should be: 0123456789ABCDEF
Decrypted verification data: 0123456789ABCDEF0A9BE086140F5A60

AGID: 00

Host certificate from: Power DVD 7.1
Host certificate (Hcert): 0200005CFFFF0000000C00006E3DEB679B9A16AD
FAA8E30878767BA6EB2A9B415385AD1181B4446C
31E9A5DD2AB808B364FF15885BAC490964318C9B
F8029FCF76F688A54FBDA03F6D9332EF04E5A613
12DA85880A4D9CBB79D8602E
Host Private Key (Hpriv): 4737676058D7029452514F0AB186DC4CCA8C578F
Host Nonce (Hn): 2923BE84E16CD6AE529049F1F1BBE9EBB3A6DB3C

Drive certificate (Dcert): ########################################
########################################
########################################
########################################
########################
Drive Nonce (Dn): ########################################

Drive key point (Dv): ########################################
########################################
Drive key signature (Dsig): ########################################
########################################

Host key (Hk): 0000000000000000000000000000000000000000
Host key point (Hv): 8E9B0E3CF41FA7DA3A829F604122EA4ED5261AA4
7570CE0BB9061A66FAF92C4A7D98ACC171CBF19B
Host key signature (Hsig): ########################################
########################################

Bus key (BK): ################################

Volume ID: 40000918200608410020202020200000
Voluem ID MAC: ################################

Volume Unique Key: 802F78B1B20D1183638D84E1A96D6EDD
Title Key File MAC: 399FE6A364D623541418E3805D1ED790

Encrypted Title Key 1: 30F8DC87B137A1607C7F2A731FF7B6BC
Encrypted Title Key 2: B5183BDC3335A1EBC8E517B6611A1CBA
Encrypted Title Key 3: A625BDC656E9D5EDE040A07B9FB8D7B1
Encrypted Title Key 4: F5ACB8900A639E85B4133933E74A92E7
Encrypted Title Key 5: 635B440099BFAB97911ABBBC4B1F25A7
Encrypted Title Key 6: 9EB5C32E0AFB0B3A4A906CB360CE57A0
Encrypted Title Key 7: 21258E976BECFF0090E371058DDDE695
Encrypted Title Key 8: E49D4100A52DB01F7F605768DB4000F2

Decrypted Title Key 1: 7D743D3C92652CC16B66D9CB87F6D132
Decrypted Title Key 2: 70B71C6E767E213AEB7456985BAAD8A4
Decrypted Title Key 3: 4BC362995030035312A5B6030D76C817
Decrypted Title Key 4: A019B5101E904A700A44F056B7EB3579
Decrypted Title Key 5: 896AB02D3D77554EABCE3CCE931DA39D
Decrypted Title Key 6: BEC07637E9C4EFA1F70FED6891DB277B
Decrypted Title Key 7: 1DC0D276F2C5B9FCFDE1414C5002BAAB
Decrypted Title Key 8: BC7EB577D1936818AEB9241F024DE681

fakker
11th March 2007, 23:11
confirmed working....

Batman Begins UK HD-DVD - 15/09/06
Here is the output given after using verbose mode:
C:\>aacskeys d v
Processing key: 09F911029D74E35BD84156C5635688C0
Encrypted C-value: C8ADC9F88E38FB152FCD5E68291C4C60
Corresponding uv: 00000001

Decrypted C-value: B0A84A4838821346834751E1E9D33B44
Media key: B0A84A4838821346834751E1E9D33B45

Encrypted verification data: 8D960C0952C0A6260AD3FDD236DF015B
Decr verif data should be: 0123456789ABCDEF
Decrypted verification data: 0123456789ABCDEF143F000821C02F93

AGID: 00

Host certificate from: Power DVD 7.1
Host certificate (Hcert): 0200005CFFFF0000000C00006E3DEB67
FAA8E30878767BA6EB2A9B415385AD11
31E9A5DD2AB808B364FF15885BAC4909
F8029FCF76F688A54FBDA03F6D9332EF
12DA85880A4D9CBB79D8602E
Host Private Key (Hpriv): 4737676058D7029452514F0AB186DC4C
Host Nonce (Hn): 2923BE84E16CD6AE529049F1F1BBE9EB

Drive certificate (Dcert): ################################
################################
################################
################################
########################
Drive Nonce (Dn): ################################

Drive key point (Dv): ################################
################################
Drive key signature (Dsig): ################################
################################

Host key (Hk): 00000000000000000000000000000000
Host key point (Hv): 8E9B0E3CF41FA7DA3A829F604122EA4E
7570CE0BB9061A66FAF92C4A7D98ACC1
Host key signature (Hsig): ################################
################################

Bus key (BK): ################################

Volume ID: 400009061209091557474844564D0000
Voluem ID MAC: ################################

Volume Unique Key: F66308D9151653672AB7D75A01DC3F7E
Title Key File MAC: 40746D614A37CE2EAC331A5939D3E238

Encrypted Title Key 1: A51DACA264BC206442AD767237E02130
Encrypted Title Key 2: A57046224AE96E17D7F2F8878E914B0A
Encrypted Title Key 3: BD21A78EADF40081516133E925066C19
Encrypted Title Key 4: 34970BF350A7342F579C7187365D3771
Encrypted Title Key 5: 872E9B67DA39B10BF8C10796F82A394D

Decrypted Title Key 1: 2D9CF93FA5F221C2135DDB06AE4F3EA5
Decrypted Title Key 2: 8B6922BEBDE8B48A25021E75F1B7B597
Decrypted Title Key 3: 4F32342FB377E0FE8A9C1166A51F3B8E
Decrypted Title Key 4: F3419DE7F77AC83E0230A3E2A7833059
Decrypted Title Key 5: 04AF9217B59BA527663CD968BDD701DB

Sorry if it looks a mess... Either way there were 64 encrypted and decrypted keys... I will not paste all of those as we get the drift. :eek:

Again, as many have already said - thanks a lot for all of your efforts, and in releasing this long awaited tool. :thanks:

mrazzido
11th March 2007, 23:36
i try it on bluray , House of Wax EUR / GER


when i read the keys from memory ( windvd )

i get these



CPS Unit Key : 9329A4976FE297AF4475BDAD13119A4F

Volume Unique Key : 83AD82670F99F9F9A64D05B0501CF20D




with your tool i get

http://img474.imageshack.us/img474/7059/hghta3.png

mrazzido
11th March 2007, 23:43
second test

on click EUR / GER


winddvd memory



CPS Unit Key : 05BAFE2DD84C0781C6CE09714726FED9

Volume Unique Key : 5928C17E732E17FCC896401715556D07



tool

http://img393.imageshack.us/img393/5159/vsvsvms3.png

arnezami
11th March 2007, 23:50
second test

on click EUR / GER


winddvd memory



CPS Unit Key : 05BAFE2DD84C0781C6CE09714726FED9

Volume Unique Key : 5928C17E732E17FCC896401715556D07



tool

Ok. There is clearly a problem with the retrieval of the Volume ID here (its all 0's) . Which is also the hardest to test for me.

Can you tell me if any of the sensitive data: Dv/Dsig/Dn/Dcert/VID MAC are also all 0's (don't post them just tell if some of them they are all 0's and if so which ones)

And are these file names on your disc(s):

G:\AACS\Unit_Key_RO.inf
G:\AACS\MKB_RO.inf

Because it seems to have problems opening the Title Key file (error on top).

I'm pretty sure the MKB file is working since the Media Key is verified.

mrazzido
11th March 2007, 23:59
yeah these files on the disc.


http://img183.imageshack.us/img183/1518/vsvsvsvsbm5.png

arnezami
12th March 2007, 00:00
Ah. I think I see the problem.

Try this one: aacskeys.exe (http://www.sendspace.com/file/8ltp8b)

mrazzido
12th March 2007, 00:05
works

test it on click


http://www.directupload.net/images/070311/rXH8PKd3.jpg

arnezami
12th March 2007, 00:09
works

test it on click




Perfect :D

Now it works for BluRay too.

mrazzido
12th March 2007, 00:10
second test of how / ger/eur

http://www.directupload.net/images/070312/zdJK8kZo.jpg






great work :-)

bourke
12th March 2007, 00:27
How do you find the 'hash' value used in programs like BackupHDDVD? Is that something that could be added to the output?

mrazzido
12th March 2007, 00:27
sometimes ago i burned a CRYPTED movie on BD-RE

when i try the tool

C:\Dokumente und Einstellungen\Administrator>aacskeys g n
Processing key: 09F911029D74E35BD84156C5635688C0
Media key: 853EC6162030F7F7EF1B61265BE30A68
Volume ID: 00000000000000000000000000000000
Volume Unique Key: 378A39F68C5FDABE94D0621BDBC4481D
Decrypted Unit Key 1: 8AF9B2644339E90931DA68DB96AA06AA

arnezami
12th March 2007, 00:29
How do you find the 'hash' value used in programs like BackupHDDVD? Is that something that could be added to the output?

Yeah. Still have to do that. :)

Very practical indeed.

arnezami
12th March 2007, 00:32
i sometimes ago i burned a CRYPTED movie on BD-RE

when i try the tool

Interesting. Volume ID is all 0's with rewritables. That sort of makes sense though. But does it give a Volume ID MAC (when doing the sensitive view). Or is that one all 0's too? If it all 0's then Players can probably not be fooled by putting encrypted movies on rewritables (even after re-encrypting the title keys). But if the Volume ID MAC is anything other than 0's then its going to be interesting to see what we can do with rewritables...

bourke
12th March 2007, 00:35
No hurry either - we all appreciate this (whole AACS caper) must have used up a lot of your time already :-)

I'm actually more waiting on the lads doing those evo demux/authoring tools (which are coming nicely) - then if they include your code they can have a very nice 1080p to 720p (~8Gb) conversion tool indeed :-)

mrazzido
12th March 2007, 00:36
Interesting. But does it give a Volume ID MAC (when doing the sensitive view). Or is that one all 0's too? If it all 0's then Players can probably not be fooled by putting encrypted movies on rewritables (even after re-encrypting the title keys). But if the Volume ID MAC is anything other than 0's then its going to be interesting to see what we can do with rewritables...





i try all 0's :-/

blutach
12th March 2007, 01:04
@arnezami

A huge thank you for this. Thread stuck.

Regards

xyz987
12th March 2007, 02:17
Excellent!!!

:thanks:

vudoodoodoo
12th March 2007, 03:13
Nice. Thank you!

woodspire
12th March 2007, 03:27
Please compile your program in Java so I can test it on my PS3 linux !

Still can't compile properly the iscsi application to mount the blu-ray drive in windows, but it's coming ...

blutach
12th March 2007, 03:40
@woodspire - I have had enough of people ignoring the policy on requests. Strike issued.

Regards

HyperHacker
12th March 2007, 04:25
Excellent work, I can't test it myself but it looks great. Just thinking though you should add an ASCII view of the volume ID, as those seem to be ASCII fairly often. :)

guile
12th March 2007, 13:20
GREAT WORK!!!! I have tested on SEVERAL BLu Ray discs and it is working on all of them (at least producing what appears to be working keys). I can't confirm the keys are valid without title hash (unless I'm missing something).

Electrox3d
12th March 2007, 17:47
GREAT WORK!!!! I have tested on SEVERAL BLu Ray discs and it is working on all of them (at least producing what appears to be working keys). I can't confirm the keys are valid without title hash (unless I'm missing something).

Yeah, thats the final question I have too... where's the Title hash? Is this not possible to get via software?

If this is a program revealing all AACS Key's needed to decrypt, does that mean it is hidden somewhere in the output?

Thanks, great job!

KenD00
12th March 2007, 18:09
The title hash is the SHA-1 hash value from the file AACS\CPSUnit00001.cci off the disc. There are many programs which can calculate a SHA-1 hash, e.g. HexWorkshop or WinHEX. Btw., this identifier is not very well chosen, there are already titles which have the same title hash. This is because this file does not contain information that is unique per title, it contains Copyright Control Information. If two discs have the same number of titles and use the same copy-rights (things like Image Constraint Token and so on) they will produce the same title hash.

Therefor, when BluRay support is included into DumpHD it will use the SHA-1 hash of the file AACS\Unit_Key_RO.inf as title hash.

:rolleyes:

arnezami
12th March 2007, 18:51
The title hash is the SHA-1 hash value from the file AACS\CPSUnit00001.cci off the disc. There are many programs which can calculate a SHA-1 hash, e.g. HexWorkshop or WinHEX. Btw., this identifier is not very well chosen, there are already titles which have the same title hash. This is because this file does not contain information that is unique per title, it contains Copyright Control Information. If two discs have the same number of titles and use the same copy-rights (things like Image Constraint Token and so on) they will produce the same title hash.

Therefor, when BluRay support is included into DumpHD it will use the SHA-1 hash of the file AACS\Unit_Key_RO.inf as title hash.

:rolleyes:
That sounds like a really good idea. I always assumed Muslix64 hashed the Unit_Key_RO.inf. But looking at it more closely its pretty obvious now we get duplicate hash values (there isn't much info in the cci info to begin with).

Theoretically the Unit Key files could be the same for some discs aswell. But I don't know if they would actually do that (different vuks with the same unit key file lead to different unit keys, so they could do this since there is no tkfmac).

Anyway. If you're going to do this then I will do the same with my program aacskeys: hashing the title key file for HD DVDs and hashing the Unit Key file for blu-ray discs. So our programs will be compatible that way. :)

What should we do if there are multiple title key file btw? (for hd dvd only I believe)

Is there a specific file format you're going to use? Or plain pipe separated? I thought about using ";" or "//" or something as comment markers at the beginning of each comment line (at the beginning of the file). Maybe also column names. I like to keep it really basic and simple though ;).

Regards,

arnezami

lightshadow
12th March 2007, 21:20
First of all, fantastic work to all that have contributed to make this program happen =)

Regaring the source, I can understand that you want to wait a while before releasing it. But the problem is, if Doom9 gets closed in the meantime, the source is not released =(

So what if you made a rar/gpg encrypted archive of the source available, and when you feel it is ready we get the passphrase? =)

The advantage is that if Doom9 should get closed, it is easier to make a passphrase slip, so someone can make a Slashdot story, that THE passphrase have slipped and it is ####, rather than having to release the soruce. =)

Another advantage is, that if you tell the passphrase to a few trusted secret people, and you should go silent, the passphrase is still out there, and you haven't released it after you have gone silent. Someone else have, and it could be anybody. Who knows who you can trust these days? =)

Ps. It would be fun if the passphrase was 4737676058d7029452514f0ab186dc4cca8c578f . Just of the irony =)

arnezami
12th March 2007, 21:44
First of all, fantastic work to all that have contributed to make this program happen =)

Regaring the source, I can understand that you want to wait a while before releasing it. But the problem is, if Doom9 gets closed in the meantime, the source is not released =(

So what if you made a rar/gpg encrypted archive of the source available, and when you feel it is ready we get the passphrase? =)

The advantage is that if Doom9 should get closed, it is easier to make a passphrase slip, so someone can make a Slashdot story, that THE passphrase have slipped and it is ####, rather than having to release the soruce. =)

Another advantage is, that if you tell the passphrase to a few trusted secret people, and you should go silent, the passphrase is still out there, and you haven't released it after you have gone silent. Someone else have, and it could be anybody. Who knows who you can trust these days? =)

Ps. It would be fun if the passphrase was 4737676058d7029452514f0ab186dc4cca8c578f . Just of the irony =)

Well ok then. For me not yet releasing the source is not about being secretive but about being proper. What I've learned about open source is that its not just about releasing the source but making it understandable and easely useable and giving credit to all that should be given credit to. I haven't had the time to do that properly. But if you instist and really want it (the raw version that is) I will release the source of the current version.

Here is is: source (http://www.sendspace.com/file/4x8imn). You need openssl for this to work.

This is not an "official" release. This is just for those who want to play around with it.

Regards,

arnezami

nincollector
13th March 2007, 00:10
does this only work for power dvd 7.1 or will it work with all software players i.e 7.2 and above?

mrazzido
13th March 2007, 00:22
the info is that the key is from power dvd 7.1

you can decrypt the movie with backuphddvd / bluray

and play fine with windvd or power dvd 6 hd or bd edition

jh87
13th March 2007, 07:10
I tried it on a bluray iso copied from PS3. I got the processing key, which is the one we all know. I also got the media key but then the program aborted with message saying "all AGIDs in use".
Then I tried it on the PS3 linux with the original movie for the above ISO, then I got the "permission denied" message.
So I guess it is no go if I don't have a BD drive connected to my PC, right? Sorry for the newb question.

arnezami
13th March 2007, 07:56
Could somebody try to compile this on linux (PS3 or PC).

aacskeys multi platform source (http://www.sendspace.com/file/7rvzff). (linux + windows)

This version should compile both on windows as on linux. But I haven't tested it yet on linux. Please keep me informed of any problems and/or solutions.

The instructions are almost the the same as for aacsauth:

INSTALL

You need openssl 0.9.8
Compile with gcc -o aacskeys -lcrypto ioctl.c ecdsa.c mmc.c aes.c aacsauth.c

There may be some warnings. But hopefully it compiles for linux now (not tested yet).

USAGE

Type something like ./aacskeys /dev/scd0 v
/dev/scd0 is the device file of your drive

Regards,

arnezami

PS. The PS3 uses a hypervisor which might prevent it from getting the volume id at all. And mounted ISOs can't handle the mmc commands properly.
PPS. The old source should't work on linux unless adapted of course :).

ebsi
13th March 2007, 10:01
This one compiles now on linux. Still untested on PS3.
http://www.sendspace.com/file/x9nmjq

KenD00
13th March 2007, 11:09
Theoretically the Unit Key files could be the same for some discs aswell. But I don't know if they would actually do that (different vuks with the same unit key file lead to different unit keys, so they could do this since there is no tkfmac).

Hmm, thats a point that i have missed. Since title keys are random, this could happen by chance, but how big is this probability? Maybe a second file should be used in addition to create the title hash? I'm open for ideas.

What should we do if there are multiple title key file btw? (for hd dvd only I believe)

For HD-DVD Advanced Content the VTKF000.AACS is still a good choice, for HD-DVD Standard Content i use the only present TKF VTKF.AACS.

Is there a specific file format you're going to use?

For now, the database format is not nice, but sufficient enough. For BluRay i will only change the key entries to be consistent with the HD-DVD format (i will store both keys in one db), that is adding a key type flag (V = VUK, U = CPS Unit Key) and numbering the CPS Unit Keys like the Title Keys. When its time for Sequence Keys i think we should think about a new format, the current one can only store one key type per entry, for Sequence Keys you would need two lines, with redundancy of the movie name and so on, thats not so nice.

:rolleyes:

arnezami
13th March 2007, 19:28
This one compiles now on linux. Still untested on PS3.
http://www.sendspace.com/file/x9nmjq

Thanks for helping to get it to work on linux. Have you tested it on PC (running linux)? HD DVD or Blu-ray? Or did you only compile it.

Also you added this to the aacskeys.h:

#if !defined(linux)
int send_cmd(drive_handle h, unsigned char *cmd, unsigned char *buf, size_t send, size_t recv);
#endif


So the definition of send_cmd will not be available for linux. But how can this work since mmc.c needs it? Did it give an error and if so which one?

Thanks.

People own a PS3 could try to compile it on their PS3 and see what happens... (i'm quite curious) :)

Regards,

arnezami

arnezami
13th March 2007, 19:33
Hmm, thats a point that i have missed. Since title keys are random, this could happen by chance, but how big is this probability? Maybe a second file should be used in addition to create the title hash? I'm open for ideas.
The chance of this happening by pure chance is zero. They really would have to do this intentionally (but it would be a little silly for them to do this). So (for now) I think it would be a good idea to use the Unit Key file: its also equivalent to the Title Key file (for HD DVD). So it would all make more sense.

For HD-DVD Advanced Content the VTKF000.AACS is still a good choice, for HD-DVD Standard Content i use the only present TKF VTKF.AACS.

Yeah. That should work fine.

For now, the database format is not nice, but sufficient enough. For BluRay i will only change the key entries to be consistent with the HD-DVD format (i will store both keys in one db), that is adding a key type flag (V = VUK, U = CPS Unit Key) and numbering the CPS Unit Keys like the Title Keys.

Sounds good. Especially the V/U differentiation. Blu-rays are bound to get more Unit keys per disc.

When its time for Sequence Keys i think we should think about a new format, the current one can only store one key type per entry, for Sequence Keys you would need two lines, with redundancy of the movie name and so on, thats not so nice.
I'm probably also creating my own kinds of files for Device/Processing keys and Host Certificates/Private Keys (probably using the some kind of format). Which would also include corresponding uv values and MKB versions and Software player name+versions. But your program will not need these files/keys (until that is you implement the mkb processing and aacsauth stuff aswell).

Regards,

arnezami

00dwan
13th March 2007, 19:47
People own a PS3 could try to compile it on their PS3 and see what happens... (i'm quite curious) :)

Regards,

arnezami

I have a ps3 and want to test it (actually I need it to work for something I'm trying to do: http://forum.doom9.org/showthread.php?t=123355), but I'm a linux n00b so I would need very clear instructions.

fakker
13th March 2007, 21:57
I have a ps3 and want to test it (actually I need it to work for something I'm trying to do: http://forum.doom9.org/showthread.php?t=123355), but I'm a linux n00b so I would need very clear instructions.

INSTALL

You need openssl 0.9.8
Compile with gcc -o aacskeys -lcrypto ioctl.c ecdsa.c mmc.c aes.c aacsauth.c

There may be some warnings. But hopefully it compiles for linux now (not tested yet).

USAGE

Type something like ./aacskeys /dev/scd0 v
/dev/scd0 is the device file of your drive

dirio49
13th March 2007, 23:53
here I tried in gentoo, and it compiles,But cannot test no HDDVd or BlUray disk nor drives :)

gcc -o aacskeys -lcrypto ioctl.c ecdsa.c mmc.c aes.c aacskeys.c
ecdsa.c: In function 'aacs_set_cert':
ecdsa.c:29: warning: initialization discards qualifiers from pointer target type
ecdsa.c: In function 'aacs_sign':
ecdsa.c:67: warning: comparison between pointer and integer

woodspire
14th March 2007, 01:44
Done under PS3 with Yellow Dog Linux 5. I have modified the ioctl.c file to match both send_cmd header. (I add unsigned to the linux header function). So now, I don't get the error between ioctl.c and aacskeys.h

But still get these errors. Seems that openssl can't get correctly installed. Don't know why. openssl ppc version (not ppc64). It seems it install itself in /usr/local/ssl/include instead of the default path.

If I run openssl, it says it's version 0.9.8a 11 october 2005
But I compiled 0.9.8e

Please someone with C compilation knowledge (I so much love perl, so such compilation problem) compile a binary for linux-ppc or linux-ppc64. Staticly linked would be better I think.

Here is the output from the gcc command:

gcc -o aacskeys -lcrypto -I/usr/local/ssl/include ioctl.c ecdsa.c mmc.c aes.c aacskeys.c
ecdsa.c: In function ‘aacs_set_cert’:
ecdsa.c:29: warning: initialization discards qualifiers from pointer target type
ecdsa.c: In function ‘aacs_sign’:
ecdsa.c:67: warning: comparison between pointer and integer
aes.c:62:2: warning: no newline at end of file
aacskeys.c: In function ‘main’:
aacskeys.c:555: warning: comparison is always false due to limited range of data type
/tmp/ccIwRoTT.o: In function `aacs_key':
ecdsa.c:(.text+0x14): undefined reference to `EC_KEY_new'
ecdsa.c:(.text+0x4c): undefined reference to `EC_KEY_set_group'
ecdsa.c:(.text+0x6c): undefined reference to `EC_KEY_free'
/tmp/ccIwRoTT.o: In function `aacs_set_cert':
ecdsa.c:(.text+0xd0): undefined reference to `EC_KEY_get0_group'
ecdsa.c:(.text+0x190): undefined reference to `EC_POINT_new'
ecdsa.c:(.text+0x1c8): undefined reference to `EC_POINT_set_affine_coordinates_GFp'
ecdsa.c:(.text+0x1fc): undefined reference to `EC_KEY_set_public_key'
/tmp/ccIwRoTT.o: In function `aacs_sign':
ecdsa.c:(.text+0x2cc): undefined reference to `EC_KEY_set_private_key'
ecdsa.c:(.text+0x2dc): undefined reference to `EVP_ecdsa'
ecdsa.c:(.text+0x34c): undefined reference to `ECDSA_do_sign'
ecdsa.c:(.text+0x3c4): undefined reference to `ECDSA_SIG_free'
ecdsa.c:(.text+0x3d8): undefined reference to `EC_KEY_free'
/tmp/ccIwRoTT.o: In function `aacs_verify':
ecdsa.c:(.text+0x458): undefined reference to `EVP_ecdsa'
ecdsa.c:(.text+0x4b4): undefined reference to `ECDSA_SIG_new'
ecdsa.c:(.text+0x534): undefined reference to `ECDSA_do_verify'
ecdsa.c:(.text+0x550): undefined reference to `ECDSA_SIG_free'
ecdsa.c:(.text+0x564): undefined reference to `EC_KEY_free'
/tmp/ccIwRoTT.o: In function `aacs_group':
ecdsa.c:(.text+0x828): undefined reference to `EC_GROUP_new_curve_GFp'
ecdsa.c:(.text+0x864): undefined reference to `EC_POINT_new'
ecdsa.c:(.text+0x918): undefined reference to `EC_POINT_set_affine_coordinates_GF2m'
ecdsa.c:(.text+0x9bc): undefined reference to `EC_GROUP_set_generator'
ecdsa.c:(.text+0xa04): undefined reference to `EC_GROUP_free'
ecdsa.c:(.text+0xa20): undefined reference to `EC_POINT_free'
collect2: ld returned 1 exit status

00dwan
14th March 2007, 02:15
I couldn't get aacskeys working on ps3 linux. I had similar errors as the ones stated above.

I just tried running aacskeys from windows xp(qemu) on the ps3 and I get the "All AGIDs are in use, aborting." message. Same thing happened when I used a daemon-tools mounted iso on my normal windows xp computer.

woodspire
14th March 2007, 02:19
If someone could compile and correctly execute the iscsi-target on the ps3, we could access the blu-ray from windows with the iscsi-initiator:

iscsi-initiator: http://www.microsoft.com/downloads/details.aspx?FamilyID=12cb3c1a-15d6-4585-b385-befd1319f825&DisplayLang=en

iscsi-target: http://iscsitarget.sourceforge.net/

Watch out, I think openssl needs to be compile in ppc64.

For my part, iscsi-target compiles correctly. It's when I run it that the're an error in /var/log/messages

For all the linux guru, please help us!

lightshadow
14th March 2007, 02:55
If I run openssl, it says it's version 0.9.8a 11 october 2005
But I compiled 0.9.8e

This sounds like the openssl that ships with your distribution is located in /usr/ where your compiled is located in /usr/local

For the rpm installed openssl you can check that by
rpm -qa|grep -i openssl|xargs rpm -ql

For the openssl you compiled, try check the --PREFIX by
./configure --help
in your unpacked openssl directory, and see what the PREFIX variable is set to. Changing it to /usr will replace your rpm installed openssl.

woodspire
14th March 2007, 04:55
recompile openssl with --prefix=/usr

Now the default openssl is 0.9.8e

Remove the -I/usr/local/ssl/include part

But still same error. Check in the /usr/include/openssl/evp.h and the function EVP_ecdsa is well defined. Why can't the compiler find it ?

arnezami
14th March 2007, 07:18
Ok. It looks like ebsi has managed to compile and run aacskeys on the PS3. It looks like his Dv/Dsig values are all zero. As far as I can see he has also added a mount point variable (to make a distinction between the device file where mmc commands are send to and the mountpoint to find the MKB/UnitKey files I guess). So my source probably requires some more tweaking for linux.

Can somebody else confirm this? I wonder if Dcert is returned by the drive (don't post it we just need to know if its not all 0's).

ebsi
14th March 2007, 14:40
http://www.sendspace.com/file/d3aava
In the archive you also find a PS3 linux binary.
It's compiled on Ubuntu Edgy for PPC.
For mounting the a BD disk this patch :
http://sourceforge.net/tracker/index.php?func=detail&aid=1671912&group_id=295&atid=300295
is needed.

To use it you must mount the BD disk. For example:
mount /dev/scd0 /media/cdrom
./aacskeys /dev/scd0 /media/cdrom s

Dv, Disg, HK and BK are empty.

arnezami
14th March 2007, 19:16
http://www.sendspace.com/file/d3aava
In the archive you also find a PS3 linux binary.
It's compiled on Ubuntu Edgy for PPC.
For mounting the a BD disk this patch :
http://sourceforge.net/tracker/index.php?func=detail&aid=1671912&group_id=295&atid=300295
is needed.

To use it you must mount the BD disk. For example:
mount /dev/scd0 /media/cdrom
./aacskeys /dev/scd0 /media/cdrom s

Dv, Disg, HK and BK are empty.

Ok. I now understand that you do get the Dcert and Dn which means the mmc command are working on the PS3.

There are some things we can do to see what is the problem with retrieving the Dsig and Dv.

(1) There is an (small) error in the report key and send key command.

This is what report_key should look like:

int report_key(drive_handle h, unsigned char * buffer, char agid, char key_format, short length, unsigned char bluray) {
unsigned char cmd[CDROM_PACKET_SIZE];
memset(cmd, 0, CDROM_PACKET_SIZE);

cmd[0] = REPORT_KEY;
cmd[1] = 0;
cmd[7] = 0x02;
cmd[8] = (length>>8)&0xff;
cmd[9] = (length)&0xff;
cmd[10] = agid<<6|(key_format&0x3f);

memset(buf, 0, length);

if(send_cmd(h, cmd, buf, 0, length) >= 0)
return 0;
else
return -1;
}


This is what send_key should look like:

int send_key(drive_handle h, unsigned char *buffer, char agid, char key_format, short length, unsigned char bluray) {
unsigned char cmd[CDROM_PACKET_SIZE];
memset(cmd, 0, CDROM_PACKET_SIZE);

cmd[0] = SEND_KEY;
cmd[1] = 0;
cmd[7] = 0x02;
cmd[8] = (length>>8)&0xff;
cmd[9] = (length)&0xff;
cmd[10] = agid<<6|(key_format&0x3f);

if(send_cmd(h, cmd, buf, length, 0) >= 0)
return 0;
else
return -1;
}


The read_vid should stay the same (with the bluray var).

(2) There could be a problem with timing or the agid being invalid (after the drive cert has been recieved).

This is unlikely but we could check if the agid is still in use after retrieving the drive cert. We do this by trying to obtain an agid just after we have done the report_drive_cert_chal. If its -1 then the agid is still in use (as it should be). But if its 0 then the agid has been dropped by the drive. Alternatively we could try to wait a little before asking the drive for the Dv/Dsig (or ask many times).

(3) We should try to compile and run this program on a PC linux system.

When using either a Bluray drive or a HD DVD drive on a linux PC (not the PS3) we can see what works. If this is working (on a PC) then the PS3 hypervisor is probably giving us trouble (or the distro/processor whatever). If it doesn't work for linux PC (or maybe only bluray) then we have to solve that first.

(4) We should make sure we get better error messages

When the report_drive_key is executed it gives back all 0's. But this can be due to several reasons. We could change this function to give us a little more info on what happened (by check the resulting value of course)

int report_drive_key(drive_handle h, char agid, unsigned char *point, unsigned char *signature, unsigned char bluray) {
if(report_key(h, buf, agid, 2, 84, bluray))
return -2;

if(buf[0] != 0 || buf[1] != 0x52)
return -1;

memcpy(point, buf+4, 40);
memcpy(signature, buf+44, 40);

return 0;
}
A return value of -2 would mean that the report_key function failed (and therefore the send_cmd function). With a return value of -1 we know that the drive has actually returned something (but not something beginning with 00 52). Maybe there is also a way to get sense data from the commands send. I don't know how to do this for linux ioctl.

Of course somebody has to do some precise debugging to see where the problem lies.

(5) We should compile and try aacsauth

We have working source code (for linux) in aacsauth (http://forum.doom9.org/showthread.php?t=122969). We could use this for trying to see what works. When we add the following in the read_vid of jx6bpm's source it should work for bluray:

int read_vid(drive_handle h, char agid, char *vid, char *mac) {
char cmd[CDROM_PACKET_SIZE];
memset(cmd, 0, CDROM_PACKET_SIZE);

cmd[0] = 0xad;
cmd[1] = 1;
cmd[7] = 0x80;
cmd[8] = 0;
cmd[9] = 36;
cmd[10] = (agid<<6)&0xc0;

if(send_cmd(h, cmd, buf, 0, 36) < 0)
return -1;

memcpy(vid, buf+4, 16);
memcpy(mac, buf+20, 16);

return 0;
}

(6) We may have to fill in vendor specific information

The report key command (aswell as the other commands) say that byte 11 is somewhat vendor specific:

http://img152.imageshack.us/img152/7964/reportxd8.jpg

Currently we set this entire byte to 0. I don't know if this is a problem (since the Dcert is working it wouldn't make sense this is the reason the Dv isn't retrieved). And what is NACA, flag and link?

There is also the question if this is correct:

cmd[8] = (length>>8)&0xff;
cmd[9] = (length)&0xff;


Maybe its better to use an unsigned char for length (and only use byte 9) to avoid potential problems regarding endian encoding? Since the (allocation) length is never going to exceed 255 anyway.

We could also do a GET CONFIGURATION command and see what comes out of that.

Hopefully we will find out soon what is going on here. The fact that the PS3 is actually returning the Dcert is very positive news because it means that the mmc commands are not blocked :).

Regards,

arnezami

Electrox3d
14th March 2007, 23:45
boy am I lost now! I thought I was getting it, then whammo!

OK, so I hope this question falls into this thread:
If the program reveals all AACS Keys needed to decrypt, then how do I get the SHA1 hash? I believe that is needed to decrypt?

In the following example of the BD movie Click, I don't know how to get the 40 character string prior to the "=Click" name. I DO know how to get the 32 character string following the "|00/00/00|".

F40F9413E223031170483DEBD0495F5D64F41392=Click |00/00/00|C1F8540A04E9405FED346872CD125990
....^ I can not figure out how to get this string.................................^ I do know how to get this one. (Its just the CPS key)

So, does this program help in revealing that 40-character string?

Thanks!

woodspire
15th March 2007, 00:05
The hash is the sha1 hash of the AACS/CPUnit00001.cci file.

under linux, type: openssl sha1 CPUnit00001.cci

Under windows, down an utility to calculate sha1 hash of file

Maybe this could help: http://www.codeproject.com/cs/files/dt_file_hasher.asp

or try this: http://hashtab.beeblebrox-org.qarchive.org/

You could also have looked in the backupblurayv21.zip source. Under src/shared/utils.java, the hashFile function explain how it's done.

And the src/main/BackupBluRay.java show which file is hashed.

woodspire
15th March 2007, 00:13
Same problem has ebsi.

Can't compile right now the binary for aacskeys (openssl problem stated above) but the binary provided by ebsi is working.

Dv, Dsig, Hk and BK all zero.

Dcert not zero.

Actually, no other info are zero except the 4 above.

Get a volume Unique Key for talladega nights:

Processing key: 09F911029D74E35BD84156C5635688C0
Encrypted C-value: CBB16165DDC196FC65D0E6A0333045F5
Corresponding uv: 00000001

Decrypted C-value: 31143BED2A2E4A23A546A708267DDC7C
Media key: 31143BED2A2E4A23A546A708267DDC7D

Encrypted verification data: B385A42078219980710627B27BF7C541
Decr verif data should be: 0123456789ABCDEF
Decrypted verification data: 0123456789ABCDEF682370557C3E243C

AGID: FF

Host certificate from: Power DVD 7.1
Host certificate (Hcert): 0200005CFFFF0000000C00006E3DEB679B9A16AD
FAA8E30878767BA6EB2A9B415385AD1181B4446C
31E9A5DD2AB808B364FF15885BAC490964318C9B
F8029FCF76F688A54FBDA03F6D9332EF04E5A613
12DA85880A4D9CBB79D8602E
Host Private Key (Hpriv): 4737676058D7029452514F0AB186DC4CCA8C578F
Host Nonce (Hn): 2923BE84E16CD6AE529049F1F1BBE9EBB3A6DB3C

Drive certificate (Dcert): ########################################
########################################
########################################
########################################
########################
Drive Nonce (Dn): ########################################

Drive key point (Dv): ########################################
########################################
Drive key signature (Dsig): ########################################
########################################

Host key (Hk): 0000000000000000000000000000000000000000
Host key point (Hv): 8E9B0E3CF41FA7DA3A829F604122EA4ED5261AA4
7570CE0BB9061A66FAF92C4A7D98ACC171CBF19B
Host key signature (Hsig): ########################################
########################################

Drive signature wrong/error
Bus key (BK): ################################

Volume ID: 8E9B0E3CF41FA7DA3A829F604122EA4E
Voluem ID MAC: ################################

Volume Unique Key: 3104B2690FA032CD8849139B2D518D0F
Encrypted Unit Key 1: 819CCCE5F7FCF2C8F30FD559F0DDCA0E

Decrypted Unit Key 1: 23403F01F9FD3023ADDF2698C12E7C03


But not the correct one: 243302819492872FB60BF20BCCE28531

It's my way to check if the application is working.

Can't make the change to the source code because can't compile but can run any binary you provide, if you want to debug (woodspire@hotmail.com)

P.S. I have a strange copy of "The Prestige" that can't be decrypt with the key provided in this forum. Hopping to correct the problem and be able to provide it to everybody after testing it.

Electrox3d
15th March 2007, 00:31
The hash is the sha1 hash of the AACS/CPUnit00001.cci file.

under linux, type: openssl sha1 CPUnit00001.cci

Under windows, down an utility to calculate sha1 hash of file

Maybe this could help: http://www.codeproject.com/cs/files/dt_file_hasher.asp

or try this: http://hashtab.beeblebrox-org.qarchive.org/

You could also have looked in the backupblurayv21.zip source. Under src/shared/utils.java, the hashFile function explain how it's done.

And the src/main/BackupBluRay.java show which file is hashed.


:devil: This is the first time it was clearly put to me what needed to be done to get this Hash... The software you linked wouldn't work based on some kind of .NET security, but a program called Pinpoint Hash by Pinpoint Laboratories pulled up that exact code! I was like :eek: then :confused: then :devil:

Thanks!

arnezami
15th March 2007, 05:58
:devil: This is the first time it was clearly put to me what needed to be done to get this Hash... The software you linked wouldn't work based on some kind of .NET security, but a program called Pinpoint Hash by Pinpoint Laboratories pulled up that exact code! I was like :eek: then :confused: then :devil:

Thanks!

Yes. I this has been discussed. Firstly: the aacskeys program is in progress and it isn't finished. Earlier in this thread I said I would include the sha1 hash at some time. Secondly: KenD00 and I agreed the wrong file is currently hashed which is likely to give us duplicate values for different movies and we agreed to change it to the Unit Key file. We even discussed the file format and the possibility of the Unit Key files being the same for different movies. Its all in this thread.

Sorry for not being more clear about this. But there is a time for building and programming stuff and there is a time for explaining stuff. Usually in that order ;).

Regards,

arnezami

arnezami
15th March 2007, 06:21
Same problem has ebsi.

Can't compile right now the binary for aacskeys (openssl problem stated above) but the binary provided by ebsi is working.

Dv, Dsig, Hk and BK all zero.

Dcert not zero.

Actually, no other info are zero except the 4 above.

Get a volume Unique Key for talladega nights:

...

It's my way to check if the application is working.

Can't make the change to the source code because can't compile but can run any binary you provide, if you want to debug (woodspire@hotmail.com)

P.S. I have a strange copy of "The Prestige" that can't be decrypt with the key provided in this forum. Hopping to correct the problem and be able to provide it to everybody after testing it.
Thanks for testing. This is interesting (and stange). It actually gives back a Volume ID (although its the wrong one).

In this post (http://forum.doom9.org/showthread.php?p=953582#post953582) the Volume ID for Talladega Nights The Ballad of Ricky Bobby was posted:

7f 58 3c b4 6c 30 99 e5 c8 99 44 08 07 f7 41 4b

I'm assuming thats the same movie. But since it gives back something it may be an encrypted Volume ID (possibly some special PS3 encryption?).** Can somebody look at their Dcert and see if the drive as Bus Key capable. As I explained earlier how to see this: look for 01 00 00 5c in there. The red value is zero if the drive is not capable of bus encryption.

There is another thing we should try. I now suspect the Dv/Dsig is not empty at all its just not copied to the appropiate buffers (because it contains something strange).

In order to test this you could remove the following code from the report_drive_key function:

int report_drive_key(drive_handle h, char agid, unsigned char *point, unsigned char *signature, unsigned char bluray) {
if(report_key(h, buf, agid, 2, 84, bluray))
return -1;

if(buf[0] != 0 || buf[1] != 0x52)
return -1;

memcpy(point, buf+4, 40);
memcpy(signature, buf+44, 40);

return 0;
}


so it would look like this:

int report_drive_key(drive_handle h, char agid, unsigned char *point, unsigned char *signature, unsigned char bluray) {
if(report_key(h, buf, agid, 2, 84, bluray))
return -1;

memcpy(point, buf+4, 40);
memcpy(signature, buf+44, 40);

return 0;
}


If it then gives any data I would be very interested in what that data is. Would the first two values be close to 0x00 0x52? It wouldn't be working according to specs btw...


[edit] Ooh wait. The agid is wrong! Huh?! There is something wrong there. It should never be FF. Ah. Ok. The check has been removed by ebsi. This explains why its acting up. No agid means no go. Although it doesn't help us yet. Will try to figure out how to proceed.



arnezami

** It may be wise/healthy paranoia to remove everything from this "Volume ID" and all stuff below that (until we know what it is).

HyperHacker
15th March 2007, 06:44
FYI, "Voluem ID MAC" is spelled wrong.

arnezami
15th March 2007, 08:35
Ok. I've completely stripped aacskeys into aacstiny.

It now doesn't need openssl. So more people can compile and help us.

It doesn't do much. Its just a test program. It gives more information about what is going with the drive so please try this and report back to us (careful: it dumps buffers so I've sort of marked potential sensitive data but if you don't trust yourself just desribe what you see)

Here is part of what I see on my PC:

Sending report key command: A40000000000000200003F00
Invalidation AGID 0. Result: 0
Sending report key command: A40000000000000200007F00
Invalidation AGID 1. Result: 0
Sending report key command: A4000000000000020000BF00
Invalidation AGID 2. Result: 0
Sending report key command: A4000000000000020000FF00
Invalidation AGID 3. Result: 0
Sending report key command: A40000000000000200080000
Returning buffer from report agid command: 0006000000000000
AGID: 00

Sending send key command: A30000000000000200740100
Host certificate from: Power DVD 7.1
Host certificate (Hcert): 0200005CFFFF0000000C00006E3DEB679B9A16AD
FAA8E30878767BA6EB2A9B415385AD1181B4446C
31E9A5DD2AB808B364FF15885BAC490964318C9B
F8029FCF76F688A54FBDA03F6D9332EF04E5A613
12DA85880A4D9CBB79D8602E
Host Private Key (Hpriv): 4737676058D7029452514F0AB186DC4CCA8C578F
Host Nonce (Hn): 2923BE84E16CD6AE529049F1F1BBE9EBB3A6DB3C

Sending report key command: A40000000000000200740100
CAREFUL SENSITIVE: Returning buffer from report drive challenge command: 00720000xxxxxxx

http://rapidshare.com/files/21107374/aacstiny.rar.html

(sorry sendspace is down atm)

Instructions:

INSTALL

Compile with gcc -o aacstiny ioctl.c mmc.c aacstiny.c

There may be some warning. But hopefully it compiles for linux now (not tested yet).

USAGE

mount /dev/scd0 /media/cdrom (this may not be needed but well doesn't hurt I guess)
./aacstiny /dev/scd0 s
/dev/scd0 is the device file of your drive

Good luck :).

arnezami

PS. On a sidenote: since AACS auth is only implemented on "PC-based systems" its also possible the PS3 doesn't support it at all. If this is the case then I have no idea how the PS3 gets its volume ids. I highly doubt though this is the case.

woodspire
15th March 2007, 11:37
Can somebody look at their Dcert and see if the drive as Bus Key capable. As I explained earlier how to see this: look for 01 00 00 5c in there. The red value is zero if the drive is not capable of bus encryption.


The only '5C' is at the start of my Dcert. Here how it starts:

0200005CFFFF00 ...

So, it seems that it's not capable of bus encryption.

And it doesn't begin with '01' but with '02'.

Also, if no bus encryption is supported, isn't that a nice thing to have... no encryption ???

lightshadow
15th March 2007, 12:13
I can't compile aacstiny Linux. The latter is a bit more verbose.
~/bdownload/aacstiny$ gcc -o aacstiny ioctl.c mmc.c aacstiny.c
aacstiny.c: In function ‘main’:
aacstiny.c:245: error: ‘EXIT_SUCCESS’ undeclared (first use in this function)
aacstiny.c:245: error: (Each undeclared identifier is reported only once
aacstiny.c:245: error: for each function it appears in.)
~/bdownload/aacstiny$ gcc -Wall -O2 -o aacstiny ioctl.c mmc.c aacstiny.c
ioctl.c: In function ‘close_drive’:
ioctl.c:167: warning: implicit declaration of function ‘close’
aacstiny.c:40: warning: return type defaults to ‘int’
aacstiny.c:83: warning: return type defaults to ‘int’
aacstiny.c: In function ‘main’:
aacstiny.c:193: warning: pointer targets in passing argument 1 of ‘output_key’ differ in signedness
aacstiny.c:245: error: ‘EXIT_SUCCESS’ undeclared (first use in this function)
aacstiny.c:245: error: (Each undeclared identifier is reported only once
aacstiny.c:245: error: for each function it appears in.)
aacstiny.c:239: warning: label ‘err’ defined but not used
~/bdownload/aacstiny$

honai
15th March 2007, 17:18
The hash is the sha1 hash of the AACS/CPUnit00001.cci file.

under linux, type: openssl sha1 CPUnit00001.cci

Under windows, down an utility to calculate sha1 hash of file

Under Windows I'd recommend the HashTab shell extension:

http://www.beeblebrox.org/hashtab/

Might also come in handy for other uses, like comparing if two files are identical, or when you want to release some software on a public server.

arnezami
15th March 2007, 19:47
I can't compile aacstiny Linux. The latter is a bit more verbose.
~/bdownload/aacstiny$ gcc -o aacstiny ioctl.c mmc.c aacstiny.c
aacstiny.c: In function ‘main’:
aacstiny.c:245: error: ‘EXIT_SUCCESS’ undeclared (first use in this function)
aacstiny.c:245: error: (Each undeclared identifier is reported only once
aacstiny.c:245: error: for each function it appears in.)
~/bdownload/aacstiny$ gcc -Wall -O2 -o aacstiny ioctl.c mmc.c aacstiny.c
ioctl.c: In function ‘close_drive’:
ioctl.c:167: warning: implicit declaration of function ‘close’
aacstiny.c:40: warning: return type defaults to ‘int’
aacstiny.c:83: warning: return type defaults to ‘int’
aacstiny.c: In function ‘main’:
aacstiny.c:193: warning: pointer targets in passing argument 1 of ‘output_key’ differ in signedness
aacstiny.c:245: error: ‘EXIT_SUCCESS’ undeclared (first use in this function)
aacstiny.c:245: error: (Each undeclared identifier is reported only once
aacstiny.c:245: error: for each function it appears in.)
aacstiny.c:239: warning: label ‘err’ defined but not used
~/bdownload/aacstiny$

Just change EXIT_SUCCESS into 0 (as in zero).

Or download this one: http://www.sendspace.com/file/tutjhl

Regards,

arnezami

arnezami
15th March 2007, 19:53
Can somebody look at their Dcert and see if the drive as Bus Key capable. As I explained earlier how to see this: look for 01 00 00 5c in there. The red value is zero if the drive is not capable of bus encryption.


The only '5C' is at the start of my Dcert. Here how it starts:

0200005CFFFF00 ...

So, it seems that it's not capable of bus encryption.

And it doesn't begin with '01' but with '02'.

Also, if no bus encryption is supported, isn't that a nice thing to have... no encryption ???
Hmm. Are you absolutely sure this is the shown Dcert value and not the Hcert? Because Hcerts begin with 0200005C while Dcerts begin with 0100005C. In other words: are the Dcert and Hcert the same for you?

This could in fact be the case because the buffer isn't cleaned up between the two and the agid isn't working (so the drive doesn't overwrite the buffer with new info). This would also mean that while the Dsig looks like its filled its not filled by the drive (which would make sense if there is no agid btw)

We need to test this (agid stuff) with aacstiny (http://www.sendspace.com/file/tutjhl) first.

lightshadow
15th March 2007, 23:57
Just change EXIT_SUCCESS into 0 (as in zero).

Or download this one: http://www.sendspace.com/file/tutjhl

Thanks.

Here is a Makefile for the Linux users that features "make" "make clean" "make install".

The file must be called "Makefile" with capital 'M'.
# Top-level Makefile for aacstiny

CC = gcc

CFLAGS=-Wall -O2

.SUFFIXES: .o .c .h

OBJS = aacstiny.o ioctl.o mmc.o
EXE = aacstiny

.c.o:
$(CC) $(CFLAGS) -c $<

$(EXE): $(OBJS)
$(CC) -o $@ $(OBJS)

all: clean $(EXE)

clean:
-rm -f *.o $(EXE)

install:
cp $(EXE) /usr/local/bin


Example:
~/tr/aacstiny$ make
gcc -Wall -O2 -c aacstiny.c
aacstiny.c:40: warning: return type defaults to ‘int’
aacstiny.c:83: warning: return type defaults to ‘int’
aacstiny.c: In function ‘main’:
aacstiny.c:193: warning: pointer targets in passing argument 1 of ‘output_key’ differ in signedness
aacstiny.c:239: warning: label ‘err’ defined but not used
aacstiny.c: In function ‘output_text’:
aacstiny.c:97: warning: control reaches end of non-void function
aacstiny.c: In function ‘output_key’:
aacstiny.c:80: warning: control reaches end of non-void function
gcc -Wall -O2 -c ioctl.c
ioctl.c: In function ‘close_drive’:
ioctl.c:167: warning: implicit declaration of function ‘close’
gcc -Wall -O2 -c mmc.c
gcc -o aacstiny aacstiny.o ioctl.o mmc.o
~/tr/aacstiny$

woodspire
16th March 2007, 00:35
Hmm. Are you absolutely sure this is the shown Dcert value and not the Hcert? Because Hcerts begin with 0200005C while Dcerts begin with 0100005C. In other words: are the Dcert and Hcert the same for you?

This could in fact be the case because the buffer isn't cleaned up between the two and the agid isn't working (so the drive doesn't overwrite the buffer with new info). This would also mean that while the Dsig looks like its filled its not filled by the drive (which would make sense if there is no agid btw)

We need to test this (agid stuff) with aacstiny (http://www.sendspace.com/file/tutjhl) first.

Yes, Dcert and Hcert identical.

here is the output from aacstiny:

Sending report key command: A40000000000000200003F00
Invalidation AGID 0. Result: 0
Sending report key command: A40000000000000200007F00
Invalidation AGID 1. Result: 0
Sending report key command: A4000000000000020000BF00
Invalidation AGID 2. Result: 0
Sending report key command: A4000000000000020000FF00
Invalidation AGID 3. Result: 0
Sending report key command: A40000000000000200080000
Returning buffer from report agid command: 0000000000000000
All AGIDs in use, aborting. AGID: -1

arnezami
16th March 2007, 07:11
Yes, Dcert and Hcert identical.

here is the output from aacstiny:

Sending report key command: A40000000000000200003F00
Invalidation AGID 0. Result: 0
Sending report key command: A40000000000000200007F00
Invalidation AGID 1. Result: 0
Sending report key command: A4000000000000020000BF00
Invalidation AGID 2. Result: 0
Sending report key command: A4000000000000020000FF00
Invalidation AGID 3. Result: 0
Sending report key command: A40000000000000200080000
Returning buffer from report agid command: 0000000000000000
All AGIDs in use, aborting. AGID: -1
Ok. This looks like the PS3 is doesn't even know what to do with an AGID request. The buffer is simply not written to at all.

I'm starting to believe the PS3 does not use the AACS-auth system (or we can't use it). Which means:

1) We can go directly for an (encrypted?) Volume ID (but what to use as AGID?). Skipping the AACS auth process. This is unlikely to be that simple. But what was that Volume ID we got earlier: was that also a buffer fluke? We have to test this seperately.
2) We simply don't know how to extract a Volume ID from the PS3. And somehow have to sniff the (hardware) bus in order to see how its retrieved.
3) The hypervisor is blocking the AGID mmc command. We would have to break the hypervisor or (maybe) hack the drive firmware. Or maybe better: try to install the drive into a PC (with no hypervisor) and see if we can get the Volume ID.

Of course we could still do something wrong. But seeing the response from aacstiny above (which is really simple) I don't think we've done anything wrong here. Somebody check this please.

Can somebody test aacskeys or aacstiny on a PC linux system (HD DVD or Blu-ray). This would confirm the program is working and that its the PS3 acting up. We really need to know this for certain.

Regards,

arnezami

woodspire
16th March 2007, 07:12
Anybody tested the aacstiny apps under linux x86 or x86-64 ?

Maybe the problem of aacstiny and aacskeys is that x86 processor are little-endian and PPC are either Big-endian or Bi-endian...

http://en.wikipedia.org/wiki/Endian

Don't know if it applies but I know that we are playing with registry, memory addresses...


Edit: Esay way to test under linux x86:

- download ubuntu livecd iso
- run
- compile aacstiny
- run

Also, there is two other ways to test aacstiny:

1- user yellow dog linux under a PowerPC G5 Mac.
Problem: not lot of people got a ppc mac, with a blu-ray drive, with linux as the OS ...

2- run linux on ps3... load linux only in memory (hardware detection, shell ans aacstiny)
- disconnect the hard drive (serial ata, so hot plug)
- plug serial ata blu-ray or ide blu-ray with converter in place of the hard drive
- detect the blu-ray drive (rerun the hardware detection)
- run aacstiny

(so no need to open the ps3, so the warranty is kept)

Usefulness: maybe the hypervisor only filter the command on the blu-ray serial ata channel, and not on the harddrive
We could be able to know if the restriction is on the hypervisor or in the blu-ray firmware (because the external blu-ray will have already been tested in windows and report no problem).

If you got any other suggestion, be my guest.

awhitehead
16th March 2007, 17:03
Anybody tested the aacstiny apps under linux x86 or x86-64 ?

Maybe the problem of aacstiny and aacskeys is that x86 processor are little-endian and PPC are either Big-endian or Bi-endian...

http://en.wikipedia.org/wiki/Endian

Don't know if it applies but I know that we are playing with registry, memory addresses...


Edit: Esay way to test under linux x86:


Endinanness might be an issue if you are packing data into structures, or reading data from structures.

There is an easy way to check for host system endianness:

#include <stdio.h>
union foo
{
char p[4];
int k;
};

int main()
{
int j;
union foo bar;
printf("Bigendian platform (ie Mac OS X PPC) would return \"abcd\"\n");
printf("Littleendian platform (ie Linux x86) would return \"dcba\"\n");
printf("Your platform returned ");
bar.k = 0x61626364;
for(j=0; j<4 ; j++)
{
printf("%c",bar.p[j]);
}

printf("\n");
return 0;

}

(save the above into file, compile using gcc -o foo foo.c )

however we already do know that PlayStation uses a PowerPC based CPU that is bigendian, while PCs are littleendian.


NAME
htonl, htons, ntohl, ntohs -- convert values between host and network
byte order

LIBRARY
Standard C Library (libc, -lc)


At this popint it might make sense to sprinkle htonl() and friends liberally through the aacstiny source.

Sorry, I don't have a PS3, so most I can do is theorise.

arnezami
17th March 2007, 18:33
Anybody tested the aacstiny apps under linux x86 or x86-64 ?

Maybe the problem of aacstiny and aacskeys is that x86 processor are little-endian and PPC are either Big-endian or Bi-endian...

http://en.wikipedia.org/wiki/Endian

Don't know if it applies but I know that we are playing with registry, memory addresses...


Edit: Esay way to test under linux x86:

- download ubuntu livecd iso
- run
- compile aacstiny
- run

Also, there is two other ways to test aacstiny:

1- user yellow dog linux under a PowerPC G5 Mac.
Problem: not lot of people got a ppc mac, with a blu-ray drive, with linux as the OS ...

2- run linux on ps3... load linux only in memory (hardware detection, shell ans aacstiny)
- disconnect the hard drive (serial ata, so hot plug)
- plug serial ata blu-ray or ide blu-ray with converter in place of the hard drive
- detect the blu-ray drive (rerun the hardware detection)
- run aacstiny

(so no need to open the ps3, so the warranty is kept)

Usefulness: maybe the hypervisor only filter the command on the blu-ray serial ata channel, and not on the harddrive
We could be able to know if the restriction is on the hypervisor or in the blu-ray firmware (because the external blu-ray will have already been tested in windows and report no problem).

If you got any other suggestion, be my guest.
Some good ideas to test whats going on with the PS3. :)

We indeed need to know where exactly the problem lies.

(btw is there a live cd available with kernel 2.6.20 with udf 2.5 support?)

I have been distracted a bit by the sequence key issue/development etc. But I'm also thinking about some test programs to see whats going on regarding the PS3: making a very simple mmc commmand actually work would be confirmation we are doing something right ;).

I'm not so sure endianess playes a role anymore: the agid request command is printed above and is (and should be) the same for any system (btw: I used a simple "for loop" to print it). So I don't think this is the problem. The commands sent are according to specs. The result is not.

Sending report key command: A40000000000000200080000
Returning buffer from report agid command: 0000000000000000

But I'm not claiming to be a linux/PS3 expert ;).

arnezami

woodspire
17th March 2007, 20:47
Endinanness might be an issue if you are packing data into structures, or reading data from structures.

There is an easy way to check for host system endianness:

#include <stdio.h>
union foo
{
char p[4];
int k;
};

int main()
{
int j;
union foo bar;
printf("Bigendian platform (ie Mac OS X PPC) would return \"abcd\"\n");
printf("Littleendian platform (ie Linux x86) would return \"dcba\"\n");
printf("Your platform returned ");
bar.k = 0x61626364;
for(j=0; j<4 ; j++)
{
printf("%c",bar.p[j]);
}

printf("\n");
return 0;

}

(save the above into file, compile using gcc -o foo foo.c )

however we already do know that PlayStation uses a PowerPC based CPU that is bigendian, while PCs are littleendian.



At this popint it might make sense to sprinkle htonl() and friends liberally through the aacstiny source.

Sorry, I don't have a PS3, so most I can do is theorise.


The result was: ABCD.

So the PS3 is big endian.

arnezami
18th March 2007, 13:42
Since we are possibly dealing with the hypervisor I think this might be useful:

http://wiki.ps2dev.org/ps3:hypervisor (discussion here (http://forums.ps2dev.org/viewtopic.php?t=7859))

It deals with hypervisor commands. I guess the ioctl function we use should at some point use the hypervisor commands to access the drive. Whether this is fully implemented or whether the right commands are available (mmc stuff) is a question I cannot anwser.

But maybe somebody else can go into this more deeply. Figure out whats going on.

Btw: on this page (http://moss.csc.ncsu.edu/~mueller/cluster/ps3/doc/LinuxKernelOverview.html) you can read about the ioctl commands being blocked :

Since the BD drive is basically ATAPI device, Linux can issue ATAPI commands by ioctl. Some of ATAPI commands have been rejected by the hypervisor call because of security issues.

Just in case you were wondering why I think the hypervisor is bugging us :)

arnezami

[edit]This looks like the command we are talking about: http://wiki.ps2dev.org/ps3:hypervisor:lv1_storage_send_device_command

arnezami
18th March 2007, 14:40
Hmmm. Might this be the problem:
These hypervisor calls consist of simple straightforward methods: open, close, read, write, ioctl.Most of all methods are asynchronous, that is, methods will return immediately after call, and then the caller must wait for its completion via other method. These completions are notified by virtualized interrupts.As in: we have to do something more than just call, but wait for the interupt (or simply wait some time) and do another call and get the info we need? Anyone have any ideas on what that other call would be? Or is it simply doing it twice??

[edit]Hmmm. It seems there is a lv1_tag (- tag to identify operation?) given back by the lv1_storage_send_device_command (http://wiki.ps2dev.org/ps3:hypervisor:lv1_storage_send_device_command) which probably has to be used when using the lv1_storage_get_async_status and lv1_storage_check_async_status methods. But the latter don't give a buffer pointer so I'm starting to believe we simply might have to wait a little longer and take another look at our buffer...

arnezami
18th March 2007, 17:33
Ok. Compile and run this one on the PS3 and see what happens. If you only get a bunch of zeroes (including the last ones) then timing is unlikely to be the issue...

aacstiny (http://www.sendspace.com/file/c5yphl) (with some buffer waiting stuff)

arnezami

PS. Just for the record: you really do need kernel 2.6.20 but I guess you have that.

woodspire
19th March 2007, 04:45
Ok. Compile and run this one on the PS3 and see what happens. If you only get a bunch of zeroes (including the last ones) then timing is unlikely to be the issue...

aacstiny (http://www.sendspace.com/file/c5yphl) (with some buffer waiting stuff)

arnezami

PS. Just for the record: you really do need kernel 2.6.20 but I guess you have that.


Doesn't use kernel 2.6.20 because I can't compile it. (not lot of experience compiling linux kernel however)...

With kernel 2.6.16 with ntfs and udf 2.5 patch here are the results:


- without a blu-ray disk:

Sending report key command: A40000000000000200003F00
Invalidation AGID 0. Result: 0
Sending report key command: A40000000000000200007F00
Invalidation AGID 1. Result: 0
Sending report key command: A4000000000000020000BF00
Invalidation AGID 2. Result: 0
Sending report key command: A4000000000000020000FF00
Invalidation AGID 3. Result: 0
Sending report key command: A40000000000000200080000
Returning buffer from report agid command: 0FFD9F8000000000
0FFD9F8000000000


And the last line repeat itself until I hit ctrl-c.

With Casino royale:


Sending report key command: A40000000000000200003F00
Invalidation AGID 0. Result: 0
Sending report key command: A40000000000000200007F00
Invalidation AGID 1. Result: 0
Sending report key command: A4000000000000020000BF00
Invalidation AGID 2. Result: 0
Sending report key command: A4000000000000020000FF00
Invalidation AGID 3. Result: 0
Sending report key command: A40000000000000200080000
Returning buffer from report agid command: 0000000000000000
0000000000000000


And the last line repeat itself also. Maybe the 2.6.20 kernel will return something different. If someone has been able to compile it, even without the udf 2.5 patch, please post a detail procedure, so I can redo the test.

arnezami
19th March 2007, 07:30
Ok. Has anybody been able to run any program released here with the 2.6.20 kernel on the PS3? The 2.6.20 enables PS3 support (including some hypervisor stuff). I don't think all that is in the udf patch alone. So until somebody is capable of compiling the (important parts of the) kernel I don't think its useful to go on trying and testing programs with the PS3. Although I'm really not sure (this is not my thing).

What needs to be done (not by me) is this: somebody with a PS3 and some programming/linux experience should make sure at least one ioctl command works properly on the PS3. Until then I'm going to concentrate on something else.

arnezami

@woodspire: please don't use ctrl-c. It will stop after 200 tries and will give a little bit more info after that. The non-zero value with tray no disc is interesting though (although probably trash). Please let it run longer too.

woodspire
19th March 2007, 23:43
First of all, I read somewhere that kernel 2.6.20 cannot boot yet on the PS3.

The only kernel that I can use are provided by YDL because they contain sony patches. (kernel 2.6.16 and 2.6.17)

I was able to compile the 2.6.17 kernel but it didn't boot up the PS3.

With the kernel 2.6.16, I was able to recompile it with the udf 2.5 patch and it can boot.

Secondly, I did 6 test with the accstiny program.

2th and 6th were without a disk.
All the other tests were with a disk (casino royale)
results:

1-
Sending report key command: A40000000000000200003F00
Invalidation AGID 0. Result: 0
Sending report key command: A40000000000000200007F00
Invalidation AGID 1. Result: 0
Sending report key command: A4000000000000020000BF00
Invalidation AGID 2. Result: 0
Sending report key command: A4000000000000020000FF00
Invalidation AGID 3. Result: 0
Sending report key command: A40000000000000200080000
Returning buffer from report agid command: 0FF6F2400FEC0F40
0FF6F2400FEC0F40
...
All AGIDs in use, aborting. AGID: -1


2-
Sending report key command: A40000000000000200003F00
Invalidation AGID 0. Result: 0
Sending report key command: A40000000000000200007F00
Invalidation AGID 1. Result: 0
Sending report key command: A4000000000000020000BF00
Invalidation AGID 2. Result: 0
Sending report key command: A4000000000000020000FF00
Invalidation AGID 3. Result: 0
Sending report key command: A40000000000000200080000
Returning buffer from report agid command: 100F507000000000
100F507000000000
...
All AGIDs in use, aborting. AGID: -1


3-
Sending report key command: A40000000000000200003F00
Invalidation AGID 0. Result: 0
Sending report key command: A40000000000000200007F00
Invalidation AGID 1. Result: 0
Sending report key command: A4000000000000020000BF00
Invalidation AGID 2. Result: 0
Sending report key command: A4000000000000020000FF00
Invalidation AGID 3. Result: 0
Sending report key command: A40000000000000200080000
Returning buffer from report agid command: 0000000000000000
0000000000000000
...
All AGIDs in use, aborting. AGID: -1

4-
Sending report key command: A40000000000000200003F00
Invalidation AGID 0. Result: 0
Sending report key command: A40000000000000200007F00
Invalidation AGID 1. Result: 0
Sending report key command: A4000000000000020000BF00
Invalidation AGID 2. Result: 0
Sending report key command: A4000000000000020000FF00
Invalidation AGID 3. Result: 0
Sending report key command: A40000000000000200080000
Returning buffer from report agid command: 0FF6F2400FEC0F40
0FF6F2400FEC0F40
...
All AGIDs in use, aborting. AGID: -1

5-
Sending report key command: A40000000000000200003F00
Invalidation AGID 0. Result: 0
Sending report key command: A40000000000000200007F00
Invalidation AGID 1. Result: 0
Sending report key command: A4000000000000020000BF00
Invalidation AGID 2. Result: 0
Sending report key command: A4000000000000020000FF00
Invalidation AGID 3. Result: 0
Sending report key command: A40000000000000200080000
Returning buffer from report agid command: 100F507000000000
100F507000000000
...
All AGIDs in use, aborting. AGID: -1

6-
Sending report key command: A40000000000000200003F00
Invalidation AGID 0. Result: 0
Sending report key command: A40000000000000200007F00
Invalidation AGID 1. Result: 0
Sending report key command: A4000000000000020000BF00
Invalidation AGID 2. Result: 0
Sending report key command: A4000000000000020000FF00
Invalidation AGID 3. Result: 0
Sending report key command: A40000000000000200080000
Returning buffer from report agid command: 0FFD9F8000000000
0FFD9F8000000000
...
All AGIDs in use, aborting. AGID: -1

Has you can see, the results are strange. Doesn't seems to be working.

Also, The PS3 boots with kboot. After this boot, we can select the kernel we want to run.

Maybe we should run a "sony patch free" kernel just to check. (anybody been able to boot kernel 2.6.20 on a PS3 ?)

Kboot is provided in a 25 meg zip file by sony.
I have never see a linux install process on the PS3 without it but I'm pretty sure that on any normal PC, either grub or lilo are used, not kboot.

arnezami
20th March 2007, 00:14
Slightly improved version. It now properly cleans the buffer before sending it to the drive:

http://www.sendspace.com/file/e8uo8w

woodspire
20th March 2007, 04:04
Slightly improved version. It now properly cleans the buffer before sending it to the drive:

http://www.sendspace.com/file/e8uo8w

Same inconsistent results.

PepsiLee2001
26th March 2007, 16:51
Dear arnezami,

I got a BDAV blu-ray disc (not BDMV) with AACS protection.

But the file structure of the disc is different from BDMV.

The file structure is shown as below (three files only)

X:\AACS\MKB_RW.info

X:\AACS\AACS_av\CPSUnit00001.cci
X:\AACS\AACS_av\Unit_Key.RW.inf

Is possible the next version of aacskey.exe can get CPSUnitkey for BDAV disc?

PepsiLee2001
27th March 2007, 07:45
Dear All,

I try to complie aacskey.exe, but some errors was happened.

error message:

ioctl.c:8:25: my_ntddscsi.h: No such file or directory
ioctl.c:9:17: sam.h: No such file or directory

ioctl.c:12: parse error before "sptd_sb"
ioctl.c:12: warning: data definition has no type or storage class
ioctl.c: In function `send_cmd':
ioctl.c:95: request for member `sptd' in something not a structure or union
ioctl.c:95: `SCSI_PASS_THROUGH_DIRECT' undeclared (first use in this function)
ioctl.c:95: (Each undeclared identifier is reported only once
ioctl.c:95: for each function it appears in.)
ioctl.c:96: request for member `sptd' in something not a structure or union
ioctl.c:97: request for member `sptd' in something not a structure or union
ioctl.c:98: request for member `sptd' in something not a structure or union
ioctl.c:99: request for member `sptd' in something not a structure or union
ioctl.c:100: request for member `sptd' in something not a structure or union
ioctl.c:100: `MAX_SENSE_LEN' undeclared (first use in this function)
ioctl.c:103: request for member `sptd' in something not a structure or union
ioctl.c:103: `SCSI_IOCTL_DATA_OUT' undeclared (first use in this function)
ioctl.c:104: request for member `sptd' in something not a structure or union
ioctl.c:106: request for member `sptd' in something not a structure or union
ioctl.c:106: `SCSI_IOCTL_DATA_IN' undeclared (first use in this function)
ioctl.c:107: request for member `sptd' in something not a structure or union
ioctl.c:110: request for member `sptd' in something not a structure or union
ioctl.c:110: `SCSI_IOCTL_DATA_UNSPECIFIED' undeclared (first use in this function)
ioctl.c:111: request for member `sptd' in something not a structure or union
ioctl.c:114: request for member `sptd' in something not a structure or union
ioctl.c:115: request for member `sptd' in something not a structure or union
ioctl.c:116: request for member `sptd' in something not a structure or union
ioctl.c:119: request for member `sptd' in something not a structure or union
ioctl.c:121: request for member `SenseBuf' in something not a structure or union
ioctl.c:125: `IOCTL_SCSI_PASS_THROUGH_DIRECT' undeclared (first use in this function)


where can I get the files(my_ntddscsi.h and sam.h)?

arnezami
27th March 2007, 17:20
Dear All,

I try to complie aacskey.exe, but some errors was happened.

error message:


where can I get the files(my_ntddscsi.h and sam.h)?

Sorry. My bad. In the post I first released the source (http://forum.doom9.org/showthread.php?p=969481#post969481) the extra three .h files (you need for compiling under windows) were still in the rar. So you can take my_ntddscsi.h, sam.h and spc.h from this old rar ;)

Later on I want to release the source properly. Including new features and compatabilities.

BTW: PepsiLee2001 and I just checked whether the Processing Key works for an encrypted BDAV disc: it does :D. So we can already get the Media Key...

arnezami

dirio49
28th March 2007, 03:22
Later on I want to release the source properly. Including new features and compatabilities.
arnezami

Thank you :)

mb2696
29th March 2007, 04:58
what does it mean if the volume id is reported as a string of zeroes? i've been having trouble getting "National Geographic - Relentless Enemies" to work.

any ideas?

thanks

arnezami
29th March 2007, 05:44
what does it mean if the volume id is reported as a string of zeroes? i've been having trouble getting "National Geographic - Relentless Enemies" to work.

any ideas?

thanks

Is it a BD or HD DVD?
What drive do you have?
What operating system?
Are other discs (still) working? Or do you only have one?
Do you get a Media Key and is the decr verif ok?
Do you get a Dcert (in sensitive mode)?
Have you tried any of the vuk keyfinder programs?
Have you tried sniffing the volume id?

A screenshot/copy-paste using the program in verbose mode would also be helpful.

arnezami

mb2696
29th March 2007, 13:32
it is an hd dvd, xbox 360 addon, win xp pro. other discs are working.

when i try to play the disc directly in powerdvd 7.1, it goes into file mode and plays the evo files in sequence. I get no error about system compliance, despite having DVI w/o HDCP (normally get an error). it is only black video and no audio however. eventually it frezees (doens't crash, just locks up).

anydvd hd is also unable to allow playback and reports the disc as NOT AACS protected.

below is the verbose output of aacskeys for this disc.

Processing key: 09F911029D74E35BD84156C5635688C0
Encrypted C-value: C990975CBD4ADDB666DD661AFE0A1FAC
Corresponding uv: 00000001

Decrypted C-value: A0BC2B16A2AD64D1A3C20FAE26681C0B
Media key: A0BC2B16A2AD64D1A3C20FAE26681C0A

Encrypted verification data: B87D991B8B5E6CF11273D29EB3F5784B
Decr verif data should be: 0123456789ABCDEF
Decrypted verification data: 0123456789ABCDEFD904126F3088DD12

AGID: 00

Host certificate from: Power DVD 7.1
Host certificate (Hcert): 0200005CFFFF0000000C00006E3DEB679B9A16AD
FAA8E30878767BA6EB2A9B415385AD1181B4446C
31E9A5DD2AB808B364FF15885BAC490964318C9B
F8029FCF76F688A54FBDA03F6D9332EF04E5A613
12DA85880A4D9CBB79D8602E
Host Private Key (Hpriv): 4737676058D7029452514F0AB186DC4CCA8C578F
Host Nonce (Hn): 2923BE84E16CD6AE529049F1F1BBE9EBB3A6DB3C

Drive certificate (Dcert): ########################################
########################################
########################################
########################################
########################
Drive Nonce (Dn): ########################################

Drive key point (Dv): ########################################
########################################
Drive key signature (Dsig): ########################################
########################################

Host key (Hk): 0000000000000000000000000000000000000000
Host key point (Hv): 8E9B0E3CF41FA7DA3A829F604122EA4ED5261AA4
7570CE0BB9061A66FAF92C4A7D98ACC171CBF19B
Host key signature (Hsig): ########################################
########################################

Drive signature wrong/error
Bus key (BK): ################################

Volume ID: 00000000000000000000000000000000
Voluem ID MAC: ################################

Volume Unique Key: DF467CB369CCBC93D6792BED0098E966
Title Key File MAC: 6E11DD594198CF674FBE74B9664EE80F

Encrypted Title Key 1: DE6785635AF17AE449571F763937684F
Encrypted Title Key 2: 853D0D63B9BD4990814009CAC2C9BCC4
Encrypted Title Key 3: 067BEE3D57983E426D2F0FF1FDE74DF9
Encrypted Title Key 4: 4891A8FEA46663CBAAFD2C23C99C9225
Encrypted Title Key 5: 2D7B7F1CA6F7D37D69AD8C496AD47A38
Encrypted Title Key 6: A009ADFCDC5989747B4C8BF28E69AC79
Encrypted Title Key 7: AAD29F9598BD98812BA3FCC6181A93F5
Encrypted Title Key 8: B6402AD20F5028BBDBC681EDF2DF28D5
Encrypted Title Key 9: 62F94819A15A8D4D37DCAA0FFC62EF12
Encrypted Title Key 10: 59ABE1644D98ED1E334094E1D826C18C
Encrypted Title Key 11: B98F04EA86D87701D07A3326374AC793
Encrypted Title Key 12: 964A86CC899551F8138C5920ED9052E4
Encrypted Title Key 13: 0823DC62F0B707D1B4DA1574ECECCA2D
Encrypted Title Key 14: 4494BC773EABC6468175905FD7DE1481
Encrypted Title Key 15: 0DD6DB058BD26DF882168BAEE60D187E
Encrypted Title Key 16: 5F19D4CF2A464ED428832291D44BE38F
Encrypted Title Key 17: E614648A79686D557814910F8B0F920C
Encrypted Title Key 18: 737D94F443D1953DD4EAB4D23DBFB497
Encrypted Title Key 19: 8924F90DBBCA432CFD67215D222BB016
Encrypted Title Key 20: 12685674EF40155416D5A4B944644664
Encrypted Title Key 21: FE36FFB973DC916A55FDF7962083C5C8
Encrypted Title Key 22: 04B3B15B96AAEB8ED837C77C9D9C159F
Encrypted Title Key 23: D29FD7212E78B144E38E1D5563B8FD04
Encrypted Title Key 24: 4B6FA66D8A4CD64CA7E85EF37F871405
Encrypted Title Key 25: 5E5E430478DCCB60A58E9AEC11D3996E
Encrypted Title Key 26: A4770F6477551BF428EB2691DE4D323D
Encrypted Title Key 27: F91905AB75F121470AEF780FA26FD2F2
Encrypted Title Key 28: 4E7D7D69C2E0BE12B0845CA16BCF0A09
Encrypted Title Key 29: 006B89CDF5A7955A38DB8D27163B0A14
Encrypted Title Key 30: ECC3BF960ECA00A37F3EB574A2879C43
Encrypted Title Key 31: AEBCA11C64856AB841AC6C948CBCF348
Encrypted Title Key 32: 8E2AA7BF0C908DAA121CFAFB81F76358
Encrypted Title Key 33: AB91207C4915A9EBDFBC1E8AE7CDBFFB
Encrypted Title Key 34: 8CBE0199CB8A826145B962DEAB65727D
Encrypted Title Key 35: 31C27F2C84D4E54E834BC7F9C27FF766
Encrypted Title Key 36: 939DB5093D5256B372B1FF8882D7A991
Encrypted Title Key 37: 900C2E111807C8C363B20A7F02D3103C
Encrypted Title Key 38: FF3715A4C288505034D1B423251C539F
Encrypted Title Key 39: 320A49E010897E2A13DE4EFC23553877
Encrypted Title Key 40: 78E5939F220D37F4FF2D5CAC529D3BF1
Encrypted Title Key 41: 12E7CD9E71284D36324B70FDC63BEB96
Encrypted Title Key 42: 652C70408C93D766950FD88444088B2D
Encrypted Title Key 43: 46B20498D6B3B61066B93D07EA47D7FC
Encrypted Title Key 44: 5FEC3D236700190DCD7B9A3CBF2EECCB
Encrypted Title Key 45: C5C8B3C739BD57E1DC6AC86C09A41395
Encrypted Title Key 46: A64BCE20A6078988828B4D901BF47E1F
Encrypted Title Key 47: 31D8DDC4C8F43620B73BCC005D668D9F
Encrypted Title Key 48: C3471E12EDA8B2E0D69FC3BB9F9A5D90
Encrypted Title Key 49: 99525C1EEE31123BF1A5C50C03512D14
Encrypted Title Key 50: 2194F56FC616A9807534DDFF802B600A
Encrypted Title Key 51: 48CDCD7C390D7D28F77A00CBC0527CE7
Encrypted Title Key 52: 912233A518C7C002CEE0105A0CD84CF3
Encrypted Title Key 53: 91322B3E8B6F031185BDD64E92B759F8
Encrypted Title Key 54: C1803CDD727E626491A666FC03A4067B
Encrypted Title Key 55: D2604E141DE6BEDE1486659243B00506
Encrypted Title Key 56: 37FB50CB9AC163F6D529CE5051B315E8
Encrypted Title Key 57: D3881422187B9E2D9B5F3CBB999241F1
Encrypted Title Key 58: 7A3D46993C90F86621CD341FD6E19092
Encrypted Title Key 59: D499AB49241EF4D8785D168BC3D07374
Encrypted Title Key 60: 5CF021DF6B7A7B272CF6BED1584094B6
Encrypted Title Key 61: 52ED5C5A71557A2EDACFCE35A370F9B6
Encrypted Title Key 62: 7E4A9004DCEC9CFE5A5F68E4C7BF3A7F
Encrypted Title Key 63: 926AAB3E041408F67D6C1999AAC2498A
Encrypted Title Key 64: 5384523CCFD947C0D736913335A41858

Decrypted Title Key 1: DE5E4DB4B7365B7CFD91107FECC3D54A
Decrypted Title Key 2: 3EFF30EB5D509F7C44BE60C1C27E1E72
Decrypted Title Key 3: C1471F2BFA77F714D134D1E35893577E
Decrypted Title Key 4: CBE9384603931E1E5F462B0A2183C8F5
Decrypted Title Key 5: 12193E2D72EBF288C49C4F6646AE62E4
Decrypted Title Key 6: 5453B697EB25A7EFADC42D9DCF7F73D8
Decrypted Title Key 7: 31405D51FE8961FBFBC69E94447E3BDF
Decrypted Title Key 8: B206367595727DE08CDA953F5B7966AC
Decrypted Title Key 9: 7099AB7C4D4D990F7D591E4166982F9E
Decrypted Title Key 10: 0A8D1F30E159231EF6CB7122AD628F3F
Decrypted Title Key 11: 400E59ED5B89ECAE4AA4197CF6857512
Decrypted Title Key 12: 84349904F473A88C4C5B5F61490439D1
Decrypted Title Key 13: 4F123A0754FB0AD1D63DE8ED1AA82BF8
Decrypted Title Key 14: 80029EF555C975713E5CC8B0A3868D33
Decrypted Title Key 15: 51FC3529176E79CEE4C74CECA09A07F9
Decrypted Title Key 16: B2B8A7F2E3DEFA0FDEC84642AD893290
Decrypted Title Key 17: DBB7516E551F78DDF554659D37281FC8
Decrypted Title Key 18: 2CDBFD80C54FD887B7EFDB98CBCD4CBE
Decrypted Title Key 19: 2177CDE40DEE61129EA12FD54243A6B6
Decrypted Title Key 20: 6C6633AFA44320321ABA8D770E259722
Decrypted Title Key 21: 1124310E7C2C871B0E4C3C2DDF75ECF5
Decrypted Title Key 22: 862818A2915A8E540C086AE6D70D5DFF
Decrypted Title Key 23: E60C4F2E0C8E2E17172EA58A6B4162BD
Decrypted Title Key 24: 6C9EF06F097A1860639F9CF67E744ED3
Decrypted Title Key 25: 666F2D6F9CACD4E8048C8B49CEE4D60F
Decrypted Title Key 26: 13DB98AD715160D50BB1630E1FE89D04
Decrypted Title Key 27: F241BC19E54FDE26D747AC749F122424
Decrypted Title Key 28: C8F699ACAD06B72D8FAA6A46D2F0E6D4
Decrypted Title Key 29: 22FAF62B92C3B097D1BC0C27F215F5BF
Decrypted Title Key 30: 28843CFB1B949AA7277BE3E5749A799A
Decrypted Title Key 31: 1FC715148F71B37D5F3D4DC8727172DF
Decrypted Title Key 32: 83E2A13D2F8198A23AA93E3ED644446A
Decrypted Title Key 33: 5E53A9C2BE85FA02965810833B1C9DBC
Decrypted Title Key 34: DE3F36220642162B321292E51CC5EE8D
Decrypted Title Key 35: FF0DFC1F529572F6FD5C3775A90C4810
Decrypted Title Key 36: E37B6BEF8883EE30131DD7E64F306A8E
Decrypted Title Key 37: 0737C851B2358E157A1C8C664F3D7A05
Decrypted Title Key 38: 35A772F991B84DCD0DDFAECA0D2FF9B8
Decrypted Title Key 39: D718824549DA46144DC015D16FB43A89
Decrypted Title Key 40: A009CC503749A69F0295657C831E1A62
Decrypted Title Key 41: 63B0072B377303237A66011A93A90EA7
Decrypted Title Key 42: CF1201B14B3CA0CE33AF640B5D8BD82E
Decrypted Title Key 43: 85E693F3BC809AA9B3B9018AEA88E926
Decrypted Title Key 44: 43FDE24CFC9A1F997D55A90EBCF7BC22
Decrypted Title Key 45: E4A3A04555291F3D03AC9304DF063B12
Decrypted Title Key 46: B761955930A726F44D556D7C8B80E999
Decrypted Title Key 47: 28B8A94901440D6465233993ACF5379A
Decrypted Title Key 48: 2D6889616F041831732B3B5521000D6D
Decrypted Title Key 49: 48E0498B6264AE80098DAE292C1A9AE9
Decrypted Title Key 50: 89E2B5BC8C2D08F69BDC0C359DB92258
Decrypted Title Key 51: F83036CB4E28D4BB1244D1A6CB141EB3
Decrypted Title Key 52: F43281CFCD726738D793B1B13CBED822
Decrypted Title Key 53: 22433445DC3B4591DE12C789073DF379
Decrypted Title Key 54: 5DB6F0B0A3E55A97F42E58A74B88B767
Decrypted Title Key 55: B8AD884889124A8EE386644410AB42BA
Decrypted Title Key 56: 5711C77BCBFB7F08B414DF23B066083B
Decrypted Title Key 57: 89F4A2EA4F836DE4CA448600D6A07CE1
Decrypted Title Key 58: 910AEF1F7FCBDD97B3BC1613FDA828E7
Decrypted Title Key 59: A934E626EDE578F2BD216564E25A07A3
Decrypted Title Key 60: E0C8ED9E39802EEE779BF6035FF2C209
Decrypted Title Key 61: A760D11F6AED68E3A392760626CF66EA
Decrypted Title Key 62: D963E8BF655DD550AA06FEB9E5F18092
Decrypted Title Key 63: 0D2E8E0B142C13B79121A786BB139CCC
Decrypted Title Key 64: 664BE38CC25FBA5CAA58D9C9FC0F15BC

arcsyn
29th March 2007, 21:44
Forgive me for being an idiot, but will this tool still work if there is a new set of AACS keys coming out next much?

Will this tool still give us the information needed to make backups, or does this program rely on something they can revoke?

dirio49
30th March 2007, 02:21
I think if they change the key, then a new version of the tool will have to be compiled with the new keys. But first we have to find the new key ;)

SBeaver
30th March 2007, 20:14
I think if they change the key, then a new version of the tool will have to be compiled with the new keys. But first we have to find the new key ;)

It would probably be best to keep this key secret until all the delayed releases start flowing, otherwise they will just change it again.
I'm guessing all software players to date will be pulled and they will force upgrades on everyone, or at least a patch that makes them more secure.
I believe it's all the better that they get this change out ASAP so that they rush it and hopefully make mistakes.
Change the keys, gives us BD+, do it all.
Then they have played all their cards and have nothing left to fall back on.

mb2696
30th March 2007, 21:36
so is this a result of a key revoke?

Fahzuu
30th March 2007, 23:46
when i try to play the disc directly in powerdvd 7.1, it goes into file mode and plays the evo files in sequence. I get no error about system compliance, despite having DVI w/o HDCP (normally get an error). it is only black video and no audio however. eventually it frezees (doens't crash, just locks up).

anydvd hd is also unable to allow playback and reports the disc as NOT AACS protected.

I have a similar effect with another disc - checked the communication over the bus, the drive in fact reports the disc to be not AACS protected, even though it is.
Probably a mastering error and that's why PowerDVD is unable to decrypt - because it doesn't even try, it just blindly plays the encrypted video data...

mb2696
30th March 2007, 23:51
I have a similar effect with another disc - checked the communication over the bus, the drive in fact reports the disc to be not AACS protected, even though it is.
Probably a mastering error and that's why PowerDVD is unable to decrypt - because it doesn't even try, it just blindly plays the encrypted video data...

hmmm...others are able to play it on standalone players. if it's a mastering error wouldn't it affect all discs?

arnezami
31st March 2007, 08:05
For mb2696.

These questions aren't answered yet:

Do you get a Dcert (in sensitive mode)?
Have you tried any of the vuk keyfinder programs?
Have you tried sniffing the volume id?

Other questions:

- What MKB version is on it? My MKBROM starts with 1000000C000410030000000121000034 (using WinHex). Meaning my MKB version is 1 and the length of the HRL is 34h. If any of this is different then its important.
- Does it play with any software player on any other PC system? Does your disc (not similar discs) work on standalones? Do similar discs (same title) work on your PC?
- Have you tried to demux the files to see if it contains streams or whatever? Using the original files on the disc.
- Are you absolutely sure your other discs/movies are still working? And does aacskeys give volume ids for these movies?
- Is it by any chance a recordable? Be sure.

hmmm...others are able to play it on standalone players. if it's a mastering error wouldn't it affect all discs?

What do you mean by "it"? Your disc or a similar disc? It is possible your disc is damaged/badly pressed somehow so the volume id cannot be retrieved. In that case if we can find somebody with the same title then he could retrieve the VUK and you might be able to decrypt it. Alternatively we could quess the volume id (tricky but maybe possible :)).

The strange thing is there is a "Drive signature wrong/error" in your report. This means the drive either doesn't see the need for AACS-Auth (as in: its a recordable or non-encrypted/damaged disc) or it has revoked the Hcert (of PowerDVD 7.1). But if it has revoked it then other discs shouldn't work either anymore. Unless your drive "forgets" it (which strangely would in itself be great).

Anyway. Something doesn't seem to add up here ;).

[edit] Just had an idea. Use KenD00's dumpvid (http://forum.doom9.org/attachment.php?attachmentid=6824&d=1171837753) (the exe is in the Release dir). It will dump the bca (Burst Cutting Area) of the disc and this should reveal half of the Volume ID :D. (you don't have to do the hammering stuff btw). We will know much more when we have that.

Regards,

arnezami

PS. A Dcert starts with 01. If not then its garbadge data.
PPS. There is another possibility: they didn't want this title to be playable on a PC. Hmmm.....

arnezami
31st March 2007, 08:06
I have a similar effect with another disc - checked the communication over the bus, the drive in fact reports the disc to be not AACS protected, even though it is.
Probably a mastering error and that's why PowerDVD is unable to decrypt - because it doesn't even try, it just blindly plays the encrypted video data...

Which movie? Release date? How did you see it was not being identified as AACS protected using the bus?

Jedi_Vader20
1st April 2007, 08:28
Running Yellow Dog 5.0 PS3 on my PAL PlayStation3, Firmware 1.60.

Under both kernel 2.6.16 and the same with the UDF 2.50 patch, I get the following output when attempting to run the most recent posted aacstiny in the thread:

[root@playstation3 aacstiny]# ./aacstiny /dev/cdrom
Sending report key command: A40000000000000200003F00
Invalidation AGID 0. Result: 0
Sending report key command: A40000000000000200007F00
Invalidation AGID 1. Result: 0
Sending report key command: A4000000000000020000BF00
Invalidation AGID 2. Result: 0
Sending report key command: A4000000000000020000FF00
Invalidation AGID 3. Result: 0
Sending report key command: A40000000000000200080000
Returning buffer from report agid command: 0FF6F2400FEC0F40
All AGIDs in use, aborting. AGID: -1


aacstiny compiled with no warnings or errors. The movie I'm attempting this against is xXx, PAL release Blu-Ray.

Boing99
1st April 2007, 21:53
I ran some very similar tests on my PS3 a few weeks ago and can comment on some of the results posted here.

First some preliminaries:

2.6.16 is the correct kernel to use, as it contains Sony's own drivers and modifications. 2.6.20 is an (incomplete) effort by the regular kernel maintainers to merge those changes back into the regular kernel source tree and integrate them with existing drivers. That effort is still work in progress and the kernel does not boot on PS3 yet.

The UDF-2.5 patch is completely unrelated to any PS3 changes or drivers and not needed if all you want to do is send SCSI commands to the drive (to extract volume ids etc.). It IS needed if you want to mount a Blu-ray volume to get access to the files on it, for decryption. Without the patch you can simply send SCSI commands directly to the underlying device. For most setups (including PS3) that is "/dev/sr0".

Now about my actual tests, run on Gentoo (not YDL), using a 64-bit kernel and userland:

I used SG_IO instead of CDROM_SEND_PACKET in the ioctl. I am not sure this made a difference, but it seems to me that SG_IO is a lower-level request closer to the ATAPI layer, with better diagnostics and it may arguably have a better chance of not having its data modified or misinterpreted by the CD-ROM driver layer.

The first thing I tried is sending ordinary SCSI commands to the drive to ensure that the ATAPI transport through the Hypervisor works correctly. INQUIRY works fine and returns meaningful results, as does GET_CONFIGURATION, so we know the ATAPI layer works. This also very likely rules out any problems regarding sync vs. async I/O, timing, buffer management, Hypervisor API access etc.

Interesting info here: The "Vendor info" and "Identification" fields in INQUIRY return "PS-SYSTEM <serial number>". I think this is fairly unusual because typically, even for standalones, those fields report the OEM manufacturer of the drive. For example the X-Box-360 HD drive simply returns "TOSHIBA <something>". I might have expected "SONY" here, but not "PS-SYSTEM". The "PS-SYSTEM" response to me suggests that either Sony used a special drive built in-house exclusively for the PS3, without any intent to ever use it in standalone Blu-ray players (probably unlikely), or that the Hypervisor intercepted INQUIRY and responded on behalf of the drive. If it is the latter then it's bad news because it would suggest that the Hypervisor does filter SCSI commands one by one, which would explain the problems with AACS commands.

Next I tried the usual AACS SCSI commands, and all of them returned driver_status=7 (hard error) and sense_key=5 (ILLEGAL_REQUEST). That seemed strange to me at first (the part about this being reported in driver_status instead of host_status), because the driver is supposed to handle different SCSI commands transparently. The explanation is in the Sony driver in the kernel sources. ps3pf_storage.c contains a table of supported SCSI commands, and maps them to Hypervisor calls. Except for REQUEST_SENSE, READ and WRITE, which have their own handling, probably for optimization purposes, all other listed commands are forwarded to the same single Hypervisor call. Commands not in the table generate the above-mentioned error. Of course AACS commands were not in the list...

So I added A3, A4 and AD to the list and in the process noticed that the PS3 ATAPI layer does not support 12-byte SCSI commands, only 6-byte, 10-byte and CDDA-FRAME-RAW, so I ended up adding support for 12-byte commands, too, since that is the format of AACS commands. Three small changes and a kernel recompilation and reboot later...

The AACS commands still fail: now driver_status is 0 (ok), but host_status=7 (error) and, strangely enough, I get a zero-ed out sense buffer.

I am not sure what to make of this. The empty sense buffer seems strange and suggests that the problem is probably not with the drive, but more likely either with using 12-byte SCSI commands through the Hypervisor (which it might not support) or with the Hypervisor blocking the request explicitly and not even bothering to set its sense buffer properly. Add to that the fact that REQUEST_SENSE is treated differently in the driver than other commands (which may well account for the empty sense buffer here), and this whole problem more and more looks like a Hypervisor issue to me -- meaning, the Hypervisor probably blocks these requests intentionally, without any chance to bypass this in a Linux kernel.

The next step would be to add diagnostic code in the driver around the Hypervisor calls to try and get more meaningful error codes out of the Hypervisor than just an empty sense buffer, and to log them... I probably won't have the time to dig into this deeper any time soon though.

arnezami
1st April 2007, 22:16
Very much thanks Boing99. Thats quite enlightning information. Thats worth an awful lot :).

It seems now though (more likely than ever) that a Hypervisor hack is needed to ever retrieve Volume IDs from a PS3. :(

arnezami

dito
2nd April 2007, 00:26
IBM Cell BE Software Development Kit 2.1 is out with Linux kernel to 2.6.20, http://www6.software.ibm.com/sdfdl/1v2/regs2/awadmin/cellsw/Xa.2/Xb.bCxnaYZiaXdlJSEfHwej7ZthLvSZss8BC7HE_Sc/Xc.CellSDK21.iso/Xd./Xf.Ltr./Xg.3819903/Xi.cellsw/XY.regsrvs/XZ.uwvNY90x6fvw1vHmT0-h0agjD5I/CellSDK21.iso

Best regards!

mb2696
2nd April 2007, 04:41
For mb2696.

These questions aren't answered yet:


Other questions:

- What MKB version is on it? My MKBROM starts with 1000000C000410030000000121000034 (using WinHex). Meaning my MKB version is 1 and the length of the HRL is 34h. If any of this is different then its important.
- Does it play with any software player on any other PC system? Does your disc (not similar discs) work on standalones? Do similar discs (same title) work on your PC?
- Have you tried to demux the files to see if it contains streams or whatever? Using the original files on the disc.
- Are you absolutely sure your other discs/movies are still working? And does aacskeys give volume ids for these movies?
- Is it by any chance a recordable? Be sure.



What do you mean by "it"? Your disc or a similar disc? It is possible your disc is damaged/badly pressed somehow so the volume id cannot be retrieved. In that case if we can find somebody with the same title then he could retrieve the VUK and you might be able to decrypt it. Alternatively we could quess the volume id (tricky but maybe possible :)).

The strange thing is there is a "Drive signature wrong/error" in your report. This means the drive either doesn't see the need for AACS-Auth (as in: its a recordable or non-encrypted/damaged disc) or it has revoked the Hcert (of PowerDVD 7.1). But if it has revoked it then other discs shouldn't work either anymore. Unless your drive "forgets" it (which strangely would in itself be great).

Anyway. Something doesn't seem to add up here ;).

[edit] Just had an idea. Use KenD00's dumpvid (http://forum.doom9.org/attachment.php?attachmentid=6824&d=1171837753) (the exe is in the Release dir). It will dump the bca (Burst Cutting Area) of the disc and this should reveal half of the Volume ID :D. (you don't have to do the hammering stuff btw). We will know much more when we have that.

Regards,

arnezami

PS. A Dcert starts with 01. If not then its garbadge data.
PPS. There is another possibility: they didn't want this title to be playable on a PC. Hmmm.....


-In sensitive mode, the Dcert is reported as a string of zeros (but not for other discs).

-i am not able to get a vuk by any means

-the mkb ver is the same "1000000C000410030000000121000034"

-i don't have a standalone to test my disc on. i'm getting a replacement disc to see if it's bad

-its definitely not recordable

-i'm sure my other discs are working now

-evo demux reports a vc-1, dd+, and subpicture stream when reading the feature evo

-here is the result of dumpvid:
DumpVID 0.3 by KenD00

Drive type is recognised as CDROM/DVD.

Sending SPC1 Test Unit CDB6 command..done.
Returned good status.

Reading BCA...
Reading Copyright Data Section...
Sense data, key:ASC:ASCQ: 05:30:02
Aborting process.
Dump failed from drive h:

arnezami
2nd April 2007, 05:58
-In sensitive mode, the Dcert is reported as a string of zeros (but not for other discs).

-i am not able to get a vuk by any means

-the mkb ver is the same "1000000C000410030000000121000034"

-i don't have a standalone to test my disc on. i'm getting a replacement disc to see if it's bad

-its definitely not recordable

-i'm sure my other discs are working now

-evo demux reports a vc-1, dd+, and subpicture stream when reading the feature evo

-here is the result of dumpvid:
DumpVID 0.3 by KenD00

Drive type is recognised as CDROM/DVD.

Sending SPC1 Test Unit CDB6 command..done.
Returned good status.

Reading BCA...
Reading Copyright Data Section...
Sense data, key:ASC:ASCQ: 05:30:02
Aborting process.
Dump failed from drive h:

Ok. No new MKB version and no different Host Revocation List means nothing is revoked here. The files are not (completely) corrupted since demuxer still sees streams (i'm not sure if this means its not encrypted, you would have to try to play any of the demuxed files).

Did the dumpvid create a bca.bin file btw? And if so is there anything in it?

It sounds to me like this disc is either damaged or badly made or was created in such a way it won't play on a PC based system. Or for some reason you drive can't handle it.

Anyway I will be interested to know if the replacement works. :)

Regards,

arnezami

HyperHacker
2nd April 2007, 07:18
its definitely not recordable[/CODE]
Are you sure? It could be a fake or something.

mb2696
2nd April 2007, 14:54
Are you sure? It could be a fake or something.

i bought it from amazon.com, i doubt it

it also has a barcode on the inner hub

mb2696
2nd April 2007, 14:58
...

Did the dumpvid create a bca.bin file btw? And if so is there anything in it?

...

Here's the entire contents of the bca.bin:

10011104481200001002100840000115
20072036000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
000000000000000000000000

mb2696
2nd April 2007, 15:12
This thread may have some important info, near the bottom about basic/advanced authoring mode and firmware:

http://www.avsforum.com/avs-vb/showthread.php?t=826140

awhitehead
2nd April 2007, 15:56
Here's the entire contents of the bca.bin:

10011104481200001002100840000115
20072036000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
000000000000000000000000

Looks like we are dealing with the date code volume ID again:
40 00 01 15 20 07 20 36

Jan 15 2007? 20:36?
What are the date and timestamps on the files on the disk itself?

mb2696
2nd April 2007, 16:57
Looks like we are dealing with the date code volume ID again:
40 00 01 15 20 07 20 36

Jan 15 2007? 20:36?
What are the date and timestamps on the files on the disk itself?

file date is 01/16/07 01:25:17

arnezami
2nd April 2007, 17:46
Here's the entire contents of the bca.bin:

10011104481200001002100840000115
20072036000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
000000000000000000000000

Hehe ;).

There is one half of a Volume ID in there :). And since we already know/can guess which form this one is the following will probably work...

Use mkb.exe (http://forum.doom9.org/showthread.php?p=953496#post953496) in the following way:

mkb h:\AACS\MKBROM.AACS 40000115200720360020202020200000

Where h should be your drive letter.

You should get a VUK and with that key you should be able to decrypt your disc using your favorite decrypter :D.

Tell us if it works.

Regards,

arnezami

mb2696
2nd April 2007, 17:59
when i decrypt using the resulting vuk, i get video with only black screen and no audio, eventually crashing pdvd 7.1

the validatevuk tool also says its not valid.

arnezami
2nd April 2007, 18:06
when i decrypt using the resulting vuk, i get video with only black screen and no audio, eventually crashing pdvd 7.1

the validatevuk tool also says its not valid.

Hmmm. I'm not sure how sensitive these programs are but did you remove the white spaces and make it all capitals? And you didn't make a typo when using mkd.exe (be sure)? Best to try with validatevuk.

Could you give a screenshot/copy paste of what mkd.exe is giving?

arnezami

[edit]also try these:
mkb h:\AACS\MKBROM.AACS 40000115200720360000000000000000
mkb h:\AACS\MKBROM.AACS 00000000000000000000000000000000

mb2696
2nd April 2007, 20:28
Could you give a screenshot/copy paste of what mkd.exe is giving?


here are each of the three you asked me to try. none could be verified with validatevuk.

>mkb.exe h:\AACS\MKBROM.AACS 40000115200720360020202020200000
Skipped section 10
Skipped section 21
Skipped section 20
Found Verification Data
Skipped section 7f
Skipped section 07
Found Explicit Subset Difference (514 records)
Found Media Key Data (513 records)
Media Key found at index 0!
a0 bc 2b 16 a2 ad 64 d1 a3 c2 0f ae 26 68 1c 0a
VUK: 4e 77 31 f8 1a 28 63 a1 9a 30 49 35 c5 79 f2 d2

>mkb.exe h:\AACS\MKBROM.AACS 40000115200720360000000000000000
Skipped section 10
Skipped section 21
Skipped section 20
Found Verification Data
Skipped section 7f
Skipped section 07
Found Explicit Subset Difference (514 records)
Found Media Key Data (513 records)
Media Key found at index 0!
a0 bc 2b 16 a2 ad 64 d1 a3 c2 0f ae 26 68 1c 0a
VUK: cb db 1a 22 49 8e 95 6b c2 34 f9 09 7d 34 d8 82

>mkb.exe h:\AACS\MKBROM.AACS 00000000000000000000000000000000
Skipped section 10
Skipped section 21
Skipped section 20
Found Verification Data
Skipped section 7f
Skipped section 07
Found Explicit Subset Difference (514 records)
Found Media Key Data (513 records)
Media Key found at index 0!
a0 bc 2b 16 a2 ad 64 d1 a3 c2 0f ae 26 68 1c 0a
VUK: df 46 7c b3 69 cc bc 93 d6 79 2b ed 00 98 e9 66

mb2696
2nd April 2007, 20:30
Could you give a screenshot/copy paste of what mkd.exe is giving?


here are each of the three you asked me to try. none could be verified with validatevuk (i'm sure i entered them properly).

>mkb.exe h:\AACS\MKBROM.AACS 40000115200720360020202020200000
Skipped section 10
Skipped section 21
Skipped section 20
Found Verification Data
Skipped section 7f
Skipped section 07
Found Explicit Subset Difference (514 records)
Found Media Key Data (513 records)
Media Key found at index 0!
a0 bc 2b 16 a2 ad 64 d1 a3 c2 0f ae 26 68 1c 0a
VUK: 4e 77 31 f8 1a 28 63 a1 9a 30 49 35 c5 79 f2 d2

>mkb.exe h:\AACS\MKBROM.AACS 40000115200720360000000000000000
Skipped section 10
Skipped section 21
Skipped section 20
Found Verification Data
Skipped section 7f
Skipped section 07
Found Explicit Subset Difference (514 records)
Found Media Key Data (513 records)
Media Key found at index 0!
a0 bc 2b 16 a2 ad 64 d1 a3 c2 0f ae 26 68 1c 0a
VUK: cb db 1a 22 49 8e 95 6b c2 34 f9 09 7d 34 d8 82

>mkb.exe h:\AACS\MKBROM.AACS 00000000000000000000000000000000
Skipped section 10
Skipped section 21
Skipped section 20
Found Verification Data
Skipped section 7f
Skipped section 07
Found Explicit Subset Difference (514 records)
Found Media Key Data (513 records)
Media Key found at index 0!
a0 bc 2b 16 a2 ad 64 d1 a3 c2 0f ae 26 68 1c 0a
VUK: df 46 7c b3 69 cc bc 93 d6 79 2b ed 00 98 e9 66

arnezami
2nd April 2007, 21:03
Ok. I think I'm running out of ideas now. There really seems to be a problem with this disc and the xbox 360 HD DVD drive. Maybe there is something wrong with the way the protected area is stored on the disc (which is if I remember correctly stored with a different pit width/length) and therefore not readable by all HD DVD drives.

Btw this may be related: http://slashdot.org/articles/07/04/02/1126209.shtml

arnezami

HyperHacker
3rd April 2007, 04:38
Well, if even authorized players aren't able to read the disc, I suspect we won't get very far either. Unless they've simply been revoked, but that doesn't seem to be the case.

PepsiLee2001
3rd April 2007, 08:34
Dear All,

I try to complie aacskey in windows platform, but something is wrong.

Please give me a hand......


System environment:
OS : WinXP Pro
OpenSSL : 0.9.8e
MinGW : 3.4.2 (detail as follow)
mingw-runtime-3.12.tar.gz
w32api-3.9.tar.gz
binutils-2.16.91-20060119-1.tar.gz
gcc-core-3.4.2-20040916-1.tar.gz
gcc-g++-3.4.2-20040916-1.tar.gz
mingw32-make-3.81-2.tar.gz


Path:
aacskey source : d:\aacskey
MinGW : D:\MinGW
OpenSSL library : D:\aacskey\lib (static link library files-->libcrypto.a & libssl.a)

command 1: gcc -o aacskeys -lcrypto -L./lib aes.c ecdsa.c ioctl.c mmc.c aacskeys.c
D:\aacskey>gcc -o aacskeys -lcrypto -L./lib aes.c ecdsa.c ioctl.c mmc.c aacskeys.c
ecdsa.c: In function `aacs_set_cert':
ecdsa.c:29: warning: initialization discards qualifiers from pointer target type
ecdsa.c: In function `aacs_sign':
ecdsa.c:67: warning: comparison between pointer and integer
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/ccV3caaa.o:aes.c:(.text+0x22): undefined reference to `AES_set_decrypt_key'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/ccV3caaa.o:aes.c:(.text+0x3e): undefined reference to `AES_decrypt'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/ccV3caaa.o:aes.c:(.text+0xba): undefined reference to `AES_set_decrypt_key'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/ccV3caaa.o:aes.c:(.text+0xd6): undefined reference to `AES_decrypt'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/ccV3caaa.o:aes.c:(.text+0x103): undefined reference to `AES_set_decrypt_key'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/ccV3caaa.o:aes.c:(.text+0x11f): undefined reference to `AES_decrypt'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/ccV3caaa.o:aes.c:(.text+0x17d): undefined reference to `AES_set_decrypt_key'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/ccV3caaa.o:aes.c:(.text+0x199): undefined reference to `AES_decrypt'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x7): undefined reference to `EC_KEY_new'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x33): undefined reference to `EC_KEY_set_group'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x4c): undefined reference to `EC_KEY_free'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x7e): undefined reference to `EC_KEY_get0_group'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0xc3): undefined reference to `BN_bin2bn'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0xf6): undefined reference to `BN_bin2bn'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x113): undefined reference to `EC_POINT_new'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x14d): undefined reference to `EC_POINT_set_affine_coordinates_GFp'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x165): undefined reference to `BN_clear_free'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x170): undefined reference to `BN_clear_free'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x182): undefined reference to `EC_KEY_set_public_key'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x1ef): undefined reference to `BN_hex2bn'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x209): undefined reference to `EC_KEY_set_private_key'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x217): undefined reference to `EVP_ecdsa'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x226): undefined reference to `EVP_DigestInit'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x240): undefined reference to `EVP_DigestUpdate'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x25a): undefined reference to `EVP_DigestUpdate'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x273): undefined reference to `EVP_DigestFinal_ex'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x28c): undefined reference to `ECDSA_do_sign'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x2a3): undefined reference to `BN_bn2bin'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x2c2): undefined reference to `BN_bn2bin'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x2e7): undefined reference to `ECDSA_SIG_free'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x2f8): undefined reference to `EC_KEY_free'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x340): undefined reference to `EVP_ecdsa'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x34f): undefined reference to `EVP_DigestInit'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x369): undefined reference to `EVP_DigestUpdate'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x383): undefined reference to `EVP_DigestUpdate'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x39c): undefined reference to `EVP_DigestFinal_ex'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x3a1): undefined reference to `ECDSA_SIG_new'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x3c6): undefined reference to `BN_bin2bn'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x3ea): undefined reference to `BN_bin2bn'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x410): undefined reference to `ECDSA_do_verify'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x424): undefined reference to `ECDSA_SIG_free'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x435): undefined reference to `EC_KEY_free'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x509): undefined reference to `BN_CTX_new'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x53e): undefined reference to `ERR_put_error'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x548): undefined reference to `BN_new'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x556): undefined reference to `BN_new'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x564): undefined reference to `BN_new'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x572): undefined reference to `BN_new'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x580): undefined reference to `BN_new'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x58e): more undefined references to `BN_new' follow
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x5c3): undefined reference to `ERR_put_error'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x5da): undefined reference to `BN_dec2bn'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x5f3): undefined reference to `BN_dec2bn'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x60c): undefined reference to `BN_dec2bn'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x63c): undefined reference to `ERR_put_error'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x661): undefined reference to `EC_GROUP_new_curve_GFp'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x696): undefined reference to `ERR_put_error'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x6a6): undefined reference to `EC_POINT_new'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x6db): undefined reference to `ERR_put_error'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x6f5): undefined reference to `BN_dec2bn'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x70e): undefined reference to `BN_dec2bn'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x73e): undefined reference to `ERR_put_error'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x76a): undefined reference to `EC_POINT_set_affine_coordinates_GF2m'

C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x79a): undefined reference to `ERR_put_error'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x7b4): undefined reference to `BN_dec2bn'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x7cb): undefined reference to `BN_set_word'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x7fb): undefined reference to `ERR_put_error'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x81d): undefined reference to `EC_GROUP_set_generator'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x84d): undefined reference to `ERR_put_error'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x867): undefined reference to `EC_GROUP_free'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x87f): undefined reference to `EC_POINT_free'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x890): undefined reference to `BN_CTX_free'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x8a1): undefined reference to `BN_free'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x8b2): undefined reference to `BN_free'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x8c3): undefined reference to `BN_free'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x8d4): undefined reference to `BN_free'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x8e5): undefined reference to `BN_free'
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cc5udaaa.o:ecdsa.c:(.text+0x8f6): more undefined references to `BN_free' follow
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp/cczOeaaa.o:aacskeys.c:(.text+0x9e2): undefined reference to `ERR_load_crypto_strings'
collect2: ld returned 1 exit status


command 2: gcc -o aacskeys aes.c ecdsa.c ioctl.c mmc.c aacskeys.c -lcrypto -L./lib
D:\aacskey>gcc -o aacskeys aes.c ecdsa.c ioctl.c mmc.c aacskeys.c -lcrypto -L./lib
ecdsa.c: In function `aacs_set_cert':
ecdsa.c:29: warning: initialization discards qualifiers from pointer target type
ecdsa.c: In function `aacs_sign':
ecdsa.c:67: warning: comparison between pointer and integer
./lib/libcrypto.a(rand_win.o):rand_win.c:(.text+0xa0c): undefined reference to `CreateDCA@16'
./lib/libcrypto.a(rand_win.o):rand_win.c:(.text+0xa19): undefined reference to `CreateCompatibleDC@4'
./lib/libcrypto.a(rand_win.o):rand_win.c:(.text+0xa2a): undefined reference to `GetDeviceCaps@8'
./lib/libcrypto.a(rand_win.o):rand_win.c:(.text+0xa3a): undefined reference to `GetDeviceCaps@8'
./lib/libcrypto.a(rand_win.o):rand_win.c:(.text+0xa50): undefined reference to `CreateCompatibleBitmap@12'
./lib/libcrypto.a(rand_win.o):rand_win.c:(.text+0xa5e): undefined reference to `SelectObject@8'
./lib/libcrypto.a(rand_win.o):rand_win.c:(.text+0xa70): undefined reference to `GetObjectA@12'
./lib/libcrypto.a(rand_win.o):rand_win.c:(.text+0xae1): undefined reference to `BitBlt@36'
./lib/libcrypto.a(rand_win.o):rand_win.c:(.text+0xaeb): undefined reference to `GetBitmapBits@12'
./lib/libcrypto.a(rand_win.o):rand_win.c:(.text+0xb42): undefined reference to `SelectObject@8'
./lib/libcrypto.a(rand_win.o):rand_win.c:(.text+0xb49): undefined reference to `DeleteObject@4'
./lib/libcrypto.a(rand_win.o):rand_win.c:(.text+0xb53): undefined reference to `DeleteDC@4'
./lib/libcrypto.a(rand_win.o):rand_win.c:(.text+0xb5d): undefined reference to `DeleteDC@4'
collect2: ld returned 1 exit status


My Questions,
1. Which command is correct?

2. if command 2 is correct, which library was missed?

PS : OpenSSL Library files was complied successful in the same platform(MinGW).

mb2696
5th April 2007, 17:10
Ok. I think I'm running out of ideas now. There really seems to be a problem with this disc and the xbox 360 HD DVD drive. Maybe there is something wrong with the way the protected area is stored on the disc (which is if I remember correctly stored with a different pit width/length) and therefore not readable by all HD DVD drives.

Btw this may be related: http://slashdot.org/articles/07/04/02/1126209.shtml

arnezami


got my replacement disc today...same problem.

also tried playback with pdvd6.5 which reports "A disc with an unsupported format in drive H:"

additionally, according to these reviews there appears to be problems on other players as well:
http://www.amazon.com/National-Geographic-Relentless-Enemies-DVD/dp/B000MQCULO

QuePaso
5th April 2007, 22:32
I am hoping we will see a version that works on the PS3 soon!

zeroprobe
9th April 2007, 13:09
Going to try ubantu 7.04 beta as I think it ships with the 2.6.20 kernel. Will give this a go to see if it works.

arnezami
10th April 2007, 08:38
what does it mean if the volume id is reported as a string of zeroes? i've been having trouble getting "National Geographic - Relentless Enemies" to work.

any ideas?

thanks

Please try the new vid.exe (http://www.ingenieria-inversa.cl/files/vid.rar) and see what it returns (mirror (http://www.sendspace.com/file/g25nhb)).

arnezami

mb2696
12th April 2007, 17:03
Please try the new vid.exe (http://www.ingenieria-inversa.cl/files/vid.rar) and see what it returns (mirror (http://www.sendspace.com/file/g25nhb)).

arnezami


still zeroes...

i also patched my fw as soon as you released it the other day, still unable to read it. it looks like this disc may not have been authored properly, as other standalone players are have trouble as well. its supposed to be fixed with a firmware update in may?

heres my output w/ patch (i AM able to get the vid from other discs with this patch/technique):

>set PLSCSI=\\.\G:

>plscsi.exe -v -x "AD 00 00 00 00 00 00 80 00 24 00 00" -i x24
x 00000000 AD 00 00:00:00:00 00 80:00:24:00 00 .. .. .. .. "-@@@@@@@@$@@"
x 00000000 AE:AE:AE:AE AE:AE:AE:AE AE:AE:AE:AE AE:AE:AE:AE "................"
x 00000010 AE:AE:AE:AE AE:AE:AE:AE AE:AE:AE:AE AE:AE:AE:AE "................"
x 00000020 AE:AE:AE:AE .. .. .. .. .. .. .. .. .. .. .. .. "...."
x 00000000 70:00:05:00 00:00:00:0A 00:00:00:00 6F:01 .. .. "p@E@@@@J@@@@oA"
// x 5 6F 01 sense // x24 (36) residue
// -x0102 = -258 = plscsi.main exit int

>

arnezami
15th April 2007, 09:11
Ok. I'm quite busy extending/improving aacskeys. :)

My new version now uses a proper Hk/Hv combination and supports Bus Key calculation (which was quite some work) and because of that it now supports Volume ID MACs (for both BD and HD DVD). It also supports TKF MAC now (for checking if a VUK is correct, which is a HD-DVD-only feature btw). It also outputs the SHA-1 hash of the Title Key File (or CPS Unit Key file for BD according to new specs by KenD00's decrypter).

I'm still in the process of putting the Processing/Device Key(s) and Host Private Key(s) into editable text files and letting the program figure out which keys to use. Essentially implementing the whole Subset Tree Difference algorithm (and make it even more flexible than the official algo so it can figure out things with less available knowledge)

I'm also working on BDAV support. But I have a problem. Maybe somebody else can help me here ;).

I need to extract the Binding Nonce. There is a command for that (which should work after AACS-Auth). The problem is in this command an address needs to be filled: LBA Extend. But I have no idea what to put there... Sure it has to be the same address the Binding Nonce was written to but how do I get this information??

Can anybody help?

Thanks.

arnezami

PS. I've also enhanced fetchvid.exe (less agressive/more subtle/time in ms) which now works with PowerDVD 7.3 and WinDVD 8 HD. But should work with any player. This will be the equivalent (for BD drive owners) of a Volume ID "hack". Although it requires a working software player.

arnezami
15th April 2007, 16:47
Here is a new windows version of aacskeys. I've also updated the link in the first post with this one.

http://www.sendspace.com/file/8q6aub

As stated above it has several improvements (most practical I think is the Title/Unit Key file hash atm).

There is still quite a lot I want to change/improve so you can expect more to come :).

Please test if its working: there has been a lot of changes ;).

mrazzido
15th April 2007, 17:02
test it with 2 bluray discs works !

great! :D

Orion17
15th April 2007, 19:47
Tested with King Kong (HD DVD). Seems to be working...Thanks arnezami

http://img523.imageshack.us/img523/1699/image1xy2.jpg (http://imageshack.us)

arnezami
15th April 2007, 19:54
Nice :).

Please check if the Bus Key is filled (don't post it) and whether the Volume ID MACs are exactly the same (don't post it).

Also fot Bluray: is the sha-1 hash the correct one? (according to the KenD00's new specs that is)

mrazzido
15th April 2007, 20:35
Nice :).

Please check if the Bus Key is filled (don't post it) and whether the Volume ID MACs are exactly the same (don't post it).

Also fot Bluray: is the sha-1 hash the correct one? (according to the KenD00's new specs that is)


For bluray .


SHA-1 is the correct one !

and Buskey is Filled :-)

PepsiLee2001
16th April 2007, 07:31
I'm also working on BDAV support. But I have a problem. Maybe somebody else can help me here ;).


I have a blu-ray BDAV, but aacskeys can't get any info from it.

message as follow:
C:\aacskeys>aacskeys.exe i v
Error opening Media Key File i:\AACS\MKBROM.AACS


Blu-ray BDAV file structure as follow,
\AACS\MKB_RW.inf
\AACS\AACS_av\CPSUnit00001.cci
\AACS\AACS_av\Unit_Key_RW.inf

Thanks a lot!!!!!!

arnezami
16th April 2007, 18:23
I have a blu-ray BDAV, but aacskeys can't get any info from it.

message as follow:
C:\aacskeys>aacskeys.exe i v
Error opening Media Key File i:\AACS\MKBROM.AACS


Blu-ray BDAV file structure as follow,
\AACS\MKB_RW.inf
\AACS\AACS_av\CPSUnit00001.cci
\AACS\AACS_av\Unit_Key_RW.inf

Thanks a lot!!!!!!

Because I haven't been able to figure out this problem (http://forum.doom9.org/showpost.php?p=989138&postcount=117) the program isn't looking for BDAV files yet.

I really need help on this.

arnezami

PepsiLee2001
17th April 2007, 02:58
Because I haven't been able to figure out this problem (http://forum.doom9.org/showpost.php?p=989138&postcount=117) the program isn't looking for BDAV files yet.

If any thing I can do, I will do it.
Just let me know how to do.

Boing99
17th April 2007, 04:34
Ok. I'm quite busy extending/improving aacskeys. :)

My new version now uses a proper Hk/Hv combination and supports Bus Key calculation (which was quite some work) and because of that it now supports Volume ID MACs (for both BD and HD DVD). It also supports TKF MAC now (for checking if a VUK is correct, which is a HD-DVD-only feature btw). It also outputs the SHA-1 hash of the Title Key File (or CPS Unit Key file for BD according to new specs by KenD00's decrypter).

Since you are being so thorough about it you may also be interested in verifying the various signatures in AACS files, using the AACS public keys. I have not seen them posted anywhere else before, so here they are (in decimal format, the same format used in the AACS specs):

#define AACS_CC_PUB_X "686795158131444840350934441718292981749606298444"
#define AACS_CC_PUB_Y "667926496774724305600543583224894590551199207"
#define AACS_LA_PUB_X "569519044145899916876682500420440111695939635058"
#define AACS_LA_PUB_Y "111297986001312168148180416490690086062371334695"

I'm also working on BDAV support. But I have a problem. Maybe somebody else can help me here ;).

I need to extract the Binding Nonce. There is a command for that (which should work after AACS-Auth). The problem is in this command an address needs to be filled: LBA Extend. But I have no idea what to put there... Sure it has to be the same address the Binding Nonce was written to but how do I get this information??

The specs say "For BDRecordable Disc, the Binding Nonce shall be stored in the User Control Data associated with the first logical Sector of the CPS Unit Key File and should be non-zero value.". I assume that "first logical sector" is the same as the "LBA (Logical Block Address) Extent". The term "extent" usually refers to a consecutive range of sectors or blocks. As for how to get this: you have two options: either implement a simple UDF 2.5 reader/handler yourself and get the starting block number of the CPS Unit Key file right out of the directory structure. Or try to get it from the OS, in an OS-specific way using some file/directory query function. I don't know how to do this for Windows, but others may be able to help with that, or just google for it.

arnezami
17th April 2007, 06:20
Since you are being so thorough about it you may also be interested in verifying the various signatures in AACS files, using the AACS public keys. I have not seen them posted anywhere else before, so here they are (in decimal format, the same format used in the AACS specs):

#define AACS_CC_PUB_X "686795158131444840350934441718292981749606298444"
#define AACS_CC_PUB_Y "667926496774724305600543583224894590551199207"
#define AACS_LA_PUB_X "569519044145899916876682500420440111695939635058"
#define AACS_LA_PUB_Y "111297986001312168148180416490690086062371334695"

Yeah I might aswell do that too. Cool find btw. :) Where did you get that? I haven't really spend much time searching for it but couldn't find it either (in mem). Must have missed it. Although I guessed its in every device and player so somebody would find it sooner or later. Changing this inside a Software Player would also allow us to let the Player do pretty much everything we want: thus potentially revealing all (and even still unused) keys inside the player (like all Device Keys and/or Sequence Keys).

The specs say "For BDRecordable Disc, the Binding Nonce shall be stored in the User Control Data associated with the first logical Sector of the CPS Unit Key File and should be non-zero value.". I assume that "first logical sector" is the same as the "LBA (Logical Block Address) Extent". The term "extent" usually refers to a consecutive range of sectors or blocks. As for how to get this: you have two options: either implement a simple UDF 2.5 reader/handler yourself and get the starting block number of the CPS Unit Key file right out of the directory structure. Or try to get it from the OS, in an OS-specific way using some file/directory query function. I don't know how to do this for Windows, but others may be able to help with that, or just google for it.

Yeah. The problem is I haven't got a BluRay player/burner AND I haven't got BDAV discs. So this makes it pretty much impossible for me to test things. Maybe I will make a small proggy so somebody that does have the above can try out different addresses and see what happens.

But only after I finished the implementation of automatic Device/Processing Key detection: this is gonna be a very cool and powerful feature :) and will be very useful for future attempts by "Key Finders" (aka hackers) to check if they have found a Key among (tons of) possible keys.

Regards,

arnezami

MickJT
19th April 2007, 03:27
Just incase anyone didn't know.. AnyDVD HD 6.1.3.6 is now capable of decrypting Blu-Ray titles from mounted .iso images created with "dd" on the PS3 in Linux.

HyperHacker
20th April 2007, 01:09
There was a thread (http://forum.doom9.org/showthread.php?t=124841) about that. It's just using a database of keys.

MickJT
20th April 2007, 16:12
I don't think it's using a database of keys.

The discs I tried it on was Casino Royale (AUS) which is different to EUR/GER and USA, and also Sky High (AUS).

No database i've seen includes keys for these discs.

FoxDisc
20th April 2007, 18:40
I don't think it's using a database of keys.
The discs I tried it on was Casino Royale (AUS) which is different to EUR/GER and USA, and also Sky High (AUS).
No database i've seen includes keys for these discs.
You didn't read the thread HyperHacker sent you to. It explains that AnyDVD doesn't need its database if you use it with an original disc, and you won't have ever seen their database. AnyDVD uses its own database as a backup, which lets it decrypt files mounted as an ISO or just copied off the original disc.

arnezami
21st April 2007, 12:51
I'm really busy implementing stuff into aacskeys. :D

Here is something to test:

http://www.sendspace.com/file/f0lh56

Its now supports automatic Device/Processing Key detection :).

But it needs to be tested. If anyone has Device Keys (from our "old" Software Players which are going to be revoked anyway so you can release them if you like) then please test them and see if they are recognized as such.

In the file "ProcessingDeviceKeysSimple.txt" you can simply throw your Device/Processing Keys. If they work on a disc then aacskeys should be able to recognize that.

Here is what I put in for testing:

DEADBEAFDEADBEAFDEADBEAFDEADBEAF
DEEDDEEDDEEDDEEDDEEDDEEDDEEDDEED
12345678123456781234567812345678
87654321876543218765432187654321
AA856A1BA814AB99FFDEBA6AEFBE1C04
DEADBEAFDEADBEAFDEADBEAFDEADBEAF
DEEDDEEDDEEDDEEDDEEDDEEDDEEDDEED
12345678123456781234567812345678
87654321876543218765432187654321
09F911029D74E35BD84156C5635688C0
DEADBEAFDEADBEAFDEADBEAFDEADBEAF
DEEDDEEDDEEDDEEDDEEDDEEDDEEDDEED
12345678123456781234567812345678
87654321876543218765432187654321

Since it starts trying keys from the top it will detect the Device Key (released by ATARI Vampire) first (the one starting with AA85). If you remove or change that key it will find the Processing Key. If you remove or change that one too it doesn't find any working key and aborts.

In order for this to work on a new disc you need to find possible Keys (of course getting these is the hard part) and use aacskeys with these Keys on the new disc (or alternatively : copy the AACS directory from your new disc to a root dir of one of your HDDs and let aacskeys operate on that drive letter. Or mount these files/disc as an ISO. This will prevent wear and tear on your disc/drive).

More will follow (like input of volume id/HPK) but this I had to get out so somebody can (hopefully) confirm its working. ;)

arnezami

PS. As for speed: you will notice it takes quite a lot of time to test many keys. The current version isn't build for speed. There are several ways to speed it up (eg precomputation due to similarity in shapes of subsets) and shortcuts (like only trying a few C-values and ignoring others). In other words: you can't scan (full) memdumps with this program. ;)

awhitehead
23rd April 2007, 05:40
No worky

Older version of aacskeys happily works with my current test disk (Total Recall):


C:\aacs>.\aacskeys.exe i v
Processing key: 09F911029D74E35BD84156C5635688C0
Encrypted C-value: B7422BF12E30C7308B66B877E376058D
Corresponding uv: 00000001

Decrypted C-value: 50D497E0D724A42B08E010619D3B6DD7
Media key: 50D497E0D724A42B08E010619D3B6DD6

Encrypted verification data: 9ED2A5E1116D544F0338E74E8A4F9A0B
Decr verif data should be: 0123456789ABCDEF
Decrypted verification data: 0123456789ABCDEF07D27BEAF4FBDC72

AGID: 00

Host certificate from: Power DVD 7.1
Host certificate (Hcert): 0200005CFFFF0000000C00006E3DEB679B9A16AD
FAA8E30878767BA6EB2A9B415385AD1181B4446C
31E9A5DD2AB808B364FF15885BAC490964318C9B
F8029FCF76F688A54FBDA03F6D9332EF04E5A613
12DA85880A4D9CBB79D8602E
Host Private Key (Hpriv): 4737676058D7029452514F0AB186DC4CCA8C578F
Host Nonce (Hn): 2923BE84E16CD6AE529049F1F1BBE9EBB3A6DB3C

Drive certificate (Dcert): ########################################
########################################
########################################
########################################
########################
Drive Nonce (Dn): ########################################

Drive key point (Dv): ########################################
########################################
Drive key signature (Dsig): ########################################
########################################

Host key (Hk): 0000000000000000000000000000000000000000
Host key point (Hv): 8E9B0E3CF41FA7DA3A829F604122EA4ED5261AA4
7570CE0BB9061A66FAF92C4A7D98ACC171CBF19B
Host key signature (Hsig): ########################################
########################################

Bus key (BK): ################################

Volume ID: 4000922B7BCD3536AC5CD7FA41FD0000
Voluem ID MAC: ################################

Volume Unique Key: F51EAABB7CD2E2ED05A6BE00126D4AA6
Title Key File MAC: 232F941592CBE19FF50865356153DEA7

Encrypted Title Key 1: 8D2F4E37CF6525FA88877BFFF77F5F50
Encrypted Title Key 2: 032609ADE9C4FB6B9C8F19E1BF3A8056
Encrypted Title Key 3: 25D499F134D0F546F346814C0E142D6C
Encrypted Title Key 4: 8C03F7420B47ECF1C6A2BEE7174E416E

[64 encrypted and decrypted title keys snipped]



With the newer version of aacskeys I get the following:
(ProcessingDeviceKeysSimpletxt as shipped)


C:\aacs\aacskeys.new>.\aacskeys.exe i v

Could not find a Processing Key or Device Key resulting in the Media Key.

Aborting...

C:\aacs\aacskeys.new>


If I go ahead and edit ProcessingDeviceKeysSimple.txt to just contain a single line:
09F911029D74E35BD84156C5635688C0
(Processing key that works with older version of aacskeys and this disk), I still get the same error message.

Hope this helps.

System in question is Windows XP, Pan European release (?), English locale. Xbox 360 HD-DVD drive connected over USB.

Are there any other tests I can run?

arnezami
23rd April 2007, 06:10
No worky

Older version of aacskeys happily works with my current test disk (Total Recall):


C:\aacs>.\aacskeys.exe i v
Processing key: 09F911029D74E35BD84156C5635688C0
Encrypted C-value: B7422BF12E30C7308B66B877E376058D
Corresponding uv: 00000001

Decrypted C-value: 50D497E0D724A42B08E010619D3B6DD7
Media key: 50D497E0D724A42B08E010619D3B6DD6

Encrypted verification data: 9ED2A5E1116D544F0338E74E8A4F9A0B
Decr verif data should be: 0123456789ABCDEF
Decrypted verification data: 0123456789ABCDEF07D27BEAF4FBDC72

AGID: 00

Host certificate from: Power DVD 7.1
Host certificate (Hcert): 0200005CFFFF0000000C00006E3DEB679B9A16AD
FAA8E30878767BA6EB2A9B415385AD1181B4446C
31E9A5DD2AB808B364FF15885BAC490964318C9B
F8029FCF76F688A54FBDA03F6D9332EF04E5A613
12DA85880A4D9CBB79D8602E
Host Private Key (Hpriv): 4737676058D7029452514F0AB186DC4CCA8C578F
Host Nonce (Hn): 2923BE84E16CD6AE529049F1F1BBE9EBB3A6DB3C

Drive certificate (Dcert): ########################################
########################################
########################################
########################################
########################
Drive Nonce (Dn): ########################################

Drive key point (Dv): ########################################
########################################
Drive key signature (Dsig): ########################################
########################################

Host key (Hk): 0000000000000000000000000000000000000000
Host key point (Hv): 8E9B0E3CF41FA7DA3A829F604122EA4ED5261AA4
7570CE0BB9061A66FAF92C4A7D98ACC171CBF19B
Host key signature (Hsig): ########################################
########################################

Bus key (BK): ################################

Volume ID: 4000922B7BCD3536AC5CD7FA41FD0000
Voluem ID MAC: ################################

Volume Unique Key: F51EAABB7CD2E2ED05A6BE00126D4AA6
Title Key File MAC: 232F941592CBE19FF50865356153DEA7

Encrypted Title Key 1: 8D2F4E37CF6525FA88877BFFF77F5F50
Encrypted Title Key 2: 032609ADE9C4FB6B9C8F19E1BF3A8056
Encrypted Title Key 3: 25D499F134D0F546F346814C0E142D6C
Encrypted Title Key 4: 8C03F7420B47ECF1C6A2BEE7174E416E

[64 encrypted and decrypted title keys snipped]



With the newer version of aacskeys I get the following:
(ProcessingDeviceKeysSimpletxt as shipped)


C:\aacs\aacskeys.new>.\aacskeys.exe i v

Could not find a Processing Key or Device Key resulting in the Media Key.

Aborting...

C:\aacs\aacskeys.new>


If I go ahead and edit ProcessingDeviceKeysSimple.txt to just contain a single line:
09F911029D74E35BD84156C5635688C0
(Processing key that works with older version of aacskeys and this disk), I still get the same error message.

Hope this helps.

System in question is Windows XP, Pan European release (?), English locale. Xbox 360 HD-DVD drive connected over USB.

Are there any other tests I can run?
Ok. Thanks. What happens if you remove the file: ProcessingDeviceKeysSimple.txt altogether? Do you get a different error message? Or does it crash?

Do others have the same problem here? Please test it.

(btw it works fine on my system and I don't see (yet) why it would not work with yours)

arnezami

awhitehead
23rd April 2007, 06:10
BTW, I have a couple of suggestions for aacskeys....

There are many revisions of it out there by now, so maybe implementing some sort of versioning as maybe the first line of the output would make sense. In the above post I refer to "older" aacskeys, but I have no idea which particular build it is. This would make your life easier with bug reports, etc.

If you add a way of adding comments to ProcessingDeviceKeysSimple.txt (ie lines that will not be processed by the aacskeys, say lines that start with # or ; ), it would probably be useful for key management, etc.

arnezami
23rd April 2007, 06:16
BTW, I have a couple of suggestions for aacskeys....

There are many revisions of it out there by now, so maybe implementing some sort of versioning as maybe the first line of the output would make sense. In the above post I refer to "older" aacskeys, but I have no idea which particular build it is. This would make your life easier with bug reports, etc.

If you add a way of adding comments to ProcessingDeviceKeysSimple.txt (ie lines that will not be processed by the aacskeys, say lines that start with # or ; ), it would probably be useful for key management, etc.

You're right about the versions. Here is the same new version again (now called v0.2). No changes but the output of the version nr:

http://www.sendspace.com/file/vdnfzt

Please read my previous post. You may have missed it.

arnezami

PS. Regarding the extension of the text file: this is the "Simple" version and is for people thinking they might have found a new key. So they can just throw in possible keys...

arnezami
23rd April 2007, 06:46
I have made some changes so it gives more info. Hopefully this will clarify where the problem lies:

aacskeys v0.2.2 (http://www.sendspace.com/file/envig6)

Please to others too: try this on different discs. Thanks :).

PepsiLee2001
23rd April 2007, 08:54
I have made some changes so it gives more info. Hopefully this will clarify where the problem lies:
aacskeys v0.2.2 (http://www.sendspace.com/file/envig6)
Please to others too: try this on different discs. Thanks :).


Does this version support BDAV disc?

Error message as follow,

C:\aacskeys_v0.2.2>aacskeys.exe m v
aacskeys v0.2.2

Error opening Media Key File m:\AACS\MKBROM.AACS

arnezami
23rd April 2007, 18:41
Ok. I now got the automatic Device Key detection working thanks to someone "lending me a hand" ;). Thanks. You know who you are :).

I'm still going to (more methodically) check whether its really accurate but it looks very good now.

Screenshot of usage for new aacskeys version:

http://img338.imageshack.us/img338/2418/aacskeysv024ym7.jpg

Anyway. Version 0.2.4 now supports volume id input too. This is going to be very handy when (well technically: if) we find the new Processing Key(s) without having a working HPK yet.

aacskeys v0.2.4 (http://www.sendspace.com/file/je0k22)

For the other problem (that awhitehead posted): anyone please test this new version (just run it) and post your results :thanks:

Regards,

arnezami

@PepsiLee2001: no this version doesn't support BDAV yet. Please read my last posts about this.

[edit] Small update: turned on something that wasn't supposed to stay turned off.

PS. If/when the new Processing/Device Key is found and released you can use fetchvid (http://forum.doom9.org/showthread.php?p=992791#post992791) to retrieve the Volume ID of a new disc and then use it as input for aacskeys. :)

awhitehead
24th April 2007, 04:24
For the other problem (that awhitehead posted): anyone please test this new version (just run it) and post your results :thanks:


Both 0.2.2 and 0.2.4 work for me now, both without the .txt file, and with it, if it contains a valid device or processing key. 0.2 didn't like the presence of .txt file, but works without it.

Tested with US release of "Syriana"

arnezami
24th April 2007, 04:32
Both 0.2.2 and 0.2.4 work for me now, both without the .txt file, and with it, if it contains a valid device or processing key. 0.2 didn't like the presence of .txt file, but works without it.

Tested with US release of "Syriana"

I can't work without txt file! :) Which means it somehow gets the txt file from a different directory. But 0.2 working when you remove the file... huh? I guess its possible your 0.2 gets his txt file from somewhere else when the file is not in its current dir (otherwise it read the one from its current dir and there is something wrong with it). Something like that.

I guess there is a problem with accessing the current dir or something (maybe your PATH settings). Bah. I hate this directory stuff.

Can you put the exe file in a different directory and see what happens? If you have a working setup can you remove/rename all occurences of the txt file on your entire HDD (one by one) and see which one is accessed?

Thanks.

arnezami

awhitehead
24th April 2007, 04:46
Can you put the exe file in a different directory and see what happens? If you have a working setup can you remove/rename all occurences of the txt file on your entire HDD (one by one) and see which one is accessed?


*sigh* You are right. Fixed my PATH, moved the programs to a new directory, re-run.

0.2.0 just dies with "Can't open file..."

0.2.2 and 0.2.4 print First u mask nr and First uv and then die.

With correct entry in the ProcessingDeviceKeysSimple.txt 0.2.4 and 0.2.2 still work, though, and with file present, but without the correct keys, complain about lack of keys.

arnezami
24th April 2007, 05:04
*sigh* You are right. Fixed my PATH, moved the programs to a new directory, re-run.

0.2.0 just dies with "Can't open file..."

0.2.2 and 0.2.4 print First u mask nr and First uv and then die.

With correct entry in the ProcessingDeviceKeysSimple.txt 0.2.4 and 0.2.2 still work, though, and with file present, but without the correct keys, complain about lack of keys.

Ok. So apart from crashing when no file is present it all works right?

Also try this: aacskeys v0.2.5 (http://www.sendspace.com/file/3e8bzt)

It should give (what it thinks is) the current path and it now uses that path. This prevents it from using the PATH stuff and removes the ambiguity.

arnezami

[edit] Have you also tried the new volumeid input feature?

Neo2011
25th April 2007, 13:44
Ok. I'm quite busy extending/improving aacskeys. :)

I'm also working on BDAV support. But I have a problem. Maybe somebody else can help me here ;).

I need to extract the Binding Nonce. There is a command for that (which should work after AACS-Auth). The problem is in this command an address needs to be filled: LBA Extend. But I have no idea what to put there... Sure it has to be the same address the Binding Nonce was written to but how do I get this information??

Can anybody help?

Thanks.

arnezami

I found the LBA Extend Value of the BD-RE. The LBA of the file "\AACS\AACS_av\Unit_Key_RW.inf" is the one.

This is the ScreenShot of IsoBuster 2.1. In this picture, "16800=0x000041A0" is the address.
7324

arnezami
26th April 2007, 18:59
I found the LBA Extend Value of the BD-RE. The LBA of the file "\AACS\AACS_av\Unit_Key_RW.inf" is the one.

This is the ScreenShot of IsoBuster 2.1. In this picture, "16800=0x000041A0" is the address.
http://soarern.hp.infoseek.co.jp/image/LBA_ext.png

Thanks :).

Is it possible for you to see if the LBA is the exactly same for every disc and any content?

arnezami


PS. As an aside: I've put the 0.2.5 version in my first post of this thread since it seems to be working quite well :).

PepsiLee2001
27th April 2007, 03:18
Is it possible for you to see if the LBA is the exactly same for every disc and any content?


I have another BDAV disc that own the same file size & LBA value with Neo2011 post one.

Neo2011
27th April 2007, 13:47
Is it possible for you to see if the LBA is the exactly same for every disc and any content?

My another BD-RE Disc's LBA is another one.:(
Ex. 16832 , 16768. etc.

awhitehead
27th April 2007, 19:14
My another BD-RE Disc's LBA is another one.:(
Ex. 16832 , 16768. etc.

*sigh*

Seems like the real solution is to write a (limited) UDF 2.5 filesystem parser, that would be able to read the disk, parse the volume descriptors, traverse the chain to root dir file entry of the file we want, and figure out at what LBA needed files start.

Recently I was tracking down a problem while trying to figure out why a particular HD-DVD drive is capable of reading a Fox Pathe HD-DVD disc, while a different one could not, and if it was a filesystem or mastering problem on the disc or a problem with the drive. To do that, I started writing a small set of scripts that call plscsi, send the commands, and then parse the output, but this is nowhere near userfriendly. In addition I'm lazy, so instead of reading UDF 2.5 spec, I started by just randomly reading blocks, and trying to see if I can parse them.

In any event, in order to do that you need to send the following CDBs to the drive:
Get Capacity
25 00 00:00:00:00 00 00:00 00

Example (on a DVD, since this is what I have on hand):

darkstar:~/plscsi$ plscsi -v -x "25 00 00:00:00:00 00 00:00 00" -i 8
x 00000000 25 00 00:00:00:00 00 00:00 00 .. .. .. .. .. .. "%@@@@@@@@@"
x 00000000 00:18:94:FF 00:00:08:00 .. .. .. .. .. .. .. .. "@XT?@@H@"
// 0 = plscsi.main exit int
darkstar:~/plscsi$ df -h /mnt/cdrom
Filesystem Size Used Avail Capacity Mounted on
/dev/disk1 3.1G 3.1G 0B 100% /mnt/cdrom
darkstar:~/plscsi$


Bytes 2-5 (we count from zero) are the total number of blocks - 1 on a disk. Blocks 7-8 are the sector byte size (which should be 2048 bytes for the optical discs)

So for example
800h = 2048 bytes/sector
1894FFh = 1611007

1611008 sectors * 2048 bytes = 3299244384 bytes ~= 3.1 G which is what df confirms.

Then you READ(10) the blocks on the disk:

darkstar:~/plscsi$ plscsi -v -x "28 00 00:00:00:10 00 00:01 00" -i x800
x 00000000 28 00 00:00:00:10 00 00:01 00 .. .. .. .. .. .. "(@@@@P@@A@"
x 00000000 01:43:44:30 30:31:01:00 20:20:20:20 20:20:20:20 "ACD001A@ "
x 00000010 20:20:20:20 20:20:20:20 20:20:20:20 20:20:20:20 " "
x 00000020 20:20:20:20 20:20:20:20 4B:55:4D:49 54:41:43:48 " KUMITACH"
x 00000030 49:20:20:20 20:20:20:20 20:20:20:20 20:20:20:20 "I "
x 00000040 20:20:20:20 20:20:20:20 00:00:00:00 00:00:00:00 " @@@@@@@@"
x 00000050 00:95:18:00 00:18:95:00 00:00:00:00 00:00:00:00 "@UX@@XU@@@@@@@@@"
x 00000060 00:00:00:00 00:00:00:00 00:00:00:00 00:00:00:00 "@@@@@@@@@@@@@@@@"
x 00000070 00:00:00:00 00:00:00:00 01:00:00:01 01:00:00:01 "@@@@@@@@A@@AA@@A"
x 00000080 00:08:08:00 2A:00:00:00 00:00:00:2A 01:01:00:00 "@HH@*@@@@@@*AA@@"
x 00000090 00:00:00:00 00:00:01:02 00:00:00:00 22:00:03:01 "@@@@@@AB@@@@"@CA"
x 000000A0 00:00:00:00 01:03:00:08 00:00:00:00 08:00:6A:07 "@@@@AC@H@@@@H@jG"
x 000000B0 01:0C:17:30 00:02:00:00 01:00:00:01 01:00:4B:55 "ALW0@B@@A@@AA@KU"
x 000000C0 4D:49:54:41 43:48:49:20 20:20:20:20 20:20:20:20 "MITACHI "
x 000000D0 20:20:20:20 20:20:20:20 20:20:20:20 20:20:20:20 " "
...
x 00000220 20:20:20:20 20:20:20:20 20:20:20:20 20:20:20:20 " "
x 00000230 20:20:20:20 20:20:20:20 20:20:20:20 20:20:44:56 " DV"
x 00000240 44:20:53:74 75:64:69:6F 20:50:72:6F 3A:34:2E:30 "D Studio Pro:4.0"
x 00000250 2E:33:2C:20 44:53:50:49 6E:74:65:72 66:61:63:65 ".3, DSPInterface"
x 00000260 3A:33:38:32 2C:20:44:56 44:41:75:74 68:6F:72:69 ":382, DVDAuthori"
x 00000270 6E:67:3A:33 37:32:2C:20 44:56:44:42 61:73:65:3A "ng:372, DVDBase:"
x 00000280 33:39:36:28 45:6E:63:6F 64:65:72:3A 20:34:38:33 "396(Encoder: 483"
x 00000290 29:2C:20:4F 78:79:67:65 6E:65:3A:34 30:39:20:20 "), Oxygene:409 "
x 000002A0 20:20:20:20 20:20:20:20 20:20:20:20 20:20:20:20 " "
...
x 00000310 20:20:20:20 20:20:20:20 20:20:20:20 20:20:20:20 " "
x 00000320 20:20:20:20 20:20:20:20 20:20:20:20 20:32:30:30 " 200"
x 00000330 36:30:37:30 31:31:32:32 33:34:38:30 30:00:30:30 "6070112234800@00"
x 00000340 30:30:30:30 30:30:30:30 30:30:30:30 30:30:00:30 "00000000000000@0"
x 00000350 30:30:30:30 30:30:30:30 30:30:30:30 30:30:30:00 "000000000000000@"
x 00000360 30:30:30:30 30:30:30:30 30:30:30:30 30:30:30:30 "0000000000000000"
x 00000370 00:01:00:00 00:00:00:00 00:00:00:00 00:00:00:00 "@A@@@@@@@@@@@@@@"
x 00000380 00:00:00:00 00:00:00:00 00:00:00:00 00:00:00:00 "@@@@@@@@@@@@@@@@"
...
x 000007F0 00:00:00:00 00:00:00:00 00:00:00:00 00:00:00:00 "@@@@@@@@@@@@@@@@"
// 0 = plscsi.main exit int
darkstar:~/plscsi$


In the READ(10) CDB 28 00 xx:xx:xx:xx 00 yy:yy 00
bytes 2:3:4:5 (xx) are the start blocks to read from. 16 is generally the first block on optical media. Bytes 7:8 (yy) are number of blocks to read (yes, you can do bulk). I only want one block, and previous CDB told me how large are blocks on this media, so I expect back 800h = 2048 bytes.

Indeed in the drive is a DVD that was authored using Apple DVD Studio Pro and labeled "KUMITACHI". 2006-07-01 12:23:48 is the creation date and time.

In reality, if you are writing the real thing, you want to read in 3 different places on a disk to obtain the Anchor Volume Descriptor Pointer. It can be 256 blocks into the filesystem, at the last block of the filesystem, or at the (last block - 256) block of the filesystem. Last two cases are more common with rewritable media that was not finalized. Since HD-DVDs are pressed and generally reasonably well authored, currently I just ignore the other two cases.

So... 256 = 100h and we started 16 blocks into the disk, so, we want to start by reading 272 (110h) blocks in, and parse the AVDP to figure out where Main Volume Descriptor Sequence is. MVDP will give us either a Logical Volume Descriptor (likely) or Partition Descriptor (very unlikely to see in the field now a days, and comes up on disks that have say HFS+ filesystem and UDF filesystem on them, so I currently just ignore this.) location. Both of the above will point us at the File Set Descriptor, that in turn will give us Root Directory File Entry location (Recall that directories are just files, that have File ID Descriptors of their children files as their File Data).

And then you traverse the disk, parse the FSD, get the RDFE, parse RDFE, find the correct file corresponding to the correct subdirectory, read it's FD, and figure out which block corresponds to the file you want.

I do some of this using scripts, and a fair bit of the above by hand right now (decoding file descriptors, parsing RDFE, etc). I am not sure what my current time commitments are, and if I'll have an opportunity to code something, so if anyone wants to get a crack at this, and contribute a module for aacskeys - Go for it! BD fans - here is your opportunity to shine!

UDF specs are at http://www.osta.org/specs/

arnezami
29th April 2007, 08:32
This may be a stupid question. :D

But has anyone tried to retrieve a VUK for a BDAV disc using bluray key finder (http://forum.doom9.org/showthread.php?p=941504#post941504)?

If we had a VUK it would be possible to see if we can properly decrypt/dump a bdav disc. If so then we know what VUK a certain disc has and we would have a validated crib to work with. Which would make it easier to figure out the LBA Extend/Binding Nonce/AES-H/Usage file/Kpa stuff.

If you haven't tried this yet please do :).

arnezami

PepsiLee2001
29th April 2007, 10:45
This may be a stupid question. :D

But has anyone tried to retrieve a VUK for a BDAV disc using bluray key finder (http://forum.doom9.org/showthread.php?p=941504#post941504)?

If we had a VUK it would be possible to see if we can properly decrypt/dump a bdav disc. If so then we know what VUK a certain disc has and we would have a validated crib to work with. Which would make it easier to figure out the LBA Extend/Binding Nonce/AES-H/Usage file/Kpa stuff.
arnezami


I had tried it, but bluray key finder can't find it.

mrazzido
29th April 2007, 11:27
I had tried it, but bluray key finder can't find it.

hey!

when you have time

made with winhex a copy of the ram from "win dvd"

pack this with rar .

upload to rapidshre i try to find the key in the ram then.

for BDAV

i think its another OFFSET.

arnezami
29th April 2007, 12:41
I had tried it, but bluray key finder can't find it.

Does it work for normal (prerecorded) movies?

arnezami


PS. Only post links to your memdumps privately (using pms). Because they (could) contain sensitive information about your drive.

mrazzido
29th April 2007, 12:48
PS. Only post links to your memdumps privately (using pms). Because they (could) contain sensitive information about your drive.



yeah i know

to pepsilee2001




when you made a memdump send it to my PM.

PepsiLee2001
29th April 2007, 14:46
Does it work for normal (prerecorded) movies?


Yes, it work fine for normal BDMV.


Does it work for normal (prerecorded) movies?

PS. Only post links to your memdumps privately (using pms). Because they (could) contain sensitive information about your drive.

OK, It's uploading.

arnezami
4th May 2007, 08:30
Hi all,

The time I talked about earlier has come.

Thanks for all :thanks:.

Here are all the source and exe files of my programs:

aacskeys v0.2.6 (exe) (http://www.sendspace.com/file/q44d83)
aacskeys v0.2.6 (source) (http://www.sendspace.com/file/5vrl6g)

fetchvid v0.2.13 (exe) (http://www.sendspace.com/file/cflczv)
fetchvid v0.2.13 (source, very messy, read remarks) (http://www.sendspace.com/file/g15bcu)

fwchecksum (exe) (http://www.sendspace.com/file/uqhj99)
fwchecksum (source, messy) (http://www.sendspace.com/file/cuftuf)

dumpvid v0.3 bd (exe) (http://www.sendspace.com/file/c1g2h0)
dumpvid v0.3 bd (source) (http://www.sendspace.com/file/kse5xd)

Or on rapidshare (http://forum.doom9.org/showthread.php?p=1010630#post1010630).

All my contributions to these programs are released in Public Domain.

Remember: always keep going as a collective :).

Double your efforts. ;)

Bye

arnezami

PS. Just to be clear: yes this is my last post.

mrazzido
4th May 2007, 08:53
Hey! arnezami great for source files!

i hope no one used this source to build there own programm and made profit!!!

insomniak1981
4th May 2007, 12:10
Many thanks for all your time and hard work arnezami, you will be greatly missed.

bourke
4th May 2007, 12:43
Hi all,
The time I talked about earlier has come.

Does anyone have a link to the post(s) where he mentioned this before?

mrazzido
4th May 2007, 12:47
Does anyone have a link to the post(s) where he mentioned this before?





http://forum.doom9.org/showthread.php?p=993940#post993940

zeroprobe
4th May 2007, 16:33
Why is he disappearing?

KenD00
4th May 2007, 19:50
These are very sad news, you have done great work for the community, i wish you all the best.

:rolleyes:

lightshadow
4th May 2007, 20:36
Yes, we can't thank you enogh for you exceeding huge contribution to the world!

We owe you greatly!

I hope you or someone sets up a PayPal (if it is anonymous?) account for people to donate $1. I think it would be a success.

I hope you have left us a red button to press, or a projector with your logo on we can point to the sky, if we ever should need your help =)

Thanks!

Orion17
4th May 2007, 21:25
Yes, Thank You arnezami. I am sure you have your reasons for leaving and wish you the best bro. I have been a silent reader since the whole Muslix64 stuff started and got to say that you have inspired us all to continue this quest as best that we can. You will be missed dude. :(

Pelican9
4th May 2007, 22:38
Hi all,

The time I talked about earlier has come.



Thank you very much! :thanks:

dirio49
5th May 2007, 00:43
Thank for all you have done.
You will be missed. :thanks: :thanks:

xyz987
5th May 2007, 01:55
PS. Just to be clear: yes this is my last post.

A great loss for us. You always will be remenbered here. Just a word:

:thanks:

HyperHacker
5th May 2007, 08:55
It's been nice having you around. You've done fantastic work for the good of users everywhere.

greath
5th May 2007, 11:59
Yes, my thanks also. A very knowledgable person who has contributed immeasureably to furthering our knowledge. Best of luck for your future endeavours.

cwl7454
6th May 2007, 10:46
According to itpro :search: the big boys have criticized the AACS LA for taking so long to react to the broken encryption scheme.

BD+ (a much more secure encryption scheme) is start being utilized out next month.:devil:

Congrats to all who have put so much time and effort into wounding the giants.:thanks:

JK1974
7th May 2007, 00:01
arnezami, thanks a lot for your effort in trying to create a fair-to-use multimedia future. With your work here you have become for sure a legend like DVD Jon and muslix64.

BTW: Good luck - and don´t get caught. :)

lightshadow
7th May 2007, 01:10
arnezami, thanks a lot for your effort in trying to create a fair-to-use multimedia future. With your work here you have become for sure a legend like DVD Jon and muslix64.

Yes, I hope someone (with a little more knowledge than me about this subject) will put him in to the history book (http://en.wikipedia.org/wiki/Advanced_Access_Content_System) =)

Actually, he and Muslix64 was mentioned, but for some reason all names have been removed.

In fact, I think in this hack, the credits should be given to a few more. awhitehead, FoxDisc, Geremia, and xt5 are names that spring to my mind, just to limit it to a top 5.

Clearly there have been more important hackers and testers that couldn't have been done without. Not to forget the brains at the Understanding AACS (including Subset-Difference) (http://forum.doom9.org/showthread.php?t=122363&page=1) thread and the programmers in this thread =)

I think we will see more to Boing99 in the next round of AACS DRM hackers. =)

eousphoros
9th May 2007, 01:14
I had some trouble getting the original aacskeys working in linux (haven't looked at the latest source release yet) so I ported it to be linux friendly and also included a sha1 hash.. and modified the output a little bit. Here it is with source.. its ugly but the output is right :)

Galileo2000
9th May 2007, 03:28
OK, it might be my last post on this forum as well.

Feeling under double pressure I think the time has come.

Of course I did not contribute even close to 0.1% compared to arnezami but at least I've tried to discuss and offered some solutions when I knew the answer.

Now they can have their formats and shave it in their A$$.

I will not spend $0.01 on either format.

If you want to talk to me, you know where to find me: http://www.avsforum.com.

I am done with this $rap.

Bye comrades.

Pelican9
9th May 2007, 10:01
OK, it might be my last post on this forum as well.

Feeling under double pressure I think the time has come.

Of course I did not contribute even close to 0.1% compared to arnezami but at least I've tried to discuss and offered some solutions when I knew the answer.

Now they can have their formats and shave it in their A$$.

I will not spend $0.01 on either format.

I am done with this $rap.

Bye comrades.

Hmmm. What happened? Double pressure? By who?

zeroprobe
9th May 2007, 12:39
aacs la must be paying everybody off lol.

muslix64, janvitos, arnezami, galileo ....

bigdog660
9th May 2007, 16:02
Props to everyone that has helped.:thanks: I've been following this from day one.

Given the sesitivity of this issue, you'd think our main contribs such as muslix64, janvitos, arnezami, galileo, etc. would have used fake reg info, fake location, one time email adds and anonymous surfing (proxy servers) to help protect themselves.

And if they did, I sure am clueless on how they still got pressured.:confused:

Anyway, good luck to all, and again, thanks for everything.

greath
10th May 2007, 13:23
aacs la must be paying everybody off lol.

muslix64, janvitos, arnezami, galileo ....

More like harrassing them. I wonder if there's a law against harrasment over the Internet.

Galileo2000
10th May 2007, 14:43
Guys, I need to make another post after my last post.

AACS LA did not contact me.

My decision to leave was for the different than that reasons.

So don't be afraid, we are not on that stage of the game, at least not yet.

My apologies if my post was ambigous on that matter.

I hope this post clears it up.

All the best.

heman
3rd June 2007, 18:14
are there some mirrors of arnezami's tools posted here?
http://forum.doom9.org/showpost.php?p=999019&postcount=155

arnezami
4th June 2007, 17:28
Pfff....

http://rapidshare.com/files/35218493/aacskeys_v0.2.6.rar.html

http://rapidshare.com/files/35218695/aacskeys_source_v0.2.6.rar.html


http://rapidshare.com/files/35219018/fetchvid_v0.2.13.rar.html

http://rapidshare.com/files/35219077/fetchvid_source_v0.2.13.rar.html


http://rapidshare.com/files/35218795/fwchecksum.rar.html

http://rapidshare.com/files/35218857/fwchecksum_source.rar.html


http://rapidshare.com/files/37033433/dumpvid_v0.3_bd.rar.html

http://rapidshare.com/files/37033559/dumpvid_v0.3_bd_source.rar.html

Revgen
8th June 2007, 20:36
@arnezami

Is that new version of AACSKeys ready yet?

arnezami
8th June 2007, 20:50
@arnezami

Is that new version of AACSKeys ready yet?

Ehm. No. Not yet.

But for the moment you can use v0.2.6 in combination with DumpHD. For MKB v3 HD DVDs you first need vid.exe to get a VID (build by xt5) and for MKB v3 BDs you first need dumpvid (by KenD00 and adapted by me, see previous page) using the new PowerDVD to get a VID.

Regards,

arnezami

paranoid87
16th June 2007, 17:14
hmm,

i currentlky use powerdvd, so DumpHD..must not be an issue..i can get a VID.

arnezami
16th June 2007, 17:54
Here is a new version of aacskeys:

http://www.sendspace.com/file/dt7o5o

Its an in-between version. But what it does already is automatically detect the xbox add-on drive and get the vid through our hack. So no need for a new Host Private Key, vid.exe or sniffing Volume IDs for HD DVD owners anymore :D. And its even (much) faster than the official method...

No flashing needed. So those that have the Xbox HD DVD drive: please test it ;).

Working on more stuff:

- incorporating vid hammering (especially for Blu-Ray drives)
- better errors and stopping when something goes wrong
- combining with DumpHD

Regards,

arnezami

SvT
16th June 2007, 18:06
arnezami !

I can report SUCCES :)

After copying the ProcessingDeviceKeysSimple.txt from a previous version to the same directory it ran without any problem !

E:\Progs\HD-DVD\aacskeys_v0.2.7>aacskeys h
aacskeys v0.2.7

Volume Unique Key: 79E3ABB4B7DBD2D37CC0B33F80812433
TKF Hash (DiscID): CD8A706BA7D6A44744F940103F51D57A63626A00

E:\Progs\HD-DVD\aacskeys_v0.2.7>

Now let me check if the numers are correct !

CD8A706BA7D6A44744F940103F51D57A63626A00=Bourne Supremacy (EU) |V|10/28/06| 79E3ABB4B7DBD2D37CC0B33F80812433 :) :) :)

Instead of the "powerDVD 7.1" numers (certificate and stuff) it now gives me my drive FW number !

Thanks for this cool program ! :)

arnezami
16th June 2007, 18:16
Ah ok :)

I changed the link so now the text file with both Processing Keys is included ;)

A verbose test would also be nice. And a test with an MKB v3 HD DVD.

arnezami

SBeaver
16th June 2007, 18:23
So does the xbox hack still require flashing a new firmware or does it get the vid through some kind of workaround? Maybe this was mentioned before

SvT
16th June 2007, 18:25
Here is the verbose output !

E:\Progs\HD-DVD\aacskeys_v0.2.7>aacskeys h v
aacskeys v0.2.7

Current path: E:\Progs\HD-DVD\aacskeys_v0.2.7
Device key: AA856A1BA814AB99FFDEBA6AEFBE1C04
Processing key: 09F911029D74E35BD84156C5635688C0
Encrypted C-value: 607101739330EB82601790C3C25F0224
Corresponding uv: 00000001

Decrypted C-value: 04E23CE9FCEAF1EDC3ED4C6F2E0A6972
Media key: 04E23CE9FCEAF1EDC3ED4C6F2E0A6973

Encrypted verification data: FB7515969AE048DE773C85C9C3728C29
Decr verif data should be: 0123456789ABCDEF
Decrypted verification data: 0123456789ABCDEF39CF7A719194F14F

Drive FW info: MC0810/03/06

AGID: 00

Volume ID: 40001027200607200020202020200000

Volume Unique Key: 79E3ABB4B7DBD2D37CC0B33F80812433
TKF Hash (DiscID): CD8A706BA7D6A44744F940103F51D57A63626A00
Title Key File MAC: D0FFF212615C4A28FEE9D4BE12DF484D
TKF MAC should be: D0FFF212615C4A28FEE9D4BE12DF484D

Encrypted Title Key 1: 19F4D956D76909C9D5DDD2DA91A303F4
Encrypted Title Key 2: 444AB92C2E962E68C412BA5E411D7354
Encrypted Title Key 3: D5D111BAA474DB0303FB83A881DDB915
Encrypted Title Key 4: EEB06A9345B18338319C667F9FF157A1
Encrypted Title Key 5: 878CB225D4BB02578EA3C98323A4DD7B

Can't help you with MKBv3 :mad: I only own 1 disc......

arnezami
16th June 2007, 18:26
So does the xbox hack still require flashing a new firmware or does it get the vid through some kind of workaround? Maybe this was mentioned before

No flashing needed. Works with the original Xbox HD DVD drive :D.

arnezami

Zotty
17th June 2007, 11:43
Its an in-between version. But what it does already is automatically detect the xbox add-on drive and get the vid through our hack. So no need for a new Host Private Key, vid.exe or sniffing Volume IDs for HD DVD owners anymore :D. And its even (much) faster than the official method...

No flashing needed. So those that have the Xbox HD DVD drive: please test it ;).
Now that's interresting. Any change of me testing this using Linux?

arnezami
17th June 2007, 12:00
Now that's interresting. Any change of me testing this using Linux?

Since this is an in-between version the source is not released. So currently there isn't a way to compile it under linux. However maybe using some VMware might work.

arnezami

Galileo2000
17th June 2007, 18:08
Just tested new version w/ Matrix Reloaded and Matrix Revolutions, MKB v3, works fine.

xbox add-on was used as a drive.

Let me know if you need some more testing or the output from Matrix Reloaded.

Great job, thanks.

Verbose output from Matrix Revolutions is below:




aacskeys v0.2.7

Current path: E:\arnezami
Processing key: 455FE10422CA29C4933F95052B792AB2
Encrypted C-value: A9060B76DA82C88A037F1C7C26C3DA0E
Corresponding uv: 00000049

Decrypted C-value: DEC16A984E6CB59538D654F621E6AFE3
Media key: DEC16A984E6CB59538D654F621E6AFAA

Encrypted verification data: E7D1A8013AB5CF59E211396347FA5829
Decr verif data should be: 0123456789ABCDEF
Decrypted verification data: 0123456789ABCDEFD1DE762378736603

Drive FW info: MC0810/03/06

AGID: 00

Volume ID: 400018074404200457474844564D0000

Volume Unique Key: E94ECC840F0BE02ABB5A2BB8AD85246A
TKF Hash (DiscID): CE20B4BF37E23CE20B2B53AEBFFE3C56315A396F
Title Key File MAC: 399072C4A8D2C400A940A686646F7592
TKF MAC should be: 399072C4A8D2C400A940A686646F7592

Encrypted Title Key 1: 7A31C513CFCDE1EC41FE9952E7615087
Encrypted Title Key 2: 9FE6EA5CB03E8C3C46AB9BB73478E383
Encrypted Title Key 3: 29A428B0540FD7C8083A7AF1363265FC
Encrypted Title Key 4: 46F9B5D8188CDC91E02E36E81DF8D501
Encrypted Title Key 5: AD13B6765478522E4452225406744B34
Encrypted Title Key 6: 284D8A10F9E1485DCDFA2719C6F95A64
Encrypted Title Key 7: B9A136A46C758EC894C83E0C07FA4886
Encrypted Title Key 8: 53A9A1D0FE5920DBEFD7AA006E6E2167
Encrypted Title Key 9: 41E255F9B17E3D989A5137BE78F95922
Encrypted Title Key 10: 8C3352A668E34BC9CD7B0411A7A1D1E7
Encrypted Title Key 11: 2B86DD84BF65927D224BC3CDCA07F147
Encrypted Title Key 12: 5A92BFFDAE65DE32FB6FD32290AD595F
Encrypted Title Key 13: 29D1265DA7C1F09B1B67C4B85D9DDC21
Encrypted Title Key 14: E3B15D7A1D82366AF688C9C96418EF8A
Encrypted Title Key 15: B7525B38B1E3931DFDE0BEEEB79E138E
Encrypted Title Key 16: 6EC4F85ACA0150FF984CA8F9A0A34591
Encrypted Title Key 17: E29E114C54D54B717D30D9C10FE7DC52
Encrypted Title Key 18: D1580D2C16A9AE224B96AC82040F0482
Encrypted Title Key 19: 0A0FC2C7C05B3AEBFD212700954AF00B
Encrypted Title Key 20: 3D12E9D35A823D5DE058B6732C3B278F
Encrypted Title Key 21: CCE24CD2BF253A8C2CD64B16BF613F82
Encrypted Title Key 22: 9617A624F575278CD3B0578F3ABC6C5C
Encrypted Title Key 23: A29945248EFC3EED2C956B85CB87E237
Encrypted Title Key 24: D0C4A4155678ACFF4BEA0C5E37547975
Encrypted Title Key 25: 8CF51F125E1520C89D4D6AF03853FE05
Encrypted Title Key 26: 2B57764651FEA334A191700DA93EB299
Encrypted Title Key 27: FA5946330E989418E5379B1EA928F837
Encrypted Title Key 28: 66FC7FCAA7D59AE60E47AF3AB5A1ABE1
Encrypted Title Key 29: 0E9D8EC0D9029A1BCD1E7B230BA10820
Encrypted Title Key 30: C8AC7BADE4004CEF67068D8C81D2CC91
Encrypted Title Key 31: F5A180E3DDB0D8FB16F75119525F24E9
Encrypted Title Key 32: 9EDC0F3084724E68DCBDC61B27BE25CA
Encrypted Title Key 33: E5C99420ABDF298840079970200558E9
Encrypted Title Key 34: 4FDF6108361CED8C46E3F963AACA839C
Encrypted Title Key 35: 1E758C21C820E63DAC28125F84E9AB32
Encrypted Title Key 36: 902DD5EC92CEF9E7C8F534AB807CDECD
Encrypted Title Key 37: 3BFD1141DF3E03CC1E9448FB1D1E8F67
Encrypted Title Key 38: B8AB4437340373EB0FB0033A71F25BB1
Encrypted Title Key 39: 07EB58BD3BE017799ECA32403BCA1621
Encrypted Title Key 40: 25791E29B8965E99F6E655738DB1ED67
Encrypted Title Key 41: DAB83F3E439AF0AE99CEB1059DEFE1B2
Encrypted Title Key 42: C9B88C752589C59BCBA63341D64970A0
Encrypted Title Key 43: E8C89EAF4B84D8F9551B0419F5D0AD0D
Encrypted Title Key 44: E68F7703AD35631608EF7211C38292EA
Encrypted Title Key 45: D88984613E990FE29A3A8E25E8DF6B4F
Encrypted Title Key 46: C342359535B2F84CDA8CCB15311E6C93
Encrypted Title Key 47: 74712670CD7FF3E54497872A7400B81E
Encrypted Title Key 48: C6F67FB1CF33E9D8B7ED8C1C5B45DF41
Encrypted Title Key 49: 7DD9EDB71B18DA677BEEB30144DE09F8
Encrypted Title Key 50: 5E6BA1C49AEA29DDD5480D0046A74744
Encrypted Title Key 51: FC8F5259686D4D439B6619A15CBA1F13
Encrypted Title Key 52: 3CB0E454238B47AB29E115508AC6DC8A
Encrypted Title Key 53: CCE460C7673635F5064FF84ACE613B31
Encrypted Title Key 54: D380B35D5E14F186A6D1AEEDDA2F901C
Encrypted Title Key 55: D881B5CB319671D0195E883E1BA959F6
Encrypted Title Key 56: B90491B884B8B918530C087C730F9019
Encrypted Title Key 57: 4B17E2C1FEAD481D0F5FE2422815E74A
Encrypted Title Key 58: 25F9E442F0C7F4108A0F7F47B4263A06
Encrypted Title Key 59: 36E977772A2535E82DC8A3AF0B06808E
Encrypted Title Key 60: 0D850B79F6323B07FF701682982EBDF1
Encrypted Title Key 61: 3FA417FC9691F6435F4492EDD77BD1A6
Encrypted Title Key 62: 99861E2F5D46359998389010EE3D0C96
Encrypted Title Key 63: 9FA9BE058789AA1DC27F9CB0E553C58E
Encrypted Title Key 64: FBC64EA5075FE7ECBC67F1435E284827

Decrypted Title Key 1: 708C3DA990BFFB794EA70CAC08E4BD9B
Decrypted Title Key 2: BCA3BDD708D89B3EA23E91D080F7DB20
Decrypted Title Key 3: B7B0BFF3AC5B0C63CD3B182CF5B29BEC
Decrypted Title Key 4: DF5E7AE1C8652958EF28E01032D20C0E
Decrypted Title Key 5: FD923782EB4E1FD6F75C645B75D28D72
Decrypted Title Key 6: 24D4242CB52A8D945F66BFCC59549C68
Decrypted Title Key 7: 8F700271F4BC2B0BD41EF652C354A99D
Decrypted Title Key 8: ADDB9BE6689D7BEAE3E59320157B6D87
Decrypted Title Key 9: 95F6BF842BD4245F3E33724AF3501BFD
Decrypted Title Key 10: 628AFEE1961E8957355B59C11852FE6D
Decrypted Title Key 11: 62F334F5155323E0540F887D6091B9AB
Decrypted Title Key 12: 59629C6CCB8AF0E03FEAD7BB49C32A16
Decrypted Title Key 13: 74961844D9C83E884F82C143E2883FF8
Decrypted Title Key 14: F11F147BB1E9144F1D9CD968BCFDEB61
Decrypted Title Key 15: 8F8B6E75C75265C981598A88D3ECC95A
Decrypted Title Key 16: 61BDE8AA45370E19288DD1309176777A
Decrypted Title Key 17: B57627DFF4B0E5D55D83E3C6970A3B70
Decrypted Title Key 18: 21E1ED862DE831576BF92D25726CDF7E
Decrypted Title Key 19: E2B85AF3893B129F9C5ADF6DB14723A7
Decrypted Title Key 20: 9FC1BD02F435BCDD93729F93A4EA6587
Decrypted Title Key 21: F0F873090FB89E5DEDCB0B5B64B711F3
Decrypted Title Key 22: 7BC51272CA6F647E0C2EF832CC13990C
Decrypted Title Key 23: 66558F995528EB8F1EF6856E55D2A8F3
Decrypted Title Key 24: 4708A0DF8E40556F16B9E52D980847C6
Decrypted Title Key 25: B81DB68F6243F63F651C7BB104E818B0
Decrypted Title Key 26: 0C944E221048859043DC5690BCE234F0
Decrypted Title Key 27: E275D5C0EC6E70FDB34A3544DFF6E075
Decrypted Title Key 28: 97D80234B96594E1DF7F9EA12FCAE6E9
Decrypted Title Key 29: E030EE1DEE5EDBF3B164F760F77DE6C5
Decrypted Title Key 30: DB9F1B560D865157EACC0F3EB086845B
Decrypted Title Key 31: 3E269A4D5713BC388A811801F56A11C0
Decrypted Title Key 32: 7C0651ECCC527B220181AB27D83F152B
Decrypted Title Key 33: 04036CC99292007D8EB821CA680DB478
Decrypted Title Key 34: 62127EEBD0393AD0C2B6F4F990CBB425
Decrypted Title Key 35: BFA54FB7DDC973FCE9CECA054BAFDF62
Decrypted Title Key 36: A856C07D63870AC0EB8C2D58B3A1A65F
Decrypted Title Key 37: 643B47623B850ED4E8014B6B54A99506
Decrypted Title Key 38: E852991122F4E236975DD8677ADE6F82
Decrypted Title Key 39: 35C5E6F8C45729BE59D716397B65008C
Decrypted Title Key 40: 95AD563298514383B561B6B4917C8275
Decrypted Title Key 41: 38DF7381CE94F29E28FB0510854C165C
Decrypted Title Key 42: 95EA80ECE5E790B76579E8506C5F8E46
Decrypted Title Key 43: 7F42BC78C596BD3BCE7417A32FBC08DD
Decrypted Title Key 44: 07D48467AD8891BA351B2252B4BDBBDF
Decrypted Title Key 45: 245F8F40958B8325541A8818DE23F8A1
Decrypted Title Key 46: 284FBBA0C6126FDBCB68B98F35DD5A72
Decrypted Title Key 47: 7F27113583567B0E9DD1AE848A69F41C
Decrypted Title Key 48: C021849410F9CE36741165B50C36CC8F
Decrypted Title Key 49: 9CB387D10465CFB526EFF8E805C84F7B
Decrypted Title Key 50: 6ECF2FCD490157D803C1B85B15D271ED
Decrypted Title Key 51: FF8DC5A3888CC267443F9E66F4C41EE7
Decrypted Title Key 52: 8CA24F1FCCB1C7056F5A94D2DE407075
Decrypted Title Key 53: 61AED602F85EC7E6FA44DF27584C0F54
Decrypted Title Key 54: FA5A52289AB32B1D0125C7E5A89F8787
Decrypted Title Key 55: 3B03D5D74407D3068B9081F2C422AAF7
Decrypted Title Key 56: 6BF3424A9F88217758225BD7E6CB5D63
Decrypted Title Key 57: CC32DF462913768EC68ABFED3D24AE8C
Decrypted Title Key 58: 5235F69F5309723C8F7AEC0EA9922EB7
Decrypted Title Key 59: 2D371EC4FECD046F9F25F6C281F18B5C
Decrypted Title Key 60: 10F33256731752AD99CE60C8C33432BD
Decrypted Title Key 61: E01CA81B9A647B671DF982DF9BB3C35E
Decrypted Title Key 62: 4B10821FA4F12EF995973E6EE178B4A5
Decrypted Title Key 63: CEFF4965A1583F068F7AF8B6CAE4DF64
Decrypted Title Key 64: A865E5DB0C079E055BFA91287ACDA5D5

arnezami
17th June 2007, 18:20
Just tested new version w/ Matrix Reloaded and Matrix Revolutions, MKB v3, works fine.

xbox add-on was used as a drive.
Arnezami, let me know if you need specifics on MKB v3.

Great job, thanks.

Ok. Thanks. Seems to work pretty good.

Keep in mind it checks if the FW is MC0810/03/06. Maybe some people have newer FW versions though. It won't do the "trick" but we would be really interested in that FW revision! :).

arnezami

Galileo2000
17th June 2007, 18:38
Ok. Thanks. Seems to work pretty good.

Keep in mind it checks if the FW is MC0810/03/06. Maybe some people have newer FW versions though. It won't do the "trick" but we would be really interested in that FW revision! :).

arnezami

You are too fast, I just posted the entire output of the program.

Do you know where to get a new version of the firmware? I don't feel like logging in to Xbox live...

I have two xbox add-ons, might as well flash one...

arnezami
17th June 2007, 18:46
You are too fast, I just posted the entire output of the program.

Do you know where to get a new version of the firmware? I don't feel like logging in to Xbox live...

I have two xbox add-ons, might as well flash one...

No idea if there even exists a new revision. But there is bound to come a new one sometime. If so it will be very interesting ;).

Thanks for the output btw :).

Galileo2000
17th June 2007, 18:52
No idea if there even exists a new revision. But there is bound to come a new one sometime. If so it will be very interesting ;).



Oh yes, there is. Look here:

"While we look forward to enjoying these new features, we wouldn't be one bit surprised if Microsoft also figured out a way to secure that pesky AACS hardware key that has caused such a ruckus."


http://www.engadgethd.com/2007/05/16/xbox-360-hd-dvd-add-on-drive-update/





Thanks for the output btw :).

Pleasure is all mine :D

arnezami
17th June 2007, 18:58
Oh yes, there is. Look here:

"While we look forward to enjoying these new features, we wouldn't be one bit surprised if Microsoft also figured out a way to secure that pesky AACS hardware key that has caused such a ruckus."

http://www.engadgethd.com/2007/05/16/xbox-360-hd-dvd-add-on-drive-update/


I'm pretty sure the famous "May Update" does not flash the drive at all. It does update the (software) player etc however.

arnezami

laserfan
17th June 2007, 19:30
Here is a new version of aacskeys...an in-between version. But what it does already is automatically detect the xbox add-on drive and get the vid through our hack.Does anyone here know if this will work with the HP HD100 (now on sale for $129 AR at Fry's)?

Galileo2000
17th June 2007, 19:37
Does anyone here know if this will work with the HP HD100 (now on sale for $129 AR at Fry's)?

I've heard HP uses the same Toshiba drive. If so, yes, it most probably will work.

If not, it won't work the same "easy" way as Arnezami mentioned because of the different firmware.

arnezami
17th June 2007, 19:38
Does anyone here know if this will work with the HP HD100 (now on sale for $129 AR at Fry's)?

Wow. Thats cheap! :)

No the xbox HD DVD trick won't work on the HP HD100. Although maybe we can find a similar exploit. Cheap drives and firmware hackers are made for eachother ;).

Anyway. As long as no exploit is found for a drive you would still be able to decrypt your discs though. You would need to use either dumpvid (the original by Kend00 for HD DVD) or use fetchvid (made by me). Depending on how it behaves. And you probably need PowerDVD 7.3 (upgraded) for it. Unless you only have old discs because then none of this is needed. But I'm assuming you want to buy new discs in the future.

Ooh. Nearly forgot. If its an usb drive you can always sniff the usb as a "fallback method". And then there is of course the online list of vuks here on this forum (if your title is in it no need for getting a vid at all, aacskeys isn't needed anymore).

arnezami

laserfan
18th June 2007, 00:59
Thanks arnezami for your complete reply!

...you can always sniff the usb as a "fallback method".Sounds kinda perverse... ;)

I dunno what this means but if I need to, I will do a "Search"! Many thanks...

mlansell
18th June 2007, 23:43
Hmmm. I tried the new version but all I get is this:


aacskeys v0.2.7


Could not find a Processing Key or Device Key resulting in the Media Key.

Aborting...


If I rename the ProcessingDeviceKeysSimple.txt file it reports that it cannot find it, so it must be trying to load it from the correct place.

I'm using an Xbox360 drive, and the disk is the UK edition of Corpse Bride.

If I use my ancient version of aacskeys, it reports an incorrect VUK, so I presume this disk requires the newer processing key.

Any ideas?

Mal

arnezami
18th June 2007, 23:49
Hmmm. I tried the new version but all I get is this:



If I rename the ProcessingDeviceKeysSimple.txt file it reports that it cannot find it, so it must be trying to load it from the correct place.

I'm using an Xbox360 drive, and the disk is the UK edition of Corpse Bride.

If I use my ancient version of aacskeys, it reports an incorrect VUK, so I presume this disk requires the newer processing key.

Any ideas?

Mal

Whats in your ProcessingDeviceKeysSimple.txt file? Two keys? Which ones?

Can you also check the MKBROM.AACS file with WinHex and post the first 16 bytes of that file (in hex)?

Does it play with PowerDVD/WinDVD? Does AnyDVD work on it?

What are the dates of the files in the AACS directory of the disc?

arnezami

mlansell
19th June 2007, 21:43
Whats in your ProcessingDeviceKeysSimple.txt file? Two keys? Which ones?
Two keys:
09F911029D74E35BD84156C5635688C0 ; Processing Key MKB v1
455FE10422CA29C4933F95052B792AB2 ; Processing Key MKB v3

Can you also check the MKBROM.AACS file with WinHex and post the first 16 bytes of that file (in hex)?
10 00 00 0C 00 04 10 03 00 00 00 03 21 00 00 64

Does it play with PowerDVD/WinDVD? Does AnyDVD work on it?
I can't play it with PowerDVD because despite having paid good money for HDCP compliant hardware, the graphics card is not on the "list", so it refuses to play. That's why I'm interested in removing this DRM horsesh*t.

My trial for AnyDVD ran out a while back. I don't really want to buy it, but if the other information I've listed here doesn't help, I guess I may have to.

What are the dates of the files in the AACS directory of the disc?
14/04/2007 09:27

Thanks

M.

Zotty
19th June 2007, 22:22
Since this is an in-between version the source is not released. So currently there isn't a way to compile it under linux. However maybe using some VMware might work.

arnezami
A little offtopic, but I just got the authentication skip method working in decrypthd, including FW checking. So I'm happy afterall ;)

Bottomline is this works in Linux aswell and seems indeed to be faster compared to actually doing authentication. Unfortunately I've got the same firmware as mentioned above, so no news there.

edit:
To be more exact;
- no authentication: 0,098 seconds
- with authentication: 1,640 seconds


10 00 00 0C 00 04 10 03 00 00 00 03 21 00 00 64

That's a v3 MKB alright.

dirio49
19th June 2007, 23:45
@Zotty.
when are you going to release it? :D

Zotty
20th June 2007, 07:56
Errr.. haven't thought about that yet. Been experimenting a bit with this and optimization. But I've also been quite busy at work lately, so development is going a bit slow.

Anyways, let's not hijack this thread. This one is about aacskeys ;)

arnezami
20th June 2007, 20:03
@mlansell: check you pm box. ;)

arnezami
23rd June 2007, 18:19
Hmmm. I tried the new version but all I get is this:



If I rename the ProcessingDeviceKeysSimple.txt file it reports that it cannot find it, so it must be trying to load it from the correct place.

I'm using an Xbox360 drive, and the disk is the UK edition of Corpse Bride.

If I use my ancient version of aacskeys, it reports an incorrect VUK, so I presume this disk requires the newer processing key.

Any ideas?

Mal
I removed a pretty major bug in aacskeys which caused this sometimes. In fact KenD00 already pointed this out to me earlier. Anyway should work now :).

aacskeys v0.2.8 (http://www.sendspace.com/file/sull3p)

Please test it.

arnezami

mlansell
24th June 2007, 00:00
I removed a pretty major bug in aacskeys which caused this sometimes. In fact KenD00 already pointed this out to me earlier. Anyway should work now :).

aacskeys v0.2.8 (http://www.sendspace.com/file/sull3p)

Please test it.

arnezami

The new aacskeys works like a dream - great work, Arnezami :-)

BTW, using AnyDVD worked as well. However, if I then try to play the decrypted pevob_1.evo in PowerDVD, it glitches for the first minute or so. Playback in Windows Media Player / Media Center is fine.

Using the key from Aacskeys to decrypt via BackupHDDVD has no such troubles.

The files produced by both methods are exactly the same size.

Weird eh?

M.

Pelican9
26th June 2007, 12:28
The files produced by both methods are exactly the same size.


Why don't compare the contents of the two file?

mlansell
26th June 2007, 14:53
Why don't compare the contents of the two file?

I would, but I don't have the corrupt one anymore. I suppose I could try it again and see if it comes out corrupt the second time...

mrazzido
27th June 2007, 14:57
Hey! my friends!

got new bluray disc today aacskeys 0.2.8 doesnt work ?? did i anything wrong?

its a new movie 4days here out in our shops.

dumpvid j

DumpVID 0.3 by KenD00 (adapted for bluray testing)

Drive type is recognised as CDROM/DVD.

Sending SPC1 Test Unit CDB6 command..done.
Returned good status.

Press ENTER to start hammering

Hammering drive...
vid: 86C48635F69A116990A78741EDDE574D
Hammering finished.



aacskeys j 86c48635f69a116990a78741edde574d

aacskeys v0.2.8


Could not find a Processing Key or Device Key resulting in the Media Key.

Aborting...




Edit 1:

okay i think i found the "Error" i used the other proccessing key yet " 455FE10422CA29C4933F95052B792AB2 "

edit 2:

hmm the key

Volume Unique Key: D0648FF3A68CF94A8E6FC900DEEB56BE
Unit Key File Hash (DiscID): 509A0A831370A1B4865802D29E05B26C69211B
Encrypted Unit Key 1: 2AA6415E92A27E2EFBAB4779F8522D52

Decrypted Unit Key 1: 6034C6A8459D212E1C00C9C4E98FF868


doenst work :-/ cant decrypt the movie :-(.

arnezami
27th June 2007, 17:52
Hey! my friends!

got new bluray disc today aacskeys 0.2.8 doesnt work ?? did i anything wrong?

its a new movie 4days here out in our shops.




Edit 1:

okay i think i found the "Error" i used the other proccessing key yet " 455FE10422CA29C4933F95052B792AB2 "

edit 2:

hmm the key

Volume Unique Key: D0648FF3A68CF94A8E6FC900DEEB56BE
Unit Key File Hash (DiscID): 509A0A831370A1B4865802D29E05B26C69211B
Encrypted Unit Key 1: 2AA6415E92A27E2EFBAB4779F8522D52

Decrypted Unit Key 1: 6034C6A8459D212E1C00C9C4E98FF868


doenst work :-/ cant decrypt the movie :-(.

Does the "Decrypted verification data" start with 0123456789ABCDEF ? If so the Processing Key is working.

Can you copy-paste the verbose output here so I can better see what is going on. And when trying to decrypt always copy-paste (better not re-type). One bit wrong and it won't work. Try the Volume ID again too...

Does the movie play in PowerDVD btw? What does AnyDVD do?

arnezami

mrazzido
27th June 2007, 18:05
i didnt try anydvd yet.

powerdvd starts the movie but some seconds later it stops because non HDCP / HDMI monitor only DVI .


hmm i see something wrong with volume ID.
its all Zero.


aacskeys v0.2.8

Current path: C:\Users\acid
Processing key: 455FE10422CA29C4933F95052B792AB2
Encrypted C-value: C3934F6EC5B1AE06E15C727D2CE9BD8F
Corresponding uv: 00000049

Decrypted C-value: 72FD3676B3F7FCC7D186813DA5C26D9B
Media key: 72FD3676B3F7FCC7D186813DA5C26DD2

Encrypted verification data: 6548954A05889EB63FA0DB52D4356B5B
Decr verif data should be: 0123456789ABCDEF
Decrypted verification data: 0123456789ABCDEF72F0033722AB4B0C

Drive FW info: AL06 R___

AGID: 01

Host certificate from: Power DVD 7.1
Host certificate (Hcert): 0200005CFFFF0000000C00006E3DEB679B9A16AD
FAA8E30878767BA6EB2A9B415385AD1181B4446C
31E9A5DD2AB808B364FF15885BAC490964318C9B
F8029FCF76F688A54FBDA03F6D9332EF04E5A613
12DA85880A4D9CBB79D8602E
Host Private Key (Hpriv): 4737676058D7029452514F0AB186DC4CCA8C578F
Host Nonce (Hn): 2923BE84E16CD6AE529049F1F1BBE9EBB3A6DB3C

Drive certificate (Dcert): ########################################
########################################
########################################
########################################
########################
Drive Nonce (Dn): ########################################

Drive key point (Dv): ########################################
########################################
Drive key signature (Dsig): ########################################
########################################

Host key (Hk): 5613E7F89B11D9CAA27B610A1096332BEED86BC4
Host key point (Hv): 8A60C80BD60C23605FBE90B27BF96B2DB38195C1
801F54EB29E0F6EC57AC2B9168E88B2D56977508
Host key signature (Hsig): ########################################
########################################

Drive signature wrong/error
Bus key (BK): ################################

Volume ID: 00000000000000000000000000000000
Volume ID MAC: ################################
Volume ID MAC should be: ################################

Volume Unique Key: D0648FF3A68CF94A8E6FC900DEEB56BE
Unit Key File Hash (DiscID): 509A0A831370A1B4865802D29E05B26C69211B3C
Encrypted Unit Key 1: 2AA6415E92A27E2EFBAB4779F8522D52

Decrypted Unit Key 1: 6034C6A8459D212E1C00C9C4E98FF868

arnezami
27th June 2007, 19:05
hmm i see something wrong with volume ID.
its all Zero.

Yep. You need to do this:

aacskeys j 86c48635f69a116990a78741edde574d

I fact you did that earlier see your post above (but then you didn't use the right processing key yet). So just do it again now. It should work :).

mrazzido
27th June 2007, 20:05
thx for help workxx *g

Immie
6th July 2007, 02:54
I think I found a problem, no matter what version of aacskeys I use, it keeps crashing after giving me just the basic keys and noticed something:

Error opening Title Key/Unit Key File: g:\AACS\VTKF000.AACS

Well, my disc doesn't have a VTKF000.AACS file. It's named something else. I've got VTKF090.AACS and VTKF100.AACS. Is there anyway we can get the program updated to work with alternate VTKF files?

In case anyone is curious, this disc is the Freedom anime HD-DVD/DVD episode 1 from Bandai Visual.

arnezami
6th July 2007, 06:19
I think I found a problem, no matter what version of aacskeys I use, it keeps crashing after giving me just the basic keys and noticed something:

Error opening Title Key/Unit Key File: g:\AACS\VTKF000.AACS

Well, my disc doesn't have a VTKF000.AACS file. It's named something else. I've got VTKF090.AACS and VTKF100.AACS. Is there anyway we can get the program updated to work with alternate VTKF files?

In case anyone is curious, this disc is the Freedom anime HD-DVD/DVD episode 1 from Bandai Visual.
Hmmm. Interesting. Could you give the directory listing of the AACS dir?

Thanks.

arnezami

PS. Read your pms.

Immie
6th July 2007, 07:05
Hmmm. Interesting. Could you give the directory listing of the AACS dir?

Thanks.

arnezami

PS. Read your pms.

Sent you a PM about this. Thanks.

sl1pkn07
13th July 2007, 02:23
hi

arnezami: aacskeys v0.2.8 runs on linux? (not include sources)

arnezami
26th July 2007, 17:29
Just a quicky:

I'm totally swamped atm. Will be back. Please have patience ;).

sxt173
28th July 2007, 16:03
@ arnezami

Thanks for this great tool, but having small problem that I can't get sorted out.

When I try to run it off of my C: drive, I get:
C:\>aacskeys k v
aacskeys v0.2.8

Current Path c:\
Could not open file: C:\\ProcessingDeviceKeysSimple.txt

I'm getting same message whichever location I try to run aacskeys from.. any ideas?

SvT
28th July 2007, 16:10
@ arnezami

Thanks for this great tool, but having small problem that I can't get sorted out.

When I try to run it off of my C: drive, I get:
C:\>aacskeys k v
aacskeys v0.2.8

Current Path c:\
Could not open file: C:\\ProcessingDeviceKeysSimple.txt

I'm getting same message whichever location I try to run aacskeys from.. any ideas?

Make sure the file "ProcessingDeviceKeysSimple.txt" is in the same dir. You can find a copy of the file in this link.

http://forum.doom9.org/showthread.php?p=1014933#post1014933

Goodluck !

sxt173
31st July 2007, 04:49
Make sure the file "ProcessingDeviceKeysSimple.txt" is in the same dir. You can find a copy of the file in this link.

http://forum.doom9.org/showthread.php?p=1014933#post1014933

Goodluck !

@ SvT
That was it, Thanks! Works great now.

MrWizard
3rd August 2007, 07:27
hi

arnezami: aacskeys v0.2.8 runs on linux? (not include sources)
I just tried it under Wine 0.9.42 and it worked fine. A native build would be nice, but this works for me for now :)

dk75
3rd August 2007, 20:41
I just tried it under Wine 0.9.42 and it worked fine. A native build would be nice, but this works for me for now :)

Did you used it with HDDVD drive or with mounted image? I can't obtain VUK from mounted image:

login@host:~/aacskey$ wine aacskeys.exe L: v
aacskeys v0.2.8

Current path: E:\aacskey
Processing key: 09F911029D74E35BD84156C5635688C0
Encrypted C-value: 47BEA12C44440DEDDAFCF95673C16D69
Corresponding uv: 00000001

Decrypted C-value: 9EA73F392FC815DABFF2FC8A20D0BA4F
Media key: 9EA73F392FC815DABFF2FC8A20D0BA4E

Encrypted verification data: F84AA53687CBA97A30353D959DB1984D
Decr verif data should be: 0123456789ABCDEF
Decrypted verification data: 0123456789ABCDEFBA41C7D9D209A3E2

Could not create handle for CD/DVD device.
Drive FW info:

All AGIDs in use, aborting.

KenD00
3rd August 2007, 22:31
You can't obtain a VUK from a mounted image because you need the VID for that which is not in a mounted image because it cannot be copied from the disc.

:rolleyes:

dk75
4th August 2007, 07:20
hm... right:

login@host:~/aacskey 0.32$ wine aacskeys.exe L: v v
aacskeys v0.2.8

Current path: E:\aacskey 0.32
Processing key: 09F911029D74E35BD84156C5635688C0
Encrypted C-value: 47BEA12C44440DEDDAFCF95673C16D69
Corresponding uv: 00000001

Decrypted C-value: 9EA73F392FC815DABFF2FC8A20D0BA4F
Media key: 9EA73F392FC815DABFF2FC8A20D0BA4E

Encrypted verification data: F84AA53687CBA97A30353D959DB1984D
Decr verif data should be: 0123456789ABCDEF
Decrypted verification data: 0123456789ABCDEFBA41C7D9D209A3E2

Volume ID: 00000000000000000000000000000000
Volume Unique Key: 9D1542E520DA01F22A053E29336DD4C9
Unit Key File Hash (DiscID): E139051278CF873697A370FC10527D4854E35681
Encrypted Unit Key 1: 306DFD64F7159FBAAAD56D28C879ECD0

Decrypted Unit Key 1: B69A4B6435C518B1262012A2065986AE


so what do I need now is... aacskeys for PS3, but the files posted a few pages away on sendspace aren't available now.

Speediakal
6th August 2007, 18:33
does anyone know the 300 Blu-Ray US AACS Key? I'm trying to rip it and decrypt it from my PS3 using BackupBluray.

peau
25th August 2007, 06:15
Ive been reading this and related threads for the last week or so and have backed up and decrypted blurays using a ps3 and windows comp assuming I have a released key combinations for that movie, but I have had no luck in obtaining a working combination of keys using either linux on the ps3, or the files in the AACS folder. I was wondering though if this quest to get keys using a bluray drive in a ps3 and/or using a backup to get it to play was still alive. Curious if anyone has done this successfully as of yet, and through what means. Thanks in advance

dk75
25th August 2007, 11:26
Wrong thread dude...
This thread is for Windows decrypting with BD-ROM/Writer connected directly to PC only (since aacskeys isn't for PS3 right now).

If you want to use PS3&Windows for decrypting then you are interested with this thread: http://forum.doom9.org/showthread.php?t=124841

d0ORk
28th August 2007, 08:47
Hello. I got a bluray which I seem cant decrypt properly.
AACSKEYS gives me the following:

Processing key: 09F911029D74E35BD84156C5635688C0
Encrypted C-value: 0B26C036A16F301B63B553B007A96F08
Corresponding uv: 00000001

Decrypted C-value: D3388BD9EB29DF366355717DA76BB915
Media key: D3388BD9EB29DF366355717DA76BB914

Encrypted verification data: 7E912AD0AE711FD9FED482CB7E765721
Decr verif data should be: 0123456789ABCDEF
Decrypted verification data: E8F80D4DC4ADFAE42A0C90997AA7A6EE

AGID: 00

Host certificate from: Power DVD 7.1
Host certificate (Hcert): 0200005CFFFF0000000C00006E3DEB679B9A16AD
FAA8E30878767BA6EB2A9B415385AD1181B4446C
31E9A5DD2AB808B364FF15885BAC490964318C9B
F8029FCF76F688A54FBDA03F6D9332EF04E5A613
12DA85880A4D9CBB79D8602E
Host Private Key (Hpriv): 4737676058D7029452514F0AB186DC4CCA8C578F
Host Nonce (Hn): 2923BE84E16CD6AE529049F1F1BBE9EBB3A6DB3C

Drive certificate (Dcert): ########################################
########################################
########################################
########################################
########################
Drive Nonce (Dn): ########################################

Drive key point (Dv): ########################################
########################################
Drive key signature (Dsig): ########################################
########################################

Host key (Hk): 0000000000000000000000000000000000000000
Host key point (Hv): 8E9B0E3CF41FA7DA3A829F604122EA4ED5261AA4
7570CE0BB9061A66FAF92C4A7D98ACC171CBF19B
Host key signature (Hsig): ########################################
########################################

Bus key (BK): ################################

Volume ID: 1BC7547FAF328373663731A98DC539D7
Voluem ID MAC: ################################

Volume Unique Key: B6664DC1AD4063C0AEB4553B2E0D460D
Encrypted Unit Key 1: 77D36C9D8113B3E88B50F3D339E1885B

Decrypted Unit Key 1: E8169FE9805700C64F29C4545D4D5412


and the newest aacskeys 0.2.8:

Processing key: 455FE10422CA29C4933F95052B792AB2
Encrypted C-value: 6062BAA9905525D7D6D0B2B023D63DE2
Corresponding uv: 00000049

Decrypted C-value: A29EEF856B39D75A7ABCD5ED78BDC1B4
Media key: A29EEF856B39D75A7ABCD5ED78BDC1FD

Encrypted verification data: 7E912AD0AE711FD9FED482CB7E765721
Decr verif data should be: 0123456789ABCDEF
Decrypted verification data: 0123456789ABCDEF72724A82FB5715C4

Drive FW info: 1.01 07/05/15 PIONEER

AGID: 00

Host certificate from: Power DVD 7.1
Host certificate (Hcert): 0200005CFFFF0000000C00006E3DEB679B9A16AD
FAA8E30878767BA6EB2A9B415385AD1181B4446C
31E9A5DD2AB808B364FF15885BAC490964318C9B
F8029FCF76F688A54FBDA03F6D9332EF04E5A613
12DA85880A4D9CBB79D8602E
Host Private Key (Hpriv): 4737676058D7029452514F0AB186DC4CCA8C578F
Host Nonce (Hn): 2923BE84E16CD6AE529049F1F1BBE9EBB3A6DB3C

Drive certificate (Dcert): ########################################
########################################
########################################
########################################
########################
Drive Nonce (Dn): ########################################

Drive key point (Dv): ########################################
########################################
Drive key signature (Dsig): ########################################
########################################

Host key (Hk): 5613E7F89B11D9CAA27B610A1096332BEED86BC4
Host key point (Hv): 8A60C80BD60C23605FBE90B27BF96B2DB38195C1
801F54EB29E0F6EC57AC2B9168E88B2D56977508
Host key signature (Hsig): ########################################
########################################

Bus key (BK): ################################

Volume ID: 1BC7547FAF328373663731A98DC539D7
Volume ID MAC: ################################
Volume ID MAC should be: ################################

Volume Unique Key: 6F4B8F19CF714805E553A17676233C25
Unit Key File Hash (DiscID): 4E008BADC49CCAB1BFB24115DC6049C2886FE0E5
Encrypted Unit Key 1: 77D36C9D8113B3E88B50F3D339E1885B

Decrypted Unit Key 1: F9713FF049FAAAB4C771A6E59CA22896


I think the first one is right but it doesn't show the Unit Key File Hash (DiscID) which I need for DumpHD or should I take the VUK from the first one and the DiscID from the second as DumpHD shows this DiscID anyway.

DumpVid didnt show anything.

Thanks in advance

jack_wuwei
7th September 2007, 07:16
I test aacskey 0.2.8, The disc is Basic Instinct 2. aacskey 0.2.8 output:
D:\aacskeys_v0.2.5>aacskeys2.8.exe h v
aacskeys v0.2.8

Current path: D:\aacskeys_v0.2.5
Device key: AA856A1BA814AB99FFDEBA6AEFBE1C04
Processing key: 09F911029D74E35BD84156C5635688C0
Encrypted C-value: 31A883FE8F48B6EB731F7D390A0900D0
Corresponding uv: 00000001

Decrypted C-value: CF8642753C67C52EC9A077D25259B530
Media key: CF8642753C67C52EC9A077D25259B531

Encrypted verification data: 0D233917C27E8084DFCE1CAAAF5F440B
Decr verif data should be: 0123456789ABCDEF
Decrypted verification data: 0123456789ABCDEF002705C060959863

Drive FW info: AL07 R___

AGID: 01

Host certificate from: Power DVD 7.1
Host certificate (Hcert): 0200005CFFFF0000000C00006E3DEB679B9A16AD
FAA8E30878767BA6EB2A9B415385AD1181B4446C
31E9A5DD2AB808B364FF15885BAC490964318C9B
F8029FCF76F688A54FBDA03F6D9332EF04E5A613
12DA85880A4D9CBB79D8602E
Host Private Key (Hpriv): 4737676058D7029452514F0AB186DC4CCA8C578F
Host Nonce (Hn): 2923BE84E16CD6AE529049F1F1BBE9EBB3A6DB3C

Drive certificate (Dcert): ########################################
########################################
########################################
########################################
########################
Drive Nonce (Dn): ########################################

Drive key point (Dv): ########################################
########################################
Drive key signature (Dsig): ########################################
########################################

Host key (Hk): 5613E7F89B11D9CAA27B610A1096332BEED86BC4
Host key point (Hv): 8A60C80BD60C23605FBE90B27BF96B2DB38195C1
801F54EB29E0F6EC57AC2B9168E88B2D56977508
Host key signature (Hsig): ########################################
########################################

Drive signature wrong/error
Bus key (BK): ################################

Volume ID: 00000000000000000000000000000000
Volume ID MAC: ################################
Volume ID MAC should be: ################################

Volume Unique Key: 100A216C1F714C0CB1970D73C33A0741
Unit Key File Hash (DiscID): 32E4DE0056128E0A88147D46BA8A98E95648CBBB
Encrypted Unit Key 1: DB55EDC19B31E13742E0EED21DA4A8DA

Decrypted Unit Key 1: 6133B7AD32B6518716B1DBF9552854C7

The key is wrong, right key is EB7DF18EF85EBB9CA12CAC4A4448EB27

jack_wuwei
7th September 2007, 07:17
BTW: I can play the disc with PowerDVD 7.3

SvT
7th September 2007, 10:55
Volume ID: 00000000000000000000000000000000
Volume ID MAC: ################################
Volume ID MAC should be: ################################


There's something wrong with the volume ID I think.
its all Zero.

I think you can get the VUK with dumpvid and use that for aacskeys:

See this post: http://forum.doom9.org/showthread.php?p=1019403#post1019403

Goodluck

gioowe
7th September 2007, 12:16
The volume id is all zero if the drive does not accept the host (certificate) and authentication fails. "Drive signature wrong/error" is another indicator. The drive deliberately returns an incorrect signature if it rejects the host.

Someone could update aacskeys to read the MKBROM from the drive to check for revoked host certificates. Would be another nice feature :)

jack_wuwei
10th September 2007, 07:05
I really appreciate Svt and Gioowe’s help. I tried the method from http://forum.doom9.org/showthread.php?p=1019403#post1019403, At last, I got the right key by using DumpVID and aacskeys software. But it is not so convenient, because DumpVID needs to run player software.

I used to get the right key only by running aacskeys. However, aacskeys can not get the right key after playing the movie Speed on the other day. This happens on both the DVD driver and pc. I doubt that the disc has recorded a kind of blacklist which contains the revealed Device Key. When the disc is played, the blacklist is written into the flash in the dvd driver. Therefore, aacskeys can not get the right key. I tried to change the device key several times, but got the same wrong key.

BTW: PowerDVD 7.3 can play normally, and AnyDVD HD 6.1.7.0 also can do that.

KenD00
10th September 2007, 13:55
I doubt that the disc has recorded a kind of blacklist which contains the revealed Device Key

And exactly that it has. Well, almost, not the found Procesing Key is blacklisted but the Host Certificate aacskeys uses. Unless the community finds a new Host Certificate the only way for BluRay users to get the VID is the DumpVID method. Enjoy the power of AACS which gives you the good feeling that you don't need to worry about using the disc in a way the content owner has not licensed it to you (hmm, i think this sentence is copyrighted by some AACS spokeperson, hopefully they won't sue me for using it without permission *g*).

:rolleyes:

gioowe
10th September 2007, 19:48
Someone able to "send" the new host revocation list? First 1024 bytes of MKBROM. I'm just curious...

jack_wuwei
11th September 2007, 03:38
Someone able to "send" the new host revocation list? First 1024 bytes of MKBROM. I'm just curious...

How to get the first 1024 bytes of MKBROM?

gioowe
11th September 2007, 21:15
By using any hex-viewer / hex-editor on X:\AACS\MKBROM.AACS

The first 256 bytes should be enought.

KenD00
11th September 2007, 22:39
This is Host Revocation List record from a MKBv3 (excluding preceeding Record Type and Record Length fields).

00000006000000060009FFFF0000000B0002FFFF000000210003FFFF000000260003FFFF000000350002FFFF0000004E0003FFFF00000054336ED852525410754F0D1221EC3BC425C621E3B580EF60673FACECFBAD3BD70DEC706B70C4E8AF87

:rolleyes:

gioowe
12th September 2007, 17:53
===============================================
RECORD >>> Type, Version (3.2.5.1)
===============================================
000000 10 Record Type = 16 --
------ -----------------------------------------------
000001 00 00 0C Record Size = 12 OK
------ -----------------------------------------------
000004 00 04 10 03 MKB Type = 266243 OK
------ -----------------------------------------------
000008 00 00 00 03 Version Number = 3 --
------ -----------------------------------------------

===============================================
RECORD >>> Host Revocation (3.2.5.3)
===============================================
00000C 21 Record Type = 33 --
------ -----------------------------------------------
00000D 00 00 64 Record Size = 100 OK
------ -----------------------------------------------
000010 00 00 00 06 Total Number of Entries = 6 --
------ -----------------------------------------------
000014 00 00 00 06 Number of Entries in Block #1 = 6 OK
------ -----------------------------------------------
000018 00 09 FF FF 00 00 00 0B Revocation #1 = FFFF0000000B..0014 --
------ -----------------------------------------------
000020 00 02 FF FF 00 00 00 21 Revocation #2 = FFFF00000021..0023 --
------ -----------------------------------------------
000028 00 03 FF FF 00 00 00 26 Revocation #3 = FFFF00000026..0029 --
------ -----------------------------------------------
000030 00 03 FF FF 00 00 00 35 Revocation #4 = FFFF00000035..0038 --
------ -----------------------------------------------
000038 00 02 FF FF 00 00 00 4E Revocation #5 = FFFF0000004E..0050 --
------ -----------------------------------------------
000040 00 03 FF FF 00 00 00 54 Revocation #6 = FFFF00000054..0057 --
------ -----------------------------------------------
000048 33 6E D8 52 52 54 10 75
000050 4F 0D 12 21 EC 3B C4 25 C6 21 E3 B5 80 EF 60 67
000060 3F AC EC FB AD 3B D7 0D EC 70 6B 70 C4 E8 AF 87 Signature of Block VERIFIED
------ -----------------------------------------------


:thanks:

MKBROM v3 in human readable form.

mrazzido
16th September 2007, 21:11
today i got Dirty Dancing 20th anniversity BD Disc

when i try to use AACSKEYS

i got the followring error :

Drive signature wrong/error
Volume Unique Key: 15AD8D1B9251FD2E46E328B2D1D1B4DB
Unit Key File Hash (DiscID): 88D4FEB81412EF57515928025B6427048DB3ECC9

when i try DUMPVID

Drive type is recognised as CDROM/DVD.

Sending SPC1 Test Unit CDB6 command..done.
Returned good status.

Press ENTER to start hammering

Hammering drive...
vid: 89037DEBD3673F9B6BE3B48AD5B4B346
Hammering finished.



i have LITE-ON LH-2B1S with latest firmware .

KenD00
17th September 2007, 19:40
This is not the first time someone asks this, so to get this finally cleared:

Current aacskeys cannot retrieve the Volume ID from any drive that has been used with a MKBv3 disc (EXCEPT the Xbox 360 HD-DVD AddOn) because its used Host Certificate has been revoked.

:rolleyes:

sillyfaith
9th October 2007, 18:01
Hi All,

I am pretty new here... so I appologize in advance in case I am asking an obvious question.
I was checking the program provided by arnezami (who seems to be a genious :)) and I noticed that when calculating the bus_key he skipped (4 + 1) bytes. I could understand that the 1 byte is due to the uncompressed code (which he commented). But I do not understand why he needed to skip 4 more bytes?!!! Any idea guys?

Thanks
Faith

gioowe
9th October 2007, 19:56
The bus key is 128 bits, the calculated ECDSA point is 160 bits wide. Therefore the msb 32 bits are skipped.

1 additional byte is skipped for signed/unsigned reasons. One additional byte is added with 00h/FFh resp.

sillyfaith
10th October 2007, 18:06
The bus key is 128 bits, the calculated ECDSA point is 160 bits wide. Therefore the msb 32 bits are skipped.

1 additional byte is skipped for signed/unsigned reasons. One additional byte is added with 00h/FFh resp.

I see,so what you are saying is that the data is represented as MSB first, right?

:thanks:

Faith

PSD83
21st October 2007, 05:42
Everyone here is amazing!

hddvdwatcher
25th October 2007, 02:04
Seems to issues with Transformers. Is there a new mkb?

C:\Program Files\aacskey>aacskeys.exe f
aacskeys v0.2.8


Could not find a Processing Key or Device Key resulting in the Media Key.

Aborting...

MoFoQ
25th October 2007, 03:50
yea...I get the same issue with aacskeys and Transformers HD.
However, I think I got the Volume ID:

40000921200710300020202020200000


And DumpHD says the id for the disc is

9767A81F1194DD5AEFDE5E38595D011DF8C5F3CD

nmeli15
26th October 2007, 05:27
where can i find 0.2.2 and 0.2.4 aacskeys ,thanx

nmeli15
26th October 2007, 05:31
Issues with TRANSFORMERS hd with aacskeys

omegahelix
26th October 2007, 05:51
Issues with TRANSFORMERS hd with aacskeys

Yeah, just post your MKB v4 key and I think somebody will be able to fix it pretty quick for you.

bcrabl
26th October 2007, 09:48
Yeah, just post your MKB v4 key and I think somebody will be able to fix it pretty quick for you.

Are you an oracle?

omegahelix
26th October 2007, 19:09
Are you an oracle?

Me? No. I wish. I thought nmeli15 might be though since he's the one insinuating that the fault lies with aacskeys.

Anyway, I suppose I might as well try to actually contribute to the topic since I've broken my cone of silence. I've tweaked the last availble aacskeys source that I could find (0.2.6) to compile on my gentoo box for anyone with interest. The binary is compiled with gcc 4.1.2 and glibc 2.6.1 for those who would like to use it with dumphd. If there's more up to date source available, I would be very interested.

aacskeys-source-0.2.6 (http://www.sendspace.com/file/ujb3to)
aacskeys-bin-0.2.6 (http://www.sendspace.com/file/mzh0je)

KenD00
17th November 2007, 15:57
aacskeys 0.2.9

Almost 2 months ago arnezami gave me his current aacskeys 0.2.9 source to test it with DumpHD and the permission to do with it what i want if he doesnt find the time to release it. Well, i think after 2 months now its time for a release ;).

I fixed some bugs, made it run under linux and now theres a library version that can be used with DumpHD. The download includes precompiled executables and libraries for windows and linux, full sourcecode is included. And before people start complaining its not working for them, there is no MKBv4 Processing Key or Host Certificate included, aacskeys still does not support MKBv4!

Download it here:
http://www.sendspace.com/file/n5nps8
http://rapidshare.com/files/70353380/aacskeys_0.2.9.zip.html

:rolleyes:

Switchback
15th December 2007, 01:51
How do you use this program? I am trying to rip Cars Blu Ray to my hard drive and am having trouble.

SvT
15th December 2007, 02:22
How do you use this program? I am trying to rip Cars Blu Ray to my hard drive and am having trouble.

This is the 3th time I read about your problem please stick to your original post.

http://forum.doom9.org/showthread.php?p=1076164#post1076164 :)

fenton06
15th February 2008, 07:58
ok, I have to admit I am getting VERY frustrated trying to get this program to work. I finally got DumpHD to find it in the directory, go all that sorted out, finally. Now when it calls aacskeys.so, it says that libcrypto.so.0.9.8 cannot be found.

Ok, so i made a symbolic link from libcrypto.so.0.9.8b to libcrypto.so.0.9.8, thinking it would pacify the issue. No such luck, now it complains about version information. WHAT THE HECK IS THE PROBLEM?! If someone could point me in the right direction, it would be greatly appreciated. I also tried to install openssl0.9.8, no dice there either.

I am not meaning to come off as an ass, but I am getting really frustrated.:(

I am also running Fedora Core 8 64 bit if that matters. I compiled my own aacskeys.so library, but don't even get me started on trying to compile he actual aacskeys program itself.:mad:

KenD00
16th February 2008, 04:47
You are using a 64 bit Linux, maybe you have a problem with mixed 32 bit and 64 bit code. Ensure that all required programs are in the same bit depth, these are in particular Java, the OpenSSL library and the aacskeys library!

I finally got DumpHD to find it in the directory, go all that sorted out, finally.

Should be enough to execute DumpHD with the included script file, this sets the lookup path for the library.

I compiled my own aacskeys.so library, but don't even get me started on trying to compile he actual aacskeys program itself.:mad:

What's not working?

:rolleyes:

fenton06
17th February 2008, 21:00
I can find the aacskeys library that I compiled in your wrapper, it is just the aacskeys program I am ahving problems with. I tried two things, using the precompiled, and compiling my own, thinking that might sort out the 64 bit problem. I have 64 bit Java, and 64 bit aacskeys library that i compiled, I believe it is the aacskeys program itself.

1) when i try to use the precompiled aacskeys:

./aacskeys: error while loading shared libraries: libcrypto.so.0.9.8: cannot open shared object file: No such file or directory

I have libcrypto.0.9.8b in /lib/libcrypto.so.9.8b and /lib64/libcrypto.so.9.8b, which is what I presume it is looking for.

Then I tried to create symbolic links named libcrypto.so.0.9.8 to solve the issue, but then I get:

./aacskeys: /lib/libcrypto.so.0.9.8: no version information available (required by ./aacskeys)

I also tried to install openssl .0.9.8 to see if that would install the correct libraries...but no such luck.

2) If I try to compile aacskeys from source, this is what I get:
g++ -O3 -Wall -o bin/linux/aacskeys src/ioctl.cpp src/mmc.cpp src/cmac.cpp src/cmac_aes.cpp src/aacs_aes.cpp src/aacs_ecdsa.cpp src/aacskeys.cpp -lcrypto
src/aacskeys.cpp: In function ‘void calculate_processing_key(unsigned char*, unsigned char*, long int, long int, long int, long int, long int, long int)’:
src/aacskeys.cpp:609: warning: ‘mask_check’ may be used uninitialized in this function
/tmp/ccbgdKq5.o: In function `calculate_title_key_file_hash(unsigned char*, unsigned long, unsigned char*)':
aacs_aes.cpp:(.text+0x22a): undefined reference to `EVP_ecdsa'
/tmp/ccI36gEa.o: In function `aacs_group()':
aacs_ecdsa.cpp:(.text+0x34d): undefined reference to `EC_GROUP_new_curve_GFp'
aacs_ecdsa.cpp:(.text+0x361): undefined reference to `EC_POINT_new'
aacs_ecdsa.cpp:(.text+0x3c9): undefined reference to `EC_GROUP_free'
aacs_ecdsa.cpp:(.text+0x3d1): undefined reference to `EC_POINT_free'
aacs_ecdsa.cpp:(.text+0x407): undefined reference to `EC_GROUP_free'
aacs_ecdsa.cpp:(.text+0x4f7): undefined reference to `EC_POINT_set_affine_coordinates_GF2m'
aacs_ecdsa.cpp:(.text+0x56f): undefined reference to `EC_GROUP_set_generator'
/tmp/ccI36gEa.o: In function `aacs_set_cert(ec_key_st*, unsigned char*)':
aacs_ecdsa.cpp:(.text+0x5b4): undefined reference to `EC_KEY_get0_group'
aacs_ecdsa.cpp:(.text+0x62b): undefined reference to `EC_POINT_new'
aacs_ecdsa.cpp:(.text+0x64c): undefined reference to `EC_POINT_set_affine_coordinates_GFp'
/tmp/ccI36gEa.o: In function `aacs_key()':
aacs_ecdsa.cpp:(.text+0x6a2): undefined reference to `EC_KEY_new'
aacs_ecdsa.cpp:(.text+0x6ba): undefined reference to `EC_KEY_set_group'
aacs_ecdsa.cpp:(.text+0x6cd): undefined reference to `EC_KEY_free'
/tmp/ccI36gEa.o: In function `aacs_sign(unsigned char*, char*, unsigned char*, unsigned char*, unsigned char*)':
aacs_ecdsa.cpp:(.text+0x725): undefined reference to `EC_KEY_new'
aacs_ecdsa.cpp:(.text+0x73d): undefined reference to `EC_KEY_set_group'
aacs_ecdsa.cpp:(.text+0x749): undefined reference to `EC_KEY_free'
aacs_ecdsa.cpp:(.text+0x7bc): undefined reference to `EC_KEY_set_private_key'
aacs_ecdsa.cpp:(.text+0x7d7): undefined reference to `EVP_ecdsa'
aacs_ecdsa.cpp:(.text+0x821): undefined reference to `ECDSA_do_sign'
aacs_ecdsa.cpp:(.text+0x843): undefined reference to `ECDSA_SIG_free'
/tmp/ccI36gEa.o: In function `aacs_calculate_bus_key(unsigned char*, unsigned char*, unsigned char*, unsigned char*)':
aacs_ecdsa.cpp:(.text+0x8b2): undefined reference to `EC_KEY_new'
aacs_ecdsa.cpp:(.text+0x8cf): undefined reference to `EC_KEY_set_group'
aacs_ecdsa.cpp:(.text+0x8db): undefined reference to `EC_KEY_free'
aacs_ecdsa.cpp:(.text+0x956): undefined reference to `EC_KEY_get0_group'
aacs_ecdsa.cpp:(.text+0x9b0): undefined reference to `EC_POINT_new'
aacs_ecdsa.cpp:(.text+0x9d5): undefined reference to `EC_POINT_set_affine_coordinates_GFp'
aacs_ecdsa.cpp:(.text+0x9ea): undefined reference to `EC_POINT_new'
aacs_ecdsa.cpp:(.text+0xa05): undefined reference to `EC_POINT_mul'
aacs_ecdsa.cpp:(.text+0xa27): undefined reference to `EC_POINT_point2bn'
/tmp/ccI36gEa.o: In function `aacs_verify(unsigned char*, unsigned char*, unsigned char*, unsigned char*)':
aacs_ecdsa.cpp:(.text+0xab8): undefined reference to `EC_KEY_new'
aacs_ecdsa.cpp:(.text+0xad0): undefined reference to `EC_KEY_set_group'
aacs_ecdsa.cpp:(.text+0xadc): undefined reference to `EC_KEY_free'
aacs_ecdsa.cpp:(.text+0xb41): undefined reference to `EVP_ecdsa'
aacs_ecdsa.cpp:(.text+0xb81): undefined reference to `ECDSA_SIG_new'
aacs_ecdsa.cpp:(.text+0xbcb): undefined reference to `ECDSA_do_verify'
aacs_ecdsa.cpp:(.text+0xbd6): undefined reference to `ECDSA_SIG_free'
/tmp/ccI36gEa.o: In function `aacs_set_cert(ec_key_st*, unsigned char*)':
aacs_ecdsa.cpp:(.text+0x690): undefined reference to `EC_KEY_set_public_key'
/tmp/cc8AZmav.o: In function `main':
aacskeys.cpp:(.text+0x1eaf): undefined reference to `calculate_title_key_file_mac(unsigned char*, unsigned long, unsigned char*, unsigned char*)'
collect2: ld returned 1 exit status
make: *** [all] Error 1

Hope this helps some...it had been pretty frustrating to say the least...

KenD00
19th February 2008, 04:11
The wrapper library i made is obsolete now, the recent aacskeys 0.2.9 can be compiled as library itself.

I am a linux n00b, but i'm pretty sure the only problem why aacskeys doesn't work / can't be compiled is OpenSSL. Either your installed OpenSSL or your LD_SEARCH_PATH are messed up... or both :D. On my system i don't have a libcrypto.0.9.8b, only one without the b. But the linker / compiler doesn't look for this file directly, it looks for the file libcrypto.so, which is usually a symbolic link to a file containing the version number in its name.

So at first i would check if this link is broken. You said you already reinstalled OpenSSL, maybe there are still remainings of a old version which cause the problem? You could also try to set LD_SEARCH_PATH to contain the directory which contains the OpenSSL library at the beginning, maybe that helps.

But as i said, i don't know much about linux, your problem seems to be a general one, maybe you should ask in the linux section for help.

:rolleyes:

sothis_
22nd February 2008, 11:01
on fedora 8 x86_64 you have to rebuild openssl yourself, since the original distribution packages aren't compiled with EC support.

fenton06
23rd February 2008, 20:33
I tried to build it from source, but i still cant get it to compile, do I need to specify EC support? If so, how?

sothis_
4th March 2008, 21:40
I tried to build it from source, but i still cant get it to compile, do I need to specify EC support? If so, how?

not really. but openssl will install into /usr/local/ssl if you don't specify another prefix. when building aacskeys you need to specify in the makefile:

-I/usr/local/ssl/inlude -L/usr/local/ssl/lib

anyways, there was a little problem with a datatype in a functions parameter list in aacskeys, which may result in a compiler error on 64 bit systems. i built a binary which should run on the fedora 8 x86_64 box, it's statically linked against openssl. i haven't tested it yet, so please let me know if the build works :)

linkage (http://copai.de/index.php?/archives/16-aacskeys-fedora-8-x86_64-static-build.html)

fenton06
6th March 2008, 04:23
it seemed to open aacskeys now...but now i egt the following error in dumpHD:

Executing aacskeys: ./aacskeys "/dev/sr1" "/media/PLANET_EARTH_D1" v
aacskeys v0.2.9

Error opening Media Key File /dev/sr1/AACS/MKBROM.AACS


ERROR: LOADMKB errnr: -1

If I run the program w/o the /dev/sr1, i get this output:

./aacskeys /media/PLANET_EARTH_D1/ v
aacskeys v0.2.9

Current path: /home/benjamin/Desktop/dumphd_0.4
Processing key: 09F911029D74E35BD84156C5635688C0
Encrypted C-value: ABAB2D12C4B7B5DF9F9960E968B8600A
Corresponding uv: 00000001

Decrypted C-value: 6210D9B91D0AB2FDAF25F24C274F58B5
Media key: 6210D9B91D0AB2FDAF25F24C274F58B4

Encrypted verification data: EE05029424A17031044697728FC19919
Decr verif data should be: 0123456789ABCDEF
Decrypted verification data: 0123456789ABCDEFB1629F02FAFB84D3

Could not find the underlying device of the given drive mountpoint, aborting.


ERROR: DRIVEDEVICE errnr: -2

sothis_
6th March 2008, 04:44
i am not sure, but if aacskeys doesn't support udf >= 2.5 itself (like anydvd on win xp) you have to wait until the kernel supports it :).
there's a patch, but if you don't want to compile a kernel on your own, you have to wait a few weeks. the patch will be most likely merged into the 2.6.26 tree (maybe even in 2.6.25, but i am not sure with that).

linux udf patches (http://sourceforge.net/tracker/?atid=300295&group_id=295&func=browse)

fenton06
6th March 2008, 08:41
I have applied the patch, it sees/mounts HDDVD's just fine

KenD00
6th March 2008, 15:19
You are using DumpHD with my wrapper library and the executable version of aacskeys, this doesn't work, the wrapper assumes another cli interface than aacskeys has. Do not use my wrapper library, it's obsolete, aacskeys 0.2.9 can be compiled itself as library.

You need to compile aacskeys as library yourself because only a 32bit binary is included. For this you need the java 6 sdk, check the makefile of aacskeys and change the path to point to your jdk location, if necessary. Then a "make lib" should do it. Copy the resulting libaacskeys.so into the directory of DumpHD, the executable binary is not required anymore, but the ProcessingDeviceKeysSimple.txt is!


./aacskeys /media/PLANET_EARTH_D1/ v

Try it without the trailing "/", if its still not working show me the contents of your /proc/mounts.

:rolleyes:

fenton06
6th March 2008, 20:48
ok, so I tried this with 2 discs using dump HD, and the first one I tried was the Bourne Identity.

I seem to have figured out the problem with the libaacskeys.so, as it tries to find the key...but I am getting no activity from the drive, and no key is found. Here is what I get, but when I go to close it it asks whether or not I want to close as an operation is running.

http://i11.photobucket.com/albums/a170/fenton06/Screenshot-DumpHD04.png

So I try the second disc, Plaent Earth Disc 1. This is found in the key database, but I already have it decrypted, I am just trying multiple discs to try and get DumpHD working. When I try to open this disc in dumpHD, it closes(crashes), and the command line shows:

java: symbol lookup error: ~/Desktop/dumphd_0.4/libaacskeys.so: undefined symbol: EVP_ecdsa

KenD00
7th March 2008, 04:13
java: symbol lookup error: ~/Desktop/dumphd_0.4/libaacskeys.so: undefined symbol: EVP_ecdsa


I have the impression that your OpenSSL is still not running properly, this is a linker error. And are you sure this happens when the disc is found in the database?? Your screenshot still shows an error in the database behind line 190. When you try to decrypt Planet Earth, does the log say "Disc found in key database". Because, if there is no bug in DumpHD i missed, aacskeys gets NOT executed if the disc is found in the database. But maybe this crash happens because of your broken OpenSSL.

Have you tried to use the executable version of aacskeys with these discs? Does this work?

How did you get the aacskeys library to compile, have you used the posted precompiled OpenSSL library? I think something is really wrong with your OpenSSL stuff, you should try to remove ALL remainings of it, check if your distribution contains an OpenSSL package, remove it, make uninstall all tarballs you have tried and get a fresh one and do a new configure, make, make install run.

:rolleyes:

fenton06
7th March 2008, 05:24
I get the error when I remove the keydb.cfg so I can see if the aacskeys is working, if it finds it we are home free.

I will try the executable version of aacskeys with the discs...

EDIT: When i run the executable on Bourne identity I get this:

./aacskeys /dev/sr1 /media/BOURNEIDENTITY v
aacskeys v0.2.9

Error opening Media Key File /dev/sr1/AACS/MKBROM.AACS


ERROR: LOADMKB errnr: -1

Different command for Bourne:

./aacskeys /media/BOURNEIDENTITY v
aacskeys v0.2.9

Current path: /home/benjamin/Desktop/aacskeys_0.2.9/bin/linux

Error opening Media Key File /media/BOURNEIDENTITY/AACS/MKBROM.AACS


ERROR: LOADMKB errnr: -1


Planet earth:

./aacskeys /dev/sr1 /media/PLANET_EARTH_D1/ v
aacskeys v0.2.9

Error opening Media Key File /dev/sr1/AACS/MKBROM.AACS


ERROR: LOADMKB errnr: -1


Planet Earth different command:

./aacskeys /media/PLANET_EARTH_D1/ v
aacskeys v0.2.9

Current path: /home/benjamin/Desktop/aacskeys_0.2.9/bin/linux

Processing key: 09F911029D74E35BD84156C5635688C0
Encrypted C-value: ABAB2D12C4B7B5DF9F9960E968B8600A
Corresponding uv: 00000001

Decrypted C-value: 6210D9B91D0AB2FDAF25F24C274F58B5
Media key: 6210D9B91D0AB2FDAF25F24C274F58B4

Encrypted verification data: EE05029424A17031044697728FC19919
Decr verif data should be: 0123456789ABCDEF
Decrypted verification data: 0123456789ABCDEFB1629F02FAFB84D3

Could not find the underlying device of the given drive mountpoint, aborting.


ERROR: DRIVEDEVICE errnr: -2

KenD00
7th March 2008, 17:25
Do not use aacskeys with 2 path parameters, no /dev/sr1 stuff, only the mountpoint like /media/BOURNEIDENTITY, and that without a trailing "/". The 2 path stuff comes from the very first experimental linux versions, now aacskeys can get the device itself, but for this to work there must be no "/" at the end of the path.

Something i forgot, do you run aacskeys with root rights? On my machine i cannot access any file from the hd-dvd if i don't have root rights, please use sudo to run aacskeys. Strange enough, it looks like Planet Earth could be read without root rights (there was only the mistake with the trailing "/") while Bourne couldn't.

:rolleyes:

fenton06
7th March 2008, 18:50
aha...I will try using sudo, thanks fro clearing everything up!

Trying to run aacskeys with sudo:

sudo ./aacskeys /media/BOURNEIDENTITY v
Password:
aacskeys v0.2.9

Current path: /home/benjamin/Desktop/aacskeys_0.2.9/bin/linux


This is what it says for a good while, my CPU is pegged at 100%, but nothing in the command line...is there any idea on how long it should take?

Hmmm...it works with both of my planet earth discs....seems to be a problem with Bourne Identity...

KenD00
8th March 2008, 04:06
Hmm, this is really strange, there should be no CPU load after the output of the current directory, aacskeys just opens some files on the disc and reads them into memory. But maybe, for some reasons, it cannot read from the disc. Can you read files from Bourne Identity? Try to open the file AACS/MKBROM.AACS in a hex editor (or text editor if you have none), does this work?

:rolleyes:

fenton06
11th March 2008, 00:03
oddly enough, I can't actually browse the directories of th disc. I can only mount the disc, but the programs can read the disc. I am not quite sure why, but thats what happens. I am not to concerned anymore, I found the key in the keydb thread. If i find any more problems I'll post them.

sothis_
11th March 2008, 08:21
oddly enough, I can't actually browse the directories of th disc. I can only mount the disc, but the programs can read the disc. I am not quite sure why, but thats what happens. I am not to concerned anymore, I found the key in the keydb thread. If i find any more problems I'll post them.

mmhhhh, might be a bug in the current udf module for the kernel, or the disc is using udf 2.60 (dunno if this possible according to the HD-DVD and BD specs)

fenton06
12th March 2008, 04:49
meh...they decrpyt so I don't mind

SimpleWhite
9th May 2008, 00:16
Hello,
I'm noob in AACS decryptions. Could anybody please tell me what to do for rip any Blue-Ray discs and watch movie or rip and burn disc step-by-step?
As I understand I need to use aacskeys.exe for get decryption key? What do next?

Thanks you very much!

mrginthehouse@hotmail.com
29th May 2008, 22:24
nothink is happening when i run the aacskeys .

Adub
29th May 2008, 22:45
Can't help you. We need a lot more information. What exactly are you typing? What are you trying to decrypt? What drive are you using, etc.

odin24
23rd June 2008, 21:35
This is my first time trying this approach at ripping a BD. I was able to retrieve the VID using DumpVid, do I then use this number with aacskeys to retrieve the CPS key? I'm using aacskeys v0.2.9

I enter; directory\aacskeys [drive letter] ["n", or, "s", or "v"] [Vol ID]

I then get this error;

Could not find a Processing Key or Device Key resulting in the Media Key.

Aborting...

ERROR: PROCESSMKB errnr: -2

Also, I'm not sure how to determine if the BD falls under the MKBv3 status as mentioned earlier in this thread.

Thanks.

KenD00
25th June 2008, 16:20
I was able to retrieve the VID using DumpVid, do I then use this number with aacskeys to retrieve the CPS key?

Yes, if your drive has been upgraded to MKBv3 or later this is the way to do it.

Unfortunately your disc seems to be MKBv4 or newer, there is no known Processing Key for these discs so you are currently out of luck (with aacskeys).

To check the MKB version of the disc, open the file AACS\MKB_RO.inf in a hex editor and look at offset 0x08, the next 4 bytes are the version number.

:rolleyes:

odin24
25th June 2008, 21:08
Yes, if your drive has been upgraded to MKBv3 or later this is the way to do it.

Upgraded? Is this through firmware provided by the manufacturer or am I missing something? I just purchased my BD drive not too long ago so I'm fairly new at this... can you tell!

To check the MKB version of the disc, open the file AACS\MKB_RO.inf in a hex editor and look at offset 0x08, the next 4 bytes are the version number.

I've never used hex editor, could you reccommend one? Preferrably noob friendly if possible. Just point me in the right direction and I'll figure out thie rest

Thanks for your help KenD00,
O!

KenD00
27th June 2008, 08:16
No, the revokation lists inside the BD drive get updated whenever a disc with a newer MKB version is authenticated by a software player (or aacskeys) to decrypt the disc, maybe already when the disc is inserted into the drive.

For a start about hex editors, maybe this can help http://en.wikipedia.org/wiki/Hex_editor.

Perhaps AnyDVD HD is the better solution for you, its also the only program which currently can decrypt MKBv4 or later discs :(.

:rolleyes:

odin24
27th June 2008, 10:47
No, the revokation lists inside the BD drive get updated whenever a disc with a newer MKB version is authenticated by a software player (or aacskeys) to decrypt the disc, maybe already when the disc is inserted into the drive.

For a start about hex editors, maybe this can help http://en.wikipedia.org/wiki/Hex_editor.

Perhaps AnyDVD HD is the better solution for you, its also the only program which currently can decrypt MKBv4 or later discs :(.

:rolleyes:

Yeah, I've since aquired AnyDVD HD... a fabulous proggy might I add. However, this sorta stuff interests me and I'd like to learn all about it eventually.

Thanks again,
O!

kkloster21
5th July 2008, 20:02
I have been reading several threads around here, trying to figure out a way to play blu-ray movies on my computer. I have an Intel core 2 quad Q9450 and i am running linux (Ubuntu 8.04 Hardy Heron, 64-bit version). I have a LG GGC-H20L blu-ray drive. The more i read, the more confused i get though.

I was able to apply the UDF 2.5 patch. I am able to get dumpHD running but i can't get the aacskeys library compiled for my 64-bit OS. (i think i am having a problem similar to fenton06 with my openssl installation) I was able to use a the precompiled binary version of aacskeys that sothis_ did. It only worked for one movie though. the other discs i tried did the same thing as fenton06 in his post #276 - it just sits there and doesn't do anything. i'm assuming that's a problem with the disc MKB version (and it probably updated the revocation list in my BD-ROM drive).

for the one disc i was able to decrypt and dump, i could watch all the special features (as separate .m2ts files) but i could NOT view the main feature (the actual movie). it started up and i could see and hear the MGM lion roar but then the picture stops moving (but the sound continues). i've read about other people having this problem also and read about some people having to mux the audio and video streams (http://forum.doom9.org/showthread.php?t=123282&highlight=dumphd&page=3) - is that necessary?

it's difficult to map the software landscape of all the tools that you guys have created. I have seen awhitehead's list of tools here:
http://forum.doom9.org/showthread.php?t=123282&highlight=dumphd
but it's tough (i think) for newer people like me to know how to use those tools together to just be able to watch a blu-ray movie on a (linux) computer.

i'd like to be able to watch blu-rays on my computer. but i'd also like to see a sort of "User's Guide to Watching Blu-ray Movies on a PC" available - a step by step guide to help new or experienced PC users get blu-ray going on their machines. I would love to write this guide myself, but first i need to know how to do it myself. I think what guys are doing (writing software tools and making them available to everyone) is awesome. i'd like to contribute in any way i can if possible.

setarip_old
5th July 2008, 21:01
@kkloster21

Hi!I have a LG GGC-H20L blu-ray drive.i'd like to be able to watch blu-rays on my computer.Is there some reason you can't play and watch your original Bluray discs on your system?

kkloster21
5th July 2008, 21:13
Maybe i should have said "i'd like to figure out how to watch blu-ray movies on my computer."

I've tried a few of these programs (DumpHD with aacskeys) and i haven't had much luck. i guess with the newest blu-ray discs, the MKB version is updated, rendering a lot of this software ineffective. (it seems this way from what i've read here - is that incorrect?)

setarip_old
5th July 2008, 22:11
Maybe i should have said "i'd like to figure out how to watch blu-ray movies on my computer."Sorry, perhaps I'm a bit slow today, but I still don't understand, if as you've stated, you have a Bluray drive as part of your system, why can't you simply play your original Bluray discs on your computer?

kkloster21
5th July 2008, 22:58
As i understand, retail blu-ray movie discs are encrypted with AACS encryption. I don't know of any linux compatible media players that can decrypt and play these movies on the fly. It's possible that such a program exists and i just don't know about it. does anyone here know of any linux media players that can playback blu-ray movies straight from the disc?

Gusar
5th July 2008, 23:01
@setarip_old: He's running Linux. So it's not just plopping in the disc and starting PowerDVD.

@kkloster21: Playing Blu-ray movies in Linux is not easy. A patched MPlayer and only a patched MPlayer can play the movie, if you can decrypt it. That's a big if though. You're basically limited to movies for which the VUK is available in this (http://forum.doom9.org/showthread.php?t=120988) thread. If no VUK is available, you're pretty much screwed unless you also have Windows on your machine.

setarip_old
5th July 2008, 23:12
Sorry, I missed the Linux-only limitation.

Be that as it may, these most recent posts are mystifying to me. Perhaps someone can explain why you would purchase a Bluray drive for a system on which you can't play Bluray discs?

kkloster21
5th July 2008, 23:16
Thanks Gusar. so a patched MPlayer is the only thing that can do it... I was able to watch some of the special features (after being dumped by DumpHD) in VLC though, as i said i wasn't able to watch the movie itself. VLC won't play decrypted movies?

kkloster21
5th July 2008, 23:20
@setarip_old: I just built the computer and i wanted to put in a blu-ray drive at time of build. I figured there would be a way to make it happen, even if it takes a few weeks or months and some work on my part. if its absolutely impossible to do on linux then i can always dual boot with windows but, i'd prefer not to have to do that.

setarip_old
6th July 2008, 01:54
@kkloster21

(I promise, this is the last question I'll ask you about this)

Thanks for taking the time to respond ;>} - But, yet again, although I know it's not important to you that I understand, perhaps you can explain what you mean by:if its absolutely impossible to do on linux then i can always dual boot with windows but, i'd prefer not to have to do that.If you have Windows available on your system, once again, you can certainly effortlessly play your original Bluray discs on your system...

kkloster21
6th July 2008, 02:42
@setarip_old: no worries about the questions! :) I don't have windows installed on my system now but if that's the only way to watch blu-rays on my computer then i'll setup a dual boot configuration.

@Gusar: any idea where i can find that mplayer patch? i looked around for it and couldn't find anything.

Turtleggjp
10th July 2008, 15:42
@setarip_old: no worries about the questions! :) I don't have windows installed on my system now but if that's the only way to watch blu-rays on my computer then i'll setup a dual boot configuration.

You can thank the studios and their paranoia about piracy for that. There are so many rules and restrictions with the HD discs, that an open environment like Linux could never be trusted with such precious material (even Macs are not good enough). Therefore, the only official players that you will see will be for Windows (because it's so darn secure and robust!! :rolleyes:). Eventually, I'm sure that open source projects like MPlayer will have the ability to playback complete HD disc structures, but it may not be for a year or two or more... They may even have the ability to decrypt on the fly by then! For now though, you will most likely need to either watch the disc in Windows, or do some processing to it in Windows (decrypting, transcoding, etc.) before it can be played in Linux.

Oopho2ei
11th July 2008, 17:07
Eventually, I'm sure that open source projects like MPlayer will have the ability to playback complete HD disc structures, but it may not be for a year or two or more...
I have like 20 hd-dvds/blue rays and they all playback nicely with mplayer (for months!). The parameters are sometimes a bit weird for linux noobs but it works.
Example for Spy Game with eac3 sound:
mplayer -demuxer lavf -ac ffeac3 -fps 24000/1001 -aid 5 FEATURE_1.EVO

my config:
cat .mplayer/config
# Write your default config options here!

lavdopts=fast=1:threads=2
vo=xv

Version: 1:1.0.rc2svn20080531-0.1

No patch or whatever is needed. Also you only need to specify those parameters if you encounter problems (like no sound/av sync/...)

---------

What i originally wanted to ask: Does anyone have a valid certificate/privkey for aacskeys? I can sniff the host_cert and host_nonce without any problems but don't have any corresponding host_key for the signature :/

Turtleggjp
12th July 2008, 21:54
mplayer -demuxer lavf -ac ffeac3 -fps 24000/1001 -aid 5 FEATURE_1.EVO

This was my point. You are not playing the disc structure, you are simply playing the main movie file, which I will agree should work just fine. You just don't have the menu system and probably not chapters either. I can open the VIDEO_TS.IFO file of a DVD with Media Player Classic, and it will play with menus and chapters. As far as I know, playback like this with HD discs is not possible with mplayer or Media Player Classic.

Oopho2ei
14th July 2008, 02:08
Could we please have a parameter for aacskeys which allows to skip authentication in the next version? I have patched my firmware of my PX-920SA (compatible with GGW-H20L). :)

fpga
14th July 2008, 23:26
@setarip_old: I just built the computer and i wanted to put in a blu-ray drive at time of build. I figured there would be a way to make it happen, even if it takes a few weeks or months and some work on my part. if its absolutely impossible to do on linux then i can always dual boot with windows but, i'd prefer not to have to do that.
I don't know how well some of the Windows DVD programs (like AnyDVD) will work since they are likely operate at a pretty low level, but you might give Wine a try (allows running Windows programs from within Linux).

KenD00
15th July 2008, 11:45
Could we please have a parameter for aacskeys which allows to skip authentication in the next version?

Regarding what you have posted here (http://forum.doom9.org/showthread.php?p=1159131#post1159131) this isn't just skipping the authentication process but an own form of "authentication". Current aacskeys is some sort of intelligent and detects if the xbox drive is present and then uses the xbox hack rather the ACCS way, so this would be the preferred way. What firmware string does aacskeys report when using your custom firmware? Maybe i can find some time and integrate this new "hack" ;).

:rolleyes:

Oopho2ei
15th July 2008, 12:58
Regarding what you have posted here (http://forum.doom9.org/showthread.php?p=1159131#post1159131) this isn't just skipping the authentication process but an own form of "authentication".
I commented out the part between "agid = report_agid(h, bluray); + error handler" and "errnr = read_vid(h, agid, volume_id, mac, bluray);" as well as the following "calculate_volume_id_mac() + error handler". That works fine.

Current aacskeys is some sort of intelligent and detects if the xbox drive is present and then uses the xbox hack rather the ACCS way, so this would be the preferred way. What firmware string does aacskeys report when using your custom firmware?
I haven't changed the firmware string so it can't be distinguished from the original firmware looking at the return of inquiry. It only behaves differently when executing the cmdAD/80 handler.

Maybe i can find some time and integrate this new "hack" ;).
The easiest way to do it is just executing read_vid() right after "report_agid() + error handler" and see if it succeeds. Only if it doesn't perform the usual authentication.

KenD00
24th July 2008, 08:40
Today i'm proud to present a new version of aacskeys. Along the usual bugfixes it has these new features:

Changed CLI, options are now passed the usual -option style
Given parameters are checked and errors are reported
You have the option to choose how the Volume ID should be retrieved
The XBox hack is used automatically for the Toshiba SD-H802A drive
Can use the recently discovered way to get the Volume ID from patched drives

The archive contains precompiled executables and libraries for Windows and Linux (32 bit and 64 bit) and the source code. The linux versions are now statically linked against OpenSSL, this hopefully solves the problems people had where OpenSSL couldn't be found.

Known issues: If you try to decrypt a MKBv4 or later disc it can happen that aacskeys seems to hang (in verbose mode it doesn't continue after it prints out the current directory) and produces 100% CPU load. I currently don't know excactly why this happens, it looks like that it comes from crypto code that fails because there is no processing key for this MKB version present. I remember people saying they would release a new processing key but want to keep the "community" one step behind Slysoft.. well, AFAIK Slysoft is at MKBv7...

Grab aacskeys 0.3.0 here (the zip and tar.gz have the same content):
aacskeys 0.3.0 (zip, Rapidshare) (http://rapidshare.com/files/132033106/aacskeys-0.3.0.zip.html)
aacskeys 0.3.0 (zip, Sendspace) (http://www.sendspace.com/file/n5c5ut)
aacskeys 0.3.0 (tar.gz, Rapidshare) (http://rapidshare.com/files/132033650/aacskeys-0.3.0.tar.gz.html)
aacskeys 0.3.0 (tar.gz, Sendspace) (http://www.sendspace.com/file/xcyyye)

:rolleyes:

derbeDeus
24th July 2008, 09:45
Excelent work :)

I see that aacskeys still tries to load /AACS/VTKF000.AACS. That will fail for some discs that don't have the file and start their title file counting not with 000; eg. Pan's Labirinth (VTKF001.AACS is the first), Terminator 2[DE] (VTKF080.AACS).

Another thing, host_key_point can be calculated from host_key and G on EC using a function like aacs_calculate_bus_key (Figure 4-6, page 32 in AACS spec).
And it would be cool if (priv_key, host_cert) pair could be read from a file, just like device/processing keys. What do you say about this? :)

KenD00
25th July 2008, 05:28
I thought about that numbering thing, DumpHD does it already but i haven't heard any complaints about aacskeys not doing it (until now ;)), so i haven't implemented that. The whole file I/O stuff is still quite messy and unsafe, i wanted to move that code to C++ too, especially because i really wanted to read the Host Cert / Priv Key from file too, but i still haven't found the time yet.

Yeah, i wondered why he doesn't calculate the host nonce and uses a precalculated one, then i looked into the spec and thought "oh shit, too much math *g*". The crypto code is also messy and i honestly don't understand much of it right now. The OpenSSL doc is also not very complete so i don't know if and when i will touch that part.

:rolleyes:

Oopho2ei
25th July 2008, 16:07
It seems to work. Well done!
Now we need more people working on the players to get new key material. They are using advanced rootkit techniques to corrupt the system. It's quite a challenge. Those people who have experiences with Themida should probably have a look at windvd :)

kkloster21
28th July 2008, 03:21
@fpga: I'm wondering if i could use AnyDVD or some other program in Windows (or even in Wine) to get the VUKs of the discs that i own and then populate the KEYDB.cfg database with those keys and just watch them in linux on mplayer (i know i can watch blu-rays in linux if i have the VUK or some key). Would this be possible? Or i guess the real question is: is there a program like aacskeys for windows that will actually show the decrypted keys for blu-ray discs up to MKBv7 (or whatever the latest is)? does AnyDVD actually output the keys?

gioowe
28th July 2008, 13:27
AnyDVD doesn't output VUKs. And there's currently no other program that can handle MKBv4, MKBv6 or MKBv7 media. Not no mention BD+.

Oopho2ei
28th July 2008, 17:08
afaik AnyDVD contains a long list of those volume unique keys. Yes the vuk is enough for decryption. But you really should try to find them yourself because currently AnyDVD is like a single point of failure for the whole decryption network. If those open source decryption tools can't keep up and AnyDVD gets sued it would be a big blow for the linux blue ray playback support.
Anyway i am trying to get some new key material for aacskeys but this will take some time. So just wait or help.

kkloster21
29th July 2008, 02:38
@Oopho2ei: I'd love to help if i am able. I may not have the skill set but i can learn. What are some ways i could help or some things i could start learning to make myself useful? I have a little bit of experience with C.

Oopho2ei
29th July 2008, 16:42
Simply choose a player (hardware/software) and start to reverse engineer it. You need to know a lot but there are plenty of documents about this you can study. I don't think you really need to program anything unless you want to write a plugin or inject code in the address space of the process (hooks).

kkloster21
30th July 2008, 07:15
can you explain a little bit more what you mean by "choose a player (hardware/software) and start to reverse engineer it." ? Choose a hardware drive and a software player in windows? One or the other? Wouldn't reverse engineering any of that stuff involve looking at code or firmware of some kind? I do have an LG GGC-H20L combo drive that i can start trying things on. I just need to know what to do with it or where to find documentation on what to do. Would it be possible for you to post or PM a few links for some documents that i could study?

Oopho2ei
30th July 2008, 07:41
The GGC doesn't contain any device keys. The software player you use to playback your encrypted blue rays has them. Yes it involves looking at the disassembly *lol* among other things. If you are a developer of one of those software players you can use the source code of course. Anyway this is going off topic now. You need to educate yourself.

zeroprobe
1st August 2008, 20:19
can you explain a little bit more what you mean by "choose a player (hardware/software) and start to reverse engineer it." ? Choose a hardware drive and a software player in windows? One or the other? Wouldn't reverse engineering any of that stuff involve looking at code or firmware of some kind? I do have an LG GGC-H20L combo drive that i can start trying things on. I just need to know what to do with it or where to find documentation on what to do. Would it be possible for you to post or PM a few links for some documents that i could study?


Look up and master Assembly language then PM him :)

pjo
5th August 2008, 02:57
Yes, if your drive has been upgraded to MKBv3 or later this is the way to do it.

Unfortunately your disc seems to be MKBv4 or newer, there is no known Processing Key for these discs so you are currently out of luck (with aacskeys).

To check the MKB version of the disc, open the file AACS\MKB_RO.inf in a hex editor and look at offset 0x08, the next 4 bytes are the version number.

:rolleyes:

Thanks KenD00 !
I appreciate your work on aacskeys.

I am using aacskeys in backupBDAVfor V1 and V3 042.

My question is \AACS\MKB_RW.inf in case of BD-RE,
MKB version is at offset 0x08, the next 4 bytes same as MKB_RO.inf ?

The other question:
If I try to read BD-RE with MKBv7 or v4 and with P-MKB v7 or v4 using a drive whose P-MKB is v1, will the drive is modified to P-MKB v7 or v4 ?

pjo

KenD00
7th August 2008, 02:57
Beeing a lazy guy i opened a MKB_RW.inf i found on one of my Blu-Rays with my never released MKBView and it decoded it just fine, so yes, both MKBs have the same structure. And that MKB had also the same version than the MKB_RO.inf MKB on that disc. I also took a quick look at the specs and they don't define an extra MKB for the Recordable Book, there is only one common MKB type.

Your second question is a bit tricky but one thing i can say for sure: if an aacs authentication process is started (e.g. by aacskeys or a software player) the drive will be updated. However, the spec doesn't forbid to update the drive earlier, so i don't know if just putting the disc into the drive will already update it. This may be even different accross different drives.

pjo, i must thank you that you mentioned backupBDAV. This tool sounded unknown to me (good that i haven't checked my HDD, i already had an older version of it) so i googled for it and couldn't believe what i've found. On some sort of japanese website i found something that looked like MKBv4 and MKBv7 Processing Keys. So i gave aacskeys a try with 2 MKBv4 HD-DVDs and it decrypted them and said the VUK is valid?!?!? Next i ran DumpHD on my only MKBv7 Blu-Ray John Rambo and WinDVD played the rip fine!! I can't believe that, the keys are there for almost 5 days now, they are real and this hasn't made big news yet? Anyone knows something about that, theres no info on that site from whom these keys are.

:rolleyes:

pjo
7th August 2008, 03:55
Beeing a lazy guy i opened a MKB_RW.inf i found on one of my Blu-Rays with my never released MKBView and it decoded it just fine, so yes, both MKBs have the same structure. And that MKB had also the same version than the MKB_RO.inf MKB on that disc. I also took a quick look at the specs and they don't define an extra MKB for the Recordable Book, there is only one common MKB type.

Your second question is a bit tricky but one thing i can say for sure: if an aacs authentication process is started (e.g. by aacskeys or a software player) the drive will be updated. However, the spec doesn't forbid to update the drive earlier, so i don't know if just putting the disc into the drive will already update it. This may be even different accross different drives.

pjo, i must thank you that you mentioned backupBDAV. This tool sounded unknown to me (good that i haven't checked my HDD, i already had an older version of it) so i googled for it and couldn't believe what i've found. On some sort of japanese website i found something that looked like MKBv4 and MKBv7 Processing Keys. So i gave aacskeys a try with 2 MKBv4 HD-DVDs and it decrypted them and said the VUK is valid?!?!? Next i ran DumpHD on my only MKBv7 Blu-Ray John Rambo and WinDVD played the rip fine!! I can't believe that, the keys are there for almost 5 days now, they are real and this hasn't made big news yet? Anyone knows something about that, theres no info on that site from whom these keys are.

:rolleyes:

Thnaks for your reply.

I mounted MKBv7 BD-RE onto a Panasonic Blueray harddisk recorder which was MKBv1 for sure. now the recorder is V7 !

But I can run BackupBdav 042 which is available on this site.
http://forum.doom9.org/showthread.php?t=125592&highlight=BDAV
with v7 processing key.

It looks like v7 has been on the internet for a few weeks already. I found it in one of a blog(in Japanese language), but it was just a hint, not direct v7.:)

I could not find v4. Pls send personal message on this if it is ok for you.

SvT
7th August 2008, 18:17
KenD00 and pjo :)

Thanks for all the hints !

I have the movie Daylight on HD-DVD and it plays fine (SAP and PC) when I load AnyDVD-HD. It wasn't untill today that I noticed it was MKBv4.

"label DAYLIGHT
AACS!
HD type: 0
MKB version 4"

So I tried aacskeys h:

Could not find a Processing Key or Device Key resulting in the Media Key.
Possible key tried: 09F911029D74E35BD84156C5635688C0
Possible key tried: 455FE10422CA29C4933F95052B792AB2

Now I replace my file with the new "ProcessingDeviceKeysSimple.txt" I found thanks to you !

Volume Unique Key: D02FFAE3253D6D41861F3D11643DBE30
TKF Hash (DiscID): 9880EC369B4C8C26C9B7188204D3E5246B8EDCE4

Seems to work great ! So indeed this is BIG news !!! This means all free tools start to work again. Please correct me if I'm wrong.

I think we are looking at the same source because all you find is files and no further info.

Greets

Oopho2ei
7th August 2008, 20:46
Awesome! Why don't you post the keys here? Has anyone started working on the virtual machine used in BD+?

pjo
7th August 2008, 23:37
KenD00 and pjo :)

Thanks for all the hints !

I have the movie Daylight on HD-DVD and it plays fine (SAP and PC) when I load AnyDVD-HD. It wasn't untill today that I noticed it was MKBv4.

"label DAYLIGHT
AACS!
HD type: 0
MKB version 4"

So I tried aacskeys h:

Could not find a Processing Key or Device Key resulting in the Media Key.
Possible key tried: 09F911029D74E35BD84156C5635688C0
Possible key tried: 455FE10422CA29C4933F95052B792AB2

Now I replace my file with the new "ProcessingDeviceKeysSimple.txt" I found thanks to you !

Volume Unique Key: D02FFAE3253D6D41861F3D11643DBE30
TKF Hash (DiscID): 9880EC369B4C8C26C9B7188204D3E5246B8EDCE4

Seems to work great ! So indeed this is BIG news !!! This means all free tools start to work again. Please correct me if I'm wrong.

I think we are looking at the same source because all you find is files and no further info.

Greets

SvT, Congratulations ! You found it.

pjo

pjo
7th August 2008, 23:41
Awesome! Why don't you post the keys here? Has anyone started working on the virtual machine used in BD+?

I heard that several people were copying BD+ ok. But I cannot test it because I do not have BD+ disk.
pjo

Oopho2ei
8th August 2008, 06:30
I heard that several people were copying BD+ ok. But I cannot test it because I do not have BD+ disk.
pjo
Nice. Where can i find the source code of those programs?

pjo
8th August 2008, 09:41
Nice. Where can i find the source code of those programs?

I do not think the source for this is available.
It looks like it is SlySoft AnyDVD.

Oopho2ei
8th August 2008, 14:24
Could we please get some experimental device key support for aacskeys? A seperate plaintext file with a simple format like "KEYDB.cfg" would be sufficient. Also maybe you could include some features of MKBView in verbose mode.

KenD00
8th August 2008, 15:57
Aacskeys should already be able to process Device Keys, just put them in the ProcessingDeviceKeysSimple.txt file. And maybe check the source code to see if that crypto stuff makes sense, i currently don't understand it :D.

I wanted at least show the MKB version of the disc, but currently i can't code anything, my main computer broke 2 days ago, seems to be the mainboard. If thats the case, i need to change my whole water cooling for the new one, that will take some time (hopefully not as much as last time :().

:rolleyes:

gioowe
8th August 2008, 18:35
aacskeys already handles devices keys. It always did.

Oopho2ei
8th August 2008, 20:55
How does aacskeys determine the position of the device key in the tree? According to the spec (3.2.3) there is a path number associated with each device key which determines the path from the root to the position of the node. Without the position i wouldn't know which device key to choose and how to proceed from that node to the processing key. You see my point: that path number isn't stored in the ProcessingDeviceKeysSimple.txt file. I was aware of the fact that the source code already allows the use of device keys but there is just no way to store them other than hacking them into the source code. All keys should generally be stored in a separate file.

gioowe
8th August 2008, 22:37
It doesn't - it tries all positions (encrypted c-values).

Oopho2ei
8th August 2008, 23:33
It doesn't - it tries all positions (encrypted c-values).
You can try all the c-values if you have a list of processing keys which isn't the case here. One has to select the correct device key of a node which is the root of the subtree which contains the node i need the processing key of. A device key is not a processing key.. maybe that is what you are thinking. Using the device key and the specified hash function (AES-G3) you can calculate the left and right subsidiary device key to go further down in the tree and the processing key for the current node. You never directly use a device key to decrypt a c-value.

gioowe
9th August 2008, 11:33
You can try all the c-values if you have a list of processing keys which isn't the case here. One has to select the correct device key of a node which is the root of the subtree which contains the node i need the processing key of. A device key is not a processing key.. maybe that is what you are thinking. Using the device key and the specified hash function (AES-G3) you can calculate the left and right subsidiary device key to go further down in the tree and the processing key for the current node. You never directly use a device key to decrypt a c-value.

You simply use all keys you have, not knowing if it is a device or processing key. First you take the first encrypted c-value and assume your key is a processing key. Check it by decrypting the corresponding verification data. If it's different you go to the corresponding subtree lowest node, go one level up assume your key is now a device key, calc down the tree and verify again. If it still isn't you continue that by going and enumerating all levels up until you are at the top of the subtree. Then you continue with all other c-values and corresponding verification data. And after that you can't use your key and take another one. And do that same procedure again. That's the way aacskey is doing it.

Oopho2ei
9th August 2008, 12:23
There seems to be a bug in the linux/amd64 version of aacskeys-0.3. I have added the new keys to the ProcessingDeviceKeysSimple.txt and run from that directory the following commands:
./bin/linux32/aacskeys -v /media/cdrom
This is working and gives the correct result.
./bin/linux64/aacskeys -v /media/cdrom
This doesn't work and it is just looping giving no ouput but the "Current path:" line. There is only one ProcessingDeviceKeysSimple.txt in the directory i am calling these commands from. I have been using the linux/amd64 version with a mkb v1 generation disk without any problems but it fails when i try to get the keys from a mkb v4 generation disc.

mkb: http://uploaded.to/?id=yurqxj

gioowe: ok, i will try it. But it would be strange that the specification demands storing redundant data. Maybe that "brute force" search implemented in aacskeys as you described it cannot be realized easily in licensed players.

gioowe
9th August 2008, 14:04
Licensed players know their device keys position and corresponding subtrees (UV mask). We do not. All publicly available keys are processing keys. Only one device key is known (53BD...) to date and that one lead to PK of MKBv1 (09F9...)

53BD... was actually a subdevice key, the true device key is 86D2...

KenD00
9th August 2008, 16:01
@Oopho2ei
This endless loop in the x64 version happens when aacskeys cannot find a processing key. But since the x32 version works with the same ProcessingDeviceKeysSimple.txt the code is more broken than i thought. I will look into this as soon as i have a working machine again.

That "brute force" approach will take longer the more revocations happen, maybe because of that the devices know their uv.

:rolleyes:

pjo
13th August 2008, 04:05
Thanks for aacskeys v0.26(BDAV v0.50) new version works for dummy drive !

Using two MKBv7 and P-MKB v7 drives, no need to
run PowerDVD or no need to run USB Inspector.

I am wondering how dummy drive works. Please explain how it works if you would.

pjo

KenD00
13th August 2008, 16:08
That version you are talking about is not from me, i even haven't seen that one so i can't help you. Just beeing curious, whats that dummy drive thing doing?

:rolleyes:

pjo
14th August 2008, 01:28
That version you are talking about is not from me, i even haven't seen that one so i can't help you. Just beeing curious, whats that dummy drive thing doing?

:rolleyes:

That aacskeys is included in BackupBDAV 050 found in this forum.

I do not know the detail on how dummy drive works but I assume that by using an extra dummy drive (physical BD-R drive) some kind of key is found so that there is no need to run PowerDVD for hammering.

pjo

edit
You can put any disk in the dummy drive. Even blank disk is fine.
This suggests that some kind of key in the dummy drive hardware is read and used in this version of aacskeys.

Oopho2ei
17th August 2008, 15:34
I need the following patch to compile aacskeys on my my linux distribution (debian/lenny) with gcc (version 4.3.1):

diff -rupN aacskeys-0.3.0/src/aacs_ecdsa.cpp aacskeys-0.3.0_fixed/src/aacs_ecdsa.cpp
--- aacskeys-0.3.0/src/aacs_ecdsa.cpp 2008-07-24 07:06:58.000000000 +0200
+++ aacskeys-0.3.0_fixed/src/aacs_ecdsa.cpp 2008-08-17 16:09:28.000000000 +0200
@@ -2,6 +2,7 @@

#include <cstdio>
#include <string>
+#include <cstring>

#include <openssl/bn.h>
#include <openssl/evp.h>
diff -rupN aacskeys-0.3.0/src/aacskeys.cpp aacskeys-0.3.0_fixed/src/aacskeys.cpp
--- aacskeys-0.3.0/src/aacskeys.cpp 2008-07-24 08:31:29.000000000 +0200
+++ aacskeys-0.3.0_fixed/src/aacskeys.cpp 2008-08-17 16:10:36.000000000 +0200
@@ -35,6 +35,7 @@
// general
#include <cstdio>
#include <string>
+#include <cstring>
//#include <malloc.h>

/* *** KenD00 start: Added include for variable argument list processing *** */
diff -rupN aacskeys-0.3.0/src/ioctl.cpp aacskeys-0.3.0_fixed/src/ioctl.cpp
--- aacskeys-0.3.0/src/ioctl.cpp 2008-07-24 07:06:58.000000000 +0200
+++ aacskeys-0.3.0_fixed/src/ioctl.cpp 2008-08-17 16:11:42.000000000 +0200
@@ -2,6 +2,7 @@

#include <cstdio>
#include <sstream>
+#include <cstring>
#include <iomanip>


diff -rupN aacskeys-0.3.0/src/mmc.cpp aacskeys-0.3.0_fixed/src/mmc.cpp
--- aacskeys-0.3.0/src/mmc.cpp 2008-07-24 07:06:58.000000000 +0200
+++ aacskeys-0.3.0_fixed/src/mmc.cpp 2008-08-17 16:12:21.000000000 +0200
@@ -1,6 +1,7 @@
#include "mmc.h"

#include <string>
+#include <cstring>
#include <cstdio>

#define CDB_SIZE 16


Otherwise i get errors like: aacs_ecdsa.cpp
src/aacs_ecdsa.cpp: In function ‘int aacs_calculate_bus_key(unsigned char*, unsigned char*, unsigned char*, unsigned char*)’:
src/aacs_ecdsa.cpp:330: error: ‘memcpy’ was not declared in this scope

copy the file in the root directory of aacskeys and use patch -p1 < patchname.diff

Maybe you can fix this in the upcomping new release too :thanks:

FoxDisc
18th August 2008, 19:26
Licensed players know their device keys position and corresponding subtrees (UV mask). We do not.

Why don't we know the UV mask? Doesn't each PK have a corresponding UV number? Doesn't each C-Value correspond to a single UV number? Once you find a PK that decrypts a C-Value, you know the matching UV. Or am I missing something?

Peer van Heuen
18th August 2008, 21:12
Why don't we know the UV mask? Doesn't each PK have a corresponding UV number? Doesn't each C-Value correspond to a single UV number? Once you find a PK that decrypts a C-Value, you know the matching UV. Or am I missing something?

No, you're not.

Oopho2ei
18th August 2008, 22:03
Why don't we know the UV mask? Doesn't each PK have a corresponding UV number? Doesn't each C-Value correspond to a single UV number? Once you find a PK that decrypts a C-Value, you know the matching UV. Or am I missing something?
I think that is correct but we were actually talking about device keys and not processing keys. But because the processing key is derived from exactly one device key and that "path" is known you would get this position as well. If more people would help reverse engineering we wouldn't even have to bother about this and could instead use the stored values.

FoxDisc
19th August 2008, 13:59
we were actually talking about device keys and not processing keys. But because the processing key is derived from exactly one device key and that "path" is known you would get this position as well.

Agreed. The reason I asked, was that I had assumed that each time a PK (or DK ) was identified that its matching uv number would be associated with it and stored somewhere. Then the correct c-value could be identified using the same basic procedures described in the AACS docs. You'd just find a c-value with a matching u number for your PK and a v-number that is not below the PK's v-number. (Clearly, you can start with either the list of c-values or the list of known PKs.)

If more people would help reverse engineering we wouldn't even have to bother about this and could instead use the stored values.

I miss the excitement of the early days of discovery (not that I did anything other than watch and try to follow the technical details). With a smile, I have to blame Peer in part. He's really too good. I suspect the payoff for discovery is a lot less when Peer's in the lead.

Peer van Heuen
19th August 2008, 21:36
I miss the excitement of the early days of discovery (not that I did anything other than watch and try to follow the technical details). With a smile, I have to blame Peer in part. He's really too good. I suspect the payoff for discovery is a lot less when Peer's in the lead.

*blush* :)

KenD00
30th August 2008, 10:58
This new release is mainly a bugfix, i hope it fixes all the problems of the previous one. Beeing to lazy to write it a second time, i copy the changelog from the README:

- Fixed to run correctly under 64 bit
- Detects if the given mountpoint is a symlink and handles it correctly (Linux)
- Accepts mountpoints with a trailing "/" (Linux)
- Uses the Title Key file with the lowest number if VTKF000.AACS isn't present
(HD-DVD Advanced Content)
- Displays version of MKB
- New option --no-preinval to disable invalidation of all AGIDs before
requesting a new one
- Added missing includes to avoid compilation errors on some machines
(thanks Oopho2ei)
- Lots of small fixes to avoid buffer overruns and null pointers


As usual, the archive contains precompiled binaries / libraries for linux (32 bit and 64 bit), windows and the source code, the zip and tar.gz have the same content.

Get them here:
aacskeys 0.3.1 (RapidShare, zip) (http://rapidshare.com/files/141253835/aacskeys-0.3.1.zip.html)
aacskeys 0.3.1 (SendSpace, zip) (http://www.sendspace.com/file/bps0f4)
aacskeys 0.3.1 (RapidShare, tar.gz) (http://rapidshare.com/files/141255292/aacskeys-0.3.1.tar.gz.html)
aacskeys 0.3.1 (SendSpace, tar.gz) (http://www.sendspace.com/file/5acnol)

:rolleyes:

Oopho2ei
30th August 2008, 15:04
Thanks a lot for the corrections. :)

KenD00
20th September 2008, 19:10
This new release has one big new feature: Blu-Ray Recordable support (BDMV and BDAV type) :).
From the changelog:

0.3.5: 2008-09-20
- Experimental Blu-Ray Recordable support (BDMV and BDAV)
- New option --pa-lba (currently this must be used with Blu-Ray Recordables if the Binding Nonce is not given on the command line)
- The Host Private Key and Host Certificate is now loaded from the external file HostKeyCertificate.txt
- Diplays more information about the drive and inserted disc
- Fixed an endianess problem

The whole recordable stuff isn't tested because i don't have any AACS protected recordings, so please test this feature and report back if something isn't working. The processing of recordables isn't fully automatic as for the other disc types because aacskeys hasn't an UDF parser integrated. This will maybe change in a later release if i find a suitable parser or have written an own one.

As usual, the archive contains precompiled binaries / libraries for linux (32 bit and 64 bit), windows and the source code, the zip and tar.gz have the same content.

Get them here:
aacskeys 0.3.5 (RapidShare, zip) (http://rapidshare.com/files/146916519/aacskeys-0.3.5.zip.html)
aacskeys 0.3.5 (RapidShare, tar.gz) (http://rapidshare.com/files/146917858/aacskeys-0.3.5.tar.gz.html)
aacskeys 0.3.5 (SendSpace, zip) (http://www.sendspace.com/file/6frubx)
aacskeys 0.3.5 (SendSpace, tar.gz) (http://www.sendspace.com/file/gmkix8)


If none of the automatic modes to retrieve the Volume ID / Binding Nonce works for you, try the following utilities to sniff them from the bus (works only under Windows and requires a licensed software player):

For Volume ID: DumpVID Package 0.31
DumpVID Package 0.31 (RapidShare) (http://rapidshare.com/files/100373276/dumpvidpkg_0.31.zip.html)
DumpVID Package 0.31 (SendSpace) (http://www.sendspace.com/file/n6wely)

For Binding Nonce: DumpBN 0.31 (from BackupBDAV 0.50)
DumpBN 0.31 (RapidShare) (http://rapidshare.com/files/147507385/dumpbn-0.31.zip.html)
DumpBN 0.31 (SendSpace) (http://www.sendspace.com/file/9kznpr)

:rolleyes:

Adub
20th September 2008, 19:33
Dude, you are awesome!! Always know that your work is appreciated!! Quick question, what MKB version are we up to now?

KenD00
20th September 2008, 20:01
Thanks :).

The situation is still unchanged, MKB up to version 7, Volume Id / Binding Nonce retrieval up to version 1 :(. Oh, if you can't get the Binding Nonce, google for dumpbn, this is based on DumpVID and does the same but for Binding Nonces.

:rolleyes:

KenD00
20th September 2008, 23:51
This post contains a link which will always point to the latest aacskeys version.

Current version: 0.4.0c, released: 2009-08-30

Download links (http://forum.doom9.org/showthread.php?p=1320065#post1320065)

:rolleyes:

CiNcH
22nd September 2008, 08:30
The situation is still unchanged, MKB up to version 7, Volume Id / Binding Nonce retrieval up to version 1

May I ask which are the latest versions that can be found on BD nowadays?

BTW, I could not find anything about dumpbn.

KenD00
22nd September 2008, 21:02
In the Slysoft forum there are reports about MKBv10.

You are right, google doesn't give anything useful about DumpBN, it's included in BackupBDAV, i have added download links for it (and DumpVID) in the upper release post.

:rolleyes:

TomZ
26th September 2008, 16:54
[...]
If none of the automatic modes to retrieve the Volume ID / Binding Nonce works for you, try the following utilities to sniff them from the bus (works only under Windows and requires a licensed software player):


I'm sorry to tell you that but you're almost wrong KenD00. You can use DumpVID under linux with wine and it works. OK, it's not a native way under linux but it's the trick.
What i do is launching dumpVID.exe with wine, access the BRD with aackeys and the VID appears on the dumpVID console. Then you can re-use aacskey program or DumpHD...

Cheers

PS : thx a lot for your crazy work...

KenD00
27th September 2008, 03:11
Well, partially you are right, i have never tried to run it under wine, so that does work, thanks for the info.

But you are using a patched drive, so you can retrieve the Volume ID in a "not official" way, but this isn't the purpose of DumpVID. DumpVID is for the case where you can't get the Volume ID, this is for all drives which are > MKBv1 and are not patched. In that case you need a licensed software player, and, correct me if im wrong, i don't know of any licensed software player that runs under linux (native or under wine).

:rolleyes:

XAvAX
29th September 2008, 02:51
Hi, here's a compile fix for Gentoo:

in libaacskeys.make, there needs to be a substitution.

/usr/lib/jvm/java-6-sun/include/
must be replaced with
/etc/java-config-2/current-system-vm/include/ , and

/usr/lib/jvm/java-6-sun/include/linux/
must be replaced with
/etc/java-config-2/current-system-vm/include/linux/ as well

The best way to check if the host distribution is Gentoo is by checking for the file:
/etc/gentoo-release

TomZ
29th September 2008, 13:39
But you are using a patched drive, so you can retrieve the Volume ID in a "not official" way, but this isn't the purpose of DumpVID. DumpVID is for the case where you can't get the Volume ID, this is for all drives which are > MKBv1 and are not patched. In that case you need a licensed software player, and, correct me if im wrong, i don't know of any licensed software player that runs under linux (native or under wine).

:rolleyes:

You're right... and you're wrong :p
You're right whent you say i don't need dumpVID as my drive is patched. But you're wrong when you say you need a commercial software. Here is the way to retrieve the VUK :

- you lanch dumpVID.exe with wine, something like that :

# wine dumpVID.exe d:

- in another console, you launch aacskeys

# aacskeys -v /media/bluray

- immediately, dumpVID will give you the VID
- then, you launch again aacskeys with the VID to get the VUK :

# aacskeys -v /media/bluray <VID>

and aacskeys will now give you the VUK !

'Z

Oopho2ei
29th September 2008, 14:44
That's correct but aacskeys displays the volume id. So why would you need to run dumpVID.exe in the background?

TomZ
29th September 2008, 15:10
If your drive is not "firmware patched" i think aacskeys doesn't display the vid, am i wrong ?
I'm not at home at the moment but i'll check all of that this evening. All i can remember is before patching my drive i had to use dumpVID to get the VUK with aacskeys.

kkloster21
29th September 2008, 15:42
i'm trying your approach of running dumpVID in the background and when i try to access the disc with aacskeys, nothing comes out of dumpVID. no VID or anything. it still just says: "Hammering drive..." I tried several different delay times (like 50, 120, 130, 150, 200). aacskeys is not outputting VID either.

this is without patching my drive.

any advice on what to try?

thanks!

TomZ
29th September 2008, 15:46
I'll check that this evening and give you a feedback.

TomZ
29th September 2008, 21:39
So... I've tried and dumpvid give me the VID when i launch aacskeys. OK, as my LG drive is patched, it's not necessary but the test is ok.

The test is done with BRD Ratatouille, french version.

I launch dumpvid with wine, press ENTER to start hammering. Then i execute aacskeys from another console

vdr@vdrbox:~/DumpHD/aacskeys-0.3.1$ ./bin/linux64/aacskeys -v /media/cdrom0

and :


vdr@vdrbox:~/DumpHD$ wine dumpvid.exe d
DumpVID 0.3 by KenD00 (adapted for bluray testing)

Drive type is recognised as CDROM/DVD.

Sending SPC1 Test Unit CDB6 command..done.
Returned good status.

Press ENTER to start hammering

Hammering drive...
vid: 525F758BFA0C85E8CA4B1E9C9EBD6BF3
Hammering finished.


then :


vdr@vdrbox:~/DumpHD/aacskeys-0.3.1$ ./bin/linux64/aacskeys -v /media/cdrom0 525F758BFA0C85E8CA4B1E9C9EBD6BF3
aacskeys 0.3.1

Current path: /home/vdr/DumpHD/aacskeys-0.3.1

MKBv: 4
Processing key: F190A1E8178D80643494394F8031D9C8
Encrypted C-value: 788A172D47C66A408D7D33F90D2D8521
Corresponding uv: 000000A0

Decrypted C-value: A775A8BD00D800A996560EF6274A5F6C
Media key: A775A8BD00D800A996560EF6274A5FCC

Encrypted verification data: BB25974BA81A2AF7644FAB5FB4668DEC
Decr verif data should be: 0123456789ABCDEF
Decrypted verification data: 0123456789ABCDEF16548E579D21D229

Volume ID (EXTERNAL): 525F758BFA0C85E8CA4B1E9C9EBD6BF3
Volume Unique Key: 67E82C738B3634E52AB8A0A7210F8524
Unit Key File Hash (DiscID): 1348C907340CA8E669F6163CFA7FF795A3DEAB4A
Encrypted Unit Key 1: 998617393B37479AA6F72F1E789732DB

Decrypted Unit Key 1: FC5DFA6B3813352E64ADB703549FB7E9


Just add a line to the KEYDB.cfg (dumpHD) :


1348C907340CA8E669F6163CFA7FF795A3DEAB4A = Ratatouille PAL fr | D | 2007-11-09 | V | 67E82C738B3634E52AB8A0A7210F8524



This should work for you.

But don't remember, if you can patch the firmware of your drive, it's a better solution !

KenD00
29th September 2008, 23:16
@XAvAX:
Thanks for the info. However, i don't know how to write a sophisticated configure script to detect everything that aacskeys needs to build properly so i can't do anything about it. For that reason i defined some variables at the beginning of the PreMake script so that everyone can make the necessary adjustments easily.

and you're wrong :p

No, i'm not. DumpVID does nothing more than sending Volume ID requests to the drive, because your drive is patched it will answer them and give you the Volume ID. This even works without running aacskeys, just start DumpVID and after a couple of seconds it will give you the Volume ID (the delay is there because DumpVID doesn't "initialize" the crypto stuff inside the drive)!

i'm trying your approach of running dumpVID in the background and when i try to access the disc with aacskeys, nothing comes out of dumpVID.

If there is no patch for your drive you currently can't do anything else than using a certified (windows) software player with DumpVID to get the Volume ID.

:rolleyes:

kkloster21
29th September 2008, 23:51
@KenD00:

there is a patch for my drive, i just can't get it to work on linux. but TomZ did so i'm hoping i can make it work.

@TomZ:

I can't get dumpVID to spit out the VID, i think because my host cert has been revoked on my drive. i think the only thing (or maybe just the best thing) i can do now is to patch the drive. is it a problem (for the patch) that i'm running 64-bit linux? it seems like it shouldn't matter...

derbeDeus
30th September 2008, 08:26
I can't get dumpVID to spit out the VID, i think because my host cert has been revoked on my drive.

That's not the reason you cannot get the VID. Just as KenD000 told you, dumpVID is not sending a certificate nor it does the auth necessary to get the VID in the official way. You need the drive to be patched or a windows player.

otoh, aacskeys does the auth with an old certificate. If that does not work, it is indeed because that certificate was revoked by your drive with the help of some new movies you played ;) Just remember, new movies revoke old certificates.

R!tman
2nd October 2008, 15:39
I have problem compiling aacskeys-0.3.5 on Gentoo Linux for amd64.
$ make
==== Building aacskeys ====
aacs_aes.cpp
aacs_ecdsa.cpp
aacskeys.cpp
cmac.cpp
cmac_aes.cpp
ioctl.cpp
src/ioctl.cpp: In constructor ‘Drive::Drive()’:
src/ioctl.cpp:12: warning: converting to non-pointer type ‘int’ from NULL
mmc.cpp
Linking aacskeys
==== Building libaacskeys ====
aacs_aes.cpp
aacs_ecdsa.cpp
aacskeys.cpp
In file included from src/aacskeys.cpp:33:
src/aacskeys.h:8:17: warning: jni.h: No such file or directory
src/aacskeys.h:19: error: ‘JNIEXPORT’ does not name a type
src/aacskeys.h:27: error: expected constructor, destructor, or type conversion before ‘void’
src/aacskeys.cpp:197: error: expected constructor, destructor, or type conversion before ‘*’ token
src/aacskeys.cpp:198: error: expected constructor, destructor, or type conversion before ‘*’ token
src/aacskeys.cpp:199: error: expected constructor, destructor, or type conversion before ‘*’ token
src/aacskeys.cpp:200: error: expected constructor, destructor, or type conversion before ‘*’ token
src/aacskeys.cpp:201: error: expected constructor, destructor, or type conversion before ‘*’ token
src/aacskeys.cpp:202: error: expected constructor, destructor, or type conversion before ‘*’ token
src/aacskeys.cpp: In function ‘int main(int, char**)’:
src/aacskeys.cpp:1722: error: ‘globalSetVuk’ was not declared in this scope
src/aacskeys.cpp:1724: error: ‘jbyteArray’ was not declared in this scope
src/aacskeys.cpp:1724: error: expected `;' before ‘jvuk’
src/aacskeys.cpp:1725: error: ‘jvuk’ was not declared in this scope
src/aacskeys.cpp:1730: error: ‘globalEnv’ was not declared in this scope
src/aacskeys.cpp:1730: error: expected type-specifier before ‘jbyte’
src/aacskeys.cpp:1730: error: expected `>' before ‘jbyte’
src/aacskeys.cpp:1730: error: expected `(' before ‘jbyte’
src/aacskeys.cpp:1730: error: ‘jbyte’ was not declared in this scope
src/aacskeys.cpp:1730: error: expected primary-expression before ‘>’ token
src/aacskeys.cpp:1733: error: ‘globalKeyData’ was not declared in this scope
src/aacskeys.cpp:1878: error: ‘globalEnv’ was not declared in this scope
src/aacskeys.cpp:1878: error: ‘globalAacsException’ was not declared in this scope
src/aacskeys.cpp: In function ‘int printfj(const char*, ...)’:
src/aacskeys.cpp:1910: error: ‘globalEnv’ was not declared in this scope
src/aacskeys.cpp:1910: error: ‘globalMessagePrinter’ was not declared in this scope
src/aacskeys.cpp:1910: error: ‘globalPrint’ was not declared in this scope
src/aacskeys.cpp: At global scope:
src/aacskeys.cpp:1919: error: ‘JNIEXPORT’ does not name a type
src/aacskeys.cpp:1930: error: expected constructor, destructor, or type conversion before ‘void’
make[1]: *** [obj/linux/ReleaseLib/aacskeys.o] Error 1
make: *** [libaacskeys] Error 2
I know there's a binary included with the package, but I couldn't get that to work either.
./bin/linux64/aacskeys: /usr/lib/gcc/x86_64-pc-linux-gnu/4.1.2/libstdc++.so.6: version `GLIBCXX_3.4.9' not found (required by ./bin/linux64/aacskeys)
Any ideas how to resolve that problem?

Oopho2ei
2nd October 2008, 16:17
Those are the debian packages which provide "jni.h"
# apt-file search jni.h
classpath-common: /usr/include/classpath/jni.h
iceape-dev: /usr/include/iceape/java/jni.h
iceape-dev: /usr/include/iceape/jni.h
icedove-dev: /usr/include/icedove/java/jni.h
icedove-dev: /usr/include/icedove/jni.h
iceowl-dev: /usr/include/iceowl/java/jni.h
iceowl-dev: /usr/include/iceowl/jni.h
java-gcj-compat-dev: /usr/lib/jvm/java-1.4.2-gcj-4.1-1.4.2.0/include/jni.h
java-gcj-compat-dev: /usr/lib/jvm/java-1.5.0-gcj-4.3-1.5.0.0/include/jni.h
kaffe-dev: /usr/lib/kaffe/include/jni.h
kaffe-dev: /usr/lib/kaffe/include/kaffe_jni.h
libgcj7-dev: /usr/lib/gcc/x86_64-linux-gnu/4.1.2/include/jni.h
libgcj8-dev: /usr/lib/gcc/x86_64-linux-gnu/4.2/include/jni.h
libgcj9-dev: /usr/lib/gcc/x86_64-linux-gnu/4.3/include/jni.h
libsablevm-classlib1-java: /usr/include/jni.h
libsablevm-native1: /usr/include/jni.h
libsablevm1-dev: /usr/include/sablevm/jni.h
libxul-dev: /usr/include/xulrunner/java/jni.h
libxul-dev: /usr/include/xulrunner/jni.h
libxul-dev: /usr/lib/xulrunner/sdk/include/jni.h
sun-java5-jdk: /usr/lib/jvm/java-1.5.0-sun-1.5.0.14/include/jni.h
sun-java6-jdk: /usr/lib/jvm/java-6-sun-1.6.0.06/include/jni.h
As you can see they are all java related. So try some java (development) packages of you distribution. The other library is in package "libstdc++6". I hope the package names are somewhat similar to those in gentoo.

XAvAX
2nd October 2008, 17:43
Ritman:
Please see http://forum.doom9.org/showthread.php?p=1189555#post1189555

Also, the GLIBCXX error is caused (I believe) by a GCC downgrade from 4.2.X or 4.3.X, which was used to build it, to 4.1.2, which you have

R!tman
3rd October 2008, 08:46
XAvAX: Thanks a ton, that work! I could compile it :-)!

odin24
8th October 2008, 05:09
I just need some clarification on how this works. I am able to get from a disc the;
-VID with DumpVid
-VUK with aacskeys, also the Disc ID

No what do I do with these numbers? I used Blu ray disc ripper, using the VUK as the CPS Key (are they the same?)... which did not work. The only think I can think as to why is the source was an unencrypted BD rip on my HDD. Does the source have to be the actual disc in the BD drive, or can it be hard drive files, or an image mounted to a virtual drive.

Also, my drive has had it's firmware patched, and no media player software was used during this whole process.

Thanks.

derbeDeus
8th October 2008, 09:39
I just need some clarification on how this works. I am able to get from a disc the;
-VID with DumpVid
-VUK with aacskeys, also the Disc ID

No what do I do with these numbers? I used Blu ray disc ripper, using the VUK as the CPS Key (are they the same?)... which did not work. The only think I can think as to why is the source was an unencrypted BD rip on my HDD. Does the source have to be the actual disc in the BD drive, or can it be hard drive files, or an image mounted to a virtual drive.

Also, my drive has had it's firmware patched, and no media player software was used during this whole process.

Thanks.

no, VUK is not CPS
CPS is called "Decrypted Unit Key 1" in aacskeys output

odin24
8th October 2008, 11:34
no, VUK is not CPS
CPS is called "Decrypted Unit Key 1" in aacskeys output


Many thanks. :)

KenD00
8th October 2008, 19:13
The only think I can think as to why is the source was an unencrypted BD rip on my HDD.

Uhh, if your source is already decrypted, why do you want to decrypt it again :confused:. I don't know what Blu-Ray Disc Ripper does in that case, but DumpHD shouldn't decrypt the files a second time.


Does the source have to be the actual disc in the BD drive, or can it be hard drive files, or an image mounted to a virtual drive.

Again i can only speak for DumpHD, if you have the VUK of that disc in the database it works all these times if you have all files from the disc present (including the AACS stuff). If you don't have the VUK, you need the original disc because the VID needs to be retrieved which isn't stored in the filesystem.


Also, my drive has had it's firmware patched

Then you don't need DumpVID because aacskeys can do all the work for you.

:rolleyes:

odin24
8th October 2008, 23:25
Then you don't need DumpVID because aacskeys can do all the work for you.

:rolleyes:

Right on, I did not know that... obviously.


Thanks, O.

Guest
10th October 2008, 23:14
Right on, I did not know that... obviously.

One other thing. Is there a way to decrypt an encrypted file that is in either .iso, or BD structure on my PC's HDD?

At the time of ripping I was unsure of this whole process... and my rental was due back. :p
Guys, don't answer this as it is a rule 6 violation.

odin24
11th October 2008, 02:53
Guys, don't answer this as it is a rule 6 violation.

Sorry 'bout that.

Guilllo
14th October 2008, 12:01
Here is what happens event with dumpvid hammering :

aacskeys 0.3.5 by arnezami, KenD00

Current path: /home/guilo/dumphd-0.46

MKBv: 4
Processing key: F190A1E8178D80643494394F8031D9C8
Encrypted C-value: 788D0BF2BAA6BCF88D545D6DE2E32FDC
Corresponding uv: 000000A0

Decrypted C-value: 8DC7B0E517FE1F513758C9E11D3E9AEC
Media key: 8DC7B0E517FE1F513758C9E11D3E9A4C

Encrypted verification data: 9AA5318EC0A587729C080AC0525235D4
Decr verif data should be: 0123456789ABCDEF
Decrypted verification data: 0123456789ABCDEF571A4CF3666E53C3

Drive FW info: 1.79 Oct24,2007
AACS Version: 01
Number of concurrent AGIDs: 4
Supports BN generation: YES
BN Block Count: 1
Inserted medium AACS protected: YES

AGID: 00

Host Private Key (Hpriv): 4737676058D7029452514F0AB186DC4CCA8C578F
Host certificate (Hcert): 0200005CFFFF0000000C00006E3DEB679B9A16AD
FAA8E30878767BA6EB2A9B415385AD1181B4446C
31E9A5DD2AB808B364FF15885BAC490964318C9B
F8029FCF76F688A54FBDA03F6D9332EF04E5A613
12DA85880A4D9CBB79D8602E
Host Nonce (Hn): 2923BE84E16CD6AE529049F1F1BBE9EBB3A6DB3C

AGID: 00

The given Host Certficate / Private Key has been revoked by your drive.


ERROR: SENDHOSTCHAL: SK: 0x1, ASC: 0x00, ASCQ: 0x00, errnr: -2


I am using aackeys 0.3.5 on linux64.

kkloster21
14th October 2008, 14:45
you need to patch your BD-ROM drive firmware. Oopho2ei and some other authors have written a drive patch for a few different drives and have posted it here:

http://forum.doom9.org/showthread.php?t=139522

you will need to have wine installed to apply this patch. take all precautions advised by Oopho2ei such as making sure your drive has a safe mode. it is possible to damage your drive if the firmware upgrade is not done properly. don't worry too much though as plenty of people have applied the patch with no problems.

raymondtrudeau
23rd October 2008, 01:37
i have searched the forum but cannot figure out how to use the program....i have my external bluray rom on my l drive....how do i use the command prompt for it to get the keys? thanks iam looking for the incrediable hulk keys...

kkloster21
23rd October 2008, 02:52
@raymond:

we need a little more info. what operating system are you using? linux i assume? if you're using windows then i would check out AnyDVD as Oopho2ei has previously told you. it sounds like you are saying that you're using an external blu-ray drive, is that right? are you able to run aacskeys at all? does it give you an error? can you post the console output?

if you are getting an error then its most likely that your host certificate has been revoked which means that you need to apply the firmware patch (to your blu-ray drive) created by Oopho2ei and company. This firmware patch can damage your blu-ray drive if not done properly so it is important that you take all precautions advised by Oopho2ei in his thread here (this is also where the programs for applying the patches are located):

http://forum.doom9.org/showthread.php?t=139522

if your drive is not on this list, then you might need to wait until the keys are posted for the discs you want to decrypt.

post more info and hopefully someone will be able to help you! :)

raymondtrudeau
23rd October 2008, 03:12
sorry iam using windows...i just do not know how to use the program...how do i use it in command prompt? my bluray drive is l drive..thanks

kkloster21
23rd October 2008, 04:12
open a command window and change to the directory where you have the aacskeys.exe file. if your blu-ray drive is d then you should be able to type

C:\>aacskeys d

at the prompt (when you have the blu-ray disc in the drive) and it should give you a bunch of info including the Volume Unique Key (VUK). if not then just type "aacskeys" and it should bring up the help description. i'm pretty sure that you can just put the drive letter in there but i'm not a windows user, sorry. it never hurts to try things out though :)

raymondtrudeau
23rd October 2008, 04:23
well i tried that and it says

c:\ is not recognized as an intrnal or external command,operable program or batch file

i did install the aacs file to my c location? thaks

KenD00
23rd October 2008, 13:25
c:\> is the command prompt, it should be already there, you don't type this. Just type something like
aacskeys -v l
but i think it won't help you because i bet your drive is already >MKBv1 and won't return the keys. And i'm not sure if there is a patch for your drive. Regarding your experience with the command shell i suggest to use AnyDVD HD, its currently the easiest solution to decrypt HD-DVD's/BD's :(.

:rolleyes:

raymondtrudeau
23rd October 2008, 14:20
c:\> is the command prompt, it should be already there, you don't type this. Just type something like
aacskeys -v l
but i think it won't help you because i bet your drive is already >MKBv1 and won't return the keys. And i'm not sure if there is a patch for your drive. Regarding your experience with the command shell i suggest to use AnyDVD HD, its currently the easiest solution to decrypt HD-DVD's/BD's :(.

:rolleyes:
well thanks but still no luck this is how i open a command prompt.. i go to start-all programs-accessories-command prompt...then it says c:\documents and settings\owner not c:\>aacskeys

i have the trial version if anydvd but it will not give me the keys for the incredible hulk so i then can use it on blu ray disc ripper 1.2...
would you happen to have the keys?:thanks:
thanks

Orion17
23rd October 2008, 22:21
Slysoft just released the AnyDVD 6.4.7.8 BETA Update which 'MAY' have the key you need added to it, though I have not tested this yet as I do not have that BD Movie yet.

You will find a link to download it in their forums. Worth a shot.

raymondtrudeau
23rd October 2008, 23:00
thanks i did get anydvd to work but for the future when they do not update and do not want to wait i thought this way would be cool....

Peer van Heuen
24th October 2008, 07:42
thanks i did get anydvd to work but for the future when they do not update and do not want to wait i thought this way would be cool....

Well, if you'd be using it in the future, you'd have to buy it anyway - and then you would not have to wait for it to update but just have it calculate the key you need.
No waiting involved.

Turtleggjp
25th October 2008, 09:07
thanks i did get anydvd to work but for the future when they do not update and do not want to wait i thought this way would be cool....

If you want to be ready for the future of decrypting Blu Rays, your best bet will be AnyDVD HD. Once you buy it, you'll be hard pressed to find discs that it doesn't work with. As a commercial company, they have the resources to keep up with all the AACS/BD+ updates. As nice as it is to see open source tools for this too, there's only so much free time that people can put into this stuff. Those interested in the fast and easy route, should just buy AnyDVD HD and be done with it. That's what I did almost 1 year ago, and I look back on it as one of the best purchases I have ever made. Now that you've seen it work, I hope you don't have any more doubts about it.

raymondtrudeau
6th November 2008, 02:49
hi guys when i run a command prompt with aacskeys i get this could not open file c:\\processing device keys simple .txt any ideas? thanks

kkloster21
6th November 2008, 03:02
@raymond

when you downloaded the aacskeys archive and unzipped it, in that directory there is a file called "ProcessingDeviceKeysSimple.txt" it needs to be in whatever directory you are running aacskeys from.

raymondtrudeau
6th November 2008, 04:17
@raymond

when you downloaded the aacskeys archive and unzipped it, in that directory there is a file called "ProcessingDeviceKeysSimple.txt" it needs to be in whatever directory you are running aacskeys from.

thanks iam a bit closer it now says this when i run it
.now i get could not find processing key or device key resulting in the media key
possible key tried xxxxxxxxxxxxxxxxxxxx

it give me 3 possible key tried then error: processmkb, errnr: -3


thanks... btw i have a liteon external blu ray rom....

KenD00
7th November 2008, 05:07
What MKBv does it display?

:rolleyes:

KenD00
13th December 2008, 00:57
From the changelog:

- Decrypts ACA content of HD-DVD's with both content types by default now
- New option --prefer-sca to decrypt SCA content of HD-DVD's with both content
types
- The library now returns all retrieved keys (MEK, VID, VUK, TUK's)

As usual, the archive contains precompiled binaries / libraries for linux (32 bit and 64 bit), windows and the source code, the zip and tar.gz have the same content.

Download links:
aacskeys 0.3.6 (zip) (http://rapidshare.com/files/172836358/aacskeys-0.3.6.zip)
aacskeys 0.3.6 (tar.gz) (http://rapidshare.com/files/172837437/aacskeys-0.3.6.tar.gz)

:rolleyes:

Esurnir
20th December 2008, 01:07
With the Dark Knight. Any hint of what I should do ^^;?

aacskeys 0.3.6 by arnezami, KenD00

Current path: C:\Users\Esurnir\Downloads\aacskeys-0.3.
6\aacskeys-0.3.6\bin\win32

MKBv: 9
Could not find a Processing Key or Device Key resulting in the Media Key.
Possible key tried: 09F911029D74E35BD84156C5635688C0
Possible key tried: 455FE10422CA29C4933F95052B792AB2
Possible key tried: F190A1E8178D80643494394F8031D9C8
Possible key tried: 7A5F8A09F833F7221BD41FA64C9C7933


ERROR: PROCESSMKB, errnr: -3

sakman
20th December 2008, 01:26
With the Dark Knight. Any hint of what I should do ^^;?

MKBv: 9

Wait for someone to release a MKBv9 Processing Key.

KenD00
12th January 2009, 02:54
yukiyuki please check your PM's.

:rolleyes:

loo3aem3ON
12th January 2009, 14:01
Could AACSkeys output the volume id before processing the MKB? Sometimes i only need the volume id (e.g. for BD+) and aacskeys exits before it's output if it can't decrypt the media key.

KenD00
12th January 2009, 20:51
I have added a command line switch that allows you to output the Volume ID only. The implementation is ugly but fits the purpose :D. I will make a new release this week, so this is your last chance for small wishes ;).

I am thinking about to transform aacskeys into a more general purpose library, but much time will pass until this will be finished.

:rolleyes:

KenD00
23rd January 2009, 00:57
A bit later than announced, but here it comes, a new aacskeys release. It has a great new feature, its running under Mac OS X now.

First a big thank you to yukiyuki for sending me his initial Mac OS X patch, without his work i probably would never have taken the time to port aacskeys to Mac OS X.

Due to the nature how Mac OS X handles low level I/O operations there are some remarks and open issues. aacskeys can use 2.5 paths to communicate with the drive. First it can use exclusive access to send commands to the drive, this has some drawbacks however so this needs to be enabled explicit by using the command line switch --exclusive-io. You can't get exclusive access easily because Finder will grab the drive when a disc gets inserted, to overcome this problem aacskeys unmounts the disc, this requires root rights currently. This has the side effect that as soon as aacskeys releases the drive Finder grabs it again and autorun gets started. This access path provides the same features as aacskeys has under windows and linux, the only benefit of using it is that only this path allows the usage of the XBox hack, there are no other advantages currently.

The non-exclusive path does not have these problems and is used by default. The 0.5 path results from a technical problem. I have tested aacskeys with two drives, a XBox drive and a LG-GGW-H20L. To get exclusive access and to query the drives firmware version and AACS features aacskeys needs to create a driver plugin (CFPlugIn) to communicate with the drive. For some unknown reason it cannot create one for the XBox drive, but everything else works so aacskeys emulates the commands and returns fake data. You can see if this path is used if the reported firmware version is F0BA and the AACS version is 0. I don't know if this happens only because my Mac is virtual, if anyone knows how to solve this problem im open for suggestions.

The archive contains quad universal binaries for Mac OS X, however only the two intel flavors were tested, i don't have access to a non-intel Mac. They should work but i would appreciate it if someone could test them on a non-intel Mac.

Along some smaller bugfixes there are two other new features. On linux full path resolval is implemented, aacskeys now accepts paths with ./, ../, multiple symlinks and relative paths as mountpath. And there is the new command line switch --dump-vid, when this is specified only the Volume ID / Binding Nonce gets retrieved. Useful if aacskeys can't decrypt the MKB but can retrieve the Volume ID / Binding Nonce to display it.


The archive contains precompiled binaries / libraries for Windows, Linux (32 bit and 64 bit), Mac OS X (quad universal) and the source code, the zip and tar.gz have the same content.

Download links:
aacskeys 0.4.0 (zip) (http://rapidshare.com/files/187908491/aacskeys-0.4.0.zip)
aacskeys 0.4.0 (tar.gz) (http://rapidshare.com/files/187914704/aacskeys-0.4.0.tar.gz)

:rolleyes:

usr139
24th January 2009, 21:02
Hi
I am a new user of dumpHD tool.
After a bit of struggle I managed to do my first attempt to dump
a BD disc (die another day).
I get the following error


I have attached the txt file here.
Please help. What am I missing.
I created a file called HostCertificateKey.txt in the dir where I run the dumHD.jar command. In that file, I cut and pasted the Host key valu that I got by running aacskeys.exe command.
THanks for your help.

Doom9
24th January 2009, 21:30
looks to me like somebody didn't read the guides.. without a drive + firmware that supports aacs bypass you need to go down the dumpvid route to get the volume id.

KenD00
25th January 2009, 21:55
@usr139
There is no need (and its no appreciated) to send me your post you made one day ago as PM. And if you don't understand what Doom9 has written, why do you ask me but not him?

Besides obviously not having read the tutorials linked from the first page of the DumpHD thread you have damaged your aacskeys installation, nowhere was written you should create the HostKeyCertificate.txt file, it is already present in the release! To enable direct key retrieval in DumpHD all you need to do is to copy the files HostKeyCertificate.txt, ProcessingDeviceKeysSimple.txt and the library appropriate to your OS, in your case Windows so aacskeys.dll, into the DumpHD folder.

But as Doom9 already pointed out, the used Certificate has been revoked so aacskeys won't work without additional help. You are in the lucky situation that there is a patched firmware for your drive (can be found in this forum), flash your drive with that one and you are ready to go as long as your discs are < MKBv9.

:rolleyes:

usr139
27th January 2009, 20:33
Sorry for the PM.
Thanks for explaining.
I will try again based on your suggestions.
thanks.

usr139
5th February 2009, 23:53
Sorry for the PM.
Thanks for explaining.
I will try again based on your suggestions.
thanks.

KenD00 & Doom9:
Thanks for the tutorial(s).
I got it to work!!!

odin24
6th February 2009, 03:00
I'm trying to back a disc with MKBv12, is this possible yet... it's been a while since I've used aacskeys. My drive is patched.

aacskeys -v f:

EDIT: Nevermind... I read a bit back... nothing beyond MKBv9.

evdberg
24th February 2009, 19:31
I am looking for MKB files of v9 and higher. Can anybody provide these? Thanks in advance!

kkloster21
24th February 2009, 19:42
@evdberg:

what files are you looking for? I have plenty of discs that are MKBv9 or above.

evdberg
24th February 2009, 20:03
The MKB_RO.inf file.

setarip_old
25th February 2009, 01:56
@Odin24

Hi!I'm trying to back a disc with MKBv12, is this possible yet...(Presently FREEWARE) "MakeMKV" is claimed to be able to rip/decrypt (and convert to MKV) BluRay discs with MKBv12.

Perhaps you can try it and report back?

What is the title?

kkloster21
25th February 2009, 07:02
I have about 10 of them for you evdberg. check PM.

Rupan
1st March 2009, 03:46
Kend00, please review the attached patch. It adds the ability to place aacs key material in a global location. It will also search for the keys in $PWD, but this patch is really needed for widespread adoption.

It might be a good idea to wrap some Windows detection code in somehow, too, and define GLOBAL_KEY_LOC to e.g. C:\bluray\aacs.

**EDIT**

Another WTF! moment... it appears that the JNI implementation in aacskeys actually calls main() -- in the shared library. Hmmmm.

KenD00
3rd March 2009, 01:42
Another WTF! moment... it appears that the JNI implementation in aacskeys actually calls main() -- in the shared library. Hmmmm.

Yes, the library actually calls main, it starts aacskeys as you would yourself by running the executable, it only enables some additional code that actually populates the object that the java code receives.

When i coded this aacskeys was still developed by arnezami, i needed a way to use his code without "disturbing" his work so that he doesn't need to take care of my needs. Because aacskeys was (and is) a noninteractive command line application with all its functionality basically put into the main method this was the best way. During the time i realized that using aacskeys as library requires a structural redesign to better fit the purpose but i still haven't found the time to do it (and i'm not sure how to do it exactly).

The dependency of the two text files is another problem, especially for the library. I still don't know how to properly realize that in a way that works well for all 3 supported OS. Thanks for your input, but i think hardcoding the paths into the binaries is a not so good solution. While this may work for the *nix variants this is not so nice for the windows version. I'm open for suggestions :).

:rolleyes:

Rupan
5th March 2009, 03:30
I think hardcoding is in fact the way to go. This can be done on Windows too, at build time. Set a define to a supported path based on the compiler environment in some global header. This also offers the advantage of a configuration file at some point in the future to fine-tune how libaacs works at runtime.

In addition, this does not remove the ability for the user to have the key file in the corrent directory. It simply adds an additional path to search rather than breaking the old behavior. These two reasons are enough to add in support. The patch I uploaded is a good start but does not implement Windows compatibility. This would, however, be trivial to add.

As far as a structural redesign for main(), on a high level it is simple:
*wrap main() in an ifdef and exclude it when the code should be linked as a shared library (detection can be trivially implemented in the build system)
*only parse command-line arguments in main(), and move the rest of the code into startup_aacs()

If there is simply too much data that must be transmitted from main to aacs_startup, define a structure to hold it all and pass that in.

My next bit of work is to reimplement trap_Sha in libbluray so that it (1) uses Gladman's SHA code and (2) handles interleaved calls. After I complete that I'll have another crack at this patch.

blutach
7th March 2009, 10:07
@drfix - please stop cross posting this request. Read rule 8.

Regards

kyoshiro378
7th April 2009, 17:55
Hi
I am a new user of dump vid and aackeys
anybody can me how to use this tool.

KenD00
13th April 2009, 15:27
This is a repack of aacskeys 0.4.0 which now contains the latest Processing Keys (MKBv9 and MKBv10), nothing else has been changed. If you have already aacskeys 0.4.0 and the MKBv9 and MKBv10 Processing Keys there is no need to download this release.

The archive contains precompiled binaries / libraries for Windows, Linux (32 bit and 64 bit), Mac OS X (quad universal) and the source code, the zip and tar.gz have the same content.

Download links:
aacskeys 0.4.0a (zip) (http://rapidshare.com/files/220830187/aacskeys-0.4.0a.zip)
aacskeys 0.4.0a (tar.gz) (http://rapidshare.com/files/220832866/aacskeys-0.4.0a.tar.gz)

:rolleyes:

Rupan
14th April 2009, 00:51
Kend00:

This is an updated version of the aacskeys global configuration patch that handles both Windows and Linux. HostKeyCertificate.txt and ProcessingDeviceKeysSimple.txt are searched for in the following order:

If your platform is Windows, look in C:\bluray\aacs
If your platform is Linux, look in /etc/bluray/aacs
If the files are not located in a global location, read them from the current directory.

One things that consistently annoys me about the aacskeys software is the lack of a way to install the software system-wide. This patch does not break current behavior, it only supplements existing functionality. Now I can install libaacs in /usr/lib and aacskeys in /usr/bin and have it work regardless of the content of $PWD. Kend00, please accept and commit the attached patch.

BTW, congrats on the v9 and v10 processing keys! I just tested them on "The X-Files: Fight the Future" and they work perfectly.

Rupan
16th April 2009, 09:46
@Kend00:

I'm working on aacskeys this week as I find time. My current focus is on moving the command-line parsing routine out of main, into a new main() then renaming main() to aacs_main(). I've also defined a structure that will hold all user-supplied runtime information, which will be passed to aacs_main(). It isn't ready to see the light yet, but it is coming along nicely. Do you have any suggestions as to how to deal with nonfatal errors and status messages? If it is to function as a library these must go away. Maybe I can redirect them to a log file...

KenD00
17th April 2009, 18:03
If your platform is Linux, look in /etc/bluray/aacs

Ok, you convinced me that this is necessary, but regarding the unix directory structure i would propose another location, either /etc/aacskeys or, because these files aren't configuration files but more some kind of data files, /usr(/local)/share/aacskeys.


If your platform is Windows, look in C:\bluray\aacs

This is not the windows way and i really hate applications which install themselves on c: ;). Either take the files from the application directory (which is a little tricky when using the library, how can it figure out the directory it is executed from?) or use the Application Data directory under Documents and Settings. I currently don't know how to query these locations but i will look into this later.


My current focus is on moving the command-line parsing routine out of main, into a new main() then renaming main() to aacs_main().

I always wanted to convert the code more to c++ but never found the time for this. The main logic is still all in main(), its a first step to move this to another location and make main() "dumb" and let it only initialize the program.


I've also defined a structure that will hold all user-supplied runtime information, which will be passed to aacs_main().

This is a c approach and i don't encourage this, i prefer c++, the code isn't c conform already and i already started with that (see ioctl files).


Do you have any suggestions as to how to deal with nonfatal errors and status messages? If it is to function as a library these must go away. Maybe I can redirect them to a log file...
Well, i would/want to split the code into multiple smaller function units that can be called externally, like getting the VID, decrypting the MKB and so on and use error codes or exceptions that the caller needs to evaluate. However, this way the caller needs to know what to do, maybe it's still possible to use one method that does it all and use a big list of error codes so that you can still figure out in detail what failed.

A library doesn't need to output status messages itself, if you want that information (e.g. MKB version, etc) provide methods for this and the caller has to query that information and display it. The current "library" just executes the program, this is the main problem and should be changed. But i'm still not sure how to do this without writing double code just to do the same things one time in the main program and the second time in the library. Oh well, i could put #ifdef's around every printf :D.

I'm currently not working on aacskeys because i'm spending my time on the BDVM/BD-J connection so a new aacskeys release will take some time.

:rolleyes:

dirio49
17th April 2009, 20:58
i agree with KenD00. writing stuff on C:\ is horrible
Appdata is better.
usually you can just type %appdata% on the run command that will take you to the appdata folder.
or you can read registry HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders

This might help
http://www.velocityreviews.com/forums/t346548-how-to-find-windows-quotapplication-dataquot-directory.html


hope it help.
but you could also ask the user where he want to install.

Rupan
18th April 2009, 04:24
Here is the sum of my current work thus far. I am posting it because I don't think I will have time to work on aacskeys in the near future and I don't want work duplicated. The changes currently suffer from the following drawbacks:

1) I'm not a Windows programmer, and hope I will never be. As a result, the Windows compatibility code is probably horribly wrong and may not even compile. I don't have any way to test it, and am relying on MSDN's online documentation.

2) Braindead Windows doesn't have getopt(). Go figure. Some drop-in replacement will have to be found. A quick google search reveals a couple of implementations, but their licenses are incompatible with aacskeys. I hear GNU has a portable getopt, but I haven't invested the time to find it.

3) The code isn't necessarily all that clean or correct. I put it together as a test, so please don't bash me on coding practices. Its pre-pre-pre alpha quality, and only meant as a starting point for the real implementation.

4) get_appdata_dir() does introduce a memory leak. It is easy to fix, but I've run out of time for at least this week.

5) Currently aacs_main() copies values from the passed structure into internal variables. This isn't the correct way to do it; the correct way would be to write bit test macros and replace all occurrences throughout the code. Again, I'm short on time.

6) probably lot of others....

The code changes compile and run on my machine, which runs 64-bit Linux. They appear to work perfectly, but the only thing I'm willing to commit to right now is that they work fine on my own personal desktop.

The license for this patch is GPL2 or any later version, at your discretion.

EDIT:
I forgot that C++ enforces typecasting so strictly. Line 1245 of aacskeys.cpp must be changed to this:
char *path = (char *)malloc(_MAX_PATH);
from this:
char *path = malloc(_MAX_PATH);

EDIT2:
I suggest that aacs_main() be split out into component functions. the real main(), the one that is for compilation as a standalone application, should parse the config options and call all of these component functions. All error printouts should be moved into main(). Compilation of main() can be conditional, depending on whether it is built as a library or application. Application developers should read the documentation and handle invalid return values gracefully in their software.

wingman1659
23rd April 2009, 21:57
I get an error when running it. Using Vista x64

error: could not open file: (directory)\ProcessingDeviceKeysSimple.txt

dirio49
24th April 2009, 17:05
download and an zip the files in the same folder.
that file is in the zip.
later

whatadeals
11th June 2009, 11:12
works fine.

drkrvn32
11th July 2009, 20:18
In reply to building on OSX Leopard:

the binary file with .40 works in CLI mode. The library does not work with DUmpHD, it crashes the JVM.
Now, saying this I have the following installed:

openSSL .98k via MacPorts[only way I have gotten this to install correctly]

When I try and compile libaacskeys I run into the same error that everyone else does with EACS?? extensions to openSSL. I'm cluless where to begin to fix it.

I can use the commandline up to MKV10. 12, as we know is still in the works.

Correct me if I'm wrong, but isnt the MKBV info inside the same file as the version header? Obviously its stored on disc somewhere near the AACS files.How difficult is it to use the discs auth against itself? Thats how we managed to break CSS, and usually that's how crypto stuff is cracked.

I'm hardly an expert in drive auth,but the ceasar cypher was broken by the number of occurances [uses per letter]of the english alphabet.Also,once you bust a hash, anything that uses that hash is now cracked. [xb-360 forums]

I hear someone says that only Volume/disc/title keys are in this file, but the MVKB has to be close to these or the set-top boxes couldn't decode the disc.
Maybe we need to start looking at firmwares and set-top firmwares.....

KenD00
12th July 2009, 18:50
openSSL .98k via MacPorts[only way I have gotten this to install correctly]

When I try and compile libaacskeys I run into the same error that everyone else does with EACS?? extensions to openSSL. I'm cluless where to begin to fix it.

The macports version of openssl contains everything that the original tarball does, at least the version i have installed (don't remember which), including ECDSA. That was the reason i used this version, because the OSX included one wasn't complete. Post the error message the compiler spits out, maybe i can help.


Correct me if I'm wrong, but isnt the MKBV info inside the same file as the version header? Obviously its stored on disc somewhere near the AACS files.How difficult is it to use the discs auth against itself? Thats how we managed to break CSS, and usually that's how crypto stuff is cracked.

I'm hardly an expert in drive auth,but the ceasar cypher was broken by the number of occurances [uses per letter]of the english alphabet.Also,once you bust a hash, anything that uses that hash is now cracked. [xb-360 forums]

I hear someone says that only Volume/disc/title keys are in this file, but the MVKB has to be close to these or the set-top boxes couldn't decode the disc.
Maybe we need to start looking at firmwares and set-top firmwares.....


Honestly, i don't understand what you are saying here. Of course, the MKB file on the disc contains the version number, thats what aacskeys reads and displays. However, this information is only informative for us, it doesn't add anything to the decryption process. Inside the MKB there are the encrypted Media Keys, one of these has to be decrypted with a Processing Key. Every new version of the MKB encrypts the Media Keys with new keys so that we can't decrypt them with our known Processing Keys. So there is no other way then finding new Processing Keys to decrypt new MKBv's.

Second problem is the revokation of certificates, there the version number is important because the drive reads this out to decide if it has to update its revokation lists or not. But this does the drive itself, there is nothing we can do about it.

:rolleyes:

KenD00
15th July 2009, 18:03
This is again a (slightly more than only a) repack of aacskeys 0.4.0, this release adds a precompiled executable and library version for windows 64 bit. While compiling the the new windows target i have also updated the 32 bit windows build to link against OpenSSL 0.9.8k (all other builds are still linked against OpenSSL 0.9.8i).

@Rupan: sorry, i haven't found the time yet to work further on aacskeys

The archive contains precompiled binaries / libraries for Windows (32 bit and 64 bit), Linux (32 bit and 64 bit), Mac OS X (quad universal) and the source code, the zip and tar.gz have the same content.

Download links:
aacskeys 0.4.0b (zip) (http://rapidshare.com/files/255993578/aacskeys-0.4.0b.zip)
aacskeys 0.4.0b (tar.gz) (http://rapidshare.com/files/256152839/aacskeys-0.4.0b.tar.gz)

:rolleyes:

KenD00
30th August 2009, 17:20
And again another repack because i still haven't found the time to work on this but forum member pynux has made a great discovery which hasn't made big news yet as it should.

He has found the Host Certificate/Private Key used by MakeMKV in one of its binaries. I don't know the exact details on how he did it but it doesn't look like Mike Chen has protected it in any way so i've taken the freedom to use it for aacskeys as well. It works for at least MKBv12, i don't know how recent the version was that pynux used so maybe it even works for current MKBv14 titles.

So what do we get from this new Certificate? While we have known Processing Keys for up to MKBv10 we had a Certificate only for MKBv1. With this new Certificate users who don't have a patched drive can finally use aacskeys again without going the painful dumpvid route and everything works automatically again as it should.

The archive contains precompiled binaries / libraries for Windows (32 bit and 64 bit), Linux (32 bit and 64 bit), Mac OS X (quad universal, NOTE: There are reports that the dylib does not work on MacOSX >= 10.5.7, i can't do anything about it right now because i have only MacOSX 10.5.4 running here) and the source code, the zip and tar.gz have the same content.

Download links:
aacskeys 0.4.0c (zip) (http://rapidshare.com/files/273471735/aacskeys-0.4.0c.zip)
aacskeys 0.4.0c (tar.gz) (http://rapidshare.com/files/273476005/aacskeys-0.4.0c.tar.gz)

:rolleyes:

---- moderator note ----

The above links are dead, you can now find the download at cyberside (http://cyberside.net.ee/ripping/BD_DeviceKeys/).

FirstBorg
4th September 2009, 22:39
Hi!
I tried the new version, 0.4.0c to get the key for the top gun bd, and I get the Error:
Could not find a Processing Key or Device Key resulting in the Media Key.

880
5th September 2009, 00:13
That means that the disc is too new; it uses MKB version 11 or later.

setarip_old
5th September 2009, 01:05
Hi!

The keys for the U.S. version of "Top Gun" are already in the "KeyDB.cfg" file for the BluRay version of "DumpHD".

Also, as noted above by "KenD00", aacskeys 0.4.0c definitely works with MKB 12 and likely MKB 13 and MKB 14, as well...

KenD00
5th September 2009, 03:50
Ok, once i again i should get some things straight here.

Basically there are two types of information we need to decrypt a disc, its Media Key and its Volume ID to calculate the Volume Unique Key. To get these two entities we need two different cryptographic elements.

First a non revoked Host Certificate and its Private Key to get the Volume ID. The recently found one (thanks Mike Chen and pynux) works for (i'm pretty sure) up to MKBv14, so with this one we can get the Volume ID of discs from MKBv1 up to MKBv14. If some day this one gets revoked (which will happen, i'm pretty sure about this) we can't get the Volume ID from ANY of these discs (this is a form of active revokation) until a new Certificate is found (or we use other ways to get it ;))!

Second we need a Processing Key to decrypt the Media Key. Currently we have Processing Keys for MKBv1 up to MKBv10. If they "revoke" a Processing Key it simply cannot decrypt new MKB versions but it still can decrypt the old ones (so this is a form of passive revokation). But if we can't get the Volume ID of a disc all our Processing Keys are worthless (see above).

To sum things up the current situation is Volume ID for MKBv14, Media Key for MKBv10, the common denominator is MKBv10, so this is the maximum MKB version we can handle now.

:rolleyes:

FirstBorg
6th September 2009, 00:19
Is it possible to find out what MKBv is used on a certain disc?

880
6th September 2009, 02:20
AACSKeys will tell you.

Current path: C:\Documents and Settings\Administrator\
Desktop\aacskeys-0.4.0c

MKBv: 12
Could not find a Processing Key or Device Key resulting in the Media Key.

FirstBorg
6th September 2009, 13:15
Ah yes, my Top Gun BD (German Version) has MKBv 12.

bvc2068
9th September 2009, 00:06
aacskeys 0.4.0c (tar.gz)[/URL]I noticed that hddump with aacskeys 0.4.0c would not try to use AACSAUTH even if the "-a" option was specified, as it fell through a "goto exit;" when finding that none of the keys in the db were fitting, before even trying to do the "conventional" AACSAUTH method.

A one-line patch (sorry, not at hand at the computer I'm writing from) to not take that "goto exit" code path fixed it for me, I wonder whether I was the only one to stumble upon this.

KenD00
9th September 2009, 05:52
A one-line patch (sorry, not at hand at the computer I'm writing from) to not take that "goto exit" code path fixed it for me


No, you haven't fixed anything, instead you have broken something that was working fine. There is no need to do AACSAUTH or any other process to get the Volume ID from the drive because you couldn't decrypt the Media Key with any of the Processing Keys. Your "patch" just let it continue to calculate the VUK with whatever crap was left behind in the array for the Media Key after testing the Processing Keys (or you could have gotten a VERIFYDATA error, depending on which goto you are talking about, you haven't given quite detailed information)!

You could have figured this out by yourself by actually trying the VUK or CPS Unit Keys, DumpHD would have told you that it couldn't find a key for any of the M2TS files!

If you really want to get the VID even if you can't decrypt the Media Key use the --dump-vid switch, then you will get the VID of the disc if one of the retrieval methods worked, nothing more.

:rolleyes:

bvc2068
10th September 2009, 00:05
There is no need to do AACSAUTH or any other process to get the Volume ID from the drive because you couldn't decrypt the Media Key with any of the Processing Keys.Ah, ok, so I was just misled by the error messages. They aren't too obvious, after all... :)

If you really want to get the VID even if you can't decrypt the Media Key use the --dump-vid switch, then you will get the VID of the disc if one of the retrieval methods worked, nothing more.Yes, that works as described.

denret
2nd October 2009, 15:10
I've been trying to get this program to run, but can't get past error message: "Could not open file c:\\ProcessingDeviceKeysSimple.txt Error: Process MKB, error: -1
when I attempt to run from the command function.

My aacskeys folder is under my C: directory and the above mentioned txt file is directly under the aacskeys folder, not under a sub folder. Based on what I've seen in the forum archives, that is correct. Confused???

Can anyone enlighten me??

880
2nd October 2009, 17:58
Change directory to the aacskeys folder first. Then run the exe.

denret
2nd October 2009, 19:51
Thank you for your prompt response. However, I'm still confused as to where to put the text file. Here's the file config I've presently got:

Local Disk (C:)
aacskeys-o.4.0 (folder)
bin (folder)
win 32 (folder)
aacskeys.exe (app file)
ProcessingDeviceKeysSimple (text file)

My command line from the C prompt in DOS is as follows:

c:\aacskeys-0.4.0\bin\win32\aacskeys.exe e

Where the last e is the drive. When I run this command, I get the error message in my last message. What am I doing wrong here??

880
2nd October 2009, 20:28
you didn't use the cd command
cd c:\aacskeys-0.4.0\bin\win32\
aacskeys.exe e

denret
2nd October 2009, 20:39
Heres exactly what I typed after opening the command screen:

CD C:\ (to change to the C: prompt)

Now I'm at the C: prompt and I typed:


aacskeys-0.4.0\bin\win32\aacskeys.exe e

Is this wrong....

Thanks

KenD00
2nd October 2009, 20:57
aacskeys looks for the Processing Key file and the Host Certificate file in the current working directory, thats the directory from where you issue the command. In your example this is C:\, apparently this is not the directory where these files reside, they are in aacskeys-0.4.0, so you have to change into that directory first.

Your steps should look like this:

C:\Users\KenD00> cd c:\aacskeys-0.4.0
C:\aacskeys-0.4.0> bin\win32\aacskeys e

:rolleyes:

HOGGER
3rd October 2009, 02:00
I had the same issue http://forum.doom9.org/showthread.php?t=149727
Place the ProcessingDeviceKeysSimple.txt here C:\ ProcessingDeviceKeysSimple.txt right where the error is telling you it's missing and ALSO the same folder as aacskeys .exe and all will be well

880
3rd October 2009, 04:09
I had the same issue http://forum.doom9.org/showthread.php?t=149727
Place the ProcessingDeviceKeysSimple.txt here C:\ ProcessingDeviceKeysSimple.txt right where the error is telling you it's missing and ALSO the same folder as aacskeys .exe and all will be well

That's unnecessary if you're smart enough to cd to the aacskeys folder before you try to run it. :rolleyes:

denret
3rd October 2009, 14:28
Thanks KenD00 for the feedback.

Yes, by using your syntax, I can get the command file to work. However, now I'm getting an error message "c:\aacskeys-0.4.0\bin\win32\aacskeys.exe is not a valid Win32 application."

I've also noticed that when I click on the aacskeys.exe file from Windows, I also get the same error message. It seems to me that earlier when I did that, I got a flash of the Command file on the screen. Not sure whats up all of sudden. Maybe I should delete and reload aacskeys files?

HOGGER
3rd October 2009, 15:32
That's unnecessary if you're smart enough to cd to the aacskeys folder before you try to run it. :rolleyes:

Either way will work, I had typed the command so much trying to get it to work
I eventually got lazy and cut and pasted the path in command prompt and than ran the exe
Guess that is where I made my mistake

denret
3rd October 2009, 16:09
KenD00

Thanks for your assistance in this issue.
I got it going by reloading the aacskeys files. It now runs, but I get an error message as attached. Reading through some of the archives, I see this may be related to drive patching?

KenD00
5th October 2009, 07:44
Hmm, the recent Host Certificate should work for all known MKB versions, are you using the 0.4.0c release?

What MKB version does the disc have that you are using, and is this the newest disc you ever played back with that drive? Run aacskeys in verbose to get the MKB version of the disc, like

aacskeys -v e

:rolleyes:

denret
5th October 2009, 20:36
I assume the Blu ray disc does not have to actually running, only mounted to run aacskeys, and the mentioned query?

denret
6th October 2009, 15:50
Tried to run the aacskeys -v e routine. Had no luck. Is that also run from the same prompt?

KenD00
7th October 2009, 11:47
Well, uhhh, of course, you are just supplying some different command line arguments...

Ok, it looks like you have not really an idea of what are you doing here so basically i wonder what are you actually trying to achieve? With the recent Host Certificate there is again a much more unexperienced user friendly free way to decrypt your HD-DVD / Blu-Ray - recent BD+ discs (read: after the initial setup insert a disc and press 5 buttons) available, maybe this is the better solution for you.

:rolleyes:

ttwater
17th December 2009, 07:50
i trace aacskeys on windows xp, i have no blu-ray drive, i use daemon tools instead, my iso is aacs protected, but it is failed to get agid. what is agid? what is it used for? why it error? any helps would be thanks.
aacskeys.exe -va k
aacskeys 0.4.0 by arnezami, KenD00

Current path: E:\work\dvd\tools\aacskeys\aacskeys-0.4.
0c

MKBv: 1
Processing key: 09F911029D74E35BD84156C5635688C0
Encrypted C-value: D4CCD72D8986CCA08A736A151A3FACD3
Corresponding uv: 00000001

Decrypted C-value: EEAE604BAC9FDF681EF4C36C840E7618
Media key: EEAE604BAC9FDF681EF4C36C840E7619

Encrypted verification data: 6E7813E65978F033DC5A71B709F82398
Decr verif data should be: 0123456789ABCDEF
Decrypted verification data: 0123456789ABCDEF3A1A2A8290AE5A52

Drive FW info: 1.03
AACS Version: 00
Number of concurrent AGIDs: 0
Supports BN generation: NO
BN Block Count: 0
Inserted medium AACS protected: NO

Host Private Key (Hpriv): 8C8647FE2A70EF0388EA9E43F432CC441C6B108C
Host certificate (Hcert): 0200005CFFFF000000AE00004142A5411F1E63F1
85581C876B939FB40B523BF69C004CA69E047606
EE5183C0ABEF1E7D04CB6E65260677E7B0573D08
E60957935503ED78F7E27B190B4A7CAFCBAFF4A2
836453ECF72E49668DAF1DB9
Host Nonce (Hn): 2923BE84E16CD6AE529049F1F1BBE9EBB3A6DB3C

All AGIDs in use.


ERROR: AGID: SK: 0x5, ASC: 0x24, ASCQ: 0x00, errnr: -2

Rupan
17th December 2009, 12:10
ttwater, you cannot do what you are trying to do. Each AACS-protected disc has a "host protected area" that the drive itself will refuse to deliver to the desktop PC directly. When you copy a blu-ray disc to an ISO image you don't get the data from the host protected area. The missing data must be read in a special way from the drive when the original blu-ray disc is inserted. I'm sorry, but the image you have is useless unless you already have the disc keys.

ttwater
18th December 2009, 03:57
ttwater, you cannot do what you are trying to do. Each AACS-protected disc has a "host protected area" that the drive itself will refuse to deliver to the desktop PC directly. When you copy a blu-ray disc to an ISO image you don't get the data from the host protected area. The missing data must be read in a special way from the drive when the original blu-ray disc is inserted. I'm sorry, but the image you have is useless unless you already have the disc keys.

Thanks for Rupan's reply, you let me know more.

your mean is that the daemon tools + iso environment is different from the blu-ray drive + blu-ray disk, now i have a new question, What is stored in the "host protected area"? What is it used for? what is its function?

thanks again...

Rupan
18th December 2009, 06:54
It contains the decryption key for the protected blu-ray video data. If you have the key already then you can decrypt the video. I believe AnyDVD HD comes with a large database of known keys, so it would be worthwhile for you to download and install it to see if it can handle your particular disc image.

ttwater
18th December 2009, 09:49
It contains the decryption key for the protected blu-ray video data. If you have the key already then you can decrypt the video. I believe AnyDVD HD comes with a large database of known keys, so it would be worthwhile for you to download and install it to see if it can handle your particular disc image.

Thanks, Rupan.

Yes, AnyDvd works well, but I want to achieve the same function without AnyDvd. it seems impossible, maybe i should give up.

Rupan, do you have any suggestions?

setarip_old
18th December 2009, 10:41
@ttwater

Hi!Yes, AnyDvd works well, but I want to achieve the same function without AnyDvd.Presently, MakeMKV can decrypt any BluRay disc, including the latest BD+...

ttwater
19th December 2009, 04:06
@ttwater

Hi!Presently, MakeMKV can decrypt any BluRay disc, including the latest BD+...

sad message.

I've tried all the functions the MakeMKV have, but it couldn't decrypt my iso too.

i know few about blu-ray now, i think i need to learn more, i will be back.


thanks setarip_old and Supan.

setarip_old
19th December 2009, 05:45
@ttwaterI've tried all the functions the MakeMKV have, but it couldn't decrypt my iso too.1) As I said, it certainly should be able to decrypt both your original BluRay disc and the .ISO image file you created from it.

2) Have you mounted and played the .ISO image file you created on your PC? If not, you may not have created a valid .ISO image file.

ttwater
20th December 2009, 04:28
@ttwater1) As I said, it certainly should be able to decrypt both your original BluRay disc and the .ISO image file you created from it.

2) Have you mounted and played the .ISO image file you created on your PC? If not, you may not have created a valid .ISO image file.

it could played with anydvd's help, powerdvd couldn't. i think my .iso image lossed some data from the original bluray disk, anydvd have a database contained the lossed data, so anydvd could decrypt.(as Supan said)

to Supan:
is it right?

Guest
20th December 2009, 20:12
[bump after edit - thread re-opened after erroneously closed - offending rule 6 post has been removed]

popop
24th December 2009, 19:43
To my knowledge, all the ISOs no matter from which application you use to create it will NOT work without the help of decrypter like AnyDVD HD due to the AACS protection. In fact the created ISOs don't contain or contain wrong information/keys, so the correct normal procedure of decryption is not possible.

I've tried ImgBurn, AnyDVD HD (with protection not removed) and Alcohol 120% to create the ISO but all are the same.

dk75
25th December 2009, 11:26
I've created iso by Linux "dd" command (at PS3) and AnyDVDHD removed protection from it.

kabelbrand
21st January 2010, 12:49
Can someone give me a hint how the VUKs for mkb 12,14,15,16 titles seen on the "Post Blu-ray Volume Unique Keys here" thread could have been discovered?
I am searching the forum and internet for a few days now, had a brief look at MakeMKV but failed to find any information.

Thank you!

[EDIT] A forum member pointed out to me that this information is not ready for public release yet. Anyway, I hope there will be new processing keys for AACS Keys some day.

646C799C
24th January 2010, 11:23
Anyway, I hope there will be new processing keys for AACS Keys some day.

While I certainly share your hope, unfortunately I wouldn't be completely surprised if there aren't anymore unrevoked processing keys released for direct use with aacskeys, since it's gotten hard enough to find them, and once they're found and posted they're often revoked quickly. (Most software player exes are now corrupted with Themida, some even loading plugins that decompress and execute more Themida code in memory in an apparent attempt to slow down hackers, while executing a million unnecessary instructions, wasting power and reducing your system performance. Also, because the processing keys aren't used to decode video directly they may never even be entirely exposed where XORs are used.) And, although it would be nice if authors of commercial decryption software would release their revoked keys, it's not exactly surprising for them to consider this a potential loss of customers, since people who pay for their software don't need VUKs anymore (even if they might be more convenient for users who don't run Windows.) Fortunately, direct access to processing keys isn't necessary to obtain VUKs (I don't have one for MKB14, and that hasn't stopped me...)

Can someone give me a hint how the VUKs for mkb 12,14,15,16 titles seen on the "Post Blu-ray Volume Unique Keys here" thread could have been discovered?

Here's a couple (possibly related):
1.When I got the "Could not find a processing key" message the first things I thought were: Exactly what does the processing key do, how does aacskeys know it can't find one, and is there any way to avoid or replace using it directly...
2.Is there anything related to VUK generation recognizable when decrypted? Most systems that know when you supplied an incorrect password are checking for some data, CRC, etc that's only present when decrypted correctly, and "password recovery" programs frequently look for this as well. (If you are able to directly monitor any player, try taking an older Bluray decryptable directly with aacskeys and use it with the player, searching for that (known) key, then comparing with your newer disc. Think dumpvid for VUKs...)

A forum member pointed out to me that this information is not ready for public release yet.

While processing keys are unique to a particular licensed player, title/volume keys are not, meaning one advantage of posting only these keys is that the player used to obtain them cannot be determined, and following the results from posting of processing keys where companies are putting glue on PCBs for hardware players and using obfuscating VMs for software, I hope the concern that posting player specific information would cause that player to be updated to make this more difficult is understandable. (Also, I would personally be concerned that if I posted anything that automated key discovery, it could end up helping p2p premieres.)
Finally, this post wouldn't be complete without a new VUK, so here's another MKB16 title:
2675EE2C3F2C093FE770341D1A8242872F3FDF9D = The Hurt Locker (US) | D | 2009-10-23 | M | D30E33F2B7960BA37AC69648FAD4CBA5 | I | FCFBCE5D415DC54BEF03BAB4BAADFDB9 | V | BF106B09A71E8F56B67FA7B90AE2C732
Have Fun! :)

jimrip
31st March 2010, 23:58
Hi

My first ever post so please be gentle. I must stress I am a newbie to using terminal commands but I am getting there slowly with the help of this forum and others.

First off, I have been creating .iso of my blu-ray discs using ubuntu on my PS3 and transferring to an external harddrive. I have then been ripping the .iso using makemkv or dumphd on Mac OS X Snow Leopard. As long as the VUK for my particular disc is in the keydb.config everything is working fine.

However I would like to be able to get the VUK for myself

So my questions are –

Can I use aacskeys on Mac OS X Snow Leopard to obtain the VUK from an .iso created on ubuntu on my PS3?

Can I use aacskeys on my PS3 to obtain the VUK?. The link to download a linux binary for PS3 says its unavailable


Thanks, any guidance is very much appreciated

880
1st April 2010, 04:14
No, because the ISO does not have the Volume ID (necessary for the VUK), and the PS3 doesn't allow low-level access to the Blu-ray drive (so you can't get the Volume ID there). The program AnyDVD HD (not free) has most keys built in, so you could use that to rip ISOs.

By the way, Sony is removing the Linux feature from PS3s soon, so beware.

jimrip
1st April 2010, 09:56
Thanks for the swift reply. I guess I will have to wait for the keydb to be updated before I can rip my Cars blu-ray. Cars is in the database but its not working.

Thanks again

setarip_old
1st April 2010, 10:23
@jimrip

Hi!

If you're going to be doing this on an ongoing basis, you really should consider getting a BluRay reader (or burner) for your Mac. You would then be able to immediately make decrypted full disc copies of your original BluRay discs, using EITHER "MakeMKV", "DVDFab Passkey", or "AnyDVDHD".

bob-flash
19th April 2010, 06:51
Without the new Certification, new player Private key, and the new Processing key, aacskeys must be going to die now...
while open source means open the key too, when the key is opened, it's quite easy to revoke...so the mouse and cat game never ends.
If we can use some source code obfuscation skills to make the key not easily be viewed, but still can be compiled with C compiler.

This may get a balance between open source & key revocation.

pynux
19th April 2010, 09:40
maybe make a close source only for the part have Processing Key
the rest can be opensource

new HostKeyCerificate :

5F63596894AB301089FCB1FDC51DE71E09C911AE
0200005CFFFF0000272B000003526E93CD01A98D92D0F8FF590767C3388D202B4799B09BEF67E1851E450E2D673C52A12A299CA777E7FA9F8AC88F4A9BF07436D8BB0400FB86AAD60E5EADB5DD69DDE2CB9E109A8212E06F963C4FF9

dirio49
20th April 2010, 13:44
I think that could be possible,
But I wonder what it would achieve, protect the key temporarily.
because any hacker could if wanted get the key, by reversing the closed app. :)

KenD00
22nd April 2010, 01:55
That idea with the closed part isn't quite good for a couple of reasons. At first it violates the open source idea thats behind this program. Second, the hiding of the key has to be VERY good, if every script kiddy can get it its pretty useless. And of course this has to work on at least 3 different OS, so the effort to realize just this little, non-productive feature, is at least a double digit factor higher than the effort to realize the whole functionality of the program ;).

And third, and thats the most important point imho, it's almost useless. The AACSLA revokes ALL Device Keys on a regular basis, so no matter how good we hide our stuff, it WILL get revoked. The only benefit of the hiding would be that they MAYBE can't figure out from where we got that key (they can still do black box tests against the program and derive this way where the key comes from) so that they can't point with their fingers on that manufacturer.

Anyway, thanks for the new Certificate, too bad that its not that helpful without recent Processing Keys, but well, better than nothing. Honestly, i haven't worked on aacskeys for a long time now, i have a slightly better version here than the last release but never bothered to make it public because the benefits are quite small. Without recent Processing Keys it doesn't help that much that BDAV's should be decrypted correctly now and that finally it doesn't crash on Mac OSX anymore :(.

:rolleyes:

bob-flash
22nd April 2010, 14:02
maybe make a close source only for the part have Processing Key
the rest can be opensource

new HostKeyCerificate :

5F63596894AB301089FCB1FDC51DE71E09C911AE
0200005CFFFF0000272B000003526E93CD01A98D92D0F8FF590767C3388D202B4799B09BEF67E1851E450E2D673C52A12A299CA777E7FA9F8AC88F4A9BF07436D8BB0400FB86AAD60E5EADB5DD69DDE2CB9E109A8212E06F963C4FF9


It's not a valid HostKeyCerificate...:mad:

I've tried my effort to dump one from DVDFab, but I only get the Certification part, i can't figure out where is the Host Private Key:

0200005CFFFF0000009400000982963083499FEB8630C1CFEDA323D0257EB4B80365EDC85EA29CD67E1A6E42389CE1EE85410F378CA4BBABBBDA4974B0D7D7C614B4B62412A93DF054E52F01201C0E0ED0E22AE6B434D90C5B14E2A2

KenD00
23rd April 2010, 18:44
Indeed neither the Certificate is valid nor does the Private Key match it. So i took a closer look at it (i know where its from) and it looks like its sort of obfuscated, i have the correct Certificate now but i still haven't got a matching Private Key.

Well, and as the name implies, the Private Key is private, it never leaves the application and should be secured almost as good as the Device Keys.

:rolleyes:

pvh1987
24th June 2010, 14:19
I'm a newbie and I'm very sorry if I ask a stupid question. I have been reading a lot in this thread to find out how to use aacskeys on discs with mkbv greater than 10. I have seen in the volume unique key posting thread, that some people has managed to get keys for discs with v12, v14, v15, v16 and even mkbv17. I see that my "ProcessingDeviceKeysSimple.txt" only contains information up to mkbv10.

Since somebody has managed to get keys from mkbv17 discs - I should be able to do this as well? But how? aacskeys works very well on my older discs released in 2007 and 2008 - all newer discs seems to fail.

As I said, I have read a lot of information in this thread and I still can't figure it out :-(

lchiu7
26th June 2010, 05:24
I am still using aacekeys but this is for my older BD titles and my entire HD-DVD collection which I am ripping to AVCHD format. But if folks post keys MKBV16 and above and I have that title I presume I can just put that key into the config.db and then dumphd can use it?

spock2000
26th June 2010, 06:18
That is correct as long as the volume unique key matches the region of the Blu ray disc you are trying to decypt. Then Dumphd will decrypt and rip it to your hard drive. By the way, new BD+ protection such as the movie Avatar won't work.

_akmal_
2nd December 2010, 09:39
Hi, i have question about aacskeys implementation.
In authType == AACSAUTH mode, when it needed to read volume id of media, for prerecorded(read-only media) it just read volume id, but when for recordable(rewritable media) it also reads bn(binding nonce?). So my question is why? I read spec(AACS_Common_cryp...) but there is nothing about reading binding nonce to get volume id, where you get this info?

P.S. sorry for my english.

KenD00
2nd December 2010, 21:33
but when for recordable(rewritable media) it also reads bn(binding nonce?).


Not also, but instead ;). Recordables don't have a Volume ID. If you compare the decryption process of prerecorded and recordable media you can see that the Volume ID and Binding Nonce actually fit the same purpose and are used in the same manner. For prerecorded media you use the Volume ID to calculate the Volume Unique Key in the same way like you use the Binding Nonce to calculate the Protected Area Key for recordable media. The VUK and PAK's are then used in the same way to calculate the Unit Keys. Just take a look at the description of the decryption process in the prerecorded and recordable books.

:rolleyes:

_akmal_
3rd December 2010, 07:54
thanks alot KenD00!
I compared content decrypting procedure for prerecorded and recordable media, and understood that Binding Nonce and Volume ID is used for same purpose. But one thing is not clear to me, how to get Binding Nonce(volume id is simple, after we get bus_key, we simply call for function to read volume id).
In AACS_Common... book, i find procedure to read binding nonce from media, but we must send to it some LBA, so what LBA we must send? I think "For BD-R / RE, the
Binding Nonce shall be stored in the User Control Data associated with the first logical Sector of the CPS Unit
Key File and shall be non-zero value.", am i right?

KenD00
3rd December 2010, 12:40
Yes, you have to send the starting LBA of the corresponding Unit_Key_RW.inf file.

:rolleyes:

_akmal_
7th December 2010, 07:28
Hi KenD00, now i\'m learning MKB processing part of the aacskeys programm, and have some questions. Before finding appropriate Subset-Difference Record value via
if ((u_mask == device_key_u_mask) && (v_mask == device_key_v_mask))
but before this we must check this condition, or not?
((Dnode & mu ) == (uv & mu)) and ((Dnode & mv) != (uv & mv))
(i get it from aacs_common...)
where i must get Dnode(from Subset-Difference index record?).

btw, i also want to know, is it possible to know protection type of media, e.g. BD+, AACS or no protection?

Thanks, alot! Sorry for my english;).

_akmal_
7th December 2010, 09:21
3.2.3 Storing Device Keys
Each device is given its Device Keys and a 31-bit number d called the device number. For each Device Key,
there is an associated number denoted the path number, and the “u” bit mask, mu, and the “v” bit mask, mv.

...

3.2.4 Calculation of Media Key
It finds the appropriate stored
Device Key as follows: assuming the Explicit Subset-Difference Record value is uv, mu, and mv, and the stored
Device Key has uv’, m’u, and m’v, the appropriate Device Key is the one that meets the following condition:
(mu == m’u) and ((uv & m’v) == (uv’ & m’v))

it is from aacs_common....
where i can find device\'s m\'v, m\'u and uv\'?

KenD00
13th December 2010, 23:43
btw, i also want to know, is it possible to know protection type of media, e.g. BD+, AACS or no protection?

For AACS there are two ways to figure that out, the quick and easy way and the proper way ;). aacskeys actually uses both but it only displays a warning if the proper way says it's not encrypted. The easy way is to check if the AACS directoy is present and maybe contains some files like the MKB. The correct way would be to read the AACS Feature Descriptor and check if it's enabled (aacskeys does this after querying the drive for its firmware version).

The presence of BD+ seems to be determined by the presence of the BDSVM directory (and maybe the 3 VM files inside it) only, but i don't know that much about BD+.


About the Subset Difference algorithm you are asking the wrong guy :). I never really understood how it works and im afraid i already forgot the part i did understand :D. Afaik we don't have the uv number of the device keys but just brute force all possible values but i'm really not sure about this, i'm afraid you have to look at the code and figure that out yourself.

:rolleyes:

_akmal_
17th December 2010, 07:44
somebody tested the program on the HD DVD or DVD media with AACS protection? What was the results?

neXyon
25th March 2011, 08:18
Hi!

[EDIT: Ahh, I just read some where, that currently only MKB up to v16 work, right? :-/]

I've installed the patched firmware version 1.03 on my GGC-H20L and it seems to work (I get some info after the sg_raw commands), but when I try to use aacskeys with the last 16 bytes of output I get still:

% aacskeys /media/cd XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
aacskeys 0.4.0 by arnezami, KenD00

MKBv: 17
Could not find a Processing Key or Device Key resulting in the Media Key.
...


ERROR: PROCESSMKB, errnr: -3

Any hints, why it doesn't work?

Regards

neXyon
3rd April 2011, 20:34
Okay, it doesn't seem to be a MKBv17 problem, a MKBv14 disk also doesn't work.

Rinse&Repeeat
27th April 2011, 00:42
I'm having a similar problem. using the DumpHD GUI


DumpHD 0.61 by KenD00

Opening Key Data File... OK
Initializing AACS... OK
Loading aacskeys library... OK
aacskeys library 0.4.0 by arnezami, KenD00
Loading BDVM... OK
BDVM 0.1.5

Initializing source...
Disc type found: Blu-Ray BDMV
Collecting input files...
Source initialized
Identifying disc... OK
DiscID : ---------
Searching disc in key database...
Disc not found in key database
Retrieving keys from source...
aacskeys 0.4.0 by arnezami, KenD00

Current path: -----

MKBv: 12
Could not find a Processing Key or Device Key resulting in the Media Key.
Possible key tried: -----
Possible key tried: -----
Possible key tried: -----
Possible key tried: -----
Possible key tried: -----
Possible key tried: -----


ERROR: PROCESSMKB, errnr: -3


aacskeys ERROR: PROCESSMKB, errnr: -3
Failed retrieving keys from source


I read all the read me files, got OK's on every thing. The MKBv is 12 as you can see. I was understanding that this program could do MKBv 17.. or higher?

I removed a lot of the key information I didn't want to take a chance on breaking a rule in my first post.
Thanks for all the great work. If only I knew what I was doing..

pynux
30th April 2011, 17:45
only mkbv 1 to 10 are in aacskeys
you want to decrypt mkbv >10
if you want to decrypt mkbv >10 add keys in ProcessingKeys.txt (only if you have this key , only makemkv / dvdfab / anydvd and legal software have this key ...)

hoppel118
13th August 2011, 15:08
Hey guys,

when I compile "aacskeys-0.4.0c" I get the following error:

make
==== Building aacskeys ====
ioctl.cpp
src/ioctl.cpp: In constructor ‘Drive::Drive()’:
src/ioctl.cpp:12:61: warning: converting to non-pointer type ‘int’ from NULL
mmc.cpp
aacs_ecdsa.cpp
cmac_aes.cpp
aacs_aes.cpp
aacskeys.cpp
cmac.cpp
Linking aacskeys
==== Building libaacskeys ====
ioctl.cpp
src/ioctl.cpp: In constructor ‘Drive::Drive()’:
src/ioctl.cpp:12:61: warning: converting to non-pointer type ‘int’ from NULL
mmc.cpp
aacs_ecdsa.cpp
cmac_aes.cpp
aacs_aes.cpp
aacskeys.cpp
In file included from src/aacskeys.cpp:33:0:
src/aacskeys.h:8:17: fatal error: jni.h: Datei oder Verzeichnis nicht gefunden
compilation terminated.
make[1]: *** [obj/linux/ReleaseLib/aacskeys.o] Fehler 1
make: *** [libaacskeys] Fehler 2

If I change the JDK_INCLUDE-path in "premake.lua" to the path where the jni.h is located (/usr/lib/jvm/java-6-openjdk/include/) I get get the following error:

==== Regenerating Makefiles ====
make: premake: Kommando nicht gefunden
make: *** [Makefile] Fehler 127

Where is the problem? What is wrong?

----------------------------------------------------------------------
EDIT:

Ok, I got it. Had to install sun-java6-jdk from a special rep. and activate it under ubuntu 11.04.
----------------------------------------------------------------------

Greetings

Hoppel

Wild Penquin
13th September 2011, 16:17
Btw. just noting there are some new MKB keys at the Japanese site (http://ysk.orz.hm/BD/DeviceKey_MediaKey/). Did someone already test them? I only have a few MKBv19 and some MKBv17 disks, they work fine....

noodle1
13th September 2011, 18:00
Btw. just noting there are some new MKB keys at the Japanese site (http://ysk.orz.hm/BD/DeviceKey_MediaKey/). Did someone already test them? I only have a few MKBv19 and some MKBv17 disks, they work fine....

Thanks! I hadn't seen that upload.

I've only got discs up to MKBv19, so I can't vouch for the last 2 keys either. The lower ones work on all of the discs I wasn't able to decrypt yet though.

spock2000
14th September 2011, 01:42
@ Wild Penquin,
Thanks for the link man! I just tested 2 movies Salt(Mkbv19) and Thor(Mkbv23). That last movie thor works with the last Processing Device Key on the list.:D:D

spock2000
17th September 2011, 00:49
Check this out!

spock-desktop aacskeys-0.4.0c # aacskeys -v /media/SOURCE_CODE
aacskeys 0.4.0 by arnezami, KenD00

Current path: /bin/aacskeys-0.4.0c

MKBv: 25
Processing key: C32238976FF44A51E2D33553CFE85772
Encrypted C-value: 21453D416FAC679D0B5785C35506F045
Corresponding uv: 00000384

Decrypted C-value: 0CD5953716C906557AA362D5EC030855
Media key: 0CD5953716C906557AA362D5EC030BD1

Encrypted verification data: 50B076C4E6A45575263D47D488138839
Decr verif data should be: 0123456789ABCDEF
Decrypted verification data: 0123456789ABCDEF3BD1C55692D74042

Drive FW info: YL05
AACS Version: 01
Number of concurrent AGIDs: 1
Supports BN generation: YES
BN Block Count: 1
Inserted medium AACS protected: YES

AGID: 00

Volume ID (AACSBYPASS): EF0627C1BE85BF658399F665B67C45B4

Volume Unique Key: 8141810DCD755C64F38200D2393990EB
Unit Key File Hash (Disc ID): 168106D53C544B57395FCE6CD3EF8D0B5CC97FA6

Encrypted Unit Key 1: 9E0446F068D84C6799B771A009440777
Encrypted Unit Key 2: A6BEEDE353622F48425602DABB570A50
Encrypted Unit Key 3: 08F66271FEC236E8FEAC58B821003D4C
Encrypted Unit Key 4: A053961713EC96FD7A64F82B59CD7615

Decrypted Unit Key 1: 947573F10C07E3C2AC45C12B04A3512E
Decrypted Unit Key 2: 7B7A09E9451E320B0F5EAE899DE0E7EB
Decrypted Unit Key 3: 752E9F700DB971D1FE73CF44B092CDB0
Decrypted Unit Key 4: 8841D33A4FD57589A827CE16AC343125


:cool::cool::cool:

jyavenard
3rd October 2011, 03:17
Following an attempt to play a BD disk (Pink Floyd The Dark Side of the moon)

Any attempts to read another disk is now failing with an error "The given Host Certficate / Private Key has been revoked by your drive."

aacskey returns the same errors.

Thanks in advance
JY

monk3y
5th October 2011, 17:11
I got the same with the Apocalypse Now Full DISCLOSURE 3-DISC DELUXE EDITION

~user:computer: aacskeys -v /media/APOCALYPSE_NOW_DISC1/
aacskeys 0.4.0 by arnezami, KenD00

Current path: /usr/share/aacskeys

...

The given Host Certficate / Private Key has been revoked by your drive.


ERROR: SENDHOSTCHAL: SK: 0x5, ASC: 0x6F, ASCQ: 0x00, errnr: -2




Thanks in advance
monk3y

ro-ee
6th October 2011, 09:39
On June 9th 2011, mbrp published a list of VUKs and of a new Host Certificate for AACSkeys in the "Post Blu-ray Volume Unique Keys here" thread.

Is that Host Certificate in use? or is it an older one?

monk3y
6th October 2011, 10:27
The download link (http://forum.doom9.org/showthread.php?p=1506970#post1506970) posted here is already used by an newer uploader from August 2011. Any other source for the hcert you are talking about ?

Should i post my used hcert here ?

Thanks in advance
monk3y

ro-ee
6th October 2011, 11:04
The download link (http://forum.doom9.org/showthread.php?p=1506970#post1506970) posted here is already used by an newer uploader from August 2011. Any other source for the hcert you are talking about ?

Should i post my used hcert here ?

Thanks in advance
monk3y

[previous nonsense deleted]

I see the original info isn't there anymore. I don't have the HCert available right now, maybe later this day. It might be enough posting the first few bytes to see if that certificate is used.

monk3y
6th October 2011, 17:39
8C8...08C
0200005CFFFF000000AE00004142A5411...CF72E49668DAF1DB9


Thats the Hcert iam using, the processing keys are from here (http://ysk.orz.hm/BD/DeviceKey_MediaKey/).

monk3y

ro-ee
8th October 2011, 11:25
8C8...08C
0200005CFFFF000000AE00004142A5411...CF72E49668DAF1DB9


Thats the Hcert iam using, the processing keys are from here (http://ysk.orz.hm/BD/DeviceKey_MediaKey/).

monk3y

That's the host certificate I have here since the olden days. I don't find the file on my computer anymore, but it was definitively another HCert, and most likely a newer one.

jyavenard
17th November 2011, 02:02
Following an attempt to play a BD disk (Pink Floyd The Dark Side of the moon)

Any attempts to read another disk is now failing with an error "The given Host Certficate / Private Key has been revoked by your drive."

aacskey returns the same errors.



Been over a month now.... No answer.

What can I do to go around the issue with my drive invalidating the key that most seem to use?

setarip_old
17th November 2011, 03:08
@jyavenard

Hi!

Have you tried using DVDFab, MakeMKV, or AnyDVDHD?

ro-ee
17th November 2011, 14:40
For those who know: if a host certificate is revoked (active revocation) and the drive doesn't accept it even with older disk, does a new certificate unlock the drive again?

I don't have the file posted previously anymore, but in there was a newer host certificate, perhaps someone who has downloaded (and not deleted) the file can post it again.

setarip_old
17th November 2011, 18:19
@ro-ee

Click on the following link:

http://www.makemkv.com/forum2/viewtopic.php?p=16597#p16597

vnu007dl
5th April 2012, 19:58
Hi
Last time I ve bought bd drive Liteon BLU-RAY iHBS112. I am Linux user. Kubuntu 11.10. I can watch movies from BD only via makemkv and VLC, and it works fine. But I try to watch without make mkv, only with libbluray, libaacs, and VLC, and KEYDB.cfg file. But in database there is no keys for a new movies, so I tried to do it myself with aacskeys.
darek@darek-kubuntu:~/aacskeys-0.4.0c$ aacskeys -va "/media/1920 BITWA WARSZAWSKA/"
aacskeys 0.4.0 by arnezami, KenD00

Current path: /home/darek/aacskeys-0.4.0c

MKBv: 25
Processing key: C32238976FF44A51E2D33553CFE85772
Encrypted C-value: DED130D0412F6B3543BC435E94E847C3
Corresponding uv: 00000384

Decrypted C-value: 14B7CE0E6F166D2EA394BB544642BD85
Media key: 14B7CE0E6F166D2EA394BB544642BE01

Encrypted verification data: 2B91AFE35112997CD33E72500F84FEFB
Decr verif data should be: 0123456789ABCDEF
Decrypted verification data: 0123456789ABCDEF5CFB8C65BC1FE8B0

Drive FW info: PL022011/11/11 16:53
AACS Version: 01
Number of concurrent AGIDs: 2
Supports BN generation: NO
BN Block Count: 0
Inserted medium AACS protected: YES

Host Private Key (Hpriv): 8C8647FE2A70EF0388EA9E43F432CC441C6B108C
Host certificate (Hcert): 0200005CFFFF000000AE00004142A5411F1E63F1
85581C876B939FB40B523BF69C004CA69E047606
EE5183C0ABEF1E7D04CB6E65260677E7B0573D08
E60957935503ED78F7E27B190B4A7CAFCBAFF4A2
836453ECF72E49668DAF1DB9
Host Nonce (Hn): 2923BE84E16CD6AE529049F1F1BBE9EBB3A6DB3C

AGID: 00

The given Host Certficate / Private Key has been revoked by your drive.


ERROR: SENDHOSTCHAL: SK: 0x5, ASC: 0x6F, ASCQ: 0x00, errnr: -2

darek@darek-kubuntu:~/aacskeys-0.4.0c$

What is wrong. Could you help me? How to get the keys?

BlurayDecrypter
8th April 2012, 07:35
Host Private Key and Host certificate have been revoked. there is no new keys public,now.

vnu007dl
8th April 2012, 09:58
So, I understand that for now there is no possible to crack this BD Discs? The only tool for now is makemkv? What about public keys? Is there any soft on this forum to crack public keys?

Guest
8th April 2012, 14:45
You can try AnyDVD HD.

vnu007dl
9th April 2012, 07:41
I am Linux user so I can not use AnyDVD - it doesnt works under Wine. Only tool for Linux is Makemkv. Do You know any recipe how to get keys from Makemkv?

2400NV
9th April 2012, 10:09
For a v25 disc, such as the one you're asking about, I'd first use dumpvid combined with makemkv to get the vid and then aacskeys to get the actual disc key. I run dumpvid in a virtualbox with windows — I've been told that wine works too — and everything else as linux programs. The process is a bit slow and annoying but it works for me.

vnu007dl
10th April 2012, 19:25
I already tryied use dumpvid via Wine, but it doesn works
darek@darek-kubuntu:~/AACS$ wine dumpvid.exe d
DumpVID 0.3 by KenD00 (adapted for bluray testing)

Drive type is recognised as CDROM/DVD.

Sending SPC1 Test Unit CDB6 command..done.
Returned good status.

Press ENTER to start hammering

Hammering drive...

But nothing happen even after few hours. I do not understand how to get key from makemkv? My drive is Liteon iHBS112

ro-ee
14th April 2012, 14:33
Is there a way to find out if a Blu-ray will have an update host certificate list, which will lead to the drive being unable to use the old HC anymore? Besides doing it on the drive, actually?
I'm wary buing newly released Blu-rays will lock out my drive b/c I currently have only the host certificate that starts with 0x0200005CFFFF (and the private key that starts with 0x8C8)

derbaer
17th January 2013, 13:43
http://ysk.orz.hm/BD/DeviceKey_MediaKey/ProcessingDeviceKeysSimple.rar

What is the password for the RAR-archive? Does anyone know it?

monk3y
28th January 2013, 16:01
If i try to open the folder it says the folder name is "ProcessingDeviceKeysSimple(-V30)",so there could be the missing v29 and v30 inside, someone should share the pw please.

Zombiedeth
1st February 2013, 18:03
v29 and v30 use the same key as v25 so there's nothing new there even if he added a password to the file.

if you find the original file ProcessingDeviceKeysSimple.txt
and change the last line from ;V23/25 to ;V23/V25-V30 the CRC matches the password protected file it's simply a documentation change.

monk3y
3rd February 2013, 19:53
Thanks for the info i thought the v25 key only works till v28, is there a source for this information?

patul
4th February 2013, 04:54
I can confirm Zombiedeth's information, with a little google, you can easily get the pwd btw.

sl1pkn07
4th February 2013, 05:48
password found!

i agree patul Zombiedeth

PD: seriussly, little google?? :rolls:

Rudde
3rd December 2013, 20:26
Hi, I get this error when I try to run this program, I have VID and a patched drive.

ERROR: PROCESSMKB, errnr: -3

dizzier
4th December 2013, 17:12
Hi, I get this error when I try to run this program, I have VID and a patched drive.

ERROR: PROCESSMKB, errnr: -3

You need proper processing key or device keys to decrypt this disc.

Rudde
4th December 2013, 20:29
You need proper processing key or device keys to decrypt this disc.

I gave it the device number, what is a processing key`?

dizzier
4th December 2013, 22:05
I gave it the device number, what is a processing key`?

I really have no idea what do you mean by "device number". The explanation of how AACS works and what is a processing key can be found on this forum (http://forum.doom9.org/showthread.php?t=122363).

And just to save you time, currently there are no processing keys available for MKBv31 and later.

dizzier
13th December 2013, 15:53
New host certificate and key, already revoked but works up to MKBv43, might still be of use for some people:
88B245EA25315F46E6E99D9D521EB1194454A82D
0201005CFFFF800000C400005BF6843ED1AA9C9DEEFEAD8174479C72AB5457691EEB75669105BB195D4B9133069A18FD5357797116CEC22D7FE8F366C2A092E1D00DB770E9E01DB687456B6FBFA28C962D88F05DD43F584ECC821AF7

Zombiedeth
15th December 2013, 08:03
I think it must be revoked at MKBv43 or earlier because it's already revoked for me and i haven't used any discs newer then MKBv43.

dizzier
15th December 2013, 11:58
I think it must be revoked at MKBv43 or earlier because it's already revoked for me and i haven't used any discs newer then MKBv43.

I've just double checked that it is not present in revocation list on MKBv43. This is a certificate with bus encryption bit set, you need aacskeys 0.4.0e in order to use it (it is floating around for a while), 0.4.0c available on this forum will not work.

Zombiedeth
15th December 2013, 13:18
I've just double checked that it is not present in revocation list on MKBv43. This is a certificate with bus encryption bit set, you need aacskeys 0.4.0e in order to use it (it is floating around for a while), 0.4.0c available on this forum will not work.

I see i tried it with Videolan but the precompiled libaacs doesn't support bus encryption. Maybe that's why it says the certificate is revoked.

dizzier
15th December 2013, 13:33
I see i tried it with Videolan but the precompiled libaacs doesn't support bus encryption. Maybe that's why it says the certificate is revoked.

It doesn't matter, libaacs supports bus encryption capable certificates just fine (even old versions). Then only thing it is not capable of is actually using bus encryption (unless you use latest version from git), but this requires disc support and such discs are right now extremely rare.

aacskey 0.4.0c doesn't work because it blindly assumes that the second byte in the certificate is 0, 0.4.0e fixes it simply by allowing 1 in there.

Anyway, it is hard to say why exactly it is not working for you. You probably should try aacskeys 0.4.0e first.

Zombiedeth
15th December 2013, 14:21
It worked with aacskeys 0.4.0e and i got it working with Videolan also there was a error in my KEYDB.cfg preventing it from working.

candela
21st December 2013, 21:56
Is there also any new processing key known to go with the host certificate? And does anyone were to get a compiled version of VLC libaacs 0.7.0

dizzier
24th December 2013, 13:10
And does anyone were to get a compiled version of VLC libaacs 0.7.0

You can try the ones attached. Choose proper version (32 or 64 bit) depending on the VLC version you have. I've tested 64 bit version and it seems to be working fine, unfortunately I am currently unable to test 32 bit version (hopefully it will work too).

EDIT: Got back to my Windows PC, both versions verified to be working fine with VLC 2.1.2 on Windows 7.

DarthM
3rd January 2014, 00:37
Hi everyone especially dizzier,

i have a patched LG-GGC-H20L and can bypass the revocation stuff, but i still need a proccessing key right?

for discs with mkbv30 and lower it is working but with discs v31 and above i can't get it working because i'm missing a processing key, i already updated the hostkey file with your posted stuff

so how do you do that?
i've seen in another topic for volume keys here you can calculate the VUK till atleast v40

i tried aacskeys 0.4.0c and e (both linux, x64)

i only get accskeys to dump the Volume ID, but that's all

man i hate that stupid stuff, the guys who just wanna watch their legally bought blurays without dumping everything need to hack and the other ones who are loading their stuff from the net, just double click their files : /

so it would be very nice if someone could give me a hint (even per pm), how to get these discs with newer mkb versions working

Big Thanks in advance
DarthM

dizzier
3rd January 2014, 01:29
Hi everyone especially dizzier,

i have a patched LG-GGC-H20L and can bypass the revocation stuff, but i still need a proccessing key right?

for discs with mkbv30 and lower it is working but with discs v31 and above i can't get it working because i'm missing a processing key, i already updated the hostkey file with your posted stuff

so how do you do that?
i've seen in another topic for volume keys here you can calculate the VUK till atleast v40

i tried aacskeys 0.4.0c and e (both linux, x64)

i only get accskeys to dump the Volume ID, but that's all

man i hate that stupid stuff, the guys who just wanna watch their legally bought blurays without dumping everything need to hack and the other ones who are loading their stuff from the net, just double click their files : /

so it would be very nice if someone could give me a hint (even per pm), how to get these discs with newer mkb versions working

Big Thanks in advance
DarthM

There is no processing key for MKBv31 or later so you cannot decrypt those discs. I have no idea how to handle that.
You can always extract VUKs from rippers, but this does not solve the problem and is rather inconvenient.

DarthM
20th January 2014, 16:56
hi again,

sorry for my late response and thank you for your lightning one.

so, we still need a processing key.

is it possible to calculate the used processing key of discs with mkbv31 and higher which you have posted VUKs for?
i mean to calculate these VUKs, a valid processing key had to be used right?
so we don't have one but the ripper had to have one right again?
i took a short look on the aacskeys source and the processing key is used for decrypting the encrypted C value right?
is it also possible to get both values from rippers?


another idea in my head is to put every possible processing key into the file and let it run
aacskeys returns the one which was successful
i know, it would be a long list and i don't want to think about the time frame : )
i guess an opencl port with endless threads would be awesome
guys with aacs-bypass drives wouldn't have a problem to let every possible key be checked right? only these with normal drives and countermeasures

or i just buy a standalone player ............ but that suxxx ......... a lot .......

dizzier
20th January 2014, 20:47
hi again,

sorry for my late response and thank you for your lightning one.

so, we still need a processing key.

is it possible to calculate the used processing key of discs with mkbv31 and higher which you have posted VUKs for?
i mean to calculate these VUKs, a valid processing key had to be used right?
so we don't have one but the ripper had to have one right again?
i took a short look on the aacskeys source and the processing key is used for decrypting the encrypted C value right?
is it also possible to get both values from rippers?

Yes, you are right, processing key needs to be extracted from a ripper or a player. That's the theory. Practice is not that easy. Some rippers simply ask their servers to provide them proper VUK (or Media Key), that means the processing key is never present on your computer at all. Others have processing keys (or device keys) heavily protected and times when processing key appeared in plain, not obfuscated way, in memory are long gone with 2007/2008. Of course you can still try if you want, please share any findings you have;)


another idea in my head is to put every possible processing key into the file and let it run
aacskeys returns the one which was successful
i know, it would be a long list and i don't want to think about the time frame : )
i guess an opencl port with endless threads would be awesome
guys with aacs-bypass drives wouldn't have a problem to let every possible key be checked right? only these with normal drives and countermeasures

or i just buy a standalone player ............ but that suxxx ......... a lot .......

Unfortunately that's just plain stupid. There are 2^128 possible keys. If you would be able to check a million keys every second (which is highly unlikely even with OpenCL) checking 1% of them would take about 107.902.830.708.060.141.889.705 years. I believe the universe will end well before we find anything useful;)

Fahzuu
21st February 2014, 15:04
If you would be able to check a million keys every second (which is highly unlikely even with OpenCL)

While this will hardly put a scratch into your reasoning, you are mildly underestimating the speed of CPUs nowadays.

A 5 year old Intel i7 can test roughly 10 million AES keys per second with a simple AES implementation in C/C++.

If you make use of its AES-NI instruction set, it will easily do - sit tight - 300 million per second.

But this will only remove a couple of digits from your number, so subjectively nothing really changes :)

dizzier
21st February 2014, 20:38
While this will hardly put a scratch into your reasoning, you are mildly underestimating the speed of CPUs nowadays.

A 5 year old Intel i7 can test roughly 10 million AES keys per second with a simple AES implementation in C/C++.

If you make use of its AES-NI instruction set, it will easily do - sit tight - 300 million per second.

But this will only remove a couple of digits from your number, so subjectively nothing really changes :)

Verifying processing key is not a single AES operation. Unless you know the position of the key in subset-difference tree you must do over 500 AES operations to test one processing key with a single version of MKB. And you have currently 46 MKB versions (not all use different processing keys though). So in the very worst case scenario you must do 23.000 AES decryptions to verify that a given key is not a processing key.

But yeah, that really does not change anything, even if we get hardware capable of doing trillions of AES operations per second:)

Fahzuu
21st February 2014, 21:32
Verifying processing key is not a single AES operation. Unless you know the position of the key in subset-difference tree you must do over 500 AES operations to test one processing key with a single version of MKB.

Actually, it is a single operation. There are roughly 500 entries, each requiring a different processing key, leading to the same media key. All you need is one, you wouldn't be looking to find all 500. Also it's only a single MKB you'd be examining.

Well, and then there is another aes op required to verify, but that's all. 2^129 aes operations to verify all possible processing keys for any chosen one of the "slots" or whatever they are called.

dizzier
22nd February 2014, 14:22
Well, OK, that depends on the approach (examining multiple subset-difference trees might be a better idea as you already have performed a key schedule for the given processing key you are testing). Anyway, you still get a processing key for a single MKB (or few, but not all, depends which tree you happen to crack).

Zombiedeth
23rd February 2014, 16:31
What about using OpenCL and Distributed computing? each person participating would only handle a small portion of the key range at a time.

dizzier
23rd February 2014, 17:34
Please read my reply with the calculations. OpenCL does not change anything at all, it is not a "magic technology that makes anything fast".
Anyway, even if you get a billion machines each verifying billions keys per second you would still not be able to get anything before the sun explodes, Earth is destroyed and universe ends. Even if you can get it a billion times faster with OpenCL it would still not be enough.

ghefgpq
27th May 2014, 13:01
Do you know the Media Key or Processing Key AACSv42 and AACSv43

dizzier
27th May 2014, 13:09
No, I don't.

pvh1987
5th July 2014, 16:23
I just got a portable BD drive for my Macbook Pro. It is a Samsung SE-506CB. When I run aacskeys it says


The given Host Certficate / Private Key has been revoked by your drive.


Then I found a newer Host Certificate and now it says


Problem with verifying the drive signature.


I am not sure what to do about this. On my Linux PC with an older Pioneer BD drive, aacskeys usually work fine. I think I might have patched this drive several years ago. I cannot find a patch for my Samsung drive, though.

Do I need a patch or could the problem be something else?

Thanks in advance :-)

dizzier
7th July 2014, 22:32
aacskeys 0.4.0c does not work with host certificates that have Bus Encryption Capable bit set, which is located in the second byte of the host cert. In short, aacskeys 0.4.0c does not support host certificates that start with 0201 (basically all recent ones).

However, the fix is trivial to make. In the aacskeys source code, locate file aacs_ecdsa.cpp. You will find 'aacs_set_cert' function there. Simply remove the first 'if' block (or modify it to allow second byte not to be zero) and recompile aacskeys, it should work.
I believe there was also aacskeys 0.4.0e floating around, hacked by someone, that has this fix applied.

pvh1987
9th July 2014, 21:45
Thanks. I did the "fix" and recompiled - now it works. However, DumpHD will not use the recompiled libaacskeys.so and throws an exception:


Creating GUI... DONE
Exception in thread "main" java.lang.UnsatisfiedLinkError: dumphd.aacs.AACSKeys.getVersionString()Ljava/lang/String;
at dumphd.aacs.AACSKeys.getVersionString(Native Method)
at dumphd.aacs.AACSDecrypter.<init>(AACSDecrypter.java:140)
at dumphd.core.DumpHD.createDumpHD(DumpHD.java:153)
at dumphd.core.DumpHD.<init>(DumpHD.java:125)
at dumphd.gui.Manager.<init>(Manager.java:173)
at dumphd.core.DumpHD.main(DumpHD.java:1032)


Is the source code for DumpHD available so I can "fix" this as well? :)

By the way, is somebody working on getting more keys for aacskeys? It seems like all Blu-Rays up to MKBv31 will work, but no new keys have been found since MKBv31 and this is like more than a year ago? Or am I missing something?

Is there other tools available than aackeys that will decrypt Blu-Ray discs on Linux and Mac OS X? I do not care about the keys or if it is not free - i just want to be able to play my BDs in VLC :-)

Thanks in advance :-)

dizzier
9th July 2014, 23:24
VLC supports on-the-fly decryption of AACS using libaacs, which is quite complete, maintained and works quite well. You don't need to use DumpHD, which is basically dead, if you just want to play a movie in VLC. Simply put libaacs library in your VLC directory and your keys in KEYDB.cfg file and it should work.
Obviously you must acquire all needed keys on your own.

As for commercial solutions you can use MakeMKV, which allows you to dump movies or play them in VLC (latest versions can emulate libaacs, so you can play disc directly in VLC without dumping it). It supports latest versions of AACS and BD+ and you don't need any keys.

The_Cre8r
7th December 2014, 01:55
Does anyone have a copy of the source and/or release for windows?

Kdmeizk
15th May 2015, 14:18
http://forum.doom9.org/showthread.php?p=1320065#post1320065

Dead links. Can you update this please ?

candela
7th March 2018, 21:07
Someone sent me a new version of Aacskeys 0.4.0f (http://s000.tinyupload.com/index.php?file_id=31122209976861014118) with a fix for this bug (https://forum.doom9.org/showthread.php?p=1779382#post1779382) so it accepts newer host certificates. The last public certificate just got revoked in MKBv63 though :(. The package contains source, Win/Linux executables and also DLL versions for use with DumpHD.

edit: included MacOS version is older and not version f

deathtical
31st May 2018, 14:44
Hey guys,

I have tried to read through this thread but haven't really seen any kind of 1-10 or a-z tutorial of how to use this tool. I have Windows 10 Pro 64bit and am very comfortable using cmd as admin (I'm an IT Engineer), I could even throw together a Linux VM if needed. Could someone please point me to a "how to" for this. I know I'm missing something. I run the exe from a cmd window as admin. if i just run the exe it gives me a list of switches and examples of command structure but everything I try fails or hangs. For example, if I type in...

C>:aacskeys e

"E" is my drive. It just goes to a blinking cursor. I've let it sit there for 5 min and nothing ever comes up. I've tried some of the switches like...

-v

And still nothing happens. How long should it take? This is on 4K UHD discs. My drive is UHD "friendly" and recognizes the discs. I have even been able to rip some that I could find the hash keys for. I'd like to use this tool to get the keys directly of the discs that no one has posted yet.

Thanks

jerrycan
31st May 2018, 17:38
It doesn't work for 4K discs.

deathtical
31st May 2018, 22:26
It doesn't work for 4K discs.

Well, shoot. That's how I found this tool. On another forum some had said they had used this to get keys off of their 4K discs.

Bummer.

Well, thanks for the quick response. Any idea if the dev is working on adding this feature?

Thanks

MartyMcNuts
25th September 2018, 13:35
Hi all,

I've spent a few hours reading through this thread (more than once!) but I cannot find the answer for what I am seeking.

AACS keys shows the 'Corresponding UV' that goes with the Decrypted C-Value to get the correct Media Key.

What I would like to know is:

Is this UV located somewhere in the MKB_RO.in file or, if it's not, can someone please explain how it is calculated.

By reading the AACS documents, I've worked out how to decrypt the Media Key and Volume Id to get the VUK, but working out the UV has me stumped!!

I'd really appreciate any words of wisdom!

Thanks... :confused:

pietro
3rd December 2018, 21:28
With manuel: Introduction and Common Cryptographic Elements Book

Interprets Blueray version 61 AACS\MKBRO.inf and AACS\MKBRW.inf file records:
10 Manuel explain with Type and Version, MKBType 00041003 (yet 00031003 inside MKBRW.inf file)
21 Manuel explain with Host Revocation List
20 Manuel explain with Drive Revocation List
81 Manuel explain with Verify Media Key
7F Manuel exclude, yet text message inside forever MKB 1 2 3 .. 61
07 Manuel explain with Subset Difference Index
04 Manuel explain with Explicit Subset Difference
05 Manuel explain with Media Key Data
02 Manuel explain with End of Media Key Block


Now on Blueray 4k discus with 256 ECDSA publick keys found:

ContentRevocation.lst deducted before - identicle with manuel yet 256 ECDSA.
Content000.cer deducted before - identicle with manuel yet 256 ECDSA.

With trying many signings possible with cloud computing every files in 4K Blueray AACS directory.

Only new signings now inside MKBRO.inf deducted with infirmations showed below.

Interprets Blueray version 61 4K "2.0" AACS\MKBRO.inf file records:
10 Identicle with manuel, yet MKBType 48141003
21 Identicle with manuel same datums with same HD Blueray version 61
31 New and infirmations and hypoethsis following
07 Identicle with manuel yet more diffrent datums
20 Identicle with manuel same datums with same HD Blueray version 61
30 New and infirmations and hypoethsis following
F8 New and infirmations and hypoethsis following
7F Identicle with Blureray text message MKB 1..61
86 New and infirmations and hypoethsis following
04 Identicle with manuel yet more diffrent datums
05 Identicle with manuel yet more diffrent datums
28 New and infirmations and hypoethsis following
02 Identicle with manuel

07 04 05 infirmations and hypoethsis:
many more datums
subset-diffrence structures with small "U"
composition with every U-UV subsets excluding many keys of composition with every HD U-UV
hypoethsis: 4K Blueray discus excluding HD Blueray from decryptions

31 infirmations and hypoethsis:
64 bytes datums
31 is 21 plus single bit added 10
Verifys as LA Publick Key 256 ECDSA signatureing records datums 10 21
Hypoethsis: AACS 2.0 Host Revocation List Verificaton
Hypoethsis: bit 10 means 4K

30 infirmations and hypoethsis:
64 bytes datums
30 is 20 plus single bit added 10
Verifys as LA Publick Key 256 ECDSA signatureing records datums 10 20
Hypoethsis: AACS 2.0 Drive Revocation List Verificaton
Hypoethsis: bit 10 means 4K

F8 infirmations and hypoethsis:
0 bytes datums
Hypoethsis: AACS 2.0 no deductings mysteryus please somebody help

86 infirmations and hypoethsis:
no more MKB record 81, how now verify Media Key?
16 bytes datums, same identicle with AACS 81 record size
Hypoethsis: AACS 2.0 Verify Media Key, yet some differing possible?

28 infirmations and hypoethsis:
64 bytes datums
Verifys as LA Publick Key 256 ECDSA signatureing every before records 10 .. 05 datums
Hypoethsis: AACS 2.0 Media Key Block Verificaton


Please somebody put all 4K Blueray MKB versions if not 61 for downloadings and analyzings

Please somebody put Patriot AACS.zip directory 2.1 for downloadings and analyzings

Please somebody put Furry AACS.zip directory 2.1 for downloadings and analyzings

There is more reasons for asking so many this questions. Somebody thank you.

candela
4th December 2018, 20:33
MKBv57,60,61,65,Fury (https://ufile.io/av44i) Don't have patriot

pietro
11th December 2018, 19:22
First analyzings of MKBRO.inf records in 2.1 Fury and Patriot:
10 Identicle with manuel, yet MKBType 48151003
21 Identicle with manuel same datums with same HD Blueray version 61
31 Identicle with AACS 2.0
07 Identicle with manuel
20 Identicle with manuel same datums with same HD Blueray version 61
30 Identicle with AACS 2.0
F8 Identicle with AACS 2.0
7F Identicle with manuel
86 Identicle with AACS 2.0
04 Identicle with manuel yet more diffrent datums from 1.0 less from 2.0
0C Manuel of 1.0 explain with Media Key Variant Data
2D New with AACS 2.1 to be analyzing soonly
88 New with AACS 2.1 to be analyzing soonly
2F New with AACS 2.1 to be analyzing soonly
28 Identicle with AACS 2.0
02 Identicle with manuel

Fury Patriot records same datums size.

0C Media Key Variant Data is big clues yet more analyzings to happen soonly.


New files in 2.1 not 2.0 AACS directory: names is big clues!
SegmentKey00001.tbl 35127304 size bytes
IndividualSegment.tbl 19528 size bytes


Hypoethsis: Blueray little changing for 2.0
Hypoethsis: Blueray 2.1 like 1.0 Unified Media Key Block with little changings
Hypoethsis: We can deduct 4K manuels just like before!


(Thanks to somebody for putting Patriot AACS.zip and discus filelisting.txt)

Please Candela put list of files in Fury discus "DIR D:" sorry asking more (forgot) yet maybe help analyzings with new files.

MartyMcNuts
12th December 2018, 00:06
@pietro,

Here is the complete AACS folder from Fury UHD.

https://dailyuploads.net/gvu5itdemwk2

Here is the Directory Structure.

https://dailyuploads.net/yihlnbs48f8f

pietro
12th December 2018, 02:56
Thanks for Candela Marty anonymus

I now having all datums I need for more 2.1 deductings.

Directory of files immedietally showing hypoethsis!

Soonly posting of more infirmations - maybe few days

pietro
12th December 2018, 18:46
Marty

Please can you put size bytes of Fury\STREAM\00001.fmts file? Or directory listing again with all sizes sorry did not know before for asking.

Is listing comings from real discus or image ripping? Hopings with discus.

Thanksing! There is big clue here. 2.1 is cracking!

MartyMcNuts
13th December 2018, 01:33
@pietro,

I didn't know of any cmd prompt switch for tree to also print the file sizes so I found a small program called Treesize Free that worked a treat. The file is saved as a pdf.

https://dailyuploads.net/dw8nkhy1iwng

This is from my original Fury 4K Disc.

pietro
15th December 2018, 16:59
Minor analyzings and reporting inside here. Major ones relating to 2.1 fmts files hopefully put soonly.


2.1 Fury discus file listings from peoples helping are showing:

Files containing in Fury CLIPINF\
119 files naming with ABCDE.clpi - A B C D E is digit
Hypoethsis: Idendicle with HD discus explain in 1.0 manuels

Files containing in Fury STREAM\
118 ABCDE.m2ts files
1 00001.fmts
Using identicle ABCDE numbers with CLIPINF\ files with including 00001
00001.fmts many more bytes of m2ts 75 GB.
Manuel of 1.0 Blueray describe m2ts files.
Manuel of 1.0 Blueray describe "Source Packets" = 192 bytes
Manuel of 1.0 Blueray describe "Aligned Units" = 32 Source Packet = 6144 bytes
Every ABCDE.m2ts file bytes size 6144 multiple.
DeUHD changing 00001.fmts to 00001.m2ts.
00001.fmts file bytes size 6144 multiple similar.
Hypoethsis: m2ts idendicle with HD discus explain in 1.0 manuels, yet single 00001.fmts
Hypoethsis 1: 2.0 and 2.1 identicle from 1.0 using Aligned Units and Source Packets for ABCDE.m2ts files.
Hypoethsis 2: fmts also using Aligned Units small changings from m2ts - major further deductings soonly.
Hypoethsis: MKB 2.1 record 0C Media Key Variant Data using this file.

00001.fmts mysteryus name:
Hypoethsis: “ts” meaning still “Transport Stream”
Hypoethsis: “fm” meaning “Forensic Mark” explain with MakeMKV “AACS versions and revisions”
Hypoethsis: fmts similar with m2ts having easy conversion for playing

If hypoethsiss all correct still format mysterius big deductings hoping soon. Waiting for files from helping peoples.


Files containing in Fury PLAYLIST\
Having 124 of ABCDE.mpls
Less ABCDE.plst files comparing ABCDE.clip:
< 00198.
< 00335.
< 00336.
< 00337.
< 00338.
< 00339.
< 00340.
< 00341.
< 00342.
< 00343.
More ABCDE.plst files comparing ABCDE.clip:
> 00099.
> 00129.
> 00197.
> 00205.
> 00210.
> 00225.
> 00242.
> 00243.
> 00244.
> 00245.
> 00246.
> 00247.
> 00248.
> 00251.
> 00252.


Patriot discus is having similar differings.


Manuel of 1.0 Blueray describe "Playlists"

Blueray HD 1,0 also having ABCDE diffrences within PLAYLIST\ABCDE.mpls comparing CLIPINF\ABCDE.clpi
Hypoethsis: Idendicle with HD discus explain in 1.0 manuels.
Belief of these diffrences are ok same as 1.0 but needing further analyzings.

pietro
29th March 2019, 16:34
This are December deductings .. being sick with the doctors from then. Soon hopping somebodys can be useful for this even yet not finished.

More Blueray 2.1 deductings

.. thinkings and hypoethsiss and deductings after from before messagings ..


New files inside Blueray 2.1 not 2.0 AACS directory:

New file inside 2.1 discus Fury\AACS\IndividualSegment.tbl 19528 size bytes
Fury dump hex IndividualSegment.tbl:
00000000 01 00 00 00 04 c4 00 10 01 00 00 00 00 01 00 01 |................|
00000010 00 05 ad c0 00 05 b7 bf 01 00 00 00 00 02 00 01 |................|
00000020 00 09 53 40 00 09 5d 3f 01 00 00 00 00 03 00 01 |..S@..]?........|
00000030 00 0d ce 80 00 0d d8 7f 01 00 00 00 00 04 00 01 |................|
00000040 00 11 d5 00 00 11 de ff 01 00 00 00 00 05 00 01 |................|
00000050 00 18 98 c0 00 18 a2 bf 01 00 00 00 00 06 00 01 |................|
00000060 00 1f 29 40 00 1f 33 3f 01 00 00 00 00 07 00 01 |..)@..3?........|
00000070 00 23 3c 80 00 23 46 7f 01 00 00 00 00 08 00 01 |.#<..#F.........|
00000080 00 27 55 00 00 27 5e ff 01 00 00 00 00 09 00 01 |.'U..'^.........|
00000090 00 2b 4c 00 00 2b 55 ff 01 00 00 00 00 0a 00 01 |.+L..+U.........|
..
00004bc0 17 22 8d c0 17 22 97 bf 01 00 00 00 00 1d 00 01 |."..."..........|
00004bd0 17 27 24 00 17 27 2d ff 01 00 00 00 00 1e 00 01 |.'$..'-.........|
00004be0 17 2b f1 c0 17 2b fb bf 01 00 00 00 00 1f 00 01 |.+...+..........|
00004bf0 17 30 f1 40 17 30 fb 3f 01 00 00 00 00 20 00 01 |.0.@.0.?..... ..|
00004c00 17 36 00 40 17 36 0a 3f 01 00 00 00 00 01 00 01 |.6.@.6.?........|
00004c10 17 3a 91 c0 17 3a 9b bf 01 00 00 00 00 02 00 01 |.:...:..........|
00004c20 17 3f 5e c0 17 3f 68 bf 01 00 00 00 00 03 00 01 |.?^..?h.........|
00004c30 17 45 8d c0 17 45 97 bf 01 00 00 00 00 04 00 01 |.E...E..........|
00004c40 17 4a 57 80 17 4a 61 7f |.JW..Ja.|

Hypoethsis name:
"IndividualSegment.tbl" meanings "Individual Segment Table"
Table meanings N rows of datums bytes. Maybe rows same size?

Pattern is showing:
After beginning 01 00 00 00 04 c4 00 10
Repeat 1220 rows having 01 00 00 00 00 XX 00 01 YY YY YY YY ZZ ZZ ZZ ZZ

File bytes size 19528 = 8 + 1220 * 16

Hypoethsis first 8 file datums bytes:
01 00 4-BYTES-ROWS-COUNT 2-BYTES-ROWS-SIZE
4-BYTES-ROWS-COUNT = 00 00 04 c4 = 1220
2-BYTES-ROWS-SIZE = 00 10 = 16

Hypoethsis XX:
XX = 01 02 03 .. 10 repeating - counting 1, 2, 3, ..32, 1, 2, 3, ..32, 1, 2, 3, ..
Mysterius, yet always 01 02 03 .. 10 repeating.
Every 1, 2, 3, .. 32 is having 38+ repeatings.



New file inside 2.1 discus Patriot\AACS\IndividualSegment.tbl 24584 size bytes
Patriot dump hex IndividualSegment.tbl:
00000000 01 00 00 00 06 00 00 10 01 00 00 00 00 01 00 01 |................|
00000010 00 02 bc 80 00 02 c6 7f 01 00 00 00 00 02 00 01 |................|
00000020 00 06 99 40 00 06 a3 3f 01 00 00 00 00 03 00 01 |...@...?........|
00000030 00 0a 0e 00 00 0a 17 ff 01 00 00 00 00 04 00 01 |................|
00000040 00 0d 68 00 00 0d 71 ff 01 00 00 00 00 05 00 01 |..h...q.........|
00000050 00 12 01 00 00 12 0a ff 01 00 00 00 00 06 00 01 |................|
00000060 00 16 27 80 00 16 31 7f 01 00 00 00 00 07 00 01 |..'...1.........|
00000070 00 1b 22 40 00 1b 2c 3f 01 00 00 00 00 08 00 01 |.."@..,?........|
00000080 00 1f 15 40 00 1f 1f 3f 01 00 00 00 00 09 00 01 |...@...?........|
00000090 00 23 68 c0 00 23 72 bf 01 00 00 00 00 0a 00 01 |.#h..#r.........|
..
00005f80 19 c6 94 00 19 c6 9d ff 01 00 00 00 00 19 00 01 |................|
00005f90 19 c9 d9 80 19 c9 e3 7f 01 00 00 00 00 1a 00 01 |................|
00005fa0 19 cc e0 c0 19 cc ea bf 01 00 00 00 00 1b 00 01 |................|
00005fb0 19 d0 19 80 19 d0 23 7f 01 00 00 00 00 1c 00 01 |......#.........|
00005fc0 19 d3 a9 c0 19 d3 b3 bf 01 00 00 00 00 1d 00 01 |................|
00005fd0 19 d7 8d 00 19 d7 96 ff 01 00 00 00 00 1e 00 01 |................|
00005fe0 19 da a3 c0 19 da ad bf 01 00 00 00 00 1f 00 01 |................|
00005ff0 19 de 2b 00 19 de 34 ff 01 00 00 00 00 20 00 01 |..+...4...... ..|
00006000 19 e1 bf c0 19 e1 c9 bf |........|

Identicle pattern, yet 1536 rows

File bytes size 24584 = 8 + 1536 * 16

Hypoethsis identicle with Patriot first 8 file datums bytes:
4-BYTES-ROWS-COUNT = 00 00 60 00 = 1536
2-BYTES-ROWS-SIZE = 00 10 = 16
Every 1, 2, 3, .. 32 is showing 48 repeatings.



Fury:
Row XXXXXXXX YYYYYYYY
1 372160 374719
2 611136 613695
3 904832 907391
..
1218 390028992 390031551
1219 390434240 390436799
1220 390748032 390750591

YYYYYYYY = 0005adc0 .. 174a5780 growings every row
ZZZZZZZZ = 0005b7bf .. 174a617f growings every row
YYYYYYYY < ZZZZZZZZ inside row
YYYYYYYY > ZZZZZZZZ after row before
YYYYYYYY and ZZZZZZZZ hypoethsis now here

Identicle growings every row.


Manuel of 1.0 Blueray describe "Segment Portion" and "non-Segment Portion"
Manuel of 1.0 Blueray describe "Source Packets" = 192 bytes
Manuel of 1.0 Blueray describe "Aligned Units" = 32 Source Packet = 6144 bytes

Fury\STREAM\00001.fmts bytes size = 75139491840
6144 bytes multiple similarly with every m2ts files.
Hypoethsis 1: 2.0 and 2.1 very like 1.0 useing Aligned Units and Source Packets for NNNNN.m2ts files.
Hypoethsis 2: fmts useing Aligned Units small changings from m2ts - further deductings now here.
Hypoethsis: MKB 2.1 record 0C Media Key Variant Data useing this file.


Maximum YYYYYYYY ZZZZZZZZ = 390750591
75139491840 / 390750591 = 192.3
Hypoethsis: YYYYYYYY ZZZZZZZZ = index of Source Packets inside 00001.fmts


Every YYYYYYYY 32 multiple.
Hypoethsis: YYYYYYYY maybe must be multiple 32 is Aligned Unit.

Every ZZZZZZZZ - YYYYYYYY = 2559
Hypoethsis 1: ZZZZZZZZ existing hense not fixed 2559 hense future discus not always 2559 within.
Adding 1 is 2560 is 32 multiple.
Hypoethsis 2: YYYYYYYY ZZZZZZZZ = first .. last Source Packets numbering both Aligned Unit - YYYYYYYY is 6144 multiple, ZZZZZZZZ = YYYYYYYY + 31 + N * 32.
Questions: What is YYYYYYYY..ZZZZZZZZ meaning for? Deducted below.



Patriot:

Row XXXXXXXX YYYYYYYY
1 179328 181887
2 432448 435007
3 658944 661503
..
1534 433759168 433761727
1535 433990400 433992959
1536 434225088 434227647

Maximum YYYYYYYY ZZZZZZZZ = 434227647
Patriot\STREAM\00001.fmts bytes size = 83429818368
83429818368 / 434227647 = 192.1

Every Fury hypoethsiss identicle of Patriot



Hypoethsis: 00001.fmts file containing non-Segment Portion, Segment Portion, non-Segment Portion, .. , non-Segment Portion, Segment Portion, non-Segment Portion
Segment Portion always here size 80 Aligned Units =
non-Segment Portion always much more size bytes = thousands Aligned Units


New file inside 2.1 discus AACS\SegmentKey00001.tbl
Fury Patriot: 35127304 size bytes
Fury dump hex SegmentKey00001.tbl:
00000000 01 00 00 00 ff ff 02 18 01 00 00 00 00 20 01 02 |............. ..|
00000010 1b ae 52 c4 ad 08 5a ba 68 a1 a8 10 75 19 bd c5 |..R...Z.h...u...|
.. binary datums
00000210 65 59 97 9c 24 d8 1a 66 20 94 55 56 48 cf e6 5c |eY..$..f .UVH..\|
00000220 01 00 00 00 00 20 01 02 65 07 88 ce 54 af 6f 57 |..... ..e...T.oW|
00000230 4b 66 c0 ac d6 8a f4 2e 36 c3 65 28 d3 9d c3 f8 |Kf......6.e(....|
.. binary datums
00000420 a5 b2 d6 bc a3 5a c5 45 5a c4 5f 7f 0a 2c b8 97 |.....Z.EZ._..,..|
00000430 65 83 23 ac 6b 42 81 ae 01 00 00 00 00 20 01 02 |e.#.kB....... ..|
00000440 51 3e 52 fd 36 33 3f 53 ce fd 71 ea 72 0a 9f a3 |Q>R.63?S..q.r...|
.. binary datums .. 01 00 00 00 00 20 01 02 .. binary datums
..
.. binary datums .. 01 00 00 00 00 20 01 02 .. binary datums
0217fbc0 64 7b 0b b2 dd 1c 1d 81 82 ec 8f 64 99 c3 a5 21 |d{.........d...!|
0217fbd0 22 10 90 7f 90 31 3b a8 01 00 00 00 00 20 01 02 |"....1;...... ..|
0217fbe0 e4 45 f5 3e 4a 31 2d 1a a9 00 2d c1 29 28 fe 26 |.E.>J1-...-.)(.&|
.. binary datums
0217fde0 06 c9 44 c2 27 9e 60 ae 1c 98 dd c7 7f 80 e8 4d |..D.'.`........M|
0217fdf0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
.. zeros datums
02180000 00 00 00 00 00 00 00 00 |........|

Patriot Fury first 16 bytes datums same:
00000000 01 00 00 00 ff ff 02 18 01 00 00 00 00 20 01 02 |............. ..|

Patriot Fury last 536 bytes datums same zeros:
0217fdf0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
.. zeros datums
02180000 00 00 00 00 00 00 00 00 |........|

Patriot Fury having 01 00 00 00 00 20 01 02 same 65535 file positions 8, 8 + 536, 8 + 2 * 536, .. , 8 + 65534 * 536


File size and datums dump datums and first 8 bytes datums reveal hypoethsiss:

Hypoethsis name:
"SegmentKey00001.tbl" meanings "Segment Key Table 1"
Table meanings N rows of datums bytes - Maybe rows same size? Maybe 536?

Hypoethsis first 8 file datums bytes:
01 00 4-BYTES-ROWS-COUNT 2-BYTES-ROWS-SIZE
(Identicle first 8 bytes with IndividualSegment.tbl)
4-BYTES-ROWS-COUNT = 00 00 ff ff = 65535
2-BYTES-ROWS-SIZE = 02 18 = 536

Hypoethsis of last 536 zeros bytes:
Mysteryus. Fake unused row?

File bytes size 35127304 = 8 + 65535 * 536 + 536

Every row having:
01 00 00 00 00 20 01 02 <528 binary datums>

Hypoethsis of 01 00 00 00 00 20 01 02:
Mysteryus. Every row begins same.

Hypoethsis of 528 binary datums:
528 not 20 divisible (not 160-ECDSA or SHA-1 list)
528 not 32 divisible (not 256-ECDSA or AES-256 or SHA-256 list)
528 = 16 * 33
File having "Key" in name. Hense maybe 33 AES-128 keys?
Maybe hint "20" is 32 within first 8 bytes position 5.
Maybe nonce with 32 AES-128 keys?
Maybe Media Key with 32 AES-128 segment keys?
How encrypted? AES-CTR? AES-CBC? Blueray never useing AES-CTR
Hypoethsis: CBC likely with nonce using Media Key Variant within MKB.
Maybe XX within IndividualSegment.tbl row counting 1,2,3,..32 is number of key 1..32 ?
Somebody helping with needing for analyzings. Maybe waiting further 2.1 discus not Fury Patriot.


fmts file Segment Portion = 80 Aligned Units always.

Sorry yet not including thinkings and weeks of how analyzings happenings here for protecting of same analyzings by Blueray.

Results of analyzings:

Outside IndividualSegment.tbl YYYYYYYY-ZZZZZZZZ values using every Aligned Units all Source Packets normally playings.
Inside IndividualSegment.tbl YYYYYYYY-ZZZZZZZZ values abnormally playings useing half of Aligned Units not every Aligned Units.
Fury and Patriot always 2560 Source Packets 40x2 Aligned Units useing always only half.
Pattern 1 inside XXXXXXXX-YYYYYYYY Packets: useing 32, not-useing 32, useing 32, not-useing 32, ... useing 32, not-useing 32
Pattern 2 inside XXXXXXXX-YYYYYYYY Packets: not-useing 32, useing 32, not-useing 32, useing 32, ... not-useing 32, useing 32
Every identicle XX 1..32 always Pattern 1 or always Pattern 2.

Patriot = 165 minutes
13579072 Aligned Units
1536 * 40 IndividualSegment.tbl Aligned Units not-useings
13517632 = 13579072 - 1536 * 40 Aligned Units Playing
1365 Aligned Units every second
Every 6.4 seconds average having .03 seconds average IndividualSegment.tbl Source Packets maybe single video picture

Fury = 134 minutes
12229735 Aligned Units
1220 * 40 IndividualSegment.tbl Aligned Units not-useings
12180935 = 12229735 - 1220 * 40 Aligned Units Playing
1515 Aligned Units every second
Every 6.6 seconds average having .02 seconds average IndividualSegment.tbl Source Packets maybe single video picture


Hypoethsis: Playing having only 1 possible of 2 every 32 keys yet not having key for not-useing.
Hypoethsis: Forensic Mark inside useing IndividualSegment.tbl so Blueray can be knowing every 32 keys useing.
Hypoethses: Maybe not always 40x2 within future discus.
Hypoethses: Maybe not always 32 keys within future discus.
Hypoethses: Maybe not always 2 possible of every keys within future discus.
Hypoethses: Maybe not always 6.5 seconds within future discus.



Hense now MKB 2,1 records can be deducted.

AACS 2.1 MKB records:
10 Identicle with manuel, yet MKBType 48151003
21 Identicle with manuel
31 Identicle with AACS 2.0
07 Identicle with manuel
20 Identicle with manuel
30 Identicle with AACS 2.0
F8 Identicle with AACS 2.0
7F Identicle with manuel
86 Identicle with AACS 2.0
04 Identicle with manuel
0C Manuel of 1.0 explain with Media Key Variant Data
2D New with infirmations and hypoethsis following
88 New with infirmations and hypoethsis following
2F New with infirmations and hypoethsis following
28 Identicle with AACS 2.0
02 Identicle with manuel

2D infirmations and hypoethsis:
2D is 0D plus single bit added 20
18 or 20 more than 2 * subsets bytes datums
0C Media Key Variant Data happens hense likelyness to Introduction and Common Cryptographic Elements Book Unified Media Key Block?
Same as 0D Variant Number, yet 16 not 10 bits, 65536 Media Key Variant values, not 1024 from manuel of 1.0
Hypoethsis: AACS 2.1 Variant Number Record having maximum 65536 of values
Hypoethsis: bit 20 means 4K

2F infirmations and hypoethsis:
16 * 65535 bytes datums
Hypoethsis: additional cryptographic datums of 65535 Media Key Variant values
Last hypoethsis possible 2: 65535 encryptings of Media Key using every Media Key Variant

88 infirmations and hypoethsis:
Size 12 + 4 * 65536 or 16 + 4 * 65535
2F record having hypoethsis 65535 hense more likely than 65536
And plus SegmentKey00001.tbl hypoethsis matching 65535
Hypoethsis: nonce, plus additional cryptographic datums of 65535 Media Key Variant values
Function mysterius still - maybe 32 bits saying which Pattern 1 or 2 for every 32 keys.


More infirmations and questions:
Not like Unified Media Key Block because MKBRO.inf 2.1 is only MKB not extra MKBs.
So how now getting Media Key?
Hypoethsis:
Media Key encrypted somewhere - within MKBRO.inf or other file.
SegmentKey00001.tbl before hypoethsis: 65535 rows with 33 keys or nonce + 32 keys
Hypoethsis:
Blueray 4K player decrypt 1 of 65535 Media Key Variant from MKBRO.inf record 0C
Possible 1: Media Key is maybe in SegmentKey00001.tbl row - maybe key not nonce.
Possible 2: Media Key encrypted in MKBRO.inf record 2F for every 65535 Media Key Variants.



All 2.0 plus 2.1 new files now with hypoethsiss!! Yet for vericating hypoethsiss now are needing Processing Keys.

EncryptedEggs
5th August 2023, 17:44
The downloads in the OP are expired, can someone tell me how to get this program? Thanks.

candela
5th August 2023, 19:44
The downloads in the OP are expired, can someone tell me how to get this program? Thanks.

Download link available in this thread (https://forum.doom9.org/showthread.php?t=176924)