Log in

View Full Version : Finally handling BD+ (?)


Pages : 1 2 3 4 5 6 7 8 9 [10] 11 12 13 14 15 16

Schwa226
27th November 2008, 09:06
About RSA attack I can give you following information:

A 512 Bit RSA done with GGNFS:

with GGNFS on 2 A64 X2 4800+ in less then 2 month...
latsieve 11.10. to 14.11.
matbuild/matprune 14.11. to 16.11.
matsolve 16.11. to 30.11.
sqrt 30.11. to 01.12.

Boost GGNFS for Dualcore:

GGNFS adjusted for Intel Core2Duo :Rapidshare (http://rapidshare.com/files/163021086/ggnfs-svn-322-p4-win.zip)

Needed libgmp-3.dll (http://www.dlldll.com/libgmp-3.dll_download.html) DLL

May it helps...

tteich
27th November 2008, 20:29
About RSA attack I can give you following information:

A 512 Bit RSA done with GGNFS:

with GGNFS on 2 A64 X2 4800+ in less then 2 month...
latsieve 11.10. to 14.11.
matbuild/matprune 14.11. to 16.11.
matsolve 16.11. to 30.11.
sqrt 30.11. to 01.12.

Boost GGNFS for Dualcore:

GGNFS adjusted for Intel Core2Duo :Rapidshare (http://rapidshare.com/files/163021086/ggnfs-svn-322-p4-win.zip)

Needed libgmp-3.dll (http://www.dlldll.com/libgmp-3.dll_download.html) DLL

May it helps...

While 512bit brute-force attacks can be done these days, this approach is really useless at a modulus size of 2048bits.

js06078
27th November 2008, 22:46
How about starting work on the newest batch of BD+ titles?

Here's a list of titles that confirmedly employ the newest version of BD+ (which AnyDVD-HD cannot handle yet):

Futurama: Bender's Game (USA)
Firefly, The Complete Series (USA)
Planet of the Apes (1968) (USA)
Planet of the Apes (all of the series) (USA)
Space Chimps (USA)
Meet Dave (USA)
X-Files 2 (USA)
X-Files 1 (USA)
Home Alone (USA)
The Day The Earth Stood Still: Special Edition (USA)

Horton Hears A Who (Hong Kong)

Predator 2 (1990) (UK)
Shine a Light (UK)

loo3aem3ON
27th November 2008, 22:49
While 512bit brute-force attacks can be done these days
The general number field sieve has a subexponential runtime (brute force is exponential). It's the latest and asymptotically fastest algorithm publicly known algorithm for integer factorization. Like all the other previous version (like the quadratic sieve) it is based on fermat factorization. That is finding a pair (x, y) with x>1,y>1 and x!=y which satisfies x^2 = y^2 (mod N). If such a pair is found the factorization of N can be obtained easily (in most cases). Now the gnfs employs very sophisticated techniques to find such pairs which are hard to understand (for me at least). A brute force search is hopeless even for a 160-bit rsa modulus.

this approach is really useless at a modulus size of 2048bits.
Our N (public modulus N = p*q) is 1280 bit long:
N =
8B169F529C28B5D45DB5D1607B831BED31381D38AEF561A43E744326DD00765E
E7A47F353D4A8C507752B08A6671259AAF140E86EEB1D05D344EF801A5AFB150
3A82BE089DCF25618852199D26CC79AE99466A231999AAC6C26E7DDA662304A7
72D1B304C9CD0C724434D640E29BE64FBBE1E7993A30939D6FB925AE0C350896
14F89FBAE9B931FC01D4D10732EB62CA8878E1894BD82F3007806D75CE172B57
Like i said 1024 bit numbers (product of two prims of about the same length) can be factored currently with expensive hardware but not 1280-bit. Maybe with classified algorithms. :rolleyes:

How about starting work on the newest batch of BD+ titles?
People have stopped reporting results so it's probably better to work on the documentation to improve the public understanding of BD+.

Here's a list of titles that confirmedly employ the newest version of BD+
Thanks for the list. Btw. there is only one version of BD+ but each disc can have a unique content code. Every time a content code doesn't run properly on SlySofts emulator they just call it a new version of BD+ but it's not. :rolleyes:

Accident
28th November 2008, 01:12
Anyone able to upload the SVMs of those non-working disks? Top two looks to be most important :)

SixKiller
29th November 2008, 06:05
I`ve got X Files 2 EU laying right here. So what do you need exactly ? I'll upload it.

loo3aem3ON
29th November 2008, 16:44
I`ve got X Files 2 EU laying right here. So what do you need exactly ? I'll upload it.
We need the contents of the BDSVM directory (without the BACKUP subdirectory). If any more data is required we will ask you for it.

Thank you for your support.

kkloster21
29th November 2008, 21:43
i have Firefly the series on blu-ray. how can i send you the BDSVM directories (for each disc)?

SixKiller
29th November 2008, 22:57
Ok so i uploaded this to rapidshare. http://rapidshare.de/files/41026609/xfiles_java.rar.html

Hope you can use this .

Greets

loo3aem3ON
30th November 2008, 00:49
Hope you can use this.
Thank you. I am getting a conversion table which means the key set is accepted. The segment keys are wrong though this is usually due to bugs or more likely in this case the wrong SHA-1 hashes of the files i don't have:
[I] TRAP_MediaSHAFileHash: Hashing AACS/MKB_RO.inf
[I] TRAP_MediaSHAFileHash: Hashing BDMV/STREAM/00008.m2ts

Please try to run the content code in the debugger: DVM Debugger v0.1.3 (http://uploaded.to/?id=j4gz5m).
I am confident that you will get the correct conversion table. You can test it's integrity using ConvTableView which is available from the Dump HD thread.

And it's not java opcode (like your filename suggests you think it is) but DLX like opcode. The content code runs on a DLX like processor. This processor is simulated by our emulator which is implemented in java. Accident has implemented the same emulator in C which runs several times faster.

yippiekayee
30th November 2008, 02:58
I'm not sure if this needs to go into the dumphd thread or this but I've been trying out the bdvmdbg today and ran into some trouble:
I got the conversion table for Prison Break Season 3 Disc 1.. and got no special errors during the process
$ Volume ID set to: 90 BB 43 94 DC C6 50 05 54 FE 96 16 96 07 DE 66
Loading E:\/BDSVM/00000.svm ...
[I] TRAP_LoadContentCode: Loading BDSVM/00001.svm (block 6)
[I] TRAP_DebugLog: 2008-11-01 01:43:11.21 playback starts
[I] TRAP_MediaSHAFileHash: Hashing BDSVM/00000.svm
[I] TRAP_MediaSHAFileHash: Hashing AACS/MKB_RO.inf
[I] TRAP_MediaSHAFileHash: Hashing BDMV/STREAM/00004.m2ts
[I] TRAP_LoadContentCode: Loading BDSVM/00001.svm (block 7)
[Event #00000000] 0110 ( 00000000, 0000FFFF )
[Event #00000001] 0210 ( 00000000, 00000001 )
[W] TRAP_DeviceAccess not implemented!
[Event #00000002] 0110 ( 00000000, 00000001 )
[I] TRAP_LoadContentCode: Loading BDSVM/00002.svm (block 0)
Conversion table set

Then I ran DumpHD and it decrypted the file 00001.mt2s just fine as far as I can tell (cursory browsing through the file - by the way, what's the recommended way of quickly checking the decrypted results? can I run md5sums on the Streams directory and compare it with the Streams directory directly on the disc when I have AnyDVD HD running?).
Anyway, DumpHD reports some potential problems
0x0000000000 Decryption enabled
Processing: BDMV\STREAM\00001.m2ts
Error! BD+ SubTable not found, dumping may fail
0x0000000000 Decryption enabled
Processing: BDMV\STREAM\00002.m2ts
Error! BD+ SubTable not found, dumping may fail
0x0000000000 Decryption enabled
Processing: BDMV\STREAM\00004.m2ts
Error! BD+ SubTable not found, dumping may fail
0x0000000000 Decryption enabled

and sure enough the second file is corrupt (this is a series so there's one m2ts file per episode.. there are 4 eps on a disc).. it starts out okay but about 20 seconds in things start to look really bad (reminds me of encrypted DVDs). Since the first file is okay I suspect it has something to do with the episodic nature of the disc.

I loaded the convtable into ConvTableView and it can successfully load the table.

more likely in this case the wrong SHA-1 hashes of the files i don't haveWould it help if he ran sha1sum on those files for comparison? I doubt uploading m2ts files is practical.

yippiekayee
30th November 2008, 03:23
Umm... I think there's a problem with Die Another Day (US).. on the right hand side of the debugger I see some stuff marked in red, though the console output doesn't contain any errors / warnings. The convtable is a lot smaller than my previous ones (592KB instead of almost 1 MB) - convtableview loads the table just fine but there's a lot of emptyness there. I'll post again when the decryption process is through.

loo3aem3ON
30th November 2008, 03:44
I'm not sure if this needs to go into the dumphd thread or this but I've been trying out the bdvmdbg today and ran into some trouble:
It's probably my fault so it's correct to report the problem in this thread.

by the way, what's the recommended way of quickly checking the decrypted results?
I use 'vbindiff' to compare with the result AnyDVD-HD produced. Using md5sum is faster if you only want to check if the files are (still) identical after making changes as developer.

can I run md5sums on the Streams directory and compare it with the Streams directory directly on the disc when I have AnyDVD HD running?).
Yes but you should use a program which shows differences between both files if you have reasons to believe they are different. You can for instance use WinHEX.

Anyway, DumpHD reports some potential problems
Those error messages say that the conversion table doesn't contain entries for all the files you have on disc. It most likely means that either the conversion table is corrupt (which you would have noticed with ConvTableView) or you are using the wrong conversion table. Is it possible that you are using the conversion table from a different movie?

Are you running dumpHD from command line like this example below?
/dumphd-0.5/dumphd.sh --infile:BDMV/STREAM/00001.m2ts --convtable:conv_tab.bin /media/cdrom/ > /tmp/00001.m2ts

and sure enough the second file is corrupt (this is a series so there's one m2ts file per episode.. there are 4 eps on a disc).. it starts out okay but about 20 seconds in things start to look really bad (reminds me of encrypted DVDs).
That's because dumpHD can't repair those m2ts files if it can't find the subtable for the file you would like to restore (AACS decrypt and BD+ repair).

I loaded the convtable into ConvTableView and it can successfully load the table.
Upload the conversion tables please. I would like to take a look at them.

Would it help if he ran sha1sum on those files for comparison? I doubt uploading m2ts files is practical.
There is no need to do that because TRAP_MediaSHAFileHash should be working fine if you have a original encrypted disc. Just make sure AnyDVD-HD is switched off while you create the conversion table.

Umm... I think there's a problem with Die Another Day (US).. on the right hand side of the debugger I see some stuff marked in red, though the console output doesn't contain any errors / warnings.
Those are the registers which have changed. Don't worry about that.

The convtable is a lot smaller than my previous ones (592KB instead of almost 1 MB) - convtableview loads the table just fine but there's a lot of emptyness there. I'll post again when the decryption process is through.
I have recently introduced code which removes bogus repair descriptors. It might be possible that a bug causes the removal of valid descriptors.

yippiekayee
30th November 2008, 04:20
Is it possible that you are using the conversion table from a different movie? No.. it's the right file.. the first of the four episodes is properly decrypted all the way through.. I jumped around the entire 4x minutes and haven't found a glitch.
Are you running dumpHD from command line like this example below?Well I'm on windows but here's a sample commandline (http://forum.doom9.org/showthread.php?p=1218522&posted=1#post1218522). Note that the same procedure has worked for two previous movies (Day after Tomorrow and Hitman).


In the meantime I'm done with Die Another Day and at first glance the decrypted output seems to be fine. DumpHD reported no issues and in jumping around the movie I have yet to discover a corrupted part.

I will compare the decrypted output with the files on the disc when I have AnyDVD HD active.

Are you interested in knowing which discs decrypt okay? I have a sizeable collection (by my count 19 from the list of Fox/MGM discs posted here (http://forum.doom9.org/showthread.php?t=140893) though I'm not convinced every one is really a BD+ disc.. plus two titles are actually series so they have 4/6 discs respectively) and if it helps I can run them all through and compare with AnyDVD HD.

yippiekayee
30th November 2008, 15:33
Yes but you should use a program which shows differences between both files if you have reasons to believe they are different. You can for instance use WinHEX.Could you elaborate on this a bit.. how would I go about doing that and what kind of information would you need to see? I just finished Dr. No and compared sh1sums (I'm back to md5sums now.. it seems to run faster plus it has a progress indicator which is good for impatient people like me).. most files seem to be the same.. there are 6 files (6 KB each) which differ and I'd like to get to the bottom of this.

The same also holds for Live and Let Die.. only that on that disc the difference are 36KB files.

By the way, is it enough to compare the Streams directory or are there other files protected by BD+?

loo3aem3ON
30th November 2008, 16:31
Could you elaborate on this a bit.. how would I go about doing that and what kind of information would you need to see?
Slow down please. I am currently writing a few functions which record the hashes returned by TRAP_MediaSHAFileHash. You will have to run this new version of the debugger once with "Prison Break" and then send me the file "hash_db.bin" it has created.
I believe there is a problem with the callback parameters (event management) and i need the hashes to fool the content code.

Below is the structure of the hash_db.bin in EBNF. Accident will probably want to add support for it. We could include the volume id.
*edit* removed. See posting #480 (https://forum.doom9.org/showpost.php?p=1219113&postcount=480) *edit*

After this issue is fixed we can take a look at the other problems.

I just finished Dr. No and compared sh1sums (I'm back to md5sums now.. it seems to run faster plus it has a progress indicator which is good for impatient people like me).. most files seem to be the same.. there are 6 files (6 KB each) which differ and I'd like to get to the bottom of this.
I would need to see what bytes differ in both files so a hash is useless to me. The conversion table is used to repair the m2ts files. If any other files differ please contact KenD00 who maintains DumpHD.

yippiekayee
30th November 2008, 17:09
I would need to see what bytes differ in both files so a hash is useless to meJust tell me how I can show you that. You suggested Winhex which I installed but I don't really know what to do with it. The files are very small so I suppose I could just upload them for you in this case as well as the convtable but suppose I see a difference in a larger file.. I cannot upload a file that spans multiple GBs.

bugnotme
30th November 2008, 17:33
I don't have access to any device that contains the private exponent. If i had one i wouldn't be sitting here writing postings ;)
Those certificates are probably created on a pc without a network connection to rule out any side channel attacks.

He wasn't highlighting the timing attack but the use of
Coppersmith's algorithm -- a low-exponent attack on RSA --
after the upper half of the bits had been determined by the
timing attack.

Since you claim the upper half bits have been obtained the method
described in the article should be directly applicable. However, I do
not think knowing the upper half bits is necessary in order to apply
Coppersmith's algorithm. I'm also unclear about how knowledge of the
upper half bits can be exploited in order to speed-up the algorithm.

Coppersmith's algorithm is implemented as zncoppersmith in PARI/GP,
coppersmith in Sage and elsewhere.

http://groups.google.com/group/sage-devel/browse_thread/thread/96b4f37e8be967fe/190c9b2a9e8d22ee?hl=en&lnk=gst&q=coppersmith's#190c9b2a9e8d22ee

loo3aem3ON
30th November 2008, 18:33
He wasn't highlighting the timing attack but the use of
Coppersmith's algorithm -- a low-exponent attack on RSA --
after the upper half of the bits had been determined by the
timing attack.
Why would i start a timing attack if i can easily calculate the upper half of the private exponent from the public key (e,N) like i did? I've tried to explain why those bits are most likely useless to factor N. A timing attack can be used to obtain some of the least significant bits. With them N can be factored efficiently.

Just tell me how I can show you that.
Download this snapshot please: http://uploaded.to/?id=7yht2d
Run it once with Prison Break and send me the hash_db.bin and the contents of the BDSVM directory (without the BACKUP subdirectory). That's all i need currently. Before running verify that the hash_db.bin has zero length. Thank you.

haggi
30th November 2008, 19:10
He wasn't highlighting the timing attack but the use of
Coppersmith's algorithm -- a low-exponent attack on RSA --
after the upper half of the bits had been determined by the
timing attack.


But to use this algorithm you need to know the upper half of p or q not the upper half of d, which is what we've got ... :(

yippiekayee
30th November 2008, 21:00
I'm afraid the new version didn't do the trick either. Same errors from dumphd and while the first episode is again properly decrypted, subsequent episodes aren't.

And I did compare the last three of my Bond discs - which played just fine but there are again small files where the md5sums differ. I also watched ripped Hitman today and watched the main movie.. it was glitch free but I haven't yet compared md5sums with AnyDVD.

bugnotme
30th November 2008, 21:06
Why would i start a timing attack if i can easily calculate the upper half of the private exponent from the public key (e,N) like i did? I've tried to explain why those bits are most likely useless to factor N. A timing attack can be used to obtain some of the least significant bits. With them N can be factored efficiently.


Forget timing attacks. The point is Coppersmith's algorithm is a
potentially useful low-exponent RSA attack.

bugnotme
30th November 2008, 21:21
But to use this algorithm you need to know the upper half of p or q not the upper half of d, which is what we've got ... :(

Chapter 6 of this PhD thesis seems pertinent:

http://www.informatik.tu-darmstadt.de/KP/publications/03/bp.ps

yippiekayee
30th November 2008, 21:32
how can i send you the BDSVM directories (for each disc)? Zip them up and upload to a file hoster like rapidshare, uploaded.to, etc and post the link here.

haggi
30th November 2008, 22:05
Chapter 6 of this PhD thesis seems pertinent:

http://www.informatik.tu-darmstadt.de/KP/publications/03/bp.ps

e ∈ [N^(0,5); N^(~0,72))

Our e is 3 which is smaller, much smaller, than N^(0,5)

I am not mathematician enough to know how to alter that equation to suit our needs.

yippiekayee
30th November 2008, 22:59
I just ripped the second disc of Prison Break Season 3. Got the same error about BD+ subtable not being found, but this time only for the episodes... subsequent m2ts files didn't yield the error and the first episode (first m2ts file) was okay again - so I think this is something systemic.. has the BD+ code ever been tested against episodic discs?
This brings me to a question: how can we verify the debugger against titles with MKB versions for which we don't have a processing key yet? Firefly is in the mail but afaik it's MKBv9.. AnyDVD HD can handle that but not the BD+. So, since DumpHD won't be able to decrypt those discs without the processing key is there a way to apply the BD+ removal without doing AACS encryption so that we could first remove BD+, then run AnyDVD HD on it to remove AACS and the verify if the output is correct.

loo3aem3ON
30th November 2008, 23:26
I just ripped the second disc of Prison Break Season 3. Got the same error about BD+ subtable not being found, but this time only for the episodes... subsequent m2ts files didn't yield the error and the first episode (first m2ts file) was okay again - so I think this is something systemic.. has the BD+ code ever been tested against episodic discs?
The problem is the debugger only announces the playback of the first m2ts file to the content code and therefor only gets this portion of the conversion table. It's the largest conversion table i have seen so far which is probably why it was split. I need to rewrite some code to handle this properly.

This brings me to a question: how can we verify the debugger against titles with MKB versions for which we don't have a processing key yet?
AnyDVD-HD will support these titles soon.

is there a way to apply the BD+ removal without doing AACS encryption so that we could first remove BD+, then run AnyDVD HD on it to remove AACS and the verify if the output is correct.
Maybe you have heard of "confusion" and "diffusion" which are properties of every serious encryption algorithm. In our case the "diffusion" property of AES would cripple the entire 128-bit block if you only change a single bit before decryption. I see no way to modify the encrypted stream so that the decryption result is already repaired (without knowing the key of course).

yippiekayee
30th November 2008, 23:55
Oh, I thought BD+ came before AACS, not after. But in this case, if there was a simple BD+ repair program we could fix the stream after decryption by AnyDVD, correct?

loo3aem3ON
1st December 2008, 01:23
Oh, I thought BD+ came before AACS, not after. But in this case, if there was a simple BD+ repair program we could fix the stream after decryption by AnyDVD, correct?
Yes, that is correct.

Try this development snapshot please: http://uploaded.to/?id=ij27kc
I still don't understand the second parameter of callback/event 0x0110 but i know this event occurs before the playback of every m2ts file. So i decided to issue event 0x0110 with the second parameter with all possible values between 0 and 50 to get all the pieces from the conversion table. It seems to work. The resulting conversion table for "Prison break" is 4MB big. ;)

loo3aem3ON
1st December 2008, 19:15
I've redesigned the hash database. It now supports multiple hashes created from a single large block. It's implemented as a chained list which is fast enough for those few entries we have. The structure is:
key = SHA-1 hash of offset, bytesToHash and Filename; 20 bytes
nextPointer = points at the beginning of the next entry; relative address; 4 bytes
bytesHashed = number of bytes used to calculate the hash; 4 bytes

database ::= {entry}
entry ::= key , nextPointer , bytesHashed , {hash}
The reason to create such a database is that the content code uses hashes from arbitrary files on the disc. If a bug prevents the correct creation of the conversion table the developers have problems reproducing the error given only the contents of the BDSVM directory. Because the hash database already contains the hashes the content code likes to verify this is no longer a problem. All the user needs to do is clear the hash_db.bin (e.g. create an empty file with that name) and run the debugger once. The resulting hash_db.bin is then to be sent to a developer.

KenD00
1st December 2008, 19:31
I have also uploaded the files that differ between AnyDVD and DumpHD from Dr. No (US)<link removed>..


Hmm, for some reason AnyDVD zeroed out the end of file 00091.m2ts, but this part looks the same as in the other files, TS packets with mostly FF as content, and the file itself isn't encrypted.

The other files are encrypted and it looks like DumpHD failed to process them. I assume this disc has multiple CPS Units and these files don't belong to CPS Unit 1. In the log of DumpHD should be written something like "Updated Disc data" with a section UM's which has entries which look like <number>[H]-<number>, is there any entry where the second number is not 1? Currently DumpHD can't process discs with multiple CPS Unit keys, maybe because of that your episodic discs don't decrypt properly too.


Those error messages say that the conversion table doesn't contain entries for all the files you have on disc. It most likely means that either the conversion table is corrupt (which you would have noticed with ConvTableView)

But this situation may be perfectly legal too. My observation was that there is a subtable for every file on the disc, but for the files which are not BD+ encrypted these subtables were empty. Maybe its allowed to ommit them in that case?

:rolleyes:

yippiekayee
1st December 2008, 20:09
@Kend00: I didn't keep the logs when I finally shut off my PC last night.. do I have to re-rip everything or will ripping just the files in question do to get the info you need?
Also, any chance for a commandline parameter in DumpHD to do this academic scenario (just fix files with a convtable and not doing any AACS decryption)? That way we could check the debugger against the latest BD+ discs while we wait for a suitable processing key to leak.

yippiekayee
1st December 2008, 20:35
Alright, I started ripping Dr.No again.. here's parts of the output:
Processing disc AACS data...
Volume Unique Key / Protected Area Keys present, decrypting Title Keys / CPS Uni
t Keys...
Searching Title Key / CPS Unit Key Files...
Decrypting e:\AACS\Unit_Key_RO.inf...
Finished decrypting CPS Unit Keys
Updated disc data:
DiscID : 413AF6BB6AF86146B922DCF83D5CF2F6E29EDC8D
Title : Movie Title
Date : 2008-08-14
MEK : N/A
VID / BN's : N/A
VUK / PAK's : 1
0-848FF6607D25510284F0A41ACE852E39
TUK's : 7
1-31D6B69028A16F7544189A1EB7E19D0B
2-85581552DC02679109AF39A4EA5077EB
3-68310D990568522BED70E07295603414
4-FA6FCBC562152AFF69A45FDB064A12B0
5-B409D918375AD199E6984ACE81260BD5
6-BF155D839EEEBFF61609DCF836DFEF6E
7-7F4E414F2EFBB9380507868FA92B14A5
UM's : 1
Set 0
0H-1
1H-1
1-1
2-1
3-1
4-1
5-1
6-1
7-1
8-1
9-1
10-1
11-1
12-1
13-1
14-1
15-1
16-1
17-1
18-1
19-1
20-1
21-1
22-1
23-1
24-1
25-1
26-1
27-1
28-1
29-1
30-1
31-1
32-1
33-1
34-1
35-1
36-1
37-1
38-1
39-1
40-1
41-1
42-1
43-1
44-1
45-1
46-1
47-1
48-1
49-1
50-1
51-1
52-1
53-1
54-1
55-1
56-1
57-1
58-2
59-2
60-2
61-2
62-2
63-2
64-2
65-2
66-3
67-3
68-3
69-3
70-3
71-3
72-3
73-3
74-4
75-4
76-5
77-5
78-6
79-6
80-7
81-7
Sequence Key Block not found (this is good)
AACS data processed

Anything I can do to help to handle those cases? And no, Prison Break only has 1's on the right hand side of the output.

Also, I did test the latest dev build of the debugger and I managed to make a successful rip of the entire disc. I'm now going to rip again using AnyDVD HD and then compare files then proceed to the second disc of the set.

SuperGoof
1st December 2008, 20:39
Currently DumpHD can't process discs with multiple CPS Unit keys

I suggest using Blu-ray Disc Ripper (http://forum.doom9.org/showthread.php?t=129663). It supports multiple CPS Unit keys for about a month now (since v.1.4). I just read the list of CPS Unit keys from Unit_Key_RO.inf, decrypt them, and on the first encrypted block of each .m2ts I try them in turn until I find one which results in correct decryption. (I just check for 16 byte long block of FFFFs within the first 512 bytes of the file :)). And even before doing that, I check if FFFFs are already there, which means that the file is not encrypted at all.

But this is for AACS decryption only, of course. This program does not support BD+ at all yet.

js06078
1st December 2008, 22:42
So, to sum up the results of the recent tests in this thread:

The newest development snapshot of the debugger handles the James Bond movies fine (the remaining problem with the small files on James Bond movies is due to AACS-CPS Unit Keys and not due to BD+), and it also handles Prison Break S03 fine?

This means, that the debugger succeeds even on the newest versions of BD+ content code that also AnyDVD-HD can handle (bringing the open source capabilities up to par to AnyDVD-HD with respect to BD+).

Also, X-Files 2 can not be decrypted by AnyDVD-HD, but the debugger still outputs a conversion table for it. However, this conversion table could still be bad: I took a look at the file, and it contains sub-tables for most of the first 25 .m2ts-files, meaning, that the main feature is split over those files. However, many of the conversion-table segments for these files are empty. Together with the fact, that the non-empty segments do NOT contain descriptors for the 'missing' segments of these files, we can deduce, that either large portions of the files from X-Files 2 are not protected by BD+, or that the created conversion table is not complete and in fact missing segments which are needed for decryption.

So it would be interesting to see, whether it is possible to repair X-Files 2 using the created conversion table. Could someone with the original disc give it a try?

Also I am wondering: If the debugger should really already create a more or less correct conversion table for X-Files 2, why is Slysoft needing so much time to fix their BD+ treatment?

bourke
1st December 2008, 23:57
Also I am wondering: If the debugger should really already create a more or less correct conversion table for X-Files 2, why is Slysoft needing so much time to fix their BD+ treatment?

Perhaps they thought it would be easier just to 'borrow' ideas from this thread - and/or their lead developer is away on annual leave?!

KenD00
2nd December 2008, 00:04
@yippiekayee
You don't need to rip the whole disc or even a whole file, just press the Dump button, then the AACS data gets processed, when the first file gets processed you can abort.

Your log shows indeed multiple CPS Units so this explains the broken files. Currently you can't do anything about it, but you can test the new DumpHD release which will address this, i just don't know when it will be finished.

You can already remove BD+ only, already AACS decrypted files won't get AACS decrypted a second time, but BD+ will get removed. Take your AACS free but BD+ infested rip, copy the AACS folder of the original disc into it, start DumpHD with a conversion table and BD+ will get removed :).

@SuperGoof
I have seen your "brute force" approach to determine the key, i was looking for a better way but unfortunately found no other way than analysing all MovieObjects/Playlists/BDJ-Objects so i will copy your approach :). But i think i won't look for these FFFF's (do you know why they are there and if they always have to be there?), i will check for the TS packet headers. To check if the file is encrypted you can look at the 2 highest order bits of the TP_Extra_Header, if not 00b then the file (Aligned Unit, on BD recordables the encryption state may change inside a file) is encrypted.

:rolleyes:

loo3aem3ON
2nd December 2008, 00:11
This means, that the debugger succeeds even on the newest versions of BD+ content code that also AnyDVD-HD can handle (bringing the open source capabilities up to par to AnyDVD-HD with respect to BD+).
The content code consists of multiple components (startup code, code specific to [player or movie or ( player && movie)], conversion table code...). It's quite a complex piece of software which can fingerprint the player at startup and then select code specific to that player to be executed. So you can't really compare our achievements with those of SlySoft unless the debugger/libblueray and AnyDVD-HD emulate the same player and are therefor executing the same code.

Also, X-Files 2 can not be decrypted by AnyDVD-HD, but the debugger still outputs a conversion table for it. However, this conversion table could still be bad:
The content code will only produce a conversion table if all security checks passed. If you don't see any warnings loading the table in ConvTableView v0.2 then it was almost certainly correctly decrypted. Empty subtables are fine because not all m2ts files are usually corrupted. If subtable x is nonempty then the file x.m2ts was damaged by BD+ and needs to be repaired using that subtable.

Also I am wondering: If the debugger should really already create a more or less correct conversion table for X-Files 2, why is Slysoft needing so much time to fix their BD+ treatment?
Maybe they emulate a different player and have to execute real nasty security checks. The conversion table may also contain repair descriptors which don't do any repairs at all. Instead they insert invisible marks (watermarks) in the decrypted stream which can contain all kinds of information (player id, any data from memory...). The existence of this marking scheme has not been publicly proven yet but i believe it exists. It's are also mentioned in descriptions about spdc which is fairly similar to BD+. So this is something SlySoft might be battling currently. It's probably easily defeated if an attacker has access to multiple different players.

yippiekayee
2nd December 2008, 00:19
So you can't really compare our achievements with those of SlySoft unless the debugger/libblueray and AnyDVD-HD emulate the same player and are therefor executing the same code.So, does that mean that my idea of running the debugger of all my BD+ titles and comparing the output with AnyDVD HD makes sense and I should go ahead (seeing as the process is tedious of it's unnecessary I wouldn't mind - on the other hand, since the process is tedious and may be too complex for people who could potentially help, I'd be happy to contribute something that I can do).

@Kend00: let me know when you're ready.. my discs won't go away and I just ordered the other three Bond discs (the quality of Dr. No really surprised me so I'm game for the old titles). And thanks for the info on processing BD+ without processing AnyDVD.. as soon as Bender's game and Firefly get here I'll run them and report the results.

P.S. The results from disc 2 of prison break look okay, too.

loo3aem3ON
2nd December 2008, 00:37
So, does that mean that my idea of running the debugger of all my BD+ titles and comparing the output with AnyDVD HD makes sense and I should go ahead (seeing as the process is tedious of it's unnecessary I wouldn't mind - on the other hand, since the process is tedious and may be too complex for people who could potentially help, I'd be happy to contribute something that I can do).
Your idea is good and i use the same method to verify the correctness of the conversion table. But to be honest i don't like to see the debugger/libblueray compete with AnyDVD-HD so if you do that in a few months it's fine but not before AnyDVD-HD adds support for these movies. In the meantime you could check if you find a movie for which libblueray is creating a different conversion table than the debugger. Thank you for your support.

yippiekayee
2nd December 2008, 00:57
In the meantime you could check if you find a movie for which libblueray is creating a different conversion table than the debugger.Is there a Windows binary/frontend of libblueray available somewhere?

Accident
2nd December 2008, 01:08
The source tarball contains Windows built binaries for those not setup with MSVC++.
libbluray-0.0.6.tar.gz (http://uploaded.to/?id=3rst84)

To run Jumper, I would run:


win32/# convtab.exe -d jumper/ -i jumper/volume_id.bin -s jumper_conv_tab.bin -v 64
[snip]
[segment] Key 5, 0: 629E6A71B7756200989C7DE66A352D5D mask:0E950C808FA5F6A2
[snip]

-rw-r--r-- 1 owner group 1035732 Dec 2 09:05 jumper_conv_tab.bin

Assuming there is a "jumper/" directory with "jumper/BDSVM/" files etc.

bugnotme
2nd December 2008, 02:49
e ∈ [N^(0,5); N^(~0,72))

Our e is 3 which is smaller, much smaller, than N^(0,5)

I am not mathematician enough to know how to alter that equation to suit our needs.

There are other results in the document which might be useful directly
or point to useful results. Theorem 51-4 on page 99 for instance. That
requires 3/4 of the bits of d, and the difference between p and q to be
big enough.

yippiekayee
2nd December 2008, 20:00
@Accident: is there a documentation of the commandline options somewhere? I cannot get it to work.
I looked at the readme and I think there are the following options:
-d: the source (full path? e.g. e:\ or just the drive letter or what?)
-i: file containing volume id (full path necessary or is it relative to the path from which the application has been started)?
-I: volume id string.. to be used instead of -i
-f: ??
-s: convtable file for the output (full path necessary or relative?)
-v: ??

The program runs and seems to do something but I'm unable to locate the output and there's no return value either.

Here are some commandlines I've tried:
convtab.exe -d e: -I 83569CAE3EEC6ADB278514D894D103B8 -s c:\temp\conv_tab.bin
convtab.exe -d e:\ -I 83569CAE3EEC6ADB278514D894D103B8 -s conv_tab.bin
convtab.exe -d e: -i volume_id.txt -s conv_tab.bin

I've also tried convtab -h, convtab --help convtab -? and replacing - with / in an attempt to get some help but with no results.

update: I finally located the source code and had a look.. sure enough there is a help but it doesn't work.. so something went wrong during compilation. I found that the program seems to do something (use a lot of cpu time at least) if I run it with -d and point it to someplace that has a BDSVM folder, but there's no output whatsoever neither in the console nor in any file.

yippiekayee
2nd December 2008, 23:19
I'm afraid calling Prison Break solved was premature. Since I couldn't run convtab.exe I went ahead with the checksum checking and I have some good news first:

Prison Break Season 3 Discs 1-3 are bit identical with the AnyDVD HD output. The same can be said for
Day after Tomorrow (US)
Hitman (US)
Stargate: Continuum (US)

However, on disc4 of Prison Break Season 3, I get the BD+ subtable not found error again. Here's the link to the BDSVM folder (http://rapidshare.com/files/169650384/PB-s3d4.7z.html) along with the convtable and list of files for which the error occurs. Interestingly though, I compared md5 hashes of all files and the only file where I had a difference in the hash was 00000.m2ts which is the file that contains the single episode on that disc (the rest is extras).. and I cannot play that file at all.

I'm still investigating why from my 3 Bond movies, I can play Die Another Day from the ripped copy despite some undecrypted files whereas I cannot get Dr. No and Live and Let Die to work from the ripped copy (but they work when played from the disc).. I'll check if TMT plays the files from any AnyDVD HD decrypted copy.. if it does, I presume that it's just a matter of using the upcoming DumpHD which supports multiple CPS'es.

Accident
3rd December 2008, 13:37
# convtab.exe -h
options:
-h : display usage help (this output)
-v <int> : enable verbose debug information, 0 to list levels
-d path : specify path to find /path/BDSVM and /path/STREAM/
-s file : specify filename of conv_tab.bin
-i file : specify filename of VolumeID
-I id : directly specify VolumeID
-f file : specify filename of flash.bin
-F : save flash.bin at the end
-t title : specify title of file specified with -u & -U
-u file : directly patch file from conv_tab.
-U : patch stdin to stdout


volume_id.bin (-i), and flash.bin (-f) are loaded first from CWD. Then it chdir() to the -d path. (absolute or relative), All BDSVM, STREAM etc files are opened from -d path POV.
Once finished, it will return to CWD, and write conv_tab.bin (-s) and flash.bin (-fF).

It should be valid to do:


# convtab.exe -i data_files/volume_id.bin -d e:/ -s output/convtab.bin

yippiekayee
3rd December 2008, 19:32
@Accident: that's exactly what I found by browing through the source code but I'm afraid the windows binary you posted does nothing like that.. it just doesn't return any output, be it as a file or via stdout/stderr. Did you actually try out your compiled version? All your commandlines look line Linux commandlines.. so it may be prudent that you try any software for distribution on a native windows system.. While I have compilers in place.. native C++ isn't one of the options I install with Visual Studio so I'm afraid I need a fully tested and working Windows version or I cannot be of any assistance as far as libbluray is concerned.

loo3aem3ON
3rd December 2008, 20:06
@Accident: that's exactly what I found by browing through the source code but I'm afraid the windows binary you posted does nothing like that.. it just doesn't return any output, be it as a file or via stdout/stderr.
Are you running this in cygwin or in the windows command prompt? In the later case please try cygwin.

Regarding your problem with Prison Break Season 4: The conversion table in your archive is from another disc (disc 1?) and you didn't include the hash database. The conversion table created by the content code (BDSVM directory contents you've included) looks fine though. It's probably KenD00's fault that you can't playback the 00000.m2ts :p

dirio49
3rd December 2008, 22:36
nothing to do with cywin
something is wrong with the compiled exe
the previews version run fine,
i just test on the files provided here.

OOPS, I spoke too soon.
it appears to fail for me a least, going by what is available here, because it cannot handle this disk.
it give no console output at all, it just blanks out
on the other alvailabe download that i could find it worked fine

BTW
Accident how do you compile it in linux?
there is not configure files.
i tried autoconfig and automake and no success.
unless I am doing something wrong
thanks

KenD00
4th December 2008, 02:39
It's probably KenD00's fault that you can't playback the 00000.m2ts :p
That can be easily checked by opening the file in a hex editor (but make sure that it doesn't create a backup file when opening :D) and checking if every 0xC0 bytes (well, a couple should be enough) a 0x47 is written, or a bunch of 0xFF and a HDMV at the bigging of the file are OK too :).


i tried autoconfig and automake and no success.
unless I am doing something wrong
thanks
There are Visual Studio Project Files inside win32\libbluray. I have tested the precompiled convtab and it produces a Conversion Table for Die Hard in 1 second and one for Jumper in 20 seconds for me (thats strange, why does Jumper take so long, its almost as slow as the Debugger).

:rolleyes: