Log in

View Full Version : Weird menu/buttons in Dark Knight


MorbidPenguin
3rd January 2009, 15:09
Just as I thought I was starting to get PGCEdit figured out, I tried editing the Dark Knight.

First thing that popped up was a warning that the speed of the first VGM was illegal and it was changed to NTSC 30 fps.

Then I open up the first menu I see (36 buttons) and I get this, which doesn't show anywhere on the DVD. What should I do with this?

http://images.dr3vil.com//files3/245/PGCEdit_DarkKnight_Menu1.jpg

M_Knox
3rd January 2009, 15:44
As far as I remember, this menu is there just to fool the rippers, be it automatic or those with the brain :)
If you search for references to this menu you'll find out, that there are several invisible buttons on real menus that lead to it. Just clean them and delete this fake menu when it's not referenced anymore.

MorbidPenguin
3rd January 2009, 15:55
Cool.

So... if I right-click on that PGC and choose "Go to Calling command" I get a list of buttons that reference that command. All I have to do is hide those buttons, then delete the PGC and I'm good to go?

Wombler
3rd January 2009, 16:30
I haven't got that disc yet but try using 'Remove Useless Stuff' (accessed via the DVD menu) on it first and see what you're left with.


Wombler

MorbidPenguin
3rd January 2009, 16:41
Nope, still remains there after removing useless stuff. I imagine it's because there are 12 buttons on the other menus that call it (these buttons are very small and I was unable to find them/mouse over them in MPC).

jinjin_jp
3rd January 2009, 16:46
This is very curious. I confirmed by PgcEdit.

This Menu is jumped from button 4 of main menu, button 11 of 1st/2nd chapter menu, button 10 of 2rd chapter menu, and button 7 of audio/subpicture menu.
All buttons seem not to be selected button's up/down/right/left, it must be directly selected by number.

In this menu button, 1 to 5 are effective other(6 to 36) button's command is all "NOP".
5 effective button each jumps to VTSM 4 to 8.

At first I thought it is similar to Easter Egg.
But VTS 4 to 8 have problem and seems to be removed when ripping.
I think it means VTS 4 to 8 have possibility to be playable.
Actually I confirmed by trace mode to be replayed this menu, but stop after it because there is nothing to be replayed(VTS 4 to 8).

So I confirmed original DISC and DVD player.
The result was; I can't selct buttons which jumps to this menu. It seems to be by PUOs, because player show "this operation is prohibitted by DISC".

Thanks for introducing curious topic.

Regards.

r0lZ
3rd January 2009, 17:24
M_Knox is right. Obviously, this menu is a pathetic attempt to fool the rippers.

The theory is simple.

All recent protections such as ARccOS or RipGuard are based on illegal stuff or read errors in some cells. Those errors are sufficient to confuse the traditional rippers. But they are also sufficient to confuse the players! Therefore, the errors must be located in PGCs or cells that can never be played. The navigation of the DVD must skip those parts.

The modern rippers have implemented a way to locate the potentially protected areas. They simulate the navigation (exactly like the PgcEdit trace) and explore all possibilities. The areas that have never been visited at the end of the exploration are highly suspect.

Some buttons of the strange menu in this DVD lead directly to the protected material. And there are hidden and unselectable buttons in the normal menus that can theoretically be used to jump to this strange menu. Therefore, if the ripper is not smart enough, it will think that the menu can really be played, and consider the protected areas as normal areas. Of course, it will probably fail when attempting to rip those areas the normal way.

I'm sure the authors of the rippers have found a way to discover when a menu button cannot be operated by the user. As jinjin_jp said, they are not selectable with the remote, and cannot be numerically activated. Conclusion: they are fake buttons, and everything behind them is probably a protected area. Simple!

I don't know what ripper you have used, but IMO it should have removed the hidden buttons, for security reasons. Most of the time, the rippers remove the PUOs, and the hidden buttons can become callable!


So, MorbidPenguin, the method to get rid of this crap explained by M_Knox is correct. Select the fake menu, find all references to it, and remove them. (You don't even need to hide the menu buttons, as they are already hidden. Just be sure to replace the command by, for example, a NOP. But hiding the buttons has the same effect.) Then, use Find Uncalled PGCs to verify if the PGCs that are not called any more are really in protected areas, and delete them (using Delete Uncalled PGCs or Remove Useless Stuff.)

Verify also if there are no Jumps To Nowhere, as if the ripper has not made a good job, it could have removed some protected PGCs that are still called. Remove also those commands.

MorbidPenguin
3rd January 2009, 17:34
Went through and deleted the calling commands, then ran "Delete Uncalled PGCs" and it picked it up and deleted it right away! Will save and test, but it seems like everything should be good to go. Thanks! I love this program more and more!

Ripper I used was the latest version of AnyDVD, which was just updated 2 days ago, I think. Load it up, Rip Video to harddisk. Occasionally I use CloneDVD, but it doesn't seem to do much different from AnyDVD (except from being able to rip specific streams).

r0lZ
3rd January 2009, 17:48
AnyDVD should be good enough, but be sure to NOT patch the navigation on the fly. AnyDVD can modify the IFOs when they are loaded, for example to remove the PUOs or jump directly to the main movie. However, it does that without analyzing the navigation too much, and that can have disastrous consequences. That's not really important when you play the original DVD, but it is better to avoid that when you rip it!

Honestly, I haven't used AnyDVD since the last ice age, and I don't know if its ripper takes the configuration of its patcher into account. If it's not the case, and if it rips the DVD without modifying it (except when it's necessary due to the protections), then ignore my remark.

jinjin_jp
3rd January 2009, 18:20
All recent protections such as ARccOS or RipGuard are based on illegal stuff or read errors in some cells. Those errors are sufficient to confuse the traditional rippers. But they are also sufficient to confuse the players! Therefore, the errors must be located in PGCs or cells that can never be played. The navigation of the DVD must skip those parts.

The modern rippers have implemented a way to locate the potentially protected areas. They simulate the navigation (exactly like the PgcEdit trace) and explore all possibilities. The areas that have never been visited at the end of the exploration are highly suspect.

The protect of "Dark Night" seems to be little different.
Bad sector seems to be in IFO file.
Because VTS_04-08_0.IFO can't be opened by IfoEdit and PgcEdit.
And DVDDecrypter and RipIt4Me freeze in mid of starting. I think they read IFO at first, but can't read and freeze.
PSL file is written only LBA of cells(VOBs), but LBA of IFO is jumped.
Perhaps I think DVDFabDecrypter and AnyDVD can rip bacause they analysis from only VIDEO_TS files ar first, then from other files. I think it possible because it can't jump between VTS and needs to go through VMG.

(Add)
And "Dark Night" has bad sectors in cells(VOB), too.
I think only method to know where(LBA) is bad secors, so I confirmed by RipIt4Me with using AnyDVD only when starting.

Regards.

r0lZ
3rd January 2009, 18:36
It's more sophisticated than I thought, but the principle is still the same. The protected IFOs are never read by the normal players, because there is nothing that is played in those VTS. The problem for the rippers is that they have to read the IFOs only when they are really needed, and therefore they must begin by reading VIDEO_TS.IFO only, then analyze the navigation, and read subsequent IFOs only when it's necessary. That should still be possible.

DVDDecrypter is too old to do that correctly, and it is true that it reads all IFOs directly, to analyze them. Pity, this excellent ripper seems to be at the end of its life!

blutach
4th January 2009, 01:49
I'd delete the PGC - it is not even entered, as r0lZ has just said.

Regards

M_Knox
4th January 2009, 08:59
The protect of "Dark Night" seems to be little different.
Bad sector seems to be in IFO file.
Because VTS_04-08_0.IFO can't be opened by IfoEdit and PgcEdit.
And DVDDecrypter and RipIt4Me freeze in mid of starting. I think they read IFO at first, but can't read and freeze.
PSL file is written only LBA of cells(VOBs), but LBA of IFO is jumped.
Perhaps I think DVDFabDecrypter and AnyDVD can rip bacause they analysis from only VIDEO_TS files ar first, then from other files.

No, the IFOs on The Dark Knight are not badsector-protected, they can be copied in Windows Explorer directly from the disc. The protection is different: the IFOs are crafted so that the rippers analysing them go crazy ;) I let DVDDecrypter go through TDK - it stopped on analysing VTS_04_0.IFO. Well, actually it did not stop, because it was still working hard - so hard, that after some time Windows notified, that the virtual memory is insufficient and it has to grow the swap file. After a while DVDDecrypter crashed with "Out of memory" error.
So, my guess is, that the IFOs contain some invalid pointers, that make the unaware rippers fall into some endless loop.

Alex_ander
4th January 2009, 09:33
What if those ifo's make players work with bup's only (considering rippers won't use bup's)? An illegal type of protection, but who knows what they 'invent' next time?

jinjin_jp
4th January 2009, 10:53
No, the IFOs on The Dark Knight are not badsector-protected, they can be copied in Windows Explorer directly from the disc. The protection is different: the IFOs are crafted so that the rippers analysing them go crazy ;) I let DVDDecrypter go through TDK - it stopped on analysing VTS_04_0.IFO. Well, actually it did not stop, because it was still working hard - so hard, that after some time Windows notified, that the virtual memory is insufficient and it has to grow the swap file. After a while DVDDecrypter crashed with "Out of memory" error.
So, my guess is, that the IFOs contain some invalid pointers, that make the unaware rippers fall into some endless loop.
Thanks for the explanation.
I don't know the technical term, I just used the term "badsector" because ripper or etc can't read. sorry.

Regards.

blutach
4th January 2009, 12:46
No, the IFOs on The Dark Knight are not badsector-protected, they can be copied in Windows Explorer directly from the disc. The protection is different: the IFOs are crafted so that the rippers analysing them go crazy ;) I let DVDDecrypter go through TDK - it stopped on analysing VTS_04_0.IFO. Well, actually it did not stop, because it was still working hard - so hard, that after some time Windows notified, that the virtual memory is insufficient and it has to grow the swap file. After a while DVDDecrypter crashed with "Out of memory" error.
So, my guess is, that the IFOs contain some invalid pointers, that make the unaware rippers fall into some endless loop.I have had a look at these IFOs. There are 600 Language Units with 600 PGCs in each LU, all pointing to the same bits of data - making the IFOs small and very efficient. The pointers are valid and so are the IFOs - it's just the number of LUs and PGCs overwhelm things.

If you want to, you can examine them with a hex editor - it's not too tough to figure out how they "work". But since they are totally unreferenced, they are irrelevant - as has been said, they are there to confuse the rippers which rely on scanning/exploring the DVD. And since rippers broke the system within a day or so, I'd say it didn't work all that well. What is interesting is that it came from Warner, which has not been too active in advanced protection to date.

Regards

r0lZ
4th January 2009, 12:59
Yes, that method is a nice idea! But I disagree when you say that the IFOs are valid. Since all LUs share exactly the same data, they have the same language code. At least that is totally illegal!
Of course, since the menu domain is never called, the players should not have problems. But the rippers (that by nature try to analyze everything) cannot handle that menu the normal way. They have to analyze the pointers to the LUs and PGCs, and load only one of them.

blutach
4th January 2009, 23:11
Yes, you are right - the codes are invalid. Cute and efficient idea though.

Regards