Welcome to Doom9's Forum, THE in-place to be for everyone interested in DVD conversion.

Before you start posting please read the forum rules. By posting to this forum you agree to abide by the rules.

 

Go Back   Doom9's Forum > General > Decrypting

Reply
 
Thread Tools Search this Thread Display Modes
Old 11th March 2007, 22:04   #1  |  Link
arnezami
Registered User
 
Join Date: Sep 2006
Posts: 390
AACS Keys - A program revealing all AACS Keys needed to decrypt (HD DVD and Blu-ray)

MODERATOR NOTE: arnezami and KenD00 are apparently no longer active in maintaining this software. New versions can be found at cyberside.

Thank you, arnezami, for your pioneering work!

Original contents of this post follow...

----------------------------------------

Finally.

Here is my program that gives a list of all keys used for aacs decryption for one disc. Currently I'm too tired to go into this deeply but I need people to test this. Especially the Blu-ray owners: I have no Blu-ray burner/player so I'm "flying blind" when it comes to programming stuff for Blu-ray. I think I've read the Blu-ray specs right and hope it all works. But it really has to be tested.

Anyway. As promised the program itself: aacskeys.exe v0.2.5 (fixed for Blu-ray now )

Go here for the new v0.2.8 version.

Its still in the early stages of development so there are probably some bugs in it.

Here is a screenshot (King Kong):



Thats gotta put a smile on your face

Keep in mind there are three types of views now: normal (n), verbose (v) and sensitive (s). But you'll figure it out .

When I iron some things out I will release the source (of course) but this will take at least a couple of days (maybe next week). There are still a couple of things to do (Hk, VID MAC, BK, TKFMAC, Device Keys etc). But I want it to work first and there is where you guys come in .

So if you can test if it works please do. Any feedback is welcome.

Thanks already

Regards,

arnezami

Last edited by foxyshadis; 28th May 2015 at 01:16.
arnezami is offline   Reply With Quote
Old 11th March 2007, 22:15   #2  |  Link
Pelican9
Coder
 
Pelican9's Avatar
 
Join Date: Jan 2007
Location: Around the World
Posts: 697
It works.
Or these are burned-in values...
Code:
Processing key:               09F911029D74E35BD84156C5635688C0
Encrypted C-value:            6D02CAC67B1A7E95C216EFD4C92809CF
Corresponding uv:             00000001

Decrypted C-value:            074E1FC88FB9B780A225CAA23BC3DB57
Media key:                    074E1FC88FB9B780A225CAA23BC3DB56

Encrypted verification data:  87B8A2B7C10B9FADF8C4361E238659E5
Decr verif data should be:    0123456789ABCDEF
Decrypted verification data:  0123456789ABCDEF0A9BE086140F5A60

AGID:                         00

Host certificate from:        Power DVD 7.1
Host certificate (Hcert):     0200005CFFFF0000000C00006E3DEB679B9A16AD
                              FAA8E30878767BA6EB2A9B415385AD1181B4446C
                              31E9A5DD2AB808B364FF15885BAC490964318C9B
                              F8029FCF76F688A54FBDA03F6D9332EF04E5A613
                              12DA85880A4D9CBB79D8602E
Host Private Key (Hpriv):     4737676058D7029452514F0AB186DC4CCA8C578F
Host Nonce (Hn):              2923BE84E16CD6AE529049F1F1BBE9EBB3A6DB3C

Drive certificate (Dcert):    ########################################
                              ########################################
                              ########################################
                              ########################################
                              ########################
Drive Nonce (Dn):             ########################################

Drive key point (Dv):         ########################################
                              ########################################
Drive key signature (Dsig):   ########################################
                              ########################################

Host key (Hk):                0000000000000000000000000000000000000000
Host key point (Hv):          8E9B0E3CF41FA7DA3A829F604122EA4ED5261AA4
                              7570CE0BB9061A66FAF92C4A7D98ACC171CBF19B
Host key signature (Hsig):    ########################################
                              ########################################

Bus key (BK):                 ################################

Volume ID:                    40000918200608410020202020200000
Voluem ID MAC:                ################################

Volume Unique Key:            802F78B1B20D1183638D84E1A96D6EDD
Title Key File MAC:           399FE6A364D623541418E3805D1ED790

Encrypted Title Key 1:        30F8DC87B137A1607C7F2A731FF7B6BC
Encrypted Title Key 2:        B5183BDC3335A1EBC8E517B6611A1CBA
Encrypted Title Key 3:        A625BDC656E9D5EDE040A07B9FB8D7B1
Encrypted Title Key 4:        F5ACB8900A639E85B4133933E74A92E7
Encrypted Title Key 5:        635B440099BFAB97911ABBBC4B1F25A7
Encrypted Title Key 6:        9EB5C32E0AFB0B3A4A906CB360CE57A0
Encrypted Title Key 7:        21258E976BECFF0090E371058DDDE695
Encrypted Title Key 8:        E49D4100A52DB01F7F605768DB4000F2

Decrypted Title Key 1:        7D743D3C92652CC16B66D9CB87F6D132
Decrypted Title Key 2:        70B71C6E767E213AEB7456985BAAD8A4
Decrypted Title Key 3:        4BC362995030035312A5B6030D76C817
Decrypted Title Key 4:        A019B5101E904A700A44F056B7EB3579
Decrypted Title Key 5:        896AB02D3D77554EABCE3CCE931DA39D
Decrypted Title Key 6:        BEC07637E9C4EFA1F70FED6891DB277B
Decrypted Title Key 7:        1DC0D276F2C5B9FCFDE1414C5002BAAB
Decrypted Title Key 8:        BC7EB577D1936818AEB9241F024DE681
Pelican9 is offline   Reply With Quote
Old 11th March 2007, 23:11   #3  |  Link
fakker
Registered User
 
Join Date: Feb 2007
Posts: 6
working

confirmed working....

Batman Begins UK HD-DVD - 15/09/06
Here is the output given after using verbose mode:
Code:
C:\>aacskeys d v
Processing key:               09F911029D74E35BD84156C5635688C0
Encrypted C-value:            C8ADC9F88E38FB152FCD5E68291C4C60
Corresponding uv:             00000001

Decrypted C-value:            B0A84A4838821346834751E1E9D33B44
Media key:                    B0A84A4838821346834751E1E9D33B45

Encrypted verification data:  8D960C0952C0A6260AD3FDD236DF015B
Decr verif data should be:    0123456789ABCDEF
Decrypted verification data:  0123456789ABCDEF143F000821C02F93

AGID:                         00

Host certificate from:        Power DVD 7.1
Host certificate (Hcert):     0200005CFFFF0000000C00006E3DEB67
                              FAA8E30878767BA6EB2A9B415385AD11
                              31E9A5DD2AB808B364FF15885BAC4909
                              F8029FCF76F688A54FBDA03F6D9332EF
                              12DA85880A4D9CBB79D8602E
Host Private Key (Hpriv):     4737676058D7029452514F0AB186DC4C
Host Nonce (Hn):              2923BE84E16CD6AE529049F1F1BBE9EB

Drive certificate (Dcert):    ################################
                              ################################
                              ################################
                              ################################
                              ########################
Drive Nonce (Dn):             ################################

Drive key point (Dv):         ################################
                              ################################
Drive key signature (Dsig):   ################################
                              ################################

Host key (Hk):                00000000000000000000000000000000
Host key point (Hv):          8E9B0E3CF41FA7DA3A829F604122EA4E
                              7570CE0BB9061A66FAF92C4A7D98ACC1
Host key signature (Hsig):    ################################
                              ################################

Bus key (BK):                 ################################

Volume ID:                    400009061209091557474844564D0000
Voluem ID MAC:                ################################

Volume Unique Key:            F66308D9151653672AB7D75A01DC3F7E
Title Key File MAC:           40746D614A37CE2EAC331A5939D3E238

Encrypted Title Key 1:        A51DACA264BC206442AD767237E02130
Encrypted Title Key 2:        A57046224AE96E17D7F2F8878E914B0A
Encrypted Title Key 3:        BD21A78EADF40081516133E925066C19
Encrypted Title Key 4:        34970BF350A7342F579C7187365D3771
Encrypted Title Key 5:        872E9B67DA39B10BF8C10796F82A394D

Decrypted Title Key 1:        2D9CF93FA5F221C2135DDB06AE4F3EA5
Decrypted Title Key 2:        8B6922BEBDE8B48A25021E75F1B7B597
Decrypted Title Key 3:        4F32342FB377E0FE8A9C1166A51F3B8E
Decrypted Title Key 4:        F3419DE7F77AC83E0230A3E2A7833059
Decrypted Title Key 5:        04AF9217B59BA527663CD968BDD701DB
Sorry if it looks a mess... Either way there were 64 encrypted and decrypted keys... I will not paste all of those as we get the drift.

Again, as many have already said - thanks a lot for all of your efforts, and in releasing this long awaited tool.

Last edited by fakker; 11th March 2007 at 23:28. Reason: changed date format to american style so nothing is mis-understood.
fakker is offline   Reply With Quote
Old 11th March 2007, 23:36   #4  |  Link
mrazzido
Registered User
 
mrazzido's Avatar
 
Join Date: Jan 2007
Posts: 114
i try it on bluray , House of Wax EUR / GER


when i read the keys from memory ( windvd )

i get these



CPS Unit Key : 9329A4976FE297AF4475BDAD13119A4F

Volume Unique Key : 83AD82670F99F9F9A64D05B0501CF20D




with your tool i get


Last edited by mrazzido; 11th March 2007 at 23:43.
mrazzido is offline   Reply With Quote
Old 11th March 2007, 23:43   #5  |  Link
mrazzido
Registered User
 
mrazzido's Avatar
 
Join Date: Jan 2007
Posts: 114
second test

on click EUR / GER


winddvd memory



CPS Unit Key : 05BAFE2DD84C0781C6CE09714726FED9

Volume Unique Key : 5928C17E732E17FCC896401715556D07



tool

mrazzido is offline   Reply With Quote
Old 11th March 2007, 23:50   #6  |  Link
arnezami
Registered User
 
Join Date: Sep 2006
Posts: 390
Quote:
Originally Posted by mrazzido View Post
second test

on click EUR / GER


winddvd memory



CPS Unit Key : 05BAFE2DD84C0781C6CE09714726FED9

Volume Unique Key : 5928C17E732E17FCC896401715556D07



tool
Ok. There is clearly a problem with the retrieval of the Volume ID here (its all 0's) . Which is also the hardest to test for me.

Can you tell me if any of the sensitive data: Dv/Dsig/Dn/Dcert/VID MAC are also all 0's (don't post them just tell if some of them they are all 0's and if so which ones)

And are these file names on your disc(s):

G:\AACS\Unit_Key_RO.inf
G:\AACS\MKB_RO.inf

Because it seems to have problems opening the Title Key file (error on top).

I'm pretty sure the MKB file is working since the Media Key is verified.

Last edited by arnezami; 11th March 2007 at 23:55.
arnezami is offline   Reply With Quote
Old 11th March 2007, 23:59   #7  |  Link
mrazzido
Registered User
 
mrazzido's Avatar
 
Join Date: Jan 2007
Posts: 114
yeah these files on the disc.



Last edited by mrazzido; 12th March 2007 at 00:06.
mrazzido is offline   Reply With Quote
Old 12th March 2007, 00:00   #8  |  Link
arnezami
Registered User
 
Join Date: Sep 2006
Posts: 390
Ah. I think I see the problem.

Try this one: aacskeys.exe
arnezami is offline   Reply With Quote
Old 12th March 2007, 00:05   #9  |  Link
mrazzido
Registered User
 
mrazzido's Avatar
 
Join Date: Jan 2007
Posts: 114
works

test it on click


mrazzido is offline   Reply With Quote
Old 12th March 2007, 00:09   #10  |  Link
arnezami
Registered User
 
Join Date: Sep 2006
Posts: 390
Quote:
Originally Posted by mrazzido View Post
works

test it on click

Perfect

Now it works for BluRay too.
arnezami is offline   Reply With Quote
Old 12th March 2007, 00:10   #11  |  Link
mrazzido
Registered User
 
mrazzido's Avatar
 
Join Date: Jan 2007
Posts: 114
second test of how / ger/eur








great work :-)
mrazzido is offline   Reply With Quote
Old 12th March 2007, 00:27   #12  |  Link
bourke
Registered User
 
Join Date: Feb 2007
Posts: 85
How do you find the 'hash' value used in programs like BackupHDDVD? Is that something that could be added to the output?
bourke is offline   Reply With Quote
Old 12th March 2007, 00:27   #13  |  Link
mrazzido
Registered User
 
mrazzido's Avatar
 
Join Date: Jan 2007
Posts: 114
sometimes ago i burned a CRYPTED movie on BD-RE

when i try the tool

Quote:
C:\Dokumente und Einstellungen\Administrator>aacskeys g n
Processing key: 09F911029D74E35BD84156C5635688C0
Media key: 853EC6162030F7F7EF1B61265BE30A68
Volume ID: 00000000000000000000000000000000
Volume Unique Key: 378A39F68C5FDABE94D0621BDBC4481D
Decrypted Unit Key 1: 8AF9B2644339E90931DA68DB96AA06AA

Last edited by mrazzido; 12th March 2007 at 00:31.
mrazzido is offline   Reply With Quote
Old 12th March 2007, 00:29   #14  |  Link
arnezami
Registered User
 
Join Date: Sep 2006
Posts: 390
Quote:
Originally Posted by bourke View Post
How do you find the 'hash' value used in programs like BackupHDDVD? Is that something that could be added to the output?
Yeah. Still have to do that.

Very practical indeed.
arnezami is offline   Reply With Quote
Old 12th March 2007, 00:32   #15  |  Link
arnezami
Registered User
 
Join Date: Sep 2006
Posts: 390
Quote:
Originally Posted by mrazzido View Post
i sometimes ago i burned a CRYPTED movie on BD-RE

when i try the tool
Interesting. Volume ID is all 0's with rewritables. That sort of makes sense though. But does it give a Volume ID MAC (when doing the sensitive view). Or is that one all 0's too? If it all 0's then Players can probably not be fooled by putting encrypted movies on rewritables (even after re-encrypting the title keys). But if the Volume ID MAC is anything other than 0's then its going to be interesting to see what we can do with rewritables...

Last edited by arnezami; 12th March 2007 at 00:38.
arnezami is offline   Reply With Quote
Old 12th March 2007, 00:35   #16  |  Link
bourke
Registered User
 
Join Date: Feb 2007
Posts: 85
No hurry either - we all appreciate this (whole AACS caper) must have used up a lot of your time already :-)

I'm actually more waiting on the lads doing those evo demux/authoring tools (which are coming nicely) - then if they include your code they can have a very nice 1080p to 720p (~8Gb) conversion tool indeed :-)
bourke is offline   Reply With Quote
Old 12th March 2007, 00:36   #17  |  Link
mrazzido
Registered User
 
mrazzido's Avatar
 
Join Date: Jan 2007
Posts: 114
Quote:
Originally Posted by arnezami View Post
Interesting. But does it give a Volume ID MAC (when doing the sensitive view). Or is that one all 0's too? If it all 0's then Players can probably not be fooled by putting encrypted movies on rewritables (even after re-encrypting the title keys). But if the Volume ID MAC is anything other than 0's then its going to be interesting to see what we can do with rewritables...




i try all 0's :-/
mrazzido is offline   Reply With Quote
Old 12th March 2007, 01:04   #18  |  Link
blutach
Country Member
 
blutach's Avatar
 
Join Date: Sep 2004
Location: is everything!
Posts: 6,499
@arnezami

A huge thank you for this. Thread stuck.

Regards
__________________
Les

Only use genuine Verbatim or Taiyo Yuden media.
blutach is offline   Reply With Quote
Old 12th March 2007, 02:17   #19  |  Link
xyz987
Registered User
 
Join Date: Dec 2006
Posts: 142
Excellent!!!

xyz987 is offline   Reply With Quote
Old 12th March 2007, 03:13   #20  |  Link
vudoodoodoo
Registered User
 
Join Date: Feb 2007
Posts: 8
Nice. Thank you!
vudoodoodoo is offline   Reply With Quote
Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 11:49.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.