PDA

View Full Version : cloning conclusions..



ekonomi
17-02-2003, 10:58 AM
Hello all,

I want to thank you all for answering my questions in previus threads.
Now I want to share some conclusions that i made through the whole process.
I surely like to see your comments.

OS: windows xp
Hardware info: phoenix/pic reader/writer MasterCRD LCD2
Software used: sim scan
pic_Card (dejan's gold cards programmer v1.0)
Cardinal v68 beta
TwinSim v1.0 and v1.1
SimEmu 5.00 (green cards)
simpic24
winphoenix v1.06
winexplorer v4.6
IC-Prog v1.05a (with xp plugin)
Xsim v0.02
ChipCard reader

As you can see i've tried a lot of software ;-) So here are the results for each one:

* sim scan: with dos window maximized or minimized it crashes after i enter the pin. The errors for crashing aren't always the same.
1st error: Error while sending data
2nd error: smth about memory
Since it's a DOS program I don't expect it to work fine with xp. Still haven't tried it with win98.

* pic_card: I've extracted the Ki and IMSI. I try to program the gold card with dejan's programmer but i get data send error.
Since it's a DOS program I don't expect it to work fine with xp.

* cardinalv68: Everything works fine. I extract Ki and imsi. I use a plugin that comes with it (KiSsMi_Ag&Au) and succesfully generate eeprom.hex and pic.hex for gold card.

* Twinsim: I have extracted Ki and IMSI from cardinal and i'm using twinsim to generate eeprom/pic.hex files. I've converted IMSI from cardinal. v1.0 generates the files but when i try to convert eeprom.hex to bin with hex2bin i get error. Same results with twinsim v1.1 (that automatically converts imsi extracted from cardinal). Notice: the eeprom.hex file generated from cardinalv86 is 5.50kb while eeprom.hex generated from twinsim is 5.60kb.

* SimEmu5.00: I try to program SIM_EMU_FL_ENG.hex with IC-PROG for green cards but i get error in verification (error at address XXXh).

* simpic24: I program simpic24.hex to the gold card with ic-prog succesfully. I use winexplorer v4.6 to load and execute the script. Winexplorer succesfully resets and anylizes ATR from the card but when i execute the script it timesout ("Timeout at command 2A").

* winphoenix v1.06: I use eeprom/pic.hex files generated from
cardinalv68.
I program the loader with IC-PROG (with pic mode in my writter). I write eeprom.bin (converted with hex2bin) with winphoenix succesfully (with writer in phoenix mode). I write pic.hex file with IC-PROG (and pic mode in writer) succesfully. So, everything seems to work fine. The card was cloned succesfully. I put the card in the phone and the sim is rejected :(

(chipcard) I read the card with chipcard.
I checks serial,phase,provider,services succesfully and i get error while it checks "Card Abilities". I can read the card's files and I that see Kc is all 00h (is this normal in cloned cards?). I can read the IMSI file without pin request. I can't read phonebook and sms-es. I can enter PIN and verify it correctly.

(XSim) I read the card with XSIM.
It scans the files succesfully. Kc record has more than 30bits (while original card had only 9bits) and the first 8bits are 00h. The other aren't 00h. I can read the IMSI without pin request). I can enter PIN and the program verifies it succesfully.

Final result the cloned sim doesn't work. I know that most of you have things to do and you are not obligated to answer in this forum but i count on your good souls ;) Comments about why the card is being rejected and about the failure of the other used softwared are welcomed.

with regards,
ekonomi.

SirGraham
17-02-2003, 07:32 PM
Hi ekonomi

Coments about your trys and XSim:



(XSim) I read the card with XSIM.
It scans the files succesfully. Kc record has more than 30bits (while original card had only 9bits) and the first 8bits are 00h. The other aren't 00h. I can read the IMSI without pin request). I can enter PIN and the program verifies it succesfully.


*All the answer of the card are 12 bytes (12*8 = 96 bits) The Fisrt 4 bytes are the SRes (to BTS) and the last 8 Bytes are the Kc.
In COMP128 v1 y COMP128 v2 the last 10bits of Kc always are zero. There is (2^56 combinations not 2^64) to encript the voice. This are document (David wargner)
Itīs correct. There is any problem.

*If you donīt enter the PIN you can not Read The IMSI, because normaly the File 7F20:6F07 (IMSI) have control of read with PIN1.
You can see this in the header of the file....
Itīs correct also . There is any problem.


Best Regards,
Sir Graham.

shelltox
18-02-2003, 10:27 AM
* SimEmu5.00: I try to program SIM_EMU_FL_ENG.hex with IC-PROG for green cards but i get error in verification (error at address XXXh).

I already have that error... first..if you are trying programm a PIC in a laptop with ic-prog... try in one desktop (laptop have COM port low power)
Disable verification during programming
Try diferent "I/O delay"..try "enable MCLR as Vcc"

try a dedicated program to your device try this
Master Burner 1.7
http://www.visoduck-discount.de/dow...er/MB-V.1.7.zip

good luck

uaepast
18-02-2003, 02:31 PM
hi all

R u guys still have problem with cloning stuff!!

well nothing easier than this, and you might thank me!

guys: do u know how to program the normal reciever cards??
well i guess u all know how to use twoprog, or icprog or uspinfinity, right?

any how its so easy! and thanx to god i've done it and it worked successfuly with me!

1-use the cardinal68 to extract the ki and imsi.
it took me about 6 hours to read the ki!! wow, any body done it in less time plz help!!

2-use SE401CONFIG software to conver the imsi so u can easly add it later to the phone new menu!! " it will start with 08...."

3-USE the multiprog or any card reader to upload the pic and eeprom to your new " pic16f877" card" which is the silvercard.

please find attachment " simemu50.zip" and read the txt file" readme"

thats all mates!! good luck

oh by the way: anyone know how to encrese the ammount of the sms/ADN?? PLZZZZZZZZ HELP OK, TAHNX

I Tried to do it through the new menu in the phone for the simemu5, but unfortiunatly doesn't work, or i may did it wrongly!

as i'm using the the green card" pic16f877" processer and 256 eeprom, working 100% as 64, but i didn't try the 128 yet. however as a good results at the 256 i expect eep128 working too!

email: [email protected]

best regards

UAEPAST

shelltox
18-02-2003, 03:56 PM
eeprom 128 it work's well

I already programm sim-emu in:
pic16f877+24lc256 - version 5.00
pic16f877+24lc128 - version 5.00
pic16f877+24lc64 - version 5.00s

uaepast
18-02-2003, 04:02 PM
Hi shelltox,

well tell me then how can i control and set the sms/adn in my new card as i like??


is there any software??

coz my the simemu50s is not doing it for me:(

regards,

uaepast

uaepast
18-02-2003, 04:20 PM
HI ALL,

its written here somewhere in this ziped file, i've read some of it, but i don't know why can't i get it till now!!

plz guys any one find out how, explane to me


thanx

best regads,

UAEPAST

ekonomi
20-02-2003, 12:19 PM
Originally posted by uaepast
[B]Hi shelltox,
well tell me then how can i control and set the sms/adn in my new card as i like??
is there any software??
coz my the simemu50s is not doing it for me:(
[B]

Hi,
i've got simemu 5.00s which includes an executable in vbasic named SE50sCFG.exe. This lets you set values for sms sms/adn/fdn. It's the official version from the site, so you should have it too.

regards,
ekonomi.

shelltox
20-02-2003, 03:22 PM
Hi...

I have other configurator for 5.00s
have options for:
ADN-SMS-FDN
64-37-4
153-20-10
208-10-10

send me mail

uaepast
20-02-2003, 06:41 PM
Hi all,


thanx for your comments.

well, these setting are usefull when u have a silver card with pic16f877 and 64 eeprom.

so what about if i have the same kind of cards but with larger eeprom" memory" such as the green card with 128eep and 256 eeprom which i'm using now, shouldn't be there more space for AND/SMS/FDN ??

someone tell me plzzzz??

supposed normal silvercard can hold about 250 ADN, and 64 sms, as its in the 12 in 1 with sim doctor!!

so what about if we r using larger eeprom with 256?? shouldn't the ammount of the sms adn and fdn incresed??

i donno!!

plz share us


regards,

uaepast