TBS 5927

Buy a TBS-6903. It is PCIe, though.
 
Buy a TBS-6903. It is PCIe, though.
A TBS 6903 is certainly an option, it it wouldn’t be for its lack of good blind scanning capability. I have seen reports that blind scan on the 6903X takes 20–40 minutes for a full Ku-band sweep, which would be a significant limitation.
 
A TBS 6903 is certainly an option, it it wouldn’t be for its lack of good blind scanning capability. I have seen reports that blind scan on the 6903X takes 20–40 minutes for a full Ku-band sweep, which would be a significant limitation.
A 6093X is a different card fhan 6903.
Scanning on 6903x is very fast (less than a minute for both polatisations and full band together)
 
A 6093X is a different card fhan 6903.
Scanning on 6903x is very fast (less than a minute for both polatisations and full band together)
Thanks for the correction. You’re right that I was mixing up two different scenarios. The 20–40 minute figure appears to come from Windows/EBS Pro usage.

Under Linux with DeepTho’s neumoDVB blind scan drivers, which I’m looking into, the stid135-based cards including the 6903X seem to perform much better. My use case is Linux-only, and I’m also interested in the dontlookup use case, so this is encouraging. Have you personally used the 6903X with something like the dontlookup project, or is your experience primarily with broadcast TV transponder scanning?
 
I meant the TBS-6903, not the TBS-6903X.

The TBS-6903 supports RFScan() with good resolution (compared to other TBS cards capable of RFScan()) and allows very fast scanning using streamreader.dll. For me it is the best card, except for lack of DVB-S2X.

The TBS-6903X supports FFTScan() which has allows better spectrum rendering. But it's blind scan performance with streamreader.dll is much worse than what can be achieved with the TBS-6903.

Under Linux, things are different - thanks to deeptho.

The TBS-5927 uses the same tuner IC as the TBS-6903, hence why I suggested it.
 

I meant the TBS-6903, not the TBS-6903X.

The TBS-6903 supports RFScan() with good resolution (compared to other TBS cards capable of RFScan()) and allows very fast scanning using streamreader.dll. For me it is the best card, except for lack of DVB-S2X.

The TBS-6903X supports FFTScan() which has allows better spectrum rendering. But it's blind scan performance with streamreader.dll is much worse than what can be achieved with the TBS-6903.

Under Linux, things are different - thanks to deeptho.

The TBS-5927 uses the same tuner IC as the TBS-6903, hence why I suggested it.
Thanks for a very helpful clarification.
So the TBS-6903 (original, STV0910-based) shares the same tuner IC as the TBS-5927 and offers fast blind scan on both Windows and Linux.

My workflow is Linux-only and I’m also interested in the dontlookuo use case. For the dontlookup use case, the raw payload capture on PCIe cards requires EBS Pro on Windows rather than the Linux driver patch approach. Is that also your understanding?

And do you have any experience with whether the TBS-6903 can reliably lock onto ACM/GSE data transponders, as opposed to standard broadcast transponders?

Any advice would be very helpful.
 
I am not literate on TBS running under Linux, but deeptho will certainly answer all your questions!
 
Do your homework, but this should be a nice purchase: TBS 6909 Octotunner | eBay.de
It is on my own eBay watch list, but I cannot afford it.

View attachment 168623
Thanks for an interesting suggestion.
One clarifying question: the TBS-6909 (original) uses the MxL5xx chipset rather than the STV0910 in the 5927/6903. For the dontlookup use case specifically, do you know if the TBS-6909 can reliably capture raw DVB-S2 baseband frames (ACM/GSE data transponders), and does blind scan work well for discovering unknown data transponders on it under Linux?
All the best, Caroline
 
If it is of any interest, I may have a TBS 5925 USB device I could sell. Hardly used, in new condition with original box and all accessories.
It uses the STV090X chip according to the CrazyScan Wiki, same chip as the TBS 6925 which was classed as a pro grade card.
 
Last edited:
If it is of any interest, I may have a TBS 5925 USB device I could sell. Hardly used, in new condition with original box and all accessories.
It uses the STV090X chip according to the CrazyScan Wiki, same chip as the TBS 6925 which was classed as a pro grade card.
Thanks, this sounds very interesting.
The TBS5925 shares the STV090x chip family with the TBS5927, which is exactly what I need.

A few quick questions before we discuss price: where are you located (for shipping to Sweden)? And do you happen to know if it has ever been used for data transponder reception, or purely for broadcast TV?
 
Thanks for an interesting suggestion.
One clarifying question: the TBS-6909 (original) uses the MxL5xx chipset rather than the STV0910 in the 5927/6903. For the dontlookup use case specifically, do you know if the TBS-6909 can reliably capture raw DVB-S2 baseband frames (ACM/GSE data transponders), and does blind scan work well for discovering unknown data transponders on it under Linux?
All the best, Caroline
I apologize - I assumed the 6909 was simply a version of the 6903 with multiple tuners. That is in fact not the case and the same image I posted shows that it does not use a STV091X.

I am unable to answer your question, since I never used the dontlookup use case.

But perhaps someone else can tell.

My opinion is that the "dontlookup" article/project is hyped and reality is much less spectacular. Also, you can analyze most data transmitted with regular TS analyzers. My own VMA Transport Stream Analyser (Windows only) will give you access to byte level data in HEX view. Yes, you can see some interesting data on some transponders, but nothing ground breaking. Not like you can dump internet over satellite and see what files users are downloading (that was possible 20 years ago, by the way). Most is encrypted and the unencrypted data is mostly telemetry data (from what I have found).

Here is a random example I just captured now:

1776854167528.webp


You can see the data in an HEX view:

1776854194822.webp


Another example:

1776854406344.webp

As you can see, no DVB services are transmitted. A regular receiver sees nothing. But there is data being sent:

1776854492980.webp
1776854492985.webp
1776854527667.webp
"QPING by PRTG N"???

Quick Google search reveals:

1776854669508.webp

There are more interesting transponders, where the data is encapsulated IP traffic that can be passed to Wireshark for further analysis.

As I understand it, the dontlookup tool, using Linux, allows to capture data that is not DVB conform and hence is not made available with by regular drivers.

I would, myself, be interested to know what you can REALLY capture using the dontlookup tools and what you can do with such data.

I don't think it allows you to read SMS text messages or see insights to military top secret information... And if it does, I would steer away from it.
 

Attachments

  • 1776854462510.webp
    1776854462510.webp
    121.7 KB · Views: 6
I captured a bit of data and sent it to ChatGPT for analysis:

Code:
Yes. This is not an MPEG transport stream capture.

What you uploaded appears to be a custom packet-bundle file with a VMPC header, followed by many small captured network packets. The dominant traffic inside it is TCP to port 2404, which is the standard port used by IEC 60870-5-104 (IEC-104), an industrial control / SCADA protocol.

What I found:

File starts with a custom wrapper: VMPC
Inside it there are many embedded IPv4 packets
Most of the meaningful traffic is TCP → port 2404
Several payloads begin with:
68 04 43 00 00 00
68 04 01 00 ...

Those are very characteristic of IEC-104 APDUs:

68 = IEC-104 start byte
04 = APDU length
control fields like 43 00 00 00 are consistent with U-frames such as link/test/start/stop control exchanges

There is also some other network traffic mixed in:

ICMP echo traffic
a little SNMP (UDP/161)
some DNS (UDP/53)

So the best interpretation is:

This capture is a bundled network trace from an industrial/SCADA environment, mainly carrying IEC-104 control traffic, not DVB or PID payload data.

One important caveat:

the .vmpid format is clearly proprietary/custom, and the records look slightly padded or partially truncated, so I cannot claim every packet was reconstructed perfectly
but the IEC-104 identification is strong enough to be confident about what the capture fundamentally is

If you want, I can do a second pass and extract:

the list of IEC-104 endpoints,
the most common client/server pairs,
and the probable meaning of the control frames.

So, I do not exactly know how much "deeper" you can dig with dontlookup.

Everything I did in this brief demo was done with Windows using a TBS6903X, but it would be possible with any other TBS card (PCI, PCIe or USB), as long as it is supported by streamreader.dll.

I am not saying that you won't be able to get more insight with dontlookup, their drivers and running this under Linux. I just question if it is worth spending hundreds in second hand hardware to see "a bit more data"?
 
Finally I would like to add, that you can do further analysis with the SDR path:

1776857625242.webp
 
Thanks, this sounds very interesting.
The TBS5925 shares the STV090x chip family with the TBS5927, which is exactly what I need.

A few quick questions before we discuss price: where are you located (for shipping to Sweden)? And do you happen to know if it has ever been used for data transponder reception, or purely for broadcast TV?


I bought it brand new, direct from the UK importer of TBS devices. It has only been used a few times, generally for scanning an RF spectrum with either CrazyScan or EBSPro in the days before I bought a Promax Ranger field strength meter. The TBS 5952 was also used with EBSPro to run the tabular output frequency scan of satellites.

If you want me to connect it up to a dish to test it on any specific frequencies/satellites I will be able to do it on Saturday or Sunday at the earliest.
I also have some Prof DVB cards that might use the same chip? They are in brand new condition and in their original boxes.

I am located in Surrey, UK. Shipping to Sweden by a courier such as DHL Express should be easy to do.
 
Last edited:
Thanks for the correction. You’re right that I was mixing up two different scenarios. The 20–40 minute figure appears to come from Windows/EBS Pro usage.

Under Linux with DeepTho’s neumoDVB blind scan drivers, which I’m looking into, the stid135-based cards including the 6903X seem to perform much better. My use case is Linux-only, and I’m also interested in the dontlookup use case, so this is encouraging. Have you personally used the 6903X with something like the dontlookup project, or is your experience primarily with broadcast TV transponder scanning?

Last time I looked it still seemed rather limited and as it is pure python it is going rather slow. Some other tools like skyscraper (windows only) are currently probably better. You can use neumo-dmx (from my blindscan tools) to save GSE streams, but dontlookup can probably not use it, as it seems to rely (via a driver patch) on some direct card access that is only possible on usb cards.

I am building my own tool to parse such streams, but they are not ready yet.
 
Finally I would like to add, that you can do further analysis with the SDR path:

View attachment 168635
Thanks again!
Both posts are very illuminating. The IEC-104 SCADA capture is a perfect real-world example of exactly what the UCSD study (dontlookup) described, and you found it with standard tools. That alone makes the point.

Your SDR screenshot raises an interesting question for me: I already have an SDRplay RSPdx. Are you using a LimeSDR or similar in that setup? And does your DATV demodulator approach in SDRangel work reliably for DVB-S2, or primarily DVB-S? I’m curious whether a software demodulation path via SDRangel could handle the kind of data transponders you’ve been capturing (the non-broadcast, low-symbol-rate links) or whether the hardware demodulator in a dedicated card is necessary for those.

Your broader point about whether dontlookup is worth the hardware investment is fair. My honest interest is less in finding sensitive data and more in understanding the full signal chain, all the way from raw RF capture through protocol parsing. The UCSD tool is interesting precisely because it reverse-engineered the proprietary encapsulation layers. But I take your point that there’s already a lot accessible without it.
 
I bought it brand new, direct from the UK importer of TBS devices. It has only been used a few times, generally for scanning an RF spectrum with either CrazyScan or EBSPro in the days before I bought a Promax Ranger field strength meter. The TBS 5952 was also used with EBSPro to run the tabular output frequency scan of satellites.

If you want me to connect it up to a dish to test it on any specific frequencies/satellites I will be able to do it on Saturday or Sunday at the earliest.
I also have some Prof DVB cards that might use the same chip? They are in brand new condition and in their original boxes.

I am located in Surrey, UK. Shipping to Sweden by a courier such as DHL Express should be easy to do.
Great, this sounds very promising.

You wrote “TBS5952”, but I assume you mean TBS5925.

No need to test it on a specific satellite. If it scanned correctly with CrazyScan it’s almost certainly in full working order.

Regarding the Prof DVB cards, which models are they? If they use the STV090x chip they could be equally useful for my purpose.

What price are you looking for, including DHL shipping to Sweden?
 
Last time I looked it still seemed rather limited and as it is pure python it is going rather slow. Some other tools like skyscraper (windows only) are currently probably better. You can use neumo-dmx (from my blindscan tools) to save GSE streams, but dontlookup can probably not use it, as it seems to rely (via a driver patch) on some direct card access that is only possible on usb cards.

I am building my own tool to parse such streams, but they are not ready yet.
Excellent and very helpful and clarifies the hardware constraint definitively. I had suspected the USB driver patch couldn’t be ported to PCIe, and you’ve confirmed it.

I’m very interested in neumo-dmx for saving GSE streams. Is there documentation on how to use it with an STV090x-based USB card like the TBS5925? And your own parsing tool, is that something you expect to release publicly at some point?

Supposed that I get hold of a TBS5925, does neumo-dmx currently support that card for GSE capture, or is it primarily tested on your stid135-based cards?

Thanks again
 
The DVB-S/S2 demodulation via SDR is mainly for amateur radio and here it is used with the Es'hail-2 satellite (25.9E).

You can demodulate DVB-S and DVB-S2 up to about 3MHz bandwidth and probably a bit beyond (just an estimate of mine).

I am fond of SDRangel for this purpose and it works well. I have used a HackRF One, Adalm Pluto and LibreSDR B220 for this purpose. I have a LibreSDR Pluto+ clone, too. They all work, but have one issue: they do not do blind scan. This means that in the absence of known modulation information, it is virtually impossible to guess the correct parameters, especially the SR.

But it does visualize potential transponders in a real time spectrum and you can lock to really low SR, which the TBS tuners struggle with - provided you know the parameters.

The IEC-104 SCADA capture is a perfect real-world example of exactly what the UCSD study (dontlookup) described, and you found it with standard tools.

Here I must correct you: "standard tools" is not the correct wording - I consider VMA Transport Stream Analyser a very specialized tool, which aims to be a reference tool for broadcast engineers. It is not free, either. Comparable tools are TSReader Pro (unfortunately the author is no longer with us), Dektec StreamXpert and 4T2 Content Analyser. The list is by no means complete and I am only mentioning Windows tools.

Also, you might want to take a look at my free online tools: Online Tools – VMA Broadcast

Here you will find several tools for TS analysis, among other tools.

For Linux you have of course deeptho's neumoDVB.
 
Back
Top