I don't know too too much about satellite receivers specifically, but if they're anything like other stuff I've done firmware hacking on, a good place to start would probably be to dump the bootloader from the flash on the board, if such a thing exists, and figure out how it decrypts the bin. I only have one box right now and I'm using it so I really don't want to risk damaging it, so I'm not sure if I'll hack at mine at all.