This is my log using reset function in tech2, im guessing if FE changes with correct pin it'l spit out a response based on the AA DPID Schedule poll rate. Looks like FE is packed with PIDS 1644, 1643?
Iv got a few security sets laying about, Ill hook them up tonight and reset/link ect and see what the hell is going on.
Your Local Aussie Reverse Engineer
Contact for Software/Hardware development and Reverse Engineering
Site:https://www.envyouscustoms.com
Mob:+61406 140 726
On a programmed unit, it says Security Code Programmed YES, and Immobiliser Function Programmed YES.
When its successful for resetting...
7E0 10 08 2C FE 16 44 16 43
7E8 30 20 02 2C 7F 7F 7F 7F
7E0 21 11 07 55 55 55 55 55
7E8 02 6C FE 00 00 00 00 00
7E0 03 AA 04 FE 55 55 55 55 -all above is setting up dpids and then executing
5E8 FE 08 A1 42 00 0C 00 00 -live data
7E0 07 AE 7D 08 33 32 30 37 -request reset, immo 3207
7E8 02 EE 7D 00 00 00 00 00 - accepted.
With that now reset, we now have a DTC of "No transponder key programmed", whereas on the rooted unit, it says "incorrect transponder key".
It also now says Security Code Programmed NO and Immobiliser Function Programmed NO.
If I now try to reset after it has been reset, the following occurs:
7E0 10 08 2C FE 16 44 16 43
7E8 30 20 02 7C FF FF FF F9
7E0 21 11 07 55 55 55 55 55
7E8 02 6C FE 00 00 00 00 00
7E0 03 AA 04 FE 55 55 55 55
5E8 FE 02 A0 42 00 0C 00 00
And then reports "System already reset"
Your Local Aussie Reverse Engineer
Contact for Software/Hardware development and Reverse Engineering
Site:https://www.envyouscustoms.com
Mob:+61406 140 726
Your Local Aussie Reverse Engineer
Contact for Software/Hardware development and Reverse Engineering
Site:https://www.envyouscustoms.com
Mob:+61406 140 726
Your Local Aussie Reverse Engineer
Contact for Software/Hardware development and Reverse Engineering
Site:https://www.envyouscustoms.com
Mob:+61406 140 726
Now looking back at the el'fucked unit, when going to reset and looking at the live data request, it reports:
5E8 FE 40 F0 42 00 0C 00 00
That second byte there is 0x40, whereas on the other unit, its 0xA0 when its reset. And 0xA1 when programmed.
So.. this unit has learnt the first key its seen, and a non-possible immobiliser which now reports as "not programmed" but has infact programmed as 0x0000. *sigh*.
So only way I can think of, is trying to do some sort of dump of the firmware and write back into it.
For shits and gigs, I just tried to program just the ECM with the other PIM/BCM.. and shes still a no go.
Your Local Aussie Reverse Engineer
Contact for Software/Hardware development and Reverse Engineering
Site:https://www.envyouscustoms.com
Mob:+61406 140 726
Right.. so appears something called "carprog" should be able to attack these ecus.. looks like it talks about some sort of 'k-line' which I wasnt aware of on these ecus.
Looks like I do actually have a carprog here.. so gonna installing into a virtual machine and give it a crack
Your Local Aussie Reverse Engineer
Contact for Software/Hardware development and Reverse Engineering
Site:https://www.envyouscustoms.com
Mob:+61406 140 726
Tazzi wrote:Now looking back at the el'fucked unit, when going to reset and looking at the live data request, it reports:
5E8 FE 40 F0 42 00 0C 00 00
That second byte there is 0x40, whereas on the other unit, its 0xA0 when its reset. And 0xA1 when programmed.
So.. this unit has learnt the first key its seen, and a non-possible immobiliser which now reports as "not programmed" but has infact programmed as 0x0000. *sigh*.
So only way I can think of, is trying to do some sort of dump of the firmware and write back into it.
For shits and gigs, I just tried to program just the ECM with the other PIM/BCM.. and shes still a no go.
is that 7E8 or 5E8? either way That's very interesting, As FE 40 is the bit we set to on for "Theft Deterrent EEPROM Access"
Ive looked at carprog before, it's needs there proprietary cable of coarse, but yes ive seen a video somewhere of it doing a Pin code read, not sure what it does but over several minutes, maybe perhaps uploading some code to read memory and spit out the result through a PID or something?
The1 wrote:
is that 7E8 or 5E8? either way That's very interesting, As FE 40 is the bit we set to on for "Theft Deterrent EEPROM Access"
Ive looked at carprog before, it's needs there proprietary cable of coarse, but yes ive seen a video somewhere of it doing a Pin code read, not sure what it does but over several minutes, maybe perhaps uploading some code to read memory and spit out the result through a PID or something?
Thats correct, 5E8.
When its outputting DPID data, it will be on the 5E8 ID.
The FE is the DPID frame, and the data after that is corresponding to the PIDs it had setup in the DPID.
Your Local Aussie Reverse Engineer
Contact for Software/Hardware development and Reverse Engineering
Site:https://www.envyouscustoms.com
Mob:+61406 140 726