“The first thing that happens is alignment. The car is driven over an alignment pit with operators under the car doing the work with about 30 individual checks. The next step is Dynamic Vehicle Test (‘DVT’). Over 8,000 checks are done in DVT. The car will check a lot of things itself. In here we communicate with the vehicle and are looking to find things like are the antennas working properly for OnStar.”
Check out the video at the bottom of the page. Skip to 16:30. They show the DVT process.
Thats something different. Apparently GM media and GM engineering use the same acronym, but for different things.....I guess they dont communicate much lol.
GM engineering, their "DVT" is Diagnostic Vehicle Tests. And its what I described, secret elevated permissions for mode AE crap that doesnt have the protections that are otherwise implemented in GDS to prevent dealer techs from doing something harmful. The engineering DVT stuff (device control) is only used by the engineers during development.
In GM media, their "DVT" is "dynamic vehicle test", and its just a catch-all term for what they do to every car as it rolls off the assembly line.
dmaxben wrote:Tazzi, just wondering if you were able to try any of those other algorithms?
Well none seemed to match your exact pair, although this could be GM trickery since I dont have a 5byte BCM on the bench currently, and am using an IOB radio but requesting different algos.. this could be the issue
kur4o wrote:
Why not unlock with regular key and than read eeprom memory and extract the dvt pairs from there.
Thats a great idea.. although from my research, only way I can dump the eeprom is by generating a custom kernel for read/writing. I killed the last 5byte BCM attempting that
Your Local Aussie Reverse Engineer
Contact for Software/Hardware development and Reverse Engineering
Site:https://www.envyouscustoms.com
Mob:+61406 140 726
dmaxben wrote:Tazzi, just wondering if you were able to try any of those other algorithms?
Well none seemed to match your exact pair, although this could be GM trickery since I dont have a 5byte BCM on the bench currently, and am using an IOB radio but requesting different algos.. this could be the issue
kur4o wrote:
Why not unlock with regular key and than read eeprom memory and extract the dvt pairs from there.
Thats a great idea.. although from my research, only way I can dump the eeprom is by generating a custom kernel for read/writing. I killed the last 5byte BCM attempting that
Correct, you'd need some custom bootloader or something to get the BCM to dump EEPROM contents via CAN.
Thats too bad that the 5 byte keys ending in 0C and 01 arent working...
dmaxben wrote:
Correct, you'd need some custom bootloader or something to get the BCM to dump EEPROM contents via CAN.
Thats too bad that the 5 byte keys ending in 0C and 01 arent working...
I believe its because Im not using a proper BCM on the bench. I might be able to validate in a few days.
Your Local Aussie Reverse Engineer
Contact for Software/Hardware development and Reverse Engineering
Site:https://www.envyouscustoms.com
Mob:+61406 140 726
Your Local Aussie Reverse Engineer
Contact for Software/Hardware development and Reverse Engineering
Site:https://www.envyouscustoms.com
Mob:+61406 140 726
I would absolutely love elevated device control, GDS is extremely frustrating. There are so many times I want to control something but it won't allow it.