OBDX Development - Developer Tools and Suggestions

Programs / Tools / Scripts
User avatar
Tazzi
Posts: 3626
Joined: Thu May 17, 2012 10:53 am
cars: VE SS Ute
Location: WA

Re: OBDX Development - Developer Tools and Suggestions

Post by Tazzi »

In-Tech wrote:
Tazzi wrote:Im assuming the D8 is indicating the flash size in that frame. If thats the case, mine indicates:
C4 10 F5 31 A0 00 D8 39 01 9F
So this would suggest 224Kb also.
I'm going to run some more tests shortly, I wasn't really watching earlier. I am looking through notes I saved that made no sense at the time. I tend to keep those cuz maybe it will some day. Is that today? :) See if your 9f xor'd or subtracted from FF makes the seed/key work.
The 9F is the PWM Checksum, so ignore that one :)
I just removed it out of my previous message now to prevent confusion.
Your Local Aussie Reverse Engineer
Contact for Software/Hardware development and Reverse Engineering
Site:https://www.envyouscustoms.com
Mob:+61406 140 726
Image
In-Tech
Posts: 785
Joined: Mon Mar 09, 2020 6:35 am
Location: California

Re: OBDX Development - Developer Tools and Suggestions

Post by In-Tech »

I think we are getting pretty close to solving this. The J1850 standard is a mandated protocol for pretty much everything OBD2, the J1979 and J2190 are just subsets of that. The later CAN stuff can get a bit weird. I don't understand it all to say the least. I think they keep it vague and different docs so it's hard to research. Or, they have to for their own "devices" which is why OBD2 was invented...so you couldn't control the market.
Anyhoosit, still researching and trying stuff :)

p.s. To me, it's all packets, we just have to structure them correctly.
User avatar
Tazzi
Posts: 3626
Joined: Thu May 17, 2012 10:53 am
cars: VE SS Ute
Location: WA

Re: OBDX Development - Developer Tools and Suggestions

Post by Tazzi »

I have no words to describe just how much I hate dealing with antivirus companies for submitting software to be analyzed/whitelisted.
I have spent the last 5 and a bit hours emailing dozens of companies for multiple installers/exes that OBDX supplies... and it is painful.

Each company wants emails formatted in a specific way, then using specific words for a password protected zip file, along with various other details that must be labelled correctly.

Luckily, some absolute champion has made a list of all companies to contact: https://github.com/yaronelh/False-Positive-Center
The above absolutely sped up the process, since it skipped some of the middle man crap, and allows directly contacting support emails.

I have now made copy/paste templates for all 'main' companies so that I don't even have to second think for software review.

Any software devs out there, bookmark that link. Its worth it.
Your Local Aussie Reverse Engineer
Contact for Software/Hardware development and Reverse Engineering
Site:https://www.envyouscustoms.com
Mob:+61406 140 726
Image
In-Tech
Posts: 785
Joined: Mon Mar 09, 2020 6:35 am
Location: California

Re: OBDX Development - Developer Tools and Suggestions

Post by In-Tech »

Tazzi wrote:Yeah, thats alot more readable. They could be applying a basic encryption which make it look all garbage if monitoring a commercial tool.

If you have an ELM, you can set it up to monitor traffic using a serial terminal. Itll fail once it goes to highspeed, but we dont care about actually seeing highspeed, we just need to actual be able to go to highspeed!

Using an ELM, just need to use:
ATL1
ATH1
ATSP1
ATMA

This turns on the line feed, turns on headers, sets protocol to PWM and then finally monitors all traffic :thumbup:
I just logged a read with KESS so I'll look that over in a bit. But shoot, with my Y-cable and the elm, I should just be able to use the above commands and log it in hyperterminal. Shoot it's been 20+ years since I used Hyperterminal so I'll have to re-learn that. If anyone has a quick tutorial for that, it would save me some time :thumbup: Should I use my winXP laptop for hyperterminal while the win7 laptop dumps with HpTuner or should I try to run them both on the win7 lappy? Does win7 have hyperterminal or is there something else I should use?
In-Tech
Posts: 785
Joined: Mon Mar 09, 2020 6:35 am
Location: California

Re: OBDX Development - Developer Tools and Suggestions

Post by In-Tech »

Well that was easy.

00 05 10 04 00 08 0B 61 00 31
64 10 F1 31 A0 00 D8 01 00 BC
C4 F1 10 7F 31 A0 00 D8 00 91
64 10 F1 27 01 48<<<<<<<<<<<<<<<<<<<<<<Request Seed
C4 F1 10 67 01 0F 11 55 8B<<<<<<<<<<<<<Received Seed 0F 11 55
64 10 F1 27 02 C5 6D D5<<<<<<<<<<<<<<<<Send Key C5 6D
C4 F1 10 67 02 34 A3<<<<<<<<<<<<<<<<<<<Key accepted
C4 10 F1 35 01 04 00 00 20 00 92<<<<<<<Use Mode 35 to request read at address 2000
C4 F1 10 7F 35 01 04 00 00 0D<<<<<<<<<<Not sure I understand this because it reads back 6 bytes at a time
C4 F1 10 36 FF FA 27 FE FF FF 33<<<<<<<Received 6 bytes via Mode 36> FF FA 27 FE FF FF and verified in my bin file
C4 F1 10 36 FF FF FF FF FF FF 7B<<<<<<<verified
C4 F1 10 36 FF FF FF FF 60 20 E6<<<<<<<verified
C4 F1 10 36 63 20 66 20 69 20 4A<<<<<<<verified
C4 F1 10 36 6C 20 6F 20 72 20 B4<<<<<<<verified
C4 F1 10 36 75 20 78 20 7D 20 9E<<<<<<<verified
C4 F1 10 36 80 20 85 20 8A 20 8B etc etc till buffer was full
User avatar
Tazzi
Posts: 3626
Joined: Thu May 17, 2012 10:53 am
cars: VE SS Ute
Location: WA

Re: OBDX Development - Developer Tools and Suggestions

Post by Tazzi »

In-Tech wrote:Well that was easy.

00 05 10 04 00 08 0B 61 00 31
64 10 F1 31 A0 00 D8 01 00 BC
C4 F1 10 7F 31 A0 00 D8 00 91
64 10 F1 27 01 48<<<<<<<<<<<<<<<<<<<<<<Request Seed
C4 F1 10 67 01 0F 11 55 8B<<<<<<<<<<<<<Received Seed 0F 11 55
64 10 F1 27 02 C5 6D D5<<<<<<<<<<<<<<<<Send Key C5 6D
C4 F1 10 67 02 34 A3<<<<<<<<<<<<<<<<<<<Key accepted
C4 10 F1 35 01 04 00 00 20 00 92<<<<<<<Use Mode 35 to request read at address 2000
C4 F1 10 7F 35 01 04 00 00 0D<<<<<<<<<<Not sure I understand this because it reads back 6 bytes at a time
C4 F1 10 36 FF FA 27 FE FF FF 33<<<<<<<Received 6 bytes via Mode 36> FF FA 27 FE FF FF and verified in my bin file
C4 F1 10 36 FF FF FF FF FF FF 7B<<<<<<<verified
C4 F1 10 36 FF FF FF FF 60 20 E6<<<<<<<verified
C4 F1 10 36 63 20 66 20 69 20 4A<<<<<<<verified
C4 F1 10 36 6C 20 6F 20 72 20 B4<<<<<<<verified
C4 F1 10 36 75 20 78 20 7D 20 9E<<<<<<<verified
C4 F1 10 36 80 20 85 20 8A 20 8B etc etc till buffer was full
Well that was unexpected, looks like you have a 3byte seed... with a 2byte key? This just gets more confusing :lol:

Also looks like it doesn't use highspeed communication either. It also seems to get the 7F 31 error that I get too.
Your Local Aussie Reverse Engineer
Contact for Software/Hardware development and Reverse Engineering
Site:https://www.envyouscustoms.com
Mob:+61406 140 726
Image
In-Tech
Posts: 785
Joined: Mon Mar 09, 2020 6:35 am
Location: California

Re: OBDX Development - Developer Tools and Suggestions

Post by In-Tech »

Aha, C4 10 F1 35 01 04 00 00 20 00 92<<<<<<<Use Mode 35 to request read at address 2000...04 00 is the block size (1024 max)

Yes, it appears to just use Mode35/36
I will do some more logging later and then on the other EecV's I have. Shoot if it just uses these modes, and if we can figure out the seed/key issue it shouldn't be too hard to port a read/write into PcmHammer :) That would be some cool freeware :thumbup: Write appears to be Mode34
In-Tech
Posts: 785
Joined: Mon Mar 09, 2020 6:35 am
Location: California

Re: OBDX Development - Developer Tools and Suggestions

Post by In-Tech »

00 05 10 04 00 08 0B 61 00 31<<<<<<<<<<<appears to be a status message
I'll look deeper to see if that means FEPS is active.
In-Tech
Posts: 785
Joined: Mon Mar 09, 2020 6:35 am
Location: California

Re: OBDX Development - Developer Tools and Suggestions

Post by In-Tech »

Hiya,
Win7 and newer doesn't have hyperterminal. I used my winXp lappy to run that and then the win7 for the reading. It worked fine but I hate to have two laptops with the grounds tied, danger. I have PuTTY installed on the win7 laptop now and seems to work well. It is supposed to have/allow a huge buffer, I'll be checking later.

Is there any other things I should do to help? I'll log the scanner software too.
User avatar
Tazzi
Posts: 3626
Joined: Thu May 17, 2012 10:53 am
cars: VE SS Ute
Location: WA

Re: OBDX Development - Developer Tools and Suggestions

Post by Tazzi »

In-Tech wrote:Hiya,
Win7 and newer doesn't have hyperterminal. I used my winXp lappy to run that and then the win7 for the reading. It worked fine but I hate to have two laptops with the grounds tied, danger. I have PuTTY installed on the win7 laptop now and seems to work well. It is supposed to have/allow a huge buffer, I'll be checking later.

Is there any other things I should do to help? I'll log the scanner software too.
Really we just need as many seed/key combinations as possible. So we can test it with the algos I pull out. Or, so i can try run numbers through the security DLL to figure that out also.

I think if I simulate to IDS a 'valid' response for the mode 31 message, it might just proceed forward and seed a seed/key request. Ill have to update my R&D software to accommodate for PWM. That way I should be able to then intercept calls made by IDS into the DLL.

Also, I believe I am seeing a trend in the algo options. It looks like it checks how many bytes are passed in for a seed, and then how many are being sent out. Certain algos indicate 2 and others 3.
So I would need to find one that has 2 bytes in, 3 bytes out for the EECV your setup seems to be using.

This would all be so much easier if I could just get IDS to work. :lol:
Your Local Aussie Reverse Engineer
Contact for Software/Hardware development and Reverse Engineering
Site:https://www.envyouscustoms.com
Mob:+61406 140 726
Image