Seed key brute force program.
-
- Posts: 695
- Joined: Thu Feb 13, 2020 11:32 pm
- cars: Mainly GM trucks, a Cruze and an Equinox for dailys..
Re: Seed key brute force program.
So if 4610 did not unlock it either the ecu is not an E38 or it's been tunerlocked or programmed with an OS mismatch. My guess is tunerlock since the seed looks like a valid seed.
No, there is no easy way to get around unlocking it. That's why I wrote the program to sit there for up to 7 days finding the key. Mine was because I screwed up and wrote an OS mismatch but this will work for tunerlocked ecm's as well..
Did you let it run until it found the key? Looks like you were using PowerPCM and that lets you enter a custom key in the box there where it says E38, there's E38,E67 and @ffff. Just replace the ffff with the key this bruteforce tool finds.. It can then unlock it and read it.
Can't fix the tunerlock though, you need a program that can write to the eeprom segments. Only cloning or write security(hpt) does that..
No, there is no easy way to get around unlocking it. That's why I wrote the program to sit there for up to 7 days finding the key. Mine was because I screwed up and wrote an OS mismatch but this will work for tunerlocked ecm's as well..
Did you let it run until it found the key? Looks like you were using PowerPCM and that lets you enter a custom key in the box there where it says E38, there's E38,E67 and @ffff. Just replace the ffff with the key this bruteforce tool finds.. It can then unlock it and read it.
Can't fix the tunerlock though, you need a program that can write to the eeprom segments. Only cloning or write security(hpt) does that..
Re: Seed key brute force program.
yes the program still works it tries the keys. my ecu is e38 i am sure of that. only the previous owner put a lock with hptuners. my problem is to open it. hptuners allows me to log in with custom key 0x... i hope it will open when i find the right key? then i can remove the password i guess? i tried with 6410 that didn't work. i hope to get a new key with the program you made.ironduke wrote: ↑Thu Dec 19, 2024 9:56 pm So if 4610 did not unlock it either the ecu is not an E38 or it's been tunerlocked or programmed with an OS mismatch. My guess is tunerlock since the seed looks like a valid seed.
No, there is no easy way to get around unlocking it. That's why I wrote the program to sit there for up to 7 days finding the key. Mine was because I screwed up and wrote an OS mismatch but this will work for tunerlocked ecm's as well..
Did you let it run until it found the key? Looks like you were using PowerPCM and that lets you enter a custom key in the box there where it says E38, there's E38,E67 and @ffff. Just replace the ffff with the key this bruteforce tool finds.. It can then unlock it and read it.
Can't fix the tunerlock though, you need a program that can write to the eeprom segments. Only cloning or write security(hpt) does that..
Re: Seed key brute force program.
The scan ended while I was replying to you. And the key was found, but when I try to log in with hptuners, it gives an error like this. It reads the computer and logs in, but it does not read the file, I cannot see the software.
1. : https://i.ibb.co/q7x16JW/as-1.jpg
2. : https://i.ibb.co/Z8Bckf7/as-3.jpg
3. : https://i.ibb.co/PQqj6Zh/as-2.jpg
1. : https://i.ibb.co/q7x16JW/as-1.jpg
2. : https://i.ibb.co/Z8Bckf7/as-3.jpg
3. : https://i.ibb.co/PQqj6Zh/as-2.jpg
-
- Posts: 695
- Joined: Thu Feb 13, 2020 11:32 pm
- cars: Mainly GM trucks, a Cruze and an Equinox for dailys..
Re: Seed key brute force program.
OK, so you were able to read it at least.. you need to use the PowerPCM program to read it out as a bin to at least get the file.
hpt know's it's tunerlocked and won't let you touch it. There are ways around it I believe but I'm not touching them.
What is your end goal with this? You can modify and write back calibration segments with powerpcm program but cannot write OS or eeprom segments with that.
Right now I don't know if a free use program that lets you overwrite the eeprom segment to put the key back to stock.
hpt know's it's tunerlocked and won't let you touch it. There are ways around it I believe but I'm not touching them.
What is your end goal with this? You can modify and write back calibration segments with powerpcm program but cannot write OS or eeprom segments with that.
Right now I don't know if a free use program that lets you overwrite the eeprom segment to put the key back to stock.
Re: Seed key brute force program.
My aim with this is to unlock the ecu code, delete the software and upload my own software, I made more efficient settings. I produced power and torque. That's why I don't want my ecuto be trash.ironduke wrote: ↑Thu Dec 19, 2024 10:23 pm OK, so you were able to read it at least.. you need to use the PowerPCM program to read it out as a bin to at least get the file.
hpt know's it's tunerlocked and won't let you touch it. There are ways around it I believe but I'm not touching them.
What is your end goal with this? You can modify and write back calibration segments with powerpcm program but cannot write OS or eeprom segments with that.
Right now I don't know if a free use program that lets you overwrite the eeprom segment to put the key back to stock.
For me, resetting the ecu is enough. I can reprogram it with Hptuners. I just need to recover the ecu password. I don't want the ecu to be trash.
-
- Posts: 695
- Joined: Thu Feb 13, 2020 11:32 pm
- cars: Mainly GM trucks, a Cruze and an Equinox for dailys..
Re: Seed key brute force program.
Do you have the original unmodified/unlocked hpt file? If so you should be able to type in that key and write security.. That writes the eeprom segments overwriting the vin, serial number, seed and key, etc.. You need your file though, not some random one.selqs wrote: ↑Thu Dec 19, 2024 10:42 pmMy aim with this is to unlock the ecu code, delete the software and upload my own software, I made more efficient settings. I produced power and torque. That's why I don't want my ecuto be trash.ironduke wrote: ↑Thu Dec 19, 2024 10:23 pm OK, so you were able to read it at least.. you need to use the PowerPCM program to read it out as a bin to at least get the file.
hpt know's it's tunerlocked and won't let you touch it. There are ways around it I believe but I'm not touching them.
What is your end goal with this? You can modify and write back calibration segments with powerpcm program but cannot write OS or eeprom segments with that.
Right now I don't know if a free use program that lets you overwrite the eeprom segment to put the key back to stock.
For me, resetting the ecu is enough. I can reprogram it with Hptuners. I just need to recover the ecu password. I don't want the ecu to be trash.
With your vin and serial number I can make you a stock file on the bench and put in your serial, then read it out.. That's one option..
Re: Seed key brute force program.
ironduke wrote: ↑Thu Dec 19, 2024 11:14 pmDo you have the original unmodified/unlocked hpt file? If so you should be able to type in that key and write security.. That writes the eeprom segments overwriting the vin, serial number, seed and key, etc.. You need your file though, not some random one.selqs wrote: ↑Thu Dec 19, 2024 10:42 pmMy aim with this is to unlock the ecu code, delete the software and upload my own software, I made more efficient settings. I produced power and torque. That's why I don't want my ecuto be trash.ironduke wrote: ↑Thu Dec 19, 2024 10:23 pm OK, so you were able to read it at least.. you need to use the PowerPCM program to read it out as a bin to at least get the file.
hpt know's it's tunerlocked and won't let you touch it. There are ways around it I believe but I'm not touching them.
What is your end goal with this? You can modify and write back calibration segments with powerpcm program but cannot write OS or eeprom segments with that.
Right now I don't know if a free use program that lets you overwrite the eeprom segment to put the key back to stock.
For me, resetting the ecu is enough. I can reprogram it with Hptuners. I just need to recover the ecu password. I don't want the ecu to be trash.
With your vin and serial number I can make you a stock file on the bench and put in your serial, then read it out.. That's one option..
Unfortunately, I don’t have an original file like that. Thanks to you, I found the key, but I tried a few more times and couldn’t read it at all with HP Tuners. I don’t know what to do; I can’t think of anything.
-
- Posts: 695
- Joined: Thu Feb 13, 2020 11:32 pm
- cars: Mainly GM trucks, a Cruze and an Equinox for dailys..
Re: Seed key brute force program.
If I remember right you have the powerpcm program and a J2534 device that works with it. Use that and type in the key and read the ecm and save the bin.
Post up or send me the bin. From there I can fix the eeprom segment to the correct key and write it to an ecm on the bench and then read it back with hpt and send you the file.
Post up or send me the bin. From there I can fix the eeprom segment to the correct key and write it to an ecm on the bench and then read it back with hpt and send you the file.
Re: Seed key brute force program.
Thank you, I sent the file privately.ironduke wrote: ↑Tue Dec 24, 2024 5:54 am If I remember right you have the powerpcm program and a J2534 device that works with it. Use that and type in the key and read the ecm and save the bin.
Post up or send me the bin. From there I can fix the eeprom segment to the correct key and write it to an ecm on the bench and then read it back with hpt and send you the file.
-
- Posts: 695
- Joined: Thu Feb 13, 2020 11:32 pm
- cars: Mainly GM trucks, a Cruze and an Equinox for dailys..
Re: Seed key brute force program.
Send, modified and completed.. Send reply back with instructions. Let me know how it works out.selqs wrote: ↑Fri Dec 27, 2024 11:50 pmThank you, I sent the file privately.ironduke wrote: ↑Tue Dec 24, 2024 5:54 am If I remember right you have the powerpcm program and a J2534 device that works with it. Use that and type in the key and read the ecm and save the bin.
Post up or send me the bin. From there I can fix the eeprom segment to the correct key and write it to an ecm on the bench and then read it back with hpt and send you the file.
edited.. Caught a mistake!! I edited the seed to match the key instead of the other way around. I brain cramped a bit.. It'll still work fine, just could be an issue if the secondary unlock 27 03 command is ever used for anything which I doubt you'll ever run into.. Already sent corrected file.