04colyZQ8 wrote: Sun Sep 14, 2025 2:57 am
2701 = 3412 which I think I was dumb in thinking this was a seed.. but maybe it is just saying not supported? Mode 34 with 7F as 12 should mean not supported correct?
I think that is a seed..
What is the reply from 2701?? The whole message..
I am not sure what you mean mode 34 with a 7f? a 7F error reply from a 2701 request would not have a 34 in it..
Have you programed the telematics module, do you have the utility frile from sps cache folder?
It reported 3412 as a seed…
00 00 06 4D 04 67 01 34 12
It’s been a while but I recall neg response as being 12, for seed and key requests
I think was the response. The sps cache I have and programming log it didn’t unlock it. I have never seen that before it just requested programming mode then started using 3B dids to write. That’s it.
If it was a failure you'd get 64D 03 7F 27 xx where xx is the reason for the failure.
67 is a positive response. That's a seed.
There's no need to guess with this stuff. It's extremely well defined in GMW3110. Step back, take a deep breath, and read it. You're fighting against yourself as much as the module at this point.
Gatecrasher wrote: Tue Sep 16, 2025 1:39 pm
If it was a failure you'd get 64D 03 7F 27 xx where xx is the reason for the failure.
67 is a positive response. That's a seed.
There's no need to guess with this stuff. It's extremely well defined in GMW3110. Step back, take a deep breath, and read it. You're fighting against yourself as much as the module at this point.
Fair enough:) But the problem still remains that apart from brute force guessing they key maybe quite difficult!
Unless the same part number has a different file from sps that actually unlocks it?
Gatecrasher wrote: Tue Sep 16, 2025 1:39 pm
If it was a failure you'd get 64D 03 7F 27 xx where xx is the reason for the failure.
67 is a positive response. That's a seed.
There's no need to guess with this stuff. It's extremely well defined in GMW3110. Step back, take a deep breath, and read it. You're fighting against yourself as much as the module at this point.
Fair enough:) But the problem still remains that apart from brute force guessing they key maybe quite difficult!
Unless the same part number has a different file from sps that actually unlocks it?
I Just checked some utility files for the onstar module, yup.. Some of the older ones have no unlock step.. I did not know that.
Patcher can try force unlock by scrolling thru all the algo's. Kur40 has posted a script here on another topic somewhere. it would have to be changed for a VCIM/Telematics module but it should work, I'll see if I can find it.
Ok thanks I was going to brute force it myself using a while loop!
I got a mc2515 with TJA1050 and Arduino nano. And it works quite well for high speed Can. Going to replace the transceiver now with a TH8056 and try single wire Can.
Managed to build my own device! Using a Mcp2515, and Ls can transceiver. Then made a custom program over uart. I sniffed the commands and this is what I made on my computer. The lock and unlock work. Probably the lights and alarm work. The remote start is most likely not going to work.
I need to get the chevy app to show remote start on order to reverse engineer it
You do not have the required permissions to view the files attached to this post.
Looks like your fairly good at reading logs.. Below is an RVS start.. low speed was not doing anything, asleep until I used my onstart app to remote start the vehicle. Maybe that'll help ya.
23.equinox.low.speed.Onstar-RVS.test.log.txt
You do not have the required permissions to view the files attached to this post.