Colorado / H3 BCM hacking
-
04colyZQ8
- Posts: 536
- Joined: Thu Jan 16, 2014 2:41 am
- cars: 2004 Colorado 4.8L swap
86/90 Jimmy 6.5L diesel swap
80 Chevrolet Silverado TBI swap
88dodge W100 LPG conversion
Re: Colorado / H3 BCM hacking
And I see GMT 355 in the code , that does not seem right?
You do not have the required permissions to view the files attached to this post.
-
04colyZQ8
- Posts: 536
- Joined: Thu Jan 16, 2014 2:41 am
- cars: 2004 Colorado 4.8L swap
86/90 Jimmy 6.5L diesel swap
80 Chevrolet Silverado TBI swap
88dodge W100 LPG conversion
Re: Colorado / H3 BCM hacking
Also I can't find where the function search is:(
-
Gatecrasher
- Posts: 435
- Joined: Fri Apr 24, 2020 8:09 pm
Re: Colorado / H3 BCM hacking
Dammit. I messed up. Sorry. Close any active projects and do File > Restore Project.
-
bbmike
- Posts: 48
- Joined: Thu Apr 02, 2015 3:10 am
- cars: Too many!!
Re: Colorado / H3 BCM hacking
04colyZQ8 wrote:and for the 04-08 BCM Ram .. it is located at 2000h or 8192 decimal, does that jive with the TMS370 as well?
Yes. Ram starts a 0x2000. I did some checks and the first instruction is to load location 0x001A into a register. 0x001A is the system reset status register.
-
04colyZQ8
- Posts: 536
- Joined: Thu Jan 16, 2014 2:41 am
- cars: 2004 Colorado 4.8L swap
86/90 Jimmy 6.5L diesel swap
80 Chevrolet Silverado TBI swap
88dodge W100 LPG conversion
Re: Colorado / H3 BCM hacking
Looking great! Did you mean "C2SI_" instead of "C2_" ?Gatecrasher wrote:Here's my work thus far. It's mostly diagnostic stuff. Go into the function window and search for "C2_". That's what I used to prefix the class 2 stuff. My idea was to figure out the known diagnostics, then backtrack from there into the memory used for the DTCs. Once I figured out what memory was used for each DTC, I could find the code that wrote those values and from there, find the IO and functionality for each system that had DTCs associated with it. That was the idea anyway. I got lost in the multitude of bytes used for each DTC, and I couldn't come at it from the hardware side since we don't have an accurate user's manual for the chip.
The board won't allow Ghidra .gar files, so just take the .txt extension off.
Good luck.
-
04colyZQ8
- Posts: 536
- Joined: Thu Jan 16, 2014 2:41 am
- cars: 2004 Colorado 4.8L swap
86/90 Jimmy 6.5L diesel swap
80 Chevrolet Silverado TBI swap
88dodge W100 LPG conversion
Re: Colorado / H3 BCM hacking
anyway, we can read the CS2 from the processor at fff7d000 using mode 35, or can we write a program upload to ram that, dumps these to another location in ram, and then read that dump out via mode 35?
Need to know what is at those locations
Need to know what is at those locations
-
04colyZQ8
- Posts: 536
- Joined: Thu Jan 16, 2014 2:41 am
- cars: 2004 Colorado 4.8L swap
86/90 Jimmy 6.5L diesel swap
80 Chevrolet Silverado TBI swap
88dodge W100 LPG conversion
Re: Colorado / H3 BCM hacking
@ gatecrasher.. your comments are incredible!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
Anyway could we not add the ram now that we know what it is, so that it stops saying invalid addresses?
Anyway could we not add the ram now that we know what it is, so that it stops saying invalid addresses?
-
Gatecrasher
- Posts: 435
- Joined: Fri Apr 24, 2020 8:09 pm
Re: Colorado / H3 BCM hacking
C2SI is the class 2 serial interface registers. If you go back to the memory map I posted on the 15th, you should be able to read them using mode 35 requests to 0xF7D000 to 0xF7D0FF. Convert those to decimal for my python script and tell it to read 256 bytes.
I don't know how much good it'll do. We don't have a user manual to break down which register is which, and if you read them while sending mode 35 requests, you'll only see the contents of those requests. It'd be like listening to a phone that just repeats your own words back to you. It might help understand the layout a little more, but I don't think it'll help much with the normal mode stuff. That work is done elsewhere. Hence the C2_ subroutines I labeled.
RAM is already labeled. Go to windows > memory map. It's 0x8000000 to 0x8001FFF.
I don't know how much good it'll do. We don't have a user manual to break down which register is which, and if you read them while sending mode 35 requests, you'll only see the contents of those requests. It'd be like listening to a phone that just repeats your own words back to you. It might help understand the layout a little more, but I don't think it'll help much with the normal mode stuff. That work is done elsewhere. Hence the C2_ subroutines I labeled.
RAM is already labeled. Go to windows > memory map. It's 0x8000000 to 0x8001FFF.
-
04colyZQ8
- Posts: 536
- Joined: Thu Jan 16, 2014 2:41 am
- cars: 2004 Colorado 4.8L swap
86/90 Jimmy 6.5L diesel swap
80 Chevrolet Silverado TBI swap
88dodge W100 LPG conversion
Re: Colorado / H3 BCM hacking
I see now the registers and ram are indeed labeled. This is amazing you did so much work!!Gatecrasher wrote:C2SI is the class 2 serial interface registers. If you go back to the memory map I posted on the 15th, you should be able to read them using mode 35 requests to 0xF7D000 to 0xF7D0FF. Convert those to decimal for my python script and tell it to read 256 bytes.
I don't know how much good it'll do. We don't have a user manual to break down which register is which, and if you read them while sending mode 35 requests, you'll only see the contents of those requests. It'd be like listening to a phone that just repeats your own words back to you. It might help understand the layout a little more, but I don't think it'll help much with the normal mode stuff. That work is done elsewhere. Hence the C2_ subroutines I labeled.
RAM is already labeled. Go to windows > memory map. It's 0x8000000 to 0x8001FFF.
Looks confusing but not what you have done!!
I’m trying to use the dtc or pid to search for the remote fob lock and and unlock:)
I could attempt a mode 35 read at the address range of the module it comes on on.
Any ideas what module?
I tried following dtc63_b3152
Door lock
Or pid210E
But no lock tracing them back to a locking segment or
Function that seems like it might control locks.
How did you trace the lights function from there dtcs?
Amazing work you did
-
04colyZQ8
- Posts: 536
- Joined: Thu Jan 16, 2014 2:41 am
- cars: 2004 Colorado 4.8L swap
86/90 Jimmy 6.5L diesel swap
80 Chevrolet Silverado TBI swap
88dodge W100 LPG conversion
Re: Colorado / H3 BCM hacking
Does mibADC control the inputs?