Uplander/montana/relay locked bcm
-
Gatecrasher
- Posts: 435
- Joined: Fri Apr 24, 2020 8:09 pm
Re: Uplander/montana/relay locked bcm
As far as disassembly goes, I'd skip the emulator executable entirely and just load the Tech2 card into Ghidra under the original Tech 2 CPU. Probably some Motorola MC-whatever. If you want to watch live RAM, maybe try to figure out where the emulated Tech2 RAM lives within the emulator's greater memory space. That could be interesting to watch live via hxd or OllyDbg or something. It'd be almost like having an in-circuit debugger for an actual Tech2.
-
04colyZQ8
- Posts: 536
- Joined: Thu Jan 16, 2014 2:41 am
- cars: 2004 Colorado 4.8L swap
86/90 Jimmy 6.5L diesel swap
80 Chevrolet Silverado TBI swap
88dodge W100 LPG conversion
Re: Uplander/montana/relay locked bcm
Yes great idea but what processor does a tech 2 use? I don’t have one so …
-
Gatecrasher
- Posts: 435
- Joined: Fri Apr 24, 2020 8:09 pm
-
04colyZQ8
- Posts: 536
- Joined: Thu Jan 16, 2014 2:41 am
- cars: 2004 Colorado 4.8L swap
86/90 Jimmy 6.5L diesel swap
80 Chevrolet Silverado TBI swap
88dodge W100 LPG conversion
Re: Uplander/montana/relay locked bcm
For the win always to my rescue:) virtual beer for you!!
Does ghidra have the that processor?
-
04colyZQ8
- Posts: 536
- Joined: Thu Jan 16, 2014 2:41 am
- cars: 2004 Colorado 4.8L swap
86/90 Jimmy 6.5L diesel swap
80 Chevrolet Silverado TBI swap
88dodge W100 LPG conversion
Re: Uplander/montana/relay locked bcm
Ghidra does not have that processor what is a close one to try?
-
Gatecrasher
- Posts: 435
- Joined: Fri Apr 24, 2020 8:09 pm
Re: Uplander/montana/relay locked bcm
You might want to check this out.
https://github.com/NationalSecurityAgen ... ssues/1244
That almost has to be the same NSFW that's a member here.
https://github.com/NationalSecurityAgen ... ssues/1244
That almost has to be the same NSFW that's a member here.
-
antus
- Site Admin
- Posts: 10015
- Joined: Sat Feb 28, 2009 10:34 am
- cars: TX Gemini 2L Twincam 8psi
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B
Subaru WRX 2007
Re: Uplander/montana/relay locked bcm
The 68332 is the same cpu in the P01 P59 and most the VPW PCMs. Ida and Ghidra support enough of it. Look at the videos about RE of the P01 and its probably pretty similar. But you'll need to figure out the ram and rom mapping. If its similar to the PCMs, ROM will be from 0x00000 but ram could be anywhere. Guessing FF8000 because its used a lot in the family, but it could start higher or lower. Also will be a couple of addresses for hardware access, but you can probably ignore that for what you need, its not like you are writing a flash kernel that needs to talk to a DLC communications chip or flash chip state machine.
There is a filesystem on the card, I wrote a tool in C that dumps the files from it. You can hit CTRL+D (hidden command) to see the card directory in tech2win. I'll see if I can find the source for the file dumper. It'll be files on the card not the whole image to load in to ida or ghidra and it'll probably load other library files in to ram as it runs, so you'll need to figure out how to handle that.
There is a filesystem on the card, I wrote a tool in C that dumps the files from it. You can hit CTRL+D (hidden command) to see the card directory in tech2win. I'll see if I can find the source for the file dumper. It'll be files on the card not the whole image to load in to ida or ghidra and it'll probably load other library files in to ram as it runs, so you'll need to figure out how to handle that.
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396
-
antus
- Site Admin
- Posts: 10015
- Joined: Sat Feb 28, 2009 10:34 am
- cars: TX Gemini 2L Twincam 8psi
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B
Subaru WRX 2007
Re: Uplander/montana/relay locked bcm
Here it is. gcc -o t2rip t2tip.c to compile with gnu c from a command line. Quick and dirty, bin file name is hard coded. You can probably clean it up, but its enough to get the files out on to a PC. Make a directory "bin" where you run it, and it'll put the files in there.
Code: Select all
// t2rip
// antus @ pcmhacking.net
// Licensed under the GPL V2
#include <stdio.h>
void dump(char *fn, int start, int length);
FILE *bin;
FILE *out;
main()
{
int i;
int page;
unsigned int offset;
unsigned int size;
unsigned int sum;
unsigned char entry[0x26];
if ((bin=fopen("Holden_157.bin", "rb"))==NULL) {
printf("Couldnt open bin\n");
return -1;
}
for (i=0; i<256; i++) {
fseek (bin, 0x18+(i*0x26), SEEK_SET);
fread(entry, 0x26, 1, bin);
if (entry[0]==0xFF) break;
page=entry[15];
offset =entry[16]<<24;
offset+=entry[17]<<16;
offset+=entry[18]<<8;
offset+=entry[19];
size =entry[20]<<24;
size+=entry[21]<<16;
size+=entry[22]<<8;
size+=entry[23];
offset-=0x200000;
sum=entry[24]<<8;
sum+=entry[25];
printf ("%s\t page %2d start %8X size %8X sum %04X\n", entry, page, offset, size, sum);
dump(entry, (page*0x100000)+offset, size);
}
}
void dump(char *fn, int start, int length)
{
int j;
char f[25]={"bin/"};
if (fn[0]==0) {
printf("Deleted file... skipping\n");
return;
}
for (j=0; (fn[j]!=0x20 && fn[j]!=0); j++) f[j+4]=fn[j];
out=fopen(f, "wb");
printf("dumping %s from %X to %X\n", fn, start, start+length);
for (j=start; j<start+length; j++) {
fseek(bin, j, SEEK_SET);
fputc(fgetc(bin),out);
}
fclose(out);
}
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396
-
antus
- Site Admin
- Posts: 10015
- Joined: Sat Feb 28, 2009 10:34 am
- cars: TX Gemini 2L Twincam 8psi
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B
Subaru WRX 2007
Re: Uplander/montana/relay locked bcm
And here is what it does. I think .dwn are the executable files.
Looking inside boot.dwn it does look like the vector table that maps to 0x00000 in the P01 etc. And it appears to contain the init code, including the code that waits for a download from a PC if its a 'blank' card. By blank I mean has boot.dwn but not anything more than that. So just enough to pull a bin from SPS/TIS. Its small enough that disassembling that would probably give a pretty good understanding of what hardware is in the tech2 and where to address it.
How useful is is this? Not sure. Its doable, but its a lot of work. You might learn more about the tech2 than anyone else, but still not answer the specific question you started with. You might be able to figure out some of the other files by inspecting their contents directly and not going the disassembly route.
Looking inside boot.dwn it does look like the vector table that maps to 0x00000 in the P01 etc. And it appears to contain the init code, including the code that waits for a download from a PC if its a 'blank' card. By blank I mean has boot.dwn but not anything more than that. So just enough to pull a bin from SPS/TIS. Its small enough that disassembling that would probably give a pretty good understanding of what hardware is in the tech2 and where to address it.
How useful is is this? Not sure. Its doable, but its a lot of work. You might learn more about the tech2 than anyone else, but still not answer the specific question you started with. You might be able to figure out some of the other files by inspecting their contents directly and not going the disassembly route.
Code: Select all
[root@vm t2rip]# gcc -o t2rip t2rip.c
[root@vm t2rip]# ./t2rip
CALIBRAT0.SPS page 28 start 0 size 100000 sum FFFF
dumping CALIBRAT0.SPS from 1C00000 to 1D00000
CALIBRAT1.SPS page 23 start 0 size 100000 sum FFFF
dumping CALIBRAT1.SPS from 1700000 to 1800000
CALIBRAT2.SPS page 24 start 0 size 100000 sum FFFF
dumping CALIBRAT2.SPS from 1800000 to 1900000
CALIBRAT3.SPS page 25 start 0 size 100000 sum FFFF
dumping CALIBRAT3.SPS from 1900000 to 1A00000
CALIBRAT4.SPS page 26 start 0 size 100000 sum FFFF
dumping CALIBRAT4.SPS from 1A00000 to 1B00000
CALIBRAT5.SPS page 27 start 0 size 100000 sum FFFF
dumping CALIBRAT5.SPS from 1B00000 to 1C00000
info.inf page 0 start 1FF00 size 21 sum 09C1
dumping info.inf from 1FF00 to 1FF21
ECU.EXT page 16 start 0 size 73CA sum 375F
dumping ECU.EXT from 1000000 to 10073CA
t2cfg.dwn page 0 start 1FFB0 size 8 sum 02B0
dumping t2cfg.dwn from 1FFB0 to 1FFB8
expire.dat page 0 start 1FFB8 size 48 sum 43FA
dumping expire.dat from 1FFB8 to 20000
devschp.ext page 0 start 20000 size 43746 sum AF59
dumping devschp.ext from 20000 to 63746
T1APPS.DWN page 1 start 0 size 2B7E4 sum A2B8
dumping T1APPS.DWN from 100000 to 12B7E4
DEVDYNM.EXT page 1 start 40000 size 72BF6 sum F052
dumping DEVDYNM.EXT from 140000 to 1B2BF6
SCENCONV.DWN page 2 start 0 size 7F0E4 sum FA97
dumping SCENCONV.DWN from 200000 to 27F0E4
datastrm.ext page 3 start 0 size 8AB1E sum 0800
dumping datastrm.ext from 300000 to 38AB1E
SCENS.DWN page 4 start 0 size D631E sum B39B
dumping SCENS.DWN from 400000 to 4D631E
t3apps.dwn page 5 start 0 size DE89A sum 41D7
dumping t3apps.dwn from 500000 to 5DE89A
candiapp.blk page 7 start 20000 size AB74 sum 3DAB
dumping candiapp.blk from 720000 to 72AB74
graphics.ext page 7 start 30000 size 7C1C sum 2A2F
dumping graphics.ext from 730000 to 737C1C
api.dwn page 7 start 80000 size 3E240 sum D7E0
dumping api.dwn from 780000 to 7BE240
opsys.dwn page 7 start C0000 size 37FE8 sum 027B
dumping opsys.dwn from 7C0000 to 7F7FE8
boot.dwn page 7 start F7FE8 size 4000 sum 2465
dumping boot.dwn from 7F7FE8 to 7FBFE8
vci_init.dwn page 7 start FBFE8 size 1FF8 sum 1215
dumping vci_init.dwn from 7FBFE8 to 7FDFE0
opschk.dwn page 7 start FDFE8 size 1FF8 sum DA41
dumping opschk.dwn from 7FDFE8 to 7FFFE0
nonsps.ext page 8 start C0000 size BE9B sum 2923
dumping nonsps.ext from 8C0000 to 8CBE9B
EPID.EXT page 12 start 0 size FA006 sum AB7A
dumping EPID.EXT from C00000 to CFA006
PSTRTHDR.EXT page 13 start 0 size 3480A sum 429D
dumping PSTRTHDR.EXT from D00000 to D3480A
fffr.ext page 13 start 40000 size 715AC sum 02D2
dumping fffr.ext from D40000 to DB15AC
PSTRUCT1.EXT page 14 start 0 size 7D004 sum 5139
dumping PSTRUCT1.EXT from E00000 to E7D004
PSTRUCT2.EXT page 14 start 80000 size 7D002 sum 784B
dumping PSTRUCT2.EXT from E80000 to EFD002
PSTRUCT4.EXT page 15 start 0 size 7D004 sum A5C6
dumping PSTRUCT4.EXT from F00000 to F7D004
CPID.EXT page 15 start 80000 size 3AB96 sum CC9A
dumping CPID.EXT from F80000 to FBAB96
SCENLST1.EXT page 17 start 0 size 2F900 sum 91AD
dumping SCENLST1.EXT from 1100000 to 112F900
PSTRUCT3.EXT page 17 start 80000 size 7D002 sum 7186
dumping PSTRUCT3.EXT from 1180000 to 11FD002
DATADISP.EXT page 18 start 0 size D4F18 sum 6481
dumping DATADISP.EXT from 1200000 to 12D4F18
DISPCONV.DWN page 19 start 0 size A62 sum 7852
dumping DISPCONV.DWN from 1300000 to 1300A62
SCENMSG.EXT page 19 start 40000 size AB026 sum E27C
dumping SCENMSG.EXT from 1340000 to 13EB026
DISPCONV.EXT page 20 start 0 size 4C29A sum 1348
dumping DISPCONV.EXT from 1400000 to 144C29A
screens.ext page 20 start 80000 size 48868 sum 3F31
dumping screens.ext from 1480000 to 14C8868
T3APPS2.DWN page 21 start 0 size 7AE60 sum F63D
dumping T3APPS2.DWN from 1500000 to 157AE60
vinproc.ext page 28 start 0 size C7A1C sum C15C
dumping vinproc.ext from 1C00000 to 1CC7A1C
DDEPID.EXT page 29 start 0 size 65A38 sum CF14
dumping DDEPID.EXT from 1D00000 to 1D65A38
tableapp.ext page 29 start 80000 size 4DA86 sum CA84
dumping tableapp.ext from 1D80000 to 1DCDA86
EPID1.EXT page 30 start 0 size 2BBB0 sum 2843
dumping EPID1.EXT from 1E00000 to 1E2BBB0
PSTRUCT5.EXT page 30 start 80000 size 55558 sum 2AD7
dumping PSTRUCT5.EXT from 1E80000 to 1ED5558
SEV.EXT page 31 start 40000 size 180F6 sum CD27
dumping SEV.EXT from 1F40000 to 1F580F6
docen.ext page 0 start 80000 size 387C2 sum 60CE
dumping docen.ext from 80000 to B87C2
strhdren.ext page 6 start 0 size 5CD4E sum 33AB
dumping strhdren.ext from 600000 to 65CD4E
strngsen.ext page 16 start 40000 size 6045C sum 25A7
dumping strngsen.ext from 1040000 to 10A045C
1252font.dwn page 7 start 0 size 1000 sum C168
dumping 1252font.dwn from 700000 to 701000
[root@vm t2rip]# ls -l bin
total 20432
-rw-r--r--. 1 root root 4096 Jul 2 14:21 1252font.dwn
-rw-r--r--. 1 root root 254528 Jul 2 14:21 api.dwn
-rw-r--r--. 1 root root 16384 Jul 2 14:21 boot.dwn
-rw-r--r--. 1 root root 1048576 Jul 2 14:21 CALIBRAT0.SPS
-rw-r--r--. 1 root root 1048576 Jul 2 14:21 CALIBRAT1.SPS
-rw-r--r--. 1 root root 1048576 Jul 2 14:21 CALIBRAT2.SPS
-rw-r--r--. 1 root root 1048576 Jul 2 14:21 CALIBRAT3.SPS
-rw-r--r--. 1 root root 1048576 Jul 2 14:21 CALIBRAT4.SPS
-rw-r--r--. 1 root root 1048576 Jul 2 14:21 CALIBRAT5.SPS
-rw-r--r--. 1 root root 43892 Jul 2 14:21 candiapp.blk
-rw-r--r--. 1 root root 240534 Jul 2 14:21 CPID.EXT
-rw-r--r--. 1 root root 872216 Jul 2 14:21 DATADISP.EXT
-rw-r--r--. 1 root root 568094 Jul 2 14:21 datastrm.ext
-rw-r--r--. 1 root root 416312 Jul 2 14:21 DDEPID.EXT
-rw-r--r--. 1 root root 470006 Jul 2 14:21 DEVDYNM.EXT
-rw-r--r--. 1 root root 276294 Jul 2 14:21 devschp.ext
-rw-r--r--. 1 root root 2658 Jul 2 14:21 DISPCONV.DWN
-rw-r--r--. 1 root root 311962 Jul 2 14:21 DISPCONV.EXT
-rw-r--r--. 1 root root 231362 Jul 2 14:21 docen.ext
-rw-r--r--. 1 root root 29642 Jul 2 14:21 ECU.EXT
-rw-r--r--. 1 root root 179120 Jul 2 14:21 EPID1.EXT
-rw-r--r--. 1 root root 1024006 Jul 2 14:21 EPID.EXT
-rw-r--r--. 1 root root 72 Jul 2 14:21 expire.dat
-rw-r--r--. 1 root root 464300 Jul 2 14:21 fffr.ext
-rw-r--r--. 1 root root 31772 Jul 2 14:21 graphics.ext
-rw-r--r--. 1 root root 33 Jul 2 14:21 info.inf
-rw-r--r--. 1 root root 48795 Jul 2 14:21 nonsps.ext
-rw-r--r--. 1 root root 8184 Jul 2 14:21 opschk.dwn
-rw-r--r--. 1 root root 229352 Jul 2 14:21 opsys.dwn
-rw-r--r--. 1 root root 215050 Jul 2 14:21 PSTRTHDR.EXT
-rw-r--r--. 1 root root 512004 Jul 2 14:21 PSTRUCT1.EXT
-rw-r--r--. 1 root root 512002 Jul 2 14:21 PSTRUCT2.EXT
-rw-r--r--. 1 root root 512002 Jul 2 14:21 PSTRUCT3.EXT
-rw-r--r--. 1 root root 512004 Jul 2 14:21 PSTRUCT4.EXT
-rw-r--r--. 1 root root 349528 Jul 2 14:21 PSTRUCT5.EXT
-rw-r--r--. 1 root root 520420 Jul 2 14:21 SCENCONV.DWN
-rw-r--r--. 1 root root 194816 Jul 2 14:21 SCENLST1.EXT
-rw-r--r--. 1 root root 700454 Jul 2 14:21 SCENMSG.EXT
-rw-r--r--. 1 root root 877342 Jul 2 14:21 SCENS.DWN
-rw-r--r--. 1 root root 297064 Jul 2 14:21 screens.ext
-rw-r--r--. 1 root root 98550 Jul 2 14:21 SEV.EXT
-rw-r--r--. 1 root root 380238 Jul 2 14:21 strhdren.ext
-rw-r--r--. 1 root root 394332 Jul 2 14:21 strngsen.ext
-rw-r--r--. 1 root root 178148 Jul 2 14:21 T1APPS.DWN
-rw-r--r--. 1 root root 8 Jul 2 14:21 t2cfg.dwn
-rw-r--r--. 1 root root 503392 Jul 2 14:21 T3APPS2.DWN
-rw-r--r--. 1 root root 911514 Jul 2 14:21 t3apps.dwn
-rw-r--r--. 1 root root 318086 Jul 2 14:21 tableapp.ext
-rw-r--r--. 1 root root 8184 Jul 2 14:21 vci_init.dwn
-rw-r--r--. 1 root root 817692 Jul 2 14:21 vinproc.ext
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396
-
Gatecrasher
- Posts: 435
- Joined: Fri Apr 24, 2020 8:09 pm