Kinda off topic.. Kinda on.. Bus hacking at its finest

A place For General Chit Chat Etc
User avatar
Tazzi
Posts: 3459
Joined: Thu May 17, 2012 8:53 pm
cars: VE SS Ute
Location: WA
Contact:

Kinda off topic.. Kinda on.. Bus hacking at its finest

Post by Tazzi »

Sooo, Iv been harassing commodores security systems lately to work out the infamous linking dramas :thumbup:
Iv sent up my own little custom module for brute-forcing information between the BCM and also at the ECU. So far so good!

During this R&D, I realised I can sit the module between the ECU, and laptop (Or scantool) that can 'bend' received messages from both scantool and ECU.
I actually hooked up both the tech2, and also SOE and realised that I can modify the received vin and serial and still process everything else the same. This includes performing full TIS updates to the device. :shock:

With that in mind. Wouldnt the entire tuning market completely collapse with such a device? I mean, I havent found a single commercial tuning software that does not rely on the vin/serial for locking. Since technically its their only real system to attach to. Primarily looking at Holdens and Fords, but it seems all other CAN based vehicles have the same situation.
Even if a little 'marker' is saved in the flash, this could be modified on the fly like the vin and serial. :wtf:

Another use is in VE's. Most of the modules are security linked by a vin. Any second hand part could be installed without any security reprogramming realistically. Hook device in with new part and away you go. Security is also easy attacked.. Install a second component (BCM, PIM ect) and bend the security to the correct value. Security system is now completely eradicated. The security example is more of a 'black hat' kinda example, but still a method since without the stupid immob value.. components are about as useful as a brick.

This is just a 'proof of concept' since I will be using this tech to obtain various calibrations from tis2web for Holdens as well as other VE/VF modules. And same for the Fords. But really, are we in the era where we can actually make our own custom "modules", implement our own routines and inject custom information?
I probably cant express how excited I am with the thought I could add a "plug-n-play" device into a VE or VF (or fords!). Add in custom sensors or abiltiies, apply a custom CAN header to that device and you could be reading completely custom information using the standard CAN format like you would with a scantool!! Add in a boost sensor, obtain reading using module and read it out using a standard ELM! The options are endless.

I would have thought something like this would have already been available. But inevitably as parts and tech become cheaper and more readily available to the public, surely tuning companies would have thought this would occur? But I guess how do you prevent/protect against something like that? The best I can think is they update terms and conditions saying do not use in conjunction with XYZ device?

Thoughts!?
(Before I get harassed (or abused?) its all just "what if" scenario!)
Your Local Aussie Reverse Engineer
Contact for Software/Hardware development and Reverse Engineering
Site:https://www.envyouscustoms.com
Mob:+61406 140 726
Image
User avatar
Gareth
Posts: 2528
Joined: Fri Mar 14, 2014 8:37 pm
Location: Bacchus Marsh, Vic

Re: Kinda off topic.. Kinda on.. Bus hacking at its finest

Post by Gareth »

Another use is in VE's. Most of the modules are security linked by a vin. Any second hand part could be installed without any security reprogramming realistically. Hook device in with new part and away you go
Sign me up!!! Finally, it looks like we might be able to repair almost 10yo commodores with affordable and most importantly available second hand components, I have a VE here at the moment that is waiting for the 'on back order' new ABS module, they can't have the vin changed (same as SDM) and are a 'one time linking' job :comp: so second hand is out of the question... until possibly now, Tazzi you F@%king legend :thumbup:

Not sure a public forum is the best place for this though? yet, anyway...
According to chemistry, alcohol is a solution...
User avatar
vlad01
Posts: 7849
Joined: Mon Oct 08, 2012 6:41 pm
cars: VP I S
VP I executive
VP II executive
VP II executive #2
VR II executive
Location: Kyneton, Vic

Re: Kinda off topic.. Kinda on.. Bus hacking at its finest

Post by vlad01 »

Awesome ! keep us posted.
I'm the director of VSH (Vlad's Spec Holden), because HSV were doing it ass about.
User avatar
Tazzi
Posts: 3459
Joined: Thu May 17, 2012 8:53 pm
cars: VE SS Ute
Location: WA
Contact:

Re: Kinda off topic.. Kinda on.. Bus hacking at its finest

Post by Tazzi »

Biggvl wrote:
Another use is in VE's. Most of the modules are security linked by a vin. Any second hand part could be installed without any security reprogramming realistically. Hook device in with new part and away you go
Sign me up!!! Finally, it looks like we might be able to repair almost 10yo commodores with affordable and most importantly available second hand components, I have a VE here at the moment that is waiting for the 'on back order' new ABS module, they can't have the vin changed (same as SDM) and are a 'one time linking' job :comp: so second hand is out of the question... until possibly now, Tazzi you F@%king legend :thumbup:

Not sure a public forum is the best place for this though? yet, anyway...
Thats exactly it. Although whether that meets engineering specifications is beyond me. You know, you hit the whole legality thing for insurance purposes.. but that assumes they even know what they are doing. The ABS modules... you mean the EBCM's in the VE's(electronic brake control module)? Holden says they cant be changed.. there full of absolute shit on that one. As far as Im aware... you can change the vin in them... just gotta know the unlocking algorithms :thumbup:
SDM on the other hand. Yep, thats locked down tight.

Nah, not bothered about it being on a public forum. Its a 'what if' kinda thing at the moment. Things that 'could' be done or used for. I guess better yet, why hasnt it already ocurred, why should only manufactures have the ability to design a custom module.
Fitting non-essential second hand modules in my eyes is ok. Its things that affect security/safety... yeah thats where things get a little more hazy on someones true intentions.

I personally love the idea of implementing my own sensors, allocating the device with a custom header and being able to request data like you would do with any other module. :thumbup:

Im sure if Antus/other moderators are unsure about it, they will let me know :thumbup:
Your Local Aussie Reverse Engineer
Contact for Software/Hardware development and Reverse Engineering
Site:https://www.envyouscustoms.com
Mob:+61406 140 726
Image
User avatar
VL400
Posts: 4991
Joined: Sun Mar 01, 2009 2:54 pm
cars: VL Calais and Toyota Landcruiser. Plus some toys :)
Location: Perth, WA
Contact:

Re: Kinda off topic.. Kinda on.. Bus hacking at its finest

Post by VL400 »

That is what's called a man in the middle attack. Its a pretty common reverse engineering and hacking technique. Using it to circumvent security of licenses is not to be discussed here, it is illegal. The big tuning companies take this very seriously. But for allowing module replacement that is unrelated to vehicle security or safety (which rules out many) i dont see a problem.

Have a couple of ALDL modules doing what you proposing for CAN. Works very well to get extra sensor info with the vehicle data :thumbup: My logger becomes a bus device that you can request its aux inputs from, or have it tack on the aux input data to the regular data frames. Have another on the bus that is a sort of universal BCM and also reads some sensors.
User avatar
Tazzi
Posts: 3459
Joined: Thu May 17, 2012 8:53 pm
cars: VE SS Ute
Location: WA
Contact:

Re: Kinda off topic.. Kinda on.. Bus hacking at its finest

Post by Tazzi »

VL400 wrote:That is what's called a man in the middle attack. Its a pretty common reverse engineering and hacking technique. Using it to circumvent security of licenses is not to be discussed here, it is illegal. The big tuning companies take this very seriously. But for allowing module replacement that is unrelated to vehicle security or safety (which rules out many) i dont see a problem.

Have a couple of ALDL modules doing what you proposing for CAN. Works very well to get extra sensor info with the vehicle data :thumbup: My logger becomes a bus device that you can request its aux inputs from, or have it tack on the aux input data to the regular data frames. Have another on the bus that is a sort of universal BCM and also reads some sensors.
Man in the middle aye. Havent read much up on it. Guess its what I sort of do for the tech2.
Yes completely understand, its not the idea/end goal. Rather not be chased wit a lawsuit! :o It was more of a question whether tuning companies are prepared for devices like these to pop up in the industry. Eventually someones going to release a "ECU bender" or.. whatever they'll call it.
Exactly, almost all modules in a VE do have a dedicated task. Minus the radio (maybe the cluster?), everything else shouldnt really be tampered with. BCM,ECU,EBCM ect are all vital units.

Cant imagine it will be long until a dedicated opensource automotive module can be purchased. This it would be awesome being able to chuck in a few different modules, make then display various different information. Custom Tyre pressure monitoring system. Custom navigation interface, update/reprogram over the bus. Chuck a couple LCD's in and can get them displaying some generic info found from the bus like the VE EDI's do. :D
Your Local Aussie Reverse Engineer
Contact for Software/Hardware development and Reverse Engineering
Site:https://www.envyouscustoms.com
Mob:+61406 140 726
Image
User avatar
barana
Posts: 98
Joined: Wed Aug 22, 2012 5:35 pm
cars: mitz L300
holdens i have owned
TD,TE TG gemini
HBII LC4 UC x2 torana
VH Commodore
EH Special

Re: Kinda off topic.. Kinda on.. Bus hacking at its finest

Post by barana »

I can see it now, holden and ford are sending out their blood men right now /jk
Onya a tazzi,love the innovation
"Its alright for god, he doesnt drive a kingswood.Even the nuns only have toranas"-Ted Bullpit
Me:yeah,corse,God's a Holden man
Mate:whaaa?
Me:Psalm 83:15 so pursue them with your Tempest and terrify them with your Storm
A Holden & a pontiac
User avatar
Tazzi
Posts: 3459
Joined: Thu May 17, 2012 8:53 pm
cars: VE SS Ute
Location: WA
Contact:

Re: Kinda off topic.. Kinda on.. Bus hacking at its finest

Post by Tazzi »

barana wrote:I can see it now, holden and ford are sending out their blood men right now /jk
Onya a tazzi,love the innovation
*Puts an aluminium foil hat on his head*

:lol:
Your Local Aussie Reverse Engineer
Contact for Software/Hardware development and Reverse Engineering
Site:https://www.envyouscustoms.com
Mob:+61406 140 726
Image
User avatar
antus
Site Admin
Posts: 8292
Joined: Sat Feb 28, 2009 8:34 pm
cars: TX Gemini 2L Twincam
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B
Contact:

Re: Kinda off topic.. Kinda on.. Bus hacking at its finest

Post by antus »

Im fine with theoretical discussion, but not about circumventing security. I imagine that any use of such a device could put you in the firing line after an accident, even if the device wasn't directly involved, but rather because it was on the bus and may or may not have interfered.

Man in the middle attacks are abbreviated MITM and searching on that will yield lots of hits, probably related more to pc security rather than vehicle bus stuff such as you propose.

There is also the risk of getting caught up in the middle of this:

https://www.techdirt.com/articles/20150 ... ight.shtml

And the gist of that is based around the DMCA, and that includes working around security, eg vin locks, and the DMCA.. i think... might technically be enforceable here under the previous "free" trade agreements. Who knows, over complicated stuff... but possible.

http://www.aph.gov.au/About_Parliament/ ... 304/04rp14

Code: Select all

Technical protection measures

A particularly important theme comes out of the US experience with technical protection measures or effective technological measures. Article 17.4.7 of the AUSFTA, which attempts to protect effective technological measures (ETM), is based on the US Digital Millennium Copyright Act 1998 (DMCA). An effective technological measure is defined so that it:

    means any technology, device or component that, in the normal course of its operation, controls access to a protected work, performance, phonogram, or other subject matter, or protects any copyright.

Plenty more can be read, but too much for me to digest and I am certainly not a lawyer.
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396
vn5000
Posts: 551
Joined: Fri Jul 17, 2009 2:11 pm
cars: vn v8 commodore
Location: GOLD COAST QLD

Re: Kinda off topic.. Kinda on.. Bus hacking at its finest

Post by vn5000 »

Unfortunately my uncertainty of the law is all that is stopping me from releasing this to all you fellow delco hackers
This tool does not require any licencing and gives you the ability to write any os (factory and aftermarket) to your ls1 pcms.
All files are read and written in .bin format
It has the capability to clone ls1 pcms thus allowing you to use your efilive or hp tuner software without requiring the purchase of any further licences .It can make all ls1 pcms appear the same to there software.
I have developed my own vpw cable to work with it ,I have written all my own bootloader files.
It will be released shortly , but to ensure I cover my ass I think im going to have to dumb it down and remove the cloning feature. :thumbdown:
Attachments
LS1 FLASH TOOL.jpg
LS1 FLASH TOOL.jpg (110.52 KiB) Viewed 4093 times
Post Reply