Tazzi wrote:Ooooooooooooo This is exciting!!
Interesting to hear you were able to read quite a bit of memory with mode23 after using the engineering seed/key unlock, thats certainly a game changer on alot of modules.
it really is exciting. Any address within the CPU was able to be read. It's just really slow so I just dumped the area I needed after verifying the addresses lined up and such. It makes me want to pull back out some other modules I've messed with in the past and see how they operate under the service device unlock...but then you have to know the key to the seed as well. Got lucky here, but all I know so far is the algo for device control seed/key isn't one of the ones used for the normal security that was hacked from the tech2. and every device may be different. I couldn't be sure without trying more stuff.
I'm going to continue the path of getting JTAG setup though. My hope is to get that running and use it as a backup as I'm fairly sure the checksum won't even matter if I go in thru JTAG. I still want to get the checksum figured out to prevent any potential issues after several run cycles and such like I've seen happen with the volkswagen crowd, but at least I can confirm my byte location for the change I need to make. And I can confirm this in parallel while hopefully finding some help in assembly for the algo. Really hoping the bootloader is the missing piece and now the assembly makes sense and has completed routines.
Also, with the TMS chip off the board, I confirmed the CAN transceivers only talk with the TMS chip. and the wheel speed sensors only talk with the Infineon chip. So the infineon is definitely handling the lower level more maintenance items while the TMS chip is the brains of the operation. This has me confident the data I need to change to make my truck work is in fact located in the TMS chip and not the infineon.
My next EBCM sample/victim doesn't come in until next Monday so I'm kind of dead in the water until then, unless the checksum algo is figured out before. But hopefully by Monday or Tuesday I'll have JTAG running.