Page 5 of 6

Re: Seed key brute force program.

Posted: Mon Nov 08, 2021 12:22 am
by Overdrive915
Yeah I did a read first. I found the dropdown menu and put the code in then read the file and saved . Then I down loaded a file and it all went south from there on. Now I have NO SUB NET FOUND and won't connect. I will disconnect for a day or 2 while I am waiting for the next e38 to unlock.

Re: Seed key brute force program.

Posted: Mon Nov 08, 2021 1:27 am
by ironduke
PowerPCM only writes calibrations.. It does not write Operating system segment or any eeprom section. You cannot mix and match calibrations and operating system segments.. It is possible to alter the calibration segments using something like universal patcher and then write them back but downloading a file and trying to write it would likely end in a soft brick at minimum.. Could try check marking recovery and writing the original file you downloaded back but even that may not work..
Good luck!!

Re: Seed key brute force program.

Posted: Mon Nov 08, 2021 8:19 pm
by Overdrive915
Thanks for the info I think I have already bricked it . Will I be able to use something like a usbjtag-nt and write a bin directly to the flash to fix the problem or will it just be trial and error?

Re: Seed key brute force program.

Posted: Mon Nov 08, 2021 10:27 pm
by ironduke
Overdrive915 wrote:Thanks for the info I think I have already bricked it . Will I be able to use something like a usbjtag-nt and write a bin directly to the flash to fix the problem or will it just be trial and error?
What happens if you run the brute force program on it? if it has a seed of 0000 then it is what I call soft bricked.. Try powerpcm in recovery mode with the original file that you read from that ecu and see if it recovers..

You can recover it with a bdm tool, not that easy but it wasn't that hard.. I bought this guys tool to recover my bench ecu that I finally managed to really screw up.. I don't think your there yet.. Even bricking the OS(which you didn't write but is kinda worse) is recoverable). Worst case you'll probably need to use sps2,DPS, or some sort of custom code to recover.
https://www.youtube.com/watch?v=098RVV-SF1U&t=181s

Re: Seed key brute force program.

Posted: Fri Nov 12, 2021 12:46 am
by Overdrive915
I can't even get the coms to work. I have tried the recovery mode still no luck so I have gone and ordered on of those u-link-nt units and I am going to give it a bash and see what happens. Nothing Ventured Nothing Gained. Thanks for the help most of the time I was playing with P04s and P59s. This was my first attempt with a e38 so I was expecting something to go wrong. Will let you know what the outcome is as I have to wait 2 to 3 weeks before the unit will arrive.

Re: Seed key brute force program.

Posted: Fri Nov 12, 2021 6:39 pm
by Overdrive915
A little bit of extra info. When i connect . ready to upload flash or download calibration up load flash ( no reply first frame. Read _FF no reply (0x35) erase calic... no reply FF frame. Send _FF frame error sending message (0x35)

Re: Seed key brute force program.

Posted: Sun May 01, 2022 9:25 pm
by julespatch
ive got one with 0000 seed. nothing ive got will get through the bootloader section. everything talks to it ok but nothing will write. tried powerpcm in recovery as well but i get the same error as overdrive915.
strange

Re: Seed key brute force program.

Posted: Mon May 02, 2022 9:23 pm
by julespatch
we are back in action!!! thank you ironduke for the words of wisdom.
basically, the message that its missing out on gets sent with his E38 Vin changer tool.
So with a y splitter cable you run that and in my case a DPS calibration archive I set up and viola, it programmed.
Once it was talking again it still had no serial and was locked with seed 3F80 / key 3F80.
I jut loaded the correct bin file right over that and now we are in business!!!!

There's a possibility it may have also worked with HP/EFI/NVS rather that DPS but that's what I had open.

Yay!

Re: Seed key brute force program.

Posted: Wed Jan 18, 2023 8:20 am
by spyder09
is it possible to add p12 to this brute force?

Re: Seed key brute force program.

Posted: Wed Jan 18, 2023 9:37 am
by ironduke
spyder09 wrote:is it possible to add p12 to this brute force?
P12 is pin 2 VPW communication, right??