Title: Need hint identify maps edc15cp2 Post by: nolo on March 27, 2018, 01:58:02 AM This is my coming back to reversing project. EDC15C2, Lancia Phedra, 2.0 JTD Engine.
Looks that I'm still rosty in reversing, it's been a long time. I'm still not able to identify maps. I don't find any references to maps. Looks like I need a hint from one of the experienced users. I can 100% identify axis in the binary file. And there is a Axis Pointer Table too. I wrote a programm to get me all addresse to the axis and imported them into ida to get either a reference to the axis or the pointer table. Now I get references, but they are wrong. (https://thumb.ibb.co/dSQz77/Bildschirmfoto_2018_03_27_um_10_34_16.png) (https://ibb.co/dSQz77) Then I wrote a program to decode opcodes to know where the dpp register points to. I found out that only dpp0 and dpp3 are used. I changed register to get a better result, did not work. (https://thumb.ibb.co/ghSJ0S/Bildschirmfoto_2018_03_27_um_10_36_22.png) (https://ibb.co/ghSJ0S) (https://thumb.ibb.co/huzRn7/Bildschirmfoto_2018_03_27_um_10_36_00.png) (https://ibb.co/huzRn7) Addressing is still wrong. Now I'm lost. What should I try next? Olaf Title: Re: Need hint identify maps edc15cp2 Post by: prj on March 27, 2018, 08:44:29 AM I am going to give you some generic info. It might not apply to your ECU.
1. EDC15 has bank switching, so DPP's are switched on the fly via coding. 2. There needs to be no reference to the exact map. Often a reference to the start of the first axis is enough. 3. At least in ME7 there is a million different map lookup routines which take different arguments. Keep that in mind. I don't really have time to look at your specific code, but maybe this info is of some use. Title: Re: Need hint identify maps edc15cp2 Post by: nolo on March 27, 2018, 10:57:54 AM Got it! Somewhere I messed everything up. Loaded everything new, found references! Now will hunt for map references.
For other people: ; assume dpp0: 3Ch (page 0xF0000) ; assume dpp1: 1 (page 0x4000) ; assume dpp2: 2 (page 0x8000) ; assume dpp3: 3 (page 0xC000) dpp3 goes to MEM_EXT:00008000, there is measurement data dpp0 goes to Calibration Data At least I can see that my imported AxisPtrTable get referenced. Olaf Title: Re: Need hint identify maps edc15cp2 Post by: prj on March 27, 2018, 11:14:42 PM Btw, as a tip - remove "run final analysis pass" and then use my IDA Pro scripts to only analyze the areas that you know are code.
That way your references will be cleaner. Title: Re: Need hint identify maps edc15cp2 Post by: nolo on April 24, 2018, 05:40:15 AM I'm still working on this. This is fun.
For those who are interested in what I have achieved so far: There are maps with direct axis and with axis pointers. Found a way to detect maps with axis pointers. Scanned the opcodes to find the corresponding addresses for axis and maps. So for a map where the axis are unknown opcodes are scanned until the corresponding axis is found even for those one where the axis is preloaded in ram. Code: 0x761E4 I will continue working on it until I have identified all maps. |