Pages: [1] 2 3
Author Topic: dump decrypted file through encryption board?  (Read 39622 times)
k0mpresd
Hero Member
*****

Karma: +146/-54
Offline Offline

Posts: 1655


« on: February 26, 2010, 07:20:47 PM »

anyone know how to do this properly?

i tried:

boot ecu with bootpin, soldered chip still in place, dump file. bad file.
boot ecu with bootpin with no flash/encryption board, reattach flash/encryption board, dump file.

the second method got what looked to be a good file. but upon closer inspection it was not good. and after flashing the file, the ecu was a brick. guess i should mention i desoldered the pin header and soldered the 29f800 directly to the ecu.

parts of the bootloader (?, hex 0-9fff) were different. so i cut and paste the hex from a stock file. the ecu would boot enough for vagcom to log in but the part # showed as THIS-IS-THE (RAM-PROGRAM). so there were other parts in the file that were no good. i tried a few more copy/paste but gave up after a short while because i just did not have the time to screw with it.

i know its possible to dump a good decrypted file using the encryption board but i had not so much luck with it. i just got a psop44 adapter in the mail today for my programmer so i wasnt able to try that method. is that the only way to get it done?
« Last Edit: February 26, 2010, 07:24:36 PM by k0mpresd » Logged
Asassini
Newbie
*

Karma: +0/-0
Offline Offline

Posts: 8


« Reply #1 on: February 27, 2010, 08:59:37 AM »

I don`t think the PSOP44 adapter will help you since the file in the flash must be encripted, I never tried to read this encripted boards.
Logged
k0mpresd
Hero Member
*****

Karma: +146/-54
Offline Offline

Posts: 1655


« Reply #2 on: February 27, 2010, 11:19:21 AM »

i think the adapter will help. the data has to be read off the flash decrypted by the ecu. so the encrypted data passes through the board and comes out decrypted. it would be the same as reading it with a programmer. theres some revo patents floating around the internet that talk about it. how thats one of the flaws of the encryption boards.
Logged
Asassini
Newbie
*

Karma: +0/-0
Offline Offline

Posts: 8


« Reply #3 on: February 27, 2010, 04:48:56 PM »

Depend of what kind of protection board is used, there are diferent makes, good luck  Wink

Keep us updated
Logged
k0mpresd
Hero Member
*****

Karma: +146/-54
Offline Offline

Posts: 1655


« Reply #4 on: February 28, 2010, 06:56:48 AM »

well its mostly moot at this point. since i i soldered the soldered the psop44 to the ecu and flashed over the "encrypted" tune that was on it.

i need a new soldered ecu to play with. Wink
Logged
Drehkraft
Jr. Member
**

Karma: +9/-0
Offline Offline

Posts: 46


« Reply #5 on: March 02, 2010, 11:59:45 PM »

well its mostly moot at this point. since i i soldered the soldered the psop44 to the ecu and flashed over the "encrypted" tune that was on it.

i need a new soldered ecu to play with. Wink

You just need a good bin file.  You will have to boot flash the ECU or remove the prom and flash it in a burner.   What ECU code is it?  I may have a stock bin file.
Logged
k0mpresd
Hero Member
*****

Karma: +146/-54
Offline Offline

Posts: 1655


« Reply #6 on: March 03, 2010, 07:39:55 AM »

it was an m box. i did bootpin and reflashed it that way. the ecu is already back in the hands of the customer.
Logged
Tony@NefMoto
Administrator
Hero Member
*****

Karma: +132/-4
Offline Offline

Posts: 1389


2001.5 Audi S4 Stage 3


« Reply #7 on: March 03, 2010, 03:31:21 PM »

I have dumped chips in encryption sockets by reading them through the ecu using boot mode and KWP2000.

I tried putting the encryption socket into my eeprom reader and I got garbage.
Logged

Remember you have to log in if you want to see the file attachments!
Info or questions, please add to the wiki: http://www.nefariousmotorsports.com/wiki
Follow NefMoto developments on Twitter: http://twitter.com/nefmoto
ktech
Jr. Member
**

Karma: +0/-0
Offline Offline

Posts: 29


« Reply #8 on: March 08, 2010, 07:09:42 AM »

I got a small program called Descrambler that I used a couple of times with great success. its mostly to descramble Superchips, Dimsport, and a couple of other types of files. It can actually scramble the file again after its modified and use the same board again. Tongue
Logged
overspeed
Sr. Member
****

Karma: +21/-5
Offline Offline

Posts: 387



« Reply #9 on: March 15, 2010, 06:22:47 PM »

I got a small program called Descrambler that I used a couple of times with great success. its mostly to descramble Superchips, Dimsport, and a couple of other types of files. It can actually scramble the file again after its modified and use the same board again. Tongue

Where can I get this Descrambler program ?

I have an ECU with no label that contains an garbage Encripted file... I Want to put the original file there, but no way of know even for sure what version it´s originaly... so I want to decript to see the Bosch numbers and put the original back
Logged
pvl
Sr. Member
****

Karma: +32/-1
Offline Offline

Posts: 350


« Reply #10 on: June 03, 2010, 02:59:12 PM »

@ overspeed :

if you can do a 'in the car' or bench-diagnose-job via vag-com, you can actually get the numbers and software-revision from the ecu.
I've yesterday successfully read-out a socketed (and perhaps also encrypted) chip from a Seat-ecu. This was
done via a home-made ME7 bench-flash-cable, KWP2000+ box and the special version from chiptunawarehouse's ME7 edition
of the kpw2000 software. Took 10 minutes (512Kb chip), and i was expecting garbage, but the file is 100% correct Smiley .

@  ktech :  I would like to have a look to that 'Descrambler' program of yours. Would you be so kind to
                PM me abouth it ? Purely for educational purposes ofcourse. I found a list of supported encryptions i think of the
                software-program you mean.

@ k0mpresd  : It's been a while, since we've spoken via email (almost a year). Thanks for the audi-tt ecu-immo-solution.
                    I've got hold of a different programmer for the chip and all is fine and working ! Thanks for that Wink 
                    If you still have that encrypted socket, perhaps i can help you out...
Logged
overspeed
Sr. Member
****

Karma: +21/-5
Offline Offline

Posts: 387



« Reply #11 on: June 24, 2010, 02:39:25 PM »

Well... that´s what I done at the end...  as I didn´t know what car it belongs (as I said no label, the ECU was a gift from a friend who receveid it as a trade UAhUAHau)... I finally used VAG in bench to get the version...

I Still can´t  "see" the file as it is encrypted... but I can say it´s garbage because the first owner trade it because after the chip service the car never runs good... he lives in a very small city and decides to buy a new one... but this ECU had no labels e he didn´t ask the code for the guy in the car shop...

Logged
Drehkraft
Jr. Member
**

Karma: +9/-0
Offline Offline

Posts: 46


« Reply #12 on: October 11, 2010, 07:36:26 PM »

We tried to read an APR chip today, was about to get it to read in boot mode - but the data was not good.

So we removed it:


Logged
Tony@NefMoto
Administrator
Hero Member
*****

Karma: +132/-4
Offline Offline

Posts: 1389


2001.5 Audi S4 Stage 3


« Reply #13 on: October 12, 2010, 09:49:21 AM »

I haven't had any luck reading the APR EMCS modules in boot mode either.
Logged

Remember you have to log in if you want to see the file attachments!
Info or questions, please add to the wiki: http://www.nefariousmotorsports.com/wiki
Follow NefMoto developments on Twitter: http://twitter.com/nefmoto
blundar
Newbie
*

Karma: +11/-1
Offline Offline

Posts: 22


« Reply #14 on: January 19, 2011, 04:49:42 PM »

You could read any of these "encrypted" chips by making a chip reader that will start on the address the MCU requests on a reset and then proceed randomly from there.  None of the encrypted chips I've seen are using very complicated logic devices.  They don't have enough logic to parse the contents of the ROM in order to predict a jump - at the best, they can watch the speed at which requests come and check for too many sequential accesses. 

I have two other projects to finish first then this is next for me.  Hopefully have it done by summertime lol.
Logged
Pages: [1] 2 3
  Print  
 
Jump to:  

Powered by SMF 1.1.21 | SMF © 2015, Simple Machines Page created in 0.023 seconds with 18 queries. (Pretty URLs adds 0s, 0q)