Pages: [1]
Author Topic: [Request] KSuite 3.37  (Read 2080 times)
SonicD007
Newbie
*

Karma: +0/-0
Offline Offline

Posts: 3


« on: May 02, 2026, 10:46:47 AM »

Anyone have a copy of this that works with a KTAG clone? Looking to do a full dump of a MED17.1 ECU with TPROT enabled. Could also use the damos file or xdf if available for a CBFA 2012 GTI VW.
Logged
_nameless
Hero Member
*****

Karma: +373/-3439
Offline Offline

Posts: 3002



« Reply #1 on: May 06, 2026, 07:59:50 AM »

This is a joke right?
Logged

If you are broke or expecting free handouts DO NOT message me. I'll probably put you on blast if you do.
SonicD007
Newbie
*

Karma: +0/-0
Offline Offline

Posts: 3


« Reply #2 on: May 07, 2026, 02:36:22 PM »

Eh just following paths down this rabbit hole as I try to learn about RE ECUs and general tuning. Never messed with ECUs before but I'd like to dump the firmware off this spare ECU for learning purposes and my research has lead to this being the next step in my path. Apologies if I violated a rule, wasn't looking explicitly for cracked software.
Logged
killpop
Newbie
*

Karma: +0/-0
Offline Offline

Posts: 11


« Reply #3 on: May 12, 2026, 11:27:37 PM »

Asking for cracked software is typically frowned on around here, this isn't mhhauto. Also, you don't need 3.37, version 2.25 that probably came with your device can do it if used and installed correctly.  Hint: P293
You should probably stay away from clone devices, legit tools aren't that expensive when you factor in all the wasted time and the eventual trip to the dealer to fix your car after the aliexpress special bricks your ecu
Logged
SonicD007
Newbie
*

Karma: +0/-0
Offline Offline

Posts: 3


« Reply #4 on: May 17, 2026, 09:00:33 AM »

Asking for cracked software is typically frowned on around here, this isn't mhhauto. Also, you don't need 3.37, version 2.25 that probably came with your device can do it if used and installed correctly.  Hint: P293
You should probably stay away from clone devices, legit tools aren't that expensive when you factor in all the wasted time and the eventual trip to the dealer to fix your car after the aliexpress special bricks your ecu

Yeah that was a mistake on my end. I wasn't thinking about it being cracked software, won't happen again.

That being said, I did hook up the KTAG to the ECU, pried it open for the SBOOT pin, and attempted to read it but the Aliexpress special KTAG couldn't do a full dump, only the maps and some config data. I was hoping to get everything but from what I read the TPROT and 2.25 software couldn't do it exactly. I read about the psuedorandom number generator vulnerability as well so I know the KTAG with the correct protocol would probably be using that to dump it but I wasn't able to get it to work. That's how I ended up looking for 3.37.

I wanted to eventually wire up a raspberry pi with a CAN Hat module to see if I could write dumping/writing software with python but that's more of a long term project as I don't have the time to dedicate to it right now. Thank you for the hint, I think I tried that but maybe my probe wasn't making good enough contact or something. I'll have to try it again with a clamp in place.

If there's any information you could share as to how Cobb and the other aftermarket tuners are able to flash tunes without opening the ECU I would appreciate it. That's one piece I haven't really figured out how they're doing. My assumption is they probably use that psuedorandom number generator vulnerability to extract the key to temporarily disable TPROT to then flash over the map files but I don't actually know if this is correct. My goal is slightly different in that I don't just want to access the map files but the entire firmware to learn more about how it all works. I know there are Tricore emulators so I figure if I can get the dump then I can attempt to debug it using an emulator or do static analysis with Ghidra.

I also have the tricore 1796 manual so theoretically I should be able to dig through that to for the raspberry pi CAN hat DIY setup. I'm new to the ECU world and real time OS but not to vulnerability/exploitation and software development.

Appreciate it and sorry again, didn't mean to ask for cracked software.
Logged
Pages: [1]
  Print  
 
Jump to:  

Powered by SMF 1.1.21 | SMF © 2015, Simple Machines Page created in 0.014 seconds with 18 queries. (Pretty URLs adds 0s, 0q)