|
RomRaider
Documentation
Community
Developers
|
| Author |
Message |
|
AJ08H65EAT
|
Post subject: Re: 5EAT TCM JECS ROM Image Posted: Tue Jul 04, 2023 8:56 am |
|
 |
| Newbie |
Joined: Tue Jul 05, 2016 7:14 am Posts: 17
|
|
First attempt, but just noticed I did not read the instructions properly and missed the 'Select' part. So attached may not be useful. Will try proper method next.
You do not have the required permissions to view the files attached to this post.
|
|
| Top |
|
 |
|
MiikaS
|
Post subject: Re: 5EAT TCM JECS ROM Image Posted: Tue Jul 04, 2023 9:02 am |
|
 |
| Experienced |
Joined: Tue Jun 06, 2017 2:11 pm Posts: 206
|
At least it does get seed from TCU so one step ahead but calculated key was wrong so take one step back 
|
|
| Top |
|
 |
|
rimwall
|
Post subject: Re: 5EAT TCM JECS ROM Image Posted: Wed Jul 05, 2023 1:09 am |
|
 |
| Experienced |
Joined: Fri Aug 21, 2020 6:05 am Posts: 315
|
Ah, excellent! Thanks @AJ08H65EAT. The TCU is now speaking CAN. A big step forward and a small step back. I think I have fixed the bug with the 0x27 step. And I've extended the code to jump into the kernel and attempt a ROM dump from the kernel. If the kernel ROM dump works then flashing is basically inevitable. New versions to try: - first get a new protocol.cfg from here- FastECU_34_short here - does a test dump of 1024 bytes to default.bin. FastECU may crash afterwards, nothing to worry about (that's the known issue). - FastECU_34_long here - does a test dump of the whole TCU to default.bin. FastECU may crash afterwards, nothing to worry about (that's the known issue). The first 0x8000 bytes will be 0xff due to a self-dumping restriction that the kernel applies. If it all works, the TCU will be left in a state where it is running from its on board kernel and it will require a power cycle to get back to normal operation. This should just be on/off with the ignition key. No erasing or flashing will occur (unless a bug somehow replicates the exact erasing / flashing commands, which is highly unlikely). Edit: @ajayel - whilst the iso14230 dump was protected in your ROM, this approach should work, so feel free to try.
|
|
| Top |
|
 |
|
AJ08H65EAT
|
Post subject: Re: 5EAT TCM JECS ROM Image Posted: Thu Jul 06, 2023 6:59 am |
|
 |
| Newbie |
Joined: Tue Jul 05, 2016 7:14 am Posts: 17
|
|
Take a look at attached and see if it is useful. I don't think successful - but perhaps another step forward?
You do not have the required permissions to view the files attached to this post.
|
|
| Top |
|
 |
|
rimwall
|
Post subject: Re: 5EAT TCM JECS ROM Image Posted: Thu Jul 06, 2023 8:57 am |
|
 |
| Experienced |
Joined: Fri Aug 21, 2020 6:05 am Posts: 315
|
|
Thanks again!
Definitely a step forward! Perhaps two steps. Security algo successfully passed. And jump to kernel successful. ROM dump command didn't work. Not sure why, I suspect something to do with its length (256+ bytes per RXd message). Please try the updated FastECU_34_short.exe in the same repo location. Definitely getting closer now...
|
|
| Top |
|
 |
|
ajayel
|
Post subject: Re: 5EAT TCM JECS ROM Image Posted: Fri Jul 07, 2023 4:38 am |
|
 |
| RomRaider Donator |
Joined: Mon Oct 30, 2017 8:19 pm Posts: 79
|
|
Here's the output from FastECU_34_short.exe v0.2 on my car with the latest protocols file. Added the .txt extension to upload the bin file.
You do not have the required permissions to view the files attached to this post.
|
|
| Top |
|
 |
|
rimwall
|
Post subject: Re: 5EAT TCM JECS ROM Image Posted: Fri Jul 07, 2023 7:50 am |
|
 |
| Experienced |
Joined: Fri Aug 21, 2020 6:05 am Posts: 315
|
|
Thanks @ajayel. Are you able to post the log window as text or a pic?
Looks like you entered the TCU ROM successfully, but the dump command didn't work fully. We only got 8 bytes instead of 1024.
|
|
| Top |
|
 |
|
ajayel
|
Post subject: Re: 5EAT TCM JECS ROM Image Posted: Fri Jul 07, 2023 4:58 pm |
|
 |
| RomRaider Donator |
Joined: Mon Oct 30, 2017 8:19 pm Posts: 79
|
Attachment: 20230708-1.png
You do not have the required permissions to view the files attached to this post.
|
|
| Top |
|
 |
|
rimwall
|
Post subject: Re: 5EAT TCM JECS ROM Image Posted: Sat Jul 08, 2023 3:15 am |
|
 |
| Experienced |
Joined: Fri Aug 21, 2020 6:05 am Posts: 315
|
|
@ajayel - looks like it’s not passing the security key stage. Your ROM could have different encryption words. What is your TCU ID? RR will report this, or higher up in the log window it will be reported. Based on what happened with ECUs, different chips (Hitachi vs Denso) had different encryption words.
|
|
| Top |
|
 |
|
ajayel
|
Post subject: Re: 5EAT TCM JECS ROM Image Posted: Sat Jul 08, 2023 4:40 am |
|
 |
| RomRaider Donator |
Joined: Mon Oct 30, 2017 8:19 pm Posts: 79
|
rimwall wrote: @ajayel - looks like it’s not passing the security key stage. Your ROM could have different encryption words. What is your TCU ID? RR will report this, or higher up in the log window it will be reported. Based on what happened with ECUs, different chips (Hitachi vs Denso) had different encryption words. Hi, Romraider logger, and FastECU shows my TCU with ID TCU 0217500 with the transmission physically labeled TG5D7CVDBA.
|
|
| Top |
|
 |
|
rimwall
|
Post subject: Re: 5EAT TCM JECS ROM Image Posted: Sat Jul 08, 2023 6:40 am |
|
 |
| Experienced |
Joined: Fri Aug 21, 2020 6:05 am Posts: 315
|
Ok, another version to try. This one (FastECU_34_short.exe here) will: - save the log window to log.txt to avoid having to snip pics. if log.txt already exists, the new log will append to the prior file, so you will need to delete log.txt if you want a clean log - tries a different approach to capturing the 256+ byte response from the TCU. @ajayel - that TCU ID looks quite different to the ones I have dug into (which are like ACD1A06000), so I suspect different encryption words. I will see if I can find a ROM image with a similar TCU ID in order to find the different encryption words. If you can run again and send me the log.txt file that may also provide some clues. Thanks!
|
|
| Top |
|
 |
|
AJ08H65EAT
|
Post subject: Re: 5EAT TCM JECS ROM Image Posted: Sun Jul 09, 2023 6:27 am |
|
 |
| Newbie |
Joined: Tue Jul 05, 2016 7:14 am Posts: 17
|
|
Thanks for updated .exe. Latest attempt attached. Log file worked, so no pic this time. Some carriage returns in the log might be nice if it is not difficult to implement.
You do not have the required permissions to view the files attached to this post.
|
|
| Top |
|
 |
|
rimwall
|
Post subject: Re: 5EAT TCM JECS ROM Image Posted: Sun Jul 09, 2023 6:56 pm |
|
 |
| Experienced |
Joined: Fri Aug 21, 2020 6:05 am Posts: 315
|
|
Super, thanks again @AJ08H65EAT. Receiving long iso15765 messages is now working. The decryption failed, not sure why because it's working code borrowed from elsewhere, but I have fixed a null pointer bug that may have caused it. Please try the new FastECU_34_short.exe. I've also updated FastECU_34_long.exe if you want to try it, but no need to - I don't want to waste your time with a long dump before I've confirmed the short version is working ok.
|
|
| Top |
|
 |
|
riksk
|
Post subject: Re: 5EAT TCM JECS ROM Image Posted: Sun Jul 09, 2023 8:47 pm |
|
 |
| Experienced |
Joined: Sun Jun 28, 2020 2:25 am Posts: 237
|
|
Let me know if you need more testers. I have a 2011 Forester S-Edition with the 5EAT aswell.
_________________ 2011 Forester S Edition 5EAT~ Flex Fuel 2011 WRX 6MT ~ Flex Fuel
|
|
| Top |
|
 |
|
rimwall
|
Post subject: Re: 5EAT TCM JECS ROM Image Posted: Sun Jul 09, 2023 10:41 pm |
|
 |
| Experienced |
Joined: Fri Aug 21, 2020 6:05 am Posts: 315
|
|
Hi @riksk, yep, the more the merrier.
Yours will most likely be CAN based, so try the FastECU_34_short mentioned in the post above. Instructions on setting up FastECU are also shown higher up in this thread. It will be interesting to see if a 2011 era 5EAT has the same encryption words as a 2008 era. Thanks.
|
|
| Top |
|
 |
Who is online |
Users browsing this forum: No registered users and 1 guest |
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot post attachments in this forum
|
|