|
RomRaider
Documentation
Community
Developers
|
|
Page 1 of 1
|
[ 10 posts ] |
|
| Author |
Message |
|
MasterCodeIT
|
Post subject: 7059 Analysis Posted: Sat Sep 14, 2024 1:04 pm |
|
 |
| Newbie |
Joined: Mon Mar 04, 2024 12:40 pm Posts: 5
|
|
After looking at some CAN comm's from various tools. The UDS shows an encryption 8 and compression 2.
Vehicle: Infiniti Model: Q50 Engine 3.7L Stock file: 14GA0D ECU: SH705927N
Flashing the stock file using commercial tooling, the encrypted payload's first 40 bytes being sent to the ECU are "7F 08 7A 90 15 CE CB F8 58 58 B7 33 44 76 B7 4C 8A D9 E8 30 E9 52 C3 47 39 A0 A6 B5 8D 0E C5 90 6C D6 68 F3 1F 52 8E 8D 02 77 83 2A EC AF E7 32 4A 2E E0 66 60 DB E4 8A 16 9E 96 84 EE 33 96 8A 7D 93 69 7A 75 99 AD 65 77 63 0C A6 D4 3F AF 8A"
I wanted to decrypt to compare the data in the stock file. I have checked with nisprog and the encode/decode does not seem to match correctly.
Anyone have any information regarding this or perhaps a working encode/decode.
Last edited by MasterCodeIT on Tue Sep 17, 2024 8:04 am, edited 2 times in total.
|
|
| Top |
|
 |
|
fenugrec
|
Post subject: Re: 7059 Analysis Posted: Sun Sep 15, 2024 9:23 pm |
|
 |
| Experienced |
 |
Joined: Wed Jan 08, 2014 11:07 pm Posts: 652
|
|
Your question lacks detail... Which ECUID (mECUNO / mProgVer) ? full dump available somewhere ?
What is that "first 40 bytes" from, a log from an official NERS / consult reflash ? aftermarket thing ? Was it a SID 0x34 * frame ? something else ?
_________________ If you like nisprog + npkern, you can support me via https://liberapay.com/fenugrec/ For sending me encrypted/secure messages, use PGP key 0xBAC61AEB3A3E6531 available from pool.sks-keyservers.net
|
|
| Top |
|
 |
|
MasterCodeIT
|
Post subject: Re: 7059 Analysis Posted: Mon Sep 16, 2024 8:33 am |
|
 |
| Newbie |
Joined: Mon Mar 04, 2024 12:40 pm Posts: 5
|
fenugrec wrote: Your question lacks detail... Which ECUID (mECUNO / mProgVer) ? full dump available somewhere ?
What is that "first 40 bytes" from, a log from an official NERS / consult reflash ? aftermarket thing ? Was it a SID 0x34 * frame ? something else ? added more information to the first post. Yes, it was the first payload sent after erasing using SID 0x34. The 40 bytes were taking from the frame after the SID request. Below is the first chunk: Raw Payload: 0x34 0x82 0x00 0x82 0x00 0x80 0x7F 0x08 0x7A 0x90 0x15 0xCE 0xCB 0xF8 0x58 0x58 0xB7 0x33 0x44 0x76 0xB7 0x4C 0x8A 0xD9 0xE8 0x30 0xE9 0x52 0xC3 0x47 0x39 0xA0 0xA6 0xB5 0x8D 0x0E 0xC5 0x90 0x6C 0xD6 0x68 0xF3 0x1F 0x52 0x8E 0x8D 0x02 0x77 0x83 0x2A 0xEC 0xAF 0xE7 0x32 0x4A 0x2E 0xE0 0x66 0x60 0xDB 0xE4 0x8A 0x16 0x9E 0x96 0x84 0xEE 0x33 0x96 0x8A 0x7D 0x93 0x69 0x7A 0x75 0x99 0xAD 0x65 0x77 0x63 0x0C 0xA6 0xD4 0x3F 0xAF 0x8A 0x02 0x99 0x32 0xCA 0xF7 0x20 0x88 0xAB 0xCC 0x10 0x1D 0xB1 0xE3 0xE6 0x17 0xE0 0x04 0x54 0x91 0xEE 0x66 0x66 0xB2 0xA2 0x77 0x27 0xA8 0x83 0x25 0x69 0x8D 0xC0 0x8E 0x6A 0xBE 0xB6 0x6E 0xDA 0xA1 0x31 0x80 0x91 0x08 0xA2 0x6F 0xD4 0x16 0x8A 0x2F 0xBB
|
|
| Top |
|
 |
|
fenugrec
|
Post subject: Re: 7059 Analysis Posted: Mon Sep 16, 2024 8:06 pm |
|
 |
| Experienced |
 |
Joined: Wed Jan 08, 2014 11:07 pm Posts: 652
|
Quote: using commercial tooling To be clear, were you trying to revert a tuned ECU back to stock ? Did you provide your "commercial tooling" with an unencrypted stock .bin , or an official .dat file straight from Nissan ?
_________________ If you like nisprog + npkern, you can support me via https://liberapay.com/fenugrec/ For sending me encrypted/secure messages, use PGP key 0xBAC61AEB3A3E6531 available from pool.sks-keyservers.net
|
|
| Top |
|
 |
|
MasterCodeIT
|
Post subject: Re: 7059 Analysis Posted: Tue Sep 17, 2024 8:09 am |
|
 |
| Newbie |
Joined: Mon Mar 04, 2024 12:40 pm Posts: 5
|
fenugrec wrote: Quote: using commercial tooling To be clear, were you trying to revert a tuned ECU back to stock ? Did you provide your "commercial tooling" with an unencrypted stock .bin , or an official .dat file straight from Nissan ? What I am asking, is the correct "decode" used to decrypt the file. It can also be used to decrypt the payload as that is just one of the chunks sent to the ECU. The tooling takes an uncrypted bin, then apply's the encryption to the file. Same way your nisprog does. However, I tried the decode / encode on the payload and it did not give me any matched bytes in the stock file. Follow?
|
|
| Top |
|
 |
|
fenugrec
|
Post subject: Re: 7059 Analysis Posted: Tue Sep 17, 2024 7:57 pm |
|
 |
| Experienced |
 |
Joined: Wed Jan 08, 2014 11:07 pm Posts: 652
|
MasterCodeIT wrote: What I am asking, is the correct "decode" used to decrypt the file. Yes, I know what you're asking. And I said fenugrec wrote: To be clear, were you trying to revert a tuned ECU back to stock ? because if you are, typical "commercial tools" modify the tuned ROM to make it more difficult to dump them, this can include using different keys or different algo completely. If this is your situation, nobody will help you to accomplish this on these forums (and not privately either, myself), for obvious reasons. Quote: The tooling takes an uncrypted bin Please post this unencrypted stock bin (zipped), so we can see if Nissan changed their encryption methods.
_________________ If you like nisprog + npkern, you can support me via https://liberapay.com/fenugrec/ For sending me encrypted/secure messages, use PGP key 0xBAC61AEB3A3E6531 available from pool.sks-keyservers.net
|
|
| Top |
|
 |
|
MasterCodeIT
|
Post subject: Re: 7059 Analysis Posted: Wed Sep 18, 2024 9:09 am |
|
 |
| Newbie |
Joined: Mon Mar 04, 2024 12:40 pm Posts: 5
|
Quote: The tooling takes an uncrypted bin Please post this unencrypted stock bin (zipped), so we can see if Nissan changed their encryption methods.[/quote] 14GA0D.zip = stock file 14GA0D_Full OBD Read.zip = full dump
You do not have the required permissions to view the files attached to this post.
|
|
| Top |
|
 |
|
fenugrec
|
Post subject: Re: 7059 Analysis Posted: Wed Sep 18, 2024 10:49 am |
|
 |
| Experienced |
 |
Joined: Wed Jan 08, 2014 11:07 pm Posts: 652
|
well the good news is, your ECU already has a stock ROM on it : Code: $ srec_cmp 14GA0D_full\ obd\ read.bin -bin 14GA0D.ori -bin -of 0x15a8 -v Left only: (0 - 0x15a7, 0x1800a8 - 0x1fffff) The "14GA0D.o r i" (wtf romraider forum, why does it auto-replace 'o r i' with hex ?) file is identical to a subset of the 'full OBD read' (and this file has some excess padding at the end for some reason, size should be 1.5MB for SH7059)
_________________ If you like nisprog + npkern, you can support me via https://liberapay.com/fenugrec/ For sending me encrypted/secure messages, use PGP key 0xBAC61AEB3A3E6531 available from pool.sks-keyservers.net
| Last edited by fenugrec on Wed Sep 18, 2024 10:51 am, edited 1 time in total. |
| stupid forum autoreplace |
|
|
| Top |
|
 |
|
MasterCodeIT
|
Post subject: Re: 7059 Analysis Posted: Wed Oct 02, 2024 6:03 pm |
|
 |
| Newbie |
Joined: Mon Mar 04, 2024 12:40 pm Posts: 5
|
fenugrec wrote: well the good news is, your ECU already has a stock ROM on it : Code: $ srec_cmp 14GA0D_full\ obd\ read.bin -bin 14GA0D.hex -bin -of 0x15a8 -v Left only: (0 - 0x15a7, 0x1800a8 - 0x1fffff) The "14GA0D.o r i" (wtf romraider forum, why does it auto-replace 'o r i' with hex ?) file is identical to a subset of the 'full OBD read' (and this file has some excess padding at the end for some reason, size should be 1.5MB for SH7059) any luck or thoughts?
|
|
| Top |
|
 |
|
fenugrec
|
Post subject: Re: 7059 Analysis Posted: Thu Oct 03, 2024 9:03 pm |
|
 |
| Experienced |
 |
Joined: Wed Jan 08, 2014 11:07 pm Posts: 652
|
MasterCodeIT wrote: any luck or thoughts? I ran out of time unfortunately.
_________________ If you like nisprog + npkern, you can support me via https://liberapay.com/fenugrec/ For sending me encrypted/secure messages, use PGP key 0xBAC61AEB3A3E6531 available from pool.sks-keyservers.net
|
|
| Top |
|
 |
|
Page 1 of 1
|
[ 10 posts ] |
|
Who is online |
Users browsing this forum: No registered users and 0 guests |
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot post attachments in this forum
|
|