![]() |
|
|
| 04-13-2020, 03:19 PM | #1 |
|
Major
![]() 1348
Rep 1,261
Posts |
MSS6x Flasher - Initial Release
I believe the app has been sufficiently proven itself to be safe at this point and am comfortable releasing it now. You can grab it here: https://nam3forum.com/forums/forum/e...r-now-released
Functionality:
Safety:
Performance:
Last edited by Terraphantm; 04-19-2020 at 12:30 AM.. |
|
Appreciate
8
|
| 04-13-2020, 04:31 PM | #3 |
|
Lieutenant General
![]() ![]() ![]() 7679
Rep 13,759
Posts |
Good job!
|
|
Appreciate
1
Alex@Alpine1367.50 |
| 04-14-2020, 12:54 AM | #4 |
|
First Lieutenant
![]() ![]() 231
Rep 316
Posts |
Good news~! great job~!
__________________
2011 LCI W/DCT / K&N drop in filter / CSF radiator / do88 oil cooler / do88 DCT cooler / Akra Evo / Moton CS 2 way coilover / Wiechers strut bar(F) / ARC strut bar(R) / Alcon Superkit BBK / Tarox rotor / Geoff steel EHPS / Sard carbon-Kevlar GT wing / GT4 carnard / Aim Evo4+G-dash+GT Steering+S/C GP HD / Bride Zeta3 / etc.
|
|
Appreciate
0
|
| 04-14-2020, 01:20 AM | #5 |
|
Save the manuals!
6272
Rep 6,848
Posts |
Amazing! You did incredible work in the MSS54 community that's been a huge help in the past for some of my custom ECU modifications.
Being able to do the same with the MSS65 would be a Godsend. Curious, does anyone have MSS65 XDF repository for hex addresses for manipulating parameters in the ECU binaries? |
|
Appreciate
0
|
| 04-14-2020, 01:28 AM | #6 | |
|
Major
![]() 1348
Rep 1,261
Posts |
Quote:
I do have an A2L for what appears to be a pre-production MSS60 software variant. Only thing is I can't remember for the life of me if it's something I found scouring the internet or if it's something that was given to me with the expectation that it stays private. |
|
|
Appreciate
3
|
| 04-14-2020, 02:17 AM | #7 |
|
Brigadier General
![]()
1646
Rep 3,149
Posts |
Amazing work, I assume it will work for those who have the BMW ICOM?
I also have a K+DCAN (non-bimmergeeks) cable with the upgraded custom firmware without the bluetooth modification, it can sucessfully program many DMEs without bricking.
__________________
North American Mr12Volt Carplay/Android Auto Distributor
INSTAGRAM: GORDON.M3 DINAN | EVOSPORT | VAC | ARP | RD SPORT | NEEZ | EIBACH | CSF | IND | BILSTEIN | KLASSEN | BREMBO | ENDLESS | BBS | BPM SPORT | PROJECT MU | EVENTURI |
|
Appreciate
0
|
| 04-14-2020, 02:40 AM | #8 |
|
Major
![]() 1348
Rep 1,261
Posts |
No ICOM support. Right now I only support K+DCAN cables (and I suppose a regular K-line cable would work on a K-line car -- I don't think that applies to M3s). In theory I can support any interface that EdiabasLib supports, but I haven't tried anything other than the K+DCAN (and right now the program is basically hard coded to look for a COM port). No support for the ICOM there as far as I'm aware.
|
|
Appreciate
1
GORDON.M31645.50 |
| 04-14-2020, 05:34 PM | #9 |
|
Major
![]() 1348
Rep 1,261
Posts |
Updated the software:
Safety changes:
New Features:
The previous link I shared with everyone should point to the latest version of the app Now I want to pose a question for everyone about how I should handle the safety of the RSA flashing: The trick I currently use to defeat RSA has the potential to permanently / unrecoverably brick non-BDMable MSS60s if flashed with a non-EdiabasLib cable I can change the method slightly so that the bricks will at least be recoverable via WinKFP when using an appropriate interface -- however this method will roughly double the time it takes to do the RSA bypass So what do you guys prefer I do? As much as it pains me to lose the speed, I'm sorta thinking it would be more responsible to do it the slower way. Even with the above change, if someone flashes the DME Program (or repeats the RSA bypass) with a non-EdiabasLib cable after an RSA bypass has already been installed, the DME will unrecoverably brick - I cannot get around that. Last edited by Terraphantm; 04-14-2020 at 05:55 PM.. |
|
Appreciate
4
|
| 04-14-2020, 06:01 PM | #10 |
|
///M Powered for Life
12760
Rep 11,154
Posts |
this is a huge deal Terra, thank you so much!
|
|
Appreciate
0
|
| 04-19-2020, 12:30 AM | #11 |
|
Major
![]() 1348
Rep 1,261
Posts |
I feel comfortable releasing the application now. See first post.
|
|
Appreciate
1
SYT_Shadow12759.50 |
| 04-22-2020, 09:55 PM | #12 |
|
Major
![]() 1348
Rep 1,261
Posts |
Dunno if anyone is interested, but I managed to unlock the BDM port on a locked MSS60. Still trying to work out a way to make it easy for people to do, but at least it's been proven that they can be unlocked.
Do note that if you write/lock a new secret key through tool32 (rather than just writing it directly via BDM), that will relock the DME. |
|
Appreciate
1
SYT_Shadow12759.50 |
| 04-22-2020, 10:03 PM | #13 |
|
///M Powered for Life
12760
Rep 11,154
Posts |
I wish I understood more of what you're talking about Terra! Where is the explanation for simple minded people?
|
|
Appreciate
0
|
| 04-22-2020, 10:28 PM | #14 | |
|
Major
![]() 1348
Rep 1,261
Posts |
Quote:
With the E9x M3, BMW started locking the port sometime in the middle of model year 2008. So we couldn't clone ECUs, nor was it possible to recover from bad flashes. It was also believed to make it impossible to recover the EWS data from the DME (though I figured out how to do that over the OBDII port with my app) Now that the port can be unlocked, we've got basically full control of these things. If you have a bad flash, just restore a backup. If the ECU messes up for some other reason, just copy a backup onto a used one. Etc. |
|
|
Appreciate
1
SYT_Shadow12759.50 |
| 04-23-2020, 07:42 AM | #15 | |
|
///M Powered for Life
12760
Rep 11,154
Posts |
Quote:
|
|
|
Appreciate
0
|
| 04-28-2020, 05:58 PM | #16 |
|
Brigadier General
![]() 3809
Rep 3,065
Posts |
Wonderful job Terra!
Good to see you on here Dunno if you remember me from the ZHP forums.
__________________
IG:@lowtecderbo
Journal: Link E9x ZCP Suspension Info: Link Track Chat Discord: https://discord.gg/VsKbTyqBVj |
|
Appreciate
0
|
| 04-29-2020, 05:00 AM | #17 |
|
BimmerPost Supporting Vendor
3592
Rep 7,300
Posts ![]() |
As someone that has spent countless weeks working on MSS6x DMEs, and I'm not referencing time tuning them as that would amount to years, I'm pretty impressed. Just curious if you are applying any type of patch in order to read the ISN? I had a lot fun nearly a decade ago identifying the Secret keys in both the DME and CAS. Those were the good times. Nice work terra.
|
|
Appreciate
1
SYT_Shadow12759.50 |
| 04-29-2020, 07:04 AM | #18 |
|
Major
![]() 1348
Rep 1,261
Posts |
The way I've got it setup, it'll try reading the ISN/SK from the real location first, and if that returns FFs (which it will if my patches haven't been written), then it'll dump RAM from the left / injection CPU and do a pattern search. I haven't had that fail on me yet, but maybe there's an odd program version I don't have access to where they actually do clear it from RAM.
I do patch the read routine to allow that section to be read out when doing the RSA bypass, so on an already patched DME it will read the ISN/SK directly rather than searching the RAM for it. |
|
Appreciate
2
SYT_Shadow12759.50 Bubbles2891.00 |
Post Reply |
| Bookmarks |
| Thread Tools | |
|
|