November 03, 2021
Here we’re trying to downgrade CAS3+ ISTAP. Because it’s encrypted since ISTAP upgrade and it doesn’t allowVVDI BIMToolor any software to write a key to it.
What we want to do is:
Write back the original FLASH data that was doing a key before.
Try to crank CAS3+ module by BIMTool and bench test platform.
Step 1
So, first we write the original FLASH into CAS3 byVVDI Prog Programmer.
Step 2
Set up bench test platform:
Connect the cable to all hardware (BIMTool, JBE, CAS3, key slot, switch…)
Notice the PIN on JBE module.
Insert the key and light on the cluster.
We see there is a steering lock but we can bring up the mileage. (The temper dot comes from the mismatch of the kilometer between CAS and cluster)
Step 3
We hook upBIMTool.
Turn to "CAS key learnâ€page and connect.
Click on "Get Key Infoâ€and "Add keyâ€.
If it’s encrypted, here it’ll prompt.
But, it asks if we’re going to update firmware, which means FLASH writing by VVDI Prog worked.
Now disconnect PC from the Internet.
Press "Noâ€to update firmware.
Then press "Yesâ€to flash CAS firmware.
Follow the instruction and it gives us key info.
Finally we manage to crack and downgrade CAS3+ ISTAP on bench.
Try if it can give us ISN.
Exchange ECU/CAS>>CAS – CAS3+ OBDII>>Read ECU ISN
No.
Try it via EEPROM dump file that we got from VVDI Prog, and a working key.
Yes.
Done!
More functions to be explored!
http://blog.xhorsevvdi.com/vvdi-prog-bimtool-and-cas3-bench-test-platform-downgrade-istap-success/
Posted by: xhorsevvdi at
10:14 AM
| No Comments
| Add Comment
Post contains 256 words, total size 9 kb.
35 queries taking 0.0456 seconds, 95 records returned.
Powered by Minx 1.1.6c-pink.