Announcement

Collapse
No announcement yet.

MSS6x Flasher - Now released!

Collapse
This is a sticky topic.
X
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • pshoey
    replied
    Originally posted by M3Gallo View Post
    Does anyone on here build and sell bench setups for the MSS60/65 DME? Or could I commission someone to undertake the task? If so PM me please.
    Lambda1 is correct, super easy to make one. Here are some pictures of most recent effort.


    Click image for larger version  Name:	IMG_5954.jpg Views:	0 Size:	126.2 KB ID:	80771 Click image for larger version  Name:	IMG_5955.jpg Views:	0 Size:	358.4 KB ID:	80770

    Leave a comment:


  • Lambda1
    replied
    Mate its super easy 5-6 wires need.
    I would bulid some with original BMW Parts but isn't really worth if you check new parts prices .
    Only parts ~60€.

    Leave a comment:


  • M3Gallo
    replied
    Does anyone on here build and sell bench setups for the MSS60/65 DME? Or could I commission someone to undertake the task? If so PM me please.

    Leave a comment:


  • terra
    replied
    Originally posted by pshoey View Post
    The keys that are used in the app to sign the seed and decrypt the signature, they are from the file SGIDC.as2 in the gdaten directory?

    I'm trying to work out the format of the lines in that file - I'm assuming each line contains several keys combined and they are probably encrypted by another key??

    I'm very familiar with the F/G series keys but never looked into the E series stuff. Happy to share F/G series knowledge.

    Any help would be much appreciated, thanks.

    P.
    They’re triple des encrypted. I’ll dig up the keys later. You can find them if you disassemble WinKFP. The symmetric encryption keys I thinks are encrypted with something else.

    For the rsa authenticated modules, each line contains the modulus and private exponent for level 3 security access (ECU Programming Mode). Public exponent is always 7 for security access.

    Leave a comment:


  • pshoey
    replied
    The keys that are used in the app to sign the seed and decrypt the signature, they are from the file SGIDC.as2 in the gdaten directory?

    I'm trying to work out the format of the lines in that file - I'm assuming each line contains several keys combined and they are probably encrypted by another key??

    I'm very familiar with the F/G series keys but never looked into the E series stuff. Happy to share F/G series knowledge.

    Any help would be much appreciated, thanks.

    P.
    Last edited by pshoey; 11-22-2020, 04:39 PM.

    Leave a comment:


  • MpowerE36
    replied
    Originally posted by terra View Post
    Uploaded everything to github: https://github.com/terraphantm/MSS6x-Flasher

    Please be gentle with your criticism. I'm a doctor, not a programmer, this is mostly cobbled together with what I was able to teach myself :P
    Thank you for your work Terra. You did an impressive job here.

    Thank you also for taking the time to explain all of your work on these ECU in the github.

    Leave a comment:


  • pshoey
    replied
    There are always multiple ways to achieve the same result - if this is the result of teaching yourself C# - I congratulate you - I'll start teaching myself to become a doctor - I bet I don't get as good a result as this!!

    Thanks for sharing.
    Last edited by pshoey; 11-16-2020, 08:49 PM.

    Leave a comment:


  • terra
    replied
    Uploaded everything to github: https://github.com/terraphantm/MSS6x-Flasher

    Please be gentle with your criticism. I'm a doctor, not a programmer, this is mostly cobbled together with what I was able to teach myself :P

    Leave a comment:


  • Lambda1
    replied
    Possible for MSS60 and MSS65 also with options for Swap like also Limiter at 5500rpm with lost abs signal, with full power and no CAN-bus problems. No Emulator, in file.

    Leave a comment:


  • terra
    replied
    Originally posted by dmlf View Post

    For MSS60 ?
    I mean really, on any dme that has program write capabilities, EWS delete is possible. You just have to figure out what instructions to bypass.

    Leave a comment:


  • dmlf
    replied
    Originally posted by Lambda1 View Post
    You don't need, but isn't freely officially released atm . Is possible in file.
    For MSS60 ?

    Leave a comment:


  • Lambda1
    replied
    I've given up on hopes for an EWS/CAS delete
    You don't need, but isn't freely officially released atm . Is possible in file.

    Leave a comment:


  • sjsuM5
    replied
    Originally posted by terra View Post
    You could make a full backup, flash to stock with WinKFP, and then flash your backup back.
    Ended up using the binary modification tool to edit my DME file after backing up the DME using MSS6x flasher. Will be taking M5 to get smog tested this weekend...

    Leave a comment:


  • dmlf
    replied
    Ah right ! So it may be patchable I guess... Would be fun

    Leave a comment:


  • terra
    replied
    The obd read protection has nothing to do with the UC3FMCR register. The read code is simply set to return 0xFF when reading certain addresses.

    Leave a comment:

Working...
X