Replies: 34 comments 43 replies
|
cff has its own chksum. |
|
I suppose I need to clarify what I'm trying to achieve. I'm a car tuner and most of my work involves MB platforms so I tried the tool and exported the CFF File segments to binary form and when I checked the exported file it had maps as I expected, now lets say I modified a map then use the tool to inherit the modified bin to the segment using "Export Spliced File CFF". To make things easier I'll name the new exported CFF as "foo.cff" . Is this foo.cff is already checksum calculated and is it ready to be flashed or do I have to calculate the checksum once I modified the map before inheriting and exporting foo.cff CFF I'm testing is for the ECU (MED177) |
|
once you modified "original" flash, lets say with winols it must correct cks so all you need to match adresses of segment area to be exported for cff. |
|
So I am going to calculate checksums using winols then I'll use the tool to export flash. I'll use vediamo to flash the software and I'll be back with feedback if It was a success or not Thanks for your replies. |
|
Sorry for the delay, did first test on flashing MED177 after modifing the extracted segment without making checksum correction for the binary, inherited it into the CFF (tool did CFF checksum), flashed it and got "Signature Failed". I thought I could fool it and pass the Signature check without making checksum correction for the binary. Next test is going to be checksum for both of them, hopefully we could mod other modules with the help of this amazing tool. |
|
So I modified the bin file and did the checksum then I inherited into the CFF file and the tool did the checksum for CFF, I tried to flash it using Vediamo and once it completed it showed a message "Signature Failed". I tried to flash the binary file with another tool and it was OK so I think maybe their is another check which checks the integrity of the file. Any suggestions? |
|
Do you have an idea to bypass this check? |
|
upload a modified flash you wish to be exported to cff. Ill fix software checksum. So you can compare what is your wrong step |
|
https://mega.nz/file/QyRigYwK#trNvymXcy7Z2FaBrOf_ol3yPDPBuka9HvEk8F9w2-M8 Here is a modified flash |
|
it is BOSCH MED17.7.1 1037540338 it is 1579033700 cff 1579033700_134500_803FDF00 is CS block segment you havent fixed |
|
post cff you tried to flash and mod file you trying to export |
|
since the feature was added by my request ive tried it with cr4_nfz with no success long time ago. At that spot i thought i made something wrong (Flash sector names orso). Now we see that it wasnt. Ill try to make trace while flashing. |
|
Dear @jglim i would like to hear from you :
|
|
What I recall that for example MED177 has 2 checksums blocks sometimes when I use WinOLS to make the checksums it does change the last block and approx 4 bytes before the starting of the maps. Does that have something to do with it? I saw some other tuners use a private tool which is not public that can flash TCU or CPC directly without using Vvediamo. Only J2534 + the private software. Maybe if you could think of a solution that would flash directly without Vediamo we could bypass that last check? That private tool flashes BIN file not CFF. |
|
maps write can trace.zip |
|
Notes on the cff algo.
|
|
Vediamo CAN verification log for sucess flashing |
|
Got another hint from cxf. |
|
DS: FN_Start_Check_Checksum_Routine Checksun Routine starten |
|
Good luck guys on the hard work hope you get to a solution |
|
have you think about removing CCC blocks? Im thinking of compare similar cffs to determine all 3 blocks. 1 and 3 is easy, but second string have pre bytes, which must be removed to set Number of securities to 0 (as far as i think- it is). |
|
One more thought. |
|
To make comparison i took same smr-d file that have correct name for thing we call CCC. and a string drom CFF |
|
Since Caesar does signature check i decided to check c32s.dll from vediamo package. |
|
How about using unsecured cff as a sketch - modify flashkey, meaning, qualifier, priority etc. |
|
variant id is stored in flash offsets section and can be easily modified, but we knew nonthing about hardcoded part.. |
|
hello together I have read your discussion with enthusiasm |
|
Hi pals, I was always successful at exporting data from CFF files to I can use that for different purposes, like tuning, DTC, etc and later on writting with either Autotuner, Flex, or AVDI. However, each time I tried to modify a CFF file and flash that to the ECU I was a complete failure, either the ECU would vediamo would fail on the post verification, or vediamo would say that the CFF is missing flash data. So far as per everything I have read here, in other places, and tried myself I understand I do have some missconception somewhere but can understand where so if anyone has any hint or can help me understand a few things would be awesome:
It is just that, at this point I tried so many things that I'm looking mostly for a "you cannot do that so will never work" or a "yes it is possible but you are doing it wrong". Thanks everyone! |
|
Hi pals,
Thanks for your answers!!
Awesome, I'm workshop too, I do programming/coding and tuning. Mostly on MB as I work closely with a few MB workshops.
Will retry once more today on an ME9.7, I have a few around, and I think I also had a SIM266 but that is older.
On ME9.7 I was able to get to the point where I it flashed but failed verification.
SIM271 CFFs for some reason once modified Vediamo stopped recognizing FLASH_DATA (Complaining that the CFF was missing it)
What I finally did because I had that ecu here for coding and tuning, I matched the CFF at the locations I needed and wrote it back with another interface.
Get Outlook for Android<https://aka.ms/AAb9ysg>
…________________________________
From: JinGen Lim ***@***.***>
Sent: Thursday, February 20, 2025 2:12:37 AM
To: jglim/CaesarSuite ***@***.***>
Cc: Diego Hernan Marciano ***@***.***>; Comment ***@***.***>
Subject: Re: [jglim/CaesarSuite] CFF Flash Files (Discussion #47)
Hey and welcome back,
That I'm able to read the data from a CFF file doesn't mean that it is unencrypted and that I can patch it to flash whatever I want right?
I haven't touched any encrypted MB firmware till date so I'd generalize that most MB firmware embedded in CFF is unencrypted. You can patch them and fix the CFF container's checksum<https://github.com/jglim/CaesarSuite/blob/580f846bf1e9797e04f77492195de9cd0f4be4c7/Caesar/Caesar/CaesarContainer.cs#L70>, and Vediamo should load the CFF without complaints. Things get trickier if you resize the segments by adding or removing bytes in the flash as it'll break some file offsets but this isn't a protection scheme, it's a file format issue.
In case the problem is the encryption itself, would it be a valid test to find some old unencrypted CFF file and use that for patching?
I can at least confirm that these are unencrypted, though in general it's safe to assume that most CFF are unencrypted.
sha1
D95485D5737888A765FB6098229E63308B234C18 2049022702_001.cff
5DDD6263A5399CAE6FE6F715C5914CB13F7BE0D1 2049022802_001.cff
My understanding after reading the discussion here is that even if I can extract the flash data area because the structure is known, there are still unknown security areas in the CFF and that it will be the main source of issues when the post flash verification executes in the ECU and fails, correct?
At least on the IC204, I can confirm that the firmware is signed and modifying the firmware breaks the signature. If the signature is broken, the ECU will not mark the flash as valid, and it will always remain in bootmode until it receives a valid firmware image. I was only able to deliver a modified payload as I found a vulnerability<https://github.com/jglim/UnsignedFlash/> in their signature check.
Bear in mind that flashing via CAN is effectively going through the "front door" where checks are present. I still do not know how tuners or WinOLS users are able to write their changes back onto the ECU. My assumption is that they use "back door" techniques like writing through physical means such as JTAG/BDM but I could be wrong.
Tagging @Feezex<https://github.com/Feezex> on this as he's an actual workshop expert, maybe he can offer some advice if he's available.
It is just that, at this point I tried so many things that I'm looking mostly for a "you cannot do that so will never work" or a "yes it is possible but you are doing it wrong".
yes it is possible but (for most parts) you cannot simply deliver a modified payload
—
Reply to this email directly, view it on GitHub<#47 (reply in thread)>, or unsubscribe<https://github.com/notifications/unsubscribe-auth/ACM5ILLILHZFWHGHBBCH6RL2QVP4LAVCNFSM6AAAAABXPWYQPOVHI2DSMVQWIX3LMV43URDJONRXK43TNFXW4Q3PNVWWK3TUHMYTEMRVHAZDCOA>.
You are receiving this because you commented.Message ID: ***@***.***>
|






Uh oh!
There was an error while loading. Please reload this page.
Really a powerful project and thanks for the hard time and effort that you've put in the development of this tool.
I am willing to help and contribute in any testing involved but will be testing on my own vehicle so we could take this project to the next level.
I have some concerns:
All reactions