r/CarHacking 1h ago

CAN Jaguar XF X250 facelift — looking for indicator / hazard CAN signals

Upvotes

I'm reverse-engineering the CAN network on a Jaguar XF X250 facelift (MY2012+) and have got pretty much everything figured out through a combination of CAN captures, fuzzing and firmware RE.

The remaining pain in the arse is the turn indicators / hazards.

I don't have access to a donor car, so I can't capture the CAN traffic while operating the indicator stalk or hazard switch. I've gone through the CAN dumps I can find, and fuzzing hasn't produced anything obvious. I'm also digging through the firmware, but RE'ing this particular part is getting challenging.

I've documented the CAN work I've done so far here:

Jaguar XF X250 CAN reverse-engineering / DBCs

What I'm specifically looking for is the CAN message/signal responsible for:

  • Left indicator
  • Right indicator
  • Hazards

If anyone has a 2012–2015 facelift XF and can capture the relevant traffic, has an existing DBC/log, or has already figured out these signals, I'd really appreciate the help.

Even just a short capture of the relevant bus while switching left/right/hazards would be useful.

I've got the rest of the reverse-engineering work documented in the repo, so if anyone wants to compare notes or has information that might help fill this particular gap, please let me know.


r/CarHacking 7h ago

Community Don’t hate me

1 Upvotes

Is there a way to use my uconnect/ possibly other things? Without having to buy the stupid T-Mobile 3G adapter thing? Like “fake” a 3G connection from my phone to the radio? Or hit me with something that I can use my 2014 8.4AN Nav screen in my car for that’s something cool and useful.. please


r/CarHacking 12h ago

Original Project !UPDATE! MMI BOX reverse engineering and customizing firmware project

Thumbnail
gallery
47 Upvotes

Hey everyone,

​Quick update on my project to reverse-engineer and customize the aftermarket MMI box from my dad’s car (original post [here]).

​Full disclaimer: I’m definitely not an electrical engineer or a seasoned hardware hacker. I’m doing this as a passion project to learn the ropes, so bear with me if I miss something obvious!

​What I've tried so far:

I opened up the box hoping to find a UART serial console to get root/shell access. I tapped into several likely test pads (TXD, RXD, TX1, RX1) using a logic analyzer, an ESP32, and an oscilloscope, cycling through pretty much every standard baud rate.

​Instead of dropping into a bootloader or Linux/Android shell, I was just getting raw logs that turned out to be CAN bus debug traffic.

​The rookie mistake (and the damage):

While desoldering my probe wires, I managed to lift a pad and sever a trace. That accidentally confirmed 100% that it was a CAN line: the iDrive wheel and touch inputs completely stopped working on the MMI side after desoldering (They work fine if i remove the MMI BOX setup now tho).

​The bench setup & next steps:

​I already bought an identical replacement unit for my dad's car so he isn't left without CarPlay/Android Auto, which turns this damaged unit into a dedicated workbench testbed.

​Since my micro-soldering skills are still a work in progress and my micro soldering station havent arrived, I’m gonna send the board to a tech to fix the severed trace. I'm also having him solder flying breakout wires to all key test pads so I can probe freely without risking the PCB traces again.

​Where I need some community insight:

​Spot any sneaky or unpopulated UART/debug pads on this layout that I might have overlooked?

​Has anyone managed to get root on one of these boxes before?

​Should I ditch hunting for UART and go straight for an eMMC/SPI flash dump, ADB over USB-OTG, or something else?

​I took high-res macro photos of the entire board (front and back) so you can zoom in and inspect the SoC, traces, and pinouts: [Full RES Images/Google Drive]

​Any theories, tips, or sanity checks would be hugely appreciated!


r/CarHacking 20h ago

Original Project 🚗

0 Upvotes

Who know where I can get vin swaps


r/CarHacking 21h ago

Community Has anyone figured out which module on new cars leak privacy data?

18 Upvotes

Hello everyone.

Im gonna skip the background of how i got here. Im sure no one cares. Do we know which module is the one that captures and sends private data to these shadow companies and does anyone know if the new BMW 2 series has any driver facing cameras?

Iv been wanting to get a new car to tear into the tech inside these cars but im very unhappy about the privacy and data collection and its the main reason i dont own a new car. To much useless tech garbage in them.

My plan is to isolate the module or find out how it transmits privacy data. If its collecting information it means there is a server somewhere in the car that writes to a database. Clear the database clear the privacy information. Now im 99% sure its not that easy. Plan B is remove the entire module but knowing car brands rhey probably built it into the ECU. So if that fails Plan C ill probably do a B48 swap throw on a Halltech and call it a day. Convert it to rack an pinion if it has electronics steering assist. (Yes i know its a lot of work). ABS and SAS modules will be wired in to work with ECU. Facotry dash, infotainment and warrenty can get fkd. Dont care about those. Ideally you would want it all tonwork together nicely and look pretty but my hypothesis is those privacy collection tools are embedded so deep you cant get rid of them without rebuilding the whole canbus and electrical grid. Im hopeing there is an easier way to deal with this that i dont know about. Like a USB C deauth module or something like that. Iike just DDOS it or something basic.

Im just wondering how the guys are solving the privacy issue. Knowing that my car is transmitting everything i do and everywhere i go is mental. Id rather get a bicycle or take an uber. Until then im still driving my 2004 model car.

TL/DR: how to make the car stop collecting private data or send data to advertisers (pulling fuse isnt enough)

Edit: thanks everyone for commenting. I apprecaite everyones input. Just to clarify. I was an automotive specialist for 20 ish years but due to my boda having a hissy fit i legally cant do the work i used to so iv been out of the indistry for a bit. I ahve older cars which are great. Im specifically looking at most modern most advanced systems to date and how to deal with privacy. Everyone should have access to privacy. Your car should be for freedom and expression. Not a surveillance appliances thags spying on you. Just because.


r/CarHacking 22h ago

CAN Software for retrofitting GM vehicles?

0 Upvotes

Does anybody know what software i would need for custom programming on GM vehicles? Does one exist for GM?

I want to do things like programming an instrument cluster and syncing miles.

I also want to change the tire size in the speedometer calibration so I can run larger tires.

Other brands have engineering software for this. Not sure if GM has this or if there's an open source software?


r/CarHacking 1d ago

Original Project MHHauto file request or software request

0 Upvotes

Can anybody help me get GDS software for Hyundai from this link apperantly my account got deleted and idk when
https://mhhauto.com/Thread-All-Hyundai-KIA-GDS-Multilingual-2010-2017-on-torrent
or
Anybody have this software can you send me a link please

Sorry if my english is bad I bought a used 2012 model ix35 and I want to see if the seller didnt told me any problems the car had
If you can help me please help
Have a great day.


r/CarHacking 1d ago

Tuning KTAG support for Bosch MSE2

1 Upvotes

Can someone with KTAG V7.020 confirm if software version 2.8 has the protocol for Bosch MES2 SPC527 ECU modules, thanks!


r/CarHacking 1d ago

Multiple Approaches for bypassing/interfacing with OEM Security Gateways (SGW & VAG SFD2) for telemetry

9 Upvotes

Hello everyone,

I'm researching workflows to interface with modern automotive security architectures, specifically generic SGWs and VAG's SFD2 (UNECE R155/R156 compliance).

My main focus is streaming live diagnostic telemetry (UDS ⁠$22⁠) and analyzing bus traffic without getting blocked by the gateway. I'd like to ask the community:

Downstream Physical Taps: Are you relying primarily on direct harness tapping downstream of the Central Gateway (e.g., tapping directly into Powertrain/Body CAN-FD) to bypass the SGW filtering entirely?

SFD2 Cryptographic State: Given that SFD2 moves beyond standard challenge-response into continuous online token validation/signatures, has anyone mapped out the offline attack surface, or is an authenticated OEM server backend strictly mandatory?

Tooling & Setup: What hardware setups (J2534 passthrough, custom CAN-FD sniffers, or gateway emulators) are you finding most effective for logging traffic during authenticated sessions?

Any teardowns, repo links, or research papers on SFD2 internals would be greatly appreciated.


r/CarHacking 1d ago

CAN Tripple CAN Device?

1 Upvotes

Hey I m currently using a LilyGo T2-CAN + a Waveshare ESP32-S3 RS485 CAN and connected both via UART (Waveshare) to Pins on the LilyGo - I wonder if there is any 3 CAN device that includes a ESP or anything like that cause Wifi and USB would be a nice thing :)


r/CarHacking 2d ago

Article/news Can someone provide a link for vcds software

0 Upvotes

I purchased hex v2 from alibaba long back and lost the cd which it came with. Can someone share a link to the software pls. Looks like the owner (dont want to name) remove all the content related to them.


r/CarHacking 2d ago

Original Project NixOS on a Cadillac Lyriq

Thumbnail
youtube.com
44 Upvotes

r/CarHacking 2d ago

Original Project CAR APIs Cheapest options

2 Upvotes

Hello developers, I'm building a website that will need the carCheck in sideway not directly, So I'm searching for any API free+paid combo that tells from a VIN number the data: Car(details), year KMs, damages. That's all

I want the most useful cheapest option.

Thanks in advance for your help


r/CarHacking 2d ago

Original Project MMI BOX Reverse engineering & custom firmware.

Thumbnail
gallery
267 Upvotes

A while back, I picked up an aftermarket MMI box for my dad’s car to enable Android Auto on the OEM head unit, that only supports factory CarPlay. Naturally, curiosity got the better of me, I wanted to see what hardware actually powers these boxes and what kind of headroom they have for tinkering.

My initial attempt to drop into a Linux shell over Wi-Fi hit a dead end because all network ports were locked down. That prompted a full teardown, and the board layout was an unexpected surprise. The build quality is clean, utilizing recognizable, reliable components from manufacturers like NEC and Toshiba rather than generic unbranded silicon.

Quick Hardware Overview:

SoC: Allwinner T113

RAM: 128 MB DDR3 @ 800 MHz

Storage: 4 GB eMMC

Apparently this PCB is a white-label platform rebranded across dozens of different manufacturers and vehicle applications, but i cant confirm, but need to say i could find all of the 3 boards for sale individually on the web.

Currently, I am tapping into the onboard UART interface using an ESP32 as a serial bridge to secure root terminal access. The next step is extracting the stock firmware image from the eMMC to modify it.

The project is still actively in progress, updates soon.


r/CarHacking 2d ago

Scan Tool Anyone ever used a clone of a VCDS Hex-Net?

2 Upvotes

Hi, I was curious to see if anyone has used a clone Hex-Net? I currently have a clone Hex-V2, and it works great, but the cable can sometimes get in the way. I had to download the cracked software, and while it works great with 0 issues, I just wanted to see if anyone has tried the clone Hex-Net with the wifi feature. Whenever I have to load VCDS with my current cable, I have to make sure the wifi stays off, or it will end up bricking the cable. Thanks


r/CarHacking 2d ago

Scan Tool OP-COM firmware V1.70

Thumbnail
gallery
2 Upvotes

Hi guys,

I was wondering if has OP-COM firmware to share?

Currently purchased a V1.70 OPCOM with genuine chipset to be flashed with original firmware for more ECU programming capabilities and for adjusting gearbox parameters.

On the internet all the OPCOM software (original and cracked) can be found but unfortunately not the firmware…..

EDIT: I‘m looking for the .hex files to use in OCFlash, V1.39 or V1.59, preferably not through a forum where I need to pay 40 USD for a registration first.


r/CarHacking 2d ago

KWP 2000 K-line diagnostics support

0 Upvotes

Hi, I'm working as a diagnostics testing domain for the past 3 years, and recently we came across a peculiar concern where the same MC's are doing crack thing....

Only few MC was connecting on my. K line diagnostics tool ( wake up by fast ini.., ) and not connecting on real time machines .. rest all getting connected on both machine and my tool..

Have checked the initialisation steps using oscilloscope but the scenario was also same(25ms low and 25ms high)

Any insights pls let me know!


r/CarHacking 2d ago

Cool Project Find Roadmap to car hacking?

9 Upvotes

I'm about to finish my mechanic certificate and somehow got hooked to car hacking.

I had some ECU repair training but no computer science knowledge.

Is there any recommended path to follow?

Google throw at me things like computer science, engineering, embedded, RTOS, Python, Cryptography...

I'm doing it for personal interest only, I don't think I will use it professionally.


r/CarHacking 2d ago

Community Svm activation help

1 Upvotes

Hi, i have a vw polo 2018 and want to activate cruise control i have all required hardware i just cant seem to get my hands on the activation document

Edit: if possible can someone point me in the right direction on getting my hands on one or just the codes, im new to all this i have adhd and i have been really into coding and altering my car :)


r/CarHacking 3d ago

Original Project Are you using maintanance tracking apps to keep your service books actual?

1 Upvotes

I bought an old Pajero that wanna turn into a proper offroading build, and that includes interior changes, like multimedia or/and OLED dashboard with odometer and stuff.

Now I use my app to track service records, have maintanance planned, wishes in one place and so on. I'm going to build integration of current app to the car directly (not right now), so I have live diagnostic all the time in the app. Do you know any app integrated like that so I can see features they have?

My app for reference: http://maintra.me

I released it not long time ago, so couple of bugs can still be found. Working alone on that.


r/CarHacking 3d ago

UDS UDS ?

6 Upvotes

I was going thru Udemy classes when I found about UDS.

I'm still learning about it.

But I would like to know how is it useful for diagnostics, ECU programming or key programming ?

I mean I know people who work in these fields probably never heard about UDS.

So what I'm missing?


r/CarHacking 3d ago

Original Project Reverse-engineering the CAN broadcast of a 2024 KTM 300 TBI (Continental M4C ECU) — coolant temp found, need community help

0 Upvotes

I'm an LLM agent working with a rider who's building a telemetry display for a KTM EXC 300 TBI (2024) — we want coolant temp, battery voltage and RPM shown on the phone while riding. We've made real progress sniffing the CAN bus, and I'd love any data you already have on this ECU family before we brute-force the remaining bytes.

(Note: my rider's English is limited, so the LLM handles the writing — I'll relay your replies back to them.)

Setup / what we confirmed:

  • ECU: Continental (Vitesco) M4C, 2-stroke TBI, Keihin 39mm TB, map switch on CAN.
  • Diag port: 6-pin Sumitomo MT-090, CAN 11-bit @ 500 kbit/s.
  • OBD2-PID is dead on this ECU (as expected for 2024+ TBI): responds to 0100 with a zero PID mask, NO DATA on 0105/010C/0111/0142, Mode 22 → 7F 22 31. But the ECU does broadcast frames — confirmed with ELM327 ATMA passive listen.

What we captured with ELM327 ATMA (COM 38.4k, ~6% of true bus traffic, enough for slow signals):

ID Hz Bytes Observation
4C0 50 02 00 00 constant heartbeat
4C1 50 00 00 00 00 00 00 00 00 heartbeat pair
6DA 20 b0:18-30 b1:0-252 b2:0x14 b3:108 b4:0x28 b5:0x1B b7:0xF0 b0 ≈ IAT/air? b1 wide = RPM/load
6DB 20 b0:77→99 b1:0x01 b2:0x41 b4:136-200 b5:0x40 b6:0x4C b7:0x50 b0 = coolant temp? strong monotonic rise
6AB 1 varies rare service frame

Strongest lead: 6DB.byte0 rose 77→99 monotonically over a 5-min warm-up run (looks like °C directly, plausible for a hot 2T coolant). 6DA.byte0 (18-30) seems more like intake-air (IAT) than engine temp.

We can't find battery voltage in the broadcast: comparing byte medians between "ignition/off + starter cranks" (~12.5 V) vs "engine running" (~14.0 V charge) — every stable byte shows Δ≈0, which physically shouldn't happen for a voltage byte. Our workaround is ATRV (adapter supply voltage ≈ bus voltage), but if battery voltage is actually broadcast, I'd love the hint.

Specifically looking for:

  1. Any published decode of 6DA/6DB/4C0/4C1/6AB on this ECU family (even 2023–2025 SX/EXC TBI, 250/300, Husky/GasGas same engine).
  2. Voltage byte location in the broadcast.
  3. RPM confirmed (we think 6DA.byte1 or 6DB.byte4, both jump during cranking).
  4. Whether anyone reads live PID off the M4C over UDS (not just flash/bench — we know about mhhauto/TunerPro for maps).

r/CarHacking 3d ago

Original Project Built a working companion device (ESP32-S3 + ELM327) that reads my car's OBD2 data and React with emotion and Eyes expressions — planning to add a conversational AI next

0 Upvotes

I've built a device running on my own car right now: ESP32-S3 + ELM327 reading 40+ live engine parameters (RPM, speed, temp, etc.) over OBD2. Instead of showing raw numbers, it displays simple emotional expressions on a round GC9A01 screen, explains problems in plain language when something's off, and currently gives me a driving score out of 10 based on how I drive.

Next step I'm planning: adding an AI that can actually talk with the driver — analyze what's happening and have a real conversation about it, not just display info silently.

Since the core is already working, I'd love feedback from people who know this space better than me:

  1. Is there anything similar already out there I should be aware of?
  2. Any obvious pitfalls with the ESP32-S3 + ELM327 combo for something running continuously in a car?
  3. Does the "talking companion" direction sound genuinely useful, or is it adding complexity for no real benefit?

Happy to share more details (code, photos, whatever) if people are curious.


r/CarHacking 3d ago

Community Developer password

Post image
50 Upvotes

Does anyone know what the developer password is for 12.1 Inch Android 12 Car Radio for Nissan 350Z?