Register
Page 5 of 138 FirstFirst 123456789101555105 ... LastLast
Results 61 to 75 of 2067
  1. #61
    Banned

    Join Date
    May 2010
    Location
    Usa
    Posts
    129
    Thanks Thanks Given 
    20
    Thanks Thanks Received 
    71
    Thanked in
    10 Posts

    Default

    Quote Originally Posted by JOHNCICY View Post
    SMALL KNOWLEDGE OF E S L.
    No need of learning with DAS
    May be this is all if someone need to make key without key maker. Just use this dump for ESL from JOHNCICY post, from my post #9 use dump for any key just put correct SSID and PASSWORD,after that put info in EZS any arhive of my post have correct place for key. After programming of key you can start the car. But for some model with automatic transmission you may need to reprogram ECU.

  2. The Following User Says Thank You to doslamer For This Useful Post:

    zas010970 (5th June, 2017)

  3. #62
    DK Veteran
    ivanrpm's Avatar
    Join Date
    Apr 2010
    Location
    costa rica
    Posts
    694
    Thanks Thanks Given 
    48
    Thanks Thanks Received 
    79
    Thanked in
    58 Posts

    Default

    Quote Originally Posted by doslamer View Post
    May be this is all if someone need to make key without key maker. Just use this dump for ESL from JOHNCICY post, from my post #9 use dump for any key just put correct SSID and PASSWORD,after that put info in EZS any arhive of my post have correct place for key. After programming of key you can start the car. But for some model with automatic transmission you may need to reprogram ECU.
    yes bro you are completly right this will work, making a summary of all info, excelent, like bram380 want to do at the beggining make a key without software,by hand!

  4. The Following User Says Thank You to ivanrpm For This Useful Post:

    zas010970 (5th June, 2017)

  5. #63
    DK Veteran JOHNCICY's Avatar
    Join Date
    Mar 2011
    Location
    EAST AFRICA
    Posts
    302
    Thanks Thanks Given 
    30
    Thanks Thanks Received 
    46
    Thanked in
    21 Posts

    Exclamation

    Quote Originally Posted by JOHNCICY View Post
    SMALL KNOWLEDGE OF E S L.
    No need of learning with DAS
    I found out that this dump works on w211 also........

  6. The Following User Says Thank You to JOHNCICY For This Useful Post:

    zas010970 (5th June, 2017)

  7. #64
    V.I.P. Member
    bram380's Avatar
    Join Date
    Aug 2009
    Location
    Indonesia +628153111774
    Posts
    3,884
    Thanks Thanks Given 
    482
    Thanks Thanks Received 
    2,018
    Thanked in
    1,013 Posts

    Default

    Welcome to the month of Ramadan, the month of forgiveness.
    God bless all.

  8. The Following 3 Users Say Thank You to bram380 For This Useful Post:

    duplikeytor (14th April, 2017), NORSHAN (8th April, 2014), zas010970 (5th June, 2017)

  9. #65
    Top Poster lexa-dok's Avatar
    Join Date
    Jun 2010
    Location
    Rim
    Posts
    188
    Thanks Thanks Given 
    39
    Thanks Thanks Received 
    4
    Thanked in
    4 Posts

    Default

    Please for me

    Mercedes EIS 210 Key by dump

    thanks
    Attached Files Attached Files

  10. The Following User Says Thank You to lexa-dok For This Useful Post:

    zas010970 (5th June, 2017)

  11. #66
    V.I.P. Member
    bram380's Avatar
    Join Date
    Aug 2009
    Location
    Indonesia +628153111774
    Posts
    3,884
    Thanks Thanks Given 
    482
    Thanks Thanks Received 
    2,018
    Thanked in
    1,013 Posts

    Default

    please info ezs type & mcu1 &2 type (zc.....)

    FYI:
    mcu1 & mcu2 without password, so new key wont work.
    please read again mcu.
    or read old key to see the password.
    Last edited by bram380; 11th August, 2012 at 03:43 PM.

  12. The Following User Says Thank You to bram380 For This Useful Post:

    zas010970 (5th June, 2017)

  13. #67
    V.I.P. Member
    bram380's Avatar
    Join Date
    Aug 2009
    Location
    Indonesia +628153111774
    Posts
    3,884
    Thanks Thanks Given 
    482
    Thanks Thanks Received 
    2,018
    Thanked in
    1,013 Posts

    Default

    ESL learning

    address: containts:
    -------- ----------
    00-0F ...?????... ---> SSID, Password ?
    10-1F key0 hash
    20-2F key1 hash
    30-3F key2 hash
    40-4F key3 hash
    50-5F key4 hash
    60-6F key5 hash
    70-7F key6 hash
    80-8F key7 hash
    90-9F ...?????.... ---> synchrone code to ecu?

    example:
    40-4F xxxx 3333 xxxx xxxxx ---> key3 used
    50-4F 4444 4444 4444 4444 ---> key4 not used
    60-6F 5555 xxxx xxxx xxxx ----> key5 used

    4444 is first 8byte of key4

    Need confirmation from mb expert about this esl.
    Last edited by bram380; 11th August, 2012 at 03:19 PM.

  14. The Following 3 Users Say Thank You to bram380 For This Useful Post:

    giovani (26th August, 2013), NORSHAN (8th April, 2014), zas010970 (5th June, 2017)

  15. #68
    Top Poster lexa-dok's Avatar
    Join Date
    Jun 2010
    Location
    Rim
    Posts
    188
    Thanks Thanks Given 
    39
    Thanks Thanks Received 
    4
    Thanked in
    4 Posts

    Default

    Quote Originally Posted by bram380 View Post
    please info ezs type & mcu1 &2 type (zc.....)

    FYI:
    mcu1 & mcu2 without password, so new key wont work.
    please read again mcu.
    or read old key to see the password.

    what to do

    can as that it is possible to restore dump with EIS

    still I apply ESL dump
    Attached Files Attached Files

  16. The Following User Says Thank You to lexa-dok For This Useful Post:

    zas010970 (5th June, 2017)

  17. #69
    V.I.P. Member
    bram380's Avatar
    Join Date
    Aug 2009
    Location
    Indonesia +628153111774
    Posts
    3,884
    Thanks Thanks Given 
    482
    Thanks Thanks Received 
    2,018
    Thanked in
    1,013 Posts

    Default

    I think ezs dump read by k-line
    Last edited by bram380; 11th August, 2012 at 11:25 PM. Reason: un-complete info

  18. The Following User Says Thank You to bram380 For This Useful Post:

    zas010970 (5th June, 2017)

  19. #70
    Top Poster lexa-dok's Avatar
    Join Date
    Jun 2010
    Location
    Rim
    Posts
    188
    Thanks Thanks Given 
    39
    Thanks Thanks Received 
    4
    Thanked in
    4 Posts

    Default

    Mercedes EZS 210 Key by dump

    re-read anew
    Attached Files Attached Files

  20. The Following User Says Thank You to lexa-dok For This Useful Post:

    zas010970 (5th June, 2017)

  21. #71
    V.I.P. Member
    bram380's Avatar
    Join Date
    Aug 2009
    Location
    Indonesia +628153111774
    Posts
    3,884
    Thanks Thanks Given 
    482
    Thanks Thanks Received 
    2,018
    Thanked in
    1,013 Posts

    Default

    Key no.0,1,2 used.
    Key no.7 have source code error
    Make new keys no.3,4,5,6
    Last edited by bram380; 13th August, 2012 at 04:10 PM.

  22. The Following 2 Users Say Thank You to bram380 For This Useful Post:

    NORSHAN (8th April, 2014), zas010970 (5th June, 2017)

  23. #72
    DK Veteran JOHNCICY's Avatar
    Join Date
    Mar 2011
    Location
    EAST AFRICA
    Posts
    302
    Thanks Thanks Given 
    30
    Thanks Thanks Received 
    46
    Thanked in
    21 Posts

    Default

    Quote Originally Posted by lexa-dok View Post
    Mercedes EZS 210 Key by dump

    re-read anew
    Here u have ......test and report
    Attached Files Attached Files

  24. The Following User Says Thank You to JOHNCICY For This Useful Post:

    zas010970 (5th June, 2017)

  25. #73
    Member mark.sch's Avatar
    Join Date
    Jan 2010
    Location
    Germany
    Posts
    72
    Thanks Thanks Given 
    0
    Thanks Thanks Received 
    6
    Thanked in
    6 Posts

    Default

    Very, very interesting thread ;-)

    When ESL contains SSID+Pass+Hashes it should be possible to manually rebuild a lost EZS eeprom? A hope for all those having their eeprom damaged due to faulty xprog (my case).

    At least when 722.9 gearbox is present, this seem to become even harder. But dismounting 7G and doing SPI coding is not an option for me right now.

    So I am taking a closer look doing it the Mercedes way with MB DAS - ESL_RESET, ECU_RESET and key learning. In one of the first posts it is said that a EZS eeprom and key without SSID+Pass is virgin. Does it mean, when you take any spare EZS remove this information from EZS and Key, it behaves like a virgin EZS with green dealer key - so you have all MB DAS possibilities?

  26. The Following User Says Thank You to mark.sch For This Useful Post:

    zas010970 (5th June, 2017)

  27. #74
    DK Veteran

    Join Date
    Apr 2010
    Posts
    546
    Thanks Thanks Given 
    174
    Thanks Thanks Received 
    1,174
    Thanked in
    383 Posts

    Default

    HI ,
    I have reversed a little ESL, attached W203_DIS, If I upload
    ESL_AUTO_LEARNING_KEY.bin will ESL adapt to EZS or EZS to ESL, what keys will be accepted?

    CF30DBFA7816FBD6747E850D5C57A115
    653B34A9371DA2D81D69584F6BA4A1DB
    1C42C469A209871003049C61C674A24C
    2A887FBB2A887FBB2A887FBB2A887FBB
    F0D5236CF0D5236CF0D5236CF0D5236C
    DD0A6ADEDD0A6ADEDD0A6ADEDD0A6ADE
    AF23065DAF23065DAF23065DAF23065D
    D2A3AF7BD2A3AF7BD2A3AF7BD2A3AF7B
    D589DCF5D589DCF5D589DCF5D589DCF5
    FFFF320163636300005514020000FFA1

    The last row is autochecked and repaired if check fails, also at $197 ussually the ESL writes $F7 by it's self!
    At 0x80 is the Password challange so ESL can be Erased.
    If someone can make some test's and inform here on forum, then reversing can be focused in less subroutines.
    Protocol can be sniffed at speed of 9600 8N1, use HTERM der-Hammer: HTerm - A Terminal Program for Windows and Linux can do a RAW log or hex with time stamp.
    Regards ficho

  28. The Following 2 Users Say Thank You to ficho For This Useful Post:

    antonypaul (22nd July, 2023), zas010970 (5th June, 2017)

  29. #75
    Member mark.sch's Avatar
    Join Date
    Jan 2010
    Location
    Germany
    Posts
    72
    Thanks Thanks Given 
    0
    Thanks Thanks Received 
    6
    Thanked in
    6 Posts

    Default

    Quote Originally Posted by ficho View Post
    HI ,
    I have reversed a little ESL, attached W203_DIS, If I upload
    ESL_AUTO_LEARNING_KEY.bin will ESL adapt to EZS or EZS to ESL, what keys will be accepted?

    CF30DBFA7816FBD6747E850D5C57A115
    653B34A9371DA2D81D69584F6BA4A1DB
    1C42C469A209871003049C61C674A24C
    2A887FBB2A887FBB2A887FBB2A887FBB
    F0D5236CF0D5236CF0D5236CF0D5236C
    DD0A6ADEDD0A6ADEDD0A6ADEDD0A6ADE
    AF23065DAF23065DAF23065DAF23065D
    D2A3AF7BD2A3AF7BD2A3AF7BD2A3AF7B
    D589DCF5D589DCF5D589DCF5D589DCF5
    FFFF320163636300005514020000FFA1

    The last row is autochecked and repaired if check fails, also at $197 ussually the ESL writes $F7 by it's self!
    At 0x80 is the Password challange so ESL can be Erased.
    If someone can make some test's and inform here on forum, then reversing can be focused in less subroutines.
    Protocol can be sniffed at speed of 9600 8N1, use HTERM der-Hammer: HTerm - A Terminal Program for Windows and Linux can do a RAW log or hex with time stamp.
    Regards ficho

    Just for understanding, you read Motorola 68HC05E6 flash memory on bench with s.th. like xprog and used IDA disassembler with Motorola instruction set? But where comes your HTERM serial sniffing into place, which interfaces with serial communication are you listening at?


  30. The Following User Says Thank You to mark.sch For This Useful Post:

    zas010970 (5th June, 2017)

 

 

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
This website uses cookies
We use cookies to store session information to facilitate remembering your login information, to allow you to save website preferences, to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners.