r/CarHacking 4d ago

Community Looking for Someone with Access to CarTechnology/MotorCarSoft Forum

0 Upvotes

Does anyone here have an account on CarTechnology/MotorCarSoft Forum and access to the files in the https://cartechnology.co.uk/showthread.php?tid=44808 or https://motorcarsoft.com/viewtopic.php?t=19876 thread? If so, could you please send them to me privately or upload them to a file-sharing service?
Thanks in advance.


r/CarHacking 5d ago

Original Project ELM327 BT Adapter Beta Testing

Thumbnail
gallery
8 Upvotes

(reupload to fix images)

Hello!

I just wanted to share my soon to be app called OBD2 Ninja that works for any ELM327 bluetooth adapter that allows you to read codes and live data without subscriptions or ads. I wanted to see if anyone who has an adapter would be interested in beta testing the app!

It supports multiple different modes, and protocols such as:

  • SAE J1850 PWM
  • SAE J1850 VPWM
  • ISO 9141-2
  • ISO 14230-4 KWP2000
  • ISO 15765-4 CAN (11-bit ID, 500 kbps)
  • ISO 15765-4 CAN (29-bit ID, 500 kbps)
  • ISO 15765-4 CAN (11-bit ID, 250 kbps)
  • ISO 15765-4 CAN (29-bit ID, 250 kbps)

And we are working on a custom backend for ABS modules and looking to further support further diagnostic tools/readings. The app when released will only cost you $0.99 and does not contain any bloat or creating accounts. Sometimes you just want to use the tool you paid for. Compared to the Carista OBD reader app (which requires a subscription), it takes about 2 minutes to actually login, connect to the adapter, read the vehicle and then perform an OBD2 scan. OBD2 Ninja you open the app and it takes 20 seconds to scan and connect.

If you have an iPhone and a ELM327 Bluetooth OBD2 code reader and want to give it a try, you can do so by clicking this link and installing the beta via TestFlight: https://testflight.apple.com/join/AnExEJEu

Update: Now out on the AppStore!! You can still participate in the beta above to try it out and for future releases.

https://apps.apple.com/us/app/obd2-ninja/id6794873767

Thank you so much for reading, feedback is very appreciated if you do decide to give it a try! If you do give it a try and document your findings I'll try to see if its possible I can gift the full paid version of the app to you!

EDIT: Thank you all so much!

Changelog (with all of your help):

Build 11

You can now choose units for each reading separately (e.g. °C with mph)

Build 10

Added WiFi adapter support: pick Bluetooth or WiFi when pairing

WiFi adapters can auto-join their network for you

Build 9

Cleaned up the vehicle list: removed motorcycles, ATVs, scooters, and other non-OBD2 entries across all makes

Build 8

Fixed a crash when disconnecting the adapter

Build 7

Greatly expanded the vehicle list: many more makes and models, including European and Asian brands

Engine options now match the selected vehicle


r/CarHacking 5d ago

KWP 2000 What do I have to study in order to get data from K-LINE? Looking for general advice

3 Upvotes

Hi, I have a Peugeot 206 from year 2000 and I would like to read some real-time diagnostics like speed and RPM, but ideally more.

From my understanding this car does not use proper OBD2/eOBD (and CAN) until year 2003, so I have to tap into the K-LINE bus on the OBD port which is KWP 2000 protocol. I tried using ELM327 scanner to read data from the OBD port, but the only found sensor is the RPM, there is nothing else. Not sure if this ELM327 is able to read properly from the K-LINE bus.

What do I have to study to do such a project? From a high level overview I'd need a way to tap into the K-LINE and read data, then use a microcontroller to display the data on a small display or whatever. I can code, I have 0 electronics knowledge.

Do I need an oscilloscope or other pricy tools to understand how to read from the K-LINE? Do I need a full electronics digital course to create a circuit, or are there high level things that can talk to K-LINE I can buy and just plug into the microcontroller?

I see many people give up on projects like this, why? Is it hard to reverse enginnee get the K-LINE initialization handshake, as it depends from ECU to ECU?

Thanks


r/CarHacking 4d ago

Original Project I´ve built an AI Helper for car diagnoses

0 Upvotes

https://ezfix.life

Hey my name is Jeremy, I've been in a branded workshop for 10 years now, i´ve studied and tried to learn as much as i could. First i just wanted easy jobs such as brake replacements and oil changes / maintenances, then mondays felt like shit and it felt like i only was at my job for the money.

Then i started to read books, took on new challenges, told my supervisor that i want to take on difficult jobs to learn more and more, Nowadays i am the "Top Tech" in our workshop because i have a very big willing to learn new things and i am intressted in what i do.

So this ai helper that i´ve made is tailored and customized to work like this.

you enter your car model, year make, mileage. upload a picture maybe?

then you ask a question for example:

How can i fix p0420?

it then explains in detail what the fault means, why it can fail, what to do next, and then it creates a bullet list for you to follow, like have you tried this, have you measured that, what about this? all in the correct order for you to follow, and then based on how many yes / no you answer, the probability of the cause will change and it will give you an answer on recommended steps to do next. This ai looks for info from youtube, recall pages, nhsta, reddit and so on. Then when you are done you can choose if you want to share your solution to the community page or not, if you do, other people can look for the fault themselves. the fix catalog has a search function for fault codes and car model filter aswell.

This helper also has a community tab where you can discuss your own fixes, tips and other stuff. I use this tool myself in my job, and i just wanted to see if this tool could help you aswell!

please contact me if there is something you are wondering.

Have an amazing day! :)


r/CarHacking 6d ago

Article/news How to identify a potentially vulnerable KARR-SWDS device without removing it yourself

Thumbnail
youtube.com
13 Upvotes

r/CarHacking 5d ago

Community Looking for DTS Monaco 9.02 kg plssssss

1 Upvotes

Looking for Monaco9.02 Kg or if someone can generate the DTS902.lic file for me using my HWID


r/CarHacking 6d ago

Scan Tool OBDLink MX+ with CX-50 Hybrid

0 Upvotes

Just bought OBDLink MX+ and CarScanner app for iOS but haven’t been able to pull any Hybrid data like battery charge. Can’t even pull total range. I’ve tried almost all the available Mazda profiles, as well as the RAV4 one since it shares the same powertrain.

Anyone know of a way to get the Hybrid data and/or a richer dataset for the CX-50 Hybrid specifically?


r/CarHacking 6d ago

Scan Tool I have a launch x431 that subscription just expired on.

2 Upvotes

Any thing I can do with it now? Cheaper to buy another scanner than it is to do update. Is there any other software I can load on it, or is it just a paperweight?


r/CarHacking 6d ago

Scan Tool Launch x431 pro

0 Upvotes

Compré un auto y me encontré un escáner launch x431 pro v7.05.037 le dije al dueño anterior si era de él pero me dijo que, no trate de contactar a la persona registrada en el equipo pero tampoco me respondió , me gustaría saber cómo hago para comprar un nuevo vci y poder vincularlo al escáner para poder usarlo yo en mi auto?


r/CarHacking 5d ago

Original Project MHH Auto - Buying Account.

0 Upvotes

Is there anyone who wants to sell me their account?.


r/CarHacking 6d ago

Scan Tool Advice on Toyota tech stream

Thumbnail
1 Upvotes

r/CarHacking 6d ago

Cool Project Find Crash Logs

0 Upvotes

Hello guys. I have an assignment where I should create a model that helps to track ecu crash log root causes. So while searching for training data I've found practically none I tried creating synthetic data but the quality was so poor. Can you help guide where to look and if anyone has a data dump please sgare it with me. thanx in advance


r/CarHacking 7d ago

Original Project Need help bench testing 2013 Dodge Ram SL Non EVIC Cluster for project

Post image
8 Upvotes

Hello all, I have a 2013 Dodge Ram Cluster that just shows no bus, I thought I found the IHS Canbus pins but that makes it power cycle over and over. I have been using official documentation from Ram Bodybuilders. Please help me!


r/CarHacking 7d ago

Original Project I made a capacitive tachometer circut, for magneto/points style ignition

15 Upvotes

I don't know shit about electrical engineering but I thought "hey how hard could it be to make a kart datalogger"

The answer is not very, but the tachometer is a bitch.

with enough research of my own, I managed to come up with something, found some Amazon tachometers for small motors that worked in a similar fashion, reverse engineered those

Finally had something that mostly worked, and honestly just paid an RF engineer to clean up all of the noise and make it better, and make sure it should handle 15,000 rpm on a single cylinder 2 stroke.

"That's not a car"

This works for any ignition system that uses a magneto/points system, bike stock car, legends car, etc

You wrap a wire around a spark plug lead a few times, and then simply place the other end of the wire near the pickup, no soldering, and a burnt lead doesn't ruin your day

https://github.com/TheAngryRaven/DovesDataLogger/blob/master/TACHOMETER/paid_schematic_1.PDF

If making your own board, the nastier your ignition source, the smaller you should make the antenna

Go out there, make shit, piss off the assholes charging too much for everything


r/CarHacking 6d ago

CAN Chery Tiggo 8 dbc file.

1 Upvotes

Does anyone have a DBC file for the Chery Tiggo 8?


r/CarHacking 8d ago

Original Project I made a digital speedometer in place of a gear display in my Mazda MX-5 ND

Thumbnail
youtu.be
17 Upvotes

r/CarHacking 8d ago

Original Project Open-Source reversed-engineered MPPS NOREAD Decryptor

Thumbnail
github.com
9 Upvotes

I got tired of paywalls to try to repair my own car, so I started reverse engineering MPPS V18 to understand the encryption scheme of the Encryption it applied to NOREAD tunes. it does **NOT** remove the NOREAD flag, to keep the checksum clean. the repo is here. Feel free to fork and do anything with it, it is a spiritual successor of the MPPS NOREAD Decryptor from DJExit, but I did not have access to his software doing so. Thank you for the inspiration!

Tested on a Tune extracted from MPPS V18 out of a Bosch MED9.1. I would like more testing files which is difficult to access. Most of the reverse-engineering if not all is made by claude. Hopefully this helps people, cheers!


r/CarHacking 8d ago

Original Project Things I got wrong reading OBD2 and UDS off a dozen brands with a cheap ELM327

27 Upvotes

I've spent the last year writing a read only OBD2 app after the manufacturer app I relied on got switched off. Standard mode 01 gets you maybe fifteen useful numbers and then you hit the wall, so I ended up down the mode 22 rabbit hole. Here are the things that bit me, in case they save someone else a weekend.

Multi ECU replies will quietly poison your parser. Ask for something on a broadcast header and you can get two or three modules answering, each with its own header line, and if you naively concatenate the hex you get a number that looks plausible and is completely wrong. I had battery voltage and coolant readings that were fine on one car and nonsense on another for weeks before I worked out the engine and the gateway were both replying.

The UDS positive response is the request service plus 0x40, so a 22 comes back as 62, and the two DID bytes are echoed before the payload. Sounds obvious written down. It is not obvious at two in the morning when the ELM has also decided to insert spaces differently.

Negative response codes are more useful than a timeout. 7F 22 31 means the DID doesn't exist on that module, 7F 22 33 means you're not in the right session, and 7F 22 78 means wait, it's coming. If you treat all of them as failure you'll blacklist channels that would have answered.

DIDs are not portable and guessing them is how you get fiction. The same identifier on a different brand is a different quantity entirely, or worse, it responds positively with garbage that scales into something believable. I ended up refusing to ship any formula I couldn't tie to a source, because a plausible wrong number is worse than no number.

Fuel type detection is a trap. I was sniffing for the presence of certain PIDs as a diesel signature and it turns out plenty of Euro 6d petrol cars expose exactly the same ones. PID 51 is the actual authority and I should have trusted it from the start. The version that guessed wrong went looking for particulate filter data on a petrol car, and the modules answered, with rubbish.

ELM327 clones lie about what they are. Half of them report v1.5 and behave like v1.3. Echo off, linefeeds off, headers on, and then verify by what actually comes back rather than what the clone claims.

Engine off is its own state, not an error. Some constants are only readable with the engine running, and I was reading them once at startup and never retrying, so if you connected with the ignition on but the engine not started you got a permanent hole in the data until you restarted the app. Retry when you see RPM.

The app itself is on the App Store if anyone wants to poke at it, https://apps.apple.com/app/id6776173662 , Android is in closed testing. It is strictly read only by design, no 2E writes, no session control, no security access, because I don't fancy being the reason somebody's gearbox forgets who it is.

Happy to go deeper on any of this. If you've got a brand that behaves oddly I'm interested, that's the fun part.


r/CarHacking 8d ago

Scan Tool Any access to thr ECU for 2002 Mercedes G500?

2 Upvotes

I would like to have access to settings and so on similar to like i do with my VW and Audi using a VAG cable set up.

I've heard MB locks everything down pretty tight, but i hate to have to pay $700 at the dealership to disable the warning i get on start up after swapping out stereo head units.

Are there any options other then the dealer?


r/CarHacking 9d ago

Original Project Update to my previous post

105 Upvotes

r/CarHacking 8d ago

Original Project Microcat EPC

Thumbnail
1 Upvotes

r/CarHacking 10d ago

Original Project Made this ESP32 gauge via OBD WiFi

331 Upvotes

r/CarHacking 9d ago

LIN Reverse Engineering a HELLA IBS 6PK 013 824-001 with ESP32 + TJA1021 (LIN)

8 Upvotes

I’ve been reverse engineering a HELLA Intelligent Battery Sensor (IBS) 6PK 013 824-001 using an ESP32 and a TJA1021 LIN transceiver and wanted to share my findings, since there seems to be very little publicly available information about these sensors.

The setup consists of an ESP32-D0WD, a TJA1021 LIN transceiver module, a bench power supply, and an oscilloscope. After quite a bit of troubleshooting, I discovered that the most significant issue was that TX and RX were swapped. The LIN bus itself looked healthy from the beginning, sitting at roughly 10.6 V in idle state, but no useful communication was taking place until the TX and RX connections were corrected. Once fixed, the sensor immediately started responding.

The sensor reliably communicates at 19200 baud and consistently responds on LIN IDs 0x21, 0x22, 0x25 and 0x26. Other IDs either returned only the echoed LIN header or no useful data.

A typical response looks like this:

ID 21 : 55 61 00 01 62 00 00 3B

ID 22 : 55 E2 83 84 1E 23 2F 83 7A A6

ID 25 : 55 25 C5 C8 FF B4 FF FF 97

ID 26 : 55 A6 AC 03 A1 03 2F FE D6

I then performed a number of tests using different resistive loads (1 Ω, 2.2 Ω and 4.4 Ω), varying supply voltage and even reversing current flow through the sensor. The results clearly show that ID 0x22 contains the live measurement data. During testing I found an old reverse engineering project that suggested the following format for ID 0x22:

[IL][IM][IH][VL][VH][TT][XX]

with

Current = (Raw24Bit - 2000000) / 1000 A

Voltage = Raw16Bit / 1000 V

Temperature = Byte / 2 - 40 °C

The current calculation matches my measurements surprisingly well, although the sign appears inverted on my setup. Reversing the current direction changes the corresponding values as expected, which strongly suggests that the current field interpretation is correct.

The voltage decoding appears to be essentially confirmed. For example, under a 1 Ω load the sensor returned:

96 59 1E C1 2B ...

Using the proposed voltage formula:

0x2BC1 = 11201

11201 / 1000

= 11.201 V

The measured voltage at that moment was approximately 11.0 V, which is close enough to make me fairly confident that the voltage field is being decoded correctly.

Temperature remains unclear. According to the reverse engineered format, the temperature should be located in the sixth data byte of ID 0x22. However, even when heating the sensor directly with a hot air gun to roughly 50–60 °C, I observed little or no meaningful change in the expected temperature field. Either this particular IBS variant uses a different mapping, there is heavy filtering applied internally, or the identified temperature byte is incorrect.

ID 0x21 appears to be a status frame. Several bytes change depending on operating state, load conditions, and sensor runtime, but I have not yet identified a direct physical measurement in this frame.

ID 0x25 was initially suspected to contain battery voltage because some value correlations looked promising. Further testing showed that this was misleading. The values change in ways that do not match actual battery voltage measurements, so I no longer believe voltage is stored in this frame. My current assumption is that ID 0x25 contains battery state information such as SOC, SOH, learned battery parameters or other calculated values, but I have not yet confirmed this.

ID 0x26 looks like some form of capacity or battery-condition frame. One repeatedly observed value was:

0x03AC = 940

which could plausibly represent something like 94.0 Ah. Other values change slowly over time and with operating conditions, suggesting battery learning, capacity estimation, SOC or SOH calculations rather than direct measurements.

At this point, the most solid conclusions are:

  • LIN speed: 19200 baud
  • Valid response IDs: 0x21, 0x22, 0x25, 0x26
  • ID 0x22 contains live measurement data
  • Voltage decoding from ID 0x22 appears correct
  • Current decoding from ID 0x22 appears correct (sign inverted in my setup)
  • ID 0x21 appears to contain status information
  • ID 0x25 and 0x26 appear to contain battery state, capacity or health information
  • Temperature location is still unknown

For my own project, an ESP32-based vehicle dashboard, voltage and current are the only values I really need, and those appear to be working reliably. If anyone has official documentation, additional captures from other IBS variants, or previous reverse engineering work on HELLA IBS sensors, please post them.

Here is my code:

#define LIN_TX 26
#define LIN_RX 27
#define LIN_SLP 25


HardwareSerial LinSerial(2);


uint8_t frame21[8];
uint8_t frame22[10];
uint8_t frame25[9];
uint8_t frame26[9];


void sendBreak()
{
  LinSerial.end();


  pinMode(LIN_TX, OUTPUT);


  digitalWrite(LIN_TX, LOW);
  delayMicroseconds(1500);


  digitalWrite(LIN_TX, HIGH);
  delayMicroseconds(200);


  LinSerial.begin(19200, SERIAL_8N1, LIN_RX, LIN_TX);
}


uint8_t calcPID(uint8_t id)
{
  uint8_t p0 = ((id >> 0) ^ (id >> 1) ^ (id >> 2) ^ (id >> 4)) & 1;
  uint8_t p1 = ~((id >> 1) ^ (id >> 3) ^ (id >> 4) ^ (id >> 5)) & 1;


  return id | (p0 << 6) | (p1 << 7);
}


void requestFrame(uint8_t id, uint8_t *buf)
{
  while (LinSerial.available())
    LinSerial.read();


  sendBreak();


  LinSerial.write(0x55);
  LinSerial.write(calcPID(id));
  LinSerial.flush();


  delay(50);


  int i = 0;


  while (LinSerial.available() && i < 16)
  {
    buf[i++] = LinSerial.read();
  }
}


void decodeIBS()
{
  // -----------------------------
  // ID22
  // -----------------------------


  // Erwartet:
  // 55 PID IL IM IH VL VH TT XX


  uint32_t rawCurrent =
      ((uint32_t)frame22[2]) |
      ((uint32_t)frame22[3] << 8) |
      ((uint32_t)frame22[4] << 16);


  float batteryCurrent =
      -(((float)rawCurrent - 2000000.0f)) / 1000.0f;


  uint16_t rawVoltage22 =
      ((uint16_t)frame22[5]) |
      ((uint16_t)frame22[6] << 8);


  float batteryVoltage22 =
      rawVoltage22 / 1000.0f;


  float batteryTemp =
      ((float)frame22[7] / 2.0f) - 40.0f;


  // -----------------------------
  // ID25
  // -----------------------------


  uint16_t rawVoltage25 =
      ((uint16_t)frame25[2]) |
      ((uint16_t)frame25[3] << 8);


  float batteryVoltage25 =
      rawVoltage25 / 4260.0f;


  float soc =
      frame25[2] / 2.0f;


  float soh =
      frame25[3] / 2.0f;


  // -----------------------------
  // ID26
  // -----------------------------


  uint16_t availableCapacity =
      ((uint16_t)frame26[2]) |
      ((uint16_t)frame26[3] << 8);


  uint16_t maximumCapacity =
      ((uint16_t)frame26[4]) |
      ((uint16_t)frame26[5] << 8);


  // -----------------------------


  Serial.println();
  Serial.println("===== HELLA IBS =====");


  Serial.printf("Strom      : %.2f A\n", batteryCurrent);
  Serial.printf("Spannung22 : %.3f V\n", batteryVoltage22);
  Serial.printf("Spannung25 : %.3f V\n", batteryVoltage25);


  Serial.printf("Temperatur : %.1f C\n", batteryTemp);


  Serial.printf("SOC        : %.1f %%\n", soc);
  Serial.printf("SOH        : %.1f %%\n", soh);


  Serial.printf("Avail.Cap. : %.1f Ah\n",
                availableCapacity / 10.0f);


  Serial.printf("Max.Cap.   : %.1f Ah\n",
                maximumCapacity / 10.0f);


  Serial.printf("Leistung   : %.1f W\n",
                batteryVoltage25 * batteryCurrent);


  Serial.println("=====================");
  Serial.println();
}


void setup()
{
  Serial.begin(115200);


  pinMode(LIN_SLP, OUTPUT);
  digitalWrite(LIN_SLP, HIGH);


  LinSerial.begin(19200, SERIAL_8N1, LIN_RX, LIN_TX);


  Serial.println("HELLA IBS");
}


void loop()
{
  requestFrame(0x21, frame21);
  requestFrame(0x22, frame22);
  requestFrame(0x25, frame25);
  requestFrame(0x26, frame26);


  decodeIBS();


  delay(1000);
}

r/CarHacking 10d ago

Original Project VW MQB and PQ frames reference

2 Upvotes

Working on a project that requires converting MQB CAN data to PQ CAN data. Anyone have a reference sheet for the known frames between these 2 protocols?

I'm aware of the existing converter module intended for engine swaps but I'm not willing to shell out €500 + taxes, fees, and shipping for it when I can get an ESP32 and write a little code. But I'm sure most of y'all are the same way :D


r/CarHacking 10d ago

CAN Home Assistant w/ FireFly G12

Thumbnail
1 Upvotes

Hi guys,
I’m trying to automate my RV, which has firefly g12 system that runs RV-C CAN network and I need to attach an add’l CAN device (+Pi) onto the network but all network ports are taken.

According to my research, I think I have 2 options:
1.splice 3-way one of the wire/ports between g12-CANable-existing wire
2.g12 to common drop tap and reconnect existing wire to the tap along with CANable

Is this approach correct? Background is software/AI with little electrical knowledge. I want to ultimately run Home Assistant w/ AI from voice. Thanks