Unfortunately we do not accept new members for free, Now Registration cost 30€, if you are interesting Send Email to [email protected]

Lock for DUMP EPT OCFD OPCOM HQ
31-05-2018, 17:38 PM,
Post: #1
Lock for DUMP EPT OCFD OPCOM HQ
Hello every one,

I want to try some work on converting an opcom china clone to HQ ,for that i need this :
- Ocfd file given the dump of eeprom of the FT232R,
- Image view of reading data by OP-COM FUT,
- Image view of reading data by FT_Prog plus the template xml dump ,

I will be very grateful if some one coud provide me with this,

Thanks
Quote this message in a reply
01-06-2018, 22:31 PM, (This post was last modified: 01-06-2018, 22:32 PM by McMihai.)
Post: #2
RE: Lock for DUMP EPT OCFD OPCOM HQ
(31-05-2018, 17:38 PM)samtimber Wrote:  Hello every one,

I want to try some work on converting an opcom china clone to HQ ,for that i need this :
- Ocfd file given the dump of eeprom of the FT232R,
- Image view of reading data by OP-COM FUT,
- Image view of reading data by FT_Prog plus the template xml dump ,

I will be very grateful if some one coud provide me with this,

Thanks
the software is paired with the serial number of the FTDI

all you need is to change the serial number of the FTDI.
or enter the serial number (FTDI) in the OPcom HQ software
Quote this message in a reply
03-06-2018, 13:09 PM,
Post: #3
RE: Lock for DUMP EPT OCFD OPCOM HQ
Thanks for reply but i 'am looking for some one who has the opcom hq and can provide me with the information that i ask before to make a public solution for every one who have the china clone.
of course,passing the information must be in private
Quote this message in a reply
04-06-2018, 18:53 PM,
Post: #4
RE: Lock for DUMP EPT OCFD OPCOM HQ
Forget about this...

The loader in OP-COM HQ is very hard protected. You need a valid license for the loader.
The license is stored in the user programable area of FTDI-RL's eeprom and it's paired against ftdi chipid. So do you need to know several secrets stuffs:
1. Encryption and hashing algorithm of the license (based on chipid)
2. Proper RSA key to digital sign the hash
3. To obtain this you need to devirtualize the lastest themida virtual machine
4. The loader is protected with severeral self checks too against cracking (for example, crc's against static patching, self debuging against debuggers and timechecking (GetTickCounter()) against dynamic patching,etc...)

Why do you think that somebody will share this secrets to destroy market?
Why do you not buy a HQ Clone and get the these informations by yourself instead of ask it for free and reshare it as your own work?

The HQ Clone are solution from the past. Nowadays there are better solutions for op-com which works like the original...
Reputation: +2 - mattydr67 [+1] , jenny123 [+1]
Quote this message in a reply
[+] 4 users say Thank You to leader for this post
06-06-2018, 09:30 AM,
Post: #5
RE: Lock for DUMP EPT OCFD OPCOM HQ
What solutions? smile
Quote this message in a reply
13-06-2018, 02:04 AM,
Post: #6
RE: Lock for DUMP EPT OCFD OPCOM HQ
(04-06-2018, 18:53 PM)leader Wrote:  Forget about this...

The loader in OP-COM HQ is very hard protected. You need a valid license for the loader.
The license is stored in the user programable area of FTDI-RL's eeprom and it's paired against ftdi chipid. So do you need to know several secrets stuffs:
1. Encryption and hashing algorithm of the license (based on chipid)
2. Proper RSA key to digital sign the hash
3. To obtain this you need to devirtualize the lastest themida virtual machine
4. The loader is protected with severeral self checks too against cracking (for example, crc's against static patching, self debuging against debuggers and timechecking (GetTickCounter()) against dynamic patching,etc...)
Or instead of all of that you can simply find those two bytes of "licence" by brute force. It is only 65k combinations at worst and FTDI EEPROM can certainly sustain that many user area byte reprograms wink.
Quote this message in a reply
13-06-2018, 04:21 AM,
Post: #7
RE: Lock for DUMP EPT OCFD OPCOM HQ
(13-06-2018, 02:04 AM)stmilosh Wrote:  Or instead of all of that you can simply find those two bytes of "licence" by brute force. It is only 65k combinations at worst and FTDI EEPROM can certainly sustain that many user area byte reprograms wink.

You are wrong. Those 2 bytes was valid only for 131223d HQ version.

In 150406HQ skladd improved his portection by rsa sign the license. The signature is stored in the User Area of FT232RL's internal eeprom. Because of the User Area size limitation the RSA key is only 20bytes (160bits) length. So it not hard to calculate private key for it....

In 170823 sklad impored the protection agains and lock his loader to computer too.

As I told before novadays there are much better solution than these HQ interfaces....
Quote this message in a reply
[+] 6 users say Thank You to leader for this post
16-06-2018, 06:29 AM, (This post was last modified: 06-07-2018, 20:08 PM by mattydr67.)
Post: #8
RE: Lock for DUMP EPT OCFD OPCOM HQ
Mr Leader you have totally right.
But in my opinion the new solutions hasn't to be public as HQ clone solution is.
As you said there are better solution for a long but this one are better because it wasn't public. You know what I mean
Let the HQ clone solution to remain for the public.
Good luck
Quote this message in a reply
[+] 2 users say Thank You to mattydr67 for this post
19-06-2018, 10:12 AM,
Post: #9
RE: Lock for DUMP EPT OCFD OPCOM HQ
What's the meaning of this?
So you say there are other sw tools/hw interfaces that do the same of OPCOM and are (possibly) free?

I cant quite understand why it should be a secret.

Thanks!
Quote this message in a reply
19-06-2018, 10:19 AM,
Post: #10
RE: Lock for DUMP EPT OCFD OPCOM HQ
here a soft and firmware that work very well for my opcom


Attached Files
New Text Document.txt
File Type: .txt
Downloaded: 284 times
Size: 70 bytes


No help for people not give a feedback
Reputation: +1 - bounce24 [+1]
Quote this message in a reply
[+] 3 users say Thank You to loki954 for this post


Possibly Related Threads…
Thread Author Replies Views Last Post
KOpel Remove VIN lock from radio crazyrs6 3 435 1 hour ago
Last Post: alanans
  Vectra C pin from CIM dump kowalwalcz 1 334 12-08-2023, 15:58 PM
Last Post: dabaca
  corsa d a12xer need dump for easytronic buca25 0 228 14-02-2023, 17:33 PM
Last Post: buca25
  Solved ✔ Vectra C pin from dump djbovorta 1 305 02-01-2023, 21:31 PM
Last Post: djbovorta
  OPCOM "NEW" V1.99 does not communicate with ESC (ECU does not reply, please wait 2 se lim0nade 30 8,333 20-03-2022, 17:01 PM
Last Post: mattydr67
  Opcom Motherboard version (can't find USB drivers) BrainBT 5 1,375 17-10-2019, 17:18 PM
Last Post: skyline
  Opcom Bootloader Repair with TL866 ICSP port aki1 3 1,637 07-10-2019, 13:07 PM
Last Post: avepla
  Opcom HQ Installers 2017 Gabriel87 18 10,370 30-09-2019, 22:30 PM
Last Post: AIR0
  opcom clone need help to repair autosolutions 1 822 18-09-2019, 02:40 AM
Last Post: mattydr67
  OPCOM problem conecting CrossMan 22 5,309 02-08-2019, 05:18 AM
Last Post: mattydr67

Forum Jump:


Users browsing this thread:
1 Guest(s)

Return to TopReturn to Content