Unfortunately we do not accept new members for free, Now Registration cost 30€, if you are interesting Send Email to [email protected]

How to decrypt ISN from CAS3+ dump with а working key
21-05-2023, 16:02 PM,
Post: #1
How to decrypt ISN from CAS3+ dump with а working key
Hello, 

I would like to share the process of decryption of the ISN from CAS3+ dump when we have a working key.

  • Read the working key ID with Hitag2 compatible reader (1)
  • Find the key number in the CAS3+ dump (2)
  • Find the Crypto/ISK Low and High (3)
  • Enter the Crypto/ISK Low and High to the Hitag2 compatible reader and read all key data (4)
  • Copy PSW string (5) to some HEX calculator (6)
  • Copy the "Pass" (7) from the CAS3+ dump to the HEX calculator (8)
  • Calculate the XOR value (9)
  • Do a "byte flip" (e.g. AA BB CC > CC BB AA) of the XOR value
  • In a HEX calculator paste 6 times the byte flipped XOR value and remove the last 4 characters (10)
  • Copy the encrypted ISN from the CAS3+ dump (11 )and paste it the HEX calc (12).
  • The result of the XOR is the decrypted ISN.



Attached Files Thumbnail(s)
   
Reputation: +13 - volavka [+2] , raffy haddad [+1] , AZCKNCLLC [+1] , BmwMerc [+1] , jaramillo [+1] , RReader [+1] , foxportal [+1] , TheNine90 [+1] , paino [+1] , kowalwalcz [+1] , bmwbmw [+1] , bram380 [+1]
Quote this message in a reply
[+] 22 users say Thank You to kalosbg for this post
02-09-2023, 01:40 AM,
Post: #2
RE: How to decrypt ISN from CAS3+ dump with а working key
Damn, would be awesome if its working.

Does it work with all long ISN ?

What if i have short ISN from DME but tango/Hitag asks me for Long isn to write key?
It wont accept my short isn since its asking for the 128bit version.

How to solve this ?
Quote this message in a reply
06-09-2023, 14:33 PM,
Post: #3
RE: How to decrypt ISN from CAS3+ dump with а working key
(02-09-2023, 01:40 AM)xMoses Wrote:  What if i have short ISN from DME but tango/Hitag asks me for Long isn to write key?
It wont accept my short isn since its asking for the 128bit version.

How to solve this ?

Describe how did you get this...

[Image: GIF-Bandiera-Italiana.gif]
Quote this message in a reply
06-09-2023, 16:36 PM,
Post: #4
RE: How to decrypt ISN from CAS3+ dump with а working key
(06-09-2023, 14:33 PM)____ANGEL___ Wrote:  
(02-09-2023, 01:40 AM)xMoses Wrote:  What if i have short ISN from DME but tango/Hitag asks me for Long isn to write key?
It wont accept my short isn since its asking for the 128bit version.

How to solve this ?

Describe how did you get this...

read it out with bmw explorer, could only read short isn... Car has no long isn but still tangos asks for it smile
Quote this message in a reply
12-10-2023, 14:02 PM,
Post: #5
RE: How to decrypt ISN from CAS3+ dump with а working key
(06-09-2023, 16:36 PM)xMoses Wrote:  
(06-09-2023, 14:33 PM)____ANGEL___ Wrote:  
(02-09-2023, 01:40 AM)xMoses Wrote:  What if i have short ISN from DME but tango/Hitag asks me for Long isn to write key?
It wont accept my short isn since its asking for the 128bit version.

How to solve this ?

Describe how did you get this...

read it out with bmw explorer, could only read short isn... Car has no long isn but still tangos asks for it smile
Some can get long ISN from short ISN for a fee, i didn't figure out how they do it, to solve this one time i changed encrypted eeprom with new unencrypted eeprom.
Quote this message in a reply
11-01-2024, 11:01 AM,
Post: #6
RE: How to decrypt ISN from CAS3+ dump with а working key
(21-05-2023, 16:02 PM)kalosbg Wrote:  Hello, 

I would like to share the process of decryption of the ISN from CAS3+ dump when we have a working key.

  • Read the working key ID with Hitag2 compatible reader (1)
  • Find the key number in the CAS3+ dump (2)
  • Find the Crypto/ISK Low and High (3)
  • Enter the Crypto/ISK Low and High to the Hitag2 compatible reader and read all key data (4)
  • Copy PSW string (5) to some HEX calculator (6)
  • Copy the "Pass" (7) from the CAS3+ dump to the HEX calculator (8)
  • Calculate the XOR value (9)
  • Do a "byte flip" (e.g. AA BB CC > CC BB AA) of the XOR value
  • In a HEX calculator paste 6 times the byte flipped XOR value and remove the last 4 characters (10)
  • Copy the encrypted ISN from the CAS3+ dump (11 )and paste it the HEX calc (12).
  • The result of the XOR is the decrypted ISN.



So i wanted to try out ur calculation. Ive came across the fact that my TMCF/PSW of my china key is 00 00 00 and the crypted config psw is 8F 98 1D. If i calculate that against obvoiusly 0, i get

8F 98 1D as an result, if i swap bytes and paste it in 6x and delete the last 4 characters, i end up with an wrong ISN.

(I know the right ISN, just wanted to try out ur calculation).

What could cause that ? The key with 00 00 00 is working.

the real and working ISN is:

3FFA6898026A3759AB7B0736075AA367


Am I missing something ?


Attached Files Thumbnail(s)
           
Quote this message in a reply
31-01-2024, 16:23 PM,
Post: #7
RE: How to decrypt ISN from CAS3+ dump with а working key
Hello xMoses,

To read the TMCF/PSW from the key you have to enter the correct secret as mentioned on step "Enter the Crypto/ISK Low and High to the Hitag2 compatible reader and read all key data (4)
"

Regards,
Quote this message in a reply
01-02-2024, 08:18 AM,
Post: #8
RE: How to decrypt ISN from CAS3+ dump with а working key
(31-01-2024, 16:23 PM)kalosbg Wrote:  Hello xMoses,

To read the TMCF/PSW from the key you have to enter the correct secret as mentioned on step "Enter the Crypto/ISK Low and High to the Hitag2 compatible reader and read all key data (4)
"

Regards,

Yeah my tmcf is 00 00 00
Quote this message in a reply


Possibly Related Threads…
Thread Author Replies Views Last Post
ZVW Virginize BMW Siemens MS43 Dump chrismo 8 146 8 hours ago
Last Post: chrismo
XZBMW Solved ✔ bmw e92 elv off cas3 0L015Y MJPOWER 2 99 23-04-2024, 21:22 PM
Last Post: MJPOWER
XZBMW Solved ✔ MEVD172 Working hours reset ahmadarifai 3 131 22-04-2024, 06:13 AM
Last Post: ahmadarifai
XZBMW CAS2 To CAS3 - Data transfer - Coding FA Problem Semi14 2 114 18-04-2024, 07:10 AM
Last Post: Semi14
XZBMW Solved ✔ MSV90 Working hour reset seohanb 0 58 18-04-2024, 05:05 AM
Last Post: seohanb
  BMW MSD81 working hours reset Spirit5676 4 135 16-04-2024, 20:18 PM
Last Post: bboctavian
XZBMW transform cas3 remote from rechargeable to regular ahmadarifai 0 66 12-04-2024, 13:21 PM
Last Post: ahmadarifai
XZBMW Solved ✔ BMW X6 E71 CAS3 ELV OFF bgpavlp 4 168 11-04-2024, 07:24 AM
Last Post: bgpavlp
ZVW please need help check dump fille vw toureg kessy unit Manoj448 1 66 10-04-2024, 13:47 PM
Last Post: dimon9555
XZBMW Please elv off bmw e90 cas3 0L015Y boweld11 1 114 09-04-2024, 05:17 AM
Last Post: huzefa

Forum Jump:


Users browsing this thread:
1 Guest(s)

Return to TopReturn to Content