VWVortex.com - Discover Pro Hack may be possible.
Username or Email Address
Do you already have an account?
Forgot your password?
  • Log in or Sign up

    VWVortex


    Page 3 of 9 FirstFirst 1234567 ... LastLast
    Results 51 to 75 of 211

    Thread: Discover Pro Hack may be possible.

    1. Member
      Join Date
      May 17th, 2006
      Location
      New England
      Posts
      232
      Vehicles
      2017 Golf R manual | 2009 WRX STi with yet another EJ257 ringland failure
      01-03-2016 07:28 PM #51
      Very cool so far!

    2. Remove Advertisements
      VWVortex.com
      Advertisements
    3. Member
      Join Date
      Apr 29th, 2009
      Location
      The Netherlands
      Posts
      351
      Vehicles
      '15 GTE
      01-04-2016 04:49 AM #52
      Thanks!
      I hope there's a way to enable shell access to the device... would make life a lot easier.

      edit:
      rSAP will probably not be useful at all, but at least I proved the wLAN device is functional for non-premium MIB1's as well. Hopefully I can turn the device into a wlan client.
      Last edited by Chillout; 01-04-2016 at 06:02 AM.

    4. 01-04-2016 10:40 PM #53
      I'm just flying by here - I own a 2016 GTI base, don't know what model radio it has but I'd love to dive into this as well. I just haven't committed to reading enough yet, though I will soon.

      I see your NMAP fingerprint and formatted it a little bit nicer.
      Code:
      r(FourOhFourRequest,B4,"HTTP/1.1 400 Bad Request
      CONNECTION: close
      SERVER: Audi-MIB/5.21 DLNADOC/1.50/1
      CONTENT-TYPE: text/html
      CONTENT-LENGTH: 50
      <html><body><h1>400 Bad Request</h1></body></html>")
      
      r(GetRequest,B4,"HTTP/1.1 400 Bad Request
      CONNECTION: close
      SERVER: Audi-MIB/5.21 DLNADOC/1.50/1
      CONTENT-TYPE: text/html
      CONTENT-LENGTH: 50
      <html><body><h1>400 Bad Request</h1></body></html>")
      
      r(HTTPOptions,B4,"HTTP/1 .1 400 Bad Request
      CONNECTION: close
      SERVER: Audi-MIB/5 .21 DLNADOC/1.50/1
      CONTENT-TYPE: text/html
      CONTENT-LENGTH: 50
      <html><body><h1>400 Bad Request</h1></body></html>")
      
      r(RPCCheck,A1,"HTTP/1 .0 400 Bad Request
      SERVER: Audi-MIB/5 .21 DLNADOC/1.50/1
      CONTENT-TYPE: text/html
      CONTENT-LENGTH: 50
      <html><body><h1>400 Bad Request</h1></body></html>")
      
      r(kumo-server,A1,"HTTP/1.0 400 Bad Request
      SERVER: Audi-MIB/5.21 DLNADOC/1.50/1 
      CONTENT-TYPE: text/html
      CONTENT-LENGTH: 50
      <html><body><h1>400 Bad Request</h1></body></html>");
      I'm sure you already know this, so I will explain it for others looking. NMap is connecting to the port with various requests types and seeing what it replies with. It's returning HTML, which is interesting to me. The other thing I find interesting is DLNADOC/1.50. This is a media service protocol.

      I'm interesting in poking around now. How did you enable the WiFi?
      Last edited by OneWheelDoin200; 01-04-2016 at 10:48 PM.

    5. Member
      Join Date
      Nov 1st, 2013
      Location
      Australia (Melbourne)
      Posts
      1,589
      Vehicles
      VW Golf mkVII 103TSI Highline (1.4L Turbo)
      01-04-2016 11:10 PM #54
      Quote Originally Posted by OneWheelDoin200 View Post
      . How did you enable the WiFi?
      If you have a Discover Pro unit installed in your car (as distinct from a Discover Media), then you should have an adaptation channel in the control module at hex5F called (not surprisingly) WLAN. This channel does not appear in any of the 5F admaps that I have seen for Discover media units. Anyway, the setting for the WLAN adaptation channel should be ON

      This is (as I understand) the basic enabling method for WiFi though Chillout may have other instructions.
      Don
      PS: If you want to download an admap for a Discover Pro unit in a Japanese mK7 (with WLAN enabled) see HERE

    6. Member
      Join Date
      Apr 29th, 2009
      Location
      The Netherlands
      Posts
      351
      Vehicles
      '15 GTE
      01-05-2016 02:14 AM #55
      Quote Originally Posted by OneWheelDoin200 View Post
      I'm just flying by here - I own a 2016 GTI base, don't know what model radio it has but I'd love to dive into this as well. I just haven't committed to reading enough yet, though I will soon.

      I see your NMAP fingerprint and formatted it a little bit nicer.
      Code:
      r(FourOhFourRequest,B4,"HTTP/1.1 400 Bad Request
      CONNECTION: close
      SERVER: Audi-MIB/5.21 DLNADOC/1.50/1
      CONTENT-TYPE: text/html
      CONTENT-LENGTH: 50
      <html><body><h1>400 Bad Request</h1></body></html>")
      
      r(GetRequest,B4,"HTTP/1.1 400 Bad Request
      CONNECTION: close
      SERVER: Audi-MIB/5.21 DLNADOC/1.50/1
      CONTENT-TYPE: text/html
      CONTENT-LENGTH: 50
      <html><body><h1>400 Bad Request</h1></body></html>")
      
      r(HTTPOptions,B4,"HTTP/1 .1 400 Bad Request
      CONNECTION: close
      SERVER: Audi-MIB/5 .21 DLNADOC/1.50/1
      CONTENT-TYPE: text/html
      CONTENT-LENGTH: 50
      <html><body><h1>400 Bad Request</h1></body></html>")
      
      r(RPCCheck,A1,"HTTP/1 .0 400 Bad Request
      SERVER: Audi-MIB/5 .21 DLNADOC/1.50/1
      CONTENT-TYPE: text/html
      CONTENT-LENGTH: 50
      <html><body><h1>400 Bad Request</h1></body></html>")
      
      r(kumo-server,A1,"HTTP/1.0 400 Bad Request
      SERVER: Audi-MIB/5.21 DLNADOC/1.50/1 
      CONTENT-TYPE: text/html
      CONTENT-LENGTH: 50
      <html><body><h1>400 Bad Request</h1></body></html>");
      I'm sure you already know this, so I will explain it for others looking. NMap is connecting to the port with various requests types and seeing what it replies with. It's returning HTML, which is interesting to me. The other thing I find interesting is DLNADOC/1.50. This is a media service protocol.

      I'm interesting in poking around now. How did you enable the WiFi?

      Thanks for formatting it the right way and explaining it in a non-nerdy way.
      It's DLNA indeed . Yesterday afternoon, I was able to stream music from BubbleUPNP (DLNA server) on my phone over bluetooth. Screenshots will follow.
      Enabling WLAN is done like DV52 said(enable WLAN in Adaptation, but with mine it was already on despite not being a Premium device), but also needs in long coding the"Phone NAD" bit to be enabled. I will find the exact bit as soon as I hook it up to VCP pro again.
      Last edited by Chillout; 01-05-2016 at 08:22 AM.

    7. Member
      Join Date
      Apr 29th, 2009
      Location
      The Netherlands
      Posts
      351
      Vehicles
      '15 GTE
      01-05-2016 05:04 AM #56
      Here's a screenshot of music playing over DLNA

    8. Junior Member XaGiCo's Avatar
      Join Date
      Jul 10th, 2014
      Location
      Ponferrada - SPAIN
      Posts
      22
      Vehicles
      2014
      01-05-2016 05:54 AM #57
      Spectacular!!

      Can you explain how?

      I have activated all the online adaptation. But to no avail.

      That Bit or necessary enable Phone NAD in long coding for module 5F? THANKS

      My progress!

      http://www.clubvwgolf.com/foro/showt...-MIB-1-Hacking

















      Best regards
      Last edited by XaGiCo; 01-05-2016 at 06:33 AM. Reason: Phone NAD in long coding for module 5F?

    9. Member
      Join Date
      Apr 29th, 2009
      Location
      The Netherlands
      Posts
      351
      Vehicles
      '15 GTE
      01-05-2016 07:23 AM #58
      Quote Originally Posted by XaGiCo View Post
      Spectacular!!

      Can you explain how?
      Best regards
      Set Phone NAD bit to 1 in VCP (Coding TXT)
      That's all..

      Also: great work!
      I've noticed that you have a different "Green menu"... mine is missing the first entry, for configuration. Can you share your long coding/adaptation channels?
      edit: could also be because of the software version... my green menu shows GEM 3.3, yours is GEM 3.0.

      I'll do full write-up after I've been back in the car with VCP


      My discoveries of undocumented/previously unknown features so far:
      - WLAN is on same chip as bluetooth and is available in all Discover Pro devices.
      - Screenshots can be made by pushing the right twist-knob
      - Overlay view of screen elements can be enabled by pushing and holding CAR button
      - Developer menu can be enabled through Adaptation.
      - Developer menu can be opened by holding MENU for ~20 seconds
      - Overlay view of screen data/names can be enabled by pushing and holding TRAFFIC button
      - Skin can be changed through Debug options in Developer menu
      - Loudness can be disabled through the Green menu in the Developer menu
      - Mirrorlink button in main menu can be enabled through Debug options in Developer menu
      - WLAN is available after enabling Phone NAD bit in long coding(which enabled Premium Phone)
      - DLNA is available after enabling WLAN (this is port 49152)
      - Wlan packets can be sniffed and saved to SD through the Green menu in the Developer menu
      Last edited by Chillout; 01-05-2016 at 08:36 AM.

    10. 01-08-2016 10:38 AM #59
      Quote Originally Posted by Chillout View Post
      This is the inside of the "Brain unit" of the Discover Pro MIB1.

      Googling some part numbers brought me here:
      http://electronics360.globalspec.com...nment-teardown
      Basically everything we need to know about the hardware of the Discovery Pro.
      This is fascinating!

      I always thought that unit in the glove box was just an external media box, but you have shown this is the actual system unit and the head unit is just display/user interface.

      You've done some awesome work here my friend, see my PM to you... ;-)

    11. 01-08-2016 11:36 AM #60
      Quote Originally Posted by Chillout View Post
      Thanks!
      I hope there's a way to enable shell access to the device... would make life a lot easier.
      As I speculated previously, if its not possible to throw a shell by abusing something already open then we might be able to do it by tampering with the OS image file and uploading a tampered one to the device.

      Looks likely that QNX can be changed like this:

      http://www.qnx.com/developers/docs/6...Fs%2Fsshd.html
      Last edited by A2theK; 01-08-2016 at 12:12 PM.

    12. 01-08-2016 11:58 AM #61
      Ahhhh here is something else from what you have...

      DNLA 1.50 server is old... try using Nikto (https://cirt.net/nikto2) against it or maybe Metasploit once Nikto has revealed any holes.

      You should be able to use either of these to execute CLI commands on the box, eventually throwing a shell.

      EDIT a bit of reading around suggests that a buffer overflow is possible in this DNLA server version by passing it a bad content icon (in XML)... definitely very real possibilities here!
      Last edited by A2theK; 01-08-2016 at 12:11 PM.

    13. Member
      Join Date
      Apr 29th, 2009
      Location
      The Netherlands
      Posts
      351
      Vehicles
      '15 GTE
      01-08-2016 03:08 PM #62
      A2theK, thanks for your information! You've got mail ;-)

      Tomorrow, I will have another evening of messing around with the device. Let's hope the software update my car got today during service didn't get in the way...

    14. Junior Member XaGiCo's Avatar
      Join Date
      Jul 10th, 2014
      Location
      Ponferrada - SPAIN
      Posts
      22
      Vehicles
      2014
      01-08-2016 05:41 PM #63
      Hi!!

      Yeah!!!

      Very Very Thanks @Chillout

      Enabled WLAN access point





      But it leaves an error!











      Example App DNL UPnP Apple:



      Example App DNL UPnP Android:



      My Golf February 2014 but my second Discover Pro May 2014. The first gave me problems navigation!

      I think that menu $configset is the MMI retrofit!


      Regards and Good Day!

    15. 01-09-2016 06:37 AM #64
      I was looking with a customer of mine a lot off time now but didn't find the green menu. Now we can acces i will look further into it. I'm also form the NL and iff need some contact you can find me true whatsapp +31 6 15228709 or by mail info @lowering.nl. I like to keep in touch

    16. Member
      Join Date
      Apr 29th, 2009
      Location
      The Netherlands
      Posts
      351
      Vehicles
      '15 GTE
      01-11-2016 05:12 AM #65
      Quote Originally Posted by A2theK View Post
      Ahhhh here is something else from what you have...

      DNLA 1.50 server is old... try using Nikto (https://cirt.net/nikto2) against it or maybe Metasploit once Nikto has revealed any holes.

      You should be able to use either of these to execute CLI commands on the box, eventually throwing a shell.

      EDIT a bit of reading around suggests that a buffer overflow is possible in this DNLA server version by passing it a bad content icon (in XML)... definitely very real possibilities here!
      I spent about 5 hours of my Saturday night in my car. Not the most spectacular night
      I ran a couple of Nikto runs on port 49152 with different settings. Nothing spectacular. I will have an other go this week with Nikto2(Kali Linux had Nikto 1.6?!) , I'm pretty sure something will show up eventually. If only I had an android client so I could easily scan while I'm on my way to work



      Quote Originally Posted by XaGiCo View Post
      Hi!!

      Yeah!!!

      Very Very Thanks @Chillout
      But it leaves an error!
      Regards and Good Day!
      Thanks for screenshots and PM Very useful!
      About the error: yes, that is common. You don't have to set the "Premium Phone" checkbox, because it will cause troubles, since the Phone module is not there.

    17. n00b
      Join Date
      Jul 15th, 2013
      Location
      uk
      Posts
      8
      01-19-2016 10:13 AM #66
      Quote Originally Posted by Chillout View Post
      I took a bunch of screenshots of all the Green menu screens, you can find them in one big album here:

      http://imgur.com/a/Y4vAo

      Here's a selection from the album:







      Next up: trying to set it in a mode other than "production", hopefully this might give us more menus and settings to access.
      hi,

      I have just bought a 2014 golf R with the discover pro installed and after reading this very interesting thread I want to play.

      I already have the green menu enabled and can see the screens similar to the ones shown in the 1st 3 pictures but I can't find anything like the ones in the last 2 pictures.

      so my question to chillout is how did you enable the green engineering mode, using the sd card script trick from the Russian forums? or did you just use vcp?

      regards,

    18. Member
      Join Date
      Apr 29th, 2009
      Location
      The Netherlands
      Posts
      351
      Vehicles
      '15 GTE
      01-20-2016 03:08 AM #67
      Quote Originally Posted by sg33 View Post
      hi,

      I have just bought a 2014 golf R with the discover pro installed and after reading this very interesting thread I want to play.

      I already have the green menu enabled and can see the screens similar to the ones shown in the 1st 3 pictures but I can't find anything like the ones in the last 2 pictures.

      so my question to chillout is how did you enable the green engineering mode, using the sd card script trick from the Russian forums? or did you just use vcp?

      regards,
      Hi,
      I only used VCP. If you can see the screens, the green engineering menu is the first entry of that menu screen

    19. 01-22-2016 10:17 AM #68
      Hi!

      Well... I retrofitted Discovery Pro into my car, but threre is some things that doesn't work - Navi is locked and TPMS button send "Implaussible signal" (??). So I tried to update firmware (with files from beggining of page 2) and... It updateg. But now there is no sound. Everything worked well, but speakres is muted (there is still a small "bum" in speakers when turning on the unit.). CP is removed. Is it back? There is no error from CP..


      There is error in memory "Check Software Version Menagement", or something like this, later will add the error code, need to check.
      Anyone can help?
      Thanks in advance

    20. Member
      Join Date
      Apr 29th, 2009
      Location
      The Netherlands
      Posts
      351
      Vehicles
      '15 GTE
      01-22-2016 11:14 AM #69
      Quote Originally Posted by Dawiww View Post
      Hi!

      Well... I retrofitted Discovery Pro into my car, but threre is some things that doesn't work - Navi is locked and TPMS button send "Implaussible signal" (??). So I tried to update firmware (with files from beggining of page 2) and... It updateg. But now there is no sound. Everything worked well, but speakres is muted (there is still a small "bum" in speakers when turning on the unit.). CP is removed. Is it back? There is no error from CP..


      There is error in memory "Check Software Version Menagement", or something like this, later will add the error code, need to check.
      Anyone can help?
      Thanks in advance
      This is not the Discover Pro support topic, but did you check your coding in VCDS? There's a setting for sound system: internal, dynaudio, etc.
      When it comes to retrofitting, Ross-tech has a specific forum board available to help you out.

    21. 01-22-2016 03:01 PM #70
      I know, i know. VCDS should be good - sound work before.

      But I can't write on Ross-Tech forum, because there is needed to say code from white sticker on side of VCDS-cable, and mine is just blank after all this years :/

      Error:
      1555 - Check Software Version Management
      B201A 00 [009] - -
      Confirmed - Tested Since Memory Clear
      Freeze Frame:
      Fault Status: 00000001
      Fault Priority: 6
      Fault Frequency: 1
      Reset counter: 140
      Mileage: 4032 km
      Date: 2016.01.22
      Time: 14:02:22

    22. 01-26-2016 02:37 AM #71
      Chillout, very interested in your ability to enable WLAN on the MIB I Nav Pro (which I have in my 2013 GTD).

      I've enabled the WLAN function in VCDS for the controller 5F (was set to off), but I still don't get the WLAN option under Media.

      You mentioned enabling Phone NAD earlier in the thread. Is this something that can only be done with VCP or is this a check box in VCDS (as I only have VCDS). Any chance you could point me in the right direction please ?

    23. 01-27-2016 02:47 PM #72
      Hi everyone. Canadian 2016 S3 user checking in here. I had my interest caught initially when I saw the words "discover pro" show up, but then assumed there could be sufficient differences in our systems for me to wait a bit. Well, I've since activated the green menu and found that the choices are the same:



      We have no SIM slot in our vehicles here. WLAN works fine (after adaptation with my VCP). About as far as I want to get right now is enabling data to the system through my phone, either through rSAP (which sounds unlikely) or USB->RJ45. The step that seems to be missing for me at least, when comparing procedures to the A1/4/5 etc is the 'install fair mode' or 'dlinkreplacesPPP' equivalent function which instructs the system to be able to look to the AMI port for its data.

      I'll continue to watch with interest. The enabling of Google etc might be possible through adaptation of various 'online' flags in the vehicle config I can see in 5F, but I haven't got as far as trying this yet, and of course with no network it's likely just going to be an exercise to see if some extra options show up.



      If there's anything that I can offer with a different vehicle to help this discussion, do let me know.

    24. Member
      Join Date
      Apr 29th, 2009
      Location
      The Netherlands
      Posts
      351
      Vehicles
      '15 GTE
      01-31-2016 08:16 AM #73
      Quote Originally Posted by davey6693 View Post
      If there's anything that I can offer with a different vehicle to help this discussion, do let me know.
      That's looking good

      I went down the road of USB-RJ45... didn't work. But I have good hopes that it's might be posible to enable WLAN Client mode, which would make it possible for the device to connect to a mobile hotspot.
      Someone told me it might be a good idea to turn OFF UPnP... might enable Wlan client mode.


      Also, I put up a BT Sync with Discover Pro Firmware versions 0200 and 0388. Feel free to download:

      https://link.getsync.com/#f=Discover...54505361&v=2.2

      I'm going to compare files on these to see the differences

    25. Member
      Join Date
      Apr 29th, 2009
      Location
      The Netherlands
      Posts
      351
      Vehicles
      '15 GTE
      02-01-2016 05:38 AM #74
      Update: Be careful playing around with this thing guys... I disabled my DVD player... Might be a loose connection or something, it currently doesn't work

      Also, I did a comparison between my adaption channels from oktober and a recent one... I did a lot of changes, but there were also a lot of things that were changed that I never changed manually... this wasn't caused by any software update, comparing adaption channel maps from before the update leads to the same conclusion: this device can do weird stuff!

    26. Semi-n00b
      Join Date
      Feb 1st, 2016
      Location
      Netherlands
      Posts
      17
      02-01-2016 07:21 AM #75
      Quote Originally Posted by Chillout View Post
      Update: Be careful playing around with this thing guys... I disabled my DVD player... Might be a loose connection or something, it currently doesn't work

      Also, I did a comparison between my adaption channels from oktober and a recent one... I did a lot of changes, but there were also a lot of things that were changed that I never changed manually... this wasn't caused by any software update, comparing adaption channel maps from before the update leads to the same conclusion: this device can do weird stuff!
      Hi,

      I'm currently trying to download the firmware files (although it still says "Connecting......") in order to decompile it. Once it is decompiled, it's a lot easier to discover vulnerabilities that could possibly be exploited.
      Once I have the files and decompiled them, I'll write a little manual on how to do this (if this is wanted)

      Cheers!

    Page 3 of 9 FirstFirst 1234567 ... LastLast

    Posting Permissions

    • You may not post new threads
    • You may not post replies
    • You may not post attachments
    • You may not edit your posts
    •