LOST JEEPS
http://www.lostjeeps.com/forum/phpBB3/

Hacking the SKIM.
http://www.lostjeeps.com/forum/phpBB3/viewtopic.php?f=5&t=90271
Page 1 of 1

Author:  Sir Sam [ Sat Jul 27, 2019 6:57 pm ]
Post subject:  Hacking the SKIM.

Something I've been trying to get around to for awhile, messing with the SKIM. I grabbed a used one from a junkyard and set about reading the memory from it. After much research and experimentation I have found that the eeprom can be desoldered, read, and then the VIN and PIN read in the file.

I have also found the factory fresh eeprom file, next step is to load the factory fresh eeprom hex back to the used eeprom, resolder it, and then attempt to program the SKIM to an ECU as if it were a new in box SKIM.

This way a cheap skim from the junkyard can be programmed to work with any Jeep I need it to. If I can figure out the eeprom coding I could even program a used skim to a jeep and then install it and go, but at the very least I should be able to clone a SKIM.

In theory a cloned skim should work with your existing keys.

Author:  ebbnflow [ Sat Jul 27, 2019 7:24 pm ]
Post subject:  Re: Hacking the SKIM.

Pretty cool Sam! I love reading your threads.

Sent from my Pixel 3 using Tapatalk

Author:  flash7210 [ Sat Jul 27, 2019 8:53 pm ]
Post subject:  Re: Hacking the SKIM.

Would be nice if the SKIM feature could be completely removed.
Or at least bypassed.
Somehow the bad guys are able to do it when stealing cars.

What about the 2005 gateway module?
Any hope in repairing those or bypassing them?
(When I dug through the FCM it appears that the SKIM connects through the gateway)

Author:  layback40 [ Sat Jul 27, 2019 10:07 pm ]
Post subject:  Re: Hacking the SKIM.

I am always impressed by what our IT smart members can do. If you nail this you probably have a nice little monet earner in the making.

Author:  TKB4 [ Sun Jul 28, 2019 12:05 am ]
Post subject:  Re: Hacking the SKIM.

I am officially impressed :JEEPIN:
Keep up the excellent work !!!

Author:  GreenDieselEngineering [ Sun Jul 28, 2019 5:08 am ]
Post subject:  Re: Hacking the SKIM.

flash7210 wrote:
Would be nice if the SKIM feature could be completely removed.
Or at least bypassed.
Somehow the bad guys are able to do it when stealing cars.

What about the 2005 gateway module?
Any hope in repairing those or bypassing them?
(When I dug through the FCM it appears that the SKIM connects through the gateway)



Green Diesel can turn off the skim in the ecm tuning upon request.

Author:  Sir Sam [ Sun Jul 28, 2019 11:00 am ]
Post subject:  Re: Hacking the SKIM.

As GDE pointed out turning off the SKIM is possible, I'm not sure what method they have to do it but what I have read online is that to do it you must heat up the ECU, remove the side cover, and then read via the pin pads to the BDM port of the processor. There is quite a bit of information online that is scattered around. It is on my list of things to do at some point - but with so many projects its way down the list.

From my understanding it is also possible to read the PIN on from the ECU as well using this method.

Author:  WWDiesel [ Sun Jul 28, 2019 11:42 am ]
Post subject:  Re: Hacking the SKIM.

That's good information to know! Keep up the good work.

Any advice from any of you IT experts on what can be done for the poor souls who are having issues with the Front Control Module that seems so far to be no longer available anywhere? :grim:
Are there any bench fixes or bypasses available for them?
GDE, Sir Sam, anybody?

Author:  Sir Sam [ Sun Jul 28, 2019 11:54 am ]
Post subject:  Re: Hacking the SKIM.

WWDiesel wrote:
That's good information to know! Keep up the good work.

Any advice from any of you IT experts on what can be done for the poor souls who are having issues with the Front Control Module that seems so far to be no longer available anywhere? :grim:
Are there any bench fixes or bypasses available for them?
GDE, Sir Sam, anybody?


My comment in the other thread is that I was planning to grab a FCM from a durango or something similar, which appears to be on the outside the exact same hardware, and then open it up and see if there is anything we can read from it. My hope is that we could get a generic module and then clone it to what our FCM does.

Author:  WWDiesel [ Sun Jul 28, 2019 12:17 pm ]
Post subject:  Re: Hacking the SKIM.

Sir Sam wrote:
WWDiesel wrote:
That's good information to know! Keep up the good work.
Any advice from any of you IT experts on what can be done for the poor souls who are having issues with the Front Control Module that seems so far to be no longer available anywhere? :grim:
Are there any bench fixes or bypasses available for them?
GDE, Sir Sam, anybody?

My comment in the other thread is that I was planning to grab a FCM from a durango or something similar, which appears to be on the outside the exact same hardware, and then open it up and see if there is anything we can read from it. My hope is that we could get a generic module and then clone it to what our FCM does.

That would be wonderful and I know there are a couple members on here that would love to hear a success story on the subject.
If anyone happens to see an 05 in the boneyard, be sure and grab the FCM if it has one. They are going to become like GOLD due to their rarity. :banghead:

Author:  casm [ Tue Jul 30, 2019 12:34 pm ]
Post subject:  Re: Hacking the SKIM.

WWDiesel wrote:
That's good information to know! Keep up the good work.

Any advice from any of you IT experts on what can be done for the poor souls who are having issues with the Front Control Module that seems so far to be no longer available anywhere? :grim:
Are there any bench fixes or bypasses available for them?
GDE, Sir Sam, anybody?


In the absence of any better ideas, I'd suggest finding a known-good unit or two and using those to build an emulation of the original unit on an FPGA. That's not likely to happen quickly, though, and someone would have to be really motivated to do it. It could also potentially involve the destruction of the good units as part of the process.

Author:  casm [ Tue Jul 30, 2019 12:35 pm ]
Post subject:  Re: Hacking the SKIM.

Sir Sam wrote:
Something I've been trying to get around to for awhile, messing with the SKIM. I grabbed a used one from a junkyard and set about reading the memory from it. After much research and experimentation I have found that the eeprom can be desoldered, read, and then the VIN and PIN read in the file.


Interesting... So does this mean that the VIN and PIN are stored in the EEPROM unencrypted?

I'm wondering what other hardware in the vehicle may take a similar approach.

Author:  Sir Sam [ Tue Jul 30, 2019 10:02 pm ]
Post subject:  Re: Hacking the SKIM.

casm wrote:
WWDiesel wrote:
That's good information to know! Keep up the good work.

Any advice from any of you IT experts on what can be done for the poor souls who are having issues with the Front Control Module that seems so far to be no longer available anywhere? :grim:
Are there any bench fixes or bypasses available for them?
GDE, Sir Sam, anybody?


In the absence of any better ideas, I'd suggest finding a known-good unit or two and using those to build an emulation of the original unit on an FPGA. That's not likely to happen quickly, though, and someone would have to be really motivated to do it. It could also potentially involve the destruction of the good units as part of the process.


Yup, could be some destruction happening, and take the right heads working on it. Again my best hope is to clone a different unit to ours. However I am not an embedded hardware/software guy, so I have to take some learning leaps to get anywhere with this stuff.

casm wrote:
Sir Sam wrote:
Something I've been trying to get around to for awhile, messing with the SKIM. I grabbed a used one from a junkyard and set about reading the memory from it. After much research and experimentation I have found that the eeprom can be desoldered, read, and then the VIN and PIN read in the file.


Interesting... So does this mean that the VIN and PIN are stored in the EEPROM unencrypted?

I'm wondering what other hardware in the vehicle may take a similar approach.


I think the VIN is stored unencrypted, but I think the pin must be encrypted. I haven't figured out how to read the pin from the SKIM bin file.

Now that I think about it, let me post the bin file for anyone who knows anything to take a crack at it.

Author:  GordnadoCRD [ Fri Aug 02, 2019 6:18 am ]
Post subject:  Re: Hacking the SKIM.

Sir Sam wrote:
Something I've been trying to get around to for awhile, messing with the SKIM. I grabbed a used one from a junkyard and set about reading the memory from it. After much research and experimentation I have found that the eeprom can be desoldered, read, and then the VIN and PIN read in the file.

I have also found the factory fresh eeprom file, next step is to load the factory fresh eeprom hex back to the used eeprom, resolder it, and then attempt to program the SKIM to an ECU as if it were a new in box SKIM.

This way a cheap skim from the junkyard can be programmed to work with any Jeep I need it to. If I can figure out the eeprom coding I could even program a used skim to a jeep and then install it and go, but at the very least I should be able to clone a SKIM.

In theory a cloned skim should work with your existing keys.

What did you use to read and reprogram the eeprom? Back when those chips were current technology, the equipment for RW eeprom chips were $400 to $1400 plus the software to run it.

Author:  Sir Sam [ Sat Aug 03, 2019 12:27 pm ]
Post subject:  Re: Hacking the SKIM.

GordnadoCRD wrote:
Sir Sam wrote:
Something I've been trying to get around to for awhile, messing with the SKIM. I grabbed a used one from a junkyard and set about reading the memory from it. After much research and experimentation I have found that the eeprom can be desoldered, read, and then the VIN and PIN read in the file.

I have also found the factory fresh eeprom file, next step is to load the factory fresh eeprom hex back to the used eeprom, resolder it, and then attempt to program the SKIM to an ECU as if it were a new in box SKIM.

This way a cheap skim from the junkyard can be programmed to work with any Jeep I need it to. If I can figure out the eeprom coding I could even program a used skim to a jeep and then install it and go, but at the very least I should be able to clone a SKIM.

In theory a cloned skim should work with your existing keys.

What did you use to read and reprogram the eeprom? Back when those chips were current technology, the equipment for RW eeprom chips were $400 to $1400 plus the software to run it.


I don't recall the model or where I bought it, but there are plenty of inexpensive ones out there:
https://www.amazon.com/Gikfun-Programme ... HXKH1J4VDY

Author:  Sir Sam [ Sat Aug 03, 2019 12:55 pm ]
Post subject:  Re: Hacking the SKIM.

Here is the link to the file if anyone wants to poke at it:

http://colorado4wheel.com/images/libby/ ... d_skim.BIN

VIN of vehicle was 1J4GL58555W617704

Author:  Duster [ Fri Jan 08, 2021 2:13 am ]
Post subject:  Re: Hacking the SKIM.

\00\00\00\00\00\00\00\00\FF\00\00\FF\00\00\00\00\FF\00\00\00\00\00\00\00\00\FF\00\00\00\00\00\00\00\00\00\FF\ED\9FןW\B8E\91a\B6}E\91a\ED)\FD<\89\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FAMes\A6\00D\00\00Å\00\00P4C\00\00\00B\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\C75W6177041J4GL5855\00)\81"o2\81"z{\81"\C7\81"hЁ"\BCo \00\00\00\00
\00
\00\00\FF\FF\FF3V0 AE)ba\D9\00\00eA\97\99\00\00\00R\00Q\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\B2QD\00VU\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\C7\C6\C1\C0\00\FF2 egC@? \C4\C0\00\C4\C0L\FF$#\E3⦥\00 qp \00\00\0087on$#\00I4\FF\00\00\FF\00\00\FF\00\00\FF\00\00\00\00\00\00\00\00\00\00\00\00\00\00\FF\00\00\00\00\00\00\00\FF\00\00\00\00\00f\EF\9FܟY\B8E\91a\B6}E\91a\ED)\FD<\89\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FAMes\A6\00D\00\00Å\00\00P4C\00\00\00B\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\FF\C75W6177041J4GL5855\00)\81"o2\81"z{\81"\C7\81"hЁ"\BCo \00\00\00\00

Author:  Duster [ Fri Jan 08, 2021 2:48 am ]
Post subject:  Re: Hacking the SKIM.

I have 2 screenshots I wish I could upload to show the raw info. There is a lot that is lost when I paste to this forum. And then more is lost when I submit the text.

Like for example there is a box between the last and first digit of the vin although it is broken up last 8 digits first [] then first 9 digits.

I could be wrong but that is the only instance of 4 digits I saw with what I opened it with.

Could you call Dodge with the VIN and get the PIN?

Author:  Duster [ Fri Jan 08, 2021 2:51 am ]
Post subject:  Re: Hacking the SKIM.

GreenDieselEngineering wrote:
flash7210 wrote:
Would be nice if the SKIM feature could be completely removed.
Or at least bypassed.
Somehow the bad guys are able to do it when stealing cars.

What about the 2005 gateway module?
Any hope in repairing those or bypassing them?
(When I dug through the FCM it appears that the SKIM connects through the gateway)



Green Diesel can turn off the skim in the ecm tuning upon request.


When you turn it off upon request, does the keyless entry still work? Or no because the SKIM module is on the WCM there in the column and has to be unplugged before installation?

Author:  Duster [ Mon Jan 18, 2021 6:35 pm ]
Post subject:  Re: Hacking the SKIM.

Duster wrote:
GreenDieselEngineering wrote:
flash7210 wrote:
Would be nice if the SKIM feature could be completely removed.
Or at least bypassed.
Somehow the bad guys are able to do it when stealing cars.

What about the 2005 gateway module?
Any hope in repairing those or bypassing them?
(When I dug through the FCM it appears that the SKIM connects through the gateway)



Green Diesel can turn off the skim in the ecm tuning upon request.


When you turn it off upon request, does the keyless entry still work? Or no because the SKIM module is on the WCM there in the column and has to be unplugged before installation?


Well I didn't get a response, so I went through another source, ordered a computer programmed with my VIN and mileage, with the SKIM delete. They had said my keyless entry on my 07 liberty would still work although the directions said to make sure to unplug the SKIM / WCM in the column before install.

Well, not true, because the keyless entry doesn't work now. The SKIM / WCM is a dual function piece for both checking the sentry key stuff and receiver antenna for the remote keyless entry.

Now I am trying to figure out if there is any wire I can snip to prevent SKIM to Computer communications so I can keep the delete, but get my keyless entry back working.

Anyone have any ideas?

I don't know what else to do besides drive it out somewhere, swap the computer back to the old one, hook the skim up, and let them scan it so I can get the codes and try to hope that the SKIM / WCM proves to be good and the computer bad... which is possible, but doubtful.

Page 1 of 1 All times are UTC - 5 hours [ DST ]
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group
http://www.phpbb.com/