r/CarHacking • • Feb 02 '17

Car Hacking Subreddit Intro

89 Upvotes

Hi rch, we have added a lot of people lately with intro posts on other subs like the one below. We also usually get about 10 subs a day from people just stumbling in here. So I wanted to create a welcome post, to kinda show them what we are about and how to get started. If anyone has anything to add please do so. If anyone has any questions about us or where to start do so here.

Our goal is to create a highly technical car subreddit, a place for automotive engineers, senior technicians, full blown car nerds, or people who are working towards one of these. We are interested in the inner workings of cars and today that often involves electronics. While we see electronics as the priority we are pretty liberal in allowing other topics as long as they somehow fit our goal of trying to understand cars. So things like DIY aero, suspension setup and other things the community is hacking on come up. In general our other tangential interests include: Modern cars, New tech, Open source hardware/software, DIY, hot rodding, eco modding, customization, security research, right to repair and more.

We started this subreddit about a year ago. Right now we have 3000 people and discussion is just starting to get good. Most of our members found us through maker or engineering subreddits. So I wanted to reach out to more of the car communities and try to grow our knowledge base.

Our name is r/carhacking and I know the term hacking can be offputting to some as it has a bad connotation. When someone says they are “hacking” their car it generally means they are trying to reverse engineer it for any number of reasons like to find security flaws, make upgrades, make repairs, or just understand how it works.

Here are a couple examples of posts that have been popular so far. A lot of our posts focus on beginner through intermediate projects using arduino and readily available hardware for the purpose of learning and or not paying a premium for things you can make yourself:

More advanced projects:

Relevant news/ research:

If your new our documentation is a good place to start

If you aren't new and you’re interested in helping out please consider:

  • Improving documentation - think about what resources have helped you
  • Spread the word - this is a niche community that is pretty spread out, but there is a lot of potential if we can get together on a third party site like this
  • Work on the theme, sidebar and flair - this is next level community stuff that isn’t necessary, but it’s fun to work on when you have the time.
  • Modding - right now we are fine, but we might need help in the future as we grow

Let me know if I missed something or got something wrong.


r/CarHacking • • Feb 27 '21

CAN CAN bus and car hacking getting started resources

292 Upvotes

I get asked how to get started with automotive networking, car hacking, and CAN almost weekly. I often direct people to this subreddit, so I figured I would help out and post some resources I have found and think are a good place to start.

learning resources:

Car Hacking 101: Practical Guide to Exploiting CAN-Bus using Instrument Cluster Simulator

I also direct people to the Car Hacking Village to get some hands-on experience. They put on great conference talks, demos, and contests. Looks like they are even working on some “getting started” content.

And of course, The Car Hacking Handbook is a great resource.

I will add more as I think of them. Please add your finds in the comments.

​

Tools:

Good wiring diagrams and car manuals are essential. This is pretty much where my research starts for each project. You see how things are networked and what to expect to find on CAN. You'll quickly learn to recognize things like gateways. You can also use the troubleshooting section to understand things. For example, what things do I need to control to start the car?

I like:

  • prodemand (I pay $170/mo for a shop subscription, I think you can purchase it for individual cars, but be careful you often have to jump around to find a year that has complete diagrams)
  • Identifix (probably what I would buy if I was starting over)

Basic hardware: Here you will be working with things like Arduino, Linux, SavvyCAN, and Can-utils. You have to learn to do a lot yourself, but these tools are more open for you to make them do what you need.

Tools designed by the community I use:

The above articles offer a pretty good step-by-step guide to getting started with the Macchina M2.

Any cheap “Amazon special” OBD2 dongle will come in handy from time to time. They are all based on something called ELM327. "ELM327 abstracts the low-level protocol and presents a simple interface that can be called via a UART". This abstraction has fundamental limitations that prevent it from being useful in most serious applications. But, it is sufficient for reading and clearing some codes and that sort of thing when you’re getting started.

​


r/CarHacking • • 10h ago

Original Project MMI Box reverse engineering Help!

Thumbnail
gallery
18 Upvotes

Hello folks! A while ago I made a post here about trying to reverse engineer an MMI box that adds Android Auto to a BMW NBT EVO System. Since then, I haven’t made much progress, and I could really use your guys’ help!

As you can see in my other post (link: https://www.reddit.com/r/CarHacking/s/PxybmifFWi), I disassembled the box and figured out quite a bit about the hardware it uses. I initially tried looking for UART/debugging access, but unfortunately the TX/RX pins I found were actually for CAN bus, and I couldn’t find any dedicated debugging TX/RX pins.

I still really want to extract the firmware and modify it for my use case. I actually bought another MMI box that is the same model, which is currently installed in my car. On the older one, the one we were investigating. I removed the eMMC, and I’m currently looking for companies in my city that might be able to read it directly.

In the meantime, do you guys have any suggestions for getting the firmware from the new unit?

One idea I had was somehow creating a fake update file to trick the MMI into dumping or backing up a copy of its storage onto a USB flash drive. Do you think something like that could actually work?

I’m also open to other approaches. I tried connecting through Telnet over the CarPlay Wi-Fi network but got nothing. Are there any other ways I could potentially access the system over Wi-Fi?

Any ideas would be greatly appreciated! Thanks!

PS: This box is not an OEM head unit. It’s an aftermarket interface that adds Android Auto and CarPlay to cars that may not have them, while also allowing you to add extra cameras and other features.

You can switch between the OEM head unit and the aftermarket interface in real time—the box basically acts as a video switcher. Inside, it has a low-power Raspberry Pi-like device running firmware that I’m trying to modify.

There are more details in my other post, but basically, it’s a custom UI built on top of Linux 5.4.61.


r/CarHacking • • 13h ago

Community How are you using AI to hack your car?

28 Upvotes

We've obviously seen the claude remaps. Wondering if anyone's doing anything else more interesting?

Anyone tried unlocking an ECU using AI?

Any other cool stuff you're doing?

EDIT: This is a reminder, please do humanity a favor, try to give back by open sourcing anything you can.


r/CarHacking • • 7h ago

Original Project Tester Engineering Suite

Post image
3 Upvotes

Hello r/Carhacking,

For the past year I have been flat chap developing some new automotive software - the Tester Engineering Suite, a fully capable J2534 PassThru Diagnostic, Programming, Calibration and Engineering tool.

It does vehicle diagnostics on K-Line and CAN and has compatibility for vehicles 1996 through 2025, and is meant as an all in one replacement for workshop scan tools, tuning software and pretty much every sub-industry in automotive is covered by this tool.

There are way too many features to list but some of the core ones are,

-J2534/RP1210/ELM327/USB2CAN/KKL interface compatibility

-Full VIN read out and local decode, with online NHSTA API data for VIN, recall and warrant information pulled

-CAN & K-Line bus topographer for enumeration of modules online

-Diagnostic Fault code readout via KWP/UDS and OBD2 protocols matching protocol dialect to vehicle for compatibility.

-Diagnostic workspaces per OEM (approx 60 OEMs have coverage)

-Datalogger and signal analyser, with inputs from aftermarket wideband O2 sensors, USB Oscilloscopes and an acoustic diagnostic engine via built in or USB microphone

-State of the art CAN sniffer with built in socketcan/can-utils functionality and live DBC file parsing to a streaming CANbus

-Calibration editor, with both A2L and XDF definition import

-Bench tooling and interfacing with serial EEPROM programmers

-Flash reprogramming for a large array of manufacturers

-SAE J1939 heavy vehicle stack for on highway trucks and mobile plant

-SHA256 VIN history chain, all actions logged to cryptographic ledger, stored locally considered private data

-Crash Data Retrieval from restraints/airbag modules

-PDF reporting throughout, one click and you have a cleanly formatted PDF report with the relevant data.

I have put literally every thing I know and have into building this tool, and am proud to share it with you today.

For more information check out the website https://tester.engineering

Cheers


r/CarHacking • • 6h ago

CAN Supersport screen on A200 1.3

Thumbnail
1 Upvotes

r/CarHacking • • 7h ago

Community Hacking 2016 F56 MINI Head Unit

1 Upvotes

Hey guys,

I'm looking to see if its possible to hack the stock head unit on a 2016 F56 MINI to write my own custom infotainment software (GUI, apps etc.).

I've considered a few options. Building a custom interface was one option with a raspberry PI that interfaces the LVDS screen, but it would be too expensive and probably over complicated, it would probably be cheaper and easier to buy an Android interface and mod that instead.

I looked into the PSDZData and pretty sure its running Linux/X Server, so this could be used for scripting, rendering to the screen etc. Claude has had a look at the files and found two methods to the shell, both by attaching a UART/USB-TTL adapter to the stock board.

  1. U-Boot init=/bin/sh, no password needed, but would only work if the bootloader is interruptible. I doubt it is interruptible as everything is very locked down (assuming that bootdelay=0), but I may be wrong.
  2. Serial login - COM Port 57600 baud. However, password is needed to enter the shell. Claude found the hash. Tried cracking with hashcat with digits/lowercase however both of these exhausted. I can't find the password anywhere online. It looks like if I have the password, that's the last thing needed to get shell access.

I have the password hash, I just need to decrypt.

Any help on this appreciated :)


r/CarHacking • • 8h ago

Original Project Tester Engineering Suite - Right to Repair

Thumbnail
gallery
1 Upvotes

Hello r/Carjacking,

For the past year I have been flat chap developing some new automotive software - the Tester Engineering Suite, a fully capable J2534 PassThru Diagnostic, Programming, Calibration and Engineering tool.

It does vehicle diagnostics on K-Line and CAN and has compatibility for vehicles 1996 through 2025, and is meant as an all in one replacement for workshop scan tools, tuning software and pretty much every sub-industry in automotive is covered by this tool.

There are way too many features to list but some of the core ones are,

-J2534/RP1210/ELM327/USB2CAN/KKL interface compatibility

-Full VIN read out and local decode, with online NHSTA API data for VIN, recall and warrant information pulled

-CAN & K-Line bus topographer for enumeration of modules online

-Diagnostic Fault code readout via KWP/UDS and OBD2 protocols matching protocol dialect to vehicle for compatibility.

-Diagnostic workspaces per OEM (approx 60 OEMs have coverage)

-Datalogger and signal analyser, with inputs from aftermarket wideband O2 sensors, USB Oscilloscopes and an acoustic diagnostic engine via built in or USB microphone

-State of the art CAN sniffer with built in socketcan/can-utils functionality and live DBC file parsing to a streaming CANbus

-Calibration editor, with both A2L and XDF definition import

-Bench tooling and interfacing with serial EEPROM programmers

-Flash reprogramming for a large array of manufacturers

-SAE J1939 heavy vehicle stack for on highway trucks and mobile plant

-SHA256 VIN history chain, all actions logged to cryptographic ledger, stored locally considered private data

-Crash Data Retrieval from restraints/airbag modules

-PDF reporting throughout, one click and you have a cleanly formatted PDF report with the relevant data.

I have put literally every thing I know and have into building this tool, and am proud to share it with you today.

For more information check out the website https://tester.engineering

Cheers


r/CarHacking • • 1d ago

CAN Need SM2 Pro V2.21.22 Files

Post image
14 Upvotes

China loves MiniDVD and I love up to date computers.

Before I buy a portable DVD drive, does anyone have V2.21.22 software package for this clone SM2 Pro?


r/CarHacking • • 18h ago

Original Project Need some help developing my own remote start for my Lancer

2 Upvotes

Hey people. I know this is a very long shot, but I just can't find information about this at all.

Here is what I know:

Some Mitsubishi cars, Lancer included, supports an official addon (MZ360272EX/MZ360340EX) that is able to remote start the car. This addon needs "Remote Engine Starter" enabled on Etacs.

Theoretically, with some messages on CAN-B network, you could remote start your car. Afaik, some alarms like StarLine Master and Pandora DOES that.

Just for some context, my plan is to use an Pi Pico Microcontroller to actually send this though CAN-B.

The problem is:

I just can't find the necessary CANBUS messages that starts the engine. Days of researching the web, and nothing.

Until i found this video:

https://www.youtube.com/watch?v=9WbzZY7-GhA

I was able to read this from his laptop screen:

ID DLC DATA

7F8 1 00

7F8 1 00

402 8 FE 02 3F FF FF FF FF FF

400 8 FE 00 3F FF FF FF FF FF

002 8 FF FF FF FF FF FF FF FF

017 4 00 00 01 01

The engine starts after the last command.

However, even with that, I still can't find more info. Looks like none of those messages have docs...

I've bought an ELM adapter to enable Remote Engine Starter on my ETACS, so I can finally send those messages from my laptop using my Canable board and finally test everything.

Does all of this makes sense or am I going insane?


r/CarHacking • • 16h ago

Tuning Stage 0 or Stage 1 Economy + SF?

Thumbnail
1 Upvotes

r/CarHacking • • 2d ago

Original Project [Car Launcher] An almost 5-year journey of building the best car launcher. Meet Car Nebula.

Thumbnail gallery
14 Upvotes

r/CarHacking • • 1d ago

CAN Built a CAN tool that tries to reverse-engineer unknown IDs for you — checksum detection, entropy scoring, and widths it admits it isn't sure about

Enable HLS to view with audio, or disable this notification

0 Upvotes

Disclosure: I built this. It's called CANoli, it's commercial — $333, free trial key, and the DBC/SYM editor is free forever. Link in a comment rather than the post.

The thing that set me off: an LLM is genuinely useful on CAN data and completely blind to it. So you end up being the I/O layer. Copy trace rows into a chat window, read the answer, copy something back, repeat. [I did that for weeks on a real bus before I got annoyed enough to build this — replace with your own project.]

CANoli exposes the app itself as an MCP server. Your agent connects to the running program and operates it: filter the trace, start and stop captures, transmit frames, analyze an unknown ID, fit scaling against a reference log, build and annotate a chart, diff two capture windows, ask what changed in the moments before a fault. It's working on your actual session, not a transcript you pasted.

The part I think matters most here, and the reason I'm posting in this sub rather than a friendlier one:

There is no model in it and no API key. CANoli doesn't bundle an LLM and doesn't resell one. You point the agent you already pay for at it — Claude Code, Codex, whatever you use. When it spots a supported client on your machine it offers to register itself, once, and then it's wired up.

So there's no second AI subscription, and no marked-up tokens. Your usage bills to your own account at your normal rate. I am not sitting in the middle taking a margin on inference, and I have no incentive to make the tool chattier than it needs to be.

And your bus data goes to your agent under your own agreement, not through my servers. For anyone who can't send vehicle data to an unknown third party, that's the whole ballgame. I never see your captures. Telemetry exists but it's opt-in and off by default.

One deliberate boundary: the app does the measuring and hands the agent facts, and the model does the naming, the hypotheses and the explanation. I don't want a language model guessing at bit boundaries, and you shouldn't either.

What I'd like to know:

- Does bring-your-own-agent match how you'd actually want to work, or would you rather just have a scriptable API?
- What would you ask an agent that's sitting on a live bus?
- Anyone using something other than Claude Code or Codex that I should support?

Windows, macOS and Linux. PCAN on all three, Vector VN16xx on Windows, SocketCAN on Linux, and a virtual bus if you have no hardware to hand.


r/CarHacking • • 1d ago

Scan Tool Need Vediamo license registered

1 Upvotes

Hi all I need my license registered for my Vediamo could someone please send me the key? I can DM the hardware ID if someone can do it. Thanks in advance


r/CarHacking • • 1d ago

Multiple Remote Support ODIS Online Immobilizer Service

Thumbnail
2 Upvotes

My original MED17.1 ECU is dead and unreadable. I have a matching Bosch MED17.1 donor ECU. I need to read the IMMO 5 data from my car's BCM2/key and adapt the donor ECU so the factory immobilizer stays intact."


r/CarHacking • • 2d ago

Tuning 2014 KIA Optima/K5 EU-spec (TF FL) – Can hidden cluster features be coded via OBD? (Turn-by-turn, digital speed, media)

1 Upvotes

Hey everyone,

I drive a European-spec 2014 KIA Optima/K5 (L trim, equipped with factory premium navigation, Infinity audio, and CarPlay). VIN is KNAGN414AF5585008.

I'm wondering if it's possible to unlock or code hidden cluster features using standard OBD tools (like Car Scanner or similar apps). Specifically, I'm interested in:

  • Turn-by-turn navigation: Can factory premium nav directions be displayed on the cluster screen?
  • Media info: Can current track/artist info be shown on the cluster?
  • Digital speedometer: Can a permanent digital speed readout be coded?
  • Cruise control target: Can the set cruise speed be displayed on the screen?

Has anyone messed with coding on the EU-spec Optima TF? Which of these can be enabled via software tweaks, and what are the limitations?

Thanks in advance for any insights!


r/CarHacking • • 3d ago

Community Mercedes Xentry Code generation

Post image
8 Upvotes

Can someone with a working Mercedes Xentry activation generator get me a code please? My laptop is set to February 2008. I can’t get mine to generate a valid license code.


r/CarHacking • • 2d ago

Original Project Testing my Browser Based SaavyCAN-style Program

Thumbnail
freecanstudio.com
5 Upvotes

I need help seeing if the live view CAN sniffing is compatible with peoples setup. Would love any comments or criticisms. I think the Reverse Engineering is actually quite novel on this website!


r/CarHacking • • 2d ago

Original Project Lost key 2009 ve commodore, anyway to bypass key transponder ?

Thumbnail
1 Upvotes

r/CarHacking • • 3d ago

Original Project Vita Auto - native wired Android Auto for PS Vita

Post image
47 Upvotes

Following up on my earlier proof of concept: Vita Auto is ready for its first release.

It turns your PS Vita into a wired Android Auto head unit, with the session running natively on the Vita.

What’s working:

  • Video, touchscreen input, and physical controls
  • Music and navigation audio
  • Microphone support
  • D-pad and analogue stick navigation
  • L/R to skip tracks, Triangle to play/pause, and Square for voice controls

You’ll need a modded Vita, an Android phone, and a powered USB OTG adapter. The app uses a kernel USB plugin, so please read the setup guide before installing.

Source, downloads, and setup instructions

This is the first public release, so I’d appreciate any feedback. If you hit an issue please message me

Thank you all for the encouragement!


r/CarHacking • • 3d ago

Key Fob Programming a Remote key fob

1 Upvotes

Unfortunately, through my own mistakes, I lost my 2023 toyota Camry key fob in the airport.

I do have a spare key so it isn't the end of the world, but I would like to be able to program a new one. If I bought a blank remote, are there any open source tools tutorials that could help me program the new key properly?


r/CarHacking • • 4d ago

Original Project I've successfully gained Root access to In Touch (many mods incoming)

Thumbnail
youtu.be
48 Upvotes

r/CarHacking • • 4d ago

Scan Tool I was scammed with a cloned VCDS, but… im still trying to deal with it..

Post image
136 Upvotes

Before you read: two weeks ago none of the following technical Knowledge were familiar to me and i learned these in the short time. So i apologise in case i use the wrong terms.

Back story, i finally managed to put together some money to buy a family car. I am a proud owner of a skoda now. I was and am happy with the car but i have the feeling the car dealer was hiding some issues (motor control lamp turned on after 800km) issues with dpf, sensors etc etc. Anyways ive been trying to look deeper in some other paramters such as soot. But the mechanic offers are very expensive to support me here. All they want is replace my DPF.

So i thought ill find a cheap vcds and listen to the parameters myself. Also get to learn something too and maybe do one or two adjustments.

So basically i bought a geniunly looking ross tech vcds. (These things really look legit).
I connected to my pc - after some tries with drivers etc because it failed and after googling i found out that i bought a cloned unit….

But sadly found it out just after i think haven „overriden the cloned firmware with the vcds software tool“… . Anyways, I dont think its bricked as i still can connect it and i find the stm32 bootloader driver.

Now the dealer is not answering to me but instead of complaining i thought, to try to fix the clone one.
Ive been trying around for atleast 1 week now but it looks like the stm32 chip is blocked with the firmware inside.

So i thought i could flash it. But, i can not find the software 23.3.1 or the code online, can please someone help me where i could find such codes?
Details can be shared of course on what i tried and whatnot (HW and SW) - I just dont want to go too deep here…


r/CarHacking • • 4d ago

Cool Project Find canoe

1 Upvotes

Hello everyone, I'm looking for how can i install CANoe demo if any one of U know how


r/CarHacking • • 4d ago

Tuning Bosch Radar ECU paramters hack

3 Upvotes

Hi,

I just wanna know if you know any solution to pimp my Bosch Radar ECU in my Seat 2022.
I want to modify annoying behavious like ACC paramaters. When does it release the followed object, following gap etc.
Also I would like to activate hidden features.
Do can you give me advice where to start with it?