Continue to Site

Welcome to EDAboard.com

Welcome to our site! EDAboard.com is an international Electronics Discussion Forum focused on EDA software, circuits, schematics, books, theory, papers, asic, pld, 8051, DSP, Network, RF, Analog Design, PCB, Service Manuals... and a whole lot more! To participate you need to register. Registration is free. Click here to register now.

How to bypass GM RFID CAR immobilizer?

Status
Not open for further replies.

david90

Advanced Member level 1
Joined
May 5, 2004
Messages
423
Helped
9
Reputation
18
Reaction score
4
Trophy points
1,298
Activity points
3,611
GM RFID CAR Immobilizer

does anyone know how the bypass module work or if there is a schematic for it? I know it's pretty complex but eh
 

Re: GM RFID CAR Immobilizer

hi,

Just a thought, follow the ignition wires to and from the imobiliser unit, all the unit really does is close a relay when you provide the correct code (RFID). So, cut, and connecting these wires together should completely bypass it. Some newer models are more complicated, controlling the ECU as well (you can get the starter going, but no ignition/sparks).

I've no experience in this, but I love a challenge :D Especially with regard to security systems......most are terribly designed.

Buriedcode.
 

GM RFID CAR Immobilizer

My car is a 06 scion tC. I doubt it uses a relay. I think the RFID goes directly to the ECU.

Is there a way to record the RF signal from the key? Maybe make a circuit that sends out the same rf signal
 

GM RFID CAR Immobilizer

i am afraid that you will always get new sequence of bytes from RF reader and transponder - as being security RF device, it has to be encrypted.
 

Re: GM RFID CAR Immobilizer

Hey,

If you have the transmitter, and it works, recording the signal from the keyfob to teh receiver (RF) wouldn't do much good. Artem is right......RFID is pretty damn robust. But thats not where the flaw is....

I doubt very much that the signal from the RFID receiver (going to the ECU) is the same. That would require adding a new lot of code to the ECU (when the immobiliser is installed) to decrypt it. So I'm betting, the immoibliser decodes the RFID signal, and sends 'immobilser ON/OFF' messages to the ecu. Or even simply making a pin high. Recirding that and playing it back for the ECU might work. One caveat: If the car in question was manufactured with the immobiliser installed, then it 'may' be hardwired. But, you never know...

I've worked with a couple of ECU's, and they're not that complicated. Because of reliability being the main ssue, they're pretty simple. Poking around where the immobilser receiver connects to it shouldn't be hard. LED, multimeter, logic analyser etc..

Alternatively, you could knock up an OBD-II -> RS232 converter and check exactly whats happening in the ECU, if the PC software showes anything to do with immobilisation, then chances are, its hardwired into the ECU.

Again, I don't have a clue what I'm talking about really, but hacking systems (hence, proving some manufacturers 'hype' wrong) is what I'm best at.

Good luck, let me know how you got on.

Buriedcode.
 

GM RFID CAR Immobilizer

I suppose that system is similar to this one or more complicated :
**broken link removed**
 

Re: GM RFID CAR Immobilizer

thanks
 

Status
Not open for further replies.

Part and Inventory Search

Welcome to EDABoard.com

Sponsor

Back
Top