HACK Navigation/Multimedia systems KIA/HYUNDAI and install third-party applications

Search This thread

olega59

Senior Member
Apr 20, 2015
56
12
Oleg, given you are the guru of all, this question is for you if you would please take the time.

I imported a 2019 kia cadenza sxl from USA to dubai, through the setting>navigation I can choose the speed displayed between miles and km, but it does not actually change in the cluster, my map is also stuck at the last location the car was last active in, California, in my own assumptions, i think because the car is not functioning with the gps the speed units have proven to be null, there are no controls from the cluster, just the head unit.

I dug around on the kia navigation update program, and when I compared both firmwares provided by the USA version and Middle East "MES", (attachments below), they both use the same format, which is YG19****STD_H. The USA file was around 20gb and the middle east was 7gb, so I downloaded the MES version onto the SD card, backed up my USA version and put it in the car but to no avail, is there a way around this? A force update or something?

Worth mentioning, I can access dealer options through the volume sequence and engineering mode through tapping 5 left to update and once to the right.

And if others have input on the matter please dont be shy to share in, thank you all for your efforts in advance.
Hello. Each region has its own navigation. Simply replacing the files on the SD card will not start navigation.
 
  • Like
Reactions: myrza_khan404

ibraheem saleh

New member
May 13, 2023
2
0
Hello, when I enter the engineer mode in Kia Niro 2017, I cannot change the settings as shown in the pictures. Is there a way to solve this problem? Thank you
 

ibraheem saleh

New member
May 13, 2023
2
0

Attachments

  • ٢٠٢٣٠٥١٣_١٢٥٧٠٦.jpg
    ٢٠٢٣٠٥١٣_١٢٥٧٠٦.jpg
    3.8 MB · Views: 93
May 7, 2023
9
0
guys quick question, I searched highs and lows but to no avail on how to change the map region on a kia, so the next step is changing the brains of the headunit, as explained the touch screen is only a screen that does not hold data, it receives from the control unit outlined in the picture below, is this true? or would I have to change out the screen aswell?

In short, my current plan is to take out the control unit outlined and fit in one that is from my region. I understand the wirings may differ and so on but that would be a me problem.
 

Attachments

  • WhatsApp Image 2023-05-13 at 7.29.48 PM.jpeg
    WhatsApp Image 2023-05-13 at 7.29.48 PM.jpeg
    107.6 KB · Views: 45

Warthog13

New member
Feb 2, 2023
4
0
Hello! I have opened ADB via USB on firmware UM_PE.KOR.SOP.048.220121.STD_H (Sorento 2017, gen 5), installed APK, changed language to Russian. But Carplay doesn't work. Turning ADB on/off didn't help.
 

Attachments

  • 1.jpg
    1.jpg
    2.4 MB · Views: 136
  • 2.jpg
    2.jpg
    2.5 MB · Views: 138
  • 4.jpg
    4.jpg
    3.3 MB · Views: 136
  • 6.jpg
    6.jpg
    2.5 MB · Views: 151
May 7, 2023
9
0
hello guys, anyone has the password for this update folder?
 

Attachments

  • update_package.zip
    257.5 MB · Views: 55
  • command.png
    command.png
    38.5 KB · Views: 128
May 7, 2023
9
0
Each firmware model has its own password. This has already been discussed.
are you implying a password is available within the treads or what?

xakcop has provided inputs about the passwords but I have had no luck with them, wondering if anyone would happen to have them on.
I have also used bkcrack but with no luck and when trying to brute force dates I am met with an error continuously.​

 

olega59

Senior Member
Apr 20, 2015
56
12
are you implying a password is available within the treads or what?

xakcop has provided inputs about the passwords but I have had no luck with them, wondering if anyone would happen to have them on.​

I have also used bkcrack but with no luck and when trying to brute force dates I am met with an error continuously.​

Each firmware has its own password.
 
May 7, 2023
9
0
Hello everyone,

I appreciate the inputs provided so far regarding the password for the update folder. I understand that each firmware model may have its own unique password. Despite trying various suggestions and even using tools like bkcrack, I haven't had any luck cracking the passkey yet.

If anyone has successfully cracked a similar firmware's password or has any guidance on how to approach this situation, I would greatly appreciate your assistance. Additionally, if there are any specific threads or resources you could point me towards, it would be very helpful.

On another note, I would like to mention that while Olega mentioned that each firmware has its own password, I believe it would be more constructive to provide specific guidance or suggestions rather than repeating the information that has been discussed before.

Thank you in advance for your support and guidance!
 

yaglnet

New member
Apr 27, 2023
4
0
To enable adb, change language, etc. we need to learn how to create our own firmware. To do this, we need to decompile the upgrade_parser. Judging by IDA Pro, there seems to be nothing complicated
 

Attachments

  • upgrade_parser.zip
    44 KB · Views: 38

olega59

Senior Member
Apr 20, 2015
56
12
On another note, I would like to mention that while Olega mentioned that each firmware has its own password, I believe it would be more constructive to provide specific guidance or suggestions rather than repeating the information that has been discussed before.
You want to get the password but don't want to give the full version of the firmware.
Do we need to guess? But that's not right!
 

Dũng Nguyễn 1186

New member
May 23, 2023
1
1
Bạn làm theo hướng dẫn trong video full này nhé. Có cả link để tải phần mềm phia dưới.

Ngoài ra bạn có thể xem bài hướng dẫn chi tiết ở nhóm kia seltos này nhé.


Nếu ko làm đc inbox mình zalo của bạn.
Cheers,
Cho em hỏi màn của em ấn ở màn hình khôi phục cài đặt gốc 5 lần góc bên trái, 5 lần góc bên phải nhưng không hiện cửa sổ ấn số mờ thì làm như thế nào ạ? Và bác có cách hack màn 10.25in không?
 
  • Like
Reactions: Hiep121184
May 7, 2023
9
0
You want to get the password but don't want to give the full version of the firmware.
Do we need to guess? But that's not right!
Sure thing, despite previously uploading two screenshots of the firmwares in question, I can understand how this has caused confusion mainly because I did not specify which version the update_package.zip is linked to. The software or firmware version is not of direct importance for the specific task of cracking the update_package.zip file in my case, but that could be different in yours. My focus has been on analyzing the ZIP file header and using tools like bkcrack to attempt password cracking.

To provide more context, the update_package.zip file I shared was obtained from the official navigation updater version YG19.MES.SOP.V134.221025.STD_H. I have been attempting to install the Middle East firmware on a 2019 head unit, which originally had the American firmware.

Regarding the steps I have been following, I have analyzed the ZIP file structure and made assumptions based on common patterns. For the plain.bin files, I created variations with different fixed values for the ZIP file header, such as the version bytes and the general purpose bit flag. This allows me to cover different possibilities during the password cracking process.

In the case of Radoslav's explanation, he made a wild guess about the subfolder's edit date being the same as the update_package.zip file, which he converted to MS-DOS format. However, I am currently trying to figure out the MS-DOS format conversion for my specific date (25 October 2022) to proceed with the attack.

Additionally, I have been exploring options to integrate Python with bkcrack to automate the process of trying different years and combining it with bkcrack. Unfortunately, I have encountered some challenges in integrating the two effectively.

If there are any additional steps or considerations that I might have missed in my previous explanations, please let me know. I appreciate your guidance and assistance in this matter.
 

olega59

Senior Member
Apr 20, 2015
56
12
Sure thing, despite previously uploading two screenshots of the firmwares in question, I can understand how this has caused confusion mainly because I did not specify which version the update_package.zip is linked to. The software or firmware version is not of direct importance for the specific task of cracking the update_package.zip file in my case, but that could be different in yours. My focus has been on analyzing the ZIP file header and using tools like bkcrack to attempt password cracking.

To provide more context, the update_package.zip file I shared was obtained from the official navigation updater version YG19.MES.SOP.V134.221025.STD_H. I have been attempting to install the Middle East firmware on a 2019 head unit, which originally had the American firmware.

Regarding the steps I have been following, I have analyzed the ZIP file structure and made assumptions based on common patterns. For the plain.bin files, I created variations with different fixed values for the ZIP file header, such as the version bytes and the general purpose bit flag. This allows me to cover different possibilities during the password cracking process.

In the case of Radoslav's explanation, he made a wild guess about the subfolder's edit date being the same as the update_package.zip file, which he converted to MS-DOS format. However, I am currently trying to figure out the MS-DOS format conversion for my specific date (25 October 2022) to proceed with the attack.

Additionally, I have been exploring options to integrate Python with bkcrack to automate the process of trying different years and combining it with bkcrack. Unfortunately, I have encountered some challenges in integrating the two effectively.

If there are any additional steps or considerations that I might have missed in my previous explanations, please let me know. I appreciate your guidance and assistance in this matter.
I don't think that by brute force you will be able to pick up a password of this type - 62166D314AC2A1BC503335801E10
Namely, such a password for the archive in these GUs.
P.S. this is not your password but just an example based on SantaFe
 
May 7, 2023
9
0
I don't think that by brute force you will be able to pick up a password of this type - 62166D314AC2A1BC503335801E10
Namely, such a password for the archive in these GUs.
P.S. this is not your password but just an example based on SantaFe
For a split second I got all hyped up thinking you had it until I saw it was for SantaFe xD

Given the difficulties I have encountered thus far in cracking the password using different approaches, including tools like bkcrack and zip_password_calculator, I am open to any alternative suggestions or methodologies that you might recommend. If there are any specific techniques or resources that have been successful in similar scenarios, I would greatly appreciate your insights.
 

olega59

Senior Member
Apr 20, 2015
56
12
For a split second I got all hyped up thinking you had it until I saw it was for SantaFe xD

Given the difficulties I have encountered thus far in cracking the password using different approaches, including tools like bkcrack and zip_password_calculator, I am open to any alternative suggestions or methodologies that you might recommend. If there are any specific techniques or resources that have been successful in similar scenarios, I would greatly appreciate your insights.
Post your firmware and give me a link.
There are many variables for opening the password.
Я посмотрю что я могу сделать.
P.S.
I downloaded your firmware myself.
Key generation is carried out according to 10 parameters. For which I will not speak, but the key to your firmware is this - EFA05D6E28D642EC1B40CF50FF34
 
Last edited:

Top Liked Posts

  • There are no posts matching your filters.
  • 15
    :D Sorry for my English! :D
    CAUTION: USE THIS AT YOUR OWN RISK!
    YouTube, your favorite navigation app, video player, online radio, online TV etc. now works on factory multimedia.
    No need to connect your multimedia to internet!
    This method works fine on models 2016-2018 of issue:
    KIA: Optima JF (K5), Rio, Soul, Ceed, Sorento Prime, Stinger, Sportage, Cerato (Forte) (may be other).
    HYUNDAI: Solaris, SantaFe, Sonata, Elantra, Creta, Genesis G70, Genesis G80 (may be other).
    On board we have Navigation/Multimedia system on Android 4.2.2;

    All fine-work applications on my Cloud drive HERE
    Please watch all videos from my YouTube channel Everything about everything

    If you like this please — Donate!:fingers-crossed:
    PayPal – [email protected]
    If you are not sure in your actions - I can lead you by Skype (WhatsApp, Telegram)

    WARNING!
    Do not install any LAUNCHERS (NovaLauncher etc.) or ROOT - it`s brick your device.
    Do not do anything else! Do not enter in other sections of Engineering mode.
    Be patient and follow the instructions strictly!

    FIRST:
    Download all the apps from my Cloud drive HERE
    And put all this files to root of the USB drive (FAT32)

    Let`s Go!
    This hack method no need`s to connect your multimedia to internet, if necessary
    - activate wifi access point on your phone or use wifi router. Connect your multimedia system to hotspot.
    You can watch my VIDEO MANUAL on YouTube HERE

    ENGINEERING MODE:
    Go to All Menus -> Settings -> Screensaver.
    To enter in the Engineering mode you need to tap 7 times under screensavers icons (on red rings) from left to right and back.

    do it fast.
    Great! Now we have password window! The password is – time on your clock now!


    Ok, its luck!

    ANDROID SETTINGS:
    Now we need to enter to Android settings -> Security and activate Unknown resources.

    Done! This will give us the opportunity to install applications from the USB drive.
    Note: this system hasn`t go Google apps, Play Market etc.
    Push Home button and then we need to access to Engineering mode again.

    INSTALLING FILE MANAGER:
    To access to the USB drive and install all the applications we need to install File Manager first!
    Go to All Menus -> Settings -> Screensaver, tap-tap-tap-tap-tap-tap-tap, password - time on clock.
    Engineering mode -> All Applications -> Browser

    On adress bar write: file:///storage/usb0/file.apk and tap OK!

    Now you can install the File Manager, install it and tap Open!


    Got it!

    INSTALLING APPS:
    In File Manager -> USB Storage you will see all apps.
    Fist install EasyTouch, when it`s intalled tap Open.

    Play EasyTouch Demo and them tap Go.
    Note: EasyTouch Settings works only on portrait orientation (don`t be afraid it`s mormal).
    So, there are many settings, they are no need us now, we need just activate EasyTouch button.

    Done! Now push Home and than tap EasyTouch button to open а window. Now we have BACK and HOME buttons.


    With long press on any icon in this window it can changed. Change one of them by choosing Engineering mode shortcut on Choose app -Done! Tap anywhere to close window.
    Call the window again, swipe left and open Android settings -> Special abilities -> Services EasyTouch - ON

    That’s Ok, now we can normally surf in internet and have all shortcuts of any apps.

    SOUND FIX:
    Note: Sound on third-party apps works only on MEDIA MODE whit connected USB flash drive (with media files) or with connected Bluetooth device.
    On RADIO or AUX MODE sounds from third-party apps doesn’t works!
    So, push EasyTouch button then swipe window and choose File Manager. Open USB storage and install SoundAbout, the Open it.

    Now we in SoundAbout settings. Choose on MEDIA AUDIO - Wired Headphones and that`s all.
    Tap EasyTouch button and BACK.
    Now we need to restart the multimedia - push reset button in SD card slot one time (or find it near you screen). Or you can turn off ACC, open and close driver door and wait 5 minutes to restart the Multimedia.
    Sound fixed!
    Now you can install any apps and it will be working fine with sound!

    YOUTUBE:
    On board we hasn`t got Google apps, so we need to install YouTube modification – YOUTUBE VANCED
    Push EasyTouch button then swipe window and choose File Manager. Open USB storage and install YouTube Vanced.
    Now you can try it!
    Open EasyTouch window and place YOUTUBE VANCED shortcut.

    VLC PLAYER:
    Push EasyTouch button then swipe window and choose File Manager. Open USB storage and install VLC Lite.
    Go to VLC Settings -> Hardware accelerationFull acceleration. Set it because we has poor hardware.
    Now you can watch films, clips, cartoons and everything you want from your USB flash drive or SD card.
    Don`t forget about shortcut.

    HERE NAVIGATION (or another favorite navigation):
    Note: Do not forget to connect WIFI first.
    Push EasyTouch button then swipe window and choose File Manager. Open USB storage and install HERE WeGo, launch, place shortcut.

    You can install everything applications you need but remember:
    DO NOT INSTALL ANY LAUNCHERS AND ROOT. DO NOT OPEN ANYTHING ELSE IN THE ENGINEERING MENU.

    If you are not sure in your actions - I can lead you by Skype (WhatsApp, Telegram)
    Thanks!:victory:
    7
    Just purchased a 2022 Telluride SX with the wide screen. Been reading this thread and noticing no one has found a way to get into engineering mode for these newer firmware, right?

    I would just like to side load some apps and be able to run them from the Kia main menu.

    If for some reason I am incorrect in that there’s no way to side load these newer widescreens then please do let me know. It’s Likely I may have scanned across a post or something that had that info.

    Thanks!

    Today on the Valentines day we have made a secret go public.
    We have been able to gain root access on the Gen5WIDE headunits from europe.

    with this hack you can grab and dump the whole system.
    extracts info, keys, decrypt files and perhaps create ur own custom fw.

    we provide this info for free, so people can share knowledge and new findings.

    Please be aware that this is mainly for devs and technical nerds and linux lovers. untill someone perhaps creates a more user friendly hack.

    Happy hunting

    4
    Hi guys,
    On my Tucson (2018 - AA) I can only access the engineering mode where I don't...

    Update on another model thet does not allow the "full engineering menu":
    2018 Elantra SEL USA version.
    NO: Cannot access the engineering mode that enables app installations (7 taps over 3 points on settings/screensaver).
    YES. Can access the engineering mode from Settings/System Info (5 taps left - 1 tab right).

    Looking forward to the hero that finds out how to jailbreak these versions!!
    3
    Now that we can sideload apps, is there any way to let Android auto work wirelessly?

    Inviato dal mio MI PAD 4 utilizzando Tapatalk

    Of course ! Just install Headunit Reloaded (4.6) on the car system.
    Set it with your phone name (SSID) used for wifi server, and leave IP blank (auto).

    The wifi mode of Headunit will automatically connect to Android Auto if this one is in developer mode and its server mode launched.

    Everything can be totally automatic, the phone can stay in the pocket. Android Auto appears on the main screen few seconds after the wifi connnection to the phone.