Jump to content

Only for the brave. Russian Hack for the Mini Pro


Recommended Posts

15 hours ago, Nospeedlimits said:

You are claiming you have the mod but I see no proof. Post a video on YouTube, post the software file..... I went to your website and it has no files....

SwallowBot video. In the no open firmware access. Wait for the news from the developer.

  • Upvote 1
Link to comment
Share on other sites

2 hours ago, MRN76 said:

SwallowBot video. In the no open firmware access. Wait for the news from the developer.

You know something about Alexey, a month ago he did not respond to e-mails. In the meantime, I'm going to make you famous, sharing your information.

Link to comment
Share on other sites

41 minutes ago, Atharif said:

You know something about Alexey, a month ago he did not respond to e-mails. In the meantime, I'm going to make you famous, sharing your information.

Alexey, at my request, recorded a video of the ride on the  mod firmware SwallowPlus. He works a lot of time, and do not always have time to respond to emails.

Link to comment
Share on other sites

32 minutes ago, MRN76 said:

Alexey, at my request, recorded a video of the ride on the  mod firmware SwallowPlus. He works a lot of time, and do not always have time to respond to emails.

Thx

Link to comment
Share on other sites

Overall very excited stuff you key people are up to!  

Im still a little confused, will the change to swallow for the ninebot pro be a wireless update or do we need to solder onto board and use a programmer?

 

How can we support your awesome work here?

 

thank you!

Link to comment
Share on other sites

3 hours ago, Junkycosmos said:

Overall very excited stuff you key people are up to!  

Im still a little confused, will the change to swallow for the ninebot pro be a wireless update or do we need to solder onto board and use a programmer?

 

How can we support your awesome work here?

 

thank you!

The update will be distributed on a commercial basis. The upgrade process will be easy, there will be an application for the android phone (with bluetooth). Works with all firmware versions (from 1.1.7 to 1.4.9)

Link to comment
Share on other sites

 

Dear friends, sincerely, I think you have to take precautions.


I invite you all to look at this document
These three people who "discovered "   ?  the Mini hack, in fact, found the way here, in this forum, in the topic dedicated to the downgrade
They used, and appropriated the work of Denniss and Alexander
After they found the way to counter
They contacted Ninebot
They also made money with
And they allowed the blocking of the downgrade and also the brickage of many Mini in the world

they are lazy, opportunistic, peepholes, I am very angry at these three people, with Denniss and Alexander i helped many people to downgrade, and when NINEBOT blocked access, with a new version of the application, I witnessed real-time user who broke their Mini because of the solution that these three big copiers broadcast to NINEBOT . In the two topics and in my mailbox, we have a lot of messages from user's bricking mini

These three guys, they are members here, or they come like insider see what happens, that's what they did, and it's their fault that we could donwgrad more

@MRN76As soon as they go to see if they have not already seen it, they will buy your solution, they will work on it and do the same thing again

 

Extract from document

***Timeline 

December 2016: IOActive conducts testing on Segway/Ninebot MiniPRO scooter.

 December 24, 2016: IOActive contacts Segway/Ninebot via a public email address to establish a line of communication.

 January 4, 2017: Segway/Ninebot responds to IOActive. © 2017 IOActive, Inc. All Rights Reserved [6] 

January 27, 2017: IOActive discloses issues to Segway/Ninebot. 

April 2017: Segway/Ninebot releases an updated application (3.20), which addresses some of IOActive’s findings. 

April 17, 2017: Segway/Ninebot informs IOActive that remediation of critical issues is complete.

 July 19, 2017: Findings are published.***

 

If you really want to be quiet, you should no longer use this ninebot application and work with Darknessbot app creator, if you do not quickly use a solution other than the use of the official application, all your work will be hacked by these three as****les

 

extract from the document, it was exactly the way we made with Denniss and Alexander, when i try first the downgrade...

 

****

5. An attacker can then upload an arbitrary firmware image to the scooter by DNS
spoofing. By changing the A-Record for apptest.ninebot.cn, the attacker can direct
the rider application to download any firmware image.
6. Next, The attacker can use the following process to notify the rider application that
there is a firmware update available:
a. On http://apptest.ninebot.cn, change the
/appversion/appdownload/NinebotMini/version.json file to match the new
firmware version and size. The example below forces the application to
update the control/mainboard firmware image (aka Driver board firmware) to
v1.3.3.7, which is 50212 bytes in size.
“CtrlVersionCode":["1337","50212"]
b. Create a matching directory and file including the malicious firmware
/appversion/appdownload/NinebotMini/v1.3.3.7/Mini_Driver_v1.3.3.7.zip with
the modified update file Mini_Driver_V1.3.3.7.bin compressed inside the
firmware update archive.
7. When launched, the Ninebot application checks to see if the firmware version on the
scooter matches the one downloaded from apptest.ninebot.cn. If there is a later
version available (that is, if the version in the JSON object is newer than the version
currently installed), the app triggers the firmware update process.

****

 

I love, I love your work on this hack, I consider it the best solution to keep having fun with MINI 
it's a great job that deserves to be known by all users
Wang said he pushed the speed limit of the MINI when testing at 28kmh
The speed of 22 / 23kmh is perfect for autonomy and safety


You did a great job !
Do not make it stolen !


I would like to publish it on my blog but if Ninebot or these three ass***es fall on it,
you will only have trouble

 

Link to comment
Share on other sites

28kph is really my dream on miniPro:dribble:

28 means that you can stay on aaverage speed mean of 23-24kph:dribble::thumbup:

 

Hope someone will realise my dream on miniPro:whistling:

Link to comment
Share on other sites

I did not steal the idea of rolling back firmware by replacing the server!
March 2016 - I began to study the processor and the structure of a ninebot one e+.
06.12.2017 the founder of ninebot.run came to me with ninebot mini with the request to help roll back the firmware from 1.4.0 to 1.1.7
Over time, people came to visit me, and I created a database of all the firmware that came out. I read them from device processors.
Then I studied the structure in detail, wrote an application that works with the processor dump.
Met with Alexey, we found how to construct the device protection.
Then I accidentally found a way to raise the speed. Alexey helped me to make it maximum beautiful.
Next, Alexey understood the algorithm for encryption of firmware 1.3.1, 1.4.0, 1.4.1, 1.4.9.
At the moment, Alexey has written an android application, for firmware devices. But this app is only for his friends.
Now Alex has remodeled encryption on his own, and soon will be released version for the whole world, so that the fans of the device could enjoy the work of the device.
To what those 3 people did we have nothing to do, we did everything absolutely differently!
At full charge, you can safely go 25km and even 26km, but after counting, having done a lot of tests we stopped at SAFE speed. Even riders weighing 110kg drive safely.
I apologize for the translation, and it's very insulting that you accuse us of stealing.
 

  • Like 2
  • Upvote 1
Link to comment
Share on other sites

MRN76, the wonderful "Dump Editor Ninebot" which you wrote has restored my faith in the MiniPro's capabilities. I am glad you are testing the load limit, as that is what is giving me real problems, since I weigh about 200lbs (90Kg) and the roads and parks around here are very hilly. Even the 1.1.7 software is occasionally throwing me when going uphill on uneven pathways, and it pushes back really aggressively (almost pushing me off the footpads) on a 15degrees bitumen surface. It is clear that the MiniPro only just supplies enough energy to deal with a rocky surface if there is a lighter weight person on it. I have changed to 90/65 knobbly tires, and this evens out the load which obstacles present to the motor - making a huge difference off-road, but obviously there is a lot of vibration and noise on bitumen :(

I am looking forward to purchasing Swallowbot to see how it helps the MiniPro intelligently handle obstacles, something the MiniPro in its default (safety-paranoia) configuration does not do. Please keep up the good work. Eagle has written to me intermittently, he really does an excellent job, considering that he also has to earn a living!

Edited by trevmar
Link to comment
Share on other sites

1 hour ago, MRN76 said:

I did not steal the idea of rolling back firmware by replacing the server!
March 2016 - I began to study the processor and the structure of a ninebot one e+.
06.12.2017 the founder of ninebot.run came to me with ninebot mini with the request to help roll back the firmware from 1.4.0 to 1.1.7
Over time, people came to visit me, and I created a database of all the firmware that came out. I read them from device processors.
Then I studied the structure in detail, wrote an application that works with the processor dump.
Met with Alexey, we found how to construct the device protection.
Then I accidentally found a way to raise the speed. Alexey helped me to make it maximum beautiful.
Next, Alexey understood the algorithm for encryption of firmware 1.3.1, 1.4.0, 1.4.1, 1.4.9.
At the moment, Alexey has written an android application, for firmware devices. But this app is only for his friends.
Now Alex has remodeled encryption on his own, and soon will be released version for the whole world, so that the fans of the device could enjoy the work of the device.
To what those 3 people did we have nothing to do, we did everything absolutely differently!
At full charge, you can safely go 25km and even 26km, but after counting, having done a lot of tests we stopped at SAFE speed. Even riders weighing 110kg drive safely.
I apologize for the translation, and it's very insulting that you accuse us of stealing.
 

i dont said you steal anything

please

read again my message

if you translate my text from english to russian, and me i wrotte from french to english, sure you will never undertsand what i want say

Edited by jojo33
Link to comment
Share on other sites

1 hour ago, MRN76 said:

I did not steal the idea of rolling back firmware by replacing the server!
March 2016 - I began to study the processor and the structure of a ninebot one e+.
06.12.2017 the founder of ninebot.run came to me with ninebot mini with the request to help roll back the firmware from 1.4.0 to 1.1.7
Over time, people came to visit me, and I created a database of all the firmware that came out. I read them from device processors.
Then I studied the structure in detail, wrote an application that works with the processor dump.
Met with Alexey, we found how to construct the device protection.
Then I accidentally found a way to raise the speed. Alexey helped me to make it maximum beautiful.
Next, Alexey understood the algorithm for encryption of firmware 1.3.1, 1.4.0, 1.4.1, 1.4.9.
At the moment, Alexey has written an android application, for firmware devices. But this app is only for his friends.
Now Alex has remodeled encryption on his own, and soon will be released version for the whole world, so that the fans of the device could enjoy the work of the device.
To what those 3 people did we have nothing to do, we did everything absolutely differently!
At full charge, you can safely go 25km and even 26km, but after counting, having done a lot of tests we stopped at SAFE speed. Even riders weighing 110kg drive safely.
I apologize for the translation, and it's very insulting that you accuse us of stealing.
 

Excuse me if I meddle, but this happens through the silence and secrecy with which you carry this, without any information, but many people eager to know the great final product.

Do not take it the wrong way, it is better to help, give this information that you just gave us a lot of help for our trust, if you are reporting something better, people will understand your great work and be less suspicious of everything.

The music appeases the beasts, give us music.

Link to comment
Share on other sites

1 hour ago, MRN76 said:

I did not steal the idea of rolling back firmware by replacing the server!

i never said that 

2 minutes ago, Atharif said:

To what those 3 people did we have nothing to do, we did everything absolutely differently!

that was not what I was talking about these three types

1 hour ago, MRN76 said:

At full charge, you can safely go 25km and even 26km, but after counting, having done a lot of tests we stopped at SAFE speed. Even riders weighing 110kg drive safely.

what did I say wrong?

8 hours ago, jojo33 said:

I love, I love your work on this hack, I consider it the best solution to keep having fun with MINI 
it's a great job that deserves to be known by all users
Wang said he pushed the speed limit of the MINI when testing at 28kmh
The speed of 22 / 23kmh is perfect for autonomy and safety

1 hour ago, MRN76 said:

I apologize for the translation, and it's very insulting that you accuse us of stealing.

you can be apologize because I never criticized your work here

the only people I'm accusing these the three guys who stole the methods
it was only to warn you that they will do that again, and this time with your work
you do not want to understand how I write
it is a problem

you misinterpret what I say

totally

Is there anyone who understands the meaning of my post here? Or do I have to retranslate it?

 

8 hours ago, jojo33 said:

 

Dear friends, sincerely, I think you have to take precautions.


I invite you all to look at this document
These three people who "discovered "   ?  the Mini hack, in fact, found the way here, in this forum, in the topic dedicated to the downgrade
They used, and appropriated the work of Denniss and Alexander
After they found the way to counter
They contacted Ninebot
They also made money with
And they allowed the blocking of the downgrade and also the brickage of many Mini in the world

they are lazy, opportunistic, peepholes, I am very angry at these three people, with Denniss and Alexander i helped many people to downgrade, and when NINEBOT blocked access, with a new version of the application, I witnessed real-time user who broke their Mini because of the solution that these three big copiers broadcast to NINEBOT . In the two topics and in my mailbox, we have a lot of messages from user's bricking mini

These three guys, they are members here, or they come like insider see what happens, that's what they did, and it's their fault that we could donwgrad more

@MRN76As soon as they go to see if they have not already seen it, they will buy your solution, they will work on it and do the same thing again

 

Extract from document

***Timeline 

December 2016: IOActive conducts testing on Segway/Ninebot MiniPRO scooter.

 December 24, 2016: IOActive contacts Segway/Ninebot via a public email address to establish a line of communication.

 January 4, 2017: Segway/Ninebot responds to IOActive. © 2017 IOActive, Inc. All Rights Reserved [6] 

January 27, 2017: IOActive discloses issues to Segway/Ninebot. 

April 2017: Segway/Ninebot releases an updated application (3.20), which addresses some of IOActive’s findings. 

April 17, 2017: Segway/Ninebot informs IOActive that remediation of critical issues is complete.

 July 19, 2017: Findings are published.***

 

If you really want to be quiet, you should no longer use this ninebot application and work with Darknessbot app creator, if you do not quickly use a solution other than the use of the official application, all your work will be hacked by these three as****les

 

extract from the document, it was exactly the way we made with Denniss and Alexander, when i try first the downgrade...

 

****

5. An attacker can then upload an arbitrary firmware image to the scooter by DNS
spoofing. By changing the A-Record for apptest.ninebot.cn, the attacker can direct
the rider application to download any firmware image.
6. Next, The attacker can use the following process to notify the rider application that
there is a firmware update available:
a. On http://apptest.ninebot.cn, change the
/appversion/appdownload/NinebotMini/version.json file to match the new
firmware version and size. The example below forces the application to
update the control/mainboard firmware image (aka Driver board firmware) to
v1.3.3.7, which is 50212 bytes in size.
“CtrlVersionCode":["1337","50212"]
b. Create a matching directory and file including the malicious firmware
/appversion/appdownload/NinebotMini/v1.3.3.7/Mini_Driver_v1.3.3.7.zip with
the modified update file Mini_Driver_V1.3.3.7.bin compressed inside the
firmware update archive.
7. When launched, the Ninebot application checks to see if the firmware version on the
scooter matches the one downloaded from apptest.ninebot.cn. If there is a later
version available (that is, if the version in the JSON object is newer than the version
currently installed), the app triggers the firmware update process.

****

 

I love, I love your work on this hack, I consider it the best solution to keep having fun with MINI 
it's a great job that deserves to be known by all users
Wang said he pushed the speed limit of the MINI when testing at 28kmh
The speed of 22 / 23kmh is perfect for autonomy and safety


You did a great job !
Do not make it stolen !


I would like to publish it on my blog but if Ninebot or these three ass***es fall on it,
you will only have trouble

 

@MRN76 me, tell you, that 3 guys will steal your idea , it's all

i never critized your work

please'

Link to comment
Share on other sites

all i am trying to say is that there is a huge risk that the three guys from this company take ownership, steal the work of mrn76 and alexis and block with ninebot this possibility to evolve the Mini

Link to comment
Share on other sites

@MRN76Я пытаюсь сказать вам, что эта компания отслеживает темы здесь
и что эти ребята могут заказать вашу прошивку
работай над этим
и заблокируйте свою прошивку

Link to comment
Share on other sites

I translate sentences from French to English and then from English to Russian, it's totally a false translation

Я переводил предложения с французского на английский
а затем с английского на русский,
это полностью ложный перевод

 

Link to comment
Share on other sites

28 minutes ago, Atharif said:

your great work and be less suspicious of everything.

i said it's a great work really

17 minutes ago, jojo33 said:

I love, I love your work on this hack, I consider it the best solution to keep having fun with MINI 
it's a great job that deserves to be known by all users

but I do not know how it was translated into Russian...

Link to comment
Share on other sites

@jojo33Sorry, I did not understand. The translation of Google incorrectly conveyed your idea, and I thought that the pritenziya to us.

2 hours ago, jojo33 said:

all i am trying to say is that there is a huge risk that the three guys from this company take ownership, steal the work of mrn76 and alexis and block with ninebot this possibility to evolve the Mini

The firmware is locked. The processor is also blocked for reading by the programmer (Unlocks only by erasing the chip). And the firmware itself on bluetooth is transmitted in encrypted form.

  • Upvote 1
Link to comment
Share on other sites

11 hours ago, jojo33 said:

@MRN76As soon as they go to see if they have not already seen it, they will buy your solution, they will work on it and do the same thing again

They already can not do anything. Only remove the process of updating the firmware via the phone application, and make it accessible only through the service connector in an authorized service center. And this will not help them, by soldering 5 wires it is easily cracked.
Alexey has already dealt with the ES scooters, a mini plus. Surely, there will be similar encryption with Zseries, and Alexey will help us to remake z6 in z10.

Edited by MRN76
  • Upvote 1
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...