pascallanger / DIY-Multiprotocol-TX-Module

Multiprotocol TX Module (or MULTI-Module) is a 2.4GHz transmitter module which controls many different receivers and models.
https://www.rcgroups.com/forums/showthread.php?t=2165676&goto=newpost
GNU General Public License v3.0
1.66k stars 441 forks source link

LANSU S&T #541

Closed knoopx closed 3 years ago

knoopx commented 3 years ago

Hi there, just got two new RC cars, one is a brushless touring "ZD Racing Rocket S16" and the other one brushed crawler "HBX 2098B Devastator". Just realised receivers are compatible between them. After disassembling both I found one its using one of the LT8900 variants, probably the LT8920 so I plugged in the logic analyser and captured some data via SPI. Looks like the data rate is 62.5kbps. Can we emulate using any of the existing modules?

Attaching a capture of the bind+idle.

Logic2 Capture

image

image

S20210223_002

pascallanger commented 3 years ago

I haven't looked at your dump but I've already seen a similar chip, the other was a 20_CKM0R1. From the config registers I also concluded it was a LT89x0 running at 62.5Kbps with everything disabled (FEC, XOR, ...) and that the CC2500 would probably be able to emulate it. But since it was a new component I've requested the TX + RX to be shipped to me as you never know how the chip is sending over the air. When I've received it and used a SDR to look at the packets, the component was in fact sending in GFSK at 1Mbps a total of 277 bytes (FEC enabled with may be other stuff) which no RF components on Multi can do... So unless you have a SDR to see what's transmitted or willing to ship a TX, there is nothing I can do with just the dump. Pascal

knoopx commented 3 years ago

I've got no SDR, but I would like to get one for further RF hacking. Does a 2.4ghz capable under 50€ SDR exist? Any recommendation?

pascallanger commented 3 years ago

I'm not aware of any cheapSDR which can do 2.4GHz unless you do like on this article and purchase a cheap radio SDR and put in front of it a downconverter: http://blog.cyberexplorer.me/2014/01/sniffing-and-decoding-nrf24l01-and.html I'm using a ADALM-Pluto.

knoopx commented 3 years ago

Ok, got myself a hackrc (clone). Will learn and report my findings later.

knoopx commented 3 years ago

Just received the HackRF. After powering the RX#1, it starts sending bind requests at 2404.4Mhz. When powering TX#1 and binding, it starts to frequency hop on 7 freqs at 2404.4Mhz, 2423.4Mhz, 2433.4Mhz, 2443.4Mhz, 2453.4Mhz, 2463.4Mhz and 2473.4Mhz. TX#2 binds and hops on 5 freq only (2404.4Mhz, 2423.4Mhz, 2433.4Mhz, 2443.4Mhz and 2463.4Mhz).

image

Unfortunately looks like it uses >1mhz bandwidth for transmission...

image

zakkhoyt commented 9 months ago

Hey @knoopx . I see this thread has been closed for years, but was wondering if this ever got any traction? It sounds like ">1mhz bandwidth for transmission..." is a no.

I've been trying to bind to what looks like the same thing (Haiboxing HBX-18859a). After disassembling my Tx, this thread is really the only info I was able to find.

hbx18859a

Thx for putting in the effort to RE this stuff.

knoopx commented 9 months ago

Hey @zakkhoyt yeah, none of the built-in multiprotocol chips is able to transmit at that bandwidth.

dogesTV commented 3 months ago

e303e9c8-6fa2-4721-9e30-f814b84adf47 98e72633-0c8d-42cb-9757-577ce5213601 I have simmular pcb but there isnt any chip only the main one (it doesnt have text the main one)