Closed knoopx closed 3 years ago
I haven't looked at your dump but I've already seen a similar chip, the other was a 20_CKM0R1. From the config registers I also concluded it was a LT89x0 running at 62.5Kbps with everything disabled (FEC, XOR, ...) and that the CC2500 would probably be able to emulate it. But since it was a new component I've requested the TX + RX to be shipped to me as you never know how the chip is sending over the air. When I've received it and used a SDR to look at the packets, the component was in fact sending in GFSK at 1Mbps a total of 277 bytes (FEC enabled with may be other stuff) which no RF components on Multi can do... So unless you have a SDR to see what's transmitted or willing to ship a TX, there is nothing I can do with just the dump. Pascal
I've got no SDR, but I would like to get one for further RF hacking. Does a 2.4ghz capable under 50€ SDR exist? Any recommendation?
I'm not aware of any cheapSDR which can do 2.4GHz unless you do like on this article and purchase a cheap radio SDR and put in front of it a downconverter: http://blog.cyberexplorer.me/2014/01/sniffing-and-decoding-nrf24l01-and.html I'm using a ADALM-Pluto.
Ok, got myself a hackrc (clone). Will learn and report my findings later.
Just received the HackRF. After powering the RX#1, it starts sending bind requests at 2404.4Mhz. When powering TX#1 and binding, it starts to frequency hop on 7 freqs at 2404.4Mhz, 2423.4Mhz, 2433.4Mhz, 2443.4Mhz, 2453.4Mhz, 2463.4Mhz and 2473.4Mhz. TX#2 binds and hops on 5 freq only (2404.4Mhz, 2423.4Mhz, 2433.4Mhz, 2443.4Mhz and 2463.4Mhz).
Unfortunately looks like it uses >1mhz bandwidth for transmission...
Hey @knoopx . I see this thread has been closed for years, but was wondering if this ever got any traction? It sounds like ">1mhz bandwidth for transmission..." is a no.
I've been trying to bind to what looks like the same thing (Haiboxing HBX-18859a). After disassembling my Tx, this thread is really the only info I was able to find.
Thx for putting in the effort to RE this stuff.
Hey @zakkhoyt yeah, none of the built-in multiprotocol chips is able to transmit at that bandwidth.
I have simmular pcb but there isnt any chip only the main one (it doesnt have text the main one)
Hi there, just got two new RC cars, one is a brushless touring "ZD Racing Rocket S16" and the other one brushed crawler "HBX 2098B Devastator". Just realised receivers are compatible between them. After disassembling both I found one its using one of the LT8900 variants, probably the LT8920 so I plugged in the logic analyser and captured some data via SPI. Looks like the data rate is 62.5kbps. Can we emulate using any of the existing modules?
Attaching a capture of the bind+idle.
Logic2 Capture