Notices
2017 - 2022 Super Duty The 2017-2022 Ford F250, F350, F450, F550 & F600 Super Duty Pickup and Chassis Cab
Sponsored by:
Sponsored by: CARiD

Custom Screen Animation

Thread Tools
 
Search this Thread
 
Old Jan 8, 2019 | 03:31 PM
  #1  
rjbrittain11's Avatar
rjbrittain11
Thread Starter
|
Mountain Pass
5 Year Member
Photogenic
Photoriffic
Joined: Dec 2018
Posts: 160
Likes: 5
From: Bay Area, CA
Custom Screen Animation

I am new here so i don't know if this has been asked before...

I have used FORscan and see that we can change the screen animation to a Raptor and some others. Im curious to know if its possible to put a custom animation here? Has anyone looked deeper into this or has done it?
 
Reply
Old Jan 8, 2019 | 04:38 PM
  #2  
TXSD6.2's Avatar
TXSD6.2
More Turbo
Joined: May 2018
Posts: 590
Likes: 32
Interested in any replies here as well.
 
Reply
Old Jan 8, 2019 | 04:44 PM
  #3  
Alaskan_Warbird's Avatar
Alaskan_Warbird
Posting Guru
Joined: Mar 2018
Posts: 1,962
Likes: 11
From: Fairbanks, AK
Good question. I'm curious too.
 
Reply
Old Jan 8, 2019 | 04:52 PM
  #4  
TXSD6.2's Avatar
TXSD6.2
More Turbo
Joined: May 2018
Posts: 590
Likes: 32
After a little googling, it looks like the stock animations are mp4 files. I couldn't find any discussions where someone stated success, but it has been suggested that you may be able to open up one of the sync 3 updates (which include the stock animations) and replace one ore more of the mp4 files with a custom animation. If the sync3 update script does something like md5 checksum verification, this may not be possible.
 
Reply
Old Jan 8, 2019 | 05:47 PM
  #5  
Tricon's Avatar
Tricon
Logistics Pro
5 Year Member
Photogenic
Photoriffic
Shutterbug
Joined: Apr 2017
Posts: 3,674
Likes: 51
From: SoCal
Its not easily done right now. The Sync system uses QNX as its OS, which is *NIX based. The update files have .IFS files and .IMG files. I've been able to unpack the IFS files using QNX dumpifs tool, but there's not much there of any use. The .IMG files on the other hand are where most of the payload is, but I haven't been able to successfully access them. I've mounted the files, they report an x86 boot sector, but they are using a QNX file system that I don't have access to. (e.g. mount -t qnx6 ./file.img -o loop/dev/loop1,blocksize=512 /media/qnx fails with a file system error).

I found a virtual machine of QNX 6.5 and got it up and running on my Windows machine, but I had issues getting the network stack to initialize and couldn't easily get the files over to the VM so I could mount them. That's where I left off about a year ago....I might take a crack at it again. This is all for naught if the update has a checksum function, but that would have to be in the update file itself, since they can't know what the checksum is until they package the update, so I guess theoretically that would be easy enough to bypass.
 
Reply
Old Jan 8, 2019 | 05:53 PM
  #6  
2009kr's Avatar
2009kr
Cargo Master
10 Year Member
Photogenic
Photoriffic
Shutterbug
Joined: Aug 2015
Posts: 2,400
Likes: 15
I tried this same exercise with my 2009 F150 sync updates. They had an HMAC MD5. It's a symmetric algorithm, so the needed key will be somewhere in the sync unit's firmware. While I could likely crack it, it wasn't worth the effort to me. You'd need to get the lower level firmware and reverse it. While I didn't "accept" a EULA prohibiting reverse engineering, the legality of this seems questionable.
 
Reply
Old Jan 8, 2019 | 05:53 PM
  #7  
Alaskan_Warbird's Avatar
Alaskan_Warbird
Posting Guru
Joined: Mar 2018
Posts: 1,962
Likes: 11
From: Fairbanks, AK
Great info Tricon, thanks!
 
Reply
Old Jan 8, 2019 | 05:59 PM
  #8  
2009kr's Avatar
2009kr
Cargo Master
10 Year Member
Photogenic
Photoriffic
Shutterbug
Joined: Aug 2015
Posts: 2,400
Likes: 15
Originally Posted by Tricon
... This is all for naught if the update has a checksum function, but that would have to be in the update file itself, since they can't know what the checksum is until they package the update, so I guess theoretically that would be easy enough to bypass.
The HMAC function combines the hash with a "secret" key. The key is shared between the OEM's programming system and the embedded systems (Sync computer). The information needed to calculate the hash is in the package, but the information needed for the HMAC, unfortunately won't be.
 
Reply
FTE Stories

Ford Trucks for Ford Truck Enthusiasts

story-0

This Hennessey Takes the Expedition Tremor's Off-Roading Capability to the Next Level

 Verdad Gallardo
story-1

Top 10 Fords at 2026 Carlisle Ford Nationals

 Joe Kucinski
story-2

3 Best / 3 Worst Parts of Modern Ford Ownership

 Brett Foote
story-3

10 Amazing Upgrades That Solve Common Ford Truck Owner Headaches

 Pouria Savadkouei
story-4

Every 2026 Ford Engine Explained

 Brett Foote
story-5

10 Ugly Ford Trucks That We Still Kinda Love

 Joe Kucinski
story-6

10 Things Every Truck Owner NEEDS (2026 Edition)

 Michael S. Palmer
story-7

Rezvani's Latest Post-Apocalyptic Monster Is a Ford F-150 Raptor Underneath

 Verdad Gallardo
story-8

Top 10 Most Expensive Ford Trucks Ever Sold on Bring a Trailer

 Joe Kucinski
story-9

2027 Ford Super Duty Buyer's Guide (Every Model, Engine, & Package)

 Brett Foote
Old Jan 8, 2019 | 06:05 PM
  #9  
Tricon's Avatar
Tricon
Logistics Pro
5 Year Member
Photogenic
Photoriffic
Shutterbug
Joined: Apr 2017
Posts: 3,674
Likes: 51
From: SoCal
Originally Posted by 2009kr
The HMAC function combines the hash with a "secret" key. The key is shared between the OEM's programming system and the embedded systems (Sync computer). The information needed to calculate the hash is in the package, but the information needed for the HMAC, unfortunately won't be.
Ahhh, I was thinking more along the lines of a simple MD5 checksum, rather than a certificate type system.
 
Reply
Old Jan 8, 2019 | 06:26 PM
  #10  
Tricon's Avatar
Tricon
Logistics Pro
5 Year Member
Photogenic
Photoriffic
Shutterbug
Joined: Apr 2017
Posts: 3,674
Likes: 51
From: SoCal
It looks like they actually have MD5 sums for the individual files that are loaded in their .der certificate files. But....this just seems to easy to circumvent? 2009kr, how did you come to the conclusion on the HMAC system, did you alter something and try to install it?

Here's a snippet from one of the image certificates:

Type = Utility
Post-Script = GB5T-14G386-AB.sh
File1 = GB5T-14G386-AB.sh
File1 Hash Value = 01bced7dc9f78d69a35ce5c3f0712b8516330e827c1a97b658 3ab1d2fbb01dbf
File1 Size = 2231
File2 = utloggingutility
File2 Hash Value = d2a94381cdda68004ee55bd0c437f3f0148cd489733f8c4469 ad63b52df675e1
File2 Size = 85628
File3 = Decoded_ODL.xml
File3 Hash Value = 9d23e743e31f7075f06d88f198297122e82a2f851fac53adab f761a5c6dd731c
File3 Size = 9478
Save Location = /tmp/
 
Reply
Old Jan 8, 2019 | 06:26 PM
  #11  
rjbrittain11's Avatar
rjbrittain11
Thread Starter
|
Mountain Pass
5 Year Member
Photogenic
Photoriffic
Joined: Dec 2018
Posts: 160
Likes: 5
From: Bay Area, CA
Originally Posted by Tricon
Its not easily done right now. The Sync system uses QNX as its OS, which is *NIX based. The update files have .IFS files and .IMG files. I've been able to unpack the IFS files using QNX dumpifs tool, but there's not much there of any use. The .IMG files on the other hand are where most of the payload is, but I haven't been able to successfully access them. I've mounted the files, they report an x86 boot sector, but they are using a QNX file system that I don't have access to. (e.g. mount -t qnx6 ./file.img -o loop/dev/loop1,blocksize=512 /media/qnx fails with a file system error).

I found a virtual machine of QNX 6.5 and got it up and running on my Windows machine, but I had issues getting the network stack to initialize and couldn't easily get the files over to the VM so I could mount them. That's where I left off about a year ago....I might take a crack at it again. This is all for naught if the update has a checksum function, but that would have to be in the update file itself, since they can't know what the checksum is until they package the update, so I guess theoretically that would be easy enough to bypass.
Originally Posted by 2009kr
I tried this same exercise with my 2009 F150 sync updates. They had an HMAC MD5. It's a symmetric algorithm, so the needed key will be somewhere in the sync unit's firmware. While I could likely crack it, it wasn't worth the effort to me. You'd need to get the lower level firmware and reverse it. While I didn't "accept" a EULA prohibiting reverse engineering, the legality of this seems questionable.
Originally Posted by 2009kr
The HMAC function combines the hash with a "secret" key. The key is shared between the OEM's programming system and the embedded systems (Sync computer). The information needed to calculate the hash is in the package, but the information needed for the HMAC, unfortunately won't be.
Originally Posted by Tricon
Ahhh, I was thinking more along the lines of a simple MD5 checksum, rather than a certificate type system.
I mean, of course, that all makes sense.....

Way above my pay-grade! So you're sayin' there's a chance?!?!
 
Reply
Old Jan 8, 2019 | 06:28 PM
  #12  
2009kr's Avatar
2009kr
Cargo Master
10 Year Member
Photogenic
Photoriffic
Shutterbug
Joined: Aug 2015
Posts: 2,400
Likes: 15
Originally Posted by Tricon
Ahhh, I was thinking more along the lines of a simple MD5 checksum, rather than a certificate type system.
It's a little easier to deal with than a cert. With the cert, the private key needed to make the signature isn't on the system. With the HMAC, you need only to find the key stored on your system and then you can make images that will work on all systems. With cert based authentication, you can replace the public cert with your own to make your images verify. This involves writing, not just reading the low level firmware. It also only works on only the one computer that you replaced the cert on.
 
Reply
Old Jan 8, 2019 | 06:28 PM
  #13  
Tricon's Avatar
Tricon
Logistics Pro
5 Year Member
Photogenic
Photoriffic
Shutterbug
Joined: Apr 2017
Posts: 3,674
Likes: 51
From: SoCal
Originally Posted by rjbrittain11
So you're sayin' there's a chance?!?!
If what 2009kr is saying is correct, then no, not really. We're hosed at not knowing the internal key. Any update we would push would fail as it wouldn't have the key to our trucks chastity belts
 
Reply
Old Jan 8, 2019 | 06:30 PM
  #14  
Tricon's Avatar
Tricon
Logistics Pro
5 Year Member
Photogenic
Photoriffic
Shutterbug
Joined: Apr 2017
Posts: 3,674
Likes: 51
From: SoCal
Originally Posted by 2009kr
It's a little easier to deal with than a cert. With the cert, the private key needed to make the signature isn't on the system. With the HMAC, you need only to find the key stored on your system and then you can make images that will work on all systems. With cert based authentication, you can replace the public cert with your own to make your images verify. This involves writing, not just reading the low level firmware. It also only works on only the one computer that you replaced the cert on.
Then I could see them using the MD5's just for file integrity, and the HMAC to stop idiots like us from borking the whole thing. I got my QNX VM up and running, and the network stack is working this time, but I don't see a easy/legal way forward anyways.
 
Reply
Old Jan 8, 2019 | 06:34 PM
  #15  
rjbrittain11's Avatar
rjbrittain11
Thread Starter
|
Mountain Pass
5 Year Member
Photogenic
Photoriffic
Joined: Dec 2018
Posts: 160
Likes: 5
From: Bay Area, CA
Originally Posted by Tricon
Then I could see them using the MD5's just for file integrity, and the HMAC to stop idiots like us from borking the whole thing. I got my QNX VM up and running, and the network stack is working this time, but I don't see a easy/legal way forward anyways.
It's ok to skirt the lines of legal....better to ask for forgiveness than permission is what I say!
 
Reply



All times are GMT -5. The time now is 12:15 PM.

story-0
This Hennessey Takes the Expedition Tremor's Off-Roading Capability to the Next Level

Slideshow: The VelociRaptor Expedition gains a lift, upgraded suspension, Brembo brakes, and trail-ready equipment while retaining the stock 440-horsepower EcoBoost V6.

By Verdad Gallardo | 2026-06-12 11:01:55


VIEW MORE
story-1
Top 10 Fords at 2026 Carlisle Ford Nationals

Slideshow: Top 10 Fords at 2026 Ford Nationals

By Joe Kucinski | 2026-06-09 11:10:08


VIEW MORE
story-2
3 Best / 3 Worst Parts of Modern Ford Ownership

Based on years of owning multiple modern Ford products.

By Brett Foote | 2026-06-09 10:53:36


VIEW MORE
story-3
10 Amazing Upgrades That Solve Common Ford Truck Owner Headaches

SPONSORED: From muddy boots to rain-soaked cargo, these upgrades address some of the most common frustrations Ford truck owners face every day.

By Pouria Savadkouei | 2026-06-08 18:50:34


VIEW MORE
story-4
Every 2026 Ford Engine Explained

Here's everything you need to know about every Ford engine available for the 2026 model year.

By Brett Foote | 2026-06-05 12:58:01


VIEW MORE
story-5
10 Ugly Ford Trucks That We Still Kinda Love

Slideshow: 10 ugly Ford trucks that we still kinda love.

By Joe Kucinski | 2026-06-03 09:51:16


VIEW MORE
story-6
10 Things Every Truck Owner NEEDS (2026 Edition)

Slideshow: the best gifts for dads & grads

By Michael S. Palmer | 2026-06-03 15:43:58


VIEW MORE
story-7
Rezvani's Latest Post-Apocalyptic Monster Is a Ford F-150 Raptor Underneath

Slideshow: Called the Fortress, the 850-horsepower pickup combines Raptor underpinnings with military-inspired features, survival equipment, and a starting price of $285,000.

By Verdad Gallardo | 2026-06-03 11:38:36


VIEW MORE
story-8
Top 10 Most Expensive Ford Trucks Ever Sold on Bring a Trailer

Slideshow: 10 most expensive Ford trucks ever sold on Bring a Trailer.

By Joe Kucinski | 2026-05-27 16:24:34


VIEW MORE
story-9
2027 Ford Super Duty Buyer's Guide (Every Model, Engine, & Package)

Here's everything that has changed for the latest model year.

By Brett Foote | 2026-05-27 16:17:28


VIEW MORE