Skip to content

Latest commit

 

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

moto-display-re

Reverse-engineering writeup for a generic Chinese motorcycle CarPlay/Android Auto display with built-in dual-camera DVR — sold under "BOSSNEY" / "M553" / "REAKO SOUND" / no-name on AliExpress, and at least a dozen sibling brands. The goal is enabling split-screen simultaneous preview of both cameras (the stock launcher only shows one at a time even though both record concurrently).

M553 hero shot

TL;DR — is this repo worth your time?

Yes if you:

  • Have a similar device (Allwinner F133-B + Melis 4.0 + SK1.4 SDK platform — Aoocci C3/C7/BX, CPMC X6/B7/Z55B, ricoel C5/C7, CarpodGo, Linkifun MT11A, Carpuride, almost any unbranded F133 motorcycle CarPlay unit) and want a head-start on RE.
  • Want to see how to defeat PAIRIP DRM on a real-world Android app via surgical binary-AXML chunk deletion, without apktool b mangling resources.
  • Want a worked example of Sunninglink's "SUN2024" cloud-API auth (sign scheme, endpoint inventory, brute-force results, why the cloud-OTA route is dead for our SKU).
  • Are interested in the broader ODM-rebrand pool — there's a comparison of MStar Gemini / Mercury6, Allwinner F133 / IMAGEWTY, FullHan FH5701A firmware formats from competitor SKUs.

No if you:

  • Want a one-click custom firmware. There isn't one — extracting M553's stock firmware needs hardware (SOIC8 clip + CH341a programmer on the SPI flash chip). Sessions 1–7 ruled out every software path.
  • Want to flash this repo's contents to your device. Don't. Most of the firmware archives here are for different SoCs and would brick your unit.

What's in here

Path Contents
WRITEUP.md Full session-by-session narrative (sessions 1–7, 2026-04-29 → 2026-05-04). The "what we did and why" reference.
NEXT_SESSION.md Tactical pickup plan: UART-pad hunt, then SOIC8 SPI-flash dump, then Ghidra on init.axf.
RESEARCH_INDEX.md Deep-link map of every artifact. Read this first if you're looking for a specific file.
samples/device_photos/ Vendor product photos (hero, mounting angles, home menu, TPMS UI, EQ UI, camera close-ups, REAKO-rebrand evidence).
samples/probe_*/ UI screenshots from each phase of probing — debug-menu series (probe_phase3), factory-code attempts (probe_codes), 000000 Update Menu states (probe_update_menu), USB-C / SD-card probes.
samples/cam_a/PICT0000.jpg, samples/cam_b/PICT0000.jpg One still per camera channel — proves both cameras output independent frames (camera A and camera B at the same timestamp 2026/04/29 13:40:22).
research/sibling_apks/com.moto.amotocam/ The MotoNavi vendor app (base.apk + split_config.arm64_v8a.apk originals, plus base_full3_aligned.apk + split_aligned.apk — final patched + signed PAIRIP-bypassed installable). All AXML/drawable patcher scripts under scripts/. findings.md is the primary RE writeup.
research/sibling_apks/com.{lg,ligo,xy}.*/ 8 sibling motorcycle/dashcam apps for diff-mining (Roadcam V1+V3 SDK, Astro/dhc/dkomine/qrdash/superdash/tcam/aroadcamai). Each has findings.md or strings.txt.
research/sibling_firmware/ Competitor firmware archives — ricoel C5/C7 (MStar Gemini), CPMC X6/B7/Z55B (Allwinner LiveSuit + MStar M6), Aoocci C4 (FullHan FH5701A). All publicly redistributed from vendor download pages.
research/aoocci_c3plus_firmware/c3plus.img Aoocci C3 Plus stock firmware (Allwinner IMAGEWTY, 17 MB) — closest publicly-available F133 image.
research/b5300_re/B5300-reverse-engineering/ Git submodule pointing at dan-os/B5300-reverse-engineering — toolchain (Melis MINFS unpacker, unpack.sh, repack.sh, flash.sh) + sample SK1.4 SDK firmwares unpacked. Run git submodule update --init after cloning to fetch.
procedures/ Reproducible probe procedures (currently just 01-system-slot-probe.md — SD-card OTA scan timing).

To clone with everything:

git clone --recurse-submodules https://github.com/fuho/moto-display-re

Note: vendor APKs (originals + patched) and competitor firmware archives total ~600 MB. They're vendor-distributed binaries we obtained through normal purchase / vendor download pages, mirrored here for diff-mining and to make the writeup self-contained. RE for interoperability is a normal practice; if any vendor objects, they can email me.

Privacy: strings that would identify the personal environment — home Wi-Fi SSID, LAN IP, throwaway Mailinator handle, captured cloud-account access token — are replaced with placeholders (<HOME_WIFI>, 10.X.X.X, etc.) in every committed text file. The only password you'll find is the WPA-PSK 12345678 for the M553's own Wi-Fi AP, which is a vendor hardcode shared across this entire device family — not a personal credential.

The device

M553 home menu

5" landscape touchscreen (1024×600), waterproof bezel, handlebar mount, two bullet cameras, 2 wireless TPMS sensors, 64 GB microSD bundled.

Field Value How we know
SoC Allwinner F133-B (RISC-V C906, 64 MB DDR2 SiP) apps/init.axf symbol set in B5300 sample matches; 64 MB confirmed by debug-menu Memory Info
OS Melis 4.0 RTOS (Allwinner proprietary) Boot log structure on B5300 sample, MINFS rootfs, init.axf ELF format
Launcher SK1.4-8168V8.5-LMA-2511111456 Setup → Version screen (samples/probe_phase3/screenshots/500.jpg)
MCU FW SK_02_20251104-1159 Same Version screen — secondary microcontroller bridges F133 to power/buttons/cameras
BT MAC 41:42:00:00:1E:16 (LAA random per power-cycle) Version screen + BT advertising packets
BT_SET BT_20250617_1557 (dual-BT firmware: phone + helmet intercom simultaneously) Version screen
Display 1024×600 IPS, MIPI-DSI panel, Goodix touch Native screenshot resolution + B5300 boot log analog
Wi-Fi MAC OUI 5C:8E:8B (Realtek) ARP probe — confirms separate Wi-Fi/BT module (F133-B has no integrated wireless)
Camera topology Topology B (independent simultaneous capture) Both DVR slot folders DCIMA/ DCIMB receive aligned MJPEG clips at 1m/2m/5m intervals
Camera bridge TechPoint TP2804 multi-channel analog video decoder init.axf strings in B5300 sample reference tp2804; CSI lanes + AHD inputs
DVR ASIC Generalplus MJPEG codec, separate from F133 video pipeline
USB-C Power-only Phase 4 probe — no enumeration in HOST or SLAVE mode, even with debug toggle

Factory codes

Entry path: Setup → Factory Set → Input Password.

Code Effect Status
112345 Debug Mode (memory/screenshot/USB/touch/network/panel test) confirmed
123579 Self-Test (自检) — diagnostic mode confirmed
230762 Interface Select (界面选择) — UI / launcher skin chooser confirmed
001106 Silent state change — dismisses keypad on Factory Set page confirmed
000000 Update Menu — exposes MCU OTA path; tap button searches SD for update file confirmed
112233 rejected (INVALID) on this build tried
113266 rejected (INVALID) on this build — B5300 "Factory" code, so M553 has a customized Config.ini tried

The two rejected codes are documented in dan-os/B5300-reverse-engineering's apps/Config.ini as logoPassword=112233 / factoryPaswword=113266 (preserves the vendor's typo "Paswword"). They're configurable per-build, which is how we proved BOSSNEY customized the same SK1.4 SDK rather than rolling a different platform.

Hardware leads

  • Power connector: 4-pin, only 2 go to battery (12V + GND). The remaining 2 are very likely K1 / K2 momentary button inputs for installer-wired handlebar buttons (debug menu shows K1:0 / K2:0 counters with no physical button on the unit).
  • Two microSD slots, one each side. DVR slot (DCIMA/DCIMB MJPEG via Generalplus). System slot (USB-C side) is firmware-writable but passive on boot — used by the 000000 Update Menu.
  • No physical UART exposed externally, but B5300 has TX at 500k baud on a board pad. Best non-invasive next step is hunting through screw holes or seam.
  • The SPI flash chip (likely EN25QH128A / cFeon QH128A 16 MB SOIC-8) is the only known firmware extraction route. CH341a programmer + flashrom + SOIC8 clip.

How we approached this (and what dead-ended)

The investigation went through 7 sessions, each ruling out a class of approaches. The detailed log is in WRITEUP.md. Here's the map:

  1. Phase 1 — what does the device expose? USB-C → nothing (power-only). Wi-Fi AP → all 17+ probed TCP ports return RST when in CarPlay/AA mode. SD-card filenames → no auto-flash trigger. Conclusion: the device is hermetic from the outside.
  2. Phase 2 — frida-unpack a sibling app. com.lg.aroadcams "Roadcam" was packed but not PAIRIP-protected. frida-dexdump -U -f com.lg.aroadcams gave us the full Allwinner V1 + V3 IPCAM SDK — 8742 classes, the entire HTTP CGI vocabulary used by F133 dashcams. This established the "language" of ?custom=1&cmd=NNNN URLs. Re-probing M553 with this vocabulary still returned RST → the SDK isn't running on M553 in any operating mode.
  3. Phase 3 — Bluetooth pairing capture. Captured the BT handover from the phone's Wireless Link mode. Extracted the WPA-PSK 12345678 (hardcoded, same on every unit). Joined M553's Wi-Fi as a client, re-probed all known V1/V3 endpoints. Still RST. Conclusion: M553 never runs the V1/V3 server stack — the AP is just a CarPlay/AA passthrough.
  4. Phase 4 — defeat MotoNavi (the vendor app). com.moto.amotocam is the universal companion app for the entire F133 motorcycle CarPlay segment. It's PAIRIP-DRM'd. Built axml_delete_pairip.py that surgically removes the <activity> and <provider> chunks for com.pairip.licensecheck from the binary AndroidManifest, without running apktool b (which silently mangles resources.arsc). Got the app running on stock Android.
  5. Phase 5 — Sunninglink cloud API. With MotoNavi running and HTTP Toolkit MITM intercepting (after an android:debuggable="true" AXML patch to make user CAs trusted), reverse-engineered the entire Sunninglink backend: 32 endpoints, the request signing scheme sign = md5("SUN2024" + ts + uuid).lower(), the _8567 deviceInfo string format (8 semicolon-separated fields parsed by FirmwareInfo.getByString()). Filed _8567 brute-force attempts against app.sunninglink.com:9412/iotcam-api-server/firmwareUpgrade/checkUpdate — every variant returned data:null. Then bindDevice returned 10201 mac does not exist. M553's MAC is not in Sunninglink's pre-provisioned DB. The BOSSNEY supply chain didn't register units with the cloud. Cloud OTA is hard-closed.
  6. Phase 6 — sibling firmware diff-mining. Collected and binwalked competitor firmware (ricoel C5/C7 MStar Gemini, CPMC Z55B MStar M6, CPMC X6/B7 Allwinner LiveSuit, Aoocci C4 FullHan, Aoocci C3 Plus IMAGEWTY) hoping for a structurally similar M553 image. None match — different SoCs, different OEM customization, different display panels.
  7. Phase 7 — definitive platform ID. Found dan-os/B5300-reverse-engineering: Allwinner F133-B + Melis 4.0 + SK1.4 SDK with full toolchain (MINFS unpacker, sample firmwares). Boot log + symbol set + Config.ini structure all match M553. Pinned the platform conclusively. Located the dual-camera control surface in apps/init.axf (RISC-V ELF, 2 MB): cameraSwitch1Gpio, cameraSwitch2Gpio, CAvinInterface_SetAvChannel, CAvinCtrl_Open/Close, tp2804. Split-screen preview is achievable as a software patch to init.axf.

Key findings

  • ✅ Platform definitively identified. Allwinner F133-B + Melis 4.0 RTOS + SK1.4 SDK + BOSSNEY-customized Config.ini. Same family as dan-os/B5300.
  • ✅ Dual-camera control surface located in init.axf. Symbols + driver are present; modifying camera switching logic to drive both channels into framebuffer regions for compositing is the path to split-screen preview.
  • ✅ MotoNavi (com.moto.amotocam) fully RE'd. PAIRIP DRM defeated, TLS pinning bypassed, all 32 cloud endpoints documented, _8567 parser reverse-engineered.
  • ❌ Cloud OTA path is dead for M553 — bindDevice returns 10201 mac does not exist. The BOSSNEY supply chain didn't register units with Sunninglink.
  • ❌ Wi-Fi AP serves no DVR HTTP API in any operating mode. All 17+ probed TCP ports return RST. The V1/V3 SDK is in the launcher binary's siblings but not running on M553.
  • ❌ USB-C is power-only. D+/D− are not wired to the F133 USB controller. The "USB Mode HOST/SLAVE" debug toggle is vestigial.
  • ❌ The 000000 Update Menu exposes the MCU OTA path (UART1 to the MCU), not the application firmware. Even with a perfect ISPBOOT.BIN we can't flash the launcher via SD card.
  • ⚠️ Stock M553 firmware is not published anywhere. Only B5300 / F1026 samples exist publicly; those have a different display panel and different OEM customization (different boot logo, different brand strings, different camera GPIO assignments). Hardware extraction (SOIC8 clip on the SPI flash) is the only remaining route.

Reproducing the patched MotoNavi build

cd research/sibling_apks/com.moto.amotocam

# Originals (vendor-distributed)
ls base.apk split_config.arm64_v8a.apk

# Final patched + signed installable
ls base_full3_aligned.apk split_aligned.apk
adb install-multiple -r base_full3_aligned.apk split_aligned.apk

# Or rebuild from scratch:
bash scripts/build_patched_apk.sh

The script chains: axml_delete_pairip.py (removes PAIRIP <activity>/<provider>), axml_add_debuggable.py (sets android:debuggable="true" so user CAs are trusted at runtime), axml_export_activity.py (exposes activities to adb am start), drawable_patch.py (repoints missing drawable refs after the manifest edits), apktool rebuild + classes8.dex steal, zipalign, apksigner.

Next session

See NEXT_SESSION.md. Concrete first move: hunt for a UART TX pad through screw holes / seam without opening the case — confirm 500k baud boot log matches B5300. If that's reachable, we've cross-validated the platform without committing to disassembly. Otherwise, open the case → SOIC8 clip on the SPI flash chip → CH341a + flashrom dump → unpack via the B5300 toolchain → diff init.axf against the SK1.4 sample → patch in Ghidra (RV32 LE).

License

MIT for the scripts and writeups in this repository. Vendor APKs and firmware archives included in research/ are vendor-copyrighted; mirrored here for non-commercial reverse-engineering, interoperability research, and security analysis only. If you're a vendor and want something removed, email me.

References

About

Reverse engineering: Allwinner F133-B + Melis 4.0 motorcycle CarPlay/AA display with dual-camera DVR. Multi-session writeup, PAIRIP-defeat scripts, MotoNavi cloud RE.

Resources

Stars

5 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages