protocol for WL Heli V911-s

More
15 Sep 2018 14:42 #70918 by mtx63
protocol for WL Heli V911-s was created by mtx63
I am looking for a protocol to control the WL Heli V911-s with the Devo.

Please Log in or Create an account to join the conversation.

More
15 Sep 2018 23:31 - 15 Sep 2018 23:34 #70924 by planger
Replied by planger on topic protocol for WL Heli V911-s
Have you tried all available protocols and sub protocols?
From what I can see it should use flysky...
Last edit: 15 Sep 2018 23:34 by planger.

Please Log in or Create an account to join the conversation.

More
16 Sep 2018 06:25 #70927 by mtx63
Replied by mtx63 on topic protocol for WL Heli V911-s
Yes I have.
There is no mode 1 transmitter. For this reason I want to fly with the Devo transmitter.

www.rcgroups.com/forums/showthread.php?3101508-Wl-v911s

Please Log in or Create an account to join the conversation.

More
16 Sep 2018 08:02 #70929 by aMax
Replied by aMax on topic protocol for WL Heli V911-s
Do yourself a favor and start with helis and quads on mode 2 (mode 3 is also suitable for pilots who want to have the throttle on the right stick), mode 1 & 4 is not good on these.
It will be more easy to have AIL & ELV on one stick.
After four decades on mode1 I switched for this reason nearly five years ago to mode 2 and since last year I even fly my planes on this mode.

Devo7e, TaranisQ X7, 4in1 MM, Futaba FC18plusV3.1/DFT/FLD-02

Please Log in or Create an account to join the conversation.

More
16 Sep 2018 11:15 #70930 by planger
Replied by planger on topic protocol for WL Heli V911-s
I've looked at the mentioned RC groups link and 1 guy states that he has tried all the protocols without luck. They are using an all in one pan163cx RF chip so no spi dump.
If you are willing to send me the TX and heli I can try an over the air attack.
Pascal

Please Log in or Create an account to join the conversation.

  • goebish
  • goebish's Avatar
  • Away
  • I Void Warranties
More
16 Sep 2018 11:51 #70931 by goebish
Replied by goebish on topic protocol for WL Heli V911-s

Please Log in or Create an account to join the conversation.

More
16 Sep 2018 13:24 #70932 by mtx63
Replied by mtx63 on topic protocol for WL Heli V911-s
Hello planger.. Thanks for the offer. My home country is Germany.
geobish ..gwoo8.. no function.

Dieter

Please Log in or Create an account to join the conversation.

More
17 Sep 2018 14:56 #70949 by planger
Replied by planger on topic protocol for WL Heli V911-s
Both goebish and I are located in France so not so far for shipping.
goebish in his precedent post was explaining that he has already used the attack over the air to reverse engineer the protcol gw008 (it was not for you to try), so he has first hand experience. On my side, I've also done some lately but only using a nrf as the receiver.
You are the one to choose if you want and where you want to send it.
Pascal

Please Log in or Create an account to join the conversation.

More
17 Sep 2018 17:12 #70953 by mtx63
Replied by mtx63 on topic protocol for WL Heli V911-s
Thank you for your offer. By DHL, the heli is fast in France.
I'm going to send him to Geobish.
Please send me the address by PM.

dieter

Please Log in or Create an account to join the conversation.

  • goebish
  • goebish's Avatar
  • Away
  • I Void Warranties
More
17 Sep 2018 17:13 #70954 by goebish
Replied by goebish on topic protocol for WL Heli V911-s
Better send it to Pascal because I won't be home until the end of the month ;)

Please Log in or Create an account to join the conversation.

More
17 Sep 2018 17:18 #70955 by mtx63
Replied by mtx63 on topic protocol for WL Heli V911-s
ok..to Pascal..

Please Log in or Create an account to join the conversation.

  • BirdBarber
  • BirdBarber's Avatar
  • Offline
  • Hummingbird Assassin
More
18 Sep 2018 23:03 - 19 Sep 2018 03:52 #70976 by BirdBarber
Replied by BirdBarber on topic protocol for WL Heli V911-s

planger wrote: I've looked at the mentioned RC groups link and 1 guy states that he has tried all the protocols without luck. They are using an all in one pan163cx RF chip so no spi dump.
If you are willing to send me the TX and heli I can try an over the air attack.
Pascal


I think that's me. I tried all protocols and most sub options and parameters except for enabling telemetry.
Here are the testing details: www.rcgroups.com/forums/showpost.php?p=40174852&postcount=135

I live in the northwest US and have a TX and heli available for snooping by any established Deviation developer in the US. I will be out of town off and on for the next few weeks, so it may take me a couple of days to respond.

Attached is a photo of the V911S TX main board. There are no components on the back side.
Attachments:
Last edit: 19 Sep 2018 03:52 by BirdBarber.

Please Log in or Create an account to join the conversation.

More
26 Sep 2018 17:20 #71043 by planger
Replied by planger on topic protocol for WL Heli V911-s
Just to give some news:
  • Since it's a PAN chip and PAN is manufacturing the XN297, I first looked if the packets have the XN297 SYNC/MAC which is not the case :-(
  • I then tried sniffing with the NRF24L01 all frequencies/all rates with sync 0x55/0xAA but I couldn't correlate anything from the noise... :-(
  • I'm now trying to look at the packets from a SDR device.
    • This is my first time in this area so I need to learn.
    • The bind time is really small so I've looked for packets only for normal mode. I've settled on one frequency 2426GHz to study the packet within the hopping.
    • You can see where I am with the attached picture.
Next steps:
  • I'll go back to the NRF and focus on this specific frequency now that I have one to focus on.
  • Try to decode the packets within the SDR.
Attachments:

Please Log in or Create an account to join the conversation.

  • goebish
  • goebish's Avatar
  • Away
  • I Void Warranties
More
30 Sep 2018 09:47 #71099 by goebish
Replied by goebish on topic protocol for WL Heli V911-s
The RF core should be xn297 compatible, bg has sold some E011 FC boards with a pan163cx instead of xn297+stm32f03 and it's compatible with the bayang protocol ( www.rcgroups.com/forums/showpost.php?p=39219748&postcount=2036 , www.rcgroups.com/forums/showpost.php?p=39230143&postcount=2048 ).
Can you share a raw SDR dump ?
(please give the parameters of the capture)

Please Log in or Create an account to join the conversation.

More
01 Oct 2018 09:08 #71119 by SeByDocKy
Replied by SeByDocKy on topic protocol for WL Heli V911-s
I am surprized they changed the RFchip for the new 911S.... now it's XN297 based .... :( ...
Hope guru's here will unbrick this one fast :)

Please Log in or Create an account to join the conversation.

  • goebish
  • goebish's Avatar
  • Away
  • I Void Warranties
More
01 Oct 2018 09:40 - 01 Oct 2018 10:57 #71121 by goebish
Replied by goebish on topic protocol for WL Heli V911-s
Pascal, can you try with gnuradio and the .grc I shared some time ago (which SDR device are you using ?):
www.deviationtx.com/forum/protocol-devel...gw008?start=40#59368
It should work for both xn297 & xn297l as they don't exactly have the same preamble (0xC710F55 vs 0x710F55).
Last edit: 01 Oct 2018 10:57 by goebish.

Please Log in or Create an account to join the conversation.

More
02 Nov 2018 23:54 #71527 by captjack01
Replied by captjack01 on topic protocol for WL Heli V911-s
Howdy
Anyone make any headway on this one , or is it looking grim?

Please Log in or Create an account to join the conversation.

More
03 Nov 2018 16:16 - 03 Nov 2018 16:16 #71531 by planger
Replied by planger on topic protocol for WL Heli V911-s
Haven't spent enough time on it yet. Please be patient.
Pascal
Last edit: 03 Nov 2018 16:16 by planger.

Please Log in or Create an account to join the conversation.

More
05 Nov 2018 19:34 #71554 by planger
Replied by planger on topic protocol for WL Heli V911-s
I finally had some proper time to look at it and I've made small progress today.
It looks like it's a xn297l. At least the signature looks like it from decoding the first bytes of the payload (71 0F 55) through SDR.
I haven't looked at all at the payload content yet (ran out of time), just an outside view for now.
It's running @250Kbps and send something like 24 bytes including CRC after the sync word (to be verified).
The bind info seems to be sent on RF channel 35 at a really high rate 2.5ms first then 5ms, why not...
The freq hopping pattern changes at each power up. It uses 8 channels spaced by 5 except the first one which is 4 (strange...). It's hopping based on a table top->bottom, bottom->top, top ->bottom even then odd,...
Pascal

Please Log in or Create an account to join the conversation.

  • goebish
  • goebish's Avatar
  • Away
  • I Void Warranties
More
06 Nov 2018 10:27 #71565 by goebish
Replied by goebish on topic protocol for WL Heli V911-s
Welcome to the world of retrieving information out of thin air :)
You didn't tell which SDR device and software you're using, sorry, I'm curious.

Please Log in or Create an account to join the conversation.

Time to create page: 0.312 seconds
Powered by Kunena Forum