Lotus Forum Lotus Forum
Go Back   LotusTalk - The Lotus Cars Community > Lotus Discussions > Electrical
User Name
Password
Register Home Forums Active Topics Gallery Search Today's Posts Mark Forums Read


       
Registered Members do not see the above ads. Please Register Today - It's quick and free!
Reply
 
LinkBack Thread Tools Search this Thread Display Modes
Old 09-29-2008, 08:03 PM   #1 (permalink)
Registered User
 
PhoneBoy's Avatar
 
Join Date: Mar 2006
Location: Lakeville, Minnesota
Posts: 1,016
Alarm PIN Hack

Alarm PIN Hack

I finally have something worthwhile to contribute to this forum! But first a little history..

Recently one of my fobs went through the wash I opened it up and dried it out. Unfortunately when reassembled, it wouldn’t mobilize the car. No big deal, I figured it just needed to be reprogrammed.. one problem, no PIN (dealer never gave it to me) .

I had several items in my “car” file that had 4-digit numbers that I thought might be the PIN. I tried them all to no avail.

One thing I did notice when attempting to enter the PIN was the tach light just kept flashing after entering the first digit. Figuring that this would likely give some indication if I made a correct entry, I repeated the procedure with different digits until I found the correct leading digit and the tell tale light went out. Moving on to the second digit and repeating this procedure I discovered the next PIN digit. Repeating several more times for the third and fourth digits I found the full PIN.

So.. if you cannot find your PIN, here is how to hack your alarm system PIN:

Be prepared to be locked out of the alarm PIN entry several times unless you are an incredibly lucky guesser (in that case, I suggest you buy a lottery ticket). You can still use working fobs when you are locked out – you just cannot continue hacking until you have a time out.

Finding the First Digit
1. With the system is immobilized (security tell tale flashing), Turn the ignition on and off 3 times within 7 seconds; the security tell tale in the tachometer will light for 3 seconds. NOTE: After several unsuccessful PIN entries the alarm system will lock out and the tachometer light will continue to flash. Simply wait 15 minutes and the system will reset so you can try again.
2. Immediately after the tell tale goes out, switch ON the ignition. After 1 to 9 tell tale flashes, turn the ignition off.
3. If the tell tale light stays off, then the number of tell tale flashes in step 2 is your first PIN digit. If the tell tale light continues to flash it is NOT your first PIN digit.
4. Turn the ignition off for 10 seconds and repeat steps 1 through 3 with remaining 1-9 digits until the first PIN digit is discovered (the tell tale light stays off).

Finding the Second Digit
5. Again, with the system is immobilized (security tell tale flashing), Turn the ignition on and off 3 times within 7 seconds; the security tell tale in the tachometer will light for 3 seconds.
6. Immediately after the tell tale goes out, switch ON the ignition. Count the number of security tell tale flashes until equal to the first number of the PIN, then turn the ignition OFF, then back ON again.
7. After 1 to 9 tell tale flashes, turn the ignition off.
8. If the tell tale light stays off, then the number of tell tale flashes in step 7 is your second PIN digit. If the tell tale light continues to flash it is NOT your second PIN digit.
9. Turn the ignition off for 10 seconds and repeat steps 5 through 7 with remaining 1-9 digits until the second PIN digit is discovered (the tell tale light stays off).

Finding the Third Digit
10. Again, with the system is immobilized (security tell tale flashing), Turn the ignition on and off 3 times within 7 seconds; the security tell tale in the tachometer will light for 3 seconds.
11. Immediately after the tell tale goes out, switch ON the ignition. Count the number of security tell tale flashes until equal to the first number of the PIN, then turn the ignition OFF, then back ON again.
12. Count the number of security tell tale flashes until equal to the second number of the PIN, then turn the ignition OFF, then back ON again.
13. After 1 to 9 tell tale flashes, turn the ignition off.
14. If the tell tale light stays off, then the number of tell tale flashes in step 13 is your third PIN digit. If the tell tale light continues to flash it is NOT your third PIN digit.
15. Turn the ignition off for 10 seconds and repeat steps 10 through 13 with remaining 1-9 digits until the third PIN digit is discovered (the tell tale light stays off).

Finding the Fourth Digit
16. Again, with the system is immobilized (security tell tale flashing), Turn the ignition on and off 3 times within 7 seconds; the security tell tale in the tachometer will light for 3 seconds.
17. Immediately after the tell tale goes out, switch ON the ignition. Count the number of security tell tale flashes until equal to the first number of the PIN, then turn the ignition OFF, then back ON again.
18. Count the number of security tell tale flashes until equal to the second number of the PIN, then turn the ignition OFF, then back ON again.
19. Count the number of security tell tale flashes until equal to the third number of the PIN, then turn the ignition OFF, then back ON again.
20. After 1 to 9 tell tale flashes, turn the ignition off.
21. If the tell tale light stays off, then the number of tell tale flashes in step 20 is your fourth PIN digit. If the tell tale light continues to flash it is NOT your fourth PIN digit.
22. Turn the ignition off for 10 seconds and repeat steps 16 through 20 with remaining 1-9 digits until the fourth PIN digit is discovered (the tell tale light stays off) and the system is mobilized.
__________________
'06 Lotus Elise - Solar Yellow, Touring, Hard Top, Star Shield, microMIRROR, Bootie, and ChaseCam
'07 Yamaha WR250F
'05 Dodge Grand Caravan CV
'04 Toyota Sienna
'02 Ford Explorer
'98 Mariah Shabah 180
PhoneBoy is offline   Reply With Quote
Old 09-29-2008, 08:37 PM   #2 (permalink)
Registered User
 
Chris Mackey's Avatar
 
Join Date: Jun 2007
Location: Austin, Texas
Posts: 1,939
You rock.
__________________
2006 Elise, Ardent Red, Black Pack, LSS wheels, shocks and springs. 55 Shot Zex nitrous kit.
Chris Mackey is offline   Reply With Quote
Old 09-29-2008, 09:01 PM   #3 (permalink)
3 years and counting
 
peck555's Avatar
 
Join Date: Sep 2004
Location: White Plains N.Y.
Posts: 2,358
Calling Keeper... we have an uberpost entry here.
__________________
Laser blue,biscuit, micro mirror, "Blue knob" ,HID lights,modded rear lights,rear badge,blue starter button, replaced speakers,perma grin,
Club111 The Sith lord of the LB's loyal henchman
peck555 is offline   Reply With Quote
Old 09-29-2008, 09:06 PM   #4 (permalink)
Registered User
 
lotusforsale's Avatar
 
Join Date: Nov 2007
Location: Maryland
Posts: 1,400
Images: 8
+1. Saved as a Favorite, and hardcopy printed and archived.
lotusforsale is offline   Reply With Quote
Old 09-29-2008, 10:20 PM   #5 (permalink)
Henry
 
habendanio's Avatar
 
Join Date: May 2006
Location: Fairfield CA
Posts: 624
So basically it should only takes like around ~36 attemps to get it right?
I know my pin and it took me like a hundred attempts to program a third fob??

Good job!
__________________
Henry
http://www.abendanio.com/albums/Lotus/
http://www.abendanio.com/wrecked.html
2005 Elise, AR, Touring, Sport, HT (RIP 10-6-08)
2005 Elise,Touring & Sports,Bordeaux Red Pearl
habendanio is online now   Reply With Quote
Old 09-30-2008, 08:13 AM   #6 (permalink)
Michigan Heavy Metal
 
ojars's Avatar
 
Join Date: Apr 2004
Location: Delray Beach, FL -- Louisville, CO
Posts: 164
No security at all!
__________________
Storm Titanium, Touring Package (Biscuit), Star Shield
01-Jun-05 delivery
mods -- removal of driver's sun shade, Multivex mirrors, CIPA 31000 rear view mirror + adaptor, battery tender
ojars is offline   Reply With Quote
Old 09-30-2008, 08:43 AM   #7 (permalink)
anglophile in exile
 
Aedo's Avatar
 
Join Date: Jan 2006
Location: Oz
Posts: 1,418
Images: 50
Quote:
Originally Posted by lotusforsale View Post
+1. Saved as a Favorite, and hardcopy printed and archived.
Getting the PIN and storing it safely before needing it is probably a better idea


Quote:
Originally Posted by ojars View Post
No security at all!
Except that you need the key, a lot of patience, plus ear plugs as the alarm will be going off!!
Aedo is online now   Reply With Quote
Old 09-30-2008, 08:50 AM   #8 (permalink)
Registered User
 
nockpoint's Avatar
 
Join Date: Nov 2006
Posts: 684
Pretty sneaky PhoneBoy. So in the end were any of your stored codes in your car file close to the actual pin? AKA did someone just record it wrong by 1 digit?
nockpoint is offline   Reply With Quote
Old 09-30-2008, 09:54 AM   #9 (permalink)
Registered User
 
macdady2424's Avatar
 
Join Date: Mar 2007
Location: Northern NJ
Posts: 937
Hmm... this might be my answer to programmnig my other fob. Maybe I have the wrong pin # and just can't get it programmed. I can use this as another check to see if I have the right pin I guess.
__________________
225 TTQC & 05 Elise
macdady2424 is offline   Reply With Quote
Old 09-30-2008, 10:45 AM   #10 (permalink)
So... Wanna Race?
 
njcu's Avatar
 
Join Date: May 2006
Location: Boerne, TX
Posts: 235
Images: 51
NICE HACK!
__________________
http://www.rafaelnieves.com - http://www.twitter.com/rnieves
2008 Infiniti EX35 - Slate Blue
2007 Craftsman DLT1500 - Red
2006 Lotus Elise - Solar Yellow
2006 Nissan Frontier - Charcoal
2004 Honda 250EX - Yellow (X2)
njcu is offline   Reply With Quote
Old 09-30-2008, 10:48 AM   #11 (permalink)
So... Wanna Race?
 
njcu's Avatar
 
Join Date: May 2006
Location: Boerne, TX
Posts: 235
Images: 51
Quote:
Originally Posted by Aedo View Post
Except that you need the key, a lot of patience, plus ear plugs as the alarm will be going off!!
Not a problem if you've towed the car to a garage and disconnected the horn. And you would have plenty of time to figure it out on your way to south America for that buyer who's just can't wait to have one.

lol not that I would know or anything... I just watch a lot of movies
__________________
http://www.rafaelnieves.com - http://www.twitter.com/rnieves
2008 Infiniti EX35 - Slate Blue
2007 Craftsman DLT1500 - Red
2006 Lotus Elise - Solar Yellow
2006 Nissan Frontier - Charcoal
2004 Honda 250EX - Yellow (X2)
njcu is offline   Reply With Quote
Old 09-30-2008, 10:48 AM   #12 (permalink)
Registered User
 
Crabman's Avatar
 
Join Date: Jan 2008
Location: Baltimore, MD
Posts: 40
I called my local Lotus dealer (not who sold it originally or who I bought it from) and gave them my VIN. They gave me the PIN in 2 minutes. Kind of defeats the purpose of the PIN, but it worked great for my needs.
__________________
'07 Exige S, Racing Green Metallic, Track & Touring Packs, Traction Control
Crabman is offline   Reply With Quote
Old 09-30-2008, 10:59 AM   #13 (permalink)
Registered User
 
PhoneBoy's Avatar
 
Join Date: Mar 2006
Location: Lakeville, Minnesota
Posts: 1,016
Quote:
Originally Posted by habendanio View Post
So basically it should only takes like around ~36 attemps to get it right?
I know my pin and it took me like a hundred attempts to program a third fob??
Good job!
Yup - it takes a while, especially when you have to often wait for the alarm lock out to expire. Other than the time waiting, the PIN can be hacked in under 30 minutes.

Quote:
Originally Posted by Aedo View Post
Getting the PIN and storing it safely before needing it is probably a better idea
Yup, unfortuanlty my dealer never provided it and I'm too cheap to pay for it

Quote:
Originally Posted by Aedo View Post
Except that you need the key, a lot of patience, plus ear plugs as the alarm will be going off!!
Yup - If you left the alarm armed, it's going to get loud.

Quote:
Originally Posted by nockpoint View Post
Pretty sneaky PhoneBoy. So in the end were any of your stored codes in your car file close to the actual pin? AKA did someone just record it wrong by 1 digit?
Nope. None of the numbers I had were even close to the PIN.

But now both my fobs work (even the one that went through the wash ) and I didn't have to spend a dime.
__________________
'06 Lotus Elise - Solar Yellow, Touring, Hard Top, Star Shield, microMIRROR, Bootie, and ChaseCam
'07 Yamaha WR250F
'05 Dodge Grand Caravan CV
'04 Toyota Sienna
'02 Ford Explorer
'98 Mariah Shabah 180
PhoneBoy is offline   Reply With Quote
Old 09-30-2008, 11:27 AM   #14 (permalink)
G-200 Driver
 
kestrel74's Avatar
 
Join Date: Jun 2004
Location: North of Detroit; Watkins Glen, NY
Posts: 7,296
I have a couple of social security numbers you could have fun with !!!
__________________
74 Europa Zetec TC Special 3614R
Elise #2292 / Chrome Orange !! / Starshield / Sachs suspension / RTDbrace / Uprights machined / Down Low rails / ...
"My daily driver does .85 Mach"
" I started flying when Sex was safe and Hang Gliding was dangerous "
BUY My Europa ! http://www.lotustalk.com/forums/f94/...pa-sale-43829/
kestrel74 is offline   Reply With Quote
Old 09-30-2008, 11:42 AM   #15 (permalink)
So... Wanna Race?
 
njcu's Avatar
 
Join Date: May 2006
Location: Boerne, TX
Posts: 235
Images: 51
hmm... Phone Phreaking?
__________________
http://www.rafaelnieves.com - http://www.twitter.com/rnieves
2008 Infiniti EX35 - Slate Blue
2007 Craftsman DLT1500 - Red
2006 Lotus Elise - Solar Yellow
2006 Nissan Frontier - Charcoal
2004 Honda 250EX - Yellow (X2)
njcu is offline   Reply With Quote
Old 09-30-2008, 12:09 PM   #16 (permalink)
Registered User
 
PhoneBoy's Avatar
 
Join Date: Mar 2006
Location: Lakeville, Minnesota
Posts: 1,016
Quote:
Originally Posted by njcu View Post
hmm... Phone Phreaking?
You'd be surprised how many people use "1111" or "1234" for voice mail passwords. I run into hacked phone systems quite often. Usually people looking for free calls (or hiding the call origination) to SE Asia, Middle East, and Central America.
__________________
'06 Lotus Elise - Solar Yellow, Touring, Hard Top, Star Shield, microMIRROR, Bootie, and ChaseCam
'07 Yamaha WR250F
'05 Dodge Grand Caravan CV
'04 Toyota Sienna
'02 Ford Explorer
'98 Mariah Shabah 180
PhoneBoy is offline   Reply With Quote
Old 09-30-2008, 12:10 PM   #17 (permalink)
Registered User
 
PhoneBoy's Avatar
 
Join Date: Mar 2006
Location: Lakeville, Minnesota
Posts: 1,016
Quote:
Originally Posted by kestrel74 View Post
I have a couple of social security numbers you could have fun with !!!
__________________
'06 Lotus Elise - Solar Yellow, Touring, Hard Top, Star Shield, microMIRROR, Bootie, and ChaseCam
'07 Yamaha WR250F
'05 Dodge Grand Caravan CV
'04 Toyota Sienna
'02 Ford Explorer
'98 Mariah Shabah 180
PhoneBoy is offline   Reply With Quote
Old 09-30-2008, 05:18 PM   #18 (permalink)
Moderator
 
TimMullen's Avatar
 
Join Date: Jun 2003
Location: Chantilly, VA
Posts: 10,688
Images: 19
Quote:
Originally Posted by PhoneBoy View Post
You'd be surprised how many people use "1111" or "1234" for voice mail passwords. I run into hacked phone systems quite often. Usually people looking for free calls (or hiding the call origination) to SE Asia, Middle East, and Central America.
I ran a telephone based time entry system that 13,000 people had to call into daily. I checked one time, and over 9,000 people had their password set to: "1234". I had to modify the software to block "easy passwords", repeat passwords, and require them to change them twice a year...
__________________
Tim Mullen --- There is no such thing as Touring suspension or Touring wheels.

I love being married. It's so great to find that one person that you want to annoy for the rest of your life. - Rita Rudner


Chantilly, VA http://members.cox.net/elans4/
05 Lotus Elise - Chrome Orange - No Touring - No LSS - No Hardtop - Lotus Driving Lights - Lotus "Chin Guards" - plain and simple.
94 Miata R Package - Black
72 Lotus Elan Sprint - Colorado Orange/Cirrus White
TimMullen is offline   Reply With Quote
Old 10-04-2008, 12:35 AM   #19 (permalink)
Oakley Witch King FTW
 
jriva's Avatar
 
Join Date: Sep 2005
Posts: 507
Hmm info we should have on the forums... i think not.
__________________
I Love this CAR!! GG/HT/T
jriva is offline   Reply With Quote
Old 10-04-2008, 11:15 AM   #20 (permalink)
Registered User
 
PhoneBoy's Avatar
 
Join Date: Mar 2006
Location: Lakeville, Minnesota
Posts: 1,016
Quote:
Originally Posted by jriva View Post
Hmm info we should have on the forums... i think not.
I gave this significant thought before originally posting. You need the correct key and many hours (because of the system lockouts) to hack the PIN. In addition, the alarm would be blaring if the system is armed.

If your car is stolen because I posted this, I'll chip in and help buy you a new one.
__________________
'06 Lotus Elise - Solar Yellow, Touring, Hard Top, Star Shield, microMIRROR, Bootie, and ChaseCam
'07 Yamaha WR250F
'05 Dodge Grand Caravan CV
'04 Toyota Sienna
'02 Ford Explorer
'98 Mariah Shabah 180
PhoneBoy is offline   Reply With Quote
Reply

  LotusTalk - The Lotus Cars Community > Lotus Discussions > Electrical



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -8. The time now is 11:03 PM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0