{"id":13681206,"url":"https://github.com/FlUxIuS/V2GInjector","last_synced_at":"2025-04-30T03:30:43.585Z","repository":{"id":44463243,"uuid":"186106644","full_name":"FlUxIuS/V2GInjector","owner":"FlUxIuS","description":"V2GInjector - Tool to intrude a V2G PowerLine network, but also to capture and inject V2G packets ","archived":false,"fork":false,"pushed_at":"2024-12-19T10:09:03.000Z","size":152,"stargazers_count":123,"open_issues_count":2,"forks_count":30,"subscribers_count":11,"default_branch":"master","last_synced_at":"2024-12-19T11:21:46.000Z","etag":null,"topics":["car","hacking","homeplug","plc","powerline","v2g"],"latest_commit_sha":null,"homepage":"","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"gpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/FlUxIuS.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2019-05-11T08:19:50.000Z","updated_at":"2024-12-19T10:09:08.000Z","dependencies_parsed_at":"2024-08-02T13:20:10.237Z","dependency_job_id":null,"html_url":"https://github.com/FlUxIuS/V2GInjector","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/FlUxIuS%2FV2GInjector","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/FlUxIuS%2FV2GInjector/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/FlUxIuS%2FV2GInjector/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/FlUxIuS%2FV2GInjector/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/FlUxIuS","download_url":"https://codeload.github.com/FlUxIuS/V2GInjector/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":251635026,"owners_count":21619127,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["car","hacking","homeplug","plc","powerline","v2g"],"created_at":"2024-08-02T13:01:27.789Z","updated_at":"2025-04-30T03:30:42.774Z","avatar_url":"https://github.com/FlUxIuS.png","language":"Python","funding_links":[],"categories":["Tools and Resources","Python"],"sub_categories":["ISO 15118"],"readme":"![V2GInjector Logo](/images/logo.png)\n\nTool to penetrate V2G networks, monitor and inject packets to attack electric cars and charging stations.\n\n## Publications\n\n- Researches paper: https://www.sstic.org/media/SSTIC2019/SSTIC-actes/v2g_injector_playing_with_electric_cars_and_chargi/SSTIC2019-Article-v2g_injector_playing_with_electric_cars_and_charging_stations_via_powerline-dudek.pdf\n- Slides from SSTIC 2019: https://www.sstic.org/media/SSTIC2019/SSTIC-actes/v2g_injector_playing_with_electric_cars_and_chargi/SSTIC2019-Slides-v2g_injector_playing_with_electric_cars_and_charging_stations_via_powerline-dudek.pdf\n- Video recording from SSTIC 2019 (in French): https://static.sstic.org/videos2019/1080p/SSTIC_2019-06-07_P06.mp4\n\nSupport: contact the [Penthertz company](https://penthertz.com/) which is the owner of the project.\n\n## Dependencies\n\n### Software \n\n- Python 2, and Python 3\n- Scapy\n- Colorama for Python\n- V2Gdecoder in submodules, that is already compiled and available here: https://github.com/FlUxIuS/V2Gdecoder/releases\n- HomePlugPWN that is provided in submodules\n\nTo install Python dependencies, use `pip install -r requirements.txt` (or `pip3` as needed).\n\nSubmodules can be fetched as follows:\n```\n$ git submodule update --init --recursive\n```\n\n### Hardware\n\nAny devices using the PowerLine-Communication Qualcomm Atheros 7k (QCA7k) series baseband (tested on QCA7420 and QCA7500). \nFor wallplugs, next to the HomePlug logo, there is a text descripting plug's interoperability including HomePlug GP.\n\nThe tool has been tested with following devices:\n\n* dLAN Green PHY eval board EU II (~150€)\n* PLC Stamp Micro 2 Evaluation Board (Home Automation) (~300€)\n* Devolo 1200+ (~50€) -\u003e to rework if you want to bind it to CP lines -\u003e dangerous to get access on TR+/- lines /!\\\n* Working on QCA7420 chips, but attenuation must be forced on EVSE side for the SLAC procedure\n* TODO: test other devices with a QCA7k PLC baseband.\n\n## Connections\n\nThe PowerLine Communication device could be plugged in three different ways:\n\n* plugging it with an IEC 61851 or any compatible connector for your targeted car (that could be found in Alibaba)\n* with an interception cable between the charging station and the car\n* or using simply use a default PLC wallplug with a QCA7k connected to the same shared electrical network as the charging station(s) and the car(s). \n\n## How to use it\n\nThe tool can be started with the following interpreter as follows:\n```\n$ python V2GInjector\n\nooooo  oooo  ooooooo     ooooooo8  \n 888    88 o88     888 o888    88  \n  888  88        o888  888    oooo \n   88888      o888   o 888o    88  \n    888    o8888oooo88  888ooo888  \nooooo             o88                         o8                        \n 888  oo oooooo  oooo  ooooooooo8  ooooooo  o888oo ooooooo  oo oooooo   \n 888   888   888  888 888oooooo8 888     888 888 888     888 888    888 \n 888   888   888  888 888        888         888 888     888 888        \no888o o888o o888o 888   88oooo888  88ooo888   888o 88ooo88  o888o       \n                 o88                                                    \n\n~\u003e\u003e\u003e\n```\n\nTo collect data automatically, two methods are provided by Network class object:\n* `Network().pcap(\u003cpcap file\u003e)`\n* `Network().sniff(iface=\u003cinterface\u003e)`\n\n### Decoding V2G packet\n\nFirst, the V2Gdecoder service must be running as follows:\n```\n$ java -jar V2Gdecoder.jar -w\n```\n\nThen, when calling `pcap()` or `sniff()` methods as follows, EXI data are simply decoded:\n```\n~\u003e\u003e\u003e n=Network()\n~\u003e\u003e\u003e n.pcap(\"/tmp/emulated.pcapng\")\n\u003cCookedLinux  pkttype=unicast lladdrtype=0x304 lladdrlen=6 src='' proto=0x86dd |\u003cIPv6  version=6 tc=0 fl=36603 plen=76 nh=TCP hlim=64 src=fe80::3e2a:b4ff:3e5f:1a4 dst=fe80::3e2a:b4ff:3e5f:1a4 |\u003cTCP  sport=54054 dport=62887 seq=1646944081 ack=4294522924 dataofs=8 reserved=0 flags=PA window=342 chksum=0xb60d urgptr=0 options=[('NOP', None), ('NOP', None), ('Timestamp', (1430435299, 1430435274))] |\u003cV2GTP  Version=1 Invers=254 PayloadType=EXI PayloadLen=36 Payload='\\x80\\x00\\xeb\\xab\\x93q\\xd3K\\x9by\\xd1\\x89\\xa9\\x89\\x89\\xc1\\xd1\\x91\\xd1\\x91\\x81\\x89\\x99\\xd2k\\x9b:#+0\\x02\\x00\\x00(\\x00@' |\u003e\u003e\u003e\u003e\n[Decoded packet]\n\u003c?xml version=\"1.0\" encoding=\"UTF-8\"?\u003e\u003cns4:supportedAppProtocolReq xmlns:ns4=\"urn:iso:15118:2:2010:AppProtocol\" xmlns:xsi=\"http://www.w3.org/2001/XMLSchema-instance\" xmlns:ns3=\"http://www.w3.org/2001/XMLSchema\"\u003e\u003cAppProtocol\u003e\u003cProtocolNamespace\u003eurn:iso:15118:2:2013:MsgDef\u003c/ProtocolNamespace\u003e\u003cVersionNumberMajor\u003e2\u003c/VersionNumberMajor\u003e\u003cVersionNumberMinor\u003e0\u003c/VersionNumberMinor\u003e\u003cSchemaID\u003e10\u003c/SchemaID\u003e\u003cPriority\u003e1\u003c/Priority\u003e\u003c/AppProtocol\u003e\u003c/ns4:supportedAppProtocolReq\u003e\n\n\u003cCookedLinux  pkttype=unicast lladdrtype=0x304 lladdrlen=6 src='' proto=0x86dd |\u003cIPv6  version=6 tc=0 fl=218843 plen=44 nh=TCP hlim=64 src=fe80::3e2a:b4ff:3e5f:1a4 dst=fe80::3e2a:b4ff:3e5f:1a4 |\u003cTCP  sport=62887 dport=54054 seq=4294522924 ack=1646944125 dataofs=8 reserved=0 flags=PA window=342 chksum=0xb5ed urgptr=0 options=[('NOP', None), ('NOP', None), ('Timestamp', (1430435378, 1430435299))] |\u003cV2GTP  Version=1 Invers=254 PayloadType=EXI PayloadLen=4 Payload='\\x80@\\x02\\x80' |\u003e\u003e\u003e\u003e\n[Decoded packet]\n\u003c?xml version=\"1.0\" encoding=\"UTF-8\"?\u003e\u003cns4:supportedAppProtocolRes xmlns:ns4=\"urn:iso:15118:2:2010:AppProtocol\" xmlns:xsi=\"http://www.w3.org/2001/XMLSchema-instance\" xmlns:ns3=\"http://www.w3.org/2001/XMLSchema\"\u003e\u003cResponseCode\u003eOK_SuccessfulNegotiation\u003c/ResponseCode\u003e\u003cSchemaID\u003e10\u003c/SchemaID\u003e\u003c/ns4:supportedAppProtocolRes\u003e\n\n\u003cCookedLinux  pkttype=unicast lladdrtype=0x304 lladdrlen=6 src='' proto=0x86dd |\u003cIPv6  version=6 tc=0 fl=36603 plen=61 nh=TCP hlim=64 src=fe80::3e2a:b4ff:3e5f:1a4 dst=fe80::3e2a:b4ff:3e5f:1a4 |\u003cTCP  sport=54054 dport=62887 seq=1646944125 ack=4294522936 dataofs=8 reserved=0 flags=PA window=342 chksum=0xb5fe urgptr=0 options=[('NOP', None), ('NOP', None), ('Timestamp', (1430435406, 1430435378))] |\u003cV2GTP  Version=1 Invers=254 PayloadType=EXI PayloadLen=21 Payload=\"\\x80\\x98\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x11\\xd0\\x18pn\\xd5\\xac'X\\x00\" |\u003e\u003e\u003e\u003e\n[Decoded packet]\n\u003c?xml version=\"1.0\" encoding=\"UTF-8\"?\u003e\u003cns7:V2G_Message xmlns:ns7=\"urn:iso:15118:2:2013:MsgDef\" xmlns:xsi=\"http://www.w3.org/2001/XMLSchema-instance\" xmlns:ns3=\"http://www.w3.org/2001/XMLSchema\" xmlns:ns4=\"http://www.w3.org/2000/09/xmldsig#\" xmlns:ns5=\"urn:iso:15118:2:2013:MsgBody\" xmlns:ns6=\"urn:iso:15118:2:2013:MsgDataTypes\" xmlns:ns8=\"urn:iso:15118:2:2013:MsgHeader\"\u003e\u003cns7:Header\u003e\u003cns8:SessionID\u003e0000000000000000\u003c/ns8:SessionID\u003e\u003c/ns7:Header\u003e\u003cns7:Body\u003e\u003cns5:SessionSetupReq\u003e\u003cns5:EVCCID\u003e1C1BB56B09D6\u003c/ns5:EVCCID\u003e\u003c/ns5:SessionSetupReq\u003e\u003c/ns7:Body\u003e\u003c/ns7:V2G_Message\u003e\n\n\u003cCookedLinux  pkttype=unicast lladdrtype=0x304 lladdrlen=6 src='' proto=0x86dd |\u003cIPv6  version=6 tc=0 fl=218843 plen=69 nh=TCP hlim=64 src=fe80::3e2a:b4ff:3e5f:1a4 dst=fe80::3e2a:b4ff:3e5f:1a4 |\u003cTCP  sport=62887 dport=54054 seq=4294522936 ack=1646944154 dataofs=8 reserved=0 flags=PA window=342 chksum=0xb606 urgptr=0 options=[('NOP', None), ('NOP', None), ('Timestamp', (1430435411, 1430435406))] |\u003cV2GTP  Version=1 Invers=254 PayloadType=EXI PayloadLen=29 Payload=\"\\x80\\x98\\x02'\\xe5\\xc2N\\x07\\xc8h\\xae\\xd1\\xe0 )\\x15YM\\x15%\\x10\\xb4\\xc0\\x1c\\xfb\\x1e\\x1c\\xc0\\xa0\" |\u003e\u003e\u003e\u003e\n[Decoded packet]\n\u003c?xml version=\"1.0\" encoding=\"UTF-8\"?\u003e\u003cns7:V2G_Message xmlns:ns7=\"urn:iso:15118:2:2013:MsgDef\" xmlns:xsi=\"http://www.w3.org/2001/XMLSchema-instance\" xmlns:ns3=\"http://www.w3.org/2001/XMLSchema\" xmlns:ns4=\"http://www.w3.org/2000/09/xmldsig#\" xmlns:ns5=\"urn:iso:15118:2:2013:MsgBody\" xmlns:ns6=\"urn:iso:15118:2:2013:MsgDataTypes\" xmlns:ns8=\"urn:iso:15118:2:2013:MsgHeader\"\u003e\u003cns7:Header\u003e\u003cns8:SessionID\u003e9F9709381F21A2BB\u003c/ns8:SessionID\u003e\u003c/ns7:Header\u003e\u003cns7:Body\u003e\u003cns5:SessionSetupRes\u003e\u003cns5:ResponseCode\u003eOK_NewSessionEstablished\u003c/ns5:ResponseCode\u003e\u003cns5:EVSEID\u003eEVSEID-0\u003c/ns5:EVSEID\u003e\u003cns5:EVSETimeStamp\u003e1557933159\u003c/ns5:EVSETimeStamp\u003e\u003c/ns5:SessionSetupRes\u003e\u003c/ns7:Body\u003e\u003c/ns7:V2G_Message\u003e\n\n\u003cCookedLinux  pkttype=unicast lladdrtype=0x304 lladdrlen=6 src='' proto=0x86dd |\u003cIPv6  version=6 tc=0 fl=36603 plen=53 nh=TCP hlim=64 src=fe80::3e2a:b4ff:3e5f:1a4 dst=fe80::3e2a:b4ff:3e5f:1a4 |\u003cTCP  sport=54054 dport=62887 seq=1646944154 ack=4294522973 dataofs=8 reserved=0 flags=PA window=342 chksum=0xb5f6 urgptr=0 options=[('NOP', None), ('NOP', None), ('Timestamp', (1430435414, 1430435411))] |\u003cV2GTP  Version=1 Invers=254 PayloadType=EXI PayloadLen=13 Payload=\"\\x80\\x98\\x02'\\xe5\\xc2N\\x07\\xc8h\\xae\\xd1\\xb8\" |\u003e\u003e\u003e\u003e\n[Decoded packet]\n\u003c?xml version=\"1.0\" encoding=\"UTF-8\"?\u003e\u003cns7:V2G_Message xmlns:ns7=\"urn:iso:15118:2:2013:MsgDef\" xmlns:xsi=\"http://www.w3.org/2001/XMLSchema-instance\" xmlns:ns3=\"http://www.w3.org/2001/XMLSchema\" xmlns:ns4=\"http://www.w3.org/2000/09/xmldsig#\" xmlns:ns5=\"urn:iso:15118:2:2013:MsgBody\" xmlns:ns6=\"urn:iso:15118:2:2013:MsgDataTypes\" xmlns:ns8=\"urn:iso:15118:2:2013:MsgHeader\"\u003e\u003cns7:Header\u003e\u003cns8:SessionID\u003e9F9709381F21A2BB\u003c/ns8:SessionID\u003e\u003c/ns7:Header\u003e\u003cns7:Body\u003e\u003cns5:ServiceDiscoveryReq/\u003e\u003c/ns7:Body\u003e\u003c/ns7:V2G_Message\u003e\n\n\u003cCookedLinux  pkttype=unicast lladdrtype=0x304 lladdrlen=6 src='' proto=0x86dd |\u003cIPv6  version=6 tc=0 fl=218843 plen=83 nh=TCP hlim=64 src=fe80::3e2a:b4ff:3e5f:1a4 dst=fe80::3e2a:b4ff:3e5f:1a4 |\u003cTCP  sport=62887 dport=54054 seq=4294522973 ack=1646944175 dataofs=8 reserved=0 flags=PA window=342 chksum=0xb614 urgptr=0 options=[('NOP', None), ('NOP', None), ('Timestamp', (1430435419, 1430435414))] |\u003cV2GTP  Version=1 Invers=254 PayloadType=EXI PayloadLen=43 Payload=\"\\x80\\x98\\x02'\\xe5\\xc2N\\x07\\xc8h\\xae\\xd1\\xc0\\x01 \\x04\\x05QU\\x88\\x18\\xda\\x18\\\\\\x99\\xda[\\x99\\xc8\\n\\x10P\\xcb\\xd1\\x10\\xca@@ \\x01\\x03\\x08H\" |\u003e\u003e\u003e\u003e\n[Decoded packet]\n\u003c?xml version=\"1.0\" encoding=\"UTF-8\"?\u003e\u003cns7:V2G_Message xmlns:ns7=\"urn:iso:15118:2:2013:MsgDef\" xmlns:xsi=\"http://www.w3.org/2001/XMLSchema-instance\" xmlns:ns3=\"http://www.w3.org/2001/XMLSchema\" xmlns:ns4=\"http://www.w3.org/2000/09/xmldsig#\" xmlns:ns5=\"urn:iso:15118:2:2013:MsgBody\" xmlns:ns6=\"urn:iso:15118:2:2013:MsgDataTypes\" xmlns:ns8=\"urn:iso:15118:2:2013:MsgHeader\"\u003e\u003cns7:Header\u003e\u003cns8:SessionID\u003e9F9709381F21A2BB\u003c/ns8:SessionID\u003e\u003c/ns7:Header\u003e\u003cns7:Body\u003e\u003cns5:ServiceDiscoveryRes\u003e\u003cns5:ResponseCode\u003eOK\u003c/ns5:ResponseCode\u003e\u003cns5:PaymentOptionList\u003e\u003cns6:PaymentOption\u003eExternalPayment\u003c/ns6:PaymentOption\u003e\u003c/ns5:PaymentOptionList\u003e\u003cns5:ChargeService\u003e\u003cns6:ServiceID\u003e1\u003c/ns6:ServiceID\u003e\u003cns6:ServiceName\u003eEV charging (AC/DC)\u003c/ns6:ServiceName\u003e\u003cns6:ServiceCategory\u003eEVCharging\u003c/ns6:ServiceCategory\u003e\u003cns6:FreeService\u003efalse\u003c/ns6:FreeService\u003e\u003cns6:SupportedEnergyTransferMode\u003e\u003cns6:EnergyTransferMode\u003eAC_three_phase_core\u003c/ns6:EnergyTransferMode\u003e\u003cns6:EnergyTransferMode\u003eAC_single_phase_core\u003c/ns6:EnergyTransferMode\u003e\u003cns6:EnergyTransferMode\u003eDC_core\u003c/ns6:EnergyTransferMode\u003e\u003cns6:EnergyTransferMode\u003eDC_extended\u003c/ns6:EnergyTransferMode\u003e\u003cns6:EnergyTransferMode\u003eDC_combo_core\u003c/ns6:EnergyTransferMode\u003e\u003c/ns6:SupportedEnergyTransferMode\u003e\u003c/ns5:ChargeService\u003e\u003c/ns5:ServiceDiscoveryRes\u003e\u003c/ns7:Body\u003e\u003c/ns7:V2G_Message\u003e\n[...]\n```\n\n### Collected HPGP keys\n\nCollected HomePlug GP keys are directly show when calling `pcap()` or `sniff()`:\n```\n~\u003e\u003e\u003e n=Network()\n~\u003e\u003e\u003e n.sniff(iface=\"eth0\")\n[...]\n[New HPGP network spotted!]\n- EVSEID: '\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00'\n- NetID: '\\xae\\x20\\x00\\xff\\x82\\x02\\x00'\n- NMK: '\\x43F\\xc8\\xaeT\\xbf\\xefs\\x01\\x84\\x94\\xf8\\xc3\\x17'\n- EVID: '\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xff'\n- RunID: '\\xef\\x34C\\xf5E\\xe0\\xa6\\x01'\n```\nThese data are stored in the `Network().hpgp` attribute.\n\nThis can then be used to configure your PLC device's PIB by dumping it with `plctool` and using `slac\\pev` tool and profile file.\n\n### Generate V2G packets\n\nAs it uses Scapy and extension layers, a V2G packet can be built using the same logic as Scapy:\n```\n~\u003e\u003e\u003e ether = Ether()\n~\u003e\u003e\u003e ip = IPv6(dst=\"fe80::3e2a:b4ff:3e5f:1a4\")\n~\u003e\u003e\u003e tcp = TCP(sport=6666, dport=54054, flags=24)\n~\u003e\u003e\u003e v2g=V2GTP()\n~\u003e\u003e\u003e packet = ether/ip/tcp/v2g\n~\u003e\u003e\u003e packet\n\u003cEther  type=0x86dd |\u003cIPv6  nh=TCP dst=fe80::3e2a:b4ff:3e5f:1a4 |\u003cTCP  sport=6666 dport=54054 flags=PA |\u003cV2GTP  |\u003e\u003e\u003e\u003e\n```\nBut we need to push an EXI encoded payload in the V2GTP layer:\n```\n~\u003e\u003e\u003e packet[V2GTP].show()\n###[ V2GTP ]### \n  Version   = 1\n  Invers    = 254\n  PayloadType= EXI\n  PayloadLen= 0\n  Payload   = ''\n```\nTo do that, as for the `analyse()` method call by `sniff()` and `pcap()` which uses `decodeEXI()` function to decode EXI data, a encoder function `encodeEXI` also exists to compress the XML payload to EXI:\n```\n~\u003e\u003e\u003e xml = '\u003c?xml version=\"1.0\" encoding=\"UTF-8\"?\u003e\u003cns7:V2G_Message xmlns:ns7=\"urn:iso:15118:2:2013:MsgDef\" xmlns:xsi=\"http://www.w3.org/2001/XMLSchema-instance\" xmlns:ns3=\"http://www.w3.org/2001/XMLSchema\" xmlns:ns4=\"http://www.w3.org/2000/09/xmldsig#\" xmlns:ns5=\"urn:iso:15118:2:2013:MsgBody\" xmlns:ns6=\"urn:iso:15118:2:2013:MsgDataTypes\" xmlns:ns8=\"urn:iso:15118:2:2013:MsgHeader\"\u003e\u003cns7:Header\u003e\u003cns8:SessionID\u003e0000000000000000\u003c/ns8:SessionID\u003e\u003c/ns7:Header\u003e\u003cns7:Body\u003e\u003cns5:SessionSetupReq\u003e\u003cns5:EVCCID\u003e1C1BB56B09D6\u003c/ns5:EVCCID\u003e\u003c/ns5:SessionSetupReq\u003e\u003c/ns7:Body\u003e\u003c/ns7:V2G_Message\u003e'\n~\u003e\u003e\u003e encoded_xml=encodeEXI(xml)\n~\u003e\u003e\u003e encoded_xml\nu'809802000000000000000011D018706ED5AC275800'\n```\nThen, the encoded/compressed data in EXI can be pushed in the V2GTP payload as follows:\n```\n~\u003e\u003e\u003e packet.Payload=encoded_xml\n~\u003e\u003e\u003e packet\n\u003cEther  type=0x86dd |\u003cIPv6  nh=TCP dst=fe80::3e2a:b4ff:3e5f:1a4 |\u003cTCP  sport=6666 dport=54054 flags=PA |\u003cV2GTP  Payload='809802000000000000000011D018706ED5AC275800' |\u003e\u003e\u003e\u003e\n```\nTo finish, the packet can be sent to the target using Scapy's `sendp()` function.\n\n## Further development\n\n* Make a native Python EXI encoder/decoder -\u003e very long task to do, or try using the C++ EXI Wrapper in Python\n* Add other wrappers\n* Add some pre-developed attacking functions during interception\n* More docs\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FFlUxIuS%2FV2GInjector","html_url":"https://awesome.ecosyste.ms/projects/github.com%2FFlUxIuS%2FV2GInjector","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FFlUxIuS%2FV2GInjector/lists"}