Skip to content

Nokia XS-010X-R mfginfo CRC algorythm #486

Description

@Troll338cz

I really would be interested what the checksum is / how the checksum of the first block is calculated.

CRC for factory data is identical algorithm to one found already, CIG nvram stuff is in cig-misc.ko, decompiled here

Function nvram_nand_eeprom_valid_check() even prints the correct lenth needed for CRC to work, being 236 bytes, verified bellow.

# Sample sourced from https://github.com/YuukiJapanTech/CA8271x/blob/main/mtd/NOKIA_XS-010X-R/mtd10.bin
import struct

mfginfo0_256 = bytes.fromhex("314b342d30303030312d313330363235323030383034343330314853463036413231383136324700000094f7175d5ce494f7175d5ce700010000000000000000000000000000000000000000000000000000000000000000011a010200000000414c434c414c434cfdb614a433544e303036363641424141303142564d50443030425241585330313058520000006f6e742e7a000000000000000000c0a86401ffffff00c0a86401000000006f6e7400000000006f6e74000000000000020000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000fdd62392")
crc_expected = struct.unpack("I", mfginfo0_256[252:])[0]

def crc32_bzip2(data, poly, init, xorout):
    crc = init & 0xFFFFFFFF
    for byte in data:
        crc ^= (byte << 24) & 0xFFFFFFFF
        for _ in range(8):
            if crc & 0x80000000:
                crc = ((crc << 1) ^ poly) & 0xFFFFFFFF
            else:
                crc = (crc << 1) & 0xFFFFFFFF
    return crc ^ xorout

crc_out = crc32_bzip2(mfginfo0_256[0:236], 0x04C11DB7, 0xFFFFFFFF, 0xFFFFFFFF)

print(f"From file: {crc_expected} | Calculated: {crc_out} | Match: {crc_expected == crc_out}")

Worth a try to test CIG backdoor packet to see if ATE/CATS2388 logins will be enbled on telnet with full shell.

Also if you are interested in getting partial Cortina SDK to obtain sources for kernel / ca_ne and other modules i have a copy willing to share.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions