diff --git a/_ont/ont-comtrend-grg-4284.md b/_ont/ont-comtrend-grg-4284.md index 3d6579e8..36b7e4a4 100644 --- a/_ont/ont-comtrend-grg-4284.md +++ b/_ont/ont-comtrend-grg-4284.md @@ -70,7 +70,7 @@ Simple change with a hex editor can be done to enable full shell, inside /lib/li Then add /bin/ash to /etc/shells to enable normal shell. -Binary patch is required to prevent `/bin/startup` from reseting ME 256 and 257 parameters on reboot. +In case device contains locked default configuration `/etc/config_default.xml` can be modified to undo any unwanted restrictions. ## Flashing new firmware diff --git a/_ont/ont-nokia-g-010s-q.md b/_ont/ont-nokia-g-010s-q.md index 9e769683..ffab5672 100644 --- a/_ont/ont-nokia-g-010s-q.md +++ b/_ont/ont-nokia-g-010s-q.md @@ -16,7 +16,7 @@ alias: CIG G-97S | ODM Product Code | G-97S | | Chipset | RTL9601CI | | Flash | 16 MB (Macronix MX25L12835F) | -| RAM | | +| RAM | 32 MB | | System | | | HSGMII | | | Optics | | @@ -33,10 +33,17 @@ alias: CIG G-97S {% include_relative ont-nokia-useful-command.md %} +## Enable full telnet shell +Full telnet and secondary factory IP can be enabled by sending [Nokia magic packet](https://github.com/YuukiJapanTech/CA8271x/blob/main/doc/rootShell.md#nokia-xs-010x-r). + +If factory mode is enabled sucessfully second IP `192.168.188.1/24` will be assinged to SFP LAN interface. + +Newly available login credentials will be `ATE` / `CATS2388` and `ONTUSER` / `sha256 of SN formated as GPONa1b2c3d4` with GponCLI shell. + # Miscellaneous Links - [Nokia G-010S-Q](https://github.com/Anime4000/RTL960x/issues/52) -- [CUG G-97S DataSheet](https://www.cigtech.com/wp-content/uploads/2018/09/G-97S_DataSheet_V2.pdf) +- [CIG G-97S DataSheet](https://web.archive.org/web/20230803034001/https://www.cigtech.com/wp-content/uploads/2018/09/G-97S_DataSheet_V2.pdf) - [MIB file parser](https://github.com/nanomad/nokia-ont-mib-parser) for NOKIA's GPON ONTs (*helps you parsing the .mib file located in `/mnt/rwdir`*) diff --git a/_ont/ont-sercomm-fg1000r.md b/_ont/ont-sercomm-fg1000r.md index 96420466..784c67d4 100644 --- a/_ont/ont-sercomm-fg1000r.md +++ b/_ont/ont-sercomm-fg1000r.md @@ -7,29 +7,29 @@ parent: Sercomm # Hardware Specifications -| | | -| --------------- | ----------------------- | -| Vendor/Brand | Sercomm | -| Model | FG1000R | -| ODM | ✅ | -| Chipset | RTL9602C | -| Flash | 128MB (MXIC MX35LF1GE4AB) | -| RAM | 64MB | -| CPU | | -| CPU Clock | 625 MHz | -| Bootloader | U-Boot RSDK 2011.12.NA-svn5 | -| Load addr | | -| 2.5GBaseT | ✅ | -| PHY Ethernet | Realtek RTL8221B | -| Optics | LC/APC | -| IP address | 192.168.1.1/24 | +| | | +| --------------- | ------------------------------ | +| Vendor/Brand | Sercomm | +| Model | FG1000R | +| ODM | ✅ | +| Chipset | RTL9602C | +| Flash | 128MB (MXIC MX35LF1GE4AB) | +| RAM | 64MB | +| CPU | | +| CPU Clock | 625 MHz | +| Bootloader | U-Boot RSDK 2011.12.NA-svn5 | +| Load addr | | +| 2.5GBaseT | ✅ | +| PHY Ethernet | Realtek RTL8221B | +| Optics | LC/APC | +| IP address | 192.168.1.1/24 | | Web Gui | ✅, User: Tech Password: ftth@! | -| SSH | | -| Telnet | | -| Serial | ✅, only TX | -| Serial baud | 115200 | -| Serial encoding | 8-N-1 | -| Form Factor | ONT | +| SSH | | +| Telnet | | +| Serial | ✅, only TX | +| Serial baud | 115200 | +| Serial encoding | 8-N-1 | +| Form Factor | ONT | {% include image.html file="fg1000r_rear.jpg" alt="Sercomm FG1000R" caption="Sercomm FG1000R rear" %} diff --git a/_ont/ont-sercomm-fgs202.md b/_ont/ont-sercomm-fgs202.md index f976c72f..54267ca7 100644 --- a/_ont/ont-sercomm-fgs202.md +++ b/_ont/ont-sercomm-fgs202.md @@ -159,9 +159,10 @@ FGS202:/# show i2c (ASCII view added for readability) 000001d0: 3230 3231 3132 0000 5343 4f4d 4647 5332 202112..SCOMFGS2 000001e0: 3032 3131 3200 ff00 0000 1000 0000 0000 02112........... 000001f0: 0000 0000 0000 0000 0000 0000 0000 0020 ............... +``` It can also be read and written using an external I2C reader. -``` + # Advanced settings @@ -181,14 +182,18 @@ Simple U-Boot-style storage `key=value\0` padded by 0xFF, after modification, a ```py from zlib import crc32 -wholeflash = open("FGS202.bin", "rb").read() # Full SPI dump -ubootenv = wholeflash[262144:262144+65536] # 0x40000-0x5FFFF -factoryenv = wholeflash[327680:327680+65536] # 0x50000-0x6FFFF -ecosenv = wholeflash[393216:393216+65536] # 0x60000-0x7FFFF +wholeflash = open("FGS202.bin", "rb").read() # Full SPI dump +ubootenv = wholeflash[262144:262144+65536] # 0x40000-0x50000 +factoryenv = wholeflash[327680:327680+65536] # 0x50000-0x60000 +ecosenv = wholeflash[393216:393216+65536] # 0x60000-0x70000 +ubootenv2 = wholeflash[262144:262144+65536] # 0x80000-0x90000 +ecosenv2 = wholeflash[8323072:8323072+65536] # 0x7F0000-0x800000 print(f'U-Boot\n| CRC: {ubootenv[0:4].hex()} | Version {ubootenv[4:5]} | New CRC: {crc32(ubootenv[5:]):08x} ') print(f'Factory\n| CRC: {factoryenv[0:4].hex()} | Version {factoryenv[4:5]} | New CRC: {crc32(factoryenv[5:]):08x} ') print(f'eCos\n| CRC: {ecosenv[0:4].hex()} | Version {ecosenv[4:5]} | New CRC: {crc32(ecosenv[5:]):08x} ') +print(f'U-Boot backup\n| CRC: {ubootenv2[0:4].hex()} | Version {ubootenv2[4:5]} | New CRC: {crc32(ubootenv2[5:]):08x}') +print(f'eCos backup\n| CRC: {ecosenv2[0:4].hex()} | Version {ecosenv2[4:5]} | New CRC: {crc32(ecosenv2[5:]):08x}') ``` ## Decrypting "encrypt_data" variable from flash @@ -221,10 +226,14 @@ At boot time, this variable is read by the modified U-Boot and waits for [sercom Due to an uninitialized SFP EEPROM, a simple SFP-to-Ethernet converter is required. -The input for sercomm-recovery tool must be a complete dump of complete flash memory, the client writes only the Image0 and Image1 regions, and the rest is skipped (so a failed write will drop you back into recovery). +The input for sercomm-recovery tool must be a complete dump of flash memory, the client writes only the Image0 and Image1 regions, and the rest is skipped (so a failed write will drop you back into recovery). It is not possible to exit this mode until the write operation completes or the environment settings are manually reset to 0. +## Boot and update log +{% include serial_dump.html file="fgs202-boot.txt" alt="eCos boot" title="eCos boot" %} + +{% include serial_dump.html file="fgs202-flash.txt" alt="Update with sercomm-recovery" title="Update with sercomm-recovery" %} # Hardware Modding diff --git a/_ont/ont-tenda-hg1-patch.md b/_ont/ont-tenda-hg1-patch.md new file mode 100644 index 00000000..88675364 --- /dev/null +++ b/_ont/ont-tenda-hg1-patch.md @@ -0,0 +1,143 @@ +--- +title: OMCI reset patch +has_children: false +layout: default +parent: Tenda HG1 +--- + +## Premade patch for V1.0.2 +This patch is for /bin/startup with MD5 `5e6db6934d662b5cef2f4c74b8cdf639` + +```diff +1073c1073 +< 00004300: 0040 2821 8f82 81c0 0040 c821 0000 0000 .@(!.....@.!.... +--- +> 00004300: 0040 2821 8f82 81c0 0040 c821 0320 f809 .@(!.....@.!. .. +1205c1205 +< 00004b40: 0000 0000 0000 0000 8fdc 0010 27c2 0030 ............'..0 +--- +> 00004b40: 0320 f809 0000 0000 8fdc 0010 27c2 0030 . ..........'..0 +1207c1207 +< 00004b60: 0000 0000 0000 0000 8fdc 0010 2404 0008 ............$... +--- +> 00004b60: 0320 f809 0000 0000 8fdc 0010 2404 0008 . ..........$... +1256c1256 +< 00004e70: 0040 c821 0000 0000 0000 0000 8fdc 0010 .@.!............ +--- +> 00004e70: 0040 c821 0320 f809 0000 0000 8fdc 0010 .@.!. .......... +1258c1258 +< 00004e90: 0040 c821 0000 0000 0000 0000 8fdc 0010 .@.!............ +--- +> 00004e90: 0040 c821 0320 f809 0000 0000 8fdc 0010 .@.!. .......... +1262c1262 +< 00004ed0: 0040 2821 8f82 81c0 0040 c821 0000 0000 .@(!.....@.!.... +--- +> 00004ed0: 0040 2821 8f82 81c0 0040 c821 0320 f809 .@(!.....@.!. .. +1264c1264 +< 00004ef0: 0040 2821 8f82 81c0 0040 c821 0000 0000 .@(!.....@.!.... +--- +> 00004ef0: 0040 2821 8f82 81c0 0040 c821 0320 f809 .@(!.....@.!. .. +``` + +Resulting patched file should have MD5 of `99aaaece6b7ed5a9ee0a075443d98943` + +Add the following to `/etc/version.sh`, `rootfs_extracted/etc/scripts/chk_swver_2.sh` and `rootfs_extracted/etc/scripts/chk_swver.sh` to skip script checks by creating empty file inside JFFS2 config. + +```diff +> if [ -f /var/config/skip_version ]; then +> echo "Version adaptation bypass" +> exit 0 +> fi +``` + +## Tweaked default configuration + +Enable telnet on LAN, disable http and telnet on WAN. + +SSH and FTP components are removed from firmware and can't be enabled. + +```diff +< +< +< +< +< +< +< +< +< +< +< +< +< +< +< +< +< +< +< +< +< +< +< +< +< +< +< +< +< +< +< +< +< +< +< +< +< +< +< +< +--- +> +> +> +> +> +> +> +> +> +> +> +> +> +> +> +> +> +> +> +> +> +> +> +> +> +> +> +> +> +> +> +> +> +> +> +> +> +> +> +> +``` + + diff --git a/_ont/ont-tenda-hg1.md b/_ont/ont-tenda-hg1.md index d6a87fbd..3e17b7af 100644 --- a/_ont/ont-tenda-hg1.md +++ b/_ont/ont-tenda-hg1.md @@ -1,6 +1,6 @@ --- title: Tenda HG1 -has_children: false +has_children: true layout: default parent: Tenda --- @@ -39,7 +39,7 @@ parent: Tenda ## List of software versions -- V1.7.1 +- V1.0.2 # List of partitions @@ -80,6 +80,14 @@ Device has a hidden page `http://192.168.1.1/tddeviceinfo.asp` for configuring O OMCI equipment ID (ME 257) and OMCI hardware version (ME 256) are hardcoded into `/etc/version.sh` and `/bin/startup` requiring a firmware patch to change. +## WAN backdoor account +There are hardcoded credentials for WAN user, it's recommended WWW and Telnet are disabled on and this second password changed. + +```xml + + +``` + # Miscellaneous Links - [Hacking RTL960x](https://github.com/Anime4000/RTL960x) diff --git a/_ont/ont-zyxel-pmg5100-t0.md b/_ont/ont-zyxel-pmg5100-t0.md index b453d990..446eb50f 100644 --- a/_ont/ont-zyxel-pmg5100-t0.md +++ b/_ont/ont-zyxel-pmg5100-t0.md @@ -30,3 +30,32 @@ parent: Zyxel {% include image.html file="zyxel-pmg5100\port.jpg" alt="PM5100-T0" caption="PM5100-T0" %} {% include image.html file="zyxel-pmg5100\back-board.jpg" alt="PM5100-T0 Teardown" caption="PM5100-T0 Teardown" %} {% include image.html file="zyxel-pmg5100\front-board.jpg" alt="PM5100-T0 Teardown" caption="PM5100-T0 Teardown" %} + +## List of software versions +- V5.42-ACEQ-0b10 (Cetin) +- V5.42-ACBF.1.1-C0 (Zyxel) + +## Unlock bootloader and root shell +Full linux shell can be accessed if the current firmware allows it, this ONT has per-device password burned into flash. + +Depending on Z-Loader version bootloader access might be protected with supervisors password until `EngDebugFlag` is enabled. + +Default passwords can be obtained with normal ATEN/ATSE unlock process. + +```sh +# Generate unlock seed +ATSE PM5100-T0 +# Generate ATEN key with https://github.com/cjdelisle/ATENv3 +ATEN 1,RESULT +# Allow nvram write +ATBT 1 +# Write EngDebugFlag to nvram +ATSB +# Dump passwords from nvram +ATCK +``` + +If network upgrade isn't disabled by ISP branding [zyeng](https://github.com/bmork/zyxel-hacks) tool can be used to write EngDebugFlag it over the network. + +When both methods fail only option is to desolder the SPI flash and locate passwords inside U-Boot ENV. + diff --git a/_ont/serial_dump/fgs202-boot.txt b/_ont/serial_dump/fgs202-boot.txt new file mode 100644 index 00000000..93da8fdb --- /dev/null +++ b/_ont/serial_dump/fgs202-boot.txt @@ -0,0 +1,66 @@ +ROM: V1.1.4 +ROM: CFG 0x00000006 +ROM: SFLASH-4 +hw fuse format 1 + + +U-Boot 2011.12-lantiq-gpon-1.2.20.1-svn20 (Aug 10 2015 - 13:49:58), Build: falcon_sfp + +Board: SFP +DRAM: internal: 1 MiB +Now running in RAM - U-Boot at: 9f2c4000 +SF: Detected MX25L6405D with page size 64 KiB, total 8 MiB +Chip: FALCON-SR (A22) +Bootmode: 0x06 +Reset cause: Power-On Reset +CPU Clock: 400 MHz +Done! +Net: SGMII, SERDES [PRIME] + +Type run flash_nfs to mount root filesystem over NFS + +SF: Detected MX25L6405D with page size 64 KiB, total 8 MiB +SF: Detected MX25L6405D with page size 64 KiB, total 8 MiB +SF: Detected MX25L6405D with page size 64 KiB, total 8 MiB +active_img 0, committed_img 1 +pid_addr 0x2a0ce8 +dbSign Addr: 0x9f200208 +imgNum: 1 +img 0: start addr: 0x100000, length: 0x1a0ce8 +checksum: 0xa39a73eb +crc32 result: 0xa39a73eb +check sum OK +name c_img +value 1 +name activate_image +value 0 +Erasing SPI flash...Writing to SPI flash...done +SF: Detected MX25L6405D with page size 64 KiB, total 8 MiB + +*************************************************** + Sercomm Boot Version 2.0.2.0 + +*************************************************** +No sc dl flag. +gpio_id:8 no found +Entering Firmware : Everything is OK. +No sc dl flag. +## Starting application at 0x10000000 ... +Overall used memory: 150616 +Available packet buffer: 769984 (llt min 6401, llt max 18432) +Init flash support +M25PXX : Init device 'Macronix 64 Mbit' with JEDEC ID 0xC22017/0x0000. +Found flash at 0x00000000-0x007fffff +Flash bank with 128 sectors, sector size is 65536 bytes +Find valid uboot environment in env_off and env_end_off +Machine: Falcon SFP Stick (SFP) +Set image#0 version: SCOMFGS202112 +Set image#1 version: SCOMFGS202112 +Successfully stored environment to 0x7f0000 +Successfully stored environment to 0x60000 +Image start address: 0xb0100000 +Image 0: 0xB0100000 - valid +Image 1: 0xB0480000 - valid +ONT Boot up #1 image +FALC(tm) ON Optic Driver, version 7.4.0.0 (c) Copyright 2015, Lantiq Beteiligungs-GmbH & Co. KG +FALC(tm) ON Base Driver, Version 7.3.3.0 (c) Copyright 2015, Lantiq Beteiligungs-GmbH & Co. KG diff --git a/_ont/serial_dump/fgs202-flash.txt b/_ont/serial_dump/fgs202-flash.txt new file mode 100644 index 00000000..5b3b3fa3 --- /dev/null +++ b/_ont/serial_dump/fgs202-flash.txt @@ -0,0 +1,82 @@ +ROM: V1.1.4 +ROM: CFG 0x00000006 +ROM: SFLASH-4 +hw fuse format 1 + + +U-Boot 2011.12-lantiq-gpon-1.2.20.1-svn20 (Aug 10 2015 - 13:49:58), Build: falcon_sfp + +Board: SFP +DRAM: internal: 1 MiB +Now running in RAM - U-Boot at: 9f2c4000 +SF: Detected MX25L6405D with page size 64 KiB, total 8 MiB +Chip: FALCON-SR (A22) +Bootmode: 0x06 +Reset cause: Power-On Reset +CPU Clock: 400 MHz +Done! +Net: SGMII, SERDES [PRIME] + +Type run flash_nfs to mount root filesystem over NFS + +SF: Detected MX25L6405D with page size 64 KiB, total 8 MiB +SF: Detected MX25L6405D with page size 64 KiB, total 8 MiB +SF: Detected MX25L6405D with page size 64 KiB, total 8 MiB +active_img 0, committed_img 1 +pid_addr 0x2a1a48 +dbSign Addr: 0x9f200208 +imgNum: 1 +img 0: start addr: 0x100000, length: 0x1a1a48 +checksum: 0x1124fafc +crc32 result: 0x1124fafc +check sum OK +name c_img +value 1 +name activate_image +value 0 +Erasing SPI flash...Writing to SPI flash...done +SF: Detected MX25L6405D with page size 64 KiB, total 8 MiB + +*************************************************** + Sercomm Boot Version 2.0.2.0 + +*************************************************** +get sc dl flag. +DEBUG_INF:=================================================== +DEBUG_INF:Sercomm Upgrade(Module Ver 2.14.02.24) Start! +DEBUG_INF:=================================================== + +0x0000: 00 c0 02 12 35 79 +Error: SGMII TBI not in sync! +Error: SGMII TBI not in sync! +SERDES: Link Speed is 1000 Mbps - FULL duplex connection +DEBUG_INF:ecc bytes 0 +PCBASN = R.BNN72O048E +DEBUG_INF:normal upgrade. +DEBUG_INF:Erase Done. +DEBUG_INF:Program Starting. +DEBUG_INF:Verify Starting. +DEBUG_INF:=================================================== +DEBUG_INF:= Stats of this Sercomm Upgrade is as below: = +DEBUG_INF:=================================================== +DEBUG_INF:Following Partitions NOT Erased, +DEBUG_INF: Index Name Offset Length +DEBUG_INF: 0 u-boot 0 40000 +DEBUG_INF: 1 u-boot-env 40000 10000 +DEBUG_INF: 2 factory_data 50000 10000 +DEBUG_INF: 3 fw_config 60000 10000 +DEBUG_INF: 4 sercomm_log 70000 10000 +DEBUG_INF: 5 u-boot-env-second 80000 10000 +DEBUG_INF: 10 image1_reserve 7f0000 10000 +DEBUG_INF:--------------------------------------------------- +DEBUG_INF:Following Partitions Updated, +DEBUG_INF: Index Name Bad Cnt Dropped +DEBUG_INF: 6, reserved_area 0 0 +DEBUG_INF: 7, image0 0 0 +DEBUG_INF: 8, image0_reserve 0 0 +DEBUG_INF: 9, image1 0 0 +DEBUG_INF:=================================================== +name sc_dl +value ff +Erasing SPI flash...Writing to SPI flash...done + diff --git a/_ont_xgs/ont-comtrend-grg-4362-patch.md b/_ont_xgs/ont-comtrend-grg-4362-patch.md new file mode 100644 index 00000000..65b8dd58 --- /dev/null +++ b/_ont_xgs/ont-comtrend-grg-4362-patch.md @@ -0,0 +1,34 @@ +--- +title: OMCI unlock patch +has_children: false +layout: default +parent: Comtrend GRG-4362 +--- + +## Premade patch for CTN-1.0.8b16 +This patch is for /bin/startup from firmware CTN-1.0.8b16 with MD5 `a5d76a686ebb6683e25d2e11d004a707` + +```diff +< 00005a30: 1f00 0071 8002 0054 0000 00b0 0120 3b91 ...q...T..... ;. +< 00005a40: e0fa 8052 1bf4 ff97 0000 00b0 0120 3b91 ...R......... ;. +< 00005a50: 00fb 8052 17f4 ff97 0000 00b0 0120 3b91 ...R......... ;. +< 00005a60: 80fb 8052 13f4 ff97 0000 00b0 0120 3b91 ...R......... ;. +< 00005a70: e0fb 8052 0ff4 ff97 0100 8052 4000 8052 ...R.......R@..R +< 00005a80: b0f4 ff97 02fd ff97 1f00 0071 cb17 0054 ...........q...T +--- +> 00005a30: 1f00 0071 8002 0054 1f20 03d5 1f20 03d5 ...q...T. ... .. +> 00005a40: 1f20 03d5 1f20 03d5 1f20 03d5 1f20 03d5 . ... ... ... .. +> 00005a50: 1f20 03d5 1f20 03d5 1f20 03d5 1f20 03d5 . ... ... ... .. +> 00005a60: 1f20 03d5 1f20 03d5 1f20 03d5 1f20 03d5 . ... ... ... .. +> 00005a70: 1f20 03d5 1f20 03d5 1f20 03d5 1f20 03d5 . ... ... ... .. +> 00005a80: 1f20 03d5 02fd ff97 1f00 0071 cb17 0054 . .........q...T +``` + +Resulting patched file should have MD5 of `e58fb01c2952e2dc053e8fa8638e45f7` + +## Mannual patch for other versions + +To patch other versions of startup, locate function that prints "startELan fail, plz check!" and delete the calls to mib_set with NOPs (0xd503201f) + +{% include image.html file="grg-4362/mib_patch.jpg" alt="Patch ASM" caption="Patch ASM" %} + diff --git a/_ont_xgs/ont-comtrend-grg-4362.md b/_ont_xgs/ont-comtrend-grg-4362.md index e550f8da..e7eb979b 100644 --- a/_ont_xgs/ont-comtrend-grg-4362.md +++ b/_ont_xgs/ont-comtrend-grg-4362.md @@ -1,6 +1,6 @@ --- title: Comtrend GRG-4362 -has_children: false +has_children: true layout: default parent: Comtrend --- @@ -20,7 +20,7 @@ parent: Comtrend | PHY Ethernet | RTL8261B | | Optics | SC/APC (SEMTECH GN28L96) | | IP address | 192.168.1.1/24 | -| Web Gui | ✅ user `root`, password `root` | +| Web Gui | ✅ | | SSH | ✅ | | Telnet | ✅ | | FTP | ✅, Download only | @@ -31,9 +31,9 @@ parent: Comtrend # External/Internal Photo -{% include image.html file="comtrend_grg-4362_teardown_1.jpg" alt="Comtrend GRG-4362 Top Cover" caption="Comtrend GRG-4362 Top Cover" %} -{% include image.html file="comtrend_grg-4362_teardown_2.jpg" alt="Comtrend GRG-4362 Bottom Cover" caption="Comtrend GRG-4362 Bottom Cover" %} -{% include image.html file="comtrend_grg-4362_teardown_3.jpg" alt="Comtrend GRG-4362 PCB" caption="Comtrend GRG-4362 PCB" %} +{% include image.html file="grg-4362/comtrend_grg-4362_teardown_1.jpg" alt="Comtrend GRG-4362 Top Cover" caption="Comtrend GRG-4362 Top Cover" %} +{% include image.html file="grg-4362/comtrend_grg-4362_teardown_2.jpg" alt="Comtrend GRG-4362 Bottom Cover" caption="Comtrend GRG-4362 Bottom Cover" %} +{% include image.html file="grg-4362/comtrend_grg-4362_teardown_3.jpg" alt="Comtrend GRG-4362 PCB" caption="Comtrend GRG-4362 PCB" %} ## Hardware Revisions @@ -303,11 +303,12 @@ mkdir /var/tmp mkdir /var/config mount -t ubifs ubi0:ubi_Config /var/config/ -# Read device login +# To regain access from locked ISP firmware: +# 1. Read device login flash get SUSER_NAME flash get SUSER_PASSWORD -# Unblock ACL rules +# 2. Unblock ACL rules flash set ACL_IP_TBL.0.any 0 flash set ACL_IP_TBL.0.telnet 1 flash set ACL_IP_TBL.0.web 1 @@ -321,7 +322,7 @@ flash set ACL_IP_TBL.1.https 0 flash set ACL_IP_TBL.1.ssh 0 flash set ACL_IP_TBL.1.icmp 0 -# Enable full shell instead of CLI +# 3. Enable full shell instead of CLI # This script runs too early in boot process, delay was needed to get /var into right state cat < /var/config/run_customized_sdk.sh #!/bin/sh @@ -345,8 +346,9 @@ Simple change with a hex editor can be done to enable full shell, inside /lib/li Then add /bin/ash to /etc/shells to enable normal shell. -Binary patch is required to prevent `/bin/startup` from reseting ME 256 and 257 parameters on reboot. +In case device contains locked default configuration `/etc/config_default.xml` can be modified to undo any unwanted restrictions. +Binary patch is required to prevent `/bin/startup` from reseting ME 256 and 257 parameters on reboot. ## Flashing new firmware - U-Boot diff --git a/_ont_xgs/ont-kaon-pm1191-fwpatch.md b/_ont_xgs/ont-kaon-pm1191-fwpatch.md new file mode 100644 index 00000000..80e3034c --- /dev/null +++ b/_ont_xgs/ont-kaon-pm1191-fwpatch.md @@ -0,0 +1,66 @@ +--- +title: Extracting and repacking the rootfs +has_children: false +layout: default +parent: KAON PM1191 +--- + +{% include alert.html content="Make sure you run all commands as root, otherwise you might get a damaged rootfs image" alert="Warning" icon="svg-warning" color="red" %} + +## Unpacking SquashFS from UBI volume + +```sh +# ubireader_extract_images rootfs1.img +# cp ubifs-root/X/squashfs_ubi/img-X_vol-squashfs_ubi.ubifs . +# as root... +unsquashfs -d rootfs_extracted/ img-X_vol-squashfs_ubi.ubifs +``` + +## Repacking SquashFS +```sh +rm -v new_squashfs.img +mksquashfs rootfs_extracted/ new_squashfs.img -comp xz -b 131072 -always-use-fragments -no-recovery -noappend +``` + +## Repacking UBI volume + +Firstly create ubinize.cfg with volume settings: + +```ini +[squashfs_ubi] +mode=ubi +image=new_squashfs.img +vol_id=0 +vol_type=static +vol_name=squashfs_ubi +vol_alignment=1 +``` + +Re-build volume: + +```sh +rm -v new_rootfs1.ubi +ubinize -o new_rootfs1.ubi -p 131072 -m 2048 -s 2048 ubinize.cfg +``` + +## Writing to flash + +Pay attention to what Image is active, inactive rootfs will be named `rootfs1` inside /proc/mtd. + +For safety only flash one slot at once to make recovery faster avoiding need for U-Boot Ymodem upload. + +# Documented modifications to rootfs + +## Enable WEB UI +On builds not ending with `_eng` file `/sbin/httpd` was deleted to disable WEBUI, copying it from `_eng` build will restore its function. + +## Disable TR-069 +UCI configuration for TR-069 is saved inside `/etc/config/easycwmp`, deleteing ACS url will disable easycwmp process starting from its init script. + +## Installing full busybox +Precompiled busybox binary with all its features can be found [here](https://github.com/YuukiJapanTech/CA8271x/tree/main/mod/busybox-full). + +Place the full version into /bin/busybox-full or overlayfs and only create symlinks for tools you need. + +Do not replace the old busybox binary, device uses mtd-utils version of ubi* commands and busybox implementation is incompatible if you replace them. + diff --git a/_ont_xgs/ont-kaon-pm1191.md b/_ont_xgs/ont-kaon-pm1191.md index b421ee57..40860af6 100644 --- a/_ont_xgs/ont-kaon-pm1191.md +++ b/_ont_xgs/ont-kaon-pm1191.md @@ -1,6 +1,6 @@ --- title: KAON PM1191 -has_children: false +has_children: true layout: default parent: KAON --- diff --git a/_ont_xgs/ont-sercomm-rhg3006.md b/_ont_xgs/ont-sercomm-rhg3006.md new file mode 100644 index 00000000..c1ecabc1 --- /dev/null +++ b/_ont_xgs/ont-sercomm-rhg3006.md @@ -0,0 +1,52 @@ +--- +title: Sercomm RHG3006 +has_children: false +layout: default +parent: Sercomm +--- + +# Hardware Specifications + +| | | +| --------------- | -------------------------- | +| Vendor/Brand | Sercomm | +| Model | RHG3006 | +| Chipset | Broadcom BCM68380 | +| Flash | 4 Gbit (MXIC MX30LF4G28AD) | +| RAM | 256 Mb | +| Bootloader | Broadcom CFE | +| 2.5GBaseT | ? | +| Optics | SC/APC | +| IP address | 192.168.1.1/24 | +| POTS | 2x RJ11 | +| WLAN 2.4Ghz | 802.11b/g/n/ax 4×4 MU-MIMO | +| WLAN 5Ghz | 802.11a/ac/ax 4×4 MU-MIMO | +| Web Gui | ✅ | +| SSH | | +| Telnet | | +| Serial | ✅, only TX | +| Serial baud | 115200 | +| Serial encoding | 8-N-1 | +| Form Factor | ONT HGU | + + +{% include image.html file="rhg3006/rhg3006-pcb-top.jpg" alt="Sercomm RHG3006 top" caption="Sercomm RHG3006 top" %} +{% include image.html file="rhg3006/rhg3006-pcb-back.jpg" alt="Sercomm RHG3006 back" caption="Sercomm RHG3006 back" %} +{% include image.html file="rhg3006/rhg3006-wlan.jpg" alt="Sercomm RHG3006 WLAN" caption="Sercomm RHG3006 WLAN" %} + +## List of software versions +- XF6_4.0.03.02 (Vodafone.cz) + +## OMCI Parameters +| | | +| ------------------------ | ------------- | +| Main Software Version | XF6_4.0.03.02 | +| Standby Software Version | XF6_4.0.03.02 | +| Vendor ID | SCOM | +| Version | RHG3006v2 | +| GPON SN | SCOMa1b2c3d4 | +| PLOAM Password | Unknown | +| LOID | Unknown | +| LOID Password | Unknown | +| Equipment ID | RHG3006 | +| OMCC Version | 161 (0xA1) | diff --git a/_ont_xgs/ont-sercomm.md b/_ont_xgs/ont-sercomm.md new file mode 100644 index 00000000..2e44445a --- /dev/null +++ b/_ont_xgs/ont-sercomm.md @@ -0,0 +1,5 @@ +--- +title: Sercomm +has_children: true +layout: default +--- \ No newline at end of file diff --git a/assets/img/comtrend_grg-4362_teardown_1.jpg b/assets/img/grg-4362/comtrend_grg-4362_teardown_1.jpg similarity index 100% rename from assets/img/comtrend_grg-4362_teardown_1.jpg rename to assets/img/grg-4362/comtrend_grg-4362_teardown_1.jpg diff --git a/assets/img/comtrend_grg-4362_teardown_2.jpg b/assets/img/grg-4362/comtrend_grg-4362_teardown_2.jpg similarity index 100% rename from assets/img/comtrend_grg-4362_teardown_2.jpg rename to assets/img/grg-4362/comtrend_grg-4362_teardown_2.jpg diff --git a/assets/img/comtrend_grg-4362_teardown_3.jpg b/assets/img/grg-4362/comtrend_grg-4362_teardown_3.jpg similarity index 100% rename from assets/img/comtrend_grg-4362_teardown_3.jpg rename to assets/img/grg-4362/comtrend_grg-4362_teardown_3.jpg diff --git a/assets/img/grg-4362/mib_patch.jpg b/assets/img/grg-4362/mib_patch.jpg new file mode 100644 index 00000000..c33e0933 Binary files /dev/null and b/assets/img/grg-4362/mib_patch.jpg differ diff --git a/assets/img/rhg3006/rhg3006-pcb-back.jpg b/assets/img/rhg3006/rhg3006-pcb-back.jpg new file mode 100644 index 00000000..02e3521f Binary files /dev/null and b/assets/img/rhg3006/rhg3006-pcb-back.jpg differ diff --git a/assets/img/rhg3006/rhg3006-pcb-top.jpg b/assets/img/rhg3006/rhg3006-pcb-top.jpg new file mode 100644 index 00000000..b4966d39 Binary files /dev/null and b/assets/img/rhg3006/rhg3006-pcb-top.jpg differ diff --git a/assets/img/rhg3006/rhg3006-wlan.jpg b/assets/img/rhg3006/rhg3006-wlan.jpg new file mode 100644 index 00000000..b0593c6e Binary files /dev/null and b/assets/img/rhg3006/rhg3006-wlan.jpg differ