Skip to content
Merged
2 changes: 1 addition & 1 deletion _ont/ont-comtrend-grg-4284.md
Original file line number Diff line number Diff line change
Expand Up @@ -70,7 +70,7 @@ Simple change with a hex editor can be done to enable full shell, inside /lib/li

Then add /bin/ash to /etc/shells to enable normal shell.

Binary patch is required to prevent `/bin/startup` from reseting ME 256 and 257 parameters on reboot.
In case device contains locked default configuration `/etc/config_default.xml` can be modified to undo any unwanted restrictions.

## Flashing new firmware

Expand Down
11 changes: 9 additions & 2 deletions _ont/ont-nokia-g-010s-q.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ alias: CIG G-97S
| ODM Product Code | G-97S |
| Chipset | RTL9601CI |
| Flash | 16 MB (Macronix MX25L12835F) |
| RAM | |
| RAM | 32 MB |
| System | |
| HSGMII | |
| Optics | |
Expand All @@ -33,10 +33,17 @@ alias: CIG G-97S

{% include_relative ont-nokia-useful-command.md %}

## Enable full telnet shell
Full telnet and secondary factory IP can be enabled by sending [Nokia magic packet](https://github.com/YuukiJapanTech/CA8271x/blob/main/doc/rootShell.md#nokia-xs-010x-r).

If factory mode is enabled sucessfully second IP `192.168.188.1/24` will be assinged to SFP LAN interface.

Newly available login credentials will be `ATE` / `CATS2388` and `ONTUSER` / `sha256 of SN formated as GPONa1b2c3d4` with GponCLI shell.

# Miscellaneous Links

- [Nokia G-010S-Q](https://github.com/Anime4000/RTL960x/issues/52)
- [CUG G-97S DataSheet](https://www.cigtech.com/wp-content/uploads/2018/09/G-97S_DataSheet_V2.pdf)
- [CIG G-97S DataSheet](https://web.archive.org/web/20230803034001/https://www.cigtech.com/wp-content/uploads/2018/09/G-97S_DataSheet_V2.pdf)
- [MIB file parser](https://github.com/nanomad/nokia-ont-mib-parser) for NOKIA's GPON ONTs (*helps you parsing the .mib file located in `/mnt/rwdir`*)


44 changes: 22 additions & 22 deletions _ont/ont-sercomm-fg1000r.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,29 +7,29 @@ parent: Sercomm

# Hardware Specifications

| | |
| --------------- | ----------------------- |
| Vendor/Brand | Sercomm |
| Model | FG1000R |
| ODM | ✅ |
| Chipset | RTL9602C |
| Flash | 128MB (MXIC MX35LF1GE4AB) |
| RAM | 64MB |
| CPU | |
| CPU Clock | 625 MHz |
| Bootloader | U-Boot RSDK 2011.12.NA-svn5 |
| Load addr | |
| 2.5GBaseT | ✅ |
| PHY Ethernet | Realtek RTL8221B |
| Optics | LC/APC |
| IP address | 192.168.1.1/24 |
| | |
| --------------- | ------------------------------ |
| Vendor/Brand | Sercomm |
| Model | FG1000R |
| ODM | ✅ |
| Chipset | RTL9602C |
| Flash | 128MB (MXIC MX35LF1GE4AB) |
| RAM | 64MB |
| CPU | |
| CPU Clock | 625 MHz |
| Bootloader | U-Boot RSDK 2011.12.NA-svn5 |
| Load addr | |
| 2.5GBaseT | ✅ |
| PHY Ethernet | Realtek RTL8221B |
| Optics | LC/APC |
| IP address | 192.168.1.1/24 |
| Web Gui | ✅, User: Tech Password: ftth@! |
| SSH | |
| Telnet | |
| Serial | ✅, only TX |
| Serial baud | 115200 |
| Serial encoding | 8-N-1 |
| Form Factor | ONT |
| SSH | |
| Telnet | |
| Serial | ✅, only TX |
| Serial baud | 115200 |
| Serial encoding | 8-N-1 |
| Form Factor | ONT |


{% include image.html file="fg1000r_rear.jpg" alt="Sercomm FG1000R" caption="Sercomm FG1000R rear" %}
Expand Down
21 changes: 15 additions & 6 deletions _ont/ont-sercomm-fgs202.md
Original file line number Diff line number Diff line change
Expand Up @@ -159,9 +159,10 @@ FGS202:/# show i2c (ASCII view added for readability)
000001d0: 3230 3231 3132 0000 5343 4f4d 4647 5332 202112..SCOMFGS2
000001e0: 3032 3131 3200 ff00 0000 1000 0000 0000 02112...........
000001f0: 0000 0000 0000 0000 0000 0000 0000 0020 ...............
```

It can also be read and written using an external I2C reader.
```


# Advanced settings

Expand All @@ -181,14 +182,18 @@ Simple U-Boot-style storage `key=value\0` padded by 0xFF, after modification, a

```py
from zlib import crc32
wholeflash = open("FGS202.bin", "rb").read() # Full SPI dump
ubootenv = wholeflash[262144:262144+65536] # 0x40000-0x5FFFF
factoryenv = wholeflash[327680:327680+65536] # 0x50000-0x6FFFF
ecosenv = wholeflash[393216:393216+65536] # 0x60000-0x7FFFF
wholeflash = open("FGS202.bin", "rb").read() # Full SPI dump
ubootenv = wholeflash[262144:262144+65536] # 0x40000-0x50000
factoryenv = wholeflash[327680:327680+65536] # 0x50000-0x60000
ecosenv = wholeflash[393216:393216+65536] # 0x60000-0x70000
ubootenv2 = wholeflash[262144:262144+65536] # 0x80000-0x90000
ecosenv2 = wholeflash[8323072:8323072+65536] # 0x7F0000-0x800000

print(f'U-Boot\n| CRC: {ubootenv[0:4].hex()} | Version {ubootenv[4:5]} | New CRC: {crc32(ubootenv[5:]):08x} ')
print(f'Factory\n| CRC: {factoryenv[0:4].hex()} | Version {factoryenv[4:5]} | New CRC: {crc32(factoryenv[5:]):08x} ')
print(f'eCos\n| CRC: {ecosenv[0:4].hex()} | Version {ecosenv[4:5]} | New CRC: {crc32(ecosenv[5:]):08x} ')
print(f'U-Boot backup\n| CRC: {ubootenv2[0:4].hex()} | Version {ubootenv2[4:5]} | New CRC: {crc32(ubootenv2[5:]):08x}')
print(f'eCos backup\n| CRC: {ecosenv2[0:4].hex()} | Version {ecosenv2[4:5]} | New CRC: {crc32(ecosenv2[5:]):08x}')
```

## Decrypting "encrypt_data" variable from flash
Expand Down Expand Up @@ -221,10 +226,14 @@ At boot time, this variable is read by the modified U-Boot and waits for [sercom

Due to an uninitialized SFP EEPROM, a simple SFP-to-Ethernet converter is required.

The input for sercomm-recovery tool must be a complete dump of complete flash memory, the client writes only the Image0 and Image1 regions, and the rest is skipped (so a failed write will drop you back into recovery).
The input for sercomm-recovery tool must be a complete dump of flash memory, the client writes only the Image0 and Image1 regions, and the rest is skipped (so a failed write will drop you back into recovery).

It is not possible to exit this mode until the write operation completes or the environment settings are manually reset to 0.

## Boot and update log
{% include serial_dump.html file="fgs202-boot.txt" alt="eCos boot" title="eCos boot" %}

{% include serial_dump.html file="fgs202-flash.txt" alt="Update with sercomm-recovery" title="Update with sercomm-recovery" %}

# Hardware Modding

Expand Down
143 changes: 143 additions & 0 deletions _ont/ont-tenda-hg1-patch.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,143 @@
---
title: OMCI reset patch
has_children: false
layout: default
parent: Tenda HG1
---

## Premade patch for V1.0.2
This patch is for /bin/startup with MD5 `5e6db6934d662b5cef2f4c74b8cdf639`

```diff
1073c1073
< 00004300: 0040 2821 8f82 81c0 0040 c821 0000 0000 .@(!.....@.!....
---
> 00004300: 0040 2821 8f82 81c0 0040 c821 0320 f809 .@(!.....@.!. ..
1205c1205
< 00004b40: 0000 0000 0000 0000 8fdc 0010 27c2 0030 ............'..0
---
> 00004b40: 0320 f809 0000 0000 8fdc 0010 27c2 0030 . ..........'..0
1207c1207
< 00004b60: 0000 0000 0000 0000 8fdc 0010 2404 0008 ............$...
---
> 00004b60: 0320 f809 0000 0000 8fdc 0010 2404 0008 . ..........$...
1256c1256
< 00004e70: 0040 c821 0000 0000 0000 0000 8fdc 0010 .@.!............
---
> 00004e70: 0040 c821 0320 f809 0000 0000 8fdc 0010 .@.!. ..........
1258c1258
< 00004e90: 0040 c821 0000 0000 0000 0000 8fdc 0010 .@.!............
---
> 00004e90: 0040 c821 0320 f809 0000 0000 8fdc 0010 .@.!. ..........
1262c1262
< 00004ed0: 0040 2821 8f82 81c0 0040 c821 0000 0000 .@(!.....@.!....
---
> 00004ed0: 0040 2821 8f82 81c0 0040 c821 0320 f809 .@(!.....@.!. ..
1264c1264
< 00004ef0: 0040 2821 8f82 81c0 0040 c821 0000 0000 .@(!.....@.!....
---
> 00004ef0: 0040 2821 8f82 81c0 0040 c821 0320 f809 .@(!.....@.!. ..
```

Resulting patched file should have MD5 of `99aaaece6b7ed5a9ee0a075443d98943`

Add the following to `/etc/version.sh`, `rootfs_extracted/etc/scripts/chk_swver_2.sh` and `rootfs_extracted/etc/scripts/chk_swver.sh` to skip script checks by creating empty file inside JFFS2 config.

```diff
> if [ -f /var/config/skip_version ]; then
> echo "Version adaptation bypass"
> exit 0
> fi
```

## Tweaked default configuration

Enable telnet on LAN, disable http and telnet on WAN.

SSH and FTP components are removed from firmware and can't be enabled.

```diff
< <Dir Name="ACL_IP_TBL"> <!--index=0-->
< <Value Name="instnum" Value="0"/>
< <Value Name="https_port" Value="443"/>
< <Value Name="https" Value="2"/>
< <Value Name="ftp_port" Value="21"/>
< <Value Name="web_port" Value="80"/>
< <Value Name="telnet_port" Value="23"/>
< <Value Name="icmp" Value="2"/>
< <Value Name="ssh" Value="2"/>
< <Value Name="snmp" Value="2"/>
< <Value Name="web" Value="2"/>
< <Value Name="tftp" Value="2"/>
< <Value Name="ftp" Value="0"/>
< <Value Name="telnet" Value="0"/>
< <Value Name="any" Value="0"/>
< <Value Name="Interface" Value="16"/> <!--LAN-->
< <Value Name="State" Value="1"/>
< <Value Name="NetMask" Value="24"/>
< <Value Name="IPAddr" Value="0.0.0.0"/>
< </Dir>
< <Dir Name="ACL_IP_TBL"> <!--index=1-->
< <Value Name="instNum" Value="1"/>
< <Value Name="https_port" Value="443"/>
< <Value Name="https" Value="2"/>
< <Value Name="ftp_port" Value="21"/>
< <Value Name="web_port" Value="80"/>
< <Value Name="telnet_port" Value="23"/>
< <Value Name="icmp" Value="0"/>
< <Value Name="ssh" Value="0"/>
< <Value Name="snmp" Value="0"/>
< <Value Name="web" Value="1"/>
< <Value Name="tftp" Value="0"/>
< <Value Name="ftp" Value="0"/>
< <Value Name="telnet" Value="0"/>
< <Value Name="any" Value="0"/>
< <Value Name="Interface" Value="128"/> <!--WAN-->
< <Value Name="State" Value="1"/>
< <Value Name="NetMask" Value="0"/>
< <Value Name="IPAddr" Value="0.0.0.0"/>
< </Dir>
---
> <Dir Name="ACL_IP_TBL"> <!--index=0-->
> <Value Name="instnum" Value="0"/>
> <Value Name="https_port" Value="443"/>
> <Value Name="https" Value="0"/>
> <Value Name="ftp_port" Value="21"/>
> <Value Name="web_port" Value="80"/>
> <Value Name="telnet_port" Value="23"/>
> <Value Name="icmp" Value="2"/>
> <Value Name="ssh" Value="0"/>
> <Value Name="snmp" Value="2"/>
> <Value Name="web" Value="2"/>
> <Value Name="tftp" Value="0"/>
> <Value Name="ftp" Value="0"/>
> <Value Name="telnet" Value="2"/>
> <Value Name="any" Value="0"/>
> <Value Name="Interface" Value="16"/> <!--LAN-->
> <Value Name="State" Value="1"/>
> <Value Name="NetMask" Value="24"/>
> <Value Name="IPAddr" Value="0.0.0.0"/>
> </Dir>
> <Dir Name="ACL_IP_TBL"> <!--index=1-->
> <Value Name="instNum" Value="1"/>
> <Value Name="https_port" Value="443"/>
> <Value Name="https" Value="0"/>
> <Value Name="ftp_port" Value="21"/>
> <Value Name="web_port" Value="80"/>
> <Value Name="telnet_port" Value="23"/>
> <Value Name="icmp" Value="0"/>
> <Value Name="ssh" Value="0"/>
> <Value Name="snmp" Value="0"/>
> <Value Name="web" Value="0"/>
> <Value Name="tftp" Value="0"/>
> <Value Name="ftp" Value="0"/>
> <Value Name="telnet" Value="0"/>
> <Value Name="any" Value="0"/>
> <Value Name="Interface" Value="128"/> <!--WAN-->
> <Value Name="State" Value="1"/>
> <Value Name="NetMask" Value="0"/>
> <Value Name="IPAddr" Value="0.0.0.0"/>
> </Dir>
```


12 changes: 10 additions & 2 deletions _ont/ont-tenda-hg1.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
title: Tenda HG1
has_children: false
has_children: true
layout: default
parent: Tenda
---
Expand Down Expand Up @@ -39,7 +39,7 @@ parent: Tenda

## List of software versions

- V1.7.1
- V1.0.2

# List of partitions

Expand Down Expand Up @@ -80,6 +80,14 @@ Device has a hidden page `http://192.168.1.1/tddeviceinfo.asp` for configuring O

OMCI equipment ID (ME 257) and OMCI hardware version (ME 256) are hardcoded into `/etc/version.sh` and `/bin/startup` requiring a firmware patch to change.

## WAN backdoor account
There are hardcoded credentials for WAN user, it's recommended WWW and Telnet are disabled on and this second password changed.

```xml
<Value Name="WAN_USER_NAME" Value="tendaxpon"/>
<Value Name="WAN_USER_PASSWORD" Value="XPON#TDWLD"/>
```

# Miscellaneous Links

- [Hacking RTL960x](https://github.com/Anime4000/RTL960x)
29 changes: 29 additions & 0 deletions _ont/ont-zyxel-pmg5100-t0.md
Original file line number Diff line number Diff line change
Expand Up @@ -30,3 +30,32 @@ parent: Zyxel
{% include image.html file="zyxel-pmg5100\port.jpg" alt="PM5100-T0" caption="PM5100-T0" %}
{% include image.html file="zyxel-pmg5100\back-board.jpg" alt="PM5100-T0 Teardown" caption="PM5100-T0 Teardown" %}
{% include image.html file="zyxel-pmg5100\front-board.jpg" alt="PM5100-T0 Teardown" caption="PM5100-T0 Teardown" %}

## List of software versions
- V5.42-ACEQ-0b10 (Cetin)
- V5.42-ACBF.1.1-C0 (Zyxel)

## Unlock bootloader and root shell
Full linux shell can be accessed if the current firmware allows it, this ONT has per-device password burned into flash.

Depending on Z-Loader version bootloader access might be protected with supervisors password until `EngDebugFlag` is enabled.

Default passwords can be obtained with normal ATEN/ATSE unlock process.

```sh
# Generate unlock seed
ATSE PM5100-T0
# Generate ATEN key with https://github.com/cjdelisle/ATENv3
ATEN 1,RESULT
# Allow nvram write
ATBT 1
# Write EngDebugFlag to nvram
ATSB
# Dump passwords from nvram
ATCK
```

If network upgrade isn't disabled by ISP branding [zyeng](https://github.com/bmork/zyxel-hacks) tool can be used to write EngDebugFlag it over the network.

When both methods fail only option is to desolder the SPI flash and locate passwords inside U-Boot ENV.

Loading
Loading