Need SBG6580 Firmware backup - Printable Version +- Haxorware Forums (http://www.haxorware.com/forums) +-- Forum: General (http://www.haxorware.com/forums/forumdisplay.php?fid=6) +--- Forum: Modems (http://www.haxorware.com/forums/forumdisplay.php?fid=7) +--- Thread: Need SBG6580 Firmware backup (/showthread.php?tid=2721) |
RE: Need SBG6580 Firmware backup - ABMJR - 23-11-2013 NOSH=NO SHELL Quote:i had telnet access but while testing don't know what happen.. for some reason it locked me from my machine to logging.. RE: Need SBG6580 Firmware backup - Rickz - 26-11-2013 (23-11-2013, 06:02 PM)ABMJR Wrote: NOSH=NO SHELL i wish to have a backup for this to gain more experience checking the telnet feature..i mean made a full flash with jtagnt before locked.. but i don't have it and that will be my next project.. keep in mind NOSH never have or give any time telnet access so far i know.. i was logged in this one. i believe the protection it has..after been logged for a while then some key was changed. Regards RE: Need SBG6580 Firmware backup - ABMJR - 26-11-2013 TELNET after registration is closed RE: Need SBG6580 Firmware backup - Rickz - 26-11-2013 Stack Sta ck Stack TaskId TaskName Priority State Size Use d Margin ---------- -------------------------------- -------- -------- -------- ----- --- -------- 0x80d81dd8 Network alarm support 6 SLEEP 5328 151 2 3816 0x80d204b0 Network support 7 SLEEP 8192 199 2 6200 0x80d86590 pthread.00000800 15 EXIT 7812 161 6 6196 0x80ce7720 tStartup 18 SLEEP 12288 692 8 5360 0x83fb8650 NonVol Device Async Helper 25 SLEEP 3072 118 8 1884 0x83f96c00 LED Controller Thread 23 SLEEP 4096 47 6 3620 0x83f95504BRCM Reset/Standby Switch Thread 23 SLEEP 8192 87 6 7316 0x83f92d50 Motorola Vendor Ctl Thread 23 SLEEP 4096 48 4 3612 0x83f916c8 CableHome Ping Thread 29 SLEEP 6144 39 6 5748 0x83fb9e14 WDOG 17 RUN 5120 512 0 0 OVERFLOW 0x83f2fb14 BFC Ping Thread 29 SLEEP 6144 187 6 4268 0x83f2f704 ConsoleThread 27 SUSP 24576 682 8 17748 0x83f01968 Telnet Thread 23 RUN 4096 262 4 1472 0x83f4eab8 SSH Thread 23 SLEEP 32768 166 4 31104 0x80d1d768 Idle Thread 31 RUN 2048 105 6 992 0x83f12994 Time Of Day Thread 23 SLEEP 6144 164 0 4504 0x83f12ea0 CmDocsisIpThread 23 SLEEP 8192 230 0 5892 0x83f835ac CmBpiManagerThd 23 SLEEP 8192 272 8 5464 0x83f7fd18 CmDsxHelper 23 SLEEP 8192 119 6 6996 0x83f18f44 CmDocsisCtlThread 21 SLEEP 8192 594 0 2252 0x82d31718 Scan Downstream Thread 23 SLEEP 4096 174 8 2348 0x83f729fc RateShaping Thread 23 SLEEP 4096 152 8 2568 0x83fb9f34 DocsisCmHalDataForwardingThread 23 SLEEP 6500 250 0 4000 0x83fba054 DocsisCmHalControlThread 22 SLEEP 4500 148 4 3016 0x83fba174 UtpRxMsgDqmThread 22 SLEEP 4500 41 2 4088 0x83fba294 AsyncDs_0 23 SLEEP 4500 36 8 4132 0x83fba3b4 AsyncDs_1 23 SLEEP 4500 121 6 3284 0x83fba4d4 AsyncDs_2 23 SLEEP 4500 104 8 3452 0x83fba5f4 AsyncDs_3 23 SLEEP 4500 91 2 3588 0x83fba714 AsyncDs_4 23 SLEEP 4500 36 8 4132 0x83fba834 AsyncDs_5 23 SLEEP 4500 36 8 4132 0x83fba954 AsyncDs_6 23 SLEEP 4500 36 8 4132 0x83fbaa74 AsyncDs_7 23 SLEEP 4500 36 8 4132 0x83fbab94 ENRX 23 SLEEP 8192 190 4 6288 0x83fbacb4 MSELNK 23 SLEEP 4500 101 2 3488 0x83fbadd4 USBCT 21 SLEEP 4500 46 8 4032 0x83fbaef4 UBCRX 23 SLEEP 4500 37 2 4128 0x83fbb014 USBRX 23 SLEEP 8192 38 8 7804 0x83fbb134 WL_TMR_scantimer 23 SLEEP 4500 34 0 4160 0x83fbb254 WL_TMR_phycal 23 SLEEP 4500 154 4 2956 0x83fbb374 WL_TMR_dfs 23 SLEEP 4500 34 0 4160 0x83fbb494 WL_TMR_resp 23 SLEEP 4500 218 4 2316 0x83fbb5b4 WL_TMR_eventq 23 SLEEP 4500 162 8 2872 0x83fbb6d4 WL_TMR_watchdog 23 SLEEP 4500 224 4 2256 0x83fbb7f4 WL_TMR_radio 23 SLEEP 4500 34 0 4160 0x83fbb914 WL_TMR_csa 23 SLEEP 4500 34 0 4160 0x83fbba34 RFMT 23 SLEEP 8596 472 8 3868 0x83fbbb54 RFNK 23 SLEEP 4500 73 6 3764 0x83fbbc74 RFBK 23 SLEEP 4500 108 8 3412 0x83fbbd94 ThreadDeleteTask 23 SLEEP 4096 42 0 3676 0x83fbbeb4 nas_wksp 23 SLEEP 12288 333 2 8956 0x83fbbfd4 EAPD 23 SLEEP 12288 217 6 10112 0x83fbc0f4 WPAT0 23 RUN 6548 79 6 5752 0x83fbc214 WifiSecureEzSetupThread 23 SLEEP 12288 229 2 9996 0x83fbc334 GuiCommandTask 23 SLEEP 16384 33 6 16048 0x83fbc454 WPSM 24 SLEEP 16384 438 0 12004 0x82c9a1e0 DHCP Client Thread 23 SLEEP 12288 270 0 9588 0x82c96bc4 DHCPv6 Client Thread 23 SLEEP 8192 47 2 7720 0x83fbc574 IpHalIst 23 SLEEP 9000 240 8 6592 0x82c88780 Forward Assist Manager 23 SLEEP 10240 314 4 7096 0x83fbc694 WPAT1 23 SLEEP 6548 306 4 3484 0x82c79578 ParentalCtlThread 23 SLEEP 40000 47 6 39524 0x82c64644 CmPropaneCtlThread 23 SLEEP 8192 160 8 6584 0x82c617a0 IGMP Thread 23 SLEEP 4096 202 4 2072 0x82c5872c CfgVB Thread 23 SLEEP 12288 295 6 9332 0x82c55154 DHCM 25 SLEEP 16384 47 2 15912 0x82c4fabc NetToMedia Thread 23 SLEEP 4096 223 6 1860 0x82c4e068 Trap Thread 23 SLEEP 16384 47 6 15908 0x82c5897c SNMP Thread 23 SLEEP 20480 566 8 14812 0x82b2c518 Event Log Thread 25 SLEEP 8192 267 2 5520 0x82ae9f84FTP Lite Client Thread for IP Stack1 23 SLEEP 8192 1008 7184 0x82ae4f4c WPA-NAS 23 SLEEP 8192 189 6 6296 0x82ae290c WiFi 80211 Configure Thread 23 RUN 8192 96 8 7224 0x82ae0624 WiFi 80211 Led Control Thread 23 RUN 8192 225 6 5936 0x82ade418 WiFi 80211 Control Thread 23 SLEEP 8192 162 8 6564 0x82adc22c HOME-PLUG 23 SLEEP 4096 139 2 2704 0x82adaad4 ND Thread for IP Stack1 23 SLEEP 6144 92 4 5220 0x82ad77a0 DHCP Server Thread 23 SLEEP 8192 321 6 4976 0x82ad4c2c Rip Client Thread 23 SLEEP 8192 84 4 7348 0x82acb914 CableHomeCtlThread 23 SLEEP 8192 573 2 2460 0x82ac8c04 Firewall Thread 29 SLEEP 8192 47 2 7720 0x82ac5d2c ArpPacketManagerThread 23 SLEEP 8192 156 4 6628 0x82aa97b0 eRouterCtlThread 23 SLEEP 8192 47 6 7716 0x82aa6ab0 BcmCspSecFwPolicyFileThread 23 SLEEP 8192 65 2 7540 0x82a9a97c Nat Timer Thread 23 SLEEP 4096 84 0 3256 0x82a96e00 RG SMTP Thread 23 SLEEP 8192 38 4 7808 0x829effb4 erouter IGMP Thread 23 SLEEP 4096 276 4 1332 0x829edff8Neighbor Discovery Thread for IP Stack3 23 SLEEP 6144 920 5224 0x829eb9a4Neighbor Discovery Thread for IP Stack5 23 SLEEP 6144 1204 4940 0x829e879c DHCPv6 Server Thread 23 SLEEP 8192 47 2 7720 0x829e5e94 DNS Server Thread 23 SLEEP 8192 89 6 7296 0x82976754 UpnpThread 23 SLEEP 8192 47 6 7716 0x829abc48 CableHomePingTool Thread 29 SLEEP 4096 348 4 612 0x829acd78 Ping Maintenance Thread 29 SLEEP 6144 40 0 5744 0x82965680 CableHomeConnSpeedTool Thread 29 SLEEP 4096 38 8 3708 0x8293ffc0 BcmStSessionTrackThread 23 SLEEP 8192 126 0 6932 0x8293d95c NAT Session Manager Thread 23 SLEEP 8192 152 4 6668 0x83fbc7b4 NATP NO-MATCH RX 23 SLEEP 8192 233 6 5856 0x83fbc8d4 NATP WIFI RX 23 SLEEP 8192 38 8 7804 0x8292a6d0 Traceroute Thread 29 SLEEP 8192 41 2 7780 0x82925390 IkeThread 23 SLEEP 8192 37 2 7820 0x829229c0 L2tp Thread 23 SLEEP 8192 48 0 7712 0x8291f884 Dynamic DNS Client Thread 23 SLEEP 8192 203 6 6156 0x8291cb30 HttpServerThread 23 SLEEP 12288 449 6 7792 0x828e5130 SLED Packet Generator Thread 23 SLEEP 8192 48 0 7712 Dear ABMJR in the node where i connect there are more modems with telnet still open..most of them has been online for days/month RE: Need SBG6580 Firmware backup - maximus64 - 19-11-2014 Ok. I have successfully recover the modem back then. But now I wanted to extract the Certs to used on my other SB6120 modem ( I have to do all this BS because TWC isn't allow that specific modem to be online and I don't want to buy another modem ). I Extract it with cmnonexp 1.1.1 but there is some error complaining about the cert format. I try to load it in to the SB6120 anyway but doesn't work. It just can't parse the CM private key file, but everything else seem ok and was able to get my config from CMTS. The warning are: WARNING: address: 033F; size: 0x02A0 (672); unknow cert type: 0xE14B Writing to file non01_2_private.key 672 bytes Clearly cmnonexp didn't parse the CFG correctly :/ cmnonexp ouput: Code: cmnonexp (CableModem non-volatile explorer for BCM3348/BCM3349) Also, Does anyone know where is the UART port on this modem (SBG6580)? or maybe someway to enable telnet/ssh? Thank you RE: Need SBG6580 Firmware backup - maximus64 - 20-11-2014 Founded UART port on the SBG6580, JTAG seen to be disabled. Got message from boot-loader but firmware seen to be silence. Anyone got a shell firmware or maybe FW dump from the "orange" diagnostic version? My modem is toast from the lightning strike. Tuner isn't working anymore. So I just playing around with it see if i can make it to a diagnostic modem. Code: BCM338031 TP0 RE: Need SBG6580 Firmware backup - maximus64 - 21-11-2014 WIN GOT SSH + TELNET Shell on NOSH FW Code: +-----------------------------------------------------------------------+ RE: Need SBG6580 Firmware backup - maximus64 - 21-11-2014 Checking the log of SBG6580. I see ***BpiPrivateKey: Using Primary key sha-1 comparison passed total size=634 ******* Decrypt Complete ******* ***BpiPlusCmCertificate: Using Primary cer ***BpiPlusCmCertificate: Using Primary cer It look like that the Private key is encrypted. Anyone know about this? RE: Need SBG6580 Firmware backup - maximus64 - 22-11-2014 Finally got my SB6120 online. Turn out that cmnonexp didn't parse the nonvol correctly. Used the SSH shell and do "/nonvol/bpi/print private" and there is the private key RE: Need SBG6580 Firmware backup - newname - 22-11-2014 hahaha......this guy is a one man show......great stuff !! |