Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Arris TG1672G - NAND chip swap
#1
Hi guys,

My old Arris TG1672G has an undocumented feature: it gives me two public IP addresses. Newer modem that I can get from my ISP give me only one IP address.
Unfortunately my old Arris TG1672G is almost dead, it reboots and freezes all the time.

How can I transplant the identity of my current modem to a different motherboard that I got from ebay ?

I swapped NAND chip, but it doesn't work.
Where is the NAND encryption key stored ?
What else do I need to swap besides NAND chip ?

If the encryption key is stored in CPU (like in xbox 360 for example), that's a bummer...
Reply
#2
(14-03-2021, 09:33 PM)Eugene@ Wrote: Hi guys,

My old Arris TG1672G has an undocumented feature: it gives me two public IP addresses. Newer modem that I can get from my ISP give me only one IP address.
Unfortunately my old Arris TG1672G is almost dead, it reboots and freezes all the time.

How can I transplant the identity of my current modem to a different motherboard that I got from ebay ?

I swapped NAND chip, but it doesn't work.
Where is the NAND encryption key stored ?
What else do I need to swap besides NAND chip ?

If the encryption key is stored in CPU (like in xbox 360 for example), that's a bummer...

1672 nand is not encrypted.
NAND swap should work fine.
you fucked up the swap, probably.
Reply
#3
(15-03-2021, 12:58 AM)BTC Wrote:
(14-03-2021, 09:33 PM)Eugene@ Wrote: If the encryption key is stored in CPU (like in xbox 360 for example), that's a bummer...

1672 nand is not encrypted.
NAND swap should work fine.
you fucked up the swap, probably.

It could be that I screwed up, I have some experience soldering TSOP 48 though.

Are there any security features preventing TG1672G from cloning ?


How do I copy NAND to a new chip ? Every time I read NAND content it doesn't match the previous dump. Random errors here and there.
Data only dump: 128MB (131,072 KB)
Full dump: 132MB (135,168 KB)

Is it possible to correct those errors manually by dumping multiple times ? There are not too many of them, about 20...30

NAND chips are different
Spansion: s34ml01g200tfi00

I soldered it to the board replacing
Macronix: mx30lf1g18ac-ti

but they should be compatible and swappable.
Reply
#4
(15-03-2021, 01:43 AM)Eugene@ Wrote:
(15-03-2021, 12:58 AM)BTC Wrote:
(14-03-2021, 09:33 PM)Eugene@ Wrote: If the encryption key is stored in CPU (like in xbox 360 for example), that's a bummer...

1672 nand is not encrypted.
NAND swap should work fine.
you fucked up the swap, probably.

It could be that I screwed up, I have some experience soldering TSOP 48 though.

Are there any security features preventing TG1672G from cloning ?


How do I copy NAND to a new chip ? Every time I read NAND content it doesn't match the previous dump. Random errors here and there.
Data only dump: 128MB (131,072 KB)
Full dump: 132MB (135,168 KB)

Is it possible to correct those errors manually by dumping multiple times ? There are not too many of them, about 20...30

NAND chips are different
Spansion: s34ml01g200tfi00

I soldered it to the board replacing
Macronix: mx30lf1g18ac-ti

but they should be compatible and swappable.

"Are there any security features preventing TG1672G from cloning ?"
no, there is none.

"NAND chips are different"
you cannot do a cross-MFG NAND clone. the NAND must be identical
the Phison manages different NANDs differently, they are not compatible.


"Random errors here and there."
random errors are normal for NANDs, it has no problems correcting these as long as your NAND is compatible
Reply
#5
anyone share tg1672g full dump for me . thank you !
Reply


Forum Jump:


Users browsing this thread: 3 Guest(s)