Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions _gpon/vendor.md
Original file line number Diff line number Diff line change
Expand Up @@ -19,8 +19,10 @@ Here is a list of the most popular Vendor IDs:
| `ALLG` | `414c4c47` | ALLNET |
| `AVMG` | `41564d47` | AVM (FRITZ!Box) |
| `ASKY` | `41534b59` | Askey |
| `CDAT` | `43444154` | C-Data |
| `CDKT` | `43444B54` | KingType |
| `CIGG` | `43494747` | Cig |
| `CMDT` | `434d4454` | Comtrend |
| `CXNK` | `43584e4b` | Calix |
| `DDKT` | `44444b54` | DKT |
| `DLNK` | `444c4e4b` | Dlink |
Expand Down Expand Up @@ -53,6 +55,7 @@ Here is a list of the most popular Vendor IDs:
| `SKYW` | `534b5957` | Skyworth |
| `SMBS` | `534d4253` | Sagemcom |
| `SPGA` | `53504741` | SourcePhotonics |
| `TDTC` | `54445443` | Tenda |
| `TMBB` | `544d4242` | Technicolor |
| `TPLG` | `54504c47` | TP-Link |
| `UBNT` | `55424e54` | Ubiquiti |
Expand Down
107 changes: 107 additions & 0 deletions _ont/ont-comtrend-grg-4284.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,107 @@
---
title: Comtrend GRG-4284
has_children: false
layout: default
parent: Comtrend
---

| | |
| --------------- | -------------------------------------------------------------------------- |
| Vendor/Brand | Comtrend |
| Model | GRG-4284 |
| ODM | Unknown |
| CPU | Realtek RTL9601D |
| DRAM | 32 MB |
| Flash Size | 16 MB |
| CPU Arch | MIPSBE Realtek Lexra |
| CPU Clock | 300MHz |
| Bootloader | U-Boot RSDK 2011 |
| System | Linux 3.10 |
| Optics | SC/APC |
| IP address | 192.168.1.1/24 |
| Web Gui | ✅ |
| SSH | ✅ |
| Telnet | ✅ |
| FTP | ✅ |
| Serial | ✅ |
| Serial baud | 115200 |
| Serial encoding | 8-N-1 |
| Form Factor | ONT |

## Hardware Revisions

- V1.0
# External/Internal Photo

{% include image.html file="comtrend_grg-4284_teardown_1.jpg" alt="Comtrend GRG-4284 PCB" caption="Comtrend GRG-4284 PCB" %}

## List of software versions

- CTN-1.0.2b51 (Cetin)
- CTN-1.1.4b6 (Cetin)

{% include_relative ont-luna-sdk-useful-commands.md
flash='flash'
ploam='asciiAndHex'
%}

## Unlocking full shell
Although the option to enter linux shell is displayed in help command, it silently fails until per-firmware password is provided.

This string is stored plaintext and hardcoded into `/bin/cli` and can be easily dumped.

```sh
# Example commands for firmware CTN-1.1.4b6
version --debug 23KcykMddk
factorymode --password y0S4QbPhAD96GYp
shell
```

## Extracting and repacking the rootfs
{% include alert.html content="Make sure you run both commands as root, otherwise you might get a damaged rootfs image" alert="Warning" icon="svg-warning" color="red" %}

```sh
# unsquashfs mtd5.bin
# mksquashfs squashfs-root rootfs -b 131072 -comp lzma -no-recovery
```

## Firmware patch
Simple change with a hex editor can be done to enable full shell, inside /lib/libmib.so, change `/bin/cli` to `/bin/ash`

Then add /bin/ash to /etc/shells to enable normal shell.

Binary patch is required to prevent `/bin/startup` from reseting ME 256 and 257 parameters on reboot.

## Flashing new firmware

U-Boot has working network and commands provided to load kernel and rootfs over TFTP.

It's recommended you preserve old firmware with md.b, SPI base address and size can be found in env.

TFTP requested filenames:
- uImage - U-Boot OS Kernel image
- rootfs - SquashFS root


```sh
# Update image0
run upk;run upr;
# Update image1
run upk1;run upr1
```

Or from linux system

```sh
# tftp <IP>
tftp> mode octet
tftp> get rootfs.img /tmp/rootfs.new
tftp> quit
# flash_eraseall /dev/mtd7
# cat /tmp/rootfs.new > /dev/mtd7
```

# Miscellaneous Links

- [Hacking RTL960x](https://github.com/Anime4000/RTL960x)
- [Modded firmware for GRG4284](https://github.com/Troll338cz/CTN_GPON/tree/main/Comtrend_GRG-4284/)
5 changes: 5 additions & 0 deletions _ont/ont-comtrend.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
title: Comtrend
has_children: true
layout: default
---
44 changes: 22 additions & 22 deletions _ont/ont-sercomm-fg1000r.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,29 +7,29 @@ parent: Sercomm

# Hardware Specifications

| | |
| --------------- | ---------------------- |
| Vendor/Brand | Sercomm |
| Model | FG1000R |
| ODM | ✅ |
| Chipset | RTL9602C |
| Flash | |
| RAM | |
| CPU | |
| CPU Clock | |
| Bootloader | |
| Load addr | |
| 2.5GBaseT | ✅ |
| PHY Ethernet | |
| Optics | LC/APC |
| IP address | 192.168.1.1 |
| | |
| --------------- | ----------------------- |
| Vendor/Brand | Sercomm |
| Model | FG1000R |
| ODM | ✅ |
| Chipset | RTL9602C |
| Flash | 128MB (MXIC MX35LF1GE4AB) |
| RAM | 64MB |
| CPU | |
| CPU Clock | 625 MHz |
| Bootloader | U-Boot RSDK 2011.12.NA-svn5 |
| Load addr | |
| 2.5GBaseT | ✅ |
| PHY Ethernet | Realtek RTL8221B |
| Optics | LC/APC |
| IP address | 192.168.1.1/24 |
| Web Gui | ✅, User: Tech Password: ftth@! |
| SSH | |
| Telnet | |
| Serial | ✅ |
| Serial baud | |
| Serial encoding | |
| Form Factor | ONT |
| SSH | |
| Telnet | |
| Serial | ✅, only TX |
| Serial baud | 115200 |
| Serial encoding | 8-N-1 |
| Form Factor | ONT |


{% include image.html file="fg1000r_rear.jpg" alt="Sercomm FG1000R" caption="Sercomm FG1000R rear" %}
Expand Down
139 changes: 121 additions & 18 deletions _ont/ont-sercomm-fgs202.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,32 +7,50 @@ parent: Sercomm

# Hardware Specifications

| | |
| ------------ | --------------------------------- |
| Vendor/Brand | Sercomm |
| Model | FGS202 |
| Chipset | Lantiq PEB98036 |
| Flash | 8 MB |
| RAM | 32 MB |
| System | eCos |
| HSGMII | Yes |
| Optics | SC/APC |
| IP address | 169.254.199.139 |
| Web Gui | No |
| SSH | No |
| Telnet | ✅ user `admin`, password `admin` |
| Serial | No |
| Form Factor | miniONT SFP |
| | |
| --------------- | --------------------------------- |
| Vendor/Brand | Sercomm |
| Model | FGS202 |
| Chipset | Lantiq PEB98036 |
| Flash | 8 MiB (MXIC MX25L6405D) |
| RAM | 1 MiB |
| System | eCos |
| HSGMII | Yes |
| Optics | SC/APC |
| IP address | 192.168.2.200/24 |
| Web Gui | No |
| SSH | No |
| Telnet | ✅ user `admin`, password `admin` |
| Serial | ✅ on SFP, only TX |
| Serial baud | 115200 |
| Serial encoding | 8-N-1 |
| Form Factor | miniONT SFP |


{% include image.html file="fgs202.jpg" alt="Sercomm FGS202" caption="Sercomm FGS202" %}
{% include image.html file="fgs202_teardown.jpg" alt="Sercomm FGS202 teardown" caption="Sercomm FGS202 teardown" %}

## Serial

The stick has a TTL 3.3v UART console (configured as 115200 8-N-1) that can be accessed from the SFP connector.

| USB TTL(UART) Adapter | SFP 20pins Molex connector |
| --------------------- | -------------------------- |
| 3.3V | pin #15 and #16 |
| TX | pin #3 |
| RX | pin #6 |
| GND | pin #14 and #10 |

## Telnet Access

The stick has telnet available only on the PON side, the only way to access it is by using an OLT.
The stick has telnet available only on the PON side by default, the only way to access it is by using an OLT.

eCos will request its IP via DHCP client once OMCI provisions IP-Host interface.

Telnet access on LAN side can be unlocked by modifying factory environment variable `ft_flag` to 1.

## List of software versions
- SCOMFGS202112 (Orange France)
- SCOMFGS202305 (TIM Italy)
- SCOMFGS202304 (TIM Italy)

Expand Down Expand Up @@ -110,6 +128,41 @@ Alarms = -
Set command exectue successfully.
```

## Getting ONU GPON PLOAM password
PLOAM Password at offset 0x1B8-0x1C1

```sh
FGS202:/# show i2c (ASCII view added for readability)
00000000: 0304 0100 0000 0000 0000 0003 0c00 14c8 ................
00000010: 0000 0000 5345 5243 4f4d 4d20 2020 2020 ....SERCOMM
00000020: 2020 2020 0000 0000 4647 5332 3032 2020 ....FGS202
00000030: 2020 2020 2020 2020 3030 3031 051e 00c1 0001....
00000040: 001a 0000 5343 4f4d 4131 4232 4333 4434 ....SCOMA1B2C3D4
00000050: 2020 2020 3137 3033 3238 2020 6cf0 0549 170328 l..I
00000060: 2020 2020 2020 2020 2020 2020 2020 2020
00000070: 2020 2020 2020 2020 2020 2020 2020 2020
00000080: 0000 0000 0000 0000 0000 0000 0000 0000 ................
*
00000100: 5000 fb00 4b00 0000 8ca0 7530 878c 7a44 P...K.....u0..zD
00000110: 88b8 0000 7530 0000 9b82 22d0 7b86 2bd4 ....u0....\".{.+.
00000120: 07cb 000c 0630 000f 0000 0000 0000 0000 .....0..........
00000130: 0000 0000 0000 0000 0000 0000 0000 0000 ................
00000140: 0000 0000 3f80 0000 0000 0000 0100 0000 ....?...........
00000150: 0100 0000 0100 0000 0100 0000 0000 0012 ................
00000160: 18d9 80e8 157f 0000 0000 0000 0000 0200 ................
00000170: 0140 0000 0140 0000 0000 0000 0000 0000 .@...@..........
00000180: 0000 0100 4647 5332 3032 2020 2020 2020 ....FGS202
00000190: 2020 2020 2020 2020 5343 4f4d 4647 5332 SCOMFGS2
000001a0: 3032 7631 2020 0100 0000 0000 18d9 0000 02v1 ..........
000001b0: 0000 0000 0000 0000 3938 3736 3534 3332 ........98765432
000001c0: 3130 004f 5241 4e47 4553 434f 4d46 4753 10.ORANGESCOMFGS
000001d0: 3230 3231 3132 0000 5343 4f4d 4647 5332 202112..SCOMFGS2
000001e0: 3032 3131 3200 ff00 0000 1000 0000 0000 02112...........
000001f0: 0000 0000 0000 0000 0000 0000 0000 0020 ...............

It can also be read and written using an external I2C reader.
```

# Advanced settings

## Showing live OMCI messages
Expand All @@ -123,6 +176,56 @@ ploam ds|ff 01 20 00 00 aa ab 59 83 20 00 00
1970-01-01 02:34:53 ploam ds: onu id - 255 / UpstreamOverhead
```

## Editing flash environment data
Simple U-Boot-style storage `key=value\0` padded by 0xFF, after modification, a new CRC32 checksum is required.

```py
from zlib import crc32
wholeflash = open("FGS202.bin", "rb").read() # Full SPI dump
ubootenv = wholeflash[262144:262144+65536] # 0x40000-0x5FFFF
factoryenv = wholeflash[327680:327680+65536] # 0x50000-0x6FFFF
ecosenv = wholeflash[393216:393216+65536] # 0x60000-0x7FFFF

print(f'U-Boot\n| CRC: {ubootenv[0:4].hex()} | Version {ubootenv[4:5]} | New CRC: {crc32(ubootenv[5:]):08x} ')
print(f'Factory\n| CRC: {factoryenv[0:4].hex()} | Version {factoryenv[4:5]} | New CRC: {crc32(factoryenv[5:]):08x} ')
print(f'eCos\n| CRC: {ecosenv[0:4].hex()} | Version {ecosenv[4:5]} | New CRC: {crc32(ecosenv[5:]):08x} ')
```

## Decrypting "encrypt_data" variable from flash

PLOAM and telnet passwords are hidden inside encrypt_data container.

Contents can be decrypted and encrypted by building a key from known device parameters.

```py
import hashlib
from Crypto.Cipher import AES

# from Factory environ
ethaddr = "78:94:B4:27:5F:2A"
nSerial = "SCOM21040A14"
# from Config environ
encrypt_data = bytes.fromhex("23cc5d5da799673708e443594e06272ffde3f449061bff7604c32cd50a186e19")

alphabet = "93axcdz25efhiv87ykmuj46stpbw"
digest = hashlib.md5(f"{ethaddr}{nSerial}".encode()).digest().hex()
key = bytes(ord(alphabet[ord(c) % 28]) for c in digest)
cipher = AES.new(key[:16], AES.MODE_CBC, iv=b'\x00'*16)
print( cipher.decrypt(encrypt_data) )
```

## Putting stick into firmware download mode
From telnet using hidden command `sercomm_download` will set environment variable `sc_dl` to 1 and reboot the stick.

At boot time, this variable is read by the modified U-Boot and waits for [sercomm-recovery](https://github.com/danitool/sercomm-recovery)

Due to an uninitialized SFP EEPROM, a simple SFP-to-Ethernet converter is required.

The input for sercomm-recovery tool must be a complete dump of complete flash memory, the client writes only the Image0 and Image1 regions, and the rest is skipped (so a failed write will drop you back into recovery).

It is not possible to exit this mode until the write operation completes or the environment settings are manually reset to 0.


# Hardware Modding

- Pin 7 GND → VCC [Fibra.Click - FAQ: 2.5Gbps su singolo dispositivo su Tim, Vodafone, Fastweb/JustSpeed](https://forum.fibra.click/d/27574-faq-25gbps-su-singolo-dispositivo-su-timvodafonefastwebjustspeed/18)
Expand All @@ -132,7 +235,7 @@ ploam ds|ff 01 20 00 00 aa ab 59 83 20 00 00

- [Support for GPON SFP FGS202](https://forum.openwrt.org/t/support-for-gpon-sfp-fgs202/42641/60)
- [SerComm FGS202](https://wikidevi.wi-cat.ru/SerComm_FGS202)

- [Modding FGS202 firmware](https://github.com/Troll338cz/CTN_GPON/tree/main/Sercomm/FGS202/SCOMFGS202112-telnet)



Loading
Loading