16-10-2011, 07:59 PM
16-10-2011, 08:18 PM
what chipset is it? take some pictures of the board as honestly only thing i can find about the modem is that it has a ttl port?
17-10-2011, 12:41 AM
TNETC4401 (TI DOCSIS chip), some one-chip tuner, etc. it has ttl and jtag port. I've been tinkering with one. They are dumpable via jtag. The firmware is VxWorks on mine. They have a nice console you can access via telnet.
.
.
Here's the innards.
.
![[Image: PA160180.jpg]](http://i302.photobucket.com/albums/nn87/acmelectronics/sbh/PA160180.jpg)
.
.
Here's the innards.
.
![[Image: PA160180.jpg]](http://i302.photobucket.com/albums/nn87/acmelectronics/sbh/PA160180.jpg)
17-10-2011, 09:23 AM
do you wish to share your dump as i want to see were the certs are located and check there size to see if they are compatable
17-10-2011, 12:58 PM
Okay, attached. I edited the obviously viewable hex/ascii mac addresses with xxxxxx, I may have missed some obfuscated ones 
Logs are located @ 0x1F0000 and 0xC000 ("ELOG" ascii header).
dual images @ 0x10000 + 0x100000 ("TiZp" ascii header)
I cant figure out the damn compression routine! ...zlib, lzma, gz, ???

Logs are located @ 0x1F0000 and 0xC000 ("ELOG" ascii header).
dual images @ 0x10000 + 0x100000 ("TiZp" ascii header)
I cant figure out the damn compression routine! ...zlib, lzma, gz, ???
06-11-2011, 03:48 AM
and what ?? any info ? any update ?
08-11-2011, 01:56 PM
What sort of update are you looking for?
04-12-2012, 03:02 AM
will be interesting to also know the OID this models uses. this is the same as SMC networks made by Hitron Technologies, use same processor and it has telnet open with same commands.. i play a little with one of those but not long enough since i had to return it to the owner.
they have port 162 open.. so if we discover the OID they use.. with snmp it's possible to extract all certs easily...without any fisical intervention
btw any info about where are located the certs in the dump ?
My Best Regards
they have port 162 open.. so if we discover the OID they use.. with snmp it's possible to extract all certs easily...without any fisical intervention
btw any info about where are located the certs in the dump ?
My Best Regards