Thread Rating:
  • 1 Vote(s) - 1 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Arris TG2492 (VM Super hub 3)
emantec Offline
Junior Member
**

Posts: 6
Threads: 1
Joined: Sep 2018
Reputation: 0
#1
Arris TG2492 (VM Super hub 3)
I've been doing some research on this cable modem in the hope of getting access to the firmware but I've hit a road block so hoping someone here has the knowledge/skills to crack this open. 

A decent breakdown of the modem can be found here which includes a mostly complete list of components and UART output: 
https://www.mobile-computer-repairs.co.u...ris-TG2492 

Having also checked myself I can confirm the console is locked, there's seemingly no way to stop or interrupt the boot script and no input is accepted. 

I then proceeded to desolder the nand and attempted to dump it. Unfortunately it would appear the nand is encrypted but for those interested you can get it here:
https://mega.nz/#!qZ5nETaI!QqGD5XRCeLUAtiDTqh3xJ17IwlnWcystaSf--kC4vy8

At this point I'm not sure how to proceed, with the nand being encrypted I tried to get some information on the eMMC chip Phison PS8211-0 but there doesn't appear to be any public information or data sheet. Does anyone know if this is what handles the nand encryption or is it being done at a bootloader level?

The only interesting information I could find was this anonymous pastebin which would appear to be from a fritzbox modem 

https://pastebin.com/GZDdJRPs

Code:
4    /etc/mmc/PS8211/phison_fw/PS8211_SLC_BFW_A.BIN
4    /etc/mmc/PS8211/phison_fw/PS8211_SLC_BFW_B.BIN
4    /etc/mmc/PS8211/phison_fw/phison.cfg
4    /etc/mmc/PS8211/read_image_version.sh
4    /etc/mmc/PS8211/read_mmc_fw_version.sh
4    /etc/mmc/PS8211/upgrade_mmc_fw.sh

It doesn't say what fritzbox modem this came from but obtaining a copy of the eMMC firmware would likely be useful in decrypting the nand.
(This post was last modified: 07-09-2018, 08:36 PM by emantec.)
07-09-2018, 08:32 PM
Find Reply
ricktendo Offline
Senior Member
****

Posts: 223
Threads: 12
Joined: Apr 2014
Reputation: 20
#2
RE: Arris TG2492 (VM Super hub 3)
If only the bootloader weren't encrypted it could be possible to mod it to be "noisy" (display output and allow input/interrupt) but it appears the bootloader is also encrypted?
08-09-2018, 02:19 PM
Find Reply
emantec Offline
Junior Member
**

Posts: 6
Threads: 1
Joined: Sep 2018
Reputation: 0
#3
RE: Arris TG2492 (VM Super hub 3)
(08-09-2018, 02:19 PM)ricktendo Wrote: If only the bootloader weren't encrypted it could be possible to mod it to be "noisy" (display output and allow input/interrupt) but it appears the bootloader is also encrypted?

Would assume the bootloader is the first/second page of the nand dump which would appear to be encrypted.
08-09-2018, 02:21 PM
Find Reply
drewmerc Offline
Prefect
******

Posts: 3,867
Threads: 18
Joined: Oct 2008
Reputation: 157
#4
RE: Arris TG2492 (VM Super hub 3)
have you considered crashing the bootloader after uboot has loaded, i'd start with connecting read-enable to ground with luck it'll crash to a uboot prompt
__________________________________________________________________________________
still retired but while stuff is currently interesting i'll give this a try https://discord.gg/gNyRVKW
09-09-2018, 05:59 PM
Website Find Reply
emantec Offline
Junior Member
**

Posts: 6
Threads: 1
Joined: Sep 2018
Reputation: 0
#5
RE: Arris TG2492 (VM Super hub 3)
Was thinking about how to do that (couldn't find any public information) so I'll give that a try!
Need to wait for a replacement to arrive first though, currently disassembling current one to trace jtag.
(This post was last modified: 09-09-2018, 06:11 PM by emantec.)
09-09-2018, 06:10 PM
Find Reply
ricktendo Offline
Senior Member
****

Posts: 223
Threads: 12
Joined: Apr 2014
Reputation: 20
#6
RE: Arris TG2492 (VM Super hub 3)
Do you have a JTAGulator or something similar?

If not how do you go about finding the JTAG pinout without something like it?
09-09-2018, 08:20 PM
Find Reply
emantec Offline
Junior Member
**

Posts: 6
Threads: 1
Joined: Sep 2018
Reputation: 0
#7
RE: Arris TG2492 (VM Super hub 3)
(09-09-2018, 08:20 PM)ricktendo Wrote: Do you have a JTAGulator or something similar?

If not how do you go about finding the JTAG pinout without something like it?

It's on its way Wink
09-09-2018, 08:33 PM
Find Reply
blacklisted Offline
Junior Member
**

Posts: 3
Threads: 0
Joined: Oct 2018
Reputation: 0
#8
RE: Arris TG2492 (VM Super hub 3)
update @emantec
02-11-2018, 11:52 AM
Find Reply
emantec Offline
Junior Member
**

Posts: 6
Threads: 1
Joined: Sep 2018
Reputation: 0
#9
RE: Arris TG2492 (VM Super hub 3)
JTAGulator didn't work, managed to work out a way to dump unencrypted firmware though so currently investigating a exploit to allow remote root access.
02-11-2018, 11:59 AM
Find Reply
andy m Offline
Senior Member
****

Posts: 161
Threads: 7
Joined: Dec 2008
Reputation: 4
#10
RE: Arris TG2492 (VM Super hub 3)
upload the dump . how have you get the dump from the route it self
03-11-2018, 09:27 AM
Find Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)