<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/">
	<channel>
		<title><![CDATA[Haxorware Forums - Modems]]></title>
		<link>http://www.haxorware.com/forums/</link>
		<description><![CDATA[Haxorware Forums - http://www.haxorware.com/forums]]></description>
		<pubDate>Tue, 22 Sep 2026 07:43:26 +0000</pubDate>
		<generator>MyBB</generator>
		<item>
			<title><![CDATA[How to extract certificates and keys from Puma 6 devices]]></title>
			<link>http://www.haxorware.com/forums/showthread.php?tid=13308</link>
			<pubDate>Fri, 14 Feb 2025 16:01:07 +0100</pubDate>
			<dc:creator><![CDATA[<a href="http://www.haxorware.com/forums/member.php?action=profile&uid=349120">EngTester</a>]]></dc:creator>
			<guid isPermaLink="false">http://www.haxorware.com/forums/showthread.php?tid=13308</guid>
			<description><![CDATA[Hi everyone!<br />
<br />
New members of the forum.  It's been a while since I actively participated.  I am familiar with the extraction of certs and keys from SB5101 using CMNonVol but now we are in a different age.<br />
<br />
I have a legit Puma 6 and I want to be able to extract its certs and keys to begin testing again but I have no clue how.<br />
<br />
Does anyone have a guide on how to extract these from Puma 6 modems?  You can share it via PM if you don't want to make it public.  I'll really appreciate it.<br />
<br />
My plan is to develop some tools for learning/testing on DOCSIS 3.0.<br />
<br />
Take care!]]></description>
			<content:encoded><![CDATA[Hi everyone!<br />
<br />
New members of the forum.  It's been a while since I actively participated.  I am familiar with the extraction of certs and keys from SB5101 using CMNonVol but now we are in a different age.<br />
<br />
I have a legit Puma 6 and I want to be able to extract its certs and keys to begin testing again but I have no clue how.<br />
<br />
Does anyone have a guide on how to extract these from Puma 6 modems?  You can share it via PM if you don't want to make it public.  I'll really appreciate it.<br />
<br />
My plan is to develop some tools for learning/testing on DOCSIS 3.0.<br />
<br />
Take care!]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[What ECC algorithm is used in Arris TG1672G NAND ?]]></title>
			<link>http://www.haxorware.com/forums/showthread.php?tid=13100</link>
			<pubDate>Sat, 28 Dec 2024 02:10:45 +0100</pubDate>
			<dc:creator><![CDATA[<a href="http://www.haxorware.com/forums/member.php?action=profile&uid=32942">Eugene@</a>]]></dc:creator>
			<guid isPermaLink="false">http://www.haxorware.com/forums/showthread.php?tid=13100</guid>
			<description><![CDATA[Hello,<br />
I have multiple dumps from multiple devices, and I see that some dumps have 52 bytes in OOB (spare), some 56 and a gap with multiple FF in the middle... Unfortunately I was not able to verify ECC using different tools.<br />
Does it use proprietary algorithm ?<br />
I also tried to feed a dump with OOB removed to binwalk, it was not able to find anything there  <img src="http://www.haxorware.com/forums/images/smilies/huh.gif" alt="Huh" title="Huh" class="smilie smilie_17" />]]></description>
			<content:encoded><![CDATA[Hello,<br />
I have multiple dumps from multiple devices, and I see that some dumps have 52 bytes in OOB (spare), some 56 and a gap with multiple FF in the middle... Unfortunately I was not able to verify ECC using different tools.<br />
Does it use proprietary algorithm ?<br />
I also tried to feed a dump with OOB removed to binwalk, it was not able to find anything there  <img src="http://www.haxorware.com/forums/images/smilies/huh.gif" alt="Huh" title="Huh" class="smilie smilie_17" />]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[AlphaMoD r0t83r]]></title>
			<link>http://www.haxorware.com/forums/showthread.php?tid=12629</link>
			<pubDate>Mon, 02 Dec 2024 23:42:14 +0100</pubDate>
			<dc:creator><![CDATA[<a href="http://www.haxorware.com/forums/member.php?action=profile&uid=200754">elmacizo</a>]]></dc:creator>
			<guid isPermaLink="false">http://www.haxorware.com/forums/showthread.php?tid=12629</guid>
			<description><![CDATA[hello all of you, Happy holidays.<br />
here it's my situation....  i got one modem sb6141 with firmware AlphaMoD rot83r <br />
i need to change the certs but it has a password and of course i don't have the password, the guy who sold the modem to me change he's mobile number so i can't get in touch with him.<br />
Can some one help me with the password ? please and Thank you in advance.]]></description>
			<content:encoded><![CDATA[hello all of you, Happy holidays.<br />
here it's my situation....  i got one modem sb6141 with firmware AlphaMoD rot83r <br />
i need to change the certs but it has a password and of course i don't have the password, the guy who sold the modem to me change he's mobile number so i can't get in touch with him.<br />
Can some one help me with the password ? please and Thank you in advance.]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[virgin media in the uk]]></title>
			<link>http://www.haxorware.com/forums/showthread.php?tid=10624</link>
			<pubDate>Sun, 14 Jul 2024 20:05:00 +0200</pubDate>
			<dc:creator><![CDATA[<a href="http://www.haxorware.com/forums/member.php?action=profile&uid=2390">shocky</a>]]></dc:creator>
			<guid isPermaLink="false">http://www.haxorware.com/forums/showthread.php?tid=10624</guid>
			<description><![CDATA[been quite a while since i have been on here and how things have changed.<br />
managed to log in to my discord and checked the group drewmerc set up and shit! its full of idiots posting edited porn!<br />
anyways, just wondering if anything as progressed with uncapping and modding of the new vm superhubs?<br />
any work arounds using the usbjtag nt on any of them? or is it still emmc card reader or something if i remember right?<br />
is there anything i really should be reading up on before delving any deeper?<br />
also a big shout out to the old skoolers if any are still on here from back in the sb101e days<br />
<br />
many thanks to all who read this post]]></description>
			<content:encoded><![CDATA[been quite a while since i have been on here and how things have changed.<br />
managed to log in to my discord and checked the group drewmerc set up and shit! its full of idiots posting edited porn!<br />
anyways, just wondering if anything as progressed with uncapping and modding of the new vm superhubs?<br />
any work arounds using the usbjtag nt on any of them? or is it still emmc card reader or something if i remember right?<br />
is there anything i really should be reading up on before delving any deeper?<br />
also a big shout out to the old skoolers if any are still on here from back in the sb101e days<br />
<br />
many thanks to all who read this post]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[i used to hack the old Ambit 256 can virgin still be done ?]]></title>
			<link>http://www.haxorware.com/forums/showthread.php?tid=9710</link>
			<pubDate>Tue, 09 Jan 2024 21:45:53 +0100</pubDate>
			<dc:creator><![CDATA[<a href="http://www.haxorware.com/forums/member.php?action=profile&uid=245277">halfwit88</a>]]></dc:creator>
			<guid isPermaLink="false">http://www.haxorware.com/forums/showthread.php?tid=9710</guid>
			<description><![CDATA[i used to hack the old Ambit 255 with the hax0ware back and the day and sniff macs etc.? what is the story with that these day can it still be done? maybe there is a new fibreware alphaware or something.. it must be 13 years ago now]]></description>
			<content:encoded><![CDATA[i used to hack the old Ambit 255 with the hax0ware back and the day and sniff macs etc.? what is the story with that these day can it still be done? maybe there is a new fibreware alphaware or something.. it must be 13 years ago now]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Console command to check corrected/uncorrected errors]]></title>
			<link>http://www.haxorware.com/forums/showthread.php?tid=9698</link>
			<pubDate>Wed, 20 Dec 2023 22:46:44 +0100</pubDate>
			<dc:creator><![CDATA[<a href="http://www.haxorware.com/forums/member.php?action=profile&uid=29776">nden</a>]]></dc:creator>
			<guid isPermaLink="false">http://www.haxorware.com/forums/showthread.php?tid=9698</guid>
			<description><![CDATA[Is there a console command to check for corrected/uncorrected errors on DS/US channels using forceWare?<br />
Thanks]]></description>
			<content:encoded><![CDATA[Is there a console command to check for corrected/uncorrected errors on DS/US channels using forceWare?<br />
Thanks]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[coda45 dump]]></title>
			<link>http://www.haxorware.com/forums/showthread.php?tid=9664</link>
			<pubDate>Thu, 23 Nov 2023 21:56:42 +0100</pubDate>
			<dc:creator><![CDATA[<a href="http://www.haxorware.com/forums/member.php?action=profile&uid=238104">QuantumSeeker</a>]]></dc:creator>
			<guid isPermaLink="false">http://www.haxorware.com/forums/showthread.php?tid=9664</guid>
			<description><![CDATA[Can somebody upload a hitron coda45 emmc dump?]]></description>
			<content:encoded><![CDATA[Can somebody upload a hitron coda45 emmc dump?]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[SB5101i question]]></title>
			<link>http://www.haxorware.com/forums/showthread.php?tid=9537</link>
			<pubDate>Fri, 14 Jul 2023 22:08:20 +0200</pubDate>
			<dc:creator><![CDATA[<a href="http://www.haxorware.com/forums/member.php?action=profile&uid=219554">CP1832</a>]]></dc:creator>
			<guid isPermaLink="false">http://www.haxorware.com/forums/showthread.php?tid=9537</guid>
			<description><![CDATA[Hi guys:<br />
<br />
Someone in my building moved out and threw away a Motorola SB5101i. Do you know if haxorware will still work on it? Is the flashing method any different from the ones I found in the forum for SB5101 or is it different somehow?]]></description>
			<content:encoded><![CDATA[Hi guys:<br />
<br />
Someone in my building moved out and threw away a Motorola SB5101i. Do you know if haxorware will still work on it? Is the flashing method any different from the ones I found in the forum for SB5101 or is it different somehow?]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[ALPHAWARE]]></title>
			<link>http://www.haxorware.com/forums/showthread.php?tid=9395</link>
			<pubDate>Sun, 19 Feb 2023 21:18:59 +0100</pubDate>
			<dc:creator><![CDATA[<a href="http://www.haxorware.com/forums/member.php?action=profile&uid=25173">espaun206</a>]]></dc:creator>
			<guid isPermaLink="false">http://www.haxorware.com/forums/showthread.php?tid=9395</guid>
			<description><![CDATA[Hi<br />
<br />
Do you know how to change the hfc mac in ALPHAWARE REV8?]]></description>
			<content:encoded><![CDATA[Hi<br />
<br />
Do you know how to change the hfc mac in ALPHAWARE REV8?]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[BW Rotator 2022...1682...1670...1602...sbg10.etc]]></title>
			<link>http://www.haxorware.com/forums/showthread.php?tid=9308</link>
			<pubDate>Thu, 29 Dec 2022 09:57:11 +0100</pubDate>
			<dc:creator><![CDATA[<a href="http://www.haxorware.com/forums/member.php?action=profile&uid=10988">infinity08</a>]]></dc:creator>
			<guid isPermaLink="false">http://www.haxorware.com/forums/showthread.php?tid=9308</guid>
			<description><![CDATA[New Years!!!!!!!!! Gift!!!!!!!!!!!PM]]></description>
			<content:encoded><![CDATA[New Years!!!!!!!!! Gift!!!!!!!!!!!PM]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[stock firmware ??]]></title>
			<link>http://www.haxorware.com/forums/showthread.php?tid=9298</link>
			<pubDate>Wed, 21 Dec 2022 20:24:27 +0100</pubDate>
			<dc:creator><![CDATA[<a href="http://www.haxorware.com/forums/member.php?action=profile&uid=15065">Rickz</a>]]></dc:creator>
			<guid isPermaLink="false">http://www.haxorware.com/forums/showthread.php?tid=9298</guid>
			<description><![CDATA[Regards,<br />
<br />
looking for firmware with the tech_support_cgi page<br />
not matter version<br />
<br />
arris tg862g<br />
<br />
anyone?<br />
<br />
Merry Chistmass]]></description>
			<content:encoded><![CDATA[Regards,<br />
<br />
looking for firmware with the tech_support_cgi page<br />
not matter version<br />
<br />
arris tg862g<br />
<br />
anyone?<br />
<br />
Merry Chistmass]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[CODA-4582 Test Mode]]></title>
			<link>http://www.haxorware.com/forums/showthread.php?tid=9260</link>
			<pubDate>Thu, 17 Nov 2022 23:46:51 +0100</pubDate>
			<dc:creator><![CDATA[<a href="http://www.haxorware.com/forums/member.php?action=profile&uid=170860">Rolph_Asudio</a>]]></dc:creator>
			<guid isPermaLink="false">http://www.haxorware.com/forums/showthread.php?tid=9260</guid>
			<description><![CDATA[Hello, I have a Hitron CODA-4582 that boots to a CLI, but from what I can tell the shell is running on the arm cpu and the atom cpu with the interesting stuff isn't accessible. <br />
<br />
I was able mount some of the partitions on the nvram and it seems there's a program for interacting between the arm and atom, 'ncpu_exec', but it's not present in any of the bin directories. Any clues for next steps? I don't really have an end goal here, just poking around. Originally I wanted to be able to encrypt/decrypt the config for a separate modem, a coda-4680 and so I found the functions on this one for encrypting and decrypting but it doesn't seem to be the same for the 4680.<br />
<br />
Some output:<br />
<br />
<div class="codeblock"><div class="title">Code:</div><div class="body" dir="ltr"><code>&gt;&gt;&gt;<br />
Console, CLI version 1.0.0.5<br />
Type 'help' for list of commands<br />
<br />
mainMenu&gt; help<br />
Console Commands for this level:<br />
 system               - Go to system Menu.<br />
 logger               - Go to Logger Menu.<br />
 eventm               - Go to Event Manager Menu.<br />
 getManifest          - Prints manifest.<br />
 version              - prints system version.<br />
 docsis               - Go to DOCSIS Menu.<br />
 help                 - Display menu commands, with optional &lt;cmd&gt;, displays only matching commands.<br />
 shortcuts            - Display key shortcuts help.<br />
 exit                 - Exit this sub-menu, go to previous menu.<br />
 shell                - Enter Linux shell [&lt;Linux Command&gt;]<br />
         without parameters CLI stays running in the background.<br />
 quit                 - Quit and terminate CLI.<br />
 reboot               - Reboot the system.<br />
 batch                - execute batch of CLI commands from file<br />
         &lt;filename&gt; - the file may contain comment lines starting with # character<br />
         [&lt;on/off&gt;] - verbose commands printing.<br />
 wait                 - wait for &lt;msec&gt;.<br />
 /&lt;search expression&gt; - '/' allows search of CLI Help for any command using grep like search.<br />
mainMenu&gt;</code></div></div><br />
<br />
<div class="codeblock"><div class="title">Code:</div><div class="body" dir="ltr"><code>Cougar Mountain B0 - Boot Ram. <br />
Version: 0.3.3 (Apr 24 2017, 14:24:33)<br />
Boot Param memory dump:<br />
[0xFFFF3FFC] - 0x00030003<br />
[0xFFFF3FF8] -FFF3FC0] - 0x00000000<br />
[0xFFFF3FBC] - 0x00000001<br />
[0xFFFF3FB8] - 0x00000007<br />
[0xFFFF3FB4] - 0x00000000<br />
[0xFFFF3FB0] - 0x0000000 done, booting the kernel.<br />
systemd 216 running in system mode. (-PAM -AUDIT -SELINUX -IMA -APPARMOR -SMACK +SYSVINIT -LIBCRYPTSETUP -GCRYPT -GNUTLS -ACL -XZ -LZ4 -SECCOMP -BLKID -ELFUTILS -KMOD -IDN )[[32m  OK  [0m] Reached target Remote File Systems.<br />
[[32m  OK  [0m] Reached target Paths.<br />
[[32m  OK  [0m] Reached target[[32m  OK  [0m] Created slice Root Slice.<br />
[[32m  OK  [0m] Listening on /dev/initctl Compatibility Named Pipe.<br />
[[32m  OK  [0m] LPuma filesystem setup...<br />
         Starting Remount Root and Kernel File Systems...<br />
         Starting Adjusting Puma kernel set         Starting Apply Kernel Variables...<br />
         Starting Create Static Device Nodes in /dev...<br />
         Starting udev Coldplu Starting Journal Service...<br />
[[32m  OK  [0m] Started Journal Service.<br />
[[32m  OK  [0m] Reached target Slices.<br />
         Mounting Temporary Directory...<br />
[[32m  OK  [0m] Started Apply Kernel Variables.<br />
[[32m  OK  [0m] Started Create Static Device Nodes in /dev.<br />
[[32m  OK  [0m] Started Remount Root and Kernel File Systems.<br />
[[32m  OK  [0m] Mounted Temporary Directory.<br />
<br />
About to set realtime runtime...<br />
<br />
[[32m  OK  [0m] Started udev Coldplug all Devices.<br />
[[32m  OK  [0m] Reached target Loc         Starting udev Kernel Device Manager...<br />
[[32m  OK  [0m] Started Adjusting Puma kernel settings.<br />
[[32m  OK  [0m] Mounted /var/volatile.<br />
[[32m  OK  [0m] Started udev Kernel Device Manager.<br />
mount -t ext3 /dev/mmcblk0p16 /nvram -o data=journal -o barrier=1<br />
/dev/mmcblk0p16 mounted successfuly to /nvram<br />
[[32m  OK  [0m] Started Puma filesystem setup.<br />
         Starting Bind mount volatile /var/lib...<br />
         Starting Bind mount volatile /etc/passwd...<br />
         Starting Bind mount volatile /etc/shadow...<br />
[[32m  OK  [0m] Started Bind mount volatile /var/lib.<br />
[[32m  OK  [0m] Started Bind mount volatile /etc/passwd.<br />
[[32m  OK  [0m] Started Bind mount volatile /etc/shadow.<br />
[[32m  OK  [0m] Reached target Local File Systems.<br />
         Starting Trigger Flushing of Journal to Persistent Storage...<br />
         Starting Create Volatile Files and Directories...<br />
Directories.<br />
         Starting Puma setup...<br />
==========================================<br />
Intel DGWSDK release SW_VERSION_SILICON.7.1.1.37<br />
Build date: Thursday, April 29 202Copyright (c) 2011, Intel Corporation.<br />
========================================================<br />
<br />
<br />
[[32m  OK  [0m] Started Trigger Flushing of Journal to Persistent Storage.<br />
[[32m  OK  [0m] Started Update UTMP about System Boot/Shutdown.<br />
[[32m  OK  [0m] Reached target System Initialization.<br />
[[32m  OK  [0m] Listening on D-Bus System Message Bus Socket.<br />
[[32m  OK  [0m] Reached target Timers.<br />
IMADISTRO_VERSION    = "3.1"<br />
DISTRO_NAME       = "DOCSIS 3.1 Cable Modem"<br />
TUNE_FEATURES     = "armv6 thumb bigendian arm1176jzs"<br />
8c7"<br />
meta-intelce-arm-common = "(nobranch):4ca5d296396942245b42581e6a573bb49506b454"<br />
meta-intelce-arm  = "(nobranch):310afa97cProductionDb_Init:2214 (pid=123): Restoring production DB from NVRAM ... SUCCESS<br />
ProductionDb_FrequencyPlanValidity:3081 (pid=1[[32m  OK  [0m] Started Puma setup.<br />
         Starting Puma Packet Processor Driver init...<br />
Setup memory config from file "/etc/sysctl_mem.conf" <br />
vm.panic_on_oom = 2<br />
vm.swappiness = 0<br />
vm.overcommit_memory = 2<br />
vm.overcommit_ratio = 100<br />
<br />
hil_drv should be running now ...<br />
<br />
<br />
The PP Doesn't exist in this image ...<br />
<br />
[[32m  OK  [0m[[32m  OK  [0m] Started Puma run validity checks.<br />
         Starting Handshake...<br />
<br />
Polling Atom Handshake Status...<br />
Waiting for packet processor on Atom... (0)<br />
<br />
<br />
<br />
Atom PP Initialization finished succussfully<br />
[[32m  OK  [0m] Started Handshake.<br />
         Starting Puma Start up...<br />
[DEBUG] main:93 puma_startup_mode STARTUP_MODE_FULL<br />
 <br />
[DEBUG] HWMB_Start:563 Start. Socket type SOCK_COMMANDER<br />
[DEBUG] HWMB_i HWMB_sendRecvMsg:427 Send-Recv message...<br />
[DEBUG] HWMB_sendRecvMsg:429 Sending message... [msgSize=8]<br />
[DEBUG] HWMB_sendMsg:28==<br />
[DEBUG] HWMB_sendRecvMsg:446 Receiving reply message...<br />
[DEBUG] HWMB_recvMsg:348 Receiving message...<br />
[DEBUG] HWMB_recvMsgng received HW_MBox message <br />
[DEBUG] ParseAck:44 ACK received <br />
[DEBUG] main:102 Done sending startup mode to Atom via HW_MBox Using DOCSIS Initialization process parameters: -debug1option 43 -debug1option 50<br />
<br />
pcd: (184): Starting TI Process Control Daemon.<br />
[[32m  OK  [0m] Started Puma Start up.<br />
[[32m  OK  [0m] Reached target Sockets.<br />
[[32m  OK  [0m] Reached target Basic Syst[[32m  OK  [0m] Started D-Bus System Message Bus.<br />
pcd: (184): Loaded 97 rules.<br />
pcd: Initialization complete.<br />
nsmod (Rule DOCSIS_SOCIFDRV).<br />
pcd: (184): Starting process insmod (Rule DOCSIS_KINTR).<br />
pcd: (184): Starting process insmod (Rue SYSTEM_GPTIMER).<br />
pcd: (184): Starting process /usr/sbin/gim (Rule SYSTEM_GIM).<br />
pcd: (184): Rule SYSTEM_WATCHDOG: Success (PrTI Watchdog-RT daemon started &lt;kick interval = 10 seconds&gt;<br />
main:864 (pid=194): Initialized successfully<br />
<br />
pcd: (184): Rule SYSTEM_GPTIMER: Success (Process /usr/sbin/gptimer (194)).<br />
pcd: (184): Rule PUMA7SYSTEM_CRU_CTRL_MKNOD: Success (Process mknod (190)).<br />
gim_init:133 (pid=195): GIM initializing...<br />
gim_init:169 (pid=195): GIM initialization complete. GIM_MODULE=3087<br />
pcd: (184): Rule SYSTEM_GIM: Success (Process /usr/sbin/gim (195)).<br />
pcd: (184): Rule PUMA7SYSTEM_DATAPIPE_INSMOD: Success (Process insmod (189)).<br />
pcd: (184): Rule DOCSIS_SOCIFDRV: Success (Process insmod (187)).<br />
pcd: (184): Starting process mknod (Rule DOCSIS_MKNODSOCIFDRV).<br />
<br />
pcd: (184): Rule DOCSIS_KINTR: Success (Process insmod (188)).<br />
pcd: (184): Rule DOCSIS_MKNODSOCIFDRV: Success (Process mknod (212)).<br />
<br />
[[32m  OK  [0m] Reached target Multi-User System.<br />
         Starting Update UTMP about System Runlevel Changes...<br />
[[32m  OK  [0m] Started Update UTMP about System Runlevel Chan<br />
TI Logger: Init complete<br />
pcd: (184): Rule SYSTEM_LOGGER: Success (Process /usr/sbin/logger (193)).<br />
pcd: (184): Starting process /usr/sbin/hw_mbox_app (Rpcd: (184): Rule PUMA7SYSTEM_HW_MBOX_APP: Success (Process /usr/sbin/hw_mbox_app (222)).<br />
pcd: (184): Starting process /usr/sbinpcd: (184): Rule PUMASYSTEM_LASTRULE: Success.<br />
<br />
<br />
iniparser: cannot open /var/tmp/lsddb_rt.ini<br />
pcd: (184): Rule SYSTEM_SHMDBINIT: Success (Process /usr/sbin/shmdb_init_app (223)).<br />
pcd: (184): Starting process /usr/sbin/halpcpcd: (184): Rule PM_INIT_APP: Success (Process /usr/sbin/pm_init_app (247)).<br />
Can't open /proc/sys/kernel/printk: No such file or directory<br />
Failed to get printk console log level</code></div></div><br />
<br />
<div class="codeblock"><div class="title">Code:</div><div class="body" dir="ltr"><code>GPT fdisk (gdisk) version 1.0.1<br />
<br />
Partition table scan:<br />
  MBR: protective<br />
  BSD: not present<br />
  APM: not present<br />
  GPT: present<br />
<br />
Found valid GPT with protective MBR; using GPT.<br />
Disk /dev/mmcblk0: 1925120 sectors, 940.0 MiB<br />
Logical sector size: 512 bytes<br />
Disk identifier (GUID): 21126DBA-B4FF-4D7C-B8EF-64585FD41F3D<br />
Partition table holds up to 128 entries<br />
First usable sector is 34, last usable sector is 1894366<br />
Partitions will be aligned on 256-sector boundaries<br />
Total free space is 222 sectors (111.0 KiB)<br />
<br />
Number  Start (sector)    End (sector)  Size       Code  Name<br />
   3             256             511   128.0 KiB   8300  SIGBLOCK0<br />
   4             512           18943   9.0 MiB     EF00  APP_CPU_KERNEL0<br />
   5           18944          207359   92.0 MiB    8300  APP_CPU_ROOTFS0<br />
   6          207360          217599   5.0 MiB     8300  NP_CPU_KERNEL0<br />
   7          217600          250367   16.0 MiB    8300  NP_CPU_ROOTFS0<br />
   8          250368          332287   40.0 MiB    8300  GW_FS0<br />
   9          332288          332543   128.0 KiB   8300  SIGBLOCK1<br />
  10          332544          350975   9.0 MiB     EF00  APP_CPU_KERNEL1<br />
  11          350976          539391   92.0 MiB    8300  APP_CPU_ROOTFS1<br />
  12          539392          549631   5.0 MiB     8300  NP_CPU_KERNEL1<br />
  13          549632          582399   16.0 MiB    8300  NP_CPU_ROOTFS1<br />
  14          582400          664319   40.0 MiB    8300  GW_FS1<br />
  15          664320          758527   46.0 MiB    8300  APP_CPU_NVRAM<br />
  16          758528          875263   57.0 MiB    8300  NP_CPU_NVRAM<br />
  17          875264          916223   20.0 MiB    8300  APP_CPU_LOG<br />
  18          916224          957183   20.0 MiB    8300  NP_CPU_LOG<br />
  19          957184         1894366   457.6 MiB   8300  THIRD_PARTY_FS</code></div></div><br />
<br />
Thanks!]]></description>
			<content:encoded><![CDATA[Hello, I have a Hitron CODA-4582 that boots to a CLI, but from what I can tell the shell is running on the arm cpu and the atom cpu with the interesting stuff isn't accessible. <br />
<br />
I was able mount some of the partitions on the nvram and it seems there's a program for interacting between the arm and atom, 'ncpu_exec', but it's not present in any of the bin directories. Any clues for next steps? I don't really have an end goal here, just poking around. Originally I wanted to be able to encrypt/decrypt the config for a separate modem, a coda-4680 and so I found the functions on this one for encrypting and decrypting but it doesn't seem to be the same for the 4680.<br />
<br />
Some output:<br />
<br />
<div class="codeblock"><div class="title">Code:</div><div class="body" dir="ltr"><code>&gt;&gt;&gt;<br />
Console, CLI version 1.0.0.5<br />
Type 'help' for list of commands<br />
<br />
mainMenu&gt; help<br />
Console Commands for this level:<br />
 system               - Go to system Menu.<br />
 logger               - Go to Logger Menu.<br />
 eventm               - Go to Event Manager Menu.<br />
 getManifest          - Prints manifest.<br />
 version              - prints system version.<br />
 docsis               - Go to DOCSIS Menu.<br />
 help                 - Display menu commands, with optional &lt;cmd&gt;, displays only matching commands.<br />
 shortcuts            - Display key shortcuts help.<br />
 exit                 - Exit this sub-menu, go to previous menu.<br />
 shell                - Enter Linux shell [&lt;Linux Command&gt;]<br />
         without parameters CLI stays running in the background.<br />
 quit                 - Quit and terminate CLI.<br />
 reboot               - Reboot the system.<br />
 batch                - execute batch of CLI commands from file<br />
         &lt;filename&gt; - the file may contain comment lines starting with # character<br />
         [&lt;on/off&gt;] - verbose commands printing.<br />
 wait                 - wait for &lt;msec&gt;.<br />
 /&lt;search expression&gt; - '/' allows search of CLI Help for any command using grep like search.<br />
mainMenu&gt;</code></div></div><br />
<br />
<div class="codeblock"><div class="title">Code:</div><div class="body" dir="ltr"><code>Cougar Mountain B0 - Boot Ram. <br />
Version: 0.3.3 (Apr 24 2017, 14:24:33)<br />
Boot Param memory dump:<br />
[0xFFFF3FFC] - 0x00030003<br />
[0xFFFF3FF8] -FFF3FC0] - 0x00000000<br />
[0xFFFF3FBC] - 0x00000001<br />
[0xFFFF3FB8] - 0x00000007<br />
[0xFFFF3FB4] - 0x00000000<br />
[0xFFFF3FB0] - 0x0000000 done, booting the kernel.<br />
systemd 216 running in system mode. (-PAM -AUDIT -SELINUX -IMA -APPARMOR -SMACK +SYSVINIT -LIBCRYPTSETUP -GCRYPT -GNUTLS -ACL -XZ -LZ4 -SECCOMP -BLKID -ELFUTILS -KMOD -IDN )[[32m  OK  [0m] Reached target Remote File Systems.<br />
[[32m  OK  [0m] Reached target Paths.<br />
[[32m  OK  [0m] Reached target[[32m  OK  [0m] Created slice Root Slice.<br />
[[32m  OK  [0m] Listening on /dev/initctl Compatibility Named Pipe.<br />
[[32m  OK  [0m] LPuma filesystem setup...<br />
         Starting Remount Root and Kernel File Systems...<br />
         Starting Adjusting Puma kernel set         Starting Apply Kernel Variables...<br />
         Starting Create Static Device Nodes in /dev...<br />
         Starting udev Coldplu Starting Journal Service...<br />
[[32m  OK  [0m] Started Journal Service.<br />
[[32m  OK  [0m] Reached target Slices.<br />
         Mounting Temporary Directory...<br />
[[32m  OK  [0m] Started Apply Kernel Variables.<br />
[[32m  OK  [0m] Started Create Static Device Nodes in /dev.<br />
[[32m  OK  [0m] Started Remount Root and Kernel File Systems.<br />
[[32m  OK  [0m] Mounted Temporary Directory.<br />
<br />
About to set realtime runtime...<br />
<br />
[[32m  OK  [0m] Started udev Coldplug all Devices.<br />
[[32m  OK  [0m] Reached target Loc         Starting udev Kernel Device Manager...<br />
[[32m  OK  [0m] Started Adjusting Puma kernel settings.<br />
[[32m  OK  [0m] Mounted /var/volatile.<br />
[[32m  OK  [0m] Started udev Kernel Device Manager.<br />
mount -t ext3 /dev/mmcblk0p16 /nvram -o data=journal -o barrier=1<br />
/dev/mmcblk0p16 mounted successfuly to /nvram<br />
[[32m  OK  [0m] Started Puma filesystem setup.<br />
         Starting Bind mount volatile /var/lib...<br />
         Starting Bind mount volatile /etc/passwd...<br />
         Starting Bind mount volatile /etc/shadow...<br />
[[32m  OK  [0m] Started Bind mount volatile /var/lib.<br />
[[32m  OK  [0m] Started Bind mount volatile /etc/passwd.<br />
[[32m  OK  [0m] Started Bind mount volatile /etc/shadow.<br />
[[32m  OK  [0m] Reached target Local File Systems.<br />
         Starting Trigger Flushing of Journal to Persistent Storage...<br />
         Starting Create Volatile Files and Directories...<br />
Directories.<br />
         Starting Puma setup...<br />
==========================================<br />
Intel DGWSDK release SW_VERSION_SILICON.7.1.1.37<br />
Build date: Thursday, April 29 202Copyright (c) 2011, Intel Corporation.<br />
========================================================<br />
<br />
<br />
[[32m  OK  [0m] Started Trigger Flushing of Journal to Persistent Storage.<br />
[[32m  OK  [0m] Started Update UTMP about System Boot/Shutdown.<br />
[[32m  OK  [0m] Reached target System Initialization.<br />
[[32m  OK  [0m] Listening on D-Bus System Message Bus Socket.<br />
[[32m  OK  [0m] Reached target Timers.<br />
IMADISTRO_VERSION    = "3.1"<br />
DISTRO_NAME       = "DOCSIS 3.1 Cable Modem"<br />
TUNE_FEATURES     = "armv6 thumb bigendian arm1176jzs"<br />
8c7"<br />
meta-intelce-arm-common = "(nobranch):4ca5d296396942245b42581e6a573bb49506b454"<br />
meta-intelce-arm  = "(nobranch):310afa97cProductionDb_Init:2214 (pid=123): Restoring production DB from NVRAM ... SUCCESS<br />
ProductionDb_FrequencyPlanValidity:3081 (pid=1[[32m  OK  [0m] Started Puma setup.<br />
         Starting Puma Packet Processor Driver init...<br />
Setup memory config from file "/etc/sysctl_mem.conf" <br />
vm.panic_on_oom = 2<br />
vm.swappiness = 0<br />
vm.overcommit_memory = 2<br />
vm.overcommit_ratio = 100<br />
<br />
hil_drv should be running now ...<br />
<br />
<br />
The PP Doesn't exist in this image ...<br />
<br />
[[32m  OK  [0m[[32m  OK  [0m] Started Puma run validity checks.<br />
         Starting Handshake...<br />
<br />
Polling Atom Handshake Status...<br />
Waiting for packet processor on Atom... (0)<br />
<br />
<br />
<br />
Atom PP Initialization finished succussfully<br />
[[32m  OK  [0m] Started Handshake.<br />
         Starting Puma Start up...<br />
[DEBUG] main:93 puma_startup_mode STARTUP_MODE_FULL<br />
 <br />
[DEBUG] HWMB_Start:563 Start. Socket type SOCK_COMMANDER<br />
[DEBUG] HWMB_i HWMB_sendRecvMsg:427 Send-Recv message...<br />
[DEBUG] HWMB_sendRecvMsg:429 Sending message... [msgSize=8]<br />
[DEBUG] HWMB_sendMsg:28==<br />
[DEBUG] HWMB_sendRecvMsg:446 Receiving reply message...<br />
[DEBUG] HWMB_recvMsg:348 Receiving message...<br />
[DEBUG] HWMB_recvMsgng received HW_MBox message <br />
[DEBUG] ParseAck:44 ACK received <br />
[DEBUG] main:102 Done sending startup mode to Atom via HW_MBox Using DOCSIS Initialization process parameters: -debug1option 43 -debug1option 50<br />
<br />
pcd: (184): Starting TI Process Control Daemon.<br />
[[32m  OK  [0m] Started Puma Start up.<br />
[[32m  OK  [0m] Reached target Sockets.<br />
[[32m  OK  [0m] Reached target Basic Syst[[32m  OK  [0m] Started D-Bus System Message Bus.<br />
pcd: (184): Loaded 97 rules.<br />
pcd: Initialization complete.<br />
nsmod (Rule DOCSIS_SOCIFDRV).<br />
pcd: (184): Starting process insmod (Rule DOCSIS_KINTR).<br />
pcd: (184): Starting process insmod (Rue SYSTEM_GPTIMER).<br />
pcd: (184): Starting process /usr/sbin/gim (Rule SYSTEM_GIM).<br />
pcd: (184): Rule SYSTEM_WATCHDOG: Success (PrTI Watchdog-RT daemon started &lt;kick interval = 10 seconds&gt;<br />
main:864 (pid=194): Initialized successfully<br />
<br />
pcd: (184): Rule SYSTEM_GPTIMER: Success (Process /usr/sbin/gptimer (194)).<br />
pcd: (184): Rule PUMA7SYSTEM_CRU_CTRL_MKNOD: Success (Process mknod (190)).<br />
gim_init:133 (pid=195): GIM initializing...<br />
gim_init:169 (pid=195): GIM initialization complete. GIM_MODULE=3087<br />
pcd: (184): Rule SYSTEM_GIM: Success (Process /usr/sbin/gim (195)).<br />
pcd: (184): Rule PUMA7SYSTEM_DATAPIPE_INSMOD: Success (Process insmod (189)).<br />
pcd: (184): Rule DOCSIS_SOCIFDRV: Success (Process insmod (187)).<br />
pcd: (184): Starting process mknod (Rule DOCSIS_MKNODSOCIFDRV).<br />
<br />
pcd: (184): Rule DOCSIS_KINTR: Success (Process insmod (188)).<br />
pcd: (184): Rule DOCSIS_MKNODSOCIFDRV: Success (Process mknod (212)).<br />
<br />
[[32m  OK  [0m] Reached target Multi-User System.<br />
         Starting Update UTMP about System Runlevel Changes...<br />
[[32m  OK  [0m] Started Update UTMP about System Runlevel Chan<br />
TI Logger: Init complete<br />
pcd: (184): Rule SYSTEM_LOGGER: Success (Process /usr/sbin/logger (193)).<br />
pcd: (184): Starting process /usr/sbin/hw_mbox_app (Rpcd: (184): Rule PUMA7SYSTEM_HW_MBOX_APP: Success (Process /usr/sbin/hw_mbox_app (222)).<br />
pcd: (184): Starting process /usr/sbinpcd: (184): Rule PUMASYSTEM_LASTRULE: Success.<br />
<br />
<br />
iniparser: cannot open /var/tmp/lsddb_rt.ini<br />
pcd: (184): Rule SYSTEM_SHMDBINIT: Success (Process /usr/sbin/shmdb_init_app (223)).<br />
pcd: (184): Starting process /usr/sbin/halpcpcd: (184): Rule PM_INIT_APP: Success (Process /usr/sbin/pm_init_app (247)).<br />
Can't open /proc/sys/kernel/printk: No such file or directory<br />
Failed to get printk console log level</code></div></div><br />
<br />
<div class="codeblock"><div class="title">Code:</div><div class="body" dir="ltr"><code>GPT fdisk (gdisk) version 1.0.1<br />
<br />
Partition table scan:<br />
  MBR: protective<br />
  BSD: not present<br />
  APM: not present<br />
  GPT: present<br />
<br />
Found valid GPT with protective MBR; using GPT.<br />
Disk /dev/mmcblk0: 1925120 sectors, 940.0 MiB<br />
Logical sector size: 512 bytes<br />
Disk identifier (GUID): 21126DBA-B4FF-4D7C-B8EF-64585FD41F3D<br />
Partition table holds up to 128 entries<br />
First usable sector is 34, last usable sector is 1894366<br />
Partitions will be aligned on 256-sector boundaries<br />
Total free space is 222 sectors (111.0 KiB)<br />
<br />
Number  Start (sector)    End (sector)  Size       Code  Name<br />
   3             256             511   128.0 KiB   8300  SIGBLOCK0<br />
   4             512           18943   9.0 MiB     EF00  APP_CPU_KERNEL0<br />
   5           18944          207359   92.0 MiB    8300  APP_CPU_ROOTFS0<br />
   6          207360          217599   5.0 MiB     8300  NP_CPU_KERNEL0<br />
   7          217600          250367   16.0 MiB    8300  NP_CPU_ROOTFS0<br />
   8          250368          332287   40.0 MiB    8300  GW_FS0<br />
   9          332288          332543   128.0 KiB   8300  SIGBLOCK1<br />
  10          332544          350975   9.0 MiB     EF00  APP_CPU_KERNEL1<br />
  11          350976          539391   92.0 MiB    8300  APP_CPU_ROOTFS1<br />
  12          539392          549631   5.0 MiB     8300  NP_CPU_KERNEL1<br />
  13          549632          582399   16.0 MiB    8300  NP_CPU_ROOTFS1<br />
  14          582400          664319   40.0 MiB    8300  GW_FS1<br />
  15          664320          758527   46.0 MiB    8300  APP_CPU_NVRAM<br />
  16          758528          875263   57.0 MiB    8300  NP_CPU_NVRAM<br />
  17          875264          916223   20.0 MiB    8300  APP_CPU_LOG<br />
  18          916224          957183   20.0 MiB    8300  NP_CPU_LOG<br />
  19          957184         1894366   457.6 MiB   8300  THIRD_PARTY_FS</code></div></div><br />
<br />
Thanks!]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[forcing config on arris shelled firmware?]]></title>
			<link>http://www.haxorware.com/forums/showthread.php?tid=9206</link>
			<pubDate>Fri, 29 Jul 2022 04:34:42 +0200</pubDate>
			<dc:creator><![CDATA[<a href="http://www.haxorware.com/forums/member.php?action=profile&uid=15065">Rickz</a>]]></dc:creator>
			<guid isPermaLink="false">http://www.haxorware.com/forums/showthread.php?tid=9206</guid>
			<description><![CDATA[Regards,<br />
<br />
as subjet says.. i was able to clone a TG862A to a TG862G<br />
<br />
the isp i'm using allow to auto server and/or force the config file as long is not edited, i got plemty of them with different speed, <br />
Haxorware does a great job forcing the config, someone from other forum told me to emulate the way haxor or forceware do it...i have no idea..<br />
where to start, some other told me to change the firmware, i want to test and keep it original/virgin for a while<br />
i'm looking for other alternatives...<br />
is there a way to force the modem reading other config file / tftp server, or maybe just the config file ?  <img src="http://www.haxorware.com/forums/images/smilies/undecided.gif" alt="Undecided" title="Undecided" class="smilie smilie_20" /> <br />
<br />
i have shell access from telnet..<br />
<br />
any help or tips are welcome!!<br />
<br />
My Best Regards]]></description>
			<content:encoded><![CDATA[Regards,<br />
<br />
as subjet says.. i was able to clone a TG862A to a TG862G<br />
<br />
the isp i'm using allow to auto server and/or force the config file as long is not edited, i got plemty of them with different speed, <br />
Haxorware does a great job forcing the config, someone from other forum told me to emulate the way haxor or forceware do it...i have no idea..<br />
where to start, some other told me to change the firmware, i want to test and keep it original/virgin for a while<br />
i'm looking for other alternatives...<br />
is there a way to force the modem reading other config file / tftp server, or maybe just the config file ?  <img src="http://www.haxorware.com/forums/images/smilies/undecided.gif" alt="Undecided" title="Undecided" class="smilie smilie_20" /> <br />
<br />
i have shell access from telnet..<br />
<br />
any help or tips are welcome!!<br />
<br />
My Best Regards]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Anyone has 6121,6141, or 1602 new firmware???]]></title>
			<link>http://www.haxorware.com/forums/showthread.php?tid=9178</link>
			<pubDate>Sun, 03 Jul 2022 07:22:11 +0200</pubDate>
			<dc:creator><![CDATA[<a href="http://www.haxorware.com/forums/member.php?action=profile&uid=27527">daddy_phill0201</a>]]></dc:creator>
			<guid isPermaLink="false">http://www.haxorware.com/forums/showthread.php?tid=9178</guid>
			<description><![CDATA[Anyone has the new firmware!????]]></description>
			<content:encoded><![CDATA[Anyone has the new firmware!????]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[how to flash a SVG6582? need help finding the connection points]]></title>
			<link>http://www.haxorware.com/forums/showthread.php?tid=9146</link>
			<pubDate>Sun, 29 May 2022 01:26:28 +0200</pubDate>
			<dc:creator><![CDATA[<a href="http://www.haxorware.com/forums/member.php?action=profile&uid=1929">jofre</a>]]></dc:creator>
			<guid isPermaLink="false">http://www.haxorware.com/forums/showthread.php?tid=9146</guid>
			<description><![CDATA[<span style="font-size: medium;" class="mycode_size"><span style="font-family: Whitney,;" class="mycode_font">hi all, anyone have some material on how to flash a SVG6582? <br />
</span></span><br />
the spansion chip has no legs, the clip is useless here<br />
<br />
where would the connection points be?<br />
<br />
<span style="font-size: medium;" class="mycode_size"><span style="font-family: Whitney,;" class="mycode_font">trying to open telnet but the oids are not working </span></span><br />
<br />
<span style="font-size: medium;" class="mycode_size"><span style="font-family: Whitney,;" class="mycode_font">the current firm is SVG6x82-6.5.2.1-GA-00-06-LTSH it's shelled, but no cake so far</span></span><br />
<br />
thank you<br />
<br />
<img src="https://i.ibb.co/FBkYfkt/photo-2022-05-29-14-36-28.jpg" loading="lazy"  alt="[Image: photo-2022-05-29-14-36-28.jpg]" class="mycode_img" /><br />
<br />
<img src="https://i.ibb.co/yShccr3/photo-2022-05-29-14-36-32.jpg" loading="lazy"  alt="[Image: photo-2022-05-29-14-36-32.jpg]" class="mycode_img" /><br />
<br />
<img src="https://i.ibb.co/RB7nfM6/photo-2022-05-29-14-32-13.jpg" loading="lazy"  alt="[Image: photo-2022-05-29-14-32-13.jpg]" class="mycode_img" /><img src="https://i.ibb.co/0Kz1Fys/photo-2022-05-29-14-32-57.jpg" loading="lazy"  alt="[Image: photo-2022-05-29-14-32-57.jpg]" class="mycode_img" /><img src="https://i.ibb.co/6RdLqXQ/photo-2022-05-29-14-33-02.jpg" loading="lazy"  alt="[Image: photo-2022-05-29-14-33-02.jpg]" class="mycode_img" />]]></description>
			<content:encoded><![CDATA[<span style="font-size: medium;" class="mycode_size"><span style="font-family: Whitney,;" class="mycode_font">hi all, anyone have some material on how to flash a SVG6582? <br />
</span></span><br />
the spansion chip has no legs, the clip is useless here<br />
<br />
where would the connection points be?<br />
<br />
<span style="font-size: medium;" class="mycode_size"><span style="font-family: Whitney,;" class="mycode_font">trying to open telnet but the oids are not working </span></span><br />
<br />
<span style="font-size: medium;" class="mycode_size"><span style="font-family: Whitney,;" class="mycode_font">the current firm is SVG6x82-6.5.2.1-GA-00-06-LTSH it's shelled, but no cake so far</span></span><br />
<br />
thank you<br />
<br />
<img src="https://i.ibb.co/FBkYfkt/photo-2022-05-29-14-36-28.jpg" loading="lazy"  alt="[Image: photo-2022-05-29-14-36-28.jpg]" class="mycode_img" /><br />
<br />
<img src="https://i.ibb.co/yShccr3/photo-2022-05-29-14-36-32.jpg" loading="lazy"  alt="[Image: photo-2022-05-29-14-36-32.jpg]" class="mycode_img" /><br />
<br />
<img src="https://i.ibb.co/RB7nfM6/photo-2022-05-29-14-32-13.jpg" loading="lazy"  alt="[Image: photo-2022-05-29-14-32-13.jpg]" class="mycode_img" /><img src="https://i.ibb.co/0Kz1Fys/photo-2022-05-29-14-32-57.jpg" loading="lazy"  alt="[Image: photo-2022-05-29-14-32-57.jpg]" class="mycode_img" /><img src="https://i.ibb.co/6RdLqXQ/photo-2022-05-29-14-33-02.jpg" loading="lazy"  alt="[Image: photo-2022-05-29-14-33-02.jpg]" class="mycode_img" />]]></content:encoded>
		</item>
	</channel>
</rss>