I have this router (called the cdr-king 3G-52 in my case). Everything is exactly the same as the OP says, except the serial number: 3GR200906578. It is not a very good router because:
1) Firewall is not 'stealth' hiding ports (just closed)
2) Wireless seems to get 'stuck' and needs a reboot
3) Wireless N performance is not so good for my MBP
There are also numerous grammar/spelling mistakes and non-sensical info (e.g. telnet to http:<WANPORT>:8080?!). I don't have a serial cable, but am trying to get my hands on one (CA-42 and DKU-5 cables aren't so easy to find in shops anymore).
Attached are some images. BTW, this router was purchased in Philippines during a holiday.
I have uploaded ddwrt onto this router based on the instructions in this thread. But here's a complete step by step guide:
1. Setup a TFTP server and download the NR22 stock firmware. An example using OSX:
Quote:
macbook-4491:var matthewh$ cd /private/tftpboot/
macbook-4491:tftpboot matthewh$ sudo curl -O ftp://autoupgrade.serveftp.com/NR22/root_uImage
Password:
% Total % Received % Xferd Average Speed Time Time Time Current
Dload Upload Total Spent Left Speed
100 3306k 100 3306k 0 0 62914 0 0:00:53 0:00:53 --:--:-- 78989
macbook-4491:tftpboot matthewh$ sudo service tftp start
service: This command still works, but it is deprecated. Please use launchctl( instead.
2. Take apart the router. The screws are behind the foam feet.
3. Connect a 3.3v TTL cable to the console port holes. I use the popular FTDI USB cable and some breadboarding wires. Soldering is not required.
4. Run a terminal program, configure the TTL cable as 57600 8N1. I use ZTerm on OSX.
5. Hold down the 2 key while connecting power to the device. Sometimes it doesn't work first go, so try again, and then check the wiring.
Quote:
U-Boot 1.1.3 (Jul 1 2010 - 14:36:4
Board: Ralink APSoC DRAM: 32 MB
relocate_code Pointer at: 81fac000
======= config usb otg =====
flash_protect ON: from 0xBF000000 to 0xBF020593
protect on 0
protect on 1
protect on 2
protect on 3
protect on 4
protect on 5
protect on 6
protect on 7
protect on 8
protect on 9
flash_protect ON: from 0xBF030000 to 0xBF03FFFF
protect on 10
============================================
Ralink UBoot Version: 3.2
--------------------------------------------
ASIC 3052_MP2 (Port5<->None)
DRAM COMPONENT: 128Mbits
DRAM BUS: 32BIT
Total memory: 32 MBytes
Date:Jul 1 2010 Time:14:36:48
============================================
icache: sets:256, ways:4, linesz:32 ,total:32768
dcache: sets:128, ways:4, linesz:32 ,total:16384
##### The CPU freq = 384 MHZ ####
SDRAM bus set to 32 bit
SDRAM size =32 Mbytes
Please choose the operation:
1: Load system code to SDRAM via TFTP.
2: Load system code then write to Flash via TFTP.
3: Boot system code via Flash (default).
4: Entr boot command line interface.
9: Load Boot Loader code then write to Flash via TFTP.
ETH_STATE_ACTIVE!!
Using Eth0 (10/100-M) device
TFTP from server 192.168.0.2; our IP address is 192.168.0.1
Filename 'root_uImage'.
TIMEOUT_COUNT=10,Load address: 0x80100000
Loading: Got ARP REPLY, set server/gtwy eth addr (00:de:ad:be:ef:00)
Got it
T #
first block received
################################################################
#len bad 103 < 544
len bad 123 < 544
len bad 163 < 544
len bad 143 < 544
####len bad 132 < 544
#######################len bad 44 < 544
#####################################
######len bad 44 < 544
#########################################len bad 44 < 544
##################
################################################################len bad 44 < 544
#
#########################len bad 128 < 544
################len bad 44 < 544
########################
##################len bad 44 < 544
###############################################
#################################################################
#################################################################
#################################################################
############################################len bad 44 < 544
#####################
############
done
Bytes transferred = 3385879 (33aa17 hex)
NetBootFileXferSize= 0033aa17
Erase linux kernel block !!
From 0xBF050000 To 0xBF38FFFF
b_end =BF3FFFFF
Erase Flash from 0xbf050000 to 0xbf38ffff in Bank # 1
System Control Status = 0x00440000
Image Type: MIPS Linux Kernel Image (lzma compressed)
Data Size: 3385815 Bytes = 3.2 MB
Load Address: 80000000
Entry Point: 80288000
Verifying Checksum ... OK
Uncompressing Kernel Image ... OK
No initrd
## Transferring control to Linux (at address 80288000) ...
## Giving linux memsize in MB, 32
Starting kernel ...
LINUX started...
THIS IS ASIC
Linux version 2.6.21 (root@localhost.localdomain) (gcc version 3.4.2) #70 Tue May 24 18:20:08 CST 2011
The CPU feqenuce set to 384 MHz
CPU revision is: 0001964c
Determined physical RAM map:
memory: 02000000 @ 00000000 (usable)
Initrd not found or empty - disabling initrd
Built 1 zonelists. Total pages: 8128
Kernel command line: console=ttyS1,57600n8 root=/dev/ram0
Primary instruction cache 32kB, physically tagged, 4-way, linesize 32 bytes.
Primary data cache 16kB, 4-way, linesize 32 bytes.
Synthesized TLB refill handler (20 instructions).
Synthesized TLB load handler fastpath (32 instructions).
Synthesized TLB store handler fastpath (32 instructions).
Synthesized TLB modify handler fastpath (31 instructions).
Cache parity protection disabled
cause = 40808010, status = 11000000
PID hash table entries: 128 (order: 7, 512 bytes)
calculating r4koff... 00177000(1536000)
CPU frequency 384.00 MHz
Using 192.000 MHz high precision timer.
Console: colour dummy device 80x25
Dentry cache hash table entries: 4096 (order: 2, 16384 bytes)
Inode-cache hash table entries: 2048 (order: 1, 8192 bytes)
Memory: 27216k/32768k available (2163k kernel code, 5552k reserved, 424k data, 2556k init, 0k highmem)
Mount-cache hash table entries: 512
NET: Registered protocol family 16
Time: MIPS clocksource has been installed.
NET: Registered protocol family 2
IP route cache hash table entries: 1024 (order: 0, 4096 bytes)
TCP established hash table entries: 1024 (order: 1, 8192 bytes)
TCP bind hash table entries: 1024 (order: 0, 4096 bytes)
TCP: Hash tables configured (established 1024 bind 1024)
TCP reno registered
detected lzma initramfs
detected lzma initramfs
initramfs: LZMA lc=3,lp=0,pb=2,dictSize=1048576,origSize=11054592
LZMA initramfs by Ming-Ching Tiew <mctiew@yahoo.com>....................................................................................
.....................................................................................<5>ralink flash device: 0x1000000 at 0x1f000000
Ralink SoC physically mapped flash: Found 1 x16 devices at 0x0 in 16-bit bank
Amd/Fujitsu Extended Query Table at 0x0040
number of CFI chips: 1
cfi_cmdset_0002: Disabling erase-suspend-program due to code brokenness.
Creating 5 MTD partitions on "Ralink SoC physically mapped flash":
0x00000000-0x00400000 : "ALL"
0x00000000-0x00030000 : "Bootloader"
0x00030000-0x00040000 : "Config"
0x00040000-0x00050000 : "Factory"
0x00050000-0x01000000 : "Kernel"
mtd: partition "Kernel" extends beyond the end of device "Ralink SoC physically mapped flash" -- size truncated to 0x3b0000
squashfs: version 3.2-r2 (2007/01/15) Phillip Lougher
squashfs: LZMA suppport for slax.org by jro
fuse init (API version 7.
io scheduler noop registered (default)
Ralink gpio driver initialized
HDLC line discipline: version $Revision: 1.1.1.1 $, maxframe=4096
N_HDLC line discipline registered.
Software Watchdog Timer: 0.07 initialized. soft_noboot=0 soft_margin=60 sec (nowayout= 0)
Serial: 8250/16550 driver $Revision: 1.7 $ 2 ports, IRQ sharing disabled
serial8250: ttyS0 at I/O 0xb0000500 (irq = 37) is a 16550A
serial8250: ttyS1 at I/O 0xb0000c00 (irq = 12) is a 16550A
RAMDISK driver initialized: 16 RAM disks of 8192K size 1024 blocksize
loop: loaded (max 8 devices)
rdm_major = 254
MAC_ADRH -- : 0x00000000
MAC_ADRL -- : 0x00000000
Ralink APSoC Ethernet Driver Initilization. v2.0 256 rx/tx descriptors allocated, mtu = 1500!
MAC_ADRH -- : 0x0000000c
MAC_ADRL -- : 0x43305277
PROC INIT OK!
IMQ starting with 2 devices...
IMQ driver loaded successfully.
Hooking IMQ after NAT on PREROUTING.
Hooking IMQ before NAT on POSTROUTING.
PPP generic driver version 2.4.2
PPP Deflate Compression module registered
PPP BSD Compression module registered
PPP MPPE Compression module registered
NET: Registered protocol family 24
PPPoL2TP kernel driver, V0.17
PPTP driver version 0.8.1
block2mtd: version $Revision: 1.1.1.1 $
nf_conntrack version 0.5.0 (256 buckets, 2048 max)
ip_tables: (C) 2000-2006 Netfilter Core Team, Type=Linux
arp_tables: (C) 2002 David S. Miller
TCP cubic registered
NET: Registered protocol family 1
NET: Registered protocol family 10
NET: Registered protocol family 17
802.1Q VLAN Support v1.8 Ben Greear <greearb@candelatech.com>
All bugs added by David S. Miller <davem@redhat.com>
Freeing unused kernel memory: 2556k freed
init started: BusyBox v1.12.1 (2011-05-23 15:20Algorithmics/MIPS FPU Emulator v1.5
:53 CST)
starting pid 675, tty '': '/etc_ro/rcS'
devpts: called with bogus options
mount: mounting none on /proc/bus/usb failed: No such file or directory
Welcome to
_______ ______ ______ ______ _ _
| __ || ___|| ___|| ___|\ \ / /
| |__| || | | |__ | |__ \ \/ /
| _ || |___ | |___ | |___ / /\ \
|__| |__||______||______||______|/_/ \_\
=System Architecture Department=
starting pid 686, tty '/dev/ttyS1': '/bin/sh'
BusyBox v1.12.1 (2011-05-23 15:20:53 CST) built-in shell (ash)
Enter 'help' for a list of built-in commands.
# goahead: waiting for nvram_daemon . Commit crc = ea287626
. . Commit crc = ea287626
internet.sh
Password for 'admin' changed
rmmod: cls: No such file or directory
rmmod: hw_nat: No such file or directory
rmmod: raeth: No such file or directory
insmod: bridge.ko: module not found
insmod: mii.ko: module not found
insmod: raeth.ko: module not found
phy_tx_ring = 0x004a1000, tx_ring = 0xa04a1000
phy_rx_ring0 = 0x004a2000, rx_ring0 = 0xa04a2000
RT305x_ESW: Link Status Changed
CDMA_CSG_CFG = 81000007
GDMA1_FWD_CFG = 710000
##### disable 1st wireless interface #####
rmmod: rt2860v2_ap_net: No such file or directory
rmmod: rt2860v2_ap: No such file or directory
rmmod: rt2860v2_ap_util: No such file or directory
rmmod: rt2860v2_sta_net: No such file or directory
rmmod: rt2860v2_sta: No such file or directory
rmmod: rt2860v2_sta_util: No such file or directory
Commit crc = daea6302
insmod: rt2860v2_ap_util.ko: module not found
rt2860v2_ap: module license 'unspecified' taints kernel.
=== pAd = c001b000, size = 516680 ===
<-- RTMPAllocAdapterBlock, Status=0
insmod: rt2860v2_ap_net.ko: module not found
rmmod: nf_nat_pptp: No such file or directory
rmmod: nf_conntrack_pptp: No such file or directory
rmmod: nf_nat_proto_gre: No such file or directory
rmmod: nf_conntrack_proto_gre: No such file or directory
RX DESC a04c4000 size = 2048
<-- RTMPAllocTxRxRingMemory, Status=0
Key1Str is Invalid key length(0) or Type(0)
Key2Str is Invalid key length(0) or Type(0)
Key3Str is Invalid key length(0) or Type(0)
Key4Str is Invalid key length(0) or Type(0)
1. Phy Mode = 9
2. Phy Mode = 9
3. Phy Mode = 9
RTMPSetPhyMode: channel is out of range, use first channel=0
MCS Set = ff ff 00 00 01
SYNC - BBP R4 to 20MHz.l
The 2-BSSID mode is enabled, the BSSID byte5 MUST be the multiple of 2
Main bssid = 00:ca:fe:b0:0b:s0
<==== rt28xx_init, Status=0
0x1300 = 00064380
vconfig: ioctl error for rem: Invalid argument
vconfig: ioctl error for rem: Invalid argument
rmmod: 8021q: No such file or directory
insmod: 8021q.ko: module not found
eth2.2: Setting MAC address to 00 0c 43 30 52 22.
device eth2 entered promiscuous mode
VLAN (eth2.2): Setting underlying device (eth2) to promiscious mode.
ifconfig: ioctl 0x8913 failed: No such device
brctl: bridge br0: No such device or address
##### config Ralink ESW vlan partition (WLLLL) #####
switch reg write offset=14, value=405555
switch reg write offset=50, value=2001
switch reg write offset=98, value=7f3f
switch reg write offset=e4, value=3f
switch reg write offset=40, value=1002
switch reg write offset=44, value=1001
switch reg write offset=48, value=1001
switch reg write offset=70, value=ffff417e
done.
device ra0 entered promiscuous mode
eth2.1: dev_set_promiscuity(master, 1)
device eth2.1 entered promiscuous mode
udhcpc (v1.12.1) started
br0: port 2(eth2.1) entering learning state
br0: port 1(ra0) entering learning state
ifconfig: ioctl 0x8914 failed: Cannot assign requested address
ifconfig: ioctl 0x8914 failed: Cannot assign requested address
/sbin/lan.sh: line 63: hostname: not found
Commit crc = daea6302
Commit crc = daea6302
killall: udhcpd: no process killed
RT305x_ESW: Link Status Changed
Set: phy[4].reg[0] = 3900
Set: phy[1].reg[0] = 3900
Set: phy[2].reg[0] = 3900
Set: phy[3].reg[0] = 3900
Set: phy[4].reg[0] = 3100
Set: phy[1].reg[0] = 3100
Set: phy[2].reg[0] = 3100
Set: phy[3].reg[0] = 3100
ifconfig: ioctl 0x8913 failed: No such device
RT305x_ESW: Link Status Changed
killall rt2860apd 1>/dev/null 2>&1
iptables -F -t filter 1>/dev/null 2>&1
iptables -D FORWARD -j macipport_filter 1>/dev/null 2>&1
iptables -F macipport_filter 1>/dev/null 2>&1
iptables -D FORWARD -j web_filter 1>/dev/null 2>&1
iptables -F web_filter 1>/dev/null 2>&1
iptables -D FORWARD -j malicious_filter 1>/dev/null 2>&1
iptables -F malicious_filter 1>/dev/null 2>&1
iptables -D INPUT -j malicious_input_filter 1>/dev/null 2>&1
iptables -F malicious_input_filter 1>/dev/null 2>&1
iptables -P INPUT ACCEPT
iptables -P OUTPUT ACCEPT
iptables -P FORWARD ACCEPT
iptables -t filter -N web_filter 1>/dev/null 2>&1
iptables -t filter -N macipport_filter 1>/dev/null 2>&1
iptables -t filter -N malicious_filter 1>/dev/null 2>&1
iptables -t filter -N synflood_filter 1>/dev/null 2>&1
iptables -t filter -N malicious_input_filter 1>/dev/null 2>&1
iptables -t filter -N synflood_input_filter 1>/dev/null 2>&1
iptables -t filter -A FORWARD -j web_filter 1>/dev/null 2>&1
iptables -t filter -A FORWARD -j macipport_filter 1>/dev/null 2>&1
iptables -t filter -A FORWARD -j malicious_filter 1>/dev/null 2>&1
iptables -t filter -A malicious_filter -p tcp --syn -j synflood_filter 1>/dev/null 2>&1
iptables -t filter -A INPUT -j malicious_input_filter 1>/dev/null 2>&1
iptables -t filter -A malicious_input_filter -p tcp --syn -j synflood_input_filter 1>/dev/null 2>&1
iptables -A FORWARD -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu 1>/dev/null 2>&1
iptables -A malicious_input_filter -i eth2.2 -p tcp --dport 80 -j DROP
iptables -A malicious_input_filter -i eth2.2 -p tcp --dport 8088 -j DROP
iptables -D malicious_input_filter -i eth2.2 -p tcp --dport 8088 -j ACCEPT
iptables: Bad rule (does a matching rule exist in that chain?)
iptables -t nat -D PREROUTING -p tcp -m tcp -d --dport 8088 -j DNAT --to-destination 192.168.0.1:80
Bad argument `8088'
Try `iptables -h' or 'iptables --help' for more information.
iptables -A malicious_input_filter -i eth2.2 -p tcp --dport 23 -j DROP
/bin/super_dmz -f
cat: can't open '/etc/resolv.conf': No such file or directory
killall: udhcpd: no process killed
RT305x_ESW: Link Status Changed
Set: phy[4].reg[0] = 3900
Set: phy[1].reg[0] = 3900
Set: phy[2].reg[0] = 3900
Set: phy[3].reg[0] = 3900
Set: phy[4].reg[0] = 3100
Set: phy[1].reg[0] = 3100
Set: phy[2].reg[0] = 3100
Set: phy[3].reg[0] = 3100
superdmz:Can't get WAN gateway
iptables -t nat -D PREROUTING -j port_forward 1>/dev/null 2>&1
iptables -t nat -F port_forward 1>/dev/null 2>&1; iptables -t nat -X port_forward 1>/dev/null 2>&1
iptables -t nat -D POSTROUTING -j nat_loopback 1>/dev/null 2>&1
iptables -t nat -F nat_loopback 1>/dev/null 2>&1; iptables -t nat -X nat_loopback 1>/dev/null 2>&1
iptables -t nat -D POSTROUTING -j SNAT --to
iptables v1.4.0rc1: Unknown arg `--to'
Try `iptables -h' or 'iptables --help' for more information.
iptables -t nat -D PREROUTING -j DMZ 1>/dev/null 2>&1
iptables -t nat -F DMZ 1>/dev/null 2>&1; iptables -t nat -X DMZ 1>/dev/null 2>&1
iptables -t nat -N port_forward 1>/dev/null 2>&1; iptables -t nat -I PREROUTING 1 -j port_forward 1>/dev/null 2>&1
iptables -t nat -N DMZ 1>/dev/null 2>&1; iptables -t nat -I PREROUTING 2 -j DMZ 1>/dev/nulRT305x_ESW: Link Status Changed
l 2>&1
iptables -t nat -N nat_loopback 1>/dev/null 2>&1; iptables -t nat -I POSTROUTING 3 -j nat_loopback 1>/dev/null 2>&1
ntp.sh
pool.ntp.org: Unknown host
sleep 2
ddns.sh
kill -9 `cat /var/run/wscd.pid.ra0`
cat: can't open '/var/run/wscd.pid.ra0': No such file or directory
kill: you need to specify whom to kill
iwprThe 2-BSSID mode is enabled, the BSSID byte5 MUST be the multiple of 2
iv ra0 set WscConfMode=0 1>/dev/null 2>&1
route delete 239.255.255.250 1>/dev/null 2>&1
greenap.sh init
killall -q zebra
killall -q ripd
/bin/qos_run
syslogd -C8 1>/dev/null 2>&1
klogd 1>/dev/null 2>&1
webs: Listening for HTTP requests at address 192.168.0.1
echo -n 3.5.3.0 > /var/version
br0: topology change detected, propagating
br0: port 2(eth2.1) entering forwarding state
br0: topology change detected, propagating
br0: port 1(ra0) entering forwarding state
7. Telnet to the device. If will need your PC to be on the 192.168.0/24 subnet, but don't use .1 because that's what the device will be using. Once connected, configure DNS resolver and a default gateway for your Internet connection. Then run ddwrt.sh
Quote:
macbook-4491:~ matthewh$ telnet 192.168.0.1
Trying 192.168.0.1...
Connected to 192.168.0.1.
Escape character is '^]'.
(none) login: admin
Password:
BusyBox v1.12.1 (2011-05-23 15:20:53 CST) built-in shell (ash)
Enter 'help' for a list of built-in commands.
# route add default gw 192.168.0.2
# echo nameserver 192.168.0.2 >> /etc/resolv.conf
# ddwrt.sh
Connecting to www.dd-wrt.com (83.141.4.210:80)
firmware 100% |************************************************| 3591k 00:00:00 ETA
*** Warning: "/var/firmware" has corrupted data!
Unlocking Kernel ...
Writing from /var/firmware to Kernel ... [w]
8. If you still have the TTL cable connected you will see the system reboot. Otherwise just wait 10 minutes.
9. Change your network settings to the 192.168.1/24 network. Connect with telnet or http to 192.168.1.1 and say hello to DDWRT.
Quote:
macbook-4491:tmp matthewh$ telnet 192.168.1.1
Trying 192.168.1.1...
Connected to 192.168.1.1.
Escape character is '^]'.
I got the cable - it's a 3 wire version with rx, tx and gnd. I also soldered a floppy power socket onto the routers PCB, just to make it easier to play with the USB-cable.
The cable works, since I can do the loop back test, but the router is completely silent, nothing at all on the serial port
I checked the voltages and got approx 3.3V on one of the 4 pins. The + pin isn't connected to my cable at all.
Currently I'm out of ideas, so any kind of help would be greatly appreciated
Got it to work now, with the Aceex NR22/Y firmware posted in the 2nd post of this thread.
I'm not really sure what the problem was, but I ended up disconnecting the GND cable between the PC and the router, having only RX and TX connected got me mostly garbage, but sometimes readable text. Then I connected the GND back again, and the text became clear.
When it comes to the TFTP, I grabbed the one at http://tftpd32.jounin.net/ extracted the exe and ini, put the root_uImage in the same dir as the two other files and ran the tftpd32 exe.
Connected the router via one of it's LAN ports to my LAN, set it to an unused IP (when asked) and pointed it to the IP of the PC running the tftp to DL the firmware.
The rest is in the code windows below ....
Code:
U-Boot 1.1.3 (Jul 1 2010 - 14:36:48)
Board: Ralink APSoC DRAM: 32 MB
relocate_code Pointer at: 81fac000
======= config usb otg =====
flash_protect ON: from 0xBF000000 to 0xBF020593
protect on 0
protect on 1
protect on 2
protect on 3
protect on 4
protect on 5
protect on 6
protect on 7
protect on 8
protect on 9
flash_protect ON: from 0xBF030000 to 0xBF03FFFF
protect on 10
*** Warning - bad CRC, using default environment
Please choose the operation:
1: Load system code to SDRAM via TFTP.
2: Load system code then write to Flash via TFTP.
3: Boot system code via Flash (default).
4: Entr boot command line interface.
9: Load Boot Loader code then write to Flash via TFTP.
2: System Load Linux Kernel then write to Flash via TFTP.
Warning!! Erase Linux in Flash then burn new one. Are you sure?(Y/N)
Please Input new ones /or Ctrl-C to discard
Input device IP (10.10.10.123) ==:192.168.10.200
Input server IP (10.10.10.3) ==:192.168.10.22
Input Linux Kernel filename () ==:root_uImage
System Control Status = 0x00440000
Image Type: MIPS Linux Kernel Image (lzma compressed)
Data Size: 3394346 Bytes = 3.2 MB
Load Address: 80000000
Entry Point: 80288000
Verifying Checksum ... OK
Uncompressing Kernel Image ... OK
No initrd
## Transferring control to Linux (at address 80288000) ...
## Giving linux memsize in MB, 32
Starting kernel ...
LINUX started...
THIS IS ASIC
Linux version 2.6.21 (root@localhost.localdomain) (gcc version 3.4.2) #132 Mon Jun 20 10:36:43 CST 2011
The CPU feqenuce set to 384 MHz
CPU revision is: 0001964c
Determined physical RAM map:
memory: 02000000 @ 00000000 (usable)
Initrd not found or empty - disabling initrd
Built 1 zonelists. Total pages: 8128
Kernel command line: console=ttyS1,57600n8 root=/dev/ram0
Primary instruction cache 32kB, physically tagged, 4-way, linesize 32 bytes.
Primary data cache 16kB, 4-way, linesize 32 bytes.
Synthesized TLB refill handler (20 instructions).
Synthesized TLB load handler fastpath (32 instructions).
Synthesized TLB store handler fastpath (32 instructions).
Synthesized TLB modify handler fastpath (31 instructions).
Cache parity protection disabled
cause = 40808050, status = 11000000
PID hash table entries: 128 (order: 7, 512 bytes)
calculating r4koff... 00177000(1536000)
CPU frequency 384.00 MHz
Using 192.000 MHz high precision timer.
Console: colour dummy device 80x25
Dentry cache hash table entries: 4096 (order: 2, 16384 bytes)
Inode-cache hash table entries: 2048 (order: 1, 8192 bytes)
Memory: 27208k/32768k available (2163k kernel code, 5560k reserved, 424k data, 2564k init, 0k highmem)
Mount-cache hash table entries: 512
NET: Registered protocol family 16
Time: MIPS clocksource has been installed.
NET: Registered protocol family 2
IP route cache hash table entries: 1024 (order: 0, 4096 bytes)
TCP established hash table entries: 1024 (order: 1, 8192 bytes)
TCP bind hash table entries: 1024 (order: 0, 4096 bytes)
TCP: Hash tables configured (established 1024 bind 1024)
TCP reno registered
detected lzma initramfs
detected lzma initramfs
initramfs: LZMA lc=3,lp=0,pb=2,dictSize=1048576,origSize=11095552
LZMA initramfs by Ming-Ching Tiew <mctiew@yahoo.com>..........................................................................................................................................................................<5>ralink flash device: 0x1000000 at 0x1f000000
Ralink SoC physically mapped flash: Found 1 x16 devices at 0x0 in 16-bit bank
Amd/Fujitsu Extended Query Table at 0x0040
number of CFI chips: 1
cfi_cmdset_0002: Disabling erase-suspend-program due to code brokenness.
Creating 5 MTD partitions on "Ralink SoC physically mapped flash":
0x00000000-0x00400000 : "ALL"
0x00000000-0x00030000 : "Bootloader"
0x00030000-0x00040000 : "Config"
0x00040000-0x00050000 : "Factory"
0x00050000-0x01000000 : "Kernel"
mtd: partition "Kernel" extends beyond the end of device "Ralink SoC physically mapped flash" -- size truncated to 0x3b0000
squashfs: version 3.2-r2 (2007/01/15) Phillip Lougher
squashfs: LZMA suppport for slax.org by jro
fuse init (API version 7.8)
io scheduler noop registered (default)
Ralink gpio driver initialized
HDLC line discipline: version $Revision: 1.1.1.1 $, maxframe=4096
N_HDLC line discipline registered.
Software Watchdog Timer: 0.07 initialized. soft_noboot=0 soft_margin=60 sec (nowayout= 0)
Serial: 8250/16550 driver $Revision: 1.7 $ 2 ports, IRQ sharing disabled
serial8250: ttyS0 at I/O 0xb0000500 (irq = 37) is a 16550A
serial8250: ttyS1 at I/O 0xb0000c00 (irq = 12) is a 16550A
RAMDISK driver initialized: 16 RAM disks of 8192K size 1024 blocksize
loop: loaded (max 8 devices)
rdm_major = 254
MAC_ADRH -- : 0x00000000
MAC_ADRL -- : 0x00000000
Ralink APSoC Ethernet Driver Initilization. v2.0 256 rx/tx descriptors allocated, mtu = 1500!
MAC_ADRH -- : 0x0000000c
MAC_ADRL -- : 0x43305277
PROC INIT OK!
IMQ starting with 2 devices...
IMQ driver loaded successfully.
Hooking IMQ after NAT on PREROUTING.
Hooking IMQ before NAT on POSTROUTING.
PPP generic driver version 2.4.2
PPP Deflate Compression module registered
PPP BSD Compression module registered
PPP MPPE Compression module registered
NET: Registered protocol family 24
PPPoL2TP kernel driver, V0.17
PPTP driver version 0.8.1
block2mtd: version $Revision: 1.1.1.1 $
nf_conntrack version 0.5.0 (256 buckets, 2048 max)
ip_tables: (C) 2000-2006 Netfilter Core Team, Type=Linux
arp_tables: (C) 2002 David S. Miller
TCP cubic registered
NET: Registered protocol family 1
NET: Registered protocol family 10
NET: Registered protocol family 17
802.1Q VLAN Support v1.8 Ben Greear <greearb@candelatech.com>
All bugs added by David S. Miller <davem@redhat.com>
Freeing unused kernel memory: 2564k freed
init started: BusyBox v1.12.1 (2011-06-17 08:49Algorithmics/MIPS FPU Emulator v1.5
:40 CST)
starting pid 675, tty '': '/etc_ro/rcS'
devpts: called with bogus options
mount: mounting none on /proc/bus/usb failed: No such file or directory
Welcome to
_______ ______ ______ ______ _ _
| __ || ___|| ___|| ___|\ \ / /
| |__| || | | |__ | |__ \ \/ /
| _ || |___ | |___ | |___ / /\ \
|__| |__||______||______||______|/_/ \_\
=System Architecture Department=
starting pid 686, tty '/dev/ttyS1': '/bin/sh'
BusyBox v1.12.1 (2011-06-17 08:49:40 CST) built-in shell (ash)
Enter 'help' for a list of built-in commands.
# goahead: waiting for nvram_daemon . Commit crc = 708a8d6c
. Commit crc = 708a8d6c
internet.sh
Password for 'admin' changed
rmmod: cls: No such file or directory
rmmod: hw_nat: No such file or directory
rmmod: raeth: No such file or directory
insmod: bridge.ko: module not found
insmod: mii.ko: module not found
insmod: raeth.ko: module not found
phy_tx_ring = 0x004ac000, tx_ring = 0xa04ac000
phy_rx_ring0 = 0x004ad000, rx_ring0 = 0xa04ad000
RT305x_ESW: Link Status Changed
CDMA_CSG_CFG = 81000007
GDMA1_FWD_CFG = 710000
##### disable 1st wireless interface #####
rmmod: rt2860v2_ap_net: No such file or directory
rmmod: rt2860v2_ap: No such file or directory
rmmod: rt2860v2_ap_util: No such file or directory
rmmod: rt2860v2_sta_net: No such file or directory
rmmod: rt2860v2_sta: No such file or directory
rmmod: rt2860v2_sta_util: No such file or directory
Commit crc = 7e5b6b2d
insmod: rt2860v2_ap_util.ko: module not found
rt2860v2_ap: module license 'unspecified' taints kernel.
=== pAd = c001b000, size = 516680 ===
<-- RTMPAllocAdapterBlock, Status=0
insmod: rt2860v2_ap_net.ko: module not found
rmmod: nf_nat_pptp: No such file or directory
rmmod: nf_conntrack_pptp: No such file or directory
rmmod: nf_nat_proto_gre: No such file or directory
rmmod: nf_conntrack_proto_gre: No such file or directory
RX DESC a04b6000 size = 2048
<-- RTMPAllocTxRxRingMemory, Status=0
Key1Str is Invalid key length(0) or Type(0)
Key2Str is Invalid key length(0) or Type(0)
Key3Str is Invalid key length(0) or Type(0)
Key4Str is Invalid key length(0) or Type(0)
1. Phy Mode = 9
2. Phy Mode = 9
3. Phy Mode = 9
RTMPSetPhyMode: channel is out of range, use first channel=0
MCS Set = ff ff 00 00 01
SYNC - BBP R4 to 20MHz.l
The 2-BSSID mode is enabled, the BSSID byte5 MUST be the multiple of 2
Main bssid = 00:b0:c0:01:fa:cd
<==== rt28xx_init, Status=0
0x1300 = 00064380
vconfig: ioctl error for rem: Invalid argument
vconfig: ioctl error for rem: Invalid argument
rmmod: 8021q: No such file or directory
insmod: 8021q.ko: module not found
eth2.2: Setting MAC address to 00 0c 43 30 52 22.
device eth2 entered promiscuous mode
VLAN (eth2.2): Setting underlying device (eth2) to promiscious mode.
ifconfig: ioctl 0x8913 failed: No such device
brctl: bridge br0: No such device or address
##### config Ralink ESW vlan partition (WLLLL) #####
switch reg write offset=14, value=405555
switch reg write offset=50, value=2001
switch reg write offset=98, value=7f3f
switch reg write offset=e4, value=3f
switch reg write offset=40, value=1002
switch reg write offset=44, value=1001
switch reg write offset=48, value=1001
device ra0 entered promiscuous mode
eth2.1: dev_set_promiscuity(master, 1)
device eth2.1 entered promiscuous mode
udhcpc (v1.12.1) started
switch reg write offset=9c, value=8a311
Set: phy[0].reg[0] = 3100
Set: phy[1].reg[0] = 3100
Set: phy[2].reg[0] = 3100
Set: phy[3].reg[0] = 3100
Set: phy[4].reg[0] = 3100
br0: port 2(eth2.1) entering learning state
br0: port 1(ra0) entering learning state
ifconfig: ioctl 0x8914 failed: Cannot assign requested address
ifconfig: ioctl 0x8914 failed: Cannot assign requested address
/sbin/lan.sh: line 65: hostname: not found
Commit crc = 7e5b6b2d
Commit crc = 7e5b6b2d
killall: udhcpd: no process killed
RT305x_ESW: Link Status Changed
Set: phy[4].reg[0] = 3900
Set: phy[1].reg[0] = 3900
Set: phy[2].reg[0] = 3900
Set: phy[3].reg[0] = 3900
Set: phy[4].reg[0] = 3100
Set: phy[1].reg[0] = 3100
Set: phy[2].reg[0] = 3100
Set: phy[3].reg[0] = 3100
RT305x_ESW: Link Status Changed
ifconfig: ioctl 0x8913 failed: No such device
killall rt2860apd 1>/dev/null 2>&1
iptables -F -t filter 1>/dev/null 2>&1
iptables -D FORWARD -j macipport_filter 1>/dev/null 2>&1
iptables -F macipport_filter 1>/dev/null 2>&1
iptables -D FORWARD -j web_filter 1>/dev/null 2>&1
iptables -F web_filter 1>/dev/null 2>&1
iptables -D FORWARD -j malicious_filter 1>/dev/null 2>&1
iptables -F malicious_filter 1>/dev/null 2>&1
iptables -D INPUT -j malicious_input_filter 1>/dev/null 2>&1
iptables -F malicious_input_filter 1>/dev/null 2>&1
iptables -P INPUT ACCEPT
iptables -P OUTPUT ACCEPT
iptables -P FORWARD ACCEPT
iptables -t filter -N web_filter 1>/dev/null 2>&1
iptables -t filter -N macipport_filter 1>/dev/null 2>&1
iptables -t filter -N malicious_filter 1>/dev/null 2>&1
iptables -t filter -N synflood_filter 1>/dev/null 2>&1
iptables -t filter -N malicious_input_filter 1>/dev/null 2>&1
iptables -t filter -N synflood_input_filter 1>/dev/null 2>&1
iptables -t filter -A FORWARD -j web_filter 1>/dev/null 2>&1
iptables -t filter -A FORWARD -j macipport_filter 1>/dev/null 2>&1
iptables -t filter -A FORWARD -j malicious_filter 1>/dev/null 2>&1
iptables -t filter -A malicious_filter -p tcp --syn -j synflood_filter 1>/dev/null 2>&1
iptables -t filter -A INPUT -j malicious_input_filter 1>/dev/null 2>&1
iptables -t filter -A malicious_input_filter -p tcp --syn -j synflood_input_filter 1>/dev/null 2>&1
iptables -A FORWARD -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu 1>/dev/null 2>&1
iptables -A malicious_input_filter -i eth2.2 -p tcp --dport 80 -j DROP
iptables -A malicious_input_filter -i eth2.2 -p tcp --dport 8088 -j DROP
iptables -D malicious_input_filter -i eth2.2 -p tcp --dport 8088 -j ACCEPT
iptables: Bad rule (does a matching rule exist in that chain?)
iptables -t nat -D PREROUTING -p tcp -m tcp -d --dport 8088 -j DNAT --to-destination 192.168.0.1:80
Bad argument `8088'
Try `iptables -h' or 'iptables --help' for more information.
iptables -A malicious_input_filter -i eth2.2 -p tcp --dport 23 -j DROP
/bin/super_dmz -f
cat: can't open '/etc/resolv.conf': No such file or directory
killall: udhcpd: no process killed
RT305x_ESW: Link Status Changed
Set: phy[4].reg[0] = 3900
Set: phy[1].reg[0] = 3900
Set: phy[2].reg[0] = 3900
Set: phy[3].reg[0] = 3900
Set: phy[4].reg[0] = 3100
Set: phy[1].reg[0] = 3100
Set: phy[2].reg[0] = 3100
Set: phy[3].reg[0] = 3100
RT305x_ESW: Link Status Changed
superdmz:Can't get WAN gateway
iptables -t nat -D PREROUTING -j port_forward 1>/dev/null 2>&1
iptables -t nat -F port_forward 1>/dev/null 2>&1; iptables -t nat -X port_forward 1>/dev/null 2>&1
iptables -t nat -D POSTROUTING -j nat_loopback 1>/dev/null 2>&1
iptables -t nat -F nat_loopback 1>/dev/null 2>&1; iptables -t nat -X nat_loopback 1>/dev/null 2>&1
iptables -t nat -D POSTROUTING -j SNAT --to
iptables v1.4.0rc1: Unknown arg `--to'
Try `iptables -h' or 'iptables --help' for more information.
iptables -t nat -D PREROUTING -j DMZ 1>/dev/null 2>&1
iptables -t nat -F DMZ 1>/dev/null 2>&1; iptables -t nat -X DMZ 1>/dev/null 2>&1
iptables -t nat -N port_forward 1>/dev/null 2>&1; iptables -t nat -I PREROUTING 1 -j port_forward 1>/dev/null 2>&1
iptables -t nat -N DMZ 1>/dev/null 2>&1; iptables -t nat -I PREROUTING 2 -j DMZ 1>/dev/null 2>&1
iptables -t nat -N nat_loopback 1>/dev/null 2>&1; iptables -t nat -I POSTROUTING 3 -j nat_loopback 1>/dev/null 2>&1
ntp.sh
pool.ntp.org: Unknown host
sleep 2
ddns.sh
kill -9 `cat /var/run/wscd.pid.ra0`
cat: can't open '/var/run/wscd.pid.ra0': No such file or directory
kill: you need to specify whom to kill
iwprThe 2-BSSID mode is enabled, the BSSID byte5 MUST be the multiple of 2
iv ra0 set WscConfMode=0 1>/dev/null 2>&1
route delete 239.255.255.250 1>/dev/null 2>&1
greenap.sh init
killall -q zebra
killall -q ripd
/bin/qos_run
syslogd -C8 1>/dev/null 2>&1
klogd 1>/dev/null 2>&1
webs: Listening for HTTP requests at address 192.168.0.1
echo -n 3.5.3.0 > /var/version
br0: topology change detected, propagating
br0: port 2(eth2.1) entering forwarding state
br0: topology change detected, propagating
br0: port 1(ra0) entering forwarding state
[/code]
Last edited by frollic on Tue Apr 03, 2012 13:25; edited 1 time in total
device br0 left promiscuous mode
device br0 entered promiscuous mode
device br0 left promiscuous mode
device br0 entered promiscuous mode
RtmpOSNetDevDetach(): RtmpOSNetDeviceDetach(), dev->name=ra0!
0x1300 = 00064380
br0: topology change detected, propagating
br0: port 1(vlan1) entering forwarding state
0x1300 = 00064380
device ra0 entered promiscuous mode
br0: port 2(ra0) entering learning state
wland: No such file or directory
SIOCGIFFLAGS: No such device
device vlan2 entered promiscuous mode
device vlan2 left promiscuous mode
vlan2: No such process
SIOCGIFFLAGS: No such device
SIOCGIFFLAGS: No such device
SIOCGIFFLAGS: No such device
br0: topology change detected, propagating
br0: port 2(ra0) entering forwarding state
SIOCGIFFLAGS: No such device
SIOCGIFFLAGS: No such device
SIOCGIFFLAGS: No such device
sh: can't create /proc/sys/net/bridge/bridge-nf-call-arptables: nonexistent directory
sh: can't create /proc/sys/net/bridge/bridge-nf-call-ip6tables: nonexistent directory
sh: can't create /proc/sys/net/bridge/bridge-nf-call-iptables: nonexistent directory
SIOCGIFFLAGS: No such device
SIOCGIFFLAGS: No such device
SIOCGIFFLAGS: No such device
SIOCGIFFLAGS: No such device
SIOCGIFFLAGS: No such device
SIOCGIFFLAGS: No such device
SIOCGIFFLAGS: No such device
sh: can't create /proc/sys/net/bridge/bridge-nf-call-arptables: nonexistent directory
sh: can't create /proc/sys/net/bridge/bridge-nf-call-ip6tables: nonexistent directory
sh: can't create /proc/sys/net/bridge/bridge-nf-call-iptables: nonexistent directory
SIOCGIFFLAGS: No such device
SIOCGIFFLAGS: No such device
SIOCGIFFLAGS: No such device
SIOCGIFFLAGS: No such device
SIOCGIFFLAGS: No such device
SIOCGIFFLAGS: No such device
SIOCGIFFLAGS: No such device
sh: can't create /proc/sys/net/bridge/bridge-nf-call-arptables: nonexistent directory
sh: can't create /proc/sys/net/bridge/bridge-nf-call-ip6tables: nonexistent directory
sh: can't create /proc/sys/net/bridge/bridge-nf-call-iptables: nonexistent directory
wland: No such file or directory
etherip: Ethernet over IPv4 tunneling driver
##########################
What does it mean SIOCGIFFLAGS? That error msg "can't create (...)" is that a problem?
What does it mean SIOCGIFFLAGS? That error msg "can't create (...)" is that a problem?
Do you really wanna know what it mean? If you device working fine - don't mention it. It is diagnostic message for firmware developers and have meaning only in context (seems like boot scripts try to apply settings on nonexistent device[s]).
And you've missed some most important information - firmware version u r used. From kernel timestamp (Wed Apr 13 12:22:39 CEST 2011) I can conclude that is not most fresh available.
What does it mean SIOCGIFFLAGS? That error msg "can't create (...)" is that a problem?
Do you really wanna know what it mean? If you device working fine - don't mention it. It is diagnostic message for firmware developers and have meaning only in context (seems like boot scripts try to apply settings on nonexistent device[s]).
And you've missed some most important information - firmware version u r used. From kernel timestamp (Wed Apr 13 12:22:39 CEST 2011) I can conclude that is not most fresh available.
The latest available firmware on "http://dd-wrt.com/site/support/router-database" for the NR22/Y is build 14896 (that means its older than mine, am I right?)
telnet has not the same pwd that webui, I would like to get ssh connections and configure VPN, where can I find information about it?
Is normal the firmware let visible features that the router does not support? I guess some of them are not supported by mine, cause when I make the configuration sometimes the router gets fickle.
Posted: Tue Jan 03, 2012 18:52 Post subject: Re: USB?
frollic wrote:
riven999 wrote:
Hello all.....
Succesfully load DDWRT on my router with the howto above.......
Any idea how to have USB working?
Thanks.........
compile your own modules, they're not a part of the Aceex image, since it doesnt have any usb port.
Hi everyone! I managed to put the aceex firmware via serial connection and tftp. Then updated to dd-wrt by the ddwrt.sh telnet comand.
Everything working but not the 3g, and that's why i buyed the "3g china router" first place.
Since the aceex router doesn't have 3g support, the ddwrt version also doesn't have too...
Is there any version of dd-wrt that i can flash into this to enable 3g support?
For what i've read in forum/wiki only ddwrt mega versions have usb/3g support, for other versions we have to mannualy add this, but i couldn't find how to do it.. Any help?