Netgear R6300v2 Advanced Debrick Notes By Sploit

Post new topic   This topic is locked: you cannot edit posts or make replies.    DD-WRT Forum Index -> Broadcom SoC based Hardware
Goto page Previous  1, 2, 3, ... 12, 13, 14  Next
Author Message
sploit
DD-WRT User


Joined: 16 Apr 2016
Posts: 307
Location: California

PostPosted: Tue Oct 04, 2016 7:03    Post subject: Now that I think about it Reply with quote
I could just build a initramfs that issues the MTD command on boot by adding it to the OpenWRT Startup Script. Would be fast and would reboot the router into tftp mode.

That would be easier huh?
Sponsor
OneMoar
DD-WRT User


Joined: 15 Jan 2011
Posts: 50

PostPosted: Tue Oct 04, 2016 7:13    Post subject: Reply with quote
that would work but I am not sure if auto nuking the firmware/nvram is the way to go reboot directly into tftpmode would be nice if it could be done without auto-nuking or at least change it to expect any .chk you throw at it
a botched mtd erase could end in permabrick if its interrupted or something unexpected happened

there has gotta be a way to get it to tftp any chk you throw it at once openwrt is loaded probly would involve including tftp client for recovery to override the cfe routine once openwrt was up that way you can use tftp32d and just have any old image renamed to say recovery.chk

I tried twice to reflash tomato from openwrt and it bombed each time eventually it crashed it self into a state where I was able to tftp the stock neargear firmware with good ol tftp2.exe (tfptd32 would't let me push a image no matter what I did)
sploit
DD-WRT User


Joined: 16 Apr 2016
Posts: 307
Location: California

PostPosted: Tue Oct 04, 2016 21:22    Post subject: I actually put that in the notes... Reply with quote
I actually put that in the notes...

You cant use TFTP2 because the transfer times out with it.

As far as not being a good idea.... On the r6300v2 its a great idea because it forces it into tftp mode and awaits any valid firmware.

However I am unsure if the 6250 is different so I would have to get one and see.


Also for KONG

What router are you needing the most to be donated right now?
OneMoar
DD-WRT User


Joined: 15 Jan 2011
Posts: 50

PostPosted: Wed Oct 05, 2016 0:48    Post subject: Re: I actually put that in the notes... Reply with quote
sploit wrote:
I actually put that in the notes...

You cant use TFTP2 because the transfer times out with it.

As far as not being a good idea.... On the r6300v2 its a great idea because it forces it into tftp mode and awaits any valid firmware.

However I am unsure if the 6250 is different so I would have to get one and see.


Also for KONG

What router are you needing the most to be donated right now?

I was thinking you could include the tftp-client package in the openwrt build and have it run on startup
once its up then you could tftp any image in and use a script on the openwrtside to self flash

and in my case I was able to tftp2.exe the stock netgear firmware(I used tftpd32 to get the vmlinuz running ) Once I issued a `mtd erase firmware` thats how I ended up recovering it
OneMoar
DD-WRT User


Joined: 15 Jan 2011
Posts: 50

PostPosted: Wed Oct 05, 2016 0:55    Post subject: Reply with quote
tftp32d would not push R6250-V1.0.4.2_10.1.10.chk

after loading vmlinuz no matter what I did so I issued a mtd erase firmware and then booted it holding the reset button which put it in tftp mode

the ping went from the stander ed 5 second wait to TTL=100 constantly until you flashed something then it would reset and load the new firmware and the light turned from steady orange to flashing green indicating waiting for image once you wrote a image with tftp2.exe it would go timeout and then destination host unreachable as it rebooted and then resume loading the new image


after that I could flash anything I wanted with tftp2.exe from windows 10 (which should't work because of 10's new netstack but it did =/ )
I tried AT first then the stock netgear firmware both images where successfully sent by tftp2.exe but only the stock netgear one took which may or may not have been because of the image size and the stablity of the openwrt session
<Kong>
DD-WRT Guru


Joined: 15 Dec 2010
Posts: 4339
Location: Germany

PostPosted: Wed Oct 05, 2016 19:54    Post subject: Re: I actually put that in the notes... Reply with quote
sploit wrote:
I actually put that in the notes...

You cant use TFTP2 because the transfer times out with it.

As far as not being a good idea.... On the r6300v2 its a great idea because it forces it into tftp mode and awaits any valid firmware.

However I am unsure if the 6250 is different so I would have to get one and see.


Also for KONG

What router are you needing the most to be donated right now?


I would like to examine the D7800, I looked through the GPL release and there is a slight chance that the DSL module is supportable since it comes with a lantiq cpe. I'm soon going to switch to VDSL I need to find me a VDSL modem or have a router with a comptible modem and this lantiq cpe has support for vectoring thus should work with german telekom.

Besides that I'm looking forward to the new Netgear R9000:

https://apps.fcc.gov/eas/GetApplicationAttachment.html?id=3143703

Judging by the label it seems like this unit comes with a 10GBit port:-)

Sounds like it could fix one of my problems, large file transfers from mobile units to a 10G backend via 60GHz wireless. Rumors tell me that you can transfer at ~2.5GBit if you have two of them.

_________________
KONG PB's: http://www.desipro.de/ddwrt/
KONG Info: http://tips.desipro.de/
Xeon2k8
DD-WRT Guru


Joined: 11 Feb 2016
Posts: 1288

PostPosted: Fri Oct 07, 2016 13:09    Post subject: Reply with quote
Hi guys, so from I what I have understood R6250 would also brick on BS builds later than 30432?

@Kong do you know when the image size problem is going to be resolved? If it's planned to be resolved at all..

Thank you all

Edit: Ok, seems that anything lower than R6400 won't work, found these
http://svn.dd-wrt.com/ticket/5530
http://svn.dd-wrt.com/ticket/5560
http://svn.dd-wrt.com/ticket/5571
sploit
DD-WRT User


Joined: 16 Apr 2016
Posts: 307
Location: California

PostPosted: Fri Oct 07, 2016 20:40    Post subject: I cant speak for the r6400 but .. Reply with quote
I cant speak for the r6400 but ..
Considering they are similar in most ways there is definitely something wrong with the builds after 09/01/2016 and the image sizes jumped by almost 3 Megs. They are bricking the r6300v2's.

Kong's builds are stable and I have flawless runtime so stick with the Kong Builds until this gets resolved with Brainslayer.

I have noticed OpenVPN issues after 09/01/2016 on Brainslayer builds on other Netgear Models also.
merrow75
DD-WRT User


Joined: 28 Jan 2016
Posts: 128

PostPosted: Mon Oct 10, 2016 18:16    Post subject: R6250 - Bricked Reply with quote
Hello,

I attempted to load dd-wrt.K3_R6250.chk (dated 2016-09-27) onto a R6250 running v1.0.1.84_1.0.78 using the Netgear GUI.

After the GUI accepted the upload of the file, the R6250 went into rolling reboots.

It is pingable at 192.168.1.1 for a few seconds until it next reboots.

I have configured a tftp server on a Ubuntu 16.04 laptop and placed the vmlinuz (unzipped) file into the root of the tftp server

I have verified that the tftp server is working by using a tftp client to get the vmlinuz file.

But the R6250 does not pull the vmlinuz file and the rolling reboots continue.

I have installed Wireshark but it does not show any evidence that the R6250 is trying to read from the tftp server.

Any suggestions?

Thank you for your help.
sploit
DD-WRT User


Joined: 16 Apr 2016
Posts: 307
Location: California

PostPosted: Mon Oct 10, 2016 20:49    Post subject: What IP is your tftp server on? Reply with quote
The TFTP server has to be on 192.168.1.2.

Also if the IP is pingable for a few seconds that suggests bootwait is enabled.
ghoffman
DD-WRT User


Joined: 03 Jan 2010
Posts: 453

PostPosted: Tue Oct 11, 2016 1:01    Post subject: Reply with quote
the major problem with this router is that the cfe checks the header on the .chk firmware against a string in the "board_data" mtd partition, which is returned by the 'burnboardid' command in stock netgear firmware as board_id=U12H240T00_NETGEAR
if firmware was loaded which does not respect the board_data partition, or which changes the the board_data, or if the uploaded image does not contain the correct header, then the tftp ddaemon will not flash the uploaded firmware.

if the board_id partion has the correct stricng, then you have to upload a .chk image made for the r6300v2.

if the board_id partiton contains HDR0 (which occurred on mine by not going correctly back to stock from dd-wrt or tomato) then i *think* serial recovery is still required.

in my case (many times0 the router would send continual ttl=100 replies to ping, would accept a tftp'd image, but would not flash.
I tried the vmlinuz-via-tftpd many times and there was never an attempt to load the image.

the only way i got out of this mess was to tftp a hdr0 file (without he extra header in a .chk file) an issue the following coomadn on the serial console:
flash -noheader : flash1.trx

i have modofed the cfe on my R6300v2 to have boot_wait=on and board_id=U12H240T00_NETGEAR in nvram. but i havent tested the softbrick-resilience yet. i have in my head a modified xvortex cfe to get around all this board_data nonsense, but i'm not far into that project yet.

my knowledge of these subjects is entirely by extensive reading of these boards and too much time obsessing with my own devices. this is meant to be helpful and i invite more help. thank you
sploit
DD-WRT User


Joined: 16 Apr 2016
Posts: 307
Location: California

PostPosted: Tue Oct 11, 2016 3:11    Post subject: The ttl 100 Ping... Reply with quote
You are correct and I stated this.

If the board is awaiting firmware it will ping 100 and you have no need for the bootwait. Simply flash the firmware.
merrow75
DD-WRT User


Joined: 28 Jan 2016
Posts: 128

PostPosted: Tue Oct 11, 2016 6:39    Post subject: Reply with quote
Thank you for the replies.

The tftp is on 192.168.1.2 - sorry for not providing this detail earlier.

I will try again otherwise I will explore recovery via serial.

Thank you again.
merrow75
DD-WRT User


Joined: 28 Jan 2016
Posts: 128

PostPosted: Tue Oct 11, 2016 21:35    Post subject: R6250 - Bricked Reply with quote
Quick update:

I returned the R6250 to Netgear firmware using serial recovery so at least the router is online.

I will attempt to load dd-wrt again.
sploit
DD-WRT User


Joined: 16 Apr 2016
Posts: 307
Location: California

PostPosted: Tue Oct 11, 2016 22:07    Post subject: Im gonna get one of these and see what it does via serial Reply with quote
Im gonna get one of these and see what it does via serial.

The process may be a little different on it.
Goto page Previous  1, 2, 3, ... 12, 13, 14  Next Display posts from previous:    Page 2 of 14
Post new topic   This topic is locked: you cannot edit posts or make replies.    DD-WRT Forum Index -> Broadcom SoC based Hardware All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum