[Unlock] WRTP54G with Firmware 5.01.04
Links: home · search · speed test · login · more ·
Links: Reply New Topic
Forums » Voice Over IP - VOIP » VOIP Tech Chat » [Unlock] WRTP54G with Firmware 5.01.04
page: 1 · 2 · 3 · 4
nezarus @ 11th Feb 11:35PM:
[Unlock] WRTP54G with Firmware 5.01.04
A couple of days ago, I bought two WRTP54G (Vonage) units.
One with firmware 1.00.62, other 1.00.20
cyt46 worked fine with 1.00.62, within 15 minutes I had an unlocked unit with firmware 3.1.24
The second unit was not that lucky.
As predicted by rcilink cyt46 didn't work with 1.00.20
After messing with it a little bit, I connected the router to my modem and hit the reset button. As expected,
firmware provisioned to 5.xx (5.01.04)
I tried many things with no results, but finally the following procedure worked:
- browser tab,go 192.168.15.1 and login admin/admin
- at dos prompt run cty46 and option 1 (starts XML server) and leave it running
- browser tab, goto 192.168.15.1/update.html
- enter user/user
- upload modified firmware 3.1.24 (for WRTP54G-NA)
- dos prompt, ESC from cyt46
- browser tab, start upgrade
- wait until upgrade is loaded and the router resets.
- my router didn't reset automatically, so I waited 10 min. (until the browser is timed out) and hit the reset button.
Now, I have two unlocked WRTP54G with 3.1.24
PS: I'm not sure if cyt46 aid for this procedure is required or not. May be the password for 'user' in 5.01.04 is 'user' (instead of tivonpw). Someone else can test the user/user on a 5.xx router see if it works for firmware page.
WHEN YOU PLAY WITH FIRMWARE, THERE IS A POSSIBILITY TO BRICK YOUR ROUTER. USE THIS INFO AT YOUR OWN RISK. DON'T BLAME ME.
reply
mazilo @ 12th Feb 12:03AM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
Thanks for sharing and am sure others will benefit from this. Please do let us know if your device will operate without any instability. Some of our unlocked WRTP54G-ER (not from Vonage version) seem to have run into problems, i.e. auto reboot, etc.
reply
naskop @ 13th Apr 05:36PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
I tried unlocking a RTP300 router, firmware version 5.01.04 according to the procedure nezaurus used but without success. Has anybody else had any luck unlocking routers with 5.01.04 firmware?
reply
anon @ 15th Apr 01:56PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
I have the same problem with RTP300 and 5.01.0 firmware... is locked.
reply
Velund @ 19th Apr 01:25PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
Just unlocked RTP300 with 5.01.04. The trick is to unlock serial console (ping hack), then downgrade firmware from bootloader. When you have access to shell - you can do everything you want, and all this was discussed here many times.
reply
mazilo @ 19th Apr 01:40PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
said by Velund :
The trick is to unlock serial console (ping hack), then downgrade firmware from bootloader.
How do you unlock serial console?
reply
anon @ 19th Apr 02:54PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
Can u please tell us how you unlocked the console?
reply
Velund @ 19th Apr 04:28PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
Used firefox with web dev. plugin to work with ping hack. First uploaded small shell file with command to change env. var to /var/tmp using wget, then chmod this file to make executable, then run it. Three groups of commands via ping hack hole. The rest of unlocking is as usual.
Ping hack does not work with any commands that have redirection, so was forced to do this little bit tricky way.
Now have -NA freely upgradeable with stock -NA firmware.
reply
mazilo @ 19th Apr 06:09PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
said by Velund :
Used firefox with web dev. plugin to work with ping hack. First uploaded small shell file with command to change env. var to /var/tmp using wget, then chmod this file to make executable, then run it. Three groups of commands via ping hack hole. The rest of unlocking is as usual.
LOL. This doesn't sound like a serial-console unlocking to me.
--
Mazilo always prays for FREEBIES!
US Phone: +1-678-601-0907
UK Phone: +44-703-194-2574
reply
Velund @ 19th Apr 06:32PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
But the result is unlocked serial console, and unit can be easily downgraded to a more useful firmware. ;) Much more can be done via ping hack (if you can throw in a shell file, you can do almost anything without opening unit, but I doubt that erasing and rewriting bootloader is safe using ping hack - I crashed router at least three times until found max. command line length that does not crash it).
So, I just feed 'echo "setenv CONSOLE_STATE unlocked" >>/proc/ticfg/env' that way and do the rest using serial console.
reply
mazilo @ 19th Apr 07:13PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
said by Velund :
But the result is unlocked serial console,
I don't think you have a serial console. What you have is a shell. A serial console can only be accessed through a USB/serial port with a USB/serial-console cable.
reply
Velund @ 19th Apr 08:20PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
said by mazilo :
A serial console can only be accessed through a USB/serial port with a USB/serial-console cable.
Hm... It's exactly what I have here. I used ping hack only to change bl env variable and get access to bootloader command prompt using serial cable (yes, the one connected to 5-pin header inside of the box, through a adm3202-based level converter, if you still in doubt). ;) Does we talking different languages? ;)
Anyway, those who need it got a confirmation that this version is unlockable and general idea about one of possible ways to go. ;) I will be glad to see reports about other methods. ;)
reply
mazilo @ 19th Apr 08:32PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
said by Velund :
Hm... It's exactly what I have here. I used ping hack only to change bl env variable and get access to bootloader command prompt using serial cable (yes, the one connected to 5-pin header inside of the box, through a adm3202-based level converter, if you still in doubt). ;) Does we talking different languages? ;)
Excellent and we are in sync! So, the problem you had was unable to access the serial console because it was locked by default. Good job.
--
Mazilo always prays for FREEBIES!
US Phone: +1-678-601-0907
UK Phone: +44-703-194-2574
reply
toro @ 19th Apr 10:43PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
I haven't been too lucky using nezarus's method, but the one described by Velund worked great ! Very nice work !
reply
goodchefro @ 20th Apr 04:52AM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
you guys really speak ....different languages!
Velund, or Liviu, would you guys care to explain in more layman's terms how you exactly do the procedure?
Of course, you have the right to not share...
thanks.
reply
mazilo @ 20th Apr 08:09AM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
said by goodchefro :
Velund, or Liviu, would you guys care to explain in more layman's terms how you exactly do the procedure?
If I understand Velund correctly, his method requires a USB/serial-console cable to unlock through the serial-console port. Since the serial-console port is disabled by default, you will first need to enable it using the SETENV through a login session. Velund used the ping hack to inject a shell to bring up a login session to enable the serial-console port using the SETENV. Once that was done, he used a USB/Serial-console cable to access the serial-console port to unlock his device.
Velund, please kindly verify what I mentioned above. Thanks.
--
Mazilo always prays for FREEBIES!
US Phone: +1-678-601-0907
UK Phone: +44-703-194-2574
reply
goodchefro @ 20th Apr 08:14AM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
I guess I can make some sense of it now, tks Mazi.
reply
mazilo @ 20th Apr 08:27AM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
said by goodchefro :
I guess I can make some sense of it now, tks Mazi.
No problem.
reply
Velund @ 20th Apr 09:28AM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
Well. Looks like some more details really necessary... I don't like to publish detailed explanation of that sort because in next firmware release found holes usually disappears.. But this time it doesn't really matters.
Assumed that you already have tftp server (like tftpd32) installed and running. Also, it is assumed that you have firefox with web developer plugin installed. Plugin is necessary to be able to remove field length limit after each ping page reload.
First, make a text file (it was named "wr" in my case, without extension) in a tftp root directory, with unix-style line terminations.
Now, login to router, go to "Administration" tab, then to "Diagnostics". Click "Ping", new window will be open.
Right click on new window, select web developer plugin entry from menu, then forms, then remove limits.
Type the following in address field:
Window will reload. Now repeat removing of field length limit and type the following:
Window will reload again. Repeat removing of field length limit and, finally, type the following:
If everything went good, you'll see current state of bootloader environment vars in ping result window with CONSOLE_STATE unlocked.
Now, console is unlocked, and you can do anything with router.
reply
Velund @ 20th Apr 09:39AM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
PS: Attempts to feed all commands in one line caused router crash, looks like there is quite small line buffer somewhere, so I split it. I don't pretend that it is optimal, but it worked for me exactly that way, and I have no more locked RTP300's to verify something more optimised before publishing... ;) Should work for both RTP300 and WRTP54G, but tested only on RTP300.
reply
mazilo @ 20th Apr 09:58AM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
Deleted due to double post.
reply
mazilo @ 20th Apr 10:03AM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
said by Velund :
... I don't like to publish detailed explanation of that sort because in next firmware release found holes usually disappears..
Worse thing Linksys will do is to remove the ping and/or the Diagnostic Menu since I believe (haven't tested, yet) traceroute can probably be used to perform the hack. OTOH, I believe it is a big mistake for Linksys to configure State Console disabled by default unless there is a known way to enable it; otherwise, no one will be able to access its serial-console port.
--
Mazilo always prays for FREEBIES!
US Phone: +1-678-601-0907
UK Phone: +44-703-194-2574
reply
Velund @ 20th Apr 10:06AM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
Ping hack is known for a quite long time, and disappeared in some firmware revisions in the past, but in 5.01.04 it is available again... So, let's use it. ;)
By the way, there is a lot of things can be done at once, not only unlock of serial console.
reply
mbuugg @ 20th Apr 09:48PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
Here is my unsuccessful story of hacking the Vonage 5.01.04.
First, user/user did not work for my Vonage 5.01.04. Then I used the ping hack and simply replaced the Admin password in /etc/shadow. After replaceing the password, I can ssh into the shell but still cannot get access to the firmware update page. So I used the methods on the Openwrt page. First I dd'ed a hacked firmware into /var/tmp/fw.bin, did not work. Then /dev/mtd/4, did not work either. Then /dev/mtd/3. Several seconds after finishing the flashing, I had a bricked wrtp54g.
I then got the -ER dump from Mazi (thanks Mazi) and JTAG flashed the whole dump. After flashing, the router will only respond to ping, nothing else will it do. This looks like the same situation boredwild had met (»wrtP54g unbrick restore help). So I emailed him how he got his to work. He told me he bricked his wrtp54g a second time, and the second time he flashed the -ER dump, the router did not work. However, he got a Vonage 5.01.04 dump which worked with user/user and had Admin password blanked, and he flashed that dump. Now I am waiting for his Vonage 5.01.04 dump to see if it will revive my wrtp54g. Any idea or flash dump that may save the wrtp54g are welcomed. Thanks.
reply
mazilo @ 20th Apr 10:31PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
said by mbuugg :I then got the -ER dump from Mazi (thanks Mazi) and JTAG flashed the whole dump. After flashing, the router will only respond to ping, nothing else will it do. This looks like the same situation boredwild had met (»
wrtP54g unbrick restore help). So I emailed him how he got his to work. He told me he bricked his wrtp54g a second time, and the second time he flashed the -ER dump, the router did not work. However, he got a Vonage 5.01.04 dump which worked with user/user and had Admin password blanked, and he flashed that dump. Now I am waiting for his Vonage 5.01.04 dump to see if it will revive my wrtp54g. Any idea or flash dump that may save the wrtp54g are welcomed. Thanks.
Sorry to hear the JTAG dump from an -ER version didn't work for you and borewild. However, I do hope the v5.01.04 dump will be able to revive your unit.
--
Mazilo always prays for FREEBIES!
US Phone: +1-678-601-0907
UK Phone: +44-703-194-2574
reply
mbuugg @ 21st Apr 12:06AM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
Hi Mazi, you are always welcomed. I read out the dump from the router to see if it made any change to the -ER dump after it had run with -ER dump. I do see some changes in the boot partition 0xb0000000-0xb000ffff, and it appended a default set of boot_env after the original boot_env that is already in the boot_env partition 0xb0010000-0xb001ffff. I reflashed some of the blocks so that the whole flash is exactly the same you sent me (including the MAC and SN). After the router booted a couple of times, I read out the dump and found similar changes the router made to the flash.
reply
boredwild @ 21st Apr 05:58AM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
Funny thing is that the -ER dump worked on the Vonage the first time. Used as a router for several weeks but the unit had a lot of static on the voice ports. JTAG flashed it with another member's Vonage 5.1.04 firmware to see if it made a difference to the voice performance, and to see if anything could be done about unlocking the version 5. Bricked it by modding the hex, so tried to go back to the same -ER binary that worked previously, but no go, so I reflashed with Vonage5 via JTAG and finally unlocked by doing a webflash to 3.1.24 modded for Vonage. Have no explanation for why the -ER worked once and not again - beyond my expertise.
reply
mazilo @ 21st Apr 08:18AM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
said by mbuugg :
I do see some changes in the boot partition 0xb0000000-0xb000ffff, and it appended a default set of boot_env after the original boot_env that is already in the boot_env partition 0xb0010000-0xb001ffff.
I was hoping you were able to perform a factory reset, do the dump, and then comparison again to see some changes. BTW, does the IVR (especially ****73738#1) work on your unit?
--
Mazilo always prays for FREEBIES!
US Phone: +1-678-601-0907
UK Phone: +44-703-194-2574
reply
mbuugg @ 21st Apr 12:21PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
Thanks to boredwild, I now have the patched Vonage 5.01.04 dump. I noticed that the HASH_DIR was not blanked out in this dump while it was blanked out with 0x20 in Mazi's dump. I don't know if this matters or not. Mazi, if you still have the original unpatched dump you can send me the first 128kbyte and I can try if that works or not before another 36 hours of JTAG flashing.
The factory reset, either by holding down the reset button or by IVR ****73738#1 did not work. I found that the reset button actually works (press and release). However, if I hold down the button to do factory reset, though it looks nothing happens to the router, the router later on will not respond to the plain reset (press and release) any more.
reply
mbuugg @ 24th Apr 04:41PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
Update: Successful with Vonage 5.01.04 dump
JTAG flashed the Vonage 5.01.04 dump from boredwild which works with user/user and has Admin password blanked. Loaded the modded firmware 3.1.24 then 3.1.27. Both work fine. Thanks to boredwild and mazilo! :)
reply
mazilo @ 24th Apr 04:49PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
said by mbuugg :
Loaded the modded firmware 3.1.24 then 3.1.27.
Congratulation! Another WRTP54G happy camper. :D BTW, Did you also have to mod firmware v3.1.27 to load it your WRTP54G?
reply
mbuugg @ 24th Apr 05:00PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
Yep. The mod is in the same way as previous versions.
offset 17H: 4D -> 4C
offset 3b0004: B0 C9 8B 1C -> 0E B6 E6 7D
reply
chinusa @ 4th May 02:22AM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
said by mbuugg :
Yep. The mod is in the same way as previous versions.
offset 17H: 4D -> 4C
offset 3b0004: B0 C9 8B 1C -> 0E B6 E6 7D
mbuugg,
Thanks, I modded the firmware version 3.1.27 NA and successully upgraded my vonage wrtp54g originally with 3.1.27 ETSI.
reply
toro @ 8th May 09:25AM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
Thanks, I modded the firmware version 3.1.27 NA and successully upgraded my vonage wrtp54g originally with 3.1.27 ETSI.
For my curiosity, does anyone know what "ETSI" means in some of the firmware versions for the RTP300/WRTP54G ? I saw it mentioned here too, but it's not clear what it is: »wiki.openwrt.org/OpenWrtDocs/Har···/WRTP54G
reply
mazilo @ 8th May 09:38AM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
said by toro :
..., does anyone know what "ETSI" means in some of the firmware versions for the RTP300/WRTP54G ?
Can ETSI be an acronym for European Telephone Standard Interchange?
reply
toro @ 8th May 10:25AM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
Thanks, I think you're on the right track, it may also be European Telecommunications Standards Institute (according to »en.wikipedia.org/wiki/ETSI).
Either way, something do do with European regulations.
And it kind of make sense, because all the ETSI firmware links at »wiki.openwrt.org/OpenWrtDocs/Har···/WRTP54G point to European VoSPs.
reply
mazilo @ 8th May 11:16AM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
said by toro :Thanks, I think you're on the right track, it may also be European Telecommunications Standards Institute (according to »
en.wikipedia.org/wiki/ETSI).
That's the right one. Thanks.
Sort of FCC in the US.
--
Mazilo always prays for FREEBIES!
US Phone: +1-678-601-0907
UK Phone: +44-703-194-2574
reply
Waxman @ 8th Jul 11:46AM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
I've gone through the procedure listed for a ping hack on an rtp300 with 5.01.04, but I don't get any messages in the display, and nothing unlocks. Can someone please give me a hand here?
reply
anon @ 16th Jul 12:37AM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
Un
Successfully unlocked the serial console on WRTP54G with Firmware 5.01.04 using the methods Velund mentions in the prior page
However 0.0.0.0 did not work I had to use 127.0.0.1 instead in all the places he had 0.0.0.0
Can someone point me to instructions on how to use the serial console to unlock?
thanks
reply
samwise3345 @ 19th Jul 09:17PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
said by wolfboy :
Successfully unlocked the serial console on WRTP54G with Firmware 5.01.04 using the methods Velund mentions in the prior page
However 0.0.0.0 did not work I had to use 127.0.0.1 instead in all the places he had 0.0.0.0
Can someone point me to instructions on how to use the serial console to unlock?
I second this. I have my serial voltage converter at the ready. I just need the pinout of the serial connector, and the commands needed to upload and flash the new firmware file. I have an rtp300 with v5.01.04, which does NOT revert to an earlier firmware when reset, and NONE of the previously posted un/pw combinations work in the web interface.
Another question i've got is about the CRYPT_KEY and ADMIN_PWD contained in the output from cat /proc/ticfg/env. The key displayed does not seem to allow me to decrypt either version of my ti001310xxxxxx.xml file (the router tftps two slightly different copies from two different directories), and the password doesn't work for anything in the web interface.
reply
rrangar @ 22nd Jul 01:02AM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
The layout and instructions are here (search for OPENWRT WRTP54G)
»www.google.com/search?q=OPENWRT+···soft:en-
US&ie=utf8&oe=utf8
However I could not get my serial console to post anything. If you get this working let me know which jumper is the serial console on the board (J1 with pins or J3 needs soldering?)
reply
toro @ 22nd Jul 10:34AM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
I second this. I have my serial voltage converter at the ready. I just need the pinout of the serial connector, and the commands needed to upload and flash the new firmware file. I have an rtp300 with v5.01.04, which does NOT revert to an earlier firmware when reset, and NONE of the previously posted un/pw combinations work in the web interface.
Another question i've got is about the CRYPT_KEY and ADMIN_PWD contained in the output from cat /proc/ticfg/env. The key displayed does not seem to allow me to decrypt either version of my ti001310xxxxxx.xml file (the router tftps two slightly different copies from two different directories), and the password doesn't work for anything in the web interface.
Once you get the serial console working, reboot and hit ESC to stop the boot process. Then you need to do the following:
format the 2 firmware partitions and the configurations, then flash the -NA firmware (modded to load on a Vonage router and to be flashed from the PSPBoot prompt - look through the other threads if you don't have it, there's plenty of info )
Replace your_TFTP_server_IP with the actual IP address and wrtp54g_na_pspboot.bin with the filename for your image.
As for the ADMIN_PWD and CRYPT_KEY: ADMIN_PWD contains the encrypted password while the web interface needs the unencrypted one. I don't know of any way to get one from the other, so this will not help you much. The CRYPT_KEY is not too useful either. As far as I can tell, the actual key for decrypting the Vonage's XML file is somehow obtained by combining the CRYPT_KEY and ADMIN_PWD environment variables. I haven't figured out how and frankly I didn't waste too much time on it since it isn't of much help to me. All I could find is that if you have access to the provisioning page on the router, you will see that the decrption key changes if you change either one of the CRYPT_KEY and ADMIN_PWD environment variables.
reply
toro @ 22nd Jul 11:09AM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
However I could not get my serial console to post anything. If you get this working let me know which jumper is the serial console on the board (J1 with pins or J3 needs soldering?)
It's J1, and the pinout is in paragraph 14 of »wiki.openwrt.org/OpenWrtDocs/Har···/WRTP54G
reply
herrdude @ 16th Aug 08:13AM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
This is my first post here, so I help you will bear with me. I bought a RTP300 from craig's list. When I brought it home, I tried all the passwords known to man, and I tried all the versions of CYT. Nothing worked. Then I noticed that I had the firmware 5.01.04. After searching, I ended up in this forum and in this post. I followed Velund's instructions on the first page using the ping hack. I had to substitute 0.0.0.0 with 127.0.0.1. I managed to get the message: control state unlocked.
Everyone states that this is a good thing and I can do what I want now (as I have read on few posts) but I am at a total loss what to do next.
I had read in another post that a quick way to get rid of the vonage provisioning was to use the following command through the ping hack with the following command: dd if=/dev/zero of=/dev/mtd/9. Would this work?
Any help would be greatly appreciated. I want to set this baby up to use my voipbuster account.
reply
mazilo @ 16th Aug 02:14PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
said by herrdude :
I followed Velund's instructions on the first page using the ping hack. I had to substitute 0.0.0.0 with 127.0.0.1. I managed to get the message: control state unlocked.
When you mentioned someone's instructions, it would be nice if you include the link here to the post on such instructions for a reference.
I had read in another post that a quick way to get rid of the vonage provisioning was to use the following command through the ping hack with the following command: dd if=/dev/zero of=/dev/mtd/9. Would this work?
This is only true after your RTP300 has been flashed with an RTP300-NA firmware released by Linksys (not Vonage). In order for your RTP300 to take an RTP300-NA firmware released by Linksys, you must make the necessary changes to the RTp300-NA firmware header. Such a mod has been discussed here in this forum numerously. Please use the search button to find out how to mod the header of this firmware.
--
Mazilo always prays for FREEBIES!
US Phone: +1-678-601-0907
UK Phone: +44-703-194-2574
reply
herrdude @ 17th Aug 10:18AM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
So, I went off to modify the software header. I followed these instructions from Rcilinks(»New WRTP54G-NA firmware 3.1.24 released 3-27-07)
1. Download the RTP300 3.1.24 firmware from the linksys site (link in previous msg)
2. Open the file in your HexEditor and change offset 0x17 from 4D to 4C.
3. At offset 0x3B0004, change 85 DA 20 BB to 3B A5 4D DA
4. Done!
At step 3. Using Hexedit, I didn't find: 85 DA 20 BB but rather EE F4 2E B9. This kinda stumps me. Is it ok to leave it like this?
After doing some reading, I was wondering if the following would be possible through the ping hack (Ping page + Firefox web developer plugin + TFTPD32), each line being sent by ping:
(A or B depending on the previous command line response)
Where flash_erase is from section 16.3 from »wiki.openwrt.org/OpenWrtDocs/Har···/WRTP54G
Would this work?
reply
Velund @ 17th Aug 05:06PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
Looks like you will not have enough free spave in /var to store whole firmware image. I used similar approach to reflash patched bootloader (to make unit -NA), but there is just 64k, and real trick was to reinit environment vars after you reflash the bootloader...
By the way, I do not recommend to try to play with flash_erase if you not understand really good what you are doing, and not have jtag and serial level converter handy.
reply
herrdude @ 17th Aug 08:08PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
Let me ask you, if you didnt have a serial hookup, what would be the best way to unlock this firmware? I dont mind fooling around and trying something out.
I appreciate any input you can give me!
reply
anon @ 19th Aug 07:03PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
I am not looking to be spoon fed. If someone could point me in the right direction to do this without a serial console.
I would be etnernally grateful.
reply
boredwild @ 20th Aug 12:41AM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
Would you mind elaborating on what changes you made to the bootloader to make it an -NA? What provider was it locked to originally? Thanks
reply
Velund @ 20th Aug 03:23PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
It was former Vonage unit.
Change CYLL->CYLM (use patched image read from this particular unit to avoid MAC address change), then erase environment variable area starting at 64K. On a next reboot bootloader will reinit environment vars with defaults, and you'll have RTP300-NA. -NA firmware images must be loaded.
reply
Pcpro745 @ 23rd Aug 04:23PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
I have the password for this firmware after spending 3 hours on the phone with vonage i finally got it, If you want it PM me or hit me up on AIM- SuperCobaltss or MSN Computerpro745@msn.com
reply
boredwild @ 23rd Aug 11:51PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
Environment variable area extends from 64K to where? Just one 64K block? Thanks.
reply
boredwild @ 23rd Aug 11:53PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
Why don't you let us all know? Surely it won't be the same in the next version of firmware.
reply
Pcpro745 @ 26th Aug 12:46AM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
More secure this way, And they cant use google to find there password online this way also
reply
boredwild @ 5th Sep 04:48PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
Will you send it to me via PM then? I'd be interested to try the v5 firmware with my provider to see if it works any more reliably than the 3.1.27. Presently it likes to drop the wireless periodically when the phone is in use. Thanks.
reply
DogFace05 @ 5th Sep 05:13PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
Vonage's practice is to assign an individually unique admin password to each and every adapter. Pcpro745's admin password won't do anyone else any good.
reply
tickticktick @ 5th Sep 09:29PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
Given that we can get into v5 thru the ping hack, and can mod the voice xml config file in /var/tmp -- i assume ggsip reads that... is there someway to cause ggsip to reload and reread the mod'd voice config? Alternatively, is it possible to mount -o rw /? The goal, as with the poster above, is to try the v5 instead of the v3 f/w.... i don't care if it's permanent yet... i can, for now, automate the re-config via the ping hack.
Another approach I was considering faking a cgi-bin post via shell with needed env mods to simulate a web post to cause a reconfig - it would think it came from the webserver....anyone have the v5 voice config pages they could post so i can see what its posting to what?
Tnx
reply
boredwild @ 6th Sep 09:11AM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
Dogface05, can you tell us what you charge to unlock the ACN SPA-2102?
reply
jetzhu @ 6th Sep 02:23PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
use ping hack.
reference to Velund's post on 2008-04-20 09:28:16:
»[Unlock] WRTP54G with Firmware 5.01.04
Suggest you go through Velund's post first, to make sure you understand how to use ping hack. That will also get the console unlocked, in case anything bad happen.
Then, you need to prepare an device acceptable firmware.
I download one from here:
»httpconfig.vonage.net/rt-11.1.0-···0327.img
(use "tftp -i ls.tftp.vonage.net GET rt-11.1.0-r021-1.00.62-r060327.img" in dos promote to get the complete file if http give you broken files. it will take almost 10minutes)
you may be able to find others here:(Warning: Their server is not stable all the time. sometimes you only download part of the file, you need to verfy the file download have size of 3,866,632 bytes.
»wiki.openwrt.org/OpenWrtDocs/Har···/WRTP54G
I tested with the version of 1.00.62.
download the file, change the name to von10062.bin and put under your tftp's file folder
Edit an script. i.e.
#!/bin/sh
cd /var/tmp
wget tftp://192.168.15.100/von10062.bin
dd if=von10062.bin of=/var/tmp/fw.bin
use unix line terminator("\n" only in c fprintf style) for each line please. save it as rf and put in your tftp's file folder
then ping hack:
127.0.0.1 &&cd /var/tmp &&wget tftp://IP addr of your PC/rf
127.0.0.1 &&cd /var/tmp &&chmod 755 rf
127.0.0.1 &&sh /var/tmp/rf
After the power light flashing, you got an firmware version 1.00.62. volla... old firmware...then. you know what to do... right...or else.... »www.bargainshare.com/index.php?s···ic=87504
Possible to change the firmware from 5.01.04 directly to modified 3.1.24 NA which is created by the following steps
»Re: New WRTP54G-NA firmware 3.1.24 released 3-27-07
For RTP300
1. Download the RTP300 3.1.24 firmware from the linksys site (»www.linksys.com/servlet/Satellit···ondetail)
2. use HexEditor change offset 0x17 from 4D to 4C.
3. At offset 0x3B0004, change 85 DA 20 BB to 3B A5 4D DA
For WRTP54G, WRTP54G have different pattern
2. Change HEX offset 0x17 from 4D to 4C
3. Change HEX offset 0x3B0004 from 71 FB 16 5F to CF 84 7B 3E
Need a hard reset (10seconds hold of reset) to change the configuration back to the firmware default, (Thanks a94cobra confirmed working).
Try at your own risk. no guarantee to work. only tested on one RTP300 unit and succeed. if you got a spare one I would like to try other shortcut.
------------------------------
Vonage is doing their job to bring the telephone service cost down. Though it may not be at the point that all customer satisfied yet, at lest, they are trying. Please only use above thought on unused device to prevent electronic waste.
reply
DogFace05 @ 8th Sep 04:26AM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
said by boredwild :
Dogface05, can you tell us what you charge to unlock the ACN SPA-2102?
I don't believe I can answer this question publicly on this forum, or in any way discuss any topic here related to services I offer, without it somehow violating forum rules.
The few times in the past, when I've posted in reply to specific questions asked of me on this forum about my unlocking service, I've gotten heat from the site moderator, and complaints from a few militant members who harbor resentment toward me for unknown reasons.
Unless this site's moderators explicitly post their consent here to my answering your question, I'm afraid all I can suggest is that you contact me by private IM or email with any questions you may have. I will not post my email address, but you may be able to find it posted by others on this and/or some other message boards.
reply
a94cobra @ 10th Sep 02:18PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
said by jetzhu :The following method is untested, just an idea:
Possible to change the firmware from 5.01.04 directly to modified 3.1.24 NA which is created by the following steps
»
Re: New WRTP54G-NA firmware 3.1.24 released 3-27-07For RTP3001. Download the RTP300 3.1.24 firmware from the linksys site (»
www.linksys.com/servlet/Satellit···ondetail)
2. use HexEditor change offset 0x17 from 4D to 4C.
3. At offset 0x3B0004, change 85 DA 20 BB to 3B A5 4D DA
For WRTP54G, WRTP54G have different pattern2. Change HEX offset 0x17 from 4D to 4C
3. Change HEX offset 0x3B0004 from 71 FB 16 5F to CF 84 7B 3E
I tried this on a WRTP54G with the 5.01.04 and was successfull. At first upon reboot the router seems bricked. Computer would not get an IP. Even after power cycle. But after the 10sec reset, it came up and I logged in to see 3.1.24 Voice section is there and reports 3.1.22
Not sure where to go from here but the router is downgraded with this method.
reply
jetzhu @ 10th Sep 05:40PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
I believe it's also unlocked. you can go gizmo5.com apply for an account. and Ipkall.com to apply for a phone number. After setup your ATA with the information you got from the above two websites, you can got other's call you at a US / DC phone number on your unlocked device.
reply
mazilo @ 10th Sep 08:01PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
said by a94cobra :
I tried this on a WRTP54G with the 5.01.04 and was successfull. At first upon reboot the router seems bricked. Computer would not get an IP. Even after power cycle. But after the 10sec reset, it came up and I logged in to see 3.1.24 Voice section is there and reports 3.1.22
After a factory reset and you still see firmware v3.1.22, then your upgrade to v5.01.04 doesn't seem to be of any success; otherwise, you would be seeing the new version of just installed firmware.
--
Mazilo always prays for FREEBIES!
US Phone: +1-678-601-0907
UK Phone: +44-703-194-2574
reply
a94cobra @ 11th Sep 02:09PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
I went from 5.01.04 to 3.1.24
Successful.
reply
mazilo @ 11th Sep 05:38PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
said by a94cobra :
I went from 5.01.04 to 3.1.24
Successful.
Congratulation! Cheers.
--
Mazilo always prays for FREEBIES!
US Phone: +1-678-601-0907
UK Phone: +44-703-194-2574
reply
janakjanak @ 13th Sep 07:06PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
Hi, I am new here please help me.
I bought RTP300 from ebay recently. It is locked by vonage firmware version 5.01.04. I tried zetzhu's instructions on the page »Re: [Unlock] WRTP54G with Firmware 5.01.04
Everything looks fine, I see von10062.bin downloaded from TFTP server log. But after that power light did not blink and firmware version is still 5.01.04.
Dont know if my ebay seller tried to unlock this unit earlier, but i see a character "n" next to unlocked as below in console_state env value.
CONSOLE_STATE unlocked n
BOOTCFG m:f:"IMAGE_B"
ProductID CYLL
Any help would be appriciated.
reply
Phoenix2088 @ 13th Sep 07:58PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
I have followed jetzhu's instructions and I think I almost got it. However at the last ping hack step
(127.0.0.1 &&sh /var/tmp/rf) I get the following.
The router's (WRTP54G) power light does not blink and is still running firmware 5.01.04. If anyone can help me and point out what I might have done wrong it would be greatly appreciated.
Background Info:
Running TFTPD32, AV and Firewall off during ping hack. Firmware is in Program Files/tftp32 directory as well as the rf file. TFTP32 is set to use the previously mentioned directory as root. I have already successfully ping hacked to unlock the console.
reply
anon @ 14th Sep 04:44PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
said by Phoenix2088 :
I have followed jetzhu's instructions and I think I almost got it. However at the last ping hack step
(127.0.0.1 &&sh /var/tmp/rf) I get the following.
The router's (WRTP54G) power light does not blink and is still running firmware 5.01.04. If anyone can help me and point out what I might have done wrong it would be greatly appreciated.
Background Info:
Running TFTPD32, AV and Firewall off during ping hack. Firmware is in Program Files/tftp32 directory as well as the rf file. TFTP32 is set to use the previously mentioned directory as root. I have already successfully ping hacked to unlock the console.
Two suggestions are:
1. Disconnect from internet and hard reset your router before doing this.
2. Make sure the script "rf" is using unix style line terminator ("0Ah" only) at the end of each line. (notice that windows programs using "0Ah 0Dh" as line break)
reply
Phoenix2088 @ 14th Sep 07:42PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
Thanks. I redid the script using Unix syntax and that sort of worked. I saw TFTP32 transfer the file over to the router successfully.
However the power light did not blink on the WRTP54G and even after a power cycle and hard reset the device is still running 5.01.04. It feels like I am very close, any help would be greatly appreciated.
reply
anon @ 15th Sep 03:56AM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
I guess that you missed an 0AH at the end of the rf file...
reply
Phoenix2088 @ 15th Sep 05:58PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
Even wrote the script in Ubuntu, same problem. Not sure what I am doing wrong.
reply
jetzhu @ 16th Sep 09:33PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
which firmware are you using for your WRTP54? »httpconfig.vonage.net/wrt-11.1.0···327.img?
Notice that the RTP300 is using different file
»httpconfig.vonage.net/rt-11.1.0-···0327.img
reply
Phoenix2088 @ 16th Sep 11:30PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
That was it! Thanks so much for the help. This doorstop is now useful. :D
I'm going to post a tutorial with all the steps to help make it easier for n00bs like me. Once again, thanks to everyone for the help.
Here it is: »[Unlock] TUTORIAL: VONAGE WRTP54G/RTP300 WITH 5.01.04
reply
ogdensburg @ 16th Sep 11:58PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
Tried to upgrade the firmware. For some reason,the upgrade failed and now my WRTP54G power light keeps blinking. Anyway to recover it?
reply
Phoenix2088 @ 17th Sep 01:11AM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
It blinks for about 2-3 minutes. If the power continues to blink, try doing a hard reset (paper clip for 10-15 seconds).
reply
ogdensburg @ 18th Sep 06:14PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
No luck. Still blinking.
said by Phoenix2088 :
It blinks for about 2-3 minutes. If the power continues to blink, try doing a hard reset (paper clip for 10-15 seconds).
reply
mazilo @ 18th Sep 07:36PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
said by ogdensburg :
Tried to upgrade the firmware. For some reason,the upgrade failed and now my WRTP54G power light keeps blinking. Anyway to recover it?
Use a serial-console cable to flash the unit with a legitimate firmware to recover this. You did enable CONSOLE_UNLOCK option when the device was working, right? Otherwise, you will probably need to ask someone to dump the whole Flash using a JTAG cable, modify the S/N and MAC Addresses, then upload to your WRTP54G using aJTAG cable. This may take more than 40 hours using an unbuffered JTAG cable.
--
Mazilo always prays for FREEBIES!
US Phone: +1-678-601-0907
UK Phone: +44-703-194-2574
reply
GrauerFuchs @ 19th Sep 03:09PM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
said by mazilo :
Otherwise, you will probably need to ask someone to dump the whole Flash using a JTAG cable, modify the S/N and MAC Addresses, then upload to your WRTP54G using aJTAG cable. This may take more than 40 hours using an unbuffered JTAG cable.
If the light is flashing, then the bootloader is still valid. If I do recall, if pspboot fails to boot, it will drop to a prompt regardless of the CONSOLE_STATE setting. If not, a simple JTAG wipe of the environment variable section (addr 0xb0010000 length 0x10000) will release the console on most devices. If, in the process, the desire is to make it entirely NA, simply use JTAG to flash the modded 64k pspboot bootloader in, wipe the above-mentioned environment space, and forget about the firmware images. The bootloader alone will take about 25 minutes if all goes well. Once the new pspboot is in place, it can accept and quickly flash the Linksys-provided NA firmware in less than 5 minutes. Then, there's no question about it reverting to a locked state, either.
reply
shycharles @ 18th Oct 03:49AM:
Re: [Unlock] WRTP54G with Firmware 5.01.04
I am a newbie in the Voip Unlocking world. You are telling the entire process, step by step marvelously. One thing you miss though is whether the device from Vonage (in my case RTP300) will be opened and we will be able to see the entire page with User id & Password, domain and port OR does this process wash every setting that was made by the provider and once we do it, we will just be able to use this device with other providers and not (or maybe) with Vonage? I understand your concern about legalities, which do not bother me as such. All I want to do it to be able to see the following:
User ID (generally 1+my Vonage phone number)
Password
Domain
Port (generally 5060 or 5061)
My Firmware version is 5.01.04 or maybe 5.01.14, basically it is the latest firmware.
reply
Thank you for using lo-fi dslreports.com - report bugs
© 99-2009 silver matrix LLC