republican-creole
site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Uniqs:
2283
Share Topic
Posting?
Post a:
Post a:
Links: ·Forum Rules ·Forum FAQ ·FTP Modes & Ports ·Linksys Home
AuthorAll Replies


renardhu

@pool.telekom.hu

[Firmware] BEFSR41 ver. 3

I got an old BEFSR41 v3 router. Its power LED is only blinking. I tried to connect to router on its LAN ports, but it is impossible, because its firmware is corrupt (I'm sure), so ping, tftp and http wont work. The only way to download the good firmware into the router is its JTAG connector. I have a good JTAG inteface (Wiggler on LPT), and I can connect to router with many applications (for example H-JTAG, JtagUtility v1.3 by ToM), and the applications can recognize the ARM CPU of the router (the core is ARM922T, the type is KENDIN KS8695), but I don't know the following required parameters to programming the flash memory with H-Flash:
- Flash Start Address (type: MX 29LV800BTC-90)
- RAM Start Address (type: V54C316162VCT)
- Initial scripts
Could anybody help me?
Thanks,
renard


61999674
Gotta Do What Ya Gotta Do
Premium
join:2000-09-02
Here
kudos:1

Have you tried this: »/forum/remark%···ode=flat
--
It is better to have it and not need it, than to need it and not have it.



renardhu

@pool.telekom.hu

reply to renardhu
Thanks, but that link cannot help me.
The firmware is corrupt, therefore at this moment the router cannot handle TCP/IP protocol. I have to use the JTAG connector.



61999674
Gotta Do What Ya Gotta Do
Premium
join:2000-09-02
Here
kudos:1

2 edits

That link is for a bad flash, there were a couple linksys firmware upgrades that were good for breaking.

That aside, you are going through an awful lot for a $40 item.
--
It is better to have it and not need it, than to need it and not have it.



renardhu

@pool.telekom.hu

I would like to know the solution, not the price
The price is known, but the solution...



61999674
Gotta Do What Ya Gotta Do
Premium
join:2000-09-02
Here
kudos:1

I gave you a solution, you want to do it the hard way.



renardhu

@pool.t-online.hu

Your solution works when the router can handle TCP/IP protocol, when the router has IP address. In my case the router has not IP address!!! In this case how could I use ping, tftp and/or http??? I tried that way (10M, half duplex, 192.168.1.2/24, ping 192.168.1.1 etc.) sometimes when I received the router many weeks later from one of my colleague.

I would not like to select the hard way, but I have to select that, because other solution isn't possible.

I hope that somebody knows this router better and can help me to find the right "debrick" procedure...

(This router is not so important thing, this is only a challenge", I don't want to repair that at any price, but I am interested in this kind of things.)



Bill_MI
Bill In Michigan
Premium,MVM
join:2001-01-03
Royal Oak, MI
kudos:1
Reviews:
·Comcast
·WOW Internet and..

1 edit

Just looking around a bit: »www.google.com/search?hl=en&as_q···e=images

Sniffing the LAN, don't be surprised if you get an ARP "courtesy notification" immediately after boot that it declares itself on 192.168.1.1 and for a short time accepts a tftp transfer of a standard *.bin image to burn FLASH. It was around the V3 time Linksys started that.

If you see that notification, the routine, network and all, is fixed address and in the boot code, not the firmware area of FLASH.

On a secondary note is a header for a serial port. That same boot code may talk to a dumb terminal.

Just a thought. They may not have done this at all on the BEFSR41 and I have no experience past the V1 which I never went that far with. Maybe one of the links above will get some info.



renardhu

@pool.t-online.hu

Thanks.
1. I know Google but I could not find anything useful information about my JTAG problem.
2. I tried to check the "ARP courtesy notification" of the router with Wireshark, but the router did not send anything. From another router I can received the expected message...
3. This kind of router has not serial port on the PCB (the serial pins of the CPU are not connected anywhere).



Bill_MI
Bill In Michigan
Premium,MVM
join:2001-01-03
Royal Oak, MI
kudos:1

1 edit

I'm not familiar enough with ARM/H-JTAG to know if you can create arbitrary reads. If so, can you go looking for valid data? That should get the FLASH location. Floating busses usually give themselves away (which may give clues to the DRAM, too).


renardhu

join:2010-03-07
Hungary

Yes...
The KS8695 CPU (ARM922T core inside) has an MMU. The MMU translates virtual addresses into physical addresses. How does the CPU handle the memory in the BEFSR41 v3 router? I don't know. This is my problem...
The Google couldn't help me...


Friday, 01-Jun 16:08:29 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 12.5 years online © 1999-2012 dslreports.com.
Most commented news this week
Hot Topics