Dumping Kaon Boxes

Thank you for your cooperation.

I understood the processor, what is the RAM?

And what software can I use?

I want to use the receiver for free channels with non-operator software
The receiver is from operator Mtel Bulgaria
 
with these providers Mtel Bulgaria, VIP Croatia you can forget about using the card in your own receiver !
game over
gotovo je.. igra na kraju
играта приключи
 
with these providers Mtel Bulgaria, VIP Croatia you can forget about using the card in your own receiver !
game over
gotovo je.. igra na kraju
играта приключи
I want to use the receiver only for free channels of another satellite, without a card, but I don't like the operator software, I want to replace it with something else if possible, and from which receiver model can I use it firmware?
 
Last edited:
not possible ! as i writed before.. fw is crypted via cpu.. maybe if you replaced bcm7358 cpu for the same cpu bought on aliexpress and you pay someone to create an enigma2 for this box, you will have a very expensive FTA receiver :D
 
not possible ! as i writed before.. fw is crypted via cpu.. maybe if you replaced bcm7358 cpu for the same cpu bought on aliexpress and you pay someone to create an enigma2 for this box, you will have a very expensive FTA receiver :D
If it is impossible, I will continue to watch the free channels with the operating software, they work without paying.
I don't like it because some channels of another satellite are not getting them, and I found out that it is from the receiver, I think that either the Tuner or the Software is the reason.
 
Hello ,
I have a Kaon CO 13000HD receiver v.3.3 - left by the operator.
Does anyone know what processor, data ram it supports, so I can find the software on which brand model it can be flashed

thanks


and did you check uart there? kaon co 1300 with bcm 7358 had open uart in older fw smp-1.1, there was possible to play with aes decryption of more parts from dump



dmesg.log lastlog sysinit.log
# cat dmesg.log
[ 0.000000] Linux version 2.6.37-3.3 (drzony@devel2) (gcc version 4.5.3 (Broadcom stbgcc-4.5.3-2.3) ) #1 Fri Aug 1 15:32:43 CEST 2014
[ 0.000000] Fetching vars from bootloader... found 6 vars.
[ 0.000000] Options: enet_en=1 enet0_mii=0 enet_no_mdio=0 enet1_en=0 moca=0
[ 0.000000] sata=0 docsis=0 pci=0 pcie=0 smp=0 usb=1
[ 0.000000] Using 512 MB + 0 MB RAM (from CFE)
[ 0.000000] MEMC0 split: 256 MB -> Linux; 256 MB -> extra bmem
[ 0.000000] CPU revision is: 00029032 (Broadcom BMIPS3300)
[ 0.000000] Determined physical RAM map:
[ 0.000000] memory: 10000000 @ 00000000 (usable)
[ 0.000000] bmem: setting up predefined bmem regions for 512 MB of RAM.
[ 0.000000] bmem: set up 2 predefined bmem regions:
[ 0.000000] bmem: 64 MB region at 192 MB (0x04000000@0x0c000000)
[ 0.000000] bmem: 256 MB region at 512 MB (0x10000000@0x20000000)
[ 0.000000] bmem: adding 188 MB LINUX region at 3 MB (0x0bc2f000@0x003d1000)
[ 0.000000] bmem: adding 64 MB RESERVED region at 192 MB (0x04000000@0x0c000000)
[ 0.000000] Initrd not found or empty - disabling initrd
[ 0.000000] Zone PFN ranges:
[ 0.000000] Normal 0x00000000 -> 0x00010000
[ 0.000000] Movable zone start PFN for each node
[ 0.000000] early_node_map[1] active PFN ranges
[ 0.000000] 0: 0x00000000 -> 0x00010000
[ 0.000000] On node 0 totalpages: 65536
[ 0.000000] free_area_init_node: node 0, pgdat 80359a00, node_mem_map 81000000
[ 0.000000] Normal zone: 512 pages used for memmap
[ 0.000000] Normal zone: 0 pages reserved
[ 0.000000] Normal zone: 65024 pages, LIFO batch:15
[ 0.000000] pcpu-alloc: s0 r0 d32768 u32768 alloc=1*32768
[ 0.000000] pcpu-alloc: [0] 0
[ 0.000000] Built 1 zonelists in Zone order, mobility grouping on. Total pages: 65024
[ 0.000000] Kernel command line: sign0=39108887E897B07FDE0EE9A79B8030084CE02C0AD60B9750356AFF361657554FAE2ED1AE93B9D405B1CC2607A7250BE2B1FAF291C8D6E7E4BFBFC197D1D691F9B82CA67D0579B5B928069B74FFF206EA577932A704002B3530F4AF2A1C61A7C1931ABA0BA72CBE27EDA592D04493E4914E1AE7A21E2CFDE43BDD2CC902E4B3546C1E7B9AC291FC6951D09069DA1CDA113D8983B819664848AE9FDD732345B5360803A24301519A5A152DFEC87827469057F3073BB840BE2735E59470C7C1741F13B5C7C13AF59D96F3D97BCB9BECA3DF01538F8031CF779B22D467C432B41D486B7605203BF3FD544D23A21CE1496867D9D6304F0B20F6F13A85485F5C438AEB sign1=46F5DD7B3FABA2B345D377BE3C036B85BA511111BAAF9474C3EF9FE170D87126609A1F6DF599A920DCB0436056913E3B18CCBCD958AA55A7B54D0D0F7463F1752B6F4FE6A2A1C303C965568A04B64F93370F2EAC80816DADA0388311FE3964A8ACC02981D8C3174C976C87E425F669C90D06DF6153BF7C3E562E9DF08A92D03649B9713E00E4C40F67884D5B4273972CC5D0E3C22F7D403E34277AA6DDAE0B8730A482022EE298717029938A1125C275A872F3E81A58AD5F9B53FE1F6D742ADB4ED2874DF9F65D294E98523A5929558FD568EA93619C11D111EC5AB3496E857F7BD3637CA182A489F50B34DFB7
[ 0.000000] PID hash table entries: 1024 (order: 0, 4096 bytes)
[ 0.000000] Dentry cache hash table entries: 32768 (order: 5, 131072 bytes)
[ 0.000000] Inode-cache hash table entries: 16384 (order: 4, 65536 bytes)
[ 0.000000] Primary instruction cache 32kB, VIPT, 4-way, linesize 16 bytes.
[ 0.000000] Primary data cache 32kB, 2-way, VIPT, cache aliases, linesize 16 bytes
[ 0.000000] Memory: 190404k/262144k available (2953k kernel code, 71740k reserved, 474k data, 372k init, 0k highmem)
[ 0.000000] NR_IRQS:160
[ 0.000000] Measuring MIPS counter frequency...
[ 0.000000] Detected MIPS clock frequency: 751 MHz (375.759 MHz counter)
[ 0.000000] Calibrating delay loop... 749.56 BogoMIPS (lpj=374784)
[ 0.020000] pid_max: default: 32768 minimum: 301
[ 0.020000] Mount-cache hash table entries: 512
[ 0.023000] bmem: adding extra 256 MB RESERVED region at 512 MB (0x10000000@0x20000000)
[ 0.023000] NET: Registered protocol family 16
[ 0.024000] USB0: IOC was not set by the bootloader; forcing default settings
[ 0.024000] USB0: power enable is active low; overcurrent is active low
[ 0.027000] bio: create slab <bio-0> at 0
[ 0.028000] Switching to clocksource wktmr
[ 0.029000] NET: Registered protocol family 2
[ 0.030000] IP route cache hash table entries: 2048 (order: 1, 8192 bytes)
[ 0.030000] TCP established hash table entries: 8192 (order: 4, 65536 bytes)
[ 0.030000] TCP bind hash table entries: 8192 (order: 3, 32768 bytes)
[ 0.031000] TCP: Hash tables configured (established 8192 bind 8192)
[ 0.031000] TCP reno registered
[ 0.031000] UDP hash table entries: 256 (order: 0, 4096 bytes)
[ 0.031000] UDP-Lite hash table entries: 256 (order: 0, 4096 bytes)
[ 0.031000] NET: Registered protocol family 1
[ 0.032000] RPC: Registered udp transport module.
[ 0.032000] RPC: Registered tcp transport module.
[ 0.032000] RPC: Registered tcp NFSv4.1 backchannel transport module.
[ 0.058000] Registered led device: brcmled:0:red
[ 0.058000] Registered led device: brcmled:1:green
[ 0.058000] Registered led device: brcmled:2:red
[ 0.059000] Setting up LEDs for 7358 TAG
[ 0.059000] LED red1 disabled
[ 0.059000] CPU status register: timer=0, gpio=0, ir=0
[ 0.059000] Splash params: 720x576 pitch 1440
[ 0.059000] Initializing FrontPanel driver - 7358 TAG mode
[ 0.059000] input: kaon_gpio_fp as /devices/virtual/input/input0
[ 0.059000] kaon_fp: frontpanel input enabled
[ 0.059000] fpdev_init Aug 1 2014 15:32:33
[ 0.061000] squashfs: version 4.0 (2009/01/31) Phillip Lougher
[ 0.062000] msgmni has been set to 371
[ 0.063000] io scheduler noop registered
[ 0.063000] io scheduler cfq registered (default)
[ 0.064000] Serial: 8250/16550 driver, 4 ports, IRQ sharing disabled
[ 0.065000] serial8250.0: ttyS0 at MMIO 0x10406800 (irq = 62) is a 16550A
[ 0.518000] console [ttyS0] enabled
[ 0.522000] serial8250.0: ttyS1 at MMIO 0x10406840 (irq = 63) is a 16550A
[ 0.529000] serial8250.0: ttyS2 at MMIO 0x10406880 (irq = 64) is a 16550A
[ 0.540000] loop: module loaded
[ 0.544000] brcmstb_nand: NAND controller driver is loaded
[ 0.550000] __clk_enable: network [1]
[ 0.550000] __clk_enable: enet [1]
[ 0.550000] bcm7552_pm_genet_enable 00
[ 0.593000] Config internal EPHY through MDIO
[ 0.617000] __clk_disable: enet [0]
[ 0.617000] bcm7552_pm_genet_disable 00
[ 0.617000] __clk_disable: network [0]
[ 0.618000] device-mapper: ioctl: 4.18.0-ioctl (2010-06-29) initialised: [email protected]
[ 0.627000] TCP cubic registered
[ 0.630000] NET: Registered protocol family 17
[ 0.635000] warning: unable to build a flash partition map, using entire device
[ 0.643000] EBI CS1: setting up NAND flash (primary)
[ 0.648000] ONFI flash detected
[ 0.651000] ONFI param page 0 valid
[ 0.655000] NAND device: Manufacturer ID: 0x2c, Chip ID: 0xf1 (Micron MT29F1G08ABAEAH4)
[ 0.663000] ONFI flash detected
[ 0.667000] ONFI param page 0 valid
[ 0.670000] NAND device: Manufacturer ID: 0x2c, Chip ID: 0xf1 (Micron MT29F1G08ABAEAH4)
[ 0.678000] brcmnand brcmnand.0: 128MiB total, 128KiB blocks, 2KiB pages, 16B OOB, 8-bit, BCH-4
[ 0.678000]
[ 0.689000] Bad block table found at page 65472, version 0x01
[ 0.695000] Bad block table found at page 65408, version 0x01
[ 0.702000] cmdlinepart partition parsing not available
[ 0.708000] RedBoot partition parsing not available
[ 0.713000] Creating 5 MTD partitions on "brcmnand.0":
[ 0.718000] 0x000000000000-0x000002500000 : "rootfs0"
[ 0.725000] 0x000002500000-0x000004a00000 : "rootfs1"
[ 0.732000] 0x000004a00000-0x000004f00000 : "vmlinuz0"
[ 0.738000] 0x000004f00000-0x000005400000 : "vmlinuz1"
[ 0.745000] 0x000005400000-0x000008000000 : "config"
[ 0.751000] EBI CS0: setting up SPI flash
[ 0.756000] spi_brcmstb spi_brcmstb.0: 1-lane output, 3-byte address
[ 0.763000] m25p80 spi0.0: found mx25l3255d, expected m25p80
[ 0.769000] m25p80 spi0.0: mx25l3255d (4096 Kbytes)
[ 0.774000] Creating 10 MTD partitions on "spi0.0":
[ 0.779000] 0x000000000000-0x000000080000 : "cfe"
[ 0.785000] 0x000000080000-0x000000090000 : "macadr"
[ 0.791000] 0x000000090000-0x0000000a0000 : "hdcp"
[ 0.798000] 0x0000000a0000-0x0000000b0000 : "cert"
[ 0.804000] 0x0000000b0000-0x0000000c0000 : "cert_sign"
[ 0.811000] 0x0000000c0000-0x0000000d0000 : "nvram"
[ 0.817000] 0x0000000d0000-0x0000000e0000 : "nvramB"
[ 0.824000] 0x0000000e0000-0x000000260000 : "logo"
[ 0.831000] 0x000000260000-0x000000280000 : "conax_store"
[ 0.838000] 0x000000280000-0x000000400000 : "reserved"
[ 0.845000] PM: CP0 COUNT/COMPARE frequency depends on divisor
[ 0.856000] Freeing unused kernel memory: 372k freed
[ 0.863000] Algorithmics/MIPS FPU Emulator v1.5
[ 0.875000] UBI: attaching mtd1 to ubi1
[ 0.880000] UBI: physical eraseblock size: 131072 bytes (128 KiB)
[ 0.887000] UBI: logical eraseblock size: 126976 bytes
[ 0.892000] UBI: smallest flash I/O unit: 2048
[ 0.897000] UBI: VID header offset: 2048 (aligned 2048)
[ 0.903000] UBI: data offset: 4096
[ 1.130000] UBI: max. sequence number: 168
[ 1.146000] UBI: attached mtd1 to ubi1
[ 1.150000] UBI: MTD device name: "rootfs0"
[ 1.155000] UBI: MTD device size: 37 MiB
[ 1.160000] UBI: number of good PEBs: 296
[ 1.165000] UBI: number of bad PEBs: 0
[ 1.169000] UBI: number of corrupted PEBs: 0
[ 1.174000] UBI: max. allowed volumes: 128
[ 1.178000] UBI: wear-leveling threshold: 4096
[ 1.183000] UBI: number of internal volumes: 1
[ 1.188000] UBI: number of user volumes: 1
[ 1.192000] UBI: available PEBs: 128
[ 1.197000] UBI: total number of reserved PEBs: 168
[ 1.202000] UBI: number of PEBs reserved for bad PEB handling: 2
[ 1.208000] UBI: max/mean erase counter: 2/0
[ 1.212000] UBI: image sequence number: 898814881
[ 1.218000] UBI: background thread "ubi_bgt1d" started, PID 42
 
and did you check uart there? kaon co 1300 with bcm 7358 had open uart in older fw smp-1.1, there was possible to play with aes decryption of more parts from dump



dmesg.log lastlog sysinit.log
# cat dmesg.log
[ 0.000000] Linux version 2.6.37-3.3 (drzony@devel2) (gcc version 4.5.3 (Broadcom stbgcc-4.5.3-2.3) ) #1 Fri Aug 1 15:32:43 CEST 2014
[ 0.000000] Fetching vars from bootloader... found 6 vars.
[ 0.000000] Options: enet_en=1 enet0_mii=0 enet_no_mdio=0 enet1_en=0 moca=0
[ 0.000000] sata=0 docsis=0 pci=0 pcie=0 smp=0 usb=1
[ 0.000000] Using 512 MB + 0 MB RAM (from CFE)
[ 0.000000] MEMC0 split: 256 MB -> Linux; 256 MB -> extra bmem
[ 0.000000] CPU revision is: 00029032 (Broadcom BMIPS3300)
[ 0.000000] Determined physical RAM map:
[ 0.000000] memory: 10000000 @ 00000000 (usable)
[ 0.000000] bmem: setting up predefined bmem regions for 512 MB of RAM.
[ 0.000000] bmem: set up 2 predefined bmem regions:
[ 0.000000] bmem: 64 MB region at 192 MB (0x04000000@0x0c000000)
[ 0.000000] bmem: 256 MB region at 512 MB (0x10000000@0x20000000)
[ 0.000000] bmem: adding 188 MB LINUX region at 3 MB (0x0bc2f000@0x003d1000)
[ 0.000000] bmem: adding 64 MB RESERVED region at 192 MB (0x04000000@0x0c000000)
[ 0.000000] Initrd not found or empty - disabling initrd
[ 0.000000] Zone PFN ranges:
[ 0.000000] Normal 0x00000000 -> 0x00010000
[ 0.000000] Movable zone start PFN for each node
[ 0.000000] early_node_map[1] active PFN ranges
[ 0.000000] 0: 0x00000000 -> 0x00010000
[ 0.000000] On node 0 totalpages: 65536
[ 0.000000] free_area_init_node: node 0, pgdat 80359a00, node_mem_map 81000000
[ 0.000000] Normal zone: 512 pages used for memmap
[ 0.000000] Normal zone: 0 pages reserved
[ 0.000000] Normal zone: 65024 pages, LIFO batch:15
[ 0.000000] pcpu-alloc: s0 r0 d32768 u32768 alloc=1*32768
[ 0.000000] pcpu-alloc: [0] 0
[ 0.000000] Built 1 zonelists in Zone order, mobility grouping on. Total pages: 65024
[ 0.000000] Kernel command line: sign0=39108887E897B07FDE0EE9A79B8030084CE02C0AD60B9750356AFF361657554FAE2ED1AE93B9D405B1CC2607A7250BE2B1FAF291C8D6E7E4BFBFC197D1D691F9B82CA67D0579B5B928069B74FFF206EA577932A704002B3530F4AF2A1C61A7C1931ABA0BA72CBE27EDA592D04493E4914E1AE7A21E2CFDE43BDD2CC902E4B3546C1E7B9AC291FC6951D09069DA1CDA113D8983B819664848AE9FDD732345B5360803A24301519A5A152DFEC87827469057F3073BB840BE2735E59470C7C1741F13B5C7C13AF59D96F3D97BCB9BECA3DF01538F8031CF779B22D467C432B41D486B7605203BF3FD544D23A21CE1496867D9D6304F0B20F6F13A85485F5C438AEB sign1=46F5DD7B3FABA2B345D377BE3C036B85BA511111BAAF9474C3EF9FE170D87126609A1F6DF599A920DCB0436056913E3B18CCBCD958AA55A7B54D0D0F7463F1752B6F4FE6A2A1C303C965568A04B64F93370F2EAC80816DADA0388311FE3964A8ACC02981D8C3174C976C87E425F669C90D06DF6153BF7C3E562E9DF08A92D03649B9713E00E4C40F67884D5B4273972CC5D0E3C22F7D403E34277AA6DDAE0B8730A482022EE298717029938A1125C275A872F3E81A58AD5F9B53FE1F6D742ADB4ED2874DF9F65D294E98523A5929558FD568EA93619C11D111EC5AB3496E857F7BD3637CA182A489F50B34DFB7
[ 0.000000] PID hash table entries: 1024 (order: 0, 4096 bytes)
[ 0.000000] Dentry cache hash table entries: 32768 (order: 5, 131072 bytes)
[ 0.000000] Inode-cache hash table entries: 16384 (order: 4, 65536 bytes)
[ 0.000000] Primary instruction cache 32kB, VIPT, 4-way, linesize 16 bytes.
[ 0.000000] Primary data cache 32kB, 2-way, VIPT, cache aliases, linesize 16 bytes
[ 0.000000] Memory: 190404k/262144k available (2953k kernel code, 71740k reserved, 474k data, 372k init, 0k highmem)
[ 0.000000] NR_IRQS:160
[ 0.000000] Measuring MIPS counter frequency...
[ 0.000000] Detected MIPS clock frequency: 751 MHz (375.759 MHz counter)
[ 0.000000] Calibrating delay loop... 749.56 BogoMIPS (lpj=374784)
[ 0.020000] pid_max: default: 32768 minimum: 301
[ 0.020000] Mount-cache hash table entries: 512
[ 0.023000] bmem: adding extra 256 MB RESERVED region at 512 MB (0x10000000@0x20000000)
[ 0.023000] NET: Registered protocol family 16
[ 0.024000] USB0: IOC was not set by the bootloader; forcing default settings
[ 0.024000] USB0: power enable is active low; overcurrent is active low
[ 0.027000] bio: create slab <bio-0> at 0
[ 0.028000] Switching to clocksource wktmr
[ 0.029000] NET: Registered protocol family 2
[ 0.030000] IP route cache hash table entries: 2048 (order: 1, 8192 bytes)
[ 0.030000] TCP established hash table entries: 8192 (order: 4, 65536 bytes)
[ 0.030000] TCP bind hash table entries: 8192 (order: 3, 32768 bytes)
[ 0.031000] TCP: Hash tables configured (established 8192 bind 8192)
[ 0.031000] TCP reno registered
[ 0.031000] UDP hash table entries: 256 (order: 0, 4096 bytes)
[ 0.031000] UDP-Lite hash table entries: 256 (order: 0, 4096 bytes)
[ 0.031000] NET: Registered protocol family 1
[ 0.032000] RPC: Registered udp transport module.
[ 0.032000] RPC: Registered tcp transport module.
[ 0.032000] RPC: Registered tcp NFSv4.1 backchannel transport module.
[ 0.058000] Registered led device: brcmled:0:red
[ 0.058000] Registered led device: brcmled:1:green
[ 0.058000] Registered led device: brcmled:2:red
[ 0.059000] Setting up LEDs for 7358 TAG
[ 0.059000] LED red1 disabled
[ 0.059000] CPU status register: timer=0, gpio=0, ir=0
[ 0.059000] Splash params: 720x576 pitch 1440
[ 0.059000] Initializing FrontPanel driver - 7358 TAG mode
[ 0.059000] input: kaon_gpio_fp as /devices/virtual/input/input0
[ 0.059000] kaon_fp: frontpanel input enabled
[ 0.059000] fpdev_init Aug 1 2014 15:32:33
[ 0.061000] squashfs: version 4.0 (2009/01/31) Phillip Lougher
[ 0.062000] msgmni has been set to 371
[ 0.063000] io scheduler noop registered
[ 0.063000] io scheduler cfq registered (default)
[ 0.064000] Serial: 8250/16550 driver, 4 ports, IRQ sharing disabled
[ 0.065000] serial8250.0: ttyS0 at MMIO 0x10406800 (irq = 62) is a 16550A
[ 0.518000] console [ttyS0] enabled
[ 0.522000] serial8250.0: ttyS1 at MMIO 0x10406840 (irq = 63) is a 16550A
[ 0.529000] serial8250.0: ttyS2 at MMIO 0x10406880 (irq = 64) is a 16550A
[ 0.540000] loop: module loaded
[ 0.544000] brcmstb_nand: NAND controller driver is loaded
[ 0.550000] __clk_enable: network [1]
[ 0.550000] __clk_enable: enet [1]
[ 0.550000] bcm7552_pm_genet_enable 00
[ 0.593000] Config internal EPHY through MDIO
[ 0.617000] __clk_disable: enet [0]
[ 0.617000] bcm7552_pm_genet_disable 00
[ 0.617000] __clk_disable: network [0]
[ 0.618000] device-mapper: ioctl: 4.18.0-ioctl (2010-06-29) initialised: [email protected]
[ 0.627000] TCP cubic registered
[ 0.630000] NET: Registered protocol family 17
[ 0.635000] warning: unable to build a flash partition map, using entire device
[ 0.643000] EBI CS1: setting up NAND flash (primary)
[ 0.648000] ONFI flash detected
[ 0.651000] ONFI param page 0 valid
[ 0.655000] NAND device: Manufacturer ID: 0x2c, Chip ID: 0xf1 (Micron MT29F1G08ABAEAH4)
[ 0.663000] ONFI flash detected
[ 0.667000] ONFI param page 0 valid
[ 0.670000] NAND device: Manufacturer ID: 0x2c, Chip ID: 0xf1 (Micron MT29F1G08ABAEAH4)
[ 0.678000] brcmnand brcmnand.0: 128MiB total, 128KiB blocks, 2KiB pages, 16B OOB, 8-bit, BCH-4
[ 0.678000]
[ 0.689000] Bad block table found at page 65472, version 0x01
[ 0.695000] Bad block table found at page 65408, version 0x01
[ 0.702000] cmdlinepart partition parsing not available
[ 0.708000] RedBoot partition parsing not available
[ 0.713000] Creating 5 MTD partitions on "brcmnand.0":
[ 0.718000] 0x000000000000-0x000002500000 : "rootfs0"
[ 0.725000] 0x000002500000-0x000004a00000 : "rootfs1"
[ 0.732000] 0x000004a00000-0x000004f00000 : "vmlinuz0"
[ 0.738000] 0x000004f00000-0x000005400000 : "vmlinuz1"
[ 0.745000] 0x000005400000-0x000008000000 : "config"
[ 0.751000] EBI CS0: setting up SPI flash
[ 0.756000] spi_brcmstb spi_brcmstb.0: 1-lane output, 3-byte address
[ 0.763000] m25p80 spi0.0: found mx25l3255d, expected m25p80
[ 0.769000] m25p80 spi0.0: mx25l3255d (4096 Kbytes)
[ 0.774000] Creating 10 MTD partitions on "spi0.0":
[ 0.779000] 0x000000000000-0x000000080000 : "cfe"
[ 0.785000] 0x000000080000-0x000000090000 : "macadr"
[ 0.791000] 0x000000090000-0x0000000a0000 : "hdcp"
[ 0.798000] 0x0000000a0000-0x0000000b0000 : "cert"
[ 0.804000] 0x0000000b0000-0x0000000c0000 : "cert_sign"
[ 0.811000] 0x0000000c0000-0x0000000d0000 : "nvram"
[ 0.817000] 0x0000000d0000-0x0000000e0000 : "nvramB"
[ 0.824000] 0x0000000e0000-0x000000260000 : "logo"
[ 0.831000] 0x000000260000-0x000000280000 : "conax_store"
[ 0.838000] 0x000000280000-0x000000400000 : "reserved"
[ 0.845000] PM: CP0 COUNT/COMPARE frequency depends on divisor
[ 0.856000] Freeing unused kernel memory: 372k freed
[ 0.863000] Algorithmics/MIPS FPU Emulator v1.5
[ 0.875000] UBI: attaching mtd1 to ubi1
[ 0.880000] UBI: physical eraseblock size: 131072 bytes (128 KiB)
[ 0.887000] UBI: logical eraseblock size: 126976 bytes
[ 0.892000] UBI: smallest flash I/O unit: 2048
[ 0.897000] UBI: VID header offset: 2048 (aligned 2048)
[ 0.903000] UBI: data offset: 4096
[ 1.130000] UBI: max. sequence number: 168
[ 1.146000] UBI: attached mtd1 to ubi1
[ 1.150000] UBI: MTD device name: "rootfs0"
[ 1.155000] UBI: MTD device size: 37 MiB
[ 1.160000] UBI: number of good PEBs: 296
[ 1.165000] UBI: number of bad PEBs: 0
[ 1.169000] UBI: number of corrupted PEBs: 0
[ 1.174000] UBI: max. allowed volumes: 128
[ 1.178000] UBI: wear-leveling threshold: 4096
[ 1.183000] UBI: number of internal volumes: 1
[ 1.188000] UBI: number of user volumes: 1
[ 1.192000] UBI: available PEBs: 128
[ 1.197000] UBI: total number of reserved PEBs: 168
[ 1.202000] UBI: number of PEBs reserved for bad PEB handling: 2
[ 1.208000] UBI: max/mean erase counter: 2/0
[ 1.212000] UBI: image sequence number: 898814881
[ 1.218000] UBI: background thread "ubi_bgt1d" started, PID 42
that was on old kernel versions new one not the same:

Bash:
You don't have permission to view the code content. Log in or register now.
 

@pachecoso

yes I know, all newer fw (smp-1.2 and higher) have uart closed, but some parts from them are decryptable with global aes swpk. example 0x000005400000-0x000008000000 : "config" part from nand
 

@pachecoso

yes I know, all newer fw (smp-1.2 and higher) have uart closed, but some parts from them are decryptable with global aes swpk. example 0x000005400000-0x000008000000 : "config" part from nand
yes but you can still have uart , put the kaon in download mode and initab will reopen uart

Code:
You don't have permission to view the code content. Log in or register now.
 
@ohmza

example of inittab in mentioned box with root access

# id:3:initdefault:
::sysinit:/etc/rcS
::ctrlaltdel:/sbin/reboot -f
::respawn:/etc/gui_start
::respawn:/sbin/getty -n -i -l /bin/sh 115200 ttyS0 vt100
::shutdown:/sbin/reboot -f
::restart:/sbin/reboot -f

inittab from another box with root access closed

# /etc/inittab
#
# Copyright (C) 2001 Erik Andersen <[email protected]>
#
# Note: BusyBox init doesn't support runlevels. The runlevels field is
# completely ignored by BusyBox init. If you want runlevels, use
# sysvinit.
#
# Format for each entry: <id>:<runlevels>:<action>:<process>
#
# id == tty to run on, or empty for /dev/console
# runlevels == ignored
# action == one of sysinit, respawn, askfirst, wait, and once
# process == program to run

# main rc script
::sysinit:/etc/init.d/rcS

# Put a shell on the serial port
# ttyS0::respawn:/sbin/getty -L 115200 ttyS0 vt102
::respawn:/bin/cttyhack /bin/sh -l

# Stuff to do before rebooting
null::shutdown:/bin/umount -a -r
 
@ohmza

ok, if you will have uart or telnet root access, you can check all active uarts

example from my box with bcm 7358

default set, where uart 0 and uart 2 are closed, uart 1 is open

cat /proc/tty/driver/serial
serinfo:1.0 driver revision:
0: uart:16550A mmio:0x10406800 irq:62 tx:0 rx:0
1: uart:16550A mmio:0x10406840 irq:63 tx:700 rx:0 RTS|CTS|DTR
2: uart:16550A mmio:0x10406880 irq:64 tx:0 rx:0 CTS
3: uart:unknown port:00000000 irq:0

same box with all 3 active uarts open after playing

cat /proc/tty/driver/serial
serinfo:1.0 driver revision:
0: uart:16550A mmio:0x10406800 irq:62 tx:34 rx:1 brk:1 RTS|DTR
1: uart:16550A mmio:0x10406840 irq:63 tx:856 rx:0 RTS|CTS|DTR
2: uart:16550A mmio:0x10406880 irq:64 tx:17 rx:1 brk:1 RTS|CTS|DTR
3: uart:unknown port:00000000 irq:0
 
Back
Top