Lorem ipsum dolor sit amet

Motorola WiMAX CPE Modem Hacks

admin


Testing speed of cloned Motorola CPEi 35775.................

Cloning Motorola CPEi35775:
BootLoader 0x90000000,0x90020000
Bootloader Config 0x90020000,0x90040000
Device Certificates 0x90CA0000,0x90CC0000

Copy these partitions from a motorola cpe to another cpe..

To change Wimax MAC just edit the HWA_0 to your desired MAC in bootloader / bootloader config

Note: Wimax mac from Bootloader / Bootloader Config must match Device certificate in-order to get connected to the network.

To Do: Bypass Certificate verification....

PSPboot Log (with console_state unlocked):

B2 Bootloader 01.01.08

Basic POST completed... Success.
Last reset cause: Hardware reset (Power-on reset)

PSPBoot1.5 rev: 1.5.0.6
(c) Copyright 2002-2006 Texas Instruments, Inc. All Rights Reserved.

BLADE2 3.5G
Press ESC for monitor... 3
(psbl) help
reboot version info fa
printenv setenv setpermenv unsetenv
defragenv fmt boot dm
oclk help tftp testram
testflash flash testled
(psbl) printenv

TOOLS_USER 0
BOOTLOADER 0x90000000,0x90020000
IMAGE_A 0x90040000,0x90C40000
CONFIG_A 0x90C40000,0x90C60000
CONFIG_B 0x90C60000,0x90C80000
IMAGE_B 0x90CE0000,0x918E0000
FNE_CERTS 0x90C80000,0x90CA0000
DEV_CERTS 0x90CA0000,0x90CC0000
FACTORY_DEF 0x90CC0000,0x90CE0000
JFFS2 0x918E0000,0x92000000
RESET_CAUSE 0
PartNumber SGDNXXXXBA
ProductID CPEi35775
HWRevision REV.D
SerialNumber TS19XXXXXX
HWA_1 00:23:XX:XX:XX:3D
GATEWAY_MAC_ADDRESS 00:23:XX:XX:XX:3E
WIFI_MAC_ADDRESS 00:23:XX:XX:XX:3F
FingerPrint ~removed~
HWA_0 00:24:XX:XX:XX:75
FactoryProvision Complete
CONSOLE_STATE unlocked
BOOTCFG m:f:"IMAGE_B"
BUILD_OPS 0xd41
MEMSZ 0x04000000
FLASHSZ 0x02000000
MODETTY0 115200,n,8,1,hw
MODETTY1 115200,n,8,1,hw
CPUFREQ 212992000
MIPSFREQ 212992000
SYSFREQ 150000000
bootloaderVersion 01.01.08
PROMPT (psbl)

P.S. MAC address & serial hidden..

1 comments:

Post a Comment