QUOTE(syahpian @ Sep 6 2024, 12:04 AM)
odd, the way VLAN is provision is not same as me even same OLT, hahaD-Link DPN-FX3060V GPON WiFi Router, (Nijika) Firmware Community Modding
D-Link DPN-FX3060V GPON WiFi Router, (Nijika) Firmware Community Modding
|
|
Sep 6 2024, 02:16 AM
Return to original view | IPv6 | Post
#21
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
2,399 posts Joined: Jul 2009 From: /dev/null |
QUOTE(syahpian @ Sep 6 2024, 12:04 AM) odd, the way VLAN is provision is not same as me even same OLT, haha syahpian liked this post
|
|
|
|
|
|
Sep 13 2024, 02:05 PM
Return to original view | IPv6 | Post
#22
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
2,399 posts Joined: Jul 2009 From: /dev/null |
|
|
|
Sep 13 2024, 07:30 PM
Return to original view | IPv6 | Post
#23
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
2,399 posts Joined: Jul 2009 From: /dev/null |
QUOTE(enduser @ Sep 13 2024, 06:59 PM) I try to compile required document, but... only I know, thing some one in Hack GPON group didn't disclose the exploit, so I can't report this as I don't know how to replicate their exploit enduser and countingcrows liked this post
|
|
|
Sep 20 2024, 02:40 PM
Return to original view | IPv6 | Post
#24
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
2,399 posts Joined: Jul 2009 From: /dev/null |
blstz like OKLY said, just use old ONT since you are on 1G plan, this much better then use D-Link on random issue later on cHiLdHo0drEaMz liked this post
|
|
|
Sep 20 2024, 08:57 PM
Return to original view | IPv6 | Post
#25
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
2,399 posts Joined: Jul 2009 From: /dev/null |
QUOTE(blstz @ Sep 20 2024, 06:53 PM) i see. you need ask to not bind the Serial Number,would you know if the suspected “unbinding” is done locally on the old ONU (remove settings) or is it done on TM “infrastructure” side. asking coz wanna know what to look out for. later technician setup new onr and in the process “unbinds” old onu 😅 anything i can do to make sure this doesn’t happen? however, you can copy D-Link SN to old ONU, like Huawei HG8240H (or H5) can set S/N, just use D-Link S/N cHiLdHo0drEaMz and blstz liked this post
|
|
|
Oct 16 2024, 07:47 PM
Return to original view | IPv6 | Post
#26
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
2,399 posts Joined: Jul 2009 From: /dev/null |
QUOTE(OKLY @ Oct 16 2024, 05:59 PM) Aware that TM is now providing a newer v2.0.3 firmware, irregardless whether they solved the speed drop issue when using bridge mode, are the CVEs patched? nope, one of my friend overseas still can enter even in v2.0.3, even they get WG working by back porting the kernel.D-Link now become VPN point for them xD |
|
|
|
|
|
Oct 16 2024, 08:30 PM
Return to original view | Post
#27
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
2,399 posts Joined: Jul 2009 From: /dev/null |
QUOTE(OKLY @ Oct 16 2024, 08:21 PM) that's a mystery,either they don't know, or already patch but still there, or they don't care since because sold to TM cheap cheap what I can told from my friend, they just say "not using known CVE", I guess they found a way to attack D-Link remotely even NATed via VLAN 209 to find another D-Link ONR. whatever it is, ISP equipment is never been secure TM not paid enough to maintain security since. many people already using own Router that managed by Asus, TP-LINK, Mikrotik, Ubiquiti, etc... that have active security patches. I know VLAN209 is for management, for good. but once got a weak point, it come a checkpoint to crawl deeper within ISP private network that is why old ONU Bridge since we been using are fine and never been use as Internet Routing. all of sudden Unifi also offer ONR solution, trade off security for cheaper internet OKLY liked this post
|
|
|
Oct 16 2024, 09:57 PM
Return to original view | Post
#28
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
2,399 posts Joined: Jul 2009 From: /dev/null |
|
|
|
Oct 16 2024, 11:35 PM
Return to original view | IPv6 | Post
#29
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
2,399 posts Joined: Jul 2009 From: /dev/null |
QUOTE(OKLY @ Oct 16 2024, 10:27 PM) apparently, just to be safestill, not to use ISP equipment if concern about security since DNS debacle, many overseas companies who use 2Gbps plan, use my PON Stick, they don't trust TM because anytime mcmc can force ISP to push stock DNS via OMCI or TR069 OKLY liked this post
|
|
|
Oct 27 2024, 03:29 AM
Return to original view | IPv6 | Post
#30
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
2,399 posts Joined: Jul 2009 From: /dev/null |
QUOTE(emilyngsc @ Oct 24 2024, 10:57 AM) I working on patching the firmware, just now I got a screenshot where D-Link DPN-FX3060V_2.0.3 successfully exploitedScreenshot, blur sensitive information ![]() ![]() It appear using msf6 (Metasploit Framework) apart from their RAT (Remote Access Tools), where msf code just striped down from RAT but it appear the D-Link can be pawned what more dangerous, can override Inactive Firmware partition as you see at last command, where: 1. Check current active partition, it appear partition 1 (secondary) is active as V2.0.3 installed. 2. Use 'NC' to accept connection and pipe hacked firmware to inactive partition 0 (primary) where V2.0.2 is reside 3. Attacker can force to boot hacked firmware and clone to another partition In order patching these exploit, I need their code, at least strip down msf code or remove all cloud stuff, disable TR142, TR069, and other stuff. even in Bridge mode, this exploit has multiple stages and can find more victim via VLAN209 and 400 the thing is, I didn't give V2.0.3 to them, somehow they manage to get it, what they told me, same exploit can be use this D-Link pawned has been sold in zero day market... because potential money generator, aka VPN Node, Botnet, etc... since who own D-Link is has high speed internet... ... I no idea then, only way to save D-Link is, by remove everything and dumb down as DUMB ONT Bridge! No Routing, No ISP Management, No WiFi what do you think? cHiLdHo0drEaMz, bizkutrai, and 3 others liked this post
|
|
|
Oct 27 2024, 05:23 AM
Return to original view | Post
#31
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
2,399 posts Joined: Jul 2009 From: /dev/null |
QUOTE(enduser @ Oct 27 2024, 03:52 AM) i think tm nut should take responsibility on this I don't think so, to make internet cheap, device security is second. (not paid enough to maintain security)How many gpon router now already been use ready to be exploited,. for example, cheap router like TOTO LINK, don't care vulnerability can't be sure how many, but plenty compromised device around the world with right fingerprint, can found on Shodan IoT search engine |
|
|
Nov 3 2024, 09:48 PM
Return to original view | IPv6 | Post
#32
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
2,399 posts Joined: Jul 2009 From: /dev/null |
QUOTE(shahzad86 @ Nov 3 2024, 03:02 PM) Hi All, i got upgraded from 800mbpsto 1GBps & was given black modem/router, which I honestly regretted this decision. The 5GHz performance and reliability has been worse than previous setup. I have to change to 2.4Ghz everytime upstairs to get Internet to work. I still have old modem & router, if I change back to old setup, is it plug & play or need much configuration? just plug old one, no config needed shahzad86 liked this post
|
|
|
Nov 16 2024, 06:51 PM
Return to original view | IPv6 | Post
#33
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
2,399 posts Joined: Jul 2009 From: /dev/null |
I put OpenSpeedTest inside D-Link DPN-FX3060V:
just dumb, the boa web server not that fast, not multi threading, and upload cannot work |
|
|
|
|
|
Nov 18 2024, 04:26 PM
Return to original view | IPv6 | Post
#34
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
2,399 posts Joined: Jul 2009 From: /dev/null |
with my spare time, I improved the stock firmware, as usual I port PON Stick to here, planning make bridge mode only ![]() I add "Nijika OS" to display hardware info, MIB and OMCI stuff still, I wont patch the vulnerability, so many binary related to each other cHiLdHo0drEaMz, emilyngsc, and 1 other liked this post
|
|
|
Nov 19 2024, 11:49 AM
Return to original view | IPv6 | Post
#35
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
2,399 posts Joined: Jul 2009 From: /dev/null |
After modding to make D-Link ONR become dumb (ONT Bridge), porting the PON Stick files into D-Link and recompile, now testing Dumb D-Link Wireless is disabled, No Router, No NAT, just bridge with ME 171 override ![]() Login Screen ![]() Nijika OS ![]() VLAN ![]() I not sure why Nokia OLT suddenly push VLAN 500 into VEIP? what's make it? previously don't have: ![]() Note: TM is clear on this, flashing modded firmware will invalidate the warranty, so, this firmware will push -NIJIKA prefixes into OMCI message. mamakap and cHiLdHo0drEaMz liked this post
|
|
|
Feb 5 2025, 06:54 PM
Return to original view | IPv6 | Post
#36
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
2,399 posts Joined: Jul 2009 From: /dev/null |
|
|
|
Feb 20 2025, 11:42 PM
Return to original view | IPv6 | Post
#37
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
2,399 posts Joined: Jul 2009 From: /dev/null |
Another Update,
It appear that Zyxel also make ONR, and use same SoC and board as D-Link DPN-FX3060V A1 hardware!!! ![]() ![]() UBoot Init D-Link A1: CODE NOTICE: Booting Trusted Firmware - Realtek Semiconductor Corp. NOTICE: BL1: v1.5(release):TAURUS_TAPEOUT_2_0 NOTICE: BL1: Built : 17:13:20, Oct 27 2021 NOTICE: BL1: CPU Speed 1000 MHz NOTICE: GLOBAL_STRAP 0xc0a NOTICE: boot from serial NAND flash NOTICE: SPI_NAND: MT29F2G01ABAGDWB/F50L2G41XA/XT26G02ELGIGA 0x2c24 NOTICE: SPI_NAND: Page 0x800, Block 0x20000, Chip 256MB NOTICE: SPI_NAND: plane_select=0x40, plane_select_bit=0x1000 NOTICE: Platform initialized NOTICE: ROTPK undeployed NOTICE: BL1: Booting BL2 NOTICE: BL2: RTL9607DQ CPU Speed 1000 MHz NOTICE: boot from serial NAND flash NOTICE: BL2: SPI_NAND: MT29F2G01ABAGDWB/F50L2G41XA/XT26G02ELGIG/WSFVC32GBID 0x2c24 NOTICE: BL2: SPI_NAND: Page 0x800, Block 0x20000, Chip 256MB NOTICE: BL2: SPI_NAND: plane_select=0x40, plane_select_bit=0x1000 ... U-Boot 2020.01-00005-g2117f28170 (Mar 08 2023 - 11:54:55 +0800)Taurus-SoC Zyxel: CODE NOTICE: Booting Trusted Firmware - Realtek Semiconductor Corp. NOTICE: BL1: v1.5(release):TAURUS_TAPEOUT_2_0 NOTICE: BL1: Built : 17:13:20, Oct 27 2021 NOTICE: BL1: CPU Speed 1000 MHz NOTICE: GLOBAL_STRAP 0xc0a NOTICE: boot from serial NAND flash NOTICE: SPI_NAND: W25N04KV 0xefaa23 NOTICE: SPI_NAND: Page 0x800, Block 0x20000, Chip 512MB NOTICE: Platform initialized NOTICE: BL1: Booting BL2 NOTICE: BL2: RTL9607DQ NOTICE: boot from serial NAND flash NOTICE: BL2: SPI_NAND: W25N04KVZEIE 0xefaa23 NOTICE: BL2: SPI_NAND: Page 0x800, Block 0x20000, Chip 512MB ... U-Boot 2020.01-svn22550 (Oct 07 2024 - 07:57:17 +0000)Taurus-SoC Booting Kernel D-Link A1: CODE Starting kernel ... [ 0.000000] Booting Linux on physical CPU 0x0000000000 [0x412fd050] [ 0.000000] Linux version 5.10.70 (wen_peng@ubuntu) (aarch64-linux-gcc (Realtek ASDK64-10.2.0 Build 3544) 10.2.0, GNU ld (Realtek ASDK64-10.2.0 Build 3544) 2.35.1.20201230) #1 SMP Wed Mar 8 11:56:34 CST 2023 Zyxel: CODE Starting kernel ... [ 0.000000] Booting Linux on physical CPU 0x0000000000 [0x412fd050] [ 0.000000] Linux version 5.10.138 (square@cdd59d47d0ed) (aarch64-openwrt-linux-gnu-gcc (OpenWrt GCC 11.2.0 r0+19487-2a59b851ac) 11.2.0, GNU ld (GNU Binutils) 2.37) #0 SMP Fri Dec 13 02:02:44 2024 Inside Zyxel ![]() WebGUI Zyxel ![]() --- Well, I waiting for him to dump NAND Flash, so we can build proper OpenWRT for D-Link A1 and Zyxel ONR. Since using OpenWRT, no more exploit |
|
|
Feb 21 2025, 12:47 PM
Return to original view | IPv6 | Post
#38
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
2,399 posts Joined: Jul 2009 From: /dev/null |
QUOTE(kwss @ Feb 21 2025, 09:48 AM) Anime4000 Zyxel and D-Link both use same SoC and same Taurus reference board, what I checked for now, only D-Link A1 hardware share quite a lot similarly.Did the Zyxel has the same GPON SoC as the D-Link? Is the Zyxel an off the shelf ONR or is it specifically customized for ISP? The problem with a lot of OpenWRT porting is the board cannot use vanilla kernel due to binary blob. The specific roadblock I can see in D-Link ONR is all the proprietary initialization sequence are in startup binary. Maybe you can swap those with your own one from PON stick. But since you have the Realtek SDK, does it comes with the toolchain for the GPON SoC? we just have incomplete reverse engineer SDK but, compile for ARM64 not that hard, like Zyxel did, use OpenWRT tool chain, see if can use Zyxel kernel and driver on D-Link, if required patching, so be it. let say DPN-FX3060V A1 has completed OpenWRT Build, still can't update firmware via WebGUI, need flash directly into NAND |
|
|
Feb 21 2025, 02:52 PM
Return to original view | IPv6 | Post
#39
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
2,399 posts Joined: Jul 2009 From: /dev/null |
QUOTE(kwss @ Feb 21 2025, 01:24 PM) Do both Zyxel and D-Link has the same mtdblock layout? since both use UBI underlying MTD, and Zyxel ONR can't login root yet, so MTD layout is unknown.If yes then it should be just re-use the "dtb" and "kimage" from D-Link. Replace all the kernel module in Zyxel "rootfs" with D-Link and it should just boot? Maybe copy over those OEM config from D-Link too, as it contains the hardcoded mesh key, VoIP config, etc? in group said, is possible just copy Zyxel to D-Link as is, they theories it will boot kwss liked this post
|
|
|
Feb 23 2025, 03:38 PM
Return to original view | IPv6 | Post
#40
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
2,399 posts Joined: Jul 2009 From: /dev/null |
|
| Change to: | 0.0233sec
0.47
7 queries
GZIP Disabled
Time is now: 28th November 2025 - 01:45 AM |