Resetting.....

Upcoming fresh hacks

Non-Technical Hacks that works - Have Fun! (Status: in progress..)

Hacking network based biometric time-attendance system - Be your own boss! (Status: Done!)
Milestone Xprotect License Bypass hack - Replace a camera without license re-activation (Status: Done!)

Wednesday, June 22, 2011

Zain Wimax: Huawei Echolife BM635 Wimax module & serial output log



Huawei Echolife BM635 Wimax Module

Serial output @115200



Board MAC address: XX.XX.XX.XX.XX.XX

VxWorks System Boot

Copyright 1984-2002 Wind River Systems, Inc.

CPU: SEQUANS SQN1130 - ARM926EJ (ARM) at 200.0MHz
Version: VxWorks5.5.1
BSP version: 1.2/6
Creation date: Aug 2 2010, 17:06:31
Sequans 4.6.1.4 [r4.6.1.4/25687]
Hardware MAC: 06.00.0000 _PHYBE: 06.00.0000 _PHYFE: 06.00.0000

Press any key to stop auto-boot...
2
1

auto-booting...

boot device : tffs=0,0
unit number : 0
processor number : 0
host name : host
file name : /tffs/vxWorks.7z
inet on ethernet (e) : 192.168.0.100:FFFFFF00
host inet (h) : 192.168.0.10
user (u) : ofdma
ftp password (pw) : ofdma
flags (f) : 0x0
target name (tn) : HW
startup script (s) : /tffs/ss1130_10M_usb.sh
other (o) : seqLoc

Attaching to TFFS... done.
Loading /tffs/vxWorks.7z...Uncompressing 425575 bytes...
Loading image... 1286848

Starting at 0x10000...

Board MAC address: XX.XX.XX.XX.XX.XX
Attached TCP/IP interface to seqLoc unit 0
Attaching network interface lo0... done.

Adding 3628 symbols for standalone.

]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]
]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]
]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]
]]]]]]]]]]] ]]]] ]]]]]]]]]] ]] ]]]] (R)
] ]]]]]]]]] ]]]]]] ]]]]]]]] ]] ]]]]
]] ]]]]]]] ]]]]]]]] ]]]]]] ] ]] ]]]]
]]] ]]]]] ] ]]] ] ]]]] ]]] ]]]]]]]]] ]]]] ]] ]]]] ]] ]]]]]
]]]] ]]] ]] ] ]]] ]] ]]]]] ]]]]]] ]] ]]]]]]] ]]]] ]] ]]]]
]]]]] ] ]]]] ]]]]] ]]]]]]]] ]]]] ]] ]]]] ]]]]]]] ]]]]
]]]]]] ]]]]] ]]]]]] ] ]]]]] ]]]] ]] ]]]] ]]]]]]]] ]]]]
]]]]]]] ]]]]] ] ]]]]]] ] ]]] ]]]] ]] ]]]] ]]]] ]]]] ]]]]
]]]]]]]] ]]]]] ]]] ]]]]]]] ] ]]]]]]] ]]]] ]]]] ]]]] ]]]]]
]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]
]]]]]]]]]]]]]]]]]]]]]]]]]]]]] Development System
]]]]]]]]]]]]]]]]]]]]]]]]]]]]
]]]]]]]]]]]]]]]]]]]]]]]]]]] VxWorks version 5.5.1
]]]]]]]]]]]]]]]]]]]]]]]]]] KERNEL: WIND version 2.6
]]]]]]]]]]]]]]]]]]]]]]]]] Copyright Wind River Systems, Inc., 1984-2003

CPU: SEQUANS SQN1130 - ARM926EJ (ARM). Processor #0, 200.0 Mhz
Memory Size: 0x1fffffc. BSP version 1.2/6.
Sequans BSP 4.6.1.4 [r4.6.1.4/25687]
Hardware MAC: 06.00.0000 _PHYBE: 06.00.0000 _PHYFE: 06.00.0000

Executing startup script /tffs/ss1130_10M_usb.sh ...


#================================================#
# #
# # # # # # # # ####### # #
# # # # # # # # # # # #
# ##### # # ##### # # # # ##### # #
# # # # # # # # # # # # # #
# # # # # # # # # ###### # #
# C O M M U N I C A T I O N S #
# #
#================================================#

ldz "/tffs/apps.7z"

Uncompressing 1862160 bytes...
Loading image...
value = 0 = 0x0

APPS_SW_VER_NAME = "EchoLife BM635 V100R001BHRC40B503"

APPS_SW_VER_NAME = 0x15be38c: value = 33006756 = 0x1f7a4a4

APPS_RFC_DRIVER_NAME = "PM8801"

APPS_RFC_DRIVER_NAME = 0x15be310: value = 33006740 = 0x1f7a494

wmdDbgChannelScheme=2

wmdDbgChannelScheme = 0x15c4bf8: value = 2 = 0x2

APPS_USBS_DRIVER_NAME = "CDC-ECM"

APPS_USBS_DRIVER_NAME = 0x15be390: value = 33006724 = 0x1f7a484

RFC_PM880X_MIN_FREQ = 3400000

RFC_PM880X_MIN_FREQ = 0x15c6f78: value = 3400000 = 0x33e140
RFC_PM880X_MAX_FREQ = 3600000

RFC_PM880X_MAX_FREQ = 0x15c6f7c: value = 3600000 = 0x36ee80

APPS_RFC_MIN_FREQUENCY = RFC_PM880X_MIN_FREQ

APPS_RFC_MIN_FREQUENCY = 0x15be308: value = 3400000 = 0x33e140
APPS_RFC_MAX_FREQUENCY = RFC_PM880X_MAX_FREQ

APPS_RFC_MAX_FREQUENCY = 0x15be30c: value = 3600000 = 0x36ee80

APPS_ENABLE_THP = 1

APPS_ENABLE_THP = 0x15be3d4: value = 1 = 0x1

RFC_PM880X_CALIBRATION_FILE = "/tffs/foo.cfg"

RFC_PM880X_CALIBRATION_FILE = 0x15c6f80: value = 33006700 = 0x1f7a46c

APPS_OFFSET_QTY_TO_SCAN = 1

APPS_OFFSET_QTY_TO_SCAN = 0x15be168: value = 1 = 0x1

#No wait Dcd

dlcsDbgNoDcdWait = 1

dlcsDbgNoDcdWait = 0x15c500c: value = 1 = 0x1

RFC_PM880X_RX_DCOC_CFG_SELECT = 1

RFC_PM880X_RX_DCOC_CFG_SELECT = 0x15c6ec8: value = 1 = 0x1
RFC_PM880X_TX_STARTUP_OFFSET_US = 11

RFC_PM880X_TX_STARTUP_OFFSET_US = 0x15c6e8c: value = 11 = 0xb
RFC_PM880X_RX_2_TX_TURNAROUND_US = 30

RFC_PM880X_RX_2_TX_TURNAROUND_US = 0x15c6e90: value = 30 = 0x1e

#Igonre ERTPS latency(Must)

smmcDbgIgnoreMaxLatency=1

smmcDbgIgnoreMaxLatency = 0x15c4730: value = 1 = 0x1

#Harq optimized(Must)

umssDbgProgMarginSb=20

umssDbgProgMarginSb = 0x15c52f4: value = 20 = 0x14


#Enable old power control(Must)

umssDbgClosedLoopRpd = 0

umssDbgClosedLoopRpd = 0x15c5310: value = 0 = 0x0
upcsDbgClosedLoopRpd = 0

upcsDbgClosedLoopRpd = 0x15c69a0: value = 0 = 0x0

#Increase T12 (Must)

APPS_ULCS_T12 = 50000

APPS_ULCS_T12 = 0x15be180: value = 50000 = 0xc350

#Set scan Times to 1 (Must)

APPS_OFFSET_QTY_TO_SCAN = 1

APPS_OFFSET_QTY_TO_SCAN = 0x15be168: value = 1 = 0x1

#Disable Power Saving (Linkem customize)

wmdsDbgDisablePowerSaving

PS has most probably been disabled.
value = 0 = 0x0

#Huawei IOT mode

cbesIotMode = 3

cbesIotMode = 0x15bf6f4: value = 3 = 0x3


# ADDITIONAL settings for scanning optimization

MOBS_SCN_REQ_ITERATION = 1

MOBS_SCN_REQ_ITERATION = 0x15c67f4: value = 1 = 0x1
swmSysInit

Version: 4.6.1.4 [r4.6.1.4[appsInitTask] initializing
/25687]
#!!# WARN: 0000.010 s - BBOX/Manager - RF configuration not found

HW version check
#!!# WARN: 0001.550 s - WMD/pms - Power Saving configuration altered (FFFFFFFF).
[XML_CSS_ParasLoadRapList] NspIdQty = 1
[XML_CSS_ParasLoadRapList] NspId = 2--2
[XML_CSS_ParasLoadRapList] Nsp priority = 1
[XML_CSS_ParasLoadCapList] NapId = 1
[XML_CSS_ParasQueryFreqByNap] tempAttribValue = 1,2
[XML_CSS_ParasQueryFreqByNap] Part of ChannelId = 1
[XML_CSS_ParasQueryFreqByNap] Call XML_CSS_ParasQueryFreqIdByChannelId B.
[XML_CSS_ParasQueryFreqByNap] ChannelId = 1
[XML_CSS_ParasQueryFreqIdByChannelId] ChannelId = 1!
[XML_CSS_ParasQueryFreqByNap] channelCfgQty is 0
[XML_CSS_ParasQueryFreqByNap] Part of ChannelId = 2
[XML_CSS_ParasQueryFreqByNap] Call XML_CSS_ParasQueryFreqIdByChannelId A.
[XML_CSS_ParasQueryFreqByNap] ChannelId = 2
[XML_CSS_ParasQueryFreqIdByChannelId] ChannelId = 2!
[XML_CSS_ParasQueryFreqByNap] channelCfgQty is 0
[XML_CSS_ParasLoadCapList] NapQty = 00000000
#!!# WARN: 0002.010 s - APPS/app - Calibration file /tffs/calibration.cfg not found.
>>>> 0002.010 s - RFC/pm880xGeneral - RFC_PM880X_BUILD_NUMBER 63.12 -
[wimax]ReadCfg UserName is
[appsInitTask] initialized
[appsInitTask] starting
[appsInitTask] started
****** Total allocated SDRAM: 11705039 Bytes
#!!# WARN: 0004.920 s - APPS/app - LED configuration file /tffs/led.cfg not found.
#!!# WARN: 0004.950 s - APPS/app - Host GPIO configuration file /tffs/gpio.cfg not found.
value = -1 = 0xffffffff

#Enable old power control

umssDbgClosedLoopRpd = 0

umssDbgClosedLoopRpd = 0x15c5310: value = 0 = 0x0
upcsDbgClosedLoopRpd = 0

upcsDbgClosedLoopRpd = 0x15c69a0: value = 0 = 0x0


epsSetFatalErrorMode 2

value = 0 = 0x0


cmd "CBE:setMii speed=100Mbits duplex=full-duplex"

value = 0 = 0x0


cmd "setuser sup"

value = 0 = 0x0
cmd "upcs:set init-rng-step=800"

value = 0 = 0x0
cmd "rngs:set max-retries=22"

value = 0 = 0x0
cmd "RNGS::setConfig init-rng-timeout=5000"

value = 0 = 0x0
cmd "setmcstate connected"

value = 0 = 0x0
cmd "sethandover off"

value = 0 = 0x0


routeAdd "192.168.1.0","192.168.0.20"

value = 0 = 0x0


cmd "setuser normal"

value = 0 = 0x0


cmd "startss"

SS startedvalue = 0 = 0x0
>>>> 0005.360 s - SPY/Ss - DL SYNCHRONIZATION

Done executing startup script /tffs/ss1130_10M_usb.sh
-> >>>> 0037.840 s - SPY/Ss - UL ACQUISITION
>>>> 0037.850 s - SPY/Ss - RANGING
>>>> 0039.270 s - SPY/Ss - ABORTED
>>>> 0039.690 s - SPY/Ss - DL SYNCHRONIZATION


End!

1 comments:

Behrooz Shie said...

Hi
How to change a MAC address?

Post a Comment