Go Back   Techwatch Support Forums: Digital & Satellite TV, FTA, Cable, Computers, Mobile Phones, Apple and General Tech Forums > Tech Forums > Digital TV > UK Cable > Cable Modems



Cable Modems Gotta start somewhere and here's the place to start :)

Reply
 
LinkBack Thread Tools
Old 03-09-08, 03:46 AM   #1 (permalink)
Member
 
Join Date: Sep 2008
Location: Great Britain
Posts: 36
Thanks: 2
Thanked 18 Times in 11 Posts
Default Console Hack to Unbrick Ambit 250s 255s no tsop lift

Water is the guy who made it creds to him
LOONEY2008
General Discussion

Moderator
Location: teeside
Thanks: 45
Thanked 19 Times in 14 Posts
Rep Power: 9



Ambit 250/255 Restore Option P
E08C007 Console Unlocker Exploit

Well the eagerly awaited Console Unlocker is here. Thanks to Water for all the effort and hard work.

Quote:
Originally Posted by Water
I completed this project a few months back, and didn’t really have much intention
of making it public as I don’t usually like to do that with my work.
But due to a mixture of being busy,
lazy and some **** wit who thinks he can copy my work and take credit for it, here we go…
A lot of people have kept on asking about this, and when it will be released etc. Well finally, here it is: the eagerly awaited 2.94.1014 software hack,
which is the firmware found on the “250/255 modems” as they are more commonly referred to as. This exploit opens up the console which ultimately
allows you to change the bootloader for some flashing fun.
It started off with some **** at Ambit who thought the 3.1.6d bootloader was a good idea.
After being locked out of my hardware, I set upon the
challenge of getting back in without lifting the flash.
The only route was a software hack, and thus after some time, patience and a lot of enthusiasm,
this exploit application was born.
The exploit is thanks to a vulnerability in the httpd which causes it to crash when you feed it quirky authentication packets. This then kick starts the
console, and after applying some voodoo to deter the watchdog, you are left with a stable console connection to your hardware. From here on, you
could read/write/erase flash regions (such as the bootloader) using SoftJtag etc.
Shoutz to everyone who has worked hard to keep the scene going.
Also thanks to my

USAGE:
1. Apply serial and Ethernet connection between your PC and the modem
2. Set your PC IP parameters to:
IP: 192.168.100.10
Subnet: 255.255.255.0
Gateway: 192.168.100.1
3. Power on the modem and wait for it to startup (10 secs)
4. Open the exploit application and hit “Execute Exploit”
5. If it says its successful, then the console is now ready to accept connections!
If it fails, power cycle the modem and try the application again.
At this point,
if you want to restore your bootloader to the original 2.1.6d that has the re-flashing menu etc, you need a copy of SoftJTAG and the
2.1.6d bootloader.
**BE CAREFUL WHEN USING SOFTJTAG -
As you can brick your modem if your not careful**
1. Open SoftJTAG, and connect via your serial port.
2. On the right hand side, click on “Write Bootloader” and select the 2.1.6d bootloader file
3. Wait till its done (this takes 10 – 15 minutes). Once it’s done, close SoftJTAG
4. Start HyperTerminal/TeraTerm and connect to your serial port
5. Reset the modem
Upon resetting the modem, you will now be given the option to stop at P as it is now booting with the 2.1.6d bootloader. You MUST press the button
and stop then, as if you miss it and let it fully boot, your bootloader will be over-written again with the 3.1.6d, in which case you will have to repeat
these steps again and be quicker not to miss it next time.
If you are successful in entering the menu,
you can now re-flash or whatever you wish to do with your modem from this menu!
Legal disclaimer: I take no responsibility for the above given information or files and what you decide to do with it. This is purely for information purposes and should not be attempted to be executed in any way,
particularly for any illegal purposes. I could tell you thumping a noob over the head with a modem would probably knock them unconscious, but that doesn’t mean you should do it.


You'll need all the following files on your PC. If you use the Ambit Tool or similar apps you've probably already installed .NET Framework & Visual J.



Console Unlocker
HTML Code:
http://***************/files/141843898/Console_Unlocker_v1.1b_Revolution_Forums_Edition.rar.html
2.1.6d Bootloader
HTML Code:
http://***************/files/142073844/2.1.6d_Bootloader.zip.html
Soft JTAG All Versions

HTML Code:
http://***************/files/142025730/Soft_Jtag_all_versions.rar.html
Microsoft .NET Framework Version 2.0 Redistributable Package (x86)
HTML Code:
http://www.microsoft.com/downloads/thankyou.aspx?familyId=0856eacb-4362-4b0d-8edd-aab15c5e04f5&displayLang=en
Microsoft Visual J#® 2.0 Redistributable Package – Second Edition (x86)
HTML Code:
http://www.microsoft.com/downloads/thankyou.aspx?familyId=e9d87f37-2adc-4c32-95b3-b5e3a21bab2c&displayLang=en
WINCOMM32.ocx & MSWINSCK.ocx
HTML Code:
http://***************/files/142015319/OCX_files.rar.html
Joker is offline   Reply With Quote
The Following 7 Users Say Thank You to Joker For This Useful Post:
advance (19-09-08), andronics (13-09-08), anthrax (30-09-08), Panikos (01-10-08), razwan1 (17-10-09), tripos (21-02-09), vitalsystms (24-05-09)
Old 05-09-08, 03:49 AM   #2 (permalink)
Super-Dooper Moderator
 
lincsat's Avatar
 
Join Date: Sep 2005
Location: In front of the PC
Posts: 6,003
Thanks: 8
Thanked 2,580 Times in 667 Posts
Default Re: Console Hack to Unbrick Ambit 250s 255s no tsop lift

The files are available from the Private FTA download links, they are untested so use at your own risk.
__________________
Blade7000 & DM800Pro/SE in Stock, Linux Sat boxes from £52.25, SkyboxF3 under £60. Kryptview £123.50 & SV6 under £72 with Members Discount - Lincsat's Nick-Nacks (Shop)

lincsat is offline   Reply With Quote
Old 28-09-08, 10:14 PM   #3 (permalink)
Stella Artois
 
50pounds's Avatar
 
Join Date: Apr 2008
Location: Teesside
Posts: 960
Thanks: 106
Thanked 151 Times in 116 Posts
Default Re: Console Hack to Unbrick Ambit 250s 255s no tsop lift

i did evrything wrote down here

now my modem has only the power light on lol

OMG this just gets really annoying the soft jag proggy timed out in the middle of flashing no way to bring this back to life??
50pounds is offline   Reply With Quote
Old 28-09-08, 10:46 PM   #4 (permalink)
Senior Member
 
abaaba's Avatar
 
Join Date: Apr 2008
Location: out of this world
Posts: 1,366
Thanks: 223
Thanked 170 Times in 157 Posts
Default Re: Console Hack to Unbrick Ambit 250s 255s no tsop lift

the link doesnt seem to work, what am i supposed to change the ****** with?
__________________
All info s 4educational purposes only!
La liga, UCL, Kings Cup, Club World Cup, Spanish Super Cup & European Super Cup champions.
abaaba is offline   Reply With Quote
Old 29-09-08, 01:17 AM   #5 (permalink)
Night owl twit twoo :P
 
toolzkit's Avatar
 
Join Date: Sep 2008
Posts: 570
Thanks: 90
Thanked 65 Times in 46 Posts
Default Re: Console Hack to Unbrick Ambit 250s 255s no tsop lift

I think you have to be a member of the forum which these links came from.... RF

Last edited by toolzkit; 29-09-08 at 01:20 AM.
toolzkit is offline   Reply With Quote
Old 29-09-08, 01:31 AM   #6 (permalink)
Stella Artois
 
50pounds's Avatar
 
Join Date: Apr 2008
Location: Teesside
Posts: 960
Thanks: 106
Thanked 151 Times in 116 Posts
Angry Re: Console Hack to Unbrick Ambit 250s 255s no tsop lift

Quote:
Originally Posted by toolzkit View Post
I think you have to be a member of the forum which these links came from.... RF
well im logged in and still no luck! ? lol shame i got em from else where and now my modem has only got the power light showing!
50pounds is offline   Reply With Quote
Old 30-09-08, 10:26 PM   #7 (permalink)
Senior Member
 
anthrax's Avatar
 
Join Date: May 2008
Location: UK NORTH
Posts: 239
Thanks: 55
Thanked 23 Times in 18 Posts
Default Re: Console Hack to Unbrick Ambit 250s 255s no tsop lift

m8, thanx so much for that, once i worked out what links were what and also helped along the way with file and that, my god it worked 1st time, i was abit dubious it first, but i thought why not , as everything else i have follwed off this site has worked be it jtag/max cable building---doing tv //modems--its worked , so thanx all, i cant beleive this----and i was gonna buy a willem---daft me!! glad i didnt¬¬¬¬ though could be usefull for future projects like wii chipping etc....

silly me though got a bit previous a month or so ago--and removed chips of 3 modems, ready for when i got a willem---ill go and buy a gas blower thingy--ant put em back now ---my other got lost-broken buy misses somewhere!!!

anyway thanx again i still cant belive it!!
__________________
anthrax

Last edited by anthrax; 30-09-08 at 10:29 PM.
anthrax is offline   Reply With Quote
Old 01-12-08, 10:41 PM   #8 (permalink)
Senior Member
 
Join Date: Nov 2008
Posts: 225
Thanks: 7
Thanked 2 Times in 2 Posts
Default Re: Console Hack to Unbrick Ambit 250s 255s no tsop lift

will this work on a epc2100 modem ..it has never been flashed or anythin just an old 1 frokm when i had the net
big guns 08 is offline   Reply With Quote
Old 02-12-08, 09:24 PM   #9 (permalink)
Senior Member
 
Join Date: Nov 2008
Posts: 225
Thanks: 7
Thanked 2 Times in 2 Posts
Default Re: Console Hack to Unbrick Ambit 250s 255s no tsop lift

?,,,,,
big guns 08 is offline   Reply With Quote
Old 02-12-08, 11:16 PM   #10 (permalink)
G77
Super Moderator
 
G77's Avatar
 
Join Date: May 2008
Posts: 6,118
Thanks: 695
Thanked 1,250 Times in 1,044 Posts
Default Re: Console Hack to Unbrick Ambit 250s 255s no tsop lift

i've not come across a 2100 without option p!
__________________
1M Motorised Dish, 45W-36E, DM800HD.
Quad LNB Mesh Mini Dish, 28.2E, DM500, TM500.
Samsung Galaxy S GT-I9000 XXJVU & CF-Root.
G77 is offline   Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
xbox 360 error code guide steve07951 Microsoft Xbox 4 16-10-09 12:06 AM


All times are GMT +1. The time now is 11:12 PM.


Powered by vBulletin® Version 3.8.5
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.6.0 ©2011, Crawlability, Inc.