AndrejkaB A. schrieb:> Hi,>> Earlier Blagus asking about JTAG-ing to STMC.> Here are interesting link to czech forum, device is different, but> processor is the same.>> http://forum.ican3800.zajsoft.net/viewtopic.php?f=...>> BR> Andrej
As I said, I already use STMC and everything is set up properly. I can
connect to all my ST boards except this VIP1003 (and I didn't test 1963
yet).
Hei
I have a "Motorola VIP1910-9"
Can any one give me an Step By Step list to change the firmware,
A have an Raspberry pi or an Windows pc to work from.
I want to be able to stream video from my NAS.
Hello Martin,
I have problem when I use ajax (jquery) to change content of div
everything works fine except closing socket. After ajax call there is
one socket CLOSE_WAIT and it hangs. In few days number of those unclosed
socket reach 1023 and webkit crash with error too many open files. When
I try portal from PC (chrome browser) sockets are automaticly closed
after 5s. In portal I use this jquery setting
jQuery.ajaxSetup({async:false,cache: false,timeout:5000,crossDomain:
true});
Have you same problem or you doesnt use jquery?
stb example:
/ # netstat -an |grep CLOSE_WAIT
tcp 1 0 10.1.99.67:55115 10.1.1.4:80
CLOSE_WAIT
tcp 1 0 10.1.99.67:37826 173.194.65.104:443
CLOSE_WAIT
tcp 1 0 10.1.99.67:33034 173.194.116.239:80
CLOSE_WAIT
tcp 1 0 10.1.99.67:36506 10.1.1.4:80
CLOSE_WAIT
tcp 1 0 10.1.99.67:37824 173.194.65.104:443
CLOSE_WAIT
tcp 1 0 10.1.99.67:55114 10.1.1.4:80
CLOSE_WAIT
tcp 1 0 10.1.99.67:36518 10.1.1.4:80
CLOSE_WAIT
tcp 1 0 10.1.99.67:52913 173.194.116.249:443
CLOSE_WAIT
Hi All.
Im new at this.
I have a VIP 1903 from Comhem Sweden. My question is, if it possible to
activate the two USB ports on it and if its possible to get the rest of
the codes to display the menu options like 7532, 2357,
I have read all that I can find but so far no luck.
Im trying to use it on my network and on a secondary Tv.
Also looking for a pinout on how to add a hdd. I have checked and it
seems like the 1903 and the 1963 using the same board.
thanks in advance
Jonny // Sweden
As far as I know that are the only codes, there are no more options to
set.
The usb can only be activated by other software but comhem uses a
unknown key to sign the software so the software found here can't be
used. (I also have a comhem 1903C box)
I don't think you can convert a 1903 to a 1963. Doesn't have comhem a
1963? Maybe you can find one cheap on an auction site.
Question for you, can you capture the boot image of the comhem box? I
like to get mine running again.
Greetz from Holland.
Hi Martin.
Hmm Ok. I got this box replaced. Comhem started to Use Tivo.
Its odd that it seems impossible to do a factory reset and install
firmware that Motorola use. Or is it so that just this VIP boxes is only
used as OEM like comhem or Telia (Sweden) ? As far as I know it uses
linux like sw. So it would be possible to just reflash it.
I can try to capture the boot image but frankly I have no clue how to do
that.
Capture the software can only be done if the box is in active use by
comhem. !! If not don't erase it because once erased you can't get
software on it. !!
The box is running linux but accept only software/ firmware which is
signed with a key.
Motorola gave the providers, like comhem, telia, comx, kpn the option to
use default (developer) keys or custom keys. Comhem & Comx choice to use
their own keys. I've tried every version of software I could find but
none are accepted by the Comhem (and Comx) box I have.
Ok I see.
Well Im connected to Comhem network and I have erased it ones but due to
the facked that Im on Comhem network it updated and downloaded new
software.
So if you like to send me how-to on getting the image out of it I can
try.
I going to try to talke to Comhem about it maby I can get hold of a tech
that can help me but im not to sure ;-)
Hi Martin.
I just talked to a really nice person on Comhem support. He couldent
help me right away but going to take contact to the tech department for
Comhem in Stockholm and ask them. He going to mail me with info. Hope we
can solv this with the sw on the boxes :-)
Some info to get the images.
Find the server address, should be listed in the IP menu -> Metadata
Default is 224.2.2.2:22222
Download the file Infocast2Tools.v1.3.zip and compile it.
Connect the pc to the iptv port of the modem. Hopefully you get an ip.
If not you can try to clone the mac address of the motorola. (this is
better because maybe Comhem's loadbalancer uses the mac to send you to
the right server)
Start the client software.
./client 224.2.2.2 22222 1
This shows what the multicast server has to offer.
With ./client 224.2.2.2 22222 2
it saves the files it get -> this is what is needed. This can take a
long time!
For more info you can also connect me directly.
Ok Ill try.
Whats the best. Try to do this in Linux or Windows.
I have Linux mint on a test computer and Windows 7 om this one I write
to you on.
I havent used Linux for a long time befor I started this.
Oki then..
Comhem dont use a specific IPTV port on the modem. Using cable modem and
its connected to one of the 4 ports on that one. Then its connected to
the wall for standard TV. Comhem using Netgear CG3100 as cablemodem.
So I have a problem to figure this out.
Is it possible to connect Motorola direct to the computer ??
The files we want are send from comhem not from the motorola.
Looks like they put the boxes in a Vlan, so with mac spoofing your pc
should be in the iptv vlan and the tools should capture the files.
sudo root
nano /etc/network/interfaces
#############
auto eth0
iface eth0 inet dhcp
hwaddress ether 01:02:03:04:05:06
############
ctrl+o
enter
reboot
replace 01:02..etc with the mac address of the Motorola.
If no IP after that try this:
Insert into /etc/network/interfaces:
clientid motorola_vip_1903 //probably, you need Wireshark to find out
If no IP after that try this:
You probably need to tweak the dhcp client also
Again Wireshark will tell you the Vendor Specific Options.
Insert those and you probably will get an IP.
Let me know
Hi I tried this tool too.
I use windows version but I have to use switch with mirrored port and
repeatly boot STB. When I try it only with pc I have no luck. When I
disconnect STB multicast stop. There was some live check or heartbeat
from STB. Maybe it helps you.
Hi.
Regarding VIP1003 JTAG I asked about earlier - it turns out that STi7105
has JTAG lock feature, which Motorola uses. So there's no JTAG for
VIP1003, unfortunately. However, STi7109 doesn't seem to have such
protection, and I have VIP1910 and VIP1963 so I'll test it on them.
How can you play channel with verimatrix? I have verimatrix.iip,
configured .ini, but when I try to play channel, nothing happens. It
doesn't even ask on verimatrix server, like I need to force it to get
license. Do I miss something?
It doesnt work. I tried every image which I have. VIP 1003 boot fine but
VIP 1103 doesnt. It has new splash screen too with progress bar. It from
arris but it doesnt matter because I have motorola 1003 and arris 1003
and they use same image.
Hei
i have a "Motorola VIP1910-9" and a "Motorola VIP1903C"
How can i make thes work like a Media center?
My real Wish is to make the "Motorola VIP1903C" work as a recive and
viewer
and let the "Motorola VIP1910-9" all the recived data like DVB-C, VCR
and USB-HDD.
But i will start to make it work as simple Media center.
Can some one pleace help me.
Hi there
Any ideas as to why my VIP 1903 (C?) keeps rebooting after installing a
custom firmware, when I alter the HTTP settings to fetch a new firmware
from my local server?
It's downloading the file
"kreatv-bi-vdr.config_4.3.IAP30.3_st40_vip19x3.bin" - installs it, saves
it .. then it reboots, and downloads it once again. Keeps doing this
until I remove the HTTP settings and let it download the firmware from
my TV provider.
Thanks
I've had the same problem with my Comhem box. Looks like they use an
other encryption key.
If you have an Comhem box, I'm interested in the provider image. My
Comhem box is just a paperweight right now.
@Ivan if you can find the SDK with the dlna & dvb-c module you can make
an image and connect the boxes just like you want.
Greetz Martin
Martin V. schrieb:>> @Ivan if you can find the SDK with the dlna & dvb-c module you can make> an image and connect the boxes just like you want.>
Does anyone have a link to the starter kit sdk? None of the links in
this thread seem to work anymore :-(
Alternatively, does anyone have an unencrypted, generic image? I'd just
like to dig around the files to get a sense of everything.
The Arcadyan can be hacked by using a timing attack on the cfe memory.
I have no idea when or what I did. I just stuck a paperclip onto the
reset pins and by resetting the device and poking on the right moment it
dumped me into cfe. Problem is I can not get out of it. But you can load
your own firmware with it. Oh, anf ofcourse they are violating the GPL.
Just to let you know.
Hello,
I try to setup SCART on vip1003 to svideo output. I want to use
component cable because if I connect stb to 4k TV and after turn off and
turn on stb crash down. But i see output only in booting, after apply
defaultVideoSetting i got NO SIGNAL only. I have EMEA version of 1003.
Could anybody help me with that?
Hello
Try set kernel and slash protocols to 323.
as some later say
"A string with the splash protocol-order to use when downloading the
splash image."
1 = BootCast
2 = TFTP
3 = Local Storage (if available)
4 = SAP (Session Announcement Protocol)
5 = DVD/CD (if available)
6 = HTTP (available from version 3.03)
323 try fist local store if has image load it, if dont have is try load
tftp. If you trying use http try use protocols 363 etc.
tftp-server/client=http://tftpd32.jounin.net/tftpd32_download.html
I looked motorola vip 1903 specs and found that has advanced boot chip
32mb and NAND512mb so if power go off is have boot image there.
Order is bootloader(32mb)[projected]->nand(512mb)[slow]->ram(2gb)[fast]
RAM(1gbx2chips)(flash2)
NAND(512mb)(flash)
df output
Filesystem 1K-blocks Used Available Use% Mounted on
tmpfs 116788 20 116768 0% /old_root
none 64940 48 64892 0%
/old_root/dynamic
/dev/rootdisk0 16512 16512 0 100% /old_root/static
unionfs 64940 48 64892 0% /
none 64940 28 64912 0% /tmp
/dev/mtdblock0 512 256 256 50% /flash
/dev/mtdblock2 65536 18016 47520 27% /flash2
mount output
rootfs on / type rootfs (rw)
tmpfs on /old_root type tmpfs (rw)
none on /old_root/proc type proc (rw)
none on /old_root/dynamic type tmpfs (rw)
/dev/rootdisk0 on /old_root/static type squashfs (ro)
unionfs on / type unionfs
(rw,noatime,dirs=/old_root/dynamic=rw:/old_root/static=ro)
none on /sys type sysfs (rw)
none on /proc type proc (rw)
none on /tmp type tmpfs (rw)
none on /dev/pts type devpts (rw)
/dev/mtdblock0 on /flash type jffs2 (rw,nodev,noexec,noatime)
/dev/mtdblock2 on /flash2 type yaffs (rw,nodev,noexec,noatime)
BusyBox v1.13.3 () multi-call binary
Copyright (C) 1998-2008 Erik Andersen, Rob Landley, Denys Vlasenko
and others. Licensed under GPLv2.
See source distribution for full notice.
Usage: busybox [function] [arguments]...
or: function [arguments]...
BusyBox is a multi-call binary that combines many common Unix
utilities into a single executable. Most people will create a
link to busybox for each function they wish to use and BusyBox
will act like whatever it was invoked as!
Currently defined functions:
[, [[, ash, awk, basename, brctl, bunzip2, bzcat, cat, chgrp,
chmod, chown, chroot, clear, cp, cut, date, dd, df, dirname,
dmesg,
du, echo, egrep, env, expr, false, fdisk, fgrep, find,
freeramdisk,
ftpget, ftpput, grep, gunzip, gzip, halt, head, hostname, id,
ifconfig, init, insmod, ip, ipaddr, iplink, iproute, kill,
killall,
ln, losetup, ls, lsmod, md5sum, mdev, mkdir, mkfifo, mknod,
mkswap,
mktemp, modprobe, more, mount, mv, netstat, nslookup, pidof,
ping,
poweroff, printf, ps, pwd, reboot, renice, reset, rm, rmdir,
rmmod,
route, sed, sh, sleep, sort, strings, swapoff, swapon, sync,
tail,
tar, telnet, telnetd, test, tftp, time, top, touch, tr,
traceroute,
true, udhcpc, umount, uniq, uptime, usleep, vi, watchdog, wc,
wget, which, xargs, yes, zcat, zcip
Installed with "kreatv-bi-vdr.config_4.3.IAP30.3_st40_vip19x3.bin" used
tftp. dmesg dont work so need use logclient to ip-address.VLC client
working fine if has address installed and http-server on advanced
settings.
so i have questions:
1.can some complete build with ext2/3/4 ???
2.can put PortalURL to set variable easer contorl ??
exsample "<PortalURL>http://192.168.3.15/portal/webkit</PortalURL>" to
"<PortalURL>http://${PORTAL_URL)/portal/webkit</PortalURL>"
export PORTAL_URL=192.168.3.15
3.can some write ir-codes for 1903 control is hard bind all ???
cd etc
rm irmap.conf
echo "
PROTOCOL=kreatvir,ID=38 # KPN
#codes found in irmaps_def
89,2 #1
105,3 #2
121,4 #3
28,5 #4
44,6 #5
60,7 #6
76,8 #7
92,9 #8
108,10 #9
29,0 #0
#inside ring
88,105 #left
104,106 #right
72,108 #down
56,103 #up
107,129 #mute
9,116 #power
#fix this
#outside ring
40,105 #left
24,106 #right
9,108 #down
127,103 #up
75,63 #red
63,64 #green
120,65 #yellow
31,66 #blue
43,67,29 #text
39,60,56 #rec
15,63 #OK select,play,pause
91,218 #back
73,88 #menu
124,59 #info
25,210 #tv
77,11 #vol +
61,12 #vol -
#fix this
">>irmap.conf
init-irdriver irmap.conf
4.can install ohter linux version example dsl,puppy,freenas ???
5.can install router firmwares tomato,dd-wrt ???
To help with ir-codes need load ir-map and read codes with
read-irdriver then control works with webprotal.
PROTOCOL=kreatvir,ID=38 # KPN version with 1903 use
#codes found in irmaps_def
To change hard way url is open:
vi /usr/applications/ekioh.conf
and change frist line:
application.homepage: http://192.168.3.15/ to
application.homepage: http://ip-address:8080/
And save file as ctrl+":" and :wq
kill ekioh pid with find ps and automatic digibox make new ekioh new
settings working and VLC-client open with mobile-control have fun lolz.
claude schrieb:> To change hard way url is open:> vi /usr/applications/ekioh.cfg> and change frist line:> application.homepage: http://192.168.3.15/ to> application.homepage: http://ip-address:8080/> And save file as ctrl+":" and :wq> kill ekioh pid with find ps and automatic digibox make new ekioh new> settings working and VLC-client open with mobile-control have fun lolz.
To change hard way url is open:
vi /usr/applications/ekioh.cfg
and change frist line:
application.homepage: http://192.168.3.15/portal/webkit to
application.homepage: http://ip-address:8080/
And save file as ctrl+":" and :wq
kill ekioh pid with find ps and automatic digibox make new ekioh new
settings working and VLC-client open with mobile-control have fun lolz.
claude schrieb:> claude schrieb:>> To change hard way url is open:>> vi /usr/applications/ekioh.cfg>> and change frist line:>> application.homepage: http://192.168.3.15/portal/webkit to>> application.homepage: http://ip-address:8080/>> And save file as ctrl+":" and :wq>> kill ekioh pid with find ps and automatic digibox make new ekioh new>> settings working and VLC-client open with mobile-control have fun lolz.
white screen means with log:
webkit_portal.sh(521) Note: OPENING URL == http://192.168.3.15/
portal/webkit
So if digibox not find portal page so be white screen so put VLC client
or
http-server up and put it to /usr/applications/ekioh.cfg and last kill
ekioh pid
Done some working on a KPN VIP19x3, KPN pushed a newer bootloader which
won't work with my software. They also stripped Http & Bootcast. The
settings menu has gone and the box has the same bootloader as a 1853.
1
System memory: 512 MB
2
Using Slot 2
3
Unpacking Image ...Done
4
Linux version 2.6.23.17_stm23_0121 (mcart@mcart) (gcc version 4.2.4 (snapshot) (STMicroelectronics Special 20090602) [build Oct 28 2009]) #1 PREEMPT Tue Jun 25 16:16:46 CEST 2013
5
Booting machvec: vip19x3
6
Reserve 10240 KiB for STAVMEM (0 KiB for graphics) @ 0x4f600000 - 0x4fffffff
when sending "option KreaTV.kernel-protocol" with dhcpd you can't send :
1 = BootCast
5 = DVD/CD
6 = HTTP (available from version 3.03)
You'll get an error
1
00:00:09 01.01.2000 src/main.c 2249 ERROR > Boot protocol type 'bootcast' is not supported
Hi Martin V try lower bootloader if support it.
firmware:http://www.mikrocontroller.net/attachment/164081/kreatv-bi-vdr.config_4.3.IAP30.3_st40_vip19x3.bin
TFTP-server:http://tftpd32.jounin.net/tftpd32_download.html
Download firmware and TFTP and put firmware inside TFTP folder and run
TFTP-server.
Go settings in TFTP-server and setup:
[x]TFTP Server
[ ]TFTP Client
[ ]SNTP server
[ ]Syslog Server
[x]DHCP Server
[ ]DNS Server
And go digibox 19x3 when is go up press menu and press factor code:
2357(Ip settings)
7532(advanced menu)Go here
kernel protocol:323
slash protocol:323
set TFTP-server your PC-address.
Digibox settings follow settings DHCP->TFTP->GET
file->"kreatv-bi-vdr.config_4.3.IAP30.3_st40_vip19x3.bin"
My setup pc(rj-45)->router<-digibox(rj-45)
My internet connection is Router->modem-router(NDIS)->internet
My TFTP-server log Viewer:
Rcvd DHCP Discover Msg for IP 0.0.0.0, Mac 00:02:9B:8B:0F:92 [06/04
21:49:22.137]
Client requested address 0.0.0.0 [06/04 21:49:22.140]
DHCP: proposed address 192.168.2.45 [06/04 21:49:22.140]
6832 Request 2 not processed [06/04 21:49:22.142]
Rcvd DHCP Rqst Msg for IP 0.0.0.0, Mac 00:02:9B:8B:0F:92 [06/04
21:49:22.142]
Previously allocated address 192.168.2.45 acked [06/04 21:49:22.143]
6832 Request 2 not processed [06/04 21:49:22.144]
Connection received from 192.168.2.45 on port 49696 [06/04 21:49:22.600]
Read request for file
<kreatv-bi-vdr.config_4.3.IAP30.3_st40_vip19x3.bin>. Mode octet [06/04
21:49:22.601]
OACK: <blksize=512,tsize=18082314,timeout=5,> [06/04 21:49:22.601]
Using local port 64819 [06/04 21:49:22.601]
<kreatv-bi-vdr.config_4.3.IAP30.3_st40_vip19x3.bin>: sent 35318 blks,
18082314 bytes in 15 s. 0 blk resent [06/04 21:49:37.692]
Logclient.exe:http://www.mikrocontroller.net/attachment/175928/http_example.rar
inside has logclient run it, dmesg dont work so you need run logclient.
putty:http://www.chiark.greenend.org.uk/~sgtatham/putty/download.html
can run digibox 19x3 and give commands for it.
Digibox ipaddress easyly get in TFTP-server logviewer because settings
is to set connect frist pc.
when you get digibox white screen then digibox running
kreatv-bi-vdr-version but is need webportal install to pc.
Now next reboot digibox load
kreatv-bi-vdr.config_4.3.IAP30.3_st40_vip19x3.bin inside
flash[NAND512mb].
Webportal change need give command inside digibox 19x3:
vi /usr/applications/ekioh.cfg
frist line:
application.homepage: http://192.168.3.15/portal/webkit
to
application.homepage: http://pc-address:8080/
:w saves the current file without quitting
http://www.cs.rit.edu/~cslab/vi.html vi-commands
ps and find [ekioh pid-number]
kill [ekioh pid-number]
Automatic digibox make new ekioh and new settings working. New webportal
is geted form pc-address, if there has http-portal-server running or
vlc-client with add interface->web.
Guess who wrote most of the stuff in this topic ;)
Problem is KPN changed the bootloader and removed a lott of stuff. Menu
isn't there anymore and it looks like the key is changed so the firmware
isn't accepted from the tftp server.
Greetz Martin
TFTP-server inside settings has boot file need set as:
Tftppd Settings:
boot file:kreatv-bi-vdr.config_4.3.IAP30.3_st40_vip19x3.bin
Now press ok then DHCP-server give that boot file that digibox load it.
Tryed load multiple Firmwars this way but no success, because bootloader
has security key so boot file need has secured boot file.
TFPT-server:http://www.ethernut.de/en/eboot/ settings
Build own
Firmware:http://sourceforge.net/projects/vip19x0.arris/files/ST40/KreaTV%204.4/kreatv-kit-oss_4.4-st40.tgz
350mb[source codes]
Need linux operation system build firmware.
Readme:
"This distribution covers the VIP19x0, VIP19x3 and VIP1003 series
set-top boxes, hereby referred to as VIP1900. To get the corresponding
description for VIP1903 or VIP1003, just replace the text "1900" with
"1903" in all places below.
VIP1900 STB's are only available in secure versions. Secure
versions will only boot signed software images. The resulting
kernel/boot images signed with the keys supplied with this
distribution (located in dist/config/keys) will boot on a development
kit secure VIP1900."
Ok Martin
But check your boot file frist error with:
"utils_getSystemImageHeader: Wrong magic number 1434553" that means no
secured boot file cant boot.
Normaly digibox go protocols what kernel has but your settings has
Kernel Protocol Order: 2 and Splash Protocol Order: 2
1 = BootCast
2 = TFTP
3 = Local Storage (if available)
But what is TFTP:"192.168.3.210" ip-address your pc ?
And "End of list describing boot protocol order reached" so no more
protocols to follow try use secured boot file in tftp-server what you
have there settings installed.
TFTP:192.168.3.210 if that is not your pc you can change your pc-address
to same as what digibox setting has.
Then install TFTP-server and settings right and try reboot digibox.
Remove software inside digibox, before download firmware your digibox.
kreatv-kit-oss_4.4-st40\bootimage\tools\build_flash_secure_boot_image
350lines with encryption with file so can secure boot file that digibox
bootloader check security keys.
Simply build_flash_secure_boot_image has header check each boot file
that is right magic number exsample my file:
kreatv-bi-vdr.config_4.3.IAP30.3_st40_vip19x3.bin frist line
53 45 43 01 80 00 02 13 E3 AB 84 FD 3A 8B EA 91
Try use diffrent versions bootfiles right getting digibox booted when
white screen is coming.
Hi Martin,
still looking for dlna? I found image
kreatv-bi-eval_4.3.IAP30.3_st40_vip19x3.bin and there isnt set telnet
password. If you boot it up you can copy out extracted iip. Log to stb
via telnet use:
cd /
tar czf dlna.tar.gz /
ftpput -u <username> -p <password> <server address> dlna.tar.gz
dlna.tar.gz
extract archive to sdk directory/extra/dlna
now open file with your image in bi directory
kreatv-rootdisk-XXXXXXXXXXX_4.3.IAP30.3_st40_vip19x3.tgz and copy file
from /etc/processlist.xml to directory extra/dlna/
edit this file and add line below before </SysmanConfig>:
<Program name="dlnamediacontroller" run="/usr/bin/start_dlna.sh"
starttime="30"/>
now add this to your image config:
kreatv-tool-include-file:/usr/bin/start_dlna.sh=../extra/dlna/usr/bin/st
art_dlna.sh,/usr/bin/dlnamediacontroller=../extra/dlna/usr/bin/dlnamedia
controller,/usr/browser/plugins/libtoi-dlnaplugin.so=../extra/dlna/usr/b
rowser/plugins/libtoi-dlnaplugin.so,/usr/lib/libdlnacommon.so=../extra/d
lna/usr/lib/libdlnacommon.so,/usr/lib/libdlnacommon-1.2.so.1=../extra/dl
na/usr/lib/libdlnacommon-1.2.so.1,/usr/lib/libdlnacommon-1.2.so.1.0.2=..
/extra/dlna/usr/lib/libdlnacommon-1.2.so.1.0.2,/usr/lib/libdlna.so=../ex
tra/dlna/usr/lib/libdlna.so,/usr/lib/libdlna-1.2.so.1=../extra/dlna/usr/
lib/libdlna-1.2.so.1,/usr/lib/libdlna-1.2.so.1.0.2=../extra/dlna/usr/lib
/libdlna-1.2.so.1.0.2,/usr/lib/libplatform-1.2.so.1=../extra/dlna/usr/li
b/libplatform-1.2.so.1,/usr/lib/libplatform.so=../extra/dlna/usr/lib/lib
platform.so,/usr/lib/libplatform-1.2.so.1.0.2=../extra/dlna/usr/lib/libp
latform-1.2.so.1.0.2,/usr/lib/streamer/libdlnasourceelement.so=../extra/
dlna/usr/lib/streamer/libdlnasourceelement.so,/etc/processlist.xml=../ex
tra/dlna/processlist.xml
now build image and use dlna plugin
logclient example:
833 13:20:33.760 webkit_portal.sh(550) Note: Registering plugin for
application/motorola-teletext-plugin
835 13:20:33.848 webkit_portal.sh(550) Note: Registering plugin for
application/x-motorola-toi-dlna
837 13:20:34.228 webkit_portal.sh(550) Note: Registering plugin for
application/x-motorola-toi
add <embed type="application/x-motorola-toi-dlna" hidden="true" /> to
your index and start using it :)
Dump from working Arcadyan_HMB2260 with possible key in debug
Same (middleware) software. It's based on Broadcom Nexus.
Ow, it runs a upnp server on some port beyond 40000
If you want the menu (html with javascript, plain, not encrypted), let
me know. It seems more hackable.
########## Break by Mac
// Whoops? Is this a hex to asci screwed up version of the key? Or is
the encrypted key in plain ascii form? Any thoughts?
########## End Break
########## Break by Mac
// Is this a hex to asci screwed up version of the signature? Or is the
encrypted signature in plain ascii form? Any thoughts?
########## End break by Mac
Arcadyan is a total other platform, don't think it uses kreatv. The
Arris is more the same because it uses the kreatv firmware even when it
is an other hardware platform. Be carefull putting an old 1963 on an
active KPN line, it might get the new firmware.
Hello, is it possible to get image for Arris VIP1003 in which remote
works. I have tried few of these and they work but remote does not
function? I have a lot of these devices and would like to use them in my
iptv if i can find correct image for them. You can contact me on email
info[at]meganet[dot]ba.
I already downloaded SDK, compile it successfully. Im not so familiar
with all this things, and im stuck in how to make .bin file? If you can
help me with this it would be really good. Thank you in advance.
Hi Martin,
I have Set-top box motorola vip1003(Sonera).
Set-top box flashing on tftp absolutely normal, but after flashing -
error 4, after reboot Set-top box - error 3....
I understand the problem is bootkast id?
@Martin
Regarding your question about 19x3 and JTAG. I was able to connect to
1963 and dump full 32MB NOR, and even write it back to STB and it's
still alive.
BL version is 2.xx (I'm not sure which one).
I can send you the dump if you want it.
Can you please send me the EMEA SDK kit which keeps disappearing from
the internet? My mail is reg.blagus[gmail]
I used FTDI's FT2232HQ Mini Module (FT4232H is fine too) and official
STMC toolset.
You also need STburner which you have to modify so it can recognize
1963's NOR. I had that copy of STburner somewhere, compiled for 1963,
I'll try to find it and send it to you, together with 2.xx bootloader
dump I made.
As far as I can remember, NOR also contains some default configuration,
XML files, MAC and serial and there might be some keys (in XML files),
but I'm not sure.
That's the least thing I can do as a thanks for your mail.
Hi Mac,
I think you mean for:
1 = BootCast
2 = TFTP
3 = Local Storage (if available)
4 = SAP (Session Announcement Protocol)
5 = DVD/CD (if available)
6 = HTTP (available from version 3.03)
I used as 323 kernel/slash
Hi all,
Kernel setup:
1.run logclient.exe 192.168.2.200
2.run putty -telnet 192.168.2.200
3.vi /usr/applications/ekioh/ekioh.cfg
4.add line application.homepage:http://192.168.2.131
5.killall ekioh
that is right order.
Hi Claude,
not really what I meant. I meant which DHCP option since our boxes have
a new bootloader which cannot be programmed by hand. I saw that Martin
had this in his debug:
00:00:08 01.01.2000 src/dhcp.c 276 DBG > Kernel Protocol Order:
00:00:08 01.01.2000 src/dhcp.c 280 DBG > 2
So I assume he knows what DHCP option that is.
Hi Mac,
That be nice have new bootloader im using old version but loading.
kreatv-bi-eval_4.3.IAP30.3_st40_vip19x3.bin(new)FW
kreatv-bi-vdr.config_4.3.IAP30.3_st40_vip19x3.bin(old)FW
It old bootloader has public key hide.
I have little problem with New-FW ekioh settings dont stay after reboot
setting are cone.
Tryed "toish is SetObject config.ekioh.application.homepageurl
http://192.168.2.131/index.html permanent" but is dont read them.
Puted /flash/securestroage is flash parition as NAND.
Now i need put script but init dont have them.
old version that toish command worked fine so. i stay new one or old one
heh.
Old bootloader working
5 green balls meaning while loading FW
1.1 ball loading FW TFTP/bootloader/http
1.1 small ball loading FW
2.1ball extract FW to flash
2.2 small ball flashing FW
3 ball check is FW unic to keys
4 ball load FW to RAM
5 ball run FW
Wrong version FW crash in 3 ball sector
Does anyone have a dump of a KPN branded box with the new bootloader?
I'd like to figure out if we can get custom code running.
Alternatively, any VIP19xx/18xx dump would be welcome, I currently have
none.
I'm also still looking for the SDK.
Email is username AT gmx com
Thanks!
/#toish
Usage: toish [<component>|<component alias>] <operation> [arguments...]
Environment variables used:
NAMESERVICE_ADDRESS The address of the name service, this has
precedence
NS_ADDRESS_FILENAME A file from which the name service address can be
read
Defaults to /tmp/nameservice_address
Available components and operations:
applicationservice, as:
Activate <application id>
Activate application <application id>
ActivateWithUri <application id> <uri> <mime type>
Activate application and load uri with it
RegisterApplication <property file path>
Register new application
Kill <application id>
Kill application <application id>
LoadUri <uri> [MIME type] [whitelist]
Load the URI <uri>; the MIME type is guessed if not specified
If "whitelist" is appended, the uri is added
to the portal whitelist (as volatile)
Info
Get info on registered applications
informationservice, is:
GetObject <object name> | all
Returns object value ("all" is for all objects)
GetObjectNames [<adapter> | all]
Returns the names of all objects provided by <adapter> or by all
adapters (default) in alphabetical order.
SetObject <object name> <value> [volatile | permanent]
Set the object, default storage type is volatile
SetObjectFromFile <object name> <file> [volatile | permanent]
Set the object, default storage type is volatile
UnsetObject <object name> [volatile | permanent]
Remove object, default storage type is volatile
platformservice, platform, ps:
RebootNow
Perform a controlled reboot, with components being shut down
properly.
RebootAtNextStandby
Reboot the platform the next time the system goes to standby state.
SetStandbyMode [ true | false | 0 | 1 ]
Deprecated. Same as SetStandby.
SetStandby [ true | false | 0 | 1 ]
Enter or leave standby.
True corresponds to standby, while false corresponds to normal
operation.
uriloaderservice, uriloader, uri:
LoadUri <uri> [MIME type]
Deprecated; use "applicationservice LoadUri" instead
videooutputservice, videooutput, vos:
SetDefaultVideoMode [ HD | SD ] [ disable | 480i | 576i | 576p | 720p
| 1080p |
1080i ]
Sets the default video mode for an output, i.e. the video mode to
use if no
adaptive rules have been set.
SetVideoSafeMode
Sets the video outputs in safe mode configuration.
SetScartMode [CVBS | YC | RGB]
Sets scart output mode.
Found command that reboot remember settings with
toish is setobject cfg.portal.whitelisturls "
<PortalURLs>
<PortalURL>http://192.168.2.131</PortalURL>
<PortalURL>http://192.168.2.131/index.html</PortalURL>
</PortalURLs>
" permanent
Now all working great.
log1.log has old loader log-file reboot to startup
Thanks for all!
Hi Martin,
thanxx for the dhcp options! You also included the numbers so I could
put them directly in dnsmasq. The reason that your (or any, even
official) old FW isn't working anymore is because the new bootloader
expects a new encryption. KAC1 (According to the header)
Here are the instructions on using JTAG to dump/write NOR flash on
VIP1963.
You need:
FT2232HQ or FT4232HQ mini module (or another 2232/4232 breakout board).
Wire and setup everything according to the instructions in this PDF:
http://www.avi-plus.com/repair-tips-forum/miscellaneous-software/others/st40-stb71xx-jtag-interfacing/page-2.html#658
(post #658)
(On Windows, grab official FTDI drivers and add modified VID/PID. Linux
will do the magic itself.)
Install latest ST40 Tools and STMC2 from here:
http://ftp.stlinux.com/pub/tools/products/
If you're on Windows 8/10, set compatibility options to Win7+Run as
Admin.
If you're on Linux, you'll also need to add tools dir and libs to PATH
and do some magic regarding the targetpacks location - I can't remember
what exactly, so I'll come back to it in a later post - but error
messages will lead you in the right direction.
Download this:
http://www.mediafire.com/download/gz430oxs3fah6q8/STBurner_vip1963.7z
Inside you'll find 4mib.bin - first 4MiB dump of my Motorola VIP-1963.
I have to play more with block sizes and add some debug output to make
it read all 32MiB instead of looping on first 4, but the essential part
- RedBoot and Linux image - are there.
Serial and MAC is spoofed. If you're brave enough, edit them to match
your STB and try writing it - worst case scenario is that you'll end up
with non-bootable STB until you (or me) figure out actual block size
values for STBurner which will read/write the dump correctly.
Executable is flasher.out, which is sent to the device with sh4xrun
utility. Targetpack for 1963 is mb448 (I used non-"se", 29-bit version).
Example commands are in run.bat file. Linux and Windows syntax is the
same.
-r option is for reading,
-p option is for writing.
I bought a KPN VIP 1960 from a thrift shop here in holland. It looks
absolutely unused and has even older firmware than the unit Martin V.
opened this thread with.
RBL 1.7, Firmware 2.20
The kernel is compiled a few months earlier than Martin V.'s 1960 unit.
I was expecting no problem booting from his images. However I get this
error message:
1
Using Bootcast
2
BC: Info download attempt 1 of 90
3
Loading control file motorola-vip1960-9-256 from 224.2.2.18:22222
4
BC: Image download attempt 1 of 90
5
Kernel name: kernel-1960
6
Kernel address: 224.2.2.18:22222
7
Unable to read from file /tmp/bootimage_version: error 22
8
Verifying image...
9
secman: Data verification failed on /tmp/bootimage.gz.sec!
10
11
Using Local Storage
12
LS: No valid kernel image available.
13
Reboot.
14
Disabling FDMA
15
Shuting down STMMAC TX and RX DMA
I tried every image I could find, including the evaluation images from
motorola. Same error message every time! Any help is appreciated!
I was finally able to install the images by switching from bootcast to
tftp.
Absolutely no idea why the bootcast download did not work. It worked
fine to install the splash image, so the server was set-up correctly as
far I know.
I lost some time figuring out how to specify the filename for the tftp
download, as my box did not use the name specified in the advanced
settings menu. It did for the splash filename, but not for the
bootimage. You need to specify the name in dhcp option 67.
May be it only uses the data from the advanced menu with static ip. I
did not test that (yet).
Hi everybody I am new here and I am looking for 4shared files that had
been removed
So does anyone still have:
kreatv-doc-sdk-user-manual_4.3.IAP30.3.tgz and
kreatv-extra-iip-package-ericsson_mu_4.3.IAP30.3.tgz
Thanks for Anwsering and Best Regards
PS: I is there any difrence between Starter Kit and SDK if someone can
send me SDK (beacuse I only have starter kit so far) it would be great
Thanks for Anwsering and Best Regards
Hi sab
Sorry belate message, but im using version 1903 version.
Ohter version i don't know how they working is take some time lookout,
how they working.
Is there software(OS) or bios(FW) replaisment ?
Bios need open box and use UART(3-4pins) and use Console(COM1).
Software can replaise with right version each boxes as unic security
key.
So wrong version don't boot but finding right verison need ask ohter
people find same version with right Software(OS).
Look luck finding
-----------------------------------------------------------------------
Source codes can build with VIP19X0/VIP19X3/VIP1003/VIP1853 set-tops
http://sourceforge.net/projects/vip19x0.arris/files/ST40/KreaTV%204.6%20-%204.9/
1.Download file
2.Config settings right version. (./configure)
2.2 read more information inside README file with notepad
3.Build it(make)
4.Then is ready right version with security code and OS.
Uploaded with how build with OS with security key script.
http://www.multiupfile.com/f/acb9316e
Found inside kreatv-kit-oss_4.4-st40.tar
Key finding is diffrent story how find it.
but that good find Blagus B dump 4mb(NAND) they meybe has right security
key.
Claude
Software engineering
ok i meybe find it.
---------------------------------------------------------
check_3pp_license(file has information how build it)
----------------------------------------------------
file=3PPLICENSE
elif [ -f $FILENAME ]; then
sha1=$(sha1sum $FILENAME | cut -f 1 -d ' ')
---------------------------------------------------------
3PPLICENSE(key code)
----------------------------------------------------
NAME=STLinux
VERSION=stm23_A27
LICENSE=GPLv2
TARGET=vip19x[03]
FILENAME=stlinux23-STAPI-kernel-sh4-2.6.23.17_stm23_A27-123.noarch.rpm
SHA1=d81112551394a0b0e19e69d0ecea0eab48d14d1f
END_HEADER
END_ATTRIBUTION
------------------------------------------------------------
GPLv2(key)[18kb]
--------------------------------------------
GNU GENERAL PUBLIC LICENSE
etc.
etc.
etc.
use the GNU Lesser General
Public License instead of this License.
----------------------------------------------
So GPLv2 need encode with OS header then is working right.
http://www.gnu.org/licenses/old-licenses/gpl-2.0.html#SEC1
there has too that GPLv2(key)(file)
claude
Nope, it doesn't have telnet enabled. I've spend few days looking for
some solutions, but seems only jtag is solution, if I found correct
pin-out and then somehow unpack firmware. I know that update firmware is
encrypted, but don't know is flash encrypted. Basically, I just want
newer version of webkit browser from image. The image mentioned above
has 536 version, but this one from starter kit is 532, which is way too
old.
Igor you have to use script from:
Beitrag "Re: Pollin MOTOROLA VIP1710"
but you need key for VIP1003 and you will need find right start position
to decrypt from. After decryption you use binwalk to check result. If
binwalk find something, use parameter -e to extract it.
Good luck
Hi there, I have VIP1853 but not remote control. Please give me solution
to enter in secret menu and delete original firmware. I use sound files
to set my Samsung TV (and unlock hidden menu). May sombody digitalize
menu, digits arrows, OK and Exit (I think that's enough) to use with
smartphone and 2 infrared leds
Hey all,
A Little help here please (hope this topic isn't closed).
I'm working with a Motorola VIP 1903. I want to make a client to
tvheadend witch may be possible. BUT first things first. The bootload
image(s). I'm was not able to get bootcast server to work. So I went
ahead and tried the tftp boot.
My tftp bootserver (and webserver, dhcp server) is on a synology ds
1815+ NAS server which can do tftp and pxe boot. PXE boot works fine on
pc boots. So I thought I just put bootimage in tftp root and pointed
boot file to the .bin boot file downloaded from this site. Then I set
the boot protocol on Motorola box to 313 (Local, tftp, local).
Tried with these:
kreatv-bi-eval_4.3.IAP30.3_st40_vip19x3.bin
kreatv-bi-test.config_4.3.IAP30.3_st40_vip19x3.bin
kreatv-bi-vdr.config_4.3.IAP30.3_st40_vip19x3.bin
No luck.
Then I thought of giving the box it's own static ip. No luck
Then I tried booting from webserver (.bin file in root folder) With
static or dynamic ip (and bootprotocol set to 363). Still no luck
I think there is some kind of information that I have missed. When setop
box is booting the first two balls goes green. By the third ball there
comes this error message: An error occur updating the software.......
Question is what didn't I do right? I hope someone can help me. This
project could really turn into something big.
Hello Martin et al,
With the expertise about Vip19x0 found in this thread, I hope this is a
good place to ask this question:
I have a Motorola VIP1920-9C Conax/ComHem box, so it seems locked to
only be used with ComHem, but I wonder if there is any way to use its
onboard DVB-C to view the free, non-ComHem cable channels available
where I live now?
From reading this thread, my guess is that the answer is that this box
is totally locked down and that there is no known way around this, but I
thought I'd ask anyway. Maybe things have changed in the last year or
so?
Anyway - great thread! Take care, everybody!
Hi, I've also a Comhem cable box with remote (and even keyboard I think)
Worked fine on Dutch Cable with Comhem software for FTA channels, untill
I started to try and replace the software which didn't work because of
missing keys.
Greetz
My box successfully boots
kreatv-bi-test.config_4.3.IAP30.3_st40_vip19x3.bin (and
kreatv-bi-vdr.config_4.3.IAP30.3_st40_vip19x3.bin) from above. Which AES
key I can use to decrypt those images with decrypt.c
(Beitrag "Re: Pollin MOTOROLA VIP1710")?
Can I use the same key to decrypt the original firmware of my box?
I found kreatv-kit-starter-kit-emea_4.3.IAP30.3.zip, but the keys are in
"KreaTV format" with SEC header and I understand that the keys
themselves are encrypted. At least using last 32 bytes of the 41-byte
file as an AES key did not work.
Since I can boot kreatv-bi-test.config_4.3.IAP30.3_st40_vip19x3.bin, I
can of course telnet to the box and read the flash, but I don't know how
to interpret the comment in decrypt.c: "Seems to come from section at
0x1cf700 in NOR. More work needs to be done to figure out how it is
decrypted."
I tried to use 32 bytes from position 0x1cf700 of the NOR flash as the
key, but that did not work. Then I checked all sections starting with
"SEC", but none of them looked like an AES key. The comment in decrypt.c
seems to imply that the key itself is encrypted. Yet
http://www.duff.dk/zaptor/ writes that "the key for decryption is piece
of cake to extract"???
Thanks for any hints!
I want to access Firmware setting menu for Arris VIP4302 STB. But I
don't know the four digit code to access the advance menu. I am trying
7532 but it does not work. So, it might not be for this model. Does any
one now this code? Thanks