3 pagesV  1 2 3 > » 

Skvo
26.05.16, 13:37
Local
*****
[offline]

Group: Friendssavagemessiahzine.com
Messages 135
Check in: 26.08.07

Reputation:-  59    +

DiscussionNetgear AirCard AC785 (S), AC790 (S), AC810 (S)




��������� LTE ������� Netgear AirCard download




Characteristics of the last three models of routers Netgear
For Russia, relevant European versions of routers (not locked). For them in the numbering of any letters at the end of the model number is not put.
Netgear AirCard AC785 Mobile Hotspot
URL to the European site Netgear
Router on Qualcomm MDM9225, LTE cat.4 chipset, no aggregation, speed up to 150Mbps
SKU code indicated on the box for a single European model: AC785-100EUS
Supported frequencies:
LTE FDD: B1, B3, B7, B8, B20
LTE TDD: B38
3G: 850/900/2100 MHz
2G: 900/1800 MHz

Battery for AC875: NETGEAR W-3
Capacity: 2000 mAh (3.7V, 7.4Wh)

Netgear aircardAC790Mobile Hotspot
URL to the European site Netgear
Router on Qualcomm MDM9230, LTE cat.6 chipset, two lanes aggregation, speed up to 300Mbps
The SKU code shown on the box for a single European model: AC790-100EUS
Supported frequencies:
LTE FDD: B1, B3, B7, B8, B20
LTE TDD: B38, B40
LTE CA: B3 + B20, B3 + B7, B7 + B20, B3 + B3, B7 + B7, B38 + B38
3G: 850/900/1900/2100
2G: not supported

Battery for AC790: NETGEAR W-7
Capacity: 2930 mAh (3.8V, 11.8Wh)

Netgear AirCard AC810 Mobile Hotspot
URL to the European site Netgear
The router on the Qualcomm MDM9240 chipset,
SKU code shown on the box for a single European model: AC810-100EUS
On the box with the router indicated - LTE cat.9, aggregation of three lanes, speed up to 450 Mbit / s
The site and datasheet indicate - LTE cat.11, aggregation of three lanes, speed up to 600Mbps
Supported frequencies:
LTE FDD: B1, B3, B7, B8, B20
LTE TDD: B38, B40, B41
LTE 2CA: B1 + B8, B1 + B20, B3 + B3, B3 + B7, B7 + B7, B3 + B8, B3 + B20, B3 + B38, B20 + B20, B38 + B38, B41 + B41
LTE 3CA: B3 + B3 + B7, B3 + B3 + B20, B3 + B7 + B7, B3 + B7 + B20, B40 + B40 + B40, B41 + B41 + B41
3G: 850/900/1900/2100
2G: not supported

Battery for AC810: NETGEAR W-7
Capacity: 2930 mAh (3.8V, 11.8Wh)


Operator versions of routers come with a letterSat the end of the model number:
Different LTE ranges for a particular operator, and usually go locked under it.
For example:
Netgear AirCard AC810S for the Australian operator Telstra
The router on the Qualcomm MDM9240 chipset, LTE cat.11, aggregation of three lanes, speed up to 600Mbps
http: //www.netgear.com...d/hotspots/AC810S.aspx
SKU code: AC810S-1TLAUS
LTE FDD: B1, B3, B7, B8, B28 (Australian frequencies, our B20 is not. Because of this, there is not much use in Russia)
LTE TDD: not supported (our B38 is not)
LTE 2CA: B3 + B28, B3 + B7, B7 + B28, B7 + B7
LTE 3CA: B28 + B3 + B7, B3 + B7 + B7, B28 + B7 + B7
3G: 850/900/1900/2100
2G: not supported

Netgear AirCard AC810S for Polish Play operator
Router on Qualcomm MDM9240, LTE cat.9 chipset, aggregation of three lanes, speed up to 450 Mbit / s
http://www.play.pl/tel…netgear-router-ac810s/
SKU code: AC810S-1P1PLS
LTE FDD: B1, B3, B7, B8, B20
LTE TDD: B38, B40, B41
LTE 2CA: B1 + B8, B1 + B20, B3 + B3, B3 + B7, B7 + B7, B3 + B8, B3 + B20, B3 + B38, B20 + B20, B38 + B38, B41 + B41
LTE 3CA: B3 + B3 + B7, B3 + B3 + B20, B3 + B7 + B7, B3 + B7 + B20, B40 + B40 + B40, B41 + B41 + B41
3G: 850/900/1900/2100
2G: not supported

The router is not locked to the Play operator. Any sim cards work.
In terms of frequencies and characteristics, the Polish router AC810S-1P1PLS is completely analogous to the European version AC810-100EUS.


Netgear AirCard AC810S for the American operator Sprint
The router on the Qualcomm MDM9640 chipset, LTE cat.9, aggregation of three lanes, speed up to 450 Mbps
CDMA / RTT / Ev-Do router
SKU code: AC810S-1SNNAS
LTE FDD: B2, B4, B5, B12, B25, B26
LTE TDD: B41
CDMA / Ev-Do: 800, 850, 1900
3G: Band II, IV, V
2G: not supported

Netgear AirCard AC815S for US AT & T operator
The router on the Qualcomm MDM9240 chipset, LTE cat.9, aggregation of three (two ???) lanes, speed up to 450 Mbit / s
- dust and moisture protected housing (IP65)
- high-capacity battery 4340 mAh
http: //www.netgear.com…/AC815S.aspx? cid = gwmng
SKU code: AC815S-1A1NAS
LTE FDD: B2, B4, B5, B7, B12, B30
LTE TDD: not supported
LTE CA: ???
3G: Band II, V
2G: 850, 1900



Useful information on Netgear routers

Access to the AT port of the router
Four ways:

1. Through the regular driver (works on any AC78X, AC79X, AC81X)
- Download port driverAC78xSDrivers.exefrom netgear site.

- install the driver, after which three COMxx virtual ports will appear in the system:
NETGEAR WWAN Modem VSP
NETGEAR DM Port VSP
NETGEAR NMEA Port VSP

- connect the router with a USB cable to the computer.

- knock on the virtual port "NETGEAR WWAN Modem VSP" terminalkoy.

2. Access directly to the port without installing the driver, via USB-cord through the network interface RNDIS

In Netgear routers - AT, the port is also active inAT port over TCP. For use:

- connect the router with a USB cable to the computer.

- Use for example Putty or any other terminal and select in the settings
HostName:192.168.1.1
Port:5510
ConnectionType:Telnet

3. Access directly to the port via Wi-Fi connection
By default, access to port 5510 via Wi-Fi is blocked. To bypass, you need to change the port number to another value.

You can connect via Wi-Fi by analogy with the example above:
HostName:192.168.1.1
Port:XXXX (which you put in the config)
ConnectionType:Telnet

Details on changing the port fromsandwern:
Netgear AirCard AC785 (S), AC790 (S), AC810 (S) - Discussion (Post sandwern # 52346558)


Attention!
Standard password from Sierra "A710" - does not fit Netgear routers for unlocking extended AT commands

Netgear uses its modified passwords. And for different models - passwords are also different.

For aircardAC810-100EUSblocking from extended AT commands is removed throughAT! ENTERCND = "whistler"
For aircardAC810S-1P1PLSblocking from extended AT commands is removed throughAT! ENTERCND = "seymour"
For aircardAC810S-1TLAUSblocking from extended AT commands is removed throughAT! ENTERCND = "grouse"
For aircardAC810S-1RDQASblocking from extended AT commands is removed throughAT! ENTERCND = "cypress"
For aircardAC790-100EUSblocking from extended AT commands is removed throughAT! ENTERCND = "lavender"


For other Aircard ACxxx - passwords are not yet known. But if you want, you can always try to find out from the router itself ...
It is enough to remove the dump sections of the flash drive and pull it out from there ...


Access to the diagnostic port of the router (for QPST, QXDM, etc.)
Two options:

1. Through the regular driver from Netgear

- Download port driverAC78xSDrivers.exefrom netgear site.

- install the driver, after which three COMxx virtual ports will appear in the system:
NETGEAR WWAN Modem VSP
NETGEAR DM Port VSP
NETGEAR NMEA Port VSP

- connect the router with a USB cable to the computer.

- Install QPST, and in the settings select the port "NETGEAR DM Port VSP"
QPST 2.7.437 you can takehereor 2.7.441here


2. Access directly to the port without installing the driver

In the AC810 router - the diagnostic port is also active in theDM port over TCP
Default values:
HostName:192.168.1.1
Port:5511

For use with QPST, we add these values ​​in IP: PORT format on the Ports tab.>Add New Port>Outgoing IP Connections.
By default, access to port 5511 is open only when the router is connected to the computer via a USB cable.
If you want to get work with the Dianhous port via Wi-Fi, then you need to change the port number to another value.

Details on changing the diagnostic port fromsandwern:
Netgear AirCard AC785 (S), AC790 (S), AC810 (S) - Discussion (Post sandwern # 52578326)


Determination of carrier parameters when working in the aggregation mode (Carrier Aggregation)
Actual for AC790 and AC810.

Parameters of carriers that are participating in the aggregation mode (Carrier Aggregation) are not visible in the web interface of the router. It displays data only on the main carrier. You can find out the parameters of all carriers only with the help of AT commands.

To see them you need:
1. Start the download and wait for the LTE-A icon to appear on the router's display.
2. send the command AT! GSTATUS?

The response in the "PCC:" section will be the parameters of the main carrier. In the sections "SCC1:" and "SCC2:" for additional.

example from Sandwern. Aggregation B7 (20Mhz) + B7 (20Mhz):
AT! GSTATUS?
! GSTATUS:
Current Time: 254 Mode: ONLINE
System mode: LTE PS state: Attached
EMM state: Registered Normal Service
RRC state: RRC Connected
IMS reg state: No Srv

PCC:
LTE band: B7
LTE bw: 20 MHz
LTE Rx chan: 2850
LTE Tx chan: 20850
RSSI (dBm): -73.5
RSRP (dBm): -101.5
RSRQ (dB): -7.2
RSSNR (dB): 19
Tx Power (dBm): 11.0
LTE Cell ID: 253717762
Physical Cell ID: 29
TAC: 9987

SCC1:
LTE band: B7
LTE bw: 20 MHz
LTE Rx chan: 3048
RSSI (dBm): -78.3
RSRP (dBm): -97.1
RSRQ (dB): -9.7
Physical Cell ID: 29

Ok


Configure user profiles for AT! BAND


Post has been editedSkvo - 25.03.17, 00:25
Forum:Netgear· View message:#49914832· Replies:2012· Views:223688

Skvo
11.02.17, 03:06
Local
*****
[offline]

Group: Friendssavagemessiahzine.com
Messages 135
Check in: 26.08.07

Reputation:-  59  +

It is necessary, probably, to make a tablet somewhere in the cap with all these birds, herbs and trees — passwords for various modifications of the various devices discussed.

Passwords picked up the cap ...

By the way.
Whistler- Mountain peak just above Vancouver, in Canada.
https://www.google.com/…0591666!4d-122.9569444

Grouse- also a mountain town near Vancouver
https://www.google.com/…3722894!4d-123.0994869

Cypress- another mountain town near Vancouver
https://www.google.com/…9.396018!4d-123.204545

Lavender- also connected with mountains, and also near Vancouver
https://www.google.com/…7543404!4d-123.4617879


P.S. What's interesting: Sierra Wireless is also from Canada. Their main office and Mobile Device Development Center are just in Vancouver ....

Post has been editedSkvo - 11.02.17, 03:14
Forum:Netgear· View message:#58217199· Replies:2012· Views:223688

Skvo
28.08.16, 10:52
Local
*****
[offline]

Group: Friendssavagemessiahzine.com
Messages 135
Check in: 26.08.07

Reputation:-  59  +

Vvevvevve @ 08/28/2016, 01:05*
And that scheme with the "firmware" of the modified nvu-file to enable ADBENABLE will not work here?

It needs to be tested.
Moreover, it is noted that nvu differ from different systems in structure and parameters, so many experiments may be required ...
Let's leave it for the most recent case if other options do not help ...

Or maybe the code calculation algorithm for privilege escalation that worked on MC7710 or MC7304, MC / EM7305 will work here?

For sure! First you need to check ...
And here Windows is not needed, from under OS X you can protest ...

vitaly_dvIn QMS, have a look, you have to cross and test the AT! OPENLOCK algorithm ...

Or maybe in some package with the original firmware is the image of EFS?

On the Netgear website, the firmware has two in common:
For European AC785-100EUS:
http: //www.downloads.n...2.08.00.51.00_EMEA.exe
And for the Australian AC785S-1TLAUS:
http: //www.downloads.n...elstra_02.08.00.17.exe

Both are gutted, but EFS is not visible in clear view. Maybe he is there, but something is packed ...

Post has been editedSkvo - 05.10.16, 10:59
Forum:Netgear· View message:#52580202· Replies:2012· Views:223688

Skvo
28.06.16, 22:10
Local
*****
[offline]

Group: Friendssavagemessiahzine.com
Messages 135
Check in: 26.08.07

Reputation:-  59  +

Sandwern @ 06/28/2016, 6:22 PM*
That's what happens ...:

at! entercnd = "whistler"
Ok

It worked. It's good.

It will be interesting to check this password on the AirCard 785 and 790. Is this the same or other passwords?
But for this we will wait in the topic of owners of such routers ...

Sandwern @ 06/28/2016, 6:22 PM*
at! custom =?
ERROR

But this is unexpected.
The first time is. See right to cut. Privilege! Entercnd is no longer enough to change the parameters! Custom ...
We will go around in other ways ..

.
Sandwern @ 06/28/2016, 6:22 PM*
AT! BAND =?
Index, Name, GW Band Mask L Band Mask
00, All Bands, 0002000004C00000 000001A0000800C5
01, Europe 3G, 0002000000400000 0000000000000000
02, North America 3G, 0000000004800000 0000000000000000
03, Europe, 0002000000400000 000000A0000800C4
04, North America, 0000000004800000 0000010000000040
05, WCDMA ALL, 0002000004C00000 0000000000000000
06, LTE ALL, 0000000000000000 000001A0000800C5

0000010000000000 - B41
0000008000000000 - B40
0000002000000000 - B38
0000000000080000 - B20
0000000000000080 - B8
0000000000000040 - B7
0000000000000004 - B3
0000000000000001 - B1
0002000000000000 - B8 (900)
0000000004000000 - B5 (850)
0000000000800000 - B2 (1900)
0000000000400000 - B1 (2100)

Ok

Here you can experience.

Configure user profiles for! Band:

(Add separate ranges):
at! entercnd = "whistler"
AT! BAND =0A7, "Band 7", 0.40
AT! BAND =0B8, "Band 20", 0.80000
AT! BAND =0D9, "Band 38", 0.20 million

Masks can be folded, for example.
AT! BAND = 5, "B3 + B7", 0.44

These profiles are stored in the router.

You can use both standard and custom profiles for selection. For example:
AT! BAND = 0 - automatic selection from any ranges
AT! BAND = 6 - automatic selection only from LTE bands
AT! BAND = 7 - only LTE Band 7
AT! BAND = 9 - only LTE Band 38
etc.

Supplement fromvitaly_dv!

Thank! Made as described, works. Team AT! BAND =<index>range is selected, but, a small addition:
the indexes seem to be consistent,

other details here:
Netgear AirCard AC785 (S), AC790 (S), AC810 (S) - Discussion (Post vitaly_dv # 52546661)

Post has been editedSkvo - 05.10.16, 00:01
Forum:Netgear· View message:#50785404· Replies:2012· Views:223688

Skvo
03.10.16, 18:54
Local
*****
[offline]

Group: Friendssavagemessiahzine.com
Messages 135
Check in: 26.08.07

Reputation:-  59  +

Sandwern @ 10/03/2016, 17:01*
There it turns out * 105 * 9 #. A source.
The answer does not come either. OK and everything ...

Switch coding does not immediately work ...
Do not immediately wait for an answer to * 105 * 9 #.


Here's the next command in the USSD, the UCS2 answers should already go.
Now they were * 100 # encoded in UCS2 and see the result ...

Post has been editedSkvo - 03.10.16, 18:55
Forum:Netgear· View message:#53735585· Replies:2012· Views:223688

Skvo
03.10.16, 16:21
Local
*****
[offline]

Group: Friendssavagemessiahzine.com
Messages 135
Check in: 26.08.07

Reputation:-  59  +

Sandwern @ 10/03/2016, 15:34*
He says the following:
at + cscs =?
+ CSCS: ("IRA", "GSM", "UCS2")
Ok

Everything is bad here!
There is nothing useful for working with the "GSM 8-bit data" encoding that Megafon uses.


As a result, if you really need a USSD for Megaphone, then everything comes back to use UCS2 ...
- we translate the router to at + cscs = "UCS2"
- network, please send messages in Cyrillic: * 105 * 1 #
- at + cusd requests are sent to UCS2
- manually translate answers from UCS2 into a visual form ...

By the way, here’s a convenient online calculator for decrypting text from GSM 7-bit, GSM 8-bit data, UCS2. Suitable for both SMS and USSD:
http://smspdu.benjaminerhart.com/

Post has been editedSkvo - 03.10.16, 16:22
Forum:Netgear· View message:#53730519· Replies:2012· Views:223688

Skvo
03.10.16, 13:33
Local
*****
[offline]

Group: Friendssavagemessiahzine.com
Messages 135
Check in: 26.08.07

Reputation:-  59  +

Sandwern @ 10/02/2016, 11:57*
Understood, now everything turned out. At MegaFon-Moscow, you can change the encoding with the command * 105 * 0 #:

at + cscs = "UCS2"
Ok

at + cusd = 1, "002A003100300035002A00300023", 15
Ok

+ CUSD: 0, "0055007300740061006E006F0076006C0065006E006100200070006F00640064006500
72007A0068006B006100200070006F006C0075006300680065006E00690079006100200055005300
530044002000760020007400720061006E0073006C006900740065 ", 15

Here is a good example for you.
Bring backat + cscs = "GSM"

And further to the requestat + cusd = 1, "* 105 * 0 #", 15you must receive the answer in symbolic form
These words"Ustanovlena podderzhka polucheniya USSD v translite"- you must see in the answer in a visual form.

Check it again.
The answer fits into the GSM 7-bit encoding - everything should be displayed in symbolic form ...


Sandwern @ 10/02/2016, 11:57*
If we talk about sad things, then at the command at + cusd = 1, "002A0031003000300023", 15 as there was no answer, no, OK is displayed and that's it, although the balance comes to the phone immediately after switching with translit.

The megaphone curve transliteration engine ...

In order for the USSD response to have symbolic information, it must be encoded in the "GSM 7-bit" encoding.

But with Megaphone, transliteration does not always fit into this encoding.
Conversion from Cyrillic to Latin is strictly according to GOST with the active use of the symbol `(reverse apostrophe).
For example, "Promised" is translated in "Obeshhanny`j".

But! The coding "GSM 7-bit" doesn’t have the symbol `(reverse apostrophe), therefore for sending text the coding is used in the format" GSM 8-bit data ", which needs to be further decoded, as well as additional decoding of the messages sent "UCS2".


Eventually:
If the characters fit into the range of the coding "GSM 7-bit" - then you will see the symbolic answer ...
If you use the "GSM 8-bit data" encoding (which is the majority of answers in Megafon's Latin mode), then you will not see anything, you need additional unpacking.
In the "UCS2" mode - just as well, the modem itself will not show you anything in the character mode, you need to decode the messages ..


By the way, what does the router say to at + cscs =?

Post has been editedSkvo - 03.10.16, 15:36
Forum:Netgear· View message:#53725221· Replies:2012· Views:223688

Skvo
03.10.16, 14:29
Local
*****
[offline]

Group: Friendssavagemessiahzine.com
Messages 135
Check in: 26.08.07

Reputation:-  59  +

Vvevvevve @ 10/03/2016, 14:15*
If this GOST is meant, then all messages that do not contain letters, e, hard and soft signs should be placed with the "GSM 7-bit" table and normally displayed in the terminal. So?

Right.
Megaphone GOST 7.79-2000, transliteration according to system B.

Translite in the "GSM 7-bit" interfere with just the letters about which you mentioned: s, uh, hard and soft sign. Also, except for letters, and some signs also do not fit into the "GSM 7-bit". Right now, I don’t remember which, but such Megaphone came across in transliteration in balance ...

If the answer does not have these letters and curved characters, then it is encoded immediately into a normal "GSM 7-bit". And we should see a symbolic response.

As a result, the request * 100 # will not always be empty. It all depends on the advertising added to the balance. Sometimes the answer will be symbolic ... Although it is rather an exception ...


P.S.
In some regions, MegaFon transliteration is better. They spit on the exact compliance with GOST, and get all the characters in the "GSM 7-bit". So, by the way, the MTS comes to transliteration ...

Post has been editedSkvo - 03.10.16, 15:24
Forum:Netgear· View message:#53726868· Replies:2012· Views:223688

Skvo
24.09.16, 15:50
Local
*****
[offline]

Group: Friendssavagemessiahzine.com
Messages 135
Check in: 26.08.07

Reputation:-  59  +

You would write a specific instruction to get a dump of the CUST section, for example. Described the procedure completely, from the very beginning.

I'll try. If where is inaccuracy - correct ...

Instructions for obtaining a password to! ENTERCND for AC785 router

1. On AC810 router - there was access to ADB by default, and through it we took a dump of the CUST section.
On the AC785 router, judging by the reviews in this topic, the ADB port is inactive, so the version by analogy with AC810 will not work, we do not have access to the Linux console ...

Let's go the other way. I suggest to take a dump through Qtools.


2. Connect to the AT port. As the cap says:
- connect the router with a USB cable to the computer.
- Use for example Putty or any other terminal and select in the settings
HostName: 192.168.1.1
Port: 5510
ConnectionType: Telnet


3. Execute AT commands:
To know which version of the router and firmware we are dealing with:
ATI
AT! PACKAGE?

We look at the flush model, and the number of bad blocks on it. (model is useful below)
AT! FMBADBLOCKS?

We look at the partition table on the flash drive (not sure what will work on the AC785, but suddenly?)
AT! PARTINFO?

Switch to Download mode:
AT! BOOTHOLD


4. According to the last AT! BOOTHOLD command - the router will switch the song to USB \ VID_0846 & PID_68E0
An unknown device appears on which to roll the driver.
Downloading from here (the link is the same as in the header):http: //www.downloads.n...stra/AC78xSDrivers.exe

After installing the driver should appear "NETGEAR QDLoader Port".
This is the Download mode intended for updating the firmware, we will try to remove the dump through it.

To remove the need qtools, take here:
https://yadi.sk/d/fu51UwOive479


5. We look in the device manager COM port number "NETGEAR QDLoader Port", we need comXx.

Next, in the console, we load the loader to the port:
qdload -pXX -k3 -i

If the loader came up, then in response we should see the type of flash memory is the same as above in AT! FMBADBLOCKS ?.

We look at the partition table on the flash:
qrflash -pXX -s @ -m

Remove section CUST
qrflash -pXX -fY
where Y is the CUST partition number from the partition table shown by the previous command.


I think this is enough for a start. All answers on AT-commands lay out here.
All answers from the qdload and qrflash programs are also fully revealed.

Exiting Download mode and switching back to normal command operation:
qcommand -pXX -c "c 0b"
or you can simply turn off and turn back the router ...

Post has been editedSkvo - 24.09.16, 20:38
Forum:Netgear· View message:#53442161· Replies:2012· Views:223688

Skvo
24.09.16, 19:30
Local
*****
[offline]

Group: Friendssavagemessiahzine.com
Messages 135
Check in: 26.08.07

Reputation:-  59  +

Is it known? Has anyone scanned all ports for him? Maybe there is just using a different port number?

There is no certainty. On ac785 it may well be ADB.
On ac810, they also didn’t immediately understand how to get through to it ...

If there is an ADB, I will publish detailed instructions for dumping sections from it ...

Slightly off topic. I remember that you recently mentioned a piece of metal like the AC340, if I'm not mistaken. Do you know how to get to the console? Simply, there is a person with AC341 who, as I understand it, should be very similar to AC340 - only he supports CDMA

I have an AC330 (on MDM9200). It is analog MC7710 - the firmware is common for them ...

AC341 goes to MDM9615. It is generationally similar to EM / MC7305.
In my opinion, ADB should turn on if you give! OPENLOCK and then AT! CUSTOM = "ADBENABLE", 1
Here is the instruction:http://forum.ixbt.com/…gi?id=17LC3544:436#436
The! OPENLOCK algorithm for AC341 is used the same as the EM / MC7305. The calculator on the link above is suitable ...
Let him try ...

We are using the latest version of qtools?

qtools last. Corrected a bit of command ...

Well, their figs - these raw dumps!

Removed bad advice ...

Post has been editedSkvo - 24.09.16, 19:33
Forum:Netgear· View message:#53448021· Replies:2012· Views:223688

Skvo
21.09.16, 11:32
Local
*****
[offline]

Group: Friendssavagemessiahzine.com
Messages 135
Check in: 26.08.07

Reputation:-  59  +

strik22 @ 09/21/2016, 02:16*
Greetings, can the YOTA speed limit be lifted at 785S? How can I change the TTL / IMEI on this modem is there any information?

There is no ready recipe for changing TTL / IMEI. This router has never been studied so deeply ...

For 785S, for the time being, even the AT! ENTERCND password has not been calculated.
Those who wish to take a flash memory dump from their own copy and share with local gurus for research - until they found ...

Post has been editedSkvo - 21.09.16, 11:35
Forum:Netgear· View message:#53337361· Replies:2012· Views:223688

Skvo
09.09.16, 09:10
Local
*****
[offline]

Group: Friendssavagemessiahzine.com
Messages 135
Check in: 26.08.07

Reputation:-  59  +

Not
Masta blasta @ 09/08/2016, 21:37*
AT! WUURL?
AT! WUURL?
! WUURL: https://acupdates.netgear.com/swiwu/updates.aspx,https://acupdates.netgear.com/swiwu/download.aspx,https://acupdates.netgear.com/swiwu/summary.aspx

Ok
AT! WUAUTH?
AT! WUAUTH?
! WUAUTH: webupdt_aircard, sH37Lbr! Gz


Thanks for the test on the AC810S-1TLAUS.
The addresses of the update server, login and password - everything exactly corresponds to that specified in European AC810-100EUS.

I’ll add two more update commands here:

AT! WUCHECKINT? - shows the interval between the automatic search for updates.
The interval is calculated in minutes. The default value should be 10080 - this will be “once a week”.

AT! WUCHECKINT = xxx - accordingly setting this interval.

AT! WURUN - manual launch of the update search procedure.


Sandwern @ 09/08/2016, 11:06*
Theoretically, you can try switching the router to Wi-Fi Offload mode and using a sniffer to see which HTTP request is sent during the update check, and then inform the old firmware version in the already created request and try to get a link to download the new one. True how to do it ...

I think that from the router itself it can be peeped, with what requests it is breaking to the update server. Access to the Linux console by ADB because we have ...

Linux guru, is this real?

Sandwern @ 09/08/2016, 11:06*
1. What is known (for some commands thanks to Skvo):

I attach here the archive with all AT! commands that are processed by the modem subsystem firmware. Pulled out of AC810-100EUS.
The archive is just the names of the teams. For many there is no documentation how to apply them. But half of them correspond to the documented commands of the Sierra Wireless modems ...

Attached files

Attached fileat.zip(1.97 KB)


Post has been editedSkvo - 09.09.16, 09:16
Forum:Netgear· View message:#52961260· Replies:2012· Views:223688

Skvo
08.09.16, 15:56
Local
*****
[offline]

Group: Friendssavagemessiahzine.com
Messages 135
Check in: 26.08.07

Reputation:-  59  +

Sandwern @ 08/28/2016, 19:53*
Official accessories for Netgear AC790 / AC810

1. Aircard Smart Cradle DC112A

Purpose: docking station for turning the router into a stationary router.
Features: on sale can rarely be found. On the official forum Netgear there are reports that the model has been removed from support. There is a device page on the official website of Netgear with characteristics. There is no support for TDD-LTE.
Where to find: search required, no data

For DC112A, add a link to the User Manual and the latest official firmware V1.0.0.30:
http: //www.downloads.n...12A_UMsrc_3Aug2015.pdf
http: //www.downloads.n...A-V1.0.0.30_1.0.60.zip

In addition to this docking station, in your post it is worth mentioning another docking station, simpler:
AirCard Signal Boosting Cradle with Ethernet (DC113A)

Official page:https: //www.netgear.co…e-hotspots/DC113A.aspx
Datasheet:http: //www.downloads.n...atasheet/en/DC113A.pdf

European version, SKU: DC113A-100EUS even imported to Russia for sale ...

DC113A - officially supports the Aircard 790, but it will work with the Aircard 810 too (there is a phrase in the datasheet, "All Future Aircard Mobile Hotspots").
P.S.
By the way, here in this post, in a note,vitaly_dvmentions her. He tried a bunch of DC113A + router AC810. The Ethernet port on the docking station worked ...
Netgear AirCard AC785 (S), AC790 (S), AC810 (S) - Discussion (Post vitaly_dv # 52546661)

Post has been editedSkvo - 08.09.16, 16:30
Forum:Netgear· View message:#52941562· Replies:2012· Views:223688

Skvo
08.09.16, 13:35
Local
*****
[offline]

Group: Friendssavagemessiahzine.com
Messages 135
Check in: 26.08.07

Reputation:-  59  +

Masta blasta @ 09/08/2016, 12:58*
correct at! entercnd = "grouse" is the one for AC810S-1TLAUS.

The password information for the AC810S-1TLAUS has gone to the header of this topic.
Password matching is unexpected by the way. The "grouse" is taken from the AT & T operator's AirCard 340U USB modem ... and then suddenly came up for Telstra ...


AT! BAND =? confirmed the ranges. The information in the header was correct, the frequencies are a bit unsuitable for our country: there is no Band 20 and no Band 38.


AT! PACKAGE? shows current firmware + configuration, AT! FACTPACKAGE? shows the factory (factory).
Since they are different, we conclude that the router was updated from the update server.
In this regard, throw more answers on a couple of teams.
I want to look at the address of the update server where the firmware is located, and the login and password to this server:

at! entercnd = "grouse"
AT! WUURL?
AT! WUAUTH?

Post has been editedSkvo - 08.09.16, 13:48
Forum: Netgear · View message: #52937104 · Replies: 2012 · Views: 223688

Skvo
08.09.16, 12:41
Local
*****
[offline]

Group: Friendssavagemessiahzine.com
Messages 135
Check in: 26.08.07

Reputation:-  59    +

Masta blasta @ 09/08/2016, 12:11*
Sorry, but I do not speak Russian, so please accept this Google translated the feedback of my experience.

I have an Australian version 810 (AC810S-1TLAUS) the AT password that works with this model was mentioned Skvo (thanks) here Netgear AirCard AC785 (S), AC790 (S), AC810 (S) - Talk

Thanks for the feedback.

As I understand it, at! Entercnd = "grouse" approached the Australian AC810S-1TLAUS.
If so, then show answers to several AT commands from your router:

ATI
at! entercnd = "grouse"
AT! BAND =?
AT! PACKAGE?
AT! FACTPACKAGE?
AT! UDINFO?
Forum:Netgear· View message:#52935312· Replies:2012· Views:223688

Skvo
28.08.16, 00:53
Local
*****
[offline]

Group: Friendssavagemessiahzine.com
Messages 135
Check in: 26.08.07

Reputation:-  59  +

vitaly_dv @ 08/22/2016, 10:20 PM*
I have a non-operator version of the AC 785-100 EUS with the latest firmware that flew through the air in July.

For starters, throw three answers to know exactly what we are dealing with:
ATI
AT! PACKAGE?
AT! FACTPACKAGE?
vitaly_dv @ 08/22/2016, 10:20 PM*
But the password from 810 did not fit, I additionally tried grouse and A710, in response to ERROR.

With a password is expected ... Each model of the router from Netgear has its own password ...

As previously mentioned in the topic, you need to climb into the flash for the password ... The original is in the EFS2 section, the backup is in the CUST section ...
As soon as we get to the dumps of any of these sections, then there will no longer be a problem to decrypt the password from it.

On the AC810, there was access to the ADB, through which the CUST dumps were removed and the password was pulled from there.

On the AC785, as you write, there is no access to the ADB, so we are going a different way.
In my opinion, it will be easier to remove dumps via qtools through the diagnostic port ... The AC785 chipset is qualcomm mdm9225, qtools is familiar with it, in the end, I think it should go without any problems ...

But first you need a computer in Windows, MacOS is not an assistant here ...
From the header, put the driver on and, for a start, configure QPST to make sure it works.

And then download qtools, transfer the router to Download mode via Diagnostic port XX:
qcommand -pXX -e -c "c 3a"

load the loader and initialize the flash controller:
qdload -pXX -k3 -s -i

and try to read the section map:
qrflash -pXX -s @ -m

....
Forum:Netgear· View message:#52574660· Replies:2012· Views:223688

Skvo
27.08.16, 13:23
Local
*****
[offline]

Group: Friendssavagemessiahzine.com
Messages 135
Check in: 26.08.07

Reputation:-  59  +

vitaly_dv @ 08.26.2016, 23:58*
And will they close it in the firmware update, and if they close it, are there any alternative ways to launch adb shell or at least an AT terminal?

vitaly_dv @ 08.26.2016, 23:58*
UPD2:
On AC785 adbd over WiFi is not available, but I would also like to add the ability to select ranges. Is there any way to get to the AT-terminal?


Following the discussion in this topic, I added four ways to reach the AT port on Netgear Aircard in the header.
The first two should earn on the AC785. Try ...


P.S. Cap in the process of filling.
Send your suggestions / corrections / additions to QMS ...


Post has been editedSkvo - 27.08.16, 13:33
Forum: Netgear · View message: #52557590 · Replies: 2012 · Views: 223688

Skvo
17.08.16, 15:13
Local
*****
[offline]

Group: Friendssavagemessiahzine.com
Messages 135
Check in: 26.08.07

Reputation:-  59   +

Skvo @ 07/08/2016, 09:50*
Got pictures of the box from the AC810S for the Polish operator PLAY.
Frequencies are not listed. The presence of Band 38 - remains in question.
...

P.S. As a result, to determine the frequencies, there is an option to peep them at AT! BAND =?
We will wait for the real owner ...

Talked a little with the Poles. As a result, we found out the frequencies ...

Here is a report on AT commands with the AC810S-1P1PLS:

AT! ENTERCND = "whistler"
Ok
AT! BAND =?
AT! BAND =?
Index, Name, GW Band Mask L Band Mask
00, All Bands, 0002000004C00000 000001A0000800C5
01, Europe 3G, 0002000000400000 0000000000000000
02, North America 3G, 0000000004800000 0000000000000000
03, Europe, 0002000000400000 000000A0000800C4
04, North America, 0000000004800000 0000010000000040
05, WCDMA ALL, 0002000004C00000 0000000000000000
06, LTE ALL, 0000000000000000 000001A0000800C5

0000010000000000 - B41
0000008000000000 - B40
0000002000000000 - B38
0000000000080000 - B20
0000000000000080 - B8
0000000000000040 - B7
0000000000000004 - B3
0000000000000001 - B1
0002000000000000 - B8 (900)
0000000004000000 - B5 (850)
0000000000800000 - B2 (1900)
0000000000400000 - B1 (2100)

Ok
AT! GSTATUS?
AT! GSTATUS?
! GSTATUS:
Current Time: 636 Mode: ONLINE
System mode: LTE PS state: Attached
EMM state: Registered Normal Service
RRC state: RRC Connected
IMS reg state: No Srv

PCC:
LTE band: B20
LTE bw: 10 MHz
LTE Rx chan: 6350
LTE Tx chan: 24350
RSSI (dBm): -83.3
RSRP (dBm): -117.0
RSRQ (dB): -16.2
RSSNR (dB): -6
Tx Power (dBm):
LTE Cell ID: 49664257
Physical Cell ID: 12
TAC: 59401


Ok



As a result, the Polish version of the AirCard AC810S, SKU code: AC810S-1P1PLS:

- not locked to the PLAY operator. Works with any SIM cards.

- frequencies are similar to the European version of the AC810-100EUS:
LTE FDD: B1, B3, B7, B8, B20
LTE TDD: B38, B40, B41

- you can safely take it as an alternative to the European version of the AC810-100EUS.
In the domestic market of Poland, prices for new packages start from 500 zlotys:
http://olx.pl/elektron...utery-i-modemy/q-810s/
http://allegro.pl/list...gory-77976&string=810s

Post has been editedSkvo - 17.08.16, 15:14
Forum: Netgear · View message: #52246980 · Replies: 2012 · Views: 223688

Skvo
08.07.16, 09:50
Local
*****
[offline]

Group: Friendssavagemessiahzine.com
Messages 135
Check in: 26.08.07

Reputation:-  59   +

Got pictures of the box from the AC810S for the Polish operator PLAY.

Frequencies are not listed. The presence of Band 38 - remains in question.
Supported aggregation combinations on the box - either.

UserManual on AC810S from Play, in which this can be told - is also not seen anywhere ...

P.S.
As a result, to determine the frequencies, there is an option to peep them at AT! BAND =?
We will wait for the real owner ...

Attached images
Attached Image
Attached Image
Attached Image
Attached Image


Post has been editedSkvo - 12.08.16, 08:51
Forum: Netgear · View message: #51042692 · Replies: 2012 · Views: 223688

Skvo
27.06.16, 13:33
Local
*****
[offline]

Group: Friendssavagemessiahzine.com
Messages 135
Check in: 26.08.07

Reputation:-  59   +

The story of getting the key for AT! ENTERCND continues ...

A bit of theory for everyone.
Sierra Wireless has always used the universal password “A710” by default.
After the transition of the mobile unit to Netgear, the new firmware changed the password to an alternative one.

Sandwern @ 06/22/2016, 6:00 PM*
at! entercnd = "grouse"
The same, ERROR, tried both upper and lower case.

This password is "grouse" fromAircard 340U

And in the first firmware from Sierra Wireless for AC340U - the password was "A710". In the latest firmware from Netgear, it became "grouse". Pulled it outthis firmware AC340U from Netgear.
It was hoped that this is a new universal from Netger, but not destiny. If this password did not fit the AirCard 810, then each Netgear product has its own separate password for AT! ENTERCND ...

Also, an attempt was made to obtain a password through elevation of rights, for example, as described hereusing AT! OPENLOCK authentication- but here we were waiting for a bummer. The algorithm for calculating the codes OPENLOCK for AC810 - varied ...

Remains an option through the search section EFS2. There will be a dump of the EFS2 section - I will try to get the password out of it ...

Although the password may be lit in other sections. For example in "CUST". This section stores a backup copy of NVRAM. It must also have a password ...

Post has been editedSkvo - 12.08.16, 08:42
Forum: Netgear · View message: #50743759 · Replies: 2012 · Views: 223688

3 pagesV  1 2 3 > » 



 mobile version Now: 06/01/19 20:14