Kitz Forum

Broadband Related => Broadband Hardware => Topic started by: waltergmw on July 09, 2014, 05:48:45 PM

Title: TalkTalk HG 635 Firmware
Post by: waltergmw on July 09, 2014, 05:48:45 PM
Gentlefolk,

Does anybody have any data on the TalkTalk "Superhub" Huawei HG635 firmware please ?

In particular does it have a similar enhanced version as BT are now running in their HG 612s that provides a very useful sync speed increase on slower poor quality lines ?

Is the modem locked down as BT's is ?

Kind regards,
Walter
Title: Re: TalkTalk HG 635 Firmware
Post by: burakkucat on July 09, 2014, 06:38:19 PM
I would also like to ask a question about this device . . . and trust Walter will not object to me raising it here.  ;)

This "Superhub" (as TalkTalk describe it) is undoubtedly a modem/router/DHCP server/DNS server/WAP/firewall. I would be interested in knowing if the modem is VDSL2 capable or, rather like the Beattie HH3 & HH4, is limited to ADSL2+ as its maximum?
Title: Re: TalkTalk HG 635 Firmware
Post by: NewtronStar on July 09, 2014, 07:36:27 PM
I would also like to ask a question about this device . . . and trust Walter will not object to me raising it here.  ;)

This "Superhub" (as TalkTalk describe it) is undoubtedly a modem/router/DHCP server/DNS server/WAP/firewall. I would be interested in knowing if the modem is VDSL2 capable or, rather like the Beattie HH3 & HH4, is limited to ADSL2+ as its maximum?

Just a Google search ->

TalkTalk Huawei HG635 Built in VDSL modem

I was part of the latest TalkTalk Labs trial for this Huawei HG635 router the trial is now complete and I no longer need the Router, I've moved on from TalkTalk.

Description
Cutting edge Huawei HG635 hardware which includes the latest 1GB capable Wi-Fi wireless networking specification, known as 802.11ac.

Built in VDSL modem (No need for the open reach modem = Reclaim one of your wall sockets)
this is the only device you need for your fibre internet.
Title: Re: TalkTalk HG 635 Firmware
Post by: waltergmw on July 09, 2014, 08:07:03 PM
@ BKK,

I think we are led to believe that the Super Router is capable of handling the BT OR VDSL2 protocol as illustrated in their wiring diagram included in:-

http://help2.talktalk.co.uk/how-do-i-check-my-fibre-connection-setup

Kind regards,
Walter
Title: Re: TalkTalk HG 635 Firmware
Post by: burakkucat on July 09, 2014, 08:44:17 PM
Thank you N*Star and Walter.

So we now need the services of an appropriate Wizard, with a fully equipped laboratory, to examine and expose the innermost secrets of such a device.  :)
Title: Re: TalkTalk HG 635 Firmware
Post by: roseway on July 09, 2014, 10:40:07 PM
It's a Broadcom based modem with a fully functional telnet interface and the normal CLI functions. DSLstats works with it, and there's no reason in principle why HG612_Modem_Stats shouldn't work with it as well.
Title: Re: TalkTalk HG 635 Firmware
Post by: GunJack on July 09, 2014, 10:40:30 PM
Hi bk and walter, long time no see :)

I've got one here, just awaiting my Friday install/go live on TT fibre. Popped it out of the box earlier to configure the wifi side - it has dual 2.4/5 GHz capability, and it is ac capable. However, I've just set it to g only @ 2.4GHz to be best compatible with most of the wifi devices in the house. Signal strength is very good, at an equal distance to the measuring point as my trusty 2640B with 10dBi gain antenna, the superhub wifi was showing around 15dB better signal !! Surprised me a bit, but if it'll be stable at that output will be well happy with it...
Title: Re: TalkTalk HG 635 Firmware
Post by: GunJack on July 11, 2014, 06:28:49 PM
taken from the router interface:-

Hardware version:
G.1.01
Software version:
v1.04t

HTH walter and b*cat
Title: Re: TalkTalk HG 635 Firmware
Post by: waltergmw on July 13, 2014, 09:55:57 AM
Thanks GJ,

It would be useful if you could add pictures of any performance stats pages you can access.

Kind regards,
Walter
Title: Re: TalkTalk HG 635 Firmware
Post by: GunJack on July 14, 2014, 10:47:37 PM
walter, best I can do at the moment.... HTH
Title: Re: TalkTalk HG 635 Firmware
Post by: GunJack on July 14, 2014, 10:49:00 PM
and p.s. Eric, I can't get DSLstats to connect, think they may have closed down the telnet port 23 for roll-out, or I'm not configuring the logon correctly  :-[
Title: Re: TalkTalk HG 635 Firmware
Post by: roseway on July 14, 2014, 10:58:01 PM
If you can't login to the telnet interface manually, it does look as though it's been blocked. I haven't yet been able to contact the person who originally reported that it worked.
Title: Re: TalkTalk HG 635 Firmware
Post by: burakkucat on July 14, 2014, 11:26:33 PM
Running nmap from the LAN-side will show what port(s), if any, is/are open.

For Walter's convenience, I have re-attached the two DSL Connection Status screen-scrapes as PNG images, below.

[It might be worth checking what is displayed when the rights, at the bottom of that GUI page, is selected.]
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on July 15, 2014, 06:20:48 AM
  I would be worth looking to see if there is a firewall acl to enable telnet and also whether the config file is is in plain text and editable. It might just be possible to enable telnet that way.
Title: Re: TalkTalk HG 635 Firmware
Post by: GunJack on July 15, 2014, 02:15:21 PM
Running nmap from the LAN-side will show what port(s), if any, is/are open.

For Walter's convenience, I have re-attached the two DSL Connection Status screen-scrapes as PNG images, below.

[It might be worth checking what is displayed when the rights, at the bottom of that GUI page, is selected.]

sorry b*cat, you're losing me.... nmap? what/where/how do I get that please?

will check later, but think the rights were standard copyright stuff....
Title: Re: TalkTalk HG 635 Firmware
Post by: burakkucat on July 15, 2014, 04:26:17 PM
A quick introduction to nmap (http://en.wikipedia.org/wiki/Nmap) via Wikipedia.

It was originally a Unix/Linux kernel OS utility but now has been ported to other OS', including BGW (Billy Gates Ware).
Title: Re: TalkTalk HG 635 Firmware
Post by: GunJack on July 15, 2014, 09:09:42 PM
hanx b*cat, will take a look. Plus, for walter, you, and possibly especially roseway, the contents of the rights link at the bottom of the stats page :)
Title: Re: TalkTalk HG 635 Firmware
Post by: GunJack on July 15, 2014, 09:33:19 PM
nmap produced this output on a port scan...looks like the hg635 has been well and truly locked down for production :(

Starting Nmap 6.46 ( http://nmap.org ) at 2014-07-15 21:27 GMT Daylight Time

Nmap scan report for 192.168.1.1

Host is up (0.0020s latency).

Not shown: 996 filtered ports

PORT     STATE SERVICE

53/tcp   open  domain

80/tcp   open  http

443/tcp  open  https

5060/tcp open  sip

MAC Address: D0:7A:B5:C7:8A:6C (Huawei Technologies Co.)



Nmap done: 1 IP address (1 host up) scanned in 33.80 seconds
Title: Re: TalkTalk HG 635 Firmware
Post by: burakkucat on July 15, 2014, 09:59:07 PM
It does seem to be rather "locked down".  :(

Contrast your result with that which I obtained from my HG622 --

[Duo2 ~]$ nmap 192.168.1.254

Starting Nmap 5.51 ( http://nmap.org ) at 2014-07-15 21:51 BST
Nmap scan report for AP (192.168.1.254)
Host is up (0.019s latency).
Not shown: 993 closed ports
PORT     STATE    SERVICE
21/tcp   filtered ftp
22/tcp   filtered ssh
23/tcp   open     telnet
80/tcp   open     http
443/tcp  filtered https
631/tcp  open     ipp
8081/tcp filtered blackice-icecap

Nmap done: 1 IP address (1 host up) scanned in 2.58 seconds
[Duo2 ~]$

The "Copyright Notice and Warranty Disclaimer" gives us some idea of the software "building blocks" used in that firmware image.

If there are header pins attached to the PCB, they may provide a serial port access to the console . . .  :-\
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on July 16, 2014, 07:32:16 AM
1.  Under something like parental controls / security / firewall there is often the option to enable or disable protocols on either the LAN or WAN interfaces.  I had a Chinese HG630 which started like this Hg635 but it was possible to enable  ssh access via the GUI acl tab (telnet was not running).   It would be worth searching through the gui for any hopeful screens which enable/disable access through various protocols.

2.  Also although it not common some routers have text editable config file.  e.g. in the Hg612 config file you find "<ACLInstance InstanceID="3" X_ATP_Service="TELNET" X_ATP_Direction="LAN" X_ATP_StartIpAddr="" X_ATP_EndIpAddr=""/>"

 Assuming the option is on the gui download a config file and see if is readable - if it is that might just make it possible to enable telnet.


 
Title: Re: TalkTalk HG 635 Firmware
Post by: broadstairs on July 16, 2014, 09:17:45 AM
My HG622 downloads a non-editable config file so I suspect the HG635 may well do the same.

Stuart
Title: Re: TalkTalk HG 635 Firmware
Post by: GunJack on July 23, 2014, 10:15:46 AM
can't find the config file unfortunately....

however, one question that the router interface has thrown up, do the upstream/downstream noise safety coefficient (dB) equate to snrm in English??
Title: Re: TalkTalk HG 635 Firmware
Post by: roseway on July 23, 2014, 10:43:59 AM
That does seem to be the case, although "coefficient" is the wrong word in this context. I get the impression that it's a Huawei term, and may be a bad English translation of the Chinese original.
Title: Re: TalkTalk HG 635 Firmware
Post by: broadstairs on July 23, 2014, 11:28:20 AM
can't find the config file unfortunately....

If the GUI allows it there is an option under the maintenance/device menu item on the HG622 to save a config file so I would expect the same on this router, it may have been disabled though by TT.

Stuart
Title: Re: TalkTalk HG 635 Firmware
Post by: GunJack on July 23, 2014, 11:44:37 AM
thanks guys, will investigate further later :)
Title: Re: TalkTalk HG 635 Firmware
Post by: GunJack on July 25, 2014, 11:09:51 AM
oh well, in typical isp fashion, it looks like pretty much the whole router is locked down, no config logs (that  can find), no nothing :(
Title: Re: TalkTalk HG 635 Firmware
Post by: bmn on July 25, 2014, 08:50:38 PM
There is a serial console (easily found) however the linux firmware only outputs to the console it doesn't accept serial input. Serial input works in the bootloader but there are no memory dump or flash commands. The bootloader has the web interface for uploading a firmware same as HG612 but no firmware image is available. Someone could request the GPL source code and make it available for download but there are no guarantees it'll be quickly hackable even with the GPL source code.

Bootloader:
Code: [Select]
CFE version 1.0.38-114.174 for BCM963268 (32bit,SP,BE)
Build Date: Sat Nov  9 13:59:00 CST 2013 (l00184769@localhost)
Copyright (C) 2000-2011 Broadcom Corporation.

NAND flash device: name , id 0x98d1 block 128KB size 131072KB
External switch id = 53125
Chip ID: BCM63168D0, MIPS: 400MHz, DDR: 400MHz, Bus: 200MHz
Main Thread: TP0
Memory Test Passed
Total Memory: 134217728 bytes (128MB)
Boot Address: 0xb8000000

 Boot :e=192.168.1.1:ffffff00 h=192.168.1.100 g= r=f f=vmlinux i=bcm963xx_fs_kernel d=1 p=0
*** Press any key to stop auto run (3 seconds) ***
Auto run second count down: 333
CFE>
web info: Waiting for connection on socket 0.
CFE> help
Available commands:

gccs                get hw chk sign mode.
p                   Print boot line and board parameter info
ccs                 hw chk sign mode.
c                   Change booline parameters
b                   Change board parameters
cg                  hw boot.
r                   Run program from flash image or from host depend on [f/h] flag
reset               Reset the board
help                Obtain help for CFE commands

Firmware (partial):

Code: [Select]
Boot :e=192.168.1.1:ffffff00 h=192.168.1.100 g= r=f f=vmlinux i=bcm963xx_fs_kernel d=1 p=0
*** Press any key to stop auto run (3 seconds) ***
Auto run second count down: 33210
Power down external PHY port.Boot from main system!
SIGN CHK ALWAYLYS.
get bootflag = 1
 check tag at block 1 crc ok
Check Image Crc Success
I have find vmlinux.lz at block 11
I have get vmlinux.lz size at block 25
Decompression OK!
Entry at 0x803bb870
Closing network.
no Disabling Switch ports.
Flushing Receive Buffers...
0 buffers found.
Closing DMA Channels.
Starting program at 0x803bb870

init started: BusyBox vv1.9.1 ()

starting pid 299, tty '': '/etc/init.d/rcS'
RCS DONE

starting pid 301, tty '': '/bin/sh'


BusyBox vv1.9.1 () built-in shell (ash)
Enter 'help' for a list of built-in commands.

rootdir=/
table='/etc/devicetable'
mount config success
mount coredump success
-/bin/sh: cannot create /proc/tty/mode: nonexistent directory
Loading drivers and kernel modules...
Start mic now ...
GlobeMac Init OKload cfm ok.
##sendmsg return 16, errno 0.
ethcmdVportEnable--------SUPPORT_ATP_ETH_BCM_EXT_SWITCH_53125-----
ARL table flush done
Success
MASK- ifconfig [eth0]**********
device eth0 is not a slave of br0
LedcmswpsChgProc :9
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on September 15, 2014, 10:05:59 AM
  I have the Business version of the HG635 now.  Works fine and the available setup options may be better if previous post have not missed things on the Home version.  However it is essentially just as locked down.  No telnet access and the serial is exactly as noted by bmm. Without xdsl stats/error info available I am unfortunately not prepared to actually use it as intended.  It does however have a wan port and looks OK for use with the HG612 as a wireless ac gigabit router.

   It would be great if anyone with one of the early unlocked ones could download from the Hg635 a config file and make it available.  That file might enable things on the later versions.
Title: Re: TalkTalk HG 635 Firmware
Post by: clienthax on October 13, 2014, 03:32:34 PM
https://mega.co.nz/#!jN9CyALT!D6553h8pN7kjmd8AmJ4zo62EaLAgaTqCngVuTMMVwcE
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on October 13, 2014, 03:41:47 PM
  Interesting.  :)  Do you know anything about that source code? e.g. is it a/the TT version or another HG635 and has any one built it and tried it?
Title: Re: TalkTalk HG 635 Firmware
Post by: burakkucat on October 13, 2014, 03:42:08 PM
Welcome to the Kitz forum clienthax.  :)

For the benefit of those kitizens who are wondering, the link you have provided is to a file containing hg635-opensource.tar.gz
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on October 14, 2014, 09:25:01 PM
  For any one interested I used an image taken from the files posted above and now have a version with telnet enabled.  Got far enough to see the dsl driver version is A2pv6F039e but it will be a few days before I have time to try it on my line.
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on October 15, 2014, 07:29:17 PM
  I found time for a quick try this afternoon.  It went well to begin with

 Since Link time = 1 hours 27 min 9 sec
FEC:      0      30
CRC:      22      3
ES:      18      3
SES:      0      0
UAS:      0      0
LOS:      0      0
LOF:      0      0

until I reached my lines peak error time of 17:00 -19:00

Since Link time = 4 hours 48 min 1 sec
FEC:      0      165
CRC:      24684      14
ES:      236      13
SES:      37      0
UAS:      0      0
LOS:      0      0
LOF:      0      0

 I am not really sure why this early evening is the problem time.   This level of errors is similar values last seen with the XyXel VMG8324-B10A.  It seem that the 63168's and 039 dsl drivers don't like my line in the early evening.

  The format of the stats is bit different. See a full example below.

   Other issues: - the xdslcmd command in this device does not have the maxdatarate option so you can't cap speeds.  In in my short test it took a while to work out how to disable telnet access from the wan and I never managed to get a ping response on the WAN working.   If anyone is thinking of trying these firmwares remember that using them is one way street as unless TT do a remote upgrade and these firmware have been  set up to support that.  There may be no going back once you use them.   That said I was very happy until the errors bit. It gave a 2Mb/s speed up over the Hg612 and the throughput and wireless were fine, it worked with dslstats and I would guess that anyone with a better line than mine would be quite happy.  I will try again another day just in case the errors today are bad luck.  If any one does try them you will need the telnet login of !!Huawei/@HuaweiHgw.

  The firmware  version is 1.04t so I would guess that the current regular TT firmware performs in a similar way but probably with a few bugs removed.

Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on October 21, 2014, 02:03:45 PM
  Any one with a TT super router who would like telnet access may wish to try this.  I can't advise on whether or not it will work as my one is no longer using the supplied firmware.

    1.  Under maintain/device save your current configuration settings as you will need them to easily get back to normal.

    2. Under maintain/device upload the attached device settings file to the TT super router.  It may or may not need renaming from .txt to .conf?

    3. If that works you may/should have telnet access with login of !!Huawei  / @HuaweiHgw

    4.  The settings are some sort of default and I take no responsibility at all for them.   

    5.  An upload of the config file you first saved should return you to normal if your not happy

 You may or may not need to change the xx@xx  connection name and password.  My TT line does not care what they are.   The only trouble I had was with the firewall side of things.  I would really welcome some one more expert than me trying this side of things.  I did get it secure with a Shields Up scan  but I could not get a response re WAN pings.   Someone who can work with iptables ought to be able to sort this all out via the telnet.  Update ==  it is report that provided TR069 is enabled the WAN ping and setting to TBB works via adding it to the acl.  I did not have TR069 enabled when testing but it is already in the config file in the next post

     Please report what happens.   


    Edit use config file from next post
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on October 23, 2014, 06:12:45 PM
  I attach an updated config file, it is basically the same but for me at least the firewall is now fully secure and as TR069 is enabled it may accept updates.  I can't get ping to work on the wan but the same issue is reported in standard configurations on the TT forums and no solution seems to offered.   

As before if you select auto under connection it will probably work but for FTTC I have made the default a normal FTTC setting. It is trivial to also add an adsl connection.  Apart from the bonus of the telnet access as noted above, a default FTTC user will probably only notice the wireless name and password not being the same as usual.  They can be edited to the usual or as needed.

 A report would be most welcome.  Having got telnet working and found error rates with it are larger than an HG612  and similar on my line to other 63168 devices with the 039 dsl driver I am not using the HG635 most of the time (the CFE actually reports the TT HG635 device as a 63268 not 63168 ?).   On my line the error rate is typically x2 that of the HG612 and slightly worse than the Billion 8800NL .  Judging by other 63168 devices,  other lines may not show this error increase.   The sync speed increase is good and 3-4 Mb/s on my line.

   Use a config file from http://forum.kitz.co.uk/index.php?topic=14185.msg273545#msg273545
Title: Re: TalkTalk HG 635 Firmware
Post by: npr on October 26, 2014, 08:01:29 PM
I can't get ping to work on the wan but the same issue is reported in standard configurations on the TT forums and no solution seems to offered.   


I've got the TBB ping graph working by adding the following firewall rule:
Service type:  ICMP
Access Direction: WAN
Start IP:  80.249.99.1
End IP:  80.249.99.254
Also for some reason TR069 needs to be enabled in the VDSL internet connection settings.
http://npr.me.uk/hg635.html


So far I've failed miserably trying the compile the hg635-opensource.tar.gz file.
This is not something I've any experience of doing before, so any tips will be gratefully received.
ie which folder do I "cd" to ?
Which commands do I run?
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on October 26, 2014, 09:23:56 PM
  Thanks for the info.  The rule in the firewall was the first thing I tried.  I never considered enabling the TR069 as well though.

 I think a build of the firmware would be difficult.  I believe a needed folder, "product" if I recall correctly, should have a Config.in file in it and that is missing.  Are you using one of the built firmwares in the output folder or using the config file that I have provided.  If that config file works then you do have the major benefit of leaving the supplied modem firmware fully intact. 

   Please can you say if the config file above gets telnet working with the supplied firmware?
Title: Re: TalkTalk HG 635 Firmware
Post by: npr on October 26, 2014, 09:57:20 PM
This is the file I have:
http://consumer.huawei.com/en/support/downloads/detail/index.htm?id=28981
AFAIK it's the same file as the link earlier in this thread.

There's a .config file in /configs/tt/hg635
It looks interesting, is that all you need to run to build the firmware?
I thought you needed to run a "Make" file -- can't find that anywhere.

Hadn't noticed what I assume is the compiled firmware in the folder
/output/images/
Not sure which one to try but as they are all v1.04t, the same as the TT version, I think I'll leave alone and wait for the forthcoming TT v1.06t release.

I'll give your config file a try tomorrow and let you know.
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on October 27, 2014, 07:10:59 AM
  That zip is the same as the other, there is a makefile is the top directory.  I tried make there, it got as far as complaining about the missing file.  The top Config.in notes the file in question as needed.   

   As I mentioned above, the firmwares work fine and the HG635v1.04t_multicast_with_multicfg_main.bin  has telnet enabled. I would however recommend just trying the config file as that will be harmless.

   If you use those images and upload one once you can get back to the supplied firmware if you solder up the serial output on the pcb and use the CFE to choose booting from the Slave image.   However if you upload an image twice both the main and Slave images are overwritten and there is no going back. That said the open source firmwares should accept an update from TT.

 Please could you give a screen shot or print of the settings on the maintenance/remote access/ page of the default firmware. (I think it is called that).  Those settings and enabling TR069 are all that may be needed to ensure the images in the opensource file accept remote firmware updates from TT OK.
Title: Re: TalkTalk HG 635 Firmware
Post by: npr on October 27, 2014, 02:04:08 PM
Hi les-70,

I've restored (installed) your config file and can now get the telnet login whereas with the default config all I got was "connecting" which eventually timed out.
Unfortunately it will not accept the routers GUI login username and password (admin for both), any ideas for the telnet username / password?
 ie:
Quote
Welcome, you are from 192.168.1.65
-------------------------------
-----Welcome to ATP Cli------
-------------------------------

Login: admin
Password:
Login incorrect. Try again.

Login:

The following are the default settings for the remote management, these settings were taken after a factory reset and before loading your config.

Quote
Page URL: http://192.168.1.1/html/advance.html#tr069

Enable remote management:  Ticked
Enable periodic information:  Ticked
Periodic information interval:  86400
ACS URL:  http://acs.talktalk.co.uk:7547/ACS-server/ACS
ACS username: Blank
ACS password: Blank
Connection request username:  cpeuser
Connection request password: (Encrypted)
Connection request port:  7547
Enable certificates: Not ticked
Certificate file path: No file selected

Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on October 27, 2014, 02:28:35 PM
  I gave it a few posts above.  "If that works you may/should have telnet access with login of !!Huawei  / @HuaweiHgw"  I am pleased that config file has worked for you. This means that TT HG635 users can get telnet without much trouble.
Title: Re: TalkTalk HG 635 Firmware
Post by: npr on October 27, 2014, 06:28:55 PM
  I gave it a few posts above. 

How did I miss that   :-[
I can login to telnet with that username and password but the response to a cli command is "Command failed".

Quote
Welcome, you are from 192.168.1.64
-------------------------------
-----Welcome to ATP Cli------
-------------------------------

Login: !!Huawei
Password:
ATP>xdslcmd info --stats
Command failed.
ATP>

The config file reduced the DHCP lease time to just 1 minute.
That and other changes I made:

DHCP server:
lease duration: was 1 minute  changed to 1 day

2.4 GHz
11n bandwidth: was 20/40MHz changed to 20MHz

UPnP: was enabled changed to disabled.

Remote Management: was enabled changed to disabled
Connection request port: was 23 changed to 7547
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on October 27, 2014, 06:35:51 PM
  You need to first type "sh" at the ATP> prompt first.   If you use dslstats with HG635 selected and the login info edited you will quickly see the stats in nice form.   

Thanks for pointing out the other things - most are my fault and some of my defaults.  I will update the config file later on to save other from the same issues.
Title: Re: TalkTalk HG 635 Firmware
Post by: npr on October 27, 2014, 07:14:20 PM
All working now, thanks for your patience.   ;D
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on October 27, 2014, 07:20:33 PM
  I have updated the config file above re DHCP lease time and remote management settings.

   @npr if your running live and connected please go to https://www.grc.com/x/ne.dll?bh0bkyd2 click proceed, then choose "all service ports"  I am hoping you get all ports marked as stealth. If not please let me know!!
Title: Re: TalkTalk HG 635 Firmware
Post by: npr on October 27, 2014, 08:47:45 PM
All marked as stealth.   ;D
Title: Re: TalkTalk HG 635 Firmware
Post by: npr on October 30, 2014, 11:27:38 AM
I've discovered that if the admin password is changed in the GUI then the telnet password is also changed from @HuaweiHgw to the new admin password.

Wish list:
1) Change the admin / telnet username.
So far I can't find the file containing this.
2) Change the SNTP servers to non-talktalk ones.
Think I can see a way to do this -- just need to give it a try.
3) Have the DHCP server remember the DNS server IP's.
Hopefully the forthcoming firmware v1.06t will correct this bug.
4) Read / edit the backup config file.
Don't think I've got a chance as it's Chinese text.

After using this router for about 3 days my long standing fibre upstream sync of 1.3 Mbps has increased to 2Mbps.  ;D I'm not giving the router the credit just yet, I'd previously used it for many weeks and the upstream sync remained stubbornly at 1.3Mbps.

Title: Re: TalkTalk HG 635 Firmware
Post by: kitzuser87430 on October 30, 2014, 02:03:34 PM
Quote
1) Change the admin / telnet username.

On hg612 /var/sshusers.cfg contains the telnet/ssh user list...in one old version of the firmwear one can use vi and edit the file.

I've got a hg 635 on its way to me now, to be used on my ADSL line.

Ian
Title: Re: TalkTalk HG 635 Firmware
Post by: npr on October 30, 2014, 04:57:15 PM
Thanks, I'm not very proficient with Busybox but I'm pretty sure that file doesn't exist in the HG635 v1.04t.
And vi doesn't appear to be installed or any other text editor that I can find -- hope someone can prove me wrong on that.  ???

The sntp server list is in the file /var/sntp.conf -- just need a way to edit that file.
I'm thinking of running a ftp server on my pc and using wget to drag a replacement file in from the ftp server.
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on October 30, 2014, 06:42:12 PM
  @npr Many thanks for the useful update. I fear that you won't find changing files in the file system trivial.  Most of the file system is read only, a change can sometimes be made by copying part of it and then mounting it over the original. See http://huaweihg612hacking.wordpress.com/2012/11/11/dynamically-swapping-out-the-hardware-driver-blob/ for an example.  I hope a real expert may look at the opensource files sometime, someone might be expert enough to make a custom build.  The config file is encoded and not Chinese.

  Getting a file in/out is really easy via any plugged in usb memory stick.  The files on it will be in e.g. /mnt/usb1_1/ but it may not be 1_1.
Title: Re: TalkTalk HG 635 Firmware
Post by: npr on October 30, 2014, 10:57:40 PM
I failed to import a file using wget and ftpget.
Will try your USB suggestion tomorrow.

I suppose the config file could be encrypted but I've never seen a file displayed as Chinese characters before.  ???

Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on October 31, 2014, 11:48:37 AM
  I doubt that it really is Chinese and I can't get it display that way.  You could try a copy and paste into google translate to see what it gives.  i tried that but it didn't work for me.
Title: Re: TalkTalk HG 635 Firmware
Post by: npr on October 31, 2014, 12:23:15 PM
Only get Chinese symbols if opened with windows notepad, if opened with Notepad++ then it's just the non-printable characters you would expect from an encrypted file.
I've already run a translation, the result is not very meaningful.
eg:

Quote
Jianlian 총 Cejinliaolv 엻쾂 additional information  Duan Hao »Jun ᠏ shelter ᥊ Qinfu ꏣᗧ 䔁 Jue 䲘 noise Chao ᕐ ៀ  Qin Ῥ Juyun 끪 䂢  Que ᫙ pour ⒆ Xuan  Nie 쮓  corner 﫽 Shen Bo  still 런  䆏 ج Lvnuo column ᜩ sets 귀 De Ἆ 츮 䒕 㾚 읽  㸦  Ji 풞씩 4 Hu  겾 Xinongjiangmu 쑩 ⋭﮻ 䵤 홿 ㅋ ridge 㸊 쬝 wei 볓 㡂 Tou Yang Tao ۉ⮏  Nu Chek pile 䰮 䠁 ጻ 䠪 ᥲ Ken cast ꅺ⦕ 졈 䪢 꼿 ꨗ Ru 䋷 㧏 ڨ 뮃  Jiu 㛸 worm screws 줫 ꔧ 릚 invited ᜽╅ 㙧 䴁 ꋿ◲ᖷ Shao Kai ݰ 㻠 퇱 braid  Che ꖻ ࿬ ჼ slough 맇 bit ھꪷ ⳬ Gong Fu 㵉 㷰 ؏ ꎙ 긔 ⮊ꌿ 䐦 㙧  횄 㧖 Lu complain Ὲɞꪵꢔꔈⅾ 톇 Wan Zhan Xiao Qiao  hip ᤄ engine 䈥 ⹒مم rejoice vi 튛 Ken ῷ lagoon Yuan 햛 Baoyidianhu ꏍ 멍 | Ni ❢ 홤 ꄀ 젭얥 pole  Re ۉ ‰ ႝ ⩺ 㘤 ꫧੋ Min ᬢ β ​​
Title: Re: TalkTalk HG 635 Firmware
Post by: kitzuser87430 on October 31, 2014, 01:04:07 PM
OK.

My HG635 has arrived and has been set-up. I deleted the default TR069 VDSL connection can anybody paste the default connection settings.

Thanks in advance

Ian

EDIT 02:30 PM: Did not require this in the end...I just added tr069 to my adsl connection.
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on October 31, 2014, 01:18:57 PM
   Save your current settings then reset via the gui or a paper clip or biro in the reset hole on back will return you to the factory defaults. Then after getting what you need upload your saved settings and edit as needed.  It would be handy for others if you could do screen prints of the default connection settings if you do the reset.  Otherwise someone may be able to paste what you need?
Title: Re: TalkTalk HG 635 Firmware
Post by: datasegment on October 31, 2014, 07:04:11 PM
I don't believe the data in the config file is either encrypted, or in a strange character set we don't get- for me, config files (for simple, non-protected data) are always in tokenized form, In other words, token followed by value. Repeated pairs, usually preceeded with a count of pairs or terminating with an end marker token, thus allowing saving of multiple profiles and allowing selection of one or more by simply reading through until you hit the version you want.

Unfortunate on two counts, as 1) I'm totally wrong- in which case apologies. 2) The interpreter that reads the config file and inserts the data knows the tokens, knows the format of the contained datastring, and will interpret as needed.

May be worth investigating though? Rather than trying to read the file through a simple text reader, hex editor or translator?

In the end though- I now have tty access from the config file given earlier (second draft) although SH access is spotty- only every second command works? (I am using windows though - maybe my tty encoding is wrong over PuTTY)

D.
Title: Re: TalkTalk HG 635 Firmware
Post by: npr on October 31, 2014, 08:02:40 PM
No problem here using windows 8.1 with putty or with windows own telnet client.

@les-70 The usb memory stick method works perfectly for copying modified files into the router.
Thanks for the tip.
Title: Re: TalkTalk HG 635 Firmware
Post by: kitzuser87430 on October 31, 2014, 08:11:17 PM
I have a problem here ...my chromebook cannot connect using the default username

Quote
Invalid username '!!Huawei'

I have to rdp into my server and use putty.

@npr I presume you have had no luck changing the telnet username and password.

My first impressions are very good...a great connection speed and I get no extra delay on my ping monitor http://f8lure.mouselike.org/proxyfirebrick.asp?ID=53705 (http://f8lure.mouselike.org/proxyfirebrick.asp?ID=53705)

Ian
Title: Re: TalkTalk HG 635 Firmware
Post by: npr on October 31, 2014, 08:24:52 PM
The telnet password changes if you changed the admin password in the GUI.
Haven't found the telnet username yet, I would think it will be in that Chinese file. ;)

You said previously that you had disabled TR069. I'm surprised the ping graph is working with that disabled.
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on October 31, 2014, 09:17:56 PM
  @datasegment  i am bit confused re tty access? Are you going in via the serial port or as is easier via telnet.
Title: Re: TalkTalk HG 635 Firmware
Post by: datasegment on October 31, 2014, 10:18:02 PM
Using the replacement config file posted here, and replacing the relevant sections from my internet settings to allow my vdsl line to actually connect :) Then connecting via PuTTY on the standard telnet port, which apparently isnt stealthed :( Although I have changed the default password in the file provided with my own to help slow down hackers while I play, and will be putting an ACL in to block that particular port from the WAN.

D.
Title: Re: TalkTalk HG 635 Firmware
Post by: kitzuser87430 on October 31, 2014, 10:41:31 PM
@npr sorry forgot to say i did indeed enable tr069

@datasegment
Quote
standard telnet port, which apparently isnt stealthed

mine was??

Ian
Title: Re: TalkTalk HG 635 Firmware
Post by: npr on October 31, 2014, 10:48:20 PM

@datasegment
Quote
standard telnet port, which apparently isnt stealthed

mine was??


All ports between 0 to 1055 are stealthed here.
Title: Re: TalkTalk HG 635 Firmware
Post by: datasegment on October 31, 2014, 11:33:58 PM
Could somebody post a totally blocked config file then? I had two ports open, 23 and 1024 (<--bloody murkysoft). Firewall profile set to 'low' as setting it to high stops me accessing *anything !

D.
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on November 01, 2014, 09:01:16 AM
  I am puzzled by what you are finding. I trust that you have  not used the full firmware files in the opensource zip. but just a config file. 

 The only port that should be open is the TR069 port.  I originally had that blocked with TR069 off.  With TR069 on you can't port forward to block it.  The current config should have that port 7547 open so TR069 can work.  I don't like that but its inevitable with  TR069.

 If it is the latest config file is at fault then I can only assume settings were lost when configuring it.  I attach another one that I just made, please do try it.  If that cures the problem I guess it must be a fault in the latest settings caused when I added TR069 in. I deleted the WAN connection and started afresh, that may have been the problem. This time I just edited the WAN.




   So please try the one below and see if it fixes things.  If not a a download from some one else may help. 

   Please let me know it case the previous file needs replacing.
Title: Re: TalkTalk HG 635 Firmware
Post by: npr on November 01, 2014, 09:47:55 AM
@ datasegment

Have you checked if there's any port forward rules active?
Have you disabled UPnP?

Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on November 01, 2014, 03:27:21 PM
  @datasegment when trying the new config file make sure you don't have more than 4 resyncs in a day and ideally leave the HG635 off for just over 30 mins each time.  Hopefully the DLM should ignore the resyncs then.
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on November 01, 2014, 07:01:18 PM
 I added a new WAN connection and can confirm that having done that port 23 is open on the wan.  Port forward can be used to put it stealth but I can't seem to repeat what I did before to get all stealth with no port forward.
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on November 01, 2014, 07:24:36 PM
  I am not able to try it for a couple of days but here is an open WAN port 23 suggestion for testing by me or another.  The opensource firmware used port 23 for its TR069.  If with a new WAN,  port 23 is open then setting the port in remote management to 23 saving then back to the correct value of 7547 and saving may fix it.  This test would not involve a resync.
Title: Re: TalkTalk HG 635 Firmware
Post by: loonylion on November 01, 2014, 09:06:19 PM
  I am not able to try it for a couple of days but here is an open WAN port 23 suggestion for testing by me or another.  The opensource firmware used port 23 for its TR069.  If with a new WAN,  port 23 is open then setting the port in remote management to 23 saving then back to the correct value of 7547 and saving may fix it.  This test would not involve a resync.

I really would not suggest having 23 open to WAN under any circumstances.
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on November 01, 2014, 09:14:08 PM
  I think we all agree on that!!  The concerned posts are about closing it should it be open.  I don't know if datasegments has resolved his issue yet but he is only one reporting an actual issue. I have been trying to reproduce the issue with a view to ensuring it does not happen by accident.  Anyone using any new device or new config should do a shields up test of all ports.
Title: Re: TalkTalk HG 635 Firmware
Post by: npr on November 02, 2014, 12:46:19 PM
I've just tested this using standard v1.04t firmware with les-70's config file.
That is the original config file with the remote management port set to 23 but since changed to 7574.

With Remote management enable I created a new WAN connection, including using TRO69.
The port used by remote management remained 7574.
ShieldsUp showed all the first 1055 ports to be stealth.

Sorry, I couldn't duplicate this bug.
Perhaps the original, uncorrected, open source config file was used.


Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on November 03, 2014, 06:12:12 PM
I think there is bug which means things need to be changed in some unknown order in order to work correctly.  When things are working correctly the port selected in remote management is open.  That is correct.  The default config file from the open source file had that port set at 23 as a default but when using that open source firmware changing the remote management 23 to the correct value closes 23 and opens the correct one selected for TR069.   Sometimes, and it has happened to me and clearly to datasegment, the although the port selected under remote management changes Ok port 23 seems to open and stay open as well.  I will try to explore the cause but things should be fine as long as you use and pass a "shields up" check. 

  Hopefully the config files below will work OK.  Unless there is real need it may be best just edit things and not create new wan's.  I would also only change the device IP if there is real need.  With that in mind there are two files below one with 192.168.1.1 and one with 192.168.0.1.

As a reminder

   1.  Under maintain/device save your current configuration settings as you will need them to easily get back to normal.

    2. Under maintain/device upload the attached device settings file to the TT super router. 

    3. If that works you may/should have telnet access with login of !!Huawei  / @HuaweiHgw

    4.  The settings are some sort of default and I take no responsibility at all for them.   

    5.  An upload of the config file you first saved should return you to normal if your not happy
Title: Re: TalkTalk HG 635 Firmware
Post by: npr on November 03, 2014, 09:43:43 PM
Do you know if the port is still stealth after a reboot?

Sorry I can't do much testing on this at present, I don't want to risk my new found sync speed by dropping the connection.
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on November 04, 2014, 07:41:56 AM
  The problem in providing these files is that my HG635 is running the full open source firmware so the real test has to be someone else.  You should not have any impact on your sync if the current down stream snrm is at or above about 6.3.  If it is lower then a resync may loose a bit of speed. Also no more than 4 resyncs a day should should not impact a line.  Are your error rates OK? e.g. how may ES per day do you get?
Title: Re: TalkTalk HG 635 Firmware
Post by: npr on November 04, 2014, 10:51:41 AM
The DLM on my line doesn't know those rules.
Aluminium wires don't help.  >:(

I can confirm after a reboot, my HG635 remains stealth on all the first 1055 ports.
Router running standard firmware v1.04t with your first config file, remote management port previously changed to 7574.

Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on November 04, 2014, 11:24:47 AM
  The new files are based on that original file starting point with the 7574 port and TR069 enable changes made.   I will wait until someone tries them.   From my tests I think it must be order in which edits are made that can cause things to go wrong.  It may be to do with changing the remote management port on a connection that does not have TR069 enabled - or the other way round!


 I also changed the base IP in one and added  under "connection mode" fibre a pppoe  connection for the wan.  This allows the use of another modem which has helped me test things by allowing experiments and reboots without an actual modem resync.  If you were using that option it is however most unlikely that you would want telnet. 

  PS I find the HG635, like other modems with the same chipset, gives more errors than an HG612, that may be an issue if you have a poor line.
Title: Re: TalkTalk HG 635 Firmware
Post by: kitzuser87430 on November 04, 2014, 12:18:36 PM
Quote
my HG635 is running the full open source firmware

Interesting; any info on how to do this.

Ian
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on November 04, 2014, 05:13:42 PM
  Start reading from http://forum.kitz.co.uk/index.php?topic=14185.msg271959#msg271959    !   I would not recommend try it unless someone can get a copy of the official firmware image out of a HG635 via telnet.    Without the official image there is no going back!!   
Title: Re: TalkTalk HG 635 Firmware
Post by: npr on November 04, 2014, 07:19:10 PM
Someone who can work with iptables ought to be able to sort this all out via the telnet.  Update ==  it is report that provided TR069 is enabled the WAN ping and setting to TBB works via adding it to the acl.

The following iptables rule will allow TBB ping graph with TR069 disabled.
Quote
su
iptables -I INPUT_SERVICE_ACL 1 -p icmp --icmp-type echo-request -j ACCEPT

The iptable rules in the ACL section of the firewall can be viewed with the following.
Quote
su
iptables -L INPUT_SERVICE_ACL --line-numbers
Note: "su" is only needed once in a session.
If you make a mistake with this, a reboot restores the original settings.
So far I can't find a way to save these settings, they are lost on a reboot.
There's no iptables-save command -- any ideas anyone?
Title: Re: TalkTalk HG 635 Firmware
Post by: kitzuser87430 on November 04, 2014, 08:38:51 PM
Hmmm..

When i try
Quote
iptables -L INPUT_SERVICE_ACL --line-numbers

I get an error "Permission denied:You must be root"

I am also having trouble reading/writing my USB device from the putty shell....I cannot cd into the mount point???

Also digging and testing today. I have always unchecked the checkbox "Enable remote management"  on the http://192.168.1.1html/advance.html#tr069 (http://192.168.1.1html/advance.html#tr069) page.

But have had to check the tr069 checkbox on the wan page (see attached piccy)this then enabled pings on the wan and port 7547 is stealth.

IAn

Title: Re: TalkTalk HG 635 Firmware
Post by: npr on November 04, 2014, 09:03:22 PM
Sorry I should have added, issue su to become root.

If I disable remote management the port 7574 is stealth.
If you allow pings the shieldsup will report the test as failed due to "Ping Reply: RECEIVED (FAILED)"

Title: Re: TalkTalk HG 635 Firmware
Post by: kitzuser87430 on November 04, 2014, 09:40:12 PM
Quote
If you allow pings the shieldsup will report the test as failed

Yep....that is why i have two acl's on my firewall

Job done.

Quote
su

damn....I tried sudo not su

Ian
Title: Re: TalkTalk HG 635 Firmware
Post by: npr on November 04, 2014, 10:15:43 PM
The default ACL config only has 3 rule and all are access direction LAN.
See my screen capture here:
http://npr.me.uk/hg635.html

You appear the have at least 3 in the WAN direction --- are you sure you need those?
Title: Re: TalkTalk HG 635 Firmware
Post by: kitzuser87430 on November 05, 2014, 08:23:25 PM
Quote
are you sure you need those?

No....I deleted the WAN HTTP acl that was not needed; the other 2 ICMP (WAN) acl's only allow ping's from my monitoring websites IP addresses, so these are required.

Ian

Title: Re: TalkTalk HG 635 Firmware
Post by: npr on November 07, 2014, 02:32:59 PM
Not surprisingly I've bricked the HG635 while experimenting with telnet, not exactly sure but I may have corrupted the "/etc/init.d/rcS" file.
Power light was on red, no other signs of life.

The good news is I've managed to restore it by installing one of the image files referred to earlier in this thread. This is how I did it:
Quote
1) starting with the router powered off
2) place the PC's ethernet port on a static IP address (I used 192.168.1.100)
3) press the routers reset button with a paperclip holding it in for about ten seconds while the router powers up.
4) If the power light stays green continue, if it goes red after about 20 seconds repeat step 3).
5) if the power light remains green connect to the PC via ethernet.
6) In a browser (I used Firefox) go to 192.168.1.1
7) if all is well the web page will ask for the location of the firmware image file, enter this and press install.
8 ) The web page says it will take 2 minutes to install. There was no indication when it was done, so after the 2 minutes I reloaded 192.168.1.1 and found the routers alive and kicking.  8)

@les-70
You may be interested to know I intalled the image file "HG635v1.04t_multicast_with_multicfg_pack.bin" and it looks very much like the vanila talktalk firmware. The remote management settings are all default TT using port 7574 etc.
The bad news is, by default telnet doesn't work with this firmware.


Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on November 07, 2014, 03:03:52 PM
  Only the HG635v1.04t_multicast_with_multicfg_main.bin file has telnet.  I am surprised that you managed to brick it, normally it is almost impossible to do that except by uploading duff firmware.   Thanks for the comments on the multicfg_pack version.  I have been running that version with the config file applied myself.  It looked the most up to date.

You should still be able to enable telnet with one of the above config files.  You will at least then be able to test the latest config files above.  If you have any trouble i still have the first one I made available.
Title: Re: TalkTalk HG 635 Firmware
Post by: npr on November 07, 2014, 05:21:06 PM
I am surprised that you managed to brick it, normally it is almost impossible to do that except by uploading duff firmware. 

Bricked it 4 times now  ???
It doesn't like a new file being placed in /etc/ or /usr/
It's ok until you turn it off then it refuses to boot.
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on November 08, 2014, 09:30:12 AM
  I am puzzled by what your doing, Surely /etc/ and most of the rest of the file system is in read-only memory. Just to be sure i tried adding a file and only get read-only failures.
Title: Re: TalkTalk HG 635 Firmware
Post by: npr on November 08, 2014, 12:09:47 PM
I'm just messing around and learning my way around busybox.
My hope is to be able to run a script at startup to configure some settings not available in the gui. eg the settings which get lost on reboot like the iptables setting to allow ping from wan.

Commands I've found useful for changing read only files / folders:
su
mount -n -o remount,rw /

So far I've discovered not to add or modify files in the folders /etc/ and /usr/ , that bricks the router on the next boot.

Folder /tmp/ gets wiped on boot.

Folder /config/ does not get wiped on boot.

What I need now is to be able to run a script in the folder /config/ on boot ---- any ideas?

The main thing I've learned is don't mess with the file system in this router unless you're prepared to brick the router.  ;D
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on November 08, 2014, 03:07:01 PM
  Thanks for the info, and yes I tried, and had the red light!  I don't know how you could make a script run from config on boot.  It is easy to automate and command file to login into the router a change things though.
Title: Re: TalkTalk HG 635 Firmware
Post by: broadstairs on November 26, 2014, 06:18:57 PM
    3. If that works you may/should have telnet access with login of !!Huawei  / @HuaweiHgw

Well I tried telnet and it asks for user & pw but neither of these worked which ever combination I tried, which is supposed to be the user andme and which the p/w?

Stuart

Edit: I just tried the 11.txt file and cant login in as it wonr respond to the IP.
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on November 26, 2014, 06:45:07 PM
  The user name is   !!Huawei   and the password  @HuaweiHgw  .  The 11.txt worked for me, if not try the one in http://forum.kitz.co.uk/index.php?topic=14185.msg273357#msg273357 .   As I have commented I no longer have standard TT firmware and can't do proper tests myself, I rely on reports and only npr has given much feedback.

 I have some older files which worked for npr but were removed as they needed some manal settings to allow TT firmware updates to be enabled.   
Title: Re: TalkTalk HG 635 Firmware
Post by: kitzuser87430 on November 26, 2014, 08:15:23 PM
Quote
user & pw
If you change the password for the admin (gui) login......then the  telnet password for the username   "!!Huawei" becomes the new password.

I used the conf attached
(Default ip address)
Ian
Title: Re: TalkTalk HG 635 Firmware
Post by: broadstairs on November 26, 2014, 09:06:09 PM
Well I cannot get the HG635 to respond to any IP address I've tried with that 11.txt file loaded as a config. I also tried a reset via the button on the back and still it does not seem to work.

Stuart
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on November 26, 2014, 09:23:57 PM
   It definitely won't work after a reset.  That will take you back to TT firmware defaults. 

The config file just needs to be uploaded and will survive reboots but not a reset.  The gui and telnet should both be on 192.168.1.1 with that file.  The O1 file should give IP 192.168.0.1. (unless I miss labeled them) The gui login is the usual admin/admin.   I can only suggest trying other one I suggested.   There is also the one kitzuser87430 has provided but he may have altered the password??
Title: Re: TalkTalk HG 635 Firmware
Post by: broadstairs on November 26, 2014, 09:28:03 PM
I tried the 01 file and that worked but telnet did not take the user/password. So I thought I'd try the 11 file but once loaded I could not find the router via the ethernet cable (only my laptop connected via cable and wireless off). So I thought I'd try a hard reset to get back to TT defaults but that has not worked either unless I'm not doing the hard reset correctly. Still the router is not showing up and the IP given to my laptop is .0.253.

Stuart
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on November 26, 2014, 09:55:34 PM
  A hard reset has always worked for me but I find the reset button a bit unreliable and needing the right length of push what ever that might be! I think the gui may be the best way to do it.   A port scan should find the HG635 maybe 0.254 if the laptop is 0.253


  Try the other file I mentioned "new downloadconfigfile.txt" that should be 1.1 and was an earlier quiet separate but less tested version.  I used a personalised 01 but will try the 11 file myself tomorrow, as I said there have been a few files to try but no reports of which ones people find work OK or have trouble with. As a result things are not as I would like.   I am baffled re it not taking the user/password -- as is normal it is case sensitive. 

  edit you havn't got a fixed ip of 0.253 on the laptop have you?
Title: Re: TalkTalk HG 635 Firmware
Post by: broadstairs on November 27, 2014, 07:15:15 AM
you haven't got a fixed ip of 0.253 on the laptop have you?

I feel an idiot now, yes I had set that when I was playing with the HG612 so as to make sure when I connected it to the lan it did not conflict with the ZyXEL.

Now I will try again with those files....

Stuart
Title: Re: TalkTalk HG 635 Firmware
Post by: broadstairs on November 27, 2014, 07:22:11 AM
Now I have corrected my settings I tried again with the 01 file and yes I can get the stats OK from telnet. So now I'll set it up so it can be used in place of the ZyXEL and the HG612 later in the week.

Stuart
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on November 27, 2014, 07:41:56 AM
  When it is online do check with a shields up that all is in stealth.  Somewhere in those files there seems to be memory that port 23 can also also be used for remote update over the WAN.  If port 23 is open on the WAN it seems to be open for TR-069 and not quite the severe risk it first seems. I have had trouble with that issue since I set TR-069 enabled so as insure updates would occur.  An update to 1.06t is supposed to be due and I think after that I will upload a version with no TR-069

I found the HG635 to be more like the Xyxel than the HG612 and you can't cap speeds on the HG635 - it is not supported.  I am hoping it might be in the update which is due.  With telnet you will be able to decide for self what the performance is like.  I hate anything locked down!!
Title: Re: TalkTalk HG 635 Firmware
Post by: npr on November 27, 2014, 09:00:44 PM
There's hints that TT have started pushing out firmware v1.06t
https://community.talktalk.co.uk/t5/TalkTalk-Labs-Trials/Fancy-taking-part-in-the-Huawei-HG635-v1-05t-Firmware-Trial/td-p/1430031/page/3


Title: Re: TalkTalk HG 635 Firmware
Post by: kitzuser87430 on November 29, 2014, 08:31:05 AM
Quote
TT have started pushing out firmware v1.06t

Yep.....tried to log into the gui this morning...locked out.....reboot....v1.06

Config not changed (on plusnet ADSL) grc shields up scan .....passed full stealth


Now to test the wifi stability

IAn
Title: Re: TalkTalk HG 635 Firmware
Post by: broadstairs on November 29, 2014, 08:36:24 AM
Does anyone know yet if you can still get stats via telnet using one of the alternative config files on the 1.06 firmware?

Stuart
Title: Re: TalkTalk HG 635 Firmware
Post by: kitzuser87430 on November 29, 2014, 08:42:40 AM
Quote
if you can still get stats via telnet

Yes .....nothing changed at all with my config.

In fact the stats were harvested all night (ppp/internet dropped at 01:00) and I presume the gui was locked out at that time.

Ian
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on November 29, 2014, 09:44:02 AM
 With 1.06t firmware please could you try a "xdslcmd info --version" command on telnet and report the outcome.  Also the outcome from xdslcmd on its own.  I am interested to see if there are any dsl driver changes.
Title: Re: TalkTalk HG 635 Firmware
Post by: kitzuser87430 on November 29, 2014, 03:41:02 PM
Quote
any dsl driver changes.

Still A2pv6F039e

will post more info when using my windows laptop sometime.

Ian
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on November 29, 2014, 04:10:28 PM
   Thanks for that.  I guess the xdslcmd on its own will show the same options but it would be good to try it sometime.  It may be possible to have updated options available even if the driver version has not changed.
Title: Re: TalkTalk HG 635 Firmware
Post by: phi2008 on December 01, 2014, 06:06:02 AM
Does the HG635 support bridge mode?
Title: Re: TalkTalk HG 635 Firmware
Post by: kitzuser87430 on December 01, 2014, 06:37:18 PM
Quote
Does the HG635 support bridge mode?

Yes

My spare hg635 recieved the update to firmware v 1.06 this afternoon, this router was on the open source software (HG635v1.04t_multicast_with_multicfg_main.bin) the only thing i changed was the "Connection request username:" from the default (userid) to the tt firmware setting of cpeuser.

Ian
Title: Re: TalkTalk HG 635 Firmware
Post by: broadstairs on December 02, 2014, 01:29:55 PM
My HG635 got updated this morning and caused me a whole load of grief. My wife's laptop would not connect to the internet and eventually after digging into W8.1 for ages I eventually found that the DHCP server part of the HG635 setup needed re-doing as it was not providing gateway and dns addresses, and once saved everything started up OK. NOT impressed - this should NOT happen.

One thing I have done it to get the help info for the xdslcmd from the f/w  as here:-

Code: [Select]
$ xdslcmd --help
Usage: xdslcmd start [--up] [--mod <a|d|l|t|2|p|e|m|v>] [--lpair <(i)nner|(o)uter>]
           [--trellis <on|off>] [--snr <snrQ4>] [--bitswap <on|off>] [--sesdrop <on|off>]
           [--sra <on|off>] [--CoMinMgn <on|off>] [--i24k <on|off>] [--phyReXmt <0xBitMap-UsDs>]
           [--TpsTc <0xBitMap-AvPvAaPa>] [--monitorTone <on|off>]
           [--profile <0x00 - 0xFF>|<"8a |8b |8c |8d |12a |12b |17a |30a">] [--us0 <on|off>]
           [--dynamicD <on|off>] [--dynamicF <on|off>] [--SOS <on|off>]
           [--forceJ43 <on|off>] [--toggleJ43B43 <on|off>]
       xdslcmd stop
       xdslcmd connection [--up] [--down] [--loopback] [--reverb]
           [--medley] [--noretrain] [--L3] [--diagmode] [--L0]
           [--tones] [--normal] [--freezeReverb] [--freezeMedley]
       xdslcmd configure [--mod <a|d|l|t|2|p|e|m|v>] [--lpair <(i)nner|(o)uter>]
           [--trellis <on|off>] [--snr <snrQ4>] [--bitswap <on|off>] [--sesdrop <on|off>]
           [--sra <on|off>] [--CoMinMgn <on|off>] [--i24k <on|off>] [--phyReXmt <0xBitMap-UsDs>]
           [--TpsTc <0xBitMap-AvPvAaPa>] [--monitorTone <on|off>]
           [--profile <0x00 - 0xFF>|<"8a |8b |8c |8d |12a |12b |17a |30a">] [--us0 <on|off>]
           [--dynamicD <on|off>] [--dynamicF <on|off>] [--SOS <on|off>]
           [--forceJ43 <on|off>] [--toggleJ43B43 <on|off>]
       xdslcmd bert [--start <#seconds>] [--stop] [--show]
       xdslcmd afelb [--time <sec>] [--tones] [--signal <1/2/8>]
       xdslcmd qlnmntr [--time <sec>] [--freq <msec>]
       xdslcmd inm [--start <BB_THRESH 10*dB> <INMIATO> <INMIATS>] [--stop] [--show]
       xdslcmd snrclamp [--shape <shapeId>] [--bpshape [bpIndex-bpLevel,]]
       xdslcmd diag [--logstart <nBytes>] [--logpause] [--logstop] [--loguntilbufferfull <nBytes>]
           [--loguntilretrain <nBytes>]
       xdslcmd info [--state] [--show] [--stats] [--SNR] [--QLN] [--Hlog] [--Hlin] [--HlinS] [--Bits]
           [--24hrhiststat]
           [--pbParams] [--linediag] [--linediag1] [--vdsllinediag] [--adsllinediag] [--total] [--testparam]
           [--toneGroupObjects][--reset] [--vendor] [--cfg]
       xdslcmd profile [--show] [--save] [--restore]
       xdslcmd --version
       xdslcmd --help

as I believe someone wanted to see it. At least the telnet access and I think everything else worked apart from DHCP.

Stuart
Title: Re: TalkTalk HG 635 Firmware
Post by: broadstairs on December 03, 2014, 10:47:57 AM
This morning I have been put back on fastpath. The issue is that I guess the router probably done a re-sync because my DHCP manual DNS server settings have been wiped out again meaning nothing gets any DNS server addresses if they are on automatic, fixed IPs are OK. I will report this to TT today.

Stuart
Title: Re: TalkTalk HG 635 Firmware
Post by: npr on December 03, 2014, 06:14:00 PM
I had the same issue of custom dns settings in DHCP being regularly lost with the old v1.04t firmware. I was hoping this issue would be fixed with new firmware.
Doesn't cause a resync though.  ???

Still waiting for the upgrade here, anyone know if remote management needs to be enabled for this to happen ?

Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on December 03, 2014, 06:30:12 PM
I don't "know" but the TR069 connection and remote mange management would normally both need to enabled.  Make sure you do a shields up if you make those changes with one of the old configs.  They are already enabled in the newer ones. 
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on December 03, 2014, 07:05:54 PM
   My HG635 updated as soon as it was swapped in today - from the version in the opensource distribution.  Not impressed.  At 1m seems 1.06 seems to have taken about 5mb/s off both 2.4 and 5g throughput plus gaining a number of niggles reported elsewhere.  Nothing positive as far as I can tell.
Title: Re: TalkTalk HG 635 Firmware
Post by: phi2008 on December 03, 2014, 07:59:28 PM
My HG635 got updated this morning and caused me a whole load of grief.

I switched over to TalkTalk today and also had issues. Had my HG635 connected waiting for TalkTalk to migrate me over and was using WiFi, almost as soon as the connection went live I lost and could not regain WiFi connectivity - resorted to a factory reset in the end and found it had been updated to 1.06t.  :-\
Title: Re: TalkTalk HG 635 Firmware
Post by: npr on December 03, 2014, 08:18:45 PM
I enabled TR069 last week but haven't received the update yet. I'll enable remote management now and see how long it takes.

Update:
Updated to v1.06t within about 3 minutes of enabling remote management.

The update process did cause a resync.

Routers Log report:
20:20:06 03/12/2014   System   Warning   Reboot from the WAN side.
20:20:06 03/12/2014   System   Notice   Upgrading finished: cwmp.
20:19:37 03/12/2014   User Level   Notice   CWMP:Cwmp post inform success.
20:19:37 03/12/2014   System   Warning   Upgrading beginning.

Edit 2:
The pinhole reset button is not working after the FW update.

After doing a factory reset through the GUI, telnet no longer works.

Also had the following hacking attempt.
Quote
20:51:45 03/12/2014    User Level    Notice    User sh login fail by telnet 186.223.109.178.
20:51:03 03/12/2014    User Level    Notice    User root login fail by telnet 186.223.109.178.
20:50:25 03/12/2014    User Level    Notice    User root login fail by telnet 186.223.109.178.
20:49:45 03/12/2014    User Level    Notice    User root login fail by telnet 186.223.109.178.
20:49:06 03/12/2014    User Level    Notice    User root login fail by telnet 186.223.109.178.
20:48:26 03/12/2014    User Level    Notice    User root login fail by telnet 186.223.109.178.
20:47:47 03/12/2014    User Level    Notice    User root login fail by telnet 186.223.109.178.
20:47:08 03/12/2014    User Level    Notice    User root login fail by telnet 186.223.109.178.
20:46:28 03/12/2014    User Level    Notice    User root login fail by telnet 186.223.109.178.
20:45:49 03/12/2014    User Level    Notice    User root login fail by telnet 186.223.109.178.
20:45:10 03/12/2014    User Level    Notice    User root login fail by telnet 186.223.109.178.
20:44:30 03/12/2014    User Level    Notice    User root login fail by telnet 186.223.109.178.
20:44:02 03/12/2014    User Level    Notice    User admin login from 192.168.1.2 successfully.
20:43:51 03/12/2014    User Level    Notice    User root login fail by telnet 186.223.109.178.
20:43:12 03/12/2014    User Level    Notice    User root login fail by telnet 186.223.109.178.
20:42:33 03/12/2014    User Level    Notice    User root login fail by telnet 186.223.109.178.

Now disabled "remote management".


Title: Re: TalkTalk HG 635 Firmware
Post by: broadstairs on December 04, 2014, 10:13:43 AM
My telnet still works OK although I dont need it as I am using an HG612 in bridge mode right now. I had one of the alternate configs loaded which still allows telnet access if you need it after f/w 1.06.

I've had a response from TT this morning where I reported the DHCP failure with this f/w. They have passed it to their product team for investigation which probably means we will not here anything for a week or two.

Stuart
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on December 04, 2014, 12:14:38 PM
I am considering reverting back to the HG635v1.04t_multicast_with_multicfg_pack.bin from which I had the upgrade work or maybe HG635v1.04t_multicast_with_multicfg_main.bin which has telnet but is further from the 1.04t default TT  settings.

  I may then disable remote update until such time as any real improvements from the original 1.04t firmware are reported by others.  For me 1.06t only has disadvantages and whilst fixing the DHCP would be good the advertised wireless improvements are definitely negative for me. I can't detect a gain with 1.06t
Title: Re: TalkTalk HG 635 Firmware
Post by: broadstairs on December 04, 2014, 01:01:33 PM
Are the other f/w packages available anywhere as sadly I don't have any copies to go back to.

I have asked TT for a copy of 1.04 since their update gave me an issue I didn't have before. Don't hold your breath though.

Stuart
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on December 04, 2014, 04:38:17 PM
   The firmwares I have been using are in a folder in output in the opensource distribution.

  http://consumer.huawei.com/en/support/downloads/detail/index.htm?id=28981

 We think HG635v1.04t_multicast_with_multicfg_pack.bin is almost if not the same as the "proper" TT 1.04t and with no telnet.   It definitely updates to 1.06t unless you disable TR069/and/or the remote management

  The version HG635v1.04t_multicast_with_multicfg_main.bin has telnet enabled and can be made safe and hopefully compatible with updates but in its raw state telent is open on the WAN and the remote update settings are not the usual ones and may not work unless changed. It is vital to change the remote update port from 23 to disable telnet on the wan.  Telnet open on the wan is a bad a security issue.  Repeated shields up checks should help keep you safe but when fiddling with the telnet version don't assume it is OK but check for all changes.

 If your not using the modem  HG635v1.04t_multicast_with_multicfg_pack.bin should be fine and with a config telnet should work. 


  I guess it depends how much 1.06t is annoying you. 
Title: Re: TalkTalk HG 635 Firmware
Post by: broadstairs on December 04, 2014, 05:28:06 PM
Thanks for pointing me at that. The current f/w bothers me because my wife's laptop is likely to not be able to access the internet if I get a re-sync. I know it is easily fixable but it will probably happen when I'm not around  :( So I might try one of those.

Stuart
Title: Re: TalkTalk HG 635 Firmware
Post by: s60sc on December 06, 2014, 10:02:32 PM
Thanks to this thread I was able to enable telnet on my new TalkTalk Super Router v1.06, using the 11.txt file, so that I can now monitor it using dslstats.

After modifying the configuration to work with TalkTalk VDSL, the only issue I had was port 23 was open to the world. After some investigation I found the following rule in iptables chain INPUT_SERVICE_ACL
ACCEPT     tcp  --  anywhere             anywhere            tcp dpt:telnet
Once I deleted that rule then port 23 was stealthed, and stayed so after reboot.
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on December 07, 2014, 09:20:48 AM
  Thanks for the very interesting report.  Yes modifying some settings seems to open up port 23 on the WAN.  I did not however think that an iptable mod would survive a reboot. I will try it out ...   


Edit yes - telnet in - su for super user -  then list iptables and delete that line - seems to work and persist.  I am not familiar with editing  iptables and I needed a quick google to find suitable commands. 
Title: Re: TalkTalk HG 635 Firmware
Post by: broadstairs on December 08, 2014, 09:54:04 AM
I have asked TT for a copy of 1.04 since their update gave me an issue I didn't have before. Don't hold your breath though.

Well I got the expected result from TT, they are unable/unwilling to provide a copy of 1.04 for me to load locally. This in my view is unacceptable. There is always the possibility for a problem to happen during the roll out after testing which make the router unsuitable for the end user to continue to use so they really should have a copy available which the end user could load locally to downlevel to a working version.

Stuart
Title: Re: TalkTalk HG 635 Firmware
Post by: broadstairs on December 09, 2014, 10:23:24 AM
Having pestered them they now say they are willing to downlevel my router to 1.04 remotely which I have agreed to. In the process of enabling TR069 it then lost my manual DNS server addresses in DHCP settings again - good job I checked. Anyway will wait and see what happens.

Stuart
Title: Re: TalkTalk HG 635 Firmware
Post by: broadstairs on December 10, 2014, 01:10:11 PM
Well TT downloaded 1.04 remotely today to my router but the strange things was that although my DNS settings disappeared again there was no indication of a reboot in the router log. Anyway will see what happens now, I've disable TR069 and Remote Management in the router so it wont update again. I've rebooted the router manually to make sure it is OK and once again my DNS addresses were not there after the reboot! I'm sure that was not happening before. I'll do some more testing.

Stuart
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on December 10, 2014, 01:31:55 PM
  That sounds odd.  A hard reset should ensure the past is forgotten.  If not as I said above the version HG635v1.04t_multicast_with_multicfg_pack.bin worked perfectly for me (no telnet version) and also updated OK. 
Title: Re: TalkTalk HG 635 Firmware
Post by: npr on December 10, 2014, 03:18:33 PM
I find both firmware versions to have dns issues:

Both versions forget custom dns settings in the DHCP section of the GUI.
However v1.06t is still issuing the correct dns IP's to my devices even though my custom settings have long since disappeared from the GUI.

Most routers I've used just have a dns relay, the HG635 however has a dns catching resolver.
The cache is a nice feature, but the resolver is pathetically slow taking over twice the time to forward a lookup to my ISP than it would for a direct lookup.

The following DNS benchmark graph shows the HG635 DNS resolver on ip 192.168.1.1.
The two ISP DNS resolvers the router forwards to are 212.159.6.10 and 212.159.6.9
Graph key:
Red == cached time
Green == uncached time
Blue == uncached "dot com" time

(https://forum.kitz.co.uk/proxy.php?request=http%3A%2F%2Foi57.tinypic.com%2Ffnxmxy.jpg&hash=33f0bf7a8f8ca613e5384f71909a9feae474890a)
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on December 10, 2014, 04:05:10 PM
 Maybe settings interact? My custom DNS were always OK with HG635v1.04t_multicast_with_multicfg_pack.bin.
Title: Re: TalkTalk HG 635 Firmware
Post by: npr on December 10, 2014, 04:34:57 PM
Is that custom dns in the "internet connection" settings?
They are the DNS IP's used by the routers DNS forwarder which I find to be unacceptably slow and therefore don't use.

The custom dns settings I have problems with are in home network > LAN interface > DHCP server.
I think this is the same settings which broadstairs has problems with.
Title: Re: TalkTalk HG 635 Firmware
Post by: broadstairs on December 10, 2014, 05:29:08 PM
The custom dns settings I have problems with are in home network > LAN interface > DHCP server.
I think this is the same settings which broadstairs has problems with.

Correct.....

Stuart
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on December 10, 2014, 06:34:14 PM
  It is the same ones -- in under DHCP settings that I use.
Title: Re: TalkTalk HG 635 Firmware
Post by: npr on December 10, 2014, 08:02:38 PM
Very strange this firmware.  ???
You find dns setting are ok but have problems with open ports.
Whereas I have dns issues but no problem with open ports.
IIRC broadstairs had problems with both.
As you said it must be some kind of settings interaction.


Title: Re: TalkTalk HG 635 Firmware
Post by: broadstairs on December 10, 2014, 09:09:19 PM
Just to clarify I only have DNS issues, it is all stealth. However I am using an alternate config loaded which also gives telnet access on my lan, although I dont need that right now as I'm still using the HG612 (unlocked) as a modem.

Stuart
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on December 10, 2014, 09:22:41 PM
   I thin I have only had ports open when creating new connections or making major changes such as the changing the modem IP. 

In case it is of relevance I have always saved settings after adding in my own DNS's.    I always keep a copy of the current working config.
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on December 11, 2014, 01:42:30 PM
  I did a hard reset of my 1.06t and yes I also had the issue.  I then uploaded the last used config file and to begin with the dns settings were there.  However after a reboot they have gone again.    Same as you have found.  I guess what ever I had done I have undone it.  I will probably downgrade to the "open source version" when it is convenient.
Title: Re: TalkTalk HG 635 Firmware
Post by: npr on December 11, 2014, 03:44:25 PM
In my experience the open source firmware is no better than v1.06t for losing the dns settings.

This morning I installed your config file in v1.06t, the same config files I've used before in v1.04t without a problem.
Checking with shieldsup showed the telnet port to be no longer stealth. Deleted two "telnet" entries in the iptables and now stealth.

So, looks like we've now duplicated each others issues.


Title: Re: TalkTalk HG 635 Firmware
Post by: s60sc on December 11, 2014, 08:33:20 PM
I'd noticed too that if a config file is reloaded, or the router is powered down, then telnet reappears, so it must be added to iptables by the config file. It appears the initial iptables settings are created by /var/firewall_init.sh on boot up (/var/atp_boot_track.log), then added to when the config file is loaded but I've not found a script for this. It may be possible to switch off telnet via the web interface, as the following appears in /html/js/security.js

if(a=="HTTP"){this.set("deleteDialogBody",Em.I18n.t("AclHttpDialog"))}else{if(a=="ICMP"){this.set("deleteDialogBody",Em.I18n.t("AclIcmpDialog"))}else{if(a=="SAMBA"){this.set("deleteDialogBody",Em.I18n.t("AclSambaDialog"))}else{if(a=="FTP"){this.set("deleteDialogBody",Em.I18n.t("AclFtpDialog"))}else{if(a=="TELNET"){this.set("deleteDialogBody",Em.I18n.t("AclTelnetDialog"))}}}}}},checkProc:function(){if("0.0.0.0"==this.get("activeItem").get("StartIpAddr")){Em.Logger.log("Enter ACL checkProc StartIpAddr .....");

It may be possible to modify the web interface to bring up this dialog, but as the directory is mounted read only and another poster indicated that modifying read only bricked the router (probably failed hash check on contents) then I don't want to try this.
Title: Re: TalkTalk HG 635 Firmware
Post by: npr on December 15, 2014, 10:54:49 AM
Warning, changes made to the routers iptable DO NOT survive a power cycle! 

I had need to turn my HG635 off for a couple of hours yesterday. Today my routers log is full of entries like these:

Quote
00:06:08 15/12/2014   User Level   Notice   User root login fail by telnet 176.35.53.104.
00:05:52 15/12/2014   User Level   Notice   User root login fail by telnet 176.35.53.104.
23:50:34 14/12/2014   User Level   Notice   User root login fail by telnet 190.200.56.168.
23:50:18 14/12/2014   User Level   Notice   User root login fail by telnet 190.200.56.168.
23:50:02 14/12/2014   User Level   Notice   User support login fail by telnet 190.200.56.168.

ShieldsUp shows port 23 as open.
iptable shows a new entry accepting telnet.

Looks like I need to go back to the default config file and not have telnet enabled.
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on December 15, 2014, 11:31:56 AM
I have been uncertain about that.  I edited iptables when off line and after a reboot and still off line and I thought the edit persisted when I looked at iptables.  I will check this later today.   However I then connected to the line and synced and I found that the edit had been removed. I had TR069 and remote management enabled and that may be a factor as that checks a number things after after a reboot.
Title: Re: TalkTalk HG 635 Firmware
Post by: broadstairs on December 15, 2014, 12:06:25 PM
I have only tested port 23 from the wan side (using a telnet client from my Android phone) with both TR069 and remote management disabled and I have never connected. I do have one of the alternate configs loaded but have never (so far) had to play with any iptables etc to get 23 stealthed. Telnet on the lan works fine. I am currently on 1.04t reloaded by TT at my request to downlevel from 1.06t.

Stuart
Title: Re: TalkTalk HG 635 Firmware
Post by: npr on December 15, 2014, 12:17:19 PM
I had TR069 and remote management enabled and that may be a factor as that checks a number things after after a reboot.

Both were disabled here.
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on December 15, 2014, 02:30:56 PM
   Your correct.  It does not survive a just reboot.  The offending iptables line seems to appear in different places when it comes back.  That is probably why I had not immediately noticed the return when off line.  It is strange that these issues did not occur right at the beginning nearly 2 months ago.   I am thinking more now on returning one to square one with one of the open source files.
Title: Re: TalkTalk HG 635 Firmware
Post by: npr on December 15, 2014, 05:10:23 PM
I never had this problem with firmware v1.04t when used together with your config file.
So I'm guessing it's a issue with v1.06t when used with your file.

It may be worth going back to your original post which linked to the config file and putting a warning about v1.06t and port 23 becoming open after a reboot.

IMO this feature makes v1.06t unfit for use with the telnet config file. In fact I'm failing to see any benefits of v1.06t over v1.04t. I'm not prepared to risk another reboot causing my routers log again becoming full of hacking attempts, so like you, I'm going back to v1.04t.

Just remembered about the disappearing custom dns in the dhcp server settings -- the settings no longer show in the GUI but are still being assigned to my devices.

This really is buggy firmware, if the router didn't give me a much needed speed boost I think it would be in the bin before now.
Title: Re: TalkTalk HG 635 Firmware
Post by: broadstairs on December 17, 2014, 09:59:32 AM
TalkTalk have just replied to my thread on theDNS issue and said that using your own DNS server addresses is not supported and may not work. IF they can recreate the problem then they will fix it at some future time in a new f/w release..

Stuart
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on December 17, 2014, 01:27:18 PM
   I have gone back to the 1.04t images in the open source.  Things seem much better and nothing at all seems worse, but as it did in the first place it remains possible to find port 23 open when you do some things.  I will try to see if I can track down which things. 

   One oddity in the opensource files is the file HG635v1.04t_packet_config.bin which is a firmware file but "not as we know it".  You use it like a firmware file but it only replaces the current config with a config that looks identical the actual telnet firmware version HG635v1.04t_multicast_with_multicfg_main.bin.  i.e. it acts identically to a config file and reset get rid of its settings.   It looks like a file that an ISP could use in remote update to get telnet access to the end users modem.   

Title: Re: TalkTalk HG 635 Firmware
Post by: npr on December 20, 2014, 04:35:11 PM
it remains possible to find port 23 open when you do some things.  I will try to see if I can track down which things. 

Is that using the firmware file with or without telnet access?
I had assumed this didn't happen if you load the one without telnet.

I'm really not happy with the security aspect of this router and am very suspicious with how quickly I received hacking attempts when port 23 became open to the world.
Just wondering if this vulnerability has anything to do with the problem.
http://mis.fortunecook.ie/
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on December 20, 2014, 05:27:56 PM
  The no telnet version is fine on its own. It is use of a "telnet config" with it can sometimes lead to port 23 opening. 

  It is pity that the port forward options seem more limited than in other routers.  In principle you should be able to make the open port 23 harmless by redirecting it to another harmless port.
Title: Re: TalkTalk HG 635 Firmware
Post by: kitzuser87430 on December 20, 2014, 05:40:40 PM
What about forwarding to a "spoofed" MAC address.
Ian
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on December 21, 2014, 09:44:50 AM
  I did try that I could get the spoof device to save.  It complained as I think it needs to actually see the "spoof"  device.  Maybe I could forward to my raspberry pi as that does not accept on port 23.  There are other possibilities but I won't have my HG635 on line for bit as I don't want to disturb things for a bit.
Title: Re: TalkTalk HG 635 Firmware
Post by: andythebrave on January 02, 2015, 09:35:01 PM
I have loaded the 1.04firmware onto my desk 635 but still cannot get the telnet to work. Help (it iis a spare router I have)
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on January 03, 2015, 07:14:03 AM
  Do you really mean firmware or have you used a config file? The needed firmware for telnet is HG635v1.04t_multicast_with_multicfg_main.bin but you need to adapt the settings to disable the very high security risk of telnet on the WAN.  If you used a config file which one did you use?
Title: Re: TalkTalk HG 635 Firmware
Post by: andythebrave on January 03, 2015, 03:10:37 PM
HG635v1.04t_multicast_with_multicfg_main.bin I have used that bit how do I adapt the settings for the config file and what setings do I change / addon the  config file I have is the one form the hugwei site and the hg635 needs a bin file to do the firmware , I tried the one on here as well (in this thread the link the firmware ahs been taken to 1.04 but no telenet, could you please give me step by step for loading the config file and the changes need for it  please
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on January 04, 2015, 12:31:00 PM
  i am a bit confused.  If you have used the HG635v1.04t_multicast_with_multicfg_main.bin file to do a firmware update you will have telnet access after doing a factory reset, you don't need another config file but you will need to set the router up.  The telnet access will be open on the WAN as well as the LAN.  It is best to make all the setting changes that you want and then set the remote management port, which defaults to port 23 in that firmware, to another value e.g 7547 is TalkTalk value.  Use shields up to be sure that things are secure.
Title: Re: TalkTalk HG 635 Firmware
Post by: andythebrave on January 06, 2015, 12:18:05 AM
ok how do I change the port to 7475 if I cannot telenet onto the router that's how wheres the config file how do I load it , reason is I want to see the line stats for the router ie the hec fec crc errors seconds etc for the ptm as I am having loads of issues with the broadband as open reach appear to be useless in fixing it , what command to I type into the config file. 
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on January 06, 2015, 09:14:11 AM
Lets take a step back. Please try to carefully say what you have done and what you find. You say you uploaded HG635v1.04t_multicast_with_multicfg_main.bin.

Have you done a hard reset either by using factory restore on the device gui or with a point in the reset hole on the rear? 

After that the wireless SSIDs should have names beginning with HG635 and and not the usual Talktalk one.  Check this report whether the ssids are HG....... or TALK...... .  ?

If they are HG..... and you did use that firmware file and not one of the other 3 you should have telnet access with username !!Huawei  and password  @HuaweiHgw.  Alternatively the firmware upload may have failed - it does some times.

If they are TALK....  you won't have telnet access until you you upload a config file from this thread using the device gui.  You may have used the wrong file or the upload may have failed.

I don't now  advise enabling telnet by any of these ways unless users feel competent to check and resolve the security issues -- by ensuring  telnet access on the WAN is disabled.  Earlier posst contain all that we know about doing this.
Title: Re: TalkTalk HG 635 Firmware
Post by: andythebrave on January 06, 2015, 05:30:29 PM
ok got the config file removed the users pcs form config file but ow ok got telenet thanks . will browse for telenet command to see fec errors etc thanks for help les
andy
Title: Re: TalkTalk HG 635 Firmware
Post by: andythebrave on January 06, 2015, 07:29:18 PM
ok now telenet working as per previous post on the tr69 its cpeuser , but the huaweii  password/login not work does not work I used the config from page 3
Title: Re: TalkTalk HG 635 Firmware
Post by: andythebrave on January 06, 2015, 07:37:28 PM
works now
reload the config
Title: Re: TalkTalk HG 635 Firmware
Post by: andythebrave on August 18, 2015, 01:57:00 PM
after loading firmware heres my instructiosn just to make it easy for logging in , if you have not loaded the firmware/config yu need to go thrugh thread and load before doing this


1.  Under maintain/device save your current configuration settings as you will need them to easily get back to normal.

    2. Under maintain/device upload the attached device settings file to the TT super router.  It may or may not need renaming from .txt to .conf?

    3. If that works you may/should have telnet access with login of !!Huawei  / @HuaweiHgw

    4.  The settings are some sort of default and I take no responsibility at all for them.   

    5.  An upload of the config file you first saved should return you to normal if your not happy
    6. on tlenet at atp eneter sh press enter
    7 then eneter xdslcmd info --stats   
Title: Re: TalkTalk HG 635 Firmware
Post by: les-70 on August 18, 2015, 09:14:35 PM
  It is much better to start with the normal config file use the approach in http://forum.kitz.co.uk/index.php/topic,15574.msg290230.html#msg290230

   I recommend that over over the config files in this thread.

Title: Re: TalkTalk HG 635 Firmware
Post by: RobV on October 21, 2015, 08:54:24 PM
Great work guys, I happily have my 1.04T running on a non TT line and telnet open via the python script :) Only issue I currently see is that one of the hidden pages http://192.168.0.254/html/advance.html#parent_control (yes im using a different ip) has issues applying the url filter rules (very hit and miss).  Im tempted to run a firmware update but 1) talktalk want to use tr069 or their own update tool 2) updating may isp lock the wan side.
So a few questions if I may - do any 1.06t users know if this firmware function is isp locked for the vdsl / wan side ?
Has anyone managed to compile the open source code ?
Has anyone captured the official firmware files ?  The TT exe opens with several dll files and smaller exe which im guessing pulls in the firmware file somehow to tmp or ram.  This maybe exploited but woud liek to ask first ?

Rob
Title: Re: TalkTalk HG 635 Firmware
Post by: kitzuser87430 on October 21, 2015, 10:02:43 PM
RobV

Welcome to the kitz forum....

The config does not change on firmware update, so no ISP lock (my hg635 on plusnet ADSL was still able to connect).

Ian
Title: Re: TalkTalk HG 635 Firmware
Post by: Weaver on October 22, 2015, 01:40:11 AM
Welcome!
Title: Re: TalkTalk HG 635 Firmware
Post by: RobV on October 22, 2015, 07:07:10 AM
Thanks :)

I may risk the TT app then but it wants default user pass and also ip ending 1.1 which on principle annoys me.
Title: Re: TalkTalk HG 635 Firmware
Post by: Bald_Eagle1 on October 22, 2015, 08:24:00 AM

The config does not change on firmware update, so no ISP lock (my hg635 on plusnet ADSL was still able to connect).



Just to add that with beta testing help from kitzuser87430, I am very close to releasing an update to HG612 Modem Stats that will work with the HG635.

Title: Re: TalkTalk HG 635 Firmware
Post by: RobV on October 25, 2015, 08:29:02 AM
Currently spending a sunday morning messing with router trying to update it. Having begrudingly changed ip and password to default it seems the talktalk app is not for huawei routers (yeah RTFM me... ;) ) so the only way to update according to tt appears to be to by doing factory reset and waiting.....
Other than not doing what i'm told - I assume a combination of tr068 and remote management have the device talk to tt servers to report stats which in turn push new firmware of required (quoted as 48 hour delay)

Fingers crossed this actually works although am sceptical now not being a tt customer (not to mention disliking tr069 and remote management full stop)
Title: Re: TalkTalk HG 635 Firmware
Post by: kitzuser87430 on October 25, 2015, 09:43:02 AM
Quote
now not being a tt customer

It will be fine; mine updated whilst on plusnet.

Ian
Title: Re: TalkTalk HG 635 Firmware
Post by: RobV on October 29, 2015, 12:21:33 PM
Mind me asking what your setting were as I'm still stuck on 1.04 ?

Internet Connection has TR069 service ticked

Via Maintain:
Remote Management enabled as is Periodic inform
Setting (via decrypted config)
<ManagementServer EnableCWMP="1" URL="http://acs.talktalk.co.uk:7547/ACS-server/ACS" Username="" Password="LlciMSOweByD1v5dj2NltG==" PeriodicInformEnable="1" PeriodicInformInterval="86400" ConnectionRequestUsername="userid" ConnecionRequestPassword="Lp0xkiAANwcYpVPbI3D/Mg==" X_ConnReqPort="7547" X_UseOpt43Url="0" UpgradesManaged="0">

Been setup like this for 3 days and still pending an update

Title: Re: TalkTalk HG 635 Firmware
Post by: Bald_Eagle1 on October 29, 2015, 04:52:04 PM

Just to add that with beta testing help from kitzuser87430, I am very close to releasing an update to HG612 Modem Stats that will work with the HG635.



Quick update:

Almost there bar a bit of fine-tuning.

Example of 1 day's Ongoing stats graphs montage attached for reference (G.DMT mode connection).

Title: Re: TalkTalk HG 635 Firmware
Post by: phi2008 on December 03, 2015, 11:10:59 PM
Is the HG635 ping latency issue fixed now?

(https://forum.kitz.co.uk/proxy.php?request=http%3A%2F%2Fi.imgur.com%2F5G0gXgu.png&hash=b39e124204d60fd8c68f39d388435a0e2bc8669b)
Title: Re: TalkTalk HG 635 Firmware
Post by: GigabitEthernet on September 13, 2016, 11:41:08 AM
Apologies for the bump.

I was wondering if there would be a way to enable VDSL bridge mode on the HG635?
Title: Re: TalkTalk HG 635 Firmware
Post by: Dray on September 13, 2016, 11:52:24 AM
Set the connection type to Bridged ?
Title: Re: TalkTalk HG 635 Firmware
Post by: kitzuser87430 on September 13, 2016, 02:01:25 PM
I seem to remember from the talk-talk members forum (can't find it at the moment)

On VDSL the hg635 can only be bridged on a TT connection just use auto/dhcp on the router (not PPPoe)

Ian
Title: Re: TalkTalk HG 635 Firmware
Post by: GigabitEthernet on September 13, 2016, 02:54:12 PM
Ah, I thought bridge mode didn't work on VDSL. Thanks! :)