Introducing the victim: Cisco Linksys BEFSR41 v4.2

Vendor support page here

This router looks a good candidate for hacking.

Jumper J1 looks like a JTAG port and J2 looks like a Serial Port.  I left my soldering station and multimeter at work, so I will tackle these asap.  Also need to build a serial cable so I dont fry anything.

Details:

  • Cable/DSL Router with 4port 10/100 switch
  • AU$29
  • Realtek RTL8650B SoC
    • Lots of info regarding this SoC
    • Last Firmware Release Date: September 29, 2008
    • Current Firmware: Version 2.00.4 Build 5
    • Firmware size: 395 KB (404,480 bytes)
  • Hynix 64Mb DRAM
    • HY57V641620ETP-H
    • Synchronous DRAM 64Mbit (4Mx16bit)
    • 54 Pin TSOPII
    • ETP = Normal Power, Lead Free
    • H = 133Mhz
    • 4Banks x 1Mbits x16
    • Datasheet Here
    • LVTTL
  • 29LV800C Macronix Int Co Ltd 8M-BIT [1Mx8/512K x16] CMOS SINGLE VOLTAGE 3V ONLY FLASH MEMORY (Datasheet)

sorry! Images are sometimes dodgy as they were taken on my iPhone. Need to bring home a decent camera too.

LOL!
Tamper

Label

Pics of the box:
Box1

Box2

Box3

Box4

Box5

Box6

Pics of the unit:
Unboxed

Front

Back

Top

Bottom

To Disassemble, pry open the side where the groove locks in, the blue front pries forwards. Don’t try to do as I did and pry the black parts apart, even though thats how it looks like is fixed.
Split1

After that the rest is easy, no screws!
Split2

The board has one single screw.
Board

Chips

The System on a Chip (SoC)
Soc

Flash memory for the firmware:
Flash

a whopping 64mbit DRAM!
DRAM

Leave a comment