Telnet Password recovery - BSR2000 | docsis.org

You are here

Telnet Password recovery - BSR2000

2 posts / 0 new
Last post
akhalil
Telnet Password recovery - BSR2000

Dear DOCSIS Teams,

Kindly to help me How to recover the forgotten telnet password of BSR2000, ?

Sincerely,

cmcaldas
Console work?

Power cycle the unit. After completing the diag (Passed below) you have 7 seconds to hit any key to interrupt the bootup.
Type the letter p to print the boot. hit enter until you return to prompt.
When you return back to the VxWorks Boot, type the letter c for change.
Hit enter until you get to Flags. Change the current flag from 0x2000 to 0x10 This will bypass the startup-config file.
When back to the VxWorks Boot, type the letter l (L in lower case) to load the image.
Once it’s back in a running state, you can enter the enable mode and type copy start run.
This will take the startup config and make it the running config with you in the enable mode. Make changes to the telnet or console passwords and copy run start to save the new startup-config file.
Reload, hit any key again to change back the flag so it boots normal. Otherwise if there’s a reload or loss of power, it will bypass the startup-config again.

Press any key to stop auto-boot...
7
[VxWorks Boot]: p

BSR 2000 Power-On Diagnostics...
Board
Assembly PN = 520699-005-00
SN = H060351000091310
REV = E
Upper Level
Assembly PN = 520025-005-00
SN = J060351000091873
REV = H

BootROM Ver: 1.0.32 Created: Tuesday, August 25, 2009 9:16:17 AM EDT

1. CPU Section ...Passed
2. Memory Section ...Passed
3. I2C Section ...Passed
4. Network Section ...Passed
5. RF MAC Section ...Passed
6. RF Tx Section ...Passed
7. RF Rx Section ...Passed

BSR 2000 Passed All Power-On Diagnostics...

Exiting Diagnostics...
Checking Sector 115 for proper TFFS format header
flMount: iTL = 0, status = 0x0
Attaching to ATA disk device... usrAtaConfig succeeded
ataFormat: Volume FLASH: already formatted

VxWorks System Boot

Copyright 1984-2005 Wind River Systems, Inc.

System : Motorola BSR 2000
Version : VxWorks5.5.1
BSP version : 1.0/0
Creation date : Aug 25 2009, 09:21:11

Press any key to stop auto-boot...
7
[VxWorks Boot]: p

boot device : NVRAM:
unit number : 0
processor number : 0
host name : host
file name : appImage_110P08TRAU.bin
inet on ethernet (e) : 172.25.8.102:ffff0000
host inet (h) : 172.25.0.1
user (u) : testing
ftp password (pw) : testing
flags (f) : 0x2000
target name (tn) : targetname

[VxWorks Boot]:
[VxWorks Boot]: ?

? - print this list
p - print boot params
c - change boot params
d adrs[,n] - display memory
e - print fatal exception
f adrs, nbytes, value - fill memory
g adrs - go to adrs
h - help (print this list)
l - load boot file
m adrs - modify memory
t adrs, adrs, nbytes - copy memory
v - print boot logo with version
n netif - print network interface device address
r - read board and psup serial eeproms
w - write board and psup serial eeproms
z - enter zli command shell for file manipulation
i - Display system memory pool information
j - Display status of both SFP slots
s - show temperatures and trip points
C - perform PCI bus scan
D - decompress image and go
E - erase nvram flash file system
F - format nvram flash file system
G - load image to nvram (boot, fpga, appl)
H - load image to compact flash (appl)
I - show flash identities
J - format compact flash file system
L - list files on nvram and compact flash
M - program MAC address
P - show PCI agents
Q - reboot without mem clear (quicker)
R - reboot with mem clear (longer)
S - show memory map
T - show spawned tasks
V - show version information
$dev(0,procnum)host:/file h=# e=# b=# g=# u=usr [pw=passwd] f=#
tn=targetname s=script o=other
Boot flags:
0x02 - load local system symbols
0x04 - don't autoboot
0x08 - quick autoboot (no countdown)
0x10 - bypass startup-config
0x20 - disable login security
0x40 - autoconfigure: NOT AVAILABLE (no method installed)
0x80 - use tftp to get boot image
0x100 - use proxy arp

Available Boot Devices:
Enhanced Network Devices
------------------------
marfec0 marfec1 marfec2 marfec3 marfec5 marfec4
File System Devices
-------------------
flash: FLASH: ata
nvram: NVRAM: tffs

[VxWorks Boot]:
[VxWorks Boot]: c

'.' = clear field; '-' = go to previous field; ^D = quit

boot device : NVRAM:0
processor number : 0
host name : host
file name : appImage_110P08TRAU.bin
inet on ethernet (e) : 172.25.8.102:ffff0000
inet on backplane (b):
host inet (h) : 172.25.0.1
gateway inet (g) :
user (u) : testing
ftp password (pw) (blank = use rsh): testing
flags (f) : 0x2000
target name (tn) : targetname
startup script (s) :
other (o) :

[VxWorks Boot]:
[VxWorks Boot]: l

boot device : NVRAM:
unit number : 0
processor number : 0
host name : host
file name : appImage_110P08TRAU.bin
inet on ethernet (e) : 172.25.8.102:ffff0000
host inet (h) : 172.25.0.1
user (u) : testing
ftp password (pw) : testing
flags (f) : 0x2000
target name (tn) : targetname

Start application from NVRAM:
Booting image appImage_110P08TRAU.bin

cmtsDecompExtApp: Inflating image from 0x1c80f0f8 to 0x00200000, size 0x004263b4...

inflating image appImage_110P08TRAU.bin success!
Starting at 0x200000...

Checking Sector 115 for proper TFFS format header
flMount: iTL = 0, status = 0x0
Attaching to ATA disk device... usrAtaConfig succeeded
ataFormat: Volume FLASH: already formatted

Adding 28276 symbols for standalone.
-> compiled @ Tuesday, May 5, 2009 11:11:27 PM EDT

Initializing FPGA

FPGA Revision 0.220

FPGA ID c0de
BCM MAC revision 3214a3.
bcm3034Init: downstream driver(3040/0) 0x164153f0 created for mac0.
Device 3140 rev 3 driver created for mac/port=0/0.
Device 3140 rev 3 driver created for mac/port=0/1.
Device 3140 rev 3 driver created for mac/port=0/2.
Device 3140 rev 3 driver created for mac/port=0/3.
Device 3140 rev 3 driver created for mac/port=0/4.
Device 3140 rev 3 driver created for mac/port=0/5.
BCM3212 driver started: 0x16ab5110.
macName = 3212

BSR 2000(tm) version 1.1.0P08.TRAU
Copyright (c) 2005 by Motorola.
Compiled Tuesday, May 5, 2009 11:11:27 PM EDT
MPC7447A processor with 512MB memory.
Boot ROM : 1.0.32
CPU : MPC7447A
Memory Size : 512 MB
Board Program ID : RD
Format Version : 11
Assembly Type : 39
Board Part Number : 520699-005-00
Board Serial Number : H060351000091310
Board Rev : E
Upper Level Part Number : 520025-005-00
Upper Level Serial Number : J060351000091873
Upper Level Rev : H
FPGA Revision : 0.220
System Up Time : 33 seconds
reload reason: reload command

Password:

Log in or register to post comments