Project

General

Profile

3Com SuperStack II RAS 1500 » History » Version 4

xent, 08/16/2024 09:19 PM

1 1 xent
h1. 3Com SuperStack II RAS 1500
2
3
@xent acquired a 3Com SuperStack II Remote Access System 1500 equipped with 2 x 2-Port ISDN BRI I/O Card 
4
5
6
7
h2. Documentation
8
9 2 xent
* attachment:3Com_RAS_1500_Getting_Started.pdf
10
* attachment:3Com_RAS_1500_System_Management.pdf
11 1 xent
12
h2. Security
13
14
The system doesn't really seems to be particularly secure, the serial console doesn't ask for any password and we found quickly exploit for the platform. (https://isec.pl/en/vulnerabilities/isec-0009-3com-ras.txt)
15
16
17 3 xent
h2. Web Interface
18
19 4 xent
!3com_ras1500_web.png!
20 3 xent
21
22 1 xent
23
h2. Boot Log
24
25
<pre>
26
27
28
Initializing....
29
30
31
32
Running Power On Diagnostics Version 2.5.0 (B 159)
33
34
2 Percent Complete
35
4 Percent Complete
36
6 Percent Complete
37
8 Percent Complete
38
10 Percent Complete
39
12 Percent Complete
40
14 Percent Complete
41
16 Percent Complete
42
18 Percent Complete
43
21 Percent Complete
44
23 Percent Complete
45
25 Percent Complete
46
27 Percent Complete
47
29 Percent Complete
48
31 Percent Complete
49
33 Percent Complete
50
35 Percent Complete
51
37 Percent Complete
52
53
ERROR !   
54
55
56
.         Error Code -> 07102000..Port FG  LRT    Type EC1 EC2 EC3
57
58
      Expected Data -> 00000080..[00] [07][01 00][02] [00  00  00]   
59
60
      Received Data -> 00000000..LRT = 36, Error Type = 2, Port = 0.
61
62
               Mask -> 000000FF
63
64
 Address of Failure -> F07A0034
65
66
       Text Message -> RTC Access Failure - Reg D - Cell exhausted
67
68
69
Test #  Test Name                                       Port   Time   Status
70
71
-------+----------------------------------------------+------+------+--------
72
73
701.RTC Reset -------------------------------------       (1) - FAILED
74
75
76
77
Enter.'C' to Continue with POST
78
79
.'B' to Reboot
80
81
.'Q' Quit and Load Operational Software
82
83
Starting Operational Software
84
85
86
** RAS 1500 Boot-Loader Ver. 2.5.0 (B 159), Built on 2000-6-3, 10:56:7 **
87
88
SDL2 is initializing the FLASH file system. Please wait....
89
90
SDL2 has completed initializing the FLASH file system.
91
92
Current contents of the FLASH file system:
93
94
.mmsram.bin;............................size:  196608 bytes.
95
96
.mmboot.bin;............................size:   65536 bytes.
97
98
.pilgrim.bin.z;.........................size: 1611888 bytes.
99
100
.hdmplus.bin.z;.........................size:  801512 bytes.
101
102
.PilgrimStrings.ind.gz;.................size:   72585 bytes.
103
104
.PilgrimStrings.str.gz;.................size:   82516 bytes.
105
106
.update1.bin.z;.........................size:    3529 bytes.
107
108
.RoboString.ind;........................size:   10612 bytes.
109
110
.RoboString.str;........................size:    8621 bytes.
111
112
.QuickSetup.cfg;........................size:     729 bytes.
113
114
.EventHandler.cfg;......................size:       0 bytes.
115
116
.CLI.cfg;...............................size:      42 bytes.
117
118
.TermProt.cfg;..........................size:      39 bytes.
119
120
.SnmpProcess.cfg;.......................size:      16 bytes.
121
122
.BridgeProcess.cfg;.....................size:      68 bytes.
123
124
.TftpProcess.cfg;.......................size:      27 bytes.
125
126
.Appletalk.cfg;.........................size:      88 bytes.
127
128
.PppProcess.cfg;........................size:      44 bytes.
129
130
.FilterMgr.cfg;.........................size:      24 bytes.
131
132
.DialOutProcess.cfg;....................size:      29 bytes.
133
134
.RemotePingProcess.cfg;.................size:      21 bytes.
135
136
.TcpProcess.cfg;........................size:      19 bytes.
137
138
.DNMSProcess.cfg;.......................size:     133 bytes.
139
140
.DNS.cfg;...............................size:     174 bytes.
141
142
.IpxProcess.cfg;........................size:     133 bytes.
143
144
.DHCP.cfg;..............................size:     208 bytes.
145
146
.RoboExecNMProcess.cfg;.................size:    1844 bytes.
147
148
.dhcpProxy.cfg;.........................size:     288 bytes.
149
150
.IPForwarder.cfg;.......................size:     503 bytes.
151
152
.CallInitProcess.cfg;...................size:    1827 bytes.
153
154
.ConfigProcess.cfg;.....................size:    2867 bytes.
155
156
.Robo.stats;............................size:     788 bytes.
157
158
.user_settings.cfg;.....................size:   15521 bytes.
159
160
Total of 33 files in the file system.
161
162
163
164
SDL2 is ready.
165
166
AT{B} <filename> .. To execute a file type
167
AT{C} ............. To continue boot sequence
168
AT{D} <filename> .. To delete a file type
169
AT{E} ............. To erase all flash files
170
AT{H} ............. To halt boot sequence
171
AT{L} ............. To list all files
172
AT{P} ............. To prepare system for download
173
AT{Z} ............. To download a file type
174
AT{?} ............. To get help
175
176
177
178
179
. RAS 1500 Boot-Loader RM Manager
180
181
Slave Image Load Address 0x80000000
182
Master Image Load Address 0x80000000
183
Slave Image File Name: hdmplus.bin.z
184
Master Image File Name: pilgrim.bin.z
185
186
Master: Initialization {ldrInitializeMaster} : .PASS
187
188
Master: Load Slave {ldrLoadSlaveProcess} : .PASS
189
190
Master: Synchronization {ldrSyncMasterToSlave} : .PASS
191
192
Master: Load Slave OpCode Image {ldrLoadApplicationImage} : 
193
Reinitializing LZH module.
194
In : 1900024 bytes
195
--10--20--30--40--50--60--70--80--90--100
196
.........................................   
197
Restored
198
.PASS
199
200
Master: Load Master OpCode Image {ldrLoadApplicationImage} : 
201
Reinitializing LZH module.
202
In : 3766556 bytes
203
--10--20--30--40--50--60--70--80--90--100
204
.........................................   
205
Restored
206
.PASS
207
208
Master: Start Slave OpCode Image {ldrExecuteApplication} : .PASS
209
210
Master: Start Master OpCode Image {ldrExecuteApplication} : 
211
-------------------------------------------------------------------------------
212
IPX/IP Dial-out networking software      Copyright (c)1985-1996,
213
       Network Products Corporation      Pasadena, CA       All rights reserved
214
AppleTalk-compatible networking software Copyright 1993-1995,
215
       Quiotix Corporation               Menlo Park, CA     All rights reserved
216
TCP/IP networking software               Copyright 1988-1995,
217
       Epilogue Corporation              Albuquerque, NM    All rights reserved
218
IP routing software                      Copyright 1993-1995,
219
       RainbowBridge Communication. Inc. Rockville, MD      All rights reserved
220
IPX networking software                  Copyright 1994-1995,
221
       RouterWare Inc.                   Newport Beach, CA  Unpublished - 
222
       Rights reserved under the Copyright Laws of the United States.
223
VJ TCP Header Compression software       Copyright (c) 1989, 1991, 1992, 1993,
224
       Regents of the University of California.             All rights reserved.
225
-------------------------------------------------------------------------------
226
227
228
RAS1500, V2.5.0
229
230
231
------3Com CORPORATION------Santa Clara, CA---------
232
Software contained in this product is Copyright 1998-1999
233
----------------ALL RIGHTS RESERVED-----------------
234
235
236
Starting up the RAS1500 system Executive...
237
Segment sizes:
238
  Control area = 11580 bytes
239
  HDM To Be Freed segment = 6260 bytes
240
  HDM Free Pool segment = 6260 bytes
241
  Inbound segment = 1620 bytes
242
  Outbound segment =
243
 1620 bytes
244
  Buffer segment = 218400 bytes (1560 buffers)
245
Starting up RAS1500Initializing Firewire Device ....
246
Initialized the Firewire Device
247
 Configuration process...
248
249
RAS1500 Configuration Process starting......
250
251
RAS1500 Initializing Network Management Processes...
252
253
RAS1500 starting RoboExec NetMan process......
254
255
RAS1500 starting Event Handler process......
256
257
RAS1500 configuring interfaces......
258
### SLot1 Type:  0 1 0 2 ff ff ff ff 
259
### SLot2 Type: 0 1 0 2 ff ff ff ff 
260
Adding BRD device
261
Adding firewire device
262
263
RAS1500 starting required processes......
264
265
RAS1500 starting Call Initiator process (CIP)......
266
267
RAS1500 configuring devices in CIP......
268
269
RAS1500 configuring networks......
270
271
RAS1500 Adding networks to LAN interfaces....
272
273
RAS1500 enabling networks on LAN interfaces....
274
275
Configuring Network Services.....
276
277
Starting the CLI......
278
Please Wait for Prompt...
279
ras1500> 
280
</pre>
Add picture from clipboard (Maximum size: 48.8 MB)