Saturday, September 8, 2018

Router Improved :: Modified to/for Superb Stability and Security


Router:: Tp-Link TL-WR840n-Version 2.0 

I have Done some work on about 28 Routers for Foreign Customers.  I have also done some work for some customers in Bangladesh on these cheap routers.  They Cost around Tk.1600/1700 New in Bangladesh which is roughly about $20.00

This is the Cheapest possible router with decent specification.  It's a 300 Mbps 2.4 Ghz. Wifi router with 1 Wan and 3 or 4 Lan Ports.

But These router design got lots of problems.  They produce a lot of heat especially the SOC becomes hot over 60 C, which makes the router unstable after a few hours of operation.  Also tp link used a crappy firmware that got a lots of bugs and they are disclosed by online community.  Besides It's found that many 7xx/8xx series routers got a backdoor introduced by the product vendor!! To know about he vulnerability of tl-wr840 Please visit this site,
https://www.cvedetails.com/vulnerability-list/vendor_id-11936/Tp-link.html

https://www.cvedetails.com/vulnerability-list/vendor_id-11936/product_id-30820/Tp-link-Tl-wr840n-Firmware.html

Video with vulnerable Tp link router,

https://www.youtube.com/watch?v=7NDrmmZ9b18&t=82s

Also read this interesting vulnerability report for tp-link,
https://threatpost.com/updated-firmware-due-for-serious-tp-link-router-vulnerabilities/123702/

Security warning: unpatched http/tftp backdoor in original firmware: TP-Link TL-WDR4300
http://sekurak.pl/tp-link-httptftp-backdoor/

TP-Link TL-WR840N/TL-WR841N - Authenticaton Bypass
https://www.exploit-db.com/exploits/44781/

TP-Link TL-WR841N/ND V13(All Versions -Mediatek SoC) Cross site request Forgery:
https://exploit.kitploit.com/2018/06/tp-link-tl-wr841n-v13-cross-site.html


All this routers use very cheap Electrolytic capacitors that do not work properly after 6 to 9 months of operation.  Also extra heat causes router to reboot while in load(Workload/normal stress).  There are memory leaks in the firmware that are not properly built, though they used linux os!!

Here are the Hardware Modifications done to the tl-wr840n-v2.
1. Modified to replace 4 Mb flash chip with a 8 mb compatible flash chip.
2. Added heat sink to SOC for Better stability and smooth operation.
3. Replaced with Better Electrolytic Capacitor with low/nominal ESR value.
4. Added Serial UART Riser for easy flash upgrade.
5. Extra : Added External Yagi Quad Antenna for a lot powerful wifi signal.

Modified router TL-WR840n-V2 :: the Motherboard view


Larger and Multiple Heatsink in some routers

Router Programming In action:: TL-WR840n-v2


Software Modification done:
1. Replaced original bootloader with more advanced and easy to use u-boot by pepe2k.
2. Replaced tp-link firmware with Openwrt, Specifically built by me for tl-wr840v2 and v3.


Minicom Serial/UART Interface Booting TL-WR840n Router

Minicom Serial/UART Interface Booting TL-WR841HP Router


After Above modification what User will Experience :

1. Superb Stability will run for days/weeks without errors or reboots.  
2. Wifi Signal will be much stronger with extra Stability.
3. Will have Highest quality ip-table firewall built-in.
4. IPV-6 Inter connection module for future operation in IPV6 System.

There are numerous other features with these routers.  Please visit my Router mod pages for further info and for do it yourself guys.


Please note that doing this kinds of work requires professional training and for Software work, Software engg. degree is prefered!! along with some work experience in any software environment.  For hardware modification a basic hardware work experience in any company and related training required, or else pls. do not blame us or anyone else for bricked routers.


Thursday, September 6, 2018

Router Modification for commercial and/or Companies


I do router modification for Local Bangladeshi and Foreign Companies.  Usually They buy me the routers and I modify according to Highest standard. Minimum is 5 routers(same model).

For Foreign companies they send me the Circuit board or mother board. I modify them and send them back to their respective country.  Usually they send 2 to 4 outer shells, along with the router boards and power supply.

What Modifications do I do with them::

Hardware Side of my work,

1. I Usually replace the Original ram with more powerful one and compatible rams.  Usually 16 Mb to 32 and 32 Mb to 64 Mb is what I have done before with DDR1 Ram.  Now a days it's 64 Mb to 128 or even 256/512 Mega Byte of ram, is replaced.  Usually they are DDR2 OR DDR3 Ram chips.

2. I replace resident flash chip with compatible more powerful chips, usually from 2 or 4 mb to 8/16 Megabyte(SPI Flash Chip). Nand chips.

3. I do Antenna mod and add real Antenna's that boost the amplification of wifi signal, Usually do Yagi, Quad Antenna for high gain i.e. 9dbi to 12dbi.

4. Replace the cheap Electrolytic capacitors with Better once.

5. Install Heatsink on SOC for heat dissipation and stable usage for days.

The reason for all above is, to replace the original firmware of the Manufacturer to Custom firmware. Firmwares are installed and configured for each router as per buyers requirements.

As soon as the Firmware are modified, these cheap routers becomes equivalent to very expensive Cisco or linksys routers. Most of the times they surpases these expensive rivals!!

Usually these routers are made by Tenda or Tp-link, Costs around $25 to $40.  After modification they rival the More expensive Asus or linksys or Cisco routers. They Become $80 to $150 routers.

Why This is done.  Usually the Stock firmware for these routers are limited in capabilities.  They have standard SOC(System on Chip) But lack live storage(ram) and lack flash storage to store Advanced firmware.  Also They use cheaper capacitors which tend to falter after a few hours of usage. They also got flimsy antennas that do little to boost wifi amplification signal.

After Doing modifications, routers becomes far more responsive then original state.  Also Makes routers free from stock firmware backdoors that are found in most commercial routers.  The firmwares I  install are well known custom version as per SOC and system level.  The firmwares I install are,

Software side of my Work,

1. Openwrt(Prefered Atheros, Mediatek, qualcomm ) 2. Tomato(Prefered broadcom) 3. Dd-wrt(If buyer wants this firmware)

After Installation of Custom firmware Buyers get extra facilities such as,
1. UPnp -Very stable.
2. Ad Block.
3. Wifi Auto Turn on/off Module
4. DMZ Creation tool
5. NTP Client or Server service(Both installed, prefer Client)
6. VLan Services(Very Important)
7. Live Usage per user/ip/system
8. Web server Login and SSH Login(Admin services)
9. Telnet Login(Not prefered)
10. High Amplification wifi module(Depending on router model)
11. High speed IPV4 AND IPV6 Connection module(Kernel In-built),
they are, pppoe, dhcp, static and all other available and possible modules with MAC Cloning.
12. High speed Ipv4 and ipv6 enabled firewall(High quality iptable switched)
13. Guest wifi network service.
14. Download service(wget default)
15. Zram Swap(Depending on SOC. 600Mhz Min.)
16. Auto Set MAC Addr. to Different id in each reboot(Stop ip/mac spoof)

Below are used for some routers with More powerful SOC's and with extra fee($$),
1. VPN Server Service.
2. Real QOS.(Realtime!, requires SOC of 1 Ghz to 1.8 Ghz, Dual core better)
3. Net Analysis tools.
4. Download manager service(aria2, rsyncd, curl/libcurl)
5. DLNA Server services(MiniDLNA etc).
6. SNMP Server Service.
7. Snort.
8. Libpcap and associated Services(e.g. wireshark, netcat, nmap etc.)
9. Libtorrent(Along with a torrent client)
10. Windows Networking i.e. SAMBA Controller
11. SMTP or Other Mail Server Service install.
12. Radius Server service.
13. IP Telephony Service(sipp etc)

There are numerous other services can be installed, depending on hardware support and compatibility drivers.

NOTE: Before a router buy, Buyer must consult with me.  Compatability and Cost/comparison is required.