Tutaj mam dostęp do komend poprzez przegladarkę
http://192.168.0.1/adm/system_command.asp
Pliki z partycja mi mogę mieć tylko w folderze /tmp lub /var
Nie mam komendy do linkowania plików a dostęp do plików przez przeglądarkę mam ograniczony tylko do folderu /etc_ro/web
Po wpisaniu w przeglądarce polecenia cat /dev/mtd0 wyskoczyło mi coś takiego
ÿ@@$@€Z
@@@X
$ H. PNüÿ)! 2@€B ø !˜€D8" P#Hb8b¬¢$œ'!à™B$C¬@¬@¬@¬@¬„@¬!(BŒàÿ½'€©„$ ø ÿ< H¨ûÿ` 8ÄðC!(€eC œ'!à™Øÿ½'$b<@òœ'!à™àÿ½'ÿÿÿ‚$ùÿf0FÀd8b@ ÿÿç$ Cˆb!(@ $P¼%"¨ƒ¨CÄ& ø ¨C¨C!À!(€üÿ¥$&¦ðöT$¦ª
%¦ ¿<¯8$ T4ƒôIþÿdGþÿ¥ú¨µ5l˜²BÖÉ»Û@ù¼¬ãlØ2u\ßEÏ
ÖÜY=Ñ«¬0Ù&:ªÉ|
Ý<qPªA'¾† É%µhW³…o Ôf¹ŸäaÎùÞ^˜ÉÙ)"˜Ð°´¨×Ç=³Y
´.;\½·lºÀ ƒ¸í¶³¿šâ¶šÒ±t9GÕê¯wÒ&ÛƒÜscã„;d”>jm
¨ZjzÏäÿ “'®±ž}D“ðÒ£‡hòþÂi]Wb÷Ëge€q6lçknvÔþà+Ó‰ZzÚÌJÝgoß¹ùùホC¾·Õް`è£ÖÖ~“Ñ¡ÄÂØ8RòßOñg»ÑgW¼¦Ýµ?K6²HÚ+
ØL
¯öJ6`zAÃï`ßUßg¨ïŽn1y¾iFŒ³a˃f¼ Òo%6âhR•wÌG»¹"/&U¾;ºÅ(½²’Z´+j³\§ÿ×Â1Ïе‹žÙ,®Þ[°Âd›&òc윣ju
“m© œ?6ë…grW îÒ
×TƒN³9a&g§÷`ÐMGiIÛwn>JjÑ®ÜZÖÙfß@ð;Ø7S®¼©Åž»ÞϲGéÿµ0ò½½ŠÂºÊ0“³S¦£´$6к“×Í)WÞT¿gÙ#.zf³¸JaÄh]”+o*7¾´¡ŽÃßZï-Ô<ÿÿd=ÿÿ>ÿÿ¨XÿÿðXÿÿ@YÿÿYÿÿZÿÿZÿÿx?ÿÿœBÿÿfreq = %d MHZ
##### The CPU freq = %d MHZ ####
SDRAM bus set to 32 bit
SDRAM bus set to 16 bit
You choosed %c
3: System Boot system code via Flash.
%d: System Load Linux to SDRAM via TFTP.
%d: System Load Linux Kernel then write to Flash via TFTP.
%d: System Enter Boot Command Line Interface.
%s
main_loop !!
%d: System Load uCos to SDRAM via TFTP.
%d: System Load UBoot to SDRAM via TFTP.
%d: System Load Boot Loader then write to Flash via TFTP.
Erase U-Boot block !!
%s
Please choose the operation:
ARP Retry count exceeded; starting again
ArpTimeoutCheck
en[%d] < ETHER_HDR_SIZE
ntohs(arp->ar_hrd) != ARP_ETHER
ntohs(arp->ar_pro) != PROT_IP
arp->ar_hln != 6
arp->ar_pln != 4
NetOurIP
NetTxPacket = 0x%08X
NetRxPackets[%d] = 0x%08X
KSEG1ADDR(NetTxPacket) = 0x%08X
NetLoop,call eth_halt !
NetLoop,call eth_init !
eth_init is fail !!
Packet Buffer is empty !
Abort
TIMEOUT_COUNT=%d,Load address: 0x%lx
%lu MB reveived
first block received
TFTP error: First block is not block 1 (%ld)
Starting again
Same block again; ignore it
done
TFTP error: '%s' (%d)
Retry count exceeded; starting again
eth_register
enetvar=%s,Eth addr:%s
Warning: %s MAC addresses don't match:
eth_current->name = %s
New Address is %02X:%02X:%02X:%02X:%02X:%02X
ETH_STATE_ACTIVE!!
Interloopback test! So RxDMA is Stop !
shnat_flow_table_free_entry_enqueue is called,item== NULL
RT2880_TX_DMA_BUSY !!! Waitting for RX_DMA_BUSY status Start... Ring0,Set TX DMA loop back to CPU !!
Header Payload scatter function is Disable !!
Precedent of Packet was pending !!
Warring!! Packet Length has error !!,In normal mode !
Warrng Packet Buffer is Empty!!
Normal Mode,Packet received from CPU port,plen=%d
Set to Normal mode !
Set to LoopBack mode !
spicmd eeprom read [address]
spicmd eeprom write [size] [address] [value]
spicmd eeprom dump
spicmd vtss read [block] [sub-block] [address]
spicmd vtss write [block] [sub-block] [address] [value]
NOTE: size is 1, 2, 4 bytes only, address and value are in hex
%s
use "help spicmd" to get more detail!
%s
%s
use "help spicmd" for detail!
mdio.w [phy_addr(dec)] [reg_addr(dec)] [data(HEX)]
mdio.anoff GMAC1 Force link status enable !!
mdio.anon GMAC1 Force link status disable !!
mdio.wb [phy register(dec)] [bit offset(Dec)] [Value(0/1)]
MDIO Read operation is ongoing !!
MDIO Read operation is ongoing and Time Out!!
MDIO Write operation is ongoing !!
MDIO Write operation is ongoing and Time Out!!
GMAC1 Force link status enable !!
GMAC1 Force link status disable !!
mdio.r addr[0x%08X]=0x%04X
Read addr[0x%08X] is Fail!!
mdio.w addr[0x%08X] value[0x%08X]
Rasd PHY fail while mdio.wb was called
Set bit[%d] to '1'
Set bit[%d] to '0'
mdio.wb addr[0x%08X] value[0x%08X]
Write[0x%08X] is Fail!!
In main_loop !!
CONFIG_BOOTDELAY
- start application at address 'addr'
passing 'arg' as arguments
## Control returned to monitor - resetting...
- boot application image stored in memory
passing arguments 'arg ...'; when booting a Linux kernel,
'arg' can be the address of an initrd image
System Control Status = 0x%08X
Data Size: %d Bytes = Entry Point: %08x
- protect FLASH from addr 'start' to addr 'end'
protect on N:SF[-SL]
- protect sectors SF-SL in FLASH bank # N
protect on bank N
- protect FLASH bank # N
protect on all
- protect all FLASH banks
protect off start end
- make FLASH from addr 'start' to addr 'end' writable
protect off N:SF[-SL]
- make sectors SF-SL writable in FLASH bank # N
protect off bank N
- make FLASH bank # N writable
protect off all
- make all FLASH banks writable
- erase FLASH from addr 'start' to addr 'end'
erase N:SF[-SL]
- erase sectors SF-SL in FLASH bank # N
erase bank N
- erase FLASH bank # N
erase all
- erase all FLASH banks
erase linux
- erase linux kernel block
b_end =%08X
addr_first[0x%08X] >= info->start[0][0x%08X] && addr_first[0x%08X] < b_end[0x%08X]
Erase linux kernel block !!
Erase u-boot block !!
- load binary file over serial line with offset 'off' and baudrate 'baud'
- copy memory
- write memory
- memory modify, read and keep address
- memory modify, auto increment address
- memory display
Copy linux image[%d byte] to Flash[0x%08X]....
Copy uboot[%d byte] to Flash[0x%08X]....
Copy %d byte to Flash... netboot_common, argc= %d
- run the commands in the environment variable(s) 'var'
- set environment variable 'name' to 'value ...'
setenv name
- delete environment variable 'name'
- print values of all environment variables
printenv name ...
- print value of environment variable 'name'
Environment size: %d/%d bytes
** Abort
Reset to Flash environment
Default FLASH_CS1_CFG = %08X
- show help information (for 'command')
'help' prints online help for the monitor commands.
Without arguments, it prints a short usage message for all commands.
To get detailed help information for specific commands you can type
'help' with one or more command names as arguments.
- echo args to console; \c suppresses newline
The Flash follow SSI standard
Set info->start[0]=%08X
Erase All
protect sect[%d]
SSI Manufacture so its small sector
sect[%d] is protected,skip
erase sector = %d
Erase to sector address[%08X]
Elase Sector 0 with 8K SIZE,The sector 0 is Total 64K
Exit Sector 0 erase !!
dest[0x%08X]=%04X
addr = 0x%08X ,cnt=%d Starting kernel ...
Końcowe krzaki oczywiście wykasowałem żeby wysłać tego posta 
Ma ktoś pomysł w jaki sposób można się dostać do bootloadera ale po ethernecie ? Portu szeregowego niestety nie zlokalizowałem.
Ciekawi mnie po co po włączeniu zasilania trzeba wciskać zawsze pomarańczowy przycisk.
Najlepsze jest to że plecenie shutdown też powoduje przejście rotuera do stanu początkowego. Wydaje mi się że to jest software'owo rozwiązane i może gdzieś jest jakaś ukryta opcja w bootloaderze oczekująca na wciśnięcie przycisku.