Microsoft Laptop

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Friday, 2 March 2012

OpenWRT Built for TP-Link WR1043ND

Posted on 20:07 by Unknown
PLEASE READ THIS POST COMPLETELY TO PREVENT ISSUES WITH YOUR ROUTER

What this firmware does

This firmware aims to be an opensource replacement for the stock TP-Link firmware in the Wireless N Gigabit TL-WR1043ND Router.
The firmware aims to provide equivalent or better features compared stock firmware.
The firmware will also leave empty flash sectors for users to install addition packages for special features they require.
Unlike stock openwrt firmware, this is a firmware fully optimized for performance, optimization is targeted at the MIPS24Kc System On Chip, debugging features stripped and scripts are minified, compressed specifically for this Router platform.

It is advised to add a heatsink to the AR9132 SoC, it does get quite hot after flashing my custom OpenWT firmware during intensive processing.

Software Feature

  1. Protoco Supported: Static/DHCP/Dual Stack/6in4/6to4/6rd/PPP/PPtP/PPPoE/3G UMTS/L2TP/Relay
  2. LuCI GUI (Bootstrap) with Lighttpd Web Server
  3. Dynamic DNS (Support HTTPS by skipping SSL Certificate checks)
  4. QoS (Quality Of Service) Scripts
  5. TinyProxy
  6. UPnP (Universal Plug & Play)
  7. SAMBA 3.6 (Windows File Sharing)
  8. MultiWAN 
  9. Harddisk Idle (Saves Power on attached External Harddisk when not in use)
  10. Add User and Delete User accounts (no su function, use ssh root@youripaddress to get root while logged into router via SSH, this saves flash and achieves the same effect )
  11. External Harddisk supporting only EXT2/3/4 FileSystem (NTFS is SLOW and FAT is unreliable, while the EXT Kernel Module allows support for all 3 versions of EXT Filesystem)
  12. Vsftpd with SSL Support
  13. MiniDLNA Media Sharing Server
  14. Layer 7 Filtering
  15. Transmission Bittorrent Capability GUI and CLI
  16. Patched Realtek Switch Driver supporting (Port Priority/Port Mirroring/Jumbo Passthrough/BCStormFiltering/VLAN4K)
  17. Reset to Defaults using the Reset Button GPIO
  18. Full Wireless Support 64/128/152-bit WEP / WPA / WPA2,WPA-PSK / WPA2-PSK including Enterprise Radius Authentication
  19. Ipset
  20. Fdisk Partitioning Tool
  21. Wake On LAN
  22. USB Printer Server
  23. Restore to OpenWRT default feature (just press and hold reset button)

    Additional Optimizations

    1. Expose more LuCI Options than Stock OpenWRT
    2. Additional LuCI patching to improve GUI for touch devices
    3. Optimized sysctl defaults
    4. Compiler flags optimization
    5. Additional packages are optimized for size
    6. All Wireless Channels unlock (if US region is selected)
    7. Max Transmit Power 24dbm
    8. Tested NAT throughput > 250Mbps LAN to WAN using jperf
    9. Minified CSS and Javascript 
    10. Patched Switch Driver for additional functionality 
    11. Remove additional debugging features from firmware
    openwrt-ar71xx-tl-wr1043nd-v1-squashfs-factory.bin - For TP-Link WR1043ND that are NOT running OpenWRT

    openwrt-ar71xx-tl-wr1043nd-v1-squashfs-sysupgrade.bin - For  TP-Link WR1043ND currently running OpenWRT

    Before Flashing please read my previous posts about TP-Link WR1043ND to know what you are getting into. Consult the documentation @ OpenWRT Website or ask if you have any queries.

    You can download and install additional packages through the OpenWRT repository (the package installer is built into LuCI) but it will occupy more space on the JJFS partitions.

    Reboot After Disabling Unused Features For Better Performance

     

    My custom firmware comes with loads of features, however OpenWRT by default enables all features so you might want to disable features you don't need.

    This will boost the performance of services you need to run.
    If you experience low performance due to insufficient memory, you might want to create and mount a swap partition.


    DO NOT DISABLE IMPORTANT FUNCTIONS LIKE NETWORK!

    If you cannot access the Router try holding down the reset button this will reset the Router back to default.
    If you still cannot access the Router try serial ttl adapter.
    (This cheap device can debrick all configuration lockups except the bootloader so don't touch the bootloader)

    DO NOT UNINSTALL THE PACKAGES THAT ARE ALREADY THERE!

    The image is built using squashfs so it is READ ONLY. If you try to uninstall it only removes the hardlinks, no space is saved. If you don't want a function just disable it.

    USE TRANSMISSION ONLY WITH AN EXTERNALLY ATTACHED HARDDISK!

    The Router only has 32MB of RAM, when you torrent, the files are over 1GB.
    You need to configure Transmission in LuCI to write all data to the externally mounted harddisk!
    By default Transmission writes to RAM because there is no harddisk.

    -------------------------------Old Firmware & New Firmware Below-------------------------------

    Make sure you have sufficient FREE RAM (Check using LuCI SystemInfo) before you Flash any firmware!

    To free up memory for upgrading firmware, ssh into the router then type
    sysctl -w vm.drop_caches=1
    This will tell the kernel to drop page caches so memory is freed up for you to upgrade firmware. You need to free up memory because before the firmware is flashed to the flash memory, it has to be copied into the DRAM.
    You can download the files here.

    As I have posted I am shifting from Mediafire due to the issues I encountered as described in this post.

    The new files will be available on my github below.
    Attitude Adjustment TP-Link WR1043ND
    Addition packages you can download and install into your OpenWRT Router to extend its capabilities.
    Attitude Adjustment TP-Link WR1043ND Packages

    If you want to build your own firmware, I have placed the files in the Git Repo below:
    OpenWRT  TL-WDR4300
    OpenWRT TL-WR1043ND
    Please note that to minify the Javascript & CSS and fix LuCI naming run the scripts in the following order del.sh -> luci.sh -> closure.sh & yuicompressor.sh.
    The path should be amended in the scripts according to where you place the buildroot.
    If you want to add my changes to whatever router you have simply diff the files and take the changes you want.

    It is recommended to reset the all the wireless client profiles to the router after an upgrade.

    I achieved 300Mbps LAN to WAN over wire NAT on this firmware. To get the same results you need to
    -Disable P2P Block
    -Disable MSS Clamping in firewall
    -Reboot

    Read More
    Posted in | No comments

    Sunday, 26 February 2012

    Configuring Pure-FTPd with TLS on OpenWRT

    Posted on 06:56 by Unknown

    This is a simple guide to configuring Pure-FTPd on OpenWRT which is available on the TP-Link WR1043ND OpenWRT Image I compiled.
    Pure-FTPd is a secure FTP Server by www.pureftpd.org
    Configuring OpenWRT is more like configuring a barebones Linux Terminal Server than many other commercial Routers. There is NO LuCI GUI for Pure-FTPd.
    The reason why I chose Pure-Pure-FTPd is
    • Offers Optional TLS Encryption on OpenWRT
    • Not a very big FTP Server
    First, you have to login via an SSH Client to your OpenWRT Router and get use to it if you are going to leverage on the Power and Flexibility on OpenWRT (If you custom compile OpenWRT without LuCI GUI you get to save even more flash memory!).

    You can use any SSH Client, in Windows I recommend PuTTY while on Linux the built-in SSH will do. To learn how to login via CLI and edit files please go through the previous postings.

    Pure-FTPd uses a few configuration files to set itself up.
    Originally Pure-FTPd is designed to run without config files. Just run the binary with the correct switches it should set itself up but in OpenWRT it is designed to read the config file to set itself up.

    To see the full switches on Pure-FTPd on OpenWRT simply cat the initialization scripts.

    The initialization script is located in /etc/init.d/pure-ftpd

    Run cat /etc/init.d/pure-ftpd  and you should see the following:
    #!/bin/sh /etc/rc.common
    # Copyright (C) 2006-2011 OpenWrt.org

    START=50

    # TODO: allow multiple instance to run with different pid-files

    # XXX: pure-ftpd changes it's name to 'pure-ftpd (SERVER) ...'
    SERVICE_MATCH_EXEC=
    SERVICE_MATCH_NAME=1
    SERVICE_USE_PID=1

    append_bool() {
            local section="$1"
            local option="$2"
            local value="$3"
            local _val
            config_get_bool _val "$section" "$option" '0'
            [ "$_val" -gt 0 ] && append args "$3"
    }

    append_string() {
            local section="$1"
            local option="$2"
            local value="$3"
            local _val
            config_get _val "$section" "$option"
            [ -n "$_val" ] && append args "$3 $_val"
    }

    start_instance() {
            local section="$1"

            config_get_bool enabled "$section" 'enabled' '1'
            [ $enabled -gt 0 ] || return 1

            args=""
            append_string "$section" trustedgid "-a"
            append_string "$section" syslogfacility "-f"
            append_string "$section" fortunesfile "-F"
            append_string "$section" maxidletime "-I"
            append_string "$section" maxdiskusagepct "-k"
            append_string "$section" limitrecursion "-L"
            append_string "$section" anonymouscancreate "-M"
            append_string "$section" maxload "-m"
            append_string "$section" quota "-n"
            append_string "$section" altlog "-O"
            append_string "$section" passiveportrange "-p"
            append_string "$section" forcepassiveip "-P"
            append_string "$section" anonymousratio "-q"
            append_string "$section" userratio "-Q"
            append_string "$section" anonymousbandwidth "-t"
            append_string "$section" userbandwidth "-T"
            append_string "$section" minuid "-u"
            append_string "$section" trustedip "-V"
            append_string "$section" tls "-Y"
            append_string "$section" tlsciphersuite "-J"

            append_bool "$section" uploadscript "-o"
            append_bool "$section" natmode "-N"
            append_bool "$section" autorename "-r"
            append_bool "$section" nochmod "-R"
            append_bool "$section" antiwarez "-s"
            append_bool "$section" allowuserfxp "-w"
            append_bool "$section" allowanonymousfxp "-W"
            append_bool "$section" prohibitdotfileswrite "-x"
            append_bool "$section" prohibitdotfilesread "-X"
            append_bool "$section" allowdotfiles "-z"
            append_bool "$section" customerproof "-Z"
            append_bool "$section" anonymouscantupload "-i"
            append_bool "$section" createhomedir "-j"
            append_bool "$section" keepallfiles "-K"
            append_bool "$section" norename "-G"
            append_bool "$section" dontresolve "-H"
            append_bool "$section" verboselog "-d"
            append_bool "$section" displaydotfiles "-D"
            append_bool "$section" anonymousonly "-e"
            append_bool "$section" brokenclientscompatibility "-b"
            append_bool "$section" notruncate "-0"
            append_bool "$section" logpid "-1"
            append_bool "$section" ipv4only "-4"
            append_bool "$section" ipv6only "-6"

            append_string "$section" bind "-S"
            append_string "$section" login "-l"

            append_bool "$section" noanonymous "-E"
            append_bool "$section" chrooteveryone "-A"
            append_string "$section" maxclientsperip "-c"
            append_string "$section" maxclientsnumber "-C"
            append_string "$section" peruserlimits "-y"
            append_string "$section" umask "-U"

            append_string "$section" port "-S"
            append_string "$section" authentication "-l"

            service_start /usr/sbin/pure-ftpd -B $args
    }

    start() {
            config_load "pure-ftpd"
            config_foreach start_instance "pure-ftpd"
    }

    stop() {
            service_stop /usr/sbin/pure-ftpd
    }
    From what you can read you can tell the initialization scripts translates switches like "-k" into human readable config options and all the available switches are shown above.

    To control Pure-FTPd the commands are as follow
    Syntax: /etc/init.d/pure-ftpd [command]

    Available commands:
            start   Start the service
            stop    Stop the service
            restart Restart the service
            reload  Reload configuration files (or restart if that fails)
            enable  Enable service autostart
            disable Disable service autostart
    Eg: To start Pure-FTPd run
    /etc/init.d/pure-ftpd start

    It is that simple so CLI isn't really as difficult as most imagine.

    Pure-FTPd also uses 2 database file as access-control lists they are located at
    /etc/pureftpd.passwd 
    (This is like your UNIX passwd file except it is for Pure-FTPd it contains user accounts, shell etc)
    /etc/pureftpd.pdb
    (It is Pure-FTPd database file I like to think of it as your UNIX shadow file)

    First you add a system user and system group as a default account on UNIX that Pure-FTPd will create virtual user from.
    addgroup pure_ftpd_grp #or any othername as you want

    adduser -H -G pure_ftpd_grp pure_ftpd_user #adds user to previously created group - change groupname accordingly, afterwards you will be asked for password for user (-H indicates that I don't want to assign home directory - if you want to you need to change -H to -h /homedirectory)
    For me I assign the home directory to the directory I want to be logging from FTP.
    FTP will fail if the directory change permission is not correct so you need to set it to the right directory.

    Next you add the virtual user to Pure-FTPd Access Control

    pure-pw useradd FTP_LOGIN -u pure_ftpd_user -d /ftp_directory #change FTP_LOGIN, pure_ftpd_user and /ftp_directory as you wish (pure_ftpd_user is same as you created in previous step). I set the same directory as above.

    To see the Pure-FTPd accounts use the commands
    pure-pw useradd <login> [-f <passwd file>] -u <uid> [-g <gid>]
                    -D/-d <home directory> [-c <gecos>]
                    [-t <download bandwidth>] [-T <upload bandwidth>]
                    [-n <max number of files>] [-N <max Mbytes>]
                    [-q <upload ratio>] [-Q <download ratio>]
                    [-r <allow client ip>/<mask>] [-R <deny client ip>/<mask>]
                    [-i <allow local ip>/<mask>] [-I <deny local ip>/<mask>]
                    [-y <max number of concurrent sessions>]
                    [-z <hhmm>-<hhmm>] [-m]

    pure-pw usermod <login> -f <passwd file> -u <uid> [-g <gid>]
                    -D/-d <home directory> -[c <gecos>]
                    [-t <download bandwidth>] [-T <upload bandwidth>]
                    [-n <max number of files>] [-N <max Mbytes>]
                    [-q <upload ratio>] [-Q <download ratio>]
                    [-r <allow client ip>/<mask>] [-R <deny client ip>/<mask>]
                    [-i <allow local ip>/<mask>] [-I <deny local ip>/<mask>]
                    [-y <max number of concurrent sessions>]
                    [-z <hhmm>-<hhmm>] [-m]

    pure-pw userdel <login> [-f <passwd file>] [-m]

    pure-pw passwd  <login> [-f <passwd file>] [-m]

    pure-pw show    <login> [-f <passwd file>]

    pure-pw mkdb    [<puredb database file> [-f <passwd file>]]
                    [-F <puredb file>]

    pure-pw list    [-f <passwd file>]

    -d <home directory> : chroot user (recommended)
    -D <home directory> : don't chroot user
    -<option> '' : set this option to unlimited
    -m : also update the /etc/pureftpd.pdb database
    For a 1:10 ratio, use -q 1 -Q 10
    To allow access only between 9 am and 6 pm, use -z 0900-1800
    Every time you modify the FTP Accounts you need to run pure-pw mkdb to apply the changes.

    Now we edit the Pure-FTPd config file at /etc/config/pure-ftpd

    vi /etc/config/pure-ftpd

    I will provide you a sample so you don't have to read about all the options and what are they used for.

    config pure-ftpd
            option port             '21'
            option noanonymous      '1'
            option chrooteveryone   '1'
            option maxclientsperip  '20'
            option maxclientsnumber '40'
            option umask            '133:022'
            option authentication   'unix'
            option enabled          '1'
            option passiveportrange '1985:2000'
            option tls              '1'
            option daemonize        '1'
            option authentication   'puredb:/etc/pureftpd.pdb'
            option prohibitdotfileswrite '1'
            option prohibitdotfilesread '1'
            option userbandwidth '50:50'
    #       option natmode '1'
    #       option brokenclientscompatibility' '1'
    Basically this runs pure-ftpd on Port 21 with passive ports from 1985-2000 with anonymous login disabled, tls set on optional (if client request it will provide if not just unencrypted communication).
    The default directory is chrooted which means user cannot change from their default directory to /.
    The # comments out lines, it should only be enabled if there are incompatibilities with the firewalls and clients. After you get good at FTP you might want to tweak the bandwidth and number of connections and other advance settings for more performance.

    Next we will do TLS encryption

    You have to generate a self-signed certification using OpenSSL, you should do it on the PC and copy the certificate to the router unless you are a masochist to want to do it on a 400MHZ MIPS Processor.

    To generate the certificate run on your PC (with OpenSSL installed) run 
    openssl req -x509 -days 365 -nodes -newkey rsa:1024 -keyout [Destination Directory]/pure-ftpd.pem -out [Destination Directory]/pure-ftpd.pem

    You can use days to specify how long before the self-signed certificate expire.

    This will create a certificate file called pure-ftpd.pem for TLS in the destination directory.
    Note the destination directory has to be the SAME.
    Pure-FTPd reads the TLS certificate in /etc/ssl/private so we make a directory there as is it is not created by default  

    mkdir -p /etc/ssl/private

    Then we Upload the file to the router to the directory we created.You should have /etc/ssl/private/pure-ftpd.pem This is location where Pure-FTPd will try to find a certificate to use for TLS communication if any.

    Then we change the file permission
    chmod 600 /etc/ssl/private/pure-ftpd.pem
    Finally we have to open the ports on the firewall to allow FTP communication.
    Note there are 2 types of ports we need to open FTP Active Ports and Passive Ports.
    We do it via LuCI GUI, go to Network -> Firewall -> Traffic Rules and Add the following Ruleset


    Save and Apply.

    Finally we restart Pure-FTPd so it will relaunch with the correct settings.
    /etc/init.d/pureftpd restart

    So now you need an FTP Client. On Web Browsers like Firefox there is a client built in by default.
    To utilise TLS encryption you have to use better clients, I recommend FileZilla.
    You specify TLS in the Connection Options.
      
    You have to get a Dynamic DNS address to reverse lookup your Router's external IP Address.
    There are free and paid options for home users free is usually good enough.
    AFRAID @ http://freedns.afraid.org/ is a good Free Dynamic DNS Address Provider(Funny name though =) ).
    It allows numerous domains for you to choose from.

    Again DDNS Updating Scripts is built into my 3.25 Kernel Trunk Router's Image by default but I will not be writing about setting up Dynamic DNS records (I modified the DDNS scripts to support HTTPS (by skipping checks) default OpenWRT DDNS does not have that).

    You should be able to login to your FTP Server from everywhere on Earth from the Internet in both Active and Passive Modes provided your workplace does not block FTP ports if so simply change port 21 to one of the unblock ports.

    Hopefully my guide is simple enough for you to understand how to setup an FTP server on OpenWRT.
    Read More
    Posted in | No comments

    Sunday, 25 September 2011

    Realtek Driver Mod

    Posted on 21:18 by Unknown
    For a while there has been a Realtek Driver Mod for Realtek Audio Codec Only.
    This Mod enables better Audio by utilizing the X-Fi Software.
    I find this mod especially effective on laptops with very low power speakers like the Acer Aspire 3810 Timeline Laptops.

    Pre-Requesites:
    • Windows Vista/7 and above
    • Local Administrative Permission on the System
    The Mod requires the use of a Malware Vector to generate the crack that affects only Delphi Files so Delphi Developers should use with caution, it should not affect most other users. It is not a trojan/worm.
    If you don't trust the software do not use it.

    Step 1:
    Download the Files and uninstall existing Realtek Sound Drivers if any.

    Step 2:
    Extract and Install the Modified Realtek Drivers (they are not WHQL) using the AsusSetup Executable.

    Step 3:
    Reboot

    Step 4:
    Extract and Install the X-Fi Software.

    Step 5:
    Reboot

    Step 6:
    Right Click on the Sound Blaster Panel icon on the System Tray,
    choose Select Audio Device and Select SB-XFi MB2.

    Step 7:
    Reboot and enter Safe Mode by pressing F8 rapidly during reboot.

    Step 8:
    Extract the activator, find the .bat file, Right Click on it and Choose Run As Administrator.
    Open the Folder C:\ProgramData\Creative\SoftwareLock
    Check that the following files below are created:
    CTD1JXF23A.kga
    CTD5H2W3DK.kga
    CTL42SW23M.kga
    CTL52C6FE2.kga
    CTLD14KLI5.kga
    CTLD2JX234.kga
    CTLE2C3BA1.kga
    CTLP22SV21.kga
    CTT78HSK12.kga
    CTT92KD23N.kga

    Step 9:
    Delete all the zip files and folders you don't need(Clean Up), Reboot and Enjoy.
    Read More
    Posted in | No comments

    Friday, 15 July 2011

    Hacking TP-Link WR1043ND Part 4

    Posted on 23:36 by Unknown
    To Tweak the OpenWRT for Pure Performance there is no other way than editing config files from Terminal so I hope you actually read Part 3 before.
    There are 4 parts to Tweaking the Performance
    1. Wireless Performance
    2. Wired Performance
    3. Web Performance
    4. QoS (Quality Of Service)
    Tweaking Wireless Performance:

    Setting to Wireless N with G backward compatibility

    The TP-Link WR1043ND Hardware has a 3 Transmit 3 Receive Radio that is only Single Band with 20/40MHZ  Frequency. It has Wireless B/G/N Capability.
    To fully understand WiFi Standards you need to read up on IEEE 802.11 standards.
    We start by tweaking the Radio.

    Wireless N allows backward compatibility with B and G, you need to set it to 802.11g+n.
    You can do this by logging into the Router via Putty using vi editor edit the file called "wireless" in /etc/config/, or do it in LuCI Web Interface(Router Config Page).


    Adjusting Channel Width:

    Next you need to make sure the Router is using 40MHZ Channel Width, this will allow greater throughput.
    You can do this by logging into the Router via Putty using vi editor edit the file called "wireless" in /etc/config/
    config 'wifi-device' 'radio0'
            option 'type' 'mac80211'
            option 'channel' '7'
            option 'macaddr' 'XX:XX:XX:XX:XX:XX'
            option 'hwmode' '11ng' #Wireless G and N Modes
            option 'htmode' 'HT40-' # Set to 2.4GHZ 40MHZ Fat Lower(-) Channel
            option 'noscan' '1' # Enable neighbour 'unfriendly' WiFi Settings
            option 'country' 'US'
            list 'ht_capab' 'SHORT-GI-40'
            list 'ht_capab' 'DSSS_CCK-40'
            option 'disabled' '0'
            option 'txpower' '24'
    config 'wifi-iface'
    option 'device' 'radio0'
    option 'network' 'lan'
    option 'mode' 'ap'
    option 'ssid' 'Your_SSID_Here'
    option 'encryption' 'psk2'
    option 'key' 'your_secret_key_here'

    Note that there are 2 htmodes, HT40+ and HT40- you set them based on the channel available. If you set it wrongly you have to log in to the router via Ethernet Cable and change it back.
    By rights 'htmode' is not allowed if there are competing BSSID using that channel (the good neighbor regulation), but you can override that with 'noscan' option. There is also a distance optimization setting which I tested the best values at 20-25.

    Below is a graph displaying the difference between 40MHZ Channel Width and 20MHZ Channel Width.
    Note that you can define more than 1 Access Point on OpenWRT. You can configure a Second AP as Guest and Fire-walling it from your own LAN.


    Higher TXPower (Transmit Power)

    Transmit Power allows you to resize the cell. Max Value is 24 only works with US regulatory settings.
    You can also try placing the Wireless Router at a higher position for better signal strength.

    Tweaking Wired Performance:

    Next you need to make sure the Router Ethernet Performance is adjusted by changing the sysctl variable this will allow greater throughput.
    You can do this by logging into the Router via Putty using vi editor edit the file called "sysctl.conf" in /etc/

    kernel.panic=3
    # The following 3 lines helps to ensure Router will always have
    # sufficient memory and will not crash during samba file copy
    vm.vfs_cache_pressure=1000
    vm.min_free_kbytes=4099
    vm.swappiness=0

    net.ipv4.conf.default.arp_ignore=1
    net.ipv4.conf.all.arp_ignore=1
    net.ipv4.ip_forward=1
    net.ipv4.icmp_echo_ignore_broadcasts=0
    net.ipv4.icmp_ignore_bogus_error_responses=1
    net.ipv4.tcp_ecn=0
    net.ipv4.tcp_fin_timeout=30
    net.ipv4.tcp_keepalive_time=120
    net.ipv4.tcp_syncookies=1
    net.ipv4.tcp_timestamps=1
    net.core.netdev_max_backlog=5000
    net.netfilter.nf_conntrack_checksum=0
    net.netfilter.nf_conntrack_max=32768
    net.netfilter.nf_conntrack_tcp_timeout_established=3600
    net.netfilter.nf_conntrack_udp_timeout=60
    net.netfilter.nf_conntrack_udp_timeout_stream=180
    # Use ipv6
    net.ipv6.conf.all.forwarding=1


    # disable bridge firewalling by default
    #net.bridge.bridge-nf-call-arptables=0
    #net.bridge.bridge-nf-call-ip6tables=0
    #net.bridge.bridge-nf-call-iptables=0
    # Increase TCP max buffer size setable using setsockopt()
    # 2 MB might be enough for some very long end-to-end paths
    net.core.rmem_max = 2097152
    net.core.wmem_max = 2097152
    # Increase Linux autotuning TCP buffer limits
    # min, default, and max number of bytes to use
    # (only change the 3rd value, and make it 2 MB or more)
    net.ipv4.tcp_rmem = 4096 87380 2097152
    net.ipv4.tcp_wmem = 4096 65536 2097152
     
    # The following 2 lines enable ipv6 privacy mode
    net.ipv6.conf.all.use_tempaddr=2
    net.ipv6.conf.default.use_tempaddr=2
    All the TCP tweaks are derived from ESnet
    Note: These tweaks are not found on OpenWRT How Tos, however I soon discovered that someone is working on bufferbloat hence the tweaks on buffersize should be approached with caution.


    Also if you have a Windows File Share you want to tell the Router firewall not to monitor SAMBA Packets.
    Windows Share also known as SAMBA in Linux uses the Port 445 so you need to tell OpenWRT to stop monitoring Packet Originating from LAN using Port 445.


    Tweaking Web Performance:
    Web Peformance typically require a lot of DNS Look up so you want to tell OpenWRT to use the Fastest DNS Server available.
    You can do this by logging into the Router via Putty using vi editor edit the file called "dnsmasq.conf" in /etc/ or do it in the file /etc/config/dhcp
    and add the fastest DNS Server closest to you.
    Add the Line Below and change the IP of the server to YOUR fastest DNS Server. My Fastest DNS Servers may not be your Fastest DNS Server.
    dhcp-option=6,165.21.83.88,8.8.8.8,208.67.222.222
    Blue is a Singapore ISP DNS Server, Green is Google DNS Server, Red is OpenDNS Server.
    There is no limit of the number of DNS Server you can set on OpenWRT

    Quality of Service                    

    What is Quality of Service?
    Quality of Service makes it so that during torrenting, your webpages doesn't take a long time to load even though you are on a 1Mbps Connection.
    It does this by prioritizing network traffic, putting webpage network packets in higher importance than torrent packets.
    The step to installing QoS is logging into the Router via Putty then
    opkg install luci-app-qos
    You set the QoS by setting the Port the Network Originate from and the Priority. Or you can set layer 7 filter to detect torrent traffic. Note that Layer 7 filtering is processor intensive activity and might cause the routing performance of the router to drop.


    Hopefully you learn a lot from this series of blog post and enjoy the high performance of your Modified Router running on OpenSource Software.
    If you run a Windows Share Server when you place the laptop beside the router and do a copy you should be getting insane WiFi Speeds @ 150Mbps at 5m line of sight
    Let the numbers speak for themselves!


    In case you modified the wrong config files and got lock out the fail safe mode is here.

    If you are interested I have a OpenWRT built for TL-WR1043ND that I use personally myself. It is optimized to my satisfaction for pure performance.
    You can get it here.
    If you actually tried my firmware you will find that all the tweaks I listed above have been already added to the firmware defaults so there is nothing additional to tweak.
    Read More
    Posted in | No comments

    Hacking TP-Link WR1043ND Part 3

    Posted on 21:26 by Unknown
    I will only be posting HOW-TO not found in OpenWRT Pages, if you need to config a particular setting please refer to the Well-Documented OpenWRT HOW-TOs here.
    Useful Wiki on OpenWRT include
    • Getting 3G Modem working
    • VPN (not complete)
    • Files and Settings
    • NFS Network FileSharing
    It is troublesome/pointless to rewrite well-documented resources.
    Reading the How-To is a must have for all OpenWRT newbies!

    First you need to set a Router Config Page Login Password.
    Otherwise the SSH ports will not be open for you to configure and upload files to it.
    Open Web Browser, Enter "192.168.1.1" in URL Bar.
    Then follow the picture below:


    From here onward is to demostrate how to login and use the Router like a Linux Terminal Computer.
    It makes little sense not to leverage on the Compute Capabilities of Linux after using a more powerful third party firmware.
    OpenWRT assumes users know Linux Terminal KungFu hence it is intimidating to those who don't.
    Hopefully after reading this you will pick up some Terminal KungFu.
    _______________________________________________
    Upload Files to Router using SCP







    ______________________________
    SSH (Login) into Router



    Basic Linux Commands in OpenWRT
    • "ls" - List Files in Existing Folder
    • "dmesg" - Display System(Router) diagnostic message 
    • "pwd" - Display Present Working Directory
    • "opkg" - OpenWRT Package Installer 
      • "opkg install package" to install a software call "package"
      • "opkg remove package" to uninstall a software call "package"
      • "opkg list-install" to list all installed software"
      • "opkg update" to update list of package available in the OpenWRT Repository the router needs to be connected to the internet before you can update
      • "opkg" to display all possible commands
    • "wifi" to restart Wireless Radio
    • "ifup/down" to start or stop a Particular Interface
      • "ifup wan" to start WAN interface
      • "ifdown wan" to stop WAN interface
      • "ifup lan" to start LAN interface
      • "ifdown lan" to stop LAN interface
    • "cd" to change directory
      • "cd .." to go up 1 level (Exit the folder)
      • "cd /" to go to Root Directory 
      • "cd /tmp/ to go to tmp directory (If you want to go to a specific directory type "cd /tm" then press Tab to auto complete the name of the folder useful if the name of the folder is very very long
    • "vi" Text Editor
      • eg. to Edit a file call "network" in folder "/etc/config/" type "vi /etc/config/network"
      • The default mode in VI is view mode to display text files
      • To enter/delete Text in vi press "i" to Enter insert mode and type to enter backspace to delete
      • To delete a particular line of text in vi Press "Esc" go to the line using arrow then enter "dd" twice and the line disappears
      • To save a file press "Esc" then ":w" (w stands for write)
      • To exit VI press "Esc" then ":q" (q stands for quit)
      • To exit without saving  press "Esc" then ":q!" (! stands for "I don't care just do it !)
      • To exit with saving  press "Esc" then ":wq"
    • "reboot" to restart Router
    • "cp" - copy eg to copy a file called "network" from inside /tmp/ to /etc/config"      
    "cp /tmp/network /etc/config/network"
      • Syntax as follows: cp <source> <destination>
    • "rm" - Delete a particular file
    • "wget" -Download file from Internet (Must be connected to Internet first, make sure the file size doesn't exceed the the total memory of the router)

    The list of commands is actually quite a chunk, you should read up on Linux Shell if you are interested.
    Read More
    Posted in | No comments

    Hacking TP-Link WR1043ND Part 2

    Posted on 21:25 by Unknown
    Part 2: Upgrading to OpenWRT


    First of all what is OpenWRT?

    It is a niche Linux Distribution meant for Routers.
    Which means after installing it you can add packages onto the Operating System to expand its capabilities.
    Much like any Linux Distribution it maintains a package repository for end-users.

    It will help alot if you have prior knowledge on Linux Terminal Commands because OpenWRT run Linux.

    Why OpenWRT out of so many Third Party Firmware?

    OpenWRT provides its own Repository brimming with numerous packages.
    It is very much like Debian is for Routers.

    Hardware Required:
    1. Working Ethernet Cable to connect the PC to the Router                                                                                (You should have 1 in the Box where you bought the Router).
    Software Required:
    The Software Required is for controlling the Router Via a PC otherwise you can't interact with it.
    1. SSH Terminal (For Windows Download Putty, Most GNU\Linux should have SSH Terminals by Default)           This Program is for Accessing the router like logging in to a server.
    2. WinSCP (For Windows Download WinSCP, Most GNU\Linux should have SCP Terminals by Default)      This Program is for Uploading and Downloading Packages to the Router.
    3. Fairly Advance Web Browser ( Either Firefox, Internet Explorer and Chrome will do)                                       This is for accessing the LuCI Web Interface installed into the router.
    a)Download the Firmware from OpenWRT Download Site.

    For TP-Link WR1043ND we access the OpenWRT Stable Repository.
    Go to the Folder for the latest release of OpenWRT then go into the /ar71xx/ subfolder.
    This folder is meant for Atheros MIPS Processor based routers.
    Scroll until you find files with the name "openwrt-ar71xx-tl-wr1043nd-v1-"

    Look carefully and you should see 2 matching files:
    The first ends with
    openwrt-ar71xx-tl-wr1043nd-v1-squashfs-sysupgrade.bin
    The second one ends with
    openwrt-ar71xx-tl-wr1043nd-v1-squashfs-factory.bin
    Sysupgrade is for Upgrading Routers already installed with OpenWRT of the older versions while factory is for Upgrading Routers on Original Firmware.

    Assuming the Router is runnning Original Stock Firmware from TP-Link, download
    openwrt-ar71xx-tl-wr1043nd-v1-squashfs-factory.bin 

    b)Flashing the Firmware
    1. Disconnect all Internet Connections on the PC and Router. 
    2. Ensure the Router/PC is on Stable Power Source.
    3. Connect the PC use to upload the file to the Router using the Ethernet Cable.
    4. Open Internet Browser on the PC
    5. Type "192.168.1.1" in the URL Bar of the Internet Browser to access the TP-Link Router Configuration Page if you did not touch any ip configuration the default is usually 192.168.1.1.
    6. Default Login name and Password is written under the Router.
    7. Go to the Firmware Upgrade Utility Page
    1. Click on Browse then navigate to the Folder where you downloaded  openwrt-ar71xx-tl-wr1043nd v1-squashfs-factory.bin
    2. Click Upgrade and Wait for 15 mins 

      1. Double Check the Lights on the Router it should blink quickly then turn off then turn on again.
      2. Type "192.168.1.1" in the URL Bar of the Internet Browser again. You should see the LuCI Webpage
       
      1. There should be no password just click login. Set a password (Under Administration) immediately to enable SSH Login.
      2. You are done your router is now running on OpenWRT, but you are not done yet you still need to configure the router for normal use.
      Read More
      Posted in | No comments

      Hacking TP-Link WR1043ND Part 1

      Posted on 05:21 by Unknown
      This is a series of blog post detailing about how to hack the TP-Link WR1043ND to maximize its potential.
      I will try to be as noob friendly as possible.
      My Mods are in no way original, it is just a collection of existing mods combined into a few articles for easy instructional reading.
      Special Thanks to the guys @ OpenWRT who made this possible.

      The hacks done are as follows:
      1. Upgrade the Internal DDR RAM from 32MB to 64MB.
      2. Upgrading the firmware from TP-Link Stock Firmware to OpenWRT.
      3. Accessing/Operating OpenWRT from Shell Commands
      4. Configuring and Tweaking the Router for Maximium Performance. Please Read 3 first.
      First of all why mod a router?
      • To make it do more for less because a router is actually an embedded system which can do more running Open Firmware rather than suffer the limitations imposed by stock firmware. After installing OpenWRT you will be able to install packages to make the router perform more tasks than ever.
      • To get better performance. Most manufacturers do not actually tweak the router performance much, rather they prefer to prettify the routers so they can sell more instead of making it do better at what it is supposed to do because most consumers are stupid.
      • Get latest updates. When running stock firmware, updates are pretty much at the mercy of manufacturers, compared to running open firmware like OpenWRT you get new updates every time there is a new release.
      • Learn more. You get to learn more about Linux and other stuff you never knew before and that itself is priceless.
      Why you do not want to mod a router:
      • Firstly it voids warranty, it is possible that during the course of modding you may damage the router if you made a mistake hence it doesn't make sense for the manufacturer to pay for your mistake.
      • It is tedious and costly if you do not have the tools or the patience or brains.
      The Router


      The Router in question is the TP-Link WR1043ND.
      Why TP-Link WR1043ND out of so many OpenWRT supported routers?
      1. It is cheap. If you check the market for routers you will find it selling for a low cost. I bought it for SGD$75. Do the conversion and you will be convinced.
      2. It is powerful. Again if you check the market you will find the next cheapest Gigabit Router priced at more than SGD$100. In the WR1043ND you will find lots of flash memory for installing OpenWRT as well. The 3 Antennas it possess further increase the Wireless Performance. It also contain a USB Port for expanded possibilities (FileSharing anybody?).
      3. It is Stable. Because of reason 1) and 2) many hardware hackers have bought and modified this router and OpenWRT to suit it, so it runs incredibly stable on OpenWRT.
      TP-Link is a Network Device Manufacturer from China but being objective, I am not concern about branding. I don't get anything useful out of branding, rather I am more concern with the performance I can get for a low cost. Moreover it is a excellent product specification wise.

      Information about the MIPS24KC Core SKU




      The Specification:

      The Core
      CPU = Atheros AR9132-BC1E rev 2
      MIPS Architecture Rev = MIPS 24Kc V7.4
      ASEs implemented = mips16
      (code-compression support only)
      CPU Speed = 400MHz
      Advance High Performance Bus (AHB) = 200MHZ
      Instruction cache = 64kB, VIPT, 4-way, linesize 32 bytes
      Data cache = 32kB, 4-way, VIPT, cache aliases, linesize 32 bytes
      Flash Type = Serial
      Flash Chip = 25P64V6P 99AJAV5 MYS722
      Flash Size = 8MB
      RAM Size = 32MB
      RAM Bus = 400MHZ
      RAM Chip = Zentel A3S56D40FTP
      Switch = Realtek RTL8366RG A1G17A2 GA05B
      Ethernet Port Count = Gigabit LAN and WAN Ports
      Power = 12V/1.5A
      USB = 1 USB 2.0 Port

      The Radio
      Wireless Radio = Atheros AR9103 3x3 MIMO
      Channel Width = 20MHZ or 40MHZ
      Antenna Connector Type = 3dBi Detachable RP-SMA Omni Directional Antenna X 3
      Wireless Standard = IEEE 802.11b/g/n
      WiFi Operating Frequency = 2.4~2.4835GHz (Single Band)
      802.11n = up to 300Mbps
      802.11g = 6, 9, 12, 18, 24, 36, 48, 54Mbps
      802.11b = 1, 2, 5.5, 11Mbps
      Part 1: Upgrading the DDR RAM

      Upgrading the DDR RAM requires soldering, if you are not good at this you can skip this section.
       
      Tools required:
      1. Soldering Iron
      2. Solder (Try to get good quality ones poor quality ones have very little flux hence difficult to solder)
      3. Soldering Flux
      4. Way to Desolder SMT Component ( I used ChipQuik, simple fast, easy, and clean )
      5. Desoldering Wick
      6. Dexterous Hands
      7. Magnifying Lens
      8. Tweezer 
      9. Isopropyl Alcohol for Cleaning also known as Rubbing Alcohol in Pharmacies
      10. Compatible DDR RAM IC (TSOP 66, 66 pins and 16bit Data Width, Check the DataSheet to be sure)
      List Of Known Compatible RAM IC:
      Hynix HY5DU121622DTP-D43
      Infineon HYB25D512160B
      a) Dissembling The Router
      1. Turn off the Power and Unplug all cables. This is common sense.
      2. Unscrew the Antennas, this is to prevent obstruction of soldering activity later.
      3. Ground yourself, depending on where you are, electrostatic charges can accumulated on your body and its discharge may damage sensitive electrical equipment.
      4. Remove the 2 Rubber Feet at the back of the router. The exposed screws are circled in Red.
      5. Pull the lid up from the back so the router lid is angled as shown below.
      6. Using a Flat Head Screw Driver, slide the tip into the slit exposed in front and give it a gentle twist and the cover should come off. Do it for both sides.                                                                                                           
      7. You should see the exposed board as shown. The DRAM to be desoldered is shown below boxed in Red                                                                                                                                                        
      b)SMT Desoldering the DRAM
      1. Ensure the tip of the Soldering Iron is clean, otherwise you will have a hard time soldering.
      2. Spread some soldering flux along on the legs of the DRAM using a tweezer.
      3. Next, I melt the ChipQuik on the legs of the IC using the soldering Iron. ChipQuik is a low temperature solder which means it remains in liquid state at warm temperatures therefore it is easy to remove it.
      4. Make sure ChipQuik fuses with the legs of the RAM. Do not apply heat directly to ChipQuik or the legs or the DRAM or the Board using the soldering Iron. The trick is to touch the ChipQuik, melt it, spread it on the legs and remove the soldering Iron. This is to lessen the likelyhood of damaging the DRAM by excessive heating. Do this quickly repeatedly until the ChipQuik fuses with the legs of the DRAM. Do this for BOTH sides of the legs on the DRAM.
      5. When the ChipQuik fuses with all the legs of the DRAM, gently but firmly nudge the DRAM to dislodge it from the solder pads using a tweezer while ChipQuik is still fluid. If it doesn't budge repeat 3) and try again until it dislodges. Remove the DRAM.
      6. After it dislodges use a desoldering wick dip with some flux and put it on the remaining ChipQuik left on the board. You do not have to use desoldering wick on big pieces of ChipQuik you can pluck it off the green board when it cools.
      7. Heat the soldering wick with the soldering Iron and it should absorb the ChipQuik like a sponge with water.
      8. Clean the Soldering Pad using the method in 7.
      9. At the end you should be left with a 66 clean soldering pads ready accept a new IC.
      10. If you are still not sure what to do after reading this watch some youtube videos on SMT Soldering it will give you a better picture on SMT Soldering.
      c) Soldering on the new DRAM
      1. You should have the DRAM IC upgrade ready as shown. 
      2. Apply some Flux on the Soldering Pad.
      3. Align the Pins of the New DRAM with the Soldering Pads. Notice there is a Black Circle on the DRAM. You need to match the Orientation of the DRAM with the Router Circuit Board diagram printed on the board.
      4. Make sure the legs are aligned on BOTH Side of the soldering pads. Apply Flux on the DRAM legs.
      5. Dip the tip of the Soldering Iron with some solder and spread it on the legs.
      6. Gently spread the solder on the legs using the Soldering Iron. Touch the solder, gently drag along the legs and release, repeat until all the legs are covered. If solder is stucked between 2 or more legs, apply more flux on the stucked solder and repeat Step 6 again.
      7. Make sure the solder do not short the legs of the DRAM.
      8. Examine the Legs using a Magnifying Lens to make sure no shorting occurs. Make sure every leg of the DRAM gets some solder. If you have too much solder remove the excess out using the soldering wick.
      9. Clean the Router Board and the DRAM using clean cloth dipped in Isopropyl Alcohol (Rubbing Alcohol) 
      10. Again If you are still not sure what to do after reading this watch some youtube videos on SMT Soldering it will give you a better picture on SMT Soldering.
      Let the Router Board Dry (Alcohol evaporate quickly) turn on the power. Your Router should boot up just fine.
      Unlike BroadCom MIPS routers most Atheros MIPS router do not need modification of the NVRAM to fully initialize the Memory.

      Note that different Routers contain different memory. TSOP 66 is used by DDR Memory and has 66 Pins.
      The other common memory found is TSOP 54 which has 54 pins but TSOP 54 has low Storage Density hence it is unlikely to find a compatible DRAM to upgrade to.

      Extra Tips: If you feel your router is overheating this is a solution:

      Read More
      Posted in | No comments
      Newer Posts Older Posts Home
      Subscribe to: Posts (Atom)

      Popular Posts

      • Delete Windows System Files
        If you play around with Windows System Files sometimes it is not possible to delte them off after you had your fun. The following commands w...
      • Internet Explorer Tweak
        Here is a registry tweak for Internet Explorer Similar to the Mozilla Firefox tweak this enable you to increase the number simultaneous ser...
      • How to Mod your Laptop VGA BIOS
        Basically there are 2 locations where the VGA BIOS in laptops. Some OEMS embed the VGA BIOS in the EFI/BIOS in your laptops, other OEMs have...
      • Acer Phoenix BIOS Emergency Recovery
        This is for people who don't listen and interrupt the flashing BIOS for unknown reasons. This will work provided the BIOS BootBlock isn...
      • Secure Your Windows CD-Key (For Vista and 7)
        As you know everytime you activate a Windows Installation your Product Key can be retrieved via Software means. Don't believe me? Downl...
      • Changing the Acer Arcade Shortcut
        While surfing the Windows Registry (You must be thinking that I am weird =P) yesterday I found something interesting It is actually possible...
      • Some Interesting Modding Ideas
        I modded my Aspire 4530 AGAIN to control resultant temperature. Below are some ideas and pictures. Another mod idea This time a black anodi...
      • How to obtain the DSDT from your laptop
        There are many ways to rip the DSDT out of the laptop BIOS. If there is a BIOS editor it is possible to rip out the .AML file. However below...
      • Acer Aspire 4530 Boot Screen
        Acer Aspire 4530 Boot Dianogostic Screen PhoenixBIOS 4.0 Release 6.1 Copyright 1985-2008 Phoenix Technologies Ltd. All Rights Reserve 1.052....
      • List Of Modified BIOS Collection
        Here are the list of Modified BIOS Collection (mainly SLIC Mods), no warranty provided use at your own discretion! Acer Aspire 4520G BIOS Ac...

      Categories

      • 32bit
      • 64bit
      • acer
      • ahci
      • amd
      • apple
      • aspire 4530
      • aspire 4535G
      • aspire 4740
      • atheros
      • atom
      • BIOS
      • boot
      • cleanup
      • configure
      • device
      • disk
      • dismantle
      • download
      • driver
      • fan control
      • firefox
      • firewall
      • firmware
      • fix
      • flash
      • graphics
      • hwmonitor
      • internet
      • linux
      • macs
      • microsoft
      • modified
      • nvidia
      • optimize
      • overclock
      • performance
      • power savings
      • powermizer
      • proxy
      • ram
      • Realtek
      • review
      • secure
      • shortcut
      • speaker
      • synaptics
      • temperature
      • theme
      • timeline
      • tweak
      • undervolt
      • update
      • wallpaper
      • windows 7
      • windows vista
      • Windows Xp
      • winsat
      • wlan

      Blog Archive

      • ▼  2013 (10)
        • ▼  November (2)
          • A Simple How to use MiniDLNA on OpenWRT
          • OpenWRT TL-WDR3600/4300/4310 Release
        • ►  October (3)
        • ►  September (1)
        • ►  August (1)
        • ►  July (1)
        • ►  May (1)
        • ►  January (1)
      • ►  2012 (4)
        • ►  September (1)
        • ►  June (1)
        • ►  March (1)
        • ►  February (1)
      • ►  2011 (21)
        • ►  September (1)
        • ►  July (4)
        • ►  June (3)
        • ►  May (3)
        • ►  April (3)
        • ►  March (4)
        • ►  February (2)
        • ►  January (1)
      • ►  2010 (36)
        • ►  December (3)
        • ►  November (2)
        • ►  October (4)
        • ►  September (1)
        • ►  August (5)
        • ►  July (1)
        • ►  June (5)
        • ►  May (3)
        • ►  April (3)
        • ►  March (6)
        • ►  February (1)
        • ►  January (2)
      • ►  2009 (81)
        • ►  December (3)
        • ►  November (3)
        • ►  October (9)
        • ►  September (5)
        • ►  August (1)
        • ►  July (5)
        • ►  June (8)
        • ►  May (15)
        • ►  April (10)
        • ►  March (13)
        • ►  February (8)
        • ►  January (1)
      • ►  2008 (8)
        • ►  November (5)
        • ►  July (3)
      Powered by Blogger.

      About Me

      Unknown
      View my complete profile