Is this a Asus Router hack?

colthorp_cross

Prominent
Nov 4, 2017
3
0
510
I have a Asus RT-AC66U, configured as a Media Bridge. I have done a hard reset and loaded the latest Firmware. I have deleted old logs and saved settings. Very unstable and stops for no reason. Here is a typical log after rebooting. The February date is the same every time, then returns to current time.
….
Jun 24 21:45:38 RT-AC66U: start httpd:80
Jun 24 21:45:41 dnsmasq-dhcp[4915]: no address range available for DHCP request via br0
Jun 24 21:45:41 rc_service: psta_monitor 386:notify_rc restart_wlcmode 1
Jun 24 21:45:41 FTP Server: daemon is stoped
Jun 24 21:45:41 Samba Server: smb daemon is stoped
Jun 24 21:45:52 RT-AC66U: start httpd:80
Feb 13 19:00:15 syslogd started: BusyBox v1.17.4
Feb 13 19:00:15 kernel: klogd started: BusyBox v1.17.4 (2018-04-27 22:16:05 CST)
Feb 13 19:00:15 kernel: start_kernel
Feb 13 19:00:15 kernel: Linux version 2.6.22.19 (root@asus) (gcc version 4.2.3) #1 Fri Apr 27 22:17:57 CST 2018
Feb 13 19:00:15 kernel: CPU revision is: 00019749
Feb 13 19:00:15 kernel: Found an ST compatible serial flash with 32 64KB blocks; total size 2MB
Feb 13 19:00:15 kernel: Determined physical RAM map:
Feb 13 19:00:15 kernel: memory: 07fff000 @ 00000000 (usable)
Feb 13 19:00:15 kernel: memory: 08000000 @ 87fff000 (usable)
Feb 13 19:00:15 kernel: Built 1 zonelists. Total pages: 585216
Feb 13 19:00:15 kernel: Kernel command line: root=/dev/mtdblock3 console=ttyS0,115200 init=/sbin/preinit
Feb 13 19:00:15 kernel: Primary instruction cache 32kB, physically tagged, 4-way, linesize 32 bytes.
Feb 13 19:00:15 kernel: Primary data cache 32kB, 4-way, linesize 32 bytes.
Feb 13 19:00:15 kernel: PID hash table entries: 2048 (order: 11, 8192 bytes)
Feb 13 19:00:15 kernel: CPU: BCM5300 rev 1 pkg 0 at 600 MHz
Feb 13 19:00:15 kernel: Using 300.000 MHz high precision timer.
Feb 13 19:00:16 kernel: Dentry cache hash table entries: 65536 (order: 6, 262144 bytes)
Feb 13 19:00:16 kernel: Inode-cache hash table entries: 32768 (order: 5, 131072 bytes)
Feb 13 19:00:16 kernel: Mount-cache hash table entries: 512
Feb 13 19:00:16 kernel: PCI: Initializing host
Feb 13 19:00:16 kernel: PCI: Reset RC
Feb 13 19:00:16 kernel: PCI: Initializing host
Feb 13 19:00:16 kernel: PCI: Reset RC
Feb 13 19:00:16 kernel: PCI: Fixing up bus 0
Feb 13 19:00:16 kernel: PCI/PCIe coreunit 0 is set to bus 1.
Feb 13 19:00:16 kernel: PCI: Fixing up bridge
Feb 13 19:00:16 kernel: PCI: Fixing up bridge
Feb 13 19:00:16 kernel: PCI: Enabling device 0000:01:00.1 (0004 -> 0006)
Feb 13 19:00:16 kernel: PCI: Fixing up bus 1
Feb 13 19:00:16 kernel: PCI/PCIe coreunit 1 is set to bus 2.
Feb 13 19:00:16 kernel: PCI: Fixing up bridge
Feb 13 19:00:16 kernel: PCI: Fixing up bridge
Feb 13 19:00:16 kernel: PCI: Enabling device 0000:02:00.1 (0004 -> 0006)
Feb 13 19:00:16 kernel: PCI: Fixing up bus 2
Feb 13 19:00:16 kernel: IP route cache hash table entries: 4096 (order: 2, 16384 bytes)
Feb 13 19:00:16 kernel: TCP established hash table entries: 16384 (order: 5, 131072 bytes)
Feb 13 19:00:16 kernel: TCP bind hash table entries: 16384 (order: 4, 65536 bytes)
Feb 13 19:00:16 kernel: highmem bounce pool size: 64 pages
Feb 13 19:00:16 kernel: pflash: found no supported devices
Feb 13 19:00:16 kernel: Boot partition size = 262144(0x40000)
Feb 13 19:00:16 kernel: Creating 2 MTD partitions on "sflash":
Feb 13 19:00:16 kernel: 0x00000000-0x00040000 : "pmon"
Feb 13 19:00:16 kernel: 0x001f0000-0x00200000 : "nvram"
Feb 13 19:00:16 kernel: Found a Zentel NAND flash with 2048B pages or 128KB blocks; total size 128MB
Feb 13 19:00:16 kernel: lookup_nflash_rootfs_offset: offset = 0x0
Feb 13 19:00:16 kernel: nflash: squashfs filesystem found at block 9
Feb 13 19:00:16 kernel: Creating 4 MTD partitions on "nflash":
Feb 13 19:00:16 kernel: 0x00000000-0x02000000 : "linux"
Feb 13 19:00:16 kernel: 0x0013528c-0x02000000 : "rootfs"
Feb 13 19:00:16 kernel: 0x04000000-0x06000000 : "linux2"
Feb 13 19:00:16 kernel: 0x0413528c-0x06000000 : "rootfs2"
Feb 13 19:00:16 kernel: Creating 3 MTD partitions on "brcmnand":
Feb 13 19:00:16 kernel: 0x00000000-0x02000000 : "trx"
Feb 13 19:00:16 kernel: 0x04000000-0x06000000 : "asustrx2"
Feb 13 19:00:16 kernel: 0x06000000-0x07f00000 : "brcmnand"
Feb 13 19:00:16 kernel: dev_nvram_init: _nvram_init
Feb 13 19:00:16 kernel: u32 classifier
Feb 13 19:00:16 kernel: Netfilter messages via NETLINK v0.30.
Feb 13 19:00:16 kernel: nf_conntrack version 0.5.0 (2048 buckets, 16384 max)
Feb 13 19:00:16 kernel: ip_tables: (C) 2000-2006 Netfilter Core Team
Feb 13 19:00:16 kernel: net/ipv4/netfilter/tomato_ct.c [Apr 27 2018 22:17:36]
Feb 13 19:00:16 kernel: ip6_tables: (C) 2000-2006 Netfilter Core Team
Feb 13 19:00:16 kernel: VFS: Mounted root (squashfs filesystem) readonly.
Feb 13 19:00:16 kernel: Warning: unable to open an initial console.
Feb 13 19:00:16 kernel: Failed to execute /sbin/preinit. Attempting defaults...
Feb 13 19:00:16 kernel: ctf: module license 'Proprietary' taints kernel.
Feb 13 19:00:16 kernel: et_module_init: passivemode set to 0x0
Feb 13 19:00:16 kernel: et_module_init: et_txq_thresh set to 0xce4
Feb 13 19:00:16 kernel: bcm_robo_enable_switch: EEE is disabled
Feb 13 19:00:16 kernel: eth0: Broadcom BCM47XX 10/100/1000 Mbps Ethernet Controller 6.30.163.2002 (r382208)
Feb 13 19:00:16 kernel: wl_module_init: passivemode set to 0x0
Feb 13 19:00:16 kernel: PCI: Enabling device 0000:01:01.0 (0000 -> 0002)
Feb 13 19:00:16 kernel: eth1: Broadcom BCM4331 802.11 Wireless Controller 6.30.163.2002 (r382208)
Feb 13 19:00:16 kernel: PCI: Enabling device 0000:02:01.0 (0000 -> 0002)
Feb 13 19:00:16 kernel: eth2: Broadcom BCM4360 802.11 Wireless Controller 6.30.163.2002 (r382208)
Feb 13 19:00:16 kernel: Algorithmics/MIPS FPU Emulator v1.5
Feb 13 19:00:17 LAN network changes (%s/%s --> %s/%s). : 192.168.1.144
Feb 13 19:00:17 Samba Server: smb daemon is stoped
Feb 13 19:00:17 kernel: wlc_phy_cal_init_acphy: NOT Implemented
Feb 13 19:00:18 dnsmasq-dhcp[356]: no address range available for DHCP request via br0
Feb 13 19:00:18 RT-AC66U: start httpd:80
Feb 13 19:00:19 syslog: Generating SSL certificate...
Feb 13 19:00:21 NAT Tunnel: AAE Service is stopped
Feb 13 19:00:21 disk monitor: be idle
Feb 13 19:00:21 AAE: AAE Service is started
Feb 13 19:00:21 jffs2: valid logs(1)
Feb 13 19:00:21 syslog: module ledtrig-usbdev not found in modules.dep
Feb 13 19:00:22 syslog: module leds-usb not found in modules.dep
Feb 13 19:00:22 rc_service: psta_monitor 388:notify_rc restart_wlcmode 0
Feb 13 19:00:23 kernel: SCSI subsystem initialized
Feb 13 19:00:23 Mastiff: init
Feb 13 19:00:26 dnsmasq-dhcp[376]: no address range available for DHCP request via br0
Feb 13 19:00:26 dnsmasq-dhcp[376]: no address range available for DHCP request via br0
Feb 13 19:00:29 rc_service: psta_monitor 388:notify_rc restart_wlcmode 1
Feb 13 19:00:29 FTP Server: daemon is stoped
Feb 13 19:00:29 Samba Server: smb daemon is stoped
Feb 13 19:00:37 RT-AC66U: start httpd:80
Feb 13 19:00:37 syslog: Generating SSL certificate...
Feb 13 19:00:38 rc_service: udhcpc_lan 501:notify_rc stop_httpd
Feb 13 19:00:38 rc_service: waitting "restart_wlcmode 1" via psta_monitor ...
Feb 13 19:00:39 rc_service: udhcpc_lan 501:notify_rc start_httpd
Feb 13 19:00:39 rc_service: waitting "stop_httpd" via udhcpc_lan ...
Feb 13 19:00:40 rc_service: udhcpc_lan 501:notify_rc start_dnsmasq
Feb 13 19:00:40 rc_service: waitting "start_httpd" via udhcpc_lan ...
Feb 13 19:00:40 RT-AC66U: start httpd:80
Feb 13 19:00:40 syslog: Generating SSL certificate...
Feb 13 19:00:41 ntp: start NTP update
Feb 13 19:00:42 LAN network changes (%s/%s --> %s/%s). : 192.168.1.1
Feb 13 19:00:42 rc_service: udhcpc_lan 501:notify_rc stop_samba
Feb 13 19:00:42 rc_service: udhcpc_lan 501:notify_rc start_samba
Feb 13 19:00:42 rc_service: waitting "stop_samba" via udhcpc_lan ...
Feb 13 19:00:42 Samba Server: smb daemon is stoped
Feb 13 19:00:44 ntp: start NTP update
Jun 24 22:01:07 rc_service: ntp 520:notify_rc restart_diskmon
Jun 24 22:01:07 disk_monitor: Finish
Jun 24 22:01:07 disk monitor: be idle
Jun 24 22:01:24 crond[378]: time disparity of 714361 minutes detected

 
Solution
Most likely the date of the firmware. 714361 is 496 days. Subtract those days from Jun 24 and you get Feb 14 2017.

https://www.asus.com/us/Networking/RTAC66U/HelpDesk_BIOS/

Firmware Version 3.0.0.4.380.7266 2017/02/14

TRENDING THREADS