прога Router Scan

Discussion in 'Беспроводные технологии/Wi-Fi/Wardriving' started by СЕРЖ32, 11 Nov 2013.

  1. mooooooon

    mooooooon Member

    Joined:
    4 Feb 2019
    Messages:
    170
    Likes Received:
    41
    Reputations:
    1
    any idea how can i login using this ?

    <Row No="3">
    <DM name="ViewName" val="IGD.AU4"/>
    <DM name="Enable" val="1"/>
    <DM name="IsOnline" val="0"/>
    <DM name="AppID" val="2"/>
    <DM name="User" val=""/>
    <DM name="Pass" val="zte"/>
    <DM name="Level" val="1"/>
    <DM name="Extra" val=""/>
    <DM name="ExtraInt" val="0"/>

    tried it using curl but it failed .. how while it's enabled ?
     
  2. qwerty_3322

    qwerty_3322 New Member

    Joined:
    31 Dec 2019
    Messages:
    12
    Likes Received:
    0
    Reputations:
    0
    mooooooon

    Do you have direct access to the router by telnet or ssh?
     
  3. mooooooon

    mooooooon Member

    Joined:
    4 Feb 2019
    Messages:
    170
    Likes Received:
    41
    Reputations:
    1
    I have both
     
  4. qwerty_3322

    qwerty_3322 New Member

    Joined:
    31 Dec 2019
    Messages:
    12
    Likes Received:
    0
    Reputations:
    0
    Then try just find the file with wps-pin and reset it. Also you probably need to find where to enable wps authentication mode on router config. And use Reaver.
     
  5. mooooooon

    mooooooon Member

    Joined:
    4 Feb 2019
    Messages:
    170
    Likes Received:
    41
    Reputations:
    1
  6. qwerty_3322

    qwerty_3322 New Member

    Joined:
    31 Dec 2019
    Messages:
    12
    Likes Received:
    0
    Reputations:
    0
  7. mooooooon

    mooooooon Member

    Joined:
    4 Feb 2019
    Messages:
    170
    Likes Received:
    41
    Reputations:
    1
    what does mean ? i opened that file two and couldn't find anything about the wps pin !


    but why ? you could just do it using 7 zip ... also i found that ssh password much earlier ... nothing new :(
     
  8. mooooooon

    mooooooon Member

    Joined:
    4 Feb 2019
    Messages:
    170
    Likes Received:
    41
    Reputations:
    1
    any help decrypting this zte zxhn h108n config file
    python decode_zte_config.py --key "GrWM2Hz&LTvz&f^5" db_default_dsl_cfg.xml config.bin.xml
    or
    python decode_zte_config.py --key "GrWM2Hz&LTvz&f^5" db_default_eth_cfg.xml config.bin.xml

    the script https://pastebin.com/GGxbngtK

    i got this error with the db_default_dsl_cfg.xml file
    struct.error: unpack requires a buffer of 24 bytes
    and this with the db_default_eth_cfg.xml file
    struct.error: unpack requires a buffer of 44 bytes

     

    Attached Files:

  9. mooooooon

    mooooooon Member

    Joined:
    4 Feb 2019
    Messages:
    170
    Likes Received:
    41
    Reputations:
    1
    thanks i was able to do it using RouterPassView
    and i found this
    upload_2020-2-23_20-1-10.png
    what is userIF ?
    note: i can't login using it .
     
  10. qwerty_3322

    qwerty_3322 New Member

    Joined:
    31 Dec 2019
    Messages:
    12
    Likes Received:
    0
    Reputations:
    0
    It mean you can write there your wps pin and try to upload configuration file to the router. Also if you have ssh access to the router you can create your own root user for access to web interface. The router system is UNIX-based
     
  11. mooooooon

    mooooooon Member

    Joined:
    4 Feb 2019
    Messages:
    170
    Likes Received:
    41
    Reputations:
    1
    What wouls i gain from that ?

    I don't care about that... asked about the accounts in case of other routers.
     
  12. qwerty_3322

    qwerty_3322 New Member

    Joined:
    31 Dec 2019
    Messages:
    12
    Likes Received:
    0
    Reputations:
    0
    Any news? Did you find something?
     
  13. mooooooon

    mooooooon Member

    Joined:
    4 Feb 2019
    Messages:
    170
    Likes Received:
    41
    Reputations:
    1
    Nob i didn't and customers support won't help
     
  14. qwerty_3322

    qwerty_3322 New Member

    Joined:
    31 Dec 2019
    Messages:
    12
    Likes Received:
    0
    Reputations:
    0
    #7274 qwerty_3322, 24 Feb 2020
    Last edited: 24 Feb 2020
  15. mooooooon

    mooooooon Member

    Joined:
    4 Feb 2019
    Messages:
    170
    Likes Received:
    41
    Reputations:
    1
  16. blaider

    blaider New Member

    Joined:
    27 Jan 2018
    Messages:
    13
    Likes Received:
    0
    Reputations:
    0
    Всем привет. Парни, подскажите, чем удобнее глянуть клиентов wifi без точки доступа?
     
  17. zimmer

    zimmer Active Member

    Joined:
    19 Jun 2015
    Messages:
    151
    Likes Received:
    136
    Reputations:
    1
    что значит без точки тоступа? если её нет, то как что-то на ней посмотреть?....
    а так это http://www.nirsoft.net/utils/wireless_network_watcher.html
    или если ты имееш ввиду что посмотреть клиентов в той точке к которой ты не подключен, то в кали airodump-ng в station смотри маки
     
  18. blaider

    blaider New Member

    Joined:
    27 Jan 2018
    Messages:
    13
    Likes Received:
    0
    Reputations:
    0
    Я имел в виду устройства, в зоне моего приема, с включенным wi-fi, но не подключенные к роутеру.
     
  19. zimmer

    zimmer Active Member

    Joined:
    19 Jun 2015
    Messages:
    151
    Likes Received:
    136
    Reputations:
    1
    тут скорее вопрос должен звучать так: "возможно ли такое?"
    да и это простым wi-fi адаптером врядли реализовать, тут надо "слушать радиоэфир" на частотах (по каналам, да и 5 Ггц в куче)
    единственное создаеш открытую точку доступа и ловиш тех у кого стоит автоматом подключение к открытой точке.

    это наверно ты вопрос задаешь в свете новости о уязвимости Kr00k?))))))))
     
    #7279 zimmer, 27 Feb 2020
    Last edited: 27 Feb 2020
  20. kaliastr2009

    kaliastr2009 New Member

    Joined:
    19 Oct 2015
    Messages:
    28
    Likes Received:
    2
    Reputations:
    0
    Добрый день . имеется роуртер ZTE ZXHN H118N с провайдерской прошивкой от дом ру . В локальной сити RS его ломает отлично . Но Из глобальной он не досупен. Покопаясь немного обнаружил у него порт 1050 . который запрашивает логи и пасс . немного по копаясь в прошивки ( нашел в интернете ) подобрал логин cracs пароль Snyk9Tl24v75fHr9Jn9V . RS при сканирование порта 1050 пишет dirname а не ZTE ZXHN H118N .
    Ip 95.79.185.0-254
    ссылка на дамп прошивки https://4pda.ru/forum/index.php?s=&showtopic=463323&view=findpost&p=38654654
    Есть предложения как из Глобальной сети его добить ?
     
    #7280 kaliastr2009, 27 Feb 2020
    Last edited: 27 Feb 2020
    4Fun likes this.