10-01-2023, 10:28 PM
A nice even 1000 passwords for the 5268AC. I think this is a good place to leave it, unless anybody has any more ideas...
https://pastebin.com/22ZGhHg4
https://pastebin.com/22ZGhHg4
5268ac routers
|
10-01-2023, 10:28 PM
A nice even 1000 passwords for the 5268AC. I think this is a good place to leave it, unless anybody has any more ideas...
https://pastebin.com/22ZGhHg4
12-23-2023, 09:37 PM
Look at what Santa left in my stocking!!!!
Let's crack it open and see if its firmware contains any mysteries....
12-29-2023, 06:47 AM
This pace edition is straight from the factory! I've got root access over UART. And check out the /usr/bin directory.... factory_set_default_wifi_passwd!
*sad trombone* It's just a script to pull the default password from elsewhere, not the algo. Now to find the elsewhere! Code: %factory# ls /usr/bin
01-12-2025, 09:59 AM
(12-06-2021, 02:03 AM)drsnooker Wrote:(11-28-2021, 03:21 AM)calexico Wrote: Looks very promising, terrific work; sorry I'm no help. Curious if you've had any luck reading the filesystem from the NAND? I couldn't find any open source implementation of OpenTDS... so I was going to try and figure it out. I'd like to be able to modify the files, but there seems to be some checksums likely for bad block detection My idea is to unpack a pkgstream and then compare the chunks with the NAND dump and go from there... another was to try and emulate with QEMU
01-12-2025, 11:37 AM
@b1tninja, I eventually got a clip and managed to get the NAND dumped in situ. However, since we know the root password as well as the algo for the password of user: rma (also with root privileges), it was no longer necessary to figure out how to binwalk the NAND dump, as you can just access the modem over UART.
01-12-2025, 12:04 PM
(01-12-2025, 11:37 AM)drsnooker Wrote: @b1tninja, I eventually got a clip and managed to get the NAND dumped in situ. However, since we know the root password as well as the algo for the password of user: rma (also with root privileges), it was no longer necessary to figure out how to binwalk the NAND dump, as you can just access the modem over UART. Unfortunately the newer firmwares seem to prevent downgrade and one of the scripts at startup disables input over the debug port. I did find a compatible connector for that the uart though which is handy: samtec MEC1-108-02-S-D-A. Alright well thanks anyway guess I'm on my own I'll report back here when I figure it out |
« Next Oldest | Next Newest »
|