Advertisement
Guest User

Untitled

a guest
Jun 8th, 2018
189
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 10.02 KB | None | 0 0
  1. Reading config...
  2. Line:defaultHost=192.168.1.1
  3. Line:defaultUsername=admin
  4. Line:defaultPassword=admin
  5. Line:defaultUpgradeFilename=
  6. Line:defaultStartupVariant=DGA4130 AGTEF 1.0.3
  7. Line:defaultFlashFirmware=0
  8. Line:defaultFlashSleepDelay=120
  9. Line:defaultConnectRetryDelay=5
  10. Line:defaultInterCommandDelay=5
  11. Line:variant=789vac v2 iiNet,Ping,dyndns.com,uci set dropbear.@dropbear[0].PasswordAuth='on';uci set dropbear.@dropbear[0].RootPasswordAuth='on';uci set dropbear.@dropbear[0].enable='1';uci commit;echo -e "root\nroot"|passwd;/etc/init.d/dropbear restart
  12. Line:variant=789vac v2 Tiscali,Ping,dyndns.com,sed -i 's#root:/bin/false#root:/bin/ash#' /etc/passwd;uci set dropbear.@dropbear[0].PasswordAuth='on';uci set dropbear.@dropbear[0].Interface='lan';uci set dropbear.@dropbear[0].RootPasswordAuth='on';uci set dropbear.@dropbear[0].enable='1';uci commit;echo -e "root\nroot"|passwd;/etc/init.d/dropbear restart
  13. Line:variant=789vac v2 iiNet Root Inactive UNO,Ping,dyndns.com,sed -i 's/off/on/' /overlay/$(cat /proc/banktable/inactive)/etc/config/dropbear;sed -i 's/0/1/' /overlay/$(cat /proc/banktable/inactive)/etc/config/dropbear;sed -i 's#root:/bin/false#root:/bin/ash#' /overlay/$(cat /proc/banktable/inactive)/etc/passwd;sed -i "1c $(sed 1q /etc/shadow)" /overlay/$(cat /proc/banktable/inactive)/etc/shadow;switchover
  14. Line:variant=DGA4130 AGTEF 1.0.3,Ping,dyndns.com,sed -i '1croot:x:0:0:root:/root:/bin/ash' /etc/passwd;uci set dropbear.@dropbear[0].RootPasswordAuth='on';uci set dropbear.@dropbear[0].enable='1';uci commit;echo -e "root\nroot"|passwd;/etc/init.d/dropbear restart
  15. Line:variant=DGA4132 AGTHP 1.0.3,DDNS,dyndns.it,sed -i 's#root:/bin/false#root:/bin/ash#' /etc/passwd;uci set dropbear.lan.enable=1;uci set dropbear.lan.RootPasswordAuth=on;uci commit;echo -e "root\nroot"|passwd;/etc/init.d/dropbear restart
  16. Line:variant=DGA4132 1.0.3 Root Inactive,DDNS,dyndns.it,sed -i 's#root:/bin/false#root:/bin/ash#' /etc/passwd;uci set dropbear.lan.enable=1;uci set dropbear.lan.RootPasswordAuth=on;uci commit;echo -e "root\nroot"|passwd;/etc/init.d/dropbear restart;sed -i 's/off/on/' /overlay/$(cat /proc/banktable/inactive)/etc/config/dropbear;sed -i 's/0/1/' /overlay/$(cat /proc/banktable/inactive)/etc/config/dropbear;sed -i 's#root:/bin/restricted_shell#root:/bin/ash#' /overlay/$(cat /proc/banktable/inactive)/etc/passwd;sed -i "/option Interface 'lan'/s/.*/&\n\toption RootPasswordAuth 'on'/" /overlay/$(cat /proc/banktable/inactive)/etc/config/dropbear;sed -i "1c $(sed 1q /etc/shadow)" /overlay/$(cat /proc/banktable/inactive)/etc/shadow;switchover
  17. Line:variant=DGA4130 1.0.3 Root Inactive,Ping,dyndns.com,sed -i '1croot:x:0:0:root:/root:/bin/ash' /etc/passwd;uci set dropbear.@dropbear[0].RootPasswordAuth='on';uci set dropbear.@dropbear[0].enable='1';uci commit;echo -e "root\nroot"|passwd;/etc/init.d/dropbear restart;sed -i 's/off/on/' /overlay/$(cat /proc/banktable/inactive)/etc/config/dropbear;sed -i 's/0/1/' /overlay/$(cat /proc/banktable/inactive)/etc/config/dropbear;sed -i 's#root:/bin/restricted_shell#root:/bin/ash#' /overlay/$(cat /proc/banktable/inactive)/etc/passwd;sed -i "/option Interface 'lan'/s/.*/&\n\toption RootPasswordAuth 'on'/" /overlay/$(cat /proc/banktable/inactive)/etc/config/dropbear;sed -i "1c $(sed 1q /etc/shadow)" /overlay/$(cat /proc/banktable/inactive)/etc/shadow;switchover
  18. Authenticating
  19. Authenticated OK
  20. Sending flash command to modem
  21.  
  22. <!DOCTYPE HTML>
  23. <html lang="en-us">
  24. <head>
  25. <meta name="viewport" content="width=device-width, initial-scale=1.0">
  26. <meta charset="UTF-8">
  27. <meta name="CSRFtoken" content="083c852e1d507ee5830dfc601f3585756c0343c4e06c8f2bc5e14633481dc29f">
  28. <link href="/css/gw.css" rel="stylesheet">
  29. <link href="/css/responsive.css" rel="stylesheet">
  30. <link href="/css/TIM.css" rel="stylesheet">
  31. <!--[if IE 7]><link rel="stylesheet" href="/css/font-awesome-ie7.css"><![endif]-->
  32. <script src="/js/main-min.js" ></script>
  33. <!--[if lt IE 9]> <script src="/js/media-min.js"></script> <![endif]-->
  34. <script src="/js/srp-min.js" ></script>
  35. <title>Login</title>
  36. </head>
  37.  
  38. <body>
  39. <div class="container">
  40. <div class="logo-technicolor">
  41. <!--<a href="http:&#47;&#47;www.technicolor.com" target="_blank"><img src="/img/logo.png"></a>-->
  42. <img class="timlogo" src="/img/TIM.png">
  43. </div>
  44. <div class="row">
  45. <div class="offset4 span4">
  46. <div class="login">
  47. <form class="form-horizontal">
  48. <fieldset>
  49. <h2>Sign in</h2>
  50.  
  51. <div id="erroruserpass" class="alert alert-error hide">
  52. <strong>Invalid Username or Password</strong>
  53. </div>
  54. <div class="control-group">
  55. <label for="srp_username"><div class="label-icon">
  56. <i class="icon-user icon-large"></i>
  57. </div></label>
  58. <input class="span3" type="text" placeholder="Your username" id="srp_username" value="admin" autofocus><br><br>
  59. </div>
  60. <div class="control-group">
  61. <label for="srp_password"><div class="label-icon"><i class="icon-lock icon-large"></i></div></label>
  62. <input class="span3" type="password" placeholder="Your password" id="srp_password"><br><br>
  63. </div>
  64. <!-- HIDE WARNING - NOT NOT USED IN DEFAULT CUSTO
  65. <div id="defaultpassword" class="alert alert-info hide">
  66. If you haven't changed it, the default password can be found on the sticker under your gateway (it's called <strong>"access code"</strong>)
  67. </div>
  68. -->
  69. <div class="pull-right">
  70. <a href="/" class="btn btn-primary btn-large">Cancel</a>
  71. &nbsp;
  72. <div id="sign-me-in" class="btn btn-primary btn-large">Sign in</div>
  73. </div>
  74. </fieldset>
  75. </form>
  76. </div>
  77. </div>
  78. </div>
  79. <div class="row"><div class="copyright span12"><p>&copy; Technicolor 2015</p></div></div>
  80. </div>
  81. <script>
  82. $(document).ready(
  83. function() {
  84. var triesbeforemsg = 3;
  85. var tries = 0;
  86. var password = "";
  87.  
  88. // Set the focus on the first input field
  89. $('form:first *:input[type!=hidden]:first').focus();
  90. // Handle press of enter. Could be handled by adding a hidden input submit but
  91. // this requires a lot of css tweaking to get it right since display:none does
  92. // not work on every browser. So go for the js way
  93. $('form input').keydown(function(e) {
  94. if(e.which == 13 || e.which == 10) {
  95. e.preventDefault();
  96. $("#sign-me-in").click();
  97. }
  98. });
  99.  
  100. $("#sign-me-in").on("click", function () {
  101. $(this).text('Verifying');
  102. password = $("#srp_password")[0].value;
  103.  
  104. //If the user has option legacy_salt, do migration
  105. var legacySalts = "";
  106. var userNames = "";
  107. var inputUsername = $("#srp_username")[0].value;
  108. var index = -1;
  109. var userNameArray = userNames.split(",")
  110. var legacySaltArray = legacySalts.split(",")
  111.  
  112. for (var i = 0; i < userNameArray.length - 1; i ++)
  113. {
  114. if ( inputUsername == userNameArray[i] )
  115. {
  116. index = i;
  117. }
  118. }
  119. if (index >= 0)
  120. {
  121. //alert(legacySaltArray[index]);
  122. var hashObj = new jsSHA((legacySaltArray[index]+tch.stringToHex(password)), "HEX");
  123. password = hashObj.getHash("SHA-1", "HEX");
  124. }
  125.  
  126. var srp = new SRP();
  127. srp.success = function() {
  128. // If we showed the login page using an internal redirect (detected
  129. // by checking if the URL ends with "/login.lp") then we simply
  130. // have to reload the page to get the actual page content now that
  131. // we're logged in.
  132. // Otherwise we explicitly go back to the main page.
  133. if (window.location.pathname.search(/\/login\.lp$/) == -1){
  134. var curl = window.location.href
  135. window.location.href = curl.substring(0,curl.indexOf("#"));
  136. }else
  137. window.location = "/";
  138. }
  139. srp.error_message = function(err) {
  140. if(err == 403){
  141. $.get("login.lp", {action:"getcsrf"}, function (data){
  142. $('meta[name=CSRFtoken]').attr('content', data);
  143. srp.identify("/authenticate", $("#srp_username")[0].value, password);
  144. });
  145. }else{
  146. $("#sign-me-in").text('Sign in');
  147. $("#erroruserpass").show();
  148. $(".control-group").addClass("error");
  149. }
  150. tries++;
  151. if(triesbeforemsg > 0 && tries >= triesbeforemsg) {
  152. $("#defaultpassword").show();
  153. }
  154. }
  155. srp.identify("/authenticate", $("#srp_username")[0].value, password);
  156. });
  157. })
  158.  
  159. </script>
  160. </body>
  161. </html>
  162.  
  163. Authenticating
  164. Authenticated OK
  165. Splitting command up using semicolons
  166. Sending command: sed -i 's#root:/bin/false#root:/bin/ash#' /etc/passwd
  167. Sleeping...
  168. Sending command: uci set dropbear.lan.enable=1
  169. Sleeping...
  170. Sending command: uci set dropbear.lan.RootPasswordAuth=on
  171. Sleeping...
  172. Sending command: uci commit
  173. Sleeping...
  174. Sending command: echo -e "root\nroot"|passwd
  175. Sleeping...
  176. Sending command: /etc/init.d/dropbear restart
  177. Sleeping...
  178. Sending command: sed -i 's/off/on/' /overlay/$(cat /proc/banktable/inactive)/etc/config/dropbear
  179. Sleeping...
  180. Sending command: sed -i 's/0/1/' /overlay/$(cat /proc/banktable/inactive)/etc/config/dropbear
  181. Sleeping...
  182. Sending command: sed -i 's#root:/bin/restricted_shell#root:/bin/ash#' /overlay/$(cat /proc/banktable/inactive)/etc/passwd
  183. Sleeping...
  184. Sending command: sed -i "/option Interface 'lan'/s/.*/&\n\toption RootPasswordAuth 'on'/" /overlay/$(cat /proc/banktable/inactive)/etc/config/dropbear
  185. Sleeping...
  186. Sending command: sed -i "1c $(sed 1q /etc/shadow)" /overlay/$(cat /proc/banktable/inactive)/etc/shadow
  187. Sleeping...
  188. Sending command: switchover
  189. Sleeping...
  190. Please try a ssh connection now to 192.168.1.1 with username root and password root (change password immediately with passwd!) Rebooting your modem now is recommended to stop any services that have been disabled.
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement