ZTE680 Hardware V4.0 (V2?) Hack

TOP meneame.net

I just got recently installed my first FTTH router (pepephone, but same model is used in masmovil and jazztel) and as any network engineer I wanted to have full access to the router. Looking over the vast internet I found a blogpost that used a USB with a symlink to smb.conf so it can be edited to add exec parameters to execute an downloaded busybox to open an alternative telnetd but the article had a big problem that make it imposible to work on my router: the F680 of the article has an ARM architecture. My router has MIPS instead. This is important to know beforehand if using external-downloaded busybox binaries. In the end I skipped the busybox hack to directly allow admin telnet connection instead the buggy limited one. This is how I did it, I will assume that router has IP address

  1. Using any windows, format any pen-drive in NTFS.
  2. Using any linux, mount the NTFS formated pen-drive, change directory to the mounted path and do the following symlink:

    ln -s /var/samba/lib/smb.conf .

  3. Plug the pen-drive in the router. Ensure Samba Service is enabled.
  4. Connect to \\ This is a tricky part because the router only has SMBv1 which has been disabled since the WannaCry mess. I used my mac to connect to smb://samba@
  5. If ecerything is going fine you will see the smb.conf file in the connected shared. This part is tricky too because in windows you can only edit it with notepad++. In mac textedit and vi failed both to properly edit the file so I ended doing the following:
    echo "[global]
      guest account = root
      deadtime = 5
      log level = 0
      server string = Samba Server
      security = share
      load printers = no
      workgroup = workgroup
      short preserve case = yes
      preserve case = yes
      netbios name = smbshare
      comment = samba share dir
      read only = no
      guest ok = yes
      guest only = yes
      short preserve case = yes
      preserve case = yes
      max connections = 3
      path = /mnt
      exec = sendcmd 1 DB set TelnetCfg 0 UserTypeFlag 0; sendcmd 1 DB save
      comment = samba share root
      read only = no
      guest ok = yes
      guest only = yes
      short preserve case = yes
      preserve case = yes
      max connections = 3
      path = /" > /Volumes/samba/usb1_1/smb.conf

    This router version only has one USB so the path ‘usb1_1′ should be fine. The differences between the original file and this version are the guest account = root and the root share, which includes a exec to change telnet behaviour. Actually the root share is just to mess with root file system but not really needed.

  6. Without disconnecting the actual share or rebooting the router (changes will be lost!) open a new connection to the router (shares samba or root will be fine).
  7. Now the telnet should be in admin mode. Try connecting to with username root and password Zte521. Congratulation! you should now have an unlimited telnet inside the router.
  8. To be able to connect as admin in the web interface do a sendcmd 1 DB p DevAuthInfo in the telnet session and search for the admin password. The admin password is a pre-router generated password so is unique to your router.

I also wanted to do a full unencrypted dump of the configuration so in the telnet terminal do the following:

for i in `sendcmd 1 DB p | awk ‘{print $2}’`; do echo $i; sendcmd 1 DB p $i; done

Prepare for a extensive dump of data.

Also you can download a precompiled busybox-mips and win some commands as vi, uname and netstat.

<< Volver

7 comments to “ZTE680 Hardware V4.0 (V2?) Hack”

  1. Comment by vinicio:

    username root and password Zte521 does not work

  2. Comment by Francesc:

    i connect, but when i have todo anything:
    /bin/sh: Access Denied
    i can’t do anything.
    can you help me, please.

  3. Comment by Ferriol:

    I can’t access at samba service, with my debian I tried to access at smb://samba@ but password is required and I don’t know. Do you know how to connect with the samba server?

  4. Zen Comment by KaR]V[aN:

    I’m afraid that your router got firmware update and this vulnerability is now closed.

  5. Comment by Julio:

    This information is useless. Does not me or everybody else.

  6. Zen Comment by KaR]V[aN:

    Hello Julio. As I already stated, this worked on a certain hardware revision and certain firmware version. Some update patched it so it stoped from working. The best you can do is to not use ISP’s routers and put your own.

  7. Comment by GeorgKniva:

    The skin color is an indicator for the composition and cell development of the pores and skin. Pathology Changes in the lower esophageal mucosa could vary from Summary of Essential Features and Diagnostic the mildest changes with blunting of the rete papillae to Criteria severe hemorrhage irritation with ulceration and Burning retrosternal pain from esophageal inflammation. J Obstet Gynaecol Can she understood why White people keep away from speaking fcult, youre most likely heading in the right direction impotence at 17 generic 25 mg nizagara.
    Brain 2011; 134(Pt 8): World Health Organization Collaborative Study of 2387–2395. Albin which runs from July 1, 2013 June 30, 2016 and a brand new five-year term of July 1, 2016 June 30, 2021. Normal affected person growth this typically present with hyperammonemia, encephalopathy, and development ought to be the principle aim of long-time period hypoglycemia, and myopathies two] erectile dysfunction medications causing levitra professional 20mg. Your colon absorbs large amounts of water thats one of its jobs to soak up liquid. Available proof signifies that each chloride and sodium contribute to this effect. Parental perspectives of the well being standing and health-related high quality of life of teenaged youngsters who had been extraordinarily low birthweight and term controls cholesterol lowering foods list pdf buy 300mg gemfibrozil. O the fundus is generally obscured as a result of opacification of the corneal epithelium. Specialist fertility counsellors might help facilitate a session where the concept is mentioned and explored. Most endpoints had nearly fixed coefficient of variation at all dose ranges for that endpoint antibiotic levofloxacin and alcohol effective 480 mg bactrim. Swimming with a companion, preferably an experienced swimmer, is recommended for anyone who has seizures. The symptoms respond well to diphenhydramine, subcutaneous epinephrine and an albuterol nebulizer remedy. There is trophic change, with progressive destruction of articu lar surfaces with disintegration and reorganization of joint construction erectile dysfunction drugs research cheap 100 mg avanafil. Cash Transfers, polygamy and intimate partner violence: Experimental proof from Mali. Main Features Prevalence: incidence unknown, depends considerably upon the factors used, in all probability rather rare. The sooner we know the strengths and weaknesses of the kid, in addition to the understanding of their traits and needs, specific actions to encourage their growth and social integration may also be fostered symptoms 9dp5dt purchase celexa 10 mg.
    Predictors of scarring and blindness for trachoma embody increasing age and constant, severe trachoma. Do these exams in triplicate; that’s, make three emery board samples of each tooth to make sure you’re correct in figuring out unhealthy tooth. Decompression: the nerve could also be compressed by intra Constant irrigation through the drilling avoids thermal damage neural edema and hematoma and a fractured bone in to the facial nerve antibiotic treatment for lyme disease generic 100mg amermycin. He subsequently performed a rotating internship compartment pressure gave rise to the term Delta pressure, and residency normally surgical procedure on the Winnipeg General or distinction between the compartment strain and imply Hospital in Manitoba. It is concluded that his torpid episode was because of an unwitnessed seizure with subsequent post-ictal drowsiness. Many sufferers Chronic and repeated aspiration wants management need emergency tracheostomy when they sufer from higher Neuritis instances could recover spontaneously respiratory tract infection symptoms panic attack best olanzapine 7.5 mg. Imagination Perception is the deliberate judgement of sight that is based on the transduction of light stimuli received as a consequence the eyes. We can say, due to this fact, that many patients included in both research, had been receiving suboptimal therapy when they have been randomised. Although the included research ranged in period from eight weeks to 5 years, analysis of shorter as compared to longer durations of therapy was not carried out, limiting the power to determine whether or not extra prolonged therapy is ready to preserve shorter term treatment positive aspects 999 bacteria what is 01 quality 250 mg sumycin. None None Novo Nordisk, Johns Hopkins School Diabetes Care (Editorial Board) of Medicine Continuing Medical Education A. The efect of hsa-miR-186 overexpression in keratinocytes gamers in response to metallic exposure. A number of diseasesпїЅfrom kidney disease to testicular most cancersпїЅmay end up in male infertility 5 asa medications proven 35 mg actonel.