Posts: 47
Threads: 6
Joined: Jul 2012
Reputation:
0
I've got a friend that I introduced to the Haxorware, but he is totally lost. Actually, I'm lost too. He is trying to follow this post on forocable/sbhacker and is trying to do something with fastcert. He used DHCP Force to find some macs with configs, and found several macs with configd. He then tried to scan with fastcert but he did not know what ranges to scan. He tried to use the hfc ip address (i.e. 10.435.334.456 would be 10.435.330.0 to 10.435.340.0 ) but he always got 0 certs found. He left the key string public, used port 161. He still got 0 certs. Does he need to download his own cert and open it with vultureware?
Question: What i.p. range do i need to use to scan with fastcert? How do i know what range to use?
ISP: Comcast
Location: California
BPI: BPI+ enabled
Posts: 1,516
Threads: 16
Joined: Dec 2009
Reputation:
79
The Public string is worthless to open up remote CM's and put them in factory mode and have them send their Certificates
Knowledge=Power
Posts: 15
Threads: 0
Joined: Jul 2012
Reputation:
3
19-09-2012, 06:22 AM
(This post was last modified: 19-09-2012, 06:31 AM by tvictor47.)
I think in order to read certain things you have to write certain things. So you may be able to read a limited amount of information from the cm. but with the write string you will be able to change settings which will allow you to read private certificates and such. -just a theory. there is so much secrecy around cm community now days because people want to keep making presentations at defcon and publicizing this info. Look how many people these idiots got arrested...
Posts: 101
Threads: 3
Joined: Sep 2011
Reputation:
0
You can use a pubic sting. Get your modem up and running and dl your config file . Down load vutureware and open your config to find your pubic string. There be limit amount of info on how to do this so im not here to spoon feed you. You must know the correct SNmP Port to scan enter that. Then you much know the tftp sever Ips. They range from citys like this.
10.247.x.x bell garden
10.245.x.x la
10.253.x.x Pico
10.36.x.x Westminster
Put the correct range of the ISP hosted ip per node to scan and you will pull certs from enabled modems.
No one PM me unless you have something to bring to the table.