Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Modem provisioned and telnet enabled
#1
During some testing I discovered that there are some modems on my network that have telnet server enabled and I can telnet into them just fine. They are ISP provisioned and working just fine, brand new D3 modems. And they have telnet enabled.

Can I extract certs via telnet or put them in the factory mode via telnet? What can I do to exploit this?
Reply
#2
considering i know nothing of d3 modems or there telnet servers, the first thing i'd try is the readmem command
if it works you can take a full dump from the modem
__________________________________________________________________________________
******new discord chat linkĀ https://discord.gg/5BQQbsb*******
Reply
#3
i also know nothing about it. What would be the exact command to wrote?
Reply
#4
I would try fastcert 1st, as that would do what you would be trying via CLI
Knowledge=Power
Reply
#5
Nope, fastcert 0.2 and 0.3 found nothing. Also snmpcertthread found nothing on 23, 161, 162. They are all asking for community string.

There is no community string in the telnet, you just open the session.


In fact access is password protected. It is asking for login name and password. You can open the telnet window but it is asking for login name and password.
Reply
#6
Interesting...

SNMP has both the "Public" and "Private" strings...Private is read and write, basically full access. Public is read only, used for "polling" or asking the modem for certain responses to queries. Firmware pushed are done with the "Private" string.
Knowledge=Power
Reply
#7
(23-08-2012, 10:52 AM)torro32 Wrote: During some testing I discovered that there are some modems on my network that have telnet server enabled and I can telnet into them just fine. They are ISP provisioned and working just fine, brand new D3 modems. And they have telnet enabled.

Can I extract certs via telnet or put them in the factory mode via telnet? What can I do to exploit this?

Yes you can extract the certs via telnet!!!
it depends in a few things if you can get pass the login and password, or you can change the username an password by snmp then read memory where the certs are!
Reply
#8
You can also read the user name and password though snmp...
Reply
#9
well on a d2 modem the help command works great so try that in every directory till you find the readmem command then start at 0x0 and continue in 1 byte increments
__________________________________________________________________________________
******new discord chat linkĀ https://discord.gg/5BQQbsb*******
Reply
#10
I can enter login name but I can't enter password. The cursor just stays on one place and not moving at all like I don't type anything and I get invalid login.

Also if I would like to change the password, what do I need to put at the end of the oid?
I just put the new password name and I get "Needs type and value".
Reply


Forum Jump:


Users browsing this thread: 5 Guest(s)