作者: gl5900as 時間: 2022-10-13 16:22 標題: 關於HKBN HUAWEL MA5671A貓棒破解偷參數設置
本帖最後由 gl5900as 於 2024-8-8 01:02 編輯
買多枝貓棒,想轉移原來HKBN MA5671A的華為貓棒設置,不過枝貓棒只打開SSH 192.168.1.10 22,冇網頁
密碼不明無法登入,只知是OPENWRT系統
熱風槍吹左HKBN的MA5671貓棒粒FLASH落黎,讀bin file,開過ROM預設shadow的密碼SHA 512加密,唔駛睇無得解,仲有一個J2FFS分區不過掛載唔到偷參數
修改過squashfs shadow清除密碼寫入機行不過無效照樣有密碼,可能修改過
可能要修改J2FFS分區先清到密碼
share編程器固件
https://mega.nz/file/p9Z3UbhD#Kw ... s27gkmjBSufTJLKRdKM
作者: aoeII 時間: 2022-10-13 16:27
TeraTerm 透過TTL不能連接,必須吹Flash?
作者: landfi 時間: 2022-10-13 16:37
好利害
作者: Tom_jerry 時間: 2022-10-13 16:38
https://www.cvps.top/10425.html
作者: gl5900as 時間: 2022-10-13 19:05
Ttl能刷機,但能不能清除jffs2分區的密碼文件?
作者: ToNg. 時間: 2022-10-13 22:33
貓棒

作者: super_hkg 時間: 2022-10-14 08:03
binwalk 完 extract 晒D file
再用unsquashfs extract 最後果個 squashfs
乜config 都睇到晒
作者: gl5900as 時間: 2022-10-14 08:26
binwalk 完 extract 晒D file
再用unsquashfs extract 最後果個 squashfs
乜config 都睇到晒 ...
super_hkg 發表於 2022-10-14 08:03
squashfs只係原裝預設ROM區,仲有jffs2分區,而jiffs分區先係真正hkbn文件存既地方
作者: super_hkg 時間: 2022-10-14 09:38
本帖最後由 super_hkg 於 2022-10-14 09:50 編輯
jffs 一野開左,入面都係有squashfs
唔見有加密
作者: gl5900as 時間: 2022-10-23 03:35
本帖最後由 gl5900as 於 2022-10-23 03:38 編輯
破解HKBN枝貓棒,用指令fw_printenv倒出哂d參數,唔駛打碼全部放出
之後可以用fw_setenv輸番d參數落去,仲發現hkbn根本冇乜改過預設其他config,只係指令加左D參數同改左密碼,試過清除哂JFFS2資料分區都可以成功連線認證,咁即係fw_printenv先係重要既參數,唔怪得其他點set都係唔得
- act_img_addr=0xBF20003C
- addip=setenv bootargs ${bootargs} ip=${ipaddr}:${serverip}:${gatewayip}:${netmask}:${hostname}:${netdev}:off
- addmisc=setenv bootargs ${bootargs} ethaddr=${ethaddr} machtype=${machtype} ignore_loglevel vpe1_load_addr=0x83f00000 vpe1_mem=1M mem=63M ${mtdparts}
- addmtdparts0=setenv mtdparts mtdparts=sflash:256k(uboot)ro,512k(uboot_env),7424k(linux),8192k(image1)
- addmtdparts1=setenv mtdparts mtdparts=sflash:256k(uboot)ro,512k(uboot_env),7424k(image0),8192k(linux)
- asc0=1
- baudrate=115200
- bertEnable=0
- boot_image=run boot_image${c_img};
- boot_image0=run kernel0_from_sf flashargs addip addmtdparts0 addmisc && bootm ${ram_addr}
- boot_image1=run kernel1_from_sf flashargs addip addmtdparts1 addmisc && bootm ${ram_addr}
- boot_image_err=setenv kernel_offs ${kernel0_offs};httpd && setenv image0_is_valid 1
- bootcmd=run flash_flash
- bootdelay=0
- committed_image=0
- env_offs=0x40000
- env_offs_redund=0x80000
- ethact=SERDES
- ethprime=SERDES
- fileaddr=80F00000
- filesize=3400AA
- flash_flash=run select_image boot_image
- flashargs=setenv bootargs rootfstype=squashfs,jffs2
- gDtiaGentEnable=false
- gatewayip=192.168.2.0
- goi_calibrated=1
- goi_config=begin-base64 644 goi_config@H4sIAB7wY1sCA+2YS2/aQBCAuZZfsVUPnOLs7MO7rtVD2qRV1FSNAqKHqLKM@vYBVzCLb6ePfdxZCMOA0VR+oD8+F9Tw8u+v51mNMlRzbRZUlxxObRVU8mplo@FpemiAozjkY48pLyY+enhKL4Qix/UXZ/KfiqA5xzqnyllOxQUCChQ2jnAHJT@VnFBSKewtvqW30P2v1SekFNL5rYiyTSeTwyppoYMviwMyVIzr7JxZorHYRh2@ne7ZxUn/7Cq6OnvpNE/IwOQLcv36fUjOqym5vjnBUf8MB++OczeO8X7X5fsu@BxZKTzIeat8D7Ye022nlzxDzLf5/Hv0f5N8HqVr+/zL+85b/f4P/j/EijUbp@L6L/O/jH8Yp/hRcc+ZdSspb/w/CfbvHvOL+lfXhyeRo9P12THpIhvhLI9dAB@LUIBnmAtyP8W/3hi/4YcjnEl5b38I/TIPx4RUikfxxSY8mXL/yGEtgj89/wn@dj7OJssDYDU8LP9MCrl5/3PX/3Ofi5b/Q0h39cQJPnzSm8zsKJ71uo/cG8HO@yYt4lo2K2I0HWW5wp7Dh7zHK6BHQI0YHDJ4KCEmZFNmiIkPl+Z4IydsXJxfu@Qnpoe/luNeS97lauwrUb5Y6ywj7DYMKbwqx60XIzmWU7UibxbPnP1Mx+Ij3q@YV3d5zHNJtM7l60saZImEfa4u8lxSmWeVZUp7rFEC/vJGdcJL2lEcT+4X1OB@U3Es95175HaeVbYWPMjiV3E2jy4vMAA2+je4iNrGr+y8KQ4eiIN74tgDcWwr@7hQ3FPeT3k6EUblng1sbB90Y5yYCvmiMczbuQ2OcmwhoaIxzNi5UzVabJPW3@9esJgtJbC/9c3W6/BwELdCB9yYONx3luU1dKSx9BPc0px6NMULqfFtehg/2s@7hnpuv86KxqOqCepVIxrrBcqmvKCw80LKH4Q+Qqz7+fFfRANeVEdaH8/LVum@FYJqrYTQVDdldQWCThQA8OPMlfd2KZu4REJzM69q8NHX0cB9IPSAyVqJDNZA@OhaFkoIFoBTTteVe9fvnEYiApnHxYe3q3hmcCQa6jvida/2uwFggaKAUMGhw@XcRFPLKzLLnz1wAcW8wg2FuazW92NCNbxpubXli7eGNTg49lx2+clNnG79Ww@j5k+j7Ge0K9tM1pppZU/UL4CJbxWZQAcAAA=@====@
- gphy0_phyaddr=0
- gphy1_phyaddr=1
- image0_addr=0xB00C0000
- image0_is_valid=1
- image0_version=V8R017C00S209
- image1_addr=0xB0800000
- image1_is_valid=0
- image_name=openwrt-lantiq-falcon-SFP
- ipaddr=192.168.1.10
- kernel0_from_sf=sf probe 0;sf read ${ram_addr} ${kernel0_offs} ${max_kernel_size}
- kernel0_offs=0xC0000
- kernel1_from_sf=sf probe 0;sf read ${ram_addr} ${kernel1_offs} ${max_kernel_size}
- kernel1_offs=0x800000
- load_kernel=tftp ${ram_addr} ${tftppath}${image_name}-uImage
- load_uboot=tftp ${ram_addr} ${tftppath}u-boot.img
- machtype=SFP
- magic_addr=0xBF200038
- magic_val=0xDEADBEEF
- max_kernel_size=180000
- nDyingGaspEnable=0
- nPassword=0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00
- nSerial=KBK2000502
- net_nfs=run load_kernel nfsargs addip addmtdparts0 addmisc;bootm ${ram_addr}
- netmask=255.255.255.0
- nfsargs=setenv bootargs root=/dev/nfs rw nfsroot=${serverip}:${rootpath},${nfsoptions}
- nfsoptions=rsize=1024,wsize=1024
- omci_loid=loid
- omci_lpwd=lpasswd
- preboot=gpio intput 100;gpio input 105;gpio input 106;gpio input 107;gpio input 108;gpio set 3;gpio set 109;gpio set 110;gpio clear 423; gpio clear 422; gpio clear 325; gpio clear 402; gpio clear 424
- ram_addr=80F00000
- reset_uboot_env=sf probe 0;sf erase 40000 80000
- save_uboot=sf probe 0;sf erase 0 40000;sf write ${ram_addr} 0 ${filesize}
- select_image=setenv activate_image -1;if itest *${magic_addr} == ${magic_val} ; then if itest *${act_img_addr} == 0 ; then setenv activate_image 0;fi;if itest *${act_img_addr} == 1 ; then setenv activate_image 1;fi;mw ${magic_addr} 0x0;mw ${act_img_addr} 0x0;fi;if test $activate_image = -1 ; then setenv c_img $committed_image;else setenv c_img $activate_image;setenv activate_image -1;fi;if test $c_img = 0 && test $image0_is_valid = 0 ; then setenv c_img 1;fi;if test $c_img = 1 && test $image1_is_valid = 0 ; then setenv c_img 0;fi;if test $image0_is_valid = 0 && test $image1_is_valid = 0 ; then setenv c_img _err;fi;exit 0
- serverip=192.168.1.100
- stderr=serial
- stdin=serial
- stdout=serial
- tx_fault_pin=2
- update_image0=tftp ${ram_addr} ${tftppath}${image_name}-squashfs.image;sf probe 0;sf erase ${kernel0_offs} +${filesize};sf write ${ram_addr} ${kernel0_offs} ${filesize}
- update_image1=tftp ${ram_addr} ${tftppath}${image_name}-squashfs.image;sf probe 0;sf erase ${kernel1_offs} +${filesize};sf write ${ram_addr} ${kernel1_offs} ${filesize}
- update_openwrt=run update_image0 && setenv committed_image 0 && setenv image0_is_valid 1 && saveenv
- update_uboot=run load_uboot && run save_uboot
- ver=U-Boot 2011.12-lantiq-gpon-1.2.24 (Nov 03 2014 - 22:46:28)
- sfp_a0_low_128=begin-base64 644 sfp_a0_low_128 @AwQBAAAAAgAAAAADDAAUyAAAAABIVUFXRUkgICAgICAgICAgAAAAAE1BNTY3@MUEgICAgICAgICAwMDAwBR4AnQAaAAAwMzFRSFUxME0zMDA1Mzk3MjAxMDE5@ICBo4ANtS0JLMjAwMDUwMiAgICAgICAgICAgICAgICAgICAgICAAAAAAAAAA@AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA@AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA@AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA@AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA@AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA@AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA@AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA@AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA@AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA@AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA@AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA@AAAAAAAAAAAAAA==@====@
- sfp_a2_info=begin-base64 644 sfp_a2_info @XwDOAFoA0wCMoHUwiLh5GK/IAACIuAAAm4Ii0HuGK9QJzwANB8sAEAAAAAAA@AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/gAAAAAAAAAEAAAABAAAAAQAAAAEA@AAAAAABMHa97SgyWAAEAAf////8CAAFA//8BQAAAcAEAAAAAEGD/////////@////////////MDMwMzFRSFUAAAAAAAD+Gv//////////////////////////@//////////8AAhQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA@AAAAAAAAAAJIV1RDlPn1pf//////////////AAD//wAAAAAAAAAAAAAAAAAA@AAAAAAAAAAAAAAAAAAAAAAAAhCclxDvZrQiJ1nWe2v4Re5jJ1kyvheujpR2Y@pFJJi/SpuUOo4l6Z8f8VA3HBY4zc2PTz9fDwG950ImCC73zZ/2kaAAAAAAAA@AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAiEAz6DNjAAAAAAAAAAAAAAAAAAAA@AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA@AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA@AAAAAAAAAAAAAAAAAAAAAAAAD/0P/gD/AAAAAAAAAAAAAAAAAAAAAAAAAAAA@AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA@AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA@AAAAAAAAAAAAAA==@====@
- gSerial=HWTC94f9f5a5
- ethaddr=88:40:33:e8:33:63
- config 'omci' 'default'
- option 'mib_file' '/etc/mibs/data_1g_8q.ini'
- option 'status_file' '/tmp/omci_status'

