Follow us on Twitter!
Your life is ending one minute at a time. If you were to die tomorrow, what would you do today?
Wednesday, April 23, 2014
Navigation
Home
HellBoundHackers Main:
HellBoundHackers Find:
HellBoundHackers Information:
Learn
Communicate
Submit
Shop
Challenges
HellBoundHackers Exploit:
HellBoundHackers Programming:
HellBoundHackers Think:
HellBoundHackers Track:
HellBoundHackers Patch:
HellBoundHackers Other:
HellBoundHackers Need Help?
Other
Members Online
Total Online: 22
Guests Online: 20
Members Online: 2

Registered Members: 82885
Newest Member: ConiBE
Latest Articles
View Thread

HellBound Hackers | Computer General | Networking

Author

dsl modem hacking (via telnet) - what to do with it?


Member

Your avatar

Posts:
Location:
Joined: 01.01.70
Rank:
Guest
Posted on 04-01-07 10:34
i recently checked my network for open ports and found out that my dsl modem is not only accessible from the internet via telnet, but also has a very weak password, the default pwd for conexant modems.
i know how to change this, no prob.

what i'm asking is: what could a hacker with bad intentions do with my modem?
i've read something on the net about using a dns server and looking at traffic, but the page was in dutch...so Shock i didn't understand much.

is it possible to sniff the traffic somehow over the telnet menu?
currently i only found a tcp statistics section...

i'm looking forward to your replies Smile

so long,
ssidd
Author

RE: dsl modem hacking (via telnet) - what to do with it?


Member

Your avatar

Posts:
Location:
Joined: 01.01.70
Rank:
Guest
Posted on 04-01-07 11:30
packet sniffer maybe , i dont have much experience with modem's never used one before
Author

RE: dsl modem hacking (via telnet) - what to do with it?


Member

Your avatar

Posts:
Location:
Joined: 01.01.70
Rank:
Guest
Posted on 04-01-07 11:40
yeah, i'd like to use some sort of packet sniffer, but that seems inpossible.
however, i can set up a dns server and resovle ips to different hostnames.
ex.: ip: 209.85.135.103 (which is google) to www.microsoft.com
but this is only useful for phishing and that is lame. :happy:
Author

RE: dsl modem hacking (via telnet) - what to do with it?


Member

Your avatar

Posts:
Location:
Joined: 01.01.70
Rank:
Guest
Posted on 04-01-07 11:51
On some modems, I remember about reading (although this may only apply to those with routers built in) stories about gaining root access to the shell of said modems. Granted I can't remember if you can only do it LAN-wise.

Now as to what someone could do, I doubt it would be too much. The y could, perhaps on a vulnerable modem, for example, collect the password for your DSL service.

And I really can't explain anymore, I'm a tad foggy on the subject as it is.
Author

RE: dsl modem hacking (via telnet) - what to do with it?


Member

Your avatar

Posts:
Location:
Joined: 01.01.70
Rank:
Guest
Posted on 04-01-07 11:58
to clarify 2 things:
1) i _have_ access to the modem's telnet shell
2) the shell is worth shit - no cool options

the "attack" isn't based exactly on a vulnerability of the modem.
it's only possible because nobody ever changed the pwd from default. :happy:

but, as i mentioned - the shell is only for some uninteresting options.... i'll up a screenshot in a few secs

here they are:

main menu

img182.imageshack.us/img182/4295/1sum9.jpg

adsl status menu

img167.imageshack.us/img167/9493/2slq2.jpg

network setup menu

img479.imageshack.us/img479/2817/4stm7.jpg


edit: any suggestions dudes?

Edited by on 04-01-07 14:21
Author

RE: dsl modem hacking (via telnet) - what to do with it?


Member

Your avatar

Posts:
Location:
Joined: 01.01.70
Rank:
Guest
Posted on 04-01-07 14:53
Looks like loads of stuff would be possible!


Author

RE: dsl modem hacking (via telnet) - what to do with it?


Member

Your avatar

Posts:
Location:
Joined: 01.01.70
Rank:
Guest
Posted on 04-01-07 15:41
yeah, lot's of stuff to fuck up the internet access, but it isn't even possible to get the pptp password...Frown
Author

RE: dsl modem hacking (via telnet) - what to do with it?


Member

Your avatar

Posts:
Location:
Joined: 01.01.70
Rank:
Guest
Posted on 09-01-07 06:58
Ah yeah, some time ago I actually scanned over 20 thousand IP's, in smaller batches (2-4thousand per scan) and found that some of them have port 23 open. So I telnet to it and bam.
Conexant modem. Ive found nothing intresting there too, except the "restore to defaults and reset" option, which I used once, and only once. Maybe if it had a network to it, a LAN, it might've showed something intresting, but that was a standalone router directly connected to a PC.

On another note, I stumbled upon an old school like BBS, but didnt have any sort of user/password combo to get into it.

Edited by on 09-01-07 06:59
Author

RE: dsl modem hacking (via telnet) - what to do with it?


Member

Your avatar

Posts:
Location:
Joined: 01.01.70
Rank:
Guest
Posted on 15-01-07 21:41
cool, an old skool bbs Smile
yeah...portscanning is fun...i'll have to do it again some time...maybe for ftps this time :happy: