Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

Unifi [Guide] UniFi - Any custom router can use UniFi, For Huawei HG655a & ZTE ZXDSL 931DII

views
     
blindbox
post Sep 3 2011, 01:56 PM

Meh
******
Senior Member
1,705 posts

Joined: Nov 2004


This post has been pointless, lol. rizvanrp did an analysis of it a long time ago.

DAMN IT. I thought this one was for HG850a.

I did some analysis on HG850a. Here's what nmap gives.

CODE

PORT     STATE    SERVICE VERSION

21/tcp   filtered ftp

22/tcp   filtered ssh

23/tcp   filtered telnet

80/tcp   filtered http

8011/tcp open     unknown


The device is set on IP 192.168.2.1 . port 80 is filtered. Either that they DISABLED the web interface, OR I need a specific IP that'd allow me to access it. nmap.org is down so I can't really interpret what filtered means in nmap.

EDIT: rizvanrp, if you're reading this, could you tell me the subnet of iptv again (PM me)?

EDIT2: A more thorough nmap scan.

CODE

Not shown: 1965 closed ports, 29 open|filtered ports

PORT     STATE    SERVICE VERSION

21/tcp   filtered ftp

22/tcp   filtered ssh

23/tcp   filtered telnet

80/tcp   filtered http

8011/tcp open     unknown

67/udp   open     dhcps?

| dhcp-discover:  

|   IP Offered: 192.168.100.2

|   DHCP Message Type: DHCPOFFER

|   Server Identifier: 192.168.100.1

|   IP Address Lease Time: 3 days, 0:00:00

|   Subnet Mask: 255.255.255.0

|   Router: 192.168.100.1

|_  Domain Name Server: 192.168.100.1, 198.41.0.4

MAC Address: 78:1D:BA:D9:FD:2B (Unknown)


This gets more and more interesting.


This post has been edited by blindbox: Sep 3 2011, 04:33 PM
blindbox
post Sep 9 2011, 11:31 AM

Meh
******
Senior Member
1,705 posts

Joined: Nov 2004


QUOTE(rizvanrp @ Sep 6 2011, 12:22 PM)
ZTE was the first VDSL2 BTU to be reconfigured for direct VLAN <-> port mapping sometime last year -- http://forum.lowyat.net/index.php?showtopi...post&p=35603950

@blindbox

What's on TCP 8011? :3

@thankyou

Did anyone try mapping out the firewall ruleset for the new HG850's? IIRC there was no drop rule running on it until recently. Is it a full drop rule or drop all but allow existing/established (in which case it would be possible to establish a TCP session via SSH/telnet and keep it running before the rules kick in)? Perhaps you could even automate the login with a script and hop into the shell + disable the ACL quickly..
*
Nothing. If you remembered from your old post (try googling it), you already did try to find services on 8011. I tried ftp, http, ssl, https and telnet, nothing.... Any other tcp protocols that I should try? (I just remembered ssl and telnet are udps, of course they don't work).

TCP 8011 is just an open port. No idea how to use it.

All we know is that the HG850a has two IP addresses, one at 192.168.2.1, another at 192.168.100.1

Hmm I haven't done a wireshark yet on those IPs though. I'll update this thread as I come along.

NEW STUFF:

Well, I did a wireshark and *drumroll*, I found already-found discoveries. I figured the reason why IPTV doesn't work on any of the Huawei ports were because it's not sending vlan 600 to the Juniper server/switch/etc they have at TMNet. Hence, it can't read it. So ignoring firewall routing and whatsoever, you could probably put the d-link given by TM to one of the port and run IPTV there. So, port 1 > Openwrt/DD-WRT hardware not capable of IPTV, and port 2 >D-Link from TM > IPTV.

Well.. gotta test it now.

This post has been edited by blindbox: Sep 9 2011, 12:13 PM

 

Change to:
| Lo-Fi Version
0.0222sec    0.56    7 queries    GZIP Disabled
Time is now: 1st December 2025 - 01:26 AM