Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

> Ditch ONU, use GPON SFP on Business Grade Router, Mikrotik/Ubiquiti/pfSense (Home Networking)

views
     
miloaisdino
post Yesterday, 08:59 PM

Regular
******
Senior Member
1,393 posts

Joined: Jul 2015
QUOTE(Anime4000 @ Sep 24 2020, 08:55 PM)
I tried run nmap scan, none sad.gif
router backup config is encrypted, cannot see inside, unless I extract router flash and binwalk it, find shadow file and run password crack?
*
https://github.com/JackDoan/TP-Link-ArcherC5-RCE
looks useful! worth a shot
TSAnime4000
post Yesterday, 10:14 PM

Regular
******
Senior Member
1,225 posts

Joined: Jul 2009
From: /dev/null


QUOTE(miloaisdino @ Sep 24 2020, 08:59 PM)
it works half way, some can be read
Attached Image
pacat
post Yesterday, 11:25 PM

New Member
*
Newbie
10 posts

Joined: Aug 2006
From: bendang, paya, selut, parit, etc.


QUOTE(Anime4000 @ Sep 24 2020, 08:55 PM)
I tried run nmap scan, none sad.gif
» Click to show Spoiler - click again to hide... «

*
USB dongle connected to PC or router?


QUOTE(Anime4000 @ Sep 24 2020, 10:14 PM)
it works half way, some can be read
Attached Image
*
Try with this https://github.com/sta-c0000/tpconf_bin_xml
miloaisdino
post Yesterday, 11:30 PM

Regular
******
Senior Member
1,393 posts

Joined: Jul 2015
QUOTE(Anime4000 @ Sep 24 2020, 10:14 PM)
it works half way, some can be read
Attached Image
*
now thats some weird encoding :/
anyways the config looks like the "TR069 xml IGD style" of config, probably because customised for maxis

This post has been edited by miloaisdino: Yesterday, 11:30 PM
TSAnime4000
post Today, 12:53 AM

Regular
******
Senior Member
1,225 posts

Joined: Jul 2009
From: /dev/null


QUOTE(pacat @ Sep 24 2020, 11:25 PM)
USB dongle connected to PC or router?
*
plug directly, so I it can print randomized device MAC Address

QUOTE(miloaisdino @ Sep 24 2020, 11:30 PM)
now thats some weird encoding :/
anyways the config looks like the "TR069 xml IGD style" of config, probably because customised for maxis
*
it appear XML type.

QUOTE(pacat @ Sep 24 2020, 11:25 PM)
I trying in my Linux Box:
Attached Image
It works!!! I love you pcat miloaisdin!!! XD

I found something inside XML:
CODE
       <User instance=2 >
         <Level val=2 />
         <Username val=MaxSysAdm />
         <Password [email protected]! />
         <Allowed_LA_Protocols val=HTTP,HTTPS />
       </User>


Login with "administrator" & "SN" as password:
Attached Image
admin

Login with "MaxSysAdm" & "[email protected]!" as password:
Attached Image
root

With root, now can set "Full Cone NAT" for Xbox and PlayStation! no need UPNP or Port Forward, since automatic incoming 1:1 NAT
Attached Image

I made a quick guide here: https://hitoha.ga/hack-stock-maxis-router-t...ink-archer-c5v/

Since I have extra Archer C5v, I going to sacrifice this for Research! I going to share conf.xml file while 4G Dongle attached!
miloaisdino
post Today, 01:18 AM

Regular
******
Senior Member
1,393 posts

Joined: Jul 2015
QUOTE(Anime4000 @ Sep 25 2020, 12:53 AM)
plug directly, so I it can print randomized device MAC Address
it appear XML type.
I trying in my Linux Box:
Attached Image
It works!!! I love you pcat miloaisdin!!! XD

I found something inside XML:
CODE
       <User instance=2 >
         <Level val=2 />
         <Username val=MaxSysAdm />
         <Password [email protected]! />
         <Allowed_LA_Protocols val=HTTP,HTTPS />
       </User>


Login with "administrator" & "SN" as password:
Attached Image
admin

Login with "MaxSysAdm" & "[email protected]!" as password:
Attached Image
root

With root, now can set "Full Cone NAT" for Xbox and PlayStation! no need UPNP or Port Forward, since automatic incoming 1:1 NAT
Attached Image

I made a quick guide here: https://hitoha.ga/hack-stock-maxis-router-t...ink-archer-c5v/

Since I have extra Archer C5v, I going to sacrifice this for Research! I going to share conf.xml file while 4G Dongle attached!
*
wow nice that fullcone works. but ive seen routers that dont support hw nat when fullcone is enabled, might have performance penalty for faster connections,wonder if tplink is liddat

and the packet capture filename that u blurred, was that yr mac address? quite disturbing if the router is made to silently packet capture traffic for no reason...

This post has been edited by miloaisdino: Today, 01:23 AM
TSAnime4000
post Today, 01:23 AM

Regular
******
Senior Member
1,225 posts

Joined: Jul 2009
From: /dev/null


QUOTE(miloaisdino @ Sep 25 2020, 01:18 AM)
wow nice that fullcone works. but ive seen routers that dont support hw nat when fullcone is enabled, might have performance penalty for faster connections,wonder if tplink is liddat
*
during UART Serial sessions, I notice this router have 4 core @ 900MHz CPU
miloaisdino
post Today, 01:28 AM

Regular
******
Senior Member
1,393 posts

Joined: Jul 2015
QUOTE(Anime4000 @ Sep 25 2020, 01:23 AM)
during UART Serial sessions, I notice this router have 4 core @ 900MHz CPU
*
i suspect its actually dual core (2 physical core) but presented as 4 logical core in linux (not 100% sure), anyway most regular ac routers max out at about 700+ mbps without hw nat, should not be an issue unless >800mbps package!

edit: good to disable tr069 and vlan 821 in case maxis releases a fw update to change the password and hash the password entry in the config file!!

This post has been edited by miloaisdino: Today, 01:31 AM
TSAnime4000
post Today, 02:19 AM

Regular
******
Senior Member
1,225 posts

Joined: Jul 2009
From: /dev/null


QUOTE(miloaisdino @ Sep 25 2020, 01:28 AM)
i suspect its actually dual core (2 physical core) but presented as 4 logical core in linux (not 100% sure), anyway most regular ac routers max out at about 700+ mbps without hw nat, should not be an issue unless >800mbps package!

edit: good to disable tr069 and vlan 821 in case maxis releases a fw update to change the password and hash the password entry in the config file!!
*
I simply disable vlan821 bridge on Mikrotik~

here conf.xml, log.txt and putty.log dump
https://gist.github.com/Anime4000/38db42c2e...a7792005420262d

I notice something this section:
» Click to show Spoiler - click again to hide... «


Especially:
» Click to show Spoiler - click again to hide... «

it is possible 4G Dongle reject traffic that not come from a hostname?
possible to replicate this in Mikrotik without change Mikrotik hostname, just unique hostname to USB 4G
pacat
post Today, 04:07 AM

New Member
*
Newbie
10 posts

Joined: Aug 2006
From: bendang, paya, selut, parit, etc.


QUOTE(Anime4000 @ Sep 25 2020, 02:19 AM)
it is possible 4G Dongle reject traffic that not come from a hostname?
possible to replicate this in Mikrotik without change Mikrotik hostname, just unique hostname to USB 4G
*
Try these commands
CODE
/ip dhcp-client option add name=lte_hostname code=12 value="'Maxis_Archer_C5v'"
/ip dhcp-client set dhcp-options=lte_hostname,clientid [find interface=lte1]
/ip dhcp-client release [find interface=lte1]
/ip dhcp-client renew [find interface=lte1]

pacat
post Today, 04:32 AM

New Member
*
Newbie
10 posts

Joined: Aug 2006
From: bendang, paya, selut, parit, etc.


https://gist.github.com/Anime4000/38db42c2e...-conf-xml-L2291
Take note remote syslog to their server was enabled.
miloaisdino
post Today, 10:09 AM

Regular
******
Senior Member
1,393 posts

Joined: Jul 2015
QUOTE(Anime4000 @ Sep 25 2020, 02:19 AM)
I simply disable vlan821 bridge on Mikrotik~

here conf.xml, log.txt and putty.log dump
https://gist.github.com/Anime4000/38db42c2e...a7792005420262d

I notice something this section:
» Click to show Spoiler - click again to hide... «


Especially:
» Click to show Spoiler - click again to hide... «

it is possible 4G Dongle reject traffic that not come from a hostname?
possible to replicate this in Mikrotik without change Mikrotik hostname, just unique hostname to USB 4G
*
<ExternalIPAddress val=192.168.0.144 /> i was looking at this.. could this be static ip on mikrotik side required for lte to work?!

<APN val=internet /> must apn manually be set to "internet"?
DHCPC: Send DISCOVER with request ip 0.0.0.0 and unicast flag 0 (from D8:0D:17:BB:00:00 to FF:FF:FF:FF:FF:FF) zte should assign ip 144 if this mac address is set on mikrotik somehow

This post has been edited by miloaisdino: Today, 10:26 AM
TSAnime4000
post Today, 10:51 AM

Regular
******
Senior Member
1,225 posts

Joined: Jul 2009
From: /dev/null


QUOTE(pacat @ Sep 25 2020, 04:32 AM)
https://gist.github.com/Anime4000/38db42c2e...-conf-xml-L2291
Take note remote syslog to their server was enabled.
*
My TP-Link now served as VoIP Gateway, and VLAN 822 get bridged

QUOTE(miloaisdino @ Sep 25 2020, 10:09 AM)
<ExternalIPAddress val=192.168.0.144 /> i was looking at this.. could this be static ip on mikrotik side required for lte to work?!

<APN val=internet /> must apn manually be set to "internet"?
DHCPC: Send DISCOVER with request ip 0.0.0.0 and unicast flag 0 (from D8:0D:17:BB:00:00 to FF:FF:FF:FF:FF:FF) zte should assign ip 144 if this mac address is set on mikrotik somehow
*
To be safe:
» Click to show Spoiler - click again to hide... «


I run some test on some laptop:
» Click to show Spoiler - click again to hide... «


Now I know why biggrin.gif
Proceed to Mikrotik LTE USB

QUOTE(pacat @ Sep 25 2020, 04:07 AM)
Try these commands
CODE
/ip dhcp-client option add name=lte_hostname code=12 value="'Maxis_Archer_C5v'"
/ip dhcp-client set dhcp-options=lte_hostname,clientid [find interface=lte1]
/ip dhcp-client release [find interface=lte1]
/ip dhcp-client renew [find interface=lte1]

*
Finally! Maxis 4G Backup Dongle works on Mikrotik!
Attached Image

Now can configure Mikrotik dual WAN fail-over~
miloaisdino
post Today, 11:04 AM

Regular
******
Senior Member
1,393 posts

Joined: Jul 2015
QUOTE(Anime4000 @ Sep 25 2020, 10:51 AM)
My TP-Link now served as VoIP Gateway, and VLAN 822 get bridged
To be safe:
» Click to show Spoiler - click again to hide... «


I run some test on some laptop:
» Click to show Spoiler - click again to hide... «


Now I know why biggrin.gif
Proceed to Mikrotik LTE USB
Finally! Maxis 4G Backup Dongle works on Mikrotik!
Attached Image

Now can configure Mikrotik dual WAN fail-over~
*
congrats! dhcp option 12 is really sneaky by maxis tongue.gif

the speedtest dl 6.53mbps is abit disappointing, maybe external antenna might help doh.gif

This post has been edited by miloaisdino: Today, 11:08 AM
pacat
post Today, 12:32 PM

New Member
*
Newbie
10 posts

Joined: Aug 2006
From: bendang, paya, selut, parit, etc.


The dongle nat iptables might be created specifically for that hostname, or created upon successful assignment of an ip with that hostname. Still better than mac address since it can change.
miloaisdino
post Today, 01:28 PM

Regular
******
Senior Member
1,393 posts

Joined: Jul 2015
btw does voip work over the lte dongle too?

7 Pages « < 5 6 7Top
 

Change to:
| Lo-Fi Version
0.0199sec    1.58    6 queries    GZIP Disabled
Time is now: 25th September 2020 - 01:49 PM