Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 XiaoMi AX3600 Hack SSH & Telnet forever

views
     
TSchong83
post Dec 12 2020, 01:16 AM, updated 4y ago

Getting Started
**
Junior Member
88 posts

Joined: May 2009
From: Kuala Lumpur


Login AX3600 in browser
CODE
192.168.31.1


First Step
Downgrade Firmware Version to 1.0.17

Go To
CODE
https://www.oxygen7.cn/miwifi/

user posted image

Key in your Router SN Click Go Calculate Your Root Password Remember Save
CODE
266XX/E0P80XXXX

user posted image

Install Putty then SSH to Your Router
username : root
password : XXXXXXX
user posted image


SSH Run
CODE
nanddump -f /tmp/bdata_mtd9.img /dev/mtd9


Install WinSCP & Login
user posted image

Backup "bdata_mtd9.img" to Desktop
CODE
/tmp/bdata_mtd9.img


Upload "fuckax3600" to /tmp

Back to Putty SSH
CODE
chmod +x /tmp/fuckax3600


CODE
/tmp/fuckax3600 unlock

Router Will Auto Reboot

After Reboot Login SSH Continue
CODE
/tmp/fuckax3600 hack

This Step SSH, Telnet, Uart Permission Done, Please Save Your Password for SSH & Telnet

CODE
/tmp/fuckax3600 lock

Restart and Factory Reset

Upgrade Firmware to CN 1.0.67 or INT 3.0.22

After Upgrade Firmware SSH cannot Login, Please Use Putty Login By Telnet & Run
CODE
sed -i 's/channel=.*/channel=\"debug\"/g' /etc/init.d/dropbear

CODE
/etc/init.d/dropbear start


SSH Work Again brows.gif


Attachment File :
Firmware, Putty, WinSCP
CODE
https://mega.nz/file/mEJ1Capa#jxenPjajUIYKe-Sgamvmg2CAEBq6wM8t3JhsOhJH5RQ


user posted image

=======================================================


Set VLan for Unifi, Maxis, Time
Login By WinSCP go to edit
CODE
etc/config/network


Add Vlan id .XXX behind eth1 example
CODE
option ifname 'eth1' to option ifname 'eth1.500'


config interface 'eth1'
option ifname 'eth1.500'
option keepup '1'

config interface 'wan'
option proto 'pppoe'
list dns '8.8.8.8'
list dns '8.8.4.4'
option peerdns '0'
option username 'abc@unifi'
option special '0'
option mru '1480'
option password 'admin1233'
option ifname 'eth1.500'
option ipv6 'auto'


user posted image

This post has been edited by chong83: Dec 12 2020, 01:49 AM

 

Change to:
| Lo-Fi Version
0.0130sec    0.39    7 queries    GZIP Disabled
Time is now: 29th March 2024 - 04:47 AM