|
发表于 2018-11-14 16:40:59
|
显示全部楼层
可以确认GM219-S 硬件版本:HV1.0.00.052 为四川天邑代工的。。。找到了地区配置文件。。。找到了各种服务的默认的密码:* D& e6 h! e8 ~
9 N5 G# ~! G- y<Account> a7 v/ L1 t/ B5 C2 R
<Entry0 Active="Yes" username="CMCCAdmin" web_passwd="aDm8H%MdA" display_mask="FF FF FF FF FF FF FF FF FF" />
, s* ]4 T- t: e- f2 I- g2 U, y <Entry1 Active="Yes" username="user" web_passwd="1234" display_mask="BF 00 0F 08 07 20 03 00 01" />4 ^) Y1 u0 R1 h0 A$ `, t4 u- c2 Y
<Entry2 Active="Yes" username="user3" web_passwd="1234" display_mask="BF 00 07 08 07 10 03 00 01" />
h" w% r( `% D <TelnetEntry Active="No" telnet_username="admin" telnet_passwd="1234" telnet_port="23" />* F0 y$ S3 u, p9 p
<FtpEntry Active="No" ftp_username="admin" ftp_passwd="1234" ftp_port="21" />) @; \) {% g/ M0 ~
<HttpEntry Active="Yes" http_right="1" />
& ]9 g) P7 _, [3 t <ConsoleEntry Active="Yes" console_username="admin" console_passwd="1234" />
7 H+ M, O C4 ~3 ^ <CTDefParaEntry setDefValueFlag="1" />5 D ~3 y9 `: K0 G( F
</Account> 本地移动不改超密,所以我一直在找telnet的用户名和密码,试了telnet的默认账号密码发现不对应该是被运营商改了。。。移动的网在家就是看电视用。。。懒得拆机ttl。。。也没法下一步玩。。。也就不开新贴献丑了。。。
9 p* e2 Z/ h( M$ _
`5 r4 u, |# y' W- t5 ?$ H) i尝试固件里/boaroot/cgi-bin/目录下的一些页面。。。发现了一些web下的隐藏页面。。。相同硬件版本的可以去尝试:+ I' X5 x2 _- V% Z+ ^1 L' x
3 p: Z+ P" `( K& X3 k4 R. q
http://192.168.1.1/cqregister.asp
0 X( d/ x* _+ D( N4 I5 w/ hhttp://192.168.1.1/cqreset.asp+ U# J3 y; L% o
http://192.168.1.1/cwmpsetting.asp/ p! ]% o0 f7 l Z: w8 G
http://192.168.1.1/getGateWay.cgi
( p/ ^5 e& R1 w) n0 e7 {/ u8 o# U6 ~0 g
#getRomfileInfo就出现个下拉菜单2 p% _9 i* {7 H/ L
http://192.168.1.1/getRomfileInfo.cgi
! v$ h9 s9 k5 j9 W+ b% |2 {- ]7 V
http://192.168.1.1/register.asp
2 [8 }; m1 q. Y6 k% Mhttp://192.168.1.1/regprocess.asp
& z& U8 z0 i0 x. Y1 a$ Jhttp://192.168.1.1/regprocess.cgi
, g" `" \( [" E. C, X
3 H+ U. x5 Q# j6 M" S, Q$ w#恢复默认设置的命令不会丢移动下发的配置 F9 O' T* E$ [1 b( F$ f
http://192.168.1.1/restorepurefactory.cgi
; g" e- D" p+ |/ R
" S5 D, O! Q5 d) }1 n, n! Jhttp://192.168.1.1/telnet.asp" J; l m. W; {/ `
http://192.168.1.1/test_factory.asp
0 V6 u0 \& G! thttp://192.168.1.1/test_info.asp, B. N5 m% f; @& C
http://192.168.1.1/test_version.asp+ h, h( M' a, d$ C; p T$ a A6 {
http://192.168.1.1/upgrade.asp3 k, z" m# c8 ]: ~8 |1 Y
# Q6 M4 v( j: k, Q/boaroot/cgi-bin/目录下的所有文件。。。其他隐藏页面有兴趣自己去尝试。。。8 y2 C$ @) e8 C8 _) { q
app-daily.asp
1 s! p2 r: R5 e. T7 a/ Sapp-ddns.asp
7 y4 `% _2 {, c2 Z% O- O( Y/ Lapp-igmpset.asp# V$ h" m+ T f( ?+ {7 D& V4 k' C
app-natset.asp* m( } b3 X3 z9 i& O: h
app-upnp.asp" R. m% d3 r* t' G
app-VoIP.asp' A; b4 n5 ~/ t* y+ M
app-VoIP248.asp N, A( A$ J, ~ |2 A8 _
app-VoIP248_Adv.asp& a1 h$ X2 H' Y3 ^
app-VoIPUser.asp
4 B/ Z- e" J B6 g# e# a, k# sapp-VoIP_Adv.asp
. H5 c/ \" l1 y" ^app_ddnslist.cgi7 D6 p$ Z# N" g
avalanch.asp2 x' T# U& K2 a2 Y" {7 A! o' L
byeBye.cgi* D6 I) U2 |- l9 N
adv_vpn.asp
$ w7 U" \- t2 r* `5 B* jcqregister.asp
8 ~/ |+ Q! M" u3 hcqreset.asp
0 a5 M) W1 o4 gadv_upnp.asp
$ \: G2 h1 a- k, @( @7 |$ t% Bcwmpsetting.asp3 L% ~: h* b! N; K# {
diag-quickdiagnose.asp, J, M7 Y" X; c* O' O$ D
ErrMsg.asp0 \" F8 w3 \/ z; C
getGateWay.cgi
4 P9 B& C. q/ f, S& ~# _getPingResult.cgi! N: A, L. q( D; h$ J0 ]
getRomfileInfo.cgi
$ s8 a8 r- z2 M; rgetTracentResult.cgi
" r4 b0 B- {0 Yhelp.asp
, W3 F3 b7 Y# M3 v4 S; U( Yhelp_content.asp
u. X0 r) K6 y/ H& k8 Xadv_qos.asp* s* J# ]7 E2 k# p: X
adv_dmz.asp
# R" o A, D! \index.asp
! x- o) k$ n: O3 jindex2.asp* a) f- R# h5 _- H8 S
index3.asp
+ q4 h1 f2 Z) v6 O/ OInsertSimcardMsg.cgi
$ M! j. f5 Q" G/ l1 \5 Bitms.cgi) S# Z S7 _0 n0 ~9 O8 Z
adv_ddns.asp) p& b1 B5 G. b |7 E
content.asp
. L4 _, N/ ]) S8 q1 c. l! klaserforce.cgi
1 b2 C2 r& m' l8 s Glasernormal.cgi3 k" B4 p$ I# R3 D/ G5 d. z
logout.cgi1 D7 a s1 n9 y4 |
mag-account.asp- y8 ^+ Y# `5 p- ^" W3 Q
mag-diagnose.asp8 c* a3 @9 U8 U0 v& i8 C
mag-reset.asp P9 y% `1 t, Z, S" D$ ~) H
mag-syslogmanage.asp
; @9 C# [0 q0 I8 }maintainreport.cgi8 A5 \3 G" k$ a. h& ^
net-binding.asp
# C; N" u6 h! \) N( y. Hnet-dhcp.asp& g& Z+ C. f' A
net-landingpage.asp9 e' C/ u% d2 |3 L+ A8 S
net-phoneapp.asp
- \# l6 C- v$ rnet-qos.asp) Y0 D4 G$ A( r' I; j$ _; ~8 d# t8 r* z
net-route6add.asp2 |1 s3 v0 f5 P+ d7 h" \
net-routeadd.asp
8 d5 X6 w7 v% }8 U8 L9 N4 dnet-routeset.asp2 B# L* z) M3 F) R! u, \2 x4 C) @
net-time.asp- t2 [5 j- {( H$ E4 j
net-tr069.asp2 X0 f4 i* ^8 D: o
net-wanset.asp
c6 ]1 W( s, { s7 c- }- ?net-wlan.asp
1 ~6 ~# b' b6 M1 M9 Anet-wlan11ac.asp% U/ s$ }+ L, o' Q' y
net-wlanshare.asp( u5 e+ N# P% H, m4 b
normal_access.asp: Q! b* W2 n; @2 b( K! n
normal_internet_wan.asp/ T) @3 i( e# ^7 r" u# I1 c+ b- z+ H
normal_manage.asp9 ]. t4 E1 N5 b( d- O8 h U
normal_manage_password.asp
9 j5 p S* K. t# ]! Z. w$ Pnormal_network.asp
: x. |+ Y: t2 ?+ F3 {+ ~. unormal_security.asp" r$ [3 t+ J) T- s% }* \
normal_sys.asp
& `7 O* l% p% o( W% J( PparentControl.asp
5 i8 s. h1 U8 z( Y8 F- f; @pushviewfinish.asp
. I6 ?% ~4 l2 X" ]! H* n9 _" ypushviewupgrade.asp4 w0 a4 \! C! I
qos-clsedit.asp
' y c* E+ u9 z8 L9 Kqos-comvlan.asp& s8 R0 R+ s/ A
qos-dslimit.asp7 Y- a. O) h7 B& ^/ l9 @1 l
redirect.cgi2 q1 P [' f6 [% z
redirect_cancel.cgi1 v) ], [- Y0 I4 R
refresh.asp
2 s! v5 m" ?! \! Z; oregister.asp
+ w( f3 E6 V) U2 Uregprocess.asp+ ?8 C* |$ d) i* G
regprocess.cgi- F- W# t5 H4 }5 c4 k, \
regstatus.asp
; C n0 m' j$ G, K. u# CRemoteUPGMsg.cgi
! J- ]$ w- D- e* e5 Nreset.asp
( x+ M# G* e4 v' C9 x: Lresetscreen.asp
8 @! E7 }- E/ F2 n" s) prestorepurefactory.cgi
, R4 k7 S' e1 _( r$ Zsec-addmacfilter.asp
7 x6 d2 }& B3 s. ksec-addportfilter.asp
$ n& d6 M$ [5 l& _+ Jsec-firewall.asp
1 o& ]4 |2 ]" m' U5 n4 rsec-macfilter.asp+ c0 @% n% p$ P6 i, {1 z1 p
sec-portfilter.asp. c) H7 \$ W; \! a3 z
sec-protocolfilter.asp; f0 D' i3 E2 f& A
sec-urlfilter.asp
, v& q8 v8 h+ N0 A- H7 _2 Csec_macfilterlist.cgi' I8 n3 t& j3 p/ I* O6 a+ J* L
sec_portfilterinlist.cgi
* I4 g) O: `+ \% q2 l* X( O& ^sec_portfilteroutlist.cgi' [! Y" C) |- b* o+ \ R
sec_urlfilterlist.cgi# H6 C a: g% S) e f
selfcheck.asp
6 ]0 v( j6 ^! Eshowhis.cgi
* D* J" z7 X$ Q, ^+ h2 Gshowusb.cgi
* Z4 r0 K7 b: Z% ~, ssta-acs.asp
9 M) |! |. t% E3 ]6 D$ m; Q$ ~sta-device.asp. N3 `6 S+ \; |0 h
sta-network.asp& _$ W, T- e) t" Z- i+ w; f
sta-position.asp" `2 _4 k" d V% V
sta-user.asp( S2 J% A9 z/ F% K; n
sta-VoIP.asp
' e- F1 K. y2 T. T7 tsta-VoIP248.asp: L9 L, s( g5 \
state_bandwidth.asp4 b% C; u9 E5 |" o/ ?5 I9 k
state_device.asp; r8 Q" D1 ?4 [& o& L( R
state_gateway.asp
) v. R# A/ U) ~$ g, y- D) Wstate_overview.asp
r& n* u. x$ X7 Q9 Qstore.asp2 Y! o+ C! S4 A% z$ B
syslog.cgi# l7 t! a% _ W4 \" D; m
telnet.asp& B' q& h0 A; W" f' x
test_factory.asp' v4 S. t6 A2 c# Z6 _6 B
test_info.asp
" C! z. K7 _" u" B5 I2 y% Ytest_version.asp
. e0 d& Y7 e7 N1 o! s* [uindex.asp2 i! j# i; g2 E4 [5 T1 P' t
UpdateMsg.cgi8 U6 q( E2 I$ f5 v
upgrade.asp
5 D% S# C/ M' Ywifi.asp 6 b+ c+ o- @7 F( x7 p) h5 A, r
由于没拿到telnet账户密码。。。也就到此为止了。。。期待有大神出现。。。% p5 _" Y5 N5 A% z# x
" B! q# i; w0 I- ~) c; D& t
8 R. Z) G! S9 ?% l0 Z) b6 b
3 U6 \: }6 r# z |
|