找回密码
 注册

QQ登录

只需一步,快速开始

楼主: ahww

[教程] hw_ctree.xml文件无法解密

[复制链接]
 楼主| 发表于 2024-10-21 23:51:01 | 显示全部楼层
改成与超密一样的字符串也不行。
发表于 2024-10-22 00:26:37 | 显示全部楼层
  1. @Echo off
    ! ~7 b) O. v/ ^
  2. echo set sh=WScript.CreateObject("WScript.Shell") >tmp.vbs
    3 j1 X/ Y# g" X' d& @7 f7 k+ h
  3. echo WScript.Sleep 1000 >>tmp.vbs
    / h' \+ A  p) N
  4. echo sh.SendKeys "open 192.168.1.1{ENTER}" >>tmp.vbs
    3 N7 {+ |4 |4 Y: v  f, v7 O
  5. echo WScript.Sleep 1000 >>tmp.vbs3 @. e3 N! {% B1 S; o, E% b
  6. echo sh.SendKeys "root{ENTER}" >>tmp.vbs
    ' N" [! H; N% P$ O+ j1 R& `  J; l
  7. echo WScript.Sleep 1000 >>tmp.vbs
    1 R4 X- K( J: ?% T  }! M: H
  8. echo sh.SendKeys "adminHW{ENTER}" >>tmp.vbs9 M% b/ I5 I2 S, G& S2 u& a
  9. echo WScript.Sleep 1000 >>tmp.vbs8 z! ]: s# q, X5 K( \4 H7 Z
  10. echo sh.SendKeys "su{ENTER}" >>tmp.vbs
    ! h$ Z# d6 m, D3 o) L$ I; [% K* a, u
  11. echo WScript.Sleep 1000 >>tmp.vbs
    ( g1 P8 |* H. `7 v" v
  12. echo sh.SendKeys "shell{ENTER}" >>tmp.vbs
    ' M0 s2 J5 b0 ]) w8 D/ m, {
  13. echo WScript.Sleep 1000 >>tmp.vbs
    ! F3 D3 i; T2 v' |9 h. r
  14. echo sh.SendKeys "cp /mnt/jffs2/hw_ctree.xml /mnt/jffs2/mycfg.xml.gz {ENTER}" >>tmp.vbs6 |2 m" p% {5 H, g  ^" {) y" W
  15. echo WScript.Sleep 1000 >>tmp.vbs9 M$ g, j' z8 u/ n2 C! P1 s! C7 z
  16. echo sh.SendKeys "cd /mnt/jffs2{ENTER}" >>tmp.vbs
    % C5 c6 X  E7 _8 A& y
  17. echo WScript.Sleep 1000 >>tmp.vbs& v$ \- C( G3 v& C" H% s4 h4 F
  18. echo sh.SendKeys "aescrypt2 1 mycfg.xml.gz tem{ENTER}" >>tmp.vbs& I3 J, h% U# A' P0 l+ z6 Q; @
  19. echo WScript.Sleep 1000 >>tmp.vbs. K: r0 y0 E4 b9 f+ r
  20. echo sh.SendKeys "gzip -d mycfg.xml.gz{ENTER}" >>tmp.vbs1 x9 B& d0 o. L) Z, j) ?8 W" K; c
  21. echo WScript.Sleep 1000 >>tmp.vbs
    : H* A7 a' W" E) A0 I% L/ v% H5 K
  22. echo sh.SendKeys "grep WebUserInfoInstance mycfg.xml{ENTER}" >>tmp.vbs
    ' h3 H1 c  r% b% r" t
  23. echo WScript.Sleep 1000 >>tmp.vbs
    % r" |* N$ {) W- j
  24. echo sh.SendKeys "rm mycfg.xml{ENTER}" >>tmp.vbs8 D% j& z$ F2 k* z7 P
  25. echo WScript.Sleep 1000 >>tmp.vbs
    ! z8 {' j) G) U: Z5 B% k3 u/ H1 I
  26. start telnet
    % N& W0 i. N  A8 i
  27. cscript //nologo tmp.vbs
    9 n5 g  p) ^3 X9 O: F! G/ H, X! j
  28. del tmp.vbs
复制代码
 楼主| 发表于 2024-10-23 10:29:28 | 显示全部楼层
Marken888 发表于 2024-10-21 20:21; Q1 Y, x6 Z6 T8 y5 e
这不清楚,听说加密方式是哈希值,还原不回去的,改成跟超密一样试试看吧 ...
3 Y8 ^6 q; |: G0 P
试了,无效。
 楼主| 发表于 2024-10-23 10:32:22 | 显示全部楼层
1 c" {, e4 D+ j! @2 _
我试试。
 楼主| 发表于 2024-10-23 11:24:13 | 显示全部楼层
  T, o' l3 _$ A; N6 N
不行,解出的密码部分仍是乱码或仍是加密的,如下:
- p$ w- R# E" a# s/ o<X_HW_WebUserInfoInstance InstanceID="1" UserName="root" Password="$2-{\&gt;L;OTS5*&amp;&gt;#YL[BsO`ghKA&lt;}TG#5]PEH[Gq|HvXVO2-vBfRGJD;2iK;$1f8&amp;I*&lt;E[$WqX&quot;0&quot;2Z@c~2o$_6scL#5q&quot;~k=V3`,U$" UserLevel="1" Enable="1" ModifyPasswordFlag="1" Salt="01efce6ddd3feac23ed85bad" PassMode="3" Alias="cpe-1"/>8 x5 c9 R) t; b- h9 _
<X_HW_WebUserInfoInstance InstanceID="2" UserName="telecomadmin" Password="$2/(E|7D&lt;JPDgbtLSQvg9W{/2^LKnb#P&lt;Yn/Z18G2NPC%.4&quot;OaL&quot;|~ayHm`vCCV7&lt;6Us^LZ)uSoH*wVWI&amp;Rh&lt;BL&amp;p^JUj/N,S*]6E$$" UserLevel="0" Enable="1" ModifyPasswordFlag="0" Salt="d4e109ad12d6ed238fb8eee1" PassMode="3" Alias="cpe-2"/>
 楼主| 发表于 2024-10-23 11:25:39 | 显示全部楼层
/ c- X* o7 k& D( m- G
试了,不行,密码部分仍是一长串各种各样的字符
0 W6 F& w( ~& @/ m  B, i; ^<X_HW_WebUserInfoInstance InstanceID="1" UserName="root" Password="$2-{\&gt;L;OTS5*&amp;&gt;#YL[BsO`ghKA&lt;}TG#5]PEH[Gq|HvXVO2-vBfRGJD;2iK;$1f8&amp;I*&lt;E[$WqX&quot;0&quot;2Z@c~2o$_6scL#5q&quot;~k=V3`,U$" UserLevel="1" Enable="1" ModifyPasswordFlag="1" Salt="01efce6ddd3feac23ed85bad" PassMode="3" Alias="cpe-1"/>
' G( R+ ?; m" {  U7 H<X_HW_WebUserInfoInstance InstanceID="2" UserName="telecomadmin" Password="$2/(E|7D&lt;JPDgbtLSQvg9W{/2^LKnb#P&lt;Yn/Z18G2NPC%.4&quot;OaL&quot;|~ayHm`vCCV7&lt;6Us^LZ)uSoH*wVWI&amp;Rh&lt;BL&amp;p^JUj/N,S*]6E$$" UserLevel="0" Enable="1" ModifyPasswordFlag="0" Salt="d4e109ad12d6ed238fb8eee1" PassMode="3" Alias="cpe-2"/>
发表于 2024-10-23 14:35:28 | 显示全部楼层
本帖最后由 358954592 于 2024-10-23 20:07 编辑 4 K& d7 q; L9 p2 n5 {- ]* \( R
* T6 k5 o0 h1 `( R) j5 a' ~
还原后的密码是保存在hw_default_ctree.xml文件里的,把这个问价下载下来解析一下,( f. x+ u& F8 F5 }
<X_HW_WebUserInfo NumberOfInstances="2">* T  u' G8 n) e* @7 ^. y7 x; ]
<X_HW_WebUserInfoInstance InstanceID="1" ModifyPasswordFlag="0" UserName="useradmin" Password="r37us" UserLevel="1" Enable="1"/>         \\光猫背后的用户名密码
" {, Q5 b0 n2 F+ H<X_HW_WebUserInfoInstance InstanceID="2" ModifyPasswordFlag="0" UserName="telecomadmin" Password="nE7jA%5m" UserLevel="0" Enable="1"/>  \\超级密码+ p  Q, x! T* y' B2 t2 H4 h% r

/ }) Q0 A, k- o$ V改成你想要的密码,加密后上传。然后再恢复出厂设置。
! ]7 x3 }# H9 I4 \. {1 G( n* i
*滑块验证:
您需要登录后才可以回帖 登录 | 注册

本版积分规则

Archiver|小黑屋|宽带技术网 |网站地图 粤公网安备44152102000001号

GMT+8, 2025-6-17 12:30 , Processed in 0.024118 second(s), 3 queries , Redis On.

Powered by Discuz! X3.5 Licensed

Copyright © 2001-2020, Tencent Cloud.

快速回复 返回顶部 返回列表