|
|
发表于 2018-11-14 16:40:59
|
显示全部楼层
可以确认GM219-S 硬件版本:HV1.0.00.052 为四川天邑代工的。。。找到了地区配置文件。。。找到了各种服务的默认的密码: X) |* v+ ~* C5 _0 E' q
( r' c: a1 u: e0 Z d, i9 W<Account>0 T: a7 |, W9 p
<Entry0 Active="Yes" username="CMCCAdmin" web_passwd="aDm8H%MdA" display_mask="FF FF FF FF FF FF FF FF FF" />
( ?" |: b, A: g, ~1 q <Entry1 Active="Yes" username="user" web_passwd="1234" display_mask="BF 00 0F 08 07 20 03 00 01" />
" M$ ]/ v. |% i b& Q, k <Entry2 Active="Yes" username="user3" web_passwd="1234" display_mask="BF 00 07 08 07 10 03 00 01" />
: l$ L, l: ^5 u <TelnetEntry Active="No" telnet_username="admin" telnet_passwd="1234" telnet_port="23" />- I5 Y: u8 L' E( w7 b' @
<FtpEntry Active="No" ftp_username="admin" ftp_passwd="1234" ftp_port="21" />) e6 H6 D5 _9 \, ~
<HttpEntry Active="Yes" http_right="1" />
2 A% z& @+ h+ D1 e+ C <ConsoleEntry Active="Yes" console_username="admin" console_passwd="1234" /># W, a& y) }0 M( i# M3 V$ i6 \
<CTDefParaEntry setDefValueFlag="1" />; C+ ?; Z1 C, U
</Account> 本地移动不改超密,所以我一直在找telnet的用户名和密码,试了telnet的默认账号密码发现不对应该是被运营商改了。。。移动的网在家就是看电视用。。。懒得拆机ttl。。。也没法下一步玩。。。也就不开新贴献丑了。。。1 `) w2 K. T" R E
; t. z4 I5 B3 o: o0 u* I
尝试固件里/boaroot/cgi-bin/目录下的一些页面。。。发现了一些web下的隐藏页面。。。相同硬件版本的可以去尝试:
. D- s7 Z" P7 E7 D' ]8 M9 t0 M& Y+ P0 U3 w# i9 l
http://192.168.1.1/cqregister.asp7 E# A- h: o5 K
http://192.168.1.1/cqreset.asp
' H% c7 r- e$ Y) R6 m( G5 Mhttp://192.168.1.1/cwmpsetting.asp
L/ x+ E* [& o4 W: nhttp://192.168.1.1/getGateWay.cgi
; X- g' X) R, A j# V0 S7 S* [, j; A$ h& T8 u1 U
#getRomfileInfo就出现个下拉菜单
# O1 Y- C( x3 E6 R p7 V& J/ v* Ahttp://192.168.1.1/getRomfileInfo.cgi
& F8 }6 q4 n# [+ j1 X" ^. t: Q/ J t# L1 S: v$ n
http://192.168.1.1/register.asp* m0 }8 Y" F3 n
http://192.168.1.1/regprocess.asp
# `) c6 N% N# ~0 x( U$ V" _& |http://192.168.1.1/regprocess.cgi @: M! u; K0 G% o% G+ j
( T1 Z2 R) K" z, Y4 X$ i
#恢复默认设置的命令不会丢移动下发的配置( \0 L* T6 S4 x& E; `$ r' s- G
http://192.168.1.1/restorepurefactory.cgi
4 E, a' \8 X+ X) w7 C1 V q* U- L# v$ L1 g+ D
http://192.168.1.1/telnet.asp" l9 C) {7 N3 J
http://192.168.1.1/test_factory.asp+ X- g0 R: Z6 O2 {
http://192.168.1.1/test_info.asp
7 R8 i) \7 X$ ?/ K* ]7 J: I! P7 Z8 nhttp://192.168.1.1/test_version.asp" u; d8 [6 w7 Q6 P/ B! D4 X
http://192.168.1.1/upgrade.asp
3 U2 ?3 F" h5 s" W& P: R5 k# ^; N3 i# i( {- \) Q; f
/boaroot/cgi-bin/目录下的所有文件。。。其他隐藏页面有兴趣自己去尝试。。。
9 A9 m% V$ m" b' Vapp-daily.asp: B7 x, Y) X1 C: w# I, M7 T8 b7 f j
app-ddns.asp
8 y3 M1 j7 j- x+ v4 Rapp-igmpset.asp
9 B3 S' ^; C6 k) aapp-natset.asp
6 q+ \ `( g2 D: s# `5 _6 `$ tapp-upnp.asp' x2 k; I. ?' \! m2 Z
app-VoIP.asp
Z7 V, s; t/ u) f Oapp-VoIP248.asp2 I" {8 N! [0 Z, R# u) [/ F
app-VoIP248_Adv.asp
' @' G; ^2 ?' w- V* G! ?8 g8 Napp-VoIPUser.asp
2 W; c/ \. p G2 s- o! v! J: ]7 qapp-VoIP_Adv.asp6 k1 G/ f3 J& d; F. p; A6 ?
app_ddnslist.cgi
5 x/ f9 o: Y& E) G% B5 Mavalanch.asp- J/ e4 J. q/ C# V# g. U
byeBye.cgi
- u. g- A, `' p. I/ dadv_vpn.asp
) ~0 O8 [- T! T9 P" N9 ^cqregister.asp
' i. w5 ~6 k8 }1 acqreset.asp7 ~) o$ R% N- R3 z1 A$ r' X+ N
adv_upnp.asp2 @ ? o0 ?4 x
cwmpsetting.asp
) y+ v4 A& l3 Q9 ?6 m( Ndiag-quickdiagnose.asp6 u, e" V. d3 J& N- M' k
ErrMsg.asp
" M0 t% z/ @6 V2 WgetGateWay.cgi
+ ^2 p# o! a- ]% k+ B1 J6 e/ ^getPingResult.cgi6 m4 L: [1 k2 X" g# F
getRomfileInfo.cgi6 e. t) K- [9 ?+ f
getTracentResult.cgi6 T* _7 Z) W& D, h/ L7 e3 U9 o% H
help.asp5 R0 b! f \/ b/ D) |% q7 q
help_content.asp
2 j$ a; _& Q6 q: r3 kadv_qos.asp$ s5 h Y# F; B; R- t! k3 P D
adv_dmz.asp
& Z- n8 r+ i. F" L5 C0 Hindex.asp
3 Y' f2 o% P7 S8 z: v( \6 |index2.asp
# F" {% h% C9 E6 h8 P4 Z# w; findex3.asp) x+ L1 U% W. F9 y7 ~3 P
InsertSimcardMsg.cgi
+ W* t7 k: {8 ]2 Mitms.cgi
$ R" v3 c) n# I! e2 R: O; _6 }adv_ddns.asp
7 F; W, S, w3 H3 fcontent.asp* `! S/ b! P, o: n) |' x8 _
laserforce.cgi
: Q# d+ Q( T5 W; G5 `6 klasernormal.cgi
" F) S1 i: z" @. Glogout.cgi+ _' D R) A5 q+ C" H/ N3 f" a7 h
mag-account.asp( ?5 R4 R6 s8 o. ~7 s+ P" H
mag-diagnose.asp' A/ T- o* ^& w3 e. @3 h: O6 U
mag-reset.asp6 H0 D8 g0 n) k, ?0 Q9 c; c
mag-syslogmanage.asp
! e* w; ~0 g j+ s4 }0 i0 Emaintainreport.cgi
C! T& o8 k5 mnet-binding.asp
# ^1 ]' l @; w# b" S: h. @" Xnet-dhcp.asp- o4 |& B& K; x p* L' D
net-landingpage.asp- `, M# V# b# X4 M8 _
net-phoneapp.asp9 Z, ]! T/ J7 `5 ]- q3 y) Q
net-qos.asp- E+ n" x5 A1 E* l5 z/ i
net-route6add.asp7 F4 V* O; M* a
net-routeadd.asp
2 H. c1 X1 E: j+ L# I1 Snet-routeset.asp
# n8 ]/ ?: F, [# u2 r0 r- cnet-time.asp
- y {9 B3 \' r2 cnet-tr069.asp
: M+ q0 h% G' D' _2 \net-wanset.asp( |* A$ Q. Y) j6 t3 h% |' S$ r
net-wlan.asp* I M) y7 ]2 F* @
net-wlan11ac.asp
% i7 c: r( q8 `- J9 qnet-wlanshare.asp! T& K: F5 Q" W# d' L
normal_access.asp7 a* r4 l% e3 [5 l' L
normal_internet_wan.asp
- M8 ^. a! S7 v% j/ Z/ B. b% `normal_manage.asp
9 S/ ?+ |6 _, R. x" H$ G7 j+ `normal_manage_password.asp
/ s0 q# t, j( y+ i+ P+ q9 n! xnormal_network.asp% Y+ T" y5 ~: F; |% @2 n" Q# X
normal_security.asp
$ ~4 y+ |- d% k7 D: {. v5 K% Lnormal_sys.asp9 }" ]0 X' w; w/ ~" s) ?, G1 i1 L
parentControl.asp
- }& @. `' T$ lpushviewfinish.asp2 u5 Q9 J1 W' l2 t/ {
pushviewupgrade.asp! o' `0 E8 S( L( l& ^4 R$ O+ `1 q
qos-clsedit.asp) m4 p' S# r* r
qos-comvlan.asp5 L; _2 b5 m5 [
qos-dslimit.asp- u, W3 A3 O1 c% k5 ]0 h
redirect.cgi& J1 b; f. `: n. |! x
redirect_cancel.cgi$ g M1 o k: M" V1 s
refresh.asp
( r1 N* ^9 Z* F& | qregister.asp2 ]0 R) I Q! t
regprocess.asp
6 Z% f r2 k' Mregprocess.cgi; N8 ~; d# l, A
regstatus.asp, N9 w# T2 R" w! x! |. e
RemoteUPGMsg.cgi
' w" n2 v0 \6 |) c; treset.asp8 {( l+ u6 `9 E' S
resetscreen.asp
3 h3 P" c& ]& j. ]: }" ^- drestorepurefactory.cgi, F- l B2 `4 {# P4 [, P9 Z
sec-addmacfilter.asp
( e3 `" a0 d5 f& e) S* Psec-addportfilter.asp
7 z5 l* }; G0 m- Gsec-firewall.asp
3 Z [; V* v9 wsec-macfilter.asp
8 F) B0 z5 N2 csec-portfilter.asp+ f3 b& q' y: k9 H. {" N5 ?; x
sec-protocolfilter.asp
" U. I4 u6 S4 g- ^% I. y0 tsec-urlfilter.asp: m% ~+ G! y" k
sec_macfilterlist.cgi8 H2 E$ p: C% \5 U7 ^# v9 Z
sec_portfilterinlist.cgi
6 m# J a# k3 z" `9 x- b7 qsec_portfilteroutlist.cgi
% E, {. k* w3 Y7 D5 c. q5 {4 `sec_urlfilterlist.cgi2 @# A" C) ?9 s3 ?. O$ q9 v# M
selfcheck.asp4 Z8 S( v2 Y- C2 K1 I
showhis.cgi
5 T. i8 @7 U1 @' c1 t: Vshowusb.cgi
$ N6 y. ^% x9 S- V/ B8 ~" Nsta-acs.asp+ w$ J6 I5 r( \" s. n6 S E
sta-device.asp
# e+ }+ z) O% ?8 n$ Xsta-network.asp7 K, ]8 E' e0 G8 C* m& ` i9 L
sta-position.asp/ J/ d7 L) T% w
sta-user.asp
" r0 `% f: ?" ?# M1 J1 ?sta-VoIP.asp
$ t8 H5 f* \7 f9 D2 X4 Dsta-VoIP248.asp6 ^' w$ i2 X# x! ]6 x9 @
state_bandwidth.asp/ c9 d) u7 I; p# U, \1 @4 v" i
state_device.asp/ K) x4 r: K% W1 B
state_gateway.asp0 ~- X' I |! r- o, W
state_overview.asp
0 B, A2 D; y/ A. gstore.asp
o; p* ]/ w- t3 [% \% {" o# N3 qsyslog.cgi
5 r& s& L6 r) K3 C7 {- Ctelnet.asp
1 {$ J% H4 ]% s9 ~+ Itest_factory.asp- J' J6 B" f) I: v( }' K" S
test_info.asp
/ T, _, d3 [6 b1 H5 ~test_version.asp) a7 L: S5 P% ~; `* U7 q" L
uindex.asp
% e( g o# r) f: dUpdateMsg.cgi
% x2 D" }$ E( yupgrade.asp
6 @, n# W2 K, Z5 Dwifi.asp
& }( g. C" A& H p6 e) L由于没拿到telnet账户密码。。。也就到此为止了。。。期待有大神出现。。。
( U& @, s8 z4 _* E) r5 y9 {* t T/ i
% E2 `9 R2 R' W7 t( X' L& d! W9 G. ?" ?* @) V; N# F
|
|