|
本帖最后由 poiu321 于 2024-4-2 03:36 编辑
光猫,huawei HS8546V,修改登录界面为huawei界面,终于获得了超户权限,发现管理页面中有个“Bundle”选项,打开后,里面存在三个插件信息:
Bundle > Bundle信息
在本页面上,您可以查询bundle信息。
1 INSTALLED com.chinamobile.smartgateway.appcore 2.4.1
2 INSTALLED com.chinamobile.smartgateway.andlink 2.3
3 INSTALLED com.chinamobile.smartgateway.cmccdpi 1.1.3
搜了一下,这三个是中国移动在光猫中内置的收集信息并上报的间谍插件,在shell中执行查找find命令,没有搜索结果:
WAP(Dopra Linux) # find / -name com.chinamobile.smartgateway.cmccdpi
WAP(Dopra Linux) #
WAP(Dopra Linux) # find / -name com.chinamobile.smartgateway.andlink
WAP(Dopra Linux) #
WAP(Dopra Linux) # find / -name com.chinamobile.smartgateway.appcore
find: /proc/10607: No such file or directory
WAP(Dopra Linux) #
在网上搜了下“光猫 插件 禁用”,按照搜索结果中的教程,find搜osgi:
WAP(Dopra Linux) # find / -name osgi
/mnt/jffs2/app/osgi
/usr/osgi
/var/osgi
WAP(Dopra Linux) # cd /mnt/jffs2/app/osgi/
WAP(Dopra Linux) #
WAP(Dopra Linux) # ls
data felix-cache security
WAP(Dopra Linux) #
WAP(Dopra Linux) # cd /usr/osgi/
WAP(Dopra Linux) #
WAP(Dopra Linux) # ls
bin conf lib secure.policy
bundle java release security
WAP(Dopra Linux) #
WAP(Dopra Linux) # cd /var/osgi
WAP(Dopra Linux) #
WAP(Dopra Linux) # ls
OSGi0.log felixrecord0.log pd_dynamic_attr
OSGi0.log.lck felixrecord0.log.lck spec.bak
bundlechange0.log java_log_0.log temp
bundlechange0.log.lck java_log_0.log.lck timezonecfg
bundlelist.info log_module.log
bundlestate log_module.log.lck
WAP(Dopra Linux) #
查看进程:
WAP(Dopra Linux) #top
Mem: 190260K used, 313460K free, 0K shrd, 7696K buff, 37408K cached
CPU: 0.0% usr 3.8% sys 0.0% nic 92.3% idle 0.0% io 0.0% irq 3.8% sirq
Load average: 1.29 1.42 1.55 1/284 10689
PID PPID USER STAT VSZ %MEM CPU %CPU COMMAND
10689 10553 srv_ssmp R 1356 0.2 0 3.8 top
2576 2575 osgi_pro S 205m 41.8 0 0.0 java -Djava.security.policy=secur
1179 1 root S 188m 38.3 0 0.0 bbsp
6600 1 root S 145m 29.6 0 0.0 upnpdmain !br+ br0 49652
2508 1 root S 122m 24.9 0 0.0 udm
1198 1 srv_ssmp S 109m 22.1 0 0.0 ssmp
2579 1 root S 102m 20.7 0 0.0 app_m
9425 1 srv_ssmp S 98m 20.0 0 0.0 clid
2555 1 root S 92780 18.4 0 0.0 osgi_proxy
2501 1 srv_web S 87644 17.3 0 0.0 web
1204 1 cfg_omci S 86304 17.1 0 0.0 omci
1197 1 srv_voic S 78808 15.6 0 0.0 voice_h248sip
1202 1 srv_amp S 70532 13.9 0 0.0 amp
1199 1 srv_wifi S 65016 12.9 0 0.0 wifi
1203 1 srv_igmp S 51620 10.2 0 0.0 igmp
2292 1 root S 45052 8.9 0 0.0 usb_mngt
1201 1 srv_etho S 44784 8.8 0 0.0 ethoam
1315 1 root S 42100 8.3 0 0.0 procmonitor ssmp amp voice_h248si
1200 1 cfg_cwmp S 38068 7.5 0 0.0 cwmp
^C491 1 root S N 27536 5.4 0 0.0 apm
WAP(Dopra Linux) # df -h
Filesystem Size Used Available Use% Mounted on
/dev/root 34.9M 34.9M 0 100% /
tmpfs 246.0M 0 246.0M 0% /dev
tmpfs 512.0M 4.0K 512.0M 0% /dev/shm
none 10.0M 32.0K 10.0M 0% /tmp
none 512.0M 656.0K 511.4M 0% /var
none 4.0K 0 4.0K 0% /mnt
none 16.0M 120.0K 15.9M 1% /var/osgi
none 30.0M 0 30.0M 0% /var/felix-temp
none 2.0M 0 2.0M 0% /tmp/QoE
/dev/ubi0_13 16.7M 2.1M 14.5M 13% /mnt/jffs2
none 8.0M 0 8.0M 0% /var/spool/cups
/dev/ubi0_14 116.6M 10.8M 101.1M 10% /mnt/jffs2/app
论坛上有相关指导说,直接删掉“osgi:x:1000:1000:OSGi User,,,:/var/osgi:/bin/sh”和“osgi:$1$U6vz.JFk$robzQ3kXsVf/GNcal1VS/1:0:0:99999:7:::”
链接:https://www.chinadsl.net/forum.php?mod=viewthread&tid=158725
WAP(Dopra Linux) # cat /etc/passwd
root:x:0:0:root:/root:/bin/sh
osgi:x:1000:1000:OSGi User,,,:/var/osgi:/bin/sh
web:x:1001:1001:Cfg User,,,:/var/web:/bin/false
cli:x:1002:1001:Cfg User,,,:/var/cli:/bin/false
srv_usb:x:3001:2002:hw_srv_usb:/var/srv_usb:/bin/sh
srv_samba:x:3002:2002:hw_srv_samba:/var/srv_samba:/bin/sh
srv_amp:x:3003:2002:hw_srv_amp:/var/srv_amp:/bin/sh
srv_web:x:3004:2002:hw_srv_web:/var/srv_web:/bin/sh
osgi_proxy:x:3005:2000:hw_osgi_proxy:/var/osgi_proxy:/bin/sh
srv_igmp:x:3006:2002:hw_srv_igmp:/var/srv_igmp:/bin/sh
cfg_cwmp:x:3007:2001:hw_cfg_cwmp:/var/cfg_cwmp:/bin/sh
srv_ssmp:x:3008:2002:hw_srv_ssmp:/var/srv_ssmp:/bin/sh
cfg_omci:x:3009:2001:hw_cfg_omci:/var/cfg_omci:/bin/sh
cfg_cli:x:3010:2001:hw_cfg_cli:/var/cfg_cli:/bin/sh
cfg_oam:x:3011:2001:hw_cfg_oam:/var/cfg_oam:/bin/sh
srv_bbsp:x:3012:2002:hw_srv_bbsp:/var/srv_bbsp:/bin/sh
srv_ethoam:x:3013:2002:hw_srv_ethoam:/var/srv_ethoam:/bin/sh
srv_dbus:x:3014:2002:hw_srv_dbus:/var/srv_dbus:/bin/sh
srv_wifi:x:3015:2002:hw_srv_wifi:/var/srv_wifi:/bin/sh
tool_mu:x:3016:2003:hw_tool_mu:/var/tool_mu:/bin/sh
srv_snmp:x:3017:2002:hw_srv_snmp:/var/srv_snmp:/bin/sh
srv_apm:x:3018:2002:hw_srv_apm:/var/srv_apm:/bin/sh
tool_iac:x:3019:2003:hw_tool_iac:/var/tool_iac:/bin/sh
nobody:x:65534:65534::/tmp:/bin/false
srv_ldsp:x:4001:2002:srv_ldsp:/var/service:/bin/sh
srv_voice:x:4002:2002:srv_voice:/var/service:/bin/sh
srv_appm:x:4003:2002:srv_appm:/var/service:/bin/sh
srv_user:x:4004:2002:srv_user:/var/srv_user:/bin/sh
WAP(Dopra Linux) # cat /etc/shadow
root:aqnaBbVaP.9Zo:14453:0:99999:7:::
osgi:$1$U6vz.JFk$robzQ3kXsVf/GNcal1VS/1:0:0:99999:7:::
nobody:!:11141:0:99999:7:::
sshd:*:11880:0:99999:7:-1:-1:0
我没敢做……然后,想通过修改java文件名的方法禁用“ 2576 2575 osgi_pro ”进程,提示没有权限:
WAP(Dopra Linux) # mv java javaCMCC
mv: can't rename 'java': Read-only file system
想请教下,如果强制更改这个java的文件权限,并重命名或者直接删除,或者删除上面两个文件中,osgi相关的行数据,对固件正常运行,是否有影响,谁有类似经验,请赐教,先谢谢了。
|
|