找回密码
 注册

QQ登录

只需一步,快速开始

楼主: ahww

[教程] hw_ctree.xml文件无法解密

[复制链接]
 楼主| 发表于 2024-10-21 23:51:01 | 显示全部楼层
改成与超密一样的字符串也不行。
发表于 2024-10-22 00:26:37 | 显示全部楼层
  1. @Echo off
    ( v1 q5 u- q; K( M
  2. echo set sh=WScript.CreateObject("WScript.Shell") >tmp.vbs
    : T: e& f: k7 I' L2 i
  3. echo WScript.Sleep 1000 >>tmp.vbs
    7 L/ e$ t  K+ G1 I
  4. echo sh.SendKeys "open 192.168.1.1{ENTER}" >>tmp.vbs
    6 o4 A$ C3 Q8 G
  5. echo WScript.Sleep 1000 >>tmp.vbs
    2 D1 Q3 w% J- p) c3 _8 Y  |
  6. echo sh.SendKeys "root{ENTER}" >>tmp.vbs
    , c) x8 c  d; Q$ t$ b
  7. echo WScript.Sleep 1000 >>tmp.vbs
    9 _! h# [8 F1 J( O+ A( h
  8. echo sh.SendKeys "adminHW{ENTER}" >>tmp.vbs
    , w2 I7 b. H5 x7 ~, J
  9. echo WScript.Sleep 1000 >>tmp.vbs
    5 Q* T+ y8 T% C1 S3 @' p
  10. echo sh.SendKeys "su{ENTER}" >>tmp.vbs
    , t7 n  i" n+ T7 x" _2 ~
  11. echo WScript.Sleep 1000 >>tmp.vbs
    ' Y$ f6 m4 }. u+ C
  12. echo sh.SendKeys "shell{ENTER}" >>tmp.vbs
    . R7 d1 {3 r9 P) @7 y
  13. echo WScript.Sleep 1000 >>tmp.vbs
    : k6 c  @+ j" [; p
  14. echo sh.SendKeys "cp /mnt/jffs2/hw_ctree.xml /mnt/jffs2/mycfg.xml.gz {ENTER}" >>tmp.vbs' Z6 A' A( R2 ]- ?' Z
  15. echo WScript.Sleep 1000 >>tmp.vbs; O6 w& O$ S2 F: U1 n# p
  16. echo sh.SendKeys "cd /mnt/jffs2{ENTER}" >>tmp.vbs) o' I' v" ]! o% m8 _  @
  17. echo WScript.Sleep 1000 >>tmp.vbs
    & x; I  I+ A1 ^2 Z
  18. echo sh.SendKeys "aescrypt2 1 mycfg.xml.gz tem{ENTER}" >>tmp.vbs2 R: Z! S, J1 E0 r0 H
  19. echo WScript.Sleep 1000 >>tmp.vbs
    6 O1 y# E: B+ T8 y4 Y9 K
  20. echo sh.SendKeys "gzip -d mycfg.xml.gz{ENTER}" >>tmp.vbs" V6 \: l, `' {4 R; i. ?" h" s6 V. L
  21. echo WScript.Sleep 1000 >>tmp.vbs
    ! _' y# X8 A; n6 [2 v
  22. echo sh.SendKeys "grep WebUserInfoInstance mycfg.xml{ENTER}" >>tmp.vbs0 H, N& T6 D$ r$ K5 n
  23. echo WScript.Sleep 1000 >>tmp.vbs
    # T% p9 }) m$ c5 T9 Y% _' V
  24. echo sh.SendKeys "rm mycfg.xml{ENTER}" >>tmp.vbs' a- S& |2 V+ f- @1 g
  25. echo WScript.Sleep 1000 >>tmp.vbs5 s/ P2 k8 a- f: P. j: C# g
  26. start telnet
    . g0 t6 V- r& U- I' w0 @
  27. cscript //nologo tmp.vbs
    $ P, k$ |/ c7 Z) v+ v
  28. del tmp.vbs
复制代码
 楼主| 发表于 2024-10-23 10:29:28 | 显示全部楼层
Marken888 发表于 2024-10-21 20:219 b2 ~5 j$ K7 _8 t
这不清楚,听说加密方式是哈希值,还原不回去的,改成跟超密一样试试看吧 ...
6 r4 {9 [1 s2 u: d0 j
试了,无效。
 楼主| 发表于 2024-10-23 10:32:22 | 显示全部楼层

9 h' E. ]% r, T! E7 C我试试。
 楼主| 发表于 2024-10-23 11:24:13 | 显示全部楼层

, I0 {9 t" k, f+ ~; X不行,解出的密码部分仍是乱码或仍是加密的,如下:
  s" \$ Q" l! n5 z9 H) x<X_HW_WebUserInfoInstance InstanceID="1" UserName="root" Password="$2-{\&gt;L;OTS5*&amp;&gt;#YL[BsO`ghKA&lt;}TG#5]PEH[Gq|HvXVO2-vBfRGJD;2iK;$1f8&amp;I*&lt;E[$WqX&quot;0&quot;2Z@c~2o$_6scL#5q&quot;~k=V3`,U$" UserLevel="1" Enable="1" ModifyPasswordFlag="1" Salt="01efce6ddd3feac23ed85bad" PassMode="3" Alias="cpe-1"/>6 k5 Y9 q; I1 R8 j( y/ q  X
<X_HW_WebUserInfoInstance InstanceID="2" UserName="telecomadmin" Password="$2/(E|7D&lt;JPDgbtLSQvg9W{/2^LKnb#P&lt;Yn/Z18G2NPC%.4&quot;OaL&quot;|~ayHm`vCCV7&lt;6Us^LZ)uSoH*wVWI&amp;Rh&lt;BL&amp;p^JUj/N,S*]6E$$" UserLevel="0" Enable="1" ModifyPasswordFlag="0" Salt="d4e109ad12d6ed238fb8eee1" PassMode="3" Alias="cpe-2"/>
 楼主| 发表于 2024-10-23 11:25:39 | 显示全部楼层

3 o  \6 {) |" e, e) s0 E试了,不行,密码部分仍是一长串各种各样的字符: |; B( ^3 B2 S# Q( ?
<X_HW_WebUserInfoInstance InstanceID="1" UserName="root" Password="$2-{\&gt;L;OTS5*&amp;&gt;#YL[BsO`ghKA&lt;}TG#5]PEH[Gq|HvXVO2-vBfRGJD;2iK;$1f8&amp;I*&lt;E[$WqX&quot;0&quot;2Z@c~2o$_6scL#5q&quot;~k=V3`,U$" UserLevel="1" Enable="1" ModifyPasswordFlag="1" Salt="01efce6ddd3feac23ed85bad" PassMode="3" Alias="cpe-1"/>9 S" p3 l4 `+ w
<X_HW_WebUserInfoInstance InstanceID="2" UserName="telecomadmin" Password="$2/(E|7D&lt;JPDgbtLSQvg9W{/2^LKnb#P&lt;Yn/Z18G2NPC%.4&quot;OaL&quot;|~ayHm`vCCV7&lt;6Us^LZ)uSoH*wVWI&amp;Rh&lt;BL&amp;p^JUj/N,S*]6E$$" UserLevel="0" Enable="1" ModifyPasswordFlag="0" Salt="d4e109ad12d6ed238fb8eee1" PassMode="3" Alias="cpe-2"/>
发表于 2024-10-23 14:35:28 | 显示全部楼层
本帖最后由 358954592 于 2024-10-23 20:07 编辑
% \( O+ G5 K+ T# v% y
/ m8 x$ f; H3 |8 Z: w5 _0 R9 H还原后的密码是保存在hw_default_ctree.xml文件里的,把这个问价下载下来解析一下,
7 J1 q  j9 v1 `% B6 H<X_HW_WebUserInfo NumberOfInstances="2">
6 [% ~0 @( s' _  S- t<X_HW_WebUserInfoInstance InstanceID="1" ModifyPasswordFlag="0" UserName="useradmin" Password="r37us" UserLevel="1" Enable="1"/>         \\光猫背后的用户名密码
  E2 t$ z* Q, |. ~4 G* P+ s<X_HW_WebUserInfoInstance InstanceID="2" ModifyPasswordFlag="0" UserName="telecomadmin" Password="nE7jA%5m" UserLevel="0" Enable="1"/>  \\超级密码0 I+ ?' r. |' {( [! M3 G$ f
+ ?+ t/ t/ A  {+ c$ P) M( T& g4 o
改成你想要的密码,加密后上传。然后再恢复出厂设置。
! w: l0 {. e2 ?7 F
*滑块验证:
您需要登录后才可以回帖 登录 | 注册

本版积分规则

Archiver|小黑屋|宽带技术网 |网站地图 粤公网安备44152102000001号

GMT+8, 2025-6-16 19:24 , Processed in 0.026282 second(s), 3 queries , Redis On.

Powered by Discuz! X3.5 Licensed

Copyright © 2001-2020, Tencent Cloud.

快速回复 返回顶部 返回列表