Bruteforce Vodafone Sercomm FG824CD PPPoE password!

Hola a todos
Estoy tratando de extraer la contraseña PPPoE del enrutador Vodafone Sercomm FG824CD sin otro enrutador como H500 + Nokia/Alcatel ONU a través de Wireshark.
La contraseña se parece a la codificación base64, si la decodifico en el HEX obtengo el hash MD5 muy popular. Vi que la contraseña de Vodafone PPPoE es de 8 números y letras en mayúsculas. Intenté aplicar fuerza bruta a través de Hashcat con la máscara "-1 ?d?u '?1?1?1?1?1?1?1?1'", pero no obtuve ningún resultado.
¿Quizás la longitud de la contraseña es más de 8?
Cualquier idea, por favor!!!
===============================
Hello everyone
I'm trying to extract PPPoE password from Vodafone Sercomm FG824CD router without another router like H500 + Nokia/Alcatel ONU via Wireshark.
The password looks as base64 coding, if I decode it into the HEX I get very popular MD5 hash. I saw that the Vodafone PPPoE password is 8 numeric and letter in uppercase length. I've tried to brute force it via Hashcat with "-1 ?d?u '?1?1?1?1?1?1?1?1'" mask but there's no result.
Maybe password length more than 8?
Any ideas, please!!!
 

Adjuntos

  • Capture.jpg
    Capture.jpg
    26.8 KB · Visitas: 92
Hola, estoy igual que tu, tengo acceso admin al router, mi gpon (ufiber nano g) sincroniza, pero no consigo la contraseña, en mi caso, es finetwork, voy a intentar llamar ahora.

De todos modos veo que has usado mayusculas y numeros, quiza la contraseña tenga minusculas, yo tengo ahora mismo la grafica a tope con el hash y -1 ?u?l?d hash ?1?1?1?1?1?1?1?1
 
Encontré algo interesante. Si coloco una nueva contraseña en PPPoE y luego Guardar -> Aplicar -> F5, ¡el enrutador cifrará mi contraseña!
¡Usaré la fuerza bruta por la sal!
===============================
I found someting interesting. If I put new password to PPPoE and then Save -> Apply -> F5, the router will encrypt my password!
I'll bruteforce for salt!

Password: DEADC0DE
Result: YDoljowOSAchV3KeA/OCsQ==
Firmware version: FG824CD3115

Hola, estoy igual que tu, tengo acceso admin al router, mi gpon (ufiber nano g) sincroniza, pero no consigo la contraseña, en mi caso, es finetwork, voy a intentar llamar ahora.

De todos modos veo que has usado mayusculas y numeros, quiza la contraseña tenga minusculas, yo tengo ahora mismo la grafica a tope con el hash y -1 ?u?l?d hash ?1?1?1?1?1?1?1?1
¿Tienes el mismo resultado que yo?
 

Adjuntos

  • Capture.jpg
    Capture.jpg
    23.3 KB · Visitas: 85
  • Capture2.JPG
    Capture2.JPG
    24.8 KB · Visitas: 102
I founded PPPoE password in app_log. It appears after lots experiments in file #5 line 839! But I don't know what I have done!
That was so easy after 1,5 weak research!
Capture2.JPG
=================================

Capture.jpg
 
I founded PPPoE password in app_log. It appears after lots experiments in file #5 line 839! But I don't know what I have done!
That was so easy after 1,5 weak research!
Ver el adjunto 100266=================================

Ver el adjunto 100260
I was trying to repeat it. From the Admin access level in the Debug logs I was able to download the "-smd" file, but there was only 1 file inside of the .gz archive and this file did not contain what you have found. Wondering what exactly you have done to face such behavior..? If you have some hint, please help. Thank you!
 
I was trying to repeat it. From the Admin access level in the Debug logs I was able to download the "-smd" file, but there was only 1 file inside of the .gz archive and this file did not contain what you have found. Wondering what exactly you have done to face such behavior..? If you have some hint, please help. Thank you!
What I have done:
1. Disconnect fiber, wait and connect again;
2. Disable and enable main PPPoE connection;
3. Change from CHAP to PAP authorization type in main PPPoE.
May be something else...
 
Arriba