-
Notifications
You must be signed in to change notification settings - Fork 224
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
WAP4410N #11
Comments
strange... I'll investigate :) |
I have a PCAP if you want me to e-mail it? Edit: Actually uploaded it here : http://filebin.ca/17UJu55XztDv/Capture.pcapng |
no, thank you, I'll search the firmware. |
Okay thanks :-). Let me know if I can help. |
The binary in your firmware have all the symbols :) nice |
Certainly will, thanks! Let me know when it's up. |
updated, could you test it and past the result? |
you can also try some commands like 'ps' |
Traceback (most recent call last): |
I added: and got: Which is backwards... So, endian? |
Yep :) |
Could you test the last version please? |
Needed to bug fix to this line: However it now works! CONFIRMED! Thank you very much for your time and patience :) |
Oh yes, my bad :) |
No, thank you :-) Can you see from the firmware if there's a similar getvar function like with yours? |
you can use the command 1 to dump all the available variables, commands numbers are the same :) If I wasn't lazy I would code a real PoC with command line parameters :D |
Ah I kept trying with 2 and forgot about 1. For 2 on this model it needs to be: The backdoor seems a bit unstable, if you try executing something it doesn't like it disconnects you and I don't seem to be able to close my connections properly (I managed to get it to refuse to let me to connect until I rebooted the AP). Here's the contents of /bin/ ls /bin/ -l and the supported features of busybox: busybox Usage: busybox [function] [arguments]...
Currently defined functions: |
Nice, thank you :) |
Just tried the new version, works well. Thanks for researching this and helping to make the product safer! Just wondering but given our endian discovery, your list of "Backdoor is not working in", do these need to be re-checked with the new code? |
I don't think so, people reported routers with closed ports. |
Thanks. Minor thing, WAP4410N is a Cisco product not Linksys : http://www.cisco.com/en/US/prod/collateral/wireless/ps5678/ps10047/ps10052/data_sheet_c78-501860.html |
woops, fixed :) |
Not works with new firmware 2.0.7.4 |
WAP4410N (also known as WAP4410N-E, it's the same device) Hardware Revision 01 and 02 are Linksys (in fact "Linksys by Cisco") products, Rev 03 is pure Cisco. Linksys was never a company on it's own. It was just a "brand" name Cisco used for their SOHO products. |
Hi, @Matthew1471 I am looking for a 2.0.6.1 or newer firmware image file for a WAP4410N-E V02 that I have. Cisco made this device unsupported in 2019 and so I am unable to find one through an official channel. Any chance that you have it, and can upload somewhere that I could download from, so I can update my device ? Thanks in advance, Gavin |
Listens to port and responds to data with "ScMM" but your Python script doesn't work in its current form.
PID VID: WAP4410N-E V02
Software Version: 2.0.6.1
The text was updated successfully, but these errors were encountered: