fs.com s5850 and s8050 series type switches have a secret mode which lets you enter a regular shell from the switch cli, like so:
The command and password are not documented by the manufacturer, i wondered wether if its possible to extract that password from the firmware. After all: its my device, and i want to have access to all the features!
Download the latest firmware image for those switch types and let binwalk do its magic:
This will extract an regular cpio archive, including the switch root FS:
The extracted files include the passwd file with hashes:
Let john do its job:
Thats it (wont reveal the password here, but well: its an easy one ;))
Now have fun poking around on your switches firmware:
even tho the good things wont work, but i guess its time to update the firmware anyways:
from Hacker News https://ift.tt/xuQE062
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.