Jump to content

I'm working on a project for school and I need to find a way to force my personal router (Netgear WNR2000v5) to restart. 

 

I've found this list of exploits: https://raw.githubusercontent.com/pedrib/PoC/master/advisories/netgear-wnr2000.txt that my router should still be vulnerable to, but I'm not sure how to run them. 

PSU Tier List | CoC

Gaming Build | FreeNAS Server

Spoiler

i5-4690k || Seidon 240m || GTX780 ACX || MSI Z97s SLI Plus || 8GB 2400mhz || 250GB 840 Evo || 1TB WD Blue || H440 (Black/Blue) || Windows 10 Pro || Dell P2414H & BenQ XL2411Z || Ducky Shine Mini || Logitech G502 Proteus Core

Spoiler

FreeNAS 9.3 - Stable || Xeon E3 1230v2 || Supermicro X9SCM-F || 32GB Crucial ECC DDR3 || 3x4TB WD Red (JBOD) || SYBA SI-PEX40064 sata controller || Corsair CX500m || NZXT Source 210.

Link to comment
https://linustechtips.com/topic/763450-hacking-a-netgear-router/
Share on other sites

Link to post
Share on other sites

6 minutes ago, Droidbot said:

download postman for chrome

 


make a post to <router IP addr.>/apply_noauth.cgi?/reboot_waiting.htm

 

I'm not on that network, since I'm trying to break into it.

PSU Tier List | CoC

Gaming Build | FreeNAS Server

Spoiler

i5-4690k || Seidon 240m || GTX780 ACX || MSI Z97s SLI Plus || 8GB 2400mhz || 250GB 840 Evo || 1TB WD Blue || H440 (Black/Blue) || Windows 10 Pro || Dell P2414H & BenQ XL2411Z || Ducky Shine Mini || Logitech G502 Proteus Core

Spoiler

FreeNAS 9.3 - Stable || Xeon E3 1230v2 || Supermicro X9SCM-F || 32GB Crucial ECC DDR3 || 3x4TB WD Red (JBOD) || SYBA SI-PEX40064 sata controller || Corsair CX500m || NZXT Source 210.

Link to comment
https://linustechtips.com/topic/763450-hacking-a-netgear-router/#findComment-9646323
Share on other sites

Link to post
Share on other sites

1 minute ago, djdwosk97 said:

I did that and it says it couldn't get a response. (I'm not on that network, since I'm trying to break into it)

Ah, you'll need the target network to have a guest network on. 

You need to make a post request with body = x-www-form-urlencoded and the key submit_flag=reboot&yes=Yes

 

 

idk

Link to comment
https://linustechtips.com/topic/763450-hacking-a-netgear-router/#findComment-9646328
Share on other sites

Link to post
Share on other sites

1 minute ago, Droidbot said:

Ah, you'll need the target network to have a guest network on. 

You need to make a post request with body = x-www-form-urlencoded and the key submit_flag=reboot&yes=Yes

 

 

I'm trying to hack the router with everything at its default settings, so I can't use a guest network. 

PSU Tier List | CoC

Gaming Build | FreeNAS Server

Spoiler

i5-4690k || Seidon 240m || GTX780 ACX || MSI Z97s SLI Plus || 8GB 2400mhz || 250GB 840 Evo || 1TB WD Blue || H440 (Black/Blue) || Windows 10 Pro || Dell P2414H & BenQ XL2411Z || Ducky Shine Mini || Logitech G502 Proteus Core

Spoiler

FreeNAS 9.3 - Stable || Xeon E3 1230v2 || Supermicro X9SCM-F || 32GB Crucial ECC DDR3 || 3x4TB WD Red (JBOD) || SYBA SI-PEX40064 sata controller || Corsair CX500m || NZXT Source 210.

Link to comment
https://linustechtips.com/topic/763450-hacking-a-netgear-router/#findComment-9646334
Share on other sites

Link to post
Share on other sites

2 minutes ago, djdwosk97 said:

I'm trying to hack the router with everything at its default settings, so I can't use a guest network. 

Ergh, that's a tough one. Maybe run ophcrack and connect and disconnect some devices from the router to get the WiFi password?

idk

Link to comment
https://linustechtips.com/topic/763450-hacking-a-netgear-router/#findComment-9646347
Share on other sites

Link to post
Share on other sites

4 minutes ago, Droidbot said:

Ergh, that's a tough one. Maybe run ophcrack and connect and disconnect some devices from the router to get the WiFi password?

I was really hoping to focus on WPS PIN cracking for gaining the password (rebooting the router is just to bypass the 3 pin attempt limit).

PSU Tier List | CoC

Gaming Build | FreeNAS Server

Spoiler

i5-4690k || Seidon 240m || GTX780 ACX || MSI Z97s SLI Plus || 8GB 2400mhz || 250GB 840 Evo || 1TB WD Blue || H440 (Black/Blue) || Windows 10 Pro || Dell P2414H & BenQ XL2411Z || Ducky Shine Mini || Logitech G502 Proteus Core

Spoiler

FreeNAS 9.3 - Stable || Xeon E3 1230v2 || Supermicro X9SCM-F || 32GB Crucial ECC DDR3 || 3x4TB WD Red (JBOD) || SYBA SI-PEX40064 sata controller || Corsair CX500m || NZXT Source 210.

Link to comment
https://linustechtips.com/topic/763450-hacking-a-netgear-router/#findComment-9646359
Share on other sites

Link to post
Share on other sites

17 minutes ago, Droidbot said:

Ah, you'll need the target network to have a guest network on. 

You need to make a post request with body = x-www-form-urlencoded and the key submit_flag=reboot&yes=Yes

 

 

Also, I did that from on the network and it says I couldn't get a response. 

Doing a GET request from 192.168.1.1/BRS_netgear_success.html worked though for getting the serial number. 

PSU Tier List | CoC

Gaming Build | FreeNAS Server

Spoiler

i5-4690k || Seidon 240m || GTX780 ACX || MSI Z97s SLI Plus || 8GB 2400mhz || 250GB 840 Evo || 1TB WD Blue || H440 (Black/Blue) || Windows 10 Pro || Dell P2414H & BenQ XL2411Z || Ducky Shine Mini || Logitech G502 Proteus Core

Spoiler

FreeNAS 9.3 - Stable || Xeon E3 1230v2 || Supermicro X9SCM-F || 32GB Crucial ECC DDR3 || 3x4TB WD Red (JBOD) || SYBA SI-PEX40064 sata controller || Corsair CX500m || NZXT Source 210.

Link to comment
https://linustechtips.com/topic/763450-hacking-a-netgear-router/#findComment-9646381
Share on other sites

Link to post
Share on other sites

bump @Droidbot

 

Any ideas?

PSU Tier List | CoC

Gaming Build | FreeNAS Server

Spoiler

i5-4690k || Seidon 240m || GTX780 ACX || MSI Z97s SLI Plus || 8GB 2400mhz || 250GB 840 Evo || 1TB WD Blue || H440 (Black/Blue) || Windows 10 Pro || Dell P2414H & BenQ XL2411Z || Ducky Shine Mini || Logitech G502 Proteus Core

Spoiler

FreeNAS 9.3 - Stable || Xeon E3 1230v2 || Supermicro X9SCM-F || 32GB Crucial ECC DDR3 || 3x4TB WD Red (JBOD) || SYBA SI-PEX40064 sata controller || Corsair CX500m || NZXT Source 210.

Link to comment
https://linustechtips.com/topic/763450-hacking-a-netgear-router/#findComment-9646715
Share on other sites

Link to post
Share on other sites

1 minute ago, Droidbot said:

no ideas, never really done something like this before

 

you could ask the exploit maker and see if he can help you

I know he included his email in the page, but I don't know if I want to bother him. 

PSU Tier List | CoC

Gaming Build | FreeNAS Server

Spoiler

i5-4690k || Seidon 240m || GTX780 ACX || MSI Z97s SLI Plus || 8GB 2400mhz || 250GB 840 Evo || 1TB WD Blue || H440 (Black/Blue) || Windows 10 Pro || Dell P2414H & BenQ XL2411Z || Ducky Shine Mini || Logitech G502 Proteus Core

Spoiler

FreeNAS 9.3 - Stable || Xeon E3 1230v2 || Supermicro X9SCM-F || 32GB Crucial ECC DDR3 || 3x4TB WD Red (JBOD) || SYBA SI-PEX40064 sata controller || Corsair CX500m || NZXT Source 210.

Link to comment
https://linustechtips.com/topic/763450-hacking-a-netgear-router/#findComment-9646742
Share on other sites

Link to post
Share on other sites

So you're trying to guess a WiFi password? What kind of security standard is it using? If its WPS then you could break it in seconds. WPA/WPA-2 is a little different.

I work as a contractor for everything from photo/video to broadcast and networking. 

I use an old HP Laptop forked up on top of a photography textbook. 

Right now this is what I use: Fuji X100T, Fuji X100, Fuji X-E1, XF 18 f2, XF 35 1.4, Nikon d7000, Nikkor 180 2,8 AFIS, Nikkor 60 1.8.

I've got more crap laying around for other jobs and hobbies, though a lot of that isn't applicable to the interests of this forum, so I'll keep myself back from adding it all to the list. 

 

 

Link to comment
https://linustechtips.com/topic/763450-hacking-a-netgear-router/#findComment-9646893
Share on other sites

Link to post
Share on other sites

7 minutes ago, JohnBRoark said:

So you're trying to guess a WiFi password? What kind of security standard is it using? If its WPS then you could break it in seconds. WPA/WPA-2 is a little different.

I'm trying to crack WPA2 through the WPS exploit, however the router I'm doing testing on disables WPS after three failed attempts and reenables it after the router restarts. So, I just need to find a way to force the router to restart. 

PSU Tier List | CoC

Gaming Build | FreeNAS Server

Spoiler

i5-4690k || Seidon 240m || GTX780 ACX || MSI Z97s SLI Plus || 8GB 2400mhz || 250GB 840 Evo || 1TB WD Blue || H440 (Black/Blue) || Windows 10 Pro || Dell P2414H & BenQ XL2411Z || Ducky Shine Mini || Logitech G502 Proteus Core

Spoiler

FreeNAS 9.3 - Stable || Xeon E3 1230v2 || Supermicro X9SCM-F || 32GB Crucial ECC DDR3 || 3x4TB WD Red (JBOD) || SYBA SI-PEX40064 sata controller || Corsair CX500m || NZXT Source 210.

Link to comment
https://linustechtips.com/topic/763450-hacking-a-netgear-router/#findComment-9646922
Share on other sites

Link to post
Share on other sites

Now from what I understand WPA2 is still vulnerable. If you capture the four way handshake when someone connects to the network wireless, you can crack the hashes and get the password (just hoping it isn't too complicated). 

 

From what I remember, aircrack-ng can do this just as long as you have a machine with wireless capabilities. It has to be set to the broadcast id of your target router, and with the right commands it can be set to find a host once someone logs into the network wireless. At this point, it'll grab hashes from the handshake. Though, I really am not very keen on wireless networking, so I can't tell you for sure how this works or why (just has to do with WPA2 encrypted handshakes), but I do know from my testing that it doesn't seem to work as well on WPA2-PSK and Business wireless. My own netgear consumer router is susceptible to getting its wireless pass cracked if using WPA2 standards though. 

I work as a contractor for everything from photo/video to broadcast and networking. 

I use an old HP Laptop forked up on top of a photography textbook. 

Right now this is what I use: Fuji X100T, Fuji X100, Fuji X-E1, XF 18 f2, XF 35 1.4, Nikon d7000, Nikkor 180 2,8 AFIS, Nikkor 60 1.8.

I've got more crap laying around for other jobs and hobbies, though a lot of that isn't applicable to the interests of this forum, so I'll keep myself back from adding it all to the list. 

 

 

Link to comment
https://linustechtips.com/topic/763450-hacking-a-netgear-router/#findComment-9646946
Share on other sites

Link to post
Share on other sites

1 hour ago, JohnBRoark said:

(just hoping it isn't too complicated). 

That's the reason I was focusing on exploiting WPS, I figured it would be easier to force the router to restart than it would be to try and crack something complicated. 

PSU Tier List | CoC

Gaming Build | FreeNAS Server

Spoiler

i5-4690k || Seidon 240m || GTX780 ACX || MSI Z97s SLI Plus || 8GB 2400mhz || 250GB 840 Evo || 1TB WD Blue || H440 (Black/Blue) || Windows 10 Pro || Dell P2414H & BenQ XL2411Z || Ducky Shine Mini || Logitech G502 Proteus Core

Spoiler

FreeNAS 9.3 - Stable || Xeon E3 1230v2 || Supermicro X9SCM-F || 32GB Crucial ECC DDR3 || 3x4TB WD Red (JBOD) || SYBA SI-PEX40064 sata controller || Corsair CX500m || NZXT Source 210.

Link to comment
https://linustechtips.com/topic/763450-hacking-a-netgear-router/#findComment-9647108
Share on other sites

Link to post
Share on other sites

Well, WPS is unbelievably breakable. There are dozens of guides out there on how to break WPS security, and from what I know it isn't done through making the router restart at all. Its just a super outdated protocol. 

I work as a contractor for everything from photo/video to broadcast and networking. 

I use an old HP Laptop forked up on top of a photography textbook. 

Right now this is what I use: Fuji X100T, Fuji X100, Fuji X-E1, XF 18 f2, XF 35 1.4, Nikon d7000, Nikkor 180 2,8 AFIS, Nikkor 60 1.8.

I've got more crap laying around for other jobs and hobbies, though a lot of that isn't applicable to the interests of this forum, so I'll keep myself back from adding it all to the list. 

 

 

Link to comment
https://linustechtips.com/topic/763450-hacking-a-netgear-router/#findComment-9647295
Share on other sites

Link to post
Share on other sites

6 hours ago, JohnBRoark said:

Well, WPS is unbelievably breakable. There are dozens of guides out there on how to break WPS security, and from what I know it isn't done through making the router restart at all. Its just a super outdated protocol. 

:

9 hours ago, djdwosk97 said:

I'm trying to crack WPA2 through the WPS exploit, however the router I'm doing testing on disables WPS after three failed attempts and reenables it after the router restarts. So, I just need to find a way to force the router to restart. 

 

4 hours ago, .spider. said:

I guess it takes several seconds to reboot the router so it would take ages to run the WPS attack.

It actually isn't that long. It would theoretically take about 60 hours to break if the router had to be restarted after every three attempts.

PSU Tier List | CoC

Gaming Build | FreeNAS Server

Spoiler

i5-4690k || Seidon 240m || GTX780 ACX || MSI Z97s SLI Plus || 8GB 2400mhz || 250GB 840 Evo || 1TB WD Blue || H440 (Black/Blue) || Windows 10 Pro || Dell P2414H & BenQ XL2411Z || Ducky Shine Mini || Logitech G502 Proteus Core

Spoiler

FreeNAS 9.3 - Stable || Xeon E3 1230v2 || Supermicro X9SCM-F || 32GB Crucial ECC DDR3 || 3x4TB WD Red (JBOD) || SYBA SI-PEX40064 sata controller || Corsair CX500m || NZXT Source 210.

Link to comment
https://linustechtips.com/topic/763450-hacking-a-netgear-router/#findComment-9648204
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×