Translate to English
This commit is contained in:
@@ -1,171 +1,172 @@
|
||||
#################################################################################### Contenuto archivio
|
||||
|
||||
Nell'archivio troverete i seguenti file
|
||||
|
||||
Leggimi.txt - Questo file
|
||||
|
||||
zyxel-qemu.bat - batch esecuzione QEMU
|
||||
qemu - file configurazione QEMU
|
||||
rootfs.ext2 - contiene il filesystem del router
|
||||
zImage - kernel di Linux
|
||||
vexpress-v2p-ca9.dtb - serve nell'architettura ARM e Linux.
|
||||
|
||||
genpass - script Linux per la gestione dei parametri
|
||||
|
||||
Nota: il file 'genpass' non serve come file ma è stato inserito solo come studio dello script Linux
|
||||
|
||||
L'uso dell'emulatore richiede obbligatoriamente l'installazione di QEMU.
|
||||
|
||||
|
||||
#################################################################################### Installazione QEMU in Windows
|
||||
|
||||
Scaricate la versione più recente dal sito
|
||||
|
||||
https://qemu.weilnetz.de/w32/ - Applicazione per Windows a 32bit (funziona anche su Windows a 64bit)
|
||||
https://qemu.weilnetz.de/w64/ - Applicazione per Windows a 64bit
|
||||
|
||||
Installate l'applicazione.
|
||||
|
||||
|
||||
- Installazione QEMU in Linux (Ubuntu/Debian)
|
||||
|
||||
sudo apt-get install qemu-system-arm
|
||||
|
||||
|
||||
#################################################################################### Uso emulatore Zyxel
|
||||
|
||||
Scaricate l'archivio dell'emulatore.
|
||||
|
||||
Decomprimete l'archivio in una cartella.
|
||||
|
||||
In Windows lanciate il batch 'zyxel-qemu.bat'
|
||||
|
||||
|
||||
#################################################################################### Info pacchetto emulatore
|
||||
|
||||
Nelle cartelle
|
||||
|
||||
/opt/zyxel
|
||||
|
||||
ci sono le librerie estratte dal firmware distribuito dalla Zyxel
|
||||
|
||||
/opt/genpass/
|
||||
|
||||
c'è la libreria libhook.so che serve per sopperire alla mancanza della flash del router in modo che il seriale invece che leggerlo sulla flash lo legge da una variabile d'ambiente
|
||||
|
||||
Il file
|
||||
|
||||
getpassword
|
||||
|
||||
è il binario che chiama le funzioni dentro le librerie della Zyxel per fargli calcolare la password ed una volta prese le stampa a schermo.
|
||||
Mentre lo script
|
||||
|
||||
genpass
|
||||
|
||||
è quello che mette insieme il tutto.
|
||||
|
||||
|
||||
#################################################################################### Modifiche al file rootfs.ext
|
||||
|
||||
Per montare il file immagine rootfs.exet2 in modifica serve un Linux e le utility relative alla gestione ext2/ext3.
|
||||
|
||||
I comandi da dare sono
|
||||
|
||||
- Creazione cartella espansione file contenuti in rootfs.ext
|
||||
|
||||
sudo mkdir /mnt/rootfs
|
||||
|
||||
- Montaggio file system rootfs.ext
|
||||
|
||||
sudo mount -t ext2 root.ext2 /mnt/rootfs
|
||||
|
||||
il file 'genpass' è nel percorso '/mnt/rootfs/opt/genpass/'
|
||||
|
||||
Si fanno le modifiche del caso es. copia nuovo file genpass)
|
||||
|
||||
Finite le modifiche si salva il nuovo file rootfs.ext dando il comando
|
||||
|
||||
sudo umount /mnt/rootfs
|
||||
|
||||
e si possono rimuovere i file in /mnt/rootfs
|
||||
|
||||
sudo rm -rf /mnt/rootfs
|
||||
|
||||
|
||||
#################################################################################### Info sul numero seriale
|
||||
|
||||
Il seriale del modem è composto
|
||||
|
||||
da una prima lettera S
|
||||
|
||||
da un seconda parte costituita da tre cifre
|
||||
|
||||
da una terza parte rappresentata da una lettera maiuscola
|
||||
|
||||
da una quarta parte numerica di 8 cifre
|
||||
|
||||
|
||||
#################################################################################### Uso emulatore Zyxel
|
||||
|
||||
Una volta che il sistema è avviato vi troverete davanti la classica console Unix/Linux.
|
||||
|
||||
root@VMG8825-B50B-emul login:
|
||||
|
||||
Potete entrare inserendo
|
||||
|
||||
user = root
|
||||
password = root
|
||||
|
||||
Volendo potete usare anche l'accesso via SSH sulla porta 2222.
|
||||
In pratica qemu-system-arm (lanciato tramite il batch) si mette in ascolto sulla porta 2222 e ridirige la connessione sulla porta 22 del router emulato.
|
||||
|
||||
Una volta avuto accesso senza dover cambiare cartella basta dare il comando
|
||||
|
||||
genpass SerialeModem
|
||||
|
||||
dove
|
||||
|
||||
SerialeModem è il seriale del modem (es. S182V12345678)
|
||||
|
||||
|
||||
La risposta al comando genpass sarà del tipo
|
||||
|
||||
Old algorithm supervisor password: cdef644b
|
||||
New algorithm supervisor password: 7QrscaaYya
|
||||
|
||||
Old algorithm admin password param 1: WJNCRMTT
|
||||
Old algorithm admin password param 2: K9KydTzT
|
||||
Old algorithm admin password param 3: S9KcdTeT
|
||||
|
||||
New algorithm admin password param 1: WJNCRMTT
|
||||
New algorithm admin password param 2: K9KydTzT
|
||||
|
||||
New algorithm admin wind password param 2: K9KydTzT73
|
||||
New algorithm admin wind password param 1: WJNCRMTTQ3
|
||||
|
||||
Old algorithm admin wind password param 2: K9KydTzT73
|
||||
Old algorithm admin wind password param 1: WJNCRMTTQ3
|
||||
Old algorithm admin wind password param 3:
|
||||
|
||||
Wifi password param 2 e 1: MPPGPCJ444MXGU34
|
||||
Wifi password param 0: C9D4CB2BADE5618AD92BEC2AC7
|
||||
Wifi password param 1: CFC9887CA2
|
||||
Wifi password param 2 e 0: SPP6WCJ444SX6U34
|
||||
Wifi password param 2 e 2: 8PPXWCJ4448XXU34
|
||||
Wifi password param 2 e 3: apprwcjpppaxrunp
|
||||
Wifi password param 2 e 4: SPP6WCJ444SX6U34
|
||||
Wifi password param 2 e 5: hPPNWCJ444hXNU34
|
||||
|
||||
|
||||
#################################################################################### Uscita dall'emulazione
|
||||
|
||||
Una volta effettuato il login per uscire digitare
|
||||
|
||||
root@VMG8825-B50B-emul:~# exit
|
||||
|
||||
quando appare
|
||||
|
||||
VMG8825-B50B-emul login:
|
||||
|
||||
chiudere la finestra DOS aperta
|
||||
|
||||
# Archive Contents
|
||||
|
||||
The archive contains the following files:
|
||||
|
||||
- `README.md` - This file
|
||||
- `zyxel-qemu.bat` - QEMU execution batch file
|
||||
- `qemu` - QEMU configuration file
|
||||
- `rootfs.ext2` - Contains the router's filesystem
|
||||
- `zImage` - Linux kernel
|
||||
- `vexpress-v2p-ca9.dtb` - Required for ARM architecture and Linux
|
||||
- `genpass` - Linux script for parameter management
|
||||
|
||||
> **Note:** The `genpass` file is not meant to be used as a file but was included only for studying the Linux script.
|
||||
|
||||
Using the emulator requires QEMU to be installed.
|
||||
|
||||
---
|
||||
|
||||
# Installing QEMU
|
||||
|
||||
## On Windows
|
||||
|
||||
Download the latest version from:
|
||||
|
||||
- [32-bit version](https://qemu.weilnetz.de/w32/) – Works on 64-bit Windows as well
|
||||
- [64-bit version](https://qemu.weilnetz.de/w64/)
|
||||
|
||||
Then install the application.
|
||||
|
||||
## On Linux (Ubuntu/Debian)
|
||||
|
||||
Run the following command:
|
||||
|
||||
```bash
|
||||
sudo apt-get install qemu-system-arm
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
# Using the Zyxel Emulator
|
||||
|
||||
1. Download the emulator archive.
|
||||
2. Extract the archive into a folder.
|
||||
3. On Windows, run the batch file `zyxel-qemu.bat`.
|
||||
|
||||
---
|
||||
|
||||
# Emulator Package Information
|
||||
|
||||
- **`/opt/zyxel`** – Contains libraries extracted from the firmware distributed by Zyxel.
|
||||
- **`/opt/genpass/`** – Contains the `libhook.so` library, which compensates for the lack of router flash memory. It allows the serial number to be read from an environment variable instead of from flash.
|
||||
|
||||
- **`getpassword`** – A binary that calls functions inside Zyxel's libraries to calculate the password and prints it to the screen.
|
||||
- **`genpass`** – A script that ties everything together.
|
||||
|
||||
---
|
||||
|
||||
# Modifying the `rootfs.ext2` File
|
||||
|
||||
To mount and modify the `rootfs.ext2` image file, you need a Linux system with ext2/ext3 utilities.
|
||||
|
||||
## Steps
|
||||
|
||||
1. **Create a mount point:**
|
||||
```bash
|
||||
sudo mkdir /mnt/rootfs
|
||||
```
|
||||
|
||||
2. **Mount the filesystem:**
|
||||
```bash
|
||||
sudo mount -t ext2 rootfs.ext2 /mnt/rootfs
|
||||
```
|
||||
The `genpass` file is located at `/mnt/rootfs/opt/genpass/`.
|
||||
|
||||
3. **Make your changes** (e.g., copy a new `genpass` file).
|
||||
|
||||
4. **Unmount the filesystem:**
|
||||
```bash
|
||||
sudo umount /mnt/rootfs
|
||||
```
|
||||
|
||||
5. **Remove the mount point (optional):**
|
||||
```bash
|
||||
sudo rm -rf /mnt/rootfs
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
# Serial Number Format
|
||||
|
||||
The modem's serial number consists of:
|
||||
|
||||
| Part | Description | Example |
|
||||
|------|------------------------------------|---------|
|
||||
| 1 | Letter `S` | `S` |
|
||||
| 2 | Three digits | `182` |
|
||||
| 3 | One uppercase letter | `V` |
|
||||
| 4 | Eight digits | `12345678` |
|
||||
|
||||
**Full example:** `S182V12345678`
|
||||
|
||||
---
|
||||
|
||||
# Using the Zyxel Emulator
|
||||
|
||||
Once the system has booted, you will see the classic Unix/Linux console:
|
||||
|
||||
```
|
||||
root@VMG8825-B50B-emul login:
|
||||
```
|
||||
|
||||
## Login credentials
|
||||
|
||||
- **Username:** `root`
|
||||
- **Password:** `root`
|
||||
|
||||
> You can also use SSH access on port `2222`. QEMU (launched via the batch file) listens on port 2222 and forwards connections to port 22 of the emulated router.
|
||||
|
||||
## Generating passwords
|
||||
|
||||
After logging in, run the following command from any directory:
|
||||
|
||||
```bash
|
||||
genpass <SerialNumber>
|
||||
```
|
||||
|
||||
Replace `<SerialNumber>` with the modem's serial number (e.g., `S182V12345678`).
|
||||
|
||||
### Example output
|
||||
|
||||
```
|
||||
Old algorithm supervisor password: cdef644b
|
||||
New algorithm supervisor password: 7QrscaaYya
|
||||
|
||||
Old algorithm admin password param 1: WJNCRMTT
|
||||
Old algorithm admin password param 2: K9KydTzT
|
||||
Old algorithm admin password param 3: S9KcdTeT
|
||||
|
||||
New algorithm admin password param 1: WJNCRMTT
|
||||
New algorithm admin password param 2: K9KydTzT
|
||||
|
||||
New algorithm admin wind password param 2: K9KydTzT73
|
||||
New algorithm admin wind password param 1: WJNCRMTTQ3
|
||||
|
||||
Old algorithm admin wind password param 2: K9KydTzT73
|
||||
Old algorithm admin wind password param 1: WJNCRMTTQ3
|
||||
Old algorithm admin wind password param 3:
|
||||
|
||||
Wifi password param 2 e 1: MPPGPCJ444MXGU34
|
||||
Wifi password param 0: C9D4CB2BADE5618AD92BEC2AC7
|
||||
Wifi password param 1: CFC9887CA2
|
||||
Wifi password param 2 e 0: SPP6WCJ444SX6U34
|
||||
Wifi password param 2 e 2: 8PPXWCJ4448XXU34
|
||||
Wifi password param 2 e 3: apprwcjpppaxrunp
|
||||
Wifi password param 2 e 4: SPP6WCJ444SX6U34
|
||||
Wifi password param 2 e 5: hPPNWCJ444hXNU34
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
# Exiting the Emulator
|
||||
|
||||
1. After logging in, type:
|
||||
```bash
|
||||
exit
|
||||
```
|
||||
|
||||
2. When the login prompt appears again:
|
||||
```
|
||||
VMG8825-B50B-emul login:
|
||||
```
|
||||
close the DOS window.
|
||||
|
||||
Reference in New Issue
Block a user