diff --git a/README.md b/README.md index 229fe0c..c0a7a2f 100644 --- a/README.md +++ b/README.md @@ -1,171 +1,172 @@ -#################################################################################### Contenuto archivio - -Nell'archivio troverete i seguenti file - - Leggimi.txt - Questo file - - zyxel-qemu.bat - batch esecuzione QEMU - qemu - file configurazione QEMU - rootfs.ext2 - contiene il filesystem del router - zImage - kernel di Linux - vexpress-v2p-ca9.dtb - serve nell'architettura ARM e Linux. - - genpass - script Linux per la gestione dei parametri - -Nota: il file 'genpass' non serve come file ma è stato inserito solo come studio dello script Linux - -L'uso dell'emulatore richiede obbligatoriamente l'installazione di QEMU. - - -#################################################################################### Installazione QEMU in Windows - -Scaricate la versione più recente dal sito - -https://qemu.weilnetz.de/w32/ - Applicazione per Windows a 32bit (funziona anche su Windows a 64bit) -https://qemu.weilnetz.de/w64/ - Applicazione per Windows a 64bit - -Installate l'applicazione. - - -- Installazione QEMU in Linux (Ubuntu/Debian) - -sudo apt-get install qemu-system-arm - - -#################################################################################### Uso emulatore Zyxel - -Scaricate l'archivio dell'emulatore. - -Decomprimete l'archivio in una cartella. - -In Windows lanciate il batch 'zyxel-qemu.bat' - - -#################################################################################### Info pacchetto emulatore - -Nelle cartelle - - /opt/zyxel - -ci sono le librerie estratte dal firmware distribuito dalla Zyxel - - /opt/genpass/ - -c'è la libreria libhook.so che serve per sopperire alla mancanza della flash del router in modo che il seriale invece che leggerlo sulla flash lo legge da una variabile d'ambiente - -Il file - - getpassword - -è il binario che chiama le funzioni dentro le librerie della Zyxel per fargli calcolare la password ed una volta prese le stampa a schermo. -Mentre lo script - - genpass - -è quello che mette insieme il tutto. - - -#################################################################################### Modifiche al file rootfs.ext - -Per montare il file immagine rootfs.exet2 in modifica serve un Linux e le utility relative alla gestione ext2/ext3. - -I comandi da dare sono - -- Creazione cartella espansione file contenuti in rootfs.ext - - sudo mkdir /mnt/rootfs - -- Montaggio file system rootfs.ext - - sudo mount -t ext2 root.ext2 /mnt/rootfs - -il file 'genpass' è nel percorso '/mnt/rootfs/opt/genpass/' - -Si fanno le modifiche del caso es. copia nuovo file genpass) - -Finite le modifiche si salva il nuovo file rootfs.ext dando il comando - - sudo umount /mnt/rootfs - -e si possono rimuovere i file in /mnt/rootfs - - sudo rm -rf /mnt/rootfs - - -#################################################################################### Info sul numero seriale - -Il seriale del modem è composto - - da una prima lettera S - - da un seconda parte costituita da tre cifre - - da una terza parte rappresentata da una lettera maiuscola - - da una quarta parte numerica di 8 cifre - - -#################################################################################### Uso emulatore Zyxel - -Una volta che il sistema è avviato vi troverete davanti la classica console Unix/Linux. - -root@VMG8825-B50B-emul login: - -Potete entrare inserendo - - user = root - password = root - -Volendo potete usare anche l'accesso via SSH sulla porta 2222. -In pratica qemu-system-arm (lanciato tramite il batch) si mette in ascolto sulla porta 2222 e ridirige la connessione sulla porta 22 del router emulato. - -Una volta avuto accesso senza dover cambiare cartella basta dare il comando - - genpass SerialeModem - -dove - - SerialeModem è il seriale del modem (es. S182V12345678) - - -La risposta al comando genpass sarà del tipo - - Old algorithm supervisor password: cdef644b - New algorithm supervisor password: 7QrscaaYya - - Old algorithm admin password param 1: WJNCRMTT - Old algorithm admin password param 2: K9KydTzT - Old algorithm admin password param 3: S9KcdTeT - - New algorithm admin password param 1: WJNCRMTT - New algorithm admin password param 2: K9KydTzT - - New algorithm admin wind password param 2: K9KydTzT73 - New algorithm admin wind password param 1: WJNCRMTTQ3 - - Old algorithm admin wind password param 2: K9KydTzT73 - Old algorithm admin wind password param 1: WJNCRMTTQ3 - Old algorithm admin wind password param 3: - - Wifi password param 2 e 1: MPPGPCJ444MXGU34 - Wifi password param 0: C9D4CB2BADE5618AD92BEC2AC7 - Wifi password param 1: CFC9887CA2 - Wifi password param 2 e 0: SPP6WCJ444SX6U34 - Wifi password param 2 e 2: 8PPXWCJ4448XXU34 - Wifi password param 2 e 3: apprwcjpppaxrunp - Wifi password param 2 e 4: SPP6WCJ444SX6U34 - Wifi password param 2 e 5: hPPNWCJ444hXNU34 - - -#################################################################################### Uscita dall'emulazione - -Una volta effettuato il login per uscire digitare - -root@VMG8825-B50B-emul:~# exit - -quando appare - -VMG8825-B50B-emul login: - -chiudere la finestra DOS aperta - +# Archive Contents + +The archive contains the following files: + +- `README.md` - This file +- `zyxel-qemu.bat` - QEMU execution batch file +- `qemu` - QEMU configuration file +- `rootfs.ext2` - Contains the router's filesystem +- `zImage` - Linux kernel +- `vexpress-v2p-ca9.dtb` - Required for ARM architecture and Linux +- `genpass` - Linux script for parameter management + +> **Note:** The `genpass` file is not meant to be used as a file but was included only for studying the Linux script. + +Using the emulator requires QEMU to be installed. + +--- + +# Installing QEMU + +## On Windows + +Download the latest version from: + +- [32-bit version](https://qemu.weilnetz.de/w32/) – Works on 64-bit Windows as well +- [64-bit version](https://qemu.weilnetz.de/w64/) + +Then install the application. + +## On Linux (Ubuntu/Debian) + +Run the following command: + +```bash +sudo apt-get install qemu-system-arm +``` + +--- + +# Using the Zyxel Emulator + +1. Download the emulator archive. +2. Extract the archive into a folder. +3. On Windows, run the batch file `zyxel-qemu.bat`. + +--- + +# Emulator Package Information + +- **`/opt/zyxel`** – Contains libraries extracted from the firmware distributed by Zyxel. +- **`/opt/genpass/`** – Contains the `libhook.so` library, which compensates for the lack of router flash memory. It allows the serial number to be read from an environment variable instead of from flash. + +- **`getpassword`** – A binary that calls functions inside Zyxel's libraries to calculate the password and prints it to the screen. +- **`genpass`** – A script that ties everything together. + +--- + +# Modifying the `rootfs.ext2` File + +To mount and modify the `rootfs.ext2` image file, you need a Linux system with ext2/ext3 utilities. + +## Steps + +1. **Create a mount point:** + ```bash + sudo mkdir /mnt/rootfs + ``` + +2. **Mount the filesystem:** + ```bash + sudo mount -t ext2 rootfs.ext2 /mnt/rootfs + ``` + The `genpass` file is located at `/mnt/rootfs/opt/genpass/`. + +3. **Make your changes** (e.g., copy a new `genpass` file). + +4. **Unmount the filesystem:** + ```bash + sudo umount /mnt/rootfs + ``` + +5. **Remove the mount point (optional):** + ```bash + sudo rm -rf /mnt/rootfs + ``` + +--- + +# Serial Number Format + +The modem's serial number consists of: + +| Part | Description | Example | +|------|------------------------------------|---------| +| 1 | Letter `S` | `S` | +| 2 | Three digits | `182` | +| 3 | One uppercase letter | `V` | +| 4 | Eight digits | `12345678` | + +**Full example:** `S182V12345678` + +--- + +# Using the Zyxel Emulator + +Once the system has booted, you will see the classic Unix/Linux console: + +``` +root@VMG8825-B50B-emul login: +``` + +## Login credentials + +- **Username:** `root` +- **Password:** `root` + +> You can also use SSH access on port `2222`. QEMU (launched via the batch file) listens on port 2222 and forwards connections to port 22 of the emulated router. + +## Generating passwords + +After logging in, run the following command from any directory: + +```bash +genpass +``` + +Replace `` with the modem's serial number (e.g., `S182V12345678`). + +### Example output + +``` +Old algorithm supervisor password: cdef644b +New algorithm supervisor password: 7QrscaaYya + +Old algorithm admin password param 1: WJNCRMTT +Old algorithm admin password param 2: K9KydTzT +Old algorithm admin password param 3: S9KcdTeT + +New algorithm admin password param 1: WJNCRMTT +New algorithm admin password param 2: K9KydTzT + +New algorithm admin wind password param 2: K9KydTzT73 +New algorithm admin wind password param 1: WJNCRMTTQ3 + +Old algorithm admin wind password param 2: K9KydTzT73 +Old algorithm admin wind password param 1: WJNCRMTTQ3 +Old algorithm admin wind password param 3: + +Wifi password param 2 e 1: MPPGPCJ444MXGU34 +Wifi password param 0: C9D4CB2BADE5618AD92BEC2AC7 +Wifi password param 1: CFC9887CA2 +Wifi password param 2 e 0: SPP6WCJ444SX6U34 +Wifi password param 2 e 2: 8PPXWCJ4448XXU34 +Wifi password param 2 e 3: apprwcjpppaxrunp +Wifi password param 2 e 4: SPP6WCJ444SX6U34 +Wifi password param 2 e 5: hPPNWCJ444hXNU34 +``` + +--- + +# Exiting the Emulator + +1. After logging in, type: + ```bash + exit + ``` + +2. When the login prompt appears again: + ``` + VMG8825-B50B-emul login: + ``` + close the DOS window.