hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

GAN_GR33N
Cayman-DSL



often when i am bored i find alot of entertainment in the old school practice of portsurfing (some of you may be familiar with this term from the GTMHH docs which do kinda suck but when you've read every doc on the net they make for some ok reading) port surfing is the practice of telneting to boxes just to see whats going on there. some of you have probably tried this and been greated with such warnings as " your ip has been logged" or "tresspassers WILL be prosicuted" which most of the time is bull but i like to play on the safe side.

somthing i have come across which some of you may find useful is the Cayman-DSL router. whoever was responsible for the security of this router should be shot but because it makes a fun tool for us we can let them slide.

the Cayman-DSL router is a small dsl modem/router that is meant for the home user but offers WAY too much functionality for the casual user including telnet server and client and about every damn commandline network tool you could ever ask for.

these tools are great for some anonymous goofy off and can be listed by the good old advice from the movie wargames "just type help" and you will be presented with this

Cayman-DSL1743234> help
help to get more: "help all" or "help help"
configure to configure unit's options
netstat to show IP information
ping to send ICMP Echo request
traceroute to send traceroute probes
nslookup to send DNS query for host
atmping to send ATM OAM loopback
arp to send ARP request
diagnose to self-test options
quit to quit this shell
reset to reset subsystems
restart to restart unit
show to show system information
start to start subsystem
status to show basic status of unit
telnet to telnet to a remote host
who to show who is using the shell
log to add a message to the diagnostic log
loglevel to report or change diagnostic log level
install to download and program an image into flash
download to download config file
upload to upload config file
clear to erase all stored configuration information
wireless to Execute wireless TEACH or LEARN


these are the admin level tools, the regular user tools are a little more limited but can still be useful.

now pretty much every big router has these tools but the cool thing about these is that since they are intended for your average internet user they are most of the time unpassworded and even if they are you can access them by typing any one letter at the login prompt and hitting enter twice (could it be any easier"

example:

login: d
Password:

Terminal shell v1.0
Cayman-DSL Model 3220-H, DMT-ADSL (Alcatel) plus 4-port hub
Running GatorSurf version 5.6.1 (build R0)
(d completed login: user level)

Cayman-DSL1663970>


now this is only user mode but it still provides you with plenty of useful tools but when you get real lucky you will be immediatly greated with this


Terminal shell v1.0
Cayman-DSL Model 3220-H, DMT-ADSL (Alcatel) plus 4-port hub
Running GatorSurf version 5.6.1 (build R0)
( completed login: administrator level)



which gives you the works.

the best way to find these is to find ip ranges that provide dsl and just scan port 23. instead of checking the results one by one try using superscan from foundstone and scanning 23 only and you will find admin accounts like freaking crazy.

for the command line challenged these router are also open on port 80 for web based configuration so you can delete log files


well have fun and be safe
GAN_GR33N
toska
sounds interesting...ill check it out. thanx
FiNaLBeTa
Hehe, this seems like a nice toy.
Will use it after my examinations
Meads
Nice discovery im gonna check this rite away see what i can find
dolle
interesting , lets find out some more about this
SteveW
Another fun piece of info - default backdoor u/p to allow the cayman techs access as needed

factory / rkwfbgox
som3aa
seems like fun biggrin.gif
unfourtunly home users only sad.gif
L0rD
yéé it seems to be a fun tools !
I'm going to test it if i can lol

+++ ph34r.gif
globey
nice discover biggrin.gif
can be fun to do

tnx.
justabit
I couldn't make a new topic sad.gif . I am wondering if anyone could help a newbie like me. I've got into weak nt accounts with dameware and wanted to know how to run files on their pc? I've also made a batch file which I want to run on startup as a service (using firedaemon)

Can i open the program interface or do i have to use firedaemon in dos? I'm having no luck.

Also, to this post I did have a cayman scanner but lost it ages back. It used to find loads of pacbell IP's biggrin.gif
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.