搬家
住蛇口
富人区边上
12平米的贫民窟里
有一个天翼网关
不让改
SSID
于是就有了此文——GO
提示:毫无技术含量,纯属娱乐
【1】登录网关
密码就在设备底部
【2】尝试修改SSID,报错
其实我挺费解,ChinaNet这样做的价值是什么
【3】抓包
第一眼就看到了%3D%3D,果断urldecode得到:
jsonCfg={"RPCMethod":"Post1", 'ID':'123', "Parameter":'eyJDbWRUeXBlIjoiU0VUX1dJRklfMF9BRFZfSU5GTyIsIlNlcXVlbmNlSWQiOiIxMjM0NTY3OCIsIlN0YXR1cyI6MCwid2xhbkVuYWJsZSI6IjEiLCJzc2lkIjoiQ2hpbmFOZXQtMjhpY2UiLCJzaWduYWxQb3dlciI6MSwiY2hhbm5lbCI6MCwid2xBdXRnTW9kZSI6InBzayBwc2syIiwid2xXcGFQc2siOiJsb3ZlQDIwMTUiLCJ3bFdwYUdUS1Jla2V5IjozMCwid2xXcGEiOiJ0a2lwK2FlcyIsIndsV2VwIjoiZGlzYWJsZWQiLCJ3bFByZWF1dGgiOjEsIndsS2V5Qml0IjoiMSIsIndsS2V5SW5kZXgiOjEsIndsS2V5MSI6IjA5ODc2NTQzMjEiLCJ3bEtleTIiOiIwOTg3NjU0MzIxIiwid2xLZXkzIjoiMDk4NzY1NDMyMSIsIndsS2V5NCI6IjA5ODc2NTQzMjEifQ=='}
然后把Parameter通过Base64decode解密得到:
{"CmdType":"SET_WIFI_0_ADV_INFO","SequenceId":"12345678","Status":0,"wlanEnable":"1","ssid":"ChinaNet-28ice","signalPower":1,"channel":0,"wlAuthMode":"psk psk2","wlWpaPsk":"love@123!","wlWpaGTKRekey":30,"wlWpa":"tkip+aes","wlWep":"disabled","wlPreauth":1,"wlKeyBit":"1","wlKeyIndex":1,"wlKey1":"0987654321","wlKey2":"0987654321","wlKey3":"0987654321","wlKey4":"0987654321"}
【4】改包
把数据包中的ChinaNet-28ice改为想要的SSID,比如Pig,然后base64+urlencode原路返回,提交,结果如图:
看到一排一排的ChinaNet-*,本强迫症还是蛮开心的
EOF
by 28ice