4 ms·
Semi-related: once some hardware arrives, I should be able to finish finding a way to rip the 802.1x certs off of the 5286AC so we can use our own routers, or a
by DominoTree 9y ago
Semi-related: once some hardware arrives, I should be able to finish finding a way to rip the 802.1x certs off of the 5286AC so we can use our own routers, or at least put these things into a proper bridged mode.
https://spun.io/2018/03/18/getting-into-the-pace-5268ac-router-part-1/ https://spun.io/2018/03/18/getting-into-the-pace-5268ac-rout...
- jmuguy 9y agoI'm sure you're pretty far down the rabbit hole of dealing with the 5268AC but the "DMZ Plus" mode does seem to bridge. I have a Ubiquiti Edgerouter on the other side with OpenVPN setup, public IP, etc. All I needed to do was enable DMZ Plus and turn off wifi.
- phil21 9y agoDMZ Plus doesn't bridge - it just fakes it by essentially 1:1 NAT'ing a public IP to your router. You are still using it's internal routing and NAT tables, which to be charitable are problematic. You also lose the ability to do ipv6 - not that AT&T's ipv6 implementation is worth even using at this point. I just moved from Comcast to AT&T gige and the speeds are certainly great - but this CPE (and horrible v6 even if it worked) is seriously making me reconsider.
- jmuguy 9y agoAh, that is a bummer. I certainly miss the days of just buying my own dumb cable modem and never thinking about it again.
- ryan-c 9y agoYou can bypass these routers with an 801.1x MitM attack. You basically put it behind your Linux router and bridge only the EAPoL frames, then do DHCP from your own router. I posted some details about this on DSLReports[1]. I have been using this method with AT&T GigaPower fiber in Austin, TX for two years and it's been totally stable and free of problems. That said, I'd love to be able to extract the cert and not have to do this. 1. https://www.dslreports.com/forum/r30708210-AT-T-Residential-Gateway-Bypass-True-bridge-mode https://www.dslreports.com/forum/r30708210-AT-T-Residential-...
- js2 9y agoShameless plug: https://github.com/jaysoffian/eap_proxy https://github.com/jaysoffian/eap_proxy (And thanks for discovering that bypass!)
- rhexs 9y agoPlease fully disclose your work! I was looking into this earlier and found the other post you mentioned. Unfortunately, they stopped following up with RE details on the 5286AC after they got a bunch of CVEs assigned. Was really disappointing. Either way, thank you! Would you be willing to send me the URL for the firmware? I don't have time to desolder anything at the moment but would love to look at the image.
- DominoTree 8y agoUpdate: private keys acquired. Need to figure out the password for these now. https://twitter.com/DominoTree/status/984272671549677568 https://twitter.com/DominoTree/status/984272671549677568 Here are links to current firmware images: http://gateway.c01.sbcglobal.net/firmware/00D09E/10.6.0.530094-PROD/5268.install.pkgstream http://gateway.c01.sbcglobal.net/firmware/00D09E/10.6.0.5300... http://gateway.c01.sbcglobal.net/firmware/00D09E/10.6.0.530094-PROD/att_config.pkgstream http://gateway.c01.sbcglobal.net/firmware/00D09E/10.6.0.5300... http://gateway.c01.sbcglobal.net/firmware/00D09E/10.6.0.530094-PROD/att_eapol-certs.pkgstream http://gateway.c01.sbcglobal.net/firmware/00D09E/10.6.0.5300... http://gateway.c01.sbcglobal.net/firmware/00D09E/10.6.0.530094-PROD/att_cms-certs.pkgstream http://gateway.c01.sbcglobal.net/firmware/00D09E/10.6.0.5300...
- DominoTree 8y agoFound the library being used to generate the passcodes for the PKCS 12 stores. We're almost there! https://pbs.twimg.com/media/DamdwvVWAAAn8_C.jpg:large https://pbs.twimg.com/media/DamdwvVWAAAn8_C.jpg:large