Your Ad Here

Sunday, February 1, 2009

How to hack ISP's Server/Router : Tells you where you stand if you are new to the world of hacking......

The most common question every one searches for after watching Hollywood movies like Hackers Triology(1, 2, 3 ), Sneakers, Die Hard-4 and other movies featuring hackers is that How to hack or How to hack an I.S.P/ Router (if you are already into computers and networking).

But for those who want it to be done in the Hollywood way i.e. without any knowledge and just by clicking few keys on you PC this discussion gives the message that what it really takes to be hacker.

So here some guy is asking for the knowledge of how to crack into his ISP so that he can improve his download speed........

Question asked was :
how to hack ISP's Server/Router?? please help me..
Hi guys..My ISP is cheating me.i got a clash wid him.keeping it in mind he is giving me 2-4 kbps download speed for 128 kbps connection..i spent 3500 rs of non refundable amount.please tell me how to hack my ISP's server to increase my speed.i do with my own risk...please help me...!!

Reply 1 : Quite Motivating
Buddy, you need to establish a telnet session with the server which can be done by a simple command in cmd
telnet {It will be most of the time xxx.xxx.xxx.1 or xxx.xxx.xxx.254}

Now,enter password when asked;Many servers have default passwords set up!Now,for the default passwords,you need to check this website,which is:
http://www.routerpasswords.com/
Now,select the company of the router on the website and click on 'find password'.Now,maybe a question arises in your mind that how to know the company of router..right?Its simple! Just use Cain to scan this IP address(of the server),and you will be getting the details of the company of the router!

Now,I have a question! Have you done CCNA? If no,then you will have to know about the commands required for the tweak/hack to be done in the router!The link goes here:
http://www.networktutorials.info/router_commands.html
Now,look into those commands and use them as required by you! The most important tweak will be using the command 'clockrate'
Well..now I have directed you,and hope that you will achieve success!
If,you find any problems,feel free to reply me,I am here to help!
As an ethical hacker,I am not supposed to encourage hacking,but as your ISP is cheating you,I am interested in helping you out!!

P.S : Hacking is an offence, do not hack to cause loss,but try to prevent it!
~~~~~~~~~~~~~~~~~~~
Agent: 1c3c0ld
ethical -4c<3r class="blsp-spelling-error" id="SPELLING_ERROR_17">MAAK®
~~~~~~~~~~~~~~~~~~~

Reply 2: Dis Heartening one but True
Ah .. never knew it was so easy to telnet into an ISPs router. And if you can actually telnet into an ISPs router .. then I must say that they've employed some really unskilled staff.

ISP routers will most probably have AAA servers for auth, their ACLs will allow only specific hosts to telnet into them.

So if AAA is being used (in all likelihood it will be used), you'll not only need a password that you don't know, but you'll also need a username that you wouldn't know.

Lets suppose you get the username that you don't know and somehow get the password that you can't get, now you'll need the host IP of the device that is allowed to use the vty lines of the router.

You might stand the slightest chance to getting into the router, if the host allowed to telnet into the router is a public IP, but if the vty lines are allowed only to certain private IP, then poof .. there goes that chance too .. Coz you can't use a private IP over the internet .. duh .. Ok .. So now you'd have to compromise some host in the ISP to actually access the router .. sigh .. (You can't even spoof a private IP, coz there will be ACLs in place to deny packets that have a Private IP that are trying to get into the router on its external interface)

Most ISPs and other large enterprises use OOB - Out Of Band management ... so even hosts within the organization cannot sniff management traffic either in or outbound from the router ..

Now even if you manage to somehow get into the router that is almost impossible to get into without proper credentials, the devices will have snmp traps and will most definitely have syslog enabled. ... Oh shoot ... Now you'll have to "hack" into the syslog server too, to actually erase all traces.

Oh darn .. I almost forgot to mention the IPS and IDS systems too .. And if it is Cisco ... the self defending network ..

Or you could just go to a consumer court and file a complaint ...

Reply 3:

Rightly said.
But i have observed it is very easy to get into local ISP as they donot bother to change the default settings and keep no authentication on their edge routers.
U can try this.
Go to any cybercafecheckout wat device they are using (if u can)if it's an ADSL router eg D-linkgo to address bar and type http://192.168.1.1/ (Default ip).
Generally no body bothers to change the default setting.
If u are able to login.. just type default username and password.
(Generally admin)
Now try to telnet next hop.
If there are no ACLs (Generally they have as u said) u might get into their network.


I am still tracking this interesting discussion and will keep updating.

Till then Keep Sharing Keep Spreading.......

Best Way to Learn is to Share

As it is said that best way to increase knowledge is to spread it, same is applicable to the online communities i.e. Best way to learn is to share what you know and let other questions. Every time you do this you either get to know the loop holes in your own concepts or you get to improve them.

Whatever happens happens the benifit you get is that you improve your as well as the knowledge of others.

So keep sharing keep spreading the knowledge that belongs to the whole world.


Do post your comments that what this blog is going to be all about.