What's new

Pisowifi Vulnerablilities.

qtEulah

Enthusiast
Joined
Jul 26, 2022
Posts
162
Reaction
73
Points
51
Found an interesting issue about pisowifi using openline modems like b310as, 936, b525s.
Remember that these models were most used on remote areas with no fiber connections present.

What is a port scan?
A Port scan attack helps attackers to identify open points to enter into a cyber network and attack the user. Ports are really significant as they help in tracking the traffic that enters and leaves a computer network.

Open ports difference

without credits
root@euls:~# nmap 10.0.0.1
Starting Nmap 7.80 ( You do not have permission to view the full content of this post. Log in or register now. )
Nmap scan report for localhost (10.0.0.1)
Host is up (1.2s latency).
Not shown: 998 closed ports
PORT STATE SERVICE
53/tcp open domain
80/tcp open http

with credits
root@euls:~# nmap 10.0.0.1
Starting Nmap 7.80 ( You do not have permission to view the full content of this post. Log in or register now. )
Nmap scan report for localhost (10.0.0.1)
Host is up (1.2s latency).
Not shown: 998 closed ports
PORT STATE SERVICE
53/tcp open domain
80/tcp open http
23/tcp open telnet

As you can see, port 23 is available. but why?
Pisowifi systems are basically just firewalls, they give access to the router when you insert coins or buy credits.

What to do with this info?
Well, telnet is a command line. you can send commands like reboot, poweroff, etc..
Anyone can halt its entire operation by installing bootloop script or changing the mac address.


here's how it works
as long as your device have a valid mac, cell towers will allow you to connect with their services. the same way works with imei and to put it simply, router with bad mac adress will be disconnected to the internet.


1673495884319.png




i dunno if lpb and other systems have options to block port 23.
hope they fix this soon

Spoiler contents are visible only to Established Members.

ps: This is for educational Purposes only
 

Attachments

Last edited:
Haha, naaalala ko noon na rooted pa ang phone ko, ini-scan ko yung mga connected na devices at kinokopya ko yung mga mac address nila.

Ez access, walang bayad.
ig9OoyenpxqdCQyABmOQBZDI0duHk2QZZmWg2Hxd4ro.jpg
 

Attachments

Back
Top