Obtain the telcomadmin super administrator password of the Telecom Optical Cat through the small wing steward, which theoretically supports all versions of the Telecom Optical Cat

Little assistant reads articles 00:00 / 00:00

reminder:
The content described in this article is dependent and may differ from the expectation due to different soft and hard conditions, so please take the actual situation as the criterion for reference only.

At home, the new version of the Optical Cat is very new, and does not include the U port. Therefore, many methods to obtain the configuration file through the U disk on the Internet are not applicable.
Occasionally, the steward of the packet capturing winglet found that the telcomadmin administrator password of the Telecom Optical Cat can be viewed through some device interfaces. If the optical cat used supports binding the winglet steward, you can theoretically view the telcomadmin administrator password.

matters needing attention

The role of login super administrator is basically to change the bridge and open IPv6. It is recommended to add a dial in the way of changing the bridge, otherwise the Xiaoyi steward cannot adjust the interface offline. Or delete the management item and record the password

1、 Install and bind the winglet steward

It is available in all major application markets. Search and install it directly, or download and install it by scanning the QR code below:

 01. QR code.jpg

After installation, log in and bind your own optical cat. The binding method refers to the binding method in APP (such as connecting the optical cat WIFI and scanning the code):

 02. Bind.jpg

2、 Start packet capture analysis

Use the packet capture tool to capture the small wing steward. There is no limit to the method of packet capture, and you can choose your own. Some packet capture software may need to install a trust certificate first.
After packet capturing is enabled, use the gateway setting function ->indicator light in the small wing butler or operate the optical cat function at will:

 03. Gateway Settings.jpg

 04. Operating equipment.jpg

3、 Extract analysis data

Find the corresponding request in the packet capture results (different packet capture software display interfaces are different, subject to the actual situation, and do not stick to the screenshot):

 05. Request Link.jpg

We can see the request of 189cube.com. This is the domain name of the direct operating device, followed by the authentication data, which is needed in the next step (if the packet capture software is not enabled, the MITM may not be visible). Click in to see the request packet:

 06. Request Data

4、 Construct request data

Some packet capturing software can directly edit the above request and send it again. In short, it uses various methods to build the request, Header and UR Use the header and URL obtained from the above packet capture, and the request packet body is the following parameter (directly copied), and then send the request:

 { "Params": [], "MethodName": "GetTAPasswd", "RPCMethod": "CallMethod", "ObjectPath": "/com/ctc/igd1/Telecom/System", "InterfaceName": "com.ctc.igd1.SysCmd", "ServiceName": "com.ctc.igd1" }

 07. Construction request

 08. Request Body.jpg

5、 Return Data

The data returned after the request is sent is roughly as follows:

 { "Ack": "CallMethod", "ID": "***", "Status": "0", "Params": ["telecomadmin***", 0, "get GetTAPasswd success"] }

In Params telecomadmin*** It is the super tube password of the light cat.

This interface can also call other functions, such as restarting the optical cat. Refer to Technical Requirements for China Telecom Smart Home Gateway for details


Reference article:

1、《 Obtain the telcomadmin super administrator password of the Telecom Optical Cat through the small wing steward, which theoretically supports all versions of the Telecom Optical Cat


ArmxMod for Typecho
Personalized, adaptive and powerful responsive theme

extension

Continue to browse about telecom course Bag grabbing password Xiaoyi housekeeper Light cat Super administrator China Telecom telecomadmin 's article

This article was last updated on 2022/02/12 16:04:44 , which may be different from the current situation due to years

Please specify: VirCloud's Blog > Operation and maintenance > Obtain the telcomadmin super administrator password of the Telecom Optical Cat through the small wing steward, which theoretically supports all versions of the Telecom Optical Cat

Selected comments

  1.  Timo sauce
    Timo sauce reply

    Windows 10 Chrome 98.0.4758.102 Great God from Henan

    You can also try telnet. My light cat can do it[ https://www.timochan.cn/posts/any_pen/china_telecom_super ]( https://www.timochan.cn/posts/any_pen/china_telecom_super )

  2.  Xu Xu came here
    Xu Xu came here reply

    Windows 10 Chrome 99.0.4844.51 Great God from Hong Kong

    Hello, blogger, my home is also a new model of Telecom Optical Cat, without U port. I want to find the super password. Please tell me the name of the package capturing software used in the article. If there is a download link, please tell me

    1.  Owens

      There are a lot of packet capturing software, such as Surge, small rocket and so on, There are also some on the PC side, but it is not recommended because the operation is complex

  3.  Piglet
    Piglet reply

    Windows 10 Chrome 86.0.4240.198 Great God from Hubei

    Niubi, have got the super password
    However, TR069 cannot be deleted in gray, and I don't know how to open TELNET or SSH
    ZTE F4600T

    1.  Owens

      Try creating a new TR069 and see if the original one can be deleted

      1.  Piglet
        Piglet reply

        iPhone 11_4_1 Safari 604.1 Great God from Australia

        I see. I'll try this operation,

  4.  be courteous and accessible
    be courteous and accessible reply

    Android 10 Chrome 99.0.4844.88 God from Sichuan Province

    Can you give me the code for calling other interfaces?

  5.  be courteous and accessible
    be courteous and accessible reply

    Android 10 Chrome 99.0.4844.88 God from Sichuan Province

    Can you give me the code or document for calling other interfaces?, Thank you very much.

    1.  Owens

      Refer to Technical Requirements for China Telecom Smart Home Gateway for details

      1.  be courteous and accessible
        be courteous and accessible reply

        Android 10 Chrome 99.0.4844.88 God from Japan

        The failure returns the result 1 -. How can I view the super password now??

        1.  Owens

          Explain that the method has been blocked. Ask the telecom broadband master the fastest