Hacking an AT&T 4G Router For Fun and User Freedom

preview_player
Показать описание
AT&T doesn't want their customers to modify their own devices. In this video, I show how hardware hackers can take back control of their devices through the process of firmware extraction and firmware analysis. Specifically, we take a look at the CDS-9010 LTE router and extract the superadmin credentials via the UART U-Boot interface.

AT&T Forum Questions:

IoT Hackers Hangout Community Discord Invite:

🛠️ Stuff I Use 🛠️

🪛 Tools:

🫠 Soldering & Hot Air Rework Tools:

🔬 Microscope Setup:

About Me:
My name is Matt Brown and I'm an Hardware Security Researcher and Bug Bounty Hunter. This channel is a place where I share my knowledge and experience finding vulnerabilities in IoT systems.

- Soli Deo Gloria

💻 Social:

#hacking #iot #cybersecurity #righttorepair #jailbreak
Рекомендации по теме
Комментарии
Автор

I am a high school Cybersecurity teacher. This content is pure gold. Amazing work. 🎉 This was a pleasure to watch.

rxjo
Автор

That's one splendid hack, and a pretty easy one at that. Since it's Linux based, AT&T is obliged to publish the parts of the software that are GPL licensed, like Cisco/Linksys famously was with their WRT54GL back in the 2000s. Device configuration, user data etc. can be protected and fortunately they did a lousy job at that, when you're in, you're in. Also, I saw a Raspberry Pi reference in the UART output, it makes things interesting as to how the system was built or developed.
You're truly exercising your right to own things here - you'd make Louis Rossmann proud!

KeritechElectronics
Автор

Please don't stop, and keep doing it, it's so interesting to watch it.

rastamanlk
Автор

Most of the routers/modems that I have dissembled would have a password hashed and not stored in plaintext, so eventually I have to modify the bin file locally on laptop and then write it back to device with custom password hash.
This is a great video for people who wants to get started.

nappinggeek
Автор

didn't expect to find a wizard today.

vp_bot
Автор

I wasn't aware of this but this process made a surprising amount of sense. You're very good at explaining what your are doing. Thanks for opening up a rabbit hole. Looking forward for more.

lejoshmont
Автор

The SoC and modem in this router are common and supported by OpenWRT, it would be cool to see port for this device as part of more open firmware in the future!

trollczytb
Автор

ATT pulling a good ol sony, locking a device down after the fact only incentivizing breaking it open completely.

excellent work!

hburke
Автор

I believe the "phone" ports on that device are for an ATA gateway, which would provide POTS lines from the cellular interface.

MattMellen
Автор

Loved the troubleshooting to identify the UART pins. Super well explained!!

mathewrtaylor
Автор

This is the first video that I see of yours, and let me say I loved it. You explain really well and seem so passionate that it is contagious. Great work!

noexisting
Автор

Dude, I've been in the Software Industry for 20+ years and I am stumped why you only have 18.3K subscribers 🤔
Really liked this video, reminds me of the stuff I use to do for fun, I had to subscribe to your channel to help you growth - Great Job 😀

UK-Expat-in-USA
Автор

My guy - your videos are off the chain. You've got a talented way of explaining and walking through these activities. Keep it up!

carlsonjeffrey
Автор

As someone with a computer engineering background, this video is up my wheelhouse. I loved your explanations and contexts you gave. I knew at the end that you were going to check if SSH was enabled.

AndrewMackoul
Автор

You did a really good job doing this live. I appreciated how authentic it was and that I was able to learn through your process. Well done + thank you.

mntalify
Автор

I’m starting starting classes for cybersecurity and this video feels like discovering the secrets the Jedi don’t want me to know. Great video, thank you!

AceTrainerBanjo
Автор

Hey Matt, great work! I love that you explain it in detail, even though you already explained in other videos. Its nice for people who are getting into this "hobby". Great videos, keep it up.

ingermany
Автор

I didn't understand a single thing you did, but I watched every second. I wish I could go back and learn stuff like this.

matth
Автор

As someone who’s never done this but is super interested in tech, I loved this. First video I’ve seen from you. Loved how you take the time to explain your logic and the “why” behind your decisions. I sub’d and look forward to the next!

bryanb
Автор

I learned more in 30 minutes than I've learned in college this semester. Thank you! +Subscribed

jcs