<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	 xmlns:media="http://search.yahoo.com/mrss/" >

<channel>
	<title>Bootrom &#8211; AnonyViet &#8211; English Version</title>
	<atom:link href="https://en.anonyviet.com/tag/bootrom/feed/" rel="self" type="application/rss+xml" />
	<link>https://en.anonyviet.com</link>
	<description>The most popular website for sharing information technology, computer networks, and security knowledge. Stay up to date with the hottest news and tips</description>
	<lastBuildDate>Tue, 31 Jan 2023 17:48:09 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.1</generator>

<image>
	<url>https://en.anonyviet.com/wp-content/uploads/2023/01/cropped-ico-logo-75x75-1.png</url>
	<title>Bootrom &#8211; AnonyViet &#8211; English Version</title>
	<link>https://en.anonyviet.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Attack the Bootrom system of the net shop</title>
		<link>https://en.anonyviet.com/attack-the-bootrom-system-of-the-net-shop/</link>
					<comments>https://en.anonyviet.com/attack-the-bootrom-system-of-the-net-shop/#respond</comments>
		
		<dc:creator><![CDATA[AnonyViet]]></dc:creator>
		<pubDate>Tue, 31 Jan 2023 17:48:09 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Attack]]></category>
		<category><![CDATA[Bootrom]]></category>
		<category><![CDATA[NET]]></category>
		<category><![CDATA[shop]]></category>
		<category><![CDATA[system]]></category>
		<guid isPermaLink="false">https://en.anonyviet.com/?p=7479</guid>

					<description><![CDATA[Today we will try to learn about how to hijack Server Bootrom, cash registers, Routers to redirect DNS, install spyware by TPress the Bootrom system of the net shop Join the channel Telegram of the AnonyViet 👉 Link 👈 Tools needed: 1 DDNS or No-ip account (Articles about DDNS, No-ip You can find a lot [&#8230;]]]></description>
										<content:encoded><![CDATA[<p></p>
<div>
<p>Today we will try to learn about how to hijack Server Bootrom, cash registers, Routers to redirect DNS, install spyware by T<strong>Press the Bootrom system of the net shop</strong></p>
<div class="code-block code-block-16" style="margin: 8px 0; clear: both;">
<div align="center">
<table class=" aligncenter" style="background-color: #c0c0c0; border-collapse: collapse; width: 59.9985%;">
<tbody>
<tr>
<td style="width: 100%; text-align: center;"><span style="font-size: 12pt;"><strong>Join the channel <span style="color: #0000ff;">Telegram</span> of the <span style="color: #008080;">AnonyViet </span> 👉 <span style="text-decoration: underline;"><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Ft.me%2Fanonyvietchat" class="local-link" rel="noopener">Link</a></span>  👈</strong></span></td>
</tr>
</tbody>
</table>
</div>
</div>
<p><strong>Tools needed:</strong></p>
<ul>
<li>1 DDNS or No-ip account (Articles about <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fhuong-dan-cau-hinh-ddns-dyndns%2F" rel="noopener" class="local-link">DDNS</a>, <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fhuong-dan-cau-hinh-no-ip-nat-port-ra-internet%2F" rel="noopener" class="local-link">No-ip</a> You can find a lot of tutorials on the website <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fhuong-dan-cau-hinh-ddns-dyndns%2F" rel="noopener" class="local-link">DDNS, </a><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fhuong-dan-cau-hinh-no-ip-nat-port-ra-internet%2F" rel="noopener" class="local-link">NO-IP</a>  ).</li>
<li>Nmap (<a target="_blank" href="https://en.anonyviet.com/next-link/?url=http%3A%2F%2Fadf.ly%2F1V4T5W" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';">Download Nmap</a>)</li>
<li>1 thinking investment</li>
</ul>
<p><strong>Let&#8217;s start practicing:</strong></p>
<p><strong>Step 1:</strong></p>
<p>First, you need to determine the IP range allocated to the workstation and its Gateway.  To determine the IP range for workstations and Router&#8217;s Gateway, go to cmd and type the command <strong>ipconfig</strong> then Enter</p>
<p><img fetchpriority="high" decoding="async" class="alignnone size-full wp-image-1214" src="https://anonyviet.com/wp-content/uploads/2016/01/1-2.jpg" alt="first" width="678" height="340" srcset="https://anonyviet.com/wp-content/uploads/2016/01/1-2.jpg 678w, https://anonyviet.com/wp-content/uploads/2016/01/1-2-300x150.jpg 300w, https://anonyviet.com/wp-content/uploads/2016/01/1-2-360x180.jpg 360w" sizes="(max-width: 678px) 100vw, 678px" title="Attack the Bootrom system of the net shop 15"/></p>
<p>IPv4 Address is the IP of my machine: 192.168.1.108</p>
<p>Default Gateway of the system is: 192.168.1.1</p>
<p>Usually, the focus will divide the system into 2 IP ranges</p>
<ul>
<li>1 series for Bootrom machines (192.168.1.2 -> 192.168.1.99)</li>
<li>1 array of workstations.  (192.168.1.100 -> 254)</li>
</ul>
<p><strong>Step 2:</strong></p>
<p>Install Nmap software.  Just click Next and you&#8217;re done.</p>
<p>After the installation is complete, open Nmap and scan the IP ranges and ports of the net shop</p>
<ul>
<li>In the Target section: is the network range to be scanned: 192.168.1.0/24.</li>
<li>Under Profile: select Intense Scan, all TCP Port.</li>
<li>Then click Scan</li>
</ul>
<p><img decoding="async" loading="lazy" class="alignnone size-full wp-image-1215" src="https://anonyviet.com/wp-content/uploads/2016/01/2-3.jpg" alt="2" width="1919" height="1036" srcset="https://anonyviet.com/wp-content/uploads/2016/01/2-3.jpg 1919w, https://anonyviet.com/wp-content/uploads/2016/01/2-3-300x162.jpg 300w, https://anonyviet.com/wp-content/uploads/2016/01/2-3-1024x553.jpg 1024w, https://anonyviet.com/wp-content/uploads/2016/01/2-3-768x415.jpg 768w, https://anonyviet.com/wp-content/uploads/2016/01/2-3-1536x829.jpg 1536w, https://anonyviet.com/wp-content/uploads/2016/01/2-3-750x405.jpg 750w, https://anonyviet.com/wp-content/uploads/2016/01/2-3-1140x615.jpg 1140w" sizes="auto, (max-width: 1919px) 100vw, 1919px" title="Attacking the Bootrom system of the 16 . net shop"/></p>
<p>Wait for the results to appear (a bit long)</p>
<p><img decoding="async" loading="lazy" class="alignnone size-full wp-image-1216" src="https://anonyviet.com/wp-content/uploads/2016/01/3-2.jpg" alt="3" width="1918" height="810" srcset="https://anonyviet.com/wp-content/uploads/2016/01/3-2.jpg 1918w, https://anonyviet.com/wp-content/uploads/2016/01/3-2-300x127.jpg 300w, https://anonyviet.com/wp-content/uploads/2016/01/3-2-1024x432.jpg 1024w, https://anonyviet.com/wp-content/uploads/2016/01/3-2-768x324.jpg 768w, https://anonyviet.com/wp-content/uploads/2016/01/3-2-1536x649.jpg 1536w, https://anonyviet.com/wp-content/uploads/2016/01/3-2-750x317.jpg 750w, https://anonyviet.com/wp-content/uploads/2016/01/3-2-1140x481.jpg 1140w" sizes="auto, (max-width: 1918px) 100vw, 1918px" title="Attack the Bootrom system of the net 17"/></p>
</p>
<p>In the result we have 10 hosts that are online:</p>
<ul>
<li>1 host can be Linux,</li>
<li>8 hosts are Windows</li>
<li>What is an unknown host?</li>
</ul>
<p>Shown above Getway of Router is 192.168.1.1, in the picture after scanning we see that it is a Linux host.  Maybe this host is the Router because usually Router devices will run on Linux source code</p>
<p>In the results of Nmap, we see that the Router is opening 2 ports, 53 and 80 (web port).</p>
<p>We try to enter a web browser and type the router&#8217;s IP: 192.168.1.1</p>
<p><img decoding="async" loading="lazy" class="alignnone size-full wp-image-1217" src="https://anonyviet.com/wp-content/uploads/2016/01/4-1.jpg" alt="4" width="1919" height="534" srcset="https://anonyviet.com/wp-content/uploads/2016/01/4-1.jpg 1919w, https://anonyviet.com/wp-content/uploads/2016/01/4-1-300x83.jpg 300w, https://anonyviet.com/wp-content/uploads/2016/01/4-1-1024x285.jpg 1024w, https://anonyviet.com/wp-content/uploads/2016/01/4-1-768x214.jpg 768w, https://anonyviet.com/wp-content/uploads/2016/01/4-1-1536x427.jpg 1536w, https://anonyviet.com/wp-content/uploads/2016/01/4-1-750x209.jpg 750w, https://anonyviet.com/wp-content/uploads/2016/01/4-1-1140x317.jpg 1140w" sizes="auto, (max-width: 1919px) 100vw, 1919px" title="Attack the Bootrom system of the net shop 18"/></p>
<p>The user and password are often changed by the net shop owner because it will be troublesome if they do not have IT knowledge, and when the technical staff comes to handle the problem, it will be more complicated.  So they usually leave the default user/password</p>
<p>Now we try user: admin, pass: admin.</p>
<p>Wow, so you can access the router&#8217;s configuration page.  They use TotoLink equipment</p>
<p><img decoding="async" loading="lazy" class="alignnone size-full wp-image-1218" src="https://anonyviet.com/wp-content/uploads/2016/01/5-1.jpg" alt="5" width="1919" height="977" srcset="https://anonyviet.com/wp-content/uploads/2016/01/5-1.jpg 1919w, https://anonyviet.com/wp-content/uploads/2016/01/5-1-300x153.jpg 300w, https://anonyviet.com/wp-content/uploads/2016/01/5-1-1024x521.jpg 1024w, https://anonyviet.com/wp-content/uploads/2016/01/5-1-768x391.jpg 768w, https://anonyviet.com/wp-content/uploads/2016/01/5-1-1536x782.jpg 1536w, https://anonyviet.com/wp-content/uploads/2016/01/5-1-750x382.jpg 750w, https://anonyviet.com/wp-content/uploads/2016/01/5-1-1140x580.jpg 1140w" sizes="auto, (max-width: 1919px) 100vw, 1919px" title="Attacking the Bootrom system of the 19 . net shop"/></p>
<p>We are already half way here.  Should not continue at the net shop, now find a way to go home and still access this Router.  So we use the DDNS function to assign the domain name to the static ip of the net shop through the Router</p>
<p>This is how I can remotely remote into the Router.  Go to menu: Management -> DDNS.</p>
<p>Select No-IP, then type the domain name registered on No-ip.  Login information then save and reboot Router</p>
<p><img decoding="async" loading="lazy" class="alignnone size-full wp-image-1219" src="https://anonyviet.com/wp-content/uploads/2016/01/6-1.jpg" alt="6" width="1909" height="634" srcset="https://anonyviet.com/wp-content/uploads/2016/01/6-1.jpg 1909w, https://anonyviet.com/wp-content/uploads/2016/01/6-1-300x100.jpg 300w, https://anonyviet.com/wp-content/uploads/2016/01/6-1-1024x340.jpg 1024w, https://anonyviet.com/wp-content/uploads/2016/01/6-1-768x255.jpg 768w, https://anonyviet.com/wp-content/uploads/2016/01/6-1-1536x510.jpg 1536w, https://anonyviet.com/wp-content/uploads/2016/01/6-1-750x249.jpg 750w, https://anonyviet.com/wp-content/uploads/2016/01/6-1-1140x379.jpg 1140w" sizes="auto, (max-width: 1909px) 100vw, 1909px" title="Attack the Bootrom system of the 20 . net shop"/></p>
<p>Finished 1 child: 192.168.1.1</p>
<p>The next time we see what is the IP 192.168.1.2 of the net shop?  (it runs Windows operating system, open port 3389 (port remote desktop) So we can remote computer 192.168.1.2 according to speculation this will be Bootroom server</p>
<p><img decoding="async" loading="lazy" class="alignnone size-full wp-image-1220" src="https://anonyviet.com/wp-content/uploads/2016/01/7-1.jpg" alt="7" width="1270" height="782" srcset="https://anonyviet.com/wp-content/uploads/2016/01/7-1.jpg 1270w, https://anonyviet.com/wp-content/uploads/2016/01/7-1-300x185.jpg 300w, https://anonyviet.com/wp-content/uploads/2016/01/7-1-1024x631.jpg 1024w, https://anonyviet.com/wp-content/uploads/2016/01/7-1-768x473.jpg 768w, https://anonyviet.com/wp-content/uploads/2016/01/7-1-750x462.jpg 750w, https://anonyviet.com/wp-content/uploads/2016/01/7-1-1140x702.jpg 1140w" sizes="auto, (max-width: 1270px) 100vw, 1270px" title="Attacking the Bootrom system of the net 21"/></p>
<p>Try Remote Desktop.</p>
<ul>
<li>Into the <strong>run</strong> type command <strong>mstsc.</strong></li>
<li>Enter Computer: <strong>192.168.1.2</strong></li>
</ul>
<p>A dialog box asking for a Remote account appears</p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fwp-content%2Fuploads%2F2016%2F01%2F8-1.jpg" rel="attachment wp-att-1221 noopener" class="local-link"><img decoding="async" loading="lazy" class="alignnone size-full wp-image-1221" src="https://anonyviet.com/wp-content/uploads/2016/01/8-1.jpg" alt="8" width="430" height="261" srcset="https://anonyviet.com/wp-content/uploads/2016/01/8-1.jpg 430w, https://anonyviet.com/wp-content/uploads/2016/01/8-1-300x182.jpg 300w" sizes="auto, (max-width: 430px) 100vw, 430px" title="Attacking the Bootrom system of the 22 . net shop"/></a> <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fwp-content%2Fuploads%2F2016%2F01%2F7-1.jpg" rel="attachment wp-att-1220 noopener"><br /></a>Now we have to use the guessing method, usually simple passwords such as the owner&#8217;s name, password, 123456, 123@abc &#8230; Good luck</p>
<p>If successful, the image below will appear</p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fwp-content%2Fuploads%2F2016%2F01%2F9.jpg" rel="attachment wp-att-1222 noopener" class="local-link"><img decoding="async" loading="lazy" class="alignnone size-full wp-image-1222" src="https://anonyviet.com/wp-content/uploads/2016/01/9.jpg" alt="9" width="397" height="398" srcset="https://anonyviet.com/wp-content/uploads/2016/01/9.jpg 397w, https://anonyviet.com/wp-content/uploads/2016/01/9-300x300.jpg 300w, https://anonyviet.com/wp-content/uploads/2016/01/9-150x150.jpg 150w, https://anonyviet.com/wp-content/uploads/2016/01/9-75x75.jpg 75w" sizes="auto, (max-width: 397px) 100vw, 397px" title="Attack the Bootrom system of the net shop 23"/></a> <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fwp-content%2Fuploads%2F2016%2F01%2F10.jpg" rel="attachment wp-att-1223 noopener" class="local-link"><img decoding="async" loading="lazy" class="alignnone size-full wp-image-1223" src="https://anonyviet.com/wp-content/uploads/2016/01/10.jpg" alt="ten" width="1061" height="769" srcset="https://anonyviet.com/wp-content/uploads/2016/01/10.jpg 1061w, https://anonyviet.com/wp-content/uploads/2016/01/10-300x217.jpg 300w, https://anonyviet.com/wp-content/uploads/2016/01/10-1024x742.jpg 1024w, https://anonyviet.com/wp-content/uploads/2016/01/10-768x557.jpg 768w, https://anonyviet.com/wp-content/uploads/2016/01/10-120x86.jpg 120w, https://anonyviet.com/wp-content/uploads/2016/01/10-750x544.jpg 750w" sizes="auto, (max-width: 1061px) 100vw, 1061px" title="Attack the Bootrom system of the 24 . net shop"/></a></p>
<p>Remote can enter Bootrom, what to do next is up to you!</p>
</p>
<p style="text-align: right;">(Author: Darkcode – Shellsec)</p>
<div class="kk-star-ratings kksr-auto kksr-align-right kksr-valign-bottom" data-payload="{&quot;align&quot;:&quot;right&quot;,&quot;id&quot;:&quot;1213&quot;,&quot;slug&quot;:&quot;default&quot;,&quot;valign&quot;:&quot;bottom&quot;,&quot;ignore&quot;:&quot;&quot;,&quot;reference&quot;:&quot;auto&quot;,&quot;class&quot;:&quot;&quot;,&quot;count&quot;:&quot;100&quot;,&quot;legendonly&quot;:&quot;&quot;,&quot;readonly&quot;:&quot;&quot;,&quot;score&quot;:&quot;5&quot;,&quot;starsonly&quot;:&quot;&quot;,&quot;best&quot;:&quot;5&quot;,&quot;gap&quot;:&quot;5&quot;,&quot;greet&quot;:&quot;\u0110\u00e1nh gi\u00e1 b\u00e0i vi\u1ebft post&quot;,&quot;legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: 5\/5 - (100 b\u00ecnh ch\u1ecdn)&quot;,&quot;size&quot;:&quot;24&quot;,&quot;width&quot;:&quot;142.5&quot;,&quot;_legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: {score}\/{best} - ({count} {votes})&quot;,&quot;font_factor&quot;:&quot;1.25&quot;}">
<p>            The article achieved: 5/5 &#8211; (100 votes)    </p>
</p></div>
<p><!-- AI CONTENT END 2 --></p></div>
]]></content:encoded>
					
					<wfw:commentRss>https://en.anonyviet.com/attack-the-bootrom-system-of-the-net-shop/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://anonyviet.com/wp-content/uploads/2016/01/Server-Rack-12.jpg" medium="image"></media:content>
            	</item>
	</channel>
</rss>
