NETWORKSTelecom Networks

Hacking an AT&T 4G Router For Fun and User Freedom

AT&T doesn’t want their customers to modify their own devices. In this video, I show how hardware hackers can take back control of their devices through the process of firmware extraction and firmware analysis. Specifically, we take a look at the CDS-9010 LTE router and extract the superadmin credentials via the UART U-Boot interface.

AT&T Forum Questions:
– https://forums.att.com/conversations/other-phones-devices/dataremote-9070-web-administration-panel-access/6006d5f4127141623b1f6ead
– https://forums.att.com/conversations/att-fiber-equipment/i-need-help/5ecea8ed48339337196a41f9

IoT Hackers Hangout Community Discord Invite:
https://discord.com/invite/vgAcxYdJ7A

🛠️ Stuff I Use 🛠️

🪛 Tools:
XGecu Universal Programmer: https://amzn.to/4dIhNWy
Multimeter: https://amzn.to/4b9cUUG
Power Supply: https://amzn.to/3QBNSpb
Oscilloscope: https://amzn.to/3UzoAZM
Logic Analyzer: https://amzn.to/4a9IfFu
USB UART Adapter: https://amzn.to/4dSbmjB
iFixit Toolkit: https://amzn.to/44tTjMB

🫠 Soldering & Hot Air Rework Tools:
Soldering Station: https://amzn.to/4dygJEv
Microsoldering Pencil: https://amzn.to/4dxPHwY
Microsoldering Tips: https://amzn.to/3QyKhrT
Rework Station: https://amzn.to/3JOPV5x
Air Extraction: https://amzn.to/3QB28yx

🔬 Microscope Setup:
Microscope: https://amzn.to/4abMMao
Microscope 0.7X Lens: https://amzn.to/3wrV1S8
Microscope LED Ring Light: https://amzn.to/4btqiTm
Microscope Camera: https://amzn.to/3QXSXsb

About Me:
My name is Matt Brown and I’m an Hardware Security Researcher and Bug Bounty Hunter. This channel is a place where I share my knowledge and experience finding vulnerabilities in IoT systems.

– Soli Deo Gloria

💻 Social:
twitter: https://twitter.com/nmatt0
linkedin: https://www.linkedin.com/in/mattbrwn/
github: https://github.com/nmatt0/

#hacking #iot #cybersecurity #righttorepair #jailbreak

source

4g lte

24 thoughts on “Hacking an AT&T 4G Router For Fun and User Freedom

  • I’m in need of your prayers and healing vibes. Please keep me in your thoughts as I work towards better health.

  • wonder if that router is using a raspberry pi zero config. would like to see the proc/cpuinfo to see if its an ARM proc. tipoff could be the line creating 15 partitions "raspi"

  • Now the att forums have closed permanently. Coincidence? I think not 😅

  • I have to say, as a life longer RE and cyber security expert, you are great. Keep up all you do and you will do well in life!

  • That was awesome. I maybe understood half of what ur doing bc I have 21yrs of being a Sound&Signal Technician only on Install/Test side, not programming..but I’ll subscribe

  • I did something similar to break into a Unifi NVR last year and everyone on my team was bewildered that I knew how to hardware hack.

    I work in IT as a systems admin and I kind of just assumed basic hardware hacking knowledge was standard.

    Turns out I am extremely overqualified for my job lmao

  • I love this 🙂 just a quick correction: SPI isn't a flash type but it's a communication protocol type. The flash does use spi in this scenario, but SPI itself stands for Serial Peripheral Interface (and it's usually denoted by 4 wires, MISO, MOSI, CLK, and CS). SPI is faster than I2C and allows (in theory) an unlimited number of slave devices 🙂

  • Hey bro i have a soectrum modem and router and I wanted to ask something

  • Nice! Well explained, and easy to understand!

    Thanks dude!

    Bet you can't get out of Vim though….

    SHIT! YOU CAN!

    Leet AF

  • The problem… it is an ‘ATT’ router… not your router.

  • Ok, now help me aaccess a xfinity sec cam that i can get into to use without xfinity service… 😢

  • Thank you for the primer. I wish I still had the technical ability to do this myself; however, my skills are too out of date.
    I have been trying to access my xfinity Security cam to turn on some features we ate locked out of unless we pay extra. I also want to end xfinity home security and use the cams without service. As yet, have not cracked the access code.

  • I mean…… Besides learning a ton of good stuff about Hardware hacking, I just learned that you can do a "cd $_" after moving a file to another directory…… and it will take you there!
    MIND… BLOWN!!

    I'm not a "hardcore terminal user", but… I do know my way around a terminal.. or so I thought.

  • You made it look easy. Mine doesn't have command line in boot. I bought a Uart reader for this

Comments are closed.