Hacking an AT&T 4G Router For Fun and User Freedom
AT&T doesn’t want their customers to modify their own devices. In this video, I show how hardware hackers can take back control of their devices through the process of firmware extraction and firmware analysis. Specifically, we take a look at the CDS-9010 LTE router and extract the superadmin credentials via the UART U-Boot interface.
AT&T Forum Questions:
– https://forums.att.com/conversations/other-phones-devices/dataremote-9070-web-administration-panel-access/6006d5f4127141623b1f6ead
– https://forums.att.com/conversations/att-fiber-equipment/i-need-help/5ecea8ed48339337196a41f9
IoT Hackers Hangout Community Discord Invite:
https://discord.com/invite/vgAcxYdJ7A
🛠️ Stuff I Use 🛠️
🪛 Tools:
XGecu Universal Programmer: https://amzn.to/4dIhNWy
Multimeter: https://amzn.to/4b9cUUG
Power Supply: https://amzn.to/3QBNSpb
Oscilloscope: https://amzn.to/3UzoAZM
Logic Analyzer: https://amzn.to/4a9IfFu
USB UART Adapter: https://amzn.to/4dSbmjB
iFixit Toolkit: https://amzn.to/44tTjMB
🫠 Soldering & Hot Air Rework Tools:
Soldering Station: https://amzn.to/4dygJEv
Microsoldering Pencil: https://amzn.to/4dxPHwY
Microsoldering Tips: https://amzn.to/3QyKhrT
Rework Station: https://amzn.to/3JOPV5x
Air Extraction: https://amzn.to/3QB28yx
🔬 Microscope Setup:
Microscope: https://amzn.to/4abMMao
Microscope 0.7X Lens: https://amzn.to/3wrV1S8
Microscope LED Ring Light: https://amzn.to/4btqiTm
Microscope Camera: https://amzn.to/3QXSXsb
About Me:
My name is Matt Brown and I’m an Hardware Security Researcher and Bug Bounty Hunter. This channel is a place where I share my knowledge and experience finding vulnerabilities in IoT systems.
– Soli Deo Gloria
💻 Social:
twitter: https://twitter.com/nmatt0
linkedin: https://www.linkedin.com/in/mattbrwn/
github: https://github.com/nmatt0/
#hacking #iot #cybersecurity #righttorepair #jailbreak
4g lte
Bro's face is like Jim Carrey
I’m in need of your prayers and healing vibes. Please keep me in your thoughts as I work towards better health.
wonder if that router is using a raspberry pi zero config. would like to see the proc/cpuinfo to see if its an ARM proc. tipoff could be the line creating 15 partitions "raspi"
Now the att forums have closed permanently. Coincidence? I think not 😅
This is really cool, thank you!
I have to say, as a life longer RE and cyber security expert, you are great. Keep up all you do and you will do well in life!
That was awesome. I maybe understood half of what ur doing bc I have 21yrs of being a Sound&Signal Technician only on Install/Test side, not programming..but I’ll subscribe
I did something similar to break into a Unifi NVR last year and everyone on my team was bewildered that I knew how to hardware hack.
I work in IT as a systems admin and I kind of just assumed basic hardware hacking knowledge was standard.
Turns out I am extremely overqualified for my job lmao
What did you use to capture and show all the received stuff? Like what board?
I love this 🙂 just a quick correction: SPI isn't a flash type but it's a communication protocol type. The flash does use spi in this scenario, but SPI itself stands for Serial Peripheral Interface (and it's usually denoted by 4 wires, MISO, MOSI, CLK, and CS). SPI is faster than I2C and allows (in theory) an unlimited number of slave devices 🙂
Oh 12:35 the device is called raspi (that seems like a raspberry pi)
Hey bro i have a soectrum modem and router and I wanted to ask something
Nice! Well explained, and easy to understand!
Thanks dude!
Bet you can't get out of Vim though….
SHIT! YOU CAN!
Leet AF
The problem… it is an ‘ATT’ router… not your router.
Ok, now help me aaccess a xfinity sec cam that i can get into to use without xfinity service… 😢
Thank you for the primer. I wish I still had the technical ability to do this myself; however, my skills are too out of date.
I have been trying to access my xfinity Security cam to turn on some features we ate locked out of unless we pay extra. I also want to end xfinity home security and use the cams without service. As yet, have not cracked the access code.
that looks like dd-wrt hahah
man shows AT&T hey can be bypassed
Totally awesome!
Try to put openwrt on the router
great job man
Hardware hacking is bizarre and pretty cool.
I mean…… Besides learning a ton of good stuff about Hardware hacking, I just learned that you can do a "cd $_" after moving a file to another directory…… and it will take you there!
MIND… BLOWN!!
I'm not a "hardcore terminal user", but… I do know my way around a terminal.. or so I thought.
You made it look easy. Mine doesn't have command line in boot. I bought a Uart reader for this