$30 off During Our Annual Pro Sale. View Details »
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Kill-Router
Search
Matheus Fidelis
January 30, 2018
Technology
0
270
Kill-Router
Talk ministrada no SecurityTricks #1 sobre a ferramenta Kill-Router
Matheus Fidelis
January 30, 2018
Tweet
Share
More Decks by Matheus Fidelis
See All by Matheus Fidelis
Engenharia de Confiabilidade - Roadmap
msfidelis
1
230
Sobrevivendo a Cenários de Caos com Istio Service Mesh
msfidelis
1
160
Road to Serverless
msfidelis
0
79
Docker para Maiores - Superlógica
msfidelis
0
120
Escalando e Consumingo Queues com NodeJS, Docker e RabbitMQ
msfidelis
0
140
Desmistificando a AWS
msfidelis
0
60
Criando API's de verdade com HapiJS
msfidelis
0
130
Desbravando o REST com Python
msfidelis
0
50
O Fantástico Mundo de GIT
msfidelis
0
97
Other Decks in Technology
See All in Technology
AWSに革命を起こすかもしれない新サービス・アップデートについてのお話
yama3133
0
470
フルカイテン株式会社 エンジニア向け採用資料
fullkaiten
0
9.9k
Lookerで実現するセキュアな外部データ提供
zozotech
PRO
0
190
AWSの新機能をフル活用した「re:Inventエージェント」開発秘話
minorun365
2
380
アプリにAIを正しく組み込むための アーキテクチャ── 国産LLMの現実と実践
kohju
0
190
20251203_AIxIoTビジネス共創ラボ_第4回勉強会_BP山崎.pdf
iotcomjpadmin
0
120
AI との良い付き合い方を僕らは誰も知らない
asei
0
230
ESXi のAIOps だ!2025冬
unnowataru
0
290
Oracle Database@Google Cloud:サービス概要のご紹介
oracle4engineer
PRO
1
740
1人1サービス開発しているチームでのClaudeCodeの使い方
noayaoshiro
2
570
SREには開発組織全体で向き合う
koh_naga
0
410
20251222_next_js_cache__1_.pdf
sutetotanuki
0
150
Featured
See All Featured
Building an army of robots
kneath
306
46k
Impact Scores and Hybrid Strategies: The future of link building
tamaranovitovic
0
170
Claude Code のすすめ
schroneko
65
200k
Tips & Tricks on How to Get Your First Job In Tech
honzajavorek
0
400
AI: The stuff that nobody shows you
jnunemaker
PRO
1
8
Visual Storytelling: How to be a Superhuman Communicator
reverentgeek
2
400
Building a A Zero-Code AI SEO Workflow
portentint
PRO
0
190
Digital Ethics as a Driver of Design Innovation
axbom
PRO
0
130
Creating an realtime collaboration tool: Agile Flush - .NET Oxford
marcduiker
35
2.3k
JavaScript: Past, Present, and Future - NDC Porto 2020
reverentgeek
52
5.8k
How to Ace a Technical Interview
jacobian
281
24k
The Organizational Zoo: Understanding Human Behavior Agility Through Metaphoric Constructive Conversations (based on the works of Arthur Shelley, Ph.D)
kimpetersen
PRO
0
200
Transcript
Kill-Router- “De um trabalho da faculdade a 2000 dispositivos hackeados”
@fidelissauro https://github.com/msfidelis/Kill-Router-
$ whoami_ Matheus Fidelis Developer / Cloud / DevOps Superlógica
/ PJBank Github: /msfidelis Twitter: @fidelissauro Email:
[email protected]
Blog: http://nanoshots.com.br
$ Kill-Router • Mineração e brute force em massa em
dispositivos • Trabalho de faculdade • Quebrar senhas dos roteadores dos prédios • Desbloquear Ah Negão, Não Salvo e etc (foda) https://github.com/msfidelis/Kill-Router-
$ Kill-Router • KISS (Keep it Simple, Stupid…) • HTTP,
SSH, FTP Attack • Mode: Standalone (Target) • Mode: Shodan Dork Search Engine (API) • Minerar dispositivos conectados a internet • Weak Passwords • Roteadores, Câmeras, Switches, Painéis e lalala
$ Stand Alone ./kill-router.py -t 192.168.0.1 -u admin -l passlist.txt
./kill-router.py -t 192.168.0.1 -u root -l passlist.txt -p 22 -m ssh
$ Default Passlists • Top 10 Passwords • Top 100
Passwords • Stupid Passwords • Ashley Madison ( ͡° ͜ʖ ͡°)
$ SHODAN • Indexador de dispositivos conectados a internet. •
Fingerprint de serviços, versões e portas • Banners HTTP, FTP, SSH, Telnet, SNMP, SIP, etc • Dork Search • API Aberta https://www.shodan.io/
$ SHODAN
None
$ SHODAN 0.0.0.0/0
$ SHODAN
None
$ Searchs • RomPager/4.07 UPnP/1.0 —– router • uc-httpd 1.0.0
—– CCTV camera • DVRDVS-Webs —– CCTV camera • microhttpd —– router • Webs —– CCTV camera • Hikvision-Webs —– CCTV • camera iBall-Baton —– CCTV camera
$ Dorks • Nginx Servers in São Paulo nginx country:
"São Paulo" • Apache Server in Subnet Range apache net:“216.219.143.0/24” • Google Servers "Server: gws"
Kill-Router- ./kill-router.py --shodan geovision
None
None
None
None
OBRIGADO!