X-Git-Url: https://iam.tj/gitweb/gitweb.cgi?p=cfe_generate_password.git;a=blobdiff_plain;f=cfe_generate_password.c;h=cdfe823cc3aea21d2f5deac66db57b65cfdf5ed4;hp=d51c0b98de6f3665423d8d227c630997c86607fe;hb=5c8d839840597bbcef9ee5a125442a41b1f6b315;hpb=c3dc2e93a04e9c9e3b8f82b1e988cfd2aceb41df diff --git a/cfe_generate_password.c b/cfe_generate_password.c index d51c0b9..cdfe823 100644 --- a/cfe_generate_password.c +++ b/cfe_generate_password.c @@ -1,79 +1,66 @@ -/* - Generate Broadcom CFE seeds and passwords for many popular modem/router devices +static const char *title = \ +"Generate Broadcom CFE seeds and passwords for many popular modem/router devices" +; +static const float VERSION = 1.4f; - Copyright 2015 TJ - Licenced on the terms of the GNU General Public Licence version 3 +static const char *copyright = \ +"Copyright 2015 TJ \n" +"Licenced on the terms of the GNU General Public Licence version 3\n" +; - To build: +static const char *help = \ +"This tool can generate passwords for use with many devices that contain Broadcom Common Firmware Environment (CFE) bootbase which has a debug mode that is enabled using the 'ATEN 1 XXXXXXXX' command, where XXXXXXXX is an eight digit hexadecimal 'password'.\n\n" - gcc -o cfe_gen_pass cfe_generate_password.c +"It is NOT necessary to have the device generate a 'seed' using 'ATSE [MODEL-ID]' because this tool can generate the seed from the device's first (base) MAC address.\n\n" - Or: +"When the device generates a seed it combines the number of seconds since 1970-01-01 00:00:00 with the router MAC address. Both are encoded in a single 6-byte hexadecimal number\n\n" - make +"Each value is truncated to its 3 least significant bytes so, for example:\n\n" - To use: +" $ date +%F.%T; echo \"obase=16;$(date +%s)\" | bc\n" +" 2016-03-26.23:06:32\n" +" 56F715F8\n\n" - ./cfe_gen_pass [options] +"and MAC Address: EC:43:F6:46:C0:80\n\n" - This tool can generate passwords for use with many devices that contain - Broadcom Common Firmware Environment (CFE) bootbase which has a debug mode - that is enabled using the "ATEN 1 XXXXXXXX" command, where XXXXXXXX is an - eight digit hexadecimal 'password'. +"becomes F715F8 concatenated with 46C080\n\n" - It is NOT necessary to have the device generate a 'seed' using "ATSE [MODEL-ID]" - because this tool can generate the seed from the device's first (base) MAC address. +" CFE> ATSE DSL-2492GNAU-B1BC\n" +" F715F846C080 <<<< last 3 bytes of MAC address\n" +" ^^^^^^\n" +" seconds since 1970-01-01 00:00:00 (2016-03-26 23:06:32)\n\n" - When the device generates a seed it combines the number of seconds since 1970-01-01 00:00:00 - with the router MAC address. Both are encoded in a single 6-byte hexadecimal +"*NOTE: the default seed after power-up is 000000 so no time value needs to be specifed if 'ATSE ' has not been executed on the device.\n\n" - Each value is truncated to its 3 least significant bytes so, for example: +"Access to the device's console via a serial UART port, or a network telnet/ssh session, is required to enter the password.\n\n" - $ date +%F.%T; echo "obase=16;$(date +%s)" | bc - 2016-03-26.23:06:32 - 56F715F8 - # MAC Address: EC:43:F6:46:C0:80 +"So, for a device with base MAC address (reported by the CFE during boot) E.g:\n\n" - becomes F715F8 concatenated with 46C080 +" CFE version 1.0.38-112.118 for BCM963268 (32bit,SP,BE)\n" +" ...\n" +" Base MAC Address : ec:43:f6:46:c0:80\n" +" ...\n" +" *** Press any key to stop auto run (1 seconds) ***\n" +" CFE>\n\n" - CFE> ATSE DSL-2492GNAU-B1BC - F715F846C080 <<<< last 3 bytes of MAC address - ^^^^^^ - seconds since 1970-01-01 00:00:00 (2016-03-26 23:06:32) +"Using this tool do:\n\n" - *NOTE: the default seed after power-up is 000000 so no time value needs to be specifed - if "ATSE " has not been executed on the device. +" ./cfe_gen_pass -s ec:43:f6:46:c0:80 -p\n\n" - Access to the device's console via a serial UART port, or a network telnet/ssh session, - is required to enter the password. +" MAC address: ec:43:f6:46:c0:80 Timestamp: 000000 Seed: 00000046c080 Password: 10f0a563\n\n" - So, for a device with base MAC address (reported by the CFE during boot) E.g: +"And on the device do:\n\n" - CFE version 1.0.38-112.118 for BCM963268 (32bit,SP,BE) - ... - Base MAC Address : ec:43:f6:46:c0:80 - ... - *** Press any key to stop auto run (1 seconds) *** - CFE> +" CFE> ATEN 1 10f0a563\n" +" OK\n" +" *** command status = 0\n\n" - Using this tool do: +"The tool can accept a timestamp as 8 hexadecimal characters (useful for testing the algorithm):\n\n" - ./cfe_gen_pass -s ec:43:f6:46:c0:80 -p +" ./cfe_gen_pass -t 56FA8C2B -s ec:43:f6:46:c0:80 -p\n\n" - MAC address: ec:43:f6:46:c0:80 Timestamp: 000000 Seed: 00000046c080 Password: 10f0a563 - - And on the device do: - - CFE> ATEN 1 10f0a563 - OK - *** command status = 0 - - The tool can accept a timestamp as 8 hexadecimal characters (useful for testing the algorithm): - - ./cfe_gen_pass -t 0FF020 -s ec:43:f6:46:c0:80 -p - - MAC address: ec:43:f6:46:c0:80 Timestamp: 0FF020 Seed: 0FF02046c080 Password: 110f65a3 - */ +" MAC address: ec:43:f6:46:c0:80 Timestamp: 56FA8C2B (2016-03-29 14:07:39) Seed: FA8C2B46c080 Password: 1111bda5\n\n" +; #include #include @@ -81,7 +68,6 @@ #include #include -static const float VERSION = 1.2f; static const size_t TIMESTAMP_SIZE = 8; static const size_t SEED_SIZE = 12; static const size_t PASSWORD_SIZE = 8; @@ -90,17 +76,17 @@ static const size_t MAC_ADDR_SIZE = 17; static const size_t DATESTRING_SIZE = 20; static void -pr_usage() +pr_usage(int verbose) { - fprintf(stderr, "%s\n", + fprintf(stderr, "Usage:\n" - " -v show version\n" " -s 00:01:02:03:04:05 create seed from MAC address\n" " -t [00000000] seconds since 1970-01-01 (defaults to NOW) \n" - " -p [SEED] generate password (with optional seed)\n\n" - " E.g. -s 01:02:03:04:05 \n" - " -s 01:02:03:04:05 -p\n" - " -p 000000030405\n" + " -p [SEED] generate password (with optional seed)\n" + " -h show additional help\n" + "\n" + "%s", + verbose ? help : "" ); } @@ -117,7 +103,7 @@ pr_error_exit(unsigned int usage, const char *error, ...) va_end(args); fprintf(stderr, "Error: %s\n", error_message); - if (usage) pr_usage(); + if (usage) pr_usage(usage); exit(EXIT_FAILURE); } @@ -186,101 +172,100 @@ int main(int argc, char **argv, char **env) { int result = 0; - - if (argc == 1) { - pr_usage(); - } - else { - unsigned int arg; - char *MAC_ADDR = NULL; - char timestamp[TIMESTAMP_SIZE + 1]; - char seed[SEED_SIZE + 1]; - char password[PASSWORD_SIZE + 1]; - char date_string[DATESTRING_SIZE + 1]; - unsigned int opt_seed, opt_pass, opt_ts; - time_t ts = 0; - struct tm *t = NULL; - seed[0] = password[0] = timestamp[0] = 0; - seed[SEED_SIZE] = password[PASSWORD_SIZE] = 0; - opt_seed = opt_pass = opt_ts = 0; - strncpy(timestamp, "00000000", TIMESTAMP_SIZE + 1); - - for (arg = 1; arg < (unsigned) argc; ++arg) { - size_t arg_len = strlen(argv[arg]); - - if (argv[arg][0] == '-') { - switch (argv[arg][1]) { - case 's': - opt_seed = 1; - break; - case 'p': - opt_pass = 1; - break; - case 't': - opt_ts = 1; - break; - case 'v': - fprintf(stderr, "Version: %0.2f\n", VERSION); - } - } else if (opt_seed == 1) { - MAC_ADDR = argv[arg]; - ++opt_seed; - } else if (opt_pass == 1 && opt_seed == 0) { - if (arg_len != SEED_SIZE) - pr_error_exit(1, "seed length must be %d characters", SEED_SIZE); - - strncpy(seed, argv[arg], SEED_SIZE); - ++opt_pass; - } else if (opt_ts == 1) { - if (arg_len != TIMESTAMP_SIZE) - pr_error_exit(1, "timestamp length must be %d hexadecimal characters", TIMESTAMP_SIZE); - - strncpy(timestamp, argv[arg], TIMESTAMP_SIZE); - ++opt_ts; + unsigned int arg; + char *MAC_ADDR = NULL; + char timestamp[TIMESTAMP_SIZE + 1]; + char seed[SEED_SIZE + 1]; + char password[PASSWORD_SIZE + 1]; + char date_string[DATESTRING_SIZE + 1]; + unsigned int opt_seed, opt_pass, opt_ts; + time_t ts = 0; + struct tm *t = NULL; + seed[0] = password[0] = timestamp[0] = 0; + seed[SEED_SIZE] = password[PASSWORD_SIZE] = 0; + opt_seed = opt_pass = opt_ts = 0; + strncpy(timestamp, "00000000", TIMESTAMP_SIZE + 1); + + fprintf(stderr, "%s\nVersion: %0.2f\n%s\n", title, VERSION, copyright); + + for (arg = 1; arg < (unsigned) argc; ++arg) { + size_t arg_len = strlen(argv[arg]); + + if (argv[arg][0] == '-') { + switch (argv[arg][1]) { + case 's': + opt_seed = 1; + break; + case 'p': + opt_pass = 1; + break; + case 't': + opt_ts = 1; + break; + case 'h': + pr_usage(1); + exit(0); } + } else if (opt_seed == 1) { + MAC_ADDR = argv[arg]; + ++opt_seed; + } else if (opt_pass == 1 && opt_seed == 0) { + if (arg_len != SEED_SIZE) + pr_error_exit(1, "seed length must be %d characters", SEED_SIZE); + + strncpy(seed, argv[arg], SEED_SIZE); + ++opt_pass; + } else if (opt_ts == 1) { + if (arg_len != TIMESTAMP_SIZE) + pr_error_exit(1, "timestamp length must be %d hexadecimal characters", TIMESTAMP_SIZE); + + strncpy(timestamp, argv[arg], TIMESTAMP_SIZE); + ++opt_ts; } - if (! opt_seed && ! opt_pass) - pr_usage(); - else if (opt_seed && opt_seed != 2) - pr_error_exit(1, "seed requires MAC-ADDRESS"); - else if (! opt_seed && opt_pass && opt_pass != 2) - pr_error_exit(1, "password on its own requires a pre-generated seed"); - else if (opt_seed && opt_pass && opt_pass != 1) - pr_error_exit(1, "generating seed and password; cannot also accept pre-generated seed"); - else if (opt_pass == 2 && opt_ts) - pr_error_exit(1, "seed already contains a timestamp; cannot over-ride it"); - else if (opt_ts == 1 || opt_pass == 2) { // no timestamp provided; use NOW - ts = time(NULL); - if (ts) - snprintf(timestamp, TIMESTAMP_SIZE + 1, "%08lX", ts); - } + } + if (! opt_seed && ! opt_pass) { + pr_usage(0); + exit(0); + } + else if (opt_seed && opt_seed != 2) + pr_error_exit(1, "seed requires MAC-ADDRESS"); + else if (! opt_seed && opt_pass && opt_pass != 2) + pr_error_exit(1, "password on its own requires a pre-generated seed"); + else if (opt_seed && opt_pass && opt_pass != 1) + pr_error_exit(1, "generating seed and password; cannot also accept pre-generated seed"); + else if (opt_pass == 2 && opt_ts) + pr_error_exit(1, "seed already contains a timestamp; cannot over-ride it"); + else if (opt_ts == 1 || opt_pass == 2) { // no timestamp provided; use NOW + ts = time(NULL); + if (ts) + snprintf(timestamp, TIMESTAMP_SIZE + 1, "%08lX", ts); + } - if (opt_pass == 2) { // try to figure out the correct date-time from the seed - // inherits the most significant 2 characters from the NOW time - strncpy(timestamp+2, seed, 6); - time_t tmp; - if (sscanf(timestamp, "%08lx", &tmp)) - if (tmp > ts-3600 && tmp < ts+3600) // timestamps are so close they must be for the same date - ts = tmp; - } + if (opt_pass == 2) { // try to figure out the correct date-time from the seed + // inherits the most significant 2 characters from the NOW time + strncpy(timestamp+2, seed, 6); + time_t tmp; + if (sscanf(timestamp, "%08lx", &tmp)) + if (tmp > ts-3600 && tmp < ts+3600) // timestamps are so close they must be for the same date + ts = tmp; + } - if(opt_ts) { // ts needs to be valid to be converted to a time string - if(! sscanf(timestamp, "%08lx", &ts)) - pr_error_exit(1, "converting timestamp string ('%s') to number", timestamp); - } - t = gmtime(&ts); - strftime(date_string, DATESTRING_SIZE, "%F %T", t); - - if (opt_seed) - if (! generate_seed(MAC_ADDR, timestamp, seed)) - pr_error_exit(1, "unable to generate seed; aborting"); - if (opt_pass) - if (! generate_pass(seed, password)) - pr_error_exit(0, "unable to generate password"); - - if (opt_seed || opt_pass) - printf("MAC address: %s Timestamp: %s (%s) Seed: %s Password: %s\n", MAC_ADDR, timestamp, date_string, seed, password); + if(opt_ts) { // ts needs to be valid to be converted to a time string + if(! sscanf(timestamp, "%08lx", &ts)) + pr_error_exit(1, "converting timestamp string ('%s') to number", timestamp); } + t = gmtime(&ts); + strftime(date_string, DATESTRING_SIZE, "%F %T", t); + + if (opt_seed) + if (! generate_seed(MAC_ADDR, timestamp, seed)) + pr_error_exit(1, "unable to generate seed; aborting"); + if (opt_pass) + if (! generate_pass(seed, password)) + pr_error_exit(0, "unable to generate password"); + + if (opt_seed || opt_pass) + printf("MAC address: %s Timestamp: %s (%s) Seed: %s Password: %s\n", MAC_ADDR, timestamp, date_string, seed, password); return result; }