Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    ATT Uverse RG Bypass (0.2 BTC)

    Scheduled Pinned Locked Moved Bounties
    555 Posts 80 Posters 1.2m Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      lmgcnbzlp @JonH
      last edited by

      @JonH I used the python script method per:

      https://www.reddit.com/r/ATT/comments/g59rwm/bgw210700_root_exploitbypass/

      Had to run it twice because the script didn't have a wait period defined to account for telnet server startup leadtime, but on the second run it appears to have worked and was able to save the certs to my local machine in the manner documented in the readme.

      1 Reply Last reply Reply Quote 0
      • F
        fresnoboy @timtrace
        last edited by fresnoboy

        @timtrace

        Did you get this to work? I am trying to enable pfsense to be moved to a different system via vmotion for doing maintenance on the host. Right now I use the netgraph bypass method, but I don't think it will work if I am using PCI device passthrough, which prevents the VM to be migrated.

        Does the vlan0 tagging get interfered with by vmware's management of the network interfaces? I can use port mirroring on a switch to make the ONT and even the gateway available on multiple systems.

        thx
        mike

        1 Reply Last reply Reply Quote 0
        • D
          DanielJay23
          last edited by

          I have the netgraph version working well on my system. I am currently running 2.4.4-RELEASE. Will upgrading to 2.4.5_1 break this setup? Will I have to re-do my setup or can I just do a straight update through the web interface of my pfSense box?

          MonkWhoM 1 Reply Last reply Reply Quote 0
          • MonkWhoM
            MonkWho @DanielJay23
            last edited by

            @DanielJay23 said in ATT Uverse RG Bypass (0.2 BTC):

            I have the netgraph version working well on my system. I am currently running 2.4.4-RELEASE. Will upgrading to 2.4.5_1 break this setup? Will I have to re-do my setup or can I just do a straight update through the web interface of my pfSense box?

            Before upgrading I would recommend you compare your current pfatt.sh script with the one if the repository here https://github.com/MonkWho/pfatt and see if any big changes are necessary.

            One major change in 2.4.5 is that ng_etf module is now part of base pfsense and you don't need to compile and upload it anymore. And it's also loaded by default so we cleaned out those parts of the script as well. If you don't update your current pfatt.sh it might hang with an error and stop the boot process of your box. Depends what version of the script you are running. Early versions required that module to load and didn't have "-nq" flag that allowed system to skip if it's already loaded.

            1 Reply Last reply Reply Quote 0
            • A
              andrew_241
              last edited by andrew_241

              I'm trying to use the supplicant version of pfatt.sh, and my pfSense box hangs on 'waiting EAP for authorization...' during boot. I had to manually break and edit the relevant parts of config.xml to be able to boot properly. I think I'm using the latest version of the script, and I did follow the instructions here. I do have the necessary certificates extracted from an unused gateway device.

              Any idea on what the problem might be?

              Thanks!

              MonkWhoM 1 Reply Last reply Reply Quote 0
              • MonkWhoM
                MonkWho @andrew_241
                last edited by

                @andrew_241 I had this issue too at some point. I believe it happened because I had a typo in the MAC field in the script.

                Have you tried booting normally and then running the script by hand to see if it creates interfaces and authenticates? You can take the script apart and run one command at a time to try and see where the problem occurs.

                I also need to look at the script and figure out a way for some sort of an escape sequence if it this happens on boot. So people are not stuck like you were. Heck there is still an incomplete "TODO" in the code from the original creator specifically for this issue with hanging on boot.

                1 Reply Last reply Reply Quote 0
                • A
                  andrew_241
                  last edited by

                  I'll try executing the script manually. Just to confirm, I'll have the WAN interface port (igb0) directly connected to the ONT, but with no mac spoofing on it. Am I correct in assuming that the script creates the interface that spoofs the MAC of the gateway device?

                  A 1 Reply Last reply Reply Quote 0
                  • A
                    AiC0315 @andrew_241
                    last edited by

                    @andrew_241 when I initially set mine up my .pem files were not named correctly, so you may want to check that.
                    On mine, I have the mac address for the certs in the script and the mac address for my RG spoofed on my pfsense box. My certs did not come from my RG that's why I use 2 MACs

                    A 1 Reply Last reply Reply Quote 0
                    • F
                      ffuentes
                      last edited by

                      can somebody pm me on where I can get the pem's. Thanks.

                      1 Reply Last reply Reply Quote 0
                      • A
                        andrew_241
                        last edited by

                        So I tried to run the script manually when the firewall was already up and running, and it still hangs at 'waiting EAP for authorization...'. I can't see the ngeth0 interface as an option under 'Interface Assignments'.

                        If I change my igb0's MAC address to that of the gateway device, and run wpa_supplicant manually with the following configuration:

                        eapol_version=2
                        fast_reauth=1
                        ap_scan=0
                        network={
                                ca_cert="/cf/conf/pfatt/wpa/ca.pem"
                                client_cert="/cf/conf/pfatt/wpa/client.pem"
                                eap=TLS
                                eapol_flags=0
                                identity="(Gateway MAC Address)"
                                key_mgmt=IEEE8021X
                                phase1="allow_canned_success=1"
                                private_key="/cf/conf/pfatt/wpa/private.pem"
                        }
                        

                        I get the log message:

                        igb0: CTRL-EVENT-EAP-SUCCESS EAP authentication completed successfully
                        

                        So the certificates work. I can get my IP address, but the connection is slow (web browsers take a long time with DNS). I probably still need netgraph.

                        GPz1100G 1 Reply Last reply Reply Quote 0
                        • A
                          andrew_241 @AiC0315
                          last edited by

                          @AiC0315

                          I found the public certs for the CAs on the web. The client certificates I'm using, as well as the private key, were extracted from a different gateway device of the same model (BGW210-700) that I had sitting around.

                          1 Reply Last reply Reply Quote 0
                          • GPz1100G
                            GPz1100 @andrew_241
                            last edited by

                            @andrew_241

                            You should see no speed difference between a dumb switch bypass and certs. All wpa_supplicant does is allow for authentication of the device. It consumes practically no resources.

                            See if you have something hogging the cpu (top command in console). Netgraph method is obsolete these days. Certs method is completely self contained requiring no gateway box to be connected.

                            A 1 Reply Last reply Reply Quote 0
                            • A
                              andrew_241 @GPz1100
                              last edited by

                              @GPz1100

                              I haven't read this entire thread, but I was under the impression that the netgraph method was required to get the WAN interface to recognize the traffic on VLAN0 from the ONT.

                              P GPz1100G 2 Replies Last reply Reply Quote 0
                              • P
                                pyrodex @andrew_241
                                last edited by

                                @andrew_241 said in ATT Uverse RG Bypass (0.2 BTC):

                                @GPz1100

                                I haven't read this entire thread, but I was under the impression that the netgraph method was required to get the WAN interface to recognize the traffic on VLAN0 from the ONT.

                                If you are physical... virtually you don't need netgraph :).

                                1 Reply Last reply Reply Quote 0
                                • GPz1100G
                                  GPz1100 @andrew_241
                                  last edited by

                                  @andrew_241

                                  You are correct. I forgot about that. I'm running a virtualized setup here (esxi). When testing pfsense/certs I had no vlan0 issues.. The other option is to use a dumb switch between the ONT and pfsense wan ports.

                                  1 Reply Last reply Reply Quote 0
                                  • A
                                    andrew_241
                                    last edited by

                                    I tried to run the pfatt.sh script on my pfSense box manually, but I get the following:

                                    [2.4.5-RELEASE][root@pfSense]/root: /cf/conf/pfatt/bin/pfatt.sh
                                    pfatt: starting pfatt...
                                    pfatt: configuration:
                                    pfatt:   ONT_IF = igb0
                                    pfatt:   RG_ETHER_ADDR = (MAC address is here)
                                    pfatt:   EAP_MODE = supplicant
                                    pfatt:   EAP_SUPPLICANT_IDENTITY = (MAC address is here)
                                    pfatt:   EAP_BRIDGE_IF = igb1
                                    pfatt:   EAP_BRIDGE_5268AC = 0
                                    pfatt: resetting netgraph...
                                    pfatt: configuring EAP environment for supplicant mode...
                                    pfatt: cabling should look like this:
                                    pfatt:   ONT---[] [igb0]pfSense
                                    pfatt: creating vlan node and ngeth0 interface...
                                    ngctl: send msg: No such file or directory
                                    ngctl: send msg: No such file or directory
                                    ngctl: send msg: No such file or directory
                                    ngctl: send msg: No such file or directory
                                    ngctl: send msg: No such file or directory
                                    pfatt: enabling promisc for igb0...
                                    pfatt: starting wpa_supplicant...
                                    pfatt: wpa_supplicant running on PID ...
                                    pfatt: setting wpa_supplicant network configuration...
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    pfatt: waiting EAP for authorization...
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    Failed to connect to non-global ctrl_ifname: (nil)  error: No such file or directory
                                    

                                    I also got the same error when trying to type in the commands manually.

                                    MonkWhoM 1 Reply Last reply Reply Quote 0
                                    • A
                                      andrew_241
                                      last edited by

                                      I've since connected a dumb switch (Netgear GS105) between the ONT and my pfSense box in order to deal with the VLAN 0 issue, and retried the gateway bypass method using only the wpa_supplicant, and a spoofed MAC address. My wpa_supplicant configuration is as it was in my comment above, and I've configured Shellcmd to execute the following toward the end of the boot up process:

                                      wpa_supplicant -s -B -Dwired -iigb0 -c/cf/conf/wpa_supplicant.conf
                                      

                                      So far, so good. There are some instances where DNS resolving takes a couple seconds though, but it seems the bypass was successful.

                                      1 Reply Last reply Reply Quote 0
                                      • A
                                        andrew_241
                                        last edited by

                                        Looks like this method isn't working. I keep losing IPv4 connectivity after about one hour (gateway goes down), among other problems, including long wait times (2 minutes or so) to renew the WAN connection after a release.

                                        1 Reply Last reply Reply Quote 0
                                        • GPz1100G
                                          GPz1100
                                          last edited by

                                          Connectivity seems to stop if dhcp is unsuccessful. Need to find out why it's taking so long/failing.

                                          1 Reply Last reply Reply Quote 0
                                          • A
                                            andrew_241
                                            last edited by andrew_241

                                            Looks like something's going on with DHCP. The lease time from the ISP is one hour, according to a packet capture. I tried the bypass method again and this time I couldn't even get a stable connection after authenticating. I get a lease offer from the ISP after about two minutes in, but for some reason, pfSense wasn't accepting it.

                                            F 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.