Explain the challenges of reading /etc/passwd and /etc/shadow
The ZyXEL B10B (VMG3925-B10B) is an all-in-one ADSL/VDSL/FTTP router with dual band, 2.4G and 5G WiFi, 4 Gigabit network ports and a separate WAN Ethernet port. Suitable for Home or small office use. AAISP started supplying these in AprilMarch 2018
'''==Basic Specs:'''==
*4x 10/100M/1000M ports.
*Modem supports VDSL (FTTC) and ADSL/ADSL2+.
*WiFi is 2.4GHz and 5Ghz5GHz, 802.11b/g/n, 802.11a/n/ac
*Broadcom 63168 chipset
*MTU 1500 when in bridge mode not possible yet, but we are working with ZyXEL on this. (2018-03)
===Suitable for:===
*VDSL (FTTC), G.Fast (Modem doesn't support G.Fast, so you'd need a separate G.Fast modem)
*VDSL (FTTC) as an Ethernet router plugged in to a VDSL modem (no longer a common setup, as Openreach no longer provide VDSL modems)
*VDSL (FTTC) or ADSL as a bridging modem to a third-party PPPoE router (e.g. FireBrick).
*FTTP using the Ethernet WAN port doing PPPoE.
===Router and Modem modes:===
*an all in one modem/router/wifi
*an Ethernet (PPPoE) router plugged in to a separate VDSL or ADSL modem or a FTTP or FTTPoD ONT
*VDSL (FTTC) or ADSL as a bridging modem to a third-party PPPoE router (e.g. FireBrick, Mikrotik etc).
==='Consumer' grade===
It's worth noting that this is a consumer grade router which ideal for home use or for small offices. Different or additional hardware may be more suitable for larger or more complex networks, larger offices or to cover a larger area with WiFi access.
==Factory Default Admin Username/Password==
Supervisor password:
The B10B has an autogenerated supervisor password (hashed from the serial number). Earlier models left a md5crypt type hash in /etc/passwd, however firmware AAVF.10 introducedchanged theseto beinga SHA-512 type hash stored in /etc/shadow. YouPrior mayto havefirmware someAAVF.10 successyou readingwill thisbe fileable to read /etc/passwd by logging into the router as the "admin" user via SSH or Telnet. With firmware AAVF.10 and later you would have to log in as the supervisor user - but you'd need to know the password.... You willwould need to crack the hash (ege.g. with hashcat), the password will be 8 characters long using characters 0-9,a-f (lower case)
