FiosFiend
Active member
@Sardukarrr glad to see you checking back on this thread! Sadly, Fios-F1nDr became mostly useless since last update when I realized the serial is broadcast in the packet. This was the only real benefit that bit of code was doing, calculating the serial based on user input MAC and our date codes from the database. Although it’s not very useful at the moment, it will still accurately tell you all the relevant device info for the G3200/E3200. So I hope to update the code with the ability to tell you a bit of info on the various models in this thread then it will at least have some minor benefit again.
Yeah unfortunately the dictionary quickly ballooned to an unmanageable size... even using just the words that I’ve collected in the database creates a huge dictionary. Earlier in the week I output the wordlists again.
Saved 0 unique words to 2_letter_words.txt
Saved 392 unique words to 3_letter_words.txt
Saved 676 unique words to 4_letter_words.txt
Saved 492 unique words to 5_letter_words.txt
Saved 332 unique words to 6_letter_words.txt
Saved 512 unique words to 7_letter_words.txt
Saved 17 unique words to 8_letter_words.txt
Saved 0 unique words to 9_letter_words.txt
The smallest password pattern that I’ve observed is the strict 15-char <word>-<word>-<word> which gives us 7,822,563,840 combinations without including samer59’s contribution. Since the dictionary is going to continue to grow every update, we need to find other ways keep reduce the keyspace. I did have a bit of time to look into this more this week.
First, I had a script match all of the passwords that have a common word. the output is attached below. There are a couple words that have 8-10 matches! Unfortunately, there wasn’t anything that really jumped out to me. Maybe others can check it out and see if they notice anything? The most interesting thing that I saw was a 2 word match in passwords (gym3-tory-germ and gym3-carat-tory) for the ASK-NCQ1338.
Next, I considered the Netgear adjective-verb-digits example, so I looked at the various parts of speech. First I reduced the entries to only those with WiFi passwords with the hyphen (<word>-<word>-<word>), and then had a script use nltk.corpus to identify the parts of speech and then sort them by pattern. Here’s the result:
All <word>-<word>-<word>
Noun Digit Noun Noun - 274 (44%)
Noun Noun Digit Noun - 241 (39%)
Noun Digit Noun Other - 13 (2%)
Noun Digit Noun Adjective - 9 (1%)
Noun Digit Verb Noun - 9 (1%)
Other Noun Digit Noun - 9 (1%)
Adjective Noun Digit Noun - 8 (1%)
Noun Noun Digit Adjective - 8 (1%)
Noun Digit Adjective Noun - 8 (1%)
Noun Noun Digit Other - 7 (1%)
Noun Noun Digit Verb - 7 (1%)
Noun Digit Noun Verb - 7 (1%)
Noun Digit Other Noun - 7 (1%)
Verb Noun Digit Noun - 7 (1%)
Noun Digit Other Other - 2 (0%)
Adjective Noun Digit Adjective - 1 (0%)
Noun Other Digit Noun Noun - 1 (0%)
Noun Digit Other Verb - 1 (0%)
Verb Noun Digit Adjective - 1 (0%)
Total - 620
If we consider only the G3200/E3200 passwords, the trend is mostly the same.
G3100/E3200 <word>-<word>-<word>
Noun Digit Noun Noun - 65 (43%)
Noun Noun Digit Noun - 53 (35%)
Noun Digit Adjective Adjective - 4 (2.5%)
Noun Digit Noun Adjective - 4 (2.5%)
Noun Digit Noun Other - 4 (2.5%)
Adjective Noun Digit Noun - 3 (2%)
Noun Digit Other Noun - 2 (1%)
Noun Digit Verb Noun - 2 (1%)
Noun Noun Digit Other - 2 (1%)
Noun Noun Digit Other - 2 (1%)
Other Noun Digit Noun - 2 (1%)
Verb Noun Digit Noun - 2 (1%)
Noun Digit Noun Verb - 1 (0%)
Noun Digit Other Other - 1 (0%)
Noun Noun Digit Adjective - 1 (0%)
Noun Other Digit Noun Noun - 1 (0%)
Total - 150
Seeing that the majority of passwords are comprised only of nouns made me excited. However, AI tells me that nouns are the most common part of speech.. and unfortunately the other hits cover 20% of the list, which means we can’t eliminate them completely. Structuring a dictionary to put all of the nouns at the top could potentially find a hit faster, but it doesn’t reduce the overall dictionary any.

After separating the passwords I also noticed for G3200/E3200/ARC-XCI55AX (255 passwords), none of the first words start with letter L. This is a bit peculiar as the only other letter that’s missing is X. It would only slightly reduce the keyspace, and unfortunately this oddity doesn’t hold across all of the devices. So it may be possible that we just haven’t picked one up yet, but something to consider.
There are 12 permutations of the 15 character <word>-<word>-<word> pattern, so I separated all of these passwords and evaluated the permutation pattern. In the output, #L is the word length, and {D} is where the digit is; here’s the result:
5L{D}-4L-3L = 56 occurrences
5L{D}-3L-4L = 42 occurrences
4L{D}-5L-3L = 39 occurrences
3L-4L{D}-5L = 38 occurrences
3L-5L{D}-4L = 38 occurrences
5L-4L{D}-3L = 38 occurrences
3L{D}-4L-5L = 34 occurrences
3L{D}-5L-4L = 31 occurrences
4L-3L{D}-5L = 31 occurrences
4L{D}-3L-5L = 28 occurrences
4L-5L{D}-3L = 26 occurrences
5L-3L{D}-4L = 26 occurrences
Again, it’s interesting that the passwords with the 5-character word first are at the top of the list, but with all of the other hits we certainly can’t eliminate anything. So after all of this, we haven’t really eliminated anything... but we can at least structure the dictionary in a way that is somewhat favorable. I am not at all convinced that these passwords are truly random, otherwise there is no way to guarantee that the same password wouldn’t be generated multiple times. Like other router algorithms, they are likely using some sort of unique identifier to generate these. We know that the algorithm isn’t on the device, since the password and other info is burned into NVRAM. One thing that caught my attention in my last post was the UUID (universally unique identifier). I was having a bit of FOMO since the UUID isn’t shown on the sticker or QR code... So I decided to look through the unencrypted CR1000A firmware and found this.
It looks like for the CR1000A/B we just append the MAC address (with : removed) to the end of this string? Let’s check the capture we have..

MAC: 0409863d0167 UUID: 876543219abcdef012340409863d0165
Hey that’s cool! The UUID is as expected, but 2 off of the broadcast MAC. Looking at the firmware a bit more we see why.
The MAC broadcast in the WiFi packet is for wlan1, but the UUID is based off what I’ll call the “real” MAC. This also explains why this model has “steps” of 7 when we compared the MAC HEX/Serial. Each devices actually takes up 7 MAC addresses!

Also while poking around the firmware, I found the hidden networks (Backhaul and TV) that @soxrok2212 had mentioned earlier.

Looking locally, I can see that Fios routers are still broadcasting the hidden networks. Without any devices connected to them though, I’m not sure how we would capture the hash.
'Fios-XDmH5' bssid=b8:f8:53:50:54:52
<HIDDEN> bssid=82:f8:53:50:54:52
'Fios-LY7d6’ bssid=3c:bd:c5:25:19:aa
<HIDDEN> bssid=82:bd:c5:25:19:ae
Yeah unfortunately the dictionary quickly ballooned to an unmanageable size... even using just the words that I’ve collected in the database creates a huge dictionary. Earlier in the week I output the wordlists again.
Saved 0 unique words to 2_letter_words.txt
Saved 392 unique words to 3_letter_words.txt
Saved 676 unique words to 4_letter_words.txt
Saved 492 unique words to 5_letter_words.txt
Saved 332 unique words to 6_letter_words.txt
Saved 512 unique words to 7_letter_words.txt
Saved 17 unique words to 8_letter_words.txt
Saved 0 unique words to 9_letter_words.txt
The smallest password pattern that I’ve observed is the strict 15-char <word>-<word>-<word> which gives us 7,822,563,840 combinations without including samer59’s contribution. Since the dictionary is going to continue to grow every update, we need to find other ways keep reduce the keyspace. I did have a bit of time to look into this more this week.
First, I had a script match all of the passwords that have a common word. the output is attached below. There are a couple words that have 8-10 matches! Unfortunately, there wasn’t anything that really jumped out to me. Maybe others can check it out and see if they notice anything? The most interesting thing that I saw was a 2 word match in passwords (gym3-tory-germ and gym3-carat-tory) for the ASK-NCQ1338.
Next, I considered the Netgear adjective-verb-digits example, so I looked at the various parts of speech. First I reduced the entries to only those with WiFi passwords with the hyphen (<word>-<word>-<word>), and then had a script use nltk.corpus to identify the parts of speech and then sort them by pattern. Here’s the result:
All <word>-<word>-<word>
Noun Digit Noun Noun - 274 (44%)
Noun Noun Digit Noun - 241 (39%)
Noun Digit Noun Other - 13 (2%)
Noun Digit Noun Adjective - 9 (1%)
Noun Digit Verb Noun - 9 (1%)
Other Noun Digit Noun - 9 (1%)
Adjective Noun Digit Noun - 8 (1%)
Noun Noun Digit Adjective - 8 (1%)
Noun Digit Adjective Noun - 8 (1%)
Noun Noun Digit Other - 7 (1%)
Noun Noun Digit Verb - 7 (1%)
Noun Digit Noun Verb - 7 (1%)
Noun Digit Other Noun - 7 (1%)
Verb Noun Digit Noun - 7 (1%)
Noun Digit Other Other - 2 (0%)
Adjective Noun Digit Adjective - 1 (0%)
Noun Other Digit Noun Noun - 1 (0%)
Noun Digit Other Verb - 1 (0%)
Verb Noun Digit Adjective - 1 (0%)
Total - 620
If we consider only the G3200/E3200 passwords, the trend is mostly the same.
G3100/E3200 <word>-<word>-<word>
Noun Digit Noun Noun - 65 (43%)
Noun Noun Digit Noun - 53 (35%)
Noun Digit Adjective Adjective - 4 (2.5%)
Noun Digit Noun Adjective - 4 (2.5%)
Noun Digit Noun Other - 4 (2.5%)
Adjective Noun Digit Noun - 3 (2%)
Noun Digit Other Noun - 2 (1%)
Noun Digit Verb Noun - 2 (1%)
Noun Noun Digit Other - 2 (1%)
Noun Noun Digit Other - 2 (1%)
Other Noun Digit Noun - 2 (1%)
Verb Noun Digit Noun - 2 (1%)
Noun Digit Noun Verb - 1 (0%)
Noun Digit Other Other - 1 (0%)
Noun Noun Digit Adjective - 1 (0%)
Noun Other Digit Noun Noun - 1 (0%)
Total - 150
Seeing that the majority of passwords are comprised only of nouns made me excited. However, AI tells me that nouns are the most common part of speech.. and unfortunately the other hits cover 20% of the list, which means we can’t eliminate them completely. Structuring a dictionary to put all of the nouns at the top could potentially find a hit faster, but it doesn’t reduce the overall dictionary any.

After separating the passwords I also noticed for G3200/E3200/ARC-XCI55AX (255 passwords), none of the first words start with letter L. This is a bit peculiar as the only other letter that’s missing is X. It would only slightly reduce the keyspace, and unfortunately this oddity doesn’t hold across all of the devices. So it may be possible that we just haven’t picked one up yet, but something to consider.
There are 12 permutations of the 15 character <word>-<word>-<word> pattern, so I separated all of these passwords and evaluated the permutation pattern. In the output, #L is the word length, and {D} is where the digit is; here’s the result:
5L{D}-4L-3L = 56 occurrences
5L{D}-3L-4L = 42 occurrences
4L{D}-5L-3L = 39 occurrences
3L-4L{D}-5L = 38 occurrences
3L-5L{D}-4L = 38 occurrences
5L-4L{D}-3L = 38 occurrences
3L{D}-4L-5L = 34 occurrences
3L{D}-5L-4L = 31 occurrences
4L-3L{D}-5L = 31 occurrences
4L{D}-3L-5L = 28 occurrences
4L-5L{D}-3L = 26 occurrences
5L-3L{D}-4L = 26 occurrences
Again, it’s interesting that the passwords with the 5-character word first are at the top of the list, but with all of the other hits we certainly can’t eliminate anything. So after all of this, we haven’t really eliminated anything... but we can at least structure the dictionary in a way that is somewhat favorable. I am not at all convinced that these passwords are truly random, otherwise there is no way to guarantee that the same password wouldn’t be generated multiple times. Like other router algorithms, they are likely using some sort of unique identifier to generate these. We know that the algorithm isn’t on the device, since the password and other info is burned into NVRAM. One thing that caught my attention in my last post was the UUID (universally unique identifier). I was having a bit of FOMO since the UUID isn’t shown on the sticker or QR code... So I decided to look through the unencrypted CR1000A firmware and found this.
Code:
uuid=$(echo "$macaddr" | sed 's/://g')
uuid_config="uuid=87654321-9abc-def0-1234-$uuid"
It looks like for the CR1000A/B we just append the MAC address (with : removed) to the end of this string? Let’s check the capture we have..

MAC: 0409863d0167 UUID: 876543219abcdef012340409863d0165
Hey that’s cool! The UUID is as expected, but 2 off of the broadcast MAC. Looking at the firmware a bit more we see why.
Code:
option mac_address '78:67:0E:33:2F:BE'
option mac_address_eth '78:67:0E:33:2F:BF'
option mac_address_wlan1 '78:67:0E:33:2F:C0'
option mac_address_wlan2 '78:67:0E:33:2F:C1'
option mac_address_wlan3 '78:67:0E:33:2F:C2'
option mac_address_moca_lan '78:67:0E:33:2F:C3'
option mac_address_iot1 '78:67:0E:33:2F:C4'
The MAC broadcast in the WiFi packet is for wlan1, but the UUID is based off what I’ll call the “real” MAC. This also explains why this model has “steps” of 7 when we compared the MAC HEX/Serial. Each devices actually takes up 7 MAC addresses!

Also while poking around the firmware, I found the hidden networks (Backhaul and TV) that @soxrok2212 had mentioned earlier.

Looking locally, I can see that Fios routers are still broadcasting the hidden networks. Without any devices connected to them though, I’m not sure how we would capture the hash.
'Fios-XDmH5' bssid=b8:f8:53:50:54:52
<HIDDEN> bssid=82:f8:53:50:54:52
'Fios-LY7d6’ bssid=3c:bd:c5:25:19:aa
<HIDDEN> bssid=82:bd:c5:25:19:ae
Attachments
Last edited by a moderator:
























































