华为Eudemon 1000E防火墙忘记了console登录密码,同时也无法telnet登录,只能寻求破解console密码的方式,破解方式还比较简单,步骤如下:
1、重启防火墙,通过console观察重启的信息,出现如下信息时,输入Ctrl+B
Enabling L1I Cache...
Enabling L1D Cache...
Enabling L2 Caches without ecc ..
Enabling L2 allocate...
Invalidate_l2_cache..
Start config dram control ...
Channel0 memory frequency:666MHz
Channel0 memory size :1024MB
Channel2 memory frequency:666MHz
Channel2 memory size :1024MB
Enabling L2 Caches with ecc
Test Data Bus ...ok
Test Addr Bus ...ok
Test Sdram Unit ...............ok
Press CTRL+A to Stop AutoBoot!
Starting...
Decompressing .....Done!
Starting at 0x8b000000...
*********************************
*********************************
Small Bootrom Ver : 022 Dec 7 2008
Big Bootrom Ver : 030 Jul 2 2009
Logical Ver : 004B
PCB Ver : VER.B
CPU Frequency : 1000 MHz
CPU Type : XLR532 Rev8
Initialize VFS, Please Waiting ......Done.
Press Ctrl+B to Enter Boot Menu... 5
2、要求输入Bootrom密码,出厂默认密码为:usg5000,不同系列不同版本的Eudemon防火墙默认Bootrom密码不同,网上也会提供一些密码,可以尝试一下,但不一定对;再不行咨询一下华为客服一般都能得到准确的密码。输入密码正确将进入Main-Bootrom菜单
Password:*******
=====================<MAIN-BOOTROM MENU>=====================
| <1> Boot With Default Mode |
| <2> Boot From Flash |
| <3> Enter Ethernet SubMenu |
| <4> Change Flash Boot File |
| <5> Modify Bootrom Password |
| <0> Reboot |
=============================================================
Enter your choice(0-5):
3、不选择任何数字,输入Ctrl+Z,进入隐藏子菜单,如下所示
======================<HIDDEN SUB-MENU>======================
| <1> Format Flash |
| <2> Delete File From Flash |
| <3> Display Flash Files |
| <4> Rename File |
| <5> Update Bootrom... |
| <0> Exit |
=============================================================
Enter your choice(0-5):
4、输入3可以查看flash下的文件列表,输入2删除flash中的某个文件,一般破解密码,可以将原配置文件更名,重启防火墙的时候就相当于空配置,使用出厂默认的console密码即可登录
Enter your choice(0-5): 3
Files in flash:
1:flash:/usg5000.bin 17463964 bytes
2:flash:/flashinfo.fls 353 bytes
3:flash:/private-data.txt 16 bytes
4:flash:/vrpcfg.zip 503 bytes
Total Space: 62553088 bytes!
Free Space: 45080576 bytes!
Current Boot Package File : <flash:/usg5000.bin>
======================<HIDDEN SUB-MENU>======================
| <1> Format Flash |
| <2> Delete File From Flash |
| <3> Display Flash Files |
| <4> Rename File |
| <5> Update Bootrom... |
| <0> Exit |
=============================================================
Enter your choice(0-5): 4
Please input the file name you want to rename:vrpcfg.zip
Please input the target file name:vrpcfg
Rename <vrpcfg.zip> to <vrpcfg> ...Done
======================<HIDDEN SUB-MENU>======================
| <1> Format Flash |
| <2> Delete File From Flash |
| <3> Display Flash Files |
| <4> Rename File |
| <5> Update Bootrom... |
| <0> Exit |
=============================================================
Enter your choice(0-5): 3
Files in flash:
1:flash:/usg5000.bin 17463964 bytes
2:flash:/flashinfo.fls 353 bytes
3:flash:/private-data.txt 16 bytes
4:flash:/vrpcfg 503 bytes
Total Space: 62553088 bytes!
Free Space: 45080576 bytes!
Current Boot Package File : <flash:/usg5000.bin>
======================<HIDDEN SUB-MENU>======================
| <1> Format Flash |
| <2> Delete File From Flash |
| <3> Display Flash Files |
| <4> Rename File |
| <5> Update Bootrom... |
| <0> Exit |
=============================================================
Enter your choice(0-5): 0
=====================<MAIN-BOOTROM MENU>=====================
| <1> Boot With Default Mode |
| <2> Boot From Flash |
| <3> Enter Ethernet SubMenu |
| <4> Change Flash Boot File |
| <5> Modify Bootrom Password |
| <0> Reboot |
=============================================================
Enter your choice(0-5): 0
Reboot System...
5、完成原配置文件的更名后,重启防火墙,出厂默认console登录用户名为:admin,密码为: Admin@123,即成功登录防火墙
Press ENTER to get started.
*********************************************************
* All rights reserved (2000-2008) *
* Without the owner's prior written consent, *
*no decompiling or reverse-engineering shall be allowed.*
*********************************************************
Login authentication
Username:admin
Password:
NOTICE:This is a private communication system.
Unauthorized access or use may lead to prosecution.
<Eudemon>
2012-11-01 12:02:00 Eudemon %%01SRM/1/StartUpWarm(t): 1.3.6.1.6.3.1.1.5.2 System startup warm!
<Eudemon>