GoHacking.com: Ethical Hacking and Cyber Security
Home » HOW-TO GUIDES, NETWORK HACKS

How to Hack an Ethernet ADSL Router

Submitted by on Sunday, 27 June 201081 Comments

Almost half of the Internet users across the globe use ADSL routers/modems to connect to the Internet however, most of them are unaware of the fact that it has a serious vulnerability in it which can easily be exploited by anyone with a basic knowledge of computer.

In this post, I will show you how to exploit a common vulnerability that lies in most ADSL routers so as to gain complete access to the router settings and ISP login details.

Every router comes with a username and password using which it is possible to gain access to the router settings and configure the device. The vulnerability actually lies in the Default username and password that comes with the factory settings. Usually the routers come preconfigured from the Internet Service provider and hence the users do not bother to change the password later.

This makes it possible for the attackers to gain unauthorized access to the router and modify it’s settings using a common set of default usernames and passwords. Here is how you can do it. Before you proceed, you need the following tool in the process:

Here is a detailed information on how to exploit the vulnerability of an ADSL router:

    1. Go to www.whatismyipaddress.com. Once the page is loaded, you will find your IP address. Note it down.

    2. Open Angry IP Scanner, here you will see an option called IP Range: where you need to enter the range of IP address to scan for.

Suppose your IP is 117.192.195.101, you can set the range something as 117.192.194.0 to 117.192.200.255 so that there exists at least 200-300 IP addresses in the range.

    1. Go to Tools->Preferences and select the Ports tab. Under Port selection enter 80 (we need to scan for port 80). Now switch to the Display tab, select the option “Hosts with open ports only” and click on OK.

IP Scanner Settings

I have used Angry IP Scanner v3.0 beta-4. If you are using a different version, you need to Go to Options instead of Tools

    1. Now click on Start. After a few minutes, the IP scanner will show a list of IPs with Port 80 open as shown in the below image:

Angry IP Scanner

  1. Now copy any of the IP from the list, paste it in your browser’s address bar and hit enter. A window will popup asking for username and password. Since most users do not change the passwords, it should most likely work with the default username and password. For most routers the default username-password pair will be admin-admin or admin-password.

Just enter the username-password as specified above and hit enter. If you are lucky you should gain access to the router settings page where you can modify any of the router settings. The settings page can vary from router to router. A sample router settings page is shown below:

Router Settings Page Hacked!

If you do not succeed to gain access, select another IP from the list and repeat the step-5. At least 1 out of 5 IPs will have a default password and hence you will surely be able to gain access.

What can an Attacker do by Gaining Access to the Router Settings?

By gaining access to the router settings, it is possible for an attacker to modify any of the router settings which results in the malfunction of the router. As a result the target user’s computer will be disconnected from the Internet. In the worst case the attacker can copy the ISP login details from the router to steal the Internet connection or play any kind of prank with the router settings.If this happens, the victim will have to reconfigure/reset the router settings in order to bring it back to the action.

The Verdict:

If you are using an ADSL router to connect to the Internet, it is highly recommended that you immediately change your password to prevent any such attacks in the future. Who knows, you may be the next victim of such an attack.

Since the configuration varies from router to router, you need to contact your ISP for details on how to change the password for your model.

Warning!
All the information provided in this post are for educational purposes only. Please do not use this information for illegal purposes.



By using/following this site you agree to our Legal Disclaimer

81 Comments »

  • Karan Kapoor said:

    Very very good information

  • xcptnaly dngrs.. said:

    hey srikanth…..

    the other i.p.’s arent working when i paste them on address bar….
    but my i.p. is working…

    and pls tell me hw to change the password too of any other i.p.

  • kartik sibal said:

    hey thnkx it really worked
    i even gt his username and password through which he used to log in
    nw i cn use it
    thnkxx

  • Muralimohan.A.R said:

    MY DOWNLOAD MANAGER AND ANTIVIRUS WARNS ME ABOUT “ANGRY IP SCANNER” THAT ,IT IS POTENTIALLY UNWANTED PROGRAM.ALSO MY ANTIVIRUS NEUTRALISED IT AS VIRUS.

    WHAT CAN I DO NEXT?

    IS IT A VIRUS?

  • Srikanth (author) said:

    @ kartik sibal

    please keep in mind that it is illegal to break other’s privacy without permission. The above post is only intended to expose the flaws in the adsl routers and not to encourage hacking.

  • Srikanth (author) said:

    @ Muralimohan.A.R

    Angry IP scanner is not a virus. However if you hesitate to use it, you can download any of the other IP scanners. Just try a Google search for “free IP scanners” or “Free port scanners” and you will definitely find an alternative!

  • Srikanth (author) said:

    @ xcptnaly dngrs..

    Try another series of IPs and they should work. Make sure that the IPs belong to ADSL ISP.

  • kartik sibal said:

    i kno hw does it fells wen someones changes ur pass i promise i will never change the pasword of the user.
    nd thnkx fr making me understand dis concept.

  • Ajith said:

    Hi Srikanth…

    Any Way to change or clone the MAC Address of cable Mode????

  • Almarghulani said:

    srikanth i wanted to ask u, ok i went to the router settings page, but how can i surf the internet?/

  • Hasanka D-Note said:

    i am published a blog about computer tips, tricks & hacks..
    but i published it in Sinhala language..
    i learn many things from Gohacking.
    i love this website.
    Srikanth is great.
    visit my blog..
    thank you…

  • Muralimohan.A.R said:

    THANKS FOR THE INFORMATION YAAR!!

    IT REALLY WORKED….

  • roshan said:

    hey srikanth
    next time create new thread abt how to identify a file is backdoor or not/
    MUCH APPRECIATED

  • shubham said:

    can i use bruteforce to break the router pass ?

  • mohit yadav said:

    good but how to open the system files and folder after breaking into router be default userid and password

  • Satyajit said:

    @srikanth nice info to share….keep sharing…hav a gud time.. :)

  • DEEPU said:

    hey…..thank u srikanth….i’ve been trying to learn hacking the adsl..bt in vain till now…u made it possible for me !!!!

    yup!!! its working…

    Thank u.

  • viraj said:

    hey man……..nice info!!
    thnx a lot…….

  • Viswa said:

    Hey..
    i succeded by doing this..
    i hav a big doubt..
    wat can b done by opening dese ip addresses? i mean wat all power v hav?

  • pinky said:

    i am new in this field of internet related tasks………..
    but reading ur article …..has made me curious bout all these stuff.
    could u plz tell wat is adsl router actually?
    the question is silly one but i really wanna know!

  • darkfuture said:

    @ Srikanth (author) - how to view the password that is hidden under asterisk from there? Hope you reply. Thanks.

  • punit said:

    how will i get the user name

  • Ruk-Com said:

    Very very good information

  • Srikanth (author) said:

    @ darkfuture

    You can download Asterisk Unmasker to view the hidden password.

  • SaRaB said:

    can i use internet if i hack into sum1′s modem……pls reply…..

  • waffles said:

    on the subject of internet, how would you find server #’s?i have looked around your site and i can’t find anything about it or RAT’s
    some help would be appreciated.oh and keep it up, i love this site, its provided me with more info than any other site :)

  • prateek said:

    what to do after gaining access to router setting please help me & can i use internet if i hack into sum1’s modem……pls reply

  • fokhwar said:

    Hey!
    Is this hacking for local DSL Router or Other DSL Router?
    Local DSL Router can be viewed by ipconfig/all.
    Please share me.

  • Monks said:

    wil u give a good link to Asterisk Unmasker. cant seem to find where i can down load a copy

  • Ashif said:

    dear srikanth,
    thanks for the post on adsl router hacking,it really worked even i got username and password of an i-baton modem,which is ayt kasaragod,kerala.i dont have internet at my home so i tried this in cafe… after reaching home i used his username and password in my netgear router but it doesnt connect…why is it???is it not possible?
    the thing is i didnt disconnect his router from internet,will it be a reason for that????pls replyyyyyy eagerly waiting for your reply and other such posts……
    yous sincerly
    Ashif

  • durvesh said:

    Thanxx friend, this articles was useful, i want to publish my website hackerscodinglab.weebly.com, so will you help me in that? please reply me soon yarrr

  • vinit said:

    whenever i”m entering the username-password(admin-admin or admin-password),a window pops up and says “the webpage cannot be displayed”….pls help

  • ssss said:

    you are the best hacker bro..
    thanx for the tricks and helps.
    i need to break the password of a wi-fi connection,what i have to do??

  • Srikanth (author) said:

    @ Ashif

    Most ISPs have port binding enabled on their end and hence using the username-password from another line (another phone) will not make you connect to the Internet.

  • Munjaal said:

    hey, thanks for the info.
    just 1 question

    will NB scanner work instead of ip scanner,

    thanks in advance

  • Srikanth (author) said:

    @ Munjaal

    Any port scanner will do the job.

  • biswajit said:

    this work in same network but is it work in different network??

  • Jason said:

    Hey I tried it out. it works. but is there any method by which i can bypass the internet connection and connect my pc to the target router from the above technique. I mean just steal the connection for speed n all???

  • faisal said:

    How to get the user name and password??????????????

    The Default password is not working.

    plz reply soon,,,

  • gaurav said:

    hey srikanth…
    Wen i click on start button den it showin the error…error show that malformed ip address specified, it should look like A.B.C.D. plz tell me wat should i do.

  • SAHIL BJ said:

    great piece of knowledge for network related ppl,. nice :)

  • arjie said:

    Thank you, now i know. I can protect my adsl.

  • Sherif Awosanya said:

    Hi boss u re best help me with this (1)Hacking a wifi server password 2 get acess to their data base or to browse with it. 2. Hackin a modem with pasword to browse with it. 3. How do i get user name and pasword cuz d default isnt workin 4. What do i use d tags for

  • Pouya said:

    thanks for the tips, when i scan with angry ip scanner 3-beta 4 no open ports (green)??

  • sopn0 said:

    man we know the ip its very easy to findout , but we need user name and password ,,, how we can get that , when password is changed

  • Srikanth (author) said:

    @ biswajit

    It works for any network!

  • kynox said:

    thanks Srikanth but you dont put full information about this hacking methods

    just a little which not help the majority of us

  • tarun said:

    this works i tried it iam able to get in a 2 dsl routers

  • Palash said:

    hello srikanth,
    thanks for the info. Generally, the broadband modems contains linux/mac OS. Those friends who says that they stole passwd and all, I dont think it would work because the MAC address will be different. However, logging into these virtual terminals doesnt suffice the role of a hacker. Hacking is not breaking into a computer or to steal passwds. It is more about how this functions. A few challanges for readers. Even logging into the virtual terminal using public ip how you people can really log into a person’s computer? How you can intrude with a firewall installed in a victim’s computer.

    Secondly, how can you keep yourself in stealth and evade.

    Please remember more knowledge more resposibility. Never harm anyone’s computer. How will you feel if someone does to you… Happy Hacking.

    :)

    palash

    [email protected]

  • Srikanth (author) said:

    @ Palash

    Thanks for your input.

  • CS said:

    hi srikant,
    i did wat was told but eventually i can find only my ip address…how do i get others ip addresses

  • risto said:

    did hi (Angry IP Scanner v3.0 beta-4) work in windows7 if don’t teel mi another

  • ranjeet said:

    its great….
    above information 100% work…

  • javaid saleem said:

    hi Srikanth your tutorial is good but there is another program that can hack Ethernet ADSL Router the software name is backtrack 3 and it can easily hack ethernet password wep-wpa-wpa2 all the passwords

  • Bala said:

    Good one….

  • samuel said:

    @ srikanth. this is interesting. i will do that exactly.
    thanx

  • Header said:

    thanks alot dear. its realy nice post.

  • DmNS said:

    @srikant

    wow !! awesome info !!

    can u pls tell how to copy the “SAM” file in windows without using linux ??

    thanx !!!

  • rahul said:

    hi i am rahul i am using bsnl broadconnection at my home ,but i have my friend bsnl username & password but when i put it on my pc its dont work what should i do i want to use my friend user name & password pls help which tool is use? i really confuse.pls help me.

  • Srikanth (author) said:

    @ rahul

    I think port binding is activated on the ISP end which makes it possible to access the Internet only from your phone line. Request them to remove the port binding; if they do it then you can access your Internet from any other BSNL phone line.

  • Sukhjit said:

    What if the default username and password are different? I would like a tutorial on that

  • waqar said:

    It is great.But how we will find the IP of a remote computer about we know that he has not changed his password of router.e.g a friend etc

  • yogesh chhabra said:

    @ Srikanth, is there any way to remove port binding? the help would be appreciated.

  • Srikanth (author) said:

    @ yogesh chhabra

    I think you need to give a request for your ISP to remove port binding.

  • shanker singh said:

    hi srikanth
    this was good
    but i am still in troubal how can i
    connet to other pc with open ports like port 80 and others

  • danny said:

    hello young fellow, i ve tried this and it seems to work …. i used ip of my mobile internet provider. though i got some other ip”s but when i try copy and paste in ma browser, an error msg normally bops up. what do u think i should do? or am i doing it the wrong way?

  • Aman Gupta said:

    Really gud piece of information…..bt i have an even shorter route 2 open up da router connections for which , one just needs 2 hav an ADSL modem. Call it stupidity or (watever suits u best), our ISP’s provide us a modem on da back side of wich, thre is url address of the router settings. Not only that, it has the username and password, boldly printed 4 ny1 2 c !!

  • Neel said:

    Hey there it was good article but really old one, is their any trick to know the ip of router which is just near by ?

  • sandy said:

    @karthick:By doing this will there be ne problem?????

  • bala sharma said:

    ya it really works

  • Rahul said:

    Hay Shri ……….. it’s too good yar… it worked bt the results r too complicated ….. I’m a beginner and just want to stop some computers to work since they keep on downloading unnecessary things 24/7 and we don’t get enough speed to surf also………
    I was abt to give all things that i came accross bt thought it would nt b safe …… so plz tell me how can i do so…….. stop those pc for some time atlist ……
    and plz tell how to restore also…..
    thanks………
    you r too good…….

  • PARTHA said:

    Angry IP Scanner is not a virus, if you hesitated to use this , then i will recommend you advance ip scanner or free ip scanner.

    enjoy;d
    advance ip - http://www.radmin.com/products/ipscanner
    free ip scanner - http://www.eusing.com/ipscan/free_ip_scanner.htm

  • mayuresh said:

    i am not able to download Angry IP Scanner
    plz provide a direct download link

  • amit said:

    at one ip i was taken to oracle http server index.what is this?

  • AKASH said:

    DOES IT WORKS WITH WIRELESS BROADBAND

  • Srikanth (author) said:

    @ AKASH

    It works with Wifi router as long as the connection is ADSL

  • arsh said:

    nice info but can we change our plan without letting isp know about it

  • amit said:

    i have two wireless connection which under range of my wifi one is of wep security and wap security how to crack them

  • dannyssy said:

    u re great young fellow, i ve gained acess to many dsl router, but i dont know what next to do to enable me gain acess to their internet connection. can u help futher more?

  • javid said:

    hi
    i know this way before
    the best & high bandwith ADSL often change their default passwords
    so how we can find their password
    i try some software like force brute,but i didn’t know how to use it,and try it on my router and it cant find my password.
    this is one static router in my local isp,and i cant finde its password.
    anyone can help me?

  • mahdi said:

    Simply a really great