mailto: blog -at- heyrick -dot- eu

Navi: Previous entry Display calendar Next entry
Switch to desktop version

FYI! Last read at 18:55 on 2024/11/21.

Livebox 2 - attempting to hack

Orange has produced apps - for Android andfor iOS - that permit you to "manage" your Livebox. After a bit of poking around between that and the web UI, I uncovered the principle of how the Livebox communicates with the management software: You send this:
POST /sysbus/NMC:getWANStatus HTTP/1.1
Accept:text/javascript
Accept-Encoding:gzip, deflate
Accept-Language:en-gb,en;q=0.5
Cache-Control:no-cache
Connection:keep-alive
Content-Length:17
Content-Type:application/x-sah-ws-1-call+json; charset=UTF-8
DNT:1
Host:192.168.1.1
Pragma:no-cache
Referer:http://192.168.1.1/supportSystemInformationAdsl.html
User-Agent:Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20100101 Firefox/12.0
X-Context:R3VYXSjjkznf6Z5DzVKCKsZssHzHYOHEEqss9Czh2NmUAhnX1YozedRuJf1vRxZm
X-Prototype-Version:1.7
X-Requested-With:XMLHttpRequest

{"parameters":{}}
And the server is supposed to reply with something like this:
{"result":
  {"status":true,"data":
    {"LinkType":"dsl",
      "LinkState":"up",
      "MACAddress":"xx:xx:xx:xx:xx:xx",
      "Protocol":"ppp",
      "ConnectionState":"Connected",
      "LastConnectionError":"ERROR_NONE",
      "IPAddress":"xx.xx.xx.xx",
      "RemoteGateway":"193.253.160.3",
      "DNSServers":"80.10.246.130,81.253.149.1",
      "IPv6Address":""}
    }
  }
This taken from a snoop on the behaviour of the Firefox Javascript interpreter.

So I send a simpler request - this:

POST /sysbus/NMC:getWANStatus HTTP/1.1
Accept:text/javascript
Content-Length:17
Content-Type:application/x-sah-ws-1-call+json; charset=UTF-8
Host:192.168.1.1

{"parameters":{}}
(a French bloke has retrieved data with less) My response? This, and immediately:
<html><head><title>Gateway Timeout</title></head>
<body><h1>504 - Gateway Timeout</h1></body></html>
You'll have to excuse me being a little bit confused as to this response.

 

Other useful things:

Haha, like I'd ever squeeze 3.5mbit out of this wire. The box is locked to 2424 max, except for the (very frequent with the new firmware) times when it connects more slowly until I pull the phone plug out of the wall and put it back again. It's almost as if the box is trying it on with me...

The Livebox 2 has two VoIP telephone ports. Evidently these can be different phone lines, but it doesn't appear to be supported at this time. I didn't know my phone had an email address.

And, finally, the others I have uncovered but haven't played with.

...and undoubtably more.

If you're an expert at JSON, you might get somewhere. I'm not, so I'm throwing in the towel for now. A fun way to waste an evening, but that's all...

 

Livebox 2 - Horrible new firmware

I'll come right out and say it. It's merdique. That means shitty. Yes, it is that bad.

Here are the version numbers:

Or SoftAtHome SG20_sip-fr-4.33.5.1, step4-sip-fr.
Mine is "sip" because I don't have a real phone line, it is only there to pass ADSL data, the phone is a (SIP) VoIP phone. If you have a real phone line, I think it says "h323" instead.
Likewise, the "SG" is because it is a Sagem Livebox. The ZTE ones will say "ZT" instead.
"20" is for a Livebox 2. It'll say "30" for a Livebox 3 (Livebox Play).
Maybe the other firmware is better? Maybe it's worse?

On the face of it, the new UI is clearer and less clunky than the older style. Here is the welcome/login screen:

I include a full screenshot so you can clearly see that this is an iPad. And that the Livebox is saying nothing is connected. Other than, you know... the iPad, the Raspberry Pi, my netbook (all WiFi), a USB memory stick, a Livephone DECT transponder (USB)... Once in a while, if I flagellate myself and make blood offerings, I can see one or other of the connected devices. Generally speaking, I cannot. Makes it "interesting" to manage the recognised devices, and equally "interesting" to correctly dismount USB memory devices. If I had kids and I needed to set up times of access, I'd need to use the app (and hope it works) because the Livebox's own UI sure-as-hell doesn't.

Oh look:

It does know that there is something connected to the USB ports.

There are maybe ten other devices known to my Livebox, but unconnected. Here is a list of them:

Sometimes you need to punch a hole in the NAT to allow a machine to run a server from within the intranet. For this, services like NoIP are useful (forget DynDNS, they sold out). My server, in the very few times it is running, is available at heyrick.ddns.net - but don't bother trying, it isn't on unless something says otherwise. Anyway, does the "new" option work? Uh, no, not really.

Here's the same thing grabbed from Firefox just now (the iPad photos are about two weeks old):
It appears that the Livebox will only switch the IP addresses for a 'name' and provide an entry for the device in the drop-down list if the device has recently been seen by the Livebox. <sarcasm>Useful.</sarcasm>

In the few, rare, times when the management works and stuff appears, you can configure your devices:

which leads on to:

There's more. Ooooh so much more.

As this upgrade is forced, I can't help but feel that Orange is using us as an army of beta testers that they'll pretty much ignore. Numerous complaints in the forums about the problems with the new firmware, no further upgrade in the last fortnight. Well, the stagiaire that put together the most recent firmware has maybe moved on? :-) At any rate, it is interesting to note that the box sort of has some passing mention of IPv6 (which I think Orange wants to roll out around 2017ish), but frankly, for now, I'd really rather downgrade to the firmware that worked.

I posted a rant (one of many) on the forum and received the standard advice - to factory-reset it. Thanks, but since the UI is broken and I use some rather specific settings here (to which the UI seems incapable of dealing with now), it may be that a factory reset fixes everything. Or it may be that a factory reset breaks things even worse. I've asked on the forum if the Orange staff adviser is willing to guarantee that a factory reset will resolve these problems. I don't expect to hear a reply...

Oh, and the English translations are extremely peculiar. That said, anybody who needs this "hint" does not deserve to have a Livebox. They probably need to be placed in a small padded room instead. Or America, where you can sue because your coffee was hot (regardless of the actual temperature it was served at, who puts a hot beverage between their legs? isn't that asking for trouble?)...

There's really nothing I can say to follow that, so I'll end here.

 

 

Your comments:

Thomas, 5th August 2014, 16:06
I could not agree with you more. We use the Livebox in a "residence secondaire", and after some absence I find the new firmware installed and ready to, hm, go? No. Let's leave it at installed. Now I am trying to downgrade. Would you know how to do that? 
 
Thomas
Sarah, 5th August 2014, 20:40
Hi. Is that message at the end really saying if you switch your internet box of you won't have internet?
Rick, 6th August 2014, 14:32
Thomas - no point. While you could possibly downgrade with JTAG to read the old firmware off an unupgraded box to your box....as soon as you hook it into the phone line, it'll go and upgrade itself. :-/ 
 
Sarah - yup. Patronising, isn't it?

Add a comment (v0.11) [help?]
Your name:

 
Your email (optional):

 
Validation:
Please type 84133 backwards.

 
Your comment:

 

Navi: Previous entry Display calendar Next entry
Switch to desktop version

Search:

See the rest of HeyRick :-)