2 require_once('RebootException.class.php');
3 require_once('RouterException.class.php');
4 require_once('CryptLib/CryptLib.php');
7 * @author Jan Altensen (Stricted)
8 * @license GNU Lesser General Public License <http://opensource.org/licenses/lgpl-license.php>
9 * @copyright 2015 Jan Altensen (Stricted)
11 class SpeedportHybrid
{
16 const VERSION
= '1.0.3';
22 private $challenge = '';
52 private $derivedk = '';
54 public function __construct ($url = 'http://speedport.ip/') {
59 * Requests the password-challenge from the router.
61 private function getChallenge () {
62 $path = 'data/Login.json';
63 $fields = array('csrf_token' => 'nulltoken', 'showpw' => 0, 'challengev' => 'null');
64 $data = $this->sentRequest($path, $fields);
65 $data = $this->getValues($data['body']);
67 if (isset($data['challengev']) && !empty($data['challengev'])) {
68 return $data['challengev'];
71 throw new RouterException('unable to get the challenge from the router');
76 * login into the router with the given password
78 * @param string $password
81 public function login ($password) {
82 $this->challenge
= $this->getChallenge();
84 $path = 'data/Login.json';
85 $this->hash
= hash('sha256', $this->challenge
.':'.$password);
86 $fields = array('csrf_token' => 'nulltoken', 'showpw' => 0, 'password' => $this->hash
);
87 $data = $this->sentRequest($path, $fields);
88 $json = $this->getValues($data['body']);
90 if (isset($json['login']) && $json['login'] == 'success') {
91 $this->cookie
= $this->getCookie($data);
93 $this->derivedk
= $this->getDerviedk($password);
96 $this->token
= $this->getToken();
98 if ($this->checkLogin(false) === true) {
107 * check if we are logged in
109 * @param boolean $exception
112 public function checkLogin ($exception = true) {
113 // check if challenge or session is empty
114 if (empty($this->challenge
) ||
empty($this->cookie
)) {
115 if ($exception === true) {
116 throw new RouterException('you musst be logged in to use this method');
122 $path = 'data/SecureStatus.json';
124 $data = $this->sentRequest($path, $fields, true);
125 $data = $this->getValues($data['body']);
127 if ($data['loginstate'] != 1) {
128 if ($exception === true) {
129 throw new RouterException('you musst be logged in to use this method');
143 public function logout () {
146 $path = 'data/Login.json';
147 $fields = array('csrf_token' => $this->token
, 'logout' => 'byby');
148 $data = $this->sentRequest($path, $fields, true);
149 $data = $this->getValues($data['body']);
150 if ((isset($data['status']) && $data['status'] == 'ok') && $this->checkLogin(false) === false) {
151 // reset challenge and session
152 $this->challenge
= '';
155 $this->derivedk
= '';
168 public function reboot () {
171 $path = 'data/Reboot.json';
172 $fields = array('csrf_token' => $this->token
, 'reboot_device' => 'true');
173 $data = $this->sentEncryptedRequest($path, $fields, true);
174 $data = $this->getValues($data['body']);
176 if ($data['status'] == 'ok') {
177 // reset challenge and session
178 $this->challenge
= '';
181 $this->derivedk
= '';
183 // throw an exception because router is unavailable for other tasks
184 // like $this->logout() or $this->checkLogin
185 throw new RebootException('Router Reboot');
192 * change dsl connection status
194 * @param string $status
197 public function changeDSLStatus ($status) {
200 $path = 'data/Connect.json';
202 if ($status == 'online' ||
$status == 'offline') {
203 $fields = array('csrf_token' => 'nulltoken', 'showpw' => 0, 'password' => $this->hash
, 'req_connect' => $status);
204 $data = $this->sentRequest($path, $fields, true);
205 $data = $this->getValues($data['body']);
207 if ($data['status'] == 'ok') {
215 throw new RouterException('unknown status');
220 * change lte connection status
222 * @param string $status
225 public function changeLTEStatus ($status) {
226 throw new Exception('unstable funtion');
227 $path = 'data/Modules.json';
229 if ($status == '0' ||
$status == '1' ||
$status == 'yes' ||
$status == 'no') {
230 if ($status == 'yes') $status = '1';
231 else if ($status == 'no') $status = '0';
233 $fields = array('csrf_token' => $this->token
, 'use_lte' => $status);
234 $data = $this->sentEncryptedRequest($path, $fields, true);
240 throw new RouterException('unknown status');
245 * get phone book entrys
249 public function getPhoneBookEntrys () {
250 $data = $this->getData('PhoneBook');
251 $data = $this->getValues($data);
253 if (isset($data['addbookentry'])) {
254 return $data['addbookentry'];
262 * get uptime based on online (connection) time
266 public function getUptime () {
267 $data = $this->getData('LAN');
268 $data = $this->getValues($data);
270 return $data['days_online'];
274 * return the given json as array
276 * @param string $file
279 public function getData ($file) {
280 if ($file != 'Status') $this->checkLogin();
282 $path = 'data/'.$file.'.json';
284 $data = $this->sentRequest($path, $fields, true);
286 return $data['body'];
290 * get the router syslog
294 public function getSyslog() {
295 $data = $this->getData('SystemMessages');
296 $data = $this->getValues($data);
298 if (isset($data['addmessage'])) {
299 return $data['addmessage'];
307 * get the Missed Calls from router
311 public function getMissedCalls() {
312 $data = $this->getData('PhoneCalls');
313 $data = $this->getValues($data);
315 if (isset($data['addmissedcalls'])) {
316 return $data['addmissedcalls'];
324 * get the Taken Calls from router
328 public function getTakenCalls() {
329 $data = $this->getData('PhoneCalls');
330 $data = $this->getValues($data);
332 if (isset($data['addtakencalls'])) {
333 return $data['addtakencalls'];
341 * get the Dialed Calls from router
345 public function getDialedCalls() {
346 $data = $this->getData('PhoneCalls');
347 $data = $this->getValues($data);
349 if (isset($data['adddialedcalls'])) {
350 return $data['adddialedcalls'];
362 public function reconnectLte () {
365 $path = 'data/modules.json';
366 $fields = array('csrf_token' => $this->token
, 'lte_reconn' => '1');
367 $data = $this->sentEncryptedRequest($path, $fields, true);
369 return $data['body'];
373 * reset the router to Factory Default
378 public function resetToFactoryDefault () {
381 $path = 'data/resetAllSetting.json';
382 $fields = array('csrf_token' => 'nulltoken', 'showpw' => 0, 'password' => $this->hash
, 'reset_all' => 'true');
383 $data = $this->sentRequest($path, $fields, true);
385 return $data['body'];
390 * check if firmware is actual
394 public function checkFirmware () {
397 $path = 'data/checkfirmware.json';
398 $fields = array('checkfirmware' => 'true');
399 $data = $this->sentRequest($path, $fields, true);
401 return $data['body'];
405 * decrypt data from router
407 * @param string $data
410 private function decrypt ($data) {
411 $iv = hex2bin(substr($this->challenge
, 16, 16));
412 $adata = hex2bin(substr($this->challenge
, 32, 16));
413 $key = hex2bin($this->derivedk
);
414 $enc = hex2bin($data);
416 $factory = new CryptLib\Cipher\
Factory();
417 $aes = $factory->getBlockCipher('rijndael-128');
419 $mode = $factory->getMode('ccm', $aes, $iv, [ 'adata' => $adata, 'lSize' => 7]);
421 $mode->decrypt($enc);
423 return $mode->finish();
427 * decrypt data for the router
429 * @param string $data
432 private function encrypt ($data) {
433 $iv = hex2bin(substr($this->challenge
, 16, 16));
434 $adata = hex2bin(substr($this->challenge
, 32, 16));
435 $key = hex2bin($this->derivedk
);
437 $factory = new CryptLib\Cipher\
Factory();
438 $aes = $factory->getBlockCipher('rijndael-128');
440 $mode = $factory->getMode('ccm', $aes, $iv, [ 'adata' => $adata, 'lSize' => 7]);
441 $mode->encrypt($data);
443 return bin2hex($mode->finish());
447 * get the values from array
449 * @param array $array
452 private function getValues($array) {
454 foreach ($array as $item) {
455 // thank you telekom for this piece of shit
456 if ($item['vartype'] == 'template') {
457 if (is_array($item['varvalue'])) {
458 $data[$item['varid']][] = $this->getValues($item['varvalue']);
461 // i dont know if we need this
462 $data[$item['varid']] = $item['varvalue'];
466 if (is_array($item['varvalue'])) {
467 $data[$item['varid']] = $this->getValues($item['varvalue']);
470 $data[$item['varid']] = $item['varvalue'];
479 * sends the encrypted request to router
481 * @param string $path
482 * @param mixed $fields
483 * @param string $cookie
486 private function sentEncryptedRequest ($path, $fields, $cookie = false) {
487 $count = count($fields);
488 $fields = $this->encrypt(http_build_query($fields));
489 return $this->sentRequest($path, $fields, $cookie, $count);
493 * sends the request to router
495 * @param string $path
496 * @param mixed $fields
497 * @param string $cookie
498 * @param integer $count
501 private function sentRequest ($path, $fields, $cookie = false, $count = 0) {
502 $url = $this->url
.$path.'?lang=en';
504 curl_setopt($ch, CURLOPT_URL
, $url);
506 if (!empty($fields)) {
507 if (is_array($fields)) {
508 curl_setopt($ch, CURLOPT_POST
, count($fields));
509 curl_setopt($ch, CURLOPT_POSTFIELDS
, http_build_query($fields));
512 curl_setopt($ch, CURLOPT_POST
, $count);
513 curl_setopt($ch, CURLOPT_POSTFIELDS
, $fields);
517 if ($cookie === true) {
518 curl_setopt($ch, CURLOPT_COOKIE
, 'lang=en; challengev='.$this->challenge
.'; '.$this->cookie
);
521 curl_setopt($ch, CURLOPT_RETURNTRANSFER
, true);
522 curl_setopt($ch, CURLOPT_HEADER
, true);
524 $result = curl_exec($ch);
526 $header_size = curl_getinfo($ch, CURLINFO_HEADER_SIZE
);
527 $header = substr($result, 0, $header_size);
528 $body = substr($result, $header_size);
531 // check if response is empty
533 throw new RouterException('empty response');
536 // check if body is encrypted (hex instead of json)
537 if (ctype_xdigit($body)) {
538 $body = $this->decrypt($body);
542 $body = preg_replace("/(\r\n)|(\r)/", "\n", $body);
543 $body = preg_replace('/\'/i', '"', $body);
544 $body = preg_replace("/\[\s+\]/i", '[ {} ]', $body);
545 $body = preg_replace("/},\s+]/", "}\n]", $body);
548 if (strpos($url, '.json') !== false) {
549 $body = json_decode($body, true);
552 return array('header' => $this->parse_headers($header), 'body' => $body);
560 private function getToken () {
563 $path = 'html/content/overview/index.html';
565 $data = $this->sentRequest($path, $fields, true);
567 $a = explode('csrf_token = "', $data['body']);
568 $a = explode('";', $a[1]);
570 if (isset($a[0]) && !empty($a[0])) {
574 throw new RouterException('unable to get csrf_token');
579 * calculate the derivedk
581 * @param string $password
584 private function getDerviedk ($password) {
587 // calculate derivedk
588 if (!function_exists('hash_pbkdf2')) {
589 $pbkdf2 = new CryptLib\Key\Derivation\PBKDF\
PBKDF2(array('hash' => 'sha1'));
590 $derivedk = bin2hex($pbkdf2->derive(hash('sha256', $password), substr($this->challenge
, 0, 16), 1000, 32));
591 $derivedk = substr($derivedk, 0, 32);
594 $derivedk = hash_pbkdf2('sha1', hash('sha256', $password), substr($this->challenge
, 0, 16), 1000, 32);
597 if (empty($derivedk)) {
598 throw new RouterException('unable to calculate derivedk');
605 * get cookie from header data
610 private function getCookie ($data) {
612 if (isset($data['header']['Set-Cookie']) && !empty($data['header']['Set-Cookie'])) {
613 preg_match('/^.*(SessionID_R3=[a-z0-9]*).*/i', $data['header']['Set-Cookie'], $match);
614 if (isset($match[1]) && !empty($match[1])) {
619 if (empty($cookie)) {
620 throw new RouterException('unable to get the session cookie from the router');
627 * parse the curl return header into an array
629 * @param string $response
632 private function parse_headers($response) {
634 $header_text = substr($response, 0, strpos($response, "\r\n\r\n"));
636 $header_text = explode("\r\n", $header_text);
637 foreach ($header_text as $i => $line) {
639 $headers['http_code'] = $line;
642 list ($key, $value) = explode(': ', $line);
643 $headers[$key] = $value;