*/
private $challenge = '';
+ /**
+ * csrf_token
+ * @var string
+ */
+ private $token = '';
+
/**
* hashed password
* @var string
*/
private $url = '';
+ /**
+ * derivedk cookie
+ * @var string
+ */
+ private $derivedk = '';
+
public function __construct ($password, $url = 'http://speedport.ip/') {
$this->url = $url;
$this->getChallenge();
throw new Exception('unable to get the session cookie from the router');
}
+ // calculate derivedk
+ $this->derivedk = hash_pbkdf2('sha1', hash('sha256', $password), substr($this->challenge, 0, 16), 1000, 32);
+
+ // get the csrf_token
+ $this->token = $this->getToken();
+
return true;
}
}
$fields = array('csrf_token' => 'nulltoken', 'showpw' => 0, 'password' => $this->hash, 'reboot_device' => 'true');
$cookie = 'challengev='.$this->challenge.'; '.$this->session;
$data = $this->sentRequest($path, $fields, $cookie);
+
$json = json_decode($data['body'], true);
return $json;
return explode("\n", $data['body']);
}
+ /**
+ * reconnect LTE
+ *
+ * @return array
+ */
+ public function reconnectLte () {
+ $path = 'data/modules.json';
+ $fields = array('csrf_token' => $this->token, 'lte_reconn' => '1');
+ $fields = $this->encrypt($fields);
+ $cookie = 'challengev='.$this->challenge.'; '.$this->session;
+ $data = $this->sentRequest($path, $fields, $cookie, 2);
+ $json = json_decode($data['body'], true);
+
+ return $json;
+ }
+
+ /*
+ // i dont want test this :D, feel free to test it and report if it works or not
+ public function resetToFactoryDefault () {
+ $path = 'data/resetAllSetting.json';
+ $fields = array('csrf_token' => 'nulltoken', 'showpw' => 0, 'password' => $this->hash, 'reset_all' => 'true');
+ $cookie = 'challengev='.$this->challenge.'; '.$this->session;
+ $data = $this->sentRequest($path, $fields, $cookie);
+ $json = json_decode($data['body'], true);
+
+ return $json;
+ }
+ */
+
+ /**
+ * check if firmware is actual
+ *
+ * @return array
+ */
+ public function checkFirmware () {
+ $path = 'data/checkfirmware.json';
+ $fields = array('checkfirmware' => 'true');
+ $cookie = 'challengev='.$this->challenge.'; '.$this->session;
+ $data = $this->sentRequest($path, $fields, $cookie);
+
+ if (empty($data['body'])) {
+ throw new Exception('unable to get checkfirmware data');
+ }
+
+ $json = json_decode($data['body'], true);
+
+ return $json;
+ }
+
+ /**
+ * decrypt data from router
+ *
+ * @param string $data
+ * @return array
+ */
+ public function decrypt ($data) {
+ require_once 'CryptLib/CryptLib.php';
+ $factory = new CryptLib\Cipher\Factory();
+ $aes = $factory->getBlockCipher('rijndael-128');
+
+ $iv = hex2bin(substr($this->challenge, 16, 16));
+ $adata = hex2bin(substr($this->challenge, 32, 16));
+ $dkey = hex2bin($this->derivedk);
+ $enc = hex2bin($data);
+
+ $aes->setKey($dkey);
+ $mode = $factory->getMode('ccm', $aes, $iv, [ 'adata' => $adata, 'lSize' => 7]);
+
+ $mode->decrypt($enc);
+
+ return $mode->finish();
+ }
+
+ /**
+ * decrypt data for the router
+ *
+ * @param array $data
+ * @return string
+ */
+ public function encrypt ($data) {
+ require_once 'CryptLib/CryptLib.php';
+ $factory = new CryptLib\Cipher\Factory();
+ $aes = $factory->getBlockCipher('rijndael-128');
+
+ $iv = hex2bin(substr($this->challenge, 16, 16));
+ $adata = hex2bin(substr($this->challenge, 32, 16));
+ $dkey = hex2bin($this->derivedk);
+
+ $aes->setKey($dkey);
+ $mode = $factory->getMode('ccm', $aes, $iv, [ 'adata' => $adata, 'lSize' => 7]);
+ $mode->encrypt(http_build_query($data));
+
+ return bin2hex($mode->finish());
+ }
+
/**
* sends the request to router
*
* @param string $path
- * @param array $fields
+ * @param mixed $fields
* @param string $cookie
+ * @param integer $count
* @return array
*/
- private function sentRequest ($path, $fields = array(), $cookie = '') {
+ private function sentRequest ($path, $fields, $cookie = '', $count = 0) {
$url = $this->url.$path;
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, $url);
if (!empty($fields)) {
- curl_setopt($ch, CURLOPT_POST, count($fields));
- curl_setopt($ch, CURLOPT_POSTFIELDS, http_build_query($fields));
+ if (is_array($fields)) {
+ curl_setopt($ch, CURLOPT_POST, count($fields));
+ curl_setopt($ch, CURLOPT_POSTFIELDS, http_build_query($fields));
+ }
+ else {
+ curl_setopt($ch, CURLOPT_POST, $count);
+ curl_setopt($ch, CURLOPT_POSTFIELDS, $fields);
+ }
}
if (!empty($cookie)) {
curl_close($ch);
// fix invalid json
+
$body = preg_replace("/(\r\n)|(\r)/", "\n", $body);
$body = preg_replace('/\'/i', '"', $body);
$body = preg_replace("/\[\s+\]/i", '[ {} ]', $body);
return array('header' => $this->parse_headers($header), 'body' => $body);
}
+ /**
+ * get the csrf_token
+ *
+ * @return string
+ */
+ private function getToken () {
+ $path = 'html/content/overview/index.html?lang=de';
+ $fields = array();
+ $cookie = 'challengev='.$this->challenge.'; '.$this->session;
+ $data = $this->sentRequest($path, $fields, $cookie);
+
+ if (empty($data['body'])) {
+ throw new Exception('unable to get csrf_token');
+ }
+
+ $a = explode('csrf_token = "', $data['body']);
+ $a = explode('";', $a[1]);
+
+ if (isset($a[0]) && !empty($a[0])) {
+ return $a[0];
+ }
+ else {
+ throw new Exception('unable to get csrf_token');
+ }
+ }
+
/**
* parse the curl return header into an array
*