Register Guidelines E-Books Search Today's Posts Mark Forums Read

Go Back   MobileRead Forums > E-Book Readers > Amazon Kindle > Kindle Developer's Corner

Notices

Reply
 
Thread Tools Search this Thread
Old 06-17-2012, 04:19 PM   #1
Oneill
Junior Member
Oneill began at the beginning.
 
Posts: 5
Karma: 10
Join Date: Jun 2012
Device: Kindle touch
Kindle touch 5.1.0 SSH password

Hi all,
i need an advice regarding SSH to my Kindle touch 5.1.0 firmware. All information at this forum were very usefull, I was able to jailbreak, install SSH and connect to device using putty.

Unfortunately neither mario nor fiona or fionaxxx with numbers works for me to get inside as root. I was able to get into device as framework user with mario password, but I cant change password for root using this account.

I tried passwd root but I get "Must be suid to work properly" message. Im more to windows environment then unix but this seems like framework account does not have sufficient rights.
After that I did cat /etc/shadow and run result through John The Ripper using dictionary attack containing fiona+3 digit number combinations. Unsuccessfuly
I also tried ;un password command via kindle web browser but this seems to have no effect. Am I doing something wrong here? Password should have been empty If I understood instructions correctly

Sorry if I messed something, this is my first post to this forum

Last edited by Oneill; 06-17-2012 at 05:35 PM. Reason: text
Oneill is offline   Reply With Quote
Old 06-17-2012, 04:58 PM   #2
knc1
Helpdesk Junkie
knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.
 
knc1's Avatar
 
Posts: 7,001
Karma: 6327868
Join Date: Feb 2012
Device: Too many.
As a new user of this forum...
Hint: Line breaks are cheap here, no extra charge if you use them in the body of your text.
knc1 is offline   Reply With Quote
Old 06-17-2012, 05:31 PM   #3
geekmaster
Всё гениальное просто.
geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.
 
geekmaster's Avatar
 
Posts: 5,070
Karma: 6789001
Join Date: Nov 2011
Location: Щедрость не имеет пределов.
Device: *.*
The framework user account is VERY limited in what it can do. About the only useful thing is "cat /etc/shadow".

Question: did you ever CHANGE the password? If so, you may need a (lengthy) john brute-force cracking session (no wordlist)...

In case you ever changed the password to fionaXXXX (4 hex digits) I also have a wordlist with 4 hex digits (if the posted one is missing them).

Last edited by geekmaster; 06-17-2012 at 05:33 PM.
geekmaster is offline   Reply With Quote
Old 06-17-2012, 05:42 PM   #4
Oneill
Junior Member
Oneill began at the beginning.
 
Posts: 5
Karma: 10
Join Date: Jun 2012
Device: Kindle touch
Hi geekmaster, thanks for reply. No I did not change the password. Why 4 hex digits? I thought that max pass length is 8 chars. Could you please provide me the list? I would like to give it a try. Thanks a lot.

@knc1: you are right indeed. I did some visual changes
Oneill is offline   Reply With Quote
Old 06-17-2012, 05:46 PM   #5
knc1
Helpdesk Junkie
knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.
 
knc1's Avatar
 
Posts: 7,001
Karma: 6327868
Join Date: Feb 2012
Device: Too many.
Quote:
Originally Posted by Oneill View Post
@knc1: you are right indeed. I did some visual changes
Thanks.
Nothing personal, yours just happened to not be the first "mind dump" post that showed up here today.
knc1 is offline   Reply With Quote
Old 06-17-2012, 05:50 PM   #6
geekmaster
Всё гениальное просто.
geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.
 
geekmaster's Avatar
 
Posts: 5,070
Karma: 6789001
Join Date: Nov 2011
Location: Щедрость не имеет пределов.
Device: *.*
Quote:
Originally Posted by Oneill View Post
Hi geekmaster, thanks for reply. No I did not change the password. Why 4 hex digits? I thought that max pass length is 8 chars. Could you please provide me the list? I would like to give it a try. Thanks a lot.

@knc1: you are right indeed. I did some visual changes
There are a lot of FALSE reports of kindles using fionaXXXX (including the PW generating javascript page). If somebody changes their password, it always stores the new password as a salted MD5 hash which encodes all characters entered, not just the first 8 characters like the simple DES hash used for default root passwords.

It would ONLY have 4 hex digits IF you changed your password to use 4 hex digits.

I just downloaded the wordlist and it contains all possible fionaXXX and fionaXXXX passwords. It does not contain "mario" though, so you may want to add that to your list. No need for a new list. If you used a different list, download it from master index / tools index.

If you did not change your password, this is the first reported case of amazon CHANGING a password, or the first reported case of a kindle coming with a DIFFERENT password (not mario or fionaXXX).

If you can send me your shadow file, I can try cracking it when I have time.
geekmaster is offline   Reply With Quote
Old 06-17-2012, 06:10 PM   #7
Oneill
Junior Member
Oneill began at the beginning.
 
Posts: 5
Karma: 10
Join Date: Jun 2012
Device: Kindle touch
Thank you for help! The problem was my password list. I generated one myself using C# and I forgot to put hex letters to lowercase All is working now, I got the password. Thanks again.
Oneill is offline   Reply With Quote
Old 06-17-2012, 06:13 PM   #8
geekmaster
Всё гениальное просто.
geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.
 
geekmaster's Avatar
 
Posts: 5,070
Karma: 6789001
Join Date: Nov 2011
Location: Щедрость не имеет пределов.
Device: *.*
Quote:
Originally Posted by Oneill View Post
Thank you for help! The problem was my password list. I generated one myself using C# and I forgot to put hex letters to lowercase All is working now, I got the password. Thanks again.
You are welcome. Thank you for thanking me. It is always nice to feel appreciated (especially after being attacked by trolls in other forums).

Was your password DIFFERENT from the one generated by the kindle pw web page? If so, did you use all UPPERCASE serial number? The serial number is NOT printed on the case. It is in the settings menu.

Last edited by geekmaster; 06-17-2012 at 06:17 PM.
geekmaster is offline   Reply With Quote
Old 06-17-2012, 06:20 PM   #9
NiLuJe
BLAM!
NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.
 
NiLuJe's Avatar
 
Posts: 5,256
Karma: 5189261
Join Date: Jun 2010
Location: Paris, France
Device: Kindle 2i, 3g, 4, 5w, PW & PW2; Kobo H2O
Did you end up with something different than from the info command of kindletool?
NiLuJe is offline   Reply With Quote
Old 06-17-2012, 06:27 PM   #10
Oneill
Junior Member
Oneill began at the beginning.
 
Posts: 5
Karma: 10
Join Date: Jun 2012
Device: Kindle touch
final password for root was fiona1b6. I bought kindle just yesterday, so I did not have time to look through all forums and did not now that somebody already generated the list. I did my list in C# and when converting int to hex I forgot that it will be in uppercase. So my list contained fiona1B6, not fiona 1b6.

Yesterday when I found out that I must register device to make it fully functional I was pretty angry, had sleepless night so I did some reading on jailbreaking - will register manualy now, I dont mind the web browser. There is a lot stuff especially at this site, so I think you all are doing very good job. There are always few people who do not appreciate hard work, but the rest do
Oneill is offline   Reply With Quote
Old 06-17-2012, 06:40 PM   #11
geekmaster
Всё гениальное просто.
geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.
 
geekmaster's Avatar
 
Posts: 5,070
Karma: 6789001
Join Date: Nov 2011
Location: Щедрость не имеет пределов.
Device: *.*
Quote:
Originally Posted by Oneill View Post
final password for root was fiona1b6. I bought kindle just yesterday, so I did not have time to look through all forums and did not now that somebody already generated the list. I did my list in C# and when converting int to hex I forgot that it will be in uppercase. So my list contained fiona1B6, not fiona 1b6.

Yesterday when I found out that I must register device to make it fully functional I was pretty angry, had sleepless night so I did some reading on jailbreaking - will register manualy now, I dont mind the web browser. There is a lot stuff especially at this site, so I think you all are doing very good job. There are always few people who do not appreciate hard work, but the rest do
You can also COMPUTE the password, where the 3 hex digits a cut from the middle of the md5sum of the serial number, using the same algorithm as the web page uses.

My questions are still unanswered:
1) Did you use an all uppercase serial number with the "kindle password" web page?
2) Is your password different from the one generated by the web page?

Try the web page again, and compare the results to your pw. If needed, we want to update the algorithm used by the web page.
geekmaster is offline   Reply With Quote
Old 06-17-2012, 07:03 PM   #12
Oneill
Junior Member
Oneill began at the beginning.
 
Posts: 5
Karma: 10
Join Date: Jun 2012
Device: Kindle touch
I did not use web page to get the code. I tried it now but I have 5.1.0 firmware and web page shows only up to version 4.
Oneill is offline   Reply With Quote
Old 06-17-2012, 07:07 PM   #13
geekmaster
Всё гениальное просто.
geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.geekmaster ought to be getting tired of karma fortunes by now.
 
geekmaster's Avatar
 
Posts: 5,070
Karma: 6789001
Join Date: Nov 2011
Location: Щедрость не имеет пределов.
Device: *.*
Quote:
Originally Posted by Oneill View Post
I did not use web page to get the code. I tried it now but I have 5.1.0 firmware and web page shows only up to version 4.
There are no reports that the pw algorithm changed on newer kindles. It works on my 5.1.0 kindle. You can ignore that obsolete "up to" version statement on the web page.

Please try the PW web page to see if the PW for your serial number matches what you found with John. If the web page does not provide your kindle PW, please let us know. Thanks.

EDIT: The password web page INCORRECTLY reports fionaXXXX (4 hex digit) passwords, when default root passwords should ALWAYS be fionaXXX (3 hex digits). It does not hurt to type the extra digit, but it only adds to the confusion. Also, the mario password is not always tied to a specific firmware version. You should try it if the fionaXXX password does not work. When I reported the mario password and fionaXXX corrections to the website owner, he added them as additional OPTIONS, and arbitrarily tied them to specific versions, contrary to my suggestions (which only complicated the web page rather than simplifying it as I wanted). It is not under my control so I could not fix it myself.

Last edited by geekmaster; 06-17-2012 at 07:52 PM.
geekmaster is offline   Reply With Quote
Old 06-18-2012, 07:45 AM   #14
aditya3098
Vala
aditya3098 ought to be getting tired of karma fortunes by now.aditya3098 ought to be getting tired of karma fortunes by now.aditya3098 ought to be getting tired of karma fortunes by now.aditya3098 ought to be getting tired of karma fortunes by now.aditya3098 ought to be getting tired of karma fortunes by now.aditya3098 ought to be getting tired of karma fortunes by now.aditya3098 ought to be getting tired of karma fortunes by now.aditya3098 ought to be getting tired of karma fortunes by now.aditya3098 ought to be getting tired of karma fortunes by now.aditya3098 ought to be getting tired of karma fortunes by now.aditya3098 ought to be getting tired of karma fortunes by now.
 
aditya3098's Avatar
 
Posts: 596
Karma: 1578840
Join Date: Jan 2012
Location: Valinor
Device: Kindle touch (hacked to the core) 5.3.2.1
Considering you have usbnet installed, won't ;un password <password> in the search bar work?
aditya3098 is offline   Reply With Quote
Old 06-18-2012, 09:49 AM   #15
knc1
Helpdesk Junkie
knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.knc1 ought to be getting tired of karma fortunes by now.
 
knc1's Avatar
 
Posts: 7,001
Karma: 6327868
Join Date: Feb 2012
Device: Too many.
Quote:
Originally Posted by aditya3098 View Post
Considering you have usbnet installed, won't ;un password <password> in the search bar work?
Does not read as if it does:
Quote:
Originally Posted by post number 1
I also tried ;un password command via kindle web browser but this seems to have no effect. Am I doing something wrong here?
Perhaps just did not use the correct format of the command.
knc1 is offline   Reply With Quote
Reply

Tags
5.1.0, password, ssh, touch

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Kindle Touch USB Networking/SSH ChrisKaos Kindle Developer's Corner 55 02-22-2013 10:53 AM
Can't SSH Into Kindle Touch magnetik Kindle Developer's Corner 28 11-18-2012 09:59 AM
Kindle Touch SSH access? firite Kindle Developer's Corner 3 05-03-2012 10:36 AM
Problems typing wifi password with Kobo Touch standardrose Kobo Reader 1 12-09-2011 08:36 PM
iLiad dropbear ssh: how to change root password? daudi iRex Developer's Corner 2 01-10-2008 05:49 PM


All times are GMT -4. The time now is 12:15 AM.


MobileRead.com is a privately owned, operated and funded community.