fs.com s5850 and s8050 series type switches have a secret mode which
lets you enter a regular shell from the switch cli, like so:
The command and password are not documented by the manufacturer,
i wondered wether if its possible to extract that password from
the firmware. After all: its my device, and i want to have access
to all the features!
Download the latest firmware image for those switch types and let binwalk do
its magic:
This will extract an regular cpio archive, including the switch root FS:
The extracted files include the passwd file with hashes:
Let john do its job:
Thats it (wont reveal the password here, but well: its an easy one ;))
Now have fun poking around on your switches firmware:
even tho the good things wont work, but i guess its time to update the firmware
anyways: