Attack Proof of Concept (Alcatel Link Zone / 4GEE WIFI)


  1. SMS Gateway




  2. USSD Gateway




  3. SMS Redirection



  4. XSS Profile

    After the injection, go to http://192.168.8.1/default.html#settings/profileManagement.html

  5. Remove **ALL** SMS

  6. Restart device

  7. Change network interfaces




    The second interface is off by default. Unfortunately, despite the inclusion of the interface doesn't work :(

    More information: http://192.168.8.1/goform/getUsbIP

Additional links

  1. Login & password: http://192.168.8.1/goform/getPasswordSaveInfo
  2. System information: http://192.168.8.1/goform/getSysteminfo
  3. Auto redirect settings: http://192.168.8.1/goform/getSMSAutoRedirectSetting