Linksys PAP2 locked to Vonage, support people funny

Sep 08, 2004 55 Replies

Based on reading the fragments of information spread across many sites

and newsgroups, it's apparent *someone* knows the steps involved in

getting into these things!

The mysterious post on linuxvoip.info leads me to believe that all can

be found by sniffing packets and perhaps some tftp craftiness

(although the message on linuxvoip.info doesn't mention anything

other than utilizing ethereal). The problem with that is after the

tftp requests, the pap2 just site there and doesn't try again.

Someone mentioned that it may make a request for an unencrypted file,

but so far all tftp requests to ls.tftp.vonage.net are for the

mac-based .xml file.

Anyone have some new thoughts? How about a source for a basic,

unencrypted xml config file?

You can dl a copy of a recent release here:

formatting link

But I'm tellin' ya, there's no way to get it onto a "locked" pap2,

that I've found anyway.

You can't simply rename it to the filename requested via tftp at boot.

It starts to transfer then errors out before comletion..probably

beacuse the device isn't expecting a firmware file, it's expecting a

config file.

The is a way to upload firmware to the pap2 via the web interface, but

it requires the admin password...which is the problem we have in the

first place.

I just want to get this thing working with my Asterisk server..I

already have Vontage on another device. But if I can't get it

working, I'm cancelling Vontage and buying a pap2-na and going with

another provider.

Could you please send me the PAP2-NA firmware? (.bin?)

I noticed that the device says it has a certificate installed. I'm assuming this is what's used to authenticate/decrypt the .xml config file the device is trying to load. If that's the case, then the configs are likely signed with a key unique to vonage, and that pretty much ends that direction. I think that will likely prevent the loading of some generic, yet properly compiled config file, since it won't be signed by vonage's key.

Besides the PAP2 provided by vonage (and which we all here are trying to unlock) I also have a PAP2-NA, that was provided by my local VoIP provider, and which I've reset once with the RESET# command (no password asked). That, indeed reseted the unit, was able to make it into the admin pages. And it also has the Client Certificate:Installed thing. This unit doesnt download any particular configuration. It's just configured by hand using SIP proxy, user & password.

By the way, let's suppose I want to cancel my account with Vonage. My credit card is "broken" (doesn't allow any charges). Vonage tries to charge me $40 disconnection fee.. And it cant do it... What happens then? Does Vonage like sue you to obtain the money? or just nothing happens at all and you just keep a useless pap2 ?

thanks.

Naw, that's not really possible...but I wouldn't be surpised if there were some "backdoor" somewhere in the http interface.

Still stumped....

Isn't there a way to trick the .htaccess file inside this thing to allow access to the /admin directory? That's how the authentication works, doesn't it?

Isn't there a way to trick the .htaccess file inside this thing to

allow access to the /admin directory? That's how the authentication

works, doesn't it?

I'm sure they will send you to collections unless you talk them out of

the fee.

As far as the certificate goes, I now believe it's only in place to

enable HTTPS transfers of config info if the provider chooses that

mechanism.

I still haven't made any more progress on this thing..

[quote:e93d20b655="summiter"]I noticed that the device says it has a

certificate installed. I'm assuming this is what's used to

authenticate/decrypt the .xml config file the device is trying to

load. If that's the case, then the configs are likely signed with a

key unique to vonage, and that pretty much ends that direction. I

think that will likely prevent the loading of some generic, yet

properly compiled config file, since it won't be signed by vonage's

key.I noticed that the device says it has a certificate installed.

I'm assuming this is what's used to authenticate/decrypt the .xml

config file the device is trying to load. If that's the case, then

the configs are likely signed with a key unique to vonage, and that

pretty much ends that direction. I think that will likely prevent

the loading of some generic, yet properly compiled config file, since

it won't be signed by vonage's key.[/quote:e93d20b655]

Besides the PAP2 provided by vonage (and which we all here are trying

to unlock) I also have a PAP2-NA, that was provided by my local VoIP

provider, and which I've reset once with the RESET# command (no

password asked). That, indeed reseted the unit, was able to make it

into the admin pages. And it also has the Client

Certificate:Installed

thing. This unit doesnt download any particular configuration. It's

just configured by hand using SIP proxy, user & password.

By the way, let's suppose I want to cancel my account with Vonage. My

credit card is "broken" (doesn't allow any charges). Vonage tries to

charge me $40 disconnection fee.. And it cant do it... What happens

then? Does Vonage like sue you to obtain the money? or just nothing

happens at all and you just keep a useless pap2 ?

thanks.[/quote:e93d20b655]

Is it really worth the effort when you can get a Sipura?

Well.. let's say that I want to make it worthy for the money I paid

for the PAP2... :(

Naw, that's not really possible...but I wouldn't be surpised if there

were some "backdoor" somewhere in the http interface.

Isn't there a way to trick the .htaccess file inside this thing to

allow access to the /admin directory? That's how the authentication

works, doesn't it?[/quote:44bc0aae47]

Figured out that my local VoIP provider doesn't configure the settings

by hand, but using a program that loads the config into the ATA.

For instance, when you go to the voice menu on the Linksys RT31P2 it

just says "Contact your service provider". No manual config

whatsoever...

I need to get my hands onto that proggie..

You think you're going to hack it! Not.

Anyone having any luck with this???

I really need to get this device unlocked, lol.

s suppose I want to cancel my account with Vonage. My

It's likely that they'll refer you to a collections agency: Vonage may or may not report the debt as unpaid to your credit report, then "sell" the debt to a collection agency, who then makes it their task to cajole, harrass and threaten you till you decide to pay up. If you have a strong will and don't mind a bad mark on your credit rating, then have at. :)

For me, it's not worth the hassle. If I ever cancel my Vonage service, they can have their useless PAP2 back.

It appears thought that the provider config is stored somewhere

outside of the main firmware, because despite flashing to different

versions, I am still prompted to enter a password for the admin

pages, and the device still makes requests to a vonage tftp server.

According to

formatting link
there's a "provisoning" option where you can specify where the pap2

should download it's configuration..

Hi All, I just read this one on the net, I do not have one handy to try. Would someone willing to try and post the results. Thanks.

UPDATE Well it appers that Vonage let ~some~ info slip this morning around

5am. The master reset is "73738" and the password is "7756112". for those of you who don't know what a master rest is (and all tose who have e-mailed me insted of trying the codes), it ONLY resets the unit BACK to the ORIGNAL factory settings. DON'T e-mail me with "your code didden't unlock my unit".. The next person who sends me an e-mail like that is going to get blasted!!!

I can get the PAP2 unlock unit. They sell for around $75.00. The ones

that are all ready locked by Vonage are not worth the trouble. I get

them directly from cisco.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required