Jump to content
Security Installer Community

JonnyB1971

Member
  • Posts

    19
  • Joined

  • Last visited

Posts posted by JonnyB1971

  1. 1 hour ago, sixwheeledbeast said:

    It's proprietary, this software is one of the main assets to the company; unlike other product manufacturers you mention.

    You're right of course. I shall end my pursuit of T-store vector.

     

    In my defence, I didn't want it for personal gain...well, except to gain precious minutes of my day back.

  2. 2 hours ago, MrHappy said:

    Unless they are a subscriber they won't get an antii code in the modern world of internet it's don't really matter

    I'm sorry, I'm not quite understanding what you mean.

     

    I've trawled through modules on Ollydbg and realised I just don't get assembly language (never have and probably never will)..and I've teawled my way through the VB code and all I found that could possibly be what I'm looking for is a bunch of sum variables that I can only assume come up with identical results every time the script is run.

     

    I'm fed up with getting phone calls asking for reset codes and having to try and find a code that works (because the ARC hasn't been setup with correct seed code)...

     

    I know, I know...security, blah blah blah, but when you can generate Orisec, Texecom, and even Gardtec reset rcodes from your Android device...FOR FREE!!! it just feels like a bind using the Galaxy way, when, at the end of the day, it's a reset that we offer free of charge and avoid a callout.

  3. On 27/05/2013 at 13:31, cybergibbons said:
    1,9,3,0,2,9,3,8,1,4,2,8,4,0,1,9,1,0,1,2,1,3,5,3,3,9,0,2,1,4,1,2,3,4,3,4,9,5,3,5,9,3,1,3,9,4,0,3,2,3,3,4,4,2,1

    Hi,

    I've been looking for this for weeks.  Unfortunately it's way beyond me.  Having loaded the exe into ollydbg and ILSpy I can only conclude that the vector is actually generated and I can't work out which bit of code generates it ?

  4. 10 hours ago, GalaxyGuy said:

     

    A tool that enters the Honeywell boot loader via Dimension / G3 RS232 port on boot. The Galaxy boot loader has a menu option to dump or write to memory in double words. The tool holds a list of address locations where the passwords are held (different firmware versions hold the codes and passwords at different offsets), or can also scan all of memory for them which takes longer.  Since these codes and passwords are plain text in memory, it can read them out or clear them.   To enter the boot loader, it does need the panel to be rebooted, so not a back door that compromises the panel. You can do it all manually from TTY, but it would take an age, so the program speeds things up.

    Yes this

     

    cheers all

     

  5. 52 minutes ago, al-yeti said:

    It's cheap and cheerful tho........ So company doesn't supply you with anything ? Or I guess self employed don't tool up

     

    eBay then sometimes although just as cheap to buy it with updated firmware

     

     

     

    I'll have another sesrch for it.  Yar, company won't pay for it...if I were self employed I'd just buy it I guess.

  6. 22 hours ago, al-yeti said:

    So what's rss telling you when you hit enter?

     

    And by now I assume you have bought spi key right ?

    Hi,

     

    It told me invalid password or something of the sort.

     

    Er..no...I don't get paid enough to just go and buy that kind gear unfortunately.

  7. 10 hours ago, james.wilson said:

    i assume its the remote password in the panel, not the rss program password

    Hi, yes I can access the Galaxy tool.  I've created a site. Upon trying to Dial the panel it requests a password as normal, but 'blank password' doesn't work as normal, nor does anything I found on site that may have been a password.

  8. 4 hours ago, james.wilson said:

    Different subject but a takeover should always be fully defaulted and reprogrammed to prevent issues like this.plus you dont know whats sparre off etc.

     

    however timstool?

    Tims tool...ah a cool piece of software... I don't think it's actually called that...buy I have seen people refer to it as that.

     

    RE: takeovers, can tou not just crash the codes and then remove comms programming? I mean it's not like anybody can do voicemail freaking from an alarm panel...or can they...duu duu duuuuu!

  9. 13 hours ago, james.wilson said:

    Sounds like it was a takeover without defaulting panel (dangerous and shouldn't be done Imo) 

    As it wasn't defaulted the comms programming is still calling home itself giving the previous provider with full remote access. 

    Only way to remove the password is to default. 

    Then only you can access etc

     

    Hi,

     

    I didn't do the take over, I'm guessing the engineer who did, just did a code crash.   

  10. 4 hours ago, PeterJames said:

    I was thinking the same, if the panel had been defaulted when it was taken over there would be no remote codes stopping you from taking a backup

    Hi,

     

    By 'defaulted' you mean fully defaulted or just codes?  I tried TimsTool and selected engineer and mgr code defaults...that didn't do the trick.

  11. 8 hours ago, al-yeti said:

    So what panel is it exactly, you got picture of label please?

    And your also not clear what codes you possess? User only ? Engineer? Master?

    Hi,

     

    It's a 520.  Our Engineer code is in, and we know the MGR code. Unsure about user codes, thats another reason I'd like RSS access.

    I didn't do the panel take over, I was there as a revisit to service it...I just like to get backups when I can...nobody else in our company uses the RSS software or can be bothered...I just like to because I can, well usually can. Haha

  12. SMH...*rolls eyes*

     

    I have connected to several Galaxys, I am aware that you ordinarily just use the blank password...it didn't work.

     

    Thanks for your input though, very helpful. (I wish there was some form of punctuation to alert the reader of sarcasm).

     

    Unfortunately I don't have the rs232 module or a dumpbox, or SPI key so can't go down that route either, which is why I was here asking a question. Didn't really fancy defaulting the panel just to take a backup...kinda defeats the object eh.  But with the log showing a rogue/unauthorized remote access I figured the issue needs to be addressed.

     

     

     

  13. Hi,

     

    Ex telecoms engineer, been playing the Electronic Security game for 2½ years now. Managed to bag myself a copy of HONEYWELL GALAXY RSS software and today encountered an ex ADT site.  We took over the alarm 18 months ago, but I'd never been to this site until today.  I thought I'd take a backup...turns out there's a password stopping me connecting.  Worryingly, after I went through the event log and saw, several weeks ago, a remote rss session doing a database save, I can only assume it was ADT accessing a site that they now no longer maintain.  Is there anyway I can bypass/remove/change this password does anybody know? Thanks

×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.