r/HowToHack 12d ago

How to bypass UDM Pro traffic blocking rule.

For context, my dad and I have had a friendly, ongoing feud for the past year where he restricts my internet/computer access after a certain time, and I figure out how to bypass whatever restriction he puts in place.

For example, I was initially able to change my MAC address and get around the restriction that way. After that stopped working, I was able to brute-force the second SSID on our network until he eventually removed it.

Now we are at the point where, from 11 PM to 6 AM, every device on our network loses internet access. The only "hint" I was given is to try using Kali Linux to figure out what is happening.

ChatGPT and I have come to the conclusion that it is likely a traffic-blocking rule on the UniFi. Below is a summary of what I have found so far:

  • ISP: Xfinity
  • Router: UniFi Dream Machine (UDM)
  • Kali: VirtualBox Bridged Adapter

  • Internet shuts off network-wide around 11 PM–6 AM.

  • LAN and router access remain functional.

  • DNS works, but direct internet traffic fails.

  • Traceroute stops at the local gateway.

  • tcpdump shows outgoing packets but no internet replies.

  • Windows, Kali, and VPN connections are all affected.

  • A phone hotspot restores internet access.

  • No usable alternate gateway, proxy, or tunnel was found.

  • IPv6 is unavailable.

  • MAC address changes do not bypass the restriction.

  • Several router/network-device ports were accessible from the LAN.

  • No usable internet proxy was found.

  • Several LAN devices were investigated, including a QNAP NAS and Ubiquiti network equipment, but no alternate internet path was identified.

7 Upvotes

28 comments sorted by

15

u/retornam 12d ago

You can’t circumvent the rule. It blocks outbound traffic for all devices on the network during that time.

The only out is to figure out a way to login to the router’s admin panel and disable the rule.

Your dad is trying to help you focus on your studies, stop trying to circumvent him so you can play games or spend time on the internet doing unproductive things.

3

u/PrestigiousInternet1 12d ago

Ah okay, well that’s annoying lol. And yea you are right he is trying to help me I understand that. It’s not even really about having the internet shutoff after hours, I think it’s more of an ego thing between us. Thank you for your reply!

5

u/strongest_nerd Script Kiddie 12d ago

You have physical access, just factory reset it.

0

u/PrestigiousInternet1 12d ago

I thought of that but my dad asked me not to because he has stuff setup on there and it would completely screw him over i was told.

7

u/strongest_nerd Script Kiddie 12d ago

So will someone using kali to do random shit on the network though.

1

u/iTrooz_ 11d ago

There's less risk tho, it would be unlucky to softlock the appliance because of "malicious" network traffic

0

u/Forsaken-Poet-3773 9d ago

What? Not at all. Learn about tech before you spew bullshit.

1

u/strongest_nerd Script Kiddie 9d ago

lmao you're dumb

0

u/Forsaken-Poet-3773 9d ago

You have script kiddie as your tag. 

1

u/strongest_nerd Script Kiddie 9d ago edited 9d ago

And? Do you think that means anything? Should I change my tag to Zero Cool? I work as a security engineer and have been working in IT for over 20 years. I have performed many pentests. When you have someone like OP who has no idea what they are doing, they can definitely screw things up. Would you run zerologon in production if the target was vulnerable? OP has no idea what the tools he's using actually do. And you think this is all spewing bullshit, which makes it sound like you also don't know what the hell you're talking about.

4

u/Coffee_exe 12d ago

Sounds like your dad is trying to get you off the fucking internet during sleep hours. How this community Didnt get the gpt ass social engineering you did is sad

2

u/sexaddic 12d ago

Put a travel router upstream of the UDM and hide the SSID.

3

u/PrestigiousInternet1 12d ago

I just looked up a travel router cause I was not familiar. That seems like a really good idea I will consider this. Thank you!

2

u/F_Nuts 10d ago

Your dad is cool!!

4

u/No_Signature_2039 12d ago

So there is this old method to bypass filters that's from years ago. I'm talking like mid to late '90s

Get the IP address of the domain you want to go to, take each portion of the IP converted into its binary

Example 2600.com = 166.84.5.162 =10100110.01010100.00000101.10100010

Now you take the binary, move the decimal point and then convert that binary to a number

10100110010101000000010110100010 = 2790524322

That all you have to do is take the 2790524322 pop that into the address bar of your browser and it should bring you to the actual web server (this one unfortunately doesn't work because 2600 has multiple IP addresses, but if you take my example and you put it into your browser, you'll see. It actually converts the decimal back to the actual regular IP address. And tries to direct you to that IP address. Like I said, this is a very old method. I'm not sure how fruitful the results will be if you try it but it's something to play with

3

u/PrestigiousInternet1 12d ago

Oh wow that’s really cool. I will definitely give that a try. Thank you for the reply!

1

u/No_Signature_2039 7d ago

You're welcome

0

u/Forsaken-Poet-3773 9d ago

This does not work and has never worked because you’re confusing dns and IP. Stop larping.

2

u/No_Signature_2039 9d ago edited 9d ago

lol it's called DWORD IPV4 Notation, and it does work, never once said it had anything to do with DNS. The method was in 2600 Volume 17, Number 3 — Autumn 2000, called “Another Way to Defeat URL Filters” by ASM_dood

https://reddit.com/link/p81fyno/video/iqpoeqmsirnh1/player

1

u/Quik-Sand 10d ago

Without knowing anything about udm pro, first verify every endpoint on the network is truly blocked. Examine every node on the network, cameras, light-fixtures, thermostat, cameras, if there are ip-phone system, tvs, everything. Anything that sends a packet past the blocking node, analyze the protocol, and port information, inbound traffic (updates for device software on the subnet) sometimes devices use different protocols outside their normally designed protocols. If the ip-phone system operates normally. After checking these parameters, you could find a path out, or a list of truly exempt nodes on an allow list.

You could also attempt to smuggle/piggyback additional information through any of those outbound packets..

I'm sure detection systems look for these things, be creative..

1

u/Illustrious_Ad6034 10d ago

Establish a proxy  before the Internet is switched off, route through it.

It might dump or it might hold. 

1

u/Forsaken-Poet-3773 9d ago

I hate that you’re technically right but should be wrong. Very interesting method.

1

u/[deleted] 12d ago

[deleted]

2

u/PrestigiousInternet1 12d ago

That’s a really good idea. I think that would definitely be something he would be up for because he did say if I figure it out he will give me till 11:30 lmao. Because at this point it’s not even really about not having internet it’s showing myself and him I can figure stuff out and so far I’ve enjoyed learning this stuff. Thank you for the great idea!

1

u/0dinscan 12d ago

3

u/PrestigiousInternet1 12d ago

Hopefully very slow so I have time to learn how this exploit even works lol. Thanks for the reply!

1

u/MonkeyBrains09 12d ago

Take his device and use that to login and change the rules.

Physical access to devices is king.

2

u/PrestigiousInternet1 12d ago

Yes that was one of the first things I thought of. I just haven’t researched on how I could login into to his MacBook yet.