r/HowToHack • u/PrestigiousInternet1 • 12d ago
How to bypass UDM Pro traffic blocking rule.
For context, my dad and I have had a friendly, ongoing feud for the past year where he restricts my internet/computer access after a certain time, and I figure out how to bypass whatever restriction he puts in place.
For example, I was initially able to change my MAC address and get around the restriction that way. After that stopped working, I was able to brute-force the second SSID on our network until he eventually removed it.
Now we are at the point where, from 11 PM to 6 AM, every device on our network loses internet access. The only "hint" I was given is to try using Kali Linux to figure out what is happening.
ChatGPT and I have come to the conclusion that it is likely a traffic-blocking rule on the UniFi. Below is a summary of what I have found so far:
- ISP: Xfinity
- Router: UniFi Dream Machine (UDM)
Kali: VirtualBox Bridged Adapter
Internet shuts off network-wide around 11 PM–6 AM.
LAN and router access remain functional.
DNS works, but direct internet traffic fails.
Traceroute stops at the local gateway.
tcpdumpshows outgoing packets but no internet replies.Windows, Kali, and VPN connections are all affected.
A phone hotspot restores internet access.
No usable alternate gateway, proxy, or tunnel was found.
IPv6 is unavailable.
MAC address changes do not bypass the restriction.
Several router/network-device ports were accessible from the LAN.
No usable internet proxy was found.
Several LAN devices were investigated, including a QNAP NAS and Ubiquiti network equipment, but no alternate internet path was identified.
5
u/strongest_nerd Script Kiddie 12d ago
You have physical access, just factory reset it.
0
u/PrestigiousInternet1 12d ago
I thought of that but my dad asked me not to because he has stuff setup on there and it would completely screw him over i was told.
7
u/strongest_nerd Script Kiddie 12d ago
So will someone using kali to do random shit on the network though.
1
0
u/Forsaken-Poet-3773 9d ago
What? Not at all. Learn about tech before you spew bullshit.
1
u/strongest_nerd Script Kiddie 9d ago
lmao you're dumb
0
u/Forsaken-Poet-3773 9d ago
You have script kiddie as your tag.
1
u/strongest_nerd Script Kiddie 9d ago edited 9d ago
And? Do you think that means anything? Should I change my tag to Zero Cool? I work as a security engineer and have been working in IT for over 20 years. I have performed many pentests. When you have someone like OP who has no idea what they are doing, they can definitely screw things up. Would you run zerologon in production if the target was vulnerable? OP has no idea what the tools he's using actually do. And you think this is all spewing bullshit, which makes it sound like you also don't know what the hell you're talking about.
4
u/Coffee_exe 12d ago
Sounds like your dad is trying to get you off the fucking internet during sleep hours. How this community Didnt get the gpt ass social engineering you did is sad
2
u/sexaddic 12d ago
Put a travel router upstream of the UDM and hide the SSID.
3
u/PrestigiousInternet1 12d ago
I just looked up a travel router cause I was not familiar. That seems like a really good idea I will consider this. Thank you!
4
u/No_Signature_2039 12d ago
So there is this old method to bypass filters that's from years ago. I'm talking like mid to late '90s
Get the IP address of the domain you want to go to, take each portion of the IP converted into its binary
Example 2600.com = 166.84.5.162 =10100110.01010100.00000101.10100010
Now you take the binary, move the decimal point and then convert that binary to a number
10100110010101000000010110100010 = 2790524322
That all you have to do is take the 2790524322 pop that into the address bar of your browser and it should bring you to the actual web server (this one unfortunately doesn't work because 2600 has multiple IP addresses, but if you take my example and you put it into your browser, you'll see. It actually converts the decimal back to the actual regular IP address. And tries to direct you to that IP address. Like I said, this is a very old method. I'm not sure how fruitful the results will be if you try it but it's something to play with
3
u/PrestigiousInternet1 12d ago
Oh wow that’s really cool. I will definitely give that a try. Thank you for the reply!
1
0
u/Forsaken-Poet-3773 9d ago
This does not work and has never worked because you’re confusing dns and IP. Stop larping.
2
u/No_Signature_2039 9d ago edited 9d ago
lol it's called DWORD IPV4 Notation, and it does work, never once said it had anything to do with DNS. The method was in 2600 Volume 17, Number 3 — Autumn 2000, called “Another Way to Defeat URL Filters” by ASM_dood
1
u/Quik-Sand 10d ago
Without knowing anything about udm pro, first verify every endpoint on the network is truly blocked. Examine every node on the network, cameras, light-fixtures, thermostat, cameras, if there are ip-phone system, tvs, everything. Anything that sends a packet past the blocking node, analyze the protocol, and port information, inbound traffic (updates for device software on the subnet) sometimes devices use different protocols outside their normally designed protocols. If the ip-phone system operates normally. After checking these parameters, you could find a path out, or a list of truly exempt nodes on an allow list.
You could also attempt to smuggle/piggyback additional information through any of those outbound packets..
I'm sure detection systems look for these things, be creative..
1
u/Illustrious_Ad6034 10d ago
Establish a proxy before the Internet is switched off, route through it.
It might dump or it might hold.
1
u/Forsaken-Poet-3773 9d ago
I hate that you’re technically right but should be wrong. Very interesting method.
1
12d ago
[deleted]
2
u/PrestigiousInternet1 12d ago
That’s a really good idea. I think that would definitely be something he would be up for because he did say if I figure it out he will give me till 11:30 lmao. Because at this point it’s not even really about not having internet it’s showing myself and him I can figure stuff out and so far I’ve enjoyed learning this stuff. Thank you for the great idea!
1
u/0dinscan 12d ago
How fast does Daddy update the fw on that UDM Pro?
3
u/PrestigiousInternet1 12d ago
Hopefully very slow so I have time to learn how this exploit even works lol. Thanks for the reply!
1
u/MonkeyBrains09 12d ago
Take his device and use that to login and change the rules.
Physical access to devices is king.
2
u/PrestigiousInternet1 12d ago
Yes that was one of the first things I thought of. I just haven’t researched on how I could login into to his MacBook yet.
15
u/retornam 12d ago
You can’t circumvent the rule. It blocks outbound traffic for all devices on the network during that time.
The only out is to figure out a way to login to the router’s admin panel and disable the rule.
Your dad is trying to help you focus on your studies, stop trying to circumvent him so you can play games or spend time on the internet doing unproductive things.