« Back to all recent discussions

Unable to change admin password via GUI on NAS326

Cooper_CCooper_C Posts: 13  Junior Member
edited December 2017 in Discussions
When logging into box via web GUI with default password, I'm prompted to change the admin password.  After entering in new password and click apply, the change password window just hangs instead of being redirected to the login page.  Firmware is v5.20.  I get the same symptom when trying to add a user.

#NAS_December

Comments

  • RoryRory Posts: 120  Warrior Member
    @Cooper_C

    Did you try to use other browser?
    Maybe the action be limited by browser.
  • Cooper_CCooper_C Posts: 13  Junior Member
    @Rory

    Found out something interesting with the password. If I use 15 characters the page hangs even though the hint suggest 8 or more characters. I saw a quick notice flash up about 14 characters. I used 14 characters and was taken back to the login page, but the new password didn't stick. Admin password still at default.  Changing the admin password via the terminal doesn't stick either.
  • WiasoudaWiasouda Posts: 147  Warrior Member
    @Cooper_C
    I see your comment in other topic, you have change the root password via terminal, so I think the account information might not match between GUI and terminal.
    So you should reset your admin setting, press reset button with 1 beep, and release to try again.
    If the problem still exist, that you may need to reset all configuration with 3 beep and hold 5 sec then release the button, the process would not delete your data, but you have to enable the shard folder.
  • Cooper_CCooper_C Posts: 13  Junior Member
    @Wiasouda
    Wow! Had to do the 3 beep reset and the password stuck that time. Was able to add myself as a user as long as I didn't exceed the 14 character limit on the password. Cycled the power on the box to verify the new admin password worked and user was still there. Thanks for the tip.
  • PhilipPhilip Posts: 1
    I had same problem. I tried changing password to just 8 numbers and it worked.
  • DKarmakarDKarmakar Posts: 2  Junior Member
    edited March 16
    Hi...
    First do remove all HDisks one by one from NAS, marked all HDisks1 to 4 without fail .
    Press Reset button on Back Panel, till to 2nd Beep.
    Install NAS starter utility on you Computer to Get connect NAS through LAN with you PC directly.
    Without Hard Disks (on RAID), some features will not work, don't worry, Just Go to Reset Password, Your default password is 1234.
    After successful reset of Admin Password, Plug all Hdisks as per Array/RAID Nos.
    The Volume might be Start to Re-Sync, let it be & Don;t shutdown NAS until the Re-Sync process will be over...
    Enjoy your NAS, your Data will be as same as Previous..   

  • ChefkochChefkoch Posts: 2  Junior Member
  • JassuJassu Posts: 5  Junior Member
    Ok, a problem... When I press the reset-button and hear 1 beep, it won't change the password and IP back to original. I read that after releasing the button you should hear another beep - there's none.

    When login to SSH with admin account I can turn myself to root and change the password with smbpasswd - login to GUI works now. I can also try to change admin password with paswd to sync it with the one changed with smbpasswd.

    Next step: I know that I would need to change the password in GUI to get it permanent (smbpasswd change in CLI won't last through a reboot) when the system asks for old and new passwords the old password would need still to be the one with special characters, and obviously it is not working. We end up here in a error situation.

    So what now? I have lots of accounts and confs and would not want to go factory reset.
  • MijzelfMijzelf Posts: 1,073  Heroic Warrior Member
    When logged in as admin, you can change the passwords of all users without providing the current password.
    Then you can reset the current password of admin using a 'single beep' reset.

    If you don't want to use that single beep reset, you can try to edit the internal database. The user configuration is stored in /etc/zyxel/ugs_conf.db, which is a sqlite3 file. The commandline tool sqlite3 is available on the box, yet I don't know how to use it. When executing

    sqlite3 /etc/zyxel.ugs_conf.db
    .dump

    you can see the contents. The password hashes are the same as those in /etc/samba/smbpasswd. I suppose it should be able to overwrite the admin password with that from smbpasswd.

  • JassuJassu Posts: 5  Junior Member
    You can change all the user passwords without knowing the old one, except the preinstalled admin-users. For that you need to know the old one.

    Even after reboot, using other admin account (I enabled admin-rights for another user) the "single beep reset" is still not working - so it seems that probably only way is to tweak the db?

    bunny Zyxel, how the h*ll you are making these kind of updates that break things?
  • JassuJassu Posts: 5  Junior Member
    As on option trying also to find a possibility to downgrade the firmware to version  V5.21(AAZF.6)C0 where the admin password change would work. And after that I could do the upgrade again.
  • MijzelfMijzelf Posts: 1,073  Heroic Warrior Member
    bunny Zyxel, how the h*ll you are making these kind of updates that break things?

    They were facing an actively exploited zeroday. Just leave it was not an option.

    As on option trying also to find a possibility to downgrade the firmware to version  V5.21(AAZF.6)C0 where the admin password change would work. And after that I could do the upgrade again.
    Sounds like a plan.
  • JassuJassu Posts: 5  Junior Member
    The system wont allow donwgrades, so it seems that path is not working.

    I understand they could not leave it like that, but now the thing is that admin-password is impossible to change if "one beep reset" is not working. At least they could allow that admin-account pw change without knowing the old one.
  • MijzelfMijzelf Posts: 1,073  Heroic Warrior Member
    You can downgrade if your first execute

    echo 1 > /firmware/mnt/info/revision

  • JassuJassu Posts: 5  Junior Member
    Cheers mate! That solved the thing :smile:

    So what I did...

    1)  connected via ssh to NAS and executed : "echo 1 > /firmware/mnt/info/revision"

    2) Downloaded older FW from Zyxel's archive

    3) login to NAS GUI with alternative admin account (not user called 'admin')

    4) Downgraded the FW via manual upload

    5) login to admin with old admin account with a password containing special characters (that were not allowed anymore)

    6) changed password to non-special-character one (with this FW it was ok to give that special pw as an old one).

    7) installed latest FW version again.

    ... all good.
Sign In or Register to comment.