Recent content by Midsteelblue

  1. M

    Reverse engineering Hikvision DVR firmware

    Finally got it to work! The issue ended up being the header CRC. Once everything was repacked I was manually changing the devclass to 0x1e but I wasn't updating the header CRC... Once I did that it was worked. Hikpack works fine using the k41 switch but needs an option for defining the...
  2. M

    Reverse engineering Hikvision DVR firmware

    I'll have a good play with this today and look around what you've mentioned. Thank you again by the way for taking the time to respond. Had anyone managed to modify the zImage within the uImage file? I wanted to see if there was a way to keep the password and configuration after upgrading the...
  3. M

    Reverse engineering Hikvision DVR firmware

    If I remember right the hikpack didn't decrypt the new_20 file. Is it encrypted in the same way the header is? p.s out of curiosity, how is the header encrypted? Read something about the first 15 bytes being an XOR key which shifts left every rotation?
  4. M

    Reverse engineering Hikvision DVR firmware

    I have been wanting to take apart my Hikvision DVR (DS-7204 HGHI-SH) and I have finally begun by using the hikpack tool by @montecrypto amoungst several others (binwalk, mkcramfs, bless) Firstly hikpack doesn't directly support this DVR but I have got round that mostly... but this is where I...
Top