Recent content by montecarlo

  1. M

    Unauthenticated Remote Code Execution (RCE) vulnerability in Hikvision IP camera/NVR firmware (CVE-2021-36260)

    when reset to inactive then your camera become offline. I did it accidentally when I deleted both ipc_db and ipc_db_backup files. I guess davinci recreate both files automatically. Did you figure out how to add users without Web? I have access to ssh as root but couldn't figure out how to...
  2. M

    Unauthenticated Remote Code Execution (RCE) vulnerability in Hikvision IP camera/NVR firmware (CVE-2021-36260)

    I tried to modify /devinfo/ipc_db and /devinfo/ipc_db_backup files by adding new admins users but even after reboot password is wrong. can you point me where is the user file? (database containing web gui users/admin info) my camera is DS-2CD2120F firmware V5.4.3 build 160729. Thanks
  3. M

    Unauthenticated Remote Code Execution (RCE) vulnerability in Hikvision IP camera/NVR firmware (CVE-2021-36260)

    Wonderful amazing works when I read your blog watchful_ip! Thank you very much for sharing this. I have one question: In your original advisory you mentioned about "Disable web authentication and login to target camera admin web pages with any password." Can you please explain how one can do...
Top