Admin password recovery - Hikvision NVR DS-7204HQHI-F1

Woolybear

n3wb
Joined
Nov 30, 2021
Messages
2
Reaction score
0
Location
UK
Evening.

Looking for some advice re password recovery on a Hikvision NVR DS-7204HQHI-F1. Parents in law's box shows in SADPTool but they're locked out. Supplier no longer around and Hikvision UK (understandably) not forthcoming with admin password from XML file extracted using SADPTool.

Can remote control his mac and run things there but not sure best way forward and looking for advice.

The installed software version is v3.4.81 build 170227 and so far I've tried:

(1) Every variation of his usual passwords I can think ok
(2) Default admin password of 12345
(3) Factory reset (hoping that would get us back to default pwd - didn't sadly)
(4) Couple of versions of the backdoor exploit.
(5) hikvision-decrypter-1.0 - said it had successfully decrypted but what it saved wasn't illuminating (code looks to be an AES128 decrypt followed by some XOR stuff) - from GitHub - WormChickenWizard/hikvision-decrypter: A simple cross platform program written in C++ used for decrypting the configuration files created by Hikvision Security Cameras. Successor to my hikvision-xor-decrypter. Pages online suggest a file which when opened in hex editor will have admin then shortly afterwords the admin password. Can't see "admin" in there.

Some posts here suggest that there are 2 versions of the exported XML format - one with 2 extra bytes which muck up the OpenSSL decrypt.

So... looking for a bit of advice if anyone can help.

Should that hikvision-decrypter code work on the XML exported by SADPTool?

If not, is there other code out there which will (happy in C, C++, Python etc etc).

If not, is there an online tool (or service) which will do the trick?

If not, is best bet just to pull the CMOS battery out, reboot and use the default password?

Any advice gratefully received.

Woolybear
 

alastairstevenson

Staff member
Joined
Oct 28, 2014
Messages
15,963
Reaction score
6,794
Location
Scotland
Hikvision UK (understandably) not forthcoming with admin password from XML file extracted using SADPTool.
Try them again - or another country Hikvision support.
Although they generally don't respond to end-users, it can vary with whichever person handles the request.
You might get lucky.
Remember to not power down the device after exporting the reset request file.

Next steps would be to use the Hikvision tftp updater to apply the same version of firmware as currently installed.
Generally, if that can be made to work, it resets the device to an inactive state, allowing a new password to be set.

If not, is best bet just to pull the CMOS battery out, reboot and use the default password?
No - that battery just maintains the real time clock when the power is off.
 

Woolybear

n3wb
Joined
Nov 30, 2021
Messages
2
Reaction score
0
Location
UK
Apologies for slow reply - managed to lock myself out of the forum.

Both excellent bits of advice. Tried HikVision again and they said supplier should unlock so went back to supplier and (hopefully) will manage reset that way. If not, I've used the Scott Lamb tftpd code before with a camera and it was straightforward so will look to track down firmware over the coming days in case I need.

Once again - excellent reply, much appreciated.

Woolybear
 

FLONE

n3wb
Joined
Apr 17, 2022
Messages
1
Reaction score
0
Location
Bucharest
I'm sorry to ask, where can I download the latest firmware for DS-7204HQHI-F1/N?
On hikvisioneurope I couldn't figure out which version. :(
I need the firmware for the same procedure ...

Thank you in advance!
 

RIsiaahw

n3wb
Joined
Mar 1, 2020
Messages
11
Reaction score
2
Location
London
Hi can ny one help me, bought an NVR for a family member on ebay ai arrived yesterday without a power lead and the admin Password. Hve been back to the seller who provided me with around six different passwords and none worked. Have down loaded the SADP tool and the Hik password recovery tool and still device remains locked can anyone help
 

alastairstevenson

Staff member
Joined
Oct 28, 2014
Messages
15,963
Reaction score
6,794
Location
Scotland
DS-7608NI-E2/8P
For this model, probably the easiest way in would be to re-apply the current firmware as shown in SADP using the Hikvision tftp updater.
This will reset the NVR to default settings.

Firmware is here :

Hikvision tftp updater and instructions are here :
 

RIsiaahw

n3wb
Joined
Mar 1, 2020
Messages
11
Reaction score
2
Location
London
Good evening Alastair
My process so far.
I have downloaded the above and place them in a folder i have named DCap.
I have placed the folder in the route of the C: drive.
I have changed my Ip Address in the TCP/IPv4 to 192.0.0.128
I have plugged the NVR directly into the LAN on the computer Confirmed in IPconfig.
then have run the TFTP it shows 192.0.0.128 initialized
its been ten minutes now and no change. where have I gone wrong?
 

RIsiaahw

n3wb
Joined
Mar 1, 2020
Messages
11
Reaction score
2
Location
London
Update
TFTP Now returns this under log information
[2022-10-02-23:01:07] TFTP server [182.0.0.128] initiated
[2022-10-02-23:01:51] Connect client[192.168.9.78] success
[2022-10-02-23:01:51 file] Open file[C:\Dcap\econt_Vision-AV2000 ]failure
 

RIsiaahw

n3wb
Joined
Mar 1, 2020
Messages
11
Reaction score
2
Location
London
This DIgcap.Dav, the file i down loaded from the site is called digicap.DAV but this turns out to be Videpad is this correct
 

alastairstevenson

Staff member
Joined
Oct 28, 2014
Messages
15,963
Reaction score
6,794
Location
Scotland
I have plugged the NVR directly into the LAN on the computer Confirmed in IPconfig.
The tftp update works best if both the NVR and the PC are both wired to their router or switch ports as normal.

[2022-10-02-23:01:07] TFTP server [182.0.0.128] initiated
The IP address is a typo / not just copied from the tftp updater window?
Should be 192.0.0.128

This DIgcap.Dav, the file i down loaded from the site is called digicap.DAV but this turns out to be Videpad is this correct
I don't understand.
Unzipping the downloaded firmware from the Hikvision site gives a file named digicap.dav that should be placed in the same folder as the tftpserve.exe program.
The filename should not be changed.
 

RIsiaahw

n3wb
Joined
Mar 1, 2020
Messages
11
Reaction score
2
Location
London
Comp and NVR connect to switch, 192.0,0t,128 typed into ipv4
but still returning the below
[2022-10-02-23:01:07] TFTP server [182.0.0.128] initiated
[2022-10-02-23:01:51] Connect client[192.168.9.78] success
[2022-10-02-23:01:51 file] Open file[C:\Dcap\econt_Vision-AV2000 ]failure
But obviously not the same times
 

alastairstevenson

Staff member
Joined
Oct 28, 2014
Messages
15,963
Reaction score
6,794
Location
Scotland
When you first started the tftpserve.exe program, did you get a Windows Firewall 'Allow' popup and did you click OK to it?
If not - maybe temporarily disable the Windows firewall.
 

RIsiaahw

n3wb
Joined
Mar 1, 2020
Messages
11
Reaction score
2
Location
London
Hi yes I did click ok but with no Success.
However, despite receiving around four messages back from various so-called Techs, I decided to send them another email back up by a phone call. and low and behold. they sent me the code, which has now unlocked the NVR. Do you believe this?
I thank you for your help so far.
I would still like to be able to learn from you, how to use the TFTP sever, so when you are able to give more F=Guidance I will be most grateful
 

RIsiaahw

n3wb
Joined
Mar 1, 2020
Messages
11
Reaction score
2
Location
London
Hi Alastair I have just bought an NVR DS-7604NI-SE/P0420131208BBRR444488965WCVU current firmware V2.3.7 Build 131112, encoding V1.0. Build 130719
cant seem to find a way to connect this unit to Hik Connect, as there seems to be No Platform access. Any ideas?
 
Top