Alternative way of recovering HikVision NVR password

Joined
Jan 7, 2022
Messages
1
Reaction score
0
Location
South Africa
Hi all -- I am so happy that I found this helpful thread!

I have recently purchased a property with a HIKVision camera & NVR installed - however, the previous owner says they can't remember any of the passwords.

The hardware & firmware are as follows:
NVR: DS7608NI-K2 (V4.30.061 build 210313)
Cam: DS2DE5225IW-AE (V5.6.14 build 190826)

I tried accessing the config file through http://<camera_IP_address>/System/configurationFile?auth=YWRtaW46MTEK , without success.
From reading this thread, I understand that the camera's firmware is too new. But the camera model also seems to be rather uncommon.
Do you think it would be possible to downgrade this particular camera to an older firmware version, and then exploit the vulnerability?

Thanks!
 

iTuneDVR

Pulling my weight
Joined
Aug 23, 2014
Messages
846
Reaction score
153
Location
Россия
I tried accessing the config file through http://<camera_IP_address>/System/configurationFile?auth=YWRtaW46MTEK , without success.
From reading this thread, I understand that the camera's firmware is too new. But the camera model also seems to be rather uncommon.
Do you think it would be possible to downgrade this particular camera to an older firmware version, and then exploit the vulnerability?

Thanks!
reboot device;
run SADP;
export xml separated;
remember startime at device;
do not reboot that;
send letter to support;
get answer;
use code to reset password ;)
 

laukkis85

n3wb
Joined
Dec 31, 2021
Messages
4
Reaction score
0
Location
sweden
Yes, that's confirmed by decrrypting the first configuration file. The Russian site was correct.

If the camera firmware is old enough that it still uses the hard-coded default passwords when reset to defaults, the NVR when adding the camera under Plug&Play will use those if it finds that they work, instead of using it's own admin password to activate and add the camera.
In other words - very old camera firmware means that this 'trojan horse' method of extracting an NVR password does not work.

If it's the NVR password you are trying to recover - you will need to use a camera that has firmware in the range 5.3.0 to 5.4.0

What does SADP show for the camera models, serial numbers (are they Chinese) and firmware versions?
Where can I download 5.3.0 for dahua Model DH-IPC-HDBW1230EP?
 

laukkis85

n3wb
Joined
Dec 31, 2021
Messages
4
Reaction score
0
Location
sweden
You need to know password from dahua ipc or ?
No, need to retrieve truvision nvr password. Have tried now twice with the customer service and doesnt work with their way for some reason... So thats why i Would like to know is there the vulnerability with the Dahua camera older firmware like HIKvision/truevision cameras have?
 
Last edited:

trempa92

Pulling my weight
Joined
Mar 26, 2020
Messages
724
Reaction score
221
Location
Croatia,Zagreb
DS7608NI-K2 (V4.30.061 build 210313) isnt this firmware subjected to RCE? U can use paramReset within, it''ll instantly go inactive state.
 

alastairstevenson

Staff member
Joined
Oct 28, 2014
Messages
15,952
Reaction score
6,787
Location
Scotland
DS7608NI-K2 (V4.30.061 build 210313) isnt this firmware subjected to RCE?
Not according to Hikvision's original list (since removed) or use-ip's enhanced list.

But check the device serial number here :
 

trempa92

Pulling my weight
Joined
Mar 26, 2020
Messages
724
Reaction score
221
Location
Croatia,Zagreb
I wouldn't be surprised if the list were only half full.

Still might wanna check with tool considering the firmware was released in march prior rce
 

tgazda

n3wb
Joined
Feb 3, 2022
Messages
2
Reaction score
0
Location
Poland
Hello, can I ask you to put 2 EZVIZ cameras away from parents who forgot both the login and the password of the account?
I canot Unbind in SADP
 

Attachments

alastairstevenson

Staff member
Joined
Oct 28, 2014
Messages
15,952
Reaction score
6,787
Location
Scotland
Hello, can I ask you to put 2 EZVIZ cameras away from parents who forgot both the login and the password of the account?
I canot Unbind in SADP
You are trying to unbind the EzViz account from the cameras?
It's not something I i know anything about, sorry.

Do you know that in the plaintext configuration files that you have attached there appears to be passwords - but I don't know if they are associated with the EzViz account :

admin / UXSRRE for the -Tube camera
admin / UWXDKV
Did you use these in the SADP unbind attempt?
 

tgazda

n3wb
Joined
Feb 3, 2022
Messages
2
Reaction score
0
Location
Poland
You are trying to unbind the EzViz account from the cameras?
It's not something I i know anything about, sorry.

Do you know that in the plaintext configuration files that you have attached there appears to be passwords - but I don't know if they are associated with the EzViz account :

admin / UXSRRE for the -Tube camera
admin / UWXDKV
Did you use these in the SADP unbind attempt?
Yes i try unbind in SADP but doest work , i se
 

Attachments

trempa92

Pulling my weight
Joined
Mar 26, 2020
Messages
724
Reaction score
221
Location
Croatia,Zagreb
Unbinding device with sadp only works if account is on hik-connect cloud not on ezviz platform. Password by default on ezviz cams is verification code on lable
 

SamM

Pulling my weight
Joined
Mar 29, 2020
Messages
245
Reaction score
109
Location
SA
Hello,
Can you tell me the password from my DVR, please?... I spent so many hours to reset it..but...no success!
This is the model DS-7216HWI-SH1620150228AA
Thank you in advance!
Have you tried the conventional recovery?

 

SamM

Pulling my weight
Joined
Mar 29, 2020
Messages
245
Reaction score
109
Location
SA
Have you tried the conventional recovery?

Try the code qrqq9Qy9zQ

using the following date that you provided for serial number R505456052
year 2012
month 01
day 17
 

16710

n3wb
Joined
May 11, 2022
Messages
8
Reaction score
3
Location
UK
Hello!

I've been reading this thread (and all the linked threads/blog posts) with interest as I've recently moved into a house and inherited a rather nice Hikvision CCTV system with NVR. Only problem is, I can't log into the NVR as nobody knows the admin password.

I've emailed hikvision EU support but not holding out much hope. I am also a bit stuck because the software the NVR and all the cameras are currently running is not vulnerable to the easy backdoor methods, so I've been unable to extract configs (and hence passwords) that way.

I like the idea of tricking the NVR into giving its config to a newly installed, and vulnerable, camera but I'm not sure if I can downgrade my existing cameras?

Software versions in use are:

Code:
Device Type            Software Version
DS-7616NI-I2/16P    V4.22.000build 190821
DS-2CD2383G0-I        V5.5.83build 190221
Many thanks in advance for any advice.


edit: I forgot to add. I don't seem to be able to use the 'Security code' reset approach either. I've tried various versions of SADP (including this old one) but whenever I select the NVR the 'security code' box disappears. Using the generated key in more recent SADP versions, in the 'Input key' box also doesn't work.

Screenshot 2022-05-12 at 09.50.19.pngScreenshot 2022-05-12 at 09.50.34.png
 
Last edited:

alastairstevenson

Staff member
Joined
Oct 28, 2014
Messages
15,952
Reaction score
6,787
Location
Scotland
I'm not sure if I can downgrade my existing cameras?
Not the G0 cameras shown in the SADP screenshot, the 'downgrade block' would prevent that.

That NVR model quoted has 16 PoE ports - are there any other cameras connected directly?
Connect the PC to an unused NVR PoE port if so, SADP will find them.

the software the NVR and all the cameras are currently running is not vulnerable to the easy backdoor methods, so I've been unable to extract configs (and hence passwords) that way.
I believe that's correct - but the passwords are now stored as a hash so extracting a plaintext form is not practical.

You may have to resort to using the tftp updater method to re-apply the NVR firmware and therefore reset to defaults.
This would 'orphan' the cameras, where the same method would be needed, or make use of the reset button under the hatch on the body if the cameras are accessible.
In both cases, the firmware is larger than the 32MB size limit of the Hikvision tftp updater program - so the Scott Lamb clone would need to be used.
Example here :

NVR firmware here - use the closest to what's already installed :
 

16710

n3wb
Joined
May 11, 2022
Messages
8
Reaction score
3
Location
UK
Thanks. There are 5 cameras, all are the same model (I've also plugged directly into the NVR and discovered the other cameras' info that way) unfortunately.

The cameras are really inaccessible so I'd prefer a method that doesn't involve me having to climb onto roofs or use a cherry picker(!) to physically reset them. Can I put them into a 'receive firmware over TFPT' mode remotely? Do they fall back to this state if I reset the NVR?

Cheers
 
Top