Backdoor found in Hikvision cameras

montecrypto

IPCT Contributor
Joined
Apr 20, 2016
Messages
104
Reaction score
304
jfyi, I plan to disclose all details of the backdoor when 6 months pass, which will be the second week of September. Updates are available and 6 months is more than enough time to apply them. There are, however, hundreds of thousands of cameras accessible via the Internet that still contain the backdoor.
 

dealpapa

Getting the hang of it
Joined
Jul 27, 2015
Messages
100
Reaction score
7
jfyi, I plan to disclose all details of the backdoor when 6 months pass, which will be the second week of September. Updates are available and 6 months is more than enough time to apply them. There are, however, hundreds of thousands of cameras accessible via the Internet that still contain the backdoor.
so the 5.4.41 works?
 

dealpapa

Getting the hang of it
Joined
Jul 27, 2015
Messages
100
Reaction score
7
Unless you've bought from eBay or Aliexpress and want to avoid a bricked camera.
Maybe it's time to openly publish the 'enhanced mtd hack' that gives a fully upgradable (R0 series) camera.
or they can learn chinese and flash them to chinese version. That will be much more easy and also they work for every single series.
 

Tolting Colt Acres

Pulling my weight
Joined
Jun 7, 2016
Messages
378
Reaction score
153
or they can learn chinese and flash them to chinese version. That will be much more easy and also they work for every single series.
As someone else pointed out on this, or another thread, you can still use the english batch configuration tool to configure a chinese camera.
 

dealpapa

Getting the hang of it
Joined
Jul 27, 2015
Messages
100
Reaction score
7
As someone else pointed out on this, or another thread, you can still use the english batch configuration tool to configure a chinese camera.
As someone else pointed out on this, or another thread, you can still use the english batch configuration tool to configure a chinese camera.
the problem is ivms-4200 and nvr will need to be chinese too.
 

Tolting Colt Acres

Pulling my weight
Joined
Jun 7, 2016
Messages
378
Reaction score
153
I had a locked-english chinese camera (until alastair was kind enough to walk me through the process of making it english upgradable) which I downgraded and reverted back to chinese for a while, neither ivms-4200 nor blueiris (my NVR) cared it was Chinese.
 

catseyenu

Getting the hang of it
Joined
Jun 13, 2014
Messages
324
Reaction score
42
jfyi, I plan to disclose all details of the backdoor when 6 months pass, which will be the second week of September. Updates are available and 6 months is more than enough time to apply them. There are, however, hundreds of thousands of cameras accessible via the Internet that still contain the backdoor.
Is there a work around apart from updating to the latest firmware?
I have a batch still on 5.16 that I'm hesitant to upgrade...
 

catseyenu

Getting the hang of it
Joined
Jun 13, 2014
Messages
324
Reaction score
42
Thank you, Hik has never been very clear on "details" and I can't remember if 5.16 was an official release or not.
FWIW, they are inaccessible from the internet other than when I remote in through another computer on the network.
 

bashis

IPCT Contributor
Joined
May 27, 2017
Messages
87
Reaction score
118
jfyi, I plan to disclose all details of the backdoor when 6 months pass, which will be the second week of September. Updates are available and 6 months is more than enough time to apply them. There are, however, hundreds of thousands of cameras accessible via the Internet that still contain the backdoor.
Dahua had more than one million when I released info about their backdoor, bad to say that didn't even help, maybe 700k are still vulnerable today for same thing, but at least many security companies do know about this and can catch the things with IPS.
 
Top