Hikvision cameras attempting to reach Chinese IP address

kell490

n3wb
Joined
Oct 8, 2018
Messages
10
Reaction score
4
Location
85022
I happen to be looking at my firewall logs notice 2 of my hikvision cameras are attempting to get out to the internet using non standard UDP ports. When I do a who is on those IP address's comes back with website says to block them seem to be Chinese IP address . My security cameras are in security camera zone they don't have NAT translation out to the internet. I don't remember this happening before maybe I just haven't looked in awhile. The 3 cameras I have it's the 2 older ones which are doing this. What ever it's trying to do it's also using DNS to look these IP address's. I use a DVR to view the cameras from the internet so none of my cameras have access to the internet. I know they had some issues with these gray market cameras backdoor if you put them directly on the internet. This seems to be built into the firmware. My newer camera I got this year has no attempts to get to the internet.

Model DS-2CD2032F-I Firmware V5.3.0 build 150814 camera number 2 is using V5.2.0 build 140721

some of the IP address's it's trying to communicate with .

35.174.255.210
52.202.153.134
52.5.46.38
170.106.2.180

UDP ports
50651
58783
41311
 

alastairstevenson

Staff member
Joined
Oct 28, 2014
Messages
15,983
Reaction score
6,805
Location
Scotland
some of the IP address's it's trying to communicate with .
The first 3 are Amazon AWS servers.
Check the cameras web GUI - you'll likely find that the Hikvision P2P (which specific service depends on the firmware version) is enabled.
That's on by default on the older firmware, not on the new firmware.
Check also if UPnP is enabled - it's also on by default.
 

kell490

n3wb
Joined
Oct 8, 2018
Messages
10
Reaction score
4
Location
85022
I did find some things turned on I disabled UPnP and some cloud access that might have been what it was trying to go to. There was no automatic firmware download on this one I know about the issues with the gray market cameras and firmware updating from the US hikvision so I usually just leave them on the firmware they came with.

Checked my firewall logs looks like that was it now no more log attempts to send to those IP address. I'm surprised those are all turned on by default I should have gone though everything turned it off.
 

Attachments

Last edited:

bickford

Getting comfortable
Joined
Mar 12, 2016
Messages
468
Reaction score
432
Old models have P2P turned on ...

BICK
 
Top