massive DOS attack on dvr's

fabiobassa

n3wb
Joined
Jun 11, 2018
Messages
3
Reaction score
3
Location
italy
Want to share my personal experience with devices drived by hisilicon socks

I do collaborate with a WISP and have some of clients with public open IP.
Unfortunately many of this camera, nvrs and dvrs have hidden open services as telnet , service ports and other, with WELL KNOWN user and passwords.
The result of this DOS attack was many dvrs not even booting or with just coloured bars on monitor

Thanks to this forum I started to study the problem and can say that until there is U-BOOT working ( but later will explain also not working U-BOOT) there is hope to revive them.

To solve problem must have access to serial console via a usb-ttl converter and have at least some skills on soldering and desoldering. If U-BOOT is dead too, must solder and desolder smd components , which leads to major difficulty.
My personal experience is on socket HI3520D but obviously the process is the same with hi3520 A/B/C and others.
On mine 8channels dvr U-BOOT was at least prompting something, and the rom was 16 mega .
the printenv showed this:
0x000000000000-0x000000080000 : "boot"
0x000000080000-0x000000480000 : "kernel"
0x000000480000-0x000000a00000 : "usr"
0x000000a00000-0x000000b80000 : "web"
0x000000b80000-0x000000e80000 : "custom"
0x000000e80000-0x000000ec0000 : "logo"
that means the starting and ending of each mtd parts. So after downloading gigas and gigas of firmwares i looked for contents of ariund 4 mega of roms, around 3%4 mega of custom,around 1%2 mega of web.
All files are extensions.x-cramfs

well i founded at least 20 different different firmware booting and all working because all those dvrs and fundamentally the same machine
Just needed to go in VIA rs 232 connection.
I know this is not user friendly but is the only way to revive them
Want to share my u-boot bin that is working on many HI3520D platforms but not all, so then you must reprogam via SPIPGMW and i am not responsable of bricking u-boot

And also, please, anyone that could share HI3520 uboot ( not a , not d, just simple hi3520)

Thanks in advance, Fabio
 

Attachments

Top