Odd NVR passwd entry

Brad_C

Banned
Joined
Jul 11, 2016
Messages
167
Reaction score
54
G'day all,

Poking around my old mans NVR on the weekend, noticed an extra user in /etc/passwd and /etc/shadow
/etc/passwd
hikvision:x:501:501:Linux User,,,:/home/hikvision:/bin/sh

/etc/shadow
hikvision:$1$ChRPh3ur$Yy6bjTErRXoajEZ1jao79/:15302:0:99999:7:::

Did a bit of googling and found that encrypted passwd mentioned incidentally on a russian site, but nothing else. Has anyone looked into this?

Relevant bits from getHardInfo
Serial NO :1620150608BBRR5XXXXXXX6WCVU
V3.1.0 build 150805
KernelVersion: V1.0.0 build 140815
dspSoftVersion: V1.0 build 140611
codecVersion: V1.0 build 100520
devType:DS-7616NI-SP

It's from the Aussie supply chain with custom firmware apparently built for Aus/NZ
 

alastairstevenson

Staff member
Joined
Oct 28, 2014
Messages
15,973
Reaction score
6,798
Location
Scotland
I have never seen anything other than root in the firmware for my 7816N-E2 from 3.0.8 upwards.
Have a look inside /home/app/cfg/devCfg.bin and see if there are any extra userIDs and paswords.
In that version of the firmware, that file should be in plaintext.
 
Top