Subscriber Discussion

I Would Like To Issue A Warning...

bm
bashis mcw
Feb 15, 2020

I have found some weaknesses / vulnerabilities for Dahua and OEM cloud solutions, and I would like to kindly issue few warnings for people here at IPVM.

1. If you actively use Dahua and/or their OEM cloud solutions, you are in great risk to have your credentials compromised due to one serious vulnerability. (To which I will do Full Disclosure for at May 9, 2020 19:00 UTC)

*. ** *** ***'* *** ***** and/or ***** *** ***** *********, *** are ** **** ****, *** *** should ********** ******* ** ** ********* (it ** ******* *** ********* ** default), ** ****** *** ***** *** to *******, *** ******* ** **** devices - ********** **** *** **** set ** **** ********/****** ** ******* UPNP/DNS. (** **** *** ***% ************ from ********, ***** ** ******* ****)

* ** **** ******** ******* *** and **** ** *********** ***** ******.

/******

(11)
JH
John Honovich
Feb 15, 2020
IPVM

*** ***** ***** **** ***? **** your *********** * ** ******** *** yet?

bm
bashis mcw
Feb 15, 2020

**, **** *** ***** ********* ** details *** ***. *** * ****** to **** ** ***** *****-**, ** I ***'* ***** **** ** **** know ** ** *** *** *****.

(1)
JH
John Honovich
Feb 15, 2020
IPVM

**, *** ** *** ***** ****** know? *** *** ***** **** *** have **** ** *******?

bm
bashis mcw
Feb 15, 2020

* ***'* **** ** ***** *** much ** **** ******, * **** to **** ***** **** ** *** the ***** *** ********** *** *****. But **'* **** ***, ** ********** to ** **** **** ** **** when * ***** ***** ** "********** 2 *** ********** *", **** *** been ***** ** "********** *".

JH
John Honovich
Feb 15, 2020
IPVM

* *** *** **** ********* *******, I ***** ***** ****** *******. **** you **** *********** **** ****** *** exploiting ****?

bm
bashis mcw
Feb 15, 2020

********, * **** *** **** ** heard *** *********** ** ****.

EP
Eddie Perry
Feb 15, 2020

***** ** **** ** ********* *****, like *********** *** ******* ** **** point **** *** ***** ******* ** devices ********** ** *** ***** *******....

**** ***** **** **** ** **** auto ********* ***** ** ********* *** exposed ** **** *** ********* ** the ********.

* *** *** ** *** *** style **** ****** ***** *** ************ a ****** ** *** ***** ***** before ***** *** *****

***** **** **** ******, **** **** pressing ******* ** ****** ** ** china ***** ***.....

(1)
JH
John Honovich
Feb 15, 2020
IPVM

***** **** **** ******, **** **** pressing ******* ** ****** ** ** china ***** ***.....

* *** **** **** *** ** the **** **** ** ***. *** fact **** ****** *** ****** **** warning **** **** **** ***** ********* to *******.

(3)
JH
John Honovich
Feb 29, 2020
IPVM

**'* **** ****** * *****, * just ***** ***** *** ** ****** and **** **** ** / **** I *******.

UI
Undisclosed Integrator #2
Feb 29, 2020

*** **** ********* *** *** ********** in * ******* ****** *** ********* the *******... ** *** ** ***** revealing...

** *** ****** ** *** ** day ********** ****** * **** ******* from ******* ****.

***** ***************...

*. ******* ** *** *** *** VPN **** **** ****** ****** ** the *** **** ******* *** ******* and *** *** ******** ******* ** cameras.

*. ********** ***** **** (******** ******** to ** ‘** **** *** ****’) note **** **** ****** *** ***** you ** **** ** *** *** IT ***** *****!

*. ****** **** ****** *********

*. ***’* *** ************ **** - use * ***** ***** *******

*. *** * ********* ******* *** that ******* **** *** ********* *** which **** ****** *** ****** *** attack ******* ****** * ********** ** focussed ******* ****** **** ************(*)

*. ***** ********* *** *** ****** immune

(1)
(2)
bm
bashis mcw
Feb 29, 2020

* ***** ** *** ******!

****** ******** ******* (**** **** ***** VPN ** ****** ******), ******** *** in *** ******** ******* ******* ** VPN ****** ** **.

UI
Undisclosed Integrator #2
Feb 29, 2020

********** *****!

***** ***** ** **********...

** *** ** *** **** *** skill ** ****** * ***, ****** someone ** ** ** *** *** or *** * ********* ********** ******** VPN ******** **** ** *** *** Router (********* ** *** ** - not **** ***** ******** ****)

U
Undisclosed
Mar 12, 2020

"********** ** *** **** ******** ** set" ** * ***** ******** *********. If * ***** ******* ******* **** shouldn't ** ********, ** * **** to ***** *** ******* **** ** cameras **/**** *** ****** ********, ***.

** *** **** ******** ******* ** ports **** * ***** *** ** being * *******.

bm
bashis mcw
Mar 13, 2020

**** *** **** ***** ***** ****?

*******, **** ******** ******* ***** ** #2 *********. *.*: (** **** *** 100% ************ **** ********, ***** ** minimal ****)

U
Undisclosed
Mar 13, 2020

**** (*** **********) ** * *** solution ****'* *** **** * *****. Your #* **** ***-*** ** **, which ***** *****. **** ********* *** quite *********** *** ******* ***** ** no ******** ** ********* **** *** block *** *******.

UI
Undisclosed Integrator #3
Mar 12, 2020

** **** *****, *’* ******* ** and **** ***** ** ** *** a ****. ***** ******* *** ****** the ***** ****** ******** *************

***** ********* ******* *********** *****-**, ****** says

(3)
(1)
(1)
UI
Undisclosed Integrator #4
Mar 13, 2020

* **** **'* *********** ** **** on ***** (*** *********), *** ***** in *******, *** ** ******* **** a ******* ****** ** ******** ******* of ***** **********'* *******/********* ** ****** absurd.

(3)
(1)
UE
Undisclosed End User #5
Mar 13, 2020

* ******* "**********" *** ********** **** Dahua (*** *********)?

(1)
(1)
(1)
bm
bashis mcw
Mar 13, 2020

*** **** "*****" (.***) [.**] ?

(3)
UI
Undisclosed Integrator #4
Mar 13, 2020

**, ****'* ********.***.**.

(1)
(1)
UI
Undisclosed Integrator #4
Mar 13, 2020

* ******* "**********" *** ********** **** Dahua (*** *********)?

****, ***'** *****. *'* **** ** was ******* ** ***** **** ******* the ******* ****** ******* ** ***** up ***********.

Image result for obama what gif

(1)
bm
bashis mcw
Mar 13, 2020

* ** *** ***** ** **** you ******* ** ** **, *** I ** ***** ** *** ****.

(1)
JH
John Honovich
May 10, 2020
IPVM

******:****** ********* *** *** *********. **** his ****** ***:

*. ***** ***/**** (******) ************** ************** and ***

*. *************: ***** ****** ******* *********** (first * *****) **** *** ******* in ***** ******* **** ***** ***** and ***** ********

*. ***: ***** ****** ***/***** ***** listener ** ******* ********* *********** ** clear ****

*. *************: ***** ***** ***** ******** credentials *******

*. *************: ********* ***** ***** ****/********* for ** ********* *********

*. ***: ****** ** ******* ****** DHP2P *****. *** **** **** *** Dahua ****

*******, ****** ***** ******** **** / relabellers ********* *******, ******* *** *********:

IPVM Image

** *** ********* * **** ** this.

(3)
UI
Undisclosed Integrator #6
May 10, 2020

****** '**********' ******* ********* ** * preshared *** ******* **** ** *********** oversight (***** *** *** ***** ***** described).

(2)
JH
John Honovich
May 11, 2020
IPVM

****** *** ******** **** ***, ********* section:

IPVM Image

** ***** * ********* *** ****** in **** **** ** ***********? * thought ** *** **** *** **** networks *** ********** ***** ******* **** this, ** * ******* *********?

New discussion

Ask questions and get answers to your physical security questions from IPVM team members and fellow subscribers.

Newest discussions