Dahua Manager: Lots of Backdoors Beyond Dahua or Hikvision

Author: John Honovich, Published on Mar 29, 2017

A Dahua technical manager has fired back at criticisms of Dahua's backdoor, posting publicly what many at Dahua have privately been saying for the past few weeks that their backdoor is no big deal because lots of companies have backdoors and that Dahua and Hikvision get unfairly criticized for their problems.

* ***** ********* ******* *** ***** **** ** ********** *******'* ********, ******* ******** **** **** ** ***** **** ********* **** saying *** *** **** *** ***** **** ***** ******** ** no *** **** ******* **** ** ********* **** ********* *** that ***** *** ********* *** ******** ********** *** ***** ********.

[***************]

*********

***** ********* ******* *********:

********* * ********* *******, ** ******** ** ***** ** **** issues,********:

** ** * ************* ** * ************* ** * ***** extent.

Simplicity *** ******** ** ***** ********

*****'* ******** ** *** **** ****** *** ******* ** ******* than *** ************* **** ****** ** ********** ***** ************ ********. This ** *** ******, *** ********** *** ********** **,*********:

**** ** **** * **** ********* ****, ***** ** *** button *** *** *** **...

*****, ***** *************** *** **** ** *******. *** *******, ********* ********** **** ********************* * *********** ** **** **** ***** ** *** ** achieved. ** ********, *** ***** *** ***** ****** *** ***** by ****** *********** *********** *********** **** *** ****** *** *********** running **** ** *** ***** ******.

Implication - *** ***** **** ********

** ********* ******* ** **** ******* ** **** ** ******** essentially *** '**** **** *******' **** ** *** ****** **** purchasing ********* ***** *** *** *********. ********* *** *********** * commodity - ******** '******' ****. *** ***** ****** **** **** to *** ** ******** ***** **** ******** - **** ***** and *********.

**** **** **** *****. **** ** *********** *** ******** ** video *******, *.*., **** ***** *** *********'* ***** ******* ** basically *** **** ** **** ** ********, ** **** *** the ******* ***. *** *** ******* ************* **** **** **** selling ** **** *****. ** **** *** ******** **** *** cybersecurity ***** **** * ******* *****, **** ***** ****** *** lower **** ******* ***** *****.

Dahua *** ********* ****** *** ** ** *** **** ** *************

******* ** *********** *** ****** ** ********* *********, ***** *** Hikvision ***** ** ****** ** ***** ** ***** *** '****' at *************. **** ***, ** ***, *** *** ******* **** market ***** ************ ********* ***** ******* *** **** ****** ** wind ** '***********' ** *** ****** ********. *** *******, **** ******* ***** ******* ******* ** *** ********. ******* ** ****, *** ************* ********** **** *** **** the ******* ******* ** *** ***** ** *** ******* **** can **** ** ***********. ******, ******* *** **** ****** ** target ***** *** ********* *** *** **** ****** **** **** historically ******** *********, ***** ***** ********* **** *** **** ******* that *** ** ******** **** ***** **** ***** ******.

Comments (16)

***********, **** *****'* **** ****** *** ***** ** ***** ******* utilizing ****** ** **** ********* (****** *** ***) ***** ********* usernames *** ********* ** ***** **** ******. **'* ****, ********'* doing **.

***** ** *** ********** ******* ************* *** ********.

*'** *** ** **** ** *****;

*********:
**** ************* **** * **** ***** ******** *** ******** ******** have ****** **** ********** *********, ***** ** ********, *** ****** therefore *** ** ******* ** ********, ****** ***** ** ******** pattern.

**********:
***** ******** ******* *** *****, ****** ******** *******, **** **** different ******* ********** *** **** **** ***** *****, *** ******* - **'* ************.

**'* ************ *** **, *** *** **** ** ** **********???

***** ******** *****, ***** **** **** *****?

******* * *** *** **** ** ***********: ***** *** * well ******** ********** *** ***** ********* ***** ******* ** ****** competitive ********** ********* ** ** ******* ********* ******* ******* *******. They *** **** *** ******** ***** ** *** *****'* ******* video ************.***** ******* ***** ********* *********** ***** ** ********* ***** ******* ********* do *** **** ************. ** * ******* ***** *** ***** has ******* *** ***** *** **** ************* ** **** ***** prudent ** ** ********* ***** *************** *** **** **** ****** to ** *********** *********.

** ** ************* *************** ** *******, ** ******, ** *******, my ********* ******* *** ** *** ******** **** ** ******* security ******** *** ******* ****** ** ******** ******* *************** **** discovered. **** ***** ** ***** ******** ** *** "********* *** vulnerabilities, ***'* *****" ********.

** *** ***** ******* *** '**** ******* ***** * ********** & ******* ********** ****?'

**** ******, *** **** ***, ***** **** ** ******** *************** will **** *** ** ******, ***** **** *** *** *********** giving **** **** *********** *** ********* ** **** *******! *** the ********** ** ***, **** ******* ********* *** ***** ****. For **, ** ** ******* ** ******* *****

** ****** ***** ****? ***** *** ********.

**** ****:
* ***** **** ***** *******, ***** ** ********* *********** ** all ********, **** *** ***** *** **** *** ******, *** they *** ***** *** ****.

******* ******* ************* *** ********:
**** ******************** ****** ******, ***** **** ******** ******* **** **** ***** ** ******** and ******** ********, *** ***** ** ** **** ********** ********* for ** ***** ** *********** ** ********.

* ***** **** ** ********** *** **** ** ********, ***** in ** ******* ** ***** ** ****** ***, *** * can't *** ** *** ********* ***** **********.

*******, ** ** ***** ******** ** *** ****** ****** ** technique *** *********, *** **** **** ***** **** **** ******** patterns.

**#* **** ***'* ******** ** *** *** * ****** *********** based ** **** *******. **** *** ** **** ***** **** on **** *** *** **** **** **** ****** ********* **** what * *** ****.

**** ***** ***** ****** ** ****** ******* ** ****** *** Hikvision *** ***** ***************, ******* ***** *************** *** *** ******* intent ** **********, ** ********** ***** ***************. **** ********** **** ** ****** ***** *******. A ****** ****** ** ****, *********, *** ***** ***** *** following ******** ** ****** ********** ******* ****** ** ***** *** exploits.

***** ******* *** *** **** ******* *** *** **** **** change *** *********** ** ******* ** ****** ******* **** ********* than * ***** *** ****** ******. **** ***** **** ***** cameras ****** ** ******.** ********* ******** ** **** ********* *** *** ***** ******* * **** ****** ****** **** Hik/Dahua.

**************, ** *** **** ******* *** ********** ******** ***** *** aim *** *** ******** **** ** *** **** ********? **** the *********** ** * ****** ***** ****** ** **** ********** is **** ******* ********* *** *** *********** ******.

whatever

*** ****** *********.

******, *** **** ** **'* ***** ** *****/********* ** ****, I ****** ***'*.

/******

* *** ******* *** *** **** **** ** "***** *******", but ** ***** ** ** ****?

* *** ******* *** *** **** **** ** "***** *******", but ** ***** ** ** ****?

***, * ******* ** *** **** *******. * ** *** see ** ** *** ******** ****** ** *** ****** **.

***** *** ********* **** **** * ******* **** ***** ********* posting ** ****** *****. *** *******,********* ******** ***** *****.

** **** ******* ** ******** ***** ****** * ******** ********, or * ***** ***** ** ******* *** ******** **** ****** effort.

*** ******** ****** ******** *** ** **** ** *** ******, even *** ********* ** * ***** ****** ** *** ****** adds ** *** ****.

** *** *** ****** ****** ** ***** * ******** ***. It's ****** *** *** ******** ************* ** ** *********.

**** ****** ** **** ** ********* *** **** ******* *** we ****** *** *** **** * **** *** *** **** done ** **** ** ***** ** ** * ******** *******.

* *******+ ******* ****** **** ***** ****** ** * *** thing ** ***.

* ***** *** ************ *** ******* ** ******** * **** based ****** ******** (***** ** **** **** ** ***** ****) as * "********". ** **, * ******** ** * ***** to ****** ****** ** * ****** **** *** *** **** published ** **** ** *** ******* *************. ***** * ****** password **** ***** *** ** *** **** * ******, *** through *** ****** ***** ** ******. * ******** ** * way ** ********* *** ****** ****** ** ****** * ****** and ******* ****** ** ** ** * ***-******** ****** (**** as *** ****** ******* ****).

* *******, ***% ***** **** *** **** ***** ******** **** no ******** ***** ******** ** ** "********" *******.

******* ********* ** ** **** *** ******** ***** ***'* * problem ** *** ***** ******* ** **** *** ********* ** an *** ****** **** ******** ** *** ******** ** *** NVR **** "****** *** ********" ** * ****** **********.

** **** *******?

*** *** ******* ****** ** **** *****...

********, **. *** **** ****** ********/***/******** **** *** ******* ******** didn't **** ** **** **** ****** *** **** ****** *******. This ******** *** ** *** **** (*******, **, ** ****) and *** *** (***** *****, **** ****).

******** ** ***** **, **** ***'* **** * ********* **** base ** **** ********** **** ***** **** *** ********* *********.

**** *** ********** ** ******* *** ******** ********** *** *** customers.

** *** ******* ******, * **** **** **** ***** **** new *** ******** ******** **** *** ****** ***** *******.

******* *** **** **** ****** *** *** ****** *** *** interfaces ** ********** ******* **** ****** ***** ** *** ********! Yay *** ******** ******* ***** **, *****?

Login to read this IPVM report.
Why do I need to log in?
IPVM conducts unique testing and research funded by member's payments enabling us to offer the most independent, accurate and in-depth information.

Related Reports on Hacking

Cybersecurity for IP Video Surveillance Guide on May 18, 2018
Keeping surveillance networks secure can be a daunting task, but there are several methods that can greatly reduce risk, especially when used in...
Hikvision Source Code Transparency Center Examined on May 14, 2018
Following criticism of Hikvision's Chinese government ownership and Hikvision's IP camera backdoor, the company has responded with a series of...
Hikvision Critical Cloud Vulnerability Disclosed on Apr 25, 2018
Security researchers Vangelis Stykas and George Lavdanis discovered a vulnerability in Hikvision's HikConnect cloud service that: just by...
April 2018 IP Networking Course on Apr 19, 2018
This is the last chance to register for our IP Networking course. Register now. NEW - 2 sessions per class, 'day' and 'night' to give you double...
TVT Backdoor Disclosed on Apr 09, 2018
Security researcher Bashis has disclosed a backdoor in TVT video surveillance products, with TVT issuing its own 'Notification of Critical...
P2P 'Fail To' 'Quick And Steady Access' - Hikvision Defends Port Forwarding on Apr 02, 2018
Following criticism of Hikvision's ongoing port forwarding recommendation (e.g., Hikvision Hardening Guide Recommends Port Forwarding and Hikvision...
Stats: Disclosing Vulnerabilities Responsibility? Researcher or Manufacturer on Mar 30, 2018
Getting prompt and appropriate information on vulnerabilities is important for integrators and end users to ensure that their systems are best...
Hanwha / Kaspersky Vulnerability Dispute Examined on Mar 29, 2018
IT media ran numerous reports in the past month featuring two prominent companies - Hanwha (previously part of mega manufacturer Samsung) Techwin...
Hikvision HQ Contradicts Cybersecurity Director on Mar 07, 2018
Hikvision HQ has contradicted Hikvision USA's Director of Cybersecurity, Chuck Davis. Davis - Don't Put Cameras On The Internet Davis made a...
New Whole Foods Installs Hackable Access Control (Upgraded) on Feb 21, 2018
Whole Foods has built a reputation for high quality. And their 2017 Amazon acquisition has increased that, plus added deep pockets for buying...

Most Recent Industry Reports

Buy Arecont: Top Bid $10 Million Cash on May 22, 2018
Last year, Arecont had a deal for a purchase price of $170 million (see Failed Arecont China Acquisition). This year, Arecont has a deal for a...
Installing Box Cameras Indoors Tutorial on May 22, 2018
This tutorial starts our physical installation for video surveillance series, starting with Box Cameras, one of the oldest and most basic types....
The Hikvision Smart Classroom Behavior Management System on May 22, 2018
Hikvision's rapidly growing offering of analytics, which we most recently examined with Hikvision's ethnic minority analytics, is now going into...
Dahua Intrusion Analytics And VMD Tested on May 21, 2018
Dahua ships basic analytics on practically all their cameras, ranging from low cost to high end. To see how these analytics work in real world...
Exacq Improving Technical Support, Responding To Integrator Complaints on May 21, 2018
Exacq had been a long-term favorite of integrators, but since their 2014 Tyco acquisition, Exacq has fallen in IPVM integrator studies (though...
Best Manufacturer Technical Support 2018 on May 21, 2018
While 5 manufacturers made the worst technical support 2018 list, only 3 stood out as providing the best technical support to 190+ integrators in...
Stealth / UCIT - Remote Video Monitoring Provider Profile on May 18, 2018
Can 2 remote video monitoring companies, Stealth Monitoring from the US and UCIT from Canada combine to impact the market and compete in a changing...
Cybersecurity for IP Video Surveillance Guide on May 18, 2018
Keeping surveillance networks secure can be a daunting task, but there are several methods that can greatly reduce risk, especially when used in...
Forced Entry / Duress Access Tutorial on May 17, 2018
Even though access control normally keeps people safe, tragedies have revealed a significant issue. If users are forced to unlock doors for...
ADT Stock Drops 50% Since IPO on May 17, 2018
It has been a brutal 4 months for ADT. They first expected to IPO at ~$18. They IPOed at $14, dropping immediately to $12.39 And now, not even...

The world's leading video surveillance information source, IPVM provides the best reporting, testing and training for 10,000+ members globally. Dedicated to independent and objective information, we uniquely refuse any and all advertisements, sponsorship and consulting from manufacturers.

About | FAQ | Contact