Hikvision Cloud / QR Codes Enables Livestreaming Child Pornography Explained

Published Jul 17, 2023 12:45 PM

Many mistakenly believe that child pornography being sold online from hacked Hikvision cameras was only due to "old" vulnerabilities. Far more concerning, it is Hikvision's own current cloud software and QR code functionality that enables criminals to livestream child pornography.

IPVM Image

While child pornography distribution is especially heinous, IPVM has found that hackers are more broadly using Hik-Connect QR codes to spy on all sorts of Hikvision end users.

IPVM already has existing Research both testing the Hik-Connect app and testing Hik-Connect's cybersecurity.

Now in this new IPVM testing, we examine how Hikvision generates QR codes, how simple they are to share with other users, the fundamental security risks involved, and what we recommend for users and Hikvision to do to stop their systems from being exploited.

QR **** **********

*** ** **** ******** ********* ****** is ********* **** **** **** *** accustomed ** **** ***** ************ *******.

*** **** ****** ******** ** **** there ** * ** **** ** the ****** *** *** ***** **** to ******* ** *** *****, *********** the ****** **** * ******** ******** account.

**** ******** ** *********** *** ********, you ** **** *** ***** ****** and ** ********* * ** **** that *** ** ****** ** ******* to *** ******.

IPVM Image

********

*** ***** ***** ********* *** **** is ********* *** *** ***** ********:

IPVM Image

Executive *******

*********'* ****** ** ******** * ** code ** ****** ******* ** *** current ***-******* *** ****** ********* ** quickly *** ****** ***** ********* ********* cameras ** **** **** *** ************ users, ******** **** ** ***** **** and ******** *****. *** ************ ****** is ********* ******* ** *** ****** owner/victim ******* ***** *** ** ************* that *** ****** *** **** ****** because *** ******** ** ***** ** administrator ******* ** ***** *** ** code.

******** ******* ***** **** *** ** code ****** **** *** ********** *****, ******* *** ** **** *** be ********* ********, ** ****** ********* to ******** * **** ******* ***** access ** *** ******. **********, ********* required * ************ **** **** *** printed ** * ******** ***** ** the ****** *** ***** *** ** changed.

Hik-Connect *** ****** ******* ******* **-**** *********

***** ********* ******** * ******* *** adding ******* ** ***-*******, *** ***** complex ****** **** * **-**** ****, which *** ** **** ** *** up ** ** ******* **** * single ****. **** ** ******* ** Hikvision's ********* ** *** *******:

IPVM Image

********* ******* ********* *************** ** ******** access *** ****** ******** **** ** administrator ******* *** **** *** * non-admin **** **** ** **** ******* to **** *****, ******** *** ****** to ****** ***** ****** *** ***** that ****** **** * ** ****.

**** **** *** ***-******* ********** *** ** ****. ***-******* ******** ** *********** *** QR ****, **** * ******** **** of *** **** *** ** ** 365 ****:

IPVM Image

***** ** *** *******, ** ******** 10+ ** ***** *** ** ********* (within ~*-* *******), *** ******* **************** blocked ** **** ******** ****. **** enables ********* ** **** ****** ** the **** ******* ******** ** *****. Below ** * **** ** ** codes ****** **** *** **** *******, within * **-****** ******:

*** ********* **** ***** ***** *** quick ** ** ** ******** * QR ****, *** *** *** ********* can *** / ********** *** ** codes, ***** *** ******* ***** *** Hik-Connect ***, ***** ***** ****** ** live *** ******** ***** **** ****:

Users ******** ** ******** ************ ** **** *******

***** *** ***-******* *** ** ***** controlled, *** ***-******* *** ********* *** QR **** ******* *** **** *** use ** *** *** ***** ** Hik-Connect's ***** *******. **** ***** ** difficult ** ***** ****** ******* *** end ***** ** ********* *******.

***** ** ** ****/******* ** *** Hik-Connect *** **** ********** ** *** camera ** ***** ******:

IPVM Image

*******, ** *** ****** ** *** using ***-*******, ** **** ** **** are *** ***** ***-******* *********, **** would ****** ***** *** *** "*******", or ** ***** ** ****/***** ****** they **. ***** ** ** *** notification **** *** ****** *** **** shared **** ******* ****. **** ** a **** *** *** *** "*******" message, **** *** *** **** **** what ** *****.

****, ** **** *** ************ ******* the ****** ******* * ***-******* ***** (e.g., * ******* ** * *********, business ***** *** *******, ***.), **** "Sharing" **** ***** ******** ** ******* and ***** *** ***** ******* *** those *****.

******, ** * ********* **** ***** to ***** *** ***** **** *** camera *** ****** ****, *** **** is *** ******* **** ********** *** infrequent *****. ** *** ***** *****, IPVM ***** *** *** ** ****** this ***** *** ***-******* ***:

******* ****** ***** * **** *** verify ** ** **** ***** "*****," they *** *********** **** * **** of ********** *** *** ****** *******:

IPVM Image

Stop ******** ** **** ******* ***********

*** **** ********* ************** ** ******* the ******* ** *** ********* ** update ***-******* ** ** ****** ******** QR ***** *** *******.

***** **** ***** ****** ********* ******** for ********** *****, ***-******* ******* ****** 2 ***** ******* *** ****** *******; manually ****** ******* ** *******/****/********, *** local ******* ******** *** ****** ********* devices.

Old ****** ******** ***** ************ ****

******* ******* ** ********* ***** ********** **** **** ** **** ********, Hikvision **** ******** ******** * "****** Verification ****" **** *** **** ******* on * ******** ***** ** *** device:

IPVM Image

*********, **** ***-******* *******, ********* ****** this ** * "****** **********/********** ***" which *** ** ****** ** *** web ********* *** **** ******* **** the ***:

IPVM Image

******* ********* *** ******* ************* ****** remotely ** ********* ********* *******, **** are **** ** *** *** *** without ****** ******** ******.

******* ** *** ************** ** ******** QR **** *******, **** ***** ****** create ********** ******** *** ********** ***** but ***** ************* ******** *** **** of ************ *******.

App ************ **** ****** ** ******

***** ***-******* ****** *** ****** "*******" in *** ***, ** **** *** pop ** ** *** ************ **** the ****** *** **** ******, ** it **** **** ****** ******, ***** notifications, ***. ***** ** **** ** email ** *** ************ **** * device *** **** ******.

*** **** **** ******** *** ***** link *** * ***-** ******* ** logging **** ***-*******:

IPVM Image

***-******* ****** ******** ** *** ************ to *** ************* ***** **** *** camera *** **** ******. *******, **** would *** **** ***** **** *** not ***** ***-*******, ****** ***** ****** cover * *********** ******* ** *********** or ***** ******** ********* *****.

Require ***** ********** - *****-****** ************** / **** *******

** ******** ** ******* ******** *******, requiring ***** ********** *** *** ****** devices **** ***-******* ***** ***** ***** to ****** *****-****** ************** *** ******* local *** ** ******. **** ****** mitigate ************ ****** ***/** ** ***** provide ****** **** ******* *********** **** could ** ******** ** ***** ** Hikvision *******.

Comments (20)
Avatar
Mark Jones
Jul 17, 2023

** ***** *** ******** ** *** that **** *** ******* ********? *** before *** ***, ** **** ******.

JW
Jermaine Wilson
Jul 17, 2023
IPVMU Certified
JH
John Honovich
Jul 17, 2023
IPVM

***, ** ******, ***** ** ****** of ******** **** *** **** ***** on *** ***** **** ****. *** the ******** ****** -***** *********** ** **** **** ****** Hikvision ******* ***** ******* ***-******* ***. ** ******* ******** ****** ** marketing ****** **** ******* ***-*******, *** example ** *****:

IPVM Image

UI
Undisclosed Integrator #1
Jul 17, 2023

*'* ******* **** ** *********** ** Hik's **** (***). *** **** **** has **** **** ******, *** **** will ****** ****** ***** **** **** may ******* ***** *******. ***** *** SO **** ******* **** *** ********* and ******* *** **** **** ***** it.

(1)
DS
David Straede
Jul 17, 2023

**** **** *** ** **?

*) ** ** ******** ****** ***: "hacked ***** *******" ** "****** ********" if *** **** ***** *** ******* to ****

*) ********* **** ** *** ** admin ******** ** * ****** ** any ***** **** ****** ********* ** file *******, *** *******: *) * video ******, *) * *******, *) A ***** **** *****, *) ***** as * ******* *******

*) ***** *** ***** ** ******* images *** *** **** *** ***** of *** ****** **** *** **** it

*) ****** **** ********* *** ***** it *** ** **** *** ***** porn

(1)
(2)
JH
John Honovich
Jul 17, 2023
IPVM

***** ** *** ** **** *** child ****

**** ** *** **** ** *****? There's * ******* *********** **** **** **** ********* ***** pornography *** ** ** * *** years** **** **** ***.

***** **** ******** **** ** ********,******** ******** *** ******** *** ******* them*** **** **** *** **** *** criminals **** ************* ***** ***-*******, ** just ***** ** ****** *** **** to ****** **. **** **** **** sense?

(1)
DS
David Straede
Jul 17, 2023

***** "****** *** *** ** *** hundreds ** ************ ****, ** *** have *** ***** ********, *** *** share ******* *******" ** **** ********?

(2)
JH
John Honovich
Jul 17, 2023
IPVM

****'* * **** ********. ****** *** admin ******** ** *** *** ** hack / ***** ****** ** * system.

****'* ********* **** ** **** *** criminals *** ***** ***-******* ** ******* their ************ / *****. **** ******** is **********. ** ***** ***-******* *** QR *****, **** ** *** ***** admin ****** *** **** ******* (*********** turn ** ** ***) *** *** access ** **** ** **** **** send *** *** **** ********* *** settings.

**** **** ****?

DS
David Straede
Jul 17, 2023

** ** * ****** *********** * webserver, *** ***, ** *** ***** of ******, **** *** **** *** and ** *** *** ****** *** then **** ** ** * *** device **** **** *** **********? ******* calling **** "*** *** **** *** uses ********, *******, *** *******, *** IoT *******" *** *** ***** **** is *** *******'* *****.

(1)
JH
John Honovich
Jul 17, 2023
IPVM

"*** *** **** *** **** ********, cameras, *** *******, *** *** *******" and *** ***** **** ** *** company's *****.

*****, **** ** * ******** ******* issue ***, *** **** *****, ** is * ******** *******'* *****, ***** they *** ********* *** ***** *** company's ***** ************** *** *** *** distribution.

(1)
Avatar
Brian Karas
Jul 17, 2023
Pelican Zero

* ******* **** * ***** ****** here ** **** *** ******* **** the ****** ** *** ***** ****, they **** ********* ** ******** *** homes **** ********.

***** ******** **** *** ** **** to ***** **** *** ** ******** used ** ***** ******* ******** ******* elsewhere, **** ** *** *** **** as **** *** ******** ****.

************, ***** *** **** ************ ** Hikvision **** ** *** **** *** ongoing ***** ******** ******. **'** ******* about *+ ***** ** ***** ***** security ****** ***** ********** *** ********* on ********* *******. ***** *** ****** can ************* **** * *************, ********* has ************ ************ **** ***** ******** is *** * *** ******* *** them. **** **** ******** ****** *** development ********* **** ********** ***** *******, such ** **** ** **** ** remote ******, ***** ***** ********.

** ** ************** **** ********** *** DIYers *** *** ***** ********** *** risks *** ******, *** ** ****-**** security ************ ****** ** ***** ** recommending ********* ** **** *****. ** would ** *** ********** ** ******* a ****** *** ******* ******** ***** ***** ****** *********** ***** ****. ****, ***** *** won't *** ***, *** ****'* *** good ******.

(3)
UI
Undisclosed Integrator #2
Jul 17, 2023

* ***** *** ** ** ******* scanning ** ****** *******, *** * am ***** **** ***** *** ***** manufacturers **** ** *** **** ****** to *** *******. ** **** **** of ******** **** ** ***** *************?

Avatar
Sean Patton
Jul 17, 2023

**, **** ** *********. ***** *** 2 *********** **********. *** **** ****** approach ** **** ***** ** * QR **** ** *** ****** *** one ***** **** ** ******* ** the *****, *********** *** ****** **** 1 ******** ******** *******.

**** ******** ** *********** *** ********, you ** **** *** ***** ****** and ** ********* * ** **** that *** ** ****** ** ******* to *** ******. ** **** ****** and ***** **** ****** *********,****** *-****** ****, ************ ** ******, ** **** * ***.

(3)
JH
John Honovich
Jul 18, 2023
IPVM

**'** ***** * ******* ** *** report ** ****** ********** ***** * different **** ** ** *****:

IPVM Image

UM
Undisclosed Manufacturer #4
Jul 18, 2023

** *******, *****, ******, ** ********* QR ***** ********** * ******* ** or ******* **** **** ******** *** device ** *** *****. *** ** is **** *** ******** *** ******** the ***** ***********. *** **** ** generating **-****** *** ** ***** **** are **** ******.

UI
Undisclosed Integrator #3
Jul 17, 2023

**** *********'* ******** ******* ******* *** remote ****** **** *** ******? *** example, **** ** ***** **** **** users ** **** *** ***** ************ (or **** **** ** ******* ********) and ******* ** ****** *********?

UM
Undisclosed Manufacturer #4
Jul 17, 2023

** **** *********, *** **** ** backwards. **** ********* *** **** *** cloud ****** ******* * ** **** or ** ** ********* **** *** use ** ******* ******** ******* *** cloud. *** ******* **** **** * username *** * ********.

** *** ***** **** ****** ** being ******, *** ****** *** ***********.

**** *** ** ***** **** ** different, ** **** *** ****** (*** mobile ***) ****** *** ** *********** generate ******** **** ** ** ***** for ****** ******. *** ***** ***** who *** ****** *** ** **** about ****, ** **** *** ********* off ******.

***, ******* ** ***'* **** ***** record ** ***** *** **** ***************, the ******* **** * ***** **** of ******* ********* *** **** *** place ***** ***** ** *** ******* of *** **** **** ****** ***** devices.

** *** ******** ***** ***** *****, they ***** ********* **** ***** ******* are *** **** *** ***** *** that **** *** *** ********* ** people *** ****/**** ***** *****, *** thus **** ****** ***** *** ***. Mandate **** *** ** ****. **** a *** ** **** ** ******* is ******. *** *********** ********* ** block **** ****** ******* * ********** area, ** ******* **-**************. ** *********.*******, they **** ***** *** *****. ** is ******* *********** *** ********** ********. Deny *** *****. **** ******** **** everything ******** ****** ****.

(3)
(2)
Avatar
Blake Murphy
Jul 17, 2023

*********** ** ** ******* **** ***** people *** ***** *** **** **** or *** ******** ** *** ***********, in ***** ** ******* ***** *** ethical ********... ********** * **** ***** supported ******* ******* ******* ** *** bedrooms ** ***** ********, ****** ** as ** ******** ** *** *****'* privacy. * ***** ** ** * bad ****** *** ****** ** ****** on ***** ******** ** ********* ***** parenting ******. **** ** * **** area, *** ** **** ********** **** no ******* ****** ***** **** ** installation.

** **** ** ***; ******* ** the ******** ** ********, ******* **/* & * ******* *** *** **** it ********* **** ** ***** ********* logins ****** *** *****. *** **** areas *** ******** ****** & ** still **** ****** ******** ***** **** saying "**'* **** *****, **'* **** smoke!"

** ***** **** ** **** ** rely ** *** ****** ********* ** argue *** ****** *** *** ********!? After ***, **** **** **** ******* this ******* ****** *** * ****** of *****. **** **?

"** **** ***'* *** ** ** the ******** ***', **** *** ***'* have ** *****."* ***** ***** "** ****, * can ****** **** ****** ******* ** now..."

(1)
UI
Undisclosed Integrator #5
Jul 18, 2023

********** * **** ***** ********* ******* putting ******* ** *** ******** ** their ********...

********** * ***** *** ********-********* ******* in *** **** *** * *** idea ***** ****. ***** **** *****'* another ******* ** ***** ***** * vulnerability, ****, ** ***** ******** ******** exposing *********. ** ****** **** *** centuries ******* ******* ******* ** *** home; ** *** ***** ** ** today.

UI
Undisclosed Integrator #5
Jul 18, 2023

**** ** ********* *** ** *** this ***** *** **** **** ** iVMS-4500. ** ***** ******** * ** code *** * ****** **** ***** bypass *** ************** *** ***** * third ***** ****** ****** ** *** live *** ******** *******; ********* ********** a '**** *** *****' **** ** action.

*** ***** *** ** ** ********* building ********* *** *****, *****, *** drugs. *** ********* *** ********** ** be ******* *** **** ** ************ persons. *** **** **** ** **** them ******* ** **** ** ***** they ***** ** **** *** ***** they ******'*, *** ** ***** ** having ** ****** ***** *********** ** a ******.

(1)