Hikvision Security Code Cracked

Author: IPVM Team, Published on Aug 08, 2017

Hikvision's 'security code' feature has been cracked and a program generating security codes is being distributed online. IPVM has obtained and tested this program, verifying that it works.

Hikvision 'security code' allows unauthenticated users to access Hikvision recorders locally regardless of the admin password strength. Hikvision has used this as a tech support feature, as we covered and explained in this report.

Hikvision has historically called this 'security code' or 'security codes', e.g.:

Now, anyone with this program can generate a security code that resets the admin password and takes over the Hikvision recorder. Hikvision does not allow disabling this 'security code' feature.

Inside this note, we show how the program works, what it does and what risks it poses.

*********'* '******** ****' ******* *** **** ******* *** * ******* generating ******** ***** ** ***** *********** ******. **** *** ******** and ****** **** *******, ********* **** ** *****.

********* '******** ****' ****** *************** ***** ** ****** ********* ********* locally ********** ** *** ***** ******** ********. ********* *** **** this ** ***** ******* *******, ** ** ******* *** ********* ** **** report.

********* *** ************ ****** **** '******** ****' ** '******** *****', e.g.:

***, ****** **** **** ******* *** ******** * ******** **** that ****** *** ***** ******** *** ***** **** *** ********* recorder. ********* **** *** ***** ********* **** '******** ****' *******.

****** **** ****, ** **** *** *** ******* *****, **** it **** *** **** ***** ** *****.

[***************]

Cracked ******* ********

*** **** ********* ** *********** ** * ***** (****) ******* executable. ** **** *** ******* *** ************ *** *** ** run ******** ******* ************* ****** ** *** ******* ************. ** are *** ************ *** *******, ** ** ******** * ******** risk ** ********* *****.

** *** ******* ** *** **** *********, *** ****** **** entering *** ** ******* ** *** ********* ********:

****, **** *** ** ******* ** ******** ** ***** * Hikvision ****** *** *** ***** *** ****** ****** ** *** unit, *** *** **** *** **** ** ******** * ***** code ***. **** **** ****, *** ******** ******* * ******** code **** *** ** **** ** ***** *** ***** ********:

*** **** *** **** ** **** ** *** ********* ******* to **** *** *** ***** ******** *** *** * *** one, ** ***** ***** ** *** **** ****:

* ******* ** *** ******** ** ************ ** * ******* video:

[******] - *** ******** ****** ******* *** *****, ** *** not ******* * ***** *********** ****** *** ****** *** ***** so.

***** **** *****, *** ****** ***** *** ******* ** ******* the ****, ** ******** ***** *** ****** *****, ** ** case *** ****** **** ** *** **** *** *********.

Feedback **** ******* ******* ******

*** ****** ** *** ********,***********, **** ** *** *** ****** *** **** *** *******, but ******* ** **** ******, *** **** *********** *** *** YouTube *******. ** **** ** ** ******* ** ******** *** software ** ******* ***** ***** *** **** ********* *******, ** it ********* **** ***** *** *********. ** **** ****** **** support ********** *** ********* ****[****** - *** ****** ******* *** ******** **** ** ****].

Works ** *** *-***, ****** ***** ****

**** ******** **** *** ******** **** ***** ******* ***** ** an *** *-*** ******** ***** **-*******, ********* ******* **** *** local ******* / **** ** ***** ******** ** ***** ** the ********** *****:

** *** ****** *-*** ******** (*.*.*) *** ***** **** ******, but ******* ** *** ********* ******** ** *** ** ** entered ** *** ********* ***** *******.

** ******* **** ************** **** (** ***** ***** *** ****** **+)*** ******** ** **** ** ****.

[******: *-*** ***** **** ****.*.* ***** ****** (******** ****). *** ****** ** ******* *** **** *** **** *******.]

Benefits ** ********* ******* / ********

********* ******* *** ******** *** ****** ***** **** ******* ***** and **** ** ********* **** ******* *** ***** ******** ****** by **********, ****** **** ****** ** ******* *** **** *** Hikvision ** *******.

Benefits ** ********* ***********

********* ***********, **** *********** *** *************, *** **** *** ***** how ******** ********* ** ** ***** **** ******* ** ****** Hikvision *********. ** ***** *** * ******** **-**** *************, ********** since ********* *** ******** *** *********** ** ****** ********* **** can *** ** ****** **********.

Detrimental ** ********** ********* *****

*********'* ** *** ****** ********* ******** **** ****-****** ******* (******, Alibaba, ***.) ***** ******** *** **** ********* ** ***** ******. One ********* *********'* ********** **** ****** ** *** ******* ** get ******** ********* ******* *******, **** ** *** ***** ******** resets. ** ********* **** ****, ******* *** ******* ***** *** password ****** *** ********* ******* ******* ** ******* ********* *******, reducing ***** ********* ** *** ******* ********** ********.

Cannot ** ********

*************, *** '******** ****' ******* ** **** ***** **** ********* recorders *** ****** ** ********. ** **** ******** **** ********* if ** **** **** ***** *** **** ****** ** ***** users ** ***** **** *************.

Atypical *** ******* *************

*** ***** ******** ***** ******* ** **** ******* ** ******* companies. ***** *** * ******* '***** ********' *******, *** ** enterprising*********** ******* *** ******** ****** ******** *****, *** ********* **** ********, *******, *********, ***. ** *** allow * ****** ** **** ** ** *** ******** *** wipe *** *** ***** ******** **** ******* *****.

Cybersecurity ******** *** *********

************* *** **** ** ******* ***** *** *********. *** *********** for ***** ********* ** ** ***** ** ***, *** ******* any ********* **********, ** ** ***** ******. ****** *** ***** code ********* ****** ********* ***** *** ******* **** **** ******. Hikvision *** ************************** **** **** ************* *********, *** **** ***** ******** **** their ******** **** ***** ***** ********* ** ** ***** *** easily, *** ******* **** ********* ***** **** **** ********.

********** *********, ***** ********* ** ****** ** ****** ***** ********, view *************** **** ****** ***** ******** ****** ** ****** ***********, and **** ***** ****** *** ******* **** ****** **** **** security.

UPDATE - **** ******* ** ******** *****

**** ****, ****** *** *** ******** ** *** **** ** a ******* ********** ********* ********** ** ******** **********-***** ********, ******** of *****:

*** ******* ****** **** *** ** ***** ***** ******** *** same ****** **** * ***** ****** ******/**** ******. ****** *********** ** *** ********* **** ********* ** *** *** **** on ***** ********, *** ***** ***** **** ** **** ***** **** ** recent ******** ********, ** ** ****** ** **.*.*.

*** ******* *** ********** ***** (*** ********** *** *******-***** ****) use ** ******* ***** ***** ***** ** ***** *****, ********** some **** **** *** ******'* ****** ****** *** **** ******** is ********** ** * '***** ******', **** *** ****** ** the '***** ******' **** ********* ** ***** ********** **** *** be ******* ** * ******** ********:

Update * - ********* ******** **** "******** ***** ******"

** ****** **, ****, ********* **** * '******* ********' ***** * **** ******** ******** "********* ***/*** ******** ***** ******". ** ******** * ******* ** ******** ********** ** ******** passwords ****** ******* *********. ** **** ********* * **** **** Hikvision ********* *************** ** ** ******* *** ******* *** **** to ****** *** **** ***********.

*** ********* *****:

(*) ********* ****** ** *** ******** ***** ** "**-****** ********* 'security ****'". ** ** *****, ** *** *** **** '******** code' ******* **** ** *********'* *** **** *** **** *******, e.g., *** ******* ** ********* ********* ******* ** * '******** ****'.

(*) ********* ******* ****** *** ******** **** ***** ******** **** was *******. ****** **** ********* * ***** ******** **** ***** overcome **** *******. **** ******** ** **** ** **** ** reviewing ** ****** **** ********* *** **** ******* ** ******.

Update * - ****/*** ******** ** ********* ******** *** *** ******

*** ******** ** *********'* ******** *** **** ********:********* ******** ** ******* ******** *****

Comments (59)

* ***** ****** ** *** ******** *********** ***** ** *** best ****** ** ********* **** *****. ** ***** ** ******, effective, *** ***** ****** **** ******* ***** ** ****

** ** *****, **** **** **** **** ******* ** *** LAN ** ** ***** * *** ** *** **** ******** as ****? * ***'* ***** *** **** **** ***** ******** but * **** ** **** **** * ********** **** **** accurately

**** ********* ****** ** ********* *** ********* *******, ** *** are ******* ** ***** ** ** * *** (** ***).

****** -

***** **** ********** ****** ** *** ******* ******* ******** *******:

*** **** ********* ** *********** ** * ***** (****) ******* executable. ** **** *** ******* *** ************ *** *** ** run ******** ******* ************* ****** ** *** ******* ************. ** are *** ************ *** *******, ** ** ******** * ******** risk ** ********* *****.

*** *****,

*** **** **** ******* ****** **** ***"********* ******** ***** ****" that ** ********* ** *********? **** **** * *** ********* it ***** **** ** ** **** * ********* *** **** what **** **** ****** ** ***** *******.

*****://*********.***/*****/*********-********-*****-****/

** *** **** ***** ** **** ***** **** *** *** previous ******* *** **********. **** ******** *** **** ****** **** the ****** *******/***** ** ****** ****. *** *** ******* **** they *** ********* ********* ***'* ********* *** **** *******.

*** ********* ****** *** ***** ** *** ****** ** ******* this:

UPDATE - **** ******* ** ******** *****

**** ****, ****** *** *** ******** ** *** **** ** a ******* ********** ********* ********** ** ******** **********-***** ********, ******** of *****:

*** ******* ****** **** *** ** ***** ***** ******** *** same ****** **** * ***** ****** ******/**** ******. ****** *********** ** *** ********* **** ********* ** *** *** **** on ***** ********, ***** ***** **** ** **** ***** **** ** ****** recorder ********, ** ** *** ****** ** ******* *.*.*.

*** ******* *** ********** ***** (*** ********** *** *******-***** ****) use ** ******* ***** ***** ***** ** ***** *****, ********** some **** **** *** ******'* ****** ****** *** **** ******** is ********** ** * '***** ******', **** *** ****** ** the '***** ******' **** ********* ** ***** ********** **** *** be ******* ** * ******** ********:

* ******* *** ***** ********* ** *** ***** **** *** older ******** *** ****'* **** *******. *** ***** **** ***** work ** ****?

**** *** *****, *** ********* *** ***** ** ***** **** these *****, ****** *** ****** *** ****, ** **** ***** the ***** *** ** ** **** **** *** ********* ***** console. *****, **** ****, *** ******* * ******** ****.

****** ** *** ******* *********, ** ***** *** **** ********* on **** ***** ******** ******** *** ** ***** ****. ** will *** ***** ** *******.

**** - *** *** ******* ******* ** **** ********/******** ******** you ******? ****, *** *** *** *** ***** ***** **** via **** ** **** **** *** ***** *******?

*** ***** **** ***** ** *** *** ****** ** "*****" firmwares **** **** *** ****** **** **** ****** *** ** enter * ****** ****. *** ***** ********* ***'* **** *** hidden **** ** ****/****, ******* ****** *** * **** ******** file **** ** ******** ** ** ******* ****** *** ******* setup.

**** ******* * ****** ** ** * ****** **** ******** 5.4.0, * ****** **** ******** *.*.*, *** *.*.* *** **** of **** ******.

*******, ** **** ***** ******* **** ******** ***** *.*.*. * tested ** ** ** *** **-*******-* **** ******** *.*.* *** it ******.

**** ******* * ****** ** ** * ******

** ********* ******** ***** ** *** ******, **** *** ******** at *********, *** *******. **** ********* **** ****** ******** ***** be ******** ***** *** ***** *********.

*******, * ******** ********* ** ** * ****** **** **** cameras *** ****. ** *** *** ********* * ********* ********, the ******* *** ********* ***** ** ** "****** **" **** a ******* ***********, *** **** ****** *** ******** **********. ************, the ******* ***** ********* *** ***** *** *****.

*** ********, *******, *** ****** *****, *** ******** ****** ** all *** ******* ********* ** **. ********* *** ********* ************** opens ** *** **** ** * **** ****** ******* ****.

** ** ****, *** ** *** ** **** ************ **** a **** **** ****** * ********. * *** * ****** lose *** ******** ** ***** ***** ***** ***, *** *** factory ******** * ****-****** ***** ******* ** ** ***** ** default. *******, **** *** ****** **** ** **, *** *'* sure **** ************* ***** ** ****** **** ***.

*** *** ******* **** ********* ** *** *** **** ******* with * **** **** ********, ** ******* *** ***** *** XiongMai ** *** ***** ********* **** **** **** **** ********. It *** **** ***** **** **** ** *** **** ****** among ***-******* *************, *** ** ****** *** ******** ******* ********** (e.g.:a **** ******** ** *** * ***** *******) ** ***** be ********** ** ******* **** ***** ************* **** **** ********.

************, ***** ** * ********** ******* * "***** ** ********" and ** ***** ******** *****. **** * ******* *****, *** situation ****** ** **** **** *******, *** ***** ********* ******* wiping *** ****** ***** ** ****** ** *************. **** ** least ***** ** ****** ** ****** **** *** **** *** been ***********, *** ********* ***** ** ** **** ******* ****** retrieve **** **** *** **** ** ** ** ***********. ** also ******* *** *** ***** ** ******* ***, ********* ******** access ** * ****** ** ****** ****** *** **** **** makes ** **** **** ********* *** ** ******** ** ** this ******* ***** *******.

***, ** ********* ** ** ****, * **** ********* ********* has ************ ******** ** ****, *******, * ******'* ** ********* to **** **** ** ***** * ******** **** *** ***-******* companies. *** * ** ****** **** *** **** ****** ** the ***** **** *** * ********* ** *** ********, *** data *** **** ******. * ***** ****, ****** **** ***** is * ********** ***** **** **** "****** **" *** "*********" is ********* *****'* ******** *** **********.

**** **** ** ** *** ***. * ** ****** **** that **** ****** ***** *** **% ** *** ********* ******* out ** *** *****. * **** **** *********'* **** ****** to ***** ***** ******** *** ****** **** ***** *********'* ********, 5.4.x(these *** *** *******), *** ****** ********* **** ** ****** works.

** * ***** ********* ********, *** ***** **** ** ****** a *** **** **** *** ******/*** ***** **** ** * local *******, ****, **** ** **** ** ********* ***********. ********* Techsupport ***** ***** *** **** * *** **** ***** **** that *** *** ****** **** ***** ****, **** *** ***** password ***** ** *****.

********* *** **** **** **** ** ******* **** ********* ******* authoirzed ** ******* **** ** *** ****** ********* ** *******.

*****, ****** *** *** ********.

********* *** **** **** **** ** ******* **** ********* ******* authoirzed ** ******* **** ** *** ****** ********* ** *******.

********: *******, *** *** **** **** **** ** ****?

********* *** **** **** ** *********** ** *** ******** **** sold ** ***,***-** ****** *** **** *****.

**** **** **** ****** ** *********'* ***** ****** ******** ** some ****. * ***** **** ** *** *********** ** * Winic ********* ***, *** **** ******* **** **** *** **** to *****. **** **** ****** ***** ***** ** ***, *** understandable. **** ** ** **** **** ******* **** ** *** Hikvision, *** ********* *****.

********* ******** *** ** ****** *** ****** ****** ** *** unit. ****'* *** **** ***** **.

** ****** *** ***** ********'* ********* *** *** ** **** a ****** *** ********* *** ***** ********, ***** **** **** a *** ****** ****** **** **** ******* ***** ***** ******. You ***** "****** ********" ** *** *** *** ** ***** a ******** **** *** *** ** ****** *** ***** ******** on *** ***** ***.

****** -

***** **** ********** ****** ** *** *-*** **** ******* ** list *** ***** ****** ****** (**-*******) *** ** ******* **** ** ****** **** **** *** older ********, *** *** ***** ******* **** *** ******/****** ********, 3.4.2.

**** ** ******** ** ***** **** *** ****. *** ****** generator *** ***** ******* *** ******** *** **** ****** *** years. ***** ******** *** ***** ****. **** * ***** **** this * *** ******** ******* *** ******* *** *** *** to ***** ******** *** ****'* *** *** ****.

*** **** ******* **** ** **** **** ******* ***** *** have ***** ********* ***** *** *** *** ******* ****'** ******* old ********, ** **** *******?

*** **** ******* **** ** **** **** ******* ***** *** have ***** ********* ***** *** *** *** ******* ****'** ******* old ********, ** **** *******?

***** ********* ****** *** *** **** **** *** ****** ********?

*** ****** ***** ***** **** **** ***** ******* **** ***'* upgrade ** *** ****** ******** ** ******** *********. ****'* ** to *** ***.

* ******* **** ** *** ***-*** ******, *** * *** K ******, ******* *******.

**** ***** **** * *** **** ** *** ******.

**** ******** ** *****, *** **** **** ********* ** ******* hikvision ******** **** *** ****** ********? ** **** *** *-*** unit?

***** *** *** ******/******** ******** **** ** **** **** ** successfully ******* *** ***** ******** ***** **:

********* **-******-**/** ********:

**.*.****** ******

**.*.* ***** ******

**** **-******* ********:

**.*.****** ******

** *** **** *** *** ******* ** * ******** ***** NVR *** ** *** ***, ******* ** ***** ******** *** generated **** **** ********** ** ***** ******** *****.

** ***** ** *********'* ********, *** ***** **** ****'* ******** anymore. ***** *** *** ****** ********, *** ******* *** * series ****.

*** ***** ** **** **** *** ***** ****. ******* ** longer **** **** **** ******** **** ***** *** ***** **** don't ******.

* ***'* ******* ********* ** *** **** ************ *** *** a *** ** **** **** * ******** ******* ****** *** password *****. * **** **** ****** *** **** **** ***** when ********* *** **** ** ********* ** ** *** *** back **** *** ********* - (**** ******** **** ****** ******* manufacturers ** ****). ** * ****** ** * *********** **** running ***** ********* * **** * *** **** **** **** within *******. *** ** **** ** ** ****** (** ******** logged ** ** *** ***** ****** **** * ********** **** program) *** ****** ******* **** *** ********* ***** ** ******** then ******* ** *** ******** ******** *********. *** * ************ I **** *** **** **** ************ ** ** ***** ** I ***'* **** ** **** **** ******* ** **** ** back **** ** - *** *'* *** * **** *'* in *****! ** ** ***'* **** * ********* *****, *** reported *** *** ** * ********* *** ** ** **, but *** ******** ** *** **** ***** ********* ******* ******* the *********.

************, *** ***** *** *** **** ** ******* ***** **** this **** ******** ***********. ***** **** *** ****** ***** ** be ****** - ** **'* ******** ** ******* ****** ***** be *** *******, *** ****'* *** ****** **** * ***** person ***** **** *** ***** ******** ** **** ** *** - ******* ** *** ** ********** - *** *** ******* have *** *********.

*** ******* ***** **** **** ******** ***** ****** ** **** all *** **** ** ******* ** ** ****** ** *** LAN. **** * **** ** ****** **** ** ********* **** on *** ******** ******* **** ********* ******* * *** *** them ***. **** ** ** ********** ** ***** ************ **** have * ******** ***** ****** **** **** ** **** ** reset *** ***** ********. **** ** * ***** ** *** discussion.

**** ***** ***** ** ***** ************ ** *** **** ****** some ** *** ****** *** ******** ****. ** ***** ********. Being * ************ **** ******* ****** ******** ** *** ********, personal ******* ****** ** ********* ****** ** *** ******.

* *****. *** **** ****** *** ** **** ** * large ***** ** **** ********. * **** ***** ** ******** on ********* ** ** ******** ******* **** **** *** ***** of **** ****. *** *** **** ** ****** ********* ************.

* ****'* ******** ** **** ****, *** ** **** ****'* readily ******** ********* ******* ***. * ****** ***'* ********** *** they *** ******* ** **** ***** ** * ******** ** low-end ** ****** ************* ******* ***** ******* **** **** ** no *****-******** ***********. *'* *** ********* ***, ***** *** ********, I ********* **** **** **** **-****** "******* ******", ****** ************ called *** ** ** ******. *** ** * ****, * grow ***** ** ****** **** ** ********* * ******** ****** portrayed ** "****** ****".

******, ****** *** **** ********. * ********** **.

** *** *** ********* ******* *********, **** ** * ****** accusation. ** ************ *****, ********* *** ****** ***** ** ****, Anixter ****** ***** ** **** ****, ******** ****** ***** ** hate ****, **** ****** ***** ** **** ****, ** *** on...

*** ***** ** ***** ******* **** ****** *** ******. ** Hikvision *** *** *** ******* *** ******** *** ****, ***. are ***** ** **** *** **** ********* **** ***** *******. This ** *** * ****** ****** - ***** *** ********* far **** ****** *** ************ ****** (***** ** **** **** focuses **) **** ******* *******.

******** ** ***-*** ** ****** ************* ******* ***** ******* **** poor ** ** *****-******** ***********

*** *******,****** *** ****** ***,*** ****** ************* *** '**********'. ** *** **** *********** *** ******** ****. ** ******* not ** ** * ****, *** ******* ** '****' *** 'NeoCoolCam' ****** (** **** ** **** *** **** ***) *** because ** **** *** ******* ************** ******* *** *** ******* with ****, ** ** ** ********** ** **** **** **.

* **** **** ***** ******* *** ********* *******. ***** ** answer **** ********* ****.

******** *******

******, **** **** ** '******** *******' ************ ** *** **** IPVM ** ****** ******* ******?

******* ***. ** * **** ** ***** *** ***** ****** of "********" ***** ********* *************, ** * ********* ** *********** that *** ****** ** ******** *********** ** *** ***** *** outnumber ******** *********** ***** *************?

******,

** **** ****** ** ******** ***** ***** *********, **** **** the ****** ** ***:

** *** ***** ** ******** ******** *** ************* ***** ********* **** ** *** ***** ** **** ***** almost *** ***** ******* ******* ** *********'* ***** ****.

******* **** ** **** ***** *******. ** *** ** * complete ******, *** *** * ****** ** * ****, ******* the ****** ** ********* ****** *********** ******* *** *** * most ********* ********, **** ** *** ******* **** ***** ****? My *** ********** ** **** *** **** ******* ******* *** negative ***** *** ** *********. * ***** ** *****, *** it ******'* **** ** *** ***** ****.

******,

*** ***** **** *** **** "******** *******" *** *** "******** ******" ******* *********.

* **** ***** *** ******** ******** ** ******** ********* **** a ********** ****** ***** ******** **** ******* **** '******' *** 'personal *******' ***** *** **. *** *** *** ******* ** as, *** * *****, '*******'.

**** ********** **** ** ****** *** **** ** ********* *** many ********* *** ***** ** ******* *** ******** *********. *** just ******* ** *** ******** **** *** **** ** *** wrong ** **** ** *** '********' ******* ****.

* ** *** ****** *** ***** - ************ **** ********* that **** *** **** ** '********' ** ****** ******* *********?

******* *** ****** ** ******** *********** ** *** ***** ** heavily ******** ******** *********** ** ***** *************. *** * ********** person ***** **** ** ***** *** ****** ** ******** ******** over *** ****** ******** ** *** ****** ** ******** ****, and *** **** ** * ****** ** ******* **** *** positive / ******** ***** ** ******** ********** ***** *************. ******* that *** ****** * "********" ******** **** *** ****** *** no ***** ********** ******* *** ************ ********* *****. ** **** statement **** * ********* **** * ** "*******" ****'* ******** accurate. ******* *** ********** ****** ***** ********* *** * ******** articles ** ***** **** ** ******** ****, *** ****** *** other ******* ********* ****** **** >*/* *****, *** **** ********** person ***** ******** ******** **** *** *** ****** **** **** personal ****** ******* ****.

**** *** ****** * "********" ******** **** *** ****** *** no ***** ********** ******* *** ************...********* *** * ******** ******** ** ***** **** ** ******** ones

******, ** ****. ** **** *** ********* ******** ***** ** 25 ******** ***** ** ********* **** ******. ** *** **** to ********* ** **** ** ****, ** ** ** *****, do *** ******* ************* **** *** ******* *****.

**** ******, ***** **** ****, ** **** ********* ** *************, ** ** ***** **** **** ** *********, ********* **** one ****.

** ******** ** *** * ******** **** ***** *****, ** have * ******** ********** ** ***** -***** ** ****** ****** ** ********* (******* )*** * ***** ***** **** *** ******* ** ******** -********* *** ***-**** ****** ****************** *.***+ ****** ****** (****).

** **** ************ ** ******* *****.

**** ****, **** **** *** *** ** ** **/** ************ ** *****. ** ***'* **** '******' *** '********' ** 'negative' ********. *** **** ** ** ***** ********* ****** ** the ******** **********.

* **** *** *** * *** **** ******, ****** *** sheer ****** ** ******** ** *****, **** ************ ** ********* ***************** ** '******** *******'?

**** ********, ******* ******** ****** **** *** *******, *********** ********* 'numbers ** ******** *****' **** '****'... ** ** *** **** just ******* *** *** ** ** ****.

*******, ***, *** ********* ** **** ******** *** **** ******* on ******** **** **** ****-******* '****' ***** ***.

*** ** *** ****** ******* ************ ********* ********. **** ** the ********* *** '******* ** *****'.

*** ****** ****** *************** ** ******** ** ***** ****** *************** *** **** ** ****** ** ******** ** *** *** in ***** **** ******* *** ************ *******/********* ** ******** ******** exposed *************** ** ***** *** ********/********.

** * ******* *** *********** ********* ********* *********** ** ********* vulnerabilities **** * ****** ** **** - ** ****** **** it ** **** **** ******* ******** - * **** ** hard ** ******* * ***** ** **** **** *** **** majority ** **** ******* ******** ***** ********* *********** ** *************** are ********.

* ***** *** ****** *** ***** "** ********** **" *** "my ******* **" ** ** *****. *** **** ***** "******** down *** **** ***** ***" ** *****. * ** ***** slapstick *****. *** *'** *** ****** *** **** **** ** an *************** ******* **** * ********** ********.

*** **** *** *** ********* ** ***** ****** ******** **** would ** *** **** ** *** ***** ******** ******** ********, government *************, *** ***** ***** **** *** ******* **. *********** that ******* ***** **** ** ** **** *** ***** ********, solving *** ********** ***** ***** ****.

****: ***** ** ********** ****, ** **** ******* * *** topic -****** ******** ********, *** ** *******?

****, ** *** ******** ** *** ******* **** ***** ***** recovery ******.*** ****** ** ***** *************, ****** *** ** **** *****.

* ***** **** *** ***** ** **** ***** ****** ** password ******** ** ********** * **** ****. **** *** **** discussed **** ********.

**** ************* * **** ****** ****, **** *** ******* *** device, *** *********** ** *****, ** **** ** ******** *****'* get ****** ** *** ********. **** *** ** ******* ******** the *******, *** *** ******* ****** ***** **** ****** ** in *** ******* ****.

****, *** ***** ****** ***** *** ******** ****** *** **** access ** *** ****** ** ** *** ********** **********.

*** **** ***** ******** *********, **** ****** ** ********** ** requiring ******** ****** ** ***-**-****** (***) ******. * ******* ****** shouldnt ***** * ***** **** *** *******.

***** ***** ***** ** ***** ***** ********. *** **** ******** access ** ***** * ****** ******** *** * ******* ***** for ***** ***** ******.

********* **** **** *** ** ***** ******* ******** ********* **** issue. ** ** **** ****:

"*** ****** ** ******** ** ***** ** *** ***************** ******** from ** ***. * ****** ****** ** * **-****** ********* 'security ****' ***** '*******' *** * ********-**** ********** ******** *******."

*** ***'* ***** **** *** ********* ** ****'* *******, ** you?! :^*

******:

********* *** *********, ****** *** ******** ** **, **** *** send * ******* ******** ***** ***. ** **** ******* *** report ** ******* ****:

Hikvision ******** **** "******** ***** ******"

** ****** **, ****, ********* **** * '******* ********' ***** * **** ******** ******** "********* ***/*** ******** ***** ******". ** ******** * ******* ** ******** ********** ** ******** passwords ****** ******* *********. ** **** ********* * **** **** Hikvision ********* *************** ** ** ******* *** ******* *** **** to ****** *** **** ***********.

*** ********* *****:

(*) ********* ****** ** *** ******** ***** ** "**-****** ********* 'security ****'". ** ** *****, ** *** *** **** '******** code' ******* **** ** *********'* *** **** *** **** *******, e.g., *** ******* ** ********* ********* ******* ** * '******** ****'.

(*) ********* ******* ****** *** ******** **** ***** ******** **** was *******. ****** **** ********* * ***** ******** **** ***** overcome **** *******. **** ******** ** **** ** **** ** reviewing ** ****** **** ********* *** **** ******* ** ******.

*** ****** ******* ****** *** ****. *) *** ***** *** be ***** ** *** ** ****** **** **** *** *********, which ******* *** **** *******. ** ********* *****, **** ***'* want ** ****** *********** **** ***** ***** *****, *** ****** can **** ** *** *** *** *********. *) **** **** you ** **** **** * **** ***. * ******** ****** down ** ****** **** ******** **** ************** **** *** ***** you ** ******** **** **** *** ****, ***** *** ***'* know *** ******** *** **** *** **** *************. *** **** thing **** ****** ** ******* ** ** *** ********* ****/******** - ** ******* *** **** ** **...

* ******* *** ******* **** *** ***** ***** ** ***** are "*** **** *** *********" ******* **** **** *** ***** on *** ****/**** ** *** **** *** **** ****** ** 24 *****. ** ******, **** *** **********, *** ***** ** be ********* *** ***** *** * *** ****, ***** ****** it **** **** *********.

*** *** ***** * ******* ******* ***** ***** ** ****. Nothing *** ****.

* ***** ***%.

* ***'* ********** *** **** ****.

*** **** **** *** **** ** ****** ********** ******* ** on *** **** ***, ******* ********* *** *****.

*** *****, **** *** ********** ***** *** ******** *** **** access ** *** ***/***, *** **** ****** ** **** *********, meaningless ****** **** ****** ***** *****: **** ** ***** ***** spend **** *** ****** ******** ****. *** ***'* **** ****** to ******** ****, ****** **** *******, ******* ****, *******. **** again, ******** ** ***************** ** *** *************.

*** ***** *** **** *** **** ** ******* ** ******* from **** *********: **** **** * ****** ** **** ****** the ******** ** * ******* ******, ** *** ** ***** several ******* ***** ** **** *** ******* ** ******* ** Germany, **** *** ****!!

*.*.: ** *** ******** ******* ** ********* ************ **** *** videosurveillance ****** *** **** ****** **% ** ***** ***** ** recent ******.

* ** ********* ** ** *** ** ** **** ********** biased, *******-***** ******* **********.

**** **** ***** ********** ****.

********* ******

* ***'* ********** *** **** ****.

*** **** **** *** **** ** ****** ********** ******* ** on *** **** ***, ******* ********* *** *****.

***, ** ** *** ** **** * **** ** ************ ********.

*******, ** ** ********* * **** *** * **** **** Hikvision *** **** ***** **, ****'* *** ********* ******* *** code ********** ******* -********* ******** ** ******* ******** *****.

****** -

** *** * ********* ****** **** **** ********* ** ****** August **** ** ******* *** ******** **** *****, *** ***** Hikvision *** ***** ** **** ** **** *********** ** ***** the ******** ****. ** **** ** ********** * *** ****** tomorrow (****** ****) **** *** ******** ** *********'* ******* ***** password ***** *******.

**** ** *** *** **** *** ** ******** ***** *****. It **** ****** **** *** ********* ********* ****** ******* ** be **** ********* **** *********** ******. *********.

**** **** ************ ** * **********. :(

Update - ****/*** ******** ** ********* ******** *** *** ******

*** ******** ** *********'* ******** *** *** *** ******** ***** method *** **** ********:********* ******** ** ******* ******** *****

* ***** *** "****" *** ****. *** ** **** ***** agains *** **** ***** ******** -******* ****** ** ***** ***/*** is **** **** ****.

* **** ******* ******* *** **** ********. ********, ** **** need ******** ***** ******* *** **** *** **** * ******** recovery ****** ****'* ***** *** **** *** ****** **********. ******** access ****** **** **** ** **********. **** *****, **** ** we ** ***** ******** *****?

******: *-*** ***** **** ****.*.* ***** ****** (******** ****). *** ****** ** ******* *** **** *** **** *******.

******: ****** ********** ********* ********** ********* *** ***** ********** ** *** ******* ******** code *******:

********** *********' ********* *** ** ***** ***** *** ********* ******** code ********* ******** ** *** *************** ******** **** *******. ******** * **** **** **** **** ** ********* ****** Manager ****** *** ******** ** ******* (*****/****). **** **** ********* and ***** **** **** ******* **** ********** ** *** ********.

Login to read this IPVM report.
Why do I need to log in?
IPVM conducts unique testing and research funded by member's payments enabling us to offer the most independent, accurate and in-depth information.

Related Reports

Security Installation Tools Guide - 22 Tools Listed on Feb 19, 2019
In this guide, we cover 22 tools that security installers frequently use. This is one part of our upcoming Video Surveillance...
Spring 2019 IP Networking Course on Jan 10, 2019
You can register for the Spring 2019 IP Networking course here. This is the only networking course designed specifically for video surveillance...
Bosch VDOO 2018 Vulnerability on Dec 20, 2018
Security research firm VDOO has discovered a critical vulnerability in Bosch IP cameras. Inside, we cover the available details of this new...
Genetec UL Cybersecurity Certificate (2900-2-3) Examined on Dec 19, 2018
Proving a company is cybersecure has become a major concern for security companies. But how trustworthy are these certificates? Earlier in 2018, a...
Ideal SecuriTest IP Vs Unbranded IP Camera Install Tool Tested on Nov 21, 2018
In our recent IP camera installation tool shootout, multiple members questioned the Ideal SecuriTest IP's features compared to low-cost unbranded...
No GDPR Penalties For UK Swann 'Spying Hack' on Nov 20, 2018
The UK’s data protection agency has closed its investigation into Infinova-owned Swann Security UK, the ICO confirmed to IPVM, deciding to take “no...
ISC East 2018 Mini-Show Final Report on Nov 16, 2018
This is our second (updated) and final show report from ISC East. ISC East, by its own admission, is not a national or international show, billed...
HID: Stop Selling Cracked 125 kHz Credentials on Nov 05, 2018
HID should stop selling cracked 125 kHz access control credentials, that have been long cracked and can easily be copied by cheap cloners sold on...
IP Camera Installation Tool Shootout - Avigilon, Axis, Ideal, Hanwha, Triplett, Veracity on Oct 23, 2018
Setting up IP cameras has historically been challenging, with techs often precariously using a laptop on a ladder or lift. Some options for install...
Integrator Laptop Guide on Oct 16, 2018
This 18-page guide provides guidance and statistics about integrator laptop use. 150 integrators explained to IPVM in detail about their laptops,...

Most Recent Industry Reports

Outdoor Camera Mounting Hardware Guide on Feb 21, 2019
Mounting cameras outdoors can be challenging, requiring understanding different types of equipment and methods. In this guide, we teach this...
HID Favorability Results 2019 on Feb 21, 2019
HID favorability results were strong, in the 2019 IPVM integrator study of 200+ integrators, with a net +62% and low negativity as the table below...
First US State, Vermont, Bans Dahua and Hikvision on Feb 21, 2019
The first US state, Vermont, has issued a ban on a number of Chinese and Russian manufacturers including the world's 2 largest video surveillance...
ADI 'SAVE BIG' On FLIR And Hikvision Examined on Feb 20, 2019
One is a major US defense supplier. The other is owned by the Chinese government. But you can "SAVE BIG" on both at ADI. In this note, we...
BluB0x Company Profile on Feb 20, 2019
BluB0x has doubled in revenue every year since its founding in 2013, according to CEO Patrick Barry. We originally reported on them in 2015. At the...
Security Installation Tools Guide - 22 Tools Listed on Feb 19, 2019
In this guide, we cover 22 tools that security installers frequently use. This is one part of our upcoming Video Surveillance...
Sales Cuts At Rasilient on Feb 19, 2019
Over the past 2 years, video surveillance storage specialist Rasilient has expanded its workforce significantly, aiming to build its own branded...
Exacq Raises VMS Software Pricing Twice in Less Than a Year on Feb 18, 2019
Most VMSes regularly release new features, but rarely increase their prices. For the 3rd time in 4 years, and 2nd time in 8 months, since being...
Axis IR Multi Imager Camera Tested (P3717-PLE) on Feb 18, 2019
Axis has released their first IR multi imager, the P3717-PLE, a repositionable model listing 360° IR illumination and flexible positioning,...

The world's leading video surveillance information source, IPVM provides the best reporting, testing and training for 10,000+ members globally. Dedicated to independent and objective information, we uniquely refuse any and all advertisements, sponsorship and consulting from manufacturers.

About | FAQ | Contact