XiongMai Master Password List Emailed By Chinese Spammer

Author: Brian Karas, Published on Dec 05, 2016

XiongMai created an international uproar as their devices drove massive botnet attacks of major Internet sites.

After pledging to recall cameras after the attack, and then threatening to sue those who criticized them, XiongMai is back.

A Chinese reseller of XiongMai equipment sent us a spam email that contains master passwords for XiongMai devices.

They consider this list a benefit for dealers, enabling faster and easier customer support, while overlooking the security risks it creates.

******** ******* ** ************* ****** ** ***** ******* ***** ******* botnet ******* ** ***** ******** *****.

***** ******** ** ****** ******* ***** *** ******, *** *************** ** *** ***** *** ********** ****, ******** ** ****.

* ******* ******** ** ******** ********* **** ** * **** ***** **** contains ****** ********* *** ******** *******.

**** ******** **** **** * ******* *** *******, ******** ****** and ****** ******** *******, ***** *********** *** ******** ***** ** creates.

[***************]

"Helpful" ********

* ***** ********, **********, ******* **. ****** **** ***** *** ****** ** *** to *** ******** (*** ******* ******), **** ******** * "***** Password ****" *** ** (********) ********:

*** ********* ***** ** * ****** **** *********** ****, ***** *** *** ***-******** ****** ******** *** **** *** of ****.

Super ******** ***** ***** ****

*** "***** ********" ******** ***** ****** ** *** ****** **** used, ********* ** **********. *** *********, *** ******** *** ** entered ******** *** *** ******** **, *** *** ******* ** additional ******* ******* ** ******** ** **** *** ********/***** ********. In ****** ****, *** *** ****** ** * ****** **** the ***** ******** *******, ******** *** * *** ***** ******** to ** ***.

But ***** *** *** ******

***** ********* *** **** *** *** ****** ****** *** **** not ****** ** ******* *** ****** ******** *********** **** ****** number ** *** *******.

Compared ** ********* ****** *********

********* ******** ********* * ****** ******** ** **** ****** ** * device **** * ********* ***** ********, ******* *** ********* *** also **** ** **** *** ****** ****** ** *** ******. By ********* *** ****** ****** ** **** ** *** *********** there ** ** ****** **** ** "****** *********" *** *********, reducing *** ******* ** **** ********. ********* *** **** ***** ****-***** ******** *****, ******** ***** ** ***** ******** ********* **** *** ****** to *******/***** * ********* ********.

Vulnerability ********

***** **** ****** **** ***** **** ** ******** ***** *** admin ********, **** ************* ***** ***** ** * *********** ************* ** users. ** ******** *** ***** ****** ** *** *** *** an ******** **, ****** ******* ******, ** ***** ****** ********* to *** ** * ******* ***** *** ****** ****** ***** utilize ***** ********* ** *** ***** ****** ** ******* ** recorders, ******* ** *** ********* *** ********** ********, ** **** accessing ***** ** ********* *********.

Sign ** *** ******?

** **** ** *********** **** **** ******** ***** ** ******* their ***********, ******* ** *** ******, ** ***** *****. **** could ** * **** **** **** ***-****** ******* ********* *** finding ** ********* ** *** *** **** *********** ** *******, and *** **** ** ****** ** ***** ******* ** ******* new ********. 

Comments (9)

*** ***'* **** ******* ***** *** ***, *** *** **** the *******?

***** ** ** ************* **** ****, ***, **** ** ** understanding.

** **** **** ********* **** **** *******.
* ***** ****** "***********" ******

****'** **** ******* ****** ** ** ***** **** ****** **** IP. **** * ******** ** ****** *****!!!!

*********** ******* ******* *** *********... ***** *** * *** ** repeated ********* ********** *** **** ** *** *** ** *** code. * ***** ***** **** ** ****** ****.

* *** *** **** *****. ****** ***. *********..

*). *** ***** *** **** **** ******** ** ****?

*). *** ***** *** ***** ** **** ******** *** ******* up *** * *****.

*). *** ***** *** ***** **...

**** **** *** *** **** ******** *******:

*****-****-*****-**********-***********@****.***

******* *** ,*********'* ****** **** ********* ***** ** ****** ****** and **** *** **** ** *** *** *** **** *****! I ***'* ******** ** ** ***** ** *** **** ** be ** **** ** ***** ** ***** *** ********.

**** **** ** **** ********* *******, **** **** * ******* reset ****** , * ***-***** **** **********, *** ******** *** all *** ****** ******. * *****'* **** **** ******** ********* on **** ******* *** ***** *** **** ******* **** **** system ****** *** *****.

******* **** ** *** ****** ( ***** ) *** ******* on *** ******** *** *** **** **** ***** ***. ***** has *** ******* *** " *** ******** " ********. ********* also **** ** **** ******.

* ***** *** ********** ** *** *** ****** *** ****** via *** ***** ****** ******** ******** ****** *** *** ******* physical ******. *** ********* ****** ** **** ******** ** ***** tool ***** *** ****** ****** *** *** ******* ********* ******** access, * **** * **** **** ** ** *********. ******* a ****** ***** *** ** ** **** *** * ***** button.

** *** ***** *** ****** ******** **** *** ** *** list ** ***** **** *** ******* ** ***** *** ******* could ****** ********** *** ********* ** **** *****. **** ** the **** *** ***** ** *** ****** **'* *** ***** to **** **** ** *****. ****** ***** *** ****** ******* but ** ** ********* ** ***** ** ** ****** *** access ** **** *****?

Login to read this IPVM report.
Why do I need to log in?
IPVM conducts unique testing and research funded by member's payments enabling us to offer the most independent, accurate and in-depth information.

Related Reports

New Whole Foods Installs Hackable Access Control on Feb 21, 2018
Whole Foods has built a reputation for high quality. And their 2017 Amazon acquisition has increased that, plus added deep pockets for buying...
Remote Network Access for Video Surveillance Guide on Feb 21, 2018
Remotely accessing surveillance systems is key in 2018, with more and more users relying on mobile apps as their main way of operating the system....
"Fear Mongering": Hikvision USA Cybersecurity Director Dismisses Chinese Government Ownership Concerns on Feb 16, 2018
The facts are: The Chinese government created Hikvision and is Hikvision's controlling shareholder. Hikvision's Chairman, a Communist Party...
Motorola Targets Chinese With Avigilon Acquisition on Feb 09, 2018
Motorola joins the growing list of companies taking aim at Chinese manufacturers. Recall, last week it was Hanwha: Chinese Products Damaged...
IP Cameras Default Passwords Directory on Feb 09, 2018
Below is a directory of 50+ manufacturer's default passwords. Note: Change Default Passwords Leaving default passwords is dangerous and makes it...
Simplisafe 'All New' Generation 3 Tested on Feb 08, 2018
Feared by the traditional alarm industry, Simplisafe has launched its 'all new' Generation 3 platform that they declare is "Stronger. Faster....
Ingram Micro Owner HNA Declares "Victim of Conspiracy Against China" on Feb 08, 2018
Just 2 years ago, Ingram Micro was acquired by a Chinese company that paid them $6 billion in cash, nearly 40% more than their then stock...
Geovision Unprecedented Security Vulnerabilities And Backdoor on Feb 06, 2018
Cybersecurity vulnerabilities have plagued the video surveillance market. Now, Bashis, discover of the Dahua backdoor, has discovered 15...
Chinese Police Wearing Facial Recognition Are Here on Feb 06, 2018
This is a very interesting and highly atypical usage of facial recognition that the Chinese government touted this week: It is a PRC police...
Barron's: If Trump Bans Hikvision on Feb 05, 2018
What happens if Trump bans Hikvision from US government entities? This is being considered in a new profile by financial magazine...

Most Recent Industry Reports

Directory of 30+ LPR / ANPR Providers on Feb 21, 2018
License Plate Recognition / Automatic Number Plate Recognition are a type of video analytics software that can identify and match license / number...
New Whole Foods Installs Hackable Access Control on Feb 21, 2018
Whole Foods has built a reputation for high quality. And their 2017 Amazon acquisition has increased that, plus added deep pockets for buying...
Remote Network Access for Video Surveillance Guide on Feb 21, 2018
Remotely accessing surveillance systems is key in 2018, with more and more users relying on mobile apps as their main way of operating the system....
Visio For Video Surveillance Design on Feb 20, 2018
Many integrators have standardized on AutoCAD for camera layouts but new users may be overwhelmed by its learning curve. Microsoft's Visio...
Health Care Insurance Integrator Benefits Statistics on Feb 20, 2018
How common and how much healthcare coverage is typically provided by security companies? 150+ integrators explained how their companies provide the...
Hikvision Deletes Genetec Support on Feb 20, 2018
There will be no peace between Hikvision and Genetec. A year after Genetec expelled Hikvision (and Huawei, citing Chinese government control...
Change Orders - Sometimes Necessary, Sometimes Unethical on Feb 19, 2018
Change orders are a common element in project sales. Sometimes they are a necessity and appropriate ways to deal with arising issues, but sometimes...
Bosch Merges Video, Intrusion and Access Businesses on Feb 19, 2018
Bosch is merging their "video systems, intrusion detection, as well as its access control and management software business units to form a single...
Why 3VR Failed on Feb 16, 2018
3VR destroyed transformed ~$65 million in VC funding into a $6.9 million exit. The reason they failed is simple. They bet on analytics. They...
"Fear Mongering": Hikvision USA Cybersecurity Director Dismisses Chinese Government Ownership Concerns on Feb 16, 2018
The facts are: The Chinese government created Hikvision and is Hikvision's controlling shareholder. Hikvision's Chairman, a Communist Party...

The world's leading video surveillance information source, IPVM provides the best reporting, testing and training for 10,000+ members globally. Dedicated to independent and objective information, we uniquely refuse any and all advertisements, sponsorship and consulting from manufacturers.

About | FAQ | Contact