Dahua backdoor Generation 2 and 3

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

I'm speechless, and almost don't know what I should write... I (hardly) can't believe what I have just found. I have just discovered (to what I strongly believe is backdoor) in Dahua DVR/NVR/IPC and possible all their clones. Since I am convinced this is a backdoor, I have my own policy to NOT notify the vendor before the community. (I simply don't want to listen on their poor excuses, their tryings to keep me silent for informing the community) In short: You can delete/add/change name on the admin users, you change password on the admin users - this backdoor simply don't care about that! It uses whatever names and passwords you configuring - by simply downloading the full user database and use your own credentials! This is so simple as: 1. Remotely download the full user database with all credentials and permissions 2. Choose whatever admin user, copy the login names and password hashes 3. Use them as source to remotely login to the Dahua devices This is like a damn Hollywood...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息