Backdoor több százezer Dahua kamerában.

Dahua Technology Co., Ltd. is a provider of video surveillance products and services, with the world’s 2nd largest market share, according to a 2015 IMS report.

In short:
You can delete/add/change name on the admin users, you change password on the admin users - this backdoor simply don't
care about that!
It uses whatever names and passwords you configuring - by simply downloading the full user database and use your own
credentials!

This is so simple as:
1. Remotely download the full user database with all credentials and permissions
2. Choose whatever admin user, copy the login names and password hashes
3. Use them as source to remotely login to the Dahua devices

via

Hozzászólások

Melyik kínaiba nincs? :)

Én be szoktam telnetelni a Provisionba ha elfelejtem a jelszót. :D (Az 1001chin -re sokkal könnyebb emlékezni mint amit én adok)