Ullaakut / cameradar

Cameradar hacks its way into RTSP videosurveillance cameras
MIT License
3.94k stars 506 forks source link

Add new credentials to the default dictionary #296

Open Robin6464 opened 2 years ago

Robin6464 commented 2 years ago

gives my list of factory logins and passwords that I could find on the Internet, including wifi spy cameras supporting RTSP using android lookcampro and hdsmartIPC applications

{ "usernames": [ "", "666666", "888888", "Admin", "admin", "admin1", "administrator", "Administrator", "aiphone", "Dinion", "guest", "root", "service", "supervisor", "ubnt", "user" ], "passwords": [ "", "0000", "00000", "000000", "1111", "111111", "1111111", "11111111", "123", "1234", "12341234", "12345", "12345abc", "12345admin", "123456", "1234567", "12345678", "123456789", "1234567890", "12345678910", "4321", "6666", "666666", "6fJjMKYx", "8888", "888888", "9999", "999999", "999988", "99999999", "ADMIN", "Admin", "admin123", "admin12345", "asdf1234", "hi3518", "jvbzd", "JVC", "Karnet", "Meins", "admin", "administrator", "Administrator", "aiphone", "camera", "fliradmin", "GRwvcj8j", "guest", "hikadmin", "hikvision", "ikwd", "jvc", "kj3TqCWv", "klv123", "meinsm", "none", "novus", "pass", "password", "password123", "qwerty", "qwerty123", "reolink", "root", "service", "supervisor", "support", "system", "tlJwpbo6", "toor", "tp-link", "ubnt", "user", "wbox123", "xc3511", "xmhdipc", "Y5eIMz3C" ] }

Ullaakut commented 2 years ago

Hi @Robin6464. Are you sure that all of those credentials are default credentials, set by the camera constructors?

Some of those password seem custom to me.

Thanks

Robin6464 commented 2 years ago

which specific passwords?

Ullaakut commented 2 years ago

Y5eIMz3C, xmhdipc, xc3511, tlJwpbo6, klv123, kj3TqCWv, hi3518 and 6fJjMKYx all seem like proper passwords 🤔

Which constructor do they come from?

Robin6464 commented 2 years ago

Network Surveillance DVR - admin/xc3511 HiSilicon - root/xmhdipc or klv123 or xc3511 or 123456 or jvbzd or hi3518 tlJwpbo6 - not mine, it is in your source kj3TqCWv - not mine, it is in your source 6fJjMKYx - not mine, it is in your source

Ullaakut commented 2 years ago

Sounds good to me then, thanks! Are you willing to open a PR for it or do you want for someone else to do it? I'll be happy to accept your PR if you write one to add those into the default dictionary :)

Robin6464 commented 2 years ago

In a few cases these passwords for me were confirmed when I used programs that also support cameras: RouterScan 2.60beta by Stas'M and routersploit. These programs exploit administration panels, but in the case of RTSP the password is the same. As for your question about PR, have someone else do it :)

Robin6464 commented 2 years ago

wyslalem ci maila pare dni temu na konto podane w twoim profilu w sprawie pewnego przypadku zlego dzialania cameradar, nie moge napisac tego publicznie, gdyz zawarte sa tam dane autoryzacyjne

Ullaakut commented 2 years ago

Your email got caught in the spam filter, sorry about that. I'll answer it shortly.