Recent content by Mike_Larry

  1. M

    Hikvision RCE Vulnerability

    Thanks Wittaj. Ive purchased a Draytek 2866 from Amazon. I haven’t opened it still in the wrapper. Anyone know if they’re any good and also anyone have any knowledge on how to setup my dvr on it?
  2. M

    Hikvision RCE Vulnerability

    Thanks again Wittaj. Just to clarify what you said - so a VPN is only affective when accessing remotely and would not provide any security if someone’s on my LAN? And also once i have the vpn installed on my router i would stop receiving push notifications whilst im off my LAN? Would i still...
  3. M

    Hikvision RCE Vulnerability

    Hello guys, hope you guys are keeping well. As advised im planning to purchase a good router with good vpn capabilities. Just wanted to clarify a few things regarding vpn’s and their compatibility with hikvision systems. If i install a vpn on my router and then connect my dvr to the router...
  4. M

    Hikvision RCE Vulnerability

    I double checked I’ve definitely disabled upnp and p2p on the nvr and router. But im still able to use hikconnect remotely
  5. M

    Hikvision RCE Vulnerability

    Just double checked my router and your right, all inbound is blocked by default. But with this current setting i was still able to use HikConnect and access all my cameras/nvr remotely and i was still getting illegal logins from unknown ip addresses, random reboots and nvr settings being...
  6. M

    Hikvision RCE Vulnerability

    Thanks for the reply @looney2ns. My current router doesn’t support vpn so am currently looking to invest in one that does. you said the answers to my questions are ‘yes’ but im really sorry i might be just thick lol can i just get further clarification on them: 1) if i block all inbound...
  7. M

    Hikvision RCE Vulnerability

    Thanks for that @cm. As im very new to this whole networking stuff can i just clarify a couple things please: my nvr cant get hacked if i block all inbound traffic to my nvr via my routers firewall? But by blocking all inbound traffic i will not be able to use apps like HikConnect and remotely...
  8. M

    Hikvision RCE Vulnerability

    Hi guys. Been going through a stressful time with people targeting my cctv system. As i was having issues i decided to completely unplug my system from the internet. But know as i have no remote viewing or notifications am having issues with people trying to tamper with the system physically...
  9. M

    Hikvision RCE Vulnerability

    Oh no. Can that actually be done so easily or are you joking Wittaj. Can they just remove chunks of footage and insert another days!?!
  10. M

    Hikvision RCE Vulnerability

    Ok thanks for that Wittaj. But can i just get clarification on 1 thing - in terms of root privileges on a cctv system, can someone alter the footage on my continuos record. Basically ive got things happening at my estate, but im going through the continuos record(even on 2X speed) but still cant...
  11. M

    Hikvision RCE Vulnerability

    Ok thanks for that Umut. Just checked my cam firmware its V5.5.84 build 191010. I understand that hackers would want root access to attack higher profile my in my case it’s different, the attackers aren’t pro’s they just want to target me and my footage. So would you be able to tell me if root...
  12. M

    Hikvision RCE Vulnerability

    Thanks for the advice Umut. I have 3 cams attached to the nvr with really old firmware. Wanted to know what a root access allows someone to do as ive been having issues lately. Would it allow picking and choosing removal of event notifications, certain items on log etc also would it allow...
  13. M

    Hikvision RCE Vulnerability

    Ok thanks will try that Alastair
  14. M

    Hikvision RCE Vulnerability

    Ah sorry Alastair completely missed this post. I tried typing the following into Python (never used Python before). This is taken from Bashis Poc tool on Github: [Examples] Safe vulnerability/verify check: $./CVE-2021-36260.py --rhost 192.168.57.20 --rport 8080 --check
  15. M

    Hikvision RCE Vulnerability

    If i bridge the tplink and have the old router as primary will the setup for the nvr still be secure? Will the vpn still be affective?
Top