- Jul 30, 2016
- 354
- 299
Hey all,
I was inspecting some things and doing some SNMP walking on my Dahua SD49225T-HN, as i found some quite interesting things, that somehow made me think a little harder.
The complete system is isolated from the internet, as it is not physically connected to the internet or any internet router. Stand alone system.
UPnP is disabled in the camera. As i do with everything that has this functionality. The thing i have found out is, that the connection state on port 5000 (UPnP port) is still established on the localhost of the camera. It should be off, but still claims that it is established.
Then i have found two extra ports on where the camera is listening for connections. Those ports are:
9989 Port 9989 (tcp/udp) - Online TCP UDP port finder - adminsub.net
9990 Port 9990 (tcp/udp) - Online TCP UDP port finder - adminsub.net
Port 9989 is also used for trojans as it seems, but also as a Apple Quicktime streaming protocol.
Port 9990 seems to be for Apple Quicktime streaming also.
Do they serve as a streaming functionality for external viewing in remote viewers, or are they used as a backdoor? That keeps me thinking. They are running on the localhost, so at the moment there is no connection to the main IP subnet, but hmm...
Maybe other people have found this already, or have an explanation to this phenomenon
I was inspecting some things and doing some SNMP walking on my Dahua SD49225T-HN, as i found some quite interesting things, that somehow made me think a little harder.
The complete system is isolated from the internet, as it is not physically connected to the internet or any internet router. Stand alone system.
UPnP is disabled in the camera. As i do with everything that has this functionality. The thing i have found out is, that the connection state on port 5000 (UPnP port) is still established on the localhost of the camera. It should be off, but still claims that it is established.
Then i have found two extra ports on where the camera is listening for connections. Those ports are:
9989 Port 9989 (tcp/udp) - Online TCP UDP port finder - adminsub.net
9990 Port 9990 (tcp/udp) - Online TCP UDP port finder - adminsub.net
Port 9989 is also used for trojans as it seems, but also as a Apple Quicktime streaming protocol.
Port 9990 seems to be for Apple Quicktime streaming also.
Do they serve as a streaming functionality for external viewing in remote viewers, or are they used as a backdoor? That keeps me thinking. They are running on the localhost, so at the moment there is no connection to the main IP subnet, but hmm...
Maybe other people have found this already, or have an explanation to this phenomenon
