Forgot Hikvision NVR pass, but have Config file

geek7899

Young grasshopper
Joined
Jul 1, 2015
Messages
93
Reaction score
6
Hi

I wanted to access some past footage so went to NVR and tried to log-in. Alas, I had forgotten my password.
I then remembered that I had iVMS-4200 installed and logged in on my PC.
I quickly grabbed the Configuration file from iVMS-4200.

I then also extracted the XML file through SADP tool, and emailed it to support@hikvision.com.

While I am waiting to get the XML file back from tech support, can I somehow extract the password from the configuration file ?

It has been done before, as this thread suggests : Alternative way of recovering HikVision NVR password

Thanks all

Edit: NVR model: DS-7616NI-E2/8P
Firmware: v3.3.2 build 150522
 

alastairstevenson

Staff member
Joined
Oct 28, 2014
Messages
15,975
Reaction score
6,800
Location
Scotland
can I somehow extract the password from the configuration file
Yes, from the configuration file of a camera that's been added to the NVR PoE port in Plug&Play mode, where the camera is running firmware of 5.4.0 or older - in other words, has the Hikvision 'backdoor vulnerability'.
It doesn't necessarily have to be an existing camera - it could be another one added, or an existing one, in an 'Inactive' state that is added.
 

alastairstevenson

Staff member
Joined
Oct 28, 2014
Messages
15,975
Reaction score
6,800
Location
Scotland
I quickly grabbed the Configuration file from iVMS-4200
I'm unfamiliar with iVMS-4200
Is that the camera configuration file that the NVR produces (used to be an Excel format file), or the NVR configuration file?
It may be worth inspecting it with a hex editor - on that very old firmware the passwords used to be held in plaintext.
 

geek7899

Young grasshopper
Joined
Jul 1, 2015
Messages
93
Reaction score
6
Hi

Thanks for your reply.
It’s not the cam, but NVR password that I am talking about.
I grabbed the NVR configuration file from iVMS-4200. It was a zip file and when I unzipped it, it further contained many files.
Here is a screenshot of all files.

 

alastairstevenson

Staff member
Joined
Oct 28, 2014
Messages
15,975
Reaction score
6,800
Location
Scotland
It’s not the cam, but NVR password that I am talking about.
Yes, but the NVR can export camera configurations, which on the older firmware included the camera admin passwords, which in Plug&Play mode came from the NVR.
 

geek7899

Young grasshopper
Joined
Jul 1, 2015
Messages
93
Reaction score
6
Thanks for your replies alastairstevenson.

I got a updated XML file back from Hikvision.
Run it through SADP, changed password, refreshed SADP, and all good to go. !

Now looking at upgrading firmware, so I can have the question/answer format in case I forget password !
 

alastairstevenson

Staff member
Joined
Oct 28, 2014
Messages
15,975
Reaction score
6,800
Location
Scotland
I got a updated XML file back from Hikvision.
Run it through SADP, changed password, refreshed SADP, and all good to go. !
Well, that's a good result. It's how Hikvision should respond, but unfortunately it's not very common.
 
Top