Hikvision camera admin password reset tool

RacerX10

n3wb
Joined
Nov 8, 2021
Messages
2
Reaction score
1
Location
Arkansas
Quite likely - that firmware will probably have the 'Hikvision backdoor' vulnerability, depending on the specific model.


Are they still connected to NVR PoE ports?

Assuming they are -
Install SADP so that you can inventory the cameras and see some of their detail.

Connect the PC to an unused NVR PoE port, and note down from SADP the cameras IP addresses and the associated firmware versions.
The addresses are likely to be in the range 192.168.254.x
Change the PC IP address to be in the same range, for example 192.168.254.100
In the browser, use this URL to hopefully extract a configuration file :
http://<camera_IP_address>/System/configurationFile?auth=YWRtaW46MTEK
replacing the IP address with a selected one from your list.
Maybe do this for each of the firmware versions.

Zip up any extracted configuration files and attach here, I should be able to decrypt and decode them to extract the camera password.
Got the file, found the offline decrypter, and found the plain text password in the file. Thanks a bunch for the instructions !
 
Last edited:

Oleglevsha

Getting the hang of it
Joined
Jan 25, 2015
Messages
299
Reaction score
77
Location
Россия г.Волгоград
Thanks! Works great =)
I remind you, everyone can use the password search form from the configuration file received when using the http request: / <Camera IP address> / System / configurationFile? auth = YWRtaW46MTEK
on this page in my blog.
Appreciate the administrator's time, work independently
 

AviCo

n3wb
Joined
Sep 27, 2018
Messages
13
Reaction score
7
Location
Israel
Would be really thankfull for helping me out with this situation :

I have about 15 cameras DS-2CD2T42WD-I5 which as understand doesn't have the 'Hikvision backdoor vulnerability' ,
firmware V5.4.5 build 170724 - not sure where they bought from ,
I tried Hikvision support and they wrote all cameras came from unknown source and can't help me,
serial number for example:DS-2CD2T42WD-I520170222BBWR718236562
Im trying to reset the camera:
1.Hard reset - not an option , no reset button ( i open it)
2.I test it with the reset tool and got unauthorize request
also tried getting configuration file:
pop up a log-in screen .

3.with no other alternative Im trying flashing the firmware with TFTP:
I download firmware ipc_r6_en_std_5.5.82_190220_0.zip
I set on my laptop IP as 192.0.0.128 - connect both the laptop and the camera on same switch - disable wifi.
run tftpserv and it stuck on first line .
The camera IP as SDAP shows is on 192.168.254.7 and i really don't know how i can change the IP so TFTP could work ...
 

amanzar

n3wb
Joined
Dec 20, 2021
Messages
2
Reaction score
0
Location
guyana
Have come across a DS-7216HGHI-SH at a client's site, happily recording away, yet no-one knows the password :sigh:

Software version is V3.3.2build 151123 according to iVMS4200

The serial is DS-7216HGHI-SH162015xxxxxxxxxxxxxxxxxWCVU but I'm not clear which bit I remove before pasting the rest into the reset password code generator page. Just take off the initial DS-7216HGHI-SH or is there more to it than that? I tried a power-cycle, checked the start date & time was today according to SADP, but the code generated just gave me a "device rejected" error when I try to sign in at SADP

Thanks for any tips!
HELLO ALL
Can some assist in reseting DS-2CD2185FWD-IS20171014AAWR110049985 ... v5.5.3 build 170929

thanks
 

amanzar

n3wb
Joined
Dec 20, 2021
Messages
2
Reaction score
0
Location
guyana
hello can someome assist in reseting some hikvision camera password.. i have 16 working all of a sunnder only 7 showing now its says bad password
 

Attachments

alastairstevenson

Staff member
Joined
Oct 28, 2014
Messages
15,929
Reaction score
6,777
Location
Scotland
can someome assist in reseting some hikvision camera password..
Only Hikvision support persons can create the response to those XML password reset request files.

The product info for the DS-2CD2185FWD suggests it has a reset button.
This will be inside, on the circuit board.
Press the button, power on the camera, wait 30seconds or more and release.
SADP should then show the camera as 'Inactive' allowing you to create your own strong password to 'Activate' it.
 

Gogo55

n3wb
Joined
Jan 2, 2022
Messages
4
Reaction score
1
Location
Germany
hello community,

i´m from germany bavaria. Nice to get into this forum.

I have problems with this camera model DS-2CD2332-I
i tried your tool but it did not work. and then i tried to export the xml files which i sended to hikvision support. But the codes which they sent to meback did not work too.

Did someone have the same problems? i think it is the earlier model which has no reset button.
 

SamM

Pulling my weight
Joined
Mar 29, 2020
Messages
245
Reaction score
109
Location
SA
Hi there

After you extract the xml file, you need to keep the system on until you receive the response from Hikvision as the new xml file will be time based linked to your original file.

If you turn off the system before you receive the new file, it won't work.

What firmware version are you using?
 

alastairstevenson

Staff member
Joined
Oct 28, 2014
Messages
15,929
Reaction score
6,777
Location
Scotland
i tried your tool but it did not work. and then i tried to export the xml files which i sended to hikvision support. But the codes which they sent to meback did not work too.
What firmware version is on the camera?
If it's 5.4.0 or earlier, you will be able to extract the configuration file using the 'Hikvision backdoor vulnerability' which can then be decrytpted and the password extracted.
 

Oleglevsha

Getting the hang of it
Joined
Jan 25, 2015
Messages
299
Reaction score
77
Location
Россия г.Волгоград
hello community,

i´m from germany bavaria. Nice to get into this forum.

I have problems with this camera model DS-2CD2332-I
i tried your tool but it did not work. and then i tried to export the xml files which i sended to hikvision support. But the codes which they sent to meback did not work too.

Did someone have the same problems? i think it is the earlier model which has no reset button.
what is the firmware version, check with the sudo utility
 

Gogo55

n3wb
Joined
Jan 2, 2022
Messages
4
Reaction score
1
Location
Germany
Hi there

After you extract the xml file, you need to keep the system on until you receive the response from Hikvision as the new xml file will be time based linked to your original file.

If you turn off the system before you receive the new file, it won't work.

What firmware version are you using?
hi thanx for your response. yes i had turned on all cams. but it did not work.

What firmware version is on the camera?
If it's 5.4.0 or earlier, you will be able to extract the configuration file using the 'Hikvision backdoor vulnerability' which can then be decrytpted and the password extracted.
thank you for response.

it is 5.3.0 where can i find "Hikvision backdoor vulnerability"
 

alastairstevenson

Staff member
Joined
Oct 28, 2014
Messages
15,929
Reaction score
6,777
Location
Scotland
it is 5.3.0 where can i find "Hikvision backdoor vulnerability"
With a PC on the same IP address range as the camera, put this URL into the browser, replacing the camera actual IP address as needed.
Zip up the resultant exported configuration file, and attach here so it can be decrypted and decoded to extract the admin password.

http://<camera_IP_address>/System/configurationFile?auth=YWRtaW46MTEK
 

Gogo55

n3wb
Joined
Jan 2, 2022
Messages
4
Reaction score
1
Location
Germany
With a PC on the same IP address range as the camera, put this URL into the browser, replacing the camera actual IP address as needed.
Zip up the resultant exported configuration file, and attach here so it can be decrypted and decoded to extract the admin password.

http://<camera_IP_address>/System/configurationFile?auth=YWRtaW46MTEK
Hey thanx.

I Found the other Tool which u can Chance password of the User. It worked fine now.
 
Top