Mystery outgoing TCP connection from my DS-2CD2342WD-I

lunokhod

Young grasshopper
Joined
Nov 16, 2015
Messages
35
Reaction score
4
Location
Australia
Hi Everybody,

After reading about the privilege escalation vulnerability found in the Hikvision cameras, I thought I would take a detailed look at what my network camera is up to.

One of the good things about Mikrotik RouterOS is being able to see exactly what IP connections are happening at any time, both in and out, in real time.
I'm a more than a little concerned that my DS-2CD2342WD-I camera has a continually established outbound TCP connection to 52.20.73.96 on port 6800.

This address comes up as being in the USA;

52.20.73.96 IP Address Details - ipinfo.io

I've seen a thread about Hikvision NVRs establishing a connection to an Amazon AWS address, but not the cameras.

This seems a little suspicious, I'm going to sniff the traffic and see if I can tell what is going on.

I can easily block outgoing connections from my cameras IP address, does it really need access to the internet to operate?

Regards,

Lunokhod.
 

alastairstevenson

Staff member
Joined
Oct 28, 2014
Messages
15,980
Reaction score
6,804
Location
Scotland
I can easily block outgoing connections from my cameras IP address, does it really need access to the internet to operate
Only if you don't disable easyviz etc in the web GUI.
You need to access the camera web GUI and disable any of those services that are (still) enabled by default that you won't be using.
 

lunokhod

Young grasshopper
Joined
Nov 16, 2015
Messages
35
Reaction score
4
Location
Australia
Only if you don't disable easyviz etc in the web GUI.
You need to access the camera web GUI and disable any of those services that are (still) enabled by default that you won't be using.
Thank you for the information. I did not look in the Network Advanced Settings (oops, my fault), but when I cleared the enable check box in Platform Access, the established TCP connection ended.

My conspiracy theory security concerns have been allayed. :)

Regards,

Lunokhod.
 
Top