Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add new credentials to the default dictionary #296

Open
boo6ster opened this issue Sep 26, 2021 · 8 comments
Open

Add new credentials to the default dictionary #296

boo6ster opened this issue Sep 26, 2021 · 8 comments

Comments

@boo6ster
Copy link

boo6ster commented Sep 26, 2021

gives my list of factory logins and passwords that I could find on the Internet, including wifi spy cameras supporting RTSP using android lookcampro and hdsmartIPC applications

{
"usernames": [
"",
"666666",
"888888",
"Admin",
"admin",
"admin1",
"administrator",
"Administrator",
"aiphone",
"Dinion",
"guest",
"root",
"service",
"supervisor",
"ubnt",
"user"
],
"passwords": [
"",
"0000",
"00000",
"000000",
"1111",
"111111",
"1111111",
"11111111",
"123",
"1234",
"12341234",
"12345",
"12345abc",
"12345admin",
"123456",
"1234567",
"12345678",
"123456789",
"1234567890",
"12345678910",
"4321",
"6666",
"666666",
"6fJjMKYx",
"8888",
"888888",
"9999",
"999999",
"999988",
"99999999",
"ADMIN",
"Admin",
"admin123",
"admin12345",
"asdf1234",
"hi3518",
"jvbzd",
"JVC",
"Karnet",
"Meins",
"admin",
"administrator",
"Administrator",
"aiphone",
"camera",
"fliradmin",
"GRwvcj8j",
"guest",
"hikadmin",
"hikvision",
"ikwd",
"jvc",
"kj3TqCWv",
"klv123",
"meinsm",
"none",
"novus",
"pass",
"password",
"password123",
"qwerty",
"qwerty123",
"reolink",
"root",
"service",
"supervisor",
"support",
"system",
"tlJwpbo6",
"toor",
"tp-link",
"ubnt",
"user",
"wbox123",
"xc3511",
"xmhdipc",
"Y5eIMz3C"
]
}

@Ullaakut
Copy link
Owner

Hi @Robin6464. Are you sure that all of those credentials are default credentials, set by the camera constructors?

Some of those password seem custom to me.

Thanks

@boo6ster
Copy link
Author

which specific passwords?

@Ullaakut
Copy link
Owner

Ullaakut commented Sep 28, 2021

Y5eIMz3C, xmhdipc, xc3511, tlJwpbo6, klv123, kj3TqCWv, hi3518 and 6fJjMKYx all seem like proper passwords 🤔

Which constructor do they come from?

@boo6ster
Copy link
Author

Network Surveillance DVR - admin/xc3511
HiSilicon - root/xmhdipc or klv123 or xc3511 or 123456 or jvbzd or hi3518
tlJwpbo6 - not mine, it is in your source
kj3TqCWv - not mine, it is in your source
6fJjMKYx - not mine, it is in your source

@Ullaakut
Copy link
Owner

Sounds good to me then, thanks! Are you willing to open a PR for it or do you want for someone else to do it? I'll be happy to accept your PR if you write one to add those into the default dictionary :)

@boo6ster
Copy link
Author

boo6ster commented Sep 28, 2021

In a few cases these passwords for me were confirmed when I used programs that also support cameras: RouterScan 2.60beta by Stas'M and routersploit. These programs exploit administration panels, but in the case of RTSP the password is the same. As for your question about PR, have someone else do it :)

@Ullaakut Ullaakut changed the title my credentials.json list Add new credentials to the default dictionary Sep 28, 2021
@boo6ster
Copy link
Author

boo6ster commented Sep 30, 2021

wyslalem ci maila pare dni temu na konto podane w twoim profilu w sprawie pewnego przypadku zlego dzialania cameradar, nie moge napisac tego publicznie, gdyz zawarte sa tam dane autoryzacyjne

@Ullaakut
Copy link
Owner

Your email got caught in the spam filter, sorry about that. I'll answer it shortly.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants