The basic functionality of the application is as follows:
- Application sends out a UDP broadcast on port 5978
- Camera sees the broadcast on port 5978 and inspects the payload – if it sees that the initial part of the payload contains "FF FF FF FF FF FF" it responds (UDP broadcast port 5978) with an encoded payload with its own MAC address
- Application retrieves the camera's response and creates another UDP broadcast but this time it sets the payload to contain the target camera's MAC address, this encoded value contains the command to send over the password
- Camera sees the broadcast on port 5978 and checks that it is meant for it by inspecting the MAC address that has been specified in the payload, it responds with an encoded payload that contains its password (base64 encoded)
After spending some time with the application in a debugger I found what looked like it was responsible for the decoding of the encoded values that are passed:
![]() |
| super exciting screen shot. |
Translated into english: the application first uses a lookup table to translate every byte in the input string, to do this it uses the value of the current byte as an offset into the table. After it is done with "stage1" it traverses the translated input buffer a dword at a time and does some bit shifting and addition to fully decode the value. The following roughly shows the "stage2" routine:
(Dword[0] << 2) + (Dword[1] >> 4) = unencoded byte 1
(Dword[1] << 4) + (Dword[2] >> 2) = unencoded byte 2
(Dword[2] << 6) + Dword[3] = unencoded byte 3
I then confirmed that this routine worked on an "encoded" value that went over the wire from the application to the camera. After confirming the encoding scheme worked, I recreated the network transaction the application does with the camera to create a stand alone script that will retrieve the password from a camera that is on the same lan as the "attacker". The script can be found here, thanks to Jason Doyle for the original finding (@jasond0yle ).
Related news
- Top Pentest Tools
- Hack Tools For Windows
- Hacking Tools Download
- Hacker Tools 2019
- Hacking Tools Github
- Pentest Tools
- Pentest Tools For Mac
- Pentest Tools Download
- Hacking Tools And Software
- Hacking Tools Github
- Hacking Tools Usb
- Pentest Tools Website
- Nsa Hacker Tools
- Hak5 Tools
- Android Hack Tools Github
- Hack App
- Hacking Tools Pc
- Hacker Tool Kit
- Hacker Tools Windows
- Hacking Tools And Software
- Install Pentest Tools Ubuntu
- Pentest Reporting Tools
- Hack Website Online Tool
- Hacker Techniques Tools And Incident Handling
- Termux Hacking Tools 2019
- Wifi Hacker Tools For Windows
- Pentest Tools For Android
- Bluetooth Hacking Tools Kali
- Hacking Tools Usb
- Hack Website Online Tool
- Hacker Search Tools
- Hacker Tools Apk
- Hacker Tools Linux
- Hacking Tools Download
- Hack Apps
- Hacker Tools Free
- Pentest Tools Subdomain
- Pentest Tools Android
- World No 1 Hacker Software
- Hacking Tools Free Download
- Hacks And Tools
- Hack Tools Download
- Hacker Tools For Pc
- Hacker Security Tools
- Hacker Tools Free Download
- Pentest Tools Subdomain
- Pentest Tools Port Scanner
- Best Hacking Tools 2020
- Hacking Tools Name
- Hack Tools Github
- Hacking Tools Windows
- Tools Used For Hacking
- Hacking Tools Name
- Black Hat Hacker Tools
- Pentest Tools Website Vulnerability
- Install Pentest Tools Ubuntu
- Pentest Automation Tools
- Game Hacking
- Tools Used For Hacking
- Hacker Tools Github
- Pentest Tools Online
- Pentest Automation Tools
- Hacker Security Tools
- Termux Hacking Tools 2019
- Usb Pentest Tools
- Pentest Tools Alternative
- Hacker Tools Apk
- Hacking Tools
- Game Hacking
- Hacking Tools For Games
- Tools 4 Hack
- What Are Hacking Tools
- Hacker Techniques Tools And Incident Handling
- Tools Used For Hacking
- Hack Tools For Windows
- Hacking Tools For Windows 7
- Hacking Tools For Windows
- Hacker Tools For Pc
- Hacker Tools For Mac
- Hacker Tools Github
- Hack Tools Github
- Top Pentest Tools
- Underground Hacker Sites

0 comments
Post a Comment