### Hikvision DVR DS-7204HGHI User Enumeration (CVE-2020-7057)
The DVR DS-7204HGHI created by Hikvision is using the Web version V4.0.1 build
1.
data:image/s3,"s3://crabby-images/320bb/320bb38499dc6a5c3b5ba1c3b98447ea4d9c67ef" alt="https://mastecsa.com/wp-content/uploads/2019/05/5c47444fec836059272e97c4.jpg"
When you try to log-in in the WebServer, the Webpage rely on the "ISAPI" for
the authentication. It makes GET requests for the username trying to
authenticate, if this username exists, it will respond a Session ID, a
Challange and a SALT (also the iterations and if is reversible). If the
username does not exist, is going to respond with a 500 Internal Server Error.
data:image/s3,"s3://crabby-images/09f44/09f44358f8aea08d00485a44d4e22c0c983b4743" alt=""
data:image/s3,"s3://crabby-images/db8f2/db8f231884d21e4c44bdceb1fae62ca8b9df3294" alt=""
But as I said before, if the username exists, is going to response with
interesting information.
data:image/s3,"s3://crabby-images/26725/267255912255018b86427f55ee8f0b80e8f6eec3" alt=""
data:image/s3,"s3://crabby-images/5dbfa/5dbfac95ae42f9ff42bc5956037ad9524401c49b" alt=""
This give us the chance to rely on a bruteforce attack for username
enumeration. Hikvision's Web Server, have a limit for fail log-ins, so be
careful with the bruteforce OR do it manually avoiding the ban and trying only
4 - 5 usernames per device until you can try again.
CVE-2020-7057
<https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7057>
暂无评论