https://github.com/bp2008/DahuaLoginBypass
Chrome extension that uses vulnerabilities CVE-2021-33044 and CVE-2021-33045 to log in to Dahua cameras without authentication.
https://github.com/bp2008/DahuaLoginBypass
Last synced: 5 months ago
JSON representation
Chrome extension that uses vulnerabilities CVE-2021-33044 and CVE-2021-33045 to log in to Dahua cameras without authentication.
- Host: GitHub
- URL: https://github.com/bp2008/DahuaLoginBypass
- Owner: bp2008
- License: gpl-3.0
- Created: 2021-10-11T22:08:47.000Z (about 4 years ago)
- Default Branch: main
- Last Pushed: 2021-10-13T22:32:36.000Z (about 4 years ago)
- Last Synced: 2024-08-05T17:37:45.282Z (over 1 year ago)
- Language: JavaScript
- Size: 85.9 KB
- Stars: 115
- Watchers: 8
- Forks: 29
- Open Issues: 1
-
Metadata Files:
- Readme: README.md
- License: LICENSE
Awesome Lists containing this project
- awesome-hacking-lists - bp2008/DahuaLoginBypass - Chrome extension that uses vulnerabilities CVE-2021-33044 and CVE-2021-33045 to log in to Dahua cameras without authentication. (JavaScript)
README
# DahuaLoginBypass
Chrome extension that uses vulnerability [CVE-2021-33044](https://packetstormsecurity.com/files/164423/Dahua-Authentication-Bypass.html) to log in to Dahua IP cameras and VTH/VTO (video intercom) devices without authentication.
For other device types (NVR/DVR/XVR, etc), there exists [CVE-2021-33045](https://packetstormsecurity.com/files/164423/Dahua-Authentication-Bypass.html) which cannot be exploited with an ordinary web browser.
These vulnerabilities are likely to be fixed in firmware released after Sept 2021.
Credit for discovering the vulnerabilities: [bashis](https://github.com/mcw0)
## Installation
Download the `.zip` file from the [releases section](https://github.com/bp2008/DahuaLoginBypass/releases).
1. Extract the folder from this zip somewhere.
2. Go to chrome's extensions page ( `chrome://extensions` ).
3. Enable the **Developer mode** option at the top right.
4. Click **Load unpacked** and choose the DahuaLoginBypass folder you extracted.
## Usage Instructions
Go to the login page of a Dahua IP camera and click the extension's icon (  ) to the right of your address bar. This should add a panel with a new button for you to use:
