关联漏洞
描述
Chrome extension that uses vulnerabilities CVE-2021-33044 and CVE-2021-33045 to log in to Dahua cameras without authentication.
介绍
# DahuaLoginBypass
Chrome extension that uses vulnerability [CVE-2021-33044](https://packetstormsecurity.com/files/164423/Dahua-Authentication-Bypass.html) to log in to Dahua IP cameras and VTH/VTO (video intercom) devices without authentication.
For other device types (NVR/DVR/XVR, etc), there exists [CVE-2021-33045](https://packetstormsecurity.com/files/164423/Dahua-Authentication-Bypass.html) which cannot be exploited with an ordinary web browser.
These vulnerabilities are likely to be fixed in firmware released after Sept 2021.
Credit for discovering the vulnerabilities: [bashis](https://github.com/mcw0)
## Installation
Download the `.zip` file from the [releases section](https://github.com/bp2008/DahuaLoginBypass/releases).
1. Extract the folder from this zip somewhere.
2. Go to chrome's extensions page ( `chrome://extensions` ).
3. Enable the **Developer mode** option at the top right.
4. Click **Load unpacked** and choose the DahuaLoginBypass folder you extracted.
## Usage Instructions
Go to the login page of a Dahua IP camera and click the extension's icon (  ) to the right of your address bar. This should add a panel with a new button for you to use:

文件快照
[4.0K] /data/pocs/5fd195922f929b39d4ede26dd0e72162e58b15f8
├── [4.5K] background.js
├── [4.0K] DahuaLoginBypass 1.0
│ ├── [4.7K] background.js
│ ├── [ 666] icon128.png
│ ├── [ 234] icon32.png
│ ├── [ 300] icon48.png
│ └── [ 455] manifest.json
├── [3.8K] DahuaLoginBypass 1.0.zip
├── [4.0K] DahuaLoginBypass v2
│ ├── [6.1K] background.js
│ ├── [ 666] icon128.png
│ ├── [ 234] icon32.png
│ ├── [ 300] icon48.png
│ └── [ 455] manifest.json
├── [4.2K] DahuaLoginBypass v2.zip
├── [4.0K] DahuaLoginBypass v3
│ ├── [6.2K] background.js
│ ├── [ 666] icon128.png
│ ├── [ 234] icon32.png
│ ├── [ 300] icon48.png
│ └── [ 455] manifest.json
├── [4.2K] DahuaLoginBypass v3.zip
├── [4.0K] DahuaLoginBypass v4
│ ├── [4.5K] background.js
│ ├── [ 666] icon128.png
│ ├── [ 234] icon32.png
│ ├── [ 300] icon48.png
│ └── [ 455] manifest.json
├── [4.2K] DahuaLoginBypass v4.zip
├── [ 666] icon128.png
├── [ 234] icon32.png
├── [ 300] icon48.png
├── [ 34K] LICENSE
├── [ 455] manifest.json
├── [4.0K] misc
│ ├── [4.4K] dahua-bypass.txt
│ ├── [6.4K] extra.js
│ ├── [2.0K] key_black_24dp.svg
│ ├── [ 199] popup.html
│ └── [2.5K] popup.js
└── [1.4K] README.md
5 directories, 36 files
备注
1. 建议优先通过来源进行访问。
2. 如果因为来源失效或无法访问,请发送邮箱到 f.jinxu#gmail.com 索取本地快照(把 # 换成 @)。
3. 神龙已为您对POC代码进行快照,为了长期维护,请考虑为本地POC付费,感谢您的支持。