Sunday, 22 June 2014

Hack unsecured DVR's using internet search engines

The internal url for accessing my new DVR is :

http://192.168.1.10/login.rsp

The default user name is admin, with no password.

During the setup wizard, it dosnt prompt you to change user accounts and set passwords, so I assume there may be DVR's out there on the net with no password ready to logon to!

How to find them? Easy, the following google search :

inurl:login.rsp

Will return many, and trust me - many have no password set!

An alternate search is :

intitle:"dvr login"

Try the search in bing as well, both engines return different results.

Enjoy DVR hacking!

1 comment: