Ads skipped

Discovering a Hardcoded Root Password - Hacking the VStarcam CB73 Security Camera

188K views · Jul 24, 2024 · Science & Technology

Comments · 437

  • @Dawidds77 · 2 years ago · pinned

    Got a question. Is it legal to upload videos like this (with precise procuct model and reverse enginneered pass)? Or it maybe depends somehow on the product/country/license/...?<br>Great work on this channel i see, subscribed :)

    57

  • @WilcovanBeijnum · 2 years ago

    You should be able to tell ghidra to decode the password as a string! To do this, select the variable (local_8c, later renamed to password), and change its type to `char [9]` (8 letters plus null byte) by pressing ctrl+l (or right click and retype variable). Then, ghidra should hopefully change the hex value to a string!

    150

  • @crashowerride · 2 years ago

    I recently discovered this channel and has become by far the most interesting one I have found in the last couple of years. I just have to say you are an incredible presenter, and every video just flies by. Looking forward to the next one. Cheers!

    84

  • @JoeBurnett · 2 years ago

    The YouTube algorithms have gifted me the knowledge of your channel today! Looking forward to watching more of your videos!

    42

  • @uwu_meow. · 2 years ago (edited)

    <a href="https://www.youtube.com/watch?v=lbSalKp_ldA&amp;t=1785">29:45</a> the reason why the rand seed is the same within a close time period is because the way that calling time(NULL) or as gihdra is showing it to be time(0x0) which is null and time() returns the unix timestamp &nbsp;to the second it was called so when u spam run the program the hashes will be very close and since the camera has no way of persisting time on bootup will always return the same salt which means rand() will always output the same &quot;randomness&quot;

    63

  • @RandyFortier · 2 years ago

    Literally as simple as a binary CTF challenge, as long as you can get the firmware.<br><br>This is great content!

    21

  • @TheShutterNinja · 2 years ago

    Please keep spoiling us all with frequent video releases!

    27

  • @cherrymountains72 · 2 years ago

    Very nice Matt, your channel is gaining traction which is well-deserved!

    14

  • @AlanAshton · 2 years ago

    With modern consumer GPU throughput, I might even expect brute forcing an 8 digit password to be faster than the IO from a 100MB file. <br><br>Now, with that said, I found your way to be pretty awesome. One of my favorite moments when it comes to cracking firmware password was watching the discord server for Marco Reps when an unsecured STM32 was read and we were all sortof looking at the binary dump and there was this random word in it. He tries it, and it works!

    3

  • @milicode5756 · 2 years ago

    As a programmer, I scare more every time I watch Matt`s videos 😂 this a the best channel I ever could find.

    2

  • @realavdhut · 2 years ago

    bro found this channel 2 days ago almost binge watched all your fkin videos. you are amazing

    4

  • @Kabodanki · 2 years ago

    very cool to do that, my young nephew is having a blast trying hack into an old router. my dude knows more than me

    3

Up next

LIVE

Hacking a Tiny Security Camera - VStarcam CB73 Firmware Extraction

Matt Brown · 57K views

LIVE

Breaking a Proprietary Chinese Encryption Protocol - Hacking the VStarcam CB73 Security Camera

Matt Brown · 119K views

LIVE

UART Shell Jail and Unlocked Bootloader - Hikvision Security Camera

Matt Brown · 51K views

LIVE

Decrypting SSL to Chinese Cloud Servers - Hacking the VStarcam CB73 Security Camera

Matt Brown · 369K views

LIVE

Every Dangerous Hacking Gadget Explained In 18 Minutes

Infomplify · 12K views

LIVE

I hacked time to recover $3 million from a Bitcoin software wallet

Joe Grand · 1.3M views

LIVE

Trump TWITCHING WITH ANGER at reporter

David Pakman Show · 223K views

LIVE

Extracting Firmware from a Chinese Security Camera - Hacking the Anran IP Camera

Matt Brown · 42K views

LIVE

🚨 PLÖTZLICH ESKALIERT DIE RUNDE! Lisa Eckhart sagt EINEN SATZ – PUBLIKUM RASTET KOMPLETT AUS!

Scharfer Blick · 39K views

LIVE

Hacking a Motorola Automatic License Plate Reader - Firmware Extraction and Password Cracking

Matt Brown · 274K views

LIVE

I Hacked This Temu Router. What I Found Should Be Illegal.

Low Level · 5M views

LIVE

DEF CON 32 - From getting JTAG on the iPhone 15 to hacking Apple's USB-C Controller - Stacksmashing

DEFCONConference · 584K views

LIVE

Statistical Attacks on Proprietary Encryption - Hacking the VStarcam CB73 Security Camera

Matt Brown · 23K views

LIVE

Complete DARK WEB Explained: Crime, Cybersecurity & the Hidden Internet

Ismail · 464K views

LIVE

Hacking an Automotive ECU!

RECESSIM · 83K views

LIVE

Counter-Surveillance Using Bluetooth!

Rob Braxman Tech · 1M views

LIVE

Hacking a weird TV censoring device

Ben Eater · 4.4M views

LIVE

Hacking a Microprocessor - Reverse Engineer shows you how it's done

RECESSIM · 176K views

LIVE

Einfach unglaublich...

Clownswelt · 96K views

LIVE

Persistent Root Shell via IoT Firmware Modification - Rooting a TP-Link Security Camera

Matt Brown · 36K views

LIVE

Access Location, Camera & Mic of any Device 🌎🎤📍📷

zSecurity · 3.7M views

LIVE

Hacking a Crowdfunded IoT Security Box - UART and Firmware Extraction

Matt Brown · 37K views

LIVE

(483) ESP32 precision GPS receiver (incl. RTK-GPS Tutorial). How to earn money with it (DePIN)

Andreas Spiess · 1M views

LIVE

Border Officials Asks For My Phone. These 4 Setups Decide What They Get

Rob Braxman Tech · 209K views

LIVE

Hacking Gadgets Every Cybersecurity Pro Should Know

David Bombal · 342K views

YouTube, with the door locked.

Aegis plays a clean stream instead of YouTube's player, so pre-roll ads, trackers, and fingerprinting never ride along. Drop Shields any time if you want the official player back.