Hacking Reolink cameras for fun and profit (2020)
thirtythreeforty.net
thirtythreeforty.net
Even for RTSP, there's often something stupid like the camera implementing 90% of the protocol except it never responds to OPTIONS requests.
And fun fact, VLC no longer supports RTSP on Debian-based distros due to licensing issues [1].
[0] - https://www.onvif.org/conformant-products
[1] - https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=981439
Netgear actually sold a rebranded/reflashed Arlo system as the FlexPower line with a special base station and reflashed Arlo cameras. The base did the magic that let the connected wireless Arlos act as ONVIF cameras in a DVR.
Cameras can't be accessed from your LAN, cameras can't access your LAN and they can't phone home easily. They just sit and feed the NVR with video content, offline. I don't even connect them to the internet for firmware updates unless there is some show stopper bug preventing them working as plain ole cams - they are just dumb RTSP endpoints.
Good blog write up about reversing Reolink B800 IP camera end result: https://github.com/thirtythreeforty/neolink
tools used:
* wireshark & dissector in Lua https://mika-s.github.io/wireshark/lua/dissector/2017/11/04/...
* binwalk
* visualize the BIN for blank space, code, etc. https://binvis.io/#/
* buildroot to make custom: gdbserver, busybox with all the fixin’s, and strace
* disassemble / decompile MIPS with https://ghidra-sre.org/
* using tcpsvd as tcp wrapper for FTPD in custom image
* quick setup env with "expect" script: https://www.thirtythreeforty.net/posts/2020/05/hacking-reoli...
* using gdb Dynamic Print commands to target certain functions. The dynamic printf command dprintf combines a breakpoint with formatted printing of your program’s data to give you the effect of inserting printf calls into your program on-the-fly, without having to recompile it. https://doc.ecoscentric.com/gnutools/doc/gdb/Dynamic-Printf....
* busybox has a watchdog minder, used like: watchdog /dev/watchdog
* background info on Baichuan protocol
* wrote new client software in Rust. https://github.com/thirtythreeforty/neolink/blob/master/src/...
* Gstreamer with RTSP server (in Rust!)
* using it with Blue Iris nvr software
Example: https://youtu.be/wAkV_fWOMFU
Then there is Dahua, which is basically Hikvision Junior. Reolink is somewhat in the middle, in the past they have OEM'd products from Dahua, and others. It can be difficult to know who actually manufactures a lot of the Chinese surveillance cameras, as the companies often go to great lengths to obscure the details.
Initially it was completely locked down, but I discovered the cameras eventually refuse connections after their RTC drifts too much. I could not get them to use my router for NTP because they preferred pool.ntp.org. I had to open up that port as well as allow them to make DNS lookups on my router.
They have been working fine with that minimal amount of internet access, but curiously, the firewall logs show frequent blocked connections to Reolink IPs on port 9999.
If you have Reolink cameras, your network is open, and you're worried about data exfiltration, then 9999 is one port you may want to block.
then you need not open them up to anything :)
Like OP, I wound up with one of these neutered Reolink cameras. I had purchased a bunch of normal ONVIF/RTSP ones, but one box contained a D800. It also had a slightly damaged mounting plate with dried silicon caulk residue on it. Seems I was a victim of Amazon return fraud, where someone sent them back the D800 instead of an RLC-822A. I was already past the return window and some couldn't even raise an issue about it.
Now I'm thinking I could have saved a lot of money by simply buying their cheaper "dumb" cameras.
Vaguely related - recently discovered that old iphones can be repurposed to serve rtsp with app heriscope hd. Works in a pretty idiot proof manner, though amount of heat generated is concerning.
Still interesting though given camera quality on old ifruits is pretty good still