MESSAGE
DATE | 2014-04-10 |
FROM | Ruben Safir
|
SUBJECT | Subject: [NYLXS - HANGOUT] cctv dvr routing
|
I have this security camera with a web interface that connects to the internet. It was on a trendnet router that was acting up so I replaced it with a fit PC and everything in the damn pharmacy is now working but this insane security camera set up.
So far, this is what I know abut it.
The original trendnet set up had port 888 open
the external views connected to http://225395.mgidvr.net:888
which seems to be some kind of dynamic dns set up... I hate those fucking things.
I believe that the video machine itself is sitting on the internal network with the ipaddress 10.0.0.12
home ~ # !dum dumpleases Mac Address IP Address Host Name Expires in 00:30:67:81:f0:4c 10.0.0.10 pharmacypos-PC 9 days 18:45:45 40:61:86:7f:cc:cb 10.0.0.11 Phserver 8 days 12:51:35 78:45:c4:0b:bc:d4 10.0.0.12 fvg5vr1 9 days 02:49:31
Which I think is a dellbox. I have no dellboxes here so that must be it. The camera box has been stripted of any identificaiton
home ~ # iptables -A PREROUTING -t nat -i eth0 -p tcp --dport 80 -j DNAT --to 10.0.0.12:888 home ~ # iptables -A PREROUTING -t nat -i eth0 -p tcp --dport 80 -j DNAT --to 10.0.0.12
that fails to do anything
home ~ # !nmap nmap -A -d -T4 10.0.0.12
Starting Nmap 5.21 ( http://nmap.org ) at 2014-04-10 14:33 EDT PORTS: Using top 1000 ports found open (TCP:1000, UDP:0, SCTP:0) --------------- Timing report --------------- hostgroups: min 1, max 100000 rtt-timeouts: init 500, min 100, max 1250 max-scan-delay: TCP 10, UDP 1000, SCTP 10 parallelism: min 0, max 0 max-retries: 6, host-timeout: 0 min-rate: 0, max-rate: 0 --------------------------------------------- NSE: Loaded 36 scripts for scanning. Initiating ARP Ping Scan at 14:33 Scanning 10.0.0.12 [1 port] Packet capture filter (device eth1): arp and arp[18:4] = 0x0001C014 and arp[22:2] = 0x3C0F Completed ARP Ping Scan at 14:33, 0.01s elapsed (1 total hosts) Overall sending rates: 122.34 packets / s, 5138.24 bytes / s. mass_rdns: Using DNS server 167.206.13.180 mass_rdns: Using DNS server 167.206.13.181 Initiating Parallel DNS resolution of 1 host. at 14:33 mass_rdns: 0.01s 0/1 [#: 2, OK: 0, NX: 0, DR: 0, SF: 0, TR: 1] Completed Parallel DNS resolution of 1 host. at 14:33, 0.01s elapsed DNS resolution of 1 IPs took 0.01s. Mode: Async [#: 2, OK: 0, NX: 1, DR: 0, SF: 0, TR: 1, CN: 0] Initiating SYN Stealth Scan at 14:33 Scanning 10.0.0.12 [1000 ports] Packet capture filter (device eth1): dst host 10.0.0.5 and (icmp or ((tcp or udp or sctp) and (src host 10.0.0.12))) Discovered open port 135/tcp on 10.0.0.12 Discovered open port 139/tcp on 10.0.0.12 Increased max_successful_tryno for 10.0.0.12 to 1 (packet drop) Completed SYN Stealth Scan at 14:33, 1.24s elapsed (1000 total ports) Overall sending rates: 870.72 packets / s, 38311.81 bytes / s. Initiating Service scan at 14:33 Scanning 2 services on 10.0.0.12 Completed Service scan at 14:33, 6.01s elapsed (2 services on 1 host) Starting RPC scan against 10.0.0.12 Packet capture filter (device eth1): dst host 10.0.0.5 and (icmp or (tcp and (src host 10.0.0.12))) Initiating OS detection (try #1) against 10.0.0.12 OS detection timingRatio() == (1397154829.418 - 1397154828.918) * 1000 / 500 == 1.002 NSE: Script scanning 10.0.0.12. NSE: Starting runlevel 1 (of 1) scan. Initiating NSE at 14:33 NSE: NSE Script Threads (4) running: NSE: Starting smbv2-enabled against 10.0.0.12. NSE: Starting smb-os-discovery against 10.0.0.12. NSE: Starting p2p-conficker against 10.0.0.12. NSE: Starting nbstat against 10.0.0.12. NSE: Conficker: Generating ports based on ip (0x0c00000a) and seed (2309) NSE: SMB: Added account '' to account list NSE: SMB: Added account 'guest' to account list NSE: SMB: Trying to start NetBIOS session with name = '*SMBSERVER' NSE: Finished nbstat against 10.0.0.12. NSE: SMB: Session request failed, trying next name NSE: SMB: None of the NetBIOS names worked! NSE: Finished smb-os-discovery against 10.0.0.12. NSE: SMB: Trying to start NetBIOS session with name = '*SMBSERVER' NSE: SMB: Session request failed, trying next name NSE: SMB: None of the NetBIOS names worked! NSE: smbv2-enabled against 10.0.0.12 threw an error! /usr/share/nmap/scripts/smbv2-enabled.nse:37: attempt to concatenate global 'smb' (a table value) stack traceback: /usr/share/nmap/scripts/smbv2-enabled.nse:37: in function 'go' /usr/share/nmap/scripts/smbv2-enabled.nse:52: in function
(tail call): ?
NSE: Finished p2p-conficker against 10.0.0.12. Completed NSE at 14:33, 0.03s elapsed NSE: Script Scanning completed. Nmap scan report for 10.0.0.12 Host is up, received arp-response (0.00048s latency). Scanned at 2014-04-10 14:33:41 EDT for 9s Not shown: 998 closed ports Reason: 998 resets PORT STATE SERVICE REASON VERSION 135/tcp open msrpc syn-ack Microsoft Windows RPC 139/tcp open netbios-ssn syn-ack MAC Address: 78:45:C4:0B:BC:D4 (Unknown) Device type: general purpose Running: Microsoft Windows XP OS details: Microsoft Windows XP SP2 or SP3, or Windows Server 2003 TCP/IP fingerprint: OS:SCAN(V=5.21%D=4/10%OT=135%CT=1%CU=38712%PV=Y%DS=1%DC=D%G=Y%M=7845C4%TM=5 OS:346E40E%P=i686-pc-linux-gnu)SEQ(SP=107%GCD=1%ISR=10A%TI=I%CI=I%II=I%SS=S OS:%TS=0)OPS(O1=M5B4NW0NNT00NNS%O2=M5B4NW0NNT00NNS%O3=M5B4NW0NNT00%O4=M5B4N OS:W0NNT00NNS%O5=M5B4NW0NNT00NNS%O6=M5B4NNT00NNS)WIN(W1=FFFF%W2=FFFF%W3=FFF OS:F%W4=FFFF%W5=FFFF%W6=FFFF)ECN(R=Y%DF=Y%T=80%W=FFFF%O=M5B4NW0NNS%CC=N%Q=) OS:T1(R=Y%DF=Y%T=80%S=O%A=S+%F=AS%RD=0%Q=)T2(R=Y%DF=N%T=80%W=0%S=Z%A=S%F=AR OS:%O=%RD=0%Q=)T3(R=Y%DF=Y%T=80%W=FFFF%S=O%A=S+%F=AS%O=M5B4NW0NNT00NNS%RD=0 OS:%Q=)T4(R=Y%DF=N%T=80%W=0%S=A%A=O%F=R%O=%RD=0%Q=)T5(R=Y%DF=N%T=80%W=0%S=Z OS:%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=N%T=80%W=0%S=A%A=O%F=R%O=%RD=0%Q=)T7(R=Y OS:%DF=N%T=80%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)U1(R=Y%DF=N%T=80%IPL=B0%UN=0%RIP OS:L=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%DFI=S%T=80%CD=Z)
Network Distance: 1 hop TCP Sequence Prediction: Difficulty=263 (Good luck!) IP ID Sequence Generation: Incremental Service Info: OS: Windows
Host script results: | nbstat: |_ ERROR: Couldn't find NetBIOS server name | smb-os-discovery: |_ ERROR: SMB: Couldn't find a NetBIOS name that works for the server. Sorry!
HOP RTT ADDRESS 1 0.48 ms 10.0.0.12 Final times for host: srtt: 477 rttvar: 107 to: 100000
Read from /usr/share/nmap: nmap-mac-prefixes nmap-os-db nmap-rpc nmap-service-probes nmap-services. OS and Service detection performed. Please report any incorrect results at http://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 10.58 seconds Raw packets sent: 1098 (49.024KB) | Rcvd: 1017 (41.244KB)
home ~ # nmap -v -sP 10.0.0.0/24
Starting Nmap 5.21 ( http://nmap.org ) at 2014-04-10 14:38 EDT Initiating ARP Ping Scan at 14:38 Scanning 5 hosts [1 port/host] Completed ARP Ping Scan at 14:38, 0.21s elapsed (5 total hosts) Nmap scan report for 10.0.0.0 [host down] Nmap scan report for 10.0.0.1 [host down] Nmap scan report for 10.0.0.2 [host down] Nmap scan report for 10.0.0.3 [host down] Nmap scan report for 10.0.0.4 [host down] Initiating Parallel DNS resolution of 1 host. at 14:38 Completed Parallel DNS resolution of 1 host. at 14:38, 0.01s elapsed Nmap scan report for 10.0.0.5 Host is up. Initiating ARP Ping Scan at 14:38 Scanning 250 hosts [1 port/host] Completed ARP Ping Scan at 14:38, 1.93s elapsed (250 total hosts) Initiating Parallel DNS resolution of 250 hosts. at 14:38 Completed Parallel DNS resolution of 250 hosts. at 14:38, 0.01s elapsed Nmap scan report for 10.0.0.6 [host down] Nmap scan report for 10.0.0.7 [host down] Nmap scan report for 10.0.0.8 [host down] Nmap scan report for 10.0.0.9 [host down] Nmap scan report for 10.0.0.10 Host is up (0.00016s latency). MAC Address: 00:30:67:81:F0:4C (Biostar Microtech Int'l) Nmap scan report for 10.0.0.11 Host is up (0.00011s latency). MAC Address: 40:61:86:7F:CC:CB (Micro-star Int'l Co.) Nmap scan report for 10.0.0.12 Host is up (0.00027s latency). MAC Address: 78:45:C4:0B:BC:D4 (Unknown)
ehhh
Any idea what port I need to open, what port i need to forward from the outside, what port I need forward to on the inside and what iptable commands I might use?
Ruben
|
|