Dahua SmartPSS V2.X device account recovery

iTuneDVR

Pulling my weight
Aug 23, 2014
883
163
Россия
[+] Decrypt Dahua SmartPSS V2.X device hash username & password from OrganizationDevice.xml
[+] Decrypt Dahua SmartPSS V2.X device hash passwords from export Device.xml
 
Last edited:
  • Like
Reactions: shelestoff
Hello,

I need help to decrypt the password for one NVR in Smart PSS V2 (old version).

Device name: Taller

Encoded username: yjEMA0HUurUHH0bSSuBr3A==
Encoded password: fRPJUOcDAdHxQl615K7r1A==

Could someone please run these through the decryption tool/bot?

Thank you very much!
 
Encoded username: yjEMA0HUurUHH0bSSuBr3A==
Encoded password: fRPJUOcDAdHxQl615K7r1A==
For bot need hash from export.xml, from loaded SmartPSS. All you show data from file OrganizationDevice.xml.
Show all file as is or make export and put hash to bot
 
Hello,

Thank you for the clarification. This is the exported device list from loaded SmartPSS (Devices > Export XML or similar).

Full device.xml content:

<?xml version="1.0" encoding="UTF-8"?>
<DeviceManager version="2.0">
<Device name="Almacén Nuevo" domain="192.168.250.26" port="37777" username="IT" password="SeUmK2U2j5IshOGhaKby5KT1P8/yXwE4u3ak5ZfBzmmUScFXSSY5AwE/8+JU" protocol="1" connect="0" />
<Device name="Curados1" domain="192.168.250.27" port="41176" username="IT" password="5EHkQoPg7XOS+nhyzNtee8B8Lik5d/kdcwD8vyoeXY8KZvgOvHtr49SxnJif" protocol="1" connect="0" />
<Device name="Curados2" domain="192.168.250.28" port="37777" username="IT" password="pFXWIJbvqVd/gRoMnYdeKHG6bLkwQRInT/8i9w6+M6Yx07vt2CdPRNnMtDgu" protocol="1" connect="0" />
<Device name="Entrada Hi...(truncated 1008 characters)...O/ebiBoWcqnEiGXWCArSxsc90dx7Ze/SPzCJ" protocol="1" connect="0" />
<Device name="Grabador Nuevo 2" domain="192.168.250.101" port="37777" username="IT" password="tIq84OUM3bwRPH2inggctKXIRwoVq50eed8FbyrpVy35ksJcZtiLxAFCmVIh" protocol="1" connect="0" />
<Device name="Grabador Nuevo 3" domain="192.168.250.102" port="37777" username="IT" password="gmHGFl+GdhF2FxUEYvNmy0LFDzAmT3EZYHypCkMLpF43mHjqmKWRlJjUfJ2B" protocol="1" connect="0" />
<Device name="Taller" domain="192.168.250.105" port="37777" username="Argal" password="RLmIoIfLBOMSwPXlP+RD1CgbAQIJ6+QeaeQm2hBt0959JUcOQZILm9cb" protocol="1" connect="0" />
</DeviceManager>

Please run this through the bot/decryption tool. Especially interested in the "Taller" device (username "Argal").

Thank you very much!
 

Attachments

All hash from device.xml decrypted.
Very strange, that all password are the same, except last one "Taller"

And this
Encoded username: yjEMA0HUurUHH0bSSuBr3A==
Encoded password: fRPJUOcDAdHxQl615K7r1A==
not corresponding to "Taller" data.
Very strange. Not clear.
 
Last edited:
All hash from device.xml decrypted.
Very strange, that all password are the same, except last one "Taller"

And this

not corresponding to "Taller" data.
Very strange. Not clear.
Thank you for checking!

Yes, all the "IT" devices share the same password (that's normal in our setup).

The one I urgently need is only for "Taller":
  • Name: Taller
  • Username: Argal
  • Encrypted password: RLmIoIfLBOMSwPXlP+RD1CgbAQIJ6+QeaeQm2hBt0959JUcOQZILm9cb

Could you please share the decrypted plain text password for this one?

Thanks a lot in advance!