daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

554-8554-pentesting-rtsp.md (6092B)


      1 ---
      2 title: "554,8554 - Pentesting RTSP"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/554-8554-pentesting-rtsp.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/554-8554-pentesting-rtsp.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 554,8554 - Pentesting RTSP
     14 
     15 ## Basic Information
     16 
     17 From [wikipedia](https://en.wikipedia.org/wiki/Real_Time_Streaming_Protocol):<sup>[[1]](#references)</sup>
     18 
     19 > The **Real Time Streaming Protocol** (**RTSP**) is a network control protocol designed for use in entertainment and communications systems to control streaming media servers. The protocol is used for establishing and controlling media sessions between end points. Clients of media servers issue VHS-style commands, such as play, record and pause, to facilitate real-time control of the media streaming from the server to a client (Video On Demand) or from a client to the server (Voice Recording).
     20 >
     21 > The transmission of streaming data itself is not a task of RTSP. Most RTSP servers use the Real-time Transport Protocol (RTP) in conjunction with Real-time Control Protocol (RTCP) for media stream delivery. However, some vendors implement proprietary transport protocols. The RTSP server software from RealNetworks, for example, also used RealNetworks' proprietary Real Data Transport (RDT).
     22 
     23 <sup>[[1]](#references)</sup>
     24 
     25 **Default ports:** 554,8554
     26 
     27 ```text
     28 PORT    STATE SERVICE
     29 554/tcp open  rtsp
     30 ```
     31 
     32 ## Key Details
     33 
     34 **RTSP** is similar to HTTP but designed for control of media sessions. RTSP 2.0 is standardized in RFC 7826, which obsoletes the older RFC 2326 still implemented by many devices.<sup>[[4]](#references)</sup>
     35 
     36 The original RTSP 1.0 specification is RFC 2326.<sup>[[4]](#references)</sup>
     37 
     38 Devices might allow **unauthenticated** or **authenticated** access. To check, a "DESCRIBE" request is sent. A basic example is shown below:
     39 
     40 `DESCRIBE rtsp://<ip>:<port> RTSP/1.0\r\nCSeq: 2`
     41 
     42 Remember, the correct formatting includes a double "\r\n" for a consistent response. A "200 OK" response indicates **unauthenticated access**, while "401 Unauthorized" signals the need for authentication, revealing if **Basic** or **Digest authentication** is required.
     43 
     44 For **Basic authentication**, you encode the username and password in base64 and include it in the request like so:
     45 
     46 `DESCRIBE rtsp://<ip>:<port> RTSP/1.0\r\nCSeq: 2\r\nAuthorization: Basic YWRtaW46MTIzNA==`
     47 
     48 This example uses "admin" and "1234" for the credentials. Here's a **Python script** to send such a request:
     49 
     50 ```python
     51 import socket
     52 req = "DESCRIBE rtsp://<ip>:<port> RTSP/1.0\r\nCSeq: 2\r\nAuthorization: Basic YWRtaW46MTIzNA==\r\n\r\n"
     53 s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
     54 s.connect(("192.168.1.1", 554))
     55 s.sendall(req.encode())
     56 data = s.recv(1024)
     57 print(data)
     58 ```
     59 
     60 **Basic authentication** is simpler to test but only Base64-encodes credentials and therefore requires TLS for confidentiality. Digest avoids sending the clear password but still needs correct nonce, realm, URI, and algorithm handling; prefer the strongest mechanism the device supports over a protected transport.<sup>[[5]](#references)</sup>
     61 
     62 This overview simplifies the process of accessing RTSP streams, focusing on **Basic authentication** for initial validation.<sup>[[5]](#references)</sup>
     63 
     64 ## Enumeration
     65 
     66 Enumerate supported methods and candidate media URLs, then perform bounded credential testing only when it is authorized.
     67 
     68 ```bash
     69 nmap -sV --script "rtsp-*" -p <PORT> <IP>
     70 ```
     71 
     72 For path discovery specifically, `rtsp-url-brute` sends `DESCRIBE` requests for entries in its URL dictionary and reports the response classes.<sup>[[2]](#references)</sup>
     73 
     74 #### Viewing the RTSP stream with `ffplay` <sup>[[6]](#references)</sup>
     75 Once you've discovered a valid RTSP path (e.g., `/mpeg4`, `/live.sdp`) and confirmed access (unauthenticated or with credentials), you can use `ffplay` to stream the feed:
     76 ```bash
     77 ffplay -rtsp_transport tcp rtsp://<IP>/mpeg4 -x 2560 -y 1440
     78 ```
     79 - `-rtsp_transport tcp`: Use TCP instead of UDP for more reliable streaming
     80 - `-x`, `-y`: Optional flags to control video resolution
     81 - Replace `<IP>` and path as needed
     82 
     83 ### [Brute Force](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/brute-force.md#rtsp)
     84 
     85 ### **Other useful programs**
     86 
     87 For bounded credential testing, `rtsp_authgrinder` is one available tool.<sup>[[7]](#references)</sup>
     88 
     89 [**Cameradar**](https://github.com/Ullaakut/cameradar)<sup>[[3]](#references)</sup>
     90 
     91 - Detect open RTSP hosts on any accessible target
     92 - Get their public info (hostname, port, camera model, etc.)
     93 - Launch automated dictionary attacks to get their stream route (for example /live.sdp)
     94 - Launch automated dictionary attacks to get the username and password of the cameras
     95 - Generate thumbnails from them to check if the streams are valid and to have a quick preview of their content
     96 - Try to create a Gstreamer pipeline to check if they are properly encoded
     97 - Print a summary of all the information Cameradar could collect
     98 
     99 ### See also
    100 
    101 [32100 Udp Pentesting Pppp Cs2 P2P Cameras](/hacktricks/network-services-pentesting/32100-udp-pentesting-pppp-cs2-p2p-cameras)
    102 
    103 ## References
    104 
    105 - [1] [Real Time Streaming Protocol - Wikipedia](https://en.wikipedia.org/wiki/Real_Time_Streaming_Protocol)
    106 - [2] [Nmap NSE — `rtsp-url-brute`](https://nmap.org/nsedoc/scripts/rtsp-url-brute.html)
    107 - [3] [Cameradar - RTSP surveillance camera access tool - GitHub](https://github.com/Ullaakut/cameradar)
    108 - [4] [RFC 7826 — Real-Time Streaming Protocol Version 2.0](https://www.rfc-editor.org/rfc/rfc7826.html)
    109 - [5] [RFC 7617 — Basic HTTP Authentication](https://www.rfc-editor.org/rfc/rfc7617.html)
    110 - [6] [FFmpeg — `ffplay` documentation](https://ffmpeg.org/ffplay.html)
    111 - [7] [Tek-Security-Group/rtsp_authgrinder](https://github.com/Tek-Security-Group/rtsp_authgrinder)